Redact is a financially motivated data-extortion brand associated with the UNC6671 cybercriminal cluster and the former BlackFile operation. Google Threat Intelligence Group linked Redact with BlackFile, Pink, Helix, and Falcon through shared credential-harvesting infrastructure, phishing templates, victimology, and extortion tradecraft. Redact emerged following the apparent retirement of the BlackFile brand in 2026 and has been associated with cloud-focused intrusions targeting high-value corporate data. Redact-associated activity uses voice phishing and help-desk impersonation, often contacting employees on personal phones and creating urgency around passkey, MFA, or SSO changes. Operators direct victims to adversary-in-the-middle phishing portals or abuse device-code authentication to obtain credentials, authenticated sessions, or OAuth-authorized access. Following compromise, they can establish persistence through attacker-controlled MFA enrollment, enumerate identity and cloud resources, access Microsoft 365 and other SaaS services, and systematically collect data from SharePoint, OneDrive, Exchange, and related platforms. The wider UNC6671 activity has also included use of compromised mailboxes to reset passwords for non-SSO applications and deletion of password-reset, MFA, and security-alert messages to reduce detection. The operation conducts data-theft extortion, threatening to publish stolen corporate information through leak-site activity unless victims pay. Reported Redact victims include U.S. healthcare and insurance organizations. Redact has been publicly characterized as a successor or rebranding of BlackFile, while the precise organizational relationship among Redact, Pink, Helix, Falcon, and other UNC6671-associated extortion brands remains operationally fluid.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a sibling brand of FALCON in a table describing adversary-in-the-middle phishing.
An extortion group Google linked to UNC6671 activity and the same broader extortion ecosystem.
One of four brands used in BlackFile's split extortion operations sharing infrastructure.
Named extortion brand sharing infrastructure with UNC6671-linked operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.