DCRat Campaign Leverages SVG Files and HTML Smuggling for Malware Delivery
Threat actors are deploying a DCRat (Remote Access Trojan) campaign utilizing social engineering and HTML smuggling to bypass traditional perimeter defenses. The attack vector involves phishing emails containing malicious SVG (Scalable Vector Graphics) files, often disguised as legal notifications. Upon being opened in a web browser, the SVG leverages JavaScript-based Blob objects to reconstruct a compressed malware archive locally on the endpoint. This client-side reconstruction allows the payload to evade network-based inspection and secure email gateways. Once deployed, the DCRat payload may utilize memory injection techniques to establish persistence, granting attackers unauthorized remote control and data exfiltration capabilities.
Iranian APT42 and APT35 Utilizing LLMs for AI-Augmented Spear-Phishing and Tamecat Malware Deployment
Iranian state-sponsored threat actors APT42 and APT35 (linked to the IRGC) are integrating Large Language Models (LLMs) to automate and refine spear-phishing campaigns. By leveraging Generative AI, these actors produce linguistically precise lures that evade traditional natural language processing (NLP)-based detection. Technical execution involves the deployment of Tamecat, a PowerShell-based backdoor, and EP3 malware to establish persistent access within high-value targets, including U.S. government officials and critical infrastructure. This tactical evolution shifts from manual social engineering to scalable, AI-driven reconnaissance and weaponized phishing, significantly increasing the efficacy of initial access attempts against geopolitical adversaries.
Midnight Blizzard and the 'CaptiveCrunch' Campaign Targeting Microsoft 365 via Hotel WiFi
The "CaptiveCrunch" campaign, attributed to the Russian state-sponsored actor Storm-2945 (a Midnight Blizzard sub-cluster), targets global travelers by compromising hospitality WiFi gateways. The attack utilizes DNS hijacking and poisoning to redirect users from legitimate captive portals to malicious, Microsoft-themed phishing sites. This redirection facilitates two primary objectives: the theft of Microsoft 365 credentials through OAuth token interception and the deployment of the CornFlake Remote Access Trojan (RAT). CornFlake enables persistent endpoint surveillance, including keystroke logging and audio/visual interception. This sophisticated operation, active since May 2026, represents a high-severity threat to enterprise users traveling internationally.
Kimsuky Integration of Local LLMs Ollama, GPT4All, Msty and GitHub C2
Kimsuky, a North Korean-linked threat actor, is evolving its social engineering and command-and-control (C2) methodologies through the integration of local Large Language Models (LLMs) and developer-centric infrastructure. By utilizing local frameworks such as Ollama, GPT4All, and Msty, the group generates high-fidelity AI-driven decoy documents to enhance spear-phishing efficacy while maintaining operational security against cloud-based monitoring. Concurrently, Kimsuky is leveraging GitHub and Git for C2 communication and payload distribution, alongside "Living-off-the-Land" (LotL) techniques using PowerShell and LNK files. This shift from manual phishing to AI-augmented, infrastructure-obfuscated operations targets diplomatic, military, and cryptocurrency sectors, necessitating a transition from signature-based detection to advanced behavior-based EDR and SaaS usage monitoring.
North Korean Threat Actors Deploy PylangGhost and GolangGhost via Sophisticated Job Interview Scams
North Korean state-sponsored actors, identified as PurpleBravo and Chollima, are executing highly targeted social engineering campaigns against the IT software supply chain. Utilizing fake recruitment processes, attackers trick developers into executing malicious files disguised as technical coding assessments or job-related documentation. This campaign introduces PylangGhost, a Python-based evolution of the GolangGhost Remote Access Trojan (RAT), enabling cross-platform execution on both Windows and macOS. The deployment of these language-specific RATs facilitates long-term espionage, intellectual property theft, and lateral movement within sensitive development environments by leveraging the inherent trust in professional recruitment workflows and bypassing traditional detection through Go and Python implementations.
Dismantling the Kratos Phishing-as-a-Service Infrastructure Targeting Microsoft
A multinational law enforcement operation led by Germany's BKA and ZIT, in coordination with the US and Indonesia, has neutralized the Kratos (aka SneakyLog/Sneaky 2FA) Phishing-as-a-Service (PhaaS) infrastructure. The operation resulted in the seizure of over 200 servers and the arrest of a primary administrator in Indonesia. Kratos leveraged Adversary-in-the-Middle (AiTM) proxying to intercept Microsoft 365 authentication flows, enabling the theft of session tokens to bypass multi-factor authentication (MFA). While the backend infrastructure is offline, approximately 1,800 active affiliates retain access to target lists and may migrate to alternative PhaaS kits, maintaining the operational threat level.
The Dismantling of SniperDz Phishing-as-a-Service PhaaS Infrastructure
Operation Ramz, a coordinated international law enforcement initiative, successfully dismantled SniperDz, a prolific Phishing-as-a-Service (PhaaS) platform that maintained operational longevity for approximately one decade. Conducted between October 2025 and February 2026, the operation targeted the platform's core infrastructure and its extensive affiliate network across the Middle East and North Africa (MENA) region. The campaign resulted in the arrest of the primary developer and administrator, "Guedz," along with 201 affiliates. This takedown neutralizes a significant source of scalable phishing payloads and credential harvesting capabilities that have historically facilitated widespread identity theft and financial fraud.
Luxembourg State Workstations Targeted by Socgholish, Amadey, and StealC Malware
Luxembourg state workstations were targeted by a coordinated cyber-espionage campaign timed with the nation's National Day. Attackers utilized spear-phishing emails to deploy Socgholish (FakeUpdates) as an initial access broker, which subsequently loaded Amadey for persistence and StealC for credential exfiltration. The infection chain focused on harvesting administrative credentials and government metadata from public sector infrastructure. The campaign was neutralized through a global disruption operation led by Europol in collaboration with GovCERT.lu, CIRCL, and CERT-EU, resulting in the dismantling of the Amadey and StealC command-and-control (C2) infrastructure.
AI-Orchestrated Phishing Campaigns Targeting the Financial Sector
A new wave of AI-orchestrated phishing campaigns is targeting the global financial sector, utilizing Large Language Models (LLMs) and deepfake synthesis to bypass legacy security perimeters. Attackers are deploying high-velocity automation, executing campaigns at an observed rate of one attack every 19 seconds. Technical vectors include Device Code Phishing designed to hijack OAuth authentication flows, AI-generated malware tailored for financial environments, and sophisticated brand impersonation that evades linguistic-based spam filters. This paradigm shift from manual templates to high-fidelity, automated social engineering significantly increases the success rates of Business Email Compromise (BEC) and session hijacking.
EvilTokens: AI-Enhanced OAuth 2.0 TaaS Phishing Targeting Microsoft 365
Threat actors are utilizing "EvilTokens," a Token-as-a-Service (TaaS) framework, to compromise Microsoft 365 accounts by exploiting the OAuth 2.0 Device Code Flow. By tricking users into authorizing malicious Client IDs on legitimate Microsoft authentication pages, attackers bypass Multi-Factor Authentication (MFA) to acquire session-persistent access and refresh tokens. The campaign is scaled via the ArToken affiliate panel and leverages AI for personalized lure generation. This methodology enables long-term persistence and complete account takeover (ATO) without requiring the victim's password, effectively neutralizing traditional identity-based security controls.
The Operationalization of Criminal AI-as-a-Service: FraudGPT, BruteForceAI, and Xanthorox
The 2026 threat landscape is defined by the operationalization of Criminal AI-as-a-Service (C-AIaaS), utilizing platforms like FraudGPT, BruteForceAI, and Xanthorox to compress the attack lifecycle. Technical vectors include specialized jailbreak wrappers for LLM safety bypass and virtual camera injection for real-time deepfake KYC bypass. Attackers leverage hijacked enterprise API keys for unauthorized compute and use LLMs to systematically analyze exfiltrated RAG embeddings. This shift has reduced average eCrime breakout times to 29 minutes and increased phishing click-through rates to 54% by eliminating traditional linguistic indicators of fraud.
Remcos RAT Deployment via Multi-Stage .NET Steganography in GST Phishing Campaigns
A sophisticated, financially motivated cybercrime campaign is targeting the Indian financial and taxation ecosystem by impersonating the Government of India's GST department. The attack leverages high-pressure social engineering via spoofed emails regarding "GST refund applications" to trick taxpayers into downloading malicious archives. Once executed, the malware initiates a multi-stage .NET infection chain utilizing advanced evasion techniques, including bitmap steganography for payload concealment and in-memory execution via .NET reflection to maintain a fileless footprint. The operation culminates in the deployment of Remcos RAT, granting attackers full remote command and control (C2) for credential theft, surveillance, and data exfiltration, while employing architecture-specific execution paths to ensure successful deployment across x86 and x64 systems.
Palo Alto Networks: The Transition to AI-Accelerated Exponential Attack Cycles
The cybersecurity landscape is undergoing a fundamental paradigm shift as Large Language Models (LLMs) evolve from passive assistants to primary operational drivers across the entire attack lifecycle. Threat actors are leveraging high-speed AI to compress weaponization windows, transforming vulnerabilities into functional exploits within hours of disclosure. This transition is characterized by the rapid development of sophisticated malware, such as the VoidLink remote control toolkit and The Gentlemen ransomware platform, and a tactical migration from heavily guarded Western models to less-restricted Chinese-origin models like DeepSeek and Qwen. The resulting "exponential attack cycle" necessitates a radical shift in defensive remediation timelines and detection capabilities to counter automated, high-fidelity threat generation.
PamStealer: macOS Information Stealer Impersonating Maccy Clipboard Manager
PamStealer is a specialized macOS information stealer that leverages social engineering to distribute a malicious clone of the open-source Maccy clipboard manager. The attack chain initiates through fraudulent websites hosting a malicious compiled AppleScript (.scpt) file, which acts as a primary loader to bypass initial macOS security hurdles. This loader facilitates the deployment of a secondary payload, likely authored in Rust, designed for high-performance data exfiltration. The malware specifically targets sensitive information including system-level credentials, metadata, and real-time clipboard contents, posing a critical risk to macOS users seeking productivity-enhancing open-source utilities.
Kali365 Phishing Kit: MFA Bypass Targeting Microsoft 365, AWS, and Okta
The FBI has issued a critical alert regarding the Kali365 phishing kit, a sophisticated tool designed to compromise enterprise cloud environments. Utilizing Adversary-in-the-Middle (AiTM) techniques, the kit intercepts authentication traffic to harvest credentials and steal active session tokens, effectively bypassing multi-factor authentication (MFA) protocols. The campaign specifically targets Microsoft 365 (Outlook, Teams, OneDrive), Amazon Web Services (AWS), and Okta identity providers. Successful exploitation grants threat actors deep access to corporate communications and critical cloud infrastructure, enabling large-scale data exfiltration and the compromise of organizational identity management systems.
WhatsApp Blocks NSO Group Pegasus Spyware Campaign
Meta has intercepted a targeted spear-phishing campaign by NSO Group aimed at deploying Pegasus spyware to WhatsApp users in Jordan and Lebanon. The attack utilizes sophisticated social engineering templates and malicious redirection URLs to bypass traditional security controls and achieve device compromise. This campaign directly violates a 2025 permanent federal injunction against NSO Group. In response, Meta is pursuing legal contempt motions to enforce judicial orders, moving beyond technical disruption to aggressive litigation to protect user privacy and platform integrity.
U.S. State Department Issues $10M Bounty Targeting UNC5792 and UNC4221 via Signal and WhatsApp Phishing Campaigns
The U.S. Department of State has announced a $10 million reward for actionable intelligence identifying Russian-linked threat actors UNC5792 and UNC4221. These actors focus on bypassing end-to-end encryption (E2EE) on Signal and WhatsApp through sophisticated account takeover (ATO) workflows. By utilizing advanced social engineering, credential harvesting, and session hijacking, the groups compromise mobile identities of high-value targets, including military and diplomatic personnel. The campaign targets the application layer to circumvent cryptographic protections, facilitating large-scale intelligence exfiltration from mobile endpoints. This shift toward identity-centric exploitation bypasses traditional network perimeter defenses, necessitating enhanced hardware-backed authentication and mobile-specific threat intelligence.
Armored Likho and the BusySnake Stealer Campaign
Armored Likho (also provisionally identified as Eagle Werewolf) is conducting a sophisticated dual-purpose campaign combining cyber espionage with financially motivated theft. The actor targets government agencies and the electric power sector, alongside private individuals, primarily in Russia, Brazil, and Kazakhstan. The technical execution involves spear-phishing and the use of AI-generated loaders to deploy BusySnake Stealer, a novel Python-based malware. By integrating the PolitePaul service into its delivery chain, the group demonstrates an ability to blend high-stakes APT tactics with commodity-style credential theft to maximize impact across both strategic and financial domains.
Adaptive Phishing Kits and BlueKit Browser-in-the-Middle BitM Frameworks
Modern phishing campaigns are deploying adaptive kits that utilize client-side JavaScript fingerprinting (User-Agent, OS, screen resolution) to serve device-specific HTML/CSS templates, increasing social engineering success rates. These kits employ Browser-in-the-Middle (BitM) frameworks, such as BlueKit, and OAuth/OIDC Device Code phishing to intercept real-time session cookies and MFA tokens, effectively bypassing traditional multi-factor authentication. Attackers utilize DNS query manipulation and environment-aware checks to evade automated sandboxes and security crawlers. The impact is a significant reduction in MFA efficacy and increased detection difficulty for legacy indicator-based security tools.
GREYVIBE Leverages ChatGPT and Google Gemini for AI-Augmented Operations against Ukraine
Russia-aligned threat group GREYVIBE is utilizing OpenAI's ChatGPT and Google Gemini to facilitate "capability equalization" during cyber offensive operations against Ukrainian infrastructure. By integrating large language models (LLMs) into the cyber kill chain, the actor automates the generation of linguistically precise phishing lures, develops malware-related scripts, and streamlines post-compromise reconnaissance and lateral movement. This AI-augmented workflow enables the concurrent execution of five parallel attack chains, significantly reducing the technical skill barrier and operational cost-per-attack. The campaign demonstrates a strategic shift toward using commercial AI to mimic APT-level sophistication, posing an increased threat to critical sectors in Ukraine.
CrySome RAT: Analysis of Targeted Logistics Sector Infection Chain
LevelBlue SpiderLabs has identified a sophisticated spear-phishing campaign targeting the logistics and supply chain sectors via the deployment of the CrySome Remote Access Trojan (RAT). The attack utilizes social engineering, specifically leveraging fraudulent "rate confirmation" documents to exploit established business workflows. The infection follows a multi-stage execution flow, moving from initial document execution through various dropper payloads to establish persistent remote access. Successful compromise grants attackers high-level control over the host, enabling lateral movement and unauthorized data exfiltration within corporate networks.
Phantom Squatting: Exploiting LLM Hallucinations for Phishing and Supply Chain Attacks
Phantom squatting is a novel attack vector that exploits the deterministic nature of Large Language Model (LLM) hallucinations. Unlike traditional typosquatting, attackers identify non-existent but plausible domains and package names generated by LLMs and pre-register them. This enables two primary exploitation paths: directing users to malicious phishing landing pages via hallucinated URLs and compromising developer environments through the installation of rogue software packages on repositories like npm and PyPI. Because these domains lack a legitimate predecessor, they effectively evade conventional brand-protection and lookalike-domain monitoring tools, leveraging the inherent authority bias users place in AI-generated technical guidance.
Evolution of Chinese PhaaS: Darcula UNC5814 and YY Lai Yu Transition to OTP Interception and Digital Wallet Tokenization
Chinese-language Phishing-as-a-Service (PhaaS) platforms, specifically Darcula (operated by UNC5814) and YY Lai Yu, have evolved from simple credential harvesting to sophisticated automated financial fraud. These platforms utilize real-time Man-in-the-Middle (MitM) modules to intercept One-Time Passcodes (OTP), effectively neutralizing traditional Multi-Factor Authentication (MFA). Furthermore, the integration of digital wallet tokenization engines allows attackers to convert stolen payment card data into mobile wallet tokens. This technical shift enables the execution of transactions that mimic legitimate, pre-authorized mobile wallet payments, successfully bypassing legacy fraud detection systems that monitor raw credit card numbers.
FIFA World Cup 2026: Multi-Tiered Cyber Threat Landscape
The upcoming FIFA World Cup 2026 is emerging as a massive attack surface spanning the USA, Canada, and Mexico, attracting a spectrum of threat actors. Adversaries are deploying multi-stage campaigns ranging from typosquatted phishing domains and social engineering lures to distribute info-stealers and ransomware. Technical vectors include the exploitation of third-party ticketing APIs, hospitality booking platforms, and the deployment of sports-themed Command and Control (C2) infrastructure to evade detection. High-impact targets include critical transportation and power infrastructure via state-aligned actors, and the logistics/hospitality sectors via ransomware, presenting significant risks to operational continuity, PII integrity, and national security during the event.
Interpol-Impersonation Campaign Deploying IcedID, Qakbot, and Custom Ransomware
Threat actors are executing a targeted phishing campaign impersonating Interpol to compromise small business networks. The attack chain leverages high-pressure social engineering to deliver IcedID and Qakbot initial access trojans (IATs), which are utilized for credential theft and lateral movement within the environment. The final stage involves the deployment of custom ransomware designed for data encryption and operational disruption. Notably, security researchers discovered decryption keys embedded within the ransomware payload, indicating a critical implementation flaw or a specific behavioral pattern in the malware's deployment logic.
LLM-Driven Phishing Campaigns Targeting Global Financial Services
Threat actors are leveraging Large Language Models (LLMs) to automate hyper-personalized phishing campaigns, targeting the global financial sector with unprecedented velocity. By utilizing AI-driven reconnaissance and LLM-generated lures, attackers are successfully evading traditional keyword-based and template-matching detection mechanisms. This transition from bulk spam to automated precision targeting facilitates Business Email Compromise (BEC) 2.0 through deepfake audio/video assets and AI-optimized malware variants designed to bypass behavioral heuristics. The current attack velocity has reached one attempt every 19 seconds, significantly increasing the operational cost of defense for financial institutions despite improved SOC response speeds.
ChatGPT: ChatGPhish Markdown Rendering Vulnerability
The "ChatGPhish" vulnerability is a high-severity indirect prompt injection flaw residing in the ChatGPT web interface's Markdown rendering engine. By leveraging the model's web-browsing and summarization capabilities, an attacker can host malicious Markdown/HTML payloads on an external webpage. When ChatGPT processes this URL, the renderer interprets the untrusted content as legitimate UI elements within the chatgpt.com domain. This facilitates "trust-transfer" attacks, allowing adversaries to inject spoofed security alerts, fraudulent hyperlinks, and phishing QR codes directly into the user's trusted session, aiming for credential theft and session hijacking via sophisticated social engineering.
Deployment of AZUREVEIL/Adaptix C2 Agent via "Operation Dragon Weave"
China-aligned threat actors have launched "Operation Dragon Weave," a sophisticated cyber espionage campaign targeting high-value sectors, including government, research, academic, technology, and financial services. The campaign utilizes highly targeted spearphishing emails to deliver malicious ZIP archives containing deceptive shortcut (.LNK) files masquerading as legitimate documents. Upon execution, these files deploy the AZUREVEIL malware framework, which leverages the Adaptix Command-and-Control (C2) agent to establish persistent communication with actor-controlled infrastructure. The campaign demonstrates a strategic geographic focus on the Czech Republic and Taiwan, aiming for long-term intelligence gathering and unauthorized access within critical infrastructure and academic networks.
ChatGPT Share Links Exploited to Bypass Security Filters and Deliver Infostealers
Threat actors are leveraging the ChatGPT "shared chat" feature to execute a sophisticated phishing campaign that bypasses corporate security infrastructure. By hosting fraudulent service outage notifications on the trusted chatgpt.com/share/ domain, attackers utilize domain reputation hijacking to circumvent Secure Web Gateways (SWG) and URL filters. The campaign redirects targets to download malicious, fake ChatGPT desktop applications for Windows (.exe) and macOS (.dmg/.pkg). These payloads deliver infostealer malware designed to exfiltrate browser cookies, session tokens, and sensitive system credentials, posing a critical risk of account takeover (ATO) and large-scale corporate data exfiltration.
The Dismantling of Scattered Spider: Tyler Robert Buchanan's Guilty Plea and Identity-Centric Attack Vectors in Cloud and MFA Environments
The formal guilty plea of Tyler Robert Buchanan marks a significant legal strike against the Scattered Spider threat group, exposing the devastating effectiveness of human-centric identity attacks. This case highlights the critical failure points in traditional multi-factor authentication (MFA) and underscores the urgent necessity for organizations to transition toward phishing-resistant security architectures.