CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (4 July 2026)

Published: Loading…

At a Glance

  • Citizen Lab found former European Parliament PEGA Committee member Stelios Kouloglou infected twice with NSO Group's Pegasus spyware.
  • A new Linux kernel flaw called Bad Epoll, CVE-2026-46242, lets unprivileged users gain root on Linux and Android.
  • ShinyHunters breached Medtronic's corporate IT systems in April, exposing personal and medical data of 3.8 million people.
  • Armored Likho, a newly identified APT group, deployed BusySnake Stealer against government and energy targets in Russia, Brazil and Kazakhstan.
  • AdaptHealth disclosed a breach in which attackers used social engineering against a third-party contractor to steal patient data.

Summary

Citizen Lab confirmed that former European Parliament member Stelios Kouloglou was infected twice with Pegasus spyware while serving on the committee investigating such tools. Forensic analysis linked the intrusions to the PWNYOURHOME zero-click exploit chain targeting iOS devices. Investigators found infrastructure overlap with a prior Pegasus campaign against Russian and Belarusian journalists.

A newly disclosed Linux kernel flaw, Bad Epoll (CVE-2026-46242), allows unprivileged users to escalate to root on Linux systems and Android devices. Researchers also disclosed seven unpatched vulnerabilities in FatFs, a filesystem library embedded in millions of devices including cameras and industrial controllers.

The Armored Likho APT group used spear-phishing to deploy BusySnake Stealer against government and electric power sector targets in Russia, Brazil, and Kazakhstan. A separate modular framework called Avalon delivered CrownX ransomware through a multi-stage phishing chain combining credential theft and lateral movement.

Researchers also identified North Korea-linked npm packages mimicking Rollup polyfill tools to steal developer secrets, and a phishing-as-a-service platform called ARToken targeting Microsoft 365 accounts through the EvilTokens toolkit.

Highlights of the Day

Avalon Malware Delivers CrownX Ransomware Through Multi-Stage Phishing

Blackpoint Cyber analysed a previously undocumented malware framework named Avalon, delivered through a phishing email linking to a password-protected Proton Drive archive containing an ISO image, an MSBuild project with inline C#, and an in-memory loader that bypassed AMSI and ETW before retrieving additional payloads. The final payload harvested browser, VPN, wallet and Windows credentials, communicated with the C2 endpoint helloxcherry[.]com, used WinHTTP for tasking and exfiltration, and supported lateral movement through scheduled tasks, DCOM and administrative shares. Avalon also contained the integrated CrownX ransomware, which used AES-GCM encryption, disabled Volume Shadow Copy and Windows recovery features, removed forensic artefacts, targeted virtual machine, database and engineering files, and included a direct disk destruction capability through \\.\PhysicalDrive.

Pegasus Hit EU Spyware Investigator During Parliamentary Inquiry

Citizen Lab found that former European Parliament member Stelios Kouloglou was infected with NSO Group's Pegasus spyware in October 2022 and again in March 2023 while serving on the PEGA Committee, with forensic evidence indicating exploitation through the PWNYOURHOME zero-click chain targeting iOS 15.5 devices. The investigation identified infrastructure overlap with a previously documented Pegasus campaign against Russian and Belarusian journalists, including the shared HomeKit email rauharepo888@gmail.com, but found no evidence attributing the attacks to the Greek government or any specific Pegasus customer.

Armored Likho Deploys AI-Generated BusySnake Stealer via Phishing

Kaspersky reported that the Armored Likho APT group used spear-phishing archives containing LNK and EXE payloads to deploy BusySnake Stealer, a Python-based infostealer distributed with PyArmor obfuscation and staged via PowerShell loaders, GitHub-hosted components, and scheduled tasks. The malware targets government and energy sector entities across Russia, Brazil, and Kazakhstan, harvesting clipboard data, browser credentials, screenshots, files, and cryptocurrency wallet artefacts while maintaining persistence through WindowsHelper scheduled tasks and VBScript launchers. BusySnake Stealer also integrates reverse SSH tunnelling and C2-driven command execution, with newer variants introducing COM-based task scheduling, in-memory script execution, and structured task-state tracking via SCHEDULED and IN_PROGRESS execution flows.

Linux Epoll Flaw Enables Root Privilege Escalation

Researchers disclosed Bad Epoll (CVE-2026-46242), a Linux kernel epoll subsystem race-condition use-after-free enabling unprivileged processes to escalate privileges to root on affected systems. Exploitation was demonstrated in Google kernelCTF with high reliability, with impact extending to Android devices and potential Chrome renderer sandbox escape chains. The issue originated from a 2023 kernel commit affecting epoll close paths, with fixes upstream applied via commit a6dc643c6931 across mainline Linux distributions.

Source: GitHub

Daily Coverage

Developments
Pegasus SpywareBad Epoll FlawMedtronic BreachArmored Likho
Vulnerabilities
CVE-2026-46242Linux 58C9B016E12855286370Dfb704C08498Edbc857A (High)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.SnakeTurla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging inhouse tools and malware, such as Uroburos.