Acronis Threat Research Unit (TRU)
acronis-tru · B · candidate
https://www.acronis.com/en/tru/
Acronis Threat Research Unit malware-analysis blog. Added 2026-08-17 as this run's single new candidate: the named original-research primary behind entries/2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack, cited by prior fires only through republishers. FETCH: WebFetch 403s the post pages; python3 tools/fetch_source.py url <post-url> returned the full body (732 KB) on 2026-08-17. Promote to active after 3 contributing runs.
Cited in 4 entries
Citation cadence
Citation days per ISO week (9 weeks of coverage span, total 4).
- PATCHCORD, SHEETCORD and HACKERAI — one espionage cluster runs three different command-and-control channels, two of them inside Google Sheets and GitHub, and persists by rewriting the victim's browser shortcuts2026-08-17
- The week's tradecraft converged on abusing trusted primitives — OAuth tokens, signed binaries, native auth APIs and legitimate SaaS2026-07-05
- Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets2026-06-30
- Threat actor: INC ransomware's Rust rewrite and BYOVD evolution2026-06-22