Threat Actor Unknown origin
UNC6671
UNC6671 is involved in credential harvesting operations, utilizing vishing tactics to impersonate IT staff and directing victims to enter credentials on a victim-branded site. They have gained access to Okta customer accounts and employed PowerShell to download sensitive data from SharePoint and OneDrive. Their extortion tactics include aggressive harassment of victim personnel, and they have used unbranded extortion emails with different Tox IDs for communication. The threat actors have shown a preference for registering domains with Tucows, indicating potential operational differences from related threat groups.
Indicators of Compromise 5
MITRE ATT&CK TTPs 17
T1003 T1027 T1059 T1059.001 T1059.003 T1071.001 T1071.004 T1078 T1190 T1486 T1496 T1530 T1531 T1555 T1566 T1566.002 T1611
OS Credential Dumping
Credential Access
Obfuscated Files or Information
Defense Evasion
Command and Scripting Interpreter
Execution
PowerShell
Execution
Windows Command Shell
Execution
Web Protocols
Command And Control
DNS
Command And Control
Valid Accounts
Defense Evasion
Exploit Public-Facing Application
Initial Access
Data Encrypted for Impact
Impact
Resource Hijacking
Impact
Data from Cloud Storage
Collection
Account Access Removal
Impact
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Spearphishing Link
Initial Access
Escape to Host
Privilege Escalation
Source Articles
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A zero-day vulnerability in Metabase, a business intelligence platform, is being exploited in the wild, allowing unauthenticated remote attackers to perform SQL injection and gain full administrator access to affected instances. This enables attackers to steal database credentials, exfiltrate data, and modify configurations. The vulnerability has a CVSS score of 10.0 but lacks a CVE identifier. One confirmed victim is Framework. Additionally, Chinese-made Zbtlink routers were found shipping with a factory-installed backdoor that phones home to Chinese C2 servers every 35 seconds, affecting at least 20 models. The backdoor enables remote command execution. Separately, the threat actor UNC6671 is conducting vishing attacks against financial firms, using voice phishing to capture credentials and MFA tokens via adversary-in-the-middle infrastructure, then deploying scripts for data exfiltration from cloud environments.
hacker-news ·3w ago
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
UNC6671, a financially motivated threat actor group, is conducting vishing attacks to steal credentials and multi-factor authentication tokens by impersonating IT help desk personnel and contacting employees on their personal mobile devices. The attackers use adversary-in-the-middle (AitM) infrastructure to capture credentials and session tokens, enabling access to SaaS platforms such as Microsoft 365 and Okta. The group operates under multiple extortion brands including Redact, Pink, Helix, and Falcon, and has exfiltrated data from organizations in North America, Australia, and the U.K., collecting over $10.6 million in Bitcoin between January and May 2026. Google and CrowdStrike assess that the group leverages social engineering rather than technical vulnerabilities, highlighting the need for phishing-resistant MFA and improved session controls.
hacker-news ·3w ago
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A cybercriminal group tracked as UNC6671, previously known as BlackFile, has been conducting vishing attacks against hedge funds, private-equity firms, and other financial organizations. The attackers spoof corporate helpdesks and trick employees into visiting phishing domains that steal credentials and session cookies via adversary-in-the-middle kits. After gaining access to Microsoft 365 or Okta single-sign-on accounts, they exfiltrate data from linked cloud services and suppress detection by deleting security notifications. The group has diversified its extortion operations under multiple brand names including Redact, Pink, Helix, and Falcon, though Falcon claims it is only affiliated with Redact.
bleeping-computer ·3w ago