Rectifyq Cybersecurity News ๐ฒ๐พ pinned ยซ๐Title: Cyber-Enabled Maritime Sanctions Evasion ๐
Date: 2026-06-11 ๐References: https://www.recordedfuture.com/research/media_12cb79eec13b6af7520af3c1ae6768c0f4b25e945.gif?width=1200&format=pjpg&optimize=medium https://www.recordedfuture.com/research/cyberโฆยป
๐Title: Affidavit in Support of Application for Criminal Complaint
๐ Date: 2026-06-09
๐References:
https://cyberscoop.com/wp-content/uploads/sites/3/2026/06/11-1.pdf
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="TA-profile"
โข sub-category="report"
โข target="broad-based"
โข topic="geopolitical"
โข TA-category="APT"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข target-information="United States"
โข threat-actor="Void Blizzard"
mitre-attack-pattern=['T1133', 'T1114', 'T1071', 'T1562', 'T1567', 'T1589', 'T1185', 'T1090', 'T1020', 'T1588.001', 'T1070', 'T1586', 'T1590', 'T1048', 'T1588.002', 'T1566', 'T1078', 'T1573', 'T1598', 'T1213']
MISP event uuid: 48a8d13e-0e7e-4d6f-8807-d4d9761dc8b5
๐ Date: 2026-06-09
๐References:
https://cyberscoop.com/wp-content/uploads/sites/3/2026/06/11-1.pdf
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="TA-profile"
โข sub-category="report"
โข target="broad-based"
โข topic="geopolitical"
โข TA-category="APT"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข target-information="United States"
โข threat-actor="Void Blizzard"
mitre-attack-pattern=['T1133', 'T1114', 'T1071', 'T1562', 'T1567', 'T1589', 'T1185', 'T1090', 'T1020', 'T1588.001', 'T1070', 'T1586', 'T1590', 'T1048', 'T1588.002', 'T1566', 'T1078', 'T1573', 'T1598', 'T1213']
MISP event uuid: 48a8d13e-0e7e-4d6f-8807-d4d9761dc8b5
๐Title: Defending the Digital Pitch: World Cup 2026 Cyber Threats
๐ Date: 2026-06-11
๐References:
https://www.cyberproof.com/blog/defending-the-digital-pitch-world-cup-2026-cyber-threats/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1557', 'T1583', 'T1539', 'T1566.002', 'T1190', 'T1583.001', 'T1589', 'T1185', 'T1588.001', 'T1586', 'T1528', 'T1204', 'T1199', 'T1566', 'T1110', 'T1078', 'T1499', 'T1598', 'T1189', 'T1498']
MISP event uuid: 1708688e-6ab1-4949-83be-1fe8e61d59e3
๐ Date: 2026-06-11
๐References:
https://www.cyberproof.com/blog/defending-the-digital-pitch-world-cup-2026-cyber-threats/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1557', 'T1583', 'T1539', 'T1566.002', 'T1190', 'T1583.001', 'T1589', 'T1185', 'T1588.001', 'T1586', 'T1528', 'T1204', 'T1199', 'T1566', 'T1110', 'T1078', 'T1499', 'T1598', 'T1189', 'T1498']
MISP event uuid: 1708688e-6ab1-4949-83be-1fe8e61d59e3
CyberProof
Defending the Digital Pitch: World Cup 2026 Cyber Threats
Contributors: Amit Gini, Tom Saar, Liora Ziv Introduction Kicking off today, the 2026 FIFA World Cup is expected to be one of the largest and most
๐Title: World Cup 2026 Mobile Targeted Phishing: The Global Social Engineering Threat
๐ Date: 2026-06-11
๐References:
https://zimperium.com/blog/world-cup-2026-mobile-targeted-phishing-the-global-social-engineering-threat?hs_amp=true
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Zimperium"
mitre-attack-pattern=['T1539', 'T1114', 'T1566.002', 'T1598.003', 'T1566.001', 'T1586.002', 'T1608.001', 'T1583.001', 'T1589', 'T1185', 'T1056.003', 'T1589.002', 'T1608.005', 'T1528', 'T1566', 'T1056', 'T1589.001', 'T1598', 'T1204.001']
MISP event uuid: 2d22208a-0035-4f4c-8dfd-a7b056feab82
๐ Date: 2026-06-11
๐References:
https://zimperium.com/blog/world-cup-2026-mobile-targeted-phishing-the-global-social-engineering-threat?hs_amp=true
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Zimperium"
mitre-attack-pattern=['T1539', 'T1114', 'T1566.002', 'T1598.003', 'T1566.001', 'T1586.002', 'T1608.001', 'T1583.001', 'T1589', 'T1185', 'T1056.003', 'T1589.002', 'T1608.005', 'T1528', 'T1566', 'T1056', 'T1589.001', 'T1598', 'T1204.001']
MISP event uuid: 2d22208a-0035-4f4c-8dfd-a7b056feab82
Zimperium
World Cup 2026 Mobile Targeted Phishing: The Global Social Engineering Threat
true
๐Title: Targets Education Sector with Oracle PeopleSoft Exploit
๐ Date: 2026-06-11
๐References:
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข mitre-att&ck="none-from-src"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Mandiant"
โข target-information="United States"
โข sector="Education"
โข threat-actor="ShinyHunters"
mitre-attack-pattern=['T1560.001', 'T1110.001', 'T1133', 'T1069', 'T1114', 'T1036.005', 'T1021.004', 'T1190', 'T1491', 'T1505.003', 'T1083', 'T1552.001', 'T1041', 'T1059.004', 'T1078', 'T1027', 'T1486', 'T1573.002', 'T1071.001', 'T1018']
MISP event uuid: 612a10dd-f897-4556-ab31-f50a1b128318
๐ Date: 2026-06-11
๐References:
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข mitre-att&ck="none-from-src"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Mandiant"
โข target-information="United States"
โข sector="Education"
โข threat-actor="ShinyHunters"
mitre-attack-pattern=['T1560.001', 'T1110.001', 'T1133', 'T1069', 'T1114', 'T1036.005', 'T1021.004', 'T1190', 'T1491', 'T1505.003', 'T1083', 'T1552.001', 'T1041', 'T1059.004', 'T1078', 'T1027', 'T1486', 'T1573.002', 'T1071.001', 'T1018']
MISP event uuid: 612a10dd-f897-4556-ab31-f50a1b128318
Google Cloud Blog
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Google Cloud Blog
An active compromise and extortion campaign attributed to ShinyHunters targeting Oracle PeopleSoft with a zero-day exploit.
๐Title: UNC1151/Ghostwriter phishing campaign targeting Gmail accounts
๐ Date: 2026-06-12
๐References:
https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข target-information="Poland"
โข threat-actor="Ghostwriter"
mitre-attack-pattern=['T1566']
MISP event uuid: 5c1e7285-f735-49d8-9fcf-ef31d47b10ae
๐ Date: 2026-06-12
๐References:
https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข target-information="Poland"
โข threat-actor="Ghostwriter"
mitre-attack-pattern=['T1566']
MISP event uuid: 5c1e7285-f735-49d8-9fcf-ef31d47b10ae
cert.pl
UNC1151/Ghostwriter phishing campaign targeting Gmail accounts
Recently, we have been observing attacks by the UNC1151/Ghostwriter group targeting Gmail accounts. This group has been regularly attacking the mailboxes of Polish citizens for several years, although in the past these attacks focused on other email providers.โฆ
๐Title: How to defend ARM64 cloud infrastructure
๐ Date: 2026-06-11
๐References:
https://www.reversinglabs.com/blog/defend-cloud-infrastructure-itscape
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข sub-category="critical-vuln"
โข target="broad-based"
โข topic="cloud"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1592', 'T1082', 'T1005', 'T1611', 'T1610', 'T1548', 'T1059', 'T1609', 'T1204', 'T1068']
MISP event uuid: b91d23b7-24fc-4cac-87d6-d5dc6b6bfd67
๐ Date: 2026-06-11
๐References:
https://www.reversinglabs.com/blog/defend-cloud-infrastructure-itscape
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข sub-category="critical-vuln"
โข target="broad-based"
โข topic="cloud"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1592', 'T1082', 'T1005', 'T1611', 'T1610', 'T1548', 'T1059', 'T1609', 'T1204', 'T1068']
MISP event uuid: b91d23b7-24fc-4cac-87d6-d5dc6b6bfd67
ReversingLabs
How to defend ARM64 cloud infrastructure from ITScape | RL Blog
RL has documented CVE-2026-46316, and developed two YARA rules to help detect exploits of the multi-tenant cloud vulnerability.
๐Title: Akira, LimeWire, and the Sour Taste of Data Exfiltration
๐ Date: 2026-06-12
๐References:
https://www.huntress.com/blog/akira-ransomware-limewire-data-exfiltration
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข TA-category="Ransomware"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
โข ransomware="Akira"
mitre-attack-pattern=['T1560.001', 'T1069', 'T1074.001', 'T1087.002', 'T1082', 'T1005', 'T1140', 'T1083', 'T1497', 'T1041', 'T1562.001', 'T1078', 'T1486', 'T1567.002', 'T1018', 'T1105', 'T1021.001', 'T1490']
MISP event uuid: bb394d28-549f-4209-a897-d318fd04266f
๐ Date: 2026-06-12
๐References:
https://www.huntress.com/blog/akira-ransomware-limewire-data-exfiltration
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข TA-category="Ransomware"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
โข ransomware="Akira"
mitre-attack-pattern=['T1560.001', 'T1069', 'T1074.001', 'T1087.002', 'T1082', 'T1005', 'T1140', 'T1083', 'T1497', 'T1041', 'T1562.001', 'T1078', 'T1486', 'T1567.002', 'T1018', 'T1105', 'T1021.001', 'T1490']
MISP event uuid: bb394d28-549f-4209-a897-d318fd04266f
Huntress
Akira, LimeWire, and the Sour Taste of Data Exfiltration | Huntress
A recent investigation uncovered an Akira affiliate abusing a website owned by file-sharing app LimeWire for data exfiltration. Here's how the attack unfolded.
๐Title: Interlock and Rhysida within the Ransomware Ecosystem
๐ Date: 2026-06-12
๐References:
https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="TA-profile"
โข TA-category="Ransomware"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="IBM X-Force"
โข target-information="United States"
โข ransomware="interlock"
โข ransomware="rhysida"
mitre-attack-pattern=['T1053.005', 'T1218.011', 'T1003', 'T1087.002', 'T1140', 'T1190', 'T1055', 'T1482', 'T1083', 'T1204', 'T1059.001', 'T1547.001', 'T1566', 'T1486', 'T1203', 'T1059.003', 'T1189', 'T1027.002', 'T1018', 'T1105', 'T1021.001', 'T1490']
MISP event uuid: 4f2a0ee4-d11b-46a6-ba6d-1f9be509076d
๐ Date: 2026-06-12
๐References:
https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="TA-profile"
โข TA-category="Ransomware"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="IBM X-Force"
โข target-information="United States"
โข ransomware="interlock"
โข ransomware="rhysida"
mitre-attack-pattern=['T1053.005', 'T1218.011', 'T1003', 'T1087.002', 'T1140', 'T1190', 'T1055', 'T1482', 'T1083', 'T1204', 'T1059.001', 'T1547.001', 'T1566', 'T1486', 'T1203', 'T1059.003', 'T1189', 'T1027.002', 'T1018', 'T1105', 'T1021.001', 'T1490']
MISP event uuid: 4f2a0ee4-d11b-46a6-ba6d-1f9be509076d
Ibm
Interlock and Rhysida within the Ransomware Ecosystem | IBM
IBM X-Force uncovers deep links between Interlock and Rhysida ransomware actors, detailing shared malware, crypters, and infrastructure across the ecosystem, with insights into infection chains, initial access brokers, and evolving tools over two years ofโฆ
๐Title: How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches
๐ Date: 2026-06-09
๐References:
https://malext.io/reports/SearchJack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1033', 'T1056.001', 'T1539', 'T1036.005', 'T1204.002', 'T1566.002', 'T1082', 'T1176', 'T1005', 'T1036', 'T1185', 'T1112', 'T1083', 'T1568', 'T1027', 'T1573', 'T1213', 'T1189', 'T1071.001']
MISP event uuid: c2e25435-9441-48e7-a5cc-c2a50ceff102
๐ Date: 2026-06-09
๐References:
https://malext.io/reports/SearchJack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1033', 'T1056.001', 'T1539', 'T1036.005', 'T1204.002', 'T1566.002', 'T1082', 'T1176', 'T1005', 'T1036', 'T1185', 'T1112', 'T1083', 'T1568', 'T1027', 'T1573', 'T1213', 'T1189', 'T1071.001']
MISP event uuid: c2e25435-9441-48e7-a5cc-c2a50ceff102
malext.io
SearchJack: How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches - MalExt Sentry
Threat intelligence report: SearchJack: How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches. Research by MalExt Sentry.
๐Title: Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
๐ Date: 2026-06-15
๐References:
https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข threat-actor="APT37"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1025', 'T1204.002', 'T1497.001', 'T1566.001', 'T1005', 'T1140', 'T1055', 'T1112', 'T1041', 'T1059.001', 'T1547.001', 'T1027', 'T1059.003', 'T1070.004', 'T1071.001', 'T1102.001']
MISP event uuid: 24638e19-caf4-4253-8ead-b7f85dda8137
๐ Date: 2026-06-15
๐References:
https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข threat-actor="APT37"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1025', 'T1204.002', 'T1497.001', 'T1566.001', 'T1005', 'T1140', 'T1055', 'T1112', 'T1041', 'T1059.001', 'T1547.001', 'T1027', 'T1059.003', 'T1070.004', 'T1071.001', 'T1102.001']
MISP event uuid: 24638e19-caf4-4253-8ead-b7f85dda8137
www.genians.co.kr
Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
Compiled Python-based malware continues to spread. Malicious LNK files execute PowerShell and batch commands, ultimately deploying NarwhalRAT.
๐Title: Inside OnyxC2: The New Stealer Targeting 210 Apps
๐ Date: 2026-06-11
๐References:
https://www.blackfog.com/inside-onyxc2-the-new-stealer-targeting-210-apps
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข target="broad-based"
โข TA-category="Cybercrime"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1539', 'T1555.005', 'T1555.003', 'T1027.001', 'T1003.001', 'T1497', 'T1041', 'T1090.003', 'T1027', 'T1564.003', 'T1071.001', 'T1574.002']
MISP event uuid: d9262ac6-5e84-4e20-82d7-6a520239ed85
๐ Date: 2026-06-11
๐References:
https://www.blackfog.com/inside-onyxc2-the-new-stealer-targeting-210-apps
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข target="broad-based"
โข TA-category="Cybercrime"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1539', 'T1555.005', 'T1555.003', 'T1027.001', 'T1003.001', 'T1497', 'T1041', 'T1090.003', 'T1027', 'T1564.003', 'T1071.001', 'T1574.002']
MISP event uuid: d9262ac6-5e84-4e20-82d7-6a520239ed85
BlackFog
Inside OnyxC2: The New Stealer Targeting 210 Apps | BlackFog
Discover OnyxC2, the new malware-as-a-service stealer targeting 210 apps, how it evades detection, steals credentials, and enables data theft.
๐Title: The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
๐ Date: 2026-06-15
๐References:
https://www.huntress.com/blog/terminal-server-phishing-stager-exposed
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
โข target-information="United Kingdom"
โข target-information="Bolivia"
mitre-attack-pattern=['T1133', 'T1114', 'T1566.002', 'T1598.003', 'T1586.002', 'T1036', 'T1185', 'T1071.003', 'T1535', 'T1589.002', 'T1090', 'T1078', 'T1027', 'T1132', 'T1189', 'T1584.004']
MISP event uuid: d5715164-f8a4-40b1-b225-96ea7a71e85e
๐ Date: 2026-06-15
๐References:
https://www.huntress.com/blog/terminal-server-phishing-stager-exposed
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
โข target-information="United Kingdom"
โข target-information="Bolivia"
mitre-attack-pattern=['T1133', 'T1114', 'T1566.002', 'T1598.003', 'T1586.002', 'T1036', 'T1185', 'T1071.003', 'T1535', 'T1589.002', 'T1090', 'T1078', 'T1027', 'T1132', 'T1189', 'T1584.004']
MISP event uuid: d5715164-f8a4-40b1-b225-96ea7a71e85e
Huntress
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed | Huntress
A compromised terminal server became a phishing stager. A fake Boots survey aimed at 8.9 million inboxes, with the payload on a hacked Bolivian government site.
๐Title: Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years: How Cybercriminals Are Targeting Travelers in 2026
๐ Date: 2026-06-15
๐References:
https://blog.checkpoint.com/research/travel-phishing-and-cyber-attacks-are-surging-in-2026-growing-122-over-the-last-3-years-heres-what-cyber-criminals-are-actually-doing/
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Check Point"
โข target-information="Malaysia"
โข target-information="Canada"
mitre-attack-pattern=['T1583', 'T1539', 'T1114', 'T1204.002', 'T1566.002', 'T1598.003', 'T1583.001', 'T1056.003', 'T1204', 'T1566', 'T1585.001', 'T1056', 'T1132', 'T1598', 'T1585', 'T1213']
MISP event uuid: be7ce1a3-06b7-40b8-baae-d4fa3adfba87
๐ Date: 2026-06-15
๐References:
https://blog.checkpoint.com/research/travel-phishing-and-cyber-attacks-are-surging-in-2026-growing-122-over-the-last-3-years-heres-what-cyber-criminals-are-actually-doing/
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Check Point"
โข target-information="Malaysia"
โข target-information="Canada"
mitre-attack-pattern=['T1583', 'T1539', 'T1114', 'T1204.002', 'T1566.002', 'T1598.003', 'T1583.001', 'T1056.003', 'T1204', 'T1566', 'T1585.001', 'T1056', 'T1132', 'T1598', 'T1585', 'T1213']
MISP event uuid: be7ce1a3-06b7-40b8-baae-d4fa3adfba87
Check Point Blog
Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here's What Cyber Criminals Are Actuallyโฆ
Every summer, hundreds of millions of people book flights, reserve hotels, and plan vacations online. And every summer, cyber criminals show up to take %Travel cyberattacks have surged 122% since 2023. Discover how hackers use fake Booking.com, Airbnb, andโฆ
๐Title: OptinMonster supply chain attack hits 1.2 million sites
๐ Date: 2026-06-13
๐References:
https://sansec.io/research/optinmonster-supply-chain-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1033', 'T1132.001', 'T1573.001', 'T1087.001', 'T1082', 'T1140', 'T1218', 'T1070.006', 'T1505.003', 'T1136.001', 'T1090.002', 'T1083', 'T1114.003', 'T1564.002', 'T1562.003', 'T1059.004', 'T1027', 'T1195.002', 'T1071.001', 'T1078.003']
MISP event uuid: f99b496b-ce4c-43ce-87f6-8024f8c36a0f
๐ Date: 2026-06-13
๐References:
https://sansec.io/research/optinmonster-supply-chain-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1033', 'T1132.001', 'T1573.001', 'T1087.001', 'T1082', 'T1140', 'T1218', 'T1070.006', 'T1505.003', 'T1136.001', 'T1090.002', 'T1083', 'T1114.003', 'T1564.002', 'T1562.003', 'T1059.004', 'T1027', 'T1195.002', 'T1071.001', 'T1078.003']
MISP event uuid: f99b496b-ce4c-43ce-87f6-8024f8c36a0f
Sansec
OptinMonster supply chain attack hits 1.2 million sites
Malware adds admin accounts and hidden backdoor to sites using OptinMonster, TrustPulse or PushEngage plugins.
๐Title: The Package That Never Shipped: Following a USPS Smishing Kit Through DNS Data
๐ Date: 2026-06-13
๐References:
https://censys.com/blog/following-a-usps-smishing-kit-through-censys-dns-data/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="censys"
mitre-attack-pattern=['T1583', 'T1056.001', 'T1036.005', 'T1566.002', 'T1598.003', 'T1071', 'T1586.002', 'T1608.001', 'T1583.001', 'T1036', 'T1185', 'T1586', 'T1608', 'T1583.006', 'T1041', 'T1566', 'T1027', 'T1573', 'T1056', 'T1598', 'T1071.001']
MISP event uuid: 5f1db648-9b34-47fd-aa68-47e63fa3de4b
๐ Date: 2026-06-13
๐References:
https://censys.com/blog/following-a-usps-smishing-kit-through-censys-dns-data/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="censys"
mitre-attack-pattern=['T1583', 'T1056.001', 'T1036.005', 'T1566.002', 'T1598.003', 'T1071', 'T1586.002', 'T1608.001', 'T1583.001', 'T1036', 'T1185', 'T1586', 'T1608', 'T1583.006', 'T1041', 'T1566', 'T1027', 'T1573', 'T1056', 'T1598', 'T1071.001']
MISP event uuid: 5f1db648-9b34-47fd-aa68-47e63fa3de4b
Censys
The Package That Never Shipped: Following a USPS Smishing Kit Through Censys DNS Data - Censys
Executive Summary It Starts With a Text Message You know the message. Everyone has gotten one. A package could not be delivered, there is an unpaid customs fee or a bad address, and here is a helpful link to fix it. This one pointed at: Believe it or notโฆ
๐Title: Attackers Weaponize Microsoft Teams Relays to Stay Hidden
๐ Date: 2026-06-16
๐References:
https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Ransomware"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Symantec"
โข target-information="United States"
mitre-attack-pattern=['T1003', 'T1087.002', 'T1190', 'T1567', 'T1055', 'T1021', 'T1112', 'T1555.003', 'T1562.006', 'T1562.001', 'T1027', 'T1486', 'T1071.001', 'T1136', 'T1018', 'T1574.002', 'T1569.002', 'T1090.001']
MISP event uuid: afa946fd-9cd9-4c73-93c2-b2147fdefd2e
๐ Date: 2026-06-16
๐References:
https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Ransomware"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Symantec"
โข target-information="United States"
mitre-attack-pattern=['T1003', 'T1087.002', 'T1190', 'T1567', 'T1055', 'T1021', 'T1112', 'T1555.003', 'T1562.006', 'T1562.001', 'T1027', 'T1486', 'T1071.001', 'T1136', 'T1018', 'T1574.002', 'T1569.002', 'T1090.001']
MISP event uuid: afa946fd-9cd9-4c73-93c2-b2147fdefd2e
Security
Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden
Backdoor.Turn, a Go-based RAT, is the first known malware to abuse Microsoft Teams' TURN relay servers to mask command-and-control traffic. The attackers also used a previously unknown vulnerability in a Huawei driver.
๐Title: Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
๐ Date: 2026-06-16
๐References:
https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข detection-rules="yara-from-src"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
mitre-attack-pattern=['T1053.005', 'T1047', 'T1056.001', 'T1568.002', 'T1036.005', 'T1204.002', 'T1218.007', 'T1140', 'T1055', 'T1021.002', 'T1555.003', 'T1021.006', 'T1218.005', 'T1547.001', 'T1056.002', 'T1562.001', 'T1027', 'T1573', 'T1071.001']
MISP event uuid: ce6915b2-f7f6-4148-96ff-9f03338de345
๐ Date: 2026-06-16
๐References:
https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข detection-rules="yara-from-src"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
mitre-attack-pattern=['T1053.005', 'T1047', 'T1056.001', 'T1568.002', 'T1036.005', 'T1204.002', 'T1218.007', 'T1140', 'T1055', 'T1021.002', 'T1555.003', 'T1021.006', 'T1218.005', 'T1547.001', 'T1056.002', 'T1562.001', 'T1027', 'T1573', 'T1071.001']
MISP event uuid: ce6915b2-f7f6-4148-96ff-9f03338de345
Huntress
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack | Huntress
A ClickFix infection drops Potemkin loader and RMMProject RAT, leading to browser theft, hidden remote desktop, and lateral movement across over 11 hosts.
๐Title: Android Banker with Complete Device Takeover Capabilities
๐ Date: 2026-06-16
๐References:
https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Zimperium"
mitre-attack-pattern=['T1517', 'T1429', 'T1624.001', 'T1616', 'T1414', 'T1637', 'T1646', 'T1417.002', 'T1516', 'T1417.001', 'T1655.001', 'T1660', 'T1582', 'T1636.004', 'T1513', 'T1418', 'T1406.002', 'T1426']
MISP event uuid: c4f048d7-9154-4c0a-9313-9f454c1e3bce
๐ Date: 2026-06-16
๐References:
https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Zimperium"
mitre-attack-pattern=['T1517', 'T1429', 'T1624.001', 'T1616', 'T1414', 'T1637', 'T1646', 'T1417.002', 'T1516', 'T1417.001', 'T1655.001', 'T1660', 'T1582', 'T1636.004', 'T1513', 'T1418', 'T1406.002', 'T1426']
MISP event uuid: c4f048d7-9154-4c0a-9313-9f454c1e3bce
Zimperium
Rokarolla : Android Banker with Complete Device Takeover Capabilities
true
๐Title: Investigation of email-based attack delivering MediaFire ZIP file with execution chain analysis
๐ Date: 2026-06-16
๐References:
https://x.com/Kostastsale/status/2066545189137629302
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1053.005', 'T1218.011', 'T1036.005', 'T1204.002', 'T1566.002', 'T1055', 'T1027.001', 'T1059.001', 'T1547.001', 'T1095', 'T1132', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: be236a57-ec5e-4964-8305-33827a5a10fc
๐ Date: 2026-06-16
๐References:
https://x.com/Kostastsale/status/2066545189137629302
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1053.005', 'T1218.011', 'T1036.005', 'T1204.002', 'T1566.002', 'T1055', 'T1027.001', 'T1059.001', 'T1547.001', 'T1095', 'T1132', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: be236a57-ec5e-4964-8305-33827a5a10fc
X (formerly Twitter)
Kostas (@Kostastsale) on X
We investigated a case where an email sent the victim to a MediaFire ZIP. We have not observed this exact chain as part of a broader campaign so far, but there are a lot of things from this that wanted to share which worth a closer look.
๐๐ ๐ฒ๐ฐ๐๐๐ถ๐ผ๐ป ๐ฐ๐ต๐ฎ๐ถ๐ปโฆ
๐๐ ๐ฒ๐ฐ๐๐๐ถ๐ผ๐ป ๐ฐ๐ต๐ฎ๐ถ๐ปโฆ
Rectifyq Cybersecurity News ๐ฒ๐พ pinned ยซ๐Title: Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years: How Cybercriminals Are Targeting Travelers in 2026 ๐
Date: 2026-06-15 ๐References: https://blog.checkpoint.com/research/travel-phishing-and-cyber-attacks-areโฆยป