Google Threat Intelligence Group reported that UNC6671 remains active after the apparent retirement of the BlackFile brand, with extortion operations now appearing under the Redact, Pink, Helix, and Falcon names. Investigators linked the brands through shared phishing infrastructure, overlapping victimology, and matching credential-harvesting templates, while noting the activity could also reflect splintered affiliates or shared phishing services. The group has increasingly targeted financial services, private equity, law firms, and other enterprises likely to hold highly sensitive corporate data.
The actor uses helpdesk-themed voice phishing to contact employees, often on personal mobile phones, and directs them to adversary-in-the-middle phishing portals designed to steal credentials and MFA tokens for persistent access to Microsoft 365, Okta, and other SaaS environments. Google also observed a faster pace of domain registrations in June and July 2026 and new evasion tactics, including deleting password-reset and security-alert emails from compromised accounts. Separately, the report attributed 141.65 BTC in BlackFile-linked ransom payments across 18 wallets between January and May 2026.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
GuidePoint reported that UNC6671/Falcon registered a new infrastructure cluster including myssoapps.com on August 7, 2026, one day after GTIG and Okta published reports on the activity. The report said active phishing sessions were observed within roughly 24 hours, indicating rapid infrastructure recovery after public exposure.
Gurucul released technical indicators tied to UNC6671, including numerous phishing and credential-harvesting domains, associated IP addresses, and detection queries for identifying related activity. The publication also described the group's use of helpdesk vishing, adversary-in-the-middle credential theft, and MFA token interception against Microsoft 365 and Okta accounts.
Reuters reported that UNC6671-linked infrastructure targeted more than 200 companies over the prior five weeks using 72 malicious websites, though Google said not all intrusion attempts were successful. The disclosure expanded the known scale of the campaign beyond previously named financial-sector victims.
In its August 6, 2026 report, Google Threat Intelligence Group assessed that UNC6671 remained active after BlackFile's apparent retirement in May and had diversified extortion activity under the Redact, Pink, Helix, and Falcon names. GTIG based the linkage on shared phishing infrastructure, overlapping victimology, and identical credential-harvesting templates.
Reuters reported that victims of the Falcon, Helix, Pink, and Redact activity included Apollo Global Management, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody’s, and TPG. The disclosure added specific named financial-sector targets to previously reported UNC6671 targeting trends.
Google researchers said the Redact brand sent new extortion demands to several organizations in the last week, indicating that the BlackFile/UNC6671 cluster remained actively conducting extortion operations. The CyberScoop report also said Google assessed the group was still targeting new victims as of late last week.
GTIG reported that seven UNC6671 domains were operationalized within a 72-hour period between July 20 and July 22, 2026. The burst of activity was cited as evidence of increased infrastructure tempo.
GTIG reported that by July 2026, UNC6671 had shifted targeting toward financial services, private equity, law firms, and financial rating agencies. GTIG assessed this focus likely aimed to maximize extortion leverage through access to highly confidential corporate data.
On June 27, 2026, Redact operators published a statement claiming they had rebranded away from BlackFile because the original brand had been compromised by a rogue affiliate. The statement also alleged the affiliate ran an unauthorized lookalike leak site and unsanctioned extortion campaigns using separate Tox identities.
GTIG reported that newly observed UNC6671 infrastructure between June 1 and July 31, 2026 was provisioned at an average rate of one domain every 1.6 days. This represented a faster tempo than the April-May activity previously observed.
GTIG reported that in June 2026, UNC6671's targeting evolved away from the broader enterprise focus seen earlier and concentrated more on technology, transportation, and hospitality organizations. The report also observed increased infrastructure activity during this period.
SOCRadar reported that Pink's branded data leak site became active on May 31, 2026. The launch marked a new extortion brand presence later assessed by GTIG as linked to the Redact/BlackFile lineage.
GTIG found that BlackFile-linked Bitcoin wallets continued receiving payments through May 12, 2026, despite the prior shutdown notice on the group's leak site. Across January 7 to May 12, the wallets received 141.65 BTC.
GTIG said the public BlackFile data leak site posted a shutdown notice on May 11, 2026. The report noted that ransom payments to BlackFile-linked wallets continued after this notice.
GTIG reported that UNC6671 activity between April 1 and May 31, 2026 involved 28 root domains provisioned at an average rate of one every 2.2 days. During this period, targeting was described as broader across enterprise sectors.
Google Threat Intelligence Group reviewed 18 BlackFile Bitcoin wallet addresses that received ransom payments beginning on January 7, 2026. The tracked wallets ultimately received 141.65 BTC across the observed payment period.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
cyberscoop.com
Open sourceguidepointsecurity.com
Open sourcecyberveille.ch
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcecloud.google.com
Open sourcesocradar.io
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.