UNC6692 is a threat actor that gains initial access by impersonating IT helpdesk personnel through social engineering.
Analyst brief
UNC6692 is a threat actor that gains initial access by impersonating IT helpdesk personnel using social engineering. They target organizations, deploying a custom modular malware suite with components like SNOWBELT, SNOWGLAZE, and SNOWBASIN for deep network penetration and lateral movement. After extracting credentials from LSASS process memory, they leverage Pass-The-Hash techniques to authenticate to domain controllers and exfiltrate data via LimeWire. Defenders should monitor for suspicious IT helpdesk interactions, abnormal LSASS access attempts, and the abuse of legitimate cloud services for C2 infrastructure.
UNC6692
unknown
UNC6692 is a threat actor that employs social engineering tactics, such as impersonating IT helpdesk personnel, to gain initial access to victim environments. They utilize a custom modular malware suite, including components like SNOWBELT, SNOWGLAZE, and SNOWBASIN, to facilitate deep network penetration and lateral movement. After extracting credentials from the LSASS process memory, they leverage Pass-The-Hash techniques to authenticate to domain controllers and exfiltrate sensitive data using LimeWire. The campaign highlights the systematic abuse of legitimate cloud services for payload delivery and command-and-control infrastructure.