Regions Targeted: Israel
Related Families: HOLLOWGRAPH, Cavern Framework
Executive Summary
Industry researchers identified HOLLOWGRAPH, a newly discovered malware component that it attributes with high confidence to the Cavern backdoor framework. Rather than relying on traditional command-and-control (C2) infrastructure, HOLLOWGRAPH abuses the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert communications channel for receiving commands and exfiltrating stolen data. The campaign appears highly targeted, with at least 12 identified victims, primarily Israeli organizations, and only a small subset actively communicating with attacker infrastructure, suggesting a disciplined espionage operation.
Read More
Executive Summary
Industry researchers have identified CrashStealer, a newly active macOS infostealer that combines a signed and notarized delivery mechanism with sophisticated credential theft, cryptocurrency wallet targeting, and extensive anti-analysis techniques. Unlike many existing macOS stealers that rely on AppleScript or Objective-C wrappers, CrashStealer is implemented primarily in native C++, reflecting an increasingly mature approach to macOS malware development. The malware abuses trusted Apple technologies to bypass user protections, validates stolen credentials locally before collection, encrypts harvested data using AES-256-GCM, and establishes persistence through LaunchAgents while masquerading as legitimate Apple components. The campaign demonstrates that macOS ecosystems are no longer niche targets.
Read More
Related Families: GigaWiper, Crucio, FlockWiper, Zebrocy
Executive Summary
Industry researchers identified GigaWiper, a sophisticated Golang-based malware platform that combines remote administration, persistence, reconnaissance, surveillance, and multiple destructive payloads within a single modular implant. Rather than deploying separate malware families for different objectives, the threat actor consolidated disk wiping, irreversible file encryption, secure data destruction, and extensive command-and-control (C2) functionality into one flexible backdoor.
Read More
Verticals Targeted: Government, Electric, Energy, Critical Infrastructure
Regions Targeted: Russia, Kazakhstan, Brazil
Related Threat Actors: Armored Likho
Related Families: BusySnake
Executive Summary
Researchers have identified an active phishing campaign introducing a previously undocumented Python-based infostealer dubbed BusySnake Stealer. Targeting government agencies and electric power organizations across Russia, Kazakhstan, and Brazil, the campaign combines AI-assisted first-stage loaders, modular malware, GitHub-hosted payload delivery, and advanced credential theft capabilities. The operation demonstrates the group's continued technical evolution and highlights how increasingly modular malware can complicate traditional signature-based detection while reinforcing the importance of behavioral analytics and threat intelligence.
Read More
Executive Summary
Industry researchers recently documented JADEPUFFER, a ransomware operation they assess to be the first publicly documented example of agentic ransomware. Unlike traditional ransomware operations that rely on manually operated toolkits or prebuilt malware, JADEPUFFER reportedly leveraged a large language model (LLM) to autonomously perform reconnaissance, credential theft, lateral movement, persistence, and database extortion. Although the campaign primarily abused well-known vulnerabilities and insecure configurations rather than novel exploits, its ability to adapt to operational failures and generate new task-specific payloads demonstrates how AI may significantly lower the barrier to conducting sophisticated cyberattacks while creating new challenges for defenders.
Read More
Executive Summary
Natural disasters create opportunities not only for emergency responders and humanitarian organizations to do good, but also for cybercriminals seeking to exploit public fear, urgency, and generosity. Following the June 2026 Venezuela earthquake, researchers observed hundreds of newly registered disaster-themed domains, highlighting how quickly threat actors and opportunistic scammers can capitalize on breaking events. This activity reflects a broader pattern observed after major disasters worldwide, where fraudulent websites, phishing campaigns, and fake charities emerge alongside legitimate relief efforts, complicating efforts to distinguish trusted resources from malicious infrastructure.
Read More
Verticals Targeted: Government, Diplomatic Organizations, Software Development
Regions Targeted: Indonesia, Taiwan, Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Nepal, Serbia
Related Families: SharkLoader, Cobalt Strike
Executive Summary
Researchers have identified a previously undocumented malware loader named SharkLoader, used by an intrusion cluster tracked as StrikeShark to deploy Cobalt Strike Beacon against organizations across multiple countries and industries. The campaign has leveraged exploitation of vulnerable internet-facing applications alongside custom droppers disguised as legitimate software installers to establish initial access. Confirmed victims include government-related organizations, diplomatic entities, software development companies, and organizations in additional sectors spanning Asia, Europe, the Middle East, and Latin America.
Read More
Verticals Targeted: Insurance, Education, Information Technology
Related Families: Mistic, ModeloRAT
Read More