Redact is a financially motivated data-extortion brand associated with the broader threat cluster tracked as UNC6671 and widely assessed to be a successor or rebrand of BlackFile. It has been linked alongside Pink, Helix, and Falcon through shared infrastructure, overlapping victimology, and a common operational playbook centered on help-desk impersonation and cloud-focused identity compromise. Reporting indicates the cluster likely operates multiple public extortion brands to monetize intrusions, compartmentalize negotiations, and complicate tracking, although the precise internal relationships among the brands are not fully resolved. Redact-linked operations rely primarily on voice phishing against enterprise employees, often via personal mobile phones, while impersonating internal IT staff or help-desk personnel and creating urgency around security migrations, passkey enrollment, or account issues. Victims are directed to adversary-in-the-middle phishing portals designed to capture credentials and multi-factor authentication material in real time. After access is obtained, the operators abuse identity platforms and SaaS environments, particularly Microsoft 365 and Okta, to establish persistence, register attacker-controlled MFA devices, reset passwords for non-SSO applications, move across connected cloud services, and rapidly exfiltrate high-value data using automated tooling. Defense-evasion behavior includes deleting password-reset confirmations, MFA notifications, and security alerts from compromised mailboxes. The actor’s targeting has included large U.S. financial institutions, private equity firms, law firms, ratings agencies, healthcare organizations, and insurance entities, with broader UNC6671 activity also spanning manufacturing, real estate, technology, transportation, hospitality, and professional services. The operational emphasis is on stealing sensitive corporate information that can support high-value extortion, including material related to mergers and acquisitions, litigation, capital deployment, investor records, intellectual property, source code, and VIP client data. Redact has been associated with ransomware and extortion incidents against U.S.-based organizations including healthcare and insurance victims, but the strongest consistent pattern is data-theft-led extortion rather than confirmed widespread encryption operations. Redact is part of a 2026 wave of identity-driven, malware-light extortion activity that prioritizes social engineering over software exploitation. Available evidence supports high-confidence linkage to UNC6671 and BlackFile, while broader ecosystem overlaps with actors such as ShinyHunters or Com-affiliated groups remain less certain and should be treated cautiously.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of four successor brands/groups that UNC6671/BlackFile reportedly split into, continuing the same vishing and extortion tradecraft.
Public extortion brand used within the broader UNC6671 operation for monetization and negotiation compartmentalization.
Financially motivated cybercriminal activity targeting major U.S. financial institutions and other firms using vishing, phishing sites, credential theft, MFA interception, and extortion/ransom demands.
A named extortion-focused cluster targeting large U.S. financial and investment firms using vishing to steal credentials and MFA codes via spoofed websites, then threatening to leak stolen data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.