Redact is a financially motivated data-extortion brand linked by multiple researchers to the broader UNC6671 cybercrime cluster and to the earlier BlackFile operation, with some reporting explicitly describing Redact as a successor or rebrand of BlackFile. It is part of a set of closely related extortion brands that also includes Pink, Helix, and Falcon, which have been tied together through shared infrastructure, overlapping phishing templates, common victimology, and a largely identical operating playbook. Some reporting also notes possible overlap with the wider Com ecosystem, but the exact organizational relationships among these brands remain unresolved. The cluster associated with Redact specializes in identity-centric intrusions and cloud data theft rather than software exploitation. Its operators commonly use voice phishing while impersonating internal IT help desk staff, often contacting employees on personal mobile phones and creating urgency around security migrations, passkey enrollment, or account issues. They also use device code phishing and adversary-in-the-middle credential harvesting to capture credentials, MFA codes, and authenticated sessions. Post-compromise activity has included abuse of Microsoft 365 and Okta, registration of attacker-controlled MFA devices for persistence, password-reset abuse against non-SSO applications, deletion of security notifications and reset confirmations for defense evasion, and automated exfiltration of enterprise data from cloud collaboration platforms such as SharePoint and OneDrive. Redact is used as a public-facing extortion identity in operations centered on stolen data and ransom demands. Reporting links the broader UNC6671 operation to multimillion-dollar extortion revenue and notes that the actors target organizations whose confidential data can support substantial ransom payments. Sector targeting attributed to the cluster has shifted over time from manufacturing, real estate, healthcare, and insurance toward technology, transportation, hospitality, financial services, private equity, and legal organizations, indicating a preference for victims holding sensitive corporate, client, or transaction-related information. Publicly reported Redact victims include organizations in U.S. healthcare and insurance. High-confidence reporting supports Redact as an extortion brand within a larger financially motivated intrusion ecosystem rather than a clearly distinct standalone group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named extortion brand sharing infrastructure with UNC6671-linked operations.
Extortion brand sharing infrastructure with Helix within the broader UNC6671-linked activity cluster.
One of four successor brands/groups that UNC6671/BlackFile reportedly split into, continuing the same vishing and extortion tradecraft.
Public extortion brand used within the broader UNC6671 operation for monetization and negotiation compartmentalization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.