SNOWGLAZE is a Python-based tunneling utility used as part of the SNOW malware ecosystem associated with the UNC6692 threat cluster. It is designed to provide covert external communications and network pivoting after initial compromise, typically alongside the SNOWBELT browser-extension backdoor and the SNOWBASIN Python backdoor.
SNOWGLAZE runs on both Windows and Linux and establishes an authenticated, persistent WebSocket tunnel between a compromised host or internal network segment and attacker-controlled command-and-control infrastructure. It supports SOCKS-style proxying of TCP traffic, allowing operators to route interactive sessions and other network communications through the victim environment while masking command-and-control activity as ordinary encrypted web traffic. Reported implementations wrap tunneled data in JSON and Base64-encoded structures for transport over WebSockets.
In observed intrusions, SNOWGLAZE was not typically the initial payload. It was delivered after social-engineering-based access, including Microsoft Teams helpdesk impersonation and email-bombing lures that led victims to execute staged AutoHotkey components and install SNOWBELT. Once deployed, SNOWGLAZE enabled deeper access into victim networks by carrying operator traffic used for reconnaissance and lateral movement. It was used to support remote administration activity, including tunneling sessions used for PsExec and RDP access into additional internal systems.
SNOWGLAZE is part of a modular intrusion set focused on stealth, persistence, and post-compromise expansion in enterprise environments. Its role is primarily communications concealment and internal pivoting rather than direct credential theft or destructive action. The broader campaigns in which it has been observed targeted enterprise users, including senior personnel, and were oriented toward credential harvesting, internal reconnaissance, lateral movement, and theft of sensitive organizational data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tool SNOWGLAZE Python based tunneling utility supporting SOCKS5 traffic to conceal command and control communications
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The hacker sends a link to a fake “Mailbox Repair” utility or asks the victim to open remote access tools like Quick Assist. Either way, they install the SNOW malware suite.
Once it's clicked, it leads to the download of an AutoHotkey script from a threat actor-controlled AWS S3 bucket.
Step 2 — The helper arrives on Teams Right away, an external Microsoft Teams account named “IT Helpdesk” messages the victim. The hacker offers to fix the email issue immediately.
Clicking it downloads a renamed AutoHotkey binary along with a script... Once the AutoHotkey script runs... It includes... a Python based tunneling tool.
...a ZIP archive containing a portable Python executable and required libraries. SnowGlaze is a Python-based tunneler... Finally, SnowBasin is a Python bindshell...
It also disguises malicious traffic by wrapping data in JSON objects and Base64 encoding it for transfer via WebSockets, which makes it look like legitimate, standard encrypted web traffic.
SNOWGLAZE is a Python tunneler that creates a persistent encrypted channel back to attacker infrastructure.
It creates an authenticated WebSocket tunnel between the victim's internal network and the attacker's command-and-control (C2) infrastructure, such as a Heroku subdomain.
SnowGlaze is a Python-based tunneler... It creates an authenticated WebSocket tunnel between the victim's internal network and the attacker's command-and-control (C2) infrastructure...
SNOWGLAZE is a Python-based tunneler to create a secure, authenticated WebSocket tunnel between the victim's internal network and the attacker's command-and-control (C2) server.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based tunneling utility in the SNOW toolkit that routes SOCKS5-style traffic through the compromised host to conceal command-and-control and support exfiltration.
A Python-based tunneling component in the SNOW malware suite that establishes a persistent encrypted channel to attacker-controlled infrastructure.
A Python-based tunneling tool that establishes a persistent encrypted channel to attacker infrastructure.
An additional malware tool downloaded by SnowBelt as part of the intrusion chain.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.