Ref6598 — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
April 14, 2026
Last Seen
June 2, 2026

Ref6598 is a threat campaign tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 14, 2026; most recent activity June 2, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • PHANTOMPULSE RAT Uses Process Injection and UAC Bypass to Compromise Windows Systems — Cybersecuritynews · June 2, 2026
  • Phantom In The Vault — www.elastic.co · April 15, 2026
  • Hackers Weaponize Obsidian Shell Commands Plugin to Launch Cross — Cybersecuritynews · April 14, 2026

CVSS v3.1 Breakdown