logo

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

ID: db1240e3-2329-5903-9170-482c5fd7b66f

STIX ID: report--db1240e3-2329-5903-9170-482c5fd7b66f

Feed Name: Threat Intelligence

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-27

Author: Mandiant

...
...

**Executive summary:** UNC6692 leveraged SNOWBELT/SNOWGLAZE to tunnel into a victim environment, performed internal port scanning and lateral movement via PsExec and RDP, dumped LSASS memory to harvest credentials, used Pass‑The‑Hash to access Domain Controllers, mounted and extracted NTDS.dit and registry hives with FTK Imager, and exfiltrated sensitive data via LimeWire while capturing screens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.