Threadlinqs IntelligenceStart free

Daily debrief · Wednesday2026-09-30

Daily Intelligence Briefing — Wednesday, September 30, 2026

8 critical8 high1 medium

On 2026-09-30, Threadlinqs published 13 new threat reports and updated 4, 8 rated critical and 8 high, spanning 153 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 153 new detection rules and 473 extracted indicators.

New threats
134 updated
Critical / high
168 critical · 8 high
ATT&CK techniques
153Observed in the day’s reports
Threat actors
5Named in the reports
Indicators
473Count only · values are Red+
Detection rules
153New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles. AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors. MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer.

Highlights

  • TL-2026-2800 — AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
  • TL-2026-2801 — MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
  • TL-2026-2802 — CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
  • TL-2026-2806 — Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
  • TL-2026-2812 — Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files

Theme of the day

Unattributed threats dominated, but known actors Star Blizzard, Void Arachne, and Contagious Interview also drove activity. No sector or technique tags were reported.

  • remote-code-execution
  • rat
  • zero-day
  • espionage
  • infostealer

Threats published

17 threat lines in the 2026-09-30 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

153 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

5 named threat actors across the reports.

Nation-state attribution

  • North Korea
  • Russia

Threat categories

  • THREAT_INTEL
  • APT
  • SUPPLY_CHAIN
  • PHISHING
  • VULNERABILITY
  • MALWARE

Severity breakdown

  • critical8
  • high8
  • medium1
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

473 indicators of compromise · Red and above. Compare plans
  • file 131
  • network 127
  • behavioral 52
  • infrastructure 45
  • entity 43
  • package 32
  • malware 23
  • tool 20
153 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans