Falcon is a financially motivated data-extortion brand linked to the broader UNC6671 cybercrime cluster, which has also been associated with BlackFile, Redact, Pink, and Helix. Available reporting indicates Falcon shares infrastructure, phishing templates, victimology, and operational tradecraft with these brands, suggesting either common operators, closely affiliated actors, or a shared phishing-and-extortion service ecosystem. Falcon has acknowledged an affiliation with Redact, while broader links to the other brands are assessed through technical and operational overlap. The cluster associated with Falcon specializes in help-desk impersonation voice phishing against enterprise employees, frequently contacting targets on personal mobile devices and directing them to adversary-in-the-middle credential-harvesting portals. These operations are designed to capture passwords, MFA codes, and authenticated sessions, after which the actors establish persistence in cloud and SaaS environments, including identity infrastructure and enterprise collaboration platforms. Observed follow-on activity includes session abuse, password-reset abuse, deletion of security notifications from compromised mailboxes, and automated large-scale data theft from cloud repositories. Falcon-associated activity is part of an extortion model centered on stealing sensitive corporate data and threatening public release rather than relying on encryption. The broader UNC6671 ecosystem has targeted organizations whose data is likely to support substantial ransom demands, including technology, transportation, hospitality, financial services, private equity, legal, manufacturing, real estate, healthcare, and insurance organizations. Reported targeting has included major U.S. financial and investment firms and other large enterprises. The actor’s tradecraft is cloud-focused, socially engineered, and optimized for rapid post-compromise exfiltration and monetization through leak-site pressure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named extortion brand sharing infrastructure with UNC6671-linked operations.
Extortion brand sharing infrastructure with Helix within the broader UNC6671-linked activity cluster.
One of four successor brands/groups that UNC6671/BlackFile reportedly split into, continuing the same vishing and extortion tradecraft.
Public extortion brand linked to UNC6671 and referenced in shared phishing-domain usage across victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.