ReliaQuest Threat Research
reliaquest · B · active
Added as candidate 2026-07-10 (one new candidate this run) — cited as published primary for the Helix data-extortion entry (2026-07-10). ReliaQuest Threat Research publishes identity-attack / data-extortion kill-chain analysis (device-code phishing, SharePoint exfil, BlackFile/ShinyHunters ecosystem tracking). FETCH: jina reader on reliaquest.com/blog/<slug> returned full clean markdown this run. Promote to active after 3 contributing runs. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 4 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs — the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-07-27 intel run: source_health probes bridge-ok, but S3 reports both WebFetch and the direct bridge return only site chrome/nav — the post grid is client-side rendered and no RSS feed was found. Host reachable, recipe does not reach content; fetch_method is already jina. Needs a structured endpoint. Not a demotion.
Cited in 6 entries
Citation cadence
Citation days per ISO week (9 weeks of coverage span, total 6).
- Two independently-operating Russian state clusters converged this week on the government user's mailbox and the government user's travel — and both leave persistence that a patch or a password reset does not remove2026-08-02
- CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff2026-08-01
- The Gentlemen (Storm-2697) status: ReliaQuest's Q2 2026 numbers put it ahead of Qilin on the ransomware leaderboard, and a European public-transport victim (Metro Mondego) landed this week2026-07-19
- Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking it2026-07-12
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration2026-07-10
- OP-512: China-linked cluster runs a cryptographically-unique, self-reporting IIS web-shell framework against legacy .NET servers2026-06-06