Falcon is a financially motivated data-extortion brand linked to the UNC6671 cybercriminal cluster and the wider BlackFile-associated ecosystem. Security researchers have identified operational overlaps among Falcon, BlackFile, Redact, Pink, and Helix, including shared phishing infrastructure, matching credential-harvesting templates, overlapping victimology, and common cloud-focused data-theft tradecraft. Falcon has also been associated with Storm-3121 initial-access activity that feeds into extortion operations. Falcon-associated activity relies heavily on voice phishing and help-desk impersonation, frequently contacting employees on personal devices with urgent passkey, MFA, or SSO-update pretexts. Operators use adversary-in-the-middle phishing and device-code phishing to obtain credentials, authenticated sessions, or authorization for attacker-controlled applications. Following account compromise, they can register attacker-controlled MFA methods for persistence, enumerate cloud tenants and applications through Microsoft Graph, and systematically collect data from Microsoft 365 services including SharePoint Online, OneDrive for Business, and Exchange Online. The ecosystem has also abused identity platforms and SaaS trust relationships, including Okta. The group uses stolen data for extortion, including threats to publish victim data through leak sites. UNC6671-linked operations have targeted manufacturing, real estate, health care, insurance, technology, transportation, hospitality, financial services, private equity, law firms, and credit-rating organizations, with an apparent focus on organizations holding commercially sensitive, legal, investor, merger-and-acquisition, and customer information. Falcon has been publicly associated with claimed intrusions affecting U.S. organizations in health care, energy and industrial distribution, and manufacturing.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Com-affiliated extortion brand described as using adversary-in-the-middle phishing, passkey or SSO-themed domains, real-time credential and MFA-token relay, bulk cloud-data exfiltration, and extortion through compromised email accounts.
Receives access from Storm-3121 initial-access operations.
An extortion group associated with Storm-3121 in the reported account-compromise ecosystem.
An extortion operation that receives access or operational support from Storm-3121.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.