Skip to main content
Emerging ThreatsMalware & Ransomware

UNC6671 Targets SaaS Data with Vishing Attacks

Person looks concerned at mobile phone with blurred figure in help-desk uniform in background.

"UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices," Google Threat Intelligence Group (GTIG) and Mandiant said.

UNC6671's vishing and AitM workflow

The group dubbed UNC6671 uses social engineering over personal mobile phones as the opening move. Callers impersonate internal help-desk staff, create urgency around account or security migrations, and direct victims to spoofed login portals. Those portals are front ends for adversary-in-the-middle (AitM) infrastructure that captures credentials and multi-factor authentication (MFA) tokens in real time. Captured authentication data and session tokens are then used to establish authenticated sessions and to move laterally across an organization’s SaaS estate, including Microsoft 365 and Okta, according to GTIG and Mandiant.

Extortion brands and a rapid timeline

UNC6671 has distributed its operations across multiple public extortion brands — Redact, Pink (aka CL-CRI-1147), Helix, and Falcon (aka CL-CRI-1182) — and previously operated under a brand called BlackFile (aka CL-CRI-1116) until that name was retired May 11, 2026. Google laid out a compact timeline of events: the cluster emerged in early January 2026; the BlackFile data leak site (DLS) launched February 6, 2026; it went offline in late April; briefly resurfaced May 11 announcing a shutdown under that name; and operators stated on May 19 that BlackFile operations were permanently ceased. New DLS activity followed, with a Pink site launching May 31 and Redact claiming hijack and infighting on June 27.

Targets, payments, and negotiation dynamics

The group targets organizations across North America, Australia, and the U.K., and has shifted industry focus month to month — from manufacturing, real estate, healthcare, and insurance in April–May 2026, to technology, transportation, and hospitality in June, and to high-value financial and legal organizations in July. Google tracked over $10.6 million in Bitcoin payments to wallets associated with the group between January 7 and May 12, 2026. Initial ransom demands were recorded above $3 million; attackers commonly offered reductions during negotiation, and in more than 53% of tracked cases they settled for an average of $750,000.

Technical tradecraft: persistence, hosting, and provenance

CrowdStrike (tracking the umbrella as Cordial Spider) and other researchers describe a set of recurring technical practices. After harvesting credentials, adversaries register attacker-controlled MFA devices to compromised accounts and remove legitimate MFA devices, gaining persistence and a "single point entry" to SaaS ecosystems through an organization’s identity provider (IdP). Operators deploy automated Python and PowerShell scripts to exfiltrate data from cloud environments and SaaS apps.

Phishing infrastructure is gated and tailored: SOCRadar’s June 2026 analysis found Okta- and Microsoft Entra ID‑specific phishing kits, access gates to block researchers, and hosting on Cloudflare and DDoS‑Guard with domain registration via Tucows and Nicenic. UNC6671 also uses generic root domains purporting to be passkey/MFA/SSO help sites — examples named in the report include passkeyhelpdesk[.]com, setupsso[.]com, and idokta[.]com — appending victim-specific subdomains to scale targeted voice-phishing campaigns. In several cases the same domain was used to target two separate victims, each claimed by different extortion brands such as Falcon and Helix.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: The report underscores the limits of knowledge‑based and device‑bound MFA when AitM pages and session token capture are in play. Recommended mitigations cited by Google include enforcing phishing‑resistant MFA, integrating SaaS apps with single sign‑on (SSO), implementing session controls, restricting authentication to trusted network sources, and monitoring IdP logs for suspicious MFA registration events.
  • Affected enterprises and procurement leaders: The attackers favor corporate compromise via IdP abuse rather than exploiting vendor product vulnerabilities, meaning investments in SSO hardening, corporate‑managed device requirements, and tooling that alerts on corporate password hashes being entered into unauthorized domains should be prioritized.
  • End users and business employees: Callers are likely to appear urgent and plausible — they may even spoof internal phone numbers and insist on an "alternate way" to access tickets. The Bridewell‑documented case described by security researcher Joshua Penny shows an employee redirected to a presumed fraudulent Okta page; existing controls blocked credential entry in that instance, and the caller disconnected when asked for time to verify.

UNC6671’s operations, as described by GTIG, Mandiant, CrowdStrike and other analysts, read like a decentralized corporate network: shared infrastructure, multiple public brands, and rapid negotiation cycles. Whether the visible fragmentation is the result of affiliates, a splintering crew, or outsourced negotiators, the immediate fact is concrete — attackers are weaponizing phone‑based social engineering to turn identity systems into a single pivot for widespread cloud theft. The next practical question for defenders is not whether this vector exists, but how quickly organizations can harden identity flows and detect anomalous IdP activity before a single compromised session becomes a full SaaS‑estate breach.

https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html