Coverage Period: June 2, 2026 | Focus: Phishing Campaigns · Native Tool / LotL Abuse | Sources: Microsoft Security · CISA · Talos · Proofpoint · CyberSecurityNews · BleepingComputer · The Hacker News
Generated: 2026-06-02
Companion: Daily Vulnerability Report (v1.3-DM)
After exhaustive research across all 20 mandatory sources — including Microsoft Security Blog, CISA, Cisco Talos, Proofpoint, Cofense, CyberSecurityNews, BleepingComputer, The Hacker News, SecurityWeek, Dark Reading, Krebs on Security, Abnormal Security, Recorded Future, CrowdStrike, Mandiant, SentinelOne, Perception Point, and the Google Threat Intelligence Blog — no qualifying Category A (Phishing) or Category B (Native Tool/LotL Abuse) articles were first published on the coverage date of June 2, 2026.
The most significant recent threat actor disclosure — DriveSurge, a new Initial Access Broker using ClickFix and FakeUpdates drive-by attacks to compromise thousands of websites at scale — was first published May 30, 2026 (SilentPush), June 1, 2026 (CyberSecurityNews, BleepingComputer). This highly relevant finding is logged in the Follow-Up section below with full IOCs. Defenders should treat the DriveSurge IOC list as actionable intelligence and block listed domains and IPs immediately regardless of the date gate. Additionally, the ATHR AI-powered vishing platform (first published April 16, 2026) remains an active threat against enterprise environments and is logged below with defensive guidance.
Exhaustive research across all 20 mandatory sources confirmed that no qualifying Category A (Phishing Campaigns) or Category B (Native Tool / LotL Abuse) articles were first published on the coverage date of June 2, 2026. The most recent major threat actor disclosure — DriveSurge (ClickFix/FakeUpdates IAB) — was published June 1, 2026, one day before coverage and is documented in the Follow-Up Log below with full IOCs.
This reflects strict adherence to the date-gate rule (Section 1A, Rule 2): only articles whose first publication date is the coverage date qualify for full finding cards. The threat landscape remains highly active — see the Follow-Up Log for actionable intelligence from prior-date findings.
Category A: Phishing — 0 new findings Category B: LotL Abuse — 0 new findings Follow-Up Log: 5 prior campaigns tracked| Technique ID | Technique Name | Tactic | Observed In | Frequency |
|---|---|---|---|---|
| No TTPs recorded for June 2, 2026. See Follow-Up Log for TTPs from prior-date findings including DriveSurge (T1059.001, T1566.001, T1204.002) and ATHR (T1566.002, T1598.004, T1621). | ||||
| Campaign / Incident Name | Category | Threat Actor | Target Platform | Target Sector | Impact Level | IOCs | First Reported | Priority Action |
|---|---|---|---|---|---|---|---|---|
| No qualifying campaigns for coverage date June 2, 2026. See Follow-Up Log below for prior-date campaigns including DriveSurge ClickFix/FakeUpdates IAB and ATHR vishing platform. | ||||||||
| Type | Indicator (Defanged) | Description |
|---|---|---|
| Domain | beacontrace[.]bond | Malicious zTDS inject domain serving t.js script |
| Domain | jclforwarding[.]com | Compromised site — serves FakeUpdate/ClickFix content |
| Domain | check[.]first-node[.]rocks | Serves fake Mozilla Firefox update page |
| Domain | cptoptious[.]com | zTDS delivery domain — obfuscated payload |
| Domain | newtdsone[.]shop | zTDS delivery domain — obfuscated payload |
| Domain | captioto[.]com | zTDS delivery domain — obfuscated payload |
| Domain | banerpanel[.]live | Advertisement Distribution System (ADS) panel domain |
| Domain | testio[.]ecartdev[.]com | Payload and development server |
| Domain | ycyfugihih[.]cfd | DriveSurge registration email pivot domain |
| Domain | brightson[.]icu | Pre-weaponized DriveSurge infrastructure |
| Domain | coverlink[.]icu | Pre-weaponized DriveSurge infrastructure |
| Domain | datumprobe[.]icu | Pre-weaponized DriveSurge infrastructure |
| Domain | webgleam[.]info | Fingerprint 3 infrastructure pattern domain |
| Domain | cptoptions[.]com | Suspicious domain loaded into jclforwarding[.]com |
| IP | 91[.]92[.]240[.]127 | Confirmed ClickFix C2 — malicious code delivery IP |
| thiagorivera197151[@]ycyfugihih[.]cfd | DriveSurge domain registration email — Fingerprint 6 pivot |