Analyst Brief
Analyst Brief β 2026-10-05
This page is the output of cyber_threat_pipeline/analysis; the data behind it is the brief_input mart (regenerated weekly by dbt). When a second provider is configured, the side-by-side comparison appears here automatically.
Claude (Anthropic) β claude-sonnet-4-6
OTX Threat Intelligence Brief β Week of 29 Sepβ05 Oct 2026
Headline
China-nexus and Russian state actors are simultaneously escalating targeted espionage campaigns against government and policy institutions, while a surge in ClickFix-delivered infostealers and multiple zero-day exploitations signal a broadly opportunistic threat environment this week.
Emerging Threats
π΄ APT / State-Sponsored Espionage
- UAT-11587 (China-nexus) is actively targeting government and policy organizations across nine Asian nations using the Antino backdoor, with C2 routed through Microsoft 365 infrastructure and delivery via DLL sideloading and spear-phishing ("China-nexus UAT-11587 targets government and policy organizations across Asia", 90 indicators). Separately, TA419 (China-aligned) is conducting browser-in-the-browser (BitB) credential phishing against U.S. AI policy think tanks ("Hallucinating Credibility: TA419"). Russia's Star Blizzard is deploying the new RedFlick technique against Ukrainian targets via SmartScreen-bypassing phishing ("Star Blizzard refines phishingβ¦").
π Zero-Day & Vulnerability Exploitation
- Three fresh zero-days are under active exploitation: CVE-2026-82078/81578 (PaperCut MF, Java loader + AdaptixC2 webshell), CVE-2026-88771 (Citrix NetScaler pre-auth command injection, two separate pulses confirming in-the-wild exploitation), and CVE-2026-73570 (Zimbra unauthenticated command injection deploying Chopper/Godzilla webshells). The Warlock ransomware group is additionally chaining five CVEs against water and telecom critical infrastructure ("Warlock Ransomware Attackers Hit Water and Telecom Operators").
π ClickFix / Infostealer Delivery
- ClickFix remains the dominant delivery mechanism this week, appearing across multiple pulses: ChatGPT Custom GPTs are being weaponized to deliver SectopRAT, Lumma Stealer, and AstarionRAT via fake PowerShell prompts ("Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix"). The Psychedelic Stealer uses fake CAPTCHA pages targeting Ukrainian users, and 2CLoader is delivering Vidar and Remus with indirect syscalls for EDR evasion ("2CLoader: A New Malware Loader").
π‘ Supply Chain & Ecosystem Abuse
- GlassWorm-linked malicious extensions are spreading across both VS Code Marketplace and Open VSX, using dead-drop resolvers to steal Solana wallet credentials ("Pretty Themes, Hidden Loaders"). The BraZetsu initial access broker ecosystem is deploying AI-enhanced reconnaissance and WebSocket C2 against Latin American financial infrastructure ("Anatomy of BraZetsu").
π‘ Ransomware
- Galago ransomware has emerged with confirmed infrastructure ties to the Panzer group, targeting healthcare with double-extortion via a Tor leak site. The "Gentlemen" RaaS group is conducting CI/CD and GitLab-targeting double-extortion operations ("Caught in 4K: The Gentlemen Files").
Corpus-Level Shifts
- CVE indicators spiked: 37 new CVE-type indicators appeared this week β a notable volume suggesting a shift toward vulnerability-centric campaigns rather than purely phishing-led intrusions. Zero-day exploitation is a recurring theme across at least four separate pulses.
- British Indian Ocean Territory appears as both a top-targeted country corpus-wide and within the new UAT-11587 and BraZetsu pulses, an unusual geographic signal that may reflect proxy/relay infrastructure attribution rather than genuine victim presence.
- ClickFix (62 total tags) and credential theft (101 tags) now dominate the tag landscape, with this week's pulses reinforcing both β suggesting these techniques have become the baseline delivery and objective pairing across threat actor tiers.
Analyst Caveats
- Attribution confidence is limited: Pulse tags such as "china-nexus" or "china-aligned" reflect community or vendor assessments, not confirmed government attribution. OTX aggregates open-source and vendor-submitted intelligence of variable quality; overlapping infrastructure does not confirm shared actor identity.
- Victim impact and dwell time are unknown: Indicator presence in OTX confirms detection or reporting, not active compromise. Many pulses lack targeted-country data entirely, and sampling bias toward English-language threat reporting likely underrepresents incidents in non-Western regions. Pulse indicator counts (some as low as 1β3) may reflect early-stage or incomplete reporting rather than
Prompt context
Show the prompt sent to every model
You are a threat-intelligence analyst. Produce a concise brief on the current
state of the AlienVault OTX corpus, focusing on **emerging threats from the
last 7 days**.
## Corpus context (as of 2026-10-05 21:13:36.120571+00:00)
- Total pulses: 716
- Total indicators: 24,088
- Active indicators: 23,054 (active = not expired AND not dropped from its pulse)
- Expired indicators: 1,016
- Top 5 indicator types: domain: 8273, FileHash-SHA256: 5165, hostname: 2900, FileHash-MD5: 2564, FileHash-SHA1: 1941
- Top 5 targeted countries: United States of America: 78, India: 38, British Indian Ocean Territory: 38, Brazil: 31, United Kingdom of Great Britain and Northern Ireland: 29
- Top 5 tags: credential theft: 101, clickfix: 62, social engineering: 62, infostealer: 58, phishing: 54
- Top 5 targeted industries: Technology: 156, Government: 148, Finance: 139, Education: 68, Healthcare: 56
## Emerging in the last 7 days
Indicator types newly seen: FileHash-SHA256: 369, domain: 259, FileHash-MD5: 174, IPv4: 119, FileHash-SHA1: 109, hostname: 87, URL: 85, CVE: 37
New pulses (first_seen_at within 7d):
- [WHITE] China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor (id=6abd2800997dc4232dd91d1d, indicators=90, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: china-nexus, antino, uat-11587, asia targeting, spear-phishing, cloudflare infrastructure, microsoft 365 c2, dll sideloading
countries: British Indian Ocean Territory, Cambodia, India, Myanmar, Pakistan, Philippines, Syrian Arab Republic, Taiwan, Thailand
- [WHITE] Fake xStocks, Pendle, and other sites bait crypto users with rewards votes (id=6abec7fc11f84dc2a20573a9, indicators=70, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: crypto impersonation, walletconnect abuse, fake voting scam, cryptocurrency phishing, blockchain fraud, wallet drainer, token theft
countries: β
- [WHITE] Anatomy of BraZetsu: How Cybercriminals Supply the Underground Ecosystem (id=6abfae3085404615c3cf7a32, indicators=54, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: ousaban, latin america, cnab targeting, infected marketplace, websocket c2, ai-enhanced reconnaissance, brazetsu, python malware, agentev2, initial access broker, nuitka compilation, cnabhunter, financial infrastructure
countries: United States of America, Argentina, Brazil, Paraguay, Portugal, Spain
- [WHITE] Phishing Abuses RMM Tools for Persistent Access (id=6abc4e4a5d637b2853f15ac1, indicators=54, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: windowssecurity_password, windowsupdate, screenconnect, phishing, msp360 rmm, social engineering, webbrowserbookmarksview, rmm abuse, hidemouse, credential theft, windowssecurity_pin, cloud infrastructure, defenderdt, defendercontrol, windverify, remote access, mousehidergui, msp360, windowspasskey, schider, webbrowserpassview
countries: β
- [WHITE] XWorm Malware: Worming Its Way From Entry to Exploitation (id=6ac34ecea12957741eb7ac1b, indicators=53, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: botnet, modular threat, data theft, phishing, xworm, ransomware delivery, rdp exploitation, ddgroup
countries: β
- [WHITE] 2CLoader: A New Malware Loader Delivering Vidar and Remus (id=6abd500c65b4bbb867b80e99, indicators=49, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: indirect syscalls, information stealer, evasion techniques, vidar, remus, xworm, loader, payload encryption, 2cloader, anti-analysis
countries: β
- [WHITE] Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix (id=6ac12c993806593609d1c30c, indicators=48, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: stardock, powershell, matanbuchus, remote access trojan, sectoprat, clickfix, gomcam, dns-over-https, amos, chatgpt custom gpt, persistence mechanisms, dll sideloading, lumma stealer, canon captureontouch, google sites, astarionrat, macsync
countries: β
- [WHITE] SMTP is the key: BPFDoor and AVERAT hitting the network edge (id=6abfb61b65922c3229d35cf8, indicators=37, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: linux, implant, bpfdoor, network-edge, rekoobe, smtp, passive-backdoor, averat, process-spoofing, telecommunications
countries: β
- [WHITE] Warlock Ransomware Attackers Hit Water and Telecom Operators (id=6abe7e463c092196777a7816, indicators=26, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: sharepoint exploitation, telecommunications, cve-2025-1055, longlegs, water utility, cve-2025-49704, cve-2025-49706, critical infrastructure, toolshell, cve-2025-53770, warlock, byovd, cve-2025-53771, storm-2603
countries: β
- [WHITE] A STUNning Disguise: Cling Malware Masquerades as Google (id=6ac368846173b592a85473db, indicators=22, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: stun protocol abuse, cve-2014-8361, cve-2023-26801, cve-2023-41011, iot botnet, realtek exploitation, command-and-control, cve-2025-34037, cve-2016-10372, cve-2016-20016, cling, cve-2024-3721, ip spoofing, ddos, cve-2021-35394, wget hijacking
countries: β
- [WHITE] Star Blizzard refines phishing and malware delivery with the RedFlick technique (id=6abd5b434cf09d69f0ee2e48, indicators=21, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: redflick, espionage, ukraine, cosmicpulse, phishing, star blizzard, powershell, smartscreen
countries: Ukraine
- [WHITE] Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles (id=6abe39636551c6c071894d2b, indicators=20, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: frameless bitb, espionage, china-aligned, credential phishing, ta419, aitm, ai policy, browser-in-the-browser, impersonation, think tanks
countries: United States of America, Japan
- [WHITE] PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 (id=6abde39c863acdfda74e5d84, indicators=20, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: java loader, adaptixc2, cve-2026-82078, papercut mf, domain compromise, web shell, lateral movement, cve-2026-81578, zero-day exploitation, credential dumping
countries: β
- [WHITE] Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 (id=6abd4fc35eecbf1cfcd9681c, indicators=18, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: privilege-escalation, looptik, jsp-webshell, zimbra, chopper, command-injection, cve-2026-73570, mail-server, godzillawebshell, snmp-exploitation, credential-theft, needymantis
countries: β
- [WHITE] New PamStealer variant targets macOS via fake crypto wallet (id=6ab2e69de1b172350066344d, indicators=16, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: persistence, ecies, infostealer, pamstealer, keychain, cryptocurrency, swift, browser credential theft, macos, pam validation
countries: β
- [WHITE] PSIRT (id=6abf0b86fb14812f2dc84fb2, indicators=16, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: system compromise, cve-2026-104286, path traversal, arbitrary file write, fortimail, unauthenticated access, ibe feature, zero-day exploitation
countries: β
- [WHITE] The Psychedelic Stealer: When the CAPTCHA Is the Installer (id=6abfb63a870eec5021127b09, indicators=13, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: cryptocurrency theft, fake captcha, native-messaging bridge, clickfix, ukraine targeting, msi execution, psychedelic stealer, psychedelic, psychedeliclove.exe, browser extension
countries: Ukraine
- [WHITE] Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators (id=6abde7dd3f829cf6b721cfaa, indicators=11, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: update_c08937.pl, configuration-exfiltration, cve-2026-88771, pre-authentication, web-shell, citrix netscaler, command-injection, credential-creation, reverse-shell, main.py
countries: β
- [WHITE] $100k in Crypto Drained by the Underground Operation (id=6abf599ea3419c5518645c45, indicators=10, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: exchange drain, tedy, vidar, aotera loader, vidar stealer, underground, aotera, clipboard clipper, browser injection, cryptocurrency theft
countries: β
- [WHITE] Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX (id=6ac07308bd5cef8481adcf61, indicators=10, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: vs code, extensions, open vsx, glassworm, dead-drop, credential theft, solana, supply chain, themes
countries: β
- [WHITE] Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers (id=6abf5aa04b47ef1458d7472a, indicators=7, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: webshell, recreation-management-platform, timestomping, china-based, file-upload-vulnerability, credential-harvesting, ai-generated-scripts, payment-card-theft
countries: β
- [WHITE] August 2026 Threat Trend Report on APT Attacks (South Korea) (id=6abf5a5d160f0149844cd8c1, indicators=7, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: apt campaign, infostealer, powershell, lnk files, dll side-loading, south korea, spear phishing, xenorat
countries: β
- [WHITE] TIKTOUK: Tracing a WordPress Credential Collection Toolkit (id=6abeceb3ed88945bc5661c7d, indicators=7, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: credential theft, wordpress, tiktouk, smtp plugin decryption, configuration exposure, aws credentials, cve-2026-63030, cve-2026-60137, rest api probing, javascript scanning
countries: β
- [WHITE] Swarming Against Citrix 0-Day Exploitation (id=6abde373c68b5d048accac49, indicators=3, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: command injection, cve-2026-88771, citrixbleed, citrix netscaler, webshell, pre-disclosure attack, cve-2025-5777, rce, zero-day exploitation
countries: β
- [WHITE] Caught in 4K: The Gentlemen Files (id=6ac3a6d89aeb3e3d383d6d06, indicators=2, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: double-extortion, ai-platform, mcp, ci/cd, leakned, exfiltration, ransomware, gentlemen, gitlab, raas
countries: β
- [WHITE] Fake iPhone Duo preorder scam triggers DarkSword attack (id=6abbc428d397735970a34334, indicators=1, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: darksword exploit, iphone duo, safari targeting, credential stealing, fake preorder, cryptocurrency theft, social engineering, darksword, ios vulnerability
countries: β
- [WHITE] RemusStealer: EtherHiding In Hidden Windows (id=6abf0d2f3741a634cbd57475, indicators=1, first_seen=2026-10-05T21:13:24.751875+00:00)
tags: remusstealer, information stealer, credential theft, ethereum smart contracts, hidden desktops, lummastealer, blockchain c2, etherhiding
countries: β
- [WHITE] Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix (id=6abb0c55e0fed2d6a1f7e51a, indicators=0, first_seen=2026-09-29T21:27:52.161464+00:00)
tags: amos, sectoprat, social engineering, macsync, lumma stealer, canon sideloading, rat deployment, clickfix, powershell obfuscation, google sites abuse, dll sideloading, chatgpt custom gpt
countries: β
- [WHITE] From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat (id=6abaccf85f7a199ca2ad50c6, indicators=8, first_seen=2026-09-29T21:27:52.161464+00:00)
tags: wireless debugging, android banking trojan, adb exploitation, rathat, blackcat panel, ai-powered automation, c2 infrastructure, panda workshop, maas operation
countries: β
- [WHITE] NeedyMantis: Unpacking a post-compromise malware family used in targeted operations (id=6abac5fd70758a52b56cb48e, indicators=4, first_seen=2026-09-29T21:27:52.161464+00:00)
tags: china-based threat actor, telecommunications, dll sideloading, custom file format, post-compromise, needymantis, websockets, modular framework
countries: β
- [WHITE] Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests (id=6abbbd28cb7e4cac7c679e36, indicators=11, first_seen=2026-09-29T21:27:52.161464+00:00)
tags: remcos rat, cve-2017-0199, hta execution, ole exploitation, phishing, remcos, south korea, steganography, powershell obfuscation
countries: β
- [WHITE] The "VPN for X" Proxy Farm β Risky Plugins (id=6abb5c0df118a53bf415b0bd, indicators=31, first_seen=2026-09-29T21:27:52.161464+00:00)
tags: traffic interception, vpn impersonation, proxy farm, chrome extensions, dynamic configuration, russian-language, browser proxy, remote control
countries: β
- [WHITE] Rise of the Jev-Clones (id=6aba80800986c7309a31cc76, indicators=28, first_seen=2026-09-29T21:27:52.161464+00:00)
tags: brand impersonation, price inflation, domain squatting, fraudulent storefronts, jev api, ai services, typesafe ai, lookalike domains
countries: β
- [WHITE] VeloCloud Orchestrator Remote Access Vulnerability (id=6ab4023773b652cd342e0854, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: remote exploitation, privileged access, velocloud orchestrator, cve-2026-93952, certificate authentication bypass, active exploitation
countries: β
- [WHITE] Galago Ransomware Emerges With Shared Infrastructure Ties to Panzer (id=6ab51a418ee0b2466a9da4f1, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: healthcare targeting, double extortion, tor leak site, iceland, raas, infrastructure sharing, galago, ransomware, panzer
countries: Iceland
- [WHITE] Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware (id=6ab51a43ec94931b637c0607, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: operation conflict compass, scheduled tasks, ukraine targeting, lnk files, north korea, spear-phishing, velvetcake, powershell
countries: Ukraine
- [WHITE] This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move (id=6ab431db415b8cd13de69a7e, indicators=10, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: closedquorum, ai models, windows malware, windows credentials, crypto, infostealer, lsass, password stealer
countries: β
- [WHITE] RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft (id=6ab561541d94721ef4ce040e, indicators=9, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: credential theft, persistence, hvnc, remotepanel, app-bound encryption, boundsiphon, bnb smart chain, clickfix, browser hijacking, cryptocurrency wallet
countries: β
- [WHITE] The Closed Quorum: Inside the first reported autonomous AI C2 implant (id=6ab2681b40bfd39454369b4f, indicators=8, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: process injection, lsass dumping, crypto wallet, closedquorum, discord exfiltration, llm orchestration, credential theft, autonomous c2
countries: β
- [WHITE] Placeholder Domains Whose Ads Serve Scams (id=6ab831882ea7368fb92b06f6, indicators=8, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: ai agents, github, placeholder domains, clickfix, malvertising, investment fraud, cloaking, scareware, affiliate fraud
countries: β
- [WHITE] TASK#STOMP PowerShell Backdoor Steals Business Documents and Maintains Persistent Remote Access (id=6ab51a6bd938b813a0c50c5c, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: scheduled tasks, data exfiltration, avisloader, vbscript, task#stomp, tls bypass, powershell backdoor, velvetcake, document theft, filesystem monitoring, persistent access
countries: β
- [WHITE] PureRAT and PureLogs Campaign Targeting Japanese Organizations (id=6ab69627dd56b82f3b52796d, indicators=78, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: purerat, process hollowing, stealer, japanese organizations, byovd, phishing campaign, purelogs, donut loader
countries: Japan
- [WHITE] Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation (id=6ab15f3f1d05b3fb6ae23973, indicators=7, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: chacha20, arx cipher, string obfuscation, vidar, custom stream cipher, bytecode interpreter, virtual machine, information stealer
countries: β
- [WHITE] Disposable Domains, Durable Hosting (id=6ab3c34aada48d498bcb50af, indicators=58, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: amatera, fake captcha, bulletproof hosting, blockchain c2, as202412, wacatac, clickfix, etherhiding, darkgate, trojanized installer, amadey, compromised websites, matanbuchus
countries: β
- [WHITE] Kothamine malware uses Tailscale's tailcat to evade network detection (id=6ab7c5997e2556d7c00c86e6, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: windows, npm packages, tailscale, encrypted c2, stealer, remote access trojan, kothamine agent, tailcat, kothamine
countries: β
- [WHITE] New RemControl Android Banking Trojan Steals PINs Using AI-Built Phishing Overlays (id=6ab51a6d40cabb350f8e954b, indicators=0, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: android trojan, ai-assisted development, phishing overlays, websocket c2, accessibility service abuse, banking credentials, maas, remcontrol, tvtap
countries: Canada, Italy
- [WHITE] The Psychedelic Stealer: When a CAPTCHA Becomes an Installer (id=6ab68af3aecfcfc39b2824d8, indicators=6, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: psychedelic, infostealer, windows run, msi package, fake captcha, clipboard
countries: Ukraine, United States of America
- [WHITE] Lunex Unmasked: A New Information Stealer Deployed Through BYOVD (id=6ab83188fddeab6ca23aeafc, indicators=52, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: browser-hijacking, cve-2023-20598, ukrainian-targeting, pdfwkrnl, byovd, lunexstealer, information-stealer, credential-theft, native-messaging-host, lunexloader, cryptocurrency-wallet, lunex, kernel-driver-abuse
countries: β
- [WHITE] The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint (id=6ab561550075cd5f0b500b25, indicators=6, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: c3pool, cryptominer, on-endpoint compilation, silentxmrminer, monero, cve-2024-7399, cve-2025-4632, anydesk, samsung magicinfo
countries: β
- [WHITE] OpenSUpdater Hides in Recompiled 7zip SFX, Evading Analysts (id=6ab524f82bf3c05dfa346cb8, indicators=5, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: 7zip sfx, nsis, opensupdater, evasion techniques, snackarcin, reflective loader, code signing abuse, certificate bloating
countries: β
- [WHITE] North Korea's Hangro Revisited (id=6ab15e0fe200afb0f82b8895, indicators=47, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: silibank, mail relay systems, north korea networks, hangro, vpn infrastructure, cross-border infrastructure, softether, certificate hierarchy
countries: β
- [WHITE] A new version of the MacSync macOS stealer targets crypto enthusiasts and developers (id=6ab5176a22ab1049d0969c4a, indicators=45, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: macsync, amos, pam stealer, social engineering, macos stealer, icloud abuse, infostealer, developer targeting, cryptocurrency theft, backdoor module
countries: β
- [WHITE] third-party.com Placeholder Domain Now Serves ClickFix (id=6ab559662b978ca478cf0b21, indicators=5, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: clipboard poisoning, social engineering, powershell, fake captcha, third-party.com, placeholder domain, clickfix, windows targeting
countries: β
- [WHITE] Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline (id=6aba46a30e26418fb09c6000, indicators=28, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: globalprotect exploitation, cve-2026-0257, cve-2024-1086, multi-tenant phishing, cve-2022-40684, adaptixc2, invoice fraud platform, cve-2022-28368, oauth device-code phishing, dns tunneling, cve-2020-1938, cve-2021-36260, energy sector targeting, pix payment fraud, cve-2023-7028, cve-2021-4034
countries: United States of America, Argentina, Belgium, Brazil, Canada, Costa Rica, El Salvador, France, Guatemala, Italy, Mexico, Netherlands, Norway, Qatar, Spain, United Kingdom of Great Britain and Northern Ireland
- [WHITE] RemControl: AI Built the Overlays. Victims Lose their PINs (id=6ab3c7511ba65533d7e207ce, indicators=28, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: unkk threat actor, android banking trojan, malware-as-a-service, screen streaming, accessibility service abuse, medusa, remcontrol, overlay injection, telegram dead-drop
countries: Canada, France, Italy, Poland, Portugal, Spain
- [WHITE] Uncovering a SectopRAT Variant Embedded in Legitimate Software (id=6ab688467ce23517fb31e378, indicators=23, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: sectoprat, rat, infostealer, embedding, crypto
countries: β
- [WHITE] DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer (id=6ab326f4234e22940c7fb969, indicators=23, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: darkme, phishing campaign, process hollowing, social engineering, visual basic 6, financial targeting, rat, cryptocurrency theft
countries: β
- [WHITE] Major vulnerability found in ancient TACACS+ networking protocol (id=6ab61e2ec525754334a6ed2d, indicators=4, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: chinese cyber-espionage, persistence, lateral movement, pre-authentication, remote code execution, tacacs+, telecommunications targeting, networking protocol
countries: β
- [WHITE] Telerik UI Exploitation Leads to Webshell Install and Scanner Execution (id=6aba1398c736673eae22c865, indicators=21, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: cve-2019-18935, telerik ui, godzilla, iis server, reverse shell, privilege escalation, wordpress scanner, web shell, sweetpotato
countries: United States of America
- [WHITE] AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution (id=6ab22dd5026bef69ef5a17fd, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: lateral-movement, attack-campaigns, data-exfiltration, cybersecurity, credential-harvesting, supply-chain, threat-intelligence, vulnerability-exploitation
countries: β
- [WHITE] Equation of Compromise: Anatomy of a Live npm Supply-Chain Campaign (id=6ab22e89f1e0c549443c6917, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: encrypted loader, blockchain infrastructure, defi developers, npm supply-chain, cryptocurrency targeting, download inflation, github actions abuse, smart contract c2
countries: β
- [WHITE] Meet AvisLoader: A Windows Loader Built to Outlast a Takedown (id=6ab40d6887e7e948c6a09d80, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: uac bypass, loader, clickfix, persistence, p2p c2, tox, cloudflare, shortcut modification, avisloader
countries: β
- [WHITE] CARBONATO: a botnet built around an AI agent (id=6ab4d79db2222977d275954f, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: cryptocurrency, credential theft, telegram, botnet, ai framework, carbonato, docker, hermes agent, container security, exposed daemon
countries: β
- [WHITE] Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation (id=6ab2691621023818faaf620e, indicators=17, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: cve-2026-60004, government breach, cve-2022-0847, cve-2023-54391, cve-2026-34909, cve-2026-60137, cve-2026-7273, kapibala, cve-2026-63030, cve-2026-34910, zyxel switches, privilege escalation, data exfiltration, cve-2026-79756, cve-2026-54569, chinese-speaking actor, cve-2026-34908, cve-2026-56271, wordpress exploitation
countries: United States of America, Albania, Australia, Austria, Belarus, Belgium, Brazil, British Indian Ocean Territory, Bulgaria, Chile, China, Colombia, Costa Rica, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Guadeloupe, Hong Kong, Hungary, Iceland, India, Iran, Islamic Republic of, Ireland, Italy, Japan, Latvia, Lithuania, Madagascar, Malaysia, Malta, Martinique, Monaco, Mongolia, Netherlands, Norway, Pakistan, Panama, Philippines, Poland, Portugal, Romania, Russian Federation, Slovakia, Slovenia, South Africa, Spain, Sweden, Switzerland, Taiwan, Thailand, Ukraine, United Arab Emirates, United Kingdom of Great Britain and Northern Ireland, Uzbekistan
- [WHITE] Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits (id=6ab3c34b893b396be1b1aedb, indicators=17, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: uta0565, cve-2026-85880, zero-day exploitation, chrome vulnerabilities, cleangulp, cve-2026-87491, chinese apt, windows privilege escalation, phishing campaigns, cve-2026-85046, domain spoofing
countries: β
- [WHITE] The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder (id=6aba46a2a513094d63bf1bd1, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: browser-data-extraction, anti-vm, python-based, webhook-exfiltration, nuitka, credential-theft, maas, infostealer, pyinstaller
countries: β
- [WHITE] Trust and the enticing consultancy offer (id=6ab59fabb977cbc4847b4dd1, indicators=14, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: trust exploitation, trojanised software, rapuncel, confidence trick, social engineering, access abuse, closedquorum, professional targeting, fake recruiters, fake consultancy
countries: β
- [WHITE] The Tale of Two INC Ransom Notes: A Ransomware Timeline (id=6ab15cd97e805a1f35130341, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: anydesk, initial access broker, inc, double extortion, lateral movement, scheduled tasks, byovd attack, impacket, inc ransomware
countries: β
- [WHITE] ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft (id=6ab77878ad1bbe2993309a09, indicators=12, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: shinyhunters, cve-2026-35273, oracle peoplesoft, unc6240, neo-regeorg, waf bypass, sideeye backdoor, data extortion, meshagent, web shells, sideeye
countries: β
- [WHITE] August 2026 Infostealer Trend Report (id=6ab27eff37df954a32a9fa29, indicators=12, first_seen=2026-09-29T01:41:31.52697+00:00)
tags: email distribution, lummac2, infostealer, dll side-loading, vidar, agenttesla, remus, acrstealer, formbook, seo poisoning
countries: British Indian Ocean Territory, India
## What to produce
Write a 250-400-word brief with:
1. **Headline** (one sentence on the week's most notable signal).
2. **Emerging threats** (3-5 bullets on the new pulses β group by theme: ransomware,
phishing, APT, supply chain, etc. β and cite pulse names).
3. **Corpus-level shifts** (1-3 bullets on changes from the stable picture: a
newly-targeted country, a TLP-distribution shift, a tag spike).
4. **Analyst caveats** (1-2 bullets on what this data can NOT tell us:
attribution confidence, victim impact, dwell time, sampling bias from OTX
subscriptions).
Use markdown. Do not invent indicators, pulse names, or numbers β work strictly
from what's above.
