UNC6692 is a newly identified cybercrime threat cluster associated with multi-stage intrusions that rely on social engineering rather than software exploitation. The actor is known for abusing Microsoft Teams external communications to impersonate IT help desk personnel, typically after first overwhelming targets with high-volume spam or email-bombing activity to create urgency and confusion. Victims are then persuaded to accept external Teams chats and follow instructions to install a supposed fix for mailbox or spam issues, leading to credential theft and malware deployment. UNC6692 has been observed using phishing pages themed as mailbox repair or synchronization utilities to harvest credentials, including repeated password-entry prompts designed to improve theft accuracy and reinforce legitimacy. The actor then deploys a custom modular malware ecosystem known as SNOW. Reported SNOW components include SNOWBELT, a malicious Chromium-based browser extension used for persistence and command relay; SNOWGLAZE, a Python-based tunneling utility that enables covert access into internal networks; and SNOWBASIN, a Python backdoor or bindshell used for remote command execution, screenshot capture, file transfer, and data staging. The intrusion chain has also involved AutoHotkey-based loaders and scripts to execute and install these components while minimizing user visibility. The group’s tradecraft emphasizes stealth through abuse of legitimate enterprise platforms, cloud services, browser functionality, scheduled tasks, and trusted administrative tools. Post-compromise activity has included credential harvesting, internal reconnaissance, network scanning, lateral movement, remote administration, and exfiltration of sensitive enterprise data. In higher-impact intrusions, UNC6692 has been reported extracting LSASS memory, using Pass-the-Hash for movement to privileged systems, accessing backup infrastructure and domain controllers, and collecting Active Directory database material and registry hives for theft. UNC6692 is frequently discussed alongside broader Teams-based help desk impersonation activity and social-engineering patterns associated with ransomware and extortion ecosystems, including operations tied to former Black Basta affiliates such as Storm-1811. However, available reporting does not establish UNC6692 as identical to those groups, and some reporting explicitly notes no confirmed overlap with other socially driven intrusion crews such as ShinyHunters or Scattered Lapsus$ Hunters. UNC6692 is best characterized as an emerging financially motivated intrusion actor distinguished by persistent live social engineering, Microsoft Teams abuse, credential theft, custom malware development, and deep post-compromise enterprise access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting social-engineering intrusions via spam flooding and Microsoft Teams helpdesk impersonation to steal credentials, gain remote access, establish persistence, harvest data, and exfiltrate information using the SNOW malware ecosystem.
Emerging offshoot mentioned as participating in similar Teams-based vishing and remote-access-enabled intrusion activity.
Impersonates IT helpdesk staff over Microsoft Teams and socially engineers employees into accepting external chat invitations.
Named activity cluster referenced as combining social engineering, malware, and cloud abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.