Attacks in Italy, cybercrime operations, developments in the APT and hacktivist landscape

Weekly Threats hor Telsy

Italy: cybercrime and hacktivist activities

Several active phishing operations have been detected in Italy that fraudulently exploit the name, logo, and visual identity of the Italian Revenue Agency (Agenzia delle Entrate) with the aim of stealing users’ financial and asset-related information. Among these, one campaign has been observed combining phishing and vishing techniques, dynamically adapting to the responses provided by the victim. Specifically, the victim is shown a screen simulating a synchronization error, claiming that the submitted information does not match the records held by the Italian Tax Registry. The page warns that an automatic tax assessment notice may be issued and that precautionary asset freezes may be enforced, prompting the user to call a phone number presented as the Milan Verification Office. Another operation aimed at distributing malware has also been identified, leveraging phishing emails targeting Italian users and organizations with invoice-themed lures to increase the likelihood of payload execution. Once installed, the malicious browser extension establishes a connection with a C2 server through which sensitive browser data are exfiltrated, including cookies associated with Google services, open tabs and URLs, the user-agent, language settings, and a persistent victim identifier. The extension is also capable of receiving remote commands, which are forwarded to the Native Messaging Host for execution on the compromised system, enabling operations such as directory listing on the local disk. In addition, security researchers have observed a significant increase in phishing campaigns targeting courier services, with a particular focus on GLS Italy. Official guidance from GLS states that the company never requests online payments or credit card information through links contained in SMS messages or emails. The pro-Russian hacktivist collective NoName057(16) has released an English-language propaganda video claiming responsibility for DDoS campaigns conducted against Italy, portraying them as a direct response to Italy’s support for Ukraine. The video reviews attacks carried out in 2023 and 2026, claiming that the disruption of Italian government services preceded the resignations of the Directors of the Italian National Cybersecurity Agency (ACN), Roberto Baldoni and Bruno Frattasi. It also reiterates the political motivation behind the group’s operations, stating that attacks will continue as long as Italy maintains its support for Kyiv. Finally, within the ransomware landscape, LockBit Team claimed on its leak site the compromise of Ravagnan S.p.A.; Stormous claimed Maglificio Liliana di Lorenzoni Andrea & C. S.N.C. and the e-commerce websites of its brands; while The Gentlemen claimed Meccanica GN S.r.l.

 

Threat: New supply chain attacks and a WhatsApp campaign identified

A threat actor known as SmartApeSG (also tracked as ZPHP or HANEYMANEY) compromised the Okendo Reviews widget, a customer review platform integrated into e-commerce websites and used by more than 18,000 brands, by injecting malicious JavaScript code in a supply chain attack. The affected websites generated traffic volumes ranging from hundreds of thousands to several million monthly visits, including one documented case involving a major U.S. retail brand receiving approximately seven million monthly visits. The vendor was notified of the incident and, after confirming the compromise, restored the widget script to a clean state. Salesforce disabled the Klue Battlecards integration following a security incident involving the Klue market intelligence platform that resulted in the theft of customer OAuth tokens and unauthorized access to their Salesforce CRM environments, leading to the exfiltration of sensitive data. The Icarus group publicly claimed responsibility for the attack on its leak site, threatening to publish the stolen data unless a ransom was paid. In response, Klue revoked all credentials and OAuth tokens, removed the malicious code, and temporarily disabled all integrations (including Salesforce, HubSpot, Gong, Slack, and others), while Salesforce disabled the Klue Battlecards connection for all customers, emphasizing that the issue was limited to the third-party integration and did not originate from a vulnerability within its own platform. Between February and May 2026, security researchers identified five malicious skills that remained active and unblocked on the OpenClaw ClawHub marketplace. These skills fall into three threat categories, ranging from data theft and persistence to deceptive monetization schemes and financial fraud, particularly affecting users of trading and financial tools. Finally, in June 2026, a malicious campaign was identified exploiting WhatsApp to distribute malicious VBScript files through direct messages sent from previously compromised accounts. The operation primarily targeted individual users of WhatsApp Desktop and WhatsApp Web, with no evidence of sector-specific or organizational targeting, indicating an opportunistic campaign aimed at a broad user base.

 

APT and hacktivism: Activities targeting Ukraine and Israel observed, alongside a North Korean supply chain attack

A threat actor tracked as GhostShell (MB-0009) conducted an espionage campaign targeting Ukraine’s drone ecosystem and the associated defense supply chain. During this operation, the actor exploited the WinRAR vulnerabilities CVE-2025-8088 and CVE-2025-6218 (previously known to have been used by Gamaredon Group) to automatically place a VBS script into the Windows Startup folder, thereby ensuring persistence on the compromised system. The primary impact consists of the theft of sensitive information and the establishment of persistent access to victim networks, enabling the collection of operational intelligence and information related to the UAV supply chain. Remaining in Ukraine, on June 25, 2026, the state-owned postal operator Ukrposhta announced a temporary disruption of its mobile application following a cyberattack against its IT systems that occurred overnight between June 24 and 25. Between mid and late March 2026, security researchers observed a campaign orchestrated by a threat actor believed to be aligned with Iran, targeting Israeli entities through a previously undocumented backdoor named BLUERABBIT. In addition to several operational capabilities, the malware also implements a ransomware module that encrypts files across all logical drives by appending the “.candy” extension and replaces the desktop wallpaper with an AI-generated image. A pro-Russian hacktivist collective known as the IT Army of Russia claimed responsibility for the attack via its Telegram channel. According to the group’s statement, it had compromised Ukrposhta’s infrastructure several weeks earlier, gaining access to a server and extracting a database exceeding 172 GB containing more than 1.2 million user records, including addresses, email contacts, phone numbers, full names, and password hashes. The threat actor also claimed to have compromised the organization’s call center, additional services, and APIs, while exfiltrating further internal information. Ukrposhta has neither confirmed any data exfiltration nor disclosed additional details regarding the scope of the incident. Finally, in North Korea-related activity, security researchers identified a large-scale supply chain attack orchestrated by Lazarus Group, affecting more than 140 packages within the mastra and @mastra scopes on the npm registry. The attack originated from the takeover of the maintainer account “ehindero”, which retained publishing privileges across the entire Mastra ecosystem despite no longer being actively used by its original owner. The timeline unfolded within just a few hours: on June 16, the clean version of easy-day-js was published; on June 17, the malicious version followed, shortly after which the Mastra packages were republished at scale. The compromised packages were subsequently removed from the npm registry, and the threat actor’s publishing privileges were revoked.

 


Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.

The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.

Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.

Learn more about our Cyber Threat Intelligence solution.