UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams Helpdesk Impersonation (SNOWBELT/SNOWGLAZE/SNOWBASIN) — Threadlinqs Intelligence
As of 2026-05-30, UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams Helpdesk Impersonation (SNOWBELT/SNOWGLAZE/SNOWBASIN) is a high-severity malware threat attributed to UNC6692 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0423 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: UNC6692 · Russia · UNKNOWN
Newly tracked threat cluster UNC6692 abuses Microsoft Teams chat invitations to impersonate IT helpdesk staff and deploy a custom modular malware suite — SNOWBELT (JavaScript Edge browser-extension
On 2026-04-23, Google Threat Intelligence Group (GTIG/Mandiant) published 'Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite,' detailing intrusions in which UNC6692 — a previously undocumented activity cluster — abused Microsoft Teams external chat invitations to compromise enterprise endpoints. The campaign begins with an email-bombing distraction phase: the actor floods a target's inbox with thousands of subscription/spam emails to manufacture urgency. Within minutes, the victim receives a Microsoft Teams chat invitation from an account outside their tenant impersonating internal IT helpdesk personnel offering to remediate the spam flood. The lure directs the user to a phishing landing page (update.html / 'Mailbox Repair Utility') hosted on attacker-controlled S3 buckets such as service-page-25144-30466-outlook.s3.us-west-2.amazonaws.com.
The phishing page uses a double-entry psychological trick: the first two credential submissions are silently rejected to entice the user to retype the password (mitigating typos) before harvesting them to a separate S3 bucket (service-page-18968-2419-outlook.s3.us-west-2.amazonaws.com, since taken down). Simultaneously, an AutoHotKey binary masquerading as 'Registration Service' (RegSrvc.exe) and an obfuscated Protected.ahk script are downloaded. The AHK loader drops a configuration file (profileB5.txt) and stages the SNOW toolset.
SNOWBELT is a Chromium browser-extension backdoor (background.js, dream.js, dream.html, helper.html) installed under %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents and loaded by a headless Microsoft Edge instance launched from scheduled tasks: msedge.exe --user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\System Data --headless=new --load-extension=%LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents --no-first-run --disable-sync. SNOWBELT generates a Service-Worker UUID prefixed 'fp-sw-', registers a hard-coded VAPID public key (BJkWCT45mL0uvV3AssRaq9Gn7iE2N7Lx38ZmWDFCjwhz0zv0QSVhKuZBLTTgAijB12cgzMzqyiJZr5tokRzSJu0) for push notifications, and resolves time-slotted (30-minute window) S3 C2 URLs via a DGA seeded with 691f7258f212fa8908a8bf06bcf9e027d2177276e13e10ff56bd434ff3755cc4 producing https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws.com endpoints. Payloads are AES-GCM encrypted with keys derived as SHA256(SEED + '|' + timeslot) and exfiltration objects encrypted as SHA256(SEED + '|ping|' + bucket + '|' + objectKey). Three companion scheduled tasks ensure persistence: (1) start headless Edge with the extension, (2) verify SNOWBELT is running, (3) terminate any Edge processes lacking CoreUIComponents.dll to clean up artifacts. A Startup-folder shortcut to the AHK script provides additional persistence.
SNOWGLAZE is a Python (Windows + Linux) tunneler that opens an authenticated WebSocket to wss://sad4w7h913-b4a57f9c36eb.herokuapp.com:443/ws and provides bidirectional Base64-wrapped SOCKS-over-WS forwarding (commands: socks_connect, socks_data, socks_close, ping/pong, agent_public_ip, disconnect) with a 5-300s exponential retry. The actor uses SNOWGLAZE to pivot a PsExec session to the victim host and tunnel an RDP session from the victim to a backup server.
SNOWBASIN is a Python multi-threaded HTTP bindshell that selects ports 8000/8001/8002 and exposes /probe, /stream (cmd.exe and powershell.exe execution), /buffer (file/dir staging), /flush, /commit (download attacker-supplied file URLs), /capture (mss/PIL screenshots), and /gc (self-termination). SNOWBELT receives commands from S3 polling and relays them to SNOWBASIN via 'command', 'buffer', 'flush', 'commit', 'stop_server', and 'screenshot' opcodes; SNOWBELT-internal opcodes include 'payload' (chrome.downloads), 'open_native_messaging', 'open_uri', 'delete_cache', 'websocket_control', and 'ping'.
Post-compromise, UNC6692 runs a Python network scanner against TCP/135, TCP/445, and TCP/3389 to identify lateral targets. The actor dumps LSASS proce
Weaknesses (CWE)
CWE-1021, CWE-829, CWE-494, CWE-200
Target sectors: enterprise, technology, professional-services
Target regions: North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1608, T1608, T1566, T1566, T1204, T1204, T1059, T1059, T1059