HackForLab Weekly Threat Advisory · June 22-28 2026 · editorial bulletin cover · The State of the Threat · 54,820 observations · 87 clusters · 632 high-severity · 7 named APTs · 5 story cards: APT Week (Gamaredon Turla MustangPanda CL-STA-1062 Silent Lynx), DragonForce Full Kill Chain, Messaging Weaponised (WhatsApp VBScript Campaign), Supply Chain Surge (GhostShell Malicious npm Browser ad-blocker), New RAT on the Block (ModeloRAT)
0 87
Posted in Threat Intelligence

Weekly Threat Advisory: APT Surge, Ransomware Full-Pivot, Messaging Weaponised — June 22-28, 2026

54,820 indicator observations across 87 adversary clusters this week. Four state-aligned APTs active in parallel (Gamaredon, Turla, MustangPanda, CL-STA-1062 + Silent Lynx + APT-C-35 + APT38). A ransomware operator rotated a full multi-pivot kill chain in 7 days (DragonForce). Direct-messaging platforms weaponised as initial-access surface (WhatsApp VBScript Campaign, 61 IOCs, tight 202.61.160.0/24 subnet anchor). Five concurrent supply-chain campaigns against the developer ecosystem (GhostShell, Miasma, Malicious npm Package, Operation FlutterBridge, Chrome ad-blocker extension cluster). A new RAT family arrived (ModeloRAT, 39 IOCs, full footprint). Full MITRE ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.

Practitioner reference cover · Indicators of Compromise and Threat Intelligence · 6 framework cards: Pyramid of Pain, IOC Standards (STIX TAXII OpenIOC MISP), Pivoting Tradecraft (passive DNS WHOIS JARM JA4 cert), Diamond Model, TI Lifecycle + F3EAD, Detection Engineering (Sigma YARA ATT&CK Navigator SOAR) · framework chip strip: Pyramid of Pain · Diamond Model · Kill Chain · ATT&CK · STIX TAXII · Sigma YARA · F3EAD
0 75
Posted in General

Indicators of Compromise and Threat Intelligence: A Practitioner Reference

A working analyst reference. 20 sections covering the Pyramid of Pain, the atomic / computed / behavioural indicator taxonomy, the four IOC domains with field-level detail, pivoting tradecraft (passive DNS, WHOIS, JA3/JA4/JARM, TLS SAN, ASN), the standards (STIX 2.1, TAXII 2.1, OpenIOC, MISP), detection content (Sigma + YARA), IOC vs IOA vs TTP, the four TI tiers with producer-consumer contracts, the six-phase lifecycle with F3EAD overlay, intelligence requirements (PIR/SIR/KIT/KIQ), the Diamond Model of Intrusion Analysis, the Cyber Kill Chain mapped to MITRE ATT&CK, the Admiralty source reliability code, Traffic Light Protocol 2.0, the Hunting Maturity Model, detection-engineering pipelines, SOAR integration patterns, KPIs (MTTD / MTTR / dwell time / coverage / hit rate), and the practitioner reference stack. Vendor-neutral. Twelve practitioner FAQs.

HACKFORLAB Weekly Threat Advisory · June 15-21, 2026 · 55,480 indicator observations across 89 adversary clusters · radar showing intelligence graph with multi-pivot locked cluster · Rhysida-Interlock 219 IOCs, ClickFix 215 IOCs, JetBrains plugin supply chain attack, AI platform abuse, APT37 and UNC6508 active
0 88
Posted in Threat Intelligence

Weekly Threat Advisory: Cluster Analysis & Top IOCs, June 15 – 21, 2026

55,480 indicator observations across 89 adversary clusters this week. A ransomware operator rotated a full multi-pivot kill chain (Rhysida-Interlock, 219 indicators across 4 IOC types). Developer supply chain became this week’s preferred attack surface (15 typosquat code-editor plugins + 8 browser extensions + 6 marketing-CDN typosquats). AI platforms began appearing as adversary infrastructure (19 chat-share redirector domains + 39-indicator AI-generated lure campaign). Full MITRE ATT&CK mapping per cluster, subnet-clustering signals, top 15 IOCs per indicator type, and 4 production-ready Sigma rules.

The AWS Threat Hunting Library — 7 hunts every cloud SOC should run · HackForLab AWS Threat Hunting series hub
0 86
Posted in Cyber Threat

The Complete AWS Threat Hunting Library: 27 Cloud Hunts, 7 Flagship Playbooks, and the Full Archive (2026)

The definitive AWS threat hunting reference — indexing all 27 published AWS hunting posts on hackforlab.com. 7 flagship 2026 hunts (CloudTrail blind spots, KMS ransomware, GuardDuty evasion, CI/CD compromise, native messaging C2, Athena data lake exfiltration, multi-account federation), plus 19 archive posts covering AWS identity attacks, Bedrock CloudTrail playbook, VPC Flow Log analytics, cloud malware case studies, and the foundational AWS attack-chain detection content.

AWS Organizations Compromise — hunting the multi-account federation attack · HackForLab AWS Threat Hunting Part 7
0 84
Posted in Cyber Threat

AWS Organizations Compromise: Hunting the Multi-Account Federation Attack

AWS Organizations centralises governance — and that centralisation creates a high-value attack target. This article covers the four most-exploited multi-account compromise patterns, the cross-account telemetry stitching required to detect them, and the response strategies for organisation-level incident response.