UNC6671, an extortion group engaging in tailored IT helpdesk voice phishing (vishing), has rebranded and diversified its operations over the past several months, Google Threat Intelligence Group (GTIG) reports.
The threat actor emerged in early 2026, operating under the ‘BlackFile’ name. In May, GTIG warned it had targeted dozens of organizations across North America, Australia, and the UK in sophisticated vishing and single sign-on (SSO) compromise attacks.
Mainly focusing on Microsoft 365 and Okta infrastructure, it was leveraging adversary-in-the-middle (AiTM) techniques to bypass defenses and multi-factor authentication (MFA) and gain access to cloud environments.
In May, GTIG now says, the group retired the BlackFile extortion name, but has continued its activities under multiple brands: Redact, Pink, Helix, and Falcon. The latest attacks have focused on the financial services, private equity, and professional services sectors.
Posing as IT helpdesk employees, UNC6671 threat actors have been calling employees at the victim organizations, often on personal mobile phones, under the pretext of mandatory, urgent security migrations, luring them to spoofed login portals to intercept their credentials and MFA tokens.
Despite different branding in extortion messages, UNC6671’s initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained consistent, GTIG says.
In June, the group established a new data leak site under the Redact brand, announcing the departure from BlackFile, claiming the operation had been hijacked by an affiliate. GTIG’s monitoring of UNC6671’s digital footprint showed overlaps with the operations of other extortion brands.
“These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible,” GTIG says.
The group has been using generic root domains across multiple victims, such as passkeyhelpdesk[.]com, portalpasskey[.]com, addssopasskey[.]com, passkeydeploy[.]com, mysecurepasskey[.]com, and passkeyuser[.]com.
While some domains were exclusively used by specific extortion brands, they could be linked to UNC6671 activity through the phishing templates deployed to harvest credentials.
“UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels,” GTIG notes.
Recent attacks have demonstrated an evolution in tactics, with the threat actor spoofing legitimate helpdesk phone numbers and using compromised email addresses to reset the passwords for non-SSO enterprise applications, while deleting confirmation messages, alerts, and notifications to prevent detection.
Between January and May, the group received over $10 million in Bitcoin across 18 wallet addresses, representing ransom payments. Some of the payments were made after the BlackFile shutdown announcement.
“Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000,” GTIG notes.
Related: Snowflake Hacker Pleads Guilty in US Court
Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
Related: Weaponized Email AI Assistants Could Help Attackers Hijack Accounts
Related: The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
