Summary & highlights
Houthi/Yemen-Based Disinformation & Influence Campaign Targeting Israel and the Gulf States (ClearSky). Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series). AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855).
Highlights
- TL-2026-0743 — Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)
- TL-2026-0745 — AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)
- TL-2026-0747 — Vidar Stealer 2.0 (Loadbaks) Distributed via Fake Game Cheats on GitHub and Reddit
- TL-2026-0751 — Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group)
- TL-2026-0752 — P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring)
Theme of the day
Activity centered on 0-day, actively-exploited, ahnlab-asec.
- windows
- defense-evasion
- masquerading
- credential-theft
- espionage
Threats published
29 threat lines in the 2026-06-10 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- FamousSparrow APT Targets Azerbaijani Oil & Gas Industry via Exchange ProxyShell/ProxyNotShell (Deed RAT, Terndoor, Mofu Loader)CRITICAL
- CVE-2026-9082: Highly Critical Anonymous SQL Injection in Drupal Core PostgreSQL Entity Query Driver (SA-CORE-2026-004)CRITICAL
- Seedworm (MuddyWater) Iranian MOIS APT Deploys Dindoor and Fakeset Backdoors Against U.S. Bank, Airport, and Defense Software CompanyCRITICAL
- CVE-2026-44748: XML Signature Wrapping in SAP NetWeaver AS ABAP SAML Authentication (CVSS 9.9)CRITICAL
- Windows Defender 0-Day Local Privilege Escalation "RoguePlanet" (Nightmare Eclipse Defender Exploit Series)HIGH
- AhnLab ASEC April 2026 APT Group Trend Report: State-Sponsored Espionage Campaigns (CVE-2026-32202, CVE-2025-20333/20362, CVE-2021-26855)HIGH
- Vidar Stealer 2.0 (Loadbaks) Distributed via Fake Game Cheats on GitHub and RedditHIGH
- Pegasus Mercenary Spyware Used for State Surveillance of Azerbaijani Journalists, Activists, and Human Rights Defenders (NSO Group)HIGH
- P2P Botnets in the Wild: Pink, Hajime, Mozi, FritzFrog, and Panchan — Decentralized C2 Landscape (360 Netlab Continuous Monitoring)HIGH
- PureCrypter — C# Malware-as-a-Service Loader Distributing 10+ Malware FamiliesHIGH
- Fodcha — Cross-Architecture DDoS Botnet Spreading via N-Day Exploits (CVE-2021-22205, CVE-2021-35394) and Telnet/SSH Brute-Force, Later Adding Ransom DDoSHIGH
- Targeted Espionage Campaign Against a Global Stock Exchange Executive via Incremental Outlook OST Mailbox Theft and Living-off-the-Land Cloud ExfiltrationHIGH
- Harvester APT Deploys New Linux Variant of GoGra (Backdoor.Gogra) Backdoor Abusing Microsoft Graph API and Outlook Mailboxes for Command-and-ControlHIGH
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass ExploitationHIGH
- CVE-2024-43451 Windows NTLM Hash Disclosure Zero-Day Exploited In-the-Wild Against Ukrainian Entities (UAC-0194 / SparkRAT)HIGH
- Iranian "Dream Job" Campaign (TA455 / Charming Kitten) — SnailResin Loader & SlugResin Backdoor Targeting Aerospace, Aviation & DefenseHIGH
- DarkCloud Infostealer — Commercial VB6 Credential-Harvesting Malware (A310Logger/BluStealer Successor)HIGH
- CVE-2026-5027: Path Traversal Arbitrary File Write in Langflow AI Dev Platform (upload_user_file) Exploited in the Wild for Unauthenticated RCEHIGH
- Capita Black Basta Ransomware Incident (March 2023) — Record £14M UK ICO Fine for 6M+ Affected IndividualsHIGH
- DBatLoader (ModiLoader/NatsoLoader): Delphi-Compiled Windows Loader Using Layered Anti-Analysis, Mock-Trusted-Directory UAC Bypass, and DLL Side-Loading to Deliver Remcos, FormBook, NetWire and WarzoneHIGH
- DeceptionAds: Fake CAPTCHA Malvertising Campaign Abusing the Monetag Ad Network to Distribute Lumma Infostealer via ClickFixHIGH
- MyFlaw: Cross-Platform RCE in Opera and Opera GX Browsers via the Built-in 'Opera Touch Background' Extension (My Flow Feature)HIGH
- DPRK (Kimsuky) Multi-Stage LNK Phishing Campaign Delivering XenoRAT via GitHub-based C2 Targeting South KoreaHIGH
- Agent Tesla Multi-Stage Phishing Campaign with Process Hollowing of Aspnet_compiler.exe and SMTP Credential ExfiltrationHIGH
- LummaStealer (V34XV4) Distributed via Fake Game-Update Comments on itch.io Linking to Patreon-Hosted nexe LoadersHIGH
- BlockBlasters Steam Game Supply-Chain Compromise Delivers StealC Infostealer and StimBlaster Backdoor via Malicious Patch (Build 19799326)HIGH
- Iranian State-Aligned Global Cyber Operations Surge Amid Iran Conflict (MuddyWater/Seedworm Dindoor & Fakeset Campaign) (update)HIGH
- Houthi/Yemen-Based Disinformation & Influence Campaign Targeting Israel and the Gulf States (ClearSky)MEDIUM
- EvilNominatus Ransomware — BAT-delivered .NET (MSIL) Filecoder attributed to an Iranian developer (update)LOW
Techniques observed
207 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1003.002
- T1005
- T1010
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1027
- T1027.002
- T1027.003
- T1033
- T1036
- T1036.003
- T1036.005
- T1037
- T1041
- T1046
- T1048
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.012
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.007
- T1068
- T1069
- T1070
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1074
- T1074.001
- T1078
- T1078.002
- T1078.004
- T1082
- T1083
- T1087
- T1090
- T1090.001
- T1090.003
- T1098
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1112
- T1113
- T1114
- T1114.001
- T1115
- T1124
- T1132
- T1133
- T1134
- T1134.003
- T1137
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1211
- T1212
- T1213
- T1218
- T1218.005
- T1218.009
- T1219
- T1398
- T1404
- T1406
- T1407
- T1409
- T1417
- T1418
- T1426
- T1429
- T1430
- T1437
- T1456
- T1480
- T1481
- T1482
- T1485
- T1486
- T1490
- T1496
- T1497
- T1497.003
- T1498
- T1499
- T1505
- T1505.003
- T1512
- T1513
- T1517
- T1518
- T1518.001
- T1528
- T1531
- T1532
- T1539
- T1542
- T1542.003
- T1543
- T1543.002
- T1543.003
- T1546.015
- T1547
- T1547.001
- T1547.006
- T1548
- T1548.002
- T1550
- T1550.001
- T1550.002
- T1550.004
- T1552
- T1552.001
- T1553
- T1555
- T1555.003
- T1555.004
- T1555.005
- T1559.001
- T1560
- T1562
- T1562.001
- T1563
- T1564
- T1565
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1568
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.002
- T1575
- T1583
- T1583.001
- T1583.007
- T1584
- T1585
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.005
- T1589
- T1590
- T1591
- T1592
- T1593
- T1595
- T1595.002
- T1598
- T1606
- T1606.002
- T1608
- T1608.004
- T1614
- T1620
- T1622
- T1628
- T1630
- T1636
- T1646
- T1656
- T1657
- T1658
- T1660
Threat actors
16 named threat actors across the reports.
- Houthi-aligned Yemeni disinformation operators (Ansar Allah)
- Nightmare Eclipse
- Vidar 2.0 MaaS operators (developer alias 'Loadbaks')
- NSO Group (Pegasus) operated by Government of Azerbaijan customer
- Fodcha operator (unattributed)
- Harvester
- Qilin / The Gentlemen / LockBit 5.0 / Cl0p (FIN11)
- UAC-0194
- TA455 (Charming Kitten subgroup)
- Darkcloud Coder
- Black Basta
- Vane Viper
- Kimsuky
- FamousSparrow
- Seedworm (MuddyWater)
- MuddyWater / Seedworm
Nation-state attribution
- Yemen
- Azerbaijan
- Russia
- Iran
- North Korea
- China
Threat categories
- THREAT_INTEL
- VULNERABILITY
- APT
- MALWARE
- RANSOMWARE
- SUPPLY_CHAIN
Severity breakdown
- critical4
- high23
- medium1
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 260
- network 226
- behavioral 155
- malware 53
- tool 40
- infrastructure 28
- entity 17
- technique 12
- package 2