The Cold Front of Cybercrime: How UNC6692 is Weaponizing Microsoft Teams with 'Snow' Malware
A threat group identified as UNC6692 has been observed utilizing social engineering tactics through Microsoft Teams to compromise enterprise environments. The attack involves the deployment of a custom-built malware suite dubbed 'Snow,' which comprises three primary components: a specialized browser extension, a network tunneler, and a persistent backdoor. By impersonating trusted colleagues or technical support, the actors trick targets into executing malicious files, ultimately gaining unauthorized access to sensitive data and maintaining long-term control over infected systems.