๐Title: Threat Actors Weaponize Tiflux RMMs in Malspam Attacks
๐ Date: 2026-05-07
๐References:
https://www.huntress.com/blog/tiflux-rmm-install
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
mitre-attack-pattern=['T1113', 'T1036.005', 'T1204.002', 'T1543.003', 'T1566.002', 'T1082', 'T1219', 'T1112', 'T1070.001', 'T1552.001', 'T1547.001', 'T1562.001', 'T1078', 'T1068', 'T1027', 'T1573', 'T1071.001', 'T1574.002']
MISP event uuid: 66e683a8-e077-43de-b903-1a8d01c2429d
๐ Date: 2026-05-07
๐References:
https://www.huntress.com/blog/tiflux-rmm-install
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
mitre-attack-pattern=['T1113', 'T1036.005', 'T1204.002', 'T1543.003', 'T1566.002', 'T1082', 'T1219', 'T1112', 'T1070.001', 'T1552.001', 'T1547.001', 'T1562.001', 'T1078', 'T1068', 'T1027', 'T1573', 'T1071.001', 'T1574.002']
MISP event uuid: 66e683a8-e077-43de-b903-1a8d01c2429d
Huntress
Threat Actors Weaponize Tiflux RMMs in Malspam Attacks | Huntress
We dug into a recent malspam campaign that involved an installer for a commercially sold remote monitoring and management (RMM) tool called Tiflux.
๐Title: PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
๐ Date: 2026-05-07
๐References:
https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข topic="cloud"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="SentinelOne"
mitre-attack-pattern=['T1613', 'T1132.001', 'T1552.005', 'T1053.003', 'T1021.004', 'T1190', 'T1525', 'T1552.004', 'T1087', 'T1609', 'T1083', 'T1552.001', 'T1041', 'T1212', 'T1059.004', 'T1078', 'T1027', 'T1570', 'T1059.006', 'T1071.001', 'T1543.002', 'T1046', 'T1105', 'T1552.007']
MISP event uuid: 695fc11f-d4b5-4df4-8563-1b8a8a3a8c7d
๐ Date: 2026-05-07
๐References:
https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข topic="cloud"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="SentinelOne"
mitre-attack-pattern=['T1613', 'T1132.001', 'T1552.005', 'T1053.003', 'T1021.004', 'T1190', 'T1525', 'T1552.004', 'T1087', 'T1609', 'T1083', 'T1552.001', 'T1041', 'T1212', 'T1059.004', 'T1078', 'T1027', 'T1570', 'T1059.006', 'T1071.001', 'T1543.002', 'T1046', 'T1105', 'T1552.007']
MISP event uuid: 695fc11f-d4b5-4df4-8563-1b8a8a3a8c7d
SentinelOne
PCPJacked | A Supply Chain Attacker Becomes the Target
Cloud attack framework skips cryptomining, harvests financial, messaging, and enterprise credentials for fraud, spam, and potential extortion.
โค1
๐Title: Custom Attack Tooling Including Undisclosed C2 Infrastructure Targeting Malaysian Organizations
๐ Date: 2026-05-15
๐References:
https://oasis-security.io/blog/malaysian-government-with-undisclosed-c2-infrastructure
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: โ Threat
โข sub-category="infra-profile"
โข target="targeted"
โข mitre-att&ck="none-from-src"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข target-information="Malaysia"
โข sector="Government, Administration"
โข online-service="8206e5d7-9189-4d8b-855d-339fa45e9c47"
mitre-attack-pattern=['T1100', 'T1505.003', 'T1552.001', 'T1567.002', 'T1190', 'T1587.001', 'T1003.003', 'T1059.001', 'T1059.006', 'T1003.002', 'T1071.001', 'T1021.006']
MISP event uuid: a30d2c51-b056-4b55-ad4d-971722af82d8
๐ Date: 2026-05-15
๐References:
https://oasis-security.io/blog/malaysian-government-with-undisclosed-c2-infrastructure
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: โ Threat
โข sub-category="infra-profile"
โข target="targeted"
โข mitre-att&ck="none-from-src"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข target-information="Malaysia"
โข sector="Government, Administration"
โข online-service="8206e5d7-9189-4d8b-855d-339fa45e9c47"
mitre-attack-pattern=['T1100', 'T1505.003', 'T1552.001', 'T1567.002', 'T1190', 'T1587.001', 'T1003.003', 'T1059.001', 'T1059.006', 'T1003.002', 'T1071.001', 'T1021.006']
MISP event uuid: a30d2c51-b056-4b55-ad4d-971722af82d8
oasis-security.io
Custom Attack Tooling Including Undisclosed C2 Infrastructure Targeting Malaysian Organizations
Oasis Security identified a targeted intrusion campaign against multiple Malaysian government organizations, characterized by purpose-built Python tooling per target for internal enumeration and data exfiltration, active webshell deployment, and previouslyโฆ
Rectifyq Cybersecurity News ๐ฒ๐พ pinned ยซ๐Title: Zu*** Fi*** Malaysia Data Leak Claims ๐
Date: 2026-05-02 ๐References: https://x.com/DailyDarkWeb/status/2050382328489447468?s=20 ๐Rectifyq Taxonomies: Relevancy: ๐ด Highly Relevant Category: ๐ฅ Data Breach โข sub-category="leak-forums" โข target="targeted"โฆยป
Rectifyq Cybersecurity News ๐ฒ๐พ pinned ยซ๐Title: Per****** Eko**** Malaysia (Malaysian Eco***** A**********) ๐
Date: 2026-05-02 ๐References: https://x.com/DailyDarkWeb/status/2050389330498130111?s=20 ๐Rectifyq Taxonomies: Relevancy: ๐ด Highly Relevant Category: ๐ฅ Data Breach โข sub-category="leakโฆยป
Rectifyq Cybersecurity News ๐ฒ๐พ pinned ยซ๐Title: Custom Attack Tooling Including Undisclosed C2 Infrastructure Targeting Malaysian Organizations ๐
Date: 2026-05-15 ๐References: https://oasis-security.io/blog/malaysian-government-with-undisclosed-c2-infrastructure ๐Rectifyq Taxonomies: Relevancy:โฆยป
๐Title: 5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer
๐ Date: 2026-05-06
๐References:
https://socket.dev/blog/5-malicious-nuget-packages-impersonate-chinese-ui-libraries
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="crypto-related"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1056.001', 'T1539', 'T1204.002', 'T1497.001', 'T1082', 'T1106', 'T1005', 'T1140', 'T1055', 'T1560', 'T1555.003', 'T1055.013', 'T1059', 'T1083', 'T1552.001', 'T1041', 'T1027', 'T1195.002', 'T1071.001']
MISP event uuid: fd4d5ee1-41ff-493f-bb7b-8f5a25b1c947
๐ Date: 2026-05-06
๐References:
https://socket.dev/blog/5-malicious-nuget-packages-impersonate-chinese-ui-libraries
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="crypto-related"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1056.001', 'T1539', 'T1204.002', 'T1497.001', 'T1082', 'T1106', 'T1005', 'T1140', 'T1055', 'T1560', 'T1555.003', 'T1055.013', 'T1059', 'T1083', 'T1552.001', 'T1041', 'T1027', 'T1195.002', 'T1071.001']
MISP event uuid: fd4d5ee1-41ff-493f-bb7b-8f5a25b1c947
Socket
5 Malicious NuGet Packages Impersonate Chinese UI Libraries ...
Five malicious NuGet packages impersonate Chinese .NET libraries to deploy a stealer targeting browser credentials, crypto wallets, SSH keys, and loca...
๐Title: Donuts and Beagles: Fake Claude site spreads backdoor
๐ Date: 2026-05-07
๐References:
https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="ai"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Sophos"
mitre-attack-pattern=['T1573.001', 'T1106', 'T1140', 'T1059', 'T1083', 'T1204', 'T1041', 'T1547.001', 'T1566', 'T1027', 'T1132', 'T1070.004', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: 7865b246-7bcb-4626-aabe-c50b31d21a89
๐ Date: 2026-05-07
๐References:
https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="ai"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Sophos"
mitre-attack-pattern=['T1573.001', 'T1106', 'T1140', 'T1059', 'T1083', 'T1204', 'T1041', 'T1547.001', 'T1566', 'T1027', 'T1132', 'T1070.004', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: 7865b246-7bcb-4626-aabe-c50b31d21a89
SOPHOS
Donuts and Beagles: Fake Claude site spreads backdoor
A malicious imitation of Anthropicโs Claude site leads to DLL sideloading โ and a backdoor
๐Title: Fake call logs, real payments: How CallPhantom tricks Android users
๐ Date: 2026-05-07
๐References:
https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/
๐Rectifyq Taxonomies:
Relevancy: ๐ก Somewhat Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข sub-category="malware-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="ESET"
โข target-information="India"
โข region="142 - Asia"
mitre-attack-pattern=['T1643', 'T1437.001']
MISP event uuid: ba57e423-eb23-4cc7-88af-cde6f2ad2e53
๐ Date: 2026-05-07
๐References:
https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/
๐Rectifyq Taxonomies:
Relevancy: ๐ก Somewhat Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข sub-category="malware-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="ESET"
โข target-information="India"
โข region="142 - Asia"
mitre-attack-pattern=['T1643', 'T1437.001']
MISP event uuid: ba57e423-eb23-4cc7-88af-cde6f2ad2e53
Welivesecurity
Fake call logs, real payments: How CallPhantom tricks Android users
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history โfor any numberโ and had been downloaded more than seven million times before being taken down.
๐Title: Operation GriefLure: Dissecting an APT Campaign Targeting Vietnam's Military Telecom & Philippine Healthcare
๐ Date: 2026-05-07
๐References:
https://www.seqrite.com/blog/operation-grieflure-dissecting-an-apt-campaign-targeting-vietnams-military-telecom-philippine-healthcare/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Seqrite"
โข target-information="Philippines"
โข target-information="Vietnam"
โข sector="Health"
โข sector="Military"
โข sector="Telecoms"
mitre-attack-pattern=['T1113', 'T1574.007', 'T1547', 'T1204.002', 'T1566.001', 'T1082', 'T1005', 'T1036', 'T1218', 'T1555.003', 'T1134.002', 'T1020', 'T1083', 'T1552.001', 'T1057', 'T1041', 'T1027', 'T1573', 'T1518.001', 'T1059.003', 'T1071.001', 'T1574.002', 'T1564.004', 'T1055.001']
MISP event uuid: 959e2151-f389-4d99-bea5-635a5f3fc2c8
๐ Date: 2026-05-07
๐References:
https://www.seqrite.com/blog/operation-grieflure-dissecting-an-apt-campaign-targeting-vietnams-military-telecom-philippine-healthcare/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Seqrite"
โข target-information="Philippines"
โข target-information="Vietnam"
โข sector="Health"
โข sector="Military"
โข sector="Telecoms"
mitre-attack-pattern=['T1113', 'T1574.007', 'T1547', 'T1204.002', 'T1566.001', 'T1082', 'T1005', 'T1036', 'T1218', 'T1555.003', 'T1134.002', 'T1020', 'T1083', 'T1552.001', 'T1057', 'T1041', 'T1027', 'T1573', 'T1518.001', 'T1059.003', 'T1071.001', 'T1574.002', 'T1564.004', 'T1055.001']
MISP event uuid: 959e2151-f389-4d99-bea5-635a5f3fc2c8
Seqrite Labs
Operation GriefLure: Dissecting an APT Campaign Targeting Vietnamโs Military Telecom & Philippine Healthcare
<p>Table of Contents: Introduction: Key Targets: Infection Chain: Initial Findings about Campaign: Analysis of Decoys: Technical Analysis: Campaign-1: Stage-1: Ho so.rar Campaign: 2 Stage-1: download.zip Stage-2: The LNK & Batch file (Common in 1 & 2 both)โฆ
๐Title: Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
๐ Date: 2026-05-06
๐References:
https://unit42.paloaltonetworks.com/captive-portal-zero-day/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข sub-category="zero-day"
โข target="broad-based"
โข mitre-att&ck="from-original-src"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Palo Alto"
mitre-attack-pattern=['T1498.001', 'T1087.002', 'T1021.004', 'T1071', 'T1190', 'T1055', 'T1572', 'T1070.001', 'T1016', 'T1090', 'T1098', 'T1562.001', 'T1078', 'T1068', 'T1078.002', 'T1070.004', 'T1071.001', 'T1018', 'T1105', 'T1021.001']
MISP event uuid: 8e814525-08af-4e45-a9b3-9402b98b3e88
๐ Date: 2026-05-06
๐References:
https://unit42.paloaltonetworks.com/captive-portal-zero-day/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข sub-category="zero-day"
โข target="broad-based"
โข mitre-att&ck="from-original-src"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Palo Alto"
mitre-attack-pattern=['T1498.001', 'T1087.002', 'T1021.004', 'T1071', 'T1190', 'T1055', 'T1572', 'T1070.001', 'T1016', 'T1090', 'T1098', 'T1562.001', 'T1078', 'T1068', 'T1078.002', 'T1070.004', 'T1071.001', 'T1018', 'T1105', 'T1021.001']
MISP event uuid: 8e814525-08af-4e45-a9b3-9402b98b3e88
Unit 42
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details.
๐Title: ClickFix campaign uses fake macOS utilities lures to deliver infostealers
๐ Date: 2026-05-06
๐References:
https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Microsoft"
mitre-attack-pattern=['T1059.007', 'T1539', 'T1555.001', 'T1082', 'T1059.002', 'T1005', 'T1140', 'T1036', 'T1560', 'T1543.004', 'T1555.003', 'T1087', 'T1083', 'T1552.001', 'T1204', 'T1041', 'T1574', 'T1027', 'T1614', 'T1543.001']
MISP event uuid: 8a797443-5fc5-4804-b43f-77813c7ad5e8
๐ Date: 2026-05-06
๐References:
https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Microsoft"
mitre-attack-pattern=['T1059.007', 'T1539', 'T1555.001', 'T1082', 'T1059.002', 'T1005', 'T1140', 'T1036', 'T1560', 'T1543.004', 'T1555.003', 'T1087', 'T1083', 'T1552.001', 'T1204', 'T1041', 'T1574', 'T1027', 'T1614', 'T1543.001']
MISP event uuid: 8a797443-5fc5-4804-b43f-77813c7ad5e8
Microsoft News
ClickFix campaign uses fake macOS utilities lures to deliver infostealers
Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands. This campaign evades traditional defenses by stealing credentials, wallets, and sensitive data.
๐Title: TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook
๐ Date: 2026-05-07
๐References:
https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข mitre-att&ck="from-original-src"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Elastic"
โข target-information="Brazil"
โข sector="Bank"
mitre-attack-pattern=['T1010', 'T1185', 'T1115', 'T1574.002', 'T1622', 'T1140', 'T1562.001', 'T1105', 'T1056.001', 'T1114.001', 'T1218.007', 'T1106', 'T1027', 'T1059.001', 'T1057', 'T1055', 'T1053.005', 'T1113', 'T1566.001', 'T1497.001', 'T1082', 'T1614.001', 'T1529', 'T1497.003', 'T1056.003', 'T1071.001', 'T1102', 'T1059.003']
MISP event uuid: 31e26c64-8653-4eb8-9977-4da1d6c0cc22
๐ Date: 2026-05-07
๐References:
https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข mitre-att&ck="from-original-src"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Elastic"
โข target-information="Brazil"
โข sector="Bank"
mitre-attack-pattern=['T1010', 'T1185', 'T1115', 'T1574.002', 'T1622', 'T1140', 'T1562.001', 'T1105', 'T1056.001', 'T1114.001', 'T1218.007', 'T1106', 'T1027', 'T1059.001', 'T1057', 'T1055', 'T1053.005', 'T1113', 'T1566.001', 'T1497.001', 'T1082', 'T1614.001', 'T1529', 'T1497.003', 'T1056.003', 'T1071.001', 'T1102', 'T1059.003']
MISP event uuid: 31e26c64-8653-4eb8-9977-4da1d6c0cc22
www.elastic.co
TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook โ Elastic Security Labs
REF3076 uses a trojanized Logitech installer to deploy TCLBANKER, a Brazilian banking trojan with environment-gated payloads, WPF fraud overlays, and self-propagating WhatsApp and Outlook worm modules.
๐Title: AI-Assisted Lure Factory Targets Developers & Gamers
๐ Date: 2026-03-23
๐References:
https://www.netskope.com/blog/openclaw-trap-ai-assisted-lure-factory-targets-developers-gamers
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="ai"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Netskope"
mitre-attack-pattern=[]
MISP event uuid: 3877fbbc-045c-47b7-88fb-f08151c3461c
๐ Date: 2026-03-23
๐References:
https://www.netskope.com/blog/openclaw-trap-ai-assisted-lure-factory-targets-developers-gamers
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="ai"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Netskope"
mitre-attack-pattern=[]
MISP event uuid: 3877fbbc-045c-47b7-88fb-f08151c3461c
Netskope
OpenClaw Trap: AI-Assisted Lure Factory Targets Developers & Gamers
Netskope Threat Labs identified a link to a malware campaign operating across at multiple GitHub repositories, spanning over 300 delivery packages,
๐Title: Abuse of Cloud-Native Infrastructure in Modern Phishing Campaigns
๐ Date: 2026-05-07
๐References:
https://www.cyfirma.com/research/abuse-of-cloud-native-infrastructure-in-modern-phishing-campaigns/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="cloud"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Cyfirma"
mitre-attack-pattern=['T1557', 'T1059.007', 'T1566.002', 'T1566.001', 'T1119', 'T1567', 'T1583.004', 'T1114.003', 'T1584', 'T1102', 'T1528', 'T1027', 'T1078.004', 'T1556']
MISP event uuid: 47aa313e-d63c-41b0-9e9b-37dc020ba38e
๐ Date: 2026-05-07
๐References:
https://www.cyfirma.com/research/abuse-of-cloud-native-infrastructure-in-modern-phishing-campaigns/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="cloud"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Cyfirma"
mitre-attack-pattern=['T1557', 'T1059.007', 'T1566.002', 'T1566.001', 'T1119', 'T1567', 'T1583.004', 'T1114.003', 'T1584', 'T1102', 'T1528', 'T1027', 'T1078.004', 'T1556']
MISP event uuid: 47aa313e-d63c-41b0-9e9b-37dc020ba38e
CYFIRMA
Abuse of Cloud-Native Infrastructure in Modern Phishing Campaigns - CYFIRMA
EXECUTIVE SUMMARY An investigation into phishing activity over the past months has surfaced a decisive structural evolution in how threat...
๐Title: Technical Advisory: Breach of Instructure Canvas LMS
๐ Date: 2026-05-09
๐References:
https://businessinsights.bitdefender.com/technical-advisory-shinyhunters-breach-instructure-canvas-lms
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ฅ Data Breach
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Bitdefender"
โข target-information="United States"
โข target-information="Australia"
โข target-information="United Kingdom"
โข threat-actor="ShinyHunters"
mitre-attack-pattern=['T1557', 'T1539', 'T1114', 'T1594', 'T1530', 'T1550', 'T1589', 'T1586', 'T1528', 'T1591', 'T1590', 'T1199', 'T1566', 'T1078', 'T1486', 'T1598', 'T1213', 'T1485', 'T1078.004', 'T1556']
MISP event uuid: 8b1cc71b-0ea8-4adb-b274-dc6938e0a183
๐ Date: 2026-05-09
๐References:
https://businessinsights.bitdefender.com/technical-advisory-shinyhunters-breach-instructure-canvas-lms
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ฅ Data Breach
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Bitdefender"
โข target-information="United States"
โข target-information="Australia"
โข target-information="United Kingdom"
โข threat-actor="ShinyHunters"
mitre-attack-pattern=['T1557', 'T1539', 'T1114', 'T1594', 'T1530', 'T1550', 'T1589', 'T1586', 'T1528', 'T1591', 'T1590', 'T1199', 'T1566', 'T1078', 'T1486', 'T1598', 'T1213', 'T1485', 'T1078.004', 'T1556']
MISP event uuid: 8b1cc71b-0ea8-4adb-b274-dc6938e0a183
Bitdefender
Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS
This security advisory details what organizations need to know about the second ShinyHunters attack against Instructure in an eight month span.
๐Title: OPERATION SILENTCANVAS: JPEG BASED MULTISTAGE POWERSHELL INTRUSION
๐ Date: 2026-05-09
๐References:
https://www.cyfirma.com/research/operation-silentcanvas-jpeg-based-multistage-powershell-intrusion/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข detection-rules="yara-from-src"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Cyfirma"
mitre-attack-pattern=['T1087', 'T1123', 'T1548.002', 'T1115', 'T1553.002', 'T1027.010', 'T1027.004', 'T1555', 'T1562.001', 'T1573', 'T1041', 'T1070.004', 'T1564.001', 'T1105', 'T1056', 'T1056.001', 'T1136.001', 'T1127.001', 'T1204.002', 'T1036.008', 'T1036.005', 'T1112', 'T1027', 'T1059.001', 'T1219', 'T1021', 'T1113', 'T1518.001', 'T1566.001', 'T1218', 'T1082', 'T1529', 'T1134.001', 'T1497', 'T1071.001', 'T1047', 'T1543.003']
MISP event uuid: 7cfaa038-80a3-4812-9a1a-2df64b55ab01
๐ Date: 2026-05-09
๐References:
https://www.cyfirma.com/research/operation-silentcanvas-jpeg-based-multistage-powershell-intrusion/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข detection-rules="yara-from-src"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Cyfirma"
mitre-attack-pattern=['T1087', 'T1123', 'T1548.002', 'T1115', 'T1553.002', 'T1027.010', 'T1027.004', 'T1555', 'T1562.001', 'T1573', 'T1041', 'T1070.004', 'T1564.001', 'T1105', 'T1056', 'T1056.001', 'T1136.001', 'T1127.001', 'T1204.002', 'T1036.008', 'T1036.005', 'T1112', 'T1027', 'T1059.001', 'T1219', 'T1021', 'T1113', 'T1518.001', 'T1566.001', 'T1218', 'T1082', 'T1529', 'T1134.001', 'T1497', 'T1071.001', 'T1047', 'T1543.003']
MISP event uuid: 7cfaa038-80a3-4812-9a1a-2df64b55ab01
CYFIRMA
OPERATION SILENTCANVAS : JPEG BASED MULTISTAGE POWERSHELL INTRUSION - CYFIRMA
EXECUTIVE SUMMARY At CYFIRMA, we identified a highly sophisticated multi-stage intrusion campaign leveraging a weaponized PowerShell payload disguised as a...
๐Title: Mysterious hacker organization operating secretly for 6 years is exploiting critical cPanel vulnerability to deploy backdoor trojans
๐ Date: 2026-05-11
๐References:
https://blog.xlab.qianxin.com/mr_rot13-the-elusive-6-year-hacker-group-weaponizing-critical-cpanel-flaws-for-backdoor-deployment_cn/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข sub-category="critical-vuln"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1059.007', 'T1119', 'T1005', 'T1140', 'T1190', 'T1219', 'T1070.006', 'T1505.003', 'T1083', 'T1552.003', 'T1552.001', 'T1041', 'T1136.003', 'T1098', 'T1059.004', 'T1078', 'T1027', 'T1567.002', 'T1071.001', 'T1543.002', 'T1136']
MISP event uuid: 2e1d4c8d-0459-4f69-be67-e0bc6a6633fd
๐ Date: 2026-05-11
๐References:
https://blog.xlab.qianxin.com/mr_rot13-the-elusive-6-year-hacker-group-weaponizing-critical-cpanel-flaws-for-backdoor-deployment_cn/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข sub-category="critical-vuln"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1059.007', 'T1119', 'T1005', 'T1140', 'T1190', 'T1219', 'T1070.006', 'T1505.003', 'T1083', 'T1552.003', 'T1552.001', 'T1041', 'T1136.003', 'T1098', 'T1059.004', 'T1078', 'T1027', 'T1567.002', 'T1071.001', 'T1543.002', 'T1136']
MISP event uuid: 2e1d4c8d-0459-4f69-be67-e0bc6a6633fd
ๅฅๅฎไฟก X ๅฎ้ชๅฎค
็งๅฏๆดปๅจ6ๅนด็็ฅ็ง้ปๅฎข็ป็ปMr_Rot13ๆญฃๅจๅฉ็จcPanel้ซๅฑๆผๆด้จ็ฝฒๅ้จๆจ้ฉฌ
่ๆฏ
CVE-2026-41940 ๆฏไธไธชๅฝฑๅ cPanel & WHM ็้ซๅฑๆชๆๆ่ฎค่ฏ็ป่ฟๆผๆดใ่ฏฅไบงๅๅนฟๆณๅบ็จไบ Linux ๆๅกๅจ่ฟ็ปดไธ่ๆไธปๆบ็ฎก็ใๆผๆด CVSS ่ฏๅ้ซ่พพ 9.8๏ผCritical๏ผ๏ผๆปๅป่ ๆ ้ๆไพ่ดฆๅทๆๅฏ็ ๏ผๅณๅฏ่ฟ็จ็ป่ฟ่บซไปฝ่ฎค่ฏๅนถๆฅ็ฎก cPanel / WHM ๆงๅถ้ขๆฟ๏ผๅฏไฝฟๆช็ป่ฟ่บซไปฝ้ช่ฏ็่ฟ็จๆปๅป่ ่ทๅพๅๅฝฑๅๆๅกๅจ็็ฎก็ๅๆ้ใ
่ช 2026 ๅนด 4 ๆ 28 ๆฅๆผๆดๅ ฌๅผๆซ้ฒไปฅๆฅ๏ผXLabๅคง็ฝๅจ่ๆ็ฅ็ณป็ปๆ็ปญ็ๆตๅฐๅคง้้ป็ฐไบง็ป็ปๆญฃๅจ็งฏๆๅฉ็จ่ฏฅๆผๆดๅฎๆฝ็ฝ็ปๆปๅป๏ผ็ธๅ ณ่กโฆ
CVE-2026-41940 ๆฏไธไธชๅฝฑๅ cPanel & WHM ็้ซๅฑๆชๆๆ่ฎค่ฏ็ป่ฟๆผๆดใ่ฏฅไบงๅๅนฟๆณๅบ็จไบ Linux ๆๅกๅจ่ฟ็ปดไธ่ๆไธปๆบ็ฎก็ใๆผๆด CVSS ่ฏๅ้ซ่พพ 9.8๏ผCritical๏ผ๏ผๆปๅป่ ๆ ้ๆไพ่ดฆๅทๆๅฏ็ ๏ผๅณๅฏ่ฟ็จ็ป่ฟ่บซไปฝ่ฎค่ฏๅนถๆฅ็ฎก cPanel / WHM ๆงๅถ้ขๆฟ๏ผๅฏไฝฟๆช็ป่ฟ่บซไปฝ้ช่ฏ็่ฟ็จๆปๅป่ ่ทๅพๅๅฝฑๅๆๅกๅจ็็ฎก็ๅๆ้ใ
่ช 2026 ๅนด 4 ๆ 28 ๆฅๆผๆดๅ ฌๅผๆซ้ฒไปฅๆฅ๏ผXLabๅคง็ฝๅจ่ๆ็ฅ็ณป็ปๆ็ปญ็ๆตๅฐๅคง้้ป็ฐไบง็ป็ปๆญฃๅจ็งฏๆๅฉ็จ่ฏฅๆผๆดๅฎๆฝ็ฝ็ปๆปๅป๏ผ็ธๅ ณ่กโฆ
๐Title: Needle: Inside a Modular Crypto-Stealing C2 That Left Its Keys in the Malware
๐ Date: 2026-05-11
๐References:
https://beelzebub.ai/blog/needle-c2-crypto-stealer-analysis/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข topic="crypto-related"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1056.001', 'T1539', 'T1036.005', 'T1204.002', 'T1566.001', 'T1082', 'T1005', 'T1140', 'T1185', 'T1112', 'T1555.003', 'T1497', 'T1041', 'T1547.001', 'T1056.002', 'T1027', 'T1573', 'T1518.001', 'T1071.001']
MISP event uuid: ddaa6a5b-b336-4e40-bd89-a509c2d2a561
๐ Date: 2026-05-11
๐References:
https://beelzebub.ai/blog/needle-c2-crypto-stealer-analysis/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข topic="crypto-related"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1056.001', 'T1539', 'T1036.005', 'T1204.002', 'T1566.001', 'T1082', 'T1005', 'T1140', 'T1185', 'T1112', 'T1555.003', 'T1497', 'T1041', 'T1547.001', 'T1056.002', 'T1027', 'T1573', 'T1518.001', 'T1071.001']
MISP event uuid: ddaa6a5b-b336-4e40-bd89-a509c2d2a561
Beelzebub
Needle: Inside a Modular Crypto-Stealing C2 That Left Its Keys in the Malware | AI-Native security platform
AI-Native security platform: Deceive, Detect, Respond. โWe turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source framework, deceive attackers during lateral movement within the network. While intruders interactโฆ
๐Title: Inside a phishing panel
๐ Date: 2026-05-07
๐References:
https://pushsecurity.com/blog/inside-criminal-phishing-panel
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="infra-profile"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
MISP event uuid: 6a96a11f-279c-4a64-aef7-4be5b9f681a9
๐ Date: 2026-05-07
๐References:
https://pushsecurity.com/blog/inside-criminal-phishing-panel
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="infra-profile"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
MISP event uuid: 6a96a11f-279c-4a64-aef7-4be5b9f681a9
Push Security
Inside a phishing panel used by ShinyHunters and BlackFile
We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Hereโs what we found.
๐Title: Honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers
๐ Date: 2026-04-29
๐References:
https://www.darktrace.com/blog/darktrace-malware-analysis-jenkins-honeypot-reveals-emerging-botnet-targeting-online-games
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1498.001', 'T1059.007', 'T1036.005', 'T1489', 'T1498.002', 'T1190', 'T1036', 'T1562.004', 'T1036.004', 'T1059.004', 'T1204.003', 'T1571', 'T1027', 'T1095', 'T1070.004', 'T1071.001', 'T1543.002', 'T1105']
MISP event uuid: 05b20c75-5ab1-49a2-9982-73d1a399edd9
๐ Date: 2026-04-29
๐References:
https://www.darktrace.com/blog/darktrace-malware-analysis-jenkins-honeypot-reveals-emerging-botnet-targeting-online-games
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1498.001', 'T1059.007', 'T1036.005', 'T1489', 'T1498.002', 'T1190', 'T1036', 'T1562.004', 'T1036.004', 'T1059.004', 'T1204.003', 'T1571', 'T1027', 'T1095', 'T1070.004', 'T1071.001', 'T1543.002', 'T1105']
MISP event uuid: 05b20c75-5ab1-49a2-9982-73d1a399edd9
Darktrace
Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers
Darktrace analysts observed attackers exploiting a Jenkins honeypot to deploy a new DDoS botnet targeting video game servers. Leveraging Jenkins scriptText abuse, the malware installs a multi-platform payload, evades detection, and launches UDP, TCP, andโฆ