# Daily Intelligence Briefing — Monday, July 13, 2026

> On 2026-07-13, Threadlinqs published 38 new threat reports, 6 rated critical and 25 high, spanning 238 MITRE ATT&CK techniques and 18 named threat actors. Coverage that day added 342 new detection rules and 895 extracted indicators.

- **Edition:** 2026-07-13 (Monday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-13
- **Last updated:** 2026-07-17
- **New threats:** 38
- **Critical / high:** 6 critical, 25 high, 6 medium, 0 low
- **ATT&CK techniques:** 238
- **Threat actors:** 18
- **Indicators (count only):** 895
- **New detection rules (count only):** 342

## Summary & highlights

SnakeKeylogger Infostealer Delivered via Phishing Emails Disguised as Project Proposals (ASEC, JS→PowerShell Fileless Loader). Misconfigured Python HTTP Server Exposes AiTM Phishing Toolkit Behind Three Active Campaigns (codemado, mail-argenta, saroula01). VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and Exploitation (95% Success Rate).

- [TL-2026-1249](https://intel.threadlinqs.com/threat/TL-2026-1249) — APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate Services
- [TL-2026-1251](https://intel.threadlinqs.com/threat/TL-2026-1251) — Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related: CVE-2024-23630, CVE-2022-34885)
- [TL-2026-1252](https://intel.threadlinqs.com/threat/TL-2026-1252) — Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmations
- [TL-2026-1253](https://intel.threadlinqs.com/threat/TL-2026-1253) — Claude Mythos / Project Glasswing: Autonomous AI Vulnerability Discovery Compresses the Find-to-Exploit Timeline (CVE-2026-4747 and the AI-Scale Disclosure Problem)
- [TL-2026-1257](https://intel.threadlinqs.com/threat/TL-2026-1257) — UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)

## Theme of the day

credential-theft, espionage, remote-code-execution, unauthenticated-rce, financially-motivated

## Threats published

- [TL-2026-1254](https://intel.threadlinqs.com/threat/TL-2026-1254) — CRITICAL — Zero-Day Exploitation of Joomla iCagenda and Balbooa Forms Extensions via Unauthenticated Arbitrary File Upload (CVE-2026-48939, CVE-2026-56291)
- [TL-2026-1262](https://intel.threadlinqs.com/threat/TL-2026-1262) — CRITICAL — Critical Authentication Bypass in WordPress OAuth Single Sign-On (SSO) Plugin by miniOrange (CVE-2026-57807)
- [TL-2026-1266](https://intel.threadlinqs.com/threat/TL-2026-1266) — CRITICAL — CISA KEV: Joomla iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) Unrestricted File Upload Flaws Under Active Exploitation
- [TL-2026-1267](https://intel.threadlinqs.com/threat/TL-2026-1267) — CRITICAL — CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions — iCagenda (CVE-2026-48939) and Balbooa Forms (CVE-2026-56291) Arbitrary File Upload
- [TL-2026-1279](https://intel.threadlinqs.com/threat/TL-2026-1279) — CRITICAL — NSA/FBI Joint Advisory: Disable Cisco Smart Install to Block Russian FSB "Static Tundra" Exploitation of CVE-2018-0171
- [TL-2026-1282](https://intel.threadlinqs.com/threat/TL-2026-1282) — CRITICAL — Static Tundra (FSB Center 16) Exploits CVE-2018-0171 Cisco Smart Install Flaw Against Critical Infrastructure
- [TL-2026-1249](https://intel.threadlinqs.com/threat/TL-2026-1249) — HIGH — APT-C-60 2026 Campaign: SpyGlace Backdoor Delivered via LNK Files and Abused Legitimate Services
- [TL-2026-1251](https://intel.threadlinqs.com/threat/TL-2026-1251) — HIGH — Unauthenticated RCE in Motorola MR2600 Wi-Fi Router via Firmware Upload Validation Bypass (related: CVE-2024-23630, CVE-2022-34885)
- [TL-2026-1252](https://intel.threadlinqs.com/threat/TL-2026-1252) — HIGH — Remcos RAT Delivered via CVE-2017-0199 Phishing Campaign Impersonating Payment Confirmations
- [TL-2026-1253](https://intel.threadlinqs.com/threat/TL-2026-1253) — HIGH — Claude Mythos / Project Glasswing: Autonomous AI Vulnerability Discovery Compresses the Find-to-Exploit Timeline (CVE-2026-4747 and the AI-Scale Disclosure Problem)
- [TL-2026-1257](https://intel.threadlinqs.com/threat/TL-2026-1257) — HIGH — UAT-7810 Expands ORB Networks with LONGLEASH, DOGLEASH, and JARLEASH Malware Suite (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2025-2492)
- [TL-2026-1258](https://intel.threadlinqs.com/threat/TL-2026-1258) — HIGH — Misconfigured Server Exposes Three Evilginx-Based Microsoft 365 Phishing Operations (codemado, mail-argenta, saroula01)
- [TL-2026-1259](https://intel.threadlinqs.com/threat/TL-2026-1259) — HIGH — UNK_MassTraction: China-Aligned Actor Exploits Roundcube CVE-2024-42009 & CVE-2025-49113 to Deploy IceCube Stealer and VShell Against University Physics Departments
- [TL-2026-1260](https://intel.threadlinqs.com/threat/TL-2026-1260) — HIGH — Armored Likho APT (Eagle Werewolf) Deploys AI-Generated Loaders to Drop BusySnake Python Stealer Against Government and Power-Sector Targets
- [TL-2026-1263](https://intel.threadlinqs.com/threat/TL-2026-1263) — HIGH — Krybit Ransomware — Babuk-Derived RaaS Operation Emerges with Double Extortion
- [TL-2026-1265](https://intel.threadlinqs.com/threat/TL-2026-1265) — HIGH — Argentine Football Association (AFA) Breached via Year-Old Infostealer Credential Compromise — "All Egyptian Cyber Warriors"
- [TL-2026-1268](https://intel.threadlinqs.com/threat/TL-2026-1268) — HIGH — Turla (Snake/Uroburos) Exploits SharePoint Flaw to Breach French Justice-Sector Server
- [TL-2026-1269](https://intel.threadlinqs.com/threat/TL-2026-1269) — HIGH — SQL Injection Leads to MSSQL Compromise, BadIIS Backdoor, and XMRig Deployment
- [TL-2026-1270](https://intel.threadlinqs.com/threat/TL-2026-1270) — HIGH — CrashStealer: Native C++ macOS Infostealer Impersonating Apple's CrashReporter, Delivered via Notarized "Werkbit" Meeting-App Lure
- [TL-2026-1271](https://intel.threadlinqs.com/threat/TL-2026-1271) — HIGH — GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and FlockWiper-Derived Multi-Pass Wiping
- [TL-2026-1272](https://intel.threadlinqs.com/threat/TL-2026-1272) — HIGH — CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage Campaign
- [TL-2026-1273](https://intel.threadlinqs.com/threat/TL-2026-1273) — HIGH — CrashStealer: Signed & Notarized macOS Infostealer Delivered via Fake Meeting App "Werkbit"
- [TL-2026-1274](https://intel.threadlinqs.com/threat/TL-2026-1274) — HIGH — CrashStealer: Native C++ macOS Infostealer Masquerading as Apple's CrashReporter via Notarized 'Werkbit' Dropper
- [TL-2026-1275](https://intel.threadlinqs.com/threat/TL-2026-1275) — HIGH — ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations
- [TL-2026-1276](https://intel.threadlinqs.com/threat/TL-2026-1276) — HIGH — FSB Center 16 (Static Tundra / Berserk Bear) Exploits Default/Weak SNMP and Unpatched Cisco Smart Install (CVE-2018-0171) to Compromise Networking Devices — AA26-194A
- [TL-2026-1277](https://intel.threadlinqs.com/threat/TL-2026-1277) — HIGH — Russian FSB Center 16 (Static Tundra/Berserk Bear) Exploiting Unpatched Cisco Smart Install Devices — Joint NSA/FBI/13-Nation Advisory
- [TL-2026-1280](https://intel.threadlinqs.com/threat/TL-2026-1280) — HIGH — Forg365 Phishing-as-a-Service Targets Microsoft 365 via Device Code and AitM Session Theft
- [TL-2026-1283](https://intel.threadlinqs.com/threat/TL-2026-1283) — HIGH — FSB Centre 16 (Berserk Bear/Static Tundra) Targets Critical Infrastructure via Weak SNMP Credentials and Cisco Smart Install Exploitation (CVE-2018-0171) — UK/EU Attribute December 2025 Poland Energy Grid Attack
- [TL-2026-1284](https://intel.threadlinqs.com/threat/TL-2026-1284) — HIGH — SpyGlace Malware Campaign by APT-C-60 (Naikon) Abuses Trusted Developer Services (GitHub, GitLab, jsDelivr, Codeberg, Bitbucket) to Target Japan
- [TL-2026-1285](https://intel.threadlinqs.com/threat/TL-2026-1285) — HIGH — Operation Capsule Vault: APT37 Weaponizes Real Academic Event Materials to Deliver RokRAT via ISO/Process Injection
- [TL-2026-1286](https://intel.threadlinqs.com/threat/TL-2026-1286) — HIGH — Check Point AI Security Report 2026: AI Shifts from Attack Tool to Autonomous Intrusion Operator (VoidLink C2, Mexico Government Breach, GTG-1002)
- [TL-2026-1255](https://intel.threadlinqs.com/threat/TL-2026-1255) — MEDIUM — SnakeKeylogger Infostealer Delivered via Phishing Emails Disguised as Project Proposals (ASEC, JS→PowerShell Fileless Loader)
- [TL-2026-1256](https://intel.threadlinqs.com/threat/TL-2026-1256) — MEDIUM — Misconfigured Python HTTP Server Exposes AiTM Phishing Toolkit Behind Three Active Campaigns (codemado, mail-argenta, saroula01)
- [TL-2026-1261](https://intel.threadlinqs.com/threat/TL-2026-1261) — MEDIUM — VEXAIoT: Autonomous Multi-Agent LLM Framework Automates End-to-End IoT Vulnerability Discovery and Exploitation (95% Success Rate)
- [TL-2026-1264](https://intel.threadlinqs.com/threat/TL-2026-1264) — MEDIUM — Former Ransomware Negotiator Angelo Martino Sentenced to 70 Months for Colluding with BlackCat/ALPHV Operators to Extort $75.3M from Five Victims
- [TL-2026-1278](https://intel.threadlinqs.com/threat/TL-2026-1278) — MEDIUM — Internet-Wide Reconnaissance Scans Target MCP Servers and Claude/Cursor AI-Agent Credentials
- [TL-2026-1281](https://intel.threadlinqs.com/threat/TL-2026-1281) — MEDIUM — Suspected AI-Generated ("Vibe-Coded") PowerShell Script Used to Map Active Directory Post-RDP Compromise
- [TL-2026-1250](https://intel.threadlinqs.com/threat/TL-2026-1250) — INFORMATIONAL — Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1010](https://intel.threadlinqs.com/technique/T1010), T1011, [T1012](https://intel.threadlinqs.com/technique/T1012), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1021.005](https://intel.threadlinqs.com/technique/T1021.005), [T1025](https://intel.threadlinqs.com/technique/T1025), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.007](https://intel.threadlinqs.com/technique/T1027.007), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.007](https://intel.threadlinqs.com/technique/T1036.007), [T1037](https://intel.threadlinqs.com/technique/T1037), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1048.003](https://intel.threadlinqs.com/technique/T1048.003), T1048.004, T1052, [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.001](https://intel.threadlinqs.com/technique/T1055.001), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, T1070.002, [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), T1071.002, T1071.003, [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.001](https://intel.threadlinqs.com/technique/T1078.001), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), T1087.003, [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1098.005](https://intel.threadlinqs.com/technique/T1098.005), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.003](https://intel.threadlinqs.com/technique/T1195.003), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1200](https://intel.threadlinqs.com/technique/T1200), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), T1213.004, [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222](https://intel.threadlinqs.com/technique/T1222), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.001](https://intel.threadlinqs.com/technique/T1491.001), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1495](https://intel.threadlinqs.com/technique/T1495), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1497.003](https://intel.threadlinqs.com/technique/T1497.003), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1538](https://intel.threadlinqs.com/technique/T1538), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1542](https://intel.threadlinqs.com/technique/T1542), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1546.015](https://intel.threadlinqs.com/technique/T1546.015), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), T1547.005, [T1547.006](https://intel.threadlinqs.com/technique/T1547.006), T1547.015, [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), T1557.003, [T1560](https://intel.threadlinqs.com/technique/T1560), [T1561](https://intel.threadlinqs.com/technique/T1561), T1561.002, T1562, T1562.001, T1562.004, T1562.008, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.005](https://intel.threadlinqs.com/technique/T1584.005), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.002](https://intel.threadlinqs.com/technique/T1589.002), [T1589.003](https://intel.threadlinqs.com/technique/T1589.003), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1599](https://intel.threadlinqs.com/technique/T1599), [T1601](https://intel.threadlinqs.com/technique/T1601), [T1601.001](https://intel.threadlinqs.com/technique/T1601.001), [T1602](https://intel.threadlinqs.com/technique/T1602), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), T1671

## Threat actors

codemado, [BlackCat](https://intel.threadlinqs.com/actor/BlackCat), [APT-C-60](https://intel.threadlinqs.com/actor/APT-C-60), [UAT-7810](https://intel.threadlinqs.com/actor/UAT-7810), [UNK_MassTraction](https://intel.threadlinqs.com/actor/UNK_MassTraction), [Armored Likho](https://intel.threadlinqs.com/actor/Armored%20Likho), [KryBit](https://intel.threadlinqs.com/actor/KryBit), [All Egyptian Cyber Warriors](https://intel.threadlinqs.com/actor/All%20Egyptian%20Cyber%20Warriors), [Turla](https://intel.threadlinqs.com/actor/Turla), [UAT-8099](https://intel.threadlinqs.com/actor/UAT-8099), [BLUERABBIT](https://intel.threadlinqs.com/actor/BLUERABBIT), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters), [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016), [Forg365 operators](https://intel.threadlinqs.com/actor/Forg365%20operators), [FSB Centre 16](https://intel.threadlinqs.com/actor/FSB%20Centre%2016), [APT37](https://intel.threadlinqs.com/actor/APT37), [TAT26-12](https://intel.threadlinqs.com/actor/TAT26-12)

Nation-state attribution: South Korea (assessed alignment), China, Russia, Iran, South Korea (suspected origin/alignment), North Korea

Threat categories: MALWARE, PHISHING, TOOL, THREAT_ACTOR, RECONNAISSANCE, THREAT_INTEL, VULNERABILITY, CAMPAIGN, RANSOMWARE, DATA_BREACH, APT, INTRUSION, NATION_STATE

## Severity breakdown

- critical: 6
- high: 25
- medium: 6
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 895 (network 206, file 189, behavioral 181, entity 101, malware 65, tool 64, infrastructure 44, technique 20, package 19, financial 3, vulnerability 3)
- New detection rules: 342 (100% of the day’s threats covered)

## More editions

- Previous: [2026-07-11](https://intel.threadlinqs.com/debrief/2026-07-11)
- Next: [2026-07-14](https://intel.threadlinqs.com/debrief/2026-07-14)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-13
