Threat Actors Weaponize Teams Messaging to Breach Enterprises

1 min read
Source: CyberSecurityNews
Threat Actors Weaponize Teams Messaging to Breach Enterprises
Photo: CyberSecurityNews
TL;DR

UNC6692 runs a multistage intrusion that begins with mass email bombardment and escalates via impersonation of IT staff in Microsoft Teams, guiding victims to a phishing landing page hosted on AWS S3. The campaign then harvests credentials, deploys a modular malware suite (SNOWBELT), and uses cloud-based C2 and data staging to exfiltrate data and compromise domain controllers, highlighting the need to restrict external Teams access and monitor cloud egress and browser extensions for anomalous activity.

Share this article

Want the full story? Read the original reporting

Read on CyberSecurityNews