logo

Crime crew impersonates help desk, abuses Microsoft Teams to steal your data

ID: e93507be-eff0-5907-af64-3b72f9904cb7

STIX ID: report--e93507be-eff0-5907-af64-3b72f9904cb7

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-25

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

UNC6692 ran a late-December 2025 campaign that combined mass email phishing with Microsoft Teams helpdesk impersonation to trick users into authenticating to a fake "Mailbox Repair Utility," capturing credentials and staging files. The attackers deployed an AutoHotkey-based dropper and a malicious Chromium extension called SnowBelt, which fetches a modular malware suite: SnowGlaze (a Python WebSocket tunneler) and SnowBasin (a Python bindshell). This ecosystem provides persistence, authenticated tunneling, remote command execution, screenshot capture and staged data exfiltration to attacker-controlled infrastructure such as Amazon S3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.