[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKH4CCImgqvFVPVL4k1jVRTnYx0tS_d3ylRTkkePBQxo":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"6ca31f66-a841-46d8-86ad-47a0d745959d","social-engineering-via-microsoft-teams-leads-to-multi-stage-malware-attack","22c81b8b-7801-47ec-b98d-2cb3c9d984a5","Social Engineering via Microsoft Teams Leads to Multi-Stage Malware Attack","UNC6692 successfully exploited user trust by impersonating IT helpdesk staff through Microsoft Teams, combining email bombing with social engineering to overwhelm and deceive victims. Users were tricked into installing malware that provided persistent access through browser extensions, network tunneling capabilities, and backdoor access. The attack demonstrates how threat actors leverage trusted communication platforms and social engineering to bypass technical security controls. Once inside, the attackers used legitimate administrative tools and techniques to move laterally, steal credentials, and exfiltrate sensitive data including Active Directory databases.","**Immediate actions:**\n- Implement strict verification procedures for IT helpdesk requests through official channels only\n- Configure Microsoft Teams to restrict external communications and file sharing\n- Deploy endpoint detection and response (EDR) solutions to monitor for suspicious browser extensions and malware\n\n**Long-term improvements:**\n- Establish comprehensive security awareness training focusing on social engineering tactics via collaboration platforms\n- Implement privileged access management (PAM) solutions to control administrative credentials\n- Deploy network segmentation to limit lateral movement and protect critical assets like domain controllers\n\n**Detection measures:**\n- Enable advanced logging for Teams communications and file transfers\n- Monitor for LSASS process access and credential dumping activities\n- Implement behavioral analytics to detect unusual network tunneling and data exfiltration patterns",[12,13,14,15,16,17,18],"CIS Control 14","CIS Control 6","CIS Control 13","NIST AC-2","NIST AC-6","NIST AT-2","NIST SI-4","published","2026-04-26T00:10:03.193161+00:00","2026-04-26T00:10:03.061+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fthreat-actor-uses-microsoft-teams-to-deploy-new-snow-malware\u002F","threat-actor-uses-microsoft-teams-to-deploy-new-snow-malware-f35dcb","Threat actor uses Microsoft Teams to deploy new “Snow” malware",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":34,"name":35,"slug":36,"description":37,"color":38},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[40],{"id":41,"date":42,"edition":43,"title":44,"audio_url":45},"cc7e86b8-009e-4407-936d-cf91a70bddf7","2026-04-26","morning","ThreatNoir Weekend Brief — April 26","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-26\u002Fthreatnoir-morning-brief-2026-04-26.mp3"]