Scworld Rebranded Vishing Group UNC6671 Targets M&A Firms with Extortion Tactics
Article Content
- •UNC6671 has rebranded to Redact while continuing extortion activities.
- •The group now targets M&A firms, significantly increasing potential extortion leverage.
- •GTIG tracked over $10 million in Bitcoin payments linked to UNC6671's operations.
The Google Threat Intelligence Group (GTIG) reported that the extortion group UNC6671, previously known as BlackFile, has rebranded to Redact and expanded its operations. Despite claiming to have retired in May 2026, the group has split into four brands: Redact, Pink, Helix, and Falcon. They continue to employ vishing tactics, impersonating IT helpdesk staff to target enterprise employees. The group has shifted focus to organizations involved in mergers and acquisitions, where extortion potential is high. GTIG tracked over $10 million in Bitcoin payments linked to these operations from January to May 2026. The attackers utilize adversary-in-the-middle techniques to harvest credentials and exfiltrate data from platforms like Microsoft 365 and Okta. Their infrastructure analysis reveals shared phishing templates and domains across all brands, indicating a coordinated effort. The operational maturity of UNC6671 is evident in their disciplined approach to registering new phishing domains and suppressing detection.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Following this threat?
Track BlackFile and Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Vishing Attacks Target Executives for Microsoft 365 Data Theft A wave of data theft and extortion targeting Microsoft 365 and other SaaS accounts has emerged, tracked by Arctic Wolf as PREY-0058. The attackers use vishing calls impersonating IT help desk staff to trick executives into providing credentials and multi-factor authentication (MFA) approvals. This method involves…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…