SOCLIFE
SOCLIFE

Evidence-led security analysis

Published knowledge

Search SOC//LIFE

Threat research

Threats

Sourced reporting translated into attack flow, behaviors to watch, and defensive opportunities.

Public reporting

Threat radar

Understand what happened, how the activity worked, and which behaviors can support hunting and detection. This is not a live feed or risk score.

  • ThreatTHREAT-001

    Cloud access after device-code phishing

    Attackers initiated legitimate device-code requests, persuaded targets to authorize them, and used the resulting cloud access for follow-on activity.

    How it began: Target authorizes a device-code request

    Behavior to watch: A successful device-code sign-in occurs outside the account's documented application or device workflow.

  • ThreatTHREAT-002

    ClickFix in 2026: From Fake Fixes to Remote Access

    ClickFix remained a fast-moving social-engineering technique in 2026 because attackers could change the lure, payload, and infrastructure while preserving the same core action: convince the user to execute attacker-supplied code. Public reporting documented distinct RAT, stealer, browser-disruption, and hands-on-keyboard outcomes rather than one universal chain.

    How it began: A lure reaches the user

    Behavior to watch: RunMRU entries contain unusual interpreters, native tools, remote URLs, or download commands.

  • ThreatTHREAT-003

    AiTM Phishing in 2026: Session Theft Beyond MFA

    Adversary-in-the-middle phishing remained a significant cloud-identity threat in 2026 because attackers could proxy legitimate authentication, capture authenticated session material, and operate as the victim even after MFA succeeded. Microsoft's January SharePoint/BEC reporting, March Tycoon2FA analysis, and April code-of-conduct campaign describe distinct operations that share this session-theft problem without forming one universal campaign.

    How it began: A trusted-looking lure reaches the user

    Behavior to watch: Trusted or previously known senders deliver unexpected SharePoint, document-sharing, compliance, or authentication links.

  • ThreatTHREAT-004

    EtherHiding in 2026: Smart Contracts as Dead-Drop C2

    EtherHiding matured from a niche blockchain-abuse technique into a repeatable infrastructure pattern in 2026. Separate investigations documented compromised websites and malware loaders querying public blockchain RPC services, reading attacker-controlled smart contracts, and using the returned value as a next-stage domain, C2 pointer, or executable browser payload. The public RPC provider is legitimate, while the contract state gives the attacker a durable place to rotate or host the malicious value.

    How it began: A compromised site or loader reaches the victim

    Behavior to watch: A device with no normal Web3 role begins contacting public blockchain RPC services.

  • ThreatTHREAT-005

    Photo ZIP Campaign in 2026: Node JS Persistence

    Microsoft identified an active multi-stage campaign targeting hospitality organizations in Europe and Asia from April 2026. The campaign delivers photo-themed archives containing fake image shortcuts, repeatedly changes PowerShell obfuscation, deploys a legitimate Node JS runtime to execute a JavaScript implant, weakens Defender inspection for staged executables, and establishes two registry persistence paths.

    How it began: Trusted services relay hospitality phishing

    Behavior to watch: A browser or user downloads a photo-themed archive and an IMG/PHOTO shortcut masquerading as a PNG appears or executes.

  • ThreatTHREAT-006

    MacSync Stealer in 2026: Behavior Survives Domain Rotation

    MacSync is a macOS-focused information stealer that uses fast-changing web infrastructure for payload delivery, command-and-control, and exfiltration. Microsoft expanded earlier infrastructure research by correlating repeated endpoint and request behaviors, linking more than thirty domains and confirming collection, staging, chunked upload, and cleanup.

    How it began: ClickFix-style Terminal execution starts the chain

    Behavior to watch: A user-facing macOS shell launches curl retrieval and native decode or unpack utilities.