The Indicator

Threat Intelligence Blog

Weekly and monthly analysis of cyber threat trends, IOC patterns, and adversary tradecraft — powered by iocget data.

Weekly Report July 17, 2026

Weekly Threat Intel: July 10–17, 2026

ClickFix’s Claude-brand impersonation triples down — a 220-IOC “ClaudeFix” macOS campaign, plus ClickLock and TELEPUZ riding the same playbook. A single report catalogs 34 legacy CVEs, some from 2017, still feeding Qilin, INC, Safepay, Medusa, DragonForce, InterLock, and Rhysida ransomware against a U.S. government target. Autonomous AI moves from lure to operator: JADEPUFFER runs a fully autonomous LLM-driven ransomware kill chain, and Patriot Bait’s operator used an AI agent to build its own C2 botnet. China-nexus ORB expansion (UAT-7810) and hijacked Brazilian government sites (PhantomEnigma) continue, APT28 debuts a new Office CVE alongside a winter-timed energy-sector campaign, and a backdoored npm package pioneers Nostr/IPFS/DHT fallback C2.

22 reports analyzed 1,359 IOCs extracted 3 Claude-branded ClickFix campaigns
Monthly Digest July 10, 2026

Threat Intel Digest: June 13–July 10, 2026

A four-week catch-up. ClickFix and fake “verify you’re human” pages become the universal malware delivery layer — one campaign even hid lures inside claude.ai shared-chat links — funneling into infostealers, RATs, and Rhysida ransomware. A nine-CVE exploitation wave hits the edge: PAN-OS, CitrixBleed 2 (→ DragonForce), Cisco SD-WAN Manager zero-days, PTC Windchill, SonicWall, and Langflow. Legitimate RMM tools (ManageEngine over WhatsApp, MeshCentral, NinjaOne) become the implant of choice. State-nexus espionage from Turla (STOCKSTAY), Ghostwriter, Cavern Manticore, ToddyCat (OAuth theft), and UNC6508. AI moves into the crosshairs — weaponized as a lure and targeted with prompt injection built to fool automated triage. Plus The Gentlemen, Sinobi, and Prinz Eugen ransomware, and a $1M Kairos payment by a U.S. government entity.

83 reports analyzed 3,073 IOCs extracted 10+ ClickFix campaigns
Weekly Report June 12, 2026

Weekly Threat Intel: June 6–12, 2026

The geopolitical week. APT36’s “Operation TrustTrap” weaponizes 16,800+ spoofed government domains for credential and payment-data theft — scale that breaks the enumerate-and-block model. A surge of state-nexus espionage maps directly onto active conflicts: GREYVIBE (Russia) against Ukraine, Operation Dragon Weave against Taiwan and Czechia, SideCopy’s XENOFISCAL against Afghanistan, an Iranian intrusion into Oman, and Mustang Panda’s LOTUSLITE against India and South Korea. Two destructive wipers strike critical infrastructure — Handala on the GCC (6 PB destroyed), Lotus Wiper on Venezuela’s energy sector. Qilin and The Gentlemen ransomware scale; CVE-2025-8088 (WinRAR) fuels GIFTEDCROOK against Ukraine; UAT-4356 deploys the firmware-persistent FIRESTARTER backdoor on Cisco firewalls; plus an AiTM kit, device-code phishing, and a poisoned Rust crate.

27 reports analyzed 1,115 IOCs extracted 16,800+ spoofed gov domains
Weekly Report June 5, 2026

Weekly Threat Intel: May 30–June 5, 2026

The deception economy comes of age. Check Point exposes a 100+ site Traffic Distribution System that spoofs Ghidra, dnSpy, ILSpy, and SpiderFoot to deliver the new RemusStealer and SessionGate families. Group-IB unmasks the “Error 524” smishing operation — 260+ impersonated brands across 72 countries, hiding live credit-card phishing kits behind fake Cloudflare error pages with WebSocket exfiltration. Elastic dissects PHANTOMPULSE (REF6598), a RAT that resolves its C2 through Ethereum, Base, and Optimism transactions and so has no domain to block. Argamal RAT ships in trojanized hentai games via COM hijacking; Kali365 PhaaS pivots from Microsoft to Okta device-code abuse; plus DesckVB RAT, JS.MonoGlyphRAT, and a fake BlueWallet macOS stealer. Almost none of it needed a CVE.

13 reports analyzed 351 IOCs extracted 100+ spoofed dev-tool sites
Weekly Report May 29, 2026

Weekly Threat Intel: May 25–29, 2026

ShinyHunters extortion spree hits Charter (40M records), Carnival (6M), and Canvas (275M education records) using the same vishing-to-SaaS-export technique three times. Scattered Spider pivots to the US with the Victoria’s Secret attack as UK police arrest four (three teenagers). PAN-OS GlobalProtect CVE-2026-0257 actively exploited with CISA KEV June 19 deadline; 18-year-old NGINX heap overflow with public ASLR bypass chain. Dutch police seize Asocks botnet (17M devices). First in-the-wild LLM-driven intrusion documented by Sysdig. ESET APT report: Lazarus poisons axios (100M weekly downloads), GREYVIBE uses AI across the full kill chain.

32 reports analyzed 6 critical CISA KEV additions 17M-device botnet seized
Weekly Report May 24, 2026

Weekly Threat Intel: May 18–24, 2026

LummaC2 global takedown seizes 2,300 C2 domains and disrupts 394,000+ active infections. Joint 21-agency advisory confirms sustained APT28 espionage against Western logistics supplying Ukraine. Ivanti EPMM chained RCE (CVE-2025-4427 + CVE-2025-4428) actively exploited by China-nexus UNC5221 with public PoCs available. DanaBot disrupted, 16 charged — dual criminal/espionage tracks revealed. Interlock ransomware exposes 1.7M Kettering Health patients after 41-day dwell. Scattered Spider expands UK campaign to cold-chain logistics, disrupting nine supermarket chains simultaneously.

28 reports analyzed 1,800+ IOCs extracted 4 critical CISA KEV additions
Weekly Report May 17, 2026

Weekly Threat Intel: May 11–17, 2026

Google GTIG documents the first AI-generated zero-day exploit used in a real attack — a 2FA bypass written by a criminal actor using an AI model, caught before mass exploitation launched. Cisco SD-WAN Manager hit by a CVSS 10.0 authentication bypass (CVE-2026-20182) already under active exploitation by UAT-8616. May Patch Tuesday fixes 120+ CVEs including unauthenticated SYSTEM RCE against domain controllers. ShinyHunters’ Canvas breach reaches a “ransom resolution” covering 275 million students and staff, and “Dirty Frag” delivers root on all major Linux distros with a public PoC and one CVE still unpatched.

25 reports analyzed 1,600+ IOCs extracted 3 critical CISA KEV additions
Weekly Report May 10, 2026

Weekly Threat Intel: May 4–10, 2026

Palo Alto PAN-OS zero-day (CVE-2026-0300, CVSS 9.3) confirmed under active exploitation since April 9 with root RCE — no patch until May 13. DOJ sentencing reveals Karakurt ransomware group co-opted Russian government databases as operational infrastructure. ShinyHunters claims 9 million Medtronic medical records, PCPJack cloud worm fully documented targeting AI API keys, and IBM discloses a Chinese-backed group using Claude for 80–90% of attack operations end-to-end.

22 reports analyzed 1,400+ IOCs extracted 2 critical CISA KEV additions
Weekly Report May 3, 2026

Weekly Threat Intel: April 27–May 3, 2026

DragonForce cartel simultaneously takes down M&S, Co-op, and Harrods via outsourced helpdesk social engineering — M&S projects £300M in losses. APT28 deploys LAMEHUG and PROMPTSTEAL, the first confirmed state-sponsored malware that queries Alibaba Cloud’s Qwen LLM at runtime. DPRK closes April at $577M in crypto theft. TeamPCP poisons four official SAP npm packages and PCPJack worm spreads through cloud infrastructure harvesting AI API keys.

28 reports analyzed 2,100+ IOCs extracted 4 supply-chain incidents
Weekly Report April 26, 2026

Weekly Threat Intel: April 19–26, 2026

The SaaS supply chain cracks open — Vercel breached via a 22-month OAuth chain that started with Lumma at Context.ai, the Bitwarden CLI npm package shipped a credential stealer for 90 minutes, and Scattered LAPSUS$ Hunters launches the first “Extortion-as-a-Service” platform. APT28 Operation Neusploit produces the week’s largest 347-IOC dataset, DPRK industrializes fake-meeting lures, and Huntress publishes the first IR report where an AI coding agent actively complicated triage.

24 reports analyzed 1,650+ IOCs extracted 5 supply-chain incidents
Weekly Report April 18, 2026

Weekly Threat Intel: April 11–18, 2026

The Iran picture sharpens — DomainTools maps the MOIS-linked ecosystem tying Handala, Homeland Justice, and Karma together, while APT28 opens two new fronts with TP-Link DNS hijacking and a PRISMEX zero-day chain. Four actively exploited zero-days, GlassWorm’s 433-package second wave, and threat actors treating n8n, Heroku, and Solana as purpose-built C2 infrastructure.

23 reports analyzed 980+ IOCs extracted 4 active zero-days