gcp Google Cloud Blog ·

UNC6671 threat actor rebrands, targets financial services with vishing

blogsecuritygcpengineerhealthcarefinanceretailmediagovernmentenergy
security announcement

The UNC6671 threat actor group, previously known for the BlackFile extortion brand, has diversified its operations under new names like Redact, Pink, Helix, and Falcon. They employ vishing tactics, impersonating IT support to trick employees into providing credentials via spoofed login portals, often targeting personal mobile devices. This allows them to exfiltrate data from cloud environments, with recent activity focusing on financial services and enterprise cloud infrastructure.

  • Vishing and AiTM used for credential harvesting
  • UNC6671 threat actor diversifies operations under multiple brands
  • Data exfiltration from enterprise cloud environments
  • Targeting evolves towards financial services and intellectual property
  • Infrastructure reuse connects multiple extortion brands
Features (1)
  • Vishing and AiTM used for credential harvesting

    UNC6671 primarily utilizes voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff for urgent security migrations. Victims are lured to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication tokens, often contacted via personal mobile devices.

Enhancements (2)
  • Data exfiltration from enterprise cloud environments

    Following successful credential harvesting, UNC6671 deploys automated scripts to exfiltrate data from enterprise cloud environments, including Microsoft 365 and Okta. The group's operations leverage shared infrastructure and phishing templates across its various associated extortion brands.

  • Targeting evolves towards financial services and intellectual property

    UNC6671's targeting patterns have evolved, shifting towards organizations that are more likely to hold sensitive information. Recent activity shows a focus on financial services, private equity, and professional services, as well as technology, transportation, and hospitality organizations holding valuable intellectual property.

Notes (3)
  • UNC6671 threat actor diversifies operations under multiple brands

    The UNC6671 threat actor group, previously associated with the BlackFile brand, has resurfaced under multiple new extortion brands including Redact, Pink, Helix, and Falcon. Despite an alleged retirement announcement for BlackFile, UNC6671 continues its operations, suggesting a rebranding rather than disbandment.

  • Infrastructure reuse connects multiple extortion brands

    Analysis reveals that UNC6671 reuses generic root domains across multiple target organizations, linking the Falcon, Helix, and Pink extortion brands. This shared infrastructure and consistent phishing templates suggest a common group of threat actors operating these distinct brands.

  • Redact claims origin from compromised BlackFile brand

    The Redact operators published a statement claiming their rebrand from BlackFile was due to a compromised and hijacked brand by an exiled affiliate. They asserted this affiliate orchestrated the 'shutdown' to cause confusion and distance themselves from the alleged rogue operations.

Read the original announcement →

https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/

Related releases