Blackstone, KKR and CME targeted in vishing wave tied to BlackFile crew
Google LLC’s Threat Intelligence Group today said the extortion crew behind the retired BlackFile brand has spent June and July working its way through private equity firms, law firms and financial services companies.
Reuters reports that the phishing domains registered for the campaign name their intended victims. Blackstone Inc., KKR & Co. Inc., Apollo Global Management Inc. and CME Group Inc. all turn up in the set, alongside the law firms Paul Hastings LLP and Greenberg Traurig LLP. None of the firms has confirmed a breach, and Greenberg Traurig told Reuters none occurred
The group is tracked as UNC6671. Earlier in the year, its operators went after manufacturers, real estate firms, hospitals and insurers in bulk. Google’s analysts read the newer target list as a play for leverage, since a firm sitting on live merger documents or litigation files has more reason to pay quietly.
Four public extortion brands now sit on top of that single intrusion cluster, according to the report. Redact, Pink, Helix and Falcon share phishing infrastructure, and in several cases, identical phishing templates went live on the same day across domains claimed by different brands. BlackFile announced its retirement on May 11. Bitcoin payments to its wallets were still landing the next day. Redact surfaced on June 27 with a statement claiming the BlackFile name had been “compromised and hijacked by an exiled affiliate.”










