logo

Crime crew impersonates help desk, abuses Microsoft Teams to steal your data

ID: 401aa455-d00f-5b87-8174-93e5ba4b70d1

STIX ID: report--401aa455-d00f-5b87-8174-93e5ba4b70d1

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-25

Date Updated: 2026-05-06

...
...

Google Threat Intelligence observed an active UNC6692 campaign that begins with a large email spam wave and social engineering via Microsoft Teams helpdesk impersonation; victims are lured to a fake "Mailbox Repair Utility" that captures credentials (including double-entry capture) and stages payloads. The attack deploys AutoHotkey scripts, a malicious Chromium extension (SnowBelt) that installs additional components, a Python-based tunneler (SnowGlaze) and a bindshell (SnowBasin) to give attackers persistent access, remote command execution, and data exfiltration to attacker-controlled infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.