Actor Profile

UNC6671 is a financially motivated data extortion group that emerged in early January 2026. The actor operates multiple extortion brands including Redact, Pink (CL-CRI-1147), Helix, and Falcon (CL-CRI-1182), and previously operated under the BlackFile (CL-CRI-1116) brand until its retirement in May 2026. CrowdStrike tracks this umbrella collective as Cordial Spider. UNC6671 was first documented by Google as one of the threat clusters leveraging tradecraft traditionally associated with ShinyHunters (Bling Libra), though the groups are assessed to operate independently. The actor's primary motivation is financial gain through rapid data theft and extortion campaigns, having collected over $10.6 million in Bitcoin payments between January 7 and May 12, 2026. UNC6671 maintains a high operational cadence, targeting dozens of organizations primarily in North America, Australia, and the U.K.

TTPs (Tactics, Techniques, Procedures)

UNC6671 employs sophisticated social engineering and technical capabilities. Primary initial access is achieved through voice phishing (vishing), where attackers impersonate IT help desk staff and contact employees via personal mobile devices, often spoofing legitimate help desk phone numbers. Victims are directed to adversary-in-the-middle (AitM) phishing infrastructure that intercepts credentials and multi-factor authentication tokens in real time. The actor uses tailored Okta and Microsoft Entra ID phishing kits hosted on generic root domains with victim-specific subdomains (e.g., passkeyhelpdesk[.]com, setupsso[.]com, idokta[.]com). For persistence, UNC6671 registers adversary-controlled MFA devices to compromised accounts after removing existing MFA devices. The group exploits trust relationships between identity providers and connected services to move laterally across SaaS ecosystems with single authenticated sessions. Data exfiltration is conducted using automated Python and PowerShell scripts targeting Microsoft 365, Okta, and other enterprise cloud environments. For defense evasion, the actor systematically deletes password-reset confirmations and security alerts from compromised email accounts. Infrastructure protection includes access gates to block sandboxes and researchers, with hosting via Cloudflare and DDoS-Guard, and domain registration through Tucows and Nicenic.

Targets & Patterns

UNC6671 targets high-value organizations across financial services, private equity, and professional services sectors. The actor demonstrates a pattern of shifting targeting focus over time: large enterprises in manufacturing, real estate, healthcare, and insurance during April-May 2026; technology, transportation, and hospitality firms in June 2026; and high-value financial and legal organizations in July 2026. This evolution suggests the group is pursuing increasingly lucrative targets as their operations mature. Geographic targeting focuses on North America, Australia, and the United Kingdom. The actor specifically targets enterprise employees who have access to SaaS applications and identity platforms, exploiting the single point of entry provided by compromised identity providers to access multiple connected services. The focus on Big Game Hunting tactics indicates UNC6671 selects victims based on their ability to pay substantial extortion demands, as evidenced by the millions collected in Bitcoin payments.

Historical Context

UNC6671 emerged in early January 2026 and launched the BlackFile Data Leak Site on February 6, 2026. The BlackFile brand went offline in late April 2026, briefly returned on May 11, 2026 with a shutdown message, and was officially ceased by May 19, 2026 when Redact operators announced permanent closure. The actor then diversified operations across multiple brands: Pink DLS launched May 31, 2026, followed by Redact, Helix, and Falcon. On June 27, 2026, Redact claimed the BlackFile brand had been compromised and hijacked by a former associate conducting unsanctioned extortion campaigns. This adoption of multiple public extortion brands is assessed as an attempt to monetize operations, compartmentalize negotiations, and frustrate tracking efforts. UNC6671 shares tradecraft similarities with ShinyHunters (Bling Libra) but is assessed to operate independently. The group has maintained consistent vishing and SSO compromise tactics throughout its operational history while continuously refining infrastructure and targeting strategies.

Defensive Recommendations

  • Deploy phishing-resistant MFA solutions (e.g., FIDO2/WebAuthn hardware tokens) that cannot be intercepted by AitM attacks, particularly for identity provider and SaaS application access
  • Implement user awareness training specifically focused on vishing tactics, emphasizing verification procedures when contacted by IT help desk staff, especially on personal mobile devices
  • Monitor for suspicious MFA device registrations and removals, particularly when existing MFA devices are deleted and replaced with new devices in rapid succession
  • Block or monitor access to known malicious domains associated with UNC6671 infrastructure (passkeyhelpdesk[.]com, setupsso[.]com, idokta[.]com) and implement DNS filtering for newly registered domains using similar naming patterns
  • Establish baseline behavioral analytics for SaaS application access patterns and alert on anomalous PowerShell or Python script execution, particularly automated data exfiltration activities targeting Microsoft 365 and Okta environments