UAT-7810 continues building ORB networks using new malware
2026-07-08T20:51:50Z•d0692f70a21635f80082e6c60ce330e5beee7afc80d63fa3ff19e2563e1d4502
AI-assisted analysisARTokenBECCOM abuseDICOMEvilTokensMicrosoft 365Microsoft Patch TuesdayORB networksPRT persistencePrimary Refresh TokenSharePoint exfiltrationUAT-7810Windows threatsdevice code phishingemail compromiseheap overflowmalwarephishing-as-a-servicereverse engineeringsnort rulestelemetrythreat huntingvbdecvulnerability research
What happened
Cisco Talos published a multi-topic feed highlighting active malicious tooling and defensive research. Notable findings: UAT-7810 continues developing custom malware to build ORB networks; ARToken (an EvilTokens affiliate phishing-as-a-service) targets Microsoft 365 with 80+ API endpoints for device-code phishing, Primary Refresh Token persistence, email/SharePoint exfiltration and BEC operations. Other posts cover COM abuse by Windows threats, AI-assisted local reverse engineering via vbdec’s live COM interface, a DICOM-related heap overflow case study, and Microsoft Patch Tuesday coverage (v
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisco_talos
- Record identifier
- d0692f70a21635f80082e6c60ce330e5beee7afc80d63fa3ff19e2563e1d4502
- Enrichment time
- 2026-07-08T20:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.