Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Mandiant Blog·34d·Reputable
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692
Categories cybersecurity · government-security · unknown-it-category-15
Original source / advisory ↗Published
4/23/2026, 2:00:00 PM
Fetched
5/27/2026, 4:13:32 AM
Trust
reputable · 80/100
Language
en