Image: redcanary.com · rights & removal
Intelligence Insights: August 2026
Reporting by Red CanaryRead the original at redcanary.com
Executive Summary
Facts Only
* ClearFake was number one in July 2026.
* JustAskJacky returned in a tie for 4th; it masqueraded as PDF readers in July 2026.
* Amber Albatross tied for 6th; it progresses to a PyInstaller EXE with stealer capabilities.
* Atomic Stealer left the list for the first time since August 2025.
* NetSupport Manager fell out of the top 10 for the first time since September 2024.
* GraphSpy debuted in a tie for 4th.
* Phexia debuted in a tie for 6th.
* CastleRAT debuted in a tie for 10th.
* EtherRAT debuted in a tie for 10th.
* GraphSpy uses a browser-based interface to abuse Entra ID and Microsoft 365 authentication tokens.
* Phexia targets macOS systems via a modular remote access tool and stealer, utilizing dead drop resolution via blockchain smart contracts.
* CastleRAT uses dead drop resolution via Pythonw and Bring Your Own Runtime execution.
* EtherRAT uses blockchain-based C2 dead drop resolution by polling Ethereum RPC endpoints.
Full Take
From the original · Red Canary
Highlights from July For the fourth month in a row, ClearFake comes in number 1 on our top 10 most prevalent threat list.Read the full story at redcanary.com
Sentinel — Human
The text presents highly specific, complex technical analysis structured around threat tracking, exhibiting strong human-like depth in explaining the implications of adversarial techniques.
