Analysis of a Year of Files Uploaded to DShield Sensors, (Wed, May 27th)

2026-05-29T01:23:46Zc7f6ffb0ec49a4303fa91cfb2f735db7addd80851ac53fa73462ba82fc11608e
ACR-stealerAkiraGitHubTeamPCPcredential-stealerdshieldforensicsmicrosoft-accesspython-sdkransomwaresoftware-trojansupply-chaintelemetryvbavulnerabilitywireshark

What happened

This ISC SANS diary digest highlights multiple security items: a TeamPCP supply-chain campaign that trojanized packages across three ecosystems and even an officially Microsoft-published Python SDK (with the actor publishing parts of its framework on GitHub); an Akira ransomware forensic analysis emphasizing the importance of joining perimeter firewall and Windows event logs to reconstruct pre-impact activity; a reported page impersonating Claude that may be distributing an ACR credential stealer; an analysis of files uploaded to DShield sensors showing upload activity peaking Dec 2025–Feb 202

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
c7f6ffb0ec49a4303fa91cfb2f735db7addd80851ac53fa73462ba82fc11608e
Enrichment time
2026-05-29T01:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.