August 2026 saw coordinated attacks targeting US and EU businesses through session hijacking, RMM abuse, and insider threats. Threat actors leveraged legitimate tools and authentication flows to bypass MFA, steal active sessions, and establish persistent remote access. Campaigns like Mirage2FA and 3DBlast targeted Microsoft 365 and Google login flows, while SnakeBiteAgent delivered full remote access capabilities via business-themed archives.
insider-threat
2 posts
Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs North Korean operatives, tracked under Lazarus/Famous Chollima, obtain remote IT and developer positions at Western companies and government agencies by combining stolen or synthetic identities, AI-generated documents, and layered network obfuscation (commercial VPNs and facilitator-operated 'laptop farms'). Once hired, operatives function as insiders with legitimate credentials and device access, and separately, malware samples such as a Python-based backdoor (newbeaver.py) have been observed being delivered through candidate technical assessments, connecting to dedicated C2 infrastructure that overlaps with known DPRK malware campaigns (BeaverTail/InvisibleFerret family). Defense requires integrating SOC-driven sandbox triage of candidate files, network telemetry analysis during interviews, and forensic document review into the hiring pipeline rather than relying solely on traditional background checks.