September 10th, 2026 — Single Target Operations (GA), Google Insights, Agentic Updates, and Detection Highlights
🎯 Introducing Single Target Operations
We are introducing Single Target Operations, a powerful new campaign sub-type that brings frontline Mandiant Managed Threat Defense (MTD) investigations directly into your security workflow.
By eliminating the need to observe an adversary targeting multiple organizations before publishing, Single Target Operations deliver high-fidelity, real-world attack campaigns within 24 hours of discovery—all supported by a 2-year historical backfill of verified frontline missions.
Key Capabilities:
- Sub-24-Hour Frontline Actionability: Gain immediate visibility into targeted intrusions and adversary missions uncovered during active Mandiant frontline engagements without waiting for multi-victim correlation. Single Target Operations stream directly into the GTI console with clear, synthesized titles and briefs.
- Rich Context & Native Catalog Integration: Explore Single Target Operations seamlessly under Global Landscape > Campaigns. Every Single Target Operations is delivered with complete contextual intelligence, including IOCs, TTPs, associations with known threat actors and malware, as well as specific industry and regional targeting. (Example: UNC6802 LOOKTOWER PDF Maestro Lure in Government)
- Unified Threat Profiles: Actor, Malware, and Campaign profiles now display associated Single Target Operations alongside traditional multi-target campaigns, providing an uncompromised view of adversary activity.
- Enterprise-Grade Victim Privacy: Built-in automated confidentiality controls safeguard victim identities while ensuring actionable TTPs and infrastructure indicators are fully shareable.
🤖 Google TI Agentic Updates
We continue to expand the analytical depth and automation capabilities of Google TI Agentic:
- MSI & MSIX Installer Parsing: The Malware Analyst can now unpack and inspect Windows Installer packages (
.msiand.msix), automatically surfacing embedded scripts, custom actions, and dropped binaries commonly used in initial-access droppers.
💪 Detection Highlights
The Google Threat Intelligence Group and Flare consistently update Google TI's YARA rules and malware configuration extractors. Over the past two weeks, we released YARA rules covering over 20 newly tracked malware families and expanded our configuration extraction platform for over 40 malware families, prioritizing threats observed in active Mandiant incident responses and SecOps customer environments.
Notable examples from these newly tracked malware families include:
- ENGINELIGHT: A backdoor written in Golang that establishes persistence via the Windows Registry and Startup folder before beaconing to its C2 over HTTPS.
- FELLSWAN: A backdoor written in C/C++ communicating via TCP, supporting screenshot capturing, shell command execution, file transfer, and process termination.
- COLDRAIN: A downloader written in Rust produced using PyOxidizer, which downloads and executes second-stage binaries provided by the C2.
- ZINCGROVE: A 32-bit x86 in-memory dropper and reflective PE loader written in C/C++ that executes embedded payloads directly in process memory without touching the filesystem.
- TELEMON: A 32-bit Windows backdoor and surveillance tool controlled via the Telegram Bot API with GitHub-based licensing validation.
- GATESENTINEL: A modular backdoor written in C using HTTP/S for command and control, featuring process listing and management, system command execution, and arbitrary shellcode injection.
- SEPIASCARP: A downloader written in C++ that communicates with a command-and-control server via HTTP POST using ChaCha20 encryption and a modified Base64 alphabet. Retrieved payloads are reflectively mapped into memory and executed, featuring Windows Scheduled Tasks persistence, indirect syscalls, Halo's Gate hook evasion, call-stack spoofing, and in-memory PE header wiping.
In addition to providing detection rules for new and emerging threats, we continue to update our detection systems for established threats, including REMCOS, SMOKELOADER, NJRAT, and XWORM. These updates ensure you have the latest indicators extracted by our configuration extraction systems.