BlackFile is a financially motivated data-theft and extortion threat actor active since at least late 2025 and prominently observed targeting retail and hospitality organizations from February 2026. The group is also tracked as UNC6671, CL-CRI-1116, and Cordial Spider, and has been assessed as likely associated with The Com, a loosely connected English-speaking cybercriminal ecosystem. Reporting indicates BlackFile ceased operations in April 2026, after which successor or rebranded operations such as Redact and Pink were suspected to emerge. BlackFile specializes in identity-centric intrusions rather than malware-heavy compromise. Its operations commonly begin with voice phishing in which operators impersonate internal IT helpdesk or support personnel, often using spoofed caller information to increase credibility. Victims are directed to phishing pages that mimic enterprise single sign-on workflows, where the actor captures credentials and one-time passcodes. BlackFile then registers attacker-controlled devices or authentication methods to bypass multifactor authentication, gains persistence, and escalates access into privileged or executive accounts. The group has also been reported scraping internal directories to identify senior personnel and broaden access. Post-compromise activity centers on data theft from cloud and SaaS platforms, especially SharePoint and Salesforce, including abuse of legitimate APIs and enterprise session activity to blend with normal user behavior. BlackFile has targeted sensitive business records and employee data, then transferred stolen information out of victim environments for extortion. The actor has operated a leak site and issued seven-figure ransom demands, using publication threats to pressure victims. Some incidents also involved swatting and other harassment tactics to intensify coercion. BlackFile’s tradecraft overlaps with other Com-affiliated extortion actors, particularly ShinyHunters, and later groups including Redact and Pink have been described as possible successors or rebrands using similar social-engineering-led data extortion methods.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a potentially linked or predecessor data extortion group based on overlapping infrastructure previously used by Helix.
Referenced as a likely ecosystem overlap or possible predecessor/offshoot relationship to Helix; its infrastructure and tradecraft reportedly resemble Helix activity.
Referenced as a possibly linked data-extortion group due to shared techniques and infrastructure with Helix.
Referenced as a possible predecessor or successor-linked operation to Helix, with overlap in identity-based attacks, social engineering, and infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.