Breaking
Cyber CrimeDeveloping Story

UNC6671 Targets SaaS via Personal Phones

Threat actors are bypassing standard enterprise security by using vishing attacks to compromise personal mobile devices.

··1 day ago·3 min read
a group of cubes that are on a black surface
Photo by Shubham Dhage on Unsplash

A sophisticated threat group identified as UNC6671 is actively targeting employees within financial services, private equity, and professional services sectors. By pivoting away from traditional corporate network vectors, these attackers are increasingly utilizing personal mobile devices to gain a foothold in secure enterprise environments.

The group relies on voice phishing, or vishing, to manipulate staff into believing they are speaking with legitimate IT help desk representatives. These interactions are often staged to create a false sense of urgency regarding mandatory security migrations, compelling victims to visit fraudulent login portals designed to capture sensitive credentials and multi-factor authentication tokens.

Tactics of Identity Compromise

Once a victim is directed to a spoofed portal, the attackers utilize adversary-in-the-middle infrastructure to intercept login data in real time. This allows the group to bypass standard security measures and establish session persistence. The attackers then deploy automated scripts, written in Python and PowerShell, to exfiltrate vast amounts of data from cloud environments and software-as-a-service applications, specifically targeting platforms like Microsoft 365 and Okta.

The group often attempts to solidify their unauthorized access by registering their own adversary-controlled devices for multi-factor authentication. Before doing so, they systematically remove any existing registered devices, effectively locking legitimate users out of their own accounts while maintaining a persistent, authenticated session for the duration of their data theft operations.

The Evolution of Extortion Brands

UNC6671 maintains a complex operational structure, often distributing its activities across multiple public-facing extortion brands. This strategy appears designed to compartmentalize negotiations and complicate efforts by security researchers to track the group's movements. Known associated brands include Redact, Pink, Helix, and Falcon.

Historically, the group operated under the BlackFile brand before it was officially retired in May 2026. Internal shifts in these brands have been marked by various claims of hijacking or compromise, with some entities, such as Falcon, publicly asserting they operate as exclusive affiliates of Redact while distancing themselves from the broader UNC6671 designation.

UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices.

— Google Threat Intelligence Group (GTIG) and Mandiant

Financial Impact and Scope

  • Between January 7 and May 12, 2026, tracked Bitcoin payments to associated wallets exceeded $10.6 million.
  • Initial ransom demands typically start above $3 million per incident.
  • Extortionists frequently reduce initial demands by 50% to 75% during active negotiations.
  • In more than 53% of cases tracked within the specified timeframe, settlements averaged $750,000.

Shifting Targets and Techniques

The group's targeting strategy has shown significant volatility throughout 2026. While early efforts focused on manufacturing, real estate, healthcare, and insurance, the focus shifted to technology, transportation, and hospitality firms by June 2026. By July 2026, the primary targets transitioned toward high-value financial and legal organizations.

The attackers also employ specialized credential harvesting panels hosted on generic domains, often appending victim-specific subdomains to increase the perceived legitimacy of their phishing campaigns. This allows them to simultaneously target multiple organizations using infrastructure that mimics official passkey or single sign-on help desk portals.

Implications for Enterprise Security

The success of these campaigns underscores a critical reality: the primary vulnerability is not necessarily a flaw in software code or infrastructure, but the human element of trust. Because these attacks leverage legitimate identity providers to gain entry, they can move laterally across an entire SaaS ecosystem using a single authenticated session.

For organizations, this suggests that traditional reliance on standard MFA is no longer sufficient. Moving toward phishing-resistant authentication methods, strictly enforcing session controls, and restricting access to corporate-managed devices may become essential. As extortion groups continue to operate with the efficiency of decentralized corporate networks, the ability to monitor identity provider logs for unauthorized MFA registration events will likely be a decisive factor in detecting and mitigating these incursions before data exfiltration occurs.

#vishing#saas#unc6671#cybercrime#identity

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories