UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware
2026-04-24T01:24:12Z•c9b08e4fcc9788fe64208e206821da0b18f0d715c067065aeeb760b324033a6a
APTaspnet-corebackdoorbitwardencanistersprawlcisa-kevcohere-terrarriumcredential-theftdockerioskicsmalwaremicrosoft-teamsnpmphishingprivilege-escalationransomwareremote-code-executionsglangsocial-engineeringsupply-chainwiper
What happened
A broad set of active cyber incidents and high-severity vulnerabilities were reported: UNC6692 is using Microsoft Teams impersonation to deploy a custom SNOW malware suite; Bitwarden CLI (@bitwarden/cli@2026.4.0) and Checkmarx-related artifacts (including malicious bw1.js and compromised KICS Docker images) are part of an ongoing supply-chain campaign; a self‑propagating npm supply‑chain worm (CanisterSprawl) is stealing developer tokens; multiple APTs and malware families (GopherWhisper, Mustang Panda/LOTUSLITE, Harvester/GoGra, Lotus Wiper, SystemBC) continue targeted operations; and several
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c9b08e4fcc9788fe64208e206821da0b18f0d715c067065aeeb760b324033a6a
- Enrichment time
- 2026-04-24T01:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.