Summary & highlights
GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide Malware. Malicious npm Package 'shai_hulululud' (v1.0.48596): Prompt Injection, AI-Safety Triggering, and Token Flooding to Evade AI Malware Scanners (Shai-Hulud Lineage). UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware.
Highlights
- TL-2026-0815 — UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware
- TL-2026-0817 — ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via Compromised WordPress and EtherHiding Polygon C2
- TL-2026-0818 — Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail
- TL-2026-0819 — DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD, CVE-2023-52271 / CVE-2025-61155 / CVE-2025-1055)
- TL-2026-0822 — Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers
Theme of the day
Routine activity — no dominant theme emerged.
- windows
- anti-analysis
- credential-theft
- masquerading
- obfuscation
Threats published
16 threat lines in the 2026-06-16 debrief, most severe first. Each links to its full profile.
- GlassWASM: TinyGo WebAssembly Malware in Open VSX Extensions Using Solana Blockchain Dead-Drop C2 (GlassWorm Successor)CRITICAL
- SimpleHelp RMM OIDC Authentication Bypass (CVE-2026-48558) — Unauthenticated Forged-Token Technician Account Creation and MFA BypassCRITICAL
- FortiSandbox Unauthenticated RCE Chain: JRPC API Path-Traversal Auth Bypass and OS Command Injection (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089)CRITICAL
- UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom MalwareHIGH
- ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via Compromised WordPress and EtherHiding Polygon C2HIGH
- Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & GmailHIGH
- DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD, CVE-2023-52271 / CVE-2025-61155 / CVE-2025-1055)HIGH
- Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams InstallersHIGH
- Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS)HIGH
- Pickle in the Middle: Vertex AI Model Upload Hijacking via GCS Bucket Squatting Enables Cross-Tenant RCE (google-cloud-aiplatform v1.139.0/v1.140.0)HIGH
- Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote CommandsHIGH
- Steam Workshop Abused to Distribute Malware via Wallpaper Engine (DarkKomet, Lumma, Vidar, RenEngine)HIGH
- BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account TakeoverHIGH
- FIFA World Cup 2026 Broadcast API Broken Access Control (Missing Server-Side Authorization) Allowed Live TV Stream TakeoverHIGH
- GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide MalwareMEDIUM
- Malicious npm Package 'shai_hulululud' (v1.0.48596): Prompt Injection, AI-Safety Triggering, and Token Flooding to Evade AI Malware Scanners (Shai-Hulud Lineage)MEDIUM
Techniques observed
177 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001.002
- T1003.006
- T1005
- T1007
- T1014
- T1016
- T1018
- T1021
- T1021.001
- T1027
- T1027.001
- T1027.004
- T1027.010
- T1036
- T1036.005
- T1041
- T1046
- T1053.005
- T1055
- T1056
- T1056.003
- T1059
- T1059.001
- T1059.003
- T1059.006
- T1059.007
- T1068
- T1070
- T1070.001
- T1070.004
- T1071
- T1071.001
- T1078
- T1078.003
- T1082
- T1083
- T1087
- T1087.002
- T1090
- T1090.002
- T1095
- T1098
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.003
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1115
- T1127
- T1132
- T1132.001
- T1136
- T1136.001
- T1137
- T1140
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.002
- T1195.003
- T1199
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1211
- T1212
- T1213
- T1213.002
- T1218.007
- T1219
- T1407
- T1411
- T1414
- T1417
- T1418
- T1426
- T1437
- T1456
- T1480
- T1486
- T1489
- T1491
- T1496
- T1497
- T1499
- T1505
- T1505.003
- T1513
- T1516
- T1517
- T1518
- T1526
- T1528
- T1530
- T1537
- T1538
- T1539
- T1541
- T1543.003
- T1546
- T1547.001
- T1548
- T1550
- T1552
- T1553.002
- T1555
- T1555.003
- T1556
- T1557
- T1558.003
- T1562
- T1562.001
- T1562.004
- T1564
- T1564.004
- T1565
- T1566
- T1566.001
- T1566.002
- T1567
- T1568.002
- T1569.002
- T1572
- T1573
- T1573.001
- T1573.002
- T1574.001
- T1574.002
- T1580
- T1582
- T1583
- T1583.001
- T1583.006
- T1584
- T1584.006
- T1585
- T1586
- T1587
- T1587.001
- T1588
- T1588.002
- T1588.003
- T1589
- T1590
- T1595
- T1596
- T1598
- T1606
- T1608
- T1608.001
- T1608.002
- T1608.006
- T1616
- T1619
- T1620
- T1623
- T1626
- T1628
- T1629
- T1636
- T1637
- T1646
- T1648
- T1655
- T1656
- T1657
- T1660
Threat actors
9 named threat actors across the reports.
- Shai-Hulud campaign operators (unattributed)
- UNC1549
- LenAI
- Storm-1747
- DragonForce
- Storm-2372 (Russia-aligned); also APT29, UTA0304, UTA0307, UNK_AcademicFlare
- BlueKit operators (PhaaS developers/resellers)
- BobDaHacker (independent security researcher; responsible disclosure)
- GlassWorm developer (zaitoona43)
Nation-state attribution
- Iran
- Russia
Threat categories
- THREAT_INTEL
- SUPPLY_CHAIN
- APT
- MALWARE
- PHISHING
- VULNERABILITY
Severity breakdown
- critical3
- high11
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 119
- network 107
- file 95
- infrastructure 31
- malware 21
- tool 16
- entity 12
- technique 6
- package 5