Back to Feed
Threat IntelligenceSep 3, 2026

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Threat actors exploit IT impersonation, OAuth, and phishing kits in various attacks.

Summary

This edition of ThreatsDay highlights several evolving attack vectors, including threat actors impersonating IT support via Microsoft Teams to gain remote access and deploy malware. The Spring Ring campaign specifically uses Teams for vishing, sometimes escalating to NTLM relay attacks. Additionally, the Gentlemen ransomware operation continues to expand with a sophisticated affiliate playbook, and the PhaaS platform Outsider shows resilience despite law enforcement actions.

Full text

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories Ravie LakshmananSep 03, 2026Hacking News / Cybersecurity News The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also ransomware, stolen ID data, hidden attack servers, and weak settings that should have been fixed long ago. Here’s the full list. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Fake IT, Real Access Threat Actors Impersonate IT Support Microsoft has warned of a human-operated intrusion campaign that leverages Microsoft Teams external collaboration to impersonate IT or help desk personnel and socially engineer users into granting an interactive remote session. "Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2)," the tech giant said. "After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim's desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management (WinRM) toward high-value assets such as domain controllers." Microsoft has described the "intrusion pattern" as high-impact as it grants an external operator interactive access to internal infrastructure. Teams Vishing at Scale Spring Ring Abuses Microsoft Teams in Vishing Campaign In more Teams-related abuse, a coordinated social engineering operation dubbed Spring Ring has been observed leveraging external Microsoft Teams accounts to masquerade as IT help desk personnel to target more than 150 employees across at least 10 companies in various industries between January and April 2026. "What seems like a benign chat is in fact a voice phishing (vishing) call, during which adversaries try to coerce victims into executing remote monitoring and management (RMM) tools or custom malware," Palo Alto Networks Unit 42 said. "In a more advanced variant, attackers transitioned from a vishing call to a full-blown Microsoft NT LAN Manager (NTLM) relay attack aimed at an organization's domain controller (DC)." As many as 26 distinct attacker identities have been identified behind the chat and call attempts. Ransomware Affiliate Playbook The Gentlemen Ransomware Operation Analyzed In a new report, Sophos revealed that The Gentlemen ransomware operation, which it tracks as Gold Sherwood, has claimed a total of 683 victims by the end of July 2026. In July alone, the group is said to have added 169 victims. "The Gentlemen ransomware intrusions [...] demonstrate a repeatable affiliate playbook that combines opportunistic initial access, rapid privilege escalation, legitimate remote access mechanisms, tool staging in trusted system paths, targeted data exfiltration, aggressive defense evasion, backup disruption, and ransomware deployment," Sophos said. "Affiliates are operationally flexible: they use native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering to adapt to victims’ environments and maximize impact before encryption." PhaaS Survives Takedown Outsider Resurfaces Despite Law Enforcement Action The Outsider phishing-as-a-service (PaaS) platform has continued to be a resilient threat in the face of law enforcement action that took down a number of domains related to the service. The kit is operated by a threat actor known as "ChenLun." Group-IB said it has identified over 700 new phishing pages created using the kit within a month after Google filed a civil lawsuit against its operators, indicating that affiliates are continuing to use the service. The campaigns are delivered via SMS. "What was once a technically demanding operation has been reduced to a subscription and a Telegram channel," Group-IB said. "The phishing kits are distributed via a dedicated Telegram ecosystem. Operators used a WebSocket connection for live keylogging and to manipulate MFA challenges." Signed Software, Hidden Payload Government-Themed Tax Campaign Uses DLL Sideloading A government-themed tax notice campaign is targeting recipients through U.A.E.- and India-themed tax assessment lures to persuade them to open a malicious disc image. "The disc image contains a legitimate, validly signed commercial executable alongside a hidden, unsigned malicious DLL," iZOOlogic said. "This makes abuse of software trust and DLL sideloading the central mechanism of the campaign. The malicious DLL acts as a loader and establishes multiple execution and persistence mechanisms. The loader contains three encrypted payloads. Two decrypt to legitimately signed kernel drivers from unrelated commercial products, while the third is a persistence script." The attack chain paves the way for a Registry-resident second stage, which connects to an external server over UDP. Executive Phishing as a Service BlueKit PhaaS Kit Detailed ZeroBEC has disclosed details of a turnkey phishing service called BlueKit that's being used to target CEOs of financial-industry groups to facilitate credential theft using a browser-in-the-middle (BitM) infrastructure. The campaign uses document-sharing lures to trigger the attack chain and employs ZeroBot to screen bots. "The campaign did not stop at credential or session theft," ZeroBEC said. "After a BlueKit browser-in-the-middle flow, selected victims were moved into a fake document-viewer workflow that delivered a legitimate ScreenConnect client configured for an attacker-used ScreenConnect cloud instance." The service advertises access at $250 for seven days, $480 for 14 days, and $940 for 30 days, placing it at the higher end of the current PhaaS market, in comparison to Tycoon 2FA, Greatness, and Forg365, which cost approximately $350, $289, and $400 per month. Dormant Domains, Ready C2 Mapping Prince of Persia's Backend Infrastructure Cybersecurity researchers have analyzed the infrastructure powering the operations of Prince of Persia (aka Indy), a little-known Iranian hacking group known for deploying malware families, Foudre and Tonnerre, to profile victims and harvest sensitive data from high-value targets. According to Whisper Security's Kaveh Azarhoosh, the backend is self-authoritative, with each live C2 server also running the nameservers for its own domains. Also identified is a dormant reserve of 58 domains that are registered and delegated to the group's own nameservers, but none of which currently points at any server. "They're staged, not live: the moment any one of them gains an address record, a new command server has gone live — and it's visible before the server does anything at all," Azarhoosh told The Hacker News via email. Remote-Controlled Rubber Ducky Fake Privacy Browser Turns into USB Rubber Ducky Intezer has detailed a fake "privacy browser" downloaded from a counterfeit site ("www.mxsetuplogi.com") that turns remote attacker commands into simulated mouse and keyboard input on a victim's machine. The site is surfaced via a sponsored search result on Google, in this case after the victim mistyped the domain name ("www.mxsetup.logi.con") on the address bar. The cybersecurity company described it as a USB Rubber Ducky attack delivered over the internet. "This attack evades EDR and sits at zero to two detections on VirusTotal," it said in a statement. "The infection began with one simple mistyped letter during routine mouse setup that routed the vict

Entities

Microsoft Teams (product)Node.js (product)Windows (product)ChenLun (threat_actor)Spring Ring (campaign)The Gentlemen ransomware operation (campaign)