Tuesday, May 26, 2026
Today's Edition

EveryNews

Stories that matter, signal over noise

Technologies

# No Vulnerabilities Were Exploited: How UNC6692 Breached Corporations Through Chat Trust

Hackers did not breach the servers — they simply wrote in Teams and asked for help. The UNC6692 attack shows that corporate politeness has become the most dangerous entry point into a corporate network.

Tetiana Suchkova-Ladik

By Tetiana Suchkova-Ladik

April 24, 2026 · 3 min read

# No Vulnerabilities Were Exploited: How UNC6692 Breached Corporations Through Chat Trust
Ілюстративне фото: Depositphotos

Google Threat Intelligence Group and Mandiant revealed on April 22 the details of an attack that exploited no technical vulnerabilities. The UNC6692 group did not break into any servers — it convinced employees to open the doors themselves.

First — panic, then — "help"

In late December 2025, targeted companies received a massive email spam attack: employee mailboxes were literally blocked by thousands of messages. While the victim was searching for a way out of the chaos, a message appeared in Microsoft Teams from a "colleague from IT support" — offering to install a patch that would "stop the spam".

A critical detail that is easy to miss: the message came from an external account. Teams allows such contacts by default — and most employees don't pay attention to the "External" label.

"UNC6692 relied on impersonating IT helpdesk employees, convincing victims to accept chat invitations in Teams from an account outside the organization".

— Mandiant researchers JP Glab, Tufail Ahmed, Josh Kelley, and Muhammad Umair

SNOW: not one tool, but a conveyor

Following the link led to a fake "Mailbox Repair and Sync Utility" page — and only in the Microsoft Edge browser (the page forced switching to it via URI scheme). Clicking the "Health Check" button collected credentials and sent them to the attackers' S3 bucket.

Then a modular malware system called SNOW unfolded:

  • SNOWBELT — malicious Chromium browser extension, persistent backdoor channel;
  • SNOWGLAZE — Python tunneler that built an encrypted WebSocket bridge between the victim's network and the attacker's C2 server;
  • SNOWBASIN — persistent backdoor with the ability to execute commands via PowerShell, capture screenshots, and download files.

After establishing a foothold in the system, attackers scanned the internal network for ports 135, 445, and 3389, dumped the LSASS process memory, and extracted NTDS.dit files — essentially a complete Active Directory user database.

77% of victims — senior management

According to researchers, between March 1 and April 1, 2026, approximately 77% of recorded incidents targeted senior executives and senior employees. The logic is simple: they have the broadest access to sensitive systems and the least time to verify each request from "IT".

The tactic of email bombardment followed by "help" via Teams is not new. As TechJuice notes, this approach was previously actively used by affiliates of the Black Basta group, which ceased operations in early 2025. UNC6692 either borrowed the method or inherited it from former members.

Microsoft fixed it — but not everywhere and not automatically

In January 2026, Microsoft rolled out the ability to block external Teams users directly through the Defender portal, consolidating access management in a single Tenant Allow/Block List interface. Previously, administrators had to switch between several control panels.

The problem is that the feature is not enabled automatically: it requires Defender for Office 365 Plan 1 or Plan 2, as well as separate Teams Admin Center configuration. According to Microsoft's estimates, over 320 million people use Teams monthly — and a significant portion of their organizations still haven't changed the default settings.

The UNC6692 attack exploited no technical vulnerabilities — only the fact that Teams is open to external contacts and employees trust messages in a "secure" corporate chat. If your organization still hasn't restricted external requests in Teams and hasn't enabled blocking through Defender, the question is not "can this happen" but — when exactly will that "support technician" arrive?

Related

Latest

Business

EU Against Google: Why the Latest Fine Could Change More Than Previous Ones

# European Regulators Target Google Again — This Time Over Digital Markets Act Violations. What's Behind the Accusations and Why It Matters Beyond the Corporation European regulators have renewed their scrutiny of Google, this time focusing on alleged violations of the Digital Markets Act. The charges underscore Brussels' increasingly aggressive stance on big tech monopolies and what officials say are anticompetitive practices. The accusations center on how Google leverages its dominance across multiple digital services — from search to advertising to mobile platforms — to disadvantage competitors. Regulators claim the company is using its market power in ways that stifle innovation and limit consumer choice. The case carries significance far beyond Google itself. It signals how the EU is attempting to enforce its landmark Digital Markets Act, legislation designed to curb the gatekeeping power of tech giants. A potential penalty could set precedent for how other large technology companies face similar scrutiny. For consumers and smaller tech firms, the outcome could reshape the digital landscape by creating more room for competition. For Google, fines and operational restrictions could fundamentally alter its business model in Europe, the world's most stringent regulatory market. The case also reflects a broader geopolitical divide, with the EU pursuing a regulatory approach that contrasts sharply with the lighter-touch oversight favored in the United States.

May 26, 2026