Intelligence Center

Threat Research

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. Learn More

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.  Learn More

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. Learn More

Fortify Your Defense

Evolve your incident response with intelligence-led proactive services and deep expertise that only Talos can offer, before –and during– an active emergency. Anyone can stand behind you – Talos IR stands beside you, every step of the way.

Together, we can reduce downtime and mitigate risk. Get started today.

Learn More

Latest Talos Takes Podcast Episodes

September 23, 2026
ClickFix, EtherHiding, and the rise of malicious code in the blockchain

In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure.Vanja walks us through how threat actors are repurposing legitimate user behaviors — like solving CAPTCHAs — to gain unauthorized access, and how they utilize blockchain smart contracts as bulletproof storage for malicious code. We also explore the divergence in final payloads, ranging from remote access tools to crypto-stealing malware. Tune in for actionable behavioral patterns that your security teams can monitor to detect these incidents before they progress.Vanja's blog: https://blog.talosintelligence.com/clearfake-webdav-infection-chain/

September 9, 2026
Browser betrayal: When your tabs turn against you

Ah, the crisp fall air, brand-new books and backpacks, and the quiet irony of cybercriminals turning on each other to steal a few extra bucks.Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. This browser-based attack tricks targets into injecting malicious code into their own sessions under the guise of exploiting a fictional vulnerability to earn crypto-profits.While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web security. Tune in to hear why it’s only a matter of time before these techniques turn from petty crypto-scams toward our enterprise supply chains, and how to protect your organization.Blog: https://blog.talosintelligence.com/clickfix-moves-into-the-browser/

Why Cisco Talos?

Talos is Cisco's threat intelligence research organization, an elite group of security experts devoted to providing superior protection for our customers, products and services.

Our job is your defense.

Talos powers the Cisco portfolio with comprehensive intelligence.

Every customer environment, every event, every single day, all around the world.