Weekly Threat Intel Report — 2026-W30
TL;DR
The week of 20–26 July 2026 was defined by three converging trends. First, an international coalition led by the UK's National Cyber Security Centre publicly exposed Laundry Bear, a Russia-linked cluster running near-zero-click phishing against Zimbra webmail servers used by Western governments and Ukrainian entities. Second, defenders confronted a wave of AI-enabled attack tradecraft — from the Hermes AI agent being pointed at Thailand's Ministry of Finance in unattended mode, to CrowdStrike's write-up of SANDWORM_MODE-style AI toolchain supply-chain attacks. Third, ransomware and extortion actors kept the pressure on: Clop pivoted to internet-exposed PTC Windchill and FlexPLM servers, Chaos debuted a browser-tunneled RAT called msaRAT, and ShinyHunters breach data is now fueling a $2,000 Bitcoin sextortion wave.
Notable Activity by Actor
Laundry Bear (Russia-linked, newly named)
On 23 July, UK NCSC and international partners publicly attributed a global phishing campaign targeting Zimbra webmail to a Russia-linked cluster designated Laundry Bear. Unit 42, DarkReading, and The Record independently corroborated the operation. The campaign is notable for its low interaction requirement: opening or previewing a crafted message is enough to trigger a malicious JavaScript payload that harvests credentials and session material from webmail sessions. Unit 42 characterized the targeting as global, with an emphasis on Western organisations and Ukrainian entities. This is one of the higher-signal state-sponsored disclosures of the quarter, and defenders operating Zimbra should treat this as an urgent hardening priority.
Clop
BleepingComputer reported that the Clop (Cl0p) ransomware crew is targeting internet-exposed PTC Windchill and FlexPLM instances in a fresh data-theft extortion campaign. This continues Clop's multi-year pattern of building campaigns around enterprise application zero-days and n-days (MOVEit, GoAnywhere, Cleo, Accellion). Product lifecycle management systems are particularly attractive because they concentrate engineering IP, supplier data, and product roadmaps.
Chaos ransomware — msaRAT
Cisco Talos published research on msaRAT, a new tool linked to the Chaos ransomware group. Rather than connecting to attacker infrastructure directly, msaRAT hijacks the victim's browser and tunnels command-and-control through WebRTC over TURN. From the victim's perspective, network telemetry sees only browser-originated web traffic; the attacker's true IP is never visible on the compromised host. Expect this pattern — living off the browser for C2 — to be copied.
ShinyHunters
BleepingComputer traced a $2,000 Bitcoin sextortion email wave to email lists sourced from previously leaked ShinyHunters breach datasets. The tradecraft itself is not novel, but it illustrates how prior mass leaks continue to power downstream monetization long after the original breach.
ClearFake
Red Canary's July Intelligence Insights placed ClearFake back at the top of its monthly threat rankings, alongside the debut of CastleLoader in the top tier. ClearFake continues to lean on compromised sites and fake browser/software update lures as initial access.
Emerging Threats
AI agents used offensively (Hermes / Thai Ministry of Finance)
BleepingComputer reported that a threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. While details remain limited, this is one of the first credible public accounts of an agentic AI system driving hands-on-keyboard-equivalent activity end-to-end inside a victim environment. Defenders should assume that both time-to-impact and attacker workforce scale will change as this tradecraft matures.
SANDWORM_MODE and AI toolchain supply-chain attacks
CrowdStrike published detection guidance for SANDWORM_MODE, a class of attack in which malicious code rides trusted AI development tools and workflows, making activity nearly indistinguishable from legitimate developer behaviour. DarkReading covered the same emerging pattern under the framing "attackers are learning to live off the AI toolchain." This ties in with ongoing coverage of slopsquatting / HalluSquatting / phantom domain attacks, in which malicious packages, repos, or domains exploit AI coding assistants that hallucinate non-existent dependency names.
WordPress "WP2Shell" (CVE-2026-60137 + CVE-2026-63030)
DarkReading reported that within three days of disclosure, attackers were widely chaining CVE-2026-60137 and CVE-2026-63030 — collectively branded "WP2Shell" — to achieve remote takeover of millions of WordPress sites. This is a classic mass-exploitation window; patch immediately if not already done.
Azure Automation cross-tenant identity takeover
DarkReading reported Microsoft has addressed a default Azure Automation configuration together with a chain of code flaws that could have allowed cross-tenant identity takeover, exposing another tenant's data, credentials, and cloud workloads. Separately, researchers ahead of Black Hat disclosed passkey implementation flaws in Microsoft's handling that permit impersonation of privileged users — a reminder that even phishing-resistant factors depend on correct implementation.
Microsoft 365 outage
Microsoft attributed a large Microsoft 365 and Azure outage this week to a bug in its automated network-maintenance request system that stripped IP routes from more devices than intended. It is an availability rather than security incident, but it underscores continued dependency risk on a small number of cloud providers.
Mobile surveillance — fake Bahrain Alert app
DarkReading reported a four-stage Android spyware delivered via typosquatted Google Play sites impersonating a Bahrain civil-defence alerting app, capitalizing on civilian fear during Iranian missile activity. This is a textbook example of geopolitical events being weaponized for mobile surveillance operations against civilians and diaspora communities.
Defender Takeaways
- Patch Zimbra now and review webmail JavaScript execution controls, session-cookie handling, and content-security policy. Assume opened/previewed messages could equal compromise until patched.
- Inventory internet-exposed PTC Windchill / FlexPLM deployments. Take them off the public internet where possible; if not, put them behind an authenticating proxy and monitor for data-egress patterns consistent with Clop's tradecraft.
- Hunt browser-mediated C2. msaRAT-style tradecraft means process-based EDR alone will not surface C2 — look for anomalous WebRTC/TURN activity from user browsers, especially on servers or non-user workstations.
- Threat-model your AI toolchain. Treat AI coding assistants, agentic build tools, and any place your organisation trusts an LLM to name a dependency, package, or endpoint as an attack surface. Adopt pre-fetch verification and pinned, governed dependencies.
- Assume ShinyHunters-era breach data is public forever. Continue to force MFA on high-value accounts, deprecate SMS where possible, and prepare users for the reality that sextortion/coercion messages will continue to reference real, historic passwords and details.
- Review Azure Automation defaults and any tenant-boundary trust decisions. Where you use passkeys, validate implementation, not just presence.
- Move on WordPress WP2Shell now — the disclosure-to-mass-exploitation window closed in about 72 hours.
- Include mobile in geopolitical crisis playbooks. During kinetic conflict, expect malicious apps impersonating emergency-alert services within days.
Sources
- UK NCSC, UK and partners expose Russian state-supported actors for new 'zero-click' phishing campaign, 2026-07-23 — https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign
- Unit 42, Russian Global Webmail Espionage, 2026-07-23 — https://unit42.paloaltonetworks.com/russian-webmail-espionage/
- The Record, International alert spotlights Russia-linked attacks on Zimbra webmail, 2026-07-23 — https://therecord.media/zimbra-webmail-zero-click-phishing-russia-laundry-bear
- DarkReading, Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets, 2026-07-23 — https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
- BleepingComputer, Clop ransomware targets Windchill, FlexPLM in data theft attacks, 2026-07-24 — https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
- Cisco Talos, Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel, 2026-07-23 — https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
- BleepingComputer, ShinyHunters data leaks fuel $2,000 sextortion email scam, 2026-07-25 — https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam/
- Red Canary, Intelligence Insights: July 2026, 2026-07-23 — https://redcanary.com/blog/threat-intelligence/intelligence-insights-july-2026/
- CrowdStrike, Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks, 2026-07-21 — https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/
- BleepingComputer, Hermes AI agent used to automate attack on Thai Finance Ministry, 2026-07-24 — https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attack-on-thai-finance-ministry/
- DarkReading, 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover, 2026-07-20 — https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover
- DarkReading, Default Azure Automation Setting Enables Cross-Tenant Identity Takeover, 2026-07-24 — https://www.darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover
- DarkReading, Fake Bahrain Alert App Deploys Android Surveillance Malware, 2026-07-22 — https://www.darkreading.com/mobile-security/fake-bahrain-alert-apps-android-surveillance-malware
- Microsoft Threat Intelligence, Email threat landscape: Q2 2026 trends and insights, 2026-07-23 — https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
- BleepingComputer, Microsoft blames massive Microsoft 365 outage on maintenance bug, 2026-07-24 — https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-massive-microsoft-365-outage-on-maintenance-bug/