Trellix SecondSight report exposes hidden cyber risks

Trust is becoming a useful weapon for attackers. The latest Trellix SecondSight report, covering five campaigns observed between January and June 2026, shows how compromised accounts, legitimate software and trusted dependencies can help attacks stay under the radar.
For Indian organisations, the findings are particularly relevant because the exposure may not always begin with an obviously malicious file or website. Instead, attackers are increasingly using systems and services that businesses already trust.
Trusted accounts can hide long-term espionage
One investigation focused on a June 2026 spear-phishing campaign against a European embassy in Asia. Attributed to Bitter APT, the campaign used a compromised diplomatic mailbox and a FIFA World Cup-themed lure to deploy BDarkRAT.
Threat hunters traced the command-and-control domain to an earlier October 2025 attack on the same embassy. The connection points to a sustained espionage effort rather than a one-off intrusion.
Another campaign, JSCeal, targeted organisations in Southeast Asia with an encoded PowerShell script and a legitimate Node.js runtime. Its in-memory payload was designed to steal browser passwords, session cookies and cryptocurrency wallet data.
The investigation highlights why threat hunting needs to look beyond individual alerts and examine how different pieces of activity connect.
Supply chain risks are harder to see
The report also examines the March 2026 compromise of Axios, a widely used JavaScript library downloaded roughly 100 million times weekly. After an npm maintainer account was taken over, two malicious package versions were published with a cross-platform remote access trojan.
For development teams, this shows how supply chain risks can enter through software dependencies rather than directly targeting an organisation.
The wider lesson for Cybersecurity India is clear: trusted does not automatically mean safe. Security teams need visibility into accounts, software and suppliers while connecting threat intelligence with activity inside their own environments.
The five investigations also cover an APT28 espionage campaign targeting European organisations and a nation-state iOS exploit chain. Together, they show the value of combining threat intelligence, AI-powered automation and human expertise.
Read More:
Christie Laser Projectors bring Kolkata’s new museum alive
National Engineers’ Day 2026: How AI is reshaping engineering and B2B technology






