Threadlinqs IntelligenceStart free

Daily debrief · Thursday2026-05-28

Daily Intelligence Briefing — Thursday, May 28, 2026

2 critical9 high

On 2026-05-28, Threadlinqs published 11 new threat reports, 2 rated critical and 9 high, spanning 140 MITRE ATT&CK techniques and 3 named threat actors. Coverage that day added 99 new detection rules and 248 extracted indicators.

New threats
1111 threat lines
Critical / high
112 critical · 9 high
ATT&CK techniques
140Observed in the day’s reports
Threat actors
3Named in the reports
Indicators
248Count only · values are Red+
Detection rules
99New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026). Fake ChatGPT Download Site openew[.]app — Dual-Platform Delivery: Windows Electron/Inno Setup PowerShell-stdin Loader & macOS Atomic Stealer (AMOS) With Ledger/Trezor Wallet Replacement. Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities.

Highlights

  • TL-2026-0612 — Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)
  • TL-2026-0614 — Fake ChatGPT Download Site openew[.]app — Dual-Platform Delivery: Windows Electron/Inno Setup PowerShell-stdin Loader & macOS Atomic Stealer (AMOS) With Ledger/Trezor Wallet Replacement
  • TL-2026-0616 — Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities
  • TL-2026-0617 — GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) Bulletproof Hosting Power Obfuscated JavaScript Backdoor Spam Campaign Targeting Energy, Automotive, FMCG, and Government Finance Across Ukraine, Russia, Poland, Germany, and Transnistria
  • TL-2026-0618 — CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)

Theme of the day

Critical vulnerabilities and phishing campaigns targeted Windows and Linux systems, with a focus on credential theft and code injection attacks. Exploits and malware attacks were actively used to compromise developer tooling.

  • windows
  • credential-theft
  • cwe-94
  • linux
  • developer-tooling

Threats published

11 threat lines in the 2026-05-28 debrief, most severe first. Each links to its full profile.

Techniques observed

140 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

3 named threat actors across the reports.

  • Silent Ransom Group (SRG)
  • PhishU Framework operators (technique disclosed by Curtis Brazzell, PhishU, LLC)
  • GreyVibe

Nation-state attribution

  • Russia

Threat categories

  • RANSOMWARE
  • MALWARE
  • VULNERABILITY
  • CLOUD
  • PHISHING

Severity breakdown

  • critical2
  • high9
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

248 indicators of compromise · Red and above. Compare plans
  • behavioral 75
  • network 53
  • file 42
  • tool 23
  • infrastructure 17
  • technique 14
  • package 10
  • entity 8
  • malware 6
99 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans