Cyber Extortion Group UNC6671 Rebrands After Raking in Millions
A sophisticated cyber extortion group known as UNC6671 has been making headlines for its clever tactics, evading detection by rebranding and diversifying its operations. According to Google Threat Intelligence Group (GTIG), the threat actor has been operating since early 2026, initially under the name “BlackFile,” before shifting to new brands such as Redact, Pink, Helix, and Falcon. What’s most alarming is that despite these changes, the group’s tactics remain consistent.
UNC6671 specializes in tailored IT helpdesk voice phishing (vishing), a sophisticated form of social engineering where attackers pose as IT support employees to trick victims into divulging sensitive information. They target organizations across North America, Australia, and the UK, focusing primarily on Microsoft 365 and Okta infrastructure. The group uses adversary-in-the-middle (AiTM) techniques to bypass defenses and multi-factor authentication (MFA), gaining access to cloud environments.
The attack typically begins with a phone call to an employee’s personal mobile phone, where the attacker poses as an IT support representative, claiming there is a mandatory security migration that requires immediate attention. The victim is lured into visiting a spoofed login portal, where their credentials and MFA tokens are intercepted. Despite the group’s branding changes, GTIG notes that the initial access and post-compromise tactics remain consistent.
The group has established multiple data leak sites under different brands, with the most recent one being Redact in June. In these sites, UNC6671 announces its departure from BlackFile, claiming the operation had been hijacked by an affiliate. However, GTIG’s monitoring of the group’s digital footprint suggests that there are overlaps between the operations of other extortion brands, suggesting a common group of threat actors.
One of the most notable aspects of UNC6671’s tactics is their use of generic root domains across multiple victims, such as passkeyhelpdesk[.]com and portalpasskey[.]com. While some domains were exclusively used by specific extortion brands, they could be linked to UNC6671 activity through the phishing templates deployed to harvest credentials.
The group has been successful in extorting over $10 million in Bitcoin across 18 wallet addresses between January and May, with initial ransom demands ranging from $1 million to upwards of $3 million. However, during negotiations, the extortion operators often agree to reductions between 50% and 75% of the initial demand.
As this cyber extortion group continues to evolve and adapt its tactics, organizations must remain vigilant in protecting their employees and infrastructure. One key takeaway is that UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. By monitoring these patterns and being aware of the tactics used by this group, organizations can take proactive measures to prevent such attacks.
Practically speaking, it’s essential for employees to be cautious when receiving unsolicited phone calls or emails from IT support representatives, especially if they’re asked to provide sensitive information or visit a spoofed login portal. Organizations should also implement robust security measures, including multi-factor authentication and regular software updates, to prevent attackers from bypassing defenses. By staying informed and taking proactive steps, organizations can minimize the risk of falling victim to UNC6671’s sophisticated cyber extortion tactics.
Source: SecurityWeek — 2026-08-07