Skip to content

other

UNC6671

Adversary-in-the-middle extortion operation running brands including Falcon, Helix, Pink, Redact, and BlackFile; GuidePoint traced over $8 million across 15 Bitcoin wallets with a $600,000 average extortion amount.

Known aliases

  • BlackFile
  • Cordial Spider
  • O-UNC-045
  • PREY-0058

Relationships

No evidence-backed relationships are recorded.

Current stories

security3 publishers

The extortion layer your IR playbook has no page for: 'Ransom Busters' emails victims mid-incident

GuidePoint says the persona offering to delete stolen data for $20,000 to $60,000 is very likely a ransomware affiliate, which makes the rescue fee a second payment to the same attacker.

Publishers:bleepingcomputer.comguidepointsecurity.comthehackernews.com

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 65%
Investor
Investor 12%

Reality

Evidence66
Adoption18
Hype gap+12
Incentives40
Confidence62
security3 publishers

PREY-0058 phones executives to harvest Microsoft 365 session tokens

Arctic Wolf says the cluster it tracks as PREY-0058 deploys no malware at all. A call from fake IT leads to a proxied login page, and the stolen session token comes back from inside the victim's own ASN.

Perspective Coverage

3 publishers
Builder
Builder 17%
Operator
Operator 75%
Investor
Investor 8%

Reality

Evidence62
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence60
security6 publishers

Storm-3121 callers demand an urgent passkey update to harvest Microsoft 365 session tokens

Microsoft has tracked passkey- and SSO-themed help desk impersonation since May 2026, with the calls steering employees into adversary-in-the-middle proxies and device-code grants that hand over live Microsoft 365 sessions.

Perspective Coverage

6 publishers
Builder
Builder 28%
Operator
Operator 62%
Investor
Investor 10%

Reality

Evidence58
Adoption
Insufficient
Hype gap+10
Incentives45
Confidence60