Verticals Targeted: Government, Water, Energy, Critical Infrastructure
Regions Targeted: US
Iranian PLC Exploitation Campaign Targets US Critical Infrastructure
Jul 27, 2026 2:18:15 PM / by The Hivemind posted in Threat Bulletin, Iranian APT, ICS cybersecurity, PLC security, Rockwell Automation, Allen-Bradley, OT security, SCADA attack
HOLLOWGRAPH: The New Face of Cloud-Based Espionage
Jul 24, 2026 2:46:49 PM / by The Hivemind posted in Threat Bulletin, cyber espionage, cloud-native malware, Cavern framework, HOLLOWGRAPH, Microsoft Graph API malware, DNS tunneling, Microsoft 365 calendar malware
Regions Targeted: Israel
Related Families: HOLLOWGRAPH, Cavern Framework
Executive Summary
Industry researchers identified HOLLOWGRAPH, a newly discovered malware component that it attributes with high confidence to the Cavern backdoor framework. Rather than relying on traditional command-and-control (C2) infrastructure, HOLLOWGRAPH abuses the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert communications channel for receiving commands and exfiltrating stolen data. The campaign appears highly targeted, with at least 12 identified victims, primarily Israeli organizations, and only a small subset actively communicating with attacker infrastructure, suggesting a disciplined espionage operation.
CrashStealer: How Native macOS Malware Is Raising the Bar
Jul 20, 2026 2:18:45 PM / by The Hivemind posted in Threat Bulletin, MacOS malware, macOS infostealer, Apple Keychain theft, browser credential theft, cryptocurrency wallet malware, CrashStealer, CrashStealer malware
Executive Summary
Industry researchers have identified CrashStealer, a newly active macOS infostealer that combines a signed and notarized delivery mechanism with sophisticated credential theft, cryptocurrency wallet targeting, and extensive anti-analysis techniques. Unlike many existing macOS stealers that rely on AppleScript or Objective-C wrappers, CrashStealer is implemented primarily in native C++, reflecting an increasingly mature approach to macOS malware development. The malware abuses trusted Apple technologies to bypass user protections, validates stolen credentials locally before collection, encrypts harvested data using AES-256-GCM, and establishes persistence through LaunchAgents while masquerading as legitimate Apple components. The campaign demonstrates that macOS ecosystems are no longer niche targets.
GigaWiper: Inside a Modular Cyberweapon
Jul 17, 2026 2:51:19 PM / by The Hivemind posted in Threat Bulletin, modular malware, Microsoft threat intelligence, GigaWiper, BLUERABBIT, Crucio ransomware, Zebrocy, Golang malware, FlockWiper
Related Families: GigaWiper, Crucio, FlockWiper, Zebrocy
Executive Summary
Industry researchers identified GigaWiper, a sophisticated Golang-based malware platform that combines remote administration, persistence, reconnaissance, surveillance, and multiple destructive payloads within a single modular implant. Rather than deploying separate malware families for different objectives, the threat actor consolidated disk wiping, irreversible file encryption, secure data destruction, and extensive command-and-control (C2) functionality into one flexible backdoor.
BusySnake Stealer: Inside Armored Likho's AI-Assisted Malware Operation
Jul 13, 2026 1:09:43 PM / by The Hivemind posted in Threat Bulletin, Infostealer, Spear Phishing, Python Malware, credential theft, Armored Likho, BusySnake Stealer, AI-assisted malware, Eagle Werewolf, reverse SSH tunnel
Verticals Targeted: Government, Electric, Energy, Critical Infrastructure
Regions Targeted: Russia, Kazakhstan, Brazil
Related Threat Actors: Armored Likho
Related Families: BusySnake
Executive Summary
Researchers have identified an active phishing campaign introducing a previously undocumented Python-based infostealer dubbed BusySnake Stealer. Targeting government agencies and electric power organizations across Russia, Kazakhstan, and Brazil, the campaign combines AI-assisted first-stage loaders, modular malware, GitHub-hosted payload delivery, and advanced credential theft capabilities. The operation demonstrates the group's continued technical evolution and highlights how increasingly modular malware can complicate traditional signature-based detection while reinforcing the importance of behavioral analytics and threat intelligence.
JADEPUFFER: Agentic Ransomware Signals a New Era of AI-Driven Cyber Operations
Jul 10, 2026 11:24:05 AM / by The Hivemind posted in Threat Bulletin, AI-powered ransomware, AI-generated malware, autonomous cyber attacks, JADEPUFFER, autonomous malware, agentic ransomware, LLM malware
Executive Summary
Industry researchers recently documented JADEPUFFER, a ransomware operation they assess to be the first publicly documented example of agentic ransomware. Unlike traditional ransomware operations that rely on manually operated toolkits or prebuilt malware, JADEPUFFER reportedly leveraged a large language model (LLM) to autonomously perform reconnaissance, credential theft, lateral movement, persistence, and database extortion. Although the campaign primarily abused well-known vulnerabilities and insecure configurations rather than novel exploits, its ability to adapt to operational failures and generate new task-specific payloads demonstrates how AI may significantly lower the barrier to conducting sophisticated cyberattacks while creating new challenges for defenders.
When Disaster Strikes, Cybercriminals Follow: The Persistent Threat of Disaster-Themed Fraud Campaigns
Jul 6, 2026 2:47:54 PM / by The Hivemind posted in Threat Bulletin, Phishing Campaigns, disaster phishing, charity fraud, natural disaster cyber threats, disaster-themed cyber campaigns, fake charities, cyber fraud
Executive Summary
Natural disasters create opportunities not only for emergency responders and humanitarian organizations to do good, but also for cybercriminals seeking to exploit public fear, urgency, and generosity. Following the June 2026 Venezuela earthquake, researchers observed hundreds of newly registered disaster-themed domains, highlighting how quickly threat actors and opportunistic scammers can capitalize on breaking events. This activity reflects a broader pattern observed after major disasters worldwide, where fraudulent websites, phishing campaigns, and fake charities emerge alongside legitimate relief efforts, complicating efforts to distinguish trusted resources from malicious infrastructure.
SharkLoader Emerges as Stealthy Cobalt Strike Delivery Framework
Jul 2, 2026 9:31:24 AM / by The Hivemind posted in Threat Bulletin, Cobalt Strike, malware loader, DLL sideloading, SharkLoader, StrikeShark
Verticals Targeted: Government, Diplomatic Organizations, Software Development
Regions Targeted: Indonesia, Taiwan, Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, Serbia
Related Families: SharkLoader, Cobalt Strike