UNC6692 is a newly identified cybercrime threat cluster associated with multi-stage intrusions that rely on social engineering rather than software exploitation. The actor is best known for impersonating IT helpdesk personnel through Microsoft Teams after first overwhelming targets with high-volume spam or email-bombing activity. This sequence is used to create urgency and trust, enabling the operators to persuade victims to accept external Teams chats, visit phishing pages, disclose credentials, launch remote-assistance sessions, or install purported fixes for mailbox or spam problems. Observed UNC6692 operations have targeted enterprise users, including senior employees and decision-makers, with activity documented against organizations such as those in the software sector. The group’s tradecraft centers on abuse of trusted enterprise platforms and legitimate cloud services for payload delivery, credential collection, command-and-control, and exfiltration, allowing malicious traffic to blend with normal business activity. A defining feature of UNC6692 is deployment of a custom modular malware ecosystem commonly referred to as SNOW. Reported components include SNOWBELT, a malicious Chromium-based browser extension used for persistence, command relay, and follow-on payload delivery; SNOWGLAZE, a Python-based tunneling utility that establishes authenticated WebSocket-based proxying and supports lateral movement; and SNOWBASIN, a Python backdoor or bindshell that enables remote command execution, screenshot capture, file transfer, and local HTTP-based tasking. Separate reporting has also described a browser-focused backdoor called Edgecution, implemented as a malicious Microsoft Edge extension paired with a Python native messaging host, with capabilities including browser monitoring, host fingerprinting, arbitrary command execution, PowerShell and Python execution, process enumeration, and file operations. UNC6692 commonly uses phishing pages masquerading as mailbox repair or synchronization utilities. These lures have been observed harvesting credentials through repeated password-entry prompts designed to improve theft accuracy and reinforce legitimacy. Initial staging has frequently involved AutoHotkey-based loaders and scripts, malicious browser-extension sideloading, scheduled-task persistence, hidden or headless browser execution, and use of native browser messaging mechanisms. Post-compromise activity indicates hands-on-keyboard operations aimed at deep enterprise access and data theft. Reported behavior includes internal reconnaissance, scanning for administrative services, credential theft, LSASS memory extraction, use of PsExec and RDP, pass-the-hash movement, access to backup infrastructure, and theft of Active Directory data including NTDS.dit and registry hives. Exfiltration has been conducted with legitimate or dual-use tools and cloud-hosted infrastructure. UNC6692 has been described as an emerging offshoot or adjacent cluster associated with tradecraft long linked to former Black Basta affiliates and has also been reported as an initial access actor linked to ransomware ecosystems including Payouts King. At the same time, reporting has stated there is no confirmed overlap with groups such as ShinyHunters, Scattered Lapsus$ Hunters, or separate Teams-impersonation activity attributed elsewhere. Overall, UNC6692 represents a socially adept, technically capable intrusion actor that combines collaboration-platform phishing, remote-support abuse, browser-extension persistence, and modular malware to obtain durable enterprise access and steal high-value data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related Teams-themed social-engineering campaign in which attackers impersonate IT helpdesk staff on Teams to deploy credential-stealing malware and backdoors.
Conducting targeted phishing and social-engineering operations using email bombing, Microsoft Teams IT-support impersonation, Quick Assist remote access, credential phishing, and deployment of the Edgecution malicious browser extension to gain initial access and persistent control.
Conducting social-engineering intrusions via spam flooding and Microsoft Teams helpdesk impersonation to steal credentials, gain remote access, establish persistence, harvest data, and exfiltrate information using the SNOW malware ecosystem.
Emerging offshoot mentioned as participating in similar Teams-based vishing and remote-access-enabled intrusion activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.