Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
April 27, 2026, 2:43 p.m.
Description
Google Threat Intelligence Group identified a sophisticated intrusion campaign by UNC6692 that combined persistent social engineering with custom malware. The attackers impersonated IT helpdesk personnel via Microsoft Teams, leveraging initial email spam campaigns to create urgency. Victims were tricked into downloading AutoHotKey scripts that installed SNOWBELT, a malicious browser extension establishing persistence through scheduled tasks. The modular SNOW ecosystem enabled deep network penetration: SNOWBELT provided initial access, SNOWGLAZE created encrypted WebSocket tunnels masking traffic as legitimate cloud communications, and SNOWBASIN functioned as a local backdoor for command execution. UNC6692 performed internal reconnaissance, escalated privileges by extracting LSASS memory, and used Pass-The-Hash techniques to access domain controllers. The operation culminated in exfiltration of Active Directory databases and credentials via LimeWire, demonstrating advanced tradecraft abusing legitimate clou...
Tags
Date
- Created: April 23, 2026, 7:25 p.m.
- Published: April 23, 2026, 7:25 p.m.
- Modified: April 27, 2026, 2:43 p.m.
Indicators
- 7f1d71e1e079f3244a69205588d504ed830d4c473747bb1b5c520634cc5a2477
- ca390b86793922555c84abc3b34406da2899382c617f9dcf83a74ac09dd18190
- 2fa987b9ed6ec6d09c7451abd994249dfaba1c5a7da1c22b8407c461e62f7e49
- c8940de8cb917abe158a826a1d08f1083af517351d01642e6c7f324d0bba1eb8
- 6e6dab993f99505646051d2772701e3c4740096ff9be63c92713bcb7fcddf9f7
- 691f7258f212fa8908a8bf06bcf9e027d2177276e13e10ff56bd434ff3755cc4
- de200b79ad2bd9db37baeba5e4d183498d450494c71c8929433681e848c3807f
Additional Informations
- G_Backdoor_SNOWBASIN_1
- G_Tunneler_SNOWGLAZE_1
- G_Backdoor_SNOWBELT_1