Skip to content

Image: redcanary.com · rights & removal

Executive Summary

ClearFake ranked number one on the threat list for the fourth consecutive month, utilizing JavaScript injection into compromised websites to deliver malware via drive-by download and fake CAPTCHA lures. The threat landscape saw shifts in July 2026 with familiar threats reappearing, notable departures, and new entries. JustAskJacky returned in a tie for fourth by masquerading as PDF readers, which is its first appearance on the top ten since March 2026. Amber Albatross tied for sixth by progressing through stages to a PyInstaller EXE with stealer capabilities, a debut since March 2026. Atomic Stealer and NetSupport Manager fell out of the top ten for the first time since August 2025 and September 2024, respectively. Four new threats debuted on the list: GraphSpy in a tie for fourth, Phexia in a tie for sixth, CastleRAT in a tie for tenth, and EtherRAT in a tie for tenth.

Facts Only

* ClearFake was number one in July 2026.
* JustAskJacky returned in a tie for 4th; it masqueraded as PDF readers in July 2026.
* Amber Albatross tied for 6th; it progresses to a PyInstaller EXE with stealer capabilities.
* Atomic Stealer left the list for the first time since August 2025.
* NetSupport Manager fell out of the top 10 for the first time since September 2024.
* GraphSpy debuted in a tie for 4th.
* Phexia debuted in a tie for 6th.
* CastleRAT debuted in a tie for 10th.
* EtherRAT debuted in a tie for 10th.
* GraphSpy uses a browser-based interface to abuse Entra ID and Microsoft 365 authentication tokens.
* Phexia targets macOS systems via a modular remote access tool and stealer, utilizing dead drop resolution via blockchain smart contracts.
* CastleRAT uses dead drop resolution via Pythonw and Bring Your Own Runtime execution.
* EtherRAT uses blockchain-based C2 dead drop resolution by polling Ethereum RPC endpoints.

Full Take

The recurring presence of methods like drive-by downloads, fake CAPTCHA lures, and living-off-the-land techniques exemplified by ClearFake suggests an ongoing focus on exploiting user trust and automated interaction points to facilitate initial compromise. The emergence of new threats like GraphSpy signals a shift toward targeting the identity infrastructure itself, specifically abusing authentication tokens within enterprise systems for reconnaissance rather than purely exfiltrating data. Simultaneously, the rise of blockchain-based dead drop resolution employed by Phexia and EtherRAT indicates an evolutionary step in C2 communication, moving away from easily detectable static domains to ephemeral, distributed ledger technology for operational security. This pattern suggests adversaries are developing methods that increase resilience against traditional network-based blocking and signature detection by leveraging public infrastructure ubiquity. The cost of this evolution is placed on the defenders' ability to monitor and block interactions with these increasingly abstract C2 channels. What systems are in place to assess the risk associated with allowing applications to interact with external blockchain services for operational data retrieval, and how does the focus on ephemeral C2 infrastructure alter the calculus for network perimeter defense?

From the original · Red Canary

Highlights from July For the fourth month in a row, ClearFake comes in number 1 on our top 10 most prevalent threat list.
Read the full story at redcanary.com

Sentinel — Human

Confidence

The text presents highly specific, complex technical analysis structured around threat tracking, exhibiting strong human-like depth in explaining the implications of adversarial techniques.

Signals Detected
low severity: Moderate sentence length variance with clear shifts between direct reporting and detailed technical explanation.
low severity: High internal coherence; the piece flows logically from high-level threat lists to deep dives on specific techniques.
low severity: Structured presentation via tables and clear section headings suggests an organized, non-random assembly of data.
low severity: Specific, complex technical details (e.g., Phexia's use of Polygon smart contracts, exact shell command structure) suggest deep, specialized knowledge that is characteristic of human security analysis, though the context requires verification.
Human Indicators
The density of highly specific, layered technical explanations regarding C2 resolution (EtherRAT, Phexia) and dead drop techniques implies an author deeply familiar with threat intelligence contexts.
The transition from general threat ranking to a forensic breakdown of underlying mechanisms demonstrates narrative intentionality beyond simple data dumping.
Intelligence Insights: August 2026 | Huntaegis