MTI A.I CyberSecurity Scoring
MTI
Company Information
Website:https://aka.ms/threatintelblog
Employees number:None
Number of followers:128,397
NAICS:541514
Industry Type:Computer and Network Security
Homepage:aka.ms
MTI Risk Score (AI oriented)
Between 0 and 549
MTIComputer and Network Security
Updated:
31/07/2026
31/07/2026
352/1000
Critical
C
MTI Global Score (TPRM)
xxxx
MTIComputer and Network Security
Score locked

MTICritical
Current Score
352C (CRITICAL)
01000
24 incidents
-21.4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
353
JULY 2026
352
Vulnerability
18 Jul 2026 • MTI
Microsoft, Novo Nordisk and NSW Rural Fire Service: The Gentlemen Ransomware Tops Qilin: 94 Victims [2026]
June 2026 Ransomware Surge: The Gentlemen Dethrone Qilin in a Fragmented Threat Landscape
348
CRITICAL-4
MICNOVBRU1784427884
June 2026 Ransomware Surge: The Gentlemen Dethrone Qilin in a Fragmented Threat Landscape
In June 2026, the ransomware ecosystem saw a dramatic shift as The Gentlemen, a previously obscure group, claimed 94 victims enough to unseat Qilin from its five-month reign as the most active ransomware operation. The shakeup reflects a broader trend: a 9% month-over-month increase in ransomware attacks, with 707 victims across 87 countries, according to tracking firm Breachsense.
### A Volatile Leaderboard
The top three groups in June accounted for over a third of all attacks, underscoring how a small number of well-resourced affiliate crews can rapidly reshape the threat landscape:
- 1st: The Gentlemen (94 victims) – A newcomer that surged to the top in its first major tracked month.
- 2nd: DeadLock (81 victims) – Another new entrant, debuting at second place, likely absorbing affiliates from disbanded operations.
- 3rd: Qilin (71 victims) – Dropped after a five-month dominance, though still a major player.
This churn is typical of the ransomware-as-a-service (RaaS) model, where groups rebrand, dissolve, or lose affiliates to rivals almost overnight. The rapid rise of The Gentlemen and DeadLock suggests they may have poached affiliates from established crews by offering better payouts or infrastructure.
### Key Incidents and Targets
June’s attacks highlighted ransomware’s focus on high-value data and critical infrastructure:
- FulcrumSec demanded $25 million from Novo Nordisk, stealing 1.3 TB of clinical trial data and AI models a prime target for resale or secondary extortion.
- Nova targeted Australia’s NSW Rural Fire Service, exfiltrating 300 GB of sensitive data, demonstrating ransomware’s persistent threat to public-sector organizations.
- Unpatched vulnerabilities remained the primary entry point, with CVE-2026-20230 (Cisco Unified CM) and CVE-2026-41089 (Windows Netlogon) exploited to gain initial access.
### Payment Rates Decline, Extortion Tactics Evolve
Despite the surge in attacks, 69% of victims refused to pay in 2026 a trend driven by better backups, stricter cyber insurance policies, and law enforcement discouragement. This has pushed gangs toward data-theft-only extortion, where stolen data (rather than encryption) is the primary leverage.
### Regulatory and Market Impact
The 9% rise in attacks and ransomware’s 48% share of all breaches (per Verizon’s 2026 DBIR) are pressuring cyber insurance underwriters to tighten requirements, while security teams must adapt to rapidly shifting threat groups. The fragmented RaaS market where new groups can dominate within weeks means defenders must focus on behavior-based detection rather than tracking specific gangs.
### Outlook for 2026
The rest of the year is expected to see:
- Further leaderboard churn, with new groups likely cracking the top three.
- Continued decline in payment rates, accelerating the shift to data-theft extortion.
- Persistent exploitation of unpatched edge devices, keeping patch management a critical priority.
- Faster disclosures due to stricter regulatory reporting, making monthly victim counts appear more volatile.
June’s surge is less an anomaly than a continuation of the post-2024 ransomware landscape, where no group stays on top for long, affiliates move quickly, and defenders must prioritize fundamental security controls over chasing the latest threat actor.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
369
Cyber Attack
14 Jul 2026 • MTI
AsyncAPI and Microsoft: AsyncAPI Malware Contains Modules to Steal GitHub, npm, Cloud and AI API Credentials
AsyncAPI npm Supply Chain Attack Exposes Developers to Credential Theft
351
CRITICAL-18
ASYMIC1785327908
AsyncAPI npm Supply Chain Attack Exposes Developers to Credential Theft
On July 14, 2026, attackers executed a supply chain compromise targeting the AsyncAPI project on the npm registry, publishing five malicious package versions within a 90-minute window. The attack bypassed traditional security measures by embedding malware that activates upon module import, rather than relying on install scripts rendering the `ignore-scripts` safety setting ineffective.
### Attack Mechanics & Impact
The malware, identified by Microsoft, delivered a modular runtime called Miasma, capable of persistence, remote command execution, and credential theft. While some harvesting modules were dormant in the analyzed sample, the framework included encrypted logic that could be activated later via remote updates.
The compromised packages @asyncapi/specs, @asyncapi/generator, generator-components, and generator-helpers were distributed through legitimate npm publishing workflows, leveraging a misconfigured GitHub Actions workflow that exposed a privileged bot token. This allowed attackers to push poisoned commits under a valid npm identity, expanding the attack’s reach to developer laptops, CI/CD pipelines, containers, and production services.
### Credential Theft Capabilities
Miasma targeted over 100 environment variables and files, including:
- Source control tokens (GitHub, GitLab, npm, Node.js auth tokens)
- Cloud credentials (AWS, Azure, Google Cloud)
- AI platform keys (Anthropic, OpenAI)
- Container & orchestration tokens (Docker, Kubernetes)
- Secret management files (.npmrc, AWS credentials, kubeconfig, Vault tokens, SSH keys)
When a GitHub token was detected, the malware could enumerate repositories and CI context via public APIs, mirroring tactics from prior npm-based credential theft campaigns.
### Persistence & Command Channels
The attack chain involved:
1. Initial compromise via a malicious pull request exploiting a misconfigured GitHub Actions workflow.
2. Poisoned package releases published through AsyncAPI’s trusted pipeline.
3. Hidden Node process execution upon package import, fetching an encrypted second-stage payload from IPFS.
4. Installation of `sync.js` in OS-specific NodeJS directories (Windows, macOS, Linux).
5. C2 communication via 85.137.53[.]71 (ports 8080, 8081, 8091) and decentralized fallback networks.
### Indicators of Compromise (IoCs)
Compromised Packages & Hashes:
- `@asyncapi/[email protected]` (SHA-256: `d425e4583cc6185d41e95c45eda00550045a5d1919b9a012236a4520d009dbd7`)
- `@asyncapi/[email protected]` (SHA-256: `9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b`)
- `@asyncapi/[email protected]` (SHA-256: `bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4`)
- `@asyncapi/[email protected]` (SHA-256: `082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab`)
- `@asyncapi/[email protected]` (SHA-256: `34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeafff236e2f6db8ad1`)
Second-Stage Payloads:
- IPFS CIDs: `Qmet4fhsAaWMBUxNDfREHwgiyDeSWy4YSYs9wiKUW5jGyf` (generator-family), `QmQobZSp1wRPrpSEQ56qnyq7ecZh5Bg5k1fnjt4SUwwHb9` (specs)
- Drop paths: `%LOCALAPPDATA%\NodeJS\sync.js` (Windows), `~/.local/share/NodeJS/sync.js` (Linux), `~/Library/Application Support/NodeJS/sync.js` (macOS)
C2 Infrastructure:
- Primary IP: `85.137.53[.]71` (ports 8080, 8081, 8091)
- Publisher identity: `npm-oidc-no-reply@github[.]com`
### Mitigation Steps (For Reference)
Teams were advised to:
- Remove compromised versions and purge npm/Yarn caches.
- Rotate all exposed secrets (cloud keys, tokens, API credentials).
- Hunt for `sync.js` in NodeJS directories and detached Node processes.
- Pin known-good versions, rebuild from clean lockfiles, and block malicious IPFS CIDs.
- Update npm CLI and review GitHub Actions token scopes to prevent recurrence.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
386
Cyber Attack
09 Jul 2026 • MTI
Microsoft: GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
GigaWiper: A Modular Backdoor with Destructive Capabilities Emerges in 2025
368
CRITICAL-18
MIC1783680524
GigaWiper: A Modular Backdoor with Destructive Capabilities Emerges in 2025
In October 2025, Microsoft Threat Intelligence uncovered GigaWiper, a sophisticated Golang-based backdoor that integrates multiple destructive payloads into a single, modular implant. Unlike traditional wipers designed solely for data destruction GigaWiper combines disk wiping, fake ransomware, and system sabotage with robust command-and-control (C2) functionality, offering threat actors unprecedented flexibility in their attacks.
### Key Features of GigaWiper
GigaWiper is not a standalone tool but an amalgamation of at least three distinct malware families, repurposed as on-demand commands within a unified backdoor. Its destructive capabilities include:
1. Physical Disk Wiping
- Operates at the raw disk level, overwriting partition metadata and disk content.
- Uses multi-pass secure wiping (zeros, `0xFF`, random bytes) to evade detection.
- Targets all drives except the Windows installation disk (unless specified).
2. Fake Ransomware (Crucio-Based)
- Encrypts files with randomly generated AES keys that are never saved, making decryption impossible.
- Drops a hard-coded wallpaper (`image_danger.jpg`) but no ransom note, confirming its true intent is destruction, not extortion.
- Excludes critical system files (`.exe`, `.dll`) to ensure the system remains bootable until further sabotage.
3. System-Level Sabotage
- Triggers Blue Screen of Death (BSOD) by corrupting boot and kernel files.
- Clears Windows event logs, including Security logs, to erase forensic evidence.
- Disables recovery options, preventing system restoration.
### Backdoor Functionality & Persistence
Beyond destruction, GigaWiper functions as a full-featured backdoor, enabling:
- Persistence via Scheduled Tasks
- Creates a task named "OneDrive Update" that runs every minute and on startup.
- Uses a registry key (`HKCU\SOFTWARE\OneDrive\Environment`) to track execution count.
- Dual C2 Communication Channels
- RabbitMQ (AMQP) for receiving commands.
- Redis for uploading command outputs and status updates.
- Hard-coded C2 servers (e.g., `185.182.193[.]21:5544`) with AES-encrypted configurations.
- 20+ Command Capabilities
GigaWiper supports a wide range of operations, including:
- File encryption/decryption (AES-256-CBC, with optional key storage).
- Screen capture & recording (saves to `C:\ProgramData\output`).
- Process & service management (kill, suspend, resume, list).
- Registry manipulation (interactive session-like control).
- Remote VNC-like control (TCP-based keyboard/mouse input and screen streaming).
- MinIO file exfiltration (uploads files to attacker-controlled storage).
### Origins & Code Reuse
Microsoft’s analysis reveals GigaWiper’s modular design stems from the reimplementation of older malware families:
- Command 3 (Fake Ransomware) derives from Crucio ransomware (CISA-documented in 2023).
- Command 12 (Secure Wiping) is a Golang port of FlockWiper, a C-based wiper first seen in June 2025.
- "GRAT" references in FlockWiper’s PDB paths (`A:\GRAT\CWipeNew\Release\CWipeNew.pdb`) and GigaWiper’s function names suggest a shared development framework.
### Impact & Evolution of Wiper Malware
GigaWiper represents a significant shift in wiper malware, moving from single-purpose destruction tools to multi-functional backdoors that enable:
- Espionage (screen recording, keylogging, data exfiltration).
- Lateral movement (process/service manipulation, registry control).
- On-demand destruction (wiping, BSOD, fake ransomware).
Its modular architecture reduces the attacker’s deployment footprint while expanding destructive potential, making it a highly efficient tool for both cybercrime and nation-state actors.
### Indicators of Compromise (IOCs)
Microsoft has released the following SHA-256 hashes and C2 IPs for detection:
- GigaWiper Backdoor:
- `633d4cbd496b1094495da89a64f5e6c31a0f6d4d1488411db5b0cba1cfe42001`
- `ce9ad5f6c12019f4aae5b189bd8ddf5bb09e75b06a0a587b25a855c65948c913`
- Standalone Wiper:
- `3c30deb6556a94cfb84ae51798f4aecfae8c7358e55fdb321c5f2376579631cd`
- Crucio Ransomware:
- `440b5385d3838e3f6bc21220caa83b65cd5f3618daea676f271c3671650ce9a3`
- FlockWiper:
- `12c39f052f030a77c0cd531df86ad3477f46d1287b8b98b625d1dcf89385d721`
- C2 Infrastructure:
- `185.182.193[.]21` (RabbitMQ/Redis)
- `212.8.248[.]104`
GigaWiper underscores the growing convergence of espionage and destructive malware, where backdoors are no longer just for surveillance but also for maximizing operational impact whether through data theft, system disruption, or irreversible destruction.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
397
Cyber Attack
17 Jun 2026 • MTI
Microsoft: Hackers Use Fake Software Update Prompts to Steal Passwords and Crypto Wallet Data From macOS Users
North Korean Threat Actor Sapphire Sleet Targets macOS Users in Sophisticated Social Engineering Campaign
379
CRITICAL-18
MIC1781713463
North Korean Threat Actor Sapphire Sleet Targets macOS Users in Sophisticated Social Engineering Campaign
A newly uncovered cyber campaign by Sapphire Sleet, a North Korean state-backed threat group active since at least March 2020, is targeting macOS users particularly those in cryptocurrency, venture capital, and blockchain sectors through a social engineering-driven attack chain that bypasses traditional software vulnerabilities.
The campaign, first detected in early 2026, leverages deceptive recruitment lures to trick victims into executing malicious files. Attackers pose as job recruiters on social media or professional platforms, directing targets to download a file disguised as a Zoom SDK or Microsoft Teams update. Once opened, the file typically a compiled AppleScript launches in macOS Script Editor, initiating a multi-stage infection process without raising suspicion.
### How the Attack Unfolds
1. Initial Compromise: Victims are convinced to run a script (e.g., Zoom SDK Update.scpt or msteams sdk update.scpt), which silently fetches additional malicious payloads.
2. Credential Harvesting: A fake application (systemupdate.app) displays a native-looking macOS password prompt, tricking users into entering their credentials. If verified, the password is exfiltrated via Telegram.
3. Data Theft & Persistence: A second decoy app (softwareupdate.app) mimics a completed update while the malware steals cryptocurrency wallets, browser passwords, SSH keys, Telegram sessions, and browsing history. Stolen data is compressed and sent to attacker-controlled servers over port 8443.
4. Backdoor Installation: The malware deploys multiple persistent backdoors, including:
- com.apple.cli: A host monitoring tool communicating over port 6783.
- icloudz: A memory-resident backdoor loaded via ~/Library/Application Support/iCloud/icloudz, evading disk-based detection.
- A launch daemon (com.google.webkit.service.plist) ensuring the backdoor restarts after reboots.
### Evolving Tactics
In June 2026, Sapphire Sleet introduced a Microsoft Teams-themed variant, using updated payload names (e.g., com.microsoft.helper, .google.docs) while maintaining the same attack chain. The group’s infrastructure includes multiple C2 servers (e.g., 83.136.208[.]246, 188.227.196[.]252) and domains (e.g., uw04webzoom[.]us, check02id[.]com).
### Defensive Measures & Indicators of Compromise (IoCs)
Microsoft’s report, shared with Cyber Security News (CSN), prompted Apple to deploy countermeasures, including XProtect signature updates and Safari Safe Browsing blocks. Key IoCs include:
- IPs: 83.136.208[.]246, 188.227.196[.]252, 104.145.210[.]107
- Domains: uw04webzoom[.]us, check02id[.]com
- Files: Zoom SDK Update.scpt, systemupdate.app, com.apple.cli, icloudz
- Persistence Paths: /Library/LaunchDaemons/com.google.webkit.service.plist, ~/Library/LaunchAgents/com.apple.identification.plist
The campaign underscores Sapphire Sleet’s focus on high-value financial targets, combining social engineering with macOS-specific evasion techniques to steal credentials and maintain long-term access.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
412
Cyber Attack
03 Jun 2026 • MTI
Microsoft and Israeli organization: HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph: Espionage Malware Hijacks Microsoft 365 Calendars for Stealthy C2 Operations
393
HIGH-19
MICISR1784565175
HollowGraph: Espionage Malware Hijacks Microsoft 365 Calendars for Stealthy C2 Operations
Security researchers at Group-IB have uncovered a novel espionage implant, HollowGraph, which leverages a compromised Microsoft 365 calendar as a command-and-control (C2) channel. The malware, a .NET DLL, evades detection by embedding operator instructions and exfiltrating stolen data via calendar events dated to 2050, ensuring they remain hidden from typical user activity.
### How HollowGraph Operates
HollowGraph exploits the Microsoft Graph API to blend malicious traffic with legitimate Microsoft 365 communications. Instead of connecting to an attacker-controlled server, it uses the victim’s mailbox calendar as a dead drop:
- Tasking retrieval: Queries a pre-planted event (dated 2050-05-13) to extract instructions from an attached file.
- Data exfiltration: Encrypts stolen files, creates a new far-future event, and uploads the data as attachments.
- Encryption: Uses hybrid RSA and AES-256, with separate key pairs for incoming and outgoing traffic.
A secondary channel maintains persistence via DNS queries to the attacker domain cloudlanecdn[.]com, refreshing Entra ID (Azure AD) credentials (tenant ID, client ID, client secret) stored in a disguised log file (logAzure.txt).
### Attribution & Campaign Scope
Group-IB links HollowGraph to Cavern, a modular backdoor framework recently documented by Check Point and attributed to Cavern Manticore, an Iranian threat actor with ties to MuddyWater and Lyceum. However, Group-IB stops short of definitive attribution, citing only a low-confidence overlap with Lyceum (an OilRig subgroup).
The campaign targeted at least 12 machines, with active communication observed between June 3 and July 9, 2026. Victims included an Israeli organization, though Group-IB treats this as geographic targeting rather than a definitive link to the attacker. The limited footprint suggests targeted espionage, though the technique could be repurposed for broader attacks.
### Detection & Defense Challenges
HollowGraph exploits legitimate Microsoft 365 functionality, requiring no software vulnerabilities only a compromised account and Graph API access. Key detection indicators include:
- Calendar anomalies: Events with 2050-05-13 dates, GUID-based subjects (e.g., Event ID:, Boss{..}ID{..}), or attachments named File{n}.txt.
- Identity risks: Unusual OAuth app permissions, newly created client secrets, or anomalous Entra ID token activity.
- DNS red flags: Frequent AAAA queries to cloudlanecdn[.]com or high-entropy subdomains.
### Broader Implications
This attack underscores the growing trend of abusing trusted cloud services for C2 operations. While previous campaigns have exploited Outlook drafts and OneDrive, HollowGraph’s use of far-future calendar events demonstrates a new evasion tactic. With victim traffic active as recently as July 2026, defenders are advised to scrutinize unusual calendar activity even in the distant future.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
428
Cyber Attack
26 May 2026 • MTI
Microsoft: ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer Campaigns Exfiltrate Enterprise Data via ClickFix Lures
410
CRITICAL-18
MIC1784291489
ACR Stealer Campaigns Exfiltrate Enterprise Data via ClickFix Lures
Since early 2024, ACR Stealer a sophisticated infostealer has been targeting enterprise networks to harvest saved browser credentials, live session tokens, PDFs, and files from synced Microsoft 365, OneDrive, and SharePoint folders. Microsoft’s Defender Experts observed a surge in activity between late April and mid-June 2025, attributing successful infections to ClickFix lures that trick users into executing malicious commands.
### Delivery Chains: Two Paths to Compromise
Microsoft documented two primary attack vectors, both initiated by a user pasting a command into the Windows Run dialog:
1. Fileless Execution (In-Memory)
- Begins with mshta.exe fetching remote HTA content via malvertising or SEO-poisoned search results.
- Uses VBScript and PowerShell to decode and execute a payload hidden in a JPEG’s pixel data (steganography).
- Extracts and decrypts Chrome/Edge passwords, cookies, and tokens using DPAPI, then exfiltrates PDFs from Desktop/Downloads.
- SANS Internet Storm Center linked this chain to fake Claude AI assistant pages served via malicious Google ads (e.g., `sites.google.com` URLs).
2. Disk-Based Execution (Leaves Traces)
- Pulls a DLL from a WebDAV share over HTTPS, often disguised with benign filenames (e.g., `google.ct`).
- Uses rundll32.exe or pushd to mount remote shares as temporary drives, evading detection.
- Drops an obfuscated Python script in `%LocalAppData%\Temp`, persisting via a hidden scheduled task and timestomping (copying timestamps from `notepad.exe`).
- Some variants employ EtherHiding, fetching payloads or C2 addresses from blockchain RPC endpoints to avoid traditional takedowns.
### Infrastructure & Attribution
- Payload Hosts/C2 Domains: `creativecommunityinfo[.]art`, `enhanceblabber[.]cc` (linked to earlier campaigns by Brad Duncan).
- Fake Claude Lures: Also observed on GitLab (e.g., `claude-desktop[.]gitlab[.]io`).
- No Exploits, No CVEs: Both chains rely on user execution no vulnerabilities are exploited.
- Threat Actor Unclear: Microsoft avoids attribution, but ACR Stealer (aka AcridRain) was previously sold by SheldIO on Russian forums before a July 2024 shutdown. Some reports suggest a rebrand to Amatera Stealer, while others link it to GrMsk Stealer.
### Detection & Mitigation
- Primary Vector: Blocking the Run dialog or restricting mshta.exe via GPO/AppLocker/WDAC can disrupt initial access.
- Behavioral Indicators:
- rundll32.exe making network connections with no command-line parameters.
- Scheduled tasks masquerading as software updates.
- Timestomping and PowerShell history clearing.
- Post-Compromise Actions: Revoke tokens (not just passwords), isolate hosts, and monitor outbound connections to remote shares/image hosts.
Microsoft released Defender XDR hunting queries and 16 campaign domains, though the report notes these are representative, not exhaustive. The lures including fake CAPTCHAs and AI assistant pages continue to evolve, with ClearFake (a web-inject cluster) ranking as the top threat in Red Canary’s April 2025 telemetry.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
447
Cyber Attack
25 May 2026 • MTI
Microsoft: Hackers Abuse Azure RBAC Permissions To Steal Key Vault Secrets
Microsoft Uncovers Storm-0249’s Cloud-Based Data Exfiltration Attack Targeting Azure and Microsoft 365
409
CRITICAL-38
MIC1779704661
Microsoft Uncovers Storm-0249’s Cloud-Based Data Exfiltration Attack Targeting Azure and Microsoft 365
Microsoft Threat Intelligence has exposed a sophisticated cyberattack by the threat actor Storm-0249, which leveraged legitimate cloud tools and Azure role-based access control (RBAC) to exfiltrate sensitive data from Microsoft 365 and Azure environments.
The attack began with highly targeted social engineering against IT personnel and senior leadership, exploiting Microsoft’s Self-Service Password Reset (SSPR) feature. Attackers impersonated IT support, tricking victims into approving fraudulent multifactor authentication (MFA) prompts, allowing them to reset passwords and register their own devices for persistent access.
Once inside, Storm-0249 used custom Python scripts and Microsoft Graph API to enumerate users, roles, and applications, stealing sensitive documents including VPN configurations from OneDrive and SharePoint. This initial breach served as a foothold to map the organization’s broader infrastructure.
Exploiting privileged Azure RBAC roles, the attackers pivoted to Azure, initially targeting auxiliary Azure App Service web apps to retrieve publishing profiles. When this failed to grant access to the primary production app, they shifted tactics, compromising the Azure Key Vault in just four minutes. They extracted database connection strings and credentials, enabling authentication into the production environment.
The attack escalated as Storm-0249 modified Azure SQL firewall rules and Azure Storage network configurations, enabling public access from attacker-controlled IPs (176.123.4.44, 91.208.197.87). Using shared access signature (SAS) tokens and Python scripts, they siphoned large volumes of data. Additionally, they abused Azure VM extensions (Run Command, VMAccess) to create backdoor admin accounts, disable Microsoft Defender Antivirus, and deploy ScreenConnect (hosted at 185.241.208.243) to harvest credentials and certificate files.
The incident highlights the growing threat of cloud-native attacks that exploit legitimate tools and misconfigured permissions to bypass traditional security measures.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2026
464
Cyber Attack
18 May 2026 • MTI
Microsoft: How Storm-2949 turned a compromised identity into a cloud-wide breach
Microsoft Uncovers Sophisticated Cloud-Based Data Exfiltration Campaign by Storm-2949
445
CRITICAL-19
MIC1779164698
Microsoft Uncovers Sophisticated Cloud-Based Data Exfiltration Campaign by Storm-2949
Microsoft Threat Intelligence recently exposed a highly coordinated cyberattack by the threat actor Storm-2949, targeting a single organization’s cloud infrastructure to exfiltrate sensitive data. The campaign, which spanned Microsoft 365 applications, Azure-hosted production environments, and file-hosting services, demonstrated a shift in attacker tactics prioritizing identity compromise and control-plane access over traditional malware-based methods.
### Attack Overview
Storm-2949 executed a two-phase assault, beginning with targeted identity compromise and escalating into a full-scale cloud infrastructure breach. The threat actor exploited legitimate Azure management features, blending malicious activity with expected administrative behavior to evade detection.
#### Phase 1: Identity Compromise via Social Engineering & SSPR Abuse
- Initial Access: Storm-2949 used social engineering to manipulate Microsoft’s Self-Service Password Reset (SSPR) process, tricking users including IT personnel and senior leadership into approving fraudulent MFA prompts.
- Persistence: After gaining access, the attacker removed existing MFA methods, enrolled their own device for Microsoft Authenticator, and locked out legitimate users.
- Discovery: Using Microsoft Graph API, the threat actor ran automated queries to enumerate users, applications, and privileged identities, identifying high-value targets.
#### Phase 2: Cloud Infrastructure Compromise & Data Exfiltration
- Microsoft 365 Exfiltration: Storm-2949 accessed OneDrive and SharePoint, downloading thousands of files including VPN configurations and remote access documents to facilitate lateral movement.
- Azure App Service & Key Vault Breach:
- The attacker exploited Azure RBAC permissions to retrieve publishing profiles from auxiliary web apps, gaining credentials for FTP, Web Deploy, and Kudu consoles.
- After failing to access the primary production app, they pivoted to Azure Key Vault, extracting database connection strings, credentials, and secrets ultimately compromising the target web app.
- Azure Storage & SQL Data Theft:
- Storm-2949 manipulated firewall rules to access Azure SQL databases and storage accounts, using SAS tokens and account keys to exfiltrate large volumes of data via custom Python scripts.
- Virtual Machine (VM) Compromise:
- The attacker deployed VMAccess extensions to create backdoor admin accounts and used Run Command to execute scripts, attempting token theft and credential harvesting.
- ScreenConnect was installed for remote access, with efforts to disable Microsoft Defender protections and obscure forensic traces.
### Impact & Key Observations
- No Traditional Malware: Storm-2949 relied on legitimate cloud features, making detection harder by mimicking normal administrative activity.
- Identity-Centric Attack: The campaign underscored how compromised cloud identities can enable lateral movement and data exfiltration with minimal indicators of compromise.
- Defense Evasion: The threat actor cleared logs, manipulated configurations, and used RMM tools to maintain persistence while avoiding detection.
Microsoft’s Defender suite generated cross-domain alerts, correlating activity across endpoints, identities, and cloud environments to provide a unified view of the attack. The incident highlights the growing trend of cloud-focused threats, where attackers exploit misconfigured permissions, weak identity controls, and legitimate administrative tools to achieve their objectives.
(Indicators of compromise, including attacker IPs and ScreenConnect instances, were identified but not exhaustive.)
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
464
Vulnerability
01 May 2026 • MTI
Citrix, Microsoft, Apache Software Foundation and Langflow: Hacker uses DeepSeek AI to autonomously attack vulnerable servers
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks
460
CRITICAL-4
MICTHESECCIT1785522270
Chinese Threat Actor Leverages AI for Autonomous Cyberattacks
Researchers at Palo Alto Networks’ Unit 42 have uncovered a campaign by a China-based threat actor using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks with minimal human oversight. The actor, operating under the aliases "knaithe" and "KnYuan," identifies as a "binary security researcher."
The discovery stemmed from an accidental exposure of the attacker’s environment after Hermes created a misconfigured web server, revealing API keys, exploit scripts, target lists, shell history, and AI attack logs. While the observed attacks did not successfully compromise targets, they demonstrated a fully autonomous offensive AI workflow capable of identifying, evaluating, and exploiting vulnerabilities.
### AI-Powered Attack Workflow
The threat actor deployed DeepSeek as the reasoning engine behind Hermes Agent, an AI framework that interacts with operating systems, executes commands, and connects to the internet. Hermes was configured to:
- Receive instructions via Telegram
- Use custom offensive-security tools
- Query FOFA, an internet asset search engine
- Operate in "Yolo" mode, executing commands without prior approval
In a recovered session from May 2026, the agent autonomously:
1. Targeted Langflow servers vulnerable to CVE-2026-33017, scanning 84 exposed instances but failing to exploit them.
2. Switched to n8n workflow automation, identifying 647,000 exposed instances and attempting to exploit CVE-2026-21858 and CVE-2025-68613 though authentication requirements prevented successful breaches.
3. Analyzed public exploit repositories and executed hundreds of hours of manual targeting analysis in minutes, managing its own compute resources.
### Manual Attacks & Successful Compromises
While the AI-driven attacks were largely unsuccessful, the threat actor also conducted manual attacks on 460+ systems, exploiting vulnerabilities in:
- Citrix NetScaler (CVE-2026-3055) – Used in three confirmed breaches to extract memory and harvest authentication cookies.
- Apache Tomcat, Marimo Notebook, Windows IKE VPN, and others.
Additional AI platforms (Qwen, GLM, Kimi, MiniMax, Claude Code, OpenAI Codex) were configured but rarely used.
### Previous Hermes Incident in Thailand
This campaign follows a separate incident where poorly secured Hermes infrastructure exposed details of an alleged cyberattack on Thailand’s Ministry of Finance. Logs revealed Hermes operating in unattended "YOLO" mode, automating post-exploitation tasks such as:
- Privilege escalation checks
- Service enumeration
- File system traversal
- Document cataloging
Unlike the autonomous attacks observed by Unit 42, the Thailand incident involved human-directed targeting, with Hermes only automating post-compromise activity.
### Significance of the Campaign
Unit 42 highlights the evolution of AI-driven cyber threats, where autonomous agents can:
- Research vulnerabilities independently
- Prioritize targets
- Download and execute exploits
- Adapt attack strategies in real time
While this campaign had limited success, it underscores the growing sophistication of offensive AI in cyber operations.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
480
Cyber Attack
22 Apr 2026 • MTI
Microsoft: Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff
UNC6692 Threat Group Exploits Microsoft Teams in Sophisticated Cloud-Based Intrusion Campaign
462
CRITICAL-18
MIC1777004961
UNC6692 Threat Group Exploits Microsoft Teams in Sophisticated Cloud-Based Intrusion Campaign
A newly uncovered threat group, UNC6692, has been executing a multistage intrusion campaign targeting enterprise networks without exploiting a single software vulnerability. Instead, the attackers leverage Microsoft Teams impersonation, custom malware, and cloud infrastructure abuse to gain deep access, as revealed by Google Threat Intelligence Group (GTIG) and Mandiant in an April 22, 2026 disclosure.
### Attack Timeline & Tactics
In late December 2025, UNC6692 launched a mass email bombing campaign to overwhelm victims, creating urgency and distraction. Exploiting this chaos, the group sent phishing messages via Microsoft Teams, posing as IT helpdesk staff offering assistance. The attack abused legitimate external collaboration features in Teams, bypassing technical exploits by convincing users to override security warnings.
### Infection Chain: From Teams Chat to Full Compromise
1. Initial Contact – Victims accepted a Teams chat from an external account, believing it to be IT support.
2. Phishing Link – The attacker directed victims to a fake "Mailbox Repair and Sync Utility" hosted on an AWS S3 bucket, masquerading as a legitimate tool.
3. Multi-Phase Exploitation:
- Environment Gating – A script forced victims onto Microsoft Edge for optimal exploitation.
- Credential Harvesting – A fake "Health Check" prompted users to re-enter passwords, ensuring accurate capture before exfiltration.
- Distraction Sequence – A fake progress bar masked real-time data theft.
- Malware Staging – An AutoHotkey binary and script installed SNOWBELT, a malicious Chromium extension disguised as "MS Heartbeat".
### The SNOW Malware Ecosystem
UNC6692’s modular malware suite consists of three components:
- SNOWBELT (JavaScript extension) – Establishes persistence, intercepts commands, and uses DGA-based S3 URLs for C2.
- SNOWGLAZE (Python WebSocket tunneler) – Routes traffic via a SOCKS proxy to a Heroku C2 server, blending malicious traffic with legitimate encrypted web traffic.
- SNOWBASIN (Python HTTP server) – Executes shell commands, captures screenshots, and exfiltrates files.
Persistence was maintained via Windows Startup shortcuts, scheduled tasks, and a headless Edge process loading the extension.
### Post-Exploitation & Data Theft
After gaining access, UNC6692:
- Scanned networks for open ports (135, 445, 3389).
- Used PsExec to move laterally, dumping LSASS memory via Task Manager to extract password hashes.
- Employed Pass-the-Hash to authenticate to domain controllers without plaintext passwords.
- Extracted Active Directory databases (NTDS.dit), SAM, SYSTEM, and SECURITY hives using FTK Imager, exfiltrating them via LimeWire.
### Cloud Abuse & Evasion Tactics
A defining feature of this campaign is its "living off the cloud" strategy, using AWS S3, Heroku, and other trusted platforms for:
- Payload delivery
- Credential exfiltration
- Command-and-control (C2) infrastructure
This approach blends malicious traffic with legitimate cloud traffic, evading domain reputation filters and IP-based blocklists.
### Indicators of Compromise (IOCs)
- Phishing URL Pattern: `https://service-page-[ID]-outlook.s3.us-west-2.amazonaws.com/update.html?email=`
- C2 Server: `wss://sad4w7h913-b4a57f9c36eb[.]herokuapp[.]com:443/ws`
- SNOWBELT C2 URL Pattern: `https://[a-f0-9]{24}-[0-9]{6,7}-[0-9]{1}.s3.us-east-2.amazonaws[.]com`
- Masquerading Files: `RegSrvc.exe` (AutoHotKey), `Protected.ahk`, `SysEvents` (SNOWBELT extension directory).
The campaign underscores how employee trust in enterprise tools rather than technical vulnerabilities can be the weakest link in cybersecurity. Organizations are advised to monitor Teams external access, browser extensions, and cloud egress traffic to detect similar threats.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
481
Vulnerability
07 Apr 2026 • MTI
TP-Link: Russian APT28 Hackers Hijack Routers to Steal Credentials
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign
477
CRITICAL-4
TP-1775579951
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign
The UK’s National Cyber Security Centre (NCSC) has issued a warning about two ongoing cyberespionage campaigns by the Russian hacking group APT28 (also known as Fancy Bear, Forest Blizzard, and Sofacy), which is linked to Russia’s GRU military intelligence unit. Since early 2024, APT28 has been hijacking vulnerable internet routers particularly TP-Link models to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations.
### How the Attack Works
APT28 has repurposed virtual private servers (VPS) as malicious DNS servers, intercepting high volumes of DNS requests from compromised routers. The group employs an opportunistic approach, initially casting a wide net to identify potential victims before narrowing down targets of intelligence value.
In one campaign, APT28 exploited CVE-2023-50224, a vulnerability in TP-Link WR841N routers that allows unauthenticated attackers to extract credentials via crafted HTTP requests. By altering the DHCP DNS settings on these routers, the group forced downstream devices (such as laptops and phones) to resolve requests through their malicious servers. This enabled adversary-in-the-middle (AitM) attacks, allowing APT28 to harvest passwords, OAuth tokens, and other credentials from web and email services.
Microsoft Threat Intelligence further reported that APT28 and its sub-group Storm-2754 have been compromising SOHO routers since at least August 2023, expanding their infrastructure to facilitate these attacks.
### Impact and Attribution
The NCSC assesses that APT28’s operations are highly targeted, focusing on entities of strategic interest to Russian intelligence. While the initial router compromises appear broad, the group refines its focus at later stages to prioritize high-value victims. The stolen credentials could enable further unauthorized access, though the exact scope of follow-on attacks remains unclear.
This campaign underscores the persistent threat posed by state-backed cyber actors leveraging common vulnerabilities in consumer-grade networking devices to conduct large-scale espionage.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
485
Vulnerability
06 Apr 2026 • MTI
PaperCut, Microsoft, VMware and Ivanti: Microsoft links Medusa ransomware affiliate to zero-day attacks
Storm-1175: China-Based Cybercrime Group Exploits Zero-Days in High-Speed Ransomware Attacks
476
CRITICAL-9
VMWMICPAPIVA1775500095
Storm-1175: China-Based Cybercrime Group Exploits Zero-Days in High-Speed Ransomware Attacks
Microsoft has identified Storm-1175, a financially motivated cybercriminal group based in China, as the force behind a series of high-velocity ransomware attacks leveraging zero-day and n-day exploits. The group, known for deploying Medusa ransomware, rapidly weaponizes newly disclosed vulnerabilities sometimes within 24 hours of discovery and, in some cases, a week before patches are released.
Storm-1175’s attacks follow a streamlined playbook: initial access via unpatched flaws, followed by credential theft, security tool disablement, and ransomware deployment often within days. The group has targeted organizations in healthcare, education, professional services, and finance, with significant impacts in the U.S., U.K., and Australia.
Recent campaigns have exploited over 16 vulnerabilities across 10 software products, including:
- Microsoft Exchange (CVE-2023-21529)
- PaperCut (CVE-2023-27351, CVE-2023-27350)
- Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887)
- ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708)
- JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199)
- SmarterMail (CVE-2026-23760, CVE-2025-52691)
- GoAnywhere MFT (CVE-2025-10035)
In October 2024, Microsoft reported Storm-1175 exploiting CVE-2025-10035 (GoAnywhere MFT) before a patch was available. The group has also chained exploits to create persistence, deploy remote monitoring tools, and exfiltrate data before encrypting systems.
A March 2025 advisory from CISA, the FBI, and MS-ISAC warned that Medusa ransomware attacks had compromised over 300 U.S. critical infrastructure organizations. Microsoft previously linked Storm-1175 to Black Basta and Akira ransomware campaigns exploiting a VMware ESXi flaw in July 2024.
The group’s rapid exploitation of zero-days suggests either advanced in-house capabilities or access to exploit brokers, though many attacks still rely on known (n-day) vulnerabilities. Their tactics highlight the growing threat of high-speed, financially driven cybercrime operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2026
502
Cyber Attack
27 Mar 2026 • MTI
Stryker and U.S. Justice Department: FBI director emails breached by Iran-linked hackers — what happened and how to protect yourself
Iranian-Backed Hackers Breach FBI Director’s Personal Email, Leak Private Photos
483
CRITICAL-19
CRISTR1774636436
Iranian-Backed Hackers Breach FBI Director’s Personal Email, Leak Private Photos
On March 27, 2026, the Iranian-linked hacktivist group Handala Hack Team claimed responsibility for accessing the personal emails of FBI Director Kash Patel, publishing alleged photos and documents as proof. The leaked images dated between 2010 and 2019 depict Patel in personal settings, including vacations and social gatherings. The U.S. Justice Department confirmed the breach, verifying the authenticity of the materials.
Handala framed the attack as retaliation for the ongoing U.S.-Iran conflict and the FBI’s $10 million bounty for information on its members. The group boasted of bypassing the FBI’s security systems, though officials clarified that only Patel’s personal Gmail account not government systems was compromised. The incident highlights persistent risks tied to officials using personal emails for professional matters.
About Handala Hack Team
Active since 2023 and linked to Iran’s Ministry of Intelligence and Security, Handala specializes in disruptive cyberattacks, often targeting Israeli and Western entities. The group has previously breached Lockheed Martin and executed a 200,000-user data wipe at medical tech firm Stryker, leveraging malware designed to delete or expose sensitive data.
The breach underscores vulnerabilities in personal email security, even among high-profile officials.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
517
Cyber Attack
11 Mar 2026 • MTI
Sophos, CrowdStrike, Microsoft, Proton Drive, SentinelOne, Bitdefender, ESET and McAfee: New Avalon Malware Framework Packs CrownX Ransomware Capabilities
New Modular Malware Framework 'Avalon' Unveiled in Sophisticated Phishing Attack
498
CRITICAL-19
CROMICBITSOPSENPROESEMCA1783117511
New Modular Malware Framework "Avalon" Unveiled in Sophisticated Phishing Attack
Cybersecurity researchers have identified a previously unknown modular malware framework, Avalon, distributed via a multi-stage phishing campaign designed to evade traditional security controls. The framework integrates credential theft, lateral movement, remote access, recovery disruption, and ransomware execution with its ransomware component internally dubbed CrownX.
The attack begins with a spoofed legal document email directing recipients to a password-protected archive hosted on Proton Drive. Instead of attaching malicious files directly, attackers embedded them within an ISO image, reducing detection at the email layer. When a victim interacts with a document-themed Windows shortcut (Secure Document CA-283505.pdf.lnk) inside the mounted image, it triggers a sequence that deploys Avalon.
The shortcut executes an MSBuild project within the ISO, which loads an embedded .NET assembly to disable Event Tracing for Windows (ETW), obscuring forensic visibility. The malware then downloads a next-stage payload over HTTPS to deploy Avalon, which includes an extensive defense evasion subsystem targeting security tools from Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender.
Avalon’s capabilities include:
- Credential harvesting from Chromium-based browsers, Firefox, cryptocurrency wallets (MetaMask, Coinbase Wallet, Exodus, etc.), and apps like Discord, Slack, and Teams.
- Data exfiltration to a remote server (helloxcherry[.]com) and command polling for further instructions.
- Reconnaissance to prioritize high-value systems for lateral movement.
- Ransomware execution using Windows Cryptography API, encrypting files tied to business operations, software development, and virtual infrastructure.
- Recovery disruption by terminating the Volume Shadow Copy Service and deleting shadow copies.
- Anti-forensic measures, including direct disk manipulation to corrupt partition data or boot records.
Researchers note that CrownX represents only the final extortion stage by the time the ransom note appears, the framework has already stolen credentials, established C2 communications, and weakened recovery options. The malware also exhibits signs of AI-assisted development, suggesting lower barriers to entry for threat actors with limited technical expertise.
### AI-Driven Ransomware and Codeless Attacks Emerge
In related developments, Sysdig reported the first publicly documented agentic ransomware attack powered by a large language model (LLM). The threat actor, JADEPUFFER, exploited CVE-2025-3248 to gain access to an exposed Langflow instance, executing an automated campaign that adapted in real-time to pivot toward a production database server for extortion.
Separately, Palo Alto Networks Unit 42 uncovered an AI-powered malware combining a Telegram bot with a public LLM API (api.groq[.]com) to enable codeless attacks. The malware forwards system details to the attacker’s Telegram bot, then polls the API every five seconds to translate natural language instructions into shell commands eliminating the need for command-line expertise. The sample, uploaded to VirusTotal in March 2026, remains undetected by all engines.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
638
Ransomware
27 Feb 2026 • MTI
Microsoft and BlackFog: Double whammy: Steaelite RAT bundles data theft, ransomware
Emergence of Steaelite RAT for Double Extortion Attacks
515
CRITICAL-123
MICBLA1772238300
New "Steaelite" RAT Emerges as a Potent Threat for Double Extortion Attacks
In November 2025, cybersecurity researchers at BlackFog uncovered Steaelite, a sophisticated remote access trojan (RAT) being sold on cybercrime forums. Marketed as "fully undetectable" and the "best Windows RAT," the malware targets Windows 10 and 11 systems, with an Android module reportedly in development.
Steaelite operates via a browser-based dashboard, automating data theft the moment a victim connects even before an attacker interacts with the system. It harvests browser-stored passwords, session cookies, and application tokens immediately upon infection. The tool’s interface includes three main sections:
- Primary Toolbar: Enables remote code execution, file management, live surveillance (webcam/microphone access), process manipulation, clipboard monitoring, password recovery, and DDoS attacks, among other functions.
- Advanced Tools: Provides ransomware deployment, hidden RDP access, Windows Defender disabling, and persistence mechanisms.
- Developer Tools: Adds keylogging, client-to-victim chat, USB spreading, cryptocurrency wallet hijacking (via clipboard manipulation), and tools to remove competing malware.
A standout feature is its clipper module, which silently replaces cryptocurrency wallet addresses in the clipboard with attacker-controlled ones, enabling theft without the victim’s knowledge. The malware also streamlines double extortion attacks by combining data theft and ransomware deployment in a single interface eliminating the need for separate tools or coordination between cybercriminal groups.
Steaelite’s active promotion across forums (with 87 messages at the time of reporting) and a YouTube demonstration video suggests aggressive marketing to expand its buyer base. Once the Android version launches, a single license could compromise both corporate Windows machines and employee mobile devices, amplifying its threat potential. The tool’s automation and integrated capabilities lower the barrier for attackers, making it a significant risk for organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
655
Cyber Attack
06 Feb 2026 • MTI
Microsoft: New Wave of Odyssey Stealer Targets macOS Users in Active Cyberattack Campaign
Odyssey Stealer Surges in Global macOS Campaign, Expands Beyond Initial Target Regions
636
CRITICAL-19
MIC1770366975
Odyssey Stealer Surges in Global macOS Campaign, Expands Beyond Initial Target Regions
A sharp rise in Odyssey Stealer activity is targeting macOS users worldwide, with recent telemetry revealing a rapid geographic expansion of the malware campaign. Initially detected in the U.S., France, and Spain, the threat has now spread to the U.K., Germany, Italy, Canada, Brazil, India, and multiple countries across Africa and Asia. Notably, the campaign avoids victims in CIS nations, a pattern often linked to Russian-aligned cybercriminal groups.
Odyssey Stealer emerged as a rebranded evolution of Poseidon Stealer, which itself originated from the AMOS Stealer. After the sale of Poseidon in fall 2024, its developer known as "Rodrigo4" relaunch the operation under the Odyssey name, introducing enhanced evasion and persistence mechanisms.
### Distribution & Infection Tactics
Threat actors deploy Odyssey Stealer through social engineering, primarily via fake CAPTCHA verification pages using the "ClickFix" technique. Victims encounter these pages on compromised websites impersonating legitimate software downloads, such as Microsoft Teams, Homebrew, or Ledger Live. The malware checks the victim’s OS before delivering malicious instructions.
Once executed, the stealer harvests a wide range of sensitive data, including:
- Cryptocurrency wallets (Tron, Electrum, Binance)
- Browser credentials, cookies, and autofill data (Chrome, Firefox, Safari)
- Over 100 browser extensions
- macOS Keychain passwords
- Payment information, browsing history, and files from Desktop and Documents folders (targeting `.txt`, `.pdf`, `.docx`, `.jpg`, `.png`, `.rtf`, and `.kdbx` files)
### Persistence & Exfiltration
Odyssey Stealer establishes persistence via LaunchDaemons with randomly generated names (e.g., `com.{random}.plist`), ensuring survival across reboots. The attack tricks users into copying and executing base64-encoded terminal commands, which decode and run malicious AppleScript to install the stealer without traditional binary drops.
Advanced variants include a SwiftUI-based "Technician Panel", using social engineering to prompt users for passwords under the guise of tech support.
Stolen data is compressed into an "out.zip" file in a temporary directory and exfiltrated to command-and-control (C2) servers via curl POST requests. If the initial upload fails, the malware retries up to 10 times with 60-second delays, ensuring data delivery even if connections are blocked. After exfiltration, the script deletes temporary files to hinder forensic analysis.
### Attacker Infrastructure & Capabilities
The Odyssey operation features a sophisticated control panel, allowing threat actors to:
- Monitor infected devices (IP addresses, online status)
- Store stolen passwords, cookies, and cryptocurrency wallets in organized logs
- Generate custom malware versions via a builder function
Some C2 infrastructure has been identified, including the IP 45.46.130[.]131, which hosts the Odyssey Stealer login panel for attackers to access harvested data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
673
Cyber Attack
01 Feb 2026 • MTI
Microsoft: New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto
Microsoft Uncovers CryptoBandits Malware Targeting Windows Systems via USB Drives
654
CRITICAL-19
MIC1782217449
Microsoft Uncovers CryptoBandits Malware Targeting Windows Systems via USB Drives
Microsoft Threat Intelligence and Defender Experts have identified a Windows-based cryptocurrency clipper, tracked as Trojan:Win32/CryptoBandits.A (CryptoBandits), active since at least February 2026. The malware operates by monitoring clipboard activity to steal cryptocurrency wallet addresses and seed phrases, while also granting attackers remote control over infected systems.
The attack spreads through malicious USB flash drives containing disguised shortcut (.lnk) files. When clicked, these files execute a hidden worm that replaces legitimate files on the drive with identical-looking shortcuts to propagate further. To evade detection, the malware configures Windows Defender exclusions for its setup folders and deploys hidden JavaScript files in C:\Users\Public\Documents, establishing persistence via scheduled tasks.
The clipper component scans the clipboard every 500 milliseconds, replacing copied cryptocurrency addresses with attacker-controlled ones. It targets specific wallet formats, including Monero, Tron, Bitcoin (Taproot, Bech32, Legacy, and P2SH), using pattern-matching techniques to swap addresses seamlessly. Additionally, the malware captures five screenshots at 10-second intervals to monitor wallet balances.
To avoid detection, CryptoBandits terminates if Task Manager is active and uses a bundled Tor client (ugate.exe) to route traffic through localhost (127.0.0.1:9050), obscuring command-and-control (C2) communications. Data is exfiltrated via three .onion endpoints /route.php (commands), /recvf.php (screenshots), and /stub.php (file downloads) while an EVAL command enables dynamic code execution from a local file (cfile), ensuring persistent remote access.
Microsoft’s findings highlight the malware’s reliance on built-in Windows tools (WScript, ActiveXObject) and self-contained Tor integration to maintain stealth and operational anonymity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
693
Cyber Attack
01 Jan 2026 • MTI
Facebook, Crypto.com and Microsoft: New 'Storm' Infostealer Remotely Decrypts Stolen Credentials
New Storm Infostealer Emerges as a Stealthy Threat to Browser and Crypto Security
671
CRITICAL-22
METMICCRY1775140151
New Storm Infostealer Emerges as a Stealthy Threat to Browser and Crypto Security
Security researchers at Varonis have identified Storm, a sophisticated infostealer malware that harvests browser credentials, session cookies, and cryptocurrency wallets before exfiltrating encrypted data to attacker-controlled servers. First observed on underground cybercrime forums in early 2026, Storm represents an evolution in credential theft tactics, bypassing traditional detection methods.
Unlike earlier infostealers that decrypted data locally making them vulnerable to endpoint security tools Storm avoids detection by transmitting encrypted files to remote infrastructure for decryption. This approach circumvents protections like Google’s App-Bound Encryption (introduced in Chrome 127 in July 2024), which previously forced attackers to rely on detectable methods such as Chrome injection or debugging protocol abuse.
Storm targets both Chromium-based (Chrome, Edge) and Gecko-based browsers (Firefox, Waterfox, Pale Moon), extracting saved passwords, session cookies, autofill data, Google account tokens, credit card details, and browsing history. It also captures system information, screenshots, and session data from messaging apps like Telegram, Signal, and Discord, while targeting crypto wallets via browser extensions and desktop applications. All operations run in memory to minimize forensic traces.
A key feature of Storm is its automation: rather than requiring manual replay of stolen logs, it uses Google Refresh Tokens and geographically matched SOCKS5 proxies to silently restore authenticated sessions, granting attackers access to SaaS platforms, internal tools, and cloud environments without triggering password-based alerts.
Available for under $1,000 per month, Storm has already compromised victims across multiple countries, including Brazil, Ecuador, India, Indonesia, the U.S., and Vietnam. Varonis identified 1,715 entries in attacker panels, though some may include test data. The stolen credentials span high-value platforms such as Google, Facebook, Twitter/X, Coinbase, Binance, and Crypto.com data commonly sold on credential marketplaces for account takeovers, fraud, and further cyber intrusions.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
697
Vulnerability
25 Dec 2025 • MTI
Microsoft: Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
Chinese-Linked Hacking Group Targets Azerbaijani Oil & Gas Firm in Multi-Wave Cyber Espionage Campaign
692
CRITICAL-5
MIC1778682934
Chinese-Linked Hacking Group Targets Azerbaijani Oil & Gas Firm in Multi-Wave Cyber Espionage Campaign
A cyber espionage campaign attributed to the China-affiliated threat group FamousSparrow (also tracked as UAT-9244) targeted an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of the group’s operational focus. The intrusion, analyzed by Bitdefender, involved three distinct waves of attacks, each deploying different backdoors while exploiting the same unpatched Microsoft Exchange Server vulnerability via the ProxyNotShell exploit chain.
The campaign leveraged two primary malware families: Deed RAT (a successor to ShadowPad, widely used by Chinese espionage groups) and TernDoor, a backdoor previously observed in attacks on South American telecommunications infrastructure since 2024. Despite the victim’s remediation attempts, the threat actors repeatedly re-exploited the same entry point, deploying Deed RAT on December 25, 2025, TernDoor in late January/early February 2026, and a modified Deed RAT variant in late February 2026.
Initial access was followed by the deployment of web shells for persistence, with Deed RAT delivered via an evolved DLL side-loading technique using the legitimate LogMeIn Hamachi binary. Unlike traditional side-loading, this method manipulated two exported functions in the malicious DLL, creating a two-stage execution trigger to evade detection. The attackers also conducted lateral movement to expand access and establish redundant footholds within the network.
The second wave, occurring nearly a month after the initial breach, saw an unsuccessful attempt to deploy TernDoor using Mofu Loader, a shellcode loader linked to the GroundPeony threat cluster. The third wave, in late February 2026, reintroduced a modified Deed RAT variant, which used the domain sentinelonepro[.]com for command-and-control (C2) communications.
Bitdefender’s analysis highlights the campaign’s adaptive persistence, with the threat actors refining their malware arsenal and re-exploiting the same vulnerability despite mitigation efforts. The targeting of Azerbaijan whose role in European energy security has grown following the 2024 expiration of Russia’s Ukraine gas transit agreement and 2026 Strait of Hormuz disruptions suggests strategic espionage motives tied to regional energy dynamics. The intrusion underscores how threat actors will repeatedly exploit unpatched systems until access is fully disrupted.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
695
OCTOBER 2025
707
Cyber Attack
01 Oct 2025 • MTI
Microsoft: GigaWiper Malware Attacking Windows Systems With Data Wipers and Fake Ransomware Notices
New Destructive Malware 'GigaWiper' Targets Windows Systems with Irreversible Damage
692
CRITICAL-15
MIC1783679126
New Destructive Malware "GigaWiper" Targets Windows Systems with Irreversible Damage
Microsoft has identified a new Windows threat, GigaWiper, a highly destructive malware designed to erase disks, corrupt files beyond recovery, and disrupt operations. First observed in October 2025, the malware marks a shift from data theft to outright system destruction, combining multiple attack methods into a single tool.
GigaWiper operates as a Golang-based backdoor, allowing attackers to persist on infected systems, collect data, and execute destructive commands on demand. Unlike traditional ransomware, it offers no recovery path files encrypted with the .candy extension are permanently lost, and disk-wiping functions target critical system structures, including boot files and partition tables. The malware also clears Windows event logs, complicating incident response efforts.
The threat leverages RabbitMQ for command-and-control (C2) communication and Redis for status updates, enabling operators to coordinate attacks across multiple devices. Persistence is maintained through a scheduled task disguised as a "OneDrive Update," blending into normal system activity.
Key capabilities include:
- Multi-pass disk wiping (targeting physical drives and Windows installations)
- Irreversible file encryption (no ransom demand or decryption key)
- Remote control, screen capture, and system discovery
- Boot disruption (deleting recovery and kernel files)
Microsoft’s analysis links GigaWiper to known malware families, including Crucio and FlockWiper, suggesting modular development. Indicators of compromise (IoCs) include multiple SHA-256 hashes and C2 IP addresses (185.182.193[.]21, 212.8.248[.]104).
The malware’s flexibility ranging from covert surveillance to full system destruction highlights the growing threat of wiper malware, which prioritizes disruption over financial gain. Organizations are advised to treat GigaWiper infections as business continuity emergencies, emphasizing isolation, backup validation, and rapid detection to mitigate damage.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
707
JANUARY 2025
699
Vulnerability
01 Jan 2025 • MTI
Ivanti, PaperCut, ConnectWise and Microsoft: Microsoft flags China-based hackers using vicious new 'rapid attack' zero-days to launch ransomware at targets across the world
Storm-1175: Rapid Ransomware Deployment via Zero-Day and N-Day Exploits
694
CRITICAL-5
CONMICPAPIVA1775607925
Storm-1175: Rapid Ransomware Deployment via Zero-Day and N-Day Exploits
A Chinese-speaking cybercriminal group, Storm-1175, is accelerating its attacks, moving from initial access to full system compromise including Medusa ransomware deployment in as little as 24 hours, according to a new Microsoft report. Unlike state-sponsored actors, the group operates for financial gain, targeting healthcare, finance, education, and professional services sectors, primarily in the U.S., U.K., and Australia.
Storm-1175 exploits a mix of zero-day and n-day vulnerabilities, often chaining flaws for maximum impact. The group has been observed abusing zero-days before public disclosure and rapidly weaponizing n-days leaving defenders minimal time to patch. Over 16 vulnerabilities across 10 products have been leveraged, including critical flaws in:
- Microsoft Exchange (CVE-2023-21529)
- PaperCut (CVE-2023-27351, CVE-2023-27350)
- Ivanti Connect Secure/Policy Secure (CVE-2023-46805, CVE-2024-21887)
- ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708)
- JetBrains TeamCity, SimpleHelp, CrushFTP, SmarterMail, and BeyondTrust
After gaining access, the group disables antivirus and endpoint protection, deploys tools for lateral movement and persistence, and exfiltrates data before encrypting systems with Medusa ransomware. Their high operational tempo and ability to identify exposed assets have made their attacks particularly effective.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JANUARY 2023
762
Ransomware
01 Jan 2023 • MTI
Oracle and Microsoft: China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
Storm-1175: China-Based Threat Actor Exploits Zero-Days and N-Days in High-Speed Ransomware Attacks
656
CRITICAL-106
ORAMIC1775551007
Storm-1175: China-Based Threat Actor Exploits Zero-Days and N-Days in High-Speed Ransomware Attacks
A China-linked threat actor, tracked as Storm-1175, has been identified as the force behind a surge of high-velocity ransomware attacks, leveraging a mix of zero-day and N-day vulnerabilities to breach internet-facing systems. According to Microsoft Threat Intelligence, the group has demonstrated rapid operational tempo, targeting organizations in healthcare, education, professional services, and finance across Australia, the UK, and the U.S.
Storm-1175 has exploited at least 16 vulnerabilities since 2023, including CVE-2025-10035 and CVE-2026-23760, which were weaponized as zero-days before public disclosure. The group has also chained multiple exploits (e.g., OWASSRF) for post-compromise activity, often gaining initial access through recently disclosed flaws before patches are widely deployed.
Once inside a network, the financially motivated actor moves swiftly exfiltrating data and deploying Medusa ransomware within 24 hours in some cases. Persistence is established through new user accounts, web shells, or legitimate remote monitoring and management (RMM) tools, while security defenses are disrupted via credential theft, firewall manipulation, and antivirus exclusions.
Recent attacks have expanded to Linux systems, including vulnerable Oracle WebLogic instances, though the exact exploited flaw remains unidentified. Storm-1175’s tactics include:
- Living-off-the-land binaries (LOLBins) like PowerShell, PsExec, and Impacket for lateral movement.
- PDQ Deployer for payload delivery, including Medusa ransomware.
- Credential dumping via Mimikatz and Impacket.
- Data exfiltration using Bandizip and Rclone.
- Abuse of RMM tools (e.g., AnyDesk, Atera, ConnectWise ScreenConnect) to blend malicious traffic with legitimate encrypted communications.
The group’s ability to rotate exploits quickly capitalizing on the window between disclosure and patch adoption highlights the growing threat of dual-use infrastructure in cyberattacks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2020
769
Cyber Attack
01 Jan 2020 • MTI
Microsoft: Microsoft experts warn North Korean attackers target macOS users with 'a highly reliable infection chain' to steal passwords, financial data and more — here's how to stay safe
North Korean APT38 Targets Western Businesses with Fake Job Scams and Infostealer Malware
749
CRITICAL-20
MIC1776436215
North Korean APT38 Targets Western Businesses with Fake Job Scams and Infostealer Malware
Microsoft has issued a warning about Sapphire Sleet (APT38), a North Korean state-sponsored threat group linked to the Lazarus Group, which has been targeting Western businesses since at least 2020 in a campaign designed to steal cryptocurrency. The group employs fake job scams, creating elaborate fictitious personas including companies, recruiters, and job postings to lure victims via email and social media with enticing employment offers.
Once engaged, attackers direct victims to a malicious Zoom lookalike instead of the legitimate platform. The fake software deploys infostealer malware to compromise devices. Microsoft’s Sherrod DeGrippo, Global Threat Intelligence GM, highlighted the effectiveness of social engineering in bypassing security measures, noting that attackers exploit human trust by mimicking routine interactions like remote support requests.
The campaign primarily targets macOS users, prompting Microsoft to collaborate with Apple, which implemented automatic platform-level protections to detect and block the malware and its infrastructure. The updates were rolled out without requiring manual intervention from users.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2016
766
Vulnerability
16 Jun 2016 • MTI
Microsoft: Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks
Microsoft Patches Actively Exploited Zero-Day in Office (CVE-2026-21509)
765
CRITICAL-1
MIC1769489765
Microsoft Patches Actively Exploited Zero-Day in Office (CVE-2026-21509)
On January 26, 2026, Microsoft released emergency out-of-band security updates to address CVE-2026-21509, a zero-day vulnerability in Microsoft Office that attackers are actively exploiting. The flaw, rated "Important" with a CVSS score of 7.8, allows threat actors to bypass OLE mitigations by leveraging untrusted inputs in security decisions.
The vulnerability enables local attackers to circumvent Office protections after tricking users into opening malicious files typically via phishing or social engineering. Exploitation requires low complexity, no privileges, and user interaction, but results in high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H).
The Microsoft Threat Intelligence Center (MSTIC) confirmed active exploitation, marking it as the second zero-day patched this month following January’s Patch Tuesday updates.
### Affected Products & Mitigation
The flaw impacts legacy and current Office editions, including:
- Office 2016 (32/64-bit) – KB5002713 (Build 16.0.5539.1001)
- Office LTSC 2024/2021 – Automatic service-side protection post-restart
- Microsoft 365 Apps (Enterprise) – Automatic updates
- Office 2019 – Build 16.0.10417.20095
Office 2016/2019 users must apply updates or manually adjust the registry by adding a DWORD "Compatibility Flags" (value 400) under:
`HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}`
(Paths may vary for Click-to-Run deployments; registry backups are recommended.)
### Threat Landscape & Recommendations
While no public proof-of-concept (PoC) or attributed threat actors have been disclosed, organizations are advised to prioritize patching, enable auto-updates, and monitor for phishing indicators of compromise (IOCs) particularly suspicious Office attachments. Attackers frequently exploit such vulnerabilities for ransomware or APT initial access, making EDR monitoring for COM/OLE anomalies critical.
The CISA Known Exploited Vulnerabilities (KEV) catalog may list this flaw in the near future.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for MTI ??
What was MTI's A.I Rankiteo Cyber Score in July 2026 ??
What was MTI's A.I Rankiteo Cyber Score in June 2026 ??
What was MTI's A.I Rankiteo Cyber Score in May 2026 ??
What was MTI's A.I Rankiteo Cyber Score in April 2026 ??
What was MTI's A.I Rankiteo Cyber Score in March 2026 ??
What was MTI's A.I Rankiteo Cyber Score in February 2026 ??
What was MTI's A.I Rankiteo Cyber Score in January 2026 ??
What was MTI's A.I Rankiteo Cyber Score in December 2025 ??
What was MTI's A.I Rankiteo Cyber Score in November 2025 ??
What was MTI's A.I Rankiteo Cyber Score in October 2025 ??
What was MTI's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on MTI's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with MTI ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view MTI's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?