HomeSecurityUNC6783: New campaign to steal corporate data via BPO

UNC6783: New campaign to steal corporate data via BPO

The UNC6783 threat group is behind a sophisticated campaign targeting business process outsourcing ( BPO ) companies to gain access to corporate data from dozens of high-value organizations. According to the Google Threat Intelligence Group (GTIG) , the group is likely linked to the online hacking persona Mr. Raccoon , who is allegedly behind a recent Adobe data breach .

UNC6783 BPO

UNC6783’s strategy exploits the trust relationships between organizations and BPO vendors. Rather than directly attacking corporate networks, the threat group targets BPO, bypassing perimeter security systems that would detect direct intrusions. This supply chain approach represents a strategic shift in how sophisticated cyberattackers gain initial access to high-value targets.

See also: Google Chrome: Vertical tabs and improved Reading Mode

The discovery came from GTIG ’s monitoring of the group’s operational patterns , which align with tactics previously attributed to the Mr. Raccoon persona . The connection became more concrete after Mr. Raccoon ’s allegations of a breach at Adobe , which was allegedly carried out through a compromised Indian BPO that worked with the company.

Attack methodology and technical details of UNC6783

UNC6783 ’s initial access is achieved through malicious emails that deploy Remote Access Tools (RATs) to compromise BPO employees . In some cases, fake security software is used to trick employees into downloading malware remote access . The RAT provides comprehensive surveillance capabilities, including camera access and WhatsApp message monitoring .

See also: Google Gemini: Improving answers to mental health questions

To evade detection, the threat group uses sophisticated social engineering. It creates domains that mimic Zendesk following the pattern `[.]zendesk-support pages phishing under the name Okta, exploiting users' trust in familiar authentication platforms. It also uses social engineering via live chat, directing support agents to fake login pages.

UNC6783: New campaign to steal corporate data via BPO

The Adobe incident and the scale of the threat

The most notable incident is the alleged Adobe breach attributed to Mr. Raccoon . According to the attacker's claims, the breach allowed access to 13 million support tickets containing personal information, 15,000 employee records , all submissions bug bounty , and internal documents. The attacker escalated his privileges by sending phishing emails to the victim employee's manager, and by obtaining credentials that allowed expanded access within Adobe 's infrastructure .

See also: Anthropic, Google and Broadcom sign the largest deal

UNC6783: New campaign to steal corporate data via BPO

Safety recommendations and protection

The researchers provide recommendations for defending against the attacks. They suggest deploying FIDO2 for multi-factor authentication (MFA), monitoring live chat systems, and blocking spoofed domains that match patterns from Zendesk and other vendor infrastructure. Organizations should also implement regular access control reviews.

The campaign highlights the increasing risks in relationships with third-party vendors, as BPOs act as critical infrastructure for multiple organizations simultaneously, impacting many customers.

Source: www.securityweek.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS