The UNC6783 threat group is behind a sophisticated campaign targeting business process outsourcing ( BPO ) companies to gain access to corporate data from dozens of high-value organizations. According to the Google Threat Intelligence Group (GTIG) , the group is likely linked to the online hacking persona Mr. Raccoon , who is allegedly behind a recent Adobe data breach .

UNC6783’s strategy exploits the trust relationships between organizations and BPO vendors. Rather than directly attacking corporate networks, the threat group targets BPO, bypassing perimeter security systems that would detect direct intrusions. This supply chain approach represents a strategic shift in how sophisticated cyberattackers gain initial access to high-value targets.
See also: Google Chrome: Vertical tabs and improved Reading Mode
The discovery came from GTIG ’s monitoring of the group’s operational patterns , which align with tactics previously attributed to the Mr. Raccoon persona . The connection became more concrete after Mr. Raccoon ’s allegations of a breach at Adobe , which was allegedly carried out through a compromised Indian BPO that worked with the company.
Attack methodology and technical details of UNC6783
UNC6783 ’s initial access is achieved through malicious emails that deploy Remote Access Tools (RATs) to compromise BPO employees . In some cases, fake security software is used to trick employees into downloading malware remote access . The RAT provides comprehensive surveillance capabilities, including camera access and WhatsApp message monitoring .
See also: Google Gemini: Improving answers to mental health questions
To evade detection, the threat group uses sophisticated social engineering. It creates domains that mimic Zendesk following the pattern `[.]zendesk-support pages phishing under the name Okta, exploiting users' trust in familiar authentication platforms. It also uses social engineering via live chat, directing support agents to fake login pages.

The Adobe incident and the scale of the threat
The most notable incident is the alleged Adobe breach attributed to Mr. Raccoon . According to the attacker's claims, the breach allowed access to 13 million support tickets containing personal information, 15,000 employee records , all submissions bug bounty , and internal documents. The attacker escalated his privileges by sending phishing emails to the victim employee's manager, and by obtaining credentials that allowed expanded access within Adobe 's infrastructure .
See also: Anthropic, Google and Broadcom sign the largest deal

Safety recommendations and protection
The researchers provide recommendations for defending against the attacks. They suggest deploying FIDO2 for multi-factor authentication (MFA), monitoring live chat systems, and blocking spoofed domains that match patterns from Zendesk and other vendor infrastructure. Organizations should also implement regular access control reviews.
The campaign highlights the increasing risks in relationships with third-party vendors, as BPOs act as critical infrastructure for multiple organizations simultaneously, impacting many customers.
Source: www.securityweek.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
