Skip to content

Executive Summary

The threat landscape in July 2026 showed significant shifts, including the continued prevalence of ClearFake and a debut of four new threats: GraphSpy, Phexia, CastleRAT, and EtherRAT. The list saw familiar elements like JustAskJacky returning, tying for fourth, and Amber Albatross tied for sixth. Notable departures included Atomic Stealer and NetSupport Manager falling out of the top ten for the first time since previous months. New threats introduced a focus on credential theft through GraphSpy, remote access via CastleRAT, and complex blockchain-based command and control (C2) mechanisms utilized by Phexia and EtherRAT. Analysis of the trends indicates that adversarial activity is increasingly leveraging sophisticated methods involving compromised web content, masquerading applications, and decentralized infrastructure like blockchain for command and control, necessitating a focus on layered detection strategies across traditional endpoints and emerging network traffic.

Facts Only

* ClearFake ranked number 1 on the top 10 threat list for the fourth consecutive month in July 2026.
* JustAskJacky returned in a tie for 4th place, masquerading as PDF readers in July 2026.
* Amber Albatross tied for 6th place, delivered via installers masquerading as free software leading to a PyInstaller EXE with stealer capabilities.
* Atomic Stealer left the top 10 for the first time since August 2025.
* NetSupport Manager fell out of the top 10 for the first time since September 2024.
* GraphSpy debuted in a tie for 4th place, functioning as an open source tool to abuse Entra ID and Microsoft 365 authentication tokens.
* Phexia debuted in a tie for 6th place, targeting macOS systems with modular stealer components utilizing blockchain smart contracts for C2 domain discovery.
* CastleRAT debuted in a tie for 10th place, a remote access trojan with keylogging and screen capturing capabilities.
* EtherRAT debuted in a tie for 10th place, a Node.js-based RAT using blockchain-based C2 resolution targeting Windows workstations and Linux servers.
* Dead drop resolution is a technique used by Phexia, CastleRAT, and EtherRAT to locate command and control infrastructure via public web services or blockchain endpoints.

Full Take

The observed patterns suggest an escalation in adversarial focus from simple malware delivery toward sophisticated methods of credential harvesting and resilient command and control. The emergence of threats like GraphSpy indicates a pivot towards exploiting identity and access management systems, using browser-based interfaces for data exfiltration rather than purely file-system compromise. Furthermore, the widespread adoption of blockchain techniques for C2 resolution across Phexia and EtherRAT signifies an attempt to build infrastructure that is inherently resistant to traditional network-based blocking. This pattern—leveraging widely accessible public ledger technology to obfuscate command channels—echoes historical patterns of digital evasion, suggesting a maturing adversarial playbook where infrastructure resilience is prioritized alongside initial access. The reliance on dead drop resolution across multiple threat families reveals an established operational preference for leveraging trusted web services as ephemeral infrastructure conduits, which challenges static network visibility. This points toward a systemic challenge: detection must evolve beyond signature-based analysis to account for dynamic, decentralized communication methods, forcing consideration of the underlying logic of trust within systems and applications themselves. What assumptions about the immutable nature of blockchain C2 routes or the security of seemingly benign web services are being challenged by this trend? How does focusing on infrastructure rotation impact the ability of defenders to establish persistent defensive boundaries?

From the original · Red Canary

Zscaler Blog Get the latest Zscaler blog updates in your inbox Intelligence Insights: August 2026 Debuts, departures, and danger on the blockchain in this month’s edition of Intelligence Insights This article was originally published by Red Canary, which is now part of Zscaler. Highlights from July For the fourth month in a row, ClearFake comes in number 1 on our top 10 most prevalent threat list.
Read the full story at redcanary.com

Sentinel — Human

Confidence

The text exhibits the structure and depth of expert threat reporting, suggesting it originated from internal security intelligence rather than generalized synthetic content.

Signals Detected
low severity: Moderate sentence length variance; use of specific technical jargon mixed with narrative explanation.
low severity: High internal coherence in structuring threat lists and explanations, demonstrating domain-specific knowledge.
low severity: Structured use of tables and clearly delineated threat profiles suggests careful compilation, not random generation.
low severity: References to specific malware tactics (Paste and Run, LaunchAgent plist, specific blockchain interactions) suggest deep familiarity with the subject matter, leaning toward authentic reporting or expert compilation.
Human Indicators
The integration of detailed technical execution steps (e.g., Phexia's use of curl, osascript, and blockchain queries) shows a level of forensic detail typically associated with security researchers or vendor communications.
The explicit disclaimer regarding Zscaler's responsibility points toward an official source context.
Intelligence Insights: August 2026 | Huntaegis