Cybercrime operations, developments in the APT landscape, data breaches and Police activities

Weekly Threats hor Telsy

Cybercrime: new campaigns and ransomware activity

A new active campaign dubbed StrikeShark has been identified, targeting organizations across multiple countries and sectors through the deployment of previously unseen malware named SharkLoader. The operation exploits several known vulnerabilities, including Microsoft Exchange CVE-2021-26855 and CVE-2022-41082, Microsoft SharePoint CVE-2021-27076, Apache Shiro CVE-2016-4437, Hikvision CVE-2021-36260, Zimbra Collaboration Suite CVE-2022-27925, F5 BIG-IP CVE-2023-46747, Fortinet FortiOS CVE-2024-21762 and CVE-2022-40684, Cisco IOS XE CVE-2023-20198, Openfire CVE-2023-32315, and GeoServer CVE-2024-36401. On June 24, 2026, security researchers observed a new wave of the Mini Shai-Hulud malicious campaign, targeting LeoPlatform npm packages and the Go ecosystem with the Miasma malware. The primary impact involves credential theft, exposing development workstations, CI/CD pipelines, and cloud resources, with the potential for further propagation with compromised tokens. In addition, a compromise case has been tracked in which the Shai-Hulud worm, attributed to TeamPCP, enabled the transition from a supply chain attack to prolonged access and the breach of sensitive data within an Amazon Web Services environment. The incident originated from the exposure of an environment to poisoned CI/CD dependencies that compromised Jenkins-based runners and resulted in significant financial losses, as well as the compromise of sensitive data stored in Amazon Redshift. In the ransomware landscape, the large-scale FortiBleed credential theft campaign has been linked to the INC Ransom and Lynx Ransomware-as-a-Service (RaaS) operations. An operator with access to the FortiBleed infrastructure was identified actively managing the negotiation panels of both groups, providing the strongest evidence to date that FortiGate credentials collected through this operation are either sold or directly leveraged for ransomware deployment. Furthermore, a new backdoor dubbed Mistic (Backdoor.Mistic, MLTBackdoor) has been detected in multiple opportunistic intrusions. The malware is believed to be linked to KongTuke (also known as Woodgnat), a financially motivated Initial Access Broker (IAB) active since at least 2024, specializing in compromising corporate networks and selling the acquired access to ransomware groups or other threat actors. In at least one observed intrusion, the backdoor was deployed in close temporal proximity to ModeloRAT, a Python-based remote access trojan (RAT) developed by the same IAB. Also in the ransomware domain, on June 30, 2026, The Gentlemen claimed on its leak site the compromise of Indra Group, a Spanish multinational leader in technology, consulting, and defense that operates as a NATO contractor. The same group also claimed responsibility for the compromise of Naturghiaccio, a company headquartered in Uta (Cagliari). Remaining in Italy, a threat actor known as Deadlock claimed the compromise of CNA Toscana Centro; World Leaks (the rebranded Hunters International Team) claimed the compromise of Starpool S.r.l.; and Bashe (also known as APT73) claimed the compromise of Flazio S.r.l.

 

APT: Chinese, Russian, and Iranian operations

Security researchers have observed a Chinese-speaking threat actor tracked as CL-STA-1062 deploying a previously unseen malware named TinyRCT during an espionage campaign targeting government entities and critical energy infrastructure across Southeast Asian countries. The attacker gained initial access by exploiting vulnerabilities in web applications and subsequently deployed a hybrid toolkit combining open-source tools with the backdoor. Also in China, during June 2026, two parallel cyber espionage operations were identified and attributed with high confidence to the state-sponsored Mustang Panda group. These campaigns targeted Indian government entities and organizations in the hydropower sector, leveraging a previously unseen toolkit comprising the SHARDLOADER, MINIRECON, and ZOHOMURK malware families while exploiting Zoho WorkDrive. The Beijing-linked APT’s objective is to collect intelligence on India’s national energy plans and defense cooperation agreements with Taiwan. Moving to Russia, Turla Group was observed orchestrating operations against government and military organizations aimed at deploying a previously unseen backdoor named STOCKSTAY, whose early samples were also identified in environments associated with entities holding interests in Italian foreign policy. An investigation conducted by the Citizen Lab revealed that Russian authorities used the UFED forensic tool developed by the Israeli company Cellebrite to extract data from the iPhone of Andrey Pivovarov, a human rights activist and executive director of the Russian branch of the opposition organization Open Russia, three months after Cellebrite had terminated all commercial relations with Russia and Belarus. The investigation also identified a possible correlation between the data extraction performed using Cellebrite—which enabled the mapping of Pivovarov’s network of contacts—and subsequent spear-phishing campaigns attributed to the Russian threat actor Callisto (COLDRIVER), linked to the FSB, targeting individuals associated with Pivovarov, including lawyer Anastasiya Burakova. Finally, a threat cluster tracked as TAG-182, almost certainly part of the Iranian state surveillance apparatus, is distributing the MarkiRAT malware to support government intelligence operations targeting Iranian citizens residing both inside and outside the country, most likely with the objective of monitoring and identifying dissidents.

 

International context: arrests, law enforcement operations, and cyber breaches

Two members of the Scattered Spider group pleaded guilty before a UK court for compromising the networks of Transport for London (TfL) between August 31 and September 3, 2024. TfL stated that the attack caused approximately three months of service disruptions, affecting 10 million customers. On June 23, 2026, Nathan Austad, a 21-year-old U.S. citizen known online by the alias “Snoopy,” was sentenced to 18 months in prison by a U.S. federal court for his role in the 2022 cyberattack against the DraftKings sports betting and fantasy sports platform. On June 24, 2026, Europol, together with the authorities of several countries, Eurojust, and private-sector partners, announced a new phase of Operation Endgame, which resulted in the dismantling of infrastructure associated with the SocGholish, Amadey, and StealC malware families. The infrastructure, offered under the Cybercrime-as-a-Service (CaaS) model, was used to distribute malware and support ransomware operations, financial fraud, and information theft. France’s National Institute of Statistics and Economic Studies (INSEE) officially announced that it had been the victim of a cyberattack resulting in the breach of its employees’ personal data. According to the organization, the identities of approximately 12,800 current and former INSEE employees, as well as individuals affiliated with the institute, together with their professional contact details, were compromised. KDDI Corporation, one of Japan’s leading telecommunications operators, disclosed that it had suffered unauthorized access to an email system used to provide email services to five Internet Service Providers (ISPs) in the country. The compromise may have exposed up to 14.22 million email addresses and passwords belonging to current customers, former customers, and inactive accounts across the affected providers. On June 30, 2026, Aflac Life Insurance Japan Ltd., the Japanese subsidiary of U.S. insurance giant Aflac Incorporated, announced that it had suffered a breach of its systems, resulting in the theft of the personal and banking information of 4.38 million customers. In addition, the U.S. Department of Homeland Security (DHS) confirmed a cybersecurity incident affecting the Homeland Security Information Network (HSIN), a platform used to share sensitive but unclassified information among federal, state, local, tribal, territorial, international, and private-sector partners. The intrusion affected HSIN servers and an associated SharePoint collaboration system. Following the data theft campaign attributed to ShinyHunters, which exploited the Oracle PeopleSoft PeopleTools zero-day vulnerability CVE-2026-35273, the National Association of Insurance Commissioners (NAIC) and Nissan Americas issued official statements regarding security incidents involving Oracle PeopleSoft. Among the operational impacts reported were the temporary suspension, by several rating agencies, of data feeds to the NAIC, resulting in a pause in the assignment of insurers’ investment designations and, in the case of Nissan Americas, the exposure of certain personal data.

 


Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.

The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.

Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.

Learn more about our Cyber Threat Intelligence solution.