A threat actor compromised an IIS web server via Adobe ColdFusion vulnerabilities and deployed steganographic ASPX webshells concealed within image files. The attacker then executed a comprehensive defense impairment script that disabled IIS logging, tampered with Microsoft Defender through multiple vectors, killed and deleted security tool services, used IFEO debugger injection to neutralize monitoring binaries, and extracted credentials using a Mimikatz kernel driver after enabling WDigest plaintext caching. The attacker further uninstalled the ModSecurity WAF, deleted critical COM/CLSID registry keys to cripple OS functionality, and cleared all Windows event logs to destroy forensic evidence.
defense-impairment
50 posts
Defence Impairment Olympics Still Circling: Blind Eagle's Toolkit Keeps Evolving Blind Eagle (APT-C-36) has evolved its toolkit with three new obfuscation schemes, a GitHub-staged AutoIt3 RunPE loader, and a significantly upgraded AsyncRAT build codenamed JC-46 featuring WNF-based process injection, HVNC banking-fraud with browser profile cloning, and a Chrome App-Bound Encryption v20 bypass. A shared internal builder is evidenced by identical 'Photo Studio' persistence artifacts across three separately obfuscated toolchains. The group continues to rely on VBScript-to-PowerShell delivery chains and commodity RATs while selectively investing in components that directly serve banking-fraud objectives.
ACR Stealer: Two observed intrusion chains amid increased threat activity Microsoft Defender Experts identified two prevalent ClickFix-based intrusion chains delivering ACR Stealer, a MaaS information stealer rebranded from Amatera Stealer. Campaign 1 leverages rundll32-driven WebDAV DLL loading, obfuscated PowerShell, Python loaders, scheduled-task persistence, and Fiber-API in-memory shellcode execution, with a subset using blockchain RPC endpoints (EtherHiding) as dead-drop C2 resolvers. Campaign 2 achieves near-fully fileless execution via MSHTA/COM-launched PowerShell that retrieves a payload hidden in JPEG steganography and executes it reflectively in memory, with both chains ultimately harvesting browser credentials, DPAPI secrets, and sensitive documents for exfiltration.
The tale of ClickFix: 5 takeaways from RL’s new threat report ClickFix is a social engineering technique that uses fake CAPTCHA pages to trick users into pasting malicious commands into Run dialogs or terminals, executing payloads in memory via LOLBins without triggering traditional AV or EDR signatures. The threat has commoditized through MaaS subscriptions ($250–$1,800), expanded its payload catalog beyond infostealers to include RATs, loaders, and rootkits, and is actively evolving with variants like CrashFix, FileFix, PromptFix, and ConsentFix. ReversingLabs released an open-source multi-condition YARA rule that detects ClickFix lures by correlating fake verification characteristics, PowerShell payload indicators, and clipboard manipulation before payload execution.
HelloNet campaign — new malicious modules launched through the ViPNet update system The HelloNet campaign is an active APT operation targeting large Russian organizations through the ViPNet secure networking software suite. Attackers achieve persistence by placing a malicious wtsapi32.dll in the ViPNet Update System directory, which is sideloaded by itcsrvup64.exe at OS startup. The loader (HelloInjector) injects into svchost.exe and deploys a modular toolkit including a network proxy, command executor, log cleaner, and a Rust-based backdoor. The campaign uses renamed PuTTY/Plink utilities for SSH reverse tunneling to C2 servers and employs IOCTL hooking to evade user-mode security solutions.
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader A global phishing campaign active since late March 2026 deploys heavily obfuscated JScript droppers that launch LuaJIT or AutoIt-based loaders disguised as TrueType Font (.ttf) files to deliver multiple RATs and infostealers including Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant dubbed Best Private LOGGER. The Lua loader leverages LuaJIT's Foreign Function Interface to call native Windows APIs for in-memory shellcode execution, employing advanced evasion techniques such as decoy memory allocation, Donut header patching, AMSI/ETW bypass, API unhooking, and VEH-based segmented shellcode decryption. The campaign has evolved from October 2025 through June 2026 with progressively more sophisticated anti-analysis capabilities.
Spirals: New Stealthy Ransomware Deployed Against Asian IT Company A previously unseen Rust-based ransomware family named Spirals was deployed in a double extortion attack against a South Asian IT services company in June 2026. The attackers compromised an internet-facing IIS web server via an ASP.NET web shell, established multiple redundant C2 channels using revsocks, Chisel, and Cloudflare tunnel, performed credential theft via SAM and LSASS dumps, and deployed the ransomware payload via PsExec across the network within 24 hours of initial access. The ransomware uses AES-128 file encryption with ECDH P-256 key wrapping and includes capabilities for defense evasion, lateral movement, and process termination.
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict Between January and June 2026, Iran integrated AI technologies as a force multiplier across its hybrid warfare model — cyber operations, influence operations, military systems, and domestic surveillance — without fundamentally altering its asymmetric strategic doctrine. Iranian state-sponsored threat actors (APT42, MuddyWater, APT34, and others) leveraged LLMs to accelerate malware development, enhance spearphishing lures, and conduct ICS reconnaissance, while AI-generated propaganda and inauthentic social media accounts flooded the information environment at unprecedented scale. Russia likely transferred AI-enabled Shahed drone variants and operational tactics to Iran, though independent confirmation of AI use in 2026 kinetic operations remains limited.
Hidden Infrastructure Exposed: ANY.RUN Reveals Hijacked Gov Websites Delivering Malware PhantomEnigma is an active Brazil-focused crimeware campaign that compromises government infrastructure (.gov.br portals and police mailboxes) to deliver a modular Node.js backdoor embedded in patched Boostnote/Electron applications via Delphi-compiled Inno Setup installers. The operation uses at least two beacon generations (GET /laravel.php and POST /nbw/), rotates C2 domains weekly behind Cloudflare, and leverages trusted government email channels to bypass SPF/DKIM/DMARC checks. ANY.RUN analysts linked 231 sandbox analyses through a recurring build-chain fingerprint and connected a separate Ofício-PC QR-code phishing arm to the same operator via shared compromised government hosts.
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet TrendAI Research analyzed 200 Gemini CLI session logs from the Russian-speaking threat actor 'bandcampro,' revealing a solo operator who used Google Gemini CLI as the primary engineering agent to deploy and operate a C&C botnet targeting a dental clinic. The AI handled architecture design, coding, deployment, debugging, and WAF bypass autonomously, migrating the entire C&C infrastructure in six minutes. The operation is encoded in three portable plain-text files (~5KB) that can be shared and deployed by non-technical actors, representing a paradigm shift where AI lowers the skill barrier for complex cyber operations and makes infrastructure disposable and rapidly rebuildable.
Forgotten UEFI shims undermining Secure Boot ESET researchers identified 11 old, Microsoft-signed UEFI shim bootloaders (version 0.9 and below) that can bypass UEFI Secure Boot on any system trusting Microsoft's third-party UEFI CA 2011 certificate. The old shims lack modern security features (MokListX enforcement, SBAT) and contain known vulnerabilities (CVE-2026-10797) that enable revocation bypass, allowing attackers to execute untrusted code during boot and deploy UEFI bootkits. Exploitation does not require the affected software to be installed — attackers can bring their own copy of the vulnerable shim to any UEFI system with the Microsoft third-party certificate enrolled.
TELEPUZ: a modular MaaS malware spreading via CLICKFIX-VIDAR chains TELEPUZ is a rapidly evolving modular MaaS malware delivered via ClickFix social engineering and VIDAR second-stage downloader chains. The 64-bit Windows DLL payload uses indirect syscalls, NTDLL unhooking, AMSI/ETW patching, and custom RC4 encryption for defense evasion, while establishing persistence as a Windows service and communicating over WebSockets with fallback C2 resolution via Telegram, Steam, DNS records, and Polygon blockchain smart contracts. The malware supports 36 commands including process hollowing, keylogging, credential theft, browser cookie extraction, and a WebInjector module that abuses Chrome DevTools Protocol to manipulate financial web forms in real-time.
OkoBot: new sophisticated malware framework targets cryptocurrency users Kaspersky identified OkoBot, a sophisticated multi-stage malware framework delivered via the TookPS PowerShell downloader and orchestrated over an attacker-controlled SSH tunnel, targeting cryptocurrency users. The framework comprises over 20 interconnected payloads that perform UAC bypass, RDP hijacking, browser-extension based credential theft (Rilide), hardware-wallet seed-phrase phishing (SeedHunter), keylogging, and screen/video capture (OkoSpyware), all coordinated through a plugin dispatcher communicating over HTTP/HTTPS C2 channels. The campaign has been active since at least March 2025, continues to evolve its tooling, and shows indicators (geoblocking, Russian code comments, use of Rilide) consistent with Russian-speaking cybercriminal operators.
11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload Eleven malicious NuGet DotnetTool packages masquerading as game cheats deliver a two-stage Windows payload. The first-stage .NET downloader resolves GitHub hosts via DNS-over-HTTPS to bypass local DNS controls, requests UAC elevation to resync the system clock, and fetches pepesoft.exe from GitHub Releases and Hugging Face. The second-stage PyInstaller-packed Python payload exfiltrates hardware fingerprints, system information, IP geolocation, and screenshots to Google Sheets and Telegram, with a server-side ban-list and hardware binding for licensing enforcement across all recovered builds.
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader Socket's Threat Research Team identified four compromised npm packages in the @asyncapi namespace delivering a multi-stage botnet loader called Miasma. The attack injects obfuscated JavaScript into package source files that executes at module load time (bypassing npm lifecycle script blocking), spawns a detached Node.js process to download an encrypted payload from IPFS, and deploys a 3+ MB tasking framework with multi-channel C2 capabilities including HTTP, Nostr, IPFS, and Ethereum RPC. The malicious packages were published via GitHub Actions trusted publishing from a compromised source commit on the 'next' branch.
Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk Kratos is a mature Phishing-as-a-Service operation impersonating Microsoft 365 login pages to steal credentials across US and European organizations. The kit uses legitimate platforms (SharePoint, Canva, Tilda) as intermediary redirect pages, Cloudflare Turnstile to block automated analysis, and PHP endpoints for credential exfiltration. Researchers identified three generations (V0, V1, V2) with distinct asset fingerprints and exfiltration code, and uncovered the operator panel with automated deployment, Telegram-based data delivery, and geographic restriction capabilities.
Malicious GitHub Campaign: Fake “Arctic Wolf” and 290+ Brand-Impersonation Repositories Deliver BoryptGrab-Lineage Infostealer An unattributed, financially motivated threat actor has operated at least 292 brand-impersonation GitHub repositories since 26 June 2026 to distribute a BoryptGrab-lineage Windows infostealer. The delivery chain abuses GitHub trust by routing users through *.github.io redirectors to actor-controlled download pages that serve ZIP archives containing a legitimate signed WinGUP updater (gup.exe) that side-loads a trojanized libcurl.dll, which reflectively executes an 11-module in-memory stealer. The stealer bypasses Chrome App-Bound Encryption v20 via in-process reflective DLL injection into the browser process, scans Steam process memory for live session tokens, harvests credentials from 19+ browsers and 41 cryptocurrency wallet paths, and exfiltrates all data via raw-socket chunked POST to a hardcoded C2 at 193.143.1.131 in Russia.
Home Field Advantage: How Attackers Reshape Victim Environments A threat actor exploited an SQL injection vulnerability in an IIS web application to gain initial access to a Windows endpoint running MSSQL. After access, the attacker performed extensive environment modifications including reconnaissance via tasklist, exfiltration to an OAST domain, creation of a new local administrator account, enabling Terminal Services, disabling Windows Defender, installing BadIIS modules, deploying an XMRig cryptocurrency miner with persistence, and adding CnCrypt Protect for defense evasion. The breadth of modifications on a single endpoint was notable compared to similar incidents.
Beware of Phishing Emails Disguised as Project Proposals A phishing campaign distributing SnakeKeylogger is using emails disguised as project proposals to deliver JavaScript malware inside compressed attachments. Upon execution, the JS malware invokes PowerShell to decrypt and load an encrypted SnakeKeylogger payload in memory without writing to disk. The infostealer then harvests browser data, system information, and keylogging data, exfiltrating it via SMTP or Telegram to attacker-controlled infrastructure.
Mitigating New Vulnerabilities with owLSM The article demonstrates how owLSM, an open-source Linux security agent with a stateful Sigma rules engine, can be used to detect and prevent exploitation of the CrackArmor vulnerability group. CrackArmor consists of nine vulnerabilities in Linux AppArmor that allow unprivileged local attackers to manipulate AppArmor profiles via SUID binaries, enabling local privilege escalation, denial of service, and access control bypass. The authors show a workflow of running owLSM in observability mode, triggering the exploit, identifying the relevant event, and writing a Sigma-style prevention rule that blocks non-root writes via SUID binaries to AppArmor control files.
Seven Steps to Ransomware: CitrixBleed 2 Weaponized by Initial Access Brokers An Initial Access Broker is exploiting CVE-2025-5777 (CitrixBleed 2), a pre-authentication memory overread in Citrix NetScaler ADC/Gateway, to steal session tokens and bypass MFA. The stolen sessions are used to access Citrix published desktops, followed by a consistent privilege escalation via a registry symbolic-link LPE tool that abuses the Windows AppMgmt service and Group Policy refresh to gain SYSTEM. The operator then creates backdoor admin accounts, installs rogue ScreenConnect/Zoho Assist RMM clients, moves laterally with PsExec and Impacket, and ultimately deploys DragonForce ransomware. The full kill chain from initial access to encryption was observed completing in under one hour in at least one case.
Hiding in the Chain: Multi-Stage LNK Attack Leveraging TON Blockchain to Deliver Node.JS Backdoor A multi-stage attack campaign uses malicious LNK files delivered via booking-themed phishing emails to deploy a Node.js-based backdoor. The LNK files use bigint arithmetic obfuscation to reconstruct C2 URLs, download a PowerShell payload that deploys a legitimate node.exe binary, and execute an AES-128-CBC encrypted JavaScript backdoor. The backdoor retrieves its C2 address from the TON blockchain using the EtherHiding technique, employs a custom bytecode VM interpreter for defense evasion, and supports downloading and executing additional payloads including PE files, PowerShell, and JavaScript.
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware GigaWiper is a sophisticated Golang-based backdoor discovered by Microsoft Threat Intelligence in October 2025 that amalgamates at least three previously separate malware families — a standalone disk wiper, Crucio ransomware, and FlockWiper — into a single modular implant with 20 commands. It uses RabbitMQ and Redis for C2 communication, establishes persistence via scheduled tasks, and offers capabilities including disk wiping, fake ransomware (with unrecoverable encryption), BSOD induction, screen recording, keylogging, registry management, event log clearing, and VNC-like remote control. The malware masquerades as legitimate Windows components (OneDrive Update, CloudExperienceHost) and uses AES-encrypted configurations with hard-coded credentials.
US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data ANY.RUN's Malware Trends Tracker data shows that phishing-as-a-service kits now dominate the US threat landscape, with five of the top ten threats being AiTM or device-code phishing platforms that defeat MFA by stealing session cookies or OAuth tokens. Commodity RATs and info stealers remain in constant high-volume circulation, while legacy threats like Emotet and WannaCry persist on unpatched systems. Several top-ranked threats (Cobalt Strike, Qbot, Emotet, DonutLoader, Smoke Loader) function as ransomware precursors, meaning their detection should trigger urgent escalation rather than routine handling.
Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories Operation Muck and Load is a supply chain attack campaign centered on a malicious Go module that impersonates a DNS scanner tool to deliver a multi-stage Windows malware loader. The campaign leverages 222 GitHub lure repositories across 190 accounts with automated commit-farming workflows to create false credibility, and uses public dead-drop resolvers across multiple platforms for resilient payload-location resolution. The final payload chain delivers AsyncRAT, Quasar, Remcos, Vidar infostealer, and cryptominers through password-protected 7z archives extracted into masqueraded Microsoft-themed directories.
Files Locked Behind a White Padlock: A Warning from WhiteLock Ransomware WhiteLock is a Windows ransomware that encrypts user files using AES-CBC symmetric encryption with RSA-2048 asymmetric key protection, appending the .Fbin extension to encrypted files. It identifies infected devices via SHA-256 hashed MAC addresses, communicates with external servers for key exchange, and deliberately terminates AnyDesk and TeamViewer services to impede remote incident response. The ransomware has been observed in campaigns where information theft malware is used for initial access prior to ransomware deployment.
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps A coordinated supply-chain campaign published 17 typosquatted npm and PyPI packages mimicking PaySafe, Skrill, and Neteller payment SDKs. The packages implement a fake SDK facade that harvests environment variables containing credentials and tokens, then exfiltrates them over HTTPS to an ngrok-based C2 server. The malware includes sandbox evasion logic and multi-layer C2 domain obfuscation to hinder analysis.
One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation UNK_MassTraction, a suspected China-aligned threat cluster, has been exploiting chained n-day vulnerabilities in Roundcube mailservers (CVE-2024-42009 XSS followed by CVE-2025-49113 PHP deserialization) targeting physics and engineering departments at US and Canadian universities since May 2026. The campaign deploys a custom JavaScript credential stealer (IceCube), a webshell (SquareShell), and the VShell backdoor via an in-memory ELF loader, treating mailservers as edge devices for network pivot. The tooling demonstrates mature operational security including anti-forensics, fallback mechanisms, and process spoofing.
Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation A financially motivated campaign active in April 2026 delivers Vidar stealer and XMRig cryptocurrency miner to victims worldwide via malvertising for fake software cracks. The campaign uses the Factory-v3 Go loader framework with per-build unique binaries, fabricated Authenticode certificates impersonating legitimate brands, file-size inflation up to 491 MB to evade sandbox analysis, and an in-memory AMSI bypass. Vidar exfiltrates browser credentials, cookies, and crypto wallets to C2 servers, while XMRig mines Monero using the pool.supportxmr.com mining pool. The operator receives Telegram notifications for each new infection.
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit REF6045 is an operator-assisted Mexican banking fraud operation that uses ClickFix fake CAPTCHA pages to deliver the SCMBANKER PowerShell toolkit. Once installed, the toolkit monitors for banking sessions, captures screenshots, deploys vishing overlays, hijacks clipboard data to swap CLABE and card numbers, redirects browsers to phishing pages, and silently installs Remote Utilities as a persistent RAT. The operation's infrastructure suffered significant OPSEC failures including open directories, a leaked web-root archive, and an unauthenticated configuration editor.
Banana RAT Evolves: Comparing Two Recent Branches Through ANY.RUN An exposed public index on 198.245.53.26 revealed two evolutionary branches of Banana RAT, a Brazilian banking-oriented RAT. The older branch (May 2026) used static ETW-themed installation paths and a pseudo-Microsoft C2 domain (c.windowns-cdn.com), while the newer branch (June 2026) shifted to randomized install identifiers, VBS-assisted persistence via hidden SYSTEM scheduled tasks, and WebSocket C2 over host-specific testewin.com subdomains derived from the victim's MachineGuid. Exposed backend scripts (servidorcompletopool.py, ofuscador.py) indicate an automated polymorphic payload generation platform. A shared fallback IP (149.56.12.51) anchors both branches to the same operator.
UAT-7810 continues building ORB networks using new malware UAT-7810, a China-nexus APT actor, continues to build Operational Relay Box (ORB) networks by exploiting n-day vulnerabilities in Ruckus and ASUS AiCloud routers. Talos identified four new malware families — LONGLEASH (an upgraded multi-protocol proxy backdoor), DOGLEASH (a passive C-based Linux backdoor), JARLEASH (a Java-based administrative backdoor), and LEASHTEST (a MIPS test binary) — deployed across MIPS, ARM, and x64 platforms. The actor uses at least four new servers to host payloads and deploy DOGLEASH via shell scripts that modify iptables rules on compromised devices.
From Phishing to Persistence: A CrySome RAT Infection Chain Analysis A structured, multi-stage infection chain delivers the CrySome RAT via a logistics-themed spear-phishing lure. Initial access is achieved through a fake rate confirmation portal that drops a batch file, which chains UAC bypass (ICMLuaUtil COM interface), in-memory AMSI patching, and the open-source WinDefCtl utility to weaken Microsoft Defender before deploying the persistent RAT payload. CrySome RAT provides the operator with remote command execution, credential theft from Chromium browsers, HVNC, keylogging, and persistence via a scheduled task executing every 5 minutes.
Cavern Manticore: Exposing Iran-Linked Modular C2 Framework Cavern Manticore, an Iran-MOIS-linked APT group, deploys a modular .NET C2 framework targeting Israeli government and IT organizations. The framework uses three compilation formats (Mixed-Mode C++/CLI, NativeAOT, .NET Framework) as an anti-analysis layer, with DLL sideloading via WinDirStat.exe for initial execution. Post-exploitation modules provide DPAPI decryption, LDAP brute-forcing, SQL browsing, network reconnaissance, and SOCKS5 tunneling, with C2 traffic XOR-encrypted over HTTPS/WebSocket channels.
6th July – Threat Intelligence Report This weekly threat intelligence bulletin covers multiple active ransomware campaigns, four critical vulnerabilities under active exploitation, and emerging AI-driven threats. Notable items include actively exploited RCE flaws in Oracle E-Business Suite and Progress Kemp LoadMaster, a Citrix NetScaler memory disclosure flaw exploited within 24 hours of disclosure, a North Korean supply-chain campaign (PolinRider) deploying 108 malicious packages, and a proof-of-concept browser-native ransomware generated by an LLM abusing Chrome's File System Access API.
Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden DragonForce ransomware operators deployed a novel Go-based backdoor called Backdoor.Turn that abuses Microsoft Teams TURN relay infrastructure to hide C2 traffic as legitimate Teams communications. The attack chain involves SQL/MSSQL server exploitation for initial access, DLL sideloading via VirtualBox/DbgView executables, multiple BYOVD techniques for defense evasion including a novel exploit of a Huawei driver, and ultimately DragonForce ransomware deployment. The group demonstrated exceptional sophistication with custom tooling and stealth techniques that evade standard network monitoring.
The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security BYOVD (Bring Your Own Vulnerable Driver) attacks have become a standard component of ransomware operations, allowing attackers to exploit signed kernel drivers for kernel-level access and subsequently disable AV/EDR products. The technique involves dropping a legitimate but vulnerable signed driver, loading it via a Windows service, and sending crafted IOCTL commands to terminate, blind, or strip privileges from security software. Microsoft's kernel hardening features and Vulnerable Driver Blocklist provide insufficient protection, as data-only kernel attacks bypass hardening and the blocklist has significant update lag. Behavioral monitoring of anomalous driver IOCTL interactions is the most effective defensive approach, as it is driver-agnostic and does not depend on prior driver identification.
Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker Backdoor.Mistic is a new stealthy backdoor deployed in cybercrime intrusions since April 2026, using DLL sideloading via legitimate MpExtMs.exe and masquerading as EndpointDlp.dll. It executes payloads in memory with a self-deleting kill switch, enabling long-term covert access. Mistic is likely linked to Woodgnat (aka KongTuke), an initial access broker whose ModeloRAT toolkit has been used in attacks delivering Qilin ransomware, connecting this backdoor to the broader ransomware ecosystem.
An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails LevelBlue GSOC has identified accelerating ValleyRAT campaigns delivered through fake installers and malicious emails targeting Chinese and Japanese-speaking users. The email-based attack chain uses DLL sideloading via a legitimate VLC executable to load a malicious DLL that downloads an RC4-encrypted, Donut-generated ValleyRAT payload, which is then injected into a suspended rundll32.exe process for fileless execution. The malware incorporates extensive anti-analysis checks (memory size, sleep timing, CPU count, VHD boot detection) and establishes persistence via registry Run keys.
AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign An active multi-stage phishing campaign distributes AsyncRAT and Remcos RATs through weaponized Excel attachments targeting sales, procurement, and vendor management staff globally. The infection chain uses VBA macros to retrieve HTA payloads via URL shorteners and Cloudflare Workers, with final payloads hidden via PNG steganography and loaded filelessly into memory via .NET assembly loading. The campaign demonstrates high-volume, automated payload generation with consistent obfuscation patterns including Base64 encoding, character substitution, and string reversal.
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency UNK_DeadDrop is a likely North Korean threat actor conducting broad phishing campaigns targeting software developers with fake job offers and code review requests. The campaign delivers malicious GitHub/GitLab repositories that abuse VS Code and Cursor IDE task automation to silently execute cross-platform malware. Linux and macOS systems receive the Overlord Go RAT with custom credential and wallet theft modules, while Windows runs a fileless Node.js/Python pipeline inside the editor's Electron process. The malware exfiltrates cryptocurrency wallets, browser credentials, and OS keychain data to a hardcoded C&C server at 23.137.105.75:5173.
Threat Actors Weaponize AI Hype to Deliver AsyncRAT Threat actors are weaponizing AI-themed lure documents to deliver a complex multi-stage infection chain culminating in AsyncRAT and a custom .NET RAT called clay_Client. The attack uses hidden LNK files inside compressed archives to initiate a chain of PowerShell scripts that extract, decrypt, and execute payloads from disguised PDF containers using AES-CBC, XOR, and GZip decompression. AutoHotkey scripts perform process hollowing into legitimate .NET Framework executables, while defense evasion includes adding Microsoft Defender exclusions and restoring disabled VBS execution. The final RAT provides full remote control with screen capture, input simulation, fileless assembly loading, and process injection capabilities.
Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula FortiGuard Labs identified an ongoing Ousaban banking Trojan campaign targeting users in Spain and Portugal, delivered via phishing PDFs that redirect victims to geofenced malicious webpages. The attack chain involves a VBS script extracting a ZIP payload from a steganographic image, with the final Ousaban EXE establishing persistence via registry Run keys and communicating with C2 servers resolved through daily-changing DDNS hostnames. The malware targets over 25 Spanish and Portuguese financial institutions and employs a custom encryption algorithm shared with the Casbaneiro family to evade detection.
- 8 minWeekly Recap — 2026-06-29 -> 2026-07-06
Token Theft and AI Poisoning Redefine the Perimeter Attackers are shifting from breaking passwords to stealing active login sessions, bypassing multi-factor authentication entirely. This week, ARToken and ConsentFix exploited Microsoft 365 OAuth flows to hijack accounts, while Anubis ransomware used the ongoing CitrixBleed 2 vulnerability to steal session tokens from network gateways. Even a standard user can become a Global Administrator in minutes if identity settings are loose, as demonstrated by a recent M365 privilege escalation analysis. Simultaneously, artificial intelligence systems have evolved from helper tools to critical vulnerabilities, serving as both the weapon and the target. Threat actors are using AI to generate malware like InfernoGrabber v9.0 and BusySnake Stealer, while also poisoning AI agent ecosystems with malicious skills like OpenClaw and tricking AI models into executing financial fraud via indirect prompt injection. The AI arms race has accelerated breakout times to under 30 minutes, with state-sponsored groups like GTG-1002 now orchestrating entire espionage campaigns via AI. Defenders must immediately audit identity and session controls, treating session tokens as highly sensitive credentials. Security teams should also implement guardrails for AI agents, verifying external URLs and restricting autonomous financial or code execution actions.
Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem A new wave of the Mini Shai-Hulud/Miasma/Hades supply chain attack campaign has compromised 23 npm packages across the LeoPlatform and RStreams ecosystems, plus the Verana Blockchain Go module. The attack uses binding.gyp install-time execution (Phantom Gyp pattern) to trigger multi-stage obfuscated JavaScript loaders that decrypt AES-GCM payloads, stage execution through Bun to evade Node.js security hooks, and steal developer/CI/CD credentials including npm, GitHub, cloud, and AI-agent tokens. The campaign also poisons GitHub Actions workflows and plants persistence hooks in AI coding assistant configurations, creating delayed execution surfaces that survive package remediation.
Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects Kaspersky's 2025 compromise assessment report reveals that organizations consistently fail to detect long-dwelling threats, with 30.8% of incidents persisting over 3 months and 52% of high-severity compromises going undetected for 90+ days. Key findings include widespread abuse of LoLBins and remote management tools in every incident-bearing engagement, 40% of web shells surviving in backups to be restored post-remediation, and a strong correlation between in-house forensics/reverse-engineering capability and reduced incident severity. Multiple case studies document dormant crypto-mining on domain controllers (4 years), in-memory LionTail implants on critical servers, PurpleFox rootkit infections evading EDR with disabled memory scanning, and ClipBanker persistence via registry Run keys with Defender exclusions.
From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks Arctic Wolf Labs documents Anubis ransomware affiliate tradecraft observed across multiple 2026 intrusions, featuring CitrixBleed 2 (CVE-2025-5777) exploitation and valid VPN credential abuse for initial access. Affiliates consistently deploy legitimate RMM tools for persistence, use Mimikatz and ntds.dit extraction for credential access, establish alternate egress via cloudflared and SSH SOCKS tunnels, and employ exfiltration tools like S3 Browser and rclone before deploying encryptors on Windows and Linux systems. The attack chain relies on commodity tools and living-off-the-land techniques that resemble legitimate administration in isolation but form a distinctive kill chain when correlated.
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos identified ARToken, a phishing-as-a-service platform linked to EvilTokens, that abuses Microsoft's OAuth 2.0 Device Authorization Grant to bypass MFA and capture victim tokens. The platform provides affiliates with a comprehensive post-compromise toolkit including PRT-based persistence surviving password resets, BEC email operations, inbox rule manipulation, and SharePoint exfiltration. ARToken deploys a sophisticated seven-layer client-side anti-analysis system and abuses legitimate sharepoint.com URLs from attacker-controlled Microsoft 365 workspaces to evade security scanners.
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them StealC is a C++ malware-as-a-service infostealer that harvests credentials, cookies, and session tokens from browsers, email clients, crypto wallets, and gaming platforms, using APC injection to bypass Chromium App-Bound Encryption. Amadey is a modular MaaS loader that delivers StealC and other payloads through a rich backdoor command set including process injection, SOCKS proxying, RDP enablement, and hidden admin account creation. Microsoft DCU disrupted over 200 C2 domains and IPs associated with both threats in a coordinated action with Europol on June 24, 2026.
Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager Mandiant identified a threat actor exploiting zero-day CVE-2026-20245 in Cisco Catalyst SD-WAN Manager to escalate privileges from a compromised administrative account to root-level access via a malicious CSV file upload. The intrusion began with rogue peering connections, potentially leveraging CVE-2026-20127 or CVE-2026-20182, followed by SSH access using the vmanage-admin account, password manipulation of the admin account, and ultimately root access through a crafted evil_tenant.csv payload that modified /etc/passwd and /etc/shadow. The threat actor employed extensive anti-forensic techniques including file deletion, configuration restoration, and validation script execution to purge indicators.