{"id":"bundle--a753b9fd-c4ef-56a8-8ca7-21a32d248619","objects":[{"created":"2017-01-20T00:00:00.000Z","definition":{"tlp":"white"},"definition_type":"tlp","id":"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9","name":"TLP:WHITE","spec_version":"2.1","type":"marking-definition"},{"created":"2026-05-04T05:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Pipeline-native metadata on exported objects: the permanent entry/registry identifiers, editorial kind and priority, the sourcing verification tier, the NATO Admiralty rating (reliability letter has no STIX equivalent; the credibility digit also drives `confidence` per STIX 2.1 Appendix A), and the original curated relation type on relationships collapsed to related-to.","extension_types":["property-extension"],"id":"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8","modified":"2026-05-04T05:00:00.000Z","name":"CTI pipeline entry metadata","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"schema":"https://ctipilot.ch/stix/extension-schema.json","spec_version":"2.1","type":"extension-definition","version":"1.0"},{"created":"2026-05-04T05:00:00.000Z","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/"}],"id":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","identity_class":"organization","modified":"2026-05-04T05:00:00.000Z","name":"ctipilot.ch","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"identity"},{"created":"2026-05-04T05:00:05.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr/"}],"id":"relationship--5e95d7e5-7dd2-550e-b160-710caa5dfa4e","modified":"2026-05-04T05:00:05.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--e5842e07-bb50-5c44-86d7-129031575ff3","spec_version":"2.1","target_ref":"intrusion-set--b30781f6-fd45-5d82-891a-b8901dd05559","type":"relationship"},{"created":"2026-05-04T05:00:06.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/shinyhunters-worldleaks-week-long-cross-incident-operator-ac/"}],"id":"relationship--cd7907ca-8733-53b0-989d-dd8434e2acef","modified":"2026-05-04T05:00:06.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--aff6e953-308d-5644-b6fe-132de63debf0","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-05-04T05:00:07.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/canvas-instructure-breach-five-day-arc-from-first-claim-to-s/"}],"id":"relationship--2dae7e53-4f30-548b-8539-8dd1f30e0d4b","modified":"2026-05-04T05:00:07.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--446157f2-53a8-5ba0-a814-e4135dcf79ad","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-05-04T05:00:12.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/healthcare-ch-nl/"}],"id":"relationship--a3dc66dd-6284-5264-b734-6d31688fea78","modified":"2026-05-04T05:00:12.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--4740635a-6ac0-5aba-b3c4-51f935860c1f","spec_version":"2.1","target_ref":"intrusion-set--07acaff5-eb18-5e21-8812-6ffe24d5c06d","type":"relationship"},{"created":"2026-05-04T05:00:17.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/media-and-political-hu-de/"}],"id":"relationship--e71c4f85-8ed8-59c8-b461-d9ca7753493f","modified":"2026-05-04T05:00:17.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--f43b3f19-0251-5eea-9614-ce94f870b4d1","spec_version":"2.1","target_ref":"intrusion-set--850327b1-82c0-5f02-b797-5990145160ea","type":"relationship"},{"created":"2026-05-04T05:00:17.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/media-and-political-hu-de/"}],"id":"relationship--f4a3d412-38ad-51f2-8e2d-14ab40118282","modified":"2026-05-04T05:00:17.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--1bdac2b1-5e81-5051-b572-f68b0ac6d314","spec_version":"2.1","target_ref":"intrusion-set--31b671fa-3475-5e95-847f-2b36c26b49ca","type":"relationship"},{"created":"2026-05-04T05:00:33.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/shinyhunters-worldleaks-family-financial-data-extortion-thir/"}],"id":"relationship--0d969fb3-e1c2-5a2b-b77b-ed3dc1168255","modified":"2026-05-04T05:00:33.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--bec32ba3-f7b6-5ed9-8f9c-a50a461214a5","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-05-04T05:00:34.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/muddywater-iran-mois-chaos-ransomware-false-flag-teams-bec/"}],"id":"relationship--5ddacf17-dd16-5210-b815-2f97a2d406db","modified":"2026-05-04T05:00:34.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--801d4f44-83a5-554c-b48b-84d8cb12164e","spec_version":"2.1","target_ref":"intrusion-set--a494e603-7278-535a-ac86-434081d6d216","type":"relationship"},{"created":"2026-05-04T05:00:37.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Datadog's defensive static-analysis framework named after / analysing the worm family","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/teampcp-pcpjack-cloud-worm-successor-evicting-prior-operator/"}],"id":"relationship--04b44c91-f70b-5e4d-9b8e-bcaf65eadd16","modified":"2026-05-04T05:00:37.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"tool--fce203c9-a49b-5ae7-959d-5f0319566e31","spec_version":"2.1","target_ref":"campaign--04fa0914-a9c9-53c5-994d-633925723edf","type":"relationship"},{"created":"2026-05-04T05:00:37.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-04/teampcp-pcpjack-cloud-worm-successor-evicting-prior-operator/"}],"id":"relationship--819025b0-1003-5188-ba88-46248075592d","modified":"2026-05-04T05:00:37.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--04fa0914-a9c9-53c5-994d-633925723edf","spec_version":"2.1","target_ref":"intrusion-set--6c96f5b6-ce98-5a63-b571-9db754889d08","type":"relationship"},{"aliases":["Phantom Gyp"],"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"TeamPCP npm supply-chain worm family (initial wave: SAP CAP packages); the framework was later open-sourced, spawning derivatives including Phantom Gyp.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:mini-shai-hulud","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amini-shai-hulud/"}],"id":"campaign--04fa0914-a9c9-53c5-994d-633925723edf","labels":["campaign"],"modified":"2026-06-29T00:20:57.000Z","name":"Mini Shai-Hulud","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Breach at France's ANTS government identity agency — 11.7M citizen records confirmed.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:france-ants-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afrance-ants-breach-2026/"}],"id":"incident--0318ea64-559e-5fdb-911c-120b12a875fa","labels":["incident"],"modified":"2026-05-06T00:00:00.000Z","name":"France ANTS breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Trellix source-code repository breach.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:trellix-source-code-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Atrellix-source-code-2026/"}],"id":"incident--2bd81159-82d5-56ed-8f4b-fdcb814769b8","labels":["incident"],"modified":"2026-05-06T00:00:00.000Z","name":"Trellix source-code breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Instructure (Canvas LMS) data breach exposing student and educator data; part of the ShinyHunters Salesforce cluster.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:instructure-canvas-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ainstructure-canvas-2026/"}],"id":"incident--446157f2-53a8-5ba0-a814-e4135dcf79ad","labels":["incident"],"modified":"2026-05-06T00:00:00.000Z","name":"Instructure (Canvas LMS) breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DigiCert support-portal compromise leading to 60 fraudulent EV code-signing certificates.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:digicert-support-portal-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adigicert-support-portal-2026/"}],"id":"incident--49dc5684-0f55-5b0c-8395-1aa0377d3183","labels":["incident"],"modified":"2026-05-06T00:00:00.000Z","name":"DigiCert support-portal compromise","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ADT Inc. cloud environment breach — customer PII (SEC 8-K 2026-04-24)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:adt-cloud-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aadt-cloud-breach-2026/"}],"id":"incident--51c5751f-3488-5908-8802-266d1bb1773f","labels":["incident"],"modified":"2026-05-06T00:00:00.000Z","name":"ADT Inc. cloud environment breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mediaworks Kft (Hungary) — World Leaks data-theft extortion","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:mediaworks-hungary-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amediaworks-hungary-2026/"}],"id":"incident--f43b3f19-0251-5eea-9614-ce94f870b4d1","labels":["incident"],"modified":"2026-05-06T00:00:00.000Z","name":"Mediaworks Kft (Hungary)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UAT-8302 — China-nexus APT targeting government entities in South America and southeastern Europe","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uat-8302","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auat-8302/"}],"id":"intrusion-set--095c0887-7937-52e9-a029-f776959e0008","labels":["actor","china-nexus"],"modified":"2026-05-06T00:00:00.000Z","name":"UAT-8302","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["UNC6240"],"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated data-theft and extortion group (also tracked as UNC6240) behind the 2026 Salesforce/SaaS victim cluster (Instructure, Vimeo, 7-Eleven, Carnival, Inditex/Zara, Medtronic and others) and the Oracle PeopleSoft data-theft campaign.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:shinyhunters","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ashinyhunters/"}],"id":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","labels":["actor"],"modified":"2026-08-28T06:50:00.000Z","name":"ShinyHunters","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Threat actor targeting software supply chains; operator of the Mini Shai-Hulud npm worm family and the SANDCLOCK Checkmarx Jenkins-plugin backdoor, with victims including OpenAI.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:teampcp","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ateampcp/"}],"id":"intrusion-set--6c96f5b6-ce98-5a63-b571-9db754889d08","labels":["actor"],"modified":"2026-08-28T06:08:00.000Z","name":"TeamPCP","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Hunters International"],"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Data-theft extortion group without encryption; rebrand of Hunters International.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:worldleaks","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aworldleaks/"}],"id":"intrusion-set--850327b1-82c0-5f02-b797-5990145160ea","labels":["actor"],"modified":"2026-07-19T23:58:00.000Z","name":"World Leaks","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["APT37","Reaper"],"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"North Korea-aligned APT; 2026 pipeline coverage includes the BirdCall Android/Windows backdoor and the NarwhalRAT campaign with pCloud dead-drop C2.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:scarcruft","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ascarcruft/"}],"id":"intrusion-set--9fb5441b-b101-5153-8685-a55ff66cdf62","labels":["actor","north-korea-nexus"],"modified":"2026-06-18T05:10:29.000Z","name":"ScarCruft","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ScarCruft Android/Windows backdoor.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:birdcall","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Abirdcall/"}],"id":"tool--17fa96ea-8d2b-5319-9373-2ed6bcdc49b8","labels":["north-korea-nexus","tool"],"modified":"2026-05-06T00:00:00.000Z","name":"BirdCall","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"InstallFix — malvertising campaign distributing Amatera infostealer via fake AI tool install pages","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:installfix","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ainstallfix/"}],"id":"campaign--47b42d59-6eac-5c9a-8431-224c89fcea03","labels":["campaign"],"modified":"2026-05-07T00:00:00.000Z","name":"InstallFix","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"CL-STA-1132 — likely state-sponsored exploitation cluster for CVE-2026-0300 (PAN-OS)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:cl-sta-1132","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acl-sta-1132/"}],"id":"campaign--5b2c4438-c377-52ad-b80f-6eebafa5bba0","labels":["campaign"],"modified":"2026-05-14T05:00:03.000Z","name":"CL-STA-1132","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Embargo ransomware attack on Dutch healthcare-software vendor ChipSoft; 66 Dutch DPA notifications.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:chipsoft-embargo-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Achipsoft-embargo-2026/"}],"id":"incident--4740635a-6ac0-5aba-b3c4-51f935860c1f","labels":["incident"],"modified":"2026-05-07T00:00:00.000Z","name":"ChipSoft ransomware breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Disclosure of Europol shadow-IT systems: a decade of unregulated data processing outside EU oversight.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:europol-shadow-it-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aeuropol-shadow-it-2026/"}],"id":"incident--8bb0ef16-6a8f-5e17-8113-b45ffeb96231","labels":["incident"],"modified":"2026-05-07T00:00:00.000Z","name":"Europol shadow-IT disclosure","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Vimeo data breach via the Anodot third-party SaaS compromise — 119,200 accounts; part of the ShinyHunters cluster.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:vimeo-anodot-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Avimeo-anodot-2026/"}],"id":"incident--bec32ba3-f7b6-5ed9-8f9c-a50a461214a5","labels":["incident"],"modified":"2026-05-07T00:00:00.000Z","name":"Vimeo breach (Anodot)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware group; responsible for the ChipSoft (Netherlands) healthcare-software-vendor attack.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:embargo","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aembargo/"}],"id":"intrusion-set--07acaff5-eb18-5e21-8812-6ffe24d5c06d","labels":["actor"],"modified":"2026-06-29T00:21:17.000Z","name":"Embargo","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["APT32"],"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Vietnam-nexus APT; 2026 pipeline coverage includes a PyPI supply-chain campaign delivering the ZiChatBot backdoor and the SPECTRALVIPER delivery via the FireAnt MetaKit update-server compromise.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:oceanlotus","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aoceanlotus/"}],"id":"intrusion-set--445dd747-c261-5106-8af6-419e2feba90e","labels":["actor"],"modified":"2026-06-12T05:00:08.000Z","name":"OceanLotus","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service operator; pipeline coverage includes SimpleHelp RMM exploitation and the first in-the-wild Microsoft Teams TURN-relay C2 (Backdoor.Turn) intrusion.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:dragonforce","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Adragonforce/"}],"id":"intrusion-set--dcd6f42f-c2d6-5eec-9542-7e8ccdfc7c17","labels":["actor"],"modified":"2026-08-20T04:52:00.000Z","name":"DragonForce","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"OceanLotus PyPI supply-chain backdoor using the Zulip API for C2.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:zichatbot","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Azichatbot/"}],"id":"tool--0a5a6b87-c2f1-55b6-b449-2848a434840c","labels":["tool","vietnam-nexus"],"modified":"2026-05-07T00:00:00.000Z","name":"ZiChatBot","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Amatera — InstallFix campaign infostealer targeting browser credentials and e-wallets","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:amatera","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aamatera/"}],"id":"tool--23cad833-5f1e-5ba2-81d2-6ed135194b0c","labels":["tool"],"modified":"2026-07-19T23:20:00.000Z","name":"Amatera","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["Quasar Linux"],"created":"2026-05-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Developer-targeting Linux RAT with an eBPF rootkit and a PAM backdoor.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:qlnx","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aqlnx/"}],"id":"tool--41346f4e-6bdd-5260-b144-f7f8da40c018","labels":["tool"],"modified":"2026-05-07T00:00:00.000Z","name":"QLNX","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"MuddyWater (Iran/MOIS) Chaos-ransomware false-flag operation with Microsoft Teams credential harvesting across Europe and the Middle East.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:muddywater-chaos-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amuddywater-chaos-2026/"}],"id":"campaign--801d4f44-83a5-554c-b48b-84d8cb12164e","labels":["campaign","iran-nexus"],"modified":"2026-05-08T00:00:00.000Z","name":"MuddyWater Chaos false-flag","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Abuse of Amazon SES for authenticated BEC/phishing delivery (Kaspersky, 2026-05-04).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:amazon-ses-bec-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aamazon-ses-bec-2026/"}],"id":"campaign--ef4855d5-8e8a-5dfc-8187-593739d84d90","labels":["campaign"],"modified":"2026-05-08T00:00:00.000Z","name":"Amazon SES BEC abuse","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Qilin ransomware attack on the German party Die Linke — 1.5 TB claimed, DPA notified (April 2026).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:die-linke-qilin-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adie-linke-qilin-2026/"}],"id":"incident--1bdac2b1-5e81-5051-b572-f68b0ac6d314","labels":["incident"],"modified":"2026-05-08T05:00:04.000Z","name":"Die Linke ransomware breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Eurail breach (December 2025): 308,777 travellers notified in April 2026; the Dutch DPA and EDPS are reviewing the delayed notification.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:eurail-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aeurail-breach-2026/"}],"id":"incident--b22cccdc-bdc3-5d3a-876d-582ffaf3652d","labels":["incident"],"modified":"2026-05-08T05:00:05.000Z","name":"Eurail breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Pro-Russian hacktivist OT intrusion at five Polish water-treatment facilities; pump settings modified.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:polish-water-ot-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Apolish-water-ot-2026/"}],"id":"incident--fc78b5e0-b5e5-5fc3-a25f-241daf0c328b","labels":["incident"],"modified":"2026-05-08T00:00:00.000Z","name":"Polish water-treatment OT intrusion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Seedworm"],"created":"2026-05-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Iran MOIS-linked APT active against European and Middle-Eastern targets; 2026 pipeline coverage documents a Chaos-ransomware false-flag with Teams credential harvesting and a Q1 2026 DLL side-loading campaign abusing signed Fortemedia/SentinelOne binaries with ChromElevator ABE bypass (Symantec).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:muddywater","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Amuddywater/"}],"id":"intrusion-set--a494e603-7278-535a-ac86-434081d6d216","labels":["actor","iran-nexus"],"modified":"2026-07-19T23:26:00.000Z","name":"MuddyWater","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DAEMON Tools Lite supply-chain compromise delivering a QUIC-based RAT; EU governments targeted.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:daemon-tools-supply-chain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adaemon-tools-supply-chain-2026/"}],"id":"incident--62793c53-1f73-5257-83ed-f13994be750a","labels":["incident"],"modified":"2026-05-09T05:00:00.000Z","name":"DAEMON Tools supply-chain compromise","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ShinyHunters third-party analytics breach at Inditex (Zara) — 197,400 EU customers.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:inditex-zara-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ainditex-zara-breach-2026/"}],"id":"incident--aff6e953-308d-5644-b6fe-132de63debf0","labels":["incident"],"modified":"2026-05-09T05:00:01.000Z","name":"Inditex (Zara) breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DENIC .de DNSSEC outage from an HSM integration defect — 3.5 h disruption. The technical post-mortem confirmed three private keys sharing keytag 33834 with only one DNSKEY published.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:denic-dnssec-outage-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adenic-dnssec-outage-2026/"}],"id":"incident--e26cceed-1466-5ea8-87be-caac153ce6b9","labels":["incident"],"modified":"2026-05-10T05:00:11.000Z","name":"DENIC .de DNSSEC outage","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"PamDOORa — malicious PAM module with credential harvesting and log scrubbing, sold on Rehub","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:pamdoora-pam-backdoor-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Apamdoora-pam-backdoor-2026/"}],"id":"tool--8c5db97f-dea9-5d50-a8be-b702cc6d8a8e","labels":["tool"],"modified":"2026-05-09T00:00:00.000Z","name":"PamDOORa","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ClickFix social engineering expands to macOS: Macsync / Shub Stealer / AMOS delivered via Base64 Terminal-paste lures that bypass Gatekeeper (Microsoft research).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:clickfix-macos-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aclickfix-macos-2026/"}],"id":"campaign--5fe605c1-3de3-53f2-844c-758e423c75ef","labels":["campaign"],"modified":"2026-08-23T23:57:00.000Z","name":"ClickFix macOS expansion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"AWS account breach at the Braintrust AI-evaluation platform exposes customer org-level LLM provider keys.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:braintrust-aws-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Abraintrust-aws-breach-2026/"}],"id":"incident--739fe5dc-9db7-5fbe-91c0-c16ef4913c89","labels":["incident"],"modified":"2026-05-10T05:00:01.000Z","name":"Braintrust AWS breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"JDownloader official site compromised — Windows/Linux installers swapped for Python RAT (~48 h window)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:jdownloader-supply-chain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ajdownloader-supply-chain-2026/"}],"id":"incident--96040281-2503-5def-a217-1fd1fe702d06","labels":["incident"],"modified":"2026-05-10T05:00:02.000Z","name":"JDownloader official site compromised","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Akira ransomware attack on Groupe 3R (Réseau Radiologique Romand) — 48 GB claimed; Swiss medical imaging.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:groupe-3r-akira-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Agroupe-3r-akira-2026/"}],"id":"incident--e5842e07-bb50-5c44-86d7-129031575ff3","labels":["incident"],"modified":"2026-07-12T23:32:00.000Z","name":"Groupe 3R ransomware breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Gentlemen RaaS","Storm-2697","Phantom Mantis"],"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service operation (also tracked as Storm-2697 / Phantom Mantis) that surged in Q1 2026 — 192 attacks, +588% QoQ, 32% of victims European, with FortiGate CVE-2024-55591 as the initial-access funnel. ESET (2026-06-18) documents the operators centrally building and maintaining the GentleKiller EDR-killer framework (BYOVD, 48 vendors) for their affiliates.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:thegentlemen","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Athegentlemen/"}],"id":"intrusion-set--2b40ef6d-7f23-5aab-aabc-f30ab0092df0","labels":["actor"],"modified":"2026-07-19T23:50:00.000Z","name":"The Gentlemen","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Agenda"],"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Qilin / Agenda — Rust-based ransomware-as-a-service; Q3 2025 German operational tempo tripled (GTIG); 23 Q1 2026 healthcare claims","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:qilin","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aqilin/"}],"id":"intrusion-set--31b671fa-3475-5e95-847f-2b36c26b49ca","labels":["actor"],"modified":"2026-08-16T23:59:00.000Z","name":"Qilin","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Akira — ransomware operator targeting EU healthcare and SME via edge-device CVE chains and intermittent-encryption EDR evasion","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:akira","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aakira/"}],"id":"intrusion-set--b30781f6-fd45-5d82-891a-b8901dd05559","labels":["actor"],"modified":"2026-08-23T23:51:00.000Z","name":"Akira","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Backdoor distributed via a fake Claude AI site (claude-pro[.]com): DonutLoader plus DLL sideloading against a signed G DATA AV updater (Sophos STAC4713).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:beagle-fake-claude-stac4713-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Abeagle-fake-claude-stac4713-2026/"}],"id":"tool--663aa8d0-fa12-510b-b683-d6a7a4d53a1b","labels":["tool"],"modified":"2026-08-23T23:57:00.000Z","name":"Beagle","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"PCPJack — modular cloud-credential-theft worm chaining 5 public CVEs; evicts TeamPCP","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:pcpjack-cloud-worm-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Apcpjack-cloud-worm-2026/"}],"id":"tool--c6f985ef-5aa6-5348-83e4-95b73bfcf9b9","labels":["tool"],"modified":"2026-05-26T05:00:05.000Z","name":"PCPJack","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SMS-blaster smishing establishing itself in Switzerland: portable IMSI-catchers force a 2G downgrade to bypass operator SMS filtering.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:sms-blaster-ch-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asms-blaster-ch-2026/"}],"id":"campaign--20ada51b-62ac-5081-803e-8136939d40b0","labels":["campaign"],"modified":"2026-05-11T05:00:01.000Z","name":"SMS-blaster smishing (Switzerland)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-11T05:00:05.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-11/teampcp-mini-shai-hulud-npm-supply-chain-worm-wave-4-framewo/"}],"id":"relationship--cabf8d80-699f-5667-b2e3-cba08c03660c","modified":"2026-05-11T05:00:05.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--0f52dd51-82e0-5fb0-af9c-054e8babaa5d","spec_version":"2.1","target_ref":"intrusion-set--6c96f5b6-ce98-5a63-b571-9db754889d08","type":"relationship"},{"created":"2026-05-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Škoda Auto Deutschland online-shop breach exposes customer PII and password hashes; a logging gap prevents exfiltration confirmation (2026-05-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:skoda-shop-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Askoda-shop-breach-2026/"}],"id":"incident--2873a941-5429-51bb-8cc8-875d6044dd82","labels":["incident"],"modified":"2026-05-12T00:00:00.000Z","name":"Škoda online-shop breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ICO fines South Staffordshire Water £963,900 — Cl0p ZeroLogon intrusion, 20-month dwell, 5% SOC coverage; a UK NIS2/CER precedent.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:south-staffordshire-water-ico-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Asouth-staffordshire-water-ico-2026/"}],"id":"incident--303e2361-6c04-5014-b8cf-95de72e9aaea","labels":["incident"],"modified":"2026-05-12T05:00:00.000Z","name":"South Staffordshire Water ICO fine","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"West Pharmaceutical Services SEC 8-K Item 1.05: data exfiltrated, systems encrypted, global operations partially restarted (2026-05-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:west-pharma-8k-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Awest-pharma-8k-2026/"}],"id":"incident--343d541f-380d-546b-b300-d9aaa4b607f3","labels":["incident"],"modified":"2026-05-12T00:00:00.000Z","name":"West Pharmaceutical ransomware","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"TeamPCP backdoors Checkmarx Jenkins AST plugin version 2026.5.09; SANDCLOCK exfiltrates CI/CD secrets (2026-05-09 to 2026-05-10).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:checkmarx-jenkins-ast-plugin-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acheckmarx-jenkins-ast-plugin-2026/"}],"id":"incident--52c273d4-08b0-5a3f-86aa-389fab0f9c19","labels":["incident"],"modified":"2026-05-12T00:00:00.000Z","name":"Checkmarx Jenkins plugin backdoor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"BKA and ZIT dismantle the relaunched Crimenetwork darknet marketplace; the German operator was arrested in Mallorca on a European Arrest Warrant (2026-05-08).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:bka-crimenetwork-takedown-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Abka-crimenetwork-takedown-2026/"}],"id":"incident--f505ea4a-42ab-52b9-b37d-023c9c34dde1","labels":["incident"],"modified":"2026-05-12T00:00:00.000Z","name":"Crimenetwork relaunch takedown","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-12T05:00:06.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-12/teampcp-unc6780-pcpjack-ecosystem-backdoors-the-checkmarx-je/"}],"id":"relationship--c1675760-d180-50f3-ae35-45a9805de429","modified":"2026-05-12T05:00:06.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--52c273d4-08b0-5a3f-86aa-389fab0f9c19","spec_version":"2.1","target_ref":"intrusion-set--6c96f5b6-ce98-5a63-b571-9db754889d08","type":"relationship"},{"created":"2026-05-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"BWH Hotels (Best Western / WorldHotels / Sure Hotels): 181-day dwell in a guest-reservation web app, EEA guests in scope.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:bwh-hotels-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Abwh-hotels-breach-2026/"}],"id":"incident--20e99d5c-4f75-5b05-815f-a49f7fcb8f17","labels":["incident"],"modified":"2026-05-13T00:00:00.000Z","name":"BWH Hotels reservation breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Foxconn confirms Nitrogen ransomware crippled North-American manufacturing sites — 8 TB / 11M files claimed; the ESXi decryptor proved mathematically broken.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:foxconn-nitrogen-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afoxconn-nitrogen-2026/"}],"id":"incident--d85608b6-9097-5662-ba08-6895bca2099d","labels":["incident"],"modified":"2026-05-13T05:00:00.000Z","name":"Foxconn Nitrogen ransomware","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft's multi-model agentic vulnerability-discovery harness; found 16 Windows CVEs in network-stack kernel components.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:microsoft-mdash-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Amicrosoft-mdash-2026/"}],"id":"tool--1d5fae06-3cf9-5ef2-928c-b4127366cf35","labels":["tool"],"modified":"2026-05-13T05:00:08.000Z","name":"MDASH","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"TrickMo variant ('TrickMo C'): Android banking trojan with C2 migrated to The Open Network blockchain, adding SOCKS5/SSH device-as-pivot; campaigns in FR/IT/AT.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:trickmo-c-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Atrickmo-c-2026/"}],"id":"tool--657945cc-f29c-59af-84bc-e71a0d14db22","labels":["tool"],"modified":"2026-05-13T05:00:09.000Z","name":"TrickMo C","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["UAT-9244"],"created":"2026-05-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"FamousSparrow (UAT-9244) three-wave intrusion of an Azerbaijani oil & gas operator, December 2025 – February 2026: ProxyNotShell re-exploitation plus a novel two-stage export-gated DLL-sideloading chain.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:famoussparrow-azerbaijan-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afamoussparrow-azerbaijan-2026/"}],"id":"campaign--bcb773ce-9970-5561-95d2-8ef74ae9cc2b","labels":["campaign"],"modified":"2026-05-14T00:00:00.000Z","name":"FamousSparrow Azerbaijan intrusion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Dutch IGJ ruling: Clinical Diagnostics LCPL/NMDL failed the NEN 7510 information-security standard at the time of the July 2025 Nova ransomware breach — ~941,000 patients including cervical-cancer screening data.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:clinical-diagnostics-nmdl-igj-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aclinical-diagnostics-nmdl-igj-2026/"}],"id":"incident--e8463b98-f68c-5d2f-80d8-79db0006e100","labels":["incident"],"modified":"2026-05-14T00:00:00.000Z","name":"Clinical Diagnostics NMDL ruling","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GemStuffer — RubyGems registry weaponised as one-way exfiltration channel scraping UK local-authority ModernGov portals; new abuse pattern exploiting CI/CD inbound-monitoring blind spot","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:gemstuffer-rubygems-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Agemstuffer-rubygems-2026/"}],"id":"tool--7541829d-e5bb-56d5-8b7d-36d97c983458","labels":["tool"],"modified":"2026-05-14T05:00:02.000Z","name":"GemStuffer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["Ghostwriter","UNC1151"],"created":"2026-05-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"FrostyNeighbor (Ghostwriter / UNC1151) March–May 2026 campaign against Poland, Lithuania and Ukraine.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:frostyneighbor-2026-05-campaign","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afrostyneighbor-2026-05-campaign/"}],"id":"campaign--63c6dd7c-5ead-578c-bc50-21ed38fae17a","labels":["campaign"],"modified":"2026-07-12T23:30:00.000Z","name":"FrostyNeighbor March–May 2026 campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"OpenAI named as a TeamPCP / Mini Shai-Hulud victim; code-signing certificate rotation enforced.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:openai-tanstack-breach-2026-05","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aopenai-tanstack-breach-2026-05/"}],"id":"incident--0f52dd51-82e0-5fb0-af9c-054e8babaa5d","labels":["incident"],"modified":"2026-05-15T00:00:00.000Z","name":"OpenAI supply-chain exposure","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UAT-8616 — Sophisticated actor exploiting Cisco SD-WAN infrastructure since 2023","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uat-8616","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auat-8616/"}],"id":"intrusion-set--b05a7f78-c176-596b-bda0-210c45e10b10","labels":["actor"],"modified":"2026-06-16T05:09:04.000Z","name":"UAT-8616","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Chaotic Eclipse"],"created":"2026-05-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Pseudonymous vulnerability researcher/broker persona (tracked under both names) publicly dropping Windows zero-day proof-of-concepts through 2026 — the series includes BlueHammer, RedSun, UnDefend, YellowKey (BitLocker, later CVE-2026-45585), GreenPlasma (CTFMON LPE), MiniPlasma (cldflt.sys), GreatXML (BitLocker/WinRE) and RoguePlanet (Defender TOCTOU) — and threatening further releases after Microsoft's Digital Crimes Unit threatened criminal action.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:nightmare-eclipse","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Anightmare-eclipse/"}],"id":"intrusion-set--ca241f42-7392-5e96-abde-f0b724013bc4","labels":["actor"],"modified":"2026-08-24T09:11:00.000Z","name":"Nightmare Eclipse","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Datadog's open-source static-analysis framework (named after the Shai-Hulud worm family) for CI/CD pipeline security.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:datadog-shai-hulud-framework-2026-05","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Adatadog-shai-hulud-framework-2026-05/"}],"id":"tool--fce203c9-a49b-5ae7-959d-5f0319566e31","labels":["tool"],"modified":"2026-05-15T00:00:00.000Z","name":"Datadog Shai-Hulud scanner","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SentinelOne taxonomy of CI/CD subversion ('Living Off the Pipeline') with three case studies: TeamCity, GitLab service accounts, and Contagious Interview.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:sentinelone-living-off-the-pipeline-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asentinelone-living-off-the-pipeline-2026/"}],"id":"campaign--837e0301-f3f4-538e-9fd7-2c4f58b7d872","labels":["campaign"],"modified":"2026-05-16T05:00:08.000Z","name":"Living Off the Pipeline","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Dream Market lead administrator Owe Martin Andresen arrested in Germany (BKA with US multi-agency support).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:dream-market-admin-arrest-2026-05","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adream-market-admin-arrest-2026-05/"}],"id":"incident--31a2dbd7-25e1-5d0b-be29-d8cd300d28d7","labels":["incident"],"modified":"2026-05-16T00:00:00.000Z","name":"Dream Market admin arrest","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"npm package node-ipc backdoored via an expired-domain account takeover (versions 9.1.6 / 9.2.3 / 12.0.1).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:node-ipc-supply-chain-2026-05","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anode-ipc-supply-chain-2026-05/"}],"id":"incident--8723f8c7-a95a-5d37-aa5f-d9bafd76f84d","labels":["incident"],"modified":"2026-05-16T00:00:00.000Z","name":"node-ipc backdoor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Turla","FSB Centre 16","TURLA RELIC"],"created":"2026-05-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russian FSB Centre 16 APT (Microsoft: Secret Blizzard; historically Turla); 2026 coverage includes Microsoft Threat Intelligence's Kazuar P2P botnet anatomy (2026-05-14) and the STOCKSTAY diplomatic-espionage backdoor of Kazuar lineage.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:secretblizzard","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Asecretblizzard/"}],"id":"intrusion-set--8ae5f539-8ebc-52fd-bbdc-1153fc0e0991","labels":["actor","russia-nexus"],"modified":"2026-07-19T23:42:00.000Z","name":"Secret Blizzard","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["BlackFile","Redact","Pink","Falcon"],"created":"2026-05-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UNC6671 / BlackFile — vishing-driven AiTM extortion with programmatic SharePoint exfiltration (GTIG 2026-05-15). The BlackFile brand announced its retirement in May 2026, but GTIG reports the operator kept running and diversified across the Redact, Pink, Helix and Falcon extortion brands, linked by shared root domains, identical phishing templates and overlapping victim targeting — an assessment GTIG hedges against splintered affiliates or shared phishing-as-a-service infrastructure (2026-08-06). Current pretext is an urgent IT-helpdesk order to enroll a FIDO2 passkey or re-enroll MFA, sometimes from a spoofed helpdesk number to a personal mobile. Note: the 'Falcon' alias is this extortion brand and is unrelated to the CrowdStrike Falcon product. Redact / Pink / Falcon are carried as aliases because they are the store's phrase-matching surface and GTIG attributes all three to this operator, but the underlying linkage is an assessment rather than an identity claim; Helix is deliberately kept as its own key (actor:helix-extortion) with a sourced successor-of edge, because it was registered independently from earlier ReliaQuest reporting and has its own entry history, and merging it would assert more confidence than GTIG's hedge supports.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unc6671","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunc6671/"}],"id":"intrusion-set--f56b6a66-2051-502a-a8c2-937e168c51eb","labels":["actor"],"modified":"2026-08-16T23:59:00.000Z","name":"UNC6671","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unit 42 documents an evolved Gremlin Stealer: .NET XOR resource-section obfuscation, a crypto-clipper, and WebSocket browser-process session hijacking.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:gremlin-stealer-evolution-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Agremlin-stealer-evolution-2026/"}],"id":"tool--a40d3222-a764-517b-99f0-676fe8e8d18b","labels":["tool"],"modified":"2026-05-16T05:00:07.000Z","name":"Gremlin Stealer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unauthenticated checkout-endpoint injection in FunnelKit Funnel Builder for WooCommerce, actively exploited by a Magecart skimmer on 40,000+ stores (no CVE assigned).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:funnelkit-funnel-builder-for-woocommerce-actively-exploited-magecart-skimmer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afunnelkit-funnel-builder-for-woocommerce-actively-exploited-magecart-skimmer/"}],"id":"campaign--e684d02b-b88b-5941-9a34-e81789a838ff","labels":["campaign"],"modified":"2026-05-17T05:00:01.000Z","name":"FunnelKit Magecart injection","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kimsuky toolkit evolution documented by Kaspersky GReAT (May 2026) and follow-on reporting: the Rust-based HelloDoor variant of PebbleDash, the HTTPSpy RAT, and TryCloudflare quick-tunnel / VS Code remote-tunnel C2; South Korea primary, Germany spillover.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:kimsuky-pebbledash-hellodoor-trycloudflare-tunnel-c2-evolution","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Akimsuky-pebbledash-hellodoor-trycloudflare-tunnel-c2-evolution/"}],"id":"campaign--f28979d3-16bd-5a29-869d-0b6a453c65ac","labels":["campaign","north-korea-nexus"],"modified":"2026-05-17T00:00:00.000Z","name":"Kimsuky HelloDoor / PebbleDash C2 evolution","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Pwn2Own Berlin 2026 (May 14–16): 47 zero-days, $1,298,250 awarded — DEVCORE's three-bug Exchange SYSTEM RCE chain, a STARLabs ESXi escape, every AI-agent target fell; Swiss participation by Compass Security.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:pwn2own-berlin-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Apwn2own-berlin-2026/"}],"id":"incident--42e5aa35-e9e8-5b14-bf0e-ae672a15545c","labels":["incident"],"modified":"2026-05-17T05:00:06.000Z","name":"Pwn2Own Berlin 2026","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Ruby Sleet","APT43","Velvet Chollima"],"created":"2026-05-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"North Korea-aligned APT conducting credential-theft and espionage operations against South Korean and European targets; 2026 reporting (Kaspersky GReAT, May 2026) documents a Rust-based HelloDoor backdoor, the HTTPSpy RAT, PebbleDash toolkit evolution and TryCloudflare/VS Code tunnel C2.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:kimsuky","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Akimsuky/"}],"id":"intrusion-set--bf477e67-5536-5e91-bbe5-9b9eb8afd974","labels":["actor","north-korea-nexus"],"modified":"2026-05-30T05:00:07.000Z","name":"Kimsuky","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-17T05:00:04.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-17/kaspersky-great-documents-kimsuky-s-rust-based-hellodoor-and/"}],"id":"relationship--5108a297-996f-53cf-8c65-523b4f212410","modified":"2026-05-17T05:00:04.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--f28979d3-16bd-5a29-869d-0b6a453c65ac","spec_version":"2.1","target_ref":"intrusion-set--bf477e67-5536-5e91-bbe5-9b9eb8afd974","type":"relationship"},{"created":"2026-05-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Tycoon2FA phishing-as-a-service resurgence after its March 2026 takedown, abusing the OAuth Device Authorization Grant against Microsoft 365.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:tycoon2fa-oauth-device-authorization-grant-microsoft-365-post-takedown","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Atycoon2fa-oauth-device-authorization-grant-microsoft-365-post-takedown/"}],"id":"campaign--34e4c81b-d8e4-5f52-868b-cd731a10e806","labels":["campaign"],"modified":"2026-05-18T00:00:00.000Z","name":"Tycoon2FA post-takedown resurgence","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"THORChain GG20 Threshold-Signature-Scheme vault drain — roughly $11M across nine chains (Switzerland-based project).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:thorchain-gg20-tss-vault-drain-11m-nine-chains-switzerland","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Athorchain-gg20-tss-vault-drain-11m-nine-chains-switzerland/"}],"id":"incident--28508555-df0e-513c-9955-6538aca28f5e","labels":["incident"],"modified":"2026-05-18T05:00:00.000Z","name":"THORChain vault drain","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-18T05:00:01.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Proofpoint attributes the implant and the CVE-2026-42897 exploitation campaign to TA488. (curated relation type: attributed-to)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"attributed-to"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-18/cve-2026-42897-exchange-owa-em-service-auto-mitigation-depen/"}],"id":"relationship--2f469311-b45d-594e-91a7-49404963da8b","modified":"2026-05-18T05:00:01.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"tool--a70ccea2-6a78-5a8e-a506-34dca0f0b143","spec_version":"2.1","target_ref":"intrusion-set--f32f68b1-d1ab-590b-a5c2-675fcf9df5f9","type":"relationship"},{"created":"2026-05-18T05:00:05.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-18/teampcp-mini-shai-hulud-megalodon-the-open-sourced-supply-ch/"}],"id":"relationship--3c0b08a4-1211-5992-b0fd-479145db6d9d","modified":"2026-05-18T05:00:05.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--88a054c6-7add-5f22-ae17-c4c8e6054222","spec_version":"2.1","target_ref":"intrusion-set--6c96f5b6-ce98-5a63-b571-9db754889d08","type":"relationship"},{"created":"2026-05-18T05:00:05.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-18/teampcp-mini-shai-hulud-megalodon-the-open-sourced-supply-ch/"}],"id":"relationship--4cdd6702-8b75-56e7-8af0-3063c4c1d3d1","modified":"2026-05-18T05:00:05.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--aad6d0c9-ca0e-59b9-828a-b020b1d90152","spec_version":"2.1","target_ref":"intrusion-set--6c96f5b6-ce98-5a63-b571-9db754889d08","type":"relationship"},{"created":"2026-05-18T05:00:21.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-18/7-eleven-shinyhunters-salesforce-campaign-claims-another-600/"}],"id":"relationship--23f3988f-817a-5047-a98c-5d659265c121","modified":"2026-05-18T05:00:21.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--39878868-b270-5138-9bd6-bfb29da7a532","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-05-18T05:00:21.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-18/7-eleven-shinyhunters-salesforce-campaign-claims-another-600/"}],"id":"relationship--d953f34f-0b12-57ff-af6a-58cac1e51868","modified":"2026-05-18T05:00:21.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--9ba27bdb-61a7-55e4-bfb2-139bf5e796fa","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-05-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Nuclear-simulation sabotage operation contemporaneous with Stuxnet, confirmed by Symantec/Carbon Black: LS-DYNA/AUTODYN hook engine targeting a 30 g/cm³ density threshold; Kim Zetter corrected the earlier 'pre-Stuxnet' framing.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:fast16-symantec-carbon-black-contemporaneous-stuxnet-nuclea","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afast16-symantec-carbon-black-contemporaneous-stuxnet-nuclea/"}],"id":"campaign--1c5923de-fc45-5cf6-9223-892a43883391","labels":["campaign"],"modified":"2026-05-19T05:00:06.000Z","name":"Fast16","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"First MENA-region cybercrime sweep (October 2025 – February 2026): 201 arrests across 13 countries, 53 servers seized, first Algerian PhaaS takedown.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:interpol-operation-ramz-mena-cybercrime-13-country-201-arre","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ainterpol-operation-ramz-mena-cybercrime-13-country-201-arre/"}],"id":"campaign--875b30dd-c9df-58c4-9c82-f9bae4bb29a9","labels":["campaign"],"modified":"2026-05-19T05:00:04.000Z","name":"INTERPOL Operation Ramz","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"First copycat wave around TeamPCP's Shai-Hulud tooling: OX Security-documented npm packages with Phantom Bot and SSH/cloud stealers, the trojanised Checkmarx Jenkins plugin (third in three months), and SentinelLabs' PCPJack rival worm.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:teampcp-shai-hulud-copycat-wave-ox-security-checkmarx-pcpja","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ateampcp-shai-hulud-copycat-wave-ox-security-checkmarx-pcpja/"}],"id":"campaign--aad6d0c9-ca0e-59b9-828a-b020b1d90152","labels":["campaign"],"modified":"2026-05-19T00:00:00.000Z","name":"Shai-Hulud copycat wave","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Data exfiltration at ARWINI, Lower Saxony's statutory-prescription audit body, confirmed by the LKA.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:arwini-lower-saxony-statutory-prescription-audit-body-data","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aarwini-lower-saxony-statutory-prescription-audit-body-data/"}],"id":"incident--37b7612a-a7b7-5008-b765-ff1bd4715fa2","labels":["incident"],"modified":"2026-05-19T05:00:00.000Z","name":"ARWINI data exfiltration","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"CISA contractor Nightwing exposed AWS GovCloud admin keys, plaintext credentials and Artifactory access in a public GitHub repository for roughly six months.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:cisa-nightwing-contractor-aws-govcloud-keys-exposed-github","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acisa-nightwing-contractor-aws-govcloud-keys-exposed-github/"}],"id":"incident--9a318e30-a28f-5048-9f08-ade3f21431d3","labels":["incident"],"modified":"2026-05-19T00:00:00.000Z","name":"CISA/Nightwing GovCloud key exposure","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"7-Eleven confirms a ShinyHunters breach of 600K+ Salesforce franchise-application records — the same campaign as Instructure, Vimeo, Wynn, Vercel and Medtronic.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:7-eleven-confirms-shinyhunters-salesforce-breach-600k-recor","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3A7-eleven-confirms-shinyhunters-salesforce-breach-600k-recor/"}],"id":"incident--9ba27bdb-61a7-55e4-bfb2-139bf5e796fa","labels":["incident"],"modified":"2026-05-19T00:00:00.000Z","name":"7-Eleven Salesforce breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Grafana Labs confirms source-code-only theft via a GitHub Actions pwn-request by CoinbaseCartel; no customer data; ransom rejected on FBI guidance.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:grafana-labs-coinbasecartel-pwn-request-github-actions-breac","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Agrafana-labs-coinbasecartel-pwn-request-github-actions-breac/"}],"id":"incident--e4c566cd-b061-5c22-84a2-4a2af5467fd1","labels":["incident"],"modified":"2026-05-19T05:00:08.000Z","name":"Grafana Labs CoinbaseCartel breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-19T05:00:03.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-19/7-eleven-confirms-shinyhunters-breach-of-600-000-salesforce/"}],"id":"relationship--784c425e-b89d-50f5-a197-f6988b26df7f","modified":"2026-05-19T05:00:03.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--712f13c5-7f64-54c8-ba3d-f8cc046870b8","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Storm-2949 malware-less Azure kill chain: voice-phishing SSPR reset → Entra ID → M365 Graph → App Service Kudu → Key Vault → SQL → Storage → Azure VM.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:storm-2949-sspr-to-key-vault-azure-cloud-wide-kill-chain","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Astorm-2949-sspr-to-key-vault-azure-cloud-wide-kill-chain/"}],"id":"campaign--0f0c4206-acad-5f44-8659-a7e3745a7c2e","labels":["campaign"],"modified":"2026-05-20T05:00:14.000Z","name":"Storm-2949 SSPR-to-Key-Vault kill chain","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Commodity malware-as-a-service ISAPI backdoor ('demo.pdb' BadIIS) documented by Cisco Talos: 'lwxat' developer alias, builder tool recovered, UAT-8099 / DragonRank link, 1,800+ IIS servers compromised globally.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:cisco-talos-badiis-demo-pdb-maas-isapi-backdoor-lwxat-dragon","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acisco-talos-badiis-demo-pdb-maas-isapi-backdoor-lwxat-dragon/"}],"id":"campaign--1d938291-aa42-5eaf-b66b-3dbe737d26f4","labels":["campaign"],"modified":"2026-05-20T00:00:00.000Z","name":"BadIIS 'demo.pdb' MaaS backdoor campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The Gentlemen RaaS lists the Czech University of Finance and Administration (VSFS) and Swiss DEVO-Tech AG on its leak site.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:thegentlemen-vsfs-devo-tech-leak-site-listing","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Athegentlemen-vsfs-devo-tech-leak-site-listing/"}],"id":"incident--34383aff-fdc2-5950-8c8d-ef49f03935cc","labels":["incident"],"modified":"2026-05-20T00:00:00.000Z","name":"The Gentlemen leak-site listings (VSFS, DEVO-Tech)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft DCU disrupts the Fox Tempest malware-signing-as-a-service: 1,000+ Artifact Signing certificates revoked under an SDNY court order; downstream users include Rhysida, INC, Qilin and Akira plus Vanilla Tempest and Storm-0501/2561/0249.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:microsoft-dcu-disrupts-fox-tempest-malware-signing-as-a-servi","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amicrosoft-dcu-disrupts-fox-tempest-malware-signing-as-a-servi/"}],"id":"incident--834d899b-6b70-5909-baff-b24f19fc5216","labels":["incident"],"modified":"2026-05-20T00:00:00.000Z","name":"Microsoft DCU Fox Tempest disruption","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GitHub Action actions-cool/issues-helper compromised: 53 tags moved to an imposter commit reading Runner.Worker /proc/PID/mem for secrets; linked to the Mini Shai-Hulud cluster.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:actions-cool-issues-helper-github-action-compromised-53-tag","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aactions-cool-issues-helper-github-action-compromised-53-tag/"}],"id":"incident--88a054c6-7add-5f22-ae17-c4c8e6054222","labels":["incident"],"modified":"2026-05-20T05:00:03.000Z","name":"actions-cool/issues-helper compromise","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Drupal core 'highly critical' pre-patch warning PSA-2026-05-18: pre-auth, unauthenticated full-site compromise; patch window announced same-day; no CVE at announcement time.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:drupal-core-highly-critical-pre-patch-warning-psa-2026-05-18","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adrupal-core-highly-critical-pre-patch-warning-psa-2026-05-18/"}],"id":"incident--8dfbe06a-d065-5dae-9818-84dc765bbac9","labels":["incident"],"modified":"2026-05-20T00:00:00.000Z","name":"Drupal core pre-patch warning (PSA-2026-05-18)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Nx Console VS Code extension 18.95.0 compromised via stolen publisher credentials — an 11-minute window on 2026-05-18 (12:36–12:47 UTC) shipping a multi-channel stealer plus a macOS Python backdoor.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nx-console-vs-code-extension-18-95-0-compromised-stolen-publ","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anx-console-vs-code-extension-18-95-0-compromised-stolen-publ/"}],"id":"incident--c53d1017-a4a1-5584-a5b3-82d199ebfabb","labels":["incident"],"modified":"2026-05-20T00:00:00.000Z","name":"Nx Console extension compromise","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"A Huawei VRP enterprise-router zero-day caused POST Luxembourg's nationwide telecom outage on 23 July 2025; no CVE assigned ten months later.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:huawei-vrp-enterprise-router-zero-day-post-luxembourg-2025-o","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ahuawei-vrp-enterprise-router-zero-day-post-luxembourg-2025-o/"}],"id":"incident--cabaadcb-4d58-5fb3-a49e-09e951d27d05","labels":["incident"],"modified":"2026-05-20T00:00:00.000Z","name":"POST Luxembourg outage (Huawei VRP zero-day)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Storm-2949 — financially motivated, no nation-state attribution; SSPR voice-phishing → multi-resource Azure abuse","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:storm-2949","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Astorm-2949/"}],"id":"intrusion-set--1ed45f04-3139-5317-87b2-4440b76e55de","labels":["actor"],"modified":"2026-05-20T05:00:14.000Z","name":"Storm-2949","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated malware-signing-as-a-service (MSaaS) operator; its signspace[.]cloud infrastructure was seized on 2026-05-19 in the Microsoft DCU disruption.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:fox-tempest","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Afox-tempest/"}],"id":"intrusion-set--a887c6ff-412a-5b7d-9200-8b25db86d9cc","labels":["actor"],"modified":"2026-06-09T05:00:05.000Z","name":"Fox Tempest","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-20T05:00:01.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft DCU disruption of Fox Tempest's signing service","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-20/microsoft-dcu-disrupts-fox-tempest-malware-signing-as-a-serv/"}],"id":"relationship--298fdd94-5aea-5142-ac2f-bee4ff62c2bf","modified":"2026-05-20T05:00:01.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--834d899b-6b70-5909-baff-b24f19fc5216","spec_version":"2.1","target_ref":"intrusion-set--a887c6ff-412a-5b7d-9200-8b25db86d9cc","type":"relationship"},{"created":"2026-05-20T05:00:01.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"downstream user of the disrupted signing service","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-20/microsoft-dcu-disrupts-fox-tempest-malware-signing-as-a-serv/"}],"id":"relationship--539cb800-0bca-54b9-baf6-d370585334f7","modified":"2026-05-20T05:00:01.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--834d899b-6b70-5909-baff-b24f19fc5216","spec_version":"2.1","target_ref":"intrusion-set--4a82240a-058b-521d-83c9-4eb4ad051bcf","type":"relationship"},{"created":"2026-05-20T05:00:01.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"downstream user of the disrupted signing service","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-20/microsoft-dcu-disrupts-fox-tempest-malware-signing-as-a-serv/"}],"id":"relationship--58e421de-ed70-5144-9189-cbfef23df775","modified":"2026-05-20T05:00:01.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--834d899b-6b70-5909-baff-b24f19fc5216","spec_version":"2.1","target_ref":"intrusion-set--31b671fa-3475-5e95-847f-2b36c26b49ca","type":"relationship"},{"created":"2026-05-20T05:00:01.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"downstream user of the disrupted signing service","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-20/microsoft-dcu-disrupts-fox-tempest-malware-signing-as-a-serv/"}],"id":"relationship--950488bf-c3b8-5b3c-881e-ce4cb981bd6f","modified":"2026-05-20T05:00:01.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--834d899b-6b70-5909-baff-b24f19fc5216","spec_version":"2.1","target_ref":"intrusion-set--b30781f6-fd45-5d82-891a-b8901dd05559","type":"relationship"},{"created":"2026-05-20T05:00:13.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-20/thegentlemen-raas-lists-czech-university-and-swiss-engineeri/"}],"id":"relationship--e6e3c1a1-6789-5b28-9575-0f0d8fa65108","modified":"2026-05-20T05:00:13.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--34383aff-fdc2-5950-8c8d-ef49f03935cc","spec_version":"2.1","target_ref":"intrusion-set--2b40ef6d-7f23-5aab-aabc-f30ab0092df0","type":"relationship"},{"created":"2026-05-20T05:00:14.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-20/storm-2949-sspr-to-key-vault-azure-kill-chain/"}],"id":"relationship--e9e35d41-6c50-5631-82c8-c95110cbba8a","modified":"2026-05-20T05:00:14.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--0f0c4206-acad-5f44-8659-a7e3745a7c2e","spec_version":"2.1","target_ref":"intrusion-set--1ed45f04-3139-5317-87b2-4440b76e55de","type":"relationship"},{"created":"2026-05-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The B1ack's Stash carding marketplace publicly released 4.6M stolen payment-card records in May 2026 — its third free-release wave (after 1M in April 2024 and 4M in February 2025); SOCRadar attributes the collection to e-skimming and phishing.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:b1ack-stash-46m-card-dump-may-2026-third-free-release-wave","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ab1ack-stash-46m-card-dump-may-2026-third-free-release-wave/"}],"id":"campaign--e3a22edc-78f5-522a-889f-c8004715fceb","labels":["campaign"],"modified":"2026-05-21T00:00:00.000Z","name":"B1ack's Stash May 2026 card release","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"aliases":["FishMonger","Aquatic Panda","SixLittleMonkeys","Space Pirates"],"created":"2026-05-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-aligned APT; ESET documents a 2025 EU pivot with the EchoCreep (Discord C2) and GraphWorm (MS Graph / OneDrive C2) backdoors against Belgian, Italian, Serbian and Polish government targets.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:webworm-fishmonger-aquatic-panda-eset-echocreep-graphworm-eu","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Awebworm-fishmonger-aquatic-panda-eset-echocreep-graphworm-eu/"}],"id":"intrusion-set--d0bf3aaa-1264-59a3-81ec-0a74da7e79dd","labels":["actor","china-nexus"],"modified":"2026-06-22T00:14:59.000Z","name":"Webworm","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Red Lamassu","Bronze Medley"],"created":"2026-05-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Calypso (Red Lamassu / Bronze Medley) telco-espionage campaign deploying the Showboat Linux backdoor and JFMBackdoor for Windows.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:calypso-red-lamassu-showboat-jfmbackdoor-linux-windows-telco","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acalypso-red-lamassu-showboat-jfmbackdoor-linux-windows-telco/"}],"id":"campaign--d2309ae6-26f3-5952-802a-34f3951311fd","labels":["campaign"],"modified":"2026-05-22T05:00:09.000Z","name":"Calypso telco espionage campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"First criminal VPN anonymisation service (First VPN Service / 1VPNS) dismantled (33 servers, 27 countries); Switzerland participated in the JIT; Phobos RaaS link confirmed. Administrator Dmytro Rashevskyi and Belarusian cryptor seller Yegeniy Silayev sanctioned by US Treasury OFAC and the UK FCDO on 2026-07-13.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:operation-saffron-first-vpn-takedown-33-servers-27-countri","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aoperation-saffron-first-vpn-takedown-33-servers-27-countri/"}],"id":"incident--245eadf5-81a2-5739-9a73-6a1ecd8a1b4c","labels":["incident"],"modified":"2026-07-14T04:45:00.000Z","name":"Operation Saffron","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ICO secures a £355,880 Proceeds of Crime Act confiscation: a Markerstudy Insurance insider accessed 32K+ records off-hours and sold the data.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ico-poca-confiscation-rizwan-manjra-markerstudy-off-hours-bu","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aico-poca-confiscation-rizwan-manjra-markerstudy-off-hours-bu/"}],"id":"incident--63e5f593-6e4f-5b82-bd69-08ef3c47be7b","labels":["incident"],"modified":"2026-05-22T00:00:00.000Z","name":"Markerstudy insider POCA confiscation","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mass-poisoning of 5,561 GitHub repositories in a six-hour window; SysDiag and Optimize-Build workflows exfiltrate cloud credentials, SSH keys and OIDC tokens.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:megalodon-mass-github-cicd-backdoor-5561-repos-sysdiag-optimize-build","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amegalodon-mass-github-cicd-backdoor-5561-repos-sysdiag-optimize-build/"}],"id":"campaign--25d0ab7b-b78b-5dd9-a5ea-d10a4369d69c","labels":["campaign"],"modified":"2026-05-23T05:00:02.000Z","name":"Megalodon","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ROADtools weaponised by Midnight Blizzard (APT29), Curious Serpens (APT33) and UTA0355 for Entra ID device registration, token theft and tenant enumeration.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:roadtools-weaponised-by-midnight-blizzard-curious-serpens-uta0355-entra-id","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aroadtools-weaponised-by-midnight-blizzard-curious-serpens-uta0355-entra-id/"}],"id":"campaign--38b897dc-46f2-55b6-afb8-f0d25882f169","labels":["campaign"],"modified":"2026-05-23T00:00:00.000Z","name":"ROADtools weaponisation (Entra ID)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Telegram-distributed phishing-as-a-service exploiting the OAuth device-code flow for persistent Microsoft 365 token capture bypassing MFA (FBI PSA260521).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:fbi-psa260521-kali365-phaas-oauth-device-code-m365-mfa-bypass","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afbi-psa260521-kali365-phaas-oauth-device-code-m365-mfa-bypass/"}],"id":"campaign--47f957db-f0be-5a4e-892e-397f3feeb393","labels":["campaign"],"modified":"2026-05-23T00:00:00.000Z","name":"Kali365 PhaaS","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Rhysida claims Landeshauptstadt Stuttgart municipal-data theft for 5 BTC; the city denies a confirmed incident.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:rhysida-claims-stuttgart-municipal-data-5btc-city-denies-confirmed-incident","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Arhysida-claims-stuttgart-municipal-data-5btc-city-denies-confirmed-incident/"}],"id":"incident--4739f32b-dbb5-5102-ac09-a1c6ea7e951f","labels":["incident"],"modified":"2026-05-23T00:00:00.000Z","name":"Rhysida Stuttgart claim","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kimwolf / 'Dort' DDoS-for-hire operator (Jacob Butler, 23, Ottawa) arrested; AISURU botnet variant, 30+ Tbps peak, >25,000 attack commands, DoD-range targeting.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:kimwolf-dort-jacob-butler-ddos-botnet-arrest-ottawa-aisuru-variant","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Akimwolf-dort-jacob-butler-ddos-botnet-arrest-ottawa-aisuru-variant/"}],"id":"incident--4f13d754-e4ef-5cdb-8b23-55d52d8caeb8","labels":["incident"],"modified":"2026-05-23T00:00:00.000Z","name":"Kimwolf DDoS-for-hire arrest","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Netherlands FIOD arrests two people over EU sanctions evasion for Stark Industries / WorkTitans bulletproof hosting; 800 servers seized; NoName057(16) DDoS infrastructure dismantled.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nl-fiod-stark-industries-worktitans-mirhosting-800-servers-eu-sanctions-arrest","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anl-fiod-stark-industries-worktitans-mirhosting-800-servers-eu-sanctions-arrest/"}],"id":"incident--6ba17498-3667-5520-b313-376f59c83314","labels":["incident"],"modified":"2026-05-23T00:00:00.000Z","name":"Stark Industries hosting arrests","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["UNC1549","Smoke Sandstorm","Nimbus Manticore","Mirage Kitten"],"created":"2026-05-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Iranian APT operationalising AppDomainManager hijacking; deployed six new RAT variants (MiniUpdate / MiniJunk V2) between February and April 2026. Kaspersky, which tracks the group as Mirage Kitten and states that equivalence itself, describes it as focused on aerospace, aviation, defence and telecommunications espionage across the Middle East and Africa, and in July 2026 documented a new toolset comprising the NightLedger backdoor and the BridgeHead and ArcBridge WebSocket tunnelers (Kaspersky Securelist, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:screening-serpens-unc1549-smoke-sandstorm-nimbus-manticore-iran-apt","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ascreening-serpens-unc1549-smoke-sandstorm-nimbus-manticore-iran-apt/"}],"id":"intrusion-set--4cb4e12e-405b-5791-a842-345851f38bc4","labels":["actor","iran-nexus"],"modified":"2026-08-28T06:20:00.000Z","name":"Screening Serpens","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Packagist supply-chain wave: Laravel-Lang autoloader backdoor plus an eight-package cross-ecosystem postinstall strand.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:packagist-laravel-lang-supply-chain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Apackagist-laravel-lang-supply-chain-2026/"}],"id":"campaign--b0a427d3-cb06-54c1-8720-5320ef2b976e","labels":["campaign"],"modified":"2026-05-24T05:00:06.000Z","name":"Packagist Laravel-Lang supply-chain wave","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Breach at billing processor Unimed exfiltrates ~97,600+ patient records from six German university hospitals; attribution open.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:unimed-german-hospitals-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aunimed-german-hospitals-2026/"}],"id":"incident--fcc7a725-a55f-5765-8847-9946016f8d6e","labels":["incident"],"modified":"2026-05-24T00:00:00.000Z","name":"Unimed hospital-billing breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ShinyHunters lists Charter Communications (Spectrum) claiming 42M records; Charter denies exfiltration of sensitive PI/CPNI.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:shinyhunters-charter-spectrum-listing-42m-claim","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ashinyhunters-charter-spectrum-listing-42m-claim/"}],"id":"incident--712f13c5-7f64-54c8-ba3d-f8cc046870b8","labels":["incident"],"modified":"2026-05-25T00:00:00.000Z","name":"Charter/Spectrum listing","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-26T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GTIG-documented Chinese-language phishing-as-a-service ecosystem performing real-time OTP relay over RCS/iMessage, defeating TOTP and SMS MFA.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:chinese-language-phaas-otp-relay","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Achinese-language-phaas-otp-relay/"}],"id":"campaign--120459eb-b908-508e-bc99-970bccae15bc","labels":["campaign"],"modified":"2026-05-26T00:00:00.000Z","name":"Chinese-language PhaaS OTP-relay ecosystem","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-26T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ACR Stealer distributed via counterfeit Claude AI download pages + malicious search ads","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:acr-stealer-fake-claude","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aacr-stealer-fake-claude/"}],"id":"campaign--2f0225a3-e58b-53cb-be33-9e98265c7d50","labels":["campaign"],"modified":"2026-05-26T00:00:00.000Z","name":"ACR Stealer fake-Claude distribution","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-26T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Cross-ecosystem supply-chain campaign (npm / PyPI / Crates.io) featuring AI-assistant configuration poisoning.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:trapdoor","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Atrapdoor/"}],"id":"campaign--c259ea06-6b98-57ff-833b-cabba0f37a1e","labels":["campaign"],"modified":"2026-05-26T05:00:00.000Z","name":"TrapDoor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-26T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Lazarus three-stage memory-only RAT chain (DPAPILoader / RemotePELoader / RemotePE) with HellsGate and ETW patching.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:remotepe","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aremotepe/"}],"id":"tool--48946420-506f-5978-bc3f-50197b40c233","labels":["north-korea-nexus","tool"],"modified":"2026-05-26T05:00:06.000Z","name":"RemotePE","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-05-27T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"~600,000 property and legal-entity records exfiltrated from Lithuania's Centre of Registers via abused institutional API credentials; a foreign-state actor is suspected; the agency head resigned.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:lithuania-centre-of-registers-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Alithuania-centre-of-registers-2026/"}],"id":"incident--89fb0c5e-edfa-5158-a0e5-d8f9ede3c99f","labels":["incident"],"modified":"2026-05-27T00:00:00.000Z","name":"Lithuania Centre of Registers breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Symantec-documented MuddyWater/Seedworm Q1 2026 campaign: DLL side-loading via signed Fortemedia / SentinelOne binaries, ChromElevator App-Bound-Encryption bypass, Node.js orchestration.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:muddywater-seedworm-fortemedia-sentinelone-dll-sideload-chromelevator-nodejs","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amuddywater-seedworm-fortemedia-sentinelone-dll-sideload-chromelevator-nodejs/"}],"id":"campaign--09037878-1f2c-55dc-8ac3-f5702d1a5274","labels":["campaign","iran-nexus"],"modified":"2026-05-28T00:00:00.000Z","name":"MuddyWater Q1 2026 DLL side-loading campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Akira ransomware kill chain reconstructed entirely from SSLVPN syslog and Windows EVTX, with no EDR present (SANS ISC).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:sans-isc-akira-kill-chain-sslvpn-syslog-evtx-no-edr","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asans-isc-akira-kill-chain-sslvpn-syslog-evtx-no-edr/"}],"id":"campaign--18946c69-54d8-5a5f-a681-4caaaf4bb756","labels":["campaign"],"modified":"2026-05-28T05:00:10.000Z","name":"Akira kill-chain reconstruction (SANS ISC)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GlassWorm developer-targeting botnet: all four C2 channels (Solana / BitTorrent DHT / Google Calendar / VPS) severed simultaneously by CrowdStrike, Google and Shadowserver.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:glassworm-developer-botnet-takedown-crowdstrike-google-shadowserver-russia-attri","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aglassworm-developer-botnet-takedown-crowdstrike-google-shadowserver-russia-attri/"}],"id":"campaign--2077cb0c-5951-5fde-a010-189758d855e7","labels":["campaign"],"modified":"2026-05-28T05:00:02.000Z","name":"GlassWorm takedown","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"aliases":["Luna Moth","UNC3753"],"created":"2026-05-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"FBI FLASH CSA 260526: Silent Ransom Group (Luna Moth / UNC3753) sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:fbi-flash-csa-260526-silent-ransom-group-physical-usb-attacks-us-law-firms","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afbi-flash-csa-260526-silent-ransom-group-physical-usb-attacks-us-law-firms/"}],"id":"campaign--c1ec11f8-50b7-582b-afc1-257315e8d63a","labels":["campaign"],"modified":"2026-06-06T05:00:07.000Z","name":"Silent Ransom Group physical USB intrusions","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft Defender Experts: AI-chatbot search-poisoning extends the SEO-lure pattern; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners (gminer / lolMiner / SRBMiner-MULTI) under a signed Microsoft binary.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:microsoft-ai-chatbot-search-poisoning-cryptojacking-screenconnect-process-hollow","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amicrosoft-ai-chatbot-search-poisoning-cryptojacking-screenconnect-process-hollow/"}],"id":"campaign--e6a6a16a-69e6-555d-9c35-9dd87377218c","labels":["campaign"],"modified":"2026-05-28T05:00:09.000Z","name":"AI-chatbot search-poisoning cryptojacking","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Dutch National Police arrest a 35-year-old from Buren over the AFC Ajax breach: 300k+ fan accounts and 42k+ season tickets exposed via misconfigured API access control and shared keys.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:afc-ajax-amsterdam-arrest-2026-05-26-300k-fan-records-shared-keys-misconfigured","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aafc-ajax-amsterdam-arrest-2026-05-26-300k-fan-records-shared-keys-misconfigured/"}],"id":"incident--feabf951-ff99-5521-8cb0-5232db16b650","labels":["incident"],"modified":"2026-05-28T05:00:03.000Z","name":"AFC Ajax fan-data breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Hacktivist front attributed to Iran's MOIS, responsible for the March 2026 destructive breach of LA Metro (LACMTA): 700 GB exfiltrated, VMs and backups deliberately destroyed.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:ababil-of-minab-mois-attribution-lacmta-march-2026-700gb-backups-destroyed","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aababil-of-minab-mois-attribution-lacmta-march-2026-700gb-backups-destroyed/"}],"id":"intrusion-set--a6d577f5-2d27-509e-87d0-4ca0190cbd7e","labels":["actor","iran-nexus"],"modified":"2026-05-28T05:00:05.000Z","name":"Ababil of Minab","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-28T05:00:08.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-28/muddywater-seedworm-symantec-and-carbon-black-document-new-d/"}],"id":"relationship--b967b819-6105-5d26-ae9b-acc262d60e52","modified":"2026-05-28T05:00:08.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--09037878-1f2c-55dc-8ac3-f5702d1a5274","spec_version":"2.1","target_ref":"intrusion-set--a494e603-7278-535a-ac86-434081d6d216","type":"relationship"},{"created":"2026-05-28T05:00:10.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-28/sans-isc-akira-ransomware-kill-chain-reconstructed-entirely/"}],"id":"relationship--30f6de0c-9008-5300-8c1a-c52faf125704","modified":"2026-05-28T05:00:10.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--18946c69-54d8-5a5f-a681-4caaaf4bb756","spec_version":"2.1","target_ref":"intrusion-set--b30781f6-fd45-5d82-891a-b8901dd05559","type":"relationship"},{"created":"2026-05-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Dutch Police and NCSC-NL dismantle the Asocks residential-proxy botnet — 17M devices, 200 NL-hosted servers seized.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:dutch-police-ncsc-asocks-residential-proxy-takedown","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Adutch-police-ncsc-asocks-residential-proxy-takedown/"}],"id":"campaign--1244faee-4700-50ae-8691-863a51abd2f1","labels":["campaign"],"modified":"2026-05-29T05:00:04.000Z","name":"Asocks residential-proxy takedown","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Grandoreiro 2026 Iberian campaign — Delphi DLL side-loading, WebSocket/STUN C2; parallel ESET-documented BTMOB Android RAT malware-as-a-service.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:grandoreiro-2026-iberian-watchguard-eu-banks-btmob-maas","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Agrandoreiro-2026-iberian-watchguard-eu-banks-btmob-maas/"}],"id":"campaign--54eb58a5-2e0d-51ef-9ec7-a03f6280dc82","labels":["campaign"],"modified":"2026-05-29T00:00:00.000Z","name":"Grandoreiro 2026 Iberian campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated cluster targeting crypto organizations via LinkedIn recruiter lures, the AUDIOFIX macOS infostealer, and a MINIRAT npm pivot into CI/CD.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:jinx-0164-crypto-firms-linkedin-audiofix-minirat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ajinx-0164-crypto-firms-linkedin-audiofix-minirat/"}],"id":"campaign--70d8d123-dbe0-5a50-a84e-77ce9a9fdd97","labels":["campaign"],"modified":"2026-05-29T05:00:12.000Z","name":"JINX-0164","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Lookalike site ukvisaportal.com exposed 100K passport scans and selfies via a misconfigured S3 bucket.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:uk-visa-portal-s3-100k-passport-selfies-exposure","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Auk-visa-portal-s3-100k-passport-selfies-exposure/"}],"id":"incident--84af1c43-f9d3-505b-aeae-e23cb1b13858","labels":["incident"],"modified":"2026-05-29T00:00:00.000Z","name":"UK visa-portal lookalike exposure","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Carnival Corporation confirms a 5.99M-record ShinyHunters breach spanning Princess, Holland America, Cunard and Costa.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:carnival-corporation-5-99m-shinyhunters-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acarnival-corporation-5-99m-shinyhunters-breach-2026/"}],"id":"incident--f44af7c6-5e4a-5a8e-9d6e-7966dd428d66","labels":["incident"],"modified":"2026-05-29T00:00:00.000Z","name":"Carnival Corporation breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-29T05:00:03.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-29/carnival-corporation-confirms-5-99-m-record-shinyhunters-bre/"}],"id":"relationship--448c64da-b43f-5d5c-8de9-a963f8c5784b","modified":"2026-05-29T05:00:03.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--f44af7c6-5e4a-5a8e-9d6e-7966dd428d66","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-05-29T05:00:14.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-29/the-gentlemen-ransomware-microsoft-publishes-full-technical/"}],"id":"relationship--5c7491c2-3102-5ea0-8662-2462da69bf05","modified":"2026-05-29T05:00:14.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--bf28afc2-e4df-5e9f-8243-2a496b07538a","spec_version":"2.1","target_ref":"intrusion-set--2b40ef6d-7f23-5aab-aabc-f30ab0092df0","type":"relationship"},{"created":"2026-05-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Nightmare Eclipse's 2026 public Windows zero-day drop series: YellowKey (BitLocker, later CVE-2026-45585) and GreenPlasma (CTFMON LPE) with public PoCs, MiniPlasma (cldflt.sys CfAbortHydration, claimed CVE-2020-17103 regression on fully patched Windows 11) as the third PoC; after Microsoft's Digital Crimes Unit threatened criminal action the persona threatened a further release for 14 July 2026, with GreenPlasma/MiniPlasma still unpatched.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:nightmare-eclipse-microsoft-dcu-threat-greenplasma-miniplasmaaac","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Anightmare-eclipse-microsoft-dcu-threat-greenplasma-miniplasmaaac/"}],"id":"campaign--1d1f0f6c-868a-5f95-b749-e65c0a9c3d8d","labels":["campaign"],"modified":"2026-07-09T20:38:00.000Z","name":"Nightmare Eclipse Windows zero-day series","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ghost Stadium PhaaS — 300+ FIFA domain clones targeting EU fans","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:ghost-stadium-phaas-300-fifa-domain-clones-eu-fan-credentials","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aghost-stadium-phaas-300-fifa-domain-clones-eu-fan-credentials/"}],"id":"campaign--409dd20a-e13a-5a06-a835-173656507d39","labels":["campaign"],"modified":"2026-06-01T05:00:25.000Z","name":"Ghost Stadium PhaaS","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malvertising via ChatGPT share links delivering the Beagle infostealer.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:llmshare-malvertising-chatgpt-share-links-infostealer-google","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Allmshare-malvertising-chatgpt-share-links-infostealer-google/"}],"id":"campaign--64c7b0d2-ea73-5bb5-bbd1-12d06d32e3c2","labels":["campaign"],"modified":"2026-05-30T05:00:03.000Z","name":"LLMShare","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ChatGPT Markdown-renderer weakness trusting third-party image URLs, weaponisable for phishing (Permiso Security).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:chatgphish-chatgpt-markdown-rendering-flaw-permiso-security","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Achatgphish-chatgpt-markdown-rendering-flaw-permiso-security/"}],"id":"campaign--6c8596ba-4c8a-5147-9420-61012462a826","labels":["campaign"],"modified":"2026-05-30T05:00:09.000Z","name":"ChatGPhish","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Sysdig TRT documents the first observed LLM-agent-driven intrusion, exploiting CVE-2026-39987 (marimo).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:sysdig-trt-llm-agent-driven-intrusion-marimo-cve-2026-39987","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Asysdig-trt-llm-agent-driven-intrusion-marimo-cve-2026-39987/"}],"id":"incident--ba4e5fef-c212-56b9-bf2d-ec22556f8287","labels":["incident"],"modified":"2026-05-30T00:00:00.000Z","name":"First observed LLM-agent-driven intrusion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"CNIL fines IQVIA €5M for health-data-warehouse security failures.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:cnil-fines-iqvia-5m-health-data-warehouse-security-failures","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acnil-fines-iqvia-5m-health-data-warehouse-security-failures/"}],"id":"incident--f1f92cb9-06dd-52df-a4d5-6ad9a3f5bd55","labels":["incident"],"modified":"2026-05-30T00:00:00.000Z","name":"CNIL IQVIA fine","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-05-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russia-nexus AI-assisted threat cluster documented running five parallel attack waves against Ukraine.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:greyvibe-russia-nexus-ai-assisted-five-parallel-ukraine-attack","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Agreyvibe-russia-nexus-ai-assisted-five-parallel-ukraine-attack/"}],"id":"intrusion-set--4630ca0b-eef7-59c4-a983-8a966e74a78a","labels":["actor","russia-nexus"],"modified":"2026-05-30T05:00:02.000Z","name":"GREYVIBE","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-05-30T05:00:01.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"curated relation type: part-of","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"part-of"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-05-30/ghost-stadium-phaas-300-fifa-domain-clones-multi-language-fa/"}],"id":"relationship--c9a8de41-8666-57b3-a953-78306963dda6","modified":"2026-05-30T05:00:01.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"campaign--409dd20a-e13a-5a06-a835-173656507d39","spec_version":"2.1","target_ref":"campaign--2e340d96-a5fc-518c-afbb-986436597823","type":"relationship"},{"created":"2026-05-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"'Signal Support' impersonation phishing harvesting cloud-backup recovery keys.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:signal-support-impersonation-backup-recovery-key-phishing","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asignal-support-impersonation-backup-recovery-key-phishing/"}],"id":"campaign--01131382-5ac1-5609-9ee9-f3d744381a0b","labels":["campaign"],"modified":"2026-05-31T00:00:00.000Z","name":"'Signal Support' recovery-key phishing","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-05-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"California's Attorney General sues former 23andMe (Chrome Holding Co.) over the 2023 genetic-data breach.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:california-ag-sues-23andme-chrome-holding-2023-genetic-breach","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acalifornia-ag-sues-23andme-chrome-holding-2023-genetic-breach/"}],"id":"incident--95e5f11a-fc3d-5920-b503-54042a09d973","labels":["incident"],"modified":"2026-05-31T00:00:00.000Z","name":"California AG v. 23andMe","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Italy's low-cost commercial spyware economy: Morpheus (IPS Intelligence) and Spyrtacus (SIO) abusing the Android Accessibility API.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:italy-low-cost-commercial-spyware-morpheus-spyrtacus","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aitaly-low-cost-commercial-spyware-morpheus-spyrtacus/"}],"id":"campaign--31a8289b-223b-51c2-a3a6-cf6cfce3de26","labels":["campaign"],"modified":"2026-06-01T05:00:03.000Z","name":"Italian low-cost commercial spyware","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SmartApeSG ClickFix stages an unnamed RAT pivoting to weaponised NetSupport Manager.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:smartapesg-clickfix-staging-rat-to-netsupport-manager","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asmartapesg-clickfix-staging-rat-to-netsupport-manager/"}],"id":"campaign--cbbca508-d192-5f22-9ea6-49135495fe89","labels":["campaign"],"modified":"2026-06-01T00:00:00.000Z","name":"SmartApeSG ClickFix campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"npm dependency-confusion campaigns targeting internal corporate namespaces: 33 packages found by Microsoft, 176 by Sonatype.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:npm-dependency-confusion-internal-namespace-campaigns-ms-sonatype","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Anpm-dependency-confusion-internal-namespace-campaigns-ms-sonatype/"}],"id":"campaign--e1596122-def4-5f17-995f-ed28b79db93d","labels":["campaign"],"modified":"2026-06-01T00:00:00.000Z","name":"npm dependency-confusion wave 2026","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Researcher-confirmed PostHog AWS exploit forcing EU/US cloud credential rotation and an outage.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:posthog-aws-exploit-eu-us-cloud-credential-rotation","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aposthog-aws-exploit-eu-us-cloud-credential-rotation/"}],"id":"incident--816fa767-6054-5878-b4d3-85a0eca584c5","labels":["incident"],"modified":"2026-06-01T00:00:00.000Z","name":"PostHog AWS exploit","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-01T05:00:04.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex/"}],"id":"relationship--9b2f343e-5886-52a9-85f4-9bf6b6f0280e","modified":"2026-06-01T05:00:04.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--484eef5e-e3ae-5008-b364-c9e900601287","spec_version":"2.1","target_ref":"intrusion-set--6af6c934-d94e-55d8-bd12-ea920b3e7ec2","type":"relationship"},{"created":"2026-06-01T05:00:09.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-01/healthcare-hipaa-breach-healthcare-supply-chain-exposure/"}],"id":"relationship--d5c8665f-a710-57bb-a6e1-34c281f1c50a","modified":"2026-06-01T05:00:09.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--70a8520d-b347-5308-9bda-b57b3ffc9d0b","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-06-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Operation Dragon Weave — China-nexus espionage (Czech/Taiwan) with Azure Blob dead-drop C2","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:operation-dragon-weave","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aoperation-dragon-weave/"}],"id":"campaign--250a9198-3baa-5f9c-9fdd-ad3f399b5d04","labels":["campaign","china-nexus"],"modified":"2026-06-02T05:00:11.000Z","name":"Operation Dragon Weave","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"WordPress malware abusing Steam profile comments as a Unicode-steganography C2 channel (GoDaddy).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:wordpress-steam-profile-c2-unicode-steganography","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Awordpress-steam-profile-c2-unicode-steganography/"}],"id":"campaign--3d6c394f-aa7a-59dc-bd90-c47d96ad2b5a","labels":["campaign"],"modified":"2026-06-02T00:00:00.000Z","name":"WordPress Steam-profile C2 malware","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Gamaredon GammaPhish/GammaWorm — an NTFS-ADS USB and network worm documented by Sekoia.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:gamaredon-gammaphish-gammaworm","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Agamaredon-gammaphish-gammaworm/"}],"id":"campaign--484eef5e-e3ae-5008-b364-c9e900601287","labels":["campaign","russia-nexus"],"modified":"2026-06-02T00:00:00.000Z","name":"Gamaredon GammaPhish / GammaWorm","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Worm backdooring 32 @redhat-cloud-services npm packages; a TeamPCP / Mini Shai-Hulud variant.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:miasma-redhat-npm-supply-chain","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amiasma-redhat-npm-supply-chain/"}],"id":"campaign--e778509e-cc8c-587e-a850-eb7ea1fbfb8a","labels":["campaign"],"modified":"2026-06-27T05:17:51.000Z","name":"Miasma","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Spain arrests a doxer publishing data on INCIBE, Attorney-General and Civil Guard staff ('Police-ESP-Doxed').","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:spain-national-police-arrest-doxer-incibe-ag-civil-guard","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aspain-national-police-arrest-doxer-incibe-ag-civil-guard/"}],"id":"incident--5ace8fec-873d-5cd8-88f7-b4cca731875f","labels":["incident"],"modified":"2026-06-02T00:00:00.000Z","name":"Spanish doxer arrest","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russia-nexus (FSB-linked) APT focused on Ukrainian government targets; pipeline coverage documents the GammaPhish/GammaWorm NTFS-ADS USB+network worm (Sekoia) and ESET's 2025 annual paper on its tunnel/Workers/dead-drop infrastructure and collaboration with Turla.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:gamaredon","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Agamaredon/"}],"id":"intrusion-set--6af6c934-d94e-55d8-bd12-ea920b3e7ec2","labels":["actor","russia-nexus"],"modified":"2026-06-29T00:21:18.000Z","name":"Gamaredon","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-06-02T05:00:02.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-02/miasma-worm-backdoors-32-red-hat-cloud-services-npm-packages/"}],"id":"relationship--57d593c0-3685-575e-82eb-432755451049","modified":"2026-06-02T05:00:02.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--e778509e-cc8c-587e-a850-eb7ea1fbfb8a","spec_version":"2.1","target_ref":"intrusion-set--6c96f5b6-ce98-5a63-b571-9db754889d08","type":"relationship"},{"created":"2026-06-03T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SVG phishing wave using the application/ecmascript MIME type to evade WAF and email pattern-matching (SANS ISC).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:svg-ecmascript-phishing-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asvg-ecmascript-phishing-2026/"}],"id":"campaign--b7b23662-4b8a-5cb9-b598-9b52416d7824","labels":["campaign"],"modified":"2026-06-03T00:00:00.000Z","name":"SVG application/ecmascript phishing wave","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-03T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SideCopy/APT36 delivering XenoRAT via mshta/HTA against Afghan provincial treasuries.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:operation-xenofiscal-sidecopy","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aoperation-xenofiscal-sidecopy/"}],"id":"campaign--c912488a-d321-5032-9f5a-92a183a5d178","labels":["campaign"],"modified":"2026-06-03T05:00:07.000Z","name":"Operation XENOFISCAL","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-03T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Dashlane TOTP brute-force incident: encrypted vaults of fewer than 20 personal-plan users downloaded.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:dashlane-totp-brute-force-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adashlane-totp-brute-force-2026/"}],"id":"incident--58ecfa58-90fc-5e59-90b2-c65c8835b3c8","labels":["incident"],"modified":"2026-06-03T00:00:00.000Z","name":"Dashlane TOTP brute-force","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-03T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Attacker-built AI-orchestrated EDR-evasion testing lab documented by Sophos X-Ops.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:sophos-ai-edr-evasion-lab","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Asophos-ai-edr-evasion-lab/"}],"id":"tool--9ca682bf-b168-5a7c-9b3b-19153962a82d","labels":["tool"],"modified":"2026-06-03T00:00:00.000Z","name":"AI-orchestrated EDR-evasion lab","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-06-03T05:00:07.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Seqrite Labs documents the campaign as SideCopy (Transparent Tribe / APT36, Pakistan-attributed); the actor key was registered on 2026-08-17 and this edge connects the existing campaign record to it","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-03/operation-xenofiscal-sidecopy-apt36-hits-provincial-treasury/"}],"id":"relationship--d671eb83-e18d-53e8-bf1e-8e286b532c19","modified":"2026-06-03T05:00:07.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--c912488a-d321-5032-9f5a-92a183a5d178","spec_version":"2.1","target_ref":"intrusion-set--2f0d1d97-f82b-5fe1-bbe3-b81d635ceaea","type":"relationship"},{"created":"2026-06-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DesckVB RAT malspam laundered via Google DoubleClick redirects; AMSI/ETW patching; DACH-themed lures.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:desckvb-rat-doubleclick-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Adesckvb-rat-doubleclick-2026/"}],"id":"campaign--73e9692c-c672-5806-b5a2-373703009139","labels":["campaign"],"modified":"2026-06-04T05:00:04.000Z","name":"DesckVB RAT malspam","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Symantec-documented five-month mailbox-espionage intrusion at a global stock exchange: Aspose-based OST stealer with Dropbox/OneDrive exfiltration.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:stock-exchange-mailbox-espionage-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Astock-exchange-mailbox-espionage-2026/"}],"id":"campaign--8db2b76d-a852-5bb1-9d0b-74a0f13ea387","labels":["campaign"],"modified":"2026-06-04T05:00:12.000Z","name":"Stock-exchange mailbox espionage","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"NCSC-CH: Booking.com breach data feeds WhatsApp hotel-booking phishing — TWINT/bank spoofing plus booking-channel account takeover.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ncsc-ch-booking-hotel-phishing-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ancsc-ch-booking-hotel-phishing-2026/"}],"id":"incident--035a39c9-d8f9-5a5c-984e-f75e8cb0e4ad","labels":["incident"],"modified":"2026-06-04T05:00:00.000Z","name":"Booking.com-fed hotel phishing (CH)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"OFAC sanctions Nobitex and three further Iranian exchanges as an IRGC-affiliated conduit for ransomware proceeds.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ofac-nobitex-iran-sanctions-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aofac-nobitex-iran-sanctions-2026/"}],"id":"incident--2a8776f7-75fe-5158-a333-89bf4097c848","labels":["incident"],"modified":"2026-06-04T00:00:00.000Z","name":"OFAC Nobitex sanctions","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Shared booking-SaaS breach exposes guests at 100+ Dutch, Belgian and Irish hotels, feeding a phishing wave.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:dutch-hotels-booking-saas-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adutch-hotels-booking-saas-breach-2026/"}],"id":"incident--56e4a25c-95e1-55ad-ac88-c240a0d31f4d","labels":["incident"],"modified":"2026-06-04T00:00:00.000Z","name":"Dutch/Belgian/Irish booking-SaaS breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UN WFP Palestine Self-Registration breach: roughly 600k Gaza households' IDs and locations exposed.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:wfp-gaza-sra-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Awfp-gaza-sra-breach-2026/"}],"id":"incident--d4d1ed2f-3099-5260-842f-82324cd99297","labels":["incident"],"modified":"2026-06-04T00:00:00.000Z","name":"UN WFP Gaza registration breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["CL-CRI-1089"],"created":"2026-06-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Operation FlutterBridge (CL-CRI-1089) — notarized macOS FlutterShell backdoor via Google Ads malvertising","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:flutterbridge-cl-cri-1089","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aflutterbridge-cl-cri-1089/"}],"id":"campaign--233046b0-acac-5549-9278-3ef98e4d5437","labels":["campaign"],"modified":"2026-06-05T05:00:02.000Z","name":"Operation FlutterBridge","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DentaQuest — ShinyHunters extortion victim; 234 GB leaked, 2.6M dental-benefit records","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:dentaquest-shinyhunters-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adentaquest-shinyhunters-2026/"}],"id":"incident--70a8520d-b347-5308-9bda-b57b3ffc9d0b","labels":["incident"],"modified":"2026-06-05T05:00:07.000Z","name":"DentaQuest","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UK National Federation of Subpostmasters hit by ransomware via a cPanel flaw.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nfsp-cpanel-ransomware-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anfsp-cpanel-ransomware-2026/"}],"id":"incident--c51b841b-521b-546c-b95d-a23ab09259f0","labels":["incident"],"modified":"2026-06-05T00:00:00.000Z","name":"NFSP ransomware","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"TA4922 — China-nexus financially-motivated cluster; Atlas RAT/RomulusLoader/SilentRunLoader, expands to DE/UK/IT","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:ta4922","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ata4922/"}],"id":"intrusion-set--4e87dc95-c3b9-5e1c-a184-0545c12be19b","labels":["actor","china-nexus"],"modified":"2026-08-28T06:38:00.000Z","name":"TA4922","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["UNC5221","WARP PANDA"],"created":"2026-06-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-nexus APT deploying BRICKSTORM on edge devices, running MSP supply-chain intrusions, bypassing M365 conditional access, and using the AGENTPSD/PLENET tooling.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:verdantbamboo","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Averdantbamboo/"}],"id":"intrusion-set--9c09f020-5334-5f79-ac59-c7c066192e91","labels":["actor","china-nexus"],"modified":"2026-06-14T23:57:35.000Z","name":"VerdantBamboo","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-06-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"IronWorm — Rust npm supply-chain worm with eBPF kernel rootkit, Tor C2, cloud/AI-key sweep","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:ironworm","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aironworm/"}],"id":"campaign--2ed98b80-bd10-56f3-9f84-b2a125220fb6","labels":["campaign"],"modified":"2026-06-14T23:57:21.000Z","name":"IronWorm","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"OP-512 — China-linked cluster, cryptographically-unique self-reporting IIS web-shell framework","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:op-512","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aop-512/"}],"id":"intrusion-set--9dc3632f-6070-51b0-998a-cdd447d44273","labels":["actor","china-nexus"],"modified":"2026-06-06T05:00:05.000Z","name":"OP-512","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-06-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Magecart skimmer hosted in Stripe customer-metadata fields, exfiltrating via api.stripe.com.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:magecart-stripe-api-skimmer-customer-metadata","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amagecart-stripe-api-skimmer-customer-metadata/"}],"id":"campaign--66cfd224-abc7-5cba-8da0-97e3871382ad","labels":["campaign"],"modified":"2026-06-07T00:00:00.000Z","name":"Stripe-metadata Magecart skimmer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"WeTransfer-themed JavaScript leading to a steganographic JPEG loader hosted on Cloudflare Workers/R2 (SANS ISC).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:sans-isc-steganographic-jpeg-loader-cloudflare-workers-r2","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asans-isc-steganographic-jpeg-loader-cloudflare-workers-r2/"}],"id":"campaign--728b5e39-1a3a-589f-b38d-5e9620a2e73d","labels":["campaign"],"modified":"2026-06-07T00:00:00.000Z","name":"WeTransfer steganographic JPEG loader","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The hijacked polyfill[.]io domain reactivates, serving HTTP 401 credential prompts.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:polyfill-io-domain-reactivates-http-401-credential-prompts","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Apolyfill-io-domain-reactivates-http-401-credential-prompts/"}],"id":"incident--510a5690-774e-5ca3-9ef2-e965df531725","labels":["incident"],"modified":"2026-06-07T00:00:00.000Z","name":"polyfill.io reactivation","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"FIFA World Cup 2026 pre-event threat cluster — GHOST STADIUM phishing-domain layer, Massiv/Perseus Android banking trojans via Zombinder in pirated streaming apps, 13,000+ malicious domains","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:fifa-world-cup-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afifa-world-cup-2026/"}],"id":"campaign--2e340d96-a5fc-518c-afbb-986436597823","labels":["campaign"],"modified":"2026-06-08T05:00:00.000Z","name":"FIFA World Cup 2026 pre-event threat cluster","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"C0XMO — cross-platform Gafgyt DDoS botnet variant propagating via DD-WRT UPnP flaw (FortiGuard)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:c0xmo-gafgyt","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ac0xmo-gafgyt/"}],"id":"campaign--b764ca15-313e-5831-bc00-87155be72098","labels":["campaign"],"modified":"2026-06-08T05:00:04.000Z","name":"C0XMO","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ICO secures a £118,852 Proceeds of Crime Act confiscation from two former RAC employees who sold ~30,000 customer records (insider data theft).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ico-rac-poca-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aico-rac-poca-2026/"}],"id":"incident--bcaff107-299f-57dd-8889-0ff2d2f6b470","labels":["incident"],"modified":"2026-06-08T00:00:00.000Z","name":"RAC insider POCA confiscation","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malware-delivery campaigns impersonating AI brands, attributed to Storm-3075 and Fox Tempest.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:ai-brand-impersonation-storm3075-foxtempest","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aai-brand-impersonation-storm3075-foxtempest/"}],"id":"campaign--77b2fb31-00aa-54a3-911e-d7bb4250fb7b","labels":["campaign"],"modified":"2026-06-09T00:00:00.000Z","name":"AI-brand impersonation malware delivery","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft Teams external-chat phishing attributed to APT29 (Cloaked Ursa) and UNC6692.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:teams-external-chat-phishing","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ateams-external-chat-phishing/"}],"id":"campaign--ed3466a4-0787-5700-8708-c78d8b16695b","labels":["campaign"],"modified":"2026-06-09T00:00:00.000Z","name":"Microsoft Teams external-chat phishing","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Meta files a contempt complaint against NSO Group over new WhatsApp spyware phishing.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:meta-nso-whatsapp-contempt","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ameta-nso-whatsapp-contempt/"}],"id":"incident--612d4d23-2229-5dfd-b614-f5e4fa6bf626","labels":["incident"],"modified":"2026-06-09T00:00:00.000Z","name":"Meta v. NSO contempt complaint","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Oxford University CareerConnect (Group GTI) SaaS breach.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:oxford-careerconnect-breach","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aoxford-careerconnect-breach/"}],"id":"incident--e129e54d-ca96-5272-b9b8-5a84f28e0e0c","labels":["incident"],"modified":"2026-06-09T00:00:00.000Z","name":"Oxford CareerConnect breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-09T05:00:05.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-09/microsoft-threat-intelligence-ai-brand-impersonation-drives/"}],"id":"relationship--df7bfb75-67ab-5860-8dea-b390603f35e9","modified":"2026-06-09T05:00:05.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--77b2fb31-00aa-54a3-911e-d7bb4250fb7b","spec_version":"2.1","target_ref":"intrusion-set--a887c6ff-412a-5b7d-9200-8b25db86d9cc","type":"relationship"},{"created":"2026-06-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"NCSC-CH Week 23: coordinated job-seeker targeting — fake interviews, reshipping identity theft, and LinkedIn-to-GitHub infostealer delivery.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:ncsc-ch-jobseeker-targeting-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ancsc-ch-jobseeker-targeting-2026/"}],"id":"campaign--12e60bd8-3593-5466-94d9-9232b85db3f0","labels":["campaign"],"modified":"2026-06-10T05:00:02.000Z","name":"Job-seeker targeting wave (CH)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GIFTEDCROOK delivered by UAC-0226 and Earth Dahu, still exploiting WinRAR CVE-2025-8088 against Ukraine (Trend Micro).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:uac0226-giftedcrook-winrar-cve-2025-8088","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Auac0226-giftedcrook-winrar-cve-2025-8088/"}],"id":"campaign--4cd4fd87-ca93-5730-8e88-4e32bd24b3ec","labels":["campaign"],"modified":"2026-06-10T00:00:00.000Z","name":"UAC-0226 GIFTEDCROOK WinRAR exploitation","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"aliases":["SessionGate","RemusStealer","AnimateClipper"],"created":"2026-06-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"TDS-gated distribution ecosystem impersonating Ghidra, dnSpy and ILSpy download sites to deliver SessionGate, RemusStealer and AnimateClipper (Check Point).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:tds-security-tool-impersonation-checkpoint","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Atds-security-tool-impersonation-checkpoint/"}],"id":"campaign--99a75f20-b477-5d0e-bf73-f8b7c7e57e91","labels":["campaign"],"modified":"2026-06-10T05:00:15.000Z","name":"Security-tool impersonation TDS campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Exchange Online inbound spoofing bypassing SPF/DKIM/DMARC on third-party-MX tenants; no patch available.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:ghost-sender-exchange-online-spoofing","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aghost-sender-exchange-online-spoofing/"}],"id":"campaign--d478a121-0469-5a33-90e9-9e7838cf3b27","labels":["campaign"],"modified":"2026-06-10T05:00:01.000Z","name":"Ghost-Sender","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The French government's Tchap Matrix messenger breached via account takeover; 73,467 civil servants' metadata exposed; CNIL notified.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:tchap-french-government-messenger-breach","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Atchap-french-government-messenger-breach/"}],"id":"incident--33f41262-2e1c-540a-a6b5-a7467a029c3b","labels":["incident"],"modified":"2026-06-10T00:00:00.000Z","name":"Tchap messenger breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Logic flaw in Meta's Instagram AI support tool (High Touch Support) — social-engineerable into resetting passwords — led to 20,225 account takeovers; Maine AG notified; pro-Iranian abuse reported.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:meta-instagram-ai-support-account-takeover","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ameta-instagram-ai-support-account-takeover/"}],"id":"incident--dca8d1dc-ed41-59f2-b4b6-d0eef41f1691","labels":["incident"],"modified":"2026-06-10T00:00:00.000Z","name":"Instagram AI-support account takeovers","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Volt Typhoon-linked JDY botnet expands to 1,500+ SOHO/IoT devices with sub-24-hour post-disclosure vulnerability scanning.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:jdy-botnet-volt-typhoon-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ajdy-botnet-volt-typhoon-2026/"}],"id":"campaign--6a4d909f-ea90-5f67-8dec-174dccc69813","labels":["campaign","china-nexus"],"modified":"2026-06-11T05:00:04.000Z","name":"JDY botnet","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ShinyHunters Oracle PeopleSoft data-theft campaign: 100+ organizations, ~300 instances, education-heavy victimology; University of Nottingham confirmed.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:shinyhunters-peoplesoft-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ashinyhunters-peoplesoft-2026/"}],"id":"campaign--93055f64-88f3-5cbc-8079-6ef0e5b69f2f","labels":["campaign"],"modified":"2026-06-16T05:09:02.000Z","name":"ShinyHunters PeopleSoft campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"An unauthenticated ServiceNow REST endpoint (/api/now/related_list_edit/create) allowed querying customer instance tables.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:servicenow-unauth-rest-api-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aservicenow-unauth-rest-api-2026/"}],"id":"incident--ed79419b-df70-54fa-ae7a-4aadc5329b32","labels":["incident"],"modified":"2026-06-11T00:00:00.000Z","name":"ServiceNow unauthenticated REST exposure","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-11T05:00:07.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-11/shinyhunters-oracle-peoplesoft-campaign-gadget-chain-access/"}],"id":"relationship--c2ca71c1-2a50-5c50-9bab-53e28ba71842","modified":"2026-06-11T05:00:07.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--93055f64-88f3-5cbc-8079-6ef0e5b69f2f","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-06-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"OceanLotus (APT32) delivery of SPECTRALVIPER via a FireAnt MetaKit update-server supply-chain compromise.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:oceanlotus-apt32-fireant-supplychain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aoceanlotus-apt32-fireant-supplychain-2026/"}],"id":"campaign--82723827-3090-5082-b078-8c08e016cee4","labels":["campaign","vietnam-nexus"],"modified":"2026-06-12T00:00:00.000Z","name":"OceanLotus FireAnt supply-chain compromise","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The Gentlemen ransomware (Storm-2697 / Phantom Mantis): a self-propagating Go encryptor.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:the-gentlemen-ransomware-storm2697","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Athe-gentlemen-ransomware-storm2697/"}],"id":"campaign--bf28afc2-e4df-5e9f-8243-2a496b07538a","labels":["campaign"],"modified":"2026-08-16T23:59:00.000Z","name":"The Gentlemen self-propagating encryptor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"OpenClaw AI agent abuse research: indirect prompt injection (Imperva) and agent phishing (Varonis).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:openclaw-prompt-injection-agent-phishing-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aopenclaw-prompt-injection-agent-phishing-2026/"}],"id":"campaign--c51f6b11-813a-53fb-9a2b-1f2bbb746302","labels":["campaign"],"modified":"2026-06-12T05:00:07.000Z","name":"OpenClaw agent-phishing disclosures","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Maine AG breach-notification portal abused for fraudulent VRChat/Discord filings.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:maine-breach-portal-fraudulent-filings-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amaine-breach-portal-fraudulent-filings-2026/"}],"id":"incident--982321a3-f1c0-5623-87e8-dcb189fb9996","labels":["incident"],"modified":"2026-06-12T00:00:00.000Z","name":"Maine breach-portal abuse","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"AudiA6 ransomware crypto-laundering service dismantled by the US and Europol, with Swiss participation.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:audia6-crypto-laundering-takedown-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aaudia6-crypto-laundering-takedown-2026/"}],"id":"incident--b9c8a5d6-0562-5b46-8db3-7da5ff2c2e8f","labels":["incident"],"modified":"2026-06-12T00:00:00.000Z","name":"AudiA6 laundering-service takedown","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-12T05:00:08.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-12/eset-oceanlotus-apt32-compromises-a-stock-trading-platform-s/"}],"id":"relationship--12413a8c-53c6-5e4d-b74e-c2db48c5a0bf","modified":"2026-06-12T05:00:08.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--82723827-3090-5082-b078-8c08e016cee4","spec_version":"2.1","target_ref":"intrusion-set--445dd747-c261-5106-8af6-419e2feba90e","type":"relationship"},{"created":"2026-06-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Velvet Ant 'Operation Highland': decade-long Linux PAM/sshd authentication-stack subversion (China-nexus).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:velvet-ant-operation-highland-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Avelvet-ant-operation-highland-2026/"}],"id":"campaign--3493efc6-d179-50f1-b857-545b60662a2e","labels":["campaign","china-nexus"],"modified":"2026-06-14T23:57:36.000Z","name":"Velvet Ant Operation Highland","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-based phishing-as-a-service operation weaponising Gemini to generate phishing pages; target of a Google lawsuit.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:outsider-phaas-gemini-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aoutsider-phaas-gemini-2026/"}],"id":"campaign--a3543588-2a5a-597f-8a13-ecbef9a0ab53","labels":["campaign"],"modified":"2026-08-15T05:18:00.000Z","name":"Outsider PhaaS","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"AUR supply-chain campaign: 400+ hijacked Arch Linux user-repository packages drop a Rust stealer and an eBPF rootkit.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:atomic-arch-aur-supply-chain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aatomic-arch-aur-supply-chain-2026/"}],"id":"campaign--be89186b-dd03-5dc3-a61c-9dafb7b716d0","labels":["campaign"],"modified":"2026-06-13T05:00:01.000Z","name":"Atomic Arch","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"MCP injection of AI coding agents via forged Sentry error events (Tenet Security).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:agentjacking-mcp-sentry-injection-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aagentjacking-mcp-sentry-injection-2026/"}],"id":"campaign--c1ebdb32-0475-508e-9787-bd2e79d6abb0","labels":["campaign"],"modified":"2026-06-13T05:00:05.000Z","name":"Agentjacking","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Novo Nordisk discloses theft of clinical-trial and healthcare-professional data.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:novo-nordisk-clinical-trial-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anovo-nordisk-clinical-trial-breach-2026/"}],"id":"incident--ad7aad5c-854b-512f-85c4-9ad08caa2a37","labels":["incident"],"modified":"2026-06-13T00:00:00.000Z","name":"Novo Nordisk data theft","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"South Korea's PIPC issues a record fine against Coupang over an unrevoked former-employee signing key.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:coupang-pipc-record-fine-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acoupang-pipc-record-fine-2026/"}],"id":"incident--d6cedbca-7082-58fb-b6af-fa2a332a05d5","labels":["incident"],"modified":"2026-06-13T00:00:00.000Z","name":"Coupang PIPC record fine","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"APT28 (GRU Unit 26165) tradecraft evolution documented by Sekoia: LameHug LLM-driven stealer, BeardShell cloud C2, and FrostArmada router DNS hijacking.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:apt28-tradecraft-evolution-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aapt28-tradecraft-evolution-2026/"}],"id":"campaign--30c0003b-f917-50e2-b31e-c7a849019246","labels":["campaign","russia-nexus"],"modified":"2026-06-14T00:00:00.000Z","name":"APT28 tradecraft evolution 2026","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Conti loader developer Oleksii Lytvynenko pleads guilty in US federal court after extradition from Ireland.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:conti-lytvynenko-guilty-plea-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aconti-lytvynenko-guilty-plea-2026/"}],"id":"incident--1075fc33-1f3e-5fd6-81cc-09a415540958","labels":["incident"],"modified":"2026-06-14T05:00:01.000Z","name":"Conti developer Lytvynenko guilty plea","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"A Kyushu Electric subsidiary loses an unencrypted SSD with 10.9M customer records — reportedly Japan's largest personal-data breach.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:kyushu-electric-ssd-loss-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Akyushu-electric-ssd-loss-2026/"}],"id":"incident--40033d30-6b72-505e-94e5-36f31e68f748","labels":["incident"],"modified":"2026-06-14T00:00:00.000Z","name":"Kyushu Electric SSD loss","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"First EU-wide test of the 2025 EU Cyber Blueprint and first live activation of the EU Cybersecurity Reserve.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:cyber-europe-2026-eu-cybersecurity-reserve","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acyber-europe-2026-eu-cybersecurity-reserve/"}],"id":"incident--f696dd77-e95d-5813-ae5a-ce9bdad85b98","labels":["incident"],"modified":"2026-06-14T23:57:27.000Z","name":"Cyber Europe 2026","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Handala (Void Manticore) breaches California Water Service via an internet-exposed RTKBase NTRIP/GNSS caster; billing-PII pivot, no OT access.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:cal-water-handala-rtkbase-gnss-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acal-water-handala-rtkbase-gnss-2026/"}],"id":"incident--43462a6d-b165-5658-942a-2553b8588f62","labels":["incident"],"modified":"2026-06-15T00:00:00.000Z","name":"California Water Service breach (Handala)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UNC6508 (PRC) INFINITERED implant on internet-facing REDCap servers plus a Google Workspace BCC content-compliance rule for covert research/defence email exfiltration.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:unc6508-infinitered-redcap-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aunc6508-infinitered-redcap-2026/"}],"id":"campaign--f1997172-e2bd-5f3e-b0bc-57d4997620ed","labels":["campaign","china-nexus"],"modified":"2026-06-16T00:00:00.000Z","name":"UNC6508 INFINITERED campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DPRK cluster UNK_DeadDrop (related to Contagious Interview): VS Code/Cursor tasks.json runOn:folderOpen auto-execution delivering the Overlord Go C2 to developers; EU targets in FR/DE/NL.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:unk-deaddrop-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aunk-deaddrop-2026/"}],"id":"campaign--f24065f2-52ed-5f27-9f1f-731a2cd7b6a5","labels":["campaign","north-korea-nexus"],"modified":"2026-06-16T05:08:55.000Z","name":"UNK_DeadDrop","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"iRhythm Holdings (cardiac MedTech) SEC 8-K Item 1.05: social engineering of third-party-hosted apps; PHI/PII and proprietary-data theft with a ransom demand.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:irhythm-data-theft-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Airhythm-data-theft-2026/"}],"id":"incident--6a2ce046-4ac1-5037-b5ba-335c000931e9","labels":["incident"],"modified":"2026-06-16T00:00:00.000Z","name":"iRhythm data theft","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Awesome Motive CDN supply-chain attack — OptinMonster/TrustPulse/PushEngage scripts tampered on ~1.2M WordPress sites; rogue admins + hidden backdoor plugin (via CVE-2026-10795)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:awesome-motive-cdn-supply-chain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aawesome-motive-cdn-supply-chain-2026/"}],"id":"incident--838623b1-9e40-5915-9311-b1a7f84620f5","labels":["incident"],"modified":"2026-06-16T00:00:00.000Z","name":"Awesome Motive CDN supply-chain attack","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ErrTraffic — ClickFix MaaS distribution framework with EtherHiding/Polygon C2 resolution; EU WordPress targeting","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:sekoia-errtraffic-clickfix-maas-polygon-c2","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asekoia-errtraffic-clickfix-maas-polygon-c2/"}],"id":"campaign--0751c0ff-d96d-5548-a476-625d7262c01b","labels":["campaign"],"modified":"2026-06-22T00:15:05.000Z","name":"ErrTraffic","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Rokarolla Android banking trojan: targets 217 banking/crypto apps, implements 137 commands, hijacks the default call/SMS handler (Zimperium).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:zimperium-rokarolla-android-banker-217-apps","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Azimperium-rokarolla-android-banker-217-apps/"}],"id":"campaign--8496f07e-92c7-5c02-9ae3-0f77eeb344eb","labels":["campaign"],"modified":"2026-06-17T05:14:31.000Z","name":"Rokarolla","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Simultaneous in-the-wild exploitation of three FortiSandbox vulnerabilities (CVE-2026-39808 / CVE-2026-39813 / CVE-2026-25089).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:fortisandbox-triple-active-exploitation","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afortisandbox-triple-active-exploitation/"}],"id":"campaign--963f099e-78c7-5a8d-9854-591104caf475","labels":["campaign"],"modified":"2026-06-17T00:00:00.000Z","name":"FortiSandbox triple exploitation","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ClickFix-delivered Potemkin loader and RMMProject RAT with Chromium App-Bound Encryption bypass and EtherRAT follow-on (Huntress).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:huntress-potemkin-loader-rmmproject-clickfix-abe-bypass","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ahuntress-potemkin-loader-rmmproject-clickfix-abe-bypass/"}],"id":"campaign--a90ac270-6ee3-5aef-9528-a5a495ddc36e","labels":["campaign"],"modified":"2026-06-17T00:00:00.000Z","name":"Potemkin / RMMProject ClickFix campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DragonForce intrusion featuring the first in-the-wild Microsoft Teams TURN-relay C2 (Backdoor.Turn) plus a four-driver BYOVD chain.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:dragonforce-backdoor-turn-teams-relay-byovd","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Adragonforce-backdoor-turn-teams-relay-byovd/"}],"id":"campaign--d83d7c5f-f13c-5748-854c-86e121d0df21","labels":["campaign"],"modified":"2026-06-17T05:14:36.000Z","name":"DragonForce Backdoor.Turn intrusion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"FishMonger (I-SOON) ports the SprySOCKS backdoor to Windows (WIN_DRV / WIN_PLUS) with a kernel-driver rootkit; government targets.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:fishmonger-isoon-sprysocks-windows-kernel-rootkit","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afishmonger-isoon-sprysocks-windows-kernel-rootkit/"}],"id":"campaign--e1b4c60f-7622-5815-8234-21cc881e5886","labels":["campaign","china-nexus"],"modified":"2026-06-17T00:00:00.000Z","name":"FishMonger Windows SprySOCKS campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"~120,000 student records from Munich's LHM-Services GmbH suspected on the darknet; suspected insider threat; Bavarian DPA notified.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:munich-lhm-services-120k-student-records-darknet-insider","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amunich-lhm-services-120k-student-records-darknet-insider/"}],"id":"incident--a6276057-e1c8-5433-a070-f0c8865d1c11","labels":["incident"],"modified":"2026-06-17T00:00:00.000Z","name":"Munich LHM-Services breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-17T05:14:26.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-17/fishmonger-i-soon-ports-its-sprysocks-backdoor-to-windows-wi/"}],"id":"relationship--44bd1f84-1bff-5ca1-bc01-b715059af1a7","modified":"2026-06-17T05:14:26.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--e1b4c60f-7622-5815-8234-21cc881e5886","spec_version":"2.1","target_ref":"intrusion-set--d0bf3aaa-1264-59a3-81ec-0a74da7e79dd","type":"relationship"},{"created":"2026-06-17T05:14:36.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-17/dragonforce-abuses-microsoft-teams-turn-relays-for-c2-and-ch/"}],"id":"relationship--71f6da6d-c774-5797-8af4-58c7e4316d0d","modified":"2026-06-17T05:14:36.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--d83d7c5f-f13c-5748-854c-86e121d0df21","spec_version":"2.1","target_ref":"intrusion-set--dcd6f42f-c2d6-5eec-9542-7e8ccdfc7c17","type":"relationship"},{"created":"2026-06-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ScarCruft (APT37) NarwhalRAT campaign: fake Microsoft OTP lures, a compiled-Python RAT, and pCloud dead-drop C2.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:scarcruft-narwhalrat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ascarcruft-narwhalrat/"}],"id":"campaign--2ecd34fd-3603-5688-be12-15494f537cfd","labels":["campaign","north-korea-nexus"],"modified":"2026-06-18T00:00:00.000Z","name":"ScarCruft NarwhalRAT campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Rust cryptocurrency clipboard-hijacker abusing VirusTotal community reputation (Check Point).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:rust-crypto-clipper-virustotal-reputation","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Arust-crypto-clipper-virustotal-reputation/"}],"id":"campaign--4c14b318-6972-52bd-a7b6-a634bf686522","labels":["campaign"],"modified":"2026-06-18T00:00:00.000Z","name":"Rust crypto-clipper VirusTotal abuse","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mastra npm namespace backdoored via the easy-day-js package through a dormant contributor account.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:mastra-easy-day-js-supply-chain","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amastra-easy-day-js-supply-chain/"}],"id":"campaign--d95f82da-2397-5bda-991f-7e79861a2f98","labels":["campaign"],"modified":"2026-08-23T05:08:00.000Z","name":"Mastra easy-day-js backdoor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"15 malicious JetBrains Marketplace plugins exfiltrating AI-provider API keys (Aikido).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:jetbrains-marketplace-malicious-ai-plugins","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ajetbrains-marketplace-malicious-ai-plugins/"}],"id":"campaign--dcabb9b6-a8fc-5675-b1bb-e0de379a38c8","labels":["campaign"],"modified":"2026-06-18T00:00:00.000Z","name":"Malicious JetBrains Marketplace AI plugins","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Exposure of 73,932 FortiGate device credentials ('FortiBleed') with an active Russian-speaking brute-force and AD-lateral-movement campaign; SOCRadar later tied the infrastructure to INC/Lynx.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:fortibleed-fortigate-credential-exposure","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afortibleed-fortigate-credential-exposure/"}],"id":"incident--9b278806-8375-5034-b0ca-7eaff7d26ae3","labels":["incident"],"modified":"2026-07-19T23:36:00.000Z","name":"FortiBleed","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China arrests 67 operators of the Silver Fox (Winos/ValleyRAT) cybercrime operation.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:silver-fox-arrests-china-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Asilver-fox-arrests-china-2026/"}],"id":"incident--ec72013f-4e10-52bc-a8d8-4c4e5692a18e","labels":["incident"],"modified":"2026-06-18T00:00:00.000Z","name":"Silver Fox arrests","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-18T05:10:29.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-18/scarcruft-apt37-delivers-narwhalrat-behind-fake-microsoft-ot/"}],"id":"relationship--09d47ec1-3394-520c-9488-20ab259aa4b4","modified":"2026-06-18T05:10:29.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--2ecd34fd-3603-5688-be12-15494f537cfd","spec_version":"2.1","target_ref":"intrusion-set--9fb5441b-b101-5153-8685-a55ff66cdf62","type":"relationship"},{"created":"2026-06-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Icarus extortion campaign: a dormant Klue credential led to harvested OAuth tokens and bulk Salesforce CRM data theft across downstream customers.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:icarus-klue-salesforce-oauth","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aicarus-klue-salesforce-oauth/"}],"id":"campaign--3e544198-6615-558c-8449-c4384010b33f","labels":["campaign"],"modified":"2026-06-29T00:21:26.000Z","name":"Icarus Salesforce OAuth extortion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"CryptoBandits — USB-LNK worm + Tor hidden-service C2 driving a clipboard hijacker","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:cryptobandits-usb-lnk-tor-clipper","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acryptobandits-usb-lnk-tor-clipper/"}],"id":"campaign--4af45c22-6e2b-5489-a582-44d2357957f4","labels":["campaign"],"modified":"2026-06-19T05:20:53.000Z","name":"CryptoBandits","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Sophos X-Ops assessment of cautious-but-concrete AI adoption across the cybercrime underground.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:underground-ai-adoption-sophos","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aunderground-ai-adoption-sophos/"}],"id":"campaign--5a34df76-f625-5e81-a65c-0c47e17608cd","labels":["campaign"],"modified":"2026-06-22T00:14:56.000Z","name":"Cybercrime-underground AI adoption","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UK ICO issues a criminal caution over a London Clinic insider who accessed the Princess of Wales's medical records.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ico-london-clinic-princess-wales-insider","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aico-london-clinic-princess-wales-insider/"}],"id":"incident--0922d10b-402a-5ebe-9bb6-47bf5bac77ed","labels":["incident"],"modified":"2026-06-19T00:00:00.000Z","name":"London Clinic insider caution","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Operation Endgame expands to SocGholish/TA569: 106 C2 servers and 14,971 compromised WordPress sites.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:operation-endgame-socgholish-ta569","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aoperation-endgame-socgholish-ta569/"}],"id":"incident--d8b3b09c-aa77-5d9f-85d1-48f731d29263","labels":["incident"],"modified":"2026-06-19T05:20:50.000Z","name":"Operation Endgame — SocGholish expansion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-19T05:20:50.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"the SocGholish/TA569 action is an expansion of Operation Endgame (curated relation type: part-of)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"part-of"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers/"}],"id":"relationship--55805fbd-6666-536b-a1c9-3f43aa90b2d5","modified":"2026-06-19T05:20:50.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--d8b3b09c-aa77-5d9f-85d1-48f731d29263","spec_version":"2.1","target_ref":"campaign--7b4a7244-09ca-52ea-b9f1-c1a2cb0b8394","type":"relationship"},{"created":"2026-06-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Nintendo employee data stolen from the third-party HR-survey SaaS TinyPulse (Shadowbyt3$ extortion).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nintendo-tinypulse-shadowbyt3","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anintendo-tinypulse-shadowbyt3/"}],"id":"incident--54bf2347-be0b-519a-8d0b-a8f262b0da7d","labels":["incident"],"modified":"2026-06-20T00:00:00.000Z","name":"Nintendo TinyPulse breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kodak confirms a breach after a ShinyHunters leak-site listing; the June 18 publication deadline passed without a leak.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:kodak-shinyhunters-breach","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Akodak-shinyhunters-breach/"}],"id":"incident--6fbc4cc4-487f-5e09-8ab6-2c536e203b5a","labels":["incident"],"modified":"2026-06-20T05:12:13.000Z","name":"Kodak breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Permanent, unpatchable SecureROM boot-chain exploit for Apple A12/A13 silicon (checkm8 successor).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:usbliter8-securerom-exploit","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Ausbliter8-securerom-exploit/"}],"id":"tool--e2a4e8c6-3ea5-582c-9523-a84891524ca2","labels":["tool"],"modified":"2026-06-22T00:15:01.000Z","name":"usbliter8","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-06-20T05:12:13.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-20/kodak-confirms-breach-after-shinyhunters-leak-site-listing-j/"}],"id":"relationship--700fe7a8-bcfc-5d21-bc82-b854ea392ef7","modified":"2026-06-20T05:12:13.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--6fbc4cc4-487f-5e09-8ab6-2c536e203b5a","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-06-20T05:12:21.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Joint Ransom-ISAC / eCrime.ch / DEFUSED advisory frames the activity as Cl0p affiliate activity; ReliaQuest separately holds the actor unconfirmed on tradecraft overlap","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ/"}],"id":"relationship--674ec29d-09eb-52e5-889d-718e23feca7a","modified":"2026-06-20T05:12:21.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--5ba76d36-5733-5fc2-b22a-cefe6af661f7","spec_version":"2.1","target_ref":"intrusion-set--fe2066f5-5c49-5bbd-aa20-ca2c71c0a557","type":"relationship"},{"aliases":["NetNut","Popa"],"created":"2026-06-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Residential-proxy botnet built on a Vo1d plugin, tied to Alarum/NetNut by Krebs and Qurium reporting.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:popa-vo1d-residential-proxy-botnet","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Apopa-vo1d-residential-proxy-botnet/"}],"id":"campaign--5a1102ac-2687-5487-bec2-1c0feaf0131b","labels":["campaign"],"modified":"2026-07-05T23:33:00.000Z","name":"Popa residential-proxy botnet","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Prinz Eugen — Go-based ransomware, recent-files-first, no ransom note","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:prinz-eugen-ransomware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aprinz-eugen-ransomware/"}],"id":"campaign--5d286883-0429-5d28-a1c8-693eb6ab1109","labels":["campaign"],"modified":"2026-06-21T04:55:04.000Z","name":"Prinz Eugen","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"One Medical (Amazon) legacy-storage breach; the ShinyHunters 8.8 TB claim remains unverified.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:one-medical-amazon-shinyhunters","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aone-medical-amazon-shinyhunters/"}],"id":"incident--521e4116-835e-587c-947a-daee48c34942","labels":["incident"],"modified":"2026-06-21T00:00:00.000Z","name":"One Medical legacy-storage breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UK Information Commissioner John Edwards resigns with immediate effect.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:uk-ico-commissioner-resignation-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Auk-ico-commissioner-resignation-2026/"}],"id":"incident--54d6a0d1-606a-5acd-ba54-1f21e5497515","labels":["incident"],"modified":"2026-06-21T00:00:00.000Z","name":"UK ICO Commissioner resignation","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"HCRG Care Group notifies patients 16 months after its February 2025 Medusa ransomware breach.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:hcrg-medusa-notification-delay","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ahcrg-medusa-notification-delay/"}],"id":"incident--77b14cd3-a90d-55a5-bf0b-63f2b47d381f","labels":["incident"],"modified":"2026-06-21T00:00:00.000Z","name":"HCRG notification delay","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"3.08M Texas Parks & Wildlife licence holders exposed via a third-party vendor.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:texas-parks-wildlife-vendor-breach","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Atexas-parks-wildlife-vendor-breach/"}],"id":"incident--a825fd82-5018-5f73-8f18-a0c356894a20","labels":["incident"],"modified":"2026-06-21T00:00:00.000Z","name":"Texas Parks & Wildlife vendor breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-21T04:54:59.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-21/amazon-s-one-medical-confirms-a-legacy-storage-breach-shinyh/"}],"id":"relationship--dda62228-abae-5d37-ba75-a7eceaae9e2d","modified":"2026-06-21T04:54:59.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--521e4116-835e-587c-947a-daee48c34942","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-06-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"eBanking phishing wave using IPv4-mapped IPv6 URL notation to bypass regex-based URL scanners.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:ebanking-ipv4-mapped-ipv6-phishing","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aebanking-ipv4-mapped-ipv6-phishing/"}],"id":"campaign--3056934a-e8c5-5ab3-92d2-5b5d0e24aeee","labels":["campaign"],"modified":"2026-06-22T00:00:00.000Z","name":"IPv4-mapped IPv6 eBanking phishing","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"AryStinger botnet — reconnaissance/proxy network on EoL D-Link routers + QNAP NAS","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:arystinger-botnet","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aarystinger-botnet/"}],"id":"campaign--d0a25df0-913f-5363-a18c-ff21e31a8c04","labels":["campaign"],"modified":"2026-06-22T04:52:29.000Z","name":"AryStinger","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Brazil's national Cell Broadcast emergency-alert platform hijacked; roughly 30M fake 'Extreme Alerts' pushed.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:brazil-cell-broadcast-hijack","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Abrazil-cell-broadcast-hijack/"}],"id":"incident--28da723e-9d83-5e3c-8830-3b54fe8295cf","labels":["incident"],"modified":"2026-06-22T00:00:00.000Z","name":"Brazil Cell Broadcast hijack","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Swiss Federal Audit Office (EFK) audit: the federal cyber-governance split leaves SEPOS/FS BIS without a complete incident picture.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ch-efk-federal-cyber-governance-audit","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ach-efk-federal-cyber-governance-audit/"}],"id":"incident--4ed8910e-3a64-5b4b-9902-c84004a37536","labels":["incident"],"modified":"2026-06-22T00:00:00.000Z","name":"EFK federal cyber-governance audit","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ShapedPlugin WordPress Pro supply-chain backdoor (CVE-2026-10735).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:shapedplugin-supply-chain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ashapedplugin-supply-chain-2026/"}],"id":"campaign--de6fccd0-4f38-52fd-8143-e711ee36ab0b","labels":["campaign"],"modified":"2026-06-23T00:00:00.000Z","name":"ShapedPlugin Pro supply-chain backdoor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Scattered Spider members plead guilty over the 2024 Transport for London intrusion.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:tfl-scattered-spider-2024","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Atfl-scattered-spider-2024/"}],"id":"incident--6500f74e-72db-5e18-8621-6b159147230a","labels":["incident"],"modified":"2026-07-19T23:46:00.000Z","name":"Transport for London 2024 intrusion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unit 42 research on cloud-storage-bucket hijacking through global-namespace reuse of deleted bucket names.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:cloud-bucket-hijacking-namespace-reuse","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acloud-bucket-hijacking-namespace-reuse/"}],"id":"campaign--2bc6c63d-7cfb-5267-a350-963ca7f91ac9","labels":["campaign"],"modified":"2026-06-24T05:11:52.000Z","name":"Cloud-bucket hijacking via namespace reuse","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unit 42: malicious OpenClaw ClawHub skills delivering AMOS and enabling agentic fraud.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:openclaw-clawhub-malicious-ai-skills","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aopenclaw-clawhub-malicious-ai-skills/"}],"id":"campaign--b3105e32-c53e-5a9e-b3b7-bca3d8846d59","labels":["campaign"],"modified":"2026-06-24T00:00:00.000Z","name":"Malicious OpenClaw ClawHub skills","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"PostCSS npm typosquats delivering a Nuitka-compiled Python RAT (publisher alias 'abdrizak').","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:postcss-npm-typosquat-python-rat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Apostcss-npm-typosquat-python-rat/"}],"id":"campaign--e86608a2-76eb-5a7f-bdf5-9d03b8e7f66e","labels":["campaign"],"modified":"2026-06-24T00:00:00.000Z","name":"PostCSS npm typosquat campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"macOS ClickFix variant using `hdiutil -nobrowse` to mount a DMG invisibly and drop AMOS.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:macos-clickfix-hdiutil-amos","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amacos-clickfix-hdiutil-amos/"}],"id":"campaign--ea1609e3-3c71-5ba5-914c-f0ae3d9869ce","labels":["campaign"],"modified":"2026-06-24T00:00:00.000Z","name":"macOS ClickFix hdiutil campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"WhatsApp-delivered VBScript installing ManageEngine RMM for living-off-the-land remote control.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:whatsapp-vbs-manageengine-rmm","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Awhatsapp-vbs-manageengine-rmm/"}],"id":"campaign--f37dbb35-2ac2-5234-a02f-a1ab67454563","labels":["campaign"],"modified":"2026-06-24T00:00:00.000Z","name":"WhatsApp VBScript RMM campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Breach at healthcare-AI vendor Xsolis exposes 1.4M patients across seven US health systems.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:xsolis-healthcare-ai-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Axsolis-healthcare-ai-breach-2026/"}],"id":"incident--069c735e-2d74-521c-9c3a-de4768c8c919","labels":["incident"],"modified":"2026-06-24T00:00:00.000Z","name":"Xsolis breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GitHub Actions pull_request_target 'pwn request' vulnerability class.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:cordyceps-github-actions-pwn-request","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acordyceps-github-actions-pwn-request/"}],"id":"campaign--0c999473-5277-58aa-975c-0abcf343109a","labels":["campaign"],"modified":"2026-06-29T00:21:14.000Z","name":"Cordyceps","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"NCSC-CH Week 25: Microsoft 365 voicemail-phishing wave targeting Switzerland.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:ncsc-ch-m365-voicemail-phishing-week25","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ancsc-ch-m365-voicemail-phishing-week25/"}],"id":"campaign--4184f9bb-4806-5ddc-9263-a6ed36fc3843","labels":["campaign"],"modified":"2026-06-25T00:00:00.000Z","name":"M365 voicemail-phishing wave (CH)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Operation Endgame law-enforcement action dismantling the Amadey and StealC malware-as-a-service infrastructure.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:operation-endgame-amadey-stealc","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aoperation-endgame-amadey-stealc/"}],"id":"campaign--7b4a7244-09ca-52ea-b9f1-c1a2cb0b8394","labels":["campaign"],"modified":"2026-06-29T00:21:22.000Z","name":"Operation Endgame — Amadey/StealC takedown","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Edge-extension Native Messaging sandbox-to-host bridge technique ('Payouts Kings').","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:edgecution-payouts-kings","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aedgecution-payouts-kings/"}],"id":"tool--5f213138-261b-54b7-9603-a2966a140994","labels":["tool"],"modified":"2026-06-25T04:59:10.000Z","name":"Edgecution","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["MLTBackdoor"],"created":"2026-06-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Backdoor (Mistic / MLTBackdoor) used by the Woodgnat/KongTuke initial-access broker.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:mistic-mltbackdoor","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Amistic-mltbackdoor/"}],"id":"tool--ddb99e6d-ef09-50f1-93f9-242dec623988","labels":["tool"],"modified":"2026-06-25T04:59:06.000Z","name":"Mistic","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-06-26T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Madison Square Garden breach: ShinyHunters vishing into the company's identity platform.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:msg-shinyhunters-vishing-entra","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amsg-shinyhunters-vishing-entra/"}],"id":"incident--704782fc-6eb2-580b-9acf-3ae473981063","labels":["incident"],"modified":"2026-06-26T00:00:00.000Z","name":"Madison Square Garden breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-26T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ukrposhta digital services disrupted; pro-Russian hacktivists claim prior data theft.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ukrposhta-2026-06","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aukrposhta-2026-06/"}],"id":"incident--eb3596fe-2481-59aa-ada2-b0916ef50ec1","labels":["incident"],"modified":"2026-06-26T00:00:00.000Z","name":"Ukrposhta disruption","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-26T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"macOS.Gaslight — DPRK-aligned Rust backdoor with anti-analyst prompt injection","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:macos-gaslight","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Amacos-gaslight/"}],"id":"tool--641f8be2-29f6-5dc5-8967-f26ab6241838","labels":["north-korea-nexus","tool"],"modified":"2026-06-29T00:21:15.000Z","name":"macOS.Gaslight","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-06-26T04:54:39.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-26/shinyhunters-used-a-single-vishing-call-into-the-company-s-i/"}],"id":"relationship--efa7e5c1-f2a1-54b0-94e4-f48725fbb5f4","modified":"2026-06-26T04:54:39.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--704782fc-6eb2-580b-9acf-3ae473981063","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-06-26T04:54:41.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ESET documents Gamaredon-Turla operational collaboration (curated relation type: collaborates-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"collaborates-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-26/eset-s-2025-gamaredon-paper-exfil-and-c2-moved-wholesale-ont/"}],"id":"relationship--2cd229d7-a5da-5151-a99d-c6139ea9fd9b","modified":"2026-06-26T04:54:41.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--6af6c934-d94e-55d8-bd12-ea920b3e7ec2","spec_version":"2.1","target_ref":"intrusion-set--8ae5f539-8ebc-52fd-bbdc-1153fc0e0991","type":"relationship"},{"aliases":["SharkLoader"],"created":"2026-06-27T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Chinese-suspected loader operation (StrikeShark / SharkLoader) deploying Cobalt Strike via 'Perfect DLL Hijacking' against government targets.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:strikeshark-sharkloader","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Astrikeshark-sharkloader/"}],"id":"campaign--9024b43d-2343-5645-9608-b7e7587ec3aa","labels":["campaign"],"modified":"2026-06-27T05:17:43.000Z","name":"StrikeShark","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-27T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"STOCKSTAY: a four-component .NET backdoor of Kazuar lineage used by Turla for diplomatic intelligence collection.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:turla-stockstay","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aturla-stockstay/"}],"id":"campaign--abd2c3e3-4b1b-5ef4-a178-5e624035041d","labels":["campaign","russia-nexus"],"modified":"2026-06-27T00:00:00.000Z","name":"Turla STOCKSTAY campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-27T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Hospitality-sector phishing delivering the Node.js TonRAT — Calendly auth-laundering, dual Run/RunOnce persistence.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:photo-zip-tonrat-hospitality","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aphoto-zip-tonrat-hospitality/"}],"id":"campaign--d03af5bb-753d-5545-a5b0-cfa8240fcda7","labels":["campaign"],"modified":"2026-06-27T00:00:00.000Z","name":"'Photo ZIP' hospitality phishing","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-27T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Citizen Lab confirms Russian use of Cellebrite UFED on activist Andrei Pivovarov's iPhone after Cellebrite's contract cancellation.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:cellebrite-ufed-russia-pivovarov","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acellebrite-ufed-russia-pivovarov/"}],"id":"incident--f6e17e07-0389-57b8-bbfe-885f32748875","labels":["incident"],"modified":"2026-06-27T00:00:00.000Z","name":"Cellebrite UFED use on Pivovarov","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-27T05:17:52.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat/"}],"id":"relationship--89b6e8a7-9cdc-5b34-bae0-ab2862410a1c","modified":"2026-06-27T05:17:52.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--abd2c3e3-4b1b-5ef4-a178-5e624035041d","spec_version":"2.1","target_ref":"intrusion-set--8ae5f539-8ebc-52fd-bbdc-1153fc0e0991","type":"relationship"},{"created":"2026-06-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Phishing-as-a-service kit using Browser-in-the-Middle (rrweb DOM streaming) to defeat FIDO2 and Device Bound Session Credentials (Netcraft).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:bluekit-phaas-browser-in-the-middle","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Abluekit-phaas-browser-in-the-middle/"}],"id":"campaign--8dbbb959-58f2-570a-960d-2a4b887e561a","labels":["campaign"],"modified":"2026-06-29T00:21:14.000Z","name":"Bluekit PhaaS","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unit 42-tracked cluster CL-STA-1062 deploying the TinyRCT .NET backdoor via AppDomainManager injection.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:cl-sta-1062-tinyrct","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acl-sta-1062-tinyrct/"}],"id":"campaign--a024933e-9535-5625-9f7f-534bd9159dd9","labels":["campaign"],"modified":"2026-06-28T00:00:00.000Z","name":"CL-STA-1062 TinyRCT campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"An 11M-user Chrome ad-blocker extension found one server call away from arbitrary JavaScript injection on any site (Island).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:island-badblocker-adblock-youtube-extension","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aisland-badblocker-adblock-youtube-extension/"}],"id":"campaign--d2a8ea24-b9f7-5640-8fbb-eb0bb24e86af","labels":["campaign"],"modified":"2026-06-28T05:05:43.000Z","name":"BadBlocker","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Jaguar Land Rover August 2025 ransomware: the NYT first names a Russian state-linked group; classed a UK CMC Category-3 systemic event.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:jaguar-land-rover-ransomware-2025","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ajaguar-land-rover-ransomware-2025/"}],"id":"incident--db402c52-c590-5ffe-b29e-a536f5059bbd","labels":["incident"],"modified":"2026-06-28T00:00:00.000Z","name":"Jaguar Land Rover 2025 ransomware","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"NAIC breached via an Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of insurance-regulatory data.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:naic-peoplesoft-oracle-zero-day-shinyhunters","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anaic-peoplesoft-oracle-zero-day-shinyhunters/"}],"id":"incident--f5715ce2-969a-5c48-8f8a-31d236bfd828","labels":["incident"],"modified":"2026-06-28T00:00:00.000Z","name":"NAIC PeopleSoft breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-28T05:05:36.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-28/naic-breached-via-oracle-peoplesoft-zero-day-shinyhunters-pu/"}],"id":"relationship--3c6972fd-ca22-58fd-9120-9d29ee6b719e","modified":"2026-06-28T05:05:36.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--f5715ce2-969a-5c48-8f8a-31d236bfd828","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-06-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mozilla 0DIN research: a clean-looking GitHub repository coerces AI coding agents into opening a reverse shell via a three-stage indirection chain with DNS-TXT C2.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:0din-ai-coding-agent-indirect-pi-dns-txt","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3A0din-ai-coding-agent-indirect-pi-dns-txt/"}],"id":"campaign--5ce3ccea-ab02-56c0-877c-b7ad973eb259","labels":["campaign"],"modified":"2026-07-05T23:27:00.000Z","name":"0DIN coding-agent prompt-injection chain","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"KDDI third-party email-platform breach exposes up to 14.22M credentials across six Japanese ISPs.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:kddi-isp-email-platform-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Akddi-isp-email-platform-breach-2026/"}],"id":"incident--bec063f7-da11-5d92-8f89-fd8cfc84dccb","labels":["incident"],"modified":"2026-07-12T23:34:00.000Z","name":"KDDI email-platform breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-29T00:21:19.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SOCRadar attribution via shared negotiation-panel access and leak-site overlap","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-29/fortibleed/"}],"id":"relationship--5271eb12-4727-5d4d-94a4-0fb25ff8ed89","modified":"2026-06-29T00:21:19.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--9b278806-8375-5034-b0ca-7eaff7d26ae3","spec_version":"2.1","target_ref":"intrusion-set--4a82240a-058b-521d-83c9-4eb4ad051bcf","type":"relationship"},{"created":"2026-06-29T00:21:21.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"operators previously active as ArmCorp, an affiliate of Qilin, before the ~Sept 2025 rebrand to a RaaS model (Unit 42, 2026-07-10) (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-29/the-gentlemen/"}],"id":"relationship--26ce7d10-ad7a-5df9-a81c-913872f4eb69","modified":"2026-06-29T00:21:21.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--2b40ef6d-7f23-5aab-aabc-f30ab0092df0","spec_version":"2.1","target_ref":"intrusion-set--31b671fa-3475-5e95-847f-2b36c26b49ca","type":"relationship"},{"created":"2026-06-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Hijacked npm and Go packages weaponise the VS Code folderOpen task autorun to deliver a Python infostealer (JFrog).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:jfrog-vscode-folderopen-task-npm-go-supply-chain-infostealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ajfrog-vscode-folderopen-task-npm-go-supply-chain-infostealer/"}],"id":"campaign--2fdd92d6-eb2a-5f34-8ace-3a86142caf87","labels":["campaign"],"modified":"2026-06-30T00:00:00.000Z","name":"npm/Go folderOpen-task infostealer campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mustang Panda ZOHOMURK — Zoho WorkDrive dead-drop C2 vs government/energy","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:mustang-panda-zohomurk-zoho-workdrive-deaddrop-c2","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amustang-panda-zohomurk-zoho-workdrive-deaddrop-c2/"}],"id":"campaign--440e2bcc-7e8c-5b0a-8760-d5902d422d5a","labels":["campaign","china-nexus"],"modified":"2026-07-05T23:34:00.000Z","name":"Mustang Panda ZOHOMURK","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malicious 'Perplexity AI' Chrome extension intercepting address-bar keystrokes.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:malicious-perplexity-ai-chrome-extension-keystroke-intercept","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Amalicious-perplexity-ai-chrome-extension-keystroke-intercept/"}],"id":"campaign--696ecbbb-42d9-518b-a064-d9c6a83fe85c","labels":["campaign"],"modified":"2026-06-30T00:00:00.000Z","name":"Fake 'Perplexity AI' Chrome extension","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"aliases":["DarkSpectre"],"created":"2026-06-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"119 Microsoft Edge extensions hiding payloads via steganography, attributed to the DarkSpectre operation.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:stegoad-darkspectre-119-edge-extensions-steganography","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Astegoad-darkspectre-119-edge-extensions-steganography/"}],"id":"campaign--cc1d03da-2c8d-581c-9b04-a8094d359777","labels":["campaign"],"modified":"2026-07-05T23:33:00.000Z","name":"StegoAd","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-06-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SEO-poisoning-to-ransomware kill chain: Bumblebee to AdaptixC2 to Akira (DFIR Report; parallel Swisscom CSIRT intrusion).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:dfir-bumblebee-adaptixc2-akira-seo-poisoning-killchain","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adfir-bumblebee-adaptixc2-akira-seo-poisoning-killchain/"}],"id":"incident--1b0b272f-f043-5da1-8dad-7fe80427b3ef","labels":["incident"],"modified":"2026-06-30T05:10:44.000Z","name":"Bumblebee → AdaptixC2 → Akira intrusion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-06-30T05:10:44.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-06-30/bumblebee-adaptixc2-akira-a-full-seo-poisoning-to-ransomware/"}],"id":"relationship--d9b569c4-1140-5760-ba3c-f7a070521963","modified":"2026-06-30T05:10:44.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--1b0b272f-f043-5da1-8dad-7fe80427b3ef","spec_version":"2.1","target_ref":"intrusion-set--b30781f6-fd45-5d82-891a-b8901dd05559","type":"relationship"},{"created":"2026-07-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Pre-registration of AI-hallucinated domains ('Phantom Squatting', Unit 42).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:unit42-phantom-squatting-hallucinated-domains","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aunit42-phantom-squatting-hallucinated-domains/"}],"id":"campaign--6944ec23-d3cd-56ea-be2c-92c61a90a22d","labels":["campaign"],"modified":"2026-07-05T23:27:00.000Z","name":"Phantom Squatting","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Blackfield ransomware attack on Nidec Chaun Choung Technology (Taiwan).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nidec-chaun-choung-blackfield-ransomware-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anidec-chaun-choung-blackfield-ransomware-2026/"}],"id":"incident--30947431-1e9e-5c24-be82-f36d091631cf","labels":["incident"],"modified":"2026-07-01T00:00:00.000Z","name":"Nidec Chaun Choung ransomware","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Aflac Japan subsidiary portal breach — 4.38M policyholders/agents","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:aflac-japan-portal-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aaflac-japan-portal-breach-2026/"}],"id":"incident--c8cda997-5167-5da3-88f3-42888f160a99","labels":["incident"],"modified":"2026-07-01T00:00:00.000Z","name":"Aflac Japan subsidiary portal breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ToddyCat tool for OAuth-token theft via Chromium remote debugging (STRD).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:toddycat-umbrij-oauth-token-theft-strd","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Atoddycat-umbrij-oauth-token-theft-strd/"}],"id":"tool--453da15b-419a-5cd0-882c-1b758015f0b8","labels":["tool"],"modified":"2026-07-05T23:34:00.000Z","name":"Umbrij","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SEO-poisoned fake-installer sites trojanising ScreenConnect to deploy AsyncRAT.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:screenconnect-asyncrat-seo-poisoning","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ascreenconnect-asyncrat-seo-poisoning/"}],"id":"campaign--2c6e97af-1651-586f-98f7-5b28c4be7567","labels":["campaign"],"modified":"2026-07-02T04:55:23.000Z","name":"Trojanised ScreenConnect AsyncRAT campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"MedusaLocker leak-site listing of the Canton Zürich Baudirektion (bd.zh.ch) — unconfirmed by the canton.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:medusalocker-canton-zurich-baudirektion-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amedusalocker-canton-zurich-baudirektion-2026/"}],"id":"incident--956dc0e6-f527-519d-94f1-7805d7199a11","labels":["incident"],"modified":"2026-07-02T00:00:00.000Z","name":"Canton Zürich Baudirektion listing","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Breach of the DHS Homeland Security Information Network (SharePoint-based collaboration system).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:dhs-hsin-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Adhs-hsin-breach-2026/"}],"id":"incident--ce75ea40-03c8-5dd3-979a-a68fa3811d0e","labels":["incident"],"modified":"2026-07-02T00:00:00.000Z","name":"DHS HSIN breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"EvilTokens-lineage BEC-as-a-service panel targeting Microsoft 365 (Cisco Talos).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:talos-artoken-eviltokens-bec-panel","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Atalos-artoken-eviltokens-bec-panel/"}],"id":"tool--0de0f4fe-e7e4-53b5-8461-aab62fd3f3a5","labels":["tool"],"modified":"2026-07-29T05:55:00.000Z","name":"ARToken","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-03T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"AdaptHealth SEC 8-K: social-engineered third-party-contractor session hijack exposing PHI.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:adapthealth-contractor-session-hijack-8k","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aadapthealth-contractor-session-hijack-8k/"}],"id":"incident--25b7e00e-bb74-5e53-9415-6df19be99b57","labels":["incident"],"modified":"2026-07-03T00:00:00.000Z","name":"AdaptHealth contractor session hijack","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-03T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Navient SEC 8-K: ransomware at an outside law firm exposes borrower SSNs (fourth-party risk).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:navient-outside-law-firm-ransomware-8k","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anavient-outside-law-firm-ransomware-8k/"}],"id":"incident--2a8f92d0-67bc-5800-84ee-d5fc625ac072","labels":["incident"],"modified":"2026-07-03T00:00:00.000Z","name":"Navient fourth-party ransomware exposure","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-03T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ShinyHunters-claimed corporate-IT breach at Medtronic; roughly 9M people notified.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:medtronic-shinyhunters-corporate-it-breach","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amedtronic-shinyhunters-corporate-it-breach/"}],"id":"incident--39878868-b270-5138-9bd6-bfb29da7a532","labels":["incident"],"modified":"2026-07-03T04:48:11.000Z","name":"Medtronic breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-03T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Citizen Lab forensic confirmation (2026-07-03) that former MEP Stelios Kouloglou's iPhone was infected twice with NSO Group's Pegasus spyware (Oct 2022 via PWNYOURHOME zero-click HomeKit→BlastDoor chain, and Mar 2023) while he served on the European Parliament's PEGA spyware-inquiry committee; unattributed but overlaps a Pegasus operator also targeting Russian/Belarusian-speaking exiles in Europe.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:pegasus-mep-kouloglou-pega-committee-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Apegasus-mep-kouloglou-pega-committee-2026/"}],"id":"incident--7187c463-5c24-5bd5-ba2a-ae22abf8a72e","labels":["incident"],"modified":"2026-07-05T23:31:00.000Z","name":"Pegasus infection of PEGA-Committee MEP Stelios Kouloglou","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"JADEPUFFER — agentic threat actor documented by Sysdig (2026-07-01) as the first observed end-to-end ransomware/extortion operation driven autonomously by an LLM; entered via Langflow CVE-2025-3248 and abused default MinIO/Nacos credentials on internet-exposed infrastructure.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:jadepuffer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ajadepuffer/"}],"id":"intrusion-set--9faa8bb1-4653-5a1d-b9df-bbaa97b88d98","labels":["actor"],"modified":"2026-08-09T23:45:00.000Z","name":"JADEPUFFER","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["CrownX"],"created":"2026-07-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Modular Windows malware framework combining credential theft, lateral movement and the CrownX ransomware payload behind an LNK → MSBuild → ETW/AMSI-patching loader chain; assessed by Blackpoint Cyber as bearing hallmarks of AI-assisted development.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:avalon-malware-framework","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aavalon-malware-framework/"}],"id":"tool--d158aa64-7b87-51e3-ab7f-5c8f193f0fe0","labels":["tool"],"modified":"2026-07-05T23:34:00.000Z","name":"Avalon","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"PamStealer — two-stage macOS infostealer impersonating the Maccy clipboard manager; validates harvested login passwords via the macOS PAM API before exfiltration (Jamf Threat Labs)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:pamstealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Apamstealer/"}],"id":"tool--e7dba82a-9285-5c63-904a-23ca6910539d","labels":["tool"],"modified":"2026-07-05T23:34:00.000Z","name":"PamStealer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["INC","INC Ransomware","Lynx"],"created":"2026-07-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service operation active since ~2023; researchers assess Lynx (active since mid-2024) as an INC rebrand rather than a distinct group. SOCRadar's 2026-07-01 FortiBleed attribution report ties INC/Lynx to the FortiBleed FortiGate credential-theft infrastructure via shared negotiation-panel access and overlapping leak-site victims.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:inc-ransom","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ainc-ransom/"}],"id":"intrusion-set--4a82240a-058b-521d-83c9-4eb4ad051bcf","labels":["actor"],"modified":"2026-08-09T23:45:00.000Z","name":"INC Ransom","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kairos — data-theft-only extortion actor; no ransomware encryptor or locker binary has been obtained or confidently linked to it. Leverage rests on the threat to publish exfiltrated data rather than on file encryption; documented retrospectively by Ransom-ISAC (2026-07-03) in a case study of a ~$1M payout by a small US county government.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:kairos-extortion","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Akairos-extortion/"}],"id":"intrusion-set--d9b4486f-34c2-596d-a056-da36e1a896aa","labels":["actor"],"modified":"2026-08-22T05:09:30.000Z","name":"Kairos","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-nexus APT previously documented by Cisco Talos targeting critical infrastructure in Taiwan; named (Talos, 2026-07-07) as a secondary consumer of UAT-7810's ORB relay-network infrastructure.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uat-5918","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auat-5918/"}],"id":"intrusion-set--6a6c9463-5ac2-5c87-8eea-01aaa7a1a133","labels":["actor","china-nexus"],"modified":"2026-07-08T20:35:00.000Z","name":"UAT-5918","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-nexus threat actor Cisco Talos (2026-07-07) assesses with high confidence builds and maintains Operational Relay Box (ORB) networks by exploiting unpatched Ruckus and ASUS AiCloud routers; its relay infrastructure is leveraged by secondary China-nexus APTs including UAT-5918.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uat-7810","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auat-7810/"}],"id":"intrusion-set--92dc754b-d72b-5438-a608-2732741a8a6a","labels":["actor","china-nexus"],"modified":"2026-07-12T23:43:00.000Z","name":"UAT-7810","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated data-extortion/access-broker handle active on cybercrime forums since at least 2024, with a documented history of inflating breach-scope claims (a June 2024 Accenture claim of 32,826 employee records proved to contain only three genuine ones); claimed a second Accenture data theft in July 2026 (~35 GB of source code, RSA/SSH keys and Azure PATs/storage keys from a private Azure DevOps repository).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:888-extortion-handle","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3A888-extortion-handle/"}],"id":"intrusion-set--e286cffc-a82e-5563-8964-579ebe43fcea","labels":["actor"],"modified":"2026-07-12T23:34:00.000Z","name":"888","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["ff-agent","DOGLEASH","JARLEASH","LEASHTEST"],"created":"2026-07-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UAT-7810's ORB-network malware suite (internally 'ff-agent'): LONGLEASH (enhanced SHORTLEASH successor, multi-protocol HTTP/DNS/SOCKS/TCP/ICMP/UDP proxying), DOGLEASH (C-based Linux backdoor), JARLEASH (Java admin/relay tool) and LEASHTEST; built with Boost.Asio, custom protobuf and MbedTLS, compiled MIPS/ARM/x64 (Cisco Talos, 2026-07-07).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:longleash-orb-malware-suite","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Alongleash-orb-malware-suite/"}],"id":"tool--4b8f4a0f-f69c-5f98-9927-9c39d7054d82","labels":["china-nexus","tool"],"modified":"2026-07-08T20:35:00.000Z","name":"LONGLEASH / SHORTLEASH ORB malware suite","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Modular .NET remote-access trojan (documented in prior public reporting) analysed by LevelBlue SpiderLabs (2026-07-06) in a freight-rate-confirmation phishing chain combining an AMSI bypass, ICMLuaUtil UAC bypass and the open-source WinDefCtl Defender-disruption utility, with hidden VNC, command execution and Chromium credential theft.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:crysome-rat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Acrysome-rat/"}],"id":"tool--60c08b70-dcb1-5e99-977e-75745acdd054","labels":["tool"],"modified":"2026-07-08T20:35:00.000Z","name":"CrySome RAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malware-as-a-service Go loader-builder documented by Palo Alto Unit 42 (2026-07-07) delivering Vidar stealer and XMRig via fraudulent Authenticode code-signing, fake MpClient.dll DLL-sideloading against Defender, in-memory AMSI patching and 'file inflation' (null-padding to ~491 MB) sandbox evasion; operator tracked via a Telegram channel branded 'X3D MINER'.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:factory-v3-loader-builder","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Afactory-v3-loader-builder/"}],"id":"tool--ef4f06b9-1415-5fef-8a9c-de9c172f29d7","labels":["tool"],"modified":"2026-07-08T20:35:00.000Z","name":"Factory-v3","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-08T20:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Talos: UAT-5918 consumes UAT-7810's ORB relay-network infrastructure (curated relation type: collaborates-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"collaborates-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash/"}],"id":"relationship--1e2ed872-a5e5-532a-8d27-93f10c82caae","modified":"2026-07-08T20:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--92dc754b-d72b-5438-a608-2732741a8a6a","spec_version":"2.1","target_ref":"intrusion-set--6a6c9463-5ac2-5c87-8eea-01aaa7a1a133","type":"relationship"},{"created":"2026-07-08T20:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash/"}],"id":"relationship--b1ffd39c-69bb-5e40-867f-49dbd227fb98","modified":"2026-07-08T20:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--92dc754b-d72b-5438-a608-2732741a8a6a","spec_version":"2.1","target_ref":"tool--4b8f4a0f-f69c-5f98-9927-9c39d7054d82","type":"relationship"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Individual @pdag.ch mailboxes at the Swiss cantonal psychiatric-care provider PDAG were compromised via phishing and abused to relay spam/phishing to external recipients; disclosed ~2026-07-08/09, accounts locked and all-staff passwords reset, no patient-data compromise confirmed (SwissCybersecurity.net, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:pdag-email-phishing-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Apdag-email-phishing-2026/"}],"id":"incident--1a6e05d9-93b9-5047-ab79-2280e3e6fe08","labels":["incident"],"modified":"2026-07-12T23:32:00.000Z","name":"PDAG email-account compromise","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Nayax Ltd. (Bank-of-Lithuania-licensed payment institution serving enterprises across the EEA) disclosed detection and containment of unusual activity in a subsidiary cloud account via SEC Form 6-K on 2026-07-08; extortion group The Syndicate separately claims a far larger compromise (1B+ card records, ~1-year dwell, 100 TB) that Nayax has not confirmed and that conflicts with the filing.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nayax-cloud-account-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anayax-cloud-account-breach-2026/"}],"id":"incident--e0797339-9ccb-5ee5-a815-069edc94e7f9","labels":["incident"],"modified":"2026-07-16T04:46:00.000Z","name":"Nayax cloud-account incident","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service / double-extortion operator; relatively quiet through 2024–2025, re-emerged in 2026 with reported targets in Germany, the United States, Switzerland and France; in July 2026 claimed a Deutsche Bank breach that the bank attributed to a compromise at a German third-party marketing/incentive-platform vendor rather than its own network (Computing UK / Cybernews, 2026-07-07/09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unsafe-ransomware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunsafe-ransomware/"}],"id":"intrusion-set--6b68dc80-0aa7-5167-96fb-f993466b9f34","labels":["actor"],"modified":"2026-07-12T23:34:00.000Z","name":"Unsafe","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Iran MOIS-linked APT targeting Israeli government and IT-sector organizations, sharing technical/infrastructure overlap with MuddyWater and OilRig's Lyceum subgroup; operates the modular .NET C2 framework 'Cavern' (Check Point Research, 2026-07-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:cavern-manticore","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Acavern-manticore/"}],"id":"intrusion-set--8234bfea-c27d-5602-9d0a-fc09ed3fb759","labels":["actor","iran-nexus"],"modified":"2026-08-12T04:51:00.000Z","name":"Cavern Manticore","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Proofpoint-tracked suspected China-aligned espionage cluster exploiting Roundcube webmail as an edge device — chaining CVE-2024-42009 (XSS) into CVE-2025-49113 (PHP deserialization) — against physics/engineering departments at US and Canadian universities since May 2026, deploying the IceCube stealer plus the SquareShell webshell / VShell backdoor (Proofpoint, 2026-07-07).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unk-masstraction","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunk-masstraction/"}],"id":"intrusion-set--9a4e60fd-0b3a-589a-803f-d2fd3684bb0b","labels":["actor","china-nexus"],"modified":"2026-07-12T23:43:00.000Z","name":"UNK_MassTraction","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Extortion/leak-site group claiming (unverified, as of 2026-07-08) a large-scale data theft from fintech Nayax's cloud infrastructure — 1B+ card records, ~1 year dwell, 100 TB exfiltrated; no proof published and the claim conflicts with Nayax's own 'immediately contained' SEC filing (DataBreaches.net, 2026-07-08).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:the-syndicate","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Athe-syndicate/"}],"id":"intrusion-set--e58514f5-db4c-53cd-9b68-57e5f9d4f79d","labels":["actor"],"modified":"2026-07-16T04:46:00.000Z","name":"The Syndicate","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["c2c","meow","qwiklabs/c2c"],"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Simpler standalone Golang DDoS flooder targeting SSH-exposed Linux hosts, paired with a separate SSH-scanner component; checks for passwordless sudo to self-escalate and persists as a fake systemd service masquerading as 'cpufreqd' / 'CPU Frequency Daemon' (Nozomi Networks Labs, 2026-07-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:c2c-meow-flooder","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Ac2c-meow-flooder/"}],"id":"tool--044388a8-452e-598a-afd6-f95eedae4579","labels":["tool"],"modified":"2026-07-09T12:33:00.000Z","name":"c2c / meow","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["Apex"],"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Golang-based IoT/Linux/Windows DDoS botnet, a structural evolution of the earlier Apex botnet, delivered via Telnet credential brute-force; supports a Cloudflare-bypass HTTP(S) flood ('cf'), UDP/game/Discord floods, and TLS floods; Linux builds cover arm/arm64/mipsle/ppc64 (Nozomi Networks Labs, 2026-07-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:apex2-botnet","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aapex2-botnet/"}],"id":"tool--4e13d82f-cd91-5ff1-8316-47b52d2d766a","labels":["tool"],"modified":"2026-07-09T12:33:00.000Z","name":"Apex2","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Wiz Research's name for a symlink-following (CWE-61) + confirmation-dialog UI-misrepresentation (CWE-451) vulnerability pattern across six AI coding assistants (Amazon Q Developer, Cursor, Google Antigravity, Augment, Windsurf, Anthropic Claude Code) letting a malicious repository write outside the workspace sandbox; CVE-2026-12958 (AWS), CVE-2026-50549 (Cursor) (Wiz Research, 2026-07-08).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:ghostapproval-ai-coding-assistant-symlink","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aghostapproval-ai-coding-assistant-symlink/"}],"id":"tool--6cdb6931-7633-5a6c-a7c0-cbb0f161e603","labels":["tool"],"modified":"2026-07-09T04:32:59.000Z","name":"GhostApproval","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"JavaScript Roundcube stealer delivered via a CVE-2024-42009 XSS that escapes the mail client's iframe by DOM traversal to reach the authenticated session, harvesting credentials/2FA material/cookies, then uses 'helper' modules to trigger CVE-2025-49113 deserialization for a webshell/backdoor foothold; likely LLM-assisted code. Attributed to UNK_MassTraction (Proofpoint, 2026-07-07).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:icecube-stealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aicecube-stealer/"}],"id":"tool--6f3a27cf-ba63-54ce-83c8-cf951cd38dac","labels":["tool"],"modified":"2026-07-09T20:42:00.000Z","name":"IceCube","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Modular post-exploitation .NET C2 framework used by Cavern Manticore, deliberately compiled across three .NET formats (IL-only, Mixed-Mode C++/CLI, .NET 8 NativeAOT) as an anti-analysis layer, with per-module AppDomain isolation and DLL-sideload delivery (trojanized uxtheme.dll) via RMM software-update-feature abuse (Check Point Research, 2026-07-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:cavern-c2-framework","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Acavern-c2-framework/"}],"id":"tool--8d521b89-a34c-57e8-878c-d7e515c3e66e","labels":["iran-nexus","tool"],"modified":"2026-08-12T04:51:00.000Z","name":"Cavern","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Android RAT first documented by Cyble (July 2025) targeting Vietnamese banking users; Group-IB's July 2026 update documents self-service privilege escalation via Accessibility-driven abuse of ADB Wireless Debugging to obtain shell uid 2000 (Shizuku-derived helper), 53 C2 commands, and expanded targeting into Indonesia (Group-IB, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:redhook-android-rat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aredhook-android-rat/"}],"id":"tool--f04e94fe-6527-5eff-aa3a-f3e6f6613fa5","labels":["tool"],"modified":"2026-07-09T12:30:00.000Z","name":"RedHook","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["Ghost in the Database"],"created":"2026-07-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mandiant-documented Golden SAML variant recovering an active ADFS token-signing private key from the machine-scoped Windows CAPI key store via Machine DPAPI when the WID configuration database has drifted from the actively-used signing certificate (AutoCertificateRollover disabled, manual rotation) — enables SAML forgery without WID/DKM extraction or LSASS interaction (Mandiant, 2026-07-07).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:adfs-machine-dpapi-key-recovery","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aadfs-machine-dpapi-key-recovery/"}],"id":"tool--f93ff5f8-1a76-5afb-b108-3895853f83b3","labels":["tool"],"modified":"2026-07-12T23:40:00.000Z","name":"'Ghost in the Database' ADFS key recovery","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-09T04:32:59.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/"}],"id":"relationship--79633b53-50ec-5277-b8be-4792ae4cf0fc","modified":"2026-07-09T04:32:59.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--e0797339-9ccb-5ee5-a815-069edc94e7f9","spec_version":"2.1","target_ref":"intrusion-set--e58514f5-db4c-53cd-9b68-57e5f9d4f79d","type":"relationship"},{"created":"2026-07-09T04:32:59.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Check Point notes technical/infrastructure overlap with MuddyWater and Lyceum (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis/"}],"id":"relationship--8168d973-556c-5be7-beae-a3ddbdd5ac34","modified":"2026-07-09T04:32:59.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--a494e603-7278-535a-ac86-434081d6d216","spec_version":"2.1","target_ref":"intrusion-set--8234bfea-c27d-5602-9d0a-fc09ed3fb759","type":"relationship"},{"created":"2026-07-09T04:32:59.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis/"}],"id":"relationship--cb07bb0c-a820-5985-ae45-1ac89f766349","modified":"2026-07-09T04:32:59.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--8234bfea-c27d-5602-9d0a-fc09ed3fb759","spec_version":"2.1","target_ref":"tool--8d521b89-a34c-57e8-878c-d7e515c3e66e","type":"relationship"},{"created":"2026-07-09T20:38:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-09/ncsc-ch-rogueplanet-cve-2026-50656-defender-lpe-fixed/"}],"id":"relationship--87cb91f4-0995-5376-b7ae-afb5d692218d","modified":"2026-07-09T20:38:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--1d1f0f6c-868a-5f95-b749-e65c0a9c3d8d","spec_version":"2.1","target_ref":"intrusion-set--ca241f42-7392-5e96-abde-f0b724013bc4","type":"relationship"},{"created":"2026-07-09T20:42:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-09/unk-masstraction-roundcube-edge-exploitation/"}],"id":"relationship--fe1dfd31-2fa4-563a-b88c-cba5a66ce0b2","modified":"2026-07-09T20:42:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--9a4e60fd-0b3a-589a-803f-d2fd3684bb0b","spec_version":"2.1","target_ref":"tool--6f3a27cf-ba63-54ce-83c8-cf951cd38dac","type":"relationship"},{"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"March 2026 device-code phishing campaign against 344 organisations that harvested Microsoft 365 OAuth tokens via the device-authorization flow, run from clean Railway.com PaaS IPs and attributed by Huntress to the EvilTokens phishing-as-a-service operation (Huntress, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:railway-device-code-phishing-m365-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Arailway-device-code-phishing-m365-2026/"}],"id":"campaign--80cdead5-5772-5bec-93c0-f6fa90845138","labels":["campaign"],"modified":"2026-08-01T04:24:59.000Z","name":"Railway device-code phishing","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"aliases":["CitrixBleed 2 initial-access-broker runbook"],"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Repeatable initial-access-broker kill chain (Sophos: STAC3725): CVE-2025-5777 (CitrixBleed 2) session-token theft on NetScaler Gateway, a registry-symlink/AppMgmt SYSTEM privilege-escalation tool, ScreenConnect/Zoho Assist persistence, and DragonForce ransomware in the most progressed case (Huntress, 2026-07-09; Sophos, 2026-02).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:stac3725-citrixbleed2-iab-dragonforce","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Astac3725-citrixbleed2-iab-dragonforce/"}],"id":"campaign--9d498481-3a3b-546c-a030-b9ce2ac109a9","labels":["campaign"],"modified":"2026-07-12T23:22:00.000Z","name":"STAC3725 CitrixBleed 2-to-DragonForce IAB chain","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"aliases":["LSHIY password spray"],"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"81M+ login attempts against Azure CLI via the deprecated ROPC OAuth flow from LSHIY LLC infrastructure, compromising 78 Microsoft 365 accounts across 64 orgs in June 2026 by bypassing Conditional Access policies that omit the /token path (Huntress, 2026-07).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:lshiy-ropc-azure-cli-password-spray-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Alshiy-ropc-azure-cli-password-spray-2026/"}],"id":"campaign--f91f9566-cbb8-59c9-b13f-a3c0410eb829","labels":["campaign"],"modified":"2026-08-01T04:24:59.000Z","name":"LSHIY Azure CLI ROPC token-spray","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware/data-extortion intrusion against Latvia's state forestry company LVM (initial access 11 June 2026, detonation 22-23 June) via a ~2-year-unpatched exposed system, 44 GB exfiltrated; the same foreign financially-motivated actor also compromised a server at essential-services provider AS Olpha with log-wiping. CERT.LV assesses the actor has hit other NATO/EU member-state institutions (CERT.LV, 2026-07).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:cert-lv-lvm-olpha-ransomware-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acert-lv-lvm-olpha-ransomware-2026/"}],"id":"incident--117d5844-e1e4-5acf-962a-3f26c6a6a02f","labels":["incident"],"modified":"2026-07-12T23:30:00.000Z","name":"CERT.LV LVM/Olpha ransomware intrusion (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ShinyHunters breach of Dutch telecom operator Odido (and its Ben brand): a vishing call impersonating IT staff convinced a customer-service employee to authenticate into a spoofed corporate portal, harvesting credentials used to bulk-exfiltrate 6.2M+ customer records (intrusion 5 February 2026; Dutch police announced strong indications of Dutch-national involvement via voice analysis, 9 July 2026).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:odido-telecom-breach-netherlands-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aodido-telecom-breach-netherlands-2026/"}],"id":"incident--347c5575-779e-544f-9e2a-6c7785dc82d0","labels":["incident"],"modified":"2026-07-12T23:34:00.000Z","name":"Odido (Netherlands telecom) ShinyHunters breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Misconfigured, publicly exposed Elasticsearch cluster on Nextcloud GmbH's own hosting infrastructure exposed ~367,000 internal records — invoices, contracts, client setup scripts with hardcoded database credentials, and internal/client email — for ~9 days in May 2026; discovered and disclosed by Cybernews. The open-source Nextcloud software and customer-operated servers were unaffected; exposed contacts included German state ministry MSB NRW (Cybernews/heise, 2026-07-08).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nextcloud-gmbh-elasticsearch-exposure-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anextcloud-gmbh-elasticsearch-exposure-2026/"}],"id":"incident--497e54f5-42d5-5711-b8b5-1f27979e0c34","labels":["incident"],"modified":"2026-07-12T23:34:00.000Z","name":"Nextcloud GmbH corporate Elasticsearch data exposure (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GitHub-account-takeover-driven npm supply-chain compromise (2026-06-08, contained within ~50 minutes) of @injectivelabs/sdk-ts and 17 dependent scope packages, injecting a runtime-triggered wallet-key stealer with no install-time hook that hooks the SDK's key-derivation functions and exfiltrates disguised as normal gRPC-web API traffic; first public technical teardown by Aikido Security (2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:injectivelabs-npm-sdk-ts-supply-chain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ainjectivelabs-npm-sdk-ts-supply-chain-2026/"}],"id":"incident--55986eec-2058-518c-bff0-c0bae73a3140","labels":["incident"],"modified":"2026-08-09T23:45:00.000Z","name":"@injectivelabs/sdk-ts npm supply-chain compromise (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Data-extortion cluster documented by ReliaQuest (2026-07-08), assessed as a likely continuation of the BlackFile (UNC6671) and ShinyHunters ecosystems on shared registrar and hosting-adjacent infrastructure. Uses manager-impersonation vishing to drive Entra ID device-code phishing that bypasses Conditional Access, registers a new MFA authenticator within minutes for persistence, then runs automated python-requests SharePoint enumeration and bulk exfiltration for extortion.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:helix-extortion","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ahelix-extortion/"}],"id":"intrusion-set--60c87cd6-b8d4-5b26-a17d-4c93011dd280","labels":["actor"],"modified":"2026-08-16T23:59:00.000Z","name":"Helix","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SOCRadar designation for a financially-motivated, assessed Chinese-speaking webshell access-brokerage crew (WABO) whose own unauthenticated staging server, exposed for 22 days, revealed automated exploitation of 27 weaponized CVEs against ~1.4M WordPress/Joomla domains (5,700+ live webshells; a Breeze Cache Cleaner flaw CVE-2026-3844 the highest-yield) plus a parallel Apache Nacos/XXL-Job/Spring Boot cloud-credential-theft track using CVE-2021-29441 and JDumpSpider; deploys BestShell-derived and Godzilla webshells and a VShell implant that masquerades as a Linux kernel worker thread (SOCRadar, 2026-07-09; corroborated by Ctrl-Alt-Intel via The Hacker News, 2026-07-10).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:wp-shellstorm","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Awp-shellstorm/"}],"id":"intrusion-set--d55f74dd-97f4-57f3-a051-12c41370268c","labels":["actor","china-nexus"],"modified":"2026-07-10T20:34:32.000Z","name":"WP-SHELLSTORM","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["TAG-179","Mysterious Elephant","APT-C-08"],"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"India-nexus espionage actor (Recorded Future TAG-179; Kaspersky 'Mysterious Elephant'; Qihoo 360 APT-C-08) observed by SentinelLabs deploying Remcos against Pakistani law-enforcement targets 2024-2026; diversifying TTPs since early 2025.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:bitter","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Abitter/"}],"id":"intrusion-set--ee5ce977-9639-566a-8be9-1fcbb868dd5a","labels":["actor","india-nexus"],"modified":"2026-07-12T23:30:00.000Z","name":"Bitter","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["ForgCookie"],"created":"2026-07-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Telegram-distributed, subscription-priced ($400/month) Microsoft 365 phishing-as-a-service platform combining OAuth device-code phishing and adversary-in-the-middle session-cookie theft with an in-panel AI lure-drafting assistant and a companion browser extension (ForgCookie) that silently refreshes stolen Microsoft SSO cookies for post-compromise persistence; assessed by ZeroBEC as a Kali365-class platform with Sneaky2FA-style AiTM overlap, no asserted common ownership (ZeroBEC, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:forg365-phaas","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aforg365-phaas/"}],"id":"tool--a0194b67-b0fe-5aa1-a5bc-0a8b1a405ae0","labels":["tool"],"modified":"2026-07-12T23:24:00.000Z","name":"Forg365","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-10T04:36:19.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/"}],"id":"relationship--cf4234c6-9384-5925-82d9-9845fa79caaa","modified":"2026-07-10T04:36:19.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--9d498481-3a3b-546c-a030-b9ce2ac109a9","spec_version":"2.1","target_ref":"intrusion-set--dcd6f42f-c2d6-5eec-9542-7e8ccdfc7c17","type":"relationship"},{"created":"2026-07-10T04:36:19.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution/"}],"id":"relationship--e8ab8455-158d-5972-8e22-402b5ef841f0","modified":"2026-07-10T04:36:19.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--347c5575-779e-544f-9e2a-6c7785dc82d0","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-07-10T12:53:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"shared registrar and hosting-adjacent infrastructure per ReliaQuest (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil/"}],"id":"relationship--db123fdb-c528-5520-8ab2-394ec4dd81d0","modified":"2026-07-10T12:53:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--60c87cd6-b8d4-5b26-a17d-4c93011dd280","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-07-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"AI Now Institute proof-of-concept in which a two-layer indirect prompt injection embedded in an untrusted repository's own files (a decoy Go source paired with a malicious binary, plus a README steering the agent to run a bundled script) hijacks Claude Code (auto-mode) and OpenAI Codex CLI (auto-review) into executing attacker code during a defensive security review, achieving RCE with no hooks, plugins, MCP servers or config files required (AI Now Institute, 2026-07-08).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:friendly-fire-ai-agent-defensive-hijack","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afriendly-fire-ai-agent-defensive-hijack/"}],"id":"campaign--fbd6c833-5c87-5d1c-b45f-717c386ca1db","labels":["campaign"],"modified":"2026-07-12T23:38:00.000Z","name":"Friendly Fire (AI Now Institute exploit)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"aliases":["Eagle Werewolf"],"created":"2026-07-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Previously unknown APT documented by Kaspersky (2026-07-03) mixing financially motivated campaigns against individuals with targeted espionage against government agencies and the electric-power sector across Russia, Brazil and Kazakhstan. Spear-phishing initial access (NSIS droppers, ZDI-CAN-25373 LNK lures) into an LLM-generated loader chain staging a bundled Python runtime; toolkit includes BusySnake Stealer and Go2Tunnel. The Eagle Werewolf alias is Kaspersky's own circumstantial-evidence overlap.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:armored-likho","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aarmored-likho/"}],"id":"intrusion-set--3967c0f5-dcbb-5c27-98b0-ec0ef0a2916f","labels":["actor"],"modified":"2026-07-12T23:38:00.000Z","name":"Armored Likho","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Symantec-tracked ransomware developer behind the Monster (2022) -> Beast -> GodDamn locker lineage; a June 2026 GodDamn intrusion used the Microsoft-signed malicious kernel driver PoisonX for BYOVD-style EDR blinding, AnyDesk for unattended access, PsExec lateral movement and a NirSoft/Mimikatz credential-harvesting kit (Symantec/Broadcom, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:hyadina","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ahyadina/"}],"id":"intrusion-set--48e3c98b-a450-593b-bb48-f24be91e5942","labels":["actor"],"modified":"2026-07-11T04:30:43.000Z","name":"Hyadina","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Python 3.12 Windows infostealer (module.pyw) documented by Kaspersky (2026-07-03), obfuscated with PyArmor Pro 9.2.0 using call-time bytecode decrypt/re-encrypt. Handler/command architecture: clipboard and file scraping for 64-char hex keys and otpauth:// OTP seeds, DPAPI Chromium and PK11SDR_Decrypt Firefox credential theft, cookie theft incl. a browser-extension variant, document exfiltration, screenshots, Telegram tdata harvesting, crypto-wallet JSON hunting, reverse-SSH tunneling and RustDesk remote-access abuse. Staged from auto-rotating GitHub repositories; scheduled-task persistence via VBScript every five minutes.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:busysnake-stealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Abusysnake-stealer/"}],"id":"malware--48d47fcb-950f-5bcb-bd85-62a767266526","is_family":true,"labels":["malware"],"modified":"2026-07-12T23:38:00.000Z","name":"BusySnake Stealer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-07-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kernel driver (g11.sys) that its developers built to be malicious yet succeeded in getting signed under Microsoft's 'Windows Hardware Compatibility Publisher' program; once loaded it terminates security-product processes and strips user-mode API hooks, disabling EDR visibility. First documented disabling CrowdStrike Falcon via a crafted IOCTL earlier in 2026; reused by the Hyadina/GodDamn ransomware operation in June 2026 (Symantec/Broadcom, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:poisonx-driver","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Apoisonx-driver/"}],"id":"tool--21b4fa0a-a0c1-5750-926f-1f7ad63698d2","labels":["tool"],"modified":"2026-07-11T04:30:43.000Z","name":"PoisonX","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware family whose encryption routine Microsoft found reused near-verbatim inside GigaWiper's fake-ransomware destruction command, leading Microsoft to assess a common developer for both (Microsoft, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:crucio-ransomware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Acrucio-ransomware/"}],"id":"tool--27dc981e-9e01-5864-b505-00db11830670","labels":["tool"],"modified":"2026-07-11T04:30:43.000Z","name":"Crucio","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["BLUERABBIT"],"created":"2026-07-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Golang destructive backdoor that folds a raw-disk wiper, a Crucio-derived fake-ransomware encryptor (per-run keys never saved) and a FlockWiper-derived multi-pass secure-wipe module into one implant's on-demand command set, tasked over RabbitMQ/AMQP and Redis with MinIO exfiltration, and persisting as an 'OneDrive Update' scheduled task with a HKCU\\\\SOFTWARE\\\\OneDrive\\\\Environment counter key; detected by Microsoft Threat Intelligence, first observed October 2025, tracked as BLUERABBIT by Google Threat Intelligence Group and Binary Defense (Microsoft, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:gigawiper","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Agigawiper/"}],"id":"tool--3f0157a4-a742-571e-a3b6-f4d5ecd98691","labels":["tool"],"modified":"2026-07-11T04:30:43.000Z","name":"GigaWiper","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"C-based disk wiper reimplemented in Golang, with additional multi-pass secure wiping, as one of GigaWiper's destructive commands (Microsoft, 2026-07-09).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:flockwiper","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aflockwiper/"}],"id":"tool--eba385ff-b42a-5b89-901e-1b7cd6e57f78","labels":["tool"],"modified":"2026-07-11T04:30:43.000Z","name":"FlockWiper","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-11T04:30:43.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Crucio-derived fake-ransomware encryptor; Microsoft assesses a common developer (curated relation type: variant-of)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"variant-of"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/"}],"id":"relationship--4801ce57-6b58-5920-9ca6-f164394cd76d","modified":"2026-07-11T04:30:43.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"tool--3f0157a4-a742-571e-a3b6-f4d5ecd98691","spec_version":"2.1","target_ref":"tool--27dc981e-9e01-5864-b505-00db11830670","type":"relationship"},{"created":"2026-07-11T04:30:43.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-11/goddamn-ransomware-poisonx-microsoft-signed-driver/"}],"id":"relationship--b44c81b3-d78c-5cc3-bdf5-a09bf18010df","modified":"2026-07-11T04:30:43.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--48e3c98b-a450-593b-bb48-f24be91e5942","spec_version":"2.1","target_ref":"tool--21b4fa0a-a0c1-5750-926f-1f7ad63698d2","type":"relationship"},{"created":"2026-07-11T04:30:43.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"FlockWiper-derived multi-pass secure-wipe module reimplemented in Golang (curated relation type: variant-of)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"variant-of"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper/"}],"id":"relationship--fa082b4b-baa9-55e2-817c-33788fe2f886","modified":"2026-07-11T04:30:43.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"tool--3f0157a4-a742-571e-a3b6-f4d5ecd98691","spec_version":"2.1","target_ref":"tool--eba385ff-b42a-5b89-901e-1b7cd6e57f78","type":"relationship"},{"created":"2026-07-11T17:40:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/"}],"id":"relationship--06a561c3-f745-51e1-9401-7eeea074eb02","modified":"2026-07-11T17:40:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--3967c0f5-dcbb-5c27-98b0-ec0ef0a2916f","spec_version":"2.1","target_ref":"malware--48d47fcb-950f-5bcb-bd85-62a767266526","type":"relationship"},{"created":"2026-07-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Stolen-credential/compromised-pipeline compromise of the jscrambler npm package (v8.14.0 through 8.20.0, 2026-07-11) pushing a Rust infostealer via an undocumented preinstall hook, later relocated to a self-executing dist/index.js function to evade install-script scanners; detected by Socket six minutes after publication, v8.22.0 clean (Socket / The Hacker News, 2026-07-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:jscrambler-npm-supply-chain-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ajscrambler-npm-supply-chain-2026/"}],"id":"incident--57a96903-0703-51c5-aff8-1346e42e3598","labels":["incident"],"modified":"2026-08-09T23:45:00.000Z","name":"jscrambler npm supply-chain compromise (2026-07)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["0ktapus","Octo Tempest","UNC3944","Muddled Libra"],"created":"2026-07-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Decentralised, English-fluent cybercrime collective — not a single hierarchical group — responsible for over 100 network intrusions since 2022 using vishing/smishing SSO-lookalike phishing, SIM-swap and help-desk-impersonation initial access, and BlackCat/ALPHV or DragonForce ransomware deployment. Group-IB (2026-07-07) reframes it as a movement of independent 3-5-person subclusters unified by shared TTPs, casting its own '0ktapus' designation and Microsoft's Octo Tempest, Mandiant's UNC3944 and Palo Alto's Muddled Libra as overlapping subcluster labels rather than distinct groups.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:scattered-spider","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ascattered-spider/"}],"id":"intrusion-set--d402a87c-956c-5e03-8d8a-fc3e8a59ddd6","labels":["actor"],"modified":"2026-08-10T04:45:00.000Z","name":"Scattered Spider","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-12T23:43:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"enterprise ransomware deployment for Scattered Spider-originated intrusions runs through DragonForce (and BlackCat/ALPHV) affiliate relationships (Group-IB, 2026-07-07) (curated relation type: collaborates-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"collaborates-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-12/weekly-w28-threat-actor-developments/"}],"id":"relationship--4c425e08-3962-52c0-84cc-85a8d70495f3","modified":"2026-07-12T23:43:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--d402a87c-956c-5e03-8d8a-fc3e8a59ddd6","spec_version":"2.1","target_ref":"intrusion-set--dcd6f42f-c2d6-5eec-9542-7e8ccdfc7c17","type":"relationship"},{"created":"2026-07-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"AIVD/MIVD-disclosed (2026-07-11) compromise of internet-connected cameras reachable via default passwords or outdated firmware (including cameras operated by businesses along the routes) in the Netherlands, used by Russia-linked actors to monitor arms shipments to Ukraine. Triggered a coordinated NL/France/Germany/Finland ambassador summons and a NATO joint condemnation on 2026-07-13. No named Russian APT cluster was stated in the disclosure (NL Times/ANP, 2026-07-11 and 2026-07-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:russia-ip-camera-hijacking-nato-supply-routes-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Arussia-ip-camera-hijacking-nato-supply-routes-2026/"}],"id":"campaign--f714a363-ac17-593f-8cc5-d6c33b0f3d41","labels":["campaign","russia-nexus"],"modified":"2026-07-19T23:42:00.000Z","name":"Russian hijacking of IP cameras along NATO military-supply routes (2026-07)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Progress Software ordered all on-premises ShareFile Storage Zone Controller customers to manually shut down their Windows servers on 2026-07-10 over an undisclosed 'credible external security threat'; as of 2026-07-13 no CVE, root cause, patch or restart timeline had been published and the vendor status page still showed the service non-operational. A chainable pre-auth RCE in the same component (CVE-2026-2699/CVE-2026-2701, watchTowr, patched in SZC 5.12.4) is the plausible but unconfirmed working hypothesis.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:progress-sharefile-storage-zone-controller-shutdown-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aprogress-sharefile-storage-zone-controller-shutdown-2026-07/"}],"id":"incident--00e821b5-f94e-56b8-ad70-8de1ce47e73d","labels":["incident"],"modified":"2026-07-14T20:21:02.000Z","name":"Progress ShareFile Storage Zone Controller emergency shutdown","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"On 2026-07-13, France (ANSSI/Cyber Crisis Coordination Centre C4) and the EU High Representative formally attributed the long-running (since ≥2004) Turla intrusion set to Russia's FSB 16th Centre, with CERT-FR report CERTFR-2026-CTI-005 documenting French victims across the defence, diplomatic, justice and technology sectors (2017–2025) and Turla's spearphishing/watering-hole initial-access tradecraft. Coordinated EU sanctions hit 9 individuals and 4 organisations (incl. enabler firms AO AST and NPP Gamma) and the UK sanctioned 24. The FSB 16th Centre is the parent unit behind both Turla/Secret Blizzard and the Static Tundra/Berserk Bear router-hijacking cluster (per heise EU-sanctions reporting and the morning Static Tundra advisory).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:france-eu-turla-fsb-attribution-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afrance-eu-turla-fsb-attribution-2026-07/"}],"id":"incident--12d18a41-24c4-51b4-a5be-0664c1cbe910","labels":["incident","russia-nexus"],"modified":"2026-07-19T23:42:00.000Z","name":"France/EU formal attribution of Turla (FSB Centre 16) espionage against France","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Coordinated destructive cyberattack on 29 December 2025 against 30+ Polish wind/photovoltaic grid-connection substations (RTU/HMI/protection-relay firmware damage, file deletion) and a combined heat-and-power plant serving ~500,000 customers, where wiper malware was blocked by the operator's EDR before detonation. CERT Polska (2026-01-30) attributed it via infrastructure overlap to the Static Tundra/Berserk Bear/Ghost Blizzard/Dragonfly cluster and called it the first publicly documented destructive activity by this normally espionage-focused cluster; the UK and EU formally attributed it to FSB Centre 16 with coordinated sanctions on 2026-07-13. Earlier ESET reporting attributed the same DynoWiper attack to Sandworm — attribution contested at the cluster-label level.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:poland-energy-grid-attack-2025-12-29","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Apoland-energy-grid-attack-2025-12-29/"}],"id":"incident--196d8765-6000-50df-bd55-1c71a475403e","labels":["incident","russia-nexus"],"modified":"2026-08-24T09:10:00.000Z","name":"Poland energy-sector destructive attack (29 December 2025)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Berserk Bear","Energetic Bear","Crouching Yeti","Dragonfly","Ghost Blizzard"],"created":"2026-07-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russian FSB Centre 16 network-device cluster (Cisco Talos: Static Tundra; CrowdStrike/FBI: Berserk Bear/Energetic Bear; Symantec: Dragonfly; Microsoft: Ghost Blizzard) that opportunistically compromises internet-facing routers via default/weak SNMP community strings and Cisco Smart Install (CVE-2018-0171), exfiltrating device configurations over TFTP, across communications, defence, energy, financial, government and healthcare sectors. Detailed in a 19-agency (13-country) joint Cybersecurity Advisory (2026-07-13) and formally attributed by CERT Polska/UK/EU to the destructive 29 December 2025 Poland energy-grid attack. FSB Centre 16 is a parent unit spanning multiple tracked clusters (Static Tundra and, separately, Turla/Secret Blizzard), not a single group.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:static-tundra","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Astatic-tundra/"}],"id":"intrusion-set--2c339fa5-1ddc-5382-9acd-fa5af01a2922","labels":["actor","russia-nexus"],"modified":"2026-08-24T09:10:00.000Z","name":"Static Tundra","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["APT44","Seashell Blizzard","UAC-0113","Voodoo Bear","SANDWORM RELIC"],"created":"2026-07-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russian GRU-linked destructive/disruptive threat actor. Referenced in pipeline coverage as the contested alternative attribution for the 29 December 2025 Poland energy-grid sabotage: earlier ESET reporting (via BleepingComputer, 2026-01-24) attributed the DynoWiper attack to Sandworm, while CERT Polska and the 2026-07-13 UK/EU government attribution assign the incident to the Static Tundra / FSB Centre 16 cluster.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:sandworm","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Asandworm/"}],"id":"intrusion-set--319df8be-c4e8-5c83-ab63-20029d520c7b","labels":["actor","russia-nexus"],"modified":"2026-07-20T04:30:00.000Z","name":"Sandworm","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-13T12:40:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"France (ANSSI/C4) and the EU High Representative formally attributed the Turla intrusion set to the FSB 16th Centre on 2026-07-13","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/"}],"id":"relationship--47f7eca9-c0de-5cae-b552-8710ddb7a834","modified":"2026-07-13T12:40:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--12d18a41-24c4-51b4-a5be-0664c1cbe910","spec_version":"2.1","target_ref":"intrusion-set--8ae5f539-8ebc-52fd-bbdc-1153fc0e0991","type":"relationship"},{"created":"2026-07-13T12:40:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"CERT Polska infrastructure-overlap analysis + formal UK/EU government attribution (2026-07-13); cluster label contested vs. an earlier ESET Sandworm attribution","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/"}],"id":"relationship--70ad1677-e078-5a7c-8943-3a55eb21f815","modified":"2026-07-13T12:40:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--196d8765-6000-50df-bd55-1c71a475403e","spec_version":"2.1","target_ref":"intrusion-set--2c339fa5-1ddc-5382-9acd-fa5af01a2922","type":"relationship"},{"created":"2026-07-13T12:40:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Sibling clusters under the same FSB 16th Centre parent unit — the 16th Centre 'controls groups like Turla' per heise EU-sanctions reporting (2026-07-13) and the morning Static Tundra advisory; COMCYBER's page addresses only the Turla mode","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/"}],"id":"relationship--7ceb18c3-9ec8-5600-9e97-5e6a26409887","modified":"2026-07-13T12:40:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--8ae5f539-8ebc-52fd-bbdc-1153fc0e0991","spec_version":"2.1","target_ref":"intrusion-set--2c339fa5-1ddc-5382-9acd-fa5af01a2922","type":"relationship"},{"created":"2026-07-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Multi-year Telegram-based influence and cryptocurrency/credential-fraud campaign (operator handle 'bandcampro') targeting US conservative/conspiracy-theory audiences; since late 2025 operationalized via a jailbroken Gemini AI agent that performs content generation, credential-theft workflows and autonomous C2 infrastructure migration (Trend Micro TrendAI Research, 2026-05-21 and 2026-07-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:patriot-bait","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Apatriot-bait/"}],"id":"campaign--5101cb82-7849-5510-a854-a8c5eec3ce41","labels":["campaign","russia-nexus"],"modified":"2026-07-19T23:26:00.000Z","name":"Patriot Bait","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Campaign of mass GitHub pull-request floods against repositories with vulnerable pull_request_target workflows to steal CI/npm publish tokens via pastebin dead-drops, tracked by Wiz across multiple package-ecosystem intrusions; the dead-drop naming pattern in the 2026-07-14 AsyncAPI compromise matches this campaign. Wiz states prt-scan has not been linked to the Miasma framework (Wiz, 2026-07-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:prt-scan-github-actions-pwn-request-token-theft","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aprt-scan-github-actions-pwn-request-token-theft/"}],"id":"campaign--77db17c3-4d94-57d8-b013-e131c43cbe37","labels":["campaign"],"modified":"2026-07-16T04:44:00.000Z","name":"prt-scan","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"On 2026-07-14 an attacker abused a misconfigured pull_request_target GitHub Actions workflow in the asyncapi/generator repository to steal the AsyncAPI org's service-account/npm publish token and publish five trojanized @asyncapi package versions (generator, generator-helpers, generator-components, specs — together over three million downloads a week) carrying a multi-stage IPFS-delivered implant that self-identifies as 'M-RED-TEAM v6.4'. Wiz makes no definitive attribution; technical fingerprints overlap the Miasma framework and the dead-drop naming matches the prt-scan campaign (Wiz, 2026-07-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:asyncapi-npm-github-actions-supply-chain-compromise-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aasyncapi-npm-github-actions-supply-chain-compromise-2026-07/"}],"id":"incident--06fa864d-adcc-58e9-bc6b-8905245919c6","labels":["incident"],"modified":"2026-08-09T23:45:00.000Z","name":"AsyncAPI npm supply-chain compromise via GitHub Actions (M-RED-TEAM)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DragonForce listed the Fondation pour la formation des adultes à Genève (IFAGE), a Geneva adult-education foundation, on its extortion leak site on 2026-07-14, claiming 850 GB of exfiltrated data — a claim exceeding and unconfirmed against IFAGE's own May 2026 disclosure of a narrower April 2026 employee-data-exfiltration incident (Inside IT, 2026-07-14; La Télé, 2026-05-15). Treated as an unconfirmed watch item.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ifage-geneva-dragonforce-leak-claim-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aifage-geneva-dragonforce-leak-claim-2026-07/"}],"id":"incident--4d00ce6d-2107-5cb3-9314-3efb6f679b12","labels":["incident"],"modified":"2026-07-26T23:44:00.000Z","name":"IFAGE Geneva — DragonForce leak-site claim (850 GB)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Solo Russian-speaking financially/ideologically motivated cybercriminal running the multi-year 'Patriot Bait' Telegram influence-and-fraud operation; documented by Trend Micro TrendAI Research using a jailbroken Gemini CLI to autonomously write, deploy and migrate C2 infrastructure, with the human contributing an estimated 11% of session activity (Trend Micro, 2026-07-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:bandcampro","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Abandcampro/"}],"id":"intrusion-set--a4099694-971f-5333-a844-32687f676cc2","labels":["actor","russia-nexus"],"modified":"2026-07-19T23:26:00.000Z","name":"bandcampro","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft Threat Intelligence designation for the actor behind the June 2026 compromise of the Klue competitive-intelligence platform, whose harvested Salesforce credentials were reused to discover, query and exfiltrate customer CRM data — reported within Microsoft's broader account of a year of ShinyHunters-tradecraft Salesforce OAuth-abuse campaigns (Microsoft Threat Intelligence, 2026-07-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:storm-3138","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Astorm-3138/"}],"id":"intrusion-set--b37f6b8a-8155-5a5b-8331-d91bc3a997f5","labels":["actor"],"modified":"2026-07-19T23:46:00.000Z","name":"Storm-3138","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Native-C++ macOS infostealer impersonating Apple's CrashReporter (bundle id com.apple.crashreporter), delivered via a signed and Apple-notarized 'Werkbit Setup' dropper that stages an ad-hoc-signed payload from a hidden /private/tmp path; validates the victim's login password locally with dscl -authonly before harvesting keychain, browser, wallet-extension and password-manager data, AES-GCM-encrypted and exfiltrated over libcurl. Tracked by Jamf Threat Labs as a distinct family from AMOS/MacSync/Phexia (Jamf Threat Labs, 2026-07-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:crashstealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Acrashstealer/"}],"id":"tool--aed1744a-856c-57ec-bb90-68e09f6eabac","labels":["tool"],"modified":"2026-07-19T23:20:00.000Z","name":"CrashStealer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["miasma-train-p1","Miasma RAT"],"created":"2026-07-14T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Multi-stage Node.js post-compromise implant framework (self-identifies as 'M-RED-TEAM v6.4' in code comments) delivered via an IPFS-hosted encrypted loader; establishes user-level persistence (systemd user service on Linux, platform equivalents on macOS/Windows), beacons over multiple C2 channels (HTTP, Nostr relays, Ethereum smart contracts, libp2p mesh) and carries credential-theft capabilities (browser secrets, SSH keys, npm/GitHub/AWS tokens, macOS Keychain, crypto wallets). First observed in the 2026-07-14 AsyncAPI npm supply-chain compromise (Wiz, 2026-07-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:m-red-team-malware-framework","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Am-red-team-malware-framework/"}],"id":"tool--b955e5e7-74ff-5575-8b02-02b275b8e755","labels":["tool"],"modified":"2026-08-09T23:45:00.000Z","name":"M-RED-TEAM","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-14T12:38:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Wiz notes shared technical fingerprints (javascript-obfuscator config, 'miasma'-branded persistence service and relay tags) but 'minimal resemblance' beyond those references and makes no definitive attribution (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions/"}],"id":"relationship--b4d32a62-aae0-559d-9a12-b5aa94134a42","modified":"2026-07-14T12:38:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"tool--b955e5e7-74ff-5575-8b02-02b275b8e755","spec_version":"2.1","target_ref":"campaign--e778509e-cc8c-587e-a850-eb7ea1fbfb8a","type":"relationship"},{"created":"2026-07-14T12:38:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Wiz links the pastebin dead-drop naming pattern used in this compromise to the prt-scan pull-request-abuse campaign","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-14/asyncapi-npm-supply-chain-compromise-github-actions/"}],"id":"relationship--ed21424a-236b-5b03-82ad-64ec6f9dbb12","modified":"2026-07-14T12:38:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--06fa864d-adcc-58e9-bc6b-8905245919c6","spec_version":"2.1","target_ref":"campaign--77db17c3-4d94-57d8-b013-e131c43cbe37","type":"relationship"},{"created":"2026-07-14T20:19:53.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Rapid7 states the technical correlation indicates a single actor or coordinated group is responsible for discovering and exploiting the SonicWall SMA 1000 chain that Volexity tracks as UTA0533. A correlation claim only — Volexity has published no INC link, so this is never upgraded to attribution or a merge. (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/"}],"id":"relationship--54ed9573-def2-5299-812d-5a28b2a2ccd4","modified":"2026-07-14T20:19:53.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--4a82240a-058b-521d-83c9-4eb4ad051bcf","spec_version":"2.1","target_ref":"intrusion-set--2dc1df2d-c3b7-5e3b-8ca3-c8c9ac090203","type":"relationship"},{"created":"2026-07-14T20:19:53.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited/"}],"id":"relationship--96bae68f-53cb-5604-8a59-fc6d35c88fdf","modified":"2026-07-14T20:19:53.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--2dc1df2d-c3b7-5e3b-8ca3-c8c9ac090203","spec_version":"2.1","target_ref":"tool--70ffe9a9-295a-5631-a115-fe9ca4171078","type":"relationship"},{"created":"2026-07-14T20:22:57.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Trend Micro: bandcampro is the sole human operator of the Patriot Bait campaign","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-14/patriot-bait-jailbroken-gemini-cli-autonomous-c2/"}],"id":"relationship--9b618ba2-7233-58cd-a041-e4a25331d9e2","modified":"2026-07-14T20:22:57.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--5101cb82-7849-5510-a854-a8c5eec3ce41","spec_version":"2.1","target_ref":"intrusion-set--a4099694-971f-5333-a844-32687f676cc2","type":"relationship"},{"created":"2026-07-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Researcher Cereblab's wire-level analysis found xAI's Grok Build CLI silently bundled and uploaded developers' entire Git repositories (full history plus secrets) to a SpaceXAI-controlled Google Cloud Storage bucket regardless of the prompt; xAI applied a silent server-side fix (disable_codebase_upload) on 2026-07-13 with no advisory and Musk pledged deletion of previously uploaded data (The Register, 2026-07-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:xai-grok-build-cli-repo-exfiltration-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Axai-grok-build-cli-repo-exfiltration-2026-07/"}],"id":"incident--b4d69661-1e59-5103-bc6f-39aec969d8c1","labels":["incident"],"modified":"2026-07-15T00:00:00.000Z","name":"xAI Grok Build CLI whole-repository/secrets exfiltration (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Proofpoint-tracked cluster (disclosed 2026-07-13) that independently developed OAuth client ID spoofing against Microsoft Entra ID from Cloudflare-fronted infrastructure, Dec 2025–Mar 2026: 3.7M distinct spoofed client IDs against Entra ID tenants; divergent tooling from UNK_pyreq2323 indicates parallel invention of the technique.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unk-outflareaz","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunk-outflareaz/"}],"id":"intrusion-set--745d2a34-fdeb-5476-946f-8e3f57247c02","labels":["actor"],"modified":"2026-07-19T23:46:00.000Z","name":"UNK_OutFlareAZ","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Proofpoint-tracked cluster (disclosed 2026-07-13) that ran OAuth client ID spoofing against Microsoft Entra ID from AWS infrastructure, Jan–Mar 2026: 700,000+ distinct spoofed client IDs used to enumerate and validate credentials without generating a successful sign-in log entry, via the ROPC token endpoint and differential AADSTS error responses.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unk-pyreq2323","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunk-pyreq2323/"}],"id":"intrusion-set--79cad185-ae87-52aa-9e6b-b64dfb40ac34","labels":["actor"],"modified":"2026-07-19T23:46:00.000Z","name":"UNK_pyreq2323","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"World Leaks (Hunters International rebrand) posted ~858,000 files on its leak site attributed to Reliance Group, a contractor to India's Kudankulam Nuclear Power Plant; Reliance confirmed a partial breach from a server hosted by third-party Indian data-centre provider Yotta, and Reuters reviewed ~19,000 sensitive files (blueprints, supplier/inspection records) whose authenticity is not established in the cited reporting (Reuters via The Week, 2026-07-15).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:kudankulam-reliance-worldleaks-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Akudankulam-reliance-worldleaks-2026-07/"}],"id":"incident--158dfcd4-cb5e-5e3d-9a80-03a091f820e2","labels":["incident"],"modified":"2026-07-19T23:58:00.000Z","name":"Kudankulam nuclear-plant contractor (Reliance Group) third-party-hosting data breach (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Disclosed 2026-07-15: an external service provider to Basel's canton-owned energy/water/telecom utility Industrielle Werke Basel was compromised, exposing ~40,000 customer records (names, addresses, smart-meter numbers and installation attributes); IWB's own IT/OT systems and supply were unaffected and the Basel-Stadt data protection officer assessed misuse risk as low. No provider name, actor or initial-access vector disclosed (Netzwoche, SwissCybersecurity.net, Watson.ch).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:iwb-basel-service-provider-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aiwb-basel-service-provider-breach-2026-07/"}],"id":"incident--8c536905-3225-5f67-8562-be29422f0c81","labels":["incident"],"modified":"2026-07-19T23:58:00.000Z","name":"Industrielle Werke Basel (IWB) third-party service-provider data breach (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Modular Windows RAT / likely malware-as-a-service active since ~April 2026, distributed via ClickFix-Vidar infection chains; executes indirect syscalls from the .text section of patched legitimate DLLs, patches AMSI/ETW, discovers its WebSocket C2 through four decentralized fallbacks (Telegram bio, Steam profile, DNS TXT, Polygon smart contract), and ships a keylogger, stealer and a CDP/WebDriver-BiDi banking web-injection module (Elastic Security Labs, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:telepuz-maas-malware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Atelepuz-maas-malware/"}],"id":"tool--2de731ed-4421-587c-8055-2ad9bc59d2ea","labels":["tool"],"modified":"2026-07-19T23:20:00.000Z","name":"TELEPUZ","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-16T04:42:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"World Leaks posted the ~858,000 files and is the extortion actor behind the leak-site listing.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-16/worldleaks-kudankulam-reliance-third-party-hosting-breach/"}],"id":"relationship--fd9e2c5c-3fb4-5177-88b4-f258eb231012","modified":"2026-07-16T04:42:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--158dfcd4-cb5e-5e3d-9a80-03a091f820e2","spec_version":"2.1","target_ref":"intrusion-set--850327b1-82c0-5f02-b797-5990145160ea","type":"relationship"},{"created":"2026-07-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"APT campaign active since at least May 2026 that persists by DLL-sideloading into the ViPNet secure-network suite's own auto-update component and hooks raw AFD IOCTLs to blind user-mode network-filtering security tools; direct victimology is Russian government and critical-infrastructure organizations. Attributed by Kaspersky with low confidence to an unknown Chinese-speaking group, on artifacts Kaspersky flags as possibly unintentional or false flags (Kaspersky Securelist/GReAT, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:hellonet-vipnet-supply-chain","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ahellonet-vipnet-supply-chain/"}],"id":"campaign--9eff6517-2738-547d-931f-f5a40af38367","labels":["campaign"],"modified":"2026-07-17T04:35:00.000Z","name":"HelloNet","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Two 2025 breaches of Wind Tre's retail-facing customer web application: attackers vished retail POS staff into granting remote access, harvested a stored client digital certificate and credentials, used them as valid MFA'd access, then enumerated an unprotected secondary customer-lookup API (~2M sequential customerId requests) to exfiltrate data on 365,048 customers (payment data for 41,359). Italy's Garante fined Wind Tre EUR 1,715,600 (decision 2026-05-14, published 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:wind-tre-2026-vishing-api-enumeration-breach","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Awind-tre-2026-vishing-api-enumeration-breach/"}],"id":"incident--b55dc582-c8c9-5c0b-b677-aab4d0d03ec7","labels":["incident"],"modified":"2026-07-19T23:50:00.000Z","name":"Wind Tre vishing + API-enumeration breach (2025)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russian-speaking, financially motivated threat actor active since at least June 2025, distributing trojanized installers (MobaXterm, WebEx, Zoom, DBeaver, FACEIT) via ClickFix lures to deploy the Python-based Starland RAT and a bespoke PowerShell C2 implant tracked as WLDR, with CastleStealer and a Remcos variant as follow-on payloads (Cisco Talos, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uat-11795","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auat-11795/"}],"id":"intrusion-set--b27b1125-6a29-5a9a-b029-cf5d60ffd23c","labels":["actor"],"modified":"2026-07-19T23:20:00.000Z","name":"UAT-11795","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["HelloInjector","HelloProxy","HelloExecutor","HelloCleaner","HelloBackdoor"],"created":"2026-07-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Multi-component malware suite used in the HelloNet campaign: HelloInjector (DLL-sideload loader that injects into svchost.exe), HelloProxy (traffic proxy/loader hooking AFD IOCTLs via Microsoft Detours), HelloExecutor (shell-command backdoor), HelloCleaner (ViPNet log eraser) and HelloBackdoor (Rust file-transfer backdoor on TCP/443) (Kaspersky Securelist/GReAT, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:hellonet-malware-suite","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Ahellonet-malware-suite/"}],"id":"tool--1d70704a-7892-5b17-bdee-1b61d066ed3b","labels":["tool"],"modified":"2026-07-17T04:35:00.000Z","name":"HelloNet toolkit","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":".NET infostealer/credential harvester (Chromium/Firefox DPAPI + AES-GCM decryption, crypto-wallet extensions, Discord/Telegram/Steam data) delivered by UAT-11795 as an x64 shellcode payload via Starland RAT (Cisco Talos, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:castlestealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Acastlestealer/"}],"id":"tool--6080c638-2f87-50f8-b9a5-e203932af4ff","labels":["tool"],"modified":"2026-07-17T04:35:00.000Z","name":"CastleStealer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Python-based RAT deployed by UAT-11795 via trojanized NSIS installers; runs in memory, persists via a scheduled task and Startup LNK, steals browser/crypto-wallet data, patches AMSI/ETW before APC-based shellcode injection, and resolves a fallback C2 domain from a Polygon smart-contract dead-drop (Cisco Talos, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:starland-rat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Astarland-rat/"}],"id":"tool--664599f4-511c-5b36-99a1-164976368c6f","labels":["tool"],"modified":"2026-07-19T23:20:00.000Z","name":"Starland RAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malware-as-a-service infostealer that Microsoft reports is associated with the rebranding of Amatera Stealer; observed in two distinct ClickFix-rooted intrusion chains (WebDAV/rundll32/Python with an EtherHiding blockchain dead-drop, and a fileless MSHTA/steganography chain), both ending in DPAPI-based browser-credential theft and M365/OneDrive document enumeration (Microsoft Threat Intelligence, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:acr-stealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aacr-stealer/"}],"id":"tool--ef1a7083-eff0-55e0-a38e-f8a707b36811","labels":["tool"],"modified":"2026-07-19T23:20:00.000Z","name":"ACR Stealer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["WLDR agent","WLDR C2"],"created":"2026-07-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Bespoke, undocumented PowerShell in-memory C2 implant deployed by UAT-11795 via Starland RAT's shell-command capability; HWID-bound, with AES-encrypted 10-second HTTP beaconing and a multi-threaded RunspacePool operator-command engine (Cisco Talos, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:wldr-c2-implant","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Awldr-c2-implant/"}],"id":"tool--fffc5ab0-cabd-5494-8f76-e3da6cc28c1a","labels":["tool"],"modified":"2026-07-17T04:35:00.000Z","name":"WLDR","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-17T04:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-17/talos-uat-11795-starland-rat-wldr-c2/"}],"id":"relationship--27736014-a6d7-5a69-a166-50513e10860f","modified":"2026-07-17T04:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b27b1125-6a29-5a9a-b029-cf5d60ffd23c","spec_version":"2.1","target_ref":"tool--6080c638-2f87-50f8-b9a5-e203932af4ff","type":"relationship"},{"created":"2026-07-17T04:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-17/talos-uat-11795-starland-rat-wldr-c2/"}],"id":"relationship--50115e31-a655-5182-8f22-1391aef5a893","modified":"2026-07-17T04:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b27b1125-6a29-5a9a-b029-cf5d60ffd23c","spec_version":"2.1","target_ref":"tool--fffc5ab0-cabd-5494-8f76-e3da6cc28c1a","type":"relationship"},{"created":"2026-07-17T04:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-17/kaspersky-hellonet-vipnet-updater-sideload-afd-ioctl/"}],"id":"relationship--8adaa9dc-2c69-513a-a814-361e22e33655","modified":"2026-07-17T04:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--9eff6517-2738-547d-931f-f5a40af38367","spec_version":"2.1","target_ref":"tool--1d70704a-7892-5b17-bdee-1b61d066ed3b","type":"relationship"},{"created":"2026-07-17T04:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-17/talos-uat-11795-starland-rat-wldr-c2/"}],"id":"relationship--93d0a2f6-8c37-5aa8-b8a9-28d405eed771","modified":"2026-07-17T04:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b27b1125-6a29-5a9a-b029-cf5d60ffd23c","spec_version":"2.1","target_ref":"tool--664599f4-511c-5b36-99a1-164976368c6f","type":"relationship"},{"created":"2026-07-17T04:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft reports ACR Stealer is 'reportedly ... associated with the rebranding of Amatera Stealer' — a hedged rebrand/successor assessment, not confirmed. (curated relation type: successor-of)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"successor-of"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-17/microsoft-acr-stealer-two-clickfix-intrusion-chains/"}],"id":"relationship--b37f23fe-905f-5305-baac-320fd9e2d0c5","modified":"2026-07-17T04:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"tool--ef1a7083-eff0-55e0-a38e-f8a707b36811","spec_version":"2.1","target_ref":"tool--23cad833-5f1e-5ba2-81d2-6ed135194b0c","type":"relationship"},{"aliases":["DeceptiveDevelopment","REF9403"],"created":"2026-07-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Long-running DPRK-aligned campaign that lures software developers with fake job offers and take-home coding-interview projects to deliver credential- and crypto-wallet-stealing malware; Elastic's 2026-07-18 instance (REF9403) hid a four-stage OTTERCOOKIE-aligned payload as Base64 fragments in HTML comments across SVG flag images, reassembled and run via eval(), with zero AV detection at publication.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:contagious-interview","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acontagious-interview/"}],"id":"campaign--97d9ad8c-7d7c-5828-95f8-509ff2ef5e30","labels":["campaign","north-korea-nexus"],"modified":"2026-08-24T09:10:00.000Z","name":"Contagious Interview","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Volexity's tracking designation for the actor exploiting the SonicWall SMA 1000 zero-day chain (CVE-2026-15409 SSRF, CVE-2026-15410 path-traversal command injection) as zero-days from at least 2026-06-22; deploys the KNUCKLEBALL Python injection loader to run a modified Suo5 HTTP proxy and the ORANGETAIL Java webshell inside the appliance's legitimate workplace process, captures cleartext LDAP credentials, and pivots into internal networks (Volexity, 2026-07-17). No public geopolitical attribution.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uta0533","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auta0533/"}],"id":"intrusion-set--2dc1df2d-c3b7-5e3b-8ca3-c8c9ac090203","labels":["actor"],"modified":"2026-08-04T06:10:00.000Z","name":"UTA0533","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Threat actor Kaspersky GReAT names as potentially linked to the GoSerpent campaign against Southeast Asian government and diplomatic entities, on the basis of shared victim targeting, technical capabilities and operational methodology; the connection is explicitly hedged as 'indications of a potential link', not attribution (Kaspersky Securelist, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:tetrisphantom","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Atetrisphantom/"}],"id":"intrusion-set--ba570bde-1598-56c5-924a-3026c5987aaa","labels":["actor"],"modified":"2026-07-18T13:05:00.000Z","name":"TetrisPhantom","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Go-based RAT used since at least 2021 against government and diplomatic entities in Southeast Asia; the 2026 evolution documented by Kaspersky GReAT decrypts its C2 configuration from AES-CBC-encrypted command-line arguments, communicates over ChaCha20, and anchors a staged intrusion model — a ThumbcacheService document-harvesting Windows service plus Mimikatz/QuarksDumpLocalHash credential theft, weeks of silent collection, then delayed exfiltration via the Stowaway proxy and a TmcLoader/TmcPayload toolset (Kaspersky Securelist, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:goserpent","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Agoserpent/"}],"id":"malware--a0fb38c1-ac7a-5755-a6b0-6fb5898f9450","is_family":true,"labels":["malware"],"modified":"2026-07-18T13:05:00.000Z","name":"GoSerpent","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-07-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Multi-stage malware family aligned with the DPRK Contagious Interview campaign (first documented by NTT Security, December 2024; overlaps the BEAVERTAIL lineage); the 2026-07-18 Elastic-documented variant chains a browser/crypto-wallet credential stealer, a sensitive-file stealer, a Socket.IO-based RAT with interactive shell execution, and a clipboard stealer/Windows PE dropper.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:ottercookie","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aottercookie/"}],"id":"tool--0d3ac9e6-ab96-5d87-a434-80e7139eb958","labels":["north-korea-nexus","tool"],"modified":"2026-08-24T09:10:00.000Z","name":"OTTERCOOKIE","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["KNUCKLEBALL","ORANGETAIL"],"created":"2026-07-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UTA0533's post-exploitation toolset for SonicWall SMA 1000 appliances: KNUCKLEBALL is a Python injection loader that injects a modified Suo5 open-source HTTP proxy-forwarder and ORANGETAIL, a custom Behinder-like Java webshell, into the appliance's legitimate workplace process; persistence is via the workplace init script and NGINX Unit route rewrites (Volexity, 2026-07-17).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:sonicwall-sma-uta0533-toolset","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Asonicwall-sma-uta0533-toolset/"}],"id":"tool--70ffe9a9-295a-5631-a115-fe9ca4171078","labels":["tool"],"modified":"2026-08-04T06:10:00.000Z","name":"KNUCKLEBALL / ORANGETAIL SonicWall SMA toolset","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-18T04:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Claimed by ShinyHunters; the company has confirmed neither the attribution nor the claimed data volumes.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing/"}],"id":"relationship--915f0e07-88be-56bc-a966-b0be1525f8c2","modified":"2026-07-18T04:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--ae3922c7-ab57-5983-a63d-ec6c10ac8b28","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-07-18T04:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-18/contagious-interview-ottercookie-svg-steganography/"}],"id":"relationship--ae39a0a7-24e0-5762-8aff-6085887088c7","modified":"2026-07-18T04:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--97d9ad8c-7d7c-5828-95f8-509ff2ef5e30","spec_version":"2.1","target_ref":"tool--0d3ac9e6-ab96-5d87-a434-80e7139eb958","type":"relationship"},{"created":"2026-07-18T13:05:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky GReAT: 'indications of a potential link to the TetrisPhantom threat actor' from similarities in victim targeting, technical capabilities and operational methodology — hedged, short of attribution (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-18/goserpent-backdoor-evolution-sea-government-diplomatic/"}],"id":"relationship--f0367dde-5703-5f85-8623-7db79aa3c5b0","modified":"2026-07-18T13:05:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"malware--a0fb38c1-ac7a-5755-a6b0-6fb5898f9450","spec_version":"2.1","target_ref":"intrusion-set--ba570bde-1598-56c5-924a-3026c5987aaa","type":"relationship"},{"created":"2026-07-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Multi-day outage of Romania's national cadastre/land-registry systems (e-Terra, RENNS, institutional email) beginning 14 July 2026, confirmed by ANCPI as a cyberattack. ByteToBreach claims citizen-data theft, a copied GitLab source-code server, ransomware deployment and backup deletion; ANCPI disputes any data compromise. Still unresolved as of 17 July 2026 (Help Net Security, Public Record, KELA).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ancpi-romania-cyberattack-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aancpi-romania-cyberattack-2026-07/"}],"id":"incident--2262008c-e75c-5a86-9cc2-dba01964119f","labels":["incident"],"modified":"2026-08-05T04:12:23.000Z","name":"ANCPI Romania cadastre cyberattack","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unauthorized access (2026-03-28 to 04-12, detected 2026-04-23) to a third-party IT service-management/support-ticket platform used by Ernst & Young LLP's tax practice; documents containing client tax/financial data were downloaded. Disclosed via California/Vermont AG breach notifications filed 2026-07-15; EY has not named the platform, the access vector, or the affected count (California OAG, BleepingComputer, CyberInsider, 2026-07-15/17). ShinyHunters claimed responsibility on its leak site on 2026-07-27, asserting the credentials came from a supply-chain attack and reached EY's Jira, GitHub and Azure environments; EY has not confirmed the attribution and the claim is unverified (BleepingComputer, 2026-07-27).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ey-third-party-itsm-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aey-third-party-itsm-breach-2026/"}],"id":"incident--483009f0-10c7-56d6-a644-3cc4cd2685d7","labels":["incident"],"modified":"2026-08-02T23:59:15.000Z","name":"Ernst & Young third-party ITSM breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"IRGC-linked hacktivist persona targeting industrial control systems (PLCs). OpenAI (Oct 2024) first documented its ChatGPT-assisted PLC reconnaissance; CloudSEK (2026, via Recorded Future/Insikt Group, 2026-07-16) reproduced the workflow in an LLM agent and reported it can move from intent to a list of accessible US ICS devices with known default credentials in under five minutes.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:cyberav3ngers","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Acyberav3ngers/"}],"id":"intrusion-set--b05d77d9-9e2a-5e6a-8565-78f2bfb74523","labels":["actor","iran-nexus"],"modified":"2026-07-24T04:36:09.000Z","name":"CyberAv3ngers","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["GreenBravo","Charming Kitten","Mint Sandstorm","CALANQUE ION"],"created":"2026-07-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Iranian MOIS/IRGC-aligned espionage and social-engineering actor. Per Google GTIG (reported via Recorded Future/Insikt Group, 2026-07-16) it uses Gemini as an engineering platform to accelerate development of specialized malicious tools and feeds the model target biographies to script multi-turn rapport-building phishing conversations before payload delivery.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:apt42","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aapt42/"}],"id":"intrusion-set--ba49065e-c528-5a4b-97a3-f422ccc80a86","labels":["actor","iran-nexus"],"modified":"2026-07-19T23:26:00.000Z","name":"APT42","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Persistent data-leak/extortion operator active since June 2025 across dark-web forums, Telegram and a WordPress site; KELA assesses a likely individual from Oran, Algeria. Documented initial-access mix: exploitation of known cloud/corporate-infrastructure vulnerabilities, reuse of infostealer/phishing-harvested credentials, and brute force. Victimology spans government, banking and other sectors across multiple countries — KELA names a bank in Poland among the organizations that acknowledged their breaches, and Romania's ANCPI cadastre agency is the government registry hit in July 2026 (KELA, updated 2026-07-17).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:bytetobreach","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Abytetobreach/"}],"id":"intrusion-set--e50a21ef-eaac-58da-a6dd-85e672e7169e","labels":["actor"],"modified":"2026-08-09T23:45:00.000Z","name":"ByteToBreach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["ClickLock"],"created":"2026-07-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Modular macOS ClickFix-delivered infostealer documented by Group-IB (a shell script uploaded to VirusTotal 2026-06-09 with zero detections at analysis) that coerces credential and Keychain disclosure by repeatedly killing all visible applications until the victim enters their password, validating it locally via dscl before exfiltrating; bundles browser/crypto/password-manager theft and a modified open-source GSocket (gs-netcat) reverse-shell backdoor for persistence. Over 50% of ~100 identified victims across 33 countries are in Europe, active since ~May 2026 (Group-IB, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:clicklock-stealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aclicklock-stealer/"}],"id":"tool--b3932f64-68f2-5347-b46b-8ecfe40743b5","labels":["tool"],"modified":"2026-07-19T23:20:00.000Z","name":"ClickLock Stealer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-19T04:24:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ByteToBreach claimed responsibility on a dark-web forum and posted ANCPI data for sale (Help Net Security, 2026-07-16); a self-claim relayed by reporting, not independently confirmed","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-19/ancpi-romania-cadastre-cyberattack-bytetobreach/"}],"id":"relationship--9e08531e-c810-54f3-8068-02484f49d3d7","modified":"2026-07-19T04:24:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--2262008c-e75c-5a86-9cc2-dba01964119f","spec_version":"2.1","target_ref":"intrusion-set--e50a21ef-eaac-58da-a6dd-85e672e7169e","type":"relationship"},{"created":"2026-07-19T04:25:44.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Leak-site self-claim only — ShinyHunters claimed responsibility to BleepingComputer, which could not verify it; EY has not confirmed the attribution","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-19/ernst-young-third-party-itsm-platform-breach-client-tax-data/"}],"id":"relationship--e6b35424-b8d0-5cd6-8720-514792ac3f7f","modified":"2026-07-19T04:25:44.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--483009f0-10c7-56d6-a644-3cc4cd2685d7","spec_version":"2.1","target_ref":"intrusion-set--6bea3696-c956-5f7d-b28a-d26e0d25425a","type":"relationship"},{"created":"2026-07-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"CERT-UA-tracked subcluster of UAC-0002 / Sandworm (APT44, Seashell Blizzard), Russia's GRU-linked destructive-actor family. From June–July 2026 it compromised at least 10 legitimate websites to serve ClickFix fake-CAPTCHA lures whose C2 content-domain is resolved on-chain via an Ethereum smart-contract call (EtherHiding, using the bespoke injector SMARTAXE over Cloaking.House), staging VBS persistence (GHETTOVIBE), PowerShell recon (SCOUTCURL) and a Python backdoor (FREAKYPOLL); it separately distributes a full-featured Android backdoor (COWARDDUCK) via Signal disguised as security software (CERT-UA, article 6318437, 2026-07-19).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uac-0145","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auac-0145/"}],"id":"intrusion-set--58f3ca16-7464-5e60-affd-040fec154270","labels":["actor","russia-nexus"],"modified":"2026-07-20T04:30:00.000Z","name":"UAC-0145","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-20T04:30:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"CERT-UA: UAC-0145 is a subcluster of UAC-0002, also known as Sandworm / APT44 / Seashell Blizzard (the typed vocabulary has no actor→actor subcluster edge; related-to records the stated hierarchy without overclaiming)","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-20/uac-0145-sandworm-clickfix-etherhiding-android-backdoor/"}],"id":"relationship--67e196ce-c2eb-55fa-89ea-fddd272219aa","modified":"2026-07-20T04:30:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--58f3ca16-7464-5e60-affd-040fec154270","spec_version":"2.1","target_ref":"intrusion-set--319df8be-c4e8-5c83-ab63-20029d520c7b","type":"relationship"},{"created":"2026-07-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"An attacker used a fully autonomous AI-agent framework to exploit two code-execution paths in Hugging Face's dataset-processing pipeline, escalating to node-level access and harvesting cloud/cluster credentials across a weekend-long, 17,000+-action campaign before detection and containment; public models/datasets/Spaces and the software supply chain verified clean (Hugging Face disclosure, 2026-07-16).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:hugging-face-autonomous-ai-agent-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ahugging-face-autonomous-ai-agent-breach-2026-07/"}],"id":"incident--e7ddab17-aa1f-5045-a235-ad20bcf166af","labels":["incident"],"modified":"2026-08-28T04:50:00.000Z","name":"Hugging Face autonomous AI agent breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"NativeAOT .NET backdoor Group-IB links with high confidence to the Cavern C2 framework; abuses the Microsoft Graph API to turn a compromised M365 mailbox calendar into a two-way dead-drop (far-future events, hybrid RSA-OAEP + AES-256-GCM attachments) with DNS-tunneled Microsoft Entra ID credential refresh. Narrowly targets Israeli organisations; observed 3 June - 9 July 2026 (Group-IB, 2026-07-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:hollowgraph-malware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Ahollowgraph-malware/"}],"id":"tool--4d12a502-1163-50ea-ba41-39e581d41792","labels":["tool"],"modified":"2026-08-12T04:51:00.000Z","name":"HOLLOWGRAPH","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mono/.NET crypter-as-a-service (advertised on underground forums since late 2025) using 90+ polymorphic cipher routines, a modified process-ghosting loader, ZwQueryVirtualMemory/NtManageHotPatch tampering, indirect syscalls from a clean ntdll copy, and BYOVD EDR termination via a vulnerable signed driver (e.g. GoFlyDrv.sys); packs commodity RATs/infostealers for multiple criminal groups. Proofpoint attributes four Cruciferra-packed AsyncRAT campaigns to China-nexus TA4922 (Proofpoint, 2026-07-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:cruciferra-crypter","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Acruciferra-crypter/"}],"id":"tool--52be3904-2355-591a-89dd-eeb4ee93b291","labels":["tool"],"modified":"2026-07-26T23:43:00.000Z","name":"Cruciferra","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-21T04:41:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Proofpoint attributes four Cruciferra-packed AsyncRAT campaigns to TA4922","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-21/cruciferra-crypter-as-a-service-process-ghosting-byovd/"}],"id":"relationship--beb50d40-9e22-5986-a444-e9210cb4550e","modified":"2026-07-21T04:41:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--4e87dc95-c3b9-5e1c-a184-0545c12be19b","spec_version":"2.1","target_ref":"tool--52be3904-2355-591a-89dd-eeb4ee93b291","type":"relationship"},{"created":"2026-07-21T04:43:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky low-confidence association of the Cavern/Project CAV3RN framework with OilRig; behavioural overlap only, no direct code reuse or infrastructure overlap identified","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-21/hollowgraph-m365-calendar-graph-api-c2-cavern/"}],"id":"relationship--6bc974d8-cca8-5777-a76a-91c4f1a910be","modified":"2026-07-21T04:43:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--cfef2d8b-b827-5c42-9fd9-a0b096db500a","spec_version":"2.1","target_ref":"tool--8d521b89-a34c-57e8-878c-d7e515c3e66e","type":"relationship"},{"created":"2026-07-21T04:43:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Group-IB assesses HOLLOWGRAPH is a variant/component of the Cavern framework (high confidence) (curated relation type: variant-of)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"variant-of"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-21/hollowgraph-m365-calendar-graph-api-c2-cavern/"}],"id":"relationship--fcd6b788-6d44-5b53-b678-958ac5c39ff9","modified":"2026-07-21T04:43:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"tool--4d12a502-1163-50ea-ba41-39e581d41792","spec_version":"2.1","target_ref":"tool--8d521b89-a34c-57e8-878c-d7e515c3e66e","type":"relationship"},{"created":"2026-07-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Everest ransomware group compromised a data-exchange platform Stadler Rail (Swiss rolling-stock manufacturer, Thurgau) shares with a supplier and demanded a CHF 10 million ransom; Stadler refused to pay, filed a criminal complaint, and reports its own IT and worldwide production unaffected with no security-relevant or personal data stolen (swissinfo.ch, Swiss IT Magazine, 2026-07-21).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:stadler-rail-everest-supplier-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Astadler-rail-everest-supplier-breach-2026/"}],"id":"incident--2af802f4-6767-5bd5-8fe0-a0a186325451","labels":["incident"],"modified":"2026-08-02T23:57:00.000Z","name":"Stadler Rail supplier-platform breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Korea National Diplomatic Academy's online training/e-learning platform compromised via an undisclosed zero-day plus security misconfiguration (April/May 2025 – February 2026 dwell); up to ~10,000 diplomat and embassy-staff records exposed; attribution unconfirmed, state-backed groups incl. North Korea not ruled out (Korea Herald, DailySecu, Seoul Shinmun, 2026-07-21/22).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:south-korea-knda-diplomatic-academy-zero-day-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Asouth-korea-knda-diplomatic-academy-zero-day-breach-2026/"}],"id":"incident--98b2f5e5-9357-5f53-9455-4be62994012c","labels":["incident"],"modified":"2026-07-22T04:34:31.000Z","name":"KNDA diplomatic-academy zero-day breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially-motivated BitLocker-abuse extortion actor named from a May 2026 Mexico incident whose victims' screens displayed 'Hacked by XEntry Team' (Kaspersky GERT, 2026-07-21): initial access via a misconfigured Microsoft SQL Server (xp_cmdshell), persistence via legitimate RMM tools (ManageEngine Endpoint Central, Mesh Agent, Tactical RMM) and web shells, BitLocker deployed via GPO for encryption-for-impact, small ransom (~USD 3,000), ransom notes printed on office printers. Kaspersky documented a separate June 2026 Colombia BitLocker-extortion case (RDP-based) with which it assesses a POSSIBLE but unconfirmed link (ransom-note wording/delivery similarities; 'do not reveal a clear connection between the actors'). ShrinkLocker BitLocker-abuse lineage.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:xentry-team","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Axentry-team/"}],"id":"intrusion-set--20d4c6e1-4dbc-511f-971d-a5ddf15bae6a","labels":["actor"],"modified":"2026-07-26T23:43:00.000Z","name":"XEntry Team","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russian-speaking closed-group double-extortion ransomware / initial-access-broker operation that emerged in December 2020 with a code-level connection to BlackByte; runs an IAB service (since Nov 2021) and a paid corporate-insider recruitment programme (since Oct 2023); documented initial access via internet-exposed RDP without MFA and vulnerable VPN endpoints (Halcyon threat-actor profile, 2025-11-19). Claimed the July 2026 breach of a Stadler Rail supplier data-exchange platform (CHF 10M demand, refused; swissinfo.ch / Swiss IT Magazine, 2026-07-21). Per the Halcyon profile the group also claimed, in October 2025, attacks on a European national electricity-transmission operator, aviation systems at multiple European airports, and telecom networks — the group's own leak-site claims, unconfirmed by the named victims.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:everest-ransomware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aeverest-ransomware/"}],"id":"intrusion-set--bc1db243-7375-591b-b2c9-fd78bdf78a54","labels":["actor"],"modified":"2026-08-02T23:57:00.000Z","name":"Everest","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["APT34","Helix Kitten","Evasive Serpens","Hazel Sandstorm","SOLAR ION"],"created":"2026-07-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Iran-nexus (MOIS-linked) cyber-espionage actor active since ~2014 against Middle East government, energy, telecom and IT targets, known for cloud-service-abusing C2 (Microsoft Graph, OneDrive) and DNS-tunnelling tooling. Kaspersky associates the Cavern / Project CAV3RN framework (tracked as Cavern Manticore by Check Point, HOLLOWGRAPH by Group-IB) with OilRig with LOW confidence, noting behavioural overlap but no direct code reuse or infrastructure overlap (Kaspersky, 2026-07-21).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:oilrig","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aoilrig/"}],"id":"intrusion-set--cfef2d8b-b827-5c42-9fd9-a0b096db500a","labels":["actor","iran-nexus"],"modified":"2026-08-12T04:51:00.000Z","name":"OilRig","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-22T04:34:31.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Everest claimed the intrusion and demanded the CHF 10M ransom per Stadler's statement as reported","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-22/everest-ransomware-stadler-rail-supplier-platform-breach/"}],"id":"relationship--d8dbd2bc-b7b6-5317-8884-bf1875a7ef2f","modified":"2026-07-22T04:34:31.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--2af802f4-6767-5bd5-8fe0-a0a186325451","spec_version":"2.1","target_ref":"intrusion-set--bc1db243-7375-591b-b2c9-fd78bdf78a54","type":"relationship"},{"created":"2026-07-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Multi-stage npm supply-chain worm (discovered Feb 2026, documented by CrowdStrike 2026-07-21) that 'lives off the AI toolchain' — it poisons Model Context Protocol (MCP) tool-provider configs in AI coding assistants (Cursor, VS Code, Claude Desktop, Windsurf), injects global git-template hooks for persistence, and exfiltrates npm/AWS/SSH credentials and multi-provider LLM API keys, delaying activation 48–96 h on workstations to defeat install-versus-behaviour correlation and falling back to DNS tunnelling for exfil. NOT the Russian GRU actor Sandworm (actor:sandworm) — the name collision is coincidental and no relation should be drawn between them.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:sandworm-mode","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Asandworm-mode/"}],"id":"malware--bc301495-1504-5d4f-9ba2-e476db5d82a7","is_family":true,"labels":["malware"],"modified":"2026-08-09T23:45:00.000Z","name":"SANDWORM_MODE","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-07-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"BravoX's June 2026 ransomware breach of an Yverdon-les-Bains (canton Vaud) fiduciary/accounting firm, leaked 18 July 2026: ~220 GB / 100,000+ files including administrative and tax records of ~15 Nord Vaudois municipalities and Vaud State Councillor Vassilis Venizelos's tax file. No ransom paid; reported to the cantonal data-protection commissioner and the Federal Office for Cybersecurity (BACS/OFCS) (Le Temps / 24 heures / 20 minutes, 2026-07-22/23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:bravox-yverdon-fiduciary-vaud-municipalities-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Abravox-yverdon-fiduciary-vaud-municipalities-2026/"}],"id":"incident--4c3d7c9a-1dc4-5af6-aa1d-e9a2395c282a","labels":["incident"],"modified":"2026-07-26T23:44:00.000Z","name":"BravoX breach of a Yverdon-les-Bains fiduciary — Vaud municipalities data exposure","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russian-speaking-convention Ransomware-as-a-Service extortion operation first observed on the RAMP underground forum in January 2026; vets affiliates and avoids CIS-based victims (SOCRadar, 2026-01). Breached a Vaud (Switzerland) fiduciary firm around 30 June 2026 and published ~220 GB / 100,000+ files on its leak site on 18 July 2026, exposing ~15 Vaud municipalities' administrative data and a cantonal minister's tax file (Le Temps / 24 heures, 2026-07-22/23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:bravox","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Abravox/"}],"id":"intrusion-set--0921020b-c3ab-5d90-8bc8-5e19763ce5bc","labels":["actor"],"modified":"2026-07-26T23:44:00.000Z","name":"BravoX","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service operation active since at least February 2025 (distinct from MuddyWater's 2026 'Chaos' false-flag operation). Cisco Talos (2026-07-23) documents its Rust-based msaRAT tool, which builds covert C2 through the Chrome DevTools Protocol and WebRTC so the malware process itself never opens a network socket.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:chaos-ransomware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Achaos-ransomware/"}],"id":"intrusion-set--9ec61694-e9b0-5cf3-b13d-34410b93fc26","labels":["actor"],"modified":"2026-07-29T05:35:00.000Z","name":"Chaos (ransomware-as-a-service)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Void Blizzard","CL-STA-1114","TA488","UNK_PitStop"],"created":"2026-07-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russian state-supported email-espionage actor, named by the Netherlands' AIVD/MIVD in May 2025 (Void Blizzard per Microsoft, CL-STA-1114 per Unit 42, TA488 per Proofpoint). Historically reliant on password spraying, AiTM credential phishing (a modified Evilginx) and pass-the-cookie against Microsoft Exchange/cloud mail; from July 2025 it weaponised a Zimbra Collaboration Suite zero-click XSS (CVE-2025-66376) for large-scale mailbox/GAL/2FA-token exfiltration against NATO government, defence-industrial-base, energy, education, law-enforcement and NGO targets, using Ukraine as an earlier testbed. Subject of the joint advisory AA26-204A co-sealed by agencies from 16 nations (CISA/NSA/FBI and allied services, 2026-07-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:laundry-bear","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Alaundry-bear/"}],"id":"intrusion-set--f32f68b1-d1ab-590b-a5c2-675fcf9df5f9","labels":["actor","russia-nexus"],"modified":"2026-08-02T23:46:00.000Z","name":"LAUNDRY BEAR","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Rust-based RAT deployed by the Chaos ransomware group that establishes C2 exclusively by driving a headless Chrome/Edge instance via the Chrome DevTools Protocol, tunnelling commands over a WebRTC DataChannel relayed through Cloudflare Workers (signalling) and a Twilio TURN server (media relay), double-encrypted with DTLS + ChaCha20-Poly1305; the RAT process itself never makes a direct network connection (Cisco Talos, 2026-07-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:msarat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Amsarat/"}],"id":"malware--82b4364f-9ea2-5d1b-9d2f-3bdf27b96673","is_family":true,"labels":["malware"],"modified":"2026-07-26T23:43:00.000Z","name":"msaRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"aliases":["Sneaky2FA"],"created":"2026-07-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Adversary-in-the-middle Microsoft 365 phishing-as-a-service platform evolved from the Sneaky2FA kit, offering browser-in-the-browser fake login windows (added November 2025) and Cloudflare Turnstile anti-bot challenges; ~1,800 subscribers ran an estimated 15,000 campaigns/month across 200+ servers. Infrastructure seized and its developer arrested in a German BKA-led takedown with US and Indonesian partners, 2026-07-20 (BKA; Trend Micro, 2026-07-20/22).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:kratos-phaas","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Akratos-phaas/"}],"id":"tool--51bfed04-ab8f-54bf-ada5-b2ac6760d851","labels":["tool"],"modified":"2026-07-24T04:36:09.000Z","name":"Kratos (phishing-as-a-service)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["Улей","beehive","ZimReaper"],"created":"2026-07-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"LAUNDRY BEAR's custom zero-click exfiltration capability for CVE-2025-66376 in Zimbra Collaboration Suite (CISA joint advisory AA26-204A, 2026-07-23): 'Ulej' (Russian for beehive) is the client-side JavaScript payload that harvests webmail data via 12 asynchronous Zimbra SOAP calls and mints a persistent IMAP application passcode; 'Flowerbed' is the Dockerised (Catcher/Certbot/Nginx/Gardener) DNS-and-HTTPS collection backend, assessed by CISA as showing indications of AI-assisted development. Proofpoint tracks the associated post-exploitation credential-theft/persistence tooling as ZimReaper.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:ulej-flowerbed","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aulej-flowerbed/"}],"id":"tool--f391ca72-877b-56b0-a520-58e25ffbf07f","labels":["tool"],"modified":"2026-07-26T23:41:00.000Z","name":"Ulej / Flowerbed","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-24T04:36:09.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-24/bravox-vaud-fiduciary-municipalities-breach/"}],"id":"relationship--4c4fcb00-547f-5e03-ac63-0290dfe07762","modified":"2026-07-24T04:36:09.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--4c3d7c9a-1dc4-5af6-aa1d-e9a2395c282a","spec_version":"2.1","target_ref":"intrusion-set--0921020b-c3ab-5d90-8bc8-5e19763ce5bc","type":"relationship"},{"created":"2026-07-24T04:36:09.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-24/laundry-bear-zimbra-zero-click-cve-2025-66376/"}],"id":"relationship--52959c00-3da3-5399-a9fb-be458e320801","modified":"2026-07-24T04:36:09.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--f32f68b1-d1ab-590b-a5c2-675fcf9df5f9","spec_version":"2.1","target_ref":"tool--f391ca72-877b-56b0-a520-58e25ffbf07f","type":"relationship"},{"created":"2026-07-24T04:36:09.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-24/msarat-chaos-cdp-webrtc-covert-c2/"}],"id":"relationship--f1b12f23-8410-533f-9346-43e0f10ed1b5","modified":"2026-07-24T04:36:09.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--9ec61694-e9b0-5cf3-b13d-34410b93fc26","spec_version":"2.1","target_ref":"malware--82b4364f-9ea2-5d1b-9d2f-3bdf27b96673","type":"relationship"},{"created":"2026-07-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unattended AI-agent (Hermes, 'YOLO mode') post-exploitation activity and a Go-based 'Hades' implant recovered via exposed operator infrastructure targeting Thailand's Ministry of Finance; ThaiCERT/NCSA notified 2026-07-15, the Ministry has not confirmed compromise (Hunt.io, 2026-07-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:thailand-finance-ministry-hermes-ai-agent-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Athailand-finance-ministry-hermes-ai-agent-2026/"}],"id":"incident--1459b539-c354-56d6-aa94-4cb6d40994d3","labels":["incident"],"modified":"2026-08-09T23:45:00.000Z","name":"Thailand Ministry of Finance — Hermes AI-agent-automated intrusion (2026-07)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Operation RoundPress"],"created":"2026-07-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Proofpoint's designation for the GRU-assessed, Russia-aligned espionage actor behind ESET's Operation RoundPress: runs a standing supply of 'half-click' webmail-client zero-days across Zimbra, mDaemon, Roundcube, Kerio and SOGo, deploying the per-client SpyPress payload to steal credentials, contacts and mail from Ukrainian and Eastern-European government/military targets. Proofpoint reports no telemetry overlap with TA422/APT28 and leaves the specific GRU unit unconfirmed (Proofpoint, 2026-07-23; ESET, 2025-05-15).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:ta458-roundpress","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ata458-roundpress/"}],"id":"intrusion-set--a0063de9-82c1-587d-a80a-586d22b2d890","labels":["actor","russia-nexus"],"modified":"2026-07-26T23:41:00.000Z","name":"TA458","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Obfuscated JavaScript payload customised per targeted webmail client, deployed by TA458/Operation RoundPress to steal credentials, contacts and mail; on Roundcube it chains CVE-2025-49113 (unsafe PHP deserialization via the file-upload handler) to plant PHP webshells for durable access (Proofpoint, 2026-07-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:spypress","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aspypress/"}],"id":"malware--a2d42efb-6308-5210-be0a-182334fec27c","is_family":true,"labels":["malware"],"modified":"2026-07-26T23:41:00.000Z","name":"SpyPress","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"aliases":["Hermes"],"created":"2026-07-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Open-source autonomous AI agent released February 2026 by Nous Research; runs as a persistent daemon with cross-session memory and a 'YOLO mode' that removes human-approval prompts before executing dangerous commands. Observed run unattended to automate host enumeration and privilege-escalation triage against Thailand's Ministry of Finance (Hunt.io, 2026-07-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:hermes-ai-agent","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Ahermes-ai-agent/"}],"id":"tool--4ba4f83a-728f-54e9-a4ed-3366c5496e37","labels":["tool"],"modified":"2026-08-28T06:15:00.000Z","name":"Hermes AI agent","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-25T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Previously-unreported Go-based cross-platform (Windows/Linux) implant providing persistence (Registry Run key + scheduled task on Windows, cron on Linux) with HTTPS C2 disguised as static JavaScript-asset requests and AES-256-GCM-encrypted payloads, plus built-in kill-dates and working-hours scheduling. Recovered alongside Hermes AI-agent tooling targeting Thailand's Ministry of Finance (Hunt.io, 2026-07-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:hades-implant","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Ahades-implant/"}],"id":"tool--b8d7026d-bf98-542c-b8fa-0ab169e72ea1","labels":["tool"],"modified":"2026-08-09T23:45:00.000Z","name":"Hades","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-25T04:38:26.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-25/ta458-roundpress-webmail-zero-days-sogo-cve-2026-8496/"}],"id":"relationship--3f69b8dd-e966-5d53-8b7e-6fb963a27cf7","modified":"2026-07-25T04:38:26.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--a0063de9-82c1-587d-a80a-586d22b2d890","spec_version":"2.1","target_ref":"malware--a2d42efb-6308-5210-be0a-182334fec27c","type":"relationship"},{"created":"2026-07-25T04:38:26.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-25/thailand-mof-hermes-ai-agent-post-exploitation/"}],"id":"relationship--472b4863-a825-5428-bfc6-597963a236de","modified":"2026-07-25T04:38:26.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"incident--1459b539-c354-56d6-aa94-4cb6d40994d3","spec_version":"2.1","target_ref":"tool--4ba4f83a-728f-54e9-a4ed-3366c5496e37","type":"relationship"},{"created":"2026-07-25T04:38:26.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-25/thailand-mof-hermes-ai-agent-post-exploitation/"}],"id":"relationship--f00f80ff-825b-530e-99da-56f36889337e","modified":"2026-07-25T04:38:26.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"incident--1459b539-c354-56d6-aa94-4cb6d40994d3","spec_version":"2.1","target_ref":"tool--b8d7026d-bf98-542c-b8fa-0ab169e72ea1","type":"relationship"},{"created":"2026-07-26T14:02:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"BleepingComputer names SectopRAT as the payload the FakeAgent installer delivers.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-26/fakeagent-claude-artifact-lure-sectoprat-dll-sideloading/"}],"id":"relationship--adbd3a5f-483b-5273-86f4-ff957a1b2c39","modified":"2026-07-26T14:02:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--6de6c8db-7545-5dcf-a3be-f44365ce5572","spec_version":"2.1","target_ref":"malware--6d39d787-b3aa-5207-892d-af7af14d7127","type":"relationship"},{"created":"2026-07-26T14:15:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Zscaler describes BINDCLOAK as the final implant of the same three-stage chain.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-26/teleshim-bindcloak-volume-serial-keying-government-espionage/"}],"id":"relationship--01df502f-8d60-5505-aeb6-81be684964d7","modified":"2026-07-26T14:15:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"malware--de558496-1f17-5afc-b718-fda750334653","spec_version":"2.1","target_ref":"malware--c5fa24d9-fc94-525b-9f4d-20eddbdc42a8","type":"relationship"},{"created":"2026-07-26T14:15:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Zscaler ThreatLabz assesses with high confidence that BINDCLOAK is a variant of OctLurk — an assessment of family relationship, carried at the confidence the source states and never upgraded to an identity claim","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-26/teleshim-bindcloak-volume-serial-keying-government-espionage/"}],"id":"relationship--607993db-10e1-510b-92c9-3f78fec204e5","modified":"2026-07-26T14:15:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"variant-of","source_ref":"malware--c5fa24d9-fc94-525b-9f4d-20eddbdc42a8","spec_version":"2.1","target_ref":"malware--b3bcfdc8-a510-5851-8383-547613484e49","type":"relationship"},{"created":"2026-07-26T14:15:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Zscaler describes MIXEDKEY as the reflective loader stage of the same three-stage chain.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-26/teleshim-bindcloak-volume-serial-keying-government-espionage/"}],"id":"relationship--79d56c29-6014-548c-8fbd-7db203eae3ac","modified":"2026-07-26T14:15:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"malware--de558496-1f17-5afc-b718-fda750334653","spec_version":"2.1","target_ref":"tool--919fab4b-52fc-5430-8235-0620c8bf827f","type":"relationship"},{"aliases":["Windchill PDMLink module serious data leak campaign"],"created":"2026-07-27T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Data-theft double-extortion campaign against internet-exposed PTC Windchill and FlexPLM deployments, chaining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with the Windchill login-servlet deserialization flaw CVE-2026-12569 for unauthenticated code execution, JSP web shells and staged exfiltration of engineering and product-design data. From 2026-07-20 Ransom-ISAC observed a mass extortion-email phase sending messages subject-lined \"Windchill PDMLink module serious data leak\" from compromised accounts to hundreds of staff per victim organisation; as of 2026-07-22 no victims had been listed on the leak site.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:clop-windchill-flexplm-extortion-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aclop-windchill-flexplm-extortion-2026/"}],"id":"campaign--5ba76d36-5733-5fc2-b22a-cefe6af661f7","labels":["campaign"],"modified":"2026-08-24T09:15:00.000Z","name":"Cl0p PTC Windchill / FlexPLM extortion campaign (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-07-27T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Hacktivist handle credited by Cyberattaque.org with publishing personal dossiers on French national and European political figures on 2026-07-25 in protest at the EU \"Chat Control\" communications-scanning file. Sources differ on scope: ZATAZ puts the number of targeted figures at 24, while Cyberattaque.org describes a second group as well and states that no total is specified. ZATAZ, reporting the same operation without naming the handle, describes the actor as previously having published around ten leaks concerning French companies and assesses the dossiers as recomposed from earlier unrelated breaches rather than any fresh intrusion.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:cybernox","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Acybernox/"}],"id":"intrusion-set--562d468e-d505-5df2-88f4-171f344ea933","labels":["actor"],"modified":"2026-07-27T04:33:46.000Z","name":"Cybernox","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Clop","Graceful Spider","Chubby Scorpius","FIN11","Lace Tempest"],"created":"2026-07-27T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated data-theft extortion group with a multi-year pattern of exploiting a zero-day in a widely deployed enterprise application, exfiltrating at scale, and only then running a mass extortion wave — previously against Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo and Oracle E-Business Suite. Ransom-ISAC, eCrime.ch and DEFUSED attribute the 2026-07 PTC Windchill / FlexPLM extortion campaign to Cl0p affiliate activity; ReliaQuest, quoted by BleepingComputer on 2026-07-24, holds the actor unconfirmed and rests on tradecraft overlap with prior Cl0p campaigns.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:clop","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aclop/"}],"id":"intrusion-set--fe2066f5-5c49-5bbd-aa20-ca2c71c0a557","labels":["actor"],"modified":"2026-08-24T09:15:00.000Z","name":"Cl0p","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Windows remote-access trojan sold as malware-as-a-service through a dedicated storefront and Telegram channel, whose hidden-VNC module opens Chrome, Edge or Firefox on a separate invisible Windows desktop using the victim's existing browser profile, giving the operator live authenticated sessions that originate from the victim's own device. Delivered through a five-stage chain: an obfuscated JScript launcher, an AutoIt interpreter that XOR-decrypts a loader and injects it into charmap.exe, and repeating-XOR plus ChaCha20 layers before the final payload, which speaks a custom protocol over raw TCP. Analysed by BlackFog (2026-07-27); no relationship to the Medusa or MedusaLocker ransomware families is claimed by any cited source.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:medusahvnc","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Amedusahvnc/"}],"id":"tool--a759132a-a316-555b-a7b5-ce2b4c7f08db","labels":["tool"],"modified":"2026-08-02T23:57:30.000Z","name":"MedusaHVNC","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"IoT botnet family tracked jointly by CNCERT and QiAnXin XLab since Q1 2026, exceeding 200,000 bots and evolved from the jackskid and fbot malware lineages. It spreads through brute-forced weak Telnet/SSH credentials and known IoT remote-code-execution flaws (XLab names thirteen identifiers and presents them as only part of the set), resolves its command-and-control addressing through Ethereum ENS and Solana SNS name records with the real IPv4 address concealed inside a decoy IPv6-formatted string, and since late June 2026 fields a DDoS-less variant that uses UPnP to open roughly 155 port-forwarding rules on the local gateway and operate the infected device as a relay/proxy node in a mesh built from other victims (QiAnXin XLab / CNCERT, 2026-07-25).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:dysphoria-botnet","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Adysphoria-botnet/"}],"id":"tool--bbb6a8c7-21fc-5087-8342-8b611a4563fd","labels":["tool"],"modified":"2026-07-28T04:53:00.000Z","name":"Dysphoria","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Cyberattack confirmed on 2026-07-28 by Universitatea de Vest 'Vasile Goldis' din Arad, a Romanian public university, as having affected its IT infrastructure and the digital services used in academic and administrative work. The university notified the national cybersecurity directorate DNSC, the data-protection authority ANSPDCP and organised-crime prosecutors DIICOT, and reported technical teams working with external specialists on gradual restoration, while declining to specify which systems were unavailable, whether personal data was accessed or exfiltrated, when the attack occurred, or who was responsible. The Qilin ransomware operation separately listed the university on its leak site with an estimated attack date of 2026-07-26; that claim rests solely on the leak-site listing and is mentioned by none of the Romanian reporting (Aradon.ro, Radio Romania, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:uvvg-arad-cyberattack-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Auvvg-arad-cyberattack-2026-07/"}],"id":"incident--028c7e78-08f7-573c-99d1-a53195e2cada","labels":["incident"],"modified":"2026-08-02T23:57:00.000Z","name":"UVVG Arad cyberattack (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Coordinated cyberattack over 26-27 July 2026 that Minnesota IT Services announced had disrupted water and wastewater utilities in more than 30 communities, affecting programmable logic controllers and cellular-connected equipment at water towers and lift stations. Plymouth disconnected affected cellular equipment from its network; Braham's water plant went offline and the city briefly asked residents to minimise use on tank level; South St. Paul reported impact to certain automated controls. No source reports impact to drinking-water safety or treatment quality. No named authority has attributed the attack to any actor — the affected city says unknown actors, and the Center for Internet Security states it has not been attributed and that it is unclear whether the internet-exposed PLC vector of joint advisory AA26-097A was involved (StateScoop, Cybersecurity Dive, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:minnesota-water-utilities-coordinated-cyberattack-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aminnesota-water-utilities-coordinated-cyberattack-2026-07/"}],"id":"incident--419be099-265b-52bb-a138-7390bb326486","labels":["incident"],"modified":"2026-08-16T23:59:00.000Z","name":"Minnesota coordinated water-utility OT cyberattack (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated intrusion cluster tracked by Sophos X-Ops, running Microsoft Teams voice-phishing against North American organisations between February and June 2026 by impersonating IT helpdesk personas from its own IT-themed domains registered under the .top TLD rather than spoofing onmicrosoft.com tenants. Talks victims into a remote-support session (Quick Assist initially, the less-commonly-blocklisted RemSupp by preference from April 2026), enables RDP via msconfig service reconfiguration, and runs Golang implants that embed CA certificates and complete TLS only against C2 servers presenting a matching issuer. At least three compromises ended in Chaos ransomware, one within 17 hours of initial access. Sophos assesses financial motivation with high confidence but states there is insufficient evidence for actor attribution, and explicitly found no evidence linking the cluster to MuddyWater (Sophos X-Ops, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:stac4749","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Astac4749/"}],"id":"intrusion-set--1bfc9a3a-8a19-5c03-9ed0-87c6b0f3c95d","labels":["actor"],"modified":"2026-07-29T05:35:00.000Z","name":"STAC4749","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Storm-2603"],"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware operation, tracked by Microsoft as Storm-2603, observed by Cisco Talos Incident Response deploying an installer for the Zoho Assist Unattended Agent — an RMM capability allowing administrative remote control of an endpoint with no user logged in — a tool Talos states it had not previously seen attributed to the group. The engagement in question did not reach encryption but Talos assessed the activity consistent with a Warlock attack it observed in May 2026 that did (Cisco Talos IR, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:warlock-storm-2603","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Awarlock-storm-2603/"}],"id":"intrusion-set--c3bd90ec-6689-508b-8a62-3e17e6ab5453","labels":["actor"],"modified":"2026-07-29T05:55:00.000Z","name":"Warlock","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Cisco Talos designation for the operator of a QR-code phishing campaign against primarily Australian organisations, running from April 2026 and still ongoing in late June 2026. Delivers auto-generated, victim-tailored PDF documents carrying embedded QR codes that route to Microsoft 365 credential-harvesting pages, then creates email inbox rules to hide the compromise, stages follow-on documents on SharePoint, and propagates by phishing each newly compromised mailbox's own contact list. Talos assesses with high confidence the operation will continue on that self-expanding model (Cisco Talos IR, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uat-11764","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auat-11764/"}],"id":"intrusion-set--d3009e21-f804-57d6-a8b4-9177fcff388a","labels":["actor"],"modified":"2026-07-29T05:55:00.000Z","name":"UAT-11764","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service operation active for roughly a year with minimal public reporting on its operators, encrypting with the .SINOBI extension. In Cisco Talos Incident Response's first engagement with the group (April 2026) the operators used a trojanized MeshAgent binary — the agent component of the open-source MeshCentral remote-management platform — installed as a SYSTEM-level auto-start service as their primary command-and-control mechanism over encrypted WebSocket, a tactic Talos states had not previously been associated with the group; they held access about three days, cracked a weak service-account password obtained from ntds.dit, moved laterally over RDP and WinRM, and deployed ransomware domain-wide through a malicious Group Policy Object logon script with rclone staging exfiltration (Cisco Talos IR, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:sinobi-ransomware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Asinobi-ransomware/"}],"id":"intrusion-set--eef4667a-3a17-5578-b793-f87ac65f098a","labels":["actor"],"modified":"2026-07-29T05:55:00.000Z","name":"Sinobi","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"WebSocket tunneling tool Kaspersky states was developed and used by Mirage Kitten, first identified April 2026. Implements a simpler control surface than the related BridgeHead — an OPEN command to create a proxy/tunnel session and a DNS command for hostname resolution — with an embedded configuration block carrying C2 host, port, retry/timeout value, an SSL flag and a likely implant identifier (Kaspersky Securelist, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:arcbridge-tunneler","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aarcbridge-tunneler/"}],"id":"tool--0a92ad8d-5102-53d2-8062-6891c4d45f2a","labels":["tool"],"modified":"2026-07-29T05:30:00.000Z","name":"ArcBridge","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Windows backdoor attributed by Kaspersky to Mirage Kitten (tracked in this registry as Screening Serpens) on code and behavioural similarity to the group's historical implants. Masquerades as SspiCli.dll and loads under a legitimate AppVShNotify.exe binary through a DLL search-order hijack of the delay-load that RPCRT4.dll performs when it invokes an authenticated RPC API, forwarding expected exports to the genuine DLL so the host process keeps functioning. Beacons over HTTPS, tokenizes C2 responses with a custom delimiter, and dispatches 16 numeric commands including host and network reconnaissance, file operations, screenshot capture, DLL loading, process listing and termination, and collection of the Windows domain-join diagnostic log. Kaspersky notes its command dispatch resembles TWOSTROKE, an implant previously documented as the same actor's (Kaspersky Securelist, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:nightledger-backdoor","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Anightledger-backdoor/"}],"id":"tool--7f5b6f7a-e980-5be7-9de3-7ca583ae588a","labels":["tool"],"modified":"2026-08-02T23:57:30.000Z","name":"NightLedger","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mirage Kitten WebSocket SOCKS5 tunneling proxy engineered to operate through defended networks: on an HTTP 407 proxy-authentication challenge it queries the supported auth schemes, selects Negotiate in preference to NTLM, supplies null credentials so Windows fills in the logged-in user's single-sign-on context, and retries, falling back to exponential connection retry capped at 60 seconds. Once connected the operator drives all tunnel connections server-side and the implant only forwards, making the victim host a relay whose traffic appears to originate inside its own network. Execution is gated on a hardcoded 3-character substring of the lowercased Windows username, so a sample exits silently anywhere but its intended host. Kaspersky states its proxy-traversal logic closely mirrors a backdoor it tracks internally as Retrograde, which it says overlaps with tooling publicly reported as MiniFast/MiniUpdate (Kaspersky Securelist, 2026-07-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:bridgehead-tunneler","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Abridgehead-tunneler/"}],"id":"tool--91d28237-1a66-5cbe-b428-0c285dbb48c5","labels":["tool"],"modified":"2026-08-02T23:57:30.000Z","name":"BridgeHead","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-29T05:30:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky attributes NightLedger to the group on code and behavioural similarity to its historical implants","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers/"}],"id":"relationship--6b7c6b5a-749c-5bfd-9090-f7ff19938819","modified":"2026-07-29T05:30:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--4cb4e12e-405b-5791-a842-345851f38bc4","spec_version":"2.1","target_ref":"tool--7f5b6f7a-e980-5be7-9de3-7ca583ae588a","type":"relationship"},{"created":"2026-07-29T05:30:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers/"}],"id":"relationship--a7dbf081-5618-5d50-89f7-4490553f40e7","modified":"2026-07-29T05:30:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--4cb4e12e-405b-5791-a842-345851f38bc4","spec_version":"2.1","target_ref":"tool--91d28237-1a66-5cbe-b428-0c285dbb48c5","type":"relationship"},{"created":"2026-07-29T05:30:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky: another WebSocket tunneling tool developed and used by the group, first identified April 2026","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-29/mirage-kitten-nightledger-proxy-aware-websocket-tunnelers/"}],"id":"relationship--e28c6aef-e12d-50a1-9b13-ffa2a60a3698","modified":"2026-07-29T05:30:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--4cb4e12e-405b-5791-a842-345851f38bc4","spec_version":"2.1","target_ref":"tool--0a92ad8d-5102-53d2-8062-6891c4d45f2a","type":"relationship"},{"created":"2026-07-29T05:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Sophos states at least three STAC4749 compromises led to Chaos ransomware deployment, but assesses only that the operators either deployed it directly OR coordinated with affiliates — the untyped edge is deliberate, since collaborates-with would assert the second branch of a disjunction the source leaves open","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-29/stac4749-teams-vishing-certificate-pinned-golang-chaos/"}],"id":"relationship--f82855a4-311d-51cb-8da4-2a5e5846aaee","modified":"2026-07-29T05:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--1bfc9a3a-8a19-5c03-9ed0-87c6b0f3c95d","spec_version":"2.1","target_ref":"intrusion-set--9ec61694-e9b0-5cf3-b13d-34410b93fc26","type":"relationship"},{"aliases":["STARDUST CHOLLIMA","BlueNoroff","CageyChameleon","Alluring Pisces","UNC1069","MIDNIGHT NEPTUNE"],"created":"2026-07-30T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DPRK-linked cluster that Amazon Threat Intelligence assesses with medium confidence — on the basis of command-and-control indicators and TTPs — to be behind the September 2025 compromises of the npm packages debug and chalk and the March 2026 compromise of axios, in each case obtaining publishing access by socially engineering a trusted package maintainer rather than exploiting a registry flaw. Amazon further assesses that a small March 2025 compromise of a package named typo-crypto — into which the actor committed a trojanised file that detonated only on a specific input value and then fetched an operating-system-appropriate second stage — was a testing ground for those later, higher-impact supply-chain operations. The attribution is Amazon's own medium-confidence assessment, independently corroborated on 2026-07-30 when Google's threat-intelligence group separately credited the axios compromise to the cluster it tracks as UNC1069 — already an alias on this record — under its new cryptonym MIDNIGHT NEPTUNE; the alias UNC1069 is sourced to CyberScoop's reporting on Amazon's media roundtable rather than to Amazon's own publication (AWS Security Blog, CyberScoop, 2026-07-29; Google Cloud/GTIG, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:sapphire-sleet","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Asapphire-sleet/"}],"id":"intrusion-set--e5dbd904-d76e-5265-b599-87733af3e889","labels":["actor","north-korea-nexus"],"modified":"2026-08-23T23:50:00.000Z","name":"Sapphire Sleet","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Breach confirmed by the UK Department for Education of two public-facing portals, the DfE Help Desk Self-Service Portal and the Turing Scheme Portal, exposing customer-service contact details of parents, officials, school leaders and university staff, alongside a separately affected Police National Legal Database holding 135,000 records naming officers, their forces and work email addresses. DfE clarified that the claimed figure of more than 600,000 pieces of data refers to lines of data rather than the count of individuals affected, and assessed the risk to individuals as not high; the NCSC is supporting the response, the Home Office declined to comment on the police-database element, and no ransom was paid (The Record, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:uk-dfe-exfilsquad-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Auk-dfe-exfilsquad-breach-2026-07/"}],"id":"incident--74f19b6c-d1c8-5d26-9f09-ab51a826c575","labels":["incident"],"modified":"2026-08-16T23:59:00.000Z","name":"UK Department for Education portal and Police National Legal Database breach (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Intrusion confirmed by Brinks Home as detected on 2026-07-20, with the company stating its alarm monitoring and system functionality were unaffected and its incident FAQ saying it has not yet confirmed exactly what information was involved or whose. ShinyHunters claims the breach began on 13 July through a Microsoft Entra voice-phishing call and asserts specific data volumes; BleepingComputer reports two unreconciled Salesforce record figures and states it has not reviewed the data and could not verify the actor's claims (BleepingComputer, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:brinks-home-shinyhunters-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Abrinks-home-shinyhunters-breach-2026-07/"}],"id":"incident--ae3922c7-ab57-5983-a63d-ec6c10ac8b28","labels":["incident"],"modified":"2026-08-02T23:59:15.000Z","name":"Brinks Home breach (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"A misconfiguration at Anthropic's evaluation partner left cybersecurity-benchmark machines with live internet access despite the models being told their environment was an offline simulation. Across three incidents spanning six of 141,006 reviewed runs, and dating back to April 2026, models compromised real third-party infrastructure: reaching a production database of several hundred rows at a company sharing a name with a fictional target, publishing a malicious PyPI package that was live for roughly an hour and ran on 15 real systems including a security vendor's malware scanner where it exfiltrated that vendor's credentials, and scanning roughly 9,000 hosts before compromising one internet-facing application. The models ran with model-specific safety training but without the additional safety classifiers applied to production systems (Anthropic, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:anthropic-cybersecurity-eval-escape-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aanthropic-cybersecurity-eval-escape-2026-07/"}],"id":"incident--fd005f6f-116d-57fa-8734-819a4b885aed","labels":["incident"],"modified":"2026-08-28T04:50:00.000Z","name":"Anthropic cybersecurity-evaluation environment escape (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Bearlyfy","Labubu","Laboo.boo"],"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated extortion group targeting Russian organisations, primarily in manufacturing, which previously relied on third-party encryptors before fielding its own. Runs neither double extortion nor a leak site, and Kaspersky found no evidence of data exfiltration in the intrusion it analysed. Kaspersky sources the group's link to the GenieLocker ransomware to Russian-language open-source reporting rather than to its own first-party attribution (Kaspersky, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:toy-ghouls","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Atoy-ghouls/"}],"id":"intrusion-set--207634e3-5f87-53be-9f9d-d97d1a68a785","labels":["actor"],"modified":"2026-08-02T23:57:30.000Z","name":"Toy Ghouls","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Data-exfiltration-only extortion brand whose Tor leak site first appeared on 2026-07-26 with 15 named victims across government, education, finance and technology. SOCRadar found no aliases, predecessor operations or rebranding history and assesses that the listings may involve reused data or fabricated allegations, with fabrication currently appearing more likely; one listing, the UK Department for Education, corresponds to an independently confirmed breach (SOCRadar, 2026-07-28; The Record, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:exfilsquad","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aexfilsquad/"}],"id":"intrusion-set--8886eebe-4658-587e-b26e-5d918ac240f2","labels":["actor"],"modified":"2026-08-16T23:59:00.000Z","name":"ExfilSquad","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["knaithe","KnYuan"],"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Chinese-speaking, Zhuhai-based exploit operator, self-described binary-security researcher and maintainer of an automated vulnerability-alerting pipeline. Ran an autonomous offensive stack pairing DeepSeek with the open-source Hermes Agent against seven CVEs and more than 460 targets; Unit 42 reports every autonomous exploitation attempt failed on target-side configuration, while the confirmed impact — all of it recorded by Unit 42 as manual rather than autonomous — spans four CVEs: data exfiltration from three Citrix NetScaler targets (CVE-2026-3055), command execution confirmed on 11 Marimo Notebook endpoints (CVE-2026-39987), Java deserialization reverse-shell attempts against nine Apache Tomcat servers (CVE-2026-34486) and reverse-shell callbacks from three IKE VPN endpoints (CVE-2026-33824), including multi-day targeting of a Malaysian government entity (Unit 42, 2026-07-30; scope corrected against the primary by the 2026-08-02 quality audit).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:knaithe-knyuan","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aknaithe-knyuan/"}],"id":"intrusion-set--94e5a8f3-e6cd-54bd-93ad-c0c1720297f1","labels":["actor","china-nexus"],"modified":"2026-08-28T06:15:00.000Z","name":"knaithe / KnYuan","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Custom Windows and Linux/ESXi ransomware active since March 2026. Refuses to execute unless its first command-line argument hashes to a value compiled into the binary, which Kaspersky assesses is intended to defeat sandboxes and automated analysis and to prevent unauthorised reuse by other actors; runs a watchdog thread polling for debuggers every 500 milliseconds and recomputing a checksum of its own code section on each pass; and deliberately writes no ransom note, which Kaspersky assesses is an attempt to avoid detection triggered by the creation of multiple readme files. The ESXi build stops running virtual machines before encrypting their disks (Kaspersky, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:genielocker","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Agenielocker/"}],"id":"malware--60e842df-f28c-5cbf-8482-39db7f26aa89","is_family":true,"labels":["malware"],"modified":"2026-08-02T23:57:30.000Z","name":"GenieLocker","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Plugin-based Windows backdoor deployed against government, healthcare, research, law-enforcement and education organisations in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan and Syria since at least January 2025. Delivered by a malicious loader DLL invoked through a repointed Windows service ServiceMain value, which decrypts its payload with a hard-coded key plus a second key derived from the victim machine's C: drive serial number and loads it reflectively into memory. Pulls File Manager, Command Shell and Interaction Manager plugins directly from its command server into memory (Kaspersky GReAT, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:octlurk","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aoctlurk/"}],"id":"malware--b3bcfdc8-a510-5851-8383-547613484e49","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-10T04:46:00.000Z","name":"OctLurk","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Sibling backdoor to OctLurk sharing its loader architecture and Central Asian and Syrian government victimology. Some victims additionally received a long-established second-stage implant with a history of Chinese-speaking-actor use, which supports Kaspersky's medium-confidence attribution language; operators were observed mounting shares with harvested administrator credentials and archiving documents before exfiltration (Kaspersky GReAT, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:silklurk","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Asilklurk/"}],"id":"malware--e0f68063-df22-5dc5-8d73-c5457d417afb","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-02T23:57:30.000Z","name":"SilkLurk","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Network-proxy utility architecturally similar to the OctLurk backdoor but not itself a backdoor, deployed alongside OctLurk and SilkLurk. Kaspersky reports several of its command-server addresses also appear in a Kazakhstani government report on a separately tracked Linux implant, indicating shared infrastructure across campaigns without establishing whether they ran concurrently (Kaspersky GReAT, 2026-07-30).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:lurkproxy","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Alurkproxy/"}],"id":"tool--90369382-61f1-56f6-a9e6-50592f4fd1b2","labels":["china-nexus","tool"],"modified":"2026-07-31T04:09:14.000Z","name":"LurkProxy","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-31T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"JavaScript browser implant delivered by TA488/LAUNDRY BEAR through the Exchange Outlook Web Access stored-XSS flaw CVE-2026-42897. Executes entirely in the OWA reading pane with no host-file footprint, harvests browser-autofilled OWA credentials via invisible input elements, steals OAuth tokens through mailbox add-ins holding read-write mailbox permission, persists in browser localStorage under a legitimate OWA settings key and in the offline message cache, and grants the Exchange 'Default' alias Owner permission on mail folders for server-side persistence that Proofpoint states survives credential rotation and device re-imaging. Proofpoint assesses it an evolution of the same actor's Zimbra implant (Proofpoint, 2026-07-29).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:owareaper","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aowareaper/"}],"id":"tool--a70ccea2-6a78-5a8e-a506-34dca0f0b143","labels":["russia-nexus","tool"],"modified":"2026-08-02T23:46:00.000Z","name":"OWAReaper","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-07-31T04:09:14.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky assesses with medium confidence that the same unattributed Chinese-speaking actor is behind both, on shared loader architecture and overlapping victims. (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-31/octlurk-silklurk-service-dll-plugin-backdoors-government/"}],"id":"relationship--21d6111d-5fc1-5e41-9212-47490d33ed19","modified":"2026-07-31T04:09:14.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"malware--b3bcfdc8-a510-5851-8383-547613484e49","spec_version":"2.1","target_ref":"malware--e0f68063-df22-5dc5-8d73-c5457d417afb","type":"relationship"},{"created":"2026-07-31T04:09:14.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky describes GenieLocker as an apparently custom design upgrading the group's toolkit.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-31/genielocker-toy-ghouls-no-ransom-note-esxi-ransomware/"}],"id":"relationship--24dde4b1-2935-50f6-a6eb-3b4a8991658e","modified":"2026-07-31T04:09:14.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--207634e3-5f87-53be-9f9d-d97d1a68a785","spec_version":"2.1","target_ref":"malware--60e842df-f28c-5cbf-8482-39db7f26aa89","type":"relationship"},{"created":"2026-07-31T04:09:14.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The Record reports the breach was claimed by extortionists calling themselves ExfilSquad.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-31/exfilsquad-uk-department-for-education-pnld-breach/"}],"id":"relationship--2928f9ae-7d4a-5b5c-9a07-8c3a30ec4fc3","modified":"2026-07-31T04:09:14.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--74f19b6c-d1c8-5d26-9f09-ab51a826c575","spec_version":"2.1","target_ref":"intrusion-set--8886eebe-4658-587e-b26e-5d918ac240f2","type":"relationship"},{"created":"2026-07-31T04:09:14.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unit 42 states the actor primarily used the Hermes Agent with DeepSeek as its reasoning agent for the attack phase of the campaign.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-31/unit42-autonomous-deepseek-hermes-netscaler-cve-2026-3055/"}],"id":"relationship--4442763e-7181-5328-a179-5a44c55b2c8f","modified":"2026-07-31T04:09:14.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--94e5a8f3-e6cd-54bd-93ad-c0c1720297f1","spec_version":"2.1","target_ref":"tool--4ba4f83a-728f-54e9-a4ed-3366c5496e37","type":"relationship"},{"created":"2026-07-31T04:09:14.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Anthropic states its review was prompted by the other vendor's disclosure of a comparable evaluation-environment escape and cites it directly.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-07-31/anthropic-cyber-eval-environment-escape-pypi-package/"}],"id":"relationship--813547dc-d62f-5f21-a866-1f2ba57e3c0c","modified":"2026-07-31T04:09:14.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--fd005f6f-116d-57fa-8734-819a4b885aed","spec_version":"2.1","target_ref":"incident--e7ddab17-aa1f-5045-a235-ad20bcf166af","type":"relationship"},{"created":"2026-08-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Operation active since early May 2026 in which Storm-2945 manipulates DNS and HTTP traffic on hospitality-sector networks served by captive portals worldwide, redirecting connecting users through actor-controlled infrastructure and answering automatic browser connectivity checks with ClickFix-style fake browser and operating-system update lures that deliver the CornFlake RAT and the ChocoShell stealer. Since 16 July 2026 a portion of the landing pages also drive Entra ID device-code phishing. Microsoft's investigation into how the captive-portal networks were initially compromised remains open, but it notes commonalities in equipment and management systems suggesting possible access to shared services within parts of the captive-portal ecosystem (Microsoft Threat Intelligence, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:captivecrunch-storm-2945-hospitality-wifi","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Acaptivecrunch-storm-2945-hospitality-wifi/"}],"id":"campaign--9db7e602-8c2d-5c5b-bc03-c5496a996c33","labels":["campaign","russia-nexus"],"modified":"2026-08-23T05:12:00.000Z","name":"CaptiveCrunch","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Compromise of a French Ministry of Education professional account overnight on 2026-07-25, used to reach the ministry's internal information system for managing agent training. Identity and professional data for every agent who has worked in a French académie since 2001 was present in the environment, with postal address, telephone number and social-security number (NIR) for a subset; the ministry states the system held no passwords, banking details or pupil data, and that it is not established that every record was actually viewed or downloaded. External access was suspended on 26 July, ANSSI and the CNIL were notified and a criminal complaint filed. Third confirmed Éducation nationale data incident of 2026, after the March COMPAS breach of roughly 243,000 agent and trainee records and an April incident exposing pupil data through an ÉduConnect-linked service (Cyberattaque.org, franceinfo, Clubic, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:france-education-nationale-agent-training-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afrance-education-nationale-agent-training-breach-2026-07/"}],"id":"incident--2590bd26-f874-56c4-b32c-7a488e2588d0","labels":["incident"],"modified":"2026-08-02T23:56:00.000Z","name":"French Éducation nationale agent-training system breach (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["APT29","Cozy Bear","Nobelium","Cloaked Ursa","ICE RELIC"],"created":"2026-08-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Russia-based cyber-espionage actor attributed by the US and UK governments to the Foreign Intelligence Service of the Russian Federation (SVR), primarily targeting governments, diplomatic entities, NGOs and IT service providers in the US and Europe; known for compromise of valid accounts, abuse of OAuth applications for cloud lateral movement, and device-code phishing (Microsoft Threat Intelligence, 2026-07-31). Referenced in this pipeline's coverage since early 2026 via campaign and incident records; registered as its own actor entity on first dedicated coverage.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:midnight-blizzard","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Amidnight-blizzard/"}],"id":"intrusion-set--cd13b049-2e43-566b-a888-7d8472d2303c","labels":["actor","russia-nexus"],"modified":"2026-08-23T05:12:00.000Z","name":"Midnight Blizzard","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["UNC7005"],"created":"2026-08-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft-tracked cluster that Microsoft Threat Intelligence assesses to be an operational sub-cluster of Midnight Blizzard, on the basis of distinctive technical and operational overlaps including similarities to the Storm-2372 initial-access sub-cluster, Graph-based email exfiltration, social engineering over commercial messaging apps and shared victimology. Runs the CaptiveCrunch captive-portal hijacking operation and has conducted device-code and OAuth-code phishing leading to Entra device registration since February 2026 (Microsoft Threat Intelligence, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:storm-2945","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Astorm-2945/"}],"id":"intrusion-set--f79e9cd0-734e-575e-b107-9bf2e46e3d8b","labels":["actor","russia-nexus"],"modified":"2026-08-23T05:12:00.000Z","name":"Storm-2945","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["XCSSET v40"],"created":"2026-08-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Modular macOS malware family targeting Apple-ecosystem developers by infecting Xcode projects and Git repositories, so the payload executes when a developer builds an infected project locally. First documented by Trend Micro in 2020 with two further versions documented by Microsoft in 2025. Version 40, analysed by Unit 42 on 2026-07-31, keeps its core logic in memory and deletes its installation files, recompiles payloads polymorphically, and adds fileless persistence that stores a Base64 staging payload in a per-host macOS defaults preferences domain. It degrades platform defences by disabling the software-update configuration channel, terminating the cloud telemetry process, holding an exclusive file lock on the XProtect signature database, and resetting the TCC AppleEvents permission database to re-prompt a user who declines (Palo Alto Networks Unit 42, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:xcsset","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Axcsset/"}],"id":"malware--376a815f-9872-5829-8b49-49ebed60aa1b","is_family":true,"labels":["malware"],"modified":"2026-08-02T23:57:30.000Z","name":"XCSSET","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Storm-2945's primary persistent Windows implant, written in Go and delivered by the CaptiveCrunch captive-portal lures. Runs first in dropper mode behind a configurable fake progress window imitating Windows Update, a security scan or a redistributable installer, then registers as a Windows service masquerading as a cloud-sync utility. Establishes redundant persistence across service registration, Registry Run keys and scheduled tasks with a watchdog that restores anything defenders remove; command and control uses ephemeral ECDH P-256 key exchange with SHA-256 session-key derivation over a custom JSON protocol. Collection covers keylogging, clipboard, screenshots, microphone and webcam capture, removable media, browser credential theft and an eighteen-category host security-posture sweep (Microsoft Threat Intelligence, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:cornflake-go-rat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Acornflake-go-rat/"}],"id":"malware--4824ebf9-8bab-585b-b16a-8dce4cf74f86","is_family":true,"labels":["malware"],"modified":"2026-08-02T23:46:00.000Z","name":"CornFlake","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-01T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Storm-2945's in-memory PowerShell infostealer, deployed alongside CornFlake in the CaptiveCrunch operation for high-volume theft of browser session cookies, saved passwords, Microsoft 365 SSO tokens and Wi-Fi credentials. Disables AMSI via .NET reflection, performs a timing-based sandbox check, and escalates through three silent UAC-bypass techniques in ordered fallback before reverting to a visible prompt. Defeats Chrome App-Bound Encryption both by impersonating a SYSTEM token and by driving the browser's own DevTools Protocol, and collects Microsoft 365 and Azure AD access, refresh and Web Account Manager tokens from the Token Broker cache, enabling SSO session replay without browser cookies (Microsoft Threat Intelligence, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:chocoshell-powershell-stealer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Achocoshell-powershell-stealer/"}],"id":"tool--b12969ed-6f21-50f5-a835-15ebf1ea285f","labels":["tool"],"modified":"2026-08-02T23:46:00.000Z","name":"ChocoShell","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-01T04:24:59.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft attributes CaptiveCrunch to Storm-2945 despite TTP similarities to a separately-tracked DNS hijacking operation.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-01/captivecrunch-storm-2945-hospitality-captive-portal-rat/"}],"id":"relationship--4bdadbfa-d338-5787-b3a1-6b6b49594140","modified":"2026-08-01T04:24:59.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--9db7e602-8c2d-5c5b-bc03-c5496a996c33","spec_version":"2.1","target_ref":"intrusion-set--f79e9cd0-734e-575e-b107-9bf2e46e3d8b","type":"relationship"},{"created":"2026-08-01T04:24:59.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-01/captivecrunch-storm-2945-hospitality-captive-portal-rat/"}],"id":"relationship--bab42c87-2794-55c0-a78b-0f2998b5e736","modified":"2026-08-01T04:24:59.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--f79e9cd0-734e-575e-b107-9bf2e46e3d8b","spec_version":"2.1","target_ref":"malware--4824ebf9-8bab-585b-b16a-8dce4cf74f86","type":"relationship"},{"created":"2026-08-01T04:24:59.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-01/captivecrunch-storm-2945-hospitality-captive-portal-rat/"}],"id":"relationship--bc34a4eb-327e-5918-8088-54534a554e1f","modified":"2026-08-01T04:24:59.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--f79e9cd0-734e-575e-b107-9bf2e46e3d8b","spec_version":"2.1","target_ref":"tool--b12969ed-6f21-50f5-a835-15ebf1ea285f","type":"relationship"},{"created":"2026-08-01T04:24:59.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft assesses Storm-2945 is an operational sub-cluster of Midnight Blizzard; the vocabulary carries no parent/sub-cluster type, so the edge is typed as the generic fallback rather than upgraded to attribution or identity.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-01/captivecrunch-storm-2945-hospitality-captive-portal-rat/"}],"id":"relationship--f9a23555-35b2-54a5-a2f7-526d6698bf55","modified":"2026-08-01T04:24:59.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--f79e9cd0-734e-575e-b107-9bf2e46e3d8b","spec_version":"2.1","target_ref":"intrusion-set--cd13b049-2e43-566b-a888-7d8472d2303c","type":"relationship"},{"created":"2026-08-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malvertising campaign named by Huntress that compromised at least 29 organisations between 2026-07-21 and 2026-07-22. Sponsored search results for the Claude Desktop application linked to a genuine claude.ai URL whose destination was a public user-created artifact on the platform imitating the official download page, viewed roughly 7,100 times before removal, so the ad, the domain and the certificate all presented as legitimate before an onward redirect to attacker infrastructure served the installer. Execution runs through signed-binary side-loading — a repurposed JetBrains Chromium Embedded Framework helper loading a VMProtect-packed trojanised libcef.dll, with a second chain using an IBM SPSS binary and a compiled DirectX shader as its decryption routine — and delivers SectopRAT (Huntress, 2026-07-22; Help Net Security, 2026-07-23; BleepingComputer, 2026-07-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:fakeagent","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Afakeagent/"}],"id":"campaign--6de6c8db-7545-5dcf-a3be-f44365ce5572","labels":["campaign"],"modified":"2026-08-02T00:00:00.000Z","name":"FakeAgent","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mass theft from Coinkite COLDCARD hardware wallets whose seeds were generated by firmware that routed key generation to MicroPython's software PRNG instead of the intended STM32 hardware TRNG. The defect entered during the March 2021 libNgU migration because the guarding preprocessor directive tested whether MICROPY_HW_ENABLE_RNG was defined rather than whether its value was non-zero, and the two implementations shared a function signature so the build succeeded. Coinkite estimates the resulting effective search space at about 40 bits on Mk2/Mk3 (firmware 4.0.1 through 4.1.9) and about 72 bits on Mk4, Mk5 and Q. Exploitation was confirmed under way by 2026-07-30, when Block Engineering published its root-cause analysis citing active exploitation; no cited source dates its start. Galaxy Research estimated 1,367.05 BTC drained across 4,585 addresses by 2026-08-01 over three waves, all funds unspent. Coinkite assumes but does not establish that an adversary found the defect using AI review of its public firmware source (Coinkite, 2026-07-30; Block Engineering, 2026-07-30; Galaxy Research via CryptoTimes, 2026-08-01).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:coldcard-rng-fallback-seed-theft-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acoldcard-rng-fallback-seed-theft-2026/"}],"id":"incident--4231f2eb-906c-5600-9506-9055999ea511","labels":["incident"],"modified":"2026-08-09T23:45:00.000Z","name":"COLDCARD hardware-RNG fallback wallet-seed theft (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Compromise of the shared JavaScript tracking library trackpoint-async.js served by Copenhagen-headquartered ad-tech platform Adform from s2.adform.net and embedded across customer websites. Two obfuscated blocks appended to the legitimate library monitored the clipboard, hooked input value setters and intercepted copy, cut, paste and input events to substitute attacker-controlled Bitcoin, Ethereum and Tron wallet addresses, and rewrote addresses displayed on the page. Discovered by researcher Kevin Beaumont; Adform states it detected the activity on 2026-07-27, removed the code and reported it to the authorities, and identifies 27 July as the affected date, while Beaumont describes roughly a week of activity and the oldest archived sample dates to 2026-07-26. The sample carried no antivirus detections and Adform has published no indicators of compromise or attacker attribution (Adform, 2026-07-31; BleepingComputer, 2026-07-31; The Hacker News, 2026-08-01).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:adform-supply-chain-crypto-clipper-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aadform-supply-chain-crypto-clipper-2026-07/"}],"id":"incident--4f22b80f-3c69-5484-91c1-521bb2aca86f","labels":["incident"],"modified":"2026-08-02T23:56:00.000Z","name":"Adform trackpoint-async.js supply-chain crypto-clipper compromise (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Compromise of an administrator account on the eDRH candidate-and-company platform of the Chambre de commerce et d'industrie Nice Côte d'Azur, the French public-law chamber of commerce for the Alpes-Maritimes. On 2026-07-18 an unauthorised party used the account's legitimate export functions to generate several exports of registered candidate and company data, including name, email, telephone, date of birth, professional history, education level and account timestamps. The chamber has not disclosed the account-takeover vector, the duration of access, or the number of people affected (Cyberattaque.org, FrenchBreaches.com, 2026-07-31/2026-08-01).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:cci-nice-cote-dazur-edrh-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acci-nice-cote-dazur-edrh-breach-2026-07/"}],"id":"incident--e53d879a-3d25-5d1a-9f17-9ac5f7359ea9","labels":["incident"],"modified":"2026-08-02T23:56:00.000Z","name":"CCI Nice Côte d'Azur eDRH administrator-account export breach (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Information stealer and remote-access tool with hands-on-keyboard capability, delivered by the FakeAgent malvertising campaign through DLL side-loading under signed third-party binaries. Huntress documents plaintext strings referencing browser logins, cookies, autofills and credit cards, and command-and-control data stored in the Ethereum blockchain — the takedown-resistant technique known as EtherHiding (Huntress, 2026-07-22; BleepingComputer, 2026-07-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:sectoprat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Asectoprat/"}],"id":"malware--6d39d787-b3aa-5207-892d-af7af14d7127","is_family":true,"labels":["malware"],"modified":"2026-08-02T00:00:00.000Z","name":"SectopRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Final-stage implant of the TELESHIM / MIXEDKEY / BINDCLOAK espionage toolkit documented by Zscaler ThreatLabz against Middle East government entities. Environmentally keyed: it decrypts only with a key derived from the victim machine's volume serial number, so a captured sample will not execute in a sandbox or on an analyst workstation and a negative dynamic-analysis result is not evidence the file is benign (Zscaler ThreatLabz, 2026-07-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:bindcloak","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Abindcloak/"}],"id":"malware--c5fa24d9-fc94-525b-9f4d-20eddbdc42a8","is_family":true,"labels":["malware"],"modified":"2026-08-10T04:46:00.000Z","name":"BINDCLOAK","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"First-stage Windows backdoor in a three-stage espionage toolkit Zscaler ThreatLabz documented against government entities in the Middle East, attributed with moderate-to-high confidence to an actor operating out of East Asia on the basis of IP geolocation, system locale and operational hours. Delivered by an ISO carrying a legitimate ASUSTek executable (RegSchdTask.exe, staged as shimgen.exe) that side-loads a malicious AsTaskSched.dll, so first execution runs under a trusted vendor binary. Persists through scheduled tasks and abuses the Telegram Bot API for command-and-control so its egress resolves to a mainstream service; carries control-flow flattening, mixed boolean arithmetic and opaque predicates (Zscaler ThreatLabz, 2026-07-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:teleshim","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Ateleshim/"}],"id":"malware--de558496-1f17-5afc-b718-fda750334653","is_family":true,"labels":["malware"],"modified":"2026-08-10T04:46:00.000Z","name":"TELESHIM","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-02T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Reflective loader stage of the TELESHIM / MIXEDKEY / BINDCLOAK espionage toolkit documented by Zscaler ThreatLabz against Middle East government entities. Shares the chain's heavy obfuscation — control-flow flattening, mixed boolean arithmetic and opaque predicates — and loads the final BINDCLOAK implant into memory (Zscaler ThreatLabz, 2026-07-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:mixedkey","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Amixedkey/"}],"id":"tool--919fab4b-52fc-5430-8235-0620c8bf827f","labels":["tool"],"modified":"2026-08-10T04:46:00.000Z","name":"MIXEDKEY","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-03T05:05:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Microsoft Threat Intelligence reports Storm-1175 began deploying StormEncryptor on 2 August 2026","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-03/cve-2026-18577-n-able-n-central-auth-bypass-exploited/"}],"id":"relationship--5d319dbe-6026-5556-b375-95f77fd8c235","modified":"2026-08-03T05:05:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--2ad93169-3e66-500e-b969-7d8e0cd27d53","spec_version":"2.1","target_ref":"malware--96e9397f-f302-5162-bfcf-e9a72ea1e503","type":"relationship"},{"created":"2026-08-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unauthorised digital access overnight into 2026-07-30 to Liechtenstein's Verzeichnis wirtschaftlich berechtigter Personen (VwbP), the national beneficial-ownership register operated by the Amt fuer Justiz under the VwbPG implementing the EU 5th Anti-Money-Laundering Directive; copies of records for roughly 31,000 legal entities were taken. The government declared it a personal-data breach under GDPR Article 33, convened a crisis unit under Head of Government Brigitte Haas and Justice Minister Emanuel Schaedler, and progressively took the eMWST VAT portal, the Lides reporting platform, the central account register and the Intax tax system offline as precautions. First forensic findings describe a targeted attack on the register with no attacks detected on other systems; no initial-access vector, actor or ransom demand had been disclosed (Regierung des Fuerstentums Liechtenstein, 2026-08-02 / 2026-08-03).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:liechtenstein-vwbp-register-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aliechtenstein-vwbp-register-breach-2026-07/"}],"id":"incident--e09b9455-9bc7-506b-b184-a711c8bc14fd","labels":["incident"],"modified":"2026-08-09T23:45:00.000Z","name":"Liechtenstein VwbP beneficial-ownership register breach (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated adversary tracked by CrowdStrike, reported in the 2026 Threat Hunting Report to have compromised more than 300 software dependencies in a single day, harvested credentials and pivoted into cloud environments as part of the 2026 open-source supply-chain wave (CrowdStrike Counter Adversary Operations, 2026-08-03).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:altered-spider","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aaltered-spider/"}],"id":"intrusion-set--137c55d1-4215-50fa-9674-3458516538eb","labels":["actor"],"modified":"2026-08-04T04:50:00.000Z","name":"ALTERED SPIDER","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-nexus adversary tracked by CrowdStrike, named in the 2026 Threat Hunting Report as having launched deliberate attacks within 24 hours of the public disclosure of a critical web-application vulnerability during H1 2026 (CrowdStrike Counter Adversary Operations, 2026-08-03).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:vault-panda","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Avault-panda/"}],"id":"intrusion-set--2917ae2e-72e7-522d-a78a-047f767a2e4c","labels":["actor","china-nexus"],"modified":"2026-08-04T04:50:00.000Z","name":"VAULT PANDA","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Belarus-nexus adversary tracked by CrowdStrike. Its exploitation of the Linux local privilege-escalation flaw CVE-2026-31431 was detected by CrowdStrike OverWatch just over 20 hours after the vulnerability's public disclosure on 2026-04-29, making it one of the fastest documented nation-state-nexus turnarounds on a public proof-of-concept (CrowdStrike Counter Adversary Operations, 2026-08-03).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:umbral-bison","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aumbral-bison/"}],"id":"intrusion-set--5e490b8a-5cc8-50a3-bfbb-0fb118487787","labels":["actor"],"modified":"2026-08-04T04:50:00.000Z","name":"UMBRAL BISON","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-04T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-nexus adversary tracked by CrowdStrike, named alongside VAULT PANDA in the 2026 Threat Hunting Report as having launched deliberate attacks within 24 hours of the public disclosure of a critical web-application vulnerability during H1 2026 (CrowdStrike Counter Adversary Operations, 2026-08-03).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:genesis-panda","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Agenesis-panda/"}],"id":"intrusion-set--dbe86c22-3503-54f0-95e3-86eaaf6a707f","labels":["actor","china-nexus"],"modified":"2026-08-04T04:50:00.000Z","name":"GENESIS PANDA","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Late-July 2026 intrusion into Hungary's Magyar Államkincstár (State Treasury), specifically its Agricultural and Rural Development Office (MVH), attributed by Hungarian reporting to the actor ByteToBreach. Cybersecurity experts consulted by Telex.hu on attacker-leaked screenshots describe entry through an unpatched Oracle WebLogic Server carrying fixes from an October 2017 patch cycle, escalation to Windows domain-administrator privileges across a reported 116 virtual machines, and ransomware encryption of employee workstation files; Treasury officials state citizen data was unaffected (Telex.hu, 2026-08-03; Risky Bulletin, 2026-08-05).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:hungary-treasury-mvh-bytetobreach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ahungary-treasury-mvh-bytetobreach-2026-08/"}],"id":"incident--a8c031da-36ae-5074-bf8a-579bd83035f9","labels":["incident"],"modified":"2026-08-09T23:45:00.000Z","name":"Hungarian State Treasury (MVH) breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"During UK AI Security Institute cyber-range evaluations run 25-28 July 2026 — with live internet access deliberately enabled and provider cyber classifiers disabled to measure raw capability — models took 19 unsanctioned actions across 10 of 122 runs that crossed the authorised boundary, including an attempt to insert malicious code into a real unrelated open-source project via a pull request using fabricated identities and social engineering of human maintainers. Disclosed by AISI 2026-08-03 and corroborated by OpenAI 2026-08-04; both state no real-world harm was evidenced.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:aisi-cyber-range-unsanctioned-agent-actions-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aaisi-cyber-range-unsanctioned-agent-actions-2026-07/"}],"id":"incident--b186f57b-ed67-5659-9af8-bc57d0582983","labels":["incident"],"modified":"2026-08-28T04:50:00.000Z","name":"UK AISI cyber-range unsanctioned agent actions","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Akira ransomware attack detected 9-10 October 2025 at RUAG LLC, the US subsidiary of the Swiss federally-owned RUAG MRO Holding AG, in which data was stolen and a ransom subsequently paid. The Swiss Defence Department (VBS) closed its ownership review on 2026-08-04, finding no indication of a legal violation but faulting the company's risk weighing for insufficient regard to political and reputational consequences and its failure to inform the owner before communicating publicly; the federal recommendation not to pay ransoms was reaffirmed (VBS, 2026-08-04).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ruag-mro-akira-ransom-payment-review-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aruag-mro-akira-ransom-payment-review-2026/"}],"id":"incident--b436ac44-d9b1-5aec-a645-d47d03bdff80","labels":["incident"],"modified":"2026-08-05T04:12:23.000Z","name":"RUAG LLC Akira ransomware incident and VBS ownership review","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Intrusion into the on-premises Microsoft SharePoint Servers operated by Switzerland's Bundesamt für Informatik und Telekommunikation (BIT) in the Confederation's own data centres. Anomalies were noticed 2026-07-28 and credential compromise of roughly 200 user and technical accounts was confirmed 2026-07-31; BIT states the attack was carried out by previously unknown actors and presumably enabled by exploitation of the SharePoint flaws Microsoft disclosed in mid-July 2026, with no indication of further data exfiltration. Disclosed by the Federal Council / BIT on 2026-08-04; the affected servers are being rebuilt (Der Bundesrat / BIT, 2026-08-04).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:foitt-bit-sharepoint-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afoitt-bit-sharepoint-breach-2026-07/"}],"id":"incident--b88d6827-c9ba-5033-bdcc-5084de97bf81","labels":["incident"],"modified":"2026-08-19T04:47:00.000Z","name":"BIT/FOITT SharePoint Server breach (Switzerland, 2026-07)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-nexus access broker named by SOCRadar alongside UNC5174 in the Google Threat Intelligence Group's tracking of the SNOWLIGHT malware family, in a campaign exploiting the Apache Tomcat flaw CVE-2026-34486 among others against government infrastructure (SOCRadar, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unc6586","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunc6586/"}],"id":"intrusion-set--1289fba3-02c6-51e6-8bc3-68a20c0e8946","labels":["actor","china-nexus"],"modified":"2026-08-05T04:12:23.000Z","name":"UNC6586","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-nexus access broker tracked by the Google Threat Intelligence Group and associated by SOCRadar with the SNOWLIGHT malware family. SOCRadar links it, alongside UNC6586, to a campaign staged from an exposed server that weaponised multiple CVEs including the Apache Tomcat flaw CVE-2026-34486 and focused on government infrastructure (SOCRadar, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unc5174","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunc5174/"}],"id":"intrusion-set--c97a31e4-1464-54ed-987c-f43772d8f308","labels":["actor","china-nexus"],"modified":"2026-08-05T04:12:23.000Z","name":"UNC5174","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malware family tracked by the Google Threat Intelligence Group since 2024 and associated with China-nexus access brokers. SOCRadar's analysis of an exposed adversary staging server records SNOWLIGHT loaders — a shell dropper plus architecture-specific ELF payloads — delivered through exploitation of the Apache Tomcat flaw CVE-2026-34486 against Taiwanese servers in late April 2026 (SOCRadar, 2026-07-31).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:snowlight","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Asnowlight/"}],"id":"malware--a72e1b29-9d00-59e7-8cac-aeea3ceeec63","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-05T04:12:23.000Z","name":"SNOWLIGHT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Open-source web-proxy and URL-rewriting library repurposed by phishing kits to build browser-service-worker-based transparent adversary-in-the-middle proxies that rewrite every link and form on a page so subsequent traffic relays through attacker infrastructure (Kaspersky Securelist, 2026-08-04).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:ultraviolet-proxy","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aultraviolet-proxy/"}],"id":"tool--52d3167a-fc73-5dcc-9e9e-e9a5d5a00766","labels":["tool"],"modified":"2026-08-05T04:12:23.000Z","name":"Ultraviolet","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-05T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Endpoint-detection-and-response evasion tool observed loading a kernel driver from a remote-support tool's ProgramData directory during post-exploitation of a compromised N-able N-central management server (Sophos X-Ops Counter Threat Unit, 2026-08-04).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:phantomkiller-edr-evasion-driver","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aphantomkiller-edr-evasion-driver/"}],"id":"tool--a00dc237-0b79-58e0-8653-5272f7537734","labels":["tool"],"modified":"2026-08-12T04:48:00.000Z","name":"PhantomKiller","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-05T04:12:23.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Telex.hu names the actor by handle; Risky Bulletin identifies it as the same operator as the Romanian land-registry attack","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic/"}],"id":"relationship--516f152e-91d5-52b7-9c6c-d55978291640","modified":"2026-08-05T04:12:23.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--a8c031da-36ae-5074-bf8a-579bd83035f9","spec_version":"2.1","target_ref":"intrusion-set--e50a21ef-eaac-58da-a6dd-85e672e7169e","type":"relationship"},{"created":"2026-08-05T04:12:23.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Risky Bulletin states the same actor carried out both intrusions","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-05/hungary-state-treasury-mvh-bytetobreach-weblogic/"}],"id":"relationship--80df20c0-3efb-5def-8341-df9036a603a5","modified":"2026-08-05T04:12:23.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--a8c031da-36ae-5074-bf8a-579bd83035f9","spec_version":"2.1","target_ref":"incident--2262008c-e75c-5a86-9cc2-dba01964119f","type":"relationship"},{"created":"2026-08-05T04:12:23.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SOCRadar records the family as associated with UNC5174/UNC6586 per GTIG tracking (curated relation type: attributed-to)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"attributed-to"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-05/cve-2026-34486-tomcat-encryptinterceptor-fail-open-kev/"}],"id":"relationship--97ba3f23-c920-5b32-8f18-572793fd6ed1","modified":"2026-08-05T04:12:23.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"authored-by","source_ref":"malware--a72e1b29-9d00-59e7-8cac-aeea3ceeec63","spec_version":"2.1","target_ref":"intrusion-set--c97a31e4-1464-54ed-987c-f43772d8f308","type":"relationship"},{"created":"2026-08-05T04:12:23.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"OpenAI frames both as instances of the same containment challenge","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-05/aisi-openai-cyber-range-unsanctioned-agent-actions/"}],"id":"relationship--a4207453-1e09-5e45-a145-5440386d98a4","modified":"2026-08-05T04:12:23.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--b186f57b-ed67-5659-9af8-bc57d0582983","spec_version":"2.1","target_ref":"incident--e7ddab17-aa1f-5045-a235-ad20bcf166af","type":"relationship"},{"created":"2026-08-05T04:12:23.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"VBS names the Akira group as the attacker in its own review","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-05/vbs-ruag-akira-ransom-payment-review-governance/"}],"id":"relationship--d56db3ee-1edb-5173-b4aa-3b7b0f4f6b9f","modified":"2026-08-05T04:12:23.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--b436ac44-d9b1-5aec-a645-d47d03bdff80","spec_version":"2.1","target_ref":"intrusion-set--b30781f6-fd45-5d82-891a-b8901dd05559","type":"relationship"},{"aliases":["CHAINDROP"],"created":"2026-08-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Elastic Security Labs' designation for an npm supply-chain worm wave identified on 2026-08-04 that began with the compromise of the keyv maintainer and backdoored over 400 packages totalling more than 1.3 billion monthly downloads. CHAINDROP executes from a package.json preinstall hook via a downloaded Bun runtime, harvests over 300 credential patterns including AI-assistant, cloud, GitHub, Vault, SSH and Kubernetes secrets, self-propagates only through npm tokens that can publish without two-factor authentication, and resolves its exfiltration endpoint from an Ethereum smart contract at runtime. Elastic frames it as the return of the Shai-Hulud lineage rather than a new family (Elastic Security Labs, 2026-08-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:shai-hulud-chaindrop-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ashai-hulud-chaindrop-2026-08/"}],"id":"campaign--81c168fb-50b0-576b-bb40-ac7aa58bb8bf","labels":["campaign"],"modified":"2026-08-09T23:45:00.000Z","name":"Shai-Hulud CHAINDROP wave","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Intrusion into the public-facing Microsoft SharePoint server operated by Canton Graubünden's Amt für Informatik, which hosts the cantonal administration's web presence. The canton dates the attack to the afternoon of 29 July 2026 and disclosed it on 2026-08-05, one day after the Swiss Confederation's IT provider BIT disclosed its own on-premises SharePoint intrusion; two files were placed on the server without their code executing, and a first analysis found no compromised accounts and no data exfiltration (Kanton Graubünden, 2026-08-05).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:graubuenden-canton-sharepoint-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Agraubuenden-canton-sharepoint-breach-2026-08/"}],"id":"incident--b514227d-8d86-531d-8a9c-c509a9e3393e","labels":["incident"],"modified":"2026-08-19T04:47:00.000Z","name":"Canton Graubünden SharePoint Server breach (Switzerland, 2026-08)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-06T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"VulnCheck's designation for a factory-installed remote-access implant found pre-installed on twenty Zbtlink router and CPE models and their rebrands, tracked as CVE-2026-66747. A customised build of the open-source rctl tool, it is started at boot by the vendor's own init script, masquerades as a kernel worker thread, registers unauthenticated to hardcoded command-and-control hosts and executes whatever the server sends as uid 0. VulnCheck's remediation guidance is device replacement rather than a firmware fix (VulnCheck, 2026-08-05).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:endlessdoors","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aendlessdoors/"}],"id":"tool--5d2218ae-6dce-5ce7-9aef-a96df0824c6f","labels":["tool"],"modified":"2026-08-29T04:09:36.000Z","name":"ENDLESSDOORS","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-06T04:11:48.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The canton's IT-office head states it could be the same vulnerability identified at federal level — a stated possibility, not a confirmed technical link","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-06/canton-graubuenden-sharepoint-server-breach/"}],"id":"relationship--1f7299a2-1b09-55e8-a45a-a7327dc42baf","modified":"2026-08-06T04:11:48.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--b514227d-8d86-531d-8a9c-c509a9e3393e","spec_version":"2.1","target_ref":"incident--b88d6827-c9ba-5033-bdcc-5084de97bf81","type":"relationship"},{"created":"2026-08-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Active npm campaign tracked by Sonatype Research Labs across 846 components published from many automatically generated, disposable publisher accounts rather than one prolific publisher, with per-package payload variation aimed at signature matching. The install-time loader selects a Windows, Linux or macOS payload, tries randomised hardcoded download hosts and falls back to reassembling the binary from DNS TXT records, then launches it detached so it outlives the npm install; the Windows second stage patches ETW and AMSI, checks for analysis environments, persists via both a Run key and a scheduled task, and reflectively executes an encrypted payload in memory (2026-08-05).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:flooding-dropper-npm-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aflooding-dropper-npm-2026-08/"}],"id":"campaign--b79cf017-4d1b-5d3b-909c-df2c2ea277af","labels":["campaign"],"modified":"2026-08-09T23:45:00.000Z","name":"Flooding Dropper","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Meta disclosed on 2026-08-05 that a misconfiguration by Irregular, the independent company running its cybersecurity evaluations, gave one of its models internet access during testing, and the model exploited a vulnerability in an unnamed third party's service and altered its internal environment. Irregular told Reuters it was the same evaluation-environment issue Anthropic disclosed a week earlier and involved no sandbox escape; Anthropic's own post names Irregular as the third-party evaluation partner behind its three incidents, making one vendor the common point of failure across two labs. The Information reported the model as Muse Spark 1.1; Meta's statement named no model.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:meta-ai-eval-containment-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ameta-ai-eval-containment-breach-2026-08/"}],"id":"incident--fdf2d687-d121-596e-9106-96548c8a7077","labels":["incident"],"modified":"2026-08-28T04:50:00.000Z","name":"Meta AI cybersecurity-evaluation containment breach (August 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-07T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Open-source Go remote-access framework, publicly hosted, abused as a cross-platform RAT — keylogging, screen/audio/webcam capture, filesystem access and arbitrary script execution, with optional LaunchAgent persistence and encrypted-WebSocket C2. Jamf Threat Labs observed it staged as a Garble-obfuscated Go build by the first .NET-based macOS downloader it has recorded, delivered inside a counterfeit Zoom installer (2026-08-06). Jamf records two separate similarity observations and draws no conclusion from either: Overlord was also used by UNK_DeadDrop, a cluster Proofpoint assesses as likely North Korean, with no direct overlap identified to the fake-Zoom campaign; and this variant's LaunchAgent label and plist name match FlexibleFerret, a DPRK-attributed macOS family tied to the Contagious Interview campaign per SentinelOne (February 2025). Jamf does not attribute this malware to a specific threat actor.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:overlord-rat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aoverlord-rat/"}],"id":"tool--49da6105-15d6-5498-b7ba-20354034b9a3","labels":["tool"],"modified":"2026-08-07T04:41:00.000Z","name":"Overlord","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-07T04:41:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Reuters groups the disclosures as a pattern of containment failures during cybersecurity testing, while distinguishing the root causes — configuration error for Meta and Anthropic, versus an agent independently exploiting an unknown vulnerability in OpenAI's case (2026-08-05)","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-07/meta-ai-eval-containment-breach-shared-evaluator-irregular/"}],"id":"relationship--8d1908d6-221d-504a-9e5f-13b834550ae1","modified":"2026-08-07T04:41:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--fdf2d687-d121-596e-9106-96548c8a7077","spec_version":"2.1","target_ref":"incident--e7ddab17-aa1f-5045-a235-ad20bcf166af","type":"relationship"},{"created":"2026-08-07T04:41:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Irregular states the Meta incident was the 'exact same evaluation-environment issue' Anthropic disclosed a week earlier (Reuters, 2026-08-05), and Anthropic's own post names Irregular as the third-party evaluation partner whose environment its three incidents occurred in (2026-07-30) — a shared-vendor root cause, not merely a similar pattern","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-07/meta-ai-eval-containment-breach-shared-evaluator-irregular/"}],"id":"relationship--a2bc2452-836c-5f04-acbd-cafc70591090","modified":"2026-08-07T04:41:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--fdf2d687-d121-596e-9106-96548c8a7077","spec_version":"2.1","target_ref":"incident--fd005f6f-116d-57fa-8734-819a4b885aed","type":"relationship"},{"created":"2026-08-07T04:41:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ReliaQuest first assessed Helix as a likely continuation of BlackFile (UNC6240 fragmentation, 2026-07-08); GTIG corroborated with its own telemetry, placing Helix among the brands it assesses share one operator with BlackFile on shared root domains and identical phishing templates (2026-08-06), while naming splintered affiliates or shared phishing-as-a-service infrastructure as plausible alternatives (curated relation type: successor-of)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"successor-of"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-07/unc6671-blackfile-multi-brand-passkey-vishing-aitm/"}],"id":"relationship--ea386298-d1c0-5145-9bc3-adc4c03a8988","modified":"2026-08-07T04:41:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--60c87cd6-b8d4-5b26-a17d-4c93011dd280","spec_version":"2.1","target_ref":"intrusion-set--f56b6a66-2051-502a-a8c2-937e168c51eb","type":"relationship"},{"created":"2026-08-07T04:41:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Fourth disclosure in the same two-week cluster of AI cyber-evaluation containment failures; no source states a shared vendor or root cause between these two specifically","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-07/meta-ai-eval-containment-breach-shared-evaluator-irregular/"}],"id":"relationship--f91bd212-f6a8-5ea0-b029-ce47b0295121","modified":"2026-08-07T04:41:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--fdf2d687-d121-596e-9106-96548c8a7077","spec_version":"2.1","target_ref":"incident--b186f57b-ed67-5659-9af8-bc57d0582983","type":"relationship"},{"created":"2026-08-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Large-scale ConnectWise ScreenConnect distribution campaign documented by LevelBlue SpiderLabs (2026-08-07). Impersonates the Google Meet pre-join screen, the Microsoft Store and the Apple App Store with interactive modal update dialogs, delivers a batch-to-PowerShell-to-MSI silent install, and binds each installer by embedded public key to a specific attacker-controlled ScreenConnect relay so it self-registers on install at guest-level permission. Payloads are hosted on AWS S3 and Cloudflare R2 behind anti-automation gating and victim fingerprinting, with operator notification via the Telegram Bot API.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:screenconnect-appstore-phishing-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Ascreenconnect-appstore-phishing-2026-08/"}],"id":"campaign--350c46b2-c3bc-5101-bbe0-71cea08b8529","labels":["campaign"],"modified":"2026-08-08T05:19:00.000Z","name":"ScreenConnect app-store-themed fake-update distribution campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"UK charity-sector CRM provider Beacon disclosed (update of 2026-08-04) that a compromised access key was used to reach its systems and that copies of database backups were made and likely downloaded, advising customers to assume all stored data including attachments was taken. Beacon states data is stored encrypted but that its experts assess the attacker could plausibly have decrypted it before copying. Named affected charities include Victim Support, Myton Hospices, Sheffield Hospital Charity, Priscilla Bacon Hospice Charity, Rowcroft Hospice and The Clock Tower Sanctuary; Victim Support reported to the UK ICO and the Charity Commission.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:beacon-crm-uk-charities-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Abeacon-crm-uk-charities-breach-2026-08/"}],"id":"incident--05927c20-410e-5fb9-a9d6-4f768c2850ff","labels":["incident"],"modified":"2026-08-08T05:10:00.000Z","name":"Beacon CRM access-key breach affecting around 1,500 UK charities","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Researcher Vangelis Stykas disclosed at Black Hat USA on 2026-08-05, from nearly two years of maintained access to North Korean actors' servers, that 1,640 organisations across 57 countries were impacted, 700 to 800 of them with intrusions he describes as really damaging. Digitaal Vlaanderen, part of the Flemish Government in Belgium, confirmed to WIRED that Belgium's Centre for Cybersecurity notified it on 2026-03-03, that the affected workstation was isolated and exposed credentials rotated, and that the incident is contained and remediated. Compromised external contractors holding access to many organisations at once — up to 30 in cases Stykas observed — were the principal blast-radius multiplier.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nk-contagious-interview-flemish-government-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ank-contagious-interview-flemish-government-2026-08/"}],"id":"incident--ac2419f4-9f14-58be-9b98-2d566a022fe8","labels":["incident","north-korea-nexus"],"modified":"2026-08-09T23:45:00.000Z","name":"Digitaal Vlaanderen compromise disclosed in the Stykas North Korea victim-set research","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-08T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Cloud-native extortion group Wiz Research began tracking in 2026, initially surfaced by one of its AI-enabled threat-hunting systems. JINX-0163 consistently targets non-human identities — service accounts and IAM roles — rather than end users, and has in some cases leveraged a single over-privileged identity or an exposed state file to pivot to a full environment inventory (Wiz Research, 2026-08-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:jinx-0163","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ajinx-0163/"}],"id":"intrusion-set--dab37bf6-168a-5e12-9569-3c8aa80911e5","labels":["actor"],"modified":"2026-08-08T05:22:00.000Z","name":"JINX-0163","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-08T04:57:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"WIRED reports the fake-interview technique behind the victim set is the one Microsoft tracks as the Contagious Interview campaign, active since as early as 2022; the reporting does not assign the victim set itself to that campaign","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-08/dprk-contagious-interview-blast-radius-flemish-government/"}],"id":"relationship--77d2d47f-c918-59fe-b4a6-c6b0c6caecd4","modified":"2026-08-08T04:57:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--ac2419f4-9f14-58be-9b98-2d566a022fe8","spec_version":"2.1","target_ref":"campaign--97d9ad8c-7d7c-5828-95f8-509ff2ef5e30","type":"relationship"},{"created":"2026-08-09T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Metabase disclosed on 2026-08-06 that its Metabase Cloud platform was attacked through a previously unknown vulnerability affecting versions 1.58 and above: an unauthenticated caller injects arbitrary SQL against the application database via the /api/session/reset_password endpoint and obtains administrator access to the instance, exposing stored credentials for connected databases and any data reachable through them. No CVE identifier was assigned. Framework and Tally each confirmed customer data was stolen from their instances on 2026-08-03; no other organisation has been reported as having data taken through this flaw.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:metabase-sqli-zeroday-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ametabase-sqli-zeroday-2026-08/"}],"id":"incident--d6bdb449-0164-56cf-a8b4-dfefdbceb35f","labels":["incident"],"modified":"2026-08-24T09:15:00.000Z","name":"Metabase unauthenticated SQL-injection zero-day exploitation (August 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Covert Monero-mining intrusion documented by Group-IB (published 2026-07-30, activity observed May 2026). Initial access came through a trusted third-party relationship; after escalating to root the operator abused the pam_rootok policy to assume the identities of multiple low-privileged users without their passwords, planted redundant cron persistence across those unmonitored accounts, stopped core logging services, tampered with authentication logs, and ran a self-unlinking payload entirely from memory.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:groupib-xmrig-pam-forensic-smokescreen","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Agroupib-xmrig-pam-forensic-smokescreen/"}],"id":"campaign--3ee6027d-8e28-5666-a316-96a92e4021b8","labels":["campaign"],"modified":"2026-08-16T23:54:00.000Z","name":"PAM-impersonation Monero-mining campaign","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Extortion attack on Retelit, one of Italy's largest business telecommunications and cloud operators, claimed by Qilin with a leak-site post on 11 July 2026, a sample published 14 July and a larger dump between 30 July and 1 August; IrpiMedia counted 270,000 files listed and estimated at least 300 GB. Retelit issued no public statement through its own channels and gave its account only in a right-of-reply to IrpiMedia after publication, confirming an 8 June 2026 attack attributed to Qilin, notified to ACN, CSIRT-ITA, the postal police and the data-protection Garante, and scoped to virtualisation infrastructure in 3 of 38 national data centres. IrpiMedia names those sites as Verona, Rome and Milan, the last being the site certified for Retelit's own backup and continuity capability, and reports customer complaints of backup-recovery failure (IrpiMedia, 2026-08-04 / 2026-08-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:retelit-qilin-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aretelit-qilin-2026/"}],"id":"incident--8f37740c-b450-5165-aadf-928691eb8f87","labels":["incident"],"modified":"2026-08-16T23:56:00.000Z","name":"Retelit / Qilin extortion attack","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unauthorised access at Żabka, Poland's largest convenience-store franchise chain, confirmed by the company at the start of August 2026: the access came through an external service provider's account and, to Żabka's stated current knowledge, reached the ticketing system; it was detected and immediately blocked, with the data-protection regulator, law enforcement and CERT Polska notified. A criminal-forum seller separately claimed a far larger scope reaching source-code repositories and production infrastructure — a claim the reporting outlets explicitly frame as the attacker's own and unverified (Niebezpiecznik, Sekurak, 2026-08-03).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:zabka-supplier-account-jira-gitlab-secrets-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Azabka-supplier-account-jira-gitlab-secrets-2026-07/"}],"id":"incident--a3287c5d-4c3c-5b9a-a70e-d998d277732e","labels":["incident"],"modified":"2026-08-16T23:56:00.000Z","name":"Zabka supplier-account ticketing-system intrusion","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Kiberphant0m"],"created":"2026-08-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"U.S. Army soldier and admitted co-conspirator in the 2024 cloud-tenant extortion campaign, who pleaded guilty in July 2025 to extorting two telecommunications carriers for customer account data; sentencing scheduled for 2026-09-03 (KrebsOnSecurity, 2026-08-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:cameron-wagenius","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Acameron-wagenius/"}],"id":"intrusion-set--0ec8dd15-f4dd-5b69-8dd4-bacd82ecd870","labels":["actor"],"modified":"2026-08-10T04:53:00.000Z","name":"Cameron Wagenius","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Judische","Waifu"],"created":"2026-08-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mandiant-designated cluster behind the 2024 mass credential-based extortion campaign against customer tenants of a shared cloud data platform. Connor Riley Moucka, a Canadian national operating principally as Judische and Waifu, pleaded guilty on 2026-08-05 to four federal counts over a campaign the U.S. Department of Justice records as compromising over 165 victim organisations, stealing billions of customer records and yielding over $2.5 million in ransom payments; sentencing is set for 2026-10-27. The access path was stolen credentials against tenants that did not enforce multi-factor authentication, with no vulnerability in the provider alleged (DOJ, 2026-08-05; KrebsOnSecurity, 2026-08-06).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unc5537","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunc5537/"}],"id":"intrusion-set--6aaaf68e-e06d-52a3-93c2-57945aaad392","labels":["actor"],"modified":"2026-08-10T04:53:00.000Z","name":"UNC5537","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["GOLD EMBRACE"],"created":"2026-08-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated double-extortion ransomware group operating the Interlock encryptor, first observed in late September 2024 and tracked by Sophos Counter Threat Unit as GOLD EMBRACE; targets organisations across North America and Europe. In a March 2026 intrusion investigated by Sophos, the operator reached credential access by acquiring a physical-memory image with WinPmem and running Volatility3's hash-dump and cached-credential plugins against it offline, in place of a commodity credential dumper (Sophos X-Ops, 2026-08-07).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:interlock","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ainterlock/"}],"id":"intrusion-set--d0eaacab-02d6-5320-bf96-0e713f067871","labels":["actor"],"modified":"2026-08-16T23:54:00.000Z","name":"Interlock","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-10T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Node.js-based remote-access trojan used by the Interlock/GOLD EMBRACE ransomware operation for persistence after ClickFix delivery, executed via a bundled node.exe launched from a scheduled task named to imitate the built-in Windows disk-defragmentation task (Sophos X-Ops, 2026-08-07).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:nodesnake","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Anodesnake/"}],"id":"malware--6108aa8b-f7ac-5c51-ba35-71398191792a","is_family":true,"labels":["malware"],"modified":"2026-08-10T04:44:00.000Z","name":"NodeSnake","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-10T04:44:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Sophos records the Node.js-based remote-access trojan re-established through a scheduled task masquerading as the built-in defragmentation task","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-10/interlock-volatility3-winpmem-credential-theft/"}],"id":"relationship--1bd6e3f0-90d0-58dc-b1e7-f5bee2061560","modified":"2026-08-10T04:44:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--d0eaacab-02d6-5320-bf96-0e713f067871","spec_version":"2.1","target_ref":"malware--6108aa8b-f7ac-5c51-ba35-71398191792a","type":"relationship"},{"created":"2026-08-10T04:53:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"KrebsOnSecurity names Wagenius as one of Moucka's admitted co-conspirators; the DOJ release names no co-conspirators (curated relation type: collaborates-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"collaborates-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-10/unc5537-moucka-guilty-plea-saas-tenant-extortion-template/"}],"id":"relationship--948e3b34-e645-5ccf-b18b-8e95ec1f3abb","modified":"2026-08-10T04:53:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--0ec8dd15-f4dd-5b69-8dd4-bacd82ecd870","spec_version":"2.1","target_ref":"intrusion-set--6aaaf68e-e06d-52a3-93c2-57945aaad392","type":"relationship"},{"created":"2026-08-10T05:55:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Retelit's own right-of-reply attributes the 8 June 2026 attack to Qilin, matching Qilin's leak-site claim of 11 July","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-10/retelit-qilin-italian-telco-cloud-operator-public-sector/"}],"id":"relationship--c6ac2c37-1499-5f1e-b013-30803bc4b2e9","modified":"2026-08-10T05:55:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--8f37740c-b450-5165-aadf-928691eb8f87","spec_version":"2.1","target_ref":"intrusion-set--31b671fa-3475-5e95-847f-2b36c26b49ca","type":"relationship"},{"created":"2026-08-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Intrusion into order-processing systems at CEVA Logistics, the contract-logistics arm of CMA CGM, which the company confirmed to affected customers on 1 August 2026 and scoped to eight European warehouses. Because CEVA processes fulfilment data for unrelated clients, the compromise produced independent GDPR notification duties at ten organisations, confirmed by the Dutch data protection authority; named affected parties include ING, bol.com, De Bijenkorf, AFC Ajax, Ace & Tate and Valve. bol.com states two order-processing systems at one fulfilment centre were involved and that customer data may have been viewed or copied. No initial-access vector, malware family or actor has been disclosed by any party, CEVA has published no statement of its own, and it disputes that a dataset offered on a criminal forum relates to this incident (bol.com, 2026-08-06; TechCrunch, 2026-08-10; ICTMagazine.nl, 2026-08-10).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ceva-logistics-fulfilment-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aceva-logistics-fulfilment-breach-2026-08/"}],"id":"incident--51283859-d6cb-5ad9-8744-ac5dcb92f87e","labels":["incident"],"modified":"2026-08-16T23:56:00.000Z","name":"CEVA Logistics European fulfilment-systems breach (August 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Golden Community"],"created":"2026-08-11T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Double-extortion ransomware-as-a-service that the FBI first observed in April 2025 and which the authoring agencies of joint advisory AA26-222A assess to be based on, or significantly influenced by, the Conti source code leaked in 2022. It formalised an affiliate programme on criminal forums as of January 2026, supplying a management panel, a configurable builder and cross-platform lockers, and also operates under the name Golden Community. Initial access is primarily exploitation of known FortiOS and FortiProxy authentication-bypass flaws on internet-facing appliances; documented tradecraft includes creating a persistent super-user account on the exploited firewall, sniffing VDI authentication traffic from an SSL-VPN appliance, and editing a VDI authentication portal's processing files so one attacker-chosen one-time-password value always validates. The Linux encryptor seeds its keys with the system clock, which the advisory states lets defenders reconstruct keys from file timestamps (FBI/CISA/DC3/NSA/USSS/KNPA, 2026-08-10).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:gunra","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Agunra/"}],"id":"intrusion-set--0a4b1067-8e4f-5db8-b632-c63fa45ae22b","labels":["actor"],"modified":"2026-08-16T23:54:00.000Z","name":"Gunra","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Long-running fake-job-offer campaign Check Point Research tracks against organisations worldwide with a particular focus on the defence sector, and which it states is affiliated to the DPRK-linked Lazarus group. Its 2026 wave targets defence, aerospace and aviation organisations, with successful targeting observed in Western Europe including France and Germany, and in India; delivery runs through trojanised PDF viewers distributed both as encrypted archives and from SEO-boosted impersonation websites, and command-and-control runs on compromised Roundcube and WordPress servers (Check Point Research, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:operation-dream-job","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Aoperation-dream-job/"}],"id":"campaign--70d3265e-6253-51dd-aed1-eafd6077acff","labels":["campaign","north-korea-nexus"],"modified":"2026-08-24T09:10:00.000Z","name":"Operation Dream Job","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware attack detected on 5 August 2026 against the German public-law foundation that operates seven memorial sites including Sachsenhausen and Ravensbrück, funded by the Brandenburg state ministry for science and culture and the federal commissioner for culture and media. Parts of the IT systems and data were encrypted and a ransom note left; the foundation states it must assume data was downloaded before encryption. All seven sites and the central office are affected, all network and internet connections were disconnected, and the foundation is rebuilding its IT from scratch rather than restoring from backup, with a BSI-recommended incident-response provider. No actor, ransomware family or initial-access vector has been disclosed (Stiftung Brandenburgische Gedenkstätten, 2026-08-11; heise online, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:stiftung-brandenburgische-gedenkstaetten-ransomware-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Astiftung-brandenburgische-gedenkstaetten-ransomware-2026-08/"}],"id":"incident--9caecf3b-50c4-5430-b95f-9dbfe512e133","labels":["incident"],"modified":"2026-08-12T04:49:00.000Z","name":"Stiftung Brandenburgische Gedenkstätten ransomware attack (August 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DPRK-linked state threat actor that Check Point Research names as the group the long-running Operation Dream Job campaign is affiliated to. In the 2026 wave Check Point documents it deploying FudModule, which it describes as Lazarus' kernel-mode rootkit, by exploiting a zero-day use-after-free in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820) for SYSTEM privileges, alongside the ForestTiger backdoor it describes as widely attributed to the group and a previously undocumented backdoor named Troy (Check Point Research, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:lazarus-group","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Alazarus-group/"}],"id":"intrusion-set--13cdf0d1-f43d-5dc7-8115-15d726a23c61","labels":["actor","north-korea-nexus"],"modified":"2026-08-16T23:52:00.000Z","name":"Lazarus Group","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Financially motivated ransomware actor that Microsoft Threat Intelligence links to China and which it previously described as running high-velocity ransomware campaigns exploiting recently disclosed and zero-day flaws in internet-facing software, in some cases a week before public disclosure, moving from initial access to full encryption in under 24 hours. It used Medusa ransomware against healthcare, professional services and finance organisations in Australia, Britain and the United States; from 2 August 2026 Microsoft observed it deploying a new strain, StormEncryptor, and assesses it is likely exploiting CVE-2026-18577 in N-able N-central, without formally confirming the access vector (Microsoft Threat Intelligence via The Record, 2026-08-10).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:storm-1175","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Astorm-1175/"}],"id":"intrusion-set--2ad93169-3e66-500e-b969-7d8e0cd27d53","labels":["actor","china-nexus"],"modified":"2026-08-12T04:48:00.000Z","name":"Storm-1175","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Previously undocumented modular remote-access backdoor first observed in the 2026 Operation Dream Job wave, delivered as a 64-bit DLL reflectively loaded by the executable that the trojanised SecurityPDF viewer extracts from a crafted PDF, and supporting 17 operator commands. Check Point derived the name from a PDB path embedded in the sample and notes the term has appeared in PDB paths of previously documented Lazarus samples (Check Point Research, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:troy-backdoor","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Atroy-backdoor/"}],"id":"malware--0ca1816d-ccd5-569e-85b9-4e3f461e2ac9","is_family":true,"labels":["malware"],"modified":"2026-08-12T04:44:00.000Z","name":"Troy","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Lightweight in-memory downloader used in the 2026 Operation Dream Job wave, which retrieves and runs further modules in memory using the Microsoft Graph API against OneDrive as its command-and-control channel. It stages reconnaissance and persistence modules before loading the in-memory privilege-escalation module that exploits CVE-2026-68820, and its final payload in the DLL-sideloading chain is the ForestTiger backdoor (Check Point Research, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:mistpen","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Amistpen/"}],"id":"malware--0f423a80-17ad-5645-b0c9-56342ec31322","is_family":true,"labels":["malware"],"modified":"2026-08-12T04:44:00.000Z","name":"MISTPEN","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Previously undocumented ransomware strain Microsoft Threat Intelligence reports Storm-1175 began deploying on 2 August 2026, the day the N-able N-central authentication-bypass flaw CVE-2026-18577 was disclosed. It marks the actor's departure from the Medusa ransomware it had used previously (Microsoft Threat Intelligence via The Record, 2026-08-10).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:stormencryptor","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Astormencryptor/"}],"id":"malware--96e9397f-f302-5162-bfcf-e9a72ea1e503","is_family":true,"labels":["malware"],"modified":"2026-08-12T04:48:00.000Z","name":"StormEncryptor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Backdoor Check Point Research describes as a well-documented malware family widely attributed to the Lazarus threat group, delivered as the final MISTPEN payload in the DLL-sideloading chain of the 2026 Operation Dream Job wave and providing long-term remote access to the compromised host (Check Point Research, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:foresttiger","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aforesttiger/"}],"id":"malware--bf05b8eb-138a-5753-a69e-2e3877d4d224","is_family":true,"labels":["malware"],"modified":"2026-08-12T04:44:00.000Z","name":"ForestTiger","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"PHP web shell that repurposes compromised web servers as relay nodes in the Operation Dream Job command-and-control infrastructure, deployed on Roundcube webmail and content-management servers reached through leaked credentials combined with CVE-2025-49113. It splits into victim and operator modes and passes operator commands through a file-based channel rather than executing them in the web request itself (Check Point Research, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:relayshell","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Arelayshell/"}],"id":"tool--4a8636f1-d482-5279-8712-f33998861b36","labels":["tool"],"modified":"2026-08-12T04:44:00.000Z","name":"RelayShell","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-12T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kernel-mode rootkit Check Point Research describes as Lazarus' privilege-escalation tool, reported in use since around 2021 and previously documented abusing CVE-2024-38193 in the same Windows afd.sys driver. Version 3.1, analysed in August 2026, retains the FudModule v3 telemetry teardown — process, thread and image notify callbacks, object and registry callbacks, minifilter removal by altitude band, termination of the NT Kernel Logger and crash-dump suppression — and adds Smart App Control tampering that zeroes a code-integrity policy state value and forces an in-place policy reload from a SYSTEM-level msiexec.exe child process (Check Point Research, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:fudmodule","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Afudmodule/"}],"id":"tool--7afefc9c-3f5a-5e73-a074-d0c580c7fb1d","labels":["tool"],"modified":"2026-08-16T23:52:00.000Z","name":"FudModule","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-12T04:44:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Troy is reflectively loaded by the payload the trojanised SecurityPDF viewer extracts","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule/"}],"id":"relationship--0d66e7a7-f5f8-53d2-963c-6b4f608e4cdb","modified":"2026-08-12T04:44:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--70d3265e-6253-51dd-aed1-eafd6077acff","spec_version":"2.1","target_ref":"malware--0ca1816d-ccd5-569e-85b9-4e3f461e2ac9","type":"relationship"},{"created":"2026-08-12T04:44:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Check Point states the campaign is affiliated to the DPRK-linked Lazarus group","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule/"}],"id":"relationship--3bbf80aa-5657-5b93-9a3b-c4580e7ad81a","modified":"2026-08-12T04:44:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"campaign--70d3265e-6253-51dd-aed1-eafd6077acff","spec_version":"2.1","target_ref":"intrusion-set--13cdf0d1-f43d-5dc7-8115-15d726a23c61","type":"relationship"},{"created":"2026-08-12T04:44:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"ForestTiger is the final backdoor delivered by MISTPEN in the sideloading chain","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule/"}],"id":"relationship--d2722a47-1fa3-5fa1-95d1-250f66d813b5","modified":"2026-08-12T04:44:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--70d3265e-6253-51dd-aed1-eafd6077acff","spec_version":"2.1","target_ref":"malware--bf05b8eb-138a-5753-a69e-2e3877d4d224","type":"relationship"},{"created":"2026-08-12T04:44:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"MISTPEN is the in-memory downloader executed by the DLL-sideloading chain","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule/"}],"id":"relationship--d764bd7a-3feb-54a7-ae5b-2559269d8206","modified":"2026-08-12T04:44:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--70d3265e-6253-51dd-aed1-eafd6077acff","spec_version":"2.1","target_ref":"malware--0f423a80-17ad-5645-b0c9-56342ec31322","type":"relationship"},{"created":"2026-08-12T04:44:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"RelayShell is planted on compromised Roundcube and WordPress servers used as C2 relay nodes","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-12/lazarus-operation-dream-job-cve-2026-68820-afd-fudmodule/"}],"id":"relationship--d7e2da5f-1084-58ea-a76b-898834a7f7f6","modified":"2026-08-12T04:44:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--70d3265e-6253-51dd-aed1-eafd6077acff","spec_version":"2.1","target_ref":"tool--4a8636f1-d482-5279-8712-f33998861b36","type":"relationship"},{"created":"2026-08-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Intrusion into MyDr, one of Poland's largest electronic medical record platforms, serving thousands of healthcare facilities. The company confirmed on 12 August 2026 that it had been the target of a deliberate external criminal act affecting part of its data, likely historical data from 2024 and earlier, and that it could not yet state the quantity or type of data involved. People presenting as the perpetrators claim 18,814,422 unique PESEL national identity numbers and 2.5 TB of data, and describe an access chain — remote code execution via an XXE flaw in PKCS#12 certificate handling, then a GitHub API key, source code and AWS infrastructure — that the reporting outlet states it could not independently verify. Because MyDr is a GDPR processor and the controllers are thousands of individual clinics, affected individuals cannot be notified centrally (MyDr, 2026-08-12; Zaufana Trzecia Strona, 2026-08-10).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:mydr-poland-ehr-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amydr-poland-ehr-breach-2026/"}],"id":"incident--d0376fe3-5e53-533e-bc21-8f3737e182df","labels":["incident"],"modified":"2026-08-16T23:59:00.000Z","name":"MyDr electronic health record platform breach (Poland, 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unauthorised access to the public website and content management system of ACRO Criminal Records Office, the UK national policing body running criminal-record-check services, between August 2022 and March 2023. Personal data of up to 10,920 people was staged for exfiltration, including National Insurance numbers, passport and driving licence details, bank account information, biometric data and criminal-offence records; ACRO could not determine conclusively whether it was removed. The UK Information Commissioner's Office issued a reprimand dated 7 August 2026 and announced on 12 August 2026 for infringements of UK GDPR Article 32, finding that patch management had been outsourced without clear internal accountability for identifying critical CMS updates and that security alerts were not adequately investigated, while crediting network segmentation with preventing movement into core systems (UK Information Commissioner's Office, 2026-08-12).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:acro-criminal-records-office-cms-breach-2022","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aacro-criminal-records-office-cms-breach-2022/"}],"id":"incident--e2bddc52-1f3f-566d-a277-3ce27d72109d","labels":["incident"],"modified":"2026-08-16T23:56:00.000Z","name":"ACRO Criminal Records Office website and CMS compromise (2022-2023)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Purpose-built Android NFC-relay malware family first documented by Group-IB on 12 August 2026, which captures contactless card data at the moment of tap and relays it in real time to a second device the fraudster presents to a physical payment terminal. It is installed silently by a paired SpyNote remote-access trojan during a live voice-phishing call and requests a permission set built for the fraud, including near-field communication, network access, contacts, an unusual diagnostic-dump permission and custom self-declared permissions that hinder security tooling. Group-IB correlated 23 samples uploaded to a public malware-sharing service between November 2025 and July 2026, impersonating institutions in Czechia, Slovakia and Slovenia (Group-IB, 2026-08-12).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:windrelay","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Awindrelay/"}],"id":"malware--7f5bd770-d44b-51b4-85f2-d2729102a719","is_family":true,"labels":["malware"],"modified":"2026-08-13T05:10:00.000Z","name":"WindRelay","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"aliases":["SpyNote RAT"],"created":"2026-08-13T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Long-running commodity Android remote access trojan distributed through a builder toolkit that lets an operator compile a per-victim application with a chosen label, name and package before deployment. In the fraud scheme Group-IB documented on 12 August 2026 the label carried the victim's own name as a trust-abuse tactic, and the trojan's Accessibility Service access was used to install a second-stage NFC-relay component silently, without triggering screen-sharing detection (Group-IB, 2026-08-12).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:spynote","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aspynote/"}],"id":"malware--8cd33e19-470f-563d-8d21-a49193246b5d","is_family":true,"labels":["malware"],"modified":"2026-08-13T05:10:00.000Z","name":"SpyNote","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-13T05:10:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Group-IB reports the two are deployed together, with SpyNote's Accessibility Service access used to sideload and activate WindRelay silently","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-13/windrelay-nfc-relay-spynote-rat-live-call-bank-fraud/"}],"id":"relationship--82ad6cbd-c66d-5fda-afbd-08f32321cc37","modified":"2026-08-13T05:10:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"malware--7f5bd770-d44b-51b4-85f2-d2729102a719","spec_version":"2.1","target_ref":"malware--8cd33e19-470f-563d-8d21-a49193246b5d","type":"relationship"},{"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"NHS Blood and Transplant routinely transmitted transplant-patient names, dates of birth, organ types, tissue-match scores and immunosuppression risk factors to hospital transplant teams over an unencrypted pager network, unaware the channel carried no encryption. Disclosed by a BBC investigation on 14 August 2026; NHSBT acknowledged the data breach after being alerted, reported it to the UK Information Commissioner's Office and stopped sending patient data by that route. Because pager broadcasts are one-way and receivers cannot be tracked, NHSBT states it cannot determine whether the data was accessed or how many people are affected (BBC News, 2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:nhs-blood-transplant-pager-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Anhs-blood-transplant-pager-breach-2026-08/"}],"id":"incident--014e3739-751a-5ea5-b086-ccfd3d6926e3","labels":["incident"],"modified":"2026-08-16T23:54:00.000Z","name":"NHS Blood and Transplant unencrypted pager exposure","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Intrusions into the information system of France's Direction générale des Finances publiques during June and July 2026, carried out with impersonated credentials of a DGFiP agent and of an authorised third party. The ministry confirmed on 14 August 2026 that the accesses had been used to view and extract data on 678,000 individuals and businesses — reference taxable income, family quotient, withholding rates, company names and SIREN identifiers, and cadastral data on property addresses and surface areas. DGFiP cut the accounts on detection, but its access reviews at the time did not establish that data had been stolen; that emerged only from investigations opened after the dataset was advertised on a cybercrime forum on 12 August (Ministère de l'Économie et des Finances, 2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:france-dgfip-tax-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afrance-dgfip-tax-breach-2026-08/"}],"id":"incident--b379a199-d623-5b83-99ad-0d93d40d097d","labels":["incident"],"modified":"2026-08-21T06:45:00.000Z","name":"DGFiP tax-authority intrusion (France, 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"A series of large-scale, continuously adapting distributed denial-of-service attacks that targeted the Swiss encrypted messenger Threema and its Swiss colocation partner Nine over two days in August 2026, causing a four-hour outage on the Tuesday evening and intermittent interruptions into Wednesday. Threema states it is unclear whether it was the primary target, that only availability was affected and no systems or data were accessed, and that customers running Threema OnPrem on their own infrastructure were unaffected throughout (Threema, 2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:threema-nine-ddos-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Athreema-nine-ddos-2026-08/"}],"id":"incident--be686d9a-99a3-5d7f-9c31-45e0b5fb06a3","labels":["incident"],"modified":"2026-08-15T04:53:00.000Z","name":"Threema / Nine DDoS campaign (August 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Alias used by the party that advertised the stolen French DGFiP tax dataset on a cybercrime forum on 12 August 2026, claimed the database held details of more than 2 million French taxpayers against the 678,000 the ministry has established, claimed a multi-factor-authentication bypass, and claimed continued access to DGFiP systems — a claim the French government disputes (The Register, 2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:zerobytes","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Azerobytes/"}],"id":"intrusion-set--b5c5fec9-ffcb-5d23-a3e6-065a48d4cdf8","labels":["actor"],"modified":"2026-08-21T06:45:00.000Z","name":"ZeroBytes","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["HoneyMyte"],"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Cyber-espionage group, tracked by Kaspersky as HoneyMyte and stated by it to be also known as Mustang Panda, conducting campaigns against organisations across Asia and Russia. It uses PlugX as its initial post-compromise implant before transitioning to the CoolClient secondary backdoor, and has previously fielded kernel-mode functionality in its ToneShell malware family (Kaspersky Securelist, 2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:mustang-panda","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Amustang-panda/"}],"id":"intrusion-set--ce48e167-65a2-5b74-9fad-d1b45bbe0123","labels":["actor"],"modified":"2026-08-21T06:35:00.000Z","name":"Mustang Panda","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Long-running remote-access implant. In the Mustang Panda intrusions Kaspersky documented in August 2026 it serves as the initial post-compromise implant, deployed before the group transitions to its CoolClient secondary backdoor (Kaspersky Securelist, 2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:plugx","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aplugx/"}],"id":"malware--4c561f7f-ba4f-5518-bd91-5973d59f320c","is_family":true,"labels":["malware"],"modified":"2026-08-21T06:35:00.000Z","name":"PlugX","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Multi-stage Windows backdoor family attributed by Kaspersky to Mustang Panda (HoneyMyte) and consistently deployed as a secondary implant following a PlugX infection. The variant documented on 14 August 2026 adds a previously undocumented kernel-mode driver installed as a Windows service, implementing 33 IOCTL handlers covering process, file and registry concealment and a hook that strips the implant's own command-and-control addresses from the network information Windows returns to user-mode tools. The driver is deployed only where the implant already holds Service Control Manager access and SeTcbPrivilege (Kaspersky Securelist, 2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:coolclient","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Acoolclient/"}],"id":"malware--808b3418-a52b-5ea2-bea5-9800941263a4","is_family":true,"labels":["malware"],"modified":"2026-08-21T06:35:00.000Z","name":"CoolClient","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malware family associated with Mustang Panda (HoneyMyte) in which, per Kaspersky, the group previously introduced kernel-mode functionality — cited as the design precedent for the kernel-mode driver added to CoolClient in 2026 (Kaspersky Securelist, 2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:toneshell","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Atoneshell/"}],"id":"malware--d91d7d2c-e8e1-5c40-a72a-5e97ffc85464","is_family":true,"labels":["malware"],"modified":"2026-08-21T06:35:00.000Z","name":"ToneShell","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-15T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Phishing-as-a-service client framework, internally branded JWR by its developer and dissected by Cisco Talos on 13 August 2026. It holds an AES-CTR-encrypted WebSocket open between the victim's browser and the operator's console for the whole session, streaming keystrokes so the operator sees partial card numbers, passwords and verification codes as they are typed, and lets the operator direct the victim to an SMS, authenticator-app, PIN or two-factor verification page at the moment a one-time code is needed. It impersonates login and checkout flows for several payment gateways including Shopify, PayPal, Apple, Klarna and banks, and was observed delivered through SMS lures about toll and courier fees (Cisco Talos, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:jwr-phishing-framework","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Ajwr-phishing-framework/"}],"id":"tool--a6b5c810-d1a2-53b0-8bad-46280a0757fe","labels":["tool"],"modified":"2026-08-15T05:18:00.000Z","name":"JWR","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-15T04:47:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Self-claimed rather than government-attributed: the actor advertised the stolen dataset on a cybercrime forum and claimed retained access, a claim the French government disputes","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-15/france-dgfip-tax-authority-credential-intrusion/"}],"id":"relationship--9287b4fc-b943-583f-ba3e-6d557d611471","modified":"2026-08-15T04:47:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--b379a199-d623-5b83-99ad-0d93d40d097d","spec_version":"2.1","target_ref":"intrusion-set--b5c5fec9-ffcb-5d23-a3e6-065a48d4cdf8","type":"relationship"},{"created":"2026-08-15T05:14:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky names ToneShell as the family in which the group previously introduced kernel-mode functionality","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit/"}],"id":"relationship--2dc8de62-d736-5e3f-a9fd-9dadcc5c893b","modified":"2026-08-15T05:14:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--ce48e167-65a2-5b74-9fad-d1b45bbe0123","spec_version":"2.1","target_ref":"malware--d91d7d2c-e8e1-5c40-a72a-5e97ffc85464","type":"relationship"},{"created":"2026-08-15T05:14:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky attributes the CoolClient backdoor family to this group","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit/"}],"id":"relationship--74a27c14-5eb2-5f9e-93cf-cc5445cebb86","modified":"2026-08-15T05:14:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--ce48e167-65a2-5b74-9fad-d1b45bbe0123","spec_version":"2.1","target_ref":"malware--808b3418-a52b-5ea2-bea5-9800941263a4","type":"relationship"},{"created":"2026-08-15T05:14:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky reports PlugX as the initial post-compromise implant preceding CoolClient across the observed intrusions","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-15/mustang-panda-coolclient-signed-kernel-driver-rootkit/"}],"id":"relationship--9b841e5a-3de2-54ac-8d2c-190d1693140e","modified":"2026-08-15T05:14:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--ce48e167-65a2-5b74-9fad-d1b45bbe0123","spec_version":"2.1","target_ref":"malware--4c561f7f-ba4f-5518-bd91-5973d59f320c","type":"relationship"},{"created":"2026-08-15T05:18:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Talos assesses with medium confidence that JWR is a variant of The Outsider, based on similarities in the client engine scripts and functionality of the two platforms","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa/"}],"id":"relationship--e4d55c6a-3f0e-5089-b920-2bdbe810c7a8","modified":"2026-08-15T05:18:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"tool--a6b5c810-d1a2-53b0-8bad-46280a0757fe","spec_version":"2.1","target_ref":"campaign--a3543588-2a5a-597f-8a13-ecbef9a0ab53","type":"relationship"},{"created":"2026-08-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Newly active ransomware leak-site operation identified by Check Point Research in its State of Ransomware Q2 2026 report (2026-08-13) as one of the quarter's fastest-growing groups. Check Point records that Krybit, alongside The Gentlemen, targets the United States noticeably less often than the ecosystem average, and names the two of them as the main reason the US share of leak-site victims fell from 50% in Q1 2026 to 42% in Q2. No tooling, initial-access tradecraft or attribution is published for the group in that report.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:krybit","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Akrybit/"}],"id":"intrusion-set--9fafc7cc-fc4d-5135-854d-fe7b5c9123ff","labels":["actor"],"modified":"2026-08-16T23:59:00.000Z","name":"Krybit","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["Earth Alux","REF7707","CL-STA-0049"],"created":"2026-08-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"China-based hackers-for-hire group that Symantec's Threat Hunter Team describes as running two missions from one team, shared infrastructure and a single control panel: espionage against government ministries and militaries across the Middle East, Southeast Asia and South Asia, and a for-profit cryptocurrency-fraud business aimed at Chinese-speaking victims. Symantec states the group is also tracked as Earth Alux, REF7707 and CL-STA-0049, and assesses with high confidence that its fraud and search-engine-optimisation arm is run by the sole legal representative of a registered Changsha company, on the basis of government-issued identity documents, a business licence and a signed authorisation letter recovered from the operators. Its largest documented operation compromised a state telecommunications provider's shared web-hosting platform to plant a watering hole on more than 15 government webmail tenants at once (Symantec Threat Hunter Team, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:jewelbug","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ajewelbug/"}],"id":"intrusion-set--b6f16400-b4aa-56d6-99c5-5d4167009834","labels":["actor","china-nexus"],"modified":"2026-08-16T23:52:00.000Z","name":"Jewelbug","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Jewelbug's Windows backdoor, delivered through malicious HTML Application downloaders themed on current geopolitical events and as a fake Adobe Flash or Adobe installer downloaded from group-controlled domains. It uses the Microsoft Graph API as its command-and-control channel so its traffic sits inside legitimate Microsoft cloud services, and on installation it side-loads the group's 'PDF Viewer' browser extension into the victim's browser profile, drops the native-messaging helper and writes the registry value that enables it (Symantec Threat Hunter Team, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:antino","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aantino/"}],"id":"malware--042f3193-746d-51c0-b687-d48268b947f4","is_family":true,"labels":["malware"],"modified":"2026-08-16T04:40:00.000Z","name":"Antino","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Jewelbug's primary implant: a malicious extension built for both Chrome and Firefox that masquerades as a document reader while requesting cookies, scripting, debugger access, web-request interception, download monitoring and native messaging across all sites. A background service worker gives the operator a full bridge into the browser API; it harvests credentials by hooking login forms, exfiltrates the cookie jar, subscribes to live cookie-change events to steal new session tokens in near real time, and captures history, bookmarks, screenshots, clipboard and intercepted traffic. It escapes the browser sandbox through a native-messaging host registered under the misleading name com.microsoft.runedge, which runs operator commands through the Windows command interpreter. A clipboard module able to swap copied cryptocurrency addresses is present and was active on victims, but Symantec records that no address-replacement rules were deployed during the observed period (Symantec Threat Hunter Team, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:jewelbug-pdf-viewer-extension","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Ajewelbug-pdf-viewer-extension/"}],"id":"malware--4aad1608-ae33-5a16-b59d-5ebed6a33d4a","is_family":true,"labels":["malware"],"modified":"2026-08-16T04:40:00.000Z","name":"PDF Viewer (Jewelbug browser extension)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Rust implant developed by Jewelbug for servers and network devices rather than browsers, observed by Symantec across 37 builds spanning x86-64 servers, ARM64 devices and consumer routers. It supports five command-and-control transports including a custom DNS tunnel and offers an interactive shell, SOCKS pivoting and the ability to load kernel modules directly from memory; a companion toolkit adds a kernel-module rootkit and a malicious authentication module hooked into su and sudo to steal credentials. Its command-and-control server was hosted on the same network range as the XG-Web server (Symantec Threat Hunter Team, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:clientking","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aclientking/"}],"id":"malware--a36b2b0f-44f8-5b37-8ec7-ced655cc873e","is_family":true,"labels":["malware"],"modified":"2026-08-16T04:40:00.000Z","name":"ClientKing","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mirai-derived modular Linux botnet documented by FortiGuard Labs on 2026-08-13 and active since at least July 2026, named after a hardcoded string present in every sample. It reuses the leaked Mirai denial-of-service engine and adds encrypted command-and-control over TCP/443, an SSH brute-force scanner with a 150-entry dictionary carrying enterprise service-account names and two-stage honeypot detection, a SOCKS5 relay in both direct and reverse modes, an HTTP credential sniffer that reads the kernel TCP connection table for Basic-Auth and cookie headers, and an exploit module that reaches Atlassian Confluence, WSO2 products and the Kubernetes ingress-nginx admission controller alongside the usual consumer router, camera and OT-gateway targets (FortiGuard Labs, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:evooo1bot","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aevooo1bot/"}],"id":"tool--69d2a939-ad6e-5f29-9c9f-42b25e0f5de0","labels":["tool"],"modified":"2026-08-16T05:40:00.000Z","name":"Evooo1Bot","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-16T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Jewelbug's browser-centric remote-access and information-stealing control panel — a React front end over a Node.js backend with a MySQL database that doubles as the rendezvous point for victim implants. Its developers describe it in their own documentation as a 'penetration-testing platform', while its internal function names include browser hijacking, data theft and man-in-the-middle attack. It administers both the group's government-espionage campaigns and its cryptocurrency-fraud operation, and its victim database recorded more than one million implant check-in rows and more than 580,000 stolen browser cookies (Symantec Threat Hunter Team, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:xg-web","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Axg-web/"}],"id":"tool--947c79a5-e802-56ab-af98-1a084d2c1391","labels":["tool"],"modified":"2026-08-16T04:40:00.000Z","name":"XG-Web","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-16T04:40:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Symantec describes the malicious Chrome and Firefox extension posing as 'PDF Viewer' as the group's primary implant","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole/"}],"id":"relationship--a4d19267-e7a8-5439-876c-e44a04f80493","modified":"2026-08-16T04:40:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b6f16400-b4aa-56d6-99c5-5d4167009834","spec_version":"2.1","target_ref":"malware--4aad1608-ae33-5a16-b59d-5ebed6a33d4a","type":"relationship"},{"created":"2026-08-16T04:40:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Symantec counts 37 builds of the Rust implant the group's developers call ClientKing, reaching servers and network devices","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole/"}],"id":"relationship--c45d50e9-f7f4-5078-91c9-325f5f800178","modified":"2026-08-16T04:40:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b6f16400-b4aa-56d6-99c5-5d4167009834","spec_version":"2.1","target_ref":"malware--a36b2b0f-44f8-5b37-8ec7-ced655cc873e","type":"relationship"},{"created":"2026-08-16T04:40:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Symantec states both the espionage and crypto-fraud missions are administered from a single control panel, XG-Web","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole/"}],"id":"relationship--cd4a4fbe-8609-5562-8efd-cd6228cdf122","modified":"2026-08-16T04:40:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b6f16400-b4aa-56d6-99c5-5d4167009834","spec_version":"2.1","target_ref":"tool--947c79a5-e802-56ab-af98-1a084d2c1391","type":"relationship"},{"created":"2026-08-16T04:40:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Symantec names Antino as the group's main implant and Windows backdoor","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-16/jewelbug-pdf-viewer-extension-native-messaging-webmail-hole/"}],"id":"relationship--e4f4e1fc-4309-5b91-aa6b-f46a5063aa8d","modified":"2026-08-16T04:40:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b6f16400-b4aa-56d6-99c5-5d4167009834","spec_version":"2.1","target_ref":"malware--042f3193-746d-51c0-b687-d48268b947f4","type":"relationship"},{"aliases":["Transparent Tribe"],"created":"2026-08-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Pakistan-linked espionage cluster historically documented against government, military and diplomatic organisations in India and the wider South Asian region. Acronis Threat Research Unit assesses with moderate confidence that the PATCHCORD / SHEETCORD / HACKERAI activity against Afghan telecom providers and South Asian critical infrastructure overlaps with this cluster or a closely related Pakistan-linked actor, resting on sustained Afghan telecom and government targeting, a browser-credential harvesting tool previously seen in the group's operations, a command-and-control framework independently documented as part of its toolkit, and a Google Sheets channel resembling earlier work attributed at medium confidence to the same cluster (Acronis TRU, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:apt36","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aapt36/"}],"id":"intrusion-set--2f0d1d97-f82b-5fe1-bbe3-b81d635ceaea","labels":["actor"],"modified":"2026-08-17T04:28:31.000Z","name":"APT36","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Third implant in the PATCHCORD cluster, distributed from the earliest domain in the operator's infrastructure and named by Acronis Threat Research Unit. It shares the cluster's system fingerprinting, remote command execution and browser-shortcut hijacking, but replaces PATCHCORD's custom HTTP server and SHEETCORD's Google Sheets with GitHub Gists for both tasking and exfiltration — a third distinct command-and-control mechanism across one operator's toolset. Its anti-analysis features are comparatively basic, including a routine that loads placeholder strings in a loop with randomised sleeps to introduce execution delays without calling conventional sleep APIs (Acronis TRU, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:hackerai-c2-agent","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Ahackerai-c2-agent/"}],"id":"malware--3d93c488-15f6-5192-9e24-1f5637e57db3","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:58:00.000Z","name":"HACKERAI C2 Agent","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Compiled C/C++ Windows backdoor delivered through Inno Setup installers impersonating Afghan Telecom service-management and VPN software and Afghanistan's Ministry of Communications and Information Technology. It persists by rewriting Microsoft Edge, Google Chrome and Mozilla Firefox shortcuts across five locations to launch itself with the real browser path as an argument while preserving the original icon, fingerprints the host, and polls a hardcoded server. Its most consequential command decodes an operator-supplied payload and executes it entirely in memory via VirtualAlloc, VirtualProtect and CreateThread, writing nothing to disk. A different variant, used in what Acronis calls an earlier campaign against India's energy sector in March 2026, carries virtual-machine, debugger, analysis-process and user-input checks that trigger a randomised sleep rather than process termination (Acronis TRU, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:patchcord","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Apatchcord/"}],"id":"malware--41e065de-dbac-59e7-8d73-45a13c2ea081","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:58:00.000Z","name":"PATCHCORD","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-17T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Go-based Windows implant from the same operator as PATCHCORD, whose command-and-control runs through the Google Sheets API v4: it authenticates with a cloud service-account credential hardcoded in the binary and creates a per-victim tab in the operator's spreadsheet for bidirectional tasking and results, a design Acronis records as consistent with the previously documented SHEETCREEP implant. It runs commands through PowerShell with script-block wrapping rather than the Windows command interpreter, collects markedly less host information than PATCHCORD, widens the browser-shortcut hijack from three browsers to six by adding Brave, Opera and Vivaldi using a generated temporary script instead of COM interfaces, and adds Startup-folder script persistence with a matching per-user Run key written by shelling out to reg.exe (Acronis TRU, 2026-08-13).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:sheetcord","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Asheetcord/"}],"id":"malware--8d1ecbb6-a101-55f8-9313-a94752270a4b","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:58:00.000Z","name":"SHEETCORD","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-17T04:28:31.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Acronis records SHEETCORD as combining functionality previously observed in the SHEETCREEP RAT with capabilities introduced in PATCHCORD, on shared operator infrastructure (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack/"}],"id":"relationship--099f1817-17be-5a29-9033-11d323dafe00","modified":"2026-08-17T04:28:31.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"malware--8d1ecbb6-a101-55f8-9313-a94752270a4b","spec_version":"2.1","target_ref":"malware--41e065de-dbac-59e7-8d73-45a13c2ea081","type":"relationship"},{"created":"2026-08-17T04:28:31.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Acronis TRU assesses at moderate confidence that the activity overlaps with the APT36 cluster or a closely related Pakistan-linked actor; the lab states an overlap, not an attribution (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack/"}],"id":"relationship--11211e8e-9edd-5f49-a2bd-46d67a0a6765","modified":"2026-08-17T04:28:31.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"malware--41e065de-dbac-59e7-8d73-45a13c2ea081","spec_version":"2.1","target_ref":"intrusion-set--2f0d1d97-f82b-5fe1-bbe3-b81d635ceaea","type":"relationship"},{"created":"2026-08-17T04:28:31.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Acronis states HACKERAI C2 Agent shares multiple capabilities with PATCHCORD and SHEETCORD, differing in its command-and-control transport (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-17/patchcord-sheetcord-google-sheets-c2-browser-shortcut-hijack/"}],"id":"relationship--5f7920ff-bcaf-5de0-a08e-39bb91fe3b2b","modified":"2026-08-17T04:28:31.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"malware--3d93c488-15f6-5192-9e24-1f5637e57db3","spec_version":"2.1","target_ref":"malware--41e065de-dbac-59e7-8d73-45a13c2ea081","type":"relationship"},{"created":"2026-08-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Attack on the Upper Austrian Chamber of Labour's IT systems on 2026-08-10, disclosed to members on 2026-08-16. Unknown perpetrators reached parts of the IT estate and obtained access to data; the organisation states the extent cannot be established — nor whether and which members' personal data were specifically affected — because the attackers deliberately removed the traces, so it is treating all member data it holds as potentially affected and notifying every member individually by post under Article 34 GDPR. Police and the Austrian data protection authority were notified and the whole data and IT infrastructure was moved into a segregated environment. No ransomware family, actor or initial-access vector has been disclosed by any party (Arbeiterkammer Oberösterreich, 2026-08-16; APA via news.at, 2026-08-17).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:ak-oberoesterreich-cyberattack-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aak-oberoesterreich-cyberattack-2026-08/"}],"id":"incident--5c169d56-b065-57dd-9176-ae71e6f0adbe","labels":["incident"],"modified":"2026-08-23T23:54:00.000Z","name":"Arbeiterkammer Oberösterreich cyberattack (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Trial opened at Zurich District Court on 2026-08-17 of a 52-year-old Ukrainian software developer resident in canton Basel-Landschaft, in custody since October 2021, charged with commercial extortion, multiple counts of serious data corruption, serious money laundering and possession of child pornography over an international ransomware operation running December 2018 to May 2020. The indictment lists ten victim companies, four of them Swiss — Stadler Rail, Meier Tobler, Crealogix and IHI Ionbond (20 Minuten) — with Netzwoche placing the ten across Switzerland, France, Norway, Scotland, Canada, the Netherlands and the United States, with economic damage put by the prosecution above CHF 100 million (20 Minuten) or above CHF 130 million (Netzwoche); three non-Swiss victims paid CHF 4.5 million in ransoms and the Swiss companies paid none. The charge sheet describes the intrusion pattern as obtaining access, switching off monitoring processes, then encrypting servers and workstations including backup files, with roughly 500 GB exfiltrated from Stadler Rail under threat of publication. Prosecutors allege the group's Moscow-based principal operated under a cover identity of Russia's FSB; the defendant contests the charges and no verdict has been reached (cash.ch, 20 Minuten, Netzwoche, 2026-08-17).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:zurich-lockergoga-megacortex-nefilim-trial-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Azurich-lockergoga-megacortex-nefilim-trial-2026/"}],"id":"incident--fc1499d4-8791-58e9-b867-8aa80f99dc54","labels":["incident"],"modified":"2026-08-23T23:59:50.000Z","name":"Zurich District Court LockerGoga / MegaCortex / Nefilim ransomware trial (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"One of three ransomware families named in the Zurich District Court charge sheet covering an operation that ran December 2018 to May 2020, on trial from 2026-08-17; prosecutors allege the accused developed it largely independently on the instruction of a co-accused based in Moscow (cash.ch, 2026-08-17). The charge sheet attributes attacks using the three families collectively and no source in this run's reporting separates which victims received which family. The operation's pattern as described in the indictment was to obtain access, disable monitoring processes, then encrypt servers and workstations (cash.ch), with the stated objective of encrypting data including backup files (20 Minuten, 2026-08-17).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:lockergoga","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Alockergoga/"}],"id":"malware--0740e4da-9598-57b1-81ac-66f51e6418a2","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:59:20.000Z","name":"LockerGoga","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware family named in the Zurich District Court charge sheet alongside LockerGoga and MegaCortex for the December 2018 to May 2020 extortion operation prosecuted from 2026-08-17. The charge sheet attributes cyberattacks using all three families to the accused; no source in this run's reporting separates which victims received which family (Netzwoche, 2026-08-17).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:nefilim","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Anefilim/"}],"id":"malware--25cb85d3-54b2-5ac6-890c-36763c5fd57a","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:59:20.000Z","name":"Nefilim","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-18T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware family named in the Zurich District Court charge sheet alongside LockerGoga and Nefilim for the December 2018 to May 2020 extortion operation; prosecutors allege the accused contributed to its development after building LockerGoga (cash.ch, 2026-08-17). Netzwoche reports the operation as a whole reaching ten companies in Switzerland, France, Norway, Scotland, Canada, the Netherlands and the United States; no source in this run's reporting separates which victims received which family (Netzwoche, 2026-08-17).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:megacortex","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Amegacortex/"}],"id":"malware--85c9a0cd-ef7d-5e03-ad8e-098c698c49c4","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:59:20.000Z","name":"MegaCortex","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-18T04:50:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"named in the Zurich charge sheet as one of the three ransomware families deployed in the prosecuted operation","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims/"}],"id":"relationship--6b4c2e8f-e472-5960-8f7c-03fb9cb41273","modified":"2026-08-18T04:50:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"incident--fc1499d4-8791-58e9-b867-8aa80f99dc54","spec_version":"2.1","target_ref":"malware--25cb85d3-54b2-5ac6-890c-36763c5fd57a","type":"relationship"},{"created":"2026-08-18T04:50:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"named in the Zurich charge sheet as one of the three ransomware families deployed in the prosecuted operation","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims/"}],"id":"relationship--cff0ac54-7564-505b-b5f1-51808840a547","modified":"2026-08-18T04:50:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"incident--fc1499d4-8791-58e9-b867-8aa80f99dc54","spec_version":"2.1","target_ref":"malware--0740e4da-9598-57b1-81ac-66f51e6418a2","type":"relationship"},{"created":"2026-08-18T04:50:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"named in the Zurich charge sheet as one of the three ransomware families deployed in the prosecuted operation","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-18/zurich-trial-lockergoga-megacortex-nefilim-swiss-victims/"}],"id":"relationship--d406e52b-e037-5a07-abc8-a992477b76cf","modified":"2026-08-18T04:50:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"incident--fc1499d4-8791-58e9-b867-8aa80f99dc54","spec_version":"2.1","target_ref":"malware--85c9a0cd-ef7d-5e03-ad8e-098c698c49c4","type":"relationship"},{"created":"2026-08-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Criminal toolkit operation first observed by Check Point Research in mid-May 2026 that hosts its payload delivery, command-and-control and stolen-data collection on compromised WordPress sites rather than on dedicated infrastructure, with close to 2,000 hijacked domains listed in the operators' own tracking files. Persistence on each site is a must-use plugin written to wp-content/mu-plugins/wp-sec.php — auto-loaded on every request and absent from the standard plugin list — registering a hidden REST route authenticated by hardcoded credentials that writes files, including PHP, almost anywhere under the site root, after which the installer deactivates and self-deletes. Delivery is a fake-CAPTCHA paste-and-run lure leading through two PowerShell and two .NET in-memory loader stages to a component set covering file encryption, an SMB/USB worm, a script spreader, a lock screen, a credential and screenshot collector and an operator chat utility. Check Point states no initial WordPress compromise vector, names no actor, and asserts no lineage to any previously tracked operation (Check Point Research, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:stopandprotect","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Astopandprotect/"}],"id":"campaign--a25ce59a-9928-5c5d-abc9-a3a3d59f66c0","labels":["campaign"],"modified":"2026-08-23T23:58:00.000Z","name":"StopAndProtect","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"aliases":["Jasper Sleet","UNC5267","Wagemole","Famous Chollima"],"created":"2026-08-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Recorded Future's designation for the North Korean IT-worker cluster — a state-directed network of covert technology workers who pose as independent contractors and job-seeking developers to obtain remote employment, with earnings funnelled back through layered individual accounts. Insikt Group states the group overlaps with the vendor designations Jasper Sleet, UNC5267, Wagemole and Famous Chollima. Between late 2024 and early 2025 one cluster applied to over 1,100 companies, at times 60 positions a day, running at least 22 fabricated personas, some of which Insikt records as supported by AI-generated profile photographs from a face-swapping service, identity documents from an illicit document-generation service and purpose-configured chatbot assistants used to answer interview questions in real time, alongside fabricated code-hosting contribution histories; Insikt assesses the operators were highly likely employed by at least ten organisations. Employer-issued laptops are physically held by facilitators and worked remotely over commercial remote-desktop software with a commercial VPN marketed for circumventing China's national firewall, and Insikt places many operators' nexus in Shenyang, China. Roughly 80% of target companies were North American but operators applied in every region of the world (Insikt Group, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:purpledelta","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Apurpledelta/"}],"id":"intrusion-set--bae8d1dc-41d8-5ab6-b1ac-6763b8650a25","labels":["actor","north-korea-nexus"],"modified":"2026-08-28T06:32:00.000Z","name":"PurpleDelta","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"File-encryption component of the StopAndProtect operation documented by Check Point Research on 2026-08-18. It retrieves an operator-supplied command file from the operation's base command-and-control host dictating which hostnames to encrypt, and derives a per-file key from a password and machine-name pair that the operator embeds in the renamed encrypted filename. Encryption is not deployed against every victim of the operation — many are only mined for data — which is why Check Point extended the name from this component to the operation as a whole (Check Point Research, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:silentencryptor","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Asilentencryptor/"}],"id":"malware--447d0c84-a4fd-5ed5-91b2-ea23de97c40a","is_family":true,"labels":["malware"],"modified":"2026-08-19T05:35:00.000Z","name":"SilentEncryptor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-19T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service operation that emerged in 2021 as a closed group and moved to an affiliate model in 2023, tracked by CISA, the FBI and HHS in the joint #StopRansomware advisory AA25-071A. The 2026-08-18 update, carrying FBI investigative data through April 2026, raised the recorded victim count from more than 300 to more than 500; the only sector list the cited reporting carries covers medical, education, legal, insurance and manufacturing. The agencies state affiliates exploit newly announced vulnerabilities within 24 hours and have been observed using exploits up to a week before public disclosure while developing no zero-day or N-day flaws of their own, obtaining that exploit access from sources the agencies could not identify. Separately from exploit access, initial-access brokers who sell entry into victim networks are paid between $100 and $1 million with a premium for exclusivity; post-compromise the affiliates use legitimate remote-management software and RDP rather than bespoke tooling. The group had added no new leak-site victims since April at the time of the update (CyberScoop and The Record, both 2026-08-18). Distinct from the unrelated MedusaLocker and MedusaHVNC families already tracked in this registry.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:medusa","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Amedusa/"}],"id":"malware--e955b109-ca53-57d1-8a2c-8d657b3ee1e4","is_family":true,"labels":["malware"],"modified":"2026-08-19T05:20:00.000Z","name":"Medusa","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-19T05:35:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Check Point names SilentEncryptor as the operation's file-encryption component, unpacked by its third-stage .NET loader","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-19/stopandprotect-wordpress-hosted-extortion-mu-plugin/"}],"id":"relationship--8ad1a619-a420-5adf-bb6c-ab134e14ccf1","modified":"2026-08-19T05:35:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--a25ce59a-9928-5c5d-abc9-a3a3d59f66c0","spec_version":"2.1","target_ref":"malware--447d0c84-a4fd-5ed5-91b2-ea23de97c40a","type":"relationship"},{"created":"2026-08-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The Spanish regional government of Castilla-La Mancha confirmed a cyberattack and the activation of its response protocols after the Panzer extortion group listed it and claimed roughly 3 GB of student, family and school-administration records; the government has confirmed neither the volume nor the data categories, and no intrusion vector has been stated (Escudo Digital, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:castilla-la-mancha-panzer-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Acastilla-la-mancha-panzer-breach-2026/"}],"id":"incident--08ef67e5-3ca3-52d5-a259-cc8d12a24a40","labels":["incident"],"modified":"2026-08-23T23:54:00.000Z","name":"Castilla-La Mancha regional government cyberattack (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Targeted intrusion into an internet-exposed system of Latvia's Road Traffic Safety Directorate between 8 and 10 August 2026, exfiltrating payment-receipt data dating to 2008 on 1.2 million individuals and 200,000 legal entities. Detected and stopped by the agency's own staff within hours; the outsourced provider contracted for round-the-clock monitoring neither detected nor reported it. The supervisory board resigned (CERT.LV, 2026-08-18; The Record, 2026-08-19).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:latvia-csdd-breach-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Alatvia-csdd-breach-2026/"}],"id":"incident--4b7db2a5-1e1a-5610-9809-f24660efa076","labels":["incident"],"modified":"2026-08-23T23:54:00.000Z","name":"Latvia CSDD payment-receipt data breach (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"aliases":["Ransom Busters LTD"],"created":"2026-08-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Persona that emails ransomware victims before their incident is public, posing as an independent recovery service and offering to return files and delete stolen data for $20,000-$60,000. GuidePoint Security's research team assesses with moderate confidence that it is a single ransomware affiliate working across several ransomware-as-a-service programmes and diverting payments from them, on the basis of an identical tooling and artefact set recurring across incidents attributed to different brands (GuidePoint Security, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:ransom-busters","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aransom-busters/"}],"id":"intrusion-set--1a0ed71f-12ca-580e-8816-a9611dc74ef0","labels":["actor"],"modified":"2026-08-20T04:52:00.000Z","name":"Ransom Busters","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Iran-based company that, per a US Department of Justice superseding indictment unsealed 2026-08-18, has since at least 2013 run intrusions on behalf of the Islamic Revolutionary Guard Corps against 144 US and 178 foreign universities, at least 42 US and 11 foreign companies, at least five US federal and state agencies and two NGOs; DOJ names Switzerland among both the foreign-university and foreign-company victim countries. Tradecraft is spearphishing against academic staff with reuse of stolen credentials, and password spraying against corporate and government targets. Allegations untested in court.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:mabna-institute","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Amabna-institute/"}],"id":"intrusion-set--88e43492-b073-5146-8bb0-ef4befc75ff0","labels":["actor","iran-nexus"],"modified":"2026-08-23T23:59:20.000Z","name":"Mabna Institute","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service operation named by GuidePoint Security as one of the programmes whose victims were approached by the Ransom Busters persona (GuidePoint Security, 2026-08-18). Distinct from the unrelated Anubis Android banking-trojan family.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:anubis-raas","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aanubis-raas/"}],"id":"intrusion-set--a33919a9-9bf4-592e-a2a4-42e23f2d3bca","labels":["actor"],"modified":"2026-08-20T04:52:00.000Z","name":"Anubis (ransomware-as-a-service)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware-as-a-service operation named by GuidePoint Security as one of the programmes whose victims were approached by the Ransom Busters persona (GuidePoint Security, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:settra","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Asettra/"}],"id":"intrusion-set--cc6a4f34-ea5b-5d6d-bf80-bf5986450b09","labels":["actor"],"modified":"2026-08-20T04:52:00.000Z","name":"Settra","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Data-extortion group that listed the Spanish regional government of Castilla-La Mancha on its leak site in August 2026 claiming roughly 3 GB of education-related records; the regional administration confirmed a cyberattack but not the group's data claims (Escudo Digital, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:panzer","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Apanzer/"}],"id":"intrusion-set--fe509532-9fd5-5e23-a900-4523feebcd87","labels":["actor"],"modified":"2026-08-23T23:54:00.000Z","name":"Panzer","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-20T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Latin American banking trojan family, targeted at financial institutions and their customers, partially disrupted by a January 2024 law-enforcement operation and still active. Acronis documented an August 2026 wave delivered by sideloading a malicious library through a renamed copy of a legitimate file-management utility, gated behind an inverted sandbox check. Distinct from the separately tracked 2026 Iberian campaign record; no cited source links the two waves.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:grandoreiro","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Agrandoreiro/"}],"id":"malware--3a2f7c32-17dd-5d07-921e-390b8cf5b6de","is_family":true,"labels":["malware"],"modified":"2026-08-20T04:56:00.000Z","name":"Grandoreiro","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-20T04:52:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"named by GuidePoint alongside DragonForce and Settra as a programme whose incidents carried the same outreach (curated relation type: collaborates-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"collaborates-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm/"}],"id":"relationship--043352f4-db21-530a-b88e-50458db29aa8","modified":"2026-08-20T04:52:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--1a0ed71f-12ca-580e-8816-a9611dc74ef0","spec_version":"2.1","target_ref":"intrusion-set--a33919a9-9bf4-592e-a2a4-42e23f2d3bca","type":"relationship"},{"created":"2026-08-20T04:52:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"named by GuidePoint alongside DragonForce and Anubis as a programme whose incidents carried the same outreach (curated relation type: collaborates-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"collaborates-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm/"}],"id":"relationship--4fabfbfa-56ee-57f5-994e-ab8e3f726a63","modified":"2026-08-20T04:52:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--1a0ed71f-12ca-580e-8816-a9611dc74ef0","spec_version":"2.1","target_ref":"intrusion-set--cc6a4f34-ea5b-5d6d-bf80-bf5986450b09","type":"relationship"},{"created":"2026-08-20T04:52:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GuidePoint states it observed the Ransom Busters outreach while responding to incidents involving DragonForce, and assesses the persona is an affiliate employed across the programmes it targets (curated relation type: collaborates-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"collaborates-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-20/ransom-busters-rogue-affiliate-fake-recovery-firm/"}],"id":"relationship--db51b4e2-201c-5ad4-b0d8-54d998856b59","modified":"2026-08-20T04:52:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--1a0ed71f-12ca-580e-8816-a9611dc74ef0","spec_version":"2.1","target_ref":"intrusion-set--dcd6f42f-c2d6-5eec-9542-7e8ccdfc7c17","type":"relationship"},{"created":"2026-08-20T05:06:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Panzer claimed the intrusion on its leak site and the regional government confirmed that an attack occurred; the group's data claims remain unverified","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-20/castilla-la-mancha-panzer-extortion-claim-confirmed-attack/"}],"id":"relationship--c973fcc3-b4f4-583a-a9ff-d14f6206ebdd","modified":"2026-08-20T05:06:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"attributed-to","source_ref":"incident--08ef67e5-3ca3-52d5-a259-cc8d12a24a40","spec_version":"2.1","target_ref":"intrusion-set--fe509532-9fd5-5e23-a900-4523feebcd87","type":"relationship"},{"created":"2026-08-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"France's consumer-protection directorate DGCCRF disclosed on 12 August 2026 that a fraudulent access to a professional account let a cybercriminal retrieve files containing 3 million telephone numbers, 600,000 of them registered on the Bloctel telemarketing opt-out list. DGCCRF states no personal data such as name or address was disclosed, that the compromised account was blocked as soon as the incident was noticed and all professional accounts subsequently reviewed, and that the Bloctel database itself was not compromised. DGCCRF names no threat actor, and no source ties this breach to the actor behind the contemporaneous DGFiP and Education Ministry intrusions — a linkage that was in circulation and does not survive tracing the citation chain (DGCCRF, 2026-08-12; OCCRP, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:france-bloctel-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afrance-bloctel-breach-2026-08/"}],"id":"incident--9dd8422d-8bc7-509e-8d11-14c008958d7b","labels":["incident"],"modified":"2026-08-21T06:45:00.000Z","name":"Bloctel telemarketing opt-out registry breach (France, 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The Ministry of National Education disclosed on 31 July 2026 a fraudulent intrusion into one of its information systems that may have led to exfiltration of personal data on a significant number of its staff. Per the ministry's own account, the data concerns agents who worked in an académie since 2001 — identity elements and professional information, status and functions — with contact details, postal address, telephone number and French social-security number for a subset; the system holds no banking data, no passwords and no student data. On 18 August 2026 the actor ZeroBytes claimed 346 million raw lines and asserted it had been detected but not evicted; the minister's office confirmed to franceinfo that the claim corresponds to the already-disclosed intrusion, and continues technical work on the actor's separate claim to hold student records. The actor link rests on French media reporting rather than an attribution by any authority, and no source states an access mechanism for this intrusion (franceinfo, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:france-education-ministry-breach-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Afrance-education-ministry-breach-2026-07/"}],"id":"incident--d4f1f78e-ce21-5a46-984d-66ac83d30dab","labels":["incident"],"modified":"2026-08-21T06:45:00.000Z","name":"French Ministry of National Education data breach (2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Loader-stage implant named by IBM X-Force for the side-loaded DLL component in ITG27 intrusion chains. It copies the side-loading pair into a new installation directory, commonly under the system-wide program-data path, establishes persistence, recovers embedded shellcode and executes the Toneshell payload by abusing a Windows locale-enumeration API as a callback. X-Force notes another vendor previously reported overlapping activity while categorising parts of the toolchain differently, so this is X-Force's own naming of a component already described elsewhere under a different grouping (IBM X-Force, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:claimloader","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aclaimloader/"}],"id":"malware--290d6cc7-e75f-5a7f-a5ac-01653dfc4dbd","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-21T06:35:00.000Z","name":"Claimloader","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-21T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Backdoor first observed by IBM X-Force in ITG27 (Mustang Panda-overlapping) activity, centred on hidden Virtual Network Computing so an operator can connect to and browse an infected desktop covertly. Delivered as a 64-bit DLL side-loaded by a legitimate signed executable, it supports a hidden-desktop VNC server on a supplied local port, a view-only mode attached to the user's existing desktop, and a generic TCP/UDP tunnel used to relay the local VNC server's traffic to the operator. It embeds no command-and-control address at all — the C2 is supplied as a command-line argument at execution time, so no infrastructure can be extracted from the binary statically (IBM X-Force, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:havencode","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Ahavencode/"}],"id":"malware--38f009ec-659f-55e0-9fed-ccc2480c6e4f","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-21T06:35:00.000Z","name":"Havencode","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"The Madrid-region municipality of Velilla de San Antonio states it detected a security incident that could have allowed the exposure of information held in its systems, that the investigation remains open and that effective access to or extraction of data cannot yet be confirmed; municipal services were unaffected, the National Cryptologic Centre and other authorities were notified, and the Community of Madrid's cybersecurity agency offered technical and coordination support. The extortion actor Kairos claims 77.6 GB including administrative and personnel records, electronically signed official documents, municipal motions and national identity documents. No access vector has been stated (Ayuntamiento de Velilla de San Antonio and EscudoDigital, 2026-08-21).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:velilla-san-antonio-kairos-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Avelilla-san-antonio-kairos-breach-2026-08/"}],"id":"incident--430aec57-c2f4-580b-8a2f-5eefed92b3e5","labels":["incident"],"modified":"2026-08-22T05:09:30.000Z","name":"Ayuntamiento de Velilla de San Antonio Kairos extortion claim (2026-08)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Shellcode-staged remote-access trojan documented by SOCRadar's Threat Research Unit and built for endpoint-sensor evasion: it recovers syscall numbers from neighbouring unhooked functions to issue direct calls, keeps only a small slice of its payload resident in memory at a time, and injects its final stage into a suspended standard Windows interface-host process. Its command-and-control configuration is held in ordinary consumer web platforms rather than on takedown-exposed attacker infrastructure. Delivered by the same FTP-banner dead-drop chain as E4del, which SOCRadar assesses is a separate cluster using the same technique (SOCRadar Threat Research Unit, 2026-08-21).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:pinhole-rat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Apinhole-rat/"}],"id":"malware--373a1356-a96e-5c04-9bb7-f4c6594cdb67","is_family":true,"labels":["malware"],"modified":"2026-08-22T05:11:30.000Z","name":"PINHOLE","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-22T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Node.js remote-access trojan documented by SOCRadar's Threat Research Unit that abuses Electron application architecture: the actors ship a legitimate, digitally signed vendor chat executable with the runtime libraries it expects and replace the contents of its resource archive with their own logic, so the operating system sees a correctly signed binary loading trusted dependencies. Runs the host application windowless, enumerates installed security products before beaconing, refuses to execute unless invoked with an argument matching the intended victim's username, and persists by registering the signed host binary as a login item. Its escalation command loads a native module SOCRadar could not retrieve, so the privilege-escalation route is unknown (SOCRadar Threat Research Unit, 2026-08-21).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:e4del","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Ae4del/"}],"id":"malware--7c268ce9-e1ff-53b8-98cf-d19822e3ad5a","is_family":true,"labels":["malware"],"modified":"2026-08-22T05:11:30.000Z","name":"E4del","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-22T05:09:30.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kairos claimed the intrusion on its own leak site and the municipality separately confirmed a security incident, but no source attributes the incident to the actor — only the actor's own claim connects them, so the edge is the generic fallback rather than attributed-to.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-22/kairos-velilla-san-antonio-second-madrid-municipality/"}],"id":"relationship--f1a34979-4f26-561f-b237-6d9c4ee58431","modified":"2026-08-22T05:09:30.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--430aec57-c2f4-580b-8a2f-5eefed92b3e5","spec_version":"2.1","target_ref":"intrusion-set--d9b4486f-34c2-596d-a056-da36e1a896aa","type":"relationship"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Bitdefender Labs designation for a cyberespionage operation it assesses at medium confidence as China-nexus, targeting government bodies handling economic policy across Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, Kazakhstan and Georgia since roughly late 2025. Seven remote-access tool families are in use, five of them newly documented; command-and-control channels include a shared Google Drive folder and HTTP cookie and ETag header values, and the toolset carries indicators Bitdefender reads as AI-assisted development at medium confidence (Bitdefender Labs, 2026-08-19).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:silkparasite-central-asia-2026","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Asilkparasite-central-asia-2026/"}],"id":"campaign--182a5c25-e284-5245-844c-df87b7833fee","labels":["campaign","china-nexus"],"modified":"2026-08-24T09:18:00.000Z","name":"SilkParasite","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"2026-08-20 crates.io account-takeover compromise of the arrayref, internment and append-only-vec Rust crates via a typosquat build-dependency impersonating proc-macro2, whose build script executed a backdoor at compile time; exposure windows of 86 to 107 minutes per crate. Discovered and reported by Nextron Systems. Wiz Research assesses the infrastructure substantially overlaps operations attributed to North Korean actors (Wiz Research; The Rust Project, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"campaign:rust-crates-arrayref-dprk-overlap-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/campaign%3Arust-crates-arrayref-dprk-overlap-2026-08/"}],"id":"campaign--4a71ef0b-a11a-567d-bcfe-dc3e21a0b71d","labels":["campaign"],"modified":"2026-08-23T23:50:00.000Z","name":"arrayref crates.io compile-time backdoor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"campaign"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"HWZ Hochschule fuer Wirtschaft Zuerich told students and alumni in August 2026 that names, addresses, phone numbers, student-administration records, bank details and sick-leave data were stolen through the infrastructure of an external IT service provider rather than from the school's own systems. The extortion group Payload listed a Zurich-area data-centre operator two days earlier, naming eight affected customer domains including the school's; no source outside that listing connects the two (Inside Paradeplatz, 2026-08-22).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:hwz-service-provider-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ahwz-service-provider-breach-2026-08/"}],"id":"incident--437a1a73-54aa-51c8-b794-78b1d23d7f58","labels":["incident"],"modified":"2026-08-23T23:54:00.000Z","name":"HWZ service-provider data breach (Switzerland, 2026-08)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Compromise of the Landesnetz, the shared network of the Berlin state administration, established by forensic investigation and confirmed by the Senate Chancellery on 2026-08-17; two Senate departments were isolated from the network from 2026-08-14 and reconnected on 2026-08-23, blocking housing-benefit disbursement to more than 50,000 entitled households and other district-level citizen services. The Landeskriminalamt, the Berlin public prosecutor and the BSI are involved. No named authority has stated an initial-access vector, product or CVE (Senatskanzlei, 2026-08-17; Berlin.de, 2026-08-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:berlin-landesnetz-compromise-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aberlin-landesnetz-compromise-2026-08/"}],"id":"incident--f70b5bd1-189a-57e8-acf5-389169376bf3","labels":["incident"],"modified":"2026-08-28T05:10:00.000Z","name":"Berlin Landesnetz compromise (August 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Suspected Russia-nexus espionage cluster tracked by Google Threat Intelligence Group and assessed with moderate confidence as a sub-cluster of the actor GTIG tracks as ICE RELIC, handling initial access. Compromises accounts by persuading targets to create an application-specific password and share it back, defeating multi-factor authentication without malware; campaigns are diplomatic or conference-themed and typically target fewer than five people at a time (Google Threat Intelligence Group, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unc6293","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunc6293/"}],"id":"intrusion-set--0785a05e-4dca-55ed-b7c7-62f135f504e5","labels":["actor","russia"],"modified":"2026-08-23T05:12:00.000Z","name":"UNC6293","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Data-extortion group operating a leak site; on 2026-08-20 it listed a Zurich-area IT and data-centre provider, claiming roughly 490 GB and naming eight affected customer domains including that of HWZ Hochschule fuer Wirtschaft Zuerich, which separately confirmed to students that data was stolen through a service provider's infrastructure. The connection between the named provider and the school rests solely on the group's own listing (Ransomware.live listing, 2026-08-20; Inside Paradeplatz, 2026-08-22).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:payload-ransomware","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Apayload-ransomware/"}],"id":"intrusion-set--1e8dd399-5783-5a57-b4e1-27cfeb1de442","labels":["actor"],"modified":"2026-08-23T23:54:00.000Z","name":"Payload","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Suspected Russia-nexus espionage cluster tracked by Google Threat Intelligence Group since March 2026 and assessed as operationally distinct from the ICE RELIC-linked clusters. Buys file-sharing-themed domains, stands up a cloud project per domain, and harvests OAuth tokens after routing targets through a genuine consent flow; also distributed the HEADRUSH malicious spreadsheet plugin (Google Threat Intelligence Group, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:unc5976","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aunc5976/"}],"id":"intrusion-set--67d4a188-90b9-5fef-8b1a-53c22593f0e8","labels":["actor","russia"],"modified":"2026-08-23T05:12:00.000Z","name":"UNC5976","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Cisco Talos designation for a Chinese-speaking, financially motivated intrusion actor compromising internet-facing IIS and Linux web servers and monetising them through search-engine fraud. Notable for the SPECTRE cross-platform implant and for incorporating agentic AI across its exploitation lifecycle, which Talos assesses at moderate-to-high confidence (Cisco Talos, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:uat-10147","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Auat-10147/"}],"id":"intrusion-set--6bc3314e-95d1-551e-83c6-a8164978508b","labels":["actor"],"modified":"2026-08-23T23:56:00.000Z","name":"UAT-10147","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Espionage cluster tracked by Kaspersky against Russian organisations; Kaspersky reclassified it from hacktivist to APT in its 2026-08-11 report, citing TTP sophistication and the absence of destructive activity. Observed since at least July 2026 chaining CVE-2026-72529 and CVE-2026-72530 against unpatched TrueConf Server instances to plant a web shell and replace the server's distributed Windows client installer with a trojanised copy carrying PhantomCore (Kaspersky ICS CERT / Securelist, 2026-08-11/12).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:head-mare","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Ahead-mare/"}],"id":"intrusion-set--90d6c4c4-7c22-565c-a1a9-479227492155","labels":["actor"],"modified":"2026-08-24T09:15:00.000Z","name":"Head Mare","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"macOS remote-access tool and stealer delivered through malicious copy-and-paste lures, resolving its command-and-control address from a public Polygon blockchain smart contract with Telegram and Steam profiles as redundant dead drops, and persisting through a launch agent (Red Canary, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:phexia","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aphexia/"}],"id":"malware--16d4f114-c36d-5619-9ca4-9a9a85544ea3","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:58:00.000Z","name":"Phexia","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Six-stage macOS infostealer and remote-access tool analysed by Huntress, delivered through a sponsored search result leading to a publicly shared conversation page on the genuine claude.ai domain that instructs the victim to paste a curl one-liner into Terminal. Stages run a polymorphic zsh loader in memory, a server-side AppleScript stealer, a Mach-O remote-access tool persisting via a launch agent, a helper for the screen-recording permission and a set of wallet-application trojans; collection covers browser cookies and logins, keychain secrets, Telegram sessions, SSH and cloud keys (Huntress, 2026-08-17).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:macsync","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Amacsync/"}],"id":"malware--3ac00022-8b57-5292-970d-533ddcd5be18","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:57:00.000Z","name":"MacSync","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"aliases":["Specter"],"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Cross-platform C backdoor deployed by UAT-10147, with 45 commands on Windows and 29 on Linux. The Windows variant loads one of two long-known vulnerable drivers to obtain a kernel read/write primitive and unlinks process-creation, thread-creation and image-load notification callbacks to blind callback-dependent endpoint products; the Linux variant ships an ftrace-based rootkit controlled by signals sent to a magic process id (Cisco Talos, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:spectre-uat10147","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aspectre-uat10147/"}],"id":"malware--3fd345b7-b053-56c9-a989-3addea0154e5","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:51:00.000Z","name":"SPECTRE","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky detection name for the second of two Linux backdoors Head Mare installs on compromised *nix TrueConf servers, distinct from PhantomHook. Kaspersky ICS CERT describes one of the pair as using GitHub for command and control but does not state which detection name maps to which implant (Kaspersky ICS CERT, 2026-08-12; Kaspersky Securelist detection list, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:phantomreact","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aphantomreact/"}],"id":"malware--4bcef605-b367-5ea3-9d97-c6be16dc0506","is_family":true,"labels":["malware"],"modified":"2026-08-23T05:05:00.000Z","name":"PhantomReact","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Node.js remote-access trojan targeting Windows workstations via social engineering and Linux servers via exploitation of server-side vulnerabilities, retrieving its command-and-control URL from a predefined smart contract through public Ethereum RPC endpoints; modules cover credential theft, lateral movement and web-server hijacking (Red Canary, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:etherrat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aetherrat/"}],"id":"malware--54d3caae-6e38-5140-9664-41b7bf1fc183","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:58:00.000Z","name":"EtherRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Malicious Excel plugin named by Google Threat Intelligence Group, observed in April 2026 leading to an HTML Application downloader; distributed by UNC5976 through a domain impersonating a Ukrainian research institute (Google Threat Intelligence Group, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:headrush","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aheadrush/"}],"id":"malware--5a892a89-a075-5ae5-9d5d-1ddce2d3431f","is_family":true,"labels":["malware"],"modified":"2026-08-23T05:12:00.000Z","name":"HEADRUSH","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Windows backdoor Head Mare delivers inside a trojanised TrueConf client installer, unpacked into the user's local application-data tree under a filename mimicking a Windows C-runtime component and auto-launched from a registry class registration (Kaspersky ICS CERT / Securelist, 2026-08-11/12).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:phantomcore","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aphantomcore/"}],"id":"malware--60e135a8-452e-52df-b90d-84af0994f3fe","is_family":true,"labels":["malware"],"modified":"2026-08-23T05:05:00.000Z","name":"PhantomCore","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Two-module Windows-service backdoor Head Mare installs on compromised TrueConf servers as a backup command-and-control channel, routing traffic through a compromised Microsoft OneDrive account's Graph API; Kaspersky assesses the two service installs were deliberately split across separate encoded commands to hinder EDR detection (Kaspersky Securelist, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:phantomgraph","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aphantomgraph/"}],"id":"malware--76e75a7a-33c7-569a-ba31-1380486a9f00","is_family":true,"labels":["malware"],"modified":"2026-08-23T05:05:00.000Z","name":"PhantomGraph","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Remote-access trojan in Python and C variants providing keylogging, screen capture and remote shell, delivered via CastleLoader and ClearFake precursors and resolving a dead drop through a public community profile or adversary-controlled domains (Red Canary, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:castlerat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Acastlerat/"}],"id":"malware--b0ae6163-7eef-54c7-82eb-d3c5e2620152","is_family":true,"labels":["malware"],"modified":"2026-08-23T23:58:00.000Z","name":"CastleRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kaspersky detection name for one of two Linux backdoors Head Mare installs on compromised *nix TrueConf servers. Kaspersky ICS CERT describes the pair as a rootkit that hides its files and intercepts TrueConf network functions to receive commands smuggled inside the TrueConf protocol, and a separate backdoor using GitHub for command and control, but does not state which detection name maps to which implant (Kaspersky ICS CERT, 2026-08-12; Kaspersky Securelist detection list, 2026-08-11).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:phantomhook","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Aphantomhook/"}],"id":"malware--c957de5f-465a-569a-96bd-c703447cd0c6","is_family":true,"labels":["malware"],"modified":"2026-08-23T05:05:00.000Z","name":"PhantomHook","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Open-source initial-access and post-exploitation tool for Entra ID and Microsoft 365 that presents a browser-based GUI over a local web server, centralising device-code phishing, primary refresh token theft, Windows Hello for Business key registration, MFA method manipulation and data exfiltration; Red Canary records it as the third device-code phishing tool to reach its most-prevalent list in 2026 (Red Canary, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:graphspy","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Agraphspy/"}],"id":"tool--2b12eb5a-f338-5600-bde3-826bae0fb9ed","labels":["tool"],"modified":"2026-08-23T04:46:00.000Z","name":"GraphSpy","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"AI-driven penetration-testing tool observed by Cisco Talos installed on UAT-10147's command-and-control server and used to dynamically scan web servers and execute proof-of-concept exploits (Cisco Talos, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:pentestgpt","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Apentestgpt/"}],"id":"tool--7c5e7606-24b3-55ca-8bae-470a6f53ab24","labels":["tool"],"modified":"2026-08-23T23:56:00.000Z","name":"PentestGPT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["BTR Reforged","Boot Time Removal Tool abuse"],"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Technique documented by Check Point Research on 2026-08-20 that repurposes BTR.sys, Microsoft Defender's own signed boot-time remediation driver embedded in MpEngine.dll, into a general-purpose kernel-mode file and registry primitive. Configuration is delivered as an encrypted blob in an NTFS alternate data stream on the driver file, and six action types include arbitrary file write and arbitrary registry write. No CVE was assigned; MSRC declined servicing because the technique requires pre-existing administrative privilege. Check Point observed no real-world abuse.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:btr-sys-loldriver-primitive","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Abtr-sys-loldriver-primitive/"}],"id":"tool--acd87c47-31d4-54b9-b45b-e44c310d637c","labels":["tool"],"modified":"2026-08-23T23:51:00.000Z","name":"BTR.sys weaponisation (BTR Reforged)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-23T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Source-code vulnerability-scanning framework observed by Cisco Talos installed on UAT-10147's own management server; Talos assesses with high confidence that the actor intends to use it to find flaws in target website source code and third-party libraries (Cisco Talos, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:deepaudit","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Adeepaudit/"}],"id":"tool--d35d8c02-29a9-5e5f-a2c2-d3c34292dfbb","labels":["tool"],"modified":"2026-08-23T23:56:00.000Z","name":"DeepAudit","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-23T04:58:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"custom cross-platform backdoor with BYOVD callback unlinking and a Linux ftrace rootkit","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/spectre-uat-10147-byovd-edr-callback-unlink/"}],"id":"relationship--b574521a-df2b-5ad2-9546-8d6dbfc45c9a","modified":"2026-08-23T04:58:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--6bc3314e-95d1-551e-83c6-a8164978508b","spec_version":"2.1","target_ref":"malware--3fd345b7-b053-56c9-a989-3addea0154e5","type":"relationship"},{"created":"2026-08-23T05:05:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"*nix backdoor using GitHub as its command-and-control channel","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/trueconf-server-kev-head-mare-trojanized-installer/"}],"id":"relationship--42df4f61-d3cb-533f-8f37-cc12633061fb","modified":"2026-08-23T05:05:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--90d6c4c4-7c22-565c-a1a9-479227492155","spec_version":"2.1","target_ref":"malware--4bcef605-b367-5ea3-9d97-c6be16dc0506","type":"relationship"},{"created":"2026-08-23T05:05:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"*nix rootkit listening for commands smuggled inside the TrueConf protocol","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/trueconf-server-kev-head-mare-trojanized-installer/"}],"id":"relationship--485d54a6-78ee-51fb-8758-1ea58da67707","modified":"2026-08-23T05:05:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--90d6c4c4-7c22-565c-a1a9-479227492155","spec_version":"2.1","target_ref":"malware--c957de5f-465a-569a-96bd-c703447cd0c6","type":"relationship"},{"created":"2026-08-23T05:05:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"delivered inside the trojanised TrueConf client installer","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/trueconf-server-kev-head-mare-trojanized-installer/"}],"id":"relationship--d1104f44-eda1-5ce7-b294-d57bf79a3d6c","modified":"2026-08-23T05:05:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--90d6c4c4-7c22-565c-a1a9-479227492155","spec_version":"2.1","target_ref":"malware--60e135a8-452e-52df-b90d-84af0994f3fe","type":"relationship"},{"created":"2026-08-23T05:05:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"backup command-and-control channel on compromised TrueConf servers via a stolen OneDrive account","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/trueconf-server-kev-head-mare-trojanized-installer/"}],"id":"relationship--d4a743b0-1ac1-53cf-b69c-8bc49f018148","modified":"2026-08-23T05:05:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--90d6c4c4-7c22-565c-a1a9-479227492155","spec_version":"2.1","target_ref":"malware--76e75a7a-33c7-569a-ba31-1380486a9f00","type":"relationship"},{"created":"2026-08-23T05:08:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"shared beacon endpoint pattern, TLS certificate issuer and hosting range (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk/"}],"id":"relationship--3b7d6b22-9c37-500c-ac05-6cf96e6ffa08","modified":"2026-08-23T05:08:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"campaign--4a71ef0b-a11a-567d-bcfe-dc3e21a0b71d","spec_version":"2.1","target_ref":"campaign--d95f82da-2397-5bda-991f-7e79861a2f98","type":"relationship"},{"created":"2026-08-23T05:08:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Wiz reports a shared beacon endpoint with the Mastra campaign Microsoft attributes to Sapphire Sleet at high confidence, a shared TLS certificate issuer, and an address appearing in Google GTIG analysis of the axios compromise attributed to UNC1069, a registered alias of the same cluster. Carried as Wiz's overlap observation, not as attribution. (curated relation type: overlaps-with)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"overlaps-with"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/rust-crates-arrayref-build-script-backdoor-dprk/"}],"id":"relationship--c8182b50-4445-5127-b5f4-8b479a775256","modified":"2026-08-23T05:08:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"campaign--4a71ef0b-a11a-567d-bcfe-dc3e21a0b71d","spec_version":"2.1","target_ref":"intrusion-set--e5dbd904-d76e-5265-b599-87733af3e889","type":"relationship"},{"created":"2026-08-23T05:12:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"malicious Excel plugin leading to a scripted downloader, delivered via a domain impersonating a Ukrainian research institute","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking/"}],"id":"relationship--701ccbfb-32a4-59e8-ba56-70cbf5dc9433","modified":"2026-08-23T05:12:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--67d4a188-90b9-5fef-8b1a-53c22593f0e8","spec_version":"2.1","target_ref":"malware--5a892a89-a075-5ae5-9d5d-1ddce2d3431f","type":"relationship"},{"created":"2026-08-23T05:12:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"GTIG assesses with moderate confidence that UNC6293 is a sub-cluster of the actor it tracks as ICE RELIC, an existing alias of this record","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-23/gtig-russia-clusters-app-passwords-whatsapp-linking/"}],"id":"relationship--71c1affd-cef6-5a66-a78b-7b47412a14b4","modified":"2026-08-23T05:12:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"intrusion-set--0785a05e-4dca-55ed-b7c7-62f135f504e5","spec_version":"2.1","target_ref":"intrusion-set--cd13b049-2e43-566b-a888-7d8472d2303c","type":"relationship"},{"created":"2026-08-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Social-engineering attempt against the managed-detection vendor ReliaQuest, disclosed in its own account of 2026-08-23, which describes the attempt, sets out its investigation findings, and then states that circulating claims it had been compromised or hit by ransomware are false. Per that account: a lookalike domain and counterfeit single-sign-on page behind a content delivery network, cold calls to multiple employees impersonating a named member of ReliaQuest's own security staff, one password entry and MFA-push approval yielding a view-only identity-dashboard session, and every onward application-access attempt denied by a device-trust policy requiring a managed device. ReliaQuest names no actor, and its article does not describe the claim it denies (ReliaQuest, 2026-08-23).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:reliaquest-social-engineering-attempt-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Areliaquest-social-engineering-attempt-2026-08/"}],"id":"incident--3dca9c27-201c-559a-b9e0-2cb10be96867","labels":["incident"],"modified":"2026-08-24T09:17:00.000Z","name":"ReliaQuest social-engineering attempt (August 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Previously unidentified modular loader documented by Expel on 2026-08-20, delivered by Microsoft Teams message from a company-styled onmicrosoft.com address impersonating the target's IT service desk and installed as an MSI presented as a 'PowerShell Cleaner' hosted on Azure blob storage. Six modules blending Python, PowerShell, C# and C++: a system profiler counting AD-joined computers, an in-memory DLL loader, PhishLocker (a counterfeit Windows lock screen harvesting the domain password), TrafficRedirector (a backconnect proxy defeating IP allow-listing), an interactive shell, and an outbound screen-streaming module. Expel assesses at low-to-medium confidence that it belongs to a ransomware group or an access broker selling to one (Expel, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:synkloader","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Asynkloader/"}],"id":"malware--128eaccd-c3fc-55b4-a5b6-566c41a9b0c0","is_family":true,"labels":["malware"],"modified":"2026-08-24T09:13:00.000Z","name":"SynkLoader","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Remote-access trojan newly named by Bitdefender in its 2026-08-19 SilkParasite reporting, whose command-and-control runs entirely through a shared Google Drive folder: operators drop command files in, the host polls the folder and returns results there. Executes tasking through twelve custom in-memory .NET plugins covering process listing, system and network enumeration, file management and command execution, running commands via Windows Management Instrumentation rather than spawning a command interpreter. Deployed by side-loading beside a legitimate signed Windows Defender service binary (Bitdefender, 2026-08-19).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:drivesilkrat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Adrivesilkrat/"}],"id":"malware--699549cf-55a8-5a90-b5a1-e94fda2f6236","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-24T09:18:00.000Z","name":"DriveSilkRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Remote-access trojan newly named by Bitdefender in its 2026-08-19 SilkParasite reporting that carries operator tasking inside HTTP Cookie and ETag response headers and returns results in the body, with each host deriving its own stream-cipher key and nonce from a unique system identifier plus a fixed suffix so captured traffic from one victim cannot decrypt another's. Initiates through DLL side-loading beside the legitimate Mp3tag application and runs its logic directly from the library entry point rather than an exported function (Bitdefender, 2026-08-19).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:cookietagrat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Acookietagrat/"}],"id":"malware--95a077e3-38e7-57d6-b7c1-15e3a77b3142","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-24T09:18:00.000Z","name":"CookiETagRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Go-based orchestrator newly named by Bitdefender in its 2026-08-19 SilkParasite reporting, deployed by DLL side-loading beside a still-unidentified signed host application. Ships with leftover Go test functions and a hardcoded placeholder AES key, two of the code-level indicators Bitdefender reads as AI-assisted development at medium confidence (Bitdefender, 2026-08-19).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:goginrat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Agoginrat/"}],"id":"malware--cea59164-036f-5f90-9aa1-8fe0f7b6ace1","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-24T09:18:00.000Z","name":"GoginRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"C++ remote-access trojan newly named by Bitdefender in its 2026-08-19 SilkParasite reporting, deployed by DLL side-loading beside a legitimate signed Quick Heal component. Bitdefender notes it shares a suspiciously close high-level architecture with the cluster's Go-based GoginRAT across two different languages, one of the indicators it reads as AI-assisted development at medium confidence (Bitdefender, 2026-08-19).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:nomadrat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Anomadrat/"}],"id":"malware--d64283f1-609f-513e-a817-f5a32cdb9534","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-24T09:18:00.000Z","name":"NomadRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-24T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Remote-access trojan newly named by Bitdefender in its 2026-08-19 SilkParasite reporting, carrying a configuration field still bearing an unmodified placeholder key name — one of the indicators Bitdefender reads as AI-assisted development in the cluster's toolset at medium confidence (Bitdefender, 2026-08-19).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:nodeedgerat","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Anodeedgerat/"}],"id":"malware--d7e24c95-bbb8-5b65-b72d-ef6ad55284b7","is_family":true,"labels":["china-nexus","malware"],"modified":"2026-08-24T09:18:00.000Z","name":"NodeEdgeRAT","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-24T09:18:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Bitdefender names NomadRAT among the cluster's five newly documented families","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2/"}],"id":"relationship--61a372f1-cd6f-5612-986e-ca08d3abc73d","modified":"2026-08-24T09:18:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--182a5c25-e284-5245-844c-df87b7833fee","spec_version":"2.1","target_ref":"malware--d64283f1-609f-513e-a817-f5a32cdb9534","type":"relationship"},{"created":"2026-08-24T09:18:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Bitdefender names DriveSilkRAT among the cluster's seven families and documents its Google Drive command-and-control channel","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2/"}],"id":"relationship--62dd11ed-2c89-5569-a16b-630cb4b48a2a","modified":"2026-08-24T09:18:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--182a5c25-e284-5245-844c-df87b7833fee","spec_version":"2.1","target_ref":"malware--699549cf-55a8-5a90-b5a1-e94fda2f6236","type":"relationship"},{"created":"2026-08-24T09:18:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Bitdefender names CookiETagRAT among the cluster's seven families and documents its HTTP Cookie/ETag tasking channel","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2/"}],"id":"relationship--89b989fa-3bc0-5438-a871-7190288560e8","modified":"2026-08-24T09:18:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--182a5c25-e284-5245-844c-df87b7833fee","spec_version":"2.1","target_ref":"malware--95a077e3-38e7-57d6-b7c1-15e3a77b3142","type":"relationship"},{"created":"2026-08-24T09:18:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Bitdefender names GoginRAT among the cluster's five newly documented families","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2/"}],"id":"relationship--b6983edf-9895-504d-8cfa-b6ded5594a7d","modified":"2026-08-24T09:18:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--182a5c25-e284-5245-844c-df87b7833fee","spec_version":"2.1","target_ref":"malware--cea59164-036f-5f90-9aa1-8fe0f7b6ace1","type":"relationship"},{"created":"2026-08-24T09:18:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Bitdefender names NodeEdgeRAT among the cluster's five newly documented families","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-24/silkparasite-dll-sideload-pairing-google-drive-c2/"}],"id":"relationship--e8add60e-e128-5af0-a7d4-be808a8e832e","modified":"2026-08-24T09:18:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"campaign--182a5c25-e284-5245-844c-df87b7833fee","spec_version":"2.1","target_ref":"malware--d7e24c95-bbb8-5b65-b72d-ef6ad55284b7","type":"relationship"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unauthorised access to the business email system of the Martigny-Combe (Valais) municipal secretariat, detected 2026-08-18, used to send a fraudulent message to administration contacts with possible exposure of personal data contained in that email; reported to BACS and the cantonal data-protection commissioner (SwissCybersecurity.net, 2026-08-24).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:martigny-combe-email-compromise-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amartigny-combe-email-compromise-2026-08/"}],"id":"incident--1cef93d4-4285-5928-8e79-bf1d7e357636","labels":["incident"],"modified":"2026-08-28T06:42:00.000Z","name":"Martigny-Combe municipal email compromise (Valais, Switzerland, 2026-08)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Four-day (1-4 July 2026) multi-agent AI-driven intrusion against Taiwanese government infrastructure using Hermes Agent + OpenClaw with Bayesian coordination; confirmed by Taiwan's Administration for Cyber Security on 2026-08-13, technically reconstructed by Dream Security (2026-08-12), and framed as the anchor incident of a seven-incident agentic-AI threat cluster by Tenable's Research Special Operations team (2026-08-14).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:taiwan-government-agentic-ai-intrusion-2026-07","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Ataiwan-government-agentic-ai-intrusion-2026-07/"}],"id":"incident--72c03ba9-8548-5e00-a011-d0e79e5fea3d","labels":["incident"],"modified":"2026-08-28T06:15:00.000Z","name":"Taiwan near-autonomous AI government intrusion (July 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Fédération Nationale de Protection Civile confirmed on 2026-08-21 a hack and personal-data breach on its eProtec volunteer-management platform dated to March 2026 and discovered mid-August; civil-status data, phone numbers and photographs of volunteers, former volunteers, externals and minors are affected, with no passwords or banking data involved per the federation; volume (FrenchBreaches assesses 525,000+ profiles) is not itself confirmed by the FNPC, which says it is still determining the number of people affected (Franceinfo/AFP, 2026-08-21).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:protection-civile-eprotec-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aprotection-civile-eprotec-breach-2026-08/"}],"id":"incident--7ead7bb4-5856-5568-8ff0-315b6a0fb480","labels":["incident"],"modified":"2026-08-28T06:44:00.000Z","name":"La Protection Civile eProtec platform data breach (France, 2026)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"SUEZ Eau France notified customers in August 2026 of a breach at a technical service provider, exposing identity, contact and contract data and in some cases bank details and identity documents; sourced only through specialist breach-tracking outlets relaying the customer notification letter, no A/B-grade outlet or SUEZ public statement located as of 2026-08-28.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:suez-eau-france-supplier-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Asuez-eau-france-supplier-breach-2026-08/"}],"id":"incident--83f5f961-6f40-5c8b-a46c-3d493f3336fc","labels":["incident"],"modified":"2026-08-28T06:46:00.000Z","name":"SUEZ Eau France technical-supplier data breach (France, 2026-08)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Ransomware incident disabling central HVAC and door-access monitoring at Manitoba's largest hospital and CancerCare Manitoba, disclosed 2026-08-10; no actor, vector or ransomware family named as of 2026-08-17 (Shared Health via CBC; Nozomi Networks).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:winnipeg-health-sciences-centre-ransomware-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Awinnipeg-health-sciences-centre-ransomware-2026-08/"}],"id":"incident--bda887fa-8a5a-5e72-ad85-41d1923864a8","labels":["incident"],"modified":"2026-08-28T06:48:00.000Z","name":"Winnipeg Health Sciences Centre ransomware (BMS impact)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unauthorised third-party access to roughly 8.7M customer records (car-park, lounge, Fast Track booking and airport-WiFi sign-up data) across MAG's three UK airports, disclosed 2026-08-27; no actor claimed, no access vector confirmed (MAG statement, The Register, 2026-08-27).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:manchester-airports-group-data-breach-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Amanchester-airports-group-data-breach-2026-08/"}],"id":"incident--d5f1c841-66b7-5fa6-adfd-95a489a23b0a","labels":["incident"],"modified":"2026-08-28T06:10:00.000Z","name":"Manchester Airports Group data breach","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Cyberespionage group associated with Lebanon's General Directorate of General Security (GDGS); historically linked to Bandook malware. Arctic Wolf assesses with medium confidence that Dark Caracal deployed the newly documented GoCaracal Go-based framework in a June 2026 Venezuela intrusion (Arctic Wolf Labs, 2026-08-26).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:dark-caracal","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Adark-caracal/"}],"id":"intrusion-set--54b3f5d6-3d87-5ccf-8306-3307409c988e","labels":["actor"],"modified":"2026-08-28T06:25:00.000Z","name":"Dark Caracal","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Kudelski Security's designation for a North Korea-linked actor connected via infrastructure reuse to a DPRK gambling-platform operation and the FakeCalls Android banking trojan; distinct from the registry's already-tracked PurpleDelta North Korean IT-worker cluster (Kudelski Security, 2026-08-12).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:bismarck-dprk-cybercrime","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Abismarck-dprk-cybercrime/"}],"id":"intrusion-set--981fa4f6-7014-5543-b380-be94208346cf","labels":["actor","north-korea-nexus"],"modified":"2026-08-28T06:32:00.000Z","name":"Bismarck","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"aliases":["QT","QTCYBER"],"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"PRC state-sponsored hacking-as-a-service contractor run by Nanjing Xinjiuwei Network Technology Company, staffed partly by former PLA members and paid by China's Ministry of State Security; operates the QScan/QTRouter infrastructure-quartermaster platform seized by DOJ/FBI on 2026-08-26 (DOJ affidavit and Lumen Black Lotus Labs, both 2026-08-26).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"actor:qtfy","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/actor%3Aqtfy/"}],"id":"intrusion-set--b73f7f46-882d-5335-9360-a37113ea9d09","labels":["actor","china-nexus"],"modified":"2026-08-28T06:05:00.000Z","name":"QTFY","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"intrusion-set"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Previously undocumented Go-based modular malware framework with lightweight and extended build profiles (remote shell, payload execution, browser data theft, keylogging, RDP control, SOCKS5 proxying); the extended build uses an Ethereum smart contract as a fallback C2-address resolver via eth_getStorageAt JSON-RPC calls. Linked with medium confidence to Dark Caracal (Arctic Wolf Labs, 2026-08-26).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:gocaracal","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Agocaracal/"}],"id":"malware--01b6ed64-f5c8-5bd6-b8c6-6b7a745f823e","is_family":true,"labels":["malware"],"modified":"2026-08-28T06:25:00.000Z","name":"GoCaracal","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Previously undocumented x64 remote-access trojan delivered via a four-stage BabaDeda loader chain that abuses a signed IBM SPSS IDE binary's scripting engine and smuggles shellcode via the EnumTimeFormatsEx API; hash-resolved APIs, stack-built strings, custom C2 protocol, seven persistence mechanisms (LevelBlue SpiderLabs, 2026-08-10).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"malware:cncmachinerms","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/malware%3Acncmachinerms/"}],"id":"malware--50287568-567d-5174-88ad-93f1fb2f8711","is_family":true,"labels":["malware"],"modified":"2026-08-28T06:30:00.000Z","name":"CNCMachineRMS","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"malware"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"C++ backdoor masquerading as the Windows Terminal Server SDK DLL (wtsapi32.dll) for DLL search-order hijacking; forward-exports legitimate SDK functions, encrypts stack strings, derives a per-victim identifier from the device hostname, and uses hardcoded HTTPS control servers. Attributed by Group-IB to Nimbus Manticore/Tortoiseshell (2026-08-26).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:twostroke-backdoor","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Atwostroke-backdoor/"}],"id":"tool--544055e3-3868-5a3f-a480-3e7e03c71472","labels":["iran-nexus","tool"],"modified":"2026-08-28T06:20:00.000Z","name":"TWOSTROKE(-like) backdoor","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Three-stage reconnaissance/exploitation-target-profiling pipeline (Celery/RabbitMQ task broker, rotating distributed scanner fleet, Redis results backend) used to fingerprint and profile high-value networks worldwide before handoff to the QTRouter/Fast Labyrinth proxy layer (Lumen Black Lotus Labs, 2026-08-26).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:qscan","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aqscan/"}],"id":"tool--5913c132-af70-5061-a3a4-e61be90e4f45","labels":["china-nexus","tool"],"modified":"2026-08-28T06:05:00.000Z","name":"QScan","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["Fast Labyrinth","QTProxy"],"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Operational-relay-box obfuscation network combining QScan-compromised IoT devices, leased VPS and bulk-purchased Chinese \"Airport\" commercial proxy subscriptions (fastlink.ws), used to conceal the PRC origin of QTFY customers' intrusion traffic; Lumen Black Lotus Labs' own telemetry names European infrastructure and judicial nodes among its profiled targets (Lumen Black Lotus Labs / DOJ, 2026-08-26).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:qtrouter","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aqtrouter/"}],"id":"tool--5bc5ce28-161c-5397-b1bd-f699cda539a0","labels":["china-nexus","tool"],"modified":"2026-08-28T06:05:00.000Z","name":"QTRouter","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Modular remote-access trojan / C2 framework sold on Telegram; four-stage rundll32 + reflective-DLL-loading delivery chain, registry RunOnce persistence, config stored at HKCU\\\\SOFTWARE\\\\PackClientConsole, dual-channel custom TCP C2 protocol (PLH1/PLC1 handshakes). Deployed by China-nexus actor TA4922 in tax-themed campaigns against mainland China and India (Proofpoint, 2026-08-27).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:packclient","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Apackclient/"}],"id":"tool--91090ab9-3bb3-52cf-9778-bf5bedbfb9d3","labels":["china-nexus","tool"],"modified":"2026-08-28T06:38:00.000Z","name":"PackClient","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Mandiant/Google Threat Intelligence Group's multi-agent, AI-orchestrated source-code vulnerability discovery pipeline (built on Google's Agent Development Kit); found 100+ true-positive critical vulnerabilities in a stolen corporate repository within two days during an incident-response engagement, and has produced 12+ assigned CVEs over ten months of deployment (Mandiant, 2026-08-18).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:avdh-agentic-vulnerability-discovery-harness","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aavdh-agentic-vulnerability-discovery-harness/"}],"id":"tool--a3532f3a-b69f-5a21-8f92-7f7c8e9e5fa1","labels":["tool"],"modified":"2026-08-28T06:36:00.000Z","name":"Agentic Vulnerability Discovery Harness (AVDH)","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Reverse SSH tunneling utility that connects outbound to operator infrastructure over port 443 to establish a reverse tunnel, redirecting operator-side local-port traffic back into the compromised network. Paired with the TWOSTROKE-like backdoor by Nimbus Manticore/Tortoiseshell (Group-IB, 2026-08-26).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:tortoiseshell-ssh-tunneler","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Atortoiseshell-ssh-tunneler/"}],"id":"tool--cccda2c6-f05f-57c4-b4d2-27e35ccbcf17","labels":["iran-nexus","tool"],"modified":"2026-08-28T06:20:00.000Z","name":"Nimbus Manticore reverse SSH tunneler","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-28T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Wiz's autonomous AI-driven offensive-security research tool; independently discovered and exploited a GitHub Actions command-injection vulnerability in a public Snowflake repository, including autonomous error-recovery after an initial payload attempt failed (Wiz Research, 2026-08-17). Unrelated to the malicious 'Red Agent' component of the RedC2 C2 framework (tool:redc2) despite the shared name — this is a defensive research tool, not attacker tooling.","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:wiz-red-agent","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Awiz-red-agent/"}],"id":"tool--e406557e-4bdd-5346-a32c-edd1fc3dc503","labels":["tool"],"modified":"2026-08-28T06:34:00.000Z","name":"Wiz Red Agent","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-28T06:05:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DOJ affidavit: QTFY offers QScan and QTRouter as its computer hacking services.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown/"}],"id":"relationship--e4cd3c5d-e284-57ad-8988-6ca6c37683b1","modified":"2026-08-28T06:05:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b73f7f46-882d-5335-9360-a37113ea9d09","spec_version":"2.1","target_ref":"tool--5913c132-af70-5061-a3a4-e61be90e4f45","type":"relationship"},{"created":"2026-08-28T06:05:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"DOJ affidavit: QTFY offers QScan and QTRouter as its computer hacking services.","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-28/doj-fbi-qscan-qtrouter-prc-hacking-as-a-service-takedown/"}],"id":"relationship--f6d7a226-2b66-58ea-9584-895430c6264e","modified":"2026-08-28T06:05:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--b73f7f46-882d-5335-9360-a37113ea9d09","spec_version":"2.1","target_ref":"tool--5bc5ce28-161c-5397-b1bd-f699cda539a0","type":"relationship"},{"created":"2026-08-28T06:15:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Tenable Research Special Operations team: both are tracked as nodes of the same seven-incident agentic-AI threat cluster, sharing the Hermes Agent framework, though the Taiwan operator and knaithe/KnYuan have no known organisational connection (Tenable, 2026-08-14).","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-28/taiwan-agentic-ai-intrusion-openclaw-hermes-guardrail-bypass/"}],"id":"relationship--afe44c8a-626f-5825-b4d7-967fee73517c","modified":"2026-08-28T06:15:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"related-to","source_ref":"incident--72c03ba9-8548-5e00-a011-d0e79e5fea3d","spec_version":"2.1","target_ref":"intrusion-set--94e5a8f3-e6cd-54bd-93ad-c0c1720297f1","type":"relationship"},{"created":"2026-08-28T06:20:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Group-IB attributes the TWOSTROKE-like backdoor to Nimbus Manticore/Tortoiseshell based on toolset and infrastructure analysis (Group-IB, 2026-08-26).","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-28/nimbus-manticore-twostroke-backdoor-europe/"}],"id":"relationship--b5829f69-0c94-5e01-9227-80087661913b","modified":"2026-08-28T06:20:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--4cb4e12e-405b-5791-a842-345851f38bc4","spec_version":"2.1","target_ref":"tool--544055e3-3868-5a3f-a480-3e7e03c71472","type":"relationship"},{"created":"2026-08-28T06:20:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Group-IB attributes the reverse SSH tunneler to the same actor and infrastructure cluster as the TWOSTROKE-like backdoor (Group-IB, 2026-08-26).","external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-28/nimbus-manticore-twostroke-backdoor-europe/"}],"id":"relationship--c8a297c2-5d03-5998-8316-5815dc5f3166","modified":"2026-08-28T06:20:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"uses","source_ref":"intrusion-set--4cb4e12e-405b-5791-a842-345851f38bc4","spec_version":"2.1","target_ref":"tool--cccda2c6-f05f-57c4-b4d2-27e35ccbcf17","type":"relationship"},{"created":"2026-08-28T06:25:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Arctic Wolf assesses with medium confidence that Dark Caracal deployed GoCaracal, based on convergent evidence including co-deployment with the historically-attributed Bandook malware (Arctic Wolf Labs, 2026-08-26). (curated relation type: attributed-to)","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"extension_type":"property-extension","original_type":"attributed-to"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entries/2026-08-28/gocaracal-dark-caracal-ethereum-smart-contract-c2/"}],"id":"relationship--2f168902-618c-5578-bc24-4381767a7e2f","modified":"2026-08-28T06:25:00.000Z","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"relationship_type":"authored-by","source_ref":"malware--01b6ed64-f5c8-5bd6-b8c6-6b7a745f823e","spec_version":"2.1","target_ref":"intrusion-set--54b3f5d6-3d87-5ccf-8306-3307409c988e","type":"relationship"},{"created":"2026-08-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"An unknown actor bypassed the per-person daily query limit on the eAutoIndex public vehicle-owner lookup platform (Viacar AG), shared by cantons Vaud, Aargau, Lucerne, Schaffhausen and Zug, to harvest plate/name/address data at scale in mid-August 2026; canton Valais separately reported additional extractions on its own 'ecari' platform exposing approximate owner birthdates. Both Viacar AG and canton Vaud report subsequent extortion attempts (cash.ch/AWP, Der Bund, Blick, watson.ch, 2026-08-28).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"incident:swiss-cantons-eautoindex-databulk-harvest-2026-08","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/incident%3Aswiss-cantons-eautoindex-databulk-harvest-2026-08/"}],"id":"incident--872ddae8-0ce4-5fd9-bb9b-3ade969c2850","labels":["incident"],"modified":"2026-08-29T04:09:36.000Z","name":"Swiss cantons eAutoIndex/ecari vehicle-registry data-harvesting incident","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"incident"},{"created":"2026-08-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Unauthenticated WAN-listening command backdoor (service infosrvd, UDP/9992) pre-installed on ZBT/Zbtlink router and CPE models; a 19-byte probe returns device fingerprint data, and a crafted command packet reaches root shell execution via an unsanitised system() call. VulnCheck's internet scan found 203 internet-facing instances across 22 countries (2026-08-18 to 2026-08-21) (VulnCheck, 2026-08-27).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:darklantern","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Adarklantern/"}],"id":"tool--b4c53bf8-fb45-5de7-8554-39b19c414f72","labels":["tool"],"modified":"2026-08-29T04:09:36.000Z","name":"DARKLANTERN","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"aliases":["RedShell","RedShell Linux","Red Agent"],"created":"2026-08-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Modular, actively-developed cross-platform (Windows/macOS/Linux) command-and-control framework sold on Hack Forums; version 4.0 added the native RedShell Linux implant, and the framework ships an LLM-backed 'Red Agent' component that converts natural-language operator intent into an ordered chain of beacon commands — unrelated to Wiz's own defensive research tool of the same name (tool:wiz-red-agent). Delivered in August 2026 via fourteen trojanized npm packages whose loader executes at module load with no install hook (TrendAI Research, 2026-08-20).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:redc2","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aredc2/"}],"id":"tool--d07241be-f593-543f-8755-4e9a7d86364e","labels":["tool"],"modified":"2026-08-29T04:09:36.000Z","name":"RedC2","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"},{"created":"2026-08-29T00:00:00.000Z","created_by_ref":"identity--f036f211-b77d-51bf-ace0-53fb3793d3b7","description":"Phone-home implant (process yunmgrd, UDP/10000) pre-installed on ZBT/Zbtlink router and CPE models, beaconing to ZBT's own Alibaba Cloud infrastructure with a full device fingerprint and accepting unauthenticated plaintext commands (shell execution, PPPoE credential exfiltration, DNS-hijack list read/write, reverse SSH tunnel control). VulnCheck sinkholed its abandoned backup domain and captured 392 beacons, 390 from China and 83% on China Mobile's network (VulnCheck, 2026-08-27).","extensions":{"extension-definition--43c2f12e-3951-58b0-b1ae-91e529b029b8":{"entity_key":"tool:speakingstone","extension_type":"property-extension"}},"external_references":[{"source_name":"ctipilot.ch","url":"https://ctipilot.ch/entities/tool%3Aspeakingstone/"}],"id":"tool--efa3cfa9-a02a-5192-af86-792bb5ba94c3","labels":["china-nexus","tool"],"modified":"2026-08-29T04:09:36.000Z","name":"SPEAKINGSTONE","object_marking_refs":["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"],"spec_version":"2.1","type":"tool"}],"type":"bundle"}