Google Threat Intelligence and Mandiant tied a wave of attacks on financial services, private equity, and professional services firms to data extortion group UNC6671, which reaches employees on their personal mobile devices. The group poses as IT help desk staff orchestrating mandatory, urgent security migrations.
Victims are walked to lookalike login pages where adversary-in-the-middle gear harvests credentials and MFA tokens. With that foothold, the attackers keep sessions alive and use automated Python and PowerShell scripts to pull data out of Microsoft 365, Okta, and other SaaS platforms.
The group now operates under several extortion labels – Redact, Pink, Helix, and Falcon – having shelved the BlackFile name back in May. It spoofs help desk phone numbers, registers adversary-controlled MFA devices to compromised accounts, and deletes password-reset confirmations and security alerts to evade detection.
Google said the group shifted its targeting from manufacturing, real estate, healthcare, and insurance in April and May to technology, transportation, and hospitality in June, and to high-value financial and legal organizations in July. CrowdStrike tracks the collective as Cordial Spider.
Organizations should push phishing-resistant MFA and treat calls from unknown numbers claiming to be help desk as suspicious.
