Weekly review

ThreatNoir Weekend Brief — July 26

2026-07-26Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — July 26, 2026

The threat landscape continues to evolve with attackers leveraging social engineering, malvertising techniques, and unpatched vulnerabilities to compromise users across gaming platforms, financial services, and enterprise applications. Today's security briefing covers emerging campaigns exploiting trust in legitimate platforms and critical zero-day conditions requiring immediate defensive action.

Steam Forum ClickFix Attacks Infect Gamers with XMRig Cryptominers

Attackers are abusing Steam discussion forums to distribute XMRig cryptominers through ClickFix social engineering attacks. The malicious campaigns impersonate legitimate fixes for game and computer problems, deceiving users into downloading and executing infected files. Once installed, the XMRig malware begins unauthorized cryptocurrency mining on compromised devices. Source: Steam forum ClickFix attacks infect gamers with XMRig cryptominers

The attack leverages the trust users place in community forums and their desire to resolve technical issues quickly. Indicators of compromise include the domain msfconfig[.]icu and the malicious URL msfconfig[.]icu:443/tmp/system.txt. Users should verify the legitimacy of any fix before execution and remain cautious of unsolicited technical solutions offered in public forums.

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A sophisticated malvertising operation dubbed SourTrade is fragmenting malware delivery to evade detection systems. Rather than serving complete executable files, the campaign uses legitimate Bun runtime as a base and instructs victims' browsers to assemble the final Windows executable piece by piece. Security researchers at Confiant documented the campaign, which has operated since late 2024 and impersonated prominent financial platforms including TradingView, Solana, and Luno to target retail traders. Source: Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

This technique represents a significant evasion innovation, as traditional URL-based detection becomes ineffective when the malicious payload is constructed dynamically within the browser environment. The domain purelogicbox[.]org has been identified as infrastructure associated with this campaign. Organizations should implement behavioral detection and monitor for suspicious browser-based assembly of executables.

ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam

Threat actors are weaponizing email addresses exposed in data breaches leaked by the ShinyHunters extortion group to conduct sextortion campaigns. Victims receive emails demanding $2,000 in Bitcoin, leveraging the psychological pressure of alleged compromising content. The use of real email addresses from confirmed breaches increases the credibility and effectiveness of these scam attempts. Source: ShinyHunters data leaks fuel $2,000 sextortion email scam

This campaign demonstrates how data breaches create cascading harm beyond the initial compromise. Users whose information appears in breach notifications should be especially vigilant regarding unsolicited emails making threats or demands. Security awareness training should emphasize that legitimate organizations do not demand cryptocurrency payments via email.

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

A critical remote code execution vulnerability in Fastjson, Alibaba's JSON library for Java, is actively being exploited with no patch currently available. Tracked as CVE-2026-16723 and assigned a CVSS score of 9.0, the flaw allows unauthenticated attackers to execute arbitrary code within affected Spring Boot applications through malicious JSON requests. ThreatBook and Imperva have confirmed active exploitation targeting this vulnerability in production environments. Source: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patch Available

The absence of an available patch creates an urgent mitigation challenge for organizations running vulnerable Fastjson versions. Defenders should immediately assess their Java application inventory for Fastjson dependencies and implement network-level controls to restrict JSON request patterns. Monitoring for suspicious Java process behavior and network connections from affected systems is critical until vendor patches become available.

As threat actors continue to innovate in delivery mechanisms and exploit unpatched systems, organizations must maintain vigilant monitoring of both emerging campaigns and critical vulnerability disclosures. Today's landscape underscores the importance of user education, rapid vulnerability assessment, and behavioral detection capabilities.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).