A Sophisticated Vishing Extortion Group Rebrands and Continues to Rake in Millions
A highly organized group of threat actors, known for their tailored IT helpdesk voice phishing (vishing) attacks, has rebranded its operations over the past several months. The group, which emerged in early 2026 under the name “BlackFile”, has been making millions by targeting organizations across North America, Australia, and the UK.
The group’s primary focus is on Microsoft 365 and Okta infrastructure, where they use adversary-in-the-middle (AiTM) techniques to bypass defenses and multi-factor authentication (MFA). By leveraging these tactics, the threat actors gain access to cloud environments and demand significant ransom payments from their victims. The group has recently diversified its operations under multiple brands: Redact, Pink, Helix, and Falcon.
The typical modus operandi of UNC6671 involves posing as IT helpdesk employees, calling employees at the victim organizations on their personal mobile phones, and convincing them to visit spoofed login portals to intercept their credentials and MFA tokens. The group’s initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained consistent despite the rebranding efforts.
One of the most striking aspects of UNC6671’s operations is its use of generic root domains across multiple victims. These domains are often used to host tailored credential harvesting panels that target specific organizations. The group has also been using compromised email addresses and spoofed helpdesk phone numbers to reset passwords for non-SSO enterprise applications, while deleting confirmation messages, alerts, and notifications to prevent detection.
According to Google Threat Intelligence Group (GTIG), the group has received over $10 million in Bitcoin across 18 wallet addresses between January and May. The ransom demands typically range from $1 million to upwards of $3 million USD, with final payments averaging $750,000 after negotiations.
The rebranding efforts by UNC6671 have raised concerns about the sophistication and adaptability of these threat actors. As organizations continue to face increasing threats from vishing attacks, it is essential for them to remain vigilant and implement robust security measures to prevent such incidents. This includes educating employees on phishing tactics, implementing robust MFA, and regularly monitoring their systems for suspicious activity.
To stay ahead of these threats, organizations should focus on enhancing their cybersecurity posture by:
* Implementing robust multi-factor authentication (MFA) and regular password rotations
* Conducting regular security awareness training for employees to identify and report suspicious activities
* Monitoring their systems for unusual login attempts and suspicious network traffic
* Regularly updating software and patches to prevent exploitation of vulnerabilities
By taking these measures, organizations can reduce the risk of falling victim to vishing attacks and protect themselves from the devastating financial consequences that follow.
Source: SecurityWeek — 2026-08-07