National Cyber Warfare Foundation (NCWF)

BlackFile


0 user ratings
2026-07-23 17:10:21
blscott

BlackFile is a financially motivated cybercrime extortion group (not a traditional state-sponsored Advanced Persistent Threat/APT group focused on espionage).


It emerged in early 2026 (activity noted from around January, with sustained campaigns from February) and is tracked under multiple aliases including UNC6671 (Google Threat Intelligence Group / GTIG), Cordial Spider (CrowdStrike), and CL-CRI-1116. Researchers (including Palo Alto Networks Unit 42) have assessed with moderate confidence that it is linked to “The Com,” a loose network of primarily English-speaking cybercriminals associated with extortion, social engineering, violence/swatting, recruitment of young people, and other criminal activity.


The group has primarily targeted organizations in retail and hospitality (with broader impact reported across healthcare, technology, transportation, logistics, and other sectors) in North America, Europe, Australia, and the UK. It has claimed or targeted dozens of victims and demanded seven-figure ransoms (commonly in the $500K–$5M+ range). Unlike classic ransomware groups, BlackFile typically avoids deploying encrypting malware or custom tools. It relies on “living off the land” techniques, social engineering, and abuse of legitimate SaaS APIs and cloud services.


Attack Lifecycle and TTPs


BlackFile’s primary initial access method is voice phishing (vishing):



  • Operators place calls from spoofed VoIP numbers or with fraudulent Caller ID Names (CNAM), impersonating corporate IT helpdesk or support staff.

  • They claim the call concerns security compliance, system updates, MFA/passkey enrollment, or account verification.

  • Victims are directed to highly realistic phishing pages mimicking corporate single sign-on (SSO) portals (Microsoft 365, Okta, etc.).

  • Credentials and one-time passcodes/MFA codes are harvested in real time (adversary-in-the-middle / AiTM techniques).


Once credentials are obtained:



  • Attackers register their own devices in the victim’s identity provider to bypass subsequent MFA challenges and establish persistence.

  • They scrape internal employee directories to identify and further socially engineer high-privilege/executive accounts.

  • Lateral movement and data collection focus on SaaS environments (Microsoft 365/Entra, SharePoint, OneDrive, Okta, Salesforce, Zendesk, ServiceNow, etc.).

  • Operators search for high-value files using keywords such as “confidential,” “SSN,” “sensitive,” etc.

  • Data is exfiltrated via legitimate APIs (e.g., Salesforce API, Microsoft Graph with permissions like Sites.Read.All), browser downloads, or scripted requests (Python with python-requests library or PowerShell). Exfiltration often mimics normal activity (e.g., triggering “FileAccessed” rather than bulk “FileDownloaded” events) and stages data on attacker infrastructure, file-sharing services (e.g., MEGA, LimeWire), or temporary cloud storage.


Extortion phase:



  • Ransom demands are sent from compromised employee email accounts, randomly generated Gmail addresses, or (later) hijacked internal accounts/Microsoft Teams.

  • Communication initially used Tox, then shifted primarily to the Session messenger (decentralized, privacy-focused).

  • Pressure tactics include threats to leak data, limited samples or directory listings posted on their data leak site, spam, threatening voicemails, and swatting (false emergency calls to police targeting employees or executives).


The group launched a dedicated BlackFile data leak site (DLS) on or around February 6, 2026, presenting itself as “security researchers.” It typically posted only limited samples/directory listings rather than full datasets and did not heavily advertise the site. The DLS went offline in late April 2026, briefly reappeared on May 11, 2026 with a message stating that BlackFile was shutting down “under this name,” and has remained inaccessible. Subsequent reporting has noted possible rebranding or successor activity under names such as REDACT or Helix, though attribution remains fluid in the broader ecosystem.


Key Executives / Leadership


No publicly identified key executives, leaders, or named individuals associated with BlackFile exist in open-source reporting.


As an underground cybercriminal operation (and one linked to the decentralized “The Com” network), members operate anonymously. There are no known corporate-style executives, public spokespeople, or court-attributed names specific to this cluster in the available intelligence as of mid-2026. Any claims of specific identities should be treated with extreme caution and verified through official law enforcement or trusted threat intelligence sources.


Websites and Other Indicators of Compromise (IOCs)


BlackFile infrastructure is ephemeral and rotated frequently. No persistent “official” clearnet organizational website is known. Related sites and indicators include:


Phishing / Credential Harvesting Domains (examples of patterns; many are short-lived, organization-specific subdomains often registered via Tucows or similar, themed around “passkey,” “enrollment,” or “SSO”):



  • Patterns such as [organization].enrollms[.]com, [organization].passkeyms[.]com, [organization].setupsso[.]com

  • Other lookalike SSO/portal domains (e.g., variants mimicking Okta or Microsoft login pages).


Communication / Related Services:



  • Session messenger client: getsession[.]org (actors provide Session IDs to victims).

  • Early use of Tox; occasional references to Telegram, Discord, or Signal in broader associated activity.


Data Leak Site:



  • BlackFile DLS (dark web / Tor-based, exact onion address not publicly disclosed in the reviewed reports; now offline).


User-Agent:



  • Python-requests/2.28.1 (commonly observed in API/exfiltration activity; also PowerShell variants such as WindowsPowerShell/5.1).


Additional behavioral indicators include new device registrations in Entra ID / Okta followed by bulk SaaS API activity (especially off-hours), anomalous FileAccessed events in Microsoft 365 Unified Audit Logs, and inbound vishing calls matching helpdesk pretexts.


Note: Full, up-to-date IOC collections are maintained by vendors such as GTIG (available via VirusTotal collections for registered users) and others. Defenders should also monitor for related activity under possible successor brands.


Defensive Recommendations (High-Level)



  • Enforce phishing-resistant MFA (FIDO2 / passkeys) wherever possible and restrict device registration.

  • Implement strict call-handling policies: verify IT support claims via official channels; limit what can be done in a single call without escalation.

  • Monitor identity provider logs for anomalous device registrations, session activity, and API usage.

  • Hunt for the listed User-Agents and IP patterns in SaaS and proxy logs.

  • Train staff (especially those handling phones or helpdesk) on vishing recognition through realistic simulations.

  • Review and restrict high-privilege SaaS API permissions.


BlackFile exemplifies the shift toward identity-centric, malware-light extortion that abuses trusted cloud and collaboration platforms. Organizations in retail, hospitality, and related sectors should treat vishing and SSO compromise as high-priority threats. Information is drawn from public reports by Unit 42 / RH-ISAC, Google Threat Intelligence Group, and corroborating coverage as of mid-2026; threat actor infrastructure and branding evolve rapidly.


BlackFile is a financially motivated cyber extortion operation that emerged publicly in early 2026. Unlike traditional ransomware groups, BlackFile generally avoids deploying custom malware or encrypting victim systems. Instead, the group focuses on stealing sensitive corporate data through sophisticated voice phishing (vishing), identity compromise, and abuse of legitimate cloud services before demanding multi-million-dollar extortion payments. Researchers track the activity under several names, including UNC6671, CL-CRI-1116, and Cordial Spider.

Overview

BlackFile represents a shift from malware-based attacks to identity-based intrusions. Rather than exploiting software vulnerabilities, operators manipulate employees into granting access through convincing social engineering.

The campaign primarily targets:

Retail
Hospitality
Large enterprises using Microsoft 365
Organizations using Okta
Salesforce customers
Organizations with significant cloud-based intellectual property

Researchers believe the group has targeted dozens of organizations across North America, the United Kingdom, and Australia.

Objectives

BlackFile\\\'s objective is straightforward:

Gain identity access
Steal sensitive corporate information
Publish sample data
Demand seven-figure extortion payments

Unlike classic ransomware operators, encryption is frequently absent from the intrusion. Instead, data theft itself becomes the weapon.

Attack Lifecycle
1. Reconnaissance

Attackers identify:

IT staff
Helpdesk personnel
Executives
Employees with privileged access
Cloud administrators
2. Voice Phishing (Vishing)

Operators impersonate:

Internal IT
Help Desk
Security Teams
MFA Support
Microsoft support personnel

Victims are directed to realistic SSO portals where credentials and MFA codes are harvested in real time.

3. Identity Takeover

Following credential theft, attackers:

Register attacker-controlled devices
Enroll those devices in Microsoft Entra ID
Bypass future MFA challenges
Establish persistent cloud access
4. Cloud Discovery

Common targets include:

Microsoft 365
SharePoint
OneDrive
Exchange Online
Salesforce
Microsoft Graph API
Okta environments
5. Data Theft

Rather than deploying malware, BlackFile abuses legitimate APIs and cloud functions to download sensitive files at scale.

6. Extortion

Victims are threatened with publication of stolen data via a dedicated leak site if payment is not made.

MITRE ATT&CK Techniques
Technique ATT&CK ID
Voice Phishing T1598
Phishing for Credentials T1566
Valid Accounts T1078
Multi-Factor Authentication Request Generation T1621
Cloud Account Abuse T1078.004
Data from Cloud Storage T1530
Data Staged T1074
Exfiltration Over Web Services T1567
Living Off the Land Multiple
Known Indicators of Compromise (IoCs)

Important: As of current public reporting, researchers have not released a comprehensive set of infrastructure IoCs such as all IP addresses, domains, or file hashes. This is largely because BlackFile relies on legitimate cloud services, compromised accounts, and rapidly changing infrastructure rather than persistent malware. Public reports emphasize behavioral indicators over static IoCs.

Threat Group Aliases
BlackFile
UNC6671
CL-CRI-1116
Cordial Spider
O-UNC-045 (community identifier)
Pink
Redact
Helix
Initial Access Indicators
Helpdesk impersonation
Voice phishing
Caller ID spoofing
Fake SSO portals
Real-time MFA relay
Adversary-in-the-middle (AiTM) phishing
Credential harvesting
Identity Indicators
Unexpected Microsoft Entra ID device registrations
Newly trusted devices without change requests
Multiple MFA enrollment events
Unusual authentication locations
New OAuth consent grants
Unexpected refresh token issuance
Unrecognized browser fingerprints
Microsoft 365 Indicators
Microsoft Graph API abuse
High-volume SharePoint downloads
Large OneDrive exports
Mass Exchange mailbox access
Unusual Teams access
Abnormal SharePoint search activity
Salesforce Indicators
Large API downloads
Bulk object exports
Excessive report generation
Large SOQL queries
Unusual API token usage
Behavioral Indicators
Large data downloads
Access outside business hours
Impossible travel events
Residential proxy usage
Anti-detect browser fingerprints
Rapid privilege escalation
Enumeration of employee directories
File Discovery Indicators

Researchers observed attackers searching for terms including:

confidential
salary
payroll
SSN
employee
HR
customer
finance
acquisition
merger
contract

Exfiltration Indicators

Reported staging and exfiltration methods include:

Microsoft Graph API
Salesforce API
SharePoint downloads
OneDrive synchronization
MEGA uploads
LimeWire cloud storage
HTTPS data transfers

Cloud Log Indicators

Monitor for:

Multiple device enrollments
New OAuth applications
Mass file downloads
Unusual PowerShell authentication
Python-based API activity
Unexpected Graph API queries
Token refresh anomalies
Infrastructure Indicators

Public reporting confirms that 21 attacker-controlled IP addresses were identified by industry partners, but the complete list has not been broadly published in open reporting. Organizations are encouraged to obtain the latest indicators through commercial or trusted information-sharing sources such as RH-ISAC or vendor threat intelligence.

Defensive Recommendations

Organizations should prioritize:

Phishing-resistant MFA (FIDO2/WebAuthn)
Restricting device enrollment in Microsoft Entra ID
Monitoring Microsoft Graph API activity
Conditional Access policies
Enhanced identity threat detection
Detection of anomalous cloud downloads
Helpdesk verification procedures
Regular vishing awareness exercises
Continuous monitoring of SaaS audit logs
Behavioral analytics focused on identity abuse rather than malware signatures
Conclusion

BlackFile demonstrates the ongoing evolution of cyber extortion from ransomware toward identity-centric operations. By exploiting human trust, legitimate cloud APIs, and compromised identities instead of deploying custom malware, the group can evade many traditional endpoint defenses. Effective detection therefore depends less on static indicators such as hashes or malware signatures and more on monitoring authentication anomalies, cloud access patterns, device registrations, and unusual data movement. Organizations that strengthen identity security, restrict privileged cloud access, and monitor SaaS telemetry are best positioned to detect and disrupt BlackFile-style attacks before significant data exfiltration occurs.


Comments
new comment
Nobody has commented yet. Will you be the first?


a.k.a
Pink
Redact
UNC6671
Helix
CL-CRI-1116
Cordial Spider
O-UNC-045
Black File
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.