🧵During a @HuntressLabs SOC investigation, a signal was raised for a user-level scheduled task launching msedge.exe in headless mode with --load-extension.
That pivot led to discovering SNOWBELT: a malicious Chromium/Edge extension mirroring UNC6692 tradecraft.
Thread below 👇
The dangers of SNOWBELT/ UNC6692 tradecraft:
SNOWBELT can act as a browser-based command relay, helping bridge operator access to local follow-on tooling such as SNOWBASIN.
That means potential command execution, data staging, and lateral movement support.
🚨 17,000+ attacks in just 10 hours 🚨
I set up a T-Pot honeypot on a cloud-based virtual machine,
left it fully exposed—no firewall, no access restrictions.
How long did it take for attackers to find it?
⏳ Less than 2 minutes.
🧵👇 What happened next? (1/4)
Key takeaways for defenders:
➡️ Default credentials are still a major risk
➡️ Scanning is rapid, constant & fully automated
➡️ Old malware is STILL actively spreading
Your internet-facing systems ARE being targeted—often within minutes.