Verticals Targeted: Policy Organizations, Academia, International Cooperation Organizations, Diplomatic Missions, Military, Security, Security Research, Virtual Assets
Regions Targeted: South Korea
Related Threat Actors: Kimsuky
Kimsuky Expands AI Capabilities Through a Local AI Development Environment in Operation GitPower
Aug 17, 2026, 2:34:51 PM / by The Hivemind posted in Threat Bulletin, Kimsuky, PowerShell malware, AI-enabled cyber attacks, malicious LNK files, Operation GitPower, North Korea APT, GitHub C2
DAEMON Tools Backdoor Enables Targeted Follow-On Malware Operations
May 11, 2026, 3:03:25 PM / by The Hivemind posted in Threat Bulletin, Supply Chain Attack, PowerShell malware, Chinese threat actors, DAEMON Tools, QUIC RAT, Trojanized Installer, Software Supply Chain Security, Backdoor Malware
Verticals Targeted: Government, Scientific Research, Manufacturing, Retail, Education
Regions Targeted: Russia, Belarus, Thailand, Brazil, Turkey, Spain, Germany, France, Italy, China
Related Families: QUIC RAT
Executive Summary
A large-scale supply chain compromise involving the widely used DAEMON Tools software platform has exposed organizations and consumers to malicious payload deployment through digitally signed installers distributed from the vendor’s legitimate infrastructure. The attack, active since at least April 8, 2026, involved trojanized versions of DAEMON Tools containing embedded backdoors capable of downloading and executing additional malware. While thousands of infection attempts were observed globally, the operation appears selectively targeted, with advanced payloads deployed against a small subset of victims.
Airstalk Used in Supply Chain Attacks
Nov 7, 2025, 12:58:20 PM / by The Hivemind posted in Threat Bulletin, Supply Chain Attack, PowerShell malware, Airstalk Malware, Browser Exfiltration, AirWatch API, MDM Abuse, Nation-State Actor, .NET Malware, CL-STA-1009
Verticals Targeted: Business Process Outsourcing (BPO)
Regions Targeted: Not Specified
Related Families: None
Executive Summary
Airstalk is a new Windows malware family deployed by a suspected nation-state actor in supply chain attacks, leveraging AirWatch API for covert C2 to exfiltrate browser data. Available in PowerShell and .NET variants, the malware highlights evolving threats to third-party vendors.
AdaptixC2
Oct 20, 2025, 4:00:36 PM / by The Hivemind posted in Threat Bulletin, Emerging Threat, PowerShell malware, AdaptixC2, post-exploitation framework, C2 framework, AI-generated malware
Verticals Targeted: Financial
Regions Targeted: Asia
Related Families: Fog Ransomware