Darktrace says the first half of 2026 was defined by attackers abusing trusted identities, SaaS, cloud entitlements, AI systems, and supply-chain relationships rather than relying on traditional exploitation, with one React2Shell honeypot compromised in under two hours. Campaigns involving StealC, AMOS, Phexia, Axios, Trivy, Hola VPN, BeyondTrust, and JadePuffer showed how quickly trust-based tradecraft, AI-generated malware, and supply-chain abuse are reshaping intrusion paths. #React2Shell #Darktrace #StealC #AMOS #Phexia #Axios #Trivy #HolaVPN #BeyondTrust #JadePuffer
Keypoints
- Attackers shifted from traditional malware and vulnerability-centric attacks toward trusted identities, SaaS platforms, cloud entitlements, automation frameworks, and non-human identities.
- A Darktrace-deployed React2Shell honeypot was compromised in less than two hours, underscoring the speed of exploitation in H1 2026.
- Email and phishing remained highly effective, with 67% of phishing emails passing DMARC and 39% using novel social engineering techniques.
- Infostealer activity was a major theme, especially StealC and AMOS campaigns, which often provided credentials for later intrusions.
- Supply-chain trust was weaponized through compromises involving Axios, Trivy, Hola VPN, and legitimate blockchain infrastructure.
- Cloud and SaaS environments increasingly served as attacker operating terrain, with compromised accounts enabling activity across email, SaaS, and network layers.
- AI became both an accelerator and an attack surface, including AI-generated malware, compromised AI proxies, and sensitive data being entered into LLM prompts.
MITRE Techniques
- [T1566 ] Phishing â Used to deliver trusted-looking malicious messages and social engineering, including high-volume text and novel techniques (âphishing emails passed DMARCâ and ânovel social engineering techniquesâ).
- [T1204 ] User Execution â ClickFix tricks users into running malicious code themselves (âtricks users into running malicious code themselvesâ).
- [T1056.001 ] Input Capture: Keylogging â Infostealers harvested credentials and other identity material for later intrusion paths (âCredentials harvested by infostealers often become the initial access vectorâ).
- [T1078 ] Valid Accounts â Attackers inherited trust by abusing compromised SaaS accounts, delegated access, and legitimate administration tools (âthey inherit them through compromised identities, delegated access, and legitimate administration toolsâ).
- [T1195 ] Supply Chain Compromise â Used against Axios, Trivy, and Hola VPN delivery paths to push malicious code or payloads (âtrusted CI/CD infrastructureâ and âissue within Holaâs own delivery pipelineâ).
- [T1105 ] Ingress Tool Transfer â Malicious payloads were downloaded through trusted services and delivery pipelines (âdevices downloaded malicious payloadsâ).
- [T1219 ] Remote Access Software â RMM and remote administration tooling were repeatedly abused for control and persistence (âremote management toolingâ and âRMM abuseâ).
- [T1027 ] Obfuscated Files or Information â The article notes stealthy intrusions and use of malicious code packages, including AI-generated malware and trojanized installers (âAI-generated malwareâ and âtrojanized installersâ).
- [T1490 ] Inhibit System Recovery â Ransomware operations were part of the observed activity in multiple monthly clusters (âransomwareâ).
- [T1059.001 ] Command and Scripting Interpreter: PowerShell â PowerShell was part of June activity tied to post-compromise operations (âPowerShellâ).
- [T1486 ] Data Encrypted for Impact â Ransomware activity linked to automation and LLM-driven attacks points to encryption for impact (âfully automated ransomware attackâ).
- [T1071.001 ] Application Layer Protocol: Web Protocols â WebSocket C2 was explicitly mentioned in January activity (âWebSocket C2â).
- [T1095 ] Non-Application Layer Protocol â C2 and infrastructure abuse included nonstandard channels and botnet activity (âWebSocket C2â and âbotnet activityâ).
- [T1110 ] Brute Force â Account creation abuse, credential abuse, and authentication-focused attacks indicate repeated attempts to gain access (âaccount creation abuseâ and âVPN credential abuseâ).
- [T1021.001 ] Remote Services: Remote Desktop Protocol â RDP abuse was specifically noted in June (âRDP abuseâ).
- [T1041 ] Exfiltration Over C2 Channel â Data theft and exfiltration were part of the observed attacker behavior (âdata exfiltrationâ and âcloud data theftâ).
- [T1068 ] Exploitation for Privilege Escalation â BeyondTrust and Fortinet exploitation show rapid use of vulnerabilities for access (âBeyondTrust exploitationâ and âFortinet exploitationâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Automation frameworks and malicious workflows imply scheduled or automated execution at scale (âautomation frameworksâ).
- [T1090 ] Proxy â Legitimate services and proxies were used to mask attacker infrastructure and reach victims (âlegitimate command-and-control (C2) infrastructureâ).
Indicators of Compromise
- [Malware / Tool Names ] infostealer and payload families seen in campaigns â StealC, AMOS, and Phexia
- [Campaign / Attack Names ] supply-chain and exploitation activity referenced in the article â React2Shell, JadePuffer, Axios, Trivy, and ClickFix
- [Organizations / Services ] abused or targeted infrastructure and platforms â Hola VPN, BeyondTrust, Darktrace, and Fortinet
- [Country / Region References ] campaign geography and targeting context â United States, Japan, United Kingdom, Zimbabwe
- [Metrics / Detections ] scale indicators tied to detections and prompting â 16 million AI service detections, 2,945 sensitive prompts, and 67% DMARC-passing phishing emails
- [File / Infrastructure Types ] examples of abused delivery and execution surfaces â malicious payloads, release artifacts, container images, and compromised LLM proxies