NEWS
Vishing Crews Recycle BlackFile Playbook Against Private Equity
Google GTIG maps Falcon Helix Pink Redact as UNC6671 rebrands that pulled $10.69M via phone scams on PE firms, echoing earlier Scattered Spider waves.
Google Threat Intelligence Group mapped four extortion brands to one persistent actor that has already moved roughly $10.69 million in Bitcoin. Falcon, Helix, Pink and Redact are the current faces of UNC6671, the crew formerly known as BlackFile, now calling private-equity and investment staff on personal cellphones while posing as IT helpdesk.
The playbook is not new. It recycles the same voice-phishing and adversary-in-the-middle chain that hit enterprises earlier in 2026 and echoes the helpdesk impersonation waves that battered casinos and retailers years before. What changed is the victim pool and the speed of the brand rotation, not the underlying hinge of live human trust.
Four Brands, One Shared Engine
In its August 7 update, GTIG states that UNC6671 never disbanded after BlackFile’s May 2026 retirement notice. Telemetry and domain overlaps tie the new labels together. Redact published a June 27 statement claiming an affiliate hijack forced the name change and offering a single verified Tox ID. Public claims of breakaways sit beside shared phishing templates and root domains.
passkeyhelpdesk.com simultaneously served Falcon and Helix victims. setupsso.com and idokta.com bridged earlier BlackFile targets into Pink clusters. Identical credential-harvesting code ran on addssopasskey.com, createssopasskey.com and related lookalikes. GTIG’s GTIG multi-brand infrastructure analysis treats the brands as affiliated fronts under one intrusion set, though splintered affiliates or shared phishing-as-a-service remain possible.
- Redact: direct BlackFile successor with authenticated Tox and PGP
- Falcon: acknowledged Redact affiliation on its own leak site
- Helix and Pink: separate data-leak sites fed by the same panel clusters
- BlackFile: original brand that kept receiving payments after its shutdown notice
Domain registration tempo rose from one every 2.2 days in April-May to one every 1.6 days across June-July, with a seven-domain spike in 72 hours mid-July. Most recent roots still resolve without wildcards, pointing to specific rather than spray targets. The faster cadence lines up with the sector pivot into finance, where each new root can be aimed at a short list of named firms rather than a broad industry spray.
The Call That Steals the Session
Operators dial personal mobiles, sometimes spoofing the real helpdesk number. The pretext is urgent: enable FIDO2 passkeys or finish a mandatory MFA enrollment. The employee is walked to a lookalike subdomain such as company.createssopasskey.com.
While the victim types credentials and the MFA code, the AiTM panel captures both in real time and replays them to the legitimate Okta or Microsoft 365 portal. A new attacker-controlled MFA device is registered before the call ends. Session cookies then power automated Python and PowerShell scripts that pull SharePoint, OneDrive and connected SaaS data. Operators delete password-reset mails, security alerts and MFA-change notices to stay quiet.
The call itself is the control plane. Once the new device is enrolled, the operator no longer needs the victim on the line. Scripts handle bulk collection; the human work shifts to silencing alerts and opening extortion contact.
Stats snapshot
- 141.65 BTC landed in 18 BlackFile wallets January 7 to May 12 2026 (~$10.69 million at transaction time)
- $1-3 million opening demands, routinely cut 50-75 percent in talks
- ~$750,000 average final payment in more than 53 percent of tracked cases
- One domain every 1.6 days during the June-July acceleration
Payments continued after the May 11 BlackFile shutdown notice, confirming the rebrand was cover, not exit. Later notes threaten data dumps and partner outreach if silence continues.
Private Equity Becomes the Focus
Targeting shifted by sector. April-May hit manufacturing, real estate, healthcare and insurance at volume. June moved to technology, transportation and hospitality holding IP or VIP data. By July the focus narrowed to financial services, private equity, law firms and rating agencies-entities sitting on merger files, capital-allocation memos and litigation material that maximize extortion leverage.
Reuters reverse-engineered 72 malicious sites from GTIG indicators and matched them to named firms. Attempts reached Blackstone, Apollo Global Management, Bain Capital, KKR, TPG, Bridgewater Associates, CME Group, Clearlake Capital and Moody’s, plus hedge funds including Point72, Two Sigma and Citadel. More than 200 organizations saw traps in a five-week window that also included Uber, Zillow, Levi Strauss and law firms such as Paul Hastings and Greenberg Traurig. Reuters could not confirm which attempts succeeded; several named firms declined comment or said no breach occurred.
| Firm or sector | Status in reporting |
|---|---|
| Blackstone, Apollo, Bain, KKR, TPG | Named via subdomain traps |
| Bridgewater, CME, Moody’s, Clearlake | Named via subdomain traps |
| Point72, Two Sigma, Citadel | Attempted breaches per sources |
| Law firms (Paul Hastings, Greenberg Traurig) | Targeted; one denied breach |
| Prior wave (Uber, Zillow, Levi’s) | Broader 200+ company set |
Austin Larsen, GTIG principal threat analyst, told reporters the choice is financial: “They think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it.” Merger files and capital memos give operators a clearer price signal than manufacturing floor plans. The same data that drives deal value also drives ransom math.
What the Wallets Show
Blockchain work on the BlackFile era supplies the only hard money numbers. Eighteen wallets took 141.65 BTC. Final settlements averaged about $750,000 once talks began. Initial asks started high and dropped fast when victims engaged. Cash-out spikes in late April and early May sat inside the rebrand window.
| Payment stage | Observed range or figure |
|---|---|
| Opening demand | $1-3 million |
| Typical discount in talks | 50-75 percent |
| Average final settlement | ~$750,000 (over 53 percent of cases) |
| BlackFile-era wallet total | 141.65 BTC (~$10.69 million) |
Extortion notes begin unbranded from throwaway Gmail accounts, then shift to Tox or Session once the victim answers. Silence triggers spam floods, C-suite voicemails and, in severe cases, swatting. The goal is data leverage, not ransomware encryption in every case.
That ladder from anonymous mail to authenticated Tox mirrors the brand story: start disposable, then prove continuity only when the victim engages. Wallets that kept filling after the May 11 notice are the clearest proof the retirement was theater.
Same Human Gap, Different Decade
The pattern is older than UNC6671. Scattered Spider (UNC3944 and aliases) scaled helpdesk vishing and IT impersonation against casinos in 2023, most visibly MGM and Caesars, then moved through retail, insurance and finance. Callers posed as staff needing password resets or MFA transfers, harvested OTPs live, and later deployed ransomware or pure extortion. CISA’s joint advisory still lists those exact voice techniques among current Scattered Spider TTPs.
A Windows identifier used in prior FBI case later helped attribute related activity, showing how forensic breadcrumbs eventually catch up. UNC6671’s current passkey-migration pretext and personal-cellphone routing are evolutionary steps on the same human hinge: when the technical fence rises, operators trick the person holding the gate.
- 2023: Scattered Spider casino breaches via helpdesk vishing and MFA fatigue
- Early 2026: UNC6671/BlackFile emerges with tailored passkey and SSO panels
- May 2026: BlackFile “retirement” notice while wallets keep filling
- June-July 2026: Redact statement plus Falcon, Helix, Pink expansion; finance pivot
- August 2026: GTIG public linkage and Reuters victim mapping
Crowd reaction on X distilled the same point: the MFA app did its job; the human on the phone did not. One widely shared observation noted that ten million dollars moved because staff trusted a live voice over established process.
Controls That Close the Channel
GTIG’s hardening list is concrete. Mandate phishing-resistant authenticators-FIDO2 security keys, passkeys, Windows Hello for Business or Okta Fastpass-so origin-bound cryptography kills lookalike domains. Fold every critical SaaS app into a single SSO so policy is consistent. Shorten sessions, enforce idle timeouts and step-up auth for sensitive resources. Bind sessions to known corporate or SASE network zones.
- Phishing-resistant MFA everywhere SSO touches
- Central SSO for Microsoft 365, Okta and line-of-business apps
- Daily re-auth and continuous access evaluation
- Network-zone restrictions on authentication
- Staff callback policy to a published internal number before any credential or MFA action
The earlier BlackFile vishing lifecycle details already showed scripted Graph API and direct-fetch exfiltration that blurs into FileAccessed events. Detection therefore needs User-Agent mismatch hunts and rapid review of new MFA device registrations after failed logins. The CISA joint advisory on Scattered Spider TTPs repeats the same phishing-resistant MFA mandate that still stops the majority of these calls.
Firms that already run hardware keys and strict callback rules report the voice channel simply fails. Those still relying on app push or SMS remain exposed to the next brand name the same operators invent.
Brand Rotation Keeps the Pressure On
Four labels in a few months force defenders to chase names instead of infrastructure. Redact’s June 27 hijack story and Falcon’s public nod to Redact create a paper trail of splits while the panels stay shared. Helix and Pink run separate leak sites fed by the same clusters, so takedown of one face leaves the others live.
Shared roots such as passkeyhelpdesk.com and the createssopasskey lookalikes are the durable signal. Domain tempo climbing from one every 2.2 days to one every 1.6 days, plus the mid-July seven-domain burst, shows capacity that a true breakup would dilute. Treating each brand as a fresh crew resets incident timelines and undercounts the $10.69 million already moved under BlackFile alone.
- Public breakaway claims without matching infrastructure splits
- One Tox ID offered as the verified Redact channel after the name change
- Payments into BlackFile wallets after the May 11 retirement notice
- Identical harvesting code across Falcon, Helix and Pink-linked domains
For private-equity and law-firm targets, the practical lesson is simple: block the panel family and the callback gap, not the logo on yesterday’s leak site.
Why Finance Data Raises the Stakes
Larsen’s point about sensitive data maps directly onto the July shortlist. Private equity, rating agencies and deal counsel hold material whose leak can move markets, scuttle closings or expose limited-partner terms. That is a sharper lever than the manufacturing and real-estate volume of April-May.
The Reuters mapping of 72 sites onto Blackstone, Apollo, Bain, KKR, TPG and peer firms shows how narrowly the traps were aimed. Hedge funds and firms such as Paul Hastings and Greenberg Traurig widen the same bet: anyone adjacent to capital allocation or litigation strategy may pay to keep files dark. Opening asks of $1-3 million and average closes near $750,000 only make sense if operators believe the stolen set is worth that much in avoided damage.
Unconfirmed outcomes at named firms do not weaken the targeting logic. The five-week window that also touched Uber, Zillow and Levi Strauss proves the crew can still run broad sets when it chooses. The finance concentration is a choice about leverage, not a limit on reach.
Frequently Asked Questions
What is UNC6671 and how does it relate to BlackFile?
UNC6671 is Google Threat Intelligence’s cluster name for the intrusion set behind the BlackFile extortion brand and its later Redact, Pink, Helix and Falcon fronts; infrastructure, templates and victim overlap support treating them as one core group or tightly linked affiliates rather than fully independent crews.
How does helpdesk vishing bypass ordinary MFA?
The caller keeps the victim on the line while an adversary-in-the-middle site captures the password and the live MFA code or push approval, then immediately registers a new attacker device so the session survives after the call ends.
What payment amounts have been observed?
Blockchain analysis of 18 BlackFile wallets from January to mid-May 2026 showed 141.65 BTC received, about $10.69 million at the time; opening demands sat between $1 million and $3 million and final settlements averaged roughly $750,000 in more than half the tracked negotiations.
Which firms appeared in the malicious subdomain data?
Reuters matched GTIG indicators to traps aimed at Blackstone, Apollo, Bain Capital, KKR, TPG, Bridgewater, CME Group, Moody’s and Clearlake Capital, plus several hedge funds and law firms; success at any named firm remains unconfirmed publicly.
What single control most reliably stops these calls?
Phishing-resistant MFA using FIDO2 keys or platform passkeys binds authentication cryptographically to the real domain, rendering the lookalike passkey-helpdesk sites useless even if the employee follows the caller’s instructions.
The same low-tech call that emptied casino systems in 2023 is now ringing desks that hold deal books. The brands change. The human gap does not.
-
FINANCE2 months agoZcash Patched a Double-Spend Bug as ZEC Climbed 5%
-
ENTERTAINMENT2 months agoSteam Summer Sale 2026 Locks In June 25 to July 9 Dates
-
FINANCE1 month agoCLARITY Act Final Text Expected This Weekend as 60-Vote Hurdle Looms
-
NEWS3 months agoMeta Adds AI Replies to Threads, But Users Can’t Block It
-
NEWS5 months agoU.S. Navy Deploys Solar-Powered Lightfish Drone to Patrol Oceans
-
ENTERTAINMENT3 months ago‘Widow’s Bay’ Review: Apple TV’s Sleeper Horror-Comedy Earns Its Fog
-
FINANCE2 months agoCLARITY Act Floor Vote Likely Shifts to August, Lummis Says
-
FINANCE1 month agoKalshi Loses Major NY Prediction Markets Ruling to Judge Torres
