UNC6671: Helpdesk Vishing, SSO and SaaS Cross-Traversal, and Multi-Brand Extortion via Notification Deletion
UNC6671: Helpdesk Vishing, SSO and SaaS Cross-Traversal, and Multi-Brand Extortion via Notification Deletion 1. Basic Information - Article Title: UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments - Publisher: Google Cloud Threat Intelligence - Publication Date: August 6, 2026 - Source: Google Cloud Threat Intelligence - Related Sources: Previous BlackFile Investigation / BleepingComputer - Related Entities: UNC6671, BlackFile, Redact, Pink, Helix, Falcon, Microsoft 365, Okta, SharePoint, OneDrive - Severity: High 2. Executive Summary This is an extortion chain where attackers use helpdesk vishing on personal mobile phones and AiTM phishing to steal SSO sessions. They use scripts to steal large amounts of data from connected SaaS platforms, and then delete password resets, MFA changes, and company-wide warning emails to delay detection. 3. Attack Flow Chain A: Identity Compromise - Attackers call a personal mobile phone while pretending to be the internal helpdesk (sometimes spoofing legitimate phone numbers). - They explain that migrating to passkeys, FIDO2, or MFA is an urgent task. - They direct the user to a lookalike domain that includes the victim organization's name in a subdomain. - An AiTM site intercepts and steals IDs, passwords, and MFA tokens or sessions. - They establish a Microsoft 365 or Okta session and move laterally to connected SaaS applications. Chain B: Automated Theft and Evidence Suppression - They scout SharePoint and OneDrive using a browser. - They switch to Python, PowerShell, or Microsoft Graph to download large numbers of files. - They use direct HTTP fetches to record some actions as FileAccessed instead ofFileDownloaded . - They reset passwords for non-SSO applications from the compromised mailbox. - They delete password resets, security notifications, MFA changes, and company-wide warning emails. - They carry out extortion under brands such as Redact, Pink, Helix, and Falcon. 4. Attacker Position and Execution Location - Callers use telephone networks, personal mobile phones, and phone number spoofing. - AiTM kits run on newly registered lookalike domains and victim-specific subdomains. - Interactive access and scripted exfiltration run from residential proxies, VPNs, and hosting providers. - The main execution locations are IdPs, mailboxes, Microsoft 365, and connected SaaS, rather than end-user devices. 5. Visibility for Victims and Administrators To users, the activity looks like a legitimate helpdesk change process. To SOCs, it looks like MFA failures and re-enrollments, unmanaged devices, residential proxies, massive FileAccessed events on the same account, and User-Agents like python-requests . Deleting notification emails can remove initial signals for both users and administrators. 6. Success and Failure Conditions Success Conditions - Attackers know the phone number, department, and internal helpdesk context. - The victim authenticates on the AiTM site and passes non-phishing-resistant factors. - The attacker can reach SSO and SaaS from the stolen session. - There is a lack of correlated monitoring for UAL, IdP, and mailbox operations. Failure Conditions - The helpdesk enforces a strict policy of never requesting authentication changes over personal mobile phones. - Device-bound passkeys/FIDO2 and managed-device conditions are enforced. - High-risk sessions are forced to re-authenticate or are revoked. - MFA changes, deleted emails, and massive FileAccessed events are detected immediately. 7. What Happens on Success Large amounts of data are stolen from emails, documents, CRMs, and support systems connected to SSO. Password resets expand the breach to non-SSO applications. After internal notifications are deleted, high-value extortion is carried out using the stolen data. 8. Observable Logs - Email: Immediate deletion of reset/MFA/security emails, deletion of company-wide warnings, and rules, searches, and sends from the compromised mailbox. - Proxy/SWG/DNS: Newly registered passkey/enrollment domains, victim-specific subdomains, and residential proxies/VPNs. - Endpoint/EDR: Generally no malware is needed. Check browser history, clipboard, and remote support tools for auxiliary confirmation. - Identity/IdP: Factor setup immediately after MFA push failures/abandonment, unmanaged devices, new sessions, and session persistence. - SaaS/Cloud: Massive FileAccessed /FileDownloaded ,python-requests ,WindowsPowerShell ,Go-http-client , and mismatches between ClientAppId and User-Agent. - Network: Parallel file access exceeding human reading speed and long-duration data transfers. 9. Attack Success Determination - Contact Only: Phone call, domain access, authentication page view. - User Engagement: Credential/MFA input, push approval, passkey registration. - Initial Execution: AiTM acquires token/session. - Authentication Success: IdP/SaaS session established from attacker infrastructure. - Data Theft / Session Compromise: Scripted file access, external transfer, password reset. - Subsequent Compromise Confirmation: Other SaaS, email deletion, internal account usage, extortion note. 10. Investigation Playbook - Trigger: Helpdesk vishing report, MFA factor change, script User-Agent, massive FileAccessed . - Initial Check: Create a single timeline for phone calls, URLs, authentication, token issuance, and initial SaaS operations. - Endpoints: Preserve browser history/cookies, downloads, and remote tools, but do not assume endpoint infection. - Authentication / Cloud: Revoke all sessions/tokens, re-register factors, and check connected SaaS and non-SSO resets across the board. - Subsequent Operations: Investigate mailbox deletions, rules, Graph/API access, file volumes, and external sharing. - Containment: Suspend accounts, reissue factors/sessions, reset passwords, block domains, and preserve related mailboxes. - Determination Levels: Contact / User Engaged / Session Stolen / SaaS Access / Data Theft / Cross-SaaS Expansion / Extortion. 11. Defense and Detection Ideas - Single Events: Newly registered domains, new factors, script User-Agents, security email deletions. - Time-Series Correlation: MFA failure/abandonment โ factor setup โ new session โ massive FileAccessed โ alert deletion. - Threat Hunting: ClientAppId is Office but User-Agent is python-requests , high volume from unmanaged devices, logins immediately following a password reset. - Log Gaps: Personal phone calls, full UAL, mailbox hard-deletes, IdP challenge lifecycle, SaaS API logs. - Priority Countermeasures: Device-bound passkeys, managed-device conditional access, helpdesk callbacks, session revocation training, UAL correlation. 12. Facts / Inference / Hypothesis Facts - GTIG reported that UNC6671 shifted to multiple brands and targeted organizations in finance, law, and investment. - AiTM, SSO, and SaaS data theft via Python/PowerShell/Graph were observed. - Attackers deleted reset, security, MFA, and company-wide warning emails. - They used direct fetches recorded as FileAccessed . Inference - SOCs that only monitor FileDownloaded will underestimate the amount of stolen data. - Once the deletion of password reset notifications is confirmed, applications other than mailboxes should also be treated as compromised. Hypothesis - Affiliates or PhaaS sharing the same kit may explain some brand overlapping. - If personal mobile information of domestic financial and legal organization employees leaks, the same pretext can be reused. 13. MITRE ATT&CK Mapping - High Confidence: T1598.004 Spearphishing Voice, T1566.002 Spearphishing Link, T1557 Adversary-in-the-Middle, T1539 Steal Web Session Cookie, T1078 Valid Accounts, T1213.002 SharePoint, T1114 Email Collection, T1567 Exfiltration Over Web Service, T1070.008 Clear Mailbox Data. - Medium Confidence: T1098 Account Manipulation, T1136 Create Account, T1583.001 Domains, T1090 Proxy. 14. Unknowns / Additional Investigation - Relationships between operators and affiliates of each brand. - Impact on victim organizations and financial payment status. - Lifespan of stolen sessions and device binding. - Password reset and theft scope for each non-SSO application. - Residential proxies, mail accounts, and tool hashes outside of public IOCs. 15. Impact on Global SOCs and Enterprises Cloud compromises can be completed entirely through phone calls to personal mobile devices, without requiring endpoint malware. Organizations are increasingly centralizing around SSO (such as Microsoft 365, Okta, and Salesforce), making it necessary to operate across helpdesk identity verification, IdPs, UALs, mailboxes, and individual SaaS audit logs. 16. Summary by Role - For SOCs: Treat FileAccessed and script User-Agents as theft signals, and correlate them with MFA changes and email deletions. - For Administrators: Enforce not only phishing-resistant MFA, but also managed devices, session revocations, and helpdesk callbacks. - For Users: Even if a call claims to be from the helpdesk, do not authenticate on provided URLs; instead, call back using known internal contact channels. Top comments (0)
Comments
No comments yet. Start the discussion.