UNC6671: Vishing-Driven Data Extortion Group
UNC6671 is a data extortion group known for using vishing (voice phishing) to target enterprise employees, often via personal mobile devices. They…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
UNC6671 is a data extortion group known for using vishing (voice phishing) to target enterprise employees, often via personal mobile devices. They…
Cordial Spider is CrowdStrike's tracking name for the umbrella collective behind UNC6671. The group conducts rapid data theft and extortion campaigns by…
Scattered LAPSUS$ Hunters (SLH) is a threat actor associated with shared phishing-kit infrastructure. Some vishing attempts have been linked to SLH tradecraft,…
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to the data extortion group…
Storm-2755 is a financially motivated threat cluster tracked by Microsoft, also known as Payroll Pirates. It hijacks employee accounts to reroute salary…
Storm-2657 is a threat actor tracked by Microsoft, associated with phishing campaigns targeting Microsoft 365 accounts. Documented since early 2025, it shares…
A new analysis by Oligo Security has uncovered that the threat actor known as TeamPCP has been active in the cybercrime scene…
TeamPCP is a threat actor active since at least 2020, initially targeting Redis servers and later evolving into sophisticated supply chain attacks.…
A threat actor exploited the CryptoJS weak RNG to drain over $5.7 million from cryptocurrency wallets across multiple networks.
Ransom Cartel is a ransomware-as-a-service operation created by Maksim Silnikau in 2021. It targeted at least 18 companies across the U.S. and…