Joe’s Take: The Teams Support Trap – Why That “Official” IT Chat is a Backdoor

Cartoon of a fake Microsoft Teams support chat on a laptop hiding a hacker with a malicious SnowBelt backdoor.
(AI-generated image)

When was the last time you questioned a message from "Microsoft Support" appearing right inside your company’s Teams app? You probably didn't. You’ve been trained to spot a phishing email from a mile away: the weird sender address, the bad grammar, the "Urgent!" subject line. But Teams? That’s different. It’s supposed to be our "safe space" for work.

That’s exactly what the hackers are counting on.

Right now, a new threat group tagged as UNC6692 is effectively bypassing your firewall by simply "logging in" instead of breaking in. They are impersonating official IT support staff to trick your employees into installing what looks like a routine patch but is actually a persistent backdoor named "SnowBelt."

If you think a password change will save you once this thing is in your system, think again. Let’s dive into how this trap works and why your current Cybersecurity Protection might be missing it entirely.

The Psychology of the Teams Hook

Why is this working? It’s simple: context. When you receive a Teams chat, you assume the person on the other end is either part of your organization or a verified guest. UNC6692 exploits this by gaining access to legitimate accounts or using deceptive "External" profiles that look identical to official Microsoft Support.

Imagine you’re halfway through your morning coffee, and a chat pops up. The icon is the familiar Microsoft logo. The name is "IT Support Desk." They tell you there’s a minor sync issue with your Outlook and that you need to apply a small browser "fix" to keep your emails flowing.

You aren't being asked for your password. You aren't being asked for a wire transfer. You’re just being asked to stay productive.

SnowBelt: The Browser Extension That Doesn’t Quit

Once the "support" agent convinces you to click their link, they push a browser extension called "SnowBelt."

Most users think of browser extensions as harmless tools: something to help with grammar or find coupon codes. In reality, a malicious extension like SnowBelt is one of the most dangerous things that can live on your computer.

Here is why SnowBelt is a nightmare for your Business Tech Solutions:

  1. Session Hijacking: Instead of stealing your password, SnowBelt steals your "session tokens." These are the digital keys that tell websites like Microsoft 365, Slack, or your bank that you’ve already logged in.
  2. Bypassing MFA: Because the hacker has your session token, they don't need your password or your Multi-Factor Authentication (MFA) code. They simply "become" you in the eyes of the server.
  3. Persistence: This is the scary part. You can change your password ten times, but if that extension is still in your browser, the hacker still has a backdoor. They can refresh their access indefinitely.

We are seeing a 40% increase in social engineering attacks that move away from email and into collaboration tools like Teams and Slack. The barrier to entry for hackers is lower because the "trust level" in these apps is significantly higher.

Why "Logging In" is the New "Breaking In"

We’ve moved into an era where hackers don't need to find a vulnerability in your software. They find a vulnerability in your trust.

UNC6692 doesn't need to write complex code to crack your encryption. They just need to be a good "actor." By posing as a helpful support person, they get you to invite them right past the front door. This is why we always emphasize to our Managed IT Support NYC clients that tech is only half the battle; the other half is culture and verification.

Joe’s Take: Trust But Verify

Here is my personal take on this: Real Microsoft support will never cold-call you on Teams.

Microsoft doesn't have the time or the staff to proactively chat every user about a minor "email sync" issue. If someone hits you up out of the blue claiming to be "Global Support" or even your own company’s IT department, and they want you to install anything: even a browser extension: alarm bells should be ringing.

At New York Computer Help, we are currently performing deep-dive audits for our managed clients. We aren't just looking for viruses; we are auditing every browser extension installed across the entire workforce. We are hunting for "SnowBelts" and other unauthorized tools that act as silent observers in your daily workflow.

If you get a suspicious chat:

  • Do not click the link.
  • Do not install the extension.
  • Call us. Or call your internal IT team on a known, verified number.

Verification takes 30 seconds. Recovering from a total session hijack can take 30 days.

Joe Reviews: The Security-First Mobile Workstation (May 2026 Edition)

Since we’re talking about security and the "new" way of working, I’ve been testing the latest 2026 Dell Latitude 9000 Series with the upgraded "SafeID" biometric hardware.

If you’re a business owner in NYC, you know your team is working from coffee shops, trains, and home offices. You need hardware that matches the threat level.

The Pros:

  • Hardware-Level Privacy: It has a dedicated chip that stores your biometric data separate from the OS. Even if SnowBelt gets into your browser, it can’t get your fingerprint or facial data.
  • Intelligent Privacy: It can actually detect if someone is looking over your shoulder and blur the screen.
  • Battery Life: 18 hours. Real-world. No "manufacturer's estimate" fluff.

The Cons:

  • Price: It’s an investment. You’re paying for the security features.
  • Weight: It’s a bit heavier than a MacBook Air, but for the port selection and security, it’s worth the trade-off.

My Verdict: If your team handles sensitive data, these are the machines you want in the field. They make the "logging in" part of the hacker's job much, much harder.

What Should You Do Right Now?

You need to take immediate action to ensure your team isn't the next victim of UNC6692.

First, send a company-wide alert. Let everyone know that Microsoft (or your IT provider) will never ask them to install a browser extension via Teams chat.

Second, consider a professional audit. Traditional antivirus often misses malicious extensions because they are "authorized" by the user during the click-through process. You need a team that knows how to look deeper into the browser environment.

Imagine a workforce working cohesively, where every employee is an extension of your security team. That starts with education and the right tech partner.

We’ve been helping NYC businesses navigate these traps for over 20 years. Don't let a "friendly chat" be the reason your company ends up in the news.

Stay safe, stay verified, and remember: if it feels "off," it probably is.


Meta Data Information:

  • Category: News
  • Tags: Cybersecurity, Microsoft Teams Phishing, UNC6692, SnowBelt Malware, IT Support NYC, Browser Extension Security, Joe’s Take
  • Meta Description: Hackers are using a new Microsoft Teams "Support" trap to install the SnowBelt backdoor. Learn how UNC6692 bypasses MFA and what Joe Silverman says you need to do to protect your NYC business.

Note: Some images in this article may be AI-generated.

Got any issues you'd like to address? Get in touch with our team for a free diagnosis.