| 1 | Threat / Category ClickFix · macOS credential theft Compromised WordPress sites turned fake verification into a cross-platform infostealer path[20]Evidence dated Jul 16, 2026 | Why it mattersLevelBlue identified hundreds of compromised sites serving a ClickFix overlay. On macOS, the victim pasted a Terminal command that retrieved in-memory code, stole Keychain, browser, and SSH material, and exfiltrated it; the campaign stored C2 location in a Polygon smart contract to resist ordinary DNS takedown. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 2 | Threat / Category MDR case · phishing to persistent RAT A logistics document chained native Windows tools into CrySome RAT persistence[19]Evidence dated Jul 6, 2026 | Why it mattersLevelBlue’s contained case began with a targeted rate-confirmation lure, then used living-off-the-land execution, a silent UAC bypass, in-memory AMSI patching, and a Defender-disruption utility disguised as svchost.exe. Correlating the business lure, interpreter chain, privilege change, and security tampering created the response opportunity. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 3 | Threat / Category Q2 observation · identity and machine trust Valid tokens and API keys let attackers arrive already authenticated[15]Evidence dated Jul 23, 2026 | Why it mattersLevelBlue’s Q2 briefing describes BEC at 45%, a spike in cloud intrusion, and software-supply-chain access through OAuth tokens, API keys, service accounts, and connected applications. The Klue compromise showed one trusted integration enabling automated Salesforce access across hundreds of organizations. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 4 | Threat / Category Q2 observation · faster intrusion path Long-dwell cases fell, but the intrusion path compressed[15]Evidence dated Jul 23, 2026 | Why it mattersIn LevelBlue’s non-MDR Q2 population, cases lasting 31 days or more fell from 38% to 23%, while 3–10 day cases rose from 23% to 42%. Faster engagement helped, but attackers also reached objectives sooner through valid identity, supply-chain access, living-off-the-land tools, and AI-assisted activity. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 5 | Threat / Category ValleyRAT · delivery diversification ValleyRAT expanded from fake installers into malicious-email delivery[18]Evidence dated Jun 30, 2026 | Why it mattersLevelBlue identified distinct fake-installer and email-driven paths targeting Chinese- and Japanese-speaking users. The malware’s evasion and anti-analysis behavior matter, but the source also warns that ValleyRAT use alone is insufficient to attribute every campaign to SilverFox. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 6 | Threat / Category Identity phishing · device code flow Device-code phishing became a commodity kit feature and peaked in May[17]Evidence dated Jun 9, 2026 | Why it mattersLevelBlue observed EvilTokens, Kali365, Ghost Hub, Cyb3r, and Tycoon2FA operationalizing device-code flow abuse with protected PDFs, QR codes, legitimate redirectors, compromised senders, and multi-stage rewrite chains. Conditional Access restrictions and token-use monitoring are more useful than waiting for a password failure. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 7 | Threat / Category The Gentlemen · multi-platform extortion The Gentlemen scaled affiliate operations across exposed access, data theft, and virtualization impact[16]Evidence dated May 18, 2026 | Why it mattersLevelBlue’s analysis describes valid credentials, VPN and firewall access, AnyDesk, SystemBC, reconnaissance, WinSCP exfiltration, security-tool tampering, and Windows, Linux, NAS, BSD, and ESXi encryption. Alleged actor-side material offered underground remains a separate unverified lead. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 8 | Threat / Category Q1 observation · trust abuse BEC increasingly became cloud data theft and extortion rather than an email-only fraud[14]Evidence dated May 5, 2026 | Why it mattersLevelBlue’s first integrated briefing placed BEC at 39%, non-ransomware network intrusion at 30%, and ransomware at 26%. It observed OAuth-token and Microsoft Graph abuse against Exchange Online, OneDrive, and SharePoint, plus IT impersonation through Teams and help-desk pressure. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 9 | Threat / Category Q1 observation · initial access Phishing still led, while edge flaws and remote services supplied nearly one-third of entry paths[14]Evidence dated May 5, 2026 | Why it mattersThe Q1 population placed phishing at 58%, exploited vulnerabilities at 20%, and external remote services such as RDP and VPN at 11%. The combined decision is to secure identity and communication workflows without easing pressure on internet-facing systems. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 10 | Threat / Category Q4 observation · incident mix BEC and ransomware remained the two leading incident types in Cybereason's Q4 cases[2]Evidence dated Feb 5, 2026 | Why it mattersCybereason reports BEC at 42% and ransomware at 28% of the described Q4 incident population, while non-ransomware network intrusions rose to 25%. The figures should drive preparation, not be treated as global prevalence. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 11 | Threat / Category Q4 observation · initial access Phishing reached 52% of initial intrusion vectors[2]Evidence dated Feb 5, 2026 | Why it mattersCalendar invitations, evolving lures, and credential capture helped phishing bypass ordinary email expectations. Defenders should monitor authentication and user behavior after delivery rather than relying on message filtering alone. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 12 | Threat / Category Q4 observation · identity control failure MFA adoption rose, but Cybereason observed bypass in 96% of MFA-present cases[2][6]First cited source Nov 3, 2025 · Latest cited source Feb 5, 2026 | Why it mattersAiTM phishing, session-token interception, and varied social engineering can turn MFA into a speed bump. Phishing-resistant methods and session telemetry are required. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 13 | Threat / Category Q4 observation · edge exposure RDP, VPNs, and edge devices represented 18% of initial intrusion vectors[2][8][9]First cited source Oct 5, 2025 · Latest cited source Feb 5, 2026 | Why it mattersCybereason's Q4 findings and CVE list show why external appliances need rapid remediation, historical log review, and identity investigation—not only present-state patch checks. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 14 | Threat / Category Q4 observation · trusted-tool abuse Remote-access-tool use for escalation rose from 3% of Q3 investigations to 60% in Q4[2][3]First cited source Feb 3, 2026 · Latest cited source Feb 5, 2026 | Why it mattersLegitimate remote tools, search-result poisoning, and user installation can create a low-friction foothold that blends with administration. Remote-tool allowlisting and behavioral monitoring need to cover both installation and use. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 15 | Threat / Category Q4 observation · dwell time Forty-two percent of cases had 31 or more days of dwell time[2]Evidence dated Feb 5, 2026 | Why it mattersCybereason notes that initial access brokers can create quiet latency between compromise and later use. Long log retention and retrospective hunting are needed even when active malicious behavior is absent. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 16 | Threat / Category Malware delivery A fake LINE installer used signed-looking packaging, PowerShell, and process injection to deploy ValleyRAT[3]Evidence dated Feb 3, 2026 | Why it mattersCybereason observed an NSIS installer add Defender exclusions, establish persistence, and use PoolParty Variant 7 to inject into trusted Windows processes. The defensive lesson is to connect download provenance, certificate anomalies, exclusion changes, scheduled tasks, injection, and outbound C2. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 17 | Threat / Category Annual IR observation Identity-led intrusions increasingly hide inside trusted cloud services and normal business workflows[4]Evidence dated Jan 9, 2026 | Why it mattersAcross the prior 12 months, Cybereason says phishing and social engineering accounted for 40% of its worldwide cases—more than double credential abuse or CVE exploitation. The source frames the forward-looking implications as predictions, not measured 2026 outcomes. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 18 | Threat / Category Vulnerability exploitation React2Shell moved from disclosure to practical exploitation within hours[12]Evidence dated Dec 5, 2025 | Why it mattersCVE-2025-55182 exposed React Server Components to unauthenticated remote code execution. Cybereason validated a public proof of concept causing Node.js to spawn a shell and advised organizations with pre-patch internet exposure to investigate, not merely patch. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 19 | Threat / Category Ransomware operation The Gentlemen combine edge access, credential abuse, and multi-platform encryption[5]Evidence dated Nov 18, 2025 | Why it mattersCybereason's technical report turns a new ransomware brand into a behavior-led watchlist for access, persistence, defense evasion, lateral movement, exfiltration, and encryption. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 20 | Threat / Category Phishing-as-a-service Tycoon 2FA operationalizes adversary-in-the-middle credential and session theft[6]Evidence dated Nov 3, 2025 | Why it mattersThe kit demonstrates why valid passwords and completed MFA challenges can still produce attacker sessions. Domain, proxy, session, and post-authentication behavior must be correlated. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 21 | Threat / Category Malware campaign Tangerine Turkey shows a campaign maturing from scripts into a repeatable system[7]Evidence dated Oct 29, 2025 | Why it mattersCybereason's campaign analysis documents a structured chain rather than a single payload. Defenders should connect delivery, execution, persistence, C2, and follow-on behaviors. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 22 | Threat / Category Mass extortion CL0P's Oracle EBS campaign ties exploited enterprise software to email extortion[9]Evidence dated Oct 5, 2025 | Why it mattersCybereason assessed that activity from late July through early September involved unauthorized access, data enumeration and exfiltration before extortion emails. CVE-2025-61882 remediation must be paired with historical investigation and evidence preservation. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 23 | Threat / Category Q3 observation · incident mix BEC, ransomware, and insider activity dominated Cybereason's Q3 case mix[8]Evidence dated Oct 23, 2025 | Why it mattersBEC represented 46% of the described cases, ransomware 39%, and insider threats rose from 2% in H1 to 7% in Q3. The insider increase included North Korean remote-worker schemes and employees taking proprietary data. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 24 | Threat / Category Q3 observation · initial access Exploited vulnerabilities more than doubled to 31% of initial intrusion vectors[8]Evidence dated Oct 23, 2025 | Why it mattersPhishing remained first at 50%, but CVE exploitation rose from 15% in H1 to 31% in Q3. The observed list included SharePoint, CentreStack, Fortinet, and SonicWall weaknesses, making edge inventory and emergency change capacity material controls. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 25 | Threat / Category Q3 observation · credential persistence Akira reused SonicWall VPN credentials stolen before patching[8]Evidence dated Oct 23, 2025 | Why it mattersCybereason observed Akira access through previously harvested credentials tied to CVE-2024-40766, including credentials migrated from older devices. Patching without resetting exposed VPN credentials left a viable path back in. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |
| 26 | Threat / Category Q3 observation · evasion and dwell Living-off-the-land use rose while 38% of cases still exceeded 31 days of dwell time[8]Evidence dated Oct 23, 2025 | Why it mattersLOLBIN use appeared in 17% of Q3 investigations, up from 13% in H1. Cybereason separately found 38% of non-MDR cases had 31-plus-day dwell, reinforcing behavior-based detection and sufficient historical telemetry. | What to monitorValidate whether the behaviors, technologies, identities, or dependencies described by Cybereason / LevelBlue exist locally; escalate only when local evidence changes exposure or response decisions. | IntelliOS coverage |