Security Signals (8/11/26-8/25/26)

?

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

?

Our Latest Blog Post

July 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.

 

Top ATT&CK Techniques Observed

T1566 – Phishing: Credential phishing, fake downloads, social engineering, and ClickFix-style lures remained common initial-access methods.

T1071 – Application Layer Protocol: Threat actors continued using legitimate services and unconventional channels, including GitHub, Microsoft 365, DNS, ICMP, and FTP infrastructure for C2.

T1195 – Supply Chain Compromise: Developer ecosystems remained a target, with malicious packages, extensions, and software distribution mechanisms appearing across several campaigns.

What Matters Most

Attackers continued moving C2 and malware delivery into trusted or less-monitored infrastructure. Cloud platforms, developer services, compromised websites, and legitimate remote-access tools repeatedly appeared in the reporting.

Credential and information theft also remained prominent, alongside espionage operations targeting government, telecommunications, and other sensitive organizations.

What Defenders Should Watch

  • C2 traffic using legitimate cloud services or unusual protocols
  • ClickFix, fake software downloads, and productivity-tool impersonation
  • Unexpected packages, extensions, remote-access tools, and software updates
  • Credential theft followed by session or account abuse

Key Insight: The recurring theme this period was attackers hiding malicious activity inside infrastructure and services organizations already trust, making context and behavioral detection increasingly important.

Articles

Late August 2026 Cyber Threat Reports highlight continued experimentation with C2 infrastructure, credential theft, software supply chain attacks, and phishing-based initial access. Research from August 12–24 also documents new malware families, espionage campaigns, abuse of trusted cloud and developer services, and techniques designed to conceal malicious traffic within legitimate infrastructure.

Beware of phishing emails disguised as requests to review quotes (PhantomStealer)

Source: AhnLab
(Published: 12 August 2026)
The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. Read more.


Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme

Source: Group-IB
(Published: 12 August 2026)
Group-IB analyzes the threat activity, techniques, and infrastructure described in Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme. Read more.


Akira Hits Safe Mode: Ransomware Rebooting Around EDR

Source: Huntress
(Published: 12 August 2026)
Huntress analyzes the threat activity, techniques, and infrastructure described in Akira Hits Safe Mode: Ransomware Rebooting Around EDR. Read more.


AmnesiaStealer: macOS Infostealer That Hijacks Browsers

Source: Jamf Threat Labs
(Published: 13 August 2026)
Jamf Threat Labs analyzes the threat activity, techniques, and infrastructure described in AmnesiaStealer: macOS Infostealer That Hijacks Browsers. Read more.


Dissecting the JWR phishing framework

Source: Cisco Talos
(Published: 13 August 2026)
JWR is a phishing framework capable of harvesting complete payment card data, login credentials, and personally identifiable information (PII) documents and images in real time. Read more.


Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

Source: Security.com
(Published: 13 August 2026)
Security.com examines Jewelbug, a China-based threat group linked to government and military espionage as well as cryptocurrency fraud, with both activities tied to shared operational infrastructure. Read more.


Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps

Source: iVerify
(Published: 13 August 2026)
iVerify analyzes the threat activity, techniques, and infrastructure described in Octagon: A New Android Bot Targeting Crypto Wallets and Banking Apps. Read more.


Multi-Functional Linux Botnet “Evooo1Bot”

Source: Fortinet
(Published: 13 August 2026)
Fortinet analyzes the threat activity, techniques, and infrastructure described in Multi-Functional Linux Botnet “Evooo1Bot”. Read more.


Expired Malicious Domains Bring New Threats to Life

Source: Infoblox
(Published: 13 August 2026)
Infoblox analyzes the threat activity, techniques, and infrastructure described in Expired Malicious Domains Bring New Threats to Life. Read more.


Signed, sealed, injected: The mechanics of DCRat in 2026

Source: Trellix
(Published: 13 August 2026)
Trellix analyzes the threat activity, techniques, and infrastructure described in Signed, sealed, injected: The mechanics of DCRat in 2026. Read more.


When SQL Server Becomes the Initial Launcher: A Deep Dive into Weaxor Ransomware Execution

Source: K7 Labs
(Published: 13 August 2026)
Recent threat intelligence highlights a sophisticated Weaxor Ransomware deployment strategy utilizing high-privilege application abuse and layered in-memory evasion. Read more.


PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

Source: Acronis
(Published: 13 August 2026)
Acronis analyzes the threat activity, techniques, and infrastructure described in PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure. Read more.


CoolClient backdoor goes deeper: HoneyMyte adds Windows kernel rootkit

Source: Kaspersky Securelist
(Published: 14 August 2026)
Kaspersky Securelist analyzes the threat activity, techniques, and infrastructure described in CoolClient backdoor goes deeper: HoneyMyte adds Windows kernel rootkit. Read more.


A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace

Source: Gen Digital
(Published: 14 August 2026)
Gen Digital analyzes the threat activity, techniques, and infrastructure described in A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace. Read more.


npm Bin Entry Harvesting: A Dependency Confusion Blind Spot

Source: SafeDep
(Published: 14 August 2026)
SafeDep analyzes the threat activity, techniques, and infrastructure described in npm Bin Entry Harvesting: A Dependency Confusion Blind Spot. Read more.


Detect ICMP-Ghost Implant ICMP and DNS Tunnelling C2 Traffic Using PacketSmith Yara-X & ICMP Detection Modules

Source: Netomize
(Published: 14 August 2026)
Netomize analyzes the ICMP-Ghost tunneling framework and develops network detections for its ICMPv4 and DNS command-and-control channels. Read more.


Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor

Source: Seqrite
(Published: 17 August 2026)
Seqrite analyzes the threat activity, techniques, and infrastructure described in Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor. Read more.


C2Looper Backdoor Uses GitHub for C2

Source: Zscaler ThreatLabz
(Published: 17 August 2026)
Zscaler ThreatLabz analyzes the threat activity, techniques, and infrastructure described in C2Looper Backdoor Uses GitHub for C2. Read more.


Rapid7 Labs: the Anatomy of a Crypto Fraud Pipeline

Source: Rapid7
(Published: 17 August 2026)
Rapid7 reconstructs Operation ASTERIX from an exposed attacker directory containing lead data, phishing panels, vishing tools, fake cryptocurrency wallet apps, persistence mechanisms, and Telegram exfiltration code. Read more.


Projextor: Malware Disguised as Productivity Software

Source: G DATA
(Published: 17 August 2026)
G DATA analyzes Projextor, a cluster of trojanized Electron productivity applications that conceal malicious functionality behind working PDF converters, meal planners, and similar tools. Read more.


Kimsuky Expands AI Capabilities Through a Local AI Development Environment in Operation GitPower

Source: PolySwarm
(Published: 17 August 2026)
Researchers identified a continuation of the North Korean Kimsuky cyber espionage campaign, designated Operation GitPower, which combines established spear-phishing techniques with emerging artificial intelligence capabilities. Read more.


Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect

Source: Check Point Research
(Published: 18 August 2026)
Check Point Research analyzes StopAndProtect, an operation that uses compromised WordPress sites for malware delivery and C2 while combining data theft with ransomware and other malicious components. Read more.


Inside the Aisuru Botnet: DDoS, ADB and Proxyware

Source: Bitsight
(Published: 18 August 2026)
Bitsight analyzes the threat activity, techniques, and infrastructure described in Inside the Aisuru Botnet: DDoS, ADB and Proxyware. Read more.


Signed Overwolf Binary Sideloads ValleyRAT Malware in India

Source: Forcepoint X-Labs
(Published: 18 August 2026)
Forcepoint X-Labs analyzes the threat activity, techniques, and infrastructure described in Signed Overwolf Binary Sideloads ValleyRAT Malware in India. Read more.


Living Off the Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 & Azure

Source: Ontinue
(Published: 18 August 2026)
Ontinue analyzes the threat activity, techniques, and infrastructure described in Living Off the Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 & Azure. Read more.


WordlistLoader Delivering Amatera via ClearFake Campaigns

Source: Gen Digital
(Published: 18 August 2026)
Gen Threat Labs examines WordlistLoader, a loader used in ClearFake campaigns to deliver Amatera Stealer while encoding shellcode as ordinary English words or UUIDs to complicate detection. Read more.


Clop Returns With Custom Implant in Mass Extortion Campaign

Source: ReliaQuest
(Published: 18 August 2026)
ReliaQuest analyzes a custom web shell linked to Clop that targets PTC Windchill, providing built-in credential theft, file discovery, data exfiltration, and extensible in-memory code execution. Read more.


Arsenal Revamped: Core Werewolf Hits Russian Organizations With CoreRAT

Source: BI.ZONE
(Published: 18 August 2026)
BI.ZONE analyzes the threat activity, techniques, and infrastructure described in Arsenal Revamped: Core Werewolf Hits Russian Organizations With CoreRAT. Read more.


Mirage2FA: A Phishing Threat to US Companies with 4K Victims

Source: ANY.RUN
(Published: 18 August 2026)
ANY.RUN analyzes the threat activity, techniques, and infrastructure described in Mirage2FA: A Phishing Threat to US Companies with 4K Victims. Read more.


SilkParasite: Tracking a China-Nexus APT Across Central Asia

Source: Bitdefender
(Published: 19 August 2026)
Bitdefender analyzes the threat activity, techniques, and infrastructure described in SilkParasite: Tracking a China-Nexus APT Across Central Asia. Read more.


Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware

Source: Huntress
(Published: 19 August 2026)
Large industry events like Black Hat and DEF CON create a target-rich environment for bad actors, with attendees exchanging new contacts, documents, invitations, and follow-up plans. Read more.


Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking

Source: Group-IB
(Published: 19 August 2026)
Group-IB analyzes the threat activity, techniques, and infrastructure described in Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking. Read more.


Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra – Killing Your EDR Since 2025

Source: eSentire
(Published: 19 August 2026)
eSentire analyzes the threat activity, techniques, and infrastructure described in Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra – Killing Your EDR Since 2025. Read more.


Beware of Solidity Pro: A Targeted Poisoning Attack on Web3 Developers

Source: SlowMist
(Published: 19 August 2026)
SlowMist investigates malicious activity tied to the Solidity Pro VS Code extension, including credential harvesting, remote payload execution, and remote extension update capabilities targeting Web3 developers. Read more.


Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

Source: Acronis
(Published: 19 August 2026)
Acronis analyzes the threat activity, techniques, and infrastructure described in Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign. Read more.


AI-Agent-Driven Offensive Operation

Source: CloudSEK
(Published: 19 August 2026)
CloudSEK analyzes the threat activity, techniques, and infrastructure described in AI-Agent-Driven Offensive Operation. Read more.


41 deceptive download sites show a real link, then send you somewhere else

Source: Malwarebytes
(Published: 19 August 2026)
Malwarebytes analyzes the threat activity, techniques, and infrastructure described in 41 deceptive download sites show a real link, then send you somewhere else. Read more.


Trapping a Mustang Panda

Source: IBM X-Force
(Published: 20 August 2026)
IBM X-Force analyzes the threat activity, techniques, and infrastructure described in Trapping a Mustang Panda. Read more.


UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

Source: Cisco Talos
(Published: 20 August 2026)
In our previous blog, Cisco Talos documented how UAT-10147 operationalized AI-assisted exploitation workflows to compromise internet-facing IIS and Linux servers at scale. Read more.


UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Source: Cisco Talos
(Published: 20 August 2026)
Cisco Talos analyzes the threat activity, techniques, and infrastructure described in UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations. Read more.


Compromised Rust crates on crates.io silently execute malware at build time

Source: JFrog
(Published: 20 August 2026)
The JFrog security research team has identified a compromise in 3 widely used Rust crates on crates.io: arrayref@0.3.10, internment@0.8.7, and append-only-vec@0.1.9. Read more.


Manic: Blend between Banking Malware & Spyware

Source: ThreatFabric
(Published: 20 August 2026)
ThreatFabric analyzes the threat activity, techniques, and infrastructure described in Manic: Blend between Banking Malware & Spyware. Read more.


How Peer2Profit and Astroproxy Turn Your Bandwidth Into Someone Else’s Product

Source: Silent Push
(Published: 20 August 2026)
Silent Push investigates the relationship between Peer2Profit and Astroproxy, showing how bandwidth-sharing software can turn residential and corporate IP addresses into commercially resold proxy nodes. Read more.


N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled “go-titan,” and how to hunt for it

Source: Datadog Security Labs
(Published: 20 August 2026)
Datadog Security Labs analyzes the threat activity, techniques, and infrastructure described in N4D Mesh Controller: New infrastructure, a UPX-packed agent labeled “go-titan,” and how to hunt for it. Read more.


Inside Kimsuky’s Abuse of Legitimate Remote Control Tools Across Northeast Asia

Source: ENKI
(Published: 20 August 2026)
ENKI WhiteHat analyzes Kimsuky spear-phishing campaigns targeting South Korean and Japanese victims, including abuse of OneDrive links, PowerShell, Chrome Remote Desktop, AnyDesk, and a malicious Gmail-stealing extension. Read more.


WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware

Source: McAfee Labs
(Published: 20 August 2026)
McAfee Labs analyzes the threat activity, techniques, and infrastructure described in WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware. Read more.


SynkLoader: when you throw in everything but the kitchen sink

Source: Expel
(Published: 20 August 2026)
Expel analyzes the threat activity, techniques, and infrastructure described in SynkLoader: when you throw in everything but the kitchen sink. Read more.


First Android malware targeting automotive head units

Source: Kaspersky Securelist
(Published: 21 August 2026)
Kaspersky Securelist analyzes the threat activity, techniques, and infrastructure described in First Android malware targeting automotive head units. Read more.


FireClient Evolves: MSI-Based Deployment in Teams Attacks

Source: BlueVoyant
(Published: 21 August 2026)
BlueVoyant analyzes the threat activity, techniques, and infrastructure described in FireClient Evolves: MSI-Based Deployment in Teams Attacks. Read more.


FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

Source: SOCRadar
(Published: 21 August 2026)
SOCRadar documents threat actors abusing FTP server banners as dead-drop resolvers for malicious commands and links the technique to two previously undocumented RATs. Read more.


Chinese Malware Delivery Domains Part V

Source: DomainTools
(Published: 21 August 2026)
In Parts I-IV of this series, we reported on a large-scale malware delivery network targeting Chinese speaking users. Read more.


AmnesiaStealer Introduces Interactive Browser Session Hijacking to macOS

Source: PolySwarm
(Published: 21 August 2026)
PolySwarm analyzes the threat activity, techniques, and infrastructure described in AmnesiaStealer Introduces Interactive Browser Session Hijacking to macOS. Read more.


CNCMachineRMS C2 Protocol

Source: Netresec
(Published: 21 August 2026)
Netresec analyzes the threat activity, techniques, and infrastructure described in CNCMachineRMS C2 Protocol. Read more.


Tracking PavinLoader across ClickFix and fake download campaigns

Source: Malwarebytes
(Published: 24 August 2026)
In our previous analysis of the malicious RenPy campaigns, we identified an infostealer being deployed through a loader we now track as PavinLoader. Read more.


When Trust Becomes the Payload in a Fake Codex ClickFix Campaign

Source: Cato Networks
(Published: 24 August 2026)
Cato CTRL analyzes a fake Codex download campaign that uses sponsored search results, Google Sites, and ClickFix instructions to trick macOS users into executing a multi-stage malware chain. Read more.


Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain

Source: SOCRadar
(Published: 24 August 2026)
SOCRadar investigates AnonyMousKIT, an AI-enabled phishing-as-a-service ecosystem built to steal Apple credentials and disable Activation Lock on stolen devices through email, messaging, and AI-assisted vishing. Read more.

Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (07/28/26-08/11/26)

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

Our Latest Blog Post

July 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.

Top ATT&CK Techniques Observed

T1566 – Phishing: Credential theft remained one of the primary initial access vectors, with campaigns using device code phishing, adversary-in-the-middle (AiTM) techniques, fake recruiters, Google Ads lures, procurement scams, eCards, and other social engineering methods.

T1071 – Application Layer Protocol: Threat actors increasingly relied on legitimate services and protocols—including Outlook, DNS, browsers, blockchain infrastructure, Telegram, and cloud platforms—for command-and-control to blend malicious traffic with normal network activity.

T1583 / T1584 – Acquire & Compromise Infrastructure: Multiple investigations focused on attacker-controlled infrastructure, compromised government websites, malicious domains, cloud resources, and software repositories used to support phishing, malware delivery, and command-and-control.

T1195 – Supply Chain Compromise: Software supply chain attacks remained highly active, targeting npm packages, PyPI repositories, SDKs, browser extensions, AI tooling, IDE components, and other developer ecosystems.

T1105 / T1059 – Ingress Tool Transfer & Command Execution: Researchers observed widespread use of custom loaders, remote access trojans, malware frameworks, scripting engines, ClickFix techniques, and living-off-the-land methods to establish persistence and evade detection.


What Matters Most

Identity has become the preferred attack surface. Rather than exploiting vulnerabilities, many campaigns focused on stealing credentials through phishing, adversary-in-the-middle attacks, Microsoft 365 abuse, and social engineering.

ClickFix continues to gain momentum. Multiple unrelated threat actors—including financially motivated groups, DPRK operators, and nation-state campaigns—adopted ClickFix techniques, reinforcing its emergence as a mainstream initial access method.

Trusted infrastructure is increasingly abused. Government websites, SaaS platforms, Microsoft 365, GitHub, Telegram, cloud services, and blockchain infrastructure were repeatedly leveraged to host payloads, deliver malware, or conceal command-and-control traffic.

Threat research is shifting toward infrastructure analysis. Many reports focused less on individual malware samples and more on mapping attacker infrastructure, command-and-control architecture, operational ecosystems, and attribution.


What Defenders Should Watch

  • Device code phishing, AiTM campaigns, and Microsoft 365 authentication abuse
  • ClickFix-style execution chains involving PowerShell, MSBuild, script interpreters, or trusted Windows utilities
  • Newly observed domains, DNS tunneling, Outlook- or browser-based C2 channels, and rapidly changing infrastructure
  • Unauthorized package updates, developer dependencies, browser extensions, SDKs, and software repositories
  • Remote administration tools, custom loaders, and malware communicating through trusted cloud services

Quick Wins

  • Strengthen phishing-resistant authentication and monitor for suspicious OAuth, device code, and session activity
  • Expand detection coverage for ClickFix techniques and script-based execution from user-accessible directories
  • Monitor outbound DNS, Outlook, browser, and cloud-service traffic for unusual command-and-control behavior
  • Verify software dependencies, package updates, browser extensions, and developer tooling before deployment
  • Continuously enrich detections with current malicious domains, URLs, IPs, and C2 infrastructure to identify emerging campaigns earlier

Key Insight: This reporting period highlighted a continued shift away from traditional exploit-driven intrusions toward attacks that abuse trusted identities, legitimate services, and widely used platforms. At the same time, researchers placed greater emphasis on uncovering attacker infrastructure and command-and-control techniques, giving defenders more opportunities to detect campaigns through behavioral patterns rather than malware signatures alone.

Articles

Early August 2026 Cyber Threat Reports highlight the latest threat research published between July 28 and August 11, 2026. This edition covers software supply chain attacks, ClickFix campaigns, ransomware, botnets, phishing, APT activity, blockchain-based command-and-control, and credential theft across enterprise and developer environments.

Chaos in Teams: Vishing

Source: Sophos
(Published: 28 July 2026)
Sophos analysts investigated a Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 that used a consistent set of IT-themed cloud domains and personas… Read more.


SilverFox Evolves

Source: Cato Networks
(Published: 28 July 2026)
SilverFox is expanding its toolkit. Read more.


Phantom Stealer: Shellcode, Steganography and Credential Theft

Source: Splunk
(Published: 28 July 2026)
STRT observed that Phantom Stealer leverages multiple loader variants to deliver its payload. Read more.


Joyfill npm Supply Chain Compromise

Source: StepSecurity
(Published: 28 July 2026)
On July 28, 2026, malicious beta versions of two Joyfill npm packages, @joyfill/components and @joyfill/layouts, were published to the npm registry. Read more.


A New RAT in the Valley: SafeRAT

Source: ExaTrack
(Published: 28 July 2026)
This article details a new malicious code, SafeRat, which we attribute to the APT group Silver Fox. Read more.


ClickFix Keeps Evolving: Rundll32 Ordinal Execution Over WebDAV

Source: CyberProof
(Published: 28 July 2026)
The CyberProof Threat Research Team has tracked a ClickFix variant that pushes execution deep into trusted Windows components. Read more.


SonicWall Credential Stuffing Campaign

Source: Huntress
(Published: 28 July 2026)
Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins… Read more.


MacSync Stealer RAT Reverse Engineering

Source: Huntress
(Published: 29 July 2026)
In mid-July, Huntress investigated a macOS intrusion in which the victim thought they were installing Claude, but instead ran a full stealer and remote access… Read more.


Inside Astaroth’s New Spambot Component

Source: CrowdStrike
(Published: 29 July 2026)
Established Latin American (LATAM) threat actors are continuously adapting their malware capabilities and attack methodologies to circumvent defensive measures and maintain effectiveness against target environments. Read more.


TA488 Comes for Outlook With Another Half-Click Exploit

Source: Proofpoint
(Published: 29 July 2026)
On 22 July 2026, TA488 initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). Read more.


Amazon Identifies North Korean Hacker Group Behind Open Source Supply Chain Attacks

Source: AWS
(Published: 29 July 2026)
Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries… Read more.


Dysphoria Botnet Evolution and Technical Analysis

Source: Qianxin XLab
(Published: 29 July 2026)
Since Q1 2026, XLab has been continuously tracking an emerging botnet family named Dysphoria whose bot population exceeds 200,000. Read more.


WP2Shell WordPress Exploit: Technical Analysis and Real Attack Data

Source: Wordfence
(Published: 29 July 2026)
On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by unauthenticated attackers… Read more.


Autonomous AI Cyber Attack Campaign

Source: Unit 42
(Published: 30 July 2026)
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. Read more.


HollowFrames: Layered Loader and Matryoshka Backdoors

Source: Blackpoint Cyber
(Published: 30 July 2026)
HollowFrame established a durable execution layer by combining persistence with multiple payload launching techniques, while Matryoshka extended… Read more.


XMRig Covert Linux PAM Abuse

Source: Group-IB
(Published: 30 July 2026)
In May 2026, a highly covert Monero (XMR) cryptomining campaign was identified, leveraging advanced stealth techniques to infiltrate and persist within targeted Linux environments. Read more.


GenieLocker Ransomware for Windows, Linux and ESXi

Source: Kaspersky Securelist
(Published: 30 July 2026)
The new GenieLocker ransomware family has been active since March 2026. Read more.


OCTLurk and SilkLurk Backdoors in Central Asia

Source: Kaspersky Securelist
(Published: 30 July 2026)
We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Read more.


Cl0p Targets Windchill

Source: Censys
(Published: 30 July 2026)
On July 22, 2026, ReliaQuest reported observations of a threat actor exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting PTC Windchill and FlexPLM. Read more.


XCSSET v4.0 Malware Analysis

Source: Unit 42
(Published: 31 July 2026)
After months of dormancy, the attackers behind the XCSSET malware released version 40 (v40), targeting the macOS ecosystem. Read more.


DarkSword’s Panel Sprawl

Source: Censys
(Published: 31 July 2026)
DarkSword is a commercial iOS exploit chain, six chained vulnerabilities spanning iOS 18.4 through 18.7, that leaked publicly via a GitHub repository… Read more.


CaptiveCrunch: Midnight Blizzard Targets Travelers Worldwide

Source: Microsoft
(Published: 31 July 2026)
Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks… Read more.


Polinrider Caused Dozens of npm and Go Compromises

Source: OpenSourceMalware
(Published: 31 July 2026)
That PolinRider connection grabbed my attention, because that campaign isn’t really known for compromising legitimate packages. Read more.


Snowlight Government Chinese Campaign

Source: SOCRadar
(Published: 31 July 2026)
SOCRadar Threat Research Unit (STRU) identified and analyzed an exposed adversary-operated staging server containing a full attack infrastructure… Read more.


From WSProxy to Root: INC Ransomware and SonicWall SMA Exploit Chain

Source: Resecurity
(Published: 1 August 2026)
Virtual private network (VPN) appliances occupy one of the most sensitive positions in modern enterprise architecture: the boundary between the untrusted public internet and the internal corporate… Read more.


NullReceiver DPRK C2 Technique

Source: OpenSourceMalware
(Published: 2 August 2026)
We just identified a new blockchain-based command-and-control technique hiding inside two trojanized npm packages, bianira-ui and fluid-type-ui. Read more.


DoubleCup ClickFix Loader and DeviceManager RATs

Source: SOCRadar
(Published: 3 August 2026)
SOCRadar’s Threat Research Unit (STRU) identified and analyzed DOUBLECUP, a Russian Loader-as-a-Service (LaaS) for ClickFix campaigns. Read more.


Developers in the Crosshairs: Fake AI Tools Deliver Infostealer

Source: Netskope
(Published: 3 August 2026)
In April 2026, Netskope Threat Labs reported a Windows-based Malware-as-a-Service (MaaS) infostealer delivered through the “Clickfix” social engineering tactic. Read more.


Targeted Attack Against Government Entities in the Middle East – Part 2

Source: Zscaler
(Published: 3 August 2026)
This is Part 2 of our two-part technical analysis on new tools used by an East Asia-linked threat actor targeting government entities in the Middle East. Read more.


Inside a Russian-Speaking Access Broker’s Dual Operation

Source: CloudSEK
(Published: 3 August 2026)
An exposed server owned by a Russia-nexus threat actor revealed months of activity from a high-volume initial access broker. Read more.


N-able Vulnerability Exploitation

Source: Huntress
(Published: 3 August 2026)
On August 1–2, 2026, N-able disclosed a critical vulnerability in N-central, its flagship remote monitoring and management (RMM) platform… Read more.


Smoke Screen: ScreenConnect RMM Abuse and Cloudflare Tunnels

Source: Securonix
(Published: 4 August 2026)
Securonix Threat Research has been tracking an active, multi-wave campaign we are calling SMOKE#SCREEN, in which threat actors use a rotating collection of social engineering lures… Read more.


QuickFox Supply Chain Attack Used to Deploy FDMTP Implant

Source: Fortinet
(Published: 4 August 2026)
FortiGuard Labs is tracking a campaign associated with a long-standing supply chain attack on the QuickFox application. Read more.


Cryptomining Attack Hiding in Memory

Source: Aqua Security
(Published: 4 August 2026)
The attacks most likely to go undetected are the ones that never touch disk. Read more.


ChainDrop Supply Chain Compromise: Anatomy of a Self-Propagating Worm

Source: Microsoft
(Published: 4 August 2026)
Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers… Read more.


Shai-Hulud Is Back: August

Source: JFrog
(Published: 4 August 2026)
The JFrog security research team identified a new version of the Shai-Hulud supply-chain malware affecting 400+ packages across 1700+ versions. Read more.


Malware Bypasses DNS With Direct-to-IP Communication

Source: Unit 42
(Published: 4 August 2026)
Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Read more.


Fake CAPTCHA, Real Business: Traffic Distribution for Hire

Source: Netskope
(Published: 4 August 2026)
A single PDF factory has stamped out more than 12,700 structurally similar FakeCaptcha documents and parked them on Webflow’s content delivery network… Read more.


Detecting CertiGhost CVE-2026-54121

Source: Nextron Systems
(Published: 4 August 2026)
Many organizations rely on Microsoft Active Directory to manage users, computers, logins, and access permissions. Read more.


macOS ClickFix Campaign Learned to Hide

Source: Microsoft
(Published: 5 August 2026)
Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. Read more.


Payroll Pirates: Strange New Tides in Business Email Compromise

Source: Arctic Wolf
(Published: 6 August 2026)
Arctic Wolf is tracking an ongoing Microsoft 365 phishing campaign affecting healthcare, education, manufacturing, government, professional services, and other sectors across the United States… Read more.


StealNui: A New Linux RAT/Clipper

Source: ExaTrack
(Published: 6 August 2026)
This binary, detected only once on VirusTotal, makes far too much noise on Exalyze to be honest, so let’s dig into it a little to understand… Read more.


22 Seconds to Compromise: Automated SSH Actors

Source: SANS ISC
(Published: 6 August 2026)
On May 23, 2026, a threat actor successfully authenticated to my Cowrie SSH honeypot using compromised credentials and, within 22 seconds, injected a backdoor SSH key… Read more.


Fake Zoom Installer Delivers Overlord RAT

Source: Jamf
(Published: 6 August 2026)
Jamf Threat Labs recently identified a campaign using a fake Zoom installer to deliver a configured build of Overlord, an open-source remote access framework… Read more.


CaptiveCrunch: Amplifying Coverage With Variant Discovery

Source: Stairwell
(Published: 6 August 2026)
CaptiveCrunch is an ongoing espionage campaign reported on by Microsoft on July 31, 2026. Read more.


CVE-2026-16812: Critical Command Injection in Arista VeloCloud Orchestrator

Source: Resecurity
(Published: 6 August 2026)
CVE-2026-16812 is a critical unauthenticated OS command injection vulnerability affecting on-premises Arista VeloCloud Orchestrator (VCO) deployments. Read more.


AI Token Jacking

Source: Unit 42
(Published: 6 August 2026)
It’s three a.m., do you know what your AI agent is doing? Read more.


Clustering macOS ClickFix Campaign Pages Using HTTP-Basma

Source: Netomize
(Published: 6 August 2026)
On August 5, 2026, the Microsoft Security Research Team (MSRT) blogged about a new macOS ClickFix campaign… Read more.


Supply Chain Attack Activities Against Domestic Electron Software

Source: Qianxin
(Published: 7 August 2026)
Since our discovery of Operation Dragon Dance in 2021, we have repeatedly emphasized the vulnerability of domestic Electron software… Read more.


BDThemes Ecosystem Supply Chain Compromise via Poisoned API Response

Source: Wordfence
(Published: 8 August 2026)
The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor… Read more.


CERT-UA Article 6318863

Source: CERT-UA
(Published: 8 August 2026)
CERT-UA ???????? ?????????? ???? ???????????? ?????????? ??????? ?????????? ????????? ????????? ??????????? UAC-0145… Read more.


Kimsuky Integrates AI/LLM Into Attack Chain

Source: Genians
(Published: 9 August 2026)
???? ???? ??(Genians Security Center)? ?? ?????? ?? ??? ?? ???? ??? ???(Kimsuky)? ??? ??? ???? GitHub ? GitLab ?? ?? ??? ????? ???? ????. Read more.


Insolent Hyena: Mixed Motives and Objectives

Source: BI-ZONE
(Published: 10 August 2026)
Hacktivists typically target organizations to generate publicity. Read more.


Aeternum Blockchain C2 Analysis

Source: Unit 42
(Published: 10 August 2026)
Aeternum is a recently discovered C++ botnet loader that shifts its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Read more.


Lazarus Group IT Workers Investigation – Part Two

Source: ANY.RUN
(Published: 10 August 2026)
Back in December, we were the first ever to fully record the Famous Chollima infiltration cycle. Read more.


Abyssos: Technical Analysis of a New Modular RAT

Source: Zscaler
(Published: 10 August 2026)
In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Read more.


Deadlock Ransomware: Rust-Based Encryptor With Decentralized Recovery Infrastructure

Source: Microsoft
(Published: 10 August 2026)
Microsoft Threat Intelligence tracks DeadLock ransomware as an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications and data leak operations. Read more.


TXTBook: A Supply Chain Heist Rehearsed in Public

Source: CloudSEK
(Published: 10 August 2026)
An operator has spent the summer of 2026 publishing malicious packages to the public npm registry under names that belong to somebody else. Read more.


AI Sidebar Extension Monetizes Its Own Updates

Source: Netskope
(Published: 11 August 2026)
The Chrome extension “AI Sidebar with DeepSeek AI” that Google removed from the Chrome Web Store in January 2026 for stealing AI conversation content resumed shipping… Read more.


Head Mare Targets TrueConf Server With PhantomCore

Source: Kaspersky Securelist
(Published: 11 August 2026)
In July 2026, Kaspersky experts detected a new attack by the Head Mare group. Read more.


Deleting the Defenders: A Commodity BYOVD Toolkit

Source: VMRay
(Published: 11 August 2026)
[Source page could not be retrieved reliably; excerpt left blank for manual verification.] Read more.


The Phishing Link That Died on Purpose

Source: Gen Digital
(Published: 11 August 2026)
The first URL was already dead. Read more.


Fake CCleaner Installs GhostDesk Chrome Spyware

Source: Malwarebytes
(Published: 11 August 2026)
A fake version of the popular PC cleaning tool CCleaner is being used to infect Windows users with a malicious Chrome extension called GhostDesk… Read more.


Shattering the Dream: When a Job Offer Becomes a Zero-Day Attack

Source: Check Point Research
(Published: 11 August 2026)
Check Point Research is tracking a long-running campaign called Operation Dream Job, targeting organizations worldwide, with a particular focus on the defense sector. Read more.


Kimwolf v7 Botnet Malware

Source: Unit 42
(Published: 11 August 2026)
We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. Read more.


ClickFix Campaign Abuses Deno Runtime for Infostealer Delivery

Source: Sophos
(Published: 11 August 2026)
Counter Threat Unit™ (CTU) researchers investigated a June 2026 campaign in which threat actors used the Deno JavaScript runtime as a core execution mechanism… Read more.

Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (07/14/26-07/28/26)

?

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

?

Events

Going to Black Hat in Las Vegas?

If you’re interested in threat intelligence, want to chat with fellow security practitioners, or simply put a face to a name, let’s grab a coffee. We’ve opened time on our calendars for meetings throughout the conference.

Looking forward to the conversations and seeing familiar faces as well as meeting new ones!

Our Latest Blog Post

June 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.

 

Top ATT&CK Techniques Observed

T1566 – Phishing: Credential theft remained one of the primary initial access vectors, with campaigns using device code phishing, adversary-in-the-middle (AiTM) techniques, fake recruiters, Google Ads lures, procurement scams, eCards, and other social engineering methods.

T1071 – Application Layer Protocol: Threat actors increasingly relied on legitimate services and protocols—including Outlook, DNS, browsers, blockchain infrastructure, Telegram, and cloud platforms—for command-and-control to blend malicious traffic with normal network activity.

T1583 / T1584 – Acquire & Compromise Infrastructure: Multiple investigations focused on attacker-controlled infrastructure, compromised government websites, malicious domains, cloud resources, and software repositories used to support phishing, malware delivery, and command-and-control.

T1195 – Supply Chain Compromise: Software supply chain attacks remained highly active, targeting npm packages, PyPI repositories, SDKs, browser extensions, AI tooling, IDE components, and other developer ecosystems.

T1105 / T1059 – Ingress Tool Transfer & Command Execution: Researchers observed widespread use of custom loaders, remote access trojans, malware frameworks, scripting engines, ClickFix techniques, and living-off-the-land methods to establish persistence and evade detection.


What Matters Most

Identity has become the preferred attack surface. Rather than exploiting vulnerabilities, many campaigns focused on stealing credentials through phishing, adversary-in-the-middle attacks, Microsoft 365 abuse, and social engineering.

ClickFix continues to gain momentum. Multiple unrelated threat actors—including financially motivated groups, DPRK operators, and nation-state campaigns—adopted ClickFix techniques, reinforcing its emergence as a mainstream initial access method.

Trusted infrastructure is increasingly abused. Government websites, SaaS platforms, Microsoft 365, GitHub, Telegram, cloud services, and blockchain infrastructure were repeatedly leveraged to host payloads, deliver malware, or conceal command-and-control traffic.

Threat research is shifting toward infrastructure analysis. Many reports focused less on individual malware samples and more on mapping attacker infrastructure, command-and-control architecture, operational ecosystems, and attribution.


What Defenders Should Watch

  • Device code phishing, AiTM campaigns, and Microsoft 365 authentication abuse
  • ClickFix-style execution chains involving PowerShell, MSBuild, script interpreters, or trusted Windows utilities
  • Newly observed domains, DNS tunneling, Outlook- or browser-based C2 channels, and rapidly changing infrastructure
  • Unauthorized package updates, developer dependencies, browser extensions, SDKs, and software repositories
  • Remote administration tools, custom loaders, and malware communicating through trusted cloud services

Quick Wins

  • Strengthen phishing-resistant authentication and monitor for suspicious OAuth, device code, and session activity
  • Expand detection coverage for ClickFix techniques and script-based execution from user-accessible directories
  • Monitor outbound DNS, Outlook, browser, and cloud-service traffic for unusual command-and-control behavior
  • Verify software dependencies, package updates, browser extensions, and developer tooling before deployment
  • Continuously enrich detections with current malicious domains, URLs, IPs, and C2 infrastructure to identify emerging campaigns earlier

Key Insight: This reporting period highlighted a continued shift away from traditional exploit-driven intrusions toward attacks that abuse trusted identities, legitimate services, and widely used platforms. At the same time, researchers placed greater emphasis on uncovering attacker infrastructure and command-and-control techniques, giving defenders more opportunities to detect campaigns through behavioral patterns rather than malware signatures alone.

Articles

Late July 2026 Cyber Threat Reports highlight the latest threat research published between July 14 and July 28, 2026. This edition covers ransomware operations, advanced phishing campaigns, supply chain compromises, malware and botnet analysis, APT activity, cloud and identity attacks, and technical investigations from leading security researchers, providing actionable intelligence for defenders and threat hunters.

Langflow Exploited to Build Custom DDoS Gafgyt Botnets

Source: Akamai
(Published: July 14, 2026)

This technical analysis examines Langflow Exploited to Build Custom DDoS Gafgyt Botnets, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.


Kratos PhaaS Targets US and EU Companies

Source: ANY.RUN
(Published: July 14, 2026)

Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the US, Europe, and other regions. Read more.


LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software

Source: Blackpoint Cyber
(Published: July 14, 2026)

This technical analysis examines LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links

Source: Ctrl-Alt-Intel
(Published: July 14, 2026)

This report investigates Burnt by Burgers: Highlighting Void Blizzard’s Russian State Links, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Compromised AsyncAPI npm Packages

Source: Datadog Security Labs
(Published: July 14, 2026)

This research details Compromised AsyncAPI npm Packages, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


SeasonalInvite: New Phishing Campaign Abuses eCards and RMM

Source: Forescout
(Published: July 14, 2026)

This research analyzes SeasonalInvite: New Phishing Campaign Abuses eCards and RMM, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.


Signed, Sealed, Stolen: CrashStealer Slips Past Gatekeeper

Source: HivePro
(Published: July 14, 2026)

This technical analysis examines Signed, Sealed, Stolen: CrashStealer Slips Past Gatekeeper, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist

Source: Infostealers.com
(Published: July 14, 2026)

This technical analysis examines How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Miasma Worm Returns to npm

Source: JFrog
(Published: July 14, 2026)

This research details Miasma Worm Returns to npm, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


HTTP-Basma – Clustering Verbosus Fingerprints

Source: Netomize
(Published: July 14, 2026)

This research maps HTTP-Basma – Clustering Verbosus Fingerprints, highlighting infrastructure relationships, operational patterns, and detection opportunities. Read more.


Detailed Analysis of BIRDCALL Malware Masquerading as Zangi Messenger

Source: S2W
(Published: July 14, 2026)

This technical analysis examines Detailed Analysis of BIRDCALL Malware Masquerading as Zangi Messenger, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Injective SDK Compromised: Crypto Wallet Private Keys Stolen

Source: SlowMist
(Published: July 14, 2026)

This research details Injective SDK Compromised: Crypto Wallet Private Keys Stolen, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Tracking Donot APT-C-35 Bangladesh Military Intrusion

Source: Cyderes
(Published: July 15, 2026)

This report investigates Tracking Donot APT-C-35 Bangladesh Military Intrusion, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


DINDoOR, DenoRAT, and NightshadeC2: TAG-150’s Evolving Tradecraft

Source: eSentire
(Published: July 15, 2026)

This report investigates DINDoOR, DenoRAT, and NightshadeC2: TAG-150’s Evolving Tradecraft, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible for the April DigiCert Incident

Source: Expel
(Published: July 15, 2026)

This research details Introducing CylindricalCanine: The GoldenEyeDog Subgroup Responsible for the April DigiCert Incident, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials

Source: Intel 471
(Published: July 15, 2026)

Intel 471 investigated an ongoing, multi-stage phishing operation that systematically abuses legitimate software-as-a-service sales and marketing platforms and cloud services to orchestrate corporate credential theft. Read more.


OkoBot Framework Targets Cryptocurrency Wallets

Source: Kaspersky Securelist
(Published: July 15, 2026)

This technical analysis examines OkoBot Framework Targets Cryptocurrency Wallets, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Unpacking the AsyncAPI npm Supply-Chain Compromise

Source: Microsoft
(Published: July 15, 2026)

This research details Unpacking the AsyncAPI npm Supply-Chain Compromise, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


MuddyWater: ClickFix to Telegram & PatchAgent Backdoor

Source: Ransom-ISAC
(Published: July 15, 2026)

This report investigates MuddyWater: ClickFix to Telegram & PatchAgent Backdoor, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Telegram Account Compromised, Wallet Swapped: macOS Malware Analysis

Source: SlowMist
(Published: July 15, 2026)

This research analyzes Telegram Account Compromised, Wallet Swapped: macOS Malware Analysis, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.


TuxBot v3: Evolution of an IoT Botnet

Source: Unit 42
(Published: July 15, 2026)

This technical analysis examines TuxBot v3: Evolution of an IoT Botnet, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.


20+ Government Websites Hijacked: PhantomEnigma Investigation

Source: ANY.RUN
(Published: July 16, 2026)

An original threat intelligence investigation uncovered how trusted government infrastructure became an attack channel, placing banking organizations and public-sector systems at risk. Read more.


UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant

Source: Cisco Talos
(Published: July 16, 2026)

This technical analysis examines UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


TELEPUZ Malware-as-a-Service Uses ClickFix

Source: Elastic Security Labs
(Published: July 16, 2026)

This technical analysis examines TELEPUZ Malware-as-a-Service Uses ClickFix, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


The TTF Trap: A Global Campaign of a Low-Detection Lua Loader

Source: Fortinet
(Published: July 16, 2026)

Since late March, 2026, we have been observing large-scale campaigns that use a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private LOGGER. Read more.


ClickLock Stealer: macOS Malware

Source: Group-IB
(Published: July 16, 2026)

This technical analysis examines ClickLock Stealer: macOS Malware, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


GoSerpent Backdoor in Southeast Asia

Source: Kaspersky Securelist
(Published: July 16, 2026)

This report investigates GoSerpent Backdoor in Southeast Asia, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Hiding in Plain Ledger: Four Months of a ClickFix Operator’s Blockchain C2

Source: Melted in Hex
(Published: July 16, 2026)

To hide its command-and-control server, this operation writes the address onto a public blockchain. Read more.


ACR Stealer: Two Observed Intrusion Chains

Source: Microsoft
(Published: July 16, 2026)

This technical analysis examines ACR Stealer: Two Observed Intrusion Chains, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


StealC: A Commodity Stealer Loader

Source: Stairwell
(Published: July 16, 2026)

This technical analysis examines StealC: A Commodity Stealer Loader, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


GigaWiper: Inside a Modular Cyberweapon

Source: PolySwarm
(Published: July 17, 2026)

This technical analysis examines GigaWiper: Inside a Modular Cyberweapon, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era

Source: XLab
(Published: July 17, 2026)

This technical analysis examines NadMesh Botnet Analysis: A Product-Grade Threat for the AI Service Era, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.


Contagious Interview Malware Uses SVG Steganography

Source: Elastic Security Labs
(Published: July 18, 2026)

This report investigates Contagious Interview Malware Uses SVG Steganography, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


GitHub Poisoning Attack Disguised as Recruitment

Source: SlowMist
(Published: July 18, 2026)

This research details GitHub Poisoning Attack Disguised as Recruitment, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Hollowgraph: Microsoft 365 Espionage

Source: Group-IB
(Published: July 20, 2026)

This research examines Hollowgraph: Microsoft 365 Espionage, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.


CloudAtlasGo Backdoor

Source: Kaspersky Securelist
(Published: July 20, 2026)

This report investigates CloudAtlasGo Backdoor, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Fake Games Spread Stealers With Ren’Py Loader, MSBuild, and EtherHiding

Source: Malwarebytes
(Published: July 20, 2026)

This technical analysis examines Fake Games Spread Stealers With Ren’Py Loader, MSBuild, and EtherHiding, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


On-Chain Backdoor in a Malicious Trae Extension

Source: SlowMist
(Published: July 20, 2026)

This research details On-Chain Backdoor in a Malicious Trae Extension, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Kali365 Targets US Organizations With Device Code Phishing

Source: ANY.RUN
(Published: July 21, 2026)

Kali365 is targeting US organizations with device code phishing attacks that abuse legitimate Microsoft authentication. Read more.


Click to Sync: From Google Ads Maintenance Notice to Credential Theft

Source: Cofense
(Published: July 21, 2026)

This research analyzes Click to Sync: From Google Ads Maintenance Notice to Credential Theft, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.


The Procurement Trap: An AiTM Campaign Targeting Global Institutions

Source: Infoblox
(Published: July 21, 2026)

This research analyzes The Procurement Trap: An AiTM Campaign Targeting Global Institutions, with attention to the lure, delivery infrastructure, credential-theft flow, and defensive indicators. Read more.


Project CAV3RN: Cyberespionage Framework Using Outlook and DNS

Source: Kaspersky Securelist
(Published: July 21, 2026)

This report investigates Project CAV3RN: Cyberespionage Framework Using Outlook and DNS, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


INC Ransomware Affiliate Targets ESXi & NAS Devices in AD Environment

Source: Ctrl-Alt-Intel
(Published: July 22, 2026)

This research examines INC Ransomware Affiliate Targets ESXi & NAS Devices in AD Environment, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.


Email Bombing, IT Impersonation, Quick Assist, and Edgecution: UNC6692

Source: eSentire
(Published: July 22, 2026)

This research examines Email Bombing, IT Impersonation, Quick Assist, and Edgecution: UNC6692, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.


Inside a TrickBot Variant Using DNS Tunneling for C2

Source: Fortinet
(Published: July 22, 2026)

FortiGuard Labs recently captured several malicious samples that were sending malformed DNS queries. Read more.


FakeAgent Claude Desktop Malvertising Ends in .NET RAT

Source: Huntress
(Published: July 22, 2026)

This technical analysis examines FakeAgent Claude Desktop Malvertising Ends in .NET RAT, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Cl0p Windchill/FlexPLM Exploitation

Source: Ransom-ISAC
(Published: July 22, 2026)

This research examines Cl0p Windchill/FlexPLM Exploitation, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.


Malicious Copilot MCP Apex npm Package Delivers macOS Infostealer

Source: SafeDep
(Published: July 22, 2026)

This research details Malicious Copilot MCP Apex npm Package Delivers macOS Infostealer, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Rondo Meets GeoServer

Source: SANS ISC
(Published: July 22, 2026)

This analysis examines Rondo Meets GeoServer, including observed exploitation activity, post-exploitation behavior, and relevant defensive guidance. Read more.


Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel

Source: Cisco Talos
(Published: July 23, 2026)

This research examines Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.


JadeProx: China-Nexus TRIBACK Loader

Source: Group-IB
(Published: July 23, 2026)

This report investigates JadeProx: China-Nexus TRIBACK Loader, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


TA488 Targets Zimbra Mail Servers With Half-Click Exploits

Source: Proofpoint
(Published: July 23, 2026)

This report investigates TA488 Targets Zimbra Mail Servers With Half-Click Exploits, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


Russian Webmail Espionage

Source: Unit 42
(Published: July 23, 2026)

Unit 42 has observed a persistent cyberespionage campaign it tracks as CL-STA-1114. Read more.


The Gentlemen RaaS: Origins, OPSEC & OSINT

Source: Ctrl-Alt-Intel
(Published: July 24, 2026)

This research examines The Gentlemen RaaS: Origins, OPSEC & OSINT, including the intrusion chain, tooling, infrastructure, or operational tradecraft associated with the activity. Read more.


Inside a DPRK BlueNoroff ClickFix Kit

Source: JUMPSEC
(Published: July 24, 2026)

This report investigates Inside a DPRK BlueNoroff ClickFix Kit, covering the campaign’s targeting, tooling, infrastructure, and observed attacker tradecraft. Read more.


MrMustard Malicious PyPI Package

Source: SafeDep
(Published: July 24, 2026)

This research details MrMustard Malicious PyPI Package, including how the software ecosystem was abused and what defenders can use to identify affected packages or systems. Read more.


Dysphoria Botnet Evolution and Technical Analysis

Source: XLab
(Published: July 25, 2026)

This technical analysis examines Dysphoria Botnet Evolution and Technical Analysis, including its propagation, command-and-control design, capabilities, and infrastructure. Read more.


From Compliant Emails to Remote Control: A Web3 Investigation

Source: SlowMist
(Published: July 26, 2026)

This research examines From Compliant Emails to Remote Control: A Web3 Investigation, highlighting the principal attacker behaviors, technical findings, and defensive implications. Read more.


The Zedxion Corporate Nexus

Source: DomainTools
(Published: July 27, 2026)

This research maps The Zedxion Corporate Nexus, highlighting infrastructure relationships, operational patterns, and detection opportunities. Read more.


The Telegram Malware Ecosystem

Source: Ransom-ISAC
(Published: July 27, 2026)

This technical analysis examines The Telegram Malware Ecosystem, including its delivery chain, execution behavior, persistence, command-and-control, and evasion techniques. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (6/16/26-6/30/26)

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

Events

Going to Black Hat in Las Vegas?

If you’re interested in threat intelligence, want to chat with fellow security practitioners, or simply put a face to a name, let’s grab a coffee. We’ve opened time on our calendars for meetings throughout the conference.

Looking forward to the conversations and seeing familiar faces as well as meeting new ones!

Our Latest Blog Post

May 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.

 

Top ATT&CK Techniques Observed

  • T1195 – Supply Chain Compromise: Software supply chain attacks remained one of the dominant themes, with compromises affecting npm packages, developer tools, IDE plugins, SDKs, and CI/CD workflows.
  • T1566 – Phishing: Attackers continued to rely on shopping scams, WhatsApp campaigns, fake domain renewals, Bubble.io phishing, and AI-themed lures to steal credentials.
  • T1555 / T1556 – Credential Access: Multiple campaigns targeted developer credentials, AI API keys, browser sessions, enterprise logins, and cloud identities.
  • T1071 – Application Layer Protocol: Modern malware increasingly used cloud services, collaboration platforms, blockchain infrastructure, and encrypted channels for command-and-control.
  • T1055 / T1059 – Defense Evasion & Execution: Attackers continued adopting reflective loading, DLL sideloading, steganography, PowerShell, and in-memory execution to reduce detection.

What Matters Most

  • Developer ecosystems remain under sustained attack. AI frameworks, npm packages, JetBrains plugins, SDKs, and developer tooling were repeatedly compromised during this reporting period.
  • Credential theft continues to drive intrusions. Whether targeting developers, cloud administrators, or end users, most campaigns ultimately sought credentials, tokens, or session access.
  • Supply chain attacks are expanding beyond package managers. Threat actors increasingly target plugins, extensions, SDKs, repositories, and software update mechanisms.
  • Nation-state operations remain highly active. Multiple reports covered activity linked to China- and DPRK-aligned actors, as well as campaigns targeting government, healthcare, and critical infrastructure.

What Defenders Should Watch

  • Unexpected package updates, dependency changes, IDE plugins, or CI/CD modifications
  • Credential theft targeting AI platforms, developer accounts, and enterprise cloud services
  • Execution from temporary folders, archive contents, DLL sideloading, and script interpreters
  • Outbound connections to newly observed infrastructure, cloud services, and fast-changing C2 endpoints

Quick Wins

  • Review package trust policies and require verification for new dependencies
  • Monitor AI platform credentials and API keys alongside traditional privileged accounts
  • Strengthen detection for phishing-resistant authentication and suspicious session activity
  • Audit developer workstations and CI/CD pipelines for unauthorized changes or plugins

Key Insight: This period marked another shift toward attacks on software development ecosystems. Rather than targeting only end users, threat actors increasingly compromised developer tools, package repositories, and AI-related workflows to gain access to organizations and their cloud environments.

Articles

Late June 2026 Cyber Threat Reports highlights a continued rise in attacks targeting software supply chains, AI development tools, enterprise credentials, and cloud environments. This edition features research on Mastra, FortiBleed, The Gentlemen, TONResolver, AryStinger, Mustang Panda, and dozens of phishing, ransomware, and malware campaigns published between June 16 and June 30, 2026.

May 2026 Infostealer Trend Report

Source: AhnLab ASEC
(Published: 17 June 2026)
This report summarizes the distribution channels, number of infostealers, number of detections, target companies, and execution types of new infostealers collected during the month of May 2026. Read more.


More Than 4,000 Legacy Routers Compromised by AryStinger, Turned into Global Attack Proxies for Hackers

Source: Qianxin XLab
(Published: 17 June 2026)
On May 20, 2026, the Ministry of State Security’s WeChat official account published an article “Your internet is slow, and the culprit turns out to be this!”, highlighting that outdated routers are becoming a key entry point for threat actors to conduct cyber espionage. Read more.


AdaptixC2: Fingerprinting an Open-Source C2 Framework at Scale

Source: Censys
(Published: 17 June 2026)
AdaptixC2 is an open-source post-exploitation framework with a default configuration that makes deployed servers trivially identifiable from passive scanning. Read more.


Klue Integration Abused in Salesforce Data Theft

Source: ReliaQuest
(Published: 17 June 2026)
In June 2026, ReliaQuest observed a compromised integration for Klue, a competitive-intelligence platform that syncs battlecard and win/loss data with Salesforce, being used to exfiltrate customer relationship management (CRM) data. Read more.


Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat

Source: StepSecurity
(Published: 17 June 2026)
On June 17, 2026, an attacker compromised the @mastra npm organization and quietly added easy-day-js as a dependency across 140+ packages in the Mastra AI framework ecosystem. Read more.


Mastra Supply Chain Compromise: easy-day-js Dropper Pulls a Cross-Platform RAT Into @mastra Installs

Source: Upwind
(Published: 17 June 2026)
On June 17 2026, a coordinated supply chain attack pushed a malicious easy-day-js package into the dependency tree of the entire @mastra/* npm organization. Read more.


PureRAT Variant Observed in AI Video Player

Source: Luke Acha
(Published: 17 June 2026)
Follow-up analysis of extracted .NET loader stage, internally named Ykzrh.exe (smveo-csharp-agent.exe) in one recovered artifact, revealed a substantial virtualization and runtime reconstruction layer. Read more.


Prinz Eugen Ransomware: A Deep Dive Into a New Go-Based Encryptor

Source: ThreatDown
(Published: 17 June 2026)
On May 11, 2026, our research team investigated a customer infected with a brand-new ransomware family called Prinz Eugen. Read more.


Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystem

Source: Cyble
(Published: 18 June 2026)
The FIFA World Cup 2026 has become more than a global sporting event. Read more.


Mastra Attack Targets Crypto, Password Managers, Authenticators, and Zapier

Source: OpenSourceMalware
(Published: 18 June 2026)
A threat actor compromised the Mastro NPM organization yesterday and published more than 140 malicious packages. Read more.


15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers

Source: StepSecurity
(Published: 18 June 2026)
On June 16, 2026, JetBrains received security reports identifying a coordinated supply chain attack involving 15 malicious third-party plugins on the JetBrains Marketplace. Read more.


Killing Me Gently: Inside Gentlemen’s EDR Killer Framework

Source: ESET Research
(Published: 18 June 2026)
ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen. Read more.


SmartApeSG Launches Okendo Reviews Supply Chain Attack

Source: Zscaler
(Published: 18 June 2026)
On May 14, 2026, the Zscaler ThreatLabz team identified unusually high activity associated with the threat actor SmartApeSG to deploy malware. Read more.


Amazon Prime Day 2026: Bargains Begin June 23 – and So Do the Scams

Source: Check Point Research
(Published: 19 June 2026)
When Amazon Prime Day returns on June 23-26, 2026, more than 25 countries will take part in one of the largest shopping windows of the year. Read more.


OXLOADER: New Loader Evading Detection to Drop Infostealer

Source: Elastic Security Labs
(Published: 19 June 2026)
After all the checks have passed, the malware makes a copy of the Windows DirectUI Engine DLL (C:\Windows\System32\dui70.dll), storing it in a temporary location using a randomly generated name with the .ocx extension. Read more.


Threat Actors Weaponizing RAR Archives to Target Thailand’s Healthcare Sector

Source: Seqrite
(Published: 19 June 2026)
Authors: Vaibhav Krushna Billade, Dixit Panchal & Rumana Siddiqui. Read more.


MyBait: Why We Lured Attackers To Encrypt Our Cloud MySQL

Source: Varonis
(Published: 19 June 2026)
Varonis Threat Labs deployed MySQL honeypots across GCP, AWS, and Azure. Read more.


@withgoogle/stitch-sdk: Scope Squat Harvests Developer Credentials

Source: SafeDep
(Published: 19 June 2026)
A malicious npm package published under @withgoogle/stitch-sdk impersonates Google’s Stitch AI design tool by squatting the @withgoogle npm scope. Read more.


FortiBleed: Anatomy of the FortiBleed Campaign Based on the Server That the Attackers Themselves Left Exposed

Source: ZenoX
(Published: 20 June 2026)
In June 19 2026 we received access to the contents of an internet-exposed directory, left open by the operators themselves of a campaign the press named FortiBleed. Read more.


A Multi-Stage Steganographic Loader Campaign Deploying Diverse Payloads Globally

Source: K7 Labs
(Published: 20 June 2026)
The final payload achieves its persistence through the Run entry, winlogon.exe, & userinit. Read more.


From PostCSS Masquerading to Windows RAT

Source: JFrog Security Research
(Published: 20 June 2026)
The downloaded bundle was not a simple script. Read more.


A VBScript Campaign Distributed Through WhatsApp Deploying RMM Software

Source: Kaspersky Securelist
(Published: 22 June 2026)
In June 2026, we observed a malware campaign distributing malicious VBScript files through direct messages in WhatsApp. Read more.


USB Worm CryptoBandits Steals Cryptocurrency via Windows Shortcut Files

Source: ThreatAft
(Published: 22 June 2026)
A financially motivated USB worm campaign has been actively stealing cryptocurrency from Windows users worldwide since at least February 2026. Read more.


What Was a 45-GPU Cracking Farm Built For?

Source: ThreatMon
(Published: 22 June 2026)
Most credential leaks are messy. Someone dumps a pile of raw data, half of it stale, and walks away. Read more.


EvilTokens: How “Ghost” Code Threatens US and European Businesses

Source: ANY.RUN
(Published: 23 June 2026)
EvilTokens can hide serious account takeover risk from your SOC through “ghost” code that appears only after browser-side decryption. Read more.


Inside FortiBleed: Reverse Engineering the CyberStrike Harvester Behind a Global FortiGate Credential Factory

Source: Arctic Wolf
(Published: 23 June 2026)
Arctic Wolf reverse-engineered a recovered CyberStrike Harvester binary and connected it to the broader FortiBleed operator workflow, showing how exposed perimeter credentials can quickly become full internal-network exposure. Read more.


CVE-2025-54068 Laravel Livewire Credential Theft Campaign: 6,000+ Applications Compromised

Source: Imperva
(Published: 24 June 2026)
The campaign, first documented here, has been running for several months, as evidenced by the large volume of stolen data. Read more.


A Burst Bubble: How Threat Actors Are Using Bubble.io to Deliver a New Phishing Campaign

Source: S-RM
(Published: 24 June 2026)
The login follows the expected Microsoft login flow, but it is using the dynamic pages copied from Microsoft’s flow but on the threat actors content delivery network. Read more.


Edgecution: Malicious Edge Extension Backdoor

Source: Zscaler
(Published: 24 June 2026)
Edgecution is a malicious Microsoft Edge extension backdoor associated with ransomware initial access activity. Read more.


May 2026 Threat Trend Report on APT Attacks (South Korea)

Source: AhnLab ASEC
(Published: 24 June 2026)
This report provides a statistical summary and analysis of APT attacks targeting South Korea in May 2026. Read more.


Operation Navy Ghost: How Attackers Planted a Telegram-Powered Backdoor Across Fake pyrogram Packages on PyPI

Source: Checkmarx
(Published: 25 June 2026)
When the attacker sends “/asu print(os.environ)” to the victim’s bot, this function compiles and executes that Python code on the victim’s machine. Read more.


Threat Intelligence Report: Nation-State Targeting of Water Systems 2024-2026

Source: DomainTools
(Published: 25 June 2026)
DomainTools assesses nation-state targeting of water systems from 2024 through 2026, including activity linked to Iran, Russia, and China. Read more.


Coinbase Cartel: Behind the Noise of a Prolific Leak Operation

Source: Intrinsec
(Published: 25 June 2026)
Coinbase Cartel is a prolific leak operation built around high-volume extortion activity and public data exposure claims. Read more.


Fake Domain Renewal Emails Trick Website Owners Into Paying Scammers

Source: Malwarebytes
(Published: 25 June 2026)
Scammers are sending fake domain renewal notices to trick website owners into paying fraudulent invoices. Read more.


Negative SEO Attack: Inside a Black Hat SEO Operation

Source: Zynap
(Published: 25 June 2026)
Negative SEO is a form of search engine manipulation aimed not at boosting the attacker’s own site, but at damaging the ranking, reputation, or visibility of a target domain. Read more.


Operation Turb00 – Part 2: A Multi-Stage HijackLoader Campaign Delivers Vidar v2.1

Source: Medium
(Published: 26 June 2026)
This is the second post in a three-part series on the Vidar infostealer and the infrastructure behind it. Read more.


From CI/CD to Cloud Data: How Shai-Hulud Persistence Leads to Redshift Breach

Source: Fortinet
(Published: 26 June 2026)
The “Shai-Hulud: The Second Coming” campaign represents a major evolution in the landscape of npm supply-chain attacks. Read more.


Beyond Banking Trojans: Rokarolla Expands the Android Fraud Playbook

Source: PolySwarm
(Published: 26 June 2026)
Rokarolla represents a new generation of Android fraud tooling that extends beyond traditional banking trojan behavior. Read more.


Gaslight: The Rust-Powered macOS Implant Designed to Mislead AI Tools

Source: HivePro
(Published: 26 June 2026)
Gaslight (macOS.Gaslight) is a Rust-based macOS implant and information stealer attributed with high confidence to DPRK-aligned activity, first seen on May 22, 2026 and targeting macOS systems worldwide. Read more.


Investigating a Novel OpenAI Poisoned Tenant Attack

Source: Push Security
(Published: 26 June 2026)
Push Security investigated a poisoned tenant attack that abused OpenAI-related workflows to target identity and application access. Read more.


Understanding Langflow CVE-2026-55255, and Why Higher CVSS Vulnerabilities Aren’t Always the Most Exploited

Source: Sysdig
(Published: 26 June 2026)
Sysdig analyzes Langflow CVE-2026-55255 and explains why vulnerabilities with lower scores may see heavier attacker adoption than higher-severity flaws. Read more.


Anatomy of a WHQL-Signed Windows Filtering Platform Kernel-Resident Network Backdoor

Source: Nextron Systems
(Published: 26 June 2026)
Nextron Systems analyzes a WHQL-signed Windows Filtering Platform kernel-resident network backdoor. Read more.


Operation DragonReturn: China-Nexus Cyber Espionage Campaign Targeting Govt. of India/MoF Tax Infrastructure via Multi-Stage DcRAT Deployment

Source: Seqrite
(Published: 26 June 2026)
Seqrite Lab actively tracks and analyse threat actors and their campaigns, focusing on attribution, infrastructure analysis, and adversary tradecraft. Read more.


Mustang Panda Targets India’s Government and Energy Sectors with ZOHOMURK and MINIRECON

Source: Acronis
(Published: 28 June 2026)
Our investigation began after identifying a suspicious archive, Hydropower Cooperation Project Proposal.zip, believed to have been distributed via spear-phishing and subsequently uploaded to VirusTotal in May 2026. Read more.


SystemBC Malware: How the Coroxy Proxy Backdoor Targets Windows

Source: Picus Security
(Published: 29 June 2026)
SystemBC, also tracked as Coroxy, is a Windows malware family that primarily turns an infected machine into a SOCKS5 proxy while also functioning as a persistent backdoor and RAT. Read more.


TONResolver RAT Abuses TON Blockchain to Target Japan’s Hotel Industry

Source: Trend Micro
(Published: 29 June 2026)
In this blog entry, TrendAI™ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved. Read more.


The Gentlemen Are Knocking: Custom Backdoors and Evolving Tactics

Source: Kaspersky Securelist
(Published: 29 June 2026)
This year saw the emergence of The Gentlemen, a prominent example of a group operating under the ransomware-as-a-service model. Read more.


RustDuck: An In-Depth Analysis of a Two-Stage Botnet

Source: Qianxin XLab
(Published: 29 June 2026)
Although the family’s current activity level and influence in DDoS attacks are not yet comparable to some mainstream botnets, its speed of technological evolution deserves significant attention. Read more.


UAC-0184 Tooling Evolution: OneDrive Sideload to Remcos

Source: Synaptic Systems
(Published: 29 June 2026)
Launching shortcuts directly from an archive can behave differently depending on the archive utility and extraction context. Read more.


Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery

Source: Synaptic Systems
(Published: 29 June 2026)
The visible text comments on the structure of a manuscript, including sections covering diversion of civilian resources to military spending, degradation of agricultural production, and inequality in food distribution. Read more.


From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks

Source: Arctic Wolf
(Published: 30 June 2026)
Arctic Wolf Labs observed Anubis ransomware attacks using CitrixBleed 2 exploitation and Cloudflared tunneling as part of the intrusion chain. Read more.


Glitch SPY: An Emerging Android RAT Distributed Through a Fake Polish Rental App

Source: Cyble
(Published: 30 June 2026)
Cyble Research and Intelligence Labs identified an emerging Android malware family tracked as Glitch SPY, distributed through a fraudulent Polish apartment and house rental platform designed to lure users into downloading an Android APK. Read more.


Not Very Gentlemanly: Analyzing a Zero-Day Exploit Used by The Gentlemen Ransomware to Disable Targets’ EDRs

Source: Expel
(Published: 30 June 2026)
Ransomware groups have long relied on disabling endpoint detection and response tools before deploying their payloads, and in recent years have utilized bring-your-own-vulnerable-driver attacks to do so. Read more.


The Polymarket Trap: A Fake Arbitrage Bot, Ten npm Accounts, and Four Ways to Deliver an Infostealer

Source: SafeDep
(Published: 30 June 2026)
A set of small npm packages, GitHub repositories, and matching themes were used to lure developers into installing infostealer code disguised as Polymarket arbitrage tooling. Read more.


ToddyCat: Your Hidden Email Assistant. Part 2

Source: Kaspersky Securelist
(Published: 30 June 2026)
We continue to share details on the malicious techniques and toolsets used by the ToddyCat APT group. Read more.


No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack

Source: Huntress
(Published: 30 June 2026)
The targeting of these attacks seems to be based entirely on password prevalence on compromised password combo lists, and is not specific to business type or industry. Read more.


Silent Swap: A Crypto Clipper Extension Campaign

Source: McAfee
(Published: 30 June 2026)
McAfee Labs analyzed a browser extension campaign designed to swap cryptocurrency wallet addresses and redirect payments to attacker-controlled wallets. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?

Security Signals (6/2/26 – 6/16/26)

Welcome to Security Signals

Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.

For more articles, check out our #onpatrol4malware blog.

Our Latest Blog Post

May 2026 Edition

Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.

?

Insights (TL;DR)

These insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the threat research featured below.

Top ATT&CK Techniques Observed

  • T1195 – Supply Chain Compromise (9/9): npm, PyPI, Rust crates, GitHub repositories, and AI coding agent workflows were repeatedly targeted.
  • T1566 – Phishing / Social Engineering (9/9): Device-code phishing, AiTM kits, fake AI tools, job lures, smishing, and copyright notices were common.
  • T1555 – Credential Access (8/9): Infostealers, token theft, session hijacking, and Microsoft 365 credential capture appeared across multiple campaigns.
  • T1190 – Exploit Public-Facing Applications (8/9): Oracle PeopleSoft, Check Point VPN, WinRAR, PAN-OS, and SOHO/IoT exploitation remained active.
  • T1071 – Application Layer C2 (7/9): Google Sheets, Microsoft Graph, Discord, cloud services, and fast-flux DNS were used for C2 or concealment.

What Matters Most

  • Developer ecosystems remain a major access path. Attackers are abusing package managers, repositories, AI coding tools, and CI/CD-adjacent workflows.
  • Identity attacks are highly active. Microsoft 365 phishing, device-code abuse, OAuth theft, and session capture remain central to many campaigns.
  • AI is now part of both lure design and attacker operations. Fake AI brands, jailbreak techniques, and agent-driven activity appeared repeatedly.
  • Nation-state activity is broadening. China-linked, Russia-linked, DPRK-linked, OceanLotus, Gamaredon, and Mustang Panda activity all appeared this period.

What Defenders Should Watch

  • Unexpected package updates, GitHub activity, CI/CD changes, or developer tool execution
  • OAuth/device-code abuse, suspicious MFA flows, and unusual Microsoft 365 session activity
  • Execution from fake AI tools, browser extensions, installers, and user-controlled directories
  • Outbound traffic to cloud-hosted, fast-flux, collaboration, or newly observed infrastructure

Quick Wins

  • Review package manager, repository, and CI/CD permissions
  • Restrict OAuth app consent and monitor device-code authentication
  • Alert on execution from downloads, temp folders, and unexpected script interpreters
  • Block newly registered domains tied to fake software, phishing kits, and impersonation lures

Key Insight: Attackers are combining developer ecosystem abuse, identity phishing, and public-facing exploitation to scale access, with credential theft and persistent control as the main objectives.

Articles

Mid June 2026 Cyber Threat Reports highlights developer ecosystem compromise, identity phishing, public-facing exploitation, and nation-state activity. This edition covers Shai-Hulud, Kali365, Check Point VPN exploitation, WinRAR attacks, OceanLotus, Gamaredon, Mustang Panda, and AI-themed phishing campaigns.

Dont Fear Repo UNKDEADDROP Phishing Campaign Targets Developers Steal

Source: Proofpoint
(Published: 2 June 2026)
Proofpoint analyzes a phishing or social engineering campaign involving Dont Fear Repo UNKDEADDROP Phishing Campaign Targets Developers Steal. Read more.


Etr Active Exploitation of Oracle PeopleSoft Zero Day CVE 2026 35273

Source: Rapid7
(Published: 2 June 2026)
Rapid7 analyzes exploitation activity and defensive implications related to Etr Active Exploitation of Oracle PeopleSoft Zero Day CVE 2026 35273. Read more.


Etr Critical Check Point VPN Zero Day Exploited in the Wild CVE 2026 50751

Source: Rapid7
(Published: 2 June 2026)
Rapid7 analyzes exploitation activity and defensive implications related to Etr Critical Check Point VPN Zero Day Exploited in the Wild CVE 2026 50751. Read more.


TA4922 Suspected Chinese Crime Group Going Global

Source: Proofpoint
(Published: 2 June 2026)
Proofpoint analyzes recent threat activity and defensive considerations related to TA4922 Suspected Chinese Crime Group Going Global. Read more.


Device Code Phishing Campaign

Source: ReversingLabs
(Published: 3 June 2026)
ReversingLabs analyzes a phishing or social engineering campaign involving Device Code Phishing Campaign. Read more.


Sheetcreep Evolved Google Sheets RAT

Source: Securonix
(Published: 3 June 2026)
Securonix analyzes malware activity, delivery tradecraft, and victim impact related to Sheetcreep Evolved Google Sheets RAT. Read more.


Silent Ransom Group Srg Uncovering DNS Fast-Flux Infrastructure

Source: Resecurity
(Published: 3 June 2026)
Resecurity analyzes ransomware or extortion activity tied to Silent Ransom Group Srg Uncovering DNS Fast-Flux Infrastructure. Read more.


Social Media Attacks Phishing

Source: ReversingLabs
(Published: 3 June 2026)
ReversingLabs analyzes a phishing or social engineering campaign involving Social Media Attacks Phishing. Read more.


Stock Exchange Espionage

Source: Security.com
(Published: 3 June 2026)
Security.com analyzes recent threat activity and defensive considerations related to Stock Exchange Espionage. Read more.


Threat Spotlight Reliaquests Agentic AI Uncovers New China Linked Cluster OP-512

Source: ReliaQuest
(Published: 3 June 2026)
ReliaQuest analyzes state-linked threat activity and targeting patterns related to Threat Spotlight Reliaquests Agentic AI Uncovers New China Linked Cluster OP-512. Read more.


Binding Gyp NPM Supply Chain Attack Spreads Like Worm

Source: StepSecurity
(Published: 4 June 2026)
StepSecurity analyzes a supply chain or developer ecosystem compromise involving Binding Gyp NPM Supply Chain Attack Spreads Like Worm. Read more.


Miasma Worm Hits Microsoft Again Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents

Source: StepSecurity
(Published: 4 June 2026)
StepSecurity analyzes a supply chain or developer ecosystem compromise involving Miasma Worm Hits Microsoft Again Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents. Read more.


Old WINRAR Flaw Fuels Attacks on Ukraine

Source: Trend Micro
(Published: 4 June 2026)
Trend Micro analyzes attacker abuse of AI-themed lures, tools, or workflows related to Old WINRAR Flaw Fuels Attacks on Ukraine. Read more.


Pythagora Io Gpt Pilot Compromised on GitHub Shai-Hulud Credential Stealer Blocked by Python Linter

Source: StepSecurity
(Published: 4 June 2026)
StepSecurity analyzes a supply chain or developer ecosystem compromise involving Pythagora Io Gpt Pilot Compromised on GitHub Shai-Hulud Credential Stealer Blocked by Python Linter. Read more.


Tracking Havoc Malware Activity and Evasion Techniques

Source: SonicWall
(Published: 4 June 2026)
SonicWall analyzes malware activity, delivery tradecraft, and victim impact related to Tracking Havoc Malware Activity and Evasion Techniques. Read more.


VerdantBamboo Just Another Brickstorm in the Firewall

Source: Volexity
(Published: 4 June 2026)
Volexity analyzes recent threat activity and defensive considerations related to VerdantBamboo Just Another Brickstorm in the Firewall. Read more.


You Do Surprise Me Exe an Unexpected Executable in Hola Browser

Source: Sophos
(Published: 4 June 2026)
Sophos analyzes recent threat activity and defensive considerations related to You Do Surprise Me Exe an Unexpected Executable in Hola Browser. Read more.


Ghost Stadium

Source: Validin
(Published: 5 June 2026)
Validin analyzes recent threat activity and defensive considerations related to Ghost Stadium. Read more.


Inside Cross Platform Propagation of New GAFGYT Variant C0XMO

Source: Fortinet
(Published: 5 June 2026)
Fortinet analyzes recent threat activity and defensive considerations related to Inside Cross Platform Propagation of New GAFGYT Variant C0XMO. Read more.


Oceanlotus External Espionage Domestic Targeting

Source: ESET Research
(Published: 5 June 2026)
ESET Research analyzes state-linked threat activity and targeting patterns related to Oceanlotus External Espionage Domestic Targeting. Read more.


Shai-Hulud Campaign Evolution Miasma Hades and AI Scanner Evasion

Source: Zscaler
(Published: 5 June 2026)
Zscaler analyzes attacker abuse of AI-themed lures, tools, or workflows related to Shai-Hulud Campaign Evolution Miasma Hades and AI Scanner Evasion. Read more.


Technical Analysis MLTBackdoor

Source: Zscaler
(Published: 5 June 2026)
Zscaler analyzes malware activity, delivery tradecraft, and victim impact related to Technical Analysis MLTBackdoor. Read more.


Fluffy Wolf Tests New Toolkit on Russian Companies 90f0785becdb

Source: Medium
(Published: 6 June 2026)
Medium analyzes recent threat activity and defensive considerations related to Fluffy Wolf Tests New Toolkit on Russian Companies 90f0785becdb. Read more.


Kali365 Expands Into AWS Microsoft Okta Xerox Max Messenger

Source: Arctic Wolf
(Published: 6 June 2026)
Arctic Wolf analyzes recent threat activity and defensive considerations related to Kali365 Expands Into AWS Microsoft Okta Xerox Max Messenger. Read more.


Monoglyphrat Attacks US Enterprise

Source: ANY.RUN
(Published: 6 June 2026)
ANY.RUN analyzes malware activity, delivery tradecraft, and victim impact related to Monoglyphrat Attacks US Enterprise. Read more.


Shai-Hulud Copycat Campaign Targets Python Developers

Source: GitLab
(Published: 6 June 2026)
GitLab analyzes attacker abuse of AI-themed lures, tools, or workflows related to Shai-Hulud Copycat Campaign Targets Python Developers. Read more.


Threat Actors Weaponize AI Hype to Deliver ASYNCRAT

Source: Fortinet
(Published: 6 June 2026)
Fortinet analyzes malware activity, delivery tradecraft, and victim impact related to Threat Actors Weaponize AI Hype to Deliver ASYNCRAT. Read more.


Browser Addons Spy on AI Chats

Source: G DATA
(Published: 7 June 2026)
G DATA analyzes attacker abuse of AI-themed lures, tools, or workflows related to Browser Addons Spy on AI Chats. Read more.


Stolen Futures the Long Term Criminal Value of Pediatric Healthcare Data

Source: PolySwarm
(Published: 7 June 2026)
PolySwarm analyzes recent threat activity and defensive considerations related to Stolen Futures the Long Term Criminal Value of Pediatric Healthcare Data. Read more.


Underthehood Believe Me I Am Mustang Panda

Source: ExaTrack
(Published: 7 June 2026)
ExaTrack analyzes state-linked threat activity and targeting patterns related to Underthehood Believe Me I Am Mustang Panda. Read more.


XWORM Sc Hok May 2026

Source: Deception Pro
(Published: 7 June 2026)
Deception Pro analyzes recent threat activity and defensive considerations related to XWORM Sc Hok May 2026. Read more.


from Minecraft Mods to Malware as a Service Inside the Weedhack Ecosystem

Source: PolySwarm
(Published: 7 June 2026)
PolySwarm analyzes malware activity, delivery tradecraft, and victim impact related to from Minecraft Mods to Malware as a Service Inside the Weedhack Ecosystem. Read more.


the Evolving Threat Landscape for Legal Services in 2026

Source: PolySwarm
(Published: 7 June 2026)
PolySwarm analyzes recent threat activity and defensive considerations related to the Evolving Threat Landscape for Legal Services in 2026. Read more.


AI Brands as Bait How Threat Actors Are Using the AI Hype in Social Engineering

Source: Microsoft Security
(Published: 8 June 2026)
Microsoft Security analyzes attacker abuse of AI-themed lures, tools, or workflows related to AI Brands as Bait How Threat Actors Are Using the AI Hype in Social Engineering. Read more.


Following a Usps Smishing Kit Through Censys DNS Data

Source: Censys
(Published: 8 June 2026)
Censys analyzes a phishing or social engineering campaign involving Following a Usps Smishing Kit Through Censys DNS Data. Read more.


Fsbs Matryoshka 2 3 Gamaredon’s Gifts That Keeps Unpacking GammaLoad

Source: Sekoia
(Published: 8 June 2026)
Sekoia analyzes state-linked threat activity and targeting patterns related to Fsbs Matryoshka 2 3 Gamaredon’s Gifts That Keeps Unpacking GammaLoad. Read more.


Fsbs Matryoshka 3 3 Gamaredon’s Gifts That Keeps Unpacking GammaSteel

Source: Sekoia
(Published: 8 June 2026)
Sekoia analyzes state-linked threat activity and targeting patterns related to Fsbs Matryoshka 3 3 Gamaredon’s Gifts That Keeps Unpacking GammaSteel. Read more.


Spam PDFS on Official EU Infrastructure Trusted Domain Dirty Search Results

Source: Synaptic Systems
(Published: 8 June 2026)
Synaptic Systems analyzes attacker abuse of AI-themed lures, tools, or workflows related to Spam PDFS on Official EU Infrastructure Trusted Domain Dirty Search Results. Read more.


a Tale of Two Eras

Source: Cisco Talos
(Published: 8 June 2026)
Cisco Talos analyzes recent threat activity and defensive considerations related to a Tale of Two Eras. Read more.


AI Brands Fuel Phishing

Source: CyberPress
(Published: 9 June 2026)
CyberPress analyzes a phishing or social engineering campaign involving AI Brands Fuel Phishing. Read more.


Prc Targets US Medical Research

Source: Google Cloud
(Published: 9 June 2026)
Google Cloud analyzes state-linked threat activity and targeting patterns related to Prc Targets US Medical Research. Read more.


Shinyhunters Targets Education Sector Oracle Exploit

Source: Google Cloud
(Published: 9 June 2026)
Google Cloud analyzes exploitation activity and defensive implications related to Shinyhunters Targets Education Sector Oracle Exploit. Read more.


Targeted Campaign US Law Firms

Source: Google Cloud
(Published: 9 June 2026)
Google Cloud analyzes attacker abuse of AI-themed lures, tools, or workflows related to Targeted Campaign US Law Firms. Read more.


UNC1151 Gmail Campaign

Source: CERT Polska
(Published: 9 June 2026)
CERT Polska analyzes attacker abuse of AI-themed lures, tools, or workflows related to UNC1151 Gmail Campaign. Read more.


from Fake Amazon Security Alert to Harborwatch Agent Clickfix Delivery of a Custom Monitoring RAT

Source: Cofense
(Published: 9 June 2026)
Cofense analyzes malware activity, delivery tradecraft, and victim impact related to from Fake Amazon Security Alert to Harborwatch Agent Clickfix Delivery of a Custom Monitoring RAT. Read more.


Agentic Threat Actor Hits the Orchestration Plane AI Agent Driven Container Escape

Source: Sysdig
(Published: 10 June 2026)
Sysdig analyzes malware activity, delivery tradecraft, and victim impact related to Agentic Threat Actor Hits the Orchestration Plane AI Agent Driven Container Escape. Read more.


Azureveil Spearphishing Delivers C2

Source: CyberPress
(Published: 10 June 2026)
CyberPress analyzes a phishing or social engineering campaign involving Azureveil Spearphishing Delivers C2. Read more.


Dark Web Profile Tengu Ransomware Shisa

Source: SOCRadar
(Published: 10 June 2026)
SOCRadar analyzes ransomware or extortion activity tied to Dark Web Profile Tengu Ransomware Shisa. Read more.


How Attackers Are Jailbreaking LLMs with Ctf Framing and How to Catch Them

Source: Sysdig
(Published: 10 June 2026)
Sysdig analyzes attacker abuse of AI-themed lures, tools, or workflows related to How Attackers Are Jailbreaking LLMs with Ctf Framing and How to Catch Them. Read more.


Kali365 Anatomy of a Microsoft 365 Phishing as a Service Kit

Source: SpyCloud
(Published: 10 June 2026)
SpyCloud analyzes a phishing or social engineering campaign involving Kali365 Anatomy of a Microsoft 365 Phishing as a Service Kit. Read more.


Pink Data Extortion Group Phishing Kits

Source: SOCRadar
(Published: 10 June 2026)
SOCRadar analyzes a phishing or social engineering campaign involving Pink Data Extortion Group Phishing Kits. Read more.


Behind Khmer Shadow Targeted Espionage Against Cambodian Government Entities

Source: Acronis
(Published: 11 June 2026)
Acronis analyzes attacker abuse of AI-themed lures, tools, or workflows related to Behind Khmer Shadow Targeted Espionage Against Cambodian Government Entities. Read more.


Cato Ctrl Previously Undocumented Ninjaone RMM Abuse Chain

Source: Cato Networks
(Published: 11 June 2026)
Cato Networks analyzes attacker abuse of AI-themed lures, tools, or workflows related to Cato Ctrl Previously Undocumented Ninjaone RMM Abuse Chain. Read more.


Check Point VPN CVE 2026 50751 Qilin Ransomware

Source: Trojan-Killer
(Published: 11 June 2026)
Trojan-Killer analyzes ransomware or extortion activity tied to Check Point VPN CVE 2026 50751 Qilin Ransomware. Read more.


Compromised Rust Crate Onering Performs Code Exfiltration

Source: Aikido
(Published: 11 June 2026)
Aikido analyzes a supply chain or developer ecosystem compromise involving Compromised Rust Crate Onering Performs Code Exfiltration. Read more.


FlutterBridge New FlutterShell Backdoor

Source: Unit 42 (Palo Alto Networks)
(Published: 11 June 2026)
Unit 42 (Palo Alto Networks) analyzes malware activity, delivery tradecraft, and victim impact related to FlutterBridge New FlutterShell Backdoor. Read more.


Optinmonster Trustpulse Pushengage Backdoor

Source: Trojan-Killer
(Published: 11 June 2026)
Trojan-Killer analyzes malware activity, delivery tradecraft, and victim impact related to Optinmonster Trustpulse Pushengage Backdoor. Read more.


Cpuid Hwmonitor Xvpn DLL Sideloading Stx RAT

Source: Cyderes
(Published: 12 June 2026)
Cyderes analyzes exploitation activity and defensive implications related to Cpuid Hwmonitor Xvpn DLL Sideloading Stx RAT. Read more.


Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency

Source: Cryptika
(Published: 12 June 2026)
Cryptika analyzes recent threat activity and defensive considerations related to Hackers Abuse Fake Utility Downloads to Install ScreenConnect and Mine Cryptocurrency. Read more.


Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees

Source: Cryptika
(Published: 12 June 2026)
Cryptika analyzes attacker abuse of AI-themed lures, tools, or workflows related to Hackers Use Microsoft Graph Reconnaissance to Target Payroll and HR Employees. Read more.


Hackers Use OnyxC2 Malware as a Service to Steal Credentials from 210 Applications

Source: Cryptika
(Published: 12 June 2026)
Cryptika analyzes malware activity, delivery tradecraft, and victim impact related to Hackers Use OnyxC2 Malware as a Service to Steal Credentials from 210 Applications. Read more.


WINRAR Vulnerability Exploited by Russian Hackers to Deploy GiftedCrook Stealer

Source: Cryptika
(Published: 12 June 2026)
Cryptika analyzes exploitation activity and defensive implications related to WINRAR Vulnerability Exploited by Russian Hackers to Deploy GiftedCrook Stealer. Read more.


the Job Hunt Trap Unmasking the Puma Careers Phishing Campaign

Source: CyberProof
(Published: 12 June 2026)
CyberProof analyzes a phishing or social engineering campaign involving the Job Hunt Trap Unmasking the Puma Careers Phishing Campaign. Read more.


GoFlateLoader Delivers Multiple Infostealers

Source: Gen Digital
(Published: 13 June 2026)
Gen Digital analyzes malware activity, delivery tradecraft, and victim impact related to GoFlateLoader Delivers Multiple Infostealers. Read more.


Greatxml Windows Zero Day

Source: Cyderes
(Published: 13 June 2026)
Cyderes analyzes exploitation activity and defensive implications related to Greatxml Windows Zero Day. Read more.


New NPM Supply Chain Campaign Identified a Multi Stage Cryptocurrency Malware with More Than 2 7 Million Downloads

Source: CYFIRMA
(Published: 13 June 2026)
CYFIRMA analyzes a supply chain or developer ecosystem compromise involving New NPM Supply Chain Campaign Identified a Multi Stage Cryptocurrency Malware with More Than 2 7 Million Downloads. Read more.


Oniondrop Malware Analysis

Source: Cyderes
(Published: 13 June 2026)
Cyderes analyzes malware activity, delivery tradecraft, and victim impact related to Oniondrop Malware Analysis. Read more.


Operation Taxshadow Multi Region Tax Phishing in Memory Malware Campaign

Source: CYFIRMA
(Published: 13 June 2026)
CYFIRMA analyzes a phishing or social engineering campaign involving Operation Taxshadow Multi Region Tax Phishing in Memory Malware Campaign. Read more.


Rogueplanet Windows Zero Day

Source: Cyderes
(Published: 13 June 2026)
Cyderes analyzes exploitation activity and defensive implications related to Rogueplanet Windows Zero Day. Read more.


Akira Ransomware Limewire Data Exfiltration

Source: Huntress
(Published: 14 June 2026)
Huntress analyzes ransomware or extortion activity tied to Akira Ransomware Limewire Data Exfiltration. Read more.


Error 524 Decoy Smishing

Source: Group-IB
(Published: 14 June 2026)
Group-IB analyzes a phishing or social engineering campaign involving Error 524 Decoy Smishing. Read more.


Inside Sniperdz PHAAS Ecosystem

Source: Group-IB
(Published: 14 June 2026)
Group-IB analyzes a phishing or social engineering campaign involving Inside Sniperdz PHAAS Ecosystem. Read more.


Kali365 Device Code Phishing Kit

Source: Huntress
(Published: 14 June 2026)
Huntress analyzes a phishing or social engineering campaign involving Kali365 Device Code Phishing Kit. Read more.


Narwhalrat

Source: Genians
(Published: 14 June 2026)
Genians analyzes malware activity, delivery tradecraft, and victim impact related to Narwhalrat. Read more.


Silabrat Hijackloader Trojan Malware

Source: Group-IB
(Published: 14 June 2026)
Group-IB analyzes malware activity, delivery tradecraft, and victim impact related to Silabrat Hijackloader Trojan Malware. Read more.


Expanded Jdy IOT and SOHO Botnet Enables Rapid Vulnerability Exploitation

Source: Lumen
(Published: 15 June 2026)
Lumen analyzes exploitation activity and defensive implications related to Expanded Jdy IOT and SOHO Botnet Enables Rapid Vulnerability Exploitation. Read more.


Fifa World Cup 2026 Emerging Domain Activity

Source: Malware Patrol
(Published: 15 June 2026)
Malware Patrol analyzes attacker abuse of AI-themed lures, tools, or workflows related to Fifa World Cup 2026 Emerging Domain Activity. Read more.


Interlock and Rhysida Within the Ransonware Ecosystem

Source: IBM X-Force
(Published: 15 June 2026)
IBM X-Force analyzes recent threat activity and defensive considerations related to Interlock and Rhysida Within the Ransonware Ecosystem. Read more.


Malspam to Deskcvb RAT Delivery Chain Analysis

Source: Huntress
(Published: 15 June 2026)
Huntress analyzes malware activity, delivery tradecraft, and victim impact related to Malspam to Deskcvb RAT Delivery Chain Analysis. Read more.


Malspam to Loader Delivery Chain Analysis

Source: Huntress
(Published: 15 June 2026)
Huntress analyzes malware activity, delivery tradecraft, and victim impact related to Malspam to Loader Delivery Chain Analysis. Read more.


These Convincing Copyright Notices Are Designed to Steal Google Logins

Source: Malwarebytes
(Published: 15 June 2026)
Malwarebytes analyzes a phishing or social engineering campaign involving These Convincing Copyright Notices Are Designed to Steal Google Logins. Read more.


Rogueplanet Anatomy of the Nightmare Eclipse Microsoft Defender Zero Day

Source: Picus Security
(Published: 16 June 2026)
Picus Security analyzes exploitation activity and defensive implications related to Rogueplanet Anatomy of the Nightmare Eclipse Microsoft Defender Zero Day. Read more.


Weedhack Minecraft Malware as a Service Campaign Research

Source: McAfee
(Published: 16 June 2026)
McAfee analyzes malware activity, delivery tradecraft, and victim impact related to Weedhack Minecraft Malware as a Service Campaign Research. Read more.


from Phishing Email to Process Injection Inside a Multi Stage Agent Tesla Infection Chain

Source: Point Wild
(Published: 16 June 2026)
Point Wild analyzes a phishing or social engineering campaign involving from Phishing Email to Process Injection Inside a Multi Stage Agent Tesla Infection Chain. Read more.


Want more articles? Check out the previous edition of Security Signals here. 

Free Evaluation

Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.

Take advantage of a free trial to test our data for yourself.

?