Skip to main content
View all authors

September 2026 On Tap: Cloud Bucket Redirection Surge & Regional DGA Subdomain Telemetry

· 8 min read

September 2026 Threat Landscape Abstract​

In September 2026, across 148 verified malicious messages, threat actors demonstrated a sharp escalation in public cloud bucket redirection—with Google Cloud Storage (storage.googleapis.com) links jumping to 901 instances-while distributing payloads through high-entropy regional subdomains (.web.id, .my.id, .biz.id, .com.de) and DGA .us domains.

MITRE ATT&CK Techniques Observed This Month​

Top Risks & Findings This Month​

Google Cloud Storage Link Surge (storage.googleapis.com)

Our link extraction identified 901 total hyperlink references pointing to storage.googleapis.com across 148 messages (averaging ~6 redirector links per email across buttons, images, and footer anchors).

Focus: deep link unwrapping, public cloud storage gateway rules

Health & Medical Supplement Spam Dominance (43.2%)

Over 43% of September spam payloads promoted erectile dysfunction remedies, weight loss hacks, and cognitive supplement claims.

Focus: content filtering, domain reputation reputation rules

Regional Subdomain & DGA Infrastructure Exploitation

Heavy reliance on free or low-cost regional subdomains (.web.id, .my.id, .biz.id, .com.de) combined with random string .us domains.

Focus: high-entropy TLD blocking, dynamic DNS inspection

Cloud Storage Account Deletion Threat Influx (32.4%)

High volume of alerts alleging imminent cloud storage capacity limits or photo/video deletion unless billing details are updated.

Focus: security awareness training, external sender banners

The September dataset demonstrated a dramatic surge in links pointing to static Google Cloud Storage buckets (storage.googleapis.com), which threat actors use to host intermediate static HTML redirectors. Additionally, attackers routinely hotlink remote images from legitimate public hosts like Imgur (i.imgur.com) to bypass inline attachment filters:

Hostname / ServiceExtracted LinksRole in TelemetryInfrastructure Type
storage.googleapis.com901Static HTML bucket redirectorsThreat-Controlled Staging
i.imgur.com109Remote logo & banner image hotlinkingAbused Legitimate Service
d3k81ch9hvuctc.cloudfront.net10Content Delivery Network (CDN) assetsAbused Legitimate Service

Primary Sender Registrar TLDs & Full URL Structure​

Threat actors heavily utilized dynamic subdomains and hash-appended bucket URLs to deliver payloads:

  • Indonesian & Regional Subdomains (.web.id, .my.id, .biz.id):
    • xhtwlhmd.markif.lightworksa.web.id
    • xpysjlaa.teleso.barviko.my.id
    • pfgvdpzh.soibm.pravento.biz.id
    • vwwdtqtw.allied.metanova.biz.id
    • olyamzcr.samsung.kalqima.my.id
  • Random String DGA .us Domains:
    • aax.lbxrvtstbtbdw.us
    • saq.hcdwqozyylqgc.us
    • mhz.kmvhompywgibm.us
    • 628mqiak.us

Every extracted storage.googleapis.com URL in the September telemetry mapped to one of eight distinct bucket/object paths:

Bucket & Object PathLink CountTarget Redirector Role
worklinks/evrtinggood.html500Primary intermediate static HTML redirector
smalbus/salaminka.html383Secondary intermediate static HTML redirector
hmdbox/hmd-v1-cl3.html9Campaign variant redirector
yassales/hreflyass.html2Campaign variant redirector
strow/strw_v3.html2Staging variant redirector
strow/strw-v1-cl2.html2Staging variant redirector
bowly/bowly.html2Campaign variant redirector
sndrr/nobotgogomailbali_v2.html1Anti-bot detection staging script

Intercepted Phishing Case Studies & Evidence​

Below are key case studies highlighting major true phishing campaigns observed during the September collection window. Use the provided Gmail search terms to locate these exact lures in your spam folder.

Case Study A: Norton Anti-Virus Expiration & Infection Lure​

  • Gmail Search Query: Your NORTON Subscription Has or Your device has been infected with (22) viruses
  • Sender Domain: ukb.zhukxkxqvbeey.us
  • Subject: Your NORTON Subscription Has Expired — Your device has been infected with (22) viruses
  • Technique: Displays a fake urgent virus infection alert and subscriber ID, embedding static Google Cloud Storage redirector links (storage.googleapis.com/smalbus/salaminka.html).

Norton Anti-Virus Expiration Lure


Case Study B: Cloud Storage Deletion Extortion Threat​

  • Gmail Search Query: ACCOUNT SUSPENDED YOUR ACCOUNT AND ALL DATA WILL BE DELETED or Claim your free renewal today
  • Sender Domain: dawrnjdv.whatsapp.norquell.my.id
  • Subject: Your account has been suspended! All your files and memories will be erased on 09-26-2026
  • Technique: Leverages high-urgency loss-aversion threats claiming cloud storage backup files will be permanently erased, routing to static HTML buckets.

CloudDrive Account Deletion Threat Lure


Case Study C: "VapoCept" 15-Second Vicks Memory Restoration Lure​

  • Gmail Search Query: "I remembered my bank password again" — The 15-second Vicks video
  • Sender Domain: udzeuwhi.info.guzojsone.biz
  • Subject: "I remembered my bank password again" — The 15-second Vicks video
  • Technique: Promotes an absurd pseudoscience "Vicks-based protocol" by "VapoCept Research" claiming to cure memory loss and restore bank passwords in 15 seconds.

Vicks Memory Restoration Lure - Header & Sender Info

Vicks Memory Restoration Lure - Body & Presentation CTA


Threat Community & Sandbox Correlation​

Our telemetry findings correlate directly with external threat intelligence repositories, automated sandbox submissions, and active phishing feeds tracking these exact Google Cloud Storage bucket redirectors:

storage.googleapis.com/worklinks/evrtinggood.html

Classification & Role: Primary intermediate HTML redirector actively observed dynamically routing targets via client-side URL hash parameters (#...).

storage.googleapis.com/smalbus/salaminka.html

Classification & Role: High-volume static HTML redirector landing page flagged across multiple credential harvesting and tech support submissions.

storage.googleapis.com/sndrr/nobotgogomailbali_v2.html

Classification & Role: Anti-bot evasion script and kit identifier (nobot-gogo-mail-bali) designed to detect and filter automated security crawlers before routing human victims.

storage.googleapis.com/yassales/hreflyass.html

Classification & Role: Tech support, browser locker, and urgency alert redirector variants (also observed alongside strow/strw_v3.html).


🍻 The Defensive Playbook​

Apply these four security controls to protect organizational inboxes against cloud bucket redirection and DGA subdomain lures:

Inspect Public Cloud Bucket Links

Enforce gateway URL inspection for links pointing to storage.googleapis.com and s3.amazonaws.com to resolve final payload destinations before delivery.

Restrict Dynamic Regional Subdomains

Flag or score inbound email containing URLs or sender domains hosted on high-entropy .web.id, .my.id, .biz.id, and random .us subdomains.

Enforce FIDO2 / Passkey Authentication

Deploy phishing-resistant MFA (FIDO2 / WebAuthn / Passkeys) to neutralize credential harvesting portals accessed via email links.

Maintain Safe Sender Allowlists

Review spam gateway rules to ensure legitimate vendor communications (rewards updates, event bulletins) avoid automated spam folder placement.

August 2026 On Tap: Gmail Telemetry, Credential Harvesting, & Cloud Redirect Evasion

· 6 min read

August 2026 Threat Landscape Abstract​

In August 2026, I took a look at email spam telemetry retrieved directly from active Gmail inboxes. Out of 141 total emails analyzed, I isolated 95 true malicious phishing payloads (67.4%) and identified 46 legitimate marketing false positives (32.6%) routed to Spam by Gmail's automated filters.

MITRE ATT&CK Techniques Observed This Month​

Top Risks & Findings This Month​

Google Cloud Storage Redirectors (storage.googleapis.com)

Massive abuse of static Google Cloud Storage HTML buckets acting as obfuscated redirectors to bypass URL reputation filters.

Focus: inbound link inspection, public cloud bucket filtering, deep URL unwrapping

High Gmail Filter False-Positive Rate (32.6%)

Nearly 1 in 3 emails in the spam folder were legitimate opt-in vendor newsletters tripped by engagement heuristics.

Focus: safe-sender domain rules, engagement scoring, header inspection

Work-From-Home & Job Lure Campaign Surge (65.3%)

Widespread targeting of users with remote recruitment lures offering high daily rates for data entry or remote roles.

Focus: security awareness training, HR outreach verification

DGA & High-Entropy TLD Exploitation (.my.id, .web.id, .us)

High concentration of automated phishing infrastructure hosted on regional free subdomains and synthetic high-entropy TLDs.

Focus: TLD reputation blocking, dynamic DNS inspection

1. True Malicious Phishing Vector Taxonomy​

After filtering out legitimate marketing false positives, our telemetry isolated 95 true malicious phishing emails. Threat actors focused heavily on urgency, financial incentive, and brand impersonation.

True Malicious Payloads (95 Messages):
+------------------------------------+-------+-------------------+
| Category / Vector | Count | Share % (of 95) |
+------------------------------------+-------+-------------------+
| Credential Harvesting Lures | 62 | 65.3% |
| Job / Work From Home Lures | 62 | 65.3% |
| Fake Invoice & Billing Lures | 29 | 30.5% |
| Account Suspension / Alert Lures | 17 | 17.9% |
| Package / Delivery Lures | 9 | 9.5% |
| Gift Cards & Sweepstakes Lures | 6 | 6.3% |
+------------------------------------+-------+-------------------+

Observed Payload Characteristics​

  1. Account Login & Portal Lures (65.3%): Messages referencing account verification, sign-in alerts, or document access requiring user action.
  2. Work-From-Home & Job Lures (65.3%): Recruitment notices promising $300–$800/day for remote roles, directing recipients to external contact links.
  3. Storage & Service Expiration Alerts (17.9%): Urgent notices alleging cloud storage capacity limits or impending file deletion unless billing details are updated.

2. Infrastructure & Domain Distribution​

Threat actors in the August dataset relied heavily on regional domain registrars (.my.id, .web.id, .biz.id) and synthetic DGA hostnames:

Top Malicious Infrastructure Hostnames & TLDs​

Registrar TLD / InfrastructureEmail CountPrimary Observed Lure Type
.my.id (Indonesian Subdomains)17Account lock & photo deletion alerts
.web.id (Regional Subdomains)8Medical & reward promotions
.biz.id (Regional Subdomains)6Account verification alerts
High-Entropy .biz Domains28DGA hostnames (cloudnatrix.biz, dataanaly.biz, ficociti.biz)
Random String .us Domains14Brand impersonation lures (628xsfhv.us, jhsmcmc.us)
Synthetic TLDs (.qcw, .ugc, .cmx)8Anti-virus expiration warnings ([email protected])

3. Intercepted Phishing Case Studies & Evidence​

Below are screenshots of real phishing lures intercepted during the August collection window, highlighting observable header, sender, and body characteristics.

Case Study A: Anti-Virus & Tech Support Security Alert​

  • Subject: FINAL WARNING — Virus Protection Turned OFF
  • Sender Domain: [email protected]
  • Observed In Payload: Contains a styled green text banner "- This message was sent from a trusted sender." and embeds links pointing to storage.googleapis.com.

Anti-Virus Scam Lure


Case Study B: Brand Impersonation & Free Gift Lure​

  • Subject: Claim your free CAA Deluxe Roadside Emergency Kit
  • Sender Domain: [email protected]
  • Observed In Payload: HTML document title set to CAA Deluxe Roadside Emergency Kit Survey, containing links to storage.googleapis.com with base64 parameter go=1&s1=2342770&s3=CAA.

CAA Roadside Kit Impersonation


Case Study C: Casino Cash Lure​

  • Subject: Daily Reward Inside: Log In to Claim Your Bonus Cash!
  • Sender Domain: jhsmcmc.us
  • Observed In Payload: Prompts recipient to click a yellow "Claim My Bonus Now" button leading to external links.

Casino Bonus Header

Casino Bonus Body Lure


Case Study D: Cloud Storage Account Deletion Warning​

  • Subject: We've blocked your account! 🚫 Your photos and videos will be deleted...
  • Sender Domain: mvglerar.aseco.tanviro.biz.id
  • Observed In Payload: Displays a red "Review billing" button and alert claiming cloud storage subscription expired and photos/videos will be deleted on a specified date.

Cloud Storage Extortion Lure

Cloud Storage Order Details


🍻 The Defensive Playbook​

To protect your inbox from cloud redirect tricks, apply these four security controls:

🍺 1. Filter Cloud Redirect Hops

Don't trust links just because they start with storage.googleapis.com or s3.amazonaws.com. Enforce deep URL unwrapping at your email gateway to unmask the final destination payload.

🍺 2. Tighten the Spigot on DGA & Regional TLDs

Restrict or flag inbound mail carrying links to high-entropy .my.id, .web.id, and random .us / .biz subdomains. These dynamic registrars are heavily abused for automated phishing rotators.

🍺 3. Call Out Synthetic Trust Banners

Train users that inline banners claiming "- This message was sent from a trusted sender" rendered in the email body are attacker-injected HTML illusions, not mail client security badges.

🍺 4. Tune Spam Filter Settings

If legitimate vendor updates (like rewards points or security bulletins) get dumped into Spam, review engagement thresholds and establish trusted sender rules for authenticated domains.

July 2026 Threat Landscape: Botnet Convergence, LLM Stack Scrapes, & Intercepted Malware

· 6 min read

July 2026 Threat Landscape Abstract​

As the malware threat landscape evolves, attacker reconnaissance is becoming hyper-targeted. Across the Malware on Tap sensor fleet, recent telemetry reveals three major trends:

  • relentless automated MySQL brute-forcing accounting for over 77% of all service touches
  • automated scanning for emerging AI/LLM infrastructure credentials (such as LiteLLM and LangChain)
  • active payload distribution targeting exposed enterprise endpoints

Top Risks Observed This Month​

Database Credential Stuffing (Port 3306)

Massive automated brute-force scripts targeting exposed MySQL instances using administrative defaults.

Focus: network segmentation, non-standard ports, strict IP allowlisting

LLM Framework Credential Harvesting

Wordlist expansion targeting emerging AI proxies (LiteLLM, LangChain, Ollama, Open WebUI).

Focus: enforce proxy authentication, API key rotation, access logs

Cloud Secret Extraction (.env & Androxgh0st)

Probing web roots for environment files to extract AWS, SendGrid, and Laravel secrets.

Focus: web server deny rules for hidden files, secret scanners

Automated Malware Payload Interception

Active delivery of Windows Trojans, SMB relay worms, and RAT agents to exposed ports.

Focus: EDR coverage, SMB protocol hardening, egress filtering

Sensor Fleet Threat Dossier​

FLEET DOSSIER

Attacker activity has shifted from indiscriminate port scanning to automated secret extraction and targeted LLM stack reconnaissance.

Primary Targets
  • Cloud-hosted MySQL & MSSQL databases
  • AI/LLM middleware proxies & APIs
  • Public web roots with unhedged .env files
Primary Vectors
  • Credential brute-forcing (cron, sa, root)
  • Androxgh0st vulnerability scraping
  • Direct HTTP / SMB binary execution
Primary EffectInitial access, credential theft, & malware staging
Technical Signals & Targeted Ports
Ports
3306 / MySQL80 / HTTP445 / SMB1433 / MSSQL5060 / SIP2222 / SSH

1. Massive MySQL Database Reconnaissance​

Database infrastructure remains the primary target for automated credential stuffing and initial access broker (IAB) scripts.

  • Port 3306 Volume: 46,354 connections representing 77.2% of all network service touches across the sensor fleet.
  • Top Credential Pairs: Attackers focused heavily on default administrative accounts, led by cron (45,802 attempts), sa (816 attempts), root (170 attempts), and admin (158 attempts).
  • Password Profiles: Over 58.7% of attempted passwords fell into simple alphanumeric patterns (1qaz2wsx, 12345678, password), highlighting that botnets continue to exploit weak credential management in cloud-hosted database instances.
Target Port: 3306 (MySQL)
Total Touches: 46,354
Top Usernames: cron (45,802), sa (816), root (170), admin (158)
Top Passwords: 1qaz2wsx (22), 12345678 (18), password (16), saadmin (15)

2. Emerging Threat Vector: LLM Proxy & AI Stack Reconnaissance​

One of the most notable telemetry developments is the shift toward harvesting credentials for Artificial Intelligence and Large Language Model (LLM) orchestration frameworks.

  • Observed Credential Attempt: ishaan-litellm:langchain
  • Analysis: Threat actors are actively updating wordlists to probe for exposed LLM proxy endpoints (such as LiteLLM proxy wrappers, LangChain agents, Ollama servers, and Open WebUI interfaces).
  • Attacker Goal: Gaining unauthorized access to underlying OpenAI/Anthropic/AWS Bedrock API keys hosted within LLM proxies, or executing prompt-injection and agent hijacking attacks against internal model workflows.

3. Secret Extraction & Androxgh0st Botnet Scanning​

Attacker web probes continue to prioritize environment variable exposure to extract high-value cloud credentials:

  • Androxgh0st Activity: Detections logged 1,142 androxgh0st_probe events designed to scrape .env files for AWS S3 credentials, SendGrid keys, Twilio auth tokens, and Laravel APP_KEY values.
  • Environment File Probing: Over 3,000 requests specifically targeted web root secret files:
    • /.env (1,521 requests)
    • /.env.production (342 requests)
    • /.env.save (330 requests)
    • /.env.local (305 requests)
    • /api/.env (302 requests)
    • /backend/.env (301 requests)

4. Captured Malware Binary Analysis​

Sensors automatically captured and recorded raw malware binary payloads delivered during active exploitation attempts:

Payload Source URL / PathIntercept CountProtocolThreat Description
http://156.238.237.180:3151/exiles.exe28HTTPWindows Trojan / Payload Dropper
smb://119.93.219.317SMBSMB Worm Propagation / NTLM Relay
http://star.zcnet.net:7766/Server.exe3HTTPRemote Access Trojan (RAT) Agent

Defensive Takeaways & IoCs​

Key Recommendations​

  1. Never Expose Port 3306 to Public Internet: Restrict MySQL and database management ports to internal VPCs or enforce strict IP allowlisting / VPN access.
  2. Secure AI & LLM Proxy Endpoints: Enforce multi-factor authentication (MFA) and strong API key rotation on LiteLLM, LangChain, and self-hosted AI middleware.
  3. Block .env Access at Reverse Proxy Level: Ensure Nginx, Apache, or Caddy rules block public HTTP access to all hidden files (location ~ /\. { deny all; }).

Technical Indicators of Compromise (IoCs)​

TypeIndicatorContext
IPv4156.238.237.180Host serving exiles.exe malware payload
IPv4119.93.219.3Host serving SMB relay / worm payload
Domainstar.zcnet.netHost serving Server.exe RAT binary
User AgentLinux Gnu (cow)Active web scanner probing exposed HTTP endpoints
Credentialishaan-litellm:langchainLLM framework credential harvesting probe

June 2026 Threat Landscape: AI-Driven Operations

· 5 min read

June 2026 Threat Landscape Abstract​

While security marketing has spent the last year yelling about hypothetical "autonomous AI zero-day writers," the reality on the ground in June is far more pragmatic. Threat actors are treating Large Language Models (LLMs) exactly like enterprise developers do: as an efficiency multiplier to scale manual, time-consuming tasks.

Why spend hours crafting the perfect social engineering script or manually scraping attack surfaces when an LLM can do it in seconds? This isn't about new attack types; it's about attack acceleration.


Threat Dossier: The Automation of Initial Access​

Europol’s flagship 2026 Internet Organised Crime Threat Assessment (IOCTA) report, titled "How encryption, proxies, and AI are expanding cybercrime," brought this shift into sharp focus. The assessment details an environment where malicious actors are actively closing the "velocity gap" against defenders by weaponizing automation.

Europol IOCTA 2026 Key Takeaway:

"Cybercriminals are rapidly exploiting advanced technologies, particularly AI tools, to enhance the speed, efficiency, and scope of their illicit activities. These tools not only enable automation in criminal processes but also blur the lines between legitimate and malicious uses of technology."

— Catherine De Bolle, Executive Director

The Four Pillars of AI-Accelerated Crime​

The June trends highlight how unfiltered, custom LLMs circulating on the dark web (alongside jailbroken public models) are expanding criminal capabilities across four specific vectors:

Improved Phishing

Eradicating the classic spelling and grammatical red flags that historically triggered human suspicion, creating perfectly localized, multi-lingual variants.

Focus: phishing defense, email hygiene

Automated Reconnaissance

Lowering the technical skill barrier required for attackers to scan perimeter environments and immediately map target architectures.

Focus: attack surface management, logs

Better Social Engineering

Generating highly dynamic conversational scripts used by extortion call centers to manipulate targets via cold-calling.

Focus: security awareness, training

Scaling Operations

Combining generative AI with legacy infrastructure enablers—like proxies, end-to-end encryption (E2EE), and SIM farms capable of distributing thousands of messages simultaneously.

Focus: identity behavioral baseline, signals

Technical Signals​

The intersection of AI, credential theft via infostealers, and the shifting tactics of major ransomware affiliates (like Qilin and Scattered Spider network fragments) shaped the primary attack paths throughout June.

Attack VectorMITRE ATT&CKObserved TTPs & Trend Data
Bespoke Phishing & Social Eng.T1566 / T1566.002Use of malicious, unaligned LLMs to draft realistic, context-aware corporate communications. The focus is on executing highly convincing multi-turn chat interactions to extract secondary authentication tokens.
Industrialized ReconnaissanceT1595 / T1046Attackers utilizing agentic AI scraping frameworks to map out exposed external network interfaces, matching public employee footprints against active infostealer credential dumps.
Pure Exfiltration (Data Theft)T1020A decisive ecosystem shift toward non-encryption extortion models (documented extensively in early summer incidents like the Canvas/Instructure breach). Attackers exfiltrate data and apply psychological pressure without touching a system's availability.
MFA Interception & ProxyingT1556Adversary-in-the-Middle (AiTM) proxy infrastructure being deployed via automated setups to defeat standard push notifications and telephony-based multi-factor authentication.

Defensive Takeaways​

Because June’s threat landscape shows attackers optimizing how they improve their use of existing entry vectors rather than inventing new ones, defensive strategy needs to adapt away from static signature detection and focus heavily on identity behavior analysis.

Mandatory FIDO2/WebAuthn Passkeys

As AI-driven social engineering makes human beings increasingly susceptible to credential harvesting, legacy multi-factor methods (such as SMS, telephony, or basic TOTP authenticator apps) are no longer sufficient boundary controls. Organizations should aggressively transition toward unphishable, hardware-backed authentication.

Focus: passkey enrollment, hardware keys

Behavioral Identity Controls (UBA)

If an attacker can purchase a valid, infostealer-harvested session cookie on a dark web marketplace and use an AI framework to seamlessly mirror user traffic, standard perimeter checks fail. Defenses should pivot to continuous session evaluation—monitoring for impossible travel, abrupt user-agent modifications, and anomalous data-access patterns.

Focus: session telemetry, anomaly detection

Prepare for Pure Data-Exfiltration Extortion

Traditional backup strategies protect against encryption-based ransomware, but they offer zero leverage when an actor threatens to leak sensitive internal data publicly. Security leaders should run table-top simulations that specifically address data theft extortion, establishing definitive legal, notification, and regulatory playbooks before an incident occurs.

Focus: incident playbooks, data classification

References​

Spring 2026 Threat Landscape: Threat Actors, Supply Chain & CI/CD Risk

· 14 min read

Spring 2026 Threat Landscape Abstract​

Nation-state actors and financially motivated groups continue to converge in tactics, with increasing emphasis on identity abuse, supply chain compromise, and infrastructure-level access.

Rather than relying solely on malware, many threat actors are shifting toward abusing legitimate access, trusted relationships, and existing enterprise tooling.

Top Risks Observed This Month​

Identity compromise (OAuth / valid accounts)

Abuse of OAuth consent flows and stolen credentials to maintain persistent access.

Focus: sign-in logs, token usage, conditional access signals

Supply chain compromise (CI/CD + dependencies)

Malicious or manipulated dependencies and pipeline injection attacks.

Focus: dependency monitoring, build-time egress controls

Exposed ICS / OT systems

Internet-facing industrial systems targeted via weak authentication and exposed protocols.

Focus: eliminate exposure, monitor ICS protocol traffic

Credential reuse across environments

Shared credentials enabling lateral movement across systems and environments.

Focus: enforce MFA, isolate dev/prod identity boundaries

Limited east-west visibility

Lack of internal network monitoring enabling undetected lateral movement.

Focus: internal traffic analytics, anomaly detection

Threat Actors Driving Activity​

Iranian-Aligned Activity​

THREAT DOSSIER

Iranian-affiliated actors were observed exploiting internet-facing PLCs and OT management tooling with a focus on energy and water sectors. Vendor and government advisories during March–April 2026 describe exploitation of Rockwell/Allen-Bradley controllers, use of legitimate engineering tools and valid credentials, and VPS-based ingress to obscure operator sessions.

Primary Targets
  • Energy and water sector operators
  • Industrial control and SCADA-adjacent environments
Primary Access
  • Exposed PLCs
  • Engineering workstations
  • Remote management paths
  • Externally exposed OT access points
Primary EffectDisruption and operational interference
Technical Signals
Ports
502 / Modbus44818 / EtherNet-IP1022222
MITRE Techniques Observed

North Korea-Aligned Activity​

THREAT DOSSIER

North Korean actors continue to blend financially motivated operations with espionage, increasingly relying on credential theft, OAuth consent abuse, and identity-based persistence rather than noisy malware.

Primary Targets
  • Cryptocurrency services & exchanges
  • Financial institutions and payment processors
  • Third-party contractors with privileged access
Primary Access
  • Spearphishing & credential phishing
  • OAuth consent/third-party app abuse
  • Stolen or purchased credential sets
Primary EffectFund diversion, long-term access, and operational footholds
Operational Focus

Rapid credential harvesting followed by account takeover and token persistence. Use of obfuscated tooling to move funds and maintain access without triggering obvious alarms.

MITRE Techniques Observed

China-Aligned Activity​

THREAT DOSSIER

China-aligned groups continue to prioritize stealth, persistence, and targeted espionage against government, defense, and strategic industry targets. Emphasis remains on minimizing operational noise and maintaining access.

Primary Targets
  • Government & defense contractors
  • Telecommunications and critical infrastructure
  • High-value enterprise IP repositories
Primary Access
  • Supply chain compromise
  • Credential harvesting & lateral movement
  • Custom backdoors & firmware-level persistence
Primary EffectIntelligence collection, long-term data exfiltration
Operational Focus

Long-term access and low-noise espionage: prioritizing firmware/backdoor persistence, stealthy lateral movement, and exfiltration of high-value data over time.

MITRE Techniques Observed

Supply Chain Attacks​

THREAT DOSSIER

Supply chain compromise persists as a high-impact vector, leveraging build pipelines, dependencies, and vendor trust relationships to spread malicious code/backdoors into dependent systems.

Primary Targets
  • CI/CD pipelines and build infrastructure
  • Open-source package ecosystems
  • Third-party integrations and vendor tooling
Primary Access
  • Compromised build secrets
  • Malicious dependency updates
  • Compromised vendor accounts
Primary EffectWidespread code injection, stealthy persistence, and rapid downstream compromise
Behavior

Malicious code introduced through dependency updates, obfuscated post-install scripts, or unauthorized build step injection.

MITRE Techniques Observed

CI/CD Pipeline Compromise​

THREAT DOSSIER

Attackers target CI/CD pipelines to insert malicious build steps, exfiltrate secrets, or cause tainted artifacts to be produced at scale.

Primary Targets
  • Build servers and artifact repositories
  • Deployment orchestration systems
  • Secrets management back-ends
Primary Access
  • Compromised deploy keys
  • Misconfigured runners with wide privileges
  • Leaked pipeline variables and tokens
Primary EffectTainted builds, secret exfiltration, and mass compromise of downstream consumers
Behavior

Injection of unauthorized build steps, unauthorized artifact signing, and exfiltration of secrets from pipeline environments.

MITRE Techniques Observed

Observations & Conclusions​

Spring 2026 reinforces a continued shift toward identity-driven attacks, infrastructure-level compromise, and scalable supply chain exploitation.

Iran-focused groups emphasize disruption of critical infrastructure, North Korean actors blend financial operations with identity abuse, and China-aligned groups prioritize stealth and persistent espionage.

Top defensive takeaways
  • Prioritize identity hygiene: MFA, conditional access, OAuth application controls
  • Eliminate internet-facing OT protocols and enforce segmentation
  • Harden CI/CD pipelines and rotate build secrets
  • Increase east-west visibility and baseline normal internal flows (especially engineering/development)

References​

  • Cybersecurity and Infrastructure Security Agency (CISA). (2026). AA26-097A: IRGC-Affiliated Cyber Actors Exploit Internet-Facing PLCs in Water and Wastewater Systems. cisa.gov.
  • Cybersecurity Dive. (2026). Iran-linked hackers targeting water, energy in US, FBI and CISA warn. cybersecuritydive.com.
  • Tenable Research. (2026). What to Know About CyberAv3ngers, the IRGC-Linked Group Targeting Critical Infrastructure. tenable.com.
  • Unit 42, Palo Alto Networks. (2026). Boggy Serpens Threat Assessment. paloaltonetworks.com.
  • Chainalysis. (2026). OFAC Targets North Korean IT Workers and Cryptocurrency Networks. chainalysis.com.
  • SC World. (2026). Drift Protocol crypto heist pinned on North Korean APT. scworld.com.
  • CyberNews. (2026). Chinese spy group TA416 targets Europe, NATO. cybernews.com.
  • Unit 42, Palo Alto Networks. (2026). Playbook of espionage campaigns against military targets. paloaltonetworks.com.