Scworld
Rebranded Vishing Group UNC6671 Targets M&A Firms with Extortion Tactics
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Google Threat Intelligence Group (GTIG) reported that the extortion group UNC6671, previously known as BlackFile, has rebranded to Redact and expanded its operations. Despite claiming to have retired in May 2026, the group has split into four brands: Redact, Pink, Helix, and Falcon. They continue to employ vishing tactics, impersonating IT helpdesk staff to target enterprise employees. The group has shifted focus to organizations involved in mergers and acquisitions, where extortion potential is high. GTIG tracked over $10 million in Bitcoin payments linked to these operations from January to May 2026. The attackers utilize adversary-in-the-middle techniques to harvest credentials and exfiltrate data from platforms like Microsoft 365 and Okta. Their infrastructure analysis reveals shared phishing templates and domains across all brands, indicating a coordinated effort. The operational maturity of UNC6671 is evident in their disciplined approach to registering new phishing domains and suppressing detection.
Key Points: • UNC6671 has rebranded to Redact while continuing extortion activities. • The group now targets M&A firms, significantly increasing potential extortion leverage. • GTIG tracked over $10 million in Bitcoin payments linked to UNC6671's operations.