Security Signals (8/11/26-8/25/26)
Welcome to Security Signals
Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.
For more articles, check out our #onpatrol4malware blog.
Our Latest Blog Post
July 2026 Edition
Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.
Insights (TL;DR)
To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.
Top ATT&CK Techniques Observed
T1566 – Phishing: Credential phishing, fake downloads, social engineering, and ClickFix-style lures remained common initial-access methods.
T1071 – Application Layer Protocol: Threat actors continued using legitimate services and unconventional channels, including GitHub, Microsoft 365, DNS, ICMP, and FTP infrastructure for C2.
T1195 – Supply Chain Compromise: Developer ecosystems remained a target, with malicious packages, extensions, and software distribution mechanisms appearing across several campaigns.
What Matters Most
Attackers continued moving C2 and malware delivery into trusted or less-monitored infrastructure. Cloud platforms, developer services, compromised websites, and legitimate remote-access tools repeatedly appeared in the reporting.
Credential and information theft also remained prominent, alongside espionage operations targeting government, telecommunications, and other sensitive organizations.
What Defenders Should Watch
- C2 traffic using legitimate cloud services or unusual protocols
- ClickFix, fake software downloads, and productivity-tool impersonation
- Unexpected packages, extensions, remote-access tools, and software updates
- Credential theft followed by session or account abuse
Key Insight: The recurring theme this period was attackers hiding malicious activity inside infrastructure and services organizations already trust, making context and behavioral detection increasingly important.
Articles
Late August 2026 Cyber Threat Reports highlight continued experimentation with C2 infrastructure, credential theft, software supply chain attacks, and phishing-based initial access. Research from August 12–24 also documents new malware families, espionage campaigns, abuse of trusted cloud and developer services, and techniques designed to conceal malicious traffic within legitimate infrastructure.
Beware of phishing emails disguised as requests to review quotes (PhantomStealer)
Source: AhnLab
(Published: 12 August 2026)
The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. Read more.
Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme
Source: Group-IB
(Published: 12 August 2026)
Group-IB analyzes the threat activity, techniques, and infrastructure described in Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme. Read more.
Akira Hits Safe Mode: Ransomware Rebooting Around EDR
Source: Huntress
(Published: 12 August 2026)
Huntress analyzes the threat activity, techniques, and infrastructure described in Akira Hits Safe Mode: Ransomware Rebooting Around EDR. Read more.
AmnesiaStealer: macOS Infostealer That Hijacks Browsers
Source: Jamf Threat Labs
(Published: 13 August 2026)
Jamf Threat Labs analyzes the threat activity, techniques, and infrastructure described in AmnesiaStealer: macOS Infostealer That Hijacks Browsers. Read more.
Dissecting the JWR phishing framework
Source: Cisco Talos
(Published: 13 August 2026)
JWR is a phishing framework capable of harvesting complete payment card data, login credentials, and personally identifiable information (PII) documents and images in real time. Read more.
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
Source: Security.com
(Published: 13 August 2026)
Security.com examines Jewelbug, a China-based threat group linked to government and military espionage as well as cryptocurrency fraud, with both activities tied to shared operational infrastructure. Read more.
Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps
Source: iVerify
(Published: 13 August 2026)
iVerify analyzes the threat activity, techniques, and infrastructure described in Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps. Read more.
Multi-Functional Linux Botnet “Evooo1Bot”
Source: Fortinet
(Published: 13 August 2026)
Fortinet analyzes the threat activity, techniques, and infrastructure described in Multi-Functional Linux Botnet “Evooo1Bot”. Read more.
Expired Malicious Domains Bring New Threats to Life
Source: Infoblox
(Published: 13 August 2026)
Infoblox analyzes the threat activity, techniques, and infrastructure described in Expired Malicious Domains Bring New Threats to Life. Read more.
Signed, sealed, injected: The mechanics of DCRat in 2026
Source: Trellix
(Published: 13 August 2026)
Trellix analyzes the threat activity, techniques, and infrastructure described in Signed, sealed, injected: The mechanics of DCRat in 2026. Read more.
When SQL Server Becomes the Initial Launcher: A Deep Dive into Weaxor Ransomware Execution
Source: K7 Labs
(Published: 13 August 2026)
Recent threat intelligence highlights a sophisticated Weaxor Ransomware deployment strategy utilizing high-privilege application abuse and layered in-memory evasion. Read more.
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
Source: Acronis
(Published: 13 August 2026)
Acronis analyzes the threat activity, techniques, and infrastructure described in PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure. Read more.
CoolClient backdoor goes deeper: HoneyMyte adds Windows kernel rootkit
Source: Kaspersky Securelist
(Published: 14 August 2026)
Kaspersky Securelist analyzes the threat activity, techniques, and infrastructure described in CoolClient backdoor goes deeper: HoneyMyte adds Windows kernel rootkit. Read more.
A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace
Source: Gen Digital
(Published: 14 August 2026)
Gen Digital analyzes the threat activity, techniques, and infrastructure described in A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace. Read more.
npm Bin Entry Harvesting: A Dependency Confusion Blind Spot
Source: SafeDep
(Published: 14 August 2026)
SafeDep analyzes the threat activity, techniques, and infrastructure described in npm Bin Entry Harvesting: A Dependency Confusion Blind Spot. Read more.
Detect ICMP-Ghost Implant ICMP and DNS Tunnelling C2 Traffic Using PacketSmith Yara-X & ICMP Detection Modules
Source: Netomize
(Published: 14 August 2026)
Netomize analyzes the ICMP-Ghost tunneling framework and develops network detections for its ICMPv4 and DNS command-and-control channels. Read more.
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor
Source: Seqrite
(Published: 17 August 2026)
Seqrite analyzes the threat activity, techniques, and infrastructure described in Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor. Read more.
C2Looper Backdoor Uses GitHub for C2
Source: Zscaler ThreatLabz
(Published: 17 August 2026)
Zscaler ThreatLabz analyzes the threat activity, techniques, and infrastructure described in C2Looper Backdoor Uses GitHub for C2. Read more.
Rapid7 Labs: the Anatomy of a Crypto Fraud Pipeline
Source: Rapid7
(Published: 17 August 2026)
Rapid7 reconstructs Operation ASTERIX from an exposed attacker directory containing lead data, phishing panels, vishing tools, fake cryptocurrency wallet apps, persistence mechanisms, and Telegram exfiltration code. Read more.
Projextor: Malware Disguised as Productivity Software
Source: G DATA
(Published: 17 August 2026)
G DATA analyzes Projextor, a cluster of trojanized Electron productivity applications that conceal malicious functionality behind working PDF converters, meal planners, and similar tools. Read more.
Kimsuky Expands AI Capabilities Through a Local AI Development Environment in Operation GitPower
Source: PolySwarm
(Published: 17 August 2026)
Researchers identified a continuation of the North Korean Kimsuky cyber espionage campaign, designated Operation GitPower, which combines established spear-phishing techniques with emerging artificial intelligence capabilities. Read more.
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Source: Check Point Research
(Published: 18 August 2026)
Check Point Research analyzes StopAndProtect, an operation that uses compromised WordPress sites for malware delivery and C2 while combining data theft with ransomware and other malicious components. Read more.
Inside the Aisuru Botnet: DDoS, ADB and Proxyware
Source: Bitsight
(Published: 18 August 2026)
Bitsight analyzes the threat activity, techniques, and infrastructure described in Inside the Aisuru Botnet: DDoS, ADB and Proxyware. Read more.
Signed Overwolf Binary Sideloads ValleyRAT Malware in India
Source: Forcepoint X-Labs
(Published: 18 August 2026)
Forcepoint X-Labs analyzes the threat activity, techniques, and infrastructure described in Signed Overwolf Binary Sideloads ValleyRAT Malware in India. Read more.
Living Off the Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 & Azure
Source: Ontinue
(Published: 18 August 2026)
Ontinue analyzes the threat activity, techniques, and infrastructure described in Living Off the Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 & Azure. Read more.
WordlistLoader Delivering Amatera via ClearFake Campaigns
Source: Gen Digital
(Published: 18 August 2026)
Gen Threat Labs examines WordlistLoader, a loader used in ClearFake campaigns to deliver Amatera Stealer while encoding shellcode as ordinary English words or UUIDs to complicate detection. Read more.
Clop Returns With Custom Implant in Mass Extortion Campaign
Source: ReliaQuest
(Published: 18 August 2026)
ReliaQuest analyzes a custom web shell linked to Clop that targets PTC Windchill, providing built-in credential theft, file discovery, data exfiltration, and extensible in-memory code execution. Read more.
Arsenal Revamped: Core Werewolf Hits Russian Organizations With CoreRAT
Source: BI.ZONE
(Published: 18 August 2026)
BI.ZONE analyzes the threat activity, techniques, and infrastructure described in Arsenal Revamped: Core Werewolf Hits Russian Organizations With CoreRAT. Read more.
Mirage2FA: A Phishing Threat to US Companies with 4K Victims
Source: ANY.RUN
(Published: 18 August 2026)
ANY.RUN analyzes the threat activity, techniques, and infrastructure described in Mirage2FA: A Phishing Threat to US Companies with 4K Victims. Read more.
SilkParasite: Tracking a China-Nexus APT Across Central Asia
Source: Bitdefender
(Published: 19 August 2026)
Bitdefender analyzes the threat activity, techniques, and infrastructure described in SilkParasite: Tracking a China-Nexus APT Across Central Asia. Read more.
Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
Source: Huntress
(Published: 19 August 2026)
Large industry events like Black Hat and DEF CON create a target-rich environment for bad actors, with attendees exchanging new contacts, documents, invitations, and follow-up plans. Read more.
Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking
Source: Group-IB
(Published: 19 August 2026)
Group-IB analyzes the threat activity, techniques, and infrastructure described in Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking. Read more.
Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra – Killing Your EDR Since 2025
Source: eSentire
(Published: 19 August 2026)
eSentire analyzes the threat activity, techniques, and infrastructure described in Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra – Killing Your EDR Since 2025. Read more.
Beware of Solidity Pro: A Targeted Poisoning Attack on Web3 Developers
Source: SlowMist
(Published: 19 August 2026)
SlowMist investigates malicious activity tied to the Solidity Pro VS Code extension, including credential harvesting, remote payload execution, and remote extension update capabilities targeting Web3 developers. Read more.
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Source: Acronis
(Published: 19 August 2026)
Acronis analyzes the threat activity, techniques, and infrastructure described in Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign. Read more.
AI-Agent-Driven Offensive Operation
Source: CloudSEK
(Published: 19 August 2026)
CloudSEK analyzes the threat activity, techniques, and infrastructure described in AI-Agent-Driven Offensive Operation. Read more.
41 deceptive download sites show a real link, then send you somewhere else
Source: Malwarebytes
(Published: 19 August 2026)
Malwarebytes analyzes the threat activity, techniques, and infrastructure described in 41 deceptive download sites show a real link, then send you somewhere else. Read more.
Trapping a Mustang Panda
Source: IBM X-Force
(Published: 20 August 2026)
IBM X-Force analyzes the threat activity, techniques, and infrastructure described in Trapping a Mustang Panda. Read more.
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
Source: Cisco Talos
(Published: 20 August 2026)
In our previous blog, Cisco Talos documented how UAT-10147 operationalized AI-assisted exploitation workflows to compromise internet-facing IIS and Linux servers at scale. Read more.
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Source: Cisco Talos
(Published: 20 August 2026)
Cisco Talos analyzes the threat activity, techniques, and infrastructure described in UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations. Read more.
Compromised Rust crates on crates.io silently execute malware at build time
Source: JFrog
(Published: 20 August 2026)
The JFrog security research team has identified a compromise in 3 widely used Rust crates on crates.io: arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9. Read more.
Manic: Blend between Banking Malware & Spyware
Source: ThreatFabric
(Published: 20 August 2026)
ThreatFabric analyzes the threat activity, techniques, and infrastructure described in Manic: Blend between Banking Malware & Spyware. Read more.
How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else’s Product
Source: Silent Push
(Published: 20 August 2026)
Silent Push investigates the relationship between Peer2Profit and Astroproxy, showing how bandwidth-sharing software can turn residential and corporate IP addresses into commercially resold proxy nodes. Read more.
N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled “go-titan,” and how to hunt for it
Source: Datadog Security Labs
(Published: 20 August 2026)
Datadog Security Labs analyzes the threat activity, techniques, and infrastructure described in N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled “go-titan,” and how to hunt for it. Read more.
Inside Kimsuky’s Abuse of Legitimate Remote Control Tools Across Northeast Asia
Source: ENKI
(Published: 20 August 2026)
ENKI WhiteHat analyzes Kimsuky spear-phishing campaigns targeting South Korean and Japanese victims, including abuse of OneDrive links, PowerShell, Chrome Remote Desktop, AnyDesk, and a malicious Gmail-stealing extension. Read more.
WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware
Source: McAfee Labs
(Published: 20 August 2026)
McAfee Labs analyzes the threat activity, techniques, and infrastructure described in WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware. Read more.
SynkLoader: when you throw in everything but the kitchen sink
Source: Expel
(Published: 20 August 2026)
Expel analyzes the threat activity, techniques, and infrastructure described in SynkLoader: when you throw in everything but the kitchen sink. Read more.
First Android malware targeting automotive head units
Source: Kaspersky Securelist
(Published: 21 August 2026)
Kaspersky Securelist analyzes the threat activity, techniques, and infrastructure described in First Android malware targeting automotive head units. Read more.
FireClient Evolves: MSI-Based Deployment in Teams Attacks
Source: BlueVoyant
(Published: 21 August 2026)
BlueVoyant analyzes the threat activity, techniques, and infrastructure described in FireClient Evolves: MSI-Based Deployment in Teams Attacks. Read more.
FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
Source: SOCRadar
(Published: 21 August 2026)
SOCRadar documents threat actors abusing FTP server banners as dead-drop resolvers for malicious commands and links the technique to two previously undocumented RATs. Read more.
Chinese Malware Delivery Domains Part V
Source: DomainTools
(Published: 21 August 2026)
In Parts I-IV of this series, we reported on a large-scale malware delivery network targeting Chinese speaking users. Read more.
AmnesiaStealer Introduces Interactive Browser Session Hijacking to macOS
Source: PolySwarm
(Published: 21 August 2026)
PolySwarm analyzes the threat activity, techniques, and infrastructure described in AmnesiaStealer Introduces Interactive Browser Session Hijacking to macOS. Read more.
CNCMachineRMS C2 Protocol
Source: Netresec
(Published: 21 August 2026)
Netresec analyzes the threat activity, techniques, and infrastructure described in CNCMachineRMS C2 Protocol. Read more.
Tracking PavinLoader across ClickFix and fake download campaigns
Source: Malwarebytes
(Published: 24 August 2026)
In our previous analysis of the malicious RenPy campaigns, we identified an infostealer being deployed through a loader we now track as PavinLoader. Read more.
When Trust Becomes the Payload in a Fake Codex ClickFix Campaign
Source: Cato Networks
(Published: 24 August 2026)
Cato CTRL analyzes a fake Codex download campaign that uses sponsored search results, Google Sites, and ClickFix instructions to trick macOS users into executing a multi-stage malware chain. Read more.
Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain
Source: SOCRadar
(Published: 24 August 2026)
SOCRadar investigates AnonyMousKIT, an AI-enabled phishing-as-a-service ecosystem built to steal Apple credentials and disable Activation Lock on stolen devices through email, messaging, and AI-assisted vishing. Read more.
Want more articles? Check out the previous edition of Security Signals here.
Free Evaluation
Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.
Take advantage of a free trial to test our data for yourself.

