Threat Research

    In August 2026, analysts investigated MDR cases involving ClickFix-style lures that deployed a Python-based tunneling implant. Unlike traditional ClickFix attacks, the lures instructed victims to open Windows Terminal, a technique known as TerminalFix....
    TIKTOUK, a WordPress credential-collection toolkit comprising Python components and a Go-based Linux crawler that probes websites and extract exposed secrets. The toolkit targets WordPress configuration, backup, environment, and log files, recovering database credentials, AWS keys, API tokens, and encrypted email credentials through configuration-key-based decryption....
    ClingSTUN is a Linux backdoor that exploits unpatched vulnerabilities in Internet-facing routers and IoT devices to establish persistent access and turn compromised systems into remotely controlled proxy nodes....
    In July 2026, China-aligned threat actor TA419 conducted multiple credential-phishing campaigns targeting AI experts. The campaigns impersonated prominent economists and AI policymakers to target experts at US think tanks, universities, and legal organizations....
    Researchers identified 70+ fake cryptocurrency websites impersonating legitimate projects such as xStocks and Pendle, using fake reward votes to lure crypto users. Clicking the voting option prompts victims to connect cryptocurrency wallets, including MetaMask and WalletConnect, potentially leading to malicious token approvals or transaction signatures....
    Researchers details active exploitation of CVE-2026-73570, an unauthenticated OS command-injection vulnerability in the Zimbra Collaboration Suite SNMP notification path, allowing attackers to execute commands on internet-facing servers without authentication....
    Threat actors are actively exploiting two critical NetScaler ADC and Gateway vulnerabilities, CVE-2026-88771 and CVE-2026-88772, both rated CVSS 4.0: 9.5. CVE-2026-88771 enables unauthenticated remote code execution through improper input validation, while CVE-2026-88772 can cause RCE or DoS through a DTLS memory overflow....
    Identified UAT-11587 targeting government and policy organizations across Asia, including Taiwan, India, the Philippines, and Cambodia. First observed in September 2025, the activity had affected or targeted at least 16 institutional environments across eight Asian countries by July 2026....
    Researchers report that Russian Star Blizzard (SEABORGIUM) has expanded its phishing operations in 2026, using large-scale phishing campaigns, compromised websites, and social engineering to target organizations, particularly those connected to Ukraine....
    Detects potential arbitrary file downloads initiated through Microsoft Office applications....
    The AgtaBackup RAT campaign uses fake Microsoft Store/video-conferencing pages to deliver legitimate RMM tools such as LogMeIn Resolve and ConnectWise ScreenConnect, giving attackers remote access to victim systems. Attackers then use PowerShell to download and silently install the .NET-based AgtaBackup RAT as a hidden SYSTEM service....
    Researchers identified a coordinated Malicious Browser Extension campaign in which Chrome extensions disguised as browser games impersonate legitimate Crypto Wallets such as TronLink, Trust Wallet, and Ledger Wallet Extension....
    NeedyMantis is a modular post-compromise malware family used in targeted intrusions against telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Active since at least October 2025, it is typically deployed after initial access to maintain long-term persistence and support follow-on operations....
    Attackers are abusing ChatGPT Custom GPTs to impersonate legitimate products and redirect victims to malicious backup sites. The team identified two Custom GPTs linked to the same campaign and used to facilitate the attacks. A ClickFix lure tricks victims into executing PowerShell, which downloads a malicious MSI and launches a multi-stage infection chain....
    Threat Intelligence Group have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), with expanded targeting across multiple sectors. In June 2026, the threat actor primarily exploited the vulnerability as a zero-day against academic institutions....
    Looking for Something?
    Threat Research Categories:
    Tags