UNC6671 uses vishing and AitM phishing to steal cloud credentials and MFA tokens, then exfiltrate data from Microsoft 365, Okta, and other SaaS apps.

The UNC6671 vishing extortion group has rebranded from BlackFile and is operating as Redact, Pink, Helix, and Falcon.

UNC6671 uses vishing and AitM phishing to steal cloud credentials and MFA tokens, then exfiltrate data from Microsoft 365, Okta, and other SaaS apps.