FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor
ESET attributes a new SparroWocky backdoor to espionage group FamousSparrow, deployed via exploited internet-facing Exchange servers across Latin American governments.
ESET's Welivesecurity team reports FamousSparrow gained initial access by exploiting publicly reachable Microsoft Exchange servers, with roughly 90 percent of targets since mid-2025 in Latin America, including governments in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group's new modular C-language backdoor SparroWocky replaces SparrowDoor and uses a three-part loader: a legitimate executable, a malicious DLL side-loaded in memory, and an encrypted payload. It persists via Windows services or Registry Run keys, supports screenshots, file operations, TCP proxying, Beacon Object Files, TLS/RC4-encrypted C2, and anti-forensics such as call-stack spoofing. IOCs including loader SHA-1 hashes and C2 IP addresses were published.
GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
GTIG's Q2 2026 tracker shows adversaries adopting agentic AI workflows, including credential harvesting in under six hours and supply chain attacks by UNC6780.
Google Threat Intelligence Group's Q2 2026 report documents adversaries moving from basic prompting to agentic AI workflows and automation, including a cloud compromise followed by agent-enabled mass credential harvesting executed in under six hours. It tracks financially motivated actor UNC6780 (TeamPCP) conducting large-scale open source supply chain compromises across PyPI, npm, and Docker Hub since March 2026, deploying credential stealers. The report also highlights growing targeting of proprietary AI models, source code, prompts, and API credentials, plus LLMJacking practices where adversaries steal developer credentials or hijack cloud infrastructure to run unauthorized AI workloads.
IT help-desk vishing tricks executives into handing over Microsoft 365 access
Arctic Wolf tracks PREY-0058 (linked to UNC6671), a vishing campaign stealing Microsoft 365 session tokens via AiTM panels for SaaS data theft and extortion.
Arctic Wolf is tracking a campaign, PREY-0058, sharing tradecraft with Google Threat Intelligence Group's UNC6671, in which callers posing as internal IT talk employees through fake passkey/MFA setups. Operator-controlled adversary-in-the-middle pages harvest passwords and MFA approvals to seize session tokens, then actors enumerate and bulk-exfiltrate data from SharePoint, OneDrive, Exchange, and Box. Extortion brands include BlackFile, Pink, Helix, Cinder, and Redact; targets are mostly US-based executives in construction, healthcare, real estate, finance, and professional services, with exfiltration shifting to residential proxies like NodeMaven.
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Arctic Wolf tracks PREY-0058, a vishing and AitM token-theft crew targeting Microsoft 365 executives for data theft and extortion.
Arctic Wolf disclosed a widespread data theft and extortion cluster, PREY-0058, which overlaps with Mandiant's UNC6671 and possibly the Pink/Cinder extortion groups. Attackers impersonate IT help desk staff by phone, direct executives to authentication-themed lure domains, and run adversary-in-the-middle Microsoft 365 logins to harvest credentials, MFA approvals, and session tokens replayed via residential proxies such as NodeMaven. After access, they run discovery in SharePoint and Entra ID, then bulk-exfiltrate data from SharePoint, OneDrive, Exchange, and Box before sending extortion demands. Targets are primarily US construction, healthcare, real estate, finance, and professional services organizations.
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
Check Point links Gambling Goblin, a Chinese-speaking cluster, to malicious Apache modules hijacking Brazilian government servers to promote betting sites.
Check Point Research tracks Gambling Goblin, a Chinese-speaking cluster, installing malicious Apache reverse-proxy modules on compromised Brazilian government and education web servers since mid-2025. The modules divert visitors to gambling and fake app-store pages while stripping the site's security headers, likely for large-scale SEO manipulation. The group's Linux arsenal includes DownPro, AlphaAgent, oRAT, a 3snake-based credential stealer, and SSH brute-forcing tools, and it is tied to Trend Micro's Earth Berberoka. Related SEO-fraud campaigns on .gov.br domains were documented by ESET (GhostRedirector), Palo Alto Networks Unit 42, and Hunt.io.
US Indicts 17 Iranians Over Years
US unsealed superseding indictment charging 17 Mabna Institute Iranians for IRGC-linked espionage stealing 31TB from universities, companies, and government agencies.
The Justice Department unsealed a superseding indictment charging 17 members of the Iran-based Mabna Institute, which conducted hacking campaigns since at least 2013 on behalf of the IRGC and other Iranian clients. The group compromised 144 US and 178 foreign universities, at least 42 US companies, and multiple government agencies, stealing over 31 terabytes of academic data and IP plus employee email inboxes. Hackers breached roughly 8,000 of 100,000 targeted professor accounts across 24 countries, selling stolen research through Megapaper.ir and Gigapaper.ir. Behzad Mesri, tied to the HBO breach and $6 million Bitcoin extortion, is among eight new defendants, and five defendants carry State Department Rewards for Justice bounties up to $10 million.
Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
Unit 42 links Stately Taurus APT activity in ASEAN region and Myanmar to the decade-old Bookworm malware family via infrastructure overlaps.
Unit 42 connected Stately Taurus (aka Mustang Panda) espionage activity targeting ASEAN-affiliated organizations and Myanmar to the Bookworm malware family, first published in 2015. Earlier attacks delivered the PubLoad stager via DLL sideloading, with a PubLoad variant communicating with C2 at 123.253.32[.]15 while mimicking Windows Update URLs. Three previously unreported loader samples from 2021-2022 used UUID-decoded shellcode loaded via heap allocation and API callbacks, ultimately decrypting and loading Bookworm DLLs. A ToneShell backdoor variant shared debug paths with Bookworm loaders, and the January 2024 CSIRT CTI post corroborated the Myanmar attacks.