Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNC6692

Also known as: tracked as, coordinat, a tunneler, a backdoor, JokerDPR

Description

UNC6692 has emerged as a high‑profile adversary that leverages multi‑faceted social engineering tactics to breach organizations’ defenses. In recent operations, the actor floods corporate inboxes with spam and spearphishing links, then impersonates IT helpdesk staff through Microsoft Teams or Quick Assist remote sessions. During these sessions they deploy an AutoHotkey script that installs the malicious Edgecution browser extension, granting persistent control over web traffic and system processes. The campaign’s execution layer employs a custom modular malware stack—comprising SNOWBELT, SNOWGLAZE, and SNOWBASIN—which orchestrates lateral movement via Sysinternals PsExec, internal port scanning (135, 445, 3389), and establishment of tunneled RDP sessions. Credential access is extracted by dumping LSASS memory through the Windows Task Manager and exporting NTDS.dit, SAM, SYSTEM, and SECURITY registry hives with FTK Imager. These credentials are then leveraged in Pass‑The‑Hash attacks to reach domain controllers. Data exfiltration follows unconventional channels: captured memory dumps and registry files are encoded within LimeWire peer‑to‑peer transfers, while other command execution is routed through a SNOW backdoor listening on port 8000 via HTTP POST. UNC6692 routinely uses legitimate cloud services—Amazon S3-hosted phishing sites, Microsoft Azure domains, and other publicly available C2 infrastructure—to deliver payloads and maintain persistence. This combination of social engineering, modular malware, credential theft, and atypical exfiltration demonstrates a sophisticated threat with clear financial motives, targeting high‑value sectors across multiple geographies.

Goals & Targeting

Targeted Sectors

Defense
Aerospace
Manufacturing
Government
Financial services
Education
Energy
Healthcare
Hospitality
Telecommunications
Nuclear
Chemical
Maritime
Information technology
Legal services
Media
Transportation

Targeted Countries / Regions

UA
CN
RU
US
IL
IR
FR
KP
KR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 9 hours ago

Executive Summary

UNC6692 is a financially motivated threat actor that exploits social engineering—particularly via Microsoft Teams and Quick Assist—to gain initial access to a wide range of sectoral targets. Once inside, they deploy a modular SNOW malware suite (SNOWBELT/SNOWGLAZE/SNOWBASIN) that performs credential dumping, lateral movement with Pass‑The‑Hash, and exfiltration over LimeWire or cloud services. The group’s rapid, multi-stage campaign targets defense, aerospace, manufacturing, government, and financial institutions across the US, EU, and Middle East.

Goals & Targeting

UNC6692’s strategic objective appears to be the acquisition of monetary value through illicit financial gains. By exploiting widely used collaboration tools (e.g., Microsoft Teams) and remote support software (Quick Assist), they are able to penetrate a broad spectrum of organizations—defense, aerospace, manufacturing, government, finance, tech, and healthcare—spanning key geopolitical regions including the US, EU, Russia, China, Israel, Iran, South Korea, North Korea, and Ukraine. Their tactics indicate a focus on high‑value information (credentials, AD databases, system files) that can be monetized or leveraged for future attacks.

Enhanced Description

Key Capabilities

  • Email bombing spam campaign
  • Impersonation of IT support via Microsoft Teams and Quick Assist remote sessions
  • Downloading files from Amazon S3-hosted phishing site
  • Execution of AutoHotkey scripts to deploy Edgecution malicious browser extension
  • Local network port scanning (135, 445, 3389) using Python script
  • Use of Sysinternals PsExec for lateral movement
  • Establishing SNOWGLAZE tunnel and RDP sessions for privileged access
  • Extraction of LSASS memory via Windows Task Manager
  • Exfiltration of captured memory through LimeWire
  • Pass‑The‑Hash lateral movement
  • Credential dumping via FTK Imager
  • Registry hive extraction (SAM, SYSTEM, SECURITY) and NTDS.dit capture
  • Screen capture on target systems
  • Modular attack pipeline using SNOWBELT/SNOWGLAZE/SNOWBASIN
  • Use of legitimate cloud services for payload delivery and C2
  • Remote command execution via HTTP POST to local backdoor

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Lateral Movement
Privilege Escalation
Defense Evasion
Credential Access
Exfiltration
Command and Control

ATT&CK Techniques

T1003.001
T1003.002
T1015
T1021.001
T1021.002
T1046
T1054
T1055
T1059
T1059.003
T1059.006
T1059.007
T1059.010
T1068
T1070.004
T1071.004
T1083
T1104
T1112
T1134
T1134.001
T1140
T1156
T1202
T1204.001
T1204.002
T1223
T1255
T1518.001
T1534
T1543
T1543.003
T1547.001
T1547.009
T1559
T1562.001
T1566.002
T1566.004
T1569.002
T1571
T1621
T1622

Software / Tooling

SNOWBELT
SNOWGLAZE
SNOWBASIN
Edgecution
AutoHotkey Script
Sysinternals PsExec
Quick Assist
LimeWire
FTK Imager

Campaigns & Victims

UNC6692 conducts rapid, multi‑stage operations that begin with mass email bombing and spearphishing. The attacker then impersonates IT personnel to gain footholds via Microsoft Teams or Quick Assist remote sessions, installs a malicious browser extension (Edgecution), and deploys a modular SNOW backdoor suite for lateral movement and persistence. Credential dumping (LSASS, AD database files) is followed by Pass‑The‑Hash attacks into domain controllers, with data exfiltration conducted over LimeWire peer‑to‑peer links or legitimate cloud services. The organization’s operational tempo spans multiple industries and regions, reflecting a broad, financially driven threat landscape.

IOC Patterns

  • Email flood/spam campaign
  • External Microsoft Teams contact impersonating IT support
  • Amazon S3-hosted phishing site URLs
  • Malicious browser extension masquerading as monitoring agent
  • NTDS.dit file capture
  • SAM registry hive extraction
  • SYSTEM registry hive extraction
  • SECURITY registry hive extraction
  • Screen capture files
  • HTTP POST traffic to local port 8000 backdoor
  • P2P file‑sharing (LimeWire) exfiltration
  • File hash patterns
  • Domain name patterns

Recommended Actions

  • Implement strict validation for external Microsoft Teams invitations and verify sender identity before accepting.
  • Provide user awareness training on recognizing impersonated IT support communications, especially via Teams or Quick Assist.
  • Block or monitor AutoHotkey scripts and unauthorized browser extensions such as Edgecution from being installed or executed.
  • Deploy network monitoring to detect internal port scanning activity (ports 135, 445, 3389) and unusual PsExec usage.
  • Enable Windows Defender Credential Guard or similar protection to prevent LSASS memory dumping via Task Manager.
  • Configure outbound filtering to block exfiltration through peer‑to‑peer channels like LimeWire.
  • Implement monitoring for Pass‑The‑Hash activity and NTLM hash passes.
  • Enable detection of forensic tools such as FTK Imager on domain controllers.
  • Block or scrutinize data exfiltration attempts involving AD database files (NTDS.dit) and registry hives (SAM, SYSTEM, SECURITY).
  • Detect and investigate screen capture behaviors on critical systems.
  • Restrict outbound HTTP POST traffic to local backdoors (e.g., port 8000) and monitor for SNOW component signatures.
  • Disable or restrict usage of peer‑to‑peer file‑sharing protocols such as LimeWire.
  • Enforce security controls on cloud service usage and block malicious URLs.
  • Deploy eDiscovery and anomaly detection solutions to flag unusual credential use.

Suggested Tags

UNC6692
Microsoft Teams phishing
Edgecution
AutoHotkey malicious script
Snow malware
Email bombing
Quick Assist remote session
LSASS dump
LimeWire exfiltration
SNOW malware ecosystem
FTK Imager abuse
Pass-The-Hash
Spearphishing link
Python-based command execution

Confidence Assessment

The information summarized here is drawn from multiple independent threat‑intelligence reports, providing a strong confidence level in the actor’s tactics and tools. However, certain details—such as precise attribution chain, first/last seen dates, full attack chronology, and any future capability development—remain incomplete or speculative. Continuous monitoring for new indicators, especially around cloud‑based delivery mechanisms and additional malware families, is recommended to fill these gaps.

ATT&CK Techniques

Collection
1 technique
Defense impairment
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 13 URL 4 Filename 1 SHA-256 Hash 1 MD5 Hash 1

References

  1. cloud.google.com — Cited by web research for: coordinat
  2. www.bleepingcomputer.com — Cited by web research for: a tunneler
  3. cloud.google.com — Cited by web research for: T1566.002
  4. www.esentire.com — Cited by web research for: PowerShell
  5. attack.mitre.org — Cited by web research for: Interception
  6. www.esentire.com — Cited by web research for: Remote access tools
  7. www.crowdstrike.com — Cited by web research for: Fal.Con
  8. https://www.instagram.com/p/DXjzSEfmJeC/ — Cited by AI analysis.
  9. https://techjacksolutions.com/scc-intel/teams-federation-phishing-apt29-and-unc6692-exploit-default-permissive-settings-for — Cited by AI analysis.
  10. https://thehackernews.com/2026/04/unc6692-impersonates-it-helpdesk-via.html — Cited by AI analysis.

Intel Summary

52

Techniques

49

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Critical Infrastructure
Data Exfiltration
UNC6692
Microsoft Teams phishing
Edgecution
AutoHotkey malicious script
Snow malware
Email bombing
Quick Assist remote session
LSASS dump
LimeWire exfiltration
SNOW malware ecosystem
FTK Imager abuse
Pass-The-Hash
Spearphishing link
Python-based command execution

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.