Skip to content
.ca
sign in

Threat intelligence from Mandiant

28 reports on cyfar.ca summarizing Mandiant research. Visit Mandiant

Mandiant7 days ago13 minLLM reporthigh

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

UNC6671 is an active extortion group that has expanded operations across five brands (BlackFile, Redact, Pink, Helix, Falcon) despite announcing BlackFile's retirement in May 2026. The group consistently uses IT helpdesk voice phishing (vishing) to target employees on personal mobile devices, directing them to Adversary-in-the-Middle (AiTM) credential harvesting panels hosted on passkey-themed domains. Stolen sessions are used to deploy automated scripts exfiltrating data from Microsoft 365 and Okta environments. Shared infrastructure, identical phishing templates, and overlapping victim targeting across all brands indicate a coordinated group. Recent targeting has narrowed to financial services, private equity, and legal sectors, with ransom demands ranging from $1M to $3M USD and final payments averaging approximately $750,000.

Mandiant15 days ago12 minLLM reporthigh

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Google Threat Intelligence Group (GTIG) and Mandiant report a significant escalation in open source software supply chain compromises throughout 2025 and early 2026, with malicious package detections increasing 1,444% year-over-year. Threat actors including UNC6780 (TeamPCP), MIDNIGHT NEPTUNE, and UNC4899 have exploited package registries (PyPI, npm, Docker Hub), GitHub Actions triggers, and developer social engineering to deploy credential stealers, backdoors, and cryptocurrency theft mechanisms. The integration of AI into development workflows further accelerates this threat vector as AI coding agents unwittingly incorporate malicious dependencies into legitimate projects.

Mandiant21 days ago4 minLLM reportlow

Updated Cyber Threat Actor Naming System

Google Threat Intelligence Group (GTIG) announced a new unified cryptonym-based naming taxonomy for threat actor tracking, merging the previously separate Mandiant and TAG naming systems. The schema assigns each actor a memorable two-word cryptonym, where the second word denotes category (e.g., origin/motivation such as nation-state attribution or cybercriminal activity), improving cross-platform consistency and reducing reliance on sequential identifiers like APT numbers.

Mandiant29 days ago9 minLLM reportlow

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

This article provides a structural blueprint for safely integrating LLM agents into vulnerability management workflows, covering both enterprise vulnerability management and product security tracks. It outlines operational guardrails including pre-agent data security, workload isolation, least-privileged machine identities, toxic flow analysis, and supply chain resilience for AI skills. The guidance emphasizes that LLMs augment but do not replace deterministic controls, human threat modeling, and secure-by-design principles, and recommends phasing memory-safe languages into new development as a long-term strategy.

Mandiant29 days ago8 minLLM reporthigh

The Risk of Exposed Cloud Functions and How to Harden

Mandiant identifies publicly exposed serverless applications lacking authentication as a significant risk during security assessments. Attackers can exploit Local File Inclusion (LFI) or command injection vulnerabilities in custom code to read sensitive files, extract hardcoded secrets, and retrieve GCP service account bearer tokens from the metadata service. Stolen tokens enable lateral movement and potential full cloud project compromise, especially when Cloud Run services use over-privileged default service accounts. The blog provides hardening guidance including least-privilege IAM, Cloud Armor WAF policies, VPC Service Controls, and Secure SDLC practices.

Mandiantabout 1 month ago11 minLLM reporthigh

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Mandiant discovered that ADFS environments with AutoCertificateRollover disabled and manually rotated certificates can expose active token-signing private keys in Machine DPAPI storage, creating a 'ghost certificate' drift condition where the WID database contains stale entries. A SYSTEM-level attacker can recover the active signing key from the machine CAPI key store using the DPAPI_SYSTEM LSA secret and machine masterkeys, bypassing LSASS and ADFS process monitoring. The recovered key enables forging valid SAML assertions for any user, including Global Administrator, which Entra ID accepts as legitimate authentication.

Mandiantabout 1 month ago8 minLLM reporthigh

Google’s Continued Disruption of Malicious Residential Proxy Networks

Google, in coordination with the FBI and Lumen, disrupted the NetNut residential proxy network (aka Popa), which is estimated to comprise at least 2 million consumer devices enrolled as proxy exit nodes via malicious SDKs embedded in apps and firmware. The network was used by 316 distinct threat clusters in a single week for masking origin IPs, password spraying, and other malicious activity. Google disabled associated C2 accounts, shared intelligence with partners, and enabled Google Play Protect to warn users about apps containing NetNut SDKs.

Mandiantabout 1 month ago11 minLLM reportcritical

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Mandiant identified a threat actor exploiting zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to escalate privileges from a compromised administrative account to root-level access via a malicious CSV file upload. The intrusion began with rogue peering connections, potentially leveraging CVE-2026-20127 or CVE-2026-20182, followed by SSH access using the vmanage-admin account, password manipulation of the admin account, and ultimately root access through a crafted evil_tenant.csv payload that modified /etc/passwd and /etc/shadow. The threat actor employed extensive anti-forensic techniques including file deletion, configuration restoration, and validation script execution to purge indicators.

Mandiantabout 1 month ago14 minLLM reporthigh

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Google Threat Intelligence Group analyzed STOCKSTAY, a modular .NET backdoor developed and operated by Turla since late 2022, which uses a WebSocket-based C2 channel, RSA/AES encrypted communications, and IPC via WM_COPYDATA between its downloader, orchestrator, tunneler, and backdoor components. STOCKSTAY exhibits strong code, architectural, and obfuscation (K1MORPHER) overlaps with KAZUAR, suggesting a shared development team, and has been deployed via phishing (malicious RDP files, HTA lures) and, most recently, exploitation of CVE-2025-8088 in WinRAR to target Ukrainian military personnel. The actor leverages legitimate hosting platforms (Render, Glitch, GitHub) and compromised third-party/government infrastructure to obscure C2 infrastructure and complicate attribution.

Mandiantabout 1 month ago11 minLLM reportmedium

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Google Threat Intelligence Group analyzes the evolution of the pro-Russia influence ecosystem four years into the full-scale invasion of Ukraine, identifying a pivot from war-focused operations back to global strategic objectives targeting the West, NATO, and the EU. The ecosystem comprises six interconnected components — overt media, covert IO campaigns, hacktivism, cyber espionage, government direction, and outsourced proxies — that cross-promote and amplify narratives. Key trends include the increasing use of generative AI for content creation, the blending of cyber espionage with influence operations via hack-and-leak tactics, and the outsourcing of capability development to contractors like NTC Vulkan for plausible deniability.

Mandiantabout 2 months ago6 minLLM reportcritical

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Google Threat Intelligence Group identified a PRC-nexus espionage campaign by UNC6508 targeting North American research and defense entities. The actors compromised REDCap servers to deploy INFINITERED, a custom malware that harvests credentials and intercepts software upgrades for persistence. Using stolen credentials, the attackers pivoted to administrative accounts and abused email content compliance rules to covertly exfiltrate sensitive intelligence.

Mandiant2 months ago6 minLLM reportcritical

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Mandiant and Google Threat Intelligence Group identified an active extortion campaign by UNC6240 (ShinyHunters) exploiting CVE-2026-35273, a critical zero-day RCE vulnerability in Oracle PeopleSoft. The threat actors targeted the higher education sector, deploying customized MeshCentral agents for C2 and utilizing custom scripts for lateral movement, defacement, and data exfiltration.

Mandiant2 months ago7 minLLM reporthigh

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

The financially motivated threat cluster UNC3753 is conducting a fast-paced data theft and extortion campaign against US legal and professional services. The group leverages vishing and IT helpdesk impersonation to trick targets into installing legitimate RMM and screen-sharing tools, enabling rapid data exfiltration from corporate repositories and VDI environments. Notably, the campaign also involves suspected physical intrusions where actors use USB media to steal data directly from endpoints.

Mandiant3 months ago6 minLLM reportcritical

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

A critical ViewState deserialization vulnerability (CVE-2026-5426) in the KnowledgeDeliver LMS allows unauthenticated remote code execution due to shared ASP.NET machine keys across deployments. Threat actors are actively exploiting this flaw to deploy the BLUEBEAM in-memory web shell and modify application JavaScript, ultimately distributing targeted Cobalt Strike BEACON payloads to end-users visiting the compromised sites.

Mandiant3 months ago5 minLLM reporthigh

2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services

Chinese-language Phishing-as-a-Service (PhaaS) platforms are evolving to utilize real-time interception and AI-driven automation to bypass MFA and tokenize stolen payment data into digital wallets. Threat actors leverage encrypted messaging protocols like RCS and iMessage for delivery, while platforms like YY Lai Yu provide highly localized, dynamic phishing infrastructure to target global consumers.

Mandiant3 months ago6 minLLM reporthigh

Welcome to BlackFile: Inside a Vishing Extortion Operation

UNC6671, operating under the BlackFile brand, conducts sophisticated vishing and Adversary-in-the-Middle (AiTM) attacks to bypass MFA and compromise SSO platforms like Microsoft 365 and Okta. Once inside, the group uses automated Python and PowerShell scripts to rapidly exfiltrate sensitive data via APIs, often masking their activity as routine file access events, before launching aggressive extortion campaigns.

Mandiant3 months ago6 minLLM reporthigh

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Google Threat Intelligence Group (GTIG) reports an escalation in adversaries leveraging generative AI for vulnerability discovery, autonomous malware orchestration, and defense evasion. Notable developments include the AI-assisted discovery of a zero-day 2FA bypass, the PROMPTSPY Android backdoor utilizing the Gemini API for autonomous UI navigation, and supply chain attacks by TeamPCP targeting AI dependencies like LiteLLM to extract cloud secrets.

Mandiant3 months ago6 minLLM reportcritical

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Google Threat Intelligence Group identified UNC6692, a threat actor utilizing Microsoft Teams phishing and email bombing to deploy a custom modular malware suite. The attack chain leverages a malicious Chromium extension (SNOWBELT), a Python tunneler (SNOWGLAZE), and a Python bindshell (SNOWBASIN) to establish persistence, move laterally, and exfiltrate sensitive Active Directory data via legitimate cloud services.

Mandiant3 months ago4 minLLM reporthigh

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

The rapid advancement of AI models has significantly lowered the barrier for threat actors to discover vulnerabilities and generate exploits at scale, compressing the attack lifecycle. To defend against these machine-speed threats, organizations must modernize their security posture by integrating AI defensively, automating vulnerability management, securing software supply chains, and protecting newly deployed AI assets.

Mandiant3 months ago4 minLLM reporthigh

The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape

In 2025, Germany became the primary focus for cyber extortion in Europe, experiencing a 92% surge in data leak site victims. The disruption of major ransomware cartels has given rise to agile mid-tier groups like SAFEPAY and Qilin, who are heavily targeting the German Mittelstand (SMEs) and critical supply chain sectors such as manufacturing and professional services.