Overview of UNC6671 Rebranding and Extortion Operations
The Google Threat Intelligence Group (GTIG) has identified that the threat actor tracking as UNC6671 is actively maintaining compromise and extortion operations despite the announced retirement of the BlackFile extortion brand. Telemetry analysis indicates that the group has diversified its monetization strategy across several distinct extortion fronts, including Redact, Pink, Helix, and Falcon. These campaigns primarily target the financial services, private equity, and professional services sectors, focusing heavily on enterprise cloud deployments.
Rather than permanently disbanding, the actors behind these intrusions continue to refine their initial access vectors while shifting data leak site (DLS) branding to evade attribution, confuse negotiators, and complicate threat intelligence tracking.
Technical Analysis: Vishing and AiTM Infrastructure
UNC6671 relies on a consistent tactical baseline centered around voice phishing (vishing) directed at enterprise employees. Threat actors frequently contact victims on personal mobile devices, impersonating internal IT helpdesk personnel. These communications manufacture false urgency around mandatory security migrations, directing targets to spoofed login portals.
To capture credentials and bypass security controls, the group deploys Adversary-in-the-Middle (AiTM) infrastructure. This setup intercepts authentication requests and multi-factor authentication (MFA) tokens in real time. Once session persistence is established, automated scripts execute data exfiltration against target SaaS platforms, specifically focusing on Microsoft 365 and Okta environments.
Infrastructure Overlaps Across Extortion Brands
Investigation into the supporting infrastructure reveals shared root domains and intermediate targets bridging multiple extortion brands. Security teams researching UNC6671 cloud extortion campaigns have tracked how generic domains masquerading as passkey support portals link disparate attacks:
- Falcon and Helix: The root domain
passkeyhelpdesk[.]comwas utilized concurrently to target organizations later listed on both Falcon and Helix DLS portals. - Pink: Domains such as
passkeyms[.]comandmysecurepasskey[.]comacted as intermediate bridges to infrastructure clusters utilizingpasskeydeploy[.]com. - BlackFile: Historical campaigns leveraging
setupsso[.]comandidokta[.]combridged directly into infrastructure associated with the Pink and Helix extortion brands.
These infrastructure overlaps confirm that a unified set of actors or shared Phishing-as-a-Service resources underpin the multi-brand strategy.
Remediation and Hardening Guidance
Defenders seeking to protect enterprise environments from UNC6671 tactics should prioritize foundational identity hardening and user awareness training:
- Deploy Phishing-Resistant MFA: Transition away from traditional OTP and push notifications to FIDO2/WebAuthn-based security keys, which render AiTM interception ineffective.
- Monitor Session Anomalies: Audit Microsoft 365 and Okta audit logs regularly for impossible travel, unexpected token generation, and unauthorized OAuth application grants.
- Establish Out-of-Band Verification: Train employees to independently verify IT helpdesk requests through official, internal communication channels before sharing credentials or registering new devices.
Related: Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks, Identity Attacks & MFA Bypass: The New Ransomware Entry Point