In a paradigm-shifting development for the global cybersecurity landscape, CYFIRMA Research and Advisory Team published a comprehensive weekly intelligence report on July 10, 2026, unveiling critical insights into emerging ransomware families, state-sponsored supply chain attacks, and sophisticated malware campaigns targeting enterprises worldwide
www.cyfirma.com
. This conspicuous intelligence briefing illuminates the proliferation of Doommageddon ransomware, the Lazarus Group's expansion of supply chain operations, and multiple high-impact breaches across diverse industries and geographies
www.cyfirma.com
.
Doommageddon Ransomware: A pernicious Double-Extortion Threat
The CYFIRMA research team has ascertained the emergence of Doommageddon ransomware, a malignant threat actor that employs asymmetric cryptographic algorithms to encrypt files while appending unique extensions to each compromised document
www.cyfirma.com
. This sophisticated ransomware family primarily targets Windows operating systems across Brazil, India, Paraguay, and Turkey, with a particular focus on financial services, manufacturing, retail, and technology sectors
www.cyfirma.com
.
What makes Doommageddon exceptionally alarming is its implementation of a double-extortion model that synthesizes file encryption with data exfiltration threats
www.cyfirma.com
. Beyond encrypting victim files, the ransomware operators maintain a hidden data leak portal (DLS) that categorizes victims according to negotiation progress and displays countdown timers alongside the volume of compromised data
www.cyfirma.com
. This psychological pressure tactic substantially increases the operational and reputational impact on affected organizations
www.cyfirma.com
.
The malware demonstrates advanced anti-recovery capabilities by intentionally terminating critical Windows processes including vssadmin.exe Delete Shadows /all /quiet and wmic shadowcopy delete /nointeractive to eliminate Volume Shadow Copies
www.cyfirma.com
. This strategic deletion ensures victims cannot recover their files via system restore points or backup utilities, compelling them to either pay the ransom or face permanent data loss
www.cyfirma.com
.
BrunoStealer Trojan: Clandestine Espionage Operations
In a concurrent discovery, CYFIRMA analysts identified BrunoStealer, a global trojan designed for espionage operations that exhibits multiple characteristics associated with advanced persistent threats
www.cyfirma.com
. Rather than performing overtly destructive actions immediately, this malware focuses on establishing execution, gathering system intelligence, and preparing the environment for potential follow-on activities
www.cyfirma.com
.
The infection commences with the execution of a malicious DLL through the Windows utility rundll32.exe, allowing the payload to run under the context of a trusted Microsoft binary
www.cyfirma.com
. This technique, known as living-off-the-land, enables the malware to blend malicious activity with normal system operations, significantly reducing its behavioral footprint
www.cyfirma.com
. The sample also invokes loaddll64.exe during execution, indicating an additional stage for loading or testing the DLL
www.cyfirma.com
.
BrunoStealer employs obfuscation and software packing mechanisms, along with environment-awareness checks, to complicate static and dynamic analysis
www.cyfirma.com
. These capabilities highlight an emphasis on evading security controls and delaying detection during execution, making it a formidable adversary for traditional security solutions
www.cyfirma.com
.
North Korean Lazarus Group: Expanding Supply Chain Campaign
Perhaps the most geopolitically significant finding is the North Korean threat actor Famous Chollima, also known as the Lazarus Group, broadening its supply chain operations beyond traditional targets
www.cyfirma.com
. The threat actor is suspected of expanding the PolinRider supply chain campaign beyond npm into Go Modules, Packagist, and Chrome extensions by compromising legitimate GitHub repositories and maintainer accounts
www.cyfirma.com
.
This campaign appears aimed at compromising developer environments to deliver malware and steal credentials, browser data, and cryptocurrency wallet information
www.cyfirma.com
. The suspected target technologies encompass an extensive range including Windows, macOS, Linux, SAP systems, cryptocurrency exchanges, financial platforms (including SWIFT), JetBrains TeamCity, Oracle products, Dell systems, Atlassian Confluence, Citrix NetScaler ADC/Gateway, and GitHub/GitLab repositories
www.cyfirma.com
.
The geographic scope is equally comprehensive, spanning Australia, Brazil, Brunei, Canada, Chile, China, France, Germany, Hong Kong, India, Indonesia, Iran, Japan, Myanmar, Philippines, Poland, South Korea, Russia, Thailand, United Kingdom, United States, Vietnam, and Bangladesh
www.cyfirma.com
. This ubiquitous targeting strategy demonstrates the Lazarus Group's ambitious objectives encompassing information theft, espionage, financial gains, and credential theft across aerospace, defense, capital markets, cryptocurrency, energy, government, media, technology, and telecommunications sectors
www.cyfirma.com
.
Active Ransomware Incidents
The report documents several concrete ransomware incidents that underscore the pervasive nature of these threats:
Krybit Ransomware — Malaysian Furniture Retailer
CYFIRMA observed Krybit ransomware impacting a Malaysian furniture retailer and home lifestyle solutions provider
www.cyfirma.com
. The compromised data includes confidential and sensitive information totaling approximately 400 GB, representing a substantial breach of organizational and customer data
www.cyfirma.com
.
Qilin Ransomware — Thai Food & Beverage Company
Qilin ransomware attacked and published data from a Thailand-based food and beverage company specializing in edible oils, palm oil-based products, margarine, shortening, and specialty fats
www.cyfirma.com
. The compromised data includes internal corporate documents, business forms, financial records, invoices, accounting statements, and operational documents
www.cyfirma.com
.
Critical Vulnerability: CVE-2026-5120
The intelligence report also highlights a critical vulnerability in BIOVIA Workbook, a scientific data management and laboratory information management software platform
www.cyfirma.com
. CVE-2026-5120, rated with a CVSS base score of 8.1, is a race condition vulnerability that allows remote users to gain access to sensitive information
www.cyfirma.com
. This finding underscores the growing risks to scientific and laboratory management platforms, which often handle proprietary research data and intellectual property
www.cyfirma.com
.
Healthcare Data Breach — India
In a disturbing development, the CYFIRMA research team identified a post on a dark web forum advertising the sale of a large database allegedly originating from a healthcare organization in India
www.cyfirma.com
. According to the forum advertisement, the seller claims to possess separate patient and employee databases containing millions of healthcare records and organizational information
www.cyfirma.com
. This incident highlights the persistent targeting of healthcare institutions and the lucrative nature of medical data on underground markets
www.cyfirma.com
.
Key Threat Intelligence Findings
- Doommageddon Ransomware: New double-extortion ransomware targeting Windows systems in Brazil, India, Paraguay, and Turkey with focus on financial services and manufacturing sectors www.cyfirma.com .
- BrunoStealer Trojan: Global espionage malware using rundll32.exe for stealthy execution and employing advanced obfuscation techniques www.cyfirma.com .
- Lazarus Group: North Korean APT expanding PolinRider supply chain campaign to Go Modules, Packagist, and Chrome extensions www.cyfirma.com .
- Active Incidents: Krybit ransomware (Malaysian furniture company, 400 GB breach), Qilin ransomware (Thai F&B company), and The Gentlemen ransomware (Japanese health and beauty brand) www.cyfirma.com .
- Critical Vulnerability: CVE-2026-5120 in BIOVIA Workbook (CVSS 8.1) allows remote access to sensitive scientific data www.cyfirma.com .
- Healthcare Breach: Millions of patient and employee records from Indian healthcare organization advertised on dark web www.cyfirma.com .
Strategic Recommendations
- Volume Shadow Copy Protection: Implement protections against VSS deletion commands and maintain offline backups to mitigate ransomware recovery prevention www.cyfirma.com .
- Supply Chain Security: Enhance monitoring of software supply chains, particularly npm, Go Modules, Packagist, and Chrome extensions for compromise indicators www.cyfirma.com .
- Developer Environment Hardening: Secure GitHub repositories, maintainer accounts, and development tools against Lazarus Group supply chain attacks www.cyfirma.com .
- LLOLBas Detection: Implement enhanced monitoring of legitimate Windows utilities like rundll32.exe to detect living-off-the-land techniques www.cyfirma.com .
- Double-Extortion Defense: Deploy data loss prevention (DLP) solutions and network segmentation to prevent data exfiltration alongside ransomware encryption www.cyfirma.com .
This comprehensive intelligence report from CYFIRMA underscores the evolving nature of cyber threats in 2026, where ransomware operators, nation-state actors, and cybercriminal organizations employ increasingly sophisticated tactics, techniques, and procedures. For comprehensive technical indicators of compromise (IOCs), mitigation strategies, and detailed threat actor profiles, security professionals should refer to the official CYFIRMA Weekly Intelligence Report.