# Daily Intelligence Briefing — Tuesday, June 16, 2026

> On 2026-06-16, Threadlinqs published 16 new threat reports, 3 rated critical and 11 high, spanning 177 MITRE ATT&CK techniques and 9 named threat actors. Coverage that day added 144 new detection rules and 412 extracted indicators.

- **Edition:** 2026-06-16 (Tuesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-06-16
- **Last updated:** 2026-06-22
- **New threats:** 16
- **Critical / high:** 3 critical, 11 high, 2 medium, 0 low
- **ATT&CK techniques:** 177
- **Threat actors:** 9
- **Indicators (count only):** 412
- **New detection rules (count only):** 144

## Summary & highlights

GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide Malware. Malicious npm Package 'shai_hulululud' (v1.0.48596): Prompt Injection, AI-Safety Triggering, and Token Flooding to Evade AI Malware Scanners (Shai-Hulud Lineage). UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware.

- [TL-2026-0815](https://intel.threadlinqs.com/threat/TL-2026-0815) — UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware
- [TL-2026-0817](https://intel.threadlinqs.com/threat/TL-2026-0817) — ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via Compromised WordPress and EtherHiding Polygon C2
- [TL-2026-0818](https://intel.threadlinqs.com/threat/TL-2026-0818) — Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail
- [TL-2026-0819](https://intel.threadlinqs.com/threat/TL-2026-0819) — DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD, CVE-2023-52271 / CVE-2025-61155 / CVE-2025-1055)
- [TL-2026-0822](https://intel.threadlinqs.com/threat/TL-2026-0822) — Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers

## Theme of the day

Routine activity — no dominant theme emerged.

windows, anti-analysis, credential-theft, masquerading, obfuscation

## Threats published

- [TL-2026-0816](https://intel.threadlinqs.com/threat/TL-2026-0816) — CRITICAL — GlassWASM: TinyGo WebAssembly Malware in Open VSX Extensions Using Solana Blockchain Dead-Drop C2 (GlassWorm Successor)
- [TL-2026-0820](https://intel.threadlinqs.com/threat/TL-2026-0820) — CRITICAL — SimpleHelp RMM OIDC Authentication Bypass (CVE-2026-48558) — Unauthenticated Forged-Token Technician Account Creation and MFA Bypass
- [TL-2026-0823](https://intel.threadlinqs.com/threat/TL-2026-0823) — CRITICAL — FortiSandbox Unauthenticated RCE Chain: JRPC API Path-Traversal Auth Bypass and OS Command Injection (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089)
- [TL-2026-0815](https://intel.threadlinqs.com/threat/TL-2026-0815) — HIGH — UNC1549 (Nimbus Manticore / Smoke Sandstorm / TA455 / Subtle Snail): Iran-Nexus IRGC APT Targeting Aerospace, Defense & Telecom via Fake Recruitment Portals and Azure-Hosted Custom Malware
- [TL-2026-0817](https://intel.threadlinqs.com/threat/TL-2026-0817) — HIGH — ErrTraffic: ClickFix Malware-as-a-Service Distribution Framework Delivering Infostealers and Loaders via Compromised WordPress and EtherHiding Polygon C2
- [TL-2026-0818](https://intel.threadlinqs.com/threat/TL-2026-0818) — HIGH — Tycoon 2FA Adversary-in-the-Middle Phishing-as-a-Service (Storm-1747) — MFA-Bypass Kit Targeting Microsoft 365 & Gmail
- [TL-2026-0819](https://intel.threadlinqs.com/threat/TL-2026-0819) — HIGH — DragonForce 'Backdoor.Turn' Abuses Microsoft Teams TURN Relays to Conceal Ransomware C2 (Go RAT, BYOVD, CVE-2023-52271 / CVE-2025-61155 / CVE-2025-1055)
- [TL-2026-0822](https://intel.threadlinqs.com/threat/TL-2026-0822) — HIGH — Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers
- [TL-2026-0824](https://intel.threadlinqs.com/threat/TL-2026-0824) — HIGH — Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS)
- [TL-2026-0825](https://intel.threadlinqs.com/threat/TL-2026-0825) — HIGH — Pickle in the Middle: Vertex AI Model Upload Hijacking via GCS Bucket Squatting Enables Cross-Tenant RCE (google-cloud-aiplatform v1.139.0/v1.140.0)
- [TL-2026-0826](https://intel.threadlinqs.com/threat/TL-2026-0826) — HIGH — Rokarolla Android Banking Trojan Targets 217 Banking and Cryptocurrency Apps with 137 Remote Commands
- [TL-2026-0827](https://intel.threadlinqs.com/threat/TL-2026-0827) — HIGH — Steam Workshop Abused to Distribute Malware via Wallpaper Engine (DarkKomet, Lumma, Vidar, RenEngine)
- [TL-2026-0828](https://intel.threadlinqs.com/threat/TL-2026-0828) — HIGH — BlueKit Phishing-as-a-Service (PhaaS) Platform Enabling Large-Scale Credential Harvesting, AiTM MFA Bypass, and Account Takeover
- [TL-2026-0859](https://intel.threadlinqs.com/threat/TL-2026-0859) — HIGH — FIFA World Cup 2026 Broadcast API Broken Access Control (Missing Server-Side Authorization) Allowed Live TV Stream Takeover
- [TL-2026-0821](https://intel.threadlinqs.com/threat/TL-2026-0821) — MEDIUM — GhostTree / GhostBranch: Recursive NTFS Directory Junctions Abused to Evade Recursive File Scanners and Hide Malware
- [TL-2026-0829](https://intel.threadlinqs.com/threat/TL-2026-0829) — MEDIUM — Malicious npm Package 'shai_hulululud' (v1.0.48596): Prompt Injection, AI-Safety Triggering, and Token Flooding to Evade AI Malware Scanners (Shai-Hulud Lineage)

## Techniques observed

T1001.002, [T1003.006](https://intel.threadlinqs.com/technique/T1003.006), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.001](https://intel.threadlinqs.com/technique/T1027.001), [T1027.004](https://intel.threadlinqs.com/technique/T1027.004), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1127](https://intel.threadlinqs.com/technique/T1127), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1137](https://intel.threadlinqs.com/technique/T1137), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1195.003](https://intel.threadlinqs.com/technique/T1195.003), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1213.002](https://intel.threadlinqs.com/technique/T1213.002), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1407](https://intel.threadlinqs.com/technique/T1407), T1411, [T1414](https://intel.threadlinqs.com/technique/T1414), [T1417](https://intel.threadlinqs.com/technique/T1417), [T1418](https://intel.threadlinqs.com/technique/T1418), [T1426](https://intel.threadlinqs.com/technique/T1426), [T1437](https://intel.threadlinqs.com/technique/T1437), [T1456](https://intel.threadlinqs.com/technique/T1456), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1513](https://intel.threadlinqs.com/technique/T1513), [T1516](https://intel.threadlinqs.com/technique/T1516), [T1517](https://intel.threadlinqs.com/technique/T1517), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1538](https://intel.threadlinqs.com/technique/T1538), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1541](https://intel.threadlinqs.com/technique/T1541), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558.003](https://intel.threadlinqs.com/technique/T1558.003), T1562, T1562.001, T1562.004, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.004](https://intel.threadlinqs.com/technique/T1564.004), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568.002](https://intel.threadlinqs.com/technique/T1568.002), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.002, [T1580](https://intel.threadlinqs.com/technique/T1580), [T1582](https://intel.threadlinqs.com/technique/T1582), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.002](https://intel.threadlinqs.com/technique/T1608.002), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), T1616, [T1619](https://intel.threadlinqs.com/technique/T1619), [T1620](https://intel.threadlinqs.com/technique/T1620), T1623, [T1626](https://intel.threadlinqs.com/technique/T1626), [T1628](https://intel.threadlinqs.com/technique/T1628), [T1629](https://intel.threadlinqs.com/technique/T1629), [T1636](https://intel.threadlinqs.com/technique/T1636), T1637, [T1646](https://intel.threadlinqs.com/technique/T1646), [T1648](https://intel.threadlinqs.com/technique/T1648), [T1655](https://intel.threadlinqs.com/technique/T1655), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660)

## Threat actors

Shai-Hulud campaign operators (unattributed), [UNC1549](https://intel.threadlinqs.com/actor/UNC1549), [LenAI](https://intel.threadlinqs.com/actor/LenAI), [Storm-1747](https://intel.threadlinqs.com/actor/Storm-1747), [DragonForce](https://intel.threadlinqs.com/actor/DragonForce), Storm-2372 (Russia-aligned); also APT29, UTA0304, UTA0307, UNK_AcademicFlare, BlueKit operators (PhaaS developers/resellers), BobDaHacker (independent security researcher; responsible disclosure), GlassWorm developer (zaitoona43)

Nation-state attribution: Iran, Russia

Threat categories: THREAT_INTEL, SUPPLY_CHAIN, APT, MALWARE, PHISHING, VULNERABILITY

## Severity breakdown

- critical: 3
- high: 11
- medium: 2
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 412 (behavioral 119, network 107, file 95, infrastructure 31, malware 21, tool 16, entity 12, technique 6, package 5)
- New detection rules: 144 (100% of the day’s threats covered)

## More editions

- Previous: [2026-06-15](https://intel.threadlinqs.com/debrief/2026-06-15)
- Next: [2026-06-18](https://intel.threadlinqs.com/debrief/2026-06-18)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-06-16
