The provided items do not describe a single cohesive cybersecurity event; they span multiple unrelated threat reports and opinion pieces. Notable incident-level reporting includes APT28 activity in Western/Central Europe (“Operation MacroMaze”) using spear-phishing lures with Office macros that beacon via INCLUDEPICTURE to webhook[.]site and then execute VBScript/CMD/batch stages for persistence and follow-on payload delivery. Separately, MuddyWater (Iran/MOIS-linked) was reported running “Operation Olalampo” against organizations in the Middle East and Africa, delivering new custom malware (including a Char backdoor using a Telegram bot for C2) and, in some cases, attempting exploitation of public-facing servers in addition to phishing.
Criminal activity and initial-access tradecraft were also covered across distinct stories: a DFIR case study described exploitation of Apache ActiveMQ CVE-2023-46604 to gain RCE, conduct post-exploitation (Metasploit/Meterpreter, privilege escalation, LSASS access, lateral movement), and ultimately deploy LockBit-branded ransomware via RDP using previously stolen credentials (with indications the payload was built using the leaked builder and used Session for communications). Multiple reports described malware delivery via compromised web assets and social engineering, including GrayCharlie injecting malicious JavaScript into WordPress sites to push NetSupport RAT, Stealc, and SectopRAT via fake updates/ClickFix-style CAPTCHAs, and a separate ClickFix campaign delivering a custom C++ RAT (MIMICRAT) through fake Cloudflare verification prompts that trick users into running PowerShell. Additional, unrelated threat reporting included a NuGet supply-chain attack (typosquatted NCryptYo plus companion packages) targeting ASP.NET Identity data and enabling backdoored authorization rules, and malicious Chrome extensions using a “Promise Bomb” browser-crash technique to drive users to run fake “CrashFix” PowerShell steps. Several other items were generic commentary/roundups (data breach trends, quantum preparedness, Enigma history, NATO public opinion polling, recon how-to, and a malware-newsletter link list) and do not add event-specific intelligence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Group-IB publicly described Operation Olalampo as a fresh MuddyWater campaign and noted that some malware components showed signs consistent with AI-assisted development, including unusual debug strings. The report also released IoCs and detection rules to help defenders identify the activity.
S2 Grupo's LAB52 publicly attributed Operation MacroMaze to the Russia-linked threat actor APT28 and detailed its webhook-based macro malware workflow. The disclosure highlighted the campaign's use of native tooling and legitimate web services to minimize artifacts and evade detection.
Researchers reported that at least fifteen US law firm websites were found injected with identical malicious JavaScript pointing to the same attacker domain. They also suspected a supply-chain compromise involving SMB Team, an IT services provider to law firms, based on stolen credentials tied to an SMB Team email address.
Socket's Threat Research Team disclosed that the four malicious NuGet packages had accumulated about 4,500 downloads and appeared linked by shared credentials, build artifacts, and metadata quirks. Socket said it submitted takedown requests to the NuGet security team and published defensive guidance for dependency auditing and detection.
In early February 2026, Elastic analysts reported a multi-stage campaign using compromised websites and fake Cloudflare verification prompts to trick users into running PowerShell commands. The infection chain deployed a custom RAT called MIMICRAT, which supports stealth, persistence, token theft, file manipulation, and SOCKS5 tunneling.
On January 26, 2026, Group-IB first discovered a new MuddyWater campaign dubbed Operation Olalampo targeting organizations and individuals mainly in MENA and parts of Africa. The activity used phishing documents and sometimes public-facing server exploitation to deliver new malware families including Char, GhostFetch, GhostBackDoor, and HTTP_VIP leading to AnyDesk.
From September 2025 through January 2026, APT28 conducted a spear-phishing campaign dubbed Operation MacroMaze against entities in Western and Central Europe. The operation used lure documents with INCLUDEPICTURE tracking beacons, evolving macro techniques, and webhook[.]site for command retrieval and exfiltration.
Researchers observed two main NetSupport RAT command-and-control clusters associated with GrayCharlie being deployed steadily through 2025. The infrastructure used distinct TLS certificate naming patterns, license keys, and serial numbers, with hosting linked in part to MivoCloud and HZ Hosting Ltd.
Between August 12 and August 21, 2024, four malicious NuGet packages — NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_ — were published by the account "hamzazaheer." The packages were designed to backdoor ASP.NET applications through JIT hooking, localhost proxying, credential and authorization-data theft, and attacker-controlled authorization responses.
Eighteen days after the first intrusion, the same actor returned through the still-unpatched Apache ActiveMQ vulnerability, reused prior C2 infrastructure, enabled RDP, installed AnyDesk, and conducted additional scanning. Ransomware consistent with LockBit, but assessed as likely built with the leaked LockBit builder, was then deployed interactively across servers including backup and file servers.
In mid-February 2024, a threat actor exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server to gain remote code execution and establish a foothold on a Windows host. The attacker downloaded a Metasploit stager, escalated privileges, dumped LSASS, scanned via SMB, and moved laterally before being evicted about a day later.
GrayCharlie has been active since mid-2023, compromising WordPress sites and injecting malicious JavaScript to deliver malware such as NetSupport RAT, Stealc, and SectopRAT to site visitors. The campaign relied on fake browser updates and ClickFix-style fake CAPTCHA lures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcesocket.dev
Open sourcethedfirreport.com
Open sourcedarkreading.com
Open sourceannex.security
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.