Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Extortion in the Enterprise: Defending Against BlackFile Attacks

112.209.151.78

TLP:CLEAR
Active

IPv4 Address

Description

Since February 2026, multiple incidents involving data theft and extortion have been attributed to activity cluster CL-CRI-1116, also known as BlackFile, UNC6671, and Cordial Spider. These financially-motivated attackers, likely associated with "The Com" collective, employ voice-based phishing combined with credential harvesting through fraudulent login pages. They impersonate IT support staff to steal credentials and bypass multi-factor authentication. The attackers focus on Living Off the Land techniques, abusing legitimate APIs like Microsoft Graph to access SharePoint sites and Salesforce data. They search for confidential information and employee data within SaaS environments, then exfiltrate it through browser downloads or API exports. To pressure victims into paying seven-figure ransoms, attackers send demands via Gmail and compromised email accounts, sometimes employing SWATting tactics against executives.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Extortion in the Enterprise: Defending Against BlackFile Attacks
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 16:06
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 112.209.151.78

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.