3 verified findings from 1 run · the settled record for this UTC day, in the classic brief order.
HIGH
Microsoft Threat Intelligence and Sonatype each documented coordinated npm dependency-confusion campaigns in the window, both distinct from the Mini Shai-Hulud / TrapDoor typosquat activity covered last week. Microsoft (published 2026-05-30) detailed malicious packages pushed in two bursts on 28–29 May by three maintainer aliases (mr.4nd3r50n, ce-rwb, t-in-one); its post is titled for the initial 33, while the body enumerates 45 across the two waves (26 + 7 + 12 by alias), impersonating internal packages across nine organisational scopes and spoofing internal-infrastructure URLs (GitHub Enterprise, Jira, docs portals) in package.json homepage/repository/bugs fields to survive manual review (Microsoft Threat Intelligence, 2026-05-30). The vector is classic dependency confusion: packages published to the public registry under inflated versions (100.100.100, 3.5.22) win npm's resolution race against private-registry equivalents whenever the consuming project's .npmrc is not scope-locked. The postinstall stager (obfuscator.io, ~7–13 KB across the two waves) carries a kill switch (T_IN_ONE_NO_TELEMETRY) and a run-once marker (~/.cache/._t-in-one_init/), fingerprints OS, and specifically detects CI/CD environments before pulling a second-stage reconnaissance payload, a two-phase design that profiles before any credential theft, frustrating payload-signature detection. Microsoft reports the offending repositories and accounts were taken down.
Separately, Sonatype documented a larger 176-package campaign (tracked Sonatype-2026-003429) using version 99.99.99 to beat private-registry precedence, with postinstall scripts likewise targeting developer and CI/CD environments; Sonatype reported Russian-language comments and coordinated infrastructure across the package set (Sonatype, 2026-05-28). The language artefact is Sonatype's observation, not an attribution. Mapped to T1195.002 Compromise Software Supply Chain with discovery TTPs (T1082, T1083, T1614) in the recon payload.
Why it matters to us: Any organisation that consumes private npm packages internally and has not scope-locked .npmrc is in scope, Swiss/EU eGovernment software factories and research institutions maintaining internal Node.js tooling included, and the CI/CD-detection logic specifically flags build pipelines as higher-value follow-on targets.
HIGH
SANS ISC handler Brad Duncan published a same-day forensic diary (2026-06-01) reconstructing an infection observed on 2026-05-27 that began with the SmartApeSG ClickFix campaign (fake browser-verification / "press Win+R" lures served from compromised pages) and ended in a full NetSupport Manager RAT deployment (SANS ISC, 2026-06-01). The ClickFix execution (T1204.001) drops a ZIP carrying an unnamed staging RAT that, per Duncan, has been beaconing a custom encoded, not TLS protocol over TCP/443 to its C2 since at least April 2026; that staging RAT then fetched the NetSupport payload as a ~17 MB Microsoft Cabinet (setup.cab). The install chain is processor.vbs (a 109-byte VBScript launcher in C:\ProgramData\, T1059.005) → token.bat (extracts the CAB into C:\ProgramData\UpdateInstaller\, sets persistence, then self-deletes all three dropper components, T1070.004) → NetSupport RAT C2 over port 443 (T1219 Remote Access Tools). Because NetSupport is legitimate commercial software, its presence and traffic blend with benign remote-support telemetry.
This is a single-source handler diary (HIGH-reliability source, single-day observation) and carries no independent corroboration of the identical chain in-window, treat the specifics as one analyst's forensic account. Detection concepts a SOC can apply without IOCs: browser process (chrome.exe/msedge.exe/firefox.exe) spawning wscript.exe/mshta.exe/cmd.exe (Sysmon EID 1 with browser parent-image); short-lived .vbs/.bat file-creates in C:\ProgramData\ (Sysmon EID 11); CAB expansion via expand.exe/wusa.exe from ProgramData; and registry Run-key persistence pointing at a non-standard NetSupport path (C:\ProgramData\UpdateInstaller\ rather than the legitimate C:\Program Files\NetSupport\). Where TLS inspection is in place, unencrypted payload on port 443 from a NetSupport process is anomalous.
HIGH
Background. The commercial-spyware conversation in Europe has been dominated by high-tier zero-click vendors, NSO Group's Pegasus and, in Italy specifically, Paragon Solutions' Graphite, whose contract with Italian intelligence agencies was terminated after public disclosure earlier in the Paragon scandal. European Digital Rights (EDRi) and the Italian NGO Osservatorio Nessuno have now documented the layer beneath that headline market: a domestic, low-cost Android-trojan industry that achieves persistent surveillance without any exploit at all (EDRi, 2026-05-28). The technical analyses of the two named tools (Morpheus and Spyrtacus) were published by Osservatorio Nessuno in April 2026 and resurfaced in late-May 2026 regional reporting; this deep dive is built on those primary investigations.
The two tools and who builds them. Morpheus (version 2025.3.0 analysed) is linked to IPS Intelligence (IPS Public Security S.p.A.) (Osservatorio Nessuno, Morpheus, 2026-04-23); Spyrtacus is actively developed by SIO S.p.A. and, per Osservatorio Nessuno's separate analysis, relies on DexGuard obfuscation and an InMemoryDexClassLoader loading stage rather than Morpheus's Accessibility-driven approach (Osservatorio Nessuno, Spyrtacus, 2026-04-09). Both are Android implants delivered by social engineering (fake carrier-update SMS or impersonated apps requiring only a user-initiated install) rather than by a zero-day, which is precisely why they are cheap and why they evade the assumption that "no exploit, no compromise."
Mechanics, privilege without a vulnerability. The infection chain is an abuse chain, not an exploit chain. Morpheus uses a two-stage model that leans on three legitimate Android subsystems: the Accessibility Services API, overlay permissions (SYSTEM_ALERT_WINDOW), and Android Debug Bridge (ADB). Once a user grants Accessibility (the single consent the whole chain hinges on) the implant programmatically self-grants further dangerous permissions and drives the UI, an elevation-by-design pattern mapped to T1626 Abuse Elevation Control Mechanism and T1516 Input Injection. Concretely, Morpheus spoofs a biometric-prompt overlay on top of WhatsApp's account-linking screen to pair an attacker device (capturing the linked session), records audio and video, and, notably for hunt teams, disables the camera and microphone privacy indicators by issuing device_config settings via ADB, and actively terminates installed mobile-AV products (Bitdefender, Sophos, Avast, AVG, Malwarebytes) to protect itself (Osservatorio Nessuno, Morpheus, 2026-04-23). The AV-killing and indicator-suppression are the behaviours most amenable to detection, because they are loud relative to the otherwise-quiet permission abuse.
Scale and the oversight gap; why this is a public-sector story. EDRi reports that Italian prosecutors authorised roughly 5,200 trojan-based interceptions in 2024 alone; a volume far exceeding any other EU member state, at a per-day cost of a few euros, with no centralised oversight: authorisation is local to individual judges, and targets cannot determine which vendor's tool was used or whether authorisation was proper, while EU internal-market rules let these vendors operate across member states with little friction (EDRi, 2026-05-28). EDRi calls for an EU-wide ban on the commercial-spyware trade backed by binding transparency obligations (EDRi, 2026-05-28). For a Swiss/EU public-sector SOC the relevance is twofold: officials, journalists and civil-society contacts are within the documented target class, and the delivery method works against any managed Android fleet because side-loaded APKs (delivered via carrier cooperation or direct messaging) bypass the Play-Store-sourcing assumption that Play Protect enforces.
Detection and hardening for managed Android fleets (no IOCs). The defensible controls are MDM- and MTD-centric, anchored on the consent the implant cannot avoid asking for:
- Alert on any Accessibility Service grant to an APK not on the approved-app list and quarantine the device; this is the chokepoint of the whole chain.
- Treat termination of a registered Mobile Threat Defence / mobile-AV agent within ~30 s of a new APK install as a high-confidence indicator (Morpheus's AV-killing).
- Alert on
SYSTEM_ALERT_WINDOW overlay activity from a non-Play-sourced APK, especially overlays on messaging apps (the WhatsApp biometric-prompt spoof). - Disable ADB over network (
adb tcpip) via MDM policy, and enforce Android Enterprise Fully Managed Device mode so users cannot side-load APKs at all; keep Play Protect enabled and non-killable (Google's March 2026 Play Protect update restricts Accessibility abuse for side-loaded apps). - On the regulatory side, Swiss agencies procuring interception tooling should note the Swiss FADP/
Datenschutzgesetz and Informationssicherheitsgesetz exposure the Italian oversight failure illustrates.
The strategic point for defenders: the cheap end of the commercial-spyware market has industrialised permission abuse as a substitute for exploit development, which moves the detection burden off "patch the zero-day" and onto "govern Accessibility/overlay/ADB consent on the fleet"; a control surface most Android MDM deployments do not yet alert on.