Police dismantle Kratos phishing platform, arrest developer
2026-07-22T01:23:32Z•68ad5c293f311456bfb52d4ea171713e45eba83c8d045b7b207b6236f6ad6960
AnubisCVE-2026-50522CVE-2026-60137CVE-2026-63030Coca-Cola-FairlifeFakeGitGitHub-malware-reposGlobalProtectKratosPAN-OSQilinSharePointSmartLoaderSonicWall-SMA1000StealCWindows-LegacyHiveagentic-AI-attacks','EncForgelaw-enforcement-takedownmachine-key-theftphishing-as-a-serviceransomwareunofficial-patcheswebshellswp2shellzero-day
What happened
Multiple high-impact active threats and law-enforcement actions were reported: German and US authorities dismantled the Kratos phishing-as-a-service infrastructure and an Indonesian developer was arrested; a large FakeGit operation used ~7,600 malicious GitHub repos to distribute SmartLoader and StealC malware; threat actors are actively exploiting critical Microsoft SharePoint RCE CVE-2026-50522 to steal machine keys and maintain persistence; WordPress ‘‘wp2shell’’ flaws (CVE-2026-63030, CVE-2026-60137) are being used to deploy persistent webshells and malicious plugins; the Qilin ransomware团
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 68ad5c293f311456bfb52d4ea171713e45eba83c8d045b7b207b6236f6ad6960
- Enrichment time
- 2026-07-22T01:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.