UNC6671
Attribution profile
- Type
- Crime Syndicate
- Location
- -
- Known incidents
- 1 incident
- Sources
- 0 sources
- First seen
- 2026-06-01
- Last seen
- 2026-06-01
- Updated
- 2026-08-13 07:20
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor tracked under the alias UNC6671 is referenced in public reporting as the broader collective to which the Helix hacking group belongs, as reflected in multiple threat feeds. Google has linked Helix to the UNC6671 collective in its threat intelligence assessments. The alias UNC6671 appears in connection with the Helix activity that targeted Uber Freight in mid‑2026. No other names or alternate identifiers for this actor are provided in the source material. The actor is described in open‑source reporting as a loosely affiliated group rather than a single, formally organized entity.
On 2026‑06‑01, Helix claimed to have exfiltrated mailboxes, cloud storage drives, accounts payable files, and dispatch documents from Uber Freight’s systems, with some of the email correspondence later appearing online. This claim was reported by TechCrunch on 2026‑08‑12, noting that Uber Freight said its operations were unaffected and that its systems remained normal while it reviewed the allegations. The alleged intrusion was directed at a logistics and freight services provider, indicating a focus on the transportation sector. The actor’s apparent objective, as evidenced by the ransom demand, is financial gain, with reports stating that Helix has accumulated at least $10.6 million in ransom payments.
The publicly described tactics of this actor rely on voice phishing as a means to obtain initial access to victim environments. Voice phishing, a form of social engineering, is cited as the primary method used by Helix to compromise credentials. No specific malware families, exploit tools, or post‑infection frameworks are mentioned in the available reporting concerning UNC6671 or its Helix component. The Uber Freight incident stands as the representative campaign that illustrates the actor’s focus on credential theft followed by data exfiltration and ransom negotiation. The combination of voice‑phishing‑based credential harvesting and the subsequent ransom demand forms the observable pattern of activity attributed to UNC6671.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 0 sources.