Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-02

UNC6671

As of 2026-08-09, UNC6671 is a threat actor tracked by Threadlinqs Intelligence across 8 threats spanning data breach, phishing, threat actor. ATT&CK coverage spans 83 techniques across 14 tactics in 8 of 8 tracked threats. Most-observed techniques: T1530 (Data from Cloud Storage), T1078 (Valid Accounts), T1566 (Phishing).

Tracked threats
82 critical · 6 high
First seen
2026-02-02
Last seen
2026-08-09
ATT&CK techniques
83across 8 of 8 threats
Related CVEs
0None referenced
8 tracked threat(s) · Categories: DATA_BREACH, PHISHING, THREAT_ACTOR, THREAT_INTEL, CAMPAIGN

Activity timeline

UNC6671 appears in 8 tracked threats between and ; the busiest month was 2026-02 with 5 reports.

ATT&CK techniques observed

83 techniques observed across 8 of 8 tracked threats · Credential Access (14), Resource Development (10), Stealth (formerly Defense Evasion) (10), Initial Access (8), Persistence (8), Collection (7)
  • T1530 Data from Cloud Storage — Collectionobserved in 8 of 8 tracked threats
  • T1078 Valid Accounts — Initial Accessobserved in 7 of 8 tracked threats
  • T1566 Phishing — Initial Accessobserved in 7 of 8 tracked threats
  • T1684.001 Impersonation — Stealth (formerly Defense Evasion)observed in 7 of 8 tracked threats
  • T1213 Data from Information Repositories — Collectionobserved in 6 of 8 tracked threats
  • T1539 Steal Web Session Cookie — Credential Accessobserved in 6 of 8 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 6 of 8 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 6 of 8 tracked threats
  • T1657 Financial Theft — Impactobserved in 6 of 8 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 5 of 8 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 5 of 8 tracked threats
  • T1537 Transfer Data to Cloud Account — Exfiltrationobserved in 5 of 8 tracked threats
  • T1552 Unsecured Credentials — Credential Accessobserved in 5 of 8 tracked threats
  • T1557 Adversary-in-the-Middle — Credential Accessobserved in 5 of 8 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 5 of 8 tracked threats

Tracked threats