UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking — Threadlinqs Intelligence
As of 2026-08-07, UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking is a high-severity phishing threat attributed to UNC6671, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1926 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: UNC6671 · FINANCIAL
Google Threat Intelligence Group (GTIG) attributes an escalating, financially motivated campaign to UNC6671, which uses helpdesk-spoofing vishing calls to lure employees onto fraudulent Okta/Microsoft
UNC6671 is a financially motivated intrusion cluster tracked by Google Threat Intelligence Group (GTIG) since early 2026, first formalized under the 'BlackFile' extortion brand when its data-leak site went live on 2026-02-06. The group's core tradecraft has remained consistent across its lifespan: operators cold-call employees on personal mobile numbers, spoofing legitimate IT-helpdesk caller IDs and claiming an urgent, mandatory FIDO2 passkey or MFA migration is required. Victims are walked through a fraudulent 'passkey enrollment' or SSO portal that functions as an adversary-in-the-middle (AiTM) reverse proxy, relaying credentials and MFA approvals to the real Okta/Microsoft 365 login in real time while capturing the resulting authenticated session. Operators then reuse the hijacked session, in several observed cases registering an attacker-controlled MFA/passkey device for durable access, resetting passwords on non-SSO applications via the compromised mailbox, and deleting password-reset confirmations, MFA alerts, and other security notifications to delay detection.
Post-access, UNC6671 runs automated, scripted collection against Microsoft 365 and Okta-connected SaaS (SharePoint, OneDrive, Exchange), querying internal search functions for high-value string literals such as 'confidential' and 'SSN' before bulk-downloading files at volumes and speeds inconsistent with human browsing. Exfiltration traffic is fronted through residential and commercial proxy pools (AT&T, Comcast, Starry, Optimum/Suddenlink IP space) to blend with legitimate employee geography, and is frequently identifiable by scripting User-Agent strings (python-requests, WindowsPowerShell).
GTIG assesses that UNC6671 operates or supplies infrastructure for a family of nominally distinct extortion brands — BlackFile (retired/'shut down' 2026-05-11, though wallet cashouts continued the next day), Redact (launched 2026-06-27 claiming to have compromised BlackFile via an exiled affiliate), Pink, Helix, and Falcon — which share root-domain infrastructure, identical phishing-kit templates deployed same-day across brands, and overlapping victimology. GTIG could not fully resolve whether this reflects one coordinated group, a splintered affiliate structure, or shared phishing-as-a-service tooling used by distinct crews.
Targeting has shifted over the campaign's life: April-May 2026 saw broad opportunistic targeting of manufacturing, real estate, healthcare, and insurance; June 2026 pivoted to technology, transportation, and hospitality; by July-August 2026 the group concentrated on financial services, private equity, hedge funds, and law firms — sectors holding high-value M&A, deal, and litigation material — registering new root phishing domains at a rate of roughly one every 1.6 days, including a spike of seven domains in 72 hours in late July. Press reporting around the 2026-08-06 GTIG publication describes vishing activity against major hedge funds (Citadel, Millennium Management, Point72, Two Sigma), private-equity firms (Blackstone, KKR, Apollo Global Management), CME Group, and law firms including Paul Hastings (Greenberg Traurig was also named in reporting but has denied being breached). GTIG tracked roughly $10.69M (141.65 BTC across 18 wallets) in extortion payments to the cluster's wallets between January and May 2026 alone, with initial demands of $1-3M typically negotiated down to roughly $750K.
Target sectors: financial services, private equity, hedge funds, legal services, professional services, health, technology, manufacturing, real estate, insurance, transport, hospitality
Target regions: North America, united kingdom, australia
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
18 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1583.001, T1566.004, T1656, T1036.005, T1557, T1539, T1078.004, T1098.005, T1070.008