UAT-7810 continues building ORB networks using new malware

2026-07-08T20:51:50Zd0692f70a21635f80082e6c60ce330e5beee7afc80d63fa3ff19e2563e1d4502
AI-assisted analysisARTokenBECCOM abuseDICOMEvilTokensMicrosoft 365Microsoft Patch TuesdayORB networksPRT persistencePrimary Refresh TokenSharePoint exfiltrationUAT-7810Windows threatsdevice code phishingemail compromiseheap overflowmalwarephishing-as-a-servicereverse engineeringsnort rulestelemetrythreat huntingvbdecvulnerability research

What happened

Cisco Talos published a multi-topic feed highlighting active malicious tooling and defensive research. Notable findings: UAT-7810 continues developing custom malware to build ORB networks; ARToken (an EvilTokens affiliate phishing-as-a-service) targets Microsoft 365 with 80+ API endpoints for device-code phishing, Primary Refresh Token persistence, email/SharePoint exfiltration and BEC operations. Other posts cover COM abuse by Windows threats, AI-assisted local reverse engineering via vbdec’s live COM interface, a DICOM-related heap overflow case study, and Microsoft Patch Tuesday coverage (v

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
d0692f70a21635f80082e6c60ce330e5beee7afc80d63fa3ff19e2563e1d4502
Enrichment time
2026-07-08T20:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · UAT-7810 continues building ORB networks using new malware · Baitaphish