1. Executive summary
A financially motivated data-theft and extortion campaign attributed to the threat cluster UNC6671 is actively targeting financial services, private equity, and professional services organisations. UNC6671 uses voice phishing (vishing) — posing as IT help desk staff conducting urgent security migrations — and increasingly contacts employees on their personal mobile devices to bypass corporate monitoring. The group tricks victims into adversary-in-the-middle (AitM) phishing portals that intercept credentials and MFA tokens, then uses those sessions to exfiltrate data from SaaS platforms including Microsoft 365 and Okta. Attribution to UNC6671 is unconfirmed: the actor has no MITRE ATT&CK profile, and the campaign overlaps structurally with clusters tracked as UNC3753 / Luna Moth / Chatty Spider / Silent Ransom Group / Cordial Spider; clients should treat the grouping as an analytic assessment by GTIG/Mandiant and CrowdStrike, not a hard attribution.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | The campaign explicitly targets financial services organisations to steal sensitive data from SaaS/identity platforms (Microsoft 365, Okta), and the full attack cycle can complete in under an hour — meaning an incident could meet the severity threshold for a major ICT-related incident before the organisation detects it. | Clients must have detection and classification workflows fast enough to meet DORA Art. 19 reporting timelines when SaaS session hijacking is confirmed; pre-build a playbook for IdP/AitM compromise scenarios. |
| DORA Art. 24: digital operational resilience testing — general requirements | The attack bypasses traditional boundary security by social-engineering users into legitimate RMM/screen-sharing tools and AitM portals; resilience testing that only covers network perimeter controls would not detect this failure mode. | Include social-engineering-to-SaaS-exfiltration scenarios in operational resilience testing programmes; validate that IdP session revocation and MFA device audit controls are exercised. |
| NIS2 Art. 23: incident reporting obligations | The campaign's targeting of professional and legal services (which fall under NIS2 essential/important entity scopes in many member states) and rapid data exfiltration timeline creates a plausible obligation to report significant incidents to national CSIRTs. | Clients in NIS2 scope should confirm their incident classification thresholds and early-warning reporting procedures account for SaaS credential theft via AitM, where data staging and theft can occur within one business day. |
3. Technical analysis & attack chain
Attribution caveat: UNC6671 has no MITRE ATT&CK profile; the attribution rests on GTIG/Mandiant and CrowdStrike reporting. The cluster overlaps with UNC3753 / Luna Moth / Chatty Spider / Silent Ransom Group (Mandiant) and Cordial Spider (CrowdStrike). GTIG assesses UNC6671 operates independently of ShinyHunters despite tradecraft similarities. Treat the actor name as an analytic label, not a confirmed identity.
Attack chain (confirmed from source material)
- Pretext establishment via email. The group sends benign, invoice-themed email lures from actor-controlled consumer email accounts. These emails contain no active links or malicious attachments — their sole purpose is to create a pretext (e.g., "hello, here is the invcoie we talked about yesterday") that makes the target more susceptible to a follow-up voice call.
- Target reconnaissance. Threat actors harvest phone numbers and email addresses of personnel across all seniority levels from organisations' public websites. The group now specifically targets employees' personal mobile devices, which bypasses corporate telephony monitoring.
- Vishing call. Actors call the target posing as internal IT help desk or security team staff, claiming a need to address a security issue or facilitate a corporate data migration. They create urgency around mandatory security migrations.
- Screen-sharing session. The caller directs the target to join a screen-sharing session using built-in or commercial services: Zoom, Microsoft Terminal Services, Microsoft Teams, or Quick Assist. In one Teams-facilitated intrusion, the actor held five distinct calls with the same target over a three-day period.
- AitM credential capture. The target is directed to a spoofed login portal. Adversary-in-the-middle (AitM) infrastructure intercepts credentials and MFA tokens in real time. CrowdStrike characterises the AitM pages as capturing "authentication data and active session tokens in real time."
- Session persistence via MFA device registration. Actors access the organisation's identity provider (IdP) using captured credentials/tokens. They establish persistence by registering adversary-controlled MFA devices to compromised accounts and removing existing MFA devices first.
- SaaS lateral movement. By abusing the trust relationship between the IdP and connected services, actors bypass the need to compromise individual SaaS apps. A single authenticated IdP session provides lateral access across the victim's entire SaaS ecosystem — described by CrowdStrike as "single point entry."
- Automated data exfiltration. Actors deploy automated Python and PowerShell scripts to exfiltrate data from enterprise cloud environments and SaaS applications, including Microsoft 365 and Okta. Data typically targeted includes proprietary legal agreements, PII, and financial records.
- RMM persistence (observed in related UNC3753 incidents). Actors attempt to install AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM agents by convincing targets to download them during the screen-sharing session.
- Extortion. Stolen data is used for subsequent extortion demands. The full cycle — from initial contact to data theft and extortion — has occurred within a single business day; in recent incidents, data searches, staging, and theft were initiated in under an hour.
Physical intrusion variant (single-sourced; verify before enforcement): Mandiant reports that individuals posing as IT technicians have entered corporate offices to attempt direct exfiltration of data from endpoints using USB storage media. GTIG assesses these physical intrusions are likely associated with UNC3753 based on "structural, timeline, and targeting overlaps," but notes "limited forensic evidence and the absence of a subsequent extortion attempt prevent formal attribution." An FBI alert from May 2026 reportedly corroborates this in-person tactic against law firms.
Brand timeline
- Early January 2026 — UNC6671 emerges
- February 6, 2026 — BlackFile Data Leak Site (DLS) launches
- Late April 2026 — BlackFile DLS goes offline
- May 11, 2026 — BlackFile DLS briefly returns to announce shutdown "under this name"
- May 19, 2026 — Redact operators state all BlackFile operations "officially and permanently ceased"
- May 31, 2026 — Pink DLS launches
- June 27, 2026 — Redact claims the original BlackFile brand was compromised/hijacked by a former associate
Extortion brands currently active: Redact, Pink (aka CL-CRI-1147), Helix, Falcon (aka CL-CRI-1182). Retired brand: BlackFile (aka CL-CRI-1116).
4. Mitigation & containment
P1 — within 24 hours
- Audit IdP MFA device registrations. Review all MFA device registrations in Okta, Microsoft 365 / Entra ID, and any other identity providers for anomalies. Look for newly registered devices that do not match known user endpoints, and for any recent MFA device removals followed by new registrations — this is the group's documented persistence technique.
- Hunt for AitM phishing sessions. Search IdP and SaaS access logs for sessions exhibiting impossible travel, unusual IP/ASN, or sessions immediately followed by access to Microsoft 365 / Okta from non-corporate infrastructure. Look for session tokens issued from unfamiliar user agents or geographies.
- Review recent RMM tool installations. Search endpoints for recent installations of AnyDesk, Bomgar, Zoho Assist, and SuperOps RMM agents that were not deployed through the organisation's standard software distribution channel.
- Block consumer screen-sharing where not required. If Quick Assist, Microsoft Teams external federation, or Zoom are not business-critical, restrict external initiation of screen-sharing sessions via policy.
P2 — within 72 hours
- Implement phishing-resistant MFA. GTIG explicitly states the campaign "underscores the critical importance of organisations moving toward phishing-resistant MFA to protect their SaaS and identity platforms." FIDO2 hardware keys or platform-authenticated passkeys are the standard; TOTP and push-based MFA are interceptable via AitM and are insufficient against this threat.
- Configure IdP session policies. Enforce session token binding to known devices; implement conditional access policies that require device compliance before issuing SaaS access tokens. Configure short session lifetimes for sensitive applications and require re-authentication for high-impact actions.
- Alert on MFA device modification. Create real-time alerts for any MFA device removal or registration events across all identity providers — this is a high-fidelity signal for this actor's persistence step.
- Brief help desk and security operations. Ensure IT help desk staff are aware that attackers are impersonating them and targeting employees' personal phones. Establish a verified callback procedure for any security-migration or account-issue call that originates from an external or unverified number.
- Review physical access controls. Given the reported physical intrusion variant, brief front-desk and facilities staff that individuals may pose as IT technicians requesting access to endpoints with USB storage. Require verified escort and management authorisation for any unscheduled IT device imaging or backup activity.
P3 — within 7 days
- Deploy SaaS exfiltration detection. Enable and tune Microsoft 365 audit log alerts for bulk download activity, MailItemsAccessed operations from unusual locations, and SharePoint/OneDrive mass file access. Configure Okta system log alerts for suspicious application access patterns.
- Hunt for Python/PowerShell exfiltration scripts. Search EDR telemetry for Python (
python.exe,pythonw.exe) and PowerShell processes launched from user-context directories or temporary paths that initiate outbound network connections to non-corporate endpoints. The group uses automated scripts for data exfiltration from SaaS environments. - Conduct tabletop exercise. Run a scenario covering vishing-to-AitM-to-SaaS-exfiltration with a sub-one-hour timeline to validate that detection, containment (session revocation), and reporting workflows can meet operational tempo.
5. Indicators of compromise
No atomic indicators of compromise (IPs, domains, hashes, email addresses) are available in the source material. The sources describe observable behaviours and tooling but do not publish specific IOCs.
Behavioural indicators
| Behaviour | Where to observe | Confidence |
|---|---|---|
| MFA device removal followed by new device registration on same account | IdP admin console / audit logs (Okta, Entra ID) | High — corroborated across GTIG and CrowdStrike reporting |
| Inbound voice call to employee's personal mobile claiming urgent security migration | Employee reporting / call logs | High — explicitly highlighted in primary source |
| Screen-sharing session initiated via Zoom, Teams, Quick Assist, or Microsoft Terminal Services from external party | Endpoint process logs, SaaS audit logs | High — corroborated across Mandiant and CrowdStrike |
| Installation of AnyDesk, Bomgar, Zoho Assist, or SuperOps RMM agent outside standard software distribution | EDR / software inventory | Medium — observed in UNC3753-linked incidents; attribution to UNC6671 variant is inferred |
| Python or PowerShell processes initiating outbound network connections from user context | EDR telemetry | Medium — described in primary source; no specific script names or hashes available |
| Bulk file download or access from Microsoft 365 / SharePoint / OneDrive in short timeframe | Microsoft 365 audit logs (MailItemsAccessed, FileAccessed) | Medium — consistent with described exfiltration methodology |
| Invoice-themed email from consumer email account with no links or attachments, containing deliberate typo (e.g., "invcoie") | Email gateway logs | Medium — single-sourced to Mandiant UNC3753 reporting |
| Unauthorised individual on premises claiming to be IT technician, requesting USB device imaging | Physical security / facilities reports | Low — single-sourced to Mandiant; formal attribution not confirmed |
6. Detection
Insufficient indicators to author detection rules. The source material describes behaviours and legitimate tooling (Zoom, Teams, Quick Assist, AnyDesk, Bomgar, Zoho Assist, SuperOps RMM, Python, PowerShell) but does not provide distinctive malicious artefacts — no file hashes, no malicious domain names, no unique command-line strings, no mutex names, no specific script contents, and no AitM portal URLs. Detection for this campaign must be behaviour-based: IdP MFA device modification alerts, anomalous SaaS access patterns, and RMM tool installation monitoring as described in §4.
7. Sources
- The Hacker News — "UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data" — https://thehackernews.com/2026/08/unc6671-vishing-attacks-target-personal.html — 2026-08-07
- SecurityWeek — "Vishing Extortion Group UNC6671 Rebrands After Making Millions" — https://www.securityweek.com/vishing-extortion-group-unc6671-rebrands-after-making-millions/ — 2026
- Mandiant / Google Cloud Blog — "Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms" (Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan) — https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/ — 2026
- The Register — "If you don't fall for these extortionists' calls, they'll show up with USB sticks" — https://www.theregister.com/cyber-crime/2026/06/05/if-you-dont-fall-for-these-extortionists-calls-theyll-show-up-with-usb-sticks/5251891 — 2026-06-05
8. Adverse Trace position
This is a high-impact campaign for EMEA financial services. The attack chain does not exploit a software vulnerability — it exploits identity infrastructure and human trust — which means traditional patching and perimeter controls are insufficient. The operational tempo (full cycle in under a day, exfiltration in under an hour) means that detection must be real-time and automated, not retrospective. The shift to targeting personal mobile devices is significant: it deliberately bypasses corporate call monitoring and endpoint controls, making employee awareness and phishing-resistant MFA the primary control gaps. Attribution to UNC6671 is unconfirmed (no MITRE profile); the cluster's relationship to UNC3753 / Luna Moth / Silent Ransom Group / Cordial Spider is based on structural and tradecraft overlap assessed by GTIG and CrowdStrike — clients should not over-index on the actor name for threat hunting but should focus on the behaviours described in §3 and §5. We will continue monitoring for atomic IOCs from GTIG/Mandiant follow-up reports and will issue an update if AitM infrastructure, script samples, or call-back numbers are published.
Published via PulseTrace — Adverse Trace threat intelligence.