ctipilot.ch

UNC6671

actor · actor:unc6671 single-source

UNC6671 / BlackFile — vishing-driven AiTM extortion with programmatic SharePoint exfiltration (GTIG 2026-05-15). Shut down April 2026, fragmenting into successor brands (Pink, Redact); ReliaQuest assesses the Helix cluster as a likely continuation (2026-07-08).

Aliases: BlackFile

Coverage timeline
6
first 2026-05-11 → last 2026-07-10
Peak priority
high
2 high · 4 notable
Sources cited
29
24 hosts
Sections touched
4
active-threats, weekly-long-running, weekly-looking-ahead
Co-occurring entities
3
see Related entities below
ATT&CK techniques
7
pinned v19.1 · see below
2026-05-116 appearances2026-07-10

ATT&CK techniques

7 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×2

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Persistence TA0003

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Privilege Escalation TA0004

T1098.005Account Manipulation: Device Registration×1

Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

Defense Impairment TA0112

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×2

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1556Modify Authentication Process×1

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SAM) on Windows, pluggable authentication modules (PAM) on Unix-based systems, and authorization plugins on MacOS systems, responsible for gathering, storing, and validating credentials. By modifying an authentication process, an adversary may be able to authenticate to a service or system without using Valid Accounts.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Collection TA0009

T1213.002Data from Information Repositories: Sharepoint×1

Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an adversary to learn about the structure and functionality of the internal network and systems. For example, the following is a list of example information that may hold potential value to an adversary and may also be found on SharePoint:

Evidence: 2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil · ATT&CK page ↗

T1557Adversary-in-the-Middle×1

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Transmitted Data Manipulation, or replay attacks (Exploitation for Credential Access). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.

Evidence: 2026-05-16/gtig-unc6671-blackfile-vishing-aitm-rogue-mfa-programmatic-s · ATT&CK page ↗

Story timeline

  1. 2026-07-10'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
    active-threatsReliaQuest: new 'Helix' extortion cluster (BlackFile/ShinyHunters lineage) vishes staff into device-code sign-ins, then bulk-loots SharePoint
  2. 2026-05-25UNC6671 / BlackFile — GTIG publishes the full profile; group announced shutdown "under this name", rebrand probable
    weekly-long-running
  3. 2026-05-18Looking ahead — 2026-W21
    weekly-looking-ahead
  4. 2026-05-16GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
    active-threats
  5. 2026-05-11Public administration and government
    weekly-sector-patterns
  6. 2026-05-11Looking ahead — 2026-W20
    weekly-looking-ahead

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

succeeded by

Where this entity is cited

  • weekly-looking-ahead2
  • active-threats2
  • weekly-sector-patterns1
  • weekly-long-running1

Source distribution

  • attack.mitre.org4 (14%)
  • cloud.google.com2 (7%)
  • msrc.microsoft.com2 (7%)
  • almalinux.org1 (3%)
  • bleepingcomputer.com1 (3%)
  • cert.pl1 (3%)
  • cyberscoop.com1 (3%)
  • digital-strategy.ec.europa.eu1 (3%)
  • other16 (55%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (29)

Entries about UNC6671 (6)

2026-07-10 · view entry permalink →

HIGHNATOB2

'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration

ReliaQuest's Threat Research team published (2026-07-08) a spotlight on Helix, a data-extortion cluster it assesses as a likely continuation of the now-fragmented BlackFile (UNC6671) operation and the broader ShinyHunters ecosystem — an assessment resting on a shared credential-harvesting-domain registrar (also used by the Scattered Spider/"The Com" community) and an exfiltration host four addresses away, on the same autonomous system, from a confirmed BlackFile address two months earlier (ReliaQuest, 2026-07-08). ReliaQuest is explicit that this is likely-ecosystem-continuation, not confirmed attribution — but "organizations already tracking those groups should treat Helix as an extension of the same data extortion campaigns."

The device-code-phishing-defeats-Conditional-Access primitive itself was covered earlier today in the Huntress Railway/LSHIY analysis (see references); Helix's contribution is the full extortion kill chain wrapped around it. Initial contact is voice phishing in which the operator impersonates the target's actual manager by name on a spoofed caller-ID and talks them through entering a device code into Chrome — the session token is captured without any password crossing the phone line, and the device-code flow bypasses Conditional Access (ReliaQuest, 2026-07-08; BleepingComputer, 2026-07-09). Persistence is deliberately minimal and hard to spot: the operator registers a new MFA Authenticator on the account, typically within minutes of sign-in, from the same residential proxy used for access — "the only persistence artifact is a legitimate MFA registration." Sign-in infrastructure is geo-matched to the target's real city to avoid impossible-travel alerts, rotating through 15+ residential IPs against a single mailbox. Collection is automated and identical across incidents — the operator issues contentclass:STS_Site and wildcard SharePoint searches to inventory reachable content, then bulk-downloads, using a python-requests user-agent from an IP reserved for exfiltration and never used for access. Dwell before mass exfil ranged from under an hour to over a week, a deliberate tuning to each environment's value and detectability. In at least one case the operator actively tested containment after the account was disabled, re-attempting MFA registration and a password reset.

Helix likely emerged from the “BlackFile” and “ShinyHunters” ecosystem. Groups fragment and rebrand, but the techniques and infrastructure persist across every iteration.

Device code phishing then sidesteps Conditional Access policies, and automated tools enumerate and mass-download SharePoint libraries before bulk exfiltration triggers an alert.

Disabling device code authentication is the single highest-impact action.

ReliaQuest 2026-07-08

Builds on: 2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns

threat10 Jul 12:53Zmulti-sourceOpen finding ↗

2026-05-25 · view entry permalink →

NOTABLE

UNC6671 / BlackFile — GTIG publishes the full profile; group announced shutdown "under this name", rebrand probable

Resolving a W21 carry-forward watch item: GTIG published a definitive UNC6671 / BlackFile profile in mid-May 2026, characterising the operation as an adversary-in-the-middle vishing specialist targeting Microsoft 365 and Okta SSO environments in retail and hospitality (vishing impersonating IT support → MFA-bypass / credential grant → AiTM session-token harvest → exfiltration → extortion over the Session messenger). The leak-site went offline in late April, briefly resumed on 2026-05-11 to announce "BlackFile is shutting down… under this name," and went dark again — GTIG's phrasing and the qualifier point to a probable rebrand rather than a genuine exit. Defenders should keep the AiTM-vishing → rogue-MFA → SSO-token-theft TTP set on watch under any new brand; the tradecraft, not the name, is the durable indicator.

synthesis25 May 05:00Zmulti-sourceOpen finding ↗

2026-05-18 · view entry permalink →

NOTABLE

Looking ahead — 2026-W21

Items already in motion at the close of 2026-W21. Not predictions — each links to the in-motion reporting underneath.

  • GitHub's fuller post-incident report on the internal-repo breach is still outstanding. GitHub's 2026-05-20 blog committed to a fuller report; the open questions are the full scope of the ~3,800 exfiltrated internal repos and whether any contained credentials or customer-impacting material. (GitHub Security Blog)
  • Shai-Hulud wave-6 candidate registries — Cargo (Rust) and Maven (Java). The OIDC-token-reuse propagation primitive is registry-agnostic; with the worm now open-sourced and commoditised, Cargo and Maven are the un-hit major ecosystems. Pre-stage Sigstore/provenance-anomaly hunts in Rust and Java dependency pipelines. (CSA research note)
  • EU 20th-package "managed security services" scope guidance, and SECO confirmation of Swiss transposition. No European Commission interpretive guidance on the managed-security-services definition was published as of 24 May; SECO confirmation of whether Switzerland's 22 May adoption includes the MSS prohibition specifically is the open compliance question for CH providers. (Greenberg Traurig)
  • PAN-OS CVE-2026-0300 wave-2 patch builds scheduled ~2026-05-28. Remaining build streams finish the staged patch arc; audit for attacker-created rogue admin accounts before patching wipes implant artefacts. (Palo Alto PSIRT; daily 2026-05-18)
  • Windows YellowKey / GreenPlasma / MiniPlasma cluster — June 2026 Patch Tuesday (~2026-06-10) is the expected first fix. Three public PoCs, no out-of-band release; until then BitLocker PIN/Network-Unlock GPOs and ctfmon.exe-injection WDAC rules are the only controls. (MSRC CVE-2026-45585; daily 2026-05-20)
  • Sparx Enterprise Architect chain and ChromaDB CVE-2026-45829 remain unpatched. Both carry public PoCs with no vendor fix; watch for the patches and, in the interim, keep both off the public internet behind authenticated access. (CERT-PL; daily 2026-05-21)
  • GTIG UNC6671 "BlackFile" probable rebrand. The DLS went offline with a shutdown message; no successor brand had emerged by week-end. Watch for a new leak-site reusing the vishing → AiTM → rogue-MFA → SharePoint-exfiltration TTP set. (daily 2026-05-23)
outlook18 May 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (3)