Weekly Threat Intel: July 10–17, 2026
ClickFix’s Claude-brand impersonation triples down — a 220-IOC “ClaudeFix” macOS campaign, plus ClickLock and TELEPUZ riding the same playbook. A single report catalogs 34 legacy CVEs, some from 2017, still feeding Qilin, INC, Safepay, Medusa, DragonForce, InterLock, and Rhysida ransomware against a U.S. government target. Autonomous AI moves from lure to operator: JADEPUFFER runs a fully autonomous LLM-driven ransomware kill chain, and Patriot Bait’s operator used an AI agent to build its own C2 botnet. China-nexus ORB expansion (UAT-7810) and hijacked Brazilian government sites (PhantomEnigma) continue, APT28 debuts a new Office CVE alongside a winter-timed energy-sector campaign, and a backdoored npm package pioneers Nostr/IPFS/DHT fallback C2.