Threadlinqs IntelligenceStart free

Daily debrief · Sunday2026-08-02

Daily Intelligence Briefing — Sunday, August 2, 2026

7 critical9 high5 medium

On 2026-08-02, Threadlinqs published 9 new threat reports and updated 12, 7 rated critical and 9 high, spanning 191 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 189 new detection rules and 746 extracted indicators.

New threats
912 updated
Critical / high
167 critical · 9 high
ATT&CK techniques
191Observed in the day’s reports
Threat actors
7Named in the reports
Indicators
746Count only · values are Red+
Detection rules
189New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Command. LogoKit Phishing-as-a-Service Evolves to Real-Time "Environment Impersonation". Alleged Revolut Data Breach — Unverified Threat-Actor Claim of 75M-User Financial Dataset for Sale ($500, Sample Data Disputed as Fabricated).

Highlights

  • TL-2026-1816 — Pre-Release Domain Abuse Campaign Targets GTA 6 (Grand Theft Auto VI) — 922 Malicious Domains Across Typosquatting, Purchase Fraud, Crypto Lures, and Malware Distribution
  • TL-2026-1817 — Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Files
  • TL-2026-1823 — SplitVPN (formerly NotVPN) "No-Logs" VPN Breach Exposes 58 Million Connection Logs, 23.4M User Records
  • TL-2026-1822 — COLDCARD Hardware Wallet RNG Flaw Linked to $88.6 Million Bitcoin Theft
  • TL-2026-0336 — Atomic Stealer (AMOS) macOS Campaign via ClickFix Script Editor Abuse

Theme of the day

  • credential-theft
  • social-engineering
  • infostealer
  • sandbox-evasion
  • phishing

Threats published

21 threat lines in the 2026-08-02 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

191 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

7 named threat actors across the reports.

Nation-state attribution

  • Russia
  • North Korea (DPRK)

Threat categories

  • MALWARE
  • PHISHING
  • DATA_BREACH
  • VULNERABILITY
  • SUPPLY_CHAIN

Severity breakdown

  • critical7
  • high9
  • medium5
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

746 indicators of compromise · Red and above. Compare plans
  • network 188
  • file 147
  • behavioral 138
  • entity 94
  • infrastructure 77
  • tool 36
  • malware 22
  • package 22
  • technique 19
  • vulnerability 3
189 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans