Threat reportMalwareTL-2026-0423

UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams Helpdesk Impersonation (SNOWBELT/SNOWGLAZE/SNOWBASIN)

highACTIVE

UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams (TL-2026-0423), also tracked as Snow Flurries, is a high-severity malware campaign, first published 2026-04-25. It is attributed to UNC6692 (Russia) with medium confidence, affects Microsoft Microsoft Teams, maps to 29 MITRE ATT&CK techniques (T1003, T1016, T1018), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
1UNC6692
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-0423

Threat ID
TL-2026-0423
Also known as
Snow Flurries, SNOW Malware Suite
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UNC6692
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
UNKNOWN
Target sectors
enterprise, technology, professional-services
Target regions
North America, Europe
Detection rules
9
Indicators of compromise
32

Malware and tooling in UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams

Malware and tooling: SNOW, SNOWBASIN, SNOWBELT, SNOWGLAZE, LimeWire, Sysinternals PsExec

How UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams works

Newly tracked threat cluster UNC6692 abuses Microsoft Teams chat invitations to impersonate IT helpdesk staff and deploy a custom modular malware suite — SNOWBELT (JavaScript Edge browser-extension backdoor), SNOWGLAZE (Python WebSocket SOCKS tunneler), and SNOWBASIN (Python local HTTP bindshell) — leading to LSASS dumping, NTDS.dit theft via FTK Imager, pass-the-hash to domain controllers, and exfiltration via LimeWire to attacker-controlled AWS S3 buckets and a Heroku-hosted WebSocket C2.

On 2026-04-23, Google Threat Intelligence Group (GTIG/Mandiant) published 'Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite,' detailing intrusions in which UNC6692 — a previously undocumented activity cluster — abused Microsoft Teams external chat invitations to compromise enterprise endpoints. The campaign begins with an email-bombing distraction phase: the actor floods a target's inbox with thousands of subscription/spam emails to manufacture urgency. Within minutes, the victim receives a Microsoft Teams chat invitation from an account outside their tenant impersonating internal IT helpdesk personnel offering to remediate the spam flood. The lure directs the user to a phishing landing page (update.html / 'Mailbox Repair Utility') hosted on attacker-controlled S3 buckets such as service-page-25144-30466-outlook.s3.us-west-2.amazonaws.com.

The phishing page uses a double-entry psychological trick: the first two credential submissions are silently rejected to entice the user to retype the password (mitigating typos) before harvesting them to a separate S3 bucket (service-page-18968-2419-outlook.s3.us-west-2.amazonaws.com, since taken down). Simultaneously, an AutoHotKey binary masquerading as 'Registration Service' (RegSrvc.exe) and an obfuscated Protected.ahk script are downloaded. The AHK loader drops a configuration file (profileB5.txt) and stages the SNOW toolset.

SNOWBELT is a Chromium browser-extension backdoor (background.js, dream.js, dream.html, helper.html) installed under %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents and loaded by a headless Microsoft Edge instance launched from scheduled tasks: msedge.exe --user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\System Data --headless=new --load-extension=%LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents --no-first-run --disable-sync. SNOWBELT generates a Service-Worker UUID prefixed 'fp-sw-', registers a hard-coded VAPID public key (BJkWCT45mL0uvV3AssRaq9Gn7iE2N7Lx38ZmWDFCjwhz0zv0QSVhKuZBLTTgAijB12cgzMzqyiJZr5tokRzSJu0) for push notifications, and resolves time-slotted (30-minute window) S3 C2 URLs via a DGA seeded with 691f7258f212fa8908a8bf06bcf9e027d2177276e13e10ff56bd434ff3755cc4 producing https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws.com endpoints. Payloads are AES-GCM encrypted with keys derived as SHA256(SEED + '|' + timeslot) and exfiltration objects encrypted as SHA256(SEED + '|ping|' + bucket + '|' + objectKey). Three companion scheduled tasks ensure persistence: (1) start headless Edge with the extension, (2) verify SNOWBELT is running, (3) terminate any Edge processes lacking CoreUIComponents.dll to clean up artifacts. A Startup-folder shortcut to the AHK script provides additional persistence.

SNOWGLAZE is a Python (Windows + Linux) tunneler that opens an authenticated WebSocket to wss://sad4w7h913-b4a57f9c36eb.herokuapp.com:443/ws and provides bidirectional Base64-wrapped SOCKS-over-WS forwarding (commands: socks_connect, socks_data, socks_close, ping/pong, agent_public_ip, disconnect) with a 5-300s exponential retry. The actor uses SNOWGLAZE to pivot a PsExec session to the victim host and tunnel an RDP session from the victim to a backup server.

SNOWBASIN is a Python multi-threaded HTTP bindshell that selects ports 8000/8001/8002 and exposes /probe, /stream (cmd.exe and powershell.exe execution), /buffer (file/dir staging), /flush, /commit (download attacker-supplied file URLs), /capture (mss/PIL screenshots), and /gc (self-termination). SNOWBELT receives commands from S3 polling and relays them to SNOWBASIN via 'command', 'buffer', 'flush', 'commit', 'stop_server', and 'screenshot' opcodes; SNOWBELT-internal opcodes include 'payload' (chrome.downloads), 'open_native_messaging', 'open_uri', 'delete_cache', 'websocket_control', and 'ping'.

Post-compromise, UNC6692 runs a Python network scanner against TCP/135, TCP/445, and TCP/3389 to identify lateral targets. The actor dumps LSASS process memory using the Windows Task Manager 'Create dump file' feature, exfiltrates the dump via LimeWire for offline credential extraction, then performs pass-the-hash to reach domain controllers. On the DC, FTK Imager is downloaded into a Domain Admin Downloads folder and used to extract NTDS.dit along with SAM, SYSTEM, and SECURITY registry hives — again exfiltrated via LimeWire. Domain controller screenshots are captured via SNOWBASIN. No specific industry vertical or geography is named; targeting tracks senior-level executives in enterprise environments.

MITRE ATT&CK techniques used in TL-2026-0423

Credential Access

T1003 OS Credential Dumping; T1056 Input Capture

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery

Exfiltration

T1020 Automated Exfiltration; T1567 Exfiltration Over Web Service

Lateral Movement

T1021 Remote Services; T1550 Use Alternate Authentication Material

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1202 Indirect Command Execution; T1564 Hide Artifacts

Execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution; T1569 System Services

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

Collection

T1074 Data Staged; T1113 Screen Capture

Persistence

T1176 Software Extensions; T1547 Boot or Logon Autostart Execution

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1608 Stage Capabilities

Affected products and versions in UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams

  • Microsoft — Microsoft Teams
    Vulnerable versions: all tenants permitting unsolicited external chat invitations
  • Microsoft — Microsoft Edge (Chromium)
    Vulnerable versions: all current versions when headless extension loading is permitted
  • Microsoft — Windows
    Vulnerable versions: Windows 10; Windows 11; Windows Server 2019; Windows Server 2022
  • Microsoft — Active Directory Domain Services
    Vulnerable versions: domains where NTDS.dit is reachable to a Domain Admin endpoint without protected-process LSA

Remediation for UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams

Immediate actions

  • Block external Microsoft Teams chat invitations from non-federated tenants; require helpdesk verification through an out-of-band channel before remote support actions.
  • Block the documented C2 indicators at the perimeter and DNS: wss://sad4w7h913-b4a57f9c36eb.herokuapp.com, all *outlook.s3.us-west-2.amazonaws.com phishing buckets, and any *.s3.us-east-2.amazonaws.com objects matching the SNOWBELT DGA pattern [a-f0-9]{24}-[0-9]{6,7}-[0-9].
  • Hunt %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents and C:\ProgramData\log on all Windows endpoints; remove and image any matches.
  • Deploy the GTIG YARA rules G_Backdoor_SNOWBELT_1, G_Tunneler_SNOWGLAZE_1, and G_Backdoor_SNOWBASIN_1 across endpoint and email gateways.
  • Disable headless Microsoft Edge launches by non-administrative users via AppLocker / WDAC, and audit msedge.exe command lines containing --headless=new --load-extension.

Workarounds

  • Tenant-wide disable of 'Allow communication with external Microsoft Teams users' until helpdesk verification controls are in place.
  • Group Policy: prohibit user-installed Edge extensions and require ExtensionInstallAllowlist enforcement.
  • Block TCP/445 lateral SMB and TCP/3389 RDP between user-segment hosts via host firewall to break SNOWGLAZE-tunneled lateral movement.

Longer-term hardening

  • Enforce Microsoft Teams external collaboration policy: restrict external chats to allow-listed federated tenants and disable unsolicited inbound invitations.
  • Deploy EDR with behavioral detections for AutoHotKey droppers (RegSrvc.exe, Protected.ahk), browser-extension persistence under unmanaged paths, and child-process execution of cmd.exe/powershell.exe by msedge.exe service workers.
  • Mandate LAPS, Credential Guard, and protected-process LSA to mitigate LSASS memory dumping; alert on Task Manager Create-Dump events targeting lsass.exe.
  • Block known dual-use forensic tools (FTK Imager) from running on user endpoints via application allowlisting; alert on FTK Imager binaries dropped to user Downloads folders.
  • Restrict outbound peer-to-peer protocols (LimeWire/Gnutella) and high-risk PaaS endpoints (Heroku, raw S3) at the egress proxy where business need does not exist.

Weaknesses (CWE) in UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams

CWE-1021, CWE-829, CWE-494, CWE-200

Timeline of UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams

  • Mandiant incident responders first observe SNOW toolset components in customer environments compromised via Microsoft Teams external chat invitations.
  • Email-bombing precursor activity scales: thousands of subscription/spam messages flood targeted enterprise inboxes minutes before Teams impersonation chats arrive.
  • Mandiant documents UNC6692 using SNOWGLAZE WebSocket tunnels to relay PsExec and RDP into backup servers, followed by FTK Imager NTDS.dit extraction on domain controllers.
  • Google Threat Intelligence Group / Mandiant publishes 'Snow Flurries' blog post (authors JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair) detailing UNC6692, the SNOW suite, IOCs, and YARA rules G_Backdoor_SNOWBELT_1 / G_Tunneler_SNOWGLAZE_1 / G_Backdoor_SNOWBASIN_1.
  • Credential-harvesting S3 bucket service-page-18968-2419-outlook.s3.us-west-2.amazonaws.com taken down following coordinated disclosure to AWS Trust & Safety.
  • Threadlinqs Intelligence opens TL-2026-0423 to track UNC6692 / SNOW campaign with full IOCs, MITRE mappings, and detection coverage.
  • BleepingComputer, The Hacker News, The Register, and TechNadu publish secondary reporting; defenders begin deploying GTIG YARA rules and Teams external-chat hardening.
  • As of 2026-05-29, UNC6692's SNOW suite (SNOWBELT/SNOWGLAZE/SNOWBASIN) via Teams helpdesk impersonation remains a live, ongoing concern — multiple firms (eSentire, HivePro, Field Effect) confirm continued activity since Dec 2025 with no takedown or arrests. It is a no-CVE social-engineering/custom-malware campaign abusing Teams config, so no patch closes it; only one phishing S3 bucket was sinkholed while the actor and DGA/Heroku C2 persist.

Sources cited for UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams

Detection coverage for TL-2026-0423

As of 2026-04-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0423 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats