UNC6783 Hackers Use Fake Okta Pages in Corporate Breach Campaign
ID: bdf19205-2376-5a5a-b4e0-7fdcd972e792
STIX ID: report--bdf19205-2376-5a5a-b4e0-7fdcd972e792
Feed Name: HackRead
Google's Threat Intelligence Group warns of UNC6783 (possibly linked to a 'Raccoon' persona) conducting a supply‑chain style campaign against Business Process Outsourcers: attackers use live-chat social engineering and phishing kits with fake Okta pages to steal credentials and clipboard data, enroll devices for persistent access, deploy RATs via malicious 'updates', exfiltrate data and issue ransom/extortion demands; recommended mitigations include FIDO2 hardware keys, monitoring live-chat logs, blocking suspicious Zendesk-pattern links, and auditing enrolled devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
