CFOtech Asia - Technology news for CFOs & financial decision-makers
Asia
Google links UNC6671 to cloud extortion brand shift

Google links UNC6671 to cloud extortion brand shift

Fri, 7th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Google has linked the UNC6671 cybercrime group to a broader set of extortion brands targeting corporate cloud environments. The activity has continued despite the apparent retirement of the BlackFile name.

Researchers at Google Threat Intelligence Group said the same actor, or closely connected operators, have been using the Redact, Pink, Helix and Falcon labels while keeping much of their approach unchanged. Their findings point to a campaign built around voice phishing calls, fake login pages and data theft from software-as-a-service platforms such as Microsoft 365 and Okta.

The group's latest activity shows a shift toward financial services, private equity, legal practices and professional services. Google said this narrower targeting suggests a focus on organisations holding sensitive corporate information related to deals, litigation and client records.

According to the researchers, UNC6671 typically calls employees while posing as IT help desk staff and urges them to carry out what it describes as an urgent security migration. In several recent cases, the calls went to personal mobile phones rather than company lines, a tactic that can bypass workplace security controls.

Victims are then directed to spoofed web domains designed to resemble passkey, single sign-on or multi-factor authentication enrolment portals. These sites use adversary-in-the-middle infrastructure to capture credentials and authentication tokens, allowing the attackers to retain access and move into enterprise cloud accounts.

Shared infrastructure

A central finding in the report is overlapping infrastructure across the different extortion brands. Root domains including passkeyhelpdesk[.]com, portalpasskey[.]com, addssopasskey[.]com, passkeydeploy[.]com, setupsso[.]com and passkeyuser[.]com were used in ways that linked victims later claimed by different leak sites.

The researchers also found matching phishing templates across multiple domains, with the same code and page design appearing on sites associated with different brands. That consistency, along with overlap in victim targeting, led Google to assess that the campaigns are most likely being run by a common group of threat actors. It said other possibilities include splintered affiliates or shared phishing infrastructure used by separate groups.

The targeting pattern has also evolved over time. Earlier waves covered a broad mix of industries, including manufacturing, real estate, healthcare and insurance. Later activity shifted toward technology, transport and hospitality before narrowing further to financial and legal organisations.

The pace of domain creation increased as the campaign developed. Google recorded about one new domain every 1.6 days across June and July, compared with one every 2.2 days in the earlier period it analysed. It also observed a short burst in which seven domains were set up within 72 hours.

Extortion payments

The financial picture outlined by the researchers suggests the rebranding did not interrupt the group's cash flow. Google reviewed 18 BlackFile bitcoin wallet addresses that received 141.65 BTC, worth about USD $10.69 million at the time of the transactions, and said payments continued after the public shutdown notice for the BlackFile leak site.

Initial ransom demands generally ranged from USD $1 million to more than USD $3 million, according to the analysis. In more than 53% of tracked cases, final payments averaged USD $750,000 after negotiations cut the original demands by 50% to 75%.

The report also describes changes in how the attackers try to avoid detection after gaining access. In recent intrusions, the group used compromised email accounts to trigger password resets for enterprise applications outside the single sign-on environment, then deleted confirmation messages, security warnings and alerts linked to account changes.

That method is intended to preserve access while reducing the chance that staff or automated systems detect suspicious activity. Google also identified signs of automated data theft from SaaS platforms, including file access events linked to scripting tools and command-line utilities rather than normal user browsing.

Defensive measures

Google urged organisations to adopt phishing-resistant authentication methods such as FIDO2 security keys and passkeys, integrate key business applications with central single sign-on systems, and shorten session lengths to force regular re-authentication. It also recommended restricting logins to trusted network sources, requiring corporate-managed devices for access, and monitoring identity provider logs for abandoned multi-factor prompts followed by setup events.

Defenders should treat scripted file access in cloud platforms as seriously as bulk downloads, especially when user-agent strings point to tools such as python-requests or Windows PowerShell. Google also advised firms to flag logins from commercial virtual private networks and residential proxy services that do not match normal employee patterns.

Tyler McLellan and Austin Larsen, authors of the research, said the growth in public extortion brands does not necessarily mean different actors are behind each one. "Regardless of whether this activity reflects a fractured threat group, outsourced extortion negotiators, or a broader affiliate network, the initial infection vector leveraged and goals of these campaigns is consistent," they said.