SNOWBASIN is a Python-based remote access backdoor and bindshell used as part of the SNOW malware ecosystem associated with the UNC6692 threat cluster. It is deployed in intrusions that rely on social engineering rather than software exploitation, most notably campaigns in which attackers impersonate IT helpdesk personnel over Microsoft Teams after email-bombing targets. In observed attack chains, victims are lured into running staged payloads that install the broader SNOW toolset, including the SNOWBELT browser-extension backdoor and the SNOWGLAZE tunneling component, after which SNOWBASIN provides direct interactive control of the compromised host.
SNOWBASIN operates as a persistent local HTTP server and serves as the execution component of the malware suite. It enables remote command execution through Windows shell interpreters, supports screenshot capture, file upload and download, data staging for exfiltration, and operator-directed self-termination. In the SNOW architecture, commands can be relayed from SNOWBELT to SNOWBASIN for execution, while SNOWGLAZE provides an authenticated WebSocket tunnel that helps route traffic between the victim environment and attacker-controlled infrastructure. This modular design allows the operators to blend browser-based persistence, covert tunneling, and host-level command execution.
The malware has been observed in enterprise intrusions focused on credential theft, internal reconnaissance, lateral movement, and theft of sensitive directory data. After deployment, the broader toolchain has been used to scan internal networks, support remote administration activity, and facilitate follow-on compromise of higher-value systems including domain infrastructure. SNOWBASIN is therefore best characterized as the host-resident backdoor component of a custom intrusion framework built for stealthy persistence, remote tasking, and support of deeper post-compromise operations in Windows enterprise environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tool SNOWBASIN Local HTTP backdoor providing a direct command channel on the compromised host
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The hacker sends a link to a fake “Mailbox Repair” utility or asks the victim to open remote access tools like Quick Assist. Either way, they install the SNOW malware suite.
Once it's clicked, it leads to the download of an AutoHotkey script from a threat actor-controlled AWS S3 bucket.
Step 2 — The helper arrives on Teams Right away, an external Microsoft Teams account named “IT Helpdesk” messages the victim. The hacker offers to fix the email issue immediately.
The first stage downloads an AutoHotKey binary and an AutoHotkey script, which immediately starts performing reconnaissance... SnowGlaze is a Python-based tunneler... Finally, SnowBasin is a Python bindshell...
SNOWBASIN... enable[s] remote command execution via "cmd.exe" or "powershell.exe"
SNOWBASIN... enable[s] remote command execution via "cmd.exe" or "powershell.exe"
...a ZIP archive containing a portable Python executable and required libraries. SnowGlaze is a Python-based tunneler... Finally, SnowBasin is a Python bindshell...
Finally, SnowBasin is a Python bindshell providing interactive control over the infected system.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A lightweight local HTTP backdoor within the SNOW ecosystem that provides a direct command channel for issuing commands and pulling data from the compromised host.
A remote access backdoor in the SNOW malware suite used to maintain persistent access to compromised endpoints.
A remote access backdoor used to provide persistent access to compromised endpoints.
An additional malware tool downloaded by SnowBelt as part of the intrusion chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.