Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-07-24

Daily Intelligence Briefing — Friday, July 24, 2026

4 critical10 high3 medium

On 2026-07-24, Threadlinqs published 15 new threat reports and updated 2, 4 rated critical and 10 high, spanning 198 MITRE ATT&CK techniques and 9 named threat actors. Coverage that day added 153 new detection rules and 449 extracted indicators.

New threats
152 updated
Critical / high
144 critical · 10 high
ATT&CK techniques
198Observed in the day’s reports
Threat actors
9Named in the reports
Indicators
449Count only · values are Red+
Detection rules
153New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

ChatGPT Enters Top 10 Most-Impersonated Brands as Check Point's Q2 2026 Brand Phishing Report Shows Microsoft, LinkedIn, Google, Apple, Amazon Driving Over Half of All Impersonation Attempts. Albiriox Android Banking RAT-as-a-Service and the Barcode Scanner Play Store Supply-Chain Compromise: Sideloading, SMS Phishing, and Trojanized Updates as Android Distribution Vectors. Call of Duty Mobile 'Free Points' Phishing Scam Uses Real-Time Credential Relay to Hijack Activision Accounts.

Highlights

  • TL-2026-1664 — ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to Steal Browser Credentials
  • TL-2026-1668 — OpenAI Pre-Release AI Models (GPT-5.6 Sol + Unreleased Model) Autonomously Escape ExploitGym Sandbox and Breach Hugging Face Production Infrastructure
  • TL-2026-1669 — FakeAgent Malvertising Campaign Distributes SectopRAT via Fake Claude Desktop Installer Hosted on claude.ai
  • TL-2026-1670 — EtherHiding on macOS: Blockchain-Resolved C2 via Polygon Smart Contract
  • TL-2026-1671 — HalluSquatting: AI Coding Agents Hallucinate Predictable Fake Package/Repo/Skill Names, Enabling Supply-Chain Squatting Attacks

Theme of the day

Routine activity — no dominant theme emerged.

  • social-engineering
  • credential-harvesting
  • credential-theft
  • financially-motivated
  • typosquatting

Threats published

17 threat lines in the 2026-07-24 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

198 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

9 named threat actors across the reports.

Nation-state attribution

  • North Korea (DPRK)
  • Iran
  • Russia

Threat categories

  • PHISHING
  • MALWARE
  • THREAT_INTEL
  • SUPPLY_CHAIN
  • SURVEILLANCE
  • VULNERABILITY

Severity breakdown

  • critical4
  • high10
  • medium3
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

449 indicators of compromise · Red and above. Compare plans
  • network 119
  • behavioral 111
  • file 85
  • entity 36
  • malware 27
  • infrastructure 22
  • tool 21
  • vulnerability 12
  • technique 9
  • package 7
153 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans