SNOWBASIN
SNOWBASIN is a Python-based remote access backdoor/bindshell in the SNOW malware ecosystem used by threat cluster UNC6692. It operates as a persistent local HTTP server, typically listening on port 8000, with some reporting also noting ports 8001 or 8002. SNOWBASIN provides interactive control of infected systems and supports remote command execution via cmd.exe or powershell.exe, screenshot capture, file upload and download, data staging for exfiltration, and self-termination. In the observed intrusion chain, UNC6692 used Microsoft Teams helpdesk impersonation and email bombing to socially engineer victims into installing a fake mailbox repair utility, which deployed SNOWBELT, a malicious Chromium extension, along with AutoHotkey scripts and a portable Python environment. SNOWBELT relayed operator commands to SNOWBASIN, while SNOWGLAZE, a Python-based tunneler, created authenticated WebSocket tunnels between victim networks and attacker infrastructure. Reported command flow included commands sent through the SNOWGLAZE tunnel, intercepted by SNOWBELT, proxied to SNOWBASIN over HTTP POST, executed locally, and returned through the same chain. SNOWBASIN was used to enable deeper network access, reconnaissance, and post-compromise operations in enterprise environments.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Finally, SnowBasin is a Python bindshell providing interactive control over the infected system. It serves as a persistent backdoor, operating as a local HTTP server and typically listening on port 8000, allowing remote command execution, screenshot capture, and data staging for exfiltration.
Techniques & procedures
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
5 techniques
Initial Access
The hacker sends a link to a fake “Mailbox Repair” utility or asks the victim to open remote access tools like Quick Assist. Either way, they install the SNOW malware suite.
Once it's clicked, it leads to the download of an AutoHotkey script from a threat actor-controlled AWS S3 bucket.
Step 2 — The helper arrives on Teams Right away, an external Microsoft Teams account named “IT Helpdesk” messages the victim. The hacker offers to fix the email issue immediately.
Execution
6 techniques
Execution
The first stage downloads an AutoHotKey binary and an AutoHotkey script, which immediately starts performing reconnaissance... SnowGlaze is a Python-based tunneler... Finally, SnowBasin is a Python bindshell...
SNOWBASIN... enable[s] remote command execution via "cmd.exe" or "powershell.exe"
SNOWBASIN... enable[s] remote command execution via "cmd.exe" or "powershell.exe"
...a ZIP archive containing a portable Python executable and required libraries. SnowGlaze is a Python-based tunneler... Finally, SnowBasin is a Python bindshell...
Persistence
1 technique
Persistence
Credential Access
1 technique
Credential Access
Discovery
2 techniques
Discovery
Lateral Movement
1 technique
Lateral Movement
Collection
2 techniques
Collection
Command and Control
3 techniques
Command and Control
Finally, SnowBasin is a Python bindshell providing interactive control over the infected system.
IOCs tracked for this family
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access backdoor in the SNOW malware suite used to maintain persistent access to compromised endpoints.
A remote access backdoor used to provide persistent access to compromised endpoints.
An additional malware tool downloaded by SnowBelt as part of the intrusion chain.
A Python bindshell and persistent backdoor that runs as a local HTTP server, typically on port 8000, enabling remote command execution, screenshot capture, and staging of data for exfiltration.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.