UAT-7810 continues building ORB networks using new malware
2026-07-07T20:51:51Z•47ec0d55ea0463ce348270694885dfc3f234d4c9c0d324ceb4d3d8bb9d3c9df8
ARTokenCOM abuseDICOM heap overflowEvilTokensMicrosoft 365ORB networkPRT persistenceSharePoint exfiltrationUAT-7810Windows threatsbusiness email compromisecustom malwaredevice code phishingemail compromisepatch tuesdayphishing-as-a-serviceprimary refresh tokenreverse engineeringsnort rulesthreat intelligencevbdecvulnerability research
What happened
Cisco Talos reports multiple noteworthy threats and research items. Key operational threats: UAT-7810 continues developing custom malware to build ORB networks, indicating ongoing active development and deployment of networked malware. ARToken, an EvilTokens affiliate phishing-as-a-service panel targeting Microsoft 365, exposes 80+ API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, email access, BEC operations, and SharePoint data exfiltration — a high-risk capability for account takeover and data theft. Additional Talos coverage includes COM abuse by Windows
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisco_talos
- Record identifier
- 47ec0d55ea0463ce348270694885dfc3f234d4c9c0d324ceb4d3d8bb9d3c9df8
- Enrichment time
- 2026-07-07T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.