Published · 5d agoSecurity3 min read
BlackFile wears four extortion brands, so your threat feed is counting one actor as several
Google says UNC6671 split its extortion into Redact, Pink, Helix and Falcon on shared infrastructure while still working finance, legal and med tech. It averages 1.5 new victims a day.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- BlackFile, which Google Threat Intelligence Group tracks as UNC6671 and associates more broadly with The Com, has been active since the start of the year, shifting its focus from one sector to the next.
- A cybercrime group responsible for a string of recent attacks against private equity firms, law firms and financial rating agencies remains active and continued to target new victims as of late last week, according to researchers.
- Austin Larsen, principal threat analyst at GTIG, told CyberScoop: "We have seen continued targeting against the financial sector with additional targeting of other organizations including in the med tech space."
- The extortion group impersonates IT support in voice-phishing and social engineering attacks.
- BlackFile recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The extortion crew that calls itself BlackFile, tracked by Google Threat Intelligence Group as UNC6671 and associated more broadly with The Com, was still picking up new victims as of late last week, and Mandiant responders were called into fresh financial sector compromises earlier this month [2][17]. The detail worth acting on is not the tradecraft, which is a help desk impersonation phone call [4], but the branding: the group recently split its extortion operations across four names sharing one set of infrastructure [5].
Those names are Redact, Pink, Helix and Falcon [5]. Austin Larsen, principal threat analyst at GTIG, told CyberScoop that "from the intrusion data that we're seeing, this does appear to be essentially the same group," with different people possibly running the individual brands but all of them tying back to the same cluster on shared infrastructure [15]. If your intel program tracks Redact as an actor, you are holding one of four demand streams belonging to a single operator, and your incident count for that operator is low by construction [4]. Several organisations received new demands from Redact alone in the past week, according to Google [6].
The volume is the second problem. Researchers put the group's pace at an average of 1.5 new victims a day [11], which works out to roughly 45 a month [1]. Mandiant has been engaged by more than two dozen organisations successfully compromised by the group since January [16], so the incident response sample is a fraction of the targeting, not a census of it. GTIG says the focus has moved sector to sector since the start of the year [1], with recent work against private equity firms, law firms and financial rating agencies [2] and, per Larsen, "continued targeting against the financial sector with additional targeting of other organizations including in the med tech space" [3]. Earlier victims span healthcare, technology, transportation, logistics, wholesale, retail and hospitality [7]. Flashpoint researchers told CyberScoop they have seen malicious infrastructure aimed at Blackstone, Bain Capital, Moody's, CME and Apollo, though whether any of those firms were compromised is unclear [10].
The money is disciplined rather than greedy. Demands often open near $3 million and have typically been negotiated down to under $1 million, including several payments in the past few weeks, according to Google [9]. That is a haircut of more than two thirds off the ask [2], which tells you the opening number is a negotiating position, not a valuation. Larsen describes the target selection as "big-game hunting," aimed at the largest organisations in each sector rather than small companies [8].
The labour model explains the throughput. Hundreds of callers, often low-level people recruited for a small fee or goodwill with the group, place the voice phishing calls for initial access [13], while Larsen estimates fewer than a dozen core operators run the brands [14]. The caller pool outnumbers the core by more than ten to one [3]. Some victims have also faced threatening messages and swatting, an escalation pattern seen across several subsets of The Com [12]. None of this is novel [18].
Watch whether Pink, Helix and Falcon begin issuing demands at Redact's rate, which would confirm the brands are load balancing rather than succeeding each other. Watch whether settlements keep landing under $1 million, because that is now the reference price [9]. And check what your help desk accepts as identity proof on an inbound call [4].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
BlackFile, which Google Threat Intelligence Group tracks as UNC6671 and associates more broadly with The Com, has been active since the start of the year, shifting its focus from one sector to the next.
ReportedView cited source - [2]
A cybercrime group responsible for a string of recent attacks against private equity firms, law firms and financial rating agencies remains active and continued to target new victims as of late last week, according to researchers.
ReportedView cited source - [3]
Austin Larsen, principal threat analyst at GTIG, told CyberScoop: "We have seen continued targeting against the financial sector with additional targeting of other organizations including in the med tech space."
ReportedSource: Austin Larsen, principal threat analyst, Google Threat Intelligence Group, via CyberScoopView cited source - [4]
The extortion group impersonates IT support in voice-phishing and social engineering attacks.
ReportedView cited source - [5]
BlackFile recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.
ReportedView cited source - [6]
Several organizations received new extortion demands from Redact in the last week, according to Google.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.comMatt Kapko5d agoDetails emerge on BlackFile’s recent attacks on financial companies
- cyberscoop.com4d agoDetails emerge on BlackFile's recent attacks on financial companies | CyberScoop
Additional citations
- Austin Larsen, principal threat analyst, Google Threat Intelligence Group, via CyberScoop
- Austin Larsen, GTIG, via CyberScoop
- Flashpoint researchers, via CyberScoop



