Verticals Targeted: Cryptocurrency
Regions Targeted: United States, Germany, Romania, Venezuela
Related Families: Starland RAT, WLDR Framework, Remcos RAT, CastleStealer
ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework
Aug 3, 2026, 1:59:52 PM / by The Hivemind posted in Threat Bulletin, Remcos RAT, ClickFix, UAT-11795, Cisco Talos, Starland RAT, WLDR, WLDR PowerShell, CastleStealer, Trojanized installers
Mirage Kitten Deploys NightLedger Backdoor in Espionage Campaign Targeting the Middle East and Africa
Jul 31, 2026, 1:58:15 PM / by The Hivemind posted in Threat Bulletin, Spear Phishing, Nimbus Manticore, cyber espionage, aerospace cybersecurity, UNC1549, Mirage Kitten, NightLedger, ArcBridge, Smoke Sandstorm, WebSocket tunneling, BridgeHead
Verticals Targeted: Aerospace, Aviation, Defense, Telecommunications, Government, Financial Services, SMBs
Regions Targeted: Egypt, Jordan, Tanzania, Pakistan, Ethiopia, Burkina Faso
Related Threat Actors: Mirage Kitten
Related Families: NightLedger, BridgeHead, ArcBridge
Executive Summary
New research details the continued evolution of Mirage Kitten, an advanced persistent threat (APT) group conducting cyber-espionage operations across the Middle East and Africa. The campaign introduces three previously undocumented malware families, NightLedger, BridgeHead, and ArcBridge, that provide reconnaissance, command execution, covert tunneling, and persistent post-compromise access capabilities. The findings demonstrate Mirage Kitten's continued investment in bespoke malware development and operational security to support long-term intelligence collection.
Iranian PLC Exploitation Campaign Targets US Critical Infrastructure
Jul 27, 2026, 2:18:15 PM / by The Hivemind posted in Threat Bulletin, Iranian APT, ICS cybersecurity, PLC security, Rockwell Automation, Allen-Bradley, OT security, SCADA attack
Verticals Targeted: Government, Water, Energy, Critical Infrastructure
Regions Targeted: US
HOLLOWGRAPH: The New Face of Cloud-Based Espionage
Jul 24, 2026, 2:46:49 PM / by The Hivemind posted in Threat Bulletin, cyber espionage, cloud-native malware, Cavern framework, HOLLOWGRAPH, Microsoft Graph API malware, DNS tunneling, Microsoft 365 calendar malware
Regions Targeted: Israel
Related Families: HOLLOWGRAPH, Cavern Framework
Executive Summary
Industry researchers identified HOLLOWGRAPH, a newly discovered malware component that it attributes with high confidence to the Cavern backdoor framework. Rather than relying on traditional command-and-control (C2) infrastructure, HOLLOWGRAPH abuses the Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert communications channel for receiving commands and exfiltrating stolen data. The campaign appears highly targeted, with at least 12 identified victims, primarily Israeli organizations, and only a small subset actively communicating with attacker infrastructure, suggesting a disciplined espionage operation.
CrashStealer: How Native macOS Malware Is Raising the Bar
Jul 20, 2026, 2:18:45 PM / by The Hivemind posted in Threat Bulletin, MacOS malware, macOS infostealer, Apple Keychain theft, browser credential theft, cryptocurrency wallet malware, CrashStealer, CrashStealer malware
Executive Summary
Industry researchers have identified CrashStealer, a newly active macOS infostealer that combines a signed and notarized delivery mechanism with sophisticated credential theft, cryptocurrency wallet targeting, and extensive anti-analysis techniques. Unlike many existing macOS stealers that rely on AppleScript or Objective-C wrappers, CrashStealer is implemented primarily in native C++, reflecting an increasingly mature approach to macOS malware development. The malware abuses trusted Apple technologies to bypass user protections, validates stolen credentials locally before collection, encrypts harvested data using AES-256-GCM, and establishes persistence through LaunchAgents while masquerading as legitimate Apple components. The campaign demonstrates that macOS ecosystems are no longer niche targets.
GigaWiper: Inside a Modular Cyberweapon
Jul 17, 2026, 2:51:19 PM / by The Hivemind posted in Threat Bulletin, modular malware, Microsoft threat intelligence, GigaWiper, BLUERABBIT, Crucio ransomware, Zebrocy, Golang malware, FlockWiper
Related Families: GigaWiper, Crucio, FlockWiper, Zebrocy
Executive Summary
Industry researchers identified GigaWiper, a sophisticated Golang-based malware platform that combines remote administration, persistence, reconnaissance, surveillance, and multiple destructive payloads within a single modular implant. Rather than deploying separate malware families for different objectives, the threat actor consolidated disk wiping, irreversible file encryption, secure data destruction, and extensive command-and-control (C2) functionality into one flexible backdoor.
BusySnake Stealer: Inside Armored Likho's AI-Assisted Malware Operation
Jul 13, 2026, 1:09:43 PM / by The Hivemind posted in Threat Bulletin, Infostealer, Spear Phishing, Python Malware, credential theft, Armored Likho, BusySnake Stealer, AI-assisted malware, Eagle Werewolf, reverse SSH tunnel
Verticals Targeted: Government, Electric, Energy, Critical Infrastructure
Regions Targeted: Russia, Kazakhstan, Brazil
Related Threat Actors: Armored Likho
Related Families: BusySnake
Executive Summary
Researchers have identified an active phishing campaign introducing a previously undocumented Python-based infostealer dubbed BusySnake Stealer. Targeting government agencies and electric power organizations across Russia, Kazakhstan, and Brazil, the campaign combines AI-assisted first-stage loaders, modular malware, GitHub-hosted payload delivery, and advanced credential theft capabilities. The operation demonstrates the group's continued technical evolution and highlights how increasingly modular malware can complicate traditional signature-based detection while reinforcing the importance of behavioral analytics and threat intelligence.
JADEPUFFER: Agentic Ransomware Signals a New Era of AI-Driven Cyber Operations
Jul 10, 2026, 11:24:05 AM / by The Hivemind posted in Threat Bulletin, AI-powered ransomware, AI-generated malware, autonomous cyber attacks, JADEPUFFER, autonomous malware, agentic ransomware, LLM malware