Threadlinqs IntelligenceStart free

Daily debrief · Friday2026-08-28

Daily Intelligence Briefing — Friday, August 28, 2026

11 critical17 high2 medium

On 2026-08-28, Threadlinqs published 25 new threat reports and updated 5, 11 rated critical and 17 high, spanning 209 MITRE ATT&CK techniques and 12 named threat actors. Coverage that day added 270 new detection rules and 642 extracted indicators.

New threats
255 updated
Critical / high
2811 critical · 17 high
ATT&CK techniques
209Observed in the day’s reports
Threat actors
12Named in the reports
Indicators
642Count only · values are Red+
Detection rules
270New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Polymorphic Phishing Page at addresses.performs.vu Regenerates Its Code on Every Load, Defeating Hash-Based Detection. Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake Video-Conference Lures Bypass MFA and Security Awareness Training. Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting.

Highlights

  • TL-2026-2174 — Ghost SPN: Active Directory SPN Misconfigurations Enable Stealthy Kerberoasting
  • TL-2026-2175 — TonRAT Phishing Campaign Impersonating Booking.com Targets Hotel Industry
  • TL-2026-2176 — Silent Ransom Group (Luna Moth) Targets US Law Firms via IT Support Impersonation and Physical Intrusion
  • TL-2026-2180 — July 2026 Domestic APT Attack Trends (South Korea): LNK-Based Spear Phishing Delivering XenoRAT and Info-Stealers
  • TL-2026-2182 — Spark RAT Campaign Targets Cambodia via BYOVD Abuse of Vulnerable OPSWAT AppRemover Driver (CVE-2026-36425)

Theme of the day

Russian state actors targeted EU officials via Signal/WhatsApp account takeover, while unknown groups exploited PaperCut and WatchGuard flaws.

  • phishing
  • social-engineering
  • credential-theft
  • lateral-movement
  • data-exfiltration

Threats published

30 threat lines in the 2026-08-28 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

209 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

12 named threat actors across the reports.

Nation-state attribution

  • Russia
  • Vietnam
  • Iran
  • China

Threat categories

  • PHISHING
  • THREAT_INTEL
  • MALWARE
  • RANSOMWARE
  • APT
  • VULNERABILITY
  • SUPPLY_CHAIN

Severity breakdown

  • critical11
  • high17
  • medium2
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

642 indicators of compromise · Red and above. Compare plans
  • file 158
  • network 151
  • tool 82
  • entity 72
  • behavioral 61
  • infrastructure 55
  • malware 36
  • package 27
270 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans