Trellix Uncovers DarkSword, JSCeal, Axios NPM Attacks, and APT28 Campaigns

Advanced Research Center Uncovers New Cyber Threats in Latest Report

Trellix’s Advanced Research Center has unveiled its latest SecondSight Threat Hunting Report, which analyzes cyber activities recorded from January 1 to June 30, 2026. The findings, shared exclusively with Hackread.com, elucidate several sophisticated cyber campaigns characterized by targeted phishing efforts, abuse of trusted software, and various evasion strategies.

One notable incident documented in the report is the DarkSword iOS exploit campaign, where threat actors dispatched a sequence of four emails within a narrow 66-minute window. These communications were directed to senior officials at organizations aligned with NATO, masquerading as Frederick Kempe, the president of the Atlantic Council. The emails solicited attendance at a bogus “Closed-Door Strategic Discussion,” targeting high-profile individuals from a Central European presidential office, a European foreign affairs ministry, a US federal agency, and a European aerospace firm.

The links embedded in these emails directed recipients to phishing pages that hosted the DarkSword exploit chain, affecting iOS versions 18.4 through 18.7. This exploit chain leveraged six distinct vulnerabilities, allowing a compromised iPhone to be manipulated simply by clicking on the malicious link, requiring no further interaction from the user. In a sophisticated maneuver, the attackers implemented server-side filtering, displaying a legitimate-looking PDF to security scanners while targeting intended recipients with the exploit.

Trellix confidently attributes this campaign to a Russian threat actor closely associated with activities reminiscent of Star Blizzard, although the specific origins of the DarkSword exploit kit remain less conclusive.

In another analysis, Trellix investigated a campaign aimed at organizations in Southeast Asia utilizing the JSCeal information stealer. This operation initiated through an encoded PowerShell script that disabled system proxy settings, subsequently downloading Node.js along with an encrypted application script disguised under the guise of legitimate system components. Once executed, JSCeal decrypted its payload using AES-256-CBC and decompressed it with Brotli, enabling it to capture a range of sensitive data including browser passwords, cookies, cryptocurrency wallet details, keystrokes, and screenshots.

Additional insights into cyber threats involve significant incidents such as the compromise of the npm account by attackers on March 31, where malicious versions of 1.14.1 and 0.30.4 were released. Although the source code of Axios itself remained unaltered, the malicious packages installed platform-specific remote access Trojans originating from sfrclak.com:8000. Trellix reported that this malicious execution occurred in 3% of exposed environments, underscoring the pervasive risks of supply chain vulnerabilities.

Other campaigns included a FIFA-themed phishing operation linked to the Bitter APT group, which targeted a European embassy in Asia in June 2026. This operation cleverly disguised its malicious intent within a legitimate diplomatic email thread related to a supposed FIFA World Cup event, significantly enhancing its credibility. Attackers hijacked existing communication to deliver a ZIP file containing a VHDX image that executed PowerShell, eventually deploying the BDarkRAT malware through a scheduled task.

The report highlights additional activity from APT28, also known as Fancy Bear, focusing on government and defense entities across nine Eastern European nations in late January. This group rapidly weaponized a new vulnerability, CVE-2026-21509, shortly after its public disclosure. They utilized RTF files disguised as .doc documents to deliver either the CovenantGrunt implant or NotDoor, a VBA backdoor that can exfiltrate email data and receive commands from attackers.

Throughout these incidents, Trellix’s Email Security successfully intercepted all 29 malicious emails before they could be delivered, emphasizing the importance of robust cybersecurity measures in mitigating risks.

The collection of these cases encompasses a wide spectrum of cyber threats ranging from iPhone exploitation to diplomatic phishing, all tied to a broader theme of government espionage observed during the first half of 2026. Security experts, such as Jason Soroko from Sectigo, caution organizations against complacency, stressing the need for vigilance in scrutinizing both familiar senders and applications. He advises that thorough threat hunting must assess what trusted software initiates, the credentials it accesses, and the connections it makes, alongside the necessity of urgent patching and proactive exposure investigation.

In recapping these significant threats, business owners are reminded of the critical nature of cybersecurity vigilance in today’s digital landscape, necessitating a comprehensive understanding of the tactics outlined in the MITRE ATT&CK framework as a means to bolster defenses against evolving adversarial methods.

Source