TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

KnowBe4 Blog

Attackers Continue to Pose as Help Desks in Social Engineering Attacks

KnowBe4 Team · 10 hours ago · Read original ↗

ATT&CK techniques detected

4 predictions
T1684.001Impersonation
82%
“attackers continue to pose as help desks in social engineering attacks researchers at google ’ s threat intelligence group ( gtig ) are tracking a new threat actor that ’ s impersonating help desks to trick users into installing malware. the threat actor, which gtig tracks as “ u…”
T1566.004Spearphishing Voice
79%
“attackers continue to pose as help desks in social engineering attacks researchers at google ’ s threat intelligence group ( gtig ) are tracking a new threat actor that ’ s impersonating help desks to trick users into installing malware. the threat actor, which gtig tracks as “ u…”
T1204.002Malicious File
35%
“attackers continue to pose as help desks in social engineering attacks researchers at google ’ s threat intelligence group ( gtig ) are tracking a new threat actor that ’ s impersonating help desks to trick users into installing malware. the threat actor, which gtig tracks as “ u…”
T1667Email Bombing
31%
“attackers continue to pose as help desks in social engineering attacks researchers at google ’ s threat intelligence group ( gtig ) are tracking a new threat actor that ’ s impersonating help desks to trick users into installing malware. the threat actor, which gtig tracks as “ u…”

Summary

Researchers at Google’s Threat Intelligence Group (GTIG) are tracking a new threat actor that’s impersonating help desks to trick users into installing malware. The threat actor, which GTIG tracks as “UNC6692,” begins by sending a large volume of spam emails to the victim, then initiates contact via Microsoft Teams to ostensibly help the user block the spam.