In a paradigm-shifting development for the global cybersecurity landscape, CYFIRMA Research and Advisory Team published a comprehensive weekly intelligence report on July 10, 2026, unveiling critical insights into emerging ransomware families, state-sponsored supply chain attacks, and sophisticated malware campaigns targeting enterprises worldwide www.cyfirma.com . This conspicuous intelligence briefing illuminates the proliferation of Doommageddon ransomware, the Lazarus Group's expansion of supply chain operations, and multiple high-impact breaches across diverse industries and geographies www.cyfirma.com . Doommageddon Ransomware: A pernicious Double-Extortion Threat The CYFIRMA research team has ascertained the emergence of Doommageddon ransomware, a malignant threat actor that employs asymmetric cryptographic algorithms to encrypt files while appending unique extensions to each compromised document www.cyfirma.com . This sophisticated ransomware family primarily targets Windows operating systems across Brazil, India, Paraguay, and Turkey, with a particular focus on financial services, manufacturing, retail, and technology sectors www.cyfirma.com . What makes Doommageddon exceptionally alarming is its implementation of a double-extortion model that synthesizes file encryption with data exfiltration threats www.cyfirma.com . Beyond encrypting victim files, the ransomware operators maintain a hidden data leak portal (DLS) that categorizes victims according to negotiation progress and displays countdown timers alongside the volume of compromised data www.cyfirma.com . This psychological pressure tactic substantially increases the operational and reputational impact on affected organizations www.cyfirma.com . The malware demonstrates advanced anti-recovery capabilities by intentionally terminating critical Windows processes including vssadmin.exe Delete Shadows /all /quiet and wmic shadowcopy delete /nointeractive to eliminate Volume Shadow Copies www.cyfirma.com . This strategic deletion ensures victims cannot recover their files via system restore points or backup utilities, compelling them to either pay the ransom or face permanent data loss www.cyfirma.com . BrunoStealer Trojan: Clandestine Espionage Operations In a concurrent discovery, CYFIRMA analysts identified BrunoStealer, a global trojan designed for espionage operations that exhibits multiple characteristics associated with advanced persistent threats www.cyfirma.com . Rather than performing overtly destructive actions immediately, this malware focuses on establishing execution, gathering system intelligence, and preparing the environment for potential follow-on activities www.cyfirma.com . The infection commences with the execution of a malicious DLL through the Windows utility rundll32.exe, allowing the payload to run under the context of a trusted Microsoft binary www.cyfirma.com . This technique, known as living-off-the-land, enables the malware to blend malicious activity with normal system operations, significantly reducing its behavioral footprint www.cyfirma.com . The sample also invokes loaddll64.exe during execution, indicating an additional stage for loading or testing the DLL www.cyfirma.com . BrunoStealer employs obfuscation and software packing mechanisms, along with environment-awareness checks, to complicate static and dynamic analysis www.cyfirma.com . These capabilities highlight an emphasis on evading security controls and delaying detection during execution, making it a formidable adversary for traditional security solutions www.cyfirma.com . North Korean Lazarus Group: Expanding Supply Chain Campaign Perhaps the most geopolitically significant finding is the North Korean threat actor Famous Chollima, also known as the Lazarus Group, broadening its supply chain operations beyond traditional targets www.cyfirma.com . The threat actor is suspected of expanding the PolinRider supply chain campaign beyond npm into Go Modules, Packagist, and Chrome extensions by compromising legitimate GitHub repositories and maintainer accounts www.cyfirma.com . This campaign appears aimed at compromising developer environments to deliver malware and steal credentials, browser data, and cryptocurrency wallet information www.cyfirma.com . The suspected target technologies encompass an extensive range including Windows, macOS, Linux, SAP systems, cryptocurrency exchanges, financial platforms (including SWIFT), JetBrains TeamCity, Oracle products, Dell systems, Atlassian Confluence, Citrix NetScaler ADC/Gateway, and GitHub/GitLab repositories www.cyfirma.com . The geographic scope is equally comprehensive, spanning Australia, Brazil, Brunei, Canada, Chile, China, France, Germany, Hong Kong, India, Indonesia, Iran, Japan, Myanmar, Philippines, Poland, South Korea, Russia, Thailand, United Kingdom, United States, Vietnam, and Bangladesh www.cyfirma.com . This ubiquitous targeting strategy demonstrates the Lazarus Group's ambitious objectives encompassing information theft, espionage, financial gains, and credential theft across aerospace, defense, capital markets, cryptocurrency, energy, government, media, technology, and telecommunications sectors www.cyfirma.com . Active Ransomware Incidents The report documents several concrete ransomware incidents that underscore the pervasive nature of these threats: Krybit Ransomware — Malaysian Furniture Retailer CYFIRMA observed Krybit ransomware impacting a Malaysian furniture retailer and home lifestyle solutions provider www.cyfirma.com . The compromised data includes confidential and sensitive information totaling approximately 400 GB, representing a substantial breach of organizational and customer data www.cyfirma.com . Qilin Ransomware — Thai Food & Beverage Company Qilin ransomware attacked and published data from a Thailand-based food and beverage company specializing in edible oils, palm oil-based products, margarine, shortening, and specialty fats www.cyfirma.com . The compromised data includes internal corporate documents, business forms, financial records, invoices, accounting statements, and operational documents www.cyfirma.com . Critical Vulnerability: CVE-2026-5120 The intelligence report also highlights a critical vulnerability in BIOVIA Workbook, a scientific data management and laboratory information management software platform www.cyfirma.com . CVE-2026-5120, rated with a CVSS base score of 8.1, is a race condition vulnerability that allows remote users to gain access to sensitive information www.cyfirma.com . This finding underscores the growing risks to scientific and laboratory management platforms, which often handle proprietary research data and intellectual property www.cyfirma.com . Healthcare Data Breach — India In a disturbing development, the CYFIRMA research team identified a post on a dark web forum advertising the sale of a large database allegedly originating from a healthcare organization in India www.cyfirma.com . According to the forum advertisement, the seller claims to possess separate patient and employee databases containing millions of healthcare records and organizational information www.cyfirma.com . This incident highlights the persistent targeting of healthcare institutions and the lucrative nature of medical data on underground markets www.cyfirma.com .

Key Threat Intelligence Findings

  • Doommageddon Ransomware: New double-extortion ransomware targeting Windows systems in Brazil, India, Paraguay, and Turkey with focus on financial services and manufacturing sectors www.cyfirma.com .
  • BrunoStealer Trojan: Global espionage malware using rundll32.exe for stealthy execution and employing advanced obfuscation techniques www.cyfirma.com .
  • Lazarus Group: North Korean APT expanding PolinRider supply chain campaign to Go Modules, Packagist, and Chrome extensions www.cyfirma.com .
  • Active Incidents: Krybit ransomware (Malaysian furniture company, 400 GB breach), Qilin ransomware (Thai F&B company), and The Gentlemen ransomware (Japanese health and beauty brand) www.cyfirma.com .
  • Critical Vulnerability: CVE-2026-5120 in BIOVIA Workbook (CVSS 8.1) allows remote access to sensitive scientific data www.cyfirma.com .
  • Healthcare Breach: Millions of patient and employee records from Indian healthcare organization advertised on dark web www.cyfirma.com .

Strategic Recommendations

  • Volume Shadow Copy Protection: Implement protections against VSS deletion commands and maintain offline backups to mitigate ransomware recovery prevention www.cyfirma.com .
  • Supply Chain Security: Enhance monitoring of software supply chains, particularly npm, Go Modules, Packagist, and Chrome extensions for compromise indicators www.cyfirma.com .
  • Developer Environment Hardening: Secure GitHub repositories, maintainer accounts, and development tools against Lazarus Group supply chain attacks www.cyfirma.com .
  • LLOLBas Detection: Implement enhanced monitoring of legitimate Windows utilities like rundll32.exe to detect living-off-the-land techniques www.cyfirma.com .
  • Double-Extortion Defense: Deploy data loss prevention (DLP) solutions and network segmentation to prevent data exfiltration alongside ransomware encryption www.cyfirma.com .

This comprehensive intelligence report from CYFIRMA underscores the evolving nature of cyber threats in 2026, where ransomware operators, nation-state actors, and cybercriminal organizations employ increasingly sophisticated tactics, techniques, and procedures. For comprehensive technical indicators of compromise (IOCs), mitigation strategies, and detailed threat actor profiles, security professionals should refer to the official CYFIRMA Weekly Intelligence Report.