Logo

Home

News

Cyber Insurance

New Mr Raccoon Hacker Group Hits Zendesk Support To Steal Corporate Data

New "Mr. Raccoon" Hacker Group Hits Zendesk Support to Steal Corporate Data

Google flags PROMPTFLUX malware that uses Gemini AI for dynamic code rewritingGoogle flags PROMPTFLUX malware that uses Gemini AI for dynamic code rewriting

New "Mr. Raccoon" Hacker Group Hits Zendesk Support to Steal Corporate Data

A sophisticated new threat group tracked as UNC6783 is targeting the customer support infrastructure of major corporations. According to a report from Google’s Mandiant, these hackers focus on stealing session tokens to hijack Zendesk accounts without needing a password. Once inside, they gain access to a goldmine of sensitive information, including private support tickets, internal communications, and customer-uploaded attachments.

The group, which some researchers link to the "Mr. Raccoon" persona, is primarily motivated by money. Instead of deploying ransomware to lock files, they quietly exfiltrate data and then contact the victim company to demand a ransom, threatening to release the stolen support logs publicly. This tactic is particularly dangerous for Business Process Outsourcing (BPO) firms that manage support for multiple global brands. By compromising just one BPO employee's credentials, the hackers can potentially access the support data of dozens of different companies simultaneously, making it a high-efficiency attack for corporate extortion.


Source: securityweek

Was this article helpful?

Secure Your Future Today!

Share your details to explore
the best insurance options for you.

Secure Your Future Today!Secure Your Future Today!