UNC6671 threat actor rebrands, targets financial services with vishing
The UNC6671 threat actor group, previously known for the BlackFile extortion brand, has diversified its operations under new names like Redact, Pink, Helix, and Falcon. They employ vishing tactics, impersonating IT support to trick employees into providing credentials via spoofed login portals, often targeting personal mobile devices. This allows them to exfiltrate data from cloud environments, with recent activity focusing on financial services and enterprise cloud infrastructure.
- →Vishing and AiTM used for credential harvesting
- →UNC6671 threat actor diversifies operations under multiple brands
- →Data exfiltration from enterprise cloud environments
- →Targeting evolves towards financial services and intellectual property
- →Infrastructure reuse connects multiple extortion brands
Features (1) ›
- Vishing and AiTM used for credential harvesting
UNC6671 primarily utilizes voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff for urgent security migrations. Victims are lured to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication tokens, often contacted via personal mobile devices.
Enhancements (2) ›
- Data exfiltration from enterprise cloud environments
Following successful credential harvesting, UNC6671 deploys automated scripts to exfiltrate data from enterprise cloud environments, including Microsoft 365 and Okta. The group's operations leverage shared infrastructure and phishing templates across its various associated extortion brands.
- Targeting evolves towards financial services and intellectual property
UNC6671's targeting patterns have evolved, shifting towards organizations that are more likely to hold sensitive information. Recent activity shows a focus on financial services, private equity, and professional services, as well as technology, transportation, and hospitality organizations holding valuable intellectual property.
Notes (3) ›
- UNC6671 threat actor diversifies operations under multiple brands
The UNC6671 threat actor group, previously associated with the BlackFile brand, has resurfaced under multiple new extortion brands including Redact, Pink, Helix, and Falcon. Despite an alleged retirement announcement for BlackFile, UNC6671 continues its operations, suggesting a rebranding rather than disbandment.
- Infrastructure reuse connects multiple extortion brands
Analysis reveals that UNC6671 reuses generic root domains across multiple target organizations, linking the Falcon, Helix, and Pink extortion brands. This shared infrastructure and consistent phishing templates suggest a common group of threat actors operating these distinct brands.
- Redact claims origin from compromised BlackFile brand
The Redact operators published a statement claiming their rebrand from BlackFile was due to a compromised and hijacked brand by an exiled affiliate. They asserted this affiliate orchestrated the 'shutdown' to cause confusion and distance themselves from the alleged rogue operations.
https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/
Related releases
- BigQuery Graph Adds Measures Support for Agentic Workloads (Preview) Google Cloud Blog ·
- Access Transparency for Firebase App Hosting enters Preview Google Cloud release notes ·
- Error Reporting Adds Rust Stack Trace Support on GCP Google Cloud release notes ·
- Firebase App Hosting Access Approval enters Preview Google Cloud release notes ·
- Apigee X Maintenance Updates Begin for Instances with Preferred Windows Google Cloud release notes ·
- Cloud Workstations adds Compute Engine VM suspend and resume in Preview Google Cloud release notes ·