Breaking
AviaMasters: Het Hoogvliegende Crash Game dat Spelers Alert HoudtPlay real money slots at Zizobet Casino: enjoy fast payouts and live actionThe Wellness of Tea Goes Beyond What’s in the CupAquaspins Casino: come sfruttare al meglio il bonus di benvenuto nel 2026Bursa Malaysia ends lower as selling pressure in oil-related counters weighs - The StarUCSI University strengthens global health and science diplomacy collaboration with UNU Global HealthAstro Celebrates 30th Anniversary With Free Access to All Channels and Exclusive Offers for CustomersJulia Farhana Initiates Divorce Proceedings Against Dr Che Hafiz After Seven Months of SeparationHarga tiket GP Bahrain di Sepang serendah RM200‘I Never Intended To Hurt Or Kill Rocky,’ Says Man Accused Of Animal CrueltyNo criminal or corruption elements found in KWAP investigationAdam Lee says old debts remain unpaid as new loans are taken.Malaysians To Receive Free 10GB Data From Five Telcos For Merdeka And Malaysia DayTEEAM at “Think Business, Think Hong Kong” SymposiumBrunei Darussalam Capital Market Development Seminar Series: An Introduction to Sukuk IssuanceOver 90% of UGM Educators Are Gemini Certified through Academic Upskilling InitiativeURIIS 2026 sasar percepat pengkomersialan inovasi universitiLelaki disyaki terjun sungai elak pemeriksaan polis ditemukan lemasBangladesh humble Australia with worst total in contest as Hasan takes 6-55How I Got My Career in Foreign Policy: Sadanand DhumeAviaMasters: Het Hoogvliegende Crash Game dat Spelers Alert HoudtPlay real money slots at Zizobet Casino: enjoy fast payouts and live actionThe Wellness of Tea Goes Beyond What’s in the CupAquaspins Casino: come sfruttare al meglio il bonus di benvenuto nel 2026Bursa Malaysia ends lower as selling pressure in oil-related counters weighs - The StarUCSI University strengthens global health and science diplomacy collaboration with UNU Global HealthAstro Celebrates 30th Anniversary With Free Access to All Channels and Exclusive Offers for CustomersJulia Farhana Initiates Divorce Proceedings Against Dr Che Hafiz After Seven Months of SeparationHarga tiket GP Bahrain di Sepang serendah RM200‘I Never Intended To Hurt Or Kill Rocky,’ Says Man Accused Of Animal CrueltyNo criminal or corruption elements found in KWAP investigationAdam Lee says old debts remain unpaid as new loans are taken.Malaysians To Receive Free 10GB Data From Five Telcos For Merdeka And Malaysia DayTEEAM at “Think Business, Think Hong Kong” SymposiumBrunei Darussalam Capital Market Development Seminar Series: An Introduction to Sukuk IssuanceOver 90% of UGM Educators Are Gemini Certified through Academic Upskilling InitiativeURIIS 2026 sasar percepat pengkomersialan inovasi universitiLelaki disyaki terjun sungai elak pemeriksaan polis ditemukan lemasBangladesh humble Australia with worst total in contest as Hasan takes 6-55How I Got My Career in Foreign Policy: Sadanand Dhume
Economy

Threat Intelligence UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments By Google Threat Intelligence Group • 36-minute read

Visibility and context on the threats that matter most. Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multi

Source: Google Threat Intelligence · August 13, 2026 at 4:13 AM · AI-assisted report

Threat Intelligence UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments By Google Threat Intelligence Group • 36-minute read
Photo: Google LLC / Public domain

KUALA LUMPUR, 13 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

**Malaysian Firms Urged to Bolster Defences as Global Cyber Gang UNC6671 Expands Extortion Campaigns**

KUALA LUMPUR, Aug 13 — A sophisticated cybercrime group tracked by Google’s threat intelligence arm has rebranded and intensified its extortion operations, targeting financial services and enterprise cloud environments, including those used by Malaysian businesses.

Google Threat Intelligence Group (GTIG) said in a report published on Wednesday that UNC6671, previously linked to the now-defunct BlackFile ransomware brand, has diversified its operations under multiple aliases—Redact, Pink, Helix, and Falcon—while continuing to deploy voice phishing (vishing) tactics to steal corporate data for extortion.

The group’s operations have evolved since May 2026, when BlackFile was allegedly retired. However, GTIG’s telemetry and infrastructure analysis indicate that UNC6671 did not disband but instead expanded its reach across new extortion fronts. The threat actor continues to impersonate IT helpdesk staff, contacting employees—including in Malaysia—on their personal mobile devices to trick them into visiting spoofed login portals.

These portals harvest credentials and multi-factor authentication (MFA) tokens via Adversary-in-the-Middle (AiTM) attacks, allowing the group to gain persistent access to enterprise cloud environments such as Microsoft 365 and Okta.

**Shared Infrastructure Links Multiple Brands** GTIG’s investigation revealed significant overlaps in infrastructure and tactics across the Redact, Pink, Helix, and Falcon brands, suggesting they are operated by the same core group or closely affiliated entities. On June 27, 2026, Redact published a blog post claiming it had rebranded from BlackFile due to an alleged affiliate breakaway.

The group alleged that a former associate had hijacked the BlackFile brand by operating an unauthorized data leak site (DLS) and conducting unsanctioned extortion campaigns under its name.

Redact stated that the rogue affiliate used unlinked Tox identities and intentionally orchestrated the shutdown of BlackFile to damage its reputation and sow confusion among cybersecurity analysts and insurers. The group introduced a single verified Tox ID and PGP key to authenticate future communications, distancing itself from the BlackFile brand.

Despite these claims, GTIG’s analysis of phishing templates, victim targeting, and shared infrastructure conduits supports the assessment that a common group is behind all four extortion brands. Alternative scenarios, such as splintered affiliates or shared Phishing-as-a-Service infrastructure, remain plausible.

**Malaysian and Regional Targets in Crosshairs** GTIG’s report highlights a clear shift in UNC6671’s targeting strategy, with a growing focus on sectors holding high-value data. Between April and May 2026, the group broadly targeted large enterprises in manufacturing, real estate, healthcare, and insurance. In June 2026, the focus expanded to technology, transportation, and hospitality firms, particularly those with valuable intellectual property, software source code, or sensitive VIP client data.

By July 2026, UNC6671 narrowed its focus to financial services, private equity, professional services, law firms, and financial rating agencies. This shift suggests the group is prioritizing organizations involved in mergers and acquisitions, capital deployment, and litigation—sectors likely to hold confidential corporate data that can be weaponized for extortion.

The group’s operational tempo has also accelerated. Between June 1 and July 31, 2026, GTIG observed the provisioning of approximately one new phishing domain every 1.6 days, primarily hosted on Cloudflare and DDOS-GUARD. A brief spike occurred between July 20 and 22, with seven domains operationalized within 72 hours. This represents a measurable increase from the April–May period, where 28 root domains were deployed at a rate of one every 2.2 days.

As of the report’s publication, seven of eight still-resolving phishing domains did not use wildcard DNS, indicating that targets were likely specifically selected rather than randomly discovered.

**Tactics Remain Consistent, but New Techniques Emerge** UNC6671’s core tactics have remained consistent: tailored vishing calls, AiTM credential harvesting, and automated data exfiltration from SaaS applications. However, GTIG noted the emergence of new techniques, including the continued use of personal mobile devices to contact employees—a tactic likely to bypass corporate security controls.

The group’s phishing infrastructure is highly modular, with root domains such as **passkeyhelpdesk[.]com**, **portalpasskey[.]com**, and **addssopasskey[.]com** used to host credential harvesting panels. These domains mimic enterprise authentication portals, incorporating terms like “passkey,” “mfa,” and “sso” to appear legitimate.

Notably, the same phishing templates have been deployed across multiple domains simultaneously. For example, **addssopasskey[.]com** was used to target organizations later extorted under the Falcon brand, while **passkeyhelpdesk[.]com**—hosting identical code—was used to target separate victims claimed by both Falcon and Helix.

**Overlapping Infrastructure Across Brands** GTIG’s analysis identified direct overlaps in targeting between brands. The domain **passkeyhelpdesk[.]com** was used to target at least one Falcon victim and one Helix victim. Similarly, **setupsso[.]com** and **idokta[.]com** were linked to BlackFile victims, with intermediary targets bridging into **passkeydeploy[.]com** (Pink) and **passkeyportal[.]com** (Helix).

The widespread reuse of identical phishing templates across different domains suggests shared underlying infrastructure, reinforcing the likelihood that these brands are operated by the same group or a tightly coordinated network of affiliates.

**Malaysia’s Exposure and Response** While the report does not specify confirmed attacks in Malaysia, the country’s growing digital economy and heavy reliance on cloud services—particularly Microsoft 365 and Okta—make it a potential target for UNC6671’s evolving tactics.

Local cybersecurity experts warn that Malaysian enterprises, especially those in financial services, private equity, and professional services, should treat this threat as imminent. The use of vishing to bypass technical controls and the targeting of personal mobile devices highlight the need for layered defences, including employee awareness training and robust MFA policies.

“Organizations must assume that credential harvesting attempts will succeed at some point,” said a cybersecurity analyst with a Malaysian firm, who requested anonymity. “The focus should be on limiting lateral movement and detecting data exfiltration early.”

GTIG’s report includes hardening guidance for organizations, emphasizing the importance of monitoring for AiTM attacks, restricting session persistence, and implementing strict access controls for cloud environments.

**Forward-Looking Assessment** The diversification of UNC6671’s extortion brands and its accelerated operational tempo suggest a group that is not only resilient but also adaptive. The shift toward high-value sectors—including those critical to Malaysia’s economic growth—indicates that the threat will likely intensify in the coming months.

As UNC6671 continues to refine its tactics, cybersecurity teams in Malaysia and across Southeast Asia must prioritize threat intelligence sharing and proactive defence measures. The group’s reliance on shared infrastructure and consistent TTPs provides defenders with opportunities to detect and disrupt its operations—but only if organizations remain vigilant and prepared.

Details not yet available on whether Malaysian entities have been directly impacted by UNC6671’s latest campaigns.

Related: Google · Google Threat Intelligence Group · Kuala Lumpur

Malaysia Impact

The threat may impact Malaysian businesses, particularly those in financial services, private equity, and professional services, by compromising their data and systems. This could lead to financial losses and reputational damage.

Reporting based on Google Threat Intelligence. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.