IP Addresses:
212.11.64.250
Get tomorrow's brief in your inbox
Today: A sophisticated phishing-as-a-service platform bypasses MFA by proxying live authentication sessions. Russian attackers used AI tools to compromise 600+ FortiGate devices exposed with weak credentials. Intellexa's Predator spyware can now completely hide iOS recording indicators while streaming surveillance feeds.
AI-Assisted Campaign Targets 600+ FortiGate Devices
A financially motivated Russian-speaking threat actor compromised over 600 FortiGate devices across 55 countries between January 11 and February 18, 2026. Amazon Threat Intelligence reports the attacker used commercial generative AI tools to overcome limited technical skills, leveraging AI for tool development, attack planning, and command generation. The campaign succeeded through exposed management ports and weak single-factor credentials, not vulnerability exploitation. The attacker systematically scanned FortiGate management interfaces exposed on ports 443, 8443, 10443, and 4443, originating from IP 212.11.64.250. Once inside, the threat actor extracted full device configurations including credentials and network topology, then pivoted to compromise Active Directory environments, harvest credential databases, and target backup infrastructure, likely in preparation for ransomware deployment.
'Starkiller' Phishing-as-a-Service Defeats MFA Through Real-Time Proxying
A new phishing-as-a-service platform called Starkiller completely bypasses multi-factor authentication by acting as a real-time proxy between victims and legitimate websites. The service, offered by the Jinkusu threat group, dynamically loads live login pages using Docker containers running headless Chrome browsers. When victims interact with phishing links, every keystroke, session token, and MFA code passes through attacker infrastructure and is logged. The service uses deceptive URLs with "@" separators (e.g., "login.microsoft.com@[malicious URL]") where everything before the @ is ignored by browsers. Starkiller offers real-time screen streaming, keylogger capture, cookie and session token theft, geo-tracking, automated Telegram alerts for new credentials, and analytics dashboards. Since the victim authenticates with the real site through the proxy, MFA functions exactly as designed but provides no protection. The platform includes a user forum for customers to share techniques and request features, plus tools to harvest contact information from compromised sessions for follow-on campaigns.
Predator Spyware Hooks iOS SpringBoard to Suppress Recording Indicators
Intellexa's Predator commercial spyware can hide iOS recording indicators while streaming camera and microphone feeds to operators, and researchers at Jamf have documented the mechanism. The spyware uses a single hook function within iOS SpringBoard that intercepts the _handleNewDomainData: method, which is called whenever sensor activity changes. By nullifying the SBSensorActivityDataProvider object before sensor updates reach the UI layer, Predator prevents green or orange recording dots from appearing. The hook works because Objective-C silently ignores calls to null objects, so SpringBoard never processes camera or microphone activation events. This single interception point disables both camera and microphone indicators because SBSensorActivityDataProvider aggregates all sensor activity. The spyware requires prior kernel-level access and does not exploit iOS vulnerabilities. Technical indicators include unexpected memory mappings in SpringBoard and mediaserverd, breakpoint-based hooks, and audio files written by mediaserverd to unusual paths.
UK Council Exposes Personal Details of Trans Complaint Submitters
Cornwall Council in the UK suffered a data breach when processing complaints against a councillor, exposing the personal information of all ten complainants including four who explicitly requested anonymity. The council sent home addresses, email addresses, and phone numbers to Councillor Dulcie Tudor along with the complaints, despite policies requiring such information to be redacted. The breach occurred because complainant personal information was only redacted in attached files, but became visible when the councillor opened them. Tudor shared the information with the Free Speech Union as part of her response to the complaints, further expanding exposure. The councillor reported the incident to the UK Information Commissioner's Office on behalf of the complainants. The council initially claimed no wrongdoing occurred because the information was redacted in attachments, not acknowledging that the redaction failed when files were opened.
Today's brief highlights how adversaries are leveraging automation and AI to scale attacks that bypass traditional defenses. The FortiGate campaign demonstrates that generative AI is lowering the technical barrier to entry for financially motivated attackers, enabling them to operate at a scale previously requiring sophisticated teams. The Starkiller phishing platform shows that even properly functioning MFA can be defeated through session proxying, requiring organizations to move toward hardware-based authentication that cannot be relayed in real time.