Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff
ID: ff005d58-c4f7-5a01-be84-fa1fd3ec5e19
STIX ID: report--ff005d58-c4f7-5a01-be84-fa1fd3ec5e19
Feed Name: cybersecurityNews.com
UNC6692 executed a sophisticated multistage intrusion campaign that leveraged Microsoft Teams impersonation and AWS-hosted phishing pages to deliver a modular malware ecosystem (SNOWBELT, SNOWGLAZE, SNOWBASIN). The attackers harvested credentials, established C2 via Heroku and S3, tunneled traffic, performed lateral movement with PsExec and RDP, dumped LSASS to obtain hashes, used Pass-the-Hash to access domain controllers, and exfiltrated NTDS.dit and registry hives; the report includes IoCs and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
