This month in security with Tony Anscombe – June 2026 edition
2026-07-01T08:51:40Z•69dacf2786e7bbf8648ad1ebc792be7990b92192e50dba137fce4b9f037bb965
APTAmadeyAndroid RATC2 abuse of legitimate servicesEDR bypassEvilTokensFishMongerGamaredonStealcWindowsbackdoorbotnet disruptioncredentialless takeoverexfiltrationinfostealerkernel drivermalwareoperation_endgamephishingsupply chain
What happened
Collection of ESET WeLiveSecurity June 2026 posts covering active APT campaigns, new malware tooling, large-scale botnet/infostealer takedown, and evolving social-engineering/phishing techniques. Notable items: Gamaredon’s 2025 toolset using legitimate online services for C2 and exfiltration; ESET’s participation in Operation Endgame disrupting the Amadey botnet and Stealc infostealer; discovery of SprySOCKS (FishMonger) — a Windows backdoor leveraging a kernel driver for stealth; EvilTokens phishing kit that bypasses passwords by subverting Microsoft authentication flows; Gentlemen RaaS EDR-k
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 69dacf2786e7bbf8648ad1ebc792be7990b92192e50dba137fce4b9f037bb965
- Enrichment time
- 2026-07-01T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.