UNC6671 is carrying out vishing-led extortion campaigns against financial services, private equity, and professional services by impersonating IT help desk staff and stealing credentials through fake login portals. The group uses captured sessions to access Microsoft 365 and Okta, exfiltrate cloud data, and operate under multiple extortion brands including Redact, Pink, Helix, Falcon, and BlackFile. #UNC6671 #Redact #Pink #Helix #Falcon #BlackFile #Microsoft365 #Okta
Keypoints
- UNC6671 uses voice phishing to impersonate IT support and target employees on personal mobile devices.
- Fake AitM login pages are used to capture credentials, MFA tokens, and active session data.
- The group abuses identity providers to move across SaaS environments such as Microsoft 365 and Okta.
- UNC6671 operates through multiple extortion brands, including Redact, Pink, Helix, Falcon, and BlackFile.
- Google recommends phishing-resistant MFA, session controls, and tighter IdP monitoring to reduce risk.
Read More: https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html