# Daily Intelligence Briefing — Tuesday, June 9, 2026

> On 2026-06-09, Threadlinqs published 20 new threat reports and updated 1, 6 rated critical and 13 high, spanning 168 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 189 new detection rules and 516 extracted indicators.

- **Edition:** 2026-06-09 (Tuesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-06-09
- **Last updated:** 2026-06-15
- **New threats:** 20 (1 updated)
- **Critical / high:** 6 critical, 13 high, 1 medium, 0 low
- **ATT&CK techniques:** 168
- **Threat actors:** 10
- **Indicators (count only):** 516
- **New detection rules (count only):** 189

## Summary & highlights

Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled Vivo / Amazon Fire TV Apps. Research: ~90% of Leaked Malware Source Code Contains Exploitable Software Weaknesses (Vouvoutsis, Patsakis & Casino, arXiv:2606.05945). RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain.

- [TL-2026-0722](https://intel.threadlinqs.com/threat/TL-2026-0722) — RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain
- [TL-2026-0723](https://intel.threadlinqs.com/threat/TL-2026-0723) — Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations
- [TL-2026-0724](https://intel.threadlinqs.com/threat/TL-2026-0724) — DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDS
- [TL-2026-0725](https://intel.threadlinqs.com/threat/TL-2026-0725) — Google Chrome V8 Out-of-Bounds Read/Write Zero-Day CVE-2026-11645 Exploited in the Wild
- [TL-2026-0726](https://intel.threadlinqs.com/threat/TL-2026-0726) — Lazarus Group npm Brandjacking Campaign — buffer-utilities Multi-Stage Staging Framework (sonatype-2026-003558)

## Theme of the day

Active exploitation of critical vulnerabilities in multiple platforms and supply chains threatens various sectors. Unknown actors and Qilin ransomware are exploiting vulnerabilities in UniFi, TeamPCP, and Check Point VPNs.

windows, credential-theft, remote-code-execution, active-exploitation, espionage

## Threats published

- [TL-2026-0730](https://intel.threadlinqs.com/threat/TL-2026-0730) — CRITICAL — CVE-2026-42271: LiteLLM AI Gateway OS Command Injection via MCP Test Endpoints, Chained to Unauthenticated RCE with CVE-2026-48710 (CISA KEV, Active Exploitation)
- [TL-2026-0734](https://intel.threadlinqs.com/threat/TL-2026-0734) — CRITICAL — Shai-Hulud 'Hades' Campaign — Trojanized PyPI Packages Auto-Execute Bun Credential Stealer via Python Wheel Startup Hooks (*-setup.pth)
- [TL-2026-0735](https://intel.threadlinqs.com/threat/TL-2026-0735) — CRITICAL — Google Chrome V8 Zero-Day CVE-2026-11645 Out-of-Bounds Read/Write Exploited in the Wild
- [TL-2026-0736](https://intel.threadlinqs.com/threat/TL-2026-0736) — CRITICAL — Miasma Supply Chain Attack Toolkit Open-Sourced on GitHub (Shai-Hulud / Mini Shai-Hulud Variant)
- [TL-2026-0738](https://intel.threadlinqs.com/threat/TL-2026-0738) — CRITICAL — CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710 (Starlette BadHost) for Unauthenticated RCE
- [TL-2026-0742](https://intel.threadlinqs.com/threat/TL-2026-0742) — CRITICAL — EndPoint (Midnight) Ransomware — Babuk-derived double-extortion targeting Windows, ESXi, and NAS
- [TL-2026-0722](https://intel.threadlinqs.com/threat/TL-2026-0722) — HIGH — RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain
- [TL-2026-0723](https://intel.threadlinqs.com/threat/TL-2026-0723) — HIGH — Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations
- [TL-2026-0724](https://intel.threadlinqs.com/threat/TL-2026-0724) — HIGH — DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDS
- [TL-2026-0725](https://intel.threadlinqs.com/threat/TL-2026-0725) — HIGH — Google Chrome V8 Out-of-Bounds Read/Write Zero-Day CVE-2026-11645 Exploited in the Wild
- [TL-2026-0726](https://intel.threadlinqs.com/threat/TL-2026-0726) — HIGH — Lazarus Group npm Brandjacking Campaign — buffer-utilities Multi-Stage Staging Framework (sonatype-2026-003558)
- [TL-2026-0727](https://intel.threadlinqs.com/threat/TL-2026-0727) — HIGH — APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509)
- [TL-2026-0728](https://intel.threadlinqs.com/threat/TL-2026-0728) — HIGH — NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)
- [TL-2026-0731](https://intel.threadlinqs.com/threat/TL-2026-0731) — HIGH — CVE-2026-23111: Linux Kernel nf_tables Use-After-Free Enables Local Privilege Escalation and Container Escape
- [TL-2026-0732](https://intel.threadlinqs.com/threat/TL-2026-0732) — HIGH — Microsoft June 2026 Patch Tuesday — 198+ CVEs Including CVE-2026-49160 (HTTP.sys 'HTTP/2 Bomb' DoS), CVE-2026-50507 (BitLocker 'YellowKey' Bypass) and CVE-2026-45586 (Collaborative Translation Framework EoP)
- [TL-2026-0733](https://intel.threadlinqs.com/threat/TL-2026-0733) — HIGH — Miasma / Shai-Hulud Supply-Chain Campaign Pushes Password-Stealing Malware via Compromised Microsoft GitHub Repos (durabletask PyPI 1.4.1-1.4.3)
- [TL-2026-0740](https://intel.threadlinqs.com/threat/TL-2026-0740) — HIGH — CVE-2026-11645: Actively Exploited V8 Out-of-Bounds Memory Access Zero-Day in Google Chrome
- [TL-2026-0741](https://intel.threadlinqs.com/threat/TL-2026-0741) — HIGH — NFCShare Android Banking Malware Steals EMV Card Data and PINs via Weaponized European Banking Apps (com.modol.nap)
- [TL-2026-0744](https://intel.threadlinqs.com/threat/TL-2026-0744) — HIGH — APT Spear-Phishing Campaign Targeting South Korean Entities (April 2026) — LNK/PowerShell Loaders, AutoIt, XenoRAT, Infostealers/Keyloggers/Backdoors (update)
- [TL-2026-0737](https://intel.threadlinqs.com/threat/TL-2026-0737) — MEDIUM — Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled Vivo / Amazon Fire TV Apps
- [TL-2026-0739](https://intel.threadlinqs.com/threat/TL-2026-0739) — INFO — Research: ~90% of Leaked Malware Source Code Contains Exploitable Software Weaknesses (Vouvoutsis, Patsakis & Casino, arXiv:2606.05945)

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1005](https://intel.threadlinqs.com/technique/T1005), T1006, [T1008](https://intel.threadlinqs.com/technique/T1008), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1025](https://intel.threadlinqs.com/technique/T1025), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1137](https://intel.threadlinqs.com/technique/T1137), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1200](https://intel.threadlinqs.com/technique/T1200), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1218](https://intel.threadlinqs.com/technique/T1218), T1406.001, T1406.002, [T1407](https://intel.threadlinqs.com/technique/T1407), [T1409](https://intel.threadlinqs.com/technique/T1409), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1422](https://intel.threadlinqs.com/technique/T1422), [T1426](https://intel.threadlinqs.com/technique/T1426), [T1429](https://intel.threadlinqs.com/technique/T1429), [T1430](https://intel.threadlinqs.com/technique/T1430), [T1437](https://intel.threadlinqs.com/technique/T1437), T1437.001, [T1456](https://intel.threadlinqs.com/technique/T1456), T1474.002, T1474.003, [T1480](https://intel.threadlinqs.com/technique/T1480), [T1480.001](https://intel.threadlinqs.com/technique/T1480.001), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1516](https://intel.threadlinqs.com/technique/T1516), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1541](https://intel.threadlinqs.com/technique/T1541), [T1542](https://intel.threadlinqs.com/technique/T1542), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1562, T1562.001, T1562.006, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1575](https://intel.threadlinqs.com/technique/T1575), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.004](https://intel.threadlinqs.com/technique/T1592.004), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1598](https://intel.threadlinqs.com/technique/T1598), T1603, [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.004](https://intel.threadlinqs.com/technique/T1608.004), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1624.001](https://intel.threadlinqs.com/technique/T1624.001), [T1628](https://intel.threadlinqs.com/technique/T1628), T1628.001, T1628.002, [T1630](https://intel.threadlinqs.com/technique/T1630), T1633.001, [T1636](https://intel.threadlinqs.com/technique/T1636), T1643, [T1646](https://intel.threadlinqs.com/technique/T1646), T1655.001, T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), T1658, [T1660](https://intel.threadlinqs.com/technique/T1660)

## Threat actors

Lazarus Group (financially-motivated subgroup), Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066), [DriveSurge](https://intel.threadlinqs.com/actor/DriveSurge), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group), APT28 / Fancy Bear, [NSO Group](https://intel.threadlinqs.com/actor/NSO%20Group), Shai-Hulud worm operators (unattributed), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), TeamPCP (suspected; copycat possible), North Korea-linked operators (EndPoint/Midnight)

Nation-state attribution: North Korea, Russia, Israel, North Korea (suspected, low confidence)

Threat categories: MALWARE, THREAT_INTEL, VULNERABILITY, SUPPLY_CHAIN, ZERO_DAY, RANSOMWARE, APT

## Severity breakdown

- critical: 6
- high: 13
- medium: 1
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 516 (behavioral 158, file 129, network 81, technique 33, package 27, entity 24, infrastructure 24, malware 20, tool 20)
- New detection rules: 189 (100% of the day’s threats covered)

## More editions

- Previous: [2026-06-02](https://intel.threadlinqs.com/debrief/2026-06-02)
- Next: [2026-06-10](https://intel.threadlinqs.com/debrief/2026-06-10)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-06-09
