08/30/2026
π¨ This week, global law enforcement dealt major blows to cybercrime networks spanning four continents, while a $320/month phishing kit turned trusted Docusign emails into Microsoft 365 session thieves, and a multi-stage RAT campaign weaponized a legitimate security driver to blind endpoint defenses.
π¦ The Good: INTERPOL's Operation Jackal IV yielded 58 arrests across 22 countries targeting Black Axe fraud networks, the FBI seized infrastructure supporting Chinese state-sponsored espionage targeting NASA and the U.S. Senate, the U.S. Treasury sanctioned Iranian MOIS-linked hackers under Operation Economic Outcast, and Australian authorities charged two men behind the TeamPCP supply chain attacks that compromised over 1,000 organizations worldwide.
The Bad: Researchers disclosed NovaCookies, a $320/month adversary-in-the-middle phishing kit that abuses genuine Docusign notifications to proxy Microsoft 365 sign-ins through attacker infrastructure, stealing authenticated sessions even from MFA-protected accounts across hundreds of organizations.
The Ugly: A newly discovered campaign targeting Cambodia deployed Spark RAT through a multi-stage infection chain that exploited a vulnerable OPSWAT driver to kill Microsoft Defender and other security tools before establishing remote access, with infrastructure overlaps pointing to a possible Chinese-linked threat actor.
This was the week in cyber. π Full technical breakdown: https://s1.ai/GBU9-Wk35