ReliaQuest Threat Research
reliaquest · B · active
Added as candidate 2026-07-10 (one new candidate this run) — cited as published primary for the Helix data-extortion entry (2026-07-10). ReliaQuest Threat Research publishes identity-attack / data-extortion kill-chain analysis (device-code phishing, SharePoint exfil, BlackFile/ShinyHunters ecosystem tracking). FETCH: jina reader on reliaquest.com/blog/<slug> returned full clean markdown this run. Promote to active after 3 contributing runs. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 4 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs — the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-07-27 intel run: source_health probes bridge-ok, but S3 reports both WebFetch and the direct bridge return only site chrome/nav — the post grid is client-side rendered and no RSS feed was found. Host reachable, recipe does not reach content; fetch_method is already jina. Needs a structured endpoint. Not a demotion.
Cited in 10 entries
Citation cadence
Citation days per ISO week (12 weeks of coverage span, total 8).
- Four remediations completed this week and left the attacker holding something the fix does not reach — warehouse credentials, a decrypted keystore, build hosts that already ran the payload, and a client installer the patched server had already replaced2026-08-23
- 2026-W34 looking ahead — items already in motion: an EU reporting clock nineteen days out, a Swiss ransomware verdict on 10 September, an intelligence library whose only fix is two commits, and a mass-extortion campaign its own analyst expects to widen2026-08-23
- UPDATE — Cl0p Windchill campaign status: the implant is now reverse-engineered and one command is shown to return the whole application keystore in plaintext, while the named-victim count has stopped moving and one heavyweight name quietly left the leak site2026-08-23
- UPDATE — Cl0p's Windchill implant, reverse-engineered: a custom request header carries the commands, one of them decrypts the whole keystore including the LDAP manager password, and a built-in class loader turns it into an unlimited backdoor2026-08-19
- Two independently-operating Russian state clusters converged this week on the government user's mailbox and the government user's travel — and both leave persistence that a patch or a password reset does not remove2026-08-02
- CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff2026-08-01
- The Gentlemen (Storm-2697) status: ReliaQuest's Q2 2026 numbers put it ahead of Qilin on the ransomware leaderboard, and a European public-transport victim (Metro Mondego) landed this week2026-07-19
- Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking it2026-07-12
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration2026-07-10
- OP-512: China-linked cluster runs a cryptographically-unique, self-reporting IIS web-shell framework against legacy .NET servers2026-06-06