bleeping-computer · Crawled Aug 7, 2026

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

1 Actors
Read original article ↗

AI Summary

A cybercriminal group tracked as UNC6671, previously known as BlackFile, has been conducting vishing attacks against hedge funds, private-equity firms, and other financial organizations. The attackers spoof corporate helpdesks and trick employees into visiting phishing domains that steal credentials and session cookies via adversary-in-the-middle kits. After gaining access to Microsoft 365 or Okta single-sign-on accounts, they exfiltrate data from linked cloud services and suppress detection by deleting security notifications. The group has diversified its extortion operations under multiple brand names including Redact, Pink, Helix, and Falcon, though Falcon claims it is only affiliated with Redact.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 41 techniques

T1003 OS Credential Dumping · Credential Access T1020 Automated Exfiltration · Exfiltration T1027 Obfuscated Files or Information · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1078 Valid Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1087 Account Discovery · Discovery T1087.003 Email Account · Discovery T1090 Proxy · Command And Control T1090.002 External Proxy · Command And Control T1095 Non-Application Layer Protocol · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1110.001 Password Guessing · Credential Access T1114 Email Collection · Collection T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1213 Data from Information Repositories · Collection T1480 Execution Guardrails · Defense Evasion T1482 Domain Trust Discovery · Discovery T1486 Data Encrypted for Impact · Impact T1495 Firmware Corruption · Impact T1496 Resource Hijacking · Impact T1529 System Shutdown/Reboot · Impact T1530 Data from Cloud Storage · Collection T1531 Account Access Removal · Impact T1538 Cloud Service Dashboard · Discovery T1538.001 T1538.001 T1555 Credentials from Password Stores · Credential Access T1566 Phishing · Initial Access T1566.002 Spearphishing Link · Initial Access T1567 Exfiltration Over Web Service · Exfiltration T1567.001 Exfiltration to Code Repository · Exfiltration T1567.002 Exfiltration to Cloud Storage · Exfiltration T1568 Dynamic Resolution · Command And Control T1568.002 Domain Generation Algorithms · Command And Control T1611 Escape to Host · Privilege Escalation