SLEEPWALKER: Passive Backdoor Awakens Only When Attackers Call
Aug 31, 2026, 2:54:48 PM / by The Hivemind posted in Threat Bulletin, DLL side-loading, passive backdoor, ESET Management Agent malware, ERAAgent.exe, SLEEPWALKER malware
UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor
Aug 28, 2026, 12:23:10 PM / by The Hivemind posted in Threat Bulletin, BYOVD attack, AI-assisted malware, UAT-10147, SPECTRE malware, AI-powered cybercrime, agentic AI cyberattacks, cross-platform malware
Verticals Targeted: Government, Education, Media, Technology, Gaming
Regions Targeted: Brazil, Bolivia, China, Canada, Vietnam
Executive Summary
Cisco Talos identified an advanced intrusion ecosystem operated by UAT-10147, a Chinese-speaking, financially motivated threat actor targeting internet-facing Windows and Linux servers. The group combines exploitation of known vulnerabilities with AI-assisted offensive workflows, custom malware, open-source tools, and commodity backdoors. Central to recent activity is SPECTRE, a cross-platform backdoor providing extensive post-exploitation, credential theft, process injection, and defense evasion capabilities. On Linux systems, SPECTRE can deploy the Specter kernel rootkit, while its Windows variant incorporates Bring Your Own Vulnerable Driver (BYOVD) functionality capable of neutralizing endpoint detection and response (EDR) visibility.
The Evolution of ClickFix: Mapping the Growing *Fix Family
Aug 24, 2026, 3:34:35 PM / by The Hivemind posted in Threat Bulletin, ClickFix, FileFix, PowerShell attacks, prompt injection, Windows Run
Verticals Targeted: Government, Financial Services, Education, Transportation, Cryptocurrency, Enterprise Environments
Regions Targeted: North America, Europe, Middle East
Executive Summary
ClickFix has evolved from fake CAPTCHA and technical support lures into a broader family of attacks that manipulate trusted intermediaries to cross security boundaries. Based on publicly documented campaigns and independent vendor research, we assess that the most significant evolution is the diversification of trusted workflows being abused rather than the proliferation of named variants. The ClickFix family now spans execution, workflow and identity-focused techniques, demonstrating a flexible methodology adaptable to both cybercriminal and state-sponsored operations while challenging defenders to prioritize behavioral detection over individual malware families.
AmnesiaStealer Introduces Interactive Browser Session Hijacking to macOS
Aug 21, 2026, 3:13:30 PM / by The Hivemind posted in Threat Bulletin, macOS infostealer malware, Chromium browser session hijacking, AmnesiaStealer malware, AmnesiaStealer macOS infostealer, ClickFix macOS malware, fake GitHub malware campaign, macOS credential stealing malware
Executive Summary
Industry researchers identified AmnesiaStealer, a multi-stage Rust-based macOS infostealer distributed through a ClickFix social engineering campaign. Victims are lured to a counterfeit GitHub download page and instructed to execute a Terminal command that deploys a three-stage malware payload capable of harvesting credentials, browser data, Apple Notes, Telegram session data, documents, and keychain contents. While these capabilities are consistent with modern macOS information stealers, AmnesiaStealer distinguishes itself through a dedicated Stage 2 browser streaming module that provides operators with hidden, interactive control of Chromium-based browsers via the Chrome DevTools Protocol (CDP). Rather than simply stealing browser artifacts for offline analysis, the malware enables attackers to directly abuse authenticated browser sessions after compromise.
Kimsuky Expands AI Capabilities Through a Local AI Development Environment in Operation GitPower
Aug 17, 2026, 2:34:51 PM / by The Hivemind posted in Threat Bulletin, Kimsuky, PowerShell malware, AI-enabled cyber attacks, malicious LNK files, Operation GitPower, North Korea APT, GitHub C2
Verticals Targeted: Policy Organizations, Academia, International Cooperation Organizations, Diplomatic Missions, Military, Security, Security Research, Virtual Assets
Regions Targeted: South Korea
Related Threat Actors: Kimsuky
Executive Summary
Researchers identified a continuation of the North Korean Kimsuky cyber espionage campaign, designated Operation GitPower, which combines established spear-phishing techniques with emerging artificial intelligence capabilities. While the campaign continues to rely on malicious LNK files, PowerShell loaders, and GitHub-hosted C2 infrastructure, investigators also uncovered evidence that the threat actor has deployed local large language model (LLM) environments, retrieval-augmented generation (RAG), AI development frameworks, and speech-to-text tools. The findings suggest Kimsuky is systematically building AI-enabled operational capabilities to support future espionage activities rather than merely experimenting with generative AI.
DeadLock Ransomware Leverages Decentralized Infrastructure to Increase Operational Resilience
Aug 14, 2026, 2:56:45 PM / by The Hivemind posted in Threat Bulletin, Ransomware, double extortion, Session messaging, ransomware-as-a-service, DeadLock ransomware, decentralized infrastructure, Polygon blockchain, Wasabi object storage
Verticals Targeted: Information Technology, Mining, Transportation and Logistics, Manufacturing, Hospitality, Consumer Goods
Regions Targeted: Europe, Asia, North America, South America, Africa
Self-Propagating ChainDrop Worm Infects More Than 400 npm Packages in Major Software Supply Chain Attack
Aug 10, 2026, 3:15:02 PM / by The Hivemind posted in Threat Bulletin, npm malware, Software Supply Chain Security, Mini Shai-Hulud, JavaScript malware, GitHub Actions OIDC, npm supply chain attack
Related Families: Mini Shai-Hulud, ChainDrop
Executive Summary
Industry researchers identified a large-scale software supply chain attack involving more than 400 compromised npm packages distributed across multiple unrelated publishers. The campaign delivers a new variant of the Mini Shai-Hulud malware, dubbed ChainDrop, through malicious preinstall lifecycle scripts, enabling credential theft, cloud and infrastructure enumeration, repository compromise, and automated propagation using stolen npm publishing credentials. By targeting both developer workstations and CI/CD environments, the campaign demonstrates how modern software supply chain attacks increasingly leverage trusted developer identities to compromise downstream software ecosystems.
OctLurk and SilkLurk: Analysis of a Modular Cyber Espionage Framework
Aug 6, 2026, 2:14:03 PM / by The Hivemind posted in Threat Bulletin, PlugX, credential theft, cyber espionage, OctLurk, SilkLurk, LurkProxy, modular backdoor
Verticals Targeted: Government, Ministries of Foreign Affairs, Healthcare, Research, Logistics, Law Enforcement, Urban Planning and Facilities Management, Education
Regions Targeted: Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, Uzbekistan
Related Families: OctLurk, SilkLurk, LurkProxy, PlugX