Also known as: tracked as, coordinat, a tunneler, a backdoor, JokerDPR
UNC6692 has emerged as a high‑profile adversary that leverages multi‑faceted social engineering tactics to breach organizations’ defenses. In recent operations, the actor floods corporate inboxes with spam and spearphishing links, then impersonates IT helpdesk staff through Microsoft Teams or Quick Assist remote sessions. During these sessions they deploy an AutoHotkey script that installs the malicious Edgecution browser extension, granting persistent control over web traffic and system processes. The campaign’s execution layer employs a custom modular malware stack—comprising SNOWBELT, SNOWGLAZE, and SNOWBASIN—which orchestrates lateral movement via Sysinternals PsExec, internal port scanning (135, 445, 3389), and establishment of tunneled RDP sessions. Credential access is extracted by dumping LSASS memory through the Windows Task Manager and exporting NTDS.dit, SAM, SYSTEM, and SECURITY registry hives with FTK Imager. These credentials are then leveraged in Pass‑The‑Hash attacks to reach domain controllers. Data exfiltration follows unconventional channels: captured memory dumps and registry files are encoded within LimeWire peer‑to‑peer transfers, while other command execution is routed through a SNOW backdoor listening on port 8000 via HTTP POST. UNC6692 routinely uses legitimate cloud services—Amazon S3-hosted phishing sites, Microsoft Azure domains, and other publicly available C2 infrastructure—to deliver payloads and maintain persistence. This combination of social engineering, modular malware, credential theft, and atypical exfiltration demonstrates a sophisticated threat with clear financial motives, targeting high‑value sectors across multiple geographies.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNC6692 is a financially motivated threat actor that exploits social engineering—particularly via Microsoft Teams and Quick Assist—to gain initial access to a wide range of sectoral targets. Once inside, they deploy a modular SNOW malware suite (SNOWBELT/SNOWGLAZE/SNOWBASIN) that performs credential dumping, lateral movement with Pass‑The‑Hash, and exfiltration over LimeWire or cloud services. The group’s rapid, multi-stage campaign targets defense, aerospace, manufacturing, government, and financial institutions across the US, EU, and Middle East.
Goals & Targeting
UNC6692’s strategic objective appears to be the acquisition of monetary value through illicit financial gains. By exploiting widely used collaboration tools (e.g., Microsoft Teams) and remote support software (Quick Assist), they are able to penetrate a broad spectrum of organizations—defense, aerospace, manufacturing, government, finance, tech, and healthcare—spanning key geopolitical regions including the US, EU, Russia, China, Israel, Iran, South Korea, North Korea, and Ukraine. Their tactics indicate a focus on high‑value information (credentials, AD databases, system files) that can be monetized or leveraged for future attacks.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNC6692 conducts rapid, multi‑stage operations that begin with mass email bombing and spearphishing. The attacker then impersonates IT personnel to gain footholds via Microsoft Teams or Quick Assist remote sessions, installs a malicious browser extension (Edgecution), and deploys a modular SNOW backdoor suite for lateral movement and persistence. Credential dumping (LSASS, AD database files) is followed by Pass‑The‑Hash attacks into domain controllers, with data exfiltration conducted over LimeWire peer‑to‑peer links or legitimate cloud services. The organization’s operational tempo spans multiple industries and regions, reflecting a broad, financially driven threat landscape.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information summarized here is drawn from multiple independent threat‑intelligence reports, providing a strong confidence level in the actor’s tactics and tools. However, certain details—such as precise attribution chain, first/last seen dates, full attack chronology, and any future capability development—remain incomplete or speculative. Continuous monitoring for new indicators, especially around cloud‑based delivery mechanisms and additional malware families, is recommended to fill these gaps.
No campaigns linked yet.
No observed data linked yet.
52
Techniques
49
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics