Crime crew impersonates help desk, abuses Microsoft Teams to steal your data
2026-04-25T19:24:07Z•a2360b64d8288ca1a24e70b37d3aface0e43ab73317684b952d1dfa7967745b5
backdoorcloud-securitydata-leakdata-theftev-chargersfast16firestarteridentity-theftiotmalwaremicrosoft-teamsnpmpasskeysrouterssnow-malwaresocial-engineeringsupply-chainteampcpthreat-intelwindows-admin-center
What happened
A security news roundup highlighting multiple active threats and systemic weaknesses: a crime group is impersonating helpdesk staff via Microsoft Teams and deploying custom ‘Snow’ malware to exfiltrate data; CISA/UK partners disclosed a previously unknown ‘Firestarter’ backdoor found on a US federal network; npm supply‑chain worm activity (with overlap to TeamPCP infections) continues to spread; and high‑profile data exposures surfaced (Carnival emails, 500k Biobank records, alleged French ID agency leak). Other notable items include warnings about China‑linked large proxy networks built from/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- a2360b64d8288ca1a24e70b37d3aface0e43ab73317684b952d1dfa7967745b5
- Enrichment time
- 2026-04-25T19:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.