<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Featured</title>
	<atom:link href="https://advisoryloom.com/almain/category/featured/feed/" rel="self" type="application/rss+xml" />
	<link>https://advisoryloom.com/almain</link>
	<description>Weaving cybersecurity advisories into one clear view</description>
	<lastBuildDate>Tue, 01 Sep 2026 18:15:53 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://advisoryloom.com/almain/wp-content/uploads/2026/04/cropped-ChatGPT-Image-Apr-17-2026-03_10_38-PM-32x32.png</url>
	<title>Featured</title>
	<link>https://advisoryloom.com/almain</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds</title>
		<link>https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 15:44:53 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Threat Intelligence]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet-seeds/</guid>

					<description><![CDATA[Confirmed Zero-Day AlertPaperCut NG/MF zero-day exploit chain used in data-theft attacksVerified September 1, 2026 8:00 amView verified coverage]]></description>
										<content:encoded><![CDATA[<div>Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.</p>
<p>&#8220;The injected code runs two operations against a site&#8217;s visitors: a mobile ad-fraud and gambling-redirect</p></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability</title>
		<link>https://cybersecuritynews.com/langflow-rce-and-rails-vulnerability-exploited/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 14:13:17 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/hackers-actively-exploiting-critical-langflow-rce-and-rails-vulnerability/</guid>

					<description><![CDATA[Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being <a href="https://cybersecuritynews.com/langflow-cve-2026-33017-exploited/" target="_blank" rel="noreferrer noopener">actively exploited,</a> with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry.</p>
<p class="wp-block-paragraph">The first issue, tracked as CVE-2026-0768, affects Langflow, a low-code platform for building AI-powered applications, agents, and workflow automations.</p>
<p class="wp-block-paragraph">VulnCheck observed exploitation attempts against its internet-facing Canary systems shortly after the vulnerability was added to its Known Exploited Vulnerabilities catalog.</p>
<p class="wp-block-paragraph">CVE-2026-0768 is an unauthenticated <a href="https://cybersecuritynews.com/langflow-vulnerability-exploit/" target="_blank" rel="noreferrer noopener">remote code execution flaw</a> in the code validator used by Langflow’s custom component editor. An attacker may be able to execute code on a vulnerable server without first authenticating.</p>
<p class="wp-block-paragraph">The flaw was disclosed through Trend Micro’s Zero Day Initiative in January, and VulnCheck said no public proof-of-concept exploit was known at the time of the observed attacks.</p>
<p class="wp-block-paragraph">The company initially recorded more than 50 detections, but the volume later increased to around 360 exploitation events. The malicious requests appeared to be designed to identify valuable credentials and access paths rather than immediately deploy ransomware or other destructive payloads.</p>
<h2 id="h-langflow-rce-and-rails-vulnerability-exploited" class="wp-block-heading"><strong>Langflow RCE and Rails Vulnerability</strong> <strong>Exploited</strong></h2>
<p class="wp-block-paragraph">Observed commands attempted to retrieve environment variables associated with Langflow administration, OpenAI APIs, and<a href="https://cybersecuritynews.com/aws-shows-how-hackers/" target="_blank" rel="noreferrer noopener"> AWS cloud access.</a></p>
<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6aunK70RmZ92Ll1ke9McMSEFFQay_XIWCvE7hQDwgumfDJ-Q89uBUxu9WiNgfYSIX38jQ2sSitUCyIKnZIn00Nxf94EPm58kEHn9aUKV3CyWIGy7hf7HnGSW3k1gnBaHjLbQ-5zJcELcvpbr93TqCbEO8sb0yw9FZlnh8-fknXFuOy7TXKSLpRIR-4FI/s1600/Screenshot 2026-09-01 184232 (1).webp" alt="Observed first-time exploitation of CVE-2026-0768 in Langflow (source : VulnCheck )"><figcaption class="wp-element-caption">Observed first-time exploitation of CVE-2026-0768 in Langflow (source: VulnCheck )</figcaption></figure>
<p class="wp-block-paragraph">Attackers also tried to read Langflow’s local secret key file at /root/.cache/langflow/secret_key, inspect SSH access, and determine the size of .bash_history files. These checks could help an intruder identify administrator activity, stolen credentials, cloud resources, and possible routes for lateral movement.</p>
<p class="wp-block-paragraph"><a href="https://www.linkedin.com/feed/update/urn:li:activity:7499493657218076672/" target="_blank" rel="noreferrer noopener nofollow">VulnCheck said</a> the Langflow traffic primarily originated from Russia and, at the time of reporting, targeted Canary systems located in the United Kingdom.</p>
<p class="wp-block-paragraph">The activity adds to a growing pattern of exploitation targeting Langflow. Several other Langflow vulnerabilities have reportedly been added to VulnCheck’s KEV catalog during 2026.</p>
<p class="wp-block-paragraph">Separately, researchers observed <a href="https://www.linkedin.com/feed/update/urn:li:activity:7497979391268892672/" target="_blank" rel="noreferrer noopener nofollow">exploitation of CVE-2026-66066</a>, a critical Ruby on Rails vulnerability described as an Active Storage file-read-to-RCE issue.</p>
<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnIdj9xVJtLdtZ3g9TQmNAeSO8r1Prdg1f3gjuK8pTkNBdsdNIPSxp-HOosLqP7gsmUQDdnlBAcoefHTjj5lT-BXOBsjgO_nM02edIkhqeM8bwJsagm_J-qp6ynWuHtYSHGWcyK9EHcC2MwM1EY1XKJSD5hZe4jGjgDnJRRxPomWHX05YY3-za_iJ9ciE/s1600/Screenshot 2026-09-01 184242 (1).webp" alt="Active exploitation of CVE-2026-66066 (source  : vulncheck )"><figcaption class="wp-element-caption">Active exploitation of CVE-2026-66066 (source: VulnCheck)</figcaption></figure>
</div>
<p class="wp-block-paragraph">The attacks hit Canary systems in Singapore, Israel, and the United Kingdom. VulnCheck linked the activity to a single source IP address in France. At the same time, command-and-control communication was established with a host in Israel.</p>
<p class="wp-block-paragraph">The Rails flaw is particularly dangerous because an attacker may first use file-reading capabilities to obtain sensitive application secrets, including secret_key_base, API tokens, database credentials, and cloud-storage keys.</p>
<p class="wp-block-paragraph">Those secrets can remain useful even after the vulnerable software is patched. A compromised Rails secret_key_base, for example, may allow session forgery or other abuse until it is rotated.</p>
<p class="wp-block-paragraph">Organizations running Langflow or Ruby on Rails should immediately identify exposed instances, apply vendor fixes, restrict public access to administrative interfaces, and review server logs for unusual commands targeting environment variables, secret files, SSH directories, or shell-history files.</p>
<p class="wp-block-paragraph">Security teams should also rotate credentials, <a href="https://cybersecuritynews.com/40-minute-litellm-hack/" target="_blank" rel="noreferrer noopener">API keys</a>, cloud secrets, and application signing keys if exploitation is suspected.<br />The incidents highlight how AI application platforms and widely deployed web frameworks are becoming high-value targets.</p>
<p class="wp-block-paragraph">For defenders, patching alone is not enough; any secrets accessible to a compromised application should be treated as potentially exposed and replaced.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: <a href="https://any.run/threat-intelligence-lookup/?utm_source=csn&amp;utm_medium=100+links&amp;utm_campaign=lookup+tier+1&amp;utm_content=ti+lookup+sales&amp;utm_term=190826#contact-sales" target="_blank" rel="noreferrer noopener">Integrate TI Lookup in your SOC</a></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/langflow-rce-and-rails-vulnerability-exploited/">Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement</title>
		<link>https://cybersecuritynews.com/hackers-weaponize-microsoft-teams/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 14:13:09 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/hackers-weaponize-microsoft-teams-help-desk-calls-for-malware-and-network-lateral-movement/</guid>

					<description><![CDATA[Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with employees, then call them and press for remote access or software execution.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313"></a></p>
<p class="wp-block-paragraph">The activity ran from January through April 2026 and approached more than 150 employees at at least 10 organizations. </p>
<p class="wp-block-paragraph">Its danger lies in the human element: a familiar sounding technician and a live conversation can make an unexpected request feel urgent and legitimate.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313" target="_blank" rel="noopener"></a></p>
<p class="wp-block-paragraph">Analysts at Unit 42 identified the operation after detecting suspicious chat creation across multiple Microsoft 365 tenants, uncovering 26 distinct attacker identities. </p>
<p class="wp-block-paragraph"><a href="https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/" data-type="link" data-id="https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/" target="_blank" rel="noreferrer noopener nofollow">Palo Alto Networks said in a report</a> shared with Cyber Security News (CSN) that the group did not exploit a flaw in Teams. Instead, it abused external communication features and the trust users place in workplace collaboration tools.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313" target="_blank" rel="noopener"></a></p>
<p class="wp-block-paragraph">The campaign shows why Teams impersonation deserves the same scrutiny as email phishing. Attackers can adjust their story during a call, persuade a victim to run a remote support utility, and quickly move from a single workstation toward systems that control an entire network.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313"></a></p>
<h2 id="h-hackers-weaponize-microsoft-teams-help-desk-calls" class="wp-block-heading"><strong>Hackers Weaponize Microsoft Teams Help Desk Calls</strong></h2>
<p class="wp-block-paragraph">Spring Ring began with a one-to-one Teams chat from attacker-controlled .onmicrosoft.com tenants. The accounts carried authoritative display names such as help desk, IT assistance, or support staff, while some used names of real people to make the contact appear more credible.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313"></a></p>
<p class="wp-block-paragraph">After a chat request, the operator placed unsolicited voice calls, sometimes leaving voicemails and repeatedly trying different targets. </p>
<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiazhgREW8BkaALkshBdWc_XWEIzAeTnMKczVQXdS3qevO4p2Zsq5lKtJ_FcDCFKZ1qw8AYf90lnem5ApCkQHi8mxMgwhosQ7jtSggyQTelm0uRIvwn5pC0XZ0B3j8DK3cHiO9-ntxu8VKrD49xCFn6CtkqvCpW7iO7EnFyYb_eqhNf8cMhBrr-QtRWfU/s1600/External chat created (Source - Unit42).webp" alt=""><figcaption class="wp-element-caption">External chat created (Source – Unit42)</figcaption></figure>
</div>
<p class="wp-block-paragraph">Successful conversations commonly lasted 10 to 15 minutes, giving the caller time to guide an employee through steps that would normally trigger suspicion in a written message.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313" target="_blank" rel="noopener"></a></p>
<p class="wp-block-paragraph">In Campaign A, the fake technician persuaded victims to launch Quick Assist or download remote monitoring and management software. </p>
<p class="wp-block-paragraph">Once remote control was granted, the intruder checked the host and domain, then used PowerShell to retrieve an obfuscated remote-access trojan from its infrastructure.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313" target="_blank" rel="noopener"></a></p>
<p class="wp-block-paragraph">That method closely echoes a recent <a href="https://cybersecuritynews.com/microsoft-teams-phishing/" target="_blank" rel="noopener">Microsoft Teams phishing campaign</a> in which fake support staff pushed malware through the collaboration service. </p>
<p class="wp-block-paragraph">It also reinforces a basic rule: employees should independently verify an unexpected support request using a known company contact, never the caller’s instructions.<a href="https://cybersecuritynews.com/microsoft-teams-phishing/" target="_blank" rel="noopener"></a></p>
<h2 id="h-from-remote-access-to-domain-control" class="wp-block-heading"><strong>From Remote Access to Domain Control</strong></h2>
<p class="wp-block-paragraph">Campaign B used a tailored cloud-hosted executable whose name included the target company and employee. </p>
<p class="wp-block-paragraph">The program copied itself into the Temp directory, created vhlp-<em>.exe and scnr-</em>.exe components for persistence, and launched a hidden Microsoft Edge process that loaded a sideloaded extension.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313" target="_blank" rel="noopener"></a></p>
<p class="wp-block-paragraph">The attackers then used Python to scan internal systems over SMB and generate NTLM traffic toward the domain controller. </p>
<p class="wp-block-paragraph">They attempted PetitPotam, a technique intended to force the controller to authenticate to an attacker-controlled machine, where that authentication could be relayed for domain-level access.</p>
<div class="wp-block-image">
<figure class="aligncenter size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7FkrcX3M3qTctpzWHzadNoE2mO578bChzS-5zzba9tnuGn5svEUlGDBTZ326loGJfmMZB8g-BLTudN6ssJYzmDUfz7UcPg0EXocuLBsGINfx9TRMp_gMwpYX_C4-309sjR69w_UneYkOxpqb3P9hlvGBOgMJQkAYeYzx4hb5arshyRviVkx3vo7U8IfY/s1600/Full attack flow of the two Spring Ring campaigns (Source - Unit42).webp" alt=""><figcaption class="wp-element-caption">Full attack flow of the two Spring Ring campaigns (Source – Unit42)</figcaption></figure>
</div>
<p class="wp-block-paragraph"><a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313" target="_blank" rel="noopener"></a>The attempted takeover was blocked, but the sequence illustrates how a help desk call can become a serious identity attack. Readers following <a href="https://cybersecuritynews.com/unc6692-hackers-uses-microsoft-teams-helpdesk-impersonation/" target="_blank" rel="noopener">Teams helpdesk impersonation scams</a> will recognize the same reliance on external accounts and a convincing support pretext.<a href="https://cybersecuritynews.com/unc6692-hackers-uses-microsoft-teams-helpdesk-impersonation/" target="_blank" rel="noopener"></a></p>
<p class="wp-block-paragraph">Organizations should limit external Teams chats to genuine business needs, flag a rapid chat-to-call shift, and investigate unusual remote-tool launches, cloud downloads, and SMB activity. </p>
<p class="wp-block-paragraph">Security teams should also watch authentication events involving domain controllers, an issue explained in coverage of <a href="https://cybersecuritynews.com/new-mitm6-ntlm-relay-attack/" target="_blank" rel="noopener">MITM6 and NTLM relay</a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/new-mitm6-ntlm-relay-attack/" target="_blank" rel="noopener"></a></p>
<p class="wp-block-paragraph">User education must be specific: IT staff should never ask workers to install unapproved tools or grant screen control after an unsolicited call. </p>
<p class="wp-block-paragraph">Combining that policy with behavioral monitoring and review of Teams audit data can catch the chain early, as outlined in reporting on <a href="https://cybersecuritynews.com/microsoft-teams-collaboration-features-exploited/" target="_blank" rel="noopener">external collaboration feature abuse</a>.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/e7e99e5c-67e7-4b28-a962-5386438517ad/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.pdf?AWSAccessKeyId=ASIA2F3EMEYEYBSPI56D&amp;Signature=jBbpiZgc9uZVyWegZIDnnBBBIwg%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEOX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCNny9ftJ0%2B6VwZ6%2BTYOch71zgZq2qCQbjbzRUqaG54VgIhALaTLONtCtjbPjdndpQAOMXwnHLaDc2erIZhkF8xcAEfKvwECK3%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQARoMNjk5NzUzMzA5NzA1IgzzIlvkDDfekYYvP4Uq0ARHryyv9cH30%2FrfwfRdObRWbIcCfs%2BBteuqJHolUwwNDpllsECHOvjFMScWBpFYXhC6o7Fn%2B5FRANn14Lw84wfJ8ASd6JDvyMP0bNl8pp54tij9laaMcGHQkNbxkk%2FwNbC5DCjar83EON4jsLn3VkDpM99aVDIfcMODX%2FD1WDC4kEDw03pPPbOgDet6uqnYiqrJcYFwiS%2F8UTYaywovHw9AMGMQoHlsFVZBcqtSwSOKNQoP4AZuX3k4mIiPkky8sPm5eKCPa0UtEIjrVh0QOALmNNSgZ%2FkPkWkYh4WUtcEjCdsUbPbsZEu9cxouXYSg8KSfW00W%2FbRmbKEB1rRiHjiEnSjFKa10UJxcesDpJ5%2F0KQJ2JJol%2FFw0eRyhDidwjQ1fqpvxvhs9btd6qCXv4XdRslbVYsjyQ2JqicL9gM50dB5ll8MaTJ3i0sHth08hyoyB6NGNN1LiyESqaJLH7DYFb0oI0X%2Fr4yvTR99D0z8urX7YqbemdldpRi%2Fkt%2F5WhY5RkLuS4cu8Jdrd2Dhchr4ylutwQ42f81k%2BQcXnfRN8AGCam0H%2F3JFqNp7fcaDQgXo07KIoB2savPbhDFrc1TQlmDSJLY3zCoUgGU6SEG9gh1yJ%2BLqbsIo3PQvMkset9QnKL4NGK0nHPnFo7EJEb6p4YYawx%2FDECrNFRmesEz87dwJcCnyZBARz%2BSW4yNT5pHhHEWfVHc0C8qY2C%2Ff8b10jZ1csF5y5V8znvawDrLlvRvR2qR9g%2Fxn5E13%2F%2Bms%2BuUQ9oAOlAtr6MRSWGG8LJXQlMMaC29QGOpcBEGe8WGdFvcN6nF2%2BAtKTS%2BAoZD%2FTzUhyO2cXMoZcbIqpAuexC%2B3%2FM08wF8dafruk1FW%2FbpIwtYQtNFozWzxt2AW6EJt83Kn6WnNC%2Fj%2B9OWmNCS1mDYrly00aa2C5IUlbE0igGADE2WkaaZ57H7d9AAIiEuMpek1BfldfoqxtT66B4Q7Im12IkL0QVeAPdVc1670uywH4ZA%3D%3D&amp;Expires=1788268313" target="_blank" rel="noopener"></a><a href="https://cybersecuritynews.com/microsoft-teams-collaboration-features-exploited/" target="_blank" rel="noopener"></a></p>
<p class="wp-block-paragraph">The trusted communication platforms are now being used as a route to domain-level exploitation. The immediate defense is simple: stop, verify the request out of band, and report the external account before any tool is opened. </p>
<p class="wp-block-paragraph">That approach reduces the chance that an attacker can turn a routine Teams exchange into a costly enterprise-wide incident overnight.</p>
<p class="wp-block-paragraph"><strong>Indicators of compromise (IoCs):-</strong><a href="https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/" target="_blank" rel="noopener"></a></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<thead>
<tr>
<th class="has-text-align-left" data-align="left">Type</th>
<th class="has-text-align-left" data-align="left">Indicator</th>
<th class="has-text-align-left" data-align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>Attacker identity</td>
<td><code>helpcenter@ithelpcenter365[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>helpdesk@itprotectiondepartment[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>helpdesk@newsystemmaintenance[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>helpdesk@officedesk365[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>helpdesk@officesecures[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>helpdesk@tbcsschid[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>internal@internalusahelpdeskIT[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>it_assistance@teams0137[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>it@infrastructurefirewall[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>itadmin@mandatorynetworkmonitoring[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>itassistant@bilelonellc[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>ithelp@certifiednetworksec[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>ithelp@internalsystemsdaily[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>ithelp@itprotectiondepartment[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>ithelp@mandatorynetworkmonitoring.onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>ithelpdesk@certifiedupdatenetwork[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>support@bilelonellc[.]onmicrosoft[.]com</code></td>
<td>Generic help desk identity used in vishing attempts</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>andreas[..]@idigitalserviceoperation.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>andrew[..]@hapsinfrastructureops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>brandon[..]@devsitoperationhub.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>brian[..]@appssupportsys.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>christopher[..]@adevpsitplatformops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>christopher[..]@itplatformops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>christopher[..]@helpaphelpitinfraops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>clara[..]@systemsupportoperations.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>daniel[..]@opsnetsupportit.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>daniel[..]@apsitsupporthub.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>emily[..]@apsitechsupportdesk.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>eric[..]@appopshelp.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>henrik[..]@enterpriseoperationsflo.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>james[..]@helpitsupportcore.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>james[..]@itcoretechhelp.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>jonathan[..]@itservicedesk.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>justin[..]@techopshelpsupp.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>kevin[..]@itopsupportdesk.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>kevin[..]@netopsdeskhelp.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>leon[..]@netcorevdapp.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>lucas[..]@applicationoperationsunit.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>martin[..]@syslanevdapp.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>matthew[..]@supportopsupp.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>michael[..]@appdeploymentservices.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>michael[..]@infratechopsdesk.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>michael[..]@itopsdeskhelp.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>patrick[..]@infrastructureopsdesk.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>rachel[..]@ioseccloudsupport.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>rebecca[..]@infrastructureopsservice.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>robert[..]@systemdeploymentcenter.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>ryan[..]@apstechopsdeskdev.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>ryan[..]@helpssupportcloudops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>ryan[..]@seqhelpitsuppnetops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>sarah[..]@secinfrahelpdesk.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>sarah[..]@apsscloudopsdesk.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>sarah[..]@helpitdevsupportops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>sarah[..]@itdevsupportops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>scott[..]@cloudinfrastr.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>steven[..]@ittechnologyopsitdesk.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>thomas[..]@networkoperationsec.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>Attacker identity</td>
<td><code>thomas[..]@seqapsitsupportops.onmicrosoft[.]com</code></td>
<td>Partially redacted impersonated username</td>
</tr>
<tr>
<td>IP address</td>
<td><code>193.32.248[.]251</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>193.138.7[.]142</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>185.65.134[.]209</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>178.130.47[.]46</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>5.181.3[.]106</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>2.56.172[.]214</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>185.234.67[.]53</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>45.8.157[.]185</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>80.66.72[.]215</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>136.0.20[.]6</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>185.213.155[.]226</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>185.155.99[.]161</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>92.118.232[.]131</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>45.182.189[.]80</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>185.65.133[.]51</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>IP address</td>
<td><code>45.33.22[.]47</code></td>
<td>VPN or proxy infrastructure used in vishing attempts</td>
</tr>
<tr>
<td>Domain</td>
<td><code>san-sid[.]com</code></td>
<td>Attacker-controlled domain hosting the PowerShell RAT payload</td>
</tr>
<tr>
<td>URL</td>
<td><code>hxxps[:]//san-sid[.]com/owners</code></td>
<td>URL hosting the obfuscated PowerShell RAT dropper</td>
</tr>
<tr>
<td>SHA-256</td>
<td><code>24ab9fe5d5be62d3bf055a0ca4508e8bca2996b6d78649dce8145d8a27bc1c5b</code></td>
<td>Obfuscated PowerShell payload</td>
</tr>
<tr>
<td>File name pattern</td>
<td><code>&lt;company_name&gt;-org-filters-update-&lt;victim_name&gt;[.]exe</code></td>
<td>Tailored Campaign B executable</td>
</tr>
<tr>
<td>File name pattern</td>
<td><code>vhlp-*.exe</code></td>
<td>Persistence-related executable copies observed in Campaign B</td>
</tr>
<tr>
<td>File name pattern</td>
<td><code>scnr-*.exe</code></td>
<td>Persistence-related executable copies observed in Campaign B</td>
</tr>
<tr>
<td>File path</td>
<td><code>C:ProgramDataIntegrityDatapython.exe</code></td>
<td>Python executable used for lateral movement activity</td>
</tr>
</tbody>
</table>
</figure>
<p class="wp-block-paragraph"><strong>Note:</strong> <em>IP addresses and domains are intentionally defanged (e.g., </em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)"><strong><strong><strong><strong>Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: </strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=csn&amp;utm_medium=100+links&amp;utm_campaign=lookup+tier+1&amp;utm_content=ti+lookup+sales&amp;utm_term=190826#contact-sales" target="_blank" rel="noreferrer noopener nofollow">Integrate TI Lookup in your SOC</a></strong></strong></strong></p>
<p class="wp-block-paragraph">
<p>The post <a href="https://cybersecuritynews.com/hackers-weaponize-microsoft-teams/">Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>White House Launches Pilot Program in Texas to Protect Water Infrastructure</title>
		<link>https://www.infosecurity-magazine.com/news/white-house-texas-protect-water/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 13:21:31 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/white-house-launches-pilot-program-in-texas-to-protect-water-infrastructure/</guid>

					<description><![CDATA[Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid]]></description>
										<content:encoded><![CDATA[<div>Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threats</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations</title>
		<link>https://cybersecuritynews.com/boston-scientific-cyberattack/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 13:21:27 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/boston-scientific-cyberattack-disrupts-medical-device-manufacturing-and-global-operations/</guid>

					<description><![CDATA[Boston Scientific is investigating a cybersecurity incident that disrupted parts of its global operations, affecting manufacturing, order processing,]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">Boston Scientific is investigating a <a href="https://cybersecuritynews.com/jaguar-land-rover-it-systems/" target="_blank" rel="noreferrer noopener">cybersecurity incident</a> that disrupted parts of its global operations, affecting manufacturing, order processing, and product shipments.</p>
<p class="wp-block-paragraph">The company said the incident was detected on August 25, 2026. It caused a network outage involving certain internal information technology systems and business applications.</p>
<p class="wp-block-paragraph">The medical device manufacturer has engaged CrowdStrike and other third-party cybersecurity specialists to investigate, contain, and recover from the incident.</p>
<p class="wp-block-paragraph">In its latest update issued August 30 at 8:25 p.m. ET, Boston Scientific said it had found no indication of unauthorized activity in its environment since August 25.</p>
<p class="wp-block-paragraph">The company said the incident is limited to certain on-premises systems. Its cloud-based systems and applications have not been impacted, according to the ongoing investigation.</p>
<p class="wp-block-paragraph">This distinction is significant because it indicates that the disruption is affecting localized enterprise infrastructure rather than the company’s broader cloud environment.</p>
<p class="wp-block-paragraph">Boston Scientific said the affected systems include operational technology support functions and business applications required to manufacture products, process customer orders, and ship medical devices.</p>
<h2 id="h-boston-scientific-cyberattack" class="wp-block-heading"><strong>Boston Scientific Cyberattack</strong></h2>
<p class="wp-block-paragraph">While customers can continue to submit orders electronically through <a href="https://cybersecuritynews.com/traffic-light-controller-authentication-bypass-vulnerability/" target="_blank" rel="noreferrer noopener">electronic data interchange, or EDI</a>, and local applications, those orders are being placed into a fulfillment queue until processing and shipping services are restored.</p>
<p class="wp-block-paragraph">The company said it is working toward a partial restoration of shipping for some products during the week following the August 30 update. Full ordering and shipping capacity will resume after the company validates that the restored systems are fully operational.</p>
<p class="wp-block-paragraph">The disruption has raised concerns for hospitals, clinicians, suppliers, and patients that depend on Boston Scientific products. However, the company said there is no known impact on devices that are not connected to a Boston Scientific network.</p>
<p class="wp-block-paragraph">It also reported no known impact on clinicians’ ability to use disconnected devices and no evidence that the incident has increased cybersecurity risks to hospital networks through Boston Scientific medical devices.</p>
<p class="wp-block-paragraph"><a href="https://news.bostonscientific.com/update-on-recent-cybersecurity-incident" target="_blank" rel="noreferrer noopener nofollow">Boston Scientific also provided an update</a> on its Cardiac Rhythm Management device portfolio, including implantable cardiac devices such as pacemakers, implantable cardioverter defibrillators, cardiac resynchronization therapy devices, subcutaneous ICDs, and insertable cardiac monitors.</p>
<p class="wp-block-paragraph">According to the company, existing remotely monitored CRM devices remain functional. Remote patient monitoring for devices enrolled before the outage is also operational, and programmer interrogations are unaffected.</p>
<p class="wp-block-paragraph">Boston Scientific said there is no evidence that the incident has disrupted transfers of <a href="https://cybersecuritynews.com/dark-web-monitoring-tools/" target="_blank" rel="noreferrer noopener">CRM monitoring</a> data to electronic medical record systems.</p>
<p class="wp-block-paragraph">However, new remote monitoring activations are affected. New communicators for newly implanted CRM devices cannot currently be activated, delaying transmission of device data to remote patient management systems.</p>
<p class="wp-block-paragraph">Newly implanted insertable cardiac monitors can continue recording episodes after activation through the Boston Scientific Clinic Assistant app. However, they cannot pair with patient mobile phones for remote transmission until systems are restored.</p>
<p class="wp-block-paragraph">Boston Scientific said it is prioritizing systems that have the greatest effect on customer access, product delivery, and patient care. The company has not disclosed the threat actor, attack method, data theft, ransomware involvement, or a timeline for full recovery.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: <a href="https://any.run/threat-intelligence-lookup/?utm_source=csn&amp;utm_medium=100+links&amp;utm_campaign=lookup+tier+1&amp;utm_content=ti+lookup+sales&amp;utm_term=190826#contact-sales" target="_blank" rel="noreferrer noopener">Integrate TI Lookup in your SOC</a></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/boston-scientific-cyberattack/">Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access</title>
		<link>https://cybersecuritynews.com/jfrog-artifactory-auth-bypass-exploited/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Tue, 01 Sep 2026 13:21:23 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/jfrog-artifactory-auth-bypass-exploited-in-attacks-to-gain-admin-access/</guid>

					<description><![CDATA[A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">A critical authentication bypass <a href="https://cybersecuritynews.com/jfrog-artifactory-zero-day/" target="_blank" rel="noreferrer noopener">vulnerability in JFrog Artifactory</a>, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges.</p>
<p class="wp-block-paragraph">WatchTowr said its intelligence team has observed attackers exploiting the issue and “minting themselves admin tokens.” An attacker with a valid administrator token could control the affected Artifactory environment, including repositories, user accounts, access permissions, build artifacts, and software packages stored in the platform.</p>
<p class="wp-block-paragraph">JFrog disclosed the vulnerability on August 28, 2026, and classified it as critical. The company described <a href="https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases" target="_blank" rel="noreferrer noopener nofollow">CVE-2026-82329</a> as an improper authentication issue, tracked under CWE-287.</p>
<p class="wp-block-paragraph">Under the default configuration, a remote attacker does not need valid credentials to exploit the weakness and may obtain administrative privileges.</p>
<h2 id="h-jfrog-artifactory-auth-bypass-exploited" class="wp-block-heading"><strong>JFrog Artifactory Auth Bypass Exploited</strong></h2>
<p class="wp-block-paragraph">Artifactory is widely used by development and DevOps teams to manage packages, container images, binaries, build dependencies, and other software artifacts.</p>
<p class="wp-block-paragraph">Because it often sits within CI/CD pipelines, compromising an Artifactory server can pose a <a href="https://cybersecuritynews.com/best-supply-chain-intelligence-security-companies/" target="_blank" rel="noreferrer noopener">serious risk to the software supply chain</a>.</p>
<p class="wp-block-paragraph">Attackers who gain admin control may be able to alter repository settings, create privileged accounts, steal stored secrets, access private packages, or attempt to introduce malicious artifacts into trusted build and deployment workflows.</p>
<p class="wp-block-paragraph"><a href="https://x.com/watchtowrcyber/status/2094639075726668267" target="_blank" rel="noreferrer noopener nofollow">According to exposure management firm WatchTowr</a>, the reported creation of administrator tokens is particularly concerning because they can provide persistent access even after an organization changes passwords or terminates active user sessions.</p>
<p class="wp-block-paragraph">Security teams should investigate whether any unexpected administrator tokens, new privileged users, unusual API activity, or configuration changes were created around the time the vulnerable instance was exposed.</p>
<p class="wp-block-paragraph">JFrog said its cloud environments have already been fortified, meaning customers using the vendor-managed cloud service do not need to take action for this specific issue.</p>
<p class="wp-block-paragraph">However, organizations running self-hosted Artifactory must upgrade immediately to a fixed release on their supported branch. The patched versions are 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.</p>
<p class="wp-block-paragraph">The affected ranges include Artifactory versions 7.111.4 through 7.111.21, 7.117.0 through 7.117.27, 7.125.0 through 7.125.19, 7.133.0 through 7.133.28, 7.146.0 through 7.146.36, and 7.161.0 through 7.161.19.</p>
<p class="wp-block-paragraph">Organizations should also restrict external <a href="https://cybersecuritynews.com/jfrog-artifactory-flaw/" target="_blank" rel="noreferrer noopener">access to Artifactory management interfaces</a>, review reverse-proxy and firewall rules, and ensure only trusted networks can reach administrative endpoints.</p>
<p class="wp-block-paragraph">Teams should inspect access logs for unfamiliar source IP addresses, failed or abnormal authentication requests, token-generation events, and calls to user, permission, or repository administration APIs.</p>
<p class="wp-block-paragraph">Administrators should treat any internet-exposed, unpatched self-hosted Artifactory deployment as potentially compromised.</p>
<p class="wp-block-paragraph">After patching, organizations should revoke and reissue administrator tokens, review all privileged accounts, validate repository integrity, and <a href="https://cybersecuritynews.com/mini-shai-hulud-compromises-antv-npm-packages-to-steal-ci-cd-credentials/" target="_blank" rel="noreferrer noopener">examine CI/CD credentials </a>that may have been accessible through the platform.</p>
<p class="wp-block-paragraph">The active exploitation report makes rapid remediation essential. A compromised artifact repository can turn a single authentication bypass into a broader breach affecting developers, build systems, production workloads, and downstream software users.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)"><strong><strong>Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: <a href="https://any.run/threat-intelligence-lookup/?utm_source=csn&amp;utm_medium=100+links&amp;utm_campaign=lookup+tier+1&amp;utm_content=ti+lookup+sales&amp;utm_term=190826#contact-sales" target="_blank" rel="noreferrer noopener">Integrate TI Lookup in your SOC</a></strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/jfrog-artifactory-auth-bypass-exploited/">JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Linux Kernel Vulnerability Enables Passwordless Root Through DRM Render Nodes</title>
		<link>https://cybersecuritynews.com/linux-kernel-bug-passwordless-root/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 15:15:07 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/linux-kernel-vulnerability-enables-passwordless-root-through-drm-render-nodes/</guid>

					<description><![CDATA[A newly patched Linux kernel vulnerability, tracked as CVE-2026-46215, allowed any local user with access to a GPU]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">A newly patched <a href="https://cybersecuritynews.com/linux-kernel-nftables-vulnerability/" target="_blank" rel="noreferrer noopener">Linux kernel vulnerability</a>, tracked as CVE-2026-46215, allowed any local user with access to a GPU render node to escalate privileges to root, without requiring any special permissions.</p>
<p class="wp-block-paragraph">The flaw affected mainline kernels from v6.18-rc1 through the fix, and was reported to security@kernel.org on 12 April 2026, with a patch landing in late May 2026.</p>
<p class="wp-block-paragraph">The bug is a <a href="https://cybersecuritynews.com/use-after-free-vulnerability/" target="_blank" rel="noreferrer noopener">use-after-free</a> in the DRM GEM core ioctl <code>DRM_IOCTL_GEM_CHANGE_HANDLE</code>, added in v6.18-rc1 for AMD’s CRIU checkpoint/restore work.</p>
<p class="wp-block-paragraph">This ioctl moves a graphics buffer object from one handle to another but never updates the object’s <code>handle_count</code>. During a brief window, the object has two IDR (ID lookup) entries while its handle count still reads 1.</p>
<p class="wp-block-paragraph">If a second thread calls <code>DRM_IOCTL_GEM_CLOSE</code> on the old handle during that window, it drives the count to 0 and frees the object while the new handle still points to the now-freed memory.</p>
<p class="wp-block-paragraph">Both ioctls carry the <code>DRM_RENDER_ALLOW</code> flag, meaning any process that can open <code>/dev/dri/renderD*</code> can trigger the race. On most desktop Linux systems, <code>systemd-logind</code> grants this access to any logged-in user by default.</p>
<h2 id="h-from-race-condition-to-root" class="wp-block-heading"><strong>From Race Condition to Root</strong></h2>
<p class="wp-block-paragraph">The Cyberstan proof-of-concept chains several techniques to turn the freed object into full root access:</p>
<ul class="wp-block-list">
<li>Reclaims the freed memory slot using a sprayed array of <code>pipe_buffer</code> structures</li>
<li>Leaks a kernel pointer through overlapping struct fields to defeat KASLR</li>
<li>Sets <code>PIPE_BUF_FLAG_CAN_MERGE</code> via a GEM object naming trick, bypassing the 2022 DirtyPipe fix</li>
<li>Overwrites the read-only <code>/etc/passwd</code> file through the page cache, removing root’s password field</li>
</ul>
<p class="wp-block-paragraph">Across 100 test boots, the exploit succeeded 99 times, taking on average under 100 race iterations to win.</p>
<p class="wp-block-paragraph">Researcher Puttimet Thammasaeng reported the same bug first before Cyberstan and received the official CVE credit and upstream “Reported-by” attribution. The author of this analysis discovered and reported it independently, contributing separate exploit research.</p>
<p class="wp-block-paragraph">AMD’s David Francis and kernel maintainer Dave Airlie shipped a fix that closes the race window with a two-stage <code>idr_replace</code> operation, rolling back cleanly if a concurrent close wins the race.</p>
<p class="wp-block-paragraph">Kernel maintainers went further, disabling the <code>GEM_CHANGE_HANDLE</code> ioctl entirely in the upcoming 7.1 release, removing the vulnerable code path altogether. Fixed versions are 6.18.32, 7.0.9, and 7.1-rc3 onward.</p>
<p class="wp-block-paragraph">The vulnerability illustrates a recurring kernel bug pattern: compound operations on refcounted objects in which a reference is added, removed, and counted in separate steps, creating windows where concurrent teardown can free memory still in use, as the <a href="https://cyberstan.co.uk/drm-lpe-linux/" target="_blank" rel="noreferrer noopener nofollow">Cyberstan advisory notes</a>.</p>
<p class="wp-block-paragraph">Subsystems that skip established helper functions for this bookkeeping remain at risk of similar race conditions.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)"><strong>Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA <strong>Vendor</strong> Checklist</strong> – <strong><a href="https://underdefense.com/ai-soc-sla-in-2026-mttr-benchmarks-clause-tables-negotiation-checklist/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_aisoc_sla_july_2026" target="_blank" rel="noreferrer noopener nofollow">Download Free <strong>AI SOC SLA </strong>Guide</a></strong></p>
<p>The post <a href="https://cybersecuritynews.com/linux-kernel-bug-passwordless-root/">Linux Kernel Vulnerability Enables Passwordless Root Through DRM Render Nodes</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware</title>
		<link>https://cybersecuritynews.com/unc6692-hackers-uses-microsoft-teams-helpdesk-impersonation/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 14:19:22 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/unc6692-hackers-uses-microsoft-teams-helpdesk-impersonation-to-deploy-snow-malware/</guid>

					<description><![CDATA[A newly identified threat group tracked as UNC6692 is hijacking Microsoft Teams to install a custom malware suite]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph">A newly identified threat group tracked as UNC6692 is hijacking Microsoft Teams to install a custom malware suite called SNOW. </p>
<p class="wp-block-paragraph">The campaign relies almost entirely on social engineering, which makes it dangerous because it feels routine to the people who fall for it. </p>
<p class="wp-block-paragraph">Attackers pose as IT helpdesk staff, exploiting a target’s trust in familiar collaboration tools to walk victims through handing over control of their machine.</p>
<p class="wp-block-paragraph">The attack begins with a wave of spam emails sent to a target’s inbox, creating chaos and urgency. </p>
<p class="wp-block-paragraph">Once the victim is overwhelmed, the same attacker reaches out through Microsoft Teams, posing as an IT support agent offering to fix the problem they caused. </p>
<p class="wp-block-paragraph">This staged setup convinces users to trust a stranger who appears to be solving an issue rather than creating one.</p>
<p class="wp-block-paragraph"><a href="https://www.extrahop.com/blog/unc6692-and-the-snow-malware-ecosystem" id="https://www.extrahop.com/blog/unc6692-and-the-snow-malware-ecosystem" target="_blank" rel="noreferrer noopener nofollow">Analysts at ExtraHOP said in a report</a> shared with Cyber Security News (CSN) identified and detailed how this coordinated chain plays out from first contact to full network compromise. </p>
<p class="wp-block-paragraph">Once a victim accepts the fake Teams invitation, the attacker sends a link claiming to install a patch that stops the spam. </p>
<p class="wp-block-paragraph">Clicking it downloads a renamed AutoHotkey binary along with a script sharing the same file name, pulled from an attacker controlled cloud bucket.<a href="https://www.helpnetsecurity.com/2026/04/27/attackers-use-ms-teams-fake-mailbox-repair-utility/" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">That download becomes the first stage of the SNOW malware ecosystem, a modular toolkit built to support activity after the breach. </p>
<p class="wp-block-paragraph">It includes a malicious browser extension, <a href="https://cybersecuritynews.com/hackers-leverage-cloudflare-tunnels/" id="111611" target="_blank" rel="noreferrer noopener">a Python based tunneling tool</a>, and a lightweight local backdoor, each handling a part of the intrusion. </p>
<p class="wp-block-paragraph">Together they let the attacker maintain a presence long after the phishing message is forgotten.</p>
<p class="wp-block-paragraph">Once inside, UNC6692 does not rush. The group moves carefully through compromised systems, harvesting credentials, exploring internal networks, and expanding access before doing anything that might trigger alarms.<a rel="noreferrer noopener" target="_blank" href="https://www.scworld.com/news/unc6692-impersonates-help-desk-employees-to-drop-snow-malware-via-teams"></a></p>
<h2 id="h-unc6692-hackers-uses-microsoft-teams-helpdesk-impersonation" class="wp-block-heading"><strong>UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation</strong></h2>
<p class="wp-block-paragraph">The impersonation trick is simple but effective because it mirrors real corporate support interactions. </p>
<p class="wp-block-paragraph">After the spam flood, the attacker contacts the victim through a Teams chat request from an account outside the organization, posing as a helpful colleague. </p>
<p class="wp-block-paragraph">Many users accept external chat invitations without a second thought, especially when the message promises to fix a problem they already face.</p>
<p class="wp-block-paragraph">Victims are directed to a phishing page disguised as a mailbox repair and sync utility, complete with a professional interface and a health check button. </p>
<p class="wp-block-paragraph">That button triggers a login prompt, and the page asks for credentials multiple times under the guise of verification, which helps the stolen data hold up if checked later. The captured logins are then quietly sent to a cloud location controlled by the attacker.</p>
<p class="wp-block-paragraph">This is the entry point for everything that follows. Once the AutoHotkey script runs, it performs reconnaissance and installs SNOWBELT, a rogue browser extension, by launching <a href="https://cybersecuritynews.com/microsoft-edge-vulnerability-arbitrary-code/" id="73062" target="_blank" rel="noreferrer noopener">Microsoft Edge in a hidden mode</a> using command line settings that skip normal installation checks.<a href="https://fieldeffect.com/blog/it-helpdesk-impersonation-microsoft-teams" target="_blank" rel="noreferrer noopener"></a></p>
<h2 id="h-inside-the-snow-malware-toolkit" class="wp-block-heading"><strong>Inside the SNOW Malware Toolkit</strong></h2>
<p class="wp-block-paragraph">SNOW is not a single piece of malware but a layered pipeline built for persistence and stealth. </p>
<p class="wp-block-paragraph">SNOWBELT operates within the browser and can survive restarts, while a Python based tunneling utility supports SOCKS5 style traffic to route commands through the compromised host, blending in with normal web activity.<a href="https://socprime.com/active-threats/unc6692-deploys-custom-malware-through-social-engineering/" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">A separate local HTTP backdoor gives the attacker a direct channel for issuing commands and pulling data without relying on infrastructure that might get flagged. </p>
<p class="wp-block-paragraph">The toolkit also supports screenshot capture, file exfiltration, and session termination, giving operators control over how long they stay hidden.<a href="https://socprime.com/active-threats/unc6692-deploys-custom-malware-through-social-engineering/" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">Because the traffic moves through legitimate cloud services and familiar Windows features, standard network monitoring often misses it entirely. </p>
<p class="wp-block-paragraph"><a href="https://cybersecuritynews.com/aligning-it-and-security-teams/" id="108197" target="_blank" rel="noreferrer noopener">Security teams should watch for unusual browser extension</a> installations, scheduled tasks that launch Edge in headless mode, and unexpected outbound connections to unfamiliar endpoints.</p>
<p class="wp-block-paragraph">Organizations are advised to restrict external chat permissions on Microsoft Teams to approved contacts and train employees to treat unsolicited helpdesk outreach with caution. </p>
<p class="wp-block-paragraph">Blocking unapproved file sharing platforms and requiring verification before remote assistance can reduce exposure to this kind of intrusion.<a href="https://fieldeffect.com/blog/it-helpdesk-impersonation-microsoft-teams" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph">This campaign shows how attackers favor patience and disguise over brute force, turning ordinary workplace habits into an opening for deep compromise.<a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010" target="_blank" rel="noreferrer noopener"></a></p>
<p class="wp-block-paragraph" id="h-indicators-of-compromise-iocs"><strong>Indicators of Compromise (IoCs):-</strong></p>
<figure class="wp-block-table">
<table class="has-fixed-layout">
<thead>
<tr>
<th class="has-text-align-left" data-align="left">Type</th>
<th class="has-text-align-left" data-align="left">Indicator</th>
<th class="has-text-align-left" data-align="left">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>File</td>
<td>AutoHotkey binary (renamed, filename matches accompanying script)</td>
<td>Delivered from attacker controlled AWS S3 bucket; initiates SNOWBELT installation <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010"></a></td>
</tr>
<tr>
<td>File</td>
<td>AutoHotkey script (same filename as binary)</td>
<td>Executes automatically upon download, bypasses standard user prompts to deploy SNOWBELT <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010"></a></td>
</tr>
<tr>
<td>File</td>
<td>7ZIP Imager tool</td>
<td>Used by threat actor to compress and exfiltrate the entire Active Directory database (NTDS.dit) <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010"></a></td>
</tr>
<tr>
<td>Tool</td>
<td>SNOWBELT</td>
<td>Malicious Chromium browser extension component of the SNOW malware ecosystem, installed via headless Microsoft Edge <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010"></a></td>
</tr>
<tr>
<td>Tool</td>
<td>SNOWGLAZE</td>
<td>Python based tunneling utility supporting SOCKS5 traffic to conceal command and control communications <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010"></a></td>
</tr>
<tr>
<td>Tool</td>
<td>SNOWBASIN</td>
<td>Local HTTP backdoor providing a direct command channel on the compromised host <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010"></a></td>
</tr>
<tr>
<td>Infrastructure</td>
<td>Amazon Web Services S3 bucket</td>
<td>Attacker controlled storage used to host and serve the initial malicious AutoHotkey payload <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010"></a></td>
</tr>
<tr>
<td>Infrastructure</td>
<td>Cloud storage exfiltration endpoint</td>
<td>Destination used by SNOWGLAZE to move harvested NTDS.dit data and credentials off the victim network <a rel="noreferrer noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/b803b5d8-064f-40cd-b433-1233351d1a07/UNC6692-Hackers-Uses-Microsoft-Teams-Helpdesk-Impersonation-to-Deploy-SNOW-Malware.pdf?AWSAccessKeyId=ASIA2F3EMEYEUWR4IWBL&amp;Signature=zTUBY2VOerkMCLmQJavhSKwPjX4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjENX%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQCa1km8V4H6nkbOOtOKO55dJAXa0W%2BmM3f8frLubM27ngIgYYipNJfooFeKnqyRf3psSNcaZgv7Fjc32BSIUCrlVM4q%2FAQInv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDDzqXqehcDMeY7QrPirQBGH%2BLdWWjk3spWBNj0ArjvSEEMKChEtAZO1ZmN8hQJGwDhcaV1vKGRukCz6IY9t%2FUfRtJubcYU6PsryG8Ao9YC9K7zaAO6DsQh5ilQNtGi%2BWdJcEx5nA%2B9nkZzX8d1LpsHIqDmCeLOR1Ph9wj3YxJ9k5NryEe5rRYrybdNg58kiWHxByHQC1HtpwRPL0fEIYMJ47I4fVWXTIS%2FDTmKuPm%2B2DBmsK0yz8rMfhtIru0wV7evrgcwBxW3%2BV1Uf7oI64F6cMJEgEeny0nnaHK2GpN1sSfJXMUlDHYp2t8eY4492PwJo%2B8vFSxYaP3zakEL%2BF3lava44bgRBdtZpEPO7HbEZu2%2B2A9c1rI46RFVBndcRvzr7tHqCgcVouBdScHf49MGarEBnp7E15bQejxt97R7yW1O3UAHzjM5h6XwSnPoGglZEvr8%2F1HVc4CFmmIr%2Bib%2Fb7dp2aZ%2BTFbNppsZRJMGKvmzA9UBPt%2B%2FkxwSqveLBe9mY%2B5lohBMCyYr9v%2FWtA1xpQul%2FeeJJxdaV9gqWFOaYPqMmUazdMDFz8vjux%2BrkL21rroI6HuQZ5VOLhXOSBbTPuK571V7ZQKOnMl3%2BV0q0mibGcigTtZzpEN0vub2RmpFid2iI3mzP5dIgcrxqfmzeO6SXm1eR5%2F9jfv9In7LpDV0KhPiWtgi%2FQBHBbX1OrsOgbdtc1kINeVZwne%2B06GsanhG16OgaKHliLZMWR2CLXZ5SS29IM71TPsf5lWPj8PTMC%2BxAa0yPrlKgClz%2FUYK70FYkV1ljUGJZ1hbJxnJIwv7K%2B0gY6mAHJ6m9vRlFrkijm%2BSEZzFGUKLxYDETqyTEzxLOHh786ny4fJ1LBl6tYuSp10CHjYWPU33AzJfx5%2BY6xsi5iaWQdjzesXiraNzDLPVo1jCfl%2BIMyqR%2BjvJb93D9g1JmXFB%2BBSMhsbr5dDGVjEfMJm2B0lYWs6dAiLe1eCFaIqLDYTIPHD8CHiu%2FsGdpruyaabUe4hIr51N1DbQ%3D%3D&amp;Expires=1783605010"></a></td>
</tr>
</tbody>
</table>
</figure>
<p class="wp-block-paragraph"><strong>Note:</strong> <em>IP addresses and domains are intentionally defanged (e.g., </em><code><em>[.]</em></code><em>) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM</em>.</p>
<p class="has-text-align-center has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)"><strong><strong><strong><strong>Prevent critical incidents and financial loss with stronger proactive defense. </strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=links&amp;utm_campaign=feeds+landing&amp;utm_content=ti+feeds+sales&amp;utm_term=070726#contact-sales" target="_blank" rel="noreferrer noopener">Integrate a live threat feed from 15K SOC Teams</a></strong>.</strong></strong></p>
<p>The post <a href="https://cybersecuritynews.com/unc6692-hackers-uses-microsoft-teams-helpdesk-impersonation/">UNC6692 Hackers Uses Microsoft Teams Helpdesk Impersonation to Deploy SNOW Malware</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>75% CISOs Fear Executives Don’t Understand Cybersecurity Risks Employees Face</title>
		<link>https://www.infosecurity-magazine.com/news/cisos-fear-execs-dont-understand/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 12:51:54 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/75-cisos-fear-executives-dont-understand-cybersecurity-risks-employees-face/</guid>

					<description><![CDATA[Survey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risks]]></description>
										<content:encoded><![CDATA[<div>Survey of cybersecurity leaders by MetaCompliance finds that many feel boards are uninterested in ever-evolving cyber risks</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Operationalizing Threat Intelligence: Bridging the Gap Between Feed Data and SOC Action</title>
		<link>https://cybersecuritynews.com/operationalizing-threat-intelligence/</link>
		
		<dc:creator><![CDATA[Advisoryloom Editor]]></dc:creator>
		<pubDate>Thu, 09 Jul 2026 12:51:50 +0000</pubDate>
				<category><![CDATA[Cyber News]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://advisoryloom.com/almain/operationalizing-threat-intelligence-bridging-the-gap-between-feed-data-and-soc-action/</guid>

					<description><![CDATA[Threat intelligence feeds have become a staple line item in security budgets. Yet a persistent gap exists between]]></description>
										<content:encoded><![CDATA[<div>
<p class="wp-block-paragraph"><a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=gap+bridging&amp;utm_content=ti+feeds&amp;utm_term=080726" type="link" id="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=gap+bridging&amp;utm_content=ti+feeds&amp;utm_term=080726" target="_blank" rel="noreferrer noopener nofollow"><strong>Threat intelligence feeds</strong></a> have become a staple line item in security budgets. Yet a persistent gap exists between purchasing a feed and actually using it to stop attacks.</p>
<p class="wp-block-paragraph">Many SOC teams receive a steady stream of indicators — IP addresses, domains, URLs — that flows into a SIEM or threat intel platform and largely stays there, rarely making it into detection rules, analyst workflows, or response playbooks in a timely, structured way.</p>
<p class="wp-block-paragraph">This is the operationalization gap. And closing it is one of the highest-leverage moves a SOC leader can make.</p>
<h2 id="h-why-most-threat-intelligence-sits-unused-nbsp" class="wp-block-heading"><strong>Why Most Threat Intelligence Sits Unused </strong></h2>
<p class="wp-block-paragraph">The <a href="https://cybersecuritynews.com/low-noise-high-confidence-optimizing-soc-costs-with-better-threat-intelligence/" target="_blank" rel="noreferrer noopener">failure mode is rarely</a> a lack of data. It is a lack of structure around the data. </p>
<p class="wp-block-paragraph">When feeds arrive as undifferentiated bulk exports, analysts face several problems simultaneously. </p>
<p class="wp-block-paragraph">The volume is too high to manually triage. Context is missing — an IP address alone tells you nothing about which threat actor uses it, which campaigns it is associated with, or how recently it was observed as malicious. Confidence levels are opaque. </p>
<p class="wp-block-paragraph">And integration with enforcement points  firewalls, EDR platforms, SIEMs  is often manual or scheduled in batch cycles that introduce dangerous lag. </p>
<p class="wp-block-paragraph">The result: intelligence arrives too slowly, in a form that requires too much analyst effort to act on, and without the context needed to prioritize it over the hundreds of other alerts already in the queue. </p>
<h2 id="h-what-operationalized-threat-intelligence-actually-looks-like-nbsp" class="wp-block-heading"><strong>What Operationalized Threat Intelligence Actually Looks Like </strong></h2>
<p class="wp-block-paragraph">Operationalized threat intelligence is intelligence that automatically flows from collection through enrichment to detection and response with minimal friction at each handoff. </p>
<p class="wp-block-paragraph"><strong>In practice, this means:</strong> </p>
<ul class="wp-block-list">
<li><strong>Automated ingestion</strong>. The Feeds connect directly to your SIEM, SOAR, or TIP via standardized formats (STIX/TAXII, MISP, CSV/JSON) or native integrations, eliminating manual export-import cycles. </li>
</ul>
<ul class="wp-block-list">
<li><strong>Contextual enrichment at ingestion time</strong>. Each indicator arrives with metadata — associated malware family, threat actor attribution, first/last seen timestamps, confidence score, and relevant MITRE ATT&amp;CK technique mappings. Analysts immediately know whether an IP is linked to a ransomware group targeting their sector or to low-confidence commodity spam infrastructure. </li>
</ul>
<ul class="wp-block-list">
<li><strong>Freshness that matches attacker infrastructure lifecycles</strong>. Threat actor IP addresses turn over in hours to days. A feed updated weekly delivers intelligence that is, at best, historical. Operational feeds update continuously, ensuring that what you are blocking and alerting on reflects today’s threat landscape, not last week’s. </li>
</ul>
<ul class="wp-block-list">
<li><strong>Bidirectional integration.</strong> Intelligence feeds — into detection rules. Alerts generated by those rules feed back into the intel workflow, generating new indicators and refining existing ones. The SOC is not a passive consumer of intelligence — it is a participant in the intelligence cycle. </li>
</ul>
<p class="has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)">Operationalize your threat intelligence. See how <strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=gap+bridging&amp;utm_content=ti+feeds+sales&amp;utm_term=080726#contact-sales" target="_blank" rel="noreferrer noopener nofollow">ANY.RUN TI Feeds help security teams</a></strong> automate IOC ingestion, enrich detections with real-world context, and reduce time to detect and respond. </p>
<h2 id="h-the-integration-stack-where-feeds-plug-in-nbsp" class="wp-block-heading"><strong>The Integration Stack: Where Feeds Plug In </strong></h2>
<p class="wp-block-paragraph">A threat intelligence feed delivers full value only when it is connected to the tools that enforce policy and generate alerts. The primary integration points are: </p>
<ul class="wp-block-list">
<li><strong>SIEM</strong>. IOCs from the feed populate lookup tables or correlation rules. Any internal log event matching a known malicious indicator triggers an alert with context already attached — the analyst sees not just a match but the associated campaign and recommended response. </li>
</ul>
<ul class="wp-block-list">
<li><strong>SOAR</strong>. Playbooks reference feed data for automated enrichment during triage. When an alert fires, the SOAR platform instantly queries the feed for additional context on the involved indicators, accelerating analyst decision-making and reducing mean time to respond. </li>
</ul>
<ul class="wp-block-list">
<li><strong>Firewall / network controls</strong>. High-confidence IOCs — particularly IPs and domains associated with active C2 infrastructure — are pushed directly to blocklists, providing automatic prevention without requiring analyst intervention. </li>
</ul>
<ul class="wp-block-list">
<li><strong>EDR</strong>. File hashes and behavioral indicators from the feed inform endpoint detection, allowing security teams to hunt retroactively across the environment for artifacts associated with active threat campaigns. </li>
</ul>
<p class="wp-block-paragraph">The key requirement across all of these: the feed must support the integration formats your stack already uses. A feed that needs custom scripting to ingest is a feed that will not be used consistently. </p>
<h2 id="h-any-run-threat-nbsp-intelligence-nbsp-feeds-built-for-operational-integration-nbsp" class="wp-block-heading"><strong>ANY.RUN Threat Intelligence Feeds: Built for Operational Integration </strong></h2>
<p class="wp-block-paragraph"><strong><a href="https://intelligence.any.run/feeds?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=gap+bridging&amp;utm_content=ti+feeds&amp;utm_term=080726" target="_blank" rel="noreferrer noopener nofollow">ANY.RUN TI Feeds</a></strong> are designed specifically to close the operationalization gap — delivering sandbox-sourced, continuously updated threat intelligence in the formats and integrations your SOC already relies on. </p>
<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwT6h57rC7tPhyphenhyphenR6R8gAOPyYkzKbpdidAYCSFYmsyNeiVMTVpnbG-Q2m61MVQKiwpyIqwOPICFaOvD_KgDz4ID9u_Bsk2OieqrtvQwnoHWAnQ9zJEhSl43PILg-H2giEAQfn16-2e5Lt_bol6KBNFvv3QTCzXmld8GSC3skxeTrnN5n6Hr5DrYUqePrg4/s1600/operational_feeds1.webp" alt=""><figcaption class="wp-element-caption"><em>ANY.RUN TI Feeds: data, options, outcome</em> </figcaption></figure>
<ul class="wp-block-list">
<li><strong>Sandbox-sourced indicators, not scraped aggregations</strong>. Every indicator in <a href="https://cybersecuritynews.com/boost-up-your-soc-dfir-operations-with-any-runs-threat-intelligence-feeds/" target="_blank" rel="noreferrer noopener">ANY.RUN TI Feeds</a> originates from dynamic analysis of real malware samples inside the ANY.RUN <strong><a href="https://any.run/features/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=gap+bridging&amp;utm_content=features&amp;utm_term=080726" target="_blank" rel="noreferrer noopener nofollow">interactive sandbox</a></strong>. This means indicators are verified against actual malicious behavior, not inferred from passive observation or aggregated from third-party sources. The result is higher fidelity, lower false positive rates, and richer contextual metadata per indicator. <br /> </li>
<li><strong>Continuous updates</strong>. ANY.RUN processes thousands of malware samples daily. TI Feeds are updated in near-real time, ensuring that newly identified <a href="https://cybersecuritynews.com/researchers-uncover-aeternum-c2-infrastructure/" target="_blank" rel="noreferrer noopener">C2 infrastructure</a>, fresh phishing domains, and emerging dropper hashes reach your defenses while they are still operationally relevant. <br /> </li>
<li><strong>Rich context by default</strong>. Each indicator is delivered with associated malware family, threat actor context where attributable, MITRE ATT&amp;CK technique tags, confidence scores, and first/last seen timestamps. Analysts are not handed a raw IP — they are handed an IP with a complete picture of why it matters and what to do with it. <br /> </li>
<li><strong>Flexible delivery formats.</strong> ANY.RUN TI Feeds support STIX/TAXII, MISP, and direct CSV/JSON export, covering the <strong>integration</strong><a href="https://any.run/integrations/" target="_blank" rel="noreferrer noopener">  </a>requirements of the major SIEM, SOAR, and TIP platforms in use across enterprise security stacks. For teams running Splunk, Microsoft Sentinel, IBM QRadar, or Palo Alto XSOAR, native connectors further reduce integration effort. <br /> </li>
<li><strong>Broad threat coverage</strong>. Feeds cover the malware families and threat actor infrastructure most active in the current threat landscape — including ransomware groups, banking trojans, infostealers, and commodity loaders — with coverage that reflects what is being actively deployed against organizations today.</li>
</ul>
<figure class="wp-block-image size-large"><img decoding="async" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYCLsMSCpVYXMnI3tY1EzuLxR2TFqTdm3FkaXwWQEmf8qY0o5tsqwyivnRabIok9a5Z6oax6bY_MbLHZS3lWcQtBaW6-NPYtqeRwIH-VGdYPC9SdoXIM3jpYJbF1KENeAscfeXJbALGY4RXEa8Hs0XmaBIcTSH3tWr4bkHxEFeaopB2Uu3XVKnuzdAbG4/s1600/operational_feeds2.webp" alt=""><figcaption class="wp-element-caption"><em>ANY.RUN TI Feeds integrations</em></figcaption></figure>
<ul class="wp-block-list">
<li><strong>On-demand investigation with Threat Intelligence Lookup.</strong> TI Feeds handle continuous, automated intelligence ingestion. But operationalization also requires the ability to answer ad-hoc questions — when an analyst encounters an unfamiliar indicator mid-investigation, they need to query the full intelligence corpus instantly, not wait for the next feed cycle. <br /> <br /><strong><a href="https://any.run/threat-intelligence-lookup/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=gap+bridging&amp;utm_content=ti+lookup&amp;utm_term=080726" target="_blank" rel="noreferrer noopener nofollow">ANY.RUN TI Lookup</a></strong> provides exactly that: a searchable threat intelligence database built on the same sandbox-derived data that powers the feeds, queryable by IP, domain, hash, MITRE technique, threat actor, malware family, and more. TI Feeds and Lookup work as complementary layers — one automates coverage at scale, the other empowers analysts to investigate on demand. </li>
</ul>
<p class="wp-block-paragraph">Together with the Interactive Sandbox, TI Feeds and TI Lookup form a unified intelligence ecosystem: from automated indicator delivery, through investigative deep-dives, to hands-on malware analysis  all drawing from the same continuously updated, behavior verified data source. </p>
<h2 id="h-making-the-business-case-to-leadership-nbsp" class="wp-block-heading"><strong>Making the Business Case to Leadership </strong></h2>
<p class="wp-block-paragraph">For CISOs presenting to <a href="https://cybersecuritynews.com/stronger-incident-prevention-takes-just-one-ciso-decision/" target="_blank" rel="noreferrer noopener">boards or justifying budget</a>, operationalized threat intelligence has a clear value story: it reduces the cost of detection and response. </p>
<p class="wp-block-paragraph">Every hour an analyst spends manually enriching an alert with context that an integrated feed could have provided automatically is an hour not spent on investigation, hunting, or response. </p>
<p class="wp-block-paragraph">Every day a malicious IP remains unblocked because the feed update cycle is too slow is a day of unnecessary exposure. </p>
<p class="wp-block-paragraph">The operational metrics that matter: reduction in mean time to detect (MTTD), reduction in mean time to respond (MTTR), analyst hours saved per week on manual enrichment tasks, and false positive rates on feed-sourced detections. </p>
<p class="wp-block-paragraph">These are the numbers that demonstrate whether your threat intelligence investment is translating into security outcomes. </p>
<h2 id="h-conclusion-nbsp" class="wp-block-heading"><strong>Conclusion </strong></h2>
<p class="wp-block-paragraph">The fastest path to operationalized threat intelligence is a feed that is already built for integration — one that does not require significant engineering effort to connect to your existing stack and that delivers context-rich, continuously updated indicators from the moment it goes live. </p>
<p class="has-background wp-block-paragraph" style="background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)">Bridge the gap between threat data and real security outcomes. <strong><a href="https://any.run/threat-intelligence-feeds/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=gap+bridging&amp;utm_content=ti+feeds+sales&amp;utm_term=080726#contact-sales" target="_blank" rel="noreferrer noopener nofollow">Use ANY.RUN TI Feeds</a></strong> to power faster detection, automated enrichment, and more effective incident response with continuously updated threat intelligence. </p>
<p class="wp-block-paragraph">
<p>The post <a href="https://cybersecuritynews.com/operationalizing-threat-intelligence/">Operationalizing Threat Intelligence: Bridging the Gap Between Feed Data and SOC Action</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>
</div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
