Category: Threat Intelligence
This Weekly Threat Advisory highlights the latest Ransomware, Malware, CVEs, Threat Actors, and Phishing Kits targeting organizations globally.
Emerging malware strains and ransomware groups are leveraging advanced exploitation techniques to bypass security defenses.
Newly disclosed CVEs are actively being weaponized by threat actors, increasing the risk of targeted attacks.
Phishing kits are evolving, enabling large-scale credential theft and unauthorized access to critical systems.
Security teams must stay vigilant, patch vulnerabilities, enhance detection, and strengthen cyber defense strategies against these evolving threats.
Weekly Threat Advisory: APT Storm — 25 Clusters Active, Polymorphic Loader Surge, ICS/OT Threat Surface (Jul 20-26, 2026)
77,118 unique IOCs across 155 clusters this cycle. 25 attributed APT clusters ran concurrently — the widest APT footprint observed year-to-date. Two loader families produced ~15,000 unique hashes combined (polymorphic-build-farm signal). ICS/OT threat surfaced — PLC-targeted exploitation campaign with three concentrated subnet anchors. DPRK-adjacent activity double-tracked (cryptocurrency-focus + IT-worker infiltration). Russian-aligned and Middle East regional operations active. Novel SVG-embedded script delivery vector. Full ATT&CK-per-tactic pressure roll-up, four production-ready Sigma rules, subnet anchors, top IOCs per indicator type.
Weekly Threat Advisory: Intel Briefing — Polygon-Based C2, 4 Chinese-Aligned APTs, 20+ Ransomware Families (Jul 13-19, 2026)
59,935 unique IOCs across 116 clusters this cycle. Polygon-based C2 surfaced (314 IOCs, novel blockchain-resolved command channel — following the TON pattern). Four Chinese-aligned APT clusters active in parallel (APT-C-60 with 121 IOCs full 5-type spread, UAT-11795, APT-C-35, APT-Q-27). 20+ ransomware families concurrent (RAWorld 213, Trigona 115, Qilin 56, MedusaLocker, Medusa, Fog, WORLDLEAKS, Spirals, Sorry + more). Package-registry supply-chain double strike (game-cheat + Go module). macOS threat layer matured (AppleScript infostealer + macOS-focused stealer + ClickFix variants). TencShell C2 operator with 4 subnet anchors (16 IPs concentrated). Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.
Weekly Threat Advisory: Beyond Ransomware — 11 RATs, 7 APTs, 1 WIPER, HASH Still Leads (Jul 6 – 12, 2026)
The non-ransomware threat layer of the week. 1,804 unique IOCs across 89 clusters (ransomware excluded). RuRAT cryptomining surge (244 IOCs — wallet-drainer domain cluster). 11 RAT families active (Vidar, Millenium RAT v4, GoodPersonRAT, Dcrat, AsyncRAT, EtherRAT, QuimaRAT, Banana RAT + more). 7 APT clusters (UAT-7810 port fingerprint 2222/8088/99, DPRK 5-type spread, Lazarus, Cavern Manticore, MustangPanda, PlugX, UNK_MassTraction). Novel multi-stage LNK + JS-runtime backdoor (135 IOCs). GigaWiper — destructive-class malware, 10 IOCs. macOS ClickFix — first observation. HASH still beats IP (810 vs 468) even without ransomware. Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.
Weekly Threat Advisory: 5 APTs, 200 RATs, 74% High-Severity — The Week the C2 Flood Went Quiet (Jun 29 – Jul 5, 2026)
1,524 unique IOCs across 64 clusters. Extraordinary week: DOMAIN volume beat IP for the first time; 74% of records HIGH severity (usual baseline: 1-2%). 5 named APTs active (UNC1151, APT36, TeamPCP, Lazarus, BitterAPT) + CyberAv3ngers subnet anchor at 185.82.73.0/24. AsyncRAT surged to 200+ IOCs — largest RAT footprint YTD. TONResolver introduces novel blockchain-based C2 resolution. Trust-anchor phishing (Fake Google/Cloudflare verification pages, 54 IOCs, two subnet anchors). Anubis + The Gentlemen ransomware active. Steganographic ad malware (StegoAd) and AI-agent phishing surface as new attack patterns. Full ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, 4 production-ready Sigma rules.
Weekly Threat Advisory: APT Surge, Ransomware Full-Pivot, Messaging Weaponised — June 22-28, 2026
54,820 indicator observations across 87 adversary clusters this week. Four state-aligned APTs active in parallel (Gamaredon, Turla, MustangPanda, CL-STA-1062 + Silent Lynx + APT-C-35 + APT38). A ransomware operator rotated a full multi-pivot kill chain in 7 days (DragonForce). Direct-messaging platforms weaponised as initial-access surface (WhatsApp VBScript Campaign, 61 IOCs, tight 202.61.160.0/24 subnet anchor). Five concurrent supply-chain campaigns against the developer ecosystem (GhostShell, Miasma, Malicious npm Package, Operation FlutterBridge, Chrome ad-blocker extension cluster). A new RAT family arrived (ModeloRAT, 39 IOCs, full footprint). Full MITRE ATT&CK mapping per cluster, subnet anchors, top 15 IOCs per indicator type, four production-ready Sigma rules.









