216.73.216.197

Law Firm Sites Hijacked in Suspected Supply-Chain Attack

· Published 18/02/2026 16:28 · Modified 18/02/2026 19:14

Export JSON

Essential information

Published
18/02/2026 16:28
Modified
18/02/2026 19:14
Tags
2026-02-18 clickfix fake browser updates hz hosting ltd law firms mivocloud netsupport rat sectoprat stealc supply chain attack wordpress
Related entities
147 observables, 1 intrusion sets (apt), 24 techniques (mitre), 3 malware, 200 others

Description

GrayCharlie, a threat actor active since mid-2023, compromises sites to inject links redirecting visitors to payloads via or mechanisms. These infections often lead to and deployments. The group's infrastructure is primarily linked to and . A cluster of US law firm sites was compromised around November 2025, possibly through a supply-chain attack. GrayCharlie uses two main attack chains: one involving and another using -style lures. The group's objectives appear to focus on data theft and financial gain, with potential access selling to other threat actors.

External references