UNC6692 Uses Teams Impersonation to Deploy SnowBelt Backdoor

Researchers report UNC6692 floods targets with emails, then impersonates Microsoft Teams helpdesk to trick victims into a fake 'Mailbox Repair Utility' that installs a browser-extension backdoor called SnowBelt. The malware uses AutoHotkey scripts and scheduled tasks to persist by launching windowless Chromium/Edge processes and can download follow-on components (SnowGlaze, SnowBasin) and a portable Python environment for further activity.

Part of the PlainSec briefing for 2026-04-27

Sources