UNC6692 is a financially motivated cybercriminal threat cluster active since at least December 2025. It conducts credential theft and data-theft intrusions and operates as an initial access broker, selling access to ransomware operations including Payouts King. Confirmed targeting includes the software industry. Its geographic origin is not established. UNC6692 combines email bombing with IT helpdesk impersonation over Microsoft Teams. After overwhelming victims with spam, attackers contact them from external Teams accounts and offer to resolve the disruption. Victims are directed to a fraudulent mailbox-repair page or persuaded to grant remote access through Microsoft Quick Assist. Credential-harvesting pages deliberately reject password submissions to encourage repeated entry, while purported repair downloads deploy AutoHotkey-based staging scripts. The group abuses legitimate cloud services, including Amazon S3, for payload delivery, credential exfiltration, and command-and-control. Its custom SNOW malware suite comprises SNOWBELT, a malicious Chromium browser-extension backdoor; SNOWGLAZE, a Python tunneler supporting authenticated WebSocket tunnels and SOCKS proxying; and SNOWBASIN, a Python backdoor exposing a local HTTP command interface. These components provide persistence, remote command execution, screenshot capture, file transfer, and access to internal networks. Persistence mechanisms include browser-extension registration, scheduled tasks, and startup shortcuts. Hidden or headless Microsoft Edge execution, cloud-hosted communications, and target-gating scripts support defense evasion. UNC6692 has also deployed Edgecution, a malicious Microsoft Edge extension paired with a Python native messaging host. Edgecution monitors browser activity and supports arbitrary command execution, host fingerprinting, process enumeration, and file writes. Observed post-compromise activity includes internal network scanning, PsExec and RDP access through tunnels, LSASS memory extraction, and pass-the-hash movement to domain controllers. Attackers have used FTK Imager to collect the Active Directory database and sensitive registry data, followed by exfiltration using LimeWire.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a user of email-bombing and vishing-style social engineering for initial access.
Named as an activity cluster using email flooding followed by IT-support impersonation. Its mention provides background on shared social-engineering methods rather than attribution of the Sauron Loader incidents.
Related Teams-themed social-engineering campaign in which attackers impersonate IT helpdesk staff on Teams to deploy credential-stealing malware and backdoors.
Conducting targeted phishing and social-engineering operations using email bombing, Microsoft Teams IT-support impersonation, Quick Assist remote access, credential phishing, and deployment of the Edgecution malicious browser extension to gain initial access and persistent control.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.