Google Warns of UNC6671 Gang Using Fake Helpdesk Calls to Breach Enterprise Cloud Accounts
Google Cloud Threat Intelligence has identified a high-severity threat actor, UNC6671, conducting multi-brand extortion campaigns targeting financial services and enterprise cloud environments. The group impersonates internal IT helpdesks via phone calls to personal mobile numbers, directing employees to lookalike phishing sites that steal Microsoft 365 and Okta SSO sessions through adversary-in-the-middle techniques. Once inside, attackers use automated scripts to mass-exfiltrate files from SharePoint, OneDrive, and connected SaaS platforms, while deliberately deleting security notification emails to delay detection by both users and security teams. The operation runs under multiple extortion brand names including Redact, Pink, Helix, and Falcon, with infrastructure routed through residential proxies and VPNs to evade monitoring. Google recommends enforcing device-bound FIDO2 passkeys, managed-device access policies, and correlated monitoring across identity providers, mailboxes, and audit logs to counter the threat.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in