Threat reportData BreachTL-2026-1962

UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion

highACTIVE

UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon (TL-2026-1962), also tracked as UNC6671 Vishing Extortion Campaign, is a high-severity data breach, first published 2026-08-09. It is attributed to UNC6671 with high confidence, affects Microsoft Microsoft 365 (SharePoint/OneDrive) & Entra ID, maps to 13 MITRE ATT&CK techniques (T1020, T1078, T1090), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
1UNC6671
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-1962

Threat ID
TL-2026-1962
Also known as
UNC6671 Vishing Extortion Campaign, O-UNC-066
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution
UNC6671
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
manufacturing, real estate, health, insurance, technology, transport, hospitality, financial services, private equity, legal, professional services
Target regions
North America
Detection rules
9
Indicators of compromise
30

Malware and tooling in UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon

Malware and tooling: Pink, WindowsPowerShell/5.1, python-requests/2.28.1

How UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon works

Google Threat Intelligence Group (GTIG/Mandiant) attributes the BlackFile extortion brand and its June 27, 2026 rebrand into Redact, plus the related Pink, Helix, and Falcon personas, to a single actor cluster tracked as UNC6671. The group vishes employees on personal phones while impersonating IT helpdesk staff pushing fake FIDO2/passkey "security migrations," harvests credentials and MFA tokens via AiTM phishing panels, then runs automated Python/PowerShell scripts to exfiltrate data from Microsoft 365 and Okta before extorting victims for Bitcoin.

UNC6671 is a financially motivated extortion cluster that GTIG links to the BlackFile brand (active since early 2026) and four apparent successor brands — Redact, Pink, Helix, and Falcon — launched after BlackFile announced its retirement in May 2026. Redact's June 27, 2026 rebrand statement claimed the original BlackFile brand had been "compromised and hijacked by an exiled affiliate," but GTIG found overlapping phishing templates, shared root domains (notably passkeyhelpdesk[.]com and passkeydeploy[.]com), consistent victimology, and shared AiTM infrastructure across all five personas, assessing they are operated by a coordinated group rather than genuinely independent actors.

The intrusion begins with voice phishing: operators call targeted employees, frequently on personal mobile devices to bypass corporate telephony controls, spoof legitimate helpdesk numbers, and claim an urgent, mandatory security migration requires the victim to enroll a FIDO2 passkey or update their MFA. Victims are walked to lookalike domains (patterned as [victim].[genericroot].com, e.g. createssopasskey[.]com, addssopasskey[.]com) hosting adversary-in-the-middle phishing kits. A related campaign tracked by Okta as O-UNC-066 documented that the kit is not a simple transparent proxy but an operator-controlled PHP panel with a 1-second heartbeat polling loop: while the victim is walked through what appears to be legitimate passkey enrollment (including a decoy step presenting fake BIP-39-style recovery phrases), the operator simultaneously authenticates to the real account with the stolen credentials and registers their OWN passkey/authenticator against the victim's account, giving them durable, MFA-satisfying access independent of the original phishing session.

Once inside Microsoft 365 and/or Okta, the group uses Python (`python-requests/2.28.1`) and PowerShell (`WindowsPowerShell/5.1`) scripts to stream data directly out of SharePoint/OneDrive and Okta via API access rather than traditional bulk downloads, and separately abuses compromised mailbox access to trigger password resets on non-SSO applications. For defense evasion, the group systematically deletes password-reset confirmations, MFA-configuration-change alerts, and other security notifications from compromised inboxes to delay detection. Exfiltration traffic has been observed proxied through both dedicated AiTM reverse-proxy infrastructure (Private Layer/Switzerland, MEVSPACE/Poland, DDoS-Guard/Russia) and residential-ISP proxy pools (AT&T, Comcast, Starry, Optimum) to blend with legitimate user geolocation.

Targeting has escalated in both scale and value: April-May 2026 hit manufacturing, real estate, healthcare, and insurance at roughly one new phishing domain every 2.2 days; June 2026 shifted to technology, transportation, and hospitality organizations holding valuable IP/source code/VIP client data at ~1 domain every 1.6 days; July 2026 pivoted to financial services, private equity, and law firms to maximize extortion leverage via M&A and litigation data, including a spike of 7 new domains in a 3-day window (July 20-22). By August 2026, GTIG and reporting outlets identified attempted targeting of major U.S. hedge funds and private-equity firms including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. GTIG tracked 18 BlackFile Bitcoin wallets receiving 141.65 BTC (~$10.69M USD) between January 7 and May 12, 2026 — with payments continuing even after the brand's public shutdown announcement — from initial ransom demands of $1-3M USD negotiated down 50-75% to average final payments near $750,000 USD, with roughly a 53% payment rate across tracked cases. Extortion is carried out via brand-specific data-leak sites (Redact, Pink, Helix, Falcon), with Redact publishing a verified Tox ID and PGP key for negotiations; the Falcon brand has publicly disputed unified attribution, claiming to operate solely as a Redact affiliate independent of Helix and Pink.

MITRE ATT&CK techniques used in TL-2026-1962

Exfiltration

T1020 Automated Exfiltration

Defense Evasion

T1078 Valid Accounts; T1684.001 Impersonation

Command and Control

T1090 Proxy

Persistence

T1098 Account Manipulation

Credential Access

T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Collection

T1114 Email Collection; T1530 Data from Cloud Storage

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure

Impact

T1657 Financial Theft

Affected products and versions in UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon

  • Microsoft — Microsoft 365 (SharePoint/OneDrive) & Entra ID
    Vulnerable versions: Cloud tenants relying on phishable MFA/passkey self-enrollment without phishing-resistant authenticators or device-trust policies
    Fixed in: N/A - mitigated via FIDO2 enforcement, conditional access, and session controls, not a patchable vulnerability
  • Okta — Okta Identity Cloud
    Vulnerable versions: Tenants relying on phishable MFA factors (TOTP, push, SMS OTP) without device-bound or phishing-resistant authenticators
    Fixed in: N/A - mitigated via FIDO2 enforcement and network/device-trust policies, not a patchable vulnerability

Remediation for UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon

Immediate actions

  • Restrict M365 and Okta authentication and admin actions to trusted network sources (corporate network, VPN, or SASE egress) via conditional access / network zone policies
  • Require re-authentication and step-up authentication at least daily for sensitive SaaS resources, with reduced idle timeouts during active campaigns
  • Alert on IdP logs where system.multifactor.factor.setup / new authenticator or passkey registration is preceded by a failed or abandoned MFA challenge
  • Treat SaaS 'FileAccessed' events with the same priority as 'FileDownloaded' and flag high-volume access from scripting-library user agents (python-requests, WindowsPowerShell, Go-http-client)

Workarounds

  • Train helpdesk staff and employees to independently verify unsolicited 'urgent security migration' or 'passkey enrollment' calls through a known-good corporate channel before taking any authentication action, especially on personal devices
  • Deploy conditional-access rules that flag or block authentication from known residential-proxy ranges and from the DDoS-Guard / Private Layer / MEVSPACE hosting ASNs observed in this campaign's AiTM infrastructure

Longer-term hardening

  • Mandate phishing-resistant, device-bound authenticators (FIDO2 security keys, platform passkeys, Windows Hello for Business) for all privileged and SSO-fronted accounts
  • Consolidate all SaaS application authentication behind Entra ID/Okta SSO with consistently enforced conditional-access and device-trust policies
  • Require corporate-managed, MDM/EDR-enrolled endpoints for access to sensitive SaaS applications and identity-platform admin consoles
  • Enable end-user notifications for every authenticator/passkey lifecycle event (registration, modification, removal) so victims see attacker-initiated enrollments in real time

Weaknesses (CWE) in UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon

CWE-451, CWE-294, CWE-287

Timeline of UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon

  • GTIG's tracking window for 18 BlackFile Bitcoin wallet addresses begins; the wallets would ultimately receive 141.65 BTC (~$10.69M USD) in ransom payments through May 12, 2026.
  • Phishing domain myoktasso[.]com registered via TUCOWS, part of the April-May 2026 wave targeting manufacturing, real estate, healthcare, and insurance sectors.
  • deploypasskey[.]com registered via DDoS-Guard hosting, part of the O-UNC-066 passkey-enrollment-abuse phishing kit infrastructure.
  • passkeydeploy[.]com registered (used as the Pink-brand infrastructure bridge), targeting healthcare and technology victims.
  • BlackFile publicly announces retirement of its extortion brand.
  • Close of GTIG's tracked Bitcoin payment window; ransom payments to BlackFile wallets are observed continuing despite the prior day's shutdown announcement.
  • Targeting shifts to large technology, transportation, and hospitality organizations holding valuable IP, source code, and VIP client data; domain-provisioning cadence accelerates to roughly one new domain every 1.6 days.
  • oskeysync[.]com registered via NICENIC/EZYDOMAIN, used by the Helix brand across 10+ target sectors.
  • Redact publicly launches its data-leak site and rebrand statement, claiming the original BlackFile brand was 'compromised and hijacked by an exiled affiliate.'
  • passkeyhelpdesk[.]com registered via NICENIC/Cloudflare, shared infrastructure between the Falcon and Helix brands, targeting financial, energy, and healthcare sectors.
  • A 3-day spike of 7 new phishing domains (July 20-22) coincides with intensified financial-services and legal-sector targeting.
  • createssopasskey[.]com registered via NICENIC/Cloudflare, continuing the financial-services-focused targeting wave.
  • UNC6671 vishing attempts are reported against major U.S. hedge funds and private-equity firms, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel.
  • Google Threat Intelligence Group / Mandiant publish consolidated attribution linking BlackFile, Redact, Pink, Helix, and Falcon to a single cluster tracked as UNC6671; Infosecurity Magazine, SecurityWeek, The Hacker News, and BleepingComputer report on the campaign.

Sources cited for UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon

Detection coverage for TL-2026-1962

As of 2026-08-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1962 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1962

21 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats