# UNC6671

> As of 2026-08-09, UNC6671 is a threat actor tracked by Threadlinqs Intelligence across 8 threats spanning data breach, phishing, threat actor. ATT&CK coverage spans 83 techniques across 14 tactics in 8 of 8 tracked threats. Most-observed techniques: T1530 (Data from Cloud Storage), T1078 (Valid Accounts), T1566 (Phishing).

- **Tracked threats:** 8
- **Categories:** DATA_BREACH, PHISHING, THREAT_ACTOR, THREAT_INTEL, CAMPAIGN
- **As of:** 2026-08-09

## ATT&CK techniques observed

83 techniques observed across 8 of 8 tracked threats. Tactics: Credential Access (14), Resource Development (10), Stealth (formerly Defense Evasion) (10), Initial Access (8), Persistence (8), Collection (7).

- [T1530](https://intel.threadlinqs.com/technique/T1530) Data from Cloud Storage — Collection — observed in 8 of 8 tracked threats
- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Initial Access — observed in 7 of 8 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 7 of 8 tracked threats
- [T1684.001](https://intel.threadlinqs.com/technique/T1684.001) Impersonation — Stealth (formerly Defense Evasion) — observed in 7 of 8 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 6 of 8 tracked threats
- [T1539](https://intel.threadlinqs.com/technique/T1539) Steal Web Session Cookie — Credential Access — observed in 6 of 8 tracked threats
- [T1550](https://intel.threadlinqs.com/technique/T1550) Use Alternate Authentication Material — Lateral Movement — observed in 6 of 8 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 6 of 8 tracked threats
- [T1657](https://intel.threadlinqs.com/technique/T1657) Financial Theft — Impact — observed in 6 of 8 tracked threats
- [T1087](https://intel.threadlinqs.com/technique/T1087) Account Discovery — Discovery — observed in 5 of 8 tracked threats
- [T1098](https://intel.threadlinqs.com/technique/T1098) Account Manipulation — Persistence — observed in 5 of 8 tracked threats
- [T1537](https://intel.threadlinqs.com/technique/T1537) Transfer Data to Cloud Account — Exfiltration — observed in 5 of 8 tracked threats
- [T1552](https://intel.threadlinqs.com/technique/T1552) Unsecured Credentials — Credential Access — observed in 5 of 8 tracked threats
- [T1557](https://intel.threadlinqs.com/technique/T1557) Adversary-in-the-Middle — Credential Access — observed in 5 of 8 tracked threats
- [T1567](https://intel.threadlinqs.com/technique/T1567) Exfiltration Over Web Service — Exfiltration — observed in 5 of 8 tracked threats

## Tracked threats

- [UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion](https://intel.threadlinqs.com/threat/TL-2026-1962) — HIGH
- [UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for Extortion](https://intel.threadlinqs.com/threat/TL-2026-1959) — CRITICAL
- [UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1926) — HIGH
- [ShinyHunters Leaks 5.1 Million Panera Bread Customer Records](https://intel.threadlinqs.com/threat/TL-2026-0055) — HIGH
- [ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-0054) — HIGH
- [ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks](https://intel.threadlinqs.com/threat/TL-2026-0045) — HIGH
- [ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0030) — HIGH
- [ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering](https://intel.threadlinqs.com/threat/TL-2026-0013) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC6671
