Telegram-Based Millenium RAT Campaign Infects 60,000 Devices

2026-06-29T14:52:14Zd43ef593b631cf17d7432dcfe9653a0333fffe350bfb4caeb634d01a62418459
Cisco Catalyst SD-WANEDR-killerGentleKillerKlue breach (OAuth)Mastra supply-chainMillenium RATOperation EndgameOracle PeopleSoftTinyRCTbackdoorbootrom-exploitcritical-infrastructuredata-breachdestructive-attackinfostealermacOS vulnerabilitymalwarenation-statenpm-malwarepre-disclosure-exploitationransomwareremote-access-trojansupply-chainunpatchablezero-day

What happened

Multiple high-impact cyber incidents and vulnerability disclosures reported: a Telegram-distributed Millenium RAT campaign (rewritten in C++) has infected ~62,289 devices across 160+ countries; the US insurance regulator NAIC suffered a breach via an exploited Oracle PeopleSoft zero-day; a destructive, novel ransomware-like attack against Jaguar Land Rover shows indicators of Kremlin-linked actors; and a China-linked group is using a new TinyRCT backdoor against Southeast Asian critical infrastructure. Additional notable items include pre-disclosure exploitation of a high-severity Cisco SD-WAN

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
d43ef593b631cf17d7432dcfe9653a0333fffe350bfb4caeb634d01a62418459
Enrichment time
2026-06-29T14:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.