talos · Crawled Aug 1, 2026

You were onto something with “It’s the Climb,” Miley

15 IoCs
Read original article ↗

AI Summary

In Q2 2026, Talos observed a significant increase in phishing attacks and authentication abuse, with over half of incident responses linked to phishing campaigns leveraging QR codes and platforms like ARToken to bypass multi-factor authentication (MFA). Ransomware actors are increasingly abusing legitimate remote management tools such as MeshAgent and Zoho Assist to establish stealthy, persistent access within networks. A new malware named msaRAT, used by the Chaos ransomware group, hijacks browsers to create covert command-and-control (C2) channels via WebRTC over TURN, enabling remote command execution while concealing attacker infrastructure.

AI-extracted · verify before operational use

Indicators of Compromise 15 extracted

Type Value Detail
SHA-256 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 Details →
MD5 2915b3f8b703eb744fc54c81f4a9c67f Details →
Filename VID001.exe Details →
SHA-256 a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 Details →
MD5 7bdbd180c081fa63ca94f9c22c457376 Details →
Filename d4aa3e7010220ad1b458fac17039c274_62_Exe.exe Details →
SHA-256 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f Details →
MD5 38de5b216c33833af710e88f7f64fc98 Details →
Filename SECOH-QAD.exe Details →
SHA-256 fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 Details →
MD5 ded73d04bb3e3525226de64c38a332e3 Details →
Filename f_000177.exe Details →
SHA-256 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 Details →
MD5 c2efb2dcacba6d3ccc175b6ce1b7ed0a Details →
Filename tmp00055df5.dll Details →