UNC6671 is a financially motivated cybercrime and data-theft extortion cluster active since early 2026 and publicly associated with the BlackFile brand before expanding or rebranding activity under Redact, Pink, Helix, and Falcon. The actor is tracked as a distinct vishing-led extortion operation that compromises enterprise identity and SaaS environments through tailored social engineering rather than software exploitation. UNC6671’s core intrusion pattern centers on impersonation of internal IT helpdesk personnel in voice phishing calls, often to employees’ personal mobile phones, using urgent pretexts such as passkey enrollment, MFA changes, or security migrations. Victims are directed to spoofed single sign-on portals that use adversary-in-the-middle credential harvesting to capture usernames, passwords, MFA codes, and session material in real time. The group has targeted Microsoft 365 and Okta environments in particular, and has been observed establishing persistence by enrolling attacker-controlled MFA devices, abusing compromised cloud identities, and deleting security notifications, password-reset confirmations, and related alerts to reduce the chance of detection. After initial access, UNC6671 pivots through single sign-on into connected SaaS platforms and conducts large-scale cloud data theft. Reported post-compromise activity includes access to SharePoint, OneDrive, Zendesk, Salesforce, and other enterprise applications, use of automated tooling and scripts for collection and exfiltration, and PowerShell-based downloads from Microsoft cloud services. The actor has also used compromised email accounts to initiate password resets for non-SSO applications and has employed aggressive pressure tactics during extortion, including harassment of victim personnel. UNC6671 is associated with data-theft extortion rather than endpoint ransomware deployment. It has operated leak-site-backed extortion under some of its public brands, and ransom demands have commonly been in the high six- to low seven-figure range. Reporting links the cluster to sustained campaigns against organizations likely to hold highly sensitive corporate, legal, financial, or client data. Recent targeting has emphasized hedge funds, private-equity firms, other financial organizations, professional services firms, law firms, and financial-rating agencies, while earlier activity also affected technology, transportation, hospitality, healthcare, manufacturing, and real-estate organizations. The cluster has been distinguished from, but noted to share tradecraft similarities with, ShinyHunters-linked activity and Scattered Spider-style helpdesk social engineering. Analysts have assessed that overlaps among BlackFile, Redact, Pink, Helix, and Falcon likely reflect a common affiliated actor set or umbrella collective, though the exact internal structure may include splintered affiliates or shared phishing infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
85 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data theft extortion operations targeting enterprise cloud environments, using IT helpdesk vishing, adversary-in-the-middle credential harvesting, MFA token interception, and large-scale cloud data exfiltration.
Vishing-based extortion group conducting tailored IT helpdesk impersonation, adversary-in-the-middle credential theft, SSO compromise, cloud account takeover, and extortion under multiple brands after rebranding from BlackFile to Redact, Pink, Helix, and Falcon.
Extortion-focused intrusion group conducting helpdesk vishing and cloud data theft campaigns against financial organizations and other sectors, operating across multiple public extortion brands.
An umbrella threat cluster that may encompass multiple public extortion brands conducting coordinated vishing-led intrusions and data-theft extortion against high-value corporate targets, especially U.S. financial and legal organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.