A cybercrime group known as BlackFile continues to target the financial sector, with reports indicating that it remains active and has been shifting its focus to new victims. This group, tracked by the Google Threat Intelligence Group as UNC6671, has been implicated in a series of attacks against private equity firms, law firms, and financial rating agencies since the beginning of the year.
According to Austin Larsen, a principal threat analyst at GTIG, BlackFile has been particularly aggressive in its targeting of the financial sector, while also expanding its operations to include organizations in the medical technology space. The group employs voice-phishing and social engineering tactics, often impersonating IT support to gain access to their targets.
Recently, BlackFile has divided its extortion efforts among four brands—Redact, Pink, Helix, and Falcon—utilizing shared infrastructure. Reports indicate that several organizations received new extortion demands from Redact in the past week. The group’s demands typically start around $3 million, although payments have been negotiated down to less than $1 million in recent cases.
BlackFile’s activities have affected a wide range of industries, including healthcare, technology, transportation, logistics, and retail. Larsen noted that the group primarily targets large organizations, stating, “This is big-game hunting.” The group is estimated to target an average of 1.5 new victims daily, highlighting the persistent threat it poses.
Some victims have reported receiving threatening messages and experiencing escalated tactics, including swatting incidents. The attackers often recruit lower-level individuals to make voice phishing calls, which are used to gain initial access to their targets. Mandiant incident responders have encountered BlackFile frequently, having assisted over two dozen organizations that were compromised by the group since January.
While voice-based phishing attacks are not new, BlackFile’s consistent effectiveness across various sectors underscores the importance of addressing human vulnerabilities in cybersecurity. For more details, refer to the full report by CyberScoop.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


