https://glm.io/208048?n #MicrosoftTeams #Malware #Snow #Blackhats #UNC6692
📢⚠️ UNC6692 hackers exploit #MicrosoftTeams with fake IT alerts to deploy SNOW malware, steal credentials, and breach corporate networks in advanced attacks.
Read: https://hackread.com/unc6692-hackers-microsoft-teams-snow-malware/
UNC6692 usa Microsoft Teams per distribuire SNOW: email bombing, impersonazione helpdesk e compromissione del dominio Active Directory
Google Threat Intelligence Group e Mandiant hanno documentato UNC6692, un gruppo che usa email bombing e impersonazione del supporto IT su Microsoft Teams per distribuire SNOW, una suite malware modulare composta da SNOWBELT, SNOWGLAZE e SNOWBASIN. Nessun exploit: pura ingegneria sociale che porta al dump di LSASS e alla compromissione del dominio Active Directory.The threat actor cluster UNC6692 is bypassing traditional email filters by impersonating IT help desk personnel directly on Microsoft Teams.
The attack starts with "email bombing" to overwhelm the victim, followed by a Teams message offering "support" that tricks users into installing a malicious browser extension called SNOWBELT.
A sophisticated new threat actor, UNC6692, is actively exploiting Microsoft Teams to deploy 'Snow' malware, proving internal communication platforms are not immune. This campaign leverages social engineering, impersonating IT Help Desk to bypass email filters and target senior leadership. The modular 'Snow' malware, including components like SNOWBELT and SNOWGLAZE, aims for deep system…
#cybersecurity #unc6692 #microsoftteams
🤖 This post was AI-generated.
Microsoft Teams Used to Deploy Sophisticated Snow Malware
Cyber attackers have cleverly used Microsoft Teams to deploy a sophisticated malware suite, dubbed Snow, by tricking victims into installing a fake anti-spam patch that ultimately led to prolonged access, credential theft, and domain compromise. They started by creating a sense of urgency through email bombing, then followed up with a…
#MicrosoftTeams #SnowMalware #Unc6692 #MalwareOperations #SocialEngineering
Threat Actors Exploit Microsoft Teams for SNOW Malware Deployment
Cyber attackers are exploiting Microsoft Teams by impersonating IT helpdesk staff, tricking victims into accepting chats from unfamiliar accounts and deploying SNOW malware. They start by flooding inboxes with urgent emails, then pose as IT support over Teams, offering to fix the problem.
#SocialEngineering #MicrosoftTeams #SnowMalware #Unc6692 #MalwareDeployment
UNC6692 Exposes Custom Malware Suite via Social Engineering
In a clever social engineering ploy, UNC6692 launched a massive email campaign in late December 2025, flooding targets with messages to create a sense of urgency and distraction, before following up with a convincing Microsoft Teams message that pushed a malicious link. The attackers then cleverly disguised their malware as…
#SocialEngineering #Unc6692 #GoogleThreatIntelligenceGroup #MicrosoftTeams #AmazonS3