Your inbox just got bombed with thousands of spam emails. A minute later, "IT" messages you on Microsoft Teams to help fix it. That's the trap. Google's Mandiant team just published the breakdown. They're calling the group UNC6692, and they've been running this playbook against companies since December 2025: email-bomb the target, pose as IT helpdesk over Microsoft Teams via outside chat invites, then get the victim to run a fake patch called "Mailbox Repair and Sync Utility." That patch silently installs SNOWBELT — a malicious Chromium browser extension on Edge — which pulls in SNOWGLAZE (a tunneler that gives the attackers a quiet pipe into the corporate network) and SNOWBASIN (a full backdoor with screenshots and remote command execution). Most of the targets so far have been senior employees, because their access puts the attacker much closer to the file servers, domain controllers, and credentials they actually want. Sources: https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware https://www.bleepingcomputer.com/news/security/threat-actor-uses-microsoft-teams-to-deploy-new-snow-malware/ More on cybersecurity, privacy, scams, and homelab on Hake Hardware. New shorts every weekday.

New VS Code Zero-Day Steals GitHub Tokens in One Click
1.5K views

Microsoft Backs Down on Threats Against Zero-Day Researcher
6.4K views

CIFSwitch Linux Kernel Bug: Any Logged-In User Gets Root
2.3K views

BusPatrol Wants 40,000 School Buses to Be Police Plate Trackers
4.2K views

How the Mirai Trio Avoided Prison (Part 6 of 6)
1.7K views

How the FBI Tracked Down the Mirai Trio (Part 5 of 6)
1.6K views