UNC6692 Combines Social Engineering, Malware, Cloud Abuse

2026-04-28T14:51:44Zd2af6cbda333b7615cc5ee8f62bd058dd6d5253225eeba46a563206427e5aedc
AI-powered phishingAWS S3Antigravity RCE fixBomgarBotnetsCVE-2026-1731ClickFixCloud abuseGentlemen gangLazarusMicrosoft TeamsNIST CVE changesPhantomRPCPrivilege EscalationRansomwareSnow malwareStuxnetSupply chain riskUNC6692Windows Defender exploitsfast16macOS

What happened

This DarkReading digest highlights a wave of high-risk activity: a newly profiled UNC6692 campaign uses Microsoft Teams, abused AWS S3 buckets, and custom “Snow” malware in multi-stage cloud-centric social engineering attacks; an architectural, unpatched Windows RPC weakness dubbed “PhantomRPC” enables multiple privilege-escalation exploit paths; and active exploitation of a critical Bomgar RMM remote code execution flaw (CVE-2026-1731) demonstrates supply-chain risk. Other notable items include discovery of a 20-year-old fast16 malware framework predating Stuxnet, North Korean Lazarus ClickF­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
d2af6cbda333b7615cc5ee8f62bd058dd6d5253225eeba46a563206427e5aedc
Enrichment time
2026-04-28T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · UNC6692 Combines Social Engineering, Malware, Cloud Abuse · Baitaphish