The Evolution of Cybercrime: Vishing Tactics Rebranded by UNC6671
In a striking development within the realm of cybercrime, a group once identified as BlackFile has resurfaced under a new guise, targeting several prominent financial and professional services. This alarming trend has attracted significant attention, especially with high-profile names like Apollo Global Management, KKR, and Moody’s among the confirmed targets. The traditional understanding of cybercriminal behavior is evolving, as evidenced by this group’s rebranding efforts and continued operations.
According to threat researchers at Google, telemetry collected from various attacks has revealed that a group now operating under the designation UNC6671 has roots tracing back to BlackFile. BlackFile had announced its purported retirement in May 2026; however, rather than exiting the cybercrime landscape, the group simply rebranded, continuing its operations under new names such as Redact, Pink, Helix, and Falcon, each operating its own data-leak site. This shift raises questions about the true motivations and strategies of modern cybercriminal organizations.
Google’s research indicates that the tactics employed by these newly minted extortion groups remain surprisingly consistent despite their rebranding. Initial access tactics such as voice phishing (or "vishing") and single sign-on compromise show a level of familiarity and efficiency among these criminal entities. The post-intrusion tactics, techniques, and procedures employed are also notably steadfast. In a related report, Bloomberg underscored the threats posed to major hedge funds, amplifying concerns about the frequency and sophistication of these attacks.
Austin Larsen, a principal threat analyst at Google Threat Intelligence Group, provided insight into the evolving nature of these tactics. He highlighted that the shift in targeting appears to stem from a monetary motivation. The actors behind these sophisticated schemes perceive that firms in the financial sector possess sensitive data that would compel them to pay hefty ransoms to safeguard their information. As Larsen noted, while the tactics may not necessarily be advanced, their effectiveness cannot be underestimated.
Recent reports from Reuters have revealed even more shocking revelations regarding the scope of this cybercriminal campaign. Evidence indicates that these actors have developed a comprehensive roadmap targeting over 200 companies in just five weeks, which extends beyond finance-related institutions. Notable companies such as ride-sharing giant Uber, housing app Zillow, jeans retailer Levi Strauss, and respected law firms like Paul Hastings and Greenberg Traurig have also drawn the ire of these cybercriminals.
The methods employed by the new brand-name entities involve acting as help desk staff, often calling employees under the pretense of conveying urgent security updates. This level of deception is alarming, showing that these groups are not only focused on breaching systems but are also skilled in social engineering. In some cases, they have gone so far as to contact employees’ personal devices, spoofing the legitimate IT help desk numbers to bypass corporate controls effectively.
Part of their strategy involves instructing individuals to enable emergency security measures, such as activating FIDO2 passkeys or updating multifactor authentication enrollment. The guidance provided during these phone calls often directs unsuspecting employees to lookalike credential-harvesting subdomains that mimic the legitimate company sites. These subdomains, which might include URLs like .addssopasskey.com or .passkeyhelpdesk.com, are designed to deceive and harvest sensitive login credentials and multifactor tokens.
Once the attackers gain entry, they employ automated scripts for data exfiltration from enterprise cloud environments such as Microsoft 365 and Okta. This capability significantly enhances their ability to manipulate and extract valuable data from organizations that they target.
The apparent need for rebranding might be driven by the desire of these criminals to avoid unnecessary attention while capitalizing on their lucrative operations. Google reported that, between January and May of 2026, Bitcoin wallets linked to BlackFile received 141.65 bitcoins, totaling around $11 million in transaction value. Intriguingly, these payments continued flowing even after BlackFile’s announcement of their retirement in May, suggesting that the group was actively cashing out their earnings during this period.
It has been observed that the ransom demands from these actors often exceed $1 million, but negotiations frequently result in reduced payments, averaging around $750,000 across more than half of tracked cases. This approach exemplifies their business-like operations within the cybercriminal underground.
As observed through various studies and reports, it becomes increasingly evident that the landscape of cybercrime is adapting and evolving. Organizations must remain vigilant and proactive in their cybersecurity measures to mitigate the risks posed by these rebranded extortionists. As cybercriminal groups like UNC6671 continue to redefine their tactics, the battle against cybercrime remains a formidable challenge for businesses and individuals alike.
