UNC6671 is a financially motivated cybercrime and data-extortion cluster active since early 2026 and previously associated with the BlackFile brand. The activity is also linked to the public extortion brands Redact, Pink, Helix, and Falcon, and has been tracked by some vendors as CORDIAL SPIDER. The group has shown sustained operational maturity, rapid infrastructure regeneration, and a compartmentalized operating model in which intrusion, phishing, and extortion functions may be separated across brands or roles. UNC6671 primarily gains initial access through tailored voice phishing in which operators impersonate corporate IT help-desk staff and pressure employees into urgent security actions such as passkey or MFA migrations. Victims are commonly contacted on personal mobile phones, sometimes with spoofed help-desk numbers, and directed to adversary-in-the-middle phishing portals designed to capture credentials, one-time passwords, and authenticated sessions in real time. The group has repeatedly targeted identity and SaaS environments, especially Okta and Microsoft 365, and has also abused access to connected enterprise applications such as Salesforce. Following compromise, UNC6671 has been observed establishing persistence through account and MFA-device takeover, abusing trust relationships between identity providers and downstream SaaS services, resetting passwords for non-SSO applications through compromised mailboxes, deleting security alerts and password-reset notifications to reduce user scrutiny, and conducting large-scale scripted cloud data theft. Its operations are centered on exfiltration and subsequent extortion rather than disruptive encryption. Victims are pressured with threats to publish stolen data on leak sites if payment is not made. Targeting evolved over 2026 from manufacturing, real estate, healthcare, and insurance toward technology, transportation, hospitality, and then high-value financial and professional-services organizations. Reported targeting includes financial services, private equity, hedge funds, law firms, financial ratings agencies, and other professional-services organizations, with a focus on data likely to maximize extortion leverage, including sensitive corporate, legal, investor, and transaction-related information. The cluster has targeted organizations across North America, the United Kingdom, and Australia. Public reporting links the activity to compromises and extortion claims affecting enterprises including firms in private equity, apparel, logistics, and industrial distribution, although not every observed target was confirmed breached. UNC6671 has been associated with substantial ransom revenue, with reporting tying the operation to more than $10 million in cryptocurrency payments during the first months of 2026. Its tradecraft overlaps with other SaaS-focused extortion actors, but it is distinguished by its infrastructure patterns, multi-brand extortion ecosystem, and repeated use of help-desk impersonation combined with cloud-focused adversary-in-the-middle phishing and data theft.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
97 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group behind a 2026 campaign targeting major financial companies, using IT helpdesk-themed vishing and social engineering to access cloud platforms. The group reportedly rebranded and expanded operations, focusing on private equity, financial services, and professional services organizations.
Activity cluster linked to Helix that shares infrastructure with multiple extortion brands and has been observed using vishing and device code phishing to gain initial access against cloud services and identity infrastructure.
A wider umbrella collective that Google says includes Helix.
Broader activity cluster linked to Helix and other extortion brands; operators use helpdesk-themed vishing, device code phishing, credential theft, and data theft from cloud services including Microsoft 365, and have also targeted Okta infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.