Full Report
A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their
Analysis Summary
Based on the article provided, here is a structured summary of the threat actor UNC6671.
# Threat Actor: UNC6671
## Attribution & Identity
* **Name/Alias:** UNC6671
* **Associated Groups/Aliases:**
* **Cordial Spider** (CrowdStrike tracking name)
* **Bling Libra / ShinyHunters** (Shares similar tradecraft, though assessed to be acting independently)
* **Extortion Brands:** Redact, Pink (CL-CRI-1147), Helix, Falcon (CL-CRI-1182), and the retired BlackFile (CL-CRI-1116).
## Activity Summary
UNC6671 is a high-cadence data extortion group that emerged in early 2026. The group specialized in vishing (voice phishing) and SSO compromise. After the retirement of their "BlackFile" brand in May 2026, the group diversified into multiple new brands (Redact, Pink, Helix, Falcon) to continue their extortion operations against enterprise cloud environments.
## Tactics, Techniques & Procedures
* **Vishing (Voice Phishing):** Impersonating IT help desk staff during phone calls to enterprise employees, often targeting personal mobile devices to bypass corporate filters.
* **Social Engineering:** Creating a false sense of urgency regarding security migrations or account issues.
* **Adversary-in-the-Middle (AitM):** Using spoofed login portals to intercept credentials and MFA tokens in real-time.
* **MFA Manipulation:** Registering adversary-controlled MFA devices to compromised accounts and removing legitimate user devices to maintain persistence.
* **Cloud Data Exfiltration:** Deploying automated Python and PowerShell scripts to pull data from SaaS applications (Microsoft 365, Okta).
* **MITRE ATT&CK IDs (Inferred):**
* T1566.004 (Phishing: Voice)
* T1557 (Adversary-in-the-Middle)
* T1098.005 (Account Manipulation: Device Registration)
* T1567 (Exfiltration Over Web Service)
## Targeting
* **Sectors:** Financial services, private equity, professional services, and hedge funds.
* **Geography:** North America, Australia, and the United Kingdom.
* **Victims:** Major Wall Street hedge funds and various enterprise organizations (specific names not disclosed in text).
## Tools & Infrastructure
* **Malware/Scripts:** Automated Python and PowerShell scripts for data theft.
* **Platforms Targeted:** Microsoft 365, Okta, and various Identity Providers (IdP).
* **Infrastructure:**
* Adversary-in-the-Middle (AitM) proxy frameworks.
* Data Leak Sites (DLS) associated with brands like BlackFile, Redact, and Pink.
* *Note: Specific C2 IPs or URLs were not provided in the source text for defanging.*
## Implications
UNC6671 demonstrates that even organizations with MFA can be compromised through sophisticated social engineering. By targeting the Identity Provider (IdP), the actor gains a "single point of entry" to all connected SaaS applications, allowing for rapid and large-scale data exfiltration. Their high operational cadence and ability to rebrand quickly suggest a highly organized and resilient criminal collective.
## Mitigations
* **Phishing-Resistant MFA:** Transitioning from SMS or push-based MFA to hardware security keys (e.g., FIDO2/WebAuthn) to prevent AitM interception.
* **Employee Awareness:** Specialized training regarding "IT help desk" vishing calls, specifically those targeting personal devices.
* **Conditional Access Policies:** Implementing strict location-based or device-compliance-based access controls for SaaS platforms.
* **Monitoring:** Auditing the registration of new MFA devices and unusual automated activity within cloud environments (e.g., rapid file downloads via PowerShell/Python).