Skip to main content

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

0
Medium
Published: 08/06/2026 (08/06/2026, 22:15:43 UTC)
Source: AlienVault OTX General

Description

UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 12:42:45 UTC

Technical Analysis

UNC6671 continues data theft extortion operations through multiple brands despite the alleged retirement of the BlackFile brand. They employ vishing tactics, impersonating IT helpdesk personnel to contact employees on personal mobile devices. Victims are directed to spoofed login portals equipped with adversary-in-the-middle infrastructure that intercepts credentials and multi-factor authentication tokens. After gaining access, automated scripts exfiltrate data from enterprise cloud environments such as Microsoft 365 and Okta. Infrastructure analysis shows shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting focuses on financial services, private equity, legal, and professional services sectors. Bitcoin wallet analysis from January to May 2026 indicates ransom payments totaling about $10.69 million USD.

Potential Impact

Successful attacks result in credential and multi-factor authentication token theft, enabling unauthorized access to enterprise cloud environments. This leads to data exfiltration from critical cloud services like Microsoft 365 and Okta, potentially causing significant data breaches and extortion losses. The financial impact is evidenced by ransom payments totaling approximately $10.69 million USD within a five-month period in 2026. The campaign targets high-value sectors, increasing the risk of sensitive data compromise and operational disruption.

Defensive Guidance

No official patch or fix applies as this is a social engineering and credential theft campaign. Organizations should enhance employee awareness training focused on vishing and social engineering tactics, especially regarding unsolicited IT helpdesk calls. Implementing and enforcing strong multi-factor authentication methods resistant to interception is recommended. Monitoring for suspicious login activity and unusual access patterns in cloud environments like Microsoft 365 and Okta can help detect compromise early. Review and restrict access privileges to minimize potential damage from credential theft. Refer to the vendor advisory at https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments for ongoing updates and guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments"]
Adversary
UNC6671
Pulse Id
6a75078f7b8e057bc29b8769

Indicators of Compromise

Domain

ValueDescriptionCopy
domainoktaenroll.com
domainidokta.com
domainmyoktasso.com
domainmypasskeysso.com
domainsetupssopasskey.com
domainpasskeyms.com
domainkeyokta.com
domainportalpasskey.com
domainoktaportalsso.com
domainpasskeyportal.com
domainpasskeyportalsetup.com
domainaddoktapasskey.com
domaindeploypasskey.com
domainmysecurepasskey.com
domainactivatemypasskey.com
domaincreatepasskey.com
domainregisterpasskey.com
domainsetupsso.com
domainpasskeycenter.com
domainpasskeyregister.com
domainsecureauthpasskey.com
domaincreatemypasskey.com
domainpasskeyset.com
domainpasskeyokta.com
domainpasskeyadd.com
domainpasskeydeploy.com
domainsetpasskey.com
domainaddmypasskey.com
domainpasskey-portal.com
domainpasskeyregistration.com
domainportalsetuphub.com
domainmynewpasskey.com
domainmyconnectkey.com
domainenablepasskey2fa.com
domainpasskeyuser.com
domainpasskeyenroll.com
domainstartpasskey.com
domainoskeysync.com
domainassignpasskey.com
domainkeysyncos.com
domainpasskeyhelpdesk.com
domainpasskeycreate.com
domainpasskeysupport.com
domaincreatessopasskey.com
domainactivatepasskey.com
domainactivatepasskeyportal.com
domainadd-passkey.com
domainaddpasskey2fa.com
domainaddssopasskey.com
domainaddyourpasskey.com
domaincheckpasskey.com
domaincreatemfa.com
domainenablepasskey.com
domainenrollpasskey.com
domainhubpasskey.com
domainmakepasskey.com
domainmspasskey.com
domainmyaccountsecurity.com
domainmypasskeyid.com
domainmyssopasskey.com
domainnewpasskey.com
domainoskeyconnect.com
domainpasskey-check.com
domainpasskey-connect.com
domainpasskey-enable.com
domainpasskeyactivation.com
domainpasskeycreator.com
domainpasskeyenable.com
domainpasskeymfa.com
domainpasskeyrollout.com
domainpasskeystatus.com
domainsecure-passkey.com
domainsqfepjvmrd.xyz
domainssopasskey.com
domainstartpasskeysetup.com

Ip

ValueDescriptionCopy
ip107.128.45.122
ip38.42.59.171
ip47.218.103.146
ip76.103.148.180

Threat ID: 6a75af5dbf8831d539217dbd

Added to database: 08/07/2026, 10:11:41 UTC

Last enriched: 08/14/2026, 12:42:45 UTC

Last updated: 09/21/2026, 09:31:20 UTC

Views: 405

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses