New research from Google Threat Intelligence Group (GTIG) has uncovered how cyber extortion group UNC6671 operates through a network of multiple public-facing ransomware and extortion brands designed to complicate investigations and maximise profits.
Rather than relying on a single identity, GTIG says the core intrusion group supplies operations carried out under several different brands, including Redact, Pink, Helix and Falcon. This decentralised approach allows operators to compartmentalise negotiations, obscure links between attacks and make attribution significantly more difficult for defenders and law enforcement.
The research also provides insight into the group’s business model. Between January and May 2026, GTIG tracked more than US$10.6 million in Bitcoin payments flowing to wallets associated with the operation.
While initial ransom demands regularly exceed US$3 million, attackers frequently negotiate settlements closer to US$750,000, demonstrating an increasingly commercial approach to cyber extortion where negotiations are treated as part of a structured business process.
According to GTIG, the findings reinforce that many modern cybercriminal groups function much like decentralised enterprises, sharing infrastructure and capabilities across multiple brands while maintaining a degree of operational separation.








