- OxideHarvestRust-based credential-stealer tool used by Gentlemen ransomware
- SystemBCProxy malware botnet linked to Gentlemen ransomware victims
- GentleKillerEDR killer tool used by Gentlemen ransomware
- HexKillerExternal EDR killer tool incorporated by Gentlemen ransomware
- ThrottleBloodExternal EDR killer tool incorporated by Gentlemen ransomware
- HavocKillerExternal EDR killer tool incorporated by Gentlemen ransomware
ThreatNoir Morning Brief — June 19
Morning Review in IT Security — June 19, 2026
The threat landscape continues to evolve rapidly as adversaries develop sophisticated evasion techniques, supply chain attacks proliferate, and law enforcement achieves significant victories against established criminal operations. Today's security briefing covers critical developments spanning ransomware defense evasion, open-source software compromises, major vendor patching efforts, and a significant botnet disruption.
Gentlemen Ransomware Deploys Multiple EDR Killers to Evade Detection
The Gentlemen ransomware-as-a-service operation has actively developed and deployed a comprehensive suite of endpoint detection and response killers designed to help affiliates disable security defenses during attacks. The threat actors have created multiple specialized tools including GentleKiller, HavocKiller, HexKiller, OxideHarvest, SystemBC, and ThrottleBlood to systematically neutralize EDR solutions before executing their encryption payloads. This represents a significant escalation in the sophistication of ransomware operations, as attackers increasingly focus on blinding defenders rather than relying solely on encryption capabilities. Source: Gentlemen ransomware uses multiple EDR killers to disable defenses
TeamPCP's Supply Chain Attack Reveals Industry's Security Vulnerabilities
The threat group TeamPCP has successfully poisoned over 1,000 open-source software packages within a four-month campaign, exposing fundamental weaknesses in the software development ecosystem's trust model. Security researchers attribute this remarkable success to the industry's widespread prioritization of rapid code shipping over security implementation and review processes. The attack demonstrates how the velocity-focused culture of modern software development has created an environment where malicious contributions can slip through inadequate vetting mechanisms. Source: How software development's speed obsession enabled TeamPCP's chaos crusade
Oracle Releases Critical Patch Update Addressing 245 Vulnerabilities
Oracle released its June 2026 Critical Patch Update, addressing 245 security vulnerabilities across multiple product families and third-party components. The quarterly update includes patches for several critical remote code execution flaws, with affected products including Oracle Fusion Middleware receiving the highest concentration of patches. Notable vulnerabilities addressed in this update include CVE-2026-35278, CVE-2026-46850, CVE-2026-46860, and CVE-2026-46861. Organizations running Oracle infrastructure should prioritize testing and deployment of these patches to mitigate exposure to actively exploitable vulnerabilities. Source: Oracle Critical Patch Update, June 2026 Security Update Review
Law Enforcement Successfully Dismantles Evil Corp's SocGholish Botnet
International authorities have disrupted the SocGholish botnet operated by Evil Corp, taking down 106 command-and-control servers and remediating nearly 15,000 infected websites. The coordinated operation between cybersecurity firms, researchers, and law enforcement agencies targeted the FakeUpdates malware distribution mechanism and the SocGholish botnet infrastructure that had been used to deliver secondary payloads to compromised systems. This takedown represents a significant blow to one of the most prolific malware distribution networks in operation. Source: Authorities disrupt Evil Corp's SocGholish botnet
These developments underscore the ongoing arms race between defenders and attackers, the critical importance of secure software development practices, and the continued success of coordinated international law enforcement efforts against cybercriminal infrastructure.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- TrivyOne of the first packages compromised by TeamPCP.
- Oracle MySQL critical vulnerability with CVSS 9.9, enables remote code execution
- Oracle MySQL critical vulnerability with CVSS 9.8, enables remote code execution
- Oracle MySQL critical vulnerability with CVSS 9.6, enables remote code execution
- Oracle PeopleSoft Performance Monitor critical vulnerability with CVSS 9.8, enables remote code execution
- SocGholishMulti-stage malware used for initial foothold and further targeting.
- FakeUpdatesAlternative name for the SocGholish botnet.