Product
Astaroth Botnet Deploys New WhatsApp Web Spambot Component
1 rule 9 TTPs 8 IOCsOperators of the Astaroth (aka Guildma) botnet, which targets Brazil-based users, introduced a new spambot component in Q4 2025 that leverages WhatsApp Web in headless browser mode for malware distribution, exhibiting evasion techniques like payload encryption and WebDriver automation indicator stripping.
Suspicious File Download via Headless Browser
1 rule 2 TTPs 26 IOCsThe DUCKTAIL threat actor leverages Chromium-based web browsers (such as Microsoft Edge and Chrome) running in headless mode with the `--dump-dom` argument to stealthily download malicious content from the internet via suspicious file-sharing domains, impacting compromised endpoints.
ClickFix Campaign Activity
16 IOCsTracking brief for the ClickFix campaign; individual sightings are folded in as reported.
Apple Security Updates — July 2026
4 CVEs 10 IOCsRoundup of Apple security advisories published in July 2026.
Google Security Updates — July 2026
5 CVEs 41 IOCsRoundup of Google security advisories published in July 2026.
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
Windows Defender Phishing Filter Override via Registry Modification
2 rules 1 TTPThe analytic detects modifications to the Windows registry that disable the Windows Defender phishing filter, potentially allowing attackers to deceive users into visiting malicious websites without browser warnings.
DNS-over-HTTPS Enabled via Registry Modification
3 rules 2 TTPsDetection of DNS-over-HTTPS (DoH) being enabled via registry modifications on Windows systems, potentially indicating defense evasion by masking network activity and hindering traditional DNS monitoring.