Security Signals (07/14/26-07/28/26)

?

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

?

Events

Going to Black Hat in Las Vegas?

If you’re interested in threat intelligence, want to chat with fellow security practitioners, or simply put a face to a name, let’s grab a coffee. We’ve opened time on our calendars for meetings throughout the conference.

Looking forward to the conversations and seeing familiar faces as well as meeting new ones!

Our Latest Blog Post

June 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.

 

Top ATT&CK Techniques Observed

T1566 – Phishing: Credential theft remained one of the primary initial access vectors, with campaigns using device code phishing, adversary-in-the-middle (AiTM) techniques, fake recruiters, Google Ads lures, procurement scams, eCards, and other social engineering methods.

T1071 – Application Layer Protocol: Threat actors increasingly relied on legitimate services and protocols—including Outlook, DNS, browsers, blockchain infrastructure, Telegram, and cloud platforms—for command-and-control to blend malicious traffic with normal network activity.

T1583 / T1584 – Acquire & Compromise Infrastructure: Multiple investigations focused on attacker-controlled infrastructure, compromised government websites, malicious domains, cloud resources, and software repositories used to support phishing, malware delivery, and command-and-control.

T1195 – Supply Chain Compromise: Software supply chain attacks remained highly active, targeting npm packages, PyPI repositories, SDKs, browser extensions, AI tooling, IDE components, and other developer ecosystems.

T1105 / T1059 – Ingress Tool Transfer & Command Execution: Researchers observed widespread use of custom loaders, remote access trojans, malware frameworks, scripting engines, ClickFix techniques, and living-off-the-land methods to establish persistence and evade detection.


What Matters Most

Identity has become the preferred attack surface. Rather than exploiting vulnerabilities, many campaigns focused on stealing credentials through phishing, adversary-in-the-middle attacks, Microsoft 365 abuse, and social engineering.

ClickFix continues to gain momentum. Multiple unrelated threat actors—including financially motivated groups, DPRK operators, and nation-state campaigns—adopted ClickFix techniques, reinforcing its emergence as a mainstream initial access method.

Trusted infrastructure is increasingly abused. Government websites, SaaS platforms, Microsoft 365, GitHub, Telegram, cloud services, and blockchain infrastructure were repeatedly leveraged to host payloads, deliver malware, or conceal command-and-control traffic.

Threat research is shifting toward infrastructure analysis. Many reports focused less on individual malware samples and more on mapping attacker infrastructure, command-and-control architecture, operational ecosystems, and attribution.


What Defenders Should Watch

  • Device code phishing, AiTM campaigns, and Microsoft 365 authentication abuse
  • ClickFix-style execution chains involving PowerShell, MSBuild, script interpreters, or trusted Windows utilities
  • Newly observed domains, DNS tunneling, Outlook- or browser-based C2 channels, and rapidly changing infrastructure
  • Unauthorized package updates, developer dependencies, browser extensions, SDKs, and software repositories
  • Remote administration tools, custom loaders, and malware communicating through trusted cloud services

Quick Wins

  • Strengthen phishing-resistant authentication and monitor for suspicious OAuth, device code, and session activity
  • Expand detection coverage for ClickFix techniques and script-based execution from user-accessible directories
  • Monitor outbound DNS, Outlook, browser, and cloud-service traffic for unusual command-and-control behavior
  • Verify software dependencies, package updates, browser extensions, and developer tooling before deployment
  • Continuously enrich detections with current malicious domains, URLs, IPs, and C2 infrastructure to identify emerging campaigns earlier

Key Insight: This reporting period highlighted a continued shift away from traditional exploit-driven intrusions toward attacks that abuse trusted identities, legitimate services, and widely used platforms. At the same time, researchers placed greater emphasis on uncovering attacker infrastructure and command-and-control techniques, giving defenders more opportunities to detect campaigns through behavioral patterns rather than malware signatures alone.

Articles

Late July 2026 Cyber Threat Reports highlight the latest threat research published between July 14 and July 28, 2026. This edition covers ransomware operations, advanced phishing campaigns, supply chain compromises, malware and botnet analysis, APT activity, cloud and identity attacks, and technical investigations from leading security researchers, providing actionable intelligence for defenders and threat hunters.

Langflow Exploited to Build Custom DDoS Gafgyt Botnets

Source: Akamai
(Published: July 14, 2026)

This technical analysis examines Langflow Exploited to Build Custom DDoS Gafgyt Botnets, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.


Kratos PhaaS Targets US and EU Companies

Source: ANY.RUN
(Published: July 14, 2026)

Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. Read more.


LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software

Source: Blackpoint Cyber
(Published: July 14, 2026)

This technical analysis examines LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links

Source: Ctrl-Alt-Intel
(Published: July 14, 2026)

This report investigates Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Compromised AsyncAPI npm Packages

Source: Datadog Security Labs
(Published: July 14, 2026)

This research details Compromised AsyncAPI npm Packages, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


SeasonalInvite: New Phishing Campaign Abuses eCards and RMM

Source: Forescout
(Published: July 14, 2026)

This research analyzes SeasonalInvite: New Phishing Campaign Abuses eCards and RMM, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.


Signed, Sealed, Stolen: CrashStealer Slips Past Gatekeeper

Source: HivePro
(Published: July 14, 2026)

This technical analysis examines Signed, Sealed, Stolen: CrashStealer Slips Past Gatekeeper, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist

Source: Infostealers.com
(Published: July 14, 2026)

This technical analysis examines How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Miasma Worm Returns to npm

Source: JFrog
(Published: July 14, 2026)

This research details Miasma Worm Returns to npm, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


HTTP-Basma – Clustering Verbosus Fingerprints

Source: Netomize
(Published: July 14, 2026)

This research maps HTTP-Basma – Clustering Verbosus Fingerprints, highlighting infrastructure relationships, operational patterns, and detection opportunities. Read more.


Detailed Analysis of BIRDCALL Malware Masquerading as Zangi Messenger

Source: S2W
(Published: July 14, 2026)

This technical analysis examines Detailed Analysis of BIRDCALL Malware Masquerading as Zangi Messenger, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Injective SDK Compromised: Crypto Wallet Private Keys Stolen

Source: SlowMist
(Published: July 14, 2026)

This research details Injective SDK Compromised: Crypto Wallet Private Keys Stolen, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Tracking Donot APT-C-35 Bangladesh Military Intrusion

Source: Cyderes
(Published: July 15, 2026)

This report investigates Tracking Donot APT-C-35 Bangladesh Military Intrusion, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


DINDoOR, DenoRAT, and NightshadeC2: TAG-150’s Evolving Tradecraft

Source: eSentire
(Published: July 15, 2026)

This report investigates DINDoOR, DenoRAT, and NightshadeC2: TAG-150’s Evolving Tradecraft, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible for the April DigiCert Incident

Source: Expel
(Published: July 15, 2026)

This research details Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible for the April DigiCert Incident, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials

Source: Intel 471
(Published: July 15, 2026)

Intel 471 investigated an ongoing, multi-stage phishing operation that systematically abuses legitimate software-as-a-service sales and marketing platforms and cloud services to orchestrate corporate credential theft. Read more.


OkoBot Framework Targets Cryptocurrency Wallets

Source: Kaspersky Securelist
(Published: July 15, 2026)

This technical analysis examines OkoBot Framework Targets Cryptocurrency Wallets, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Unpacking the AsyncAPI npm Supply-Chain Compromise

Source: Microsoft
(Published: July 15, 2026)

This research details Unpacking the AsyncAPI npm Supply-Chain Compromise, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


MuddyWater: ClickFix to Telegram & PatchAgent Backdoor

Source: Ransom-ISAC
(Published: July 15, 2026)

This report investigates MuddyWater: ClickFix to Telegram & PatchAgent Backdoor, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Telegram Account Compromised, Wallet Swapped: macOS Malware Analysis

Source: SlowMist
(Published: July 15, 2026)

This research analyzes Telegram Account Compromised, Wallet Swapped: macOS Malware Analysis, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.


TuxBot v3: Evolution of an IoT Botnet

Source: Unit 42
(Published: July 15, 2026)

This technical analysis examines TuxBot v3: Evolution of an IoT Botnet, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.


20+ Government Websites Hijacked: PhantomEnigma Investigation

Source: ANY.RUN
(Published: July 16, 2026)

An original threat intelligence investigation uncovered how trusted government infrastructure became an attack channel, placing banking organizations and public-sector systems at risk. Read more.


UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant

Source: Cisco Talos
(Published: July 16, 2026)

This technical analysis examines UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


TELEPUZ Malware-as-a-Service Uses ClickFix

Source: Elastic Security Labs
(Published: July 16, 2026)

This technical analysis examines TELEPUZ Malware-as-a-Service Uses ClickFix, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

Source: Fortinet
(Published: July 16, 2026)

Since late March, 2026, we have been observing large-scale campaigns that use a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER. Read more.


ClickLock Stealer: macOS Malware

Source: Group-IB
(Published: July 16, 2026)

This technical analysis examines ClickLock Stealer: macOS Malware, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


GoSerpent Backdoor in Southeast Asia

Source: Kaspersky Securelist
(Published: July 16, 2026)

This report investigates GoSerpent Backdoor in Southeast Asia, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Hiding in Plain Ledger: Four Months of a ClickFix Operator’s Blockchain C2

Source: Melted in Hex
(Published: July 16, 2026)

To hide its command-and-control server, this operation writes the address onto a public blockchain. Read more.


ACR Stealer: Two Observed Intrusion Chains

Source: Microsoft
(Published: July 16, 2026)

This technical analysis examines ACR Stealer: Two Observed Intrusion Chains, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


StealC: A Commodity Stealer Loader

Source: Stairwell
(Published: July 16, 2026)

This technical analysis examines StealC: A Commodity Stealer Loader, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


GigaWiper: Inside a Modular Cyberweapon

Source: PolySwarm
(Published: July 17, 2026)

This technical analysis examines GigaWiper: Inside a Modular Cyberweapon, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era

Source: XLab
(Published: July 17, 2026)

This technical analysis examines NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.


Contagious Interview Malware Uses SVG Steganography

Source: Elastic Security Labs
(Published: July 18, 2026)

This report investigates Contagious Interview Malware Uses SVG Steganography, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


GitHub Poisoning Attack Disguised as Recruitment

Source: SlowMist
(Published: July 18, 2026)

This research details GitHub Poisoning Attack Disguised as Recruitment, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Hollowgraph: Microsoft 365 Espionage

Source: Group-IB
(Published: July 20, 2026)

This research examines Hollowgraph: Microsoft 365 Espionage, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.


CloudAtlasGo Backdoor

Source: Kaspersky Securelist
(Published: July 20, 2026)

This report investigates CloudAtlasGo Backdoor, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Fake Games Spread Stealers With Ren’Py Loader, MSBuild, and EtherHiding

Source: Malwarebytes
(Published: July 20, 2026)

This technical analysis examines Fake Games Spread Stealers With Ren’Py Loader, MSBuild, and EtherHiding, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


On-Chain Backdoor in a Malicious Trae Extension

Source: SlowMist
(Published: July 20, 2026)

This research details On-Chain Backdoor in a Malicious Trae Extension, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Kali365 Targets US Organizations With Device Code Phishing

Source: ANY.RUN
(Published: July 21, 2026)

Kali365 is targeting US organizations with device code phishing attacks that abuse legitimate Microsoft authentication. Read more.


Click to Sync: From Google Ads Maintenance Notice to Credential Theft

Source: Cofense
(Published: July 21, 2026)

This research analyzes Click to Sync: From Google Ads Maintenance Notice to Credential Theft, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.


The Procurement Trap: An AiTM Campaign Targeting Global Institutions

Source: Infoblox
(Published: July 21, 2026)

This research analyzes The Procurement Trap: An AiTM Campaign Targeting Global Institutions, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.


Project CAV3RN: Cyberespionage Framework Using Outlook and DNS

Source: Kaspersky Securelist
(Published: July 21, 2026)

This report investigates Project CAV3RN: Cyberespionage Framework Using Outlook and DNS, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


INC Ransomware Affiliate Targets ESXi & NAS Devices in AD Environment

Source: Ctrl-Alt-Intel
(Published: July 22, 2026)

This research examines INC Ransomware Affiliate Targets ESXi & NAS Devices in AD Environment, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.


Email Bombing, IT Impersonation, Quick Assist, and Edgecution: UNC6692

Source: eSentire
(Published: July 22, 2026)

This research examines Email Bombing, IT Impersonation, Quick Assist, and Edgecution: UNC6692, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.


Inside a TrickBot Variant Using DNS Tunneling for C2

Source: Fortinet
(Published: July 22, 2026)

FortiGuard Labs recently captured several malicious samples that were sending malformed DNS queries. Read more.


FakeAgent Claude Desktop Malvertising Ends in .NET RAT

Source: Huntress
(Published: July 22, 2026)

This technical analysis examines FakeAgent Claude Desktop Malvertising Ends in .NET RAT, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Cl0p Windchill/FlexPLM Exploitation

Source: Ransom-ISAC
(Published: July 22, 2026)

This research examines Cl0p Windchill/FlexPLM Exploitation, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.


Malicious Copilot MCP Apex npm Package Delivers macOS Infostealer

Source: SafeDep
(Published: July 22, 2026)

This research details Malicious Copilot MCP Apex npm Package Delivers macOS Infostealer, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Rondo Meets GeoServer

Source: SANS ISC
(Published: July 22, 2026)

This analysis examines Rondo Meets GeoServer, including observed exploitation activity, post-exploitation behavior, and relevant defensive guidance. Read more.


Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel

Source: Cisco Talos
(Published: July 23, 2026)

This research examines Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.


JadeProx: China-Nexus TRIBACK Loader

Source: Group-IB
(Published: July 23, 2026)

This report investigates JadeProx: China-Nexus TRIBACK Loader, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


TA488 Targets Zimbra Mail Servers With Half-Click Exploits

Source: Proofpoint
(Published: July 23, 2026)

This report investigates TA488 Targets Zimbra Mail Servers With Half-Click Exploits, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Russian Webmail Espionage

Source: Unit 42
(Published: July 23, 2026)

Unit 42 has observed a persistent cyberespionage campaign it tracks as CL-STA-1114. Read more.


The Gentlemen RaaS: Origins, OPSEC & OSINT

Source: Ctrl-Alt-Intel
(Published: July 24, 2026)

This research examines The Gentlemen RaaS: Origins, OPSEC & OSINT, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.


Inside a DPRK BlueNoroff ClickFix Kit

Source: JUMPSEC
(Published: July 24, 2026)

This report investigates Inside a DPRK BlueNoroff ClickFix Kit, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


MrMustard Malicious PyPI Package

Source: SafeDep
(Published: July 24, 2026)

This research details MrMustard Malicious PyPI Package, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Dysphoria Botnet Evolution and Technical Analysis

Source: XLab
(Published: July 25, 2026)

This technical analysis examines Dysphoria Botnet Evolution and Technical Analysis, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.


From Compliant Emails to Remote Control: A Web3 Investigation

Source: SlowMist
(Published: July 26, 2026)

This research examines From Compliant Emails to Remote Control: A Web3 Investigation, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.


The Zedxion Corporate Nexus

Source: DomainTools
(Published: July 27, 2026)

This research maps The Zedxion Corporate Nexus, highlighting infrastructure relationships, operational patterns, and detection opportunities. Read more.


The Telegram Malware Ecosystem

Source: Ransom-ISAC
(Published: July 27, 2026)

This technical analysis examines The Telegram Malware Ecosystem, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (6/16/26-6/30/26)

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

Events

Going to Black Hat in Las Vegas?

If you’re interested in threat intelligence, want to chat with fellow security practitioners, or simply put a face to a name, let’s grab a coffee. We’ve opened time on our calendars for meetings throughout the conference.

Looking forward to the conversations and seeing familiar faces as well as meeting new ones!

Our Latest Blog Post

May 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.

 

Top ATT&CK Techniques Observed

  • T1195 – Supply Chain Compromise: Software supply chain attacks remained one of the dominant themes, with compromises affecting npm packages, developer tools, IDE plugins, SDKs, and CI/CD workflows.
  • T1566 – Phishing: Attackers continued to rely on shopping scams, WhatsApp campaigns, fake domain renewals, Bubble.io phishing, and AI-themed lures to steal credentials.
  • T1555 / T1556 – Credential Access: Multiple campaigns targeted developer credentials, AI API keys, browser sessions, enterprise logins, and cloud identities.
  • T1071 – Application Layer Protocol: Modern malware increasingly used cloud services, collaboration platforms, blockchain infrastructure, and encrypted channels for command-and-control.
  • T1055 / T1059 – Defense Evasion & Execution: Attackers continued adopting reflective loading, DLL sideloading, steganography, PowerShell, and in-memory execution to reduce detection.

What Matters Most

  • Developer ecosystems remain under sustained attack. AI frameworks, npm packages, JetBrains plugins, SDKs, and developer tooling were repeatedly compromised during this reporting period.
  • Credential theft continues to drive intrusions. Whether targeting developers, cloud administrators, or end users, most campaigns ultimately sought credentials, tokens, or session access.
  • Supply chain attacks are expanding beyond package managers. Threat actors increasingly target plugins, extensions, SDKs, repositories, and software update mechanisms.
  • Nation-state operations remain highly active. Multiple reports covered activity linked to China- and DPRK-aligned actors, as well as campaigns targeting government, healthcare, and critical infrastructure.

What Defenders Should Watch

  • Unexpected package updates, dependency changes, IDE plugins, or CI/CD modifications
  • Credential theft targeting AI platforms, developer accounts, and enterprise cloud services
  • Execution from temporary folders, archive contents, DLL sideloading, and script interpreters
  • Outbound connections to newly observed infrastructure, cloud services, and fast-changing C2 endpoints

Quick Wins

  • Review package trust policies and require verification for new dependencies
  • Monitor AI platform credentials and API keys alongside traditional privileged accounts
  • Strengthen detection for phishing-resistant authentication and suspicious session activity
  • Audit developer workstations and CI/CD pipelines for unauthorized changes or plugins

Key Insight: This period marked another shift toward attacks on software development ecosystems. Rather than targeting only end users, threat actors increasingly compromised developer tools, package repositories, and AI-related workflows to gain access to organizations and their cloud environments.

Articles

Late June 2026 Cyber Threat Reports highlights a continued rise in attacks targeting software supply chains, AI development tools, enterprise credentials, and cloud environments. This edition features research on Mastra, FortiBleed, The Gentlemen, TONResolver, AryStinger, Mustang Panda, and dozens of phishing, ransomware, and malware campaigns published between June 16 and June 30, 2026.

May 2026 Infostealer Trend Report

Source: AhnLab ASEC
(Published: 17 June 2026)
This report summarizes the distribution channels, number of infostealers, number of detections, target companies, and execution types of new infostealers collected during the month of May 2026. Read more.


More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers

Source: Qianxin XLab
(Published: 17 June 2026)
On May 20, 2026, the Ministry of State Security’s WeChat official account published an article “Your internet is slow, and the culprit turns out to be this!”, highlighting that outdated routers are becoming a key entry point for threat actors to conduct cyber espionage. Read more.


AdaptixC2: Fingerprinting an Open-Source C2 Framework at Scale

Source: Censys
(Published: 17 June 2026)
AdaptixC2 is an open-source post-exploitation framework with a default configuration that makes deployed servers trivially identifiable from passive scanning. Read more.


Klue Integration Abused in Salesforce Data Theft

Source: ReliaQuest
(Published: 17 June 2026)
In June 2026, ReliaQuest observed a compromised integration for Klue, a competitive-intelligence platform that syncs battlecard and win/loss data with Salesforce, being used to exfiltrate customer relationship management (CRM) data. Read more.


Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat

Source: StepSecurity
(Published: 17 June 2026)
On June 17, 2026, an attacker compromised the @mastra npm organization and quietly added easy-day-js as a dependency across 140+ packages in the Mastra AI framework ecosystem. Read more.


Mastra Supply Chain Compromise: easy-day-js Dropper Pulls a Cross-Platform RAT Into @mastra Installs

Source: Upwind
(Published: 17 June 2026)
On June 17 2026, a coordinated supply chain attack pushed a malicious easy-day-js package into the dependency tree of the entire @mastra/* npm organization. Read more.


PureRAT Variant Observed in AI Video Player

Source: Luke Acha
(Published: 17 June 2026)
Follow-up analysis of extracted .NET loader stage, internally named Ykzrh.exe (smveo-csharp-agent.exe) in one recovered artifact, revealed a substantial virtualization and runtime reconstruction layer. Read more.


Prinz Eugen Ransomware: A Deep Dive Into a New Go-Based Encryptor

Source: ThreatDown
(Published: 17 June 2026)
On May 11, 2026, our research team investigated a customer infected with a brand-new ransomware family called Prinz Eugen. Read more.


Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystem

Source: Cyble
(Published: 18 June 2026)
The FIFA World Cup 2026 has become more than a global sporting event. Read more.


Mastra Attack Targets Crypto, Password Managers, Authenticators, and Zapier

Source: OpenSourceMalware
(Published: 18 June 2026)
A threat actor compromised the Mastro NPM organization yesterday and published more than 140 malicious packages. Read more.


15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers

Source: StepSecurity
(Published: 18 June 2026)
On June 16, 2026, JetBrains received security reports identifying a coordinated supply chain attack involving 15 malicious third-party plugins on the JetBrains Marketplace. Read more.


Killing Me Gently: Inside Gentlemen’s EDR Killer Framework

Source: ESET Research
(Published: 18 June 2026)
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen. Read more.


SmartApeSG Launches Okendo Reviews Supply Chain Attack

Source: Zscaler
(Published: 18 June 2026)
On May 14, 2026, the Zscaler ThreatLabz team identified unusually high activity associated with the threat actor SmartApeSG to deploy malware. Read more.


Amazon Prime Day 2026: Bargains Begin June 23 – and So Do the Scams

Source: Check Point Research
(Published: 19 June 2026)
When Amazon Prime Day returns on June 23-26, 2026, more than 25 countries will take part in one of the largest shopping windows of the year. Read more.


OXLOADER: New Loader Evading Detection to Drop Infostealer

Source: Elastic Security Labs
(Published: 19 June 2026)
After all the checks have passed, the malware makes a copy of the Windows DirectUI Engine DLL (C:\Windows\System32\dui70.dll), storing it in a temporary location using a randomly generated name with the .ocx extension. Read more.


Threat Actors Weaponizing RAR Archives to Target Thailand’s Healthcare Sector

Source: Seqrite
(Published: 19 June 2026)
Authors: Vaibhav Krushna Billade, Dixit Panchal & Rumana Siddiqui. Read more.


MyBait: Why We Lured Attackers To Encrypt Our Cloud MySQL

Source: Varonis
(Published: 19 June 2026)
Varonis Threat Labs deployed MySQL honeypots across GCP, AWS, and Azure. Read more.


@withgoogle/stitch-sdk: Scope Squat Harvests Developer Credentials

Source: SafeDep
(Published: 19 June 2026)
A malicious npm package published under @withgoogle/stitch-sdk impersonates Google’s Stitch AI design tool by squatting the @withgoogle npm scope. Read more.


FortiBleed: Anatomy of the FortiBleed Campaign Based on the Server That the Attackers Themselves Left Exposed

Source: ZenoX
(Published: 20 June 2026)
In June 19 2026 we received access to the contents of an internet-exposed directory, left open by the operators themselves of a campaign the press named FortiBleed. Read more.


A Multi-Stage Steganographic Loader Campaign Deploying Diverse Payloads Globally

Source: K7 Labs
(Published: 20 June 2026)
The final payload achieves its persistence through the Run entry, winlogon.exe, & userinit. Read more.


From PostCSS Masquerading to Windows RAT

Source: JFrog Security Research
(Published: 20 June 2026)
The downloaded bundle was not a simple script. Read more.


A VBScript Campaign Distributed Through WhatsApp Deploying RMM Software

Source: Kaspersky Securelist
(Published: 22 June 2026)
In June 2026, we observed a malware campaign distributing malicious VBScript files through direct messages in WhatsApp. Read more.


USB Worm CryptoBandits Steals Cryptocurrency via Windows Shortcut Files

Source: ThreatAft
(Published: 22 June 2026)
A financially motivated USB worm campaign has been actively stealing cryptocurrency from Windows users worldwide since at least February 2026. Read more.


What Was a 45-GPU Cracking Farm Built For?

Source: ThreatMon
(Published: 22 June 2026)
Most credential leaks are messy. Someone dumps a pile of raw data, half of it stale, and walks away. Read more.


EvilTokens: How “Ghost” Code Threatens US and European Businesses

Source: ANY.RUN
(Published: 23 June 2026)
EvilTokens can hide serious account takeover risk from your SOC through “ghost” code that appears only after browser-side decryption. Read more.


Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory

Source: Arctic Wolf
(Published: 23 June 2026)
Arctic Wolf reverse-engineered a recovered CyberStrike Harvester binary and connected it to the broader FortiBleed operator workflow, showing how exposed perimeter credentials can quickly become full internal-network exposure. Read more.


CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised

Source: Imperva
(Published: 24 June 2026)
The campaign, first documented here, has been running for several months, as evidenced by the large volume of stolen data. Read more.


A Burst Bubble: How Threat Actors Are Using Bubble.io to Deliver a New Phishing Campaign

Source: S-RM
(Published: 24 June 2026)
The login follows the expected Microsoft login flow, but it is using the dynamic pages copied from Microsoft’s flow but on the threat actors content delivery network. Read more.


Edgecution: Malicious Edge Extension Backdoor

Source: Zscaler
(Published: 24 June 2026)
Edgecution is a malicious Microsoft Edge extension backdoor associated with ransomware initial access activity. Read more.


May 2026 Threat Trend Report on APT Attacks (South Korea)

Source: AhnLab ASEC
(Published: 24 June 2026)
This report provides a statistical summary and analysis of APT attacks targeting South Korea in May 2026. Read more.


Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI

Source: Checkmarx
(Published: 25 June 2026)
When the attacker sends “/asu print(os.environ)” to the victim’s bot, this function compiles and executes that Python code on the victim’s machine. Read more.


Threat Intelligence Report: Nation-State Targeting of Water Systems 2024-2026

Source: DomainTools
(Published: 25 June 2026)
DomainTools assesses nation-state targeting of water systems from 2024 through 2026, including activity linked to Iran, Russia, and China. Read more.


Coinbase Cartel: Behind the Noise of a Prolific Leak Operation

Source: Intrinsec
(Published: 25 June 2026)
Coinbase Cartel is a prolific leak operation built around high-volume extortion activity and public data exposure claims. Read more.


Fake Domain Renewal Emails Trick Website Owners Into Paying Scammers

Source: Malwarebytes
(Published: 25 June 2026)
Scammers are sending fake domain renewal notices to trick website owners into paying fraudulent invoices. Read more.


Negative SEO Attack: Inside a Black Hat SEO Operation

Source: Zynap
(Published: 25 June 2026)
Negative SEO is a form of search engine manipulation aimed not at boosting the attacker’s own site, but at damaging the ranking, reputation, or visibility of a target domain. Read more.


Operation Turb00 – Part 2: A Multi-Stage HijackLoader Campaign Delivers Vidar v2.1

Source: Medium
(Published: 26 June 2026)
This is the second post in a three-part series on the Vidar infostealer and the infrastructure behind it. Read more.


From CI/CD to Cloud Data: How Shai-Hulud Persistence Leads to Redshift Breach

Source: Fortinet
(Published: 26 June 2026)
The “Shai-Hulud: The Second Coming” campaign represents a major evolution in the landscape of npm supply-chain attacks. Read more.


Beyond Banking Trojans: Rokarolla Expands the Android Fraud Playbook

Source: PolySwarm
(Published: 26 June 2026)
Rokarolla represents a new generation of Android fraud tooling that extends beyond traditional banking trojan behavior. Read more.


Gaslight: The Rust-Powered macOS Implant Designed to Mislead AI Tools

Source: HivePro
(Published: 26 June 2026)
Gaslight (macOS.Gaslight) is a Rust-based macOS implant and information stealer attributed with high confidence to DPRK-aligned activity, first seen on May 22, 2026 and targeting macOS systems worldwide. Read more.


Investigating a Novel OpenAI Poisoned Tenant Attack

Source: Push Security
(Published: 26 June 2026)
Push Security investigated a poisoned tenant attack that abused OpenAI-related workflows to target identity and application access. Read more.


Understanding Langflow CVE-2026-55255, and Why Higher CVSS Vulnerabilities Aren’t Always the Most Exploited

Source: Sysdig
(Published: 26 June 2026)
Sysdig analyzes Langflow CVE-2026-55255 and explains why vulnerabilities with lower scores may see heavier attacker adoption than higher-severity flaws. Read more.


Anatomy of a WHQL-Signed Windows Filtering Platform Kernel-Resident Network Backdoor

Source: Nextron Systems
(Published: 26 June 2026)
Nextron Systems analyzes a WHQL-signed Windows Filtering Platform kernel-resident network backdoor. Read more.


Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment

Source: Seqrite
(Published: 26 June 2026)
Seqrite Lab actively tracks and analyse threat actors and their campaigns, focusing on attribution, infrastructure analysis, and adversary tradecraft. Read more.


Mustang Panda Targets India’s Government and Energy Sectors with ZOHOMURK and MINIRECON

Source: Acronis
(Published: 28 June 2026)
Our investigation began after identifying a suspicious archive, Hydropower Cooperation Project Proposal.zip, believed to have been distributed via spear-phishing and subsequently uploaded to VirusTotal in May 2026. Read more.


SystemBC Malware: How the Coroxy Proxy Backdoor Targets Windows

Source: Picus Security
(Published: 29 June 2026)
SystemBC, also tracked as Coroxy, is a Windows malware family that primarily turns an infected machine into a SOCKS5 proxy while also functioning as a persistent backdoor and RAT. Read more.


TONResolver RAT Abuses TON Blockchain to Target Japan’s Hotel Industry

Source: Trend Micro
(Published: 29 June 2026)
In this blog entry, TrendAIâ„¢ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. Read more.


The Gentlemen Are Knocking: Custom Backdoors and Evolving Tactics

Source: Kaspersky Securelist
(Published: 29 June 2026)
This year saw the emergence of The Gentlemen, a prominent example of a group operating under the ransomware-as-a-service model. Read more.


RustDuck: An In-Depth Analysis of a Two-Stage Botnet

Source: Qianxin XLab
(Published: 29 June 2026)
Although the family’s current activity level and influence in DDoS attacks are not yet comparable to some mainstream botnets, its speed of technological evolution deserves significant attention. Read more.


UAC-0184 Tooling Evolution: OneDrive Sideload to Remcos

Source: Synaptic Systems
(Published: 29 June 2026)
Launching shortcuts directly from an archive can behave differently depending on the archive utility and extraction context. Read more.


Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery

Source: Synaptic Systems
(Published: 29 June 2026)
The visible text comments on the structure of a manuscript, including sections covering diversion of civilian resources to military spending, degradation of agricultural production, and inequality in food distribution. Read more.


From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks

Source: Arctic Wolf
(Published: 30 June 2026)
Arctic Wolf Labs observed Anubis ransomware attacks using CitrixBleed 2 exploitation and Cloudflared tunneling as part of the intrusion chain. Read more.


Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App

Source: Cyble
(Published: 30 June 2026)
Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as Glitch SPY, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK. Read more.


Not Very Gentlemanly: Analyzing a Zero-Day Exploit Used by The Gentlemen Ransomware to Disable Targets’ EDRs

Source: Expel
(Published: 30 June 2026)
Ransomware groups have long relied on disabling endpoint detection and response tools before deploying their payloads, and in recent years have utilized bring-your-own-vulnerable-driver attacks to do so. Read more.


The Polymarket Trap: A Fake Arbitrage Bot, Ten npm Accounts, and Four Ways to Deliver an Infostealer

Source: SafeDep
(Published: 30 June 2026)
A set of small npm packages, GitHub repositories, and matching themes were used to lure developers into installing infostealer code disguised as Polymarket arbitrage tooling. Read more.


ToddyCat: Your Hidden Email Assistant. Part 2

Source: Kaspersky Securelist
(Published: 30 June 2026)
We continue to share details on the malicious techniques and toolsets used by the ToddyCat APT group. Read more.


No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack

Source: Huntress
(Published: 30 June 2026)
The targeting of these attacks seems to be based entirely on password prevalence on compromised password combo lists, and is not specific to business type or industry. Read more.


Silent Swap: A Crypto Clipper Extension Campaign

Source: McAfee
(Published: 30 June 2026)
McAfee Labs analyzed a browser extension campaign designed to swap cryptocurrency wallet addresses and redirect payments to attacker-controlled wallets. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (6/2/26 – 6/16/26)

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

Our Latest Blog Post

May 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

These insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the threat research featured below.

Top ATT&CK Techniques Observed

  • T1195 – Supply Chain Compromise (9/9): npm, PyPI, Rust crates, GitHub repositories, and AI coding agent workflows were repeatedly targeted.
  • T1566 – Phishing / Social Engineering (9/9): Device-code phishing, AiTM kits, fake AI tools, job lures, smishing, and copyright notices were common.
  • T1555 – Credential Access (8/9): Infostealers, token theft, session hijacking, and Microsoft 365 credential capture appeared across multiple campaigns.
  • T1190 – Exploit Public-Facing Applications (8/9): Oracle PeopleSoft, Check Point VPN, WinRAR, PAN-OS, and SOHO/IoT exploitation remained active.
  • T1071 – Application Layer C2 (7/9): Google Sheets, Microsoft Graph, Discord, cloud services, and fast-flux DNS were used for C2 or concealment.

What Matters Most

  • Developer ecosystems remain a major access path. Attackers are abusing package managers, repositories, AI coding tools, and CI/CD-adjacent workflows.
  • Identity attacks are highly active. Microsoft 365 phishing, device-code abuse, OAuth theft, and session capture remain central to many campaigns.
  • AI is now part of both lure design and attacker operations. Fake AI brands, jailbreak techniques, and agent-driven activity appeared repeatedly.
  • Nation-state activity is broadening. China-linked, Russia-linked, DPRK-linked, OceanLotus, Gamaredon, and Mustang Panda activity all appeared this period.

What Defenders Should Watch

  • Unexpected package updates, GitHub activity, CI/CD changes, or developer tool execution
  • OAuth/device-code abuse, suspicious MFA flows, and unusual Microsoft 365 session activity
  • Execution from fake AI tools, browser extensions, installers, and user-controlled directories
  • Outbound traffic to cloud-hosted, fast-flux, collaboration, or newly observed infrastructure

Quick Wins

  • Review package manager, repository, and CI/CD permissions
  • Restrict OAuth app consent and monitor device-code authentication
  • Alert on execution from downloads, temp folders, and unexpected script interpreters
  • Block newly registered domains tied to fake software, phishing kits, and impersonation lures

Key Insight: Attackers are combining developer ecosystem abuse, identity phishing, and public-facing exploitation to scale access, with credential theft and persistent control as the main objectives.

Articles

Mid June 2026 Cyber Threat Reports highlights developer ecosystem compromise, identity phishing, public-facing exploitation, and nation-state activity. This edition covers Shai-Hulud, Kali365, Check Point VPN exploitation, WinRAR attacks, OceanLotus, Gamaredon, Mustang Panda, and AI-themed phishing campaigns.

Dont Fear Repo UNKDEADDROP Phishing Campaign Targets Developers Steal

Source: Proofpoint
(Published: 2 June 2026)
Proofpoint analyzes a phishing or social engineering campaign involving Dont Fear Repo UNKDEADDROP Phishing Campaign Targets Developers Steal. Read more.


Etr Active Exploitation of Oracle PeopleSoft Zero Day CVE 2026 35273

Source: Rapid7
(Published: 2 June 2026)
Rapid7 analyzes exploitation activity and defensive implications related to Etr Active Exploitation of Oracle PeopleSoft Zero Day CVE 2026 35273. Read more.


Etr Critical Check Point VPN Zero Day Exploited in the Wild CVE 2026 50751

Source: Rapid7
(Published: 2 June 2026)
Rapid7 analyzes exploitation activity and defensive implications related to Etr Critical Check Point VPN Zero Day Exploited in the Wild CVE 2026 50751. Read more.


TA4922 Suspected Chinese Crime Group Going Global

Source: Proofpoint
(Published: 2 June 2026)
Proofpoint analyzes recent threat activity and defensive considerations related to TA4922 Suspected Chinese Crime Group Going Global. Read more.


Device Code Phishing Campaign

Source: ReversingLabs
(Published: 3 June 2026)
ReversingLabs analyzes a phishing or social engineering campaign involving Device Code Phishing Campaign. Read more.


Sheetcreep Evolved Google Sheets RAT

Source: Securonix
(Published: 3 June 2026)
Securonix analyzes malware activity, delivery tradecraft, and victim impact related to Sheetcreep Evolved Google Sheets RAT. Read more.


Silent Ransom Group Srg Uncovering DNS Fast-Flux Infrastructure

Source: Resecurity
(Published: 3 June 2026)
Resecurity analyzes ransomware or extortion activity tied to Silent Ransom Group Srg Uncovering DNS Fast-Flux Infrastructure. Read more.


Social Media Attacks Phishing

Source: ReversingLabs
(Published: 3 June 2026)
ReversingLabs analyzes a phishing or social engineering campaign involving Social Media Attacks Phishing. Read more.


Stock Exchange Espionage

Source: Security.com
(Published: 3 June 2026)
Security.com analyzes recent threat activity and defensive considerations related to Stock Exchange Espionage. Read more.


Threat Spotlight Reliaquests Agentic AI Uncovers New China Linked Cluster OP-512

Source: ReliaQuest
(Published: 3 June 2026)
ReliaQuest analyzes state-linked threat activity and targeting patterns related to Threat Spotlight Reliaquests Agentic AI Uncovers New China Linked Cluster OP-512. Read more.


Binding Gyp NPM Supply Chain Attack Spreads Like Worm

Source: StepSecurity
(Published: 4 June 2026)
StepSecurity analyzes a supply chain or developer ecosystem compromise involving Binding Gyp NPM Supply Chain Attack Spreads Like Worm. Read more.


Miasma Worm Hits Microsoft Again Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents

Source: StepSecurity
(Published: 4 June 2026)
StepSecurity analyzes a supply chain or developer ecosystem compromise involving Miasma Worm Hits Microsoft Again Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents. Read more.


Old WINRAR Flaw Fuels Attacks on Ukraine

Source: Trend Micro
(Published: 4 June 2026)
Trend Micro analyzes attacker abuse of AI-themed lures, tools, or workflows related to Old WINRAR Flaw Fuels Attacks on Ukraine. Read more.


Pythagora Io Gpt Pilot Compromised on GitHub Shai-Hulud Credential Stealer Blocked by Python Linter

Source: StepSecurity
(Published: 4 June 2026)
StepSecurity analyzes a supply chain or developer ecosystem compromise involving Pythagora Io Gpt Pilot Compromised on GitHub Shai-Hulud Credential Stealer Blocked by Python Linter. Read more.


Tracking Havoc Malware Activity and Evasion Techniques

Source: SonicWall
(Published: 4 June 2026)
SonicWall analyzes malware activity, delivery tradecraft, and victim impact related to Tracking Havoc Malware Activity and Evasion Techniques. Read more.


VerdantBamboo Just Another Brickstorm in the Firewall

Source: Volexity
(Published: 4 June 2026)
Volexity analyzes recent threat activity and defensive considerations related to VerdantBamboo Just Another Brickstorm in the Firewall. Read more.


You Do Surprise Me Exe an Unexpected Executable in Hola Browser

Source: Sophos
(Published: 4 June 2026)
Sophos analyzes recent threat activity and defensive considerations related to You Do Surprise Me Exe an Unexpected Executable in Hola Browser. Read more.


Ghost Stadium

Source: Validin
(Published: 5 June 2026)
Validin analyzes recent threat activity and defensive considerations related to Ghost Stadium. Read more.


Inside Cross Platform Propagation of New GAFGYT Variant C0XMO

Source: Fortinet
(Published: 5 June 2026)
Fortinet analyzes recent threat activity and defensive considerations related to Inside Cross Platform Propagation of New GAFGYT Variant C0XMO. Read more.


Oceanlotus External Espionage Domestic Targeting

Source: ESET Research
(Published: 5 June 2026)
ESET Research analyzes state-linked threat activity and targeting patterns related to Oceanlotus External Espionage Domestic Targeting. Read more.


Shai-Hulud Campaign Evolution Miasma Hades and AI Scanner Evasion

Source: Zscaler
(Published: 5 June 2026)
Zscaler analyzes attacker abuse of AI-themed lures, tools, or workflows related to Shai-Hulud Campaign Evolution Miasma Hades and AI Scanner Evasion. Read more.


Technical Analysis MLTBackdoor

Source: Zscaler
(Published: 5 June 2026)
Zscaler analyzes malware activity, delivery tradecraft, and victim impact related to Technical Analysis MLTBackdoor. Read more.


Fluffy Wolf Tests New Toolkit on Russian Companies 90f0785becdb

Source: Medium
(Published: 6 June 2026)
Medium analyzes recent threat activity and defensive considerations related to Fluffy Wolf Tests New Toolkit on Russian Companies 90f0785becdb. Read more.


Kali365 Expands Into AWS Microsoft Okta Xerox Max Messenger

Source: Arctic Wolf
(Published: 6 June 2026)
Arctic Wolf analyzes recent threat activity and defensive considerations related to Kali365 Expands Into AWS Microsoft Okta Xerox Max Messenger. Read more.


Monoglyphrat Attacks US Enterprise

Source: ANY.RUN
(Published: 6 June 2026)
ANY.RUN analyzes malware activity, delivery tradecraft, and victim impact related to Monoglyphrat Attacks US Enterprise. Read more.


Shai-Hulud Copycat Campaign Targets Python Developers

Source: GitLab
(Published: 6 June 2026)
GitLab analyzes attacker abuse of AI-themed lures, tools, or workflows related to Shai-Hulud Copycat Campaign Targets Python Developers. Read more.


Threat Actors Weaponize AI Hype to Deliver ASYNCRAT

Source: Fortinet
(Published: 6 June 2026)
Fortinet analyzes malware activity, delivery tradecraft, and victim impact related to Threat Actors Weaponize AI Hype to Deliver ASYNCRAT. Read more.


Browser Addons Spy on AI Chats

Source: G DATA
(Published: 7 June 2026)
G DATA analyzes attacker abuse of AI-themed lures, tools, or workflows related to Browser Addons Spy on AI Chats. Read more.


Stolen Futures the Long Term Criminal Value of Pediatric Healthcare Data

Source: PolySwarm
(Published: 7 June 2026)
PolySwarm analyzes recent threat activity and defensive considerations related to Stolen Futures the Long Term Criminal Value of Pediatric Healthcare Data. Read more.


Underthehood Believe Me I Am Mustang Panda

Source: ExaTrack
(Published: 7 June 2026)
ExaTrack analyzes state-linked threat activity and targeting patterns related to Underthehood Believe Me I Am Mustang Panda. Read more.


XWORM Sc Hok May 2026

Source: Deception Pro
(Published: 7 June 2026)
Deception Pro analyzes recent threat activity and defensive considerations related to XWORM Sc Hok May 2026. Read more.


from Minecraft Mods to Malware as a Service Inside the Weedhack Ecosystem

Source: PolySwarm
(Published: 7 June 2026)
PolySwarm analyzes malware activity, delivery tradecraft, and victim impact related to from Minecraft Mods to Malware as a Service Inside the Weedhack Ecosystem. Read more.


the Evolving Threat Landscape for Legal Services in 2026

Source: PolySwarm
(Published: 7 June 2026)
PolySwarm analyzes recent threat activity and defensive considerations related to the Evolving Threat Landscape for Legal Services in 2026. Read more.


AI Brands as Bait How Threat Actors Are Using the AI Hype in Social Engineering

Source: Microsoft Security
(Published: 8 June 2026)
Microsoft Security analyzes attacker abuse of AI-themed lures, tools, or workflows related to AI Brands as Bait How Threat Actors Are Using the AI Hype in Social Engineering. Read more.


Following a Usps Smishing Kit Through Censys DNS Data

Source: Censys
(Published: 8 June 2026)
Censys analyzes a phishing or social engineering campaign involving Following a Usps Smishing Kit Through Censys DNS Data. Read more.


Fsbs Matryoshka 2 3 Gamaredon’s Gifts That Keeps Unpacking GammaLoad

Source: Sekoia
(Published: 8 June 2026)
Sekoia analyzes state-linked threat activity and targeting patterns related to Fsbs Matryoshka 2 3 Gamaredon’s Gifts That Keeps Unpacking GammaLoad. Read more.


Fsbs Matryoshka 3 3 Gamaredon’s Gifts That Keeps Unpacking GammaSteel

Source: Sekoia
(Published: 8 June 2026)
Sekoia analyzes state-linked threat activity and targeting patterns related to Fsbs Matryoshka 3 3 Gamaredon’s Gifts That Keeps Unpacking GammaSteel. Read more.


Spam PDFS on Official EU Infrastructure Trusted Domain Dirty Search Results

Source: Synaptic Systems
(Published: 8 June 2026)
Synaptic Systems analyzes attacker abuse of AI-themed lures, tools, or workflows related to Spam PDFS on Official EU Infrastructure Trusted Domain Dirty Search Results. Read more.


a Tale of Two Eras

Source: Cisco Talos
(Published: 8 June 2026)
Cisco Talos analyzes recent threat activity and defensive considerations related to a Tale of Two Eras. Read more.


AI Brands Fuel Phishing

Source: CyberPress
(Published: 9 June 2026)
CyberPress analyzes a phishing or social engineering campaign involving AI Brands Fuel Phishing. Read more.


Prc Targets US Medical Research

Source: Google Cloud
(Published: 9 June 2026)
Google Cloud analyzes state-linked threat activity and targeting patterns related to Prc Targets US Medical Research. Read more.


Shinyhunters Targets Education Sector Oracle Exploit

Source: Google Cloud
(Published: 9 June 2026)
Google Cloud analyzes exploitation activity and defensive implications related to Shinyhunters Targets Education Sector Oracle Exploit. Read more.


Targeted Campaign US Law Firms

Source: Google Cloud
(Published: 9 June 2026)
Google Cloud analyzes attacker abuse of AI-themed lures, tools, or workflows related to Targeted Campaign US Law Firms. Read more.


UNC1151 Gmail Campaign

Source: CERT Polska
(Published: 9 June 2026)
CERT Polska analyzes attacker abuse of AI-themed lures, tools, or workflows related to UNC1151 Gmail Campaign. Read more.


from Fake Amazon Security Alert to Harborwatch Agent Clickfix Delivery of a Custom Monitoring RAT

Source: Cofense
(Published: 9 June 2026)
Cofense analyzes malware activity, delivery tradecraft, and victim impact related to from Fake Amazon Security Alert to Harborwatch Agent Clickfix Delivery of a Custom Monitoring RAT. Read more.


Agentic Threat Actor Hits the Orchestration Plane AI Agent Driven Container Escape

Source: Sysdig
(Published: 10 June 2026)
Sysdig analyzes malware activity, delivery tradecraft, and victim impact related to Agentic Threat Actor Hits the Orchestration Plane AI Agent Driven Container Escape. Read more.


Azureveil Spearphishing Delivers C2

Source: CyberPress
(Published: 10 June 2026)
CyberPress analyzes a phishing or social engineering campaign involving Azureveil Spearphishing Delivers C2. Read more.


Dark Web Profile Tengu Ransomware Shisa

Source: SOCRadar
(Published: 10 June 2026)
SOCRadar analyzes ransomware or extortion activity tied to Dark Web Profile Tengu Ransomware Shisa. Read more.


How Attackers Are Jailbreaking LLMs with Ctf Framing and How to Catch Them

Source: Sysdig
(Published: 10 June 2026)
Sysdig analyzes attacker abuse of AI-themed lures, tools, or workflows related to How Attackers Are Jailbreaking LLMs with Ctf Framing and How to Catch Them. Read more.


Kali365 Anatomy of a Microsoft 365 Phishing as a Service Kit

Source: SpyCloud
(Published: 10 June 2026)
SpyCloud analyzes a phishing or social engineering campaign involving Kali365 Anatomy of a Microsoft 365 Phishing as a Service Kit. Read more.


Pink Data Extortion Group Phishing Kits

Source: SOCRadar
(Published: 10 June 2026)
SOCRadar analyzes a phishing or social engineering campaign involving Pink Data Extortion Group Phishing Kits. Read more.


Behind Khmer Shadow Targeted Espionage Against Cambodian Government Entities

Source: Acronis
(Published: 11 June 2026)
Acronis analyzes attacker abuse of AI-themed lures, tools, or workflows related to Behind Khmer Shadow Targeted Espionage Against Cambodian Government Entities. Read more.


Cato Ctrl Previously Undocumented Ninjaone RMM Abuse Chain

Source: Cato Networks
(Published: 11 June 2026)
Cato Networks analyzes attacker abuse of AI-themed lures, tools, or workflows related to Cato Ctrl Previously Undocumented Ninjaone RMM Abuse Chain. Read more.


Check Point VPN CVE 2026 50751 Qilin Ransomware

Source: Trojan-Killer
(Published: 11 June 2026)
Trojan-Killer analyzes ransomware or extortion activity tied to Check Point VPN CVE 2026 50751 Qilin Ransomware. Read more.


Compromised Rust Crate Onering Performs Code Exfiltration

Source: Aikido
(Published: 11 June 2026)
Aikido analyzes a supply chain or developer ecosystem compromise involving Compromised Rust Crate Onering Performs Code Exfiltration. Read more.


FlutterBridge New FlutterShell Backdoor

Source: Unit 42 (Palo Alto Networks)
(Published: 11 June 2026)
Unit 42 (Palo Alto Networks) analyzes malware activity, delivery tradecraft, and victim impact related to FlutterBridge New FlutterShell Backdoor. Read more.


Optinmonster Trustpulse Pushengage Backdoor

Source: Trojan-Killer
(Published: 11 June 2026)
Trojan-Killer analyzes malware activity, delivery tradecraft, and victim impact related to Optinmonster Trustpulse Pushengage Backdoor. Read more.


Cpuid Hwmonitor Xvpn DLL Sideloading Stx RAT

Source: Cyderes
(Published: 12 June 2026)
Cyderes analyzes exploitation activity and defensive implications related to Cpuid Hwmonitor Xvpn DLL Sideloading Stx RAT. Read more.


Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency

Source: Cryptika
(Published: 12 June 2026)
Cryptika analyzes recent threat activity and defensive considerations related to Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency. Read more.


Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees

Source: Cryptika
(Published: 12 June 2026)
Cryptika analyzes attacker abuse of AI-themed lures, tools, or workflows related to Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees. Read more.


Hackers Use OnyxC2 Malware as a Service to Steal Credentials from 210 Applications

Source: Cryptika
(Published: 12 June 2026)
Cryptika analyzes malware activity, delivery tradecraft, and victim impact related to Hackers Use OnyxC2 Malware as a Service to Steal Credentials from 210 Applications. Read more.


WINRAR Vulnerability Exploited by Russian Hackers to Deploy GiftedCrook Stealer

Source: Cryptika
(Published: 12 June 2026)
Cryptika analyzes exploitation activity and defensive implications related to WINRAR Vulnerability Exploited by Russian Hackers to Deploy GiftedCrook Stealer. Read more.


the Job Hunt Trap Unmasking the Puma Careers Phishing Campaign

Source: CyberProof
(Published: 12 June 2026)
CyberProof analyzes a phishing or social engineering campaign involving the Job Hunt Trap Unmasking the Puma Careers Phishing Campaign. Read more.


GoFlateLoader Delivers Multiple Infostealers

Source: Gen Digital
(Published: 13 June 2026)
Gen Digital analyzes malware activity, delivery tradecraft, and victim impact related to GoFlateLoader Delivers Multiple Infostealers. Read more.


Greatxml Windows Zero Day

Source: Cyderes
(Published: 13 June 2026)
Cyderes analyzes exploitation activity and defensive implications related to Greatxml Windows Zero Day. Read more.


New NPM Supply Chain Campaign Identified a Multi Stage Cryptocurrency Malware with More Than 2 7 Million Downloads

Source: CYFIRMA
(Published: 13 June 2026)
CYFIRMA analyzes a supply chain or developer ecosystem compromise involving New NPM Supply Chain Campaign Identified a Multi Stage Cryptocurrency Malware with More Than 2 7 Million Downloads. Read more.


Oniondrop Malware Analysis

Source: Cyderes
(Published: 13 June 2026)
Cyderes analyzes malware activity, delivery tradecraft, and victim impact related to Oniondrop Malware Analysis. Read more.


Operation Taxshadow Multi Region Tax Phishing in Memory Malware Campaign

Source: CYFIRMA
(Published: 13 June 2026)
CYFIRMA analyzes a phishing or social engineering campaign involving Operation Taxshadow Multi Region Tax Phishing in Memory Malware Campaign. Read more.


Rogueplanet Windows Zero Day

Source: Cyderes
(Published: 13 June 2026)
Cyderes analyzes exploitation activity and defensive implications related to Rogueplanet Windows Zero Day. Read more.


Akira Ransomware Limewire Data Exfiltration

Source: Huntress
(Published: 14 June 2026)
Huntress analyzes ransomware or extortion activity tied to Akira Ransomware Limewire Data Exfiltration. Read more.


Error 524 Decoy Smishing

Source: Group-IB
(Published: 14 June 2026)
Group-IB analyzes a phishing or social engineering campaign involving Error 524 Decoy Smishing. Read more.


Inside Sniperdz PHAAS Ecosystem

Source: Group-IB
(Published: 14 June 2026)
Group-IB analyzes a phishing or social engineering campaign involving Inside Sniperdz PHAAS Ecosystem. Read more.


Kali365 Device Code Phishing Kit

Source: Huntress
(Published: 14 June 2026)
Huntress analyzes a phishing or social engineering campaign involving Kali365 Device Code Phishing Kit. Read more.


Narwhalrat

Source: Genians
(Published: 14 June 2026)
Genians analyzes malware activity, delivery tradecraft, and victim impact related to Narwhalrat. Read more.


Silabrat Hijackloader Trojan Malware

Source: Group-IB
(Published: 14 June 2026)
Group-IB analyzes malware activity, delivery tradecraft, and victim impact related to Silabrat Hijackloader Trojan Malware. Read more.


Expanded Jdy IOT and SOHO Botnet Enables Rapid Vulnerability Exploitation

Source: Lumen
(Published: 15 June 2026)
Lumen analyzes exploitation activity and defensive implications related to Expanded Jdy IOT and SOHO Botnet Enables Rapid Vulnerability Exploitation. Read more.


Fifa World Cup 2026 Emerging Domain Activity

Source: Malware Patrol
(Published: 15 June 2026)
Malware Patrol analyzes attacker abuse of AI-themed lures, tools, or workflows related to Fifa World Cup 2026 Emerging Domain Activity. Read more.


Interlock and Rhysida Within the Ransonware Ecosystem

Source: IBM X-Force
(Published: 15 June 2026)
IBM X-Force analyzes recent threat activity and defensive considerations related to Interlock and Rhysida Within the Ransonware Ecosystem. Read more.


Malspam to Deskcvb RAT Delivery Chain Analysis

Source: Huntress
(Published: 15 June 2026)
Huntress analyzes malware activity, delivery tradecraft, and victim impact related to Malspam to Deskcvb RAT Delivery Chain Analysis. Read more.


Malspam to Loader Delivery Chain Analysis

Source: Huntress
(Published: 15 June 2026)
Huntress analyzes malware activity, delivery tradecraft, and victim impact related to Malspam to Loader Delivery Chain Analysis. Read more.


These Convincing Copyright Notices Are Designed to Steal Google Logins

Source: Malwarebytes
(Published: 15 June 2026)
Malwarebytes analyzes a phishing or social engineering campaign involving These Convincing Copyright Notices Are Designed to Steal Google Logins. Read more.


Rogueplanet Anatomy of the Nightmare Eclipse Microsoft Defender Zero Day

Source: Picus Security
(Published: 16 June 2026)
Picus Security analyzes exploitation activity and defensive implications related to Rogueplanet Anatomy of the Nightmare Eclipse Microsoft Defender Zero Day. Read more.


Weedhack Minecraft Malware as a Service Campaign Research

Source: McAfee
(Published: 16 June 2026)
McAfee analyzes malware activity, delivery tradecraft, and victim impact related to Weedhack Minecraft Malware as a Service Campaign Research. Read more.


from Phishing Email to Process Injection Inside a Multi Stage Agent Tesla Infection Chain

Source: Point Wild
(Published: 16 June 2026)
Point Wild analyzes a phishing or social engineering campaign involving from Phishing Email to Process Injection Inside a Multi Stage Agent Tesla Infection Chain. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (5/19/26-6/2/26)

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

May 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

These insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the threat research featured below, helping highlight what mattered most during this reporting period.

 

Top ATT&CK Techniques Observed

  • T1195 – Supply Chain Compromise (9/9): Laravel Lang, Red Hat Cloud Services, CI/CD, GitHub, and developer package compromise dominated this period.
  • T1566 – Phishing / Social Engineering (8/9): AiTM kits, fake copyright notices, fake Teams/Claude/Gemini tools, and malvertising were common delivery paths.
  • T1555 – Credential Access (8/9): Infostealers, OAuth abuse, cloud token theft, and session-hijacking campaigns repeatedly targeted identity data.
  • T1071 – Application Layer C2 (7/9): Microsoft Teams, Google Drive, Azure, Discord, smart contracts, and cloud services were abused for C2 and concealment.
  • T1190 – Exploit Public-Facing Apps (7/9): PAN-OS, Ghost CMS, FortiClient EMS, Kubernetes, Ollama, and ViewState exploitation appeared across multiple reports.

What Matters Most

  • Supply chain compromise is the top signal. Attackers continue targeting developer ecosystems and trusted package flows for scalable access.
  • Identity remains the primary target. Many campaigns are built around stealing credentials, tokens, sessions, and cloud access.
  • Trusted platforms are being used as cover. Collaboration tools, cloud services, and developer platforms are central to multiple attack chains.
  • AI-themed lures are now routine. Fake Claude, Gemini, and LLM-related tools are being used to improve click-through and malware delivery.

What Defenders Should Watch

  • Unexpected package updates, CI/CD changes, GitHub repo activity, or developer tool execution
  • OAuth/AiTM behavior, suspicious MFA flows, and unusual cloud or identity token access
  • Outbound traffic to cloud-hosted, collaboration, blockchain, or newly observed infrastructure
  • Infostealer behavior targeting browsers, wallets, session cookies, and cloud credentials

Quick Wins

  • Monitor package managers, CI/CD pipelines, and developer repositories for unauthorized changes
  • Review OAuth app approvals, MFA prompts, and identity provider logs for anomalous activity
  • Restrict execution from temp, download, and user-controlled directories
  • Block newly registered domains tied to fake software, phishing, and supply chain lures

Key Insight: Attackers are scaling through trusted software, identity systems, and cloud platforms, with credential theft and persistent access as the consistent objectives.

 


Articles

Late May 2026 Cyber Threat Reports highlights a threat landscape shaped by software supply chain compromise, cloud abuse, credential theft, and nation-state activity. This edition covers Red Hat npm attacks, Laravel Lang compromise, Lazarus, Kimsuky, PAN-OS exploitation, AiTM phishing, and attacker abuse of Microsoft Teams, Google Drive, Azure, Discord, and developer ecosystems.

ASEC Threat Report

Source: AhnLab ASEC
(Published: 20 May 2026)
ASEC analyzed recent malware and phishing activity affecting users and organizations. Read more.


From Token Bingo to MAX Takeover: Kali365 Expands Into AWS, Microsoft, Okta, Xerox, MAX Messenger

Source: Arctic Wolf
(Published: 21 May 2026)
Kali365 operators expanded their account takeover operation across cloud, identity, messaging, and business platforms. Read more.


SEO Poisoning Campaign Leverages Gemini and Claude Code Impersonation to Deliver Infostealer

Source: EclecticIQ
(Published: 21 May 2026)
Financially motivated eCrime actors are impersonating AI developer tools to compromise workstations and steal sensitive data. Read more.


Fake Apps Deliver DonutLoader and Remcos RAT

Source: G DATA
(Published: 21 May 2026)
Researchers analyzed a malware campaign using fake applications to deliver DonutLoader and Remcos RAT. Read more.


Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT

Source: PolySwarm
(Published: 22 May 2026)
Lazarus-linked operators are expanding financial espionage with memory-resident malware and follow-on tooling. Read more.


SolyxImmortal: Analysis of a Python-Based Information Stealer

Source: Pulsedive
(Published: 22 May 2026)
Researchers analyzed SolyxImmortal, a Python-based infostealer targeting credentials and sensitive data. Read more.


Gamaredon’s Matryoshka Campaign Keeps Unpacking Gammaphish and Gammaworm

Source: Sekoia
(Published: 22 May 2026)
Sekoia analyzed a Gamaredon campaign using layered delivery techniques to deploy Gammaphish and Gammaworm payloads. Read more.


UAC-0247 Malware Targeting FPV Operators

Source: Synaptic Systems
(Published: 23 May 2026)
Researchers identified malware activity targeting FPV operators in a campaign tied to UAC-0247. Read more.


The Art of Being Ungovernable

Source: Cisco Talos
(Published: 23 May 2026)
Cisco Talos examined threat activity involving evasion, persistence, and abuse of infrastructure. Read more.


Ghost CMS Mass Compromised via CVE-2026-26980 Now Fueling ClickFix Attacks

Source: Qianxin XLab
(Published: 23 May 2026)
Attackers are exploiting Ghost CMS at scale to fuel ClickFix-style attacks and malicious infrastructure. Read more.


Mustang Panda PlugX Analysis: A Multi-Layer Execution Chain

Source: BlueCyber
(Published: 24 May 2026)
Researchers analyzed a Mustang Panda PlugX sample using a multi-layer execution chain. Read more.


CERT-UA Article 6315762

Source: CERT-UA
(Published: 24 May 2026)
CERT-UA published an advisory describing recent cyber activity and defensive guidance. Read more.


FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch

Source: Arctic Wolf
(Published: 27 May 2026)
Arctic Wolf observed a threat cluster exploiting CVE-2026-35616 to deploy an infostealer disguised as a Fortinet patch to FortiClient EMS-managed endpoints. Read more.


KnowledgeDeliver: ViewState Deserialization Vulnerability Exploitation

Source: Google Cloud
(Published: 27 May 2026)
Google Threat Intelligence analyzed exploitation activity involving a ViewState deserialization vulnerability. Read more.


AzureVeil Spearphishing Delivers C2

Source: CyberPress
(Published: 27 May 2026)
AzureVeil uses spearphishing to deliver command-and-control tooling against targeted victims. Read more.


China APT Webworm Hides European Government Espionage Traffic Inside Discord and Microsoft Cloud

Source: CyberSecSentinel
(Published: 27 May 2026)
A China-linked APT is hiding espionage traffic inside trusted cloud and collaboration platforms. Read more.


OverlayPhantom Android Banking Trojan

Source: Cyble
(Published: 28 May 2026)
Cyble analyzed OverlayPhantom, an Android banking trojan abusing overlay techniques to steal financial data. Read more.


Modern Supply Chain Intrusions: From CI/CD Abuse to Ecosystem-Wide Compromise

Source: DarkAtlas
(Published: 28 May 2026)
Researchers examined supply chain intrusions abusing CI/CD workflows and trusted developer ecosystems. Read more.


The Gentlemen Russia RaaS Operation Rocket Leak Analysis

Source: FalconFeeds
(Published: 28 May 2026)
FalconFeeds analyzed leaked materials related to The Gentlemen ransomware-as-a-service operation. Read more.


Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet

Source: CrowdStrike
(Published: 28 May 2026)
CrowdStrike detailed a takedown operation against a botnet targeting developers and software ecosystems. Read more.


Codestorm: A Microsoft 365 AiTM Phishing Kit With Storm-1167 Overlap

Source: HexaStrike
(Published: 29 May 2026)
Codestorm is a Microsoft 365 adversary-in-the-middle phishing kit with overlap to Storm-1167 activity. Read more.


Tracking North Korea Nation-State APT Infrastructure: Kimsuky

Source: Idan Malihi
(Published: 29 May 2026)
Researchers mapped infrastructure associated with Kimsuky-linked North Korean operations. Read more.


Fake Microsoft Teams Campaign Delivers ValleyRAT

Source: K7 Computing
(Published: 29 May 2026)
Threat actors are using fake Microsoft Teams lures to deliver ValleyRAT through NSIS installers and DLL sideloading. Read more.


FlutterBridge: New FlutterShell Backdoor

Source: Unit 42 (Palo Alto Networks)
(Published: 29 May 2026)
Unit 42 analyzed FlutterBridge, a new FlutterShell backdoor used in targeted activity. Read more.


Tracking Tampered Chef Clusters

Source: Unit 42 (Palo Alto Networks)
(Published: 29 May 2026)
Researchers tracked compromised Chef clusters and related attacker tradecraft. Read more.


Stealthy P2P Cryptominer Targets Ollama Endpoints

Source: Akamai
(Published: 29 May 2026)
Akamai observed a stealthy peer-to-peer cryptominer targeting exposed Ollama endpoints. Read more.


GreyVibe

Source: WithSecure Labs
(Published: 30 May 2026)
WithSecure analyzed GreyVibe malware activity and related tradecraft. Read more.


LLMShare Malvertising Campaign

Source: Push Security
(Published: 30 May 2026)
Push Security analyzed a malvertising campaign abusing LLM-themed lures to target users. Read more.


Laravel Lang Supply Chain Advisory

Source: Snyk
(Published: 30 May 2026)
Snyk disclosed a Laravel Lang supply chain compromise affecting package users and downstream environments. Read more.


Laravel Lang Compromise

Source: Socket
(Published: 30 May 2026)
Socket analyzed a compromise affecting Laravel Lang packages in the open-source ecosystem. Read more.


AI Agent at the Wheel: From CVE to Internal Database in Four Pivots

Source: Sysdig
(Published: 30 May 2026)
Sysdig analyzed how an attacker used LLMs to move from vulnerability exploitation to an internal database in four pivots. Read more.


Supply Chain Attack Targets Laravel-Lang Packages With Credential Stealer

Source: Aikido
(Published: 30 May 2026)
Aikido analyzed a Laravel-Lang supply chain attack that introduced credential-stealing code into package workflows. Read more.


Fake Claude Code Installer Infostealer

Source: Cyderes
(Published: 30 May 2026)
Cyderes analyzed a fake Claude Code installer used to deliver infostealer malware. Read more.


Kimsuky’s Advanced Attack Techniques: JSONPing, WebEx Spoofing, and HTTPSpy Variant

Source: ENKI
(Published: 30 May 2026)
Researchers analyzed advanced Kimsuky techniques involving JSONPing, WebEx spoofing, and a new HTTPSPY variant. Read more.


Trapdoor: Cross-Ecosystem Supply-Chain Credential Theft Operation

Source: SlowMist
(Published: 31 May 2026)
Researchers analyzed Trapdoor, a cross-ecosystem supply chain operation designed to steal credentials. Read more.


Nimbus RAT Abuses Microsoft Teams and Google Drive to Deploy Java RAT

Source: eSentire
(Published: 31 May 2026)
Threat actors are abusing Microsoft Teams and Google Drive to deploy Nimbus RAT. Read more.


Misconfigured, Enrolled, and Dormant: Anatomy of a P2PInfect Kubernetes Compromise

Source: Fortinet
(Published: 31 May 2026)
Fortinet analyzed a Kubernetes compromise involving P2PInfect activity and misconfigured cluster exposure. Read more.


Ghost Stadium Football Fraud

Source: Group-IB
(Published: 31 May 2026)
Group-IB analyzed football-themed fraud infrastructure targeting users with deceptive campaigns. Read more.


The Gentlemen Ransomware Defense Evasion TTPs

Source: Huntress
(Published: 31 May 2026)
Huntress analyzed defense evasion techniques used by The Gentlemen ransomware operators. Read more.


Pivoting on a Malspam Infrastructure Delivering JS Malware

Source: Intrinsec
(Published: 31 May 2026)
Intrinsec tracked malspam infrastructure used to deliver JavaScript malware through bulletproof networks. Read more.


From Fake Purchase Orders to Remote Access: Analyzing the JS.MonoGlyphRAT Threat to US Enterprises

Source: ANY.RUN
(Published: 02 June 2026)
Learn how JS.MonoGlyphRAT targets organizations, enables remote access, and creates costly security risks. Read more.


These Convincing Copyright Notices Are Designed to Steal Google Logins

Source: Security Boulevard
(Published: 02 June 2026)
Scammers use fake takedown requests, countdown timers, and spoofed sign-in screens to steal Google logins from Chrome developers. Read more.


New npm Supply Chain Attack: Red Hat Cloud Services Compromised

Source: OX Security
(Published: 02 June 2026)
A new npm supply chain attack compromised packages associated with Red Hat Cloud Services. Read more.


Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257

Source: Rapid7
(Published: 02 June 2026)
Rapid7 observed exploitation of a PAN-OS GlobalProtect authentication bypass vulnerability tracked as CVE-2026-0257. Read more.


ATMZOW Skimmer

Source: Reflectiz
(Published: 02 June 2026)
Reflectiz analyzed ATMZOW, a skimmer campaign targeting payment data through compromised web infrastructure. Read more.


Hunting Megalodon Fossils

Source: ReversingLabs
(Published: 02 June 2026)
ReversingLabs described hunting techniques for identifying Megalodon-related malware artifacts and infrastructure. Read more.


Red Hat Cloud Service npm Packages Backdoored in 72 Seconds

Source: ReversingLabs
(Published: 02 June 2026)
Researchers analyzed how Red Hat Cloud Service npm packages were backdoored shortly after compromise. Read more.


Operation Dragon Weave Targets Czech Republic and Taiwan Using Azure Cloud C2

Source: Seqrite
(Published: 02 June 2026)
Seqrite uncovered a China-linked campaign targeting Czech Republic and Taiwan using Azure cloud command-and-control. Read more.


DriveSurge

Source: Silent Push
(Published: 02 June 2026)
Silent Push analyzed DriveSurge infrastructure and related threat activity. Read more.


GitHub Internal Repositories Breached

Source: Sophos
(Published: 02 June 2026)
Sophos analyzed activity involving breached internal GitHub repositories and related security implications. Read more.


Multiple Red Hat Cloud Services npm Packages Compromised

Source: StepSecurity
(Published: 02 June 2026)
StepSecurity analyzed multiple compromised Red Hat Cloud Services npm packages and associated supply-chain risks. Read more.


Kali365 PhaaS Inside Attack Infrastructure

Source: Todyl
(Published: 02 June 2026)
Todyl analyzed Kali365 phishing-as-a-service infrastructure and its role in account compromise operations. Read more.


Void Dokkaebi Uses InvisibleFerret Malware

Source: Trend Micro
(Published: 02 June 2026)
Trend Micro analyzed Void Dokkaebi activity using InvisibleFerret malware in targeted campaigns. Read more.


Smart Contracts for Command and Control

Source: Trend Micro
(Published: 02 June 2026)
Trend Micro analyzed attacker use of smart contracts as command-and-control infrastructure. Read more.


Validin Python SDK for Threat Monitoring

Source: Validin
(Published: 02 June 2026)
Validin introduced a Python SDK for threat monitoring and infrastructure analysis workflows. Read more.


Webworm: New Burrowing Techniques

Source: ESET Research
(Published: 02 June 2026)
ESET Research analyzed Webworm’s new techniques for persistence, stealth, and intrusion activity. Read more.


Threat Actors Target Crypto Organizations

Source: Wiz
(Published: 02 June 2026)
Wiz analyzed attacker targeting of cryptocurrency organizations and related cloud security risks. Read more.


Wiz Sensor Forensics GA

Source: Wiz
(Published: 02 June 2026)
Wiz announced forensic capabilities for incident response and cloud investigation workflows. Read more.


Premium Deception: Global Android Carrier Billing Fraud Campaign

Source: Zimperium
(Published: 02 June 2026)
Zimperium uncovered a global Android carrier billing fraud campaign using deceptive premium service flows. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (5/5/26-5/19/26)

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

April 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

These insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the threat research featured below, helping highlight what mattered most during this reporting period.

Top ATT&CK Techniques Observed

  • T1195 – Supply Chain Compromise (9/9): npm, PyPI, OpenSearch, TanStack, TeamPCP, and Shai-Hulud activity dominated this period.
  • T1566 – Phishing / Social Engineering (8/9): Smishing, OAuth device-code phishing, fake apps, aid-themed lures, and AI-assisted campaigns remained prominent.
  • T1555 – Credential Access (8/9): Infostealers, banking trojans, OAuth token theft, and cloud credential harvesting appeared across multiple campaigns.
  • T1059 – Command Execution (7/9): PowerShell, Python, Bun, Git hooks, loaders, and RATs supported multi-stage execution chains.
  • T1071 – Application Layer C2 (7/9): Telegram, NATS, Microsoft Teams, and other trusted channels were abused for C2 and operations.

What Matters Most

  • Supply chain attacks remain the clearest trend. Developer ecosystems and package managers continue to be used for scalable access.
  • Credential theft is the common objective. Many campaigns ultimately target passwords, sessions, tokens, banking data, or cloud keys.
  • AI is moving into attacker workflows. Adversaries are using AI for exploitation, lures, targeting, and operational scale.
  • Trusted platforms are being abused. Teams, Git hooks, package repositories, and cloud services are central to multiple attack chains.

What Defenders Should Watch

  • Unexpected package installs, Git hook activity, or developer tool execution
  • OAuth device-code abuse, suspicious MFA flows, and session theft patterns
  • Outbound traffic to Telegram, NATS, cloud-hosted, or newly observed infrastructure
  • Infostealer behavior targeting browsers, wallets, tokens, and cloud credentials

Quick Wins

  • Restrict and monitor package manager activity in developer environments
  • Review OAuth app approvals and device-code authentication policies
  • Alert on execution from temp, download, and user-controlled directories
  • Block newly registered domains tied to phishing, fake apps, and software lures

Key Insight: Attackers are increasingly abusing trusted developer ecosystems, social engineering campaigns, and cloud platforms to scale operations, with credential theft remaining the primary objective.

Articles

Early May 2026 Cyber Threat Reports highlights a fast-moving mix of supply chain compromise, phishing infrastructure, infostealer activity, and AI-assisted attacker workflows. This edition includes Shai-Hulud, TeamPCP, Tycoon 2FA, AMOS, Kazuar, and campaigns abusing npm, PyPI, Microsoft Teams, OAuth flows, and developer tooling.

Mini Shai-Hulud: Cross-Ecosystem Supply Chain Worm Targeting npm and PyPI

Source: Expel
(Published: 06 May 2026)
Expel researchers detail Mini Shai-Hulud, a wormable supply chain campaign targeting both npm and PyPI ecosystems to spread malicious packages. Read more.


Inside a Criminal Phishing Panel

Source: Push Security
(Published: 06 May 2026)
Push Security analyzes a modern phishing panel used to automate credential theft, session hijacking, and operational management for phishing campaigns. Read more.


PureLogs Delivery via PawsRunner and Steganography

Source: Fortinet
(Published: 06 May 2026)
Fortinet researchers observed PureLogs malware being distributed through PawsRunner loaders combined with steganography techniques. Read more.


Operation HumanitarianBait: An Infostealer Campaign in Disguise

Source: Cyble
(Published: 07 May 2026)
Cyble analyzes Operation HumanitarianBait, a stealthy espionage campaign using aid-themed lures to deploy a fileless Python infostealer. Read more.


Industrialized Smishing Infrastructure Targeting UAE and Singapore

Source: Medium
(Published: 07 May 2026)
Researchers uncovered a large-scale smishing infrastructure impersonating transportation and government services in the UAE and Singapore. Read more.


TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Source: Elastic Security Labs
(Published: 07 May 2026)
REF3076 uses a trojanized Logitech installer to deploy TCLBANKER, a Brazilian banking trojan with environment-gated payloads, WPF fraud overlays, and self-propagating WhatsApp and Outlook worm modules. Read more.


Architecture Deception Investment Crypto Fraud

Source: Group-IB
(Published: 07 May 2026)
Group-IB uncovered a cryptocurrency investment fraud operation using deceptive infrastructure and impersonation tactics. Read more.


Suspicious Microsoft Store Apps May Deliver Go Backconnect Proxy Malware

Source: Luke Acha
(Published: 08 May 2026)
A suspicious Microsoft Store utility package impersonating WinDirStat loads a Go-based backconnect proxy implant through a native DLL. Read more.


PAN-OS Buffer Overflow Flaw Under Active State-Sponsored Exploitation

Source: HivePro
(Published: 08 May 2026)
A critical PAN-OS buffer overflow vulnerability is being actively exploited in campaigns linked to state-sponsored threat actors. Read more.


Orbit Returns

Source: Intezer
(Published: 08 May 2026)
Intezer researchers observed the return of Orbit malware, a Linux-focused threat using stealthy persistence and credential harvesting techniques. Read more.


Lookalike Domains Expose the iPhone Theft Economy

Source: Infoblox
(Published: 08 May 2026)
Infoblox researchers identified lookalike domains supporting large-scale iPhone theft and resale fraud operations. Read more.


Mobidash Android Ad Fraud Click Injection Analysis

Source: Jamf
(Published: 08 May 2026)
Jamf researchers analyzed Mobidash, an Android ad fraud campaign abusing click injection techniques for monetization. Read more.


OpenSearch Compromised in TeamPCP Campaign

Source: OpenSourceMalware
(Published: 09 May 2026)
TeamPCP operators compromised OpenSearch infrastructure to distribute malicious payloads and expand supply chain access. Read more.


Attackers Adopt Bun Runtime to Spread NWHStealer

Source: Malwarebytes
(Published: 09 May 2026)
Threat actors are leveraging the JavaScript runtime Bun to distribute NWHStealer malware and evade traditional detections. Read more.


DPRK Git Hooks Malware Campaign

Source: OpenSourceMalware
(Published: 10 May 2026)
North Korean operators are abusing Git hooks to silently execute malware within developer environments and repositories. Read more.


Sinkholing CountLoader: Insights Into Recent Campaigns

Source: McAfee
(Published: 10 May 2026)
McAfee Labs shares insights from sinkholing CountLoader infrastructure tied to malware delivery campaigns. Read more.


GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Source: Google Cloud Blog
(Published: 11 May 2026)
Google Threat Intelligence Group describes adversaries leveraging AI for vulnerability exploitation, augmented operations, and initial access. Read more.


Shai-Hulud compromises the @tanstack ecosystem: 160+ packages compromised

Source: Endor Labs
(Published: 11 May 2026)
Attackers planted credential-stealing malware in 84 @tanstack package versions across React, Solid, Vue, and Start as part of the fifth Shai-Hulud wave in eight months. Read more.


April 2026 Phishing Email Trends Report

Source: AhnLab ASEC
(Published: 12 May 2026)
In April 2026, the most common threat in phishing email attachments was Trojan, followed by phishing and downloader activity. Read more.


The Ultimate Guide to Detection Engineering with Censys

Source: Censys
(Published: 12 May 2026)
Vendor detection is not enough, and Censys frames infrastructure context as a way to turn indicators into reusable detection patterns. Read more.


Tycoon 2FA Operators Adopt OAuth Device Code Phishing

Source: eSentire
(Published: 12 May 2026)
Tycoon 2FA operators have adopted OAuth device code phishing to bypass traditional phishing defenses and capture user authentication tokens. Read more.


Malicious npm Packages Deliver Telegram RAT

Source: SafeDep
(Published: 13 May 2026)
Researchers uncovered malicious npm packages distributing a Telegram-controlled remote access trojan through open-source ecosystems. Read more.


FamousSparrow APT Targets Azerbaijani Oil and Gas Industry

Source: Bitdefender
(Published: 13 May 2026)
Bitdefender Labs tracked a multi-wave intrusion targeting an Azerbaijani oil and gas company from late December 2025 through late February 2026. Read more.


Suspected China-Linked Threat Actor Targets Global Manufacturer With Undocumented TencShell Malware

Source: Cato Networks
(Published: 13 May 2026)
The observed infection chain moves from a first-stage dropper to Donut shellcode retrieval through a masqueraded .woff resource, reflective shellcode execution, in-memory loading, and attempted C2 communication. Read more.


Kimsuky AppleSeed and PebbleDash Campaigns

Source: Kaspersky Securelist
(Published: 14 May 2026)
Kimsuky operators continue deploying AppleSeed and PebbleDash malware in espionage-focused campaigns targeting regional organizations. Read more.


NATS-as-C2: Inside a New Technique Attackers Are Using to Harvest Cloud Credentials and AI API Keys

Source: Sysdig
(Published: 14 May 2026)
The Sysdig Threat Research Team identified a novel command-and-control technique in which a threat actor used a NATS server as C2 infrastructure. Read more.


Amatera Stealer 4.0.2 Beta: What’s New in This Variant

Source: eSentire
(Published: 14 May 2026)
eSentire’s Threat Response Unit analyzes Amatera Stealer 4.0.2 Beta and changes in this variant’s behavior, delivery, and capability set. Read more.


Kazuar: Anatomy of a Nation-State Botnet

Source: Microsoft Security
(Published: 14 May 2026)
Microsoft details Kazuar malware infrastructure and tradecraft associated with nation-state activity. Read more.


ModeloRAT Campaign Uses Microsoft Teams Compromise

Source: Rapid7
(Published: 14 May 2026)
Rapid7 researchers dissected a ModeloRAT campaign leveraging Microsoft Teams compromise and social engineering. Read more.


OceanLotus Suspected PyPI Campaign

Source: Kaspersky Securelist
(Published: 15 May 2026)
Researchers identified suspected OceanLotus-linked malicious Python packages uploaded to PyPI to target developers and organizations. Read more.


Gremlin Stealer’s Evolved Tactics: Hiding in Plain Sight With Resource Files

Source: Unit 42 (Palo Alto Networks)
(Published: 15 May 2026)
Unit 42 researchers describe how Gremlin Stealer has evolved to hide malicious content in resource files while targeting credentials and sensitive data. Read more.


Dirty Pipe Variant Enables Linux Privilege Escalation

Source: ReversingLabs
(Published: 15 May 2026)
Researchers analyzed DirtyFrag, a Linux privilege escalation exploit targeting vulnerable systems. Read more.


Fake Claude Site Spreads Backdoor Malware

Source: Sophos
(Published: 15 May 2026)
Sophos researchers identified fake Claude AI websites distributing backdoor malware through deceptive downloads. Read more.


AMOS Malware Steals macOS Data at Scale

Source: Sophos
(Published: 16 May 2026)
Sophos details how AMOS malware is increasingly targeting macOS users for large-scale credential and data theft. Read more.


TeamPCP Supply Chain Attacks Analysis

Source: Trend Micro
(Published: 16 May 2026)
Trend Micro analyzes TeamPCP supply chain attacks affecting developer ecosystems and open-source infrastructure. Read more.


OpenClaw Skill Distributes Remcos RAT and GhostLoader

Source: Zscaler
(Published: 17 May 2026)
Zscaler researchers observed malicious OpenClaw skills distributing Remcos RAT and GhostLoader malware. Read more.


Funnull Sanctioned: What the Polyfill[.]io Attack Exposed About Infrastructure Laundering

Source: cside
(Published: 17 May 2026)
OFAC sanctioned Funnull Technology Inc. on 2025-05-29, along with administrator Liu Lizhi. Read more.


SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain

Source: SentinelOne
(Published: 18 May 2026)
Infostealers targeting macOS have continued to proliferate over the last two years, with threat actors iterating on successful techniques across related malware families. Read more.


 

Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (4/21/26-5/5/26)

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

April 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

Top ATT&CK Techniques Observed

  • T1195 – Supply Chain Compromise (Score: 9/9): Abuse of trusted software distribution channels including npm packages, developer tools, and compromised updates.
  • T1566 – Phishing / Social Engineering (Score: 8/9): OAuth AiTM attacks, smishing kits, CAPTCHA lures, and AI-generated phishing campaigns.
  • T1555 – Credential Access (Score: 8/9): Widespread infostealer activity targeting credentials, sessions, and financial data.
  • T1190 – Exploit Public-Facing Applications (Score: 7/9): Active exploitation of cPanel, LLM infrastructure, and internet-facing services.
  • T1071 – Application Layer C2 (Score: 7/9): Use of SaaS platforms, OAuth workflows, and blockchain-based communication channels.
  • T1059 – Command Execution (Score: 6/9): PowerShell, Python backdoors, and multi-stage loaders enabling execution and persistence.

What Matters Most This Period

  • Supply chain attacks are leading initial access. Compromised packages, repositories, and software updates are being used to scale access across enterprise environments.
  • Credential theft is the common objective. Across phishing, malware, and supply chain attacks, the end goal is consistently identity and account access.
  • AI is increasing attacker efficiency. Threat actors are using AI-generated lures and automation to improve targeting and scale campaigns.
  • Trusted platforms are being systematically abused. GitHub, SaaS tools, browser extensions, and developer ecosystems are central to multiple attack chains.
  • Infrastructure exploitation remains high-impact. Targeting of appliances and exposed services continues to deliver significant access.

What Defenders Should Watch

  • Execution from developer tools, package managers, and software installers
  • OAuth abuse, MFA bypass attempts, and unusual authentication flows
  • Browser extensions and macOS scripting activity tied to credential theft
  • Outbound connections to newly observed or cloud-hosted infrastructure
  • Mobile applications requesting sensitive permissions tied to financial workflows

Quick Wins

  • Restrict and monitor package manager and developer tool usage
  • Enforce MFA with additional verification for high-risk actions
  • Alert on execution from temporary and download directories
  • Block newly registered domains associated with phishing and fake software
  • Review exposure of internet-facing services and administrative interfaces

Key Insight: Attackers are converging on three scalable entry points: 1) trusted software (supply chain), 2) trusted users (phishing), and 3) trusted platforms (SaaS/cloud) – all with credential theft as the consistent objective.

Articles

Late April 2026 Cyber Threat Reports highlight a surge in supply chain compromises, OAuth phishing, and infostealer activity, alongside growing abuse of developer ecosystems, SaaS platforms, and AI-driven attack techniques. From npm package backdoors and trojanized software to credential theft campaigns and ransomware operations like Qilin and Kyber, attackers continue to scale access through trusted environments while targeting identity and infrastructure at speed.

Tropic Trooper Pivots to AdaptixC2 and Custom Beacon Listener

Source: Zscaler
(Published: 22 April 2026)
Tropic Trooper has shifted tactics by adopting AdaptixC2 and a custom beacon listener in a multi-stage campaign targeting organizations across East Asia. Read more.


When Malware Authors Study Algebra: The Group Theory Inside Bedep’s DGA

Source: Gen Digital
(Published: 22 April 2026)
Bedep was a malware family active mainly in 2014 and 2015 that used an unusually sophisticated domain generation algorithm, or DGA, to hide its command-and-control infrastructure. Read more.


DragonBreath: Dragon in the Kernel

Source: Ransom-ISAC
(Published: 22 April 2026)
A 0-day BYOVD vulnerability in dragoncore_k.sys signed by Zhengzhou 403 Network Technology, with shell company analysis, Dragon Breath APT-Q-27 attribution, and an APT31 / Wuhan Xiaoruizhi personnel nexus. Read more.


The Gentlemen RaaS and SystemBC Activity Observed in Enterprise Intrusions

Source: PolySwarm
(Published: 22 April 2026)
Recent enterprise intrusions reveal increased activity from The Gentlemen ransomware-as-a-service operation alongside SystemBC malware used for command-and-control. Read more.


Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions

Source: Socket
(Published: 22 April 2026)
Docker and Socket have uncovered malicious Checkmarx KICS images and suspicious code extension releases in a broader supply chain compromise. Read more.


The Meta 2FA Trap: From Verified Badge to Account Takeover

Source: Cofense
(Published: 22 April 2026)
Attackers are exploiting Meta’s verified badge system to bypass 2FA protections and take over user accounts through social engineering techniques. Read more.


Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs

Source: Infoblox
(Published: 23 April 2026)
CAPTCHAs, the mundane tasks where we demonstrate our ability to select bicycles or distinguish chihuahuas from blueberry muffins, are increasingly being weaponized to trick users into performing actions with unexpected consequences. Read more.


Analyzing a Full ClickFix Attack Chain – Part 1

Source: Stormshield
(Published: 23 April 2026)
In a previous article, we introduced the ClickFix technique. Read more.


Komari C2 Agent Abuse

Source: Huntress
(Published: 23 April 2026)
Threat actors are abusing Komari C2 agents to establish persistence and execute malicious commands across compromised environments. Read more.


Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Source: Google Cloud Blog
(Published: 23 April 2026)
Google Threat Intelligence Group identified a multistage intrusion campaign by UNC6692 that used persistent social engineering, custom malware, and pivoting inside victim environments. Read more.


Operation TrustTrap: Domain Spoofing Campaign

Source: Cyble
(Published: 23 April 2026)
Operation TrustTrap leverages domain spoofing techniques to deceive users and facilitate phishing and credential theft campaigns. Read more.


Inside agenteV2: How Brazilian Attackers Use Fake Court Summons to Steal Banking Credentials in Real Time

Source: ANY.RUN
(Published: 24 April 2026)
A new phishing campaign targeting Brazilian users demonstrates how modern financial malware has evolved from simple credential theft into full-scale, operator-driven fraud platforms. Read more.


Bitwarden CLI Supply Chain Compromise

Source: SafeDep
(Published: 24 April 2026)
The malicious @bitwarden/cli npm release was not a normal Bitwarden update. Read more.


Kyber Ransomware: Double Trouble With Windows and ESXi Attacks

Source: Rapid7
(Published: 24 April 2026)
Kyber ransomware operators are targeting both Windows and ESXi environments, increasing impact through multi-platform encryption strategies. Read more.


Compromised eScan Update Enables Multi-Stage Malware and Blockchain C2

Source: Darktrace
(Published: 24 April 2026)
A compromised eScan software update was used to deliver multi-stage malware that communicates with blockchain-based command-and-control infrastructure. Read more.


KYCShadow Android Banking Malware Exploits Fake KYC Workflows

Source: CYFIRMA
(Published: 25 April 2026)
KYCShadow malware targets Android users by abusing fake KYC processes to steal credentials and one-time passwords. Read more.


Lotus Wiper Malware Campaign

Source: Kaspersky Securelist
(Published: 25 April 2026)
Lotus Wiper is a destructive malware campaign targeting organizations with data wiping capabilities following initial compromise. Read more.


CVE-2026-33626 Exploited in LLM Inference Engines Within Hours

Source: Sysdig
(Published: 25 April 2026)
Attackers rapidly weaponized CVE-2026-33626 to exploit LMDeploy-based LLM inference engines within hours of disclosure. Read more.


Mustang Panda Targets Banking Sector and Geopolitical Entities

Source: Acronis
(Published: 26 April 2026)
Mustang Panda is conducting campaigns targeting banking institutions and geopolitical organizations using advanced malware delivery techniques. Read more.


High-Risk GenAI Browser Extensions Expose Users to Data Theft

Source: Unit 42 (Palo Alto Networks)
(Published: 26 April 2026)
Researchers identified multiple GenAI browser extensions exposing sensitive user data through excessive permissions and insecure handling of inputs. Read more.


BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector

Source: Arctic Wolf
(Published: 27 April 2026)
Arctic Wolf has identified a targeted intrusion against a North American Web3/cryptocurrency company, which we attribute with a high confidence level to BlueNoroff, a financially motivated subgroup of DPRK’s Lazarus Group. Read more.


New NGate Variant Hides in Trojanized NFC Payment App

Source: ESET Research
(Published: 27 April 2026)
A new NGate malware variant is distributed through trojanized NFC payment apps to steal financial data from mobile users. Read more.


Critical cPanel Authentication Bypass Actively Exploited

Source: Cato Networks
(Published: 27 April 2026)
A critical authentication bypass vulnerability in cPanel/WHM is being actively exploited in the wild to gain unauthorized access to systems. Read more.


Oluomo OAuth AiTM Phishing Campaign

Source: Censys
(Published: 28 April 2026)
Attackers are leveraging OAuth-based adversary-in-the-middle techniques using naturalization-themed lures to harvest credentials. Read more.


Silent Lures: Empty Subject Email Attacks

Source: Cyberproof
(Published: 28 April 2026)
Attackers are using empty subject lines in phishing emails to bypass filters and increase user engagement rates. Read more.


GachiLoader Uses AI-Themed Lures to Deliver Rhadamanthys Infostealer

Source: Malwarebytes (ThreatDown)
(Published: 29 April 2026)
GachiLoader campaigns use AI-themed lures and fake repositories to distribute Rhadamanthys infostealer malware. Read more.


Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer

Source: Aikido
(Published: 29 April 2026)
A new npm supply-chain compromise is targeting the SAP developer ecosystem. Read more.


Claude Adds Malware to Crypto Agent

Source: ReversingLabs
(Published: 29 April 2026)
ReversingLabs researchers discovered malicious code in a crypto trading project after an AI-based coding agent added a malicious package as a dependency. Read more.


Fake DHL Phishing Campaign Targets Credentials

Source: Forcepoint
(Published: 29 April 2026)
A phishing campaign impersonating DHL delivery notifications is being used to steal user credentials through fake tracking pages. Read more.


ClickFix Removes Your Background but Leaves the Malware

Source: Huntress
(Published: 30 April 2026)
BackgroundFix is a ClickFix lure dressed up as a free image-editing tool. Read more.


OtterCookie and Shifty Corsair Attack Strategy

Source: BlueVoyant
(Published: 30 April 2026)
Researchers observed a bifurcated attack strategy combining OtterCookie malware with shifting infrastructure to evade detection. Read more.


Mapping Remus Infostealer

Source: Cyber Intelligence Insights
(Published: 30 April 2026)
Researchers mapped Remus infostealer infrastructure using indicators, hosting patterns, ASN analysis, and blockchain pivots to uncover additional C2 domains and operator infrastructure. Read more.


Email Threat Landscape: Q1 2026 Trends and Insights

Source: Microsoft Security
(Published: 30 April 2026)
Microsoft analyzed Q1 2026 email threat activity, highlighting trends in phishing, social engineering, malware delivery, and credential theft. Read more.


RDP Security Risks Highlight Need for Secure Remote Access

Source: Forescout
(Published: 30 April 2026)
Ongoing threats targeting RDP services are driving the need for stronger remote access security controls and monitoring. Read more.


Watch Guard! Qilin Affiliate Exploits Network Appliances for Initial Access

Source: Ctrl-Alt-Intel
(Published: 01 May 2026)
Qilin is a long-standing and prolific Ransomware-as-a-Service group, active since late 2022, causing real-world impact across numerous sectors globally. Read more.


Inside Lazarus: AI-Driven Attacks on Developers

Source: Expel
(Published: 01 May 2026)
Lazarus Group is leveraging AI tools to scale attacks targeting developers and software supply chains. Read more.


Phoenix Phishing-as-a-Service Kit for Smishing Campaigns

Source: Group-IB
(Published: 02 May 2026)
The Phoenix PhaaS kit is enabling large-scale smishing campaigns with automated phishing infrastructure. Read more.

Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (4/7/26-4/21/26)

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

March 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

This Edition’s Articles

Mid April 2026 Cyber Threat Reports highlights a surge in supply chain attacks like STX RAT delivery via trojanized software, alongside APT28 router exploitation, Banshee Stealer activity, and evolving payroll phishing campaigns such as Storm-2755. Across cloud platforms, macOS environments, and critical infrastructure, attackers continue to blend social engineering, credential theft, and infrastructure abuse to scale real-world intrusions.

GlassWorm goes native: New Zig dropper infects every IDE on your machine

Source: Aikido
(Published: 08 April 2026)
We have been tracking GlassWorm for over a year. Read more.


Cyber Saga: In the Footsteps of the DPRK IT Workers

Source: Group-IB
(Published: 08 April 2026)
In recent years, the shift toward remote work has introduced unprecedented vulnerabilities into corporate hiring pipelines. Read more.


ClickFix technique uses Script Editor instead of Terminal on macOS

Source: Jamf
(Published: 08 April 2026)
Jamf Threat Labs discovered a ClickFix-style macOS attack that abuses the applescript:// URL scheme to launch Script Editor and deliver an Atomic Stealer infostealer payload – bypassing Terminal entirely. Read more.


Evasive Blob Phishing Detection

Source: ANY.RUN
(Published: 09 April 2026)
Attackers are increasingly using blob URLs in phishing campaigns to evade traditional detection and obscure malicious payload delivery. Read more.


MicroStealer and SparkStealer Credential Theft Infrastructure

Source: FalconFeeds
(Published: 09 April 2026)
Researchers uncovered a gaming-themed campaign distributing MicroStealer and SparkStealer malware through credential theft infrastructure. Read more.


Operation Phantom Claude: macOS Infostealer Campaign

Source: FalconFeeds
(Published: 09 April 2026)
Threat actors are impersonating Anthropic’s Claude platform to deliver macOS infostealers in a campaign dubbed Phantom Claude. Read more.


Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees

Source: Microsoft
(Published: 09 April 2026)
Microsoft observed Storm-2755 targeting Canadian employees in payroll-themed attacks that use phishing and adversary-in-the-middle tradecraft to steal credentials and redirect salaries. Read more.


Unholy Trinity: Werewolves Target Law Enforcers

Source: BI.ZONE
(Published: 10 April 2026)
A coordinated campaign dubbed “Unholy Trinity” is targeting law enforcement agencies using a combination of advanced malware and social engineering techniques. Read more.


Fake GitHub Repositories Deliver SmartLoader and StealC

Source: HexaStrike
(Published: 10 April 2026)
Over 100 fake GitHub repositories were identified distributing SmartLoader and StealC malware to unsuspecting developers. Read more.


Active Exploitation of Critical Adobe Prototype Pollution Vulnerability

Source: Hive Pro
(Published: 10 April 2026)
Threat actors are actively exploiting a critical Adobe prototype pollution vulnerability to execute arbitrary code in affected environments. Read more.


Monitoring the Monitor: How CPUID’s HWMonitor Supply Chain Was Hijacked to Deploy STX RAT

Source: Cyderes
(Published: 10 April 2026)
Monitoring the Monitor: How CPUID’s HWMonitor Supply Chain Was Hijacked to Deploy STX RAT. Read more.


CPU-Z Trojan Delivers STX RAT and PureLogs Data Exfiltration

Source: Deception Pro
(Published: 11 April 2026)
A supply chain attack involving trojanized CPU-Z software installs STX RAT and PureLogs to exfiltrate sensitive data from infected systems. Read more.


APT28 Exploits SOHO Routers for DNS Hijacking

Source: Hive Pro
(Published: 11 April 2026)
APT28 is exploiting vulnerable SOHO routers to conduct large-scale DNS hijacking and credential theft operations. Read more.


Healthcare in the Crosshairs: Iran-Linked Cyber Threats

Source: PolySwarm
(Published: 12 April 2026)
Iran-linked cyber operations are increasingly targeting healthcare organizations and supply chains, raising risks across hospitals and medical infrastructure. Read more.


Iran-Linked PLC Exploitation Expands Across US Critical Infrastructure

Source: PolySwarm
(Published: 12 April 2026)
Threat actors linked to Iran are expanding PLC exploitation campaigns targeting US critical infrastructure sectors. Read more.


CyberAv3ngers Exploit Internet-Exposed PLCs in the US

Source: Hive Pro
(Published: 12 April 2026)
Iranian-affiliated CyberAv3ngers are targeting exposed PLC systems in the US to disrupt industrial control environments. Read more.


Pawn Storm Dual Zero-Day Exploitation Campaign

Source: Hive Pro
(Published: 13 April 2026)
Pawn Storm threat actors are leveraging dual zero-day vulnerabilities to execute targeted attacks against high-value organizations. Read more.


108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure

Source: Socket
(Published: 13 April 2026)
Socket’s Threat Research Team identified 108 malicious Chrome extensions operating as a coordinated campaign under a shared C2 infrastructure at `cloudapi[.]stream`. Read more.


Building a last-resort unpacker with AI

Source: Gen Digital
(Published: 13 April 2026)
Malicious software is often designed to hide its true behavior, wrapping its underlying logic in layers that make it difficult to analyze. Read more.


New Lua-Based Malware LucidRook

Source: Cisco Talos
(Published: 14 April 2026)
Cisco Talos identified LucidRook, a Lua-based malware strain designed for persistence and data exfiltration in targeted environments. Read more.


Storm-2755 Payroll Fraud Campaign

Source: Hive Pro
(Published: 14 April 2026)
Storm-2755 is conducting a stealthy payroll diversion campaign targeting organizations in Canada. Read more.


Are Former Black Basta Affiliates Automating Executive Targeting?

Source: ReliaQuest
(Published: 14 April 2026)
A new campaign is successfully evolving “Black Basta’s” signature social engineering playbook into a faster, more targeted, and increasingly automated intrusion method aimed at senior leadership. Read more.


The N8N N8mare Campaign

Source: Cisco Talos
(Published: 15 April 2026)
Threat actors are exploiting n8n automation workflows in a campaign dubbed N8mare to deploy malware and maintain persistence. Read more.


Vercel Confirms Data Breach

Source: CyberPress
(Published: 15 April 2026)
Vercel confirmed a data breach after attackers claimed access to internal systems and sensitive information. Read more.


UAT-10362 Deploys LucidRook Malware

Source: Hive Pro
(Published: 15 April 2026)
UAT-10362 is deploying LucidRook malware in targeted attacks against Taiwanese non-governmental organizations. Read more.


CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace

Source: Sysdig
(Published: 15 April 2026)
Three days after the April 8, 2026, disclosure of a critical pre-authorization remote code execution (RCE) in the marimo Python notebook platform, the Sysdig Threat Research Team (TRT) observed multiple unique attacks, including a threat actor deploying malware that was hosted on HuggingFace Spaces using a marimo exploit. Read more.


CPU-Z Supply Chain Attack Delivers STX RAT

Source: CyberSec Sentinel
(Published: 16 April 2026)
A trojanized version of CPU-Z and HWMonitor software is being used to distribute STX RAT through a supply chain attack. Read more.


Astral Injection Supply Chain Attack

Source: JFrog Security Research
(Published: 16 April 2026)
The Astral Injection attack demonstrates a new supply chain technique targeting developer environments and package ecosystems. Read more.


A Deep Dive Into Attempted Exploitation of CVE-2023-33538

Source: Unit 42 (Palo Alto Networks)
(Published: 16 April 2026)
Unit 42 researchers analyzed attempted exploitation of CVE-2023-33538 and linked the activity to botnet-style command injection campaigns targeting vulnerable WiFi routers. Read more.


MiningDropper Android Malware Campaign

Source: Cyble
(Published: 17 April 2026)
MiningDropper is a modular Android malware campaign designed to deploy cryptomining payloads across infected devices globally. Read more.


Malicious dom-utils-lite NPM Package Installs SSH Backdoor

Source: SafeDep
(Published: 17 April 2026)
A malicious npm package installs an SSH backdoor, allowing attackers to maintain unauthorized access to compromised systems. Read more.


Banshee Stealer Technical Analysis

Source: DarkAtlas
(Published: 18 April 2026)
Researchers provide an in-depth technical breakdown of Banshee Stealer, highlighting its capabilities for credential theft and persistence. Read more.


FakeWallet Crypto Stealer in iOS App Store

Source: Kaspersky Securelist
(Published: 18 April 2026)
FakeWallet apps discovered in the iOS App Store are stealing cryptocurrency credentials from unsuspecting users. Read more.


Lumma Stealer Infection With Sectop RAT and ArechClient2

Source: SANS ISC
(Published: 19 April 2026)
A multi-stage infection chain involving Lumma Stealer deploys additional payloads including Sectop RAT and ArechClient2 for expanded compromise. Read more.


JanelaRAT Financial Threat in Latin America

Source: Kaspersky Securelist
(Published: 19 April 2026)
JanelaRAT is emerging as a financial malware threat targeting banking users across Latin America. Read more.


MOIS-Linked Threat Actor Campaign Evolution

Source: DomainTools
(Published: 20 April 2026)
DomainTools researchers track evolving campaigns linked to MOIS-associated threat actors targeting geopolitical and infrastructure objectives. Read more.


Supply Chain Attack Hits Vercel: User Data is Being Sold on BreachForums For $2M

Source: OX Security
(Published: 20 April 2026)
On April 19, 2026, Vercel, a web development platform that enables developers to host and scale websites, announced it was breached via a third party, Context AI, which was also breached. Read more.


Dark Storm Team and Middle East Cyber Conflict

Source: FalconFeeds
(Published: 21 April 2026)
The Dark Storm Team is actively participating in cyber operations tied to geopolitical tensions across the Middle East, targeting critical infrastructure. Read more.


GlassWorm goes native: New Zig dropper infects every IDE on your machine

Source: Aikido
(Published: 08 April 2026)
We have been tracking GlassWorm for over a year. Read more.


ClickFix technique uses Script Editor instead of Terminal on macOS

Source: Jamf
(Published: 08 April 2026)
Jamf Threat Labs discovered a ClickFix-style macOS attack that abuses the applescript:// URL scheme to launch Script Editor and deliver an Atomic Stealer infostealer payload – bypassing Terminal entirely. Read more.


MicroStealer and SparkStealer Credential Theft Infrastructure

Source: FalconFeeds
(Published: 09 April 2026)
Researchers uncovered a gaming-themed campaign distributing MicroStealer and SparkStealer malware through credential theft infrastructure. Read more.


Unholy Trinity: Werewolves Target Law Enforcers

Source: BI.ZONE
(Published: 10 April 2026)
A coordinated campaign dubbed “Unholy Trinity” is targeting law enforcement agencies using a combination of advanced malware and social engineering techniques. Read more.


Active Exploitation of Critical Adobe Prototype Pollution Vulnerability

Source: Hive Pro
(Published: 10 April 2026)
Threat actors are actively exploiting a critical Adobe prototype pollution vulnerability to execute arbitrary code in affected environments. Read more.


CPU-Z Trojan Delivers STX RAT and PureLogs Data Exfiltration

Source: Deception Pro
(Published: 11 April 2026)
A supply chain attack involving trojanized CPU-Z software installs STX RAT and PureLogs to exfiltrate sensitive data from infected systems. Read more.


Healthcare in the Crosshairs: Iran-Linked Cyber Threats

Source: PolySwarm
(Published: 12 April 2026)
Iran-linked cyber operations are increasingly targeting healthcare organizations and supply chains, raising risks across hospitals and medical infrastructure. Read more.


CyberAv3ngers Exploit Internet-Exposed PLCs in the US

Source: Hive Pro
(Published: 12 April 2026)
Iranian-affiliated CyberAv3ngers are targeting exposed PLC systems in the US to disrupt industrial control environments. Read more.


108 Chrome Extensions Linked to Data Exfiltration and Session Theft via Shared C2 Infrastructure

Source: Socket
(Published: 13 April 2026)
Socket’s Threat Research Team identified 108 malicious Chrome extensions operating as a coordinated campaign under a shared C2 infrastructure at `cloudapi[.]stream`. Read more.


Storm-2755 Payroll Fraud Campaign

Source: Hive Pro
(Published: 14 April 2026)
Storm-2755 is conducting a stealthy payroll diversion campaign targeting organizations in Canada. Read more.


The N8N N8mare Campaign

Source: Cisco Talos
(Published: 15 April 2026)
Threat actors are exploiting n8n automation workflows in a campaign dubbed N8mare to deploy malware and maintain persistence. Read more.


UAT-10362 Deploys LucidRook Malware

Source: Hive Pro
(Published: 15 April 2026)
UAT-10362 is deploying LucidRook malware in targeted attacks against Taiwanese non-governmental organizations. Read more.


CPU-Z Supply Chain Attack Delivers STX RAT

Source: CyberSec Sentinel
(Published: 16 April 2026)
A trojanized version of CPU-Z and HWMonitor software is being used to distribute STX RAT through a supply chain attack. Read more.


A Deep Dive Into Attempted Exploitation of CVE-2023-33538

Source: Unit 42 (Palo Alto Networks)
(Published: 16 April 2026)
Unit 42 researchers analyzed attempted exploitation of CVE-2023-33538 and linked the activity to botnet-style command injection campaigns targeting vulnerable WiFi routers. Read more.


Malicious dom-utils-lite NPM Package Installs SSH Backdoor

Source: SafeDep
(Published: 17 April 2026)
A malicious npm package installs an SSH backdoor, allowing attackers to maintain unauthorized access to compromised systems. Read more.


Lumma Stealer Infection With Sectop RAT and ArechClient2

Source: SANS ISC
(Published: 19 April 2026)
A multi-stage infection chain involving Lumma Stealer deploys additional payloads including Sectop RAT and ArechClient2 for expanded compromise. Read more.


MOIS-Linked Threat Actor Campaign Evolution

Source: DomainTools
(Published: 20 April 2026)
DomainTools researchers track evolving campaigns linked to MOIS-associated threat actors targeting geopolitical and infrastructure objectives. Read more.


Dark Storm Team and Middle East Cyber Conflict

Source: FalconFeeds
(Published: 21 April 2026)
The Dark Storm Team is actively participating in cyber operations tied to geopolitical tensions across the Middle East, targeting critical infrastructure. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

?
?

Security Signals (3/24/26-4/7/26)

?

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

?

March 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

This Edition’s Articles

Early April 2026 Cyber Threat Reports spotlights a fast-changing threat landscape shaped by Medusa ransomware activity, Axios and PyPI supply chain compromises, EvilTokens-driven BEC fraud, and malware campaigns abusing Claude Code, SaaS notifications, and Kubernetes exposure. This roundup reflects how quickly attackers are scaling social engineering, open-source compromise, credential theft, and cloud-focused intrusion techniques across real-world environments.

AppsFlyer Supply Chain Attack Analysis

Source: Reflectiz
(Published: 26 March 2026)
Researchers uncovered a supply chain attack targeting AppsFlyer, where malicious code was injected into third-party integrations to compromise downstream users. Read more.


Axios NPM Package Compromised: Supply Chain Attack Hits JavaScript HTTP Client

Source: Trend Micro
(Published: 28 March 2026)
A compromised Axios npm package introduced malicious code into a widely used JavaScript HTTP client, impacting downstream applications and developers. Read more.


The Axios Breach: When NPM Trust Becomes an APT Attack Vector

Source: PolySwarm
(Published: 31 March 2026)
The Axios compromise demonstrates how trusted open-source packages can be weaponized as advanced persistent threat vectors within software supply chains. Read more.


EvilTokens: An AI-Augmented Phishing-as-a-Service for Automating BEC Fraud (Part 2)

Source: Sekoia
(Published: 01 April 2026)
EvilTokens is an AI-augmented phishing-as-a-service platform designed to automate business email compromise attacks and streamline credential harvesting operations. Read more.


BYOVD Ransomware Attacks Now Capable of Defeating Every Major EDR Product

Source: CyberSec Sentinel
(Published: 01 April 2026)
Threat actors are increasingly leveraging bring-your-own-vulnerable-driver techniques to bypass endpoint detection and response solutions across major security platforms. Read more.


Supply Chain Attacks Surge in March 2026

Source: Zscaler
(Published: 01 April 2026)
Researchers observed a significant increase in supply chain attacks throughout March 2026, targeting open-source ecosystems and developer pipelines. Read more.


ClickFix Detection With YARA Rules

Source: ReversingLabs
(Published: 01 April 2026)
ReversingLabs developed YARA-based detection techniques to identify ClickFix-related malware activity across compromised systems. Read more.


NightSpire Ransomware Analysis

Source: Huntress
(Published: 02 April 2026)
NightSpire ransomware has emerged as a new threat, using multi-stage execution and stealthy techniques to evade detection and encrypt victim systems. Read more.


CrystalX RAT With Prankware Features

Source: Kaspersky Securelist
(Published: 02 April 2026)
Researchers identified CrystalX RAT, a remote access trojan that combines espionage capabilities with disruptive prankware features targeting victims. Read more.


Iran, US, and Israel Cyberwar Analysis 2026

Source: Seqrite
(Published: 02 April 2026)
Analysts highlight escalating cyber conflict activity involving Iran, the United States, and Israel, with increased targeting of critical infrastructure and government entities. Read more.


The Axios Breach: Plain Crypto JS Compromises Packages

Source: Resecurity
(Published: 02 April 2026)
A supply chain malware incident involving compromised crypto libraries demonstrates how attackers can poison widely used packages to distribute malicious code. Read more.


Hermes PyPI Package Analysis

Source: JFrog Security Research
(Published: 02 April 2026)
JFrog researchers analyzed a malicious PyPI package named Hermes that steals sensitive data from AI-related workflows and developer environments. Read more.


A Technique-Based Approach to Hunting Web-Delivered Malware

Source: Censys
(Published: 02 April 2026)
Researchers outline a technique-driven methodology for detecting and tracking malware delivered via web-based attack chains. Read more.


Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads

Source: Trend Micro
(Published: 03 April 2026)
A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code, which threat actors rapidly weaponized to distribute Vidar and GhostSocks malware via fake GitHub repositories. Read more.


Weaponizing SaaS Notification Pipelines

Source: Cisco Talos
(Published: 03 April 2026)
Threat actors are abusing SaaS notification systems to deliver malicious payloads and bypass traditional security controls. Read more.


ComfyUI Servers Abused in Cryptomining Proxy Botnet

Source: Censys
(Published: 03 April 2026)
Exposed ComfyUI servers are being leveraged as part of a cryptomining proxy botnet, enabling attackers to route malicious traffic through compromised infrastructure. Read more.


Reddit and TradingView Lures Lead to Vidar and Amos Stealers

Source: HexaStrike
(Published: 03 April 2026)
Threat actors are using Reddit and TradingView-themed lures to distribute Vidar and Amos stealer malware to unsuspecting users. Read more.


Team PCP Strikes Again: Telnyx Library Supply Chain Compromise

Source: JFrog Security Research
(Published: 03 April 2026)
Threat actor Team PCP continues supply chain attacks by compromising a widely used Telnyx library to inject malicious functionality. Read more.


CIFRAT Malware Analysis

Source: CERT Polska
(Published: 03 April 2026)
CERT Polska analyzed CIFRAT malware, highlighting its modular design and capabilities for credential theft and remote control. Read more.


Axios Supply Chain Compromise: Detection and Response

Source: Elastic Security Labs
(Published: 03 April 2026)
Elastic provides detection strategies and telemetry insights for identifying malicious activity stemming from the Axios npm supply chain compromise. Read more.


The Scanner Was the Weapon: DevSecOps Supply Chain Attacks

Source: CloudSEK
(Published: 03 April 2026)
CloudSEK documents long-term supply chain attacks targeting DevSecOps infrastructure through malicious scanning tools and automation pipelines. Read more.


Contagious Interview Campaign Spreads Across 5 Ecosystems

Source: Socket
(Published: 04 April 2026)
The Contagious Interview campaign has expanded across multiple software ecosystems, distributing malicious packages designed to steal credentials and deploy backdoors. Read more.


Malicious Hermes PyPI Package Steals AI Conversation Data

Source: SafeDep
(Published: 04 April 2026)
A malicious PyPI package disguised as Hermes has been discovered stealing sensitive AI-generated conversation data from developers. Read more.


Modern Kubernetes Threat Landscape

Source: Unit 42 (Palo Alto Networks)
(Published: 04 April 2026)
Unit 42 outlines evolving threats targeting Kubernetes environments, including misconfigurations, exposed services, and supply chain vulnerabilities. Read more.


DPRK Malware: Modularity, Diversity, and Functional Specialization

Source: DomainTools
(Published: 04 April 2026)
Researchers detail how DPRK-linked malware ecosystems are evolving with modular architectures and specialized tooling for targeted campaigns. Read more.


Tax Season 2026: Cybercriminal Campaign Preparation

Source: Check Point
(Published: 04 April 2026)
Cybercriminals are preparing tax-themed phishing campaigns months in advance, leveraging seasonal lures to maximize victim engagement. Read more.


Tycoon 2FA Infrastructure Update Following Global Takedown

Source: eSentire
(Published: 04 April 2026)
Threat actors behind Tycoon 2FA phishing infrastructure have adapted their operations following disruption efforts by global law enforcement coalitions. Read more.


Anthropic Claude Code Leak: Security Implications

Source: Zscaler
(Published: 04 April 2026)
Zscaler analyzes the security risks introduced by the Claude Code leak and how attackers are leveraging it in active campaigns. Read more.


A Little Bit Pivoting: What Web Shells Are Attackers Looking For

Source: SANS ISC
(Published: 05 April 2026)
Attackers are actively scanning for specific web shells that enable lateral movement and pivoting within compromised environments. Read more.


Malicious Strapi Plugin Deploys Command-and-Control Agent

Source: SafeDep
(Published: 05 April 2026)
A malicious npm plugin targeting Strapi deployments installs a command-and-control agent to maintain persistence within compromised environments. Read more.


Qilin Ransomware EDR Killer Analysis

Source: Cisco Talos
(Published: 05 April 2026)
Cisco Talos examines how Qilin ransomware incorporates EDR-killing techniques to disable security defenses prior to encryption. Read more.


Fake Installers Deliver Monero Mining Malware

Source: Elastic Security Labs
(Published: 05 April 2026)
Elastic researchers identified campaigns distributing fake software installers that deploy Monero cryptomining malware on infected systems. Read more.


Axios NPM Supply Chain Compromise Analysis

Source: Datadog Security Labs
(Published: 05 April 2026)
Datadog researchers provide detailed analysis of the Axios npm compromise and its impact on developer ecosystems and production environments. Read more.


Storm-1175 Targets Vulnerable Web-Facing Assets in Medusa Ransomware Operations

Source: Microsoft
(Published: 06 April 2026)
Microsoft observed Storm-1175 conducting high-tempo ransomware operations by exploiting vulnerable internet-facing assets to deploy Medusa ransomware. Read more.


Business Email Compromise Fraud Becomes More Accessible

Source: Cisco Talos
(Published: 06 April 2026)
The democratization of business email compromise is lowering the barrier to entry, enabling more threat actors to launch sophisticated fraud campaigns. Read more.


Understanding the Axios NPM Compromise

Source: Endor Labs
(Published: 06 April 2026)
Endor Labs examines how the Axios compromise unfolded and what it reveals about modern supply chain attack techniques. Read more.


Phantom Stealer: Credential Theft Campaign Analysis

Source: Group-IB
(Published: 06 April 2026)
Phantom Stealer is being distributed through phishing campaigns to harvest credentials and sensitive user data across multiple platforms. Read more.


Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do

Source: Trend Micro
(Published: 07 April 2026)
Threat actors continue to exploit the Claude Code packaging error as a lure, distributing Vidar, GhostSocks, and PureLog stealer malware through malicious GitHub releases. Read more.


Cybersecurity Advisory AA26-097A

Source: CISA
(Published: 07 April 2026)
CISA released advisory AA26-097A detailing ongoing threat activity and providing guidance for detecting and mitigating active cyber threats affecting organizations. Read more.


Mamont Banking Trojan: Android Malware Analysis

Source: NCC Group
(Published: 07 April 2026)
NCC Group analyzes Mamont, an Android banking trojan designed to steal financial data and credentials from infected mobile devices. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

?

How big are your threat data gaps?

See for yourself.

?

Security Signals (3/10/24-3/24/26)

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

February 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

This Edition’s Articles

Late March 2026 Cyber Threat Reports captures a surge in real-world attacks – from ClickFix and Agent Tesla campaigns to MuddyWater activity and Trivy supply chain compromise impacting CI/CD pipelines. This cycle highlights the growing abuse of trusted platforms like GitHub, Microsoft Teams, and browser extensions, alongside AI-assisted phishing, credential theft, and ransomware operations moving faster and scaling wider across enterprise environments.

Phishers hide scam links with IPv6 trick in “free toothbrush” emails

Source: Malwarebytes
(Published: 11 March 2026)
United Healthcare impersonators are using an IPv6 trick to hide the real destination of phishing links in emails promising free Oral-B toothbrushes. Read more.


Evil evolution: ClickFix and macOS infostealers

Source: Sophos
(Published: 11 March 2026)
Across three recent campaigns, Sophos X-Ops notes shifts in both lures and malware capabilities, as threat actors leveraging ClickFix techniques increasingly target macOS users with infostealers. Read more.


Ransomware TTPs Shifting in the Threat Landscape

Source: Google Cloud
(Published: 12 March 2026)
Ransomware operators are continuing to evolve their tactics, techniques, and procedures to improve access, persistence, and monetization across targeted environments. Read more.


Moving up the Assemblyline: Exposing malicious code in browser extensions

Source: Red Canary
(Published: 12 March 2026)
Browser extensions are ubiquitous, offering users enhanced functionality and customization. Read more.


Fileless Multi-Stage Remcos RAT: From Phishing to Memory

Source: Trellix
(Published: 12 March 2026)
Trellix researchers detail a fileless multi-stage attack chain delivering Remcos RAT entirely in memory to evade traditional detection mechanisms. Read more.


Fake ChatGPT Invites Target Users With Malware

Source: CyberPress
(Published: 13 March 2026)
Threat actors are distributing fake ChatGPT invitation links to lure victims into downloading malware disguised as legitimate AI tools. Read more.


GIBCrypto Ransomware With Snake Keylogger Connection

Source: K7 Computing
(Published: 13 March 2026)
Researchers identified GIBCrypto ransomware as a destructive threat linked to Snake keylogger activity and capable of significant data loss. Read more.


The Rise of Fake Shipment Tracking Scams in MEA

Source: Group-IB
(Published: 13 March 2026)
Every day, billions of people rely on postal and courier services to deliver everything from handwritten letters to high value online orders. Read more.


Inside Keitaro Abuse: A Persistent Stream of AI-Driven Investment Scams

Source: Infoblox
(Published: 13 March 2026)
Infoblox researchers identified ongoing abuse of Keitaro traffic distribution systems to deliver AI-driven investment scams targeting unsuspecting users. Read more.


Slopoly Backdoor Powers Interlock Ransomware Intrusion

Source: Hive Pro
(Published: 14 March 2026)
Threat actors are using the Slopoly backdoor, enhanced with AI-assisted techniques, to support Interlock ransomware intrusion campaigns. Read more.


Asyncing Feeling: When Your Download Comes With Something Extra

Source: NCC Group
(Published: 14 March 2026)
NCC Group researchers uncovered a malware campaign where compromised downloads include hidden payloads that execute during installation. Read more.


ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push

Source: StepSecurity
(Published: 14 March 2026)
The StepSecurity threat intelligence team was the first to discover and report on an ongoing campaign – which we are tracking as ForceMemo – in which an attacker is compromising hundreds of GitHub accounts and injecting identical malware into hundreds of Python repositories. Read more.


Scarface Stealer: An In-Depth Analysis

Source: SonicWall
(Published: 15 March 2026)
SonicWall researchers analyze Scarface Stealer, a credential harvesting malware designed to extract sensitive information from infected systems. Read more.


Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys

Source: StepSecurity
(Published: 15 March 2026)
The StepSecurity threat intelligence team discovered that dev-protocol – a verified GitHub organization with 568 followers belonging to a legitimate Japanese DeFi project – has been hijacked and is now being used to distribute malicious Polymarket trading bots. Read more.


AI-Assisted Phishing Campaign Exploits Browser Permissions to Capture Victim Data

Source: Cyble
(Published: 16 March 2026)
Cyble analyzes an AI-driven phishing campaign that abuses browser permissions to capture victims images and exfiltrate the data to attacker-controlled Telegram bots. Read more.


Boggy Serpens Threat Assessment

Source: Unit 42 (Palo Alto Networks)
(Published: 16 March 2026)
Unit 42 provides a detailed assessment of the Boggy Serpens threat group, including its tactics, infrastructure, and observed campaigns. Read more.


Web Shells, Tunnels, and Ransomware: Dissecting a Warlock Attack

Source: Trend Micro
(Published: 16 March 2026)
Warlock continues to enhance its attack chain with new tactics to improve persistence, lateral movement, and defense evasion using an expanded toolset: TightVNC, Yuze, and a persistent BYOVD technique leveraging the NSec driver. Read more.


Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat

Source: ReliaQuest
(Published: 17 March 2026)
Ransomware operator “LeakNet” is currently averaging about three victims per month, but it’s scaling up and shifting tactics. Read more.


MuddyWater APT Uses Tsundere Botnet and EtherHiding for C2

Source: eSentire
(Published: 17 March 2026)
The MuddyWater threat group is leveraging the Tsundere botnet and EtherHiding techniques to obscure command-and-control infrastructure. Read more.


PureLog Stealer Delivered Through Copyright Lures

Source: Trend Micro
(Published: 17 March 2026)
Attackers are using copyright infringement lures to deliver a multi-stage infection chain that ultimately installs the PureLog information stealer. Read more.


Trivy Supply Chain Attack: What You Need to Know

Source: Aqua Security
(Published: 18 March 2026)
A supply chain attack targeting Trivy introduced malicious code into CI/CD pipelines through compromised GitHub Actions workflows. Read more.


Data Exfiltration Infrastructure Exposed

Source: Huntress
(Published: 18 March 2026)
Huntress uncovered a threat actor infrastructure used for large-scale data exfiltration operations across compromised environments. Read more.


AI-Enhanced Ransomware Attacks Leveraging Slopoly

Source: IBM X-Force
(Published: 18 March 2026)
IBM X-Force reports that threat actors are incorporating AI capabilities into ransomware campaigns to improve targeting and execution efficiency. Read more.


Microsoft Teams Social Engineering Delivers A0Backdoor Malware

Source: Hive Pro
(Published: 19 March 2026)
Threat actors are using Microsoft Teams as a delivery mechanism for A0Backdoor malware through social engineering tactics. Read more.


WebRTC Skimmer Targets E-Commerce Platforms

Source: Sansec
(Published: 19 March 2026)
Researchers uncovered a WebRTC-based skimmer that captures payment data from compromised e-commerce sites in real time. Read more.


Fake Telegram Malware Campaign Uses Multi-Stage Loader

Source: K7 Computing
(Published: 20 March 2026)
A multi-stage malware campaign is leveraging fake Telegram applications distributed via typosquatted domains to infect users. Read more.


PixRevolution: Android Trojan Targets Brazil’s PIX Payment System

Source: Zimperium
(Published: 20 March 2026)
PixRevolution is an Android banking trojan that hijacks Brazil’s PIX payment system in real time to steal funds from victims. Read more.


ROADK1LL: A WebSocket-Based Pivoting Implant

Source: Blackpoint Cyber
(Published: 21 March 2026)
ROADK1LL is a post-exploitation implant that uses WebSocket communication to pivot within compromised networks and maintain persistence. Read more.


TeamPCP Expands Supply Chain Compromise From Trivy to Checkmarx

Source: Sysdig
(Published: 22 March 2026)
The TeamPCP threat actor has expanded its supply chain attack operations by targeting additional CI/CD tools and GitHub Actions workflows. Read more.


Perseus DTO Malware: Stealthy Data Theft Capabilities

Source: ThreatFabric
(Published: 22 March 2026)
Perseus DTO malware enables attackers to silently capture sensitive data while maintaining persistence on infected systems. Read more.


Bucklog: Kubernetes-Focused Threat Activity Observed in the Wild

Source: GreyNoise
(Published: 23 March 2026)
GreyNoise observed active exploitation attempts targeting Kubernetes environments associated with a campaign dubbed Bucklog. Read more.


CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem

Source: StepSecurity
(Published: 23 March 2026)
Following Trivy’s compromise, StepSecurity’s AI Package Analyst flagged suspicious new releases across multiple npm scopes – revealing CanisterWorm, a self-propagating npm worm deployed by the TeamPCP threat actor. Read more.


VoidStealer Bypasses ABE Protections

Source: Gen Digital
(Published: 24 March 2026)
Researchers identified VoidStealer malware capable of bypassing Application Bound Encryption protections to extract sensitive credentials. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

?

How big are your threat data gaps?

See for yourself.

?

Security Signals (2/24/26-3/10/26)

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

February 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

This Edition’s Articles

Early March 2026 Cyber Threat Reports highlights fast-moving threats shaping the current landscape, from Agent Tesla, LockBit, MuddyWater, and APT37 to attacks targeting AWS credentials, Android devices, AI development tools, and enterprise SaaS access. This roundup reflects the real-world pace of phishing, credential theft, supply chain compromise, exposed infrastructure abuse, and ransomware-driven operations affecting defenders right now.

Punchbowl Phishing Attack Explained: How Digital Invites Are Used to Steal Credentials

Source: Cofense
(Published: 24 February 2026)
In today’s digital age, receiving online invitations to events has become commonplace. Read more.


Open Redirects: A Forgotten Vulnerability

Source: SANS Internet Storm Center
(Published: 24 February 2026)
Open redirect vulnerabilities often receive less attention than other web security issues, but they can still be abused in phishing campaigns and malware delivery chains. Read more.


Abusing Windows File Explorer and WebDAV for Malware Delivery

Source: Cofense
(Published: 25 February 2026)
Cofense Intelligence has been tracking how threat actors are abusing Windows File Explorer’s ability to retrieve remote files over Web-based Distributed Authoring and Versioning (WebDAV), and HTTP-based file management protocol, to trick victims into downloading malware. Read more.


Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains – Part 1

Source: Abstract Security
(Published: 25 February 2026)
The ASTRO team has been actively tracking Contagious Interview techniques that abuse task auto-execution in integrated development environments (IDEs) such as Microsoft Visual Studio Code (VSCode) and Cursor to deliver malware. Read more.


Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign

Source: Google Cloud Blog
(Published: 25 February 2026)
Last week, Google Threat Intelligence Group (GTIG), Mandiant, and partners took action to disrupt a global espionage campaign targeting telecommunications and government organizations in dozens of nations across four continents. Read more.


OCRFix: Botnet Trojan delivered through ClickFix and EtherHiding

Source: CYJAX
(Published: 25 February 2026)
During routine analysis, CYJAX identified a typosquatting phishing campaign which impersonated the Optical Character Recognition (OCR) tool Tesseract OCR. Read more.


Reynolds Ransomware: BYOVD Evasion & NSecKrnl Abuse

Source: Brandefense
(Published: 25 February 2026)
A new ransomware group tracked as “Reynolds” emerged in February 2026 and is reported to use Bring Your Own Vulnerable Driver (BYOVD) technique to disable security controls before encryption, thereby significantly increasing its chances of success even in well-equipped environments. Read more.


Unmasking Agent Tesla: A Deep Dive Into a Multi-Stage Campaign

Source: Fortinet
(Published: 25 February 2026)
Agent Tesla remains one of the most persistent threats in the cyber landscape today, continuing to evolve through multi-stage delivery chains and stealthy credential theft techniques. Read more.


[Op Report] Velvet Tempest linked to ClickFix campaigns for Termite Ransomware, HoK Activity Observed

Source: Deception.Pro
(Published: 26 February 2026)
During a 12-day Deception.Pro operation, researchers observed a high-severity, multi-stage intrusion chain that began with malvertising and a ClickFix-style fake CAPTCHA. Read more.


Free Games, Costly Consequences

Source: G DATA Security Blog
(Published: 26 February 2026)
PiviGames, a popular Spanish gaming platform is well-known in the gaming community for providing download links to pirated PC games. Read more.


GTFire Phishing Scheme Targets Organizations

Source: Group-IB
(Published: 26 February 2026)
Researchers uncovered a phishing campaign dubbed GTFire that leverages convincing login pages and infrastructure designed to harvest credentials from targeted organizations. Read more.


Henry IV, Hotspur, Hal, and hallucinations

Source: Cisco Talos
(Published: 26 February 2026)
Welcome to this week’s edition of the Threat Source newsletter. Read more.


Malicious Go “crypto” Module Steals Passwords and Deploys Rekoobe Backdoor

Source: Socket
(Published: 26 February 2026)
Socket’s Threat Research Team uncovered a malicious Go module, github[.]com/xinfeisoft/crypto, that imitates the legitimate golang[.]org/x/crypto codebase but inserts a backdoor in ssh/terminal/terminal.go. Read more.


New Dohdoor malware campaign targets education and health care

Source: Cisco Talos
(Published: 26 February 2026)
Cisco Talos discovered an ongoing malicious campaign since at least as early as December 2025 by a threat actor we track as “UAT-10027,” delivering a previously undisclosed backdoor dubbed “Dohdoor.”. Read more.


Novel DPRK stager using Pastebin and text steganography

Source: kmsec.uk
(Published: 26 February 2026)
This is a quick one as FAMOUS CHOLLIMA has been keeping me busy this week by testing Google Drive as a stager and my longer write-up on tracking their IP addresses through temporary mailboxes. Read more.


PlugX Meeting Invitation via MSBuild and GDATA

Source: LAB52
(Published: 26 February 2026)
In relation to the latest variant of the PlugX RAT executed by STATICPLUGIN analyzed by IIJ-SECT, LAB52 aims to complement this information with additional observed deployment activity and encryption characteristics in samples analyzed by this team. Read more.


ShinyHunters Fast-Tracks SaaS Access With Subdomain Impersonation

Source: ReliaQuest
(Published: 26 February 2026)
Researchers observed threat actor ShinyHunters leveraging subdomain impersonation techniques to accelerate access to SaaS environments and improve the credibility of phishing lures. Read more.


VEN0m Ransomware: DFIR Analysis, Detection Engineering & Key Recovery

Source: Ransom-ISAC
(Published: 26 February 2026)
On February 23, 2026, Tammy Harper raised with the Ransom-ISAC community of a new ransomware payload utilising User Access Control (UAC) bypass and Bring Your Own Vulnerable Driver (BYOVD) techniques. Read more.


APT36 : Multi-Vector Execution Malware Campaign Targeting Indian Government Entities

Source: CYFIRMA
(Published: 27 February 2026)
CYFIRMA has identified a targeted malware campaign attributed to the Pakistan-aligned threat actor Transparent Tribe (also known as APT36). Read more.


Contagious Interview Campaign Abusing VSCode Distributed on Github

Source: ENKI WhiteHat
(Published: 27 February 2026)
We recently identified multiple instances of malware on Github that abuse VS Code automation features. Read more.


Fake Zoom and Google Meet Scams Install Teramind

Source: Malwarebytes
(Published: 27 February 2026)
Researchers identified a campaign using fake Zoom and Google Meet downloads that silently install the Teramind monitoring tool to spy on victims. Read more.


Hook, line, and vault: A technical deep dive into the 1Phish kit

Source: Datadog Security Labs
(Published: 27 February 2026)
The 1Phish kit evolved between September 2025 and February 2026 from a basic credential harvester into an MFA-aware, multi-stage phishing kit targeting 1Password users. Read more.


Inside a Fake Google Security Check That Becomes a Browser RAT

Source: Malwarebytes
(Published: 27 February 2026)
A website disguised as a Google Account security check is distributing a browser-based remote access tool capable of surveillance and credential theft. Read more.


StegaBin: 26 Malicious npm Packages Use Pastebin Steganography to Deploy Multi-Stage Credential Stealer

Source: Socket
(Published: 27 February 2026)
Socket’s AI-powered threat detection systems identified 26 malicious npm packages published over a two-day period that deploy a multi-stage credential and secret harvesting operation targeting developers. Read more.


The ClawHavoc Campaign

Source: PolySwarm
(Published: 27 February 2026)
The ClawHavoc campaign exploited the permissive nature of ClawHub, the official marketplace for OpenClaw Skills, which are plugin packages that extend the open-source AI agent’s capabilities across automation, cryptocurrency monitoring, social media assistance, and productivity tasks. Read more.


Why Digital Squatting Still Works in 2026-And Why Defense Is So Hard

Source: LastPass
(Published: 27 February 2026)
Digital squatting and phishing are often treated as separate threat vectors, but they are deeply intertwined. Read more.


Zerobot Malware Targets n8n Automation Platform

Source: Akamai
(Published: 27 February 2026)
The Akamai SIRT discovered an ongoing Mirai-based malware campaign, dubbed Zerobot, targeting a variety of recent CVEs, including those affecting Tenda AC1206 routers and the n8n workflow automation platform. Read more.


A Fake FileZilla Site Hosts a Malicious Download

Source: Malwarebytes
(Published: 02 March 2026)
Attackers are distributing malware through a fake FileZilla website designed to trick users into downloading a malicious installer. Read more.


Exorcising Demons: Fake Tech Support Delivers Havoc Command and Control

Source: Huntress
(Published: 02 March 2026)
Fake browser alerts and tech support lures are being used to deliver the Havoc command-and-control framework through deceptive user prompts and staged execution chains. Read more.


Funnull Resurfaces: Exposing RingH23 Arsenal and MacCMS Supply Chain Attacks

Source: QiAnXin X Lab
(Published: 02 March 2026)
Funnull (Funnull Technology Inc.), also known as Fangneng CDN, is a Philippines-registered company that publicly claims to provide CDN services. Read more.


Iranian APT Activity During Geopolitical Escalation

Source: Nozomi Networks
(Published: 02 March 2026)
Researchers observed increased cyber activity linked to Iranian threat groups during escalating geopolitical tensions in the Middle East. Read more.


Oblivion RAT – An Android Spyware Platform With a Built-In APK Factory

Source: iVerify
(Published: 02 March 2026)
Oblivion RAT is a new Android remote access trojan sold as a malware-as-a-service (MaaS) platform on cybercrime networks for $300/month. Read more.


PromptSpy Android Malware Uses Generative AI

Source: PolySwarm
(Published: 02 March 2026)
PromptSpy is the first documented Android malware family to integrate generative AI, specifically Google’s Gemini, into its execution flow for dynamic, context-aware persistence. Read more.


SloppyLemming Deploys BurrowShell and Rust-Based RAT to Target Pakistan and Bangladesh

Source: Arctic Wolf
(Published: 02 March 2026)
Over the last 12 months, Arctic Wolf has been tracking an extensive cyber espionage campaign conducted by SloppyLemming, an India-nexus threat actor, targeting government entities and critical infrastructure operators in Pakistan and Bangladesh. Read more.


Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild

Source: Unit 42 (Palo Alto Networks)
(Published: 03 March 2026)
Large language models (LLMs) and AI agents are becoming deeply integrated into web browsers, search engines and automated content-processing pipelines. Read more.


Doppelganger RRN Disinformation Infrastructure Ecosystem

Source: DomainTools Intelligence
(Published: 04 March 2026)
Researchers identified a large disinformation infrastructure linked to the Doppelganger campaign that leverages cloned news domains and coordinated social amplification. Read more.


Fake Discount Scams Spread Across E-Commerce Platforms

Source: Guard.io
(Published: 04 March 2026)
Security researchers observed a wave of fake discount campaigns designed to lure users into phishing pages that harvest payment details and login credentials. Read more.


Fake FedEx Email Delivers Donut Malware

Source: SANS Internet Storm Center
(Published: 04 March 2026)
A phishing email impersonating FedEx delivery notifications is distributing malware using malicious attachments designed to trick recipients into executing embedded payloads. Read more.


Malicious NuGet Package Targets Stripe Developers

Source: ReversingLabs
(Published: 04 March 2026)
Researchers discovered a malicious NuGet package designed to target developers working with Stripe integrations and steal sensitive credentials. Read more.


SurxRAT Downloads Large LLM Module From Hugging Face

Source: Cyble
(Published: 04 March 2026)
Security researchers discovered SurxRAT downloading a large language model module from Hugging Face to enhance its command processing and evasion capabilities. Read more.


2026 Ransomware Cartelization: Qilin, LockBit, and Akira Convergence

Source: SecureBlink
(Published: 05 March 2026)
Researchers highlight increasing collaboration between ransomware groups including Qilin, LockBit, and Akira as part of a growing trend of ransomware cartelization. Read more.


ActiveMQ Exploit Deploys LockBit Ransomware

Source: CyberPress
(Published: 05 March 2026)
Threat actors are exploiting vulnerable Apache ActiveMQ servers to deploy LockBit ransomware in targeted intrusion campaigns. Read more.


Agent Tesla Campaign Evolves to Evade Detection

Source: CyberPress
(Published: 05 March 2026)
A new campaign distributing Agent Tesla malware is using updated delivery techniques and obfuscation to evade traditional detection mechanisms. Read more.


ZeroDayRAT Targets Mobile Devices

Source: CyberPress
(Published: 05 March 2026)
Researchers uncovered a new remote access trojan called ZeroDayRAT designed to target mobile devices and steal sensitive data. Read more.


Charming Kitten Activity Escalates in Iran-Israel Cyber Conflict

Source: FalconFeeds
(Published: 06 March 2026)
Researchers observed increased cyber activity linked to the Iranian threat group Charming Kitten amid escalating tensions in the Iran-Israel cyber conflict. Read more.


Inside a New Violetrat Campaign

Source: SonicWall
(Published: 06 March 2026)
Researchers uncovered a multi-stage malware campaign delivering Violetrat through layered payload execution designed to evade security detection. Read more.


Moonrise RAT: Emerging Remote Access Threat

Source: CyberSec Sentinel
(Published: 06 March 2026)
The Moonrise RAT malware family has emerged as a serious threat capable of persistent access, credential theft, and remote command execution. Read more.


TAXISPY RAT : Analysis of TaxiSpy RAT – Russian Banking – Focused Android Malware with Full Remote Control

Source: CYFIRMA
(Published: 06 March 2026)
This report analyzes a highly sophisticated Android Banking Trojan with integrated Remote Access Trojan (RAT) functionality, specifically targeting Russian financial institutions. Read more.


UnsolicitedBooker Deploys MarsSnake Against Telecom Providers

Source: CyberSec Sentinel
(Published: 06 March 2026)
A threat actor tracked as UnsolicitedBooker has been deploying the MarsSnake malware family against telecommunications organizations. Read more.


Hydra-Saiga: Covert Espionage and Infiltration of Critical Utilities

Source: VMRay
(Published: 07 March 2026)
Analysts detail a covert espionage campaign dubbed Hydra-Saiga that targets critical utility infrastructure with stealthy malware implants. Read more.


Iran-Linked Dust Specter Launches Cyberattack on Iraqi Officials

Source: Hive Pro
(Published: 07 March 2026)
Iranian-linked threat group Dust Specter conducted targeted cyber operations against Iraqi officials in a campaign involving credential harvesting and malware delivery. Read more.


Mercenary Akula’s Court-Themed Campaign Hits European Finance

Source: Hive Pro
(Published: 07 March 2026)
A campaign attributed to Mercenary Akula used court-themed lures to target financial institutions across Europe with phishing and malware payloads. Read more.


Operation Olalampo: MuddyWater Expands Campaign Across MENA

Source: Hive Pro
(Published: 08 March 2026)
The MuddyWater threat group expanded its Operation Olalampo campaign targeting organizations across the Middle East and North Africa region. Read more.


APT37 Adds New Capabilities to Target Air-Gapped Networks

Source: Zscaler
(Published: 09 March 2026)
Researchers report that North Korean threat group APT37 has developed new techniques for targeting air-gapped networks and sensitive systems. Read more.


Behind the console: Active phishing campaign targeting AWS console credentials

Source: Datadog Security Labs
(Published: 09 March 2026)
Datadog Security Research identified an active adversary-in-the-middle (AiTM) phishing campaign targeting AWS Console credentials. Read more.


Iranian APT MuddyWater Uses Dindoor Malware to Target U.S. Networks

Source: SOCRadar
(Published: 09 March 2026)
A recently uncovered cyber espionage campaign attributed to the Iranian state-linked threat group MuddyWater has drawn attention from security researchers after several organizations in the United States were compromised using newly observed malware. Read more.


Sandworm_MODE NPM Supply Chain Attack Targets AI Development Tools

Source: Hive Pro
(Published: 09 March 2026)
Researchers uncovered a supply chain attack on the NPM ecosystem targeting AI development tools and attributed to activity consistent with Sandworm operations. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

?

How big are your threat data gaps?

See for yourself.

?

Security Signals (2/10/26-2/24/26)

?

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

?

January 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

This Edition’s Articles

Late February 2026 Cyber Threat Reports spotlight fast-moving real-world attacks – from FortiGate access at scale and WebDAV delivery tricks to LockBit activity and Lazarus-linked Medusa ransomware. Themes this round: abuse of trusted software, exposed infrastructure exploitation, and phishing/credential theft feeding downstream operations.

Nation-State Actors Exploit Notepad++ Supply Chain

Source: Unit 42 (Palo Alto Networks)
(Published: 11 February 2026)
Between June and December 2025, the official hosting infrastructure for the text editor Notepad++ was compromised by a state-sponsored threat group known as Lotus Blossom. Read more.


OysterLoader Unmasked: The Multi-Stage Evasion Loader

Source: Sekoia.io Blog
(Published: 12 February 2026)
OysterLoader, also known as Broomstick and CleanUp, is a malware developed in C++, composed of multiple stages, belonging to the loader (A.k.a.: downloader) malware family. Read more.


Unpacking the New “Matryoshka” ClickFix Variant: Typosquatting Campaign Delivers macOS Stealer

Source: Intego Mac Security Blog
(Published: 12 February 2026)
Intego Antivirus Labs is tracking an evolution of the “ClickFix” social engineering campaign targeting macOS users. Read more.


GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use

Source: Google Cloud Blog
(Published: 12 February 2026)
In the final quarter of 2025, Google Threat Intelligence Group (GTIG) observed threat actors increasingly integrating artificial intelligence (AI) to accelerate the attack lifecycle, achieving productivity gains in reconnaissance, social engineering, and malware development. Read more.


LockBit strikes with new 5.0 version, tastargeting Windows, Linux and ESXI systems

Source: Acronis
(Published: 12 February 2026)
The Acronis Threat Research Unit (TRU) analyzed the latest version of LockBit ransomware (version 5), which targets Windows, Linux and ESXi systems, and shares some similarities with the previous version 4. Read more.


Fake CAPTCHA in Action

Source: CERT Polska
(Published: 12 February 2026)
CERT Polska observed an ongoing campaign leveraging fake CAPTCHA verification pages to deliver malware to unsuspecting users. Read more.


RenEngine Campaign with HijackLoader, Lumma and ACR Stealer

Source: Securelist (Kaspersky)
(Published: 13 February 2026)
Researchers uncovered a multi-stage malware campaign distributing HijackLoader alongside Lumma and ACR Stealer payloads through compromised websites and phishing vectors. Read more.


Odyssey Stealer: macOS Crypto-Stealing Operation

Source: Censys
(Published: 14 February 2026)
Researchers identified Odyssey Stealer, a macOS-focused malware operation targeting cryptocurrency users through credential harvesting and wallet theft. Read more.


Multiple Threat Actors Rapidly Exploit React2Shell: A Case Study of Active Compromise

Source: JPCERT/CC
(Published: 16 February 2026)
JPCERT/CC observed multiple threat actors actively exploiting the React2Shell vulnerability shortly after disclosure, demonstrating rapid weaponization timelines. Read more.


AI LLM-Generated Malware Used to Exploit React2Shell

Source: Darktrace
(Published: 16 February 2026)
Darktrace researchers identified malware generated with assistance from large language models being used in exploitation attempts targeting React2Shell vulnerabilities. Read more.


CVE-2026-1731: BeyondTrust Exploitation Wave

Source: Darktrace
(Published: 16 February 2026)
Darktrace observed active exploitation attempts targeting CVE-2026-1731, highlighting rapid attacker adoption following vulnerability disclosure. Read more.


Shadow Campaigns Show Evidence of Global Espionage Using ShadowGuard Rootkit

Source: PolySwarm
(Published: 17 February 2026)
Researchers uncovered coordinated espionage activity leveraging the ShadowGuard rootkit to maintain stealthy long-term access across targets worldwide. Read more.


LATAM Businesses Hit by XWorm via Fake Financial Receipts: Full Campaign Analysis

Source: ANY.RUN
(Published: 17 February 2026)
Malware campaigns targeting Latin America (LATAM) are evolving. Read more.


From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day

Source: Google Cloud Blog
(Published: 17 February 2026)
Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769, with a CVSSv3.1 score of 10.0. Read more.


Spam Campaign Abuses Atlassian Jira, Targets Government and Corporate Entities

Source: Trend Micro
(Published: 17 February 2026)
Threat actors used Atlassian Jira Cloud and its connected email system to run automated spam campaigns, effectively bypassing traditional email security by abusing the strong domain reputation of Atlassian Jira Cloud products. Read more.


Spam Campaign Abuses Atlassian Jira, Targets Government and Corporate Entities

Source: Trend Micro
(Published: 17 February 2026)
Threat actors used Atlassian Jira Cloud and its connected email system to run automated spam campaigns, effectively bypassing traditional email security by abusing the strong domain reputation of Atlassian Jira Cloud products. Read more.


Invitation to Trouble: The Rise of Calendar Phishing Attacks

Source: Cofense Blog
(Published: 17 February 2026)
Before you click “Accept” on calendar invites, think twice – it could be a phishing scheme. Read more.


Banners, Bots and Butchers: An Automated Long Con Targeting Japan, Asia, and Beyond

Source: Infoblox Blog
(Published: 17 February 2026)
Over the past few months, we investigated cryptocurrency investment scam campaigns that combined two distinct fraud models: malvertising, which typically directs victims to fake investment platforms, and pig butchering, a scam that relies heavily on social engineering to gradually extract larger and larger sums of money from each victim over time. Read more.


Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets

Source: Securelist (Kaspersky)
(Published: 17 February 2026)
Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets. Read more.


UNC1069’s Social Engineering Operations Focused on Crypto Sector

Source: Hive Pro
(Published: 17 February 2026)
UNC1069, a financially motivated North Korea-linked threat actor, conducted a targeted intrusion against a financial technology (FinTech) entity in the cryptocurrency sector. Read more.


Operation MacroMaze: New APT28 Campaign Using Basic Tooling and Legit Infrastructure

Source: Lab52
(Published: 18 February 2026)
Researchers documented a new APT28 campaign leveraging legitimate services and simple tooling to evade traditional detection mechanisms. Read more.


Tech Impersonators, ClickFix and macOS Infostealers

Source: Datadog Security Labs
(Published: 18 February 2026)
Datadog researchers analyzed campaigns using impersonation techniques and ClickFix lures to distribute macOS infostealer malware. Read more.


Job scam uses fake Google Forms site to harvest Google logins

Source: Malwarebytes
(Published: 18 February 2026)
As part of our investigation into a job-themed phishing campaign, we came across several suspicious URLs that all looked like this:. Read more.


Malicious Chrome Extension Steals Meta Business Manager Exports and TOTP 2FA Seeds

Source: Socket
(Published: 19 February 2026)
Researchers discovered a malicious Chrome extension capable of exfiltrating Meta Business Manager data alongside time-based one-time password authentication seeds. Read more.


AI-augmented threat actor accesses FortiGate devices at scale

Source: AWS Security Blog
(Published: 20 February 2026)
Commercial AI services are enabling even unsophisticated threat actors to conduct cyberattacks at scale – a trend Amazon Threat Intelligence has been tracking closely. Read more.


UNC1069 Uses New Tools to Target Crypto Entities

Source: PolySwarm
(Published: 20 February 2026)
A targeted intrusion into a FinTech entity in the cryptocurrency sector was attributed to UNC1069, a North Korea-nexus financially motivated threat actor. Read more.


Apache ActiveMQ Exploit Leads to LockBit Ransomware

Source: The DFIR Report
(Published: 23 February 2026)
This intrusion began in mid-February 2024 after a threat actor exploited a vulnerability (CVE-2023-46604) on an exposed Apache ActiveMQ server. Read more.


North Korean Lazarus Group Now Working With Medusa Ransomware

Source: SECURITY.COM
(Published: 24 February 2026)
North Korean state-backed attackers are now using the Medusa ransomware and are continuing to mount extortion attacks on the U.S. healthcare sector. Read more.


1Campaign: A New Cloaking Platform Helping Attackers Abuse Google Ads

Source: Varonis
(Published: 24 February 2026)
1Campaign is a new cloaking platform that helps attackers bypass Google Ads screening, evade security researchers, and keep phishing and crypto drainer pages online longer. Read more.

Want more articles? Check out the previous edition of Security Signals here. 

?

How big are your threat data gaps?

See for yourself.

?

Security Signals (1/27/26-2/10/26)

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

January 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

This Edition’s Articles

Early February 2026 Cyber Threat Reports capture the momentum behind real-world attacks: APT28 exploiting CVE-2026-21509, DynoWiper destructive activity, and ransomware tradecraft tied to LockBit/Black Basta, alongside infostealer- and phishing-driven abuse of platforms like Google Cloud, WordPress, and macOS/Android.

New Year, New Sector: Transparent Tribe Targets India’s Startup Ecosystem

Source: Acronis Threat Research Unit
(Published: 27 January 2026)
Transparent Tribe, a well-known APT group, has expanded its targeting to India’s rapidly growing startup ecosystem. Read more.


The Pyrat Code: Python-Based RAT and Its Internals

Source: K7 Labs
(Published: 28 January 2026)
Pyrat is a Python-based Remote Access Trojan that has been observed in multiple attack campaigns targeting Windows systems. Read more.


Interlock Ransomware: New Techniques, Same Old Tricks

Source: Fortinet Threat Research
(Published: 27 January 2026)
Interlock ransomware operators continue to refine their tooling while relying on well-established intrusion techniques. Read more.


No Place Like Home Network: Disrupting the World’s Largest Residential Proxy Network

Source: Google Cloud Blog
(Published: 28 January 2026)
This week Google and partners took action to disrupt what we believe is one of the largest residential proxy networks in the world, the IPIDEA proxy network. Read more.


Shadow Campaigns: Uncovering Global Espionage

Source: Palo Alto Networks Unit 42
(Published: 28 January 2026)
Unit 42 researchers have uncovered a set of previously undocumented campaigns conducting cyber espionage across multiple regions. Read more.


PureRAT: Attacker Now Using AI to Build Toolset

Source: SECURITY.COM
(Published: 28 January 2026)
A Vietnamese threat actor is likely using AI to author code powering an ongoing phishing campaign delivering the PureRAT malware and other payloads. Read more.


TAMECAT – Analysis of an Iranian PowerShell-Based Backdoor

Source: Pulsedive Threat Research
(Published: 29 January 2026)
Artifacts from our analysis are available on our GitHub. Read more.


Meet IClickFix: a widespread WordPress-targeting framework using the ClickFix tactic

Source: Sekoia.io
(Published: 29 January 2026)
In November 2025, during our threat hunting routine for unveiling emerging adversary clusters, TDR analysts identified a widespread malware distribution campaign leveraging the ClickFix social engineering tactic through a Traffic Distribution System (TDS). Read more.


Dissecting UAT-8099: New persistence mechanisms and regional focus

Source: Cisco Talos Intelligence Blog
(Published: 29 January 2026)
Cisco Talos has identified a new campaign by UAT-8099, active from late 2025 to early 2026, that is targeting vulnerable Internet Information Services (IIS) servers across Asia with a specific focus on victims in Thailand and Vietnam. Read more.


RedKitten: AI-accelerated campaign targeting Iranian protests

Source: HarfangLab
(Published: 29 January 2026)
RedKitten is a newly identified campaign targeting Iranian interests, likely including non-governmental organizations and individuals involved in documenting recent human rights abuses, first observed in early January 2026. Read more.


Honeymyte Updates: CoolClient Uses Browser Stealers and Scripts

Source: Securelist (Kaspersky)
(Published: 29 January 2026)
We continue to track the Honeymyte activity cluster and recently observed new updates to the CoolClient malware family. Read more.


New ShadowSyndicate Infrastructure Identified

Source: Group-IB
(Published: 29 January 2026)
Group-IB researchers have identified new infrastructure linked to the ShadowSyndicate cybercriminal group. Read more.


Silent Brothers | Ollama Hosts Form Anonymous AI Network Beyond Platform Guardrails

Source: SentinelOne
(Published: 29 January 2026)
A joint research project between SentinelLABS and Censys reveals that open-source AI deployment has created an unmanaged, publicly accessible layer of AI compute infrastructure spanning 175,000 hosts worldwide, operating outside the guardrails and monitoring systems that platform providers implement by default. Read more.


The Rise of Arsink Rat

Source: Zimperium
(Published: 29 January 2026)
Arsink is a cloud-native Android Remote Access Trojan (RAT) that aggressively harvests private data and gives remote operators intrusive control over infected devices. Read more.


PRC Targets NATO Frontline States

Source: Jamestown Foundation
(Published: 30 January 2026)
The People’s Republic of China (PRC) is expanding its presence along the North Atlantic Treaty Organization’s (NATO) frontline through technology access, influence networks, and dual-use infrastructure, creating openings that could weaken alliance cohesion and expose vulnerabilities in Europe’s defense posture. Read more.


Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS

Source: Google Cloud Blog
(Published: 30 January 2026)
Mandiant is tracking a significant expansion and escalation in the operations of threat clusters associated with ShinyHunters-branded extortion. Read more.


Stan Ghouls in Uzbekistan

Source: Securelist (Kaspersky)
(Published: 30 January 2026)
We uncovered a series of attacks in Uzbekistan that appear to be linked to the long-running “Stalkerware” ecosystem. Read more.


DynoWiper update: Technical analysis and attribution

Source: WeLiveSecurity (ESET Research)
(Published: 30 January 2026)
In this blog post, we provide more technical details related to our previous DynoWiper publication. Read more.


Iconics Suite Vulnerability Exploited in the Wild (CVE-2025-0921)

Source: Palo Alto Networks Unit 42
(Published: 31 January 2026)
Unit 42 researchers have observed active exploitation of a vulnerability in the Iconics Suite software platform. Read more.


DynoWiper: Destructive Malware Targeting Hybrid Environments

Source: Elastic Security Labs
(Published: 1 February 2026)
Elastic Security Labs identified DynoWiper, a destructive malware strain designed to disrupt hybrid cloud environments. Read more.


The Autonomous Adversary: From Chatbot to Criminal Enterprise

Source: InfoStealers
(Published: 1 February 2026)
Advances in large language models are beginning to reshape how cybercriminals automate operations and decision-making. Read more.


Android Trojan Campaign Uses Hugging Face to Host RAT Payload

Source: Bitdefender Labs
(Published: 2 February 2026)
Bitdefender researchers have identified an Android malware campaign abusing the Hugging Face platform to host malicious payloads. Read more.


Dark Web Marketplaces: An Overview

Source: DEXpose
(Published: 2 February 2026)
Dark web marketplaces continue to play a central role in the cybercrime ecosystem by facilitating the sale of illicit goods and services. Read more.


Citrix Recon Using Residential Proxies

Source: GreyNoise
(Published: 2 February 2026)
GreyNoise researchers observed widespread reconnaissance activity targeting Citrix environments using residential proxy infrastructure. Read more.


Infostealers Without Borders: macOS Python Stealers and Platform Abuse

Source: Microsoft Security Blog
(Published: 2 February 2026)
Microsoft researchers are tracking a rise in macOS-focused Python-based infostealers abusing legitimate platforms for distribution. Read more.


APT28 Leverages CVE-2026-21509 in Operation Neusploit

Source: Zscaler ThreatLabz
(Published: 2 February 2026)
In January 2026, Zscaler ThreatLabz identified a new campaign in-the-wild, tracked as Operation Neusploit, targeting countries in the Central and Eastern European region. Read more.


APT28: Geofencing as a Targeting Signal (CVE-2026-21509 Campaign)

Source: Synaptic Security Blog
(Published: 3 February 2026)
Since the beginning of this year, we have again observed an increased number of attacks by APT28 targeting various European countries. Read more.


APT28’s Campaign Leveraging CVE-2026-21509 and Cloud C2 Infrastructure

Source: StrikeReady
(Published: 3 February 2026)
APT28 has launched a new campaign exploiting CVE-2026-21509 and leveraging cloud-hosted command-and-control infrastructure. Read more.


Likely Fake Ransomware Operator 0apt Causes Panic: Our Analysis

Source: Intel 471
(Published: 3 February 2026)
Intel 471 analysts assess that the ransomware operator known as 0apt is likely engaging in deception rather than conducting real attacks. Read more.


SnappyBee Malware Analysis

Source: Darktrace
(Published: 3 February 2026)
Darktrace analysts investigated a new malware family dubbed SnappyBee observed in recent intrusions. Read more.


19 Shades of LockBit 5.0: Inside the Latest Cross-Platform Ransomware (Part 1)

Source: LevelBlue SpiderLabs
(Published: 3 February 2026)
Researchers analyzed LockBit 5.0 to understand how the ransomware has evolved into a cross-platform threat. Read more.


Analysis of Suspected Malware Linked to APT-Q-27 Targeting Financial Institutions

Source: CyStack
(Published: 4 February 2026)
In mid-January 2026, CyStack’s security team observed anomalous activity on a corporate customer’s environment. Read more.


Russian Cyber Threat Activity Ahead of the 2026 Winter Olympics

Source: Palo Alto Networks Unit 42
(Published: 4 February 2026)
Russian cyber threat actors are likely to increase activity in the lead-up to the 2026 Winter Olympics, according to Unit 42 analysis. Read more.


When Malware Talks Back

Source: PointWild
(Published: 4 February 2026)
Modern malware increasingly incorporates interactive capabilities that allow operators to adapt campaigns in real time. Read more.


Operation Bizarre Bazaar

Source: Pillar Security
(Published: 4 February 2026)
Operation Bizarre Bazaar documents a coordinated campaign abusing trusted platforms to distribute malicious payloads. Read more.


Inside a Multi-Stage Android Malware Campaign Leveraging RTO-Themed Social Engineering

Source: Seqrite
(Published: 4 February 2026)
In recent years, Android malware campaigns in India have increasingly abused the trust associated with government services and official digital platforms. Read more.


CISA tells agencies to stop using unsupported edge devices

Source: CyberScoop
(Published: 5 February 2026)
A binding operational directive issued Thursday looks to combat an attack pathway that has been behind some of the biggest attacks and most common exploits in recent years. Read more.


Substack Breach: 662,752 User Records Leaked on Cybercrime Forum

Source: Hackread
(Published: 5 February 2026)
Three days before Substack told users about a security incident, a very different version of the story was already circulating in underground cyber crime forums. Read more.


Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework

Source: Cisco Talos Intelligence Blog
(Published: 5 February 2026)
Cisco Talos uncovered “DKnife,” a fully featured gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants that perform deep-packet inspection, manipulate traffic, and deliver malware via routers and edge devices. Read more.


Please Don’t Feed the Scattered Lapsus-Shiny Hunters

Source: Krebs on Security
(Published: 5 February 2026)
Researchers are warning that attention-seeking cybercrime groups thrive on publicity and notoriety. Read more.


ClickFix Variant CrashFix Deploying Python RAT Trojan

Source: Microsoft Security Blog
(Published: 5 February 2026)
Microsoft has identified a new ClickFix variant dubbed CrashFix that deploys a Python-based RAT. Read more.


Reynolds: Defense Evasion Capability Embedded in Ransomware Payload

Source: SECURITY.COM
(Published: 5 February 2026)
A recent Reynolds ransomware campaign was notable because the ransomware contained a bring-your-own-vulnerable-driver (BYOVD) defense evasion component embedded within the ransomware payload itself. Read more.


AppleScript Abuse: Unpacking a macOS Phishing Campaign

Source: Darktrace
(Published: 5 February 2026)
Darktrace researchers uncovered a phishing campaign abusing AppleScript to target macOS users. Read more.


China’s Salt Typhoon Hackers Broke Into Norwegian Companies

Source: TechCrunch
(Published: 6 February 2026)
Hackers linked to the Chinese state-sponsored group known as Salt Typhoon have breached multiple Norwegian companies. Read more.


Incognito Market Operator Sentenced to Thirty Years

Source: The Record
(Published: 6 February 2026)
The operator of the darknet drug marketplace Incognito Market has been sentenced to thirty years in prison. Read more.


Git Metadata Leak Exposes Sensitive Information

Source: Mysterium VPN
(Published: 6 February 2026)
Researchers uncovered widespread exposure of sensitive information due to leaked Git metadata in public repositories. Read more.


Nginx Traffic Hijacking in React2Shell Campaign

Source: The Cybersecurity Guru
(Published: 7 February 2026)
Researchers have uncovered a campaign abusing exposed Nginx configurations to hijack web traffic and deploy malicious payloads. Read more.


Malicious Bing Ads Lead to Widespread Azure Tech Support Scams

Source: Netskope
(Published: 7 February 2026)
Netskope researchers uncovered a large-scale campaign abusing Bing ads to deliver Azure-themed tech support scams. Read more.


Aisuru Botnet Sets New Record With 3.14 Tbps DDoS Attack

Source: BleepingComputer
(Published: 8 February 2026)
The Aisuru botnet has set a new distributed denial-of-service record with a massive 3.14 Tbps attack. Read more.


Labyrinth Chollima Evolves Into Three Adversaries

Source: CrowdStrike
(Published: 8 February 2026)
CrowdStrike researchers have observed the threat group Labyrinth Chollima splintering into three distinct adversaries. Read more.


The GRU Illegals

Source: Lab52
(Published: 8 February 2026)
Russian intelligence services have historically relied on so-called “illegals” – deep-cover operatives who live for years in foreign countries under false identities. Read more.


Prince of Persia, Part II

Source: SafeBreach Labs
(Published: 8 February 2026)
SafeBreach researchers continue their analysis of the Prince of Persia campaign, revealing additional tradecraft and tooling. Read more.


LTX Stealer: Analysis of a Node.js-Based Credential Stealer

Source: Cyfirma
(Published: 9 February 2026)
Cyfirma researchers analyzed a new credential-stealing malware written in Node.js dubbed LTX Stealer. Read more.


Re-Emerging Telegram Phishing Campaign Targeting User Authorization Prompts

Source: Cyfirma
(Published: 9 February 2026)
A phishing campaign abusing Telegram authorization prompts has resurfaced with updated infrastructure and lures. Read more.


S’pore’s major telcos came under attack by UNC3886 in 2025

Source: The Straits Times
(Published: 9 February 2026)
SINGAPORE – All four major telcos in Singapore came under attack by state-sponsored cyberespionage group UNC3886, whose activities to disrupt critical services here were first made public in July 2025. Read more.

Want more articles? Check out the previous edition of Security Signals here. 

?

How big are your threat data gaps?

See for yourself.

?

Security Signals (1/13/26-1/27/26)

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

Turn Insights Into Action with Free Threat Intel

Security Signals gives you the insights and our Risk Indicators OSINT feeds help you apply them.

This Edition’s Articles

Late January 2026 Cyber Threat Reports spotlight real-world abuse of trusted platforms and exposed infrastructure – from LockBit 5.0 and KONNI to BRICKSTORM, Gootloader-style delivery tricks, and attacks leveraging tools like Visual Studio Code, PAN-OS GlobalProtect, and Google Gemini. Expect recurring themes of phishing/credential theft, malware staging, and operational tooling that turns everyday enterprise workflows into attack paths.

Planned failure: Gootloader’s malformed ZIP actually works perfectly

Source: Expel
(Published: 15 January 2026)
Gootloader malware is delivered to victims in a ZIP archive and the ZIP itself is designed to bypass detection. Read more.


Keylogger targets 200,000+ employees at major US bank

Source: Sansec
(Published: 15 January 2026)
Sansec discovered an active keylogger on the employee merchandise store of a top 3 US bank. Read more.


Inside LockBit 5.0: Analyzing the Ransomware Group’s Latest Affiliate Panel and Encryption Variants

Source: Flare
(Published: 16 January 2026)
The leaked materials provide unprecedented visibility into LockBit’s affiliate management system, showing the interface used by ransomware operators to coordinate attacks and manage victim negotiations. Read more.


Remcos RAT Being Distributed to Korean Users

Source: ASEC (AhnLab)
(Published: 16 January 2026)
AhnLab SEcurity intelligence Center (ASEC) has confirmed the distribution of the Remcos RAT targeting users in South Korea. Read more.


Mandiant releases rainbow table that cracks weak admin password in 12 hours

Source: Ars Technica
(Published: 16 January 2026)
Windows laggards still using the vulnerable hashing function: Your days are numbered. Read more.


Poland Under Intensified DDoS Siege: Weekly DDoS Threat Intelligence Analysis

Source: SOCRadar
(Published: 18 January 2026)
Between 12 and 18 January 2026, SOCRadar identified an intensive coordinated DDoS campaign conducted by the pro-Russian threat actor NoName057(16) and their DDoSia attack tool. Read more.


CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal

Source: Palo Alto Networks
(Published: 19 January 2026)
A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Read more.


NCSC issues warning over hacktivist groups disrupting UK organisations and online services

Source: UK National Cyber Security Centre (NCSC)
(Published: 19 January 2026)
New alert warns of state-aligned hacktivists targeting UK organisations, looking to cripple services and disable websites. Read more.


Hacker admits to leaking stolen Supreme Court data on Instagram

Source: BleepingComputer
(Published: 19 January 2026)
A Tennessee man has pleaded guilty to hacking the U.S. Supreme Court’s electronic filing system and breaching accounts at the AmeriCorps U.S. federal agency and the Department of Veterans Affairs. Read more.


Broker who sold malware to the FBI set for sentencing

Source: The Register
(Published: 19 January 2026)
Feras Khalil Ahmad Albashiti, 40, admitted to facilitating cyberattacks on at least 50 companies stateside. Read more.


Operation Covert Access: Weaponized LNK-Based Spear-Phishing Targeting Argentina’s Judicial Sector to Deploy a Covert RAT

Source: Seqrite
(Published: 19 January 2026)
Seqrite Labs has identified and uncovered a globally active spear-phishing campaign targeting Argentina’s judicial sector. Read more.


Weaponizing Calendar Invites: A Semantic Attack on Google Gemini

Source: Miggo
(Published: 19 January 2026)
A standard calendar invite became an attack vector, exposing how prompt injection in Google Gemini bypassed privacy controls through language alone. Read more.


Kimwolf Botnet Lurking in Corporate, Govt. Networks

Source: Krebs on Security
(Published: 20 January 2026)
A new Internet-of-Things (IoT) botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic. Read more.


BRICKSTORM Malware Report Highlights the Criticality of Network-Derived Telemetry

Source: Gigamon
(Published: 20 January 2026)
Although GTIG laments the lack of security telemetry in its analysis of the BRICKSTORM malware, network-derived telemetry from the analysis of network traffic is a rich source that can and should be leveraged by threat hunters and IR teams. Read more.


Inside a Multi-Stage Windows Malware Campaign

Source: Fortinet (FortiGuard Labs)
(Published: 20 January 2026)
FortiGuard Labs recently identified a multi-stage malware campaign primarily targeting users in Russia. Read more.


IntelBroker Unmasked – The Story of Hacker Kai Logan West

Source: Picus Security
(Published: 20 January 2026)
If you’ve been following cybersecurity news lately, you’ve almost certainly heard the name “IntelBroker.”. Read more.


Threat Actors Expand Abuse of Microsoft Visual Studio Code

Source: Jamf
(Published: 20 January 2026)
Jamf Threat Labs identifies additional abuse of Visual Studio Code. Read more.


Predator bots are exploiting APIs at scale. Here’s how defenders must respond.

Source: CyberScoop
(Published: 20 January 2026)
With malicious bots now accounting for roughly 37% of all web traffic, security teams are left feeling like they’re playing a giant game of bot whack-a-mole. Read more.


PyPI Package Impersonates SymPy to Deliver Cryptomining Malware

Source: Socket
(Published: 21 January 2026)
Socket’s Threat Research Team identified a malicious PyPI package, sympy-dev, that impersonates SymPy, a widely used symbolic mathematics library with roughly 85 million downloads per month. Read more.


Peruvian Peaks: The digital loan illusion

Source: Group-IB
(Published: 21 January 2026)
A deep dive into loan phishing scams in Peru and Latin America. Read more.


Detailed Analysis of LockBit 5.0

Source: S2W (Medium)
(Published: 21 January 2026)
The LockBit ransomware group was affiliated with the Maze ransomware cartel, but after Maze announced its retirement, it began operating independently under the name ABCD ransomware starting in September 2019. Read more.


Phishing kits adapt to the script of callers

Source: Okta
(Published: 22 January 2026)
The threat actor convinces the targeted user to navigate in their browser to the phishing site under the pretext of an IT support or security requirement. Read more.


KONNI Adopts AI to Generate PowerShell Backdoors

Source: Check Point Research
(Published: 22 January 2026)
The PowerShell backdoor strongly indicates AI-assisted development rather than traditional operator-authored malware. Read more.


Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign

Source: eSentire
(Published: 22 January 2026)
eSentire’s Threat Response Unit tracks this activity as “SyncFuture Espionage campaign” based on the abuse of SyncFuture/Yangtu enterprise software and a sophisticated multi-stage infection chain targeting Indian entities. Read more.


Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw

Source: Forbes
(Published: 22 January 2026)
Microsoft confirmed it does provide BitLocker recovery keys if it receives a valid legal order. Read more.


ErrTraffic: Inside a GlitchFix Attack Panel

Source: Censys
(Published: 20 January 2026)
ErrTraffic is a Traffic Distribution System (TDS) designed specifically for ClickFix-like campaigns. Read more.


Microsoft shared BitLocker keys with FBI, raising privacy fears

Source: TechRepublic
(Published: 26 January 2026)
Microsoft confirmed it can hand over BitLocker recovery keys stored in the cloud under warrant, reviving debate over who controls encrypted data. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

?

Take advantage of our free data evaluation.

?

Security Signals (12/30/25-01/13/26)

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

Turn Insights Into Action with Free Threat Intel

Security Signals gives you the insights and our Risk Indicators OSINT feeds help you apply them.

This Edition’s Articles

These early January 2026 cyber threat reports showcase how attackers are actively abusing trusted software, exposed infrastructure, and popular platforms to reach victims at scale. This roundup highlights GoBruteforcer server attacks, UAT-7290 telecom targeting, fake WinRAR installers delivering malware, malicious Chrome extensions abusing AI tools, and ongoing MacSync stealer campaigns impacting macOS users.

APT36 : Multi-Stage LNK Malware Campaign Targeting Indian Government Entities

Source: CYFIRMA
(Published: 30 December 2025)
CYFIRMA has identified a targeted malware campaign attributed to APT36 (Transparent Tribe), a Pakistan aligned threat actor actively engaged in cyber espionage operations against Indian governmental, academic, and strategic entities. Read more.


From Victim to Vector: How Infostealers Turn Legitimate Businesses into Malware Hosts

Source: InfoStealers
(Published: 30 December 2025)
This entry in the Hudson Rock database means that a computer – likely belonging to a developer or admin at jrqsistemas.com – was infected by an Infostealer. Read more.


2 Security Experts Plead Guilty In BlackCat Ransomware Case

Source: The Cyber Express
(Published: 30 December 2025)
Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, were indicted in the BlackCat ransomware case in October. Read more.


Knownsec Data Breach: A Trove of Espionage Tradecraft with an Insider Narrative

Source: Resecurity
(Published: 31 December 2025)
The Knownsec leak is a pivotal incident of 2025 because it exposed the inner workings of a major state-linked Chinese cybersecurity firm, revealed espionage tools and global targets, internal documentation, and evidence of ongoing cyber operations targeting other countries. Read more.


VVS Discord Stealer Using Pyarmor for Obfuscation and Detection Evasion

Source: Unit 42 (Palo Alto Networks)
(Published: 2 January 2026)
This article details our technical analysis of VVS stealer, also styled VVS $tealer, including its distributors’ use of obfuscation and detection evasion. Read more.


Resurgence of Scattered Lapsus$ hunters

Source: CYFIRMA
(Published: 3 January 2026)
Recent monitoring of underground forums and Telegram communities has identified the resurgence of the Scattered Lapsus$ collective. Read more.


D-Link DSL/DIR/DNS Command Injection via DNS Configuration Endpoint

Source: VulnCheck
(Published: 5 January 2026)
severity critical. Read more.


NordVPN Denies Breach After Hacker Leaks Data

Source: SecurityWeek
(Published: 6 January 2026)
The VPN company has conducted an investigation after a threat actor claimed to have hacked its systems. Read more.


Phishing actors exploit complex routing and misconfigurations to spoof domains

Source: Microsoft Security Blog
(Published: 6 January 2026)
Any third-party connectors – such as a spam filtering service, security solution, or archiving service – must be configured properly or spoof detections cannot be calculated correctly, allowing phishing emails such as the examples below to be delivered. Read more.


The Great VM Escape: ESXi Exploitation in the Wild

Source: Huntress
(Published: 7 January 2026)
In December 2025, Huntress observed an intrusion leading to the deployment of VMware ESXi exploits. Read more.


Malicious NPM Packages Deliver NodeCordRAT

Source: Zscaler ThreatLabz
(Published: 7 January 2026)
Zscaler ThreatLabz regularly monitors the `npm` database for suspicious packages. Read more.


Researchers rush to warn defenders of max-severity defect in n8n

Source: CyberScoop
(Published: 7 January 2026)
Roughly 100,000 servers running the automated workflow platform for AI and other enterprise tools are potentially exposed to exploitation. Read more.


Chrome Extensions Impersonate AI Tools to Steal ChatGPT & DeepSeek Chats

Source: SOCRadar
(Published: 7 January 2026)
A recently uncovered malware campaign involving Chrome extensions demonstrates how seemingly legitimate AI-focused add-ons can be abused to quietly collect sensitive user data at scale. Read more.


Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns

Source: Check Point Research
(Published: 7 January 2026)
GoBruteforcer is a botnet that turns compromised Linux servers into scanning and password brute-force nodes. Read more.


UAT-7290 targets high value telecommunications infrastructure in South Asia

Source: Cisco Talos
(Published: 8 January 2026)
Cisco Talos is disclosing a sophisticated threat actor we track as UAT-7290, who has been active since at least 2022. Read more.


Fake WinRAR downloads hide malware behind a real installer

Source: Malwarebytes
(Published: 8 January 2026)
A member of our web research team pointed me to a fake WinRAR installer that was linked from various Chinese websites. Read more.


Maduro Arrest Used as a Lure to Deliver Backdoor

Source: Darktrace
(Published: 9 January 2026)
Darktrace researchers observed threat actors exploiting reports of Venezuelan President Maduro’s arrest to deliver backdoor malware. Read more.


MacSync stealer is using a notarized app to bypass Mac defenses

Source: Moonlock
(Published: 9 January 2026)
MacSync, the new macOS stealer in town, is back with new tricks. Read more.


Boto-Cor-de-Rosa campaign reveals Astaroth WhatsApp-based worm activity in Brazil

Source: Acronis Threat Research Unit
(Published: 8 January 2026)
In a newly identified campaign, internally referred to as Boto Cor-de-Rosa, our researchers discovered that Astaroth now exploits WhatsApp Web as part of its propagation strategy. Read more.


Under Medusa’s Gaze: How Darktrace Uncovers RMM Abuse in Ransomware Campaigns

Source: Darktrace
(Published: 8 January 2026)
Medusa ransomware increasingly exploits remote monitoring and management (RMM) tools for persistence, lateral movement, and data exfiltration. Read more.


Reborn in Rust: Muddy Water Evolves Tooling with RustyWater Implant

Source: CloudSEK
(Published: 8 January 2026)
CloudSEK’s TRIAD recently identified a spear-phishing campaign attributed to the Muddy Water APT group targeting multiple sectors across the Middle East, including diplomatic, maritime, financial, and telecom entities. Read more.


North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities

Source: FBI IC3 (FLASH)
(Published: 8 January 2026)
The Federal Bureau of Investigation (FBI) is releasing this FLASH to alert NGOs, think tanks, academia, and other foreign policy experts with a nexus to North Korea of evolving tactics employed by the North Korean state-sponsored cyber threat group Kimsuky and to provide mitigation recommendations. Read more.


Iran Implements Nationwide Military Jamming to Cripple Starlink and Enforce Digital Blackout

Source: Reclaim The Net
(Published: 12 January 2026)
Iran’s government has expanded its control over digital communication, deploying military jamming systems that have largely disabled Starlink satellite access. Read more.


Stealthy malware masking its activity, deploying infostealer

Source: Kaspersky
(Published: 12 January 2026)
Our experts have detected a new wave of malicious emails targeting Russian private-sector organizations. Read more.


Hunting Lazarus: Inside the Contagious Interview C2 Infrastructure

Source: Red Asgard
(Published: 12 January 2026)
We found North Korean malware in a client’s Upwork project. Read more.


Unmasking the DPRK Remote Worker Problem

Source: Silent Push
(Published: 12 January 2026)
For decades, the “insider threat” was synonymous with the disgruntled staffer or the negligent contractor. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

?

Take advantage of our free data evaluation.

?

Security Signals (12/02/25-12/16/25)

Welcome to your biweekly digest of curated cybersecurity intelligence.

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

Turn Insights Into Action with Free Threat Intel

Security Signals gives you the insights and our Risk Indicators OSINT feeds help you apply them.

This Edition’s Articles

Mid December 2025 Cyber Threat Reports highlight how rapidly evolving threats are colliding with geopolitics, cloud infrastructure, and everyday consumer tech. This roundup spans everything from React2Shell mass exploitation to new Android banking malware, Mirai botnets at sea, and fresh ransomware tooling targeting ESXi and EDR.

Investigating an AiTM Phishing Campaign Targeting M365 and Okta

Source: Datadog Security Labs
(Published: 10 December 2025)
Datadog researchers detail an adversary-in-the-middle phishing campaign designed to bypass MFA protections for Microsoft 365 and Okta users. Read more.


Share ChatGPT Chat ClickFix: macOS AMOS Infostealer

Source: Kaspersky
(Published: 9 December 2025)
Kaspersky researchers describe a macOS infostealer campaign abusing fake ChatGPT sharing prompts to trick users into executing malicious commands. Read more.


Detecting Mythic C2 in Network Traffic

Source: Kaspersky Securelist
(Published: 11 December 2025)
This research outlines techniques for identifying Mythic command-and-control traffic using network-level indicators and behavioral patterns. Read more.


IT, Geopolitics, and Cyber Risk: How Global Tensions Shape the Attack Surface

Source: Rapid7
(Published: 11 December 2025)
Rapid7 examines how geopolitical instability influences cyber operations, threat actor targeting, and organizational risk exposure. Read more.


CyberVolk Returns: Flawed VolkLocker Brings New Features With Growing Pains

Source: SentinelOne
(Published: 10 December 2025)
SentinelOne analyzes the reemergence of CyberVolk ransomware, highlighting technical flaws alongside newly added capabilities. Read more.


Cato CTRL: Deep Dive Into New JSCeal Infostealer Campaign

Source: Cato Networks
(Published: 11 December 2025)
Cato Networks investigates a new JSCeal infostealer campaign leveraging obfuscated JavaScript to harvest credentials at scale. Read more.


What Happens to Stolen Data After Phishing Attacks?

Source: Kaspersky Securelist
(Published: 12 December 2025)
This article examines how stolen credentials and personal data are monetized, resold, and reused following phishing attacks. Read more.


The Infostealer to APT Pipeline: How Lazarus Hijacked a Yemen Disinformation Network

Source: Infostealers.com
(Published: 12 December 2025)
Researchers describe how the Lazarus Group leveraged infostealer infrastructure to compromise and repurpose a Yemen-based disinformation network. Read more.


Hamas-Affiliated Ashen Lepus Targets Middle Eastern Diplomatic Entities With New AshTag Malware Suite

Source: Unit 42 (Palo Alto Networks)
(Published: 11 December 2025)
Unit 42 researchers detail how Hamas-affiliated threat actor Ashen Lepus is using a new AshTag malware suite to target Middle Eastern diplomatic entities. Read more.


Apple fixes two zero-day flaws exploited in ‘sophisticated’ attacks

Source: BleepingComputer
(Published: 12 December 2025)
Apple has released emergency updates to patch two zero-day vulnerabilities that were exploited in an extremely sophisticated attack targeting specific individuals. Read more.


Operation MoneyMount-ISO – Deploying Phantom Stealer via ISO-Mounted Executables

Source: Seqrite
(Published: 12 December 2025)
At Seqrite Labs, we continuously monitor global cyber threat activity. Read more.


Threats Behind the Mask of Gentlemen Ransomware

Source: ASEC
(Published: 11 December 2025)
ASEC researchers analyze threats hidden behind the so-called Gentlemen ransomware, including its infection vector, encryption behavior, and tactics for evading detection. Read more.


Evolution of Composite Cyber Threats: 2025 Analysis and 2026 Key Response Strategies

Source: Medium (@nshcthreatrecon)
(Published: 15 December 2025)
This long-form analysis explores how composite cyber threats evolved in 2025 and outlines key response strategies defenders should prioritize in 2026. Read more.


Free Micropatches for Windows Remote Access Connection Manager DoS

Source: 0patch
(Published: 11 December 2025)
0patch ships free micropatches for a Windows Remote Access Connection Manager zero day that attackers can abuse to gain Local System privileges on vulnerable hosts. Read more.


Microsoft Teams to Introduce External Domains Anomalies Report for Enhanced Security

Source: Cybersecurity News
(Published: 11 December 2025)
Microsoft is adding an External Domains Anomalies report to Teams so administrators can spot unusual communication patterns with outside tenants and clamp down on risky connections. Read more.


New DroidLock Malware Locks Android Devices and Demands a Ransom

Source: Cybersecurity News
(Published: 11 December 2025)
Researchers warn that the DroidLock Android malware is being pushed via phishing sites, locking victims’ phones for ransom while also enabling attackers to take remote control. Read more.


Notepad++ Vulnerability Let Attackers Hijack Network Traffic to Install Malware via Updates

Source: Cybersecurity News
(Published: 11 December 2025)
A vulnerability in Notepad++ update traffic could allow threat actors to intercept requests on the network and deliver malicious payloads disguised as legitimate software updates. Read more.


Threat actors exploit React2Shell CVE-2025-55182

Source: Google Cloud Threat Intelligence
(Published: 12 December 2025)
Google Threat Intelligence details how multiple actors quickly weaponized the React2Shell (CVE-2025-55182) remote code execution flaw in React Server Components to gain initial access to internet facing services. Read more.


How NoName05716 Uses DDoSia to Attack NATO Targets

Source: Picus Security
(Published: 14 December 2025)
Picus analyzes how pro Russian hacktivist group NoName05716 leverages its DDoSia platform to coordinate politically motivated DDoS attacks against NATO aligned governments and organizations. Read more.


Frogblight threatens you with a court case: a new Android banker targets Turkish users

Source: Securelist
(Published: 15 December 2025)
Kaspersky describes Frogblight, an Android banking trojan distributed via smishing and fake government court case portals that steals banking credentials and can remotely control infected devices. Read more.


DDoS Threat Intelligence: Belgium, 15 Dec 2025

Source: SOCRadar
(Published: 15 December 2025)
SOCRadar details a DDoSia campaign by pro Russian group NoName05716 that generated thousands of DDoS attacks focusing on Belgium as well as Ukraine and other European targets between 8 and 14 December 2025. Read more.


Cyberattack on the Sun

Source: Cato Networks
(Published: 15 December 2025)
Cato Networks examines how insecure legacy protocols in solar power infrastructure could let attackers manipulate inverters at scale and cause widespread power disruption. Read more.


TR SantaStealer Is Coming to Town: A New, Ambitious Infostealer Advertised on Underground Forums

Source: Rapid7
(Published: 15 December 2025)
Rapid7 profiles SantaStealer, a new information stealing malware as a service offering on underground forums that targets browser, cryptocurrency wallet, and application credentials. Read more.


Phishing Kits: An Interactive Deep Dive

Source: Flare
(Published: 15 December 2025)
Flare takes an interactive look at modern phishing kits, showing how they bundle cloned login pages, evasion features, and automation to let low skill actors harvest credentials at scale. Read more.


GhostPairing Attacks: from phone number to full access in WhatsApp

Source: Gen Digital
(Published: 15 December 2025)
Gen researchers describe GhostPairing, a WhatsApp account takeover technique where attackers trick victims into pairing an attacker controlled device without ever stealing their password. Read more.


16TB of MongoDB Database Exposes 4.3 Billion Lead Gen Records

Source: Hackread
(Published: 15 December 2025)
Hackread reports on an unsecured 16TB MongoDB instance left open online that exposed over 4.3 billion professional lead generation records containing extensive personal and business data. Read more.


BreachForums Reemerges, Admin Apologizes for Honeypot Confusion, Claims the Attack the French Govt Announced Impacting Over 16M Individuals

Source: TechNadu
(Published: 15 December 2025)
TechNadu covers BreachForums administrators resurfacing to deny being a law enforcement honeypot while claiming responsibility for a French government data breach affecting more than 16 million people. Read more.


Kimsuky Distributing Malicious Mobile App via QR Code

Source: Enki White Hat
(Published: 16 December 2025)
Enki’s White Hat team analyzes new DOCSWAP APK variants delivered via QR code phishing sites and attributes the campaign to DPRK aligned threat actor Kimsuky. Read more.


Inside Ink Dragon: Revealing the Relay Network and Inner Workings of a Stealthy Offensive Operation

Source: Check Point Research
(Published: 16 December 2025)
Check Point Research exposes Chinese espionage actor Ink Dragon, showing how it turns compromised IIS servers into a ShadowPad based relay mesh spanning government and telecom victims worldwide. Read more.


CastleRAT malware detection with Splunk and MITRE ATT&CK

Source: Splunk
(Published: 5 December 2025)
Splunk Threat Research shows how defenders can detect CastleRAT infections by mapping the malware’s behaviors to MITRE ATT&CK techniques and translating them into Splunk detections. Read more.


Hypervisor defenses against ransomware targeting ESXi

Source: Huntress
(Published: 8 December 2025)
Hypervisors are the backbone of modern virtualized environments, but when ransomware targets ESXi hosts the blast radius can quickly extend across an entire organization. Read more.


White Lynx uses CAPTCHA macros

Source: Unit 42 (Palo Alto Networks)
(Published: 8 December 2025)
This Unit 42 timely threat intel note documents a White Lynx phishing campaign that uses a CAPTCHA themed Word macro to deliver malware and harvest victim credentials. Read more.


React2Shell exploitation escalates into mass attacks

Source: The Hacker News
(Published: 10 December 2025)
The Hacker News reports that a critical ReactPHP vulnerability dubbed React2Shell, tracked as CVE 2025 55182, is now being widely exploited to deploy web shells on vulnerable servers. Read more.


Windows PowerShell 0 day vulnerability allows attackers to execute malicious code

Source: Cybersecurity News
(Published: 10 December 2025)
Security researchers warn that a newly disclosed Windows PowerShell 0 day vulnerability could allow attackers to execute arbitrary code on Windows systems if it is abused by threat actors. Read more.


Fortinet FortiGate under active attack

Source: The Hacker News
(Published: 11 December 2025)
A critical flaw in Fortinet FortiOS and FortiProxy is being actively exploited, allowing attackers to bypass authentication on FortiGate devices and gain full control of vulnerable appliances. Read more.


NANOREMOTE, cousin of FINALDRAFT

Source: Elastic Security Labs
(Published: 11 December 2025)
In October 2025, Elastic Security Labs discovered a newly observed Windows backdoor in telemetry that they call NanoRemote, which closely resembles the FINALDRAFT implant. Read more.


Shanya emerges as top EDR killing tool for ransomware gangs

Source: Techworm
(Published: 11 December 2025)
Techworm profiles Shanya, a new EDR killing utility aggressively marketed to ransomware gangs for disabling security tools before encryption begins. Read more.


Intellexa leaks: Predator spyware operations exposed

Source: Amnesty International Security Lab
(Published: 11 December 2025)
Amnesty International’s Security Lab analyzes a large leak of Intellexa documents that exposes how the Predator spyware platform has been sold and deployed around the world. Read more.


Cracking ValleyRAT: from builder secrets to kernel rootkits

Source: Check Point Research
(Published: 12 December 2025)
Throughout 2025, Check Point Research tracked the evolution of ValleyRAT, following the malware from leaked builder tools to sophisticated kernel level rootkits used in the wild. Read more.


Technical analysis of the BlackForce phishing kit

Source: Zscaler
(Published: 12 December 2025)
Zscaler ThreatLabz provides a technical deep dive into the BlackForce phishing as a service kit, which automates Microsoft 365 credential theft using reverse proxy techniques and extensive anti analysis features. Read more.


China-Nexus Cyber Threat Groups Rapidly Exploit React2Shell Vulnerability (CVE-2025-55182)

Source: AWS Security Blog
(Published: 4 December 2025)
Within hours of the React2Shell CVE-2025-55182 disclosure, Amazon threat intelligence teams observed multiple China-nexus actors attempting to exploit vulnerable Next.js applications at scale. Read more.


Advent of Configuration Extraction – Part 2: Unwrapping QuasarRAT’s Configuration

Source: Sekoia.io
(Published: 8 December 2025)
This second installment of the Advent of Configuration Extraction series shows how analysts can unpack QuasarRAT samples and extract their encrypted configuration from the .NET binary. Read more.


BYOVD Loader Deploys DeadLock Ransomware

Source: Talos Intelligence
(Published: 9 December 2025)
Cisco Talos details a new bring-your-own-vulnerable-driver (BYOVD) loader used to disable security products and deploy DeadLock ransomware in targeted attacks. Read more.


Cydome Identifies Broadside, a New Mirai Botnet Variant Targeting Maritime IoT

Source: Cydome
(Published: 3 December 2025)
Cydome researchers uncover Broadside, a Mirai-based botnet variant that abuses weakly secured maritime IoT devices to build a DDoS-capable fleet. Read more.


Malicious VSCode Extension Launches Multi-Stage Attack Chain with Anivia Loader and OctoRAT

Source: Hunt.io
(Published: 3 December 2025)
Hunt.io describes a malicious Visual Studio Code extension that delivers a multi-stage attack chain, ultimately deploying the Anivia loader and OctoRAT for persistent remote control. Read more.


SMS Phishers Pivot to Points, Taxes, Fake Retailers

Source: Krebs on Security
(Published: 4 December 2025)
Brian Krebs reports that China-based SMS phishing crews now sell phishing kits for mass-creating fake e-commerce sites that funnel victims’ card data into mobile wallets, alongside lures about tax refunds and rewards points. Read more.


OSINT Kitten: The Headquarters for Hacktivist Operations Against Israel

Source: Medium
(Published: 5 December 2025)
This investigation profiles OSINT Kitten as a coordination hub for hacktivist campaigns targeting Israel, outlining how propaganda, leaks, and operational chatter intersect on the platform. Read more.


Inside Shanya: A Packer-as-a-Service Fueling Modern Attacks

Source: Sophos News
(Published: 6 December 2025)
Sophos examines Shanya, a packer-as-a-service offering that ransomware groups increasingly use to obfuscate payloads, evade analysis, and extend the lifespan of their campaigns. Read more.


Nothing to Steal? Let’s Wipe. We Are Analyzing the Shai Hulud 2.0 npm Worm

Source: Securelist (Kaspersky)
(Published: 9 December 2025)
Kaspersky researchers dissect Shai Hulud 2.0, a destructive npm worm that abuses developer tooling and supply chain trust to spread and wipe systems instead of stealing data. Read more.


Cato CTRL: Weaponizing Claude Skills with MedusaLocker

Source: Cato Networks
(Published: 10 December 2025)
Cato Networks describes how red-teamers simulated an attack in which MedusaLocker operators combine LLM-powered automation with C2 infrastructure to accelerate discovery, lateral movement, and impact. Read more.


New eBPF Filters for Symbiote and BPFdoor Malware

Source: Fortinet
(Published: 9 December 2025)
Fortinet introduces new eBPF-based detection filters that help defenders identify and hunt for stealthy Linux threats such as Symbiote and BPFdoor in production environments. Read more.


UDPGangster Campaigns Target Multiple Countries

Source: Fortinet
(Published: 4 December 2025)
FortiGuard Labs reveals UDPGangster, a UDP-based backdoor linked to MuddyWater that is being used in campaigns against organizations across several Middle Eastern and neighboring states. Read more.


Investigating Indonesia’s Gambling Ecosystem: Indicators of National-Level Cyber Operations

Source: Malanta
(Published: 3 December 2025)
Malanta’s research team maps Indonesia’s online gambling infrastructure and highlights technical and behavioral indicators that could signal involvement by state-linked operators. Read more.


Deceptive Layoff-Themed HR Email Distributes Remcos RAT Malware

Source: Seqrite
(Published: 9 December 2025)
Seqrite analyzes phishing emails masquerading as layoff notifications that deliver a weaponized attachment used to install the Remcos remote access trojan. Read more.


Operation DupeHike: UNG0902 Targets Russian Employees with DupeRunner and AdaptixC2

Source: Seqrite
(Published: 3 December 2025)
This report documents Operation DupeHike, where the UNG0902 group uses phishing lures and custom malware families DupeRunner and AdaptixC2 to target employees in Russia. Read more.


Africa in the Crosshairs: Covert Influence, Cyber Operations, and the New Geopolitics

Source: Silobreaker
(Published: 9 December 2025)
Silobreaker explores how non-Western powers use information operations, cyber activity, and local partnerships to shape narratives and political outcomes across Africa. Read more.


AI-Automated Threat Hunting Brings GhostPenguin Out of the Shadows

Source: Trend Micro
(Published: 8 December 2025)
Trend Micro introduces GhostPenguin, a previously undocumented Linux backdoor discovered through AI-assisted threat hunting and low-detection telemetry analysis. Read more.


Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks

Source: Volexity
(Published: 4 December 2025)
Volexity details a campaign in which a Russian threat actor sends spoofed invitations to high-profile European security conferences to deliver malware to selected targets. Read more.


Attackers Actively Exploiting Critical Vulnerability in King Addons for Elementor Plugin

Source: Wordfence
(Published: 2 December 2025)
Wordfence warns that a critical privilege escalation flaw in the King Addons for Elementor plugin is under active exploitation, enabling unauthenticated attackers to gain admin access. Read more.


Technical Analysis of Matanbuchus 3.0

Source: Zscaler
(Published: 2 December 2025)
Zscaler ThreatLabz provides a deep technical dive into Matanbuchus 3.0, a C++ downloader malware-as-a-service that now plays a growing role in ransomware operations. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

?

Take advantage of our free data evaluation.

?