Mailbox Rule Abuse Emerges as Stealthy Post-Compromise Threat
2026-04-13T20:52:17Z•201a3e50e0e64c54baba6e8706896a10d43c59eb206e7afae2dfe194e55e6f27
ai-security-governanceandroid-trojan-miraxapache-activemq-bugapt28-dns-hijackingbitcoin-depot-breachbitter-apt-espionagechrome-session-cookie-protectionsfortinet-forticlient-ems-0daygithub-c2-covert-channelgoogle-api-keys-geminigpu-rowhammer-gpubreachgrafanaghost-ai-exfiltrationinfostealer-venom-storm-phantommacos-atomic-stealer-clickfixmicrosoft-365-mailbox-rulesninja-forms-rceoperation-atlanticphishing-w3llransomware-qilin-akira-dragonforceresidential-proxiesstx-ratsupply-chain-npm-axios
What happened
This feed highlights a surge in active post-compromise and supply‑chain threats, widespread phishing and MaaS activity, and several high‑impact vulnerabilities. Notable items include abuse of Microsoft 365 mailbox rules for stealthy persistence and exfiltration; the Mirax Android banking trojan using MaaS, remote access and residential proxying; dismantling of the $20M W3LL phishing operation and Operation Atlantic’s $12M crypto seizure; concentration of ransomware activity from Qilin, Akira and Dragonforce; emerging stealth RATs and infostealers (STX RAT, Storm, Venom, Phantom, Atomic Stealer
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 201a3e50e0e64c54baba6e8706896a10d43c59eb206e7afae2dfe194e55e6f27
- Enrichment time
- 2026-04-13T20:52:17Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.