Redact is a financially motivated data-theft and extortion group formerly operating under the BlackFile name. It is associated with UNC6671, a cloud-focused intrusion cluster linked through shared infrastructure and phishing templates to the Redact, Pink, Helix, and Falcon extortion brands. These brands should not be treated as interchangeable actor identities. Related activity is tracked within CrowdStrike's Cordial Spider collective and overlaps with Arctic Wolf's PREY-0058 cluster. Redact-associated campaigns target U.S. enterprises, particularly financial services, insurance, private equity, healthcare, and professional services. The broader UNC6671 operation has also targeted manufacturing, technology, transportation, hospitality, and real estate. Target selection emphasizes organizations holding confidential corporate, investor, litigation, and transaction data that can provide substantial extortion leverage. The intrusion playbook centers on voice phishing against employees, often on their personal mobile phones. Operators impersonate corporate IT help desks, sometimes spoofing legitimate telephone numbers, and claim that urgent passkey, multifactor authentication, or single sign-on updates are required. Victim-branded adversary-in-the-middle phishing portals capture passwords, authentication codes, and authenticated sessions. Associated campaigns also use device-code phishing to obtain authorized cloud access. After compromise, operators abuse identity-provider access to reach connected SaaS applications, register attacker-controlled MFA methods for persistence, enumerate cloud resources, and automate data collection from Microsoft 365 services, including SharePoint, OneDrive, and Exchange. Compromised mailboxes support password resets for additional applications. Residential proxies and deletion of security notifications help conceal activity. Monetization centers on demands for payment to prevent publication of stolen data, rather than demonstrated file encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against Graybar Electric Company, Inc., a U.S.-based electrical-equipment/manufacturing organization.
The Redact ransomware operation claims Graybar Electric Company, Inc., a United States electrical-equipment company, as a victim. The listing was discovered and published on 2026-10-01; it provides no claim details regarding stolen data, ransom terms, deadline, or intrusion method.
Mentioned only as a sibling brand of FALCON in a table describing adversary-in-the-middle phishing.
An extortion group Google linked to UNC6671 activity and the same broader extortion ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.