SNOW is a custom modular malware suite associated with the threat cluster UNC6692 and used in socially engineered intrusions that abuse Microsoft Teams helpdesk impersonation. The intrusion chain commonly begins with email bombing to create urgency and confusion, followed by contact from an attacker posing as IT support through external Teams messaging. Victims are persuaded to follow a fake remediation workflow and execute a purported patch, after which SNOW is deployed on the compromised Windows host.
The SNOW ecosystem has been described as comprising multiple components, including SNOWBELT, a malicious Chromium-based browser extension used for stealth, persistence, and command relay; SNOWGLAZE, a tunneling utility that supports proxying and covert operator communications; and SNOWBASIN, a local HTTP backdoor that enables remote command execution and host interaction. Observed behavior includes hidden or headless browser launches to install the extension, scheduled-task or startup-based persistence, command execution, screenshot capture, file operations, credential harvesting, and data exfiltration. The tooling is designed to blend command-and-control and exfiltration traffic with legitimate cloud services and normal Windows activity, complicating detection.
Post-compromise activity attributed to UNC6692 includes internal reconnaissance, scanning for reachable services, lateral movement using stolen credentials, and broader domain compromise objectives. Reported follow-on actions include credential theft, pass-the-hash-style expansion, access to domain controllers, and theft of sensitive directory data. The malware suite is therefore best characterized as a backdoor platform used to establish durable access and support hands-on-keyboard post-exploitation and exfiltration in enterprise environments.
Separately, Snow has also been identified in another context as an ITG23-related crypter first observed in late 2022 and likely the successor to Hexa based on code overlap. That usage ties Snow to malware protection and obfuscation activity around families such as Qakbot. Because the same name is used for both a UNC6692 malware suite and an ITG23-linked crypter, the label is overloaded and should be interpreted carefully in context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The second is Snow, which was first observed in December 2022. Its introduction coincided with the retirement of Hexa, and code overlap between the two indicates that Snow is likely Hexa’s successor.
A newly identified threat group tracked as UNC6692 is hijacking Microsoft Teams to install a custom malware suite called SNOW.
Secondary Payload Deployment: Rapid execution of malicious loaders or novel backdoors (such as SNOW malware) within minutes of session establishment.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
That button triggers a login prompt, and the page asks for credentials multiple times under the guise of verification... The captured logins are then quietly sent to a cloud location controlled by the attacker.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular malware ecosystem used after initial social-engineering compromise via Microsoft Teams. It includes a malicious browser extension, a Python-based tunneling tool, and a local backdoor to maintain persistence, harvest credentials, support command-and-control, capture screenshots, exfiltrate files, and terminate sessions.
A novel backdoor cited as a secondary payload deployed shortly after remote-session establishment in Teams-based intrusion activity.
Custom malware suite used after social-engineering-based initial access to steal sensitive data following deep network compromise. It includes SnowBelt for persistence and command relay, SnowGlaze for WebSocket tunneling and SOCKS proxying, and SnowBasin, a Python-based backdoor that provides remote shell access, command execution, data exfiltration, file download, screenshot capture, and file management.
SNOW is used after initial phishing-based access to enable lateral movement and data exfiltration within the victim network.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.