UNC6671 Rebrands: Vishing Extortion Targets Financial Firms
Quick answer
UNC6671 rebrands as Redact, Pink, Helix, and Falcon, targeting financial services with vishing and AiTM phishing. Learn how to defend your cloud.
Google Threat Intelligence Group (GTIG) has been tracking UNC6671, a threat actor that supposedly retired its BlackFile extortion brand back in May 2026. But guess what? They didn’t pack their bags and head for the swamp—they just changed their hats. Now they’re operating under multiple brands: Redact, Pink, Helix, and Falcon.
These folks are the caimans of the phishing world—sneaky, persistent, and always looking for the next meal. Their favorite trick? Vishing, or voice phishing, where they pose as IT helpdesk staff and call employees on their personal phones, claiming there’s an urgent security migration. They then direct victims to spoofed login portals that steal credentials and MFA tokens.
Once they’ve got a session, they deploy automated scripts to exfiltrate data from enterprise cloud environments like Microsoft 365 and Okta. And they’re not just casting a wide net—they’re zeroing in on financial services, private equity, and professional services. Time to batten down the hatches, folks.
The Rebranding Shell Game
In June 2026, the Redact operators posted a blog on their new data leak site, claiming the BlackFile brand had been hijacked by a rogue affiliate. They said they rebranded to distance themselves from the chaos. But GTIG’s telemetry tells a different story: the infrastructure overlaps are too tight to be coincidence.
They’re reusing the same phishing domains across different brands. For example, passkeyhelpdesk[.]com was used to target victims claimed by both Falcon and Helix. The same phishing templates are hosted on multiple domains simultaneously. It’s like watching a capybara family share the same mud hole—they’re all in it together.
Targeting Evolution: From Broad to Bullseye
UNC6671’s domain registrations show a clear shift in targeting strategy. Between April and May, they were going after large enterprises in manufacturing, real estate, healthcare, and insurance. But by June, they pivoted to tech, transportation, and hospitality—places with juicy intellectual property and VIP client data.
By July, they narrowed their focus to financial and legal sectors: private equity firms, law firms, and financial rating agencies. Makes sense—if you’re going to extort, you want data that’s worth the ransom. They’re also picking up the pace, registering a new domain every 1.6 days in June and July, compared to every 2.2 days earlier.
New Tricks in the Playbook
UNC6671 is getting craftier. They’re spoofing legitimate helpdesk numbers to add an air of legitimacy. They’re calling employees on personal mobiles, bypassing corporate security controls. And they’re using the pretext of enabling FIDO2 passkeys or updating MFA to lure victims to lookalike domains.
They’ve also stepped up their evasion game. After compromising an account, they delete password-reset confirmations and security alerts to avoid detection. It’s like they’re sweeping their footprints in the mud before the caimans arrive.
The Money Trail
Between January and May 2026, GTIG tracked 18 BlackFile Bitcoin wallets that received 141.65 BTC—about $10.69 million at the time. Ransom payments continued even after the supposed shutdown. Initial demands range from $1 million to $3 million, but they often settle for 50-75% less, with final payments averaging around $750,000.
How to Protect Your Swamp
GTIG recommends a bunch of hardening measures. Here are the highlights:
- Enforce phishing-resistant MFA: Use FIDO2 security keys or passkeys that bind to specific domains, making AiTM proxies useless.
- Integrate SaaS apps with SSO: Centralize authentication with platforms like Entra ID or Okta to avoid configuration drift.
- Enforce session controls: Shorten session lengths, require re-authentication, and use token theft mitigations like IP binding.
- Restrict authentication to trusted networks: Define corporate VPN ranges and enforce them in your IdP policies.
- Require corporate-managed devices: Use MDM and EDR to ensure only managed endpoints can authenticate.
- Deploy credential guarding: Use tools like Google Workspace Password Alert or Microsoft Defender SmartScreen to block credential submission on fake sites.
- Monitor IdP logs: Look for MFA setup events following abandoned challenges—a classic sign of AiTM phishing.
- Audit for scripted exfiltration: Treat
FileAccessedevents with the same urgency as downloads when the user agent is a scripting library likepython-requests. - Alert on residential proxy auth: Flag SSO attempts from commercial VPNs or residential proxy pools that don’t match employee baselines.
The Bottom Line
UNC6671 is a prime example of how threat actors adapt and rebrand while keeping the same playbook. Whether it’s a single group running multiple brands or a splintered network, the tactics remain consistent: vishing, AiTM phishing, and SaaS exfiltration.
For developers and security teams, the takeaway is clear: phishing-resistant MFA and vigilant SaaS auditing are your best defenses. Don’t let these caimans sneak into your swamp—keep your authentication tight and your logs monitored.
For more on securing your cloud environments, check out our reviews of Cloudflare Workers and Google Cloud to see how they stack up against these threats.
Original announcement published on Google Cloud.