Skip to content
Actor tied to Raccoon targets 'several dozen' companies by exploiting BPOs and helpdesks

Actor tied to Raccoon targets 'several dozen' companies by exploiting BPOs and helpdesks

Scworld • April 9, 2026

The Google Threat Intelligence Group (GTIG) on April 7 reported that the threat group UNC6783, a financially-motivated actor potentially tied to the “Raccoon” persona has been observed conducting targeted social engineering and phishing campaigns on at least several dozen “high-value” companies.

In a post , Austin Larsen, a principal threat analyst at GTIG, said UNC6783 primarily focuses on compromising business process outsourcers (BPOs) that work with these targeted companies. Larsen said GTIG researchers have also seen them target the support and helpdesk staff of these organizations directly to gain trusted access and steal sensitive data for extortion operations. According to Larsen, the campaign relies on social engineering via live chat to direct employees to malicious, spoofed Okta login pages. These domains frequently masquerade as the targeted organization using a domain pattern such as [.]zendesk-support [.]com. Larsen said the attackers then bypass standard multi-factor authentication (MFA) by stealing clipboard contents, which then let the attackers enroll their own devices for persistent access. “We have also observed them using fake security software updates to trick victims into downloading remote access malware,” said Larsen. “Following data exfiltration, UNC6783 has been known to use Proton Mail accounts to deliver ransom notes for data theft extortion operations.”

Denis Calderone, principal/CTO at Suzu Labs, said BPOs have the security community very nervous right now. Calderone said his team has recently observed attacks targeting helpdesks, support platforms, and service providers, from Zendesk platform abuse to the Hims & Hers support system breach to Okta SSO vishing campaigns .

“Now, Google's GTIG is tracking UNC6783 going after BPOs and enterprise help desks specifically for data extortion,” said Calderone. “When these services are provided as part of BPO operations, it's not hard to see how this escalates very quickly. BPO agents typically operate across multiple client environments, so one compromised helpdesk agent can become a doorway into every customer that BPO serves.”

Calderone added that the live chat vector is also worth calling out. He said researchers have seen it with WhatsApp delivery, with ticketing system abuse, and now with live chat social engineering.

“These are all channels that sit outside traditional email security," said Calderone. "Organizations have spent years hardening email with gateways, sandboxing, and link scanning, but live chat, messaging apps, and support platforms have almost none of those controls. Attackers are finding the gaps, and the gaps are in the communication channels we aren't monitoring.”

John Watters, chief executive officer and managing partner at iCOUNTER, added that what’s emerging with UNC6783 and the Raccoon persona is not just another social engineering campaign: it’s a deliberate strategy to enter through the ecosystem instead of attacking the enterprise head-on.

“By targeting BPOs, help desks, and live support channels, the attackers are exploiting the operational trust layer that connects companies to their vendors, partners, and customers,” said Watters. “These are environments where identity is routinely verified, reset, and extended, often under time pressure, making them ideal insertion points.”

Watters said the real shift is that the ecosystem has become the new attack surface. Attackers understand that compromising a third-party interaction or a support workflow can be more effective than breaching hardened infrastructure.

“Once inside, they can move laterally through identity systems, enroll persistent access, and operate as a legitimate user,” said Watters. “This isn’t better phishing detection, it’s recognizing that your security posture is now only as strong as the weakest operational link in your ecosystem.”

Here's how Watters said organizations should respond:

Extracted Entities

Attack Types (2)

Companies (2)

Platforms (2)