August 10, 2026 Emerging Threats Weekly
This week’s briefing covers:
00:00 – Intro
00:45 [CAMPAIGN] Voice Phishing Campaign by Newly Tracked Falcon Actor
Kroll has observed a growing extortion campaign, largely focused on the finance and technology sectors, that relies on voice phishing and text messages to trick employees into submitting credentials to phishing domains with the end goal of exfiltrating and extorting corporate and personal data.
04:30 [THREAT ACTOR] ExfilSquad Extortion Group Emerges
ExfilSquad is a newly emerged data-extortion operation that first appeared publicly in July 2026. By late July, the group had listed 15 alleged victims on its Tor-based leak site across multiple countries and sectors, but public reporting has not shown consistent evidence of ransomware encryption or disruptive malware deployment.
08:14 [THREAT ACTOR] DPRK Group Linked to High-Impact npm Package Compromises
The DPRK is targeting open-source software libraries used by the private sector. These open-source software libraries are used by companies for the development of applications. Amazon Threat Intelligence attributed attacks on several Node Package Manager to the same DPRK-linked threat actor (SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces). The impacted npm entities include but not limited to axios, debug, chalk, and typo-crypto libraries.
10:47 [RANSOMWARE] INC Exploits SonicWall SMA1000 Appliances for Root Access
Threat actors associated with INC Ransomware have been observed rapidly exploiting SonicWall SMA1000 remote-access appliances. The attack utilizes CVE-2026-15409 and CVE-2026-15410. The vulnerability exploitation has impacted organizations in the United States, Australia, United Arab Emirates, Colombia, and Switzerland.
13:02 [SUPPLY CHAIN] Shai-Hulud npm Campaign Steals Developer and Cloud Secrets
On August 4, Netskope researchers identified 28 malicious npm package versions published across four unrelated enterprise namespaces. The releases occurred in rapid, closely timed bursts and carried identical or functionally equivalent payloads associated with the Shai-Hulud campaign.
15:33 [CAMPAIGN] Midnight Blizzard Compromises Hotel Wi-Fi to Steal Microsoft 365 Sessions
A global campaign targeting hotel and conference Wi-Fi infrastructure to Storm-2945, assessed to be a sub-cluster of the Russian state-sponsored group Midnight Blizzard, also known as APT29. The campaign, designated CaptiveCrunch, manipulates legitimate public Wi-Fi services to steal Microsoft 365 credentials and deliver malware to travellers. Microsoft observed related activity from at least May 2026, with device-code and OAuth phishing operations beginning earlier in the year.
Dive deeper:
Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report
Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing
Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto
Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist
Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber
Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services
Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports
Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber
#krollcyber #threatintelligence #cyberthreats