Threat reportMalwareTL-2026-0423
UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams Helpdesk Impersonation (SNOWBELT/SNOWGLAZE/SNOWBASIN)
UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams (TL-2026-0423), also tracked as Snow Flurries, is a high-severity malware campaign, first published 2026-04-25. It is attributed to UNC6692 (Russia) with medium confidence, affects Microsoft Microsoft Teams, maps to 29 MITRE ATT&CK techniques (T1003, T1016, T1018), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 29MITRE ATT&CK
- Actors
- 1UNC6692
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-0423
- Threat ID
- TL-2026-0423
- Also known as
- Snow Flurries, SNOW Malware Suite
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- UNC6692
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- UNKNOWN
- Target sectors
- enterprise, technology, professional-services
- Target regions
- North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams
Malware and tooling: SNOW, SNOWBASIN, SNOWBELT, SNOWGLAZE, LimeWire, Sysinternals PsExec
How UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams works
Newly tracked threat cluster UNC6692 abuses Microsoft Teams chat invitations to impersonate IT helpdesk staff and deploy a custom modular malware suite — SNOWBELT (JavaScript Edge browser-extension backdoor), SNOWGLAZE (Python WebSocket SOCKS tunneler), and SNOWBASIN (Python local HTTP bindshell) — leading to LSASS dumping, NTDS.dit theft via FTK Imager, pass-the-hash to domain controllers, and exfiltration via LimeWire to attacker-controlled AWS S3 buckets and a Heroku-hosted WebSocket C2.
On 2026-04-23, Google Threat Intelligence Group (GTIG/Mandiant) published 'Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite,' detailing intrusions in which UNC6692 — a previously undocumented activity cluster — abused Microsoft Teams external chat invitations to compromise enterprise endpoints. The campaign begins with an email-bombing distraction phase: the actor floods a target's inbox with thousands of subscription/spam emails to manufacture urgency. Within minutes, the victim receives a Microsoft Teams chat invitation from an account outside their tenant impersonating internal IT helpdesk personnel offering to remediate the spam flood. The lure directs the user to a phishing landing page (update.html / 'Mailbox Repair Utility') hosted on attacker-controlled S3 buckets such as service-page-25144-30466-outlook.s3.us-west-2.amazonaws.com.
The phishing page uses a double-entry psychological trick: the first two credential submissions are silently rejected to entice the user to retype the password (mitigating typos) before harvesting them to a separate S3 bucket (service-page-18968-2419-outlook.s3.us-west-2.amazonaws.com, since taken down). Simultaneously, an AutoHotKey binary masquerading as 'Registration Service' (RegSrvc.exe) and an obfuscated Protected.ahk script are downloaded. The AHK loader drops a configuration file (profileB5.txt) and stages the SNOW toolset.
SNOWBELT is a Chromium browser-extension backdoor (background.js, dream.js, dream.html, helper.html) installed under %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents and loaded by a headless Microsoft Edge instance launched from scheduled tasks: msedge.exe --user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\System Data --headless=new --load-extension=%LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents --no-first-run --disable-sync. SNOWBELT generates a Service-Worker UUID prefixed 'fp-sw-', registers a hard-coded VAPID public key (BJkWCT45mL0uvV3AssRaq9Gn7iE2N7Lx38ZmWDFCjwhz0zv0QSVhKuZBLTTgAijB12cgzMzqyiJZr5tokRzSJu0) for push notifications, and resolves time-slotted (30-minute window) S3 C2 URLs via a DGA seeded with 691f7258f212fa8908a8bf06bcf9e027d2177276e13e10ff56bd434ff3755cc4 producing https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws.com endpoints. Payloads are AES-GCM encrypted with keys derived as SHA256(SEED + '|' + timeslot) and exfiltration objects encrypted as SHA256(SEED + '|ping|' + bucket + '|' + objectKey). Three companion scheduled tasks ensure persistence: (1) start headless Edge with the extension, (2) verify SNOWBELT is running, (3) terminate any Edge processes lacking CoreUIComponents.dll to clean up artifacts. A Startup-folder shortcut to the AHK script provides additional persistence.
SNOWGLAZE is a Python (Windows + Linux) tunneler that opens an authenticated WebSocket to wss://sad4w7h913-b4a57f9c36eb.herokuapp.com:443/ws and provides bidirectional Base64-wrapped SOCKS-over-WS forwarding (commands: socks_connect, socks_data, socks_close, ping/pong, agent_public_ip, disconnect) with a 5-300s exponential retry. The actor uses SNOWGLAZE to pivot a PsExec session to the victim host and tunnel an RDP session from the victim to a backup server.
SNOWBASIN is a Python multi-threaded HTTP bindshell that selects ports 8000/8001/8002 and exposes /probe, /stream (cmd.exe and powershell.exe execution), /buffer (file/dir staging), /flush, /commit (download attacker-supplied file URLs), /capture (mss/PIL screenshots), and /gc (self-termination). SNOWBELT receives commands from S3 polling and relays them to SNOWBASIN via 'command', 'buffer', 'flush', 'commit', 'stop_server', and 'screenshot' opcodes; SNOWBELT-internal opcodes include 'payload' (chrome.downloads), 'open_native_messaging', 'open_uri', 'delete_cache', 'websocket_control', and 'ping'.
Post-compromise, UNC6692 runs a Python network scanner against TCP/135, TCP/445, and TCP/3389 to identify lateral targets. The actor dumps LSASS process memory using the Windows Task Manager 'Create dump file' feature, exfiltrates the dump via LimeWire for offline credential extraction, then performs pass-the-hash to reach domain controllers. On the DC, FTK Imager is downloaded into a Domain Admin Downloads folder and used to extract NTDS.dit along with SAM, SYSTEM, and SECURITY registry hives — again exfiltrated via LimeWire. Domain controller screenshots are captured via SNOWBASIN. No specific industry vertical or geography is named; targeting tracks senior-level executives in enterprise environments.
MITRE ATT&CK techniques used in TL-2026-0423
Credential Access
T1003 OS Credential Dumping; T1056 Input Capture
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery
Exfiltration
T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service
Lateral Movement
T1021 Remote Services; T1550 Use Alternate Authentication Material
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1564 Hide Artifacts
Execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution; T1569 System Services
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
Collection
T1074 Data Staged; T1113 Screen Capture
Persistence
T1176 Software Extensions; T1547 Boot or Logon Autostart Execution
Initial Access
Resource Development
Affected products and versions in UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams
- Microsoft — Microsoft Teams
Vulnerable versions: all tenants permitting unsolicited external chat invitations - Microsoft — Microsoft Edge (Chromium)
Vulnerable versions: all current versions when headless extension loading is permitted - Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11; Windows Server 2019; Windows Server 2022 - Microsoft — Active Directory Domain Services
Vulnerable versions: domains where NTDS.dit is reachable to a Domain Admin endpoint without protected-process LSA
Remediation for UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams
Immediate actions
- Block external Microsoft Teams chat invitations from non-federated tenants; require helpdesk verification through an out-of-band channel before remote support actions.
- Block the documented C2 indicators at the perimeter and DNS: wss://sad4w7h913-b4a57f9c36eb.herokuapp.com, all *outlook.s3.us-west-2.amazonaws.com phishing buckets, and any *.s3.us-east-2.amazonaws.com objects matching the SNOWBELT DGA pattern [a-f0-9]{24}-[0-9]{6,7}-[0-9].
- Hunt %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents and C:\ProgramData\log on all Windows endpoints; remove and image any matches.
- Deploy the GTIG YARA rules G_Backdoor_SNOWBELT_1, G_Tunneler_SNOWGLAZE_1, and G_Backdoor_SNOWBASIN_1 across endpoint and email gateways.
- Disable headless Microsoft Edge launches by non-administrative users via AppLocker / WDAC, and audit msedge.exe command lines containing --headless=new --load-extension.
Workarounds
- Tenant-wide disable of 'Allow communication with external Microsoft Teams users' until helpdesk verification controls are in place.
- Group Policy: prohibit user-installed Edge extensions and require ExtensionInstallAllowlist enforcement.
- Block TCP/445 lateral SMB and TCP/3389 RDP between user-segment hosts via host firewall to break SNOWGLAZE-tunneled lateral movement.
Longer-term hardening
- Enforce Microsoft Teams external collaboration policy: restrict external chats to allow-listed federated tenants and disable unsolicited inbound invitations.
- Deploy EDR with behavioral detections for AutoHotKey droppers (RegSrvc.exe, Protected.ahk), browser-extension persistence under unmanaged paths, and child-process execution of cmd.exe/powershell.exe by msedge.exe service workers.
- Mandate LAPS, Credential Guard, and protected-process LSA to mitigate LSASS memory dumping; alert on Task Manager Create-Dump events targeting lsass.exe.
- Block known dual-use forensic tools (FTK Imager) from running on user endpoints via application allowlisting; alert on FTK Imager binaries dropped to user Downloads folders.
- Restrict outbound peer-to-peer protocols (LimeWire/Gnutella) and high-risk PaaS endpoints (Heroku, raw S3) at the egress proxy where business need does not exist.
Weaknesses (CWE) in UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams
Timeline of UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams
- Mandiant incident responders first observe SNOW toolset components in customer environments compromised via Microsoft Teams external chat invitations.
- Email-bombing precursor activity scales: thousands of subscription/spam messages flood targeted enterprise inboxes minutes before Teams impersonation chats arrive.
- Mandiant documents UNC6692 using SNOWGLAZE WebSocket tunnels to relay PsExec and RDP into backup servers, followed by FTK Imager NTDS.dit extraction on domain controllers.
- Google Threat Intelligence Group / Mandiant publishes 'Snow Flurries' blog post (authors JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair) detailing UNC6692, the SNOW suite, IOCs, and YARA rules G_Backdoor_SNOWBELT_1 / G_Tunneler_SNOWGLAZE_1 / G_Backdoor_SNOWBASIN_1.
- Credential-harvesting S3 bucket service-page-18968-2419-outlook.s3.us-west-2.amazonaws.com taken down following coordinated disclosure to AWS Trust & Safety.
- Threadlinqs Intelligence opens TL-2026-0423 to track UNC6692 / SNOW campaign with full IOCs, MITRE mappings, and detection coverage.
- BleepingComputer, The Hacker News, The Register, and TechNadu publish secondary reporting; defenders begin deploying GTIG YARA rules and Teams external-chat hardening.
- As of 2026-05-29, UNC6692's SNOW suite (SNOWBELT/SNOWGLAZE/SNOWBASIN) via Teams helpdesk impersonation remains a live, ongoing concern — multiple firms (eSentire, HivePro, Field Effect) confirm continued activity since Dec 2025 with no takedown or arrests. It is a no-CVE social-engineering/custom-malware campaign abusing Teams config, so no patch closes it; only one phishing S3 bucket was sinkholed while the actor and DGA/Heroku C2 persist.
Sources cited for UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams
- Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
- Threat actor uses Microsoft Teams to deploy new 'Snow' malware
- UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware
- Crime crew impersonates help desk, abuses Teams chats
- UNC6692 Deploys SNOW Malware via IT Helpdesk Impersonation on Teams
- MITRE ATT&CK T1176.001 - Browser Extensions
- MITRE ATT&CK T1566.004 - Spearphishing Voice / Trusted-Channel Social Engineering
Detection coverage for TL-2026-0423
As of 2026-04-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0423 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.