During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on the pefile library[2] to extract some info from the PE headers. Indeed, the PE file format contains a lot of metadata! They can be accessed using a lot of tools, like Detect It Easy:
Dark Caracal has deployed GoCaracal, an upgraded variant of the Bandook toolkit, targeting a communications organization in Venezuela with novel command-and-control capabilities. The malware incorporates an Ethereum-based C2 fallback mechanism designed to maintain resilient communications even if primary command channels are disrupted. Arctic Wolf Labs researchers attribute the June 2026 intrusion to the Lebanon-linked espionage group, marking a continuation of their targeting of Venezuelan entities.
A 296K-node IoT botnet and coordinated targeting of over 100 water systems represent escalating threats to critical infrastructure, while researchers have identified a SharePoint RCE exploit chain among emerging vulnerabilities. Social engineering tactics leveraging fake login pages, security scans, and productivity applications continue to serve as effective initial access vectors alongside more sophisticated techniques including AI-augmented botnets and command-and-control traffic obfuscation. The threat landscape this week demonstrates attackers' evolving methods from credential harvesting to supply chain compromise and delayed malware activation to evade detection systems.