Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Microsoft Threat Intelligence

Microsoft Threat Intelligence Vendor Cyber Rating & Cyber Score

aka.ms

The Microsoft Threat Intelligence community is made up of more than 10,000 world-class experts, security researchers, analysts, and threat hunters analyzing 78 trillion signals daily to discover threats and deliver timely and hyper-relevant insight to protect customers. Our research covers a broad spectrum of threats, including threat actors and the infrastructure that enables them, as well as the tools and techniques they use in their attacks.


MTI A.I CyberSecurity Scoring

MTI
Company Information
Website:https://aka.ms/threatintelblog
Employees number:None
Number of followers:128,397
NAICS:541514
Industry Type:Computer and Network Security
Homepage:aka.ms
MTI Risk Score (AI oriented)
Between 0 and 549
logo
MTIComputer and Network Security
Updated:
21/09/2026
159/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
MTI Global Score (TPRM)
xxxx
logo
MTIComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MTICritical
Current Score
159C (CRITICAL)
01000
30 incidents
-28.17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
148Before Incident
AUGUST 2026
154Before Incident
Cyber Attack
11 Aug 2026 • MTI
Microsoft: DeadLock Ransomware Hides C2 on Polygon Blockchain, 80-Plus Victims Hit

DeadLock Ransomware Pioneers Blockchain-Based Command-and-Control in Large-Scale Extortion Campaign

136After Incident
CRITICAL-18
MIC1786568300
DeadLock Ransomware Pioneers Blockchain-Based Command-and-Control in Large-Scale Extortion Campaign A ransomware group known as DeadLock has breached over 80 organizations across four continents since July 2025, deploying a novel tactic that sets it apart from other financially motivated threat actors: command-and-control (C2) infrastructure built on the Polygon blockchain. Microsoft Threat Intelligence detailed the group’s operations in an August 10 report, revealing a sophisticated extortion framework that leverages smart contracts, decentralized messaging, and cloud storage to evade traditional law enforcement takedowns. ### A Censorship-Resistant Extortion Machine Unlike conventional ransomware groups that rely on dark-web leak sites vulnerable to seizures or hosting provider interventions DeadLock’s infrastructure is effectively immune to disruption. Its core components include: - Two Polygon smart contracts: One stores the current proxy server URL, while the other hosts the group’s blog posts and stolen data listings. - Decentralized Session messaging: Victims communicate with operators via an onion-routed network, eliminating the need for centralized servers. - Wasabi cloud storage: Stolen files are stored off-chain, with download links generated on demand via blockchain-stored metadata. When an infected machine checks in, it queries public Polygon RPC endpoints to retrieve the latest proxy address no transactions, fees, or wallets required. Operators can rotate proxy servers by updating the smart contract, ensuring continuity even if individual components are disrupted. This technique, dubbed EtherHiding, was previously observed in North Korean-linked operations and the Aeternum botnet, but DeadLock is the first ransomware group to deploy it at scale in a double-extortion campaign. ### Unbreakable Encryption and Stealthy Execution DeadLock’s Rust-based encryptor employs a three-layer hybrid cryptographic scheme designed to eliminate recovery options: - Per-file ephemeral Curve25519 keypairs: Each file generates a unique shared secret via elliptic-curve Diffie-Hellman, wrapped with XChaCha20 and Poly1305 for authenticated encryption. - Tiered encryption: Files under 50 MB are fully encrypted, while larger files are chunk-encrypted (e.g., 10% of a 1 GB file), rendering them unusable without significantly increasing detection risk. - Resource-aware throttling: Encryption pauses if CPU load exceeds 70% or memory use hits 29%, avoiding performance spikes that might trigger behavioral alerts. Before encryption begins, DeadLock systematically disables defenses: - Language-based exclusion: Self-deletes if the system language matches Russian, Ukrainian, CIS regions, or select Middle Eastern countries a pattern linked to operators avoiding local legal exposure. - Service termination: Kills Windows Defender, Volume Shadow Copy, Hyper-V, Active Directory, and cloud sync clients (OneDrive, Dropbox, Google Drive). - BYOVD (Bring Your Own Vulnerable Driver): Exploits CVE-2024-51324 in a signed Baidu Antivirus driver to gain kernel-level access, terminating EDR processes before they can respond. - Event log destruction: Clears Windows logs, disables future logging, and restricts access permissions, leaving minimal forensic evidence. ### Interactive Extortion via Blockchain and Decentralized Messaging After encryption, victims receive: - A ransom note (HOW_RECOVER.<UID>.txt) in every encrypted directory. - A self-contained HTML application (RECOVERY_CHAT.<UID>.html) that functions as a browser-based negotiation portal, requiring no server. The Chat tab generates a Session messenger identity from victim credentials, enabling onion-routed communication with operators. The Blog tab fetches data-leak posts directly from the Polygon smart contract, allowing victims to browse stolen files via pre-signed Wasabi download URLs. ### Targets and Operational Scale DeadLock has impacted organizations in IT, mining, transportation, manufacturing, hospitality, and consumer goods, with over half of its 80+ victims in Europe and the remainder across Asia, the Americas, and Africa. The group operated quietly for 11 months before accelerating in June 2026, posting 75 new victims a pace rivaling established ransomware-as-a-service (RaaS) programs. Microsoft observed affiliates from the Lynx and INC ecosystems deploying DeadLock, suggesting a partial RaaS model. ### The Future of Blockchain-Based Ransomware Security firm ReliaQuest warned in its July 2026 quarterly report that blockchain-based C2 is likely to spread before year’s end, citing Cry0 ransomware’s adoption of the Internet Computer Protocol (ICP) blockchain for negotiations. The low technical barrier requiring only a smart contract and ~$1 in cryptocurrency means other groups may replicate DeadLock’s approach. For defenders, monitoring outbound Polygon RPC traffic (e.g., to polygon-rpc.com, drpc.org) and Session messenger activity from enterprise endpoints could help detect similar threats. Microsoft’s mitigation recommendations include: - Enabling tamper protection in Defender Antivirus. - Running EDR in block mode to counter post-compromise telemetry loss. - Enforcing Microsoft’s vulnerable-driver block list via Windows Defender Application Control (WDAC) with HVCI to block BYOVD attacks. - Maintaining offline, immutable backups the only reliable recovery method against DeadLock’s encryption. DeadLock’s SHA-256 encryptor hash (a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4) and leak site domains (deadlock.liveblog365[.]com, dlock.liveblog365[.]com, deadlockblog.great-site[.]net) serve as key indicators of compromise. Encrypted files are appended with the .dlock extension.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (double-extortion campaign)
IMPACT
Data Compromised: Stolen files stored in Wasabi cloud storage, downloadable via blockchain-stored metadataSystems Affected: Windows systems with disabled defenses (Windows Defender, Volume Shadow Copy, Hyper-V, Active Directory, cloud sync clients)Operational Impact: Encryption of files, termination of critical services, destruction of event logsBrand Reputation Impact: High (public data leaks via blockchain-based blog)Identity Theft Risk: High (personally identifiable information exposed in data leaks)
DATA BREACH
Type Of Data Compromised: Stolen files (sensitive corporate data)Sensitivity Of Data: High (personally identifiable information, corporate secrets)
JULY 2026
144Before Incident
Vulnerability
18 Jul 2026 • MTI
Microsoft, Novo Nordisk and NSW Rural Fire Service: The Gentlemen Ransomware Tops Qilin: 94 Victims [2026]

June 2026 Ransomware Surge: The Gentlemen Dethrone Qilin in a Fragmented Threat Landscape

141After Incident
CRITICAL-3
MICNOVBRU1784427884
June 2026 Ransomware Surge: The Gentlemen Dethrone Qilin in a Fragmented Threat Landscape In June 2026, the ransomware ecosystem saw a dramatic shift as The Gentlemen, a previously obscure group, claimed 94 victims enough to unseat Qilin from its five-month reign as the most active ransomware operation. The shakeup reflects a broader trend: a 9% month-over-month increase in ransomware attacks, with 707 victims across 87 countries, according to tracking firm Breachsense. ### A Volatile Leaderboard The top three groups in June accounted for over a third of all attacks, underscoring how a small number of well-resourced affiliate crews can rapidly reshape the threat landscape: - 1st: The Gentlemen (94 victims) – A newcomer that surged to the top in its first major tracked month. - 2nd: DeadLock (81 victims) – Another new entrant, debuting at second place, likely absorbing affiliates from disbanded operations. - 3rd: Qilin (71 victims) – Dropped after a five-month dominance, though still a major player. This churn is typical of the ransomware-as-a-service (RaaS) model, where groups rebrand, dissolve, or lose affiliates to rivals almost overnight. The rapid rise of The Gentlemen and DeadLock suggests they may have poached affiliates from established crews by offering better payouts or infrastructure. ### Key Incidents and Targets June’s attacks highlighted ransomware’s focus on high-value data and critical infrastructure: - FulcrumSec demanded $25 million from Novo Nordisk, stealing 1.3 TB of clinical trial data and AI models a prime target for resale or secondary extortion. - Nova targeted Australia’s NSW Rural Fire Service, exfiltrating 300 GB of sensitive data, demonstrating ransomware’s persistent threat to public-sector organizations. - Unpatched vulnerabilities remained the primary entry point, with CVE-2026-20230 (Cisco Unified CM) and CVE-2026-41089 (Windows Netlogon) exploited to gain initial access. ### Payment Rates Decline, Extortion Tactics Evolve Despite the surge in attacks, 69% of victims refused to pay in 2026 a trend driven by better backups, stricter cyber insurance policies, and law enforcement discouragement. This has pushed gangs toward data-theft-only extortion, where stolen data (rather than encryption) is the primary leverage. ### Regulatory and Market Impact The 9% rise in attacks and ransomware’s 48% share of all breaches (per Verizon’s 2026 DBIR) are pressuring cyber insurance underwriters to tighten requirements, while security teams must adapt to rapidly shifting threat groups. The fragmented RaaS market where new groups can dominate within weeks means defenders must focus on behavior-based detection rather than tracking specific gangs. ### Outlook for 2026 The rest of the year is expected to see: - Further leaderboard churn, with new groups likely cracking the top three. - Continued decline in payment rates, accelerating the shift to data-theft extortion. - Persistent exploitation of unpatched edge devices, keeping patch management a critical priority. - Faster disclosures due to stricter regulatory reporting, making monthly victim counts appear more volatile. June’s surge is less an anomaly than a continuation of the post-2024 ransomware landscape, where no group stays on top for long, affiliates move quickly, and defenders must prioritize fundamental security controls over chasing the latest threat actor.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortionSecondary extortion
IMPACT
1.3 TB of clinical trial data and AI models (Novo Nordisk)300 GB of sensitive data (NSW Rural Fire Service)Brand Reputation Impact: High
DATA BREACH
Clinical trial dataAI modelsSensitive operational dataSensitivity Of Data: HighData Exfiltration: YesData Encryption: Partial (ransomware cases)
JULY 2026
161Before Incident
Cyber Attack
14 Jul 2026 • MTI
AsyncAPI and Microsoft: AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials

AsyncAPI npm Supply Chain Attack Exposes Developers to Credential Theft

143After Incident
CRITICAL-18
ASYMIC1785327908
AsyncAPI npm Supply Chain Attack Exposes Developers to Credential Theft On July 14, 2026, attackers executed a supply chain compromise targeting the AsyncAPI project on the npm registry, publishing five malicious package versions within a 90-minute window. The attack bypassed traditional security measures by embedding malware that activates upon module import, rather than relying on install scripts rendering the `ignore-scripts` safety setting ineffective. ### Attack Mechanics & Impact The malware, identified by Microsoft, delivered a modular runtime called Miasma, capable of persistence, remote command execution, and credential theft. While some harvesting modules were dormant in the analyzed sample, the framework included encrypted logic that could be activated later via remote updates. The compromised packages @asyncapi/specs, @asyncapi/generator, generator-components, and generator-helpers were distributed through legitimate npm publishing workflows, leveraging a misconfigured GitHub Actions workflow that exposed a privileged bot token. This allowed attackers to push poisoned commits under a valid npm identity, expanding the attack’s reach to developer laptops, CI/CD pipelines, containers, and production services. ### Credential Theft Capabilities Miasma targeted over 100 environment variables and files, including: - Source control tokens (GitHub, GitLab, npm, Node.js auth tokens) - Cloud credentials (AWS, Azure, Google Cloud) - AI platform keys (Anthropic, OpenAI) - Container & orchestration tokens (Docker, Kubernetes) - Secret management files (.npmrc, AWS credentials, kubeconfig, Vault tokens, SSH keys) When a GitHub token was detected, the malware could enumerate repositories and CI context via public APIs, mirroring tactics from prior npm-based credential theft campaigns. ### Persistence & Command Channels The attack chain involved: 1. Initial compromise via a malicious pull request exploiting a misconfigured GitHub Actions workflow. 2. Poisoned package releases published through AsyncAPI’s trusted pipeline. 3. Hidden Node process execution upon package import, fetching an encrypted second-stage payload from IPFS. 4. Installation of `sync.js` in OS-specific NodeJS directories (Windows, macOS, Linux). 5. C2 communication via 85.137.53[.]71 (ports 8080, 8081, 8091) and decentralized fallback networks. ### Indicators of Compromise (IoCs) Compromised Packages & Hashes: - `@asyncapi/[email protected]` (SHA-256: `d425e4583cc6185d41e95c45eda00550045a5d1919b9a012236a4520d009dbd7`) - `@asyncapi/[email protected]` (SHA-256: `9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b`) - `@asyncapi/[email protected]` (SHA-256: `bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4`) - `@asyncapi/[email protected]` (SHA-256: `082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab`) - `@asyncapi/[email protected]` (SHA-256: `34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeafff236e2f6db8ad1`) Second-Stage Payloads: - IPFS CIDs: `Qmet4fhsAaWMBUxNDfREHwgiyDeSWy4YSYs9wiKUW5jGyf` (generator-family), `QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9` (specs) - Drop paths: `%LOCALAPPDATA%\NodeJS\sync.js` (Windows), `~/.local/share/NodeJS/sync.js` (Linux), `~/Library/Application Support/NodeJS/sync.js` (macOS) C2 Infrastructure: - Primary IP: `85.137.53[.]71` (ports 8080, 8081, 8091) - Publisher identity: `npm-oidc-no-reply@github[.]com` ### Mitigation Steps (For Reference) Teams were advised to: - Remove compromised versions and purge npm/Yarn caches. - Rotate all exposed secrets (cloud keys, tokens, API credentials). - Hunt for `sync.js` in NodeJS directories and detached Node processes. - Pin known-good versions, rebuild from clean lockfiles, and block malicious IPFS CIDs. - Update npm CLI and review GitHub Actions token scopes to prevent recurrence.
INCIDENT DETAILS -
TYPE
Supply Chain Compromise
MOTIVATION
Credential theft, data exfiltration
IMPACT
Data Compromised: Source control tokens, cloud credentials, AI platform keys, container & orchestration tokens, secret management filesSystems Affected: Developer laptops, CI/CD pipelines, containers, production servicesOperational Impact: Potential unauthorized access to repositories, CI/CD pipelines, and cloud environmentsBrand Reputation Impact: High (trusted npm packages compromised)Identity Theft Risk: High (PII and credentials exposed)
DATA BREACH
Source control tokensCloud credentialsAI platform keysContainer & orchestration tokensSecret management filesSensitivity Of Data: High (authentication tokens, API keys, SSH keys)Data Exfiltration: Yes (via C2 communication)Data Encryption: Yes (encrypted second-stage payload).npmrcAWS credentialskubeconfigVault tokensSSH keys
JULY 2026
177Before Incident
Cyber Attack
09 Jul 2026 • MTI
Microsoft: GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

GigaWiper: A Modular Backdoor with Destructive Capabilities Emerges in 2025

159After Incident
CRITICAL-18
MIC1783680524
GigaWiper: A Modular Backdoor with Destructive Capabilities Emerges in 2025 In October 2025, Microsoft Threat Intelligence uncovered GigaWiper, a sophisticated Golang-based backdoor that integrates multiple destructive payloads into a single, modular implant. Unlike traditional wipers designed solely for data destruction GigaWiper combines disk wiping, fake ransomware, and system sabotage with robust command-and-control (C2) functionality, offering threat actors unprecedented flexibility in their attacks. ### Key Features of GigaWiper GigaWiper is not a standalone tool but an amalgamation of at least three distinct malware families, repurposed as on-demand commands within a unified backdoor. Its destructive capabilities include: 1. Physical Disk Wiping - Operates at the raw disk level, overwriting partition metadata and disk content. - Uses multi-pass secure wiping (zeros, `0xFF`, random bytes) to evade detection. - Targets all drives except the Windows installation disk (unless specified). 2. Fake Ransomware (Crucio-Based) - Encrypts files with randomly generated AES keys that are never saved, making decryption impossible. - Drops a hard-coded wallpaper (`image_danger.jpg`) but no ransom note, confirming its true intent is destruction, not extortion. - Excludes critical system files (`.exe`, `.dll`) to ensure the system remains bootable until further sabotage. 3. System-Level Sabotage - Triggers Blue Screen of Death (BSOD) by corrupting boot and kernel files. - Clears Windows event logs, including Security logs, to erase forensic evidence. - Disables recovery options, preventing system restoration. ### Backdoor Functionality & Persistence Beyond destruction, GigaWiper functions as a full-featured backdoor, enabling: - Persistence via Scheduled Tasks - Creates a task named "OneDrive Update" that runs every minute and on startup. - Uses a registry key (`HKCU\SOFTWARE\OneDrive\Environment`) to track execution count. - Dual C2 Communication Channels - RabbitMQ (AMQP) for receiving commands. - Redis for uploading command outputs and status updates. - Hard-coded C2 servers (e.g., `185.182.193[.]21:5544`) with AES-encrypted configurations. - 20+ Command Capabilities GigaWiper supports a wide range of operations, including: - File encryption/decryption (AES-256-CBC, with optional key storage). - Screen capture & recording (saves to `C:\ProgramData\output`). - Process & service management (kill, suspend, resume, list). - Registry manipulation (interactive session-like control). - Remote VNC-like control (TCP-based keyboard/mouse input and screen streaming). - MinIO file exfiltration (uploads files to attacker-controlled storage). ### Origins & Code Reuse Microsoft’s analysis reveals GigaWiper’s modular design stems from the reimplementation of older malware families: - Command 3 (Fake Ransomware) derives from Crucio ransomware (CISA-documented in 2023). - Command 12 (Secure Wiping) is a Golang port of FlockWiper, a C-based wiper first seen in June 2025. - "GRAT" references in FlockWiper’s PDB paths (`A:\GRAT\CWipeNew\Release\CWipeNew.pdb`) and GigaWiper’s function names suggest a shared development framework. ### Impact & Evolution of Wiper Malware GigaWiper represents a significant shift in wiper malware, moving from single-purpose destruction tools to multi-functional backdoors that enable: - Espionage (screen recording, keylogging, data exfiltration). - Lateral movement (process/service manipulation, registry control). - On-demand destruction (wiping, BSOD, fake ransomware). Its modular architecture reduces the attacker’s deployment footprint while expanding destructive potential, making it a highly efficient tool for both cybercrime and nation-state actors. ### Indicators of Compromise (IOCs) Microsoft has released the following SHA-256 hashes and C2 IPs for detection: - GigaWiper Backdoor: - `633d4cbd496b1094495da89a64f5e6c31a0f6d4d1488411db5b0cba1cfe42001` - `ce9ad5f6c12019f4aae5b189bd8ddf5bb09e75b06a0a587b25a855c65948c913` - Standalone Wiper: - `3c30deb6556a94cfb84ae51798f4aecfae8c7358e55fdb321c5f2376579631cd` - Crucio Ransomware: - `440b5385d3838e3f6bc21220caa83b65cd5f3618daea676f271c3671650ce9a3` - FlockWiper: - `12c39f052f030a77c0cd531df86ad3477f46d1287b8b98b625d1dcf89385d721` - C2 Infrastructure: - `185.182.193[.]21` (RabbitMQ/Redis) - `212.8.248[.]104` GigaWiper underscores the growing convergence of espionage and destructive malware, where backdoors are no longer just for surveillance but also for maximizing operational impact whether through data theft, system disruption, or irreversible destruction.
INCIDENT DETAILS -
TYPE
BackdoorWiperFake Ransomware
MOTIVATION
Data DestructionEspionageSystem Sabotage
IMPACT
Windows systemsDowntime: Irreversible system disruption (BSOD, disk wiping)Operational Impact: Permanent data loss, system inoperability
DATA BREACH
Screen capturesProcess/service dataRegistry dataFile exfiltration via MinIOSensitivity Of Data: High (potential PII, operational data)AES-encrypted filesSystem logsScreen recordings
JUNE 2026
183Before Incident
Cyber Attack
17 Jun 2026 • MTI
Microsoft: Hackers Use Fake Software Update Prompts to Steal Passwords and Crypto Wallet Data From macOS Users

North Korean Threat Actor Sapphire Sleet Targets macOS Users in Sophisticated Social Engineering Campaign

166After Incident
CRITICAL-17
MIC1781713463
North Korean Threat Actor Sapphire Sleet Targets macOS Users in Sophisticated Social Engineering Campaign A newly uncovered cyber campaign by Sapphire Sleet, a North Korean state-backed threat group active since at least March 2020, is targeting macOS users particularly those in cryptocurrency, venture capital, and blockchain sectors through a social engineering-driven attack chain that bypasses traditional software vulnerabilities. The campaign, first detected in early 2026, leverages deceptive recruitment lures to trick victims into executing malicious files. Attackers pose as job recruiters on social media or professional platforms, directing targets to download a file disguised as a Zoom SDK or Microsoft Teams update. Once opened, the file typically a compiled AppleScript launches in macOS Script Editor, initiating a multi-stage infection process without raising suspicion. ### How the Attack Unfolds 1. Initial Compromise: Victims are convinced to run a script (e.g., Zoom SDK Update.scpt or msteams sdk update.scpt), which silently fetches additional malicious payloads. 2. Credential Harvesting: A fake application (systemupdate.app) displays a native-looking macOS password prompt, tricking users into entering their credentials. If verified, the password is exfiltrated via Telegram. 3. Data Theft & Persistence: A second decoy app (softwareupdate.app) mimics a completed update while the malware steals cryptocurrency wallets, browser passwords, SSH keys, Telegram sessions, and browsing history. Stolen data is compressed and sent to attacker-controlled servers over port 8443. 4. Backdoor Installation: The malware deploys multiple persistent backdoors, including: - com.apple.cli: A host monitoring tool communicating over port 6783. - icloudz: A memory-resident backdoor loaded via ~/Library/Application Support/iCloud/icloudz, evading disk-based detection. - A launch daemon (com.google.webkit.service.plist) ensuring the backdoor restarts after reboots. ### Evolving Tactics In June 2026, Sapphire Sleet introduced a Microsoft Teams-themed variant, using updated payload names (e.g., com.microsoft.helper, .google.docs) while maintaining the same attack chain. The group’s infrastructure includes multiple C2 servers (e.g., 83.136.208[.]246, 188.227.196[.]252) and domains (e.g., uw04webzoom[.]us, check02id[.]com). ### Defensive Measures & Indicators of Compromise (IoCs) Microsoft’s report, shared with Cyber Security News (CSN), prompted Apple to deploy countermeasures, including XProtect signature updates and Safari Safe Browsing blocks. Key IoCs include: - IPs: 83.136.208[.]246, 188.227.196[.]252, 104.145.210[.]107 - Domains: uw04webzoom[.]us, check02id[.]com - Files: Zoom SDK Update.scpt, systemupdate.app, com.apple.cli, icloudz - Persistence Paths: /Library/LaunchDaemons/com.google.webkit.service.plist, ~/Library/LaunchAgents/com.apple.identification.plist The campaign underscores Sapphire Sleet’s focus on high-value financial targets, combining social engineering with macOS-specific evasion techniques to steal credentials and maintain long-term access.
INCIDENT DETAILS -
TYPE
Social Engineering, Malware, Credential Theft, Data Exfiltration
MOTIVATION
Financial Gain, Data Theft, Espionage
IMPACT
Data Compromised: Cryptocurrency wallets, browser passwords, SSH keys, Telegram sessions, browsing historySystems Affected: macOS systemsOperational Impact: Persistent backdoor access, unauthorized data exfiltrationIdentity Theft Risk: High (PII and credentials stolen)Payment Information Risk: High (cryptocurrency wallets targeted)
DATA BREACH
CredentialsCryptocurrency walletsBrowser dataSSH keysTelegram sessionsBrowsing historySensitivity Of Data: HighData Exfiltration: Yes (via Telegram and attacker-controlled servers on port 8443)Personally Identifiable Information: Yes (credentials, browsing history)
JUNE 2026
195Before Incident
Cyber Attack
03 Jun 2026 • MTI
Microsoft and Israeli organization: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

HollowGraph: Espionage Malware Hijacks Microsoft 365 Calendars for Stealthy C2 Operations

177After Incident
HIGH-18
MICISR1784565175
HollowGraph: Espionage Malware Hijacks Microsoft 365 Calendars for Stealthy C2 Operations Security researchers at Group-IB have uncovered a novel espionage implant, HollowGraph, which leverages a compromised Microsoft 365 calendar as a command-and-control (C2) channel. The malware, a .NET DLL, evades detection by embedding operator instructions and exfiltrating stolen data via calendar events dated to 2050, ensuring they remain hidden from typical user activity. ### How HollowGraph Operates HollowGraph exploits the Microsoft Graph API to blend malicious traffic with legitimate Microsoft 365 communications. Instead of connecting to an attacker-controlled server, it uses the victim’s mailbox calendar as a dead drop: - Tasking retrieval: Queries a pre-planted event (dated 2050-05-13) to extract instructions from an attached file. - Data exfiltration: Encrypts stolen files, creates a new far-future event, and uploads the data as attachments. - Encryption: Uses hybrid RSA and AES-256, with separate key pairs for incoming and outgoing traffic. A secondary channel maintains persistence via DNS queries to the attacker domain cloudlanecdn[.]com, refreshing Entra ID (Azure AD) credentials (tenant ID, client ID, client secret) stored in a disguised log file (logAzure.txt). ### Attribution & Campaign Scope Group-IB links HollowGraph to Cavern, a modular backdoor framework recently documented by Check Point and attributed to Cavern Manticore, an Iranian threat actor with ties to MuddyWater and Lyceum. However, Group-IB stops short of definitive attribution, citing only a low-confidence overlap with Lyceum (an OilRig subgroup). The campaign targeted at least 12 machines, with active communication observed between June 3 and July 9, 2026. Victims included an Israeli organization, though Group-IB treats this as geographic targeting rather than a definitive link to the attacker. The limited footprint suggests targeted espionage, though the technique could be repurposed for broader attacks. ### Detection & Defense Challenges HollowGraph exploits legitimate Microsoft 365 functionality, requiring no software vulnerabilities only a compromised account and Graph API access. Key detection indicators include: - Calendar anomalies: Events with 2050-05-13 dates, GUID-based subjects (e.g., Event ID:, Boss{..}ID{..}), or attachments named File{n}.txt. - Identity risks: Unusual OAuth app permissions, newly created client secrets, or anomalous Entra ID token activity. - DNS red flags: Frequent AAAA queries to cloudlanecdn[.]com or high-entropy subdomains. ### Broader Implications This attack underscores the growing trend of abusing trusted cloud services for C2 operations. While previous campaigns have exploited Outlook drafts and OneDrive, HollowGraph’s use of far-future calendar events demonstrates a new evasion tactic. With victim traffic active as recently as July 2026, defenders are advised to scrutinize unusual calendar activity even in the distant future.
INCIDENT DETAILS -
TYPE
Espionage
MOTIVATION
Espionage
IMPACT
Data Compromised: Stolen files, Entra ID credentialsSystems Affected: Microsoft 365 calendars, Entra ID (Azure AD)Operational Impact: Data exfiltration, unauthorized accessIdentity Theft Risk: High (PII and credentials compromised)
DATA BREACH
Stolen filesEntra ID credentialsSensitivity Of Data: High (PII, credentials)Data Encryption: Hybrid RSA and AES-256
JUNE 2026
372Before Incident
Ransomware
01 Jun 2026 • MTI
Microsoft: Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

New Windows RAT 'SloppyRAT' Emerges as Ransomware Enabler

195After Incident
CRITICAL-177
MIC1789115702
New Windows RAT "SloppyRAT" Emerges as Ransomware Enabler A recently identified Windows remote-access trojan (RAT), dubbed SloppyRAT, has been observed in the wild as a tool for ransomware operations. First detected in June 2026, the malware employs a multi-stage ClickFix infection chain to evade detection while enabling post-compromise activity, lateral movement, and reverse proxying. ### Infection Chain & Execution SloppyRAT avoids traditional executable drops by abusing the legacy finger.exe utility (TCP port 79) to fetch a batch script from an attacker-controlled server. The script then: - Copies curl.exe to the user’s AppData directory under a numeric .com filename. - Downloads IronPython from GitHub to execute a compressed, Base64-encoded Python payload. - Retrieves CastleLoader and CastleRAT components from skipraid[.]com using the K8VGmQTrzX User-Agent string tools previously linked to deceptive delivery campaigns and remote control. The final stage fetches config.py from Azure Blob Storage, reflectively loading SloppyRAT from a DLL (hostfxr.dll) with the User-Agent Mozilla/5.0 (compatible; DLLMemLoader/1.0). ### Capabilities & Evasion Techniques SloppyRAT supports a range of reconnaissance and command-execution functions, including: - Host enumeration (processes, services, users, network connectivity). - File/registry manipulation, WMI queries, and Defender preference alteration. - 47 PowerShell-like commands implemented in C++ (e.g., whoami, Get-Process) to reduce reliance on PowerShell logs. - Arbitrary PowerShell execution via in-process .NET CLR invocation (PSInline). For persistence, the malware attempts to modify the Run registry key but fails due to incorrect DLL path invocation. It also executes commands via Win32_Process::Create (WMI) to blend into legitimate admin activity. A key feature is its reverse SOCKS proxy, allowing attackers to route traffic through infected endpoints for internal network reconnaissance and lateral movement. ### Defensive Evasion & C2 Resilience SloppyRAT employs multiple obfuscation techniques: - Per-string XOR encryption, API hashing, and indirect syscalls (Hell’s Gate-style). - TLS certificate pinning to block man-in-the-middle inspection. - EtherHiding fallback for C2 resolution via Polygon blockchain (though no active smart-contract addresses were observed). Despite flawed persistence logic and other errors, its current capabilities pose a significant threat for ransomware-affiliated intrusions. ### Indicators & Detection Opportunities Security teams should monitor for: - Outbound TCP/79 traffic (finger.exe abuse). - Unexpected IronPython or pythonw.exe executions from user-writable directories. - Domains linked4x[.]com, skipraid[.]com, and Azure Blob Storage paths. - User-Agent strings K8VGmQTrzX and DLLMemLoader/1.0. - ClickFix lures prompting users to paste commands into Run, PowerShell, or Terminal. Hashes (SHA-256): - 9f84cfcf988530941555d1cb7780a091743cf567396201eff7731f5475768f9a - 8774533134d9d1514106c4090a0c5bccab4550facdcfe03f4e02b9764343a990 - ff142fc192daa2a83bc565e5b38ebbe05561f3a19c7fc2d08e38c97e1986bbc5 - 680c3a9f5fdddfcc34856c7a67d21bbdd2b47d70bdfb829ff59cfa0e3bc72d21 - bdcf8fe230e23692b658b62b6547374e2234f2a497b19d26637018a1839e6dfd
INCIDENT DETAILS -
TYPE
RAT (Remote Access Trojan)
MOTIVATION
Ransomware enablement, lateral movement, reverse proxying for internal reconnaissance
IMPACT
Systems Affected: Windows systemsOperational Impact: Potential unauthorized access, lateral movement, reverse proxying for further attacks
DATA BREACH
Data Encryption: RAT capabilities include data manipulation, but no specific encryption mentioned beyond ransomware context
MAY 2026
389Before Incident
Cyber Attack
26 May 2026 • MTI
Microsoft: ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer Campaigns Exfiltrate Enterprise Data via ClickFix Lures

370After Incident
CRITICAL-19
MIC1784291489
ACR Stealer Campaigns Exfiltrate Enterprise Data via ClickFix Lures Since early 2024, ACR Stealer a sophisticated infostealer has been targeting enterprise networks to harvest saved browser credentials, live session tokens, PDFs, and files from synced Microsoft 365, OneDrive, and SharePoint folders. Microsoft’s Defender Experts observed a surge in activity between late April and mid-June 2025, attributing successful infections to ClickFix lures that trick users into executing malicious commands. ### Delivery Chains: Two Paths to Compromise Microsoft documented two primary attack vectors, both initiated by a user pasting a command into the Windows Run dialog: 1. Fileless Execution (In-Memory) - Begins with mshta.exe fetching remote HTA content via malvertising or SEO-poisoned search results. - Uses VBScript and PowerShell to decode and execute a payload hidden in a JPEG’s pixel data (steganography). - Extracts and decrypts Chrome/Edge passwords, cookies, and tokens using DPAPI, then exfiltrates PDFs from Desktop/Downloads. - SANS Internet Storm Center linked this chain to fake Claude AI assistant pages served via malicious Google ads (e.g., `sites.google.com` URLs). 2. Disk-Based Execution (Leaves Traces) - Pulls a DLL from a WebDAV share over HTTPS, often disguised with benign filenames (e.g., `google.ct`). - Uses rundll32.exe or pushd to mount remote shares as temporary drives, evading detection. - Drops an obfuscated Python script in `%LocalAppData%\Temp`, persisting via a hidden scheduled task and timestomping (copying timestamps from `notepad.exe`). - Some variants employ EtherHiding, fetching payloads or C2 addresses from blockchain RPC endpoints to avoid traditional takedowns. ### Infrastructure & Attribution - Payload Hosts/C2 Domains: `creativecommunityinfo[.]art`, `enhanceblabber[.]cc` (linked to earlier campaigns by Brad Duncan). - Fake Claude Lures: Also observed on GitLab (e.g., `claude-desktop[.]gitlab[.]io`). - No Exploits, No CVEs: Both chains rely on user execution no vulnerabilities are exploited. - Threat Actor Unclear: Microsoft avoids attribution, but ACR Stealer (aka AcridRain) was previously sold by SheldIO on Russian forums before a July 2024 shutdown. Some reports suggest a rebrand to Amatera Stealer, while others link it to GrMsk Stealer. ### Detection & Mitigation - Primary Vector: Blocking the Run dialog or restricting mshta.exe via GPO/AppLocker/WDAC can disrupt initial access. - Behavioral Indicators: - rundll32.exe making network connections with no command-line parameters. - Scheduled tasks masquerading as software updates. - Timestomping and PowerShell history clearing. - Post-Compromise Actions: Revoke tokens (not just passwords), isolate hosts, and monitor outbound connections to remote shares/image hosts. Microsoft released Defender XDR hunting queries and 16 campaign domains, though the report notes these are representative, not exhaustive. The lures including fake CAPTCHAs and AI assistant pages continue to evolve, with ClearFake (a web-inject cluster) ranking as the top threat in Red Canary’s April 2025 telemetry.
INCIDENT DETAILS -
TYPE
Infostealer Campaign
MOTIVATION
Data exfiltration for financial gain
IMPACT
Browser credentialsLive session tokensPDFsFiles from Microsoft 365, OneDrive, and SharePointEnterprise networksWindows systemsOperational Impact: Data exfiltration, potential unauthorized access to enterprise systemsIdentity Theft Risk: High
DATA BREACH
Browser credentialsLive session tokensPDFsFiles from Microsoft 365, OneDrive, and SharePointSensitivity Of Data: HighPDFs
MAY 2026
408Before Incident
Cyber Attack
25 May 2026 • MTI
Microsoft: Hackers Abuse Azure RBAC Permissions To Steal Key Vault Secrets

Microsoft Uncovers Storm-0249’s Cloud-Based Data Exfiltration Attack Targeting Azure and Microsoft 365

370After Incident
CRITICAL-38
MIC1779704661
Microsoft Uncovers Storm-0249’s Cloud-Based Data Exfiltration Attack Targeting Azure and Microsoft 365 Microsoft Threat Intelligence has exposed a sophisticated cyberattack by the threat actor Storm-0249, which leveraged legitimate cloud tools and Azure role-based access control (RBAC) to exfiltrate sensitive data from Microsoft 365 and Azure environments. The attack began with highly targeted social engineering against IT personnel and senior leadership, exploiting Microsoft’s Self-Service Password Reset (SSPR) feature. Attackers impersonated IT support, tricking victims into approving fraudulent multifactor authentication (MFA) prompts, allowing them to reset passwords and register their own devices for persistent access. Once inside, Storm-0249 used custom Python scripts and Microsoft Graph API to enumerate users, roles, and applications, stealing sensitive documents including VPN configurations from OneDrive and SharePoint. This initial breach served as a foothold to map the organization’s broader infrastructure. Exploiting privileged Azure RBAC roles, the attackers pivoted to Azure, initially targeting auxiliary Azure App Service web apps to retrieve publishing profiles. When this failed to grant access to the primary production app, they shifted tactics, compromising the Azure Key Vault in just four minutes. They extracted database connection strings and credentials, enabling authentication into the production environment. The attack escalated as Storm-0249 modified Azure SQL firewall rules and Azure Storage network configurations, enabling public access from attacker-controlled IPs (176.123.4.44, 91.208.197.87). Using shared access signature (SAS) tokens and Python scripts, they siphoned large volumes of data. Additionally, they abused Azure VM extensions (Run Command, VMAccess) to create backdoor admin accounts, disable Microsoft Defender Antivirus, and deploy ScreenConnect (hosted at 185.241.208.243) to harvest credentials and certificate files. The incident highlights the growing threat of cloud-native attacks that exploit legitimate tools and misconfigured permissions to bypass traditional security measures.
INCIDENT DETAILS -
TYPE
Data Exfiltration
IMPACT
Data Compromised: Sensitive documents, VPN configurations, database connection strings, credentials, certificate filesMicrosoft 365AzureOneDriveSharePointAzure App ServiceAzure Key VaultAzure SQLAzure StorageAzure VMOperational Impact: Data exfiltration, unauthorized access, backdoor admin accounts, disabled security toolsIdentity Theft Risk: High
DATA BREACH
Sensitive documentsVPN configurationsDatabase connection stringsCredentialsCertificate filesSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Likely
MAY 2026
424Before Incident
Cyber Attack
18 May 2026 • MTI
Microsoft: How Storm-2949 turned a compromised identity into a cloud-wide breach

Microsoft Uncovers Sophisticated Cloud-Based Data Exfiltration Campaign by Storm-2949

406After Incident
CRITICAL-18
MIC1779164698
Microsoft Uncovers Sophisticated Cloud-Based Data Exfiltration Campaign by Storm-2949 Microsoft Threat Intelligence recently exposed a highly coordinated cyberattack by the threat actor Storm-2949, targeting a single organization’s cloud infrastructure to exfiltrate sensitive data. The campaign, which spanned Microsoft 365 applications, Azure-hosted production environments, and file-hosting services, demonstrated a shift in attacker tactics prioritizing identity compromise and control-plane access over traditional malware-based methods. ### Attack Overview Storm-2949 executed a two-phase assault, beginning with targeted identity compromise and escalating into a full-scale cloud infrastructure breach. The threat actor exploited legitimate Azure management features, blending malicious activity with expected administrative behavior to evade detection. #### Phase 1: Identity Compromise via Social Engineering & SSPR Abuse - Initial Access: Storm-2949 used social engineering to manipulate Microsoft’s Self-Service Password Reset (SSPR) process, tricking users including IT personnel and senior leadership into approving fraudulent MFA prompts. - Persistence: After gaining access, the attacker removed existing MFA methods, enrolled their own device for Microsoft Authenticator, and locked out legitimate users. - Discovery: Using Microsoft Graph API, the threat actor ran automated queries to enumerate users, applications, and privileged identities, identifying high-value targets. #### Phase 2: Cloud Infrastructure Compromise & Data Exfiltration - Microsoft 365 Exfiltration: Storm-2949 accessed OneDrive and SharePoint, downloading thousands of files including VPN configurations and remote access documents to facilitate lateral movement. - Azure App Service & Key Vault Breach: - The attacker exploited Azure RBAC permissions to retrieve publishing profiles from auxiliary web apps, gaining credentials for FTP, Web Deploy, and Kudu consoles. - After failing to access the primary production app, they pivoted to Azure Key Vault, extracting database connection strings, credentials, and secrets ultimately compromising the target web app. - Azure Storage & SQL Data Theft: - Storm-2949 manipulated firewall rules to access Azure SQL databases and storage accounts, using SAS tokens and account keys to exfiltrate large volumes of data via custom Python scripts. - Virtual Machine (VM) Compromise: - The attacker deployed VMAccess extensions to create backdoor admin accounts and used Run Command to execute scripts, attempting token theft and credential harvesting. - ScreenConnect was installed for remote access, with efforts to disable Microsoft Defender protections and obscure forensic traces. ### Impact & Key Observations - No Traditional Malware: Storm-2949 relied on legitimate cloud features, making detection harder by mimicking normal administrative activity. - Identity-Centric Attack: The campaign underscored how compromised cloud identities can enable lateral movement and data exfiltration with minimal indicators of compromise. - Defense Evasion: The threat actor cleared logs, manipulated configurations, and used RMM tools to maintain persistence while avoiding detection. Microsoft’s Defender suite generated cross-domain alerts, correlating activity across endpoints, identities, and cloud environments to provide a unified view of the attack. The incident highlights the growing trend of cloud-focused threats, where attackers exploit misconfigured permissions, weak identity controls, and legitimate administrative tools to achieve their objectives. (Indicators of compromise, including attacker IPs and ScreenConnect instances, were identified but not exhaustive.)
INCIDENT DETAILS -
TYPE
Data Exfiltration
MOTIVATION
Data Exfiltration
IMPACT
Data Compromised: Thousands of files including VPN configurations, remote access documents, database connection strings, credentials, and secretsMicrosoft 365 (OneDrive, SharePoint)Azure App ServiceAzure Key VaultAzure SQL DatabasesAzure Storage AccountsVirtual MachinesOperational Impact: Lateral movement within cloud infrastructure, unauthorized remote access, and data exfiltrationIdentity Theft Risk: High (compromised identities and credentials)
DATA BREACH
VPN configurationsRemote access documentsDatabase connection stringsCredentialsSecretsSensitivity Of Data: High
MAY 2026
442Before Incident
Cyber Attack
01 May 2026 • MTI
Microsoft: Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Midnight Blizzard’s CaptiveCrunch Campaign Targets Hospitality Wi-Fi Networks

419After Incident
CRITICAL-23
MIC1785803042
Midnight Blizzard’s CaptiveCrunch Campaign Targets Hospitality Wi-Fi Networks Microsoft has attributed a global cyber campaign, dubbed CaptiveCrunch, to the Russian threat actor Midnight Blizzard (also known as APT29 or Storm-2945). The operation, active since at least early May 2024 with precursor phishing activity dating back to February targets hospitality Wi-Fi networks, including hotels and conference centers, to steal Microsoft 365 credentials and deploy malware. ### Attack Methodology The attackers exploit captive portal equipment by manipulating DNS and HTTP traffic, redirecting users to malicious pages. Victims are tricked into: - Phishing portals mimicking Microsoft 365 logins. - Device code phishing abusing Microsoft Entra ID authentication (observed since July 2024). - Fake update prompts (e.g., browser or OS updates) delivering malware via ClickFix verification, including Android APKs in some cases. ### Malware Payloads Microsoft identified two new malware families: 1. CornFlake – A Go-based remote access trojan (RAT) with capabilities including: - Remote shell access, keylogging, and clipboard monitoring. - Screenshot, microphone, and webcam surveillance. - Theft of browser credentials, cookies, and Microsoft 365 session tokens. - File exfiltration, USB monitoring, and system reconnaissance. - Persistence via fake progress windows (e.g., Windows updates, Defender scans) and multiple registry/Task Scheduler entries. 2. ChocoShell – An in-memory PowerShell credential stealer targeting: - Browser cookies and saved passwords. - Microsoft 365 and Azure AD tokens. - Wi-Fi credentials. Both malware families show AI-generated code signatures, suggesting tool-assisted development. Attackers also used FruitStone, an unprotected web-based management panel, to control infected systems, execute commands, and exfiltrate data. ### Initial Compromise & Impact While the exact entry point remains unclear, Microsoft observed breaches in shared infrastructure rather than isolated devices. The campaign highlights risks of untrusted Wi-Fi networks, particularly in high-traffic hospitality settings, where attackers can intercept credentials and deploy surveillance tools.
INCIDENT DETAILS -
TYPE
Cyber Espionage, Credential Theft, Malware Deployment
MOTIVATION
Cyber Espionage, Credential Theft, Surveillance
IMPACT
Microsoft 365 credentialsBrowser credentialsCookiesWi-Fi credentialsMicrosoft 365/Azure AD tokensPersonally Identifiable Information (PII)Hospitality Wi-Fi networksCaptive portal equipmentUser devices connecting to compromised networksOperational Impact: Potential unauthorized access to corporate systems, surveillance of affected usersBrand Reputation Impact: Risk of reputational damage for hospitality entities due to compromised Wi-Fi networksIdentity Theft Risk: High (due to stolen credentials and session tokens)
DATA BREACH
CredentialsSession TokensBrowser DataWi-Fi CredentialsSensitivity Of Data: High (PII, corporate credentials, surveillance data)Data Exfiltration: Yes (via CornFlake and ChocoShell malware)Personally Identifiable Information: Yes (browser credentials, session tokens, Wi-Fi credentials)
Vulnerability
01 May 2026 • MTI
Citrix, Microsoft, Apache Software Foundation and Langflow: Hacker uses DeepSeek AI to autonomously attack vulnerable servers

Chinese Threat Actor Leverages AI for Autonomous Cyberattacks

419After Incident
CRITICAL-23
MICTHESECCIT1785522270
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks Researchers at Palo Alto Networks’ Unit 42 have uncovered a campaign by a China-based threat actor using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks with minimal human oversight. The actor, operating under the aliases "knaithe" and "KnYuan," identifies as a "binary security researcher." The discovery stemmed from an accidental exposure of the attacker’s environment after Hermes created a misconfigured web server, revealing API keys, exploit scripts, target lists, shell history, and AI attack logs. While the observed attacks did not successfully compromise targets, they demonstrated a fully autonomous offensive AI workflow capable of identifying, evaluating, and exploiting vulnerabilities. ### AI-Powered Attack Workflow The threat actor deployed DeepSeek as the reasoning engine behind Hermes Agent, an AI framework that interacts with operating systems, executes commands, and connects to the internet. Hermes was configured to: - Receive instructions via Telegram - Use custom offensive-security tools - Query FOFA, an internet asset search engine - Operate in "Yolo" mode, executing commands without prior approval In a recovered session from May 2026, the agent autonomously: 1. Targeted Langflow servers vulnerable to CVE-2026-33017, scanning 84 exposed instances but failing to exploit them. 2. Switched to n8n workflow automation, identifying 647,000 exposed instances and attempting to exploit CVE-2026-21858 and CVE-2025-68613 though authentication requirements prevented successful breaches. 3. Analyzed public exploit repositories and executed hundreds of hours of manual targeting analysis in minutes, managing its own compute resources. ### Manual Attacks & Successful Compromises While the AI-driven attacks were largely unsuccessful, the threat actor also conducted manual attacks on 460+ systems, exploiting vulnerabilities in: - Citrix NetScaler (CVE-2026-3055) – Used in three confirmed breaches to extract memory and harvest authentication cookies. - Apache Tomcat, Marimo Notebook, Windows IKE VPN, and others. Additional AI platforms (Qwen, GLM, Kimi, MiniMax, Claude Code, OpenAI Codex) were configured but rarely used. ### Previous Hermes Incident in Thailand This campaign follows a separate incident where poorly secured Hermes infrastructure exposed details of an alleged cyberattack on Thailand’s Ministry of Finance. Logs revealed Hermes operating in unattended "YOLO" mode, automating post-exploitation tasks such as: - Privilege escalation checks - Service enumeration - File system traversal - Document cataloging Unlike the autonomous attacks observed by Unit 42, the Thailand incident involved human-directed targeting, with Hermes only automating post-compromise activity. ### Significance of the Campaign Unit 42 highlights the evolution of AI-driven cyber threats, where autonomous agents can: - Research vulnerabilities independently - Prioritize targets - Download and execute exploits - Adapt attack strategies in real time While this campaign had limited success, it underscores the growing sophistication of offensive AI in cyber operations.
INCIDENT DETAILS -
TYPE
AI-driven cyberattackManual exploitation
IMPACT
Authentication cookies (Citrix NetScaler breaches)Systems Affected: 460+ systems (including Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN)
DATA BREACH
Authentication cookiesSensitivity Of Data: High (authentication credentials)
APRIL 2026
459Before Incident
Cyber Attack
22 Apr 2026 • MTI
Microsoft: Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff

UNC6692 Threat Group Exploits Microsoft Teams in Sophisticated Cloud-Based Intrusion Campaign

440After Incident
CRITICAL-19
MIC1777004961
UNC6692 Threat Group Exploits Microsoft Teams in Sophisticated Cloud-Based Intrusion Campaign A newly uncovered threat group, UNC6692, has been executing a multistage intrusion campaign targeting enterprise networks without exploiting a single software vulnerability. Instead, the attackers leverage Microsoft Teams impersonation, custom malware, and cloud infrastructure abuse to gain deep access, as revealed by Google Threat Intelligence Group (GTIG) and Mandiant in an April 22, 2026 disclosure. ### Attack Timeline & Tactics In late December 2025, UNC6692 launched a mass email bombing campaign to overwhelm victims, creating urgency and distraction. Exploiting this chaos, the group sent phishing messages via Microsoft Teams, posing as IT helpdesk staff offering assistance. The attack abused legitimate external collaboration features in Teams, bypassing technical exploits by convincing users to override security warnings. ### Infection Chain: From Teams Chat to Full Compromise 1. Initial Contact – Victims accepted a Teams chat from an external account, believing it to be IT support. 2. Phishing Link – The attacker directed victims to a fake "Mailbox Repair and Sync Utility" hosted on an AWS S3 bucket, masquerading as a legitimate tool. 3. Multi-Phase Exploitation: - Environment Gating – A script forced victims onto Microsoft Edge for optimal exploitation. - Credential Harvesting – A fake "Health Check" prompted users to re-enter passwords, ensuring accurate capture before exfiltration. - Distraction Sequence – A fake progress bar masked real-time data theft. - Malware Staging – An AutoHotkey binary and script installed SNOWBELT, a malicious Chromium extension disguised as "MS Heartbeat". ### The SNOW Malware Ecosystem UNC6692’s modular malware suite consists of three components: - SNOWBELT (JavaScript extension) – Establishes persistence, intercepts commands, and uses DGA-based S3 URLs for C2. - SNOWGLAZE (Python WebSocket tunneler) – Routes traffic via a SOCKS proxy to a Heroku C2 server, blending malicious traffic with legitimate encrypted web traffic. - SNOWBASIN (Python HTTP server) – Executes shell commands, captures screenshots, and exfiltrates files. Persistence was maintained via Windows Startup shortcuts, scheduled tasks, and a headless Edge process loading the extension. ### Post-Exploitation & Data Theft After gaining access, UNC6692: - Scanned networks for open ports (135, 445, 3389). - Used PsExec to move laterally, dumping LSASS memory via Task Manager to extract password hashes. - Employed Pass-the-Hash to authenticate to domain controllers without plaintext passwords. - Extracted Active Directory databases (NTDS.dit), SAM, SYSTEM, and SECURITY hives using FTK Imager, exfiltrating them via LimeWire. ### Cloud Abuse & Evasion Tactics A defining feature of this campaign is its "living off the cloud" strategy, using AWS S3, Heroku, and other trusted platforms for: - Payload delivery - Credential exfiltration - Command-and-control (C2) infrastructure This approach blends malicious traffic with legitimate cloud traffic, evading domain reputation filters and IP-based blocklists. ### Indicators of Compromise (IOCs) - Phishing URL Pattern: `https://service-page-[ID]-outlook.s3.us-west-2.amazonaws.com/update.html?email=` - C2 Server: `wss://sad4w7h913-b4a57f9c36eb[.]herokuapp[.]com:443/ws` - SNOWBELT C2 URL Pattern: `https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws[.]com` - Masquerading Files: `RegSrvc.exe` (AutoHotKey), `Protected.ahk`, `SysEvents` (SNOWBELT extension directory). The campaign underscores how employee trust in enterprise tools rather than technical vulnerabilities can be the weakest link in cybersecurity. Organizations are advised to monitor Teams external access, browser extensions, and cloud egress traffic to detect similar threats.
INCIDENT DETAILS -
TYPE
Phishing, Malware, Credential Theft, Lateral Movement, Data Exfiltration
IMPACT
Data Compromised: Active Directory databases (NTDS.dit), SAM, SYSTEM, SECURITY hives, Password hashes, Personally Identifiable Information (PII)Systems Affected: Enterprise networks, Domain controllers, User workstationsOperational Impact: Network scanning, Lateral movement, Data exfiltrationIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Active Directory databases, Password hashes, Personally Identifiable Information (PII)Sensitivity Of Data: HighData Exfiltration: YesFile Types Exposed: NTDS.dit, SAM, SYSTEM, SECURITY hivesPersonally Identifiable Information: Yes
APRIL 2026
459Before Incident
Vulnerability
07 Apr 2026 • MTI
TP-Link: Russian APT28 Hackers Hijack Routers to Steal Credentials

Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign

455After Incident
CRITICAL-4
TP-1775579951
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign The UK’s National Cyber Security Centre (NCSC) has issued a warning about two ongoing cyberespionage campaigns by the Russian hacking group APT28 (also known as Fancy Bear, Forest Blizzard, and Sofacy), which is linked to Russia’s GRU military intelligence unit. Since early 2024, APT28 has been hijacking vulnerable internet routers particularly TP-Link models to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations. ### How the Attack Works APT28 has repurposed virtual private servers (VPS) as malicious DNS servers, intercepting high volumes of DNS requests from compromised routers. The group employs an opportunistic approach, initially casting a wide net to identify potential victims before narrowing down targets of intelligence value. In one campaign, APT28 exploited CVE-2023-50224, a vulnerability in TP-Link WR841N routers that allows unauthenticated attackers to extract credentials via crafted HTTP requests. By altering the DHCP DNS settings on these routers, the group forced downstream devices (such as laptops and phones) to resolve requests through their malicious servers. This enabled adversary-in-the-middle (AitM) attacks, allowing APT28 to harvest passwords, OAuth tokens, and other credentials from web and email services. Microsoft Threat Intelligence further reported that APT28 and its sub-group Storm-2754 have been compromising SOHO routers since at least August 2023, expanding their infrastructure to facilitate these attacks. ### Impact and Attribution The NCSC assesses that APT28’s operations are highly targeted, focusing on entities of strategic interest to Russian intelligence. While the initial router compromises appear broad, the group refines its focus at later stages to prioritize high-value victims. The stolen credentials could enable further unauthorized access, though the exact scope of follow-on attacks remains unclear. This campaign underscores the persistent threat posed by state-backed cyber actors leveraging common vulnerabilities in consumer-grade networking devices to conduct large-scale espionage.
INCIDENT DETAILS -
TYPE
Cyberespionage
MOTIVATION
Cyberespionage, credential theft for intelligence gathering
IMPACT
Data Compromised: Passwords, OAuth tokens, credentials from web and email servicesSystems Affected: TP-Link WR841N routers, downstream devices (laptops, phones)Identity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Credentials (passwords, OAuth tokens), web and email service dataSensitivity Of Data: High (personally identifiable information, authentication tokens)Data Exfiltration: YesPersonally Identifiable Information: Yes
APRIL 2026
463Before Incident
Vulnerability
06 Apr 2026 • MTI
PaperCut, Microsoft, VMware and Ivanti: Microsoft links Medusa ransomware affiliate to zero-day attacks

Storm-1175: China-Based Cybercrime Group Exploits Zero-Days in High-Speed Ransomware Attacks

455After Incident
CRITICAL-8
VMWMICPAPIVA1775500095
Storm-1175: China-Based Cybercrime Group Exploits Zero-Days in High-Speed Ransomware Attacks Microsoft has identified Storm-1175, a financially motivated cybercriminal group based in China, as the force behind a series of high-velocity ransomware attacks leveraging zero-day and n-day exploits. The group, known for deploying Medusa ransomware, rapidly weaponizes newly disclosed vulnerabilities sometimes within 24 hours of discovery and, in some cases, a week before patches are released. Storm-1175’s attacks follow a streamlined playbook: initial access via unpatched flaws, followed by credential theft, security tool disablement, and ransomware deployment often within days. The group has targeted organizations in healthcare, education, professional services, and finance, with significant impacts in the U.S., U.K., and Australia. Recent campaigns have exploited over 16 vulnerabilities across 10 software products, including: - Microsoft Exchange (CVE-2023-21529) - PaperCut (CVE-2023-27351, CVE-2023-27350) - Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887) - ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708) - JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199) - SmarterMail (CVE-2026-23760, CVE-2025-52691) - GoAnywhere MFT (CVE-2025-10035) In October 2024, Microsoft reported Storm-1175 exploiting CVE-2025-10035 (GoAnywhere MFT) before a patch was available. The group has also chained exploits to create persistence, deploy remote monitoring tools, and exfiltrate data before encrypting systems. A March 2025 advisory from CISA, the FBI, and MS-ISAC warned that Medusa ransomware attacks had compromised over 300 U.S. critical infrastructure organizations. Microsoft previously linked Storm-1175 to Black Basta and Akira ransomware campaigns exploiting a VMware ESXi flaw in July 2024. The group’s rapid exploitation of zero-days suggests either advanced in-house capabilities or access to exploit brokers, though many attacks still rely on known (n-day) vulnerabilities. Their tactics highlight the growing threat of high-speed, financially driven cybercrime operations.
INCIDENT DETAILS -
TYPE
ransomwaredata exfiltration
MOTIVATION
financial gain
IMPACT
Microsoft ExchangePaperCutIvanti Connect SecureConnectWise ScreenConnectJetBrains TeamCitySmarterMailGoAnywhere MFTOperational Impact: ransomware deployment leading to system encryption and disruption
MARCH 2026
480Before Incident
Cyber Attack
27 Mar 2026 • MTI
Stryker and U.S. Justice Department: FBI director emails breached by Iran-linked hackers — what happened and how to protect yourself

Iranian-Backed Hackers Breach FBI Director’s Personal Email, Leak Private Photos

461After Incident
CRITICAL-19
CRISTR1774636436
Iranian-Backed Hackers Breach FBI Director’s Personal Email, Leak Private Photos On March 27, 2026, the Iranian-linked hacktivist group Handala Hack Team claimed responsibility for accessing the personal emails of FBI Director Kash Patel, publishing alleged photos and documents as proof. The leaked images dated between 2010 and 2019 depict Patel in personal settings, including vacations and social gatherings. The U.S. Justice Department confirmed the breach, verifying the authenticity of the materials. Handala framed the attack as retaliation for the ongoing U.S.-Iran conflict and the FBI’s $10 million bounty for information on its members. The group boasted of bypassing the FBI’s security systems, though officials clarified that only Patel’s personal Gmail account not government systems was compromised. The incident highlights persistent risks tied to officials using personal emails for professional matters. About Handala Hack Team Active since 2023 and linked to Iran’s Ministry of Intelligence and Security, Handala specializes in disruptive cyberattacks, often targeting Israeli and Western entities. The group has previously breached Lockheed Martin and executed a 200,000-user data wipe at medical tech firm Stryker, leveraging malware designed to delete or expose sensitive data. The breach underscores vulnerabilities in personal email security, even among high-profile officials.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Retaliation for U.S.-Iran conflictResponse to FBI's $10 million bounty
IMPACT
Data Compromised: Personal photos and documentsSystems Affected: Personal Gmail accountBrand Reputation Impact: High (FBI Director's personal data exposed)Identity Theft Risk: High (personal photos and documents exposed)
DATA BREACH
Type Of Data Compromised: Personal photos and documentsSensitivity Of Data: High (personal and potentially sensitive images)Data Exfiltration: Yes (leaked publicly)ImagesDocumentsPersonally Identifiable Information: Yes (personal photos, potential metadata)
MARCH 2026
494Before Incident
Cyber Attack
11 Mar 2026 • MTI
Sophos, CrowdStrike, Microsoft, Proton Drive, SentinelOne, Bitdefender, ESET and McAfee: New Avalon Malware Framework Packs CrownX Ransomware Capabilities

New Modular Malware Framework 'Avalon' Unveiled in Sophisticated Phishing Attack

476After Incident
CRITICAL-18
CROMICBITSOPSENPROESEMCA1783117511
New Modular Malware Framework "Avalon" Unveiled in Sophisticated Phishing Attack Cybersecurity researchers have identified a previously unknown modular malware framework, Avalon, distributed via a multi-stage phishing campaign designed to evade traditional security controls. The framework integrates credential theft, lateral movement, remote access, recovery disruption, and ransomware execution with its ransomware component internally dubbed CrownX. The attack begins with a spoofed legal document email directing recipients to a password-protected archive hosted on Proton Drive. Instead of attaching malicious files directly, attackers embedded them within an ISO image, reducing detection at the email layer. When a victim interacts with a document-themed Windows shortcut (Secure Document CA-283505.pdf.lnk) inside the mounted image, it triggers a sequence that deploys Avalon. The shortcut executes an MSBuild project within the ISO, which loads an embedded .NET assembly to disable Event Tracing for Windows (ETW), obscuring forensic visibility. The malware then downloads a next-stage payload over HTTPS to deploy Avalon, which includes an extensive defense evasion subsystem targeting security tools from Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender. Avalon’s capabilities include: - Credential harvesting from Chromium-based browsers, Firefox, cryptocurrency wallets (MetaMask, Coinbase Wallet, Exodus, etc.), and apps like Discord, Slack, and Teams. - Data exfiltration to a remote server (helloxcherry[.]com) and command polling for further instructions. - Reconnaissance to prioritize high-value systems for lateral movement. - Ransomware execution using Windows Cryptography API, encrypting files tied to business operations, software development, and virtual infrastructure. - Recovery disruption by terminating the Volume Shadow Copy Service and deleting shadow copies. - Anti-forensic measures, including direct disk manipulation to corrupt partition data or boot records. Researchers note that CrownX represents only the final extortion stage by the time the ransom note appears, the framework has already stolen credentials, established C2 communications, and weakened recovery options. The malware also exhibits signs of AI-assisted development, suggesting lower barriers to entry for threat actors with limited technical expertise. ### AI-Driven Ransomware and Codeless Attacks Emerge In related developments, Sysdig reported the first publicly documented agentic ransomware attack powered by a large language model (LLM). The threat actor, JADEPUFFER, exploited CVE-2025-3248 to gain access to an exposed Langflow instance, executing an automated campaign that adapted in real-time to pivot toward a production database server for extortion. Separately, Palo Alto Networks Unit 42 uncovered an AI-powered malware combining a Telegram bot with a public LLM API (api.groq[.]com) to enable codeless attacks. The malware forwards system details to the attacker’s Telegram bot, then polls the API every five seconds to translate natural language instructions into shell commands eliminating the need for command-line expertise. The sample, uploaded to VirusTotal in March 2026, remains undetected by all engines.
INCIDENT DETAILS -
TYPE
MalwareRansomwarePhishing
MOTIVATION
Financial GainData ExfiltrationExtortion
IMPACT
Data Compromised: Credentials, cryptocurrency wallet data, business documents, software development files, virtual infrastructure filesSystems Affected: Windows systems with Chromium-based browsers, Firefox, cryptocurrency wallets, Discord, Slack, Teams, and security tools from Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and BitdefenderOperational Impact: Recovery disruption, encryption of critical files, termination of Volume Shadow Copy ServiceIdentity Theft Risk: High (credential harvesting, PII exposure)
DATA BREACH
CredentialsCryptocurrency wallet dataBusiness documentsSoftware development filesVirtual infrastructure filesSensitivity Of Data: High (PII, financial data, operational files)Data Exfiltration: Yes (to helloxcherry[.]com)Data Encryption: Yes (Windows Cryptography API for ransomware)Personally Identifiable Information: Yes (credentials, wallet data)
FEBRUARY 2026
615Before Incident
Ransomware
27 Feb 2026 • MTI
Microsoft and BlackFog: Double whammy: Steaelite RAT bundles data theft, ransomware

Emergence of Steaelite RAT for Double Extortion Attacks

492After Incident
CRITICAL-123
MICBLA1772238300
New "Steaelite" RAT Emerges as a Potent Threat for Double Extortion Attacks In November 2025, cybersecurity researchers at BlackFog uncovered Steaelite, a sophisticated remote access trojan (RAT) being sold on cybercrime forums. Marketed as "fully undetectable" and the "best Windows RAT," the malware targets Windows 10 and 11 systems, with an Android module reportedly in development. Steaelite operates via a browser-based dashboard, automating data theft the moment a victim connects even before an attacker interacts with the system. It harvests browser-stored passwords, session cookies, and application tokens immediately upon infection. The tool’s interface includes three main sections: - Primary Toolbar: Enables remote code execution, file management, live surveillance (webcam/microphone access), process manipulation, clipboard monitoring, password recovery, and DDoS attacks, among other functions. - Advanced Tools: Provides ransomware deployment, hidden RDP access, Windows Defender disabling, and persistence mechanisms. - Developer Tools: Adds keylogging, client-to-victim chat, USB spreading, cryptocurrency wallet hijacking (via clipboard manipulation), and tools to remove competing malware. A standout feature is its clipper module, which silently replaces cryptocurrency wallet addresses in the clipboard with attacker-controlled ones, enabling theft without the victim’s knowledge. The malware also streamlines double extortion attacks by combining data theft and ransomware deployment in a single interface eliminating the need for separate tools or coordination between cybercriminal groups. Steaelite’s active promotion across forums (with 87 messages at the time of reporting) and a YouTube demonstration video suggests aggressive marketing to expand its buyer base. Once the Android version launches, a single license could compromise both corporate Windows machines and employee mobile devices, amplifying its threat potential. The tool’s automation and integrated capabilities lower the barrier for attackers, making it a significant risk for organizations.
INCIDENT DETAILS -
TYPE
Malware (RAT)
MOTIVATION
Financial gain, data theft, ransomware deployment
IMPACT
Data Compromised: Browser-stored passwords, session cookies, application tokens, cryptocurrency wallet addressesSystems Affected: Windows 10, Windows 11 (Android module in development)Operational Impact: Potential unauthorized access, data exfiltration, ransomware deploymentIdentity Theft Risk: High (PII and credentials compromised)Payment Information Risk: High (cryptocurrency wallet hijacking)
DATA BREACH
Browser-stored passwordsSession cookiesApplication tokensCryptocurrency wallet addressesSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
FEBRUARY 2026
631Before Incident
Cyber Attack
06 Feb 2026 • MTI
Microsoft: New Wave of Odyssey Stealer Targets macOS Users in Active Cyberattack Campaign

Odyssey Stealer Surges in Global macOS Campaign, Expands Beyond Initial Target Regions

613After Incident
CRITICAL-18
MIC1770366975
Odyssey Stealer Surges in Global macOS Campaign, Expands Beyond Initial Target Regions A sharp rise in Odyssey Stealer activity is targeting macOS users worldwide, with recent telemetry revealing a rapid geographic expansion of the malware campaign. Initially detected in the U.S., France, and Spain, the threat has now spread to the U.K., Germany, Italy, Canada, Brazil, India, and multiple countries across Africa and Asia. Notably, the campaign avoids victims in CIS nations, a pattern often linked to Russian-aligned cybercriminal groups. Odyssey Stealer emerged as a rebranded evolution of Poseidon Stealer, which itself originated from the AMOS Stealer. After the sale of Poseidon in fall 2024, its developer known as "Rodrigo4" relaunch the operation under the Odyssey name, introducing enhanced evasion and persistence mechanisms. ### Distribution & Infection Tactics Threat actors deploy Odyssey Stealer through social engineering, primarily via fake CAPTCHA verification pages using the "ClickFix" technique. Victims encounter these pages on compromised websites impersonating legitimate software downloads, such as Microsoft Teams, Homebrew, or Ledger Live. The malware checks the victim’s OS before delivering malicious instructions. Once executed, the stealer harvests a wide range of sensitive data, including: - Cryptocurrency wallets (Tron, Electrum, Binance) - Browser credentials, cookies, and autofill data (Chrome, Firefox, Safari) - Over 100 browser extensions - macOS Keychain passwords - Payment information, browsing history, and files from Desktop and Documents folders (targeting `.txt`, `.pdf`, `.docx`, `.jpg`, `.png`, `.rtf`, and `.kdbx` files) ### Persistence & Exfiltration Odyssey Stealer establishes persistence via LaunchDaemons with randomly generated names (e.g., `com.{random}.plist`), ensuring survival across reboots. The attack tricks users into copying and executing base64-encoded terminal commands, which decode and run malicious AppleScript to install the stealer without traditional binary drops. Advanced variants include a SwiftUI-based "Technician Panel", using social engineering to prompt users for passwords under the guise of tech support. Stolen data is compressed into an "out.zip" file in a temporary directory and exfiltrated to command-and-control (C2) servers via curl POST requests. If the initial upload fails, the malware retries up to 10 times with 60-second delays, ensuring data delivery even if connections are blocked. After exfiltration, the script deletes temporary files to hinder forensic analysis. ### Attacker Infrastructure & Capabilities The Odyssey operation features a sophisticated control panel, allowing threat actors to: - Monitor infected devices (IP addresses, online status) - Store stolen passwords, cookies, and cryptocurrency wallets in organized logs - Generate custom malware versions via a builder function Some C2 infrastructure has been identified, including the IP 45.46.130[.]131, which hosts the Odyssey Stealer login panel for attackers to access harvested data.
INCIDENT DETAILS -
TYPE
Malware (Stealer)
MOTIVATION
Data theft, financial gain (cryptocurrency, credentials, payment information)
IMPACT
Data Compromised: Cryptocurrency wallets, browser credentials, cookies, autofill data, macOS Keychain passwords, payment information, browsing history, files from Desktop and Documents foldersSystems Affected: macOS systemsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Cryptocurrency walletsBrowser credentialsCookiesAutofill datamacOS Keychain passwordsPayment informationBrowsing historyFiles (.txt, .pdf, .docx, .jpg, .png, .rtf, .kdbx)Sensitivity Of Data: HighData Exfiltration: Yes (via curl POST requests to C2 servers).txt.pdf.docx.jpg.png.rtf.kdbxPersonally Identifiable Information: Yes (browser credentials, payment information, Keychain passwords)
FEBRUARY 2026
650Before Incident
Cyber Attack
01 Feb 2026 • MTI
Microsoft: New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto

Microsoft Uncovers CryptoBandits Malware Targeting Windows Systems via USB Drives

631After Incident
CRITICAL-19
MIC1782217449
Microsoft Uncovers CryptoBandits Malware Targeting Windows Systems via USB Drives Microsoft Threat Intelligence and Defender Experts have identified a Windows-based cryptocurrency clipper, tracked as Trojan:Win32/CryptoBandits.A (CryptoBandits), active since at least February 2026. The malware operates by monitoring clipboard activity to steal cryptocurrency wallet addresses and seed phrases, while also granting attackers remote control over infected systems. The attack spreads through malicious USB flash drives containing disguised shortcut (.lnk) files. When clicked, these files execute a hidden worm that replaces legitimate files on the drive with identical-looking shortcuts to propagate further. To evade detection, the malware configures Windows Defender exclusions for its setup folders and deploys hidden JavaScript files in C:\Users\Public\Documents, establishing persistence via scheduled tasks. The clipper component scans the clipboard every 500 milliseconds, replacing copied cryptocurrency addresses with attacker-controlled ones. It targets specific wallet formats, including Monero, Tron, Bitcoin (Taproot, Bech32, Legacy, and P2SH), using pattern-matching techniques to swap addresses seamlessly. Additionally, the malware captures five screenshots at 10-second intervals to monitor wallet balances. To avoid detection, CryptoBandits terminates if Task Manager is active and uses a bundled Tor client (ugate.exe) to route traffic through localhost (127.0.0.1:9050), obscuring command-and-control (C2) communications. Data is exfiltrated via three .onion endpoints /route.php (commands), /recvf.php (screenshots), and /stub.php (file downloads) while an EVAL command enables dynamic code execution from a local file (cfile), ensuring persistent remote access. Microsoft’s findings highlight the malware’s reliance on built-in Windows tools (WScript, ActiveXObject) and self-contained Tor integration to maintain stealth and operational anonymity.
INCIDENT DETAILS -
TYPE
Malware (Cryptocurrency Clipper)
MOTIVATION
Financial gain (cryptocurrency theft)
IMPACT
Data Compromised: Cryptocurrency wallet addresses, seed phrases, screenshots of wallet balancesSystems Affected: Windows systemsOperational Impact: Remote control of infected systems, clipboard monitoring, data exfiltrationIdentity Theft Risk: High (seed phrases and wallet addresses compromised)Payment Information Risk: High (cryptocurrency theft)
DATA BREACH
Cryptocurrency wallet addressesSeed phrasesScreenshots of wallet balancesSensitivity Of Data: HighScreenshotsClipboard dataPersonally Identifiable Information: Cryptocurrency wallet addresses, seed phrases
JANUARY 2026
673Before Incident
Cyber Attack
01 Jan 2026 • MTI
Facebook, Crypto.com and Microsoft: New 'Storm' Infostealer Remotely Decrypts Stolen Credentials

New Storm Infostealer Emerges as a Stealthy Threat to Browser and Crypto Security

647After Incident
CRITICAL-26
METMICCRY1775140151
New Storm Infostealer Emerges as a Stealthy Threat to Browser and Crypto Security Security researchers at Varonis have identified Storm, a sophisticated infostealer malware that harvests browser credentials, session cookies, and cryptocurrency wallets before exfiltrating encrypted data to attacker-controlled servers. First observed on underground cybercrime forums in early 2026, Storm represents an evolution in credential theft tactics, bypassing traditional detection methods. Unlike earlier infostealers that decrypted data locally making them vulnerable to endpoint security tools Storm avoids detection by transmitting encrypted files to remote infrastructure for decryption. This approach circumvents protections like Google’s App-Bound Encryption (introduced in Chrome 127 in July 2024), which previously forced attackers to rely on detectable methods such as Chrome injection or debugging protocol abuse. Storm targets both Chromium-based (Chrome, Edge) and Gecko-based browsers (Firefox, Waterfox, Pale Moon), extracting saved passwords, session cookies, autofill data, Google account tokens, credit card details, and browsing history. It also captures system information, screenshots, and session data from messaging apps like Telegram, Signal, and Discord, while targeting crypto wallets via browser extensions and desktop applications. All operations run in memory to minimize forensic traces. A key feature of Storm is its automation: rather than requiring manual replay of stolen logs, it uses Google Refresh Tokens and geographically matched SOCKS5 proxies to silently restore authenticated sessions, granting attackers access to SaaS platforms, internal tools, and cloud environments without triggering password-based alerts. Available for under $1,000 per month, Storm has already compromised victims across multiple countries, including Brazil, Ecuador, India, Indonesia, the U.S., and Vietnam. Varonis identified 1,715 entries in attacker panels, though some may include test data. The stolen credentials span high-value platforms such as Google, Facebook, Twitter/X, Coinbase, Binance, and Crypto.com data commonly sold on credential marketplaces for account takeovers, fraud, and further cyber intrusions.
INCIDENT DETAILS -
TYPE
Infostealer Malware
MOTIVATION
Financial gain (credential theft, fraud, account takeovers, crypto wallet compromise)
IMPACT
Data Compromised: Browser credentials, session cookies, autofill data, Google account tokens, credit card details, browsing history, system information, screenshots, messaging app session data, cryptocurrency wallet dataSystems Affected: Chromium-based browsers (Chrome, Edge), Gecko-based browsers (Firefox, Waterfox, Pale Moon), crypto wallet extensions, desktop applications (Telegram, Signal, Discord)Operational Impact: Unauthorized access to SaaS platforms, internal tools, and cloud environmentsIdentity Theft Risk: High (PII, financial data, and authentication tokens compromised)Payment Information Risk: High (credit card details and crypto wallet data exposed)
DATA BREACH
Browser credentialsSession cookiesAutofill dataGoogle account tokensCredit card detailsBrowsing historySystem informationScreenshotsMessaging app session dataCryptocurrency wallet dataNumber Of Records Exposed: 1,715 entries (some may include test data)Sensitivity Of Data: High (PII, financial data, authentication tokens, crypto wallet data)Data Exfiltration: Encrypted data transmitted to attacker-controlled servers for decryptionData Encryption: Data encrypted during exfiltration to bypass detectionPersonally Identifiable Information: Yes (saved passwords, autofill data, credit card details, Google account tokens)
Vulnerability
01 Jan 2026 • MTI
Microsoft: Chinese Hackers Chain Chrome and Windows Zero-Days to Deploy Backdoors and Steal Credentials

Chinese APT Groups Exploit Chrome and Windows Zero-Days in Targeted Espionage Campaign

647After Incident
CRITICAL-26
MIC1789201438
Chinese APT Groups Exploit Chrome and Windows Zero-Days in Targeted Espionage Campaign A recently uncovered exploit chain targeting Google Chrome and the Windows kernel has been leveraged by Chinese state-linked threat groups UTA0560 (APT31/Violet Typhoon/TA412) and JungleBamboo to deploy espionage malware and steal browser credentials. The campaign exploited CVE-2026-85046, a type-confusion flaw in Chrome’s V8 JavaScript engine, alongside CVE-2026-87491 (a WebAssembly sandbox-escape vulnerability) and CVE-2026-85880 (a Windows kernel privilege-escalation flaw in `RtlpCreateServerAcl`). Despite a fix being available in the Chromium codebase, the patch had not yet been rolled out to Chrome users, creating a patch-gap window that effectively turned the vulnerability into a zero-day exploit. Victims were lured via spear-phishing emails containing links to legitimate but vulnerable websites compromised with reflected cross-site scripting (XSS). The XSS flaw redirected users to attacker-controlled infrastructure, where a hidden iframe executed the exploit while displaying a decoy donation-form image tailored to the victim’s organization. The exploit chain began by escaping Chrome’s V8 sandbox, then leveraging the WebAssembly flaw to break out of the renderer process. The Windows kernel exploit allowed attackers to inject code into Chrome’s main process, bypassing security restrictions. The exploit included automatic retry mechanisms (up to five attempts) and host fingerprinting to assess system details such as Windows version, token privileges, and virtualization status before proceeding with privilege escalation. While the exploit code was identical across both threat groups, their post-exploitation payloads differed: - UTA0560 deployed GRIMWEDGE, a JScript backdoor delivered via a DLL sideloading technique using a legitimate executable (`msgbox.exe`). The malware established persistence via a scheduled task named “Windows Scheduled System” and operated in memory within `msiexec.exe`. Capabilities included reconnaissance, file theft, process manipulation, and command execution, with C2 traffic containing victim identifiers and command outputs. - JungleBamboo delivered SUPERSTOMP, a tool that tampered with Chrome’s Secure Preferences to install a malicious extension (LONGTALE). By removing encrypted hashes and generating valid legacy HMAC values, the attackers bypassed extension-integrity checks. The extension, disguised as a Google Gemini add-on, enabled keylogging, form data capture, clipboard theft, cookie exfiltration, screenshot harvesting, and browsing history collection. Volexity’s analysis suggests the exploit chain may have been shared or sold among multiple Chinese threat actors, highlighting the risks of publicly disclosed upstream fixes providing attackers a narrow window to weaponize vulnerabilities before downstream patches are deployed. The campaign underscores the criticality of rapid patching for Chrome and Windows, as well as the need to monitor for browser extension tampering and phishing redirects through compromised legitimate sites.
INCIDENT DETAILS -
TYPE
Espionage, Cyber Attack
MOTIVATION
Espionage, Data Theft
IMPACT
Browser credentialsKeylogging dataForm dataClipboard dataCookiesScreenshotsBrowsing historyGoogle ChromeWindows kernelIdentity Theft Risk: High
DATA BREACH
Browser credentialsPersonally Identifiable Information (PII)Browsing historyScreenshotsCookiesSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
DECEMBER 2025
677Before Incident
Vulnerability
25 Dec 2025 • MTI
Microsoft: Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

Chinese-Linked Hacking Group Targets Azerbaijani Oil & Gas Firm in Multi-Wave Cyber Espionage Campaign

673After Incident
CRITICAL-4
MIC1778682934
Chinese-Linked Hacking Group Targets Azerbaijani Oil & Gas Firm in Multi-Wave Cyber Espionage Campaign A cyber espionage campaign attributed to the China-affiliated threat group FamousSparrow (also tracked as UAT-9244) targeted an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of the group’s operational focus. The intrusion, analyzed by Bitdefender, involved three distinct waves of attacks, each deploying different backdoors while exploiting the same unpatched Microsoft Exchange Server vulnerability via the ProxyNotShell exploit chain. The campaign leveraged two primary malware families: Deed RAT (a successor to ShadowPad, widely used by Chinese espionage groups) and TernDoor, a backdoor previously observed in attacks on South American telecommunications infrastructure since 2024. Despite the victim’s remediation attempts, the threat actors repeatedly re-exploited the same entry point, deploying Deed RAT on December 25, 2025, TernDoor in late January/early February 2026, and a modified Deed RAT variant in late February 2026. Initial access was followed by the deployment of web shells for persistence, with Deed RAT delivered via an evolved DLL side-loading technique using the legitimate LogMeIn Hamachi binary. Unlike traditional side-loading, this method manipulated two exported functions in the malicious DLL, creating a two-stage execution trigger to evade detection. The attackers also conducted lateral movement to expand access and establish redundant footholds within the network. The second wave, occurring nearly a month after the initial breach, saw an unsuccessful attempt to deploy TernDoor using Mofu Loader, a shellcode loader linked to the GroundPeony threat cluster. The third wave, in late February 2026, reintroduced a modified Deed RAT variant, which used the domain sentinelonepro[.]com for command-and-control (C2) communications. Bitdefender’s analysis highlights the campaign’s adaptive persistence, with the threat actors refining their malware arsenal and re-exploiting the same vulnerability despite mitigation efforts. The targeting of Azerbaijan whose role in European energy security has grown following the 2024 expiration of Russia’s Ukraine gas transit agreement and 2026 Strait of Hormuz disruptions suggests strategic espionage motives tied to regional energy dynamics. The intrusion underscores how threat actors will repeatedly exploit unpatched systems until access is fully disrupted.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Strategic espionage tied to regional energy dynamics
IMPACT
Systems Affected: Microsoft Exchange Server, internal network systemsOperational Impact: Lateral movement, persistent access, potential data exfiltration
DATA BREACH
Data Exfiltration: Potential (not confirmed)
DECEMBER 2025
680Before Incident
Vulnerability
01 Dec 2025 • MTI
Microsoft: Copilot tricked into telling reseachers how to hack itself

Microsoft Copilot Vulnerability 'CoSnitch' Exposed via AI Self-Disclosure

675After Incident
CRITICAL-5
MIC1787063334
Microsoft Copilot Vulnerability "CoSnitch" Exposed via AI Self-Disclosure Researchers at Varonis Threat Labs uncovered a critical vulnerability in Microsoft Copilot Personal, dubbed "CoSnitch," which allowed attackers to manipulate the AI assistant into revealing its own security flaws, exfiltrating sensitive data, and poisoning its persistent memory. The flaw was reported to Microsoft in December 2025, with a planned patch and CVE assignment announced for Tuesday of the same week. The attack, termed "meta-hacking," involved socially engineering Copilot’s reasoning engine by persistently questioning why certain exploits wouldn’t work. Rather than requiring reverse engineering, the AI voluntarily disclosed its vulnerabilities during normal interactions, including an undocumented `autorun=1` parameter that enabled automatic prompt execution without user interaction. ### How the Exploit Worked 1. Initial Weakness: Copilot’s web interface previously allowed the `?q=` URL parameter to inject pre-filled prompts, which Microsoft later disabled to prevent prompt injection. 2. AI Self-Exposure: When researchers asked Copilot how to bypass user interaction requirements, the AI provided detailed technical explanations, including the existence of the `autorun=1` parameter despite claiming it was disabled. 3. Malicious URL Construction: Combining `?q=<malicious_prompt>&autorun=1`, attackers could craft a link that: - Loaded Copilot in the victim’s authenticated session. - Executed the injected prompt automatically with no visible confirmation. - Gained access to emails, chat history, connected apps (Gmail, Google Drive), and session memory. ### Potential Attack Scenarios - Data Exfiltration: Stealing emails, credentials, or files via OAuth connectors. - Memory Poisoning: Modifying stored prompts to manipulate future Copilot responses. - Reconnaissance: Scanning connected apps for sensitive information. - Disinformation Injection: Altering Copilot’s outputs in subsequent sessions to mislead users. ### Broader Implications Varonis researchers highlighted that the flaw stems from LLMs’ lack of strict separation between data and system instructions, allowing untrusted inputs (e.g., emails, documents) to be executed as commands. The attack bypasses traditional security measures by weaponizing Copilot’s own authorized access to user data. While the vulnerability was discovered in the personal version of Copilot, Varonis warned that similar architectural weaknesses could extend to enterprise environments, where AI assistants interact with corporate databases and internal systems. Microsoft has not yet responded to requests for comment on the patch or CVE details.
INCIDENT DETAILS -
TYPE
AI Vulnerability Exploitation
MOTIVATION
Security Research, Vulnerability Disclosure
IMPACT
Data Compromised: Emails, chat history, connected apps (Gmail, Google Drive), session memory, credentials, filesSystems Affected: Microsoft Copilot PersonalOperational Impact: Potential unauthorized access to user data, memory poisoning, disinformation injectionBrand Reputation Impact: Potential reputational damage due to AI security flawsIdentity Theft Risk: High (PII exposure)
DATA BREACH
EmailsChat historyCredentialsFilesSession memorySensitivity Of Data: High (Personally Identifiable Information, OAuth tokens)Data Exfiltration: Possible via malicious promptsPersonally Identifiable Information: Yes
NOVEMBER 2025
680Before Incident
OCTOBER 2025
694Before Incident
Cyber Attack
01 Oct 2025 • MTI
Microsoft: GigaWiper Malware Attacking Windows Systems With Data Wipers and Fake Ransomware Notices

New Destructive Malware 'GigaWiper' Targets Windows Systems with Irreversible Damage

676After Incident
CRITICAL-18
MIC1783679126
New Destructive Malware "GigaWiper" Targets Windows Systems with Irreversible Damage Microsoft has identified a new Windows threat, GigaWiper, a highly destructive malware designed to erase disks, corrupt files beyond recovery, and disrupt operations. First observed in October 2025, the malware marks a shift from data theft to outright system destruction, combining multiple attack methods into a single tool. GigaWiper operates as a Golang-based backdoor, allowing attackers to persist on infected systems, collect data, and execute destructive commands on demand. Unlike traditional ransomware, it offers no recovery path files encrypted with the .candy extension are permanently lost, and disk-wiping functions target critical system structures, including boot files and partition tables. The malware also clears Windows event logs, complicating incident response efforts. The threat leverages RabbitMQ for command-and-control (C2) communication and Redis for status updates, enabling operators to coordinate attacks across multiple devices. Persistence is maintained through a scheduled task disguised as a "OneDrive Update," blending into normal system activity. Key capabilities include: - Multi-pass disk wiping (targeting physical drives and Windows installations) - Irreversible file encryption (no ransom demand or decryption key) - Remote control, screen capture, and system discovery - Boot disruption (deleting recovery and kernel files) Microsoft’s analysis links GigaWiper to known malware families, including Crucio and FlockWiper, suggesting modular development. Indicators of compromise (IoCs) include multiple SHA-256 hashes and C2 IP addresses (185.182.193[.]21, 212.8.248[.]104). The malware’s flexibility ranging from covert surveillance to full system destruction highlights the growing threat of wiper malware, which prioritizes disruption over financial gain. Organizations are advised to treat GigaWiper infections as business continuity emergencies, emphasizing isolation, backup validation, and rapid detection to mitigate damage.
INCIDENT DETAILS -
TYPE
Wiper Malware
MOTIVATION
Disruption (system destruction)
IMPACT
Data Compromised: Files encrypted irreversibly, disk wipingSystems Affected: Windows systemsOperational Impact: Business continuity emergency, potential permanent data loss
DATA BREACH
Type Of Data Compromised: Files (irreversibly encrypted), system logs (cleared)Data Encryption: Yes (irreversible, .candy extension)
MAY 2025
700Before Incident
Cyber Attack
01 May 2025 • MTI
LastPass and Microsoft: Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal Passwords

Sophisticated Malware Campaign Abuses Microsoft-Signed Driver to Disable Security Tools and Steal Data

685After Incident
CRITICAL-15
MICLAS1789993625
Sophisticated Malware Campaign Abuses Microsoft-Signed Driver to Disable Security Tools and Steal Data Researchers from LastPass Threat Intelligence and Delphos Labs uncovered a malware campaign leveraging a Microsoft-attested Windows kernel driver to disable 145 antivirus and endpoint security processes before exfiltrating sensitive data. The operation, tracked as Rapuncel, impersonated LastPass Authenticator via fraudulent GitHub pages to distribute the malicious payload. Attackers created a fake GitHub organization mimicking an official LastPass product page, complete with branding and SEO-optimized descriptions. Victims searching for "LastPass Authenticator download" were redirected through multiple GitHub Pages and Cloudflare-protected infrastructure before reaching attacker-controlled servers. The final payload was delivered as an oversized ZIP archive often exceeding 100 MB containing junk files to evade automated sandbox analysis. The malware employed DLL side-loading via a renamed Microsoft debugging tool (vsdbg.exe) and a malicious vsdbg.dll, allowing execution under the guise of a legitimate Microsoft component. Once elevated, it deployed Alinubx.sys, a kernel driver disguised as nvfsflt64.sys and registered as the "NVIDIA File System Filter Driver." Despite its malicious functionality, the driver carried a valid Microsoft Windows Hardware Compatibility Publisher signature, enabling it to bypass security controls. The driver contained 145 hardcoded process names, using kernel-level termination to disable antivirus and EDR tools including those protected by Windows Protected Process Light. Researchers linked the driver to the CnCrypt/CcProtect family, associated with Henan Dafeng Software, though it was not flagged in Microsoft’s vulnerable driver blocklist at the time of discovery. After disabling security tools, Rapuncel targeted browser-stored passwords from over 25 browsers, including Chrome and Edge, via process injection to decrypt credentials. It also harvested cryptocurrency wallet files, Discord tokens, Steam sessions, Telegram data, Windows Credential Manager entries, screenshots, and documents containing keywords like "password" or "wallet." Stolen data was compressed into a ZIP file and exfiltrated to a command-and-control server at 2.26.126[.]50. Key indicators of compromise include the NvFsFilter service, writes to C:\Windows\System32\drivers\vfsflt64.sys, and artifacts such as \.\Alinubx, Alinubx.ccf, ProtectR3.dll, and Henan Dafeng Software in driver-signing metadata. Organizations are advised to monitor for renamed vsdbg.exe processes, unusual kernel driver loads, and large ZIP downloads from suspicious GitHub Pages. Systems executing the fake installer should be treated as fully compromised.
INCIDENT DETAILS -
TYPE
Malware Campaign
MOTIVATION
Data TheftCredential HarvestingFinancial Gain
IMPACT
Data Compromised: Browser-stored passwords, cryptocurrency wallet files, Discord tokens, Steam sessions, Telegram data, Windows Credential Manager entries, screenshots, and documents containing keywords like 'password' or 'wallet'Systems Affected: Windows systems with disabled antivirus/EDR toolsOperational Impact: Disabling of 145 security processes, potential full system compromiseBrand Reputation Impact: Impersonation of LastPass AuthenticatorIdentity Theft Risk: High (PII and credentials stolen)Payment Information Risk: High (cryptocurrency wallet files and credentials stolen)
DATA BREACH
Browser credentialsCryptocurrency wallet filesDiscord tokensSteam sessionsTelegram dataWindows Credential Manager entriesScreenshotsDocuments with sensitive keywordsSensitivity Of Data: High (PII, financial, and authentication data)Data Exfiltration: Compressed into ZIP and sent to C2 server at *2.26.126[.]50*ZIPBrowser credential filesWallet filesDocumentsPersonally Identifiable Information: Yes (credentials, tokens, and sensitive documents)
JANUARY 2025
699Before Incident
Vulnerability
01 Jan 2025 • MTI
Ivanti, PaperCut, ConnectWise and Microsoft: Microsoft flags China-based hackers using vicious new 'rapid attack' zero-days to launch ransomware at targets across the world

Storm-1175: Rapid Ransomware Deployment via Zero-Day and N-Day Exploits

694After Incident
CRITICAL-5
CONMICPAPIVA1775607925
Storm-1175: Rapid Ransomware Deployment via Zero-Day and N-Day Exploits A Chinese-speaking cybercriminal group, Storm-1175, is accelerating its attacks, moving from initial access to full system compromise including Medusa ransomware deployment in as little as 24 hours, according to a new Microsoft report. Unlike state-sponsored actors, the group operates for financial gain, targeting healthcare, finance, education, and professional services sectors, primarily in the U.S., U.K., and Australia. Storm-1175 exploits a mix of zero-day and n-day vulnerabilities, often chaining flaws for maximum impact. The group has been observed abusing zero-days before public disclosure and rapidly weaponizing n-days leaving defenders minimal time to patch. Over 16 vulnerabilities across 10 products have been leveraged, including critical flaws in: - Microsoft Exchange (CVE-2023-21529) - PaperCut (CVE-2023-27351, CVE-2023-27350) - Ivanti Connect Secure/Policy Secure (CVE-2023-46805, CVE-2024-21887) - ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708) - JetBrains TeamCity, SimpleHelp, CrushFTP, SmarterMail, and BeyondTrust After gaining access, the group disables antivirus and endpoint protection, deploys tools for lateral movement and persistence, and exfiltrates data before encrypting systems with Medusa ransomware. Their high operational tempo and ability to identify exposed assets have made their attacks particularly effective.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Operational Impact: Full system compromise, data exfiltration, and encryption with Medusa ransomware
JANUARY 2023
762Before Incident
Ransomware
01 Jan 2023 • MTI
Oracle and Microsoft: China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware

Storm-1175: China-Based Threat Actor Exploits Zero-Days and N-Days in High-Speed Ransomware Attacks

656After Incident
CRITICAL-106
ORAMIC1775551007
Storm-1175: China-Based Threat Actor Exploits Zero-Days and N-Days in High-Speed Ransomware Attacks A China-linked threat actor, tracked as Storm-1175, has been identified as the force behind a surge of high-velocity ransomware attacks, leveraging a mix of zero-day and N-day vulnerabilities to breach internet-facing systems. According to Microsoft Threat Intelligence, the group has demonstrated rapid operational tempo, targeting organizations in healthcare, education, professional services, and finance across Australia, the UK, and the U.S. Storm-1175 has exploited at least 16 vulnerabilities since 2023, including CVE-2025-10035 and CVE-2026-23760, which were weaponized as zero-days before public disclosure. The group has also chained multiple exploits (e.g., OWASSRF) for post-compromise activity, often gaining initial access through recently disclosed flaws before patches are widely deployed. Once inside a network, the financially motivated actor moves swiftly exfiltrating data and deploying Medusa ransomware within 24 hours in some cases. Persistence is established through new user accounts, web shells, or legitimate remote monitoring and management (RMM) tools, while security defenses are disrupted via credential theft, firewall manipulation, and antivirus exclusions. Recent attacks have expanded to Linux systems, including vulnerable Oracle WebLogic instances, though the exact exploited flaw remains unidentified. Storm-1175’s tactics include: - Living-off-the-land binaries (LOLBins) like PowerShell, PsExec, and Impacket for lateral movement. - PDQ Deployer for payload delivery, including Medusa ransomware. - Credential dumping via Mimikatz and Impacket. - Data exfiltration using Bandizip and Rclone. - Abuse of RMM tools (e.g., AnyDesk, Atera, ConnectWise ScreenConnect) to blend malicious traffic with legitimate encrypted communications. The group’s ability to rotate exploits quickly capitalizing on the window between disclosure and patch adoption highlights the growing threat of dual-use infrastructure in cyberattacks.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial Gain
IMPACT
WindowsLinuxOperational Impact: Disruption via credential theft, firewall manipulation, and antivirus exclusions
DATA BREACH
Personally Identifiable InformationCorporate DataSensitivity Of Data: High
JANUARY 2020
769Before Incident
Cyber Attack
01 Jan 2020 • MTI
Microsoft: Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe

North Korean APT38 Targets Western Businesses with Fake Job Scams and Infostealer Malware

749After Incident
CRITICAL-20
MIC1776436215
North Korean APT38 Targets Western Businesses with Fake Job Scams and Infostealer Malware Microsoft has issued a warning about Sapphire Sleet (APT38), a North Korean state-sponsored threat group linked to the Lazarus Group, which has been targeting Western businesses since at least 2020 in a campaign designed to steal cryptocurrency. The group employs fake job scams, creating elaborate fictitious personas including companies, recruiters, and job postings to lure victims via email and social media with enticing employment offers. Once engaged, attackers direct victims to a malicious Zoom lookalike instead of the legitimate platform. The fake software deploys infostealer malware to compromise devices. Microsoft’s Sherrod DeGrippo, Global Threat Intelligence GM, highlighted the effectiveness of social engineering in bypassing security measures, noting that attackers exploit human trust by mimicking routine interactions like remote support requests. The campaign primarily targets macOS users, prompting Microsoft to collaborate with Apple, which implemented automatic platform-level protections to detect and block the malware and its infrastructure. The updates were rolled out without requiring manual intervention from users.
INCIDENT DETAILS -
TYPE
Cyber Espionage, Cryptocurrency Theft
MOTIVATION
Financial Gain (Cryptocurrency Theft)State-Sponsored Espionage
IMPACT
Data Compromised: Device compromise, potential cryptocurrency theftmacOS devices
DATA BREACH
Type Of Data Compromised: Device data, potential cryptocurrency credentials
JUNE 2016
766Before Incident
Vulnerability
16 Jun 2016 • MTI
Microsoft: Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks

Microsoft Patches Actively Exploited Zero-Day in Office (CVE-2026-21509)

765After Incident
CRITICAL-1
MIC1769489765
Microsoft Patches Actively Exploited Zero-Day in Office (CVE-2026-21509) On January 26, 2026, Microsoft released emergency out-of-band security updates to address CVE-2026-21509, a zero-day vulnerability in Microsoft Office that attackers are actively exploiting. The flaw, rated "Important" with a CVSS score of 7.8, allows threat actors to bypass OLE mitigations by leveraging untrusted inputs in security decisions. The vulnerability enables local attackers to circumvent Office protections after tricking users into opening malicious files typically via phishing or social engineering. Exploitation requires low complexity, no privileges, and user interaction, but results in high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). The Microsoft Threat Intelligence Center (MSTIC) confirmed active exploitation, marking it as the second zero-day patched this month following January’s Patch Tuesday updates. ### Affected Products & Mitigation The flaw impacts legacy and current Office editions, including: - Office 2016 (32/64-bit) – KB5002713 (Build 16.0.5539.1001) - Office LTSC 2024/2021 – Automatic service-side protection post-restart - Microsoft 365 Apps (Enterprise) – Automatic updates - Office 2019 – Build 16.0.10417.20095 Office 2016/2019 users must apply updates or manually adjust the registry by adding a DWORD "Compatibility Flags" (value 400) under: `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}` (Paths may vary for Click-to-Run deployments; registry backups are recommended.) ### Threat Landscape & Recommendations While no public proof-of-concept (PoC) or attributed threat actors have been disclosed, organizations are advised to prioritize patching, enable auto-updates, and monitor for phishing indicators of compromise (IOCs) particularly suspicious Office attachments. Attackers frequently exploit such vulnerabilities for ransomware or APT initial access, making EDR monitoring for COM/OLE anomalies critical. The CISA Known Exploited Vulnerabilities (KEV) catalog may list this flaw in the near future.
INCIDENT DETAILS -
TYPE
Zero-Day Vulnerability
IMPACT
Systems Affected: Microsoft Office (legacy and current editions)Operational Impact: High impact on confidentiality, integrity, and availability (C:H/I:H/A:H)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MTI ?
?
What was MTI's A.I Rankiteo Cyber Score in August 2026 ?
?
What was MTI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was MTI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was MTI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MTI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MTI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MTI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MTI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MTI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MTI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MTI's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on MTI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MTI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MTI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?