Menu
Browse

Cyber Threat Actor: Zestix

Updated 2026-07-18 01:28
Actor Type Location Known Incidents
 Icon
Criminal
1 incident
Profile

Zestix is an alias associated with a threat actor that gained public attention following a reported breach of Adobe in April 2026. The intrusion began with a phishing email that delivered a remote access tool to an employee of an Indian Business Process Outsourcing contractor working with Adobe. Using that foothold, the actor pivoted to a manager’s account and subsequently accessed the helpdesk environment, where a single support agent could export all tickets in one request. The operation exposed roughly thirteen million customer support tickets, fifteen thousand employee records, and the complete set of HackerOne bug bounty submissions, including customer names, email addresses, account IDs, internal technical notes, and unpublished vulnerability reports. Adobe has neither confirmed nor denied the incident publicly.

The actor’s observed tactics, techniques, and procedures center on a supply‑chain compromise that combines phishing for initial access with privilege escalation to move laterally within a target’s network. The remote access tool employed in the phishing payload enabled the attacker to execute commands on the contractor’s system and then use stolen credentials to reach higher‑privileged accounts. Once inside the helpdesk infrastructure, the actor leveraged the platform’s export functionality to gather large volumes of sensitive data in a single action, demonstrating a focus on data exfiltration rather than destructive disruption. No specific malware families or custom tooling beyond the generic remote access tool are described in the public reporting.

Public attribution of Zestix to a state sponsor, criminal consortium, or other organized group has not been established; the available sources do not link the actor to any known nation‑state program or affiliated cybercrime syndicate. The Adobe breach remains the sole publicly documented operation attributed to Zestix, serving as the primary example of the actor’s methodology. Consequently, the profile is limited to the confirmed details of that incident, with no extrapolation regarding the actor’s broader goals, size, or geographic focus beyond what is explicitly stated in the reported event.

Incidents
Attributed incidents available to members
1 incident
Sources
Sources available to members
0 sources