The latest from Italy, emerging APT operations, newly announced breaches, and law enforcement activity

Weekly Threats hor Telsy

Italy: malware, smishing, and ransomware activity

On July 9, 2026, security researchers identified a campaign in Italy impersonating the UniCredit brand by promoting a fake banking rewards program designed to distribute an Android banking RAT known as Albiriox. The distribution relies on a recently registered domain that redirects users to a dedicated Telegram bot, where instructions are provided for downloading and installing the APK outside official app stores. A successful compromise results in loss of control over the device, theft of banking credentials, and enables remote adversaries to perform on-device fraud within legitimate banking applications, potentially obscuring the victim’s screen during malicious activity. Regarding smishing activity, an ongoing campaign has been detected abusing the Trenitalia brand to exfiltrate users’ personal information. To obtain victims’ phone numbers and credit card details, the threat actor employs social engineering techniques, including typosquatting. Turning to the ransomware landscape, the following groups have claimed attacks against Italian organizations: Payload, targeting Vela Film S.r.l.; AiLock, targeting Studio Sardano Rag. Vincenzo; Space Bears, targeting BiesSse; Payouts King, claiming an unspecified Italian victim; and The Gentlemen, targeting Vicenzi S.p.A.

 

APT: supply chain and cyber espionage campaigns

Security researchers have uncovered a supply chain campaign dubbed PolinRider, attributed to the Lazarus Group, targeting development environments, developers’ workstations, and CI/CD pipelines through the deployment of two previously undocumented malware families, DEV#POPPER and OmniStealer. Remaining in North Korea, a campaign has been tracked and attributed with high confidence to ScarCruft, leveraging a CHM file as the initial infection vector in a multi-stage execution chain based exclusively on built-in Windows utilities. The operation features a selective payload delivery mechanism, although the exact selection criteria remain unknown and may include IP address verification, request timing, or other client-specific characteristics. Moving to Belarus, the state-sponsored Ghostwriter group (UNC1151, FrostyNeighbor) conducted a spear-phishing campaign aimed at stealing Google account credentials, including two-factor authentication codes, through an Adversary-in-the-Middle (AiTM) technique. The operation leveraged Bunny CDN to conceal the real IP addresses of phishing servers, while TLS certificates were frequently associated with infrastructure hosted in Poland. In Russia, researchers recently observed an espionage campaign conducted by the Moscow-based APT Sofacy, characterized by a high degree of stealth and a multi-stage infection process beginning with malicious documents containing macros. The attack chain employs advanced evasion techniques, including macro encryption, COM hijacking for persistence, and the abuse of a legitimate cloud service for command-and-control (C2) communications. In the Middle East, an Iranian threat actor tracked as Cavern Manticore has been observed deploying a new modular C2 framework called Cavern in targeted operations against Israeli organizations, primarily within the government and IT sectors. The actor shares technical similarities with other adversaries linked to Iran’s Ministry of Intelligence and Security (MOIS), including MuddyWater and OilRig. Additionally, a previously undocumented APT group, dubbed Armored Likho (also known as Eagle Werewolf), has been conducting and continues to maintain an active spear-phishing campaign targeting government agencies and organizations in the electric power sector across Russia, Brazil, and Kazakhstan. The campaign deploys a previously unseen Python-based infostealer named BusySnake Stealer. Since May 2026, a cluster tracked as UNK_MassTraction, suspected to be a China-aligned cyber espionage group, has exploited vulnerabilities in Roundcube Webmail to target the physics and engineering departments of leading universities in the United States and Canada. The campaign focuses on administrative and academic personnel involved in research areas with national security implications, particularly astrophysics and particle physics. Finally, an investigation conducted by the Citizen Lab at the University of Toronto revealed that Stelios Kouloglou, former Member of the European Parliament and Greek investigative journalist, was repeatedly targeted with the Pegasus spyware developed by the Israeli company NSO Group while serving as a substitute member of the European Parliament’s Committee of Inquiry investigating the use of Pegasus and equivalent surveillance spyware (PEGA). The evidence collected does not allow attribution of the infections to any specific government, nor does it indicate responsibility on the part of the Greek government. However, researchers identified an overlap between the first infection and a previous Pegasus campaign targeting exiled Russian- and Belarusian-speaking journalists and independent activists in Europe. This finding suggests that the operation was carried out by a Pegasus customer authorized to operate across multiple European countries.

 

Cybercrime: breaches, law enforcement operations, and credential theft

Regarding data breaches, Medtronic, a global leader in medical technologies, devices, and services, has notified approximately 3.8 million individuals potentially affected by the cyber incident that impacted certain corporate IT systems in April 2026. The attack was claimed by the ShinyHunters group, which alleged it had stolen approximately 9 million records and threatened to publish them unless a ransom was paid. In addition, the multinational IT services and consulting company Accenture confirmed that it had suffered a security breach following the publication of a data sale advertisement on underground forums. In the post, a threat actor identified as 888 claimed to have exfiltrated 35 GB of source code and other corporate data in July 2026. According to the claim, the stolen data includes source code, RSA keys, SSH keys, Azure Personal Access Tokens (PATs), Azure Storage access keys, and configuration files. On the law enforcement front, Spanish authorities arrested a suspected collaborator of the pro-Russian hacktivist groups CyberArmy of Russia Reborn (CARR) and Z-Pentest. The suspect is alleged to have participated in activities attributed to the pro-Russian hacktivist collective NoName057(16). In the same context, on July 2, 2026, the Google Threat Intelligence Group (GTIG) announced that it had conducted an operation against a residential proxy network known as NetNut (also known as Popa), in coordination with the FBI, Lumen Technologies, and other industry partners. The NetNut service has been associated with the Israeli company Alarum Technologies, which stated that it is cooperating with the authorities to investigate any potential abuse of its infrastructure. Regarding credential theft activity, according to a report published by a major UK national newspaper, threat actors stole login credentials belonging to numerous British government officials and Foreign Office personnel stationed overseas. The incident is linked to the FortiBleed campaign, which has compromised more than 80,000 Fortinet firewalls worldwide and is believed to have been active since at least February 2026. At present, there is no evidence indicating direct state involvement.

 


Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.

The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.

Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.

Learn more about our Cyber Threat Intelligence solution.