Cargo thieving hackers running sophisticated remote access campaigns, researchers find

2026-04-17T08:51:39Zf0c7d647c82dac830076b49ed60ec16323e8cbca52eb5aa7dbdfc546da45bfd1
AI agentsAI securityMicrosoft 365RATRussiacargo theftemail fraudemail rule abuseexfiltrationiOS spywareiPhone spywareinsider risklogistics attacksmailbox rulesnation-statepersistencephishingremote accesssupply chainthreat intelligence

What happened

Proofpoint newsroom feed (Apr 2026) highlighting multiple active threat trends: a cargo‑theft actor running sophisticated remote‑access campaigns targeting logistics/shipping; abuse of Microsoft 365 mailbox rules for data exfiltration and persistence; elevated email‑fraud risk tied to FIFA World Cup partners; reports of suspected Russian iPhone spyware; and broader coverage of AI security, AI agents changing insider‑risk models, and defensive guidance for M&A. These items indicate active, targeted threats against enterprise email and logistics, nation‑state spyware concerns, and emerging risks

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
proofpoint_blog
Record identifier
f0c7d647c82dac830076b49ed60ec16323e8cbca52eb5aa7dbdfc546da45bfd1
Enrichment time
2026-04-17T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Cargo thieving hackers running sophisticated remote access campaigns, researchers find · Baitaphish