Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-02-02

Daily Intelligence Briefing — Monday, February 2, 2026

9 critical23 high14 medium1 low

On 2026-02-02, Threadlinqs published 47 new threat reports, 9 rated critical and 23 high, spanning 214 MITRE ATT&CK techniques and 12 named threat actors. Coverage that day added 728 new detection rules and 2228 extracted indicators.

New threats
4747 threat lines
Critical / high
329 critical · 23 high
ATT&CK techniques
214Observed in the day’s reports
Threat actors
12Named in the reports
Indicators
2228Count only · values are Red+
Detection rules
728New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Microsoft NTLM Phase-Out: Detection & Migration Guidance. Global HYIP Investment Scam Campaign - 4,200+ Fake Trading Platforms. Microsoft NTLM Deprecation - Enterprise Migration Planning Required.

Highlights

  • TL-2026-0005 — Malicious Chrome Extensions: Affiliate Hijacking & ChatGPT Token Theft Campaign
  • TL-2026-0006 — Automated MongoDB Extortion Campaign Targeting Exposed Instances
  • TL-2026-0007 — UAT-8099 (China) BadIIS Malware Campaign Targeting IIS Servers for SEO Fraud
  • TL-2026-0008 — OpenClaw CVE-2026-25253: One-Click RCE via Token Exfiltration
  • TL-2026-0010 — Microsoft Office Zero-Day CVE-2026-21509: OLE Security Bypass Under Active Exploitation

Theme of the day

  • credential-theft
  • social-engineering
  • cwe-306
  • cwe-287
  • cwe-345

Threats published

47 threat lines in the 2026-02-02 debrief, most severe first. Each links to its full profile.

Techniques observed

214 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

12 named threat actors across the reports.

Nation-state attribution

  • China
  • North Korea (partial)
  • United States
  • China (referenced threat)
  • Russia
  • France
  • North Korea

Threat categories

  • ADVISORY
  • FRAUD
  • MISCONFIGURATION
  • PHISHING
  • THREAT_INTEL
  • DATA_BREACH
  • POLICY
  • MALWARE
  • RANSOMWARE
  • APT
  • CVE
  • CAMPAIGN
  • SUPPLY_CHAIN
  • VULNERABILITY
  • EXTORTION
  • THREAT_ACTOR
  • ICS_SCADA

Severity breakdown

  • critical9
  • high23
  • medium14
  • low1

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

2228 indicators of compromise · Red and above. Compare plans
  • behavioral 1301
  • network 580
  • host 277
  • file 61
  • email 6
  • financial 3
728 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans