惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
B
Blog
博客园_首页
云风的 BLOG
云风的 BLOG
S
SegmentFault 最新的问题
罗磊的独立博客
Jina AI
Jina AI
C
Check Point Blog
Martin Fowler
Martin Fowler
J
Java Code Geeks
博客园 - 司徒正美
美团技术团队
MongoDB | Blog
MongoDB | Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
U
Unit 42
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
小众软件
小众软件

PYMNTS.com

Crypto Payments Are Back. Will Merchants Actually Care This Time? B2B’s New Battlefield Is Everything Before the Button Amazon Targets the GLP-1 Gap Big Pharma Left Open LendingClub Signals Expanded Capabilities With Happen Bank Rebrand Congress Moves to Give FinTechs Direct Fed Payment Access Microsoft Tests Mythos to Identify and Mitigate Vulnerabilities United Airlines Hikes Fares as Fuel Costs Surge OpenAI Images 2.0 Is a Real Leap With a Real Price Tag Morgan Stanley Says Gaming Could Score $22 Billion With AI FTC Shuts Down Alleged Healthcare Fraud Scheme Sam’s Club Offers eCommerce Shoppers Hour-or-Less Deliveries FinTechs Cut Staff as AI and Margins Redefine Growth JPMorganChase Extends Critical Industries Investment Program to Continental Europe OpenAI Lands $75 Million Investment From Robinhood Ventures House Bill Would Reduce Small Lenders’ Reporting Requirements Coinbase Lists tGBP to Expand Locally-Denominated Stablecoin Access BNY Names New Head for Payments/Trade Client Platform KnowBe4 Automates Global Cash Flow Via Flywire Partnership Treasury Calls for Programmable Financial Enforcement Across Crypto DeepSeek Seeks $20 Billion Valuation as Tech Giants Weigh Investment Google Accelerates Agentic AI Shift With New Enterprise Platform OpenAI Begins Briefing Governments on Cybersecurity Capabilities DeFi Security Suffers New Blow With $3 Million Volo Exploit Uninvited Users Access Anthropic’s Mythos AI Model Block and Uber Expand Partnership Across Several Global Markets OpenAI Pledges $1.5 Billion to PE Enterprise AI Project Podcast: Inside the $9 Billion DeFi Hack That’s Shaking Crypto’s Foundations Synchrony CFO Flags Momentum in Spending and Credit Banks Risk Slowing the Emerging Middle Market Firms Driving Growth Paysafe Expands Digital Wallet Availability Across 18 European Markets
Hackers Pose as Microsoft Support to Breach Corporate Def...
PYMNTS · 2026-04-29 · via PYMNTS.com

By  |  April 28, 2026

 | 

cyberattacks, hackers, cybersecurity

Hackers have begun impersonating Microsoft Teams help desk workers to dupe victims into installing data-stealing malware.

That’s according to findings from Mandiant, the cybersecurity company owned by Google, flagged in a report Monday (April 27) from The Record.

The campaign is from a threat group called UNC6692, and combines email flooding, phishing messages and malicious browser extensions to breach corporate systems, Mandiant said.

“As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization,” Mandiant said on its blog.

“The UNC6692 campaign demonstrates an interesting evolution in tactics, particularly the use of social engineering, custom malware, and a malicious browser extension, playing on the victim’s inherent trust in several different enterprise software providers.”

According to Mandiant, the operation starts with a surge of emails designed to overwhelm the target inbox. From there, the attacker will make contact via Microsoft Teams using an account outside the victim’s organization, pretending to be an IT support worker and offering to help fix the email disruption.

Advertisement: Scroll to Continue

The hacker will tell the victim to install what seems to be a “patch” designed to stop the spam, but is actually a gateway to installing a malicious browser extension called SnowBelt. SnowBelt, Mandiant says, gives attackers a back entrance to hold on to access to corporate accounts and move within their systems without needing to repeatedly authenticate their presence.

These attacks are part of a larger trend PYMNTS covered last week, one that sees hackers “logging in” rather than breaking in.

“Cybercriminals ranging from state actors to industrialized ransomware syndicates are converging on the same strategic truth: the shortest path into a target is often through the digital relationships that help the target function,” that report said.

The fulcrum of enterprise cybersecurity is no longer the company laptop or data center,” PYMNTS added. It is the software-as-a-service layer between employees and the systems that matter most. These vulnerabilities have gone from being side channels to the main terrain.

That shift can be seen in some of the most consequential criminal operations so far this year.

These include the exposure of the FBI director’s personal inbox, a breach at Mercor — an AI data vendor to OpenAIAnthropic, and Meta — and a wide-ranging Salesforce-centered extortion wave tied to the combined capabilities of multiple hacking groups.

“Taken together, these are not just breaches,” PYMNTS wrote. “They are signals. And the signal is clear: the architecture of digital risk has fundamentally changed.”