BlackFile is a financially motivated data-extortion threat actor tracked as UNC6671 and also referred to as CL-CRI-1116 and Cordial Spider. The group is broadly associated with The Com ecosystem and became prominent in 2026 for large-scale identity-centric intrusions that relied on voice phishing and social engineering rather than software exploitation. BlackFile operators commonly impersonate internal IT helpdesk staff, create urgency around security migrations, passkey enrollment, or MFA updates, and direct employees—often on personal mobile devices—to adversary-in-the-middle phishing portals that capture credentials, MFA codes, tokens, or authenticated sessions. After initial access, BlackFile abuses enterprise identity infrastructure and connected SaaS platforms, including Microsoft 365, Okta, SharePoint, OneDrive, and Salesforce. Observed post-compromise behavior includes registering attacker-controlled MFA devices for persistence, resetting passwords for additional enterprise applications, deleting security notifications and password-reset alerts for defense evasion, abusing trust relationships between identity providers and downstream services, escalating into privileged or executive accounts, and rapidly exfiltrating sensitive cloud-hosted data. The actor has also used automated scripting for collection and exfiltration and has leveraged compromised accounts to send extortion communications internally and externally. BlackFile has targeted organizations opportunistically across multiple sectors, with especially notable activity against retail and hospitality, and later against financial services, private equity, law firms, credit-rating and other professional-services organizations. Additional victim sectors reported in 2026 include healthcare, med tech, technology, transportation, logistics, wholesale, manufacturing, real estate, and insurance. The group appears to favor large enterprises and organizations likely to hold highly sensitive corporate, transactional, or legal data that can increase extortion leverage. BlackFile is primarily a data-theft extortion actor rather than an encryption-focused ransomware operator. It steals data from enterprise cloud repositories, publishes or threatens publication through leak-site operations, and issues high-value ransom demands that have often begun in the seven-figure range. Coercive pressure tactics have included threatening messages and swatting incidents targeting company personnel, including executives. In 2026, the BlackFile brand was publicly retired, but the underlying activity cluster continued. High-confidence reporting links BlackFile with successor or parallel extortion brands including Redact, Pink, Helix, and Falcon through shared infrastructure, overlapping victimology, and closely aligned phishing templates and tradecraft. Google assessed these brands were likely used to monetize operations, compartmentalize negotiations, obscure total victim volume, and isolate fallout from individual extortion events. While some fragmentation may reflect splintering or affiliate disputes, the broader UNC6671 cluster has remained active under multiple names.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An active cybercrime/extortion group conducting big-game hunting against large organizations across multiple sectors, using voice-phishing and social engineering to gain initial access and issue extortion demands.
Referenced as a retired predecessor or related extortion brand in background context about fragmentation of associated groups.
Previously active extortion brand whose infrastructure is linked to newer brands including Helix.
Former extortion brand associated with UNC6671 that targeted organizations through vishing and SSO compromise before being retired.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.