Threat actors are shifting away from relying solely on traditional email phishing for initial access. Instead, modern adversaries combine classic email tactics with enterprise collaboration platforms to build a deceptive level of trust.
A recent campaign by the threat group UNC6692 perfectly illustrates this evolution.
By weaponizing Microsoft Teams alongside targeted email attacks, the group executes sophisticated “”clickfix”” scenarios that manufacture an operational crisis to offer a fake security patch.
Recent incident reports highlight this exact trend, revealing that nearly half of all social engineering attacks now involve impersonating internal personnel to establish credibility.
Industry breach data bolsters this statistic, noting that attackers achieve significant success when impersonating IT helpdesk employees.
In a documented attack, UNC6692 initiated their intrusion with a massive email-bombing campaign.
This flooded the target’starget’s inbox, creating immediate administrative friction and user panic. While the victim struggled to manage the overwhelming spam, the attackers actively intervened via Microsoft Teams.
Helpdesk Pushes SNOW Malware
The SNOW malware toolkit operates as a cohesive pipeline that seamlessly enables access and supports post-compromise activities.
Once a user clicks the malicious repair link, they are directed to a fake authentication portal that harvests their credentials.
Further interaction triggers the automatic download of an AutoHotkey script, which bypasses standard user prompts and deploys the first payload.
To maintain persistence, SNOWBELT anchors itself within the operating system using native Windows features and scheduled tasks.
It silently downloads the remaining components of the intrusion suite. Once staged, the tools initiate local network reconnaissance by performing targeted port scans to identify internal lateral movement targets.
SNOWGLAZE establishes a WebSocket tunnel to the attacker’sattacker’s infrastructure, allowing malicious traffic to blend with normal web activity.
With access to backup servers, the actors dump the memory of the Local Security Authority Subsystem Service to capture cleartext credentials and Kerberos tickets.
Using these harvested administrative credentials, the actors execute a Pass-the-Hash attack to move laterally to the Active Directory domain controller.
According to extrahop research, the modular nature of the SNOW campaign demonstrates why security teams require a holistic view of their network.
Because UNC6692 uses legitimate tools such as Microsoft Edge and portable Python, alongside encrypted tunnels, individual endpoint security tools often struggle to detect the active breach.
Relying solely on endpoint data misses the critical lateral movement and network clues left behind during the attack.
| Stage | Activity | Technical details |
|---|---|---|
| Initial lure | Email bombing + Teams impersonation | UNC6692 flooded the victim’s inbox, then contacted the user on Microsoft Teams while posing as IT helpdesk staff. |
| User interaction | Fake repair utility | The victim was directed to a malicious “Mailbox Repair and Sync Utility” link that presented a fake health check and login flow. |
To effectively detect and stop this behavior, organizations need a defense-in-depth strategy backed by network detection and response capabilities.
Defenders should monitor for network behavioral anomalies from the very beginning of an attack. This includes spotting irregular connections, suspicious payload downloads, and hidden tunnels routing through otherwise normal traffic.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.