Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Terafab Rendered in a Video – NextBigFuture.com

    August 7, 2026

    Best Mid-Range Phone 2026: Unbeatable value

    August 7, 2026

    Here’s an easy way to display your steelbooks as art

    August 7, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Vishing Extortion Group UNC6671 Rebrands After Making Millions
    Vishing Extortion Group UNC6671 Rebrands After Making Millions
    Cybersecurity

    Vishing Extortion Group UNC6671 Rebrands After Making Millions

    The Tech GuyBy The Tech GuyAugust 7, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    UNC6671, an extortion group engaging in tailored IT helpdesk voice phishing (vishing), has rebranded and diversified its operations over the past several months, Google Threat Intelligence Group (GTIG) reports.

    Advertisement

    The threat actor emerged in early 2026, operating under the ‘BlackFile’ name. In May, GTIG warned it had targeted dozens of organizations across North America, Australia, and the UK in sophisticated vishing and single sign-on (SSO) compromise attacks.

    Mainly focusing on Microsoft 365 and Okta infrastructure, it was leveraging adversary-in-the-middle (AiTM) techniques to bypass defenses and multi-factor authentication (MFA) and gain access to cloud environments.

    In May, GTIG now says, the group retired the BlackFile extortion name, but has continued its activities under multiple brands: Redact, Pink, Helix, and Falcon. The latest attacks have focused on the financial services, private equity, and professional services sectors.

    Posing as IT helpdesk employees, UNC6671 threat actors have been calling employees at the victim organizations, often on personal mobile phones, under the pretext of mandatory, urgent security migrations, luring them to spoofed login portals to intercept their credentials and MFA tokens.

    Despite different branding in extortion messages, UNC6671’s initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained consistent, GTIG says.

    Advertisement. Scroll to continue reading.

    In June, the group established a new data leak site under the Redact brand, announcing the departure from BlackFile, claiming the operation had been hijacked by an affiliate. GTIG’s monitoring of UNC6671’s digital footprint showed overlaps with the operations of other extortion brands.

    “These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible,” GTIG says.

    The group has been using generic root domains across multiple victims, such as passkeyhelpdesk[.]com, portalpasskey[.]com, addssopasskey[.]com, passkeydeploy[.]com, mysecurepasskey[.]com, and passkeyuser[.]com.

    While some domains were exclusively used by specific extortion brands, they could be linked to UNC6671 activity through the phishing templates deployed to harvest credentials.

    “UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels,” GTIG notes.

    Recent attacks have demonstrated an evolution in tactics, with the threat actor spoofing legitimate helpdesk phone numbers and using compromised email addresses to reset the passwords for non-SSO enterprise applications, while deleting confirmation messages, alerts, and notifications to prevent detection.

    Between January and May, the group received over $10 million in Bitcoin across 18 wallet addresses, representing ransom payments. Some of the payments were made after the BlackFile shutdown announcement.

    “Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000,” GTIG notes.

    Related: Snowflake Hacker Pleads Guilty in US Court

    Related: Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

    Related: Weaponized Email AI Assistants Could Help Attackers Hijack Accounts

    Related: The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Podcast: Compliance Won’t Save You: The Future of Cyber Risk with Edna Conway

    August 7, 2026

    Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts

    August 6, 2026

    Snowflake Hacker Pleads Guilty in US Court

    August 6, 2026

    Meta AI Hacked External Systems During Cybersecurity Testing

    August 6, 2026

    The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

    August 6, 2026

    How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones 

    August 5, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Terafab Rendered in a Video – NextBigFuture.com

    August 7, 2026

    Best Mid-Range Phone 2026: Unbeatable value

    August 7, 2026

    Here’s an easy way to display your steelbooks as art

    August 7, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.