Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Threat Actor Expansion: The Continuing Evolution of UNC6671's Extortion Scheme


Threat Actor Expansion: The Continuing Evolution of UNC6671's Extortion Scheme

  • UNC6671 is a sophisticated threat actor conducting extensive operations across multiple domains.
  • The group has diversified its operations, using multiple extortion fronts, including Redact, Pink, Helix, and Falcon.
  • The attackers use voice phishing (vishing) tactics to contact employees on their personal mobile devices.
  • The actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta.
  • GTIG observed a regular shift in target selection towards organizations holding sensitive information.
  • The group leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels.
  • The threat actor increasingly relies on defense evasion tactics to maintain account-level persistence and conceal its operations.



  • The threat landscape continues to evolve at an alarming rate, with new actors and tactics emerging every day. In recent times, Google Threat Intelligence Group (GTIG) has been tracking a particularly sophisticated threat actor known as UNC6671. This group has been conducting extensive operations across multiple domains, including financial services, healthcare, manufacturing, media and entertainment, public sector, retail, supply chain, telecommunications, and more.

    In May 2026, GTIG initially reported on the activity of UNC6671, which was then attributed to a rebranded BlackFile extortion group. However, further analysis revealed that this initial assertion was incorrect, and the group had actually diversified its operations across multiple extortion fronts, including Redact, Pink, Helix, and Falcon.

    These different brands operate under various pretext messages, such as an urgent helpdesk mandate or an offer of a free passkey to boost security. The attackers often contact employees on their personal mobile devices, using voice phishing (vishing) tactics. These calls lure victims to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens.

    Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta. The root domains used by UNC6671 are often generic and masquerade as being related to passkeys, appending victim-specific subdomains to facilitate targeted voice phishing campaigns.

    The same phishing templates were used across all these domains, with identical code and design hosted simultaneously on different websites. For instance, while addssopasskey[.]com was strictly used to target organizations later extorted by Falcon, the identically configured passkeyhelpdesk[.]com domain was simultaneously used to target two entirely separate victims—one of which was claimed by Falcon, and the other by Helix.

    GTIG observed that UNC6671’s domain registration patterns demonstrate a regular shift in target selection, seemingly towards those that are more likely to hold sensitive information. The group leverages subdomains that incorporate prospective victim names to host tailored credential harvesting panels. Their root domains mimic enterprise authentication enrollment portals pairing terms as "passkey," "mfa," or "sso" paired with verbs.

    The observed subdomains in the following months appeared to represent a progression in UNC6671’s extortion model. In June 2026, targeting transitioned toward large technology, transportation, and hospitality organizations, seemingly focusing on entities holding valuable intellectual property, software source code, or sensitive VIP client data. By July 2026, the target profile narrowed to focus on the financial and legal sectors, with observed infrastructure directed at private equity firms, law firms, and financial rating agencies.

    The threat actor increasingly relies on defense evasion to maintain account-level persistence and conceal its operations. In recent intrusions, the group used compromised email accounts to initiate unauthorized password resets for non-SSO enterprise applications. To prevent end-user detection or automated security alerts, operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.

    GTIG also observed that the tactics across UNC6671 intrusions have been largely consistent; however, they have noticed several new techniques. IT Helpdesk and Passkey Pretexts involve calling targeted employees on their personal mobile numbers, spoofing legitimate helpdesk phone numbers, and directing them to lookalike credential-harvesting subdomains.

    EvasionTechniques include the use of compromised email accounts for unauthorized password resets, systematically deleting security-related notifications, and using defense evasion tactics such as deleting temporary files or modifying system logs. Ransom Negotiations and Blockchain Analysis indicate that ransom payments continued past the publicized Blackfile data leak site shutdown notice on May 11, 2026.

    The final verdict of this report is that the threat actor expansion observed in UNC6671’s extortion scheme likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes, and isolate any negotiation fallout. Regardless of whether this activity reflects a fractured threat group, outsourced extortion negotiators, or a broader affiliate network, the initial infection vector leveraged and goals of these campaigns is consistent.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Threat-Actor-Expansion-The-Continuing-Evolution-of-UNC6671s-Extortion-Scheme-ehn.shtml

  • https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/


  • Published: Thu Aug 6 13:14:07 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us