Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-06-09

Daily Intelligence Briefing — Tuesday, June 9, 2026

6 critical13 high1 medium

On 2026-06-09, Threadlinqs published 20 new threat reports and updated 1, 6 rated critical and 13 high, spanning 168 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 189 new detection rules and 516 extracted indicators.

New threats
201 updated
Critical / high
196 critical · 13 high
ATT&CK techniques
168Observed in the day’s reports
Threat actors
10Named in the reports
Indicators
516Count only · values are Red+
Detection rules
189New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled Vivo / Amazon Fire TV Apps. Research: ~90% of Leaked Malware Source Code Contains Exploitable Software Weaknesses (Vouvoutsis, Patsakis & Casino, arXiv:2606.05945). RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain.

Highlights

  • TL-2026-0722 — RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain
  • TL-2026-0723 — Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations
  • TL-2026-0724 — DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDS
  • TL-2026-0725 — Google Chrome V8 Out-of-Bounds Read/Write Zero-Day CVE-2026-11645 Exploited in the Wild
  • TL-2026-0726 — Lazarus Group npm Brandjacking Campaign — buffer-utilities Multi-Stage Staging Framework (sonatype-2026-003558)

Theme of the day

Active exploitation of critical vulnerabilities in multiple platforms and supply chains threatens various sectors. Unknown actors and Qilin ransomware are exploiting vulnerabilities in UniFi, TeamPCP, and Check Point VPNs.

  • windows
  • credential-theft
  • remote-code-execution
  • active-exploitation
  • espionage

Threats published

21 threat lines in the 2026-06-09 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

168 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

10 named threat actors across the reports.

  • Lazarus Group (financially-motivated subgroup)
  • Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066)
  • DriveSurge
  • Lazarus Group
  • APT28 / Fancy Bear
  • NSO Group
  • Shai-Hulud worm operators (unattributed)
  • TeamPCP
  • TeamPCP (suspected; copycat possible)
  • North Korea-linked operators (EndPoint/Midnight)

Nation-state attribution

  • North Korea
  • Russia
  • Israel
  • North Korea (suspected, low confidence)

Threat categories

  • MALWARE
  • THREAT_INTEL
  • VULNERABILITY
  • SUPPLY_CHAIN
  • ZERO_DAY
  • RANSOMWARE
  • APT

Severity breakdown

  • critical6
  • high13
  • medium1
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

516 indicators of compromise · Red and above. Compare plans
  • behavioral 158
  • file 129
  • network 81
  • technique 33
  • package 27
  • entity 24
  • infrastructure 24
  • malware 20
  • tool 20
189 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans