Cybersecurity Threats: Game Cheat Spyware, Ransomware Incidents, and Evolving Phishing Tactics
Game Cheat Spyware, 24-Hour Ransomware, and Chrome Sync Stalking Headline a Dangerous Week in Cybersecurity
A wave of cyberattacks exploiting trusted tools, familiar software, and overlooked defaults struck businesses and individuals globally in the week of July 16, 2026, with threats ranging from malicious game cheats to ransomware that encrypted an entire corporate network in under 24 hours.
The scale and speed of these attacks reflect a troubling shift in how cybercriminals operate. Rather than relying on exotic exploits, attackers are weaponizing everyday conveniences — a Chrome sync setting, a popular installer, a GitHub repository — to move from initial access to full compromise faster than most security teams can respond. For businesses and individuals alike, the cost of inaction is rising sharply.
Malware Hiding in Plain Sight
Trojanized Packages and the NuGet Supply Chain Threat
Eleven malicious NuGet packages, disguised as game cheats and utility bots, were discovered deploying a Windows surveillance payload named "pepesoft.exe." Cybersecurity firm Socket found that the packages functioned as first-stage downloaders that fetched a second-stage Python payload from GitHub Releases and Hugging Face paths under the username "pepegit666."
"The recovered payloads use downloader-supplied AWS-style key material to retrieve remote configuration, authenticate to Google Sheets, bind activations to hardware, and honor a remote HWID/UUID ban-list," Socket reported. A dormant BitTorrent fallback mechanism was also built into the packages as a contingency delivery method — a detail that underscores just how much operational redundancy modern threat actors are building into their campaigns.
This type of supply chain attack is particularly difficult to detect because the malicious packages mimic the naming conventions, metadata, and even functionality of legitimate tools. Developers and IT teams downloading packages from public repositories without rigorous vetting are especially exposed. Understanding the different types of malware used in supply chain attacks is an important first step in recognising and responding to these threats before they take hold.
RAT Campaigns Targeting Trusted Software Users
Separately, a Russian-speaking financially motivated threat actor tracked as UAT-11795 has been targeting users in the United States and Europe since at least June 2025. The group distributes a Python-based remote access tool called Starland RAT and a PowerShell-based command-and-control memory implant known as WLDR agent through trojanized installers for widely trusted software including Zoom, WebEx, MobaXterm, and DBeaver.
"The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a Runspace execution engine for executing additional payloads," Cisco Talos said. The majority of infections were recorded in the United States, with additional victims in Germany, Romania, and Venezuela.
The same ClickFix lure technique has also been linked to ClickLock Stealer, a macOS-focused malware targeting users in Europe, North America, and the Middle East and Africa. Group-IB noted that ClickLock Stealer "targets data from 8 browsers, 31 crypto wallet browser extensions, 7 password manager extensions, 8 desktop wallet applications, extracts blockchain addresses across 6 chains, macOS Keychain, shell history, and FTP credentials." The breadth of that targeting list is a stark reminder that macOS users are no longer operating in a lower-risk environment.
Fake GitHub Repositories and In-Memory Infostealers
More than 290 fake GitHub repositories impersonating trusted vendors — including security firm Arctic Wolf — were also identified distributing a Windows infostealer sharing code with the known BoryptGrab malware family. Arctic Wolf described the payload as "a pure smash-and-grab in-memory infostealer, with a 41-entry cryptocurrency wallet path table and 19+ targeted browser names." Stolen data is packaged into a ZIP archive and sent to a command-and-control server with a Russian IP address.
The use of impersonated vendor repositories is a calculated social engineering tactic. By exploiting the trust users place in recognised brand names, attackers dramatically increase the likelihood of installation before suspicion is raised.
Ransomware, Exploited Flaws, and Infrastructure Under Fire
A 24-Hour Network Encryption: The Spirals Ransomware Incident
A previously undocumented ransomware family called Spirals struck an IT services company in South Asia in June 2026, encrypting the victim's network within 24 hours of the initial breach. Broadcom's Symantec and Carbon Black Threat Hunter Team confirmed that the Rust-based payload is either a new ransomware family or one purpose-built for this specific attack.
The attacker gained initial access by compromising an internet-facing IIS web server and uploading an ASP.NET web shell. Within three hours, they had established persistence, conducted reconnaissance, uninstalled endpoint security software, dumped the Security Account Manager hive, and deployed the payload network-wide using PsExec. The ransom note threatens to publish stolen data within six days if payment is not made.
The speed of this attack — from initial web shell upload to full network encryption in under a day — illustrates why reactive security postures are no longer sufficient. Organisations that have not rehearsed their incident response plans or implemented network segmentation face an asymmetric disadvantage against threat actors operating at this pace. If your organisation has not yet reviewed how to respond effectively to a ransomware attack, the Spirals incident provides an urgent case study for doing so.
Critical Vulnerabilities Added to CISA's KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency added two new vulnerabilities to its Known Exploited Vulnerabilities catalog this week.
- CVE-2026-46817 — an improper privilege management flaw in Oracle E-Business Suite, with a federal patch deadline of July 18, 2026
- CVE-2023-4346 — an account lockout vulnerability in KNX Association's KNX Protocol, with a federal patch deadline of July 29, 2026
Federal agencies are required to remediate both within the specified deadlines, but private sector organisations should treat CISA's KEV catalog as an authoritative signal of active exploitation risk regardless of regulatory obligation.
EDR Bypass Techniques and Eastern European Infrastructure Threats
Bitdefender Labs disclosed three techniques by which Windows bind links can be abused to blind endpoint detection and response products. The techniques — File-Binding, Process-Binding, and Silo-Binding — allow a local administrator to bypass EDR sensors and Windows defences including AMSI and AppLocker. Microsoft assessed the findings as low severity due to the administrator-level access requirement, though security teams should note that local administrator access is frequently achievable through credential theft or lateral movement in a compromised environment.
Hunt.io's analysis mapped more than 3,900 threat-enabling servers across 302 Eastern European infrastructure providers over the past three months. Proton66 OOO was linked to active exploitation of CVE-2026-35273, a critical Oracle PeopleSoft zero-day attributed to the ShinyHunters group — a finding that reinforces the need to monitor infrastructure-level threat intelligence alongside individual vulnerability disclosures.
Fraud Networks Dismantled and New Phishing Tactics Emerge
International Fraud Operations Brought Down
Dutch authorities arrested a 46-year-old dual Israeli-Polish citizen alleged to be the mastermind behind an international fraud network employing more than 700 people across approximately 20 fake call centers. Posing as financial advisors, scammers built trust with victims over months before redirecting their cryptocurrency investments into criminal accounts.
Spanish National Police separately dismantled a cybercrime network responsible for stealing and laundering approximately €140 million through fake investment platforms, CEO fraud, and adversary-in-the-middle attacks. Four arrests were made across Portugal, Spain, and Panama. The group operated a network of over 800 bank accounts using money mules to launder funds through third-country accounts.
The U.S. Justice Department unsealed a December 2024 indictment charging three Russian nationals — Alexander Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yulia Vladimirovna Pankova — along with two bulletproof hosting companies, Media Land LLC and ML.Cloud LLC, for cybercrimes causing over $62 million in losses. The U.S. Department of State's Rewards for Justice program is offering up to $10 million for actionable information on the defendants.
AI-Powered Phishing, MFA Interception, and Chrome Sync Abuse
On the phishing front, researchers identified a new AI-powered device code phishing toolkit called Jalisco and a credential harvester named OmegaLord that captures phone numbers alongside passwords to intercept MFA codes — a technique that effectively neutralises one of the most widely recommended account security controls.
A phishing campaign called SeasonalInvite has been abusing commercial Remote Monitoring and Management tools since at least January 2026 using eCard-themed lures. Researchers identified 959 eCard domains and 2,658 gate pages routing victims to phishing sites — a distribution network of considerable scale that points to organised, well-resourced threat actors rather than opportunistic individuals.
Chrome's sync feature is also being weaponized by stalkers. By briefly accessing a victim's phone and signing into their own Google account within Chrome with sync enabled, an attacker can silently mirror the victim's browsing history, saved passwords, and autofill data to a remote device without leaving obvious traces. This requires no technical expertise — only brief physical access — making it a credible threat in domestic abuse scenarios and insider threat contexts alike.
Lessons and Immediate Actions for Security Teams
The week's events carry direct lessons for anyone managing devices or networks.
- Audit third-party packages and repositories before installation — malicious code increasingly mimics legitimate tools with convincing names and metadata. Treat any unverified package as untrusted until proven otherwise.
- Review all accounts signed into shared or personal devices, particularly browser-level accounts where sync permissions may expose sensitive data without obvious alerts. Chrome's account management settings should be reviewed on any device that has been out of your direct control.
- Ensure patch cycles prioritise actively exploited vulnerabilities on CISA's KEV catalog. Attackers are demonstrating the ability to move from initial access to full network encryption in under 24 hours — a timeline that makes delayed patching increasingly indefensible.
Understanding what ransomware is and how it operates remains foundational knowledge for any security team working to contextualise the speed and severity of attacks like Spirals. The technical sophistication on display this week is not the exception — it is the baseline against which every organisation's defences now need to be measured.