logo

UNC6692 Uses MS Teams and Cloud Reputations to Hijack Active Directory

ID: a7135bb9-a094-5fc2-8982-378a27c00dc1

STIX ID: report--a7135bb9-a094-5fc2-8982-378a27c00dc1

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-27

Date Updated: 2026-05-05

Author: Ddos

...
...

A Google Threat Intelligence Group report details UNC6692’s sophisticated campaign that begins with an “email bomb” and Microsoft Teams helpdesk impersonation to capture credentials via a fake Mailbox Repair Utility, then deploys a coordinated SNOW malware ecosystem (SNOWBELT extension, SNOWGLAZE tunneler, SNOWBASIN bindshell) to establish persistence, tunnel traffic, move laterally (PsExec, RDP, Pass‑The‑Hash), and exfiltrate the Active Directory database while hosting components on trusted cloud platforms to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.