# UNC6671 Rebrands BlackFile into Redact, Pink, Helix, Falcon: Vishing + AiTM Campaign Steals M365/Okta Data for Extortion

> Google Threat Intelligence Group (GTIG/Mandiant) attributes the BlackFile extortion brand and its June 27, 2026 rebrand into Redact, plus the related Pink, Helix, and Falcon personas, to a single actor cluster tracked as UNC6671. The group vishes employees on personal phones while impersonating IT helpdesk staff pushing fake FIDO2/passkey "security migrations," harvests credentials and MFA tokens via AiTM phishing panels, then runs automated Python/PowerShell scripts to exfiltrate data from Microsoft 365 and Okta before extorting victims for Bitcoin.

- **Published:** 2026-08-09T00:00:00Z
- **Last reviewed:** 2026-08-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1962
- **ID:** TL-2026-1962
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Actor:** UNC6671
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

UNC6671 is a financially motivated extortion cluster that GTIG links to the BlackFile brand (active since early 2026) and four apparent successor brands — Redact, Pink, Helix, and Falcon — launched after BlackFile announced its retirement in May 2026. Redact's June 27, 2026 rebrand statement claimed the original BlackFile brand had been "compromised and hijacked by an exiled affiliate," but GTIG found overlapping phishing templates, shared root domains (notably passkeyhelpdesk[.]com and passkeydeploy[.]com), consistent victimology, and shared AiTM infrastructure across all five personas, assessing they are operated by a coordinated group rather than genuinely independent actors.

The intrusion begins with voice phishing: operators call targeted employees, frequently on personal mobile devices to bypass corporate telephony controls, spoof legitimate helpdesk numbers, and claim an urgent, mandatory security migration requires the victim to enroll a FIDO2 passkey or update their MFA. Victims are walked to lookalike domains (patterned as [victim].[genericroot].com, e.g. createssopasskey[.]com, addssopasskey[.]com) hosting adversary-in-the-middle phishing kits. A related campaign tracked by Okta as O-UNC-066 documented that the kit is not a simple transparent proxy but an operator-controlled PHP panel with a 1-second heartbeat polling loop: while the victim is walked through what appears to be legitimate passkey enrollment (including a decoy step presenting fake BIP-39-style recovery phrases), the operator simultaneously authenticates to the real account with the stolen credentials and registers their OWN passkey/authenticator against the victim's account, giving them durable, MFA-satisfying access independent of the original phishing session.

Once inside Microsoft 365 and/or Okta, the group uses Python (`python-requests/2.28.1`) and PowerShell (`WindowsPowerShell/5.1`) scripts to stream data directly out of SharePoint/OneDrive and Okta via API access rather than traditional bulk downloads, and separately abuses compromised mailbox access to trigger password resets on non-SSO applications. For defense evasion, the group systematically deletes password-reset confirmations, MFA-configuration-change alerts, and other security notifications from compromised inboxes to delay detection. Exfiltration traffic has been observed proxied through both dedicated AiTM reverse-proxy infrastructure (Private Layer/Switzerland, MEVSPACE/Poland, DDoS-Guard/Russia) and residential-ISP proxy pools (AT&T, Comcast, Starry, Optimum) to blend with legitimate user geolocation.

Targeting has escalated in both scale and value: April-May 2026 hit manufacturing, real estate, healthcare, and insurance at roughly one new phishing domain every 2.2 days; June 2026 shifted to technology, transportation, and hospitality organizations holding valuable IP/source code/VIP client data at ~1 domain every 1.6 days; July 2026 pivoted to financial services, private equity, and law firms to maximize extortion leverage via M&A and litigation data, including a spike of 7 new domains in a 3-day window (July 20-22). By August 2026, GTIG and reporting outlets identified attempted targeting of major U.S. hedge funds and private-equity firms including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. GTIG tracked 18 BlackFile Bitcoin wallets receiving 141.65 BTC (~$10.69M USD) between January 7 and May 12, 2026 — with payments continuing even after the brand's public shutdown announcement — from initial ransom demands of $1-3M USD negotiated down 50-75% to average final payments near $750,000 USD, with roughly a 53% payment rate across tracked cases. Extortion is carried out via brand-specific data-leak sites (Redact, Pink, Helix, Falcon), with Redact publishing a verified Tox ID and PGP key for negotiations; the Falcon brand has publicly disputed unified attribution, claiming to operate solely as a Redact affiliate independent of Helix and Pink.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1566 Phishing
- T1684.001 Impersonation
- T1078 Valid Accounts
- T1098 Account Manipulation
- T1557 Adversary-in-the-Middle
- T1111 Multi-Factor Authentication Interception
- T1539 Steal Web Session Cookie
- T1114 Email Collection
- T1530 Data from Cloud Storage
- T1020 Automated Exfiltration
- T1090 Proxy
- T1657 Financial Theft

## Sources

- [Redact Extortion Group is Rebrand of Notorious BlackFile Collective](https://www.infosecurity-magazine.com/news/redact-extortion-group-blackfile/)
- [UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments](https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments)
- [Vishing actors target Entra passkey enrollment](https://www.okta.com/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/)
- [Vishing Extortion Group UNC6671 Rebrands After Making Millions](https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/)
- [UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data](https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html)
- [Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group](https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1962
