Telegram-Based Millenium RAT Campaign Infects 60,000 Devices
2026-06-29T14:52:14Z•d43ef593b631cf17d7432dcfe9653a0333fffe350bfb4caeb634d01a62418459
Cisco Catalyst SD-WANEDR-killerGentleKillerKlue breach (OAuth)Mastra supply-chainMillenium RATOperation EndgameOracle PeopleSoftTinyRCTbackdoorbootrom-exploitcritical-infrastructuredata-breachdestructive-attackinfostealermacOS vulnerabilitymalwarenation-statenpm-malwarepre-disclosure-exploitationransomwareremote-access-trojansupply-chainunpatchablezero-day
What happened
Multiple high-impact cyber incidents and vulnerability disclosures reported: a Telegram-distributed Millenium RAT campaign (rewritten in C++) has infected ~62,289 devices across 160+ countries; the US insurance regulator NAIC suffered a breach via an exploited Oracle PeopleSoft zero-day; a destructive, novel ransomware-like attack against Jaguar Land Rover shows indicators of Kremlin-linked actors; and a China-linked group is using a new TinyRCT backdoor against Southeast Asian critical infrastructure. Additional notable items include pre-disclosure exploitation of a high-severity Cisco SD-WAN
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- d43ef593b631cf17d7432dcfe9653a0333fffe350bfb4caeb634d01a62418459
- Enrichment time
- 2026-06-29T14:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.