logo

Cyber-Actors are “Laundering Trust” to Hijack the Global Supply Chain

ID: fd511b02-4aa6-5d9d-878e-02cc72f9946a

STIX ID: report--fd511b02-4aa6-5d9d-878e-02cc72f9946a

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Proofpoint uncovered a month-long, operator-driven intrusion campaign targeting transportation firms that began with load-board phishing delivering a VBS decoy and PowerShell-based remote access installation. The actor deployed multiple RMM/backdoor tools (ScreenConnect, Pulseway, SimpleHelp) for redundancy, executed extensive PowerShell reconnaissance to identify financially valuable targets (banks, fuel card services, fleet payment platforms, browser extensions and crypto wallets), and abused a third-party signing-as-a-service (signer.bulbcentral.com) to re-sign malicious binaries, enabling trust bypass and prolonged persistence for financial theft and cargo diversion operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.