Skip to content

threat.wiki

Threat intelligence notes, group profiles, named-person records, and defensive guidance.

Recent entries

  • Mirage Kitten pivots to Node.js/JavaScript: NodeRabbit + PollCat delivered via trojanized "coding challenge" archives on S3, targeting aviation and FinTech in the Middle East and Africa (Kaspersky, Sep 1, 2026) — Kaspersky GReAT discloses NodeRabbit (Node.js) and PollCat (JavaScript), the group's first publicly documented Node.js/JavaScript implants (a departure from its native DLL-search-order-hijacking malware). Cross-platform (Windows/Linux/macOS, NodeRabbit also WSL), delivered through recruiter-themed "technical assessment" ZIPs on Amazon S3 (oracle-challenge.s3[.]us-east-1.amazonaws[.]com), with a six-digit recruiter-supplied OTP and one-hour window to force execution. NodeRabbit's v3 persists via a fake "GitHub Copilot Helper" VS Code extension and # shepherd-persist lines in .git/hooks/post-merge/post-checkout; PollCat registers via POST /beacon and treats an HTTP 400 (carrying a socketId) as success — the same handshake as the group's Retrograde/MiniFast. C2 on Azure Websites + Cloudflare domains (including subdomains that embed the target org's name). Confirmed victims: fintech and aviation/aerospace in Egypt, Ethiopia, and Afghanistan.
  • Toy Ghouls' first custom backdoor: "Angry Birds" over HiveMQ MQTT and Element/Matrix C2, WinRM delivery, machine-bound ChaCha20 config (Kaspersky, Sep 4, 2026) — Kaspersky GERT/Security Services reports that in early July 2026 Toy Ghouls (aka Bearlyfy, Laboo.boo, Feral Wolf) deployed a bespoke two-variant backdoor for the first time, delivered over WinRM (Evil-WinRM / WinRM-fs). mqtt-bird-agent runs C2 through the public HiveMQ broker (broker.hivemq.com:8883, per-cluster /status//metrics3//cmd/req//cmd/res paths, commands via hidden powershell.exe); matrix-bird-agent runs C2 through an attacker-hosted Element/Matrix server on meet.element[.]tw with a dedicated room and a panel-bot operator account. Both persist as Windows services (cplsupport "Problem Reports Control Panel", wtas "Windows Telemetry Aggregator Service") and machine-bind their config.toml with a ChaCha20-Poly1305 key derived from HKLM\Software\Microsoft\Cryptography\MachineGuid — the Element variant deletes the file after first run and moves config to the registry. Signals a shift from public GitHub tooling and leaked Babuk/LockBit builders toward custom, hard-to-detect control tooling.
  • StyleSmuggler (CVE-2026-75650): Magento / Adobe Commerce unauthenticated RCE zero-day under active attack — Adobe emergency hotfix VULN-39341 / APSB26-146 (Sansec, Sep 5; Adobe, Sep 7) — Sansec's Sep 5 disclosure (updated Sep 7) documents an unauthenticated RCE 0-day affecting all in-range versions of Magento Open Source and Adobe Commerce: Adobe's Sep 7 emergency advisory APSB26-146 (priority 1) assigns CVE-2026-75650, CVSS 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), covering 2.4.4–2.4.9 (Adobe Commerce + Magento Open Source) and B2B 1.3.3–1.5.3 (2.4.7/2.4.8/2.4.9 confirmed on clean installs; one victim on 2.4.6-p15 with July + August 2026 patches and a clean security:patch-status was still compromised). Attacks began Sep 4, 22:40 UTC, three days before the hotfix existed. The fix ships as emergency composer hotfix VULN-39341 (from repo.magento.com; verify with vendor/bin/magento-patches -n status | grep "39341\|Status") — not a full release, and patching does not remove a live backdoor: Adobe requires rotating the encryption key plus every credential it protected (admin passwords, REST/SOAP/GraphQL tokens, OAuth client secrets, payment gateway keys, DB credentials, SSH/deploy keys, extension API keys), at the source. Two-stage chain: (1) inject — an unauthenticated GraphQL request whose styles property carries PHP payload written into a Magento-generated file; (2) execute — the poisoned file runs server-side during rendering of a "Payment Transaction Failed Reminder" email. Confirmed intrusions install a persistent Rust backdoor disguised as a kernel thread (rotating process names [kworker/u:8:0]fc-cachechronyd), writing cron entries directly into the spool, beaconing over NTP-shaped UDP/123 to ntp.timesync.to / ntp.timesysnc.net185.157.160.251. A second, distinct actor is dropping a 485-byte PHP web shell into the product-image cache (pub/media/catalog/product/cache/ss_<10hex>/sync_<10hex>.php, X-Cache-Token-gated). Until patched: disable GraphQL (takes headless/PWA storefronts offline) or apply Aikido's drop-in patch; the free detection tell is crontab[pid]: (www-data) AUTH (crontab command not allowed) in auth logs plus find pub/media -name '*.php'. E-commerce RCE of this shape is a Magecart / skimmer + PII / payment-data vector.
  • Shai-Hulud payload back after 111 days: hash-identical May-19 AntV worm republished on scan-gated npm — the registry-scan "easy case" missed (Aikido, Sep 7) — Aikido's Sep 7 post documents four packages (feishu-docx-mcp@0.3.2, bmc-i18n-extract-cli@1.1.1, blueai-cli@0.7.0, bmc-translate-utils@1.1.1) published within the same hour by one npm account carrying a root-level index.js byte-identical to the May 19 @antv wave (SHA-256 e37e3dde…b1a6, preinstallbun run index.js, .vscode/tasks.json / .claude/settings.json persistence, C2 t[.]m-kosche[.]com, Dune-themed dead-drop repos). Aikido's detection history: 319 package versions with that hash, all first seen May 19, zero hits May 20 → Sep 6, then these four on Sep 7 — a 111-day dormancy-to-reactivation gap it calls the longest it has seen from a Shai-Hulud payload. The durable lesson is about registry-level scanning, not the worm: npm has run publish-time malware scanning (5–15 min pre-publish hold) since July 2026, and a hash-identical reactivation of a publicly fingerprinted, internationally covered payload is a lookup the scanner should have caught as the floor of its claimed coverage. Attribution kept caveated (no self-identifying campaign marker recovered; public tooling + copycat reuse plausible). Triage: hunt the SHA-256, the four package names, and Dune-themed repos.
  • Langflow CVE exploitation canary timeline: two attackers, two playbooks on the same AI-stack target (VulnCheck, Aug 2026) — VulnCheck's Aug 28 post (companion to its 1H-2026 State of Exploitation report) publishes canary telemetry on Langflow: 12 Langflow CVEs now with in-the-wild exploitation evidence (11 added during 2026) and 15,000+ successful canary attempts across CVE-2026-0769 / CVE-2025-3248 / CVE-2026-5027, with hundreds of Langflow hosts still active and vulnerable on the public internet (highest concentration: US). Two financially motivated attackers ran independent playbooks on the same target in the same window: Attacker 1 (May 12–Jun 8) entered via CVE-2026-5027, deployed a Python credential harvester + SimpleHelp RAT, exfiltrated to 23.234.98[.]182:9999, and established IRC C2 to 185.117.74[.]172:6667 with cron persistence 0 * * * * /usr/bin/3WA72N.sh; Attacker 2 (Apr 22–Jun 25) entered via CVE-2025-3248, then Chisel SOCKS5 → pearl-miner XMR mining → auditd disabled (forensic blind spot from Jun 10) → CVE-2026-0769 dropping .sysd/.cache-sysd/.watchdog.sh → PocSuite3 → SSH pivot to 216.78.235[.]34 for target expansion. Durable read: same target, divergent entry CVE, objective, C2, and kit — the tell is per-operator post-exploitation behavior, not "Langflow was hit."
  • Sality P2P botnet disrupted: CrowdStrike P2P sinkholing operation with DOJ/FBI ends a 23-year file-infecting botnet (Aug 31, 2026) — CrowdStrike Counter Adversary Operations, with the DOJ, FBI, DoD OIG DCIS, and Shadowserver (support: Europol, Eurojust, and LE in Bulgaria/Hungary/Romania), executed an Aug 31, 2026 P2P sinkholing disruption of the Sality botnet — a polymorphic file-infecting criminal infrastructure operating since 2003 across 33,000+ machines. Sality's durability came from two properties the sinkhole turned against it: no peer authentication (any host answering the P2P handshake was accepted — so a defender could join as an indistinguishable peer) and a file-infecting protocol that cannot be code-updated (every protocol weakness has been permanent for 20 years). The operation poisoned each bot's super-peer list during its ~40-minute peer-verification cycle, purging real super peers and injecting CrowdStrike-operated sinkholes; law enforcement simultaneously took down the URL-pack payload-hosting URLs, so infected hosts can no longer receive URL packs or file packs. Two independent P2P networks (v3/v4, same codebase/operator, incompatible protocols + different RSA keys) are now isolated and beaconing to sinkholes. The operator (a single financially motivated criminal, no state attribution) had used Sality's ~8-year-primary payload EggJagger (crypto-wallet clipjacking: clipboard monitoring, BTC/ETH address swap) to steal ≥₽12.1M (~$150K; portfolio peaked ~₽147M in Jan 2025) plus ran on-demand DDoS (Arabic financial forum 2016; Ukrainian forum Feb 25 2022, day after Russia's invasion; Russian crypto exchange Sept 2023). Durable defender core: the disruption does not remove installed malware — hunt the lighthouse UDP beacon to 188.166.101[.]148, the v3/v4 URL-pack URLs (theunforgiven.p8[.]hu, painelwebradiodigital.awardspace[.]info, sgwebdesigner.free[.]fr, yonelco[.]com, pozdravizbeograda[.]com, highclass.atspace[.]com, situluimihai.3x[.]ro, v4 gatheredovertime[.]com/nb4), and CrowdStrike's two YARA rules on the embedded RSA public keys; file-infecter hygiene (shared folders, removable media, self-modifying executables) is the standing prevention (CrowdStrike, Sep 1).
  • Rogue ScreenConnect installations across unrelated hosts: worm-like VBS propagation via guest file transfer (Huntress, Sep 3) — Huntress' Sep 3 report on three separate-organization incidents (Aug 20/20/24) where tech-support-scam social engineering lands a rogue ScreenConnect client that spawns wscript.exe and a four-stage VBS loader chain (1.vbs4.vbs from a RAR on C2): host profiling + EDR enumeration → Base64/XOR-0x90 catalogue (map.txt) → encrypted out.enc fetch → AES-CBC decrypt to sys_cache.zip + elevated PyTorchFix.ps1 (inline-C# Password.exe, ms-settings:/ComputerDefaults.exe UAC bypass, amsiInitFailed AMSI bypass, C:\Users-wide Defender exclusion, concealed ScreenConnect client with removed Registry Uninstall entry, WindowsServiceHost Run-Key persistence, combo.zip miner + WinRing0 svcdrv64.sys, plus UltraViewer on some hosts). The differentiator is worm-like propagation: when the host profile state is 010/011, the fourth stage mirrors all four VBS files into C:\Users\Public\Libraries\Default\Lib\Lib1, making each infected host a content-delivery node for newly connected ScreenConnect endpoints. Same-day ConnectWise advisory: guest file-transfer capability affects Cloud + On-Premise, CVE/fix "within the week", interim mitigation = disable TransferFiles/TransferFilesInSession role permissions; the RunFiles/RanFiles Process: Guest audit-log entry is the durable tell.
  • Impersonating IT support: human-operated Teams external-collaboration intrusion that hands off to a portable Node.js JavaScript implant and WinRM pivoting to DCs/CA (Microsoft, Sep 2) — Microsoft Security Research documents a full HOBK enterprise intrusion that abuses Teams external collaboration to impersonate IT/helpdesk (vishing layered so malicious instructions never land in chat logs), socially engineers a victim into an interactive remote session (Quick Assist / RMM), then uses in-session PowerShell to download and silently install a benign-named MSI ("devfix"/"Hotfix") from attacker cloud storage. The MSI stages a portable Node.js runtime + encrypted JavaScript implant under LocalAppData (per-user EdgeUpdate Run-key/Startup persistence; loaders use .tmp/.ini/.dat/.bin/.cfg extensions, sometimes a renamed node.exe), which randomized-HTTPS long-polls C2 and executes C2-delivered JavaScript: host/AD recon, display-adapter + AV sandbox checks, periodic Base64 desktop screenshots, rundll32 follow-on DLLs, ADSI domain enumeration, and WinRM 5985 lateral movement toward domain controllers and CAs. Recovered builds also carry dormant Ethereum smart-contract C2 URL discovery (disabled; contract stores only a URL string). Durable read: a signed, trusted Node.js runtime executing attacker JavaScript plus EdgeUpdate-named per-user persistence is the high-signal tell — this is the same "trusted interpreter as malware-delivery channel" pattern Symantec catalogued on Sep 4.
  • Counterfeit installers to system compromise: the Silver Fox / Yinhu fake-software campaign, per-request payload regeneration, and a TrueUpdate-abusing ~60s scheduled-task persistence loop (Microsoft, Sep 1) — Microsoft Defender Experts (moderate-confidence Silver Fox / Yinhu assessment, commodity/non-nation-state) tracks a campaign where high-fidelity vendor-clone .com.cn/.hl.cn download pages (Razer pc-razerzone[.]com[.]cn, Microsoft Edge, Kaspersky, Sejda, NetEase Youdao, DiskGenius, Baidu Pan, oCam, draw.io, SteelSeries, Sogou, Calibre, MindMaster-typosquat + others) all funnel to a small set of dedicated delivery hosts (gehie246[.]com/712down, yimxg25tiy[.]com/73inst, cc8ttkv35b[.]com/7qinst, n7b8t85zsg[.]com/ins711) and an attacker Alibaba Cloud OSS bucket. The defining behavior: the installer archive keeps the same filename but its hash changes on every download — server-side, per-request payload regeneration (two content-distinct copies of app_setup.6653004.zip written ~69s apart). Wrapper → randomized stage-one (stable SHA-256 676a2a7b… under many names) → later-stage 6d6ba2bc… (forged "Philips Speech Driver" version resource with a TODO: <Product name> placeholder — confirmed fabrication) → TrueUpdate-abusing persistent stage c6100166… in C:\ProgramData\<random>\, re-launched every ~60s by the Task Scheduler (svchost -k netsvcs -s Schedule), connecting to the Alibaba OSS bucket over TLS to fetch further payloads; it writes sweeping Defender exclusions, runs vssadmin delete shadows, and disables Windows Update (wuauserv/UsoSvc/uhssvc/WaaSMedicSvc) — the classic pre-ransomware posture. C2 on 9 IPs × 9 ports + six-character .net domains; delivery domains in shared ASN AS132839 / AS8796 pairs (treat as hunting pivots, not blocklists). Primarily China-based multinational operations and Chinese-speaking users across healthcare, manufacturing, gaming, tech, logistics, government, and education. Durable read: same-filename/changing-hash + archiver-parented randomized drop + Defender-exclusion/shadow/WinUpdate triad = the Silver Fox / Yinhu shape; correlate with Qianxin's Operation Phnom Penh MODBEACON distributor.
  • SiYuan kernel publish-mode security batch: 3 critical 10.0 unauthenticated SQL-execution flaws in publish mode + 9 high / 8 medium access-control bypasses across 20 GHSAs — A coordinated 20-advisory GHSA batch (Sep 3) against the self-hosted SiYuan knowledge-base kernel: the 3 critical (10.0) unauthenticated SQL-execution flaws (CVE-2026-69083 via fullTextSearchAssetContent, CVE-2026-69084 via searchEmbedBlock, CVE-2026-72811 backlink/mention search) each pass a client-supplied full SQL statement verbatim to a read-write siyuan.db handle through a statement-stacking-capable driver — so an anonymous attacker (when Publish.Auth.Enable is off) can read and write across all cleartext notebooks; the 9 high include CVE-2026-72809 (localhost-trust admin bypass via the fixed-port proxy, remotely reachable if bound to a network interface), CVE-2026-72807 (second-order SSTI→SQL via an imported malicious AV package), and CVE-2026-72801 (encrypted-notebook key-derivation material + wrapped keys disclosed to anonymous readers), with 8 medium access-control bypasses rounding out the batch; fixed in v3.8.3-alpha.1 (hardening commits 2026-07-21→07-23) — inventory self-hosted SiYuan instances, don't expose the kernel to the open internet, set Publish.Auth.Enable to true and enforce the publish-password tier, and treat any imported AV package as potentially hostile (GitHub GHSAs, Sep 3)

Sections

  • Ops — campaign timelines, compromise chains, and sequencing
  • Tools — malware, payloads, implants, and attacker infrastructure
  • Groups — crews, cluster names, and shared operational personas
  • People — publicly identified individuals or project personas when public sourcing supports it
  • Patterns — reusable defender heuristics
  • Notes — taxonomy, usage, and editorial guidance