RST TI Report Digest: 20 Jul 2026
ID: ceb25b78-48d0-5c4d-a3cc-06d0c0dab737
STIX ID: report--ceb25b78-48d0-5c4d-a3cc-06d0c0dab737
Feed Name: RST Cloud Blog
**UAC-0247 (UAC-0244) campaign targeting hospitals and local governments** — The report documents an active, targeted campaign delivering multi-stage loaders and malware (RAVENSHELL, AGINGFLY, SILENTLOOP, CHROMELEVATOR, ZAPIXDESK) via deceptive humanitarian-themed emails and malicious HTA/archives, using DLL sideloading, scheduled tasks, and various tunneling/scanning tools for lateral movement; it provides numerous IOCs (IPs, domains, URLs, hashes, emails) and notes a March 10, 2026 compromise involving a malicious FPV software update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
