← Back to Feed
UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
August 6, 2026 · Google Cloud Security · Severity: MEDIUM
Google Threat Intelligence Group tracks UNC6671, which uses vishing to target enterprises, posing as IT helpdesk to steal credentials and MFA tokens. They have rebranded under multiple extortion brands and focus on financial services, private equity, and cloud environments.
Key Takeaways
- UNC6671 continues data theft extortion via vishing despite announced retirement of BlackFile.
- The threat actor poses as IT helpdesk to steal credentials and MFA tokens.
- UNC6671 has diversified into multiple extortion brands including Redact, Pink, Helix, and Falcon.