September 8, 2026
- SideCopy / Transparent Tribe activity against Indian defence targets continues with the same LNK plus BAT/PowerShell tradecraft. Qihoo 360's Advanced Threat Research Institute published further CrimsonRAT samples and a separate Go-based RAT, with infrastructure reuse across both campaigns (360 ATRI report).
· Threat Activity
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
August 14, 2026
- SideCopy delivering CrimsonRAT via Outlook
.msg lures, and BitterAPT using malicious .accdr documents against government, defense, and maritime targets — both flagged by Nextron with fresh IOCs. (SideCopy, BitterAPT)
· Threat Activity
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
June 18, 2026
- SideCopy (APT36 / Transparent Tribe) continues its double-extension LNK → PowerShell → CrimsonRAT chain against Indian defense, swapping lures between fake PowerPoint briefings and Word "Minutes of Meeting" docs; staged components barely register at delivery. IOCs via Nextron (Nextron).
· Threat Activity & Ransomware
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
June 17, 2026
- SideCopy / APT36 (Transparent Tribe) targeted Indian defense personnel with a weaponized PowerPoint package and a double-extension
.pptx.lnk shortcut launching a .NET CrimsonRAT loader. Nextron Research.
· Threat Activity
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists