๐Title: Interlock and Rhysida within the Ransomware Ecosystem
๐ Date: 2026-06-12
๐References:
https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="TA-profile"
โข TA-category="Ransomware"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="IBM X-Force"
โข target-information="United States"
โข ransomware="interlock"
โข ransomware="rhysida"
mitre-attack-pattern=['T1053.005', 'T1218.011', 'T1003', 'T1087.002', 'T1140', 'T1190', 'T1055', 'T1482', 'T1083', 'T1204', 'T1059.001', 'T1547.001', 'T1566', 'T1486', 'T1203', 'T1059.003', 'T1189', 'T1027.002', 'T1018', 'T1105', 'T1021.001', 'T1490']
MISP event uuid: 4f2a0ee4-d11b-46a6-ba6d-1f9be509076d
๐ Date: 2026-06-12
๐References:
https://www.ibm.com/think/x-force/interlock-and-rhysida-within-the-ransonware-ecosystem
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="TA-profile"
โข TA-category="Ransomware"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="IBM X-Force"
โข target-information="United States"
โข ransomware="interlock"
โข ransomware="rhysida"
mitre-attack-pattern=['T1053.005', 'T1218.011', 'T1003', 'T1087.002', 'T1140', 'T1190', 'T1055', 'T1482', 'T1083', 'T1204', 'T1059.001', 'T1547.001', 'T1566', 'T1486', 'T1203', 'T1059.003', 'T1189', 'T1027.002', 'T1018', 'T1105', 'T1021.001', 'T1490']
MISP event uuid: 4f2a0ee4-d11b-46a6-ba6d-1f9be509076d
Ibm
Interlock and Rhysida within the Ransomware Ecosystem | IBM
IBM X-Force uncovers deep links between Interlock and Rhysida ransomware actors, detailing shared malware, crypters, and infrastructure across the ecosystem, with insights into infection chains, initial access brokers, and evolving tools over two years ofโฆ
๐Title: How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches
๐ Date: 2026-06-09
๐References:
https://malext.io/reports/SearchJack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1033', 'T1056.001', 'T1539', 'T1036.005', 'T1204.002', 'T1566.002', 'T1082', 'T1176', 'T1005', 'T1036', 'T1185', 'T1112', 'T1083', 'T1568', 'T1027', 'T1573', 'T1213', 'T1189', 'T1071.001']
MISP event uuid: c2e25435-9441-48e7-a5cc-c2a50ceff102
๐ Date: 2026-06-09
๐References:
https://malext.io/reports/SearchJack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1033', 'T1056.001', 'T1539', 'T1036.005', 'T1204.002', 'T1566.002', 'T1082', 'T1176', 'T1005', 'T1036', 'T1185', 'T1112', 'T1083', 'T1568', 'T1027', 'T1573', 'T1213', 'T1189', 'T1071.001']
MISP event uuid: c2e25435-9441-48e7-a5cc-c2a50ceff102
malext.io
SearchJack: How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches - MalExt Sentry
Threat intelligence report: SearchJack: How 23 Browser Extensions Silently Monetize ~758,000 Users' Searches. Research by MalExt Sentry.
๐Title: Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
๐ Date: 2026-06-15
๐References:
https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข threat-actor="APT37"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1025', 'T1204.002', 'T1497.001', 'T1566.001', 'T1005', 'T1140', 'T1055', 'T1112', 'T1041', 'T1059.001', 'T1547.001', 'T1027', 'T1059.003', 'T1070.004', 'T1071.001', 'T1102.001']
MISP event uuid: 24638e19-caf4-4253-8ead-b7f85dda8137
๐ Date: 2026-06-15
๐References:
https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข threat-actor="APT37"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1025', 'T1204.002', 'T1497.001', 'T1566.001', 'T1005', 'T1140', 'T1055', 'T1112', 'T1041', 'T1059.001', 'T1547.001', 'T1027', 'T1059.003', 'T1070.004', 'T1071.001', 'T1102.001']
MISP event uuid: 24638e19-caf4-4253-8ead-b7f85dda8137
www.genians.co.kr
Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2
Compiled Python-based malware continues to spread. Malicious LNK files execute PowerShell and batch commands, ultimately deploying NarwhalRAT.
๐Title: Inside OnyxC2: The New Stealer Targeting 210 Apps
๐ Date: 2026-06-11
๐References:
https://www.blackfog.com/inside-onyxc2-the-new-stealer-targeting-210-apps
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข target="broad-based"
โข TA-category="Cybercrime"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1539', 'T1555.005', 'T1555.003', 'T1027.001', 'T1003.001', 'T1497', 'T1041', 'T1090.003', 'T1027', 'T1564.003', 'T1071.001', 'T1574.002']
MISP event uuid: d9262ac6-5e84-4e20-82d7-6a520239ed85
๐ Date: 2026-06-11
๐References:
https://www.blackfog.com/inside-onyxc2-the-new-stealer-targeting-210-apps
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข target="broad-based"
โข TA-category="Cybercrime"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1053.005', 'T1113', 'T1056.001', 'T1539', 'T1555.005', 'T1555.003', 'T1027.001', 'T1003.001', 'T1497', 'T1041', 'T1090.003', 'T1027', 'T1564.003', 'T1071.001', 'T1574.002']
MISP event uuid: d9262ac6-5e84-4e20-82d7-6a520239ed85
BlackFog
Inside OnyxC2: The New Stealer Targeting 210 Apps | BlackFog
Discover OnyxC2, the new malware-as-a-service stealer targeting 210 apps, how it evades detection, steals credentials, and enables data theft.
๐Title: The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed
๐ Date: 2026-06-15
๐References:
https://www.huntress.com/blog/terminal-server-phishing-stager-exposed
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
โข target-information="United Kingdom"
โข target-information="Bolivia"
mitre-attack-pattern=['T1133', 'T1114', 'T1566.002', 'T1598.003', 'T1586.002', 'T1036', 'T1185', 'T1071.003', 'T1535', 'T1589.002', 'T1090', 'T1078', 'T1027', 'T1132', 'T1189', 'T1584.004']
MISP event uuid: d5715164-f8a4-40b1-b225-96ea7a71e85e
๐ Date: 2026-06-15
๐References:
https://www.huntress.com/blog/terminal-server-phishing-stager-exposed
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="targeted"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
โข target-information="United Kingdom"
โข target-information="Bolivia"
mitre-attack-pattern=['T1133', 'T1114', 'T1566.002', 'T1598.003', 'T1586.002', 'T1036', 'T1185', 'T1071.003', 'T1535', 'T1589.002', 'T1090', 'T1078', 'T1027', 'T1132', 'T1189', 'T1584.004']
MISP event uuid: d5715164-f8a4-40b1-b225-96ea7a71e85e
Huntress
The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed | Huntress
A compromised terminal server became a phishing stager. A fake Boots survey aimed at 8.9 million inboxes, with the payload on a hacked Bolivian government site.
๐Title: Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years: How Cybercriminals Are Targeting Travelers in 2026
๐ Date: 2026-06-15
๐References:
https://blog.checkpoint.com/research/travel-phishing-and-cyber-attacks-are-surging-in-2026-growing-122-over-the-last-3-years-heres-what-cyber-criminals-are-actually-doing/
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Check Point"
โข target-information="Malaysia"
โข target-information="Canada"
mitre-attack-pattern=['T1583', 'T1539', 'T1114', 'T1204.002', 'T1566.002', 'T1598.003', 'T1583.001', 'T1056.003', 'T1204', 'T1566', 'T1585.001', 'T1056', 'T1132', 'T1598', 'T1585', 'T1213']
MISP event uuid: be7ce1a3-06b7-40b8-baae-d4fa3adfba87
๐ Date: 2026-06-15
๐References:
https://blog.checkpoint.com/research/travel-phishing-and-cyber-attacks-are-surging-in-2026-growing-122-over-the-last-3-years-heres-what-cyber-criminals-are-actually-doing/
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Cybercrime"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Check Point"
โข target-information="Malaysia"
โข target-information="Canada"
mitre-attack-pattern=['T1583', 'T1539', 'T1114', 'T1204.002', 'T1566.002', 'T1598.003', 'T1583.001', 'T1056.003', 'T1204', 'T1566', 'T1585.001', 'T1056', 'T1132', 'T1598', 'T1585', 'T1213']
MISP event uuid: be7ce1a3-06b7-40b8-baae-d4fa3adfba87
Check Point Blog
Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years. Here's What Cyber Criminals Are Actuallyโฆ
Every summer, hundreds of millions of people book flights, reserve hotels, and plan vacations online. And every summer, cyber criminals show up to take %Travel cyberattacks have surged 122% since 2023. Discover how hackers use fake Booking.com, Airbnb, andโฆ
๐Title: OptinMonster supply chain attack hits 1.2 million sites
๐ Date: 2026-06-13
๐References:
https://sansec.io/research/optinmonster-supply-chain-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1033', 'T1132.001', 'T1573.001', 'T1087.001', 'T1082', 'T1140', 'T1218', 'T1070.006', 'T1505.003', 'T1136.001', 'T1090.002', 'T1083', 'T1114.003', 'T1564.002', 'T1562.003', 'T1059.004', 'T1027', 'T1195.002', 'T1071.001', 'T1078.003']
MISP event uuid: f99b496b-ce4c-43ce-87f6-8024f8c36a0f
๐ Date: 2026-06-13
๐References:
https://sansec.io/research/optinmonster-supply-chain-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1033', 'T1132.001', 'T1573.001', 'T1087.001', 'T1082', 'T1140', 'T1218', 'T1070.006', 'T1505.003', 'T1136.001', 'T1090.002', 'T1083', 'T1114.003', 'T1564.002', 'T1562.003', 'T1059.004', 'T1027', 'T1195.002', 'T1071.001', 'T1078.003']
MISP event uuid: f99b496b-ce4c-43ce-87f6-8024f8c36a0f
Sansec
OptinMonster supply chain attack hits 1.2 million sites
Malware adds admin accounts and hidden backdoor to sites using OptinMonster, TrustPulse or PushEngage plugins.
๐Title: The Package That Never Shipped: Following a USPS Smishing Kit Through DNS Data
๐ Date: 2026-06-13
๐References:
https://censys.com/blog/following-a-usps-smishing-kit-through-censys-dns-data/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="censys"
mitre-attack-pattern=['T1583', 'T1056.001', 'T1036.005', 'T1566.002', 'T1598.003', 'T1071', 'T1586.002', 'T1608.001', 'T1583.001', 'T1036', 'T1185', 'T1586', 'T1608', 'T1583.006', 'T1041', 'T1566', 'T1027', 'T1573', 'T1056', 'T1598', 'T1071.001']
MISP event uuid: 5f1db648-9b34-47fd-aa68-47e63fa3de4b
๐ Date: 2026-06-13
๐References:
https://censys.com/blog/following-a-usps-smishing-kit-through-censys-dns-data/
๐Rectifyq Taxonomies:
Relevancy: โซ Not Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="censys"
mitre-attack-pattern=['T1583', 'T1056.001', 'T1036.005', 'T1566.002', 'T1598.003', 'T1071', 'T1586.002', 'T1608.001', 'T1583.001', 'T1036', 'T1185', 'T1586', 'T1608', 'T1583.006', 'T1041', 'T1566', 'T1027', 'T1573', 'T1056', 'T1598', 'T1071.001']
MISP event uuid: 5f1db648-9b34-47fd-aa68-47e63fa3de4b
Censys
The Package That Never Shipped: Following a USPS Smishing Kit Through Censys DNS Data - Censys
Executive Summary It Starts With a Text Message You know the message. Everyone has gotten one. A package could not be delivered, there is an unpaid customs fee or a bad address, and here is a helpful link to fix it. This one pointed at: Believe it or notโฆ
๐Title: Attackers Weaponize Microsoft Teams Relays to Stay Hidden
๐ Date: 2026-06-16
๐References:
https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Ransomware"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Symantec"
โข target-information="United States"
mitre-attack-pattern=['T1003', 'T1087.002', 'T1190', 'T1567', 'T1055', 'T1021', 'T1112', 'T1555.003', 'T1562.006', 'T1562.001', 'T1027', 'T1486', 'T1071.001', 'T1136', 'T1018', 'T1574.002', 'T1569.002', 'T1090.001']
MISP event uuid: afa946fd-9cd9-4c73-93c2-b2147fdefd2e
๐ Date: 2026-06-16
๐References:
https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="Ransomware"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Symantec"
โข target-information="United States"
mitre-attack-pattern=['T1003', 'T1087.002', 'T1190', 'T1567', 'T1055', 'T1021', 'T1112', 'T1555.003', 'T1562.006', 'T1562.001', 'T1027', 'T1486', 'T1071.001', 'T1136', 'T1018', 'T1574.002', 'T1569.002', 'T1090.001']
MISP event uuid: afa946fd-9cd9-4c73-93c2-b2147fdefd2e
Security
Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden
Backdoor.Turn, a Go-based RAT, is the first known malware to abuse Microsoft Teams' TURN relay servers to mask command-and-control traffic. The attackers also used a previously unknown vulnerability in a Huawei driver.
๐Title: Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack
๐ Date: 2026-06-16
๐References:
https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข detection-rules="yara-from-src"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
mitre-attack-pattern=['T1053.005', 'T1047', 'T1056.001', 'T1568.002', 'T1036.005', 'T1204.002', 'T1218.007', 'T1140', 'T1055', 'T1021.002', 'T1555.003', 'T1021.006', 'T1218.005', 'T1547.001', 'T1056.002', 'T1562.001', 'T1027', 'T1573', 'T1071.001']
MISP event uuid: ce6915b2-f7f6-4148-96ff-9f03338de345
๐ Date: 2026-06-16
๐References:
https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข detection-rules="yara-from-src"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Huntress"
mitre-attack-pattern=['T1053.005', 'T1047', 'T1056.001', 'T1568.002', 'T1036.005', 'T1204.002', 'T1218.007', 'T1140', 'T1055', 'T1021.002', 'T1555.003', 'T1021.006', 'T1218.005', 'T1547.001', 'T1056.002', 'T1562.001', 'T1027', 'T1573', 'T1071.001']
MISP event uuid: ce6915b2-f7f6-4148-96ff-9f03338de345
Huntress
Potemkin Loader & RMMProject The Anatomy of a ClickFix Attack | Huntress
A ClickFix infection drops Potemkin loader and RMMProject RAT, leading to browser theft, hidden remote desktop, and lateral movement across over 11 hosts.
๐Title: Android Banker with Complete Device Takeover Capabilities
๐ Date: 2026-06-16
๐References:
https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Zimperium"
mitre-attack-pattern=['T1517', 'T1429', 'T1624.001', 'T1616', 'T1414', 'T1637', 'T1646', 'T1417.002', 'T1516', 'T1417.001', 'T1655.001', 'T1660', 'T1582', 'T1636.004', 'T1513', 'T1418', 'T1406.002', 'T1426']
MISP event uuid: c4f048d7-9154-4c0a-9313-9f454c1e3bce
๐ Date: 2026-06-16
๐References:
https://zimperium.com/blog/rokarolla-android-banker-with-complete-device-takeover-capabilities
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข topic="mobile-attack"
โข target="broad-based"
โข samples-found-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Zimperium"
mitre-attack-pattern=['T1517', 'T1429', 'T1624.001', 'T1616', 'T1414', 'T1637', 'T1646', 'T1417.002', 'T1516', 'T1417.001', 'T1655.001', 'T1660', 'T1582', 'T1636.004', 'T1513', 'T1418', 'T1406.002', 'T1426']
MISP event uuid: c4f048d7-9154-4c0a-9313-9f454c1e3bce
Zimperium
Rokarolla : Android Banker with Complete Device Takeover Capabilities
true
๐Title: Investigation of email-based attack delivering MediaFire ZIP file with execution chain analysis
๐ Date: 2026-06-16
๐References:
https://x.com/Kostastsale/status/2066545189137629302
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1053.005', 'T1218.011', 'T1036.005', 'T1204.002', 'T1566.002', 'T1055', 'T1027.001', 'T1059.001', 'T1547.001', 'T1095', 'T1132', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: be236a57-ec5e-4964-8305-33827a5a10fc
๐ Date: 2026-06-16
๐References:
https://x.com/Kostastsale/status/2066545189137629302
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="intrusion-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1053.005', 'T1218.011', 'T1036.005', 'T1204.002', 'T1566.002', 'T1055', 'T1027.001', 'T1059.001', 'T1547.001', 'T1095', 'T1132', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: be236a57-ec5e-4964-8305-33827a5a10fc
X (formerly Twitter)
Kostas (@Kostastsale) on X
We investigated a case where an email sent the victim to a MediaFire ZIP. We have not observed this exact chain as part of a broader campaign so far, but there are a lot of things from this that wanted to share which worth a closer look.
๐๐ ๐ฒ๐ฐ๐๐๐ถ๐ผ๐ป ๐ฐ๐ต๐ฎ๐ถ๐ปโฆ
๐๐ ๐ฒ๐ฐ๐๐๐ถ๐ผ๐ป ๐ฐ๐ต๐ฎ๐ถ๐ปโฆ
Rectifyq Cybersecurity News ๐ฒ๐พ pinned ยซ๐Title: Travel Phishing and Cyber Attacks are Surging in 2026, Growing 122% over the last 3 years: How Cybercriminals Are Targeting Travelers in 2026 ๐
Date: 2026-06-15 ๐References: https://blog.checkpoint.com/research/travel-phishing-and-cyber-attacks-areโฆยป
๐Title: [Ransomware] Unconfirmed: mli******** UPD******** DAT* DUM* NEW LIN* 10G*
๐ Date: 2026-06-24
๐References: https://www.ransomware.live/id/bWxpdC5jb20ubXkgVVBEQVRFLUZVTEwgREFUQSBEVU1QIE5FVyBMSU5LIDEwR0JAc3Rvcm1vdXM=
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: ๐ฅ Data Breach
- TA-category="Ransomware"
๐MISP Galaxies:
- target-information="Malaysia"
- sector="Public Sector"
- ransomware="stormous"
mitre-attack-pattern=[]
MISP event uuid: 3f90713d-8875-4d1f-96e2-5a4aefbfe476
๐ Date: 2026-06-24
๐References: https://www.ransomware.live/id/bWxpdC5jb20ubXkgVVBEQVRFLUZVTEwgREFUQSBEVU1QIE5FVyBMSU5LIDEwR0JAc3Rvcm1vdXM=
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: ๐ฅ Data Breach
- TA-category="Ransomware"
๐MISP Galaxies:
- target-information="Malaysia"
- sector="Public Sector"
- ransomware="stormous"
mitre-attack-pattern=[]
MISP event uuid: 3f90713d-8875-4d1f-96e2-5a4aefbfe476
Ransomware.live
Victim: mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB โ stormous
Ransomware.live discovered on 2026-06-24 that mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB has been claimed by Stormous ransomware group
๐Title: How attackers are jailbreaking LLMs with CTF framing and how to catch them
๐ Date: 2026-06-15
๐References:
https://www.sysdig.com/blog/how-attackers-are-jailbreaking-llms-with-ctf-framing-and-how-to-catch-them
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="ai"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
MISP event uuid: a667f34d-d768-47b3-9f64-ae7a72b86b82
๐ Date: 2026-06-15
๐References:
https://www.sysdig.com/blog/how-attackers-are-jailbreaking-llms-with-ctf-framing-and-how-to-catch-them
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="ai"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
MISP event uuid: a667f34d-d768-47b3-9f64-ae7a72b86b82
Sysdig
How attackers are jailbreaking LLMs with CTF framing and how to catch them | Sysdig
Sysdig TRT caught threat actors jailbreaking LLMs with CTF framing to generate CVE exploits โ and the prompt structure leaks into headers, passwords, and IAM logs.
๐Title: Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research
๐ Date: 2026-06-16
๐References:
https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Mandiant"
โข target-information="United States"
โข target-information="Canada"
mitre-attack-pattern=['T1190', 'T1555', 'T1567', 'T1505.003', 'T1056.003', 'T1114.003', 'T1554', 'T1090.003', 'T1562.001', 'T1027', 'T1213', 'T1071.001', 'T1689']
MISP event uuid: aa407ecb-686f-4bfa-a7cd-42fa26fd2128
๐ Date: 2026-06-16
๐References:
https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="from-original-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Mandiant"
โข target-information="United States"
โข target-information="Canada"
mitre-attack-pattern=['T1190', 'T1555', 'T1567', 'T1505.003', 'T1056.003', 'T1114.003', 'T1554', 'T1090.003', 'T1562.001', 'T1027', 'T1213', 'T1071.001', 'T1689']
MISP event uuid: aa407ecb-686f-4bfa-a7cd-42fa26fd2128
Google Cloud Blog
Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, andโฆ
๐Title: WebAssembly Malware Found in Trojanized Open VSX Extensions
๐ Date: 2026-06-15
๐References:
https://socket.dev/blog/glasswasm-malware-open-vsx-extensions
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="37ebf9d7-5e9a-466f-a42c-6e60313db868"
mitre-attack-pattern=['T1195.001', 'T1036.005', 'T1204.002', 'T1573.001', 'T1497.001', 'T1140', 'T1497.003', 'T1102', 'T1059.001', 'T1059.004', 'T1562.001', 'T1027', 'T1518.001', 'T1059.003', 'T1071.001', 'T1105', 'T1102.001']
MISP event uuid: 43eb70af-9f4f-4cb9-98c9-15bcea35e6a9
๐ Date: 2026-06-15
๐References:
https://socket.dev/blog/glasswasm-malware-open-vsx-extensions
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข topic="supply-chain"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="37ebf9d7-5e9a-466f-a42c-6e60313db868"
mitre-attack-pattern=['T1195.001', 'T1036.005', 'T1204.002', 'T1573.001', 'T1497.001', 'T1140', 'T1497.003', 'T1102', 'T1059.001', 'T1059.004', 'T1562.001', 'T1027', 'T1518.001', 'T1059.003', 'T1071.001', 'T1105', 'T1102.001']
MISP event uuid: 43eb70af-9f4f-4cb9-98c9-15bcea35e6a9
Socket
GlassWASM: WebAssembly Malware Found in Trojanized Open VSX ...
The trojanized extensions use TinyGo-compiled WebAssembly and Solana transaction memos to resolve command-and-control infrastructure.
๐Title: Gamers beware: malicious wallpapers on Steam found stealing accounts
๐ Date: 2026-06-16
๐References:
https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Kaspersky"
โข target-information="British Indian Ocean Territory"
โข target-information="Canada"
โข target-information="China"
โข target-information="Germany"
โข target-information="Hong Kong"
โข target-information="India"
โข target-information="Russia"
โข target-information="Singapore"
mitre-attack-pattern=['T1543', 'T1539', 'T1547', 'T1564', 'T1071', 'T1140', 'T1562', 'T1555', 'T1055', 'T1560', 'T1608', 'T1204', 'T1574', 'T1078', 'T1027', 'T1573', 'T1496', 'T1485', 'T1518', 'T1105']
MISP event uuid: 51c79e71-685f-4c88-b907-1579de218020
๐ Date: 2026-06-16
๐References:
https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="campaign-analysis"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข samples-found-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="Kaspersky"
โข target-information="British Indian Ocean Territory"
โข target-information="Canada"
โข target-information="China"
โข target-information="Germany"
โข target-information="Hong Kong"
โข target-information="India"
โข target-information="Russia"
โข target-information="Singapore"
mitre-attack-pattern=['T1543', 'T1539', 'T1547', 'T1564', 'T1071', 'T1140', 'T1562', 'T1555', 'T1055', 'T1560', 'T1608', 'T1204', 'T1574', 'T1078', 'T1027', 'T1573', 'T1496', 'T1485', 'T1518', 'T1105']
MISP event uuid: 51c79e71-685f-4c88-b907-1579de218020
๐Title: New APT-Q-27 sample spotted
๐ Date: 2026-06-17
๐References:
https://x.com/askardyuss/status/2066859258130665974
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1204.002', 'T1553.002', 'T1036', 'T1059', 'T1027', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: 2af465d9-1888-4e99-abe1-dc82d348aa41
๐ Date: 2026-06-17
๐References:
https://x.com/askardyuss/status/2066859258130665974
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: โ Threat
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="malware-analysis"
โข TA-category="APT"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
mitre-attack-pattern=['T1204.002', 'T1553.002', 'T1036', 'T1059', 'T1027', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: 2af465d9-1888-4e99-abe1-dc82d348aa41
X (formerly Twitter)
Askar (@askardyuss) on X
#ThreatIntel New APT-Q-27 sample spotted! ๐จ
The attack leverages a valid digital signature from "ๅนฟๅทๆ ฉๅ ็งๆๆ้ๅ ฌๅธ" (not revoked yet). The dropper fetches an extension-based module list from C2. Current payloads use DLL Side-Loading via a legitimate Tencent-signedโฆ
The attack leverages a valid digital signature from "ๅนฟๅทๆ ฉๅ ็งๆๆ้ๅ ฌๅธ" (not revoked yet). The dropper fetches an extension-based module list from C2. Current payloads use DLL Side-Loading via a legitimate Tencent-signedโฆ
๐Title: Bluekit Phishing as a Service (PhaaS)
๐ Date: 2026-06-16
๐References:
https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="CloudSEK"
mitre-attack-pattern=[]
MISP event uuid: cab18fbe-dd41-40ba-9768-7b2329c53e94
๐ Date: 2026-06-16
๐References:
https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas
๐Rectifyq Taxonomies:
Relevancy: ๐ต Potentially Relevant
Category: ๐ Vulnerability
โข mitre-att&ck="none-from-src"
โข mitre-att&ck="from-OTX"
โข sub-category="tool-profile"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
๐MISP Galaxies:
โข producer="CloudSEK"
mitre-attack-pattern=[]
MISP event uuid: cab18fbe-dd41-40ba-9768-7b2329c53e94
Cloudsek
Bluekit Phishing as a Service (PhaaS) | CloudSEK
BlueKit is turning phishing into a subscription business, offering 87 ready-made kits, automated account takeover and stealthy peer-to-peer infrastructure. CloudSEKโs investigation reveals how this mature PhaaS platform helps even low-skilled criminals targetโฆ
๐Title: FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed โ Claim Your Ethical Disclosure
๐ Date: 2026-06-17
๐References:
https://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/
https://www.linkedin.com/feed/update/urn:li:activity:7471222472193830913/
https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: ๐ฅ Data Breach
โข sub-category="report"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
MISP event uuid: 62d63a50-b78f-45df-98a9-da606487a500
๐ Date: 2026-06-17
๐References:
https://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/
https://www.linkedin.com/feed/update/urn:li:activity:7471222472193830913/
https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8
๐Rectifyq Taxonomies:
Relevancy: ๐ด Highly Relevant
Category: ๐ฅ Data Breach
โข sub-category="report"
โข target="broad-based"
โข no-samples-in="MalwareBazaar"
โข no-samples-in="Tria.ge"
โข action-taken="VT-comment"
MISP event uuid: 62d63a50-b78f-45df-98a9-da606487a500
InfoStealers
FortiBleed: 75,000 Fortinet Firewalls Compromised: Global Enterprises Exposed โ Claim Your Ethical Disclosure