# Cybersecurity Threat Landscape: 20 Major Attack Campaigns and Vulnerabilities Exposed This Week
The cybersecurity world continues to witness a relentless wave of sophisticated attacks that blur the line between legitimate software and malicious intent. From AI-powered social engineering to hardware-backed identity theft, threat actors are exploiting trust, outdated configurations, and human error at an unprecedented scale. This week alone, researchers and government agencies have uncovered attack chains that span everything from compromised remote access tools to entire phishing ecosystems operating on encrypted messaging platforms.
Here is a comprehensive breakdown of the most significant cybersecurity developments making headlines.
—
## 1. Fraudulent IT Support Exploits Microsoft Teams to Breach Enterprises
Microsoft has issued urgent warnings about a human-operated intrusion campaign that hijacks Teams’ external collaboration features to impersonate IT and help desk personnel. Attackers socially engineer employees into granting interactive remote sessions, which they then use to install malicious software silently.
Once a threat actor gains remote control through legitimate remote monitoring and management (RMM) tools, they deploy PowerShell scripts to silently install malicious MSI packages. These packages stage a portable Node.js runtime along with an obfuscated JavaScript implant that provides persistent command-and-control capabilities. From there, attackers conduct extensive reconnaissance of the host machine and Active Directory, capture screenshots, and pivot across the enterprise using Windows Remote Management (WinRM) to reach high-value targets like domain controllers.
The intrusion pattern has been classified as high-impact because it grants an external operator interactive access to internal infrastructure without requiring a single password compromise.
—
## 2. Large-Scale Voice Phishing Campaign Targets Over 150 Employees
Dubbed **Spring Ring**, a coordinated social engineering operation has been observed abusing external Microsoft Teams accounts to impersonate IT help desk personnel. The campaign targeted more than 150 employees across at least 10 companies spanning multiple industries between January and April 2026.
What begins as a seemingly benign chat conversation quickly escalates into a voice phishing call, during which adversaries pressure victims into executing remote monitoring and management tools or custom malware. In more advanced instances, attackers transitioned from a vishing call directly into a full-scale Microsoft NTLM relay attack targeting an organization’s domain controller.
Researchers at Palo Alto Networks Unit 42 identified as many as 26 distinct attacker identities behind the chat and call attempts, signaling a well-resourced and organized operation.
—
## 3. The Gentlemen Ransomware Claims Over 683 Victims
A detailed report from Sophos reveals that The Gentlemen ransomware operation, tracked as **Gold Sherwood**, has claimed a staggering 683 victims by the end of July 2026 — with 169 new victims added in that month alone.
The operation follows a repeatable affiliate playbook combining opportunistic initial access, rapid privilege escalation, and the use of legitimate remote access mechanisms. Affiliates deploy tool staging in trusted system paths, conduct targeted data exfiltration, and employ aggressive defense evasion techniques. They make use of native Windows utilities, commercial and open-source tools, Bring Your Own Vulnerable Driver (BYOVD)-based EDR killers, and backup service tampering to maximize damage before deploying encryption.
The affiliates demonstrate remarkable operational flexibility, adapting their approach to each victim’s environment to ensure maximum disruption.
—
## 4. Phishing-as-a-Service Platform Remains Resilient Despite Law Enforcement Action
The **Outsider** phishing-as-a-service (PhaaS) platform has proven remarkably resilient in the face of law enforcement action that took down multiple domains related to the service. Operated by a threat actor known as **ChenLun**, the platform continues to churn out phishing campaigns distributed via SMS.
Group-IB reported identifying over 700 new phishing pages created using the kit within a single month after Google filed a civil lawsuit against its operators. The phishing ecosystem is managed through a dedicated Telegram channel, with operators using WebSocket connections for live keylogging and real-time manipulation of multi-factor authentication challenges.
This development underscores a troubling trend: what once required significant technical expertise has been reduced to a subscription service accessible to nearly anyone with an internet connection.
—
## 5. Government-Themed Tax Lures Deploy Sophisticated DLL Sideloading
A government-themed tax notice campaign is actively targeting recipients through U.A.E.- and India-themed tax assessment lures. The campaign persuades victims to open a malicious disc image that contains a legitimate, validly signed commercial executable alongside a hidden, unsigned malicious DLL.
The attack’s core mechanism abuses software trust and DLL sideloading. Once executed, the malicious DLL acts as a loader and establishes multiple execution and persistence mechanisms. It contains three encrypted payloads — two decrypt into legitimately signed kernel drivers from unrelated commercial products, while the third is a persistence script.
The attack chain ultimately paves the way for a Registry-resident second stage that communicates with an external server over UDP, making detection and remediation particularly challenging.
—
## 6. Turnkey Executive Phishing Service Targets CEOs
Security firm ZeroBEC has uncovered **BlueKit**, a turnkey phishing service being used to target CEOs of financial-industry groups for credential theft. The service employs a browser-in-the-middle (BitM) infrastructure and uses document-sharing lures to trigger the attack chain, with a tool called ZeroBot screening for automated defenses.
What makes BlueKit particularly dangerous is its evolution beyond simple credential theft. After the BitM flow, selected victims are moved into a fake document-viewer workflow that delivers a legitimate ScreenConnect client configured for an attacker-controlled cloud instance.
The service is priced at $250 for seven days, $480 for 14 days, and $940 for 30 days — placing it at the higher end of the current phishing-as-a-service market, which includes competitors like Tycoon 2FA ($350/month), Greatness ($289/month), and Forg365 ($400/month).
—
## 7. Iranian Hacking Group Stages 58 Dormant Domains for Future C2 Infrastructure
Researchers have analyzed the infrastructure behind **Prince of Persia** (also known as Indy), a little-known Iranian hacking group deploying malware families Foudre and Tonnerre to profile victims and harvest sensitive data from high-value targets.
The group’s backend is self-authoritative, with each live command-and-control server also running the nameservers for its own domains. Most notably, researchers identified a dormant reserve of 58 domains registered and delegated to the group’s own nameservers, but none currently pointing to any server.
As researcher Kaveh Azarhoosh explained, these domains are “staged, not live” — the moment any one of them gains an address record, a new command server goes live and becomes visible before the server does anything at all. This infrastructure design provides the group with a rapid deployment capability that makes takedown efforts extremely difficult.
—
## 8. Fake Privacy Browser Delivers USB Rubber Ducky Attack Over the Internet
Security researchers at Intezer have detailed a fake “privacy browser” downloaded from a counterfeit website (**www.mxsetuplogi.com**) that transforms remote attacker commands into simulated mouse and keyboard input on a victim’s machine. The site surfaces through a sponsored Google search result after a victim mistypes the domain name in their browser’s address bar.
This attack has been described as a USB Rubber Ducky attack delivered over the internet, effectively bypassing endpoint detection and response (EDR) tools and registering at zero to two detections on VirusTotal. The infection chain begins with a single mistyped letter that routes the victim through a malvertising network into an MSIX installer signed through Microsoft’s own infrastructure.
The campaign has been tracked back to a similar operation from January 2016, indicating the underlying activity has been active for at least a decade.
—
## 9. New Identity Theft Service Advertises Over 153 Million Driver’s Licenses for Sale
The FBI is investigating a dark web identity theft service called **Nexus**, which claims to have digital scans of over 153 million driver’s licenses from people in the United States and Canada. According to independent security journalist Brian Krebs, the service allegedly siphons images collected by a widely used identity verification company called IDScan.net, based in Louisiana.
The service, which launched on the dark web on August 31, 2026, also boasts over 10 million identification cards, more than three million travel documents and international IDs, and at least 579,000 medical cards. Each record can be unlocked for $100. Shortly after the exposé was published, Nexus went offline, and IDScan.net is reportedly investigating the incident.
—
## 10. Malicious AI Instruction Files Exploit llms.txt Misconfigurations
A scan of 6,214 live domains belonging to defense contractors, Fortune 500 companies, and Big Tech firms has uncovered **llms.txt** and **llms-full.txt** files placed at the root of their websites — files designed as curated instruction sets for AI agents.
Of the 8,265 such files surfaced from the scan, 120 featured install instructions pointing to PyPI or npm package names and domains that had never been registered. Researchers deliberately selected a set of package names that appeared in the llms.txt files of well-known companies, registered them on PyPI and npm, and embedded a minimal beacon in each one. The first callback arrived in under four minutes.
At least one active attack has already exploited this misconfiguration: authentication vendor Clerk’s llms.txt included a reference to an npm package named “clerk-next-fix-auth-protection” instead of its actual scoped package. An unknown threat actor registered a public package with the same name, which transmitted the installer’s username, machine name, working directory, and timestamp to an external server. Clerk has since addressed the issue.
—
## 11. Major AI and Tech Coalition Calls for Urgent Cybersecurity Action
A coalition of over 100 companies — including Anthropic, Google, OpenAI, Microsoft, and Perplexity — has published an open letter calling for improvements to cybersecurity as AI continues to compress cyberattack timelines and accelerate the speed and scale of attacks.
The signatories warn that current cybersecurity approaches are not equipped to handle the incoming surge in AI-enabled attacks. Threat actors can leverage AI tools to target longstanding vulnerabilities, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication, and technical debt in legacy systems.
The letter emphasizes that today’s AI advances already give defenders new ways to fix weaknesses that have accumulated for years and urges decisive action to protect critical infrastructure including hospitals, water treatment plants, and the backbone of the internet itself.
—
## 12. Dropbox Breach Exposes 5,000 Accounts Through Legacy Lenovo Integration
Dropbox has disclosed that approximately 5,000 accounts were compromised last month, allowing threat actors to view and download content stored on the cloud-storage platform. The company told Reuters that unauthorized access affected accounts linked to a Lenovo ID that did not have its two-factor authentication enabled.
Dropbox terminated all sessions authenticated through a Lenovo ID. Lenovo said the issue is related to a “legacy integration” between Lenovo ID and Dropbox that “could be used to improperly authenticate certain Dropbox accounts.”
This breach highlights the risks of legacy account linkages and the importance of enabling multi-factor authentication on all connected services.
—
## 13. Microsoft Expands Kernel-Level Memory Protection by Default
Microsoft has announced that it will expand **memory integrity protection** across eligible devices starting October 2026. The initiative aims to provide users with stronger kernel-level protection from sophisticated attacks by default, requiring little or no additional configuration.
Built on **Virtualization-based Security (VBS)**, memory integrity helps protect critical parts of Windows from tampering. The company noted this change reduces security complexity while establishing a stronger security baseline across environments and forms a foundation for modern security innovations such as hotpatch updates.
—
## 14. Pro-Ukraine Ransomware Group Rebrands as VantaCore
A new ransomware group named **VantaCore** has targeted at least seven Russian companies with a proprietary ransomware strain demanding millions of dollars in ransom. The threat actor is assessed to be a rebranding of a known pro-Ukrainian group tracked as **Thor**.
The attacks employ a suite of tools including **VantaCoreLoader** to distribute the ransomware and other malicious programs, **VantaCoreRAT** — a backdoor capable of harvesting system information and executing commands — and **SnowKiller**, which can terminate security software using the BYOVD technique.
—
## 15. Two Nigerian Nationals Extradited to U.S. for Sextortion of Minors
Two Nigerian nationals, **Adebola Festus Adekunle** (26) and **Mudasiru Afeez Olawale** (24), have been extradited to the United States to face prosecution in two separate cases involving the financially motivated sextortion of minors. The crimes led to the death of minors in both the Northern District of Mississippi and the Middle District of North Carolina.
Both defendants face a maximum penalty of life in prison and mandatory minimum prison sentences, with the child exploitation resulting in death charge carrying a minimum penalty of 30 years in prison.
—
## 16. Google Expands Android Ready SE Initiative for Hardware-Backed Digital IDs
Google has announced it is expanding the **Android Ready SE** initiative to bring together silicon vendors, device manufacturers, wallet developers, and government issuers to streamline compliance and scale certified hardware security across the mobile ecosystem.
The development is viewed as a way to scale high-assurance, tamper-resistant digital identity amid accelerating global demand for securely storing national electronic IDs (eIDs) and mobile driver licenses (mDLs) in hardware-backed mobile wallets.
—
## 17. FBI Warns of OAuth Consent Phishing Targeting Prominent Figures
The FBI has issued a warning that malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique called **OAuth consent phishing**.
The attacks target government officials, media personalities, and other publicly known individuals on commercial messaging applications, urging them to access a malicious link under the guise of a file-sharing service through an application under the malicious actor’s control. The FBI noted that previous phishing campaigns have also impersonated event coordinators and planners, sending malicious links under the guise of event invitations requiring identity verification.
—
## 18. Trojanized Electron Apps Distribute Windows Information Stealer
Trojanized Electron desktop applications impersonating legitimate software are being used to distribute a Windows information stealer called **RevStealer**. The malicious applications are shared via GitHub repositories and game-cheat-themed sites, including a fake Claude Opus 5 Free Desktop project.
The malware is delivered by an Electron loader that hides an AES-encrypted native payload inside an application resource, attempts to add the user’s AppData folder to Microsoft Defender’s exclusion list, and launches the payload with no visible window. The malware runs anti-analysis and anti-VM checks before unpacking the main payload.
If the primary command-and-control server is unreachable, RevStealer reads a fallback address from a smart contract on the Polygon blockchain, allowing operators to rotate infrastructure without rebuilding the malware. Notably, the malware is not designed for persistence — it prioritizes capturing as much data as possible in a single run before deleting itself.
—
## 19. Legitimate Faronics Deploy Platform Weaponized for Remote Access
Threat actors are weaponizing **Faronics Deploy**, a legitimate endpoint management platform, to run attacker-controlled PowerShell after phishing victims install the software. Security firm Huntress observed more than 457 endpoints encountering Faronics-related lures.
In observed cases, threat actors chained Faronics Deploy to ScreenConnect, blending malicious remote access activity into trusted software workflows. The delivery method varies between scripts — some use curl or MSHTA to retrieve additional content, while others invoke msiexec to install payloads hosted on attacker-controlled infrastructure. These scripts are subsequently used to install ScreenConnect, establishing an additional remote access mechanism on the compromised endpoint.
—
## 20. Cross-Platform Ransomware-as-a-Service Targets Both Windows and macOS
Security researchers have described **CRPx0** as a ClickFix-delivered ransomware-as-a-service (RaaS) operation that employs lures related to Windows and macOS update prompts and reCAPTCHA checks to trick victims into running copied commands.
On Windows, the attack starts a multi-stage DLL chain. On macOS, it downloads the Python payload directly. The final payload is a cross-platform Python ransomware that exfiltrates data before encryption, encrypts files with AES-128-CBC via Fernet, wraps the per-victim key with an embedded RSA-4096 public key, attempts lateral movement, and drops ransom notes demanding Bitcoin or Monero payment within 48 hours.
The RaaS program first appeared on June 7, 2026, and as of late August, the group has advertised the operation on a clearnet site as an offensive control panel to manage compromised machines, harvest files and credentials, monitor stolen cryptocurrency artifacts, run remote commands, and launch ransomware manually.
—
## Frequently Asked Questions
### What is the most common attack vector highlighted in this week’s cybersecurity threats?
Social engineering remains the most prevalent attack vector. Whether through fake IT support on Microsoft Teams, voice phishing calls, OAuth consent phishing, or ClickFix lures, the vast majority of these attacks rely on manipulating human behavior rather than exploiting technical vulnerabilities. Attackers understand that it is often easier to trick someone into granting access than to break through technical defenses.
### How does DLL sideloading work as an attack technique?
DLL sideloading exploits the Windows dynamic-link library loading mechanism. Attackers place a malicious DLL with the same name as a legitimate library that a trusted application expects to load. When the application runs, it loads the attacker’s DLL instead of the legitimate one, executing malicious code in the context of a trusted process. This technique is particularly effective because the host application is signed and trusted, making it harder for security tools to flag the activity.
### What is the significance of dormant domain infrastructure?
Dormant domains pre-registered by threat actors serve as an insurance policy for command-and-control infrastructure. By registering domains in advance and configuring them with their own nameservers but without pointing them to any active server, attackers can rapidly activate new infrastructure when existing servers are taken down. This makes takedown operations significantly less effective, as new servers can come online almost instantly.
### Why are AI instruction files (llms.txt) being exploited by attackers?
llms.txt and llms-full.txt files are designed to guide AI agents on what resources to access and trust. Attackers are exploiting the fact that many organizations deploy these files without proper security review. By registering malicious package names referenced in these files, attackers create a trust chain where AI agents or the systems that follow their instructions unwittingly pull down and execute malicious code.
### How can organizations protect themselves from RMM tool abuse?
Organizations should implement strict controls on remote access tools, including requiring multi-factor authentication for all RMM sessions, maintaining an approved allowlist of remote access applications, monitoring for unusual remote access patterns, regularly auditing which tools are installed on endpoints, and ensuring that no single user can approve and execute remote sessions without oversight.
### What should I do if I suspect my accounts have been compromised through legacy integrations?
Immediately change your passwords, enable multi-factor authentication on all connected accounts, review and revoke any third-party application access connected to your accounts, check your login activity for unfamiliar sessions, and contact your service provider to disable any legacy integrations you no longer use or recognize.
—
## Conclusion
The cybersecurity threat landscape continues to evolve at a staggering pace. This week’s discoveries reveal a disturbing trend: attackers are increasingly leveraging trust, legitimate tools, and human psychology to bypass traditional defenses. From weaponizing enterprise collaboration platforms like Microsoft Teams to exploiting AI instruction files and pre-staging dormant infrastructure for rapid deployment, the sophistication and scale of these attacks demand a proactive security posture.
Organizations and individuals alike must recognize that changing a password alone is no longer sufficient. Recovery efforts must include terminating all active sessions, revoking unknown application permissions, auditing remote access tools, and scrutinizing every new access request before granting it. As Microsoft’s upcoming expansion of kernel-level memory protection demonstrates, the industry is gradually moving toward stronger default security settings — but the responsibility does not rest solely with vendors.
The safest approach remains vigilant: check what already has access before adding anything new, question unexpected requests for remote sessions or approvals, verify URLs carefully, and ensure that multi-factor authentication is enabled and enforced across all services. The adversaries are adapting quickly, and so must we.
Thank you for reading



