Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6671

Also known as: tracked as, UNC6040, UNC6240, STATIC TUNDRA, also tracked as Sandwo, CovertNetwork-1658, the 7777 Botnet, CVE-2024-39717, Sandworm Team

Description

UNC6671, often referenced under aliases such as STATIC TUNDRA, BlackFile, and others, has emerged as a sophisticated adversary that leverages voice phishing (spearphishing voice) to impersonate IT personnel and direct victims toward custom credential‑harvesting portals. These portals are carefully crafted subdomains of passkey or enrollment themed sites, registered through Tucows and frequently appended with victim‑specific identifiers to increase spoofing credibility. Once an employee is convinced to submit credentials, UNC6671 employs Adversary‑in‑the‑Middle tactics—including MFA request generation and token capture—to bypass Okta SSO and Microsoft 365 authentication. The group then proceeds to download sensitive data from SharePoint, OneDrive, Salesforce, Slack, and other cloud services using automated Python and PowerShell scripts before exfiltrating information in a stealthy manner. Extortion is a key component of their operations: the actors send ransom notes from programmatically generated consumer email accounts and negotiate through encrypted messaging platforms such as Tox or Session. Demand amounts range from low‑six‑figure sums to multimillion dollar figures, often accompanied by direct threats of credential exposure or further attack. UNC6671’s digital footprint intersects with other extortion brands like Redact, Pink, Helix, and Falcon, suggesting shared infrastructure or affiliation. The group has also attempted to exploit CVE‑2025‑61882 and CVE‑2021‑35587 as potential vectors for initial access.

Goals & Targeting

Targeted Sectors

Financial services
Government
Energy
Telecommunications
Defense
Healthcare
Education
Critical infrastructure
Manufacturing
Transportation
Aviation
Retail
Hospitality
Maritime
Information technology
Media
Chemical
Think tank
Aerospace
Construction
Legal services
Oil gas
Non profit
Nuclear

Targeted Countries / Regions

US
CN
UA
GB
IN
JP
AU
IR
KR
PL
CA
SG
VN
TW
RU
DE
KZ
IL
TR
FR
BR
MX
ES
IT

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 10 hours ago

Executive Summary

UNC6671 is a financially motivated threat actor executing highly targeted vishing-based credential‑harvesting and extortion campaigns against organizations using Okta, Microsoft 365, and other cloud SaaS platforms. They deploy subdomain phishing portals registered through Tucows to capture SSO credentials and MFA tokens via Adversary‑in‑the‑Middle techniques, then exfiltrate data with Python and PowerShell scripts while demanding ransom through encrypted channels like Tox or Session.

Goals & Targeting

The actor’s strategic objective centers on financial exploitation of high‑profile organizations worldwide, focusing on sectors with critical cloud deployments—financial services, government, energy, healthcare, defense, and technology. By harvesting SSO credentials and MFA tokens they aim to achieve persistent footholds, enabling both data exfiltration and subsequent extortion. Their choice of voice phishing underscores a reliance on human trust vectors rather than purely technical exploitation. They target regions with complex organizational structures or significant cloud usage, including the US, Canada, UK, Germany, India, Japan, Australia, China, and Russia, among others. The group demonstrates a preference for organizations that rely heavily on Okta and Microsoft 365 for identity management, indicating a calculated effort to maximize impact and leverage widely used platforms. UNC6671 also appears opportunistic, leveraging public CVEs and low‑cost cloud services (e.g., Python, PowerShell) to reduce operational overhead while maintaining effectiveness across different enterprises. Key capabilities such as voice phishing, Adversary‑in‑the‑Middle tactics, credential harvesting portals, MFA bypass, automated exfiltration scripts, and encrypted communication for ransom negotiation underpin the threat actor’s ability to scale its financial gains.

Enhanced Description

Key Capabilities

  • Voice phishing (vishing) / spearphishing voice
  • Adversary-in-the-Middle exploitation to bypass MFA and perimeter defenses
  • Credential harvesting via custom subdomain‑based phishing portals registered through Tucows
  • Single sign-on credential theft from Okta and Microsoft 365
  • Multi-factor authentication token capture
  • Automated data exfiltration using Python and PowerShell scripts
  • Extortion via encrypted communication channels (Tox, Session) and ransom notes
  • Credential harvesting via web‑based panels
  • Targeted voice phishing campaigns using victim‑specific subdomains
  • Operating generic root domains masquerading as passkeys

MITRE ATT&CK Tactics

Initial Access
Credential Access
Execution
Exfiltration
Impact

ATT&CK Techniques

T1557
T1621
T1078
T1566.004
T1671
T1566.001

Software / Tooling

Python scripts
PowerShell scripts
Tox (encrypted messaging)
Session (encrypted messaging)

Campaigns & Victims

UNC6671’s campaigns are highly methodical, employing a blend of social engineering and technical exploitation to gain initial foothold before extracting data or demanding ransom. The actor frequently registers new phishing domains through Tucows that mimic passkey enrollment portals, then escalates the attack via voice calls posing as IT support to deceive employees into revealing SSO credentials. A notable operational pattern is the use of encrypted channels for ransom negotiation—leveraging Tox or Session—to reduce detection risk. The group’s infrastructure overlaps with other known extortion brands; shared domain registries and similar exfiltration tactics hint at a possible collaborative or umbrella framework. While specific attack timelines are unclear, evidence points to an ongoing presence in multiple geographic locales targeting high‑value public and private sectors. The actor shows flexibility by attempting to exploit both cloud platform credentials and publicly disclosed software vulnerabilities (CVE-2025-61882, CVE-2021-35587), expanding its reach.

IOC Patterns

  • Subdomain-based credential harvesting domains registered through Tucows
  • Domains referencing passkey or enrollment themes
  • Encrypted communication channels like Tox or Session used for ransom negotiation
  • Programmatically generated consumer email accounts used in ransom notes
  • Exploitation of CVE-2025-61882 and CVE-2021-35587
  • Victim-specific subdomains appended to generic root domains for phishing

Recommended Actions

  • Conduct comprehensive employee training on vishing and spearphishing voice awareness, emphasizing verification procedures for IT support calls. Deploy network monitoring to detect traffic to newly registered custom phishing domains and block suspicious subdomains via DNS filtering or web proxy rules. Implement MFA methods resistant to Adversary-in-the-Middle attacks—such as app‑based authenticators or push notifications—and enforce least‑privilege SSO permissions within Okta and Microsoft 365. Maintain real‑time threat intelligence feeds on credential‑harvesting domain registrations (Tucows) and block known malicious subdomains or root domains used for phishing panels. Apply patches or mitigations promptly for publicly disclosed CVEs (CVE-2025-61882, CVE-2021-35587) across all affected systems. Monitor outbound data flows from cloud services (SharePoint, OneDrive, Salesforce, Slack) for anomalous exfiltration patterns and limit large-volume data downloads to approved channels.
  • suggested_tags
  • vishing
  • spearphishing voice
  • adversary-in-the-middle
  • credential harvesting
  • MFA bypass
  • Okta compromise
  • Microsoft 365 compromise
  • SSO credential theft
  • extortion
  • encrypted communication (Tox, Session)
  • custom phishing portal
  • CVE exploitation
  • shared infrastructure

Confidence Assessment

The available data provides a coherent picture of UNC6671’s tactics and capabilities, supported by multiple reports detailing their vishing campaigns, domain registration practices at Tucows, and use of cloud platform credentials. However, gaps remain regarding the actor’s exact organizational structure, overall operational tempo, and comprehensive mapping to other known groups (e.g., BlackFile). The lack of documented first/last seen dates and detailed attribution evidence introduces some uncertainty about the current activity level. Overall confidence in identified tactics and indicators is moderate to high.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 15 Email Address 2 IPv4 Address 3

References

  1. www.huntress.com — Cited by web research for: UNC6040
  2. attack.mitre.org — Cited by web research for: STATIC TUNDRA
  3. cloud.google.com — Cited by web research for: Guard
  4. cloud.google.com — Cited by web research for: PowerShell
  5. fortiguard.fortinet.com — Cited by web research for: Matrix
  6. www.crowdstrike.com — Cited by web research for: Fal.Con

Intel Summary

6

Techniques

44

Tools

0

Campaigns

72

IOCs

0

Observed Data

4

Tactics

Tags

Critical Infrastructure
Phishing
Data Exfiltration

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.