UNC6671 Puts Help-Desk Trust on the Line

Google Threat Intelligence Group linked UNC6671, former BlackFile affiliates, to extortion attacks in recent weeks against private equity firms, financial-ratings agencies and law firms after BlackFile’s supposed retirement in May. The group is using voice phishing to pose as IT help desk staff and steer employees onto adversary-in-the-middle infrastructure that captures credentials and multifactor authentication (MFA) proof as it passes through. That means the victim is logging into a real service while the attacker sits between the user and the site, so the stolen access looks valid. Once inside, the group uses automated scripts to pull large corporate data repositories and then turns that data into extortion pressure. The sector shift matters because finance and legal targets tend to hold sensitive transaction records and are often seen as more likely to pay through cyber insurance. If your workforce trusts phone-based help-desk verification plus MFA, the break is in that approval path, and the exposure can extend to whatever repositories the account can reach.

Sources