CyberSecurity SEE

Google Links Redacted Extortion Group to BlackFile Rebrand

Google Links Redacted Extortion Group to BlackFile Rebrand

The notorious BlackFile extortion group, known for its vishing scams, has recently undergone a significant rebranding to a new name: Redact. An analysis published by the Google Threat Intelligence Group (GTIG) reveals that, despite the group’s intention to retire the BlackFile brand by 2026, it has instead opted to move forward with a new identity.

The researchers at GTIG noted that the group’s official communication attributed the rebrand to a split with an affiliate. However, even with this change, evidence suggests that there is continuity in certain aspects of their operations. The use of similar phishing templates, overlapping victim profiles, and shared infrastructure has led many experts to believe that the actors associated with BlackFile have also been utilizing the extortion brands Pink, Helix, and Falcon to enhance their financial gains.

On June 27, the newly rebranded Redact released a blog entry detailing their new Data Lead Site (DLS) alongside their transformation from BlackFile. In this announcement, the group claimed that the original BlackFile name had been compromised by an exiled affiliate, who was allegedly responsible for operating a fraudulent, lookalike DLS. This rogue affiliate is said to have conducted unauthorized extortion campaigns using unassociated Tox identities and played a key role in engineering the supposed retirement of BlackFile in May 2026.

Despite the name change, experts from GTIG have pointed out that the organization’s threat tactics, techniques, and procedures (TTPs) have remained largely unchanged. The group’s activities suggest that multiple coordinated actors may be operating under different public extortion brands. This strategy appears to be aimed at compartmentalizing their operations, thereby obscuring the overall number of breaches and minimizing the impact of any fallout during negotiations.

The method of choice for Redact remains the audacious technique of voice phishing, or vishing, which targets employees within enterprises. Craftily pretending to be IT helpdesk personnel, the group lures victims into believing they must complete urgent security migrations. Typically, personal devices are the conduits through which victims are contacted.

During these deceptive calls, targets are guided to fake login portals wherein an Adversary-in-the-Middle (AiTM) infrastructure captures not only their credentials but also any multi-factor authentication (MFA) tokens they might have. Once the attackers secure session persistence, they employ automated scripts for data exfiltration, primarily focusing on enterprise cloud environments, including prominent platforms like Microsoft 365 and Okta.

GTIG’s in-depth investigation has identified substantial overlaps among the extortion brands connected to BlackFile, Redact, Pink, Helix, and Falcon. Instead of maintaining isolated infrastructures for each operation, it appears that UNC6671, the underlying group, utilizes shared root domains across various target organizations. For instance, domains such as passkeyhelpdesk[.]com and passkeydeploy[.]com have been used by multiple groups simultaneously.

Furthermore, GTIG found that identical phishing templates were employed across these domains. Some of these domains were reported to have been used to target distinct victims—one being attributed to Falcon and another to Helix. This widespread application of matching templates strongly indicates a reliance on shared infrastructure to harvest credentials for different DLS brands.

In a significant development, UNC6671 has started to adopt new techniques, such as spoofing legitimate helpdesk phone numbers. This tactic is part of a broader strategy that involves less straightforward pretexts for their calls, steering employees toward hastily enabling FIDO2 passkeys or modifying multi-factor authentication setups. The actors guide them toward lookalike credential-harvesting subdomains to maximize their success rate.

The group’s targeting strategy has morphed considerably from April to July 2026. Initially focused on substantial enterprises in sectors like manufacturing, real estate, healthcare, and insurance from April to May, it subsequently transitioned to technology, transportation, and hospitality firms. By July, their focus narrowed further to high-value financial and legal organizations, comprising private equity firms, law firms, and credit rating agencies.

GTIG’s review of BlackFile’s Bitcoin wallets from January 7 to May 12 uncovered that 18 wallet addresses collectively received 141.65 BTC, amounting to roughly $10.69 million USD at the time. Alongside this troubling trend, the intelligence group has issued recommendations for curbing such extortion campaigns. Proposed measures include implementing phishing-resistant authentication systems, integrating single sign-on (SSO), enforcing tighter session controls to limit session duration, and restricting authentication practices to secure network sources.

As vishing scams predominantly target personal devices, GTIG stresses that companies should prioritize authenticating access through corporate-managed endpoints employing Mobile Device Management (MDM) and Endpoint Detection and Response (EDR) solutions, thereby enhancing their security posture against attacks from groups like Redact.

Source link

Exit mobile version