Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2287 articles · 122338 vulns · 38/41 feeds (7d)
← Back to list
EST
PRE-CVEEXPLOITED

UNC6692 Social Engineering Campaign with Custom Malware Deployment

60% confidence

Description

A multistage intrusion campaign by UNC6692 leveraged social engineering via Microsoft Teams to deploy a custom modular malware suite, including a malicious Chromium browser extension (SNOWBELT). The attack involved impersonating IT helpdesk staff,诱导用户安装本地补丁, and establishing persistence through AutoHotKey scripts and scheduled tasks.

Related News (1 articles)

Tier C
Mandiant Blog4h ago
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedApr 23, 2026
Last enriched3h ago
Tags
social-engineeringphishingmalware-deploymentbrowser-extensionpersistence
Trending Score39
Source articles1
Independent1
Info Completeness5/14
Missing: cve_id, vendor, product, versions, cvss, epss, cwe, kev, patch

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 60%

Vulnerability Timeline

CVE Published
Apr 23, 2026
Actively Exploited
Apr 23, 2026
Exploit Available
Apr 23, 2026
Discovered by ZDM
Apr 23, 2026