Security Signals (07/14/26-07/28/26)
Welcome to Security Signals
Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.
For more articles, check out our #onpatrol4malware blog.
Events
Going to Black Hat in Las Vegas?
If you’re interested in threat intelligence, want to chat with fellow security practitioners, or simply put a face to a name, let’s grab a coffee. We’ve opened time on our calendars for meetings throughout the conference.
Looking forward to the conversations and seeing familiar faces as well as meeting new ones!
Our Latest Blog Post
June 2026 Edition
Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.
Insights (TL;DR)
To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.
Â
Top ATT&CK Techniques Observed
T1566 – Phishing: Credential theft remained one of the primary initial access vectors, with campaigns using device code phishing, adversary-in-the-middle (AiTM) techniques, fake recruiters, Google Ads lures, procurement scams, eCards, and other social engineering methods.
T1071 – Application Layer Protocol: Threat actors increasingly relied on legitimate services and protocols—including Outlook, DNS, browsers, blockchain infrastructure, Telegram, and cloud platforms—for command-and-control to blend malicious traffic with normal network activity.
T1583 / T1584 – Acquire & Compromise Infrastructure: Multiple investigations focused on attacker-controlled infrastructure, compromised government websites, malicious domains, cloud resources, and software repositories used to support phishing, malware delivery, and command-and-control.
T1195 – Supply Chain Compromise: Software supply chain attacks remained highly active, targeting npm packages, PyPI repositories, SDKs, browser extensions, AI tooling, IDE components, and other developer ecosystems.
T1105 / T1059 – Ingress Tool Transfer & Command Execution: Researchers observed widespread use of custom loaders, remote access trojans, malware frameworks, scripting engines, ClickFix techniques, and living-off-the-land methods to establish persistence and evade detection.
What Matters Most
Identity has become the preferred attack surface. Rather than exploiting vulnerabilities, many campaigns focused on stealing credentials through phishing, adversary-in-the-middle attacks, Microsoft 365 abuse, and social engineering.
ClickFix continues to gain momentum. Multiple unrelated threat actors—including financially motivated groups, DPRK operators, and nation-state campaigns—adopted ClickFix techniques, reinforcing its emergence as a mainstream initial access method.
Trusted infrastructure is increasingly abused. Government websites, SaaS platforms, Microsoft 365, GitHub, Telegram, cloud services, and blockchain infrastructure were repeatedly leveraged to host payloads, deliver malware, or conceal command-and-control traffic.
Threat research is shifting toward infrastructure analysis. Many reports focused less on individual malware samples and more on mapping attacker infrastructure, command-and-control architecture, operational ecosystems, and attribution.
What Defenders Should Watch
- Device code phishing, AiTM campaigns, and Microsoft 365 authentication abuse
- ClickFix-style execution chains involving PowerShell, MSBuild, script interpreters, or trusted Windows utilities
- Newly observed domains, DNS tunneling, Outlook- or browser-based C2 channels, and rapidly changing infrastructure
- Unauthorized package updates, developer dependencies, browser extensions, SDKs, and software repositories
- Remote administration tools, custom loaders, and malware communicating through trusted cloud services
Quick Wins
- Strengthen phishing-resistant authentication and monitor for suspicious OAuth, device code, and session activity
- Expand detection coverage for ClickFix techniques and script-based execution from user-accessible directories
- Monitor outbound DNS, Outlook, browser, and cloud-service traffic for unusual command-and-control behavior
- Verify software dependencies, package updates, browser extensions, and developer tooling before deployment
- Continuously enrich detections with current malicious domains, URLs, IPs, and C2 infrastructure to identify emerging campaigns earlier
Key Insight: This reporting period highlighted a continued shift away from traditional exploit-driven intrusions toward attacks that abuse trusted identities, legitimate services, and widely used platforms. At the same time, researchers placed greater emphasis on uncovering attacker infrastructure and command-and-control techniques, giving defenders more opportunities to detect campaigns through behavioral patterns rather than malware signatures alone.
Articles
Late July 2026 Cyber Threat Reports highlight the latest threat research published between July 14 and July 28, 2026. This edition covers ransomware operations, advanced phishing campaigns, supply chain compromises, malware and botnet analysis, APT activity, cloud and identity attacks, and technical investigations from leading security researchers, providing actionable intelligence for defenders and threat hunters.
Langflow Exploited to Build Custom DDoS Gafgyt Botnets
Source: Akamai
(Published: July 14, 2026)
This technical analysis examines Langflow Exploited to Build Custom DDoS Gafgyt Botnets, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.
Kratos PhaaS Targets US and EU Companies
Source: ANY.RUN
(Published: July 14, 2026)
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. Read more.
LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software
Source: Blackpoint Cyber
(Published: July 14, 2026)
This technical analysis examines LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links
Source: Ctrl-Alt-Intel
(Published: July 14, 2026)
This report investigates Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
Compromised AsyncAPI npm Packages
Source: Datadog Security Labs
(Published: July 14, 2026)
This research details Compromised AsyncAPI npm Packages, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
SeasonalInvite: New Phishing Campaign Abuses eCards and RMM
Source: Forescout
(Published: July 14, 2026)
This research analyzes SeasonalInvite: New Phishing Campaign Abuses eCards and RMM, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.
Signed, Sealed, Stolen: CrashStealer Slips Past Gatekeeper
Source: HivePro
(Published: July 14, 2026)
This technical analysis examines Signed, Sealed, Stolen: CrashStealer Slips Past Gatekeeper, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist
Source: Infostealers.com
(Published: July 14, 2026)
This technical analysis examines How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
Miasma Worm Returns to npm
Source: JFrog
(Published: July 14, 2026)
This research details Miasma Worm Returns to npm, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
HTTP-Basma – Clustering Verbosus Fingerprints
Source: Netomize
(Published: July 14, 2026)
This research maps HTTP-Basma – Clustering Verbosus Fingerprints, highlighting infrastructure relationships, operational patterns, and detection opportunities. Read more.
Detailed Analysis of BIRDCALL Malware Masquerading as Zangi Messenger
Source: S2W
(Published: July 14, 2026)
This technical analysis examines Detailed Analysis of BIRDCALL Malware Masquerading as Zangi Messenger, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
Injective SDK Compromised: Crypto Wallet Private Keys Stolen
Source: SlowMist
(Published: July 14, 2026)
This research details Injective SDK Compromised: Crypto Wallet Private Keys Stolen, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
Tracking Donot APT-C-35 Bangladesh Military Intrusion
Source: Cyderes
(Published: July 15, 2026)
This report investigates Tracking Donot APT-C-35 Bangladesh Military Intrusion, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
DINDoOR, DenoRAT, and NightshadeC2: TAG-150’s Evolving Tradecraft
Source: eSentire
(Published: July 15, 2026)
This report investigates DINDoOR, DenoRAT, and NightshadeC2: TAG-150’s Evolving Tradecraft, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible for the April DigiCert Incident
Source: Expel
(Published: July 15, 2026)
This research details Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible for the April DigiCert Incident, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
Source: Intel 471
(Published: July 15, 2026)
Intel 471 investigated an ongoing, multi-stage phishing operation that systematically abuses legitimate software-as-a-service sales and marketing platforms and cloud services to orchestrate corporate credential theft. Read more.
OkoBot Framework Targets Cryptocurrency Wallets
Source: Kaspersky Securelist
(Published: July 15, 2026)
This technical analysis examines OkoBot Framework Targets Cryptocurrency Wallets, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
Unpacking the AsyncAPI npm Supply-Chain Compromise
Source: Microsoft
(Published: July 15, 2026)
This research details Unpacking the AsyncAPI npm Supply-Chain Compromise, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
MuddyWater: ClickFix to Telegram & PatchAgent Backdoor
Source: Ransom-ISAC
(Published: July 15, 2026)
This report investigates MuddyWater: ClickFix to Telegram & PatchAgent Backdoor, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
Telegram Account Compromised, Wallet Swapped: macOS Malware Analysis
Source: SlowMist
(Published: July 15, 2026)
This research analyzes Telegram Account Compromised, Wallet Swapped: macOS Malware Analysis, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.
TuxBot v3: Evolution of an IoT Botnet
Source: Unit 42
(Published: July 15, 2026)
This technical analysis examines TuxBot v3: Evolution of an IoT Botnet, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.
20+ Government Websites Hijacked: PhantomEnigma Investigation
Source: ANY.RUN
(Published: July 16, 2026)
An original threat intelligence investigation uncovered how trusted government infrastructure became an attack channel, placing banking organizations and public-sector systems at risk. Read more.
UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant
Source: Cisco Talos
(Published: July 16, 2026)
This technical analysis examines UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
TELEPUZ Malware-as-a-Service Uses ClickFix
Source: Elastic Security Labs
(Published: July 16, 2026)
This technical analysis examines TELEPUZ Malware-as-a-Service Uses ClickFix, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader
Source: Fortinet
(Published: July 16, 2026)
Since late March, 2026, we have been observing large-scale campaigns that use a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER. Read more.
ClickLock Stealer: macOS Malware
Source: Group-IB
(Published: July 16, 2026)
This technical analysis examines ClickLock Stealer: macOS Malware, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
GoSerpent Backdoor in Southeast Asia
Source: Kaspersky Securelist
(Published: July 16, 2026)
This report investigates GoSerpent Backdoor in Southeast Asia, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
Hiding in Plain Ledger: Four Months of a ClickFix Operator’s Blockchain C2
Source: Melted in Hex
(Published: July 16, 2026)
To hide its command-and-control server, this operation writes the address onto a public blockchain. Read more.
ACR Stealer: Two Observed Intrusion Chains
Source: Microsoft
(Published: July 16, 2026)
This technical analysis examines ACR Stealer: Two Observed Intrusion Chains, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
StealC: A Commodity Stealer Loader
Source: Stairwell
(Published: July 16, 2026)
This technical analysis examines StealC: A Commodity Stealer Loader, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
GigaWiper: Inside a Modular Cyberweapon
Source: PolySwarm
(Published: July 17, 2026)
This technical analysis examines GigaWiper: Inside a Modular Cyberweapon, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era
Source: XLab
(Published: July 17, 2026)
This technical analysis examines NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.
Contagious Interview Malware Uses SVG Steganography
Source: Elastic Security Labs
(Published: July 18, 2026)
This report investigates Contagious Interview Malware Uses SVG Steganography, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
GitHub Poisoning Attack Disguised as Recruitment
Source: SlowMist
(Published: July 18, 2026)
This research details GitHub Poisoning Attack Disguised as Recruitment, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
Hollowgraph: Microsoft 365 Espionage
Source: Group-IB
(Published: July 20, 2026)
This research examines Hollowgraph: Microsoft 365 Espionage, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.
CloudAtlasGo Backdoor
Source: Kaspersky Securelist
(Published: July 20, 2026)
This report investigates CloudAtlasGo Backdoor, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
Fake Games Spread Stealers With Ren’Py Loader, MSBuild, and EtherHiding
Source: Malwarebytes
(Published: July 20, 2026)
This technical analysis examines Fake Games Spread Stealers With Ren’Py Loader, MSBuild, and EtherHiding, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
On-Chain Backdoor in a Malicious Trae Extension
Source: SlowMist
(Published: July 20, 2026)
This research details On-Chain Backdoor in a Malicious Trae Extension, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
Kali365 Targets US Organizations With Device Code Phishing
Source: ANY.RUN
(Published: July 21, 2026)
Kali365 is targeting US organizations with device code phishing attacks that abuse legitimate Microsoft authentication. Read more.
Click to Sync: From Google Ads Maintenance Notice to Credential Theft
Source: Cofense
(Published: July 21, 2026)
This research analyzes Click to Sync: From Google Ads Maintenance Notice to Credential Theft, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.
The Procurement Trap: An AiTM Campaign Targeting Global Institutions
Source: Infoblox
(Published: July 21, 2026)
This research analyzes The Procurement Trap: An AiTM Campaign Targeting Global Institutions, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.
Project CAV3RN: Cyberespionage Framework Using Outlook and DNS
Source: Kaspersky Securelist
(Published: July 21, 2026)
This report investigates Project CAV3RN: Cyberespionage Framework Using Outlook and DNS, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
INC Ransomware Affiliate Targets ESXi & NAS Devices in AD Environment
Source: Ctrl-Alt-Intel
(Published: July 22, 2026)
This research examines INC Ransomware Affiliate Targets ESXi & NAS Devices in AD Environment, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.
Email Bombing, IT Impersonation, Quick Assist, and Edgecution: UNC6692
Source: eSentire
(Published: July 22, 2026)
This research examines Email Bombing, IT Impersonation, Quick Assist, and Edgecution: UNC6692, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.
Inside a TrickBot Variant Using DNS Tunneling for C2
Source: Fortinet
(Published: July 22, 2026)
FortiGuard Labs recently captured several malicious samples that were sending malformed DNS queries. Read more.
FakeAgent Claude Desktop Malvertising Ends in .NET RAT
Source: Huntress
(Published: July 22, 2026)
This technical analysis examines FakeAgent Claude Desktop Malvertising Ends in .NET RAT, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
Cl0p Windchill/FlexPLM Exploitation
Source: Ransom-ISAC
(Published: July 22, 2026)
This research examines Cl0p Windchill/FlexPLM Exploitation, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.
Malicious Copilot MCP Apex npm Package Delivers macOS Infostealer
Source: SafeDep
(Published: July 22, 2026)
This research details Malicious Copilot MCP Apex npm Package Delivers macOS Infostealer, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
Rondo Meets GeoServer
Source: SANS ISC
(Published: July 22, 2026)
This analysis examines Rondo Meets GeoServer, including observed exploitation activity, post-exploitation behavior, and relevant defensive guidance. Read more.
Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel
Source: Cisco Talos
(Published: July 23, 2026)
This research examines Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.
JadeProx: China-Nexus TRIBACK Loader
Source: Group-IB
(Published: July 23, 2026)
This report investigates JadeProx: China-Nexus TRIBACK Loader, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
TA488 Targets Zimbra Mail Servers With Half-Click Exploits
Source: Proofpoint
(Published: July 23, 2026)
This report investigates TA488 Targets Zimbra Mail Servers With Half-Click Exploits, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
Russian Webmail Espionage
Source: Unit 42
(Published: July 23, 2026)
Unit 42 has observed a persistent cyberespionage campaign it tracks as CL-STA-1114. Read more.
The Gentlemen RaaS: Origins, OPSEC & OSINT
Source: Ctrl-Alt-Intel
(Published: July 24, 2026)
This research examines The Gentlemen RaaS: Origins, OPSEC & OSINT, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.
Inside a DPRK BlueNoroff ClickFix Kit
Source: JUMPSEC
(Published: July 24, 2026)
This report investigates Inside a DPRK BlueNoroff ClickFix Kit, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.
MrMustard Malicious PyPI Package
Source: SafeDep
(Published: July 24, 2026)
This research details MrMustard Malicious PyPI Package, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.
Dysphoria Botnet Evolution and Technical Analysis
Source: XLab
(Published: July 25, 2026)
This technical analysis examines Dysphoria Botnet Evolution and Technical Analysis, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.
From Compliant Emails to Remote Control: A Web3 Investigation
Source: SlowMist
(Published: July 26, 2026)
This research examines From Compliant Emails to Remote Control: A Web3 Investigation, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.
The Zedxion Corporate Nexus
Source: DomainTools
(Published: July 27, 2026)
This research maps The Zedxion Corporate Nexus, highlighting infrastructure relationships, operational patterns, and detection opportunities. Read more.
The Telegram Malware Ecosystem
Source: Ransom-ISAC
(Published: July 27, 2026)
This technical analysis examines The Telegram Malware Ecosystem, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.
Want more articles? Check out the previous edition of Security Signals here.Â
Free Evaluation
Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.
Take advantage of a free trial to test our data for yourself.
