Category: Threat Intelligence
This Weekly Threat Advisory highlights the latest Ransomware, Malware, CVEs, Threat Actors, and Phishing Kits targeting organizations globally.
Emerging malware strains and ransomware groups are leveraging advanced exploitation techniques to bypass security defenses.
Newly disclosed CVEs are actively being weaponized by threat actors, increasing the risk of targeted attacks.
Phishing kits are evolving, enabling large-scale credential theft and unauthorized access to critical systems.
Security teams must stay vigilant, patch vulnerabilities, enhance detection, and strengthen cyber defense strategies against these evolving threats.
Weekly Threat Advisory: Drive-By Doubles + Phishing-Framework Surge + DPRK APT Triple-Track (Aug 10-16, 2026)
3,269 unique high-confidence indicators across 118 tracked clusters this cycle. Dominant signals: the drive-by fake-update domain wave scaled 2.5x from the prior week (906 attacker domains), a massive new phishing-framework infrastructure surge, three concurrent DPRK-linked APT clusters active, and a coordinated 737-extension browser abuse campaign. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, top IOCs per type, adversary analytics with platform screenshots.
Weekly Threat Advisory: Drive-By Domain Surge + 9 Concurrent Ransomware Operators (Aug 3-9, 2026)
1,827 unique high-confidence indicators across 102 tracked clusters this cycle. Dominant signal: a drive-by fake-update domain wave producing 371 attacker-registered domains from a single campaign. Nine ransomware operators active concurrently. Info-stealer and credential-drainer surge across Windows and macOS. Third consecutive week of macOS multi-family activity. Continued supply-chain wave targeting the developer ecosystem. Attributed APT clusters concurrent. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, top IOCs per type.
Weekly Threat Advisory: Framework-C2 Surge + Emerging Supply-Chain Wave (Jul 27 – Aug 2, 2026)
54,763 unique indicators across 107 tracked clusters this cycle. Dominant signal: framework-C2 infrastructure surge with 25+ concentrated /24 subnet anchors. Emerging supply-chain wave — fake npm packages, fake installers, developer-ecosystem targeting. macOS malware surge across three concurrent families. Three ransomware operators active. Iranian-linked APT clusters continue. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per type.
Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)
77,118 unique IOCs across 155 clusters this cycle. 25 attributed APT clusters ran concurrently — the widest APT footprint observed year-to-date. Two loader families produced ~15,000 unique hashes combined (polymorphic-build-farm signal). ICS/OT threat surfaced — PLC-targeted exploitation campaign with three concentrated subnet anchors. DPRK-adjacent activity double-tracked (cryptocurrency-focus + IT-worker infiltration). Russian-aligned and Middle East regional operations active. Novel SVG-embedded script delivery vector. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per indicator type.
Weekly Threat Advisory: Intel Briefing — Polygon-Based C2, 4 Chinese-Aligned APTs, 20+ Ransomware Families (Jul 13-19, 2026)
59,935 unique IOCs across 116 clusters this cycle. Polygon-based C2 surfaced (314 IOCs, novel blockchain-resolved command channel — following the TON pattern). Four Chinese-aligned APT clusters active in parallel (APT-C-60 with 121 IOCs full 5-type spread, UAT-11795, APT-C-35, APT-Q-27). 20+ ransomware families concurrent (RAWorld 213, Trigona 115, Qilin 56, MedusaLocker, Medusa, Fog, WORLDLEAKS, Spirals, Sorry + more). Package-registry supply-chain double strike (game-cheat + Go module). macOS threat layer matured (AppleScript infostealer + macOS-focused stealer + ClickFix variants). TencShell C2 operator with 4 subnet anchors (16 IPs concentrated). Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.









