Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
3 clusters · 7 sources · 9 days · First seen · Last updated
Global malware and cyber threat evolution
Overview
Global malware activity continues to surge, driven by remote access trojans (RATs), information stealers, and loaders. AsyncRAT remains a dominant threat, with approximately 211 weekly sample uploads observed; it frequently utilizes trusted cloud infrastructure, such as Cloudflare, to evade detection. Remcos RAT has also seen a sharp rise in activity, with newer variants focusing on real-time surveillance capabilities like live webcam streaming and instant keystroke transmission.
Attackers are increasingly employing sophisticated delivery methods, such as using Visual Basic Script (VBS) and PowerShell to deploy malicious script chains. These chains often utilize DuckDNS hosts to distribute scripts that mimic legitimate Windows activity, employing AES-256 encryption and process hollowing to bypass security defenses and steal browser data, keystrokes, and clipboard contents.
Parallel to these technical shifts, threat actors are investing heavily in “dropcatch” domains to facilitate malware distribution, illegal gambling, and scams. In the first half of 2026, approximately 65,000 re-registered domains were observed daily, accounting for nearly 20% of all newly observed domains. High rates of this activity are noted in .net and .xyz extensions, where nearly 30% of new registrations are previously registered domains. By acquiring these, attackers exploit inherited reputation, backlinks, and web traffic to bypass security algorithms.
Specific actors have been identified using these methods: Sable Squirrel is estimated to have spent over $7 million to acquire more than 10,000 expired domains to support ecosystems involving illegal streaming and malware. Other actors, including Shady Squirrel, Stuffy Squirrel, and Swiping Squirrel, utilize these infrastructures for SocGholish “fake update” campaigns, advertising fraud, and scams.
Entities
Sable Squirrel · Shady Squirrel · SocGholish · Xworm · DuckDNS
Timeline
-
25 days ago
[TECHNOLOGY] 2 sourcesInfoblox Threat Intel exposes cybercriminal use of expired domainsInfoblox Threat Intel reports that cybercriminals are spending millions to acquire expired domains, using their established reputation to distribute malware and host illegal content.
-
27 days ago
[TECHNOLOGY] 3 sourcesThreat actors spend millions on expired domains for malwareCybercriminals are spending millions on expired domains to exploit their existing reputation and traffic for malware delivery, scams, and illegal operations, according to Infoblox research.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesMalware activity surges as remote access trojans and stealthy script chains increaseMalware activity is surging, led by remote access trojans like AsyncRAT and Remcos. Attackers are also using VBS and PowerShell scripts via DuckDNS to deploy sophisticated, stealthy data-stealing payloads.
Sources
countryrebel.com · cybersecurityasean.com · cybersecuritynews.com · it-daily.net · programmez.com · securityaffairs.com · techcoffeehouse.com
This summary has been updated 1 time: see revision history