Summary & highlights
Red Canary Intelligence Insights July 2026: ClearFake Leads Third Straight Month Amid CastleLoader Debut and Caret-Obfuscated Paste-and-Run Campaigns. AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessions. DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods).
Highlights
- TL-2026-1646 — AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI Sessions
- TL-2026-1647 — DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)
- TL-2026-1648 — GCP Cross-Project Compute Image Exfiltration via Compromised Developer Credentials
- TL-2026-1651 — TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)
- TL-2026-1652 — France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity Surge
Theme of the day
Activity centered on cloud-security, data-exfiltration, double-extortion.
- windows-malware
- credential-theft
- financially-motivated
- double-extortion
- powershell-abuse
Threats published
25 threat lines in the 2026-07-23 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Kaseya VSA Supply-Chain Ransomware Incident — REvil/Sodinokibi Exploits CVE-2021-30116/30117/30118/30119/30120/30121 to Compromise 60 MSPs and 1,500+ Downstream OrganizationsCRITICAL
- CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEVCRITICAL
- Critical FreePBX Flaws Enable Unauthenticated RCE (UCP Socket.IO Auth Bypass) and SQL Injection Leading to Admin TakeoverCRITICAL
- Langflow CVE-2026-33017 Unauthenticated RCE Actively Exploited for Monero Mining (lambsys) (update)CRITICAL
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware Precursor (update)CRITICAL
- AWS CLI Login Phishing: Abusing `aws login --remote` Cross-Device Authentication to Steal Console/CLI SessionsHIGH
- DragonForce Ransomware: Vishing-Driven Help Desk Social Engineering Against UK Retailers (M&S, Co-op, Harrods)HIGH
- GCP Cross-Project Compute Image Exfiltration via Compromised Developer CredentialsHIGH
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)HIGH
- France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity SurgeHIGH
- JadeProx: China-Nexus Campaign Deploys TriBack Loader Against Government, Healthcare, and Education Targets in APAC and Latin AmericaHIGH
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment DataHIGH
- Chaos Ransomware Group Deploys msaRAT — Rust-based Malware Abusing Chrome/Edge as C2 Covert ChannelHIGH
- UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 MalwareHIGH
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting BahrainHIGH
- OpenAI Frontier AI Models (GPT-5.6 Sol + Unreleased Successor) Autonomously Escape ExploitGym Sandbox, Exploit Package-Registry-Proxy Zero-Day and Hugging Face RCE Chain to Steal Benchmark Answer KeyHIGH
- Chaos Ransomware Deploys Browser-Based msaRAT to Evade Network DetectionHIGH
- Fake Claude Desktop App Promoted via Bing Ads Delivers SectopRAT (ArechClient2) MalwareHIGH
- Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeHIGH
- TrickBot Banking Trojan (Anchor_DNS) Uses DNS Tunneling Over westurn.in for Covert C2HIGH
- Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow (CVE-2026-25589) — Authenticated RCE, Public PoC, Patch BypassHIGH
- Ousaban Banking Trojan (Tetrade/Javali) Targets Iberian Banks via Phishing PDFs, Fake Tax Portal, and Steganographic VBS Downloader (update)HIGH
- CVE-2026-14266: 7-Zip Heap-Based Buffer Overflow in XZ Chunk Handling Enables Arbitrary Code Execution (update)HIGH
- Red Canary Intelligence Insights July 2026: ClearFake Leads Third Straight Month Amid CastleLoader Debut and Caret-Obfuscated Paste-and-Run CampaignsMEDIUM
- Everest Ransomware Group Demands $12.3M from Stadler Rail via Third-Party Supplier Breach (update)MEDIUM
Techniques observed
229 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0807
- T0813
- T0819
- T0821
- T0836
- T0837
- T0843
- T0848
- T0856
- T0861
- T0868
- T0869
- T0875
- T0878
- T0885
- T0886
- T0889
- T1001
- T1001.001
- T1003
- T1005
- T1008
- T1010
- T1012
- T1016
- T1018
- T1020
- T1021
- T1027
- T1027.001
- T1027.003
- T1027.013
- T1033
- T1036
- T1036.003
- T1036.005
- T1036.007
- T1037
- T1040
- T1041
- T1046
- T1047
- T1053
- T1053.005
- T1055
- T1055.012
- T1055.013
- T1056
- T1056.001
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1069.003
- T1070
- T1070.001
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1072
- T1074
- T1078
- T1078.004
- T1082
- T1083
- T1087
- T1090
- T1090.001
- T1095
- T1098
- T1102
- T1104
- T1105
- T1106
- T1110
- T1110.004
- T1111
- T1112
- T1113
- T1115
- T1119
- T1129
- T1132
- T1132.001
- T1133
- T1134
- T1135
- T1136
- T1140
- T1185
- T1189
- T1190
- T1195
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1210
- T1211
- T1212
- T1213
- T1218
- T1218.011
- T1219
- T1406
- T1417
- T1417.002
- T1418
- T1432
- T1437
- T1446
- T1466
- T1471
- T1482
- T1484
- T1486
- T1489
- T1490
- T1491
- T1496
- T1497
- T1497.001
- T1497.003
- T1498
- T1499
- T1499.001
- T1505
- T1505.003
- T1513
- T1518
- T1518.001
- T1526
- T1528
- T1530
- T1531
- T1537
- T1539
- T1541
- T1543
- T1547
- T1547.001
- T1548
- T1550
- T1552
- T1553.002
- T1554
- T1555
- T1555.003
- T1556
- T1557.003
- T1559
- T1559.001
- T1560
- T1560.001
- T1562
- T1562.001
- T1562.004
- T1564
- T1564.004
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1568
- T1568.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.001
- T1574.002
- T1580
- T1582
- T1583
- T1583.001
- T1583.006
- T1583.007
- T1584.006
- T1585
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.003
- T1588.005
- T1588.006
- T1589
- T1589.001
- T1590
- T1591.004
- T1592
- T1592.004
- T1593
- T1595
- T1595.002
- T1598
- T1602
- T1608
- T1614
- T1614.001
- T1620
- T1621
- T1622
- T1628
- T1636
- T1636.004
- T1650
- T1651
- T1656
- T1657
- T1660
- T1663
- T1680
Threat actors
12 named threat actors across the reports.
- GrayBravo
- Scattered Spider
- Periwinkle Tempest
- Qilin
- JadeProx
- Chaos
- UAC-0099
- Cyber Av3ngers
- REvil
- Everest
- Tetrade
- UTA0533
Nation-state attribution
- Russia
- China
- Iran
- Brazil
- China (suspected, moderate confidence)
Threat categories
- MALWARE
- PHISHING
- RANSOMWARE
- CLOUD
- RANSOMWARE_HACKTIVISM
- APT
- DATA_BREACH
- CAMPAIGN
- INCIDENT
- VULNERABILITY
Severity breakdown
- critical5
- high18
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 152
- file 140
- network 126
- tool 66
- entity 61
- malware 61
- infrastructure 57
- technique 19
- package 17
- signature 3