Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories

April 11, 2026

Google Chrome Rolls Out Protection Against Infostealers

April 11, 2026

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners

April 11, 2026
Facebook X (Twitter) Instagram
Saturday, April 11
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Google Warns of New Threat Group Targeting BPOs and Helpdesks
News

Google Warns of New Threat Group Targeting BPOs and Helpdesks

Team-CWDBy Team-CWDApril 9, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A new threat group is targeting business process outsourcers (BPOs) and large enterprises for extortion using live chat channels, Google has warned.

Google Threat Intelligence Group (GTIG) principal threat analyst, Austin Larsen, said UNC6783 is a financially motivated threat cluster that may be tied to the “Raccoon” persona.

The group has targeted several dozen “high-value corporate entities” across multiple sectors – focusing mainly on their BPOs, but sometimes also hitting their in-house helpdesk and support teams directly.

The end goal is to steal sensitive data for extortion, Larsen explained.

Read more on helpdesk targeting: Scattered Spider Uses Tech Vendor Impersonation and Phishing Kits to Target Helpdesks

“The campaign relies on social engineering via live chat to direct employees to malicious, spoofed Okta login pages. These domains frequently masquerade as the targeted organization using a domain pattern such as [.]zendesk-support<##>[.]com,” Larsen noted.

“Their phishing kit is used to bypass standard multi-factor authentication (MFA) verification by stealing clipboard contents, which then allows the attackers to enroll their own devices for persistent access.”

Alternatively, the GTIG team has also observed UNC6783 using fake security software updates to trick users into downloading remote access malware. It sometimes uses Proton Mail accounts to deliver ransom notes following data exfiltration, Larsen continued.

The tactics are not dissimilar to those of notorious extortion-focused collective Scattered Lapsus$ Hunters.

Last year, reports emerged of a campaign using Zendesk phishing domains to harvest employee credentials. The hackers also submitted fraudulent tickets to helpdesk staff to infect them with remote access trojans (RATs) and other types of malware.

Advice for BPOs and Helpdesk Staff

GTIG’s Larsen urged organizations to:

  • Implement phishing-resistant MFA such as FIDO2 hardware security keys (e.g. Titan Security Keys) for all users, especially those in high-risk roles like support and helpdesk
  • Monitor live chat for suspicious interactions such as those directing users to external links
  • Educate employees on this specific campaign
  • Proactively block any unauthorized domains with the [.]zendesk-support[.]com pattern
  • Monitor for unauthorized binary execution, especially installers or “updates” downloaded during support sessions
  • Regularly audit newly enrolled MFA devices across the organization for unauthorized additions



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAndroid Developer Verification Rollout Begins Ahead of September Enforcement
Next Article Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
Team-CWD
  • Website

Related Posts

News

ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories

April 11, 2026
News

Google Chrome Rolls Out Protection Against Infostealers

April 11, 2026
News

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners

April 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views

Why the Identity Security Fabric is Essential for Securing AI and Non-Human Identities

November 27, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Our Picks

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

AI-powered financial scams swamp social media

September 11, 2025

It’s all fun and games until someone gets hacked

September 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.