Full Report
Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices. These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta. In this update to our May 2026 blog, we detail the infrastructure linkages connecting these extortion brands. We also examine the evolution of UNC6671's targeting including recent activity focused on financial services, private equity, and professional services, and provide hardening guidance to help organizations protect themselves from this threat. UNC6671 Associated Extortion Brands Across UNC6671 intrusions, the initial access and post-compromise tactics, techniques, and procedures (TTPs) have remained remarkably consistent. These operations uniformly leverage tailored IT helpdesk voice phishing (vishing), AiTM credential harvesting panels, and data theft from SaaS applications. Despite this unified technical baseline, extortion messages have used different branding and victim data stolen during these intrusions has been published across distinct data leak sites (DLS) (Figure 1). While public group communications cited an affiliate breakaway as the rationale for the initial rebranding to Redact, subsequent overlaps in phishing templates, victimology, and shared infrastructure conduits suggests that associated actors have subsequently leveraged the Pink, Helix, and Falcon extortion brands to monetize their operations. Figure 1: UNC6671 Associated DLS Listings by Site Figure 2: Helix and Pink DLS Figure 3: Falcon DLS Initial REDACT Rebranding On June 27, 2026, the Redact operators published a blog post on their newly established Data Leak Site (DLS) addressing their alleged rebrand away from BlackFile. In the publication, the group claimed that the original BlackFile brand had been compromised and hijacked by an exiled affiliate. According to Redact, this former associate purportedly operated an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns under their name using unlinked Tox identities. The operators asserted that this rogue affiliate intentionally orchestrated the "shutdown" of the BlackFile brand in May 2026 to sow confusion among threat intelligence analysts and cyber insurance negotiators, thereby damaging the brand's reputation. To distance themselves from BlackFile, the operators stated that they rebranded as Redact, introducing a single verified Tox ID and PGP key to authenticate all future correspondence. Additionally, the post explicitly denied that pressure from the rival groups influenced their rebranding decision. Figure 3: REDACT statement on alleged break from BlackFile Shared Infrastructure: Connecting the Phishing Ecosystem UNC6671 uses credential harvesting panels hosted on generic root domains masquerading as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns. Monitoring this consistent digital footprint revealed overlaps in specific victim targeting associated with multiple extortion brands. These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible. Rather than maintaining isolated infrastructure for each target, UNC6671 reuses generic root domains across multiple target organizations, creating a traceable chain between extortion brands: Falcon: The root domain passkeyhelpdesk[.]com was used to target at least one organization extorted using the Falcon brand. This same domain was simultaneously used to target an organization extorted using the Helix brand, as well as numerous other companies that we did not observe later posted on a DLS. Additionally, root domains such as portalpasskey[.]com and addssopasskey[.]com targeted organizations extorted by Falcon, while hosting intermediate targets that bridged directly into Helix infrastructure. Pink: A subset of unlisted companies were concurrently targeted using additional root domains (such as passkeyms[.]com and mysecurepasskey[.]com), which acted as intermediate bridges to another infrastructure cluster focused on passkeydeploy[.]com. This final domain was simultaneously used to target at least one organization extorted by Pink. Helix: The root domain passkeyhelpdesk[.]com directly overlapped targeting between Falcon and Helix. Furthermore, intermediate target organizations bridged additional infrastructure into clusters of subdomains on oskeysync[.]com and keysyncos[.]com. These clusters targeted multiple organizations later listed on the Helix DLS. BlackFile: Root domains such as setupsso[.]com and idokta[.]com were used to target an organization extorted using the BlackFile brand. Intermediary target organizations on setupsso[.]com acted as bridges to passkeydeploy[.]com (Pink). Concurrently, passkeyuser[.]com was used to target another BlackFile victim, where intermediate target organizations bridged into passkeyportal[.]com (Helix) and mysecurepasskey[.]com. Figure 4: Shared infrastructure across multiple brands Phishing templates Analysis shows that the same phishing templates were used across all these domains, with identical code and design hosted simultaneously on different websites, including addssopasskey[.]com, createssopasskey[.]com, and passkeyhelpdesk[.]com. For instance, while addssopasskey[.]com was strictly used to target organizations later extorted by Falcon, the identically configured passkeyhelpdesk[.]com domain was simultaneously used to target two entirely separate victims—one of which was claimed by Falcon, and the other by Helix. The widespread deployment of these matching templates to harvest credentials for multiple DLS brands suggests they rely on shared underlying infrastructure. Evolution of Targeting UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. UNC6671 leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels. Their root domains mimic enterprise authentication enrollment portals pairing terms as "passkey," "mfa," or "sso" paired with verbs. Between April and May 2026, we observed domains broadly designed to target mature, large-scale enterprises across multiple industries including the manufacturing, real estate, healthcare, and insurance sectors. During this wave of activity, the threat actors appeared to prioritize high-volume credential harvesting across these established enterprise verticals. The observed subdomains in the following months appeared to represent a progression in UNC6671’s extortion model. In June 2026, targeting transitioned toward large technology, transportation, and hospitality organizations, seemingly focusing on entities holding valuable intellectual property, software source code, or sensitive VIP client data. By July 2026, the target profile narrowed to focus on the financial and legal sectors, with observed infrastructure directed at private equity firms, law firms, and financial rating agencies. Concentrating on organizations involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage extortion demands. Comparing these two time periods also illustrates an increase in operational tempo. The volume of newly observed infrastructure was evenly distributed between June 1 and July 31, 2026, establishing an accelerated cadence of approximately one domain every 1.6 days, primarily across Cloudflare and DDOS-GUARD. A brief spike in provisioning also occurred between July 20 and July 22, during which seven domains were operationalized within a 72-hour window. This overall June and July tempo represents a measurable increase from earlier activity observed between April 1 and May 31, 2026, where a set of 28 root domains was provisioned at a less frequent rate of one every 2.2 days. On the date of publication of this blog, 7 of 8 still resolving phishing domains did not use wildcard DNS indicating that targets discovered through passive DNS data were likely specifically targeted by UNC6671. Figure 5: Root domain registrations New Techniques Since our last blog, the tactics across UNC6671 intrusions have been largely consistent; however, we have observed several new techniques. IT Helpdesk and Passkey Pretexts UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls. In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy. During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multi-factor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain (e.g., [company].createssopasskey[.]com or [company].addssopasskey[.]com). EvasionTechniques UNC6671 increasingly relies on defense evasion to maintain account-level persistence and conceal its operations. In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications. To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations. Ransom Negotiations and Blockchain Analysis Between January 7, 2026, and May 12, 2026, GTIG reviewed 18 BlackFile Bitcoin wallet addresses receiving a total of 141.65 BTC, representing approximately $10.69 million USD at the time of the transactions. Notably, ransom payments to these wallets continued past the publicized Blackfile data leak site shutdown notice on May 11, 2026. Multiple significant cashout events observed in late April and early May confirm that financial operations proceeded without interruption during the rebranding phase. Initial ransom demands typically range from $1 million to upwards of $3 million USD. However, the extortion operators shifted demands during negotiations, often agreeing to reductions between 50% and 75% of the initial ransom demand. In over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC). Remediation and Hardening Guidance GTIG recommends that corporate defenders implement the following controls to mitigate identity-centric vishing, AiTM phishing, and programmatic SaaS exfiltration: Enforce Phishing-Resistant Multi-factor Authentication: Mandate phishing-resistant authenticators such as FIDO2-compliant roaming security keys, passkeys, and platform authenticators (e.g., Windows Hello for Business, Okta Fastpass) across all SSO environments and enterprise identity providers (IdPs). These authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective. Integrate SaaS Applications and Cloud Platforms with SSO: Maintaining authentication standards across multiple platforms increases the propensity for configuration drift. Different SaaS applications require or support different security features. Integrating business-critical applications with a standard SSO platform such as Entra ID or Okta allows consistent application of security controls across disparate platforms. Enforce Session Controls: Reduce session lengths to enforce re-authentication at least once per work day. Enforce idle session timeouts, especially for privileged access. These timeouts can be reduced further during active phishing campaigns. Enforce step-up authentication when accessing critical or sensitive resources. Utilize token theft mitigations within authentication platforms such as IP session binding, Device-Bound Session Credentials, or Continuous Access Evaluation. Restrict Authentication to Trusted Network Sources: Utilize defined network zones coming from known sources such as corporate networks, VPN ranges, and Secure Access Service Edge (SASE) platforms. Define and enforce these ranges within SaaS apps or cloud platforms as well as within authentication policies in Entra ID or Okta. Require Corporate-Managed Devices for Access: Enforcing that authentication comes from a corporate-managed endpoint with MDM and EDR reduces the attack surface and likelihood that an attacker can utilize an arbitrary device for access. Device checks can be configured as part of authentication policies in Entra ID or Okta. Deploy Endpoint and Browser Credential Guarding: Enable Google Workspace Password Alert to trigger automated administrative alerts or resets if corporate password hashes are entered into unauthorized domains. For Microsoft 365 environments, configure Microsoft Defender SmartScreen and Credential Protection to block credential submissions on unverified sites. Monitor IdP Logs for Abandoned Challenge Patterns: Query Okta and Microsoft Entra ID audit logs for MFA registration events (system.multifactor.factor.setup) that are immediately preceded by authentication failures (user.authentication.auth_via_mfa) or abandoned push challenges. Audit UAL Telemetry for Direct Stream Exfiltration: Configure Security Operations Center (SOC) detection pipelines to treat FileAccessed events with the same criticality as FileDownloaded when the UserAgent string identifies a scripting library (python-requests, WindowsPowerShell, Go-http-client) or when the access volume exceeds normal human browsing thresholds. Restrict and Alert on Residential Proxy Authentication: Create conditional access policies and anomaly alerts for SSO authentication attempts originating from commercial VPN providers (Mullvad, Private Layer) or unassociated residential broadband proxy pools (AT&T, Comcast, Charter) that diverge from established employee geographic baselines. Outlook and Implications The activity associated with UNC6671 highlights the fluidity of threat actor brands relative to persistent tactics, techniques, and procedures. While the extortion brands associated with this activity continue to multiply, the tradecraft across these operations remains anchored in helpdesk vishing, AiTM session interception, and SaaS exfiltration. We believe that this most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout. This assessment is supported by the tight infrastructure overlaps, shared vishing panel deployments, and overlaps in victim targeting observed across BlackFile, Redact, Pink, Helix, and Falcon. However, there are several other scenarios that could explain the broader dynamics across these brands: Actor Splintering: Internal rifts, financial disputes, or operational security compromises routinely lead to group fragmentation. Former affiliates or splinter cells retaining access to shared initial access playbooks, panel code, and target lists can easily establish independent extortion fronts while continuing to execute identical TTPs. Shared Ecosystem and Panel use: Separate threat groups may simply be leveraging the same commoditized phishing panels, voice-phishing callers, and shared infrastructure. As these AiTM panels and VaaS services become widely available, distinct threat actors can deploy matching infrastructure and pretexts without requiring direct organizational alignment. Outsourced Extortion: The intrusion operators driving initial access and cloud data exfiltration could remain the same core group of actors, while the extortion and negotiation phases are outsourced to different actors. Regardless of whether this activity reflects a fractured threat group, outsourced extortion negotiators, or a broader affiliate network, the initial infection vector leveraged and goals of these campaigns is consistent. Organizations should prioritize phishing-resistant authenticators and behavioral SaaS auditing to disrupt these identity-centric attacks. Indicators of Compromise (IOCs) To assist the wider community in hunting and identifying activity outlined in this blog post, we have provided indicators of compromise (IOCs) in a free GTI Collection for registered users. At the time of publication, identified phishing domains have been added to Google Safe Browsing. While this collection provides a comprehensive list of IOCs, defenders should note that the majority of identified IP addresses are commercial VPN nodes, and actual source IPs tend to vary as the actor continuously cycles through new infrastructure. Furthermore, the domains are often stood up and used within minutes of registration; as such, they are provided primarily as examples of past naming conventions and usage patterns rather than as a primary mechanism for real-time blocking. Domain Creation Date Registrar Name Servers Targeted Industry myoktasso[.]com 2026-04-04 TUCOWS.COM, CO. Njalla / Pipe.ma Financial Services, Transportation mypasskeysso[.]com 2026-04-04 TUCOWS.COM, CO. Cloudflare Healthcare setupssopasskey[.]com 2026-04-07 TUCOWS.COM, CO. Cloudflare Financial Services, Healthcare, Media & Entertainment mspasskey[.]com 2026-04-08 TUCOWS.COM, CO. Cloudflare Real Estate, Healthcare, Technology activatepasskey[.]com 2026-04-10 TUCOWS.COM, CO. Cloudflare Financial Services, Hospitality, Healthcare enrollpasskey[.]com 2026-04-10 TUCOWS.COM, CO. Cloudflare Financial Services, Energy, Healthcare keyokta[.]com 2026-04-13 TUCOWS.COM, CO. Cloudflare Healthcare, Financial Services oktaenroll[.]com 2026-04-13 TUCOWS.COM, CO. Cloudflare Healthcare, Construction & Engineering oktaportalsso[.]com 2026-04-16 TUCOWS.COM, CO. Cloudflare Retail & Consumer Goods, Healthcare, Legal passkeyportal[.]com 2026-04-16 TUCOWS.COM, CO. Cloudflare N/A portalpasskey[.]com 2026-04-16 TUCOWS.COM, CO. Cloudflare Transportation passkeyportalsetup[.]com 2026-04-20 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Technology addoktapasskey[.]com 2026-04-21 NICENIC INTERNATIONAL GROUP CO., LIMITED Private Layer (31.7.56.61) Financial Services, Technology, Media & Entertainment deploypasskey[.]com 2026-04-21 TUCOWS.COM, CO. DDOS-GUARD Retail & Consumer Goods passkeydeploy[.]com 2026-04-23 Internet Domain Service BS Corp. DDOS-GUARD Healthcare, Technology activatemypasskey[.]com 2026-04-24 TUCOWS.COM, CO. Cloudflare Financial Services registerpasskey[.]com 2026-04-29 NICENIC INTERNATIONAL GROUP CO., LIMITED MEVSPACE (193.34.212.132) Manufacturing createpasskey[.]com 2026-05-03 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare N/A passkeyadd[.]com 2026-05-08 TUCOWS.COM, CO. DDOS-GUARD Business Services, Technology passkeyregister[.]com 2026-05-08 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / MEVSPACE Energy, Technology, Healthcare passkeycenter[.]com 2026-05-11 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Legal, Financial Services, Healthcare secureauthpasskey[.]com 2026-05-14 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Healthcare passkeyrollout[.]com 2026-05-18 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / MEVSPACE Non-Corporate, Insurance, Legal setpasskey[.]com 2026-05-22 Internet Domain Service BS Corp. DDOS-GUARD Technology, Business Services, Construction & Engineering passkeyokta[.]com 2026-05-26 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Media & Entertainment, Transportation passkeyset[.]com 2026-05-27 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Transportation createmypasskey[.]com 2026-05-27 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering newpasskey[.]com 2026-05-28 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Media & Entertainment passkeysupport[.]com 2026-05-29 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Healthcare, Technology, Legal, Retail & Consumer Goods sqfepjvmrd[.]xyz 2026-06-01 NICENIC INTERNATIONAL GROUP CO., LIMITED MY-NDNS N/A passkeyregistration[.]com 2026-06-02 PDR Ltd. d/b/a PublicDomainRegistry.com Suspended-Domain N/A addmypasskey[.]com 2026-06-03 TUCOWS.COM, CO. Private Layer (31.7.56.52) Financial Services, Healthcare, Transportation passkey-setup[.]com 2026-06-03 Tucows Domains Inc. Cloudflare Legal, Financial Services passkey-portal[.]com 2026-06-05 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Retail & Consumer Goods, Technology, Media & Entertainment startpasskeysetup[.]com 2026-06-05 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Technology, Healthcare, Retail & Consumer Goods, Construction & Engineering, Media & Entertainment, Financial Services passkey-connect[.]com 2026-06-05 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Technology portalsetuphub[.]com 2026-06-10 PDR Ltd. d/b/a PublicDomainRegistry.com Suspended-Domain Financial Services, Healthcare, Energy, Real Estate, Technology, Construction & Engineering activatepasskeyportal[.]com 2026-06-12 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Technology, Energy assignpasskey[.]com 2026-06-13 Internet Domain Service BS Corp. DDOS-GUARD Construction & Engineering, Financial Services, Energy myconnectkey[.]com 2026-06-13 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Transportation, Financial Services, Construction & Engineering, Real Estate, Business Services, Retail & Consumer Goods, Healthcare mynewpasskey[.]com 2026-06-13 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Retail & Consumer Goods, Healthcare, Financial Services, Energy passkeycreate[.]com 2026-06-16 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering, Financial Services, Retail & Consumer Goods, Legal, Energy oskeyconnect[.]com 2026-06-17 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Real Estate, Legal, Healthcare, Transportation, Utilities, Construction & Engineering, Retail & Consumer Goods, Hospitality passkeycreator[.]com 2026-06-19 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Non-Corporate, Media & Entertainment, Legal, Healthcare, Energy, Technology oskeysync[.]com 2026-06-20 NICENIC INTERNATIONAL GROUP CO., LIMITED EZYDOMAIN Healthcare, Financial Services, Transportation, Real Estate, Technology, Construction & Engineering, Retail & Consumer Goods, Legal, Energy, Utilities, Hospitality enablepasskey[.]com 2026-06-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Legal enablepasskey2fa[.]com 2026-06-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Healthcare, Media & Entertainment checkpasskey[.]com 2026-06-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Legal, Construction & Engineering, Retail & Consumer Goods, Transportation passkeyuser[.]com 2026-06-25 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering, Legal, Aerospace & Defense, Financial Services, Technology keysyncos[.]com 2026-06-30 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Real Estate, Healthcare, Technology, Construction & Engineering, Transportation, Legal, Retail & Consumer Goods, Energy, Utilities, Hospitality myaccountsecurity[.]com 2026-06-30 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering addpasskey2fa[.]com 2026-07-01 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Financial Services, Legal passkeyenroll[.]com 2026-07-07 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services startpasskey[.]com 2026-07-07 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Construction & Engineering, Retail & Consumer Goods passkeyenable[.]com 2026-07-08 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Legal passkeyactivation[.]com 2026-07-09 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services createmfa[.]com 2026-07-09 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Construction & Engineering, Energy, Financial Services, Healthcare, Transportation passkeyhelpdesk[.]com 2026-07-10 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Financial Services, Energy, Healthcare makepasskey[.]com 2026-07-13 Internet Domain Service BS Corp. DDOS-GUARD N/A add-passkey[.]com 2026-07-13 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Healthcare, Energy passkey-check[.]com 2026-07-13 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Media & Entertainment addyourpasskey[.]com 2026-07-20 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services, Utilities passkey-enable[.]com 2026-07-20 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Aerospace & Defense, Technology mypasskeyid[.]com 2026-07-21 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Technology, Retail & Consumer Goods passkeystatus[.]com 2026-07-21 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Energy, Technology secure-passkey[.]com 2026-07-21 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Energy, Financial Services addssopasskey[.]com 2026-07-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Financial Services ssopasskey[.]com 2026-07-22 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare N/A createssopasskey[.]com 2026-07-28 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare / Private Layer Financial Services myssopasskey[.]com 2026-07-31 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services hubpasskey[.]com 2026-08-03 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services passkeymfa[.]com 2026-08-03 NICENIC INTERNATIONAL GROUP CO., LIMITED Cloudflare Financial Services Table 1: Indicators of compromise Network Infrastructure and Exfiltration Observables IP Address Role ASN 31.7.56.61 Panel AiTM Reverse Proxy AS51852 Private Layer INC (Switzerland) 31.7.56.52 Panel AiTM Reverse Proxy AS51852 Private Layer INC (Switzerland) 193.34.212.132 Phishing Kit Backend Proxy AS201814 MEVSPACE (Poland) 185.178.208.153 Phishing Reverse Proxy AS57724 DDOS-GUARD LTD (Russia) 23.234.75.84 Automated SaaS Data Exfiltration AS11878 Tzulo, Inc. (United States) 195.140.213.114 Automated SaaS Data Exfiltration AS25369 Hydra Communications Ltd (United Kingdom) 195.140.213.115 Automated SaaS Data Exfiltration AS25369 Hydra Communications Ltd (United Kingdom) 107.128.45.122 M365 / Okta Residential Proxy AS7018 AT&T Enterprises, LLC (United States) 76.103.148.180 M365 / Okta Residential Proxy AS7922 Comcast Cable Communications (United States) 38.42.59.171 M365 / Okta Residential Proxy AS395354 Starry, Inc. (United States) 47.218.103.146 M365 / Okta Residential Proxy AS19108 Optimum / Suddenlink (United States) Table 2: Network infrastructure and exfiltration observables Scripting and SDK User-Agent Strings python-requests/2.28.1 WindowsPowerShell/5.1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:146.0) Gecko/20100101 Firefox/146.0 0811A9866E.com.okta.android.auth/8.18.0 DeviceSDK/1.0.94 Android/16 Google/Pixel_9_Pro_XL Figure 6: Scripting and SDK user-agent strings Google Security Operations (SecOps) Detections Google SecOps customers have access to automated detection rules under the Okta and Microsoft 365 rule packs that identify the vishing, MFA modification, and programmatic streaming activity described in this report: Okta Admin Console Access Failure Okta Suspicious Actions from Anonymized IP Okta MFA Factor Setup Following Abandoned Challenge O365 SharePoint Bulk File Access or Download via PowerShell O365 SharePoint High Volume File Access Events O365 SharePoint Query for Proprietary or Privileged Information Okta User Authentication with Suspicious Behavioral Flags Acknowledgements Special thanks to researcher ZachXBT for assisting with cryptocurrency analysis.
Analysis Summary
# Threat Actor: UNC6671
## Attribution & Identity
* **Identification:** UNC6671 is a sophisticated threat group specialized in data theft and extortion.
* **Known Aliases/Associated Brands:** BlackFile (allegedly retired May 2026), Redact, Pink, Helix, and Falcon.
* **Status:** Active; currently operating under multiple diversified extortion fronts to compartmentalize operations and evade attribution.
## Activity Summary
Following the publicized "retirement" of the BlackFile brand in May 2026, UNC6671 shifted operations to several new Data Leak Sites (DLS). Despite claims of an internal rift or "hijacking" by a rogue affiliate (the pretext for the Redact rebrand), infrastructure analysis confirms that the same core group continues to operate across these disparate brands. Recent campaigns involve high-tempo provisioning of phishing infrastructure (averaging one domain every 1.6 days) to support vishing-led credential harvesting and subsequent cloud environment exfiltration.
## Tactics, Techniques & Procedures
* **Initial Access:** Highly tailored Voice Phishing (vishing) targeting employees on personal mobile devices, posing as IT helpdesk staff.
* **Pretext:** Mandatory/urgent security migrations, specifically the enablement of FIDO2 passkeys or MFA updates.
* **Credential Harvesting:** Use of Adversary-in-the-Middle (AiTM) phishing panels to intercept credentials and MFA tokens in real-time.
* **Persistence & Evasion:**
* Initiating password resets for non-SSO applications.
* Systematic deletion of security notifications and alerts from victim inboxes to hide activity.
* Use of residential proxy pools (AT&T, Comcast, etc.) to blend with legitimate employee traffic.
* **Data Exfiltration:** Automated scripting (Python, PowerShell) to rapidly exfiltrate data from SaaS environments like Microsoft 365 (SharePoint) and Okta.
* **Extortion:** Multi-stage negotiations; initial demands range from $1M–$3M USD, often settled for ~$750k USD via Bitcoin.
## Targeting
* **Sectors:**
* *Early 2026:* Manufacturing, Real Estate, Healthcare, Insurance.
* *Mid 2026:* Technology, Transportation, Hospitality (focus on IP and VIP data).
* *Recent (July 2026):* Financial Services, Private Equity, Legal, and Financial Rating Agencies (focus on M&A and litigation data).
* **Geography:** Primarily North America and Europe, indicated by the targeting of major Western enterprise verticals and the use of Western residential ISP proxies.
## Tools & Infrastructure
* **Infrastructure:**
* **Root Phishing Domains:** `passkeyhelpdesk[.]com`, `portalpasskey[.]com`, `addssopasskey[.]com`, `setupsso[.]com`, `idokta[.]com`, `passkeydeploy[.]com`, `oskeysync[.]com`.
* **Hosting/CDNs:** Heavy reliance on Cloudflare and DDOS-GUARD.
* **Network Nodes:**
* `31[.]7[.]56[.]61` (AiTM Reverse Proxy)
* `185[.]178[.]208[.]153` (Phishing Proxy)
* `23[.]234[.]75[.]84` (Exfiltration Server)
* **User-Agents:** `python-requests/2.28.1`, `WindowsPowerShell/5.1`, `0811A9866E.com.okta.android.auth/8.18.0`.
## Implications
UNC6671 demonstrates the "fluidity of branding," where a single threat group operates under multiple names to confuse investigators and insurance negotiators. Their shift toward financial services and private equity indicates a strategic move to target high-leverage data (M&A, capital deployment) to maximize extortion success. Their ability to bypass MFA via AiTM and vishing makes them a high-tier threat to identity-centric security models.
## Mitigations
* **Phishing-Resistant MFA:** Enforce FIDO2-compliant keys or platform authenticators (Windows Hello, Okta FastPass) to defeat AiTM proxies.
* **Session Hardening:** Implement short session lengths, idle timeouts, and IP session binding.
* **Managed Devices:** Restrict authentication to corporate-managed endpoints with verified MDM/EDR states.
* **Network Restrictions:** Use Conditional Access policies to block logins from residential proxy pools or unauthorized geographic regions.
* **Monitoring:** Audit logs for "MFA registration following authentication failure" patterns and high-volume `FileAccessed` events via non-standard User-Agents (scripting libraries).