logo

UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware

ID: 3ec9f97d-756f-5624-9fa9-20958568a32c

STIX ID: report--3ec9f97d-756f-5624-9fa9-20958568a32c

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Deeba Ahmed

...
...

**Executive summary:** UNC6692 conducted a credential-theft campaign beginning in late December 2025 that used email bombing and a Microsoft Teams helpdesk lure to deliver a credential-stealing landing page and an AutoHotkey loader, then deployed a modular SNOW toolset (SNOWBELT, SNOWGLAZE, SNOWBASIN) to maintain persistence, perform internal reconnaissance, steal credentials from LSASS, use Pass-the-Hash for lateral movement, extract NTDS.dit and registry hives, and exfiltrate sensitive Active Directory data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.