Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-06 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity & Cloud

UNC6671 did not retire — BlackFile split into four vishing brands aimed at M&A

GTIG 6 August 2026 — helpdesk vishing to personal mobiles, sometimes spoofing the real helpdesk number, FIDO2/MFA pretext, lookalike SSO, then scripts out of the cloud. July aim: PE, law, ratings. BlackFile wallets ~$10.7M Jan–May.

RWP Ventures · 2026-09-07 · event 2026-08-06 · 1 min read · priority 8.5

Bottom line up front

CONFIRMED 6 August 2026 GTIG — UNC6671 did not go away when BlackFile “retired” in May. Extortion brands observed: Redact, Pink, Helix, Falcon (TechCrunch; GTIG treats them as associated brands under one umbrella). Call the employee's personal mobile, pose as IT, sometimes spoof the real helpdesk CLI. Pretext: urgent FIDO2 passkey or MFA enrollment. Victim is walked to a lookalike subdomain, SSO + MFA captured, attacker device enrolled, cloud exfil by script.

Targeting shift GTIG documented: Apr–May manufacturing/real estate/healthcare/insurance (volume creds); June tech/transport/hospitality (IP, source, VIP); July financial/legal, PE, law, ratings (M&A/litigation leverage). SC Media citing GTIG: ~$10.69M through 18 BlackFile BTC wallets Jan–May, negotiated payments averaging ~$750k. Reuters names in TechCrunch (Apollo, Bain, Blackstone, Bridgewater, CME, KKR, Moody's, TPG) are reported targeting — Point72/Two Sigma/Greenberg Traurig publicly said they saw no theft. Being named is not a confirmed breach.

Do not merge with UNC3753/Luna Moth (RMM after vishing) without overlap evidence. Same class of helpdesk theater, different cluster IDs.

What happened

Identity is the product. The “exploit” is a phone call that bypasses corporate email controls.

Why it matters

PE and law firms hold other people's secrets. Extortion math is better than encrypting a plant.

What is confirmed vs not

CONFIRMED GTIG TTPs and sector shift.

REPORTED wallet totals, specific firm names.

UNKNOWN whether all four brands are the same operators vs shared kit.

What defenders should do

  1. Helpdesk never initiates MFA reset to a personal cell. Call-back to a known internal number.
  2. Alert on new FIDO/MFA device enrollments.
  3. SaaS Data Loader / mass-download is the theft, not ransomware notes.

RWP assessment

Confidence: High on the vishing-to-cloud path. Treat board “we were named” as UNVERIFIED until IR says otherwise.

Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-06 and was added to the RWP archive on 2026-09-07.

Sources

  1. GTIG — UNC6671 rebrands vishing extortion
  2. TechCrunch — Hackers calling financial firm employees
  3. SC Media — UNC6671 extorting M&A firms