Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: talos Clear filter
Give yourself room to be human

2d ago · talos

Cisco Talos identified a threat actor group, UAT-11587, linked to China, targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia. The campaign delivers a previously undocumented backdoor named 'Antino', identified from developer artifacts. The actors are using targeted malware deployments, with specific malicious files observed in telemetry. This activity represents a focused espionage effort against high-value geopolitical targets.

15 IoCs
Trust and the enticing consultancy offer

1w ago · talos

The article is a commentary on social engineering tactics targeting cybersecurity professionals through fake consultancy offers and job scams, emphasizing the importance of trust in the industry. It does not describe a specific malware, vulnerability, or attack campaign with technical indicators. The piece also promotes a new open-source toolkit, CAIRN, and includes general security news summaries without detailed technical analysis or IoCs tied to a single threat event.

The Closed Quorum: Inside the first reported autonomous AI C2 implant

1w ago · talos

CLOSEDQUORUM is a Windows-based malware implant that uses commercial large language models (LLMs) from DeepSeek, Qwen, Mistral, and Google Gemini as an autonomous command and control (C2) infrastructure. It delegates tactical decisions such as credential theft, process injection, and persistence to a panel of LLMs, which vote on the next action via a structured JSON schema. The malware targets user credentials and cryptocurrency wallets, exfiltrating stolen data via an operator-controlled Discord webhook using AES-256-GCM encryption and Base64 encoding. While the distributed version contains placeholder keys and is non-functional, development builds suggest a 'credentials-as-a-service' model where customized binaries are provided to operators.

10 IoCs
Should you care about an “AI slowdown?”

2w ago · talos

Cisco Talos reports on a rising ransomware threat landscape in Japan, with a nearly 5% increase in incidents in the first half of 2026. Two prominent ransomware actors, 'The Gentlemen' and 'Qilin', are driving this surge. Qilin leverages generative AI to accelerate attacks by creating destructive scripts, while The Gentlemen uses legitimate red-teaming tools like AdaptixC2 to blend in and evade detection. Both groups target small- and medium-sized enterprises using double-extortion tactics, emphasizing the need for improved credential management, MFA enforcement, and updated defenses using available Snort rules.

15 IoCs 2 Malware
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

2w ago · talos

In the first half of 2026, ransomware incidents in Japan increased slightly by 4.7%, with The Gentlemen emerging as the most active group, responsible for 14 incidents. The group operates via a Ransomware-as-a-Service (RaaS) model and uses a double-extortion tactic, leveraging infrastructure including AdaptixC2 for command-and-control. Evidence from Russian-language artifacts in scripts and bash history suggests Russian-speaking actors are involved. Qilin, the second most active group, showed signs of using generative AI in developing attack scripts, with code exhibiting structured, LLM-like patterns in tools for deploying ransomware and wiping backups.

1 IoCs 2 Malware 2 CVEs
We've got one word for it, and it's usually the wrong one

3w ago · talos

Cisco Talos identified a complex WebDAV-based infection chain used in an attack against a Ukrainian government organization. The campaign is attributed to the Russian threat actor UAT-10820 and delivers multiple payloads, including the Amatera stealer, ZigCryptoStealer, and NetSupport Manager. The attackers abuse legitimate infrastructure such as the BNB Smart Chain for hosting and use fake CAPTCHA prompts to evade detection. The operation is assessed as opportunistic, focused on stealing cryptocurrency and credentials, with techniques including memory-resident malware, DLL sideloading via 'rundll32.exe', and use of vulnerable drivers to disable EDR solutions.

15 IoCs 1 Malware
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

3w ago · talos

Cisco Talos is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software: CVE-2026-20079, a critical authentication bypass flaw, and CVE-2026-20316, which allows login via a low-privileged account. Three distinct threat clusters have been identified: UAT-12197 deployed a JSP web shell and a JAR-based command executor; UAT-11823, linked to Sandworm, used CVE-2026-20079 and CVE-2026-20316 to deploy Cyclops Blink malware via a Netcat reverse shell; and UAT-11988, a Qilin ransomware operator, leveraged static credentials to conduct reconnaissance, deploy tunneling tools, and execute ransomware. Customers are urged to apply available patches immediately.

10 IoCs 1 Malware
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

3w ago · talos

Cisco Talos identified a cryptocurrency theft campaign dubbed ClickFix that abuses legitimate services, particularly the Google Visualization API, for command and control (C2). The attackers use social engineering to trick victims into pasting malicious JavaScript into their browser or installing it via the Tampermonkey browser extension, enabling persistent access. The malicious script acts as a web skimmer, intercepting and altering cryptocurrency deposit addresses in real time, hijacking clipboard content, and injecting fake UI elements to deceive users into believing they are receiving transaction bonuses. The campaign primarily targets cryptocurrency traders through lures distributed on Telegram, DarkForums, and paste sites, using Google Sheets to host obfuscated payloads and evade detection.

5 IoCs
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

3w ago · talos

Cisco Talos identified a multi-stage WebDAV-based infection chain dubbed ClearFake, delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The attack begins with malicious JavaScript injected via a compromised site and Cloudflare Worker, retrieving code from BNB Smart Chain contracts, leading to a fake CAPTCHA prompt that tricks users into executing a malicious command. This command retrieves a disguised DLL over WebDAV and executes it via rundll32.exe. Two distinct loader variants—'pf.ch' and 'verification.google'—were observed, both delivering Amatera stealer with different secondary payloads based on C2 instructions. The 'pf.ch' chain delivers ZigCryptoStealer and a Go reverse proxy, while the 'verification.google' chain installs an unauthorized NetSupport Manager instance, indicating a Russian threat actor.

32 IoCs 1 Malware
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

1mo ago · talos

Cisco Talos identified a Chinese-speaking threat actor, UAT-10147, conducting a global campaign targeting Windows and Linux web servers in government, education, media, technology, and gaming sectors. The actor leverages publicly disclosed vulnerabilities for initial access, including CVE-2022-27925, CVE-2021-23758, and CVE-2019-18935, and uses AI-driven tooling to automate exploitation, reconnaissance, payload generation, and validation. Post-compromise, the actor deploys malware such as QuasarRAT, Gh0stCringe, and SPECTRE, establishes persistence via scheduled tasks and rogue user accounts, and uses AI-generated scripts to refine attacks and bypass defenses. A misconfigured command-and-control server at 139.180.197[.]150 exposed operational details, including a target list of 170,000 URLs and AI-assisted attack workflows.

14 IoCs 2 Malware 8 CVEs
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

1mo ago · talos

UAT-10147, a Chinese-speaking threat actor, is deploying a new cross-platform backdoor named SPECTRE that targets both Windows and Linux systems. The implant includes advanced capabilities such as process injection, credential theft, anti-analysis routines, and EDR evasion via Bring Your Own Vulnerable Driver (BYOVD) techniques. On Linux, SPECTRE deploys a kernel rootkit called Specter, disguised as 'acpi_pad.ko', which uses ftrace-based hooking to hide processes, modules, and enable UID 0 escalation. The actor also leverages SEO fraud tools like BadIIS and a custom ASHX web handler targeting Vietnamese users, along with multiple backdoors including Meterpreter, Noodle RAT, QuasarRAT, and Gh0stCringe for persistence.

7 IoCs 4 Malware
Is Cyber missing the Marque?

1mo ago · talos

UAT-10147, a Chinese-speaking cybercrime group, is leveraging agentic AI to automate and scale sophisticated post-compromise operations across global web servers. The group uses AI to generate operational playbooks, customize malware, and dynamically validate exploit paths, including through stolen ASP.NET MachineKeys for ViewState deserialization attacks. A newly identified backdoor called SPECTRE features a cross-platform capability with a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) techniques designed to evade endpoint detection and response (EDR) solutions. Defenders are advised to patch internet-facing applications, secure MachineKeys, block vulnerable drivers, and monitor for anomalous HTTP 500 errors used during exploitation.

15 IoCs
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

1mo ago · talos

Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities across various products, including 62 labeled as 'critical'. One actively exploited vulnerability, CVE-2026-68820, is an elevation of privilege issue in the Windows Ancillary Function Driver for WinSock. Multiple remote code execution vulnerabilities are present in Windows, SharePoint, Office, Azure, and other Microsoft services, with several rated high or critical severity. Cisco Talos has released Snort rules to detect exploitation attempts against some of these vulnerabilities, emphasizing those deemed more likely to be exploited, such as CVE-2026-62893 in Windows Deployment Services and CVE-2026-65665 in SharePoint Server.

Curiouser and Curiouser

1mo ago · talos

Cisco Talos discovered 'JWR', a previously undocumented real-time phishing framework and likely variant of the 'The Outsider' phishing-as-a-service platform. JWR uses open WebSocket connections to enable attackers to monitor victim keystrokes in real time and dynamically guide them through fake login and checkout flows. The campaign is currently distributed via SMS lures impersonating regional toll and postal authorities, allowing threat actors to steal payment data, two-factor authentication (2FA) codes, identity documents, and device fingerprints.

15 IoCs
Dissecting the JWR phishing framework

1mo ago · talos

Cisco Talos identified a new phishing framework named JWR, likely a variant of the 'Outsider' PhaaS platform, used in active smishing campaigns targeting users in Southeast Asia and the Middle East. The framework enables real-time, operator-driven session manipulation via AES-CTR encrypted WebSocket connections, allowing threat actors to harvest payment data, login credentials, 2FA codes, identity documents, and full device fingerprints. The client engine uses Vue.js to render 44 phishing pages and supports live keystroke streaming, enabling actors to monitor victim input as it is typed. The campaign delivers the phishing kit via SMS lures impersonating toll, postal, and courier services, with operator interfaces in Simplified Chinese, indicating a Chinese-speaking actor.

7 IoCs
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI

2mo ago · talos

Cisco Talos researchers analyzed how adversaries are weaponizing AI across multiple attack vectors, including malicious software development, criminal force multiplication, and vulnerability research. Threat actors with varying skill levels are using AI to create DDoS tools, bulk-email validation platforms, credential harvesters, and cryptojacking fleets, often bypassing model guardrails through simple evasion techniques like ownership claims or CTF labeling. A francophone actor developed an automated 'Token Pipeline' to exploit React2Shell vulnerabilities and harvest credentials from exposed Git configurations, while a Turkish-speaking actor leveraged AI to manage a Monero-mining operation via compromised torrent clients. Spanish and Russian-speaking actors used AI to conduct autonomous pentesting, build scam chatbots, and target Telegram Mini Apps for cryptocurrency theft.

5 IoCs
You were onto something with “It’s the Climb,” Miley

2mo ago · talos

In Q2 2026, Talos observed a significant increase in phishing attacks and authentication abuse, with over half of incident responses linked to phishing campaigns leveraging QR codes and platforms like ARToken to bypass multi-factor authentication (MFA). Ransomware actors are increasingly abusing legitimate remote management tools such as MeshAgent and Zoho Assist to establish stealthy, persistent access within networks. A new malware named msaRAT, used by the Chaos ransomware group, hijacks browsers to create covert command-and-control (C2) channels via WebRTC over TURN, enabling remote command execution while concealing attacker infrastructure.

15 IoCs
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

2mo ago · talos

In Q2 2026, phishing remained the dominant initial access vector, accounting for over half of incident response engagements, with attackers increasingly leveraging QR code-embedded PDFs and trusted cloud platforms to bypass defenses. Threat actors, including the newly observed Sinobi ransomware group and Warlock (Storm-2603), weaponized legitimate remote management tools such as trojanized MeshAgent and Zoho Assist for stealthy persistence and lateral movement. Authentication abuse surged, with adversaries bypassing MFA using adversary-in-the-middle proxies, session token theft, and MFA fatigue attacks. The PhaaS platform ARToken was identified, offering a comprehensive toolkit for Microsoft 365 compromise via OAuth-based phishing, highlighting a growing trend in commoditized, sophisticated access-as-a-service operations.

4 IoCs 2 Actors 1 Malware
BeaverTail and OtterCookie evolve with a new Javascript module

2mo ago · talos

Cisco Talos identified a new attack campaign linked to the DPRK-aligned threat group Famous Chollima, which uses social engineering through fake job offers to distribute trojanized Node.js applications. The campaign leverages malicious npm packages like 'node-nvm-ssh' and combines the BeaverTail and OtterCookie malware tools to steal credentials, cryptocurrency wallets, and system information. Recent evolution includes merged functionality between BeaverTail and OtterCookie, with new capabilities such as keylogging, screenshot capture, and clipboard monitoring delivered via a modular JavaScript-based framework.

26 IoCs 1 Actors 4 Malware
Uncovering Qilin attack methods exposed through multiple cases

2mo ago · talos

The Qilin ransomware group, active since 2022 and operating as a Ransomware-as-a-Service (RaaS), has intensified its global operations in 2025, targeting primarily the manufacturing, professional services, and wholesale trade sectors. The group employs a double-extortion strategy, combining file encryption with data exfiltration, leveraging tools such as Mimikatz, Cyberduck, and Cobalt Strike. Initial access is suspected via compromised credentials on exposed VPNs without MFA, followed by extensive reconnaissance, credential dumping, lateral movement, and deployment of dual encryptors to maximize impact.

26 IoCs 3 Malware
Don’t swing at everything

2mo ago · talos

Cisco Talos has identified a new Rust-based remote access trojan (RAT) named msaRAT, deployed by the Chaos ransomware group. The malware leverages the Tokio asynchronous runtime and hijacks Chrome or Edge browsers via the Chrome DevTools Protocol (CDP) to establish a covert command-and-control (C2) channel. It is distributed through a deceptive MSI file impersonating a Windows update, enabling in-memory execution and evasion of traditional network detection. The RAT facilitates double-extortion ransomware attacks by enabling persistence and lateral movement.

15 IoCs
Preview: Cisco Talos at Black Hat USA 2026

2mo ago · talos

Cisco Talos is presenting at Black Hat USA 2026, showcasing research on emerging threats involving AI agents, Warlock ransomware, and vulnerability discovery trends. The discussions emphasize the evolving tactics of adversaries using AI-driven tools and prompts to enhance attack efficiency. A main focus is on securing enterprise environments against autonomous systems acting as insider threats and improving defensive strategies using AI in security operations.

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

2mo ago · talos

Cisco Talos has identified a new Rust-based remote access trojan (RAT) named msaRAT, attributed to the Chaos ransomware group. The malware leverages Chrome DevTools Protocol (CDP) to hijack a browser and establish a covert command-and-control (C2) channel via WebRTC, using Cloudflare Workers and Twilio TURN for signaling and relay. This technique allows the RAT to avoid direct network communication, instead routing traffic through legitimate browser processes to evade detection and firewall rules.

5 IoCs
Begun, the Patch Wars have

2mo ago · talos

Cisco Talos has identified a new campaign by UAT-11795, a financially motivated Russian-speaking threat actor, targeting users in the U.S. and Europe since at least June 2025. The group uses trojanized installers of legitimate software such as Webex, Zoom, and MobaXterm to deliver a custom Python-based remote access tool called 'Starland RAT'. This tool enables deployment of additional payloads, including the in-memory PowerShell-based 'WLDR agent', CastleStealer, and Remcos RAT, to steal credentials and cryptocurrency.

12 IoCs
UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

2mo ago · talos

UAT-11795 is a financially motivated, Russian-speaking threat actor active since June 2025, targeting users in the U.S. and Europe. The group deploys a novel Python-based remote access tool (RAT) named Starland RAT and a bespoke PowerShell-based C2 implant, WLDR, using trojanized installers of legitimate software. The campaign focuses on stealing credentials and cryptocurrency wallets, utilizing a multi-stage infection chain involving HTA downloaders, Telegram beacons, and resilient C2 infrastructure, including a fallback mechanism via a Polygon smart contract.

13 IoCs
The Hunter's Paradox: Is it time to embrace automated threat hunting?

2mo ago · talos

The article discusses the 'Hunter's Paradox' in cybersecurity, where human analysts can no longer keep up with the volume, velocity, and complexity of modern threats, necessitating the use of AI-driven threat hunting. However, AI systems are vulnerable to deception by attackers who operate through lies and obfuscation, making full trust in AI problematic. The author argues for redefining threat hunting as a reasoning-driven process rather than a human-only activity, advocating for a balanced approach where AI executes hunts under human-defined strategies and constraints. The path forward involves careful implementation of AI with guardrails, graduated autonomy, and continued human oversight in creative and strategic aspects.

Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

2mo ago · talos

Microsoft's July 2026 Patch Tuesday addresses 622 vulnerabilities, including 57 rated critical, with two already exploited in the wild. Critical vulnerabilities include remote code execution (RCE), elevation of privilege, spoofing, and security feature bypass flaws across Windows, Office, SharePoint, and cloud services. Cisco Talos has released Snort rules to detect exploitation attempts for several of these vulnerabilities, particularly focusing on RCE and privilege escalation issues.

[Video] Where protection starts: Cisco Talos Intelligence Integrations

2mo ago · talos

The article discusses the evolving challenges in cybersecurity, where attackers are increasingly leveraging AI to dynamically alter malicious commands and adapt malware behavior. Cisco Talos Intelligence Integrations aims to help defenders by applying real-time threat intelligence across Cisco’s security technologies to identify and block malicious activity. The integrations assist in answering critical security questions, such as identifying malicious domains or unusual user behavior, by leveraging up-to-date threat intelligence. The article highlights the importance of visibility and context in defending against modern threats.

The serpent’s tongue: Luring the Python out of its den

2mo ago · talos

Threat actors are increasingly targeting Python developers through malicious packages and supply chain attacks, leveraging trusted ecosystems like PyPI to distribute payloads. These attacks exploit native Python features such as setup.py, .pth files, and site hooks to execute arbitrary code during installation or runtime, achieving persistence or conditional execution. Techniques include build hook abuses and package content manipulation, enabling adversaries to hijack legitimate binaries, override functions, or exfiltrate data. The blog highlights defensive strategies including dependency auditing, version pinning, and isolated build environments to mitigate these risks.

1 Actors
WolfSSL, GeoVision, VTK vulnerabilities

2mo ago · talos

Cisco Talos identified multiple vulnerabilities in WolfSSL, GeoVision, and VTK-DICOM software. The vulnerabilities include improper input validation, integer underflow, memory corruption, OS command injection, buffer overflows, privilege escalation, XSS, and encryption weaknesses. These issues have been patched by the vendors, and Snort rules are available to detect potential exploitation attempts.

Next →