Details emerge on BlackFile's recent attacks on financial companies
BlackFile (UNC6671), a The Com-linked extortion crew, keeps hitting financial and med tech firms with voice-phishing IT-support scams and ~$3 million demands.
Google Threat Intelligence Group (tracking BlackFile as UNC6671, linked to The Com) reports the extortion group remains active, shifting focus to the financial sector and med tech organizations, with new Redact-brand extortion demands issued last week. The group impersonates IT support in voice-phishing attacks using hundreds of recruited callers, targets large firms in what researchers call big-game hunting, and processes an average of 1.5 new victims daily. Extortion demands start around $3 million and are typically negotiated below $1 million; Flashpoint observed infrastructure targeting Blackstone, Bain Capital, Moody's, CME, and Apollo, though compromise is unconfirmed. Mandiant has responded to more than two dozen BlackFile compromises since January, and victims face escalation tactics including swatting.
- Four brands — Redact, Pink, Helix, Falcon — share infrastructure and are one cluster
- Hundreds of recruited callers pose as IT support; about 1.5 new victims daily
- Demands start near $3 million, typically negotiated below $1 million
- Infrastructure observed aimed at Blackstone, Bain Capital, Moody's, CME, Apollo
- Victims face escalation including swatting; Mandiant engaged by two dozen orgs since January
Full article722 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google.
Listen to this article
0:00
Learn more.
A cybercrime group responsible for a string of recent attacks against private equity firms, law firms and financial rating agencies remains active and continued to target new victims as of late last week, according to researchers.
BlackFile, which Google Threat Intelligence Group tracks as UNC6671 and associates more broadly with The Com, has been active since the start of the year, shifting its focus from one sector to the next.
“We have seen continued targeting against the financial sector with additional targeting of other organizations including in the med tech space,” Austin Larsen, principal threat analyst at GTIG, told CyberScoop.
The extortion group impersonates IT support in voice-phishing and social engineering attacks, and recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.
Several organizations received new extortion demands from Redact in the last week, according to Google.
BlackFile and its various affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, retail and hospitality.
“BlackFile does go after some of the largest organizations in the sectors that they go for. They’re not going after small companies,” Larsen said. “This is big-game hunting.”
The group’s extortion demands often start around $3 million and payments, including several in the past few weeks, have typically been negotiated down to less than $1 million, according to Google.
Flashpoint researchers told CyberScoop they have observed malicious infrastructure targeting Blackstone, Bain Capital, Moody’s, CME and Apollo, but it’s unclear if any of those firms were compromised.
BlackFile’s steady pace of activity underscores the persistent threat it poses, as it targets an average of 1.5 new victims daily, researchers said.
Some of the group’s recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents, a tactic adopted by several subsets of The Com, according to Google.
The attackers use hundreds of callers, often lower-level people that are recruited for a small fee or an opportunity to earn goodwill with the group, who make the voice phishing calls to obtain initial access. Larsen estimates less than a dozen core operators run the different brands under the BlackFile umbrella.
“From the intrusion data that we’re seeing, this does appear to be essentially the same group,” he said, adding that different people may be operating the various brands, but they’re all linked back to the same threat cluster using shared infrastructure.
Mandiant incident responders encounter BlackFile often, having been engaged by more than two dozen organizations successfully compromised by the threat group since January. New victims in the financial sector were calling Mandiant in for help earlier this month.
Voice-based phishing attacks for data theft extortion aren’t sophisticated or novel, but BlackFile and other cybercrime groups consistently prove their continued effectiveness across virtually any sector or organization. “They’re really hitting on the human weakness element here,” Larsen said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/blackfile-cyberattacks-financial-sector/