Analyst Brief
Analyst Brief — 2026-07-13
This page is the output of cyber_threat_pipeline/analysis; the data behind it is the brief_input mart (regenerated weekly by dbt). When a second provider is configured, the side-by-side comparison appears here automatically.
Claude (Anthropic) — claude-sonnet-4-6
Threat Intelligence Brief — Week of 13 July 2026
Headline
China-nexus ORB network expansion, a CitrixBleed 2 ransomware kill-chain, and a wave of supply-chain compromises across npm, PyPI, and gaming platforms define the most consequential threat activity of the past seven days.
Emerging Threats
Ransomware & Destructive Malware: Three distinct ransomware-adjacent campaigns surfaced this week. CitrixBleed 2 (CVE-2025-5777) → DragonForce documents a full seven-step kill-chain from NetScaler session hijacking to ransomware deployment. GodDamn Ransomware (a Beast rebrand) abuses a malicious kernel driver via BYOVD to blind defenses before encryption. GigaWiper masquerades as ransomware while executing destructive disk-wiping, assembled from multiple malware families including FlockWiper and Crucio — a deception tactic that complicates victim response.
APT & Espionage Activity: Nation-state actors are notably active. A China-nexus cluster ("Continues building ORB networks") is deploying at least five new malware families (LongLeash, ShortLeash, DogLeash, JarLeash, LeashTest) against Ruckus routers, exploiting multiple CVEs. Iran's MOIS-linked Cavern Manticore is operating a modular C2 framework with NativeAOT compilation against Israeli targets. One Target, Two Flags reveals simultaneous China- and India-nexus espionage actors targeting Pakistani law enforcement, deploying ShadowPad, PlugX, AsyncRAT, and Cobalt Strike concurrently.
Phishing & Credential Theft at Scale: The "Sign here… and install an unwanted RMM" pulse (577 indicators — the week's largest) describes a DocuSign-impersonation campaign delivering ConnectWise ScreenConnect via JavaScript droppers. Separately, AiTM phishing infrastructure was exposed across 13 countries via a misconfigured operator server, leveraging EvilGinx and OAuth abuse. Vidar Stealer campaigns are running dual tracks: malvertising with Go loaders and code-signing abuse, and phishing emails using Discord and Telegram as dead-drop resolvers.
Supply Chain Compromises: Four distinct supply-chain incidents emerged: the jscrambler npm package compromise, a coordinated npm/PyPI typosquatting campaign targeting payment SDKs (58 indicators), the Injective SDK compromise exfiltrating blockchain wallet keys, and a gaming platform supply-chain attack deploying an Android trojan (BirdCall) targeting Yanbian users.
Corpus-Level Shifts
Indonesia and the BFSI Sector Surge: Indonesia appears as a newly prominent target this week, anchored by the Indonesian Banking Sector Threat Landscape pulse, which clusters at least eight distinct malware families (ValleyRAT, Havoc, Cobalt Strike, AmberDoor, RustSL, LotusLite, Chrysalis, ShadowGuard) and references CVE-2025-8088 — suggesting a coordinated, multi-actor campaign against financial infrastructure not previously prominent in this corpus.
Tag Spike — Supply Chain & Living-off-the-Land: Supply chain attack tags (24 total in corpus) and living-off-the-land techniques appear across at least five new pulses simultaneously, indicating these are not isolated incidents but a cross-campaign tactical preference this week.
AI-Assisted Threat Development Emerging: Two pulses (Browser-Only Ransomware using LLM-generated code, CrownX ransomware with AI-assisted development) signal an early but notable trend of threat actors leveraging generative AI tooling — a pattern not previously tagged in this corpus.
Analyst Caveats
Attribution confidence is low-to-moderate throughout. OTX pulses aggregate open-source reporting and vendor blog posts; "China-nexus" or "Iran-linked" designations reflect submitter assessments, not independently verified intelligence. Overlapping actor targeting (e.g., two nation-state actors on the same Pakistani victim) may reflect shared tooling or infrastructure reuse rather than confirmed separate campaigns.
This corpus reflects detection and publication bias, not ground truth. Pulses appear when researchers publish, not when intrusions occur — dwell times, actual victim counts, and campaign scope are unknown. The 577-indicator RMM pulse and the 87-indicator ORB network pulse dominate the week's indicator volume, which may skew perceived threat priority relative to lower-profile but operationally significant activity that has not yet been publicly reported.
Prompt context
Show the prompt sent to every model
You are a threat-intelligence analyst. Produce a concise brief on the current
state of the AlienVault OTX corpus, focusing on **emerging threats from the
last 7 days**.
## Corpus context (as of 2026-07-13 15:41:36.541228+00:00)
- Total pulses: 304
- Total indicators: 13,345
- Active indicators: 13,345 (active = not expired AND not dropped from its pulse)
- Expired indicators: 0
- Top 5 indicator types: domain: 5462, FileHash-SHA256: 2515, hostname: 1752, FileHash-MD5: 1198, FileHash-SHA1: 916
- Top 5 targeted countries: United States of America: 34, British Indian Ocean Territory: 16, India: 16, Russian Federation: 15, Brazil: 15
- Top 5 tags: credential theft: 52, social engineering: 31, infostealer: 30, phishing: 28, supply chain attack: 24
- Top 5 targeted industries: Technology: 66, Finance: 59, Government: 59, Education: 26, Healthcare: 24
## Emerging in the last 7 days
Indicator types newly seen: FileHash-SHA256: 686, domain: 529, URL: 337, FileHash-MD5: 215, hostname: 175, FileHash-SHA1: 165, IPv4: 95, CVE: 31, email: 5, CIDR: 1
New pulses (first_seen_at within 7d):
- [WHITE] From Phishing to Persistence: A CrySome RAT Infection Chain Analysis (id=6a4d09e0fbf878666b3d5afd, indicators=17, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: spear-phishing, credential theft, living-off-the-land, amsi bypass, browser hijacking, crysome rat, uac bypass, windefctl
countries: —
- [WHITE] Continues building ORB networks using new malware (id=6a4d0a8afd30c55d7e2c19d5, indicators=87, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: leashtest, shortleash, cve-2020-22653, cve-2020-22658, backdoor, longleash, china-nexus, dogleash, cve-2025-2492, uat-7810, ruckus routers, jarleash, cve-2023-25717, orb networks
countries: —
- [WHITE] Indonesian Banking Sector Threat Landscape (id=6a4fdf500b5e6dffde939998, indicators=33, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: phishing campaigns, apt espionage, chrysalis, financial cybercrime, bfsi sector, rustsl, amaranth loader, valleyrat, lotuslite, havoc, data breach, shadowguard, abcdoor, cve-2025-8088, ransomware extortion, tgamaranth rat, cobalt strike, indonesian banking, supply chain compromise
countries: British Indian Ocean Territory, India, Indonesia, Japan, Russian Federation, South Africa, Thailand
- [WHITE] CitrixBleed 2 (CVE-2025-5777) 7 Steps to Dragonforce Ransomware (id=6a4fa0227d951890d045e399, indicators=13, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: cve-2025-5777, mimikatz, screenconnect, initial access broker, impacket, citrixbleed 2, dragonforce, session hijacking, privilege escalation, netscaler, ransomware
countries: —
- [WHITE] Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation (id=6a4d89812b006d2839a4dc49, indicators=165, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: vidar stealer, cryptojacking, vidar, amsi bypass, xmrig, go loader, credential theft, factory-v3, code signing abuse, malvertising
countries: United States of America
- [WHITE] Bundled to Steal: The Salat Stealer Campaign (id=6a4c3a7bc1e7623521754884, indicators=11, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: infostealer, surveillance capabilities, credential theft, cryptocurrency wallets, windows defender evasion, go language, salat stealer, xeno executor
countries: —
- [WHITE] Massive offensive launched on Russian businesses (id=6a4f99c8656ebbe895c7e9e5, indicators=76, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: lnk file, chemical industry, powershell loader, netsupport manager, belarus, phishing campaign, russian targets, url shortener
countries: Belarus, Russian Federation
- [WHITE] One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement (id=6a501da43fb3cb230cc9a9b9, indicators=41, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: pakistan, china-nexus, india-nexus, law enforcement targeting, shadowpad, remcos, asyncrat, balochistan police, cyberespionage, cobalt strike, plugx
countries: Pakistan
- [WHITE] Fake Banking Rewards, Telegram Delivery and Albiriox: Anatomy of an Android Malware Campaign (id=6a501da5e79e415cb0ec861e, indicators=10, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: banking trojan, overlay attacks, sms interception, android, albiriox, brand impersonation, accessibility abuse, telegram delivery, italy
countries: Italy
- [WHITE] Cavern Manticore: Exposing Iran-Linked Modular C2 Framework (id=6a4bb565cb9499639bf4125b, indicators=25, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: modular c2 framework, rmm abuse, sysaid, supply-chain compromise, iran, nativeaot compilation, mois, dll sideloading
countries: Israel
- [WHITE] One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation (id=6a4cc5e62f81e1c341eba563, indicators=9, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: squareshell, cve-2024-42009, snowlight, cve-2023-2868, university targeting, roundcube exploitation, squareshell webshell, vshell, china-aligned, icecube, icecube stealer, cve-2025-49113, unk_masstraction, vshell backdoor, cross-site scripting
countries: United States of America, Canada
- [WHITE] Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories (id=6a4f5adbd8cb65e0d44c0d53, indicators=40, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: asyncrat, go module, vidar, quasar, operation muck and load, commit farming, powershell loader, github lure network, xmrig, dead drop resolver, remcos
countries: —
- [WHITE] One Misconfigured Server, Three Active Campaigns: Full exposure of three AiTM Phishing Operators (id=6a54bfc57c70fae743cb883e, indicators=73, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: madoo blaster, asyncrat, rmm tools, oauth abuse, evilginx, aitm, phishing infrastructure
countries: United States of America, Australia, Brazil, Canada, France, Norway, Poland, Singapore, Slovenia, Spain, Switzerland, United Kingdom of Great Britain and Northern Ireland
- [WHITE] GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware (id=6a4fdb50b88e8fc2bfbd26dd, indicators=20, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: multi-stage intrusion, wprcree, flockwiper, destructive wiper, crucio, gigawiper, fake ransomware, rabbitmq, wprflock, cutbrooch, disk wiping, golang backdoor
countries: —
- [WHITE] Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2 (id=6a5414fab18f9d7456d7eda8, indicators=7, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: rokrat, yandex, pcloud, spear-phishing
countries: —
- [WHITE] GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses (id=6a4f99c77bfb2dde4f69e174, indicators=38, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: kernel driver, defense evasion, anydesk, credential harvesting, mimikatz, goddamn, beast, poisonx, monster, byovd, poisonx driver
countries: —
- [WHITE] How WP-SHELLSTORM Exposed 1.4M WordPress Sites (id=6a54b716f22fd928cabf4eb8, indicators=19, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: wordpress, botnet, vshell, godzilla, webshell, access-brokerage
countries: —
- [WHITE] RedHook Returns with a Dangerous Upgrade (id=6a4fa023bcc8675bb1b91cfc, indicators=6, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: adb wireless debugging, phishing, persistence mechanisms, android rat, redhook, shizuku framework, social engineering, privilege escalation, southeast asia
countries: Indonesia
- [WHITE] Threat Insight: Cybercriminals Abusing Vercel to Deliver Remote Access Malware (id=6a501da309cbaaa917ea732a, indicators=6, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: trusted platform exploitation, logmein, vercel abuse, executable disguise, email campaign, pdf impersonation, remote access, phishing
countries: —
- [WHITE] jscrambler npm Package Compromised in Supply Chain Attack (id=6a52d7f22883fcd1f11046c2, indicators=6, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: npm compromise, infostealer, supply chain attack
countries: —
- [WHITE] From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations (id=6a4f858d17f60f10d1e16c2c, indicators=17, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: scheduled task persistence, remote access tool, aerospace targeting, smtp exfiltration, russian victims, living-off-the-land, anydesk, spear-phishing
countries: Russian Federation
- [WHITE] Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics (id=6a506b1789bdc92f8fe1d6d5, indicators=4, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: npm compromise, wallet credential exfiltration, typescript sdk, blockchain, developer account compromise, cryptocurrency theft, supply chain attack, infostealer
countries: —
- [WHITE] Vidar Infostealer Being Spread through Phishing Emails (id=6a4f85b7629d0335b2a22436, indicators=17, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: dead drop resolver, discord, infostealer, browser credential theft, cryptocurrency theft, steam, telegram, phishing, vidar
countries: —
- [WHITE] Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps (id=6a4d89817cfad2c0f464e67a, indicators=58, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: pypi, npm, token exfiltration, payment sdk, ngrok, credential theft, sandbox evasion, multi-ecosystem, typosquatting
countries: —
- [WHITE] Phishers Abuse Business Account Manager Service (id=6a4d09f2b48d42a59af0ffa3, indicators=3, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: credential theft, telegram exfiltration, vietnamese threat actor, business account manager abuse, meta phishing, facebook messenger chatbot, identity document theft, mfa bypass
countries: —
- [WHITE] Sign here… and install an unwanted RMM (id=6a512b20f12a5adf6bf2c1b3, indicators=577, first_seen=2026-07-13T15:41:16.054812+00:00)
tags: social engineering, javascript dropper, telegram tracking, phishing, rmm abuse, docusign impersonation, connectwise screenconnect
countries: —
- [WHITE] An Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails (id=6a446c5df8b0ab9d5af62b64, indicators=6, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: phishing emails, process injection, fake installers, donut shellcode, japanese targets, dll sideloading, chinese targets, valleyrat
countries: —
- [WHITE] GitHub Impersonation Deploys Information Stealer (id=6a468e99941f9e2f4d672d80, indicators=6, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: information stealer, dll side-loading, social engineering, github impersonation, boryptgrab stealer, boryptgrab, seo poisoning, fake repositories
countries: —
- [WHITE] A Djinn in the Machine: TaskWeaver's Node.js Intrusion Chain (id=6a432365e2207bde8681b975, indicators=5, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: ai development tools, cve-2026-48558, taskweaver, supply chain risk, credential theft, node.js, djinn stealer, simplehelp, rmm exploitation
countries: —
- [WHITE] Not very gentlemanly: Analyzing a zero-day exploit used to disable targets' EDRs (id=6a43f039e387ddd12ed0896c, indicators=3, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: the gentlemen, edr killer, byovd, ransomware, kontron driver, zero-day, endpoint protection bypass, ktapi.sys, kernel exploit
countries: —
- [WHITE] Inside an affiliate panel targeting Microsoft 365 (id=6a4500fd1580f75d3cf32d5e, indicators=3, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: oauth abuse, phishing-as-a-service, eviltokens, business email compromise, microsoft 365, artoken, device code phishing, primary refresh token
countries: —
- [WHITE] Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique (id=6a4500ffd044499efcd70db1, indicators=1, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: infernograbber, llm-generated malware, android chrome exploitation, social engineering, deepseek, voidlink, ai-assisted attacks, phishing lures, file system access api, browser-native ransomware
countries: —
- [WHITE] RAT Abuses TON Blockchain to Target Japan's Hotel Industry (id=6a42d46fe5317e409adbaaa3, indicators=142, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: ton blockchain, dead drop resolver, node.js abuse, japan targeting, hotel industry, booking.com, credential theft, tonresolver, phishing campaign
countries: Japan
- [WHITE] How a single ScreenConnect incident exposed a massive campaign (id=6a4545dbc77aff75fe16cee7, indicators=134, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: remote access trojan, fake software, c2 infrastructure, process hollowing, screenconnect, powershell loader, typosquatting, seo poisoning, dll sideloading, asyncrat
countries: —
- [WHITE] Iran-Nexus Disseminates MarkiRAT Surveillance Tool (id=6a45471afccee96152675f88, indicators=85, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: ferocious kitten, irgc, furball, surveillance, iran, fake vpn, bouldspy, markirat, tag-182, dchspy, farsi-speaking targets
countries: Iran, Islamic Republic of
- [WHITE] Roblox, Minecraft, and the Insidious Internet for Children (id=6a47950711440db76d84e5de, indicators=55, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: minecraft, gaming platforms, roblox, children targeting, offerwall schemes, subscription traps, disposable domains, data harvesting, credential phishing
countries: —
- [WHITE] The Gentlemen are knocking: сustom backdoors and evolving tactics (id=6a42506c95cc259404196a5b, indicators=48, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: vulnerable drivers, sharkloader, zichatbot, coolclient, gpo deployment, ransomware-as-a-service, powercloud, appleseed, mgbot, encryption tactics, byovd, reversesocks, cobalt strike, network reconnaissance, custom backdoor, lateral movement
countries: Brazil, China, Indonesia, Taiwan, Thailand
- [WHITE] Armored Likho's new weapon: BusySnake Stealer (id=6a47a77e01d1e457798b3a33, indicators=46, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: busysnake stealer, pyarmor obfuscation, credential theft, electric power sector, go2tunnel, reverse ssh tunnel, aquilarat, spear-phishing, browser password extraction, government targeting
countries: Brazil, Kazakhstan, Russian Federation
- [WHITE] A rigged game: compromises gaming platform in a supply-chain attack (id=69f9c539da459757922d22d8, indicators=38, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: supply-chain attack, birdcall, android trojan, yanbian targeting, gaming platform compromise
countries: —
- [WHITE] What Is the BabaDeda Loader? Analysis of a New ClickFix Malware Campaign. (id=6a47b2cc64d3d9241377df01, indicators=38, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: BabaDeda, ClickFix
countries: —
- [WHITE] Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula (id=6a45880f3df872860c77a553, indicators=36, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: credential theft, phishing, portugal, iberian peninsula, ousaban, geofencing, casbaneiro, spain, banking trojan
countries: Portugal, Spain
- [WHITE] PamStealer: a Rust-based macOS infostealer that validates credentials through PAM (id=6a471de6cf9848f2ef9503c0, indicators=28, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: clipboard stealer, applescript dropper, fake maccy, pam authentication, jxa downloader, browser data theft, pamstealer, rust-based, macos infostealer, credential theft
countries: —
- [WHITE] A single RedLine C2 pivots into a maritime spear-phishing cluster and attacker-owned infrastructure. (id=6a464b96bef17724be5668a0, indicators=27, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: spear-phishing, south korean victims, business email compromise, infrastructure pivoting, maritime sector targeting, formbook, metamorfo, redline stealer, domain impersonation, casbaneiro, xloader
countries: —
- [WHITE] Phishing in the Balkans: Fake Traffic Fines, Real Losses (id=6a4545d3f23bbaf07db98a73, indicators=25, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: phoenix, government impersonation, darcula, smishing, phaas, traffic fines, payment card theft, serbia, balkans
countries: Serbia
- [WHITE] RustDuck: An In-Depth Analysis of a Two-Stage Botnet (id=6a4635e7998db450b0ccdee2, indicators=23, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: two-stage loader, ddos botnet, cve-2025-29635, iot compromise, cve-2018-8007, weak password attacks, encrypted c2, cross-platform, cve-2017-17215, cve-2024-1781, anti-debugging, rustduck
countries: —
- [WHITE] From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira (id=6a429369377f216bcfbdda03, indicators=22, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: rustdesk, trojanized installer, lateral movement, adaptixc2, akira, credential dumping, bumblebee, seo poisoning
countries: —
- [WHITE] Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates (id=6a43b188e88186c48de04785, indicators=19, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: vpn impersonation, firefox add-ons, free vpn by vpn go, staged updates, supply chain, credential theft, chrome web store, clipboard stealer, vpn go: free vpn, browser extension
countries: —
- [WHITE] India's government and energy sectors targeted with ZOHOMURK and MINIRECON (id=6a42d4a95543681c96ad0e57, indicators=17, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: india, government targeting, websocket, minirecon, zohomurk, shadowpad, cloud c2, hydropower, espionage, pubload, shardloader, toneshell, zoho workdrive, dll sideloading
countries: British Indian Ocean Territory, India
- [WHITE] Branded Gambling Campaigns: How Scammers Are Exploiting Trusted Brand Names to Drive Casino Traffic (id=6a46d12100d65a16f173e8a4, indicators=14, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: fake app stores, online gambling scams, casino redirection, brand impersonation, affiliate fraud, social media advertising, progressive web apps, pwa
countries: Canada, Germany, Spain, United Kingdom of Great Britain and Northern Ireland
- [WHITE] The Crown Prince, Nezha (id=6a4828eab61bec7567ac88b1, indicators=14, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: phpmyadmin, gh0st rat, china-nexus, nezha, ghost rat, china chopper, web compromise, antsword, log poisoning, web shell
countries: United States of America, Angola, Argentina, Australia, Bangladesh, Belgium, Bosnia and Herzegovina, Brazil, British Indian Ocean Territory, Canada, Chile, Colombia, Finland, France, Georgia, Germany, Greece, Guatemala, Hong Kong, India, Indonesia, Ireland, Japan, Kazakhstan, Kenya, Macao, Malaysia, Mexico, Mongolia, Morocco, Nepal, Nigeria, Pakistan, Peru, Philippines, Portugal, Russian Federation, Saudi Arabia, Serbia, Singapore, Slovakia, South Georgia and the South Sandwich Islands, Sri Lanka, Taiwan, Tanzania, United Republic of, Thailand, Trinidad and Tobago, United Arab Emirates, United Kingdom of Great Britain and Northern Ireland, Zambia
- [WHITE] How access to Gmail accounts is gained (id=6a43aeed1ecda1a314aec59e, indicators=11, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: tomberbil, remote debugging, corporate espionage, oauth token theft, chromium exploitation, dll sideloading, toddycat, umbrij, gmail compromise
countries: —
- [WHITE] Indirect Prompt Injection in Web Content Targets AI Agents (id=6a46cc8d21232689c52266a2, indicators=11, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: llm manipulation, typosquatting, seo poisoning, indirect prompt injection, payment fraud, ipi, cryptocurrency scam, ai agents
countries: —
- [WHITE] Vibe Coded Extortion: Path from Legal Lure to CrownX Ransom Capabilities (id=6a46d120d41fcc87a8a52932, indicators=10, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: ransomware, credential theft, lateral movement, avalon, defense evasion, phishing, crownx, ai-assisted development
countries: —
- [WHITE] Defence Impairment Olympics (id=6a4323652af5f050747cd53a, indicators=9, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: cve-2023-29298, wdigest, cve-2023-26360, coldfusion exploitation, defence evasion, credential dumping, steganography, mimikatz, defence impairment, timestomping, webshell, iis server, cve-2023-29300
countries: —
- [WHITE] Blacksite: New AiTM Phishing Kit Evades URL Scanners via Cloaked.gg (id=6a463469f06125cbab68ef8c, indicators=8, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: credential-theft, url-evasion, aitm, mfa-bypass, blacksite, session-hijacking, cloaking, reverse-proxy, tycoon 2fa, phishing-as-a-service
countries: —
- [WHITE] AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign (id=6a471de4dcdacfc396979ab8, indicators=7, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: formbook, steganography, asyncrat, remcos, vba macros, url shorteners, lumma, multi-stage infection, cloudflare workers, hta payload, phishing campaign, spreadsheet dropper
countries: —
- [WHITE] Chromium extension uses AI‑related branding to redirect browser search (id=6a42d0b89159dccad1ff7879, indicators=7, first_seen=2026-07-06T16:20:20.140339+00:00)
tags: keystroke capture, typosquatting, browser extension, declarativenetrequest, perplexity ai spoofing, data interception, search hijacking, chrome extension
countries: —
## What to produce
Write a 250-400-word brief with:
1. **Headline** (one sentence on the week's most notable signal).
2. **Emerging threats** (3-5 bullets on the new pulses — group by theme: ransomware,
phishing, APT, supply chain, etc. — and cite pulse names).
3. **Corpus-level shifts** (1-3 bullets on changes from the stable picture: a
newly-targeted country, a TLP-distribution shift, a tag spike).
4. **Analyst caveats** (1-2 bullets on what this data can NOT tell us:
attribution confidence, victim impact, dwell time, sampling bias from OTX
subscriptions).
Use markdown. Do not invent indicators, pulse names, or numbers — work strictly
from what's above.
