Acronis Threat Research Unit (TRU)
acronis-tru · B · active
https://www.acronis.com/en/tru/
Acronis Threat Research Unit malware-analysis blog. Added 2026-08-17 as this run's single new candidate: the named original-research primary behind entries/2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack, cited by prior fires only through republishers. FETCH: WebFetch 403s the post pages; python3 tools/fetch_source.py url <post-url> returned the full body (732 KB) on 2026-08-17. Promote to active after 3 contributing runs. | 2026-08-18: promoted candidate -> active on the documented lifecycle bar; the state digest counted three contributing runs and the bar is three. Reached through the generic bridge transport where a direct fetch is refused.
Cited in 5 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 5).
- CVE-2026-7273, Zyxel GS1900 switches: pre-auth stack overflow reaches CISA KEV after GreyNoise catches an actor overlapping Red Heron exfiltrating configs and hashed root credentials from 996 devices in 48 countries2026-09-22
- CVE-2026-60004: Gitea's diffpatch endpoint turns an attacker-supplied patch into a live Git hook, giving command execution as the service account; KEV-listed after miner deployment2026-08-30
- Grandoreiro's loader decides it is in a sandbox when it finds seven ordinary desktop shortcuts, an inverted environment check, behind a two-hop DLL sideload2026-08-20
- PATCHCORD, SHEETCORD and HACKERAI; one espionage cluster runs three different command-and-control channels, two of them inside Google Sheets and GitHub, and persists by rewriting the victim's browser shortcuts2026-08-17
- Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets2026-06-30