threat-intel New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication HollowGraph, a new malware dubbed by Group-IB, leverages Microsoft 365 calendars to establish command-and-control communication, specifically targeting Israeli entities. The malware uses a sophisticated technique to hide… SecurityWeek · Jul 21, 2026 High ILmicrosoft 365c&ccalendar
threat-intel New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery Kaspersky researchers have uncovered a sophisticated new module, Project CAV3RN, leveraging Outlook calendar events accessed through Microsoft Graph for C2 communication and DNS AAAA records to recover configuration data… Securelist · Jul 21, 2026 High ISc2microsoftdns
threat-intel Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A Russian-speaking threat actor, “bandcampro,” leveraged Google Gemini CLI to orchestrate a botnet and conduct various cybercrime activities, including dental clinic control and cryptocurrency fraud. The actor utilized t… The Hacker News · Jul 20, 2026 High USCARUaicybercrimebotnet
supply-chain Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT A sophisticated software supply chain attack, dubbed ViteVenom, is leveraging a blockchain-based command-and-control (C2) infrastructure to deliver a remote access trojan (RAT) targeting Vite frontend developers. The att… The Hacker News · Jul 17, 2026 High supply chainblockchainc2
threat-intel New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage A previously undocumented Go-based malware, GoSerpent, has been actively targeting government and diplomatic entities in Southeast Asia since 2021, with a renewed surge in activity in 2026. Developed by the threat actor… The Hacker News · Jul 17, 2026 High BAAPmalwareespionagedata theft
threat-intel GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration A sophisticated, evolving threat actor, potentially linked to TetrisPhantom, has been targeting government and diplomatic entities in Southeast Asia since late 2025 with a campaign utilizing tools like GoSerpent, Stowawa… Securelist · Jul 16, 2026 High VNTHproxyremote accessdata exfiltration
threat-intel 20+ Hijacked Government Websites Became an Attack Channel A sophisticated campaign, dubbed PhantomEnigma, has hijacked over 20 Brazilian government websites to deliver malware and conduct attacks against banks and public agencies. Attackers leveraged compromised .gov.br infrast… The Hacker News · Jul 16, 2026 High BRgovernmentphishingmalware
threat-intel UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign A sophisticated, Russian-speaking threat actor, UAT-11795, has been conducting a financially motivated campaign targeting users in the U.S. and Europe since June 2025. The campaign utilizes a novel combination of tools,… Cisco Talos · Jul 16, 2026 High USGEROclickfixsocial engineeringc2
threat-intel TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Researchers at Palo Alto Networks Unit 42 have uncovered TuxBot v3 Evolution, a developing IoT botnet framework leveraging AI assistance. While the LLM provided some code, it also introduced errors that needed manual cor… The Hacker News · Jul 15, 2026 High iotbotnetddos
threat-intel GigaWiper Lets Threat Actors Choose Their Own Destructive Attack GigaWiper is a novel, modular malware that combines backdoor and wiper capabilities, allowing attackers to choose how to destroy a targeted system while minimizing their operational footprint. Initially identified as a G… Dark Reading · Jul 13, 2026 High IRRUVEwiperbackdoormodular
threat-intel New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic A China-linked cybercrime group, Silver Fox, is using a new Rust-based remote access trojan called MODBEACON to target technology, education, and state-owned enterprises in Asia. The trojan utilizes gRPC streaming for en… The Hacker News · Jul 10, 2026 High CNrustgrpcc2
threat-intel SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraud operation, tracked as REF6045, is targeting Mexican banks, fintech companies, and cryptocurrency exchanges using a malware toolset called SCMBANKER. The operation leverages fake CAPTCHA verification p… The Hacker News · Jul 8, 2026 High MXbankingmalwarephishing
threat-intel China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware A Chinese APT group, UAT-7810, is expanding its Operational Relay Box (ORB) network by utilizing custom malware, including LONGLEASH and LEASHTEST, to establish persistent access for secondary threat actors. The group le… The Hacker News · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717TWaptmalwarec2
threat-intel UAT-7810 continues building ORB networks using new malware Cisco Talos Intelligence has identified UAT-7810, a China-nexus APT group, continuing to develop and deploy malware as part of its Operational Relay Box (ORB) network. The group is actively creating new malware variants,… Cisco Talos · Jul 7, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CHaptmalwarechina
threat-intel Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations Iranian hackers, linked to Iran's Ministry of Intelligence and Security (MOIS) and operating under the moniker Cavern Manticore, are utilizing a new, modular command-and-control (C2) framework called ‘Cavern’ to target I… The Hacker News · Jul 6, 2026 High CVE-2025-52691CVE-2025-68613CVE-2025-9316ISIRc2command and controldotnet
malware The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign A large-scale cyber campaign utilized the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware onto compromised systems. Threat actors disguised installers of popular software like OBS Studio and DNS Ju… Securelist · Jul 1, 2026 High GDremote accessdll sideloadingpersistence
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia
threat-intel Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses The Russian cyber espionage group Gamaredon (also known as Aqua Blizzard) has significantly upgraded its arsenal and tactics, becoming a more effective threat actor, particularly in support of the war in Ukraine. The gro… Dark Reading · Jun 25, 2026 High RUUKaptespionagec2
supply-chain OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat This report details a significant supply chain attack leveraging OpenClaw’s Skill Marketplace, highlighting the emerging threat of AI agentic software. Malicious skills, including infostealers and evasion techniques, wer… Palo Alto Unit 42 · Jun 23, 2026 High USaiagenticsupply chain
threat-intel Windows version of SprySOCKS Linux malware used to attack govt orgs Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva… BleepingComputer · Jun 16, 2026 High CVE-2023-24932TWTHPKlinuxstealthbackdoor