Observations: 2026-07-28

This is a post—the first of many—to encourage discussion about what we’re seeing out there in terms of threat actor activity. I’ll go first:

  • Lots of ClickFix with mshta or pcalua.exe-flavored execution strings
  • WP2Shell recon

I’m confident these are related. There’s no doubt in my mind that WP2Shell exploitation will lead to higher numbers of WordPress sites delivering ClickFix payloads.

What about you? What are you seeing?

Cybercrime

  1. The return of Vigorish Viper in a big way, surrounding the World Cup. Vigorish Viper - Cybercriminal Using Football to Fuel Gambling Ops
  2. Increasing centralization around DNS smuggling or etherhiding for C2/exfil/etc.
  3. Increasing threat actor sophistication around BGP. Seeing more than I used to around ASN-washing, org takeovers, and rotating IP blocks in and out of multiple different ASNs on a cycle. Same is true for nation-state, but I actually think the criminals are more advanced at the moment.

Nation-state level:

  1. Dubai’s continued rise as a universal cutout for money laundering criminal proceeds has accelerated.
  2. Singapore’s continued rise as a technical cutout for sanctioned/blacklisted entities has accelerated.

How would mere mortals track this and usefully act on the information?