Sign in

ThreatInsight

@threatinsight.proofpoint.com
419 followers 2 following 482 posts

Proofpoint's insights on targeted attacks and the cybersecurity threat landscape.

PostsRepliesMedia
ThreatInsight @threatinsight.proofpoint.com · 02/10/2026
TA419 targeted AI experts at US think tanks, universities, and legal-sector orgs and likely served Chinese intel objectives. They began w/ benign outreach, followed up w/ a shortened URL leading to a fake OneDrive AitM cred-phishing page to access the target’s cloud account.
TA419 campaign inviting users to contribute to AI supply chain report.
110
ThreatInsight @threatinsight.proofpoint.com · 02/10/2026
In July 2026, a China-aligned threat actor, TA419, ran credential-phishing campaigns impersonating prominent economists and AI policymakers, including a former White House Office of Science & Technology Policy leader. More info: www.proofpoint.com/us/blog/thre...
TA419 campaign spoofing former White House Office of Science and Technology Policy employee.
165
ThreatInsight @threatinsight.proofpoint.com · 30/09/2026
Threat actors are stealing U.S. university .edu credentials and using them to run job scams, fake scholarships, and other advance-fee fraud scams. We engaged with the fraudsters to learn how they operate. See our blog for our findings and screenshots. www.proofpoint.com/us/blog/thre...
042
ThreatInsight @threatinsight.proofpoint.com · 22/09/2026
Within 90 seconds of compromise, a threat actor triggered multiple post-access sequences. Our threat researchers believe this activity was AI-enabled. Our new blog examines this active TeamFiltration campaign, tracked as UNK_CondorFiltration. www.proofpoint.com/us/blog/thre...
110
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026
TA4922 used PackClient to deliver payloads inside tax-themed lures, impersonating the Shandong Provincial Tax Bureau and the Government of India Income Tax Department. PackClient dropped ManageEngine RMM. We used the Deception Pro malware observability environment to view follow-on payloads.
TA4922 phishing email impersonating the Indian Income Tax Department and using a tax recovery and penalty notice lure.
100
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026
Our research shows that PackClient is sold on Telegram and TA4922 used it to target organizations in Asia. Other actors are likely already using (or will use) this malware and may expand targeting to organizations in other regions.
Suspected PackClient posting on Telegram, from March 2026.
100
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026
Proofpoint has observed a Chinese-speaking threat actor (TA4922) using a command and control (C2) framework called PackClient. The framework enables data theft, surveillance, and downloading of additional plugins and payloads. Blog: www.proofpoint.com/us/blog/thre... #impersonation #phishing
TA4922 phishing email impersonating the Shandong Provincial Tax Bureau using a tax inspection notice lure.
113
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026
Our research shows that PackClient is sold on Telegram and TA4922 used it to target organizations in Asia. Other actors are likely already using (or will use) this malware and may expand targeting to organizations in other regions.
Suspected PackClient posting on Telegram, from March 2026.
000
ThreatInsight @threatinsight.proofpoint.com · 12/08/2026
We've joined the #vb2026 conference lineup! Join us for a grounded, data-validated talk focused on modern cybercrime. We'll share our take on 3️⃣ myths: "AI is making threat actors smarter." "Prioritize threats that target your vertical or geo." "Lures reliably reflect major events/holidays/news."
052
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026
The site also features a “Customer Service” chat box. If a user messages, a threat actor responds and walks through the steps to install ScreenConnect. Based on the chats we've examined, a real person (not AI) is likely operating the chat to instruct users on malware installation.
100
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026
Emails impersonate COLDCARD and purport to highlight a security audit relating to the incident. Messages contain a URL that leads to a site impersonating COLDCARD with a “Start Hardware Audit” button.
100
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026
A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering with “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns.
100
ThreatInsight @threatinsight.proofpoint.com · 28/07/2026
Our Proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods that are being actively developed and sold: www.proofpoint.com/us/blog/thre....
232
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026
Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra mailservers. We alerted government partners, with whom we have collaborated on further discovery. Blog: www.proofpoint.com/us/blog/thre...
265
ThreatInsight @threatinsight.proofpoint.com · 21/07/2026
The StealC ecosytem #OperationEndgame led to the seizure of more than 25.6M unique creds stolen from +385k compromised sites. Proofpoint was proud to contribute to the operation alongside industry partners. Listen to Discarded for a scoop inside the disruption. www.proofpoint.com/us/podcasts/...
011
ThreatInsight @threatinsight.proofpoint.com · 20/07/2026
• Targeting is opportunistic, but campaigns aimed at Finserv, healthcare, and government entities were more frequent. • It's always executed via DLL side-loading. Purpose: ensure the target system isn’t a sandbox or malware analyst’s VM before dropping and executing the payload.
110
ThreatInsight @threatinsight.proofpoint.com · 20/07/2026
Researchers at Proofpoint are tracking Cruciferra, a crypter service that is used by multiple unrelated threat actors. The self-proclaimed “underground's most lethal crypter” has been observed delivering a wide range of RATs and infostealers. Blog: www.proofpoint.com/us/blog/thre...
A public advertisement and notice of Cruciferra (from exploit[.]in).
122
ThreatInsight @threatinsight.proofpoint.com · 17/07/2026
Back by popular demand, senior threat researcher Joe Wise will join our next Intercepted livestream on July 22nd. Joe will share real examples of active threat campaigns, malware samples, tips, tricks, and more research for defenders. Register to join us 👉 www.proofpoint.com/uk/resources...
020
ThreatInsight @threatinsight.proofpoint.com · 08/07/2026
The campaign featured two one-month clusters of spraying activity against roughly 80,000 user accounts across nearly 3,000 tenants.
100
ThreatInsight @threatinsight.proofpoint.com · 07/07/2026
Since May 2026, we’ve seen UNK_MassTraction target physics and engineering departments by chaining Roundcube vulns to: • Execute JavaScript via XSS • Steal browser-stored credentials • Gain mail server access • Deploy either a webshell or an in-memory VShell backdoor
UNK_MassTraction lure emails.
100
ThreatInsight @threatinsight.proofpoint.com · 07/07/2026
🚨 New research: Proofpoint has identified a suspected China-aligned espionage cluster, UNK_MassTraction, exploiting multiple Roundcube n-day vulnerabilities to compromise mail servers at U.S. and Canadian universities. Analysis, infection chain & IOCs: www.proofpoint.com/us/blog/thre....
UNK_MassTraction infection chain.
157
ThreatInsight @threatinsight.proofpoint.com · 01/07/2026
In April 2026, Proofpoint’s cloud telemetry captured a shift in the ISPs from which NovaCookies activity originated, a pattern is consistent with established tradecraft of migrating hosting or proxy services to evade detection.
100
ThreatInsight @threatinsight.proofpoint.com · 01/07/2026
Proofpoint observed an intermittent burst in Sneaky2FA activity until February 2026, when researchers first identified the NovaCookies variant. Malicious activity intensified from March to May as this new variant was adopted, but declined in June.
100
ThreatInsight @threatinsight.proofpoint.com · 01/07/2026
Researchers from Proofpoint have reported an increase in AitM activity originating from #NovaCookies, a suspected variant of the #Sneaky2FA phishing kit.
111
ThreatInsight @threatinsight.proofpoint.com · 30/06/2026
FIFA FANS ‼️ Cybercriminals are using #FIFAWorldCup excitement to steal your personal info and credit card details. One recent email scam we observed used the subject line: “Congratulations! You're Eligible for the FIFA World Cup 2026 Giveaway” 🧵 1/5
110
ThreatInsight @threatinsight.proofpoint.com · 24/06/2026
Just announced by @europol.europa.eu: the global #OperationEndgame initiative has disrupted the #StealC ecosystem, a prominent information-stealing malware operation. See our blog for details: www.proofpoint.com/us/blog/thre...
121
ThreatInsight @threatinsight.proofpoint.com · 18/06/2026
#SocGholish, the “FakeUpdates” web injects framework linked to major ransomware events, has been disrupted by #OperationEndgame. ❌ 100 servers and domains worldwide dismantled ❌ 14,971 websites remediated Learn more: www.proofpoint.com/us/blog/thre.... 🧵⤵️
141
ThreatInsight @threatinsight.proofpoint.com · 11/06/2026
Emails contained a URL that led to counterfeit authentication pages designed to harvest user credentials.
100
ThreatInsight @threatinsight.proofpoint.com · 11/06/2026
The campaigns impersonated two financial firms, CommSec and FSM One, to target people in #Australia and #Singapore. The messages purported to invite people to apply for eligibility to purchase SpaceX stock.
100
ThreatInsight @threatinsight.proofpoint.com · 09/06/2026
Over six weeks, we observed the actor targeting nearly 100 organizations across technology, #cryptocurrency, finance, and education sectors. Targets were lured through fake recruiter outreach, code review requests, and developer collaboration opportunities.
Distribution of UNK_DeadDrop targeting across sector and geography.
110
ThreatInsight @threatinsight.proofpoint.com · 03/06/2026
We consider it one of the most unique actors we track due to its high volume and wide variety of lure themes, targeting, and objectives. In our blog, we share recent campaigns observed by TA4922 that illustrate typical behaviors.
Targeted country assessment.
100
ThreatInsight @threatinsight.proofpoint.com · 19/05/2026
Sarah Sabotka, staff threat researcher at Proofpoint, is speaking at #Layer8Conference — the only event dedicated to #OSINT and #socialengineering threats facing businesses today. If you're a security leader, you won't want to miss it! June 5–6 | Boston, MA Event info: layer8conference.com
041
ThreatInsight @threatinsight.proofpoint.com · 14/05/2026
Like EvilTokens, most of the activity we see is using “vibe coded” techniques. It's unclear whether most are copying & modifying publicly known tools or using similar prompts to generate nearly identical attack flows wholesale. Here's an EvilTokens landing page from March 2026.
Example of EvilTokens landing page, observed by Proofpoint in March 2026.
100
ThreatInsight @threatinsight.proofpoint.com · 14/05/2026
Device code phishing is exploding across the threat landscape, with new device code phishing tools emerging every week. Our new blog explores why adoption of this technique has surged over the past year. www.proofpoint.com/us/blog/thre... A few key points below. 🧵⤵️
Example of multiple device code phishing landing pages.
121
ThreatInsight @threatinsight.proofpoint.com · 04/05/2026
ODx’s device code capabilities are using Kali365, a device code PhaaS. Kali365 is just one of many such kits available for purchase. It’s unclear whether ODx stole or purchased Kali365, or partnered with them to integrate directly into their service.
110
ThreatInsight @threatinsight.proofpoint.com · 04/05/2026
In the observed campaign, the actor used compromised senders to deliver URLs leading to the ODx device code phishing landing page. The landing pages included multiple different themes including impersonating SharePoint, Adobe, and Docusign.
110
ThreatInsight @threatinsight.proofpoint.com · 28/04/2026
Our award-winning threat research podcast series, Discarded, is celebrating 100 episodes this week! 🎉 Stream now for a trip down memory lane, a few laughs, and a look ahead to what's next in cybersecurity. Cheers to 100 episodes! 🍾 www.proofpoint.com/us/podcasts/...
000
ThreatInsight @threatinsight.proofpoint.com · 16/04/2026
Proofpoint baited a cargo/transport industry threat actor into performing its malicious activities in a decoy environment operated by Deception.Pro for 30+ days. What resulted: rare, extended visibility into post-compromise operations, tooling, & decision-making. www.proofpoint.com/us/blog/thre...
Email content sent after responding to a fraudulent load posted on a load board.
130
ThreatInsight @threatinsight.proofpoint.com · 14/04/2026
Our new Discarded podcast episode explores the stealthy world of backdoors, malware detection, and the “secret signals” threat actors use to stay hidden. Stream now for expert insights on signature development, PCAP analysis, and countering espionage tools. 🎙️ www.proofpoint.com/us/podcasts/...
010
ThreatInsight @threatinsight.proofpoint.com · 13/04/2026
Have you checked your mailbox rules lately? Proofpoint cloud threat researchers found that approx. 10% of compromised accounts in Q4-2025 had malicious mailbox rules created by threat actors shortly after initial access. Details: www.proofpoint.com/us/blog/thre... Here are some highlights. ⤵️
Rule creation example in Microsoft Outlook.
100
ThreatInsight @threatinsight.proofpoint.com · 01/04/2026
In March 2026, after the outbreak of the Iran war, TA416 targeted Middle Eastern govt and diplomatic entities. This was a departure from its usual focus and aligned with a broader shift by state-aligned actors to gather regional intel on the conflict’s trajectory and impact.
120
ThreatInsight @threatinsight.proofpoint.com · 30/03/2026
In the example below from 5 Feb 2026, we observed a campaign impersonating the U.S. IRS. The lure purported to relate to the target’s recent IRS filing. IRS is a common lure theme used by criminals, as impersonating government agencies can be an effective social engineering tactic.
Phishing lure impersonating the IRS delivering N-able RMM.
100
ThreatInsight @threatinsight.proofpoint.com · 27/03/2026
Related compromised first stage domains also include motorbeylimited[.]com and bridetvstreaming[.]org. Only the activity from March 26 spoofing Atlantic Council has been linked to DarkSword usage; previous TA446 activity shows no indication of exploit use.
110
ThreatInsight @threatinsight.proofpoint.com · 27/03/2026
The activity on March 26 was a similar spike, but with links instead of attachments. Proofpoint automated analysis was redirected to a benign decoy PDF, likely because of server-side filtering to only redirect iPhone browsers to the exploit kit.
110
ThreatInsight @threatinsight.proofpoint.com · 20/03/2026
Proofpoint assesses that the Edge scheme handoff was likely intended to direct victims into the browser path that supports the next stage. This is consistent with UNK_VaporVibes’ repeated use of ClickOnce-focused delivery. 4/8
101
ThreatInsight @threatinsight.proofpoint.com · 20/03/2026
The notable part came after the click. The PDF link used the “microsoft-edge:” URI scheme before redirecting to a Cloudflare Workers hosted (*[.]adobe-org[.]workers[.]dev) ClickOnce application resource. 3/8
100
ThreatInsight @threatinsight.proofpoint.com · 20/03/2026
The actor used compromised accounts from a Pakistani university and a government organization to deliver PDF attachments with a fake Adobe Reader prompt. 2/8
100
ThreatInsight @threatinsight.proofpoint.com · 20/03/2026
Proofpoint identified a targeted campaign against operations personnel at energy firms linked to projects in Pakistan. The messages were sent on 18 March 2026, and mimicked invitations to the upcoming Pakistan Energy Exhibition & Conference (PEEC). We track the activity as UNK_VaporVibes. 1/8
196
ThreatInsight @threatinsight.proofpoint.com · 19/03/2026
The cloud threat research team at Proofpoint has discovered an account takeover campaign targeting around 40,000 users. Malicious activity has been recorded as early as Feb. 2nd, with a surge on Feb. 10th and a peak on Feb. 12th.
111
ThreatInsight @threatinsight.proofpoint.com · 12/03/2026
Interesting poll results from our February session of Intercepted, our monthly interactive threat research webinar! Replay here: brnw.ch/21x0GAL On March 18, Yaniv Miron will share his expert insights on the cloud threat landscape. ☁️ Register now and prepare your questions! brnw.ch/21x0GAR
000