Cybercrime
,
Finance & Banking
,
Fraud Management & Cybercrime
What’s in a Name? Vishing-Savvy BlackFile Rebrands as Redact, Pink, Helix, Falcon

A supposedly retired cybercrime group is behind a wave of attacks against financial and professional services sectors including a clutch of mainstream names such as Apollo Global Management, KKR and Moody’s.
See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime
Threat researchers at Google said Thursday that telemetry collected from multiple attacks form a group is tracks as UNC6671 point to an extortion threat actor that once identified as BlackFile.
BlackFile declared its end in May – but rather than disappearing, it merely rebranded and carried on with social engineering attacks under a variety of different names, including Redact, Pink, Helix and Falcon, each with its own data-leak site.
Confirmed targets additional have included Bain Capital, Blackstone, Bridgewater Associates, Clearlake Capital, CME Group and TPG, among others, reported Reuters, which first described Google’s research.
Google says the initial access tactics for each putatively different extortion group – such as voice phishing and single sign-on compromise – remain “remarkably consistent,” as do the post-intrusion tactics, techniques and procedures.
Bloomberg separately reported on attacks on Wall Street hedge fund giants a day before Google’s research came out.
“This shift in targeting is really a money thing. The threat actors think that these firms or organizations have data sensitive enough that, if taken, they would pay to prevent it. While their help desk vishing tactics might seem complex, sophisticated is not the right word. It is just really effective,” said Austin Larsen, principal threat analyst at Google Threat Intelligence Group, in a post to LinkedIn.
Reuters-reviewed internet intelligence data showed the cybercriminals built an extensive roadmap to target more than 200 companies in the past five weeks, which, in addition to financial firms, included ride-sharing app Uber, housing broker Zillow, jeans retailer Levi Strauss and laws firms such as Paul Hastings and Greenberg Traurig.
Google said BlackFile and its new brand-name entities continue to pose as help desk staff and call employees inform them about a supposedly urgent, emergency security mitigation they must put in place. In some cases, to help sidestep corporate controls, the callers phone employees’ personal devices and spoof the legitimate IT help desk phone number.
“During these phone calls, operating under the false pretext of an urgent helpdesk mandate to enable FIDO2 passkeys or update multifactor authentication enrollment, the caller directs the employee to a lookalike credential-harvesting subdomain,” researchers said. These subdomains often feature the target company’s name plus a phrase such as .addssopasskey.com, .createssopasskey.com or .passkeyhelpdesk.com.
The sites are landing pages created by phishing toolkits to perpetrate adversary-in-the-middle attacks, designed to facilitate the real-time capture of credentials and multifactor tokens (see: Phishing Defense: Tracking Adversary-in-the-Middle Attacks).
“Once session persistence is established, the actors deploy automated scripts for data exfiltration from enterprise cloud environments, including Microsoft 365 and Okta,” Google said.
Rebranding Moves
One potential explanation for the group’s attempt to rebrand is an attempt at avoiding too much independent attention, especially given how lucrative its hacking as been.
Google said that from Jan. 7 through May 12, 18 bitcoin wallet addresses tied to BlackFile received 141.65 bitcoins, worth about $11 million when the transaction occurred. Incoming payments to those wallets occurred after BlackFile announced its retirement on May 11, and the group made “multiple significant cashout events” in April and May.
The group usually makes ransom demands of between $1 million or more than $3 million, Google said, although the attackers often agreed to ransom amounts worth half or three-quarters of their initial demand, Google said. “In over 53% of tracked cases in this timeframe, final payments averaged $750,000,” it said.
With reporting by ISMG’s Tiffany Wang in New York.
