Quishing (QR Code Phishing) to bypass email security and MFA
Integration of local LLMs (Ollama, GPT4All, Msty) for malware development and data analysis
Supply chain attacks targeting software vendors to reach downstream customers
Abuse of Git-based repositories (GitHub/GitLab) for C2 infrastructure (Operation GitPower)
Spoofing of legitimate security software installation pages and Webex meetings
Session token theft and replay for cloud identity hijacking
DMARC spoofing to conceal spear-phishing origins
Deployment of custom malware including Gomir (Linux), Durian (Golang), and HTTPSpy
Use of .msc (MMC) files disguised as documents to execute shellcode