
Two separate threat disclosures dropped this week that, read together, describe the same underlying problem: attackers have figured out that your collaboration stack is softer than your firewall. UNC6692 is using Microsoft Teams to deliver a custom malware suite called Snow, while the China-linked APT group GopherWhisper is tunneling its command-and-control traffic through legitimate cloud services to stay invisible inside government networks. Neither of these campaigns requires a zero-day. Both of them require you to rethink where your defensive perimeter actually sits — and what ipban and edge-layer controls can realistically catch when the payload arrives wrapped in a trusted brand.
What Snow and GopherWhisper Are Actually Doing to Your Environment
The Snow campaign, attributed to UNC6692, starts with a Teams message — usually a social engineering lure impersonating IT support or an internal helpdesk. Once the target interacts, they’re guided into installing a malicious browser extension, a network tunneler, and a backdoor. That’s not one payload; that’s a complete capability suite delivered in a single session. The browser extension harvests credentials and session tokens. The tunneler handles covert connectivity. The backdoor persists. By the time your SIEM flags something unusual, the attacker already has everything they need to move laterally without ever touching a traditional attack surface.
GopherWhisper is operating differently but arriving at the same destination. The group — assessed as China-linked — relies on Go-based backdoors paired with custom loaders that blend C2 traffic into legitimate service traffic. Slack channels, cloud storage APIs, developer platforms: all of them become communication paths that look indistinguishable from normal business activity at the packet level. Government agencies in particular are being targeted, which suggests the primary objective is persistent access and data exfiltration, not ransomware.
The common thread isn’t the malware family or the nation-state attribution. It’s the deliberate choice to route intrusions through channels that your security team has implicitly trusted. Your firewall isn’t blocking Teams. Your proxy isn’t flagging Slack API calls. Your endpoint agent might catch Snow’s installer — or it might not, depending on how the extension is delivered. That trust gap is the attack surface both groups are exploiting.
Why Perimeter Controls See These Attacks Late — and What They Still Catch
There’s a tempting conclusion here that perimeter defense is useless against collaboration-layer attacks. That’s wrong, but the nuance matters. Traditional firewall rules and IP-based blocking don’t operate at the application semantics layer — they can’t read a Teams message and decide it’s malicious. What they can do is disrupt the post-compromise infrastructure that both Snow and GopherWhisper depend on to function.
Snow’s tunneler has to call home. The backdoor needs to beacon to infrastructure that, however carefully staged, eventually resolves to IP ranges or domains that threat intelligence feeds can identify. GopherWhisper’s Go-based backdoors, when analyzed, reveal staging servers and relay nodes that are detectable at the network layer. This is where ipban-style automated blocking and firewall controls earn their keep — not at preventing the initial social engineering, but at severing the command-and-control lifeline before the attacker can act on their access.
The operational reality is that these attacks unfold in phases. The first phase — luring the user — is a people and policy problem. The second phase — malware execution — is an endpoint problem. The third phase — C2 beaconing and lateral movement — is a network problem, and it’s the phase where perimeter threat detection and automated response can still disrupt the kill chain before real damage is done. Treating those layers as independent rather than complementary is how defenders end up chasing incidents after the fact.

Concrete Steps for Incident Responders Seeing These Indicators
If you’re actively investigating a potential Snow or GopherWhisper-style compromise, or if you’re hardening against this class of attack, the following steps are ordered by what you can do right now versus what requires longer lead time.
- Audit third-party app permissions in Teams and Slack immediately. Both platforms allow external apps and bots. Pull a full list, remove anything unrecognized, and enforce allow-listing through your admin console.
- Hunt for anomalous browser extensions across your fleet. Centrally managed browsers can report installed extensions. Look for anything installed outside your approved baseline — particularly extensions with broad permissions like “read and change all data on websites you visit.”
- Block outbound connections to uncommon ports and flag new external DNS resolutions. Snow’s tunneler and GopherWhisper’s C2 infrastructure both require outbound connectivity. DNS logging combined with egress filtering on non-standard ports will surface beaconing activity that’s otherwise invisible.
- Check for Go-compiled binaries in user-writable directories. GopherWhisper’s toolchain relies on Go-based loaders. Presence of unsigned, recently dropped Go binaries in temp folders, AppData, or user profile directories is a high-fidelity indicator.
- Pull and review conditional access logs for Teams sessions originating from unexpected geolocations or devices. Social engineering works better when the attacker can impersonate a known colleague’s context. Session anomalies often appear in access logs before endpoint telemetry catches up.
- Feed known Snow and GopherWhisper infrastructure IOCs into your firewall and DNS blocklists. Bleeping Computer and SecurityWeek have both published associated infrastructure details. Getting those into your block lists within hours of disclosure is standard hygiene — treat it as mandatory.
On the ongoing side: your response playbook needs a dedicated branch for collaboration-platform compromise. Most IR playbooks still treat the network as the primary entry point. That assumption is getting organizations hurt in 2026. A Teams-originated compromise needs a different initial triage path than a VPN credential spray — the evidence trail is different, the containment steps are different, and the scope of potential credential exposure is broader.
Security Hardening That Makes This Class of Attack More Expensive for Attackers
The single most effective structural change you can make right now is reducing implicit trust in collaboration platforms at the configuration level. That means enforcing external tenant restrictions in Teams so users can’t receive messages from arbitrary outside organizations. It means requiring admin approval for any application that integrates with your productivity suite. It means treating browser extensions as software deployments — vetted, approved, and centrally managed — rather than as user preferences.
Defense in depth still applies, even when the attack surface is a chat window. GopherWhisper’s success in government environments isn’t because those networks lack security tooling. It’s because the tooling was tuned for traditional network intrusions and the attackers adapted their infrastructure to blend into approved traffic patterns. The security hardening response isn’t to buy a new product — it’s to close the configuration gaps that make legitimate services exploitable, layer your detection across the network, endpoint, and application tiers, and make sure your automated response controls can act on threat intelligence within minutes, not days.
Brute-force and credential stuffing attacks at the perimeter remain real and ongoing — automated IP blocking and rate-limiting still absolutely belong in your stack. But if Snow and GopherWhisper tell us anything, it’s that the front door isn’t where every fight starts anymore. Your collaboration tools are infrastructure. Secure them like it.
Frequently Asked Questions
- Can a firewall or IP blocking tool stop the Snow malware campaign?
- Not at the initial access phase — Snow enters through social engineering in Teams, which is trusted traffic. Firewall and IP-blocking controls become relevant in the post-compromise phase, where Snow’s tunneler and backdoor need to beacon to external C2 infrastructure. Blocking known malicious IPs and flagging anomalous outbound connections can still disrupt the attack before damage is done.
- What makes GopherWhisper hard to detect compared to typical APT campaigns?
- GopherWhisper deliberately routes C2 traffic through legitimate cloud and SaaS platforms, making it look like normal business activity at the packet level. Its Go-based backdoors are also relatively easy to recompile with new signatures, reducing the effectiveness of hash-based detection. Behavioral detection — looking at what processes are doing rather than what they look like — is more reliable against this toolchain.
- Is Microsoft Teams inherently unsafe for enterprise use?
- No, but it requires active configuration hardening to be safe. By default, Teams allows inbound messages from external tenants, which is the primary vector UNC6692 exploits. Restricting external access, enforcing app approval policies, and enabling anomaly alerting on session activity significantly reduces the attack surface without limiting legitimate functionality.
Sources
- Threat actor uses Microsoft Teams to deploy new “Snow” malware — BleepingComputer
- China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks — SecurityWeek
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
