This month in security with Tony Anscombe – June 2026 edition

2026-07-01T08:51:40Z69dacf2786e7bbf8648ad1ebc792be7990b92192e50dba137fce4b9f037bb965
APTAmadeyAndroid RATC2 abuse of legitimate servicesEDR bypassEvilTokensFishMongerGamaredonStealcWindowsbackdoorbotnet disruptioncredentialless takeoverexfiltrationinfostealerkernel drivermalwareoperation_endgamephishingsupply chain

What happened

Collection of ESET WeLiveSecurity June 2026 posts covering active APT campaigns, new malware tooling, large-scale botnet/infostealer takedown, and evolving social-engineering/phishing techniques. Notable items: Gamaredon’s 2025 toolset using legitimate online services for C2 and exfiltration; ESET’s participation in Operation Endgame disrupting the Amadey botnet and Stealc infostealer; discovery of SprySOCKS (FishMonger) — a Windows backdoor leveraging a kernel driver for stealth; EvilTokens phishing kit that bypasses passwords by subverting Microsoft authentication flows; Gentlemen RaaS EDR-k

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
69dacf2786e7bbf8648ad1ebc792be7990b92192e50dba137fce4b9f037bb965
Enrichment time
2026-07-01T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · This month in security with Tony Anscombe – June 2026 edition · Baitaphish