Threat reportPhishingTL-2026-1926

UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking

highACTIVE

UNC6671 Automates Microsoft 365 Data Theft via (TL-2026-1926), also tracked as BlackFile, is a high-severity phishing campaign, first published 2026-08-07. It is attributed to UNC6671 with medium confidence, affects Microsoft Microsoft 365, maps to 14 MITRE ATT&CK techniques (T1020, T1036.005, T1070.008), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
1UNC6671
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-1926

Threat ID
TL-2026-1926
Also known as
BlackFile, Redact, Pink, Helix, Falcon
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
UNC6671
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial services, private equity, hedge funds, legal services, professional services, health, technology, manufacturing, real estate, insurance, transport, hospitality
Target regions
North America, united kingdom, australia
Detection rules
9
Indicators of compromise
25

Malware and tooling in UNC6671 Automates Microsoft 365 Data Theft via

Malware and tooling: Pink, 0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16, Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0, WindowsPowerShell/5.1, python-requests/2.28.1

How UNC6671 Automates Microsoft 365 Data Theft via works

Google Threat Intelligence Group (GTIG) attributes an escalating, financially motivated campaign to UNC6671, which uses helpdesk-spoofing vishing calls to lure employees onto fraudulent Okta/Microsoft passkey-enrollment portals that run adversary-in-the-middle (AiTM) credential and MFA-token theft, then hijacks the resulting sessions to automate large-scale Microsoft 365/Graph data exfiltration for extortion. GTIG links the activity to a rotating set of public extortion brands (BlackFile, Redact, Pink, Helix, Falcon) that share phishing infrastructure and templates.

UNC6671 is a financially motivated intrusion cluster tracked by Google Threat Intelligence Group (GTIG) since early 2026, first formalized under the 'BlackFile' extortion brand when its data-leak site went live on 2026-02-06. The group's core tradecraft has remained consistent across its lifespan: operators cold-call employees on personal mobile numbers, spoofing legitimate IT-helpdesk caller IDs and claiming an urgent, mandatory FIDO2 passkey or MFA migration is required. Victims are walked through a fraudulent 'passkey enrollment' or SSO portal that functions as an adversary-in-the-middle (AiTM) reverse proxy, relaying credentials and MFA approvals to the real Okta/Microsoft 365 login in real time while capturing the resulting authenticated session. Operators then reuse the hijacked session, in several observed cases registering an attacker-controlled MFA/passkey device for durable access, resetting passwords on non-SSO applications via the compromised mailbox, and deleting password-reset confirmations, MFA alerts, and other security notifications to delay detection.

Post-access, UNC6671 runs automated, scripted collection against Microsoft 365 and Okta-connected SaaS (SharePoint, OneDrive, Exchange), querying internal search functions for high-value string literals such as 'confidential' and 'SSN' before bulk-downloading files at volumes and speeds inconsistent with human browsing. Exfiltration traffic is fronted through residential and commercial proxy pools (AT&T, Comcast, Starry, Optimum/Suddenlink IP space) to blend with legitimate employee geography, and is frequently identifiable by scripting User-Agent strings (python-requests, WindowsPowerShell).

GTIG assesses that UNC6671 operates or supplies infrastructure for a family of nominally distinct extortion brands — BlackFile (retired/'shut down' 2026-05-11, though wallet cashouts continued the next day), Redact (launched 2026-06-27 claiming to have compromised BlackFile via an exiled affiliate), Pink, Helix, and Falcon — which share root-domain infrastructure, identical phishing-kit templates deployed same-day across brands, and overlapping victimology. GTIG could not fully resolve whether this reflects one coordinated group, a splintered affiliate structure, or shared phishing-as-a-service tooling used by distinct crews.

Targeting has shifted over the campaign's life: April-May 2026 saw broad opportunistic targeting of manufacturing, real estate, healthcare, and insurance; June 2026 pivoted to technology, transportation, and hospitality; by July-August 2026 the group concentrated on financial services, private equity, hedge funds, and law firms — sectors holding high-value M&A, deal, and litigation material — registering new root phishing domains at a rate of roughly one every 1.6 days, including a spike of seven domains in 72 hours in late July. Press reporting around the 2026-08-06 GTIG publication describes vishing activity against major hedge funds (Citadel, Millennium Management, Point72, Two Sigma), private-equity firms (Blackstone, KKR, Apollo Global Management), CME Group, and law firms including Paul Hastings (Greenberg Traurig was also named in reporting but has denied being breached). GTIG tracked roughly $10.69M (141.65 BTC across 18 wallets) in extortion payments to the cluster's wallets between January and May 2026 alone, with initial demands of $1-3M typically negotiated down to roughly $750K.

MITRE ATT&CK techniques used in TL-2026-1926

Exfiltration

T1020 Automated Exfiltration

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1070.008 Clear Mailbox Data

Persistence

T1078.004 Cloud Accounts; T1098.005 Device Registration

Command and Control

T1090.002 External Proxy

Collection

T1213.002 Sharepoint; T1530 Data from Cloud Storage

Credential Access

T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Initial Access

T1566.004 Spearphishing Voice

Resource Development

T1583.001 Domains

Reconnaissance

T1589 Gather Victim Identity Information

stealth

T1684.001 Impersonation

Affected products and versions in UNC6671 Automates Microsoft 365 Data Theft via

  • Microsoft — Microsoft 365
    Vulnerable versions: cloud service - all tenants relying on password/MFA authentication susceptible to AiTM relay
  • Microsoft — Microsoft Graph API
    Vulnerable versions: cloud service - accessible via any hijacked authenticated session or access token
  • Okta — Okta Identity Cloud (SSO / MFA)
    Vulnerable versions: cloud service - passkey/MFA enrollment ceremony susceptible to AiTM relay when driven by social engineering

Remediation for UNC6671 Automates Microsoft 365 Data Theft via

Immediate actions

  • Verify unsolicited IT-helpdesk or passkey/MFA-enrollment phone calls through a known-good internal channel before acting on any instruction received
  • Block or alert on authentication and network traffic to/from the identified AiTM reverse-proxy and phishing-kit-backend IP addresses
  • Force session revocation and mandatory re-authentication for any account that completed an MFA/passkey enrollment triggered by an inbound call

Workarounds

  • Deploy conditional-access policies blocking authentication from known residential/commercial proxy ASNs and geographically anomalous sources
  • Alert on Okta system.multifactor.factor.setup events immediately preceded by an abandoned auth_via_mfa challenge
  • Alert on O365 FileAccessed/FileDownloaded bulk events carrying python-requests or WindowsPowerShell User-Agent strings

Longer-term hardening

  • Mandate phishing-resistant FIDO2/WebAuthn authenticators (hardware security keys or platform authenticators) so AiTM relay cannot replay captured credentials or tokens
  • Shorten Microsoft 365/Okta session lifetimes and enable Continuous Access Evaluation with IP- and device-bound session credentials
  • Consolidate SaaS authentication behind a single SSO provider (Entra ID or Okta) to remove configuration drift across individually-authenticated apps
  • Restrict authentication to managed, MDM/EDR-enrolled devices from defined trusted network zones

Timeline of UNC6671 Automates Microsoft 365 Data Theft via

  • BlackFile data-leak site (DLS) goes live, formalizing the extortion brand after months of unbranded vishing-driven intrusions.
  • First broad-wave passkey/Okta-themed AiTM phishing domain, myoktasso.com, registered, opening a months-long domain-registration campaign.
  • passkeydeploy.com registered; later identified as shared phishing infrastructure bridging the Pink and Falcon extortion brands.
  • BlackFile publicly announces it is 'shutting down under this name,' taking its data-leak site offline.
  • Bitcoin wallets tied to BlackFile record cashout activity the day after the announced shutdown, contradicting the retirement claim.
  • Helix-branded AiTM infrastructure (oskeysync.com) registered as part of a wave targeting technology, transportation, and hospitality victims.
  • The 'Redact' brand publicly launches, claiming BlackFile's infrastructure was compromised and repurposed by an exiled affiliate.
  • createmfa.com and passkeyactivation.com registered as campaign targeting pivots toward financial services and legal sectors.
  • Seven new root phishing domains registered within a 72-hour window, marking a sharp acceleration in operational tempo.
  • Vishing calls reported against major hedge funds, private-equity firms, and CME Group as part of the late-stage financial-services wave.
  • Google Threat Intelligence Group publishes 'UNC6671 Rebrands,' formally linking BlackFile, Redact, Pink, Helix, and Falcon to a single tracked cluster.
  • Cyber Security News and other outlets report on the GTIG findings; hunt phase ingests the coverage.

Sources cited for UNC6671 Automates Microsoft 365 Data Theft via

Detection coverage for TL-2026-1926

As of 2026-08-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1926 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1926

18 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats