Threadlinqs IntelligenceStart free

Daily debrief · Sunday2026-06-28

Daily Intelligence Briefing — Sunday, June 28, 2026

15 critical5 high

On 2026-06-28, Threadlinqs published 18 new threat reports and updated 2, 15 rated critical and 5 high, spanning 151 MITRE ATT&CK techniques and 11 named threat actors. Coverage that day added 180 new detection rules and 506 extracted indicators.

New threats
182 updated
Critical / high
2015 critical · 5 high
ATT&CK techniques
151Observed in the day’s reports
Threat actors
11Named in the reports
Indicators
506Count only · values are Red+
Detection rules
180New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Photo ZIP Phishing Campaign Delivering TonRAT via Node.js Abuse Targeting Hospitality Sector. Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088. Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware Intrusions.

Highlights

  • TL-2026-0965 — Photo ZIP Phishing Campaign Delivering TonRAT via Node.js Abuse Targeting Hospitality Sector
  • TL-2026-0966 — Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088
  • TL-2026-0967 — Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware Intrusions
  • TL-2026-0968 — Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
  • TL-2026-0970 — Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)

Theme of the day

Unknown actors actively exploited various vulnerabilities, including Cloud Bucket Hijacking and Bluekit PhaaS. Critical vulnerabilities in cloud infrastructure and software posed significant risks.

  • data-exfiltration
  • lateral-movement
  • social-engineering
  • anti-analysis
  • persistence

Threats published

20 threat lines in the 2026-06-28 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

151 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

11 named threat actors across the reports.

Nation-state attribution

  • Russia
  • China
  • India
  • North Korea

Threat categories

  • PHISHING
  • MALWARE
  • APT
  • SUPPLY_CHAIN
  • VULNERABILITY

Severity breakdown

  • critical15
  • high5
  • medium0
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

506 indicators of compromise · Red and above. Compare plans
  • network 156
  • behavioral 142
  • file 84
  • malware 40
  • infrastructure 34
  • tool 25
  • entity 15
  • technique 7
  • package 3
180 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans