ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
This ThreatsDay report details a range of sophisticated cyberattacks, including CEO phishing kits, large-scale Dropbox account hacks, and OAuth traps, alongside 17 other security incidents.
Intelligence analysis by Gemini 2.5 Flash

The latest ThreatsDay bulletin highlights how attackers are increasingly leveraging social engineering and legitimate tools to gain access, impersonating IT support, deploying advanced phishing-as-a-service platforms, and utilizing ransomware playbooks to compromise organizations across various sectors.
Imagine a sneaky trickster who pretends to be your school's IT helper or a friend sharing a file. They might ask you to click a button or install a program, but it's actually a trap to get into your computer and steal your secrets, like your passwords or important documents. Sometimes, they even use special tools to lock up your files and demand money to unlock them, just like a digital kidnapper. It's all about tricking people into opening the door for them.
Analysis
The landscape of cyber threats continues to evolve, with a clear trend towards exploiting human trust and legitimate software functionalities. This edition of ThreatsDay underscores the sophistication of modern attack campaigns, moving beyond simple malware to intricate social engineering and abuse of trusted platforms. The common thread across many of these incidents is the attackers' ability to make their malicious activities appear normal, blurring the lines between legitimate interactions and dangerous traps.
Microsoft Teams
Microsoft has issued warnings regarding human-operated intrusion campaigns that exploit Microsoft Teams' external collaboration features. Threat actors are impersonating IT or help desk personnel to socially engineer users into granting interactive remote sessions. Once remote control is established via Remote Monitoring and Management (RMM) tools, the attackers deploy malicious MSI packages, staging Node.js runtimes and obfuscated JavaScript implants for persistent command execution and control. This allows for extensive host and Active Directory reconnaissance, screenshot capture, and lateral movement towards high-value assets like domain controllers, highlighting the severe impact of such interactive access to internal infrastructure.
Another coordinated social engineering operation, dubbed Spring Ring, has also been observed abusing Microsoft Teams. This campaign involves external Teams accounts masquerading as IT help desk personnel to target over 150 employees across at least 10 companies. These seemingly benign chats escalate into voice phishing (vishing) calls, coercing victims into executing RMM tools or custom malware. In more advanced variants, attackers transition to Microsoft NT LAN Manager (NTLM) relay attacks aimed at an organization's domain controller, demonstrating a significant escalation in tactics and the potential for widespread compromise through a trusted communication platform.
The Gentlemen Ransomware
Sophos has released a detailed report on The Gentlemen ransomware operation, which it tracks as Gold Sherwood. This group has claimed a staggering 683 victims by the end of July 2026, with 169 new victims added in July alone. The operation's success is attributed to a repeatable affiliate playbook that combines opportunistic initial access with rapid privilege escalation. This playbook leverages legitimate remote access mechanisms, stages tools in trusted system paths, and executes targeted data exfiltration.
The affiliates of The Gentlemen ransomware demonstrate remarkable operational flexibility. They utilize a diverse toolkit including native Windows utilities, commercial and open-source tools, BYOVD-based EDR killers, and backup service tampering. This adaptability allows them to tailor their attacks to specific victim environments, maximizing impact before the final encryption stage. The consistent growth in victim count underscores the effectiveness of their methods and the persistent threat posed by ransomware-as-a-service models.
BlueKit PhaaS
ZeroBEC has provided insights into BlueKit, a turnkey phishing-as-a-service (PaaS) platform specifically designed to target CEOs of financial-industry groups. This sophisticated service facilitates credential theft through a browser-in-the-middle (BitM) infrastructure. The campaigns typically employ document-sharing lures to initiate the attack chain, utilizing ZeroBot to screen for bots and ensure human interaction. This focus on high-value targets like CEOs indicates a strategic approach to maximize potential financial gain and access to sensitive corporate data.
The BlueKit campaign extends beyond mere credential or session theft, suggesting a more comprehensive attack objective. The availability of such advanced phishing kits as a service lowers the barrier for entry for less skilled attackers, enabling them to launch highly effective and targeted campaigns. The resilience of phishing-as-a-service platforms, as seen with Outsider resurfacing despite law enforcement action, further complicates defensive efforts, as these services continue to evolve and adapt to countermeasures, making them a persistent and adaptable threat in the cybercrime ecosystem.
Key points
- Threat actors are impersonating IT support via Microsoft Teams to socially engineer users into granting remote access and deploying malware.
- The 'Spring Ring' operation uses Teams vishing to target employees across multiple companies, escalating to NTLM relay attacks on domain controllers.
- The Gentlemen ransomware operation has claimed 683 victims by July 2026, utilizing a flexible affiliate playbook for initial access, privilege escalation, and data exfiltration.
- Phishing-as-a-service platforms like Outsider and BlueKit remain resilient, offering turnkey solutions for credential theft, including highly targeted campaigns against CEOs.
- Government-themed tax campaigns are using DLL sideloading with legitimate software to establish persistence and connect to external command-and-control servers.
The continued evolution of phishing-as-a-service platforms and the increasing sophistication of social engineering attacks, particularly those leveraging trusted communication tools like Microsoft Teams, suggest that organizations will face an uphill battle in defending against these highly adaptable threats. The consistent success of ransomware operations like The Gentlemen indicates that current defensive measures are often insufficient, leading to ongoing data breaches and significant financial losses.



