- Dell RecoverPoint for Virtual Machines vulnerability exploited by UNC6201.
ThreatNoir Afternoon Brief — June 8
Afternoon Review in IT Security — June 8, 2026
The cybersecurity landscape continues to evolve with sophisticated threat actors deploying advanced malware variants, targeting critical infrastructure and professional services, and exploiting supply chain vulnerabilities. Today's threat intelligence reveals coordinated nation-state activities, ransomware operations utilizing evasion techniques, and malicious software distribution through compromised repositories.
VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux Appliances
A China-nexus cyber espionage group tracked as VerdantBamboo has been observed deploying a BSD variant of the BRICKSTORM backdoor alongside two additional malware families designated PLENET (also known as GRIMBOLT) and AGENTPSD. These tools are specifically engineered to compromise Linux systems and appliances. The activity has been attributed by Volexity to VerdantBamboo, which overlaps with hacking groups previously identified by Microsoft as Clay Typhoon.
The deployment of platform-specific variants demonstrates the threat actor's sophistication and commitment to maintaining persistent access across diverse infrastructure environments. Organizations operating Linux appliances should prioritize patching efforts, particularly addressing CVE-2026-22769, which appears central to this campaign. Source: The Hacker News
Silent Ransom Group Uses DNS Fast Flux in Attacks
The Silent Ransom Group has emerged as a significant threat to United States law firms, employing DNS fast flux techniques to obscure and protect its command-and-control infrastructure. This evasion methodology allows the threat actors to dynamically shift their network presence, complicating detection and attribution efforts by defenders. The group's targeting of legal entities suggests a deliberate focus on organizations likely to contain valuable intellectual property and sensitive client information.
The use of fast flux infrastructure represents an escalation in operational sophistication, enabling the group to maintain persistent access while evading traditional network-based defenses. Organizations within the legal sector should implement robust DNS monitoring and threat intelligence feeds to identify associated domains including business-data-leaks[.]com and ep6pheij[.]com. Source: SecurityWeek
Malicious DocuSign Executable Distributed via Compromised GitHub Repository
A fraudulent DocuSign release has been identified on GitHub containing a malicious executable file named DocuSignSetup.exe bearing a Microsoft-issued certificate. The malware communicates with command-and-control infrastructure at bbytati25iy2.anondns[.]net and IP address 84.54.33[.]250, indicating an active distribution campaign leveraging GitHub's trusted status as a software repository platform.
This supply chain attack vector exploits user trust in legitimate software distribution channels and the perceived security of Microsoft-owned platforms. The use of valid code-signing certificates significantly increases the likelihood of successful execution on target systems. Users should verify software authenticity through official vendor channels and avoid downloading releases from unofficial repositories. Source: Malwr Hunter Team
Software Supply Chain Attacks: Check Your Dependencies
Open-source package compromises continue to represent a critical vulnerability vector as attackers systematically target dependencies within software supply chains. Cyber defenders are urged to conduct comprehensive reviews of their organizational dependencies to identify and mitigate exposure to compromised packages before deployment in production environments.
The prevalence of supply chain attacks underscores the necessity for organizations to implement software composition analysis tools, maintain updated vulnerability databases, and establish verification procedures for third-party components. Source: National Cyber Security Centre
Conclusion
Today's threat intelligence landscape reflects a coordinated effort by sophisticated adversaries to exploit multiple attack vectors simultaneously. From nation-state backdoor deployments targeting critical infrastructure to ransomware operations targeting professional services and supply chain compromises affecting software development pipelines, defenders must maintain heightened vigilance across all organizational systems and dependencies. Immediate action on vulnerability patching, dependency auditing, and threat intelligence integration remains essential to mitigating these escalating risks.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
ep6pheij[.]comDomain used in SRG's fast flux botnetbusiness-data-leaks[.]comDomain used in SRG's fast flux botnet
84.54.33[.]250Command and control IP address
bbytati25iy2.anondns[.]netCommand and control domain
hxxps://github[[.]]com/lonergigs-code/DocuSign/releases/GitHub repository hosting the malicious executable