BlackFile is a financially motivated data-extortion operation tracked as UNC6671 and also identified as CL-CRI-1116. It is associated with The Com ecosystem and has conducted cloud-focused intrusions against large enterprises. The operation uses help-desk impersonation, voice phishing, SMS lures, caller-ID spoofing, and authentication-update pretexts involving passkeys, MFA, or SSO. Victims are directed to adversary-in-the-middle phishing portals or device-code authentication flows, enabling theft of credentials, authenticated sessions, or authorization tokens. Following account compromise, BlackFile operators register attacker-controlled authentication methods for persistence; enumerate identities, privileges, applications, OAuth permissions, cloud storage, and mail through Microsoft Graph; and collect data from Microsoft 365 services including SharePoint, OneDrive, and Exchange Online. The group also targets identity and SaaS environments including Okta. Collection is automated and paced to reduce detection, and the actors have deleted security notifications and password-reset messages from compromised mailboxes. Stolen data is used to demand payment under threat of public disclosure, with reported escalation including threatening communications and swatting. BlackFile retired its original public brand during 2026, but UNC6671 activity continued under the Redact, Pink, Helix, and Falcon extortion brands. These brands have been linked through shared phishing infrastructure, matching credential-harvesting templates, victimology, and consistent intrusion tradecraft. Helix is associated with a BlackFile splinter designated Storm-3032. Although UNC6671 activity has tradecraft overlap with ShinyHunters, it has been assessed to operate independently.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Predecessor group from which the Storm-3032 actors split.
An extortion group whose members are believed to now operate under the Helix name and are tied to Storm-3032.
A threat actor group identified as the origin from which Storm-3032 grew.
A cybercriminal group identified as the origin of Storm-3032.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.