# UNC6692 Snow Flurries — Microsoft Teams Helpdesk Impersonation Delivers SNOW Malware Suite (SNOWBELT / SNOWGLAZE / SNOWBASIN)

> Google Mandiant (GTIG) disclosed UNC6692, a newly tracked actor cluster that couples Microsoft Teams helpdesk impersonation with a custom modular SNOW malware ecosystem. The intrusion chain flooded victims with spam email, lured them into a Teams chat with a fake helpdesk account, directed them to an AWS S3-hosted phishing page that harvested credentials and deployed an AutoHotKey-driven Chromium extension backdoor (SNOWBELT), a Python WebSocket/SOCKS tunneler (SNOWGLAZE), and a Python HTTP bindshell (SNOWBASIN). The actor achieved domain-wide compromise via LSASS scraping, Pass-the-Hash lateral movement to domain controllers, FTK Imager abuse to dump NTDS.dit / SAM / SYSTEM / SECURITY hives, and LimeWire-based data exfiltration.

- **Published:** 2026-04-23T12:00:00Z
- **Last reviewed:** 2026-04-23T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0415
- **ID:** TL-2026-0415
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UNC6692 (Russia)
- **Detections:** 9 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Google Threat Intelligence Group (GTIG) and Mandiant published analysis on 2026-04-23 of a multistage intrusion campaign conducted by a newly tracked cluster, UNC6692, observed in late December 2025. The campaign, dubbed 'Snow Flurries' after the naming of the custom malware family, stands out for (a) a layered social engineering lure combining high-volume email bombing with Microsoft Teams helpdesk impersonation, (b) abuse of legitimate cloud services (AWS S3, Heroku) as payload, credential-exfiltration, and command-and-control infrastructure, and (c) a modular cross-platform malware ecosystem that uses a malicious Chromium browser extension as its primary foothold instead of a traditional native backdoor.

Initial access began with an email-bombing distraction campaign targeting selected users. The operator then contacted the victim via Microsoft Teams from an account external to the organization, posing as IT helpdesk offering to install a 'local patch' to stop the spam. The Teams message included a link of the form https://service-page-25144-30466-outlook.s3.us-west-2.amazonaws.com/update.html?email=<victim> — an AWS S3-hosted 'Mailbox Repair and Sync Utility v2.1.5' landing page. The page (a) gated execution on the presence of the ?email= parameter, redirecting to about:blank otherwise, (b) forced the victim into Microsoft Edge via the microsoft-edge: URI scheme with a persistent overlay warning, (c) harvested credentials twice through a 'Health Check' modal that intentionally rejected the first two attempts, PUTting them to an attacker-controlled S3 bucket, and (d) staged a renamed AutoHotKey binary (RegSrvc.exe) plus same-named AutoHotKey script, relying on AutoHotKey's behavior of auto-loading a sibling script with a matching name.

The AutoHotKey script installed SNOWBELT, a JavaScript-based Chromium browser extension sideloaded into headless Microsoft Edge from %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents, often labeled 'MS Heartbeat' or 'System Heartbeat'. Persistence was layered: a Startup-folder shortcut pointing at an AutoHotKey watchdog script, a Scheduled Task to launch headless Edge with --load-extension pointing at the SNOWBELT directory, and a second Scheduled Task that enumerates msedge.exe processes and terminates any lacking CoreUIComponents.dll — a heuristic for identifying and cleaning up stray headless instances.

SNOWBELT's background.js service worker generates a per-victim identity of the form fp-sw-<UUID>, then derives a time-based DGA registry URL scoped to 30-minute slots from the hard-coded seed 691f7258f212fa8908a8bf06bcf9e027d2177276e13e10ff56bd434ff3755cc4. The URL pattern is https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws.com. Manifests fetched from that registry are decrypted via AES-GCM using a key derived from SHA256(SEED + '|' + timeslot). For low-latency tasking, SNOWBELT registers with the browser's Push Notification service using the VAPID public key BJkWCT45mL0uvV3AssRaq9Gn7iE2N7Lx38ZmWDFCjwhz0zv0QSVhKuZBLTTgAijB12cgzMzqyiJZr5tokRzSJu0, enabling the operator to wake the Service Worker asynchronously without polling. A persistent REGISTRY_WEBSOCKET_URL connection is also maintained. Exfiltration uploads are AES-GCM encrypted with a keying scheme SHA256(SEED + '|ping|' + bucket + '|' + objectKey) before being PUT to S3 via the sendJsonDataToS3 routine. Sandbox bypasses include a native-messaging host bridge (open_native_messaging via chrome.runtime.connectNative) and a protocol-handler abuse primitive (open_uri via dream.html / dream.js) that can invoke arbitrary URI schemes. SNOWBELT also monitors chrome.downloads.onChanged to report blocked downloads (e.g., FILE_VIRUS_INFECTED) back to the C2, providing defender-telemetry feedback.

SNOWBELT relays six operational commands (command, buffer, flush, commit, stop_server, screenshot) to SNOWBASIN, a Python HTTP bindshell staged on disk at C:\ProgramData\log that listens on localhost:8000 (fallback 8001, 8002). SNOWBASIN exposes /stream (cmd.exe or powershell.exe execution), /buffer (file exfil / directory listing), /flush (buffer drain), /commit (file ingress, CERT_NONE HTTPS fetch), /capture (mss + PIL multi-monitor screenshot to base64), and /gc (self-termination). SNOWGLAZE is the network glue — a Python tunneler (also at C:\ProgramData\log) that opens a WebSocket to wss://sad4w7h913-b4a57f9c36eb.herokuapp.com:443/ws with a Microsoft Edge User-Agent, authenticates with hard-coded login/password/uuid, and exposes SOCKS-over-WebSocket proxying with socks_connect / socks_data / socks_close / disconnect message types. All SOCKS payloads are Base64 encapsulated inside JSON.

Post-compromise, UNC6692 ran a Python port scanner for 135/445/3389 on the local subnet, used SNOWGLAZE as a SOCKS tunnel to PsExec into the victim, enumerated local administrators, and RDP'd into a backup server. On the backup server the operator used Windows Task Manager to dump the LSASS process memory and exfiltrated the dump via LimeWire — offloading credential extraction to their offline environment to avoid on-host EDR triggers. The recovered NTLM hashes were used for Pass-the-Hash to the Domain Controller, where the operator opened headless Edge, downloaded an FTK Imager ZIP to the Domain Administrator's Downloads folder, mounted the local drive, and wrote NTDS.dit, SAM, SYSTEM, and SECURITY registry hives to disk before exfiltrating via LimeWire a second time. Screen captures specifically framing in-focus Microsoft Edge and FTK Imager windows were logged by EDR during this final stage.

AWS, in collaboration with Mandiant, took down the attacker-controlled S3 buckets. The Heroku tunnel endpoint sad4w7h913-b4a57f9c36eb.herokuapp.com has been reported. The campaign illustrates 'living off the cloud' tradecraft: the attacker's C2, staging, exfiltration, and credential-harvest infrastructure all rode reputable cloud domains, defeating simple reputation-based filtering. Detection opportunities now shift to browser telemetry (unsanctioned extensions, unexpected headless Edge), unusual Python HTTP listeners on localhost, outbound WebSockets to PaaS hosts, FTK Imager execution on DCs, and LSASS memory access by Task Manager (taskmgr.exe).

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608.002 Stage Capabilities: Upload Tool
- T1608.005 Stage Capabilities: Link Target
- T1566.002 Phishing: Spearphishing Link
- T1566.003 Phishing: Spearphishing via Service
- T1204.001 User Execution: Malicious Link
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1059.006 Command and Scripting Interpreter: Python
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1059.010 Command and Scripting Interpreter: AutoHotKey & AutoIT
- T1053.005 Scheduled Task/Job: Scheduled Task
- T1559 Inter-Process Communication
- T1569.002 Service Execution
- T1176.001 Browser Extensions
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1547.009 Boot or Logon Autostart Execution: Shortcut Modification
- T1027 Obfuscated Files or Information
- T1027.010 Obfuscated Files or Information: Command Obfuscation
- T1036.005 Masquerading: Match Legitimate Resource Name or Location
- T1140 Deobfuscate/Decode Files or Information
- T1202 Indirect Command Execution
- T1003.001 OS Credential Dumping: LSASS Memory
- T1003.002 OS Credential Dumping: Security Account Manager
- T1003.003 OS Credential Dumping: NTDS
- T1555 Credentials from Password Stores
- T1552.001 Unsecured Credentials: Credentials In Files
- T1087.001 Account Discovery: Local Account
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1082 System Information Discovery
- T1021.001 Remote Services: Remote Desktop Protocol
- T1021.002 Remote Services: SMB/Windows Admin Shares
- T1550.002 Use Alternate Authentication Material: Pass the Hash
- T1005 Data from Local System
- T1074 Data Staged
- T1113 Screen Capture
- T1071.001 Application Layer Protocol: Web Protocols
- T1090 Proxy

## Sources

- [Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite](https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/)
- [MITRE ATT&CK: T1566.002 Phishing — Spearphishing Link](https://attack.mitre.org/techniques/T1566/002/)
- [MITRE ATT&CK: T1176.001 Browser Extensions](https://attack.mitre.org/techniques/T1176/001/)
- [MITRE ATT&CK: T1003.003 OS Credential Dumping — NTDS](https://attack.mitre.org/techniques/T1003/003/)
- [MITRE ATT&CK: T1059.010 Command and Scripting Interpreter — AutoHotKey & AutoIT](https://attack.mitre.org/techniques/T1059/010/)
- [MITRE ATT&CK: T1572 Protocol Tunneling](https://attack.mitre.org/techniques/T1572/)
- [Microsoft Teams External Access configuration](https://learn.microsoft.com/en-us/microsoftteams/manage-external-access)
- [Microsoft Defender ASR Rule: Block credential stealing from lsass.exe](https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference)
- [LOLBAS Project entry: AutoHotKey (script auto-load behavior)](https://lolbas-project.github.io/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0415
