Threadlinqs IntelligenceStart free

Daily debrief · Thursday2026-07-16

Daily Intelligence Briefing — Thursday, July 16, 2026

13 critical23 high7 medium

On 2026-07-16, Threadlinqs published 38 new threat reports and updated 7, 13 rated critical and 23 high, spanning 261 MITRE ATT&CK techniques and 11 named threat actors. Coverage that day added 396 new detection rules and 1200 extracted indicators.

New threats
387 updated
Critical / high
3613 critical · 23 high
ATT&CK techniques
261Observed in the day’s reports
Threat actors
11Named in the reports
Indicators
1200Count only · values are Red+
Detection rules
396New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Cofense Report: Finance-Sector Phishing Shifts to Operational, Non-Urgency Lures (Payment/Invoice/Contract Themes). Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet Against a Dental Clinic. TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifacts.

Highlights

  • TL-2026-1386 — TELEPUZ: New Modular Malware-as-a-Service Distributed via ClickFix Social Engineering
  • TL-2026-1400 — Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced Daxin
  • TL-2026-1402 — ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor
  • TL-2026-1406 — Photo ZIP Campaign Delivers TonRAT Node.js Implant to Hospitality Sector via Authentication Laundering
  • TL-2026-1408 — Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe

Theme of the day

Activity centered on social-engineering, credential-harvesting, cwe-269.

  • credential-theft
  • financially-motivated
  • social-engineering
  • privilege-escalation
  • masquerading

Threats published

45 threat lines in the 2026-07-16 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

261 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

11 named threat actors across the reports.

Nation-state attribution

  • Russia
  • China
  • Iran
  • Indonesia

Threat categories

  • PHISHING
  • MALWARE
  • SUPPLY_CHAIN
  • VULNERABILITY
  • SOCIAL_ENGINEERING
  • THREAT_INTEL
  • RANSOMWARE
  • THREAT_ACTOR

Severity breakdown

  • critical13
  • high23
  • medium7
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

1200 indicators of compromise · Red and above. Compare plans
  • behavioral 293
  • file 261
  • network 256
  • entity 117
  • malware 78
  • tool 65
  • infrastructure 56
  • technique 42
  • package 30
  • vulnerability 2
396 new detection rules (98% of the day’s threats covered) · Blue and above. Compare plans