UNC6692 is a newly identified cybercrime threat cluster that conducts socially engineered intrusions centered on Microsoft Teams helpdesk impersonation. The actor typically begins with high-volume email bombing to create urgency and confusion, then contacts victims from external Teams accounts while posing as internal IT support. Victims are directed to a fake mailbox repair or spam-fix workflow that harvests credentials and delivers malware, or in some cases are persuaded to grant remote access through legitimate support tools such as Quick Assist. UNC6692 has been linked to targeted intrusions against enterprise environments, including the software sector, and reporting indicates a focus on senior employees and decision-makers for broader organizational access. The group is notable for deploying a custom modular malware ecosystem known as SNOW. This toolset includes SNOWBELT, a malicious Chromium-based browser extension used for persistence and command relay; SNOWGLAZE, a Python-based tunneling utility that creates authenticated WebSocket tunnels and supports proxying of internal traffic; and SNOWBASIN, a Python backdoor that provides remote command execution, screenshot capture, file operations, and data staging. Separate reporting also describes a related browser-focused backdoor called Edgecution, delivered through AutoHotkey-based staging and implemented as a malicious Microsoft Edge extension paired with a Python native messaging host. Across these operations, UNC6692 abuses legitimate cloud services for payload delivery, command-and-control, and exfiltration in order to blend malicious traffic with normal enterprise activity. Observed tradecraft includes credential theft through repeated password-entry phishing prompts, browser-extension sideloading, persistence via scheduled tasks and startup mechanisms, internal reconnaissance, local network scanning, use of PsExec and RDP for pivoting, LSASS memory extraction, and Pass-the-Hash for lateral movement to higher-value systems. Post-compromise objectives include theft of enterprise credentials and sensitive directory data, including Active Directory database material and registry hives, followed by exfiltration using legitimate-looking tools and cloud-hosted infrastructure. UNC6692 has been described as an initial access broker associated with ransomware ecosystems, including links to activity tied to Payouts King and tradecraft long associated with former Black Basta affiliates, but the cluster itself is primarily characterized by initial access, credential theft, persistence, lateral movement, and data theft rather than confirmed operation of a named ransomware program under its own banner.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related Teams-themed social-engineering campaign in which attackers impersonate IT helpdesk staff on Teams to deploy credential-stealing malware and backdoors.
Conducting targeted phishing and social-engineering operations using email bombing, Microsoft Teams IT-support impersonation, Quick Assist remote access, credential phishing, and deployment of the Edgecution malicious browser extension to gain initial access and persistent control.
Conducting social-engineering intrusions via spam flooding and Microsoft Teams helpdesk impersonation to steal credentials, gain remote access, establish persistence, harvest data, and exfiltrate information using the SNOW malware ecosystem.
Emerging offshoot mentioned as participating in similar Teams-based vishing and remote-access-enabled intrusion activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.