Mailbox Rule Abuse Emerges as Stealthy Post-Compromise Threat

2026-04-13T20:52:17Z201a3e50e0e64c54baba6e8706896a10d43c59eb206e7afae2dfe194e55e6f27
ai-security-governanceandroid-trojan-miraxapache-activemq-bugapt28-dns-hijackingbitcoin-depot-breachbitter-apt-espionagechrome-session-cookie-protectionsfortinet-forticlient-ems-0daygithub-c2-covert-channelgoogle-api-keys-geminigpu-rowhammer-gpubreachgrafanaghost-ai-exfiltrationinfostealer-venom-storm-phantommacos-atomic-stealer-clickfixmicrosoft-365-mailbox-rulesninja-forms-rceoperation-atlanticphishing-w3llransomware-qilin-akira-dragonforceresidential-proxiesstx-ratsupply-chain-npm-axios

What happened

This feed highlights a surge in active post-compromise and supply‑chain threats, widespread phishing and MaaS activity, and several high‑impact vulnerabilities. Notable items include abuse of Microsoft 365 mailbox rules for stealthy persistence and exfiltration; the Mirax Android banking trojan using MaaS, remote access and residential proxying; dismantling of the $20M W3LL phishing operation and Operation Atlantic’s $12M crypto seizure; concentration of ransomware activity from Qilin, Akira and Dragonforce; emerging stealth RATs and infostealers (STX RAT, Storm, Venom, Phantom, Atomic Stealer

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
201a3e50e0e64c54baba6e8706896a10d43c59eb206e7afae2dfe194e55e6f27
Enrichment time
2026-04-13T20:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.