The Indicator

Threat Intelligence Blog

Weekly and monthly analysis of cyber threat trends, IOC patterns, and adversary tradecraft — powered by iocget data.

Weekly Report August 28, 2026

Weekly Threat Intel: August 21–28, 2026

The ChainDrop npm worm picks up its sixth and seventh independent vendor confirmations — still persisting via the same .claude/settings.json and .vscode/tasks.json hooks — while PolySwarm publishes eight reports in under three minutes mixing new material (Kimsuky's AI-tooling-equipped Operation GitPower, an Iranian PLC campaign against US critical infrastructure) with second opinions on campaigns already tracked here. A suspected China-nexus APT chains a VMware vCenter CVE straight to root access and ransomware, Security.com matches PolySwarm's publishing cadence with four reports in 24 seconds, and this week's two largest reports both funnel fake-media lures into commodity RATs.

40 reports analyzed 1,372 IOCs extracted 7 vendors confirm one npm worm
Monthly Digest August 21, 2026

Threat Intel Digest: August 1–21, 2026

A three-week catch-up. Five vendors independently confirm the same Shai-Hulud/ChainDrop npm supply-chain worm across six days, while a separate trojanized QuickFox VPN installer campaign lands two more vendors on the same FDMTP backdoor infrastructure. Cisco Talos publishes three reports on UAT-10147, a group now using agentic AI to automate its own exploit refinement and post-compromise operations. Claude-brand abuse continues as MacSync's fake install guide resurfaces and an AI-built crypto fraud pipeline layers in a lookalike domain. Lazarus burns a Windows zero-day for Operation Dream Job, Head Mare chains TrueConf Server flaws twice in nine days, and two SonicWall SMA CVEs chain to zero-click root compromise.

92 reports analyzed 4,382 IOCs extracted 5 vendors confirm one npm supply-chain worm
Weekly Report July 31, 2026

Weekly Threat Intel: July 24–31, 2026

HivePro publishes nine reports across two four-report batch windows — including two actively-exploited zero-days in Check Point SmartConsole and Arista VeloCloud Orchestrator — while Censys independently corroborates Cl0p’s exploitation of a PTC Windchill RCE and HOLLOWGRAPH picks up a third vendor write-up naming Israeli targets. Claude-brand abuse and AI-agent targeting span four separate reports, including a new “AgentBaiting” technique built to be discovered by AI coding agents rather than human developers, and two unrelated Microsoft Teams vishing campaigns converge on remote-access tooling before diverging into a backdoor toolkit and a straight run to Chaos ransomware.

29 reports analyzed 656 IOCs extracted 9 reports from one vendor across two batches
Weekly Report July 24, 2026

Weekly Threat Intel: July 17–24, 2026

One vendor, StrikeReady, publishes ten reports in a single three-minute window — a Bitter/Sidewinder South Asian espionage triad targeting Pakistani government and military entities, plus four Russia-nexus campaigns against Ukraine including a sandbox-evading, mouse-movement-gated HTML lure. Trend Micro formally confirms the first documented case of a fully autonomous, AI-driven ransomware attack — the same campaign, CVEs, and C2 IP as last week’s JADEPUFFER report — while FakeAgent malvertises a fake Claude Desktop installer for a third straight week of Claude-brand abuse. Federal agencies warn of ongoing PLC exploitation against U.S. critical infrastructure, three unrelated malware families converge independently on Rust, and Group-IB’s HOLLOWGRAPH turns out to share a C2 domain with Securelist’s Project CAV3RN.

34 reports analyzed 1,675 IOCs extracted 10 reports from one vendor in one day
Weekly Report July 17, 2026

Weekly Threat Intel: July 10–17, 2026

ClickFix’s Claude-brand impersonation triples down — a 220-IOC “ClaudeFix” macOS campaign, plus ClickLock and TELEPUZ riding the same playbook. A single report catalogs 34 legacy CVEs, some from 2017, still feeding Qilin, INC, Safepay, Medusa, DragonForce, InterLock, and Rhysida ransomware against a U.S. government target. Autonomous AI moves from lure to operator: JADEPUFFER runs a fully autonomous LLM-driven ransomware kill chain, and Patriot Bait’s operator used an AI agent to build its own C2 botnet. China-nexus ORB expansion (UAT-7810) and hijacked Brazilian government sites (PhantomEnigma) continue, APT28 debuts a new Office CVE alongside a winter-timed energy-sector campaign, and a backdoored npm package pioneers Nostr/IPFS/DHT fallback C2.

22 reports analyzed 1,359 IOCs extracted 3 Claude-branded ClickFix campaigns
Monthly Digest July 10, 2026

Threat Intel Digest: June 13–July 10, 2026

A four-week catch-up. ClickFix and fake “verify you’re human” pages become the universal malware delivery layer — one campaign even hid lures inside claude.ai shared-chat links — funneling into infostealers, RATs, and Rhysida ransomware. A nine-CVE exploitation wave hits the edge: PAN-OS, CitrixBleed 2 (→ DragonForce), Cisco SD-WAN Manager zero-days, PTC Windchill, SonicWall, and Langflow. Legitimate RMM tools (ManageEngine over WhatsApp, MeshCentral, NinjaOne) become the implant of choice. State-nexus espionage from Turla (STOCKSTAY), Ghostwriter, Cavern Manticore, ToddyCat (OAuth theft), and UNC6508. AI moves into the crosshairs — weaponized as a lure and targeted with prompt injection built to fool automated triage. Plus The Gentlemen, Sinobi, and Prinz Eugen ransomware, and a $1M Kairos payment by a U.S. government entity.

83 reports analyzed 3,073 IOCs extracted 10+ ClickFix campaigns
Weekly Report June 12, 2026

Weekly Threat Intel: June 6–12, 2026

The geopolitical week. APT36’s “Operation TrustTrap” weaponizes 16,800+ spoofed government domains for credential and payment-data theft — scale that breaks the enumerate-and-block model. A surge of state-nexus espionage maps directly onto active conflicts: GREYVIBE (Russia) against Ukraine, Operation Dragon Weave against Taiwan and Czechia, SideCopy’s XENOFISCAL against Afghanistan, an Iranian intrusion into Oman, and Mustang Panda’s LOTUSLITE against India and South Korea. Two destructive wipers strike critical infrastructure — Handala on the GCC (6 PB destroyed), Lotus Wiper on Venezuela’s energy sector. Qilin and The Gentlemen ransomware scale; CVE-2025-8088 (WinRAR) fuels GIFTEDCROOK against Ukraine; UAT-4356 deploys the firmware-persistent FIRESTARTER backdoor on Cisco firewalls; plus an AiTM kit, device-code phishing, and a poisoned Rust crate.

27 reports analyzed 1,115 IOCs extracted 16,800+ spoofed gov domains
Weekly Report June 5, 2026

Weekly Threat Intel: May 30–June 5, 2026

The deception economy comes of age. Check Point exposes a 100+ site Traffic Distribution System that spoofs Ghidra, dnSpy, ILSpy, and SpiderFoot to deliver the new RemusStealer and SessionGate families. Group-IB unmasks the “Error 524” smishing operation — 260+ impersonated brands across 72 countries, hiding live credit-card phishing kits behind fake Cloudflare error pages with WebSocket exfiltration. Elastic dissects PHANTOMPULSE (REF6598), a RAT that resolves its C2 through Ethereum, Base, and Optimism transactions and so has no domain to block. Argamal RAT ships in trojanized hentai games via COM hijacking; Kali365 PhaaS pivots from Microsoft to Okta device-code abuse; plus DesckVB RAT, JS.MonoGlyphRAT, and a fake BlueWallet macOS stealer. Almost none of it needed a CVE.

13 reports analyzed 351 IOCs extracted 100+ spoofed dev-tool sites
Weekly Report May 29, 2026

Weekly Threat Intel: May 25–29, 2026

ShinyHunters extortion spree hits Charter (40M records), Carnival (6M), and Canvas (275M education records) using the same vishing-to-SaaS-export technique three times. Scattered Spider pivots to the US with the Victoria’s Secret attack as UK police arrest four (three teenagers). PAN-OS GlobalProtect CVE-2026-0257 actively exploited with CISA KEV June 19 deadline; 18-year-old NGINX heap overflow with public ASLR bypass chain. Dutch police seize Asocks botnet (17M devices). First in-the-wild LLM-driven intrusion documented by Sysdig. ESET APT report: Lazarus poisons axios (100M weekly downloads), GREYVIBE uses AI across the full kill chain.

32 reports analyzed 6 critical CISA KEV additions 17M-device botnet seized
Weekly Report May 24, 2026

Weekly Threat Intel: May 18–24, 2026

LummaC2 global takedown seizes 2,300 C2 domains and disrupts 394,000+ active infections. Joint 21-agency advisory confirms sustained APT28 espionage against Western logistics supplying Ukraine. Ivanti EPMM chained RCE (CVE-2025-4427 + CVE-2025-4428) actively exploited by China-nexus UNC5221 with public PoCs available. DanaBot disrupted, 16 charged — dual criminal/espionage tracks revealed. Interlock ransomware exposes 1.7M Kettering Health patients after 41-day dwell. Scattered Spider expands UK campaign to cold-chain logistics, disrupting nine supermarket chains simultaneously.

28 reports analyzed 1,800+ IOCs extracted 4 critical CISA KEV additions
Weekly Report May 17, 2026

Weekly Threat Intel: May 11–17, 2026

Google GTIG documents the first AI-generated zero-day exploit used in a real attack — a 2FA bypass written by a criminal actor using an AI model, caught before mass exploitation launched. Cisco SD-WAN Manager hit by a CVSS 10.0 authentication bypass (CVE-2026-20182) already under active exploitation by UAT-8616. May Patch Tuesday fixes 120+ CVEs including unauthenticated SYSTEM RCE against domain controllers. ShinyHunters’ Canvas breach reaches a “ransom resolution” covering 275 million students and staff, and “Dirty Frag” delivers root on all major Linux distros with a public PoC and one CVE still unpatched.

25 reports analyzed 1,600+ IOCs extracted 3 critical CISA KEV additions
Weekly Report May 10, 2026

Weekly Threat Intel: May 4–10, 2026

Palo Alto PAN-OS zero-day (CVE-2026-0300, CVSS 9.3) confirmed under active exploitation since April 9 with root RCE — no patch until May 13. DOJ sentencing reveals Karakurt ransomware group co-opted Russian government databases as operational infrastructure. ShinyHunters claims 9 million Medtronic medical records, PCPJack cloud worm fully documented targeting AI API keys, and IBM discloses a Chinese-backed group using Claude for 80–90% of attack operations end-to-end.

22 reports analyzed 1,400+ IOCs extracted 2 critical CISA KEV additions
Weekly Report May 3, 2026

Weekly Threat Intel: April 27–May 3, 2026

DragonForce cartel simultaneously takes down M&S, Co-op, and Harrods via outsourced helpdesk social engineering — M&S projects £300M in losses. APT28 deploys LAMEHUG and PROMPTSTEAL, the first confirmed state-sponsored malware that queries Alibaba Cloud’s Qwen LLM at runtime. DPRK closes April at $577M in crypto theft. TeamPCP poisons four official SAP npm packages and PCPJack worm spreads through cloud infrastructure harvesting AI API keys.

28 reports analyzed 2,100+ IOCs extracted 4 supply-chain incidents
Weekly Report April 26, 2026

Weekly Threat Intel: April 19–26, 2026

The SaaS supply chain cracks open — Vercel breached via a 22-month OAuth chain that started with Lumma at Context.ai, the Bitwarden CLI npm package shipped a credential stealer for 90 minutes, and Scattered LAPSUS$ Hunters launches the first “Extortion-as-a-Service” platform. APT28 Operation Neusploit produces the week’s largest 347-IOC dataset, DPRK industrializes fake-meeting lures, and Huntress publishes the first IR report where an AI coding agent actively complicated triage.

24 reports analyzed 1,650+ IOCs extracted 5 supply-chain incidents
Weekly Report April 18, 2026

Weekly Threat Intel: April 11–18, 2026

The Iran picture sharpens — DomainTools maps the MOIS-linked ecosystem tying Handala, Homeland Justice, and Karma together, while APT28 opens two new fronts with TP-Link DNS hijacking and a PRISMEX zero-day chain. Four actively exploited zero-days, GlassWorm’s 433-package second wave, and threat actors treating n8n, Heroku, and Solana as purpose-built C2 infrastructure.

23 reports analyzed 980+ IOCs extracted 4 active zero-days