Signal

New malware campaigns exploit trusted cloud services and hacked web infrastructure for stealthy operations

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-08-18 11:07 UTCUpdated 2026-08-18 17:08 UTC
rss
malwarethreat_actorssecurity_toolingincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Hunting MacSync Stealer infrastructure through behavioral pivots
Microsoft Security Blog · News · microsoft.com · 2026-08-18 17:08 UTC
Overview

Recent investigations have revealed sophisticated malware campaigns leveraging trusted cloud platforms and compromised web infrastructure to evade detection and conduct large-scale attacks.

Score total
1.48
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
  • TWINLOOT and MacSync Stealer campaigns were recently uncovered and actively tracked in August 2026.
  • StopAndProtect operation logs reveal ongoing large-scale infections across thousands of IPs worldwide.
  • These findings highlight evolving attacker tactics exploiting trusted services and infrastructure for stealth and persistence.
Why it matters
  • Attackers abusing trusted cloud services can bypass traditional detection tools that whitelist such traffic.
  • Rapidly changing infrastructure and behavioral pivoting complicate efforts to track and mitigate malware campaigns.
  • Compromised web platforms like WordPress enable large-scale malware distribution and data theft affecting diverse regions.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • TWINLOOT malware uses Microsoft cloud services for command-and-control to evade detection.
  • MacSync Stealer employs rapidly rotating infrastructure and behavioral pivots to maintain persistence and data exfiltration on macOS.
  • StopAndProtect operation abuses thousands of hacked WordPress sites to spread malware and steal data globally.
How sources frame it
  • Ontinue Cyber Defense Center Researchers: neutral
  • Microsoft Defender Experts: neutral
  • Check Point Research: neutral
This briefing highlights advanced malware campaigns exploiting trusted cloud and web infrastructure to evade detection and conduct widespread attacks.
All evidence
All evidence
Hunting MacSync Stealer infrastructure through behavioral pivots
Microsoft Security Blog · microsoft.com · 2026-08-18 17:08 UTC
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Check Point Research · research.checkpoint.com · 2026-08-18 13:05 UTC
TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks
thehackernews · thehackernews.com · 2026-08-18 12:38 UTC
New Malware turns Microsoft cloud into its control center
CSO Online · csoonline.com · 2026-08-18 11:07 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 0
Top publishers (this list)
  • Microsoft Security Blog (1)
  • Check Point Research (1)
  • thehackernews (1)
  • CSO Online (1)
Top origin domains (this list)
  • microsoft.com (1)
  • research.checkpoint.com (1)
  • thehackernews.com (1)
  • csoonline.com (1)