← Carolina Clear Tech

Cyber Threat Brief

2026-07-05

Listen to this brief (6:12)

Download MP3
Show Notes

Show Notes - 2026-07-05

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - 2026-07-05

Today: A U.S. county paid $1 million to data extortionists who never encrypted a file, North Korean developers are poisoning over 100 packages across npm, Go, and Chrome to drop BeaverTail malware, and AdaptHealth lost patient data after attackers social engineered a third-party contractor into cloud access. The shift from ransomware to pure data theft extortion is now complete.

Ransomware & Extortion

U.S. County Paid $1M to Kairos Group in Pure Data Theft Extortion

Union County, Ohio paid approximately $1 million in June 2025 to prevent the leak of stolen files containing prosecutors' office records, Social Security numbers, financial details, fingerprints, and passport data from 45,487 residents and staff. The Kairos group never encrypted a single file. They stole 2 TB of data (1.6 million files), threatened to publish the most sensitive folders first, and ran a month-long negotiation from a $3 million opening demand down to a hard $1 million deadline. The county started at $100,000 and paid 9.44 bitcoin on June 13, 2025. Blockchain analysis traced the payment through Bybit, OKX, and Russian exchange BELQI within hours. The attackers sent a "proof of deletion" file that only proves they once had the files, not that originals were destroyed.

This is the clearest example yet of the industry shift away from encryption. Sophos reported in 2025 that only 50% of ransomware attacks still involve encryption, the lowest rate in six years. Silent Ransom Group, a Conti offshoot, has run pure data-theft extortion against U.S. law and finance firms for years with no encryptor. Kairos itself has gone quiet (leak site down, last known victim June 2026), but wallets tied to the operation moved money as recently as May 2026.

AdaptHealth Patient Data Stolen After Social Engineering Attack on Third-Party Contractor

Attackers used social engineering to compromise a third-party contractor and gain access to AdaptHealth's cloud environment, stealing sensitive patient data including insurance billing passwords. The breach affected internal patient management systems, document storage platforms, and external EHR portals. The attackers disclosed the theft to AdaptHealth on June 15, 2026.

Business & Infrastructure Threats

North Korean Hackers Publish 108 Malicious Packages in PolinRider Campaign

North Korean threat actors linked to Contagious Interview have published 108 unique malicious packages and extensions across npm (19 packages), Packagist (10), Go (61), and Google Chrome (1 extension) as part of the active PolinRider campaign. The campaign has compromised 1,951 public GitHub repositories associated with 1,047 unique owners as of April 11, 2026. Attackers are taking over maintainer accounts, likely through expired domain takeover or account recovery paths, then injecting obfuscated JavaScript loaders that deliver BeaverTail malware, DEV#POPPER RAT, and OmniStealer. The malware searches for developer config files (postcss.config.mjs, tailwind.config.js, eslint.config.mjs, next.config.mjs, babel.config.js, app.js) and appends malicious code. It also uses Git history rewriting with force pushes and anti-dated commits to make changes appear older and less suspicious.

The campaign merges with another cluster called TaskJacker that drops malicious VS Code task files with "runOn: 'folderOpen'" to trigger arbitrary code execution when a folder is opened as a workspace. The payload fetches encrypted second-stage payloads from blockchain infrastructure (TRON, Aptos, BNB Smart Chain). The threat actors weaponize fake job interviews and assessments, masquerading as recruiters on LinkedIn, GitHub, and freelance sites with elaborate front companies and AI-generated employee profiles.

Patch Priority

Trends & Context

Pure data theft extortion is now the dominant ransomware business model, with encryption becoming optional. North Korean threat actors are aggressively poisoning developer toolchains at scale, compromising over 1,900 repositories to drop malware via fake job interviews. Social engineering remains the primary entry vector for both extortion crews and nation-state operators targeting cloud environments.