Cybersecurity Threat Research ‘Weekly’ Recap. The report highlights frequent ransomware and identity-focused intrusion chains, including PAYLOAD’s abuse of Active Directory GPO/SYSVOL, Qilin’s continued cross-sector activity in ANZ, and multiple OAuth/session and phishing techniques such as TeamFiltration, CSuite, and token theft even in MFA-protected environments. It also covers software supply-chain and platform abuse (MemTensor, OpenCode, CI/CD hardening, and AWS IAM key protection), plus notable loader/infostealer malware (ShinyHunters/UNC6240, Kothamine, AvisLoader, Vidar, MacSync, SilentXMRMiner) and exploitation work like pfSense stored XSS to root RCE and MagicINFO leading to miner deployment.
#PAYLOAD #ActiveDirectory #Qilin #TeamFiltration #CSuite #OAuth #AppX #WWAHost #MemTensor #OpenCode #ShinyHunters #UNC6240 #Kothamine #AvisLoader #Vidar #MacSync #SilentXMRMiner #pfSense #MagicINFO #VolzTyphoon #SaltTyphoon #UNC6293 #UNC7005 #UNC5976
#PAYLOAD #ActiveDirectory #Qilin #TeamFiltration #CSuite #OAuth #AppX #WWAHost #MemTensor #OpenCode #ShinyHunters #UNC6240 #Kothamine #AvisLoader #Vidar #MacSync #SilentXMRMiner #pfSense #MagicINFO #VolzTyphoon #SaltTyphoon #UNC6293 #UNC7005 #UNC5976
Ransomware, Extortion & Initial Access
- PAYLOAD ransomware abused Active Directory GPO/SYSVOL to disable defenses, stage data, and extort a Middle East manufacturer; group policy weaponization recap.
- Qilin remained the most active cross-sector ransomware actor in ANZ, alongside broader identity-driven intrusion trends; ANZ threat landscape.
- Ransomware defense is most effective pre-encryption, using threat intel to spot exposed creds and attacker infrastructure earlier; stop ransomware with threat intelligence.
Phishing, Account Takeover & Credential Theft
- TeamFiltration hit 5,700+ Microsoft 365 accounts via service-account password spraying and session hijacking in Latin America; Andes campaign details.
- CSuite used device-code phishing, session theft, and legitimate remote tools to compromise US and EU orgs; CSuite attack analysis.
- OAuth token theft abused a sideloaded AppX and WWAHost to capture Microsoft login tokens even with MFA; Microsoft front-door abuse.
- Firefox extension takeover impersonated a PDF tool to hijack Google accounts and steal OAuth cookies; Google account hijack via extension.
- Ledger phishing used Google Ads and rapid Vercel redirects to steal wallet recovery phrases; Ledger lure campaign.
- ACI tax phishing abused the Automobile Club d’Italia brand to collect payment and card data; ACI phishing alert.
- MintsLoader spread through compromised PEC mailboxes with fake payment reminders and malware-laden ZIPs; PEC lure campaign.
- Google Ads also delivered fake security-locker tech-support scams with hidden C2 and anti-analysis tricks; fake locker delivery.
Supply Chain, Developer & CI/CD Threats
- MemTensor compromise pushed malicious npm/PyPI releases to steal developer secrets, tokens, and cloud creds; package supply-chain breach.
- OpenCode RCE turned a content-type confusion bug into remote code execution via a crafted npm tarball; OpenCode vulnerability report.
- CI/CD hardening guidance stressed secret scanning, isolated runners, provenance, and stronger identities across the SDLC; pipeline defense recap.
- AWS compromised key quarantine now auto-isolates exposed IAM keys, tied to GitHub secret scanning and push protection; AWS IAM protection.
Loaders, RATs, Stealers & Malware Tradecraft
- ShinyHunters/UNC6240 mass-exploited Oracle PeopleSoft CVE-2026-35273 with web shells, SIDEEYE, Neo-ReGeorg, and MeshAgent; PeopleSoft exploitation.
- Kothamine Agent used Tailscale/tailcat for encrypted control while stealing browser data and media on some builds; Kothamine malware recap.
- AvisLoader used ClickFix, Tox P2P C2, persistence artifacts, and anti-removal tooling; AvisLoader analysis.
- Vidar advanced string obfuscation with per-build virtual machines and custom stream ciphers; Vidar obfuscation update.
- MacSync evolved into a macOS infostealer with fake apps, malicious DMGs, iCloud abuse, and layered exfiltration; MacSync deep dive.
- Python MaaS stealer builder packaged browser, Discord, Wi-Fi, and webhook-based exfiltration for Windows theft; TokenGrabberBuilder report.
- Larva-25012 resumed proxyware distribution using DPLoader, PowerShell, scheduled tasks, and sideloading; proxyware campaign.
- SilentXMRMiner was compiled on-host after MagicINFO exploitation and Defender tampering for Monero mining; endpoint miner intrusion.
Exploitation, Malware Delivery & Vulnerability Research
- pfSense/pfBlockerNG flaw enabled stored XSS from DNS poisoning and could escalate to root RCE; CVE-2026-78902 write-up.
- Samsung MagicINFO exploitation served as the initial access point for follow-on miner deployment; MagicINFO intrusion.
- Third-party ICS integrator guidance from FBI/CISA emphasized least privilege, remote-access monitoring, and secure contracting; ICS integrator advice.
Sector, Region & Nation-State Activity
- ANZ threat landscape highlighted credential stuffing, stolen creds, and IAB sales across finance, manufacturing, and mining; Australia/New Zealand recap.
- South Asian manufacturing faces sustained ransomware and nation-state pressure across IT/OT and vendor access paths; India & SAARC manufacturing assessment.
- Russian threat groups UNC6293, UNC7005, and UNC5976 were linked to malicious infrastructure and targeting of persons of interest; campaign infrastructure report.
- Volt Typhoon and Salt Typhoon continued state-aligned pre-positioning activity in the ANZ region; state actor activity overview.