Find notable cyber news and cases, enriched with sources, timelines, and signals.

MarlboroMan ecosystem shift changes threat-actor operations

Threat Actor Meta
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

MarlboroMan publicly marketed RedC2 4.0 as a cross-platform C2 framework, widening access to evasion-focused intrusion tooling across Windows, macOS, and Linux. The offering packages surveillance, credential theft, payload loading, and mass-operation functions into a purchasable underground product. Its Red Agent layer adds LLM-driven command execution, reducing operator effort and increasing task speed. The result is a more commercialized and scalable offensive-tool ecosystem.

Related Happenings

Trojanized npm packages deliver RedC2 4.0 Linux implant

Malware Activity
H score31 First: 21.08.2026 21:53 Last: 21.08.2026 21:53 Sources 1

How related: Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0.

About this happening: Trojanized npm packages are now delivering the RedC2 4.0 Linux implant through a supply-chain execution path, turning a routine package import into remote malware depl...

Armored Likho spear-phishing and malware-delivery campaign targeting government and power sectors

Campaign
H score37 First: 03.07.2026 16:36 Last: 03.07.2026 16:36 Sources 1

About this happening: The Armored Likho campaign is using spear-phishing and malware-delivery chains to target government agencies and the electric power sector across Russia, Brazil,...

The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up

Threat Actor Meta
H score57 First: 21.04.2026 17:00 Last: 21.04.2026 17:00 Sources 1

About this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...

Shadow-Void-044 and Shadow-Earth-045 PeckBirdy cyber-espionage campaigns

Campaign
H score34 First: 28.01.2026 18:19 Last: 28.01.2026 18:19 Sources 1

About this happening: Two China-aligned PeckBirdy espionage campaigns were identified, widening risk to Chinese gambling websites, Asian government entities, and a Philippine educatio...

Timeline

  1. 21.08.2026 21:53 2 articles · 2h ago

    MarlboroMan ecosystem shift changes threat-actor operations

    Initial Disclosure

    In early June 2026, MarlboroMan promoted RedC2 4.0 on Hack Forums as an evasion-focused framework for Windows, Linux, and macOS. The listing positioned the toolkit as a purchasable underground product rather than a one-off payload.

    Show sources