2026-08-07 · view entry permalink →
UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey
The retirement of a ransomware brand is a press release, not an outcome. Google Threat Intelligence Group reports that UNC6671, the actor behind the BlackFile extortion brand whose shutdown was announced in May 2026, went on operating and diversified across four further extortion fronts (Redact, Pink, Helix and Falcon) with the intrusion tradecraft essentially untouched (GTIG / Mandiant, 2026-08-06). The linkage is an assessment rather than a certainty, and GTIG says so: overlapping victim targeting across brands "support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible" (GTIG / Mandiant, 2026-08-06). The evidentiary basis is infrastructure economics: rather than isolating infrastructure per victim, the operator reuses generic root domains across many targets and appends victim-name subdomains, so one root domain used against a Falcon-extorted organisation was simultaneously used against a Helix-extorted one, and the same phishing templates, identical in code and design, were served from several of those domains at once.
The lure is the important change, and it inverts the standard advice. The pretext is an urgent helpdesk mandate to enable FIDO2 passkeys or update MFA enrolment, delivered by a caller who reaches the employee on their personal mobile; GTIG records that "UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls", and that "in at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy" (GTIG / Mandiant, 2026-08-06). Root domains pair authentication vocabulary (passkey, mfa, sso) with a verb, so the destination reads as an enrolment portal. GTIG's own hardening guidance names phishing-resistant authenticators as the durable control, because "these authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective" (GTIG / Mandiant, 2026-08-06). The operational catch is that origin binding protects an authenticator that already exists; this actor attacks the moment one is created. A defender who has deployed passkeys and considers the identity problem closed has hardened the authentication step and left the enrolment step as the way in.
Post-compromise, the chain is deliberately quiet. With session persistence established, the operator uses compromised mailboxes to trigger password resets on non-SSO enterprise applications, then blinds the victim: GTIG records that "operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations" (GTIG / Mandiant, 2026-08-06). Exfiltration is scripted rather than hands-on-keyboard, pulling data from Microsoft 365 and other SaaS stores at machine rates. GTIG characterises the operation as data-theft extortion throughout and no cited source describes an encryption stage; the leverage on the evidence published is publication.
Targeting has moved deliberately upmarket. Between April and May 2026 the domains were aimed broadly at large enterprises in manufacturing, real estate, healthcare and insurance; in June the focus shifted to technology, transportation and hospitality; and "by July 2026, the target profile narrowed to focus on the financial and legal sectors, with observed infrastructure directed at private equity firms, law firms, and financial rating agencies" (GTIG / Mandiant, 2026-08-06), organisations holding merger, capital-deployment and litigation material, which is leverage rather than data. Operational tempo rose with it, to "an accelerated cadence of approximately one domain every 1.6 days" across June and July against one every 2.2 days in the preceding two months (GTIG / Mandiant, 2026-08-06). BleepingComputer, relaying Reuters and Bloomberg, reports that recent targets in this financial-sector phase include several large US hedge funds and private-equity firms; GTIG names no victims itself (BleepingComputer, 2026-08-06).
The economics explain why announced retirements mean nothing. GTIG reviewed 18 BlackFile Bitcoin wallet addresses receiving 141.65 BTC (roughly $10.69 million at transaction time) between 2026-01-07 and 2026-05-12, with payments continuing past the 2026-05-11 shutdown notice and significant cash-out events in late April and early May. Initial demands run from $1 million to upwards of $3 million, negotiated down by 50% to 75%, and "in over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC)" (GTIG / Mandiant, 2026-08-06). GTIG's read is that the multi-brand structure most likely compartmentalises operations, hides total breach volume and isolates negotiation fallout, which is why brand-based tracking misleads and TTP-based tracking does not.
These overlaps support our assessment that a common group of threat actors are affiliated with the BlackFile, Redact, Pink, Helix, and Falcon extortion brands, although other scenarios such as splintered affiliates or shared Phishing-as-a-Service infrastructure may also be plausible.
UNC6671 callers have continued to call targeted employees on their personal mobile numbers, circumventing corporate security controls.
In at least some recent cases, the threat actor has spoofed the legitimate helpdesk phone number adding an air of legitimacy.
operators systematically deleted password-reset confirmations, secondary security notifications, company-wide security alerts, and any alerts generated during modifications to account security or MFA configurations.
In over 53% of tracked cases in this timeframe, final payments averaged $750,000 USD (~10.2 BTC).
These authenticators implement WebAuthn standard to enforce cryptographic origin binding between the authenticator and the specific domains it can authenticate to, rendering lookalike domains and AiTM proxies ineffective.