Crime crew impersonates help desk, abuses Microsoft Teams to steal your data
ID: e93507be-eff0-5907-af64-3b72f9904cb7
STIX ID: report--e93507be-eff0-5907-af64-3b72f9904cb7
Feed Name: The Register (Security)
UNC6692 ran a late-December 2025 campaign that combined mass email phishing with Microsoft Teams helpdesk impersonation to trick users into authenticating to a fake "Mailbox Repair Utility," capturing credentials and staging files. The attackers deployed an AutoHotkey-based dropper and a malicious Chromium extension called SnowBelt, which fetches a modular malware suite: SnowGlaze (a Python WebSocket tunneler) and SnowBasin (a Python bindshell). This ecosystem provides persistence, authenticated tunneling, remote command execution, screenshot capture and staged data exfiltration to attacker-controlled infrastructure such as Amazon S3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
