# UNC6692

> As of 2026-05-30, UNC6692 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning malware. Also known as Snow Flurries. ATT&CK coverage spans 64 techniques across 11 tactics in 2 of 2 tracked threats. Most-observed techniques: T1018 (Remote System Discovery), T1020 (Automated Exfiltration), T1027 (Obfuscated Files or Information).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** MALWARE
- **Also known as:** Snow Flurries
- **As of:** 2026-05-30

## ATT&CK techniques observed

64 techniques observed across 2 of 2 tracked threats. Tactics: Execution (14), Command and Control (7), Credential Access (7), Stealth (formerly Defense Evasion) (7), Discovery (5), Lateral Movement (5).

- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1020](https://intel.threadlinqs.com/technique/T1020) Automated Exfiltration — Exfiltration — observed in 2 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1074](https://intel.threadlinqs.com/technique/T1074) Data Staged — Collection — observed in 2 of 2 tracked threats
- [T1090](https://intel.threadlinqs.com/technique/T1090) Proxy — Command and Control — observed in 2 of 2 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 2 of 2 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 2 of 2 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1202](https://intel.threadlinqs.com/technique/T1202) Indirect Command Execution — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1572](https://intel.threadlinqs.com/technique/T1572) Protocol Tunneling — Command and Control — observed in 2 of 2 tracked threats
- [T1583](https://intel.threadlinqs.com/technique/T1583) Acquire Infrastructure — Resource Development — observed in 2 of 2 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 2 tracked threats
- [T1003.001](https://intel.threadlinqs.com/technique/T1003.001) LSASS Memory — Credential Access — observed in 1 of 2 tracked threats
- [T1003.002](https://intel.threadlinqs.com/technique/T1003.002) Security Account Manager — Credential Access — observed in 1 of 2 tracked threats

## Tracked threats

- [UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams Helpdesk Impersonation (SNOWBELT/SNOWGLAZE/SNOWBASIN)](https://intel.threadlinqs.com/threat/TL-2026-0423) — HIGH
- [UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT / SNOWGLAZE / SNOWBASIN)](https://intel.threadlinqs.com/threat/TL-2026-0415) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UNC6692
