hacker-news · Crawled Jul 16, 2026
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
3 IoCs 2 Actors 1 Malware
Read original article ↗
AI Summary
Multiple cyber threat campaigns were observed in mid-2026, including malicious NuGet packages distributing spyware disguised as game cheats, fake installers delivering the Starland RAT and WLDR C2 implant, and a new ransomware family named Spirals that encrypted a South Asian IT firm's network within 24 hours. Threat actors exploited known vulnerabilities such as CVE-2026-46817 and CVE-2023-4346, while also leveraging social engineering via phishing eCards and OAuth device code attacks. Additional threats include large-scale infostealer distribution through fake GitHub repositories, Chrome Sync abuse for stalking, and dual monetization campaigns deploying Vidar stealer and XMRig miner.
AI-extracted · verify before operational use
Extracted Entities 3 found
Indicators of Compromise 3 extracted
MITRE ATT&CK TTPs 93 techniques
T1003.002 Security Account Manager · Credential Access T1021.002 SMB/Windows Admin Shares · Lateral Movement T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1085 T1085 T1133 External Remote Services · Persistence T1204.002 Malicious File · Execution T1212 Exploitation for Credential Access · Credential Access T1485 Data Destruction · Impact T1558 Steal or Forge Kerberos Tickets · Credential Access T1566 Phishing · Initial Access T1003 OS Credential Dumping · Credential Access T1020 Automated Exfiltration · Exfiltration T1021.001 Remote Desktop Protocol · Lateral Movement T1021.003 Distributed Component Object Model · Lateral Movement T1021.004 SSH · Lateral Movement T1056.001 Keylogging · Collection T1056.002 GUI Input Capture · Collection T1071.004 DNS · Command And Control T1078.002 Domain Accounts · Defense Evasion T1078.004 Cloud Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1090 Proxy · Command And Control T1098 Account Manipulation · Persistence T1102 Web Service · Command And Control T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1113 Screen Capture · Collection T1114 Email Collection · Collection T1120 Peripheral Device Discovery · Discovery T1132 Data Encoding · Command And Control T1190 Exploit Public-Facing Application · Initial Access T1192 T1192 T1195.002 Compromise Software Supply Chain · Initial Access T1202 Indirect Command Execution · Defense Evasion T1210 Exploitation of Remote Services · Lateral Movement T1213 Data from Information Repositories · Collection T1400 T1400 T1484.001 Group Policy Modification · Defense Evasion T1490 Inhibit System Recovery · Impact T1491 Defacement · Impact T1499 Endpoint Denial of Service · Impact T1530 Data from Cloud Storage · Collection T1542 Pre-OS Boot · Defense Evasion T1543.003 Windows Service · Persistence T1557 Adversary-in-the-Middle · Credential Access T1558.003 Kerberoasting · Credential Access T1566.001 Spearphishing Attachment · Initial Access T1566.002 Spearphishing Link · Initial Access T1573 Encrypted Channel · Command And Control T1588.001 Malware · Resource Development T1595 Active Scanning · Reconnaissance T1659 Content Injection · Initial Access T1012 Query Registry · Discovery T1027 Obfuscated Files or Information · Defense Evasion T1027.002 Software Packing · Defense Evasion T1027.003 Steganography · Defense Evasion T1027.013 Encrypted/Encoded File · Defense Evasion T1036.005 Match Legitimate Name or Location · Defense Evasion T1053.003 Cron · Execution T1053.005 Scheduled Task · Execution T1057 Process Discovery · Discovery T1060 T1060 T1070.004 File Deletion · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1089 T1089 T1095 Non-Application Layer Protocol · Command And Control T1102.001 Dead Drop Resolver · Command And Control T1106 Native API · Execution T1110.001 Password Guessing · Credential Access T1112 Modify Registry · Defense Evasion T1129 Shared Modules · Execution T1135 Network Share Discovery · Discovery T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1160 T1160 T1170 T1170 T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1197 BITS Jobs · Defense Evasion T1203 Exploitation for Client Execution · Execution T1205.001 Port Knocking · Defense Evasion T1543.001 Launch Agent · Persistence T1543.002 Systemd Service · Persistence T1548.002 Bypass User Account Control · Privilege Escalation T1548.004 Elevated Execution with Prompt · Privilege Escalation T1555.003 Credentials from Web Browsers · Credential Access T1564.003 Hidden Window · Defense Evasion T1570 Lateral Tool Transfer · Lateral Movement T1574.002 DLL Side-Loading · Persistence T1608.001 Upload Malware · Resource Development T1685 T1685