Threat reportPhishingTL-2026-1926
UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking
UNC6671 Automates Microsoft 365 Data Theft via (TL-2026-1926), also tracked as BlackFile, is a high-severity phishing campaign, first published 2026-08-07. It is attributed to UNC6671 with medium confidence, affects Microsoft Microsoft 365, maps to 14 MITRE ATT&CK techniques (T1020, T1036.005, T1070.008), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 1UNC6671
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-1926
- Threat ID
- TL-2026-1926
- Also known as
- BlackFile, Redact, Pink, Helix, Falcon
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- UNC6671
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial services, private equity, hedge funds, legal services, professional services, health, technology, manufacturing, real estate, insurance, transport, hospitality
- Target regions
- North America, united kingdom, australia
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in UNC6671 Automates Microsoft 365 Data Theft via
Malware and tooling: Pink, 0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16, Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0, WindowsPowerShell/5.1, python-requests/2.28.1
How UNC6671 Automates Microsoft 365 Data Theft via works
Google Threat Intelligence Group (GTIG) attributes an escalating, financially motivated campaign to UNC6671, which uses helpdesk-spoofing vishing calls to lure employees onto fraudulent Okta/Microsoft passkey-enrollment portals that run adversary-in-the-middle (AiTM) credential and MFA-token theft, then hijacks the resulting sessions to automate large-scale Microsoft 365/Graph data exfiltration for extortion. GTIG links the activity to a rotating set of public extortion brands (BlackFile, Redact, Pink, Helix, Falcon) that share phishing infrastructure and templates.
UNC6671 is a financially motivated intrusion cluster tracked by Google Threat Intelligence Group (GTIG) since early 2026, first formalized under the 'BlackFile' extortion brand when its data-leak site went live on 2026-02-06. The group's core tradecraft has remained consistent across its lifespan: operators cold-call employees on personal mobile numbers, spoofing legitimate IT-helpdesk caller IDs and claiming an urgent, mandatory FIDO2 passkey or MFA migration is required. Victims are walked through a fraudulent 'passkey enrollment' or SSO portal that functions as an adversary-in-the-middle (AiTM) reverse proxy, relaying credentials and MFA approvals to the real Okta/Microsoft 365 login in real time while capturing the resulting authenticated session. Operators then reuse the hijacked session, in several observed cases registering an attacker-controlled MFA/passkey device for durable access, resetting passwords on non-SSO applications via the compromised mailbox, and deleting password-reset confirmations, MFA alerts, and other security notifications to delay detection.
Post-access, UNC6671 runs automated, scripted collection against Microsoft 365 and Okta-connected SaaS (SharePoint, OneDrive, Exchange), querying internal search functions for high-value string literals such as 'confidential' and 'SSN' before bulk-downloading files at volumes and speeds inconsistent with human browsing. Exfiltration traffic is fronted through residential and commercial proxy pools (AT&T, Comcast, Starry, Optimum/Suddenlink IP space) to blend with legitimate employee geography, and is frequently identifiable by scripting User-Agent strings (python-requests, WindowsPowerShell).
GTIG assesses that UNC6671 operates or supplies infrastructure for a family of nominally distinct extortion brands — BlackFile (retired/'shut down' 2026-05-11, though wallet cashouts continued the next day), Redact (launched 2026-06-27 claiming to have compromised BlackFile via an exiled affiliate), Pink, Helix, and Falcon — which share root-domain infrastructure, identical phishing-kit templates deployed same-day across brands, and overlapping victimology. GTIG could not fully resolve whether this reflects one coordinated group, a splintered affiliate structure, or shared phishing-as-a-service tooling used by distinct crews.
Targeting has shifted over the campaign's life: April-May 2026 saw broad opportunistic targeting of manufacturing, real estate, healthcare, and insurance; June 2026 pivoted to technology, transportation, and hospitality; by July-August 2026 the group concentrated on financial services, private equity, hedge funds, and law firms — sectors holding high-value M&A, deal, and litigation material — registering new root phishing domains at a rate of roughly one every 1.6 days, including a spike of seven domains in 72 hours in late July. Press reporting around the 2026-08-06 GTIG publication describes vishing activity against major hedge funds (Citadel, Millennium Management, Point72, Two Sigma), private-equity firms (Blackstone, KKR, Apollo Global Management), CME Group, and law firms including Paul Hastings (Greenberg Traurig was also named in reporting but has denied being breached). GTIG tracked roughly $10.69M (141.65 BTC across 18 wallets) in extortion payments to the cluster's wallets between January and May 2026 alone, with initial demands of $1-3M typically negotiated down to roughly $750K.
MITRE ATT&CK techniques used in TL-2026-1926
Exfiltration
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1070.008 Clear Mailbox Data
Persistence
T1078.004 Cloud Accounts; T1098.005 Device Registration
Command and Control
Collection
T1213.002 Sharepoint; T1530 Data from Cloud Storage
Credential Access
T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Initial Access
Resource Development
Reconnaissance
T1589 Gather Victim Identity Information
stealth
Affected products and versions in UNC6671 Automates Microsoft 365 Data Theft via
- Microsoft — Microsoft 365
Vulnerable versions: cloud service - all tenants relying on password/MFA authentication susceptible to AiTM relay - Microsoft — Microsoft Graph API
Vulnerable versions: cloud service - accessible via any hijacked authenticated session or access token - Okta — Okta Identity Cloud (SSO / MFA)
Vulnerable versions: cloud service - passkey/MFA enrollment ceremony susceptible to AiTM relay when driven by social engineering
Remediation for UNC6671 Automates Microsoft 365 Data Theft via
Immediate actions
- Verify unsolicited IT-helpdesk or passkey/MFA-enrollment phone calls through a known-good internal channel before acting on any instruction received
- Block or alert on authentication and network traffic to/from the identified AiTM reverse-proxy and phishing-kit-backend IP addresses
- Force session revocation and mandatory re-authentication for any account that completed an MFA/passkey enrollment triggered by an inbound call
Workarounds
- Deploy conditional-access policies blocking authentication from known residential/commercial proxy ASNs and geographically anomalous sources
- Alert on Okta system.multifactor.factor.setup events immediately preceded by an abandoned auth_via_mfa challenge
- Alert on O365 FileAccessed/FileDownloaded bulk events carrying python-requests or WindowsPowerShell User-Agent strings
Longer-term hardening
- Mandate phishing-resistant FIDO2/WebAuthn authenticators (hardware security keys or platform authenticators) so AiTM relay cannot replay captured credentials or tokens
- Shorten Microsoft 365/Okta session lifetimes and enable Continuous Access Evaluation with IP- and device-bound session credentials
- Consolidate SaaS authentication behind a single SSO provider (Entra ID or Okta) to remove configuration drift across individually-authenticated apps
- Restrict authentication to managed, MDM/EDR-enrolled devices from defined trusted network zones
Timeline of UNC6671 Automates Microsoft 365 Data Theft via
- BlackFile data-leak site (DLS) goes live, formalizing the extortion brand after months of unbranded vishing-driven intrusions.
- First broad-wave passkey/Okta-themed AiTM phishing domain, myoktasso.com, registered, opening a months-long domain-registration campaign.
- passkeydeploy.com registered; later identified as shared phishing infrastructure bridging the Pink and Falcon extortion brands.
- BlackFile publicly announces it is 'shutting down under this name,' taking its data-leak site offline.
- Bitcoin wallets tied to BlackFile record cashout activity the day after the announced shutdown, contradicting the retirement claim.
- Helix-branded AiTM infrastructure (oskeysync.com) registered as part of a wave targeting technology, transportation, and hospitality victims.
- The 'Redact' brand publicly launches, claiming BlackFile's infrastructure was compromised and repurposed by an exiled affiliate.
- createmfa.com and passkeyactivation.com registered as campaign targeting pivots toward financial services and legal sectors.
- Seven new root phishing domains registered within a 72-hour window, marking a sharp acceleration in operational tempo.
- Vishing calls reported against major hedge funds, private-equity firms, and CME Group as part of the late-stage financial-services wave.
- Google Threat Intelligence Group publishes 'UNC6671 Rebrands,' formally linking BlackFile, Redact, Pink, Helix, and Falcon to a single tracked cluster.
- Cyber Security News and other outlets report on the GTIG findings; hunt phase ingests the coverage.
Sources cited for UNC6671 Automates Microsoft 365 Data Theft via
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing
- UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
- Welcome to BlackFile: Inside a Vishing Extortion Operation
- Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
- Blackstone, KKR and CME targeted in vishing wave tied to BlackFile crew
- Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
- Vishing Campaign Hijacks Microsoft 365 Passkey Enrollment Across Six Industries
- UNC6671 GTI IOC Collection
Detection coverage for TL-2026-1926
As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1926 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1926
18 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.