# UNC6692 'SNOW' Malware Suite Deployed via Microsoft Teams Helpdesk Impersonation (SNOWBELT/SNOWGLAZE/SNOWBASIN)

> Newly tracked threat cluster UNC6692 abuses Microsoft Teams chat invitations to impersonate IT helpdesk staff and deploy a custom modular malware suite — SNOWBELT (JavaScript Edge browser-extension backdoor), SNOWGLAZE (Python WebSocket SOCKS tunneler), and SNOWBASIN (Python local HTTP bindshell) — leading to LSASS dumping, NTDS.dit theft via FTK Imager, pass-the-hash to domain controllers, and exfiltration via LimeWire to attacker-controlled AWS S3 buckets and a Heroku-hosted WebSocket C2.

- **Published:** 2026-04-25T12:00:00Z
- **Last reviewed:** 2026-04-25T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0423
- **ID:** TL-2026-0423
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UNC6692 (Russia)
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-04-23, Google Threat Intelligence Group (GTIG/Mandiant) published 'Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite,' detailing intrusions in which UNC6692 — a previously undocumented activity cluster — abused Microsoft Teams external chat invitations to compromise enterprise endpoints. The campaign begins with an email-bombing distraction phase: the actor floods a target's inbox with thousands of subscription/spam emails to manufacture urgency. Within minutes, the victim receives a Microsoft Teams chat invitation from an account outside their tenant impersonating internal IT helpdesk personnel offering to remediate the spam flood. The lure directs the user to a phishing landing page (update.html / 'Mailbox Repair Utility') hosted on attacker-controlled S3 buckets such as service-page-25144-30466-outlook.s3.us-west-2.amazonaws.com.

The phishing page uses a double-entry psychological trick: the first two credential submissions are silently rejected to entice the user to retype the password (mitigating typos) before harvesting them to a separate S3 bucket (service-page-18968-2419-outlook.s3.us-west-2.amazonaws.com, since taken down). Simultaneously, an AutoHotKey binary masquerading as 'Registration Service' (RegSrvc.exe) and an obfuscated Protected.ahk script are downloaded. The AHK loader drops a configuration file (profileB5.txt) and stages the SNOW toolset.

SNOWBELT is a Chromium browser-extension backdoor (background.js, dream.js, dream.html, helper.html) installed under %LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents and loaded by a headless Microsoft Edge instance launched from scheduled tasks: msedge.exe --user-data-dir=%LOCALAPPDATA%\Microsoft\Edge\System Data --headless=new --load-extension=%LOCALAPPDATA%\Microsoft\Edge\Extension Data\SysEvents --no-first-run --disable-sync. SNOWBELT generates a Service-Worker UUID prefixed 'fp-sw-', registers a hard-coded VAPID public key (BJkWCT45mL0uvV3AssRaq9Gn7iE2N7Lx38ZmWDFCjwhz0zv0QSVhKuZBLTTgAijB12cgzMzqyiJZr5tokRzSJu0) for push notifications, and resolves time-slotted (30-minute window) S3 C2 URLs via a DGA seeded with 691f7258f212fa8908a8bf06bcf9e027d2177276e13e10ff56bd434ff3755cc4 producing https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws.com endpoints. Payloads are AES-GCM encrypted with keys derived as SHA256(SEED + '|' + timeslot) and exfiltration objects encrypted as SHA256(SEED + '|ping|' + bucket + '|' + objectKey). Three companion scheduled tasks ensure persistence: (1) start headless Edge with the extension, (2) verify SNOWBELT is running, (3) terminate any Edge processes lacking CoreUIComponents.dll to clean up artifacts. A Startup-folder shortcut to the AHK script provides additional persistence.

SNOWGLAZE is a Python (Windows + Linux) tunneler that opens an authenticated WebSocket to wss://sad4w7h913-b4a57f9c36eb.herokuapp.com:443/ws and provides bidirectional Base64-wrapped SOCKS-over-WS forwarding (commands: socks_connect, socks_data, socks_close, ping/pong, agent_public_ip, disconnect) with a 5-300s exponential retry. The actor uses SNOWGLAZE to pivot a PsExec session to the victim host and tunnel an RDP session from the victim to a backup server.

SNOWBASIN is a Python multi-threaded HTTP bindshell that selects ports 8000/8001/8002 and exposes /probe, /stream (cmd.exe and powershell.exe execution), /buffer (file/dir staging), /flush, /commit (download attacker-supplied file URLs), /capture (mss/PIL screenshots), and /gc (self-termination). SNOWBELT receives commands from S3 polling and relays them to SNOWBASIN via 'command', 'buffer', 'flush', 'commit', 'stop_server', and 'screenshot' opcodes; SNOWBELT-internal opcodes include 'payload' (chrome.downloads), 'open_native_messaging', 'open_uri', 'delete_cache', 'websocket_control', and 'ping'.

Post-compromise, UNC6692 runs a Python network scanner against TCP/135, TCP/445, and TCP/3389 to identify lateral targets. The actor dumps LSASS process memory using the Windows Task Manager 'Create dump file' feature, exfiltrates the dump via LimeWire for offline credential extraction, then performs pass-the-hash to reach domain controllers. On the DC, FTK Imager is downloaded into a Domain Admin Downloads folder and used to extract NTDS.dit along with SAM, SYSTEM, and SECURITY registry hives — again exfiltrated via LimeWire. Domain controller screenshots are captured via SNOWBASIN. No specific industry vertical or geography is named; targeting tracks senior-level executives in enterprise environments.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1569 System Services
- T1176 Software Extensions
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1202 Indirect Command Execution
- T1564 Hide Artifacts
- T1003 OS Credential Dumping
- T1056 Input Capture
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1016 System Network Configuration Discovery
- T1021 Remote Services
- T1550 Use Alternate Authentication Material
- T1113 Screen Capture
- T1074 Data Staged
- T1071 Application Layer Protocol
- T1090 Proxy
- T1572 Protocol Tunneling
- T1105 Ingress Tool Transfer
- T1567 Exfiltration Over Web Service
- T1020 Automated Exfiltration

## Sources

- [Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite](https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware)
- [Threat actor uses Microsoft Teams to deploy new 'Snow' malware](https://www.bleepingcomputer.com/news/security/threat-actor-uses-microsoft-teams-to-deploy-new-snow-malware/)
- [UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware](https://thehackernews.com/2026/04/unc6692-impersonates-it-helpdesk-via.html)
- [Crime crew impersonates help desk, abuses Teams chats](https://www.theregister.com/2026/04/25/new_crime_crew_impersonates_help_desks)
- [UNC6692 Deploys SNOW Malware via IT Helpdesk Impersonation on Teams](https://www.technadu.com/unc6692-deploys-custom-snow-malware-via-impersonating-it-helpdesks-on-microsoft-teams/626911/)
- [MITRE ATT&CK T1176.001 - Browser Extensions](https://attack.mitre.org/techniques/T1176/001/)
- [MITRE ATT&CK T1566.004 - Spearphishing Voice / Trusted-Channel Social Engineering](https://attack.mitre.org/techniques/T1566/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0423
