Full Report
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group. [...]
Analysis Summary
This summary is based on the article provided regarding the threat actor designated as UNC6671.
# Threat Actor: UNC6671
## Attribution & Identity
* **Designation:** UNC6671 (Tracked by Google Threat Intelligence Group/Mandiant).
* **Associated Brands/Aliases:** BlackFile (original public brand), Redact, Pink, Helix, and Falcon.
* **Identity:** Assessed to be a single core intrusion group driving help-desk vishing and cloud data theft across multiple extortion brands.
* **Distinctions:** Distinct from Scattered Spider (UNC3944), despite using similar social engineering tactics.
## Activity Summary
* **Recent Campaigns:** A wave of attacks (July–August 2026) targeting high-value financial institutions using sophisticated vishing and session theft.
* **Historical Activity:** First emerged in February 2025. Previously targeted retail and hospitality; diversified in 2026 to include manufacturing, healthcare, and technology.
* **Financial Impact:** GTIG tracked over $10.6 million USD in Bitcoin payments to group wallets between January and May 2026.
## Tactics, Techniques & Procedures
* **Vishing (Voice Phishing):** Operators call employees on personal mobile phones, spoofing corporate help-desks.
* **Social Engineering:** Claims that employees must enroll in passkeys or update Multi-Factor Authentication (MFA) settings.
* **Adversary-in-the-Middle (AiTM):** Use of phishing kits on look-alike domains to capture credentials and session cookies in real-time.
* **Cloud Access & Lateral Movement:** Compromising Microsoft 365 or Okta SSO accounts to access linked cloud platforms.
* **Defense Evasion:** Automated deletion of security notifications and password-reset emails from compromised inboxes to delay detection.
* **Extortion:** Data theft followed by ransom demands (typically settling for ~$750,000 USD).
## Targeting
* **Sectors:** Hedge funds, private-equity firms, major law firms, financial-rating agencies, retail, hospitality, manufacturing, healthcare, real estate, technology, and transportation.
* **Geography:** Global (Implied focus on Western financial hubs).
* **Victims (Targeted/Attacked):** Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel.
## Tools & Infrastructure
* **Phishing Kits:** AiTM kits designed for real-time session hijacking.
* **SSO Exploitation:** Direct targeting of Okta and Microsoft 365 dashboards.
* **Infrastructure:** Specific domain registration patterns distinct from other known groups.
* **Payment:** Bitcoin (BTC) for ransom collections.
## Implications
UNC6671 represents a highly organized extortion threat that has successfully moved upmarket from retail targets to Tier-1 financial institutions. Their ability to bypass MFA via AiTM kits and session theft makes them a significant risk to organizations relying solely on traditional SMS or push-based authentication. The group's "multi-brand" strategy suggests an attempt to obfuscate their scale and evade unified attribution.
## Mitigations
* **FIDO2/WebAuthn:** Implement hardware-based security keys (passkeys) to defend against AiTM phishing, as these are not easily proxied by phishing kits.
* **Employee Awareness:** Specialized training for high-value targets regarding "help-desk" vishing and the dangers of providing credentials over the phone.
* **Session Management:** Implement shorter session lifetimes and restrict session token usage to known/trusted IP ranges.
* **Enhanced Monitoring:** Monitor for suspicious SSO logins, particularly those followed by the creation of inbox rules or the mass deletion of emails.
* **Identity Guarding:** Implement stricter verification protocols for help-desk interactions involving MFA resets or credential changes.