● BREAKING
Black Basta affiliates pivoting to Microsoft Teams for initial access. Incident Report: Help desk impersonation leads to full compromise in 12 minutes. M365 Identity: 130,000 compromised devices identified in latest password spraying botnet. Black Basta affiliates pivoting to Microsoft Teams for initial access. Incident Report: Help desk impersonation leads to full compromise in 12 minutes. M365 Identity: 130,000 compromised devices identified in latest password spraying botnet.
VOL.01 · ISSUE №1 — a security engineer's obsession with the why and the how — TUE · 05 MAY 2026
INCIDENT RESPONSE

The 12-Minute Help Desk: Tracking the SNOW Suite

A technical deep dive into Teams-based impersonation, vishing automation, and the SNOW malware ecosystem used by former Black Basta affiliates.

Read →
# dwell-time analysis
$ grep -E "BackupSvc.*POST" access.log
...368 days of legitimate-looking writes
found: 1 anomaly
## ~/posts $ ls -lt

The feed