Obfuscated JavaScript or Nothing, (Thu, Apr 9th)

2026-04-11T07:23:52Zc09a33cdca60135b92e1e2750872a8111a1109096ac5e04081f2eadd87bbcf69
TeamPCPTrivyUNC6780credentialsdata-thefthoneypot-fingerprintingjavascriptmalware-sampleobfuscated-jsopen-redirectsphishingrarsource-code-exposuresupply-chainvirus-totalwebshell

What happened

Collection of SANS ISC diary entries (Apr 6–10, 2026) highlighting multiple active threats: a phishing-delivered obfuscated JavaScript sample (cbmjlzan.JS, SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) inside a RAR with low AV detection (~15 engines on VirusTotal); a significant TeamPCP supply-chain campaign update reporting Cisco source-code theft via a Trivy-linked breach and GTIG tracking TeamPCP as UNC6780; and operational observations on webshells, honeypot fingerprinting, password/year usage in breached credentials, and use of redirects in phishing. Overall, an

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
c09a33cdca60135b92e1e2750872a8111a1109096ac5e04081f2eadd87bbcf69
Enrichment time
2026-04-11T07:23:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.