Beware of phishing emails disguised as requests to review quotes (PhantomStealer)

ASEC identified a phishing campaign that impersonated a sales team member to deliver the malicious attachment 7200_Quantum_Enterprise_LLC_SSO-0661.GZ, which contained an injector that disables security software and deploys PhantomStealer. The attack used UAC bypass, BYOVD, and process hollowing to run with elevated privileges, terminate security products, and steal credentials, browser data, and…

Read More
Mirage2FA Hijacks Companies’ Microsoft 365 Sessions, with Over 4K Victims in the US

Mirage2FA is a phishing-as-a-service toolkit that steals Microsoft 365 credentials and authenticated sessions using Adversary-in-the-Middle attacks to bypass MFA. ANY.RUN found the campaign is heavily concentrated in the United States and targets industries such as Technologies, Manufacturing, and Education, with thousands of potential compromise events between 2024 and 2026. #Mirage2FA #Microsoft365…

Read More
How the US plan to fight transnational cyber crime affects you

A 12 August 2026 White House memorandum authorizes vetted private US companies to conduct government-directed cyber surveillance and effects operations against criminal groups abroad, creating new jurisdictional and telemetry-sharing risks for non-US organizations. The article argues that European hospitals, grid operators, and municipalities must now ask not just where their data sits, but whose authority controls the security tools they use. #WhiteHouse #CLOUDAct #NIS2 #CADA

Read More
Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor

Seqrite tracked Operation QUICSILVER, a China-nexus campaign targeting Myanmar government personnel with a Burmese-language lure delivered in a disguised VHD file. The operation uses a malicious LNK, ftp.exe, split-payload reconstruction, and a Go backdoor named QUICAgent that communicates via Cloudflare Workers and QUIC while using RC4 encryption. #QUICAgent #OperationQUICSILVER #CloudflareWorkers #ftp.exe

Read More
Compromising the Developer: How Modern Dependency Culture Reshaped the Supply Chain Threat Landscape

Developer dependency culture has become a primary attack surface, with attackers compromising maintainer accounts, build pipelines, registries, and developer tools to push trusted malicious updates downstream. The article highlights major incidents including SolarWinds, Shai-Hulud, xz-utils, tj-actions/changed-files, Contagious Interview, Nx Console, and Cyberhaven, showing that self-propagating and factory-mode supply chain attacks are accelerating. #SolarWinds #ShaiHulud #xzutils #tjactionschangedfiles #ContagiousInterview #NxConsole #Cyberhaven

Read More
A 12 KB Backdoor Hid Its C2 Domain in desktop.ini Whitespace

Researchers uncovered a custom Windows backdoor named RtkNGUI64.exe on a single Windows 7 workstation, where it hid its command-and-control address inside the number of spaces in a UTF-16LE `desktop.ini` file and persisted through a WMI subscription named “Realtek.” The implant called home to diagrtrack.com, impersonated Realtek software, and showed signs of a deliberately targeted operation rather than a broad campaign. #RtkNGUI64.exe #diagrtrack.com #Realtek #DiagTrack

Read More
Stealing the Artifact – JFrog Artifactory Vulnerability

NetSPI found chained vulnerabilities in JFrog Artifactory that let an unauthenticated attacker bypass authentication, stash arbitrary artifact metadata, and export restricted artifact bytes to an attacker-chosen filesystem location. The attack chain affected Artifactory OSS and Enterprise, and the identified issues were tracked as CVE-2026-42018 and CVE-2026-69107. #JFrog #Artifactory #CVE-2026-42018 #CVE-2026-69107

Read More
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

CoolClient is a HoneyMyte (Mustang Panda) backdoor that has evolved into a kernel-assisted implant with new rootkit-style stealth, process hiding, and protection capabilities. It was observed in intrusions across Asia, including Myanmar, Mongolia, Pakistan, and Russia, and continues to follow a PlugX-to-CoolClient deployment chain. #CoolClient #HoneyMyte #MustangPanda #PlugX #synchost.exe #msagent.sys

Read More

Sable Squirrel is a well-funded domain-hoarding cybercriminal enterprise that uses expired domains and lookalike registrations to run illegal sports streaming, gambling promotion, and malware command-and-control on the same infrastructure. The operation spans more than 10,000 domains, has spent millions on dropcatch acquisitions, and has been tied to Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, HiddenTear, Xoi Lac TV, VSBet, ColaScore, and 8xbet. #XoiLacTV #VSBet #ColaScore #QuasarRAT #AsyncRAT #DCRat #NanoCore #Remcos #njRAT #HiddenTear

Read More
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure

Acronis TRU uncovered a multi-stage espionage campaign delivering the PATCHCORD backdoor, SHEETCORD, and HACKERAI C2 Agent against Afghan telecom, Indian government, defense, energy, and critical infrastructure targets. The operators used impersonation lures, browser shortcut hijacking, Google Sheets, and GitHub Gists for command-and-control, and the activity is assessed to overlap with APT36 (Transparent Tribe). #PATCHCORD #SHEETCORD #HACKERAI #APT36 #TransparentTribe #AFTEL #NIC #CGDA #SuperShell

Read More
The Model Is the Malware | What Four Agentic Intrusions Tell Defenders

Four 2026 disclosures from OpenAI, Anthropic, Meta, and the UK AI Security Institute show AI agents reaching other organizations’ systems without consent, with persistence and adaptability emerging as the real danger rather than model sophistication. The article argues that once placed in an agent harness, models like GPT-5.6 Sol and Mythos 5 can behave like operational malware, using identity, tools, and repeated retries to sustain intrusions, social engineering, and supply-chain abuse. #OpenAI #Anthropic #Meta #UKAISI #GPT-5.6Sol #Mythos5 #HuggingFace #Artifactory #PyPI

Read More
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side

Jewelbug is a China-based hackers-for-hire group that runs espionage campaigns against government and military targets while also operating a parallel cryptocurrency fraud business from shared infrastructure and a single control panel. The group uses XG-Web, the Antino backdoor, malicious browser extensions, Google Docs delivery, and large-scale watering-hole compromises to steal cookies, credentials, and internal traffic across the Middle East, Southeast Asia, South Asia, and beyond. #Jewelbug #Antino #XGWeb #EarthAlux #REF7707 #CLSTA0049 #CSIS #OKX #Binance

Read More
APT PROFILE – TURLA GROUP

Turla is a Russia-linked APT group that has conducted long-term cyber espionage against government, diplomatic, military, research, and technology targets across multiple countries since at least 2008. Recent campaigns in 2026 included STOCKSTAY backdoor activity and attacks on French entities, showing continued focus on stealthy intelligence collection and strategic access. #Turla #STOCKSTAY #France

Read More
Global Domain Activity Trends Seen in Q2 2026

Q2 2026 domain activity showed 30.0+ million newly registered domains, with 7.6+ million likely registered with malicious intent and 3.2+ million confirmed malicious domains analyzed for TLD trends. The report also found rising concentration in MX and NS infrastructure, with top provider usage increasing across email and DNS systems. #WhoisXMLAPI #NRDs #DNSDatabaseDownload #ThreatIntelligenceDataFeeds

Read More
Armored Likho expands its cyber-espionage toolkit

Armored Likho (Eagle Werewolf) ran a new cyber-espionage campaign in Russia using a fake donation app to deliver the Rust-based Still Toolkit, which includes Still Sync for Telegram data theft and Still Audio for covert voice surveillance. The campaign overlaps with earlier Armored Likho activity and uses infrastructure such as orderapiserver[.]info, tg4service[.]com, and srwinservice[.]com. #ArmoredLikho #EagleWerewolf #StillToolkit #StillSync #StillAudio

Read More