A lot of security still comes down to trusting the wrong screen.
This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder.
Some defenses improved. The loose parts still got found first. Anyway, here’s the mess.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
-
Phishing delivers XWorm
A cybercrime group known as xplogs22 has been observed targeting Russia and other CIS countries with phishing emails that deliver Xworm. The group, per F6, is believed to have been active since November 2023. Prior attacks mounted by the threat actors leveraged Formbook and Snake Keylogger, before switching to XWorm around July 2025. In recent months, Russian customers of the banking sector have also been targeted by an Android trojan called LunaSpy as part of social engineering attacks. LunaSpy can capture camera streams, record audio and the screen, and collect sensitive data. The malware is disguised as an antivirus application to evade detection.
-
Custom ransomware targets Russia
The financially motivated extortion group known as Toy Ghouls (aka Bearlyfy and Labubu) has targeted organizations in the Russian Federation, primarily in the manufacturing, financial services, retail, and technology sectors, with a custom ransomware family called GenieLocker since March 2026. According to Kaspersky, the group previously relied on third-party encryptors like RedAlert, LockBit, and Babuk. “GenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software,” Kaspersky said. In at least one case, initial access to the target environment was obtained via an OpenVPN connection originating from an external partner’s network, with the attackers likely exploiting the trusted relationship to breach the target, conduct reconnaissance, deliver additional tools for credential harvesting, and perform lateral movement via RDP and SSH to reach other Windows and Linux hosts. “During the impact phase, the attackers encrypted files on the compromised Windows machines with the PE version of the GenieLocker ransomware,” Kaspersky said. “On the compromised Linux and ESXi servers, they stopped active virtual machines and encrypted their disks using the ELF version of GenieLocker.” Details of the activity were first highlighted by F6 in March 2026.
-
Crypto-stealing payloads deployed
The malware loader known as CastleLoader, which has been previously used to deliver CastleStealer and a Python-based remote access trojan (RAT) via ClickFix-style lures, has now been used to distribute two payloads tied to the Needle Stealer framework: a Rust-based desktop wallet spoofer, and a Golang-based malicious browser extension installer. Arctic Wolf said it also identified a new shellcode loader variant spreading via digitally signed installers. The campaign has been codenamed Noidret. The introduction of these new tools is seen as an attempt to focus on cryptocurrency-specific targeting and establish browser-level persistence.
-
Fileless WebDAV execution
Speaking of ClickFix, CyberProof said it tracked a ClickFix variant that involves tricking victims into pasting a single command into the Windows Run dialog, which then communicates with a WebDAV endpoint and uses rundll32.exe to load a remote, non-DLL payload and call its first export by ordinal without having to leave any artifacts on disk. “The payload (gc.key, j.pm, or goog.ct) is a file served from the attacker WebDAV share and is not a standard DLL by extension,” CyberProof said. “It is invoked by rundll32.exe through ordinal #1, which runs its primary routine while keeping the export name off the command line.”
-
Fake Claude guide spreads malware
Victims searching Google for how to install Claude on a Mac are being served sponsored results that lead them to a weaponized claude.ai/share conversation dressed up as an Apple Support install guide. The “guide” instructs them to open Terminal and paste a single curl command, ultimately leading to execution of MacSync Stealer. “MacSync is a six-stage kill chain, not a smash-and-grab,” Huntress said. “The components are a thin zsh loader, a server-side AppleScript stealer that keeps the valuable logic off the endpoint and behind an api-key gate, a native Mach-O RAT for hands-on access, a separately signed helper built to steal a single TCC permission (Screen Recording), and a set of wallet-app trojans. Each stage sets up the ones that follow.”
-
Malware, intrusions, and influence ops
A Russian-speaking threat group is said to be behind an active campaign called Operation STANDOFF that combines commodity-malware distribution, a proxy-botnet that conscripts victims into relay infrastructure, targeted hands-on-keyboard intrusion of enterprise networks, and an AI-driven, multi-channel influence and engagement-manipulation capabilities under one roof. “The operation is materially more than a botnet,” VMRay Labs said. “It couples automated, scaled cybercrime with hands-on-keyboard, targeted intrusion and a coordinated influence capability, all on the same infrastructure and built by a common development team.” The influence apparatus uses networks of fake Telegram accounts and AI-generated personas to artificially boost the visibility of content, push commercial promotions, and drive traffic to gambling and fraud-adjacent services.

