Hackers impersonate Microsoft Teams staff to deploy SNOW malware
…Once on a domain controller, Mandiant says UNC6692 uses FTK Imager to pull the Active Directory database file, along with Security Account Manager and SYSTEM registry hives, then exfiltrates everything via LimeWire…