UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware

2026-04-24T07:24:13Zde2994e6531003d94a60cd2c2e553ee3b08eafed190eeb8aae973dbcb3e55256
CISA-KEVGoGraGopherWhisperHarvesterLOTUSLITELotus-WiperSNOW-malwareSystemBCThe-Gentlemen-ransomwareUNC6692active-exploitationbitwardencanistersprawlcheckmarxcredential-theftkics-dockernpm-wormsoftware-supply-chainsupply-chainvulnerability-disclosure

What happened

A batch of high-impact incidents and disclosures: multiple supply‑chain compromises (Checkmarx campaign affecting @bitwarden/cli@2026.4.0, malicious checkmarx/kics Docker images, npm worm/CanisterSprawl) and active abuse of developer tokens; several APT/malware operations (UNC6692 using Microsoft Teams to deploy SNOW, GopherWhisper Go backdoors in Mongolian government, Mustang Panda LOTUSLITE, Harvester deploying GoGra via Microsoft Graph, Lotus Wiper destructive attacks, SystemBC botnet tied to The Gentlemen ransomware); and critical/actively exploited vulnerabilities and patches (Cohere Terr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
de2994e6531003d94a60cd2c2e553ee3b08eafed190eeb8aae973dbcb3e55256
Enrichment time
2026-04-24T07:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.