Google Threat Intelligence Group (GTIG) is tracking UNC6671, a cybercrime group using voice phishing attacks to steal corporate data and extort victims.
Although the BlackFile extortion brand reportedly shut down in May 2026, the group’s operations appear to have continued under several new names, including Redact, Pink, Helix, and Falcon.
The group targets enterprise workers by posing as internal IT helpdesk staff. Attackers call employees, often on personal mobile numbers, and claim that an urgent security update is required.
The caller may say the employee must enroll a FIDO2 passkey, update multi-factor authentication (MFA), or complete a mandatory Microsoft 365 or Okta migration.
Victims are then directed to fraudulent login pages hosted on domains that imitate passkey, MFA, single sign-on (SSO), and helpdesk services.
These websites use adversary-in-the-middle (AiTM) phishing infrastructure, which can capture usernames, passwords, MFA approvals, and active session tokens.
After gaining access, UNC6671 abuses compromised cloud accounts to access data stored in Microsoft 365, Okta, and other SaaS platforms.
The actors then exfiltrate sensitive files and demand payment in exchange for not publishing the stolen information.
UNC6671 Vishing Hits Financials
GTIG found strong infrastructure links between the BlackFile, Redact, Pink, Helix, and Falcon brands.
While the groups use separate data leak sites and public identities, their attacks frequently rely on identical phishing templates, recurring domain patterns, shared victim targeting, and overlapping infrastructure.

Many phishing domains use terms such as “passkey,” “sso,” “okta,” “setup,” and “portal” to appear credible during helpdesk-themed calls.
Examples include passkeyhelpdesk[.]com, addssopasskey[.]com, createssopasskey[.]com, portalpasskey[.]com, and passkeydeploy[.]com.
The same root domains were often used to target different organizations later associated with separate extortion brands. For example, passkeyhelpdesk[.]com reportedly overlapped with both Falcon and Helix activity.
This does not conclusively prove that every brand is operated by one group, but it indicates either a coordinated operation, splintered affiliates, outsourced extortion services, or shared phishing-as-a-service infrastructure.
UNC6671’s targeting has also shifted. Earlier activity focused broadly on large organizations in healthcare, manufacturing, real estate, insurance, and technology.

By July 2026, the group appeared to prioritize financial services, private equity firms, law firms, and rating agencies.
These sectors hold valuable data related to mergers, acquisitions, litigation, investments, and client financial records. Such information can increase the pressure on victims during extortion negotiations.
The group also increased the speed of its infrastructure deployment.
GTIG observed a faster pace of new phishing-domain registrations in June and July, including a short period when seven domains became active within three days, Google cloud said.
Indicators of Compromise
| IOC Type | Indicator | Role / Notes |
|---|---|---|
| Domain | passkeyhelpdesk[.]com | Shared AiTM phishing infrastructure linked to Falcon and Helix activity |
| Domain | addssopasskey[.]com | Falcon-associated credential-harvesting panel |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN. Gain complete phishing visibility to strengthen your SOC and reduce MTTR