Inside UNC6671’s “BlackFile” Cloud Extortion Campaigns
ID: 757995a4-b4e9-5a33-8ca7-2d5ed1b2f58c
STIX ID: report--757995a4-b4e9-5a33-8ca7-2d5ed1b2f58c
Feed Name: securityonline.info
UNC6671, also known as BlackFile, is an identity-focused extortion group that used vishing and adversary-in-the-middle (AiTM) proxy infrastructure to intercept credentials and active session cookies, bypass MFA, and exfiltrate sensitive data from Microsoft 365 and Okta environments across dozens of organizations in North America, Australia, and the UK; the group published stolen data on a data-leak site for extortion before announcing a shutdown of the BlackFile brand, though its methods remain a significant blueprint for future attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
