# UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking

> Google Threat Intelligence Group (GTIG) attributes an escalating, financially motivated campaign to UNC6671, which uses helpdesk-spoofing vishing calls to lure employees onto fraudulent Okta/Microsoft passkey-enrollment portals that run adversary-in-the-middle (AiTM) credential and MFA-token theft, then hijacks the resulting sessions to automate large-scale Microsoft 365/Graph data exfiltration for extortion. GTIG links the activity to a rotating set of public extortion brands (BlackFile, Redact, Pink, Helix, Falcon) that share phishing infrastructure and templates.

- **Published:** 2026-08-07T00:00:00Z
- **Last reviewed:** 2026-08-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1926
- **ID:** TL-2026-1926
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** UNC6671
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UNC6671 is a financially motivated intrusion cluster tracked by Google Threat Intelligence Group (GTIG) since early 2026, first formalized under the 'BlackFile' extortion brand when its data-leak site went live on 2026-02-06. The group's core tradecraft has remained consistent across its lifespan: operators cold-call employees on personal mobile numbers, spoofing legitimate IT-helpdesk caller IDs and claiming an urgent, mandatory FIDO2 passkey or MFA migration is required. Victims are walked through a fraudulent 'passkey enrollment' or SSO portal that functions as an adversary-in-the-middle (AiTM) reverse proxy, relaying credentials and MFA approvals to the real Okta/Microsoft 365 login in real time while capturing the resulting authenticated session. Operators then reuse the hijacked session, in several observed cases registering an attacker-controlled MFA/passkey device for durable access, resetting passwords on non-SSO applications via the compromised mailbox, and deleting password-reset confirmations, MFA alerts, and other security notifications to delay detection.

Post-access, UNC6671 runs automated, scripted collection against Microsoft 365 and Okta-connected SaaS (SharePoint, OneDrive, Exchange), querying internal search functions for high-value string literals such as 'confidential' and 'SSN' before bulk-downloading files at volumes and speeds inconsistent with human browsing. Exfiltration traffic is fronted through residential and commercial proxy pools (AT&T, Comcast, Starry, Optimum/Suddenlink IP space) to blend with legitimate employee geography, and is frequently identifiable by scripting User-Agent strings (python-requests, WindowsPowerShell).

GTIG assesses that UNC6671 operates or supplies infrastructure for a family of nominally distinct extortion brands — BlackFile (retired/'shut down' 2026-05-11, though wallet cashouts continued the next day), Redact (launched 2026-06-27 claiming to have compromised BlackFile via an exiled affiliate), Pink, Helix, and Falcon — which share root-domain infrastructure, identical phishing-kit templates deployed same-day across brands, and overlapping victimology. GTIG could not fully resolve whether this reflects one coordinated group, a splintered affiliate structure, or shared phishing-as-a-service tooling used by distinct crews.

Targeting has shifted over the campaign's life: April-May 2026 saw broad opportunistic targeting of manufacturing, real estate, healthcare, and insurance; June 2026 pivoted to technology, transportation, and hospitality; by July-August 2026 the group concentrated on financial services, private equity, hedge funds, and law firms — sectors holding high-value M&A, deal, and litigation material — registering new root phishing domains at a rate of roughly one every 1.6 days, including a spike of seven domains in 72 hours in late July. Press reporting around the 2026-08-06 GTIG publication describes vishing activity against major hedge funds (Citadel, Millennium Management, Point72, Two Sigma), private-equity firms (Blackstone, KKR, Apollo Global Management), CME Group, and law firms including Paul Hastings (Greenberg Traurig was also named in reporting but has denied being breached). GTIG tracked roughly $10.69M (141.65 BTC across 18 wallets) in extortion payments to the cluster's wallets between January and May 2026 alone, with initial demands of $1-3M typically negotiated down to roughly $750K.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1583.001 Domains
- T1566.004 Spearphishing Voice
- T1684.001 Impersonation
- T1036.005 Match Legitimate Resource Name or Location
- T1557 Adversary-in-the-Middle
- T1539 Steal Web Session Cookie
- T1078.004 Cloud Accounts
- T1098.005 Device Registration
- T1070.008 Clear Mailbox Data
- T1213.002 Sharepoint
- T1530 Data from Cloud Storage
- T1020 Automated Exfiltration
- T1090.002 External Proxy

## Sources

- [UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing](https://cybersecuritynews.com/unc6671-automates-microsoft-365/)
- [UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments](https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments)
- [Welcome to BlackFile: Inside a Vishing Extortion Operation](https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/)
- [Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group](https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/)
- [Blackstone, KKR and CME targeted in vishing wave tied to BlackFile crew](https://siliconangle.com/2026/08/06/blackstone-kkr-cme-targeted-vishing-wave-tied-blackfile-crew/)
- [Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers](https://www.securityweek.com/okta-warns-of-vishing-attacks-targeting-microsoft-365-customers/)
- [Vishing Campaign Hijacks Microsoft 365 Passkey Enrollment Across Six Industries](https://www.techtimes.com/articles/320145/20260711/vishing-campaign-hijacks-microsoft-365-passkey-enrollment-across-six-industries.htm)
- [UNC6671 GTI IOC Collection](https://www.virustotal.com/gui/collection/68a3ad0b80290ff51410cc95d0b1e728d5ffaa933e2230b291bd48fbdc406756)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1926
