INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 5/15/2026, 2:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Welcome to BlackFile: Inside a Vishing Extortion Operation Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass tra…
https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation
sha256:73eda6bcf0063d530295e09bcfa678c6c0a584dedd5382bce965a1c72e073384
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| victim.user |
| Open → |
| domain | organization.com | Open → |
| domain | organization.sharepoint.com | Open → |
| domain | company.com | Open → |
| domain | report.pbix | Open → |
| domain | company.sharepoint.com | Open → |
| domain | system.multifactor.factor.setup | Open → |
| domain | user.authentication | Open → |
| url | https://organization.sharepoint.com/sites/Legal_Archive/ | Open → |
| url | https://company.sharepoint.com/sites/ProductionOps/ | Open → |