IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling Cybereason Threat Watch

Cybereason Threat Research & Defense Rolling Intelligence Card

A source-cited rolling one-year monitor of Cybereason's public frontline TTP briefings and threat research, continued through LevelBlue after the integrated Q1 2026 briefing explicitly incorporated Cybereason, Stroz Friedberg, Trustwave, and Alert Logic capabilities. The active monitoring window is July 27, 2025–July 26, 2026, and the chronology now runs from September 2025 through July 2026 across identity abuse, edge exploitation, trusted tools, malware delivery, ransomware, cloud and API-key compromise, dwell time, exfiltration, and extortion. Pre-integration Cybereason percentages and broader LevelBlue percentages remain separate populations.

Coverage
Sep 12, 2025–Sep 11, 2026
Record Version
v10
Updated
Sep 9, 2026
AI Monitor
Weekly · Wed midday ET
Evidence
19 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 1-Year Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Sep 12, 2025Sep 11, 2026

365 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

365-day windowWeekly on Wednesday at midday ET

45%[15]

Q2 BEC Share

LevelBlue's integrated Q2 incident-response population, not global prevalence.Evidence dated Jul 23, 2026

65%[15]

Q2 Phishing Initial Access

Share of initial intrusion vectors in LevelBlue's Q2 briefing.Evidence dated Jul 23, 2026

23%[15]

Q2 31+ Day Cases

Non-MDR cases with 31 or more days before IR engagement, down from 38% in Q1.Evidence dated Jul 23, 2026

42%[15]

Q2 3–10 Day Cases

Share of non-MDR cases in the 3–10 day band, up from 23% in Q1.Evidence dated Jul 23, 2026

28%[2]

Q4 Ransomware Share

Earlier Cybereason Q4 case population; not directly comparable to the broader LevelBlue population.Evidence dated Feb 5, 2026

52%[2]

Q4 Phishing Initial Access

Earlier Cybereason Q4 initial-vector population.Evidence dated Feb 5, 2026

Evidence-Prioritized Access Paths

Top Initial Access & Account-Takeover Vectors

The Cybereason-to-LevelBlue corpus prioritizes phishing, device-code and token abuse, edge exploitation, valid human and machine identity, compromised integrations, and trusted-tool delivery; defensive value comes from detecting the transition from authenticated access to persistence, exfiltration, extortion, or impact.

1

Publisher-observed access path

OAuth tokens, API keys, and connected applications[15]Evidence dated Jul 23, 2026

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
A vendor integration or machine identity is compromised and retains trusted access to connected SaaS services.
Attacker outcome
Authenticated cloud access, automated data collection, persistence, and downstream compromise without another user prompt.
What to monitor
New grants, unusual API clients, high-volume Graph or Salesforce access, token use from new infrastructure, scope changes, and cross-tenant activity.
2

Publisher-observed access path

OAuth device-code phishing[17]Evidence dated Jun 9, 2026

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
A lure convinces a user to authorize an attacker-supplied device code through a legitimate identity flow.
Attacker outcome
A valid session that can bypass password-focused and ordinary MFA monitoring.
What to monitor
Device-code grants, unapproved client applications, risky token issuance, unusual redirect chains, QR delivery, and post-authentication access.
3

Publisher-observed access path

Compromised websites and ClickFix[20]Evidence dated Jul 16, 2026

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
An injected overlay on a legitimate website instructs a visitor to paste an attacker-supplied command.
Attacker outcome
In-memory execution and theft of browser, Keychain, SSH, and other credential material.
What to monitor
Injected WordPress scripts, browser-to-terminal workflows, shell pipelines, osascript behavior, Polygon RPC lookups, staging archives, and outbound credential exfiltration.
4

Publisher-observed access path

Phishing and calendar invitations[2]Evidence dated Feb 5, 2026

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
A trusted-looking message or calendar event carries a malicious login or delivery path.
Attacker outcome
Credential theft, session capture, or user-installed tooling.
What to monitor
New domains, suspicious calendar content, authentication anomalies, and post-login behavior.
5

Publisher-observed access path

Adversary-in-the-middle phishing[2][6]First cited source Nov 3, 2025 · Latest cited source Feb 5, 2026

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
A reverse proxy relays the real authentication flow.
Attacker outcome
Credentials and authenticated session tokens despite MFA completion.
What to monitor
Token replay, unfamiliar devices, proxy infrastructure, impossible session transitions, and mailbox or SaaS changes.
6

Publisher-observed access path

SEO poisoning and fake installers[2][3]First cited source Feb 3, 2026 · Latest cited source Feb 5, 2026

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
Search results lead users to a legitimate-looking download.
Attacker outcome
Remote access or ValleyRAT-style malware execution.
What to monitor
Browser-to-download chains, unsigned or mismatched installers, remote-tool installation, persistence, and C2.
7

Publisher-observed access path

Malicious browser extensionsEvidence dated Source date not published

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
A fake AI advertising tool convinces a business user to grant a Chrome extension broad access.
Attacker outcome
Credential, session-token, Meta Business account, or business-data theft.
What to monitor
Unapproved extensions, broad host permissions, content injection, network interception, and anomalous advertiser-account sessions.
8

Publisher-observed access path

Internet-facing React Server Components[12]Evidence dated Dec 5, 2025

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
A crafted unauthenticated request reaches vulnerable React or Next.js server logic.
Attacker outcome
Server-side command execution, secret theft, persistence, payload deployment, or lateral movement.
What to monitor
Malformed RSC requests, unexpected POST traffic, Node.js spawning shells, web shells, and post-exploitation access.
9

Publisher-observed access path

Edge and enterprise-application exploitation[2][8][9]First cited source Oct 5, 2025 · Latest cited source Feb 5, 2026

Retained Cybereason / LevelBlue evidence; local exposure and prevalence require validation

How it starts
Exposed VPN, firewall, RDP, or Oracle EBS weaknesses are exploited.
Attacker outcome
Network access, data theft, extortion, or ransomware staging.
What to monitor
Exploit indicators, new accounts, web shells, anomalous data access, and extortion contact.

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentExecutives, CISOs, CIOs, incident-response leaders, threat-intelligence teams, SOC leaders, risk owners, and business-continuity leaders who need a decision-ready view of one publisher's strongest public research.
Audience fieldDecision useAssessmentUse the card to identify recurring access paths, actor and campaign changes, affected technologies, likely business impact, and control priorities that deserve validation inside the reader's own environment.
Audience fieldSource postureAssessmentCybereason / LevelBlue is the controlling source for publisher-specific observations. External facts repeated in a publication retain the original attribution and are not upgraded into independently verified IntelliOS findings.
Audience fieldUpdate modelAssessmentA dedicated publisher agent checks the complete monitored corpus weekly on wednesday at midday et, keeps a cumulative rolling one-year window, and sends Page Alerts only for material source-backed changes.

Chronology and Decision Milestones

Timeline of Notable Activity

Entries are ordered from oldest to newest. Q3 and Q4 findings use the end of Cybereason's stated observation period; Citations preserve the later publication date. One-off research uses the stated activity, disclosure, or publication date as labeled. The monitored archive was checked through July 26, 2026 and contains no qualifying public threat-research post after February 5, so the card preserves that visible source gap instead of inventing March–July activity.

  1. Q3 observation · incident mix

    BEC, ransomware, and insider activity dominated Cybereason's Q3 case mix

    BEC represented 46% of the described cases, ransomware 39%, and insider threats rose from 2% in H1 to 7% in Q3. The insider increase included North Korean remote-worker schemes and employees taking proprietary data.[8]

  2. Q3 observation · initial access

    Exploited vulnerabilities more than doubled to 31% of initial intrusion vectors

    Phishing remained first at 50%, but CVE exploitation rose from 15% in H1 to 31% in Q3. The observed list included SharePoint, CentreStack, Fortinet, and SonicWall weaknesses, making edge inventory and emergency change capacity material controls.[8]

  3. Q3 observation · credential persistence

    Akira reused SonicWall VPN credentials stolen before patching

    Cybereason observed Akira access through previously harvested credentials tied to CVE-2024-40766, including credentials migrated from older devices. Patching without resetting exposed VPN credentials left a viable path back in.[8]

  4. Q3 observation · evasion and dwell

    Living-off-the-land use rose while 38% of cases still exceeded 31 days of dwell time

    LOLBIN use appeared in 17% of Q3 investigations, up from 13% in H1. Cybereason separately found 38% of non-MDR cases had 31-plus-day dwell, reinforcing behavior-based detection and sufficient historical telemetry.[8]

  5. Mass extortion

    CL0P's Oracle EBS campaign ties exploited enterprise software to email extortion

    Cybereason assessed that activity from late July through early September involved unauthorized access, data enumeration and exfiltration before extortion emails. CVE-2025-61882 remediation must be paired with historical investigation and evidence preservation.[9]

  6. Malware campaign

    Tangerine Turkey shows a campaign maturing from scripts into a repeatable system

    Cybereason's campaign analysis documents a structured chain rather than a single payload. Defenders should connect delivery, execution, persistence, C2, and follow-on behaviors.[7]

  7. Phishing-as-a-service

    Tycoon 2FA operationalizes adversary-in-the-middle credential and session theft

    The kit demonstrates why valid passwords and completed MFA challenges can still produce attacker sessions. Domain, proxy, session, and post-authentication behavior must be correlated.[6]

  8. Ransomware operation

    The Gentlemen combine edge access, credential abuse, and multi-platform encryption

    Cybereason's technical report turns a new ransomware brand into a behavior-led watchlist for access, persistence, defense evasion, lateral movement, exfiltration, and encryption.[5]

  9. Vulnerability exploitation

    React2Shell moved from disclosure to practical exploitation within hours

    CVE-2025-55182 exposed React Server Components to unauthenticated remote code execution. Cybereason validated a public proof of concept causing Node.js to spawn a shell and advised organizations with pre-patch internet exposure to investigate, not merely patch.[12]

  10. Q4 observation · incident mix

    BEC and ransomware remained the two leading incident types in Cybereason's Q4 cases

    Cybereason reports BEC at 42% and ransomware at 28% of the described Q4 incident population, while non-ransomware network intrusions rose to 25%. The figures should drive preparation, not be treated as global prevalence.[2]

  11. Q4 observation · initial access

    Phishing reached 52% of initial intrusion vectors

    Calendar invitations, evolving lures, and credential capture helped phishing bypass ordinary email expectations. Defenders should monitor authentication and user behavior after delivery rather than relying on message filtering alone.[2]

  12. Q4 observation · identity control failure

    MFA adoption rose, but Cybereason observed bypass in 96% of MFA-present cases

    AiTM phishing, session-token interception, and varied social engineering can turn MFA into a speed bump. Phishing-resistant methods and session telemetry are required.[2][6]

  13. Q4 observation · edge exposure

    RDP, VPNs, and edge devices represented 18% of initial intrusion vectors

    Cybereason's Q4 findings and CVE list show why external appliances need rapid remediation, historical log review, and identity investigation—not only present-state patch checks.[2][8][9]

  14. Q4 observation · trusted-tool abuse

    Remote-access-tool use for escalation rose from 3% of Q3 investigations to 60% in Q4

    Legitimate remote tools, search-result poisoning, and user installation can create a low-friction foothold that blends with administration. Remote-tool allowlisting and behavioral monitoring need to cover both installation and use.[2][3]

  15. Q4 observation · dwell time

    Forty-two percent of cases had 31 or more days of dwell time

    Cybereason notes that initial access brokers can create quiet latency between compromise and later use. Long log retention and retrospective hunting are needed even when active malicious behavior is absent.[2]

  16. Annual IR observation

    Identity-led intrusions increasingly hide inside trusted cloud services and normal business workflows

    Across the prior 12 months, Cybereason says phishing and social engineering accounted for 40% of its worldwide cases—more than double credential abuse or CVE exploitation. The source frames the forward-looking implications as predictions, not measured 2026 outcomes.[4]

  17. Malware delivery

    A fake LINE installer used signed-looking packaging, PowerShell, and process injection to deploy ValleyRAT

    Cybereason observed an NSIS installer add Defender exclusions, establish persistence, and use PoolParty Variant 7 to inject into trusted Windows processes. The defensive lesson is to connect download provenance, certificate anomalies, exclusion changes, scheduled tasks, injection, and outbound C2.[3]

  18. Q1 observation · trust abuse

    BEC increasingly became cloud data theft and extortion rather than an email-only fraud

    LevelBlue’s first integrated briefing placed BEC at 39%, non-ransomware network intrusion at 30%, and ransomware at 26%. It observed OAuth-token and Microsoft Graph abuse against Exchange Online, OneDrive, and SharePoint, plus IT impersonation through Teams and help-desk pressure.[14]

  19. Q1 observation · initial access

    Phishing still led, while edge flaws and remote services supplied nearly one-third of entry paths

    The Q1 population placed phishing at 58%, exploited vulnerabilities at 20%, and external remote services such as RDP and VPN at 11%. The combined decision is to secure identity and communication workflows without easing pressure on internet-facing systems.[14]

  20. The Gentlemen · multi-platform extortion

    The Gentlemen scaled affiliate operations across exposed access, data theft, and virtualization impact

    LevelBlue’s analysis describes valid credentials, VPN and firewall access, AnyDesk, SystemBC, reconnaissance, WinSCP exfiltration, security-tool tampering, and Windows, Linux, NAS, BSD, and ESXi encryption. Alleged actor-side material offered underground remains a separate unverified lead.[16]

  21. Identity phishing · device code flow

    Device-code phishing became a commodity kit feature and peaked in May

    LevelBlue observed EvilTokens, Kali365, Ghost Hub, Cyb3r, and Tycoon2FA operationalizing device-code flow abuse with protected PDFs, QR codes, legitimate redirectors, compromised senders, and multi-stage rewrite chains. Conditional Access restrictions and token-use monitoring are more useful than waiting for a password failure.[17]

  22. Q2 observation · identity and machine trust

    Valid tokens and API keys let attackers arrive already authenticated

    LevelBlue’s Q2 briefing describes BEC at 45%, a spike in cloud intrusion, and software-supply-chain access through OAuth tokens, API keys, service accounts, and connected applications. The Klue compromise showed one trusted integration enabling automated Salesforce access across hundreds of organizations.[15]

  23. Q2 observation · faster intrusion path

    Long-dwell cases fell, but the intrusion path compressed

    In LevelBlue’s non-MDR Q2 population, cases lasting 31 days or more fell from 38% to 23%, while 3–10 day cases rose from 23% to 42%. Faster engagement helped, but attackers also reached objectives sooner through valid identity, supply-chain access, living-off-the-land tools, and AI-assisted activity.[15]

  24. ValleyRAT · delivery diversification

    ValleyRAT expanded from fake installers into malicious-email delivery

    LevelBlue identified distinct fake-installer and email-driven paths targeting Chinese- and Japanese-speaking users. The malware’s evasion and anti-analysis behavior matter, but the source also warns that ValleyRAT use alone is insufficient to attribute every campaign to SilverFox.[18]

  25. MDR case · phishing to persistent RAT

    A logistics document chained native Windows tools into CrySome RAT persistence

    LevelBlue’s contained case began with a targeted rate-confirmation lure, then used living-off-the-land execution, a silent UAC bypass, in-memory AMSI patching, and a Defender-disruption utility disguised as svchost.exe. Correlating the business lure, interpreter chain, privilege change, and security tampering created the response opportunity.[19]

  26. ClickFix · macOS credential theft

    Compromised WordPress sites turned fake verification into a cross-platform infostealer path

    LevelBlue identified hundreds of compromised sites serving a ClickFix overlay. On macOS, the victim pasted a Terminal command that retrieved in-memory code, stole Keychain, browser, and SSH material, and exfiltrated it; the campaign stored C2 location in a Polygon smart contract to resist ordinary DNS takedown.[20]

Bottom Line Up Front

BLUF

Coverage periodSep 12, 2025Sep 11, 2026365 calendar days, inclusiveUpdated Sep 9, 2026
  • Compromised WordPress sites turned fake verification into a cross-platform infostealer path: LevelBlue identified hundreds of compromised sites serving a ClickFix overlay. On macOS, the victim pasted a Terminal command that retrieved in-memory code, stole Keychain, browser, and SSH material, and exfiltrated it; the campaign stored C2 location in a Polygon smart contract to resist ordinary DNS takedown.[20]Evidence dated Jul 16, 2026

  • A logistics document chained native Windows tools into CrySome RAT persistence: LevelBlue’s contained case began with a targeted rate-confirmation lure, then used living-off-the-land execution, a silent UAC bypass, in-memory AMSI patching, and a Defender-disruption utility disguised as svchost.exe. Correlating the business lure, interpreter chain, privilege change, and security tampering created the response opportunity.[19]Evidence dated Jul 6, 2026

  • Valid tokens and API keys let attackers arrive already authenticated: LevelBlue’s Q2 briefing describes BEC at 45%, a spike in cloud intrusion, and software-supply-chain access through OAuth tokens, API keys, service accounts, and connected applications. The Klue compromise showed one trusted integration enabling automated Salesforce access across hundreds of organizations.[15]Evidence dated Jul 23, 2026

  • Long-dwell cases fell, but the intrusion path compressed: In LevelBlue’s non-MDR Q2 population, cases lasting 31 days or more fell from 38% to 23%, while 3–10 day cases rose from 23% to 42%. Faster engagement helped, but attackers also reached objectives sooner through valid identity, supply-chain access, living-off-the-land tools, and AI-assisted activity.[15]Evidence dated Jul 23, 2026

  • ValleyRAT expanded from fake installers into malicious-email delivery: LevelBlue identified distinct fake-installer and email-driven paths targeting Chinese- and Japanese-speaking users. The malware’s evasion and anti-analysis behavior matter, but the source also warns that ValleyRAT use alone is insufficient to attribute every campaign to SilverFox.[18]Evidence dated Jun 30, 2026

  • Device-code phishing became a commodity kit feature and peaked in May: LevelBlue observed EvilTokens, Kali365, Ghost Hub, Cyb3r, and Tycoon2FA operationalizing device-code flow abuse with protected PDFs, QR codes, legitimate redirectors, compromised senders, and multi-stage rewrite chains. Conditional Access restrictions and token-use monitoring are more useful than waiting for a password failure.[17]Evidence dated Jun 9, 2026

Decision Context

Executive Summary

Coverage periodSep 12, 2025Sep 11, 2026365 calendar days, inclusiveUpdated Sep 9, 2026

Across the full September 2025–July 2026 chronology, the Cybereason-to-LevelBlue research lineage is most valuable when read as an intrusion-path dataset. Malicious browser extensions, phishing, device codes, exposed edge systems, valid sessions, OAuth and API keys, remote tools, vulnerable applications, RAT chains, cloud data theft, and ransomware are connected stages rather than independent alerts. Detection engineering should correlate transitions across browser, identity, endpoint, network, cloud, SaaS, and business telemetry.[2][3][5][6][8][9][12][14][15][17][18][19][20]First cited source Oct 5, 2025 · Latest cited source Jul 23, 2026

Cybereason's own public archive ends its retained sequence in February, but the threat-intelligence lineage does not. LevelBlue's Q1 briefing explicitly says its unified population integrates Cybereason, Stroz Friedberg, Trustwave, and Alert Logic capabilities. This card therefore follows Q1 and Q2 frontline findings and SpiderLabs technical research while marking the source-population change; it does not pretend the pre- and post-integration percentages form one directly comparable series.[1][13][14][15]First cited source May 5, 2026 · Latest cited source Jul 23, 2026

The most important 2026 shift is from human credentials to every form of trusted identity. Q2 activity used OAuth tokens, API keys, service accounts, connected applications, device-code flows, and valid sessions to skip familiar controls and reduce the time between entry and impact. Inventory and behavior monitoring must cover machine identities and SaaS integrations as rigorously as employee accounts.[15][17]First cited source Jun 9, 2026 · Latest cited source Jul 23, 2026

The Q4 briefing shows the control gap clearly: MFA was widely present, yet bypass was observed at a very high rate in the described cases. The practical answer is not to abandon MFA but to move toward phishing-resistant authentication, restrict risky flows, and investigate session creation, token use, device registration, and post-authentication behavior.[2][6]First cited source Nov 3, 2025 · Latest cited source Feb 5, 2026

Trusted software and business tooling remain active delivery paths. Search poisoning can lead users to remote tools; fake installers and email deliver ValleyRAT; a malicious Chrome extension can hijack advertiser sessions; a logistics document can chain native Windows components into CrySome RAT; and compromised WordPress sites can push macOS ClickFix. Provenance, extension and script governance, egress controls, remote-tool control, patch-plus-hunt workflows, and behavioral correlation matter.[2][3][12][18][19][20]First cited source Dec 5, 2025 · Latest cited source Jul 16, 2026

Attack speed is becoming as important as dwell time. The Q2 population had fewer 31-plus-day cases but many more cases in the 3–10 day band. Organizations still need enough historical telemetry to reconstruct brokered or quiet access, while containment authority and cross-system correlation must also operate quickly enough for compressed intrusions.[2][15]First cited source Feb 5, 2026 · Latest cited source Jul 23, 2026

The executive priority is to fund controls that repeatedly interrupt the path: phishing-resistant identity, device-code and token restrictions, machine-identity governance, edge exposure management, browser and software provenance, remote-tool governance, rapid exploitation response, useful historical telemetry, EDR tamper protection, tested recovery, and practiced incident command.[2][5][6][8][9][10][12][14][15][17][19][20]First cited source Sep 23, 2025 · Latest cited source Jul 23, 2026

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    Compromised WordPress sites turned fake verification into a cross-platform infostealer pathLevelBlue identified hundreds of compromised sites serving a ClickFix overlay. On macOS, the victim pasted a Terminal command that retrieved in-memory code, stole Keychain, browser, and SSH material, and exfiltrated it; the campaign stored C2 location in a Polygon smart contract to resist ordinary DNS takedown.[20]Evidence dated Jul 16, 2026

  2. 2

    A logistics document chained native Windows tools into CrySome RAT persistenceLevelBlue’s contained case began with a targeted rate-confirmation lure, then used living-off-the-land execution, a silent UAC bypass, in-memory AMSI patching, and a Defender-disruption utility disguised as svchost.exe. Correlating the business lure, interpreter chain, privilege change, and security tampering created the response opportunity.[19]Evidence dated Jul 6, 2026

  3. 3

    Valid tokens and API keys let attackers arrive already authenticatedLevelBlue’s Q2 briefing describes BEC at 45%, a spike in cloud intrusion, and software-supply-chain access through OAuth tokens, API keys, service accounts, and connected applications. The Klue compromise showed one trusted integration enabling automated Salesforce access across hundreds of organizations.[15]Evidence dated Jul 23, 2026

  4. 4

    Long-dwell cases fell, but the intrusion path compressedIn LevelBlue’s non-MDR Q2 population, cases lasting 31 days or more fell from 38% to 23%, while 3–10 day cases rose from 23% to 42%. Faster engagement helped, but attackers also reached objectives sooner through valid identity, supply-chain access, living-off-the-land tools, and AI-assisted activity.[15]Evidence dated Jul 23, 2026

  5. 5

    ValleyRAT expanded from fake installers into malicious-email deliveryLevelBlue identified distinct fake-installer and email-driven paths targeting Chinese- and Japanese-speaking users. The malware’s evasion and anti-analysis behavior matter, but the source also warns that ValleyRAT use alone is insufficient to attribute every campaign to SilverFox.[18]Evidence dated Jun 30, 2026

  6. 6

    Device-code phishing became a commodity kit feature and peaked in MayLevelBlue observed EvilTokens, Kali365, Ghost Hub, Cyb3r, and Tycoon2FA operationalizing device-code flow abuse with protected PDFs, QR codes, legitimate redirectors, compromised senders, and multi-stage rewrite chains. Conditional Access restrictions and token-use monitoring are more useful than waiting for a password failure.[17]Evidence dated Jun 9, 2026

  7. 7

    The Gentlemen scaled affiliate operations across exposed access, data theft, and virtualization impactLevelBlue’s analysis describes valid credentials, VPN and firewall access, AnyDesk, SystemBC, reconnaissance, WinSCP exfiltration, security-tool tampering, and Windows, Linux, NAS, BSD, and ESXi encryption. Alleged actor-side material offered underground remains a separate unverified lead.[16]Evidence dated May 18, 2026

  8. 8

    BEC increasingly became cloud data theft and extortion rather than an email-only fraudLevelBlue’s first integrated briefing placed BEC at 39%, non-ransomware network intrusion at 30%, and ransomware at 26%. It observed OAuth-token and Microsoft Graph abuse against Exchange Online, OneDrive, and SharePoint, plus IT impersonation through Teams and help-desk pressure.[14]Evidence dated May 5, 2026

  9. 9

    Phishing still led, while edge flaws and remote services supplied nearly one-third of entry pathsThe Q1 population placed phishing at 58%, exploited vulnerabilities at 20%, and external remote services such as RDP and VPN at 11%. The combined decision is to secure identity and communication workflows without easing pressure on internet-facing systems.[14]Evidence dated May 5, 2026

  10. 10

    BEC and ransomware remained the two leading incident types in Cybereason's Q4 casesCybereason reports BEC at 42% and ransomware at 28% of the described Q4 incident population, while non-ransomware network intrusions rose to 25%. The figures should drive preparation, not be treated as global prevalence.[2]Evidence dated Feb 5, 2026

  11. 11

    Phishing reached 52% of initial intrusion vectorsCalendar invitations, evolving lures, and credential capture helped phishing bypass ordinary email expectations. Defenders should monitor authentication and user behavior after delivery rather than relying on message filtering alone.[2]Evidence dated Feb 5, 2026

  12. 12

    MFA adoption rose, but Cybereason observed bypass in 96% of MFA-present casesAiTM phishing, session-token interception, and varied social engineering can turn MFA into a speed bump. Phishing-resistant methods and session telemetry are required.[2][6]First cited source Nov 3, 2025 · Latest cited source Feb 5, 2026

  13. 13

    RDP, VPNs, and edge devices represented 18% of initial intrusion vectorsCybereason's Q4 findings and CVE list show why external appliances need rapid remediation, historical log review, and identity investigation—not only present-state patch checks.[2][8][9]First cited source Oct 5, 2025 · Latest cited source Feb 5, 2026

  14. 14

    Remote-access-tool use for escalation rose from 3% of Q3 investigations to 60% in Q4Legitimate remote tools, search-result poisoning, and user installation can create a low-friction foothold that blends with administration. Remote-tool allowlisting and behavioral monitoring need to cover both installation and use.[2][3]First cited source Feb 3, 2026 · Latest cited source Feb 5, 2026

  15. 15

    Forty-two percent of cases had 31 or more days of dwell timeCybereason notes that initial access brokers can create quiet latency between compromise and later use. Long log retention and retrospective hunting are needed even when active malicious behavior is absent.[2]Evidence dated Feb 5, 2026

  16. 16

    A fake LINE installer used signed-looking packaging, PowerShell, and process injection to deploy ValleyRATCybereason observed an NSIS installer add Defender exclusions, establish persistence, and use PoolParty Variant 7 to inject into trusted Windows processes. The defensive lesson is to connect download provenance, certificate anomalies, exclusion changes, scheduled tasks, injection, and outbound C2.[3]Evidence dated Feb 3, 2026

  17. 17

    Identity-led intrusions increasingly hide inside trusted cloud services and normal business workflowsAcross the prior 12 months, Cybereason says phishing and social engineering accounted for 40% of its worldwide cases—more than double credential abuse or CVE exploitation. The source frames the forward-looking implications as predictions, not measured 2026 outcomes.[4]Evidence dated Jan 9, 2026

  18. 18

    React2Shell moved from disclosure to practical exploitation within hoursCVE-2025-55182 exposed React Server Components to unauthenticated remote code execution. Cybereason validated a public proof of concept causing Node.js to spawn a shell and advised organizations with pre-patch internet exposure to investigate, not merely patch.[12]Evidence dated Dec 5, 2025

  19. 19

    The Gentlemen combine edge access, credential abuse, and multi-platform encryptionCybereason's technical report turns a new ransomware brand into a behavior-led watchlist for access, persistence, defense evasion, lateral movement, exfiltration, and encryption.[5]Evidence dated Nov 18, 2025

  20. 20

    Tycoon 2FA operationalizes adversary-in-the-middle credential and session theftThe kit demonstrates why valid passwords and completed MFA challenges can still produce attacker sessions. Domain, proxy, session, and post-authentication behavior must be correlated.[6]Evidence dated Nov 3, 2025

  21. 21

    Tangerine Turkey shows a campaign maturing from scripts into a repeatable systemCybereason's campaign analysis documents a structured chain rather than a single payload. Defenders should connect delivery, execution, persistence, C2, and follow-on behaviors.[7]Evidence dated Oct 29, 2025

  22. 22

    CL0P's Oracle EBS campaign ties exploited enterprise software to email extortionCybereason assessed that activity from late July through early September involved unauthorized access, data enumeration and exfiltration before extortion emails. CVE-2025-61882 remediation must be paired with historical investigation and evidence preservation.[9]Evidence dated Oct 5, 2025

  23. 23

    BEC, ransomware, and insider activity dominated Cybereason's Q3 case mixBEC represented 46% of the described cases, ransomware 39%, and insider threats rose from 2% in H1 to 7% in Q3. The insider increase included North Korean remote-worker schemes and employees taking proprietary data.[8]Evidence dated Oct 23, 2025

  24. 24

    Exploited vulnerabilities more than doubled to 31% of initial intrusion vectorsPhishing remained first at 50%, but CVE exploitation rose from 15% in H1 to 31% in Q3. The observed list included SharePoint, CentreStack, Fortinet, and SonicWall weaknesses, making edge inventory and emergency change capacity material controls.[8]Evidence dated Oct 23, 2025

  25. 25

    Akira reused SonicWall VPN credentials stolen before patchingCybereason observed Akira access through previously harvested credentials tied to CVE-2024-40766, including credentials migrated from older devices. Patching without resetting exposed VPN credentials left a viable path back in.[8]Evidence dated Oct 23, 2025

  26. 26

    Living-off-the-land use rose while 38% of cases still exceeded 31 days of dwell timeLOLBIN use appeared in 17% of Q3 investigations, up from 13% in H1. Cybereason separately found 38% of non-MDR cases had 31-plus-day dwell, reinforcing behavior-based detection and sufficient historical telemetry.[8]Evidence dated Oct 23, 2025

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationOrganizations with $1M–$100M revenue[15]Evidence dated Jul 23, 2026SectorsCross-industry mid-marketGeographyLevelBlue's integrated Q2 case populationConfirmation statusLargest company-size band in the Q2 briefing; not a global victim censusHow companies should use itTreat mid-market identity, SaaS integrations, edge systems, telemetry, and containment speed as primary controls rather than assuming lower revenue reduces attacker interest.
Victim / exposure populationFinancial services, education and research, and legal/professional services[15]Evidence dated Jul 23, 2026SectorsFinancial services 28%; education and research 13%; legal/professional services 11%GeographyLevelBlue's integrated Q2 case populationConfirmation statusSector distribution within the stated Q2 incident-response populationHow companies should use itPrioritize phishing-resistant identity, machine-token governance, connected-app monitoring, edge hardening, and rapid escalation around seasonal or business-process pressure.
Victim / exposure populationSmall organizations with $1M–$10M revenue[2]Evidence dated Feb 5, 2026SectorsCross-industryGeographyCybereason's case populationConfirmation statusMost frequently impacted revenue band in the Q4 briefingHow companies should use itDo not treat small size as protection; prioritize identity, edge, logging, and recovery maturity.
Victim / exposure populationFinancial services[2]Evidence dated Feb 5, 2026SectorsFinancial servicesGeographyCybereason's case populationConfirmation statusMost targeted industry in the Q4 briefingHow companies should use itEmphasize phishing-resistant identity, payment-process verification, privileged access, and rapid containment.
Victim / exposure populationLegal, professional services, and manufacturing[2][8]First cited source Oct 23, 2025 · Latest cited source Feb 5, 2026SectorsLegal, professional services, manufacturingGeographyCybereason's case populationConfirmation statusIncreasing targeting reported across Q3/H1 comparisonsHow companies should use itReview remote access, sensitive repositories, service relationships, and operational continuity.
Victim / exposure populationOracle EBS users[9]Evidence dated Oct 5, 2025SectorsCross-industry enterprise software usersGeographyGlobalConfirmation statusCampaign targeting tied to a named CVE and extortion reportingHow companies should use itPatch, hunt for exploitation and data access, preserve evidence, and validate extortion claims.

Distinct Operational Records

Cybereason Research Themes & Operations

Device-code phishing kits

EvilTokens, Kali365, Ghost Hub, Cyb3r, and Tycoon2FA used commodity delivery, redirect, QR, and compromised-account techniques to obtain authenticated access.[17]Evidence dated Jun 9, 2026

Klue integration compromise

Compromised API credentials enabled automated access to Salesforce-connected environments and showed how one vendor integration can skip several intrusion stages.[15]Evidence dated Jul 23, 2026

macOS ClickFix infostealer

Compromised WordPress sites, fake verification, blockchain-resolved C2, in-memory execution, and Keychain, browser, and SSH theft formed a cross-platform credential pipeline.[20]Evidence dated Jul 16, 2026

CrySome RAT infection chain

A business-process spear-phish progressed through native Windows execution, UAC bypass, AMSI patching, Defender disruption, and persistent RAT delivery.[19]Evidence dated Jul 6, 2026

Q4 phishing and RAT surge

Calendar phishing, SEO poisoning, and remote-access tools combine delivery with trusted-software abuse.[2][3]First cited source Feb 3, 2026 · Latest cited source Feb 5, 2026

React2Shell exploitation

Public proof-of-concept code and reported exploitation turned an internet-facing React Server Components flaw into a rapid initial-access problem.[12]Evidence dated Dec 5, 2025

ValleyRAT fake installer

A fake LINE installer chained Defender exclusions, persistence, trusted-process injection, and C2 into a concrete malware-delivery path.[3]Evidence dated Feb 3, 2026

The Gentlemen ransomware

A multi-platform ransomware operation using access, evasion, lateral movement, exfiltration, and encryption.[5]Evidence dated Nov 18, 2025

Tycoon 2FA

Phishing-as-a-service infrastructure captures credentials and authenticated sessions.[6]Evidence dated Nov 3, 2025

CL0P Oracle EBS

Enterprise application exploitation leads to data-theft and email-extortion pressure.[9]Evidence dated Oct 5, 2025

Tangerine Turkey

A structured campaign chain demonstrates repeatable malware operations beyond one payload.[7]Evidence dated Oct 29, 2025

Source-Bound Actor Context

Threat Actors, Operators & Decision Owners

The Gentlemen

Ransomware operator tracked through technical behavior rather than leak-site volume alone.[5]Evidence dated Nov 18, 2025

CL0P

Extortion operator linked to exploitation of Oracle EBS CVE-2025-61882.[9]Evidence dated Oct 5, 2025

Tangerine Turkey

Cybereason campaign label for a structured malware operation.[7]Evidence dated Oct 29, 2025

Initial access brokers

Can create a quiet delay between compromise and follow-on activity, extending dwell time.[2]Evidence dated Feb 5, 2026

Phishing-as-a-service operators

Package infrastructure, lures, proxying, and session theft for broader criminal use.[6]Evidence dated Nov 3, 2025

Enterprise Exposure

Affected Technologies & Trust Boundaries

OAuth tokens, API keys, service accounts, and connected applications

Machine identities can give attackers authenticated access across SaaS platforms without another password or MFA prompt.[15]Evidence dated Jul 23, 2026

OAuth device-code flow

Commodity kits and legitimate redirect infrastructure can trick users into authorizing attacker sessions; restrict the flow where unnecessary and monitor resulting token use.[17]Evidence dated Jun 9, 2026

WordPress, macOS Keychain, browsers, and SSH keys

The ClickFix campaign turned compromised websites into a delivery layer for high-value local and cloud access material.[20]Evidence dated Jul 16, 2026

RDP and VPN edge devices

Remain recurring access points and require rapid remediation plus historical authentication review.[2][8]First cited source Oct 23, 2025 · Latest cited source Feb 5, 2026

Remote access tools

AnyDesk, NetSupport, and related tools can be installed through SEO poisoning and blend with legitimate administration.[2][3]First cited source Feb 3, 2026 · Latest cited source Feb 5, 2026

React Server Components and Next.js

React2Shell exposed vulnerable internet-facing servers to trivial pre-authentication code execution and required retrospective compromise review.[12]Evidence dated Dec 5, 2025

MFA and session tokens

AiTM and token interception can bypass ordinary MFA outcomes.[2][6]First cited source Nov 3, 2025 · Latest cited source Feb 5, 2026

Oracle E-Business Suite

Named enterprise technology tied to a CVE-driven extortion campaign.[9]Evidence dated Oct 5, 2025

Endpoint and network telemetry

Must be retained long enough to reconstruct 31-plus-day dwell and access-broker latency.[2][10]First cited source Sep 23, 2025 · Latest cited source Feb 5, 2026

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized source-backed developments that convert the rolling activity record into named operational monitoring requirements.

1Threat / Category

ClickFix · macOS credential theft

Compromised WordPress sites turned fake verification into a cross-platform infostealer path[20]Evidence dated Jul 16, 2026

Why it mattersLevelBlue identified hundreds of compromised sites serving a ClickFix overlay. On macOS, the victim pasted a Terminal command that retrieved in-memory code, stole Keychain, browser, and SSH material, and exfiltrated it; the campaign stored C2 location in a Polygon smart contract to resist ordinary DNS takedown.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
2Threat / Category

MDR case · phishing to persistent RAT

A logistics document chained native Windows tools into CrySome RAT persistence[19]Evidence dated Jul 6, 2026

Why it mattersLevelBlue’s contained case began with a targeted rate-confirmation lure, then used living-off-the-land execution, a silent UAC bypass, in-memory AMSI patching, and a Defender-disruption utility disguised as svchost.exe. Correlating the business lure, interpreter chain, privilege change, and security tampering created the response opportunity.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
3Threat / Category

Q2 observation · identity and machine trust

Valid tokens and API keys let attackers arrive already authenticated[15]Evidence dated Jul 23, 2026

Why it mattersLevelBlue’s Q2 briefing describes BEC at 45%, a spike in cloud intrusion, and software-supply-chain access through OAuth tokens, API keys, service accounts, and connected applications. The Klue compromise showed one trusted integration enabling automated Salesforce access across hundreds of organizations.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
4Threat / Category

Q2 observation · faster intrusion path

Long-dwell cases fell, but the intrusion path compressed[15]Evidence dated Jul 23, 2026

Why it mattersIn LevelBlue’s non-MDR Q2 population, cases lasting 31 days or more fell from 38% to 23%, while 3–10 day cases rose from 23% to 42%. Faster engagement helped, but attackers also reached objectives sooner through valid identity, supply-chain access, living-off-the-land tools, and AI-assisted activity.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
5Threat / Category

ValleyRAT · delivery diversification

ValleyRAT expanded from fake installers into malicious-email delivery[18]Evidence dated Jun 30, 2026

Why it mattersLevelBlue identified distinct fake-installer and email-driven paths targeting Chinese- and Japanese-speaking users. The malware’s evasion and anti-analysis behavior matter, but the source also warns that ValleyRAT use alone is insufficient to attribute every campaign to SilverFox.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
6Threat / Category

Identity phishing · device code flow

Device-code phishing became a commodity kit feature and peaked in May[17]Evidence dated Jun 9, 2026

Why it mattersLevelBlue observed EvilTokens, Kali365, Ghost Hub, Cyb3r, and Tycoon2FA operationalizing device-code flow abuse with protected PDFs, QR codes, legitimate redirectors, compromised senders, and multi-stage rewrite chains. Conditional Access restrictions and token-use monitoring are more useful than waiting for a password failure.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
7Threat / Category

The Gentlemen · multi-platform extortion

The Gentlemen scaled affiliate operations across exposed access, data theft, and virtualization impact[16]Evidence dated May 18, 2026

Why it mattersLevelBlue’s analysis describes valid credentials, VPN and firewall access, AnyDesk, SystemBC, reconnaissance, WinSCP exfiltration, security-tool tampering, and Windows, Linux, NAS, BSD, and ESXi encryption. Alleged actor-side material offered underground remains a separate unverified lead.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
8Threat / Category

Q1 observation · trust abuse

BEC increasingly became cloud data theft and extortion rather than an email-only fraud[14]Evidence dated May 5, 2026

Why it mattersLevelBlue’s first integrated briefing placed BEC at 39%, non-ransomware network intrusion at 30%, and ransomware at 26%. It observed OAuth-token and Microsoft Graph abuse against Exchange Online, OneDrive, and SharePoint, plus IT impersonation through Teams and help-desk pressure.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
9Threat / Category

Q1 observation · initial access

Phishing still led, while edge flaws and remote services supplied nearly one-third of entry paths[14]Evidence dated May 5, 2026

Why it mattersThe Q1 population placed phishing at 58%, exploited vulnerabilities at 20%, and external remote services such as RDP and VPN at 11%. The combined decision is to secure identity and communication workflows without easing pressure on internet-facing systems.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
10Threat / Category

Q4 observation · incident mix

BEC and ransomware remained the two leading incident types in Cybereason's Q4 cases[2]Evidence dated Feb 5, 2026

Why it mattersCybereason reports BEC at 42% and ransomware at 28% of the described Q4 incident population, while non-ransomware network intrusions rose to 25%. The figures should drive preparation, not be treated as global prevalence.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
11Threat / Category

Q4 observation · initial access

Phishing reached 52% of initial intrusion vectors[2]Evidence dated Feb 5, 2026

Why it mattersCalendar invitations, evolving lures, and credential capture helped phishing bypass ordinary email expectations. Defenders should monitor authentication and user behavior after delivery rather than relying on message filtering alone.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
12Threat / Category

Q4 observation · identity control failure

MFA adoption rose, but Cybereason observed bypass in 96% of MFA-present cases[2][6]First cited source Nov 3, 2025 · Latest cited source Feb 5, 2026

Why it mattersAiTM phishing, session-token interception, and varied social engineering can turn MFA into a speed bump. Phishing-resistant methods and session telemetry are required.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
13Threat / Category

Q4 observation · edge exposure

RDP, VPNs, and edge devices represented 18% of initial intrusion vectors[2][8][9]First cited source Oct 5, 2025 · Latest cited source Feb 5, 2026

Why it mattersCybereason's Q4 findings and CVE list show why external appliances need rapid remediation, historical log review, and identity investigation—not only present-state patch checks.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
14Threat / Category

Q4 observation · trusted-tool abuse

Remote-access-tool use for escalation rose from 3% of Q3 investigations to 60% in Q4[2][3]First cited source Feb 3, 2026 · Latest cited source Feb 5, 2026

Why it mattersLegitimate remote tools, search-result poisoning, and user installation can create a low-friction foothold that blends with administration. Remote-tool allowlisting and behavioral monitoring need to cover both installation and use.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
15Threat / Category

Q4 observation · dwell time

Forty-two percent of cases had 31 or more days of dwell time[2]Evidence dated Feb 5, 2026

Why it mattersCybereason notes that initial access brokers can create quiet latency between compromise and later use. Long log retention and retrospective hunting are needed even when active malicious behavior is absent.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
16Threat / Category

Malware delivery

A fake LINE installer used signed-looking packaging, PowerShell, and process injection to deploy ValleyRAT[3]Evidence dated Feb 3, 2026

Why it mattersCybereason observed an NSIS installer add Defender exclusions, establish persistence, and use PoolParty Variant 7 to inject into trusted Windows processes. The defensive lesson is to connect download provenance, certificate anomalies, exclusion changes, scheduled tasks, injection, and outbound C2.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
17Threat / Category

Annual IR observation

Identity-led intrusions increasingly hide inside trusted cloud services and normal business workflows[4]Evidence dated Jan 9, 2026

Why it mattersAcross the prior 12 months, Cybereason says phishing and social engineering accounted for 40% of its worldwide cases—more than double credential abuse or CVE exploitation. The source frames the forward-looking implications as predictions, not measured 2026 outcomes.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
18Threat / Category

Vulnerability exploitation

React2Shell moved from disclosure to practical exploitation within hours[12]Evidence dated Dec 5, 2025

Why it mattersCVE-2025-55182 exposed React Server Components to unauthenticated remote code execution. Cybereason validated a public proof of concept causing Node.js to spawn a shell and advised organizations with pre-patch internet exposure to investigate, not merely patch.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
19Threat / Category

Ransomware operation

The Gentlemen combine edge access, credential abuse, and multi-platform encryption[5]Evidence dated Nov 18, 2025

Why it mattersCybereason's technical report turns a new ransomware brand into a behavior-led watchlist for access, persistence, defense evasion, lateral movement, exfiltration, and encryption.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
20Threat / Category

Phishing-as-a-service

Tycoon 2FA operationalizes adversary-in-the-middle credential and session theft[6]Evidence dated Nov 3, 2025

Why it mattersThe kit demonstrates why valid passwords and completed MFA challenges can still produce attacker sessions. Domain, proxy, session, and post-authentication behavior must be correlated.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
21Threat / Category

Malware campaign

Tangerine Turkey shows a campaign maturing from scripts into a repeatable system[7]Evidence dated Oct 29, 2025

Why it mattersCybereason's campaign analysis documents a structured chain rather than a single payload. Defenders should connect delivery, execution, persistence, C2, and follow-on behaviors.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
22Threat / Category

Mass extortion

CL0P's Oracle EBS campaign ties exploited enterprise software to email extortion[9]Evidence dated Oct 5, 2025

Why it mattersCybereason assessed that activity from late July through early September involved unauthorized access, data enumeration and exfiltration before extortion emails. CVE-2025-61882 remediation must be paired with historical investigation and evidence preservation.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
23Threat / Category

Q3 observation · incident mix

BEC, ransomware, and insider activity dominated Cybereason's Q3 case mix[8]Evidence dated Oct 23, 2025

Why it mattersBEC represented 46% of the described cases, ransomware 39%, and insider threats rose from 2% in H1 to 7% in Q3. The insider increase included North Korean remote-worker schemes and employees taking proprietary data.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
24Threat / Category

Q3 observation · initial access

Exploited vulnerabilities more than doubled to 31% of initial intrusion vectors[8]Evidence dated Oct 23, 2025

Why it mattersPhishing remained first at 50%, but CVE exploitation rose from 15% in H1 to 31% in Q3. The observed list included SharePoint, CentreStack, Fortinet, and SonicWall weaknesses, making edge inventory and emergency change capacity material controls.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
25Threat / Category

Q3 observation · credential persistence

Akira reused SonicWall VPN credentials stolen before patching[8]Evidence dated Oct 23, 2025

Why it mattersCybereason observed Akira access through previously harvested credentials tied to CVE-2024-40766, including credentials migrated from older devices. Patching without resetting exposed VPN credentials left a viable path back in.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage
26Threat / Category

Q3 observation · evasion and dwell

Living-off-the-land use rose while 38% of cases still exceeded 31 days of dwell time[8]Evidence dated Oct 23, 2025

Why it mattersLOLBIN use appeared in 17% of Q3 investigations, up from 13% in H1. Cybereason separately found 38% of non-MDR cases had 31-plus-day dwell, reinforcing behavior-based detection and sufficient historical telemetry.What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert the retained public evidence into repeatable executive standards. Each lesson remains bounded to its cited sources.

Coverage periodSep 12, 2025Sep 11, 2026365 calendar days, inclusiveUpdated Sep 9, 2026
  1. 1

    Best Practice

    Govern machine identities and integrations[15]Evidence dated Jul 23, 2026

    Lesson Learned

    An OAuth token, API key, or service account can place an attacker past several controls at once.

    Minimum Operating Standard

    Inventory every connected application and machine identity; minimize scopes, rotate secrets, monitor API behavior, and maintain immediate revocation and downstream-notification procedures.

  2. 2

    Best Practice

    Restrict device-code flow[17]Evidence dated Jun 9, 2026

    Lesson Learned

    Legitimate authorization can be phished and converted into an attacker session.

    Minimum Operating Standard

    Disable device-code authentication where it is not required, require approved clients, and investigate anomalous grants and resulting token use.

  3. 3

    Best Practice

    Use phishing-resistant MFA[2][6]First cited source Nov 3, 2025 · Latest cited source Feb 5, 2026

    Lesson Learned

    Ordinary MFA can be defeated by AiTM and token theft.

    Minimum Operating Standard

    Prioritize FIDO2/WebAuthn for privileged and high-risk users and investigate risky session creation.

  4. 4

    Best Practice

    Govern remote tools[2][3]First cited source Feb 3, 2026 · Latest cited source Feb 5, 2026

    Lesson Learned

    Legitimate RATs can become persistence and escalation infrastructure.

    Minimum Operating Standard

    Maintain allowlists, owner and purpose, deployment controls, egress policy, and behavior-based detection.

  5. 5

    Best Practice

    Retain enough history[2]Evidence dated Feb 5, 2026

    Lesson Learned

    Access-broker latency can make a compromise look inactive for weeks.

    Minimum Operating Standard

    Set identity, VPN, endpoint, DNS, proxy, and cloud retention to support 31-plus-day reconstruction.

  6. 6

    Best Practice

    Patch and hunt together[2][9]First cited source Oct 5, 2025 · Latest cited source Feb 5, 2026

    Lesson Learned

    A fixed edge or enterprise application does not prove it was not already used.

    Minimum Operating Standard

    Every emergency remediation includes exploitation review, credential reset criteria, persistence hunting, and closure evidence.

  7. 7

    Best Practice

    Correlate the intrusion path[2][3][5][6]First cited source Nov 3, 2025 · Latest cited source Feb 5, 2026

    Lesson Learned

    Delivery, identity, tool use, persistence, exfiltration, and ransomware appear in different systems.

    Minimum Operating Standard

    Build detections and investigations that connect stages across email, identity, endpoint, network, cloud, and business data.

  8. 8

    Best Practice

    Implement the repeatable controls[10]Evidence dated Sep 23, 2025

    Lesson Learned

    Thousands of investigations point to a small set of recurring control needs.

    Minimum Operating Standard

    Track the eleven essential controls as measured capabilities with owners, tests, exceptions, and evidence.

Automation Transparency

AI Agent Run Status

AgentCybereason / LevelBlue Rolling Intelligence Card Publisher
StatusActive · rolling one-year automation
CadenceWeekly on Wednesday at midday ET
Previous run26 Jul 2026 · material revision · Run cybereason-publisher-activity-2026-07-26-chronology-backfill
Previous resultExtended the chronology through July 2026 by following Cybereason's TTP and threat-research lineage into LevelBlue's integrated IR and SpiderLabs corpus. Added Q1 and Q2 frontline findings plus The Gentlemen, device-code phishing, ValleyRAT, CrySome RAT, and macOS ClickFix activity; retained a clear comparability break between the pre- and post-integration populations.
What the previous run found
  • Enumerated the monitored Cybereason / LevelBlue collection pages and retained individual publications that control displayed conclusions.
  • Created 27 source-cited briefing points plus a publication chronology, victimology, actor, campaign, technology, access, and response sections.
  • Kept first-party observations, third-party claims, survey data, and product statements in their proper evidence classes.
  • Enabled subscriber alerts for material revisions and suppressed routine no-change email.
Next runWeekly on Wednesday at midday ET
Sources monitored
  • Cybereason All Posts — https://www.cybereason.com/blog/category/all
  • LevelBlue SpiderLabs Blog — https://www.levelblue.com/blogs/spiderlabs-blog
  • PETRA report database query constrained to the active rolling one-year publication window; duplicate matches are reconciled to the direct publisher source
Publication and alert policyCheck weekly on wednesday at midday et. Publish and alert only when a new Cybereason / LevelBlue publication materially changes an actor, campaign, technology, initial-access, victimology, impact, response, resilience, or executive conclusion. No-change checks are logged but do not email subscribers.

Related Intelligence and CARDS Records

Other IntelliOS Products

Publication History

Version Change Log

Versionv1Date26 Jul 2026ChangeCreated the Cybereason / LevelBlue rolling one-year publisher card with Research Framing, Timeline, BLUF, Executive Summary, top-ten findings, victimology, campaigns, actors, technologies, access vectors, operational practices, AI agent status, and citations.MonitoringWeekly on Wednesday at midday ET; material-change-only Page Alerts.
Versionv3Date26 Jul 2026ChangeExtended the chronology through July 2026 by following Cybereason's TTP and threat-research lineage into LevelBlue's integrated IR and SpiderLabs corpus. Added Q1 and Q2 frontline findings plus The Gentlemen, device-code phishing, ValleyRAT, CrySome RAT, and macOS ClickFix activity; retained a clear comparability break between the pre- and post-integration populations.MonitoringWeekly on Wednesday at midday ET; material-change-only Page Alerts.

Citations

Retained Sources and Claim Treatment

Source1PublisherCybereasonPublishedNot availablePublication / evidenceSource indexecosystem monitorWhy used / claim treatmentAuthoritative first-party corpus index monitored weekly. Checked through July 26, 2026; the newest qualifying public threat-research post listed is the February 5, 2026 Q4 briefing. Individual research posts control retained claims.SourceCybereason All Posts

https://www.cybereason.com/blog/category/all

Source2PublisherCybereasonPublished2026-02-05Publication / evidenceSource indexincident responseWhy used / claim treatmentFrontline IR and SOC findings for Q4 2025. Percentages describe Cybereason's stated case population and are not global prevalence.SourceCybereason TTP Briefing Q4 2025

https://www.cybereason.com/blog/ttp-briefing-q4-2025

Source3PublisherCybereasonPublished2026-02-03Publication / evidenceSource indexprimary researchWhy used / claim treatmentTechnical analysis of a documented infection chain; it does not establish campaign prevalence.SourceFake Installer: Ultimately, ValleyRAT Infection

https://www.cybereason.com/blog/fake-installer-valleyrat

Source4PublisherCybereasonPublished2026-01-09Publication / evidenceSource indexincident responseWhy used / claim treatmentForward-looking expert assessment. Predictions are separated from observed incident facts.SourceIdentity & Beyond: 2026 Incident Response Predictions

https://www.cybereason.com/blog/identity-beyond-2026-incident-response-predictions

Source5PublisherCybereasonPublished2025-11-18Publication / evidenceSource indexprimary researchWhy used / claim treatmentTechnical and operational research on a ransomware group; actor claims and external victim reporting remain qualified.SourceLicense to Encrypt: The Gentlemen Make Their Move

https://www.cybereason.com/blog/the-gentlemen-ransomware

Source6PublisherCybereasonPublished2025-11-03Publication / evidenceSource indexprimary researchWhy used / claim treatmentTechnical analysis of a phishing-as-a-service kit and MFA-bypass workflow.SourceTycoon 2FA Phishing Kit Analysis

https://www.cybereason.com/blog/tycoon-phishing-kit-analysis

Source7PublisherCybereasonPublished2025-10-29Publication / evidenceSource indexprimary researchWhy used / claim treatmentCampaign and malware-chain analysis bounded to Cybereason's reported observations.SourceFrom Scripts to Systems: Tangerine Turkey Operations

https://www.cybereason.com/blog/tangerine-turkey

Source8PublisherCybereasonPublished2025-10-23Publication / evidenceSource indexincident responseWhy used / claim treatmentFrontline IR and SOC findings for Q3 2025; percentages remain bounded to the described dataset.SourceCybereason TTP Briefing Q3 2025

https://www.cybereason.com/blog/ttp-briefing-q3-2025

Source9PublisherCybereasonPublished2025-10-05Publication / evidenceSource indexprimary researchWhy used / claim treatmentSource-qualified campaign guidance for CVE-2025-61882 and CL0P extortion activity.SourceAddressing CL0P Extortion Campaign Targeting Oracle EBS

https://www.cybereason.com/blog/oracle-ebs-extortion-cl0p

Source10PublisherCybereasonPublished2025-09-23Publication / evidenceSource indexincident responseWhy used / claim treatmentControl recommendations derived from Cybereason's stated incident-response experience; not every control maps to every organization.Source7000+ IRs Later: The 11 Essential Cybersecurity Controls

https://www.cybereason.com/blog/11-essential-controls

Source12PublisherCybereasonPublished2025-12-05Publication / evidenceSource indexprimary researchWhy used / claim treatmentTechnical analysis and controlled proof-of-concept validation for React2Shell. Early exploitation attribution remains source-qualified, and public exposure does not by itself establish compromise.SourceCVE-2025-55182: React2Shell Allows Unauthenticated Remote Code Execution

https://www.cybereason.com/blog/cve-2025-55182-rce-vulnerability

Source13PublisherLevelBlue SpiderLabsPublishedNot availablePublication / evidenceSource indexecosystem monitorWhy used / claim treatmentAuthoritative first-party continuation lane monitored weekly after Cybereason's integration into LevelBlue. Individual LevelBlue publications control retained findings.SourceLevelBlue SpiderLabs Blog

https://www.levelblue.com/blogs/spiderlabs-blog

Source14PublisherLevelBluePublished2026-05-05Publication / evidenceSource indexincident responseWhy used / claim treatmentFrontline Q1 incident-response findings from the broader LevelBlue ecosystem, which the source says integrates Cybereason, Stroz Friedberg, Trustwave, and Alert Logic capabilities. Historical comparisons are not made because the source population broadened.SourceLevelBlue TTP Briefing Q1 2026: Trust Abuse Exposes Weaknesses

https://www.levelblue.com/blogs/spiderlabs-blog/ttp-briefing-q1-2026

Source15PublisherLevelBluePublished2026-07-23Publication / evidenceSource indexincident responseWhy used / claim treatmentFrontline Q2 incident-response findings from LevelBlue's integrated teams. Percentages describe the stated case population; they are not global prevalence and are not directly trended against pre-integration Cybereason quarters.SourceLevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses

https://www.levelblue.com/blogs/spiderlabs-blog/ttp-briefing-q2-2026

Source16PublisherLevelBlue SpiderLabsPublished2026-05-18Publication / evidenceSource indexprimary researchWhy used / claim treatmentOperational ransomware research that visibly separates observed and public evidence from an unverified underground offer of alleged Gentlemen-related material.SourceA Closer Look at The Gentlemen's Alleged Leak

https://www.levelblue.com/blogs/spiderlabs-blog/a-closer-look-at-the-gentlemens-alleged-leak

Source17PublisherLevelBlue SpiderLabsPublished2026-06-09Publication / evidenceSource indexprimary researchWhy used / claim treatmentObserved phishing-kit and delivery research. Named kits and campaign volume describe LevelBlue's stated telemetry and do not establish compromise of a particular organization.SourceThe Device Code Phishing Tsunami: What We're Seeing in the Wild

https://www.levelblue.com/blogs/spiderlabs-blog/the-device-code-phishing-tsunami-what-were-seeing-in-the-wild

Source18PublisherLevelBlue SpiderLabsPublished2026-06-30Publication / evidenceSource indexprimary researchWhy used / claim treatmentTechnical analysis of two ValleyRAT delivery paths. ValleyRAT use alone is not treated as sufficient attribution to SilverFox.SourceAn Analysis of ValleyRAT Infection Campaigns from Fake Installers, Japanese Malicious Emails

https://www.levelblue.com/blogs/spiderlabs-blog/an-analysis-of-valleyrat-infection-campaigns-from-fake-installers-japanese-malicious-emails

Source19PublisherLevelBlue SpiderLabsPublished2026-07-06Publication / evidenceSource indexincident responseWhy used / claim treatmentCase-bounded MDR and threat-hunting analysis of one contained multi-stage infection chain; it demonstrates behavior and response opportunities rather than prevalence.SourceFrom Phishing to Persistence: A CrySome RAT Infection Chain Analysis

https://www.levelblue.com/blogs/spiderlabs-blog/from-phishing-to-persistence-a-crysome-rat-infection-chain-analysis

Source20PublisherLevelBlue SpiderLabsPublished2026-07-16Publication / evidenceSource indexprimary researchWhy used / claim treatmentTechnical campaign research spanning hundreds of compromised WordPress sites. Site compromise and payload delivery do not establish how many visitors executed the infostealer.SourceClickFix on macOS: Blockchain-Powered Infostealer Hidden Inside Compromised Websites

https://www.levelblue.com/blogs/spiderlabs-blog/clickfix-on-macos-blockchain-powered-infostealer-hidden-inside-compromised-websites