UNC6692 Uses MS Teams and Cloud Reputations to Hijack Active Directory
ID: a7135bb9-a094-5fc2-8982-378a27c00dc1
STIX ID: report--a7135bb9-a094-5fc2-8982-378a27c00dc1
Feed Name: securityonline.info
A Google Threat Intelligence Group report details UNC6692’s sophisticated campaign that begins with an “email bomb” and Microsoft Teams helpdesk impersonation to capture credentials via a fake Mailbox Repair Utility, then deploys a coordinated SNOW malware ecosystem (SNOWBELT extension, SNOWGLAZE tunneler, SNOWBASIN bindshell) to establish persistence, tunnel traffic, move laterally (PsExec, RDP, Pass‑The‑Hash), and exfiltrate the Active Directory database while hosting components on trusted cloud platforms to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
