Skip to content
Attackers Exploit Trusted Tools in Cyber Campaigns

Attackers Exploit Trusted Tools in Cyber Campaigns

First seen 3 Apr 2026, 09:14 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 4, 2026 at 08:47 UTC
  • •BaoLoader accounted for 40.9% of tracked cyber incidents, primarily through drive-by compromises.
  • •ClickFix social engineering technique was involved in over 44% of defense evasion activities.
  • •CVE-2026-1731 in BeyondTrust software is actively exploited for initial and ongoing access.

ReliaQuest's analysis reveals a significant rise in cyberattacks utilizing trusted tools and user behavior manipulation from December to February. The report identifies BaoLoader as the leading malware, involved in 40.9% of incidents, primarily through drive-by compromises disguised as legitimate software. ClickFix, a social engineering tactic, was linked to over 44% of defense evasion incidents. The analysis indicates a shift from complex malware to exploiting familiar tools, especially during the US tax season when searches for financial software increased. Shai-Hulud, a new malware variant, ranked second at 27.3%, evolving into a threat targeting cloud credentials. Remote monitoring tools like ConnectWise ScreenConnect and BeyondTrust were also exploited, with BeyondTrust's CVE-2026-1731 being actively exploited shortly after its disclosure. This trend highlights the growing sophistication of cyber threats leveraging legitimate software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 189d ago How this analysis works

Timeline

2026-02-06
CVE-2026-1731 published
2026-02-11
First public PoC for CVE-2026-1731
2026-02-13
CVE-2026-1731 added to CISA KEV for active exploitation
Recent
ReliaQuest report published detailing attack trends

More articles in this cluster (4)

Following this threat?

Track CVE-2026-1731 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed