UNC6671 Vishing Campaign Impersonates IT Support to Target 200+ Financial and Enterprise Organizations for Extortion
UNC6671 Vishing Campaign Impersonates IT Support to Target (TL-2026-1959), also tracked as BlackFile, is a critical-severity phishing campaign, first published 2026-08-09. It is attributed to UNC6671 with medium confidence, affects Microsoft Microsoft 365 (SharePoint, OneDrive, Entra ID SSO), maps to 14 MITRE ATT&CK techniques (T1005, T1048, T1078), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1959
- Threat ID
- TL-2026-1959
- Also known as
- BlackFile, Redact, Pink, Helix, Falcon
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-09
- Last reviewed
- 2026-08-09
- Attribution
- UNC6671
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial-services, private-equity, hedge-funds, legal, asset-management, health, technology, real-estate, transport, energy, construction-engineering, manufacturing
- Target regions
- North America, united kingdom, australia
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in UNC6671 Vishing Campaign Impersonates IT Support to Target
Malware and tooling: Pink, Session messenger (getsession.org), Tox
Google Threat Intelligence Group (GTIG) is tracking UNC6671, a financially motivated extortion group operating under the brands BlackFile, Redact, Pink, Helix, and Falcon, that vishes employees' personal phones posing as IT helpdesk staff to lure them onto lookalike FIDO2 passkey/MFA-enrollment domains, hijacking Microsoft 365 and Okta SSO sessions in real time via adversary-in-the-middle infrastructure.
How UNC6671 Vishing Campaign Impersonates IT Support to Target works
UNC6671 (Mandiant/GTIG designation; CrowdStrike tracks related activity as Cordial Spider) emerged in early 2026 running high-volume voice-phishing (vishing) operations against enterprise employees. Callers, spoofing legitimate helpdesk phone numbers, contact victims' personal mobile devices to sidestep corporate security tooling and claim a mandatory FIDO2 passkey migration or MFA update is required. Victims are walked through enrollment on a lookalike SSO/passkey portal (e.g. subdomains of createssopasskey[.]com, addssopasskey[.]com, passkeyhelpdesk[.]com) fronted by adversary-in-the-middle (AiTM) reverse-proxy infrastructure that captures usernames, passwords, and real-time MFA codes/session tokens, then relays them to the legitimate Microsoft 365 or Okta login flow to hijack the session live on the call. Once inside, operators register an adversary-controlled MFA device (after removing the victim's own), reset passwords on non-SSO legacy applications, and systematically delete password-reset and security-alert notifications to slow detection. Data theft is then automated against SharePoint, OneDrive, and Okta-fronted applications using python-requests and PowerShell scripts that reuse stolen session cookies (FedAuth) and spoof the Microsoft Office ClientAppId, generating SharePoint audit-log entries as lower-scrutiny FileAccessed events rather than FileDownloaded. GTIG has observed cases exceeding one million exfiltrated SharePoint/OneDrive files. The group monetizes stolen data through extortion: initial ransom demands of $1-3M+ are negotiated down 50-75%, settling near $750,000 in the majority of tracked cases, communicated first via Tox and later via Session messenger, backed by hijacked corporate email/Teams accounts, spam-bombing, threatening voicemails to executives, and swatting. GTIG tracked 141.65 BTC (~$10.69M) across 18 wallets tied to the original 'BlackFile' data-leak site (launched February 6, 2026) between January and May 2026. BlackFile announced a shutdown on May 11, 2026, but GTIG assesses operations continued uninterrupted under the brands Redact, Pink, Helix, and Falcon — infrastructure analysis (54+ root domains sharing the same passkey/SSO naming convention, registrars, and reverse-proxy IPs) shows the brands are tightly linked, most likely as a single group compartmentalizing its operations across public personas, though actor-splintering or a shared-panel ecosystem among affiliates cannot be ruled out. Targeting has escalated from broad opportunistic hits (healthcare, manufacturing, real estate) in April-May 2026 to a deliberate focus on financial services and law firms in July-August 2026 — private equity, M&A, and litigation data maximizes extortion leverage. Reuters/press reporting named Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Moody's, Clearlake Capital, and the law firms Paul Hastings and Greenberg Traurig as targeted, with Point72, Millennium Management, Two Sigma, and Citadel also reportedly targeted; as of publication no named firm had confirmed a resulting breach. GTIG's tradecraft comparison notes overlap with techniques associated with ShinyHunters (Bling Libra)/Scattered Spider (UNC3944)-style social engineering, but assesses UNC6671 as operating independently.
MITRE ATT&CK techniques used in TL-2026-1959
Collection
T1005 Data from Local System; T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1537 Transfer Data to Cloud Account
Defense Evasion
T1078 Valid Accounts; T1684.001 Impersonation
Discovery
T1087 Account Discovery; T1526 Cloud Service Discovery
Credential Access
T1111 Multi-Factor Authentication Interception
Lateral Movement
T1550 Use Alternate Authentication Material
Persistence
T1556 Modify Authentication Process
Initial Access
Resource Development
Affected products and versions in UNC6671 Vishing Campaign Impersonates IT Support to Target
- Microsoft — Microsoft 365 (SharePoint, OneDrive, Entra ID SSO)
Vulnerable versions: Cloud SaaS tenants relying on phishable MFA (SMS/TOTP/push) for sign-in
Fixed in: N/A — social-engineering/identity-abuse campaign, not a software vulnerability; mitigated by FIDO2/passkey enforcement - Okta — Okta Identity Cloud (SSO/MFA)
Vulnerable versions: Cloud SaaS tenants relying on phishable MFA (SMS/TOTP/push) for sign-in
Fixed in: N/A — social-engineering/identity-abuse campaign, not a software vulnerability; mitigated by FIDO2/passkey enforcement (Okta FastPass)
Remediation for UNC6671 Vishing Campaign Impersonates IT Support to Target
Immediate actions
- Mandate FIDO2/WebAuthn hardware security keys or platform passkeys (Windows Hello, Okta FastPass) for all Microsoft 365/Okta admin and privileged accounts to close the AiTM MFA-interception gap this campaign exploits
- Instruct employees and helpdesk staff to never act on unsolicited passkey/MFA-enrollment requests received via inbound calls to personal phones; require callback verification through a known internal number before any credential or MFA change
- Alert on Okta system.multifactor.factor.setup events preceded by authentication failures, and treat SharePoint/OneDrive FileAccessed events from non-browser User-Agents (python-requests, PowerShell) with the same severity as FileDownloaded
- Block and sinkhole known UNC6671 phishing domains (createssopasskey[.]com, addssopasskey[.]com, passkeyhelpdesk[.]com, myoktasso[.]com, oktaenroll[.]com, and related passkey/SSO-themed domains) at DNS/web proxy
Workarounds
- Where phishing-resistant MFA cannot yet be deployed org-wide, disable self-service MFA-device enrollment and require verified-identity callback before any new authenticator is registered on an account
Longer-term hardening
- Consolidate SaaS authentication behind a single IdP (Entra ID or Okta) with unified conditional-access policy enforcement
- Enforce daily re-authentication, idle session timeouts, and token-theft mitigations (IP binding, Device-Bound Session Credentials, Continuous Access Evaluation) to blunt stolen-session-cookie replay
- Require corporate MDM/EDR-managed devices as a condition for cloud authentication
- Deploy conditional-access alerting for authentication from commercial VPN or residential-proxy exit nodes that diverges from an employee's established baseline
Timeline of UNC6671 Vishing Campaign Impersonates IT Support to Target
- GTIG's earliest tracked Bitcoin transaction to a BlackFile-linked wallet; UNC6671 vishing operations already at high operational tempo.
- The BlackFile data-leak site (DLS) is launched, formalizing the group's extortion brand after an earlier phase of unbranded ransom notes.
- UNC6671 begins a wave of passkey/SSO-themed domain registrations (28 root domains through May 31, roughly one every 2.2 days), targeting a broad mix of industries.
- The BlackFile data-leak site goes offline.
- BlackFile's DLS briefly comes back online to announce it is shutting down 'under this name'; ransom payments to BlackFile-linked wallets continue afterward.
- Redact operators publicly announce the permanent cessation of BlackFile operations.
- The 'Pink' data-leak site launches, one of the brands GTIG later links to the same UNC6671 infrastructure.
- Domain-registration cadence accelerates to roughly one new domain every 1.6 days through July 31, as Helix and Falcon infrastructure comes online.
- Redact publishes a statement claiming the original BlackFile brand was compromised and hijacked by a former, 'exiled' affiliate, denying that rival-group pressure drove the rebrand.
- A spike of 7 new phishing domains is registered in 72 hours as targeting sharpens toward financial-services and legal-sector victims (private equity, M&A, litigation data).
- GTIG publishes 'UNC6671 Rebrands,' detailing 54+ linked phishing domains, AiTM/exfiltration infrastructure, and the Redact/Pink/Helix/Falcon brand overlap.
- Reuters and follow-on press reporting name Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Moody's, Paul Hastings, and Greenberg Traurig among 200+ organizations targeted; no named firm has confirmed a breach.
Sources cited for UNC6671 Vishing Campaign Impersonates IT Support to Target
- Hackers impersonate IT support to breach leading financial companies
- Welcome to BlackFile: Inside a Vishing Extortion Operation
- UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
- UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
- Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
- Blackstone, KKR and CME targeted in vishing wave tied to BlackFile crew
- Vishing group UNC6671 now focuses on extorting M&A firms
- Vishing Extortion Group UNC6671 Rebrands After Making Millions
- Google Links Redact Extortion Group to BlackFile Rebrand
- UNC6671 Rebrands BlackFile Into Redact, Pink, Helix, and Falcon Extortion Operations
Threats related to UNC6671 Vishing Campaign Impersonates IT Support to Target
- AI Voice-Cloning Vishing Wave Hits Point72, Citadel, Two Sigma, Millennium Management — Tied to UNC6671 (BlackFile/Redact) Extortion Group
- UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking
- AI-Generated Phishing Shifts to Malware-Free In-Browser AiTM Session Theft
- New Phishing Kits 'Jalisco' and 'OmegaLord' Bypass MFA on Microsoft 365 Accounts via OAuth Device Code Abuse and Fake PDF-Reader Credential Harvesting
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)
Detection coverage for TL-2026-1959
As of 2026-08-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1959 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1959
14 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.