Threat Hunt Feed (2026-07-04)
BleepingComputer
- NetNut proxy network disrupted, 2 million infected devices cut off — Fri, 03 Jul 2026 13:50:04 -0400
- Matched TTPs: IP Addresses (T1590.005), Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), Botnet (T1584.005), Domains (T1584.001), Proxy (T1090), Tool (T1588.002), Phishing (T1566), Software (T1592.002), Exploits (T1588.005), At (T1053.002)
- ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit — Fri, 03 Jul 2026 10:12:22 -0400
- Matched TTPs: Sharepoint (T1213.002), JavaScript (T1059.007), Malware (T1588.001), Hardware (T1592.001), Proxy (T1090), Compromise Accounts (T1586), Tool (T1588.002), Phishing (T1566), Multi-Factor Authentication (T1556.006), Software (T1592.002), At (T1053.002)
The Hacker News
- Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices — Sat, 04 Jul 2026 01:49:31 +0530
- Matched TTPs: Malware (T1588.001), Hardware (T1592.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Firmware (T1592.003), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)
- New Avalon Malware Framework Packs CrownX Ransomware Capabilities — Sat, 04 Jul 2026 00:25:24 +0530
- Matched TTPs: Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), Group Policy Preferences (T1552.006), Tool (T1588.002), Phishing (T1566), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), MSBuild (T1127.001), Windows Credential Manager (T1555.004), At (T1053.002), Inhibit System Recovery (T1490)
- Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer — Fri, 03 Jul 2026 19:06:33 +0530
- Matched TTPs: Scheduled Task (T1053.005), Artificial Intelligence (T1588.007), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), Server (T1584.004), Proxy (T1090), PowerShell (T1059.001), Tool (T1588.002), Phishing (T1566), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), Python (T1059.006), Remote Desktop Software (T1219.002), Visual Basic (T1059.005), At (T1053.002)
- PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords — Fri, 03 Jul 2026 13:33:37 +0530
- Matched TTPs: Pluggable Authentication Modules (T1556.003), JavaScript (T1059.007), Keychain (T1555.001), Malware (T1588.001), Vulnerabilities (T1588.006), SSH (T1021.004), Botnet (T1584.005), AppleScript (T1059.002), Server (T1584.004), Proxy (T1090), Tool (T1588.002), Compute Hijacking (T1496.001), Software (T1592.002), Social Media (T1593.001), Credentials (T1589.001), At (T1053.002)