Google Links UNC6671 to Multiple Extortion Brands After BlackFile’s Apparent Retirement
- Threat evolution: GTIG says UNC6671 continued operating after the apparent retirement of BlackFile by rebranding into Redact, Pink, Helix, and Falcon.
- Attack method: The group uses IT helpdesk voice phishing (vishing) and Adversary-in-the-Middle (AiTM) phishing to steal Microsoft 365 and Okta credentials.
- Financial trail: Google’s threat intelligence tracked 141.65 Bitcoin (BTC) across 18 BlackFile-linked wallets.
UNC6671 remained active after the apparent retirement of the BlackFile extortion brand, instead expanding its operations under several new names such as Redact, Pink, Helix, and Falcon, indicating that the same threat cluster is likely behind all five brands.
Google Threat Intelligence Group (GTIG), working with Mandiant, has published new research that identifies operational links between the clusters, concluding that the threat actor diversified its infrastructure and branding rather than ceasing operations.
GTIG Connects BlackFile, Redact, Pink, Helix, and Falcon
According to GTIG, the transition became publicly visible on June 27, 2026, when operators behind Redact claimed the original BlackFile brand had been compromised by an exiled affiliate.
Despite that statement, Google's investigation found significant overlaps in phishing templates, victim selection, infrastructure, and operational techniques across the different brands. Those shared characteristics led GTIG to assess that the campaigns are linked to a common group of operators rather than representing separate threat actors.
UNC6671 Uses Vishing and AiTM to Target Microsoft 365 and Okta
The report says UNC6671 primarily gains initial access through voice phishing (vishing) campaigns in which attackers impersonate internal IT helpdesk personnel. Victims are often contacted on their personal mobile phones and told they need to complete an urgent security migration or account update.
During these calls, users are directed to spoofed authentication portals that employ AiTM techniques to capture usernames, passwords, and multi-factor authentication (MFA) tokens. Once authenticated, automated scripts are used to access and exfiltrate data from Microsoft 365 and Okta environments.
More Than $10 Million in Bitcoin Linked to BlackFile
As part of the investigation, GTIG analyzed 18 Bitcoin wallets associated with BlackFile between January 7 and May 12, 2026, identifying incoming payments totaling 141.65 BTC, valued at approximately $10.69 million during the analysis period. Cryptocurrency researcher ZachXBT assisted with the blockchain investigation.
To reduce the risk of similar attacks, GTIG recommends:
- deploying phishing-resistant authentication, including FIDO2 security keys,
- Integrate SaaS Applications and Cloud Platforms with single sign-on (SSO),
- Enforce session controls,
- Restrict authentication to trusted network sources,
- Monitor IdP logs for abandoned challenge patterns,
- Audit UAL telemetry for direct stream exfiltration,
- Restrict and alert on residential proxy authentication.
In a July report, Palo Alto Networks Unit 42 said the Pink extortion group, linked to UNC6671 and The Com, uses vishing and fake helpdesk calls to target enterprise data. In February, Europol announced 30 arrests and over 170 identifications related to The Com.
GTIG tracks distinct threat clusters UNC6671, UNC6661, and UNC6240 in a February report on ShinyHunters extortion tactics, vishing, and SSO compromise targeting cloud environments to harvest credentials and MFA codes.
In other recent news, a new AiTM campaign bypasses MFA across US, Canadian, and European firms via fake voicemail.







