UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

UNC6671 continues conducting data theft extortion operations despite the alleged retirement of the BlackFile brand in May 2026. The threat actor has diversified across multiple extortion fronts including Redact, Pink, Helix, and Falcon. They employ voice phishing tactics, posing as IT helpdesk staff to contact employees on personal mobile devices, directing them to spoofed login portals with Adversary-in-the-Middle infrastructure that intercepts credentials and multi-factor authentication tokens. Once access is established, automated scripts exfiltrate data from enterprise cloud environments including Microsoft 365 and Okta. Infrastructure analysis reveals shared phishing panels, overlapping victim targeting, and connected domains across all brands. Recent targeting has evolved toward financial services, private equity, legal, and professional services sectors. Between January and May 2026, Bitcoin wallet analysis showed approximately $10.69 million USD in ransom payments, with demands typically ranging fr...

blackfile
saas-exfiltration
pink
adversary-in-the-middle
phishing-resistant-mfa
redact
data-theft-extortion
vishing
credential-harvesting
helix
Read More

Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam

A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.

macos
stealer
cryptocurrency theft
macsync
social engineering
credential harvesting
aeza group
clickfix
mach-o
Read More

Token Jacking: Cybercriminals Could Be Stealing Your AI Resources

Cybercriminals are exploiting API keys used by developers to access AI platforms through a technique called token jacking. Attackers steal these authentication tokens to gain unauthorized access to expensive AI resources, which they either use themselves or resell through gray-market services called transfer stations. These transfer stations act as intermediaries, offering frontier AI model access at discounted rates using stolen credentials. The financial impact can be catastrophic, with victims potentially losing hundreds of thousands to millions of dollars before detection due to unlimited scaling defaults and cyclical billing. Attackers obtain tokens through information stealers, phishing campaigns, compromised code repositories, and poisoned npm packages. Organizations can mitigate risks through spending limits, privileged account reviews, short-term bearer tokens, AI gateways, and tight development environment management.

token jacking
shai-hulud
llm abuse
npm supply chain
credential theft
transfer stations
miasma
ai api theft
gray-market ai
Read More