PortsuppeApp
SearchSourcesAboutDE/EN

Welcome to BlackFile: Inside a Vishing Extortion Operation

Mandiant Blog·12d·Reputable

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gains deep access to cloud environments. The group primarily targets Microsoft 365 and Okta infrastructur

Categories cybersecurity · government-security · unknown-it-category-15
Original source / advisory
Published
5/15/2026, 2:00:00 PM
Fetched
5/27/2026, 4:13:32 AM
Trust
reputable · 80/100
Language
en