UNC6671 Targets SaaS via Personal Phones
Threat actors are bypassing standard enterprise security by using vishing attacks to compromise personal mobile devices.
A sophisticated threat group identified as UNC6671 is actively targeting employees within financial services, private equity, and professional services sectors. By pivoting away from traditional corporate network vectors, these attackers are increasingly utilizing personal mobile devices to gain a foothold in secure enterprise environments.
The group relies on voice phishing, or vishing, to manipulate staff into believing they are speaking with legitimate IT help desk representatives. These interactions are often staged to create a false sense of urgency regarding mandatory security migrations, compelling victims to visit fraudulent login portals designed to capture sensitive credentials and multi-factor authentication tokens.
Tactics of Identity Compromise
Once a victim is directed to a spoofed portal, the attackers utilize adversary-in-the-middle infrastructure to intercept login data in real time. This allows the group to bypass standard security measures and establish session persistence. The attackers then deploy automated scripts, written in Python and PowerShell, to exfiltrate vast amounts of data from cloud environments and software-as-a-service applications, specifically targeting platforms like Microsoft 365 and Okta.
The group often attempts to solidify their unauthorized access by registering their own adversary-controlled devices for multi-factor authentication. Before doing so, they systematically remove any existing registered devices, effectively locking legitimate users out of their own accounts while maintaining a persistent, authenticated session for the duration of their data theft operations.
The Evolution of Extortion Brands
UNC6671 maintains a complex operational structure, often distributing its activities across multiple public-facing extortion brands. This strategy appears designed to compartmentalize negotiations and complicate efforts by security researchers to track the group's movements. Known associated brands include Redact, Pink, Helix, and Falcon.
Historically, the group operated under the BlackFile brand before it was officially retired in May 2026. Internal shifts in these brands have been marked by various claims of hijacking or compromise, with some entities, such as Falcon, publicly asserting they operate as exclusive affiliates of Redact while distancing themselves from the broader UNC6671 designation.
UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via their personal mobile devices.
— Google Threat Intelligence Group (GTIG) and Mandiant
Financial Impact and Scope
- Between January 7 and May 12, 2026, tracked Bitcoin payments to associated wallets exceeded $10.6 million.
- Initial ransom demands typically start above $3 million per incident.
- Extortionists frequently reduce initial demands by 50% to 75% during active negotiations.
- In more than 53% of cases tracked within the specified timeframe, settlements averaged $750,000.
Shifting Targets and Techniques
The group's targeting strategy has shown significant volatility throughout 2026. While early efforts focused on manufacturing, real estate, healthcare, and insurance, the focus shifted to technology, transportation, and hospitality firms by June 2026. By July 2026, the primary targets transitioned toward high-value financial and legal organizations.
The attackers also employ specialized credential harvesting panels hosted on generic domains, often appending victim-specific subdomains to increase the perceived legitimacy of their phishing campaigns. This allows them to simultaneously target multiple organizations using infrastructure that mimics official passkey or single sign-on help desk portals.
Implications for Enterprise Security
The success of these campaigns underscores a critical reality: the primary vulnerability is not necessarily a flaw in software code or infrastructure, but the human element of trust. Because these attacks leverage legitimate identity providers to gain entry, they can move laterally across an entire SaaS ecosystem using a single authenticated session.
For organizations, this suggests that traditional reliance on standard MFA is no longer sufficient. Moving toward phishing-resistant authentication methods, strictly enforcing session controls, and restricting access to corporate-managed devices may become essential. As extortion groups continue to operate with the efficiency of decentralized corporate networks, the ability to monitor identity provider logs for unauthorized MFA registration events will likely be a decisive factor in detecting and mitigating these incursions before data exfiltration occurs.
Sources
- The Hacker News Original source
Continue Reading
Unlimited Technology Systems Data Exposure
A server breach at Unlimited Technology Systems has exposed the personal and medical records of 3,803,750 individuals.
NHS Tayside Probes Unauthorized Record Access
A Scottish health trust is investigating reports that staff improperly accessed the medical files of a recently deceased child.
Mac Crypto Drainer Uses ClickFix Tactics
A newly identified Go-based malware targets macOS users by leveraging social engineering to steal credentials and crypto assets.