#unc6692
📢⚠️ UNC6692 hackers exploit #MicrosoftTeams with fake IT alerts to deploy SNOW malware, steal credentials, and breach corporate networks in advanced attacks.

Read: hackread.com/unc6692-hack...

#CyberSecurity #Microsoft #MSTeams #UNC6692 #Malware
UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware
UNC6692 hackers exploit Microsoft Teams with fake IT alerts to deploy SNOW malware, steal credentials, and breach corporate networks in advanced attacks.
hackread.com
April 27, 2026 at 12:26 PM
📢⚠️ UNC6692 hackers exploit #MicrosoftTeams with fake IT alerts to deploy SNOW malware, steal credentials, and breach corporate networks in advanced attacks.

Read: hackread.com/unc6692-hack...

#CyberSecurity #Microsoft #MSTeams #UNC6692 #Malware
UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware
UNC6692 hackers exploit Microsoft Teams with fake IT alerts to deploy SNOW malware, steal credentials, and breach corporate networks in advanced attacks.
hackread.com
April 27, 2026 at 12:28 PM
A threat group tracked as UNC6692 uses social engineering to deploy a new "Snow" malware set that includes a browser extension, a tunneler, and a backdoor.
Threat actor uses Microsoft Teams to deploy new “Snow” malware
A threat group tracked as UNC6692 uses social engineering to deploy a new "Snow" malware set that includes a browser extension, a tunneler, and a backdoor.
www.bleepingcomputer.com
April 25, 2026 at 3:09 PM
UNC6692 Uses Email Bombing, Social Engineering to Deploy 'Snow' Malware - SecurityWeek www.securityweek.com/unc6692-uses...
UNC6692 Uses Email Bombing, Social Engineering to Deploy 'Snow' Malware
UNC6692 relies on email bombing and social engineering to infect victims with Snow malware: Snowbelt, Snowglaze, and Snowbasin.
www.securityweek.com
April 28, 2026 at 5:53 AM
-NCSC announces SilentGlass device
-Russia revokes almost 2,000 telco licenses
-Two privacy bills arrive in Congress
-CyberCom carried out 8k operations last year
-100+ countries have spyware now
-HexDex arrested in France
-US charges scam compound operators
-UNC6692 behind Teams social eng attacks
April 24, 2026 at 8:13 AM
Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff
Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff
A newly identified threat group, UNC6692, has been caught running a sophisticated multistage intrusion campaign that uses Microsoft Teams impersonation , a custom modular malware suite, and cloud infrastructure abuse to deeply penetrate enterprise networks, all without exploiting a single software vulnerability. Google Threat Intelligence Group (GTIG) and Mandiant researchers disclosed the campaign on April 22, 2026, revealing how UNC6692 systematically manipulates employee trust in everyday enterprise tools to gain full domain-level access. In late December 2025, UNC6692 launched a mass email bombing campaign against its targets, deliberately flooding inboxes to create a sense of urgency and confusion. With victims overwhelmed and distracted, the threat actor delivered the critical blow by sending a phishing message directly over Microsoft Teams, with the attacker posing as an IT helpdesk employee offering assistance with the email volume. This technique is not a zero-day exploit or a software flaw. As Microsoft noted in its own April 2026 advisory, the campaign abuses legitimate external collaboration features in Teams, with attackers convincing users to override multiple, clearly presented security warnings. Victims accepted the Teams chat invitation from an account outside their organization, a seemingly minor action with catastrophic consequences. Infection Chain: From Teams Chat to Full Compromise Once in contact, the attacker directed the victim to click a link to install a “local patch” that purportedly prevents email spamming. The link led to a convincing phishing landing page masquerading as a “Mailbox Repair and Sync Utility v2.1.5”, hosted on an attacker-controlled AWS S3 bucket, Google said . The page enforced a multi-phase attack pipeline: Phase 1 – Environment Gating: A gatekeeper script checked the URL for a mandatory ?email= parameter and forced victims onto Microsoft Edge via the microsoft-edge: URI scheme, ensuring exploits would be most effective. Phase 2 – Credential Harvesting: A fake “Health Check” triggered an authentication prompt that rejected the first two password attempts by design — a psychological “double-entry” trick to ensure typo-free credential capture before exfiltrating them to an S3 bucket. Phase 3 – Distraction Sequence: A fake progress bar displayed messages like “Parsing configuration data” and “Checking mailbox integrity” to mask real-time data exfiltration in the background. Phase 4 – Malware Staging: While the progress bar ran, an AutoHotkey binary and script were downloaded from AWS S3 and automatically executed upon landing in the same directory — installing SNOWBELT, a malicious Chromium browser extension masquerading as “MS Heartbeat” or “System Heartbeat”. The SNOW Malware Ecosystem UNC6692’s toolset, dubbed the SNOW ecosystem, is a coordinated three-component modular framework: Component Type Role SNOWBELT JavaScript browser extension Initial foothold; intercepts and relays C2 commands; uses DGA-based S3 URLs for C2 SNOWGLAZE Python-based WebSocket tunneler Routes TCP traffic through the victim via a SOCKS proxy to a Heroku C2 server SNOWBASIN Python local HTTP server (port 8000) Executes shell commands, captures screenshots, exfiltrates files SNOWBELT maintained persistence through a Windows Startup folder shortcut, two scheduled tasks, and a headless Microsoft Edge process silently loading the extension. SNOWGLAZE masked malicious traffic by wrapping data in Base64-encoded JSON objects over WebSockets, making it appear as standard encrypted web traffic. After establishing initial access, UNC6692 executed a Python script via SNOWBASIN to scan the local network for open ports 135, 445, and 3389. Using PsExec sessions routed through the SNOWGLAZE tunnel, the attackers enumerated local administrator accounts and initiated an RDP session to a backup server. On the backup server, the threat actor used Windows Task Manager to dump the LSASS process memory, capturing password hashes, and exfiltrated the dump via LimeWire. With hashes in hand and safely off the network, the attacker performed offline credential extraction, then used Pass-the-Hash to authenticate directly to domain controllers without ever needing plaintext passwords. On the domain controller, the attacker downloaded FTK Imager, mounted the local drive, and extracted the Active Directory database (NTDS.dit), SAM, SYSTEM, and SECURITY registry hives, the crown jewels of any Windows enterprise environment. These were also exfiltrated via LimeWire. EDR telemetry captured the attacker taking targeted screenshots of active FTK Imager and Edge windows, confirming mission completion. A defining characteristic of the UNC6692 campaign is its systematic abuse of legitimate cloud services for every stage of the attack payload delivery, credential exfiltration, C2 infrastructure, and data staging, all of which relied on trusted platforms like AWS S3 and Heroku. This “living off the cloud” strategy allows malicious traffic to blend into high volumes of encrypted, reputably sourced web traffic, rendering domain reputation filters and IP-based blocklists largely ineffective. Defenders must expand visibility beyond traditional process monitoring to include browser extension activity, unauthorized cloud egress traffic, and headless browser processes. Critically, organizations should restrict or closely monitor Microsoft Teams external access settings to prevent unknown tenants from initiating chat sessions with employees. As UNC6692 demonstrates, the weakest link in enterprise security is not always a misconfigured server it is an employee who trusts a Teams message from someone claiming to be IT. Indicators of Compromise (IOCs) Phishing URL Pattern: https://service-page-[ID]-outlook.s3.us-west-2.amazonaws.com/update.html?email= C2 Server: wss://sad4w7h913-b4a57f9c36eb[.]herokuapp[.]com:443/ws SNOWBELT C2 URL Pattern: https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws[.]com SNOWBELT VAPID Key: BJkWCT45mL0uvV3AssRaq9Gn7iE2N7Lx38ZmWDFCjwhz0zv0QSVhKuZBLTTgAijB12cgzMzqyiJZr5tokRzSJu0 Masquerading Files: RegSrvc.exe (AutoHotKey binary), Protected.ahk , SysEvents (SNOWBELT extension directory). Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff appeared first on Cyber Security News .
cybersecuritynews.com
April 24, 2026 at 2:25 AM
Great summary. UNC6692 shows why Teams security is now as vital as email. Remind users to verify any "helpdesk" chat through a second channel to protect your AD. Stay safe! 🛡️
April 27, 2026 at 12:08 PM
UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware

UNC6692 hackers exploit Microsoft Teams with fake IT alerts to deploy SNOW malware, steal credentials, and breach corporate networks in advanced attacks.
#hackernews #microsoft #news
UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware
UNC6692 hackers exploit Microsoft Teams with fake IT alerts to deploy SNOW malware, steal credentials, and breach corporate networks in advanced attacks.
hackread.com
April 28, 2026 at 6:40 AM
UNC6692 targeted 77% senior employees between March 1–April 1, 2026, via Teams impersonation, enabling malware, data theft.
UNC6692 Impersonates IT Help Desk via Microsoft Teams to Deploy SNOW Malware
thehackernews.com
April 25, 2026 at 6:18 AM
UNC6692 executes a multistage intrusion using social engineering via email and Microsoft Teams, AWS S3 abuse, and custom malware like SNOWBELT to steal credentials and move laterally with pass-the-hash. #UNC6692 #CloudAbuse #USA
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
Google Threat Intelligence Group and Mandiant disclosed a multistage intrusion campaign by UNC6692 that combines persistent social engineering, abuse of AWS S3, and custom modular malware to steal credentials. The attackers used AutoHotkey stagers and a malicious Chromium extension (SNOWBELT) to deploy tools like Snowglaze and Snowbasin, extract LSASS memory via LimeWire, and move laterally with pass-the-hash. #UNC6692 #SNOWBELT
www.hendryadrian.com
April 28, 2026 at 3:45 AM
🚨Threat group UNC6692 uses email bombing + fake IT helpdesk calls via Microsoft Teams to deploy “Snow” malware. Victims install a fake patch that drops a malicious extension for data theft after credential compromise. #CyberSecurity #Infosec #Malware #Snow #Microsoft
April 27, 2026 at 9:37 AM
Hacker tricksen Teams-Nutzer mit Spam aus
https://glm.io/208048?n #microsoftteams #malware #snow #blackhats #unc6692
April 28, 2026 at 12:34 PM
UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware
UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware
A newly identified threat group tracked as UNC6692 is hijacking Microsoft Teams to install a custom malware suite called SNOW. The campaign relies almost entirely on social engineering, which makes it dangerous because it feels routine to the people who fall for it. Attackers pose as IT helpdesk staff, exploiting a target’s trust in familiar collaboration tools to walk victims through handing over control of their machine. The attack begins with a wave of spam emails sent to a target’s inbox, creating chaos and urgency. Once the victim is overwhelmed, the same attacker reaches out through Microsoft Teams, posing as an IT support agent offering to fix the problem they caused. This staged setup convinces users to trust a stranger who appears to be solving an issue rather than creating one. Analysts at ExtraHOP said in a report shared with Cyber Security News (CSN) identified and detailed how this coordinated chain plays out from first contact to full network compromise. Once a victim accepts the fake Teams invitation, the attacker sends a link claiming to install a patch that stops the spam. Clicking it downloads a renamed AutoHotkey binary along with a script sharing the same file name, pulled from an attacker controlled cloud bucket. That download becomes the first stage of the SNOW malware ecosystem, a modular toolkit built to support activity after the breach. It includes a malicious browser extension, a Python based tunneling tool , and a lightweight local backdoor, each handling a part of the intrusion. Together they let the attacker maintain a presence long after the phishing message is forgotten. Once inside, UNC6692 does not rush. The group moves carefully through compromised systems, harvesting credentials, exploring internal networks, and expanding access before doing anything that might trigger alarms. UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation The impersonation trick is simple but effective because it mirrors real corporate support interactions. After the spam flood, the attacker contacts the victim through a Teams chat request from an account outside the organization, posing as a helpful colleague. Many users accept external chat invitations without a second thought, especially when the message promises to fix a problem they already face. Victims are directed to a phishing page disguised as a mailbox repair and sync utility, complete with a professional interface and a health check button. That button triggers a login prompt, and the page asks for credentials multiple times under the guise of verification, which helps the stolen data hold up if checked later. The captured logins are then quietly sent to a cloud location controlled by the attacker. This is the entry point for everything that follows. Once the AutoHotkey script runs, it performs reconnaissance and installs SNOWBELT, a rogue browser extension, by launching Microsoft Edge in a hidden mode using command line settings that skip normal installation checks. Inside the SNOW Malware Toolkit SNOW is not a single piece of malware but a layered pipeline built for persistence and stealth. SNOWBELT operates within the browser and can survive restarts, while a Python based tunneling utility supports SOCKS5 style traffic to route commands through the compromised host, blending in with normal web activity. A separate local HTTP backdoor gives the attacker a direct channel for issuing commands and pulling data without relying on infrastructure that might get flagged. The toolkit also supports screenshot capture, file exfiltration, and session termination, giving operators control over how long they stay hidden. Because the traffic moves through legitimate cloud services and familiar Windows features, standard network monitoring often misses it entirely. Security teams should watch for unusual browser extension installations, scheduled tasks that launch Edge in headless mode, and unexpected outbound connections to unfamiliar endpoints. Organizations are advised to restrict external chat permissions on Microsoft Teams to approved contacts and train employees to treat unsolicited helpdesk outreach with caution. Blocking unapproved file sharing platforms and requiring verification before remote assistance can reduce exposure to this kind of intrusion. This campaign shows how attackers favor patience and disguise over brute force, turning ordinary workplace habits into an opening for deep compromise. Indicators of Compromise (IoCs):- Type Indicator Description File AutoHotkey binary (renamed, filename matches accompanying script) Delivered from attacker controlled AWS S3 bucket; initiates SNOWBELT installation  File AutoHotkey script (same filename as binary) Executes automatically upon download, bypasses standard user prompts to deploy SNOWBELT  File 7ZIP Imager tool Used by threat actor to compress and exfiltrate the entire Active Directory database (NTDS.dit)  Tool SNOWBELT Malicious Chromium browser extension component of the SNOW malware ecosystem, installed via headless Microsoft Edge  Tool SNOWGLAZE Python based tunneling utility supporting SOCKS5 traffic to conceal command and control communications  Tool SNOWBASIN Local HTTP backdoor providing a direct command channel on the compromised host  Infrastructure Amazon Web Services S3 bucket Attacker controlled storage used to host and serve the initial malicious AutoHotkey payload  Infrastructure Cloud storage exfiltration endpoint Destination used by SNOWGLAZE to move harvested NTDS.dit data and credentials off the victim network  Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Prevent critical incidents and financial loss with stronger proactive defense.  Integrate a live threat feed from 15K SOC Teams . The post UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware appeared first on Cyber Security News .
cybersecuritynews.com
July 9, 2026 at 2:09 PM
UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
April 24, 2026 at 5:30 PM
Hackers Are Now Using Microsoft Teams to Breach Company Networks Without Using Any Exploits propakistani.pk/2026/04/26/h...
Hackers Are Now Using Microsoft Teams to Breach Company Networks Without Using Any Exploits
A newly identified threat group, UNC6692, has been caught running a sophisticated cyberattack campaign that uses Microsoft Teams impersonation, fake IT
propakistani.pk
April 27, 2026 at 6:39 AM
Snow Flurries:UNC6692がソーシャルエンジニアリングを用いてカスタムマルウェアスイートを展開した方法
#CybersecurityNews
cloud.google.com/blog/topics/...
How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite | Google Cloud Blog
UNC6692 uses social engineering via email spamming and Microsoft Teams phishing to deploy a modular malware suite.
cloud.google.com
April 28, 2026 at 8:39 AM
--An Indian media giant was hacked by alleged Afghan group,
--Coupang breach has triggered a corporate crisis,
--Customer data for Canada Life compromised in breach,
--UNC6692 is running an intrusion campaign that impersonates Teams, 3/4
April 24, 2026 at 2:30 PM
Threat actor uses Microsoft Teams to deploy new “Snow” malware
Threat actor uses Microsoft Teams to deploy new “Snow” malware
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named 'Snow' which includes a browser extension, a tunneler, and a backdoor.
www.bleepingcomputer.com
April 25, 2026 at 5:31 PM