logo

Intelligence Insights: May 2026

ID: 4d79b22c-1100-541c-ae3b-3c08595e0992

STIX ID: report--4d79b22c-1100-541c-ae3b-3c08595e0992

Feed Name: Red Canary

Threat Score
70/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: The Red Canary Team

...
...

Monthly highlights: ClearFake—an activity cluster delivering malware via JavaScript-injected drive-by downloads and fake CAPTCHA paste-and-run lures—rises to the top of the prevalence list, delivering payloads including ArechClient2, LummaC2 and the newly observed ACR Stealer. GraphRunner and OAuth device code abuse are increasing as adversaries exploit Microsoft Graph and device authentication grants (also offered via PhaaS like Kali365/EvilTokens) to bypass MFA and exfiltrate data; recommended mitigations include blocking device code flows, limiting device join permissions, and enabling continuous access evaluation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.