UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
UNC6671, a data extortion group linked to ShinyHunters and potentially SLH, is leveraging sophisticated vishing tactics to steal SaaS data from organizations across multiple sectors. They impersonate IT help desks, directing victims to fake login portals via compromised mobile devices, to intercept credentials and MFA tokens. The group utilizes multiple extortion brands – Redact, Pink, Helix, and Falcon – to monetize their operations and evade tracking. They exploit vulnerabilities in SSO and IdP systems, establishing persistence through compromised MFA devices, and operate as a decentralized network, outsourcing extortion negotiations. Google has tracked over $10.6 million in Bitcoin payments associated with the group.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
