logo

Threat actor uses Microsoft Teams to deploy new “Snow” malware

ID: 470c152f-468a-595f-af5c-220acc05f034

STIX ID: report--470c152f-468a-595f-af5c-220acc05f034

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-04-25

Date Updated: 2026-04-25

Author: Bill Toulas

...
...

UNC6692 conducted a targeted campaign using Microsoft Teams social-engineering to trick victims into installing a dropper that deploys the “Snow” toolset—SnowBelt (browser extension/persistence), SnowGlaze (WebSocket/SOCKS tunneler), and SnowBasin (Python backdoor). The actors performed internal reconnaissance, credential theft (LSASS dumps, pass-the-hash), lateral movement to domain controllers, and exfiltrated AD and registry hives, with Mandiant providing IoCs and YARA rules for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.