Breaking
Cyber CrimeDeveloping Story

Analyzing the BlackFile to Redact Pivot

Google Threat Intelligence Group links the retired BlackFile extortion brand to the active Redact group through shared infrastructure.

··1 hour ago·3 min read
a blue and white logo
Photo by Growtika on Unsplash

New analysis from the Google Threat Intelligence Group (GTIG) has connected the BlackFile extortion group, which utilized vishing scams to target victims, to a rebranding effort under the name Redact. Despite the BlackFile brand announcing its retirement in 2026, researchers have observed a continuation of operations under new identifiers.

Rebranding and Affiliate Claims

Redact operators published a blog post about their new data lead site (DLS) and the rebrand from Black File on June 27. The group claimed that the original BlackFile brand had been compromised and hijacked by an exiled affiliate. A rogue affiliate was apparently responsible for operating an unauthorized, lookalike DLS and conducted unsanctioned extortion campaigns under BlackFile’s name using unlinked Tox identities. They were also accused of orchestrating the supposed shutdown of the BlackFile brand in May 2026.

Operational Infrastructure Overlaps

Despite the change in name, the initial access and post-compromise tactics, techniques, and procedures (TTPs) have largely remained the same, according to GTIG. The investigation identified that associated actors have leveraged the Pink, Helix and Falcon extortion brands to monetize operations. GTIG identified that the group reuses generic root domains across multiple target organizations rather than maintaining isolated infrastructure.

This most likely reflects a coordinated group of threat actors operating multiple public extortion brands possibly in an effort to compartmentalize operations, hide overall breach volumes and isolate any negotiation fallout.

— Google Threat Intelligence Group

Shared Phishing and Domains

Specific root domains such as passkeyhelpdesk[.]com and passkeydeploy[.]com were used by more than one of the groups. Across these domains, researchers noted that the same phishing templates were used. In some instances, domains were simultaneously used to target two entirely separate victims, with one claimed by Falcon and the other by Helix. The researchers said, “The widespread deployment of these matching templates to harvest credentials for multiple DLS brands suggests they rely on shared underlying infrastructure.”

Vishing and Credential Harvesting

The group uses voice phishing to target enterprise employees, posing as IT helpdesk staff facilitating mandatory, urgent security migrations. Targets are often lured via personal devices to spoofed login portals where Adversary-in-the-Middle (AiTM) infrastructure intercepts credentials and multi-factor authentication (MFA) tokens. New techniques observed by GTIG include the use of a spoofed legitimate helpdesk phone number, where the caller directs the employee to a lookalike credential-harvesting subdomain under the pretext of an urgent mandate to enable FIDO2 passkeys or update MFA enrollment.

Persistence and Evolution

Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta. The group has also been observed using compromised email accounts to reset passwords for enterprise applications and then delete security notifications and alert emails to evade detection. Between April and May 2026, the group focused on large enterprises in the manufacturing, real estate, healthcare and insurance sectors. In June, it shifted to technology, transportation and hospitality firms, and in July, it narrowed its focus to high-value financial and legal organizations, including private equity firms, law firms and credit rating agencies.

Financial Analysis of Activity

  • GTIG reviewed 18 BlackFile Bitcoin wallet addresses.
  • These wallets received a total of 141.65 BTC.
  • The total value of these transactions was approximately $10.69m USD at the time of the transactions.
  • The review period for these transactions was between January 7 and May 12.

Mitigation and Recommendations

GTIG provided several recommendations for mitigation, including enforcing phishing-resistant authenticators, integrating single sign-on (SSO), enforcing session controls to reduce session length and restricting authentication to trusted network sources. Because the scam often involves vishing calls that target personal devices, GTIG said firms should ensure that authentication comes from a corporate-managed endpoint with MDM and EDR.

Strategic Implications

The findings suggest that the emergence of new extortion brands does not necessarily indicate a change in the threat actor behind the activity. For organizations, this highlights that infrastructure and TTPs may persist even after a brand is declared retired. Maintaining visibility into shared UNC6671 infrastructure and securing against vishing-based credential theft remains a critical component of enterprise defense.

#extortion#phishing#vishing#gtig#cybercrime

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories