BlackFile is a financially motivated data-extortion threat actor tracked as UNC6671, CL-CRI-1116, and Cordial Spider, and assessed by multiple defenders as likely associated with the broader Com-affiliated cybercriminal ecosystem. The group emerged in 2026 and became known for identity-centric intrusions that relied on social engineering rather than software exploitation, especially voice phishing in which operators impersonated internal IT helpdesk staff and created urgency around security migrations, passkey enrollment, or multifactor authentication updates. Victims were directed to spoofed single sign-on portals using adversary-in-the-middle infrastructure to capture credentials, one-time codes, MFA tokens, and authenticated sessions. BlackFile also used device registration and MFA enrollment abuse to maintain access, targeted employees on personal mobile phones, and in some cases spoofed legitimate helpdesk phone numbers. After initial compromise, BlackFile focused on cloud and SaaS environments, including Microsoft 365, Okta, SharePoint, Salesforce, and related identity infrastructure. Reported post-compromise behavior included session persistence, password-reset abuse, deletion of security notifications and alert emails for defense evasion, escalation into privileged and executive accounts, and rapid data theft from enterprise repositories. The actor used legitimate APIs and standard download mechanisms to collect data and then extorted victims with seven-figure ransom demands, publishing stolen information on a leak site when victims did not pay. Swatting and other coercive pressure tactics were also reported in some cases. BlackFile initially targeted retail and hospitality organizations, then broadened and shifted victimology during 2026 to include manufacturing, real estate, healthcare, insurance, technology, transportation, financial services, private equity, law firms, and other professional-services organizations. The actor’s operations were characterized as opportunistic but increasingly focused on organizations holding sensitive corporate, legal, or transactional data that could maximize extortion leverage. In 2026, the BlackFile brand was publicly retired, but the underlying activity cluster was assessed to have continued under successor or related extortion brands including Redact, Pink, Helix, and Falcon. Researchers linked these brands through overlaps in phishing templates, infrastructure, victimology, and tradecraft, while noting that some fragmentation may reflect compartmentalization, affiliate disputes, or shared tooling rather than a single monolithic group. BlackFile has also been compared with ShinyHunters because of similar social-engineering-led extortion tradecraft, though reporting distinguished UNC6671 as an independent cluster despite those similarities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
37 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a retired predecessor or related extortion brand in background context about fragmentation of associated groups.
Previously active extortion brand whose infrastructure is linked to newer brands including Helix.
Former extortion brand associated with UNC6671 that targeted organizations through vishing and SSO compromise before being retired.
An extortion group conducting vishing-led intrusions against enterprises. It impersonates IT help desk staff, uses spoofed login portals and adversary-in-the-middle infrastructure to steal credentials and MFA tokens, establishes session persistence, and automates data exfiltration from enterprise cloud environments. The group appears to operate or reuse multiple extortion brands to monetize operations and obscure activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.