Weekly review

ThreatNoir Morning Brief — June 8

2026-06-08Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — June 8, 2026

The threat landscape continues to evolve rapidly as attackers exploit unpatched infrastructure vulnerabilities, deploy sophisticated social engineering tactics against high-value targets, and compromise government and commercial systems across multiple nations. Today's review highlights critical threats affecting IoT devices, professional services organizations, and government infrastructure.

C0XMO Botnet Spreads via DD-WRT Router Flaw, Kills Rival Malware

A dangerous new variant of the Gafgyt botnet designated C0XMO is actively exploiting vulnerabilities in DD-WRT router firmware to establish widespread command and control infrastructure. The malware demonstrates the ability to target routers running DD-WRT and subsequently move laterally to compromise additional device types across various CPU architectures, expanding its reach beyond initial infection vectors. The botnet's capacity to eliminate competing malware strains indicates a sophisticated threat actor seeking to monopolize compromised device resources for maximum operational impact.

Organizations running DD-WRT firmware should prioritize immediate patching of CVE-2021-27137 and conduct thorough network scans to identify potentially compromised devices. Source: Bleeping Computer

Silent Ransom Group Targets Law Firms with Fake IT Support Calls

The Silent Ransom Group extortion gang has launched a coordinated campaign targeting United States law firms and professional services organizations through social engineering attacks initiated via fraudulent IT support calls. According to analysis by cybersecurity firm Mandiant, these attacks frequently result in successful data theft within hours of the initial contact, demonstrating the speed and effectiveness of the threat actors' operational methodology. The campaign exploits the trust relationships that organizations maintain with IT support infrastructure and the urgency typically associated with technical emergencies.

Law firms and professional services providers should implement strict verification protocols for all IT support communications and establish secure out-of-band communication channels for confirming legitimate support requests. Source: Bleeping Computer

French Government Messaging Platform Tchap Data Allegedly Scraped

A threat actor operating under the handle misere has announced the distribution of a dataset allegedly obtained through unauthorized access to Tchap, the official encrypted messaging platform of the French government. Tchap is developed by DINUM and serves as the primary communication infrastructure for civil servants across multiple critical ministries including the Interior, Finance, and Defense departments. The alleged compromise of this government communication platform represents a significant security incident with potential implications for national security operations and sensitive government communications.

The incident underscores the importance of securing government-grade communication platforms with robust access controls and continuous security monitoring. Source: Dark Web Informer

Spanish Helicopter Company Suffers Major Data Breach Exposing 2M User Records

A threat actor known as Sophia is actively selling a dataset allegedly derived from Helity, a Spanish company providing helicopter passenger transport services. The actor claims the compromised database contains approximately two million records including usernames, passwords, and additional personally identifiable information. The scale of this breach and the public sale of credentials poses immediate risks to affected users and the organization's operational security.

Organizations in the transportation and logistics sectors should review their access control mechanisms and credential management practices to prevent similar large-scale data exfiltration. Source: Dark Web Informer


Today's threat intelligence reveals persistent vulnerabilities in unpatched infrastructure, the continued effectiveness of social engineering against high-value targets, and the ongoing compromise of both government and commercial systems. Security teams should prioritize vulnerability remediation, implement multi-factor authentication, and enhance employee awareness training to defend against these evolving threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Silent Ransom Group targets law firms with fake IT support calls
Domain4
  • privnote.com
    Used to share installation links and commands during remote sessions.
  • itdesk.com
    Phishing domain impersonating internal IT portals.
  • it.com
    Phishing domain impersonating internal IT portals.
  • helpdesk.com
    Phishing domain impersonating internal IT portals.