# Daily Intelligence Briefing — Sunday, June 28, 2026

> On 2026-06-28, Threadlinqs published 18 new threat reports and updated 2, 15 rated critical and 5 high, spanning 151 MITRE ATT&CK techniques and 11 named threat actors. Coverage that day added 180 new detection rules and 506 extracted indicators.

- **Edition:** 2026-06-28 (Sunday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-06-28
- **Last updated:** 2026-07-04
- **New threats:** 18 (2 updated)
- **Critical / high:** 15 critical, 5 high, 0 medium, 0 low
- **ATT&CK techniques:** 151
- **Threat actors:** 11
- **Indicators (count only):** 506
- **New detection rules (count only):** 180

## Summary & highlights

Photo ZIP Phishing Campaign Delivering TonRAT via Node.js Abuse Targeting Hospitality Sector. Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088. Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware Intrusions.

- [TL-2026-0965](https://intel.threadlinqs.com/threat/TL-2026-0965) — Photo ZIP Phishing Campaign Delivering TonRAT via Node.js Abuse Targeting Hospitality Sector
- [TL-2026-0966](https://intel.threadlinqs.com/threat/TL-2026-0966) — Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088
- [TL-2026-0967](https://intel.threadlinqs.com/threat/TL-2026-0967) — Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware Intrusions
- [TL-2026-0968](https://intel.threadlinqs.com/threat/TL-2026-0968) — Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
- [TL-2026-0970](https://intel.threadlinqs.com/threat/TL-2026-0970) — Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)

## Theme of the day

Unknown actors actively exploited various vulnerabilities, including Cloud Bucket Hijacking and Bluekit PhaaS. Critical vulnerabilities in cloud infrastructure and software posed significant risks.

data-exfiltration, lateral-movement, social-engineering, anti-analysis, persistence

## Threats published

- [TL-2026-0969](https://intel.threadlinqs.com/threat/TL-2026-0969) — CRITICAL — WeedHack MaaS Campaign: Minecraft Fake Mod Loader with RSA-Signed Blockchain C2 (LoaderClient)
- [TL-2026-0971](https://intel.threadlinqs.com/threat/TL-2026-0971) — CRITICAL — CISA KEV: PTC Windchill RCE and Cisco Unified CM SSRF - Critical Remote Code Execution Vulnerabilities
- [TL-2026-0972](https://intel.threadlinqs.com/threat/TL-2026-0972) — CRITICAL — ClickFix Campaign Deploying Potemkin Loader, RMMProject RAT, and EtherRAT - May 2026 Enterprise Compromise
- [TL-2026-0976](https://intel.threadlinqs.com/threat/TL-2026-0976) — CRITICAL — Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration
- [TL-2026-0981](https://intel.threadlinqs.com/threat/TL-2026-0981) — CRITICAL — TeamPCP Malware Injection into Microsoft-Linked GitHub Repositories (42+ repos, 236 branches, 2026-06-05)
- [TL-2026-0984](https://intel.threadlinqs.com/threat/TL-2026-0984) — CRITICAL — Kali365/Octopi365 Device Code Phishing-as-a-Service Campaign
- [TL-2026-0986](https://intel.threadlinqs.com/threat/TL-2026-0986) — CRITICAL — Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 Countries
- [TL-2026-0987](https://intel.threadlinqs.com/threat/TL-2026-0987) — CRITICAL — JadeSnow: Hijacked npm/Go Supply Chain Attack with VSCode Exploitation and Blockchain Dead Drops
- [TL-2026-0989](https://intel.threadlinqs.com/threat/TL-2026-0989) — CRITICAL — Dropping Elephant Malware Campaign - China-Themed Loader Chain for Initial Access and Payload Delivery
- [TL-2026-0990](https://intel.threadlinqs.com/threat/TL-2026-0990) — CRITICAL — Showboat: Sophisticated Linux Post-Exploitation Framework Targeting Middle East Telecommunications
- [TL-2026-0992](https://intel.threadlinqs.com/threat/TL-2026-0992) — CRITICAL — Klue SaaS Integration Platform OAuth Token Compromise – Multi-Organization Salesforce CRM Access
- [TL-2026-0993](https://intel.threadlinqs.com/threat/TL-2026-0993) — CRITICAL — Fake AI Tool Attacks on SMBs: 33,300 Cyberattacks Masquerading as ChatGPT, Copilot, Claude in Early 2026
- [TL-2026-0994](https://intel.threadlinqs.com/threat/TL-2026-0994) — CRITICAL — macOS.Gaslight - Rust Backdoor with AI-Analysis Evasion & Prompt Injection
- [TL-2026-0980](https://intel.threadlinqs.com/threat/TL-2026-0980) — CRITICAL — ServiceNow Scripted REST Resource Unauthenticated Access - /api/now/related_list_edit/create (update)
- [TL-2026-0983](https://intel.threadlinqs.com/threat/TL-2026-0983) — CRITICAL — Miasma: Supply Chain Compromise in RedHat npm Packages - Credential Harvesting Malware (update)
- [TL-2026-0965](https://intel.threadlinqs.com/threat/TL-2026-0965) — HIGH — Photo ZIP Phishing Campaign Delivering TonRAT via Node.js Abuse Targeting Hospitality Sector
- [TL-2026-0966](https://intel.threadlinqs.com/threat/TL-2026-0966) — HIGH — Turla STOCKSTAY .NET Backdoor Targeting Ukraine Government and Military via CVE-2025-8088
- [TL-2026-0967](https://intel.threadlinqs.com/threat/TL-2026-0967) — HIGH — Mistic Self-Destructing In-Memory Backdoor (MLTBackdoor) Deployed by KongTuke Access Broker Enabling Multi-Group Ransomware Intrusions
- [TL-2026-0968](https://intel.threadlinqs.com/threat/TL-2026-0968) — HIGH — Russian APT Gamaredon Upgrades Arsenal with Six New PowerShell Downloaders, Cloudflare/Devtunnel C2 Concealment, and Turla Collaboration Delivering Kazuar Backdoor (2025)
- [TL-2026-0970](https://intel.threadlinqs.com/threat/TL-2026-0970) — HIGH — Alleged Huntress Insider Leaked Law Enforcement Communications to DevMan Ransomware Operation (DragonForce/Conti Lineage)

## Techniques observed

[T1001](https://intel.threadlinqs.com/technique/T1001), [T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1025](https://intel.threadlinqs.com/technique/T1025), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.006](https://intel.threadlinqs.com/technique/T1027.006), [T1030](https://intel.threadlinqs.com/technique/T1030), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1037](https://intel.threadlinqs.com/technique/T1037), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1072](https://intel.threadlinqs.com/technique/T1072), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.004](https://intel.threadlinqs.com/technique/T1087.004), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1091](https://intel.threadlinqs.com/technique/T1091), T1092, [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.001](https://intel.threadlinqs.com/technique/T1098.001), [T1098.003](https://intel.threadlinqs.com/technique/T1098.003), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.001](https://intel.threadlinqs.com/technique/T1114.001), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), T1131, [T1132](https://intel.threadlinqs.com/technique/T1132), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), T1136.003, [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1559](https://intel.threadlinqs.com/technique/T1559), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1561](https://intel.threadlinqs.com/technique/T1561), T1562, T1563, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1578](https://intel.threadlinqs.com/technique/T1578), [T1580](https://intel.threadlinqs.com/technique/T1580), T1581, [T1583](https://intel.threadlinqs.com/technique/T1583), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.003](https://intel.threadlinqs.com/technique/T1589.003), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1591.004](https://intel.threadlinqs.com/technique/T1591.004), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1594](https://intel.threadlinqs.com/technique/T1594), [T1598](https://intel.threadlinqs.com/technique/T1598), T1598.002, [T1608](https://intel.threadlinqs.com/technique/T1608), [T1614](https://intel.threadlinqs.com/technique/T1614), T1633, T1656, [T1657](https://intel.threadlinqs.com/technique/T1657)

## Threat actors

[Turla](https://intel.threadlinqs.com/actor/Turla), [KongTuke](https://intel.threadlinqs.com/actor/KongTuke), [Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon), [DevMan](https://intel.threadlinqs.com/actor/DevMan), [Majanito](https://intel.threadlinqs.com/actor/Majanito), [Icarus](https://intel.threadlinqs.com/actor/Icarus), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), [Earth Lusca](https://intel.threadlinqs.com/actor/Earth%20Lusca), [Patchwork](https://intel.threadlinqs.com/actor/Patchwork), [Calypso](https://intel.threadlinqs.com/actor/Calypso), [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky)

Nation-state attribution: Russia, China, India, North Korea

Threat categories: PHISHING, MALWARE, APT, SUPPLY_CHAIN, VULNERABILITY

## Severity breakdown

- critical: 15
- high: 5
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 506 (network 156, behavioral 142, file 84, malware 40, infrastructure 34, tool 25, entity 15, technique 7, package 3)
- New detection rules: 180 (100% of the day’s threats covered)

## More editions

- Previous: [2026-06-23](https://intel.threadlinqs.com/debrief/2026-06-23)
- Next: [2026-06-30](https://intel.threadlinqs.com/debrief/2026-06-30)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-06-28
