Threadlinqs IntelligenceStart free

Daily debrief · Thursday2026-09-03

Daily Intelligence Briefing — Thursday, September 3, 2026

4 critical12 high1 medium

On 2026-09-03, Threadlinqs published 15 new threat reports and updated 2, 4 rated critical and 12 high, spanning 188 MITRE ATT&CK techniques and 6 named threat actors. Coverage that day added 153 new detection rules and 447 extracted indicators.

New threats
152 updated
Critical / high
164 critical · 12 high
ATT&CK techniques
188Observed in the day’s reports
Threat actors
6Named in the reports
Indicators
447Count only · values are Red+
Detection rules
153New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network. Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding Ransomware Access Brokers. Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain.

Highlights

  • TL-2026-2304 — Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding Ransomware Access Brokers
  • TL-2026-2305 — Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain
  • TL-2026-2308 — US-First RMM Phishing Campaign Spans 46 Countries via Disposable Vercel/Netlify Infrastructure and Password-Protected VBS-to-PowerShell Delivery
  • TL-2026-2310 — Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum Crypto
  • TL-2026-2311 — Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channel

Theme of the day

Unattributed actors dominated today's activity with multiple new threats, while critical exploits targeting Sangoma Switchvox and JFrog Artifactory fueled active RCE and takeover campaigns.

  • credential-theft
  • infostealer
  • social-engineering
  • unauthenticated-rce
  • blockchain-c2

Threats published

17 threat lines in the 2026-09-03 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

188 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

6 named threat actors across the reports.

Nation-state attribution

  • Brazil
  • CN
  • Serbia
  • Russia

Threat categories

  • THREAT_INTEL
  • MALWARE
  • PHISHING
  • APT
  • ICS_SCADA
  • VULNERABILITY
  • RANSOMWARE

Severity breakdown

  • critical4
  • high12
  • medium1
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

447 indicators of compromise · Red and above. Compare plans
  • network 147
  • file 108
  • infrastructure 55
  • entity 40
  • behavioral 29
  • tool 27
  • malware 20
  • package 15
  • technique 6
153 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans