UNC6692 poses as IT helpdesk in Teams to install malware

The actor tracked as UNC6692 has run a targeted campaign that gains its first foothold by impersonating internal IT support in Microsoft Teams. Victims are primed with a flood of email spam so that a message from "IT" feels natural. Over Teams the user is talked into installing a fake update that deploys the SNOW malware family, a modular toolkit that establishes persistence, provides remote access and enables further compromise across the network.

What this means for your organisation

The attack sidesteps technical controls by going after the trust between staff and the IT department. No vulnerability is exploited; the user does what she is asked, and does it faster because her inbox has just collapsed. That makes Teams an attack surface on a par with email. Organisations that have never defined how genuine support makes contact leave staff with no way to tell the difference.

Berigo recommends

  • Limit who outside the organisation can start Teams conversations with staff, and switch off external chat where there is no real need.
  • Establish and communicate one fixed way that IT support makes contact, so anything else can be declined without awkwardness.
  • Give staff a fast, simple channel for reporting suspicious approaches, particularly when they come under pressure.
  • Require IT approval before remote control tools can run on client machines.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch