Analyst Brief

Analyst Brief β€” 2026-10-05

This page is the output of cyber_threat_pipeline/analysis; the data behind it is the brief_input mart (regenerated weekly by dbt). When a second provider is configured, the side-by-side comparison appears here automatically.

Claude (Anthropic) β€” claude-sonnet-4-6

OTX Threat Intelligence Brief β€” Week of 29 Sep–05 Oct 2026

Headline

China-nexus and Russian state actors are simultaneously escalating targeted espionage campaigns against government and policy institutions, while a surge in ClickFix-delivered infostealers and multiple zero-day exploitations signal a broadly opportunistic threat environment this week.


Emerging Threats

πŸ”΄ APT / State-Sponsored Espionage

  • UAT-11587 (China-nexus) is actively targeting government and policy organizations across nine Asian nations using the Antino backdoor, with C2 routed through Microsoft 365 infrastructure and delivery via DLL sideloading and spear-phishing ("China-nexus UAT-11587 targets government and policy organizations across Asia", 90 indicators). Separately, TA419 (China-aligned) is conducting browser-in-the-browser (BitB) credential phishing against U.S. AI policy think tanks ("Hallucinating Credibility: TA419"). Russia's Star Blizzard is deploying the new RedFlick technique against Ukrainian targets via SmartScreen-bypassing phishing ("Star Blizzard refines phishing…").

🟠 Zero-Day & Vulnerability Exploitation

  • Three fresh zero-days are under active exploitation: CVE-2026-82078/81578 (PaperCut MF, Java loader + AdaptixC2 webshell), CVE-2026-88771 (Citrix NetScaler pre-auth command injection, two separate pulses confirming in-the-wild exploitation), and CVE-2026-73570 (Zimbra unauthenticated command injection deploying Chopper/Godzilla webshells). The Warlock ransomware group is additionally chaining five CVEs against water and telecom critical infrastructure ("Warlock Ransomware Attackers Hit Water and Telecom Operators").

🟠 ClickFix / Infostealer Delivery

  • ClickFix remains the dominant delivery mechanism this week, appearing across multiple pulses: ChatGPT Custom GPTs are being weaponized to deliver SectopRAT, Lumma Stealer, and AstarionRAT via fake PowerShell prompts ("Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix"). The Psychedelic Stealer uses fake CAPTCHA pages targeting Ukrainian users, and 2CLoader is delivering Vidar and Remus with indirect syscalls for EDR evasion ("2CLoader: A New Malware Loader").

🟑 Supply Chain & Ecosystem Abuse

  • GlassWorm-linked malicious extensions are spreading across both VS Code Marketplace and Open VSX, using dead-drop resolvers to steal Solana wallet credentials ("Pretty Themes, Hidden Loaders"). The BraZetsu initial access broker ecosystem is deploying AI-enhanced reconnaissance and WebSocket C2 against Latin American financial infrastructure ("Anatomy of BraZetsu").

🟑 Ransomware

  • Galago ransomware has emerged with confirmed infrastructure ties to the Panzer group, targeting healthcare with double-extortion via a Tor leak site. The "Gentlemen" RaaS group is conducting CI/CD and GitLab-targeting double-extortion operations ("Caught in 4K: The Gentlemen Files").

Corpus-Level Shifts

  • CVE indicators spiked: 37 new CVE-type indicators appeared this week β€” a notable volume suggesting a shift toward vulnerability-centric campaigns rather than purely phishing-led intrusions. Zero-day exploitation is a recurring theme across at least four separate pulses.
  • British Indian Ocean Territory appears as both a top-targeted country corpus-wide and within the new UAT-11587 and BraZetsu pulses, an unusual geographic signal that may reflect proxy/relay infrastructure attribution rather than genuine victim presence.
  • ClickFix (62 total tags) and credential theft (101 tags) now dominate the tag landscape, with this week's pulses reinforcing both β€” suggesting these techniques have become the baseline delivery and objective pairing across threat actor tiers.

Analyst Caveats

  • Attribution confidence is limited: Pulse tags such as "china-nexus" or "china-aligned" reflect community or vendor assessments, not confirmed government attribution. OTX aggregates open-source and vendor-submitted intelligence of variable quality; overlapping infrastructure does not confirm shared actor identity.
  • Victim impact and dwell time are unknown: Indicator presence in OTX confirms detection or reporting, not active compromise. Many pulses lack targeted-country data entirely, and sampling bias toward English-language threat reporting likely underrepresents incidents in non-Western regions. Pulse indicator counts (some as low as 1–3) may reflect early-stage or incomplete reporting rather than

Prompt context

Show the prompt sent to every model
You are a threat-intelligence analyst. Produce a concise brief on the current
      state of the AlienVault OTX corpus, focusing on **emerging threats from the
      last 7 days**.

      ## Corpus context (as of 2026-10-05 21:13:36.120571+00:00)
      - Total pulses:                 716
      - Total indicators:             24,088
      - Active indicators:            23,054  (active = not expired AND not dropped from its pulse)
      - Expired indicators:           1,016
      - Top 5 indicator types:        domain: 8273, FileHash-SHA256: 5165, hostname: 2900, FileHash-MD5: 2564, FileHash-SHA1: 1941
      - Top 5 targeted countries:     United States of America: 78, India: 38, British Indian Ocean Territory: 38, Brazil: 31, United Kingdom of Great Britain and Northern Ireland: 29
      - Top 5 tags:                   credential theft: 101, clickfix: 62, social engineering: 62, infostealer: 58, phishing: 54
      - Top 5 targeted industries:    Technology: 156, Government: 148, Finance: 139, Education: 68, Healthcare: 56

      ## Emerging in the last 7 days
      Indicator types newly seen:     FileHash-SHA256: 369, domain: 259, FileHash-MD5: 174, IPv4: 119, FileHash-SHA1: 109, hostname: 87, URL: 85, CVE: 37
      New pulses (first_seen_at within 7d):
        - [WHITE] China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor (id=6abd2800997dc4232dd91d1d, indicators=90, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: china-nexus, antino, uat-11587, asia targeting, spear-phishing, cloudflare infrastructure, microsoft 365 c2, dll sideloading
    countries: British Indian Ocean Territory, Cambodia, India, Myanmar, Pakistan, Philippines, Syrian Arab Republic, Taiwan, Thailand
- [WHITE] Fake xStocks, Pendle, and other sites bait crypto users with rewards votes (id=6abec7fc11f84dc2a20573a9, indicators=70, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: crypto impersonation, walletconnect abuse, fake voting scam, cryptocurrency phishing, blockchain fraud, wallet drainer, token theft
    countries: β€”
- [WHITE] Anatomy of BraZetsu: How Cybercriminals Supply the Underground Ecosystem (id=6abfae3085404615c3cf7a32, indicators=54, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: ousaban, latin america, cnab targeting, infected marketplace, websocket c2, ai-enhanced reconnaissance, brazetsu, python malware, agentev2, initial access broker, nuitka compilation, cnabhunter, financial infrastructure
    countries: United States of America, Argentina, Brazil, Paraguay, Portugal, Spain
- [WHITE] Phishing Abuses RMM Tools for Persistent Access (id=6abc4e4a5d637b2853f15ac1, indicators=54, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: windowssecurity_password, windowsupdate, screenconnect, phishing, msp360 rmm, social engineering, webbrowserbookmarksview, rmm abuse, hidemouse, credential theft, windowssecurity_pin, cloud infrastructure, defenderdt, defendercontrol, windverify, remote access, mousehidergui, msp360, windowspasskey, schider, webbrowserpassview
    countries: β€”
- [WHITE] XWorm Malware: Worming Its Way From Entry to Exploitation (id=6ac34ecea12957741eb7ac1b, indicators=53, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: botnet, modular threat, data theft, phishing, xworm, ransomware delivery, rdp exploitation, ddgroup
    countries: β€”
- [WHITE] 2CLoader: A New Malware Loader Delivering Vidar and Remus (id=6abd500c65b4bbb867b80e99, indicators=49, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: indirect syscalls, information stealer, evasion techniques, vidar, remus, xworm, loader, payload encryption, 2cloader, anti-analysis
    countries: β€”
- [WHITE] Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix (id=6ac12c993806593609d1c30c, indicators=48, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: stardock, powershell, matanbuchus, remote access trojan, sectoprat, clickfix, gomcam, dns-over-https, amos, chatgpt custom gpt, persistence mechanisms, dll sideloading, lumma stealer, canon captureontouch, google sites, astarionrat, macsync
    countries: β€”
- [WHITE] SMTP is the key: BPFDoor and AVERAT hitting the network edge (id=6abfb61b65922c3229d35cf8, indicators=37, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: linux, implant, bpfdoor, network-edge, rekoobe, smtp, passive-backdoor, averat, process-spoofing, telecommunications
    countries: β€”
- [WHITE] Warlock Ransomware Attackers Hit Water and Telecom Operators (id=6abe7e463c092196777a7816, indicators=26, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: sharepoint exploitation, telecommunications, cve-2025-1055, longlegs, water utility, cve-2025-49704, cve-2025-49706, critical infrastructure, toolshell, cve-2025-53770, warlock, byovd, cve-2025-53771, storm-2603
    countries: β€”
- [WHITE] A STUNning Disguise: Cling Malware Masquerades as Google (id=6ac368846173b592a85473db, indicators=22, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: stun protocol abuse, cve-2014-8361, cve-2023-26801, cve-2023-41011, iot botnet, realtek exploitation, command-and-control, cve-2025-34037, cve-2016-10372, cve-2016-20016, cling, cve-2024-3721, ip spoofing, ddos, cve-2021-35394, wget hijacking
    countries: β€”
- [WHITE] Star Blizzard refines phishing and malware delivery with the RedFlick technique (id=6abd5b434cf09d69f0ee2e48, indicators=21, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: redflick, espionage, ukraine, cosmicpulse, phishing, star blizzard, powershell, smartscreen
    countries: Ukraine
- [WHITE] Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles (id=6abe39636551c6c071894d2b, indicators=20, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: frameless bitb, espionage, china-aligned, credential phishing, ta419, aitm, ai policy, browser-in-the-browser, impersonation, think tanks
    countries: United States of America, Japan
- [WHITE] PaperCut MF Zero-Day Intrusion: Java Loader, Web Shell, and AdaptixC2 via CVE-2026-82078 and CVE-2026-81578 (id=6abde39c863acdfda74e5d84, indicators=20, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: java loader, adaptixc2, cve-2026-82078, papercut mf, domain compromise, web shell, lateral movement, cve-2026-81578, zero-day exploitation, credential dumping
    countries: β€”
- [WHITE] Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 (id=6abd4fc35eecbf1cfcd9681c, indicators=18, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: privilege-escalation, looptik, jsp-webshell, zimbra, chopper, command-injection, cve-2026-73570, mail-server, godzillawebshell, snmp-exploitation, credential-theft, needymantis
    countries: β€”
- [WHITE] New PamStealer variant targets macOS via fake crypto wallet (id=6ab2e69de1b172350066344d, indicators=16, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: persistence, ecies, infostealer, pamstealer, keychain, cryptocurrency, swift, browser credential theft, macos, pam validation
    countries: β€”
- [WHITE] PSIRT (id=6abf0b86fb14812f2dc84fb2, indicators=16, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: system compromise, cve-2026-104286, path traversal, arbitrary file write, fortimail, unauthenticated access, ibe feature, zero-day exploitation
    countries: β€”
- [WHITE] The Psychedelic Stealer: When the CAPTCHA Is the Installer (id=6abfb63a870eec5021127b09, indicators=13, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: cryptocurrency theft, fake captcha, native-messaging bridge, clickfix, ukraine targeting, msi execution, psychedelic stealer, psychedelic, psychedeliclove.exe, browser extension
    countries: Ukraine
- [WHITE] Citrix NetScaler CVE-2026-88771: Observed Exploitation Artifacts and Hunt Indicators (id=6abde7dd3f829cf6b721cfaa, indicators=11, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: update_c08937.pl, configuration-exfiltration, cve-2026-88771, pre-authentication, web-shell, citrix netscaler, command-injection, credential-creation, reverse-shell, main.py
    countries: β€”
- [WHITE] $100k in Crypto Drained by the Underground Operation (id=6abf599ea3419c5518645c45, indicators=10, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: exchange drain, tedy, vidar, aotera loader, vidar stealer, underground, aotera, clipboard clipper, browser injection, cryptocurrency theft
    countries: β€”
- [WHITE] Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX (id=6ac07308bd5cef8481adcf61, indicators=10, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: vs code, extensions, open vsx, glassworm, dead-drop, credential theft, solana, supply chain, themes
    countries: β€”
- [WHITE] Determined Attacker Uploads Malicious Webshells to Parks and Rec Management Platform Servers (id=6abf5aa04b47ef1458d7472a, indicators=7, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: webshell, recreation-management-platform, timestomping, china-based, file-upload-vulnerability, credential-harvesting, ai-generated-scripts, payment-card-theft
    countries: β€”
- [WHITE] August 2026 Threat Trend Report on APT Attacks (South Korea) (id=6abf5a5d160f0149844cd8c1, indicators=7, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: apt campaign, infostealer, powershell, lnk files, dll side-loading, south korea, spear phishing, xenorat
    countries: β€”
- [WHITE] TIKTOUK: Tracing a WordPress Credential Collection Toolkit (id=6abeceb3ed88945bc5661c7d, indicators=7, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: credential theft, wordpress, tiktouk, smtp plugin decryption, configuration exposure, aws credentials, cve-2026-63030, cve-2026-60137, rest api probing, javascript scanning
    countries: β€”
- [WHITE] Swarming Against Citrix 0-Day Exploitation (id=6abde373c68b5d048accac49, indicators=3, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: command injection, cve-2026-88771, citrixbleed, citrix netscaler, webshell, pre-disclosure attack, cve-2025-5777, rce, zero-day exploitation
    countries: β€”
- [WHITE] Caught in 4K: The Gentlemen Files (id=6ac3a6d89aeb3e3d383d6d06, indicators=2, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: double-extortion, ai-platform, mcp, ci/cd, leakned, exfiltration, ransomware, gentlemen, gitlab, raas
    countries: β€”
- [WHITE] Fake iPhone Duo preorder scam triggers DarkSword attack (id=6abbc428d397735970a34334, indicators=1, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: darksword exploit, iphone duo, safari targeting, credential stealing, fake preorder, cryptocurrency theft, social engineering, darksword, ios vulnerability
    countries: β€”
- [WHITE] RemusStealer: EtherHiding In Hidden Windows (id=6abf0d2f3741a634cbd57475, indicators=1, first_seen=2026-10-05T21:13:24.751875+00:00)
    tags: remusstealer, information stealer, credential theft, ethereum smart contracts, hidden desktops, lummastealer, blockchain c2, etherhiding
    countries: β€”
- [WHITE] Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix (id=6abb0c55e0fed2d6a1f7e51a, indicators=0, first_seen=2026-09-29T21:27:52.161464+00:00)
    tags: amos, sectoprat, social engineering, macsync, lumma stealer, canon sideloading, rat deployment, clickfix, powershell obfuscation, google sites abuse, dll sideloading, chatgpt custom gpt
    countries: β€”
- [WHITE] From BlackCat to Panda Workshop: Inside the Evolving C2 Panel Behind RATHat (id=6abaccf85f7a199ca2ad50c6, indicators=8, first_seen=2026-09-29T21:27:52.161464+00:00)
    tags: wireless debugging, android banking trojan, adb exploitation, rathat, blackcat panel, ai-powered automation, c2 infrastructure, panda workshop, maas operation
    countries: β€”
- [WHITE] NeedyMantis: Unpacking a post-compromise malware family used in targeted operations (id=6abac5fd70758a52b56cb48e, indicators=4, first_seen=2026-09-29T21:27:52.161464+00:00)
    tags: china-based threat actor, telecommunications, dll sideloading, custom file format, post-compromise, needymantis, websockets, modular framework
    countries: β€”
- [WHITE] Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests (id=6abbbd28cb7e4cac7c679e36, indicators=11, first_seen=2026-09-29T21:27:52.161464+00:00)
    tags: remcos rat, cve-2017-0199, hta execution, ole exploitation, phishing, remcos, south korea, steganography, powershell obfuscation
    countries: β€”
- [WHITE] The "VPN for X" Proxy Farm β€” Risky Plugins (id=6abb5c0df118a53bf415b0bd, indicators=31, first_seen=2026-09-29T21:27:52.161464+00:00)
    tags: traffic interception, vpn impersonation, proxy farm, chrome extensions, dynamic configuration, russian-language, browser proxy, remote control
    countries: β€”
- [WHITE] Rise of the Jev-Clones (id=6aba80800986c7309a31cc76, indicators=28, first_seen=2026-09-29T21:27:52.161464+00:00)
    tags: brand impersonation, price inflation, domain squatting, fraudulent storefronts, jev api, ai services, typesafe ai, lookalike domains
    countries: β€”
- [WHITE] VeloCloud Orchestrator Remote Access Vulnerability (id=6ab4023773b652cd342e0854, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: remote exploitation, privileged access, velocloud orchestrator, cve-2026-93952, certificate authentication bypass, active exploitation
    countries: β€”
- [WHITE] Galago Ransomware Emerges With Shared Infrastructure Ties to Panzer (id=6ab51a418ee0b2466a9da4f1, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: healthcare targeting, double extortion, tor leak site, iceland, raas, infrastructure sharing, galago, ransomware, panzer
    countries: Iceland
- [WHITE] Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware (id=6ab51a43ec94931b637c0607, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: operation conflict compass, scheduled tasks, ukraine targeting, lnk files, north korea, spear-phishing, velvetcake, powershell
    countries: Ukraine
- [WHITE] This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move (id=6ab431db415b8cd13de69a7e, indicators=10, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: closedquorum, ai models, windows malware, windows credentials, crypto, infostealer, lsass, password stealer
    countries: β€”
- [WHITE] RemotePanel and BoundSiphon: A Dual-Payload Toolkit for Persistent Access and Browser Theft (id=6ab561541d94721ef4ce040e, indicators=9, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: credential theft, persistence, hvnc, remotepanel, app-bound encryption, boundsiphon, bnb smart chain, clickfix, browser hijacking, cryptocurrency wallet
    countries: β€”
- [WHITE] The Closed Quorum: Inside the first reported autonomous AI C2 implant (id=6ab2681b40bfd39454369b4f, indicators=8, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: process injection, lsass dumping, crypto wallet, closedquorum, discord exfiltration, llm orchestration, credential theft, autonomous c2
    countries: β€”
- [WHITE] Placeholder Domains Whose Ads Serve Scams (id=6ab831882ea7368fb92b06f6, indicators=8, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: ai agents, github, placeholder domains, clickfix, malvertising, investment fraud, cloaking, scareware, affiliate fraud
    countries: β€”
- [WHITE] TASK#STOMP PowerShell Backdoor Steals Business Documents and Maintains Persistent Remote Access (id=6ab51a6bd938b813a0c50c5c, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: scheduled tasks, data exfiltration, avisloader, vbscript, task#stomp, tls bypass, powershell backdoor, velvetcake, document theft, filesystem monitoring, persistent access
    countries: β€”
- [WHITE] PureRAT and PureLogs Campaign Targeting Japanese Organizations (id=6ab69627dd56b82f3b52796d, indicators=78, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: purerat, process hollowing, stealer, japanese organizations, byovd, phishing campaign, purelogs, donut loader
    countries: Japan
- [WHITE] Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation (id=6ab15f3f1d05b3fb6ae23973, indicators=7, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: chacha20, arx cipher, string obfuscation, vidar, custom stream cipher, bytecode interpreter, virtual machine, information stealer
    countries: β€”
- [WHITE] Disposable Domains, Durable Hosting (id=6ab3c34aada48d498bcb50af, indicators=58, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: amatera, fake captcha, bulletproof hosting, blockchain c2, as202412, wacatac, clickfix, etherhiding, darkgate, trojanized installer, amadey, compromised websites, matanbuchus
    countries: β€”
- [WHITE] Kothamine malware uses Tailscale's tailcat to evade network detection (id=6ab7c5997e2556d7c00c86e6, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: windows, npm packages, tailscale, encrypted c2, stealer, remote access trojan, kothamine agent, tailcat, kothamine
    countries: β€”
- [WHITE] New RemControl Android Banking Trojan Steals PINs Using AI-Built Phishing Overlays (id=6ab51a6d40cabb350f8e954b, indicators=0, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: android trojan, ai-assisted development, phishing overlays, websocket c2, accessibility service abuse, banking credentials, maas, remcontrol, tvtap
    countries: Canada, Italy
- [WHITE] The Psychedelic Stealer: When a CAPTCHA Becomes an Installer (id=6ab68af3aecfcfc39b2824d8, indicators=6, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: psychedelic, infostealer, windows run, msi package, fake captcha, clipboard
    countries: Ukraine, United States of America
- [WHITE] Lunex Unmasked: A New Information Stealer Deployed Through BYOVD (id=6ab83188fddeab6ca23aeafc, indicators=52, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: browser-hijacking, cve-2023-20598, ukrainian-targeting, pdfwkrnl, byovd, lunexstealer, information-stealer, credential-theft, native-messaging-host, lunexloader, cryptocurrency-wallet, lunex, kernel-driver-abuse
    countries: β€”
- [WHITE] The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint (id=6ab561550075cd5f0b500b25, indicators=6, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: c3pool, cryptominer, on-endpoint compilation, silentxmrminer, monero, cve-2024-7399, cve-2025-4632, anydesk, samsung magicinfo
    countries: β€”
- [WHITE] OpenSUpdater Hides in Recompiled 7zip SFX, Evading Analysts (id=6ab524f82bf3c05dfa346cb8, indicators=5, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: 7zip sfx, nsis, opensupdater, evasion techniques, snackarcin, reflective loader, code signing abuse, certificate bloating
    countries: β€”
- [WHITE] North Korea's Hangro Revisited (id=6ab15e0fe200afb0f82b8895, indicators=47, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: silibank, mail relay systems, north korea networks, hangro, vpn infrastructure, cross-border infrastructure, softether, certificate hierarchy
    countries: β€”
- [WHITE] A new version of the MacSync macOS stealer targets crypto enthusiasts and developers (id=6ab5176a22ab1049d0969c4a, indicators=45, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: macsync, amos, pam stealer, social engineering, macos stealer, icloud abuse, infostealer, developer targeting, cryptocurrency theft, backdoor module
    countries: β€”
- [WHITE] third-party.com Placeholder Domain Now Serves ClickFix (id=6ab559662b978ca478cf0b21, indicators=5, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: clipboard poisoning, social engineering, powershell, fake captcha, third-party.com, placeholder domain, clickfix, windows targeting
    countries: β€”
- [WHITE] Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline (id=6aba46a30e26418fb09c6000, indicators=28, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: globalprotect exploitation, cve-2026-0257, cve-2024-1086, multi-tenant phishing, cve-2022-40684, adaptixc2, invoice fraud platform, cve-2022-28368, oauth device-code phishing, dns tunneling, cve-2020-1938, cve-2021-36260, energy sector targeting, pix payment fraud, cve-2023-7028, cve-2021-4034
    countries: United States of America, Argentina, Belgium, Brazil, Canada, Costa Rica, El Salvador, France, Guatemala, Italy, Mexico, Netherlands, Norway, Qatar, Spain, United Kingdom of Great Britain and Northern Ireland
- [WHITE] RemControl: AI Built the Overlays. Victims Lose their PINs (id=6ab3c7511ba65533d7e207ce, indicators=28, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: unkk threat actor, android banking trojan, malware-as-a-service, screen streaming, accessibility service abuse, medusa, remcontrol, overlay injection, telegram dead-drop
    countries: Canada, France, Italy, Poland, Portugal, Spain
- [WHITE] Uncovering a SectopRAT Variant Embedded in Legitimate Software (id=6ab688467ce23517fb31e378, indicators=23, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: sectoprat, rat, infostealer, embedding, crypto
    countries: β€”
- [WHITE] DarkMe RAT: A VB6 APT Trojan Turned Conventional Infostealer (id=6ab326f4234e22940c7fb969, indicators=23, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: darkme, phishing campaign, process hollowing, social engineering, visual basic 6, financial targeting, rat, cryptocurrency theft
    countries: β€”
- [WHITE] Major vulnerability found in ancient TACACS+ networking protocol (id=6ab61e2ec525754334a6ed2d, indicators=4, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: chinese cyber-espionage, persistence, lateral movement, pre-authentication, remote code execution, tacacs+, telecommunications targeting, networking protocol
    countries: β€”
- [WHITE] Telerik UI Exploitation Leads to Webshell Install and Scanner Execution (id=6aba1398c736673eae22c865, indicators=21, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: cve-2019-18935, telerik ui, godzilla, iis server, reverse shell, privilege escalation, wordpress scanner, web shell, sweetpotato
    countries: United States of America
- [WHITE] AI Security Incident Case: Trusted AI Platforms Become a New Channel for Malware Distribution (id=6ab22dd5026bef69ef5a17fd, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: lateral-movement, attack-campaigns, data-exfiltration, cybersecurity, credential-harvesting, supply-chain, threat-intelligence, vulnerability-exploitation
    countries: β€”
- [WHITE] Equation of Compromise: Anatomy of a Live npm Supply-Chain Campaign (id=6ab22e89f1e0c549443c6917, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: encrypted loader, blockchain infrastructure, defi developers, npm supply-chain, cryptocurrency targeting, download inflation, github actions abuse, smart contract c2
    countries: β€”
- [WHITE] Meet AvisLoader: A Windows Loader Built to Outlast a Takedown (id=6ab40d6887e7e948c6a09d80, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: uac bypass, loader, clickfix, persistence, p2p c2, tox, cloudflare, shortcut modification, avisloader
    countries: β€”
- [WHITE] CARBONATO: a botnet built around an AI agent (id=6ab4d79db2222977d275954f, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: cryptocurrency, credential theft, telegram, botnet, ai framework, carbonato, docker, hermes agent, container security, exposed daemon
    countries: β€”
- [WHITE] Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation (id=6ab2691621023818faaf620e, indicators=17, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: cve-2026-60004, government breach, cve-2022-0847, cve-2023-54391, cve-2026-34909, cve-2026-60137, cve-2026-7273, kapibala, cve-2026-63030, cve-2026-34910, zyxel switches, privilege escalation, data exfiltration, cve-2026-79756, cve-2026-54569, chinese-speaking actor, cve-2026-34908, cve-2026-56271, wordpress exploitation
    countries: United States of America, Albania, Australia, Austria, Belarus, Belgium, Brazil, British Indian Ocean Territory, Bulgaria, Chile, China, Colombia, Costa Rica, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Guadeloupe, Hong Kong, Hungary, Iceland, India, Iran, Islamic Republic of, Ireland, Italy, Japan, Latvia, Lithuania, Madagascar, Malaysia, Malta, Martinique, Monaco, Mongolia, Netherlands, Norway, Pakistan, Panama, Philippines, Poland, Portugal, Romania, Russian Federation, Slovakia, Slovenia, South Africa, Spain, Sweden, Switzerland, Taiwan, Thailand, Ukraine, United Arab Emirates, United Kingdom of Great Britain and Northern Ireland, Uzbekistan
- [WHITE] Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits (id=6ab3c34b893b396be1b1aedb, indicators=17, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: uta0565, cve-2026-85880, zero-day exploitation, chrome vulnerabilities, cleangulp, cve-2026-87491, chinese apt, windows privilege escalation, phishing campaigns, cve-2026-85046, domain spoofing
    countries: β€”
- [WHITE] The Stealer Factory: Unpacking a Python-Based MaaS Infostealer Builder (id=6aba46a2a513094d63bf1bd1, indicators=3, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: browser-data-extraction, anti-vm, python-based, webhook-exfiltration, nuitka, credential-theft, maas, infostealer, pyinstaller
    countries: β€”
- [WHITE] Trust and the enticing consultancy offer (id=6ab59fabb977cbc4847b4dd1, indicators=14, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: trust exploitation, trojanised software, rapuncel, confidence trick, social engineering, access abuse, closedquorum, professional targeting, fake recruiters, fake consultancy
    countries: β€”
- [WHITE] The Tale of Two INC Ransom Notes: A Ransomware Timeline (id=6ab15cd97e805a1f35130341, indicators=2, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: anydesk, initial access broker, inc, double extortion, lateral movement, scheduled tasks, byovd attack, impacket, inc ransomware
    countries: β€”
- [WHITE] ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft (id=6ab77878ad1bbe2993309a09, indicators=12, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: shinyhunters, cve-2026-35273, oracle peoplesoft, unc6240, neo-regeorg, waf bypass, sideeye backdoor, data extortion, meshagent, web shells, sideeye
    countries: β€”
- [WHITE] August 2026 Infostealer Trend Report (id=6ab27eff37df954a32a9fa29, indicators=12, first_seen=2026-09-29T01:41:31.52697+00:00)
    tags: email distribution, lummac2, infostealer, dll side-loading, vidar, agenttesla, remus, acrstealer, formbook, seo poisoning
    countries: British Indian Ocean Territory, India

      ## What to produce
      Write a 250-400-word brief with:
      1. **Headline** (one sentence on the week's most notable signal).
      2. **Emerging threats** (3-5 bullets on the new pulses β€” group by theme: ransomware,
         phishing, APT, supply chain, etc. β€” and cite pulse names).
      3. **Corpus-level shifts** (1-3 bullets on changes from the stable picture: a
         newly-targeted country, a TLP-distribution shift, a tag spike).
      4. **Analyst caveats** (1-2 bullets on what this data can NOT tell us:
         attribution confidence, victim impact, dwell time, sampling bias from OTX
         subscriptions).

      Use markdown. Do not invent indicators, pulse names, or numbers β€” work strictly
      from what's above.