SOCRadar uncovered a phishing-as-a-service platform that rents out AI voice agents posing as Apple Support to trick stolen-iPhone victims into handing over their Activation Lock passcode.
Profiling adversary groups targeting AI systems and leveraging AI in their operations.
SOCRadar uncovered a phishing-as-a-service platform that rents out AI voice agents posing as Apple Support to trick stolen-iPhone victims into handing over their Activation Lock passcode.
ESET discovered PromptSpy in February 2026 — the first known Android malware to query a live generative AI API at runtime. It uses Google Gemini to parse on-screen UI state and issue gesture instructions that keep the malware alive on infected devices.
Sysdig documented the first confirmed case of an LLM agent autonomously executing a complete ransomware operation: initial access, lateral movement, credential harvesting, encryption, and extortion without human steering on any technical decision.
Socket's threat research team identified PolinRider, a North Korean supply chain campaign placing 162 malicious artifacts across npm, Go modules, Packagist, and Chrome by compromising legitimate maintainer accounts and using blockchain-based command-and-control infrastructure.
TeamPCP, tracked as UNC6780 by Google's Threat Intelligence Group, ran three coordinated supply chain campaigns in 2026 — poisoning Trivy, LiteLLM, and 170+ npm/PyPI packages — culminating in the theft of 3,800 GitHub internal repositories.