>samit_hota
Back to security news

Security News · SN-2026-334

HIGHOPEN

UNC6671 Rebrands Vishing Extortion Operation After $10 Million Ransom Spree

Affected: Microsoft 365 · Okta · Financial Services · Private Equity · Professional Services

Samit Hota·
#news#phishing-social-engineering#unc6671

The vishing extortion group tracked as UNC6671 has restructured its operations, abandoning its original “BlackFile” brand in favor of a multi-brand extortion model operating under the names Redact, Pink, Helix, and Falcon. According to threat research from Google Threat Intelligence Group (GTIG), the threat actor has successfully extracted more than $10 million in Bitcoin payments across 18 wallet addresses between January and May alone. The group’s success stems from a highly effective combination of direct voice phishing (vishing) targeting enterprise employees and adversary-in-the-middle (AiTM) credential harvesting frameworks that bypass standard multi-factor authentication (MFA) controls protecting Microsoft 365 and Okta environments.

First identified in early 2026, UNC6671 focused its initial campaigns on organizations across North America, Australia, and the UK. Recent operational telemetry indicates a deliberate shift toward high-value targets in the financial services, private equity, and professional services sectors—industries where rapid access to sensitive deal rooms, client portfolios, and intellectual property translates directly to high-leverage extortion.

Anatomy of the AiTM Vishing Attack

The initial compromise vector relies heavily on social engineering executed over phone calls rather than traditional phishing emails. Attackers contact employees directly—frequently on personal mobile phone numbers—posing as members of the victim organization’s internal IT helpdesk. To establish credibility, the callers reference real internal corporate initiatives, citing urgent or mandatory passkey rollouts and security infrastructure migrations. In recent campaigns, UNC6671 operators have elevated their tactics by spoofing legitimate internal helpdesk phone numbers to evade initial caller-ID skepticism.

Once an employee is on the line, the caller directs them to a tailored credential harvesting portal designed to mirror the target’s authentic single sign-on (SSO) login interface. The group relies on generic root domains registered specifically for these campaigns, incorporating keywords designed to reassure victims during a supposed security upgrade:

  • passkeyhelpdesk[.]com
  • portalpasskey[.]com
  • addssopasskey[.]com
  • passkeydeploy[.]com
  • mysecurepasskey[.]com
  • passkeyuser[.]com

Underneath these domain structures, UNC6671 provisions victim-specific subdomains hosting customized phishing panels. Because these sites operate as AiTM proxies, the underlying infrastructure relays the victim’s entering credentials and MFA tokens directly to the legitimate identity provider (IdP) in real time. When the user completes their push notification, SMS prompt, or time-based one-time password (TOTP) verification, the AiTM proxy intercepts the resulting session cookie or access token.

This technique renders standard MFA mechanisms ineffective, granting the attacker an active, authenticated session inside the victim’s cloud tenant without ever needing to crack underlying passwords or solve cryptographic MFA challenges directly.

Post-Compromise Pivoting and Extortion Dynamics

Once inside an enterprise environment, UNC6671 focuses on expanding its blast radius beyond primary SSO applications. Threat actors leverage their administrative or high-level user foothold to access non-SSO enterprise applications, initiating password resets via compromised internal email accounts. To prolong silent access, the actors actively clean up after themselves by deploying mail flow rules and manually deleting confirmation emails, password reset alerts, and security notifications before the legitimate user notices them.

Exfiltrated data is subsequently uploaded to extortion sites. In June, UNC6671 launched a public leak site under the “Redact” brand, accompanying the launch with a public narrative claiming that the former BlackFile brand had been hijacked by a disgruntled affiliate. However, technical infrastructure monitoring confirms extensive TTP, code, and domain template overlaps between BlackFile, Redact, Pink, Helix, and Falcon, indicating that a unified core threat actor group is managing or sharing infrastructure across these distinct operational fronts.

The group’s financial negotiations reflect an aggressive initial posture combined with flexible settlement terms:

  • Initial Demands: Typically range between $1 million and $3 million USD in cryptocurrency.
  • Negotiation Slips: Operators frequently accept reductions between 50% and 75% during active dialogue.
  • Final Payouts: In over 53% of tracked cases where ransoms were paid, final payments averaged $750,000 USD.

Mitigating Vishing and AiTM SSO Compromise

Defending against UNC6671 requires technical controls that do not rely on human discernment during real-time phone interactions. Because traditional push-based or TOTP-based MFA can be proxied by AiTM kits, organizations must enforce phishing-resistant authentication methods.

  • Deploy FIDO2 / WebAuthn Hardware Keys or Passkeys: FIDO2 standards bind the authentication challenge directly to the origin domain (FQDN) in the browser. If an employee visits passkeyhelpdesk[.]com instead of the legitimate login.microsoftonline.com or Okta domain, the browser will refuse to supply the cryptographic response, completely neutralizing AiTM proxy harvesting.
  • Implement Out-of-Band Helpdesk Verification: Establish strict protocol rules requiring helpdesk staff to verify employee identities via secondary internal channels (e.g., direct messaging on authenticated corporate platforms) before assisting with account access, passkey enrollments, or MFA resets. Helpdesk agents should never instruct users to navigate to external domains over phone calls.
  • Monitor Domain Registrations and Infrastructure: Ingest domain telemetry searching for newly registered domains combining target brand names with high-risk keywords like passkey, sso, portal, and helpdesk.
  • Audit Email Inbox Rules and Application Resets: Configure SIEM detection alerts for automated mail deletion rules targeting terms like “password reset,” “security alert,” or “MFA,” alongside anomalous password reset requests originating from non-SSO SaaS applications.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call