UNC6671, an extortion group engaging in tailored IT helpdesk voice phishing (vishing), has rebranded and diversified its operations over the past several months, Google Threat Intelligence Group (GTIG) reports.

The threat actor emerged in early 2026, operating under the ‘BlackFile’ name. In May, GTIG warned it had targeted dozens of organizations across North America, Australia, and the UK in sophisticated vishing and single sign-on (SSO) compromise attacks.

Mainly focusing on Microsoft 365 and Okta infrastructure, it was leveraging adversary-in-the-middle (AiTM) techniques to bypass defenses and multi-factor authentication (MFA) and gain access to cloud environments.

In May, GTIG now says, the group retired the BlackFile extortion name, but has continued its activities under multiple brands: Redact, Pink, Helix, and Falcon. The latest attacks have focused on the financial services, private equity, and professional services sectors.

Posing as IT helpdesk employees, UNC6671 threat actors have been calling employees at the victim organizations, often on personal mobile phones, under the pretext of mandatory, urgent security migrations, luring them to spoofed login portals to intercept their credentials and MFA tokens.