Threats · 140 days ago
Teams Trust Turned Into Browser Persistence Enterprise collaboration trust is now the entry point for durable access. UNC6692 used Microsoft Teams impersonation to get victims to accept outside chat invites, then pushed a malicious browser-based payload that let the group stay inside the browser and move past the controls that usually catch email-only phishing.
Mandiant says the late-December 2025 campaign combined inbox flooding, Teams helpdesk impersonation, and a custom modular malware suite. The victim was led to a page that downloaded a renamed AutoHotKey binary and script from attacker-controlled infrastructure, and the campaign also used a malicious browser extension to deepen access inside the environment.
The risk is not just initial compromise. Once attackers can operate through a browser extension and modular payloads, they can keep access in the collaboration layer and pivot inside the network even after the original lure is spotted.
Timeline Sources 7 sources covering this story
Dark Reading Apr 27
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
A newly discovered threat actor is using Microsoft Teams, AWS S3 buckets, and custom "Snow" malware in a multipronged campaign.
The Record from Recorded Future Apr 27
Hackers impersonate Microsoft Teams help desk to breach corporate networks
Hackers are impersonating Microsoft Teams help desk workers to trick victims into installing data-stealing malware, researchers found.
SecurityWeek Apr 27
UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware
The threat actor infected victims with the Snow malware family – Snowbelt, Snowglaze, and Snowbasin – for persistent access.
BleepingComputer Apr 25
Threat actor uses Microsoft Teams to deploy new “Snow” malware
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named 'Snow' which includes a browser extension, a tunneler, and a backdoor.
The Register Security Apr 25
Crime crew impersonates help desk, abuses Teams chats
: Coming in cold with custom Snow malware
The Hacker News Apr 24
UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware
UNC6692 targeted 77% senior employees between March 1–April 1, 2026, via Teams impersonation, enabling malware, data theft.
Mandiant Apr 23
How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Google Cloud Blog
UNC6692 uses social engineering via email spamming and Microsoft Teams phishing to deploy a modular malware suite.
Entities Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-04-27
Editions Related stories
Threats · 140 days ago
Teams Trust Turned Into Browser Persistence Enterprise collaboration trust is now the entry point for durable access. UNC6692 used Microsoft Teams impersonation to get victims to accept outside chat invites, then pushed a malicious browser-based payload that let the group stay inside the browser and move past the controls that usually catch email-only phishing.
Mandiant says the late-December 2025 campaign combined inbox flooding, Teams helpdesk impersonation, and a custom modular malware suite. The victim was led to a page that downloaded a renamed AutoHotKey binary and script from attacker-controlled infrastructure, and the campaign also used a malicious browser extension to deepen access inside the environment.
The risk is not just initial compromise. Once attackers can operate through a browser extension and modular payloads, they can keep access in the collaboration layer and pivot inside the network even after the original lure is spotted.
Timeline Sources 7 sources covering this story
Dark Reading Apr 27
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
A newly discovered threat actor is using Microsoft Teams, AWS S3 buckets, and custom "Snow" malware in a multipronged campaign.
The Record from Recorded Future Apr 27
Hackers impersonate Microsoft Teams help desk to breach corporate networks
Hackers are impersonating Microsoft Teams help desk workers to trick victims into installing data-stealing malware, researchers found.
SecurityWeek Apr 27
UNC6692 Uses Email Bombing, Social Engineering to Deploy ‘Snow’ Malware
The threat actor infected victims with the Snow malware family – Snowbelt, Snowglaze, and Snowbasin – for persistent access.
BleepingComputer Apr 25
Threat actor uses Microsoft Teams to deploy new “Snow” malware
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named 'Snow' which includes a browser extension, a tunneler, and a backdoor.
The Register Security Apr 25
Crime crew impersonates help desk, abuses Teams chats
: Coming in cold with custom Snow malware
The Hacker News Apr 24
UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware
UNC6692 targeted 77% senior employees between March 1–April 1, 2026, via Teams impersonation, enabling malware, data theft.
Mandiant Apr 23
How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Google Cloud Blog
UNC6692 uses social engineering via email spamming and Microsoft Teams phishing to deploy a modular malware suite.
Entities Vendor digest: Microsoft
Part of the PlainSec briefing for 2026-04-27
Editions Related stories