ThreatInsight @threatinsight.proofpoint.com · 11hThreat actors are stealing U.S. university .edu credentials and using them to run job scams, fake scholarships, and other advance-fee fraud scams. We engaged with the fraudsters to learn how they operate. See our blog for our findings and screenshots. www.proofpoint.com/us/blog/thre... 041
ThreatInsight @threatinsight.proofpoint.com · 22/09/2026Today at #Protect26, Sumit Dhawan highlighted how attackers can use AI to research targets, mimic trusted behavior, and accelerate lateral movement once they gain access. AI is changing the account takeover playbook. Organizations should ensure all exposed gaps are filled. 010
ThreatInsight @threatinsight.proofpoint.com · 22/09/2026It targeted over 5,700 accounts across 28 Microsoft 365 tenants in Latin America. The common theme among compromised accounts: all were service accounts, still open on the tenant’s identity plane, belonging to no specific person. 121
ThreatInsight @threatinsight.proofpoint.com · 22/09/2026Within 90 seconds of compromise, a threat actor triggered multiple post-access sequences. Our threat researchers believe this activity was AI-enabled. Our new blog examines this active TeamFiltration campaign, tracked as UNK_CondorFiltration. www.proofpoint.com/us/blog/thre... 110
ThreatInsight @threatinsight.proofpoint.com · 09/09/2026See our blog for the full details. The broader dynamic revealed by this activity is likely to recur beyond BlueMoon as this development model becomes accessible to a wider range of threat actors. 000
ThreatInsight @threatinsight.proofpoint.com · 09/09/2026The observed patch-gap weaponization, use of a privilege escalation exploit targeting older Windows builds, and TTPs observed point to an ephemeral capability rushed out ahead of an anticipated patch. This contrasts starkly with the tradecraft typically seen in historical browser exploit activity. 100
ThreatInsight @threatinsight.proofpoint.com · 09/09/2026Both browser vulns were "patch-gap" zero-days at the time of the observed activity, meaning they had already been fixed in public upstream Chromium source code but remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public. 100
ThreatInsight @threatinsight.proofpoint.com · 09/09/2026We assess most activity to date as China-aligned, but given its ease of adoption, it is likely to proliferate further and be adopted by espionage- and financially motivated threat actors as patched versions roll out across all Chromium-based browsers. 100
ThreatInsight @threatinsight.proofpoint.com · 09/09/2026It combines three vulnerabilities: a type confusion RCE in Chromium's V8 engine (CVE-2026-85046), a V8 sandbox escape, and a Windows kernel privilege escalation zero-day present in older Windows builds (CVE-2026-85880). 100
ThreatInsight @threatinsight.proofpoint.com · 09/09/2026New research from Proofpoint: BlueMoon, a Chrome-to-Windows exploit kit, has been used by at least four state-sponsored threat actors since late August. www.proofpoint.com/us/blog/thre...proofpoint.comOnce in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint USAnalyst note: Proofpoint uses the UNK_ designator to define clusters of activity that are still developing and have not been observed for long enough to receive a numerical TA designation. 164
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026PackClient consists of: • 1st-stage loader executable • 2nd-stage loader (PackClientLauncher) DLL module • Core module (PackClientCore) • Several optional plugins that can be downloaded with op command Full malware analysis in our blog. We also shared detection tips & IOCs. 000
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026TA4922 used PackClient to deliver payloads inside tax-themed lures, impersonating the Shandong Provincial Tax Bureau and the Government of India Income Tax Department. PackClient dropped ManageEngine RMM. We used the Deception Pro malware observability environment to view follow-on payloads. 100
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026Our research shows that PackClient is sold on Telegram and TA4922 used it to target organizations in Asia. Other actors are likely already using (or will use) this malware and may expand targeting to organizations in other regions. 100
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026We’ve noticed an increase in new malware from Chinese-speaking ecosystems compared to previous years. This is likely due in part to increased hunting and detection, but also because more malware families are emerging in commodity marketplaces. 100
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026Proofpoint has observed a Chinese-speaking threat actor (TA4922) using a command and control (C2) framework called PackClient. The framework enables data theft, surveillance, and downloading of additional plugins and payloads. Blog: www.proofpoint.com/us/blog/thre... #impersonation #phishing 113
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026Our research shows that PackClient is sold on Telegram and TA4922 used it to target organizations in Asia. Other actors are likely already using (or will use) this malware and may expand targeting to organizations in other regions. 000
ThreatInsight @threatinsight.proofpoint.com · 27/08/2026We’ve noticed an increase in new malware from Chinese-speaking ecosystems compared to previous years. This is likely due in part to increased hunting and detection, but also because more malware families are emerging in commodity marketplaces. 100
ThreatInsight @threatinsight.proofpoint.com · 18/08/2026@selenalarson.bsky.social of Proofpoint presented at @cactuscon.com 2026. Her hot take: the way we talk about AI is pretty muddy. Buzzwords, miscommunication, hype... 😵💫 Here, she shares her perspective, helps differentiate hype from reality, and highlights the real threat. youtu.be/VIHoPyrW4nQ?...youtu.beCC14 Keynote: The Importance of Being HumanYouTube video by CactusCon 011
ThreatInsight @threatinsight.proofpoint.com · 12/08/2026We've joined the #vb2026 conference lineup! Join us for a grounded, data-validated talk focused on modern cybercrime. We'll share our take on 3️⃣ myths: "AI is making threat actors smarter." "Prioritize threats that target your vertical or geo." "Lures reliably reflect major events/holidays/news." 052
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026IOCs: • Sender email - compliance@coldcardteamnews[.]com •Fake site - coldcardcompliance[.]com •Payload - hxxps://github[.]com/newallyson/ColdCard/releases/download/5.7/Coldcard_Diagnostic_Tool.bat •ScreenConnect C2 - activeretirementrelocation[.]com 000
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026The #COLDCARD breach may be an effective #socialengineering lure for cybercriminals, preying on the fear and concern people might have for the security of their #cryptocurrency to convince them to take risky decisions. 100
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026The site also features a “Customer Service” chat box. If a user messages, a threat actor responds and walks through the steps to install ScreenConnect. Based on the chats we've examined, a real person (not AI) is likely operating the chat to instruct users on malware installation. 100
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026If clicked, the button leads to a BAT file hosted on GitHub, which drops an MSI file and ultimately installs ScreenConnect. This can lead to data or financial theft, or the installation of follow-on malware like ransomware. #dataloss #ransomware #malware #COLDCARD 100
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026Emails impersonate COLDCARD and purport to highlight a security audit relating to the incident. Messages contain a URL that leads to a site impersonating COLDCARD with a “Start Hardware Audit” button. 100
ThreatInsight @threatinsight.proofpoint.com · 03/08/2026A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering with “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns. 100
ThreatInsight @threatinsight.proofpoint.com · 29/07/2026The exploitation of Outlook Web Access instances highlights the increased risk TA488 poses. See our blog for guidance on detection and remediation. ⚠️ Organizations should review and audit their Exchange permissions and revoke tokens for affected add-ins. 011
ThreatInsight @threatinsight.proofpoint.com · 29/07/2026This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA. OWAReaper can survive browser reboots, credential rotation, and a full reimage of the victim's device. 100
ThreatInsight @threatinsight.proofpoint.com · 29/07/2026The activity shows: • That TA488 has greatly improved its operational security measures • Is writing more subtle and capable malware • Targets a wide range of sectors but still prioritizes collecting government/defense intelligence 100
ThreatInsight @threatinsight.proofpoint.com · 29/07/2026🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits. The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). New blog: www.proofpoint.com/us/blog/thre...proofpoint.comCleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint USThreat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release 152
ThreatInsight @threatinsight.proofpoint.com · 28/07/2026Prompt injection has been a hot topic among defenders as they anticipate how threat actors will adapt their tradecraft for the AI era. Our research shows that this vector is ramping up underground. Companies should be prepared to defend against these attacks in the coming months. 010
ThreatInsight @threatinsight.proofpoint.com · 28/07/2026Case 3 in our blog, "IDPI via calendar invite," is particularly interesting. It involves the threat actor generating calendar invites with an injected prompt in the invite body, appearing as a meeting agenda. When an agent proccesses it, it also processes the malicious prompt. 110
ThreatInsight @threatinsight.proofpoint.com · 28/07/2026Security teams should be prepared to encounter these techniques in the near future. · IDPI via email · IDPI via PDF · IDPI via calendar invite · IDPI via malvertising 110
ThreatInsight @threatinsight.proofpoint.com · 28/07/2026Our Proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods that are being actively developed and sold: www.proofpoint.com/us/blog/thre.... 232
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026While this vulnerability was patched, TA488 and other Russian espionage actors continue to focus on webmail targeting, using these so-called “half-click” exploits to steal highly sensitive email data. Learn more here: www.proofpoint.com/us/blog/thre...proofpoint.comOperation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 | Proofpoint USThis is part 2 of a 2-part blog series Proofpoint is publishing about Russian espionage actors using half-click exploits to target government webmail servers. Read part 1 about TA488 here, and the 000
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026· The activity is attributed to TA488 (AKA Laundry Bear / Void Blizzard). They're likely directed by Russian intelligence w/ the goal of long-term email collection and surveillance. Since at least July 2025, TA488 has exploited Zimbra mailservers to target organizations in Ukraine and the USA. 100
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026· Once triggered, the malware could exfiltrate up to 90 days of emails, credentials, and authentication data, and establish persistent access to the mailbox. Following a successful attack, TA488 has used its access to send follow-on exploit-laden emails to additional targets. 100
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026· To execute the exploit, the target needs only to open the email. No social engineering is required to entice or trick a user into clicking a link or opening an attachment. This is dangerous, as the average employee has thousands of emails in their inbox that appear ordinary. 100
ThreatInsight @threatinsight.proofpoint.com · 23/07/2026Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra mailservers. We alerted government partners, with whom we have collaborated on further discovery. Blog: www.proofpoint.com/us/blog/thre... 265
ThreatInsight @threatinsight.proofpoint.com · 21/07/2026Recommendations: monitor authentication logs, minimize fallback MFA options where operationally feasible, deploy solutions capable of detecting AiTM session hijacking Learn more about Proofpoint ATO Protection. ⤵️ www.proofpoint.com/us/products/...proofpoint.comAccount Takeover Protection: ATO Prevention & Solutions | Proofpoint USDiscover Proofpoint account takeover protection. Learn how our solutions can help you detect, investigate, respond, and prevent account takeovers. 010
ThreatInsight @threatinsight.proofpoint.com · 21/07/2026Proofpoint Account Takeover protection has detection mechanisms specifically designed to identify FIDO downgrade scenarios. It leverages extensive threat intel, behavioral and ML analytics, and cloud monitoring to provide detection of account takeovers and malicious actions. 110
ThreatInsight @threatinsight.proofpoint.com · 21/07/2026Our commitment to proactive threat research enables us to identify emerging attack techniques before widespread adoption. While most companies have an alt authentication method for account recovery, adding FIDO downgrade to Evilginx Pro creates an exploitable path for attackers. 110
ThreatInsight @threatinsight.proofpoint.com · 21/07/2026Last year, we warned defenders how FIDO-based authentication can be downgraded via a phishlet to force FIDO to less secure MFA methods, enabling session cookie theft via AiTM phishing. www.proofpoint.com/us/blog/thre... We recently learned that this capability was added to Evilginx Pro.proofpoint.comDon’t Phish-let Me Down: FIDO Authentication Downgrade | Proofpoint USKey takeaways FIDO-based passkeys remain a highly recommended authentication method to protect against prevalent credential phishing and account takeover (ATO) threats. 112
ThreatInsight @threatinsight.proofpoint.com · 21/07/2026The StealC ecosytem #OperationEndgame led to the seizure of more than 25.6M unique creds stolen from +385k compromised sites. Proofpoint was proud to contribute to the operation alongside industry partners. Listen to Discarded for a scoop inside the disruption. www.proofpoint.com/us/podcasts/... 011
ThreatInsight @threatinsight.proofpoint.com · 20/07/2026• Cruciferra can use one of 90+ different encryption algorithms to encrypt and decrypt stored payloads. Its sophisticated technology is enabling the cybercrime ecosystem. We will continue to monitor Cruciferra and provide updates as new capabilities and campaigns are observed. 010
ThreatInsight @threatinsight.proofpoint.com · 20/07/2026• Targeting is opportunistic, but campaigns aimed at Finserv, healthcare, and government entities were more frequent. • It's always executed via DLL side-loading. Purpose: ensure the target system isn’t a sandbox or malware analyst’s VM before dropping and executing the payload. 110
ThreatInsight @threatinsight.proofpoint.com · 20/07/2026We reported on its functionality and observed real-world use, as well as the campaigns and malware families associated with the service. Some details: • Cruciferra has been delivered alongside zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos. 110
ThreatInsight @threatinsight.proofpoint.com · 20/07/2026Crypters are commonly used to evade detection and increase malware delivery and execution success rates. Cruciferra distinguishes itself through its extensive and unique defense-evasion capabilities, modular design, and highly customized and varied approach to payload protection. 110
ThreatInsight @threatinsight.proofpoint.com · 20/07/2026Researchers at Proofpoint are tracking Cruciferra, a crypter service that is used by multiple unrelated threat actors. The self-proclaimed “underground's most lethal crypter” has been observed delivering a wide range of RATs and infostealers. Blog: www.proofpoint.com/us/blog/thre... 122
ThreatInsight @threatinsight.proofpoint.com · 17/07/2026Back by popular demand, senior threat researcher Joe Wise will join our next Intercepted livestream on July 22nd. Joe will share real examples of active threat campaigns, malware samples, tips, tricks, and more research for defenders. Register to join us 👉 www.proofpoint.com/uk/resources... 020
ThreatInsight @threatinsight.proofpoint.com · 14/07/2026⚠️ Detection tip: Hunt for Entra sign-in events with blank application names or IDs. Also, don’t dismiss AADSTS700016 as simply an invalid app. It may indicate valid credentials were identified. See our blog for full detection guidance and technical details. 010