Skip to main content

Tag: unc6671

8 articles

A brightly-lit financial sector setting with a sense of unease, featuring a blurred laptop screen and empty whiteboard in…

BlackFile Targets Financial Firms in Ongoing Extortion Campaign

Financial firms are under attack by a relentless extortion group called BlackFile, which has been targeting the sector with alarming persistence since the start of the year. This threat actor has also set its sights on other industries, including med tech, with no signs of slowing down.

Analyst 207
Person looks concerned at mobile phone with blurred figure in help-desk uniform in background.

UNC6671 Targets SaaS Data with Vishing Attacks

Beware of voice phishing scams where attackers pose as IT help desk staff, contacting employees on their personal mobile devices with urgent security migration requests that lead to fake login portals. These clever scams capture sensitive credentials and multi-factor authentication tokens in real-time, putting your SaaS data at risk.

Analyst 207
Cluttered desk with laptop, papers, and empty pizza boxes in a dimly lit room.

Google Exposes Redact Extortion Group's Ties to BlackFile Rebrand

Google's Threat Intelligence Group uncovered a clever rebranding scheme by the notorious extortion group formerly known as BlackFile, which has now resurfaced under the name Redact, after allegedly being hijacked by a rogue affiliate. The group had claimed retirement, but clearly wasn't done causing trouble, raking in around $10.69 million in Bitcoin transactions.

Analyst 207
Blurred device screen on a desk in a busy financial office with employees in the background.

Cyberattacks on Hedge Funds Tied to UNC6671 Extortion Group

Meet UNC6671, a notorious extortion group linked to a string of cyberattacks on hedge funds, operating under a web of public brands to deceive and exploit its victims. Using voice-phishing tactics, the group tricks employees into divulging sensitive info, paving the way for a potentially devastating breach.

Analyst 207
Person receiving phone call in office setting with blurred phone screen and computer in background.

Google Exposes BlackFile Extortion Operation's Tactics

Google's Threat Intelligence Group just exposed the clever tactics of the notorious BlackFile extortion operation, revealing how they use voice phishing and sneaky tech tricks to swindle dozens of organizations worldwide. Their clever scheme starts with a simple phone call, where fake IT helpers trick victims into spilling their secrets.

Analyst 207
Brightly-lit retail setting with a point-of-sale terminal in the foreground, hinting at unease.

BlackFile Targets Retail, Hospitality with Extortion Attacks

Meet BlackFile, a notorious extortion group wreaking havoc on the retail and hospitality sectors with high-stakes attacks, demanding seven-figure ransoms from its victims. With a modus operandi that includes impersonation and voice-phishing, this threat actor is using pressure tactics to get what they want.

Analyst 207
Person interacting with a blurred payment terminal in a retail setting.

BlackFile Group Launches Vishing Attacks on Retail, Hospitality Firms

Retail and hospitality firms are under siege from a financially motivated threat group, known as BlackFile Group, that's launching vishing attacks to extort money, with a campaign that has been quietly escalating since February 2026. This persistent threat uses no custom malware, making it a stealthy and formidable foe.

Analyst 207
Retail customer service desk with blurred computer screen nearby in daytime setting.

BlackFile Targets Retail with Vishing Extortion Tactics

Meet BlackFile, a financially motivated group that's been wreaking havoc on retail and hospitality organizations with a clever vishing extortion tactic, posing as IT support staff to steal data since February 2026. They're using spoofed VoIP numbers and fake Caller ID names to pull off their scams.

Analyst 207