The back half of July showed a sharp rise in stealthy, long-dwell threats: ransomware crews leaned on faster automation, cloud pivots, and polished extortion, while APTs pushed supply-chain abuse, identity attacks and browser-based C2. Active exploits across Fortinet, Cisco, Langflow, SharePoint and WordPress kept pressure high, making rapid patching and tighter admin controls essential for defenders.
Report Links
Download Threat Brief For July 16-31 2026
Byer-Nichols Threat Brief Podcast July 16-31 2026
Ransomware Actors
| Ransomware | Percentage | Last Period | Two Ago |
|---|---|---|---|
| The Gentlemen | 18.66% | 2 | 1 |
| Qilin | 15.32% | 1 | 2 |
| CRPxO | 5.70% | 18 | N/A |
| Global Secret Group | 4.91% | N/A | N/A |
| INC Ransom | 4.72% | 4 | 6 |
The second half of July saw The Gentlemen surge to the top with fast, automated intrusions hitting mid-market firms. Qilin stayed active in healthcare and manufacturing, leaning on harsher leak-site pressure. CRPxO jumped from obscurity by exploiting weak cloud segmentation, while Global Secret Group debuted with polished extortion operations. INC Ransom kept its steady pace, relying on long-term persistence to quietly expand access.
Victim Sector
| Sector | Percentage | Last Period | Movement |
|---|---|---|---|
| Manufacturing | 16.70% | 2 | 2 -> 1 |
| Retail | 14.54% | 5 | 5 -> 2 |
| Construction | 11.20% | 3 | same |
| Technology | 11.00% | 1 | 1 -> 4 |
| Financial Services | 11.00% | 4 | 4 -> 5 |
Victim Location
| Victim | Percentage | Last Period | Movement |
|---|---|---|---|
| USA | 42.63% | 1 | same |
| Canada | 6.29% | new | new |
| Germany | 4.32% | 2 | 2 -> 3 |
| India | 4.32% | new | new |
| UK | 3.14% | 3 | 3 -> 5 |
Victim Org Size
| Size | Percentage | Last Period | Change |
|---|---|---|---|
| Small Business (500 or less) | 80.16% | 79.72% | +0.44% |
| Mid-Market (501-5000) | 12.38% | 17.97% | -5.59% |
| Large Enterprise (5000+) | 7.47% | 2.30% | +5.17% |
Trending Adversaries
Recent activity from CyberAv3ngers, LAUNDRY BEAR, Mirage Kitten, REF9403, STAC4749, and UTA0533 shows a clear tilt toward supply-chain abuse, credential harvesting, and long-dwell espionage. Several groups are leaning on living-off-the-land tactics and cloud-service impersonation, making detection tougher. Mirage Kitten stands out as the most concerning thanks to its rapid pivoting and focus on high-value government and tech targets, signaling a rising need for stronger identity and cloud-control hygiene.
- CyberAv3ngers
- LAUNDRY BEAR
- Mirage Kitten
- REF9403
- STAC4749
- UTA0533
Trending & Actively Exploited Vulnerabilities
Late July exploitation is clustering around management planes: FortiOS and FortiSandbox bugs, Langflow RCE, Check Point SmartConsole, and Cisco Secure FMC all give attackers direct control over security tooling, while fresh SharePoint and WordPress core flaws open easy paths into collaboration sites and public-facing blogs. The big worry is chained use: Fortinet or Cisco for initial foothold, then SharePoint/WordPress for spread and persistence. Defenders should patch per vendor guidance, lock down internet-exposed consoles, enforce MFA, and watch for odd admin and content changes.
| CVE | Vendor | Product |
|---|---|---|
| CVE-2025-68686 | Fortinet | FortiOS |
| CVE-2026-0770 | Langflow | Langflow |
| CVE-2026-16232 | Check Point | SmartConsole |
| CVE-2026-20316 | Cisco | Secure Firewall Management Center |
| CVE-2026-25089 | Fortinet | FortiSandbox |
| CVE-2026-39808 | Fortinet | FortiSandbox |
| CVE-2026-50522 | Microsoft | SharePoint |
| CVE-2026-58644 | Microsoft | SharePoint |
| CVE-2026-60137 | WordPress | Core |
| CVE-2026-63030 | WordPress | Core |
Trending Malware
| Trending Malware | Details |
|---|---|
| ClickLock | ClickLock is a modular macOS infostealer delivered via ClickFix-style phishing pages that trick users into running a malicious shell script in Terminal. Once executed, it harvests browser credentials, password manager data, crypto wallets, and other sensitive files while the victim is distracted by a fake Cloudflare verification screen. The malware then displays a convincing macOS password prompt and, if the user refuses, repeatedly kills core processes so the Mac becomes unusable until the correct password is entered. Stolen data and the system password are sent to a Telegram channel, after which most modules self-delete but a GSocket-based backdoor remains for long-term remote access and potential lateral movement. |
| EncForge | EncForge is a statically compiled Go ransomware designed specifically to target AI infrastructure, with an extension list covering roughly 180 AI-related formats such as PyTorch and TensorFlow checkpoints, SafeTensors, ONNX, GGUF/GGML, FAISS indexes, and Parquet or Arrow training datasets. Delivered in recent campaigns by the JADEPUFFER operator via Langflow RCE and Docker escape, it focuses on encrypting the "crown jewels" of AI environments rather than generic business documents. EncForge uses AES-256-CTR in partial-file mode to quickly corrupt large model files, wrapping the symmetric key with an embedded RSA-2048 public key so only the attacker can generate decryption keys. It does not include data exfiltration code, making the impact primarily operational, disrupting AI services, destroying expensive models, and driving ransom leverage around business-critical ML assets. |
| HelloNet (HelloInjector, HelloProxy, HelloExecutor, HelloCleaner, HelloBackdoor) | HelloNet is a toolset abusing the update mechanism of the ViPNet private networking suite widely used in Russian government and regulated sectors. Attackers drop a malicious DLL (HelloInjector) into the ViPNet update directory so it is side-loaded by a legitimate service, gaining elevated privileges and persistence. In memory, HelloInjector runs HelloProxy to connect to C2 and pull additional modules such as HelloExecutor for command execution and reconnaissance, HelloCleaner to scrub ViPNet logs, and a Rust-based HelloBackdoor for file transfer and remote control. The campaign blends into trusted VPN infrastructure traffic and has been tentatively linked to a Chinese-speaking APT, posing significant risk of stealthy compromise and long-term espionage in high-value Russian networks. |
| HollowGraph | HollowGraph is a .NET espionage implant that authenticates to Microsoft Graph using compromised Microsoft 365 credentials and then abuses the mailbox calendar as a two-way dead drop. Operators plant far-future events (for example, dated May 13, 2050) with tasking embedded in attachments, which the malware retrieves via Graph API using a simple "get" command, while exfiltrated files are uploaded as encrypted attachments on its own calendar events via "send." All calendar traffic is protected with hybrid RSA plus AES-256 encryption, using separate key pairs for inbound tasking and outbound data to keep channels cryptographically distinct. A secondary DNS tunneling channel periodically refreshes Entra ID tenant, client, and secret values from attacker-controlled AAAA records, allowing the implant to maintain access while its C2 traffic blends seamlessly into normal Microsoft 365 activity, ideal for long-term, low-noise espionage. |
| msaRAT | msaRAT is a Rust-based remote access trojan used by the Chaos ransomware group that never talks directly to the network; instead, it drives Chrome or Edge via the Chrome DevTools Protocol. The malware launches the browser in headless mode, opens a remote debugging port, and injects JavaScript that sets up a WebRTC DataChannel using Cloudflare Workers for signaling and Twilio TURN for relaying traffic, so all C2 flows appear as legitimate browser WebRTC activity. Commands and data are additionally encrypted with a ChaCha-Poly1305 scheme layered on top of WebRTC's DTLS, with keys derived via ECDH, giving the channel double encryption and strong resistance to interception. From there, msaRAT can run reverse shells, move files, and tunnel arbitrary traffic, providing Chaos operators with a covert, resilient C2 path that hides inside everyday browser communications. |
| OWAReaper | OWAReaper is a JavaScript backdoor deployed by TA488 (Void Blizzard/Laundry Bear) via CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access where simply opening a crafted email in OWA triggers attacker-controlled code. The implant lives entirely in the browser, rewriting the malicious email to erase evidence, disabling UI elements to reduce user suspicion, and persisting by storing an encrypted copy of itself in localStorage and poisoned offline message caches so it reloads whenever OWA is opened. It harvests saved OWA credentials via autofill, abuses Outlook add-ins with ReadWriteMailbox permissions to steal OAuth tokens, and silently grants Owner-level permissions to the "Default" user across folders, effectively giving the actor organization-wide mailbox access that survives password resets and device reimaging. OWAReaper then uses web services and DNS tunneling for command-and-control and exfiltration, turning a single "half-click" email view into durable, server-side email espionage across targeted enterprises. |
Top News
- 1M+ Emails Use Hidden Text to Dupe AI Security Filters
- FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
- Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
- Microsoft warns of surge in ACR Stealer attacks on customers
- New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
- OpenAI models used Artifactory zero-days to escape to the internet, breach multiple orgs
- Police dismantle Kratos phishing platform, arrest developer
Contributors
Written by Jeremy Nichols, Director, Security Programs & Strategy at SecureSky Executive Summaries & Adversary Bio's by Geoff Rehmet, Cybersecurity Architect Produced & Distributed By Phish Tank Digital