Attacks in Italy, offensive campaigns and APT activity, compromises and global efforts to counter North Korean threats

Weekly Threats hor Telsy

Italy: multiple malicious activities observed

Security researchers identified two phishing websites targeting Telepass customers. Data entered by victims is intercepted instantly via WebSocket (WSS), ensuring successful theft even if the form is never submitted. The phishing kit’s control panel, based on Phoenix System, indicates developers of Chinese origin. An ongoing phishing campaign targeting Italy has also been observed, abusing the name and logos of AgID and SPID to fraudulently collect users’ personal and banking information. In addition, researchers tracked an operation abusing the name, logos and branding of the Italian State Police and pagoPA to trick victims into paying a fake traffic fine and stealing their payment information. Specifically, the malicious website impersonates a Traffic Police portal for consulting traffic violation notices and submitting driver information, while using the logos and branding of the Italian State Police to increase its credibility. Furthermore, another campaign was identified abusing the name and logo of ARERA (Italian Regulatory Authority for Energy, Networks and Environment) to steal users’ personal and financial information. In particular, the lure consists of a fake reimbursement related to the social water bonus, an existing government measure intended to reduce water supply costs for households experiencing economic or physical hardship. Finally, security researchers observed a smishing campaign themed around GLS aimed at stealing victims’ payment card information. Specifically, the fraudulent SMS claims that a parcel delivery has been suspended due to missing information required to complete the shipment. Concluding with the ransomware landscape, SAFEPAY claimed on its leak site the compromise of New Point S.P.A., an Italian wholesale company based in Signa (Florence) and a leading distributor of clothing and haberdashery products.

 

Threat and APT: ChainDrop, phishing and Asian operations

On August 4, 2026, ChainDrop, a large-scale supply chain attack targeting the npm registry, was discovered. The attackers compromised the GitHub account of the maintainer of several widely used caching packages, including keyv, flat-cache, and cache-manager, and published malicious versions through legitimate GitHub Actions workflows. The compromised packages automatically execute a malicious payload during installation, harvesting credentials and secrets from developers’ workstations and CI/CD environments, including GitHub and npm tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, and other sensitive information. The malware, a variant of Mini Shai-Hulud, is self-propagating: it uses stolen npm tokens to compromise and republish additional packages, and GitHub tokens to establish persistence in repositories by modifying Claude Code and Visual Studio Code configurations. Security researchers documented several campaigns highlighting the evolution of initial access, persistence and system compromise techniques. In particular, two Phishing-as-a-Service platforms named TokenLover and YaksaLover were identified, designed to automate Business Email Compromise (BEC) operations targeting organizations using Microsoft 365. The toolkits abuse the OAuth Device Code Flow authentication mechanism to obtain valid access tokens without directly stealing user credentials, allowing attackers to maintain persistence even after password changes by registering new Windows Hello for Business credentials. TokenLover also integrates language model-based capabilities to automatically analyze compromised email inboxes and reconstruct organizations’ financial workflows, facilitating Business Email Compromise fraud. At the same time, a cryptomining campaign targeting Linux environments was observed distributing a modified version of XMRig, initially gaining access through trusted third-party relationships before abusing PAM framework mechanisms to maintain persistence and regenerate itself even after the root account has been cleaned. The malware operates entirely in memory, tampers with logging systems and automatically optimizes system resources to maximize mining performance. During the same period, researchers identified the multi-wave operation SMOKE#SCREEN, which uses Zoom-, Adobe- and business document-themed lures to deploy a legitimately signed ScreenConnect agent, enabling attackers to obtain persistent remote access to compromised systems through infection chains employing obfuscated scripts, .NET loaders and evasion techniques designed to bypass Microsoft Defender, SmartScreen and EDR solutions. On the APT front, researchers attributed to an adversary named Larva-24009 a phishing campaign targeting users in South Korea and globally that distributes QuasarRAT and UltraVNC through malicious LNK files to gain remote control of victim systems and steal credentials, screenshots, system information and other sensitive data using NirSoft utilities and a dedicated keylogger. Finally, the Chinese threat actor Void Arachne was observed conducting an SEO poisoning operation targeting Chinese users through fake software download websites, tricking victims into installing the Winos RAT, delivered through the VCONSOLE2 loader and designed to operate exclusively on systems configured with the Chinese language, maintaining persistence through scheduled tasks and communicating with its C2 infrastructure over TLS connections.

 

Cybercrime: new data breaches and joint advisory on fake North Korean IT workers

On July 28, 2026, Unitel S.A., Angola’s leading telecommunications operator, disclosed that it had suffered a cyberattack affecting its technology infrastructure, causing nationwide disruptions to voice, mobile data and Internet services and impacting more than 21 million customers. The company initiated containment and recovery activities, stating that no sensitive customer data had been compromised. At this time, neither the attack vector nor any ransom demands or claims of responsibility have been disclosed. In the United Kingdom, the Police National Legal Database (PNLD), the legal database used by police forces and criminal justice organizations, disclosed a security incident resulting in the compromise of the names and email addresses of police personnel, criminal justice staff, government partners and users of the Ask the Police portal. The ExfilSquad group claimed responsibility for the attack, stating that it had stolen approximately 1.9 GB of data containing around 135,000 records and threatening to publish the information. The same threat actor also claimed responsibility for the compromise of Analog Devices in the United States, an incident that resulted in unauthorized access to the company’s systems and the exfiltration of several files. However, the group subsequently removed any reference to the company from its leak site. Also in the United States, Amgen, one of the leading U.S. biotechnology companies specializing in the development and manufacturing of pharmaceuticals disclosed a security incident affecting multiple cloud environments managed by third-party service providers, resulting in the exfiltration of corporate data and patients’ Protected Health Information (PHI). The investigation remains ongoing to determine whether additional sensitive information, including intellectual property and research and development data, has also been compromised, while the company stated that the incident has had no material impact on its business operations. Moving to Switzerland, the Federal Office of Information Technology, Systems and Telecommunication (FOITT) detected an attack targeting its SharePoint servers, resulting in the compromise of the credentials associated with approximately 200 accounts. The agency immediately restricted external access to the platform, reset the affected passwords and implemented mitigations for the SharePoint vulnerabilities previously addressed by Microsoft, which are believed to be the likely attack vector. Finally, the authorities of the United States, Japan, the Republic of Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the United Kingdom published a joint advisory regarding North Korean IT workers who use false identities to obtain remote employment in order to finance Pyongyang’s nuclear and ballistic missile programs. The advisory highlights that these individuals also pose an insider threat to organizations, as they are involved in data exfiltration, cryptocurrency theft and the theft of sensitive information, and provides recommendations to help identify their activities during recruitment and hiring processes.

 


Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.

The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.

Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.

Learn more about our Cyber Threat Intelligence solution.