惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园_首页
Engineering at Meta
Engineering at Meta
量子位
A
About on SuperTechFans
阮一峰的网络日志
阮一峰的网络日志
Recent Announcements
Recent Announcements
博客园 - 司徒正美
V
Visual Studio Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
F
Fortinet All Blogs
Martin Fowler
Martin Fowler
腾讯CDC
Jina AI
Jina AI
C
Check Point Blog
H
Help Net Security
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
爱范儿
爱范儿
I
InfoQ

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
www.theregister.com
Jessica Lyons · 2026-04-10 · via The Register - Security: Cyber-crime

Cyber-crime

'Several dozen' high-value corporations hit by new extortion crew in helpdesk phishing spree

Possible link to Mr. Raccoon's claimed Adobe break-in

A new extortion crew has targeted “several dozen high-value” corporations through phishing and helpdesk social-engineering, according to Google.

Google Threat Intelligence Group tracks the financially motivated group as UNC6783, and in a blog post, principal threat analyst Austin Larsen said that it may have ties to the "Raccoon" persona. 

"We are aware of several dozen high-value corporate entities targeted across multiple sectors," Larsen wrote.

UNC6783 primarily compromises call centers and business process outsourcers (BPOs) that work with larger companies - an attack method popularized by groups like Scattered Spider and ShinyHunters. Once the criminals have access to the BPOs' networks, they can use stolen legitimate credentials from BPO employees to break into their customers' IT environments.

Google has also observed the extortionists targeting corporations' support and helpdesk staff directly to gain access and steal sensitive data.

"The campaign relies on social engineering via live chat to direct employees to malicious, spoofed Okta login pages," Larsen said. "These domains frequently masquerade as the targeted organization using a domain pattern such as <org>[.]zendesk-support<##>[.]com."

The attackers use a custom phishing kit to bypass multi-factor authentication (MFA) by stealing clipboard contents, and then enrolling their own devices for persistent access to victim environments.

Google has also spotted the miscreants using fake security software updates to trick victims into downloading remote access malware. 

Once they steal corporations' data, the crew uses Proton Mail accounts to deliver ransom notes to their victims.

When asked how many of these were successful intrusions, Larsen told The Register that “we are aware of several successful attacks as part of this campaign.”

Last week, International Cyber Digest reported that Adobe was allegedly breached by an attacker calling themselves Mr. Raccoon, who reportedly gained access through an Indian BPO by first deploying a remote access tool on one employee and then phishing that worker’s manager.

The data thief claimed to have stolen 13 million support tickets with personal data, 15,000 employee records, all HackerOne submissions, internal documents, and other information.

Adobe did not immediately respond to The Register's request for comment.

According to malware hunters vx-underground, the Adobe breach appears to be legitimate, and "anyone who submitted a helpdesk ticket to Adobe, or requested assistance in any capacity, could be impacted." ®