eSentire TRU reported a July 2026 phishing campaign attributed to UNC6692 that used email bombing, Microsoft Teams impersonation, Quick Assist, and a phishing site to deliver the Edgecution malicious browser extension to a software industry victim. Edgecution abused a Microsoft Edge extension plus a native messaging host to monitor targeted websites, steal credentials, and execute commands on the host system. #UNC6692 #Edgecution #MicrosoftEdge #MicrosoftTeams
Keypoints
- UNC6692 targeted a customer in the software industry in July 2026 using a phishing campaign investigated by eSentire TRU.
- The attack began with email bombing, then shifted to Microsoft Teams impersonation under the identity âIT Support | Corporate IT Service (Internal).â
- The victim was guided to use Quick Assist, enabling the attackers to gain hands-on access and direct the browser-based infection flow.
- Attackers used an Amazon S3-hosted phishing site that mimicked Office 365 and delivered AutoHotkey, a stager script, and related files for Edgecution.
- Edgecution is a malicious Microsoft Edge extension paired with a Python native messaging host that escapes the browser sandbox to control the host.
- The malware can monitor targeted websites in real time, capture Office 365 credentials, write files, enumerate processes, and run arbitrary shell, Python, or PowerShell commands.
- UNC6692 is described as an initial access broker associated with ransomware groups such as Payouts King.
MITRE Techniques
- [T1566 ] Phishing â The campaign used a phishing site and credential capture flow to trick the victim into entering Office 365 credentials (âdesigned to resemble a legitimate Office 365 siteâ and âcapture the victimâs Office 365 passwordâ).
- [T1589 ] Gather Victim Identity Information â The threat actors impersonated internal IT support over Microsoft Teams to build trust and direct the victim (âwhile impersonating âIT Support | Corporate IT Service (Internal).ââ).
- [T1090 ] Proxy: External Proxy â Attackers used Microsoft Teams and Quick Assist as intermediary trusted channels to reach the victim and obtain interactive access (âcontact the victim via Microsoft Teamsâ and âinstructed the victim to launch Quick Assistâ).
- [T1056.001 ] Input Capture: Keylogging â The phishing form captured the victimâs password as it was entered (âthe victimâs password is capturedâ and âAfter the victim clicks the submit buttonâ).
- [T1204.001 ] User Execution: Malicious Link â The victim was induced to interact with links and downloads on the phishing site (âutilized the first two buttons on the page to download AutoHotkeyâ).
- [T1105 ] Ingress Tool Transfer â The stager downloaded the ZIP archive, AutoHotkey, and other payload components from S3 (âIt downloads a password-protected ZIP archive from AWS S3 containing Edgecutionâ).
- [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell â The malware used cmd.exe for self-deletion and command execution (âcmd /c start /min ⌠delâ).
- [T1059.001 ] Command and Scripting Interpreter: PowerShell â The native host executed PowerShell commands for enumeration and arbitrary code execution (âExecute arbitrary PowerShell codeâ and âGet-CimInstance Win32_Processâ).
- [T1059.006 ] Command and Scripting Interpreter: Python â The native messaging host supported arbitrary Python code execution (âExecute arbitrary python code async/syncâ).
- [T1055 ] Process Injection â Not observed directly; instead, the malware used browser extension and native messaging host bridging to extend control beyond the sandbox (âeffectively allowing the sandboxed browser extension to escape browser limitationsâ).
- [T1060 ] Registry Run Keys / Startup Folder â The stager created registry entries for the native messaging host and Edge configuration (âcreating registry entries⌠under Microsoft Edgeâs NativeMessagingHosts registry keyâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Persistence was established by creating and immediately running a scheduled task to launch Edge with the extension (âCreates a Scheduled Task ⌠configured to launch Microsoft Edgeâ).
- [T1027 ] Obfuscated Files or Information â The stager and native host strings were XOR-obfuscated and decoded at runtime (âAll strings in the stager are obfuscatedâ and âStrings within are decrypted at run-timeâ).
- [T1027.013 ] Obfuscated Files or Information: Encrypted/Encoded File â The ZIP archive was password-protected and reconstructed from stripped bytes (âThe ZIP archive is also password protectedâ and âreconstruction of the ZIP archiveâ).
- [T1115 ] Clipboard Data â The script parsed the victimâs clipboard to extract a reference code (âthe victimâs clipboard is parsed using the regex patternâ).
Indicators of Compromise
- [Domain-Name ] Edgecution C2 infrastructure â d385m5skczp5q5.cloudfront[.]net, d7xpwoah6gdv2.cloudfront[.]net, and 5 more domains
- [SHA256 ] Suspicious phishing site and payload artifacts â 232bca658c585627830623fcdce56647dc291666b25c901ee56212681198067a, e88c196a86c74ea0e53dfe77c93f577cb441ee590756cf7f3284522a2d6a6be5, and da1cf68c9dc1cebcebf8ec7d1cf99ac9c0291db7b21bf279b9cad24c7a49948c
- [URL ] Phishing and payload delivery URLs hosted on S3 â hxxps://app7040.s3.us-east-1.amazonaws[.]com/patch.html, hxxps://app5805.s3.us-east-1.amazonaws[.]com/js/patch3265343.a, and 3 more URLs
- [Command Line ] Edgecution deployment and execution â tar.exe -xf â.zipâ -C â%LOCALAPPDATA%MicrosoftEdgeUser Datatest1âł âpassphrase â â, cmd.exe /c python âversion 2>&1
- [Microsoft Teams Account ] IT impersonation accounts used by attackers â [email protected][.]com, [email protected][.]com