Threat Intelligence, Supply chain

Scattered Lapsus$ Hunters prepping Zendesk-aimed intrusions

Robotic spiders invade circuit board; digital attack background

Hacking group Scattered Lapsus$ Hunters may have already commenced attacks aimed at Zendesk environments, following the creation of nearly 40 typosquatted domains for the cloud-based customer service and sales software during the last six months, Cybersecurity Dive reports.

Included in the illicit domains were Cloudflare-masked nameservers, U.S.- and UK-based registrant contact details, and NiceNik registration, with certain domains redirecting to bogus single sign-on portals aimed at pilfering user credentials, an analysis from ReliaQuest revealed.

"The primary objective at this stage appears to be harvesting credentials from users within organizations that rely on Zendesk, such as system administrators or helpdesk personnel likely due to their elevated permissions," noted a ReliaQuest spokesperson.

Zendesk has assured continuous monitoring of possible phishing intrusions in the wake of the findings, which were noted by ReliaQuest to resemble Scattered Lapsus$ Hunters' sweeping attack campaign against Salesforce environments in August.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds