CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 314

As cited

Copy frozen at (site build).

threat intel

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence identified UNC6692, a previously unknown threat group, conducting a multistage intrusion campaign that combined mass email bombardment, Microsoft Teams social engineering impersonating IT helpdesk staff, and a custom malware suite. The attack chain involved tricking victims into downloading a renamed AutoHotkey binary that deployed SNOWBELT, a malicious Chromium browser extension, with persistence established through scheduled tasks and startup folder shortcuts.

Why it matters: Organizations should implement multi-factor authentication for Teams and email systems, train employees on social engineering tactics targeting IT support scenarios, and monitor for unsigned browser extensions and suspicious AutoHotkey execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence identified UNC6692, a previously unknown threat group, conducting a multistage intrusion campaign that combined mass email bombardment, Microsoft Teams social engineering impersonating IT helpdesk staff, and a custom malware suite. The attack chain involved tricking victims into downloading a renamed AutoHotkey binary that deployed SNOWBELT, a malicious Chromium browser extension, with persistence established through scheduled tasks and startup folder shortcuts.

Why it matters: Organizations should implement multi-factor authentication for Teams and email systems, train employees on social engineering tactics targeting IT support scenarios, and monitor for unsigned browser extensions and suspicious AutoHotkey execution.

VendorsMicrosoftGoogleAmazon Web Services
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary