Listen to this Post

Introduction, A New Era of Social Engineering
Cybercriminals are no longer relying solely on malware or software vulnerabilities to compromise corporate networks. Instead, they are increasingly exploiting the weakest link in every organization, human trust. One of the most sophisticated examples of this evolution is the cybercrime group tracked by Google Threat Intelligence Group (GTIG) as UNC6671, an organization that has reinvented itself several times under names including Redact, Pink, Falcon, Helix, and previously BlackFile.
Rather than launching noisy ransomware attacks, this group specializes in convincing employees to willingly surrender their credentials during carefully orchestrated voice phishing campaigns. Their victims include some of the world’s largest private equity firms, financial institutions, investment companies, and legal organizations. Their success has reportedly generated millions of dollars in ransom payments while leaving many victims unwilling to publicly admit they were compromised.
This campaign demonstrates how modern cybercrime has become a blend of psychology, automation, cloud abuse, and financial extortion, making it one of the most dangerous enterprise threats observed in recent years.
How the Attack Campaign Works
According to Google Threat Intelligence Group, UNC6671 continues operating aggressively despite the public retirement of its former BlackFile extortion brand in May 2026.
Instead of disappearing, investigators discovered that the attackers simply expanded under multiple identities including Redact, Pink, Helix, and Falcon. Although the names changed, their infrastructure, operational style, and attack methodology remained nearly identical.
This indicates that the rebranding was intended to confuse investigators rather than end criminal operations.
Targeting the
The attackers created fake credential-harvesting websites specifically customized for hundreds of organizations.
Among the targeted companies were major financial institutions such as:
Blackstone
Bridgewater Associates
Apollo Global Management
Bain Capital
KKR
TPG
CME Group
Clearlake Capital
Moody’s
The campaign also expanded beyond finance, targeting technology companies, law firms, and major corporations including Uber, Zillow, Levi Strauss, Point72 Asset Management, Two Sigma Investments, Citadel, Paul Hastings, and Greenberg Traurig.
The breadth of the operation illustrates a carefully planned campaign aimed at organizations capable of paying large extortion demands.
The Voice Phishing Strategy
Unlike traditional phishing emails, UNC6671 relies heavily on voice phishing, commonly known as vishing.
Employees receive phone calls directly on their personal mobile devices from individuals pretending to be members of the corporate IT helpdesk.
In several incidents, the attackers spoofed legitimate corporate support phone numbers, making the calls appear authentic.
The criminals claimed that urgent security migrations required immediate action.
Victims were instructed to visit websites that closely resembled official company authentication portals.
The fake domains often followed convincing naming conventions such as:
company.createssopasskey.com
company.addssopasskey.com
Employees believed they were enabling new security features such as FIDO2 passkeys or updating multi-factor authentication enrollment.
Instead, they unknowingly handed over their corporate credentials.
Real-Time Credential Theft
The sophistication of the operation extends far beyond simple phishing pages.
After victims entered their username and password, attackers remained on the phone while requesting the one-time authentication code generated by MFA.
This allowed them to authenticate into corporate accounts before the code expired.
Within seconds:
Username stolen
Password collected
MFA code captured
Session established
Corporate account compromised
By the time the employee hung up the phone, the attackers had already gained full access.
Many victims reportedly remained unaware that anything suspicious had occurred.
Erasing the Evidence
One particularly dangerous aspect of
Once inside cloud accounts, the attackers immediately searched for:
Password reset notifications
Security alert emails
Login warning messages
Authentication notifications
These alerts were deleted before employees noticed them.
This dramatically delayed detection and gave attackers valuable time to continue their operations.
Cloud Services Become Primary Targets
The attackers focused heavily on cloud identity providers and productivity platforms.
Among their primary objectives were:
Microsoft 365
Okta
Using automated tools, they rapidly collected:
Corporate emails
Internal documents
Financial records
Authentication information
Sensitive cloud data
Because modern enterprises centralize enormous amounts of information in cloud platforms, compromising a single identity often grants access to multiple systems.
Why Financial Companies Were Chosen
Financial organizations remain among the most attractive ransomware and extortion targets.
They possess:
Confidential investment strategies
Merger documents
Legal agreements
Customer financial information
Regulatory communications
Intellectual property
Rather than encrypting systems immediately, UNC6671 frequently focused on stealing sensitive information first.
The threat of public disclosure often proved more profitable than operational disruption.
Millions in Ransom Revenue
Google researchers tracked 18 Bitcoin wallets connected to the BlackFile operation between January and May 2026.
Those wallets reportedly received:
141.65 BTC
Approximately $10.69 million
Interestingly, payments continued even after BlackFile publicly announced its shutdown.
Investigators believe this demonstrates that the criminal infrastructure never actually ceased operations.
Instead, the attackers simply shifted branding while maintaining identical financial operations.
Negotiated Extortion
UNC6671 typically demanded between $1 million and $3 million per victim.
However, negotiations frequently resulted in discounts ranging between 50% and 75%.
Researchers estimate that more than half of tracked victims ultimately paid.
Average payments were approximately $750,000.
Whether additional organizations quietly paid remains unknown because most victims refuse public disclosure.
More Than 200 Companies Targeted
Reuters independently examined dozens of malicious domains identified by Google.
Using threat intelligence services including DomainTools and urlscan, researchers linked the fake websites to over 200 companies during only a five-week period.
Not every intrusion succeeded.
However, the sheer scale demonstrates industrialized phishing infrastructure capable of rapidly generating customized credential harvesting portals for virtually any organization.
Corporate Silence Benefits Attackers
Most organizations contacted regarding the attacks declined to comment.
Some never responded.
Greenberg Traurig stated that its security controls prevented any data breach.
Point72 Asset Management confirmed that it had been targeted.
For many other organizations, the public may never know whether attacks succeeded.
This lack of transparency continues to benefit cybercriminals because victims often prioritize reputation management over public disclosure.
The Mystery Behind Multiple Criminal Brands
One of the most confusing aspects of this campaign involves the relationship between Redact, Falcon, Pink, and Helix.
Redact publicly stated that its members were “not politically or morally motivated,” effectively confirming financial profit as the sole objective.
Falcon acknowledged connections with Redact while denying involvement with Helix or Pink.
Despite these claims, investigators continue observing overlapping infrastructure, similar phishing domains, identical techniques, and consistent operational patterns.
Whether these are separate criminal organizations or divisions within one larger operation remains uncertain.
Deep Analysis
Technical Indicators of the Attack Chain
The campaign illustrates a classic identity-based intrusion rather than malware deployment.
Example workflow:
Phone Call
│
▼
Victim Trusts Fake IT Support
│
▼
Fake Passkey Website
│
▼
Credential Submission
│
▼
Live MFA Capture
│
▼
Cloud Account Access
│
▼
Data Exfiltration
│
▼
Extortion
Investigating Suspicious Authentication Logs
Example Microsoft 365 PowerShell:
Get-AzureADAuditSignInLogs
Review conditional access policies:
Get-AzureADMSConditionalAccessPolicy
Export Azure sign-in events:
Get-MgAuditLogSignIn
Search for mailbox forwarding rules:
Get-InboxRule
Review recent password changes:
Get-MgUserAuthenticationMethod
Check unusual login locations:
grep "Impossible Travel" security.log
Review authentication failures:
journalctl | grep authentication
Inspect DNS requests:
tcpdump -i any port 53
Search for suspicious domains:
whois suspicious-domain.com
Verify TLS certificates:
openssl s_client -connect suspicious-domain.com:443
Investigate phishing URLs:
curl -I https://example-phishing-site.com
These commands help security teams validate authentication events, identify compromised identities, and investigate suspicious infrastructure associated with cloud-focused phishing campaigns.
What Undercode Say
Identity Has Become the New Perimeter
Traditional cybersecurity focused on protecting devices and networks. Today’s attackers increasingly bypass technical defenses by targeting human behavior. UNC6671 demonstrates that compromising one employee can provide broader access than exploiting dozens of software vulnerabilities.
Voice Phishing Is Rapidly Maturing
Many organizations invest heavily in email filtering but underestimate voice-based attacks. Attackers understand that hearing a confident “IT technician” on the phone creates urgency that bypasses skepticism. This campaign shows that telephone-based social engineering deserves the same level of defensive investment as email security.
Passkeys Alone Are Not a Complete Defense
Although passkeys improve authentication security, they cannot protect users who are tricked into interacting with fraudulent enrollment portals. Organizations must ensure employees understand when and how legitimate passkey enrollment occurs.
Cloud Identity Is the Primary Target
Microsoft 365 and Okta have become central hubs for enterprise operations. Compromising these platforms provides access to email, collaboration tools, documents, and identity management. Defending cloud identities should now be considered a board-level security priority.
Rebranding Helps Criminals Evade Attention
Changing names from BlackFile to Redact, Falcon, Pink, and Helix does not change the underlying operation. Threat intelligence should focus on infrastructure, tactics, and procedures rather than branding alone.
Deleting Security Notifications Is a Clever Tactic
Many compromises are discovered because users notice login alerts. Removing those alerts extends attacker dwell time significantly. Security teams should implement independent monitoring that does not rely solely on user notifications.
Financial Institutions Remain Premium Targets
Investment firms, private equity groups, and law firms possess information that can influence markets and negotiations. Even without ransomware deployment, stolen documents alone can generate substantial leverage for extortion.
Security Awareness Must Include Personal Devices
Because attackers called employees on personal mobile phones, traditional corporate call monitoring offered little protection. Organizations should prepare employees for attacks that originate outside company-controlled communication channels.
Customized Infrastructure Signals Significant Resources
Building hundreds of company-specific phishing domains within weeks requires automation, planning, and infrastructure investment. This is no longer the work of isolated criminals but of organized cybercrime enterprises operating like legitimate businesses.
Incident Response Needs Faster Identity Detection
Organizations should continuously monitor unusual authentication patterns, impossible travel events, rapid MFA enrollments, and privilege escalation. The speed of these attacks leaves little room for manual response.
The Future Will Bring AI-Enhanced Vishing
As voice synthesis technology improves, future campaigns may use AI-generated voices that closely mimic executives or IT staff. Combining artificial intelligence with social engineering could dramatically increase success rates if organizations fail to adapt.
Prediction
(+1) Defensive Technologies Will Shift Toward Identity Intelligence 📈
Identity-centric security platforms will become a primary investment across financial institutions. Organizations are expected to adopt phishing-resistant authentication, behavioral analytics, continuous verification, and AI-assisted anomaly detection to reduce the effectiveness of sophisticated voice phishing campaigns. Increased employee awareness training and stronger cloud identity monitoring should gradually improve resilience against attacks like those conducted by UNC6671.
✅ Confirmed: Google Threat Intelligence Group has publicly documented UNC6671’s continued operations, linking the group to multiple extortion brands and ongoing voice phishing campaigns.
✅ Confirmed: The campaign relied on fake passkey and MFA enrollment websites, live credential harvesting, and cloud service targeting, particularly Microsoft 365 and Okta, consistent with published threat intelligence.
✅ Partially Confirmed: While blockchain analysis identified Bitcoin wallets associated with the operation and ransom payments totaling millions of dollars, the identities of many victim organizations and the exact number of successful breaches remain undisclosed, meaning some operational details cannot be independently verified publicly.
▶️ Related Video (76% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




