Cloud Security, Application security, Identity, Phishing

Actor tied to Raccoon targets ‘several dozen’ companies by exploiting BPOs and helpdesks

(Adobe Stock)

The Google Threat Intelligence Group (GTIG) on April 7 reported that the threat group UNC6783, a financially-motivated actor potentially tied to the “Raccoon” persona has been observed conducting targeted social engineering and phishing campaigns on at least several dozen “high-value” companies.

In a LinkedIn post, Austin Larsen, a principal threat analyst at GTIG, said UNC6783 primarily focuses on compromising business process outsourcers (BPOs) that work with these targeted companies. Larsen said GTIG researchers have also seen them target the support and helpdesk staff of these organizations directly to gain trusted access and steal sensitive data for extortion operations.

According to Larsen, the campaign relies on social engineering via live chat to direct employees to malicious, spoofed Okta login pages. These domains frequently masquerade as the targeted organization using a domain pattern such as <org>[.]zendesk-support<##>[.]com. Larsen said the attackers then bypass standard multi-factor authentication (MFA) by stealing clipboard contents, which then let the attackers enroll their own devices for persistent access.

“We have also observed them using fake security software updates to trick victims into downloading remote access malware,” said Larsen. “Following data exfiltration, UNC6783 has been known to use Proton Mail accounts to deliver ransom notes for data theft extortion operations.”

Denis Calderone, principal/CTO at Suzu Labs, said BPOs have the security community very nervous right now. Calderone said his team has recently observed attacks targeting helpdesks, support platforms, and service providers, from Zendesk platform abuse to the Hims & Hers support system breach to Okta SSO vishing campaigns.

“Now, Google's GTIG is tracking UNC6783 going after BPOs and enterprise help desks specifically for data extortion,” said Calderone. “When these services are provided as part of BPO operations, it's not hard to see how this escalates very quickly. BPO agents typically operate across multiple client environments, so one compromised helpdesk agent can become a doorway into every customer that BPO serves.” 

Calderone added that the live chat vector is also worth calling out. He said researchers have seen it with WhatsApp delivery, with ticketing system abuse, and now with live chat social engineering.

“These are all channels that sit outside traditional email security," said Calderone. "Organizations have spent years hardening email with gateways, sandboxing, and link scanning, but live chat, messaging apps, and support platforms have almost none of those controls. Attackers are finding the gaps, and the gaps are in the communication channels we aren't monitoring.”

John Watters, chief executive officer and managing partner at iCOUNTER, added that what’s emerging with UNC6783 and the Raccoon persona is not just another social engineering campaign: it’s a deliberate strategy to enter through the ecosystem instead of attacking the enterprise head-on.

“By targeting BPOs, help desks, and live support channels, the attackers are exploiting the operational trust layer that connects companies to their vendors, partners, and customers,” said Watters. “These are environments where identity is routinely verified, reset, and extended, often under time pressure, making them ideal insertion points.”

Watters said the real shift is that the ecosystem has become the new attack surface. Attackers understand that compromising a third-party interaction or a support workflow can be more effective than breaching hardened infrastructure.

“Once inside, they can move laterally through identity systems, enroll persistent access, and operate as a legitimate user,” said Watters. “This isn’t about better phishing detection, it’s about recognizing that your security posture is now only as strong as the weakest operational link in your ecosystem.”

Here's how Watters said organizations should respond:

  • Treat the BPO ecosystem as a live threat environment: Move beyond periodic vendor reviews to continuous monitoring of third-party exposure and active compromise signals.
  • Secure operational trust channels: Apply controls and verification to live chat, support desks, and outsourced operations, as these are now frontline attack surfaces.
  • Focus on identity as the pathway, not the control: Monitor for signs of identity manipulation, not just login attempts, including abnormal resets, enrollments, and session behaviors.
  • Act on intelligence before compromise: The advantage goes to organizations that can detect and respond to adversary activity as it emerges across their ecosystem.

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds