Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-09-01

Daily Intelligence Briefing — Tuesday, September 1, 2026

8 critical10 high1 medium1 low

On 2026-09-01, Threadlinqs published 12 new threat reports and updated 8, 8 rated critical and 10 high, spanning 221 MITRE ATT&CK techniques and 10 named threat actors. Coverage that day added 180 new detection rules and 605 extracted indicators.

New threats
128 updated
Critical / high
188 critical · 10 high
ATT&CK techniques
221Observed in the day’s reports
Threat actors
10Named in the reports
Indicators
605Count only · values are Red+
Detection rules
180New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors. "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay. Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion Operations.

Highlights

  • TL-2026-2273 — EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors
  • TL-2026-2276 — "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay
  • TL-2026-2278 — Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion Operations
  • TL-2026-2279 — Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads Malvertising
  • TL-2026-2283 — Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor Download Sites

Theme of the day

Routine activity — no dominant theme emerged.

  • credential-theft
  • social-engineering
  • cisa-kev
  • clickfix
  • smb-lateral-movement

Threats published

20 threat lines in the 2026-09-01 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

221 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

10 named threat actors across the reports.

Nation-state attribution

  • North Korea, Iran
  • Russia
  • Pakistan
  • North Korea
  • China

Threat categories

  • MALWARE
  • PHISHING
  • RANSOMWARE
  • APT
  • VULNERABILITY
  • SUPPLY_CHAIN

Severity breakdown

  • critical8
  • high10
  • medium1
  • low1

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

605 indicators of compromise · Red and above. Compare plans
  • network 185
  • file 183
  • behavioral 61
  • entity 48
  • tool 47
  • infrastructure 44
  • malware 30
  • package 7
180 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans