UNC6671, a threat actor group, has been conducting sophisticated data theft campaigns targeting Microsoft 365 and Okta environments. Their operations commence with voice phishing, or ‘vishing,’ where they impersonate IT helpdesk personnel to deceive employees into providing access credentials.
These attackers contact employees on their personal mobile devices, often spoofing legitimate helpdesk numbers. They claim that urgent security migrations, such as mandatory passkey or multi-factor authentication (MFA) updates, are required. This pretext directs victims to counterfeit enrollment portals designed to harvest credentials.
Once an employee enters their login information, UNC6671 employs an adversary-in-the-middle (AitM) technique. This method captures both the username-password combination and the live authentication token, effectively bypassing MFA protections. With these credentials, the attackers gain unauthorized access to Microsoft 365 and Okta accounts, allowing them to infiltrate services like SharePoint, OneDrive, and other connected applications.
Automated Data Exfiltration
After securing access, UNC6671 utilizes automated scripts written in Python and PowerShell to systematically exfiltrate data. These scripts are designed to search for and extract high-value information, including confidential documents and sensitive personal data. The exfiltration process is executed in a manner that often evades standard security detections, as the data is streamed directly, avoiding traditional download alerts.
To further obfuscate their activities, the group employs residential proxy services. This tactic masks their true location, making the malicious traffic appear as if it originates from legitimate user environments, thereby complicating incident response efforts.
Persistence and Concealment
UNC6671 takes deliberate steps to maintain prolonged access and avoid detection. They manipulate compromised mailboxes to reset passwords for applications not integrated with single sign-on (SSO) and subsequently delete any security notifications related to these changes. This strategy ensures that victims remain unaware of the unauthorized access, allowing the attackers to continue their operations undisturbed.
Additionally, the group has been observed using various brand names, such as Redact, Pink, Helix, and Falcon, to conduct their campaigns. Despite these changes, the underlying tactics and infrastructure remain consistent, indicating a coordinated effort or shared resources among affiliated entities.
Organizations, particularly those in financial services, private equity, and professional sectors, should be vigilant against such sophisticated social engineering attacks. Implementing phishing-resistant authentication methods, reducing session lifetimes, enforcing stringent access controls, and educating employees on verifying unexpected IT requests through established company channels are critical measures to mitigate the risks posed by groups like UNC6671.
As cyber threats continue to evolve, staying informed about the latest attack vectors and adopting proactive security measures are essential for safeguarding sensitive corporate data and maintaining operational integrity.