A wave of vishing attacks against hedge funds and private-equity firms has been attributed to UNC6671, a group linked to the BlackFile extortion campaign. The attackers used help-desk impersonation and cloud phishing to steal credentials, access Microsoft 365 and Okta accounts, and extort organizations including Point72, Two Sigma, Millennium, and Citadel. #UNC6671 #BlackFile #Point72 #TwoSigma #Millennium #Citadel #Okta #Microsoft365
Keypoints
- UNC6671 is tied to a recent wave of attacks on financial firms.
- The group is associated with the BlackFile extortion campaign.
- Attackers used vishing to impersonate corporate help desks.
- Victims were tricked into visiting phishing sites that stole credentials and session cookies.
- Mandiant says it is helping several dozen compromised organizations.