Live threat advisory · Q2 2026
FIG. 09 The 2026 threat brief

The attackers brought AI. Most SMBs didn't.

A field report from the IronCastle SOC: what changed in 2025, what's hitting small businesses right now, and the defensive architecture that actually works against agent-driven offence.

§ 01 Threat vectors

Six attack patterns. All new. All in active use.

Curated from incidents seen across our fleet and confirmed by partners at Mandiant, Recorded Future, and the regional CERTs. We list our defence for each.

VECTOR 01 · MALWARE

Self-rewriting implants.

LLM-driven malware regenerates its own code on every connection. Function bodies are paraphrased, control flow is restructured, strings are re-encoded. The SHA256 that defended you yesterday is useless today.

↑ 312% novel implant variants observed YoY · MalwareBazaar 2025
What IronCastle doesYARA scanning against signed rule packs catches semantic patterns (function shapes, API call sequences) — not literal strings. AI Guardian reads the verdict. Auto-cascade kills + quarantines + tenant-wide blocklists the hash. Every hash. Every endpoint.
VECTOR 02 · POST-EX

Autonomous operators.

Frameworks like Mythic 4.x, Sliver 1.6, and Havoc ship with agent operators built in. They pick their own lateral targets, dump their own credentials, decide their own dwell time — no human at the keyboard. The signature of "intent" disappears.

4 min median dwell before first lateral move in observed campaigns
What IronCastle doesBehavioural Sigma rules trigger on pattern of action, not single events. Tamper-resistant agent telemetry can't be quietly disabled. Auto-isolate cuts the host off the network within seconds of the first lateral move.
VECTOR 03 · SOCIAL ENG

Voice-cloned spearphishing.

"Your CFO" calls and asks about an urgent wire. The voice is right. The follow-up email comes from the right address (or a perfect lookalike). The agent on the other end knows your org chart from LinkedIn and adapts in real time.

1 in 7 SMBs hit by AI-tailored phishing in the last 12 months · ENISA 2025
What IronCastle doesM365 / Workspace audit-log monitoring catches downstream identity actions (impossible travel, MFA bypass, mailbox forwarding). We can't stop the call — but we catch the consequence within minutes and revoke sessions before money moves.
VECTOR 04 · CLOUD

Identity-first compromise.

Modern attacks don't bother with malware. Phish a single Entra ID session, use the OAuth token to enumerate the tenant, exfiltrate via Graph API, then pivot to SharePoint and Teams. Your EDR never fires — there's no endpoint involved.

62% of cloud incidents in 2025 involved zero endpoint malware · Microsoft Digital Defense
What IronCastle doesDirect ingestion of your identity and cloud audit streams. Detection rules for impossible-travel, OAuth grants to unknown apps, and mass-download patterns. AI Guardian correlates user + session + action across surfaces.
VECTOR 05 · SUPPLY CHAIN

The MSP backdoor.

Threat actors compromise your IT provider's RMM tool (ConnectWise, Kaseya, N-able) and pivot into every customer of that MSP at once. The malicious script is signed, scheduled, and runs as SYSTEM. By the time the MSP notices, the ransomware is already deployed.

3 of the top 5 ransomware campaigns in 2025 originated via MSP RMM compromise · CISA
What IronCastle doesProcess-tree detection flags anomalous parent processes from RMM agents. Tamper-resistant agent can't be killed by the MSP's own RMM. The auto-cascade fires regardless of who launched the payload — including your IT provider.
VECTOR 06 · DEEPFAKE

Synthetic auditors.

Video calls with "your auditor", "your bank's compliance officer", "your insurance broker" — using real-time deepfake video and voice over Zoom. The ask is almost always the same: a credential, an access grant, a one-time code.

$900M+ reported losses from deepfake-aided fraud in APAC alone · 2024-25
What IronCastle doesDetection rules for the technical artefacts that follow: new OAuth grants, mailbox-forwarding rules, sudden privilege changes, IP-address jumps. We cover what's downstream of the call. Defence in depth assumes the human will sometimes be fooled.
§ 02 The toolkit

The frameworks we're actually seeing.

Public red-team frameworks repurposed for criminal use. We track every release and ship detections within days of public disclosure.

Mythic
4.x · ACTIVE
Modular C2 with agent-based operators. Detected in 18 incidents YTD.
Sliver
1.6 · ACTIVE
Bishop Fox's Go-based implant. Heavily abused. YARA + behavioural caught.
Havoc
0.7 · ACTIVE
Modern Cobalt Strike alternative. Detection ships at the Sigma layer.
Cobalt Strike
4.10 · DECLINING
Still everywhere. Cracked builds dominate. Memory-scan YARA catches.
BRC4 / Brute Ratel
RARE
Premium tool, occasional cracked builds. AI Guardian flags via behaviour.
Metasploit
6.x · LEGACY
Mostly red-team and CTF now. Caught reliably at every layer.
Mimikatz
2.2 · CONSTANT
Credential dumper. In our default YARA pack — caught in 100% of tests.
Empire / Starkiller
RARE · LEGACY
PowerShell-based. Heavily logged. Trivial to detect on modern Windows.
§ 03 What we did

The IronCastle defensive build, in order.

Every defensive capability mapped to the threat that drove it. Built in 2026 in response to what we saw, not in response to a marketing roadmap.

2026 · Q1

Sigma rule engine + macOS / Windows pack

Field-level behavioural detection against an open, auditable rule set. ~9 macOS + ~14 Windows rules in production. Updated weekly.

2026 · Q1

Network isolation via pf

One-click host quarantine. pf-based, IPv6-aware, with a Cloudflare CIDR allowlist so the host can still reach us for forensics. Reversible from the portal.

2026 · Q2

Threat intel cascade — MalwareBazaar + AlienVault OTX

Every event joined against live hash and IP feeds. Free-tier feeds for SMBs; commercial Mandiant + Recorded Future on Keep and Citadel.

2026 · Q2

YARA scanning with signed rule packs

libyara, on-device. Every non-Apple-signed process scanned before it finishes spawning. Rule pack is Ed25519-signed; agent verifies before compile.

2026 · Q2

Agent tamper resistance

LaunchDaemon KeepAlive, watchdog heartbeat, tamper-attempt critical events. Attempting to kill the agent generates a critical incident with attacker process and command line.

2026 · Q2

Auto-response cascade + AI Guardian

Kill / quarantine / blocklist / isolate, queued automatically on critical detections. AI Guardian (latest frontier models) reads every incident in plain English and recommends action.

2026 · Q3

Linux read-only telemetry · GCC compliance · MSSP partner portal (in progress)

Read-only Ubuntu / RHEL agent, native GCC compliance overlays (NESA, ITDA, NCA), and full white-label partner-portal toolchain for regional SOCs.

Stop reading. Start defending.

The next attack doesn't wait.

Book a 30-minute walkthrough with a real engineer — not a sales lead. We'll show the live SOC, walk through your environment, and answer anything procurement needs.

Book a walkthrough →