UNC6671 Extortion Group Rebrands After Targeting Hedge Funds

Google Threat Intelligence ties hedge fund vishing attacks to UNC6671 (BlackFile), an extortion group rebranding across Redact, Pink, Helix, and Falcon.
Table of Contents
    Add a header to begin generating the table of contents

    Google Threat Intelligence Group has tied a recent wave of attacks on hedge funds and private-equity firms to UNC6671, an extortion group associated with the BlackFile threat actors that now operates under multiple public brands including Redact, Pink, Helix, and Falcon. The attacks relied on voice phishing to trick employees into granting access to corporate accounts, according to reporting by Reuters and Bloomberg cited in the analysis, and several major financial firms have confirmed being targeted.

    How the UNC6671 Vishing Campaign Breached Financial Firms

    Point72 told investors it had been attacked but found no evidence that client data was stolen, while Two Sigma said it blocked an attempted intrusion and Millennium and Citadel declined to comment. The operators call employees on personal mobile phones while spoofing corporate helpdesks, claiming workers must enroll in passkeys or update multi-factor authentication settings. Victims are directed to company-impersonating domains hosting AitM phishing kits that steal credentials and session cookies in real time, after which the attackers log into the Microsoft 365 or Okta single-sign-on dashboard and gain access to every linked cloud platform.

    From Helpdesk Spoofing to Automated Data Exfiltration

    After taking control of an SSO account, the operators use automated tools to exfiltrate data and delete security notifications and password-reset emails. Google Threat Intelligence Group tracks the group as UNC6671 and assesses that a single core intrusion group drives the helpdesk vishing and cloud data theft across the various public extortion brands. The group has also evolved to spoof legitimate helpdesk phone numbers and to use compromised emails to reset passwords for non-SSO enterprise applications while deleting the confirmation messages.

    From BlackFile to Redact, Pink, Helix, and Falcon

    BlackFile first emerged in February 2025 targeting retail and hospitality, and announced a rebrand to Redact in May 2026 after its targeting shifted toward private-equity firms, hedge funds, major law firms, and financial-rating agencies. Google Threat Intelligence Group notes that the group uses generic root domains across victims such as passkeyuser.com and portalpasskey.com, alongside subdomains that incorporate individual victim names.

    The Millions in Bitcoin Payments and a $3 Million Pattern

    Between January and May 2026, Google Threat Intelligence Group tracked social engineering and negotiation across 18 addresses, with initial demands reaching upward of $3 million. In 53 percent of tracked cases, the final payments averaged $750,000. Google Threat Intelligence Group notes the group’s payments pattern illustrates that the extortionists routinely accept far less than their opening demands.

    Why This Differs From Scattered Spider

    The vishing and token-relay tactics overlap with Scattered Spider’s, but Google Threat Intelligence Group says UNC6671’s infrastructure and extortion network differ from Scattered Spider’s. Mandiant is assisting several dozen compromised organizations, and at least one brand dispute has surfaced: the Falcon extortion group publicly disputed Mandiant’s reporting, claiming it is exclusively a Redact affiliate and not affiliated with Helix or Pink.

    Why Helpdesk Vishing Now Targets Financial Payouts

    The UNC6671 pattern reflects a growing reliance on social engineering to reach cloud identity systems that otherwise resist brute-force and credential-stuffing attacks. By calling employees on their personal lines and spoofing a helpdesk, the operators bypass the perimeter and land directly on the account that controls access to the whole tenant. Financial firms, which hold the payout capacity the group seeks, are rational targets.

    Defensive Response for Financial Institutions

    Financial institutions should treat unsolicited helpdesk-style calls, especially to personal numbers, as a social-engineering vector, enforce phishing-resistant MFA, monitor for token issuance anomalies on Microsoft 365 and Okta, and verify password-reset requests out of band. No patch applies because the entry point is behavioral rather than technical. Google Threat Intelligence Group’s assessment that a single core intrusion group drives the multiple brands is the central finding, and it bears directly on defenders: the rebranding discipline the group maintains means incident responders should link brand-associated indicators to a common campaign.

    The attack wave is the strongest evidence yet that the extortion model has moved from commodity ransomware to targeted cloud-account takeover, with the negotiation model scaled to victims that can pay. As the Mandiant dispute over brand affiliations shows, the group’s outward fragmentation is now a deliberate part of how it operates, complicating law enforcement response and victim attribution.

    Related Posts