Threadlinqs IntelligenceStart free

Daily debrief · Monday2026-02-16

Daily Intelligence Briefing — Monday, February 16, 2026

9 critical16 high1 medium

On 2026-02-16, Threadlinqs published 15 new threat reports and updated 11, 9 rated critical and 16 high, spanning 260 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 243 new detection rules and 723 extracted indicators.

New threats
1511 updated
Critical / high
259 critical · 16 high
ATT&CK techniques
260Observed in the day’s reports
Threat actors
7Named in the reports
Indicators
723Count only · values are Red+
Detection rules
243New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown Complexity. GitHub Codespaces RCE via VS Code Configuration Files. SystemBC Malware Resurges with 10K+ Infections.

Highlights

  • TL-2026-0099 — Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown Complexity
  • TL-2026-0100 — GitHub Codespaces RCE via VS Code Configuration Files
  • TL-2026-0101 — SystemBC Malware Resurges with 10K+ Infections
  • TL-2026-0104 — Screensaver (.SCR) Files Used as Initial Access Vector
  • TL-2026-0106 — APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform Espionage

Theme of the day

  • cisa-kev
  • credential-theft
  • critical-infrastructure
  • fileless-execution
  • pre-auth-rce

Threats published

26 threat lines in the 2026-02-16 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

260 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

7 named threat actors across the reports.

  • APT36 / Transparent Tribe
  • KongTuke
  • Femwar02 (BaBlock/Rorschach affiliate)
  • Qilin (Agenda)
  • Aisuru-Kimwolf (Forky)
  • Azote Group / UNC4696
  • TGR-STA-1030

Nation-state attribution

  • Russia
  • Pakistan
  • Russia, Belarus
  • China (APT10), Unattributed (FIN7)
  • Switzerland
  • China (predecessor exploitation)
  • China
  • China (assessed with high confidence — Asian state-aligned, GMT+8, AS 9808, regional tooling, JackMa handle)

Threat categories

  • VULNERABILITY

Severity breakdown

  • critical9
  • high16
  • medium1
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

723 indicators of compromise · Red and above. Compare plans
  • behavioral 287
  • technique 185
  • network 155
  • file 92
  • email 4
243 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans