Vishing Crew Turns Helpdesks Into Credential Farms
BlackFile turns the helpdesk into the weak point. Its operators call employees from spoofed numbers, pose as IT support, and use the stolen credentials to get into corporate accounts and extort the victim. The standard response of tightening email security misses the real problem: voice-based social engineering can bypass the controls that protect the inbox.
Unit 42 links the group, also tracked as CL-CRI-1116, UNC6671, and Cordial Spider, to a wave of attacks on retail and hospitality firms since February 2026. RH-ISAC says the crew uses fake login pages, stolen one-time passcodes, and device registration to get around multifactor authentication. Unit 42 also gave the group moderate-confidence ties to The Com, a criminal network known for recruitment, extortion, violence, and CSAM-related activity.
The threat is broader than ransom demands. If that link holds, BlackFile may be part of a criminal ecosystem that mixes credential theft with coercion and abuse, which raises the stakes for any organization that treats this as a simple extortion campaign.