Threat reportMalwareTL-2026-0415

UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT / SNOWGLAZE / SNOWBASIN)

highACTIVE

UNC6692 Snow Flurries (TL-2026-0415), also tracked as Snow Flurries, is a high-severity malware campaign, first published 2026-04-23. It is attributed to UNC6692 (Russia) with medium confidence, affects Microsoft Microsoft Teams, maps to 47 MITRE ATT&CK techniques (T1003.001, T1003.002, T1003.003), and is covered by 9 detection rules and 40 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
47MITRE ATT&CK
Actors
1UNC6692
Detection rules
9SPL · KQL · Sigma
IOCs
40Indicators of compromise

Key facts for TL-2026-0415

Threat ID
TL-2026-0415
Also known as
Snow Flurries, SNOW Ecosystem, SNOWBELT Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UNC6692
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
UNKNOWN
Target sectors
enterprise, technology
Target regions
Global
Detection rules
9
Indicators of compromise
40

Malware and tooling in UNC6692 Snow Flurries

Malware and tooling: SNOWBASIN, SNOWBELT, SNOWGLAZE, AutoHotKey, FTK Imager, LimeWire, SNOW Custom Ecosystem (SNOWBELT + SNOWGLAZE + SNOWBASIN), Sysinternals PsExec

How UNC6692 Snow Flurries works

Google Mandiant (GTIG) disclosed UNC6692, a newly tracked actor cluster that couples Microsoft Teams helpdesk impersonation with a custom modular SNOW malware ecosystem. The intrusion chain flooded victims with spam email, lured them into a Teams chat with a fake helpdesk account, directed them to an AWS S3-hosted phishing page that harvested credentials and deployed an AutoHotKey-driven Chromium extension backdoor (SNOWBELT), a Python WebSocket/SOCKS tunneler (SNOWGLAZE), and a Python HTTP bindshell (SNOWBASIN). The actor achieved domain-wide compromise via LSASS scraping, Pass-the-Hash lateral movement to domain controllers, FTK Imager abuse to dump NTDS.dit / SAM / SYSTEM / SECURITY hives, and LimeWire-based data exfiltration.

Google Threat Intelligence Group (GTIG) and Mandiant published analysis on 2026-04-23 of a multistage intrusion campaign conducted by a newly tracked cluster, UNC6692, observed in late December 2025. The campaign, dubbed 'Snow Flurries' after the naming of the custom malware family, stands out for (a) a layered social engineering lure combining high-volume email bombing with Microsoft Teams helpdesk impersonation, (b) abuse of legitimate cloud services (AWS S3, Heroku) as payload, credential-exfiltration, and command-and-control infrastructure, and (c) a modular cross-platform malware ecosystem that uses a malicious Chromium browser extension as its primary foothold instead of a traditional native backdoor.

Initial access began with an email-bombing distraction campaign targeting selected users. The operator then contacted the victim via Microsoft Teams from an account external to the organization, posing as IT helpdesk offering to install a 'local patch' to stop the spam. The Teams message included a link of the form https://service-page-25144-30466-outlook.s3.us-west-2.amazonaws.com/update.html?email=<victim> — an AWS S3-hosted 'Mailbox Repair and Sync Utility v2.1.5' landing page. The page (a) gated execution on the presence of the ?email= parameter, redirecting to about:blank otherwise, (b) forced the victim into Microsoft Edge via the microsoft-edge: URI scheme with a persistent overlay warning, (c) harvested credentials twice through a 'Health Check' modal that intentionally rejected the first two attempts, PUTting them to an attacker-controlled S3 bucket, and (d) staged a renamed AutoHotKey binary (RegSrvc.exe) plus same-named AutoHotKey script, relying on AutoHotKey's behavior of auto-loading a sibling script with a matching name.

The AutoHotKey script installed SNOWBELT, a JavaScript-based Chromium browser extension sideloaded into headless Microsoft Edge from %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents, often labeled 'MS Heartbeat' or 'System Heartbeat'. Persistence was layered: a Startup-folder shortcut pointing at an AutoHotKey watchdog script, a Scheduled Task to launch headless Edge with --load-extension pointing at the SNOWBELT directory, and a second Scheduled Task that enumerates msedge.exe processes and terminates any lacking CoreUIComponents.dll — a heuristic for identifying and cleaning up stray headless instances.

SNOWBELT's background.js service worker generates a per-victim identity of the form fp-sw-<UUID>, then derives a time-based DGA registry URL scoped to 30-minute slots from the hard-coded seed 691f7258f212fa8908a8bf06bcf9e027d2177276e13e10ff56bd434ff3755cc4. The URL pattern is https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws.com. Manifests fetched from that registry are decrypted via AES-GCM using a key derived from SHA256(SEED + '|' + timeslot). For low-latency tasking, SNOWBELT registers with the browser's Push Notification service using the VAPID public key BJkWCT45mL0uvV3AssRaq9Gn7iE2N7Lx38ZmWDFCjwhz0zv0QSVhKuZBLTTgAijB12cgzMzqyiJZr5tokRzSJu0, enabling the operator to wake the Service Worker asynchronously without polling. A persistent REGISTRY_WEBSOCKET_URL connection is also maintained. Exfiltration uploads are AES-GCM encrypted with a keying scheme SHA256(SEED + '|ping|' + bucket + '|' + objectKey) before being PUT to S3 via the sendJsonDataToS3 routine. Sandbox bypasses include a native-messaging host bridge (open_native_messaging via chrome.runtime.connectNative) and a protocol-handler abuse primitive (open_uri via dream.html / dream.js) that can invoke arbitrary URI schemes. SNOWBELT also monitors chrome.downloads.onChanged to report blocked downloads (e.g., FILE_VIRUS_INFECTED) back to the C2, providing defender-telemetry feedback.

SNOWBELT relays six operational commands (command, buffer, flush, commit, stop_server, screenshot) to SNOWBASIN, a Python HTTP bindshell staged on disk at C:\ProgramData\log that listens on localhost:8000 (fallback 8001, 8002). SNOWBASIN exposes /stream (cmd.exe or powershell.exe execution), /buffer (file exfil / directory listing), /flush (buffer drain), /commit (file ingress, CERT_NONE HTTPS fetch), /capture (mss + PIL multi-monitor screenshot to base64), and /gc (self-termination). SNOWGLAZE is the network glue — a Python tunneler (also at C:\ProgramData\log) that opens a WebSocket to wss://sad4w7h913-b4a57f9c36eb.herokuapp.com:443/ws with a Microsoft Edge User-Agent, authenticates with hard-coded login/password/uuid, and exposes SOCKS-over-WebSocket proxying with socks_connect / socks_data / socks_close / disconnect message types. All SOCKS payloads are Base64 encapsulated inside JSON.

Post-compromise, UNC6692 ran a Python port scanner for 135/445/3389 on the local subnet, used SNOWGLAZE as a SOCKS tunnel to PsExec into the victim, enumerated local administrators, and RDP'd into a backup server. On the backup server the operator used Windows Task Manager to dump the LSASS process memory and exfiltrated the dump via LimeWire — offloading credential extraction to their offline environment to avoid on-host EDR triggers. The recovered NTLM hashes were used for Pass-the-Hash to the Domain Controller, where the operator opened headless Edge, downloaded an FTK Imager ZIP to the Domain Administrator's Downloads folder, mounted the local drive, and wrote NTDS.dit, SAM, SYSTEM, and SECURITY registry hives to disk before exfiltrating via LimeWire a second time. Screen captures specifically framing in-focus Microsoft Edge and FTK Imager windows were logged by EDR during this final stage.

AWS, in collaboration with Mandiant, took down the attacker-controlled S3 buckets. The Heroku tunnel endpoint sad4w7h913-b4a57f9c36eb.herokuapp.com has been reported. The campaign illustrates 'living off the cloud' tradecraft: the attacker's C2, staging, exfiltration, and credential-harvest infrastructure all rode reputable cloud domains, defeating simple reputation-based filtering. Detection opportunities now shift to browser telemetry (unsanctioned extensions, unexpected headless Edge), unusual Python HTTP listeners on localhost, outbound WebSockets to PaaS hosts, FTK Imager execution on DCs, and LSASS memory access by Task Manager (taskmgr.exe).

MITRE ATT&CK techniques used in TL-2026-0415

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory; T1003.002 OS Credential Dumping: Security Account Manager; T1003.003 OS Credential Dumping: NTDS; T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores

Collection

T1005 Data from Local System; T1074 Data Staged; T1113 Screen Capture

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087.001 Account Discovery: Local Account

Exfiltration

T1020 Automated Exfiltration; T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol; T1021.002 Remote Services: SMB/Windows Admin Shares; T1550.002 Use Alternate Authentication Material: Pass the Hash

Defense Evasion

T1027 Obfuscated Files or Information; T1027.010 Obfuscated Files or Information: Command Obfuscation; T1036.005 Masquerading: Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution

Execution

T1053.005 Scheduled Task/Job: Scheduled Task; T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript; T1059.010 Command and Scripting Interpreter: AutoHotKey & AutoIT; T1204.001 User Execution: Malicious Link; T1204.002 User Execution: Malicious File; T1559 Inter-Process Communication; T1569.002 Service Execution

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1568.002 Dynamic Resolution: Domain Generation Algorithms; T1572 Protocol Tunneling; T1573.001 Symmetric Cryptography

Persistence

T1176.001 Browser Extensions; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder; T1547.009 Boot or Logon Autostart Execution: Shortcut Modification

Initial Access

T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service

Resource Development

T1583 Acquire Infrastructure; T1608.002 Stage Capabilities: Upload Tool; T1608.005 Stage Capabilities: Link Target

Affected products and versions in UNC6692 Snow Flurries

  • Microsoft — Microsoft Teams
    Vulnerable versions: All tenants allowing external federation
  • Microsoft — Microsoft Edge (Chromium)
    Vulnerable versions: All versions supporting --load-extension and --headless=new
  • Microsoft — Windows Active Directory (Domain Controllers)
    Vulnerable versions: All Windows Server versions where NTDS.dit is readable via FTK Imager offline mount
  • Google — Chromium browsers (extension platform)
    Vulnerable versions: Any Chromium-based browser that permits --load-extension sideloading

Remediation for UNC6692 Snow Flurries

Patches

  • No patch — this is a malware/social-engineering campaign, not a CVE. Mitigations are configuration and detection-based.

Immediate actions

  • Block all observed SNOW IOCs at egress: service-page-25144-30466-outlook.s3.us-west-2.amazonaws.com, cloudfront-021.s3.us-west-2.amazonaws.com, service-page-11369-28315-outlook.s3.us-west-2.amazonaws.com, service-page-18968-2419-outlook.s3.us-west-2.amazonaws.com, sad4w7h913-b4a57f9c36eb.herokuapp.com
  • Restrict Microsoft Teams external federation: disable external chat/federation by default, or allow-list only known-trusted tenants via Teams Admin Center (External Access policy).
  • Alert on any Chromium extension loaded via --load-extension= or from %LOCALAPPDATA%\Microsoft\Edge\Extension Data outside of the managed extension allowlist; block ExtensionInstallSources via GPO/Intune and enforce ExtensionInstallAllowlist.
  • Hunt for headless msedge.exe processes (--headless=new) with --load-extension= arguments and kill any that are not part of an approved automation workflow.
  • Hunt for AutoHotKey (AutoHotkey.exe or renamed variants such as RegSrvc.exe) launched from user %TEMP% / %LOCALAPPDATA% / Downloads directories.
  • Hunt for Python processes listening on localhost:8000/8001/8002 and Python WebSocket client traffic to *.herokuapp.com.
  • Block FTK Imager (FTK*.exe, AccessData) execution on Domain Controllers; alert on any non-forensic workstation execution.
  • Force password reset and invalidate Kerberos TGTs (KRBTGT double-reset) for any environment where NTDS.dit exfiltration is suspected.
  • Reset all local administrator account passwords; deploy LAPS if not already in place.

Workarounds

  • Temporarily disable Microsoft Teams federation with external tenants via Teams Admin Center -> External Access -> 'Block all external domains' or allow-list mode until inspection is in place.
  • Enforce Edge group policy BrowserAddProfileEnabled = 0 and ExtensionInstallSources = [] to prevent arbitrary extension sideloading.
  • Block outbound traffic to herokuapp.com and *.s3.us-east-2.amazonaws.com / *.s3.us-west-2.amazonaws.com at TLS inspection unless the bucket is known-good.

Longer-term hardening

  • Deploy browser-extension management policy across Edge and Chrome using ExtensionInstallAllowlist / ExtensionInstallBlocklist / ExtensionSettings with force_installed managed extensions only.
  • Disable or tightly scope the microsoft-edge: URI handler from web content in non-browser contexts where possible.
  • Introduce helpdesk-impersonation user awareness training emphasizing that IT never contacts users via external Teams invitations and always identifies via verified channels.
  • Enforce phishing-resistant MFA (FIDO2/WebAuthn) on all corporate identities; deprecate password-only Teams federation flows.
  • Deploy Attack Surface Reduction rule 'Block credential stealing from the Windows local security authority subsystem (lsass.exe)' via Microsoft Defender for Endpoint.
  • Implement LSASS PPL (RunAsPPL) and Credential Guard on domain-joined endpoints, especially servers.
  • Tier 0 isolation: domain controllers must not have internet egress; block direct DC->Internet and DC->S3/Heroku routes at the firewall.
  • Enable EDR browser-telemetry sensors that inspect Service Worker registrations, chrome.runtime.connectNative usage, and extension-level network activity.
  • Monitor for FTK Imager, LimeWire, PsExec, and Sysinternals usage outside of authorized admin workstations via allowlist software inventory.

Timeline of UNC6692 Snow Flurries

  • UNC6692 begins high-volume email spam campaign against selected targets to create urgency and distraction (late December 2025, per Mandiant).
  • Scheduled Tasks created to (a) launch headless Edge with --load-extension pointing at SNOWBELT and (b) kill msedge.exe processes lacking CoreUIComponents.dll; Startup-folder shortcut added to re-launch SNOWBELT watchdog.
  • AutoHotKey binary (RegSrvc.exe / Protected.ahk) plus sibling script delivered from S3; AutoHotKey auto-loads the sibling script and installs SNOWBELT Chromium extension into %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents.
  • Victim clicks Teams link to service-page-25144-30466-outlook.s3.us-west-2.amazonaws.com/update.html?email=<redacted>; landing page gates on ?email=, forces Edge via microsoft-edge: URI, harvests credentials via 'Health Check' modal.
  • Operator contacts victim via Microsoft Teams from an external-tenant account posing as IT helpdesk offering a 'local patch' to stop the email spam.
  • On backup server, Windows Task Manager used to dump LSASS process memory; dump exfiltrated via LimeWire peer-to-peer client to operator infrastructure for offline credential extraction.
  • Python port scanner enumerates 135/445/3389 on local subnet; SNOWGLAZE WebSocket tunnel to sad4w7h913-b4a57f9c36eb.herokuapp.com established; PsExec used to pivot via SNOWGLAZE SOCKS; RDP to backup server.
  • FTK Imager mounts local drive; NTDS.dit, SAM, SYSTEM, and SECURITY registry hives written to \Downloads folder; files exfiltrated via LimeWire. EDR logs screen captures framing Edge and FTK Imager windows.
  • Pass-the-Hash with extracted NTLM hashes against Domain Controller; operator opens headless Edge on DC, downloads FTK Imager ZIP to Domain Administrator's Downloads folder.
  • Threadlinqs Intelligence ingests TL-2026-0415; BeaconBeagle correlation and detection engineering kicked off.
  • Google Mandiant / GTIG publishes 'Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite' with full SNOW ecosystem analysis, YARA rules, and IOCs. AWS confirms takedown of attacker S3 buckets.
  • As of 2026-05-29, UNC6692's "Snow Flurries" SNOW malware campaign (Teams helpdesk impersonation, no CVE) remains active and ongoing per Mandiant/GTIG and May 2026 reporting, with incidents escalating Mar-Apr 2026 (77% targeting senior leaders). AWS sinkholed some S3 buckets, but the actor, SNOW tooling, and tradecraft persist with no arrests or takedown.

Sources cited for UNC6692 Snow Flurries

Detection coverage for TL-2026-0415

As of 2026-04-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0415 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
40 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats