Minacce · 156 giorni fa
Teams Trust Turned Into Browser Persistence Enterprise collaboration trust is now the entry point for durable access. UNC6692 used Microsoft Teams impersonation to get victims to accept outside chat invites, then pushed a malicious browser-based payload that let the group stay inside the browser and move past the controls that usually catch email-only phishing.
Mandiant says the late-December 2025 campaign combined inbox flooding, Teams helpdesk impersonation, and a custom modular malware suite. The victim was led to a page that downloaded a renamed AutoHotKey binary and script from attacker-controlled infrastructure, and the campaign also used a malicious browser extension to deepen access inside the environment.
The risk is not just initial compromise. Once attackers can operate through a browser extension and modular payloads, they can keep access in the collaboration layer and pivot inside the network even after the original lure is spotted.
Cronologia Fonti 7 fonti che coprono questa storia
Dark Reading 27 apr
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
A newly discovered threat actor is using Microsoft Teams, AWS S3 buckets, and custom "Snow" malware in a multipronged campaign.
The Record from Recorded Future 27 apr
Hackers impersonate Microsoft Teams help desk to breach corporate networks
Hackers are impersonating Microsoft Teams help desk workers to trick victims into installing data-stealing malware, researchers found.
SecurityWeek 27 apr
UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware
The threat actor infected victims with the Snow malware family – Snowbelt, Snowglaze, and Snowbasin – for persistent access.
BleepingComputer 25 apr
Threat actor uses Microsoft Teams to deploy new “Snow” malware
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named 'Snow' which includes a browser extension, a tunneler, and a backdoor.
The Register Security 25 apr
Crime crew impersonates help desk, abuses Teams chats
: Coming in cold with custom Snow malware
The Hacker News 24 apr
UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware
UNC6692 targeted 77% senior employees between March 1–April 1, 2026, via Teams impersonation, enabling malware, data theft.
Mandiant 23 apr
How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Google Cloud Blog
UNC6692 uses social engineering via email spamming and Microsoft Teams phishing to deploy a modular malware suite.
Entità Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-04-27
Editions Storie correlate
Minacce · 156 giorni fa
Teams Trust Turned Into Browser Persistence Enterprise collaboration trust is now the entry point for durable access. UNC6692 used Microsoft Teams impersonation to get victims to accept outside chat invites, then pushed a malicious browser-based payload that let the group stay inside the browser and move past the controls that usually catch email-only phishing.
Mandiant says the late-December 2025 campaign combined inbox flooding, Teams helpdesk impersonation, and a custom modular malware suite. The victim was led to a page that downloaded a renamed AutoHotKey binary and script from attacker-controlled infrastructure, and the campaign also used a malicious browser extension to deepen access inside the environment.
The risk is not just initial compromise. Once attackers can operate through a browser extension and modular payloads, they can keep access in the collaboration layer and pivot inside the network even after the original lure is spotted.
Cronologia Fonti 7 fonti che coprono questa storia
Dark Reading 27 apr
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
A newly discovered threat actor is using Microsoft Teams, AWS S3 buckets, and custom "Snow" malware in a multipronged campaign.
The Record from Recorded Future 27 apr
Hackers impersonate Microsoft Teams help desk to breach corporate networks
Hackers are impersonating Microsoft Teams help desk workers to trick victims into installing data-stealing malware, researchers found.
SecurityWeek 27 apr
UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware
The threat actor infected victims with the Snow malware family – Snowbelt, Snowglaze, and Snowbasin – for persistent access.
BleepingComputer 25 apr
Threat actor uses Microsoft Teams to deploy new “Snow” malware
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named 'Snow' which includes a browser extension, a tunneler, and a backdoor.
The Register Security 25 apr
Crime crew impersonates help desk, abuses Teams chats
: Coming in cold with custom Snow malware
The Hacker News 24 apr
UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware
UNC6692 targeted 77% senior employees between March 1–April 1, 2026, via Teams impersonation, enabling malware, data theft.
Mandiant 23 apr
How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Google Cloud Blog
UNC6692 uses social engineering via email spamming and Microsoft Teams phishing to deploy a modular malware suite.
Entità Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-04-27
Editions Storie correlate