SNOW is a custom modular malware suite associated with the threat actor UNC6692 and used in socially engineered intrusions that abuse Microsoft Teams helpdesk impersonation. The malware is typically deployed after an email-bombing pretext and a follow-on chat interaction in which the victim is persuaded to run a supposed remediation or patch. Observed delivery has involved an AutoHotkey-based loader that installs and launches multiple SNOW components while attempting to minimize user visibility.
The SNOW ecosystem includes at least three named components: SNOWBELT, SNOWGLAZE, and SNOWBASIN. SNOWBELT is a malicious Chromium-family browser extension used for persistence and command relay, including execution through hidden or headless Microsoft Edge instances. SNOWGLAZE is a tunneling utility that supports covert communications and SOCKS-style proxying, enabling operators to route traffic through the compromised host. SNOWBASIN is a backdoor that exposes a local HTTP-based command channel and supports remote command execution, shell access, file operations, screenshot capture, data exfiltration, and self-termination.
Operationally, SNOW is designed to provide stealthy post-compromise access and facilitate deeper enterprise intrusion. Reported activity includes credential harvesting, internal reconnaissance, lateral movement, and expansion toward high-value systems such as domain controllers. Operators have used stolen credentials and pass-the-hash techniques after initial compromise, and have targeted Active Directory data for theft. The malware’s communications and staging methods are intended to blend with legitimate cloud services and normal Windows activity, complicating detection by reputation-based and conventional network monitoring controls.
SNOW appears tailored for hands-on-keyboard intrusion operations rather than indiscriminate mass infection. Its observed use aligns with campaigns focused on enterprise compromise, data theft, and preparation for broader follow-on activity. Targeting has centered on organizations whose users can be manipulated through trusted collaboration platforms and fake internal support workflows, making the malware notable for combining social engineering, browser-extension abuse, tunneling, and local backdoor functionality in a coordinated intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A newly identified threat group tracked as UNC6692 is hijacking Microsoft Teams to install a custom malware suite called SNOW.
Secondary Payload Deployment: Rapid execution of malicious loaders or novel backdoors (such as SNOW malware) within minutes of session establishment.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
That button triggers a login prompt, and the page asks for credentials multiple times under the guise of verification... The captured logins are then quietly sent to a cloud location controlled by the attacker.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular malware ecosystem used after initial social-engineering compromise via Microsoft Teams. It includes a malicious browser extension, a Python-based tunneling tool, and a local backdoor to maintain persistence, harvest credentials, support command-and-control, capture screenshots, exfiltrate files, and terminate sessions.
A novel backdoor cited as a secondary payload deployed shortly after remote-session establishment in Teams-based intrusion activity.
Custom malware suite used after social-engineering-based initial access to steal sensitive data following deep network compromise. It includes SnowBelt for persistence and command relay, SnowGlaze for WebSocket tunneling and SOCKS proxying, and SnowBasin, a Python-based backdoor that provides remote shell access, command execution, data exfiltration, file download, screenshot capture, and file management.
SNOW is used after initial phishing-based access to enable lateral movement and data exfiltration within the victim network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.