Hackers Impersonate Microsoft Teams in UNC6692 Attacks
Microsoft Teams impersonation by UNC6692 used email bombing and phishing to steal credentials and deploy SNOWBELT, researchers said on April 22, 2026.
Jason Kwon ·

Microsoft Teams impersonation is being used in a newly detailed enterprise intrusion campaign tied to a threat group tracked as UNC6692, according to researchers from Google Threat Intelligence Group (GTIG) and Mandiant. The researchers said on April 22, 2026, that the operation uses a multi-stage approach designed to turn routine workplace communications into an entry point for network compromise.
They described the campaign as relying on social engineering rather than exploiting software vulnerabilities.
Researchers said the activity began with a mass email bombing wave in late December 2025 aimed at target organizations. After inboxes were flooded, UNC6692 shifted to direct outreach inside Microsoft Teams, where the actor impersonated IT helpdesk staff and offered to help address the email volume. Victims were persuaded to accept chat invitations from external accounts and then follow instructions presented as a practical fix.
According to GTIG and Mandiant, the Teams messages directed recipients to click a link to install what was presented as a “local patch” intended to stop the spamming. The link led to a phishing landing page hosted on an attacker-controlled AWS S3 bucket. That page was made to look like a legitimate tool labeled “Mailbox Repair and Sync Utility v2.1.5,” and it served as the front door to a staged attack pipeline.
The researchers said the landing page enforced multiple phases, including environment gating and credential harvesting through a fake authentication prompt. They also described a distraction sequence intended to conceal real-time data exfiltration while the victim interacted with the page. After those steps, an AutoHotkey binary and script were downloaded and executed on the victim system, moving the intrusion from initial access into deeper persistence and control.
GTIG and Mandiant reported that the AutoHotkey components installed SNOWBELT, a malicious Chromium browser extension. SNOWBELT was described as part of UNC6692’s broader SNOW malware ecosystem, which also includes SNOWGLAZE and SNOWBASIN. The researchers said these components support command and control, tunneling, and data exfiltration, and that the overall campaign is structured to culminate in full domain-level access.
Uncertainties remain in the public description of the operation, including which organizations were targeted and how widely the campaign has spread, as the researchers’ disclosure focused on the intrusion chain and tooling. The reporting nonetheless highlights how attackers can use familiar enterprise platforms and trusted internal roles to drive high-impact outcomes without relying on a software flaw.