Threat Intelligence Negative 6

Darktrace: 100M-Weekly Axios Downloads Hijacked as Cloud Top Attack Target

For cybersecurity teams, the H1 2026 shift to identity-based attacks in cloud and SaaS environments means traditional defenses are failing. Attackers now inherit trust through compromised accounts, libraries, and admin tools, expanding the breach surface exponentially.

· 4 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Threat Intelligence

8 stories
5.9 avg impact
13% positive
25% negative
vs prior 7 days -1 -1 story vs prior 7 days

Impact 5.9/10 (+0.1 vs prior). Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 12 percentage points.

  • 13% positive
  • 63% neutral
  • 25% negative

This story sits in Threat Intelligence — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

6 impact
Negativesentiment
2sources
4min read
  1. For cybersecurity teams, the H1 2026 shift to identity-based attacks in cloud and SaaS environments means traditional defenses are failing.
  2. Attackers now inherit trust through compromised accounts, libraries, and admin tools, expanding the breach surface exponentially.
Drawn from
  • James Coker
  • It Security News

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Darktrace report reveals cloud and SaaS environments are now the top targets for cyber-threat actors in H1 2026.
  2. 2Attackers moved beyond credential theft to compromise email authentication, cloud entitlements, AI gateways, remote admin tools, and non-human identities.
  3. 3A single compromised SaaS account led to malicious email rule changes, phishing attacks, and lateral network movement, evading detection by appearing innocuous in isolation.
  4. 4In April 2026, the Axios JavaScript library, downloaded over 100 million times per week, was hijacked to distribute remote access trojans (RATs).
  5. 5Legitimate blockchain infrastructure was abused to spread infostealers such as AMOS and Phexia, targeting users with limited security resources.
  6. 6Trust is the new attack surface, as attackers inherit legitimate access through compromised identities rather than bypassing controls.
Weekly JavaScript library downloads
100M targeted

Axios library hijacked to distribute RATs in April 2026

Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools.

Darktrace Threat Intelligence Report

H1 2026 trends

Analysis

Cybersecurity professionals have long prepared for malware and vulnerability exploits, but Darktrace’s new report makes a stark case: the battlefield has moved to the cloud, and your biggest blind spot is trust. In the first half of 2026, attackers didn’t just steal credentials—they turned AI gateways, CI/CD pipelines, and even a ubiquitous JavaScript library into attack highways, leaving signature-based tools blind to the intrusion.

The cybersecurity landscape has undergone a significant transformation in the first half of 2026, with cloud and SaaS environments emerging as the primary targets for sophisticated threat actors. According to a new report by Darktrace, attackers have completed a pivot away from traditional malware and vulnerability exploitation toward a strategy centered on compromising identities. While 2025 saw a heavy focus on stealing account credentials, H1 2026 has witnessed an alarming expansion into email authentication protocols, cloud entitlement abuse, software supply chain corruption, AI gateway infiltration, remote administration tooling, and non-human identities. This shift effectively makes 'trust' the new attack surface, as malicious actors inherit established permissions and legitimate access rather than forcibly bypassing them.

Similarly, Darktrace observed the abuse of legitimate blockchain infrastructure to disseminate infostealers like AMOS and Phexia, preying on users who often lack robust security measures.

The implications are profound. In one illustrative case highlighted by Darktrace, a single compromised SaaS account triggered a cascade of malicious activity across email, SaaS applications, and network layers—including inbox rule modifications and internal phishing campaigns. Crucially, none of these individual indicators were severe enough to trip traditional detection mechanisms on their own; only when correlated did they reveal a clear intrusion. This underscores a fundamental challenge for defenders: as attack patterns grow more subtle and span multiple platforms, security teams must evolve from isolated alerting to holistic behavioral analysis.

The threat multiplies further when attackers target the software supply chain. In April 2026, malicious actors hijacked Axios, a widely used JavaScript library downloaded over 100 million times per week, to distribute remote access trojans (RATs). Because Axios is deeply embedded in countless developer environments and CI/CD pipelines, the breach not only infected end-user machines but gave attackers a foothold in the software development lifecycle itself. Similarly, Darktrace observed the abuse of legitimate blockchain infrastructure to disseminate infostealers like AMOS and Phexia, preying on users who often lack robust security measures. These tactics demonstrate a disturbingly efficient model: by compromising a single trusted node—be it a library, a SaaS account, or a blockchain service—attackers can reach an exponentially larger victim base with minimal effort.

Behind these developments lies a broader industrial trend: the rapid adoption of cloud services has expanded the organizational attack perimeter far beyond the traditional network boundary. Businesses now rely on a web of interconnected SaaS applications, APIs, and third-party integrations, each representing a potential trust relationship that can be exploited. Darktrace's observation that attackers no longer need to bypass trust controls but instead inherit them through compromised identities or delegated access is a sobering reminder that the very mechanisms designed to enable seamless collaboration—single sign-on, OAuth tokens, service accounts—are now prime vectors for intrusion.

What to Watch

For security practitioners, the report serves as a call to action on several fronts. First, identity and access management (IAM) must be elevated from an administrative function to a core security discipline, with continuous monitoring of privilege escalations and anomalous behavior. Second, software supply chain security demands uncompromising rigor: vetting library dependencies, implementing code-signing, and adopting zero-trust principles even within trusted pipelines. Third, AI-driven anomaly detection becomes essential, as legacy rule-based systems fail to spot the subtle, multi-stage attacks that now define the threat landscape.

Looking ahead, the trajectory is unlikely to reverse. As organizations migrate more critical operations to the cloud and increasingly rely on AI gateways and automated workflows, the opportunities for identity-based attacks will only multiply. Non-human identities—service accounts, bots, and machine-to-machine interactions—represent a particularly fast-growing and under-protected segment. Darktrace's findings indicate that the industry must fundamentally rethink trust architectures, moving from implicit to explicit verification and embracing real-time, context-aware security models. The lesson of H1 2026 is clear: in a world where trust is the attack surface, the only sustainable defense is to assume no identity, no library, and no service is inherently trustworthy.

Timeline

Timeline

  1. Shift to Identity-Based Attacks Begins

  2. H1 2026 Attack Surface Expands

  3. Axios JavaScript Library Hijacked

Source cluster

Primary reporting

2articles

Cite This Page

"Darktrace: 100M-Weekly Axios Downloads Hijacked as Cloud Top Attack Target." Cyber Intelligence Brief, August 5, 2026. https://getcyberbrief.com/story/darktrace-100m-axios-hijack-cloud-attack-target

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.