CISA advisory AA26-204A (July 23, 2026) formally attributed a sustained Zimbra Collaboration Suite zero-day campaign to Laundry Bear, a Russia-state-supported actor first identified by Dutch intelligence in May 2025. The group exploited CVE-2025-66376, a 'half-click' or 'zero-click' XSS flaw in Zimbra webmail — meaning simply viewing a malicious email in a vulnerable client is enough to trigger credential and email theft, including up to 90 days of mail and 2FA bypass via IMAP application passcodes. The campaign ran from at least July 2025 through February 2026, targeting Ukrainian government agencies, US government bodies, NATO-member governments, and defense contractors before the group tore down infrastructure following public disclosure.
Documented by Symantec's Threat Hunter Team on July 16, 2026, Spirals is a previously unseen Rust-based ransomware family that struck a South Asian IT services company in June 2026, moving from initial IIS web shell upload to full network-wide encryption in under 24 hours. The ransomware uses per-file AES-128 keys wrapped with an attacker-controlled ECDH P-256 public key and deploys intermittent encryption on files over 5MB for speed. The sophistication of execution — including UAC bypass, SAM hive extraction, redundant tunneling via revsocks, Chisel, and Cloudflare Tunnels, and WMI-based lateral movement to over a dozen systems within minutes — suggests a technically capable operator likely to target more victims.
Kaspersky's Securelist published a detailed analysis on July 30, 2026 of GenieLocker, a new custom-built cross-platform ransomware family deployed by Toy Ghouls (also tracked as Bearlyfy/Labubu) exclusively against Russian Federation organizations since March 2026. The group previously relied entirely on third-party encryptors (RedAlert, LockBit, Babuk) but has now developed proprietary tooling with PE builds for Windows and ELF builds for Linux/ESXi, using libsodium's XChaCha20-Poly1305 and Curve25519 cryptography. Notably, the group does not employ double extortion — no data is exfiltrated and no ransom note is dropped on disk, with demands delivered manually to evade proactive detection.
On July 13, 2026, Microsoft published a major research mapping a year-long ShinyHunters campaign (mid-2025 to mid-2026) targeting Salesforce environments across more than 700 organizations via three distinct attack paths: vishing attacks impersonating IT support to gain OAuth consent for malicious apps, supply chain compromise through trusted integrations (Salesloft Drift in Aug 2025, Gainsight in Nov 2025, Klue in Jun 2026), and abuse of misconfigured Salesforce guest-user Aura endpoints. Because all activity flows through legitimate OAuth tokens and approved application identities, it appears indistinguishable from routine Salesforce API usage, evading conventional sign-in detections. The Klue incident (June 2026) cascaded to expose data from Huntress and Recorded Future via downstream Salesforce and Gong integrations.
Newly publicly surfaced by F6 threat intelligence in late July 2026, xplogs22 is a cybercrime group active since November 2023 that targets Russian and CIS-region organizations with phishing campaigns delivering commodity RAT malware. The group evolved its tooling from Formbook and Snake Keylogger to XWorm around July 2025, and most recently has been observed deploying LunaSpy, an Android trojan disguised as an antivirus application that captures camera streams, records audio and screen activity, and collects credentials from Russian banking customers.
BlueNoroff, the financial cybercrime arm of North Korea's Lazarus Group, has launched a highly targeted wallet-profiling operation using fake Zoom and Microsoft Teams meetings. JUMPSEC recovered live phishing kit source code after operators exposed JavaScript source maps on active infrastructure, revealing a pipeline that scans browser crypto wallets before selectively delivering malware — compromising victims in under five minutes. The campaign has hit 100+ victims across 20+ countries with 45% of targets being founders or CEOs; five distinct kit versions were shipped between May 31 and July 14, 2026 indicating rapid active development.
Cl0p affiliates are actively exploiting CVE-2026-12569 (CVSS 9.8), a critical unauthenticated RCE deserialization flaw in PTC Windchill and FlexPLM PLM platforms used by 30,000+ organizations globally. Suspected zero-day exploitation began in early June 2026 — five weeks before disclosure — with Ransom-ISAC, eCrime.ch, and DEFUSED publishing a coordinated advisory on July 25, 2026 confirming the attack chain. The campaign mirrors Cl0p's playbook from MOVEit and GoAnywhere: mass silent exploitation followed by bulk extortion emails sent to hundreds of users inside victim organizations.
Microsoft Threat Intelligence published a July 9, 2026 teardown of GigaWiper, a Golang Windows backdoor that bundles three distinct destruction mechanisms — raw disk wiper, multi-pass OS drive overwrite, and fake ransomware (.candy extension with irrecoverable key discard) — alongside full spyware and remote access capabilities, with the operator selecting the destruction mode post-compromise. Binary Defense and Google TIG track the same malware as BLUERABBIT and attribute it to an Iran-nexus cluster previously responsible for BLUEWIPE and SEWERGOO (June 2025); Crucio code lineage within GigaWiper directly matches a December 2023 CISA advisory on CyberAv3ngers, the IRGC-linked group behind 2023 US/Israeli/UK/Irish water and energy infrastructure intrusions.
PRODAFT disclosed on July 25, 2026 that DevMan (tracked as Funky Mantis) operated a highly sophisticated RaaS portal functioning as a full 'CRM for extortion' — integrating payload building, victim lifecycle management, affiliate team creation, automated profit sharing, and victim chat. DevMan emerged in April 2025 as a multi-RaaS affiliate (Qilin, DragonForce, Apos, RansomHub) before pivoting to its own operation, claiming 184 victims before going dark after February 4, 2026 following a doxxing incident by whistleblower 'GangExposed.' LARVA-367 is a former member of Phantom Mantis (The Gentlemen's affiliate cluster) with suspected but unconfirmed infrastructure overlap with The Gentlemen RaaS.
Amazon Web Services Threat Intelligence publicly attributed a sustained npm supply-chain campaign to Sapphire Sleet on July 29, 2026, connecting four previously unlinked package compromises — typo-crypto (Mar 2025), debug and chalk (Sep 2025), axios (Mar 2026), and Mastra AI framework (Jun 2026) — to the same DPRK actor. The group socially engineers trusted open-source maintainers to publish trojanized updates containing post-install hooks that steal credentials and cryptocurrency wallets. This is the first time these compromises have been publicly unified under a single DPRK attribution.
ENKI WhiteHat published a full technical analysis on July 20, 2026, disclosing that Kimsuky spent nearly a year embedded inside at least two South Korean enterprise groupware vendors, deploying two previously unknown Linux backdoors — BirdTroy and DriveTroy — that use HTTP/3 QUIC transport and Google Drive API for C2 respectively, making both families near-invisible to conventional network security tooling. By compromising the vendors, Kimsuky silently pivoted to downstream customers without triggering alerts.
Trend Micro disclosed in March 2026 that APT28 has been running the PRISMEX campaign since September 2025, deploying a novel interconnected malware suite combining steganography, COM hijacking, and cloud service C2 abuse against Ukraine's defense supply chain and allied NATO logistics. Infrastructure preparations began two weeks before the zero-day CVE-2026-21509 was publicly disclosed, confirming advance knowledge of the vulnerability. The TrendAI H1 2026 APT roundup (released July 29, 2026) confirmed Pawn Storm as one of the most active Russia-aligned threats of the first half of 2026.
Two overlapping Iran-aligned threat activities were highlighted in the TrendAI H1 2026 APT roundup (July 29, 2026): Earth Vetala (MuddyWater) scanned for a newly disclosed Ivanti vulnerability within days of its release, and separately, Iran-aligned actors conducted hands-on manipulation of internet-exposed Automatic Tank Gauge (ATG) systems at U.S. gas stations across multiple states. The ATG campaign — detected May 2026 and investigated by FBI, CISA, NSA, DOE, EPA, and TSA — tampered with fuel-level display readings and in some cases deleted sensor data, escalating in parallel with the U.S.-Israeli military campaign against Iran.
Russian state-sponsored APT group named by the Netherlands AIVD/MIVD, publicly attributed in a major joint CISA/NSA/FBI advisory (AA26-204A) on July 23, 2026. The group exploited CVE-2025-66376, a stored XSS zero-day in Zimbra Collaboration Suite's Classic UI, deploying a custom capability called 'Ulej' (Russian: beehive) to silently exfiltrate email, 2FA tokens, and app-specific passwords — requiring only that a victim view a malicious email to trigger exploitation. A notable OPSEC trait is the use of Mullvad VPN services to obscure origin, and the advisory noted possible AI-assisted development in Ulej's codebase.
TheGentlemen is a rapidly ascending Ransomware-as-a-Service operation that emerged in mid-July 2025 when a former Qilin affiliate (alias 'hastalamuerte') launched the program after a $48,000 payment dispute on the RAMP forum. By mid-2026 the group had claimed nearly 500 victims across 60+ countries, ranking second only to Qilin by leak-site volume, with a particular concentration in US healthcare and global manufacturing. A significant OPSEC failure in May 2026 exposed the group's internal Rocket.Chat platform, leaking 23 chat rooms and thousands of messages that provided unprecedented visibility into a live RaaS ecosystem, including details of the administrator's travel to Dubai, China, Vietnam, and Thailand. Romania's cybersecurity directorate linked the group to Russian state-sponsored interests following an attack on a major Romanian energy producer.
CRPxO is a newly surfaced ransomware-as-a-service operation, first observed in July 2026, with at least 6 confirmed victims across the US and China within its debut month. The group runs a double-extortion leak site and is actively recruiting affiliates at a 70/30 revenue split with a low $333 buy-in, suggesting rapid scaling intent. A significant OPSEC failure exposed its backend admin and phpMyAdmin database login pages publicly, a hallmark of immature operations — though its v2.0 platform advertises hybrid encryption, multi-stage data theft, and anti-sandbox evasion.
Newly identified group discovered by Kaspersky GReAT in July 2026, active in Colombia and Mexico between May–June 2026. XEntry Team is notable for exploiting exposed RDP and misconfigured MSSQL services — not custom malware — to encrypt drives with BitLocker and deliver ransom demands physically via corporate network printers, a rare psychological pressure tactic. Attribution between the two confirmed incidents (Colombia and Mexico) remains inconclusive per Kaspersky.
ToddyCat is a long-running APT active since at least 2020, targeting organizations across Europe and Asia. In early July 2026, Kaspersky GReAT published analysis of Umbrij — a new .NET tool used by ToddyCat that abuses Google OAuth authorization flows to silently extract Gmail access tokens from live browser sessions, converting existing Windows footholds into durable off-box access to victims' Gmail, Drive, and Calendar. The technique (Shadow Token via Remote Debug / STRD) requires no Google-side vulnerability and evades MFA on already-authenticated sessions.
Medialand LLC and ML.Cloud LLC, operated by three Russian nationals out of St. Petersburg, were indicted by the DOJ on July 14, 2026 following a seven-year FBI investigation. Described by U.S. prosecutors as the largest bulletproof hosting service in the world, Medialand's infrastructure was used by ransomware groups including LockBit, BlackSuit, and Play, and caused over $62 million in victim losses across 21 U.S. states and multiple countries. The State Department is offering a $10M reward for information on foreign government links to the operators, who remain in Russia.
ShinyHunters remained one of the most prolific data extortion actors through July 2026, with a confirmed breach of Abbott Laboratories' Cancer Diagnostics business (via a vishing campaign in mid-June 2026 that compromised a Microsoft Entra SSO account) and a subsequent claim against Fairlife, the Coca-Cola dairy brand, alleging exfiltration of 1TB of confidential data. Microsoft Defender Security Research published research on July 13 mapping a year of ShinyHunters campaigns abusing trusted OAuth relationships and long-lived application tokens across Salesforce environments, matching the Abbott intrusion's technical fingerprint. The group threatened Abbott with a July 18 deadline later extended to July 21, claiming 30M+ records including 1M+ Social Security numbers.
Chaos is a RaaS group confirmed active since February 2025 that has now introduced msaRAT, a novel Rust-based RAT discovered and detailed by Cisco Talos on July 23, 2026. msaRAT routes all C2 traffic exclusively through the victim's own Chrome or Edge browser via the Chrome DevTools Protocol (CDP), meaning the malware process itself never makes a direct network connection — defenders see only legitimate browser traffic to Cloudflare and Twilio, not attacker infrastructure. This 'living off the browser' technique represents a significant evasion advance over traditional C2 methods.
Qilin (originally launched as 'Agenda' in July 2022, rebranded as a RaaS in February 2023) remains one of the top two most prolific ransomware groups globally in 2026 with 289 victims in Q2 alone. A major campaign update disclosed July 20–22, 2026 by Arctic Wolf Labs revealed Qilin affiliates actively exploiting CVE-2026-0257, a critical PAN-OS GlobalProtect authentication bypass (CVSS 9.1), enabling unauthenticated VPN access to corporate networks and leading directly to domain-wide encryption. Multiple distinct intrusions in June 2026 were traced to this single entry point across unpatched Palo Alto Networks firewall appliances.
Media Land LLC and ML.Cloud operated what US prosecutors described as the world's largest bulletproof hosting service, providing infrastructure that concealed ransomware gangs and malware operators targeting US banks, hospitals, and government agencies. On July 14, 2026, the DOJ unsealed indictments against three Russian nationals (Alexander Volosovik, Kirill Zatolokin, and Yulia Pankova) following a seven-year FBI investigation under Operation Riptide, alleging over $62 million in losses to victims across 21 US states. The State Department is offering up to $10 million for information on foreign government-linked associates of the defendants.
CISA updated advisory AA26-097A on July 22, 2026, confirming this Iranian-affiliated APT has expanded its PLC targeting beyond Rockwell Automation to now include Schneider Electric and Siemens hardware. The FBI observed actors using vendors' own engineering software (Studio 5000, EcoStruxure Control Expert, TIA Portal) to download malicious project files directly to internet-exposed PLCs, overriding safety alarm and shutdown logic, causing confirmed operational disruption and financial loss at victim sites. The campaign, active since at least March 2026, reflects a deliberate platform shift toward Western-made controllers far more widely deployed across U.S. infrastructure.
Microsoft Threat Intelligence published a detailed teardown of GigaWiper on July 9, 2026, a Golang Windows backdoor attributed by Binary Defense and Google's Threat Intelligence Group to a likely Iran-nexus cluster (overlapping with CyberAv3ngers based on shared Crucio code fingerprints). GigaWiper is uniquely dangerous as a single implant combining espionage and three distinct operator-selectable destruction mechanisms: raw disk wipe via WMI, multi-pass Windows drive overwrite, and a fake ransomware module (.candy extension) that encrypts files while discarding keys, making recovery impossible. The malware masquerades as Microsoft OneDrive via a scheduled task and registry key, using legitimate services RabbitMQ, Redis, and MinIO for C2 to blend into normal network traffic.
GREYVIBE is a Russia-nexus threat cluster formally disclosed by WithSecure Labs on May 28, 2026, and assessed to have been active since at least August 2025. The group is distinguished by systematic weaponization of commercial AI platforms — including ChatGPT, Google Gemini, and Ideogram AI — across every stage of its attack lifecycle including lure creation, malware code generation, infrastructure setup, and post-compromise scripting. WithSecure assesses the group operates in a grey zone between state-aligned espionage and financially motivated cybercrime, with technical ties to the TrickBot gang and UAC-0098, and evidence of crypto mining on compromised hosts. Despite AI augmentation, the group exhibits low-to-moderate sophistication with notable operational security failures.
Medialand LLC and ML.Cloud LLC were indicted on July 14, 2026 in the Northern District of Ohio following a seven-year FBI investigation, charged with operating the world's largest bulletproof hosting service enabling ransomware, malware, phishing, and fraud attacks causing over $62 million in losses across 21 US states and multiple countries. Three Russian nationals — Alexander Volosovik (43), Kirill Zatolokin (34), and Yulia Pankova (29), all of St. Petersburg — face charges of computer fraud conspiracy, wire fraud, and money laundering. The U.S. State Department offered a $10 million reward for information on foreign government-linked associates, signaling possible state nexus under investigation.
UAC-0145 is a confirmed sub-cluster of Sandworm, Russia's GRU-affiliated advanced hacking unit responsible for some of the most destructive cyber operations of the past decade. CERT-UA published a major advisory on July 19, 2026 documenting a significant tactical shift: the cluster has largely abandoned torrent-distributed malware installers in favor of ClickFix-style social engineering using fake CAPTCHA prompts on compromised websites to trick Ukrainian users into self-executing malicious PowerShell commands. The campaign employs blockchain-based C2 obfuscation via the EtherHiding technique, making infrastructure disruption significantly harder.
CylindricalCanine is a newly named operational subgroup within the China-linked GoldenEyeDog (APT-Q-27) cybercrime cluster, identified and named by Expel researchers on July 17, 2026. The subgroup is responsible for the April 2026 breach of DigiCert, where attackers compromised a support employee's device via the Golden Gh0st Loader malware delivered through DigiCert's support ticketing system. This enabled interception of certificate initialization codes, ultimately resulting in 60 certificate revocations — at least 27 linked to malware signing — representing a significant supply-chain escalation in the group's tradecraft.
UTA0533 is a newly disclosed, previously undocumented threat actor attributed by Volexity on July 19, 2026 after an incident response investigation involving compromised SonicWall SMA 1000 series VPN appliances. The actor chained two critical zero-day vulnerabilities (CVE-2026-15409 CVSS 10.0 and CVE-2026-15410 CVSS 7.2) to achieve unauthenticated root-level access, deploy custom SonicWall-specific malware, sniff unencrypted LDAP credentials, and attempt lateral movement weeks before patches existed. No nation-state attribution has been made; CISA has added both CVEs to its KEV catalog.
DeadLock emerged in July 2025 operating quietly without a data leak site before detonating onto the ransomware leaderboard in June 2026 with 75–81 claimed victims, jumping to second place globally. The group is technically distinguished by its use of Polygon blockchain smart contracts for C2 proxy address rotation (EtherHiding technique), and by kernel-level EDR termination via a BYOVD attack exploiting the vulnerable Baidu Antivirus driver (CVE-2024-51324). Its sudden leap in victim volume in June 2026 after 11 months of relative silence suggests a deliberate backlog-release strategy or rapid affiliate expansion.
Hyadina is a RaaS operation tracked by Symantec since March 2022 through three successive locker rebrands: Monster (2022) → Beast (June 2024) → GodDamn (May 2026). On July 9, 2026, Symantec disclosed the GodDamn variant's use of PoisonX, a custom kernel driver bearing a legitimate Microsoft Hardware Compatibility Publisher signature obtained via GitHub alias 'oxfemale,' enabling a novel BYOVD attack that forcibly blinds endpoint security tools before ransomware deployment. The PoisonX driver was also incorporated into the GentleKiller toolkit distributed to The Gentlemen RaaS affiliates, indicating cross-group tool sharing.
Media Land LLC and ML.Cloud LLC were Russia-based bulletproof hosting providers operated by three St. Petersburg nationals — Alexander Volosovik (alias 'Yalishanda'), Yulia Pankova, and Kirill Zatolokin — running since 2014. On July 14, 2026, the DOJ unsealed a December 2024 federal grand jury indictment charging all three and both companies with computer fraud, wire fraud, and money laundering after a seven-year FBI Cleveland investigation. Their infrastructure hosted LockBit, BlackSuit, and Play ransomware groups; carding forums (BidenCash, Briansclub); and banking trojans (Ermac, RedAlert), causing over $62 million in losses across 21 US states and multiple countries. The EU issued simultaneous sanctions on July 13, 2026, and the US State Department is offering up to $10 million for information on foreign government ties.
On July 2 2026, the FBI and IRS Criminal Investigation division seized hundreds of NetNut domains in a coordinated action with Google Threat Intelligence Group, Lumen Technologies, and the Shadowserver Foundation, dismantling the Popa botnet — a 2-million-device residential proxy network built on hijacked Android smart TVs, streaming boxes, and off-brand devices via malicious SDKs. Google's GTIG observed 316 distinct threat clusters (criminal and espionage) using NetNut exit nodes in a single week during June 2026, including for password spraying, credential stuffing, and masking APT C2 traffic. This is Google's second major residential proxy botnet disruption in 2026, following the IPIDEA takedown in January.
Hyadina is a 4-year-old RaaS operation tracked by Symantec that has serially rebranded its locker: Monster (2022) → Beast (Jun 2024) → GodDamn (May 2026). Its latest iteration, GodDamn, disclosed by Symantec on July 9, 2026, introduces PoisonX — a kernel-mode driver that obtained a legitimate Microsoft Hardware Compatibility Publisher signature and is weaponized to silently kill EDR and antivirus processes before ransomware deployment, a significant escalation in defensive evasion capability. The group's consistent toolchain (AnyDesk, NirSoft suite, PsExec, Mimikatz) across all iterations confirms a single persistent developer organization systematically hardening the same operation.
The Gentlemen emerged in September 2025 following a payment dispute within the Qilin RaaS program and scaled to 478+ publicly claimed victims across 66+ countries by mid-2026 — the fastest growth trajectory of any RaaS operation on record, comparable to early LockBit 3.0. As of July 10, 2026, the group remains the #2 most active ransomware operation globally by victim count. A May 4, 2026 backend database leak exposed the group's full operator roster, toolchain, victim lists, and Bitcoin laundering chains, yet failed to interrupt operations. Microsoft tracks the encryptor as Storm-2697; it uses Go with Garble obfuscation and supports a self-propagating worm mode (--spread flag) enabling enterprise-wide encryption within minutes via Group Policy weaponization.
Scattered Spider is a Western, English-speaking cybercrime collective specializing in social engineering rather than technical exploits, responsible for 100+ intrusions and $100M+ in ransom payments. In a major law enforcement development on July 1, 2026, the DOJ announced the extradition of 19-year-old Peter Stokes ('Bouquet') from Finland to face federal conspiracy, computer intrusion, and fraud charges — the latest in a sustained dismemberment campaign also including guilty pleas from UK members Thalha Jubair and Owen Flowers in June 2026, and a prior April 2026 guilty plea from Tyler Buchanan. International pressure is materially degrading the group's operational leadership roster, though the crew continues activity.
INTERPOL announced on July 9, 2026 the results of Operation First Light 2026, a four-month enforcement campaign (Jan 15–Apr 30) across 97 countries and territories that resulted in 5,811 arrests, $293 million in intercepted illicit assets, and identification of over 142,000 victims across 152,808 analyzed fraud cases. The operation targeted industrialized social engineering syndicate networks running BEC, romance scams, pig-butchering crypto investment fraud, sextortion, and authority impersonation schemes — many operating out of Southeast Asian scam compounds with trafficked workers. A 20-year-old Thai suspect's crypto wallet was found to have processed over $122.5 million in romance-scam proceeds in 10 months using cross-chain token swaps to obscure the financial trail. DOJ had previously indicted operators of the Shunda compound in Myanmar for targeting American victims via fake crypto investment platforms.
A newly exposed initial access broker operation, active since at least February 2026 and disclosed publicly in June-July 2026, that deployed a custom Golang tool called FortigateSniffer onto compromised FortiGate devices to passively intercept VPN credentials at scale across 150+ countries. SOCRadar confirmed on July 2, 2026 that an operator with access to FortiBleed infrastructure was simultaneously logged into ransomware negotiation panels for both INC Ransom and Lynx, directly tying the credential-harvesting pipeline to live extortion deployments for the first time. The operation involved roughly 20 individuals in a tiered structure and utilized approximately 500 servers globally.
JADEPUFFER is the first documented threat operator to conduct a ransomware attack entirely end-to-end via a large language model agent, with no human at the keyboard. Disclosed by Sysdig TRT on July 1, 2026, the LLM autonomously performed reconnaissance, credential theft, lateral movement, persistence, and database encryption against a production Nacos/MySQL server after pivoting from an exploited Langflow instance. The attack self-corrected in real time — recovering from a failed login to a working fix in under 31 seconds — signaling the arrival of autonomous 'agentic' extortion at operational scale.
Turla (Secret Blizzard), attributed to Russia's FSB Center 16 and active since at least 2004, received a major intelligence update on July 7, 2026, when researchers published fresh analysis of its STOCKSTAY and Kazuar backdoor campaigns targeting Ukraine and Europe. A defining and re-highlighted tradecraft is its brazen hijacking of rival threat actors' C2 infrastructure — previously co-opting Iranian OilRig, Pakistani Storm-0156, and Russian cybercriminal Amadey botnet infrastructure — to conduct operations while degrading attribution. Recent campaigns deploy STOCKSTAY via compromised Ukrainian government and IT infrastructure, staging payloads on trusted local domains to evade detection.
Lynx/INC ransomware was newly linked on July 1, 2026, to the massive 'FortiBleed' credential theft campaign, which exposed credentials from over 73,000 FortiGate devices. SOCRadar's investigation identified a FortiBleed infrastructure server whose browser sessions accessed negotiation panels for both Lynx and INC, providing direct evidence of an affiliate overlap between the two groups. Lynx, which emerged in mid-2024, is broadly assessed by researchers as a rebrand of the INC ransomware operation. The FortiBleed operation used a custom 'FortiGate Sniffer' tool deployed on compromised firewalls to intercept VPN credentials in-transit from network traffic.
Sophos CTU disclosed on July 2, 2026 a formal operational partnership between TeamPCP (supply chain compromise specialists, ex-The Com) and Vect (RaaS operator launched Dec 2025), described by researchers as an 'unprecedented model of industrialized ransomware deployment.' TeamPCP poisons trusted open-source security tools (Trivy, KICS, LiteLLM) to harvest 500,000+ cloud credentials at scale, feeding them directly into Vect's ransomware affiliate network, which has also partnered with BreachForums to mass-distribute affiliate keys to ~300,000 registered users. At least one confirmed Vect ransomware deployment using TeamPCP-sourced credentials was verified. Prior to the Vect partnership, TeamPCP operated the CipherForce ransomware brand, and also collaborates with Lapsus$ for data-leak monetization.
Socket Threat Research Team disclosed on July 1–6, 2026 that the North Korea-linked PolinRider supply chain campaign has massively expanded across npm, Packagist, Go modules, and Chrome extensions, with 162 malicious artifacts identified across 108 unique packages. The campaign, attributed to the Famous Chollima / Contagious Interview cluster (Lazarus subset), compromises legitimate maintainer accounts and rewrites Git history to conceal injected obfuscated JavaScript loaders that deliver DEV#POPPER RAT and OmniStealer. As of July 7, 2026, the campaign remains fully active with new compromises continuously surfacing.
Google and the FBI disrupted the NetNut/Popa residential proxy botnet on July 2, 2026, seizing hundreds of domains and disabling Google accounts used for C2, cutting millions of devices from the network. NetNut covertly enrolled over 2 million Android devices (smart TVs, streaming boxes) as exit nodes via trojanized apps and Badbox 2.0 botnet plugins, renting the proxies to threat actors to mask attack origins. GTIG observed 316 distinct threat clusters using NetNut exit nodes in a single June 2026 week. NetNut also operated a white-label reseller program, meaning the takedown cascades across many apparently independent proxy brands.
Kaspersky publicly named Armored Likho on July 4, 2026 after uncovering an active espionage campaign hitting government agencies and electric power operators in Russia, Kazakhstan, and Brazil using a newly documented Python-based infostealer called BusySnake Stealer. The group overlaps substantially with the threat cluster BI.ZONE tracks as Eagle Werewolf, active since May 2023, which previously targeted UAV development organizations and compromised a drone-focused Telegram channel to distribute AquilaRAT in February 2026. Notably, first-stage loader code shows signs of LLM-assisted generation, erasing traditional coding-style attribution fingerprints.
SOCRadar's Threat Research Unit on July 2, 2026 confirmed that the FortiBleed credential-harvesting campaign — which targeted over 430,000 FortiGate firewalls globally and collected 110 million+ credentials using a custom Golang sniffer — is directly operated by or feeding into the INC Ransom and Lynx RaaS groups, representing the first confirmed link between mass FortiGate credential theft and ransomware deployment. An operator with access to FortiBleed infrastructure was found simultaneously logged into negotiation panels for both groups, with victim overlap confirmed. The operation involves approximately 20 individuals with defined roles across a ~500-server infrastructure, and actors are also exploiting an unpatched Nextcloud zero-day to expand access.
Kairos is a data-extortion actor first appearing in November 2024 that, per a Ransom-ISAC case study published July 4–5, 2026, extorted approximately $1 million from a U.S. government entity (likely Union County, Ohio) using only stolen-data exposure threats — no ransomware encryption was ever deployed. The group accessed the network via brute-force credential attack, exfiltrated 1.6 million files (2+ TB), and leveraged prosecutors' office records as maximum-pressure leverage. Kairos's leak site was seized by the Ukrainian Security Service (SBU); its last known victim was posted June 2026 and a linked wallet showed activity as recently as May 2026.
Blackpoint Cyber's Adversary Pursuit Group disclosed on July 3, 2026 a previously undocumented modular malware framework called Avalon, featuring a ransomware component internally named CrownX, delivered through a multi-stage phishing chain abusing Proton Drive and ISO images to bypass email-layer security controls. Avalon is notable for consolidating credential theft, lateral movement, anti-forensics, recovery disruption, and ransomware execution into a single payload — and shows signs of AI-assisted development, significantly lowering the barrier to entry. The framework specifically targets backup and virtualization platforms (Veeam, Acronis, NetApp, vCenter, Hyper-V) to maximize recovery disruption.
The U.S. DOJ announced on July 1, 2026 the extradition of alleged Scattered Spider member Peter Stokes, 19, a dual U.S.-Estonian citizen, from Finland to face federal conspiracy, computer intrusion, and fraud charges in Chicago — the latest in an accelerating series of arrests dismantling the group. Scattered Spider has been linked to 100+ network intrusions resulting in over $100 million in ransom payments through help-desk impersonation, SIM swapping, and fake SSO phishing. The group's decentralized 'The Com' structure is proving resilient despite successive arrests of members including Tyler Buchanan (guilty plea April 2026), Noah Urban (sentenced August 2025), and UK members Thalha Jubair and Owen Flowers (guilty pleas June 2026).
UAT-9244 is a newly designated China-nexus APT cluster tracked by Cisco Talos, assessed with high confidence to closely overlap with FamousSparrow and Tropic Trooper based on shared tooling, TTPs, and victimology. The group has been targeting South American telecommunications providers since 2024 using three previously undocumented implants — TernDoor (Windows), PeerTime (Linux), and BruteEntry (edge devices) — revealing a comprehensive, multi-platform telecom intrusion toolkit. PeerTime's use of the BitTorrent protocol for C2 communications and BruteEntry's conversion of edge devices into ORB proxy nodes represent significant tradecraft innovations complicating attribution and detection.
World Leaks emerged January 1, 2025 as the confirmed rebrand of Hunters International ransomware, shifting entirely to encryption-less data exfiltration and extortion — a significant operational and strategic pivot driven by declining ransomware profitability and law enforcement pressure. The group has claimed 169 victims across 28 countries as of late June 2026, with a +80% month-over-month activity surge, targeting healthcare most heavily. Darktrace detected a World Leaks compromise in early 2026 where encryption was deployed despite the group's public claims, suggesting operational inconsistency and possible affiliate deviation. The group has also been linked to sharing leak site infrastructure with Secp0, positioning itself as shared extortion infrastructure for multiple threat groups.
AudiA6 was one of the most trusted cryptocurrency laundering platforms in the ransomware ecosystem, processing over €336 million (~$389M) in illicit funds between 2022 and 2025 for ransomware groups, darknet markets, and cybercriminals. On June 10, 2026, a coalition of international law enforcement including Europol, the US DOJ, Secret Service, IRS-CI, and Polish Police arrested two alleged administrators (Ruslan Igorevich Tkachuk and Alexander Vladimirovich Ledenev) in Batumi, Georgia, seized 25 domains, took 30+ servers offline, and froze ~€692,000 in cryptocurrency assets. The group also administered Dark2Web, a cybercrime forum where crimes against specific targets were commissioned. Blockchain analysis linked AudiA6 proceeds to over 15 international ransomware investigations including the 2022 LastPass breach and the Swissborg hack.
Palo Alto Networks Unit 42 published a detailed report on June 25, 2026 formally naming CL-STA-1062, a Chinese-speaking APT cluster active since March 2022 that shifted its focus to Southeast Asian government and state-owned critical energy infrastructure from mid-2025 onward. The group compromised at least 10 organizations between October and December 2025 alone and has now introduced TinyRCT, a bespoke previously undocumented .NET backdoor providing persistent access, command execution, screenshot capture, and AES-encrypted file exfiltration. Unit 42 assesses with high confidence this is the same cluster Cisco Talos previously tracked as UAT-7237 in connection with 2025 Taiwan web-hosting attacks.
Operation Endgame's latest phase, announced June 24, 2026, dismantled the infrastructure behind the Amadey loader and StealC infostealer simultaneously, seizing 326 servers and 142 domains and recovering approximately 27 million stolen credentials from over 385,000 compromised systems. Microsoft and Europol assessed that in the first two weeks of May 2026 alone, the two malware families infected over 140,000 computers globally. The operation, coordinated between June 15–19, 2026, used AI-assisted analysis under expanded RICO charges to treat both malware families as a single criminal conspiracy — a novel law enforcement tactic.
On June 26–27, 2026, the FBI and CISA issued an updated joint advisory (PSA I-062626-PSA) naming two previously untracked Russian Intelligence Services clusters, UNC5792 and UNC4221, behind an evolving campaign to hijack Signal and other commercial messaging app accounts. The actors evolved tactics since a March 2026 advisory, now targeting Signal Backup Recovery Keys to silently restore full account history even after victims change devices. The SSU and FBI confirmed on June 27 that the campaign has compromised thousands of accounts across Ukraine, Europe, and the United States.
Active since at least February 2026, FortiBleed is the largest confirmed Fortinet credential-harvesting campaign in history, compromising verified admin and SSL VPN credentials for 86,644 FortiGate devices across 194 countries — roughly 50% of all internet-facing Fortinet firewalls globally. The Russian-speaking IAB deployed a custom Golang-based tool (FortigateSniffer) to passively capture cleartext credentials passing through compromised firewalls, cracked hashes via a 45-GPU Hashtopolis cluster, and pivoted into Active Directory environments. A NATO defense contractor was confirmed compromised with classified documents exfiltrated on June 15. CISA, UK NCSC, and Fortinet all issued emergency advisories by June 18–19, 2026.
UNC3886 is a highly disciplined China-nexus APT group that confirmed its status as one of the most capable telecom-targeting actors globally after Singapore's CSA disclosed on February 9, 2026 that the group had breached all four of Singapore's major telcos (M1, SIMBA Telecom, Singtel, StarHub) in a campaign persisting undetected for nearly a year. The group used a zero-day exploit to bypass perimeter firewalls, deployed the REPTILE and MEDUSA Linux kernel rootkits for stealth persistence, and exfiltrated technical network data. Singapore mounted Operation CYBER GUARDIAN — its largest-ever coordinated cyber incident response — involving 100+ defenders across 11 months to evict the group. Campaign TTPs overlap with broader Salt Typhoon telecom targeting patterns observed in the U.S., Canada, and Norway.
AudiA6 was an industrial-scale cryptocurrency laundering operation linked to more than 15 global investigations related to ransomware attacks and large-scale crypto theft. On June 10, 2026, Europol and the U.S. DOJ coordinated the arrest of two administrators — Ruslan Igorevich Tkachuk and Alexander Vladimirovich Ledenev — in Georgia, froze €692,000 in cryptocurrency assets, and seized the AudiA6 and associated Dark2Web cybercrime forum. The operation originated from a September 2025 Polish Police arrest of a Ukrainian national whose seized devices identified additional operators.
As part of the ongoing Operation Endgame Phase 4 (June 2026), Europol and partners from six countries disrupted the Amadey and StealC malware-as-a-service networks, seizing 326 servers, freezing $47M in criminal cryptocurrency, and recovering 27 million stolen login credentials from 385,000 compromised systems. Microsoft's Digital Crimes Unit filed a RICO civil lawsuit after AI-assisted analysis (using Microsoft Copilot) revealed Amadey and StealC shared the same C2 infrastructure despite being developed by separate criminal groups, enabling a unified takedown of 200+ C2 servers. In May 2026 alone, the two infostealers were linked to 140,000 infected computers.
On June 24, 2026, Europol announced Phase 4 of Operation Endgame — the largest international operation ever undertaken to dismantle ransomware enablers — targeting the criminal assembly line behind SocGholish (Evil Corp), Amadey, and StealC. Law enforcement and private-sector partners from six countries seized 326 servers and 142 domains, froze €41M ($47M) in criminal cryptocurrency, and recovered 27 million stolen credentials from 385,000 compromised systems. Microsoft's DCU simultaneously filed a civil RICO lawsuit against Amadey and StealC operators after AI-assisted analysis revealed shared C2 infrastructure, enabling unified takedown of 200+ servers in a single court action — a novel legal precedent in cybercrime prosecution.
SocGholish (TA569) is a long-running JavaScript-based malware framework and initial access broker, directly linked to Evil Corp (the Zeus/Dridex/WastedLocker syndicate), that converts compromised legitimate WordPress sites into drive-by malware delivery vehicles via convincing fake browser update prompts. On June 18, 2026, Operation Endgame — a multinational coalition led by the Dutch NHTCU, FBI, German BKA, and RCMP — seized 106 servers and domains and remotely cleaned ~14,971 compromised WordPress sites, its most significant disruption to date. A follow-on June 24 Europol action expanded Operation Endgame to seize 326 total servers, freeze $47M in criminal cryptocurrency, and recover 27 million stolen credentials targeting Amadey and StealC infostealer infrastructure that shared the same C2 backend.
KimWolf is an Android-focused IoT DDoS botnet operated as a DDoS-for-hire service, directly descended from the Aisuru botnet with a redesigned codebase to evade detection. At its peak it infected approximately 2 million devices (Android TV boxes, web cameras, DVRs, digital photo frames) generating ~12 million unique IPs weekly and was linked to a record-breaking 30 Tbps DDoS attack. Infrastructure was seized in a March 2026 international operation; operator Jacob Butler ('Dort') was arrested by Ontario Provincial Police on May 21, 2026 and faces U.S. extradition on computer intrusion charges.
DragonForce has transitioned from a standard RaaS operation to a highly organized cartel structure with APT-grade tradecraft. A Symantec/Carbon Black report published June 16–17 2026 revealed the group deployed Backdoor.Turn — the first known malware to abuse Microsoft Teams TURN relay infrastructure — to mask C2 traffic as legitimate Teams traffic during a months-long dwell inside a major US services firm. The group also used a then-undocumented BYOVD exploit against a Huawei driver, reflecting substantial investment in offensive tooling.
Qilin (aka Agenda) is a highly active RaaS operation that dominated the ransomware landscape in 2025 and remains a top-tier threat in 2026, ranking #1 by total victim count over the past 12 months with an estimated 1,448 attacks. In a major escalation disclosed June 8, 2026, a Qilin affiliate was confirmed to have exploited CVE-2026-50751 — a critical CVSS 9.3 authentication bypass zero-day in Check Point Remote Access VPN — since May 7, 2026, a full month before a patch was available. CISA added the vulnerability to its KEV catalog on June 9, 2026 with a three-day federal patch deadline, underscoring the severity of active exploitation.
The FortiBleed threat cluster is a newly identified Russian-speaking group responsible for what researchers are calling the largest industrialized credential-harvesting campaign in Fortinet's history. First publicly surfaced on June 13, 2026, by researcher Volodymyr Diachenko, the group systematically collected configuration files from internet-facing FortiGate firewalls, cracked SHA-256 password hashes using a dedicated 45-GPU cluster, and built a verified database of working administrator and VPN credentials for up to 86,644 devices across 194 countries. CISA issued an emergency advisory on June 18, Fortinet's PSIRT published a formal warning on June 19, and the UK NCSC issued a global alert — all within a six-day window. The credential pool is confirmed to be circulating in criminal underground markets and is already being leveraged by both opportunistic criminals and more sophisticated state-adjacent actors for targeted intrusions, including confirmed exfiltration of classified documents from a Turkish NATO defense contractor.
Twill Typhoon (Mustang Panda) was identified by Darktrace in May 2026 conducting a sustained APAC-focused espionage campaign active since September 2025, deploying an updated version (v3.2.5.1) of the FDMTP modular .NET backdoor via DLL sideloading. The campaign involved infrastructure impersonating Yahoo and Apple CDN services to blend malicious traffic with legitimate web activity, and used legitimate Windows binaries (vshost.exe, dfsvc.exe, Sogou Pinyin IME) as sideloading vehicles. In a concurrent development, Salt Typhoon — a related Chinese APT cluster — was observed targeting an Azerbaijani oil and gas company between December 2025 and February 2026, marking a geopolitical pivot linked to Azerbaijan's expanding role in European energy security.
AudiA6 was a prolific cryptocurrency laundering service and the operators of the Dark2Web underground cybercrime forum, collectively serving as a critical financial pipeline for ransomware groups and Eastern European cybercrime syndicates since 2021. The service laundered an estimated €336 million (~$389M) using thousands of fraudulent KYC-verified exchange accounts and was linked by Europol to more than 15 international ransomware investigations. On June 10, 2026, a coordinated international law enforcement operation involving the US DOJ/Secret Service/IRS-CI, Europol, Eurojust, Polish Police, and partners from 11 countries dismantled the operation — arresting both administrators in Georgia, seizing 30+ servers, taking down 25 domains, and recovering 6,000+ money mule KYC records.
Atomic Arch is a large-scale, actively expanding supply chain campaign first detected by Sonatype on June 11, 2026, in which an unidentified threat actor systematically adopted orphaned Arch Linux AUR packages and injected malicious PKGBUILD scripts to deploy a Rust-based credential stealer ('deps') and optional eBPF rootkit. By June 12 a second wave emerged using Bun-based delivery, and the total affected package count grew to approximately 1,500 — one of the largest documented AUR compromises on record. The attack targets developer workstations specifically, aiming to harvest credentials that enable lateral movement into enterprise environments without direct exploitation.
SniperDz was one of the world's longest-running phishing-as-a-service (PhaaS) platforms, active since 2015 and serving cybercriminals in at least 13 MENA-region countries. Operating via Telegram and Facebook, it offered 80 ready-made phishing templates in five languages targeting 30+ global brands including PayPal, Facebook, Netflix, and Steam across 20,000+ domains. The platform and its primary developer-administrator were taken down by INTERPOL Operation Ramz (announced June 11, 2026), resulting in 201 arrests across MENA and the seizure of 53 servers.
New CYFIRMA research published June 10, 2026 revealed that the energy and utilities sector appeared in 66.6% of all observed APT campaigns over the preceding three months — with Chinese actor Mustang Panda, North Korea's Lazarus Group, and Russia's Sandworm (APT44) identified as the most active adversaries across attacks spanning 18 countries. The China-aligned MISSION2074 cluster recorded the highest campaign count of any single actor across all sectors in the most recent reporting period, with Volt Typhoon, Salt Typhoon, Earth Estries, and Hafnium providing additional Chinese representation. Sandworm was separately linked to a destructive DynoWiper malware campaign targeting Poland's energy sector in late 2025.
First VPN Service was a criminal-focused virtual private network operating since 2014 across 27 countries, almost exclusively advertised on Russian-language dark web forums. At least 25 ransomware groups — including Avaddon — used its infrastructure to mask network intrusions and scope targets globally. The service was seized on June 9, 2026 as the first major action under the FBI's newly announced Operation Riptide, a 60-day coordinated international cyber enforcement campaign targeting criminal infrastructure, tools, and financial networks.
ESET Research disclosed on June 11, 2026 that OceanLotus (APT32) has undergone a significant strategic pivot toward domestic espionage inside Vietnam, marking a departure from its historically external targeting of China and Southeast Asian governments. Two distinct 2024–2026 campaigns were revealed: a 15-month intrusion into a Vietnamese infrastructure and transport construction corporation, and a precision supply-chain attack against FireAnt MetaKit — a stock market data platform — that selectively delivered the SPECTRALVIPER backdoor to a handful of high-value investors linked to Vietnam's ongoing financial market investigations. Researchers assess OceanLotus is now acting as a digital surveillance arm of the Vietnamese state's anti-corruption apparatus.
Scattered Lapsus$ Hunters (SLSH) is a declared alliance of three notorious English-speaking cybercrime collectives — Scattered Spider, Lapsus$, and ShinyHunters — that formalized a joint operation in August 2025 following a series of coordinated Salesforce platform intrusions claiming 91 victim organizations. The alliance is now developing ShinySp1d3r, a custom RaaS platform featuring novel ETW hook-based logging suppression, self-propagating encryptor, and planned Linux/VMware ESXi variants — representing a leap from the groups' historical reliance on third-party encryptors (BlackCat, Qilin, DragonForce). The collective is actively recruiting corporate insiders targeting organizations with $500M+ annual revenues, excluding CIS countries and healthcare, with aggressive commission-based IAB deals and insider outreach on Telegram and dark web forums heading into mid-2026.
On June 9, 2026, the FBI's Cyber Division announced Operation Riptide — a coordinated, 60-day international law enforcement campaign targeting the full criminal ecosystem supporting cyber-enabled crime, including infrastructure, tools, communications platforms, and financial networks. The first major action under Riptide was the international takedown of 'First VPN Service' (active 2014–2026, 27 countries), used by at least 25 ransomware groups including Avaddon; concurrently, on June 10, Europol dismantled the AudiA6 Russian cryptocurrency mixing service — linked to over €336M ($389M) in laundered ransomware proceeds since 2021 — and its associated Dark2Web cybercrime forum. Additional actions by FBI, France's DNPJ, Dutch National Police, and partners across Ukraine, UK, Switzerland, and Luxembourg have included arrests, indictments, cryptocurrency seizures, and server confiscations; further actions are expected through August 2026.
Vect is a newly emerged RaaS operation identified by Halcyon and analyzed by Red Piranha, notable for building its encryptor in C++ from scratch (not repurposing LockBit 3.0 or Conti leaked code) and using ChaCha20-Poly1305 AEAD encryption — 2.5x faster than AES-256-GCM on non-accelerated hardware. The group demonstrates unusual operational maturity for its age: cross-platform targeting of Windows, Linux, and VMware ESXi; Safe Mode execution to suppress security tools; Monero-only payments; TOX protocol for affiliate communications; and exclusively TOR hidden services with no clearnet presence. Analysts from Red Piranha assess Vect is likely a rebrand or new venture by experienced RaaS operators, given the sophistication of its initial launch.
Payload emerged in February 2026 and rapidly listed 50+ victims across 7+ countries within its first month of operations. The group uses Babuk-derived source code for cross-platform Windows and ESXi encryption (ChaCha20 + Curve25519 ECDH per-file key exchange) paired with aggressive anti-forensics including ETW memory patching, VSS deletion, and Windows Event Log clearing. Notable for a 'MakeAmericaGreatAgain' mutex string embedded in its binary — a distinct operator fingerprint — and for targeting emerging markets including the MENA region as a primary focus.
Rapid7 disclosed in May 2026 that MuddyWater (Seedworm) conducted a sophisticated false-flag ransomware operation in early 2026, operating under the Chaos RaaS banner while forensic analysis revealed MOIS-linked code-signing certificates ('Donald Gay' + 'Amy Cherne' cert cluster) tying the intrusion to Operation Olalampo. The group used interactive Microsoft Teams sessions to harvest MFA credentials under an 'IT Support' social engineering persona. This marks a significant evolution: MuddyWater adopting a commercially available RaaS brand to project a cybercriminal identity while conducting intelligence-driven targeted operations, blurring the line between espionage and ransomware.
SHADOW-EARTH-053, disclosed by Trend Micro on April 30, 2026, is a newly identified China-aligned intrusion cluster targeting government and defense sectors across South, East, and Southeast Asia — including Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan — as well as Poland (a NATO member). Analysts at The Diplomat characterized the campaign as a qualitative shift in Beijing's playbook, with a single workflow fusing traditional state espionage against ministries of defense with active phishing of Uyghur, Tibetan, Taiwanese, and Hong Kong dissidents abroad. The campaign is among the first major operations assessed to have emerged under China's reorganized Cyberspace Force following the April 2024 dissolution of the Strategic Support Force.
CARR, founded, funded, and directed by the GRU, claimed credit for hundreds of destructive cyberattacks worldwide including attacks on US public drinking water systems across multiple states and a November 2024 attack on a Los Angeles meat processing facility that triggered an ammonia leak. A Ukrainian national, Victoria Dubranova (aka SovaSonya), was extradited to the US and faces trial in 2026 for her roles supporting both CARR and NoName057(16) under DOJ Operation Red Circus — the first prosecution of a GRU-directed hacktivist operator. CARR had over 100 members and 75,000+ Telegram followers at peak activity.
LockBit resurfaced in September 2025 with LockBit 5.0 (internally codenamed 'ChuongDong'), announcing the release on the group's sixth anniversary on underground forums. The new variant introduces advanced anti-forensics including ETW patching, DLL reflection loading, randomized 16-character file extensions, and full cross-platform support for Windows, Linux, ESXi, and Proxmox. In Q1 2026, LockBit posted 163 victims — a 106% increase over Q4 2025 — climbing to 4th globally. In October 2025, LockBit formalized an alliance with Qilin and DragonForce, creating a ransomware cartel with shared infrastructure, mutual affiliate referrals, and coordinated OPSEC designed to resist law enforcement disruption.
JINX-0164 is a newly identified, financially motivated threat actor first named by Wiz Research in May 2026 after investigating multiple intrusions against cryptocurrency organizations. The group targets macOS-reliant software developers via LinkedIn recruiter-themed social engineering, deploying two custom malware families — AUDIOFIX (Python-based infostealer/RAT) and MINIRAT (Go-based backdoor) — and has demonstrated supply chain attack capability by trojanizing the npm package @velora-dex/sdk (v4.9.1) in April 2026. Despite tactical similarities to known North Korean clusters, no confirmed infrastructure overlap with state-sponsored groups has been established.
GHOST STADIUM is a Chinese-speaking, financially motivated threat actor exposed by Group-IB in late May 2026 as the primary operator at the center of a massive fraud ecosystem targeting the 2026 FIFA World Cup. The group runs 300+ active phishing domains built on a custom React/Layui phishing kit that clones fifa.com to near pixel-perfect fidelity, replicating even the PingIdentity SSO authentication flow using the real FIFA client_id. Campaign losses across all six associated fraud schemes — credential phishing, fake ticket sales, counterfeit merchandise, fake streaming, fraudulent betting, and infostealer-driven theft — are projected to reach into the billions, with premium ticket fraud alone estimated at $71M–$474M.
SideCopy, a Pakistan-linked sub-cluster of the broader Transparent Tribe (APT36) umbrella, disclosed a new campaign on June 2, 2026 (Operation XENOFISCAL) targeting Afghanistan's Ministry of Finance and all 34 provincial revenue and finance directorates. The group deployed Xeno RAT 1.8.7 via Pashto-language LNK lure files and a compromised Afghan education domain as a staging server, demonstrating operational familiarity with the Afghan government environment. The campaign is assessed as ongoing since at least May 2025 and reflects a sustained effort to collect national financial intelligence.
Crimson Collective is an emerging extortion group that surfaced in September 2025 and rapidly gained notoriety by breaching Red Hat's internal GitLab in October 2025, exfiltrating approximately 570 GB of data from 28,000+ repositories with downstream impact on Nissan customer PII. In January 2026, the group claimed to have stolen data on over 1 million Brightspeed fiber broadband customers and listed the dataset for sale at 3 BTC. The group specializes in targeting misconfigured cloud environments, AWS IAM exploitation, and development infrastructure rather than traditional endpoint ransomware deployment, using Telegram-based extortion pressure.
UAT-9244 is a China-nexus APT cluster tracked by Cisco Talos that has been targeting critical telecommunications infrastructure in South America since 2024, deploying three previously undocumented malware implants: TernDoor (Windows), PeerTime (Linux/embedded), and BruteEntry (ORB proxy builder). Disclosed publicly on March 6, 2026, the campaign demonstrates continued Chinese state investment in telecom compromise tradecraft, including P2P BitTorrent-based C2 on Linux and ORB-style relay infrastructure designed to complicate attribution and defeat IOC-based blocking. Cisco Talos assesses with high confidence that UAT-9244 closely overlaps with FamousSparrow and Tropic Trooper based on shared tooling and TTP overlap, though a confirmed direct link to the separately tracked Salt Typhoon cluster has not been established.
Salt Typhoon, the China-linked APT behind the 2024 US telecom lawful intercept compromise, remains confirmed 'still very much ongoing' per FBI leadership as of February 2026. New confirmed 2026 activity includes: breach of US House Committee staff emails (January 9, 2026) focused on national security personnel overseeing China policy; penetration of all four major Singapore telecom providers (disclosed February 2026, triggering Singapore's largest-ever cyber counteroperation CYBER GUARDIAN); and reports of operations now spanning 80+ countries. New implants TernDoor, PeerTime, and BruteEntry attributed to the closely related UAT-9244/FamousSparrow cluster further illustrate the breadth of China-aligned telecom targeting.
TeamPCP is a highly sophisticated criminal threat actor responsible for the ongoing Shai-Hulud supply chain worm campaign, the most technically advanced open-source supply chain attack series documented to date. The May 2026 'Mini Shai-Hulud' wave compromised 172+ npm and PyPI packages across 518 million cumulative downloads—including TanStack, Mistral AI, UiPath, OpenSearch, and OpenAI packages—by defeating SLSA Build Level 3 provenance attestations through GitHub Actions CI cache-poisoning rather than signature forgery. The group has confirmed partnerships feeding harvested credentials to the Vect RaaS operation and LAPSUS$ extortion group, and on May 13, 2026 open-sourced the Shai-Hulud worm on BreachForums, transforming into a platform operation with affiliate contest mechanics targeting the AI developer toolchain.
First VPN was a criminal anonymization service operating since 2014 that marketed exclusively on cybercriminal forums, promising no-logging and no-cooperation with judicial authorities across 5,000+ accounts. It was dismantled May 19–20, 2026 in Operation Saffron, led by French and Dutch authorities with Europol/Eurojust support, seizing 33 servers across 27 countries and identifying hundreds of users. Intelligence generated was linked to 25 distinct ransomware groups including the Phobos RaaS outfit, and 83 intelligence packages covering 506 users were shared with partner countries for follow-on prosecution.
The BlueNoroff/UNC1069 sub-unit of Lazarus executed the most significant npm supply chain attack of 2026 on March 30-31, poisoning the axios JavaScript package (~100M weekly downloads, present in ~80% of cloud environments) by socially engineering the lead maintainer to steal a long-lived npm access token and publish two malicious versions injecting the WAVESHAPER.V2 RAT (also tracked as SILKBELL by GTIG). The attack was contained in roughly three hours but generated ~600,000 poisoned downloads; OpenAI's macOS app-signing pipeline was exposed, forcing full code-signing certificate rotation. CISA issued an advisory on April 20, 2026, and attribution was confirmed by Microsoft (Sapphire Sleet), Google GTIG (UNC1069), and ThreatBook (Lazarus) independently.
Lapsus$ returned to headlines in late April 2026 with a confirmed breach of Vodafone UK's internal network, publishing 7.1GB of source code, infrastructure diagrams, GitHub repository trees, and internal network maps on May 28, 2026 after Vodafone refused to pay within a 15-day negotiation window. This is the second Vodafone breach by Lapsus$ (the first was in February 2022). In mid-2025, Lapsus$ merged with Scattered Spider and ShinyHunters into the loosely federated 'Scattered Lapsus$ Hunters' (Trinity of Chaos) conglomerate, sharing infrastructure and leak sites while maintaining individual operational autonomy.
First VPN was a cybercriminal anonymization service operating since 2014 that was marketed exclusively on Russian-speaking cybercrime forums and used by at least 25 ransomware groups including Phobos RaaS affiliates. On May 19-20, 2026, Operation Saffron — led by French and Dutch authorities with Europol and Eurojust support — seized 33 servers across 27 countries, shut down all domains, and interviewed the Ukrainian-based administrator in a house search. Intelligence packages covering 506 identified users were shared with 83 partner countries. Law enforcement obtained live access to criminal traffic prior to the takedown, de-anonymizing the entire user base.
IRGC-affiliated Iranian APT that dramatically accelerated operations during the US-Israeli military campaign against Iran in early 2026, deploying a brand-new AI-assisted backdoor (MiniFast) mid-conflict across three distinct campaign waves between February and April 2026. Check Point Research disclosed the campaigns on May 22-26 2026, marking this as the most significant Iranian APT disclosure in the last 48 hours. The group introduced SEO poisoning for the first time as a delivery vector, pushing a fake SQL Developer download page to the top of Bing and DuckDuckGo results, and replaced DLL sideloading with AppDomain hijacking.
A Russia-linked extortion group that spun off from the Conti post-shutdown ecosystem in 2022 and has now escalated to a historically unprecedented physical intrusion tactic: sending operatives in person to victim law firm offices, disguised as IT support staff, to insert USB drives and exfiltrate data directly. The FBI issued a FLASH-severity alert (FLASH-20260526-01) on May 26, 2026 — the highest-urgency classification — detailing this active Spring 2026 development. SRG deploys no malware or encryption, leaving minimal forensic artifacts and defeating most EDR tooling; 38+ firms have had data publicly posted and total attack count exceeds 100 confirmed incidents.
First VPN was a criminal VPN service operating since 2014 that provided anonymization infrastructure to over 25 ransomware groups and 5,000+ criminal accounts. It was dismantled on May 19-20, 2026 under Operation Saffron, led by France and the Netherlands with Europol/Eurojust coordination, resulting in 33 server seizures across 27 countries and the interviewing of the Ukrainian operator. The operation exposed 506 identified users whose intelligence packages have been shared with partner countries, generating ongoing investigative leads into ransomware attacks, fraud schemes, and the Phobos RaaS operation.
Operation Saffron, executed May 19–20, 2026 by French and Dutch authorities with Europol/Eurojust support, dismantled First VPN — a criminal anonymization service operational since 2014 that appeared in virtually every major Europol cybercrime investigation in recent years. The service was used by at least 25 ransomware groups (including Avaddon and Phobos), had over 5,000 accounts, and was promoted exclusively on Russian-speaking cybercrime forums. Law enforcement obtained criminal traffic logs, seized 33 servers across 27 countries, arrested the Ukrainian administrator, and shared 83 intelligence packages on 506 users with partner nations — generating downstream investigative leads for ongoing ransomware prosecutions.
CERT-UA issued an advisory on May 21, 2026 warning that Ghostwriter (UAC-0057/UNC1151) had launched a new phishing campaign against Ukrainian government organizations using lures themed around the Prometheus online learning platform. The attack delivers a three-stage malware chain: OYSTERFRESH (JS decoy/dropper), OYSTERBLUES (registry-persisted encrypted payload), and OYSTERSHUCK (decoder), with C2 infrastructure hidden behind Cloudflare on .icu TLD domains. This represents a fresh tooling update from the group's prior tradecraft.
Operation Saffron, executed May 19–20, 2026 by French and Dutch authorities with Europol/Eurojust support, dismantled First VPN — a criminal anonymization service operational since 2014 and embedded in virtually every major Europol cybercrime investigation in recent years. 33 servers across 27 countries were seized, the administrator was arrested in Ukraine, and 83 intelligence packages were shared with partner countries covering 506 identified users. Bitdefender supported the investigation. This marks the first VPN-category takedown in Europol history and will fuel follow-on prosecutions across the ransomware ecosystem.
SpaceBears, a Phobos RaaS affiliate first observed in April 2024, posted a new victim on ransomware.live on May 27, 2026 (within the last 48 hours) — Ridge Law Firm in the Bronx, New York — with an attack estimated on May 12. On May 26, the group also claimed an attack against Italian logistics firm BASE S.p.A. The group is notable for its 'corporate' aesthetic data leak site and has accumulated 122+ listed victims primarily in the US, Germany, Spain, Italy, and Canada across technology, healthcare, and manufacturing sectors.
Iran-nexus APT group newly detailed by Unit 42 (Palo Alto Networks) in a report published May 22, 2026. Between February and April 2026, the group dramatically escalated operations aligned with the outbreak of the US-Israel-Iran regional conflict on Feb 28, deploying six new RAT variants across two new malware families (MiniUpdate and MiniJunk V2) against targets in the US, Israel, UAE, and at least two additional Middle Eastern countries. For the first time, researchers observed the group fusing its standard DLL sideloading techniques with advanced AppDomainManager hijacking, disabling security mechanisms before applications fully start. The group's campaigns are tightly correlated to geopolitical escalation, with campaign spikes tracked within 72–96 hours of kinetic events.
Rapid7 disclosed on May 6, 2026 that MuddyWater — Iran's MOIS-linked APT — conducted a sophisticated false-flag operation disguised as a Chaos ransomware attack in early 2026. The group used Microsoft Teams social engineering to harvest credentials and manipulate MFA, then deployed the custom Darkcomp (Game.exe) RAT, but deliberately withheld file encryption to prioritize long-term espionage persistence while creating the illusion of a financially motivated attack. Confirmed targets include a US bank, a US airport, nonprofits, and a defense/aerospace software supplier with Israeli operations. Attribution rests on the 'Donald Gay' code-signing certificate, C2 infrastructure at moonzonet[.]com, and use of pythonw.exe for process injection — all previously tied to MuddyWater's 'Operation Olalampo.'
Formally attributed by the US DOJ (March 2026) as an Iranian MOIS 'fake activist persona,' Handala dramatically escalated operations following the Feb 28 US-Israel military strikes on Iran. In March 2026 alone, the group executed a destructive MDM-abuse wiper operation against Stryker Corporation deleting data from 200,000+ devices across 79 countries, compromised FBI Director Kash Patel's personal email, and published PII for 28 Lockheed Martin engineers in Israel. The State Department issued a $10M reward for operator identification; the FBI seized four Handala leak site domains. The group continued operating through Iran's internet blackout by using Starlink VSAT connectivity, and executed a WhatsApp threat campaign against US Marines at Naval Support Activity Bahrain in late April 2026.
First VPN — a criminal VPN service operating since 2014 and marketed exclusively on Russian-speaking cybercrime forums — was dismantled May 19–20, 2026 in Operation Saffron, led by French and Dutch authorities with Europol and Eurojust support. The service had over 5,000 accounts, was linked to at least 25 ransomware groups including the Phobos RaaS outfit, and facilitated more than $70M in illicit proceeds laundering. Law enforcement seized 33 servers across 27 countries, shut down domains including 1vpns.com and associated .onion addresses, and generated 83 intelligence packages covering 506 users shared with partner countries. All users were notified their identities are now known to authorities. This represents a significant blow to the anonymization layer of the ransomware supply chain.
KimWolf was a massive IoT DDoS-for-hire botnet operated by Jacob Butler (alias 'Dort'), a 23-year-old Ottawa resident arrested by Canadian authorities on May 21, 2026 under a US extradition warrant. Assessed as a variant/successor of the AISURU botnet, KimWolf infected nearly two million devices globally — targeting inherently vulnerable endpoints including digital photo frames, web cameras, and Android smart TVs — and issued over 25,000 attack commands linked to a record-breaking 31.4 Tbps DDoS attack. The DOJ unsealed charges the same day and simultaneously disrupted 45 DDoS-for-hire platforms that collaborated with the KimWolf ecosystem.
First VPN was a criminal VPN service operating since 2014, marketed exclusively on Russian-speaking cybercriminal forums and used by over 5,000 accounts including at least 25 ransomware groups (notably Phobos RaaS affiliates). Taken offline May 19–20, 2026 via Operation Saffron — a joint French/Dutch/Europol/Eurojust action seizing 33 servers across 27 countries and interviewing the Ukrainian operator. Before shutdown, law enforcement gained covert visibility into criminal user traffic; 83 intelligence packages covering 506 identified users were disseminated to partner countries for ongoing ransomware and fraud investigations.
Rapid7 disclosed on May 6, 2026 that MuddyWater conducted a sophisticated false-flag intrusion in early 2026, masquerading as a Chaos RaaS affiliate to conceal state-sponsored espionage. The campaign involved Microsoft Teams social engineering, MFA manipulation, credential harvesting, and deployment of a custom Darkcomp (Game.exe) RAT — but never deployed file-encrypting ransomware, exposing the espionage intent. This follows a pattern: MuddyWater previously used Qilin ransomware against an Israeli organization in late 2025, then switched to Chaos branding post-attribution to reduce detection risk. Confirmed U.S. victims include a bank, an airport, nonprofits, and a defense/aerospace software supplier.
KimWolf was a record-breaking IoT DDoS botnet operated as a criminal rental service, assessed by the DOJ as a variant of the AISURU botnet. The botnet infected nearly 2 million IoT devices globally — including digital photo frames, web cameras, and streaming TV boxes — and generated attack traffic peaking at nearly 30 Tbps, the largest DDoS volume publicly disclosed at the time. Its administrator, Jacob Butler ('Dort') of Ottawa, was arrested on May 20, 2026 under a U.S. extradition warrant and charged in the District of Alaska; infrastructure was seized in a March 2026 multinational operation alongside related botnets Aisuru, JackSkid, and Mossad.
First VPN was a cybercriminal-market VPN service operating since 2014, dismantled May 19–20, 2026 in Operation Saffron by French and Dutch authorities with Europol/Eurojust support. The service had over 5,000 accounts and was confirmed used by at least 25 ransomware groups, including Phobos RaaS affiliates. Europol seized 33 servers across 27 countries and generated 83 intelligence packages covering 506 identified users, enabling downstream ransomware and fraud investigations across multiple countries. All active users were notified their identities are known to law enforcement.
GopherWhisper is a previously undocumented China-aligned APT group publicly disclosed by ESET Research on April 23, 2026, after being discovered in January 2025 targeting a Mongolian government institution. The group wields a seven-tool Go-based malware suite routing all C2 traffic through legitimate enterprise platforms — Slack, Discord, and Microsoft 365 Outlook — to evade network detection. Analysis of recovered C2 traffic from attacker-controlled Slack and Discord servers indicates dozens of additional victims beyond the confirmed Mongolian target.
Rapid7's May 6, 2026 report 'Muddying the Tracks' disclosed that MuddyWater conducted a sophisticated false-flag intrusion in early 2026, masquerading as a Chaos RaaS affiliate to conceal state-sponsored espionage objectives. The campaign used Microsoft Teams social engineering to harvest credentials and manipulate MFA, deploying the custom Darkcomp/Game.exe RAT and remote management tools (DWAgent, AnyDesk) for persistent access — but never deployed actual file-encrypting ransomware. This follows a pattern established in late 2025 when MuddyWater used Qilin RaaS against an Israeli organization; the switch to Chaos branding is assessed as a deliberate move to reduce attribution risk after the Qilin incident was attributed to MOIS.
APT73, also known as Bashe, is a ransomware group that emerged in mid-April 2024, self-styling as an Advanced Persistent Threat and operating a TOR-based data leak site bearing a striking resemblance to LockBit's infrastructure. The group has surged in activity in May 2026, posting multiple high-profile victims within 48 hours including Turkey's General Directorate of Land Registry (TKGM, a government agency), Thailand's National Astronomical Research Institute (NARIT), and Mexican corn producer Minsa S.A.B. de C.V. — all claimed on May 21–22, 2026. The group previously claimed 50GB stolen from UK investment platform Hargreaves Lansdown in late April 2026.
KryBit is an emerging RaaS operation that launched in late March 2026, offering affiliates an aggressive 80/20 revenue split with cross-platform ransomware builders for Windows, Linux, ESXi, and NAS devices. The group posted 10 legitimate victims within its first two weeks and engaged in a high-profile ransomware turf war with rival group 0APT in April 2026, in which KryBit successfully hacked back, defaced 0APT's infrastructure, and exposed its full operational dataset — revealing that 0APT's 190+ claimed victims were entirely fabricated. Despite active affiliate operations and staged victim data (10–250GB per victim, ransom demands $40K–$100K), KryBit had collected zero ransom payments as of mid-April 2026 per leaked wallet data. The group employs structured double-extortion with shadow copy deletion and TOR-based leak infrastructure.
First VPN was a criminal-facing VPN anonymization service active since 2014, advertised exclusively on Russian-speaking cybercrime forums and used by threat actors across ransomware, fraud, and data theft operations including the Phobos RaaS outfit. The service was dismantled on May 19–20, 2026, by French and Dutch authorities under Operation Saffron with Europol/Eurojust support, in one of the first VPN-category takedowns in law enforcement history. Authorities seized 33 servers across 27 countries, took down domains including 1vpns.com/net/org and .onion mirrors, and generated 83 intelligence packages on 506 users linked to active ransomware investigations.
Silver Fox is a China-linked APT group newly documented by Kaspersky (May 2026) as having significantly expanded its geographic targeting to include Russia and India, using tax-authority impersonation phishing to deploy a newly discovered Python-based backdoor called ABCDoor alongside the established ValleyRAT (Winos 4.0) RAT. The group's technical maturity is growing: ABCDoor features visual remote control via FFmpeg screen-broadcasting, DPAPI-encrypted persistence, and self-updating/self-deletion logic — distinct from traditional shell-based RATs. Over 1,600 malicious emails were recorded in a single month-long period in early 2026.
First VPN was a criminal VPN service operating since 2014, exclusively promoted on Russian-speaking cybercrime forums, used by ransomware actors including those linked to the Phobos RaaS operation. On May 19–20, 2026, French and Dutch authorities dismantled the service under Operation Saffron, seizing 33 servers across 27 countries, shutting down domains (1vpns.com/.net/.org and .onion mirrors), and interviewing the Ukrainian administrator. Law enforcement had covert access to criminal traffic prior to takedown and issued identification notifications to over 5,000 user accounts, generating 83 intelligence packages covering 506 users for partner nations.
SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated initial-access broker operating in direct support of Volt Typhoon. The group gains footholds across OT-adjacent organizations in North America, Europe, South Korea, Guam, the Philippines, and Saudi Arabia, then hands off access to Volt Typhoon for deeper persistence and OT reconnaissance. Dragos has attributed several recent high-profile vulnerability exploitation campaigns — including Ivanti and Trimble Cityworks GIS — to SYLVANITE, making it a critical link in China's critical infrastructure pre-positioning strategy.
Coinbase Cartel is a data-extortion-only group active since September 2025, assessed by Halcyon and Fortinet FortiGuard Labs as an offshoot of the ShinyHunters, Scattered Spider, and LAPSUS$ ecosystems. The group does not deploy ransomware encryption; instead it steals sensitive data and extorts victims under threat of public disclosure, amassing 170+ victims. In the last 48 hours (May 15–18, 2026), the group claimed Grafana Labs after exploiting a misconfigured GitHub Actions workflow to exfiltrate Grafana's entire private codebase.
UAT-8616 is a highly sophisticated, assessed China-nexus threat actor designated by Cisco Talos that has been persistently exploiting Cisco Catalyst SD-WAN infrastructure since at least 2023. In the last 48 hours (May 14–15, 2026), the group was attributed with high confidence to exploitation of CVE-2026-20182 (CVSS 10.0), the sixth SD-WAN zero-day exploited in 2026, prompting a CISA Emergency Directive 26-03 mandating federal patching by May 17. The actor's infrastructure overlaps with Operational Relay Box (ORB) networks previously associated with China-nexus espionage operations by Mandiant researchers.
Gunra first emerged in April 2025 targeting South Korean organizations using a Conti-based locker, then evolved into a full RaaS operation by pivoting to a custom-built encryptor. Confirmed at 32 victims as of March 2026 following a late-2025 lull, with activity surging again after new affiliate recruitment. The group is notable for imposing no restrictions on target industries — including hospitals and critical infrastructure — and operating almost exclusively in darkweb forums including RAMP, Rehub, Tierone, and Darkforums.
A previously undocumented threat cluster disclosed by Google Threat Intelligence Group (GTIG) / Mandiant in April 2026. UNC6692 combines email-bombing tactics with Microsoft Teams helpdesk impersonation to deliver the custom 'SNOW' malware suite (SNOWBELT browser extension, SNOWGLAZE Python tunneler, SNOWBASIN persistent backdoor). The group abuses legitimate cloud infrastructure — AWS S3 buckets and Heroku subdomains — for payload delivery and C2, and targets senior-level employees at an elevated rate (77% of observed incidents from March–April 2026). Assessed as financially motivated based on credential-focused post-compromise actions including LSASS dumping, Pass-the-Hash, and Active Directory database exfiltration.
A rapidly maturing ransomware group first observed in February 2025 and strongly assessed as a rebrand of the defunct Rbfs operation, based on overlapping victims, shared infrastructure, and synchronized activity cessation. NightSpire reached 259 claimed victims across 30+ countries by May 2026, posting 74 victims in Q1 2026 alone to rank among the top active groups. In April 2026, the group publicly announced a shift toward a RaaS affiliate model, marking a structural evolution from its closed in-house operation.
DragonForce has evolved from a pro-Palestine hacktivist group into a self-styled ransomware 'cartel' offering a white-label infrastructure model where affiliates operate independent brands using DragonForce encryption, negotiation portals, and leak sites. Ranked 6th by victim volume (426 DLS postings) with 56 victims in March 2026 alone, the group absorbed displaced RansomHub affiliates in April 2025 and formalized a partnership with Scattered Spider. The alliance struck Marks & Spencer (April 2025), Co-op, and Harrods in a coordinated UK retail wave causing over £500M in M&S market cap loss. Law enforcement pressure on Scattered Spider is intensifying: alleged leader Tyler Buchanan pleaded guilty in early April 2026, and member 'Bouquet' (Peter Stokes, 19) was arrested at Helsinki Airport on April 10, 2026 and federally charged on April 28.
Rapid7 disclosed in early May 2026 that MuddyWater conducted a sophisticated false-flag operation, masquerading as the Chaos ransomware-as-a-service group to obscure Iranian state espionage activity. Rather than encrypting files, the group focused exclusively on credential harvesting via Microsoft Teams screen-sharing, MFA manipulation, and deploying remote access tools (DWAgent, AnyDesk, Game.exe RAT) for long-term persistence. The operation — linked to MOIS via the 'Donald Gay' code-signing certificate and moonzonet[.]com C2 infrastructure — represents a documented escalation in Iranian state actors adopting criminal RaaS branding to complicate attribution and delay defensive response.
Bitdefender Labs disclosed on May 13, 2026 that FamousSparrow conducted a multi-wave intrusion against an unnamed Azerbaijani oil and gas company between December 2025 and February 2026 — the first documented FamousSparrow targeting of South Caucasus energy infrastructure. The group repeatedly re-exploited the same vulnerable Microsoft Exchange Server entry point across three distinct waves despite remediation attempts, deploying the Deed RAT (ShadowPad successor) and TernDoor backdoors. This campaign is assessed as geopolitically driven: Azerbaijan has become a critical European energy supplier following the 2024 expiration of Russia's Ukraine gas transit agreement and 2026 Strait of Hormuz disruptions.
Newly tracked threat actor disclosed in Google/Mandiant's May 2026 GTIG report. In March 2026, TeamPCP (UNC6780) compromised multiple GitHub repositories including LiteLLM (a widely-used AI gateway library) and the Trivy vulnerability scanner, embedding a credential stealer called SANDCLOCK in affected build environments. Stolen AWS keys and GitHub tokens were then provided to ransomware affiliates, marking the first documented AI supply chain attack specifically targeting LLM infrastructure for downstream ransomware operations.
On May 11, 2026, Google's Threat Intelligence Group disclosed the first confirmed real-world case of a threat actor using an AI-developed zero-day exploit targeting a popular open-source web-based system administration tool. The group used a large language model to identify a semantic logic flaw — a hard-coded trust assumption in the authentication flow — and generated a Python-based 2FA bypass exploit bearing unmistakable LLM fingerprints (educational docstrings, a hallucinated CVSS score, textbook Pythonic formatting). The group had planned a mass exploitation event; Google coordinated a silent patch with the vendor to disrupt the operation before it launched.
Bitdefender published a major report on May 13, 2026 documenting FamousSparrow's first confirmed intrusion into South Caucasus energy infrastructure — a multi-wave campaign against an Azerbaijani oil and gas company running from December 2025 through February 2026. The group exploited the ProxyNotShell Exchange vulnerability chain (CVE-2022-41082/41040), returned to the same access vector three separate times despite remediation attempts, and deployed evolved variants of the Deed RAT and Terndoor backdoors with a novel two-stage DLL sideloading technique designed to evade sandbox analysis. This expansion marks a strategic pivot into European energy supply-chain targets driven by Azerbaijan's growing role as a gas supplier to 13 EU nations after the collapse of Russian transit agreements.
Rapid7 published research on May 6, 2026 exposing a new MuddyWater false-flag operation in which the Iranian MOIS-affiliated group masqueraded as the Chaos ransomware-as-a-service gang to conduct credential harvesting and long-term espionage against U.S. and MENA organizations. Rather than encrypting files, attackers used Microsoft Teams social engineering with interactive screen-sharing to steal VPN credentials and manipulate MFA, then established persistence via DWAgent and AnyDesk RATs. The operation follows a late-2025 case where MuddyWater similarly impersonated the Qilin RaaS ecosystem against an Israeli target, reflecting a systematic escalation of RaaS false-flag tradecraft to confuse defenders and complicate attribution.
The Gentlemen is the breakout ransomware group of Q1 2026, climbing to #2 globally with 400+ public victims in under 10 months of operation. Founded by 'hastalamuerte,' a former senior Qilin affiliate who departed after a $48,000 commission dispute, the group arrived with a pre-staged stockpile of approximately 14,700 compromised FortiGate devices (exploited via CVE-2024-55591) and 969 validated brute-forced VPN credentials. On May 4, 2026, the group itself was breached by an anonymous party who exfiltrated its internal database from hosting provider 4VPS, exposing full operational structure, ransom negotiations, and confirmed use of DeepSeek and Qwen AI models to accelerate ransomware development. Chain-victimization — using data from one victim to attack that victim's clients — is a confirmed tactic.
On May 11, 2026, Google's Threat Intelligence Group (GTIG) disclosed the first confirmed in-the-wild case of a threat actor using an AI model to discover and weaponize a zero-day vulnerability — a 2FA bypass logic flaw in a popular open-source web-based administration tool. The AI-generated Python exploit script contained hallmark indicators of LLM generation: educational docstrings, a fabricated CVSS score, and textbook Pythonic formatting. GTIG assessed with high confidence that the actors planned a mass exploitation campaign and intervened with the vendor to silently patch the flaw before it could launch. The case demonstrates that AI has compressed the timeline from vulnerability existence to weaponized exploit from weeks to days.
CYFIRMA's Research and Advisory Team discovered Rex Ransomware in underground forums on or before May 15, 2026. The strain encrypts files appending a '.rex48' extension (numeric suffix varies by variant) and drops an HTML ransom note (RANSOM_NOTE.html) claiming to have exfiltrated data for double-extortion leverage. Currently assessed as an early-stage threat with conventional encryption mechanics and no confirmed advanced capabilities, though CYFIRMA assesses it has potential to mature into a more sophisticated operation with expanding cross-platform support and structured extortion methodologies.