Cyber Threat Brief — July 31 2026

⚠️ This report is AI-generated. Always validate findings.

1. SonicWall Credential Stuffing Campaign — 30+ Orgs Compromised

TL;DR: Active credential stuffing campaign since July 25 has compromised 92 user accounts across 30+ organizations via SonicWall VPN/firewall portals. Five DigitalOcean IPs driving automated credential validation at scale.

What’s New:

  • Huntress SOC disclosed July 28; campaign ongoing through at least July 27
  • 92 unique accounts compromised: 26 on July 25, 34 on July 26, 32 on July 27
  • No post-compromise hands-on-keyboard activity observed yet — credential validation phase
  • Same accounts targeted in prior incident May 22, 2026 — indicates credential reuse from earlier breaches
  • Pattern consistent with SonicWall SSLVPN compromise spikes in October 2025 and February 2026

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
157.245.88[.]153IPv4T1110.004Firewall/VPN auth logsBlock
162.243.31[.]111IPv4T1110.004Firewall/VPN auth logsBlock
167.71.150[.]1IPv4T1110.004Firewall/VPN auth logsBlock
209.97.151[.]148IPv4T1110.004Firewall/VPN auth logsBlock
64.227.15[.]20IPv4T1110.004Firewall/VPN auth logsBlock
DigitalOcean ASNASNT1583.003Network logsHunt
HTTP/1.0 + Chrome UAAnomalyT1071.001WAF/proxy logsHunt

Detection

SourceRuleGap
Splunk ESCUAuthentication - Brute Force Access Behavior DetectedNo SonicWall-specific correlation for multi-org stuffing campaigns
ElasticCredential Stuffing - Multiple Auth Failures Followed by SuccessMissing DigitalOcean ASN enrichment
Sigmawin_security_susp_failed_logons_single_source.ymlNot applicable to SonicWall VPN — need appliance-specific rule

Sources: Huntress Threat Advisory


2. TELESHIM APT Campaign — East Asia Targeting Middle East Governments

TL;DR: Undisclosed East Asia-linked actor deploying three novel malware families (TELESHIM, MIXEDKEY, BINDCLOAK) against Middle East government entities using Telegram Bot API for C2, with heavy code obfuscation and environmental keying.

What’s New:

  • Zscaler ThreatLabz disclosure July 27 with full technical analysis
  • TELESHIM abuses Telegram Bot API for C2 — polls via HTTPS mimicking legitimate browser traffic
  • Initial access via ISO file sideloading legitimate ASUSTek RegSchdTask.exe with malicious AsTaskSched.dll
  • Environmental keying: decryption key derived from machine volume serial number, preventing sandbox analysis
  • Heavy obfuscation: control flow flattening (CFF), mixed boolean arithmetic (MBA), opaque predicates

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
5c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6dSHA-256 (TELESHIM)T1059EDR/AVBlock
cert.hypersnet[.]comDomain (C2)T1071.001DNS/proxyBlock
AsTaskSched.dllFilename (sideload)T1574.002Sysmon EID 7Hunt
RegSchdTask.exe (ASUSTek)LOLBin proxyT1036.005Process creationHunt
Telegram Bot API pollingC2 PatternT1102.002HTTPS/TLS logsHunt for api.telegram.org from non-user processes

Detection

SourceRuleGap
Splunk ESCUNoneNo detection for Telegram Bot API C2 abuse or ASUSTek DLL sideloading
ElasticSuspicious DLL Loaded via Side-Loading (generic)Does not cover ASUSTek-specific sideloading path
Sigmaproc_creation_win_sideload_asustek.yml — NoneNeed rule for RegSchdTask.exe loading unsigned DLLs

Sources: Zscaler ThreatLabz Part 1, The Hacker News


3. Sapphire Sleet npm Supply Chain Attribution — debug/chalk/axios

TL;DR: Amazon Threat Intelligence attributed the 2025-2026 npm supply chain compromises of debug, chalk, and axios (combined 1B+ weekly downloads) to North Korea’s Sapphire Sleet (BlueNoroff). Social engineering of maintainers, not typosquatting.

What’s New:

  • Amazon published attribution July 29-30 linking four package compromises to single DPRK actor
  • September 2025 debug/chalk hijack affected ~10% of cloud environments within 2 hours
  • March 2026 axios compromise (100M+ weekly downloads) via same actor
  • Methodology: phishing via npm-lookalike domain to steal maintainer credentials, then publishing poisoned updates from trusted accounts
  • Wallet-draining scripts embedded in 18+ packages; post-install hooks for automatic execution
  • typo-crypto (March 2025) served as testing ground before escalation

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Post-install hooks in npm packagesExecution techniqueT1195.001CI/CD pipeline logsAudit npm install scripts
npm-lookalike phishing domainsSocial engineeringT1566.002Email/DNS logsHunt
Cryptocurrency wallet-draining functionsPayloadT1496EDR/process monitoringHunt for crypto wallet API calls from Node.js
debug versions 4.3.5-4.3.6 (malicious)Package versionT1195.002SBOM/dependency scanAudit
chalk versions 5.3.1-5.3.2 (malicious)Package versionT1195.002SBOM/dependency scanAudit

Detection

SourceRuleGap
Splunk ESCUNoneNo detection for malicious npm post-install hook execution
ElasticNoneNo supply chain package integrity monitoring
SigmaNoneNeed rule for suspicious npm postinstall script spawning shells or network connections

Sources: BleepingComputer, The Hacker News


Status Updates

  • CVE-2026-20316 (Cisco FMC): Federal CISA KEV deadline TOMORROW August 1. Zero-day exploitation via hardcoded credential ongoing. Original brief.
  • CVE-2026-6875 (ServiceNow): Active exploitation ongoing since July 18. Two sandbox-escape gadget chains confirmed. Fortune 500 and critical infrastructure victims. Still NOT on CISA KEV despite confirmed mass exploitation. Original brief.
  • CVE-2026-12569 (PTC Windchill/Cl0p): Cl0p extortion campaign ongoing via support@cryptohox[.]com. JSP webshells and flst.txt recon active. Original brief.
  • LegacyHive-Windows-LPE: UNPATCHED zero-day. ACROS Security released free 0patch micropatches July 20. Microsoft still has not assigned CVE or released fix. Original brief.