# Daily Intelligence Briefing — Thursday, May 28, 2026

> On 2026-05-28, Threadlinqs published 11 new threat reports, 2 rated critical and 9 high, spanning 140 MITRE ATT&CK techniques and 3 named threat actors. Coverage that day added 99 new detection rules and 248 extracted indicators.

- **Edition:** 2026-05-28 (Thursday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-05-28
- **Last updated:** 2026-06-03
- **New threats:** 11
- **Critical / high:** 2 critical, 9 high, 0 medium, 0 low
- **ATT&CK techniques:** 140
- **Threat actors:** 3
- **Indicators (count only):** 248
- **New detection rules (count only):** 99

## Summary & highlights

Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026). Fake ChatGPT Download Site openew\[.\]app — Dual-Platform Delivery: Windows Electron/Inno Setup PowerShell-stdin Loader & macOS Atomic Stealer (AMOS) With Ledger/Trezor Wallet Replacement. Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities.

- [TL-2026-0612](https://intel.threadlinqs.com/threat/TL-2026-0612) — Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)
- [TL-2026-0614](https://intel.threadlinqs.com/threat/TL-2026-0614) — Fake ChatGPT Download Site openew\[.\]app — Dual-Platform Delivery: Windows Electron/Inno Setup PowerShell-stdin Loader & macOS Atomic Stealer (AMOS) With Ledger/Trezor Wallet Replacement
- [TL-2026-0616](https://intel.threadlinqs.com/threat/TL-2026-0616) — Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities
- [TL-2026-0617](https://intel.threadlinqs.com/threat/TL-2026-0617) — GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) Bulletproof Hosting Power Obfuscated JavaScript Backdoor Spam Campaign Targeting Energy, Automotive, FMCG, and Government Finance Across Ukraine, Russia, Poland, Germany, and Transnistria
- [TL-2026-0618](https://intel.threadlinqs.com/threat/TL-2026-0618) — CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)

## Theme of the day

Critical vulnerabilities and phishing campaigns targeted Windows and Linux systems, with a focus on credential theft and code injection attacks. Exploits and malware attacks were actively used to compromise developer tooling.

windows, credential-theft, cwe-94, linux, developer-tooling

## Threats published

- [TL-2026-0613](https://intel.threadlinqs.com/threat/TL-2026-0613) — CRITICAL — Notepad++ v8.9.6 — Critical Arbitrary Code Execution via config.xml commandLineInterpreter and shortcuts.xml (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)
- [TL-2026-0615](https://intel.threadlinqs.com/threat/TL-2026-0615) — CRITICAL — Gogs Authenticated RCE via Argument Injection in git rebase --exec (Unpatched, CVSSv4 9.4, GHSA-qf6p-p7ww-cwr9)
- [TL-2026-0612](https://intel.threadlinqs.com/threat/TL-2026-0612) — HIGH — Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)
- [TL-2026-0614](https://intel.threadlinqs.com/threat/TL-2026-0614) — HIGH — Fake ChatGPT Download Site openew\[.\]app — Dual-Platform Delivery: Windows Electron/Inno Setup PowerShell-stdin Loader & macOS Atomic Stealer (AMOS) With Ledger/Trezor Wallet Replacement
- [TL-2026-0616](https://intel.threadlinqs.com/threat/TL-2026-0616) — HIGH — Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities
- [TL-2026-0617](https://intel.threadlinqs.com/threat/TL-2026-0617) — HIGH — GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) Bulletproof Hosting Power Obfuscated JavaScript Backdoor Spam Campaign Targeting Energy, Automotive, FMCG, and Government Finance Across Ukraine, Russia, Poland, Germany, and Transnistria
- [TL-2026-0618](https://intel.threadlinqs.com/threat/TL-2026-0618) — HIGH — CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)
- [TL-2026-0619](https://intel.threadlinqs.com/threat/TL-2026-0619) — HIGH — First AI-Agent-Driven Cloud Intrusion — Marimo CVE-2026-39987 RCE → AWS Secrets Manager → SSH Bastion → Internal PostgreSQL Exfiltration (Sysdig TRT, 2026-05-10)
- [TL-2026-0620](https://intel.threadlinqs.com/threat/TL-2026-0620) — HIGH — VaultJacking — Google Password Manager Vault Theft via Single Captured 6-Digit PIN (PhishU Framework)
- [TL-2026-0621](https://intel.threadlinqs.com/threat/TL-2026-0621) — HIGH — mouse5212-super-formatter — AI-Generated Malicious npm Package Exfiltrating Anthropic Claude AI /mnt/user-data Sandbox to Attacker GitHub Repository (Malware-Slop Campaign)
- [TL-2026-0622](https://intel.threadlinqs.com/threat/TL-2026-0622) — HIGH — GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs & FallSpy Android Spyware (WithSecure)

## Techniques observed

[T1005](https://intel.threadlinqs.com/technique/T1005), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.003](https://intel.threadlinqs.com/technique/T1036.003), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1039](https://intel.threadlinqs.com/technique/T1039), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1048](https://intel.threadlinqs.com/technique/T1048), T1048.002, T1052.001, [T1053](https://intel.threadlinqs.com/technique/T1053), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), T1070.008, [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), T1074.002, [T1078](https://intel.threadlinqs.com/technique/T1078), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.001](https://intel.threadlinqs.com/technique/T1098.001), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1200](https://intel.threadlinqs.com/technique/T1200), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1430](https://intel.threadlinqs.com/technique/T1430), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1533](https://intel.threadlinqs.com/technique/T1533), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), T1552.003, [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), T1555.006, [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), T1562, T1562.001, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.005](https://intel.threadlinqs.com/technique/T1583.005), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.003](https://intel.threadlinqs.com/technique/T1589.003), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), T1606.001, [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1636](https://intel.threadlinqs.com/technique/T1636), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657)

## Threat actors

Silent Ransom Group (SRG), PhishU Framework operators (technique disclosed by Curtis Brazzell, PhishU, LLC), [GreyVibe](https://intel.threadlinqs.com/actor/GreyVibe)

Nation-state attribution: Russia

Threat categories: RANSOMWARE, MALWARE, VULNERABILITY, CLOUD, PHISHING

## Severity breakdown

- critical: 2
- high: 9
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 248 (behavioral 75, network 53, file 42, tool 23, infrastructure 17, technique 14, package 10, entity 8, malware 6)
- New detection rules: 99 (100% of the day’s threats covered)

## More editions

- Previous: [2026-05-27](https://intel.threadlinqs.com/debrief/2026-05-27)
- Next: [2026-06-01](https://intel.threadlinqs.com/debrief/2026-06-01)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-05-28
