Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-05-22

Daily Intelligence Briefing — Friday, May 22, 2026

5 critical9 high

On 2026-05-22, Threadlinqs published 14 new threat reports, 5 rated critical and 9 high, spanning 171 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 126 new detection rules and 361 extracted indicators.

New threats
1414 threat lines
Critical / high
145 critical · 9 high
ATT&CK techniques
171Observed in the day’s reports
Threat actors
6Named in the reports
Indicators
361Count only · values are Red+
Detection rules
126New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Cross-Platform Node.js NPM Stealer — Browser Credentials, Sensitive File Exfiltration, and WebSocket Reverse Shell (SHA256 049300aa…ddeb9, C2 216.126.225.243). DeepLoad Fileless Loader — ClickFix Delivery, APC Injection into LockAppHost.exe, USB .lnk Worm and Credential Theft. DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RAT.

Highlights

  • TL-2026-0557 — Cross-Platform Node.js NPM Stealer — Browser Credentials, Sensitive File Exfiltration, and WebSocket Reverse Shell (SHA256 049300aa…ddeb9, C2 216.126.225.243)
  • TL-2026-0558 — DeepLoad Fileless Loader — ClickFix Delivery, APC Injection into LockAppHost.exe, USB .lnk Worm and Credential Theft
  • TL-2026-0559 — DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RAT
  • TL-2026-0560 — Kali365 PhaaS — Telegram-Distributed Microsoft 365 Device-Code Phishing with OAuth Token Theft & MFA Bypass (FBI PSA I-052126-PSA)
  • TL-2026-0561 — ROADtools Misuse in Cloud Intrusions — Nation-State Abuse of the Open-Source Entra ID Offensive Toolkit (Unit 42)

Theme of the day

DPRK and nation-state activity dominated, with Contagious Interview npm keyloggers, Famous Chollima's InvisibleFerret, UNC1549 espionage, and Ghostwriter targeting Ukraine. Infostealers, Composer/npm supply-chain backdoors, and M365 device-code phishing rounded out a credential-theft-heavy day.

  • active-exploitation
  • windows
  • lateral-movement
  • infostealer
  • linux

Threats published

14 threat lines in the 2026-05-22 debrief, most severe first. Each links to its full profile.

Techniques observed

171 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

6 named threat actors across the reports.

  • Contagious Interview (DPRK / Famous Chollima)
  • Kali365 PhaaS operators (cluster overlap with Storm-1755; opportunistic abuse by APT29 / Midnight Blizzard)
  • Screening Serpens (UNC1549)
  • Ghostwriter (UAC-0057 / UNC1151)
  • Void Dokkaebi (Famous Chollima)
  • UNC2891

Nation-state attribution

  • North Korea (DPRK)
  • Russia / Iran
  • Iran
  • Belarus
  • North Korea

Threat categories

  • MALWARE
  • SUPPLY_CHAIN
  • PHISHING
  • CLOUD
  • APT
  • VULNERABILITY
  • ZERO_DAY

Severity breakdown

  • critical5
  • high9
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

361 indicators of compromise · Red and above. Compare plans
  • behavioral 99
  • network 82
  • file 63
  • infrastructure 32
  • technique 19
  • malware 18
  • entity 17
  • package 17
  • tool 14
126 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans