Google Warns of New Threat Group Targeting BPOs and Helpdesks
ID: 19766d6e-a15f-5dcb-a8d0-32673c751400
STIX ID: report--19766d6e-a15f-5dcb-a8d0-32673c751400
Feed Name: Infosecurity Magazine (News)
Google Threat Intelligence Group warns that UNC6783 is conducting an active extortion campaign against BPOs and enterprise helpdesks using live-chat social engineering and spoofed Okta/Zendesk-support domains to harvest credentials, bypass MFA by stealing clipboard contents, enroll attacker devices for persistent access, and deploy remote access trojans for data exfiltration and ransom; recommended mitigations include implementing phishing-resistant MFA (e.g., FIDO2), monitoring live chat for suspicious links, blocking unauthorized zendesk-support domains, auditing newly enrolled MFA devices, and watching for unauthorized binary execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
