Google Threat Intelligence Group and Mandiant disclosed that a newly tracked threat cluster, UNC6692, breached enterprise networks by posing as IT help desk staff in Microsoft Teams after first overwhelming targets with high-volume spam emails. Victims were persuaded to accept chats from external Teams accounts and visit a fake "Mailbox Repair Utility" or "Mailbox Repair and Sync Utility" page, which harvested credentials with a double-entry trick that intentionally rejected the first password submissions before installing malware. The campaign relied on trusted cloud services including AWS S3 and Heroku for payload delivery, command-and-control, and exfiltration, allowing the activity to blend into normal enterprise traffic without exploiting a software vulnerability.
After initial access, UNC6692 deployed the modular SNOW malware suite, including SNOWBELT for browser-extension persistence and command relay, SNOWGLAZE for tunneling and proxying, and SNOWBASIN for remote command execution, screenshots, and file transfer, alongside AutoHotkey scripts and a portable Python environment. Investigators said the attackers scanned internal networks, used PsExec and RDP to pivot to a backup server, dumped LSASS memory, performed Pass-the-Hash against domain controllers, and used FTK Imager to steal NTDS.dit and registry hives before exfiltrating data through LimeWire. Google said the tradecraft resembles social-engineering operations associated with other criminal actors but found no confirmed overlap, and the campaign appears separate from other recently reported Teams-based help desk impersonation activity.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
In late December 2025, UNC6692 began a multistage social-engineering campaign using high-volume email bombing followed by Microsoft Teams messages impersonating IT help desk staff. Victims were lured to a fake "Mailbox Repair Utility" page that harvested credentials and initiated malware deployment.
Reporting on the campaign said defenders were provided with infrastructure indicators, file hashes, detection queries, and YARA rules tied to UNC6692 and the SNOW malware suite. These technical details were published to support detection and response efforts.
On April 23, 2026, Google Cloud published a detailed report describing how UNC6692 used SNOWBELT, SNOWGLAZE, and SNOWBASIN, along with AutoHotkey scripts and portable Python tooling, to maintain access and move laterally. The report also documented post-compromise actions including reconnaissance, credential theft, and domain controller access.
After initial access, UNC6692 conducted internal reconnaissance, used PsExec and RDP to pivot to a backup server, dumped LSASS memory, and performed Pass-the-Hash to reach domain controllers. The actor then used FTK Imager to extract NTDS.dit and registry hives and exfiltrated the stolen files via LimeWire.
Google Threat Intelligence Group and Mandiant disclosed on April 22, 2026 that they had identified the previously undocumented threat cluster UNC6692. The disclosure described the Teams impersonation tradecraft, the SNOW malware ecosystem, and the campaign's use of legitimate cloud services for delivery, command-and-control, and exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
11 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcetherecord.media
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcecommunity.gurucul.com
Open sourceinfosec.pub
Open sourcethehackernews.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.