Same Scammers, New Names: Vishing Extortion Gang Rebrands to Evade Detection
Security researchers at Google Threat Intelligence Group say a threat actor known as UNC6671 has not disappeared despite publicly announcing the retirement of its 'BlackFile' extortion brand in May 2026. Instead, the group has spread its operations across several new extortion fronts, including brands called Redact, Pink, Helix, and Falcon, all sharing the same underlying infrastructure and techniques.
The group's method relies heavily on voice phishing, where attackers call employees on their personal mobile phones pretending to be IT helpdesk staff carrying out an urgent, mandatory security migration. Victims are directed to fake login pages that intercept usernames, passwords, and multi-factor authentication codes in real time. Once the attackers gain access, they use automated tools to steal data from cloud platforms such as Microsoft 365 and Okta.
Researchers note that although each extortion brand publishes stolen data on its own separate leak site, the phishing templates, target selection, and shared infrastructure make clear these are the same actors operating under different names. Recent targeting has focused on financial services, private equity, and professional services firms.