2026-06-11
2026-06-11 13:00Z
MED

Enabling Proper PCI Testing with Internal Penetration Tests

Bishop Fox Labs·bishopfox.com

Bishop Fox publishes a detailed methodology for scoping and executing PCI DSS v4.0.1-compliant internal penetration tests, highlighting expanded scope requirements that now explicitly include cloud infrastructure, SaaS applications, and CI/CD pipelines. The article covers scoping documentation requirements, segmentation testing across network and authentication/authorization controls, and deliverable structure aligned with QSA expectations.

SRFApplicationSRFNetworkTACTA0007SRFCloudTACTA0008TYPResearchSTGDiscoverySTGCred Access
62
Edit Score
2026-06-11
2026-06-11 12:16Z
HIGH

CVE-2026-6552 — GitLab: has remediated an issue in GitLab EE affecting all versions from 15.5 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6552

GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with group Owner role to take over another group member's GitLab account due to improper authorization in the Group SAML identity management functionality. CVSSv3.1 8.7 (HIGH)

CWECWE 639VNDGitlabTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 12:16Z
HIGH

CVE-2026-10087 — GitLab: has remediated an issue in GitLab EE affecting all versions from 17.1 before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10087

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code on behalf of a targeted user due to improper input sanitization in the Analytics Dashboard. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDGitlabTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 09:32Z
CRIT

FSB’s matryoshka #3/3: Gamaredon's Gammasteel Infostealer

Sekoia.io·sekoia.ioin the wild

Sekoia's TDR team published the third installment of their FSB Gamaredon investigation, detailing GammaSteel, a sophisticated PowerShell-based infostealer deployed in January 2026 campaigns targeting Ukrainian government and critical infrastructure. The malware operates fileless in memory using DPAPI encryption, stages 71 obfuscated functions in the Windows registry (HKCU\Printers), and exfiltrates documents via three concurrent mechanisms: hourly drive scans, USB insertion monitoring, and real-time file-change surveillance. Data is deduplicated locally against MD5 hashes and uploaded to S3-compatible cloud storage (Tebi.io) with fallback to operator-controlled C2 servers.

SRFOsTACTA0007TACTA0009TACTA0010SWPowershellVNDMicrosoftTYPResearchSTGDiscovery
88
Edit Score
2026-06-11
2026-06-11 09:32Z
HIGH

FSB’s matryoshka #2/3: Gamaredon's Gammaload Malware

Sekoia.io·sekoia.ioin the wild

Sekoia.io's TDR team published a detailed technical analysis of Gamaredon's GammaLoad malware—a three-stage VBScript/PowerShell loader chain used by the FSB-linked intrusion set to stage and deploy the GammaSteel stealer. The infection chain uses registry-cached C2 URLs, Dead Drop Resolvers (Telegraph, Telegram, Check-Host) for failover, Alternate Data Streams for persistence via scheduled tasks, and multi-stage in-memory execution to evade detection. This is part 2 of a 3-part series documenting Gamaredon's 2026 arsenal targeting Ukrainian government and critical infrastructure.

SRFApplicationTACTA0005TACTA0001SRFNetworkTACTA0003TACTA0011OSWindowsSWGamaredon
82
Edit Score
2026-06-11
2026-06-11 09:31Z
CRIT

FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations

Sekoia.io·sekoia.ioCVE-2025-8088CVE-2018-20250in the wild

Sekoia's TDR team published a comprehensive analysis of Gamaredon (FSB-linked APT targeting Ukraine) detailing a January 2026 infection chain spanning initial phishing (GammaPhish), modular loaders (GammaLoad), USB/network propagation worms (GammaWorm), and registry-staged stealers (GammaSteel). The campaign exploits CVE-2025-8088 in WinRAR to extract HTA files into Windows Startup, leverages HTML smuggling and mshta.exe for code execution, and uses NTFS Alternate Data Streams, Dead Drop Resolvers, and S3-compatible cloud storage for C2 and exfiltration. The report establishes a unified taxonomy across fragmented vendor nomenclature and confirms Gamaredon's shift from the Pteranodon framework to a modular architecture where every stage functions as an independent backdoor.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006TACTA0007SRFWebTACTA0003
88
Edit Score
2026-06-11
2026-06-11 09:31Z
HIGH

From APT28 to RePythonNET: automating .NET malware analysis

Sekoia.io·sekoia.io

Sekoia's TDR team released RePythonNET-MCP, an open-source tool for automating .NET malware analysis. The post details methodology for reverse-engineering obfuscated .NET implants (specifically APT28's Covenant), combining pythonnet and dnlib to automate string decryption via IL signature matching, then wrapping ILSpy's decompiler as an MCP server to enable AI-assisted analysis of decompiled C# code.

SRFApplicationTACTA0005SWCovenantSWDnlibSWIlspySWPythonnetTYPResearchTYPTool
78
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-11
2026-06-11 09:31Z
CRIT

EvilTokens: AI PhaaS for automating BEC fraud - Part 2

Sekoia.io·sekoia.ioin the wild

Sekoia TDR published Part 2 of their EvilTokens analysis, detailing a fully-operationalized Phishing-as-a-Service (PhaaS) platform selling Microsoft device code phishing kits since February 2026. The service includes AI-driven post-compromise tooling that automatically analyzes stolen emails via Graph API reconnaissance, identifies financial exposure, and generates tailored BEC attack emails using Groq/OpenAI LLMs. EvilTokens operates via Telegram bots with lifetime panel access for $1,500 plus $500/month licensing, and includes a custom "Portal Browser" for managing multiple compromised M365 accounts with token refresh automation.

SRFApplicationTACTA0001TACTA0006TACTA0007SRFIdentitySRFCloudTACTA0009TYPResearch
92
Edit Score
2026-06-11
2026-06-11 09:30Z
CRIT

EvilTokens Kit: Device Code Phishing-as-a-service - Part 1

Sekoia.io·sekoia.ioin the wild

Sekoia TDR uncovered EvilTokens, a sophisticated device code phishing-as-a-service kit targeting Microsoft 365 accounts. The kit exploits Microsoft's OAuth 2.0 device authorization flow to harvest access and refresh tokens, which can be converted to Primary Refresh Tokens (PRTs) enabling 90-day silent access and MFA bypass. The backend exposes REST APIs for token weaponization, cookie generation, and Azure/Graph reconnaissance, with campaigns actively delivering phishing lures across multiple file formats (PDF, HTML, XLSX, SVG, DOCX) to organizations globally.

TACTA0001TACTA0006SRFIdentitySRFCloudSWEntra IdSWMicrosoft 365VNDMicrosoftTYPResearch
92
Edit Score
2026-06-11
2026-06-11 09:30Z
HIGH

UEBA vs. Stealth Intrusions: Catching Identity & Credential Abuse

Sekoia.io·sekoia.io

Sekoia publishes a practitioner-focused guide on using User and Entity Behavior Analytics (UEBA) to detect credential-abuse and identity-driven intrusions that evade traditional indicator-based SOC rules. The article presents five real-world attack scenarios—valid-account lateral movement, MFA fatigue, OAuth abuse, cloud console misuse, and insider exfiltration—and explains how behavioral baselines and context-correlation catch attackers operating through legitimate tools and authentication flows.

SRFApplicationTACTA0001SRFIdentityTACTA0003SRFCloudTACTA0008TYPResearchSTGInitial Access
72
Edit Score
2026-06-11
2026-06-11 09:30Z
HIGH

Silver Fox: The only Tax Audit Where Fine Print Installs Malware

Sekoia.io·sekoia.io

Sekoia's TDR team tracks Silver Fox, a China-based intrusion set, through three distinct campaign waves (2025–2026) targeting South Asian entities with tax-themed phishing. The group evolved from ValleyRAT delivery via malicious PDFs to abusing a misconfigured Chinese RMM tool, then to a custom Python-based WhatsApp stealer, while maintaining dual objectives: opportunistic cybercrime and APT-style espionage operations.

SRFApplicationTACTA0001TACTA0002SRFNetworkTACTA0006TACTA0007TACTA0003VNDSekoia
78
Edit Score
2026-06-11
2026-06-11 09:30Z
HIGH

Shadow IT: The Initial Access You Didn’t Log

Sekoia.io·sekoia.io

Sekoia's research documents five recurring attack patterns where adversaries exploit shadow IT—unmanaged organizational assets invisible to SOC telemetry—to establish initial access: unpatched edge infrastructure (VPN/Citrix), exposed cloud storage repurposed as staging, OAuth persistence in unmonitored tenants, leaked credentials in developer ecosystems, and domain lifecycle abuse. The core insight is that attackers map organizations externally (domains, certificates, cloud tenants, repositories) while defenders map only managed, inward-facing assets, creating a visibility gap where compromise occurs before detection infrastructure exists.

SRFApplicationTACTA0001SRFNetworkTACTA0007SRFCloudTYPResearchSTGDiscoverySTGInitial Access
72
Edit Score
2026-06-11
2026-06-11 09:30Z
HIGH

OysterLoader Unmasked: The Multi-Stage Evasion Loader

Sekoia.io·sekoia.ioin the wild

Sekoia's analysis of OysterLoader (aka Broomstick, CleanUp) dissects a four-stage C++ loader primarily used to deliver Rhysida ransomware and Vidar infostealer. The malware employs API hammering, custom LZMA decompression with non-standard headers, steganography-embedded payloads, and spoofed HTTP headers to evade detection. Distribution occurs via fake installer websites impersonating legitimate tools like PuTTY and WinSCP.

SRFApplicationSRFOsTACTA0005TACTA0001TACTA0011OSWindowsTYPResearchTYPThreat Intel
72
Edit Score
2026-06-11
2026-06-11 09:29Z
HIGH

Meet IClickFix: a widespread framework using the ClickFix tactic

Sekoia.io·sekoia.ioin the wild

Sekoia TDR researchers disclosed IClickFix, a widespread malware distribution framework injected into over 3,800 compromised WordPress sites across 82 countries since December 2024. The framework uses the ClickFix social engineering tactic—a fake Cloudflare Turnstile CAPTCHA—to trick users into executing a PowerShell command that delivers NetSupport RAT. The operator abuses the open-source YOURLS URL shortener as a Traffic Distribution System (TDS) to filter visitors and evade detection.

SRFApplicationTACTA0005TACTA0001TACTA0002SRFWebTACTA0003SWWordpressSWNetsupport
78
Edit Score
2026-06-11
2026-06-11 09:29Z
MED

Leveraging Landlock Telemetry for Linux Detection Engineering

Sekoia.io·sekoia.ioCVE-2024-3094

Sekoia TDR explores Landlock, a Linux Security Module available since kernel 5.13, as both a hardening mechanism and telemetry source for detection engineering. Since kernel 6.15, Landlock denials flow into the Audit system with low false-positive rates. The post demonstrates practical detection use cases including filesystem/network sandbox violations and references the XZ Utils supply chain attack where the attacker deliberately disabled Landlock compilation.

SRFOsTACTA0005TACTA0011OSLinuxTYPResearchSTGDefense EvasionTECT1562
72
Edit Score
2026-06-11
2026-06-11 09:29Z
INFO

Advent of Config Extraction, Part 4: Extracting TinyShell Configs

Sekoia.io·sekoia.io

Sekoia's TDR team demonstrates a configuration extraction pipeline for TinyShell-derived Linux backdoors using capa for RC4 function detection, Capstone for instruction analysis, and LIEF/malduck for decryption. The technique locates obfuscated C2 configuration data in stripped ELF binaries by identifying RC4 PRGA encryption routines, reconstructing stack-based keys, and decrypting contiguous data blobs from read-only sections.

SRFApplicationTACTA0007SWCapaSWCapstoneSWLiefSWMalduckTYPResearchTYPTool
68
Edit Score
2026-06-11
2026-06-11 09:29Z
HIGH

Advent of Configuration Extraction, Part 3: SNOWLIGHT Config

Sekoia.io·sekoia.io

Sekoia's TDR team publishes Part 3 of their Advent of Configuration Extraction series, detailing reverse-engineering methodology for SNOWLIGHT, a sub-10KB ELF downloader attributed to UNC5174 campaigns. The writeup demonstrates automated extraction of C2 configuration (IP and TCP port) using LIEF for ELF parsing and Capstone for disassembly, with focus on GOT/PLT resolution to identify dynamically-linked function calls and recover hardcoded network parameters.

SRFApplicationSRFOsTACTA0007OSLinuxTYPResearchTYPWriteupSTGDiscoverySTGRecon
72
Edit Score
2026-06-11
2026-06-11 09:28Z
MED

Advent of Configuration Extraction, Part 2: QuasarRAT Config

Sekoia.io·sekoia.io

Sekoia's TDR team publishes a technical deep-dive on extracting QuasarRAT configuration from both clean and obfuscated .NET samples using pythonnet and dnlib. The article demonstrates IL-level analysis to recover plaintext configs from unobfuscated builds and AES-256 CBC decryption techniques for obfuscated variants, with reproducible Jupyter Notebook code.

SRFApplicationTACTA0007SWQuasarratTYPResearchTYPWriteupSTGDiscoveryEXPDeserialization
72
Edit Score
2026-06-11
2026-06-11 09:28Z
INFO

Advent of Configuration Extraction, Part 1: Kaiji Configuration

Sekoia.io·sekoia.ioCVE-2024-7954CVE-2023-1389

Sekoia's TDR team publishes Part 1 of an Advent of Configuration Extraction series, detailing their automated malware configuration extraction pipeline built on Assemblyline and MACO. The article walks through extracting C2 configuration from Kaiji, a Go-based IoT botnet, by identifying Base64-encoded strings preceded by a marker, decoding them, and normalizing the output into structured MACO fields for threat intelligence ingestion.

SRFApplicationSWKaijiSWAssemblylineSWFlossSWMacoTYPResearchTYPToolSTGDiscovery
68
Edit Score
2026-06-11
2026-06-11 09:28Z
HIGH

Calisto Targets Reporters Without Borders in Phishing Campaign

Sekoia.io·sekoia.io

Sekoia TDR analyzed a 2025 spear-phishing campaign by Calisto (FSB Center 18/Star Blizzard) targeting Reporters Without Borders and a second organization. The campaign used ProtonMail impersonation with a homemade AiTM phishing kit, leveraging the signature Calisto tactic of sending emails with missing/broken attachments to prompt credential-harvesting follow-ups. The phishing kit employed patched JavaScript to relay two-factor authentication and was hosted on compromised websites via PHP redirectors.

TACTA0001TACTA0006SRFIdentitySRFWebTYPResearchTYPThreat IntelSTGInitial AccessSTGCred Access
72
Edit Score
2026-06-11
2026-06-11 09:28Z
HIGH

Booking.com Phishing Campaign Targeting Hotels and Customers

Sekoia.io·sekoia.ioin the wild

Sekoia.io researchers exposed the "I Paid Twice" phishing campaign targeting Booking.com hotels and customers since April 2025. Threat actors compromise hotel admin accounts via ClickFix social engineering, deploy PureRAT malware for persistence, then use stolen reservation data to phish guests with banking credential harvesting pages. The campaign leverages a professionalized cybercrime ecosystem selling Booking.com credentials, log checkers, and traffic distribution services.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006SRFWebTACTA0003TACTA0009
78
Edit Score
2026-06-11
2026-06-11 09:28Z
HIGH

TransparentTribe Targets Indian Military with DeskRAT Malware

Sekoia.io·sekoia.ioin the wild

Sekoia's TDR team analyzed a TransparentTribe (APT36) campaign targeting Indian military entities on Linux systems with DeskRAT, a Golang-based RAT. The infection chain begins with phishing emails containing ZIP archives with malicious .desktop files that hide bash commands between PNG data blocks, ultimately delivering DeskRAT which establishes persistence via four Linux methods and communicates over insecure WebSocket. The campaign opportunistically leverages geopolitical events such as the September 2025 Ladakh unrest to increase social engineering effectiveness.

SRFApplicationSRFOsTACTA0005TACTA0001TACTA0003TACTA0011OSLinuxSWDeskrat
78
Edit Score
2026-06-11
2026-06-11 09:28Z
INFO

UserAuthenticationMethod: Understanding M365 Sign-In Logs

Sekoia.io·sekoia.io

Sekoia.io documents the previously undocumented UserAuthenticationMethod field in Microsoft 365 audit logs, revealing it is a bitfield where each bit position maps to a distinct authentication method. Through correlation with Entra ID sign-in logs using shared correlation identifiers, researchers decoded 24 bit positions representing authentication methods ranging from password variants to passkeys and Windows Hello for Business. The field accumulates values during multi-factor authentication flows, capturing both primary and secondary factors in a single numeric value.

TACTA0006SRFIdentitySRFCloudSWEntra IdSWMicrosoft 365VNDMicrosoftTYPResearchTECT1110
72
Edit Score
2026-06-11
2026-06-11 09:27Z
HIGH

PolarEdge Backdoor on QNAP: CVE-2023-20118 Analysis

Sekoia.io·sekoia.ioCVE-2023-20118in the wild

Sekoia TDR reverse-engineered the PolarEdge Backdoor, a TLS-based implant deployed on QNAP, Cisco, Asus, and Synology devices via CVE-2023-20118. The 1.6 MB ELF binary implements a custom mbedTLS server listening on port 49254 for unauthenticated binary protocol commands, with configuration obfuscated via one-byte XOR and PRESENT block cipher encryption. The implant includes anti-analysis techniques (process masquerading, /proc remounting, watchdog fork), daily host fingerprinting to C2, and auxiliary connect-back and debug modes for C2 updates.

SRFOsTACTA0005TACTA0001SRFNetwork ApplianceTACTA0003TACTA0011VNDSynologyVNDCisco
78
Edit Score
2026-06-11
2026-06-11 09:27Z
HIGH

APT28 Operation Phantom Net Voxel: BeardShell & Covenant

Sekoia.io·sekoia.ioin the wild

Sekoia TDR published a detailed technical analysis of APT28's Operation Phantom Net Voxel targeting Ukrainian military personnel via Signal Desktop. The campaign chains weaponized Office documents with VBA macros, COM-hijack DLL persistence, PNG steganography to extract shellcode, Covenant Grunt C2 via Koofr cloud API, and BeardShell backdoor via icedrive. Analysis of compromised Koofr accounts revealed 42 unique infected hosts dating back to December 2024, with exfiltrated reconnaissance data.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0003SRFCloudTACTA0011OSWindows
88
Edit Score