UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
AI Analysis
Technical Summary
UNC6671 continues data theft extortion operations through multiple brands despite the alleged retirement of the BlackFile brand. They employ vishing tactics, impersonating IT helpdesk personnel to contact employees on personal mobile devices. Victims are directed to spoofed login portals equipped with adversary-in-the-middle infrastructure that intercepts credentials and multi-factor authentication tokens. After gaining access, automated scripts exfiltrate data from enterprise cloud environments such as Microsoft 365 and Okta. Infrastructure analysis shows shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting focuses on financial services, private equity, legal, and professional services sectors. Bitcoin wallet analysis from January to May 2026 indicates ransom payments totaling about $10.69 million USD.
Potential Impact
Successful attacks result in credential and multi-factor authentication token theft, enabling unauthorized access to enterprise cloud environments. This leads to data exfiltration from critical cloud services like Microsoft 365 and Okta, potentially causing significant data breaches and extortion losses. The financial impact is evidenced by ransom payments totaling approximately $10.69 million USD within a five-month period in 2026. The campaign targets high-value sectors, increasing the risk of sensitive data compromise and operational disruption.
Mitigation Recommendations
No official patch or fix applies as this is a social engineering and credential theft campaign. Organizations should enhance employee awareness training focused on vishing and social engineering tactics, especially regarding unsolicited IT helpdesk calls. Implementing and enforcing strong multi-factor authentication methods resistant to interception is recommended. Monitoring for suspicious login activity and unusual access patterns in cloud environments like Microsoft 365 and Okta can help detect compromise early. Review and restrict access privileges to minimize potential damage from credential theft. Refer to the vendor advisory at https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments for ongoing updates and guidance.
Indicators of Compromise
- domain: oktaenroll.com
- domain: idokta.com
- domain: myoktasso.com
- domain: mypasskeysso.com
- domain: setupssopasskey.com
- domain: passkeyms.com
- domain: keyokta.com
- domain: portalpasskey.com
- domain: oktaportalsso.com
- domain: passkeyportal.com
- domain: passkeyportalsetup.com
- domain: addoktapasskey.com
- domain: deploypasskey.com
- domain: mysecurepasskey.com
- domain: activatemypasskey.com
- domain: createpasskey.com
- domain: registerpasskey.com
- domain: setupsso.com
- domain: passkeycenter.com
- domain: passkeyregister.com
- domain: secureauthpasskey.com
- domain: createmypasskey.com
- domain: passkeyset.com
- domain: passkeyokta.com
- domain: passkeyadd.com
- domain: passkeydeploy.com
- domain: setpasskey.com
- domain: addmypasskey.com
- domain: passkey-portal.com
- domain: passkeyregistration.com
- domain: portalsetuphub.com
- domain: mynewpasskey.com
- domain: myconnectkey.com
- domain: enablepasskey2fa.com
- domain: passkeyuser.com
- domain: passkeyenroll.com
- domain: startpasskey.com
- domain: oskeysync.com
- domain: assignpasskey.com
- domain: keysyncos.com
- domain: passkeyhelpdesk.com
- domain: passkeycreate.com
- domain: passkeysupport.com
- domain: createssopasskey.com
- ip: 107.128.45.122
- ip: 38.42.59.171
- ip: 47.218.103.146
- ip: 76.103.148.180
- domain: activatepasskey.com
- domain: activatepasskeyportal.com
- domain: add-passkey.com
- domain: addpasskey2fa.com
- domain: addssopasskey.com
- domain: addyourpasskey.com
- domain: checkpasskey.com
- domain: createmfa.com
- domain: enablepasskey.com
- domain: enrollpasskey.com
- domain: hubpasskey.com
- domain: makepasskey.com
- domain: mspasskey.com
- domain: myaccountsecurity.com
- domain: mypasskeyid.com
- domain: myssopasskey.com
- domain: newpasskey.com
- domain: oskeyconnect.com
- domain: passkey-check.com
- domain: passkey-connect.com
- domain: passkey-enable.com
- domain: passkeyactivation.com
- domain: passkeycreator.com
- domain: passkeyenable.com
- domain: passkeymfa.com
- domain: passkeyrollout.com
- domain: passkeystatus.com
- domain: secure-passkey.com
- domain: sqfepjvmrd.xyz
- domain: ssopasskey.com
- domain: startpasskeysetup.com
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
Description
UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
UNC6671 continues data theft extortion operations through multiple brands despite the alleged retirement of the BlackFile brand. They employ vishing tactics, impersonating IT helpdesk personnel to contact employees on personal mobile devices. Victims are directed to spoofed login portals equipped with adversary-in-the-middle infrastructure that intercepts credentials and multi-factor authentication tokens. After gaining access, automated scripts exfiltrate data from enterprise cloud environments such as Microsoft 365 and Okta. Infrastructure analysis shows shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting focuses on financial services, private equity, legal, and professional services sectors. Bitcoin wallet analysis from January to May 2026 indicates ransom payments totaling about $10.69 million USD.
Potential Impact
Successful attacks result in credential and multi-factor authentication token theft, enabling unauthorized access to enterprise cloud environments. This leads to data exfiltration from critical cloud services like Microsoft 365 and Okta, potentially causing significant data breaches and extortion losses. The financial impact is evidenced by ransom payments totaling approximately $10.69 million USD within a five-month period in 2026. The campaign targets high-value sectors, increasing the risk of sensitive data compromise and operational disruption.
Defensive Guidance
No official patch or fix applies as this is a social engineering and credential theft campaign. Organizations should enhance employee awareness training focused on vishing and social engineering tactics, especially regarding unsolicited IT helpdesk calls. Implementing and enforcing strong multi-factor authentication methods resistant to interception is recommended. Monitoring for suspicious login activity and unusual access patterns in cloud environments like Microsoft 365 and Okta can help detect compromise early. Review and restrict access privileges to minimize potential damage from credential theft. Refer to the vendor advisory at https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments for ongoing updates and guidance.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments"]
- Adversary
- UNC6671
- Pulse Id
- 6a75078f7b8e057bc29b8769
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainoktaenroll.com | — | |
domainidokta.com | — | |
domainmyoktasso.com | — | |
domainmypasskeysso.com | — | |
domainsetupssopasskey.com | — | |
domainpasskeyms.com | — | |
domainkeyokta.com | — | |
domainportalpasskey.com | — | |
domainoktaportalsso.com | — | |
domainpasskeyportal.com | — | |
domainpasskeyportalsetup.com | — | |
domainaddoktapasskey.com | — | |
domaindeploypasskey.com | — | |
domainmysecurepasskey.com | — | |
domainactivatemypasskey.com | — | |
domaincreatepasskey.com | — | |
domainregisterpasskey.com | — | |
domainsetupsso.com | — | |
domainpasskeycenter.com | — | |
domainpasskeyregister.com | — | |
domainsecureauthpasskey.com | — | |
domaincreatemypasskey.com | — | |
domainpasskeyset.com | — | |
domainpasskeyokta.com | — | |
domainpasskeyadd.com | — | |
domainpasskeydeploy.com | — | |
domainsetpasskey.com | — | |
domainaddmypasskey.com | — | |
domainpasskey-portal.com | — | |
domainpasskeyregistration.com | — | |
domainportalsetuphub.com | — | |
domainmynewpasskey.com | — | |
domainmyconnectkey.com | — | |
domainenablepasskey2fa.com | — | |
domainpasskeyuser.com | — | |
domainpasskeyenroll.com | — | |
domainstartpasskey.com | — | |
domainoskeysync.com | — | |
domainassignpasskey.com | — | |
domainkeysyncos.com | — | |
domainpasskeyhelpdesk.com | — | |
domainpasskeycreate.com | — | |
domainpasskeysupport.com | — | |
domaincreatessopasskey.com | — | |
domainactivatepasskey.com | — | |
domainactivatepasskeyportal.com | — | |
domainadd-passkey.com | — | |
domainaddpasskey2fa.com | — | |
domainaddssopasskey.com | — | |
domainaddyourpasskey.com | — | |
domaincheckpasskey.com | — | |
domaincreatemfa.com | — | |
domainenablepasskey.com | — | |
domainenrollpasskey.com | — | |
domainhubpasskey.com | — | |
domainmakepasskey.com | — | |
domainmspasskey.com | — | |
domainmyaccountsecurity.com | — | |
domainmypasskeyid.com | — | |
domainmyssopasskey.com | — | |
domainnewpasskey.com | — | |
domainoskeyconnect.com | — | |
domainpasskey-check.com | — | |
domainpasskey-connect.com | — | |
domainpasskey-enable.com | — | |
domainpasskeyactivation.com | — | |
domainpasskeycreator.com | — | |
domainpasskeyenable.com | — | |
domainpasskeymfa.com | — | |
domainpasskeyrollout.com | — | |
domainpasskeystatus.com | — | |
domainsecure-passkey.com | — | |
domainsqfepjvmrd.xyz | — | |
domainssopasskey.com | — | |
domainstartpasskeysetup.com | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip107.128.45.122 | — | |
ip38.42.59.171 | — | |
ip47.218.103.146 | — | |
ip76.103.148.180 | — |
Threat ID: 6a75af5dbf8831d539217dbd
Added to database: 08/07/2026, 10:11:41 UTC
Last enriched: 08/14/2026, 12:42:45 UTC
Last updated: 09/21/2026, 09:31:20 UTC
Views: 405
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.