Obfuscated JavaScript or Nothing, (Thu, Apr 9th)
2026-04-11T07:23:52Z•c09a33cdca60135b92e1e2750872a8111a1109096ac5e04081f2eadd87bbcf69
TeamPCPTrivyUNC6780credentialsdata-thefthoneypot-fingerprintingjavascriptmalware-sampleobfuscated-jsopen-redirectsphishingrarsource-code-exposuresupply-chainvirus-totalwebshell
What happened
Collection of SANS ISC diary entries (Apr 6–10, 2026) highlighting multiple active threats: a phishing-delivered obfuscated JavaScript sample (cbmjlzan.JS, SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) inside a RAR with low AV detection (~15 engines on VirusTotal); a significant TeamPCP supply-chain campaign update reporting Cisco source-code theft via a Trivy-linked breach and GTIG tracking TeamPCP as UNC6780; and operational observations on webshells, honeypot fingerprinting, password/year usage in breached credentials, and use of redirects in phishing. Overall, an
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c09a33cdca60135b92e1e2750872a8111a1109096ac5e04081f2eadd87bbcf69
- Enrichment time
- 2026-04-11T07:23:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.