Welcome to BlackFile: Inside a Vishing Extortion Operation
ID: 5eabfeff-6450-5834-ac6d-489c82de3b34
STIX ID: report--5eabfeff-6450-5834-ac6d-489c82de3b34
Feed Name: Threat Intelligence
UNC6671 (aka BlackFile) runs a large-scale extortion campaign using voice phishing (vishing) and AiTM techniques to bypass MFA and compromise SSO accounts (Microsoft 365 and Okta), then programmatically exfiltrate sensitive data (SharePoint, OneDrive, Zendesk, Salesforce) using scripts and stolen session cookies; GTIG documents their credential-harvesting domains, tactics for device registration persistence, and recommends phishing-resistant MFA and telemetry-focused detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
