UNC6671 Rebrands and Targets Hedge Funds: Vishing MFA Bypass Hits Finance Firms in August 2026

Proactive Security for the AI Era
NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.
UNC6671, the vishing extortion group that collected $10.6 million in Bitcoin from victims in five months, has rebranded as four simultaneous criminal fronts -- REDACT, Pink, Helix, and Falcon -- and shifted its targeting to the highest-value data repositories in finance: hedge funds, private equity firms, merger and acquisition advisors, and law firms handling capital markets transactions.
Google's Threat Intelligence Group confirmed in August 2026 that the same infrastructure, affiliate network, and vishing scripts behind BlackFile now operate under multiple brand identities simultaneously. Intrusion attempts hit Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and unnamed private equity firms within weeks of the rebrand becoming visible. The multi-brand structure is deliberate: when one front faces law enforcement scrutiny, the others continue without disruption.
The attack method requires no CVE, no malware, and no perimeter breach. UNC6671 operators call employees on personal mobile phones, impersonate corporate IT helpdesk, and claim a mandatory passkey or FIDO2 enrollment is required immediately. Victims who comply are directed to adversary-in-the-middle phishing portals that capture credentials and MFA session tokens in real time. The attacker lands directly inside Microsoft 365 and Okta tenants with a valid, MFA-verified session.
The financial sector pivot is calculated. M&A files, capital deployment records, fund valuations, and portfolio company data command far higher extortion leverage than retail customer records. UNC6671 demands $1 million to $3 million per victim, with settlements averaging approximately $750,000. The 33% increase in domain registration tempo between June and July 2026 signals an accelerating campaign -- one new AiTM phishing domain every 1.6 days.
Who Is UNC6671? Origin and Attribution
UNC6671 is Google's internal tracking designation for the criminal vishing cluster that emerged in early 2025 under the public brand BlackFile. The group is Russian-speaking based on linguistic indicators in negotiation communications and infrastructure hosted across Switzerland, Poland, and Russia. No confirmed attribution to a state sponsor exists -- Google and Mandiant assess UNC6671 as purely financially motivated.
BlackFile operated from approximately February 2025 through May 11, 2026, targeting retail, hospitality, healthcare, and insurance organizations with vishing-based extortion. On May 11, 2026, the group announced a false shutdown, citing a "hijacking by exiled affiliates" as cover for a planned rebrand. Bitcoin payments to confirmed BlackFile wallets continued past the shutdown date.
The rebrand produced four simultaneous extortion fronts. REDACT and Pink share Tucows-registered domain infrastructure. Helix and Falcon overlap on Swiss VPS nodes at AS51852 Private Layer INC. Google's GTIG confirmed the links through shared domain registration patterns, identical AiTM proxy configurations, Bitcoin wallet reuse, and near-identical vishing scripts across all four brands.
The affiliate model gives UNC6671 structural resilience. Operators build the AiTM infrastructure and vishing playbooks; affiliates conduct the calls and splits vary by brand. This compartmentalization means law enforcement action against one affiliate does not expose the core infrastructure operators.
For a comparison with the BlackFile extortion group's retail targeting campaign that preceded this financial sector pivot, see the full April 2026 breakdown with retail-specific IOCs and Salesforce API theft TTPs.
How UNC6671's Vishing AiTM Attack Chain Works
UNC6671 attacks follow a seven-step chain that exploits human trust rather than software vulnerabilities. No patch closes this attack surface.
Step one is reconnaissance. Operators map target organizations on LinkedIn, identifying employees in IT support, identity management, helpdesk, and IT administration roles by title and recent activity. Victim-branded phishing portals are registered within hours of target selection using the company's name in predictable patterns: companyname-sso.com, companyname-passkey.com, or support-companyname.com.
Step two is the call. The operator contacts the target employee on their personal mobile phone -- not corporate-controlled endpoints, which would log the call. The caller spoofs the legitimate corporate helpdesk number so caller ID shows a familiar identity. The pretext has evolved: current campaigns claim an urgent FIDO2 passkey enrollment deadline or a required MFA security upgrade, framing noncompliance as a policy violation.
Step three is the redirect. The victim is directed to an AiTM phishing portal. The portal replicates the organization's actual SSO login page and relays every credential the victim enters to the legitimate Microsoft 365 or Okta authentication service in real time.
Step four is token theft. When the victim completes MFA -- entering a TOTP code, approving a push notification, or entering an SMS code -- the proxy intercepts the authenticated session cookie Microsoft or Okta returns. The victim is redirected to a plausible "enrollment complete" page. The attacker now holds a live, MFA-verified session.
Steps five through seven involve automated exfiltration via python-requests and PowerShell scripts targeting SharePoint, email, and connected SaaS applications, followed by deletion of MFA registration alerts and password reset notifications from the compromised inbox. The victim typically discovers the breach only when the extortion demand arrives.
This attack chain mirrors the STAC4749 vishing methodology documented in Microsoft Teams-based attacks, applied here to direct phone calls rather than collaboration platform messages.
LinkedIn Reconnaissance and Portal Registration
UNC6671 identifies IT and identity management employees on LinkedIn by title. A victim-branded AiTM phishing domain is registered within hours of target selection using patterns like companyname-sso.com or companyname-passkey.com (Tucows or NICENIC registrars). The portal mirrors the target organization's real SSO login page.
Personal Mobile Vishing Call
Operator calls the target employee's personal mobile phone, spoofing the corporate helpdesk number so caller ID shows a trusted identity. The pretext claims an urgent FIDO2 passkey enrollment or MFA security upgrade is required immediately, framing noncompliance as a policy violation.
AiTM Credential and MFA Token Capture
Victim enters credentials on the phishing portal. The portal proxies the login to the real Microsoft 365 or Okta endpoint in real time, intercepts the authenticated session cookie returned after MFA completion (TOTP, push, or SMS), and delivers it to the attacker. The victim sees a 'enrollment complete' page.
Automated Cloud Data Exfiltration
Using the stolen session cookie, the attacker runs automated scripts (python-requests/2.28.1, WindowsPowerShell/5.1) to bulk-access SharePoint, Exchange, and connected SaaS applications. M&A files, fund valuations, portfolio company data, and legal documents are exfiltrated to attacker-controlled MEGA or cloud storage staging infrastructure.
Alert Deletion and Extortion Demand
All MFA enrollment notifications, password reset emails, and security alerts generated during the intrusion are deleted from the compromised mailbox. The attacker exits the session and delivers a ransom demand of $1-3 million, with average negotiated settlements of approximately $750,000.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
The Financial Sector Pivot: Scope and Active Targets
UNC6671's sector targeting follows a deliberate value hierarchy. Retail and hospitality organizations targeted in 2025 yielded customer PII -- data with a finite black-market price. Financial services targets yield M&A transaction data, fund performance records, portfolio company valuations, and confidential legal filings -- data whose confidentiality is worth millions to its owners and whose disclosure is catastrophic for clients.
The targeting shift began in June 2026 when Google's GTIG observed UNC6671 infrastructure moving from retail-focused phishing domains to financial-services-specific patterns. By July 2026, domain registration tempo accelerated to one new AiTM phishing domain every 1.6 days, a 33% increase from the April-May average of one every 2.2 days.
Confirmed August 2026 attack attempts documented by Google and BleepingComputer include Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and multiple unnamed private equity firms. Point72 detected and contained the intrusion attempt with no confirmed data theft. Two Sigma blocked the attack at the portal stage. Citadel and Millennium have not confirmed breach outcomes publicly.
The operational logic is straightforward. An M&A advisory firm handling a $2 billion acquisition faces catastrophic client exposure if deal documents are leaked. A hedge fund whose proprietary trading models or LP relationships are exposed faces regulatory scrutiny and investor flight. UNC6671 targets the data whose confidentiality justifies the settlement demand, not the data whose quantity is largest.
UNC6671 TTPs Mapped to MITRE ATT&CK
UNC6671's attack chain spans six ATT&CK tactics with no overlap with the exploit-based techniques most enterprise detection stacks prioritize.
Initial Access (TA0001): T1566.004 -- Phishing: Spearphishing via Voice. The personal phone call is the sole initial access mechanism. UNC6671 has not been observed using email phishing, CVE exploitation, or credential stuffing for initial entry.
Credential Access (TA0006): T1539 -- Steal Web Session Cookie. The AiTM proxy intercepts the authenticated session token Microsoft 365 or Okta returns after MFA completion. T1556.006 -- Modify Authentication Process: Multi-Factor Authentication, covering the post-compromise addition of attacker-controlled MFA factors to maintain persistence.
Persistence (TA0003): T1098.005 -- Account Manipulation: Device Registration. Following initial access, operators register attacker-controlled devices in Okta or Entra ID to maintain durable access after the stolen session cookie expires.
Defense Evasion (TA0005): T1070.004 -- Indicator Removal: File Deletion. All MFA setup alerts, security notification emails, and password reset confirmations are deleted from the compromised mailbox. T1564 -- Hide Artifacts, covering the systematic removal of attacker activity from the victim's view.
Exfiltration (TA0010): T1567 -- Exfiltration Over Web Service. Automated scripts using python-requests/2.28.1 and WindowsPowerShell/5.1 bulk-access SharePoint document libraries, Exchange mailboxes, and connected SaaS platforms. T1078.004 -- Valid Accounts: Cloud Accounts, since all post-compromise activity uses the legitimately issued session token.
Impact (TA0040): T1657 -- Financial Theft via extortion, with initial demands of $1-3 million per victim and average settlements of $750,000.
Active Campaign Infrastructure and IOCs
Google GTIG has identified 56 AiTM phishing domains tied to UNC6671 operations across all four active brands. The nine domains listed below represent the highest-confidence indicators tied to August 2026 financial services targeting and were active as recently as August 3, 2026. Block all of them at DNS resolvers, corporate web gateways, and email security filters.
The IP infrastructure separates into two functional tiers. The AiTM reverse proxy tier (31.7.56.61 and 31.7.56.52) handles real-time credential relay at AS51852 Private Layer INC in Switzerland. The exfiltration tier (23.234.75.84 and 195.140.213.114) routes bulk data from compromised M365 tenants. The phishing backend nodes (193.34.212.132 at MEVSPACE Poland and 185.178.208.153 at DDOS-GUARD Russia) serve the portal HTML and manage AiTM sessions.
The residential proxy ASNs used for M365 and Okta authentication blending (AT&T, Comcast, Starry, Optimum) are difficult to block without false-positive impact. Focus detection on behavioral signals instead: MFA setup events within 60 seconds of an authentication failure, FileAccessed events with scripting user-agents, and session starts from known anonymizing proxy infrastructure.
Full current IOC list including all 56 domains is published by Google GTIG at the Cloud Blog post linked in sources below.
Subscribe to unlock Indicators of Compromise
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Sigma Detection Rules for UNC6671 Vishing Activity
No CVE-specific Sigma rule exists for UNC6671 because the group exploits no software vulnerability. Detection must target behavioral signals: AiTM phishing blocks in Okta, legacy authentication bypass in Azure, and session starts from anonymizing proxies. Deploy these three rules against Okta system logs and Azure AD sign-in logs.
The Okta FastPass Phishing Detection rule fires when Okta FastPass identifies and blocks an AiTM phishing attempt during the authentication flow -- the most direct indicator of an active UNC6671 attack in progress.
The Legacy Authentication MFA Bypass rule catches the python-requests/2.28.1 and WindowsPowerShell/5.1 user-agents that UNC6671 uses for automated post-compromise exfiltration -- the bulk data theft phase that follows successful credential capture.
The Okta Proxy Session rule catches session starts from commercial VPNs, Tor exit nodes, and residential proxies -- the anonymization infrastructure UNC6671 uses to blend post-compromise activity with normal user traffic.
Subscribe to unlock Sigma Detection Rules
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Subscribe to unlock WAF Detection Rules
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
How to Stop a UNC6671 Vishing Attack Before It Lands
UNC6671's attack chain has no technical step that a perimeter firewall or EDR can interrupt before the employee answers the phone. Every defensive control that matters operates before the call, during identity policy enforcement, or immediately after an anomalous authentication event.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The bottom line
UNC6671 vishing attacks require no CVE, no malware, and no perimeter breach. The group collected $10.6 million in five months by calling employees on personal phones and proxying their MFA responses in real time. The financial sector pivot in August 2026 -- targeting Point72, Millennium, Two Sigma, and Citadel -- signals that UNC6671 has optimized its extortion model for maximum leverage. Three actions protect your organization now: mandate FIDO2 keys for all cloud access, block the nine AiTM phishing domains at DNS today, and alert on MFA setup events that follow authentication failures.
This analysis is generic. create a free account to score threats like this against your own stack.
Frequently asked questions
What is UNC6671?
UNC6671 is a financially motivated criminal extortion group tracked by Google's Threat Intelligence Group (GTIG) and Mandiant. The group operated publicly as 'BlackFile' from early 2025 until May 11, 2026, when it announced a false shutdown and rebranded simultaneously as REDACT, Pink, Helix, and Falcon. UNC6671 specializes in voice phishing (vishing) attacks that steal cloud credentials without exploiting any software vulnerability, bypassing MFA through adversary-in-the-middle proxy infrastructure.
How does UNC6671 vishing bypass MFA?
UNC6671 calls employees on personal mobile phones, impersonating corporate IT helpdesk and citing a passkey or FIDO2 enrollment requirement. Victims are directed to a lookalike login portal hosted on a passkey-themed domain. The portal acts as an AiTM proxy: it relays the victim's real credentials and MFA token to the legitimate Microsoft 365 or Okta login page in real time, capturing the authenticated session cookie before the victim realizes anything is wrong. Push-based MFA, SMS OTP, and TOTP codes are all interceptable this way. Only hardware-bound FIDO2 keys (YubiKey, passkeys with device attestation) block the attack.
What is adversary-in-the-middle phishing?
Adversary-in-the-middle (AiTM) phishing places an attacker-controlled reverse proxy between a victim and the legitimate authentication service. The victim believes they are logging into their employer's real SSO portal, but every credential and MFA response they enter passes through the proxy first. The proxy captures the authenticated session token Microsoft or Okta returns and passes it to the attacker, who now has a valid, MFA-verified session without ever knowing the user's password. AiTM toolkits like Evilginx2 and Modlishka are commonly used in these operations.
Which financial firms did UNC6671 target in August 2026?
Google GTIG and BleepingComputer identified five named targets in August 2026: Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several unnamed private equity firms. Point72 reported an attack but found no evidence of data theft. Two Sigma blocked an intrusion attempt before any system compromise. Citadel and Millennium have not made public disclosures as of this writing. The common thread is that all named targets hold M&A data, fund valuations, and portfolio company information that commands premium extortion leverage.
Has UNC6671 been arrested or sanctioned?
No arrests or sanctions targeting UNC6671 specifically have been announced as of August 2026. The group's false BlackFile shutdown on May 11, 2026 -- timed to news of law enforcement interest -- was a rebranding exercise, not a result of arrests. Bitcoin payments to confirmed UNC6671 wallets continued after the shutdown date, and Google GTIG confirmed new intrusion activity across multiple brands through August 2026. The group operates from infrastructure spread across Switzerland, Poland, and Russia, complicating law enforcement jurisdiction.
How do I detect UNC6671 vishing activity in my environment?
Deploy the three Sigma rules below: Okta FastPass Phishing Detection catches AiTM block events in Okta system logs; Potential MFA Bypass Using Legacy Client Authentication catches automated exfiltration via python-requests or PowerShell user-agents in Azure sign-in logs; Okta User Session Start Via Anonymising Proxy catches sessions sourced from commercial VPNs or residential proxy ASNs. Alert on any MFA factor setup event (system.multifactor.factor.setup) that follows within 60 seconds of a failed authentication attempt -- this is UNC6671's credential takeover pattern.
What should my team do if an employee receives a vishing call from 'IT helpdesk'?
Hang up immediately and call the IT helpdesk back on the number listed in the corporate directory -- never the number that called them. Report the call to the security team with the caller's number, call time, and what was requested. Check whether the employee visited any URL sent or mentioned during the call, and if so, treat their Microsoft 365 or Okta session as compromised: revoke active sessions, reset credentials, and check MFA registrations for unauthorized additions. File a phishing report with your identity provider (Microsoft DART or Okta Security).
What is the difference between BlackFile and UNC6671?
UNC6671 is Google's internal tracking designation for the threat cluster; BlackFile was the public-facing extortion brand that cluster operated between early 2025 and May 2026. When BlackFile announced a shutdown on May 11, 2026, the same infrastructure, personnel, and affiliate network continued operating under four new brand names: REDACT, Pink, Helix, and Falcon. Google confirmed the link through infrastructure overlaps, shared domain registration patterns, identical vishing scripts, and Bitcoin wallet reuse across all five brand identities.
Sources & references
- Google GTIG, UNC6671 Targets Financial Services and Enterprise Cloud Environments
- BleepingComputer, Hedge Fund Cyberattacks Tied to BlackFile-Linked UNC6671
- SecurityWeek, Vishing Extortion Group UNC6671 Rebrands After Making Millions
- The Hacker News, UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
