Trellix Advanced Research Center

The
Cyber​threat report
April 2026

The
Cyber​threat report

April 2026

Insights Gleaned from a Global Network of Experts, Sensors, Telemetry, and Intelligence

October 1, 2025 – March 31, 2026


Presented by Trellix Advanced Research Center Logo

The CyberThreat Report

Authored by the Trellix Advanced Research Center, this report (1) highlights insights, intelligence, and guidance gleaned from multiple sources of critical data on cybersecurity threats and (2) develops expert, rational, and reasonable interpretations of this data to inform and enable best practices in cyber defense. This edition focuses on data and insights captured primarily between October 1, 2025, and March 31, 2026.

This report covers:

  1. A look into the evolving APT landscape

  2. Command-and-control (C2) methodologies transformation

  3. Ransomware: Structural volatility and AI-assisted extortion

  4. Vulnerability exploitation: Chaining new flaws and legacy debt

  5. Cybercriminal use of AI-generated malware

  6. Supply chain attacks

Over the past six months, we observed an increase in detections and advanced threats alongside the evolution and propagation of  AI-generated malware, the exploitation of vulnerabilities in the software supply chain, and an increased focus on developed economies and critical infrastructure.
Read the Executive Summary for a high-level overview and key takeaways.
Read the Executive Summary

Preface

Over the past six months, the threat landscape has been defined less by specific campaigns or actors and more by the accelerating convergence of tradecraft, access models, and operational intent. Nation-state groups, ransomware operators, access brokers, and hacktivist ecosystems increasingly borrow from the same playbook: Abusing legitimate tools, moving faster after initial compromise, and blending espionage, disruption, and financially motivated activity in ways that made early attribution more difficult for defenders. What stood out in this period was the volume of activity and the efficiency with which adversaries adapted proven techniques to new objectives. They frequently relied on trusted administrative utilities, staged infrastructure, and low-friction intrusion methods that reduced cost while preserving impact.

A key enabler in this evolution has been the growing use of artificial intelligence across the cybercriminal ecosystem. AI is not replacing established intrusion methods, but is making them more scalable, convincing, and accessible. Threat actors are using AI to improve the effectiveness of phishing and social engineering lures, accelerate malware development, refine impersonation content, and support faster reconnaissance and targeting. In practice, this means more polished deception, shorter development cycles, and a lower barrier to entry for less sophisticated operators. At the same time, more mature adversaries use the same capabilities to enhance speed and precision. The result is a threat environment where innovation is increasingly iterative rather than revolutionary, but no less dangerous for defenders.

Against this backdrop, geopolitical instability continued to shape cyber activity, especially as the reporting period closed with heightened concern around the conflict involving Iran. This reinforced a pattern we have observed repeatedly: cyber operations intensify when regional tensions rise, and the distinction between strategic signaling, opportunistic disruption, and intelligence collection becomes harder to separate in real time. 

For defenders, this environment demands resilience over reaction. Effective security programs must look beyond isolated indicators and instead focus on behavior, context, and operational coordination across intelligence, security operations, and incident response. In a landscape where adversaries are becoming faster, more adaptive, and increasingly enabled by AI, organizations will be best positioned when they can absorb disruption, detect subtle shifts in behavior, and respond with clarity before activity escalates into material impact.

Portrait of John Fokker, Head of Threat Intelligence and Principal Engineer, Trellix Advanced Research Center
John Fokker
VP, Threat Intelligence Strategy, Trellix

Geopolitical events impacting the cyber domain

Cyber operations in a geopolitical crisis: Iran, China, and Russia

The geopolitical instability of 2025 has escalated into direct state-level conflict in early 2026, marking a clear inflection point in the evolution of modern warfare. Cyber operations are no longer isolated or episodic activities; instead, they are increasingly being deployed in lockstep with physical military strikes, functioning as an integrated component of broader conflict dynamics.

A major inflection point occurred in late February 2026, when the United States and Israel launched coordinated military strikes against Iran under a large-scale operation targeting nuclear facilities, military infrastructure, and senior leadership. The strikes triggered immediate retaliation from Iran, including missile and drone attacks against U.S. and allied assets across the Middle East.

Cyber operations are now in lockstep with physical military strikes, functioning as an integrated component of broader conflict dynamics.

This escalation—building on earlier Israel–Iran hostilities in 2025 and longstanding tensions surrounding Iran’s nuclear program—further reinforced cyberspace as a parallel operational domain used for both pre-conflict shaping and post-strike retaliation.

Between October 2025 and March 2026, there was a 77% increase in globally observed Iranian cyber activity, with operations closely aligned to geopolitical developments and military events.

Trellix telemetry further reinforces the alignment between geopolitical tensions and cyber targeting priorities, with the highest concentration of activity observed across government and critical infrastructure sectors. This aligns with observed pre-positioning behavior, in which access to government networks can provide insight into diplomatic posture and military planning, consistent with preparations for potential disruption or leverage in response to geopolitical developments.

Post-strike surge: Iranian cyber activity in early 2026

Based on Trellix telemetry data, the first quarter of 2026 saw a clear escalation in detections following the U.S. and Israeli strikes on Iran in February 2026. 

The period begins with an important inflection point in January 2026. Despite a nationwide internet blackout in Iran, telemetry data shows a 14% increase in cyber threat activity. This suggests that cyber operations likely continued through government-approved or allowlisted channels, enabling sustained activity both to support internal stability and to maintain external targeting efforts.

However, this momentum shifted in February 2026 with a temporary reduction in activity. This decline likely reflects a strategic pre-strike operational pause, aligned with final-stage diplomatic efforts and tactical coordination ahead of kinetic engagements. During this period, cyber operations were likely refined and recalibrated to better align with broader military objectives in anticipation of escalation.

Following the strikes on February 28, Iranian cyber operations rapidly intensified as part of a broader retaliatory response, culminating in a 37% surge in March 2026. Activity reached its highest level since October 2025, surpassing the January peak associated with the December 2025 Iran–Israel escalation. This pattern signals a clear transition in the conflict, characterized by a significant increase in both the scale and intensity of cyber operations following kinetic events.

At the onset of the Iran–Israel–U.S. war, Iranian cyber operations shifted to coordinated, high-intensity attacks tightly integrated with the opening phase of kinetic hostilities.

Global Iranian Cyber Operations (Oct 2025 – Mar 2026)

Source: Trellix ATLAS

Strategic opportunism: The surge in Chinese cyber activity

Between October 2025 and March 2026, Chinese global cyber threat detections skyrocketed to over 1.4 million—a staggering 88% increase. This surge is not merely a reflection of escalating geopolitical friction; it highlights a sophisticated "gray zone" strategy designed to exploit global instability for long-term statecraft.

While Iranian cyber operations during this period were largely reactive—characterized by sudden, disruption-focused bursts aligned with kinetic strikes—China’s approach remains a more deliberate instrument of long-term strategy. Operating within the "gray zone," cyber activity is carefully calibrated to achieve strategic objectives without provoking a direct military or political response.

This approach is consistent with China’s long-standing emphasis on long-term strategic advantage rather than short-term disruption. Rather than engaging in overt or destructive actions, Chinese cyber threat actors tend to prioritize persistence, intelligence collection, and pre-positioning within high-value networks.

Viewed through this lens, the surge in Chinese cyber activity—both globally and in targeting U.S. organizations—should not be interpreted as a random escalation. Specifically, our data shows global detections from Chinese cyber threat actors began rising sharply in December 2025 and peaked in January 2026, aligning with heightened regional tensions and Iran’s internet blackout period. While U.S.-focused activity represents a smaller share of overall volume, it exhibited a pronounced and sustained increase. Notably, direct targeting of U.S. assets nearly doubled by March 2026 following the February kinetic events associated with the Israel–U.S.–Iran conflict.

This pattern suggests opportunistic exploitation. Historically, Chinese APT groups increase their operational tempo during periods of geopolitical crisis—not to directly engage in the conflict, but to take advantage of reduced attention, heightened operational noise, and stretched defensive resources. As security teams focus on immediate, high-visibility threats, such as Iranian retaliatory activity, the likelihood of detecting more subtle, persistent intrusions decreases.

As the world’s attention was fixed on the potential for a broader regional war, Chinese cyber threat actors exploited the chaos to expand their access and deepen their intelligence pools. The result is a parallel layer of cyber activity: less visible than Iranian strikes, but strategically more significant, unfolding in the shadows of overt global conflict.

Chinese APT groups ramp up operations during geopolitical crises, exploiting increased noise and overstretched defenses to strike while attention is diverted.

Monthly Detection Breakdown (2025–2026)

Source: Trellix ATLAS

The cyber-kinetic nexus: Russian strategic operations

Global Russian cyber operations from October 2025 to March 2026 totaled over 1.2 million detections, representing a 70% increase. A substantial share of this activity, more than 47%, was directed at government entities.

Most importantly, this upward trajectory in cyber activity closely aligns with the progression of Russian military operations over the same period. In February 2026, Russia executed one of its largest energy-sector strike campaigns of the year, targeting critical infrastructure to degrade power generation capacity and apply systemic pressure. During February, we observed a more than 25% increase in Russian cyber threat activity compared to January 2026.

The escalation became even more pronounced in March 2026, when Russia shifted from intermittent strike patterns to a sustained, high-frequency aerial-assault model. This involved nearly 1,000 drones and missiles launched in coordinated waves across multiple regions. Trellix ARC assessed that the concurrent escalation of Israel–U.S.–Iran conflict likely established favorable strategic conditions for Russian exploitation. While not directly linked to the conflict, the increased global cyber “noise,” divided defensive attention, and stretched security resources may have provided Russia with greater operational latitude to scale activity and pursue opportunistic gains.

Overall, our data suggests a strong operational alignment between cyber and kinetic domains. Russian cyber activity appears to be functioning in parallel with military operations, supporting broader objectives through intelligence collection, targeting enablement, and disruption of critical systems.

Global Russian Cyber Operations (Oct 2025 – Mar 2026)

Source: Trellix ATLAS

Key findings

A look into the evolving APT landscape

  • U.S. & Türkiye are most targeted: The concentration( 59.4%) of global APT detections in just two countries (United States 31.7%, Türkiye 27.7%) suggests coordinated, strategic targeting aligned with geopolitical interests.

  • Preference toward critical infrastructure: The APT detections demonstrate clear sectoral preferences, with telecom and transportation and shipping sectors bearing the highest threat burden. 

  • APT group dominance: The top three threat actors, Gamaredon Group (9.6%), Mustang Panda (9.4%), and Lazarus (7.9%), are responsible for over a quarter of all recorded detections.

  • Living-off-the-land usage: APT groups demonstrate continuous use of living-off-the-land techniques, with Cmd (48.9%) and PowerShell (49.6%) leading tool usage.

Command-and-control (C2) methodologies transformation

  • Decentralized and blockchain-based C2: Attackers increasingly use EtherHiding on Binance and Ethereum to host immutable instructions. This architecture allows operators to update malicious pointers without re-infecting victims, making infrastructure nearly impossible to sinkhole.

  • Blending and blinding defense evasion: Tools like DCRat and Remcos blind security monitoring by patching AMSI and ETW in memory. Attackers also use Living-off-the-Land C2 to mask data exfiltration through trusted APIs like Microsoft Graph and Discord.

  • AI-driven polymorphism and new protocols: C2 frameworks use AI to rewrite loader code every 15 minutes and mimic legitimate traffic metadata. Tools have also adopted HTTP/3 and gRPC to encrypt metadata and blend into modern microservice architectures.

  • User-mediated execution via ClickFix: Attackers bypass sandboxes by tricking users into manually running malicious PowerShell commands via Win+R under the guise of browser errors. Because the action is performed by the user, security tools often misidentify it as authorized activity.

Ransomware: new dominance and emerging threats

  • Widespread operational risk: Ransomware detections across industrials (1334 posts), Government/Administration (116 posts), and healthcare (287 posts) indicate the potential for broad operational disruption. 

  • Extortion workflow automation: Leak Bazaar’s ML-powered monetization platform with ransomware negotiation support lowers the technical bar for new entrants.

  • Consumer Services as a supply chain risk: Holding steady at 17.8% of attacks across all identified sectors, consumer services remains a critical vector for supply chain attacks that can cascade to numerous downstream clients.

  • North America bears the greatest ransomware burden: Combined, the US and Canada received  2,084 leak posts (60.4% of all enriched records), likely driven by the concentration of high-value enterprise targets and the prevalence of cyber insurance that may incentivize ransom payments.

Complex attack chains and increased exploitation of vulnerabilities

  • Rapid compression of exploit timelines: The mean time-to-exploit dropped from 23.2 days in 2025 to 1.3 days in Q1 2026. Approximately 69.7% of exploited CVEs are now zero-days, occurring on or before the date of disclosure.

  • Attacks on modern frameworks and infrastructure: React Server Components were targeted via CVE-2025-55182, becoming the #4 most detected CVE globally. Microsoft SharePoint and Office also faced rapid exploitation, with APT28 weaponizing new flaws within 24 hours.

  • Persistence of legacy technical debt: Sophisticated actors like SideWinder continue to exploit eight-year-old vulnerabilities in Microsoft Office. Telemetry also confirms ongoing exploitation of decade-old flaws such as Log4j, ProxyShell, and Bash Shellshock.

Cybercriminal use of AI

  • The "vibeware" doctrine of mass production: Threat actors like APT36 have begun using AI to mass-produce diverse "mediocre" implants in niche programming languages (e.g., Nim, Zig, Crystal) to overwhelm detection engines through sheer volume and variety.

  • Emergence of AI-integrated malware families: New malware, PromptFlux and PromptSteal, call LLM APIs at runtime to dynamically generate unique malicious behavior, breaking the traditional assumption that malicious code must be pre-encoded in a binary.

  • Collapse of technical barriers for low-skilled actors: Commercial AI enables unskilled actors to achieve nation-state-level operational scale. One instance includes a single actor compromising 600 devices globally via automated AI reconnaissance.

  • Commoditization of deepfake-driven fraud: Deepfake and voice synthesis tools transitioned into mass-market commodities, with underground services offering high-quality video for as little as $100 to bypass financial KYC controls and MFA.

Protecting Sensitive Data in the Age of AI

Assess Your Risk

Supply chain attacks

  • Takedown-resistant C2 infrastructure: Threat actors have integrated immutable blockchains such as Solana and ICP to host C2 channels. These sophisticated tactics, including "phantom dependencies" and invisible Unicode, allow malicious traffic to blend with legitimate Web3 activity.

  • Cascading security tool compromises: A single Trivy scanner breach enabled TeamPCP to propagate attacks across the ecosystem. By using "tag poisoning" on trusted tools, attackers gained elevated access to secrets and built environments for KICS and LiteLLM.

  • High-impact maintainer account takeovers: The Axios compromise demonstrated the massive blast radius of a single maintainer account takeover, impacting a library with 100 million weekly downloads. These attacks bypass source code auditing by using hidden dependencies to deploy remote access trojans.

Methodology overview

Experts from our Trellix Advanced Research Center gather the statistics, trends, and insights comprising this report from a wide range of global sources, both captive and open. The aggregated data is fed into our Insights and ATLAS platforms. Leveraging AI, machine learning, automation, and human acuity via our research and SecondSight hunting, the team cycles through an intensive, integrated, and iterative set of processes – normalizing the data, analyzing the information, and developing insights meaningful to cybersecurity leaders and SecOps teams on the front lines of cybersecurity worldwide. For a more detailed description of our methodology, please see the end of this report.

Report analysis, insights, and data

 

  • U.S. & Türkiye are most targeted: The concentration( 59.4%) of global APT detections in just two countries (United States 31.7%, Türkiye 27.7%) suggests coordinated, strategic targeting aligned with geopolitical interests.
  • Preference toward critical infrastructure: The APT detections demonstrate clear sectoral preferences, with telecom and transportation and shipping sectors bearing the highest threat burden.
  • APT group dominance: The top three threat actors, Gamaredon Group (9.6%), Mustang Panda (9.4%), and Lazarus (7.9%), are responsible for over a quarter of all recorded detections.
  • Living-off-the-land usage: APT groups demonstrate continuous use of living-off-the-land techniques, with Cmd (48.9%) and PowerShell (49.6%) leading tool usage.

A look into the evolving APT landscape

Geographical distribution of APT activity

Advanced persistent threat (APT) detections spanned 98 countries during the last quarter of 2025 and the first quarter of 2026, with the top 10 nations accounting for nearly 500K detections, 89.0% of the total global APT volume. The geographic distribution reveals a pronounced concentration in North America and Türkiye, with secondary clusters in Southeast Asia, Western Europe, and South Asia.

The United States leads with most APT detections by absolute volume (31.7%), most likely driven by its status as the world’s largest economy and the concentration of high-value technology, defense, and government infrastructure. Türkiye has the next highest number of detections (27.7%), potentially reflecting the country’s strategic position at the intersection of European, Middle Eastern, and Central Asia.

Indonesia emerges as the third country with the most APT detection (5.6%). It is almost entirely attributable to a single, highly focused group, APT40, which accounted for 94.3% of Indonesian detections, using a variety of toolkits, including Cobalt Strike, Gh0st RAT, and China Chopper, consistent with government espionage objectives in the Indo-Pacific region.

Top 10 affected countries

Source: Trellix ATLAS

Q4 2025 vs. Q1 2026 Geographic distribution of detections

Source: Trellix ATLAS

The United States has the highest number of detections with 31.7%, likely driven by its status as the world’s largest economy and the concentration of high-value technology, defense, and government infrastructure

Türkiye has the second-highest detections with 27.7%, potentially reflecting the country’s strategic position at the intersection of European, Middle Eastern, and Central Asia

Indonesia received the third most APT detections almost entirely due to Chinese state-sponsored actors’ interest in government espionage objectives in the Indo-Pacific region

Analysis of the top three targeted countries

United States (US) Türkiye (TR) Indonesia (ID)

The United States accounts for the largest share of APT detections with 31.7% of the total global volume.

This concentration of activity is driven by the country's position as the world's largest economy and the high concentration of technology, defense, and government infrastructure.

Türkiye has the next highest number of detections with 27.7%, with the biggest increase in activity between Q4 of 2025 and Q1 of 2026.

This potentially reflects Türkiye's strategic geopolitical position at the intersection of European, Middle Eastern, and Central Asian threat vectors.

Indonesia received the third most detections, making up 5.6% of the total global APT volume.

This high ranking is almost entirely due to Chinese state-sponsored actors, which are particularly interested in government espionage objectives in the Indo-Pacific region.

Top five sectors observed

Technology: 3.35%
Telecom: 0.70%
Business Services: 0.06%
Education: 0.03%
Government: 0.02%

The US threat landscape is characterized by a strong focus on technology and telecommunications infrastructure, which account for the vast majority of sector-attributed detections.

Transportation & Shipping: 9.5%
Government: 9.2%
Telecom: 0.9%
Finance: 0.2%

Detections in Türkiye are heavily concentrated on critical sectors, with Transportation & Shipping and Government accounting for the highest attributed volumes.

Transportation & Shipping: 0.4% of total Indonesian detections
Telecom: 72 0.2%

The lack of contextual information makes it difficult to draw meaningful conclusions.

Top five APT actors observed

Gamaredon Group: 25.8%
Lazarus: 8.7%
APT29: 7.2%
Kimsuky: 5.0%
Mustang Panda: 4.3%
MuddyWater: 3.4%

While APT activity spans a diverse range of threat actors, the Russian-linked Gamaredon Group remains the primary driver, accounting for 25.8% of U.S. detections. Other highly active groups include Lazarus, APT29, Kimsuky, and Mustang Panda.

MuddyWater appears in the top 5 most active groups, underscoring the recent Iranian crisis.

Lazarus: 9.7%
Kimsuky: 6.6%
Mustang Panda: 6.4%
MuddyWater: 5.3%
APT29: 4.7%

The top five APT groups targeting Türkiye are led by North Korean-linked Lazarus (9.7% of detections) and Kimsuky (6.6%), followed by Mustang Panda, MuddyWater, and APT29.

APT40: 94.3%
Mustang Panda: 5.0%
UNC4698: 4.6%
CL-STA-1009: 0.5%
Bitter APT: 0.04%

The threat profile for Indonesia is unique, as nearly all APT activity is attributable to Chinese state-sponsored threat actors, APT40 and Mustang Panda.

Top five tools observed

Cmd: 56.9%
PowerShell: 52.7%
WMIC: 31.2%
Taskkill: 30.7%
Net: 25.2%

Cmd: 49.1%
PowerShell: 48.0%
Schtasks.exe: 28.7%
Rundll32: 23.6%
Net: 20.4%

PowerShell: 95.0%
Cobalt Strike: 94.4%
Gh0st RAT: 94.3%
China Chopper: 94.3%
BADFLICK: 94.3%

Top five MITRE ATT&CK techniques observed

File and Directory Discovery (T1083): 99.2%
Exfiltration Over C2 Channel (T1041): 98.9%
Drive-by Compromise (T1189): 94.5%
Disable or Modify Tools (T1562.001): 94.5%
Domains (T1583.001): 94.5%

System Information Discovery (T1082): 78.1%
Web Protocols (T1071.001): 76.8%
Deobfuscate/Decode Files or Information (T1140): 71.5%
Ingress Tool Transfer (T1105): 68.1%
File and Directory Discovery (T1083): 65.9%

Web Protocols (T1071.001): 83.9%
Deobfuscate/Decode Files or Information (T1140): 73.6%
Ingress Tool Transfer (T1105): 73.5%
File and Directory Discovery (T1083): 71.6%
Exfiltration Over C2 Channel (T1041): 70.9%

Sectoral impact

The technology and critical infrastructure sectors remain the preferred targets for APT groups, according to our analysis.

Telecom leads with 47.0% of sector-attributed volume, reflecting nation-state actors’ strategic interest in communications infrastructure for signals intelligence collection, subscriber data harvesting, and potential disruption capabilities.

The transportation & shipping sector’s 21.4% share is heavily influenced by a surge during the first quarter of 2026, which made this sector one of the main targets of APT actors. Government sector detections (20.6%) demonstrate consistent, sustained attention for all six months.

Top 10 affected sectors

Source: Trellix ATLAS

47

At 47%, telecommunications continues to be the most impacted industry, highlighting its prominence in adversary campaigns.

Threat actor analysis

The APT threat landscape is concentrated, with the top three threat actors, Gamaredon Group, Mustang Panda, and Lazarus, responsible for over a quarter of all recorded detections, totaling 26.6% of the overall volume. The Russian-linked Gamaredon Group is the leading actor overall (9.6%), closely followed by the Chinese-linked Mustang Panda (9.4%) and the North Korean-linked Lazarus (7.9%). These groups showcase the persistent and high-volume operations originating from established nation-state threat centers.

Analysis of the quarter-over-quarter (QoQ) trends reveals a significant shift in the operational dominance of these groups between Q4 2025 and Q1 2026. The Gamaredon Group, which was the most active actor in Q4 2025 with 13.67% of detections, saw its volume nearly halved, dropping to 6.90% and falling to the third rank in Q1 2026. Conversely, Mustang Panda maintained its high tempo, holding steady at approximately 9.3% of the detection volume in both quarters and rising to the number one position in Q1 2026. Lazarus also demonstrated sustained activity, rising to the second spot in Q1 2026 with 7.90% of detections. Finally, MuddyWater, an Iranian-linked threat actor, saw its activity levels surge; detection volume doubled from 2.08% in Q4 2025 to 5.03% in Q1 2026, a spike presumably attributed to the 2026 conflict.

North Korean-affiliated groups (Lazarus and Kimsukey) demonstrate consistent activity levels.

Chinese-affiliated groups (APT36, Mustang Panda, APT40) suggest sustained Chinese APT operations with Mustang Panda primarily focused on Myanmar and Türkiye.

Russian-affiliated groups (APT29, APT28, and MuddyWater) maintain consistent activity levels, with the Gamaredon Group as the most active APT group (9.6% of total APT activity), with their activity primarily focused on the U.S. (84%), potentially gathering NATO intelligence.

Top 10 threat actors responsible for detections

Source: Trellix ATLAS

Q4 2025 and Q1 2026 top threat actors by detections

Source: Trellix ATLAS

Analysis of the most aggressive APT groups

Gamaredon Group Mustang Panda Lazarus

Gamaredon Group recorded the highest volume of activity, accounting for 9.6% of total detections.

Gamaredon Group is a highly active, Russian state-sponsored cyber espionage group that primarily focuses on political and military espionage targeting Ukraine. However, it has increasingly expanded its operations to surveil NATO-aligned entities and Western allies.

Mustang Panda follows closely behind the top spot, making up 9.4% of the total recorded events.

Mustang Panda is a China-nexus cyber threat actor that focuses on global espionage campaigns. They are well known for relying heavily on custom variants of the PlugX remote access trojan (RAT) and highly tailored phishing lures.

Lazarus generated 7.9% detections, making them the third most frequently observed group.

Lazarus is a notorious, versatile, and highly prolific North Korean state-sponsored threat group. Lazarus conducts both traditional cyber espionage and massive, financially motivated attacks designed to fund the heavily sanctioned North Korean state.

Top five country detections observed

United States (US): 84.0%
Canada (CA): 6.1%
Türkiye (TR): 5.9%
Germany (DE): 1.9%
Spain (ES): 0.3%

The recorded footprint of the Gamaredon Group was predominantly centered in the United States, accounting for 84% of their activity, while Canada accounted for an additional 6.1% of the total. Gamaredon targets these North American nations primarily to gather intelligence on NATO-aligned geopolitical strategies and Western military aid intended for Ukraine.

Myanmar (MM): 19.9%
Türkiye (TR): 19.0%
United States (US): 14.9%
Cameroon (CM): 6.4%
India (IN): 4.6%

Mustang Panda primarily focused its operations in Myanmar and Türkiye (39% of the total volume) to conduct state-sponsored espionage aligned with Chinese strategic interests, gathering intelligence on Southeast Asian regional dynamics, government policies, and broader Middle Eastern and Western Asian military capabilities.

United States (US): 35.0%
Türkiye (TR): 33.9%
Germany (DE): 6.4%
India (IN): 4.0%
UAE (AE): 3.6%

Activity from the Lazarus group is heavily concentrated in Türkiye and the United States, which together represent 68.9% of its total volume. This pattern of focused operations indicates that their strategic targeting is closely aligned with North Korea's with the geopolitical priorities and economic goals.

Top five sector detections observed

Telecom: 3,428 (6.2%)
Government: 327 (0.6%)
Transportation & Shipping: 196 (0.4%)
Technology: 141 (0.3%)
Finance: 26 (0.05%)

Telecom: 2,095 (3.9%)
Transportation & Shipping: 1,256 (2.4%)
Government: 645 (1.2%)
Media & Communications: 564 (1.1%)
Technology: 335 (0.6%)

Government: 1,669 (3.7%)
Transportation & Shipping: 1,017 (2.3%)
Technology: 535 (1.2%)
Telecom: 249 (0.6%)
Industrial: 42 (0.09%)

Top five tool detections observed

Cmd: 52,786 (95.5%)
Taskkill: 50,903 (92.1%)
UltraVNC: 50,703 (91.8%)
WMIC: 50,382 (91.2%)

Gamaredon Group strongly relies on LOLBins during its operations.

PlugX: 35,156 (66.3%)
Cmd: 25,670 (48.4%)
Schtasks.exe: 16,822 (31.7%)
PowerShell: 10,545 (19.9%)
Rundll32: 8,959 (16.9%)

The group's signature tool PlugX dominates usage, indicating standardized operational procedures.

Cmd: 26,650 (59.4%)
PowerShell: 18,996 (42.4%)
Rundll32: 13,741 (30.6%)
Mimikatz: 12,326 (27.5%)
Net: 9,636 (21.5%)

Lazarus tends to use a mix of custom and publicly available tools, along with LOLBins, to fulfill its operation goals.

Top five MITRE ATT&CK techniques observed

Malicious File (T1204.002): 54,054 (97.8%)
File and Directory Discovery (T1083): 54,008 (97.7%)
Deobfuscate/Decode Files or Information (T1140): 53,985 (97.7%)
Ingress Tool Transfer (T1105): 53,839 (97.4%)
Obfuscated Files or Information (T1027): 53,487 (96.8%)

DLL Side-Loading (T1574.002): 50,115 (94.5%)
Deobfuscate/Decode Files or Information (T1140): 44,311 (83.6%)
Malicious File (T1204.002): 40,304 (76.0%)
File and Directory Discovery (T1083): 36,550 (68.9%)
Registry Run Keys / Startup Folder (T1547.001): 33,764 (63.7%)

System Information Discovery (T1082): 36,739 (81.9%)
Exfiltration Over C2 Channel (T1041): 36,647 (81.7%)
Malicious File (T1204.002): 35,445 (79.1%)
Web Protocols (T1071.001): 33,890 (75.6%)
Ingress Tool Transfer (T1105): 33,221 (74.1%)

Tools and techniques

APT actors in this period demonstrate a clear preference for living-off-the-land (LotL) techniques, with native Windows utilities (PowerShell, Cmd, Schtasks.exe, WMIC, Net, Rundll32, Reg) dominating the toolset. This approach minimizes the footprint of custom malware, leverages trusted system processes to evade detection, and exploits the inherent difficulty of distinguishing malicious from legitimate administrative activity.

The MITRE ATT&CK technique landscape is dominated by C2 communication, reconnaissance, and delivery techniques — consistent with the post-exploitation and persistence phases of APT operations. The near-universal prevalence of Web Protocols (T1071.001) at 78.2% reflects the ubiquity of HTTP/HTTPS-based C2 channels, which blend into normal enterprise web traffic.

Top 10 APT tools

Source: Trellix ATLAS

Top 10 MITRE techniques

Source: Trellix ATLAS

Use of MITRE techniques remained relatively stable, with System Information Discovery, Ingress Tool Transfer, and Web Protocols consistently ranking in the top positions. This stability indicates mature operational procedures across APT groups.

Top 10 tool types

Source: Trellix ATLAS

Top tools used

Backdoor Infostealer Downloader

20.1%

The analysis of APT toolsets highlights a focus on sophisticated operational tactics, with backdoors being the most frequently used tool. This high frequency suggests that APT actors value establishing a long-term presence over rapid exploitation, a strategy that supports their broader intelligence-gathering goals for over extended periods.

12.4%

Information stealers are the second-most-common tool type, highlighting their role in systematic data harvesting by persistent threat actors.

9.5%

Downloaders were the third most used tool, highlighting its use to deploy further and more sophisticated malware to achieve threat groups' goals.

Top 10 tool names

Source: Trellix ATLAS

Implications

The assessment delineates a mature APT landscape characterized by standardized toolsets, persistent innovation, and a calculated alignment with strategic intelligence mandates. Mitigating these advanced threats requires deploying multi-tiered defensive frameworks capable of addressing both specialized malware and the exploitation of legitimate system processes.

Developing a mature security posture requires a strategic transition from legacy signature-based alerting to behavioral and contextual detection methodologies. This mandate requires the institutionalization of comprehensive activity baselining, rigorous least-privilege protocols, and the logical segmentation of administrative domains. Continuous proactive hunting for the exploitation of native system utilities—specifically PowerShell, WMI, and PsExec—complemented by the stringent auditing of privileged accounts, remains paramount. Ultimately, synchronized collaboration across SOC, IT, and threat intelligence functions is vital to identify nuanced anomalies, such as atypical command-line execution or lateral movement leveraging legitimate credentials.

Command-and-control (C2) methodologies transformation

 

  • Decentralized and blockchain-based C2: Attackers increasingly use EtherHiding on Binance and Ethereum to host immutable instructions. This architecture allows operators to update malicious pointers without re-infecting victims, making infrastructure nearly impossible to sinkhole.

  • Blending and blinding defense evasion: Tools like DCRat and Remcos blind security monitoring by patching AMSI and ETW in memory. Attackers also use Living-off-the-Land C2 to mask data exfiltration through trusted APIs like Microsoft Graph and Discord.

  • AI-driven polymorphism and new protocols: C2 frameworks use AI to rewrite loader code every 15 minutes and mimic legitimate traffic metadata. Tools have also adopted HTTP/3 and gRPC to encrypt metadata and blend into modern microservice architectures.

  • User-mediated execution via ClickFix: Attackers bypass sandboxes by tricking users into manually running malicious PowerShell commands via Win+R under the guise of browser errors. Because the action is performed by the user, security tools often misidentify it as authorized activity.

Overview

Over the last six months and as part of a larger trend (over the previous 12 months), the C2 Intelligence Matrix: 2026 provides a comprehensive technical analysis of the radical transformation in command-and-control (C2) methodologies. It serves as a strategic roadmap for security operations centers (SOCs) and threat hunters to navigate a landscape where traditional perimeter defenses are increasingly bypassed by decentralized, "post-malware" strategies. By synthesizing data from real-world telemetry and the evolution of adversary tradecraft, it bridges the gap between theoretical vulnerability and active exploitation in the 2026 threat environment.

Key Takeaway

In 2026, the primary threat vector shifted from "hiding" traffic to "blending" and "blinding," as attackers leverage legitimate blockchain infrastructure and AI-driven polymorphism to render traditional signature-based and behavioral detections obsolete.

  • ClickFix: Social engineering-driven execution

C2 Intelligence Matrix: 2026

Between October 2025 and March 2026, Trellix observed an evolution of C2 techniques marked by a shift from centralized, dedicated infrastructure to decentralized, "post-malware" and blockchain-based strategies.

This matrix categorizes the heavy hitters during this period, separating specialized Red Team frameworks from the aggressive "commodity" tools often favored by initial access brokers (IABs).

APT tool evolution between October 2025 and March 2026

Framework / tool Previous technique (pre-2023) 2026 evolution (transition to new technique) Key architectural shift

Lumma C2

Simple HTTP C2; static domain polling.

EtherHiding & ClickFix:
Uses Blockchain RPC nodes as Living-off-the-Land C2 infrastructure.

On-chain resilience:
Infrastructure cannot be sinkholed without disrupting the blockchain.

XWorm (v7.2)

Disk-based .NET execution; simple persistence.

In-memory Gzip reflection:
Reflectively loads modular DLLs into Msbuild.exe via process hollowing.

BYOI (bring your own interpreter):
Executes full post-ex suites without touching the disk or local binaries.

Remcos RAT

Local log storage (Keylogs/Screenshots); plaintext C2 config.

Real-time stream exfiltration:
Direct live webcam/audio streaming via memory-only DLLs; zero local artifacts.

Volatile exfiltration:
Moves from "Store-and-Forward" to "Live Surveillance," leaving no forensic trail on disk.

AsyncRAT

Basic asynchronous beacons; hardcoded IPs/Ports.

Cloud-tunneling (Cloudflare/TryCloudflare):
Masks C2 traffic through legitimate WebDAV and tunnel providers.

Traffic blending:
C2 communication is indistinguishable from standard enterprise SaaS traffic.

DCRat

Basic plugin support; focused on simple credential theft.

Active AMSI/ETW patching:
Dynamically patches AmsiScanBuffer and Event Tracing for Windows in memory.

Defensive blindness:
Actively silences the host's telemetry before executing the secondary payload.

Deep dive: The 2026 technical tradecraft

Below is a detailed list of the groundbreaking techniques that emerged and became standard during the October 2025 to March 2026 timeframe.

1. EtherHiding (Blockchain-as-a-C2)

Emerging as one of the most resilient techniques during this time period, EtherHiding weaponizes Web3 technology. Instead of a server, attackers use the Binance Smart Chain (BSC) or Ethereum to host their C2 instructions.

  • Decentralized resolver: Malware uses eth_call (read-only requests) to query a smart contract. The contract returns a pointer or an encrypted payload. Because it's a read-only request, it leaves no transaction history on the chain.

  • The three-tier contract architecture:

    • Level 1 (anchor): A static contract address hardcoded in the malware.

    • Level 2 (router): A switchboard contract that points to the actual payload.

    • Level 3 (payload): A payload that holds the encrypted command or the next stage of the malware.

    • If a payload is flagged, the attacker simply updates the pointer in Level 2 to a new Level 3 contract, keeping the infection alive without re-infecting the victim.

2. AI-driven polymorphism & adaptive beaconing

C2 frameworks have integrated generative AI to automate evasion.

  • AI-generated traffic profiles: Rather than simple "jitter" (random timing), AI models analyze a network's normal traffic (e.g., a specific company's Slack or Teams usage) and generate C2 beacons that perfectly mimic the specific organization’s metadata. 

  • Code metamorphism: AI "predator swarms" rewrite their own loader code every 15 minutes to ensure that file hashes never repeat, rendering static signature-based detection useless.

3. Living-off-the-land C2 (LOTL C2)

Starting in 2022 and maturing by 2025, attackers moved away from buying domains and instead began "borrowing" the reputation of legitimate cloud services.

  • TryCloudflare & Ngrok tunneling: C2 traffic is tunneled through *.trycloudflare.com or *.ngrok.io. Since these are trusted developer tools, many firewalls allow the traffic by default.

  • C2 via SaaS APIs: Malware now uses Microsoft Graph API, Discord Webhooks, or Telegram API to exfiltrate data. To a defender, the traffic appears to be an employee uploading a file to their corporate OneDrive or sending a chat message.

4. Security blinding (AMSI & ETW patching)

A significant shift between the 2024 and 2026 variants (such as Remcos v7.x and DCRat) is the proactive "blinding" of the operating system's built-in defenses.

  • AMSI (antimalware scan Interface) patching: The malware overwrites the AmsiScanBuffer function in memory with a "return clean" instruction. This tells security monitoring tools that everything it's seeing is safe, even if it's a known malicious script.

  • ETW (event tracing for Windows) silencing: By patching EtwEventWrite, the malware prevents Windows from logging its activities. This effectively silences EDR tools that rely on system events to trigger alerts.

5. Protocol evolution (HTTP/3 (QUIC) & gRPC):

As network sensors improved at spotting TLS-encrypted TCP traffic, C2s like AdaptixC2 (2025) adopted newer protocols.

  • QUIC (HTTP/3): Because QUIC is UDP(user datagram protocol)-based and encrypts connection metadata (like the SNI), it is significantly harder for legacy firewalls to inspect. It also allows for faster "zero-latency" check-ins.

  • gRPC tunneling: Using Google's high-performance RPC (remote procedure call) framework allows C2 traffic to blend into the modern microservice architecture common in enterprise data centers.

6. Social engineering-driven execution (ClickFix)

In 2025, the delivery mechanism changed to bypass automated sandboxes.

  • User-mediated execution: Instead of a self-running file, the malware shows a fake "browser error" or "CAPTCHA." It asks the user to copy a "fix" (malicious PowerShell) and run it manually via Win+R. Because the user performs the action, automated security tools often treat it as authorized administrator activity.

Shift from Perimeter Defense to Telemetry Integrity

  • Assume EDR Blindness: Since C2s now patch AMSI and ETW in memory, prioritize tools that utilize hardware-assisted monitoring to detect "security blinding" at the kernel level.

  • Audit Web3/RPC Access: Block or strictly monitor workstation access to Blockchain RPC nodes (e.g., Infura), as these are the new decentralized points for stealthy C2.

  • Verify the "Human-in-the-Loop": Combat "ClickFix" tactics by enforcing strict policies against user-initiated system commands (Win+R) and copy-pasting code into terminal prompts.

  • Enforce API-Level Egress: Treat legitimate SaaS traffic (Microsoft Graph, Discord) as high-risk by implementing granular filters to prevent C2 "blending" within enterprise cloud services.

  • Monitor Protocol Anomalies: Update network sensors to inspect HTTP/3 (QUIC) and gRPC, as attackers increasingly use these UDP-based protocols to bypass legacy TCP-focused firewalls.

  • Prioritize Identity over Signatures: In an era of AI-driven polymorphism where file hashes change every 15 minutes, focus your budget on behavioral identity baselining and zero-trust access.

Ransomware landscape pivot: Structural volatility and the rise of AI-assisted extortion

 

  • Widespread operational risk: Ransomware detections across industrials (1334 posts), Government/Administration (116 posts), and healthcare (287 posts) indicate the potential for broad operational disruption. 

  • Extortion workflow automation: Leak Bazaar’s ML-powered monetization platform with ransomware negotiation support lowers the technical bar for new entrants.

  • Consumer Services as a supply chain risk: Holding steady at 17.8% of attacks across all identified sectors, consumer services remains a critical vector for supply chain attacks that can cascade to numerous downstream clients.

  • North America bears the greatest ransomware burden: Combined, the US and Canada received  2,084 leak posts (60.4% of all enriched records), likely driven by the concentration of high-value enterprise targets and the prevalence of cyber insurance that may incentivize ransom payments.

The period from October 2025 through March 2026 represents a structurally elevated ransomware threat environment. During this time, the Trellix Advanced Research Center observed 4,801 victim posts, and a steady average of 800 monthly posts from legitimate ransomware operators. Additionally, Trellix telemetry recorded over 2M ransomware-related detections across 76 unique campaigns throughout this window.

The ecosystem underwent significant structural reshuffling. Previously dominant groups, including RansomHub, LockBit3, BlackBasta, and Cactus, effectively vanished, likely due to law enforcement operations and internal disruptions.  It didn’t take long for a wave of new entrants, including Qilin, Sinobi, Nightspire, and LockBit5, to fill the void.

Simultaneously, the threat landscape grew more sophisticated as nation-state and criminal activity converged, evidenced by the Lazarus Group partnering with Medusa RaaS. Additionally, this period also saw AI-assisted malware development and the emergence of ClickFix, which is displacing traditional phishing as the dominant initial access vector.

Key findings

From October 2025 to March 30, 2026, the Trellix Advanced Research Center observed:

  • Significant ransomware double-peak activity: Ransomware-related detections peaked at just over 1M during December–January; following a February lull, March 2026 saw a sharp 36.6% rebound.

  • Primary execution and post-exploitation tools remain consistent: PowerShell appeared in 54.6% of detections and Cobalt Strike in 33.9%, confirming their continued centrality in ransomware kill chains.

  • Near-universal evasion and impact techniques: Detections reflected standard pre-encryption kill-chain behavior at scale with Data Encrypted for Impact (T1486) appeared in 97.4% of detections, while Service Stop (T1489) and Disable or Modify Tools (T1562.001) appeared in 70.5% and 48.5%, respectively. 

  • Widespread operational risk: Ransomware detections across industrials (1334 posts), Government/Administration (116 posts), and healthcare (287 posts) indicate the potential for broad operational disruption. 

  • Nation-state healthcare threats: The Lazarus-Medusa partnership targeting U.S. organizations poses a threat to critical patient safety infrastructure.

  • Extortion workflow automation: Leak Bazaar’s ML-powered monetization platform with ransomware negotiation support lowers the technical bar for new entrants.

Ransomware group activity

Between October 2025 and March 2026, the ransomware landscape underwent a structural reset. Once dominant groups, including RansomHub, LockBit3, BlackBasta, and Cactus, disappeared, most likely due to law enforcement pressure and internal turmoil. However, this void was short-lived; a wave of new groups—including Sinobi, Nightspire, and LockBit5—filled the gap, illustrating the resilience and adaptability of the cybercriminal underground.

Top ransomware groups by victim posts, 0apt excluded (October 2025 - March 2026)

Source: Trellix ATLAS

New ransomware groups emerge

The emergence of several high-output groups that transitioned from non-existent to major market players almost overnight. Groups include Sinobi with a 4.4% share of the total ransomware activity, followed closely by Devman2 at 4.1% and The Gentleman at 2.8%. 

This rapid scaling is potentially symptomatic of a broader trend: the continued lowering of the Ransomware-as-a-Service (RaaS) barrier to entry. During the Q4 2025 - Q1 2026 period, over 15 groups posted 10 or more victims despite having no meaningful prior-period presence. This influx is fueled by leaked builder tools and commoditized infrastructure, allowing fledgling threat actors to launch high-impact campaigns with minimal technical overhead.

Groups dramatically escalating threat activity

In the wake of leading ransomware groups collapsing, several newer groups significantly increased their ransomware activity. After a slow start following its debut on October 28, 2025, Nightspare nearly doubled its output compared to the mid-2025 period, surging to become the third-most-active group by March 2026. Similarly, Everest also nearly doubled its output between the Q2/Q3 2025 and the Q4 2025/Q1 2026 period.

The LockBit evolution 

Following the decline of LockBit 3, which accounted for a mere 0.58% of ransomware activity between April to September 2025, the group's newer iteration, LockBit5, saw its activity volume surge nearly fivefold during the Q4 2025 to Q1 2026 period. Although this relaunch gained significant momentum in December 2025 and peaked in January 2026, its activity began to decline toward the end of the first quarter.

Qilin’s continued dominance

While other segments of the landscape experienced volatility, Qilin remains the ransomware leader. The organization expanded its operational footprint, growing from 13.45% of total ransomware activity in mid-2025 to 17.2% during the Q4 2025 to Q1 2026 period.

Affected sectors

The industrial sector's continued dominance remains a primary focus of ransomware activity, accounting for 37.9% of all attacks across all identified sectors between Q4 2025 and Q1 2026. This sustained targeting suggests that threat actors continue to prioritize industrial organizations because of their heavy reliance on operational technology (OT) and their low tolerance for downtime. These factors create a high-pressure environment in which ransom payments are more likely, and the cost of recovery is disproportionately high. 

  • Consumer Services as a supply chain risk: Holding steady at 17.8% of attacks across all identified sectors, consumer services—including MSPs, staffing firms, and facilities—remains a critical vector for supply chain attacks that can cascade to numerous downstream clients.

  • Financial services targeting: Although financial sector attacks dropped slightly to 7.7% of all identified sectors, the industry continues to face sophisticated threats from groups like Clop and Akira, who leverage high-value data for double-extortion tactics.

  • Healthcare high-stakes vulnerability: Representing 8.1% of total ransomware activity, healthcare remains a persistent, high-risk target, where operational disruptions directly endanger patient safety and critical care delivery.

  • Technology sector's appeal: Attacks on the technology sector (9.7%) increase slightly over the last two quarters, indicating that the industry remains an attractive target for groups seeking to exfiltrate valuable intellectual property.

  • Government sector persistence: Accounting for 116 posts, government entities continue to be targeted despite limited ransom-payment capacity, suggesting that data exfiltration and geopolitical disruption serve as the primary motivators for these campaigns.

Top five most targeted sectors (October 2025 - March 2026)

Source: Trellix ATLAS

Geographic distribution

The United States remains the dominant ransomware target by a substantial margin, accounting for 1,912 victim posts (55.4%). That is nearly double the combined total of the next four countries, including Canada ( 5.0%), United Kingdom (3.5%), Germany (3.2%), and France (2.3%).  

From a detection standpoint Trellix telemetry revealed that the U.S. received the most ransomware detections (27.66% of total detections), followed by Spain (16.56%) South Korea ( 10.66%), India (8.91%), and Türkiye (8.44%). Additionally,  ATLAS Campaign intelligence identified the U.S. (16 campaigns), UK (9), Germany (7), Brazil (6), and Canada (6) as the most campaign-targeted nations..

Regional patterns

  • North America bears the greatest ransomware burden: Combined, the US and Canada received 2,084 posts (60.4% of all enriched records). This is likely driven by the concentration of high-value enterprise targets and the prevalence of cyber insurance, which may incentivize ransom payments.

  • Western Europe remains heavily targeted: The UK, Germany, France, Italy, and Spain collectively account for ~14.2% of victim posts, with Germany and the UK also appearing prominently in campaign attribution data.

  • APAC targeting is growing: South Korea (10.66% of detections), India (8.91% detections), and Malaysia (32 victim posts) indicate expanding ransomware operator interest in Asia-Pacific markets.


  • Latin America is an active campaign theater: Brazil appeared in six documented campaigns. That is the highest LATAM representation, reflecting growing interest among ransomware operators in the region’s large enterprise base.

Top five most targeted countries (October 2025 - March 2026)

Source: Trellix ATLAS

Top 15 Most Targeted Countries (October 2025 – March 2026)

Country Count of records

1

United States of America

1,911

2

Canada

172

3

United Kingdom

121

4

Germany

113

5

France

81

6

Italy

58

7

Spain

56

8

India

53

9

Australia

52

10

Brazil

46

11

Japan

41

12

United Arab Emirates

40

13

Malaysia

32

14

Georgia

31

15

Thailand

31

Other

609

Top 10 most targeted countries by detections (October 2025 - March 2026)

Source: Trellix ATLAS

Top 10 most targeted countries by reported campaigns (October 2025 - March 2026)

Source: Trellix ATLAS

TTPs detected in ransomware activity

Key attack patterns

  • ClickFix is the new initial access vector: Browser-based social engineering and malicious copy-and-paste that bypasses email security control (T1204.003) emerged as the dominant new initial access vector.  It replaces traditional phishing attachments across Interlock, Qilin, Velvet Tempest, and LeakNet campaigns. Underground forum activity on exploit.in confirms active development of ClickFix payloads for RMM staging, with actors sharing technical implementation guidance (mshta + JavaScript on the domain).

  • Primary technical initial access method: Exploit public-facing application appearing in 32% of campaigns. SonicWall VPN (Akira), enterprise firewall zero-days (Interlock), Oracle E-Business Suite CVE-2025-61882 (Clop), and GoAnywhere MFT CVE-2025-10035 (Storm-1175) are the most exploited entry points.

  • Credential harvesting is near-universal in post-exploitation: Mimikatz appeared in 11 campaigns, and DCSync was documented in Warlock’s attack chain. Valid Accounts (T1078) appeared in 32% of campaigns, confirming that stolen credentials, not just exploits, are a primary persistence mechanism.

  • Double extortion is standard practice: Financial Theft (T1657) appeared in 24% of campaigns, characterized by the use of cloud-syncing tools like  RCLONE and Restic (INC Ransom) to steal data before encryption begins. The launch of Leak Bazaar, an ML-powered data monetization platform, signals a trend toward a corporate-style extortion workflow.

  • Legitimate tool weaponization evasion strategy: Cloudflare Tunnel (8 campaigns), Velociraptor DFIR tool (Warlock, Storm-2603), SimpleHelp/ConnectWise/AnyDesk RMM tools, and Restic backup software were all systematically abused to live-off-the-land, blend ransomware activity into normal IT operations, and evade detection.

Top 20 Tools by Detection Count (October 2025 – March 2026)

Tool Detections % of total detections

1

PowerShell

1,453,901

54.6%

2

Cmd

1,018,784

38.3%

3

Cobalt Strike

901,815

33.9%

4

curl

891,004

33.5%

5

esxcli

780,403

29.3%

6

JavaScript

770,143

28.9%

7

echo

745,684

28.0%

8

ESXiArgs Ransomware

737,923

27.7%

9

mkdir

728,905

27.4%

10

tar

712,780

26.8%

11

PsExec

668,044

25.1%

12

Net

634,744

23.8%

13

ipconfig

617,616

23.2%

14

UPX

583,336

21.9%

15

Reg

558,462

21.0%

16

ping

557,195

20.9%

17

msiexec

552,001

20.7%

18

whoami

538,133

20.2%

19

python.exe

533,433

20.0%

20

Mimikatz

496,894

18.7%

Top MITRE ATT&CK techniques

Technique ATT&CK ID Detections % of total

Data Encrypted for Impact

T1486

2,592,102

97.4%

File and Directory Discovery

T1083

2,332,782

87.6%

System Information Discovery

T1082

2,290,656

86.0%

File Deletion

T1070.004

1,923,749

72.3%

Obfuscated Files or Information

T1027

1,912,957

71.9%

Service Stop

T1489

1,877,036

70.5%

Exploit Public-Facing Application

T1190

1,671,445

62.8%

PowerShell

T1059.001

1,512,613

56.8%

Process Discovery

T1057

1,483,537

55.7%

Ingress Tool Transfer

T1105

1,450,112

54.5%

Security Software Discovery

T1518.001

1,368,481

51.4%

Windows Command Shell

T1059.003

1,348,849

50.7%

Web Protocols

T1071.001

1,346,011

50.6%

DLL Side-Loading

T1574.002

1,298,665

48.8%

Disable or Modify Tools

T1562.001

1,289,026

48.4%

Strategic implications and recommendations

The ransomware landscape from October 2025 to March 2026 demands a fundamental reassessment of defensive priorities. Dominant legacy groups collapsed and were rapidly replaced by new, more sophisticated actors. This shift coincides with the convergence of nation-state and criminal interests.  Additionally,  attackers utilize AI tools and systematically weaponize legitimate IT management tools.  Combined, these factors indicate that traditional signature-based defenses and perimeter-focused strategies are increasingly insufficient. Organizations must assume ransomware operators have already adapted to common defensive measures and are actively developing novel evasion techniques.

The shift from traditional phishing to ClickFix (browser-based social engineering that bypasses email security controls) as a primary initial access vector requires immediate investment in user awareness training specifically targeting browser-based social engineering, alongside endpoint controls that prevent unauthorized script execution from browser contexts.

Key defensive priorities

  • Implement zero-trust controls for RMM tools: Attackers systematically abused AnyDesk (16 campaigns), ConnectWise Control (10), and SimpleHelp to maintain persistent access and enable lateral movement. Establish an approved RMM tool inventory, block unauthorized endpoint remote access software, and require MFA for all remote access sessions.

  • Prioritize VPN appliance patching: Implement VPN appliance patches immediately, especially for SonicWall, Fortinent, and Cisco GlobalProtect. Akira achieved full compromise-to-encryption in under one hour via SonicWall VPN exploitation. Underground forums show active recruitment of AD experts specifically for VPN-based initial access, and brute-forcing tools for these platforms are actively sold on exploit.in.

  • Deploy behavioral detection for BYOVD (Bring Your Own Vulnerable Driver) attacks: Multiple campaigns, including CrazyHunter, DeadLock, Interlock, and Warlock, used vulnerable gaming and DFIR drivers to disable EDR/AV before encryption. Implement driver allowlisting and monitor for known vulnerable driver hashes.

  • Establish shadow copy and backup integrity monitoring: Inhibit System Recovery (T1490) appeared in 38% of documented campaigns, and VSSAdmin was the fifth most commonly used tool across campaigns. Maintain offline, immutable backups and test restoration procedures quarterly.

Vulnerability exploitation at the extremes: Chaining new flaws and mining legacy debt

 

  • Rapid compression of exploit timelines: The mean time-to-exploit dropped from 23.2 days in 2025 to 1.3 days in Q1 2026. Approximately 69.7% of exploited CVEs are now zero-days, occurring on or before the date of disclosure.
  • Attacks on modern frameworks and infrastructure: React Server Components were targeted via CVE-2025-55182, becoming the #4 most detected CVE globally. Microsoft SharePoint and Office also faced rapid exploitation, with APT28 weaponizing new flaws within 24 hours.
  • Persistence of legacy technical debt: Sophisticated actors like SideWinder continue to exploit eight-year-old vulnerabilities in Microsoft Office. Telemetry also confirms ongoing exploitation of decade-old flaws such as Log4j, ProxyShell, and Bash Shellshock.

The Q4 2025 to Q1 2026 vulnerability landscape is defined by two converging crises: an unprecedented volume of new disclosures and an exponential collapse in the time defenders have to mitigate them. AI has dramatically lowered the barrier to discovering new vulnerabilities. Open-source software (OSS) maintainers and enterprise security teams are already overwhelmed trying to keep up, and this AI-assisted discovery trend suggests the storm has barely begun.

Data aggregated from the National Vulnerability Database (NVD) illustrates a trajectory that is rapidly outpacing traditional triage methodologies. In Q4 2025, the NVD recorded 13,166 new vulnerabilities, a number that accelerated to at least 14,128 in Q1 2026. Predictive modeling from FIRST anticipates approximately 59,000 vulnerabilities for the entirety of 2026, warning that reaching 70,000 to 100,000 vulnerabilities is entirely realistic. This sheer volume represents a massive operational burden for security teams, preparing the industry for a shift to a 100,000-vulnerability paradigm.

While the sheer number of vulnerabilities expands, the window to defend against them is aggressively shrinking, signaling the death of the 30-day patch cycle. Intelligence from the Zero Day Clock indicates the defender's response window is approaching zero. In 2025, the mean time-to-exploit (TTE)—the gap between public disclosure and a confirmed, weaponized exploit—was 23.2 days. By Q1 2026, this “mean TTE” had been violently compressed to just 1.3 days.

The mean TTE in 2025 was 23.2 days; by Q1 2026, it has dramatically dropped to 1.3 days

A strong wake-up call is buried within this data: most exploitation now happens before disclosure. In Q1 2026, an estimated 69.7% of exploited CVEs were true zero-days, meaning they were exploited before or on the very day of disclosure. Given this, highly sophisticated actors are clearly sitting in the “negative weeks” or “negative months” for their true TTE. If the exploit is already in the wild before the CVE is published, the speed of patching cycles becomes largely irrelevant.

The bleeding edge: Rapid weaponization of zero-days and 1-days

Against this macro backdrop, Trellix telemetry reveals the frontline reality. Our sensors observed an unprecedented speed of exploitation for newly disclosed vulnerabilities, confirming that the "patching grace period" is obsolete.

  • The "React2Shell" Crisis (CVE-2025-55182): Trellix NX IPS telemetry recorded over 34K hits for this critical pre-authentication RCE in React Server Components, making it the #4-most-detected CVE globally. Validating this massive volume, Trellix SecondSight hunting operations observed threat actors aggressively exploiting this framework flaw to deploy backdoors almost immediately after its late-2025 disclosure, highlighting a severe supply chain risk.

  • The "ToolShell" chain: Trellix NX IPS recorded 3K hits for Microsoft SharePoint vulnerability CVE-2025-53771, while Trellix Helix telemetry identified frequent attempts against its sister vulnerability, CVE-2025-53770. Buttressing these telemetry metrics, SecondSight observed attackers chaining these exact late-2025 vulnerabilities (an auth bypass and a deserialization flaw) to achieve unauthenticated RCE. Ransomware affiliates heavily used this chain to establish beachheads before organizations could apply out-of-band patches.

  • Infrastructure strikes (CVE-2025-49844): Trellix telemetry flagged emerging exploitation attempts against this critical vulnerability. On October 8, 2025, SecondSight tracked the targeted weaponization of this flaw, observing malicious net_help.exe and explorer.exe processes sending POST requests to attacker infrastructure (signedward[.]com). Based on code overlaps with "SingleCamper," Trellix assesses with medium confidence that the RomCom threat group was behind this activity.

  • The 24-Hour weaponization cycle (CVE-2026-21509): On January 28, 2026, Trellix SecondSight detected Russian state-sponsored group APT28 (Fancy Bear) launching a sophisticated spear-phishing campaign. Remarkably, APT28 weaponized CVE-2026-21509 (a Microsoft Office security feature bypass) within 24 hours of its public disclosure. The infection chain executed a fileless .NET loader in memory, deploying the "CovenantGrunt" implant—which abused legitimate cloud storage (filen.io) for C2—and "NotDoor," an Outlook macro backdoor. Highlighting the rapid proliferation of 1-day attacks, SecondSight observed a separate campaign just weeks later using the same CVE to target foreign ministries, establishing C2 on infrastructure previously linked to DPRK operations. Trellix Email Security successfully blocked both campaigns.

Shift the defense to runtime. When vulnerability weaponization timelines shrink to zero, the traditional "find and patch" model is simply too slow. Stop measuring success solely by patch deployment speed. Shift your strategy toward prevention and robust runtime behavioral controls that can catch zero-day exploits—like fileless memory injection—as they execute.

The silent killers: The N-day long tail

While there is a tendency to fixate on the latest zero-days, our telemetry paints a stark picture of the "background radiation" of the internet. Threat actors do not need new exploits when legacy technical debt remains so pervasive.

  • Automated perimeter scanning: Trellix NX IPS telemetry recorded more than 70K hits for Nmap, making it the second-most-detected "application" in our global data. The sheer volume of continuous perimeter scanning suggests a highly automated reconnaissance landscape, likely increasingly augmented by agentic AI and botnets mapping the internet 24/7.

  • Legacy application and edge risk: Trellix NX IPS recorded just over 100K hits targeting PHP and 59K hits targeting F5 BIG-IP, underscoring the severe risk of legacy web applications and edge infrastructure.

  • Sustained targeting of collaboration platforms: Trellix Helix telemetry confirms that attackers ruthlessly target internal collaboration tools. Top Helix detections are heavily dominated by older, critical enterprise software flaws, specifically Atlassian Confluence (CVE-2022-26134 & CVE-2021-26084) and Microsoft Exchange (ProxyShell).

  • Ubiquitous legacy vulnerabilities: Trellix NX IPS logged just over 13K hits for Log4j (CVE-2021-44228), keeping the 2021 bug firmly in the top 10 globally. Trellix Helix also continues to detect the 2014 Bash Shellshock HTTP exploit.

  • APT adoption of legacy debt (CVE-2017-11882): The use of old vulnerabilities is not limited to unsophisticated actors. Serving as a prime example, on November 21, 2025, Trellix SecondSight intercepted a highly targeted spear-phishing campaign by the SideWinder APT group. Despite deploying advanced tradecraft—including geographic payload filtering and dynamic generation to evade sandboxes—the core exploit successfully relied on an eight-year-old memory corruption vulnerability in Microsoft Office.

Quiet the noise and build resilience. You cannot patch your way out of legacy technical debt. The sheer volume of automated scanning against decade-old vulnerabilities creates dangerous alert fatigue. Radically shrink your attack surface by quarantining or outright deprecating legacy systems, and ensure your network is segmented enough to withstand a compromised edge device.

Cybercriminal use of AI

 

  • The "vibeware" doctrine of mass production: Threat actors like APT36 have begun using AI to mass-produce diverse "mediocre" implants in niche programming languages (e.g., Nim, Zig, Crystal) to overwhelm detection engines through sheer volume and variety.
  • Emergence of AI-integrated malware families: New malware, PromptFlux and PromptSteal, call LLM APIs at runtime to dynamically generate unique malicious behavior, breaking the traditional assumption that malicious code must be pre-encoded in a binary.
  • Collapse of technical barriers for low-skilled actors: Commercial AI enables unskilled actors to achieve nation-state-level operational scale. One instance includes a single actor compromising 600 devices globally via automated AI reconnaissance.
  • Commoditization of deepfake-driven fraud: Deepfake and voice synthesis tools transitioned into mass-market commodities, with underground services offering high-quality video for as little as $100 to bypass financial KYC controls and MFA.

October 2025 through March 2026 marks a threshold that threat intelligence analysts have long anticipated but hoped would arrive more slowly. Adversarial AI adoption has crossed from augmentation into integration. AI is no longer a productivity tool that helps a human write better phishing emails or cleaner exploit code. It is now embedded in the execution layer of attacks themselves, generating malicious commands at runtime, operating autonomously across CI/CD pipelines without human direction, and poisoning the AI tools that defenders and developers rely on daily. The question that dominated last year’s reporting: are criminals actually using AI, or just talking about it? has been definitively answered. The more pressing question now is whether the defensive ecosystem can adapt quickly enough to a threat landscape where the attacker’s toolchain is itself intelligent.

Adversarial AI adoption has crossed from augmentation into integration — it is now embedded in the execution layer of attacks themselves.

The “vibeware” doctrine: AI-generated malware at industrial scale

The most operationally significant shift in this reporting period is not a single novel malware family or a clever new evasion technique—it is a new doctrine of malware production. It was first documented in APT36’s campaign targeting Indian and Afghan government entities. Transparent Tribe, aka APT36, the Pakistan-attributed group with a decade-long history of targeting South Asian diplomatic and military networks, adopted what researchers have termed a vibeware strategy. Threat actors are using AI code generation to mass-produce implants across a deliberately diverse set of niche programming languages (e.g., Nim, Zig, Crystal, Rust, and Go) chosen not for their technical superiority but for their near-absence from commercial detection engine signature databases.

The vibeware strategy: Using AI-generated code to mass produce scripts and implants at scale.

The resulting arsenal was remarkable in its breadth and deliberate mediocrity. Fourteen distinct tools were identified in a single campaign (e.g., BackupSpy, CreepDropper, CrystalShell, ZigLoader, ZigShell, NimShellCodeLoader, SheetCreep, MailCreep, and more), all communicating through legitimate cloud services such as Slack, Discord, Google Sheets, Firebase, and Supabase, in what the industry calls “living off trusted services” (LOTS). 

The code quality was, by traditional standards, poor. Logical errors, implementation flaws, and structural inconsistencies typical of AI-generated output were present throughout. APT36 did not care. The operational logic was not to build one excellent implant but to deploy many adequate ones simultaneously, overwhelming detection through sheer diversity. By consciously accepting lower code quality in exchange for higher volume, the nation-state actor has adopted a “distributed denial of detection” (DDoD) model that fundamentally changes the economics of malware development.

The vibeware doctrine is not to build one excellent implant but to deploy many adequate ones simultaneously, overwhelming detection through sheer diversity.

This doctrine has propagated beyond APT36. In January 2026, a Vietnamese cybercrime actor was identified using AI to generate malicious  PureRAT scripts for their attack campaigns. These scripts featured detailed Vietnamese-language comments and numbered debug messages, representing the unmistakable fingerprint of native-language prompting.

Static Tundra APT’s campaign against Poland’s energy sector in December 2025 is another example of the vibeware doctrine’s spreading. The attack on a manufacturing company deployed a PowerShell-based wiper, LazyWiper. This presumably AI-generated script overwrites approximately two-thirds of a file, rendering it irrecoverable. Its core file-corruption component, a C# function named WriteRandomBytes, displayed structural inconsistencies, nonsensical comments, and non-standard indentation, strongly suggesting LLM-generated code. Although the partial overwriting method was likely intended to be faster than full overwrites, it was significantly slower in practice, illustrating the doctrine’s conscious acceptance of flawed, AI-generated components in exchange for volume.

Screenshot of LazyWiper code excerpt highlighting its potential AI generation
LazyWiper code excerpt highlighting its potential AI generation

What was once a nation-state capability is now a regional cybercrime technique. The barrier to entry for sophisticated malware development has not merely lowered; it has effectively collapsed.

From AI-assisted to AI-integrated: a qualitative leap

The most technically significant development in this reporting period is not AI-assisted malware development - it is AI-integrated malware execution. Google’s Threat Intelligence Group documented two malware families, PromptFlux and PromptSteal, that call LLM APIs at runtime to dynamically generate their own malicious commands. Rather than executing a fixed payload, these tools query a language model mid-operation and act on the response, enabling real-time behavioral adaptation that renders static analysis and signature detection fundamentally insufficient. A parallel family, HonestCue, was documented abusing Google’s own Gemini API for the same purpose - runtime code generation as a core malware capability.

This is a qualitative leap, not an incremental one. Traditional malware analysis depends on the assumption that malicious behavior is encoded in the binary or script being examined. PromptFlux breaks that assumption entirely. The malicious behavior is generated fresh at execution time, shaped by the current environment, the target’s defenses, and whatever the LLM produces in response to the attacker’s prompt. The implications for detection engineering are severe. Behavioral analysis can still catch the effects of these tools, but the window between execution and detection narrows dramatically when the payload is never the same twice.

PromptFlux breaks the assumption that malicious behavior is encoded in the binary. Now it is generated in real time during execution  and shaped by the environment and target defenses.

The same period saw a tool called CyberStrikeAI assessed as linked to Chinese Ministry of State Security operations. It is not a conventional penetration testing framework with an AI module bolted on. Its architecture is built around LLM-driven decision-making for attack path selection. The AI determines which vulnerabilities to prioritize, which credentials to harvest, and which exploit to deploy against a given target profile. Automated vulnerability scanning, target profiling, credential harvesting, and exploit selection are all orchestrated by the AI layer rather than by a human operator making sequential decisions.

This represents a significant shift from “AI-assisted” to “AI-native” offensive tooling. The practical implication is that the human operator’s role shifts from tactical decision-maker to strategic director and the AI handles the execution logic. A campaign Trellix observed in February 2026 illustrated what this looks like in practice. An actor used AI to automate and optimize the exploitation of FortiGate devices globally, with the AI making tactical decisions about lateral movement sequencing (DCSync, Pass-the-Hash, LLMNR poisoning), rather than a human operator working through a playbook. The AI was not generating code; it was orchestrating post-exploitation operations autonomously.

With the shift from “AI-assisted” to “AI-native” offensive tooling, AI now handles the execution logic and orchestrates post-exploitation operations autonomously.

AI infrastructure: from tool to target

As AI platforms have become critical enterprise infrastructure, they have become critical attack targets. In November 2025, Trellix witnessed a campaign exploiting a vulnerability in the Ray AI compute engine to compromise over 230,000 exposed servers, transforming them into a self-propagating botnet capable of cryptomining, DDoS, and data theft. A key element of this campaign was the use of AI against AI, where threat actors utilized LLM-generated code to enhance their attack methods. The attack involved a sophisticated Python payload that intelligently allocated 60% of cluster resources to maximize profits while skillfully avoiding immediate detection.

The attack surface expanded further in February 2026 with the discovery of 2,200 malicious OpenClaw AI agent skills, each containing encoded commands in SKILL.md files that deploy the Atomic macOS Stealer when executed by an AI agent. This is a supply chain attack against the AI agent ecosystem itself. The plugin and skill marketplaces that AI platforms depend on for extensibility have become malware distribution channels.

Screenshot of Malicious OpenClaw skill designed to deploy Atomic MacOS stealer via mandatory skill prerequisites
Malicious OpenClaw skill designed to deploy Atomic MacOS stealer via mandatory skill prerequisites

A week later, malicious GitHub repositories posing as OpenClaw installers became the top-rated result in Bing AI search for “OpenClaw Windows,” exploiting AI-powered search recommendations to surface malware at the moment of highest user trust.

In February 2026, VirusTotal highlighted the abuse of OpenClaw infrastructure involving several sophisticated attack techniques, including indirect prompt injection, execution hijacking, semantic worm propagation, SSH injection, environment harvesting, and prompt file implantation. The exploitation of the OpenClaw AI ecosystem is driving a significant evolution in the AI-based threat landscape, marked by the emergence of these types of novel cyberattack methods. Trellix anticipates this trend will only continue, leading to a new wave of sophisticated, hard-to-detect attacks that exploit OpenClaw's inherent advanced capabilities.

The Shai-Hulud-Style npm worm campaign, identified in February 2026, combined nineteen typosquatted npm packages with MCP server injection targeting AI coding assistants - Cursor, Claude Desktop, and similar tools - to harvest LLM API keys and poison the code generation pipeline. The campaign’s most alarming feature was its use of local LLMs to generate polymorphic evasion variants, combined with a 48-96 hour time-gated execution delay to evade sandbox analysis. If an AI coding assistant is compromised, every piece of code it generates or reviews for a developer becomes a potential attack vector. The implications for software supply chain security are profound and largely unaddressed by current tooling.

Separately, between October 2025 and January 2026, systematic reconnaissance of LLM infrastructure was documented at scale: over 80,000 sessions from two IP addresses probing 73 or more LLM endpoints across major providers, using carefully crafted queries to fingerprint models while maintaining consistent JA4H signatures to avoid detection. Professional cybercriminals are building target lists of LLM deployments. The reconnaissance phase of a broader campaign against AI infrastructure appears to be well underway.

The shift of AI infrastructure "from tool to target" means these critical platforms are now facing mass resource compromises and novel supply chain threats that poison code generation and agent marketplaces. This demonstrates that adversarial AI is integrated into the core execution of attacks, necessitating an urgent defense adaptation to counter these new threats against the software supply chain.

Protecting Sensitive Data in the Age of AI

Assess Your Risk

AI as a capability multiplier for low-skill actors

Perhaps the most consequential long-term implication of this reporting period is not what sophisticated nation-state actors are doing with AI, but  what unsophisticated actors are now capable of doing with it. 

In February 2026, a Russian-speaking threat actor assessed to have limited independent technical capability used commercial AI services to automate reconnaissance, credential extraction, and post-exploitation DCSync attacks across 600 FortiGate devices in 55 countries. The tools used—  Mimikatz, Meterpreter, Impacket, Nuclei— are not novel. The scale of the operation, however, would previously have required a team with substantial operational experience to coordinate. AI augmentation collapsed that requirement entirely.

This finding demands a revision of how the industry thinks about threat actor tiers. The traditional model, where nation-states were at the top, organized crime was in the middle, and script kiddies were at the bottom,  assumed that operational scale correlated with technical sophistication. That assumption is no longer valid. A low-skilled actor with access to commercial AI services and a willingness to automate can now achieve operational reach that was previously the exclusive domain of well-resourced groups. Threat modeling that relies on capability assessment as a proxy for likely impact is increasingly unreliable.

Adversarial, commercial AI has collapsed the technical barrier, enabling unskilled attackers to achieve the high-impact, global reach once exclusive to nation-states.

The underground marketplace has responded to this demand. In January 2026, a threat actor operating as ‘ImpactSolutions’ advertised an AI-enhanced metamorphic crypter on the Exploit forum, using AI to generate polymorphic code variants that evade signature detection - a purchasable service, not a bespoke capability. A separate listing by ‘Shadowx007’ on Darkforums offered APEX AI, described as an automated APT-level penetration-testing tool covering cloud exploitation, ransomware deployment, and exploit-kit functionality.

Screenshot of APEX API APT-level penetration testing tool advertised on underground forums
APEX API APT-level penetration testing tool advertised on underground forums

The commoditization of AI-enhanced offensive capabilities through underground markets means that the capability uplift documented in nation-state campaigns will propagate to criminal actors on a timeline measured in months, not years.

Deepfakes, voice synthesis, and the social engineering frontier

North Korea’s BlueNoroff sub-group deployed AI-generated deepfake video as an initial access vector against cryptocurrency and DeFi firms across 10 countries in a campaign observed from  October 2025 to February 2026. The attack chain included  a compromised Telegram account and a fake Zoom meeting featuring an AI deepfake of a trusted contact.  A ClickFix prompt then granted initial access deploying a seven-family macOS malware ecosystem coordinated to bypass macOS Transparency, Consent, and Control (TCC) security, steal browser data, and establish multiple persistence mechanisms. The deployment of seven novel malware families in a single campaign against a single target sector reflects industrial-scale tooling investment that AI-assisted development has made economically viable.

The underground market has arrived at the same destination from a different direction. In February 2026, a seller operating as ‘BlackStoneX’ on BHF forum began advertising a full-service AI deepfake bureau specifically engineered to defeat financial KYC controls, at prices starting from $100 per video.

Screenshot of Deepfake creation services by BlackstoneX advertised on underground forums
Deepfake creation services by BlackstoneX advertised on underground forums

Post translation

Toggle translation

DEEPFAKE AND GENERATION OF VIDEO by BLACKSTONEX CORP.

BLACKSTONEX | AI Production of the Future :rocket:

We blur the boundaries between reality and graphics. Our BLACKSTONEX team specializes in advanced neural network solutions for business and personal branding.

With our help, you can complete KYC (KYC verification) for services that require video verification of your face or documents.

We offer the following services:

• Deepfake creation / from scratch or using your documents

• Character generation from a photo in any location/clothing

• Face swapping in photos/videos

• Creating videos of fictitious products/cars/houses in your location (ideal if you need to send a video to a client waiting for a product, but you don't have it)

• Video reviews

• Recording a video fake with your character holding documents/a piece of paper

• Your Character + Your Text

• Perfect Deepfake: Clean face swapping without the "uncanny valley effect" and artifacts

• Recording a video with YOUR data from a document using our drop (suitable for those who entered data but didn't provide a face photo)

 

• And anything else that comes with your imagination.

 

Prices start at $100.

We focus exclusively on quality. Clients understand what they're paying for. Successful completion of video verifications in VCC/BET/CASINO/CRYPTO/FIN services, and much more.

We also create documents based on your data. We can then fulfill your order via video with the same document.

Link to the channel with examples - https://t.me/+EKAqhCEdCbFiZmMx

Contacts:

Telegram: @BlackStone_X (https://t.me/BlackStone_X)

TOX: 300E9FCC81D749CD0246DF8DC982DCC7ACD04CB6643259579A187C845362AE40867B80D56F45

Jabber: in PM

Garant +

The service offers face replacement, document forgery combined with matching deepfake video, and verified successful bypasses across cryptocurrency platforms, virtual credit card services, betting sites, and casinos. At $100 per identity package, this is not a boutique service; it is a commodity. Multiple competing services were referenced in the same thread, indicating a mature, competitive market with sustained demand from fraud operators who need clean account access at scale.

The Scattered Lapsus$ alliance  (a consolidation of Scattered Spider, Lapsus$, and ShinyHunters operating as a coordinated threat group) continued its AI-powered voice phishing operations through this period. Using synthesized voices, they  impersonated IT staff during  real-time calls to bypass MFA and gain access to Salesforce and Snowflake environments across retail, telecoms, finance, and aviation targets. The technique requires no malware, no exploit, and no technical sophistication at the point of entry. It  only needs a convincing voice and a target who follows standard IT support procedures. AI voice synthesis has made that convincing voice available on demand.

North Korean threat actors also built a fully functional fake job platform impersonating Anthropic and Anchorage Digital, specifically targeting AI researchers, cryptocurrency professionals, and software developers in the United States. The platform, built in React Next.js with convincing job application workflows,  represents a strategic intelligence collection priority. DPRK is not merely targeting AI companies for financial gain but appears to be systematically attempting to acquire AI research, access, and talent intelligence. The choice to impersonate Anthropic specifically, rather than a generic technology company, suggests a level of targeting precision that goes beyond opportunistic credential theft.

AI-driven fraud has transitioned from a boutique capability to a cheap, mass-market commodity, allowing any attacker to bypass sophisticated security through on-demand deepfakes and synthesized voices for as little as $100.

The C2 channel hiding in plain sight

A campaign identified in November 2025 introduced a C2 evasion technique that deserves particular attention from network defenders. It involved malware traffic disguised as LLM API calls, routed through Tencent Cloud Function servers using the standard /v1/chat/completions endpoint format with Base64 and XOR encoding. The technique exploits a specific gap in enterprise security posture— the widespread allowlisting of AI service traffic that organizations have implemented to support legitimate AI tool usage. By mimicking the traffic patterns of commercial LLM APIs, the malware’s C2 communications blend into the background noise of normal AI operations, invisible to network monitoring tools that treat AI service traffic as inherently benign.

This emerging threat vector has been further exemplified by the discovery of SesameOp, a backdoor that leverages the OpenAI Assistants API C2 channel. SesameOp is a novel backdoor that uses the legitimate OpenAI Assistants API for its C2 communications. Instead of relying on traditional attacker-controlled servers, SesameOp abuses the OpenAI API as a relay mechanism to stealthily fetch encrypted commands and exfiltrate data. The malware uses defense evasion techniques, such as .NET AppDomainManager injection through compromised Microsoft Visual Studio utilities. Specifically, it interacts with vector store lists and custom Assistants within the OpenAI platform to orchestrate its activities. This sophisticated abuse of a legitimate, trusted AI service further highlights the challenge of distinguishing between benign AI service traffic and covert malicious operations.

This technique of masquerading in legitimate AI communication will continue to proliferate. As enterprise AI adoption increases and AI service traffic becomes a larger proportion of total network activity, the signal-to-noise ratio for detecting malicious traffic masquerading as LLM calls will only worsen.

Security teams that have not yet developed specific detection logic for anomalous AI API traffic patterns, such as unusual volumes, off-hours activity, unexpected destination IPs claiming to be AI services, should treat this as an urgent gap.

Conclusion

From October 2025 to March 2026, the use of adversarial AI by cybercriminals reached a pivotal point. It is no longer just aiding human attackers but is now systematically embedded in the core execution phase of AI-empowered attacks.

AI has not merely made existing attacks faster or cheaper - it has created new attack categories (autonomous agents, runtime LLM integration, C2 evasion), new targets (AI infrastructure and models), and new capability distributions (low-skill actors achieving nation-state operational scale).

For defenders, the implication is urgent: security teams must now rapidly develop specific detection logic for anomalous AI API traffic patterns and adapt to a threat environment where the attacker's tools possess inherent intelligence. The industry’s response to these structural changes will define the threat landscape for the next several years.

Supply chain attacks

 

  • The "vibeware" doctrine of mass production: Threat actors like APT36 have begun using AI to mass-produce diverse "mediocre" implants in niche programming languages (e.g., Nim, Zig, Crystal) to overwhelm detection engines through sheer volume and variety.
  • Emergence of AI-integrated malware families: New malware, PromptFlux and PromptSteal, call LLM APIs at runtime to dynamically generate unique malicious behavior, breaking the traditional assumption that malicious code must be pre-encoded in a binary.
  • Collapse of technical barriers for low-skilled actors: Commercial AI enables unskilled actors to achieve nation-state-level operational scale. One instance includes a single actor compromising 600 devices globally via automated AI reconnaissance.
  • Commoditization of deepfake-driven fraud: Deepfake and voice synthesis tools transitioned into mass-market commodities, with underground services offering high-quality video for as little as $100 to bypass financial KYC controls and MFA.

The period between October 2025 and March 2026 represents a grim maturation of supply chain warfare. Moving beyond simple typosquatting, threat actors integrated immutable blockchains into their C2 infrastructure to evade traditional security scanners. These sophisticated tactics, ranging from tag-poisoning to phantom dependencies, exploit the fundamental trust we place in developer tools and open-source registries.

Regarding Trivy and LiteLLM from TeamPCP
Regarding Trivy and LiteLLM from TeamPCP
Credit: Trend Micro
Regarding Trivy and LiteLLM from TeamPCP
Regarding Trivy and LiteLLM from TeamPCP
Credit: Wiz
Regarding Trivy and LiteLLM from TeamPCP
Regarding Trivy and LiteLLM from TeamPCP
Credit: Grip Security

GlassWorm

First observed in October 2025, GlassWorm is a threat actor cluster targeting IDE extensions on the Open VSX Registry and Microsoft Visual Studio Marketplace. The initial variants used invisible Unicode characters to conceal malicious code from editors and review tools, impersonating popular extensions for Flutter, Angular, Tailwind, and Vue. A credential theft module harvested developer tokens from infected machines and used them to propagate further, creating a self-reinforcing cycle. Developers’ compromised credentials were used to inject malware into their repositories, which in turn infected downstream consumers.

By March 2026, GlassWorm had expanded into two new delivery vectors. ForceMemo compromised hundreds of GitHub repositories by force-pushing obfuscated malware into Python projects, rewriting git history to make the injections invisible during normal code review. Combined with a parallel wave using invisible Unicode injection and the npm hijacking operation described below, GlassWorm affected over 400 projects and packages across Python and JavaScript repositories, VS Code extensions, and npm libraries.

A parallel operation hijacked the npm maintainer account behind two widely used React Native packages with approximately 130,000 combined monthly downloads. It ultimately distributed the malware through both direct and transitive dependency paths where surface-level scanners were unlikely to detect it.

Key takeaways

All three GlassWorm delivery vectors (IDE extensions, ForceMemo, and npm hijacking) use the Solana blockchain as a command-and-control (C2) channel, posting base64-encoded payload URLs as transaction memos and polling public RPC endpoints to retrieve them. The C2 infrastructure is immutable, resistant to traditional takedown mechanisms, and the traffic blends with legitimate Web3 activity.

The npm campaign evolved rapidly. The first wave used obvious install hooks and was caught within minutes. By the third wave, days later, the attacker had locked out the legitimate maintainer, removed all visible indicators from the parent package, and shifted to floating version pins so the payload could be updated through the deepest transitive dependency alone.

The force-push technique used in ForceMemo poses a particular challenge for organizations that rely on commit-level auditing.The rewritten history preserves original author information and commit messages, leaving only subtle metadata discrepancies as forensic evidence. Across all GlassWorm activity, compromised developer credentials are the primary propagation mechanism.

TeamPCP

Between late February and  late March 2026, a second threat actor cluster, TeamPCP, executed a cascading series of compromises against widely used open source security and infrastructure tools. The initial target was Trivy, one of the most widely adopted open-source vulnerability scanners, deployed in thousands of GitHub Actions workflows. The attackers gained access through incomplete remediation of a prior security incident involving the Trivy repository. They then used tag poisoning to redirect nearly all version tags to malicious commits. The compromised action extracted secrets from the CI/CD runner memory and exfiltrated them.

Credentials harvested from Trivy runners likely enabled the subsequent compromise of Checkmarx KICS, an infrastructure-as-code scanner, using the same tag-poisoning technique. Within the same week, a PyPI token exposed through the Trivy incident was used to publish backdoored versions of LiteLLM, an AI proxy framework that Wiz estimates is present in 36% of cloud environments. Three days after that, the same operator backdoored the Telnyx Python SDK.

TeamPCP also deployed CanisterWorm, a self-propagating npm worm that used stolen tokens to inject itself into more than 60 packages across multiple npm namespaces.

Key takeaways

The TeamPCP campaign demonstrated how a single initial compromise can propagate across the ecosystem. Credentials stolen from the Trivy incident directly enabled the LiteLLM and CanisterWorm compromises. Additionally, KICS and Telnyx were linked to the same operator through shared forensic artifacts. The LiteLLM and Telnyx compromises shared an identical RSA-4096 encryption key, and all four attacks were linked through shared infrastructure and methodology, confirming a single threat actor.

The TeamPCP campaign demonstrated how a single initial compromise can propagate across the ecosystem.

The Trivy and KICS compromises exfiltrated stolen credentials to typosquatted domains impersonating the legitimate vendor brands. CanisterWorm used a different approach, relying on Internet Computer Protocol (ICP) blockchain canisters, a form of decentralized smart contract, for takedown-resistant command and control. The LiteLLM compromise relied on traditional C2 domains, while the Telnyx payload exfiltrated to a bare IP address.

Security tools run with elevated privileges in build pipelines, have access to secrets by design, and are generally trusted by default. Compromising one gives an attacker credentials, network access, and a position inside the security boundary in a single step.

The tag-poisoning technique used to compromise Trivy and KICS exploits a common GitHub Actions practice, where workflows reference actions by mutable version tags rather than immutable commit hashes. Any workflow following this convention pulls the compromised code automatically. The LiteLLM compromise introduced an additional evasion technique. It leveraged a Python interpreter feature to execute code on every process startup without any install hook or postinstall script, bypassing a class of security scanners entirely.

Because security tools possess inherent high-level access and trust, compromising one provides an attacker immediate, full-scale entry into the build environment's secrets and network.

Axios

On March 31, 2026, attackers compromised the npm account of Axios’ lead maintainer. It is a  widely used HTTP client library with approximately 100 million weekly downloads. Two malicious versions were published within 39 minutes.

The Axios source code itself was left untouched. Instead, the attacker added a phantom dependency, a typosquat of a legitimate cryptography library, that was never imported anywhere in the codebase. The dependency's primary purpose was to execute its postinstall hook, which deployed platform-specific remote access trojans for macOS, Windows, and Linux. The RAT provided arbitrary code execution and secondary payload deployment capabilities, with persistent access on Windows established via a combination of file drops and a Registry Run key. After execution, the dropper deleted itself and replaced the package manifest with a clean stub, complicating post-incident forensics on affected machines.

The C2 domain had been registered approximately eight hours before the first malicious version was published, suggesting a tightly coordinated operation. npm's security team removed both versions in approximately three hours. Google’s Threat Intelligence Group has since attributed the attack to UNC1069, a financially motivated North Korean threat actor. No connection to GlassWorm or TeamPCP has been identified.

Key takeaways

The Axios compromise shows the blast radius of a single maintainer account compromise at the top of the dependency tree. Even with a three-hour exposure window, the library's download volume means a significant number of organizations likely pulled one of the compromised versions before they were removed.

The phantom dependency technique is effective because automated tools comparing source code diffs between versions would find no changes; the only indicator was the addition of an unfamiliar dependency in the package manifest. Organizations monitoring their software supply chains should be tracking dependency changes, not just source code changes, across the packages they consume.

The Axios compromise shows the blast radius of a single maintainer account compromise at the top of the dependency tree impacting a significant number of organizations.

The attack also reflects a structural weakness in the open source ecosystem: high-impact packages with hundreds of millions of downstream consumers can be compromised through a single maintainer account with publish access, and the authentication requirements for those accounts are set by the registry, not by the downstream organizations that depend on them. Until registries enforce stronger authentication and token management requirements for maintainers of high-impact packages, account takeover will remain the most efficient entry point for supply chain attacks.

The supply chain attacks in Q1 2026 share a common root cause: compromised developer and maintainer credentials. Require hardware security keys for all accounts that can publish packages or push to production repositories. Pin CI/CD actions to immutable commit references rather than mutable version tags. Implement monitoring for unexpected dependency changes in lockfiles, particularly the addition of unfamiliar transitive dependencies or shifts from pinned to floating version references.

Industry reports, vetted by Trellix Advanced Research Center

 

 

The following section is derived from industry reporting and reflects information on publicly reported events and campaigns. These insights are not necessarily based on Trellix detections or direct observations. However, to provide a broader view of the threat landscape and understand what our industry peers are tracking, we have included this overview for contextual awareness.

The analysis of industry reports provides a comprehensive overview of the global cybersecurity landscape from October 2025 to March 2026 (Q4 and Q1). The period was characterized by a rapid acceleration in the weaponization of AI, a pronounced shift towards sophisticated defense-evasion strategies, and the widespread abuse of legitimate cloud services and development infrastructures to execute highly targeted cyber espionage and financially motivated campaigns. Threat actors are moving away from traditional push-based attacks toward complex, pull-based social engineering and deeply embedded persistent frameworks.

  • Rise of AI-generated payloads: Adversaries are leveraging large language models (LLMs) to rapidly generate, obfuscate, and iterate malicious payloads. A notable example is the deployment of AI-generated code, such as the DCRat "vibe coded" scripts, which utilize AI to dynamically bypass static detection signatures. These AI-assisted malware families often contain Russian or Farsi language prompts and intentional bloat code to confuse heuristic analysis.

  • Proliferation of virtual machine evasion: With rising frequency, threat actors are using the Run Virtual Instance technique to bypass host-based EDR telemetry. For example, the Curly COMrades campaign deployed custom Alpine Linux VMs via Hyper-V to host CurlyShell and CurlCat, successfully shielding their malicious tools from host-level security.

  • "Living-off-the-cloud" for C2 and hosting: Threat groups are demonstrating widespread abuse of trusted cloud platforms, particularly GitHub and Telegram, for C2 and payload staging. By utilizing web services and web protocols, actors blend malicious communications with legitimate enterprise traffic. Campaigns like the Astaroth banking trojan utilized GitHub repositories to host configuration files via steganography. At the same time, numerous Python-based RATs leveraged the Telegram Bot API for encrypted exfiltration and command execution.

  • SEO poisoning and "pull" social engineering: There is a distinct paradigm shift toward "pull" social engineering tactics that uses SEO poisoning to lure victims to malicious infrastructure. Advanced operations guide users searching for legitimate software (e.g., VPN clients, AI tools) into "FakeCaptcha" frameworks. This mechanism forces the victim to manually copy and paste malicious scripts, thereby executing malware like Latrodectus or NetSupport RAT while bypassing standard email gateways.

  • Targeting the developer supply chain: Threat actors aggressively compromised npm, PyPI, and VS Code extensions to target software developers. State-sponsored groups, such as North Korea's UNC5267 (Lazarus), deployed hundreds of malicious packages to deliver BeaverTail and InvisibleFerret malware. These campaigns specifically harvested source code, CI/CD secrets, and cryptocurrency wallets via compromise software dependencies and tools.

  • Exploitation of critical edge infrastructure: Rapid weaponization of zero-day and n-day vulnerabilities dominated initial access vectors. High-profile exploitation included the React2Shell vulnerability (CVE-2025-55182), which saw global attacks deploying cryptominers and RATs within hours of disclosure. Furthermore, extensive attacks on SonicWall VPNs (CVE-2024-40766) and Oracle WebLogic environments facilitated rapid ransomware deployments and deep network infiltration.

  • Ransomware cartels and advanced extortion: Ransomware operations evolved from decentralized affiliates into well-organized cartels. The DragonForce group matured into a multi-variant cartel operation, partnering with initial access brokers like Scattered Spider. Extortion groups uniformly adopted bring your own vulnerable driver (BYOVD) tactics to terminate EDR processes and leverage legitimate RMM tools (e.g., SimpleHelp, ScreenConnect) exfiltrating data to deploying payloads.

  • Geopolitical espionage and hybrid warfare: Nation-state operations closely mirrored kinetic conflicts. Russian-aligned actors (APT28, Sandworm) aggressively targeted Ukrainian infrastructure and European defense entities using zero-days and wipers (e.g., DynoWiper). Concurrently, Chinese actors (Mustang Panda, Silver Fox, APT41) expanded operations across Southeast Asia and the Middle East. Additionally, Iran-aligned groups (MuddyWater, Boggy Serpens) escalated attacks against critical infrastructure in response to regional tensions.

Top 10 reported victim countries

  • United States: 6.80%
  • India: 5.27%
  • Brazil: 3.45%
  • Canada: 3.35%
  • Russia: 3.25%
  • Japan: 3.04%
  • United Kingdom: 2.84%
  • Germany: 2.84%
  • China: 2.54%
  • Taiwan: 2.43%

Top 10 reported sectors

Top 10 reported actors

Top 10 reported malware

Top 10 dual-use tools

Top MITRE ATT&CK techniques

Hover or tap each bar to see the full name of the Technique

Comparison with previous six months

The global threat landscape shifted notably during the current period. Geographically, while the USA remains the primary target, India moved into the second position as South Korea’s share of activity declined. Brazil also emerged as a significant focal point, appearing as the third most targeted nation globally.

Sector targeting saw Government return to the top of the list, followed by Finance. Both industries, however, saw their relative shares decrease as targeting became more distributed across the landscape. Conversely, threat actor attribution grew more concentrated; groups like MuddyWater and UNC5267 became highly active, with the top five actors accounting for a much larger portion of total activity than before. Tactically, traditional dual-use tools like PowerShell remain central to operations despite a decline in reported frequency.

Outlook for CISOs

Based on the highly evasive and infrastructure-centric attacks observed between October 2025 and March 2026, organizations must continue to adapt their defensive postures to counter threats that actively manipulate trust and user behavior. We recommend focusing on the following strategic imperatives:

  • Integrate strategic threat intelligence: Institutionalize continuous, strategic, and operational threat and vulnerability intelligence consumption to stay ahead of the most sophisticated emerging threats, TTPs, and dedicated threat actors.

  • Fortify proactive deception and end-user trust defenses: Prioritize hardening the user execution environment and moving beyond traditional email filtering to  counter social engineering that leverages trusted interfaces. 

  • Ensure supply chain integrity and development environment security: Establish rigorous zero-trust principles for the software development lifecycle (SDLC) and stay ahead of the most pervasive efforts to secure the entire developer toolchain against external compromise.

  • Manage cloud egress and prevent lateral movement: Implement advanced behavioral monitoring and strict egress control to prevent the abuse of legitimate cloud platforms for C2 and data exfiltration.

  • Accelerate vulnerability response for public-facing infrastructure: Treat all public-facing and edge infrastructure as the most critical access vectors, demanding a sub-24-hour response for patching and robust continuous monitoring to prevent rapid weaponization.

Methodology

 

Collection: Trellix and the world-class experts from our Advanced Research Center gather the statistics, trends, and insights that comprise this report from a wide range of global sources.

  • Captive sources: In some cases, telemetry is generated by Trellix security solutions on customer cybersecurity networks and defense frameworks deployed around the world in both public and private sector networks, including those delivering technology, infrastructure, or data services. These systems, which number in the millions, generate data from a billion sensors.

  • Open sources: In other cases, Trellix leverages a combination of patented, proprietary, and open-source tools to scrape sites, logs, and data repositories on the internet, as well as the dark web, such as “leak sites” where malicious actors publish information about or belonging to their ransomware victims.

Normalization: The aggregated data is fed into our Insights and ATLAS platforms. Leveraging machine learning, automation, and human acuity, the team cycles through an intensive, integrated, and iterative set of processes – normalizing the data, enriching results, removing personal information, and identifying correlations across attack methods, agents, sectors, regions, strategies, and outcomes.

Analysis: Next, Trellix analyzes this vast reservoir of information, with reference to (1) its extensive threat intelligence knowledge base, (2) cybersecurity industry reports from highly respected and accredited sources, and (3) the experience and insights of Trellix cybersecurity analysts, investigators, reverse engineering specialists, forensic researchers, and vulnerability experts.

Interpretation: Finally, the Trellix team extracts, reviews, and validates meaningful insights that can help cybersecurity leaders and their SecOps teams (1) understand the most recent trends in the cyber threat environment, and (2) use this perspective to improve their ability to anticipate, prevent, and defend their organization from cyberattacks in the future.

Application: How to use this information

It’s imperative that any industry-leading assessment team and process understand, acknowledge, and, where possible, mitigate the effects of bias – the natural, embedded, or invisible inclination to either accept, reject, or manipulate facts and their meaning. The same precept holds true for consumers of the content.

Unlike a highly structured, control-based mathematical test or experiment, this report is inherently a sample of convenience – a non-probability type of study often used in medical, healthcare, psychology, and sociology testing that makes use of data that is available and accessible.

  • In short, our findings here are based on what we can observe and, pointedly, do not include evidence of threats, attacks, or tactics that evaded detection, reporting, and data capture. 

  • In the absence of “complete” information or “perfect” visibility, this is the type of study best suited to this report’s objective: to identify known sources of critical data on cybersecurity threats and develop rational, expert, and ethical interpretations of this data that inform and enable best practices in cyber defense

How to understand the analysis in this report

Understanding the insights and data in this report requires briefly reviewing the following guidelines:

  • A snapshot in time: Nobody has access to all the logs of all the systems connected to the internet, not all security incidents are reported, and not all victims are extorted and included in the leak sites. However, tracking what we can leads to a better understanding of the various threats, while reducing analytical and investigative blind spots.

  • False positives and false negatives: Among the high-performance technical characteristics of Trellix’s special tracking and telemetry systems to collect data are mechanisms, filters, and tactics that help counter or remove false positive and negative results. These help to elevate the level of analysis and the quality of our findings.

  • Detections, not infections: When we talk about telemetry, we talk about detections, not infections. A detection is recorded when a file, URL, IP address, or other indicator is detected by one of our products and reported back to us.

  • Uneven data capture: Some data sets require careful interpretation. Telecommunications data, for example, includes telemetry from ISP clients operating in many other industries and sectors.

  • Nation-state attribution: Similarly, determining nation-state responsibility for various cyberattacks and threats can be very difficult, given the common practice among nation-state hackers and cybercriminals to spoof one another or disguise malicious activity as coming from a trusted source.

Trellix

  

Trellix Advanced Research Center

   Newsletter

Acknowledgements

The Advanced Research Center and team members across all of Trellix contribute to this report. We would like to thank those below for their efforts to pour over telemetry, provide detailed analysis and context, write, edit, design, and layout this report.

  • Adithya Chandra
  • Ale Houspanossian
  • Alfred Alvarado
  • Anil Ramabhatta
  • Anne An
  • Anthony Berglund
  • Ashok B
  • Bing Sun
  • Chrissy Polchito
  • Daksh Kapur
  • Duy-Phuc Pham
  • Ernesto Fernández Provecho
  • Haowei Ren
  • Heather Mackey
  • Henry Bernabe
  • Ian Shefferman
  • Ilya Kolmanovich
  • Jambul Tologonov
  • Jeffrey Sman
  • Jenn Jackson
  • Joao Marques
  • John Fokker
  • Jonathan Omakun
  • Lennard Galang
  • Melanie Maben
  • Megan Haley
  • Pavan Pothamsetti
  • PJ Mullen
  • Pranay Balaji
  • Rohan Shah
  • Srini Seethapathy
  • Tim Hux
  • Tola Olawale

About the Trellix Advanced Research Center

The Trellix Advanced Research Center is at the forefront of research into the emerging methods, trends, and tools used by cyber threat actors across the global cyber threat landscape. Our elite team of researchers serve as the premier partner of CISOs, senior security leaders, and their security operations teams worldwide. The Trellix Advanced Research Center provides operational and strategic threat intelligence through cutting-edge content to security analysts, powers our industry leading AI-powered cybersecurity platform, and offers intelligence products, and services to customers globally.

Trellix Advanced Research Center

About Trellix

Trellix is a global cybersecurity company delivering intelligence-led cyber resilience for security-conscious organizations at any stage in their journey. Transforming over 30 years of threat intelligence into high-fidelity detections and automating AI-driven detection and response across cloud, on-premises, air-gapped, and operational technology environments, Trellix helps minimize organizational risk and ensure business continuity. Working with a broad partner ecosystem, global intelligence partners, and trusted collaborators, Trellix helps customers proactively adapt to the evolving threat landscape while strengthening the collective defense against cybercriminals and state-sponsored attacks.

Subscribe to Receive Our Threat Information

This document and the information continued herein describes computer security research for educational purposes only and the convenience of Trellix customers. Trellix conducts research in accordance with its Vulnerability Reasonable Disclosure Policy I Trellix. Any attempt to recreate part or all of the activities described is solely at the user’s risk, and neither Trellix nor its affiliates will bear any responsibility or liability.

Trellix is a trademark or registered trademark of Musarubra US LLC or its affiliates in the US and other countries. Other names and brands may be claimed as the property of others.