BlackFile Reborn as Redact: How a Vishing Extortion Network Is Expanding Through AI-Era Social Engineering Attacks + Video

Listen to this Post

Featured Image

Introduction: The New Face of Enterprise Extortion

Cybercrime groups are no longer relying only on ransomware encryption or traditional malware attacks. The modern threat landscape has shifted toward psychological manipulation, identity theft, and cloud compromise. One of the latest examples is the evolution of the BlackFile extortion operation, a cybercriminal group that has transformed its public identity while keeping the same dangerous attack methods.

According to research from the Google Threat Intelligence Group (GTIG), the group previously known as BlackFile has rebranded itself as Redact, while related operations have continued under additional names including Pink, Helix, and Falcon. The investigation suggests that these brands are not independent groups but likely connected operations sharing infrastructure, phishing templates, and technical resources.

The transformation demonstrates a growing trend in cybercrime: when one criminal brand becomes exposed, operators do not necessarily disappear. Instead, they often rebuild under a new identity, restructure their affiliate networks, and continue targeting organizations with improved deception techniques.

BlackFile’s Rebrand: A Criminal Identity Transformation

The BlackFile extortion group announced that it was retiring its original brand in 2026, claiming that the decision was caused by an internal dispute involving a rogue affiliate.

The group later introduced a new data leak site (DLS) under the name Redact, claiming that the original BlackFile identity had been compromised and hijacked by a former affiliate.

According to the group’s own statements, an unauthorized actor allegedly created a fake BlackFile leak platform, conducted independent extortion campaigns, and used disconnected communication identities to operate without approval.

However, GTIG researchers found evidence suggesting that the rebrand was not simply an internal conflict. Instead, the activity appeared connected to a broader ecosystem of extortion brands sharing common technical foundations.

The investigation connected BlackFile, Redact, Pink, Helix, and Falcon through overlapping infrastructure, identical phishing materials, and similar victim targeting strategies.

The Rise of Vishing-Based Extortion Attacks

Traditional ransomware attacks usually begin with malicious attachments, vulnerable systems, or stolen credentials purchased from underground markets. BlackFile’s approach represents a more advanced method: voice phishing, also known as vishing.

In these attacks, criminals impersonate corporate IT support employees and contact workers directly by phone.

The attackers create a believable emergency scenario, such as:

Mandatory security upgrades

MFA enrollment changes

FIDO2 passkey migration

Identity verification procedures

Corporate account protection requirements

The victim is pressured into following instructions quickly, reducing the chance that they will question the legitimacy of the request.

The attackers then direct employees to fake login portals designed to steal usernames, passwords, authentication tokens, and active cloud sessions.

Deep Analysis: How UNC6671 Compromises Enterprise Environments

The BlackFile/Redact operators rely heavily on identity-based attacks rather than traditional malware deployment.

Their attack chain generally follows this structure:

1. Initial Contact Through Voice Social Engineering

Attackers research employees through public sources and organizational information.

They select individuals who are likely to have access to important cloud resources.

Example reconnaissance commands attackers may use:

whois target-company.com
nslookup target-company.com

subfinder -d target-company.com

These tools help attackers discover domains, infrastructure, and possible employee information.

2. Fake Helpdesk Communication

The attacker contacts the employee while pretending to represent internal IT teams.

The conversation usually creates urgency:

Your account requires immediate migration.

Your MFA settings must be updated today.

Your security token is expiring.

The goal is not technical exploitation but human manipulation.

3. Adversary-in-the-Middle Credential Theft

The victim receives a link leading to a fake authentication portal.

These pages imitate legitimate enterprise services.

Common examples include:

Microsoft 365 login pages

Okta authentication portals

Corporate VPN systems

The attacker uses AiTM frameworks to capture:

Passwords

MFA tokens

Session cookies

Example defensive investigation:

grep -r "login.microsoftonline" /var/log/
grep -r "suspicious-domain.com" /var/log/auth.log
4. Cloud Data Theft

Once access is obtained, attackers automate data collection from cloud platforms.

Targets include:

Microsoft 365 mailboxes

SharePoint documents

OneDrive storage

Okta-managed applications

Example defensive cloud monitoring:

Get-AzureADAuditSignInLogs
Get-MgAuditLogSignIn

Organizations should monitor unusual login locations, impossible travel events, and suspicious OAuth applications.

Shared Infrastructure Reveals Connected Extortion Brands

One of the strongest indicators linking these groups together is infrastructure reuse.

GTIG researchers discovered that multiple extortion brands used similar root domains, including domains such as:

passkeyhelpdesk[.]com

passkeydeploy[.]com

These domains were used against different organizations under different criminal identities.

The same phishing templates appeared across campaigns attributed to separate groups.

This suggests that the criminals are not operating isolated businesses but instead maintaining a shared attack ecosystem.

The use of multiple brands provides several advantages:

Reduces public attention on one name

Makes law enforcement tracking harder

Allows affiliates to continue operations

Creates confusion during investigations

Helps hide the total number of victims

New Attack Techniques Used by UNC6671

The threat group has continued improving its methods.

One notable technique involves spoofing legitimate helpdesk phone numbers.

Instead of calling from unknown numbers, attackers can make calls appear to originate from trusted corporate support lines.

This increases the probability that employees will comply.

Another technique involves abusing compromised email accounts.

Attackers may:

Reset passwords

Remove security notifications

Delete warning emails

Maintain persistent access

By controlling both email and identity systems, criminals can remain hidden for extended periods.

Victim Targeting Changes: From Manufacturing to Finance

GTIG observed that UNC6671 adjusted its targeting strategy throughout 2026.

During the early months, the group focused heavily on:

Manufacturing companies

Real estate organizations

Healthcare providers

Insurance companies

Later, the attackers shifted toward:

Technology firms

Transportation companies

Hospitality organizations

By July, the focus moved toward high-value targets including:

Private equity firms

Law firms

Credit rating organizations

This evolution indicates that the group is becoming more selective.

Rather than attacking random companies, the criminals appear to prioritize organizations where stolen information has higher extortion value.

The Financial Impact of BlackFile Operations

GTIG analysis identified 18 Bitcoin wallet addresses connected to BlackFile campaigns.

Between January 7 and May 12, these wallets received approximately:

141.65 BTC

At the time of transactions, this represented roughly:

$10.69 million USD

This financial activity demonstrates that the operation was not a small criminal experiment.

The group had established a profitable extortion model capable of generating millions of dollars.

Defensive Strategies Against Vishing Extortion Campaigns

Organizations must recognize that cybersecurity is no longer only about protecting servers.

Employees themselves have become primary targets.

Recommended protections include:

Enforce Phishing-Resistant Authentication

Traditional MFA methods such as SMS codes are vulnerable.

Organizations should adopt:

FIDO2 security keys

Passkeys

Hardware-based authentication

Strengthen Identity Monitoring

Security teams should monitor:

Suspicious login locations

New devices

Abnormal authentication patterns

Unusual password resets

Control Session Access

Companies should reduce the lifespan of authentication sessions.

Recommended controls:

Short session expiration

Conditional access policies

Trusted network restrictions

Protect Personal Devices

Because attackers often target employees through personal phones, companies should ensure that sensitive authentication happens only through managed devices.

Security tools should include:

Mobile Device Management (MDM)

Endpoint Detection and Response (EDR)

Device compliance checks

What Undercode Say:

The BlackFile-to-Redact transformation represents a major shift in how modern cybercriminal organizations operate.

Cybercrime groups are becoming more similar to traditional businesses.

They create brands, recruit affiliates, manage communication channels, and develop specialized infrastructure.

A criminal group disappearing does not always mean the threat is gone.

Rebranding has become a survival strategy.

Attackers understand that reputation damage is temporary if the infrastructure remains operational.

Identity theft has become one of the most valuable attack methods.

A stolen password can sometimes provide more access than a malware infection.

Cloud platforms have increased productivity but also expanded the attack surface.

Microsoft 365 and Okta accounts have become prime targets because they connect to entire corporate ecosystems.

Social engineering is becoming more sophisticated because humans remain the weakest security layer.

The BlackFile campaign demonstrates that technical defenses alone are insufficient.

Organizations must train employees to recognize psychological manipulation.

Attackers no longer need to break through security walls if they can convince employees to open the door.

AI technology may further improve these campaigns.

Future attackers could use AI-generated voices, personalized scripts, and automated reconnaissance.

A convincing phone conversation may soon become as dangerous as a malicious attachment.

The reuse of phishing templates shows that criminal groups are sharing resources.

The cybercrime economy is becoming more collaborative.

Different ransomware brands may actually represent different marketing identities of the same operation.

Security researchers must focus on infrastructure relationships instead of only tracking names.

Domain reuse remains one of the strongest indicators of criminal connections.

Companies should assume that attackers may already know employee names, roles, and organizational structures.

The future of cyber defense will depend heavily on identity protection.

Password security alone is no longer enough.

Session security, device trust, and behavioral analytics are becoming essential.

Employees working remotely create additional opportunities for attackers.

Personal devices create a bridge between private life and corporate access.

Criminal groups are increasingly targeting this bridge.

The financial success of BlackFile proves that extortion remains highly profitable.

Millions of dollars encourage criminals to continuously improve.

Security teams must treat social engineering campaigns as serious incidents.

Vishing attacks should receive the same attention as ransomware events.

The combination of voice manipulation and cloud theft creates a dangerous hybrid threat.

Organizations should conduct realistic phishing and vishing simulations.

Security awareness training must evolve beyond simple email examples.

Modern employees need to understand identity-based attacks.

Criminal rebranding will continue because it helps avoid reputation loss.

Threat intelligence sharing will become increasingly important.

Collaboration between security companies is necessary to track these flexible criminal networks.

The BlackFile case shows that the next generation of cyber attacks will target trust itself.

✅ Confirmed: BlackFile rebranded into Redact according to GTIG research.
The Google Threat Intelligence Group identified connections between BlackFile and Redact operations, including infrastructure and operational similarities.

✅ Confirmed: The group uses vishing and AiTM techniques.
Researchers documented campaigns where attackers impersonated IT support personnel and harvested credentials through fake authentication portals.

✅ Confirmed: Multiple extortion brands share infrastructure.

The overlap between BlackFile, Pink, Helix, and Falcon suggests coordinated operations rather than completely separate groups.

❌ Unconfirmed: The affiliate conflict explanation is entirely accurate.
The group claimed a rogue affiliate caused the original shutdown, but researchers indicate that the situation may involve broader operational restructuring.

Prediction

(+1) Cybersecurity companies will increasingly develop stronger identity protection systems as attackers move away from traditional malware toward social engineering and cloud compromise.

(+1) Phishing-resistant authentication methods such as passkeys and FIDO2 will become standard requirements for enterprise security.

(+1) Threat intelligence platforms will focus more on tracking infrastructure connections between criminal brands rather than individual hacker groups.

(-1) Criminal organizations will likely continue creating new identities after exposure, making attribution and disruption more difficult.

(-1) AI-generated voice attacks may increase the effectiveness of vishing campaigns, creating new challenges for employee verification.

(-1) Organizations that rely only on traditional MFA methods may remain vulnerable to advanced identity-based attacks.

Final Thoughts: The Future Battle Will Be Over Digital Trust

The BlackFile and Redact evolution highlights a critical reality: cybersecurity is no longer only a battle between software and malware.

It is a battle over trust.

Attackers are learning how employees think, how companies operate, and how digital identities connect everything together.

The organizations that succeed will not only deploy stronger technology but also build stronger security cultures where every employee understands that a convincing voice, message, or login page can become the beginning of a major cyber incident.

▶️ Related Video (76% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.infosecurity-magazine.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube