Operation Endgame successfully disrupted the SocGholish (TA569) initial access framework, which relies on compromised WordPress sites and Traffic Distribution Systems (TDS) to deliver fake browser updates. The threat actor utilizes domain shadowing and a multi-stage JScript payload to establish footholds, primarily targeting corporate environments during standard work weeks to facilitate follow-on ransomware deployment.
Critical Infrastructure
9 posts
Hot Take: Operation Endgame vs. SocGholish NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems The NCSC CEO reported that approximately 75% of the 200+ cyber incidents affecting UK critical national infrastructure over the past year were linked to hostile state actors such as Russia, China, and Iran. The NCSC warns that unpatched legacy systems pose a severe risk, particularly as AI-enabled cyber capabilities are projected to accelerate the exploitation of known vulnerabilities at scale by 2028.
APT28, an evolution of tradecraft Sekoia's Threat Detection & Research team details the two-decade evolution of APT28's tradecraft, highlighting a strategic shift from monolithic implants to disposable, single-purpose tools and compromised edge-router infrastructure. Recent operations demonstrate a return to custom cloud-resident backdoors and novel experimentation with LLM-driven infostealers.
FSB’s matryoshka #2/3 – Gamaredon’s gifts that keeps unpacking – GammaLoad Gamaredon, a Russia-nexus threat actor, utilizes a multi-stage VBScript loader framework named GammaLoad to establish persistent access and deploy subsequent payloads like GammaSteel. The infection chain leverages Dead Drop Resolvers on legitimate platforms, stores C2 configurations in the Windows Registry, and uses Alternate Data Streams (ADS) combined with Scheduled Tasks for stealthy execution.
CISA and Partners Urge Hardening Automatic Tank Gauge Systems (2026-06-02) CISA and partner agencies have observed unattributed malicious cyber activity targeting internet-exposed Automatic Tank Gauge (ATG) systems across multiple U.S. critical infrastructure sectors. Threat actors are leveraging authentication bypass, hardcoded credentials, and command execution vulnerabilities to gain administrative control, enabling them to manipulate tank parameters, disable safety alerts, and create denial-of-view conditions.
The State of Ransomware – Q1 2026 In Q1 2026, the ransomware ecosystem experienced significant consolidation, with top groups like Qilin, Akira, The Gentlemen, and LockBit 5.0 dominating the landscape. Notably, The Gentlemen leveraged a massive stockpile of pre-exploited FortiGate devices (CVE-2024-55591) to rapidly scale operations, while LockBit 5.0 returned with multi-platform capabilities and a strategic shift away from US targets to evade law enforcement.
Iran War: Future Scenarios and Business Implications Insikt Group analyzed the evolving Iran conflict using the PESTLE-M framework to generate multiple future scenarios, ranging from a fragile ceasefire to regional war or nuclear crisis. The report highlights the persistent threat of economic disruption, maritime coercion, and intensified cyber operations targeting critical infrastructure, urging organizations to build resilience across supply chains and cybersecurity postures.
TrendAI Insight: New U.S. National Cyber Strategy The White House Office of the National Cyber Director (ONCD) has released a new National Cyber Strategy detailing six pillars of focus. The strategy emphasizes modernizing federal networks, securing critical infrastructure, maintaining superiority in emerging technologies like AI, and building cyber talent capacity.
Preparing for Russia’s New Generation Warfare in Europe Over the next two years, Russia is expected to escalate its hybrid warfare against NATO into a coordinated New Generation Warfare (NGW) campaign. This strategy integrates cyber operations, physical sabotage, influence campaigns, and airspace/maritime incursions to degrade European critical infrastructure and political unity while remaining below the threshold of conventional armed conflict.