UnknownUnknown

UNC6692

Threat actor using social engineering via email spamming and Microsoft Teams phishing to deploy a modular malware suite.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
7.2
Moderate signal strength
Mentions9
Sources1
High conf.9
Last seenMay 2026
First observed
Last active
Origin
Aliases
1
Techniques
0
Campaigns
0

Attribution signals

9 mentions · 1 source
#1identifiedhigh
TTP matchMalware
mandiant
May 2026

"Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim's environment to achieve deep network penetration."

#2demonstrateshigh
TTP matchMalware
mandiant
May 2026

"The UNC6692 campaign demonstrates an interesting evolution in tactics, particularly the use of social engineering, custom malware, and a malicious browser extension, playing on the victim's inherent trust in several different enterprise software providers."

#3recordedhigh
MalwareTTP match
mandiant
May 2026

"Evidence of AutoHotKey execution was recorded immediately following the downloads resulting in initial reconnaissance commands and the installation of SNOWBELT, a malicious Chromium browser extension (not distributed through the Chrome Web Store)."

#4downloadedhigh
MalwareTTP match
mandiant
May 2026

"Using the SNOWBELT extension, UNC6692 downloaded additional files including SNOWGLAZE, SNOWBASIN, AutoHotkey scripts, and a ZIP archive containing a portable Python executable and required libraries."

#5recordedhigh
TTP match
mandiant
May 2026

"process execution telemetry recorded UNC6692 using a Python script to scan the local network for ports 135, 445, and 3389."

#6establishedhigh
TTP match
mandiant
May 2026

"Following internal port scanning, the threat actor established a Sysinternals PsExec session to the victims system via the SNOWGLAZE tunnel, and executed commands to enumerate local administrator accounts."

#7utilizedhigh
TTP match
mandiant
May 2026

"After gaining access to the backup server the threat actor utilized the local administrator account to extract the system's LSASS process memory with Windows Task Manager."

#8exfiltratedhigh
TTP match
mandiant
May 2026

"After extracting the process memory, UNC6692 exfiltrated it via LimeWire."

#9usedhigh
TTP match
mandiant
May 2026

"Now armed with the password hashes of elevated users, UNC6692 used Pass-The-Hash to move laterally to the network's domain controllers."

Hedge terms observed

demonstratesdownloadedestablishedexfiltratedidentifiedrecordedusedutilized