Crime crew impersonates help desk, abuses Microsoft Teams to steal your data
ID: 401aa455-d00f-5b87-8174-93e5ba4b70d1
STIX ID: report--401aa455-d00f-5b87-8174-93e5ba4b70d1
Feed Name: The Register (Security)
Google Threat Intelligence observed an active UNC6692 campaign that begins with a large email spam wave and social engineering via Microsoft Teams helpdesk impersonation; victims are lured to a fake "Mailbox Repair Utility" that captures credentials (including double-entry capture) and stages payloads. The attack deploys AutoHotkey scripts, a malicious Chromium extension (SnowBelt) that installs additional components, a Python-based tunneler (SnowGlaze) and a bindshell (SnowBasin) to give attackers persistent access, remote command execution, and data exfiltration to attacker-controlled infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
