PULSE NAME
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
WHITE UNC6692 AlienVault 2026-04-23 Modified: 2026-04-24
13
IOCs
MEDIUM VOLUME
Google Threat Intelligence Group identified a sophisticated intrusion campaign by UNC6692 that combined persistent social engineering with custom malware. The attackers impersonated IT helpdesk personnel via Microsoft Teams, leveraging initial email spam campaigns to create urgency. Victims were tricked into downloading AutoHotKey scripts that installed SNOWBELT, a malicious browser extension establishing persistence through scheduled tasks. The modular SNOW ecosystem enabled deep network penetration: SNOWBELT provided initial access, SNOWGLAZE created encrypted WebSocket tunnels masking traffic as legitimate cloud communications, and SNOWBASIN functioned as a local backdoor for command execution. UNC6692 performed internal reconnaissance, escalated privileges by extracting LSASS memory, and used Pass-The-Hash techniques to access domain controllers. The operation culminated in exfiltration of Active Directory databases and credentials via LimeWire, demonstrating advanced tradecraft abusing legitimate clou...
Indicators of Compromise (13)
All FileHash-SHA256 FileHash-SHA1 YARA
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 2fa987b9ed6ec6d09c7451abd994249dfaba1c5a7da1c22b8407c461e62f7e49 2026-04-23
FileHash-SHA256 691f7258f212fa8908a8bf06bcf9e027d2177276e13e10ff56bd434ff3755cc4 2026-04-23
FileHash-SHA256 6e6dab993f99505646051d2772701e3c4740096ff9be63c92713bcb7fcddf9f7 2026-04-23
FileHash-SHA256 7f1d71e1e079f3244a69205588d504ed830d4c473747bb1b5c520634cc5a2477 2026-04-23
FileHash-SHA256 c8940de8cb917abe158a826a1d08f1083af517351d01642e6c7f324d0bba1eb8 2026-04-23
FileHash-SHA256 ca390b86793922555c84abc3b34406da2899382c617f9dcf83a74ac09dd18190 2026-04-23
FileHash-SHA256 de200b79ad2bd9db37baeba5e4d183498d450494c71c8929433681e848c3807f 2026-04-23
FileHash-SHA1 726c48860d8d840044dccb3919b773d502a1e60d 2026-04-23
FileHash-SHA1 9c685523fce5e6ad6d6ee4fa02693cefc8c6e102 2026-04-23
FileHash-SHA1 d83494bd8a7f816ce39576c776e67c2e9f568080 2026-04-23
YARA d83494bd8a7f816ce39576c776e67c2e9f568080 2026-04-24
YARA 726c48860d8d840044dccb3919b773d502a1e60d 2026-04-24
YARA 9c685523fce5e6ad6d6ee4fa02693cefc8c6e102 2026-04-24