logo

UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware

ID: 70a64dbe-a74a-5990-8224-405d9f23bd4a

STIX ID: report--70a64dbe-a74a-5990-8224-405d9f23bd4a

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-04-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Mandiant and other vendors observed UNC6692 using Microsoft Teams helpdesk impersonation combined with an email-bombing campaign to socially engineer primarily senior executives into installing a malicious payload via a phishing page that downloads AutoHotkey scripts and a malicious Edge extension (SNOWBELT); this deploys a modular toolkit including SNOWGLAZE (Python tunneler) and SNOWBASIN (persistent backdoor) enabling lateral movement, credential theft (Pass‑The‑Hash), remote execution, and exfiltration while abusing cloud services for payload delivery and C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.