hacker-news · Crawled Jul 23, 2026
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
5 IoCs 4 Malware
Read original article ↗
AI Summary
Recent cyber threats include malicious npm and PyPI packages delivering infostealers, counterfeit VS Code extensions exfiltrating machine data, and Android spyware disguised as legitimate safety apps. Iranian-affiliated actors are targeting PLC systems in critical infrastructure, while attackers leverage AI models for prompt injection and malware development. Campaigns also involve malvertising distributing SectopRAT and MarkiRAT, DNS tunneling by TrickBot for C2 communication, and exploitation of trust in legitimate platforms to deliver malware.
AI-extracted · verify before operational use
Extracted Entities 4 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 15 techniques
T1001.003 Protocol or Service Impersonation · Command And Control T1014 Rootkit · Defense Evasion T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1497 Virtualization/Sandbox Evasion · Defense Evasion T1539 Steal Web Session Cookie · Credential Access T1555 Credentials from Password Stores · Credential Access