Ref6598 is a threat campaign tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 14, 2026; most recent activity June 2, 2026.
A sophisticated social engineering campaign has been uncovered, targeting individuals in the financial and cryptocurrency sectors through the Obsidian note-taking application. The attackers, posing as representatives of…
The PHANTOMPULSE remote access trojan (RAT) has emerged as a significant threat, leveraging UAC bypass and process injection techniques to compromise Windows systems. It is the final payload in a multi-stage attack…