UNC6671 Runs Multi-Brand Vishing Extortion Against Financial and Legal Cloud Environments

Share:

Google Threat Intelligence has detailed UNC6671, a financially motivated group that tricks employees
into handing over their logins by phone. Callers pose as IT helpdesk staff, claim an urgent passkey or
multi-factor authentication update is required, and send the victim to a fake login page that steals the
password and the MFA code in real time, then quietly copies data out of Microsoft 365 and Okta. The
group hides behind several extortion brands (Redact, Pink, Helix, and Falcon), has collected roughly
10.69 million US dollars in tracked ransoms, and is now focused on financial, private equity, and legal
firms

1. Campaign Overview

Google Threat Intelligence Group tracks UNC6671 as a coordinated extortion operation that rebranded from BlackFile to Redact around May 2026 and now publishes victims under the Redact, Pink, Helix, and Falcon brands, tied together by shared phishing infrastructure and templates. Targeting has shifted steadily toward higher-value data: broad enterprises in April and May, technology and hospitality in June, and financial, private equity, and legal firms by July, at a pace of about one new phishing domain every 1.6 days. GTIG tracked 141.65 BTC, roughly 10.69 million US dollars, paid to 18 BlackFile wallets between January and May 2026, with payments continuing past the group’s public shutdown.

2. Attack Details

Vishing pretext

Callers pose as IT helpdesk and phone employees, often on their personal mobile numbers and sometimes spoofing the real helpdesk number, claiming an urgent mandate to enrol a FIDO2 passkey or update MFA.

AiTM credential theft

Victims are directed to passkey, SSO, or MFA-themed lookalike domains carrying their company name, where adversary-in-the-middle infrastructure captures credentials and MFA tokens in real time, defeating standard multifactor authentication

Session persistence and exfiltration

With a live session established, the actor runs automated scripts to exfiltrate data from Microsoft 365 and Okta, using scripting user agents and residential or commercial VPN proxies to blend in with normal traffic.

Evasion

The actor uses compromised mailboxes to reset passwords on non-SSO applications and systematically deletes password-reset confirmations, security notifications, and MFA-change alerts to avoid detection.

Extortion

Stolen data is used for extortion, with victims published across the group’s multiple data-leak sites. Initial demands run from one to over three million US dollars, often negotiated down by 50 to 75 per cent.

3. Adversary Toolkit

Tool / IndicatorTypeFunction
AiTM phishing panelsAdversary-in-the-middle kitReverse-proxy panels on passkey, SSO, and MFA-themed
domains that capture credentials and MFA tokens in real
time.
Automated SaaS
exfiltration scripts
Scripting (python-requests,
PowerShell, Go)
Programmatically pull data from Microsoft 365 and Okta
once a session is hijacked.
Residential and VPN
proxies
Anonymisation
infrastructure
Commercial VPN (Private Layer) and residential proxy pools
used to blend authentication into normal user geographies.

4. Indicators of Compromise (IOCs)

Full IOC collection published to VirusTotal:

  • https://www.virustotal.com/gui/collection/68a3ad0b80290ff51410cc95d0b1e728d5ffaa933e2230b291bd48fbdc406756

5. Recommendations

  • Enforce phishing-resistant MFA (FIDO2 security keys, passkeys, Windows Hello for Business, Okta FastPass) across all SSO environments and identity providers; WebAuthn origin binding defeats lookalike domains and adversary-in-the-middle proxies.
  • Integrate business-critical SaaS applications and cloud platforms with a single SSO provider such as Entra ID or Okta so security controls apply consistently.
  • Enforce session controls: short session lifetimes, idle timeouts, step-up authentication for sensitive resources, and token-theft mitigations such as IP session binding, Device-Bound Session Credentials, and Continuous Access Evaluation.
  • Restrict authentication to trusted network sources (corporate networks, VPN ranges, SASE) within SaaS and identity-provider policies.
  • Require corporate-managed devices with MDM and EDR for access, enforced through Entra ID or Okta device checks.
  • Deploy endpoint and browser credential guarding: Google Workspace Password Alert, and Microsoft Defender SmartScreen with Credential Protection for Microsoft 365.
  • Monitor Okta and Entra ID logs for MFA setup events (system.multifactor.factor.setup) that immediately follow authentication failures or abandoned push challenges.
  • In SaaS audit logs, treat FileAccessed events like FileDownloaded when the user agent is a scripting library (python-requests, WindowsPowerShell, Go-http-client) or the access volume exceeds normal human levels.
  • Create conditional-access alerts for SSO logins from commercial VPNs (Mullvad, Private Layer) or residential proxy pools that diverge from an employee’s usual location.
  • Block the IOCs at their respective controls, https://www.virustotal.com/gui/collection/68a3ad0b8029
  • 0ff51410cc95d0b1e728d5ffaa933e2230b291bd48fbdc406756

6. Sources

  • https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments
  • https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operat

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert