Analysis of a Year of Files Uploaded to DShield Sensors, (Wed, May 27th)
2026-05-29T01:23:46Z•c7f6ffb0ec49a4303fa91cfb2f735db7addd80851ac53fa73462ba82fc11608e
ACR-stealerAkiraGitHubTeamPCPcredential-stealerdshieldforensicsmicrosoft-accesspython-sdkransomwaresoftware-trojansupply-chaintelemetryvbavulnerabilitywireshark
What happened
This ISC SANS diary digest highlights multiple security items: a TeamPCP supply-chain campaign that trojanized packages across three ecosystems and even an officially Microsoft-published Python SDK (with the actor publishing parts of its framework on GitHub); an Akira ransomware forensic analysis emphasizing the importance of joining perimeter firewall and Windows event logs to reconstruct pre-impact activity; a reported page impersonating Claude that may be distributing an ACR credential stealer; an analysis of files uploaded to DShield sensors showing upload activity peaking Dec 2025–Feb 202
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c7f6ffb0ec49a4303fa91cfb2f735db7addd80851ac53fa73462ba82fc11608e
- Enrichment time
- 2026-05-29T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.