The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?
That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough.
There is also ransomware, stolen ID data, hidden attack servers, and weak settings that should have been fixed long ago. Here’s the full list.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
- Fake IT, Real Access
Microsoft has warned of a human-operated intrusion campaign that leverages Microsoft Teams external collaboration to impersonate IT or help desk personnel and socially engineer users into granting an interactive remote session. "Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2)," the tech giant said. "After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim's desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management (WinRM) toward high-value assets such as domain controllers." Microsoft has described the "intrusion pattern" as high-impact as it grants an external operator interactive access to internal infrastructure.
-
Teams Vishing at Scale
In more Teams-related abuse, a coordinated social engineering operation dubbed Spring Ring has been observed leveraging external Microsoft Teams accounts to masquerade as IT help desk personnel to target more than 150 employees across at least 10 companies in various industries between January and April 2026. "What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware," Palo Alto Networks Unit 42 said. "In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC)." As many as 26 distinct attacker identities have been identified behind the chat and call attempts.
-
Ransomware Affiliate Playbook
In a new report, Sophos revealed that The Gentlemen ransomware operation, which it tracks as Gold Sherwood, has claimed a total of 683 victims by the end of July 2026. In July alone, the group is said to have added 169 victims. "The Gentlemen ransomware intrusions [...] demonstrate a repeatable affiliate playbook that combines opportunistic initial access, rapid privilege escalation, legitimate remote access mechanisms, tool staging in trusted system paths, targeted data exfiltration, aggressive defense evasion, backup disruption, and ransomware deployment," Sophos said. "Affiliates are operationally flexible: they use native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering to adapt to victims’ environments and maximize impact before encryption."
-
PhaaS Survives Takedown
The Outsider phishing-as-a-service (PaaS) platform has continued to be a resilient threat in the face of law enforcement action that took down a number of domains related to the service. The kit is operated by a threat actor known as "ChenLun." Group-IB said it has identified over 700 new phishing pages created using the kit within a month after Google filed a civil lawsuit against its operators, indicating that affiliates are continuing to use the service. The campaigns are delivered via SMS. "What was once a technically demanding operation has been reduced to a subscription and a Telegram channel," Group-IB said. "The phishing kits are distributed via a dedicated Telegram ecosystem. Operators used a WebSocket connection for live keylogging and to manipulate MFA challenges."
-
Signed Software, Hidden Payload
A government-themed tax notice campaign is targeting recipients through U.A.E.- and India-themed tax assessment lures to persuade them to open a malicious disc image. "The disc image contains a legitimate, validly signed commercial executable alongside a hidden, unsigned malicious DLL," iZOOlogic said. "This makes abuse of software trust and DLL sideloading the central mechanism of the campaign. The malicious DLL acts as a loader and establishes multiple execution and persistence mechanisms. The loader contains three encrypted payloads. Two decrypt to legitimately signed kernel drivers from unrelated commercial products, while the third is a persistence script." The attack chain paves the way for a Registry-resident second stage, which connects to an external server over UDP.
-
Executive Phishing as a Service
ZeroBEC has disclosed details of a turnkey phishing service called BlueKit that's being used to target CEOs of financial-industry groups to facilitate credential theft using a browser-in-the-middle (BitM) infrastructure. The campaign uses document-sharing lures to trigger the attack chain and employs ZeroBot to screen bots. "The campaign did not stop at credential or session theft," ZeroBEC said. "After a BlueKit browser-in-the-middle flow, selected victims were moved into a fake document-viewer workflow that delivered a legitimate ScreenConnect client configured for an attacker-used ScreenConnect cloud instance." The service advertises access at $250 for seven days, $480 for 14 days, and $940 for 30 days, placing it at the higher end of the current PhaaS market, in comparison to Tycoon 2FA, Greatness, and Forg365, which cost approximately $350, $289, and $400 per month.
-
Dormant Domains, Ready C2
Cybersecurity researchers have analyzed the infrastructure powering the operations of Prince of Persia (aka Indy), a little-known Iranian hacking group known for deploying malware families, Foudre and Tonnerre, to profile victims and harvest sensitive data from high-value targets. According to Whisper Security's Kaveh Azarhoosh, the backend is self-authoritative, with each live C2 server also running the nameservers for its own domains. Also identified is a dormant reserve of 58 domains that are registered and delegated to the group's own nameservers, but none of which currently points at any server. "They're staged, not live: the moment any one of them gains an address record, a new command server has gone live — and it's visible before the server does anything at all," Azarhoosh told The Hacker News via email.
-
Remote-Controlled Rubber Ducky
Intezer has detailed a fake "privacy browser" downloaded from a counterfeit site ("www.mxsetuplogi.com") that turns remote attacker commands into simulated mouse and keyboard input on a victim's machine. The site is surfaced via a sponsored search result on Google, in this case after the victim mistyped the domain name ("www.mxsetup.logi.con") on the address bar. The cybersecurity company described it as a USB Rubber Ducky attack delivered over the internet. "This attack evades EDR and sits at zero to two detections on VirusTotal," it said in a statement. "The infection began with one simple mistyped letter during routine mouse setup that routed the victim through a malvertising network into an MSIX installer signed through Microsoft's own infrastructure." The campaign has been tracked back to a similar operation from January 2016, indicating that the activity has been active for at least a decade.
-
153 Million IDs for Sale
The U.S. Federal Bureau of Investigation (FBI) is investigating a new ID theft service called Nexus, which claims to have digital scans of over 153 million driver's licenses from people in the U.S. and Canada. According to independent security journalist Brian Krebs, the service is said to be siphoning images collected by a widely used identity verification company called IDScan.net based in Louisiana. The service, launched on the dark web on August 31, 2026, also boasts of more than 10 million identification cards, more than three million travel documents and/or international IDs, and at least 579,000 medical cards. Each record can be unlocked for $100. Shortly after the exposé was published, Nexus went offline. IDscan.net is said to be investigating the incident on its end.
-
AI Instructions Become a Trap
A scan of 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies has uncovered llms.txt or llms-full.txt that are being placed at the root of their websites, alongside robots.txt. "The file is not a sitemap and it is not a disclaimer," an Israeli stealth startup said. "It is a curated instruction set for AI agents: what to read, which APIs to call, which packages to install, which domains to trust. OpenAI, Anthropic, and Google publish their own." Of the 8,265 llms.txt and llms-full.txt files surfaced from the scan, 120 of them, each on a different site, featured install instructions pointing to PyPI or npm package names and domains that had never been registered. "We selected a small set of package names that appeared in the llms.txt files of companies you have definitely heard of, and registered them on PyPI and npm," Alon Hertz, one of the researchers said. "Into each one we embedded a single phone-home — a minimal beacon that reported the fact of installation back to infrastructure we controlled. The first callback arrived in under four minutes." What's troubling here is that at least one active attack has already exploited this misconfiguration, in which authentication vendor Clerk's llms.txt included a reference to an npm package named "clerk-next-fix-auth-protection" instead of referencing its scoped package, @clerk/eslint-plugin. An unknown threat actor registered a public package with the same name. The package contained code to transmit the installer's username, machine name, working directory, and timestamp to an external server. Clerk has since addressed the issue.
-
AI Defenders Sound the Alarm
A coalition of over 100 companies, including Anthropic, Google, OpenAI, Microsoft, Perplexity, and others, has published an open-leet calling for improvements to cybersecurity as AI continues to compress compress cyberattack timelines, as well as accelerate the speed and scale of cyber attacks, leaving defenders with an ever-shortening window to address security issues before they are exploited. The signatories noted that current approaches to cybersecurity are not equipped to deal with the incoming surge in AI-enabled attacks, and that threat actors can rely on AI tools to target longstanding vulnerabilities, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems. "In the coming months, AI-enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable," the letter warns. "The companies and public services our communities depend on – from hospitals to water treatment plants to the infrastructure that powers the internet – are at risk. Today’s AI advances are already giving defenders new ways to fix weaknesses that have accumulated for years. If we act decisively, we can use the defenders' window to make our digital world much more secure."
-
Legacy Login Exposes 5K Accounts
Dropbox has disclosed that about 5,000 accounts were compromised last month, allowing threat actors to view and download content stored on the cloud-storage platform. The company told Reuters that it "identified unauthorized access affecting accounts linked to a Lenovo ID that did not have its two-factor authentication enabled," adding it terminated all sessions authenticated through a Lenovo ID. Lenovo said the issue is related to a "legacy integration" between Lenovo ID and Dropbox that "could be used to improperly authenticate certain Dropbox accounts."
-
Kernel Protection by Default
Microsoft has announced that it will expand memory integrity protection across eligible devices starting October 2026, to help users benefit from "stronger kernel-level protection from sophisticated attacks by default with little or no additional configuration." The company continued: "This change reduces security complexity while helping you establish a stronger security baseline across your environment. Built on Virtualization-based Security (VBS), memory integrity helps protect critical parts of Windows from tampering. It forms a foundation for modern security innovations such as hotpatch updates that improve user experience and productivity, as well as protection."
-
Pro-Ukraine Ransomware Rebrand
A new ransomware group named VantaCore has targeted at least seven Russian companies with a proprietary ransomware strain and demanding millions of dollars in ransom. The threat actor is assessed to be a rebranding of a known pro-Ukrainian group tracked as Thor, F6 said. Also put to use in the attacks are VantaCoreLoader, to distribute the ransomware and other malicious programs, VantaCoreRAT, a backdoor that can harvest information about infected systems and execute commands, and SnowKiller, which can terminate security software using the BYOVD technique.
-
Sextortion Suspects Face Life
Two Nigerian nationals, Adebola Festus Adekunle, 26, and Mudasiru Afeez Olawale, 24, have been extradited to the U.S. to face prosecution in two separate cases for the financially-motivated sextortion of minors that led to the death of minors in both the Northern District of Mississippi and the Middle District of North Carolina. Both of them face a maximum penalty of life in prison and mandatory minimum prison sentences, with the child exploitation resulting in death charge carrying a minimum penalty of 30 years in prison.
-
Hardware-Backed Digital IDs
Google said it's expanding the Android Ready SE initiative to bring together silicon vendors, device manufacturers, wallet developers, and government issuers to streamline compliance and scale certified hardware security across the mobile ecosystem. The development is seen as a way to scale high-assurance, tamper-resistant digital identity amid accelerating global demand for securely storing national electronic IDs (eIDs) and mobile driver licenses (mDLs) in hardware-backed mobile wallets.
-
OAuth Access Outlives Passwords
The FBI has warned that malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique called OAuth consent phishing to gain access to their accounts. The activity has targeted government officials, media, and other publicly known personalities on a commercial messaging application (CMA), urging them to access a malicious link under the guise of a file-sharing service through an application under the malicious actor's control. "Previous phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target's identity through a malicious application under the actor's control," the FBI said. Authorities did not provide any details about how many people may have been compromised by these attacks, or who is behind them.
-
Electron Apps Hide a Stealer
Trojanized Electron desktop applications impersonating legitimate software are being used to distribute a Windows information stealer called RevStealer. The applications are shared via GitHub repositories and game-cheat-themed sites, including a fake Claude Opus 5 Free Desktop project. "It is delivered by an Electron loader that hides an AES-encrypted native payload inside an application resource, attempts to add the user's AppData folder to Microsoft Defender's exclusion list, and launches the payload with no visible window," Morphisec said. The malware also runs a series of anti-analysis and anti-VM checks before unpacking the main payload. "If the primary C2 is unreachable, RevStealer reads a fallback address from a smart contract on the Polygon blockchain, letting operators rotate infrastructure without rebuilding the malware," the company said. What's notable about the malware is that it's not designed for persistence. Rather, it prioritizes capturing as much data as possible in a single run, exfiltrates it in encrypted typed records, and then deletes itself.
-
Trusted Tool, Rogue Access
Threat actors are weaponizing Faronics Deploy, a legitimate endpoint management platform, to run attacker-controlled PowerShell after phishing victims install the software. Huntress said it observed more than 457 endpoints encountering Faronics-related lures. "In observed cases, threat actors chained Faronics Deploy to ScreenConnect, blending malicious remote access activity into trusted software workflows," it said. "The delivery method varies between scripts, with observed examples using curl or MSHTA to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructure. These scripts are subsequently used to install ScreenConnect, establishing an additional remote access mechanism on the compromised endpoint."
-
ClickFix Goes Cross-Platform
Cybersecurity researchers have described CRPx0 as a ClickFix-delivered ransomware-as-a-service (RaaS) operation that employs lures related to Windows and macOS update prompts and reCAPTCHA checks to trick victims into running a copied command. "On Windows, it starts a multi-stage DLL chain. On macOS, it downloads the Python payload directly," the Ransom-ISAC Research Team said. "The final payload is a cross-platform Python ransomware that exfiltrates data before encryption, encrypts files with AES-128-CBC via Fernet, wraps the per-victim key with an embedded RSA-4096 public key, attempts lateral movement, and drops ransom notes demanding Bitcoin or Monero payment within 48 hours." The RaaS program first appeared on June 7, 2026. As of late August, the group has advertised the operation on a clearnet site ("crpx0[.]su/v3.txt") as an offensive control panel to manage compromised machines, harvest files and credentials, monitor stolen cryptocurrency artifacts, run remote commands, and launch ransomware manually.
One point is easy to miss: changing a password may not shut every door. A bad app approval or remote session can give attackers access without the password. Recovery should also end open sessions, remove unknown app access, and check remote tools.
Better security settings are slowly becoming the default, which helps. But old account links, weak sign-in options, and trusted software still give attackers room to work. The safest rule this week is simple: check what already has access before adding anything new.








