🚨Here are the top malicious infrastructure threats observed during July 2026, based on intelligence collected by our CTI team.
Last month, Amnesia Stealer remained the most frequently observed threat, while Cobalt Strike, AdaptixC2, and SuperShell C2 all saw increased activity.
These trends provide valuable insight into the tools and infrastructure threat actors continue to leverage across the cyber threat landscape.
Explore our latest Intelligence Insights to discover the threats security teams should be monitoring. ⬇️
Tycoon 2FA quickly returned after a temporary disruption, highlighting how resilient phishing-as-a-service operations have become. Discover what this means for defenders.
Read more ➡️https://t.co/jrbNzHVvoK
#BCONCollective#CTI#Tycoon2FA
Threat actors continue to exploit trusted brands. We analysed a phishing campaign targeting the hospitality sector and explain what security teams can learn from the attackers' tactics.
Read more ➡️https://t.co/4bqsMVKpTn
#BCONCollective#CTI#Phishing
Of the three ShinyHunters victims that appear in our recent blog, the average time between domain creation/update is 12.7 days. The time to identify and block is less than that. Make sure proactive monitoring for domain impersonation and COM registration patterns is in place.
Last week, we shared intelligence on an active campaign observed targeting one of Bridewell's customers - sharing domains indicating wider com-affiliated activity. Today, another org in our data set (RingCentral) has been published by ShinyHunters.
LegacyHive is a new, unpatched local privilege escalation vulnerability that targets the Windows User Profile service. Disclosed in July by independent researcher, Nightmare Eclipse, this exploit enables a standard user to mount, read or modify another user's registry hive.
Bridewell's BCON Collective has developed a threat hunting package, targeting the main stages of the attack chain, covering:
1. GUID Root Staging
2. User Shell Redirection
3. Offreg Dll Loading
4. COM Object Hijacking
5. Anomalous User Directory Logons
What organisations should do:
✅ Review and block the published IOCs
✅ Be wary of unsolicited IT support or “ticket closure” calls, particularly to personal devices
✅ Always verify help-desk requests through a trusted internal channel
🚨 From a fake IT support ticket to uncovering a wider Com-affiliated vishing campaign.
Bridewell is tracking an active, accelerating wave of Com-affiliated vishing activity. Here’s how one vishing call against a customer led to a much broader investigation. ��
#BCONCollective
Registration data for this naming pattern accelerated sharply in the two weeks before this incident, suggesting a new wave of activity.
Current targeting appears to focus on:
• Finance
• Technology
• Retail
One of those sub-clusters (passkey) aligns closely with infrastructure previously associated with Pink (CL-CRI-1147).
Our assessment: this activity is most likely ShinyHunters tradecraft, or a Com-affiliated actor using ShinyHunters-consistent infrastructure.
(c) to evade automated detection.
Post 4
Fingerprinting the kit’s favicon, redirect behaviour and DOM structure uncovered 100+ related domains across four naming conventions:
• helpdesk-
• it.*.support
• passkey
• Older https://t.co/hBbJ7XCOqz typo squats
Behind that blocked page was:
• A fake Okta login
• Protected by a fraudulent Cloudflare CAPTCHA
A legitimate Turnstile widget was wrapped in fake “verifying you’re human” branding. The phishing kit also silently redirected bots and sandboxes to https://t.co/gMMHo0IjQA
The attack began with:
• A spoofed caller ID
• A fabricated IT support ticket
• Pressure to bypass the organisation’s legitimate help desk
The employee attempted to access the “alternate access” link, but security controls blocked it before any credentials were entered.