CTIPilot

fingerprint

actor · actor:fingerprint single-source

Self-styled pseudonymous actor Zaufana Trzecia Strona identifies as behind both August 2026's MyDr breach (18.8M Polish patient records) and September 2026's Qbusoft/Medyc SQL-injection breach; attribution rests on ZTS's own reporting and is not independently confirmed by a second assessor (Zaufana Trzecia Strona, 2026-09-24/25).

Coverage timeline
26
first 2026-05-11 → last 2026-09-27
Peak priority
high
11 high · 15 notable
Sources cited
112
58 hosts
Sections touched
4
active-threats, deep-dive, research
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
110
pinned v19.2 · see below
2026-05-1126 appearances2026-09-27

ATT&CK techniques

110 techniques observed across 24 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1592.004Gather Victim Host Information: Client Configurations×1

Adversaries may gather information about the victim's client configurations that can be used during targeting. Information about client configurations may include a variety of details and settings, including operating system/version, virtualization, architecture (ex: 32 or 64 bit), language, and/or time zone.

Evidence: 2026-08-29/german-carriers-imei-leak-call-setup-signaling · ATT&CK page ↗

T1595Active Scanning×1

Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes victim infrastructure via network traffic, as opposed to other forms of reconnaissance that do not involve direct interaction.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1595.002Active Scanning: Vulnerability Scanning×2

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

Resource Development TA0042

T1584.004Compromise Infrastructure: Server×1

Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1588.005Obtain Capabilities: Exploits×1

Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than developing their own exploits, an adversary may find/modify exploits from online or purchase them from exploit vendors.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1608.001Stage Capabilities: Upload Malware×1

Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server.

Evidence: 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-12/sap-august-2026-cve-2026-58231-commerce-cloud-data-hub-rce · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-08-07/ai-api-token-jacking-transfer-station-resale · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1189Drive-by Compromise×1

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

T1190Exploit Public-Facing Application×7
T1195Supply Chain Compromise×3

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

Evidence: 2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-16/node-ipc-npm-package-backdoored-via-expired-domain-account-t · ATT&CK page ↗

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×3

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-16/node-ipc-npm-package-backdoored-via-expired-domain-account-t · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗

T1566Phishing×2

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · 2026-05-11/sms-blaster-smishing-establishing-itself-in-switzerland-port · ATT&CK page ↗

T1566.001Phishing: Spearphishing Attachment×2

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1566.002Phishing: Spearphishing Link×2

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×1

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗

Execution TA0002

T1053.005Scheduled Task/Job: Scheduled Task×2

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1059Command and Scripting Interpreter×5

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-08-12/sap-august-2026-cve-2026-58231-commerce-cloud-data-hub-rce · 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-11/cve-2026-6722-php-soap-use-after-free-in-soap-global-ref-map · ATT&CK page ↗

T1059.001Command and Scripting Interpreter: PowerShell×3

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1059.003Command and Scripting Interpreter: Windows Command Shell×1

Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1059.004Command and Scripting Interpreter: Unix Shell×3

Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux, macOS, and ESXi systems, though many variations of the Unix shell exist (e.g. sh, ash, bash, zsh, etc.) depending on the specific OS or distribution. Unix shells can control every aspect of a system, with certain commands requiring elevated privileges.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · 2026-05-11/cve-2026-6722-php-soap-use-after-free-in-soap-global-ref-map · ATT&CK page ↗

T1059.006Command and Scripting Interpreter: Python×1

Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.

Evidence: 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1204User Execution×1

An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious code by, for example, opening a malicious document file or link. These user actions will typically be observed as follow-on behavior from forms of Phishing.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1204.002User Execution: Malicious File×4

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1204.004User Execution: Malicious Copy and Paste×1

An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×3

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗

Persistence TA0003

T1053.005Scheduled Task/Job: Scheduled Task×2

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-12/sap-august-2026-cve-2026-58231-commerce-cloud-data-hub-rce · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-08-07/ai-api-token-jacking-transfer-station-resale · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1098.001Account Manipulation: Additional Cloud Credentials×1

Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.

Evidence: 2026-08-07/ai-api-token-jacking-transfer-station-resale · ATT&CK page ↗

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1136.001Create Account: Local Account×1

Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗

T1505Server Software Component×1

Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.

Evidence: 2026-05-11/cve-2026-6722-php-soap-use-after-free-in-soap-global-ref-map · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-05-11/cve-2026-6722-php-soap-use-after-free-in-soap-global-ref-map · ATT&CK page ↗

T1543Create or Modify System Process×1

Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.

Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗

T1543.002Create or Modify System Process: Systemd Service×2

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×2

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

T1547.009Boot or Logon Autostart Execution: Shortcut Modification×1

Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗

Privilege Escalation TA0004

T1053.005Scheduled Task/Job: Scheduled Task×2

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1055Process Injection×2

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1068Exploitation for Privilege Escalation×2

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-12/sap-august-2026-cve-2026-58231-commerce-cloud-data-hub-rce · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-08-07/ai-api-token-jacking-transfer-station-resale · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1098.001Account Manipulation: Additional Cloud Credentials×1

Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.

Evidence: 2026-08-07/ai-api-token-jacking-transfer-station-resale · ATT&CK page ↗

T1543Create or Modify System Process×1

Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.

Evidence: 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗

T1543.002Create or Modify System Process: Systemd Service×2

Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×2

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

T1547.009Boot or Logon Autostart Execution: Shortcut Modification×1

Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic links are used to reference other files or programs that will be opened or executed when the shortcut is clicked or executed by a system startup process.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1548.002Abuse Elevation Control Mechanism: Bypass User Account Control×1

Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows a program to elevate its privileges (tracked as integrity levels ranging from low to high) to perform a task under administrator-level permissions, possibly by prompting the user for confirmation. The impact to the user ranges from denying the operation under high enforcement to allowing the user to perform the action if they are in the local administrators group and click through the prompt or allowing them to enter an administrator password to complete the action.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

Stealth TA0005

T1014Rootkit×1

Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware by intercepting/hooking and modifying operating system API calls that supply system information.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1027Obfuscated Files or Information×3

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1036Masquerading×2

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Evidence: 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×5

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗

T1055Process Injection×2

Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1070.006Indicator Removal: Timestomp×1

Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1078Valid Accounts×2

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-12/sap-august-2026-cve-2026-58231-commerce-cloud-data-hub-rce · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×3

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-08-07/ai-api-token-jacking-transfer-station-resale · 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1140Deobfuscate/Decode Files or Information×3

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1218System Binary Proxy Execution×1

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files, indicating that they have been either downloaded from Microsoft or are already native in the operating system. Binaries signed with trusted digital certificates can typically execute on Windows systems protected by digital signature validation. Several Microsoft signed binaries that are default on Windows installations can be used to proxy execution of other files or commands.

Evidence: 2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain · ATT&CK page ↗

T1218.005System Binary Proxy Execution: Mshta×1

Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats leveraging mshta.exe during initial compromise and for execution of code

Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1497.001Virtualization/Sandbox Evasion: System Checks×2

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗

T1564.003Hide Artifacts: Hidden Window×2

Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks.

Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×3

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗

T1620Reflective Code Loading×1

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1622Debugger Evasion×1

Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

Defense Impairment TA0112

T1112Modify Registry×1

Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1553.002Subvert Trust Controls: Code Signing×1

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. The certificates used during an operation may be created, acquired, or stolen by the adversary. Unlike Invalid Code Signature, this activity will result in a valid signature.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗

T1685Disable or Modify Tools×2

Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping specific services, killing processes, modifying or deleting tool configuration files and Registry keys, or preventing tools from updating. This may also include impairing defenses more broadly by disrupting preventative, detection, and response mechanisms across host, network, and cloud environments.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1685.002Disable or Modify Tools: Disable or Modify Cloud Log×1

An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities.

Evidence: 2026-08-07/ai-api-token-jacking-transfer-station-resale · ATT&CK page ↗

Credential Access TA0006

T1003.002OS Credential Dumping: Security Account Manager×1

Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

T1003.005OS Credential Dumping: Cached Domain Credentials×1

Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

T1110Brute Force×1

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1528Steal Application Access Token×4
T1539Steal Web Session Cookie×2

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1552Unsecured Credentials×2

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×3

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · 2026-08-07/ai-api-token-jacking-transfer-station-resale · 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · ATT&CK page ↗

T1552.004Unsecured Credentials: Private Keys×3

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-07/ai-api-token-jacking-transfer-station-resale · 2026-05-23/cve-2026-46333-ssh-keysign-pwn-a-9-year-ptrace-race-in-the-l · ATT&CK page ↗

T1555Credentials from Password Stores×2

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain · 2026-05-16/node-ipc-npm-package-backdoored-via-expired-domain-account-t · ATT&CK page ↗

T1555.003Credentials from Password Stores: Credentials from Web Browsers×2

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.

Evidence: 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · 2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain · ATT&CK page ↗

T1556.006Modify Authentication Process: Multi-Factor Authentication×1

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗

T1558.003Steal or Forge Kerberos Tickets: Kerberoasting×1

Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

Discovery TA0007

T1016System Network Configuration Discovery×1

Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several operating system administration utilities exist that can be used to gather this information. Examples include Arp, ipconfig/ifconfig, nbtstat, and route.

Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗

T1033System Owner/User Discovery×1

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1046Network Service Discovery×2

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods to acquire this information include port, vulnerability, and/or wordlist scans using tools that are brought onto a system.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗

T1049System Network Connections Discovery×1

Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1057Process Discovery×2

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1069.002Permission Groups Discovery: Domain Groups×1

Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

T1082System Information Discovery×3

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1083File and Directory Discovery×2

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-05-24/packagist-supply-chain-wave-laravel-lang-autoloader-backdoor · 2026-05-16/node-ipc-npm-package-backdoored-via-expired-domain-account-t · ATT&CK page ↗

T1497Virtualization/Sandbox Evasion×1

Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1497.001Virtualization/Sandbox Evasion: System Checks×2

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox. If the adversary detects a VME, they may alter their malware to disengage from the victim or conceal the core functions of the implant. They may also search for VME artifacts before dropping secondary or additional payloads. Adversaries may use the information learned from Virtualization/Sandbox Evasion during automated discovery to shape follow-on behaviors.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗

T1614System Location Discovery×2

Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · ATT&CK page ↗

T1622Debugger Evasion×1

Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-08-10/interlock-volatility3-winpmem-credential-theft · ATT&CK page ↗

T1550Use Alternate Authentication Material×1

Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls.

Evidence: 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-05-18/tycoon2fa-after-the-march-2026-takedown-oauth-device-authori · ATT&CK page ↗

Collection TA0009

T1005Data from Local System×1

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.

Evidence: 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1113Screen Capture×1

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.

Evidence: 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1115Clipboard Data×1

Adversaries may collect data stored in the clipboard from users copying information within or between applications.

Evidence: 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1123Audio Capture×1

An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive conversations to gather information.

Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗

T1125Video Capture×1

An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information. Images may also be captured from devices or applications, potentially in specified intervals, in lieu of video files.

Evidence: 2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking · ATT&CK page ↗

T1213Data from Information Repositories×2

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-09-27/qbusoft-medyc-poland-healthcare-breach-fingerprint-actor · 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · ATT&CK page ↗

T1560Archive Collected Data×1

An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the network. Encryption can be used to hide information that is being exfiltrated from detection or make exfiltration less conspicuous upon inspection by a defender.

Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗

Command and Control TA0011

T1001.002Data Obfuscation: Steganography×1

Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control.

Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗

T1071Application Layer Protocol×1

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain · ATT&CK page ↗

T1071.001Application Layer Protocol: Web Protocols×5

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-20/grandoreiro-dll-sideload-inverted-sandbox-check · 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain · ATT&CK page ↗

T1071.004Application Layer Protocol: DNS×1

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1090Proxy×1

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

Evidence: 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1090.001Proxy: Internal Proxy×1

Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use internal proxies to manage command and control communications inside a compromised environment, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between infected systems to avoid suspicion. Internal proxy connections may use common peer-to-peer (p2p) networking protocols, such as SMB, to better blend in with the environment.

Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗

T1090.002Proxy: External Proxy×1

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths to avoid suspicion.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · ATT&CK page ↗

T1090.003Proxy: Multi-hop Proxy×2

Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.

Evidence: 2026-08-07/ai-api-token-jacking-transfer-station-resale · 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1102Web Service×1

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Evidence: 2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055 · ATT&CK page ↗

T1102.001Web Service: Dead Drop Resolver×1

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.

Evidence: 2026-05-22/red-lamassu-calypso-bronze-medley-showboat-jfmbackdoor-telco · ATT&CK page ↗

T1102.002Web Service: Bidirectional Communication×1

Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems can then send the output from those commands back over that Web service channel. The return traffic may occur in a variety of ways, depending on the Web service being utilized. For example, the return traffic may take the form of the compromised system posting a comment on a forum, issuing a pull request to development project, updating a document hosted on a Web service, or by sending a Tweet.

Evidence: 2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack · ATT&CK page ↗

T1105Ingress Tool Transfer×2

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · ATT&CK page ↗

T1219Remote Access Tools×3

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · 2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

T1571Non-Standard Port×1

Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.

Evidence: 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · ATT&CK page ↗

T1572Protocol Tunneling×3

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.

Evidence: 2026-09-03/gambling-goblin-earth-berberoka-gov-apache-seo-fraud · 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-05-29/forticlient-ems-cve-2026-35616-ekz-infostealer-kill-chain · ATT&CK page ↗

T1048Exfiltration Over Alternative Protocol×1

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Evidence: 2026-05-16/node-ipc-npm-package-backdoored-via-expired-domain-account-t · ATT&CK page ↗

T1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol×1

Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.

Evidence: 2026-05-16/node-ipc-npm-package-backdoored-via-expired-domain-account-t · ATT&CK page ↗

T1567Exfiltration Over Web Service×1

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel. Popular Web services acting as an exfiltration mechanism may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to compromise. Firewall rules may also already exist to permit traffic to these services.

Evidence: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · ATT&CK page ↗

T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.

Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗

Impact TA0040

T1496.004Resource Hijacking: Cloud Service Hijacking×1

Adversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks, which may impact hosted service availability.

Evidence: 2026-08-07/ai-api-token-jacking-transfer-station-resale · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm · ATT&CK page ↗

Story timeline

  1. 2026-09-27Qbusoft's Medyc practice-management software, used by Polish healthcare providers, is breached via SQL injection by the same actor behind August's over-18-million-patient MyDr leak
    active-threatsA second Polish health-records vendor falls to the same actor, and it never told the national CERT
  2. 2026-09-03Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network
    deep-diveThe victim domain never changes in the browser bar, a hooked Apache module quietly reverse-proxies matching requests to attacker infrastructure
  3. 2026-08-29German mobile carriers leaked callees' IMEI, device model and OS version to callers during call setup, GSMA confirmed the flaw and warned its 1,000+ member operators worldwide
    researchA phone call alone could fingerprint the callee's device and patch level, and GSMA's warning suggests the gap is not Germany-specific
  4. 2026-08-23Three Russia-nexus espionage clusters compromise European diplomats and academics without malware, by talking targets through app passwords, device-code approvals and WhatsApp device-linking, all of which are legitimate features working as designed
    active-threatsNo exploit and no payload, the victim approves the attacker's session, or issues a credential the second factor never sees
  5. 2026-08-20"Ransom Busters" emails ransomware victims before their incident is public, offering to delete the stolen data for a fee, and the tooling says it is the same affiliate who took it
    active-threatsThe tell is the timing: a recovery offer that arrives while the intrusion is still private is foreknowledge, not marketing
  6. 2026-08-20Grandoreiro's loader decides it is in a sandbox when it finds seven ordinary desktop shortcuts, an inverted environment check, behind a two-hop DLL sideload
    active-threatsThe evasion logic is backwards on purpose: a clean, well-stocked desktop is what makes this malware quit
  7. 2026-08-17PATCHCORD, SHEETCORD and HACKERAI; one espionage cluster runs three different command-and-control channels, two of them inside Google Sheets and GitHub, and persists by rewriting the victim's browser shortcuts
    active-threatsEspionage implants run command-and-control through the Google Sheets API and persist by rewriting browser shortcuts
  8. 2026-08-15Mustang Panda's CoolClient backdoor gains a kernel driver signed with a 2013 certificate that expired in 2014, and it hides the malware's own C2 traffic by hooking the driver Windows uses to report network state
    active-threatsKaspersky documents a previously undocumented CoolClient rootkit driver, deployed only once the implant already holds SCM access and SeTcbPrivilege
  9. 2026-08-13MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion, and because it is a processor, not a controller, the people affected cannot be told directly
    active-threatsA Polish health-records processor confirms an intrusion, and because it is not the data controller it cannot tell the affected people
  10. 2026-08-12CVE-2026-58231, SAP Commerce Cloud: an unauthenticated request to the Data Hub Adapter import endpoint reaches arbitrary code execution (CVSS 10.0), and the fix needs a rebuild and redeploy
    trending-vulnerabilitiesSAP's August patch day is led by a CVSS 10.0 pre-auth code-execution flaw in the Commerce Cloud Data Hub Adapter, fixed only by a rebuild and redeploy
  11. 2026-08-10Interlock ran Volatility3 and WinPmem against a live endpoint to harvest credentials, the responder's own memory-forensics toolkit used in place of a commodity dumper
    active-threatsA ransomware operator acquired a memory image and ran hashdump and cachedump offline against it, leaving traces that look like an IR engagement
  12. 2026-08-07Stolen AI API tokens reach a reselling proxy within minutes, Unit 42 documents the 'transfer station' market and the account-takeover variant that mints its own keys
    researchAn exposed AI API key is a billing incident on a clock: Unit 42 saw one reach a reseller in minutes and run up nearly a million dollars
  13. 2026-08-06ENDLESSDOORS (CVE-2026-66747); twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser's remedy is replacement
    trending-vulnerabilitiesThe implant is not an intrusion; it is a vendor component started by the vendor's own init script
  14. 2026-07-31Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent
    active-threatsThe autonomous agent attacked at scale and landed nothing; the same operator's hand-driven NetScaler exploitation took data from three organisations
  15. 2026-07-14Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerability
    researchMicrosoft maps a year of Salesforce OAuth abuse (vishing consent, supply-chain secret reuse, guest-access Aura abuse) invisible to sign-in detection
  16. 2026-07-11Armored Likho: new APT hits government and electric-power targets with an AI-generated loader and the Python 'BusySnake' stealer
    active-threatsKaspersky names Armored Likho, spear-phishing into an LLM-written loader chain that stages a full Python runtime and a PyArmor-protected stealer
  17. 2026-06-28Netcraft: Bluekit PhaaS uses Browser-in-the-Middle to defeat FIDO2 and Device Bound Session Credentials
    research
  18. 2026-06-13Google sues China-based "Outsider" PhaaS network for weaponising Gemini to mass-produce phishing pages
    research
  19. 2026-05-29FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain
    deep-dive
  20. 2026-05-24Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
    deep-dive
  21. 2026-05-23CVE-2026-46333 ssh-keysign-pwn: a 9-year ptrace race in the Linux kernel reaching root and SSH host keys
    deep-dive
  22. 2026-05-22Red Lamassu (Calypso/Bronze Medley): Showboat + JFMBackdoor telco espionage implant pair
    deep-dive
  23. 2026-05-18Tycoon2FA after the March 2026 takedown, OAuth Device Authorization Grant abuse on Microsoft 365
    deep-dive
  24. 2026-05-16node-ipc npm package backdoored via expired-domain account takeover, 90+ credential categories exfiltrated, three malicious versions, ~3-minute window to detection
    active-threatsnode-ipc npm package backdoored via expired-domain account takeover, 90+ credential categories exfiltrated, three malicious versions, ~3-minute window to
  25. 2026-05-11SMS-blaster smishing establishing itself in Switzerland, portable IMSI-catchers force 2G downgrade, bypass operator SMS filtering
    active-threats
  26. 2026-05-11CVE-2026-6722 PHP SOAP Use-After-Free in SOAP_GLOBAL(ref_map)
    deep-dive

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • active-threats12
  • deep-dive7
  • research5
  • trending-vulnerabilities2

Source distribution

  • attack.mitre.org23 (21%)
  • thehackernews.com9 (8%)
  • bleepingcomputer.com5 (4%)
  • github.com4 (4%)
  • zaufanatrzeciastrona.pl4 (4%)
  • socket.dev3 (3%)
  • acronis.com2 (2%)
  • blog.qualys.com2 (2%)
  • other60 (54%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (112)

Entries about fingerprint (26)

2026-09-27 · view entry permalink →

NOTABLENATOB2

Qbusoft's Medyc practice-management software, used by Polish healthcare providers, is breached via SQL injection by the same actor behind August's over-18-million-patient MyDr leak

Qbusoft Sp. z o.o., the Polish company behind the Medyc practice-management application used by medical clinics across the country, was breached via an SQL-injection vulnerability on 22-23 August 2026; the attackers exfiltrated an "encrypted database archive," per the Inowrocław facility's own breach notice (Zaufana Trzecia Strona, 2026-09-24). Qbusoft itself did not learn of the intrusion until the night of 8-9 September, roughly two and a half weeks later, and had made no public statement of its own as of this reporting, even in response to ZTS's direct press questions sent days earlier; the breach surfaced instead when the Addiction and Psychiatric Treatment Center in Inowrocław notified its own patients that their data had leaked from the Medyc system, the same facility that had earlier notified patients of the unrelated MyDr leak (Zaufana Trzecia Strona, 2026-09-24). Stolen fields include name, surname, national PESEL identity number, residential address, phone number and email address; per the facility's own notice, the name, surname and PESEL fields were stored encrypted, but the vendor had told the facility the encryption was easy to break, so the attackers could still reach that data, and ZTS assesses there is a good chance medical discharge-summary data was taken as well (Zaufana Trzecia Strona, 2026-09-24).

Zaufana Trzecia Strona, the outlet that first revealed August's MyDr breach of more than 18 million Polish patients' records, identifies the actor behind both intrusions as the same self-styled group or individual using the pseudonym "fingerprint": "The perpetrators of the leak are the same people who were behind the attack on the MyDr systems, from which the data of over 18 million Poles was stolen" (translated from Polish) (Zaufana Trzecia Strona, 2026-09-24). A follow-up ZTS post relays the attackers' own claim of far greater scale than the outlet's initial estimate: "we ourselves assessed the scale of the incident at at least a million people; according to the perpetrators it is five million. The perpetrators also mention that they stole 8 million \"very private\" photos" (translated from Polish) (Zaufana Trzecia Strona, 2026-09-25); ZTS states plainly it could not confirm the claimed photo count reached the perpetrators, though it does not dispute that photos of some kind may have been taken, and DataBreaches.net separately notes that whether this is genuinely the same attacker "has not been disclosed" from its own reporting vantage (DataBreaches.net, 2026-09-26); treat the same-actor link as ZTS's own attribution, not an independently confirmed fact. A second ZTS source states that, as with MyDr, Qbusoft's main company resources were stored in cloud services, specifically Microsoft Azure infrastructure, unlike MyDr's AWS-hosted environment (Zaufana Trzecia Strona, 2026-09-25).

Poland's Digital Affairs Minister Krzysztof Gawkowski confirmed the incident and disclosed a notification gap: although Qbusoft reported the intrusion to the Central Office for Combating Cybercrime, it never passed information to CSIRT CEZ, the CERT established specifically for the healthcare sector, or to CERT Polska, the national CERT that coordinated the MyDr incident and holds Poland's deepest incident-response experience (Zaufana Trzecia Strona, 2026-09-25). As of this reporting, the attackers had not published or offered the stolen data for sale, consistent with their pattern after the MyDr breach.

According to information we have, a new large leak of personal and medical data has occurred, this time from the systems of Qbusoft Sp. z o.o., the maker of the Medyc.pl practice application. The perpetrators of the leak are the same people who were behind the attack on the MyDr systems, from which the data of over 18 million Poles was stolen. (translated from Polish)

The Addiction and Psychiatric Treatment Center in Inowrocław reported having received information about a leak of its patients' data from the Medyc system (the same center had earlier reported a leak of its patients' data from the MyDr system, which is bad luck). (translated from Polish)

As we read in the Inowrocław facility's own notice, the attack on Qbusoft took place on 22-23 August of this year. The perpetrators, using an SQL Injection vulnerability, stole an "encrypted database archive." The company learned of the incident on the night of 8-9 September. (translated from Polish)

we ourselves assessed the scale of the incident at at least a million people; according to the perpetrators it is five million. The perpetrators also mention that they stole 8 million "very private" photos. (translated from Polish)

The incident at Qbusoft was also confirmed by Minister Gawkowski, who pointed out that although the victim of the attack informed the Central Office for Combating Cybercrime about it, it did not pass information to either the CSIRT CEZ team, established to handle incidents in the healthcare sector, or to the CERT Polska team, which coordinates the largest incidents and has the greatest experience in Poland in this regard (it handled, among others, the coordination of the incident at MyDr). (translated from Polish)

Zaufana Trzecia Strona 2026-09-24

Whether it’s the same attacker or whether any ransom demand has been involved has not been disclosed.

DataBreaches.net 2026-09-26

Builds on: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap

incident27 Sep 04:34Zmulti-sourceOpen finding ↗

2026-09-03 · view entry permalink →

NOTABLENATOB1

Gambling Goblin (Earth Berberoka overlap): a Chinese-speaking cluster compiles malicious Apache modules on compromised Brazilian .gov.br servers, borrowing their search-engine trust for a global gambling-SEO fraud network

Check Point Research documents Gambling Goblin, a Chinese-speaking cluster it assesses with medium-to-high confidence overlaps Earth Berberoka, first documented by Trend Micro in 2022 targeting gambling platforms serving Chinese-speaking users. Active against Brazilian organisations since mid-2025, primarily government and educational institutions, the operation's distinguishing move is weaponising the search-engine trust of compromised .gov.br domains: navigation tiles on the resulting fraud pages point to dozens of real domains spanning a federal ministry, a national public agency, a state legislative assembly, state courts of accounts, a state utility, and numerous municipal administrations (Check Point Research, 2026-09-02). The technique (compromising a government web server to graft attacker content onto its own trusted domain) is directly transferable to any public-sector web-hosting estate, at any administrative tier, regardless of region.

On an already-compromised Linux host, a Bash installer confirms root, fingerprints the distribution, patches a missing macro, and compiles a custom Apache module (opsproxy.c) via apxs, then deletes the build artefacts and timestomps the resulting .so and its load configuration to match legitimate modules such as mod_ssl or mod_suexec (Check Point Research, 2026-09-02). The module registers at Apache's name-translation stage and inspects every incoming request for a small set of hardcoded URL prefixes (/wps, /bmw, /card in the analysed samples); a match rewrites the request into a reverse proxy to a hardcoded upstream, so the visitor is silently relayed to attacker infrastructure while the request still appears, from the outside, to originate from the legitimate compromised domain (Check Point Research, 2026-09-02). The module also strips the site's own Content-Security-Policy header and replaces it with a permissive one allowing inline/eval'd scripts and third-party assets, so the injected phishing content renders unrestricted. A second, separate Apache module disguises itself as a basic filter, decrypts an RC4-protected ruleset keyed on path/referrer/User-Agent/client-IP, locates the page body via a compiled-in <body.*?> regex, and injects fetched remote content via ap_rwrite, classic SEO-cloaking and content-injection behaviour, distinct from the reverse-proxy module (Check Point Research, 2026-09-02). The upstream phishing pages impersonate Google Play, Microsoft Store and Amazon with fabricated ratings and schema.org metadata, pushing gambling and sports-betting content.

Beyond the Apache modules, the group runs an internet-facing reconnaissance agent (a Go ELF binary wrapping dirprobe, httpx, naabu, nuclei v3, subfinder and whatweb over gRPC C2) to map attack surface, plus a downloader (DownPro) that stages the rest of the toolkit, blending its drop paths into names mimicking legitimate system binaries. Two backdoors carry Check Point's own attribution basis: oRAT, a Go RAT with an embedded SSH/SFTP server that persists as a systemd service disguised as the legitimate xtables-addons netfilter package, disables SELinux enforcement (setenforce 0) as part of its setup routine, and masquerades its process as sshd: root@pts/0, sharing the same orat/cmd/agent codebase and REST-style operator routes Check Point tied to Earth Berberoka in 2022 (Check Point Research, 2026-09-02). AlphaAgent, a modular Go backdoor using gRPC-over-HTTPS with browser-fingerprint mimicry (or a DNS covert channel) and bundling a SOCKS5 proxy and Ligolo-style relay for pivoting, was recovered from the same archive as tools already attributed to Earth Berberoka, placing it directly alongside the group's known toolset (Check Point Research, 2026-09-02). A third attribution point is infrastructure: the group's command-and-control shares Earth Berberoka's historical Amazon ASN (AS16509) (Check Point Research, 2026-09-02). A credential stealer built on the open-source 3snake project intercepts sshd/sudo/su/ssh/passwd/kinit/ login executions via netlink process-event monitoring and ptrace, masquerading as one of roughly 29 fake kernel-thread process names. Check Point states the model is already exported beyond Brazil: parallel phishing templates localised for Vietnamese, Spanish and English audiences, with daily domain generation.

No source describes how the group obtains its initial foothold on a target web server, the reporting begins from already-established root access. Defenders should read this as post-compromise infrastructure abuse, not an exploitation narrative to patch against.

Triage and hunting: a sudden absence of Content-Security-Policy headers on specific URL paths of a public-sector web server is a strong signal of injected reverse-proxy behaviour (Check Point Blog, 2026-09-02). Audit installed Apache modules for .so files timestamped to match legitimate modules such as mod_ssl or mod_suexec; a mismatch between a module's claimed identity and its actual behaviour is the core detection concept, not any single file name (Check Point Blog, 2026-09-02). Further behavioural artefacts a defender can hunt for without treating them as fixed indicators: a systemd service claiming to be xtables-addons that does not match the real package's binary; a process presenting as sshd but running from an unexpected path; unexplained apxs/module-compilation activity on a production web server outside a maintenance window; and process names drawn from common kernel-worker naming conventions (kworker, ksoftirqd, watchdog, journald) that do not correspond to genuine kernel threads when inspected further.

The group compromises legitimate Brazilian government web servers, many of them .gov.br sites spanning federal, state, and municipal institutions, and installs malicious modules that silently turn them into reverse proxies for phishing content, invisible to the visitor

Check Point Blog 2026-09-02

We assess with medium-to-high confidence that Gambling Goblin is tied to Earth Berberoka

Check Point Research 2026-09-02

Audit Apache configurations and installed modules. Look for unexpected .so files, especially any timestamped to match legitimate modules like mod_ssl or mod_suexec.

Check Point Blog 2026-09-02

oRAT was tied to Earth Berberoka in 2022, and the variant we analyzed shares the same orat/cmd/agent codebase and REST-style operator routes

one of the AlphaAgent samples we recovered was uploaded in the same archive as other tools previously attributed to Earth Berberoka, placing AlphaAgent directly alongside the group's known toolset

Check Point Research 2026-09-02
threat03 Sep 05:15Zmulti-sourceOpen finding ↗

2026-08-29 · view entry permalink →

HIGHNATOB2

German mobile carriers leaked callees' IMEI, device model and OS version to callers during call setup, GSMA confirmed the flaw and warned its 1,000+ member operators worldwide

Bayerischer Rundfunk (BR) published an investigation, corroborated the same window by heise, that found Germany's three mobile network operators (Deutsche Telekom, Vodafone and Telefónica/O2) forwarded device-identifying data to the calling party during call setup, before the callee ever answered (BR24, 2026-08-27). Across more than 70 test calls, Telekom's and O2's networks in several cases forwarded the callee's full 15-digit IMEI (confirmed by Wireshark packet captures of the call-setup traffic) and Telekom's and Vodafone's networks separately exposed the callee's smartphone model and operating-system version, specific enough to reveal whether a target device was missing a given security update (BR24, 2026-08-27; heise Security, 2026-08-27). The leak occurred only in certain unspecified network/device constellations rather than on every call, and BR could not establish since when the gap existed; BR notified the three operators in late June 2026, after which Vodafone said it had "further narrowed" transmitted call data, Telekom said in mid-August it would adjust its network, and Telefónica said it had implemented technical measures; all three state they otherwise meet international industry standards (BR24, 2026-08-27).

The GSMA confirmed the flaw on inquiry and, per a nine-page briefing BR obtained, warned its 1,000+ member operators worldwide to review their networks and filter unnecessarily transmitted call-setup information, an implicit acknowledgment that the same signaling gap plausibly extends beyond Germany's three carriers to any GSMA member network (BR24, 2026-08-27). Germany's domestic security service (BfV) assessed the flaw as security-relevant, stating that given cyberattacks against mobile devices by state-affiliated actors already on record, it is "near-certain" that foreign intelligence services use such information for their own purposes (BR24, 2026-08-27). A scenario in the Bundeswehr's own magazine "Y" illustrates the mechanism: correlating a soldier's IMEI between a domestic posting and a later deployment abroad (its example is a training ground in Lithuania) could put that individual "in a spy's focus"; the Federal Ministry of Defense separately told BR that intelligence services can use such device identifiers to build movement profiles and identify individuals (BR24, 2026-08-27). HPI mobile-security researcher Jiska Classen called it a serious flaw enabling mass profile-building and said it shows how poorly such carrier systems are tested (BR24, 2026-08-27). SRLabs founder Karsten Nohl, asked by heise to elaborate, added that device-model exposure also enables more targeted attacks and IMEI cloning, while stating he sees no dramatic security impact in the finding on its own (heise Security, 2026-08-27). BR notes the finding parallels an April-2026 discovery of a similar flaw in Norwegian networks by Mnemonic researcher Harrison Sand, who shared his methodology with BR, suggesting the underlying signaling gap is not specific to any one carrier or country (BR24, 2026-08-27).

Neither BR nor heise names the precise signaling layer, an SS7 interconnect field, a Diameter/IMS parameter, or a VoLTE SIP header, carrying the leaked data; this is recorded as an unresolved open question, not an invented mechanism. Detection concept for a telco SOC or network-security team: audit outbound call-setup signaling at the interconnect boundary for device-identifying parameters (IMEI, UE capability/OS-version fields) reaching the calling party or a foreign network, consistent with GSMA and IETF guidance (RFC 7254, RFC 7255) that such fields be anonymized or stripped before leaving the home network (heise Security, 2026-08-27). Hardening lever: filter or strip unnecessary device-identifying call-setup parameters at the network edge, per the GSMA's own briefing recommendation.

In the networks of Telekom and Telefónica (O2), IMEI numbers reached the caller in several cases.

The Federal Office for the Protection of the Constitution (BfV) assesses the security vulnerability discovered by BR research, on inquiry, as "security-relevant".

After BR approached the association with questions, it warned its more than 1,000 member companies, which also include the German network operators.

Bayerischer Rundfunk (BR24) 2026-08-27
research29 Aug 04:09Zmulti-sourceOpen finding ↗

Earlier coverage (23)

2026-08-06NOTABLEupdatedNATOB2ENDLESSDOORS (CVE-2026-66747); twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser's remedy is replacementVulnCheck documented ENDLESSDOORS on 2026-08-05, a pre-installed remote-access implant enabled by default on twenty Zbtlink router and CPE models, including units rebranded under another name and sold through mainstream e-commerce; VulnCheck notes the true affected population might be larger than the twenty it examined. The implant is a customised build of the open-source rctl tool, launched at boot by the vendor's own init script and masquerading as a kernel worker thread. It registers outbound to hardcoded command-and-control hosts and then passes whatever the server sends straight to a shell as uid 0, with no handshake, key exchange or authentication of any kind, and a second command opens an interactive reverse shell. Because this is a shipped component rather than a memory-corruption defect, VulnCheck's guidance is to replace affected devices, or at minimum place them behind strict egress control and treat their LAN as untrusted. VulnCheck says it did not notify Zbtlink, on the reasoning that there is no patch to coordinate; Zbtlink itself has publicly said it is suspending sales of affected routers and pulling the affected firmware while it develops updates.2026-08-23HIGHNATOB2Three Russia-nexus espionage clusters compromise European diplomats and academics without malware, by talking targets through app passwords, device-code approvals and WhatsApp device-linking, all of which are legitimate features working as designedGoogle Threat Intelligence Group published research on 2026-08-20 on three distinct suspected Russia-nexus clusters whose primary access method is abuse of legitimate authentication workflows rather than malware. UNC6293 talks targets into creating an application-specific password and sharing it back, which grants access without ever triggering the second factor. UNC7005 (the cluster this store already tracks as Storm-2945) runs device-code phishing through spoofed conference sites that fingerprint the browser to evade automated scanners before showing the code, and separately abuses WhatsApp device-linking by generating a genuine link request against a victim-supplied phone number, then instructing the victim to approve it; a fake voice call on the same page captures microphone and camera through the browser under cover of the call. UNC5976 stands up a cloud project per phishing domain and harvests OAuth tokens after a real consent flow. The target set is academia, aerospace and defence, governments and think tanks across Europe.2026-08-15NOTABLEupdatedNATOB2Mustang Panda's CoolClient backdoor gains a kernel driver signed with a 2013 certificate that expired in 2014, and it hides the malware's own C2 traffic by hooking the driver Windows uses to report network stateKaspersky's GReAT team published on 2026-08-14 a new CoolClient backdoor variant, attributed to the actor it tracks as HoneyMyte and also known as Mustang Panda, that installs a signed kernel-mode driver as a Windows service. The driver hides processes, files, registry keys and (distinctively) strips the implant's own C2 addresses from the network information Windows returns to user-mode tools. It is deployed only where the implant already holds Service Control Manager access and SeTcbPrivilege, and follows a PlugX foothold.2026-08-20NOTABLENATOB2Grandoreiro's loader decides it is in a sandbox when it finds seven ordinary desktop shortcuts, an inverted environment check, behind a two-hop DLL sideloadAcronis's Threat Research Unit analysed a Grandoreiro banking-trojan wave delivered as a renamed copy of the legitimate Duplicate Files Finder utility, which loads its genuine dependency and is in turn used to sideload a malicious library under the ordinary-looking name of a MinGW runtime component. Before any command-and-control attempt the loader runs a staged environment gate whose standout check is inverted: if desktop shortcuts for all seven of a named set of mainstream consumer applications are present at once, it concludes it is in an analysis image and terminates. Acronis's telemetry places the largest share of samples in Mexico, with Spain and several Latin American countries forming a secondary cluster and European presence described as limited but notable. The command-and-control server was offline during analysis, so the protocol detail is static analysis rather than observed traffic.2026-08-20NOTABLENATOB2"Ransom Busters" emails ransomware victims before their incident is public, offering to delete the stolen data for a fee, and the tooling says it is the same affiliate who took itGuidePoint Security's research team documents an entity calling itself Ransom Busters that emails ransomware victims at their own domain, asking for the CEO or IT leadership, claiming years of unauthorised access to criminal infrastructure and offering to return stolen files and delete the attackers' copies for $20,000-$60,000. The anomaly that gives it away is timing: the outreach arrives before the intrusion is public knowledge. Across two responses GuidePoint found the same reconnaissance scanner, the same cloud-exfiltration utility, the same remote-management tool installed by script, a local backdoor account with an identical fixed password and an identical attacker workstation name, an operator-level match recurring across incidents attributed to DragonForce, Settra and Anubis. GuidePoint assesses with moderate confidence this is one affiliate working across those programmes and diverting payments from them; Coveware independently confirmed responding to at least one incident with contact from the same party.2026-07-31HIGHexploitedupdatedNATOB2Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agentPalo Alto Unit 42 obtained full visibility into a Chinese-speaking operator's offensive tooling after the operator's own agent framework started an HTTP file server from its home directory, exposing tool configurations, API keys, exploit scripts, target lists and session logs. The operator ran DeepSeek behind the open-source Hermes Agent for fully autonomous target enumeration and exploitation against seven CVEs and more than 460 targets, and every autonomous exploitation attempt failed, defeated only by target-side configuration. The three confirmed compromises came from the operator's own manual work against Citrix NetScaler ADC/Gateway (CVE-2026-3055), exfiltrating appliance memory and searching it for session cookies, including multi-day targeting of a Malaysian government entity. That CVE is KEV-listed and was already being exploited by an unrelated cluster months earlier.2026-08-17NOTABLENATOB2PATCHCORD, SHEETCORD and HACKERAI; one espionage cluster runs three different command-and-control channels, two of them inside Google Sheets and GitHub, and persists by rewriting the victim's browser shortcutsAcronis Threat Research Unit documents three previously undocumented implants sharing one operator's infrastructure against Afghan telecom providers and South Asian critical infrastructure: PATCHCORD, a C/C++ backdoor delivered by fake Afghan Telecom VPN and ministry installers, SHEETCORD, a Go implant whose command-and-control runs entirely through the Google Sheets API v4 using a hardcoded cloud service account and a per-victim spreadsheet tab, and HACKERAI C2 Agent, which does the same job through GitHub Gists. All three persist by hijacking browser shortcuts so the implant launches first and then starts the real browser, and PATCHCORD executes operator-supplied shellcode entirely in memory. The targeting is South Asian, but the tradecraft is not: two of the three channels terminate on Google- and GitHub-owned endpoints that most egress policy treats as benign.2026-08-12HIGHexploitedupdatedNATOA1CVE-2026-58231, SAP Commerce Cloud: an unauthenticated request to the Data Hub Adapter import endpoint reaches arbitrary code execution (CVSS 10.0), and the fix needs a rebuild and redeploySAP's 2026-08-11 Security Patch Day fixes CVE-2026-58231, an improper-authorization flaw in the SAP Commerce Cloud Data Hub Adapter that Onapsis describes as insufficient authorization checks and input validation reachable without authentication, rated CVSS 10.0 and capable of arbitrary code execution. Further notes cover code injection in SAP Manufacturing Integration and Intelligence (CVE-2026-44772, 9.9; CVE-2026-44758, 9.1) and an unauthenticated memory-corruption flaw in the NetWeaver AS ABAP kernel's DIAG protocol parser (CVE-2026-34265, 9.8). No exploitation is reported by any party; Commerce Cloud fixes require rebuilding and redeploying the release rather than installing a patch, and an IP filter set is the vendor-side interim control.2026-08-13HIGHupdatedNATOB2MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion, and because it is a processor, not a controller, the people affected cannot be told directlyMyDr, one of Poland's largest electronic medical record providers, confirmed on 2026-08-12 that it was the target of a deliberate external criminal act affecting part of its data, saying the data is likely historical (2024 and earlier) and that it cannot yet state what was taken. Attackers who approached Polish outlet Zaufana Trzecia Strona claim 18,814,422 unique PESEL national identity numbers and 2.5 TB of data, and describe an access chain the outlet could not independently verify: remote code execution through an XXE flaw in PKCS#12 certificate handling, a GitHub API key, source code, then AWS. The transferable finding is structural: MyDr is a GDPR processor and the controllers are thousands of individual healthcare facilities, so affected individuals cannot be notified centrally and must wait for their own clinic.2026-08-10HIGHNATOB2Interlock ran Volatility3 and WinPmem against a live endpoint to harvest credentials, the responder's own memory-forensics toolkit used in place of a commodity dumperSophos's incident-response team investigated a March 2026 Interlock intrusion in which the operator captured a full physical-memory image with WinPmem and then ran Volatility3's Windows credential plugins offline against that image, instead of using a commodity credential dumper on the live host. Initial access was a ClickFix paste-and-run lure reached through a search result, and the chain ran to domain-controller compromise inside roughly 26 hours including a deliberate day-long pause. The defensive problem is that both binaries are legitimate DFIR tooling, so their presence and their command shapes are indistinguishable from a real investigation on artifact alone; Sophos's own discriminator was that the customer knew of no legitimate use.2026-08-07NOTABLENATOB2Stolen AI API tokens reach a reselling proxy within minutes, Unit 42 documents the 'transfer station' market and the account-takeover variant that mints its own keysUnit 42 describes "token jacking" (theft of AI-provider API tokens via infostealers, phishing, poisoned packages or credentials left in improperly secured file shares and code repositories) and the gray market that monetises them. "Transfer station" services built on open-source LLM-proxy software sit in front of the stolen token, hide it from the buyer, and resell discounted model access; Unit 42 responded to cases where an exposed credential reached one within minutes and generated nearly a million dollars in charges before containment. A second variant needs no leaked key at all: an attacker using a corporate developer account harvested by an infostealer, taken by phishing or bought from an access broker mints new keys, removes billing limits and disables usage alerts and logging. Recovering the billed funds is largely not possible.2026-07-14NOTABLENATOB2Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerabilityMicrosoft Threat Intelligence documented a year (mid-2025 to mid-2026) of campaigns using ShinyHunters-associated tradecraft (registry alias UNC6240) against Salesforce-integrated SaaS environments via three intrusion paths: vishing-driven malicious-OAuth-consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138's June 2026 Klue compromise), and guest-access Aura abuse. None exploited a Salesforce flaw, all abuse trusted OAuth relationships, so sign-in-anomaly detection gives limited visibility.2026-07-11NOTABLENATOB3Armored Likho: new APT hits government and electric-power targets with an AI-generated loader and the Python 'BusySnake' stealerKaspersky documented (2026-07-03) Armored Likho (aka Eagle Werewolf), a previously unknown APT targeting government agencies and the electric-power sector across Russia, Brazil and Kazakhstan. Spear-phishing delivers an NSIS dropper or a ZDI-CAN-25373 LNK lure whose loader (assessed as LLM-generated) stages a bundled Python 3.12 runtime and the PyArmor-protected BusySnake Stealer from rotating GitHub repositories. Campaign active at publication; concrete low-noise hunt pivots exist. Published as an audit-recovered item: the primary fell inside the 2026-07-07 scheduler outage's backfill blind spot.2026-06-28NOTABLENetcraft: Bluekit PhaaS uses Browser-in-the-Middle to defeat FIDO2 and Device Bound Session CredentialsNetcraft published a technical breakdown (2026-06-25) of Bluekit, a phishing-as-a-service platform first documented by Varonis Threat Labs (2026-04-29) and now seen by Netcraft at scale (~70 active hostnames in a single week) (Netcraft, 2026-06-25; Varonis, 2026-04-29).2026-06-13HIGHupdatedGoogle sues China-based "Outsider" PhaaS network for weaponising Gemini to mass-produce phishing pagesGoogle filed a federal lawsuit against the operators of "Outsider Enterprise," a phishing-as-a-service network that prompted Google's own Gemini model with innocuous-seeming HTML-generation requests and imported the output directly into its kit to stand up live scam pages (Google, 2026-06-12).2026-05-29NOTABLEexploitedFortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chainBackground. CVE-2026-35616 is the improper-access-control (CWE-284) flaw in Fortinet FortiClient EMS 7.4.5 and 7.4.6 disclosed on 2026-04-04 and added to the CISA KEV catalog on 2026-04-06; vendor coverage at disclosure focused on the auth-bypass primitive, with Arctic Wolf's 2026-05-27 publication being the …2026-05-24HIGHPackagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strandA Packagist (PHP/Composer) supply-chain wave hit the Laravel-Lang ecosystem, 700+ version tags rewritten to point at attacker forks, an autoload.files backdoor that executes on every request, and a separate 8-package package.json postinstall strand dropping a Linux implant. Full mechanics in today's deep dive (Socket, 2026-05-23).2026-05-23NOTABLECVE-2026-46333 ssh-keysign-pwn: a 9-year ptrace race in the Linux kernel reaching root and SSH host keysBackground. The Linux kernel's __ptrace_may_access() permission check in kernel/ptrace.c has been a recurring source of local-privilege-escalation primitives ever since the dumpable / capability model was introduced.2026-05-22NOTABLERed Lamassu (Calypso/Bronze Medley): Showboat + JFMBackdoor telco espionage implant pairBackground. Calypso (also tracked as Red Lamassu and Bronze Medley) is a China-aligned espionage cluster active since at least mid-2022 based on Lumen's binary upload and victim telemetry, the Showboat/JFMBackdoor campaign dates to this period.2026-05-18HIGHTycoon2FA after the March 2026 takedown, OAuth Device Authorization Grant abuse on Microsoft 365Tycoon2FA PhaaS pivots from credential-relay AiTM to OAuth 2.0 Device Authorization Grant abuse against Microsoft 365. Victims paste an attacker-supplied device code into the legitimate microsoft.com/devicelogin endpoint; MFA succeeds on the real Microsoft endpoint and tokens are issued to the attacker's registered device. eSentire documented the campaign with a four-layer browser chain ending in a fake Microsoft CAPTCHA (BleepingComputer, 2026-05-17; eSentire TRU, 2026-05-12).2026-05-16HIGHnode-ipc npm package backdoored via expired-domain account takeover, 90+ credential categories exfiltrated, three malicious versions, ~3-minute window to detectionnode-ipc npm package (widely-used Node.js IPC library) hijacked via expired-domain account takeover; three malicious versions (9.1.6, 9.2.3, 12.0.1) exfiltrate ~90 categories of cloud / CI/CD / SSH / Keychain credentials over DNS TXT and HTTPS to attacker C2; rotate any secret accessible from a workstation that installed the package on 2026-05-14 (Socket Security, 2026-05-14 · StepSecurity, 2026-05-14).2026-05-11NOTABLECVE-2026-6722 PHP SOAP Use-After-Free in SOAP_GLOBAL(ref_map)#### Vulnerability class and primitive2026-05-11HIGHSMS-blaster smishing establishing itself in Switzerland, portable IMSI-catchers force 2G downgrade, bypass operator SMS filteringSMS-blaster smishing fraud establishing itself in Switzerland. ebas.ch (Swiss banking + HSLU) reports portable IMSI-catcher devices broadcasting as rogue base stations and forcing nearby smartphones within several hundred metres to attach and downgrade from 4G/5G to 2G, then delivering smishing payloads that bypass operator SMS filtering (ebas.ch, 2026-05-07). Banking and credit-card credentials are the primary target, relevant for federal mobile-security policy guidance.