Alanna
River

UNC6671 Hedge Fund Attacks: Vishing, AiTM Phishing, and Cloud Identity Defense

Alanna River

Aug 10, 2026

3 min read

UNC6671

The "What Happened"

  • BleepingComputer reported that recent cyberattacks targeting hedge funds, private-equity firms, and other financial organizations were linked to UNC6671.
  • Google Threat Intelligence Group told BleepingComputer that UNC6671 is associated with BlackFile-linked extortion operations and multiple public brands including Redact, Pink, Helix, and Falcon.
  • Reuters and Bloomberg reported that Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and several private-equity firms were targeted in attacks using voice phishing.
  • Point72 reportedly told investors it had been attacked but had not found evidence that client data was stolen, while Two Sigma said it blocked an attempted intrusion and saw no indication its systems or data were affected.
  • UNC6671 operators typically call employees on personal mobile phones while spoofing corporate helpdesks and claiming users must enroll passkeys or update MFA settings.
  • Victims are directed to company-impersonation domains hosting adversary-in-the-middle phishing kits that steal credentials and session cookies in real time.
  • After compromising Microsoft 365 or Okta SSO accounts, the attackers access linked cloud platforms, automate data theft, and delete security notifications or password-reset emails from compromised inboxes.

A wave of attacks targeting hedge funds and private-equity firms shows how helpdesk vishing, MFA manipulation, and adversary-in-the-middle (AiTM) phishing can compromise trusted SSO accounts, giving attackers access to connected SaaS environments for cloud data theft and extortion.

How UNC6671 turns vishing into cloud access

UNC6671 uses voice phishing (vishing) to impersonate corporate IT or helpdesk personnel, directing employees to attacker-controlled sites under the pretext of mandatory passkey migration or MFA updates. These victim-branded sites support real-time credential harvesting: attackers capture usernames and passwords, relay them to the legitimate SSO provider, and obtain the victim’s MFA code or approval to complete authentication.

After gaining access, UNC6671 can establish persistence by registering an attacker-controlled MFA device and use compromised Microsoft 365 or Okta identities to access connected SaaS applications. By using adversary-in-the-middle (AiTM) proxying, attackers can intercept authentication flows and steal authenticated session tokens, effectively bypassing MFA; where device compliance controls are absent or not enforced, the compromised identity can also update credentials or authentication methods from a non-compliant device because access is not conditioned on the device meeting organizational security requirements. Google Threat Intelligence Group (GTIG) observed the operators targeting services including SharePoint, OneDrive, Salesforce, and Zendesk, then using Python and PowerShell scripts, Microsoft Graph, and direct HTTP requests to automate data exfiltration. GTIG also documented the reuse of valid session cookies, such as FedAuth, to stream SharePoint content directly to attacker-controlled infrastructure.

Strengthening identity security with endpoint trust

Hexnode XDR provides endpoint-focused threat detection, investigation, and response, helping security teams identify malicious processes, files, vulnerabilities, and other endpoint security risks. Hexnode UEM can complement these controls by evaluating device compliance and supplying compliance status to supported identity and conditional-access workflows.

For Microsoft environments, Hexnode UEM can integrate with Microsoft Entra Conditional Access to apply device-compliance-based access controls for supported Windows, macOS, iOS, and Android devices, allowing policies to require a device to meet Hexnode-defined compliance criteria before corporate resources are made available. In this model, UEM provides device posture and compliance context at authentication and access time; it does not replace XDR, which provides runtime threat detection, investigation, and response on endpoints and across the broader environment. Together, these controls can strengthen sensitive Microsoft 365 and SaaS access by reducing reliance on credentials alone while maintaining runtime protection against threats that occur after authentication.

6-steps-To-Hexnode-Quick-Start-Guide
Feature Resource

Hexnode Quick Start Guide: How to set up Hexnode for your business

Get the infographic to learn how you can set up Hexnode for your business

Get the Infographic

Conclusion

UNC6671 demonstrates how helpdesk impersonation and compromised SSO sessions can become pathways to cloud data theft and extortion. Enterprises should harden identity-verification procedures, detect and respond to suspicious authenticated sessions, enforce device-based access controls, and treat vishing-driven identity compromise as a potential cloud-wide security incident rather than an isolated credential reset. A defense-in-depth approach should combine device-bound access controls, using UEM, provided device posture and compliance signals with Conditional Access to restrict authentication and resource access to trusted, compliant devices, with XDR capabilities that detect, investigate, and respond to threats at runtime. Together, these layers help limit both unauthorized access through compromised identities and malicious activity that occurs on endpoints after authentication.

Share

Alanna River

I’m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.