[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDFcqEhdzJWLbZXDpXp0156R-zG5k8WUd-Q-jgyY7F6M":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"60afd0fe-914a-44b0-84d3-7121c4359399","Vishing Extortion Group UNC6671 Rebrands After Making Millions","vishing-extortion-group-unc6671-rebrands-after-making-millions-7c6beb","Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.","The vishing extortion group UNC6671, previously known as BlackFile, has rebranded and expanded its operations under new names including Redact, Pink, Helix, and Falcon. The group targets organizations by posing as IT helpdesk staff to trick employees into revealing credentials and MFA tokens through spoofed login portals. UNC6671 has reportedly extorted over $10 million in Bitcoin, with initial ransom demands ranging from $1 million to $3 million.","Vishing extortion group UNC6671, formerly BlackFile, rebrands under new names and continues operations.","UNC6671, an extortion group engaging in tailored IT helpdesk voice phishing (vishing), has rebranded and diversified its operations over the past several months, Google Threat Intelligence Group (GTIG) reports. The threat actor emerged in early 2026, operating under the ‘BlackFile’ name. In May, GTIG warned it had targeted dozens of organizations across North America, Australia, and the UK in sophisticated vishing and single sign-on (SSO) compromise attacks. Mainly focusing on Microsoft 365 and Okta infrastructure, it was leveraging adversary-in-the-middle (AiTM) techniques to bypass defenses and multi-factor authentication (MFA) and gain access to cloud environments. In May, GTIG now says, the group retired the BlackFile extortion name, but has continued its activities under multiple brands: Redact, Pink, Helix, and Falcon. The latest attacks have focused on the financial services, private equity, and professional services sectors. Posing as IT helpdesk employees, UNC6671 threat actors have been calling employees at the victim organizations, often on personal mobile phones, under the pretext of mandatory, urgent security migrations, luring them to spoofed login portals to intercept their credentials and MFA tokens. Despite different branding in extortion messages, UNC6671’s initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained consistent, GTIG says.Advertisement. Scroll to continue reading. In June, the group established a new data leak site under the Redact brand, announcing the departure from BlackFile, claiming the operation had been hijacked by an affiliate. GTIG’s monitoring of UNC6671’s digital footprint showed overlaps with the operations of other extortion brands. “These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible,” GTIG says. The group has been using generic root domains across multiple victims, such as passkeyhelpdesk[.]com, portalpasskey[.]com, addssopasskey[.]com, passkeydeploy[.]com, mysecurepasskey[.]com, and passkeyuser[.]com. While some domains were exclusively used by specific extortion brands, they could be linked to UNC6671 activity through the phishing templates deployed to harvest credentials. “UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels,” GTIG notes. Recent attacks have demonstrated an evolution in tactics, with the threat actor spoofing legitimate helpdesk phone numbers and using compromised email addresses to reset the passwords for non-SSO enterprise applications, while deleting confirmation messages, alerts, and notifications to prevent detection. Between January and May, the group received over $10 million in Bitcoin across 18 wallet addresses, representing ransom payments. Some of the payments were made after the BlackFile shutdown announcement. “Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000,” GTIG notes. Related: Snowflake Hacker Pleads Guilty in US Court Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison Related: Weaponized Email AI Assistants Could Help Attackers Hijack Accounts Related: The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Critical Paperclip Flaw Allowed Admin Access, Code ExecutionBelarusian Ransom Cartel Mastermind Gets 16 Years in PrisonCisco Patches Critical SD-WAN, IOS XE, FMC VulnerabilitiesHackers Start Exploiting Recent JetBrains TeamCity Vulnerability311,000 Impacted by Brown Health Medical Group-MA Data BreachAI Agents Targeted Real People and Projects During Cybersecurity TestsCISA Warns of Exploited Langflow, N-central, and Tomcat VulnerabilitiesOver 400 NPM Packages Infected in ChainDrop Supply Chain Attack Latest News Truck Brake Controller’s Safety Recall Doubled as Hidden Security FixBlack Hat USA 2026 – Summary of Vendor Announcements (Part 4)Microsoft, Apple Release Fresh Security Updates3.8 Million Impacted by Unlimited Technology Systems Data BreachCritical Vulnerabilities Patched With Chrome 151 UpdateSnowflake Hacker Pleads Guilty in US CourtZero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X PostsPodcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move1Kosmos has named Frank Cohen Chief Revenue Officer.ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.James Wilkinson has been named Chief Information Security Officer for the City of Dallas.More People On The MoveExpert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fvishing-extortion-group-unc6671-rebrands-after-making-millions\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F07\u002Fvishing.jpeg","2026-08-07T11:06:01+00:00","2026-08-07T12:00:14.471594+00:00",8,[18,21,23,26,28,31],{"name":19,"type":20},"UNC6671","threat_actor",{"name":22,"type":20},"BlackFile",{"name":24,"type":25},"Microsoft 365","product",{"name":27,"type":25},"Okta",{"name":29,"type":30},"Adversary-in-the-Middle (AiTM)","technology",{"name":32,"type":30},"Multi-Factor Authentication (MFA)","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":33,"icon":35,"name":36,"slug":37},null,"Threat Intelligence","threat-intelligence",[39,44,49,54],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":50},{"id":51,"icon":35,"name":52,"slug":53},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":55},{"id":33,"icon":35,"name":36,"slug":37},[57,61,63,65,67,69],{"type":58,"value":59,"context":60},"domain","passkeyhelpdesk[.]com","Generic root domain used by UNC6671 for credential harvesting.",{"type":58,"value":62,"context":60},"portalpasskey[.]com",{"type":58,"value":64,"context":60},"addssopasskey[.]com",{"type":58,"value":66,"context":60},"passkeydeploy[.]com",{"type":58,"value":68,"context":60},"mysecurepasskey[.]com",{"type":58,"value":70,"context":60},"passkeyuser[.]com"]