VB2026 preview: Griffith, LANDFALL, Gorbag research
A VB2026 conference preview details five 2026 threat-research findings: the Griffith cyber-mercenary group, hospitality-sector reservation fraud, Samsung zero-click Android spyware (LANDFALL), Russia-aligned espionage group Gorbag, and new attacks against agentic AI platforms.
This piece previews five research talks slated for VB2026, spanning distinct areas of the threat landscape. Kaspersky researchers cluster the VB6-based DarkMe malware and a new C++ implant, GriffithRAT, into a single cyber-mercenary intrusion set dubbed Griffith, active against fintech and iGaming platform users since late 2024, with initial access via Telegram and Skype. Gen Digital documents 'Reservation Hijack', a multi-stage hospitality fraud chain that begins with phishing against hotel/booking staff and pivots to guest-facing fraud using stolen reservation context delivered through Booking.com, Cloudbeds, SMS, WhatsApp, and email. Unit 42 details LANDFALL, a previously unknown commercial-grade Android spyware framework that exploited a zero-day in Samsung's image-processing library for zero-click compromise via WhatsApp-delivered malformed DNG files, attributed to a UAE-linked actor also running parallel Windows intrusions against Middle Eastern government and financial targets.
ESET introduces Gorbag, a Russia-aligned espionage group targeting Ukrainian military, law enforcement, defence-industry, and local-government entities since early 2025 via spear-phishing with conscription- and drone-procurement-themed lures, deploying a PowerShell backdoor or custom infostealer and self-deleting to hinder forensics. Finally, Gen/Avast researchers examine emerging threats to agentic AI platforms (Claude Code, Cursor, OpenClaw), including the ClawHavoc campaign weaponizing the ClawHub skill ecosystem to spread AMOS and Amatera infostealers, and the Skynet malware's embedded prompt injections designed to fool AI-based security tools. The researchers also cite an incident where an autonomous coding agent deleted 1.9 million rows of customer data due to misidentifying a production environment, underscoring risks from agent autonomy beyond adversarial attack.
Collectively, the article is a research roundup rather than an active incident report, but it surfaces concrete, named intrusion sets, a zero-day exploitation chain, and a genuinely new attack surface (agentic AI abuse) that defenders should track ahead of broader disclosure at VB2026 in October.
Mentioned in this report
Source reporting: https://www.virusbulletin.com/blog/2026/08/what-cybersecurity-experts-are-talking-about-2026
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free