Darktrace reported that cyber intrusions in the first half of 2026 increasingly targeted trusted relationships rather than relying mainly on malware or direct vulnerability exploitation. The company said attackers abused cloud entitlements, SaaS accounts, email authentication, software supply chains, remote administration tools, and non-human identities, making trust itself a primary attack surface. Phishing remained effective despite defensive controls, with roughly two-thirds of phishing emails passing DMARC and VIP users singled out in about a quarter of campaigns, while social-engineering lures became more tailored and text-heavy.
The report highlighted multiple incidents showing how trusted infrastructure is being weaponized, including a compromised SaaS account that enabled cross-layer malicious activity, supply-chain compromises involving Axios, Trivy, and Hola VPN, and infostealer distribution through blockchain infrastructure using malware such as StealC, AMOS, and Phexia. Darktrace also warned that enterprise AI adoption is expanding risk, citing LLM-generated exploitation of React2Shell, a compromised LLM proxy at an automation technology manufacturer, and broader exposure of sensitive data in prompts. It said attackers are moving faster as well, with a React2Shell honeypot compromised in under two hours and BeyondTrust exploitation observed in less than a day, while state-aligned actors linked to China, Russia, Iran, and North Korea continued using legitimate services for persistence, intelligence collection, and strategic positioning.

Get the infrastructure and lures behind it.
9 events from the most recent confirmed update back to the earliest known activity.
Darktrace published its mid-year 2026 threat update on August 3, reporting that cloud and SaaS environments had become top attacker targets in the first half of the year. The report emphasized a shift toward compromising trust relationships, identities, supply chains, and AI-related infrastructure.
Darktrace said security researchers highlighted JadePuffer in July as the first fully AI-generated ransomware campaign. The campaign involved an agentic threat actor exploiting a vulnerability in an internet-facing server before launching a fully automated ransomware attack.
Darktrace said threat actors hijacked the widely used Axios JavaScript library in April to distribute remote access trojans. The compromise abused trust in a heavily used software dependency and developer ecosystem component.
Darktrace reported a February–March campaign that delivered malicious payloads to devices using Hola VPN. The activity was later linked to an issue in Hola’s delivery pipeline, and Darktrace said it detected anomalous activity across multiple customers before a public advisory was released.
Darktrace reported that at an automation technology manufacturer, attackers used a compromised LLM proxy as a steppingstone to additional AI services before pivoting to cryptomining. The case illustrated AI infrastructure becoming both an attack surface and a trusted intermediary.
Darktrace reported that attackers used legitimate blockchain infrastructure during the first half of 2026 to distribute infostealers including AMOS and Phexia. The company said this approach helped threat actors inherit trust and broaden victim reach.
Darktrace described a case in the first half of 2026 where one compromised SaaS account led to inbox rule changes, phishing activity, and suspicious connections across email, SaaS, and network layers. It presented the incident as an example of attackers abusing trusted identities and platforms rather than relying on malware alone.
Darktrace reported a case in which an attacker used a large language model to generate working exploit code for React2Shell and deploy it at scale. The incident was cited as an example of AI-assisted offensive activity in the first half of 2026.
Darktrace said a purpose-built React2Shell honeypot deployed in early 2026 was compromised in less than two hours. It cited the incident as evidence of how quickly attackers operationalize newly disclosed vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
darktrace.com
Open sourceinfosecurity-magazine.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.