# Daily Intelligence Briefing — Thursday, July 16, 2026

> On 2026-07-16, Threadlinqs published 38 new threat reports and updated 7, 13 rated critical and 23 high, spanning 261 MITRE ATT&CK techniques and 11 named threat actors. Coverage that day added 396 new detection rules and 1200 extracted indicators.

- **Edition:** 2026-07-16 (Thursday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-07-16
- **Last updated:** 2026-07-21
- **New threats:** 38 (7 updated)
- **Critical / high:** 13 critical, 23 high, 7 medium, 0 low
- **ATT&CK techniques:** 261
- **Threat actors:** 11
- **Indicators (count only):** 1200
- **New detection rules (count only):** 396

## Summary & highlights

Cofense Report: Finance-Sector Phishing Shifts to Operational, Non-Urgency Lures (Payment/Invoice/Contract Themes). Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet Against a Dental Clinic. TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifacts.

- [TL-2026-1386](https://intel.threadlinqs.com/threat/TL-2026-1386) — TELEPUZ: New Modular Malware-as-a-Service Distributed via ClickFix Social Engineering
- [TL-2026-1400](https://intel.threadlinqs.com/threat/TL-2026-1400) — Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced Daxin
- [TL-2026-1402](https://intel.threadlinqs.com/threat/TL-2026-1402) — ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor
- [TL-2026-1406](https://intel.threadlinqs.com/threat/TL-2026-1406) — Photo ZIP Campaign Delivers TonRAT Node.js Implant to Hospitality Sector via Authentication Laundering
- [TL-2026-1408](https://intel.threadlinqs.com/threat/TL-2026-1408) — Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe

## Theme of the day

Activity centered on social-engineering, credential-harvesting, cwe-269.

credential-theft, financially-motivated, social-engineering, privilege-escalation, masquerading

## Threats published

- [TL-2026-1393](https://intel.threadlinqs.com/threat/TL-2026-1393) — CRITICAL — Zoom Windows Apps Critical Unauthenticated Account Takeover (CVE-2026-53412) Plus Three Chained Local Privilege Escalation Flaws
- [TL-2026-1395](https://intel.threadlinqs.com/threat/TL-2026-1395) — CRITICAL — CISA Adds CVE-2026-46817 (Oracle E-Business Suite Payments Unauthenticated Takeover) and CVE-2023-4346 (KNX Protocol Account-Lockout) to KEV Catalog
- [TL-2026-1396](https://intel.threadlinqs.com/threat/TL-2026-1396) — CRITICAL — SonicWall SMA1000 Zero-Day Vulnerabilities Chained for Full Appliance Compromise (CVE-2026-15409, CVE-2026-15410)
- [TL-2026-1403](https://intel.threadlinqs.com/threat/TL-2026-1403) — CRITICAL — Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)
- [TL-2026-1404](https://intel.threadlinqs.com/threat/TL-2026-1404) — CRITICAL — Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoor
- [TL-2026-1405](https://intel.threadlinqs.com/threat/TL-2026-1405) — CRITICAL — Zoom Patches Critical Windows Client Flaw (CVE-2026-53412, CVSS 9.8) Enabling Unauthenticated Account Takeover
- [TL-2026-1407](https://intel.threadlinqs.com/threat/TL-2026-1407) — CRITICAL — CVE-2026-53412: Unauthenticated Remote Account Takeover in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows
- [TL-2026-1422](https://intel.threadlinqs.com/threat/TL-2026-1422) — CRITICAL — CVE-2025-54068 Exploited in Large-Scale Laravel Livewire Credential Theft Campaign
- [TL-2026-1054](https://intel.threadlinqs.com/threat/TL-2026-1054) — CRITICAL — CVE-2026-46817: Critical Unauthenticated File-Read/Takeover Flaw in Oracle E-Business Suite Payments Exploited Pre-PoC (update)
- [TL-2026-1073](https://intel.threadlinqs.com/threat/TL-2026-1073) — CRITICAL — CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances (update)
- [TL-2026-1324](https://intel.threadlinqs.com/threat/TL-2026-1324) — CRITICAL — Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation (update)
- [TL-2026-1378](https://intel.threadlinqs.com/threat/TL-2026-1378) — CRITICAL — CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) (update)
- [TL-2026-1390](https://intel.threadlinqs.com/threat/TL-2026-1390) — CRITICAL — SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) Chained With Appliance Management Console Command Injection (CVE-2026-15410, CVSS 7.2) Under Active Zero-Day Exploitation (update)
- [TL-2026-1386](https://intel.threadlinqs.com/threat/TL-2026-1386) — HIGH — TELEPUZ: New Modular Malware-as-a-Service Distributed via ClickFix Social Engineering
- [TL-2026-1400](https://intel.threadlinqs.com/threat/TL-2026-1400) — HIGH — Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced Daxin
- [TL-2026-1402](https://intel.threadlinqs.com/threat/TL-2026-1402) — HIGH — ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoor
- [TL-2026-1406](https://intel.threadlinqs.com/threat/TL-2026-1406) — HIGH — Photo ZIP Campaign Delivers TonRAT Node.js Implant to Hospitality Sector via Authentication Laundering
- [TL-2026-1408](https://intel.threadlinqs.com/threat/TL-2026-1408) — HIGH — Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe
- [TL-2026-1409](https://intel.threadlinqs.com/threat/TL-2026-1409) — HIGH — Multiple Splunk Enterprise Vulnerabilities Enable Path Traversal and Information Disclosure (CVE-2026-20296, CVE-2026-20297, CVE-2026-20298)
- [TL-2026-1410](https://intel.threadlinqs.com/threat/TL-2026-1410) — HIGH — Spirals Ransomware: Rust-Based Double-Extortion Family Breaches South Asian IT Services Firm via IIS Web Shell in Under 24 Hours
- [TL-2026-1411](https://intel.threadlinqs.com/threat/TL-2026-1411) — HIGH — UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 Implant
- [TL-2026-1412](https://intel.threadlinqs.com/threat/TL-2026-1412) — HIGH — New "Spirals" Ransomware Encrypts Victim Network in Under 24 Hours via Exposed IIS Server
- [TL-2026-1413](https://intel.threadlinqs.com/threat/TL-2026-1413) — HIGH — UAT-11795 Deploys Novel Starland RAT and Bespoke WLDR C2 Implant in Financially Motivated Campaign
- [TL-2026-1414](https://intel.threadlinqs.com/threat/TL-2026-1414) — HIGH — LegacyHive: Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day PoC (Unpatched, No CVE)
- [TL-2026-1415](https://intel.threadlinqs.com/threat/TL-2026-1415) — HIGH — GoSerpent Backdoor Campaign Targets Southeast Asian Government and Diplomatic Entities
- [TL-2026-1416](https://intel.threadlinqs.com/threat/TL-2026-1416) — HIGH — PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched Electron Apps
- [TL-2026-1417](https://intel.threadlinqs.com/threat/TL-2026-1417) — HIGH — Iran's AI-Enhanced Asymmetric Playbook: State Actors Integrate AI Across Cyber, Influence, and Military Operations (2026 Conflict)
- [TL-2026-1418](https://intel.threadlinqs.com/threat/TL-2026-1418) — HIGH — The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWorm
- [TL-2026-1420](https://intel.threadlinqs.com/threat/TL-2026-1420) — HIGH — TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chain
- [TL-2026-1421](https://intel.threadlinqs.com/threat/TL-2026-1421) — HIGH — ClickLock: New macOS Infostealer Uses ClickFix Lure and App-Killing LaunchAgents to Force Credential Entry
- [TL-2026-1424](https://intel.threadlinqs.com/threat/TL-2026-1424) — HIGH — macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain, Browser Credentials, Apple Notes, and 16 Crypto Wallets
- [TL-2026-1427](https://intel.threadlinqs.com/threat/TL-2026-1427) — HIGH — Ransomware Attack on Coca-Cola's Fairlife Dairy Subsidiary Halts US Production
- [TL-2026-1428](https://intel.threadlinqs.com/threat/TL-2026-1428) — HIGH — CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code Execution
- [TL-2026-1494](https://intel.threadlinqs.com/threat/TL-2026-1494) — HIGH — macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App Replacement
- [TL-2026-1148](https://intel.threadlinqs.com/threat/TL-2026-1148) — HIGH — GodDamn Ransomware (Hyadina) — Third Rebrand from Monster/Beast, Deploys Signed PoisonX Kernel Driver (update)
- [TL-2026-1401](https://intel.threadlinqs.com/threat/TL-2026-1401) — HIGH — LabubaRAT: Rust-based RAT Disguised as NVIDIA Container Runtime Toolkit (update)
- [TL-2026-1392](https://intel.threadlinqs.com/threat/TL-2026-1392) — MEDIUM — Cofense Report: Finance-Sector Phishing Shifts to Operational, Non-Urgency Lures (Payment/Invoice/Contract Themes)
- [TL-2026-1394](https://intel.threadlinqs.com/threat/TL-2026-1394) — MEDIUM — Gemini CLI Abused as Autonomous AI Hacking Agent to Build and Operate "Patriot Bait" (bandcampro) C2 Botnet Against a Dental Clinic
- [TL-2026-1397](https://intel.threadlinqs.com/threat/TL-2026-1397) — MEDIUM — TuxBot v3 Evolution: Keksec-Linked IoT/Linux Botnet with Verbatim LLM Chain-of-Thought Code Artifacts
- [TL-2026-1399](https://intel.threadlinqs.com/threat/TL-2026-1399) — MEDIUM — Coordinated GitHub API Enumeration and Access Token Abuse Campaign (Ghost Accounts + Compromised PAT/OAuth Tokens)
- [TL-2026-1423](https://intel.threadlinqs.com/threat/TL-2026-1423) — MEDIUM — AnyDesk "Send Support Information" Link-Following Denial-of-Service (CVE-2026-15682)
- [TL-2026-1425](https://intel.threadlinqs.com/threat/TL-2026-1425) — MEDIUM — FaceTime Impersonation Scam Targets Bank and Apple Support Victims ("DarkSword"-style Campaign)
- [TL-2026-1426](https://intel.threadlinqs.com/threat/TL-2026-1426) — MEDIUM — Text-Salting Phishing Campaigns Abuse CSS-Hidden Text to Evade AI Email Security Filters
- [TL-2026-1398](https://intel.threadlinqs.com/threat/TL-2026-1398) — INFO — Identity Attacks Overtake Exploits as Top Ransomware Cause (Sophos State of Ransomware 2026)
- [TL-2026-1419](https://intel.threadlinqs.com/threat/TL-2026-1419) — INFO — CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK Publish Joint Guidance: Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers

## Techniques observed

[AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051), AML.T0068, T0813, T0814, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1005](https://intel.threadlinqs.com/technique/T1005), T1006, [T1008](https://intel.threadlinqs.com/technique/T1008), [T1010](https://intel.threadlinqs.com/technique/T1010), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1020](https://intel.threadlinqs.com/technique/T1020), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.004](https://intel.threadlinqs.com/technique/T1027.004), T1027.005, T1027.016, [T1030](https://intel.threadlinqs.com/technique/T1030), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.007](https://intel.threadlinqs.com/technique/T1036.007), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1048.003](https://intel.threadlinqs.com/technique/T1048.003), [T1049](https://intel.threadlinqs.com/technique/T1049), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.004](https://intel.threadlinqs.com/technique/T1055.004), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.002](https://intel.threadlinqs.com/technique/T1056.002), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1069.002](https://intel.threadlinqs.com/technique/T1069.002), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.001, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), T1070.009, [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1074](https://intel.threadlinqs.com/technique/T1074), [T1074.001](https://intel.threadlinqs.com/technique/T1074.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.002](https://intel.threadlinqs.com/technique/T1078.002), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.001](https://intel.threadlinqs.com/technique/T1087.001), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), T1102.003, [T1104](https://intel.threadlinqs.com/technique/T1104), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.001](https://intel.threadlinqs.com/technique/T1136.001), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1187](https://intel.threadlinqs.com/technique/T1187), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1200](https://intel.threadlinqs.com/technique/T1200), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.004](https://intel.threadlinqs.com/technique/T1204.004), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1219](https://intel.threadlinqs.com/technique/T1219), T1222.001, [T1414](https://intel.threadlinqs.com/technique/T1414), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1484](https://intel.threadlinqs.com/technique/T1484), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1491.002](https://intel.threadlinqs.com/technique/T1491.002), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1498](https://intel.threadlinqs.com/technique/T1498), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1538](https://intel.threadlinqs.com/technique/T1538), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1543.004](https://intel.threadlinqs.com/technique/T1543.004), [T1546](https://intel.threadlinqs.com/technique/T1546), T1546.003, [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.006](https://intel.threadlinqs.com/technique/T1547.006), [T1547.013](https://intel.threadlinqs.com/technique/T1547.013), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.002](https://intel.threadlinqs.com/technique/T1552.002), T1552.003, [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.004](https://intel.threadlinqs.com/technique/T1555.004), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1560.002, T1562, T1562.001, T1562.002, T1562.004, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1584.001](https://intel.threadlinqs.com/technique/T1584.001), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1586.002](https://intel.threadlinqs.com/technique/T1586.002), T1586.003, [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1591.004](https://intel.threadlinqs.com/technique/T1591.004), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1592.004](https://intel.threadlinqs.com/technique/T1592.004), [T1593](https://intel.threadlinqs.com/technique/T1593), [T1593.003](https://intel.threadlinqs.com/technique/T1593.003), [T1594](https://intel.threadlinqs.com/technique/T1594), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1602](https://intel.threadlinqs.com/technique/T1602), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1608.002](https://intel.threadlinqs.com/technique/T1608.002), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1619](https://intel.threadlinqs.com/technique/T1619), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657)

## Threat actors

bandcampro, [Keksec-affiliated developer](https://intel.threadlinqs.com/actor/Keksec-affiliated%20developer), China-linked threat actor, [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev), [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse), [TetrisPhantom](https://intel.threadlinqs.com/actor/TetrisPhantom), [APT42](https://intel.threadlinqs.com/actor/APT42), China-linked espionage actor, [Hyadina](https://intel.threadlinqs.com/actor/Hyadina), [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603)

Nation-state attribution: Russia, China, Iran, Indonesia

Threat categories: PHISHING, MALWARE, SUPPLY_CHAIN, VULNERABILITY, SOCIAL_ENGINEERING, THREAT_INTEL, RANSOMWARE, THREAT_ACTOR

## Severity breakdown

- critical: 13
- high: 23
- medium: 7
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 1200 (behavioral 293, file 261, network 256, entity 117, malware 78, tool 65, infrastructure 56, technique 42, package 30, vulnerability 2)
- New detection rules: 396 (98% of the day’s threats covered)

## More editions

- Previous: [2026-07-15](https://intel.threadlinqs.com/debrief/2026-07-15)
- Next: [2026-07-17](https://intel.threadlinqs.com/debrief/2026-07-17)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-07-16
