UNC6692 Combines Social Engineering, Malware, Cloud Abuse

2026-04-27T20:51:42Z2eab4f922863845709dd2e141f7b2834d9b59263c804d4dea129783fdc238023
2FA/device-code phishingAI phishingAWS S3Bomgar RMMCVE-2026-1731ClickFixLazarusMicrosoft TeamsNGINX MCP integrationOAuth token theftPhantomRPCRCESnow malwareUNC6692Vercel breachWhatsApp metadata leakWindows Defender exploitationWindows RPCagentic LLM threatscloud abusemacOSprivilege escalationransomwareserial-to-IP vulnerabilitiessupply chain risk

What happened

Multiple DarkReading stories report elevated active threats and widespread attack surface risks: a new UNC6692 campaign abuses Microsoft Teams, AWS S3 and custom “Snow” malware for cloud-enabled social engineering; multiple high-impact vulnerabilities and unpatched architectural flaws (including an unpatched Windows RPC/PhantomRPC privilege-escalation class and active RCEs) are being exploited; Bomgar RMM remote-code-execution (CVE-2026-1731) is under active exploitation; North Korean ClickFix/macOS campaigns, expanding ransomware groups, and growing AI-enabled phishing/agentic threats round‑d

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
2eab4f922863845709dd2e141f7b2834d9b59263c804d4dea129783fdc238023
Enrichment time
2026-04-27T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · UNC6692 Combines Social Engineering, Malware, Cloud Abuse · Baitaphish