Weekly review

ThreatNoir Afternoon Brief — May 15

2026-05-15Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — May 15, 2026

The threat landscape continues to evolve with increased sophistication in supply chain attacks, phishing campaigns targeting enterprise cloud environments, and coordinated efforts by state-linked threat actors. Today's security briefing highlights critical incidents affecting major technology companies and critical infrastructure sectors, alongside emerging malware distribution tactics that pose significant risks to organizational security postures.

OpenAI Hit by TanStack Supply Chain Attack

OpenAI has fallen victim to a supply chain attack that resulted in the compromise of two employee devices and the theft of credential material from OpenAI code repositories. The incident underscores the persistent vulnerability of high-profile technology companies to sophisticated supply chain threats. Source: OpenAI Hit by TanStack Supply Chain Attack

The attack involved the Shai-Hulud malware, demonstrating how threat actors continue to leverage supply chain vulnerabilities to gain access to sensitive systems and intellectual property. This incident highlights the critical need for enhanced monitoring of dependency management and code repository access controls across the technology sector.

CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

A sophisticated phishing campaign is actively exploiting Outlook calendar invites and device code phishing techniques to steal Microsoft 365 session tokens and bypass multi-factor authentication protections. The attack leverages the EvilTokens kit and ConsentFix malware to compromise enterprise accounts and gain unauthorized access to organizational cloud environments. Source: CalPhishing Scam Uses EvilTokens Kit, Outlook Invites to Steal M365 Sessions

This campaign represents a significant evolution in cloud-focused attacks, as threat actors exploit legitimate communication channels and device authentication flows to circumvent traditional security controls. Organizations utilizing Microsoft 365 should implement additional verification procedures for calendar invitations and monitor for suspicious device code authentication attempts.

TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code

The hacking group TeamPCP has released the source code for the Shai-Hulud worm and is actively encouraging other threat actors to utilize the code in supply chain attacks. The group is reportedly offering monetary rewards to incentivize the weaponization and deployment of the malware across target organizations. Source: TeamPCP Ups the Game, Releases Shai-Hulud Worm's Source Code

The open-source distribution of Shai-Hulud represents a troubling trend in the threat landscape, as it democratizes access to sophisticated supply chain attack capabilities. The financial incentives offered by TeamPCP suggest a coordinated effort to expand the scope and frequency of supply chain compromises against critical technology infrastructure.

FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit

Bitdefender Labs has identified a targeted campaign by the China-linked hacking group FamousSparrow against an Azerbaijani energy company, leveraging the ProxyNotShell Microsoft Exchange Server exploit. The attack chain involved multiple malware components including Deed RAT, Mofu loader, Terndoor, and vmflt.sys, demonstrating a sophisticated multi-stage infection process. Source: FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit

This campaign highlights the continued targeting of critical infrastructure sectors by state-linked threat actors, with a focus on energy companies that play vital roles in regional economic stability. The use of advanced malware toolsets and exploitation techniques underscores the elevated threat level facing the oil and gas industry and the necessity for comprehensive patch management and network segmentation strategies.

The convergence of supply chain attacks, cloud-focused phishing campaigns, and critical infrastructure targeting reflects an increasingly aggressive threat environment. Organizations across all sectors must prioritize enhanced monitoring, rapid patch deployment, and advanced authentication mechanisms to mitigate the evolving risks presented by these coordinated threat campaigns.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit
Malware4
  • Deed RAT
    Backdoor deployed via DLL sideloading (lmiguardiandll.dll) and updated in third wave
  • vmflt.sys
    Rootkit driver deployed via Terndoor to establish god-mode control
  • Mofu loader
    Obfuscated stager used to evade antivirus and hide malware instructions in memory
  • Terndoor
    Malware deployed in second wave; installed rootkit driver vmflt.sys for system-level access