Analyzing the BlackFile to Redact Pivot
Google Threat Intelligence Group links the retired BlackFile extortion brand to the active Redact group through shared infrastructure.
New analysis from the Google Threat Intelligence Group (GTIG) has connected the BlackFile extortion group, which utilized vishing scams to target victims, to a rebranding effort under the name Redact. Despite the BlackFile brand announcing its retirement in 2026, researchers have observed a continuation of operations under new identifiers.
Rebranding and Affiliate Claims
Redact operators published a blog post about their new data lead site (DLS) and the rebrand from Black File on June 27. The group claimed that the original BlackFile brand had been compromised and hijacked by an exiled affiliate. A rogue affiliate was apparently responsible for operating an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns under BlackFile’s name using unlinked Tox identities. They were also accused of orchestrating the supposed shutdown of the BlackFile brand in May 2026.
Operational Infrastructure Overlaps
Despite the change in name, the initial access and post-compromise tactics, techniques, and procedures (TTPs) have largely remained the same, according to GTIG. The investigation identified that associated actors have leveraged the Pink, Helix and Falcon extortion brands to monetize operations. GTIG identified that the group reuses generic root domains across multiple target organizations rather than maintaining isolated infrastructure.
This most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes and isolate any negotiation fallout.
— Google Threat Intelligence Group
Shared Phishing and Domains
Specific root domains such as passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of the groups. Across these domains, researchers noted that the same phishing templates were used. In some instances, domains were simultaneously used to target two entirely separate victims, with one claimed by Falcon and the other by Helix. The researchers said, “The widespread deployment of these matching templates to harvest credentials for multiple DLS brands suggests they rely on shared underlying infrastructure.”
Vishing and Credential Harvesting
The group uses voice phishing to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Targets are often lured via personal devices to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. New techniques observed by GTIG include the use of a spoofed legitimate helpdesk phone number, where the caller directs the employee to a lookalike credential-harvesting subdomain under the pretext of an urgent mandate to enable FIDO2 passkeys or update MFA enrollment.
Persistence and Evolution
Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta. The group has also been observed using compromised email accounts to reset passwords for enterprise applications and then delete security notifications and alert emails to evade detection. Between April and May 2026, the group focused on large enterprises in the manufacturing, real estate, healthcare and insurance sectors. In June, it shifted to technology, transportation and hospitality firms, and in July, it narrowed its focus to high-value financial and legal organizations, including private equity firms, law firms and credit rating agencies.
Financial Analysis of Activity
- GTIG reviewed 18 BlackFile Bitcoin wallet addresses.
- These wallets received a total of 141.65 BTC.
- The total value of these transactions was approximately $10.69m USD at the time of the transactions.
- The review period for these transactions was between January 7 and May 12.
Mitigation and Recommendations
GTIG provided several recommendations for mitigation, including enforcing phishing-resistant authenticators, integrating single sign-on (SSO), enforcing session controls to reduce session length and restricting authentication to trusted network sources. Because the scam often involves vishing calls that target personal devices, GTIG said firms should ensure that authentication comes from a corporate-managed endpoint with MDM and EDR.
Strategic Implications
The findings suggest that the emergence of new extortion brands does not necessarily indicate a change in the threat actor behind the activity. For organizations, this highlights that infrastructure and TTPs may persist even after a brand is declared retired. Maintaining visibility into shared UNC6671 infrastructure and securing against vishing-based credential theft remains a critical component of enterprise defense.
Sources
- Infosecurity Magazine Original source
- said Also reporting
Continue Reading
AitM Phishing Targets Financial Data
A sophisticated phishing campaign uses adversary-in-the-middle tactics to compromise Microsoft 365 accounts for financial espionage.
Ransomware Activity Rebounds in July
New data indicates a sharp rise in ransomware incidents throughout July 2026, breaking a multi-month period of lower activity.
ChainDrop Worm Exploits npm Ecosystem
A self-propagating malware campaign has compromised over 1,300 npm packages, leveraging legitimate GitHub workflows to spread.