Is Zendesk Scattered Lapsus$ Huntersâ Latest Campaign Target?
ID: 54696ac7-1312-5d89-a4c8-d107706ccbf8
STIX ID: report--54696ac7-1312-5d89-a4c8-d107706ccbf8
Feed Name: ReliaQuest Blog
Threat Score
ReliaQuest identified a likely campaign by the Scattered Lapsus$ Hunters collective targeting Zendesk via 40+ typosquatted/impersonating domains and fraudulent tickets that host fake SSO pages to harvest credentials and deliver RATs; the activity mirrors prior attacks on Salesforce, Discord, and Gainsight and includes observable registry and infrastructure patterns, prompting mitigation guidance such as MFA, domain monitoring, and stricter Zendesk controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
