Researchers report UNC6692 floods targets with emails, then impersonates Microsoft Teams helpdesk to trick victims into a fake 'Mailbox Repair Utility' that installs a browser-extension backdoor called SnowBelt. The malware uses AutoHotkey scripts and scheduled tasks to persist by launching windowless Chromium/Edge processes and can download follow-on components (SnowGlaze, SnowBasin) and a portable Python environment for further activity.
Part of the PlainSec briefing for 2026-04-27