UPDATES
threat
UPDATES
AUSTRALIA
According to Cisco Talos, a persistent QR code phishing campaign has been targeting primarily Australian organisations since April 2026, using compromised Microsoft 365 accounts to steal credentials and spread attacks through trusted contact lists.
Cisco Talos attributed the activity to a threat actor it tracks as UAT- 11764. The campaign uses automatically generated, victim-specific PDF documents containing QR codes that redirect users to attackercontrolled Microsoft 365 credential-harvesting pages.
Once credentials are captured, the attackers attempt to access the victim’ s Microsoft account and carry out several post-compromise activities. These include creating inbox rules to evade detection, using SharePoint to host malicious documents and sending further phishing emails to internal and external contacts.
Cisco Talos assesses with high confidence that UAT-11764 is likely to continue the campaign, exploiting each newly compromised mailbox and its contact lists to expand its reach. By abusing legitimate Microsoft 365 and SharePoint infrastructure, the attackers can also circumvent many conventional email security gateways.
NORTH KOREA
North Korea-linked adversary FAMOUS CHOLLIMA has emerged as a significant threat to the AI developer ecosystem, using software supply chain attacks to compromise organisations through trusted development tools.
According to CrowdStrike’ s 2026 Threat Hunting Report, FAMOUS CHOLLIMA conducted a targeted supply chain campaign in January and February 2026 against cryptocurrency and blockchain companies by weaponising an AI-centric integrated development environment.
The adversary created outwardly legitimate project repositories, primarily hosted on GitHub, while sharing at least one repository directly through Telegram. These repositories contained legitimatelooking project files alongside hidden malicious scripts embedded in post-install hooks.
When developers opened the projects, the IDE’ s terminal or task runner automatically executed the malicious commands, requiring no further interaction from the victim. This enabled attackers to introduce malicious code into developer environments through software that appeared trustworthy.
The campaign highlights how AI development tools and open-source ecosystems are becoming attractive attack surfaces as organisations accelerate AI adoption. CrowdStrike warns that adversaries are increasingly targeting the tools, packages and infrastructure developers interact with every day.
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 35