# Daily Intelligence Briefing — Wednesday, May 27, 2026

> On 2026-05-27, Threadlinqs published 14 new threat reports, 5 rated critical and 9 high, spanning 216 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 126 new detection rules and 398 extracted indicators.

- **Edition:** 2026-05-27 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-05-27
- **Last updated:** 2026-06-02
- **New threats:** 14
- **Critical / high:** 5 critical, 9 high, 0 medium, 0 low
- **ATT&CK techniques:** 216
- **Threat actors:** 6
- **Indicators (count only):** 398
- **New detection rules (count only):** 126

## Summary & highlights

BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039). BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse. Nested Triple-Chain Google Domain Phishing — Microsoft SafeLinks -> meet.google.com/linkredirect -> google.com/url -> adservice.google.com.ph Evades SEGs and Lands M365 Credential Theft Plus OAuth 2.0 Device-Code Phishing (KnowBe4 ThreatLabs Nested Delivery Matrix).

- [TL-2026-0599](https://intel.threadlinqs.com/threat/TL-2026-0599) — BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)
- [TL-2026-0600](https://intel.threadlinqs.com/threat/TL-2026-0600) — BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse
- [TL-2026-0601](https://intel.threadlinqs.com/threat/TL-2026-0601) — Nested Triple-Chain Google Domain Phishing — Microsoft SafeLinks -> meet.google.com/linkredirect -> google.com/url -> adservice.google.com.ph Evades SEGs and Lands M365 Credential Theft Plus OAuth 2.0 Device-Code Phishing (KnowBe4 ThreatLabs Nested Delivery Matrix)
- [TL-2026-0602](https://intel.threadlinqs.com/threat/TL-2026-0602) — Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container Images Across 31,000+ Self-Hosted Instances
- [TL-2026-0603](https://intel.threadlinqs.com/threat/TL-2026-0603) — GlassWorm Developer Supply Chain Campaign Takedown — CrowdStrike + Google + Shadowserver Disrupt 4-Channel C2 (Solana / BitTorrent DHT / Google Calendar / VPS)

## Theme of the day

Credential theft and active exploitation prevailed: Android banking trojans OverlayPhantom and BTMOB, nested Google-domain phishing, and Akira ransomware via SSLVPN. Critical CVEs hit Windows Kernel, GitHub Enterprise, Starlette/AI infra, plus a multi-CVE BIND 9 disclosure.

credential-theft, linux, active-exploitation, financially-motivated, phishing

## Threats published

- [TL-2026-0598](https://intel.threadlinqs.com/threat/TL-2026-0598) — CRITICAL — OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and Crypto Apps (Cyble CRIL)
- [TL-2026-0604](https://intel.threadlinqs.com/threat/TL-2026-0604) — CRITICAL — Windows Kernel CVE-2026-40369 — NtQuerySystemInformation ProbeForWrite Bypass Enables Arbitrary Kernel Memory Increment → SYSTEM LPE from Browser Sandboxes (Ori Nimron)
- [TL-2026-0605](https://intel.threadlinqs.com/threat/TL-2026-0605) — CRITICAL — GitHub Enterprise Server 3.20.3 — Pre-Auth SSRF in Upload Endpoint (CVE-2026-9312) + Bundled "Dirty Frag" Kernel LPEs (CVE-2026-43284, CVE-2026-43500) + Mandatory GPG Signing Key Rotation
- [TL-2026-0606](https://intel.threadlinqs.com/threat/TL-2026-0606) — CRITICAL — BadHost CVE-2026-48710 — Starlette HTTP Host Header Authentication Bypass Affecting FastAPI/AI Infrastructure (MCP, vLLM, LiteLLM)
- [TL-2026-0607](https://intel.threadlinqs.com/threat/TL-2026-0607) — CRITICAL — JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn Social Engineering and Internal CI/CD Hijacking (Wiz CIRT)
- [TL-2026-0599](https://intel.threadlinqs.com/threat/TL-2026-0599) — HIGH — BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)
- [TL-2026-0600](https://intel.threadlinqs.com/threat/TL-2026-0600) — HIGH — BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse
- [TL-2026-0601](https://intel.threadlinqs.com/threat/TL-2026-0601) — HIGH — Nested Triple-Chain Google Domain Phishing — Microsoft SafeLinks -> meet.google.com/linkredirect -> google.com/url -> adservice.google.com.ph Evades SEGs and Lands M365 Credential Theft Plus OAuth 2.0 Device-Code Phishing (KnowBe4 ThreatLabs Nested Delivery Matrix)
- [TL-2026-0602](https://intel.threadlinqs.com/threat/TL-2026-0602) — HIGH — Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container Images Across 31,000+ Self-Hosted Instances
- [TL-2026-0603](https://intel.threadlinqs.com/threat/TL-2026-0603) — HIGH — GlassWorm Developer Supply Chain Campaign Takedown — CrowdStrike + Google + Shadowserver Disrupt 4-Channel C2 (Solana / BitTorrent DHT / Google Calendar / VPS)
- [TL-2026-0608](https://intel.threadlinqs.com/threat/TL-2026-0608) — HIGH — forge-jsxy npm Supply Chain RAT — 22 Versions in 22 Days with Crypto Wallet Theft, WebRTC P2P Exfil & Cross-Platform Persistent Backdoor (OSV MAL-2026-3609, SafeDep)
- [TL-2026-0609](https://intel.threadlinqs.com/threat/TL-2026-0609) — HIGH — Grandoreiro Banking Trojan Resurgence (May 2026) — Dual-Vector DLL Side-Loading & VBS Geofenced Campaign with SGC WebSockets/WebRTC C2 Tunneled Through Google Cloud Pub/Sub, Azure MQTT and AWS MQTT Targeting 20+ Portuguese Banks, Spain, Mexico and LATAM
- [TL-2026-0610](https://intel.threadlinqs.com/threat/TL-2026-0610) — HIGH — Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)
- [TL-2026-0611](https://intel.threadlinqs.com/threat/TL-2026-0611) — HIGH — EKZ Infostealer Campaign — FortiClient EMS CVE-2026-35616 Abused via on_connect Script Injection (Arctic Wolf, May 2026)

## Techniques observed

[T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), T1029, [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.003](https://intel.threadlinqs.com/technique/T1036.003), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1039](https://intel.threadlinqs.com/technique/T1039), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), T1053.004, [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), T1053.006, [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069.002](https://intel.threadlinqs.com/technique/T1069.002), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.002](https://intel.threadlinqs.com/technique/T1078.002), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.004](https://intel.threadlinqs.com/technique/T1090.004), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1134.001](https://intel.threadlinqs.com/technique/T1134.001), [T1134.002](https://intel.threadlinqs.com/technique/T1134.002), T1134.004, [T1136.002](https://intel.threadlinqs.com/technique/T1136.002), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1213.003](https://intel.threadlinqs.com/technique/T1213.003), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1406](https://intel.threadlinqs.com/technique/T1406), [T1409](https://intel.threadlinqs.com/technique/T1409), [T1414](https://intel.threadlinqs.com/technique/T1414), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1417.002](https://intel.threadlinqs.com/technique/T1417.002), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1422](https://intel.threadlinqs.com/technique/T1422), [T1426](https://intel.threadlinqs.com/technique/T1426), [T1429](https://intel.threadlinqs.com/technique/T1429), [T1430](https://intel.threadlinqs.com/technique/T1430), [T1437](https://intel.threadlinqs.com/technique/T1437), [T1453](https://intel.threadlinqs.com/technique/T1453), [T1456](https://intel.threadlinqs.com/technique/T1456), T1474, T1476, [T1481](https://intel.threadlinqs.com/technique/T1481), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484.001](https://intel.threadlinqs.com/technique/T1484.001), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1498](https://intel.threadlinqs.com/technique/T1498), T1498.002, [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), T1509, [T1512](https://intel.threadlinqs.com/technique/T1512), [T1513](https://intel.threadlinqs.com/technique/T1513), [T1516](https://intel.threadlinqs.com/technique/T1516), [T1517](https://intel.threadlinqs.com/technique/T1517), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1521](https://intel.threadlinqs.com/technique/T1521), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1531](https://intel.threadlinqs.com/technique/T1531), T1532, [T1533](https://intel.threadlinqs.com/technique/T1533), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1541](https://intel.threadlinqs.com/technique/T1541), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.009](https://intel.threadlinqs.com/technique/T1547.009), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), T1550.003, [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1552.007](https://intel.threadlinqs.com/technique/T1552.007), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1558.003](https://intel.threadlinqs.com/technique/T1558.003), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1560](https://intel.threadlinqs.com/technique/T1560), T1562, T1562.001, T1562.002, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), T1574.002, [T1575](https://intel.threadlinqs.com/technique/T1575), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1582](https://intel.threadlinqs.com/technique/T1582), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), T1583.002, [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.003](https://intel.threadlinqs.com/technique/T1585.003), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1590](https://intel.threadlinqs.com/technique/T1590), T1590.002, [T1592](https://intel.threadlinqs.com/technique/T1592), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1596.005](https://intel.threadlinqs.com/technique/T1596.005), [T1602](https://intel.threadlinqs.com/technique/T1602), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1614.001](https://intel.threadlinqs.com/technique/T1614.001), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1624](https://intel.threadlinqs.com/technique/T1624), [T1624.001](https://intel.threadlinqs.com/technique/T1624.001), [T1626](https://intel.threadlinqs.com/technique/T1626), [T1628](https://intel.threadlinqs.com/technique/T1628), T1628.001, T1632, [T1636](https://intel.threadlinqs.com/technique/T1636), T1640, T1641, T1644, [T1646](https://intel.threadlinqs.com/technique/T1646), [T1655](https://intel.threadlinqs.com/technique/T1655), T1655.001, T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660)

## Threat actors

BTMOB MaaS operator (Unattributed), GlassWorm Operators (Russian-speaking crimeware crew), jacksonkaandorp2 (npm supply-chain operator), [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators), Akira (ransomware-as-a-service operation), [JINX-0164](https://intel.threadlinqs.com/actor/JINX-0164)

Nation-state attribution: Russia, Brazil

Threat categories: VULNERABILITY, MALWARE, PHISHING, SUPPLY_CHAIN, RANSOMWARE, APT

## Severity breakdown

- critical: 5
- high: 9
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 398 (network 111, behavioral 104, file 64, infrastructure 29, package 29, technique 22, malware 19, tool 16, entity 4)
- New detection rules: 126 (100% of the day’s threats covered)

## More editions

- Previous: [2026-05-22](https://intel.threadlinqs.com/debrief/2026-05-22)
- Next: [2026-05-28](https://intel.threadlinqs.com/debrief/2026-05-28)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-05-27
