Email Bombing, IT Impersonation, Quick Assist, and Edgecution: Breaking Down UNC6692’s Tradecraft

Email Bombing, IT Impersonation, Quick Assist, and Edgecution: Breaking Down UNC6692’s Tradecraft
eSentire TRU reported a July 2026 phishing campaign attributed to UNC6692 that used email bombing, Microsoft Teams impersonation, Quick Assist, and a phishing site to deliver the Edgecution malicious browser extension to a software industry victim. Edgecution abused a Microsoft Edge extension plus a native messaging host to monitor targeted websites, steal credentials, and execute commands on the host system. #UNC6692 #Edgecution #MicrosoftEdge #MicrosoftTeams

Keypoints

  • UNC6692 targeted a customer in the software industry in July 2026 using a phishing campaign investigated by eSentire TRU.
  • The attack began with email bombing, then shifted to Microsoft Teams impersonation under the identity “IT Support | Corporate IT Service (Internal).”
  • The victim was guided to use Quick Assist, enabling the attackers to gain hands-on access and direct the browser-based infection flow.
  • Attackers used an Amazon S3-hosted phishing site that mimicked Office 365 and delivered AutoHotkey, a stager script, and related files for Edgecution.
  • Edgecution is a malicious Microsoft Edge extension paired with a Python native messaging host that escapes the browser sandbox to control the host.
  • The malware can monitor targeted websites in real time, capture Office 365 credentials, write files, enumerate processes, and run arbitrary shell, Python, or PowerShell commands.
  • UNC6692 is described as an initial access broker associated with ransomware groups such as Payouts King.

MITRE Techniques

  • [T1566 ] Phishing – The campaign used a phishing site and credential capture flow to trick the victim into entering Office 365 credentials (‘designed to resemble a legitimate Office 365 site’ and ‘capture the victim’s Office 365 password’).
  • [T1589 ] Gather Victim Identity Information – The threat actors impersonated internal IT support over Microsoft Teams to build trust and direct the victim (‘while impersonating “IT Support | Corporate IT Service (Internal).”‘).
  • [T1090 ] Proxy: External Proxy – Attackers used Microsoft Teams and Quick Assist as intermediary trusted channels to reach the victim and obtain interactive access (‘contact the victim via Microsoft Teams’ and ‘instructed the victim to launch Quick Assist’).
  • [T1056.001 ] Input Capture: Keylogging – The phishing form captured the victim’s password as it was entered (‘the victim’s password is captured’ and ‘After the victim clicks the submit button’).
  • [T1204.001 ] User Execution: Malicious Link – The victim was induced to interact with links and downloads on the phishing site (‘utilized the first two buttons on the page to download AutoHotkey’).
  • [T1105 ] Ingress Tool Transfer – The stager downloaded the ZIP archive, AutoHotkey, and other payload components from S3 (‘It downloads a password-protected ZIP archive from AWS S3 containing Edgecution’).
  • [T1059.003 ] Command and Scripting Interpreter: Windows Command Shell – The malware used cmd.exe for self-deletion and command execution (‘cmd /c start /min … del’).
  • [T1059.001 ] Command and Scripting Interpreter: PowerShell – The native host executed PowerShell commands for enumeration and arbitrary code execution (‘Execute arbitrary PowerShell code’ and ‘Get-CimInstance Win32_Process’).
  • [T1059.006 ] Command and Scripting Interpreter: Python – The native messaging host supported arbitrary Python code execution (‘Execute arbitrary python code async/sync’).
  • [T1055 ] Process Injection – Not observed directly; instead, the malware used browser extension and native messaging host bridging to extend control beyond the sandbox (‘effectively allowing the sandboxed browser extension to escape browser limitations’).
  • [T1060 ] Registry Run Keys / Startup Folder – The stager created registry entries for the native messaging host and Edge configuration (‘creating registry entries… under Microsoft Edge’s NativeMessagingHosts registry key’).
  • [T1053.005 ] Scheduled Task/Job: Scheduled Task – Persistence was established by creating and immediately running a scheduled task to launch Edge with the extension (‘Creates a Scheduled Task … configured to launch Microsoft Edge’).
  • [T1027 ] Obfuscated Files or Information – The stager and native host strings were XOR-obfuscated and decoded at runtime (‘All strings in the stager are obfuscated’ and ‘Strings within are decrypted at run-time’).
  • [T1027.013 ] Obfuscated Files or Information: Encrypted/Encoded File – The ZIP archive was password-protected and reconstructed from stripped bytes (‘The ZIP archive is also password protected’ and ‘reconstruction of the ZIP archive’).
  • [T1115 ] Clipboard Data – The script parsed the victim’s clipboard to extract a reference code (‘the victim’s clipboard is parsed using the regex pattern’).

Indicators of Compromise

  • [Domain-Name ] Edgecution C2 infrastructure – d385m5skczp5q5.cloudfront[.]net, d7xpwoah6gdv2.cloudfront[.]net, and 5 more domains
  • [SHA256 ] Suspicious phishing site and payload artifacts – 232bca658c585627830623fcdce56647dc291666b25c901ee56212681198067a, e88c196a86c74ea0e53dfe77c93f577cb441ee590756cf7f3284522a2d6a6be5, and da1cf68c9dc1cebcebf8ec7d1cf99ac9c0291db7b21bf279b9cad24c7a49948c
  • [URL ] Phishing and payload delivery URLs hosted on S3 – hxxps://app7040.s3.us-east-1.amazonaws[.]com/patch.html, hxxps://app5805.s3.us-east-1.amazonaws[.]com/js/patch3265343.a, and 3 more URLs
  • [Command Line ] Edgecution deployment and execution – tar.exe -xf “.zip” -C “%LOCALAPPDATA%MicrosoftEdgeUser Datatest1″ –passphrase ” “, cmd.exe /c python –version 2>&1
  • [Microsoft Teams Account ] IT impersonation accounts used by attackers – [email protected][.]com, [email protected][.]com


Read more: https://www.esentire.com/blog/email-bombing-it-impersonation-quick-assist-and-edgecution-breaking-down-unc6692s-tradecraft