Minacce e avversari · Spionaggio APT

Teams Trust Turned Into Browser Persistence

Enterprise collaboration trust is now the entry point for durable access. UNC6692 used Microsoft Teams impersonation to get victims to accept outside chat invites, then pushed a malicious browser-based payload that let the group stay inside the browser and move past the controls that usually catch email-only phishing.

Mandiant says the late-December 2025 campaign combined inbox flooding, Teams helpdesk impersonation, and a custom modular malware suite. The victim was led to a page that downloaded a renamed AutoHotKey binary and script from attacker-controlled infrastructure, and the campaign also used a malicious browser extension to deepen access inside the environment.

The risk is not just initial compromise. Once attackers can operate through a browser extension and modular payloads, they can keep access in the collaboration layer and pivot inside the network even after the original lure is spotted.

7 fonti · 27 apr

Valutazione della community

Threat researchers at Mandiant add that UNC6692’s SNOW ecosystem includes SNOWBELT, SNOWGLAZE, and SNOWBASIN, indicating a modular intrusion chain built for deeper network penetration and exfiltration beyond the initial Teams lure.

Cronologia

Fonti

Riepilogo fornitore: Microsoft

Part of the PlainSec briefing for 2026-04-25

Every edition of this story: Teams Trust Turned Into Browser Persistence

Altro da oggi