UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments
UNC6671, a threat actor, has continued its operations despite allegedly retiring the BlackFile extortion brand. They're using vishing to target enterprise employees, posing as IT helpdesk staff, and stealing credentials and MFA tokens. This data is then used for data exfiltration from cloud environments like Microsoft 365 and Okta. Financial services and enterprise cloud environments are being targeted. Organizations should harden their security to protect against this threat.