- Winos4.0Previously documented malware (tracked as ValleyRAT) providing remote access features deployed by TA4922
- Atlas RATRemote access trojan with reconnaissance, file theft, keylogging, and surveillance capabilities deployed by TA4922
- RomulusLoaderCustom malware loader using process hollowing and shellcode injection to deploy AnyDesk and SyncFuture
- SilentRunLoaderPython-based loader and information stealer targeting Google Chrome credentials and browsing data
ThreatNoir Morning Brief — June 4
Morning Review in IT Security — June 4, 2026
Today's threat landscape reveals critical vulnerabilities spanning nation-state operations, AI security gaps, infrastructure attacks, and mobile platform weaknesses. Organizations face immediate risks from multiple vectors requiring urgent attention and remediation efforts.
Chinese Hackers Deploy New Atlas RAT Malware in European Cyberattacks
A Chinese-speaking cybercrime group has significantly expanded its operational scope to target European organizations with previously undocumented malware capabilities. The threat actors are deploying the Atlas backdoor alongside multiple loader variants including RomulusLoader, SilentRunLoader, and Winos4.0, indicating a sophisticated and evolving toolkit designed for persistent access and lateral movement. This campaign demonstrates the group's intent to establish footholds in European infrastructure through coordinated supply-chain and targeted phishing operations.
Source: Chinese hackers use new Atlas RAT malware in European cyberattacks
WhatsApp and Slack Notifications Could Hijack Google Gemini on Android
A critical vulnerability in Google Gemini's voice assistant implementation on Android devices allows attackers to hijack the AI system through poisoned notifications originating from mainstream communication platforms including WhatsApp, Slack, SMS, Signal, Instagram, and Messenger. A single malicious notification could enable attackers to open victim windows, fabricate messages from authority figures, initiate unwanted video calls, or compromise the assistant's long-term memory without requiring any malicious application installation on the target device. This attack vector exploits the assistant's notification processing logic, creating a significant security gap in AI-powered mobile interfaces.
Source: WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
HTTP/2 Bomb DoS Attack Crashes Web Servers in Under a Minute
A newly discovered denial-of-service attack designated HTTP/2 Bomb enables attackers to incapacitate web servers within seconds using a single machine, exploiting fundamental flaws in HTTP/2 protocol implementation tracked as CVE-2026-49975. The attack's efficiency and low resource requirements present an immediate threat to web infrastructure globally, allowing threat actors to launch devastating service disruptions without sophisticated distributed attack infrastructure. Organizations running vulnerable HTTP/2 implementations face urgent risk of availability loss.
Source: New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
Microsoft 365 Android Apps Allow Token Theft via Production Debug Flag
Multiple Microsoft 365 Android applications contain a critical vulnerability stemming from a development debug flag that remains enabled in production builds, disabling the security mechanism that restricts account-token sharing to trusted Microsoft applications. This configuration flaw allows any application installed on the same device to request and obtain signed-in user tokens without authentication prompts or permission dialogs, enabling unauthorized access to email, files, calendar data, and messaging capabilities tracked under CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, and CVE-2026-42832. The vulnerability represents a fundamental identity and access control failure requiring immediate patching across all affected Microsoft 365 mobile deployments.
Source: Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
Security teams must prioritize immediate remediation of these vulnerabilities, particularly the Microsoft 365 token theft and HTTP/2 implementation flaws, while implementing network segmentation and notification filtering to mitigate the Gemini hijacking risk. Continuous monitoring for Atlas RAT indicators of compromise remains essential for European-based organizations.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- HTTP/2 Bomb DoS vulnerability in Apache httpd mod_http2
- Microsoft Excel token theft vulnerability (CVSS 7.7)
- Microsoft 365 Copilot token theft vulnerability (CVSS 4.4)
- Microsoft Word token theft vulnerability (CVSS 7.1)
- Microsoft PowerPoint token theft vulnerability (CVSS 7.1)