Back Scworld Vishing group UNC6671 now focuses on extorting M&A firms | news
An Aug. 6 report by the Google Threat Intelligence Group (GTIG) offers some excellent insight into how attackers change tactics and vertical sector targets in a matter of weeks.
This most recent GTIG blog focused on the financially motivated vishing and extortion group UNC6671, which aims to exploit employees and gain entry into enterprise networks by impersonating corporate help-desk workers.
Known as BlackFile , the group supposedly retired in May 2026, but in actuality, regrouped and branched out as four different groups: Redact, Pink, Helix, and Falcon.
GTIG traces how UNC6671 may have shifted the vertical sectors it was attacking from April-May of this to this July, but still kept vishing employees via impersonating help-desk workers. Here’s a thumbnail:
Denis Calderone, chief technology officer at Suzu Labs, said SOC teams need to stop tracking brand names and start tracking behaviors.
Calderone said BlackFile didn't shut down, it split into four new brands — and the playbook across all of them is identical: vishing calls to personal mobile phones posing as IT helpdesk workers, adversary-in-the-middle (AiTM) credential harvesting through passkey-themed phishing domains, and automated exfiltration from Microsoft 365 and Okta using python-requests and PowerShell.
“GTIG's infrastructure analysis shows the same phishing templates and shared domains connecting all five brands,” said Calderone. “The name on the extortion note changed. Nothing else did.”
And the most recent attacks are potentially the most profitable yet.
Calderone said UNC6671 made a deliberate move toward organizations holding M&A data, litigation files, and investor records, the kind of information where the extortion leverage is enormous. He said GTIG tracked more than $10 million in Bitcoin payments across 18 wallet addresses between January and May alone, with final payments averaging around $750,000 after negotiation.
“And those payments kept flowing even after the BlackFile shutdown announcement in May,” said Calderone. “This is a well-funded operation that just moved upmarket.”
Shane Barney, chief information security officer at Keeper Security, added that what GTIG’s infrastructure analysis actually reveals is the operational maturity of UNC6671. Barney said they are registering new phishing domains at roughly one every 1.6 days, appending victim organization names as subdomains to make the URLs look internally legitimate and immediately deleting password reset confirmations and security alerts from compromised inboxes to suppress detection.
“That’s a disciplined, repeatable operation with staying power, and it’s now deliberately targeting organizations that hold merger and acquisition data, capital deployment details and litigation strategy — assets where the leverage for extortion is high,” said Barney.
Seemant Sehgal, founder and CEO at BreachLock, explained that the security teams that stay resilient in the face of these challenging attacks enforce hard rules on out-of-band verification for any request touching credentials, access, or wire transfers – no matter who’s calling or how urgent it sounds.
“They know which help desk workflows can be socially engineered, and they have removed the exceptions that let a convincing caller skip the process,” said Sehgal. “Making it inconvenient and expensive is what pushes groups like UNC667 toward easier targets. The organizations that get hit are rarely the ones that were unlucky. They are the ones with a verification step that had a loophole a caller could talk their way through."
Calderone from Suzu Labs said for SOC teams, the detection surface here is actually well-defined because the TTPs are so consistent. Here are three mitigation tips Calderone offers security teams:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
