UNC6671, a financially motivated threat group known for UNC6671 vishing extortion, has changed its public-facing branding—yet the underlying playbook stays strikingly consistent. According to Google Threat Intelligence Group (GTIG), the group diversified its operations over recent months, retiring an earlier extortion name and shifting activity under multiple aliases. For security teams and employees alike, the important takeaway is this: the voice-driven social engineering, credential harvesting, and attempts to intercept authentication tokens remain central.
This article summarizes what GTIG observed, why the rebranding matters, and how organizations can reduce the risk of falling for these helpdesk impersonation calls.
From BlackFile to multiple aliases
GTIG reports that UNC6671 emerged in early 2026 under the name BlackFile. By May, the group had targeted dozens of organizations across North America, Australia, and the UK using sophisticated vishing and cloud-account compromise attempts.
In May, GTIG says the operators retired the BlackFile extortion brand. However, that did not mean the campaign stopped. Instead, the same threat activity continued under multiple names, including Redact, Pink, Helix, and Falcon.
The most recent focus sectors include financial services, private equity, and professional services. In other words, the group did not limit itself to one industry vertical; it selected targets where sensitive data and high-impact disruption could produce meaningful ransom leverage.
IT helpdesk impersonation and the “urgent migration” hook
A core element of UNC6671’s approach is social engineering that starts with the phone. GTIG describes attackers posing as IT helpdesk employees and calling individuals at victim organizations. The calls often reach employees via personal mobile phones, which helps the scam blend into everyday communication patterns.
The message follows a familiar pattern: the caller claims there is an urgent, mandatory security migration that the employee must complete right away. In practice, that urgency is used to lower the victim’s guard and steer them toward a spoofed login page designed to capture sensitive data.
Rather than merely collecting usernames and passwords, the phishing workflow is built to intercept authentication artifacts. Attackers aim to harvest not only credentials but also MFA tokens, which can enable further access even when multi-factor authentication is deployed—especially when the attacker can place themselves between the user and the legitimate service.
Targeting Microsoft 365 and Okta infrastructure
GTIG reports that UNC6671’s technical focus includes Microsoft 365 and Okta infrastructure. This matters because these environments are commonly used for identity, single sign-on, and access control—so compromising them can cascade into broader account and session control.
To bypass protections, the threat actor relied on adversary-in-the-middle (AiTM) techniques. AiTM attacks can be effective because they manipulate the authentication flow in real time. Even with MFA enabled, an attacker who can intercept the user’s interaction may capture the token or session details required to gain access to cloud resources.
In addition, GTIG notes that the group used phishing and single sign-on (SSO) compromise tactics together, increasing the chance of successful takeover in modern identity setups.
How the phishing panels are delivered
UNC6671 also appears to use a systematic way of setting up phishing infrastructure. GTIG observed the group using generic root domains across multiple victims, including examples such as passkeyhelpdesk[.]com, portalpasskey[.]com, addssopasskey[.]com, passkeydeploy[.]com, mysecurepasskey[.]com, and passkeyuser[.]com.
Some domains were exclusive to specific extortion brand identities, but GTIG links activity across the aliases through the phishing templates used to harvest credentials. The templates act like fingerprints: even when the campaign message changes, the underlying mechanics can look similar.
GTIG also points to patterns in domain registration and infrastructure choices. The operators appeared to shift target selection over time, seemingly prioritizing organizations more likely to hold sensitive information. Subdomains incorporated prospective victim names to host credential-harvesting panels tailored for the targeted user population.
Consistent TTPs despite branding shifts
Even with different naming in extortion communications, GTIG says the group’s initial access and post-compromise tactics, techniques, and procedures (TTPs) remained consistent. That means defenders should treat the aliases—BlackFile, Redact, Pink, Helix, Falcon—as different “fronts” of the same operational ecosystem rather than as separate threats with unrelated behaviors.
This consistency is one reason rebranding should not reduce urgency. If the human lure and the authentication-interception approach remain, then the risk profile remains high as well.
New extortion infrastructure: a data leak site
In June, UNC6671 established a new data leak site under the Redact brand. The site announced the group’s departure from BlackFile and claimed the original operation had been taken over by an affiliate.
GTIG’s monitoring of the group’s digital footprint indicated overlaps between the various extortion brands. Those overlaps suggest affiliation among the operations using BlackFile, Redact, Pink, Helix, and Falcon. At the same time, GTIG notes that other explanations could be plausible as well, such as splintered affiliates or shared “phishing-as-a-service” infrastructure.
Evolution in the delivery and cleanup steps
GTIG reports that the threat actor has evolved how it interacts with victims. For example, it spoofed legitimate helpdesk phone numbers to increase call credibility and used compromised email addresses to reset passwords for enterprise applications that are not limited to SSO.
In addition, UNC6671 reportedly attempted to reduce the chance of discovery. GTIG describes the deletion of confirmation messages, alerts, and notifications tied to account changes. If defenders rely on users noticing login attempts or password reset notices, removing those signals can delay detection and extend the attackers’ time to escalate access.
Ransom payments and negotiation behavior
UNC6671 vishing extortion appears to be highly profitable. Between January and May, GTIG reports the group received over $10 million in Bitcoin across 18 wallet addresses, corresponding to ransom payments. Some payments were recorded after the BlackFile shutdown announcement, reinforcing the idea that the brand change did not stop operations.
GTIG also describes a typical bargaining pattern. Initial ransom demands often ranged from $1 million up to $3 million USD. During negotiations, the operators frequently accepted reductions of 50% to 75% compared to the initial demand. In more than 53% of tracked cases during that period, final payments averaged around $750,000.
For security leaders, this payment pattern is a sobering reminder: the group’s methods are not experimental. They have produced repeatable outcomes that support ongoing investment in infrastructure and social engineering.
What organizations can do to reduce exposure
Because UNC6671’s scheme blends phone-based persuasion with cloud-targeted phishing and AiTM interception, defenses need to address both people and identity workflows.
Strengthen helpdesk verification
Train employees to treat unexpected “urgent security migration” instructions as a trigger to verify through a trusted channel—such as calling a known corporate helpdesk number from company directories or using an internal ticketing process. If an attacker can spoof calls, then employees must have a reliable way to confirm legitimacy.
Harden authentication flows against AiTM
Identity teams should review how authentication is performed across Microsoft 365, Okta, and related applications. Focus on protections that reduce the chance of token interception during real-time authentication events, and validate that MFA implementations align with your risk model and current threat landscape.
Improve detection of password resets and unusual changes
Since GTIG reports deletion of confirmations and notifications, relying solely on user visibility is insufficient. Use monitoring to alert on abnormal password reset patterns, suspicious login behaviors, and changes to critical identity settings—especially when resets are triggered from compromised emails.
Watch for tailored phishing infrastructure
Organizations can also build practical detection around phishing infrastructure traits. Subdomains tailored to victim names and consistent template patterns can be used to prioritize investigation. When possible, incorporate threat intelligence feeds and block known credential-harvesting domains or suspicious lookalikes.
Conclusion
GTIG’s findings show that UNC6671 vishing extortion has rebranded its public-facing names, moving from BlackFile to brands such as Redact, Pink, Helix, and Falcon. Yet the core mechanics remain: attackers impersonate IT helpdesk staff, use urgent migration narratives to move victims toward spoofed portals, and apply AiTM techniques to harvest credentials and MFA-related access.
The most effective response, therefore, is not to track names but to prevent the steps that make the campaign successful—especially phone-based social engineering and identity takeover pathways in Microsoft 365 and Okta-driven environments.
Source: https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/
