Skip to content
.ca
sign in

Threat intelligence from Microsoft

25 reports on cyfar.ca summarizing Microsoft research. Visit Microsoft

Microsoft4 days ago11 minLLM reporthigh

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Microsoft Threat Intelligence tracked a macOS ClickFix campaign distributing AMOS and MacSync infostealers through 250+ algorithmically named domains. The campaign evolved from openly embedding malicious Terminal commands in HTML to deploying a server-side browser-fingerprinting gate (TDS) that only serves the ClickFix lure to visitors presenting a genuine macOS browser fingerprint, significantly reducing visibility for automated scanners and researchers. The infection chain uses social engineering to trick users into running curl-piped-to-shell commands that download and execute AMOS, which exfiltrates credentials, browser data, and cryptocurrency wallets.

Microsoft5 days ago12 minLLM reportcritical

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 400+ packages across multiple publishers, delivering a self-propagating credential-stealing worm called Mini Shai-Hulud. The malware executes via npm preinstall lifecycle hooks, harvests credentials from developer workstations and CI/CD environments, authenticates to cloud and infrastructure services to enumerate additional secrets, and uses stolen npm publishing tokens to automatically modify and republish packages — creating worm-like propagation. Persistence is achieved by injecting malicious configuration files into Claude and VS Code workspace settings within compromised GitHub repositories.

Microsoft9 days ago14 minLLM reportcritical

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Threat Intelligence identifies Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread captive portal traffic manipulation attacks since May 2026 targeting travelers at hospitality venues worldwide. The campaign delivers CornFlake, a Go-based Windows RAT with comprehensive surveillance and credential theft capabilities, and ChocoShell, a PowerShell-based infostealer that bypasses AMSI, employs multiple UAC bypass techniques, and extracts browser credentials via Chrome DevTools Protocol to circumvent Chrome App-Bound Encryption. The operation also integrates device code phishing against Microsoft Entra ID, leveraging AI-augmented social engineering and ClickFix techniques to maximize victim compliance.

Microsoft17 days ago12 minLLM reportmedium

Email threat landscape: Q2 2026 trends and insights

Microsoft's Q2 2026 email threat report details the sustained downstream impact of the Tycoon2FA PhaaS disruption (92% volume decline) alongside a broader shift toward alternative delivery mechanisms including QR codes, CAPTCHA-gated pages, and increasingly Microsoft Teams-based vishing. Two notable campaigns illustrate operational sophistication: a fully automated, API-driven BEC operation reaching tens of thousands of victims in hours, and a multi-stage credential-phishing-to-malware chain abusing Microsoft's OAuth silent sign-in flow and a legitimate ClickUp attachment host to deliver a PowerShell-based BAT dropper.

Microsoft23 days ago11 minLLM reporthigh

ACR Stealer: Two observed intrusion chains amid increased threat activity

Microsoft Defender Experts identified two prevalent ClickFix-based intrusion chains delivering ACR Stealer, a MaaS information stealer rebranded from Amatera Stealer. Campaign 1 leverages rundll32-driven WebDAV DLL loading, obfuscated PowerShell, Python loaders, scheduled-task persistence, and Fiber-API in-memory shellcode execution, with a subset using blockchain RPC endpoints (EtherHiding) as dead-drop C2 resolvers. Campaign 2 achieves near-fully fileless execution via MSHTA/COM-launched PowerShell that retrieves a payload hidden in JPEG steganography and executes it reflectively in memory, with both chains ultimately harvesting browser credentials, DPAPI secrets, and sensitive documents for exfiltration.

Microsoft25 days ago14 minLLM reportcritical

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

A coordinated supply chain compromise of the @asyncapi npm organization delivered malicious payloads through five package versions published via the project's legitimate GitHub Actions OIDC trusted publishing pipeline. The attack originated from a pwn request exploiting a misconfigured pullrequesttarget workflow that exposed the asyncapi-bot PAT, enabling unauthorized commits to auto-publish branches. Unlike typical npm supply-chain attacks, the payload executes at import/require time rather than through lifecycle hooks, bypassing --ignore-scripts mitigations. The second stage fetches an encrypted ~8.2 MB Miasma modular runtime from IPFS, establishing C2 at 85.137.53.71 with OS-specific persistence and decentralized fallback channels.

Microsoftabout 1 month ago12 minLLM reportcritical

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

GigaWiper is a sophisticated Golang-based backdoor discovered by Microsoft Threat Intelligence in October 2025 that amalgamates at least three previously separate malware families — a standalone disk wiper, Crucio ransomware, and FlockWiper — into a single modular implant with 20 commands. It uses RabbitMQ and Redis for C2 communication, establishes persistence via scheduled tasks, and offers capabilities including disk wiping, fake ransomware (with unrecoverable encryption), BSOD induction, screen recording, keylogging, registry management, event log clearing, and VNC-like remote control. The malware masquerades as legitimate Windows components (OneDrive Update, CloudExperienceHost) and uses AES-encrypted configurations with hard-coded credentials.

Microsoftabout 1 month ago12 minLLM reporthigh

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them

StealC is a C++ malware-as-a-service infostealer that harvests credentials, cookies, and session tokens from browsers, email clients, crypto wallets, and gaming platforms, using APC injection to bypass Chromium App-Bound Encryption. Amadey is a modular MaaS loader that delivers StealC and other payloads through a rich backdoor command set including process injection, SOCKS proxying, RDP enablement, and hidden admin account creation. Microsoft DCU disrupted over 200 C2 domains and IPs associated with both threats in a coordinated action with Europol on June 24, 2026.

Microsoftabout 2 months ago8 minLLM reportcritical

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet

Microsoft identified a large-scale npm supply chain attack by North Korean threat actor Sapphire Sleet, compromising over 140 packages in the Mastra ecosystem. The attackers used a compromised maintainer account to inject a malicious typosquat dependency that executes a cross-platform Node.js implant during installation, leading to cryptocurrency wallet theft, host reconnaissance, and persistent backdoor access.

Microsoft2 months ago7 minLLM reporthigh

AI brands as bait: How threat actors are using the AI hype in social engineering

Threat actors are increasingly leveraging the hype around AI platforms like ChatGPT, Claude, and DeepSeek to conduct social engineering attacks. These campaigns utilize phishing, malvertising, and SEO poisoning to distribute infostealers such as Vidar or facilitate credential theft via adversary-in-the-middle (AiTM) infrastructure.

Microsoft2 months ago6 minLLM reportcritical

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

The Gentlemen ransomware, operated by Storm-2697, is a Go-based encryptor that combines robust Curve25519/XChaCha20 encryption with aggressive lateral movement capabilities. It utilizes multiple redundant propagation methods (PsExec, WMI, scheduled tasks, services) to maximize network compromise while employing extensive defense evasion techniques to hinder detection and recovery.

Microsoft3 months ago6 minLLM reporthigh

Exposing Fox Tempest: A malware-signing service operation

Fox Tempest is a financially motivated threat actor providing malware-signing-as-a-service (MSaaS) to the cybercrime ecosystem. By abusing Microsoft Artifact Signing via stolen identities, they generate short-lived, fraudulent code-signing certificates that allow threat actors like Vanilla Tempest to bypass security controls and deploy payloads such as the Oyster backdoor and Rhysida ransomware.

Microsoft3 months ago6 minLLM reportcritical

Kazuar: Anatomy of a nation-state botnet

Kazuar is a sophisticated, modular P2P botnet attributed to the Russian state-sponsored actor Secret Blizzard. It utilizes a tripartite architecture (Kernel, Bridge, Worker) and a leader election mechanism to minimize external C2 traffic, relying on Mailslots, Window Messaging, and Named Pipes for internal communication and HTTP, WSS, or EWS for external C2.

Microsoft3 months ago6 minLLM reportcritical

Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise

A sophisticated threat actor compromised a third-party IT services provider to abuse legitimate HPE Operations Agent infrastructure, enabling stealthy execution and discovery. The attackers established persistence and harvested credentials using malicious network provider and password filter DLLs on domain controllers, while utilizing web shells and ngrok tunnels to maintain long-term, undetected access.

Microsoft3 months ago5 minLLM reporthigh

Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

A large-scale Adversary-in-the-Middle (AiTM) phishing campaign targeted over 35,000 users using sophisticated 'code of conduct' lures. The attack chain leveraged legitimate email services, PDF attachments, and multiple CAPTCHA gates to evade detection, ultimately proxying Microsoft 365 authentication sessions to steal tokens and bypass standard MFA.

Microsoft3 months ago6 minLLM reporthigh

Email threat landscape: Q1 2026 trends and insights

In Q1 2026, Microsoft observed 8.3 billion email-based phishing threats, characterized by a 146% surge in QR code phishing and rapid evolution in CAPTCHA-gated payload delivery. Despite disruption efforts against the Tycoon2FA adversary-in-the-middle (AiTM) platform, threat actors quickly adapted their infrastructure, while Business Email Compromise (BEC) remained highly prevalent using conversational social engineering.

Microsoft3 months ago7 minLLM reporthigh

Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise

Microsoft Threat Intelligence identified a macOS-focused campaign by North Korean threat actor Sapphire Sleet that uses social engineering to deliver malicious AppleScripts disguised as Zoom updates. The attack leverages built-in macOS utilities like curl and osascript to bypass security controls, manipulate TCC databases, harvest credentials, and exfiltrate sensitive data such as cryptocurrency wallets.

Microsoft3 months ago5 minLLM reporthigh

Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees

Storm-2755 is a financially motivated threat actor targeting Canadian organizations with 'payroll pirate' attacks. By leveraging SEO poisoning and Adversary-in-the-Middle (AiTM) techniques, the actor steals session tokens to bypass legacy MFA, maintains persistence using the Axios HTTP client, and alters direct deposit information to steal employee salaries.

Microsoft3 months ago4 minLLM reporthigh

SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks

Russian military intelligence actor Forest Blizzard is compromising vulnerable SOHO routers to alter DNS settings and hijack network traffic. This compromised infrastructure is subsequently used to conduct selective Adversary-in-the-Middle (AiTM) attacks, intercepting TLS connections to steal credentials and sensitive data from targeted organizations.

Microsoft3 months ago7 minLLM reportcritical

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations

Storm-1175 is a financially motivated threat actor that rapidly exploits N-day and zero-day vulnerabilities in web-facing assets to deploy Medusa ransomware. The group utilizes a high-tempo attack chain, leveraging LOLBins, RMM tools, and credential theft to move laterally and exfiltrate data before executing ransomware, often completing the entire attack lifecycle within days.