ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
This edition of ThreatsDay highlights a concerning trend of increasingly sophisticated and normalized attacks leveraging human interaction and AI. Key takeaways include a campaign impersonating IT support to install malicious tools, a massive leak of 153 million IDs, a new AI-powered phishing service targeting CEOs, and a growing threat landscape fueled by AI-enabled attacks. The overall theme is that attackers are increasingly using legitimate tools and processes to gain access, and that traditional security measures are struggling to keep pace.
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?
That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.
There is also ransomware, stolen ID data, hidden attack servers, and weak settings that should have been fixed long ago.
Here’s the full list:
- **Fake IT, Real Access:** Microsoft has warned of a human-operated intrusion campaign that leverages Microsoft Teams external collaboration to impersonate IT or help desk personnel and socially engineer users into granting an interactive remote session. "Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2),” the tech giant said. "After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim’s desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management (WinRM) toward high-value assets such as domain controllers." Microsoft has described the "intrusion pattern" as high-impact as it grants an external operator interactive access to internal infrastructure.
- **Teams Vishing at Scale:** In more Teams-related abuse, a coordinated social engineering operation dubbed Spring Ring has been observed leveraging external Microsoft Teams accounts to masquerade as IT help desk personnel to target more than 150 employees across at least 10 companies in various industries between January and April 2026. "What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware,” Palo Alto Networks Unit 42 said. “In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization’s domain controller (DC).” As many as 26 distinct attacker identities have been identified behind the chat and call attempts.
- **Ransomware Affiliate Playbook:** In a new report, Sophos revealed that The Gentlemen ransomware operation, which it tracks as Gold Sherwood, has claimed a total of 683 victims by the end of July 2026. In July alone, the group is said to have added 169 victims. “The Gentlemen ransomware intrusions [...] demonstrate a repeatable affiliate playbook that combines opportunistic initial access, rapid privilege escalation, legitimate remote access mechanisms, tool staging in trusted system paths, targeted data exfiltration, aggressive defense evasion, backup disruption, and ransomware deployment,” Sophos said. “Affiliates are operationally flexible: they use native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering to adapt to victims’ environments and maximize impact before encryption.”
- **PhaaS Survives Takedown:** The Outsider phishing-as-a-service (PaaS) platform has continued to be a resilient threat in the face of law enforcement action that took down a number of domains related to the service. The kit is operated by a threat actor known as “ChenLun.” Group-IB said it has identified over 700 new phishing pages created using the kit within a month after Google filed a civil lawsuit against its operators, indicating that affiliates are continuing to use the service. The campaigns are delivered via SMS. “What was once a technically demanding operation has been reduced to a subscription and a Telegram channel,” Group-IB said. “The phishing kits are distributed via a dedicated Telegram ecosystem. Operators used a WebSocket connection for live keylogging and to manipulate MFA challenges.”
- **Signed Software, Hidden Payload:** A government-themed tax notice campaign is targeting recipients through U.A.E.- and India-themed tax assessment lures to persuade them to open a malicious disc image. “The disc image contains a legitimate, validly signed commercial executable alongside a hidden, unsigned malicious DLL,” iZOOlogic said. “This makes abuse of software trust and DLL sideloading the central mechanism of the campaign. The malicious DLL acts as a loader and establishes multiple execution and persistence mechanisms. The loader contains three encrypted payloads. Two decrypt to legitimately signed kernel drivers from unrelated commercial products, while the third is a persistence script.” The attack chain paves the way for a Registry-resident second stage, which connects to an external server over UDP.
- **Executive Phishing as a Service:** ZeroBEC has disclosed details of a turnkey phishing service called BlueKit that’s being used to target CEOs of financial-industry groups to facilitate credential theft using a browser-in-the-middle (BitM) infrastructure. The campaign uses document-sharing lures to trigger the attack chain and employs ZeroBot to screen bots. “The campaign did not stop at credential or session theft,” ZeroBEC said. “After a BlueKit browser-in-the-middle flow, selected victims were moved into a fake document-viewer workflow that delivered a legitimate ScreenConnect client configured for an attacker-used ScreenConnect cloud instance.” The service advertises access at $250 for seven days, $480 for 14 days, and $940 for 30 days, placing it at the higher end of the current PhaaS market, in comparison to Tycoon 2FA, Greatness, and Forg365, which cost approximately $350, $289, and $400 per month.
- **Dormant Domains, Ready C2:** Cybersecurity researchers have analyzed the infrastructure powering the operations of Prince of Persia (aka Indy), a little-known Iranian hacking group known for deploying malware families, Foudre and Tonnerre, to profile victims and harvest sensitive data from high-value targets. According to Whisper Security’s Kaveh Azarhoosh, the backend is self-authoritative, with each live C2 server also running the nameservers for its own domains. Also identified is a dormant reserve of 58 domains that are registered and delegated to the group’s own nameservers, but none of which currently points at any server. “They're staged, not live: the moment any one of them gains an address record, a new command server has gone live — and it’s visible before the server does anything at all,” Azarhoosh told The Hacker News via email.
- **Remote-Controlled Rubber Ducky:** Intezer has detailed a fake “privacy browser” downloaded from a counterfeit site (“www.mxsetuplogi.com”) that turns remote attacker commands into simulated mouse and keyboard input on a victim’s machine. The site is surfaced via a sponsored search result on Google, in this case after the victim mistyped the domain name (“www.mxsetup.logi.con”) on the address bar. The cybersecurity company described it as a USB Rubber Ducky attack delivered over the internet. “This attack evades EDR and sits at zero to two detections on VirusTotal,” it said in a statement. “The infection began with one simple mistyped letter during routine mouse setup that routed the victim through a malvertising network into an MSIX installer signed through Microsoft's own infrastructure.” The campaign has been tracked back to a similar operation from January 2016, indicating that the activity has been active for at least a decade.
- **153 Million IDs for Sale:** The U.S. Federal Bureau of Investigation (FBI) is investigating a new ID theft service called Nexus, which claims to have digital scans of over 153 million driver's licenses from people in the U.S. and Canada. According to independent security journalist Brian Krebs, the service is said to be siphoning images collected by a widely used identity verification company called IDScan.net based in Louisiana. The service, launched on the dark web on August 31, 2026, also boasts of more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards. Each record can be unlocked for $100. Shortly after the exposé was published, Nexus went offline. IDscan.net is said to be investigating the incident on its end.
- **AI Instructions Become a Trap:** A scan of 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies has uncovered llms.txt or llms-full.txt that are being placed at the root of their websites, alongside robots.txt. “The file is not a sitemap and it is not a disclaimer,” an Israeli stealth startup said. “It is a curated instruction set for AI agents: what to read, which APIs to call, which packages to install, which domains to trust. OpenAI, Anthropic, and Google publish their own.” Of the 8,265 llms.txt and llms-full.txt files surfaced from the scan, 120 of them, each on a different site, featured install instructions pointing to PyPI or npm package names and domains that had never been registered. “We selected a small set of package names that appeared in the llms.txt files of companies you have definitely heard of, and registered them on PyPI and npm,” Alon Hertz, one of the researchers said. “Into each one we embedded a single phone-home — a minimal beacon that reported the fact of installation back to infrastructure we controlled. The first callback arrived in under four minutes.” What’s troubling here is that at least one active attack has already exploited this misconfiguration, in which authentication vendor Clerk's llms.txt included a reference to an npm package named “clerk-next-fix-auth-protection” instead of referencing its scoped package, @clerk/eslint-plugin. An unknown threat actor registered a public package with the same name. The package contained code to transmit the installer's username, machine name, working directory, and timestamp to an external server. Clerk has since addressed the issue.
- **AI Defenders Sound the Alarm:** A coalition of over 100 companies, including Anthropic, Google, OpenAI, Microsoft, Perplexity, and others, has published an open-letter calling for improvements to cybersecurity as AI continues to compress compress cyberattack timelines, as well as accelerate the speed and scale of cyber attacks, leaving defenders with an ever-shortening window to address security issues before they are exploited. The signatories noted that current approaches to cybersecurity are not equipped to deal with the incoming surge in AI-enabled attacks, and that threat actors can rely on AI tools to target longstanding vulnerabilities, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems. “In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the letter warns. “The companies and public services our communities depend on – from hospitals to water treatment plants to the infrastructure that powers the internet – are at risk. Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders’ window to make our digital world much more secure.”
- **Legacy Login Exposes 5K Accounts:** Dropbox has disclosed that about 5,000 accounts were compromised last month, allowing threat actors to view and download content stored on the cloud-storage platform. The company told Reuters that it “identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled,” adding it terminated all sessions authenticate
