Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-06-16

Daily Intelligence Briefing — Tuesday, June 16, 2026

3 critical11 high2 medium

On 2026-06-16, Threadlinqs published 16 new threat reports, 3 rated critical and 11 high, spanning 177 MITRE ATT&CK techniques and 9 named threat actors. Coverage that day added 144 new detection rules and 412 extracted indicators.

New threats
1616 threat lines
Critical / high
143 critical · 11 high
ATT&CK techniques
177Observed in the day’s reports
Threat actors
9Named in the reports
Indicators
412Count only · values are Red+
Detection rules
144New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide Malware. Malicious npm Package 'shai_hulululud' (v1.0.48596): Prompt Injection, AI-Safety Triggering, and Token Flooding to Evade AI Malware Scanners (Shai-Hulud Lineage). UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware.

Highlights

  • TL-2026-0815 — UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware
  • TL-2026-0817 — ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via Compromised WordPress and EtherHiding Polygon C2
  • TL-2026-0818 — Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail
  • TL-2026-0819 — DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD, CVE-2023-52271 / CVE-2025-61155 / CVE-2025-1055)
  • TL-2026-0822 — Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers

Theme of the day

Routine activity — no dominant theme emerged.

  • windows
  • anti-analysis
  • credential-theft
  • masquerading
  • obfuscation

Threats published

16 threat lines in the 2026-06-16 debrief, most severe first. Each links to its full profile.

Techniques observed

177 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

9 named threat actors across the reports.

  • Shai-Hulud campaign operators (unattributed)
  • UNC1549
  • LenAI
  • Storm-1747
  • DragonForce
  • Storm-2372 (Russia-aligned); also APT29, UTA0304, UTA0307, UNK_AcademicFlare
  • BlueKit operators (PhaaS developers/resellers)
  • BobDaHacker (independent security researcher; responsible disclosure)
  • GlassWorm developer (zaitoona43)

Nation-state attribution

  • Iran
  • Russia

Threat categories

  • THREAT_INTEL
  • SUPPLY_CHAIN
  • APT
  • MALWARE
  • PHISHING
  • VULNERABILITY

Severity breakdown

  • critical3
  • high11
  • medium2
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

412 indicators of compromise · Red and above. Compare plans
  • behavioral 119
  • network 107
  • file 95
  • infrastructure 31
  • malware 21
  • tool 16
  • entity 12
  • technique 6
  • package 5
144 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans