UNC6692 Uses Email Bombing, IT Impersonation and Quick Assist to Deploy Edgecution

Summary
eSentire details a UNC6692 phishing campaign that used email bombing and Microsoft Teams IT impersonation to gain Quick Assist access, steal Office 365 credentials, and attempt to install the Edgecution backdoor.
Key points
- eSentire attributed a July 2026 targeted campaign affecting a Software industry customer to UNC6692.
- Attackers flooded the victim's inbox, then posed as internal IT support on Microsoft Teams and used Quick Assist to gain hands-on access.
- A phishing site hosted on Amazon S3 mimicked Office 365, captured passwords, and delivered AutoHotkey tools used to install Edgecution.
- Edgecution combines a malicious Edge extension with a Python native messaging host, enabling keyword-based browser monitoring and arbitrary command, Python, and PowerShell execution on the host.
- The malware uses scheduled-task persistence, obfuscated strings, and a WebSocket connection to its command-and-control server; the stager also changes its Edge launch options when it detects CrowdStrike or Sophos.
- eSentire isolated the affected host, assisted with remediation, and said it was developing detection content; its recommendations include restricting unrecognized external Teams contacts and using endpoint detection and response.
Article Details
- Attack Vectors
- Email bombing created a disruption that UNC6692 used as a pretext for contacting the victim through an external Microsoft Teams account while impersonating internal IT support.
- The victim was instructed to start Quick Assist and grant remote access. The attackers then visited an Amazon S3-hosted phishing site and downloaded AutoHotkey and a malicious installation script.
- The phishing site imitated Office 365 and offered an updates registration form that captured passwords. Captured credentials were uploaded to an S3 bucket through PUT requests.
- The AutoHotkey stager downloaded a password-protected archive, reconstructed its ZIP header, registered a native messaging host, and created a scheduled task to launch a malicious browser extension.
- A malicious browser extension paired with a Python-based native messaging host enabled website monitoring, arbitrary command execution, file writes, process enumeration, and host fingerprinting.
- The phishing site also supported alternative delivery options that copied Batch or PowerShell scripts to the victim's clipboard.
- Defensive Notes
- eSentire isolated the affected host to contain the infection and assisted the customer with remediation.
- Restrict or disable external collaboration contacts from unrecognized tenants where business requirements permit; otherwise require explicit approval for external contacts.
- Provide phishing and security awareness training using realistic social-engineering scenarios.
- Use continuous, multi-signal managed detection and response for threat hunting, containment, and rapid response; at minimum, deploy next-generation antivirus or endpoint detection and response.
- The stager checks for specific endpoint security software and changes browser launch parameters to avoid displaying a window.
- The archive's missing ZIP magic bytes were assessed as a likely evasion measure against network detections for ZIP downloads.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | d1jp293q9tvi92[.]cloudfront[.]net | CloudFront hostname listed as Edgecution C2 infrastructure. |
| DOMAIN | d23l50n6ubud7p[.]cloudfront[.]net | CloudFront hostname listed as Edgecution C2 infrastructure. |
| DOMAIN | d2g6dl71gua1qa[.]cloudfront[.]net | CloudFront hostname listed as Edgecution C2 infrastructure. |
| DOMAIN | d3434apz0x8t7d[.]cloudfront[.]net | CloudFront hostname listed as Edgecution C2 infrastructure. |
| DOMAIN | d385m5skczp5q5[.]cloudfront[.]net | CloudFront hostname listed as Edgecution C2 infrastructure. |
| DOMAIN | d3nh8sl98s2554[.]cloudfront[.]net | CloudFront hostname listed as Edgecution C2 infrastructure. |
| DOMAIN | d7xpwoah6gdv2[.]cloudfront[.]net | CloudFront hostname listed as Edgecution C2 infrastructure. |
| SHA256 | 232bca658c585627830623fcdce56647dc291666b25c901ee56212681198067a | Hash provided for the phishing site analyzed in the attack. |
| SHA256 | da1cf68c9dc1cebcebf8ec7d1cf99ac9c0291db7b21bf279b9cad24c7a49948c | Hash provided for the Edgecution archive analyzed in the article. |
| SHA256 | e88c196a86c74ea0e53dfe77c93f577cb441ee590756cf7f3284522a2d6a6be5 | Malicious AutoHotkey stager that downloads and installs Edgecution. |
| URL | hxxps[:]//app5805[.]s3[.]us-east-1[.]amazonaws[.]com/js/patch3265343[.]a | Specific S3-hosted Edgecution archive download URL. |
| URL | hxxps[:]//app7040[.]s3[.]us-east-1[.]amazonaws[.]com/patch[.]html | S3-hosted phishing page used in the attack. |
| URL | hxxps[:]//app7570[.]s3[.]us-east-1[.]amazonaws[.]com/js/set36418917[.]a | Specific S3-hosted Edgecution archive download URL. |
| URL | hxxps[:]//app7570[.]s3[.]us-east-1[.]amazonaws[.]com/js/set36418917[.]ahk | Specific S3-hosted malicious AutoHotkey stager download URL. |
| URL | hxxps[:]//app7570[.]s3[.]us-east-1[.]amazonaws[.]com/js/set36418917[.]exe | Attacker-used S3 resource distributing AutoHotkey for execution of the malicious stager. |
| URL | hxxps[:]//cloud3043[.]s3[.]us-east-1[.]amazonaws[.]com/patch[.]html | S3-hosted phishing page listed in the indicators. |
| URL | hxxps[:]//cloud48949[.]s3[.]us-east-1[.]amazonaws[.]com/patch[.]html | S3-hosted phishing page listed in the indicators. |
| URL | hxxps[:]//cloud9069[.]s3[.]us-east-1[.]amazonaws[.]com/patch[.]html | S3-hosted phishing page listed in the indicators. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe stager uses XOR-obfuscated strings; the native host uses Base64 and XOR string encoding, and the extension's JavaScript is obfuscated.T1033 · System Owner/User DiscoveryThe native host's fingerprinting command collects the victim's username.T1041 · Exfiltration Over C2 ChannelThe extension sends full URLs and matched monitoring keywords to its C2, queuing them when the WebSocket connection is unavailable.T1053.005 · Scheduled TaskThe stager creates and immediately runs a Windows scheduled task that launches Microsoft Edge with the malicious extension.T1056.003 · Web Portal CaptureThe phishing site's updates registration form captures the victim's Office 365 password and displays a hard-coded incorrect-password message to prompt re-entry.T1057 · Process DiscoveryThe native host enumerates running processes using Get-CimInstance Win32_Process and returns process identifiers, paths, and command lines.T1059.001 · PowerShellThe native messaging host executes arbitrary PowerShell code and uses PowerShell to enumerate running processes.T1059.003 · Windows Command ShellThe stager uses cmd to run its delayed self-deletion command, and native-host PowerShell execution is wrapped in a cmd command line.T1059.006 · PythonThe Python-based native messaging host supports executing arbitrary Python code synchronously or asynchronously.T1070.004 · File DeletionThe stager deletes its script and AutoHotkey executable after installation; the native host also supports deleting the file containing the C2 URL.T1082 · System Information DiscoveryThe native host fingerprints the victim's computer name, operating system version, and Python version.T1105 · Ingress Tool TransferThe attackers downloaded the AutoHotkey stager, and the stager retrieved an Edgecution archive from S3; the native host also supports receiving files from C2.T1112 · Modify RegistryThe stager registers an Edge native messaging host through registry entries and writes an AppKey registry value containing the payload's XOR key.T1115 · Clipboard DataThe phishing page parses the victim's clipboard for a reference code using the pattern 00FFAE45\-[0-9A-F\-]+.T1140 · Deobfuscate/Decode Files or InformationThe stager decrypts XOR-obfuscated strings and reconstructs the downloaded archive by prepending ZIP magic bytes; the native host decrypts strings at runtime.T1176 · Software ExtensionsEdgecution is sideloaded into Microsoft Edge as a malicious extension masquerading as "Edge Monitoring Agent".T1219 · Remote Access ToolsThe attackers instructed the victim to launch Quick Assist and used the granted remote access to stage the malware.T1518.001 · Security Software DiscoveryThe stager checks for CrowdStrike or Sophos and selects different browser launch parameters when either is detected.T1566.003 · Spearphishing via ServiceUNC6692 contacted the victim through an external Microsoft Teams account using an IT support pretext after email bombing.T1567.002 · Exfiltration to Cloud StorageThe phishing page uploads captured credentials to an S3 bucket through PUT requests.T1656 · ImpersonationThe attackers impersonated "IT Support | Corporate IT Service (Internal)" to persuade the victim to grant access.
Threat Actors
Payouts KingNamed as a ransomware group for which UNC6692 operates as an initial access broker, according to Zscaler reporting cited by the article; its involvement in this specific incident was not established.UNC6692eSentire attributed the July 2026 attack against a Software industry customer to this actor. The article cites Zscaler reporting that it operates as an initial access broker for ransomware groups.
Malware
Vendors
Amazonand instructed the victim to launch Quick Assist. After obtaining hands-on access, they navigated to an Amazon S3-hosted phishing site and downloaded the files required to load Edgecution.CrowdStrikeEdge command line to load the Edgecution extension from disk. If EDR is detected, specifically CrowdStrike or Sophos, it avoids using --headless=new parameter and uses the --no-startup-window parameter instead.eSentireIn July 2026, eSentire's Threat Response Unit (TRU) identified a targeted phishing campaign attributed to UNC6692 that impacted a customer in the Software industry. The campaign began with an email bombing attack, afterMicrosoftThe campaign began with an email bombing attack, after which the threat actors contacted the victim via Microsoft Teams while impersonating "IT Support | Corporate IT Service (Internal)." Further investigation into theSophoscommand line to load the Edgecution extension from disk. If EDR is detected, specifically CrowdStrike or Sophos, it avoids using --headless=new parameter and uses the --no-startup-window parameter instead. In either
Products
Amazon S3and instructed the victim to launch Quick Assist. After obtaining hands-on access, they navigated to an Amazon S3-hosted phishing site and downloaded the files required to load Edgecution.AutoHotkeyaccess. Once connected, threat actors navigated to an Amazon S3-hosted phishing site and downloaded AutoHotkey along with a malicious AutoHotkey script, which was then executed to install Edgecution.eSentire MDR for EndpointTRU is closely monitoring campaigns involving Edgecution and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.eSentire MDR for LogTRU is closely monitoring campaigns involving Edgecution and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.eSentire MDR for NetworkTRU is closely monitoring campaigns involving Edgecution and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.Microsoft EdgeActing as a backdoor, Edgecution gives operators extensive control over the victim's Microsoft Edge browser and host system, enabling them to monitor visits to targeted websites, such as banking, email, VPN, andMicrosoft Teamscampaign began with an email bombing attack, after which the threat actors contacted the victim via Microsoft Teams while impersonating "IT Support | Corporate IT Service (Internal)." Further investigation into theOffice 365The phishing site's landing page, shown in the figure below, is designed to resemble a legitimate Office 365 site, helping reassure the victim and reduce suspicion that anything unusual is taking place.PowerShellhowever there are alternative delivery strategies where some of these buttons copy a Batch script or PowerShell script to the victim's clipboard.Pythonextension named, "Edge Monitoring Agent", and uses a malicious Microsoft Edge extension paired with a Python-based native messaging host to move beyond the browser's sandbox, enabling real-time monitoring ofQuick Assistvictim. The threat actors then initiated a screen-sharing session and instructed the victim to launch Quick Assist. After obtaining hands-on access, they navigated to an Amazon S3-hosted phishing site and downloadedWindows Task SchedulerEdge browser extension and Python-based native messaging host, registers persistence via Windows Task Scheduler, launches Microsoft Edge with the sideloaded extension, and deletes itself from disk.
Tools
CyberChefand the Output, containing the deobfuscated script, after all obfuscated strings were decrypted using CyberChef. This was achieved by using a regex with the Register operation to capture the XOR constant, thenObfuscator.ioservice worker. The file in question was obfuscated through the free JavaScript obfuscation service Obfuscator.io. Deobfuscating it reveals that it establishes a persistent WebSocket connection to the C2 server,