UNC6692UNC6692

Also known as: UNC6692

Known aliases
1

Profile

UNC6692 is a threat actor that employs social engineering tactics, such as impersonating IT helpdesk personnel, to gain initial access to victim environments. They utilize a custom modular malware suite, including components like SNOWBELT, SNOWGLAZE, and SNOWBASIN, to facilitate deep network penetration and lateral movement. After extracting credentials from the LSASS process memory, they leverage Pass-The-Hash techniques to authenticate to domain controllers and exfiltrate sensitive data using LimeWire. The campaign highlights the systematic abuse of legitimate cloud services for payload delivery and command-and-control infrastructure.

Aliases· 1

UNC6692

References

  1. https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UNC6671
Actor
UNC6691
Actor
UNC6293
Actor
UNC2465
Actor
UNC6395
Actor
UNC2659
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.