Executive Summary
Facts Only
* ClearFake ranked number 1 on the top 10 threat list for the fourth consecutive month in July 2026.
* JustAskJacky returned in a tie for 4th place, masquerading as PDF readers in July 2026.
* Amber Albatross tied for 6th place, delivered via installers masquerading as free software leading to a PyInstaller EXE with stealer capabilities.
* Atomic Stealer left the top 10 for the first time since August 2025.
* NetSupport Manager fell out of the top 10 for the first time since September 2024.
* GraphSpy debuted in a tie for 4th place, functioning as an open source tool to abuse Entra ID and Microsoft 365 authentication tokens.
* Phexia debuted in a tie for 6th place, targeting macOS systems with modular stealer components utilizing blockchain smart contracts for C2 domain discovery.
* CastleRAT debuted in a tie for 10th place, a remote access trojan with keylogging and screen capturing capabilities.
* EtherRAT debuted in a tie for 10th place, a Node.js-based RAT using blockchain-based C2 resolution targeting Windows workstations and Linux servers.
* Dead drop resolution is a technique used by Phexia, CastleRAT, and EtherRAT to locate command and control infrastructure via public web services or blockchain endpoints.
Full Take
From the original · Red Canary
Zscaler Blog Get the latest Zscaler blog updates in your inbox Intelligence Insights: August 2026 Debuts, departures, and danger on the blockchain in this month’s edition of Intelligence Insights This article was originally published by Red Canary, which is now part of Zscaler. Highlights from July For the fourth month in a row, ClearFake comes in number 1 on our top 10 most prevalent threat list.Read the full story at redcanary.com
Sentinel — Human
The text exhibits the structure and depth of expert threat reporting, suggesting it originated from internal security intelligence rather than generalized synthetic content.
