UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion — Threadlinqs Intelligence
As of 2026-08-09, UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion is a high-severity data breach threat attributed to UNC6671, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-1962 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Attribution: UNC6671 · FINANCIAL
Google Threat Intelligence Group (GTIG/Mandiant) attributes the BlackFile extortion brand and its June 27, 2026 rebrand into Redact, plus the related Pink, Helix, and Falcon personas, to a single
UNC6671 is a financially motivated extortion cluster that GTIG links to the BlackFile brand (active since early 2026) and four apparent successor brands — Redact, Pink, Helix, and Falcon — launched after BlackFile announced its retirement in May 2026. Redact's June 27, 2026 rebrand statement claimed the original BlackFile brand had been "compromised and hijacked by an exiled affiliate," but GTIG found overlapping phishing templates, shared root domains (notably passkeyhelpdesk[.]com and passkeydeploy[.]com), consistent victimology, and shared AiTM infrastructure across all five personas, assessing they are operated by a coordinated group rather than genuinely independent actors.
The intrusion begins with voice phishing: operators call targeted employees, frequently on personal mobile devices to bypass corporate telephony controls, spoof legitimate helpdesk numbers, and claim an urgent, mandatory security migration requires the victim to enroll a FIDO2 passkey or update their MFA. Victims are walked to lookalike domains (patterned as [victim].[genericroot].com, e.g. createssopasskey[.]com, addssopasskey[.]com) hosting adversary-in-the-middle phishing kits. A related campaign tracked by Okta as O-UNC-066 documented that the kit is not a simple transparent proxy but an operator-controlled PHP panel with a 1-second heartbeat polling loop: while the victim is walked through what appears to be legitimate passkey enrollment (including a decoy step presenting fake BIP-39-style recovery phrases), the operator simultaneously authenticates to the real account with the stolen credentials and registers their OWN passkey/authenticator against the victim's account, giving them durable, MFA-satisfying access independent of the original phishing session.
Once inside Microsoft 365 and/or Okta, the group uses Python (`python-requests/2.28.1`) and PowerShell (`WindowsPowerShell/5.1`) scripts to stream data directly out of SharePoint/OneDrive and Okta via API access rather than traditional bulk downloads, and separately abuses compromised mailbox access to trigger password resets on non-SSO applications. For defense evasion, the group systematically deletes password-reset confirmations, MFA-configuration-change alerts, and other security notifications from compromised inboxes to delay detection. Exfiltration traffic has been observed proxied through both dedicated AiTM reverse-proxy infrastructure (Private Layer/Switzerland, MEVSPACE/Poland, DDoS-Guard/Russia) and residential-ISP proxy pools (AT&T, Comcast, Starry, Optimum) to blend with legitimate user geolocation.
Targeting has escalated in both scale and value: April-May 2026 hit manufacturing, real estate, healthcare, and insurance at roughly one new phishing domain every 2.2 days; June 2026 shifted to technology, transportation, and hospitality organizations holding valuable IP/source code/VIP client data at ~1 domain every 1.6 days; July 2026 pivoted to financial services, private equity, and law firms to maximize extortion leverage via M&A and litigation data, including a spike of 7 new domains in a 3-day window (July 20-22). By August 2026, GTIG and reporting outlets identified attempted targeting of major U.S. hedge funds and private-equity firms including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. GTIG tracked 18 BlackFile Bitcoin wallets receiving 141.65 BTC (~$10.69M USD) between January 7 and May 12, 2026 — with payments continuing even after the brand's public shutdown announcement — from initial ransom demands of $1-3M USD negotiated down 50-75% to average final payments near $750,000 USD, with roughly a 53% payment rate across tracked cases. Extortion is carried out via brand-specific data-leak sites (Redact, Pink, Helix, Falcon), with Redact publishing a verified Tox ID and PGP key for negotiations; the Falcon brand has publicly disputed unified attribution, claiming to operate solely as a Redact affiliate independent of Helix and Pink.
Weaknesses (CWE)
CWE-451, CWE-294, CWE-287
Target sectors: manufacturing, real estate, health, insurance, technology, transport, hospitality, financial services, private equity, legal, professional services
Target regions: North America
Detections & IOCs
As of 2026-08-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
21 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1583, T1566, T1684.001, T1078, T1098, T1557, T1111, T1539, T1114, T1530