Falcon, also tracked as CL-CRI-1182, is a financially motivated cybercriminal extortion brand associated with cloud-account compromise and theft of sensitive enterprise data. Its targeting includes U.S. businesses and a broader campaign against financial institutions, private equity firms, law firms, and financial ratings agencies. Falcon is affiliated with Redact, formerly BlackFile. Researchers have linked Falcon to the broader UNC6671 activity cluster through shared phishing infrastructure, credential-harvesting templates, and overlapping targeting. These links do not establish that Falcon, Redact, Pink, and Helix are interchangeable identities or share a unified command structure. Falcon-associated operations use voice phishing and IT help-desk impersonation to persuade employees, often contacted on personal phones, to complete purported passkey, MFA, or SSO updates. Spoofed authentication portals and adversary-in-the-middle phishing capture credentials and authenticated sessions; device-code phishing induces victims to authorize attacker-controlled clients. Microsoft tracks Storm-3121 as an initial-access cluster whose intrusions lead to Falcon and ShinyHunters extortion operations, rather than as an alias for Falcon. The associated intrusion workflow abuses valid cloud accounts, registers attacker-controlled MFA methods for persistence, and uses Microsoft Graph for identity, application, and repository reconnaissance. Operators systematically collect documents and email from SharePoint Online, OneDrive, and Exchange Online, using automation and throttled collection to reduce detection. Related activity includes password-reset abuse to access connected applications and deletion of security notifications. Falcon monetizes stolen information through extortion and threatened publication. Its established operating model is data-theft extortion; descriptions of individual incidents as ransomware attacks do not establish the use of file encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Com-affiliated extortion brand described as using adversary-in-the-middle phishing, passkey or SSO-themed domains, real-time credential and MFA-token relay, bulk cloud-data exfiltration, and extortion through compromised email accounts.
Receives access from Storm-3121 initial-access operations.
An extortion group associated with Storm-3121 in the reported account-compromise ecosystem.
An extortion operation that receives access or operational support from Storm-3121.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.