BlackFile Extortion Group Leverages Vishing and AiTM for SaaS Data Theft (cloud.google.com)
0xBASE INTEL BRIEF
- UNC6671 (BlackFile) uses vishing and AiTM
- Targets: retail and hospitality
- SaaS data theft with seven-figure ransom demands
"The UNC6671 threat actor, operating under the 'BlackFile' brand, targets retail and hospitality sectors via voice phishing (vishing) and Adversary-in-the-Middle (AiTM) techniques to bypass MFA, exfiltrate sensitive data from SaaS environments, and demand seven-figure ransoms."
no comments yet.