MSP cybersecurity news digest, January 5, 2026
ID: 04d95b55-c85c-595c-ae96-b1e80e90f22c
STIX ID: report--04d95b55-c85c-595c-ae96-b1e80e90f22c
Feed Name: TRU Security by Acronis
This report summarizes several active and high-impact campaigns: Mustang Panda deploying a ToneShell backdoor via a signed kernel-mode loader against government targets; a large-scale fake KMSAuto campaign distributing malware that manipulates clipboard/crypto addresses and enabled widespread crypto theft; compromised browser extensions (Trust Wallet and multiple Zoom-themed extensions) used to steal funds and corporate meeting data; and GlassWorm trojanized developer extensions targeting macOS. The incidents highlight a trend of blending malicious implants with trusted components (signed drivers, extensions, stealth loaders) and supply-chain/marketplace compromises to scale theft, persistence, and evasion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
