Threadlinqs IntelligenceStart free

Daily debrief · Wednesday2026-09-02

Daily Intelligence Briefing — Wednesday, September 2, 2026

4 critical11 high2 medium1 low

On 2026-09-02, Threadlinqs published 12 new threat reports and updated 6, 4 rated critical and 11 high, spanning 170 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 162 new detection rules and 408 extracted indicators.

New threats
126 updated
Critical / high
154 critical · 11 high
ATT&CK techniques
170Observed in the day’s reports
Threat actors
5Named in the reports
Indicators
408Count only · values are Red+
Detection rules
162New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks. Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International Coalition. Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time.

Highlights

  • TL-2026-2288 — MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abuse
  • TL-2026-2293 — Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK
  • TL-2026-2294 — Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception
  • TL-2026-2295 — TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
  • TL-2026-2296 — Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts

Theme of the day

Criminal RaaS operators and unattributed actors drove activity, exploiting VPN and RCE flaws while deploying custom implants via social engineering.

  • credential-theft
  • remote-code-execution
  • privilege-escalation
  • social-engineering
  • supply-chain-attack

Threats published

18 threat lines in the 2026-09-02 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

170 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

5 named threat actors across the reports.

Nation-state attribution

  • Russia
  • China
  • North Korea (STARDUST CHOLLIMA); unattributed/eCrime (ALTERED SPIDER)
  • Vietnam
  • Mixed (China-nexus assessed for the Silver Fox truesight.sys campaign; financially motivated for the RaaS affiliates)

Threat categories

  • SUPPLY_CHAIN
  • MALWARE
  • THREAT_INTEL
  • APT
  • VULNERABILITY
  • PHISHING
  • RANSOMWARE

Severity breakdown

  • critical4
  • high11
  • medium2
  • low1

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

408 indicators of compromise · Red and above. Compare plans
  • file 89
  • network 77
  • behavioral 57
  • malware 40
  • entity 39
  • infrastructure 38
  • tool 34
  • package 31
  • technique 3
162 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans