0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Google Threat Intelligence Tracks Expansive 'BlackFile' Extortion Campaign (cloud.google.com)

· 69d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • BlackFile (UNC6671) uses vishing and AiTM to bypass MFA.
  • Targets organizations in North America, Australia, and the UK.
  • Google recommends FIDO2 tokens and employee training as countermeasures.

"The BlackFile group (UNC6671) is using sophisticated vishing and Adversary-in-the-Middle (AiTM) techniques to bypass multi-factor authentication and exfiltrate corporate data from organizations in North America, Australia, and the UK. Attackers employ social engineering to steal credentials and circumvent security measures, focusing on extorting companies through stolen sensitive data."

Discussion Matrix

0 segments

no comments yet.