UNC6671 is a financially motivated cybercrime and data-extortion cluster, formerly associated with the BlackFile brand. It has operated through or been linked to multiple extortion brands, including BlackFile, Redact, Pink, Helix, and Falcon; CORDIAL SPIDER is also used as a tracking designation. The cluster’s use of multiple brands and separate leak sites is assessed to support operational compartmentalization, although the precise relationships among all branded operations and possible affiliates are not fully established. UNC6671 primarily obtains initial access through voice phishing. Operators impersonate corporate IT or help-desk staff, often contact employees on personal phones, spoof help-desk telephone numbers, and use urgent passkey, MFA, SSO-migration, or account-recovery pretexts. Victims are directed to tailored adversary-in-the-middle authentication portals that capture credentials, MFA approvals, and authenticated session material; device-code phishing has also been associated with the cluster. The group replays stolen sessions, including through residential proxy services, to access Microsoft 365, Okta, and other SaaS environments. Following compromise, UNC6671 conducts cloud and identity reconnaissance, enumerates accessible applications and data, and may register attacker-controlled authentication methods to retain access. It automates collection from SharePoint, OneDrive, Exchange Online, and other cloud services, including SaaS platforms accessible through compromised identity sessions. Operators have suppressed password-reset and security-warning notifications to reduce detection. The group’s extortion model centers on theft of cloud-hosted information and threats of public disclosure, commonly using data leak sites and time-bounded payment demands rather than endpoint encryption. Observed targeting has included financial services, hedge funds, private equity, legal services, manufacturing, real estate, healthcare, insurance, technology, transportation, and hospitality organizations. Activity has particularly focused on high-value enterprises and senior personnel, including directors, vice presidents, executives, and IT staff.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
121 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses phone-based social engineering and passkey-themed phishing infrastructure to compromise corporate identities and access enterprise cloud environments. Its activity has been linked to the same extortion ecosystem.
A contemporaneous vishing-led extortion activity cluster using adversary-in-the-middle credential harvesting and exfiltration from enterprise cloud environments. It is discussed as a comparison case; the content concludes that its infrastructure and target set are separate from those of the ShinyHunters-attributed domain campaign.
A data-extortion group assessed in the reference to have significant tradecraft similarities to PREY-0058.
Named activity cluster associated by the report with ShinyHunters activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.