cloud.google.com 8/6/2026, 6:41:33 PM · external

UNC6671 uses vishing to push Redact, Pink extortion on firms

UNC6671 uses vishing to push Redact, Pink extortion on firms
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

THE Google Threat Intelligence Group (GTIG) reports on the ongoing activities of threat actor UNC6671, which is now using multiple extortion brands including Redact, Pink, Helix, and Falcon, instead of disbanding after the perceived retirement of BlackFile. Unlike prior methods, UNC6671 increasingly employs voice phishing (vishing) to deceive employees into revealing credentials, often targeting them through personal phones.

Key techniques involve directing victims to spoofed login pages that harvest credentials and multi-factor authentication tokens. GTIG highlights a consistent pattern in tactics while outlining the affiliations between various extortion brands, showing that they share infrastructure and phishing templates.

The report discusses the evolution of UNC6671's targeting, emphasizing a focus on the financial and legal sectors, and provides hardening guidance including the enforcement of phishing-resistant authentication methods. Indicators of compromise (IOCs) and new techniques employed by the group are also presented, emphasizing the need for organizations to bolster their defenses against identity-centric attacks.

View full article

Article by CyberSIXT