SecPod

Learn Search

Search across all Learn content

← Back to Security Research
2026  Second quarter attacker campaigns

2026 Second quarter attacker campaigns

Oct 7, 2026By Rinu K
threat intelligence

Quarterly Attack Trends Briefing

Between July and September 2026, the most consequential intrusions again began at systems that organizations were relying on to keep them safe: a fully updated browser, a WAF rule in front of an ERP server, an MFA-protected VPN gateway, a self-hosted Git server, a content-management platform and the camera network at the perimeter. Several of the operations in this report started in late spring and only became visible this quarter, but each was disclosed, escalated or materially updated between July and September.

The defining trend was the speed at which capability moved from one actor to the next. BlueMoon chained two Chrome V8 zero-days with a Windows kernel bug and was in the hands of four espionage clusters within about two weeks. Red Heron turned public Gitea proof-of-concept code into an automated exploitation framework within days of the advisory. wp2shell was probed on the day it was disclosed and reached CISA's Known Exploited Vulnerabilities catalog four days later. ShinyHunters showed the other side of the same compression: when defenders answered its PeopleSoft zero-day with WAF rules instead of patches, it changed a single character of the request path and walked around them.

Identity and session material were the second theme. CitrixBleed 2 let Anubis affiliates replay stolen NetScaler sessions that had already satisfied MFA. NightEagle logged in to corporate VPNs with valid stolen credentials and then used an Exchange backdoor, RDP tunnels and DCSync to reach domain controllers. UTA0533 took root on SonicWall SMA appliances, where it could sniff LDAP credentials in transit. In each case the attacker inherited a trusted position instead of fighting its way in.

The third theme was where the valuable data lives. Cl0p went after PTC Windchill and FlexPLM, the platforms that hold engineering drawings and product data, and extorted victims without encrypting a single file. Red Heron's access to Gitea reached source code, tokens and, in one environment, root on a Proxmox cluster, while ShinyHunters went after PeopleSoft systems that hold HR, payroll and student records. At the other end of the scale, RustDuck and Operation CameraSwarm showed that exposed Telnet, SSH, ADB and camera-management ports still feed botnets and access brokers at volume.

Taken together, these campaigns show an attacker ecosystem moving toward shorter patch-gap exploitation windows, shared exploit capability, trusted-session abuse, engineering and development systems as extortion targets, and durable access to exposed infrastructure at scale. The technical chapters that follow trace how each operation progressed, which ATT&CK techniques were visible, what evidence defenders can hunt, and where intervention is most likely to break the chain.

Browser zero-day espionage

TA412 and BlueMoon: Chrome-to-Windows exploitation for browser espionage

A China-aligned espionage actor delivered a Chrome V8 exploit chain and a Windows kernel privilege-escalation zero-day through spearphishing links, then installed a fake Gemini extension for browser surveillance and credential theft.

01disclosure9 September 2026
02ActorTA412 / APT31 / Violet Typhoon
03TargetsUS NGOs, mining and commodity-trading firms
04First observed28 August 2026

Why TA412 and BlueMoon matters

Researchers identified BlueMoon as an exploit kit that chains CVE-2026-85046 (a V8 type confusion in the TurboFan compiler), CVE-2026-87491 (a V8 sandbox escape through WebAssembly metadata corruption) and CVE-2026-85880 (a Windows ALPC/WNF kernel privilege-escalation zero-day that only works on older builds). Both Chrome flaws were patch-gap zero-days: the upstream fix for the first was committed on 7 August but did not reach stable Chrome until 3 September. TA412 was the first observed user, sending internship and conference lures to a small set of US organizations before a loader installed a malicious Chromium extension posing as Google Gemini.

Visual attack flow

01
IAInitial access
Spearphish with a link to an actor-controlled exploit page
02
EXEExecution
Run V8 type-confusion exploit (CVE-2026-85046) in the renderer
03
OPOperation
Escape the V8 sandbox via WebAssembly corruption (CVE-2026-87491)
04
DSDiscovery
Fingerprint Windows build and process integrity level
05
OPOperation
Elevate with the ALPC/WNF kernel exploit (CVE-2026-85880)
06
EXEExecution
Inject into the Chrome broker; curl downloads the loader
07
PSPersistence
Forge Secure Preferences HMACs and install the GemStone extension
08
EXExfiltration
Send keystrokes, cookies, storage and screenshots to a Cloudflare Worker C&C

Attack methodology and infection process

  1. Initial access. Phishing messages posed as students seeking internships or as outreach about the AAS-in-Asia 2026 conference, sometimes after rapport-building exchanges. Victims saw a loading page for several seconds and were then redirected to a legitimate site such as github.com or asianstudies.org.
  2. Browser exploitation. An orchestration script (driver-html.js) runs as a worker and controls retries and the follow-on download. The TurboFan bug, triggered by mutating an array mid-sort, yields addrof/fakeobj primitives and arbitrary read/write inside the V8 cage; the WebAssembly corruption then runs shellcode outside the sandbox.
  3. Windows escalation. A reflectively loaded DLL collects the Windows build, token integrity level and kernelbase.dll version. Only Windows 10 1809 through 22H2, Server 2019, Server 2022 and Windows 11 21H2 proceed to the LPE DLL, which obtains kernel read/write and enables SeDebugPrivilege.
  4. Payload launch. Injector shellcode writes a CreateProcess stub into the parent Chrome broker process and runs a curl command that saves msgbox.exe or ChromeUpdate.exe to %TEMP% and executes it.
  5. Extension install. The installer extracts the extension to C:\Users\Public\stomp_ext, closes Chrome, Edge, Brave and Vivaldi, recomputes the Secure Preferences HMACs and super_mac, and relaunches the browser with --restore-last-session.
  6. GemStone surveillance. The extension registers with a Cloudflare Workers C&C, polls for commands every 30 seconds or 60 minutes, and can inject a keylogger, capture cookies and storage, take screenshots and issue arbitrary HTTP requests from the browser context.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
Initial AccessT1566.002Phishing: Spearphishing LinkInternship and conference lures with exploit-page links
ExecutionT1203Exploitation for Client ExecutionV8 type confusion and sandbox escape
Privilege EscalationT1068Exploitation for Privilege EscalationALPC/WNF kernel exploit CVE-2026-85880
Defense EvasionT1055Process InjectionStub injected into the Chrome broker process
Command and ControlT1105Ingress Tool Transfercurl download of msgbox.exe / ChromeUpdate.exe
PersistenceT1176Browser ExtensionsGemStone installed in Chromium-family browsers
Defense EvasionT1036MasqueradingExtension presented as a Google Gemini companion
CollectionT1056.001Input Capture: KeyloggingInjected keylogger/recorder
Credential AccessT1539Steal Web Session CookieCAPTURE_COOKIES command
CollectionT1113Screen CaptureSCREENSHOT_NOW and keyword-triggered captures
Command and ControlT1102Web ServiceCloudflare Workers used for C&C

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
SHA-256779b3e1a470e589d492b99154ba11622fbaebb19b3de694f660c725411b7096ddriver-html.js (TA412 BlueMoon exploit JavaScript)
SHA-2567d6f6dcb17a423bdd7715f8a4e34f2939501a761bc9bf7aa005f805ef1f82288ChromeUpdate.exe / msgbox.exe installer
SHA-256353b5bd2780c1b0c07c1283d83cf16cf1e9ec226c17b2d09d56848893f9d98eeGemStone background.js service worker
Domainsecboxes[.]com; msbenefit[.]com; attcdn[.]comTA412 exploit delivery and download domains
Hostnameextension-management-portal.centerfjdr658.workers[.]devGemStone C&C on a Cloudflare Worker
PathC:\Users\Public\stomp_extExtension staging directory
Processchrome.exe → cmd.exe → curl.exe → msgbox.exeDefault BlueMoon process tree
Artifactv8ctf_exp_attempt (sessionStorage); kc_state; portal_sync_configExploit retry counter and GemStone extension state keys

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Update Chrome and every Chromium-based browser (Edge, Brave, Vivaldi) as soon as stable builds ship, apply the September 2026 Windows updates, and retire the older Windows builds the LPE targets.
  • Alert on chrome.exe spawning cmd.exe or curl.exe, and on executables written to %TEMP% by a browser child process.
  • Inventory extensions installed outside the Web Store; hunt for Secure Preferences changes, C:\Users\Public\stomp_ext and Gemini-themed extensions that request cookies and scripting permissions.
  • Deploy the public Emerging Threats signatures for the BlueMoon loader and GemStone C&C (SIDs 2071919–2071924 and 2071996–2072001) and restrict workers.dev callbacks where there is no business need.
  • Treat confirmed victims as credential and session compromises: revoke sessions, remove the extension and rotate passwords entered in the browser.

Enterprise application exploitation

ShinyHunters: renewed Oracle PeopleSoft mass exploitation

An extortion group re-weaponized a patched PeopleSoft flaw by URL-encoding one character of the request path, bypassing WAF-only mitigations and deploying web shells, a trojanized-installer backdoor and tunneling tools on dozens of servers worldwide.

01update25 September 2026
02ActorShinyHunters (UNC6240)
03VulnerabilityCVE-2026-35273 (PSEMHUB)
04TargetsHigher education, technology, IT services, healthcare, agriculture, transportation, government

Why ShinyHunters matters

CVE-2026-35273 is a critical unauthenticated deserialization flaw in PeopleSoft's Environment Management Hub (PSEMHUB) servlet. UNC6240 exploited it as a zero-day between 27 May and 9 June 2026, mostly against universities, and Oracle issued an out-of-band alert on 10 June. Mandiant and Google Threat Intelligence Group now report a second wave in which the group adapted to published guidance: requesting /%50SEMHUB/ instead of /PSEMHUB/ slips past WAF rules that match the literal path before decoding. ShinyHunters also claimed a PeopleSoft-based compromise of FBI infrastructure on 22 September; the point of entry has not been established, and no link to CVE-2026-35273 has been confirmed. [mandiant-peoplesoft]

Visual attack flow

01
DSDiscovery
Verify exploitability with quiet POSTs to /%50SEMHUB/hub
02
IAInitial access
Send a serialized Java object through the encoded path to bypass WAF rules
03
PSPersistence
Write x.jsp web shells to every load-balanced node, or run fileless commands
04
EXEExecution
Run hex-encoded commands; upload binaries in chunks with u.jsp
05
OPOperation
Launch Ple64.exe, a trojanized installer that loads the SIDEEYE backdoor
06
LMLateral move
Tunnel with Neo-reGeorg; persist on Linux with MeshAgent
07
CRCredentials
Read psappsrv.cfg, database strings and service-account secrets
08
EXExfiltration
Archive with tar/zstd, move data by rsync/curl and extort

Attack methodology and infection process

  1. Target verification. Servers typically receive five to 15 POST requests to /%50SEMHUB/hub carrying a serialized Java object. Unpatched servers answer with the host operating system without writing files, which lets the actor confirm exploitability quietly.
  2. WAF bypass. %50 is the encoded form of P. WAF and proxy rules that match /PSEMHUB before decoding miss the request, while WebLogic decodes the path and serves the vulnerable servlet.
  3. Exploitation. Two methods were seen: a burst of requests followed by x.jsp or sequentially numbered JSP files in PSEMHUB.war (the repetition likely ensures every node behind a load balancer gets a copy), and fileless execution where command output returns in the HTTP response.
  4. Post-exploitation tooling. x.jsp accepts hex-encoded commands and detects the operating system; u.jsp and u2.jsp write 150 KB Base64 chunks. On Windows, Ple64.exe masquerades as a signed Light Alloy installer, unpacks a VMProtect-protected launcher and loads SIDEEYE, which talks to its C2 over raw TCP ports 3333 and 3334. Neo-reGeorg tunnel.jsp and tunnel.jspx provide SOCKS5 over HTTP(S).
  5. Persistence and access. On Linux, UNC6240 deployed MeshAgent and used IT-themed infrastructure (winmanage-me[.]network). A quarter of observed commands ran as root or NT AUTHORITY\SYSTEM; the rest ran as PeopleSoft or WebLogic service accounts, which still expose configuration files and database connection strings.
  6. Collection and extortion. Defenders should look for large tar, tar.gz or zstd archives, and for rsync, sshpass or curl launched by the WebLogic service account, ahead of extortion contact.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
ReconnaissanceT1595.002Active Scanning: Vulnerability ScanningFive to 15 verification POSTs per target
Initial AccessT1190Exploit Public-Facing ApplicationCVE-2026-35273 via /%50SEMHUB/hub
PersistenceT1505.003Server Software Component: Web Shellx.jsp, u.jsp and tunnel.jsp/jspx
ExecutionT1059.003Windows Command Shellcmd.exe spawned by the WebLogic Java process
ExecutionT1059.004Unix Shell/bin/sh reconstructed from an ASCII character array
Defense EvasionT1027Obfuscated Files or InformationHex-encoded commands; VMProtect-packed launcher
Credential AccessT1552.001Credentials In Filespsappsrv.cfg and application secrets
Command and ControlT1090ProxyNeo-reGeorg SOCKS5 over HTTP(S)
Command and ControlT1219Remote Access SoftwareMeshAgent / MeshCentral
ExfiltrationT1048Exfiltration Over Alternative Protocolrsync (TCP 873), SSH and HTTP POST

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
IP5.199.162[.]157Attack controller, scanner and HTTP callback receiver
IP104.219.234[.]138Exfiltration staging and MeshCentral host
IP162.219.30[.]165SIDEEYE C2 (TCP 3333/3334)
Domainwinmanage-me[.]networkMeshCentral infrastructure
URI/%50SEMHUB/Percent-encoded WAF bypass; assume other variants exist
SHA-2563ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3Ple64.exe trojanized installer delivering SIDEEYE
SHA-25648b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494x.jsp (hashes vary with whitespace)
PathPSEMHUB.war/x.jsp; u.jsp; tunnel.jsp; tunnel.jspx; Ple64.exeFiles that are not part of the shipped product

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Apply Oracle's Security Alert patch for CVE-2026-35273; WAF rules and path blocking are not a substitute for patching.
  • Disable EMHub in multi-server configurations or remove PSEMHUB in single-server ones, and enforce blocking on the normalized path, including percent-encoded and mixed-case variants.
  • Search WebLogic access logs for /PSEMHUB/ and encoded variants, POST requests to /hub, and requests to unexpected .jsp files; check every node behind the load balancer.
  • Alert on shell processes spawned by the WebLogic Java process, especially those using base64 -d, curl, /dev/tcp, tasklist or start /b.
  • Rotate every credential readable by the PeopleSoft tier and prepare for extortion contact if a web shell is found.

Credential-led cyberespionage

NightEagle: stolen VPN access to GhostContainer and Active Directory compromise

A cyberespionage group that previously focused on Asia used valid VPN credentials, an in-memory Exchange backdoor and legitimate tunneling features to move from the perimeter to Active Directory at Russian manufacturing and construction organizations.

01disclosure16 September 2026
02ActorNightEagle (APT-Q-95)
03TargetsRussian manufacturing and construction organizations
04Active sinceAt least 2023

Why NightEagle matters

Incident responders investigated several NightEagle intrusions over the past year. Most began with stolen VPN credentials used from Russian addresses linked to Cloudflare WARP tunnels and from European VPS providers. The operators placed GhostContainer, a .NET backdoor, on Microsoft Exchange servers, hosted their tooling in GitHub repositories named to look benign, exposed RDP through Microsoft dev tunnels and rdp2tcp, and used BlueKeep, Kerberos ticket abuse and DCSync to reach domain controllers. The defensive problem is that almost every step uses a valid account or a legitimate feature.

Visual attack flow

01
IAInitial access
Log in to the corporate VPN with stolen valid credentials
02
EXEExecution
Load GhostContainer on Exchange in memory through a VIEWSTATE payload
03
OPOperation
Pull archived tools from GitHub repositories with benign-looking names
04
PSPersistence
Expose RDP with Microsoft dev tunnels and rdp2tcp
05
OPOperation
Forward ports with netsh portproxy via Impacket atexec tasks
06
LMLateral move
Move over RDP; use BlueKeep to create a local administrator
07
CRCredentials
Request Kerberos tickets with unusual flags and run DCSync
08
OPOperation
Use long-lived tickets to reach domain controllers and the wider AD estate

Attack methodology and infection process

  1. Initial access. In most incidents the operators connected to corporate VPNs with compromised valid credentials, routing through Cloudflare WARP-linked Russian addresses and European virtual infrastructure providers.
  2. GhostContainer on Exchange. The backdoor is a .NET assembly that incorporates the Neo-reGeorg tunnel, a CVE-2020-0688 exploit and the GhostWebShell class from ysoserial. Analysts assess with high confidence that it was delivered by extracting Exchange cryptographic keys from the ASP.NET configuration, overwriting the VIEWSTATE parameter and injecting a payload that starts the backdoor in memory. C2 commands arrive in x-owa-urlpostdata headers, and the code overwrites addresses in amsi.dll and ntdll.dll to evade AMSI and event logging.
  3. Tool staging. Archives were hosted in GitHub repositories such as mirror-js/mirror-js and browserthemes/resourcepack, and the executables inside mimic Adobe, TrueConf and 1C software.
  4. Tunneling. Microsoft dev tunnels published port 3389 on *.devtunnels.ms, rdp2tcp carried TCP traffic over established RDP sessions, and Impacket atexec created scheduled tasks that ran netsh interface portproxy rules.
  5. Active Directory compromise. In one incident BlueKeep (CVE-2019-0708) created a local account that was added to Administrators and Remote Desktop Users. The operators also requested Kerberos tickets with Forwardable, Proxiable and Renewable flags and attempted DCSync to impersonate a domain controller.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
Initial AccessT1133External Remote ServicesCorporate VPN access with stolen credentials
Initial AccessT1078Valid AccountsCompromised VPN accounts from WARP and VPS ranges
ExecutionT1620Reflective Code LoadingVIEWSTATE payload starts GhostContainer in memory
Defense EvasionT1562.001Impair Defenses: Disable or Modify ToolsAMSI and event-log evasion in the backdoor
Command and ControlT1105Ingress Tool TransferGitHub-hosted archives with disguised executables
Command and ControlT1572Protocol TunnelingDev tunnels, rdp2tcp and netsh portproxy
Lateral MovementT1021.001Remote Desktop ProtocolRDP to internal servers through tunnels
Lateral MovementT1210Exploitation of Remote ServicesBlueKeep (CVE-2019-0708)
ExecutionT1053.005Scheduled TaskImpacket atexec tasks for port forwarding
Credential AccessT1003.006OS Credential Dumping: DCSyncReplication of the Domain-Password object

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
MD51dcafb7f8448683281106b06dd22409aAdobeSync.exe
MD51f3034b706c78b35d8e34044e68c693aadobe_32.exe
MD53ecd1cd627d0340c92901a478a7caad8; 631fb131a56caf4ca0f287ed73e876abApp_Web_Container_1.dll (GhostContainer)
MD54aa9fb1bf9223dfcdac920759bc7a3c71c-office-plugin.exe, 1cbroker.exe, trueconf.exe
URLgithub[.]com/mirror-js/mirror-js; github[.]com/browserthemes/resourcepackRepositories hosting the tool archives
Domain*.devtunnels[.]msDev tunnel used to expose RDP
Event logRdpCoreTS Operational events 132/148 with channel name rdp2tcpVirtual-channel creation by rdp2tcp or random channel names
Commandnetsh interface portproxy add v4tov4 listenport=443 ... connectport=445Port forwarding created through scheduled tasks

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Require strong MFA on VPN access, review VPN accounts that appear in credential leaks, and alert on sessions from Cloudflare WARP or VPS ranges.
  • Enable and retain RDP operational logs, scheduled-task auditing, PowerShell logging, DNS records and Active Directory replication auditing.
  • Alert on DNS lookups for *.devtunnels.ms, RDP virtual channels named rdp2tcp, and netsh portproxy changes created by remote scheduled tasks.
  • Patch or retire systems exposed to BlueKeep and monitor for DCSync requests from hosts that are not domain controllers and for Kerberos tickets with unusual flag combinations.
  • Rotate Exchange validation and decryption keys after suspected VIEWSTATE abuse, and hunt for unexpected App_Web_*.dll assemblies on Exchange servers.

Development-infrastructure compromise

Red Heron: Gitea exploitation to virtualization root access

A suspected PRC-linked actor weaponized a critical Gitea RCE within days of its advisory, stole repositories and secrets at scale, and in one Taiwanese environment pivoted from a Synology-hosted Gitea server to root on a three-node Proxmox cluster.

01disclosure13 September 2026
02VulnerabilityCVE-2026-60004 (CVSS 9.8)
03Scanned1,386 Gitea instances in seven countries
04AttributionChinese-speaking, PRC-linked context (moderate confidence)

Why Red Heron matters

Gitea 1.27.1 fixed CVE-2026-60004 on 27 July 2026, and the advisory with a working proof of concept followed on 28 July. Acronis TRU found that Red Heron began adapting a public PoC on 29 July and, by early August, had an automated framework (exp_enhanced.py) that registered accounts, exploited servers, dumped repositories and cleaned up traces. Confirmed compromises affected organizations in Canada, Argentina, Taiwan, the United States and Sri Lanka. Because the actor left its staging server open, researchers saw its target lists, command history, stolen repositories and a new Linux implant, JITTERLY, with an embedded rootkit, SIXZUT. [acronis-red-heron]

Visual attack flow

01
DSDiscovery
Scan Gitea hosts with FOFA and probe for open registration
02
IAInitial access
Register a throwaway account and submit the crafted patch twice (CVE-2026-60004)
03
EXEExecution
Git runs hooks/post-index-change as the Gitea service account
04
CRCredentials
Dump gitea.db and repositories; crack bcrypt hashes; take JWT and internal tokens
05
PSPersistence
Plant SSH keys and a TCP or /api/v1/metrics backdoor
06
LMLateral move
Pivot from the Synology-hosted server to a Proxmox root ticket
07
EXExfiltration
Pull repositories and start vzdump VM backups on three nodes
08
PSPersistence
Deploy JITTERLY with the SIXZUT LD_PRELOAD rootkit

Attack methodology and infection process

  1. Vulnerability. The diffpatch endpoint runs git apply with three-way merge fallback inside a bare temporary clone. Submitting the same patch twice forces a checkout to disk, so a file written to hooks/post-index-change executes as the Gitea service account. Open registration, enabled by default, removes the need for prior credentials. Affected versions are 1.17 through 1.27.0.
  2. Targeting. Targets were classified with Simplified Chinese sector labels (defense, elections, energy, aerospace, telecom, government, research); 128 had open signup, and a separate list held 477 Taiwanese instances.
  3. Exploitation and theft. The framework registers accounts with a word_word_NNN pattern, exploits each server, dumps the filesystem and repositories with --dump-fs, and attempts to remove its traces from the Gitea database. Hashcat was used on stolen bcrypt hashes.
  4. Persistence. SSH keys named like victim-backdoor and root-shell were planted, a raw TCP backdoor accepted key:command input, and one victim was accessed through the Gitea metrics API.
  5. Virtualization takeover. On a Taiwanese Synology NAS the actor obtained a Proxmox root@pam ticket, uploaded payloads to three nodes and launched vzdump backups, which could have exposed full VM disk images.
  6. Implant and rootkit. JITTERLY, a C++ implant compatible with the Adaptix C2 protocol, supports more than 30 commands. SIXZUT drops libglthread.so.2, writes it to LD_PRELOAD, hides files, processes and connections, blocks kill signals and relaunches the implant.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
ReconnaissanceT1595.002Active Scanning: Vulnerability ScanningFOFA-driven scan of 1,386 Gitea instances
Initial AccessT1190Exploit Public-Facing ApplicationCVE-2026-60004 in the diffpatch workflow
ExecutionT1059.004Unix ShellCommands run as the Gitea service account
Credential AccessT1110.002Password CrackingHashcat against stolen Gitea bcrypt hashes
Credential AccessT1552.001Credentials In FilesJWT, internal tokens and SSH host keys from config
PersistenceT1098.004SSH Authorized KeysPlanted ed25519 backdoor keys
PersistenceT1574.006Dynamic Linker HijackingSIXZUT through /etc/ld.so.preload
Defense EvasionT1014RootkitHidden files, processes and connections
CollectionT1213.003Data from Information Repositories: Code RepositoriesBulk repository and database theft
Privilege EscalationT1068Exploitation for Privilege EscalationGitea access to Proxmox root administrative access

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
SHA-256b441f793c87e54cb7e3f7205e25442aa19920d325cb6af41d2afdc8a0b5cf54fagent.elf (JITTERLY implant)
SHA-25628b132ad55bd310bb5cf3ddb4ace580529ad735204a48cf388830d9039843d8eSIXZUT rootkit decrypted from JITTERLY
Domains2.981666[.]xyz:8082JITTERLY C2 (parent domain 981666[.]xyz)
IP72.11.138[.]109Staging server (port 8888)
Ports48931; 48932Raw TCP backdoor ports
Filelibglthread.so.2; .ld_aux_cahe; /tmp/.X11-unix.lkSIXZUT artifacts (hidden from userland tools)
Accountdsaopk; pvenum02; word_word_NNN pattern; @poc.localExploit and Proxmox enumeration accounts
NetworkUser-Agent gitea-rce-poc/4.0; /api/v1/metrics?k=<key>&x=<cmd>Exploit user-agent and metrics-API backdoor

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Upgrade Gitea to 1.27.1 or later, disable open registration, restrict the diffpatch route and keep Gitea behind a VPN or authenticating proxy.
  • Review accounts and repositories created since 28 July; alert on Gitea spawning shells, interpreters or curl.
  • Check /etc/ld.so.preload and hunt for SIXZUT artifacts from a known-good kernel, offline image or EDR telemetry, because the rootkit hides them on the live host.
  • Audit authorized_keys and outbound connections; treat every credential, token and SSH host key stored in Gitea as disclosed and rotate it.
  • Rebuild compromised hosts rather than cleaning them, and segment Proxmox and NAS management planes from developer tooling.

Shared zero-day exploitation capability

BlueMoon proliferation: four espionage groups adopt one Chrome-Windows exploit kit

Within days of TA412's first use, three more espionage clusters deployed the same exploit chain with different lures and payloads, including ShadowPad, a Rust loader and a DNS-over-HTTPS-resolved backdoor.

01disclosure9 September 2026
02ClustersTA412, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket
03Adoption window28 August to 3 September 2026
04RegionsUnited States, Vietnam, Indonesia, Singapore

Why BlueMoon proliferation matters

Researchers report that the same orchestration and loading code appeared in every build, so the kit almost certainly came from one source, but it is not known how four actors obtained it. Volexity published parallel research on the same day. Analysts saw rushed deployments: infrastructure created the same day as campaigns, a default payload that is just a curl download, and development artifacts (verbose logging, a markdown handover reference and v8CTF strings) that are consistent with, though not proof of, AI-assisted development. The broader lesson is that open-source patch gaps shorten the time between a public Chromium fix and a working exploit.

Visual attack flow

01
IAInitial access
Send themed phishing links: RFQs, vaccination notices, internships, Indonesian conferences
02
EXEExecution
Landing page runs the BlueMoon worker and retries the chain
03
OPOperation
Chain two V8 patch-gap bugs with the Windows ALPC LPE
04
EXEExecution
Run the operator-chosen command from the injected stub
05
PSPersistence
Create tasks: EdgeCore_AutoUpdate, GeForceService, Avpcheckup
06
OPOperation
Sideload DLL pairs and inject into processes such as wmpnetwk.exe
07
CRCredentials
Steal Firefox profile data and sniff network traffic (ShadowPad)
08
EXExfiltration
Beacon through HTTPS, Cloudflare Workers and Google DoH TXT lookups

Attack methodology and infection process

  1. UNK_LateNight (from 2 September). RFQ-themed emails aimed at US aerospace and defense companies linked to domains spoofing aerospace firms. The loader dropped a DLL-sideloading pair plus an AES-encrypted TMP file, injected ShadowPad into targets such as wmpnetwk.exe, and created the scheduled task EdgeCore_AutoUpdate. ShadowPad unhooks 20 network-monitoring functions and beacons to ms.checrity[.]com.
  2. UNK_DoubleCheck (from 2 September). Emails from a compromised Southeast Asian government address, themed around vaccination appointments, hit a Vietnamese manufacturer. The only obfuscated BlueMoon variant used curl to fetch wint.exe, calibre-launcher.dll and an RC4-encrypted SysPr.prx, which loads a Rust executable that pulls a second stage from a Cloudflare R2 bucket and uses fracons[.]com for C&C.
  3. UNK_QuietRacket (from 3 September). Indonesian conference lures (Indo Startup Expo & Forum 2026 and WCCE 2026) targeted government, consulting and finance organizations in Indonesia and Singapore. A modified injector fetched GfExperienceService64.exe and GFExperienceUpdate.dll, which resolve C&C by decrypting Google DoH TXT records and then use Cloudflare Workers.
  4. Shared pattern. All builds share the exploit chain and the loader structure (p1 reconnaissance DLL, p2 LPE DLL, pp injector shellcode), and the default process tree is chrome.exe, cmd.exe, curl.exe, then the payload.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
Initial AccessT1566.002Phishing: Spearphishing LinkRFQ, vaccination and conference lures
ExecutionT1203Exploitation for Client ExecutionV8 type confusion and sandbox escape
Privilege EscalationT1068Exploitation for Privilege EscalationCVE-2026-85880 on older Windows builds
Defense EvasionT1574.002DLL Side-Loadingwint.exe, GfExperienceService64.exe and ShadowPad pairs
PersistenceT1053.005Scheduled TaskEdgeCore_AutoUpdate, GeForceService, Avpcheckup
PersistenceT1546.015Component Object Model HijackingCLSID InprocServer32 registry write (UNK_DoubleCheck)
Defense EvasionT1055Process InjectionInjection into the Chrome broker and wmpnetwk.exe
Command and ControlT1102Web ServiceCloudflare Workers and R2 buckets
Command and ControlT1573Encrypted ChannelChaCha20-decrypted DoH TXT records; ShadowPad binary C&C
CollectionT1040Network SniffingShadowPad traffic sniffing

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
Processchrome.exe → cmd.exe → curl.exe → msgbox.exeDefault BlueMoon process tree
TaskEdgeCore_AutoUpdateUNK_LateNight ShadowPad persistence
TaskMicrosoftEdgeUpdatesTaskMachine; AvpcheckupUNK_DoubleCheck persistence
TaskGeForceService (C:\ProgramData\GfExperienceService64.exe)UNK_QuietRacket persistence
Domainms.checrity[.]com; 79.133.56[.]90ShadowPad C&C and fallback IP
Domainbrianwilli[.]com; fracons[.]comUNK_DoubleCheck download and C&C domains
Domainelixnovorem[.]com; getaiexo[.]com; velodynaity[.]comUNK_QuietRacket DoH TXT lookup domains
ArtifactMutex Dataupcheckinfo; sessionStorage key v8ctf_exp_attemptUNK_DoubleCheck mutex and exploit retry counter
SHA-256295fc584f75e94108c9be945977db33ed80421f5d374eab188587c911dffd915UNK_LateNight msgbox.exe loader

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Roll out Chrome and Chromium-based browser updates within hours, not weeks, and apply the September Windows updates; move off Windows builds targeted by the LPE.
  • Alert on browser child processes running curl and on first-run executables or DLL pairs in %APPDATA%, %TEMP% and ProgramData.
  • Hunt for the listed scheduled task names, CLSID registry persistence and unusual DoH or Cloudflare Workers traffic from non-browser processes.
  • Apply the published YARA rule (MAL_BlueMoon_ExploitKit) and ET signatures 2071919–2071924 to proxy and web telemetry.
  • Expect further adopters: add detections based on the chain, not on any one actor's infrastructure.

WordPress mass exploitation

wp2shell: pre-authentication WordPress RCE moves from disclosure to exploitation

Two WordPress Core flaws chain a REST batch route confusion with a SQL injection into pre-authentication remote code execution, and attacks began on the day of disclosure.

01disclosure17 July 2026
02CVEsCVE-2026-63030 + CVE-2026-60137
03AffectedWordPress 6.9.0–6.9.4 and 7.0.0–7.0.1
04StatusFixed in 6.9.5 / 7.0.2; on CISA KEV

Why wp2shell matters

Searchlight Cyber's Assetnote team disclosed wp2shell on 17 July 2026. It works against default installations with no plugins, and the REST batch endpoint it abuses has shipped since WordPress 5.6. Wordfence recorded probing on the day of disclosure, public PoCs followed within days, and CrowdSec saw first exploitation on 20 July; CISA added the flaws to KEV on 21 July. By 22 August CrowdSec had logged more than 3.1 million matching signals and 62,802 attacking IPs. F5 Labs captured a replayed UNION-based injection but did not observe a web shell in that traffic. [crowdsec-wp2shell]

Visual attack flow

01
DSDiscovery
Probe /wp-json/batch/v1 and ?rest_route=/batch/v1
02
IAInitial access
Nest batch requests with malformed paths to cause route confusion (CVE-2026-63030)
03
OPOperation
Inject SQL through author_exclude into WP_Query (CVE-2026-60137)
04
CRCredentials
Read users and secrets with UNION-based or blind queries
05
OPOperation
Poison the object cache or forge a Customizer changeset
06
PSPersistence
Create an administrator account
07
EXEExecution
Upload a plugin that exposes a command route (public PoC behavior)
08
IMImpact
Run commands as the web server user and take over the site

Attack methodology and infection process

  1. Discovery. Scanners test the batch route in three forms: /wp-json/batch/v1, /index.php?rest_route=/batch/v1 and /?rest_route=/batch/v1, which work when pretty permalinks are off.
  2. Route confusion. An outer batch request wraps an inner batch with malformed sub-request paths; a parse failure shifts indexes between the validation and match arrays so the dispatcher reaches handlers it should not.
  3. SQL injection. The posts endpoint maps author_exclude to WP_Query's author__not_in argument, which is not sanitized enough. Detection should key on author_exclude, the name visible in HTTP traffic.
  4. Escalation (public PoCs). Public tools use the injection to forge cache objects and a changeset that creates an administrator, then upload a plugin to run commands. Observed in-the-wild activity so far is dominated by scanning and injection attempts.
  5. Post-exploitation. Defenders should look for unexpected administrators, new files in wp-content/plugins/ and wp-content/cache/, and commands launched by the web server process.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
ReconnaissanceT1595.002Active Scanning: Vulnerability ScanningBatch endpoint and wp-json enumeration
Initial AccessT1190Exploit Public-Facing ApplicationBatch route confusion plus author_exclude injection
CollectionT1213Data from Information RepositoriesDatabase content exposed through SQL injection
PersistenceT1136Create AccountAdministrator creation in public PoC chains
PersistenceT1505.003Server Software Component: Web ShellPlugin-based web shell in public PoC chains

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
IP185.242.3[.]238Source of an F5-captured, replayed 735-byte exploit
RequestPOST /wp-json/batch/v1 with nested "requests" arrays and "///" pathsRoute-confusion signature
Parameterauthor_exclude containing UNION, SELECT, hex values or %29+UNIONSQL injection through WP_Query
User-AgentStrings referencing wp2shellPurpose-built tooling
Pathwp-content/plugins/; wp-content/cache/Unexpected PHP files or plugins after exploitation
BehaviorNew administrator account created without a login eventChangeset-forgery outcome

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Update to WordPress 6.9.5, 7.0.2 (or 6.8.6 for the SQL injection alone) or later; auto-updates should be enabled for core.
  • Where patching is delayed, block unauthenticated access to /wp-json/batch/v1 and ?rest_route=/batch/v1 at the edge.
  • Add WAF rules for nested batch requests and for author_exclude values containing SQL metacharacters or hex strings.
  • Audit administrator accounts, plugins, wp-content/cache/ and recently modified PHP files on every site exposed before patching.
  • Monitor outbound connections from the web tier and rotate database and salt secrets on suspected compromises.

Enterprise data-theft campaign

Cl0p and PTC Windchill: centralized engineering data becomes an extortion target

Cl0p exploited a critical deserialization flaw in PTC Windchill and FlexPLM, planted JSP web shells, stole engineering and product data and extorted victims without deploying ransomware.

01exploitationFrom about June 2026
02Extortion emails20 July 2026
03Leak site43 organizations, 14–19 August 2026
04VulnerabilityCVE-2026-12569 (CVSS 9.8)

Why Cl0p and PTC Windchill matters

CVE-2026-12569 is an unauthenticated deserialization flaw in PTC Windchill PDMLink and FlexPLM, added to CISA's KEV catalog on 25 June. Intrusions were weeks old when Ransom-ISAC began seeing extortion emails titled "Windchill PDMLink module serious data leak" on 20 July, sent to hundreds of employees at each victim. ZeroFox counted 43 organizations posted between 14 and 19 August and read the campaign as a shift from personal and financial records to engineering intellectual property. Cl0p followed its MOVEit, GoAnywhere, Cleo and Oracle E-Business Suite pattern: one widely deployed application, many victims in a short window, then public pressure. [secpod-blog]

Visual attack flow

01
DSDiscovery
Find exposed Windchill and FlexPLM; probe the FlexPLM WSDL endpoint
02
IAInitial access
Exploit unsafe deserialization (CVE-2026-12569)
03
PSPersistence
Write JSP web shells to /Windchill/login/ with hexadecimal names
04
OPOperation
Use a custom implant to run code inside the application process
05
DSDiscovery
Enumerate files and repositories; create listings such as flst.txt
06
CRCredentials
Decrypt keystore credentials and application secrets
07
EXExfiltration
Stage and exfiltrate databases, backups, drawings and project files
08
IMImpact
Send mass extortion emails and publish victims on the leak site

Attack methodology and infection process

  1. Discovery. Attackers identify internet-facing Windchill and FlexPLM servers and use reconnaissance against the FlexPLM WSDL functionality.
  2. Exploitation. Unsafe processing of attacker-controlled serialized data gives unauthenticated code execution; the flaw has been paired with a pre-authentication information disclosure on the FlexPLM WSDL endpoint.
  3. Web shells. JSP files appear in /Windchill/login/ with 16-character or six-character hexadecimal names, and a dpr_ variant with eight hex characters.
  4. Implant capability. Reporting describes a custom implant that can decrypt credentials in the Windchill keystore, enumerate connected file repositories and pull data in bulk, rather than a simple command shell.
  5. Theft. Operators list files, stage selected data and exfiltrate it; some victims claim multi-terabyte theft.
  6. Extortion. Emails come from compromised accounts, include Cl0p contact details and name Windchill PDMLink. The leak site began naming victims in August; no file encryption was used.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
Initial AccessT1190Exploit Public-Facing ApplicationCVE-2026-12569 against Windchill and FlexPLM
PersistenceT1505.003Server Software Component: Web ShellJSP shells in /Windchill/login/
DiscoveryT1083File and Directory Discoveryflst.txt file listings
Credential AccessT1552Unsecured CredentialsKeystore credentials and application secrets
Command and ControlT1105Ingress Tool TransferTooling brought onto compromised servers
CollectionT1074Data StagedSelected files prepared for transfer
CollectionT1213Data from Information RepositoriesEngineering and PLM repositories
ImpactT1657Financial TheftData-theft extortion without encryption

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
Path/Windchill/login/[0-9a-f]{16}.jsp; [0-9a-f]{6}.jsp; dpr_[0-9a-f]{8}.jspWeb shell hunting patterns
Path/Windchill/login/7c0a0a34c9d8d53b.jsp; 46b158b8607a4c00.jspKnown web shell names
HeaderX-windchill-req: ?x8FmgowMalicious request header
IP5.180.41[.]35; 38.60.157[.]212; 74.50.76[.]146; 78.128.113[.]10Campaign infrastructure (correlate; not proof alone)
IP104.194.9[.]14; 137.184.184[.]209; 185.227.83[.]236; 216.152.151[.]204Campaign infrastructure
SHA-256321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bfIncident-observed file
Fileflst.txtFile-listing artifact from discovery
EmailSubject "Windchill PDMLink module serious data leak"Extortion message sent to many employees

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Apply PTC's fixes for CVE-2026-12569 on every Windchill and FlexPLM instance and remove direct internet exposure where possible.
  • Hunt for JSP files in /Windchill/login/ by pattern, not only by hash, and review logs back to June 2026.
  • Search HTTP telemetry for the X-windchill-req header and correlate with JSP execution and outbound connections.
  • Rotate keystore, database and service credentials reachable from the Windchill server.
  • Prepare an extortion-response plan for data theft without encryption, including legal, customer and IP-exposure assessment.

VPN appliance zero-day exploitation

UTA0533 and KNUCKLEBALL: root-level compromise of SonicWall SMA appliances

A previously unknown actor chained two SonicWall SMA 1000 zero-days to reach root, installed appliance-specific implants and sniffed LDAP credentials before the flaws were disclosed.

01earliest compromise22 June 2026
02disclosure14 July 2026 (Volexity report 17 July)
03ProductsSonicWall SMA 1000: 6210, 7210, 8200v
04CVEsCVE-2026-15409 (CVSS 10.0), CVE-2026-15410 (CVSS 7.2)

Why UTA0533 and KNUCKLEBALL matters

Volexity found the intrusion during incident response in early July after suspicious authentication and lateral-movement attempts originated from SMA appliances. CVE-2026-15409 is a pre-authentication /wsproxy bypass that tunnels to localhost-only services; CVE-2026-15410 is a command injection in the control service's remove-hotfix method that runs a script as root. Patches are in 12.4.3-03453 and 12.5.0-02835. UTA0533 used 200+ source IPs, including commercial VPN ranges, and appears to have had limited success moving laterally. [volexity-sonicwall]

Visual attack flow

01
IAInitial access
Send /wsproxy with User-Agent "SMA Connect Agent" and bmID starting -3389
02
OPOperation
Tunnel to CouchDB (port 1050) and use default admin:admin to write a script
03
DSDiscovery
Read product_uuid to derive the control-service password
04
EXEExecution
Call execRemoveHotfix with path traversal to run /tmp script as root
05
PSPersistence
Drop ROOTRUN and KNUCKLEBALL; add deploy_new.py to /etc/init.d/workplace
06
OPOperation
Inject Suo5 and ORANGETAIL JARs; add nginx routes /__api__/login and /logout
07
CRCredentials
Capture unencrypted LDAP traffic with tcpdump
08
LMLateral move
Attempt authentication from the appliance to internal systems

Attack methodology and infection process

  1. Tunnel. Requests to /wsproxy with the right user-agent and bmID return HTTP 101 and open WebSockets to EPMD (1051), CouchDB (1050) and the control service (8188) without a session cookie.
  2. Root. The actor used CouchDB's built-in admin:admin credentials to stage a script that reads the appliance UUID, then traversed out of the rollback directory (../../../../../tmp/1234.sh) to execute it as root.
  3. Implants. ROOTRUN (/usr/bin/xzfind) is a setuid root command runner. KNUCKLEBALL (deploy_new.py) injects two JARs into workplace.startup.CommandStartup using the Java Attach API and is made persistent through init.d.
  4. Java agents. Suo5 is an HTTP proxy tool; ORANGETAIL is a Behinder-style webshell with a hardcoded AES key. Both only answer a specific fake user-agent, so passive scans see 404s.
  5. Credential theft and pivoting. On the second appliance, tcpdump scripts captured LDAP on TCP 389; the actor leaked hostnames including DESKTOP-5P0TSCP and KALI. A reboot on 2 July removed memory-resident implants there.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
Initial AccessT1190Exploit Public-Facing Application/wsproxy authentication bypass (CVE-2026-15409)
Initial AccessT1078.001Valid Accounts: Default AccountsCouchDB admin:admin
Privilege EscalationT1068Exploitation for Privilege EscalationexecRemoveHotfix traversal (CVE-2026-15410)
Privilege EscalationT1548.001Abuse Elevation Control: SetuidROOTRUN setuid binary
PersistenceT1037.004RC Scriptsdeploy_new.py added to /etc/init.d/workplace
ExecutionT1059.006PythonKNUCKLEBALL injector
Defense EvasionT1055Process InjectionJARs injected through the Java Attach API
PersistenceT1505.003Server Software Component: Web ShellORANGETAIL
Command and ControlT1090ProxySuo5 HTTP proxy
Credential AccessT1040Network Sniffingtcpdump capture of LDAP traffic

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
SHA-25681a9af3846bad3a1107164ff7cf0a08e020b31a3b32fd17866e17d4c1565f7f2ROOTRUN (xzfind)
SHA-2568c470301dcb7278f73e622f1950073567b34011c64b60cdfbb0f89803923a5a3KNUCKLEBALL (deploy_new.py)
SHA-2561e1e68bbb899450a57274a8b12082ed4e2040a2aae77014f20431689d2b4edeeagent_wp8.jar (Suo5)
SHA-256ea9154e374e4f77bc2cf54282e23543573980342a85bc888cb23f20b8bbba081agent_wp9.jar (ORANGETAIL)
Path/usr/bin/xzfind; /usr/lib/python3.11/site-packages/deploy_new.pyDropped implant files
Config/var/lib/unit/conf.json routes to http://127.0.0.1:8085Rewrites for /__api__/login and /__api__/logout
Log/wsproxy?bmID=-3389...&host=0.0.0.0&port=1050 or 8188 (HTTP 101)Exploitation in extraweb_access.log
Log"running hotfix removal for:../../../../../tmp/..." in ctrl-service.logCVE-2026-15410 execution
UAMozilla/6.0 (Windows NT 11.0; ...) Chrome/149.0.0.1Gate string for the implants

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Install SonicWall's fixed builds (12.4.3-03453 or 12.5.0-02835) and hunt back to 22 June, not to the disclosure date.
  • Review extraweb_access.log, access_servers.log and ctrl-service.log for /wsproxy abuse and traversal strings.
  • Check unit/conf.json for unexpected routes, run find / -perm -4000 for unexpected setuid binaries, and inspect /tmp and /var/tmp.
  • Monitor appliances for outbound connections and authentication attempts to internal hosts; rebooting alone does not remove persistence.
  • Reimage compromised appliances and rotate LDAP, VPN and service credentials that crossed them; use LDAPS to limit sniffing exposure.

Edge-to-ransomware intrusion

CitrixBleed 2 and Anubis: stolen sessions open the path to ransomware

Anubis affiliates reached victims through valid VPN credentials and CitrixBleed 2 session theft, blended in with legitimate RMM tools and encrypted Windows, Linux and NAS systems.

01disclosure30 June 2026 (Arctic Wolf Labs)
02VulnerabilityCVE-2025-5777 (CVSS 4.0: 9.3)
03EcosystemAnubis RaaS, 83–91 claimed victims
04Common toolingRMM, cloudflared, Rclone, S3 Browser

Why CitrixBleed 2 and Anubis matters

Arctic Wolf found that Anubis affiliates entered through valid VPN credentials or CitrixBleed 2, a pre-authentication memory disclosure on NetScaler Gateway and AAA servers that can reveal session tokens and bypass MFA. Because affiliates differ, the report is a catalog of affiliate tradecraft rather than a single operator's playbook. The consistent pattern is remote access, then RDP or SMB movement, RMM deployment, credential access and exfiltration tools before encryption. Patching alone does not evict a stolen session. Victim totals vary by date: Arctic Wolf cited up to 83 at publication and later coverage cites 91. [secpod-blog]

Visual attack flow

01
IAInitial access
Exploit CVE-2025-5777 or log in with valid VPN credentials
02
CRCredentials
Replay a stolen NetScaler session token to bypass MFA
03
LMLateral move
Use RDP, SMB and PsExec toward RDS servers, DCs and hypervisors
04
PSPersistence
Deploy ScreenConnect, Zoho Assist, MeshAgent, Remotely or UltraVNC
05
CRCredentials
Run Mimikatz, export browser passwords and copy ntds.dit
06
OPOperation
Create cloudflared, proxy or SSH SOCKS tunnels, including from NAS devices
07
EXExfiltration
Transfer data with S3 Browser, Rclone, s5cmd or WinSCP
08
IMImpact
Disable Defender, clear logs and run the Anubis encryptor

Attack methodology and infection process

  1. Initial access. Valid VPN credentials (including Cisco AnyConnect logins from hosting ASNs) or CitrixBleed 2. In the example log, the session's Source IP (45.227.254[.]25) differed from the original broadband Client_ip.
  2. Lateral movement. RDP between VPN client ranges and servers that normally get no interactive logons, Hyper-V servers used as jump hosts, and PsExec service creation (PSEXESVC.exe).
  3. RMM abuse. ScreenConnect from lookalike azuremicrosoft[.]us, Zoho Assist agents under the ZohoMeeting path, MeshAgent (mvtcs.exe, sysagent.exe, MeshUserTask), Remotely, UltraVNC and Total Software Deployment.
  4. Credential access. Mimikatz in Public and temp folders, Chrome and Edge password exports, and an ntds.dit copy followed within an hour by encryption in one case.
  5. Tunneling and exfiltration. cloudflared on Synology NAS and Windows servers, an authenticated proxy, ssh -D SOCKS proxies, and S3 Browser, rclone, s5cmd, WinSCP and PuTTY.
  6. Impact. Defender disablement, SophosUninstall, PCHunter and log clearing preceded encryption. Anubis writes .anubis files and RESTORE FILES.html on Windows and Linux.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
Initial AccessT1190Exploit Public-Facing ApplicationCitrixBleed 2 on NetScaler Gateway / AAA
Initial AccessT1078Valid AccountsStolen VPN credentials and hijacked sessions
Lateral MovementT1021.001Remote Desktop ProtocolRDP to RDS servers, DCs and hypervisors
ExecutionT1569.002System Services: Service ExecutionPsExec service creation
Command and ControlT1219Remote Access SoftwareScreenConnect, Zoho Assist, MeshAgent and others
Credential AccessT1003.001LSASS MemoryMimikatz on Windows servers
Credential AccessT1003.003NTDSCopy of ntds.dit
Command and ControlT1572Protocol Tunnelingcloudflared and SSH dynamic forwarding
ExfiltrationT1567.002Exfiltration to Cloud StorageS3 Browser, rclone and s5cmd
Defense EvasionT1562.001Impair DefensesDefender disabled; Sophos uninstall
ImpactT1486Data Encrypted for ImpactAnubis encryptors on Windows, Linux and NAS

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
IP45.227.254[.]25Source of a suspicious NetScaler VPN session
IP45.76.79[.]92Remotely Desktop C2
Domainazuremicrosoft[.]us; promotds[.]us (relay.promotds[.]us)ScreenConnect installer and relay lookalikes
TaskMeshUserTaskMeshAgent persistence
ProcessPSEXESVC.exe; tniwinagent.exe; cloudflared in C:\WindowsPsExec, Total Software Deployment and tunnel client
Extension.anubis; RESTORE FILES.htmlEncrypted files and ransom note
PathC:\audit\Active Directory\ntds.dit; C:\Users\Public\mimikatz.exeCredential staging locations
BehaviorRemote access → RDP/SMB → RMM → credentials → exfiltration toolingSequence that is detectable before encryption

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Patch NetScaler for CVE-2025-5777 and then terminate all active ICA, PCoIP, RDP Proxy and AAA sessions per Citrix guidance.
  • Compare Client_ip and Source in gateway logs and alert on VPN sessions from VPS or hosting ASNs.
  • Maintain an RMM allow-list; alert on a second or third RMM product appearing on a host within a short window.
  • Detect Rclone, S3 Browser, cloudflared and SSH SOCKS tunnels on servers and NAS devices, and tamper attempts against EDR.
  • Segment Hyper-V, NAS and backup infrastructure and keep immutable, tested backups.

Resilient IoT botnet activity

RustDuck: a Rust-based DDoS botnet engineered to outlast detection

A still-small DDoS botnet is being rewritten from C to Rust, hardening its loader, anti-analysis checks and C2 encryption while recruiting routers, cameras, Android boxes and exposed servers.

01disclosure30 June 2026 (QiAnXin XLab)
02Tracked sinceFebruary 2026
03TargetsRouters, IP cameras, Android TV boxes, servers
04ObjectiveDDoS (Loader + Core architecture)

Why RustDuck matters

XLab describes RustDuck as small compared with the largest botnets but fast-moving. The loader has gone through four variants with different encryption schemes, and the core module is shifting to Rust, which resists the toolkit analysts have used on Mirai-style malware. It spreads through weak Telnet and SSH credentials, exposed Android ADB, and known flaws in TVT, Ruijie, TP-Link, ZTE, ThinkPHP, Jenkins, Hadoop YARN and Apache CouchDB, plus CVE-2025-29635, CVE-2017-17215, CVE-2024-1781 and CVE-2018-8007. More than 20 IPs were spreading it, led by 176.65.139[.]204. [xlab-rustduck]

Visual attack flow

01
DSDiscovery
Scan for exposed Telnet, SSH and ADB services
02
IAInitial access
Brute-force weak credentials or exploit device and web RCE flaws
03
EXEExecution
Run the loader, which decrypts and unpacks the core module
04
OPOperation
Score the environment for debuggers, sandboxes and honeypots; erase and exit on a high score
05
OPOperation
Resolve DuckDNS C2 and complete a Noise-IK-style handshake
06
OPOperation
Wrap traffic in TLS-like headers and rotate keys every 10 minutes
07
EXEExecution
Accept attack, stop, update, status and C2-update commands
08
IMImpact
Launch DDoS floods from the infected fleet

Attack methodology and infection process

  1. Infection paths. Weak or default Telnet and SSH passwords, exposed ADB, and RCE in routers, DVRs and cameras, plus web and enterprise components such as ThinkPHP, Jenkins and YARN.
  2. Two-stage loading. The loader appends compressed core data and config to an ELF. Variants moved from LCG with XOR and LZ4, to Xoshiro128 with BLZ, to standard XOR with a fixed magic string, to ChaCha20.
  3. Anti-analysis. The core scores process lists (Wireshark, gdb, frida), TracerPid, injected libraries, an appended SHA-256 checksum, Cowrie and Dionaea files, sandbox environment variables, a connect test to 192.0.2.1, dual-clock sleep timing and VM hardware or MAC prefixes; high scores trigger cleanup and exit.
  4. C2 protocol. Handshake with Curve25519 and HKDF-SHA256, ChaCha20-Poly1305 for authentication, then AES-GCM with separate uplink and downlink keys; command traffic carries a three-byte header resembling TLS records.
  5. Commands. Attack (types 3 and 8), stop (9), update (10), status (11) and C2 update (14), so operators can rotate infrastructure without losing bots.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
Initial AccessT1110.001Brute Force: Password GuessingWeak Telnet and SSH credentials
Initial AccessT1190Exploit Public-Facing ApplicationDevice, ThinkPHP, Jenkins, YARN and CouchDB flaws
Defense EvasionT1027Obfuscated Files or InformationEncrypted and compressed core; evolving loaders
Defense EvasionT1497.001Virtualization/Sandbox Evasion: System ChecksHardware, MAC, process and honeypot checks
Defense EvasionT1497.003Virtualization/Sandbox Evasion: Time BasedDual-clock sleep comparison
Defense EvasionT1622Debugger EvasionTracerPid and tool checks
Command and ControlT1568Dynamic ResolutionDuckDNS C2 domains
Command and ControlT1573.002Encrypted Channel: Asymmetric CryptographyCurve25519 key exchange
ImpactT1498.001Network Denial of Service: Direct Network FloodDDoS attack commands

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
SHA-18315f650e9e4f67c00277b076ab304eed23db47dLoader variant 1
SHA-16aa791c76b3107fca9d57b7ecea8f46d97d83738Loader variant 2
SHA-14d11bd496da82d15b3ed13050f414e44f5a892d4Loader variant 3
SHA-1d39a3ee96be6b8f5238cb1253514ab55c88f714cLoader variant 4
IP176.65.139[.]204Most active delivery source
Domainigmc[.]duckdns[.]org; qewqewqewqtq[.]duckdns[.]orgDuckDNS C2 (more in the XLab report)
Domaindhdsjsdjxc[.]duckdns[.]org; fcfrfxrfrsfs5f[.]duckdns[.]orgAdditional DuckDNS C2 hostnames
NetworkConnection attempt to 192.0.2.1; TLS-like 17 03 03 record headerSandbox check and C2 framing

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Remove Telnet, SSH and ADB from the internet, and change default passwords on every device.
  • Patch or replace end-of-life gear; CISA's guidance for the D-Link DIR-823X is to remove it from service.
  • Monitor for DuckDNS or other dynamic-DNS lookups from IoT and server networks and block where unneeded.
  • Update analysis tooling to handle Rust binaries and feed XLab's hashes and domains into monitoring, expecting variants to change them.
  • Use upstream DDoS mitigation and egress filtering so compromised devices cannot join attacks.

Surveillance infrastructure compromise

Operation CameraSwarm: 14,530 Dahua devices compromised at scale

One operator brute-forced, bypassed and relayed its way into more than 14,000 Dahua cameras in 35 days, planting a backdoor account on 1,923 devices and building transferable admin access.

01window17 June – 22 July 2026
02disclosure18 August 2026 (Hunt.io)
03Scale14,530+ devices
04GeographyUkraine and Russia (largest confirmed share)

Why Operation CameraSwarm matters

Hunt.io reconstructed the campaign from a 407 MB operator directory that was left exposed (2,616 files). Three paths ran in parallel: brute force against TCP/37777 reached 12,324 unique IPs, the CVE-2021-33044 and CVE-2021-33045 authentication bypasses planted a backdoor on 1,923 cameras, and abuse of Dahua's P2P relay reached 283 more by serial number. The operator's own code records that 89.4 percent of live serials returned an open channel. Counts come from Hunt.io's analysis and have not been independently confirmed. [secpod-blog]

Visual attack flow

01
DSDiscovery
Scan TCP/37777 with masscan; harvest serials via Shodan and DDNS
02
CRCredentials
Run an asyncio brute-force engine against Easy4IP
03
IAInitial access
Bypass authentication with CVE-2021-33044 and CVE-2021-33045
04
PSPersistence
Install the p2pwn / p2password backdoor account
05
IAInitial access
Reach NAT-protected cameras through the P2P relay by serial number
06
CRCredentials
Generate offline recovery codes for administrative reset
07
EXExfiltration
Send credentials and snapshots to Telegram; export SMART PSS XML
08
LMLateral move
Dump ONVIF credentials cached for NVRs

Attack methodology and infection process

  1. Scanning. masscan swept Russian address space and then the full IPv4 range on port 37777, skipping blocks outside local business hours.
  2. Brute force. The Easy4IP engine scaled from 300 to 4,000 workers, abandoned hosts after five failures to preserve them for a later CVE pass, captured filtered snapshots and exported results for SMART PSS (13,229 records, 52 XML files).
  3. Bypass chain. p2pwn exploits NetKeyboard trust (CVE-2021-33044) and a loopback source-address spoof (CVE-2021-33045), then installs the backdoor account over RPC; it survives password changes and, on most firmware, a factory reset.
  4. P2P relay. Fixed SDK credentials in every Dahua client authenticate to the relay, and a serial number is enough to reach management ports; control still needs credentials or a bypass.
  5. Transferable access. Offline recovery-code generation and SMART PSS exports led Hunt.io to assess, with moderate confidence, that the toolkit was built to hand access to a third party.
  6. Separate capability. A UPX-packed Windows binary (SalatStealer-tagged) and a Defender exclusion script on the same host should be treated as a distinct incident.

MITRE ATT&CK mapping

TacticIDTechniqueObserved use
ReconnaissanceT1595.001Active Scanning: IP Block Scanningmasscan of TCP/37777
ReconnaissanceT1596.005Search Open Technical Databases: Scan DatabasesShodan queries and DDNS enumeration
Initial AccessT1190Exploit Public-Facing ApplicationCVE-2021-33044, CVE-2021-33045 and relay abuse
Credential AccessT1110.003Password SprayingAsyncio engine against port 37777
PersistenceT1136.001Create Account: Local Accountp2pwn account on 1,923 cameras
CollectionT1113Screen CaptureSnapshot capture with quality filtering
ExfiltrationT1567.004Exfiltration Over WebhookTelegram Bot API notifications
Lateral MovementT1210Exploitation of Remote ServicesRelay tunnel access; ONVIF credential dumping

Technique mappings are based on reported behavior; they are not a claim that every affiliate or victim exhibited every technique.

Indicators of compromise and high-signal artifacts

TypeIndicatorWhy it matters
IP154.86.119[.]60Operator server with exposed directory
IP185.132.53[.]56Second sighting of the staged Windows payload
Accountp2pwn / p2passwordBackdoor account on compromised cameras
Port37777/TCPDahua Easy4IP management protocol
SHA-256694bfbe44bcd9b4844e15294be74dafe86ff8ae40b8b1067f4dae70a6ef75da8p2pwn compiled Go ELF
SHA-256de03a0ae5c7aa0c237ae36a649875f986fd9701ac06857dd214054367ce5090c1.exe / xeno.exe (SalatStealer-tagged, separate incident)
RequestclientType "NetKeyboard"; loginType "Loopback" with ipAddr 127.0.0.1Does not occur in legitimate Dahua client traffic
Noteeasy4ipcloud[.]com relay addressesLegitimate Dahua infrastructure; do not block

Note: Defang network indicators before operational use. Validate age, ownership and local context; do not block shared infrastructure solely by hostname.

Campaign-specific detection and mitigation

  • Treat any Dahua camera reachable on port 37777 between June and July 2026 as potentially compromised; search for and remove the p2pwn account.
  • Update firmware (Dahua SA-2021-0130 fixes the bypasses), which also stops new recovery codes from working; removing the account alone is not enough.
  • Disable P2P unless required and keep port 37777 off the internet.
  • Rotate all credentials stored on affected devices and NVRs, including ONVIF accounts.
  • Do not block Dahua relay addresses wholesale; detect on login patterns instead.

Consolidated defense

Mitigations across all campaigns

These controls are ordered around the recurring attack surfaces visible across the campaigns: patch gaps and half-measures, trusted sessions and credentials, remote-management and development platforms, incomplete telemetry, and weak recovery assurance.

01

Close patch gaps, not just exposure

  • Treat browser and edge-device updates as hours-level work when exploitation is reported; Chrome, Edge and WordPress core need automatic updates.
  • Do not accept WAF rules as a substitute for patches; enforce blocking on normalized paths and verify the fix.
  • Retire unsupported Windows builds and end-of-life routers, cameras and appliances.
02

Protect identities and sessions

  • Terminate sessions after patching gateway flaws such as CitrixBleed 2, and correlate VPN logins with identity-provider records.
  • Review VPN accounts that appear in leaks; alert on logins from hosting, WARP or commercial-VPN ranges.
  • Remove default credentials from embedded services and cameras; rotate secrets reachable from any compromised web tier.
03

Govern remote management and development platforms

  • Keep an approved RMM list and alert on additional tools; restrict Gitea registration and exposure; place Windchill, PeopleSoft and similar systems behind authenticated access.
  • Monitor application servers for shell children, new JSP or PHP files and web-root changes.
  • Audit browser extensions and treat extension installs outside the store as incidents.
04

Detect defense impairment and stealth

  • Alert on AMSI or ETW tampering, EDR loss, log clearing, LD_PRELOAD changes and unexpected setuid binaries.
  • Forward appliance, firewall, VPN, application and camera logs off the device to immutable storage.
  • Inspect appliances and Linux hosts from outside the running system when rootkits are suspected.
05

Prepare for destructive impact and extortion

  • Keep offline, immutable, tested backups, and segment hypervisors, NAS, backup and management planes from user networks.
  • Rebuild appliances and rootkit-affected hosts instead of cleaning them, then rotate every credential they touched.
  • Plan for data-theft extortion without encryption, including intellectual-property exposure assessment.

Featured Posts

Open Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products
vulnerability researchCritical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

CVE Research

Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.

Oct 8, 2026

Open Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality
vulnerability researchCritical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

CVE Research

Critical SonicWall SMA 1000 Flaw Lets Unauthenticated Attackers Reach Internal Functionality

SonicWall has disclosed CVE-2026-102255, a critical pre-authentication SSRF vulnerability in SMA 1000 Work Place that can let unauthenticated attackers reach internal functionality and perform unauthorized operations. The advisory also covers three additional SMA 1000 issues. Fixed platform-hotfixes are available; SonicWall reports no evidence of in-the-wild exploitation at publication.

Oct 8, 2026

Open New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service
vulnerability researchNew NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

CVE Research

New NetScaler SAML Zero-Day Exploited in Targeted Attacks, Causes Denial of Service

Citrix has disclosed CVE-2026-88779, a high-severity memory overflow in NetScaler ADC and NetScaler Gateway that can cause denial of service when the appliance is configured as a SAML service provider or identity provider. Targeted attacks on unmitigated deployments have been observed. This article covers impact, affected versions, configuration checks, temporary Global Deny List guidance, and fixed builds.

Oct 8, 2026

Open Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

CVE Research

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

Oct 5, 2026