Skip to content

threat.wiki

Threat intelligence notes, group profiles, named-person records, and defensive guidance.

Recent entries

  • AWS root user password-spraying campaign across 150+ organizations: two fixed user agents, residential-proxy tunneling, no confirmed success (Datadog Security Labs, Aug 31, 2026) — Datadog Security Research reports a password-spraying campaign against the AWS account root user that ran July 24 – August 23, 2026: repeated failed ConsoleLogin attempts against the root user account at 150+ organizations (median 2, up to 8 attempts each), fingerprinted by two user agents (an Edge/Chrome 85 signature and a Firefox 120 signature) with proxy-tunneled source traffic (all flagged hosting/residential-proxy infrastructure). No actor named, no victimology pattern, and no successful authentication observed — intent undetermined. The tradecraft tell: a failed ConsoleLogin requires the root-account email address, so the operator either already held root emails for 150+ orgs or brute-forced valid ones — pre-staged targeting data, not random noise. Durable read: MFA alone is not the control — enforce AWS Organizations SCPs that block direct root activity in member accounts, use centralized short-lived AssumeRoot sessions (which do not cover the management account), and alert on all root ConsoleLogin activity; Datadog publishes the exact CloudTrail query to check whether you were hit.
  • DeepSeek Harness CVE-2026-82533: a sandboxed AI agent disables its own sandbox with one shell command (OX Security, Sep 8, 2026) — OX Research disclosed CVE-2026-82533 (CWE-807, CVSS 9.4) in DeepSeek Harness (dsh), DeepSeek's open-source AI coding-agent harness (>215,000 GitHub stars within weeks). On shipped defaults, with no network exposure and no credentials, a sandboxed agent could disable its own confinement with a single shell command: the harness's local control API on 127.0.0.1:3080 authenticated a request by its client-supplied Host header (isTrustedApiRequest → loopback authority or trustedHosts) without ever checking the connection's actual peer address, while the OS sandbox (bubblewrap/Seatbelt/Landlock) restricted file writes but left loopback networking open and ordinary bash calls needed no approval. The agent's one curl to the control plane lifted its session to danger-full-access with approval never — no approval/request event, and the policy change logged source: {kind: 'user'} (the harness couldn't tell the agent's shell from the human). A matched control proved the sandbox was actively enforcing before the escape. Second path: wherever the port was reachable (tunnel / reverse proxy / SSH forward / editor port-forward), an unauthenticated remote attacker could take full control of the agent and export every stored conversation with no key. Fixed in 0.1.2-alpha.1 (disclosed to VulnCheck Aug 24; published Sep 8). Durable read: a localhost API is a network boundary, not a trust assumption — a coding-agent harness that holds a shell is a host-execution primitive, so authenticate the control plane on the real peer, network-isolate the agent sandbox, and never gate escalation on a header a non-browser client can forge.
  • XCSSET hides inside a pub.dev Flutter package: universal_file_viewer 0.1.5 on the official Dart/Flutter registry (Aikido, Sep 8, 2026) — Aikido reports XCSSET, the macOS build-hook worm, found inside universal_file_viewer@0.1.5 on pub.dev — the first compromised package Aikido has detected on the official Dart/Flutter registry. Not a targeted attack: the worm on the maintainer's infected machine spams malicious build hooks into every local Gradle/Xcode/Git project it finds, and the infected files shipped when the maintainer published from that host. The lib/ Dart code is clean; all three infected files are in the example/ directory, which ships in the tarball but is never compiled when used as a dependency — risk is to anyone who clones the repo and builds the example/ app locally. Three build hooks, each injected by a different worm module: an Android Gradle preBuild hook (reconstructed xxd via printf xAxd | tr -d A, C2 5yotmxcc54l9xda[.]ru, tag p=android_kotlin), and iOS + macOS PBXBuildRules fired on any .md file (obfuscated A3EA261 build setting, C2 qdgs232i-q[.]ru / ejntin6hkjt7gj2[.]ru, tag p=xcode_rule). threat.wiki verified the subsequent tarballs: 0.1.6 still carries the iOS + macOS Xcode hooks (Android hook removed) and 0.1.7 appears clean — treat 0.1.5/0.1.6 as poisoned, re-verify 0.1.7 before re-adopting. Durable read: XCSSET propagation is endpoint-driven, not registry-driven, and it has now reached a brand-new package ecosystem.
  • CISA KEV September 8, 2026: four exploited flaws — Adobe/Magento StyleSmuggler unauth RCE (CVE-2026-75650, 10.0, due 2026-09-11), N-able N-central pre-auth RCE zero-day (CVE-2026-86218, 10.0, Hotfix 4, due 2026-09-11), and two Windows local LPEs — Update-Stack link following (CVE-2026-81963) and ALPC heap overflow (CVE-2026-85880), both 7.8, due 2026-09-22; all BOD 26-04, Forensics Triage on the two pre-auth RCEs, ransomware use unknown, no actor named
  • N-able N-central: net-new exploit chain, Hotfix 3 + Hotfix 4, and a CVSS 10.0 pre-auth RCE zero-day under active exploitation — CVE-2026-86206 / -86207 / -86218 (Huntress / N-able, Sep 5–6, 2026) — On Sep 4, 2026 a fully-patched customer's production N-central was compromised; Huntress reproduced a net-new exploit chain against build 2026.3.1.10, distinct from the August CVE-2026-18556/-18577 flaws. N-able shipped Hotfix 3 (build 2026.3.1.13, Sep 5) fixing two auth-bypass flaws (CVE-2026-86206 / CVE-2026-86207 — unauthorized admin account creation), then Hotfix 4 (build 2026.3.1.14, Sep 6) fixing CVE-2026-86218, a CVSS 10.0 pre-authentication RCE zero-day exploited in the wild. On-prem N-central must move to 2026.3.1.14 (hotfix chain; no full 2026.3.1 release yet); hosted NCOD already patched. New tradecraft: account-name anomalies (.invalid suffixes, character swaps), /remoteControlAction.do?method=getPierDetails recon probes, and URL-encoded internal-API-route requests (%2F) in envoy_proxy_HTTPS.log / syslog ncentraldms; Huntress initiated a Cloudflare tunnel takedown.
  • 13 malicious Packagist Composer themes deliver iOS spyware + crypto-wallet seed theft on Vietnamese movie/comic CMS sites (Socket / FUNNULL, Aug 31, 2026) — Socket confirmed 13 malicious Composer themes across five Packagist vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) on OphimCMS/KKPhim streaming CMSes that inject platform- and referrer-gated JavaScript into every visitor: a mobile gambling/ad-fraud redirect plus, on iPhones, a WebKit-to-kernel exploit chain (renderer CVE-2025-31277/CVE-2025-43529 → GPU-process pivot → an AppleM2ScalerCSCDriver kernel escape) that installs spyware exfiltrating keychain, Wi-Fi, SMS, contacts, and cookies to a rotating C2 pool. The Aug 12 redeployment added a keychain crypto-wallet seed/mnemonic stealer (Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, OKX). All stages are n-days (kernel escape fixed in iOS/macOS 26.1; the WebKit entry points are on CISA KEV); operators target unpatched iOS ≤ 18.6.x and redeploy under fresh filenames.
  • Mirage Kitten pivots to Node.js/JavaScript: NodeRabbit + PollCat delivered via trojanized "coding challenge" archives on S3, targeting aviation and FinTech in the Middle East and Africa (Kaspersky, Sep 1, 2026) — Kaspersky GReAT discloses NodeRabbit (Node.js) and PollCat (JavaScript), the group's first publicly documented Node.js/JavaScript implants (a departure from its native DLL-search-order-hijacking malware). Cross-platform (Windows/Linux/macOS, NodeRabbit also WSL), delivered through recruiter-themed "technical assessment" ZIPs on Amazon S3 (oracle-challenge.s3[.]us-east-1.amazonaws[.]com), with a six-digit recruiter-supplied OTP and one-hour window to force execution. NodeRabbit's v3 persists via a fake "GitHub Copilot Helper" VS Code extension and # shepherd-persist lines in .git/hooks/post-merge/post-checkout; PollCat registers via POST /beacon and treats an HTTP 400 (carrying a socketId) as success — the same handshake as the group's Retrograde/MiniFast. C2 on Azure Websites + Cloudflare domains (including subdomains that embed the target org's name). Confirmed victims: fintech and aviation/aerospace in Egypt, Ethiopia, and Afghanistan.
  • Toy Ghouls' first custom backdoor: "Angry Birds" over HiveMQ MQTT and Element/Matrix C2, WinRM delivery, machine-bound ChaCha20 config (Kaspersky, Sep 4, 2026) — Kaspersky GERT/Security Services reports that in early July 2026 Toy Ghouls (aka Bearlyfy, Laboo.boo, Feral Wolf) deployed a bespoke two-variant backdoor for the first time, delivered over WinRM (Evil-WinRM / WinRM-fs). mqtt-bird-agent runs C2 through the public HiveMQ broker (broker.hivemq.com:8883, per-cluster /status//metrics3//cmd/req//cmd/res paths, commands via hidden powershell.exe); matrix-bird-agent runs C2 through an attacker-hosted Element/Matrix server on meet.element[.]tw with a dedicated room and a panel-bot operator account. Both persist as Windows services (cplsupport "Problem Reports Control Panel", wtas "Windows Telemetry Aggregator Service") and machine-bind their config.toml with a ChaCha20-Poly1305 key derived from HKLM\Software\Microsoft\Cryptography\MachineGuid — the Element variant deletes the file after first run and moves config to the registry. Signals a shift from public GitHub tooling and leaked Babuk/LockBit builders toward custom, hard-to-detect control tooling.
  • StyleSmuggler (CVE-2026-75650): Magento / Adobe Commerce unauthenticated RCE zero-day under active attack — Adobe emergency hotfix VULN-39341 / APSB26-146 (Sansec, Sep 5; Adobe, Sep 7) — Sansec's Sep 5 disclosure (updated Sep 7) documents an unauthenticated RCE 0-day affecting all in-range versions of Magento Open Source and Adobe Commerce: Adobe's Sep 7 emergency advisory APSB26-146 (priority 1) assigns CVE-2026-75650, CVSS 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), covering 2.4.4–2.4.9 (Adobe Commerce + Magento Open Source) and B2B 1.3.3–1.5.3 (2.4.7/2.4.8/2.4.9 confirmed on clean installs; one victim on 2.4.6-p15 with July + August 2026 patches and a clean security:patch-status was still compromised). Attacks began Sep 4, 22:40 UTC, three days before the hotfix existed. The fix ships as emergency composer hotfix VULN-39341 (from repo.magento.com; verify with vendor/bin/magento-patches -n status | grep "39341\|Status") — not a full release, and patching does not remove a live backdoor: Adobe requires rotating the encryption key plus every credential it protected (admin passwords, REST/SOAP/GraphQL tokens, OAuth client secrets, payment gateway keys, DB credentials, SSH/deploy keys, extension API keys), at the source. Two-stage chain: (1) inject — an unauthenticated GraphQL request whose styles property carries PHP payload written into a Magento-generated file; (2) execute — the poisoned file runs server-side during rendering of a "Payment Transaction Failed Reminder" email. Confirmed intrusions install a persistent Rust backdoor disguised as a kernel thread (rotating process names [kworker/u:8:0]fc-cachechronyd), writing cron entries directly into the spool, beaconing over NTP-shaped UDP/123 to ntp.timesync.to / ntp.timesysnc.net185.157.160.251. A second, distinct actor is dropping a 485-byte PHP web shell into the product-image cache (pub/media/catalog/product/cache/ss_<10hex>/sync_<10hex>.php, X-Cache-Token-gated). Until patched: disable GraphQL (takes headless/PWA storefronts offline) or apply Aikido's drop-in patch; the free detection tell is crontab[pid]: (www-data) AUTH (crontab command not allowed) in auth logs plus find pub/media -name '*.php'. E-commerce RCE of this shape is a Magecart / skimmer + PII / payment-data vector.
  • Shai-Hulud payload back after 111 days: hash-identical May-19 AntV worm republished on scan-gated npm — the registry-scan "easy case" missed (Aikido, Sep 7) — Aikido's Sep 7 post documents four packages (feishu-docx-mcp@0.3.2, bmc-i18n-extract-cli@1.1.1, blueai-cli@0.7.0, bmc-translate-utils@1.1.1) published within the same hour by one npm account carrying a root-level index.js byte-identical to the May 19 @antv wave (SHA-256 e37e3dde…b1a6, preinstallbun run index.js, .vscode/tasks.json / .claude/settings.json persistence, C2 t[.]m-kosche[.]com, Dune-themed dead-drop repos). Aikido's detection history: 319 package versions with that hash, all first seen May 19, zero hits May 20 → Sep 6, then these four on Sep 7 — a 111-day dormancy-to-reactivation gap it calls the longest it has seen from a Shai-Hulud payload. The durable lesson is about registry-level scanning, not the worm: npm has run publish-time malware scanning (5–15 min pre-publish hold) since July 2026, and a hash-identical reactivation of a publicly fingerprinted, internationally covered payload is a lookup the scanner should have caught as the floor of its claimed coverage. Attribution kept caveated (no self-identifying campaign marker recovered; public tooling + copycat reuse plausible). Triage: hunt the SHA-256, the four package names, and Dune-themed repos.

Sections

  • Ops — campaign timelines, compromise chains, and sequencing
  • Tools — malware, payloads, implants, and attacker infrastructure
  • Groups — crews, cluster names, and shared operational personas
  • People — publicly identified individuals or project personas when public sourcing supports it
  • Patterns — reusable defender heuristics
  • Notes — taxonomy, usage, and editorial guidance