Italy targeted by multiple adversaries, novel APT operations, emerging threats, and supply chain compromises
Italy: New ransomware claims
The pro-Russian hacktivist collective NoName057(16) has resumed targeting Italian websites following the allocation of an additional €10 million in support of Ukraine for the restoration of its energy infrastructure. Specifically, over the past week, the group claimed responsibility for DDoS attacks against the following targets: the Municipality of Cavallino-Treporti; the Municipality of Albignasego; the Province of Padua; the Province of Treviso; the Province of Verona; the Province of Vicenza; the Municipalities of Arzignano and Lonigo; the Metropolitan City of Venice; the Veneto Region; MutuiOnline S.p.A.; Segugio.it Broker di Assicurazioni S.r.l.; Segugio.it S.r.l.; QUIXA Assicurazioni S.p.A.; 24hassistance – B2C Innovation S.p.A.; Coverwise; Alilaguna S.p.A.; Ve.La. S.p.A. (Venezia Unica); Venezia Terminal Passeggeri S.p.A.; the Port System Authority of the Strait of Messina; the Port System Authority of the Central Tyrrhenian Sea; the Port System Authority of the Western Sicilian Sea; the Port System Authority of the Western Ligurian Sea; Unione Sindacale di Base; CESTES – Centre for Economic and Social Transformations Studies; Assoporti; the Port System Authority of the Southern Adriatic Sea; Banca Prealpi SanBiagio; Veneto Sviluppo S.p.A.; and the Italian Customs and Monopolies Agency. Furthermore, between 25 and 26 May 2026, the adversary claimed alleged compromises affecting: an industrial automation system associated with the Colombaretta flood retention basin, a hydraulic infrastructure located in the Municipality of Montecchia di Crosara (Verona); a video surveillance system belonging to an unspecified small solar power plant in Italy; a control system managing the PACKAGING A and PACKAGING B production lines of TECNO GROUP LAB S.r.l., a company based in Belpasso (Catania) specializing in automated fruit sorting and packaging lines (primarily citrus fruits); and a video surveillance system linked to a retail outlet of the Italian supermarket chain MD S.p.A. Turning to the ransomware landscape, The Gentlemen claimed on its leak site responsibility for the breach of Fonderia Corrà S.p.A., Nova of CasaSafer, Space Bears of BASE S.p.A., and Akira Team of GITIS S.R.L. Since the beginning of 2026, CSIRT Italia has recorded a significant number of ransomware attacks attributed to Qilin Team targeting Italian organizations, primarily SMEs but also major cloud service providers. Initial access is mainly achieved through the exploitation of known vulnerabilities affecting perimeter devices, as well as through brute-force attacks or Initial Access Brokers (IABs) targeting VPN services. Finally, a phishing campaign targeting students and staff of the University of Bari Aldo Moro (UniBA) was detected in Italy, aiming to exfiltrate institutional credentials.
APT: Multiple offensive campaigns identified
Security researchers have described a spear-phishing campaign orchestrated by the North Korean Lazarus Group aimed at deploying RemotePE against companies operating in the financial and cryptocurrency sectors, including DeFi operators. The malware supports several capabilities, including modification of C2 configurations, file and directory operations with secure deletion through multiple overwrites of up to seven times, process management, dynamic loading of DLL-based plugins, command execution, and controlled sleep and termination mechanisms. The Chinese state-sponsored group Calypso (also known as Red Lamassu) conducted an espionage campaign targeting telecommunications operators and international internet service providers, deploying previously undocumented Linux and Windows backdoors named Showboat (also known as kworker) and JFMBackdoor, respectively. The two tools are believed to be shared among multiple China-aligned groups, each targeting different regions while leveraging the same malware ecosystem. Security researchers also identified a data exfiltration campaign—destructive in some cases—orchestrated by an adversary known as Ababil of Minab (also referred to as Babil of Minab), which has been linked with high confidence to Iran’s Ministry of Intelligence (MOIS). The actor employs infrastructure previously associated with the Black Shadow group. Targets include major U.S. public transportation entities such as the Los Angeles County Metropolitan Transportation Authority (LA Metro) and the South Florida Regional Transportation Authority (Tri-Rail), as well as private companies including Vyncs, active in GPS vehicle tracking, and UNIMAC, a Saudi company operating in the infrastructure sector. Organizations in Israel, particularly in the media and higher education sectors, and in Turkey, including an insurance brokerage firm, were also affected.
Cybercrime: New threats and supply chain attacks
A campaign orchestrated by the Chinese group Webworm targeted government organizations across Europe and academic institutions in South Africa through the deployment of two previously unknown backdoors named EchoCreep and GraphWorm. Specifically, EchoCreep uses Discord as a C2 channel, transmitting AES-encrypted and Base64-encoded commands within channels named after the victim’s IP address or hostname; and GraphWorm abuses Microsoft Graph APIs and the OneDrive service to manage job queues, upload exfiltrated files, and receive commands, organizing victim data into dedicated folders. Turning to supply chain attacks, researchers identified an operation involving at least eight packages published on Packagist and more than 700 public GitHub repositories. Approximately 17 hours elapsed between the initial detection and the recognition of the campaign’s full scope. A GitHub search for the account parikhpreyash4 returned hundreds of results in public code repositories, including numerous Node.js projects. Additionally, researchers uncovered a coordinated cross-ecosystem supply chain operation dubbed TrapDoor, which targeted npm, PyPI, and Crates.io to distribute infostealers. Among the most advanced techniques observed was the injection of hidden instructions through zero-width Unicode characters embedded within configuration files used by AI tools, such as .cursorrules and CLAUDE.md. On the same topic, CISA added to its Known Exploited Vulnerabilities (KEV) catalog CVE-2026-45321 affecting TanStack, an unspecified vulnerability that enabled the publication of malicious releases in the npm registry to distribute credential-stealing malware under a trusted identity; and CVE-2026-8398 affecting Daemon Tools Lite, classified as Embedded Malicious Code with a high impact on confidentiality, integrity, and availability. The latter relates to a supply chain attack that compromised official DAEMON Tools Lite installers. Turning to ransomware activity, the cybercriminal group known as Silent Ransom Group (SRG), also tracked as Luna Moth, Chatty Spider, and UNC3753, has been observed targeting law firms and organizations operating in the insurance, financial, and healthcare sectors across the United States. The stolen information is subsequently leveraged during the extortion phase, with SRG sending ransom emails threatening to sell or publish the data on its website. Finally, an active phishing campaign distributing a variant of the PureLogs infostealer was identified, designed to collect and exfiltrate sensitive information from Windows systems; as well as an operation targeting Android users in Latin America to distribute a RAT known as BTMOB RAT which, unlike traditional banking trojans, goes beyond financial credential theft and enables deep, persistent compromise of infected devices.
Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.
The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.
Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.
Learn more about our Cyber Threat Intelligence solution.
