As cited
Copy frozen at (site build).
threat intel
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Google Threat Intelligence Group reports that UNC6671, the threat actor behind the BlackFile extortion brand, has rebranded and diversified operations across multiple extortion sites including Redact, Pink, Helix, and Falcon rather than retiring as announced. The group continues to use voice phishing impersonating IT helpdesk staff to target employees at financial services, private equity, and professional services firms, directing victims to spoofed login portals that capture credentials and multi-factor authentication tokens for cloud environment compromise. Infrastructure analysis and overlapping targeting patterns indicate a unified technical operation monetizing stolen data across distinct data leak sites.
Why it matters: Security teams at financial services, private equity, and professional services organizations should heighten employee awareness and implement controls against voice phishing campaigns targeting personal mobile devices, and deploy session anomaly detection for cloud platforms like Microsoft 365 and Okta to catch compromised credentials before data exfiltration occurs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Google Threat Intelligence Group reports that UNC6671, the threat actor behind the BlackFile extortion brand, has rebranded and diversified operations across multiple extortion sites including Redact, Pink, Helix, and Falcon rather than retiring as announced. The group continues to use voice phishing impersonating IT helpdesk staff to target employees at financial services, private equity, and professional services firms, directing victims to spoofed login portals that capture credentials and multi-factor authentication tokens for cloud environment compromise. Infrastructure analysis and overlapping targeting patterns indicate a unified technical operation monetizing stolen data across distinct data leak sites.
Why it matters: Security teams at financial services, private equity, and professional services organizations should heighten employee awareness and implement controls against voice phishing campaigns targeting personal mobile devices, and deploy session anomaly detection for cloud platforms like Microsoft 365 and Okta to catch compromised credentials before data exfiltration occurs.
- Source published
- First seen by Cybersecurity Tracker