Hacking group Scattered Lapsus$ Hunters may have already commenced attacks aimed at Zendesk environments, following the creation of nearly 40 typosquatted domains for the cloud-based customer service and sales software during the last six months, Cybersecurity Dive reports.Included in the illicit domains were Cloudflare-masked nameservers, U.S.- and UK-based registrant contact details, and NiceNik registration, with certain domains redirecting to bogus single sign-on portals aimed at pilfering user credentials, an analysis from ReliaQuest revealed."The primary objective at this stage appears to be harvesting credentials from users within organizations that rely on Zendesk, such as system administrators or helpdesk personnel likely due to their elevated permissions," noted a ReliaQuest spokesperson.Zendesk has assured continuous monitoring of possible phishing intrusions in the wake of the findings, which were noted by ReliaQuest to resemble Scattered Lapsus$ Hunters' sweeping attack campaign against Salesforce environments in August.
Threat Intelligence, Supply chain
Scattered Lapsus$ Hunters prepping Zendesk-aimed intrusions
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
