basicsecurity.net
Proof, not just disclosure.
Threats / Actors / UNC6671
UNC6671 Criminalour call,
not MITRE’s
ATT&CK Group

UNC6671

How MITRE ATT&CK characterizes this group: UNC6671 is a financially motivated threat cluster tracked by Google Threat Intelligence Group (GTIG/Mandiant), active since at least early January 2026. It operates in the ShinyHunters-style SaaS data-theft ecosystem but is tracked separately from UNC6661 and UNC6240 to account for evolving partnerships and possible impersonation. Its chain is entirely social-engineering driven: vishing calls impersonating IT staff direct victims to victim-branded…

Origin / sponsor: not established from a curated public advisory — see Coverage & confidence. Not asserted here.

Also tracked as: BlackFile (extortion brand) Redact (reported rebrand) Pink (reported rebrand) Helix (reported rebrand) Falcon (reported rebrand) — ATT&CK group page
Read this as · tier is our editorial call, not MITRE’s

Motivation not classified from the public record.

We could not place this actor into a coarse motivation tier from ATT&CK’s intrusion-set type and description prose. That uncertainty is itself a finding — the tradecraft below is still cited; the “why” is a coverage gap. All tradecraft below is sourced to MITRE ATT&CK.

active since early January 2026approx.
Activity bounds (campaign floor)
approximate1
01

Known for

— signature moves, each sourced to ATT&CK
ReachFurthest outcome. This cluster's cited tradecraft reaches as far as outcome 5 — Lights out — disruption & extortion. (editorial mapping over ATT&CK tactics).
02

Tradecraft heatmap

— ATT&CK techniques mapped onto the five attacker-outcome narratives

Each row is a documented technique (MITRE ATT&CK). Each column is one of the five attacker-outcome narratives a defender funds against. A filled cell means this technique’s own ATT&CK tactic defensibly advances that outcome. DOUBLY editorial on this card: (1) the technique list itself is our curated mapping of GTIG/press-reported behavior onto ATT&CK techniques — MITRE has no group entry for UNC6671, so no technique is MITRE-attributed; (2) the technique→outcome column mapping is the standard editorial alignment over each technique's own ATT&CK tactics. Enabler tactics (Resource Development, Defense Evasion) heat no column.

Reach: this actor’s cited techniques light columns 1·2·4·5 — furthest is 5 · Lights out. (furthest-position idiom, reused from the landing map).

A dot = this technique advances that outcomeColumn 3 (Lateral reach) is empty — Compare: a hands-on-keyboard intruder lights column 3.
Editorial: the technique→outcome alignment is our call over ATT&CK’s tactic data, not a separately-sourced MITRE edge — same basis the landing page declares. Enabler tactics (C2, defense evasion, discovery) heat no column.
03

Arsenal

— named tools & malware ATT&CK attributes to this group
No named arsenalCoverage gap

ATT&CK attributes no software to UNC6671 at this snapshot. Absence is a finding, not a claim of harmlessness.

04

Campaign highlights

— attributed operations in the ATT&CK record
?

No attributed campaigns — coverage gap

Stated, not hidden
ATT&CK lists no first-class campaign object for UNC6671 at this snapshot. Public reporting may tie this actor to operations; those enter only with a named advisory under the same cite-or-die rule.
05

Latest activity

— with explicit confidence, and what we cannot yet claim
ATT&CK
snapshot

The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.

ATT&CK snapshot, compiled n/a — no ATT&CK group entry (enterprise snapshot 2026-06-22 checked)Coverage gap — live “currently active” status not asserted
CVE ↔ actor bridge: no confirmed CVE link is established for this group. ATT&CK provides no first-class group→CVE relationship, so this card does not claim specific CVEs as “exploited by this actor” unless a named advisory says so. Absence of a CVE here is a coverage gap, never a clean bill — confirmed links surface as a cited, linked list as the advisory bridge grows.
06

Coverage & confidence

— what we know, and what we don’t

Established (cited)

  • Cluster identity, motivation, and tracking rationale — GTIG/Mandiant primary reporting (Jan–Feb 2026): financially motivated; tracked separately from UNC6661/UNC6240 for partnership-vs-impersonation clarity
  • Initial access — vishing impersonating IT staff; victim-branded SSO credential-harvesting domains (<company>sso[.]com, my<company>sso[.]com, <company>internal[.]com), registered via Tucows (a discriminator from UNC6661's NICENIC registrations) — GTIG
  • Credential/MFA capture — victims directed to enter SSO credentials and MFA codes on the harvesting site — GTIG
  • Post-compromise — Okta customer accounts accessed; PowerShell used to bulk-download data from SharePoint and OneDrive — GTIG
  • Extortion — unbranded emails, distinct Tox ID (separate from UNC6240's negotiation account), 72-hour payment demands, harassment of victim personnel — GTIG
  • Explicitly NOT vulnerability-driven — GTIG: 'This activity is not the result of a security vulnerability in vendors' products or infrastructure' — the entire chain is social engineering
  • BlackFile extortion brand association — Mandiant public statement
  • Financial-sector victims (hedge funds) — press reporting
  • Coverage gaps — stated, not hidden

  • No MITRE ATT&CK group entry (no G-id) as of the enterprise-attack snapshot 2026-06-22 — this card is CURATED from cited vendor and press reporting, NOT produced by the deterministic ATT&CK builder; the deterministic-only guarantee that covers the other actor cards does not apply here and this card says so out loud.
  • No CVE linkage BY DESIGN — the chain exploits people and process, not software. This cluster is structurally invisible to the KEV/EPSS-keyed record corpus and to the ATT&CK-keyed actor corpus simultaneously; that double absence is the headline coverage finding of this card.
  • The technique list is our editorial mapping of reported behavior onto ATT&CK techniques — no technique here is MITRE-attributed to this cluster.
  • Rebrand set (Redact, Pink, Helix, Falcon) is single-sourced press reporting citing Google — pending a primary GTIG publication, treat as reported, not confirmed. BlackFile is Mandiant-stated.
  • Aliases listed are extortion BRAND names, not vetted group aliases — brand-vs-operator identity is exactly the kind of claim this corpus cannot yet represent structurally (see provenance note).
  • Relationship to UNC6661/UNC6240 and the ShinyHunters ecosystem unresolved — GTIG's own caveat: separate tracking to account for evolving partnerships and potential impersonation.
  • Victimology beyond financial services not established; victim counts unknown; no public IOC set beyond domain-pattern shapes is catalogued here (link-never-host applies to infrastructure lists too).
  • Threat tier is OUR editorial classification, not a MITRE field — labeled as such.