August 26th, 2026 — Google Insights, Agentic Updates, and Detection Highlights

🌐 Introducing Google Insights

We are thrilled to introduce Google Insights, an exciting new capability for all GTI Enterprise and Enterprise Plus customers. This powerful new feature leverages Google's global threat visibility to enrich indicator lookups with real-world in-the-wild prevalence and observational telemetry. This empowers security teams to confidently distinguish between isolated noise and active, targeted campaigns executing in the wild.

Key Capabilities:

  • Global Organization Counts: View the deduplicated number of impacted organizations globally, allowing analysts to immediately distinguish between high-frequency local noise and widespread campaigns.
  • In-the-Wild Observation Timelines: Access verified First Seen and Last Seen timestamps and track observation trends to identify emerging campaigns or resurging dormant threats.
  • Industry & Geographic Distributions: Visualize targeting patterns across various industry sectors and global regions to instantly evaluate victimology and exposure.
  • API Access: Queryable programmatically via the GTI Telemetry REST endpoints (GET /v3/indicators/{type}/{id}/telemetry).

🤖 Google TI Agentic Updates

We are continuously enhancing our Agentic capabilities to provide more context, accuracy, and efficiency to your security workflows. This release brings several powerful upgrades:

  • Verifiable Source Citations in Flow Emails: To ensure transparency and confidence in automated analysis, we have expanded our inline, clickable source citations to scheduled email digests. Just like in the Agentic UI, the automated email summaries generated by your Flows now feature direct links to the underlying sources, allowing analysts to easily verify intelligence straight from their inbox.
  • Automated Rule Translation: To save analysts time on manual coding, Agentic can now automatically translate generic Sigma detection rules into approximately 10 specific SIEM query languages (like EQL).
  • Interactive URL Screenshot Analysis: Agentic URL scanning has been upgraded to allow you to interact with captured screenshots. You can now ask the AI agent specific questions about the visual elements of a scanned URL—such as identifying color palettes or spoofed brand logos—to gain deeper context into suspicious or brand-impersonating pages. View an example conversation here.

💪 Detection Highlights

The Google Threat Intelligence Group and FLARE team consistently update Google TI's YARA rules and malware configuration extractors. Over the past few weeks, we've released YARA rules covering over 25 newly tracked malware families and expanded configuration extraction for several others. We prioritize content based on threats actively observed in Mandiant incident response engagements, Google SecOps customer environments, and top GTI search trends.

Notable examples from these newly tracked malware families include:

  • ZINCSPIRE: A credential stealer written in C/C++ targeting web browsers, cryptocurrency wallets, and messaging applications. It captures screenshots and extracts protected browser data before exfiltrating to a remote server or Telegram via a proxy.
  • BEAMSHIFT: A Go-based sideloading dropper that targets Windows systems by masquerading as legitimate Microsoft Defender components, using reflective loading to execute payloads entirely in memory.
  • PUNCHBOWL: A Go-based backdoor with extensive infostealer capabilities, automated USB monitoring, and integrated ChromeKatz functionality to extract Chromium browser credentials.
  • COALDUST: A downloader delivered as a DLL and executed via DLL Search Order Hijacking. It decrypts and executes embedded payloads or fetches them from an external C2 server.
  • SILVERROOK: A dropper written in C++ that terminates security software using Bring Your Own Vulnerable Driver (BYOVD) techniques.
  • DIAMOTRIX: A .NET NativeAOT dropper that elevates privileges, disables EDR agents using a BYOVD kernel driver, and deploys payloads via in-memory process hollowing.
  • DUSKVAULT: A C++-based information stealer that targets messaging applications and utilizes an on-demand clipboard hijacking engine.

In addition to providing detection rules for new and emerging threats, we continue to update our detection systems for established threats, including QUASARRAT, WARZONE, MIRAI, SOGU.SEC, CORNFLAKE.V2, and BEACON. These updates ensure you have the latest indicators extracted by our configuration extraction systems.