Skip to main content

Validation Content Update - July 22, 2026

  • July 22, 2026
  • 0 replies
  • 3 views

Forum|alt.badge.img+5

VHR20260722 - July 22, 2026

The Mandiant Intelligence Validation Research Team (VRT) has published VHR20260722 - Content Expansion. This content pack requires Director version 4.12.1.0-0 or higher.

If you’ve enabled the Content Service, this content pack will automatically download and be applied to your Director. Otherwise, you can download the security content pack from the Mandiant Documentation Portal.

Summary of Changes

  • 109 Actions added
  • 88 Files added

Release Highlights

  • A new Action covering Campaign 26-069, an initial access campaign by actor UNC6910 leveraging social engineering lures and delivering CURLYGATECURLYFENCE, and NEONSLIDE malware.
  • A new Action covering Campaign 26-014, involving North Korea-nexus threat actor UNC5342 deploying Python backdoors such as JADESNOW and INVISIBLEFERRET.JAVASCRIPT to target GitHub repositories for unauthorized code modification.
  • New Actions demonstrating Campaign 26-068, a campaign by UNC6468 using recipe-themed executables to deliver PINESAP and establish initial access.
  • New Actions demonstrating Campaign 26-072, a China-nexus financial gain campaign by UNC6727 leveraging trojanized VPN installers to deploy SUNBRICKED malware.
  • A new Action covering Campaign 26-087, a campaign leveraging financial-themed phishing and malicious VBS scripts to target US government entities and deploy BADWRAP.
  • New Actions demonstrating Campaign 26-085, a North Korean threat actor campaign targeting developer environments and CI/CD pipelines to facilitate DeFi supply chain compromises, leveraging GATEKEEPER and SOMBERMEME malware.
  • A new Action covering Campaign 26-080, a financially motivated actor campaign deploying malicious LNK payloads via fake browser updates to establish persistence.
  • New Actions detailing Campaign 24-061, where financially motivated threat actor UNC5518 distributes FAKETREFF leading to other payloads including QUICKBIND, NETSUPPORT, BANANACOOKIE, CLEANBOOST, CORNFLAKEDARKGATE, and VOLTMARKER via fake browser updates.
  • New Actions demonstrating Campaign 26-083, a suspected East Asia-nexus actor utilizing masqueraded dual-use tools and VBScript to download secondary payloads from cloud infrastructure.

For full details on this release, see the Release Notes on the Mandiant Documentation Portal.