UNC6692 Combines Social Engineering, Malware, Cloud Abuse
2026-04-27T20:51:42Z•2eab4f922863845709dd2e141f7b2834d9b59263c804d4dea129783fdc238023
2FA/device-code phishingAI phishingAWS S3Bomgar RMMCVE-2026-1731ClickFixLazarusMicrosoft TeamsNGINX MCP integrationOAuth token theftPhantomRPCRCESnow malwareUNC6692Vercel breachWhatsApp metadata leakWindows Defender exploitationWindows RPCagentic LLM threatscloud abusemacOSprivilege escalationransomwareserial-to-IP vulnerabilitiessupply chain risk
What happened
Multiple DarkReading stories report elevated active threats and widespread attack surface risks: a new UNC6692 campaign abuses Microsoft Teams, AWS S3 and custom “Snow” malware for cloud-enabled social engineering; multiple high-impact vulnerabilities and unpatched architectural flaws (including an unpatched Windows RPC/PhantomRPC privilege-escalation class and active RCEs) are being exploited; Bomgar RMM remote-code-execution (CVE-2026-1731) is under active exploitation; North Korean ClickFix/macOS campaigns, expanding ransomware groups, and growing AI-enabled phishing/agentic threats round‑d
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 2eab4f922863845709dd2e141f7b2834d9b59263c804d4dea129783fdc238023
- Enrichment time
- 2026-04-27T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.