SNOWBELT is a malicious Chromium-based browser extension used as part of the SNOW malware ecosystem. It functions as a JavaScript backdoor that provides attackers with an initial foothold on compromised systems and maintains persistence through the browser extension registration mechanism. The malware has been observed masquerading as benign browser components such as heartbeat or system-monitoring extensions to reduce suspicion.
SNOWBELT has been associated with the threat cluster UNC6692 in socially engineered intrusions that begin with email bombing and Microsoft Teams helpdesk impersonation. In observed campaigns, victims are lured into downloading an AutoHotkey-based payload presented as a mailbox repair or anti-spam utility. That loader performs reconnaissance and installs SNOWBELT into Microsoft Edge or another Chromium-based browser, including by launching the browser in hidden or headless mode with extension-loading arguments to bypass normal user-driven installation flow.
Once installed, SNOWBELT acts as both a persistence mechanism and a command relay. It has been used to harvest saved browser credentials and session cookies, enabling continued access to enterprise accounts and reducing the need for repeated authentication. It also supports delivery and coordination of additional SNOW components, notably SNOWGLAZE, a Python-based tunneling utility, and SNOWBASIN, a local backdoor used for command execution and follow-on operations. In reported intrusions, commands were relayed through SNOWBELT to downstream tooling that enabled remote shell access, screenshot capture, file transfer, reconnaissance, and lateral movement.
The malware is designed for stealth and blends into normal enterprise activity by abusing trusted platforms, legitimate browser functionality, and common administrative workflows rather than exploiting a software vulnerability. It has been used in enterprise-focused compromises targeting corporate environments, with follow-on activity including credential theft, internal network discovery, expansion of access, and staging of sensitive data for exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once the AutoHotkey script runs, it performs reconnaissance and installs SNOWBELT, a rogue browser extension, by launching Microsoft Edge in a hidden mode.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
SnowBelt functions as a backdoor that allows attackers to maintain access to corporate accounts and move through internal systems without repeated authentication.
The hacker sends a link to a fake “Mailbox Repair” utility or asks the victim to open remote access tools like Quick Assist. Either way, they install the SNOW malware suite.
Once it's clicked, it leads to the download of an AutoHotkey script from a threat actor-controlled AWS S3 bucket.
Step 2 — The helper arrives on Teams Right away, an external Microsoft Teams account named “IT Helpdesk” messages the victim. The hacker offers to fix the email issue immediately.
Security teams should watch for... scheduled tasks that launch Edge in headless mode...
The extension executes on a headless Microsoft Edge instance, so the victim doesn’t notice anything, while scheduled tasks and a startup folder shortcut are also created for persistence.
The first stage downloads an AutoHotKey binary and an AutoHotkey script, which immediately starts performing reconnaissance... SnowGlaze is a Python-based tunneler... Finally, SnowBasin is a Python bindshell...
Security teams should watch for... scheduled tasks that launch Edge in headless mode...
The extension executes on a headless Microsoft Edge instance, so the victim doesn’t notice anything, while scheduled tasks and a startup folder shortcut are also created for persistence.
SnowBelt functions as a backdoor that allows attackers to maintain access to corporate accounts and move through internal systems without repeated authentication.
The hacker sends a link to a fake “Mailbox Repair” utility or asks the victim to open remote access tools like Quick Assist. Either way, they install the SNOW malware suite.
Once the AutoHotkey script runs, it performs reconnaissance and installs SNOWBELT, a rogue browser extension, by launching Microsoft Edge in a hidden mode using command line settings that skip normal installation checks.
Security teams should watch for... scheduled tasks that launch Edge in headless mode...
The extension executes on a headless Microsoft Edge instance, so the victim doesn’t notice anything, while scheduled tasks and a startup folder shortcut are also created for persistence.
SnowBelt functions as a backdoor that allows attackers to maintain access to corporate accounts and move through internal systems without repeated authentication.
This directs victims to a landing page masquerading as a 'Mailbox Repair Utility'... SnowBelt... often hides behind names like 'MS Heartbeat' or 'System Heartbeat.'
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malicious Chromium browser extension component of the SNOW ecosystem that is installed via hidden/headless Edge execution, operates within the browser, and survives restarts to support persistence and post-compromise activity.
A malicious Chromium browser extension used as part of the SNOW malware suite to provide backdoor access and steal saved credentials and session cookies from the browser.
A malicious Chromium browser extension that provides backdoor access and steals saved credentials and session cookies.
A malicious browser extension/backdoor used to maintain access to corporate accounts and enable movement through internal systems without repeated authentication. It can also download additional malicious components.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.