logo

Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff

ID: ff005d58-c4f7-5a01-be84-fa1fd3ec5e19

STIX ID: report--ff005d58-c4f7-5a01-be84-fa1fd3ec5e19

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Guru Baran

...
...

UNC6692 executed a sophisticated multistage intrusion campaign that leveraged Microsoft Teams impersonation and AWS-hosted phishing pages to deliver a modular malware ecosystem (SNOWBELT, SNOWGLAZE, SNOWBASIN). The attackers harvested credentials, established C2 via Heroku and S3, tunneled traffic, performed lateral movement with PsExec and RDP, dumped LSASS to obtain hashes, used Pass-the-Hash to access domain controllers, and exfiltrated NTDS.dit and registry hives; the report includes IoCs and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.