Security1 distinct publisher3 min readPublished
A week of takedowns removed people and froze assets across five separate actions, while the kit that manufactures the stolen Microsoft 365 sessions those crews depend on still sells on Telegram for $320 a month.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Seizing a hardcoded C2 domain breaks rendezvous for implants that carry no fallback, and it leaves every compromised router exactly as compromised as it was the day before. QScan and QTRouter existed to put consumer IoT devices between Chinese operators and their targets, according to SentinelOne's week 35 roundup, which credits the group QTFY with direct ties to China's military and intelligence services and names the Federal Reserve and NASA among the targeted US networks [4][5]. That relay layer is a telemetry problem: espionage traffic arrives from residential address space, where geography and reputation scoring read it as consumer noise. The FBI and DoJ took the core domains written into the frameworks [6]. What that buys a defender is retrospective, because any historical resolution of those names in DNS or proxy logs is now a finding. The roundup does not publish them.
On the fraud side the numbers set the ceiling. Jackal IV produced 58 arrests against more than 200 identified suspects across 22 nations [1], which leaves at least 142 people named and not in custody [15] and puts arrest coverage under 30% of the identified set [16]. The operation dismantled elements of Black Axe, and the evidence stops short of the syndicate itself [2]. BEC runs on mailbox access and a plausible payment instruction rather than on hosting, so removing headcount from the syndicate behind romance, investment and BEC schemes [2] does not change what a remaining operator can send tomorrow.
The same roundup prices the replacement capability. NovaCookies, a variant of Sneaky2FA sold on Telegram at $320 monthly [9][12], works out to $3,840 a year [17] for an adversary-in-the-middle proxy already used against hundreds of organizations in the US, UK, Germany and the UAE [9]. The lure ships inside a genuine DocuSign notification, so it clears sender authentication and reputation filters on the way in, and the malicious link sits inside the shared document, below where most gateways inspect [10]. From there an OAuth error-redirect walks the browser through legitimate Microsoft or Google endpoints before it lands on the proxy [11], which relays credentials and MFA codes to Microsoft in real time [13]. The asset freezes in South Africa, Argentina and Romania [3] take money off operators, but that $320 price tag holds steady regardless.
Indicators in the write-up are thin and perishable: .vu landing pages, alternating-case subdomains such as PwPt-sHaRe [13]. The session is where this is catchable, which is why the analysts quoted place the browser at the intersection of the hops [14]. TeamPCP shows the residue of the other approach. The AFP has charged two people over principal roles, while the credentials taken through backdoored Trivy, Checkmarx KICS and LiteLLM releases number in the hundreds of thousands [8], a stockpile the arrest leaves untouched.
All five actions come from one weekly roundup that supplies no dates, case numbers or domain lists [18]. That applies equally to the Treasury figures: five Mabna Institute members and close to 60 Iran-linked entities sanctioned under Economic Outcast, with indictments and a $10 million reward [7]. Whether any of it changed a specific network's exposure is answerable only in that network's logs, and only once the seized names are public.
Ranked by verification strength, evidence, and original report placement.
Operation Jackal IV, coordinated by INTERPOL across 22 nations, led to the arrest of 58 individuals and the identification of over 200 suspects linked to West African cybercrime networks.
The joint action dismantled elements of the Black Axe syndicate, which orchestrates global romance, investment and business email compromise scams.
The FBI, working with the DoJ, disrupted the global QScan and QTRouter hacking platforms operated by Chinese state-sponsored threat actors.
Law enforcement seized the core command-and-control domains hardcoded within the QScan and QTRouter frameworks.
A US Treasury operation dubbed Economic Outcast imposed sanctions on five Mabna Institute members and nearly 60 Iran-linked entities acting under Iran's Ministry of Intelligence and Security, which breached American critical infrastructure organizations, state governments and defense contractors; the actors face federal indictments alongside a $10 million reward.
The Australian Federal Police arrested and charged two individuals for principal roles in TeamPCP, which compromised Trivy, Checkmarx KICS and LiteLLM by stealing developer credentials and distributing backdoored updates, facilitating theft of hundreds of thousands of credentials.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless1 distinct publisher
science
TeamPCP hid its infostealer inside the scanners that audit everyone else's code1 distinct publisher
science
A backdoored litellm release turns every CI job that installed it into a credential incident1 distinct publisher
security
A misconfigured GitHub Actions workflow handed TeamPCP the token that poisoned five ecosystems1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor post, no paper trail
Five enforcement actions across INTERPOL, three national forces, the FBI, Treasury and the AFP are all summarised in a paragraph each, with no dates, no case numbers and none of the seized domains the post says were taken. The strongest material is SentinelOne's own NovaCookies research, where the specifics are concrete; the weakest is the QTFY attribution, which asserts military and intelligence ties and names the Federal Reserve and NASA as targets without pointing to an indictment.
Kit widely used, counts unaudited
There is real-world uptake on both sides here. NovaCookies is priced, marketed and reportedly already inside hundreds of organizations in four named countries, and TeamPCP's backdoored releases moved through Trivy, Checkmarx KICS and LiteLLM — ecosystems with wide installed bases. What holds the number down is that every count is the reporter's own tally: no victim is named, no affected version is listed, and no third party has checked the arithmetic.
'Dismantled' outruns the numbers
The language is victory language — dismantled, sweeping, disrupted — and the figures in the same paragraphs do not carry it. Fifty-eight arrests against more than 200 identified suspects leaves at least 142 people untouched, and none of the five actions is reported as having reached the phishing-as-a-service layer: the kit that mints the stolen Microsoft 365 sessions was still listed on Telegram at $320 a month as the arrests were announced. The gap is one of framing rather than fabrication; the post gives you the numbers that undercut it.
Vendor blog, vendor conclusion
SentinelOne sells endpoint and identity protection, and the post's closing line — that the browser is the critical intersection where these events converge — is a product thesis dressed as an analyst observation, sourced to unnamed analysts inside the vendor's own write-up. That does not make the NovaCookies technical detail wrong; it is specific enough to test. But the selection is telling: threats get depth, enforcement gets applause, and the recurring weekly format rewards volume over verification.
Plausible, uncorroborated
The mechanics of the phishing chain are the part worth trusting — they are internally consistent, specific, and the kind of thing the publisher observes first-hand. The enforcement half is a different matter: five actions, no dates, no dockets, no second outlet. Anything downstream of those paragraphs, including the arrest arithmetic this story leads with, is only as good as one weekly post that has not yet been checked by anyone else.