talos · Crawled Aug 1, 2026
You were onto something with “It’s the Climb,” Miley
15 IoCs
Read original article ↗
AI Summary
In Q2 2026, Talos observed a significant increase in phishing attacks and authentication abuse, with over half of incident responses linked to phishing campaigns leveraging QR codes and platforms like ARToken to bypass multi-factor authentication (MFA). Ransomware actors are increasingly abusing legitimate remote management tools such as MeshAgent and Zoho Assist to establish stealthy, persistent access within networks. A new malware named msaRAT, used by the Chaos ransomware group, hijacks browsers to create covert command-and-control (C2) channels via WebRTC over TURN, enabling remote command execution while concealing attacker infrastructure.
AI-extracted · verify before operational use
Indicators of Compromise 15 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | Details → |
| MD5 | 2915b3f8b703eb744fc54c81f4a9c67f | Details → |
| Filename | VID001.exe | Details → |
| SHA-256 | a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 | Details → |
| MD5 | 7bdbd180c081fa63ca94f9c22c457376 | Details → |
| Filename | d4aa3e7010220ad1b458fac17039c274_62_Exe.exe | Details → |
| SHA-256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | Details → |
| MD5 | 38de5b216c33833af710e88f7f64fc98 | Details → |
| Filename | SECOH-QAD.exe | Details → |
| SHA-256 | fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1 | Details → |
| MD5 | ded73d04bb3e3525226de64c38a332e3 | Details → |
| Filename | f_000177.exe | Details → |
| SHA-256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | Details → |
| MD5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | Details → |
| Filename | tmp00055df5.dll | Details → |