logo

Hackers Exploit Microsoft Teams to Breach Organizations While Posing as IT Helpdesk Staff

ID: 7d08a8f0-2200-542b-9b03-78b14ca272a0

STIX ID: report--7d08a8f0-2200-542b-9b03-78b14ca272a0

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-24

Date Updated: 2026-04-25

Author: AnuPriya

...
...

UNC6692 is conducting targeted enterprise intrusions by abusing Microsoft Teams social engineering to trick users into a fake Mailbox Repair Utility that captures credentials, then deploying a modular malware suite called 'SNOW' (SNOWBELT, SNOWGLAZE, SNOWBASIN) to maintain persistence, create encrypted tunnels, execute commands, dump LSASS for credential theft, perform Pass-the-Hash attacks against domain controllers, and exfiltrate Active Directory and other data to attacker-controlled cloud endpoints; multiple IoCs are provided for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.