Summary & highlights
Fake American Express "non-compliance" card-lock phishing campaign targets Australians. Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a Service. PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/Channels.
Highlights
- TL-2026-2766 — Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock Binaries
- TL-2026-2767 — OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
- TL-2026-2768 — Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data
- TL-2026-2773 — SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- TL-2026-2774 — AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
Theme of the day
Activity centered on account-takeover, american-express, amex.
- phishing
- credential-theft
- social-engineering
- unattributed
- windows
Threats published
26 threat lines in the 2026-09-29 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation)CRITICAL
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible Zero-Day Attack (update)CRITICAL
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat (update)CRITICAL
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of Canon and Stardock BinariesHIGH
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX InstallersHIGH
- Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order DataHIGH
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows DefensesHIGH
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity VerificationHIGH
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 SignalingHIGH
- CVE-2026-50610: Acer System Monitor (NitroSense/PredatorSense) local privilege escalation from standard user to SYSTEM via unauthenticated named pipe registry writeHIGH
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)HIGH
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent AccessHIGH
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)HIGH
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond UkraineHIGH
- Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508)HIGH
- Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS, information leaks)HIGH
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining (update)HIGH
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft (update)HIGH
- NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations (update)HIGH
- RatHat Android RAT: MaaS Consoles Add Gemini AI-Driven Victim Prioritization (update)HIGH
- Remcos RAT phishing campaign disguised as project material purchase requests exploits CVE-2017-0199 against Korean companies (update)HIGH
- CaptiveCrunch: Midnight Blizzard (Storm-2945) Hospitality Captive-Portal AiTM Campaign (update)HIGH
- Fake American Express "non-compliance" card-lock phishing campaign targets AustraliansMEDIUM
- Hacker-for-Hire Economy: Cyber Mercenaries Offer Account Compromise, Surveillance, Doxxing and DDoS as a ServiceMEDIUM
- PhantomSub: 101 Malicious npm Baileys Forks Force Developers' WhatsApp Accounts into Attacker-Controlled Groups/ChannelsMEDIUM
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ OrganizationsMEDIUM
Techniques observed
192 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0034
- T1003.008
- T1005
- T1014
- T1016
- T1018
- T1020
- T1021.002
- T1021.004
- T1027
- T1027.001
- T1027.003
- T1027.007
- T1027.009
- T1027.013
- T1033
- T1036
- T1036.001
- T1036.004
- T1036.005
- T1036.008
- T1037.004
- T1041
- T1046
- T1047
- T1053.003
- T1053.005
- T1053.006
- T1055
- T1055.012
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1069.002
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1078
- T1078.004
- T1082
- T1083
- T1087.004
- T1090
- T1090.002
- T1098.004
- T1098.005
- T1102.001
- T1102.002
- T1105
- T1110.003
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1114.003
- T1119
- T1123
- T1125
- T1129
- T1132.001
- T1140
- T1190
- T1195.001
- T1195.002
- T1202
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1212
- T1213.003
- T1217
- T1218.002
- T1218.005
- T1218.007
- T1218.011
- T1219
- T1219.002
- T1222.001
- T1222.002
- T1406
- T1417.001
- T1417.002
- T1426
- T1429
- T1437.001
- T1451
- T1453
- T1482
- T1489
- T1490
- T1496
- T1497.001
- T1497.003
- T1498.001
- T1498.002
- T1499.002
- T1499.003
- T1499.004
- T1505.003
- T1512
- T1513
- T1516
- T1517
- T1518.001
- T1528
- T1539
- T1541
- T1543.002
- T1543.003
- T1544
- T1546.012
- T1546.015
- T1547.001
- T1548.002
- T1550.001
- T1550.002
- T1552.001
- T1553.002
- T1553.005
- T1555.003
- T1555.005
- T1557
- T1560.001
- T1560.003
- T1562.004
- T1564.001
- T1564.003
- T1565.002
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1566.004
- T1567
- T1568
- T1568.001
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574.001
- T1574.002
- T1574.011
- T1577
- T1583.001
- T1583.006
- T1583.008
- T1584
- T1584.008
- T1585.001
- T1586.002
- T1588.005
- T1588.007
- T1589
- T1589.001
- T1595.002
- T1598
- T1598.003
- T1608.005
- T1609
- T1610
- T1611
- T1620
- T1622
- T1623.001
- T1626
- T1629.001
- T1633
- T1636.003
- T1636.004
- T1651
- T1655
- T1655.001
- T1657
- T1660
- T1663
- T1684.001
- T1684.002
- T1685
- T1685.005
Threat actors
7 named threat actors across the reports.
Nation-state attribution
- North Korea
- Russia
- Costa Rica
- China (suspected; Microsoft has not formally attributed Storm-3069 to a Chinese nation-state actor)
- China
Threat categories
- PHISHING
- THREAT_INTEL
- SUPPLY_CHAIN
- MALWARE
- DATA_BREACH
- VULNERABILITY
- APT
- ZERO_DAY
Severity breakdown
- critical3
- high19
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 173
- file 155
- entity 66
- infrastructure 41
- malware 40
- behavioral 37
- tool 27
- package 23