VYPR
advisoryPublished Aug 6, 2026· 1 source

UNC6671 Rebrands as REDACT, Expands Multi-Brand Vishing Extortion

The threat actor UNC6671, formerly known as BlackFile, has rebranded to REDACT and is actively diversifying its extortion operations under multiple aliases, targeting financial services and enterprise cloud environments with multi-brand vishing tactics.

Google Threat Intelligence Group (GTIG) continues to track the threat actor UNC6671, which remains active in data theft extortion operations despite the alleged retirement of its BlackFile brand in May 2026. Analysis of telemetry and infrastructure reveals that UNC6671 has not disbanded but has instead diversified its operations across several distinct extortion fronts, including REDACT, Pink, Helix, and Falcon. This strategic rebranding and diversification allow the group to maintain operational tempo and potentially evade detection.

The group's modus operandi consistently involves voice phishing (vishing) to target enterprise employees. Attackers pose as IT helpdesk staff, claiming to facilitate urgent security migrations. Notably, these calls are often directed at employees' personal mobile devices, luring them to spoofed login portals. These portals are designed to intercept credentials and multi-factor authentication (MFA) tokens through Adversary-in-the-Middle (AiTM) infrastructure. Once session persistence is achieved, the actors deploy automated scripts to exfiltrate data from cloud environments, specifically targeting platforms like Microsoft 365 and Okta.

While the initial access and post-compromise tactics, techniques, and procedures (TTPs) employed by UNC6671 have remained remarkably consistent across intrusions—leveraging vishing, AiTM credential harvesting, and SaaS data theft—the extortion messaging and data leak sites (DLS) have varied. Public statements from the group cited an affiliate breakaway as the reason for the initial rebrand to Redact. However, subsequent overlaps in phishing templates, victimology, and shared infrastructure conduits suggest a common set of threat actors are behind these various brands.

On June 27, 2026, the operators behind the Redact brand published a statement on their new DLS, detailing their alleged rebrand from BlackFile. They claimed that the original BlackFile brand had been compromised and hijacked by a former affiliate who operated an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns. According to Redact, this rogue affiliate intentionally orchestrated the "shutdown" of the BlackFile brand to create confusion among threat intelligence analysts and cyber insurance negotiators, thereby damaging the brand's reputation. Redact asserted that their rebranding was solely to distance themselves from this rogue activity and introduced a single verified Tox ID and PGP key for authentication.

Analysis of UNC6671's infrastructure reveals a shared ecosystem connecting these various phishing operations. The threat actors reuse generic root domains, often masquerading as passkey-related services, and append victim-specific subdomains to facilitate targeted vishing campaigns. This consistent digital footprint has exposed overlaps in victim targeting across multiple extortion brands, supporting the assessment that a common group of actors is affiliated with BlackFile, Redact, Pink, Helix, and Falcon. While other scenarios like splintered affiliates or shared Phishing-as-a-Service infrastructure are plausible, the evidence points to a unified operational base.

Specific examples highlight this shared infrastructure. The root domain passkeyhelpdesk[.]com was used to target organizations extorted under both the Falcon and Helix brands. Similarly, domains like portalpasskey[.]com and addssopasskey[.]com, used by Falcon, hosted intermediate targets that bridged directly into Helix infrastructure. The Pink brand utilized domains such as passkeyms[.]com and mysecurepasskey[.]com as intermediate bridges to infrastructure focused on passkeydeploy[.]com, which was also used to target BlackFile victims. This intricate web of shared domains and intermediate targets demonstrates a deliberate strategy to consolidate resources and potentially monetize compromised data across multiple fronts.

UNC6671's recent targeting has expanded to include financial services, private equity, and professional services firms. This shift in focus, combined with their sophisticated vishing and AiTM techniques, poses a significant threat to organizations in these sectors. The group's ability to operate under multiple aliases and leverage shared infrastructure makes them a persistent and adaptable adversary. Organizations are advised to implement robust security measures, including enhanced employee training on phishing and vishing, strict MFA policies, and continuous monitoring of cloud environments for suspicious activity.

Synthesized by Vypr AI