Vishing Extortion Group UNC6671 Rebrands After Making Millions

Vishing Extortion Group UNC6671 Rebrands After Making Millions
UNC6671 has rebranded its extortion operation multiple times while continuing tailored IT helpdesk vishing attacks against organizations using Microsoft 365 and Okta. Google Threat Intelligence Group says the group has shifted branding from BlackFile to Redact, Pink, Helix, and Falcon while collecting more than $10 million in ransom payments. #UNC6671 #BlackFile #Redact #Pink #Helix #Falcon #Microsoft365 #Okta

Keypoints

  • UNC6671 uses IT helpdesk vishing to target employees with urgent security migration pretexts.
  • The group focuses on Microsoft 365 and Okta environments to steal credentials and MFA tokens.
  • BlackFile was retired, but the same operators continued under Redact, Pink, Helix, and Falcon.
  • Recent attacks have targeted financial services, private equity, and professional services organizations.
  • GTIG linked the campaign to over $10 million in Bitcoin and ransom demands that were often negotiated down.

Read More: https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/