Google tracks UNC6671 across new extortion brands
Google Threat Intelligence Group says UNC6671 has continued data-theft extortion activity after the alleged retirement of the BlackFile brand in May 2026. The group is now associated by Google with multiple public extortion fronts, including Redact, Pink, Helix and Falcon. The reported campaign is centered on helpdesk-themed voice phishing, credential interception and cloud data theft from enterprise environments such as Microsoft 365 and Okta.Shared infrastructure ties the brands together
GTIG assessed that overlaps in phishing templates, victim targeting and infrastructure connect BlackFile, Redact, Pink, Helix and Falcon activity. The firm said the evidence supports a common group of affiliated actors, while leaving open alternative explanations such as splintered affiliates or shared phishing-as-a-service infrastructure.The common pattern matters more than the public name used in an extortion message. Google described repeated use of generic root domains themed around passkeys, MFA and SSO, with victim-specific subdomains used for tailored campaigns. In practice, that means defenders should track behavioral and infrastructure patterns rather than treating a new leak-site brand as a clean break from earlier activity.
The intrusion path starts with helpdesk vishing
The reported initial access method is voice phishing against enterprise employees, with callers posing as IT helpdesk staff responsible for urgent security migrations. GTIG said the actors often call personal mobile devices, which can place the interaction outside normal corporate communications controls and make verification harder for the targeted employee.The pretext is built around enabling passkeys or updating MFA enrollment. Victims are directed to lookalike login pages where adversary-in-the-middle infrastructure can capture credentials and MFA tokens. Once account persistence is established, Google said the actors use automation to exfiltrate data from enterprise cloud services, including Microsoft 365 and Okta. The defensive implication is direct: security teams need controls that assume a valid user may be socially engineered, not only controls that look for malware on a workstation.
Financial and legal targets became more prominent
Google reported a shift in targeting over the spring and summer of 2026. Between April and May, observed domains were broadly aimed at large enterprises across sectors including manufacturing, real estate, healthcare and insurance. In June, observed targeting moved toward large technology, transportation and hospitality organizations.By July, GTIG said the profile narrowed toward financial and legal sectors, including private equity firms, law firms and financial rating agencies. The firm linked that focus to organizations likely to hold confidential corporate information, including merger, acquisition, capital deployment and litigation-related data. That does not prove every listed sector organization was breached, but it does show why identity controls at cloud-heavy financial and professional-services firms are now a priority risk area.
Google reports faster infrastructure provisioning
GTIG also described an increase in operational tempo. It said newly observed infrastructure between June 1 and July 31 was provisioned at approximately one domain every 1.6 days, compared with one every 2.2 days between April 1 and May 31, when 28 root domains were observed.A short spike occurred between July 20 and July 22, when seven domains were operationalized within 72 hours, according to the report. Google also said that, on the publication date of its blog, seven of eight still resolving phishing domains did not use wildcard DNS, suggesting that targets found through passive DNS were likely specifically selected. For defenders, the lesson is that blocking old indicators is not enough when infrastructure can be created and used quickly.
Bitcoin analysis points to continued monetization
The report includes blockchain analysis of BlackFile-linked Bitcoin wallets. Between January 7 and May 12, 2026, GTIG reviewed 18 wallet addresses that received 141.65 BTC, worth about $10.69 million at the time of the transactions. Google said payments continued after the publicized BlackFile data leak site shutdown notice on May 11.GTIG reported that initial ransom demands typically ranged from $1 million to more than $3 million, with operators often accepting reductions of 50% to 75% during negotiations. In more than 53% of tracked cases in that period, final payments averaged $750,000, or about 10.2 BTC. These figures are not a forecast and are not investment information; they are Google’s retrospective analysis of alleged extortion payment flows.
Defensive priorities focus on identity and SaaS telemetry
Google’s recommended mitigations focus on identity resilience, session control and cloud activity monitoring. The strongest control named in the report is phishing-resistant MFA, including FIDO2-compliant security keys, passkeys and platform authenticators that bind authentication to the legitimate domain.GTIG also recommends bringing critical SaaS and cloud platforms under consistent SSO policy, limiting session duration, enforcing step-up authentication for sensitive resources and restricting access to trusted networks or corporate-managed devices. Monitoring should include identity provider logs for suspicious MFA enrollment patterns and SaaS audit telemetry for high-volume or automated file access. The practical goal is to make stolen credentials and intercepted sessions less useful, while giving security teams earlier signals when cloud data access stops resembling normal user behavior.
Conclusion
UNC6671 shows how extortion branding can change while the core intrusion model remains stable. According to GTIG, the relevant pattern is not only BlackFile, Redact, Pink, Helix or Falcon, but the repeated combination of helpdesk vishing, adversary-in-the-middle credential theft and cloud data exfiltration.For financial services, legal and other data-rich enterprises, this turns identity security into a front-line extortion control. Phishing-resistant authenticators, tighter session policy, managed-device requirements and SaaS behavior monitoring are not cosmetic hardening steps; they directly target the path Google described in these intrusions.
Sources
Editorial Team - CoinBotLab