Threat Intelligence — Page 26

Threat Intelligence

SharkLoader Drops Cobalt Strike on Asian Government Targets in 'StrikeShark' Campaign

A previously undocumented loader is being used against a diplomatic office in Indonesia and government bodies in Taiwan, with operators staging Cobalt Strike Beacon as the final payload.

2 min read
Threat Intelligence

TinyRCT Backdoor Surfaces in CL-STA-1062 Intrusions Across Southeast Asia

Palo Alto Networks ties the previously undocumented implant to a Chinese-speaking cluster targeting state-owned energy and government entities.

2 min read
Threat Intelligence

North Korean Malware Tells AI Analyzers to Look Away

A macOS sample attributed to Pyongyang-linked actors contains prompts designed to make LLM-assisted security tools abandon their analysis. Defenders are starting to notice the pattern.

2 min read
Threat Intelligence

ASIO Found State Hackers Pre-Positioned for Sabotage Inside Australian Critical Infrastructure

Australia's domestic intelligence agency says a foreign state actor had stolen valid credentials from IT staff at a critical infrastructure operator — and was staging for disruption, not just espionage.

2 min read
Threat Intelligence

Week in Brief: Russia's Cellebrite Use, Five Eyes AI Warning, macOS Backdoor, Scattered Spider Pleas

Four stories that deserved more attention: state-backed mobile forensics against activists, an intelligence alliance's AI threat advisory, a new Mac implant, and a high-profile cybercrime case moving toward resolution.

2 min read
Threat Intelligence

Mini Shai-Hulud Worm Jumps to Go, Hits LeoPlatform and RStreams npm Packages

The self-propagating supply chain campaign tied to Miasma and Hades has spread again — abusing GitHub Actions workflows and now reaching Go modules.

2 min read
Threat Intelligence

Hotel Front Desks Hit by Photo-ZIP Phishing Dropping Node.js Implant

Microsoft flags an unattributed campaign active since April 2026 against hospitality targets in Europe and Asia.

3 min read
Threat Intelligence

Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome

Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

2 min read
Threat Intelligence

Featured Chrome Ad Blocker with 10M+ Installs Carries Dormant JS Injection Capability

Researchers flagged a Featured-badge extension that can pull and execute remote JavaScript — a capability common to supply-chain abuse clusters tracked across the Chrome Web Store.

2 min read
Threat Intelligence

The Week in Cheap Crime: Stale Creds, Trusted Apps, and Phishing Through the Front Door

Not elite. Not cinematic. Just effective — and that's the problem.

2 min read
Threat Intelligence

Iranian Group Handala Claimed It Could Poison California's Water. Forensics Say Otherwise.

California Water Service brought in Mandiant after Handala threatened disruption. Investigators found no evidence the group ever touched operational technology.

2 min read
Threat Intelligence

Mistic Backdoor Shows Up in IAB-Brokered Intrusions Across Four Verticals

A quiet new implant tied to the KongTuke access broker is landing on insurance, education, IT, and professional services networks — and it's not riding a CVE to get there.

3 min read
Threat Intelligence

Mistic Backdoor Ties to IAB Selling Enterprise Footholds to Ransomware Gangs

A new in-memory backdoor named Mistic has been active since April, and the threat actor behind it has reportedly funneled access to Qilin, Akira, Black Basta, and others.

2 min read
Threat Intelligence

Operation Endgame Hits Amadey and StealC, Pulls 27M Credentials From Loader Infrastructure

Europol-led takedown dismantled command servers behind two of the most prolific malware-as-a-service loaders, with Microsoft, ESET, Bitdefender, and Bitsight providing technical support.

3 min read
Threat Intelligence

Law Enforcement and Microsoft Tear Down Command Infrastructure Behind Amadey and StealC

Hundreds of C2 servers went dark in a coordinated takedown targeting the shared hosting backbone used by two prolific infostealer families.

2 min read
© 2026 Threat Vectr