← Back to Crime & Security

Cyber Group UNC6671 Targets Cloud Credentials via Voice Phishing and MITM Attacks

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A cyber threat group identified as UNC6671, also known by the alias Cordial Spider, is conducting a sophisticated campaign to steal cloud credentials and multi-factor authentication tokens from organizations using software-as-a-service platforms. The group employs voice phishing tactics combined with adversary-in-the-middle attacks to compromise accounts on Microsoft 365 and Okta systems.

The operation focuses on intercepting user sessions to exfiltrate sensitive data, which the attackers subsequently leverage for financial extortion. By positioning themselves between users and cloud service providers, UNC6671 captures authentication tokens in real-time, allowing them to bypass standard security controls without triggering immediate alerts from traditional perimeter defenses. The stolen credentials grant access to email archives, internal communications, and proprietary business documents.

Security researchers have observed the group targeting a wide range of sectors, with particular emphasis on organizations heavily reliant on cloud-based identity management solutions. The attackers utilize social engineering techniques delivered via phone calls to trick employees into revealing verification codes or clicking malicious links that redirect traffic through compromised infrastructure. Once inside, UNC6671 moves laterally within networks to aggregate data before initiating ransom demands.

The campaign represents an evolution in how threat actors exploit the convergence of human error and technical vulnerabilities in modern cloud environments. Unlike previous waves of attacks focused solely on credential stuffing or brute-force methods, this group relies heavily on active interception techniques that require direct interaction with targeted users during authentication processes. The use of voice phishing adds a layer of urgency to their operations, pressuring victims into bypassing standard security protocols under the guise of IT support or administrative necessity.

Organizations are advised to review access logs for Microsoft 365 and Okta platforms to identify unauthorized sessions originating from unfamiliar locations or devices. Implementing strict device binding policies and requiring hardware-based authentication tokens may mitigate risks associated with token theft, though voice phishing remains a significant challenge due to its reliance on human interaction rather than technical exploits alone.

The full scope of the data exfiltration remains unclear as many victims have not yet disclosed breaches publicly. Questions persist regarding whether UNC6671 operates independently or in coordination with other criminal syndicates known for similar extortion schemes. Additionally, it is unknown if the group has developed new tools specifically designed to evade detection by advanced endpoint security solutions currently deployed across enterprise networks.

As of now, no specific attribution beyond the designation UNC6671 and alias Cordial Spider has been confirmed by law enforcement agencies or national cybersecurity authorities. The group continues to refine its methods, suggesting an ongoing commitment to exploiting cloud infrastructure vulnerabilities for financial gain.

Discussion

0 / 2000