logo

UNC6692 Combines Social Engineering, Malware, Cloud Abuse

ID: 486a0d80-a571-5b07-8781-391ec9608e78

STIX ID: report--486a0d80-a571-5b07-8781-391ec9608e78

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Alexander Culafi

...
...

Google Threat Intelligence Group and Mandiant reported on UNC6692, a newly tracked financially motivated threat actor that executed a multistage intrusion campaign combining targeted social engineering via Microsoft Teams, abuse of AWS S3 for payload/C2, and custom tooling (AutoHotkey payloads, SNOWBELT browser extension, Snowglaze/Snowbasin Python components). The actor performed reconnaissance, credential theft (LSASS memory extraction and pass-the-hash) and lateral movement to the domain controller; Google published IOCs and YARA rules and urged defenders to monitor browser activity and cloud egress alongside traditional process monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.