Out of the Crypt: The Evolving Cyber Extortion Economy
2026-05-28T08:51:41Z•e568173fcbee6951bc6a45d023fff9b6d12c6f8fcc27dfd2c5ac0bb3f305bd78
AD CS exploitationAPTActive Directory Certificate ServicesAppDomainManager hijackCI/CD persistenceCVE-2026-0300CVE-2026-31431Copy FailGremlin stealerIranian APTLinux kernel LPEPAN-OS captive portalRATROADtoolsScreening Serpenscloud intrusionscredential theftcyber extortiondata theftgen‑AI browser extensions privacy risk','autonomous AI attacks (malvertisingnpm supply chainobfuscationransomwaretrojanized apps
What happened
Unit 42 (Palo Alto Networks) published multiple May 2026 threat reports covering an array of high-impact topics: the evolving cyber extortion and data‑theft economy; Iranian APT “Screening Serpens” using AppDomainManager hijacking and new RAT variants against tech and defense targets; misuse of the open‑source ROADtools framework for cloud intrusions; an updated npm supply‑chain threat landscape with wormable malware, CI/CD persistence and multi‑stage attacks; TamperedChef clusters delivering trojanized productivity apps via malvertising; an evolved Gremlin stealer using advanced obfuscation,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- e568173fcbee6951bc6a45d023fff9b6d12c6f8fcc27dfd2c5ac0bb3f305bd78
- Enrichment time
- 2026-05-28T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.