P7 DarkSword iOS Exploit Kit: Bidirectional C2 and Crypto-Wallet Targeting
The P7 DarkSword iOS exploit kit, discovered in August 2026, is a memory-resident malware-as-a-service that leverages dyld_insert_library for in‑memory payload execution, bypassing iOS code‑signing, and persists via a masqueraded launchd plist (com.apple.securityd.plist). It establishes bidirectional C2 over TLS 1.3/WebSocket, uses private Security.framework APIs to dump Keychain credentials, and scans for MetaMask, Trust Wallet, and Coinbase Wallet to steal seed phrases and private keys, encrypting loot with AES‑256‑GCM for exfiltration to /api/v1/collect.
Graphalgo Campaign Targets HashiCorp Terraform Registry via Malicious Go-Based Providers
The Graphalgo campaign involves the distribution of malicious Go modules and Terraform providers via the HashiCorp Terraform Registry. Threat actors, attributed to a DPRK-linked group, utilize fake job application lures to induce the initialization of compromised providers such as gocommunity-io/dockerd and kreuzwenker/terraform-provider-vault. These modules execute obfuscated init routines and goroutines to deploy a Go-compiled Remote Access Trojan (RAT) and establish reverse TCP shells. The campaign has affected over 120 organizations through 379 observed downloads, facilitating credential theft, persistence via cron, and lateral movement within CI/CD pipelines.
QTYF Threat Group Utilizes qscan and qtrouter to Breach US Federal Agencies via IoT Botnets
The Chinese state-sponsored threat group QTYF conducted a sophisticated espionage campaign targeting the US Department of Justice, NASA, the Federal Reserve, and the US Senate. The actors deployed a global botnet of hijacked IoT devices—including routers and smart appliances—to mask their origins and provide a resilient C2 infrastructure. Using custom binaries qscan for network reconnaissance and qtrouter for traffic obfuscation and routing, QTYF successfully exfiltrated high-value national security and economic data. The operation was disrupted through FBI-led domain seizures and the neutralization of the core routing toolsets.