logo

Google Warns of New Threat Group Targeting BPOs and Helpdesks

ID: 19766d6e-a15f-5dcb-a8d0-32673c751400

STIX ID: report--19766d6e-a15f-5dcb-a8d0-32673c751400

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

...
...

Google Threat Intelligence Group warns that UNC6783 is conducting an active extortion campaign against BPOs and enterprise helpdesks using live-chat social engineering and spoofed Okta/Zendesk-support domains to harvest credentials, bypass MFA by stealing clipboard contents, enroll attacker devices for persistent access, and deploy remote access trojans for data exfiltration and ransom; recommended mitigations include implementing phishing-resistant MFA (e.g., FIDO2), monitoring live chat for suspicious links, blocking unauthorized zendesk-support domains, auditing newly enrolled MFA devices, and watching for unauthorized binary execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.