ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
AI Summary
A Chinese-speaking threat actor is leveraging AI models like Anthropic Claude, Alibaba Qwen, and DeepSeek to automate cyber intrusions against government and financial systems in multiple countries, including Taiwan, Afghanistan, Thailand, and the U.S. The campaign uses an AI orchestration framework called SecFlow to divide tasks among specialized AI agents for reconnaissance, exploitation, and data collection. Exploited vulnerabilities include Log4Shell, Spring4Shell, and Shiro deserialization, leading to web shell deployment and lateral movement using a Go-based backdoor named SecBox. The campaign was first reported in July 2026. Another related campaign involves EtherRAT and TukTuk malware, where attackers deploy ransomware known as The Gentlemen after gaining access via malicious MSI installers and conducting credential theft and lateral movement.
AI-extracted · verify before operational use