UAT-7810 continues building ORB networks using new malware

2026-07-07T20:51:51Z47ec0d55ea0463ce348270694885dfc3f234d4c9c0d324ceb4d3d8bb9d3c9df8
ARTokenCOM abuseDICOM heap overflowEvilTokensMicrosoft 365ORB networkPRT persistenceSharePoint exfiltrationUAT-7810Windows threatsbusiness email compromisecustom malwaredevice code phishingemail compromisepatch tuesdayphishing-as-a-serviceprimary refresh tokenreverse engineeringsnort rulesthreat intelligencevbdecvulnerability research

What happened

Cisco Talos reports multiple noteworthy threats and research items. Key operational threats: UAT-7810 continues developing custom malware to build ORB networks, indicating ongoing active development and deployment of networked malware. ARToken, an EvilTokens affiliate phishing-as-a-service panel targeting Microsoft 365, exposes 80+ API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, email access, BEC operations, and SharePoint data exfiltration — a high-risk capability for account takeover and data theft. Additional Talos coverage includes COM abuse by Windows

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
47ec0d55ea0463ce348270694885dfc3f234d4c9c0d324ceb4d3d8bb9d3c9df8
Enrichment time
2026-07-07T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.