Threat Actor Unknown origin

UNC6671

UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter credentials on a victim-branded site. They have gained access to Okta customer accounts and employed PowerShell to download sensitive data from SharePoint and OneDrive. Their extortion tactics include aggressive harassment of victim personnel, and they have used unbranded extortion emails with different Tox IDs for communication. The threat actors have shown a preference for registering domains with Tucows, indicating potential operational differences from related threat groups.

Indicators of Compromise 25

MITRE ATT&CK TTPs 41

T1003
OS Credential Dumping
Credential Access
T1020
Automated Exfiltration
Exfiltration
T1027
Obfuscated Files or Information
Defense Evasion
T1059
Command and Scripting Interpreter
Execution
T1059.001
PowerShell
Execution
T1059.003
Windows Command Shell
Execution
T1071.001
Web Protocols
Command And Control
T1071.004
DNS
Command And Control
T1078
Valid Accounts
Defense Evasion
T1078.004
Cloud Accounts
Defense Evasion
T1087
Account Discovery
Discovery
T1087.003
Email Account
Discovery
T1090
Proxy
Command And Control
T1090.002
External Proxy
Command And Control
T1095
Non-Application Layer Protocol
Command And Control
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1110.001
Password Guessing
Credential Access
T1114
Email Collection
Collection
T1133
External Remote Services
Persistence
T1190
Exploit Public-Facing Application
Initial Access
T1213
Data from Information Repositories
Collection
T1480
Execution Guardrails
Defense Evasion
T1482
Domain Trust Discovery
Discovery
T1486
Data Encrypted for Impact
Impact
T1495
Firmware Corruption
Impact
T1496
Resource Hijacking
Impact
T1529
System Shutdown/Reboot
Impact
T1530
Data from Cloud Storage
Collection
T1531
Account Access Removal
Impact
T1538
Cloud Service Dashboard
Discovery
T1538.001
T1538.001
T1555
Credentials from Password Stores
Credential Access
T1566
Phishing
Initial Access
T1566.002
Spearphishing Link
Initial Access
T1567
Exfiltration Over Web Service
Exfiltration
T1567.001
Exfiltration to Code Repository
Exfiltration
T1567.002
Exfiltration to Cloud Storage
Exfiltration
T1568
Dynamic Resolution
Command And Control
T1568.002
Domain Generation Algorithms
Command And Control
T1611
Escape to Host
Privilege Escalation

Source Articles

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft identified two distinct attack campaigns targeting enterprise cloud environments. The first involved a large-scale phishing campaign using CEO impersonation and AI-generated content to trick finance teams into executing fraudulent ACH transfers. The second, more technically sophisticated campaign used social engineering around passkey and MFA updates to compromise Microsoft cloud identities, enabling persistent access through adversary-in-the-middle attacks and abuse of Microsoft Graph API for reconnaissance and data exfiltration. The activity is attributed to multiple threat actor groups, including Storm-3121 and Storm-3032 (UNC6671), with infrastructure linked to known cybercrime collectives.
hacker-news ·1w ago
Passkey-themed phishing attacks lead to Microsoft 365 data theft
Threat actors linked to ShinyHunters, Helix, and other extortion gangs are conducting passkey and single sign-on-themed phishing campaigns to compromise corporate Microsoft 365 accounts. The attacks begin with social engineering via phone or messaging, impersonating IT help desks to trick employees into visiting phishing sites or authorizing device-code authentication, enabling adversary-in-the-middle attacks. Attackers perform extensive reconnaissance using Microsoft Graph, persist by adding attacker-controlled MFA methods, and exfiltrate data from SharePoint, OneDrive, and Exchange over prolonged periods to evade detection.
bleeping-computer ·1w ago
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
A threat cluster tracked as PREY-0058 by Arctic Wolf is conducting data theft and extortion attacks targeting Microsoft 365 users, primarily executives, through vishing (voice phishing) and adversary-in-the-middle (AitM) attacks. Attackers impersonate IT help desk personnel and direct victims to malicious authentication pages using domains that mimic legitimate services, such as 'mfaregister[.]com', to steal credentials and MFA tokens. These tokens are then replayed via residential proxy infrastructure to access Microsoft 365 services, enabling large-scale data exfiltration from SharePoint, OneDrive, Exchange, and Box without deploying malware or moving laterally within networks.
hacker-news ·1w ago
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A zero-day vulnerability in Metabase, a business intelligence platform, is being exploited in the wild, allowing unauthenticated remote attackers to perform SQL injection and gain full administrator access to affected instances. This enables attackers to steal database credentials, exfiltrate data, and modify configurations. The vulnerability has a CVSS score of 10.0 but lacks a CVE identifier. One confirmed victim is Framework. Additionally, Chinese-made Zbtlink routers were found shipping with a factory-installed backdoor that phones home to Chinese C2 servers every 35 seconds, affecting at least 20 models. The backdoor enables remote command execution. Separately, the threat actor UNC6671 is conducting vishing attacks against financial firms, using voice phishing to capture credentials and MFA tokens via adversary-in-the-middle infrastructure, then deploying scripts for data exfiltration from cloud environments.
hacker-news ·1mo ago
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
UNC6671, a financially motivated threat actor group, is conducting vishing attacks to steal credentials and multi-factor authentication tokens by impersonating IT help desk personnel and contacting employees on their personal mobile devices. The attackers use adversary-in-the-middle (AitM) infrastructure to capture credentials and session tokens, enabling access to SaaS platforms such as Microsoft 365 and Okta. The group operates under multiple extortion brands including Redact, Pink, Helix, and Falcon, and has exfiltrated data from organizations in North America, Australia, and the U.K., collecting over $10.6 million in Bitcoin between January and May 2026. Google and CrowdStrike assess that the group leverages social engineering rather than technical vulnerabilities, highlighting the need for phishing-resistant MFA and improved session controls.
hacker-news ·1mo ago
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A cybercriminal group tracked as UNC6671, previously known as BlackFile, has been conducting vishing attacks against hedge funds, private-equity firms, and other financial organizations. The attackers spoof corporate helpdesks and trick employees into visiting phishing domains that steal credentials and session cookies via adversary-in-the-middle kits. After gaining access to Microsoft 365 or Okta single-sign-on accounts, they exfiltrate data from linked cloud services and suppress detection by deleting security notifications. The group has diversified its extortion operations under multiple brand names including Redact, Pink, Helix, and Falcon, though Falcon claims it is only affiliated with Redact.
bleeping-computer ·1mo ago