ctipilot.ch

Home · Briefs · CTI Weekly Summary — 2026-W22 (May 25 – May 31, 2026)

UNC6671 / BlackFile — GTIG publishes the full profile; group announced shutdown "under this name", rebrand probable

From CTI Weekly Summary — 2026-W22 (May 25 – May 31, 2026) · published 2026-05-25

Resolving a W21 carry-forward watch item: GTIG published a definitive UNC6671 / BlackFile profile in mid-May 2026, characterising the operation as an adversary-in-the-middle vishing specialist targeting Microsoft 365 and Okta SSO environments in retail and hospitality (vishing impersonating IT support → MFA-bypass / credential grant → AiTM session-token harvest → exfiltration → extortion over the Session messenger). The leak-site went offline in late April, briefly resumed on 2026-05-11 to announce "BlackFile is shutting down… under this name," and went dark again — GTIG's phrasing and the qualifier point to a probable rebrand rather than a genuine exit. Defenders should keep the AiTM-vishing → rogue-MFA → SSO-token-theft TTP set on watch under any new brand; the tradecraft, not the name, is the durable indicator.