No single cybersecurity event or topic coherently links the provided items; the set mixes unrelated malware/campaign reporting (e.g., Steaelite RAT MaaS capabilities; a fake Google security-check PWA leading to browser/Android surveillance; Velvet Tempest-linked ClickFix activity associated with Termite ransomware; the SeaFlower backdoored Web3-wallet campaign; and ResidentBat Android spyware attributed to the Belarusian KGB) with healthcare breach notifications/settlements (multiple provider incidents and a DragonForce-related settlement) and policy/legal/governance coverage (US healthcare cyber reform legislation; UK Court of Appeal ruling on “personal data”; South Korea considering cyber/data law updates). Several entries are primarily opinion, interviews, newsletters, podcasts, or generic guidance (agentic AI “hype vs reality,” AI for incident response, board metrics/risk signals, IAM exam playbook, dark web monitoring advice, crypto safety tips, and conference/podcast promos), which do not describe a specific incident and should be treated as low-signal for incident-driven intelligence.
For operational relevance, the incident-focused items provide discrete, unconnected takeaways: Steaelite is described as an “all-in-one” Windows 10/11 RAT with credential theft, RCE, file management, and ransomware/DDoS-style modules managed via a web panel; Malwarebytes details a social-engineering flow impersonating Google that abuses PWA behavior and browser APIs (notifications, contacts, GPS, clipboard) and can drop an Android companion implant; Deception.Pro logs a ClickFix-to-LOLBins chain (e.g., curl.exe, tar.exe, PowerShell) with observed C2 and hands-on-keyboard AD discovery leading toward ransomware activity; Confiant-reported SeaFlower uses trojanized clones of major crypto wallets to steal seed phrases; Censys documents ResidentBat infrastructure fingerprints and notes physical/ADB sideloading as the installation method. Separately, HIPAA Journal items cover multiple healthcare entities disclosing unauthorized access/exfiltration and a class-action settlement tied to a prior DragonForce ransomware incident, while government/legal pieces address sector-wide reforms and evolving interpretations of data-protection duties rather than a single breach.

See the actors and campaigns active against you right now.
12 events from the most recent confirmed update back to the earliest known activity.
KnowBe4 released a report on the Kratos phishing-as-a-service kit, outlining its modular architecture, anti-analysis controls, Adobe-themed lures, and Telegram-based credential exfiltration. The report also provided indicators of compromise and mapped the activity to MITRE ATT&CK techniques.
Black Fog published findings on Steaelite, describing a browser-accessible criminal platform that unifies credential theft, remote administration, ransomware deployment, and DDoS functions. The report warned that the integrated tooling lowers the barrier for double-extortion operations.
Malwarebytes detailed a phishing site impersonating a Google Account security page that installs a browser-resident surveillance toolkit as a Progressive Web App. The campaign used push-based command and control, contact and location theft, browser proxying, and in some cases delivered an Android APK disguised as a critical security update.
SANS Internet Storm Center documented a FedEx-themed phishing email carrying a 7z archive with a batch script that established persistence, launched PowerShell, decrypted shellcode, and injected it into explorer.exe. The final payload was identified as XWorm communicating with command-and-control server 204.10.160.190:7003.
Confiant reported a previously unreported SeaFlower campaign using cloned Coinbase Wallet, MetaMask, TokenPocket, and imToken apps on iOS and Android to steal seed phrases and drain funds. The activity was attributed to Chinese-speaking threat actors based on code artifacts, developer identifiers, and infrastructure patterns.
After the recovery phrase was exposed, attackers reportedly accessed and emptied the seized cryptocurrency wallet almost immediately. The theft was estimated at roughly $4.8 million and reportedly affected a wallet tied to a taxpayer identified as 'Case 3.'
During a publicized display of seized assets, South Korea's National Tax Service exposed the mnemonic recovery phrase for a seized cryptocurrency wallet in a press-release photo. The leak effectively revealed the wallet's master key.
As of February 2026, Censys tracking found ResidentBat-associated command-and-control hosts concentrated in several countries and identifiable through distinctive self-signed TLS certificates, banner hashes, and port usage. The research highlighted certificate reuse and recommended TLS-based detection because the servers resist HTTP fingerprinting.
KnowBe4 Threat Labs first observed the Kratos phishing-as-a-service kit around the beginning of 2026. The platform was described as a modular, centralized phishing system used in Adobe-themed credential theft campaigns across more than 20 countries.
Reporters Without Borders and RESIDENT.NGO publicly documented the ResidentBat Android spyware in December 2025. Their reporting described its use for targeted surveillance of journalists and civil society members.
The Steaelite malware-as-a-service platform began being advertised on cybercrime forums in November 2025. It was promoted as an all-in-one RAT combining credential theft, remote control, ransomware, DDoS, and other post-exploitation features.
Code analysis of the ResidentBat Android spyware indicates the implant was under development by at least 2021. The malware is attributed to the Belarusian KGB and was designed for targeted surveillance via hands-on device compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemalwarebytes.com
Open sourceblog.knowbe4.com
Open sourceisc.sans.edu
Open sourcedatabreaches.net
Open sourceblog.deception.pro
Open sourcecybersecuritynews.com
Open sourcecensys.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.