TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Infosecurity Magazine

Google Warns of New Threat Group Targeting BPOs and Helpdesks

2026-04-09 · Read original ↗

ATT&CK techniques detected

3 predictions
T1566.002Spearphishing Link
95%
“by stealing clipboard contents, which then allows the attackers to enroll their own devices for persistent access. ” alternatively, the gtig team has also observed unc6783 using fake security software updates to trick users into downloading remote access malware. it sometimes use…”
T1566.002Spearphishing Link
74%
“google warns of new threat group targeting bpos and helpdesks a new threat group is targeting business process outsourcers ( bpos ) and large enterprises for extortion using live chat channels, google has warned. google threat intelligence group ( gtig ) principal threat analyst,…”
T1556.006Multi-Factor Authentication
70%
“on this specific campaign - proactively block any unauthorized domains with the [. ] zendesk - support [. ] com pattern - monitor for unauthorized binary execution, especially installers or " updates " downloaded during support sessions - regularly audit newly enrolled mfa device…”

Summary

Google’s threat intel team warns UNC6783, a new extortion group possibly linked to the “Raccoon” persona, is targeting BPOs and enterprises