Summary & highlights
Photo ZIP Phishing Campaign Delivering TonRAT via Node.js Abuse Targeting Hospitality Sector. Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088. Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware Intrusions.
Highlights
- TL-2026-0965 — Photo ZIP Phishing Campaign Delivering TonRAT via Node.js Abuse Targeting Hospitality Sector
- TL-2026-0966 — Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088
- TL-2026-0967 — Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware Intrusions
- TL-2026-0968 — Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
- TL-2026-0970 — Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)
Theme of the day
Unknown actors actively exploited various vulnerabilities, including Cloud Bucket Hijacking and Bluekit PhaaS. Critical vulnerabilities in cloud infrastructure and software posed significant risks.
- data-exfiltration
- lateral-movement
- social-engineering
- anti-analysis
- persistence
Threats published
20 threat lines in the 2026-06-28 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- WeedHack MaaS Campaign: Minecraft Fake Mod Loader with RSA-Signed Blockchain C2 (LoaderClient)CRITICAL
- CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF - Critical Remote Code Execution VulnerabilitiesCRITICAL
- ClickFix Campaign Deploying Potemkin Loader, RMMProject RAT, and EtherRAT - May 2026 Enterprise CompromiseCRITICAL
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data ExfiltrationCRITICAL
- TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)CRITICAL
- Kali365/Octopi365 Device Code Phishing-as-a-Service CampaignCRITICAL
- Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 CountriesCRITICAL
- JadeSnow: Hijacked npm/Go Supply Chain Attack with VSCode Exploitation and Blockchain Dead DropsCRITICAL
- Dropping Elephant Malware Campaign - China-Themed Loader Chain for Initial Access and Payload DeliveryCRITICAL
- Showboat: Sophisticated Linux Post-Exploitation Framework Targeting Middle East TelecommunicationsCRITICAL
- Klue SaaS Integration Platform OAuth Token Compromise – Multi-Organization Salesforce CRM AccessCRITICAL
- Fake AI Tool Attacks on SMBs: 33,300 Cyberattacks Masquerading as ChatGPT, Copilot, Claude in Early 2026CRITICAL
- macOS.Gaslight - Rust Backdoor with AI-Analysis Evasion & Prompt InjectionCRITICAL
- ServiceNow Scripted REST Resource Unauthenticated Access - /api/now/related_list_edit/create (update)CRITICAL
- Miasma: Supply Chain Compromise in RedHat npm Packages - Credential Harvesting Malware (update)CRITICAL
- Photo ZIP Phishing Campaign Delivering TonRAT via Node.js Abuse Targeting Hospitality SectorHIGH
- Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088HIGH
- Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware IntrusionsHIGH
- Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)HIGH
- Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)HIGH
Techniques observed
151 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1005
- T1008
- T1012
- T1014
- T1016
- T1018
- T1020
- T1021
- T1025
- T1027
- T1027.006
- T1030
- T1033
- T1036
- T1037
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1055
- T1056
- T1057
- T1059
- T1068
- T1069
- T1070
- T1071
- T1072
- T1074
- T1078
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.004
- T1090
- T1091
- T1092
- T1098
- T1098.001
- T1098.003
- T1102
- T1104
- T1105
- T1106
- T1110
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1114.001
- T1114.002
- T1115
- T1119
- T1123
- T1125
- T1131
- T1132
- T1133
- T1134
- T1135
- T1136
- T1136.003
- T1140
- T1176
- T1187
- T1189
- T1190
- T1195
- T1199
- T1203
- T1204
- T1204.001
- T1210
- T1212
- T1213
- T1217
- T1218
- T1219
- T1480
- T1482
- T1485
- T1486
- T1489
- T1490
- T1491
- T1496
- T1497
- T1505
- T1518
- T1526
- T1528
- T1529
- T1530
- T1531
- T1537
- T1539
- T1543
- T1546
- T1547
- T1548
- T1550
- T1550.001
- T1552
- T1553
- T1555
- T1556
- T1559
- T1560
- T1561
- T1562
- T1563
- T1564
- T1566
- T1566.002
- T1567
- T1568
- T1569
- T1570
- T1571
- T1572
- T1573
- T1574
- T1578
- T1580
- T1581
- T1583
- T1584
- T1585
- T1587
- T1588
- T1589
- T1589.003
- T1591
- T1591.004
- T1592
- T1593
- T1594
- T1598
- T1598.002
- T1608
- T1614
- T1633
- T1656
- T1657
Threat actors
11 named threat actors across the reports.
Nation-state attribution
- Russia
- China
- India
- North Korea
Threat categories
- PHISHING
- MALWARE
- APT
- SUPPLY_CHAIN
- VULNERABILITY
Severity breakdown
- critical15
- high5
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 156
- behavioral 142
- file 84
- malware 40
- infrastructure 34
- tool 25
- entity 15
- technique 7
- package 3