NoName057(16) targets Italy, new cybercrime offensives, the latest from Moscow and Pyongyang
Italy: DDoS offensives targeting Italian organizations
Following the trend observed last week, the pro-Russian hacktivist collective NoName057(16) renewed its focus on Italy. The adversary claimed DDoS attacks against the following portals: Municipality of Lonigo; Province of Vicenza; B2C Innovation S.p.A. (24hassistance); Coverwise; Alilaguna S.p.A.; Port System Authority of the Strait of Messina; Port System Authority of the Central Tyrrhenian Sea; Port System Authority of the Western Sicilian Sea; Port System Authority of the Western Ligurian Sea; Unione Sindacale di Base (USB); Centre for the Study of Socio-Economic Transformations (CESTES); Port System Authority of the Southern Adriatic Sea; Veneto Sviluppo S.p.A.; Italian Customs and Monopolies Agency (ADM); Europa Verde; Municipality of Potenza; Regional Council of Aosta Valley; Lazio Region; Municipality of Giugliano in Campania; Tiscali Italia S.p.A.; HERABIT S.p.A.; Municipality of Parma; Municipality of Reggio Emilia; Italian Public Administration Workers Union (UILPA); Piedmont Region; Port System Authority of the Sea of Sardinia – Port of Olbia and Golfo Aranci; Municipality of Palermo; Sicilian Regional Assembly (ARS); Sinfomar; Ministry of Labour and Social Policies; Port System Authority of the Eastern Adriatic Sea; A2A S.p.A.; Province of Padua; Municipality of Arzignano; Public Digital Identity System (SPID); Directa SIM S.p.A.; CoopVoce; NTC Italia S.r.l.; Contship Italia Group; Terminal Napoli S.p.A.; Marnavi S.p.A. On June 4, the adversary specified that Italy was targeted due to the political support and cooperation provided to Ukraine. In particular, the group referred to statements made by Ukrainian Presidential Office Deputy Head Serhiy Kyslytsya regarding the expected completion of the “Drone Deal agreement” between Italy and Ukraine, as well as his gratitude toward Italy and Prime Minister Giorgia Meloni for their continued support for Kyiv. On May 30, the Dark Storm Team collective also claimed DDoS offensives targeting Italian portals, including: MutuiOnline; Segugio.it Insurance Broker S.r.l.; QUIXA Assicurazioni S.p.A.; Municipality of Arzignano; Municipality of Lonigo; Province of Vicenza; Veneto Region. The attacks were marked with the hashtags #DARKSTORM #DARKSTORMTEAM #OpItaly and #NONAME057. The presence of the hashtag #NONAME057, together with the use of #OpItaly, suggests that the operation was conducted as a sign of support for, or alignment with, the anti-Italian campaign promoted by NoName057(16).
Cybercrime: several global campaigns reported
Security researchers observed a Chinese group known as TA4922 distributing previously undocumented threats dubbed Atlas RAT, RomulusLoader, and SilentRunLoader worldwide. The activity initially focused on Japan before expanding to Taiwan, South Korea, Singapore, India, Malaysia, and Indonesia. Since March 2026, it has also reached Europe (United Kingdom, Germany, and Italy) and Africa (South Africa). The campaigns leverage phishing emails featuring highly contextualized lures related to human resources, payroll, taxation, invoicing, and compliance topics. These lures are adapted to the language and regulations of the targeted countries to obtain corporate and personal data, credentials, and system information. In May 2026, an active operation named Operation TaxShadow was tracked targeting India and Japan and aimed at delivering a multi-stage malware executed entirely in memory. The adversary impersonates official tax authorities, tricking victims into downloading a malicious ZIP archive that initiates the infection chain. The campaign appears designed to facilitate data exfiltration or prepare for subsequent compromises. The presence of Chinese-language artifacts within the code suggests, with moderate confidence, the use of Chinese-origin development templates, although no direct links to known threat groups have been identified. In the supply-chain domain, new offensives were also identified. In May 2026, an attack affecting four widely used Laravel-Lang community packages distributed through Composer was tracked. The Malware-Slop campaign distributed a new malicious npm package named mouse5212-super-formatter, designed to upload files from the /mnt/user-data directory, which is used by Anthropic’s Claude platform to manage uploads and background outputs. Finally, on June 1, 2026, a supply-chain compromise affecting multiple official npm packages published under the @redhat-cloud-services namespace was publicly disclosed, resulting in the distribution of Miasma, malware capable of stealing sensitive credentials associated with development environments and cloud infrastructures, including GitHub Actions secrets, npm tokens, AWS/GCP/Azure credentials, Vault secrets, Kubernetes configurations, SSH keys, and .env files. According to Red Hat, the incident originated from a compromised GitHub account belonging to an employee, which was used to introduce unauthorized commits into repositories associated with the RedHatInsights organization. Turning to the malware landscape, the previously undocumented infostealer EKZ was delivered through the exploitation of CVE-2026-35616, an Improper Access Control vulnerability affecting FortiClient Endpoint Management Server, in a campaign tracked during May 2026. The threat is capable of exfiltrating credentials, cookies, and autofill data from Chrome, Microsoft Edge, and other Chromium-based browsers, as well as Firefox/Gecko-based browsers.
APT: operations by Russian GREYVIBE and North Korean Lazarus Group reported
Security researchers observed an espionage campaign active since at least August–September 2025 that leverages artificial intelligence (AI) to target Ukrainian entities. The operation is attributed to a previously undocumented Russian threat actor dubbed GREYVIBE. The attacker specifically targets government institutions, energy-sector companies, military personnel, and intelligence staff, including frontline operators. The defining characteristic of the operation is the extensive and systematic use of artificial intelligence tools and large language models throughout every stage of the attack lifecycle. ChatGPT, Google Gemini, and image-generation tools are used to draft phishing content, create fake website imagery, develop malware code and loaders, and implement obfuscation techniques. Moving to North Korea, Lazarus Group targeted financial institutions and blockchain infrastructures using COPPERHEDGE, a fully featured remote access trojan (RAT) distributed through exploitation of the React2Shell vulnerability (CVE-2025-55182). The campaign’s presumed objectives include self-financing activities, data theft, and intelligence collection.
Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.
The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.
Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.
Learn more about our Cyber Threat Intelligence solution.
