Back Infosecurity-Magazine Google Warns of New Threat Group Targeting BPOs and Helpdesks
A new threat group is targeting business process outsourcers (BPOs) and large enterprises for extortion using live chat channels, Google has warned.
Google Threat Intelligence Group (GTIG) principal threat analyst, Austin Larsen, said UNC6783 is a financially motivated threat cluster that may be tied to the “Raccoon” persona.
The group has targeted several dozen “high-value corporate entities” across multiple sectors – focusing mainly on their BPOs, but sometimes also hitting their in-house helpdesk and support teams directly.
The end goal is to steal sensitive data for extortion, Larsen explained.
“The campaign relies on social engineering via live chat to direct employees to malicious, spoofed Okta login pages. These domains frequently masquerade as the targeted organization using a domain pattern such as [.]zendesk-support [.]com,” Larsen noted.
“Their phishing kit is used to bypass standard multi-factor authentication (MFA) verification by stealing clipboard contents, which then allows the attackers to enroll their own devices for persistent access.”
Alternatively, the GTIG team has also observed UNC6783 using fake security software updates to trick users into downloading remote access malware. It sometimes uses Proton Mail accounts to deliver ransom notes following data exfiltration, Larsen continued.
The tactics are not dissimilar to those of notorious extortion-focused collective Scattered Lapsus$ Hunters .
Last year, reports emerged of a campaign using Zendesk phishing domains to harvest employee credentials. The hackers also submitted fraudulent tickets to helpdesk staff to infect them with remote access trojans (RATs) and other types of malware.
GTIG’s Larsen urged organizations to:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
