Also known as: tracked as, UNC6040, UNC6240, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Sandworm Team
UNC6671, often referenced under aliases such as STATIC TUNDRA, BlackFile, and others, has emerged as a sophisticated adversary that leverages voice phishing (spearphishing voice) to impersonate IT personnel and direct victims toward custom credential‑harvesting portals. These portals are carefully crafted subdomains of passkey or enrollment themed sites, registered through Tucows and frequently appended with victim‑specific identifiers to increase spoofing credibility. Once an employee is convinced to submit credentials, UNC6671 employs Adversary‑in‑the‑Middle tactics—including MFA request generation and token capture—to bypass Okta SSO and Microsoft 365 authentication. The group then proceeds to download sensitive data from SharePoint, OneDrive, Salesforce, Slack, and other cloud services using automated Python and PowerShell scripts before exfiltrating information in a stealthy manner. Extortion is a key component of their operations: the actors send ransom notes from programmatically generated consumer email accounts and negotiate through encrypted messaging platforms such as Tox or Session. Demand amounts range from low‑six‑figure sums to multimillion dollar figures, often accompanied by direct threats of credential exposure or further attack. UNC6671’s digital footprint intersects with other extortion brands like Redact, Pink, Helix, and Falcon, suggesting shared infrastructure or affiliation. The group has also attempted to exploit CVE‑2025‑61882 and CVE‑2021‑35587 as potential vectors for initial access.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6671 is a financially motivated threat actor executing highly targeted vishing-based credential‑harvesting and extortion campaigns against organizations using Okta, Microsoft 365, and other cloud SaaS platforms. They deploy subdomain phishing portals registered through Tucows to capture SSO credentials and MFA tokens via Adversary‑in‑the‑Middle techniques, then exfiltrate data with Python and PowerShell scripts while demanding ransom through encrypted channels like Tox or Session.
Goals & Targeting
The actor’s strategic objective centers on financial exploitation of high‑profile organizations worldwide, focusing on sectors with critical cloud deployments—financial services, government, energy, healthcare, defense, and technology. By harvesting SSO credentials and MFA tokens they aim to achieve persistent footholds, enabling both data exfiltration and subsequent extortion. Their choice of voice phishing underscores a reliance on human trust vectors rather than purely technical exploitation. They target regions with complex organizational structures or significant cloud usage, including the US, Canada, UK, Germany, India, Japan, Australia, China, and Russia, among others. The group demonstrates a preference for organizations that rely heavily on Okta and Microsoft 365 for identity management, indicating a calculated effort to maximize impact and leverage widely used platforms. UNC6671 also appears opportunistic, leveraging public CVEs and low‑cost cloud services (e.g., Python, PowerShell) to reduce operational overhead while maintaining effectiveness across different enterprises. Key capabilities such as voice phishing, Adversary‑in‑the‑Middle tactics, credential harvesting portals, MFA bypass, automated exfiltration scripts, and encrypted communication for ransom negotiation underpin the threat actor’s ability to scale its financial gains.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6671’s campaigns are highly methodical, employing a blend of social engineering and technical exploitation to gain initial foothold before extracting data or demanding ransom. The actor frequently registers new phishing domains through Tucows that mimic passkey enrollment portals, then escalates the attack via voice calls posing as IT support to deceive employees into revealing SSO credentials. A notable operational pattern is the use of encrypted channels for ransom negotiation—leveraging Tox or Session—to reduce detection risk. The group’s infrastructure overlaps with other known extortion brands; shared domain registries and similar exfiltration tactics hint at a possible collaborative or umbrella framework. While specific attack timelines are unclear, evidence points to an ongoing presence in multiple geographic locales targeting high‑value public and private sectors. The actor shows flexibility by attempting to exploit both cloud platform credentials and publicly disclosed software vulnerabilities (CVE-2025-61882, CVE-2021-35587), expanding its reach.
IOC Patterns
Recommended Actions
Confidence Assessment
The available data provides a coherent picture of UNC6671’s tactics and capabilities, supported by multiple reports detailing their vishing campaigns, domain registration practices at Tucows, and use of cloud platform credentials. However, gaps remain regarding the actor’s exact organizational structure, overall operational tempo, and comprehensive mapping to other known groups (e.g., BlackFile). The lack of documented first/last seen dates and detailed attribution evidence introduces some uncertainty about the current activity level. Overall confidence in identified tactics and indicators is moderate to high.
No campaigns linked yet.
No observed data linked yet.
6
Techniques
44
Tools
0
Campaigns
72
IOCs
0
Observed Data
4
Tactics