Snow
Snow is a custom malware suite associated with threat actor UNC6692. It is deployed through a social-engineering intrusion chain that uses email bombing and Microsoft Teams helpdesk impersonation to pressure victims into opening a phishing link presented as a spam-fix or security patch. The delivered toolset includes SnowBelt, a malicious browser extension used for persistence and command relay; SnowGlaze, a tunneler that establishes WebSocket communications and supports SOCKS proxying; and SnowBasin, a Python-based backdoor that runs a local HTTP server and supports remote shell access, execution of CMD and PowerShell commands, file download and management, screenshot capture, data exfiltration, and self-termination. Reported persistence mechanisms include scheduled tasks and a startup-folder shortcut, and SnowBelt was observed executing in a headless Microsoft Edge instance to reduce user visibility. After initial compromise, UNC6692 was observed conducting internal reconnaissance, scanning for SMB and RDP services, dumping LSASS for credential theft, using pass-the-hash for lateral movement, and ultimately reaching domain controllers. In the final stage of observed intrusions, the actor used FTK Imager to collect the Active Directory database along with the SYSTEM, SAM, and SECURITY registry hives, then exfiltrated the stolen data using LimeWire. The objective described in the reporting is theft of sensitive data following deep network compromise and domain takeover. The content also separately mentions "Snow" as the name of an ITG23-related crypter referenced by IBM X-Force in campaigns involving Hive0118/TA577, but no further technical detail is provided there.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named “Snow,” which includes a browser extension, a tunneler, and a backdoor.
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware suite used after social-engineering-based initial access to steal sensitive data following deep network compromise. It includes SnowBelt for persistence and command relay, SnowGlaze for WebSocket tunneling and SOCKS proxying, and SnowBasin, a Python-based backdoor that provides remote shell access, command execution, data exfiltration, file download, screenshot capture, and file management.
SNOW is used after initial phishing-based access to enable lateral movement and data exfiltration within the victim network.
Crypter used in campaigns associated with ITG23-related activity to protect/obfuscate delivered malware payloads.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.