UNC6692 Hackers Exploit Microsoft Teams to Deploy SNOW Malware
ID: 3ec9f97d-756f-5624-9fa9-20958568a32c
STIX ID: report--3ec9f97d-756f-5624-9fa9-20958568a32c
Feed Name: HackRead
**Executive summary:** UNC6692 conducted a credential-theft campaign beginning in late December 2025 that used email bombing and a Microsoft Teams helpdesk lure to deliver a credential-stealing landing page and an AutoHotkey loader, then deployed a modular SNOW toolset (SNOWBELT, SNOWGLAZE, SNOWBASIN) to maintain persistence, perform internal reconnaissance, steal credentials from LSASS, use Pass-the-Hash for lateral movement, extract NTDS.dit and registry hives, and exfiltrate sensitive Active Directory data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
