UNC6692 Leverages Teams Phishing and Cloud Malware
Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- UNC6692 launched a multistage intrusion campaign that exploits Microsoft Teams impersonation, custom modular malware, and cloud infrastructure abuse, without any software vulnerability.
- Google Threat Intelligence Group and Mandiant disclosed the campaign on April 22 2026, describing how the group manipulates employee trust in everyday enterprise tools to gain domain‑level access.
- Microsoft Teams was used to send phishing messages posing as IT helpdesk staff after a mass email‑bombing in late December 2025, prompting victims to click a malicious “local patch” link.
- AWS S3 hosted the phishing landing page and the malicious payloads, including an AutoHotkey binary and the SNOWBELT browser extension, which installed silently via a headless Microsoft Edge process.
- SNOWBELT is a malicious Chromium browser extension that establishes persistence via startup shortcuts, scheduled tasks, and a headless Edge process.
- SNOWGLAZE tunnels victim traffic through a WebSocket connection to a Heroku C2 server, enabling the attackers to execute commands via the SNOWBASIN local HTTP server.
Why it matters: Enterprises lose control of their networks as UNC6692 gains domain‑level access and exfiltrates credentials and Active Directory data, while security teams must expand monitoring to cloud egress and browser extensions to counter a “living off the cloud” attack that sidesteps traditional vulnerability‑based defenses.
Ask SkimNews



