Summary & highlights
Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles. AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors. MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer.
Highlights
- TL-2026-2800 — AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- TL-2026-2801 — MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
- TL-2026-2802 — CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- TL-2026-2806 — Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
- TL-2026-2812 — Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
Theme of the day
Unattributed threats dominated, but known actors Star Blizzard, Void Arachne, and Contagious Interview also drove activity. No sector or technique tags were reported.
- remote-code-execution
- rat
- zero-day
- espionage
- infostealer
Threats published
17 threat lines in the 2026-09-30 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)CRITICAL
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code ExecutionCRITICAL
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)CRITICAL
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)CRITICAL
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027CRITICAL
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wildCRITICAL
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation (update)CRITICAL
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog (update)CRITICAL
- AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based BackdoorsHIGH
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerHIGH
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU OrganizationsHIGH
- Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)HIGH
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host filesHIGH
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWormHIGH
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2 (update)HIGH
- Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine (update)HIGH
- Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT RolesMEDIUM
Techniques observed
153 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1003.001
- T1003.003
- T1003.007
- T1005
- T1012
- T1021.001
- T1021.002
- T1027
- T1027.010
- T1027.013
- T1033
- T1036
- T1036.004
- T1036.005
- T1036.008
- T1037.001
- T1040
- T1041
- T1046
- T1053.003
- T1053.005
- T1055
- T1055.002
- T1055.012
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.010
- T1068
- T1069.002
- T1070
- T1070.002
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1078
- T1078.002
- T1078.004
- T1082
- T1083
- T1087
- T1090.001
- T1090.003
- T1098.004
- T1102.001
- T1102.002
- T1105
- T1106
- T1112
- T1114
- T1114.002
- T1132.001
- T1133
- T1134.001
- T1134.004
- T1136
- T1136.002
- T1140
- T1190
- T1195.001
- T1195.002
- T1199
- T1202
- T1203
- T1204.001
- T1204.002
- T1204.003
- T1204.005
- T1210
- T1211
- T1212
- T1213
- T1218
- T1218.002
- T1218.005
- T1218.007
- T1219
- T1451
- T1480
- T1480.001
- T1482
- T1496
- T1497
- T1497.001
- T1497.003
- T1499
- T1499.004
- T1505.003
- T1528
- T1529
- T1539
- T1543
- T1543.001
- T1543.002
- T1546.004
- T1547.001
- T1547.002
- T1548.001
- T1548.003
- T1550
- T1550.002
- T1552
- T1552.001
- T1552.005
- T1553.002
- T1554
- T1555.003
- T1556
- T1557
- T1560
- T1562.001
- T1564.003
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.001
- T1572
- T1573.001
- T1573.002
- T1574.001
- T1574.006
- T1583.001
- T1583.003
- T1583.006
- T1584
- T1585
- T1587.001
- T1587.004
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1591
- T1595.002
- T1608.001
- T1611
- T1614
- T1620
- T1621
- T1622
- T1650
- T1657
- T1685
Threat actors
5 named threat actors across the reports.
Nation-state attribution
- North Korea
- Russia
Threat categories
- THREAT_INTEL
- APT
- SUPPLY_CHAIN
- PHISHING
- VULNERABILITY
- MALWARE
Severity breakdown
- critical8
- high8
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 131
- network 127
- behavioral 52
- infrastructure 45
- entity 43
- package 32
- malware 23
- tool 20