Threadlinqs IntelligenceStart free

Daily debrief · Thursday2026-07-23

Daily Intelligence Briefing — Thursday, July 23, 2026

5 critical18 high2 medium

On 2026-07-23, Threadlinqs published 20 new threat reports and updated 5, 5 rated critical and 18 high, spanning 229 MITRE ATT&CK techniques and 12 named threat actors. Coverage that day added 225 new detection rules and 702 extracted indicators.

New threats
205 updated
Critical / high
235 critical · 18 high
ATT&CK techniques
229Observed in the day’s reports
Threat actors
12Named in the reports
Indicators
702Count only · values are Red+
Detection rules
225New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Red Canary Intelligence Insights July 2026: ClearFake Leads Third Straight Month Amid CastleLoader Debut and Caret-Obfuscated Paste-and-Run Campaigns. AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessions. DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods).

Highlights

  • TL-2026-1646 — AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessions
  • TL-2026-1647 — DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)
  • TL-2026-1648 — GCP Cross-Project Compute Image Exfiltration via Compromised Developer Credentials
  • TL-2026-1651 — TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)
  • TL-2026-1652 — France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity Surge

Theme of the day

Activity centered on cloud-security, data-exfiltration, double-extortion.

  • windows-malware
  • credential-theft
  • financially-motivated
  • double-extortion
  • powershell-abuse

Threats published

25 threat lines in the 2026-07-23 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

229 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

12 named threat actors across the reports.

Nation-state attribution

  • Russia
  • China
  • Iran
  • Brazil
  • China (suspected, moderate confidence)

Threat categories

  • MALWARE
  • PHISHING
  • RANSOMWARE
  • CLOUD
  • RANSOMWARE_HACKTIVISM
  • APT
  • DATA_BREACH
  • CAMPAIGN
  • INCIDENT
  • VULNERABILITY

Severity breakdown

  • critical5
  • high18
  • medium2
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

702 indicators of compromise · Red and above. Compare plans
  • behavioral 152
  • file 140
  • network 126
  • tool 66
  • entity 61
  • malware 61
  • infrastructure 57
  • technique 19
  • package 17
  • signature 3
225 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans