๐Title: Spring harvest - Leek Likho group's campaign to hunt for documents
๐ Date: 2026-05-15
๐References:
https://securelist.ru/tr/leek-likho-hunting-for-data-with-tor-and-llms/115601/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข topic="ai"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Kaspersky"
โข sector="Government, Administration"
โข target-information="Belarus"
โข target-information="Russia"
mitre-attack-pattern=['T1547', 'T1090', 'T1059']
MISP event uuid: 8483102e-5129-4460-b958-d38750a66fe4
๐ Date: 2026-05-15
๐References:
https://securelist.ru/tr/leek-likho-hunting-for-data-with-tor-and-llms/115601/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข topic="ai"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Kaspersky"
โข sector="Government, Administration"
โข target-information="Belarus"
โข target-information="Russia"
mitre-attack-pattern=['T1547', 'T1090', 'T1059']
MISP event uuid: 8483102e-5129-4460-b958-d38750a66fe4
๐Title: Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor
๐ Date: 2026-05-14
๐References:
https://www.darktrace.com/blog/chinese-apt-campaign-targets-entities-with-updated-fdmtp-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ก Somewhat Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข country="china"
โข region="142 - Asia"
mitre-attack-pattern=['T1007', 'T1027', 'T1030', 'T1053', 'T1071', 'T1082', 'T1095', 'T1140', 'T1547', 'T1574', 'T1127', 'T1562', 'T1499', 'T1195', 'T1490', 'T1056', 'T1123', 'T1059', 'T1134', 'T1055', 'T1574.001', 'T1106', 'T1547.001', 'T1053.005']
MISP event uuid: 4583b718-a906-4818-8811-97ba5fae34a6
๐ Date: 2026-05-14
๐References:
https://www.darktrace.com/blog/chinese-apt-campaign-targets-entities-with-updated-fdmtp-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ก Somewhat Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข country="china"
โข region="142 - Asia"
mitre-attack-pattern=['T1007', 'T1027', 'T1030', 'T1053', 'T1071', 'T1082', 'T1095', 'T1140', 'T1547', 'T1574', 'T1127', 'T1562', 'T1499', 'T1195', 'T1490', 'T1056', 'T1123', 'T1059', 'T1134', 'T1055', 'T1574.001', 'T1106', 'T1547.001', 'T1053.005']
MISP event uuid: 4583b718-a906-4818-8811-97ba5fae34a6
Darktrace
Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor
Darktrace researchers identified a Twill Typhoonโlinked Chinaโnexus campaign targeting APJ customers. The activity observed includes CDN impersonation, legitimate binaries, and DLL sideloading to deploy a modular .NET RAT.
๐Title: Cato CTRL Threat Research: Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware
๐ Date: 2026-05-13
๐References:
https://www.catonetworks.com/blog/cato-ctrl-suspected-china-linked-threat-actor-targets-global-manufacturer/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1005', 'T1036', 'T1041', 'T1055', 'T1057', 'T1059', 'T1071', 'T1082', 'T1083', 'T1090', 'T1102', 'T1105', 'T1106', 'T1113', 'T1129', 'T1547', 'T1548', 'T1548.002', 'T1070.004', 'T1090.001', 'T1036.008', 'T1571', 'T1620', 'T1547.001', 'T1071.001', 'T1059.003']
MISP event uuid: 2a009741-12ae-4be9-8bd5-9f1fb78483bf
๐ Date: 2026-05-13
๐References:
https://www.catonetworks.com/blog/cato-ctrl-suspected-china-linked-threat-actor-targets-global-manufacturer/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1005', 'T1036', 'T1041', 'T1055', 'T1057', 'T1059', 'T1071', 'T1082', 'T1083', 'T1090', 'T1102', 'T1105', 'T1106', 'T1113', 'T1129', 'T1547', 'T1548', 'T1548.002', 'T1070.004', 'T1090.001', 'T1036.008', 'T1571', 'T1620', 'T1547.001', 'T1071.001', 'T1059.003']
MISP event uuid: 2a009741-12ae-4be9-8bd5-9f1fb78483bf
๐Title: Vidar v1.5 in Go: same family, new language, heavy sandbox checks
๐ Date: 2026-05-16
๐References:
https://www.derp.ca/research/vidar-go-sandbox-dead-drop/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข malpedia="Vidar"
mitre-attack-pattern=['T1497']
MISP event uuid: 086035cf-56d1-42da-82a8-35dfa8c0e324
๐ Date: 2026-05-16
๐References:
https://www.derp.ca/research/vidar-go-sandbox-dead-drop/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข malpedia="Vidar"
mitre-attack-pattern=['T1497']
MISP event uuid: 086035cf-56d1-42da-82a8-35dfa8c0e324
Derp
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
A Go 1.25.4 Vidar v1.5 sample uses a twelve-category sandbox scoring system, Telegram and Steam dead-drop C2 discovery, and process injection APIs.
๐Title: FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation
๐ Date: 2026-05-14
๐References:
https://sublime.security/blog/flowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข sub-category="campaign-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1566']
MISP event uuid: 0e1d220e-d9da-4f25-ac9e-469b98eadcad
๐ Date: 2026-05-14
๐References:
https://sublime.security/blog/flowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข sub-category="campaign-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1566']
MISP event uuid: 0e1d220e-d9da-4f25-ac9e-469b98eadcad
๐Title: macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
๐ Date: 2026-05-18
๐References:
https://www.sentinelone.com/blog/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="SentinelOne"
mitre-attack-pattern=['T1560.001', 'T1539', 'T1074.001', 'T1036.005', 'T1555.001', 'T1204.002', 'T1082', 'T1059.002', 'T1005', 'T1555.003', 'T1083', 'T1566', 'T1059.004', 'T1027', 'T1567.002', 'T1543.001', 'T1070.004', 'T1071.001', 'T1102.001']
MISP event uuid: 9f05b1a5-3943-44f0-9c7a-e5523c92663d
๐ Date: 2026-05-18
๐References:
https://www.sentinelone.com/blog/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="SentinelOne"
mitre-attack-pattern=['T1560.001', 'T1539', 'T1074.001', 'T1036.005', 'T1555.001', 'T1204.002', 'T1082', 'T1059.002', 'T1005', 'T1555.003', 'T1083', 'T1566', 'T1059.004', 'T1027', 'T1567.002', 'T1543.001', 'T1070.004', 'T1071.001', 'T1102.001']
MISP event uuid: 9f05b1a5-3943-44f0-9c7a-e5523c92663d
SentinelOne
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
SHub Reaper bypasses Apple's Terminal mitigation, steals credentials and documents, and plants a persistent backdoor for continued access after infection.
๐Title: Active Supply Chain Attack Compromises Packages on npm
๐ Date: 2026-05-19
๐References:
https://socket.dev/blog/antv-packages-compromised
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="37ebf9d7-5e9a-466f-a42c-6e60313db868"
โข malpedia="Shai-Hulud"
mitre-attack-pattern=['T1059.007', 'T1552.005', 'T1573.001', 'T1106', 'T1219', 'T1552.004', 'T1552.001', 'T1567.001', 'T1059.004', 'T1027', 'T1195.002', 'T1070.004', 'T1071.001', 'T1543.002', 'T1105', 'T1078.004', 'T1552.007']
MISP event uuid: 05e5980c-095e-4789-a521-73f3eb7e7b31
๐ Date: 2026-05-19
๐References:
https://socket.dev/blog/antv-packages-compromised
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="37ebf9d7-5e9a-466f-a42c-6e60313db868"
โข malpedia="Shai-Hulud"
mitre-attack-pattern=['T1059.007', 'T1552.005', 'T1573.001', 'T1106', 'T1219', 'T1552.004', 'T1552.001', 'T1567.001', 'T1059.004', 'T1027', 'T1195.002', 'T1070.004', 'T1071.001', 'T1543.002', 'T1105', 'T1078.004', 'T1552.007']
MISP event uuid: 05e5980c-095e-4789-a521-73f3eb7e7b31
Socket
Mini Shai-Hulud Hits @antv Ecosystem, 639 Compromised npm Pa...
Active npm supply chain attack compromises @antv packages in a fast-moving malicious publish wave tied to Mini Shai-Hulud.
๐Title: Copycat hits another npm package
๐ Date: 2026-05-18
๐References:
https://www.theregister.com/cyber-crime/2026/05/18/shai-hulud-copycat-hits-another-npm-package/5242180
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข malpedia="Shai-Hulud"
mitre-attack-pattern=['T1543', 'T1082', 'T1053', 'T1005', 'T1140', 'T1567', 'T1552.004', 'T1016', 'T1087', 'T1059', 'T1552.001', 'T1027', 'T1573', 'T1195.002', 'T1496', 'T1485', 'T1498', 'T1071.001', 'T1552.007']
MISP event uuid: e1975520-e8cf-4ff6-91ab-31ba2c8ec017
๐ Date: 2026-05-18
๐References:
https://www.theregister.com/cyber-crime/2026/05/18/shai-hulud-copycat-hits-another-npm-package/5242180
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข malpedia="Shai-Hulud"
mitre-attack-pattern=['T1543', 'T1082', 'T1053', 'T1005', 'T1140', 'T1567', 'T1552.004', 'T1016', 'T1087', 'T1059', 'T1552.001', 'T1027', 'T1573', 'T1195.002', 'T1496', 'T1485', 'T1498', 'T1071.001', 'T1552.007']
MISP event uuid: e1975520-e8cf-4ff6-91ab-31ba2c8ec017
theregister
Shai-Hulud copycat worm infects yet another npm package
Plus three other stealers in three other packages, all from the same scumbag
๐Title: Popular Go Decimal Library Targeted by Long-Running Typosquat with DNS Backdoor
๐ Date: 2026-05-20
๐References:
https://socket.dev/blog/popular-go-decimal-library-typosquat-dns-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="37ebf9d7-5e9a-466f-a42c-6e60313db868"
mitre-attack-pattern=['T1071.004', 'T1583.001', 'T1572', 'T1059', 'T1568', 'T1195.002']
MISP event uuid: dc882c2c-c7f2-45d3-b3fb-29500dcf9b18
๐ Date: 2026-05-20
๐References:
https://socket.dev/blog/popular-go-decimal-library-typosquat-dns-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="37ebf9d7-5e9a-466f-a42c-6e60313db868"
mitre-attack-pattern=['T1071.004', 'T1583.001', 'T1572', 'T1059', 'T1568', 'T1195.002']
MISP event uuid: dc882c2c-c7f2-45d3-b3fb-29500dcf9b18
Socket
Popular Go Decimal Library Targeted by Long-Running Typosqua...
A long-running Go typosquat impersonated the popular shopspring/decimal library and used DNS TXT records to execute commands.
๐Title: Inside Banana RAT: From Build Server to Banking Fraud
๐ Date: 2026-05-19
๐References:
https://www.trendmicro.com/en_us/research/26/e/banana-rat.html
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Trend Micro"
โข target-information="Brazil"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1036.005', 'T1204.002', 'T1573.001', 'T1115', 'T1082', 'T1140', 'T1055', 'T1185', 'T1112', 'T1083', 'T1041', 'T1059.001', 'T1566', 'T1001', 'T1027', 'T1071.001', 'T1564.001']
MISP event uuid: 0b84e4bb-274b-4d06-a180-f52c8b474e6d
๐ Date: 2026-05-19
๐References:
https://www.trendmicro.com/en_us/research/26/e/banana-rat.html
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Trend Micro"
โข target-information="Brazil"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1036.005', 'T1204.002', 'T1573.001', 'T1115', 'T1082', 'T1140', 'T1055', 'T1185', 'T1112', 'T1083', 'T1041', 'T1059.001', 'T1566', 'T1001', 'T1027', 'T1071.001', 'T1564.001']
MISP event uuid: 0b84e4bb-274b-4d06-a180-f52c8b474e6d
Trend Micro
Inside SHADOW-WATER-063โs Banana RAT: From Build Server to Banking Fraud
๐Title: Latest PyPi Compromise
๐ Date: 2026-05-19
๐References:
https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Wiz Blog"
mitre-attack-pattern=['T1195.001', 'T1555.005', 'T1106', 'T1005', 'T1555.003', 'T1552.004', 'T1083', 'T1552.001', 'T1552.006', 'T1087.004', 'T1547.001', 'T1078', 'T1027', 'T1195.002', 'T1573.002', 'T1570', 'T1059.006', 'T1071.001', 'T1021.001', 'T1552.007']
MISP event uuid: 1e57b118-ee0f-4afc-a1fb-2b6687f960df
๐ Date: 2026-05-19
๐References:
https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Wiz Blog"
mitre-attack-pattern=['T1195.001', 'T1555.005', 'T1106', 'T1005', 'T1555.003', 'T1552.004', 'T1083', 'T1552.001', 'T1552.006', 'T1087.004', 'T1547.001', 'T1078', 'T1027', 'T1195.002', 'T1573.002', 'T1570', 'T1059.006', 'T1071.001', 'T1021.001', 'T1552.007']
MISP event uuid: 1e57b118-ee0f-4afc-a1fb-2b6687f960df
wiz.io
durabletask: TeamPCP's Latest PyPi Compromise | Wiz Blog
Discover the latest on malicious versions of the pypi package durabletask, matching TeamPCP tactics.
๐Title: Exposing Fox Tempest: A malware-signing service operation
๐ Date: 2026-05-19
๐References:
https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข TA-category="Cybercrime"
โข TA-category="Ransomware"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Microsoft"
โข target-information="United States"
โข target-information="British Indian Ocean Territory"
โข target-information="China"
โข target-information="France"
โข target-information="India"
mitre-attack-pattern=['T1204.002', 'T1553.002', 'T1082', 'T1140', 'T1567', 'T1218', 'T1136.001', 'T1083', 'T1059.001', 'T1566', 'T1562.001', 'T1078', 'T1027', 'T1036.001', 'T1486', 'T1195.002', 'T1189', 'T1071.001', 'T1105', 'T1021.001']
MISP event uuid: 7d52bcc6-a889-4f8a-a841-d5ae3b3714c5
๐ Date: 2026-05-19
๐References:
https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข TA-category="Cybercrime"
โข TA-category="Ransomware"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Microsoft"
โข target-information="United States"
โข target-information="British Indian Ocean Territory"
โข target-information="China"
โข target-information="France"
โข target-information="India"
mitre-attack-pattern=['T1204.002', 'T1553.002', 'T1082', 'T1140', 'T1567', 'T1218', 'T1136.001', 'T1083', 'T1059.001', 'T1566', 'T1562.001', 'T1078', 'T1027', 'T1036.001', 'T1486', 'T1195.002', 'T1189', 'T1071.001', 'T1105', 'T1021.001']
MISP event uuid: 7d52bcc6-a889-4f8a-a841-d5ae3b3714c5
Microsoft News
Exposing Fox Tempest: A malware-signing service operation
Fox Tempest is a financially motivated threat actor operating a malwareโsigningโasโaโservice (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware.
๐Title: 9 Year-Old PHP Vulnerability Keeps Swinging As One of the Most Targeted Vulnerabilities
๐ Date: 2026-05-19
๐References:
https://www.vulncheck.com/blog/cve-2017-9841
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="critical-vuln"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1133', 'T1082', 'T1071', 'T1608.001', 'T1190', 'T1595.002', 'T1505.003', 'T1595', 'T1087', 'T1059', 'T1083', 'T1608', 'T1059.004', 'T1027', 'T1505', 'T1071.001', 'T1018', 'T1046', 'T1105']
MISP event uuid: aa2425c7-fd98-4e8e-84c7-d5a56208bbfe
๐ Date: 2026-05-19
๐References:
https://www.vulncheck.com/blog/cve-2017-9841
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="critical-vuln"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1133', 'T1082', 'T1071', 'T1608.001', 'T1190', 'T1595.002', 'T1505.003', 'T1595', 'T1087', 'T1059', 'T1083', 'T1608', 'T1059.004', 'T1027', 'T1505', 'T1071.001', 'T1018', 'T1046', 'T1105']
MISP event uuid: aa2425c7-fd98-4e8e-84c7-d5a56208bbfe
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
๐Title: [Ransomware] Unconfirmed: Sha******** Met***
๐ Date: 2026-05-29
๐References: https://www.ransomware.live/id/U2hhbnBvb3JuYW0gTWV0YWxzQGxhbWFzaHR1
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: ๐ฅ Data Breach
- TA-category="Ransomware"
๐MISP Galaxies:
- target-information="Malaysia"
- sector="Manufacturing"
- ransomware="lamashtu"
mitre-attack-pattern=[]
MISP event uuid: f2f56dd8-e0fe-45c7-9e83-de9237df5602
๐ Date: 2026-05-29
๐References: https://www.ransomware.live/id/U2hhbnBvb3JuYW0gTWV0YWxzQGxhbWFzaHR1
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: ๐ฅ Data Breach
- TA-category="Ransomware"
๐MISP Galaxies:
- target-information="Malaysia"
- sector="Manufacturing"
- ransomware="lamashtu"
mitre-attack-pattern=[]
MISP event uuid: f2f56dd8-e0fe-45c7-9e83-de9237df5602
Ransomware.live
Victim: Shanpoornam Metals โ lamashtu
Ransomware.live discovered on 2026-05-29 that Shanpoornam Metals has been claimed by Lamashtu ransomware group
Rectifyq Cybersecurity News ๐ฒ๐พ pinned ยซ๐Title: [Ransomware] Unconfirmed: Sha******** Met*** ๐
Date: 2026-05-29 ๐References: https://www.ransomware.live/id/U2hhbnBvb3JuYW0gTWV0YWxzQGxhbWFzaHR1 ๐Rectifyq Taxonomies: Relevancy: ๐ด Highly Relevant Category: ๐ฅ Data Breach - TA-category="Ransomware"โฆยป
๐Title: New burrowing techniques
๐ Date: 2026-05-20
๐References:
https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข sub-category="TA-profile"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข TA-category="APT"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="ESET"
โข target-information="Belgium"
โข target-information="Czech Republic"
โข target-information="Hungary"
โข target-information="Italy"
โข target-information="Nigeria"
โข target-information="Poland"
โข target-information="Serbia"
โข target-information="South Africa"
โข target-information="Spain"
โข threat-actor="Webworm"
โข online-service="7347d685-8e08-4ed9-9f34-264e5e4b567a"
โข online-service="3b16bb5a-eb4f-4603-a909-bebc5df4a46d"
mitre-attack-pattern=['T1550.001', 'T1573.002', 'T1102.002', 'T1078.004', 'T1021.007', 'T1005', 'T1027.013', 'T1041', 'T1567.002', 'T1090.002', 'T1070.004', 'T1090.001', 'T1074.001', 'T1112', 'T1090.003', 'T1547.001', 'T1074.002', 'T1053.005', 'T1583.004', 'T1132.001', 'T1070.006', 'T1608.002', 'T1583.003', 'T1588.006', 'T1595.002', 'T1071.001', 'T1584.006', 'T1059.003', 'T1595.003']
MISP event uuid: 55a58703-da62-4330-bd76-3189d2635e28
๐ Date: 2026-05-20
๐References:
https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข sub-category="TA-profile"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข TA-category="APT"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="ESET"
โข target-information="Belgium"
โข target-information="Czech Republic"
โข target-information="Hungary"
โข target-information="Italy"
โข target-information="Nigeria"
โข target-information="Poland"
โข target-information="Serbia"
โข target-information="South Africa"
โข target-information="Spain"
โข threat-actor="Webworm"
โข online-service="7347d685-8e08-4ed9-9f34-264e5e4b567a"
โข online-service="3b16bb5a-eb4f-4603-a909-bebc5df4a46d"
mitre-attack-pattern=['T1550.001', 'T1573.002', 'T1102.002', 'T1078.004', 'T1021.007', 'T1005', 'T1027.013', 'T1041', 'T1567.002', 'T1090.002', 'T1070.004', 'T1090.001', 'T1074.001', 'T1112', 'T1090.003', 'T1547.001', 'T1074.002', 'T1053.005', 'T1583.004', 'T1132.001', 'T1070.006', 'T1608.002', 'T1583.003', 'T1588.006', 'T1595.002', 'T1071.001', 'T1584.006', 'T1059.003', 'T1595.003']
MISP event uuid: 55a58703-da62-4330-bd76-3189d2635e28
Welivesecurity
Webworm: New burrowing techniques
ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal.
๐Title: PureLogs: Delivery via PawsRunner Steganography
๐ Date: 2026-05-15
๐References:
https://www.fortinet.com/blog/threat-research/purelogs-delivery-via-pawsrunner-steganography
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Fortinet"
โข malpedia="PureLogs Stealer"
mitre-attack-pattern=[]
MISP event uuid: 3c80a5eb-e55b-46df-87f5-aa09ba9bb5d2
๐ Date: 2026-05-15
๐References:
https://www.fortinet.com/blog/threat-research/purelogs-delivery-via-pawsrunner-steganography
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Fortinet"
โข malpedia="PureLogs Stealer"
mitre-attack-pattern=[]
MISP event uuid: 3c80a5eb-e55b-46df-87f5-aa09ba9bb5d2
Fortinet Blog
PureLogs: Delivery via PawsRunner Steganography
FortiGuard Labs has analyzed a steganography-based malware campaign that uses PawsRunner to deliver the PureLogs infostealer, highlighting evolving delivery methods and detection strategies.โฆ
๐Title: The Worm That Keeps on Digging: Latest Wave
๐ Date: 2026-05-19
๐References:
https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Wiz Blog"
โข malpedia="Shai-Hulud"
โข online-service="3b16bb5a-eb4f-4603-a909-bebc5df4a46d"
mitre-attack-pattern=['T1059.007', 'T1539', 'T1555.003', 'T1552.004', 'T1552.001', 'T1567.001', 'T1552.006', 'T1102.003', 'T1574.010', 'T1195.002', 'T1102.002', 'T1059.006', 'T1543.001', 'T1071.001', 'T1543.002', 'T1105', 'T1102.001']
MISP event uuid: a8121f4e-198f-47f3-a649-0b881e64d745
๐ Date: 2026-05-19
๐References:
https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Wiz Blog"
โข malpedia="Shai-Hulud"
โข online-service="3b16bb5a-eb4f-4603-a909-bebc5df4a46d"
mitre-attack-pattern=['T1059.007', 'T1539', 'T1555.003', 'T1552.004', 'T1552.001', 'T1567.001', 'T1552.006', 'T1102.003', 'T1574.010', 'T1195.002', 'T1102.002', 'T1059.006', 'T1543.001', 'T1071.001', 'T1543.002', 'T1105', 'T1102.001']
MISP event uuid: a8121f4e-198f-47f3-a649-0b881e64d745
wiz.io
The Worm That Keeps on Digging: TeamPCP Hits @antv in Latest Wave | Wiz Blog
Multi-ecosystem supply chain compromise by TeamPCP targets GitHub, NPM, and VSCode to steal credentials and establish persistence.
๐Title: Fresh mischief and digital shenanigans
๐ Date: 2026-05-14
๐References:
https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="ESET"
โข target-information="Lithuania"
โข target-information="Poland"
โข target-information="Ukraine"
โข threat-actor="FrostyNeighbor"
โข region="151 - Eastern Europe"
โข sector="Government, Administration"
โข sector="Military"
โข malpedia="Cobalt Strike"
โข malpedia="PicassoLoader"
mitre-attack-pattern=['T1053.005', 'T1583', 'T1036.005', 'T1204.002', 'T1566.001', 'T1082', 'T1059', 'T1608', 'T1057', 'T1041', 'T1060', 'T1588.002', 'T1027', 'T1071.001', 'T1027.009']
MISP event uuid: 62c6b987-cf0c-4a4b-9c57-a5a107789688
๐ Date: 2026-05-14
๐References:
https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="ESET"
โข target-information="Lithuania"
โข target-information="Poland"
โข target-information="Ukraine"
โข threat-actor="FrostyNeighbor"
โข region="151 - Eastern Europe"
โข sector="Government, Administration"
โข sector="Military"
โข malpedia="Cobalt Strike"
โข malpedia="PicassoLoader"
mitre-attack-pattern=['T1053.005', 'T1583', 'T1036.005', 'T1204.002', 'T1566.001', 'T1082', 'T1059', 'T1608', 'T1057', 'T1041', 'T1060', 'T1588.002', 'T1027', 'T1071.001', 'T1027.009']
MISP event uuid: 62c6b987-cf0c-4a4b-9c57-a5a107789688
Welivesecurity
FrostyNeighbor: Fresh mischief and digital shenanigans
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the groupโs continual cyberespionage operations.
๐Title: Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
๐ Date: 2026-05-21
๐References:
https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข sub-category="critical-vuln"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1218.011', 'T1132.001', 'T1059.007', 'T1140', 'T1190', 'T1583.001', 'T1055', 'T1102', 'T1583.006', 'T1204', 'T1059.001', 'T1212', 'T1547.001', 'T1566', 'T1027', 'T1573', 'T1059.003', 'T1071.001', 'T1105']
MISP event uuid: 63a2d681-adb1-4ca3-a1ae-f2d332ea8de5
๐ Date: 2026-05-21
๐References:
https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข sub-category="critical-vuln"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1218.011', 'T1132.001', 'T1059.007', 'T1140', 'T1190', 'T1583.001', 'T1055', 'T1102', 'T1583.006', 'T1204', 'T1059.001', 'T1212', 'T1547.001', 'T1566', 'T1027', 'T1573', 'T1059.003', 'T1071.001', 'T1105']
MISP event uuid: 63a2d681-adb1-4ca3-a1ae-f2d332ea8de5
ๅฅๅฎไฟก X ๅฎ้ชๅฎค
Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
Background
On May 7, 2026, XLab detected a poisoning incident targeting Ghost CMS belonging to one of important clients. The attacker exploited the high-risk SQL injection vulnerability CVE-2026-26980 in Ghost CMS to obtain the target site's Admin API Keyโฆ
On May 7, 2026, XLab detected a poisoning incident targeting Ghost CMS belonging to one of important clients. The attacker exploited the high-risk SQL injection vulnerability CVE-2026-26980 in Ghost CMS to obtain the target site's Admin API Keyโฆ
๐Title: SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
๐ Date: 2026-05-21
๐References:
https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข sub-category="campaign-analysis"
โข topic="ai"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="EclecticIQ"
โข target-information="United States"
โข target-information="United Kingdom"
mitre-attack-pattern=['T1552.001', 'T1555.003', 'T1552.002', 'T1005', 'T1140', 'T1562.001', 'T1189', 'T1573', 'T1041', 'T1083', 'T1562.006', 'T1105', 'T1204.002', 'T1204.001', 'T1027', 'T1059.001', 'T1057', 'T1608.006', 'T1539', 'T1218', 'T1497.001', 'T1071.001', 'T1555.004']
MISP event uuid: 6c37649e-5ce2-4c1b-8fb0-c90e251a93a2
๐ Date: 2026-05-21
๐References:
https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข sub-category="campaign-analysis"
โข topic="ai"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="EclecticIQ"
โข target-information="United States"
โข target-information="United Kingdom"
mitre-attack-pattern=['T1552.001', 'T1555.003', 'T1552.002', 'T1005', 'T1140', 'T1562.001', 'T1189', 'T1573', 'T1041', 'T1083', 'T1562.006', 'T1105', 'T1204.002', 'T1204.001', 'T1027', 'T1059.001', 'T1057', 'T1608.006', 'T1539', 'T1218', 'T1497.001', 'T1071.001', 'T1555.004']
MISP event uuid: 6c37649e-5ce2-4c1b-8fb0-c90e251a93a2
Eclecticiq
SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
Financially motivated eCrime actors will likely continue to expand opportunistic campaigns by impersonating AI platforms. These campaigns generate direct supply chain risk for enterprises, as threat actors target software developer tooling, including AI codingโฆ