logo

UNC6783 Turns BPO Providers into Cyberattack Gateways

ID: 3d3466f0-c49e-5d27-a5d7-23aa65059665

STIX ID: report--3d3466f0-c49e-5d27-a5d7-23aa65059665

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

Google Threat Intelligence Group reports that UNC6783 (possibly linked to a persona known as "Raccoon") is actively targeting BPO companies to gain access to large enterprises. The group uses phishing and live-chat social engineering to direct employees to fake Okta-like login pages, employs a toolkit that can capture clipboard data to bypass MFA and register devices, distributes fake security updates that install remote access trojans, and exfiltrates support data for extortion. Mandiant recommends FIDO2 hardware keys, monitoring live chat systems, blocking lookalike domains, and auditing MFA device registrations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.