Google Threat Intelligence Group tracks UNC6671 as an active extortion operation that uses vishing, AiTM credential theft, and SaaS exfiltration while operating across multiple brands including BlackFile, Redact, Pink, Helix, and Falcon. The report also details shared infrastructure, shifting targeting toward financial and legal sectors, and a Bitcoin-based ransom operation that continued even after the alleged BlackFile shutdown. #UNC6671 #BlackFile #Redact #Pink #Helix #Falcon
Keypoints
- UNC6671 remains active despite the alleged retirement of the BlackFile extortion brand.
- The group operates across multiple extortion brands, including Redact, Pink, Helix, and Falcon, with shared infrastructure and overlapping victim targeting.
- Initial access relies heavily on voice phishing against enterprise employees, often by impersonating IT helpdesk staff and calling personal mobile phones.
- Victims are sent to spoofed login portals where AiTM infrastructure steals credentials and MFA tokens, enabling session persistence and cloud access.
- The actors use automated tools to exfiltrate data from cloud services such as Microsoft 365 and Okta.
- Targeting shifted from broader enterprise sectors to higher-value organizations in technology, transportation, hospitality, financial services, and legal services.
- Google observed Bitcoin ransom payments, negotiation-driven reductions, and continued financial activity after the public BlackFile shutdown notice.
MITRE Techniques
- [T1566.004] Spearphishing Voice – UNC6671 calls employees and poses as IT helpdesk staff to lure them into entering credentials on fake portals (‘the threat actor often contacts employees via their personal mobile devices’ / ‘operating under the false pretext of an urgent helpdesk mandate’).
- [T1056.004] Input Capture: Credential API Hooking / Adversary-in-the-Middle style credential capture – The group uses AiTM infrastructure to intercept credentials and MFA tokens from spoofed portals (‘AiTM infrastructure intercepts credentials and multi-factor authentication (MFA) tokens’).
- [T1110.003] Password Spraying / Automated guessing not indicated directly; omitted. – Not enough direct evidence in the article.
- [T1110.004] Credential Stuffing – Stolen credentials and tokens are reused to gain access to enterprise cloud accounts (‘Once session persistence is established’).
- [T1098] Account Manipulation – Compromised email accounts are used to initiate unauthorized password resets and alter security settings (‘used compromised email accounts to initiate unauthorized password resets’).
- [T1070.008] Clear Mailbox Data – The actors delete security notifications and password-reset confirmations to avoid detection (‘systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts’).
- [T1021.007] Cloud Services: SaaS – UNC6671 exfiltrates data from SaaS platforms such as Microsoft 365 and Okta (‘data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta’).
- [T1020] Data Exfiltration – The operation automates streaming/exfiltration of cloud data after access is obtained (‘deploy automated scripts for data exfiltration’).
- [T1090.002] Proxy: External Proxy – The infrastructure uses reverse proxies and residential proxies to hide source traffic (‘Panel AiTM Reverse Proxy’, ‘M365 / Okta Residential Proxy’).
- [T1584.001] Develop Capabilities: Domains – The group registers numerous lookalike domains to host phishing portals (‘root domains masquerading as being related to passkeys’).
- [T1056.001] Keylogging – Not explicitly stated; omitted. – No direct evidence in the article.
Indicators of Compromise
- [Domains] phishing and credential-harvesting portals – passkeyhelpdesk[.]com, addssopasskey[.]com, createssopasskey[.]com, myssopasskey[.]com, passkeymfa[.]com
- [Domains] additional lookalike infrastructure – myoktasso[.]com, setupssopasskey[.]com, passkeydeploy[.]com, oskeysync[.]com, keysyncos[.]com
- [IP addresses] AiTM reverse proxies and backend infrastructure – 31.7.56.61, 31.7.56.52, 193.34.212.132, 185.178.208.153
- [IP addresses] automated SaaS exfiltration and residential proxy nodes – 23.234.75.84, 195.140.213.114, 107.128.45.122, 76.103.148.180
- [User-Agent strings] scripting and SDK-based exfiltration activity – python-requests/2.28.1, WindowsPowerShell/5.1, 0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94
- [Wallet addresses] BlackFile ransom payment addresses – 18 Bitcoin wallet addresses were tracked, including addresses receiving payments totaling 141.65 BTC
- [Registrar / hosting infrastructure] domain services linked to phishing kit registration – TUCOWS.COM, CO., NICENIC INTERNATIONAL GROUP CO., LIMITED, Cloudflare, DDOS-GUARD