# Daily Intelligence Briefing — Wednesday, September 30, 2026

> On 2026-09-30, Threadlinqs published 13 new threat reports and updated 4, 8 rated critical and 8 high, spanning 153 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 153 new detection rules and 473 extracted indicators.

- **Edition:** 2026-09-30 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-30
- **Last updated:** 2026-10-05
- **New threats:** 13 (4 updated)
- **Critical / high:** 8 critical, 8 high, 1 medium, 0 low
- **ATT&CK techniques:** 153
- **Threat actors:** 5
- **Indicators (count only):** 473
- **New detection rules (count only):** 153

## Summary & highlights

Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles. AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors. MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer.

- [TL-2026-2800](https://intel.threadlinqs.com/threat/TL-2026-2800) — AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- [TL-2026-2801](https://intel.threadlinqs.com/threat/TL-2026-2801) — MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
- [TL-2026-2802](https://intel.threadlinqs.com/threat/TL-2026-2802) — CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- [TL-2026-2806](https://intel.threadlinqs.com/threat/TL-2026-2806) — Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
- [TL-2026-2812](https://intel.threadlinqs.com/threat/TL-2026-2812) — Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files

## Theme of the day

Unattributed threats dominated, but known actors Star Blizzard, Void Arachne, and Contagious Interview also drove activity. No sector or technique tags were reported.

remote-code-execution, rat, zero-day, espionage, infostealer

## Threats published

- [TL-2026-2803](https://intel.threadlinqs.com/threat/TL-2026-2803) — CRITICAL — Google Chrome 154 Update Fixes 32 Security Flaws Including Critical ANGLE Buffer Overflow (CVE-2026-102331)
- [TL-2026-2805](https://intel.threadlinqs.com/threat/TL-2026-2805) — CRITICAL — Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote Code Execution
- [TL-2026-2813](https://intel.threadlinqs.com/threat/TL-2026-2813) — CRITICAL — WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)
- [TL-2026-2816](https://intel.threadlinqs.com/threat/TL-2026-2816) — CRITICAL — CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)
- [TL-2026-2818](https://intel.threadlinqs.com/threat/TL-2026-2818) — CRITICAL — GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027
- [TL-2026-2820](https://intel.threadlinqs.com/threat/TL-2026-2820) — CRITICAL — Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
- [TL-2026-2184](https://intel.threadlinqs.com/threat/TL-2026-2184) — CRITICAL — PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation (update)
- [TL-2026-2711](https://intel.threadlinqs.com/threat/TL-2026-2711) — CRITICAL — CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog (update)
- [TL-2026-2800](https://intel.threadlinqs.com/threat/TL-2026-2800) — HIGH — AhnLab ASEC August 2026 APT Attack Trend Report (South Korea): LNK Spear Phishing Delivering XenoRAT and Script-Based Backdoors
- [TL-2026-2801](https://intel.threadlinqs.com/threat/TL-2026-2801) — HIGH — MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer
- [TL-2026-2802](https://intel.threadlinqs.com/threat/TL-2026-2802) — HIGH — CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- [TL-2026-2806](https://intel.threadlinqs.com/threat/TL-2026-2806) — HIGH — Mini Shai-Hulud: Compromised @antv npm Packages Steal Developer and CI/CD Credentials (TeamPCP)
- [TL-2026-2812](https://intel.threadlinqs.com/threat/TL-2026-2812) — HIGH — Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
- [TL-2026-2819](https://intel.threadlinqs.com/threat/TL-2026-2819) — HIGH — 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- [TL-2026-2635](https://intel.threadlinqs.com/threat/TL-2026-2635) — HIGH — DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2 (update)
- [TL-2026-2795](https://intel.threadlinqs.com/threat/TL-2026-2795) — HIGH — Star Blizzard (FSB) RedFlick mass-phishing campaigns deliver CosmicPulse backdoor, expanding beyond Ukraine (update)
- [TL-2026-2799](https://intel.threadlinqs.com/threat/TL-2026-2799) — MEDIUM — Insiders for Hire: Underground Market for Employee Access Expands Beyond Privileged IT Roles

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1003.003](https://intel.threadlinqs.com/technique/T1003.003), [T1003.007](https://intel.threadlinqs.com/technique/T1003.007), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), T1037.001, [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), T1055.002, [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), T1059.010, [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069.002](https://intel.threadlinqs.com/technique/T1069.002), [T1070](https://intel.threadlinqs.com/technique/T1070), T1070.002, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.002](https://intel.threadlinqs.com/technique/T1078.002), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1098.004](https://intel.threadlinqs.com/technique/T1098.004), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1132.001](https://intel.threadlinqs.com/technique/T1132.001), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134.001](https://intel.threadlinqs.com/technique/T1134.001), T1134.004, [T1136](https://intel.threadlinqs.com/technique/T1136), [T1136.002](https://intel.threadlinqs.com/technique/T1136.002), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1202](https://intel.threadlinqs.com/technique/T1202), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1204.003](https://intel.threadlinqs.com/technique/T1204.003), T1204.005, [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1218](https://intel.threadlinqs.com/technique/T1218), T1218.002, [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1219](https://intel.threadlinqs.com/technique/T1219), T1451, [T1480](https://intel.threadlinqs.com/technique/T1480), [T1480.001](https://intel.threadlinqs.com/technique/T1480.001), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1497.003](https://intel.threadlinqs.com/technique/T1497.003), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), T1547.002, [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1548.003](https://intel.threadlinqs.com/technique/T1548.003), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.002](https://intel.threadlinqs.com/technique/T1550.002), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), T1562.001, [T1564.003](https://intel.threadlinqs.com/technique/T1564.003), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.001](https://intel.threadlinqs.com/technique/T1567.001), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1591](https://intel.threadlinqs.com/technique/T1591), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1621](https://intel.threadlinqs.com/technique/T1621), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1650](https://intel.threadlinqs.com/technique/T1650), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1685](https://intel.threadlinqs.com/technique/T1685)

## Threat actors

[SHADOWBYT3$](https://intel.threadlinqs.com/actor/SHADOWBYT3%24), [MALFEX operator](https://intel.threadlinqs.com/actor/MALFEX%20operator), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group), [Star Blizzard](https://intel.threadlinqs.com/actor/Star%20Blizzard)

Nation-state attribution: North Korea, Russia

Threat categories: THREAT_INTEL, APT, SUPPLY_CHAIN, PHISHING, VULNERABILITY, MALWARE

## Severity breakdown

- critical: 8
- high: 8
- medium: 1
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 473 (file 131, network 127, behavioral 52, infrastructure 45, entity 43, package 32, malware 23, tool 20)
- New detection rules: 153 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-29](https://intel.threadlinqs.com/debrief/2026-09-29)
- Next: [2026-10-02](https://intel.threadlinqs.com/debrief/2026-10-02)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-30
