As cited
Copy frozen at (site build).
threat intel
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Google Threat Intelligence identified UNC6692, a previously unknown threat group, conducting a multistage intrusion campaign that combined mass email bombardment, Microsoft Teams social engineering impersonating IT helpdesk staff, and a custom malware suite. The attack chain involved tricking victims into downloading a renamed AutoHotkey binary that deployed SNOWBELT, a malicious Chromium browser extension, with persistence established through scheduled tasks and startup folder shortcuts.
Why it matters: Organizations should implement multi-factor authentication for Teams and email systems, train employees on social engineering tactics targeting IT support scenarios, and monitor for unsigned browser extensions and suspicious AutoHotkey execution.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Google Threat Intelligence identified UNC6692, a previously unknown threat group, conducting a multistage intrusion campaign that combined mass email bombardment, Microsoft Teams social engineering impersonating IT helpdesk staff, and a custom malware suite. The attack chain involved tricking victims into downloading a renamed AutoHotkey binary that deployed SNOWBELT, a malicious Chromium browser extension, with persistence established through scheduled tasks and startup folder shortcuts.
Why it matters: Organizations should implement multi-factor authentication for Teams and email systems, train employees on social engineering tactics targeting IT support scenarios, and monitor for unsigned browser extensions and suspicious AutoHotkey execution.
- Source published
- First seen by Cybersecurity Tracker