Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-09-29

Daily Intelligence Briefing — Tuesday, September 29, 2026

3 critical19 high4 medium

On 2026-09-29, Threadlinqs published 18 new threat reports and updated 8, 3 rated critical and 19 high, spanning 192 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 234 new detection rules and 562 extracted indicators.

New threats
188 updated
Critical / high
223 critical · 19 high
ATT&CK techniques
192Observed in the day’s reports
Threat actors
7Named in the reports
Indicators
562Count only · values are Red+
Detection rules
234New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Fake American Express "non-compliance" card-lock phishing campaign targets Australians. Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a Service. PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels.

Highlights

  • TL-2026-2766 — Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
  • TL-2026-2767 — OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
  • TL-2026-2768 — Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data
  • TL-2026-2773 — SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
  • TL-2026-2774 — AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification

Theme of the day

Activity centered on account-takeover, american-express, amex.

  • phishing
  • credential-theft
  • social-engineering
  • unattributed
  • windows

Threats published

26 threat lines in the 2026-09-29 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

192 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

7 named threat actors across the reports.

Nation-state attribution

  • North Korea
  • Russia
  • Costa Rica
  • China (suspected; Microsoft has not formally attributed Storm-3069 to a Chinese nation-state actor)
  • China

Threat categories

  • PHISHING
  • THREAT_INTEL
  • SUPPLY_CHAIN
  • MALWARE
  • DATA_BREACH
  • VULNERABILITY
  • APT
  • ZERO_DAY

Severity breakdown

  • critical3
  • high19
  • medium4
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

562 indicators of compromise · Red and above. Compare plans
  • network 173
  • file 155
  • entity 66
  • infrastructure 41
  • malware 40
  • behavioral 37
  • tool 27
  • package 23
234 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans