Skip to main content
Emerging ThreatsMalware & Ransomware

Google Exposes Redact Extortion Group's Ties to BlackFile Rebrand

Cluttered desk with laptop, papers, and empty pizza boxes in a dimly lit room.

Between January 7 and May 12, Google Threat Intelligence Group (GTIG) reviewed 18 BlackFile Bitcoin wallet addresses that received a total of 141.65 BTC — approximately $10.69m USD at the time of the transactions.

Rebrand: BlackFile declared retired, returned as Redact

GTIG’s analysis shows that the extortion group long tracked as BlackFile (UNC6671) announced the retirement of its brand in 2026 but resurfaced under the name Redact. The operators published a blog post on June 27 about a new data leak site (DLS) and the rebrand from Black File, claiming the original brand had been compromised and hijacked by an exiled affiliate. According to GTIG, the group said a rogue affiliate operated an unauthorized lookalike DLS, ran unsanctioned extortion campaigns under BlackFile’s name using unlinked Tox identities, and was responsible for an apparent May 2026 shutdown of the BlackFile brand.

Vishing, spoofed helpdesks, and AiTM credential capture

Despite the name changes, GTIG reports the group’s initial-access and post-compromise techniques have “largely remained the same.” UNC6671 uses voice phishing (vishing) calls that impersonate IT helpdesk staff and instruct employees to perform urgent security migrations. Callers have been observed using a spoofed legitimate helpdesk phone number and directing targets to lookalike credential‑harvesting subdomains. The phishing funnels employ Adversary‑in‑the‑Middle (AiTM) infrastructure to intercept credentials and multi‑factor authentication (MFA) tokens. Once session persistence is established, the group deploys automated scripts to exfiltrate data from enterprise cloud environments, including Microsoft 365 and Okta.

Shared infrastructure: passkeyhelpdesk[.]com, passkeydeploy[.]com and matching templates

GTIG links BlackFile, Redact, Pink, Helix and Falcon to the same core UNC6671 activity by identifying reuse of generic root domains and identical phishing templates. Root domains such as passkeyhelpdesk[.]com and passkeydeploy[.]com were used across multiple campaigns and target organizations. The researchers noted that “the widespread deployment of these matching templates to harvest credentials for multiple DLS brands suggests they rely on shared underlying infrastructure.” In several cases GTIG observed a single domain simultaneously used to target two separate victims, with one claim credited to Falcon and the other to Helix — evidence, GTIG says, of overlapping actor groups leveraging the same technical conduits to monetize breaches under multiple public brands.

Operational shifts: sector targeting from April through July 2026

GTIG documented a notable change in UNC6671’s victimology between April and July 2026. From April to May, the group focused on large enterprises in manufacturing, real estate, healthcare and insurance. In June the focus shifted to technology, transportation and hospitality firms. By July the campaign narrowed to high‑value financial and legal organizations, including private equity firms, law firms and credit rating agencies. GTIG also observed the group using compromised email accounts to reset passwords for enterprise applications and then delete security notifications and alert emails to evade detection and maintain persistent access.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: GTIG recommends enforcing phishing‑resistant authenticators, integrating single sign‑on (SSO), enforcing session controls to reduce session length, and restricting authentication to trusted network sources. These recommendations are tied directly to UNC6671’s use of AiTM interception and session persistence.
  • Affected enterprises and procurement leaders: Firms should be aware that UNC6671 often targets employees on personal devices; GTIG advises ensuring authentication comes from a corporate‑managed endpoint protected by mobile device management (MDM) and endpoint detection and response (EDR).
  • End users and corporate helpdesk staff: The campaign’s pretext—mandatory FIDO2 passkey enablement or MFA enrollment updates—and the use of spoofed phone numbers mean staff should treat unusual urgent helpdesk calls as high‑risk and verify changes through established, corporate‑managed channels.

GTIG’s findings portray a group that has folded multiple public extortion brands into a shared operational model: compartmentalized branding sitting atop reused domains, matching phishing templates, and a vishing-first access vector that specifically targets personal devices and MFA flows. The unanswered operational question the evidence raises is whether the compartmentalization into Redact, Pink, Helix and Falcon will make detection and attribution harder or simply provide redundancy for a single underlying actor set — a core challenge defenders must address by removing the weak link UNC6671 exploits: unmanaged authentication endpoints and non‑phishing‑resistant MFA.

Read the original report at Infosecurity Magazine.