Last Updated On

CCTTII--22002266--00992233
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

Edge Zero Days Active Exploitation Surge And Massive Identity Infrastructure Takeover

Critical edge network infrastructure is weathering an unprecedented wave of concurrent zero day attacks targeting Cisco, F5, Arista, and Check Point appliances.

Concurrently, Microsoft disrupted the massive EvilTokens platform after automated device code phishing compromised more than twelve thousand corporate inboxes across global enterprises.

Security operations must immediately deploy out of band appliance hotfixes, restrict OAuth device login flows, and hunt for active post exploitation implants.

10

CVSS Score

68

IOC Count

32

Source Count

87

Confidence Score

CVEs

CVE-2026-20079, CVE-2026-20316, CVE-2026-94127, CVE-2026-93952, CVE-2026-93616, CVE-2026-91843, CVE-2026-85102, CVE-2026-76460, CVE-2026-7273, CVE-2026-85880, CVE-2026-81963, CVE-2026-85046, CVE-2026-87491, CVE-2026-32996, CVE-2026-63030, CVE-2026-60137, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-60004, CVE-2026-56271, CVE-2026-79756, CVE-2026-54569, CVE-2023-54391, CVE-2022-0847, CVE-2025-39682, CVE-2025-39964, CVE-2026-53266, CVE-2026-84869, CVE-2026-69730, CVE-2026-69676, CVE-2026-69852, CVE-2026-69854, CVE-2026-83501, CVE-2026-70585, CVE-2026-69857, CVE-2026-62916, CVE-2026-83941, CVE-2026-65818, CVE-2026-80098, CVE-2026-70352, CVE-2026-72957, CVE-2026-83548, CVE-2026-83549, CVE-2026-9586, CVE-2026-82329, CVE-2026-48710, CVE-2026-49869, CVE-2026-59822, CVE-2026-19490, CVE-2025-25249, CVE-2026-42016, CVE-2026-42018, CVE-2026-67277, CVE-2026-86060, CVE-2026-87886, CVE-2026-85706, CVE-2026-44756, CVE-2026-58240, CVE-2026-67279, CVE-2026-94545, CVE-2026-87902, CVE-2026-45498

Actors

UAT-11823, Sandworm, UAT-11988, Qilin, UAT-12197, Storm 2992, APT31, UTA0565, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket, Kapibala, ShinyHunters, WaterPlum, Payroll Pirates, Black Axe, Unattributed Threat Actors

Sectors

Government, Defense Industrial Base, Aerospace, Critical Manufacturing, Financial Services, Consulting, Non-Governmental Organizations, Commodity Trading, Telecommunications, Cloud and Artificial Intelligence Infrastructure, Healthcare, Higher Education, Software Engineering, Construction, Wholesale Distribution, Real Estate, Municipal Utilities

Regions

Global, United States, Canada, United Kingdom, European Union, Italy, France, Germany, Netherlands, Ukraine, Singapore, Indonesia, Vietnam, Taiwan, South Korea, India, Australia, Latin America, Morocco

Chapter 01 - Executive Overview

Executive leadership faces an acute convergence of perimeter collapse and identity infrastructure compromise across the enterprise landscape. During the current observation window, multiple critical edge platforms have experienced concurrent zero day exploitation, while industrialized credential operations bypassed conventional multifactor authentication barriers at scale.

Cisco Secure Firewall Management Center: Critical: Enterprise And Government Estates

[+] Threat overview: Unauthenticated remote adversaries actively weaponize a vulnerability pair within Cisco Secure Firewall Management Center web services under CVE-2026-20079 and CVE-2026-20316 to achieve root execution and appliance takeover.

[+] Strategic risk context: Compromise of centralized firewall management engines exposes underlying network topologies, yields access to internal administrative credentials, and enables direct traffic manipulation across managed enforcement points.

[+] Threat actor activity: Three distinct adversary groups are actively exploiting these flaws, including Russian state sponsored military intelligence operators deploying persistent implants, criminal ransomware syndicates staging network wide encryption, and credential theft operators.

[+] Leadership directive: Infrastructure leaders must immediately enforce out of band hotfixes across all exposed firewall management appliances and isolate web interfaces from external routing.

F5 BIG IP Access Policy Manager: Critical: Enterprise And Financial Perimeters

[+] Threat overview: Consulted sources confirm in the wild exploitation of CVE-2026-94127, an unauthenticated heap buffer overflow vulnerability in F5 BIG IP Access Policy Manager instances operating as OAuth Authorization Servers.

[+] Strategic risk context: The vulnerability resides in the data plane processing pipeline, allowing remote attackers to execute arbitrary system code directly on internet facing authentication gateways without user interaction.

[+] Severity and business impact: Exploitation completely compromises corporate identity perimeters, jeopardizes downstream single sign on sessions, and invalidates zero trust network architectures.

[+] Leadership directive: Security leadership must deploy engineering hotfixes immediately or apply vendor supplied traffic filtering rules to block malformed OAuth token requests.

Arista VeloCloud Orchestrator: Critical: Software Defined Networking Estates

[+] Threat overview: Threat actors are actively exploiting an unauthenticated input validation flaw under CVE-2026-93952 in on premises VeloCloud Orchestrator platforms configuring certificate based Edge authentication.

[+] Strategic risk context: Successful exploitation grants access to privileged internal management functions without requiring tenant credentials, creating a systemic supply chain exposure across all connected branch edges.

[+] Patch gap exposure: Vendor fixes remain restricted to specific release branches, leaving several active operational trains completely unpatched and reliant entirely on strict network isolation.

[+] Leadership directive: Network engineering directors must restrict orchestrator administrative interfaces to trusted internal subnets and audit connected branch edge device configurations.

Check Point Security Management Infrastructure: Critical: Enterprise Network Operations

[+] Threat overview: Adversaries conducted approximately two months of undetected access by exploiting preauthentication directory traversal and arbitrary file upload vulnerabilities under CVE-2026-93616 and CVE-2026-91843.

[+] Strategic risk context: The flaw allows unauthenticated attackers to execute scripts as root across security management, multi domain management, and event logging appliances.

[+] Operational blast radius: Centralized policy stores, administrative keys, and audit logging repositories are directly exposed to adversary modification and covert exfiltration.

[+] Leadership directive: Operations teams must deploy the latest vendor jumbo hotfix and inspect management service transaction logs for oversized administrative authentication sequences.

Industrialized Identity Theft Platform Disruption: High: Cloud Enterprise Environments

[+] Threat overview: Major cloud telemetry providers dismantled the core infrastructure supporting EvilTokens, an automated phishing as a service architecture that compromised more than twelve thousand accounts across ten thousand corporate entities.

[+] Strategic risk context: Operating under threat actor Storm 2992, the platform weaponized OAuth device login flows to bypass standard multifactor authentication, harvest application access tokens, and automate enterprise reconnaissance.

[+] Post breach compromise: Infiltrated organizations experienced automated corporate mailbox analysis, unauthorized device registrations for persistent primary refresh tokens, and malicious forwarding rule deployments.

[+] Leadership directive: Identity security teams must immediately restrict OAuth device code authentication flows within conditional access policies to explicitly authorized hardware profiles.

Multi Platform Mass Exploitation And Government Infiltration: High: Public Sector And Networking

[+] Threat overview: A sophisticated adversary tracked as Kapibala compromised nearly one thousand Zyxel network switches globally under CVE-2026-7273 while executing structured intrusions across public sector web properties.

[+] Strategic risk context: Attackers chained web application vulnerabilities to penetrate database backends, exfiltrating tens of thousands of sensitive records including law enforcement identity details and cleartext credentials.

[+] Technical tradecraft: The campaign combined obfuscated exploit binaries, defense evasion bypass scripts, token impersonation primitives, and automated network share credential spraying.

[+] Leadership directive: Security executives must mandate immediate firmware upgrades across peripheral network switching fleets and initiate enterprise credential rotations across impacted public domains.

Chapter 02 - Threat & Exposure Analysis

Adversary operations across this reporting window reflect a pronounced emphasis on perimeter control planes, identity session theft, and autonomous exploitation loops that collapse traditional defense timelines.

Incident Identifier

Vulnerability Or Vector

Threat Actor Or Nexus

Primary Mechanism And Impact

Cisco FMC Intrusion Wave

CVE-2026-20079, CVE-2026-20316

Sandworm, Qilin, UAT-12197

Web application auth bypass enabling root execution, credential theft, and reverse SSH proxying

F5 BIG IP APM Breach

CVE-2026-94127

Under Attribution

Preauthentication heap buffer overflow in OAuth authorization server profile yielding data plane RCE

VeloCloud Orchestrator Flaw

CVE-2026-93952

Under Attribution

Improper input validation in certificate based edge authentication granting privileged internal access

Check Point Management Zero Day

CVE-2026-93616, CVE-2026-91843

Under Attribution

Preauthentication directory traversal and file upload permitting unauthenticated script execution as root

EvilTokens Identity Platform

Device Code Flow Abuse

Storm 2992

Industrialized OAuth device flow phishing bypassing MFA to capture access tokens and automate BEC

Kapibala Edge And Web Campaign

CVE-2026-7273, CVE-2026-63030

Kapibala (Red Heron overlap)

Mass switch exploitation and WordPress compromise leading to privilege escalation and database theft

BlueMoon Espionage Chain

CVE-2026-85046, CVE-2026-87491

APT31, UTA0565, Linked Clusters

Chromium V8 type confusion chained with sandbox escape and Windows ALPC kernel escalation

Microsoft Zero Day Releases

CVE-2026-85880, CVE-2026-81963

Commercial And State Clusters

Windows ALPC heap overflow and Update Stack link resolution exploited for unprivileged SYSTEM escalation

[+] Cisco FMC exploitation dynamics: Attackers leverage CVE-2026-20079, a root cause failure in Tomcat request validation that routes unauthenticated web traffic directly into privileged script processing pipelines. When combined with CVE-2026-20316 low privilege access, actors execute arbitrary commands through package installation scripts that run natively with root authority.

[+] Adversary divergence on Cisco FMC: Consulted sources track three separate operational clusters exploiting the same management interface. UAT-12197 places Java server page web shells titled home.jsp and deploys cmd.jar to query user credential databases via OmniQuery utilities. UAT-11823, exhibiting strong behavioral overlap with Russian GRU Sandworm operators, drops self extracting archives containing Netcat reverse shells and deploys the modular Cyclops Blink ELF implant configured for DNS over HTTPS communication and device configuration exfiltration. UAT-11988, associated with Qilin ransomware affiliates, leverages living off the land scripts to map Active Directory infrastructures, stages SOCKS5 proxies alongside reverse SSH tunnels forwarding LDAP, Kerberos, SMB, and WinRM ports, and terminates antivirus software prior to deploying ransomware.

[+] F5 BIG IP APM execution pathway: Exploitation targets the Traffic Management Microkernel data plane where virtual servers host both an access policy and an OAuth Authorization Server profile. Crafted network traffic induces a heap buffer overflow in token validation parsing, resulting in arbitrary code execution without requiring administrative credentials or control plane access.

[+] VeloCloud Orchestrator control plane exposure: In on premises environments utilizing certificate based authentication between edge hardware and the centralized orchestrator, CVE-2026-93952 allows attackers possessing edge certificate public components to access backend configuration APIs. This enables unauthorized adversaries to alter software defined routing rules and issue arbitrary management commands across downstream network estates.

[+] Check Point long term persistence: Adversaries leveraged CVE-2026-93616 to bypass administrative authentication barriers on management servers, uploading arbitrary web payloads and Java classes. Consulted sources indicate attackers maintained persistent access across targeted organizations for approximately sixty days prior to public disclosure.

[+] EvilTokens attack automation: Operating across distributed cloud computing platforms including Vercel, Cloudflare Workers, and AWS Lambda, Storm 2992 orchestrated automated phishing campaigns simulating corporate applications. Victims entering authentication codes on legitimate vendor login portals unknowingly authorized attacker sessions, granting OAuth access tokens that automated scripts immediately leveraged to conduct corporate directory mapping and deploy email exfiltration rules.

[+] Kapibala campaign forensics: Threat actors tracked as Kapibala executed scanning operations dating back to early 2026 before launching automated exploit packages against nearly one thousand Zyxel network switches using PyArmor obfuscated Python binaries. On parallel vectors, the group breached public sector WordPress deployments via web shell injection, conducted local account creation with backdated timestamps, utilized MSBuild inline tasks to bypass security controls, and dumped local security accounts to facilitate database exfiltration.

[+] BlueMoon browser exploit kit chaining: Espionage actors deployed multi stage exploit chains beginning with spear phishing lures directing victims to actor controlled web pages. The chain triggers a type confusion vulnerability in the Chromium V8 engine under CVE-2026-85046, escapes renderer sandboxes via CVE-2026-87491, and escalates to SYSTEM privileges on Windows endpoints through ALPC kernel pool corruption under CVE-2026-85880, ultimately installing browser extensions that survive standard software updates.

Chapter 03 - Operational Response

Security operations, threat hunting, and infrastructure teams must immediately adopt an aggressive containment posture across perimeter management planes, identity tenants, and endpoint fleets.

Perimeter Appliances And Control Planes: Immediate Response And Containment

[+] Emergency perimeter isolation: Immediately restrict network access to administrative web interfaces for Cisco FMC, F5 BIG IP, Arista VeloCloud, and Check Point systems to dedicated, out of band management networks.

[+] F5 BIG IP APM hotfix deployment: Apply engineering hotfixes across active branches including 21.1.0, 17.5.x, and 17.1.x, or implement vendor supplied traffic inspection rules to drop malformed OAuth authorization server requests.

[+] Cisco FMC remediation: Apply emergency vendor hotfixes for CVE-2026-20079 and CVE-2026-20316, followed by inspecting web directory paths for unauthorized JSP files or unusual Java archive execution.

[+] Arista VeloCloud exposure mitigation: Upgrade orchestrator software on supported release trains 5.2 and 6.4 to versions 5.2.3.16 and 6.4.2.8; for unsupported trains 6.1 and 7.0, enforce strict source IP access control lists and isolate edge certificate stores.

[+] Check Point management hotfix: Install the designated jumbo hotfix accumulator across all security management, multi domain, and log recording appliances, ensuring legacy gateway communication is monitored.

Identity And Cloud Systems: Immediate Response And Containment

[+] Restrict device code flow: Implement conditional access policies within corporate identity tenants to block OAuth device code authentication across all user groups except explicitly designated conference hardware.

[+] Revoke compromised sessions: Terminate active refresh tokens and revoke user sessions for identities exhibiting anomalous sign in events or rapid geographic transitions following authentication.

[+] Malicious inbox rule remediation: Execute automated tenant wide scans for newly registered mailbox forwarding rules containing keywords related to financial transactions, invoices, or administrative credentials.

[+] Device registration audit: Inspect corporate device directories for newly joined or registered endpoints that lack hardware compliance records and were enrolled immediately following external authentication events.

Endpoint And Fleet Hardening: Immediate Response And Containment

[+] Windows operating system patching: Deploy security updates addressing kernel privilege escalation flaws CVE-2026-85880 and CVE-2026-81963 across all domain controllers, workstations, and member servers.

[+] Browser update enforcement: Verify enterprise wide installation of Google Chrome and Microsoft Edge versions equal to or greater than 129.0.6668.89 to remediate active V8 memory corruption primitives.

[+] Peripheral switch remediation: Upgrade firmware across Zyxel GS1900 series devices to releases matching or exceeding 2.90(AAxx.2)C0, rotate administrative passwords, and disable remote web management.

[+] Software package integrity verification: Audit development environments and package managers for unauthorized dependencies including compromised MemTensor packages, isolating systems hosting untrusted libraries.

Defender Priority Action Matrix

Sequence Priority

Action Target

Operational Rationale

Execution Window

Priority 1

F5 BIG IP APM

Remediate data plane remote code execution on public authentication gateways

Within 4 hours

Priority 2

Cisco FMC

Patch actively weaponized management flaw utilized by ransomware syndicates

Within 4 hours

Priority 3

Arista VCO And Check Point

Upgrade control plane orchestrators and apply management jumbo hotfixes

Within 12 hours

Priority 4

Cloud Identity Tenants

Disable OAuth device code authentication and audit inbox forwarding rules

Within 24 hours

Priority 5

Enterprise Endpoints

Deploy Windows ALPC patches and enforce updated browser releases

Within 24 hours

Priority 6

Zyxel And Edge Switches

Upgrade switch firmware, rotate default credentials, and audit local TFTP logs

Within 48 hours

[+] 2026/05/07: Threat telemetry records initial scanning activity from single source IP addresses associated with the Kapibala threat actor group.

[+] 2026/06/11: Kapibala initiates systematic vulnerability scanning operations targeting enterprise remote access portals.

[+] 2026/06/12: Threat actors attempt exploitation against peripheral appliance chains, delivering initial stage backdoor payloads from dedicated staging servers.

[+] 2026/06/16: Hardware vendors release proactive firmware patches for peripheral switching hardware prior to wide scale in the wild exploitation.

[+] 2026/07/20: Adversaries begin mass exploitation of public web applications via automated command injection chains.

[+] 2026/07/22 01:27 to 06:01: Threat operators execute a complete public sector intrusion, deploying web shells, executing multiple privilege escalation variants, dumping security databases, and exfiltrating thousands of records.

[+] 2026/07/23: Telemetry sources observe targeted exploitation of unauthenticated path traversal vulnerabilities within Check Point security management platforms.

[+] 2026/08/17: Kapibala launches wide scale automated exploitation targeting nearly one thousand Zyxel network switches across dozens of countries.

[+] 2026/08/28: Intelligence teams observe the BlueMoon exploit kit weaponized in spear phishing campaigns chaining browser zero days with local privilege escalation.

[+] 2026/09/02: Forensic investigators document an autonomous intrusion workflow where human operators utilized frontier artificial intelligence agents to compress a multi week intrusion into hours.

[+] 2026/09/08: Security researchers detect active zero day exploitation of Windows ALPC and Update Stack vulnerabilities ahead of monthly scheduled patch releases.

[+] 2026/09/16: Advisory bodies issue urgent alerts regarding active exploitation of Cisco Identity Services Engine authentication bypass vulnerabilities under federal compliance directives.

[+] 2026/09/22: Coordinated vendor disclosures confirm active in the wild exploitation of F5 BIG IP APM, Arista VeloCloud Orchestrator, and Check Point Management Servers, accompanied by emergency federal tracking updates.

[+] 2026/09/22 14:30: Microsoft details the disruption of the EvilTokens phishing as a service infrastructure following widespread cloud account compromises.

[+] 2026/09/23 10:40: Reporting window concludes with multiple critical edge appliances under active exploitation and emergency remediation operations underway globally.

Chapter 04 - Detection Intelligence

Cisco FMC Authentication Bypass And Privilege Escalation

[+] Vulnerability classification: Authentication bypass leading to remote root command execution under CVE-2026-20079 and low privilege session establishment under CVE-2026-20316.

[+] Underlying root cause: Flawed URI path normalization and authentication filtering inside the Apache Tomcat web layer permits external requests to bypass identity verification checks and invoke backend administrative controllers.

[+] Exploitation mechanics: Unauthenticated HTTP requests directly target vulnerable servlets, passing parameters to underlying Perl maintenance scripts including package_info.pl, which executes with native operating system root privileges.

[+] Post exploitation tooling: Adversaries deploy home.jsp, a minimal web shell that receives Base64 encoded class names via parameter strings to load arbitrary bytecode into the Java Virtual Machine.

[+] Credential harvesting mechanics: Operators execute cmd.jar via Java runtime wrappers, invoking OmniQuery command line utilities to extract database credentials directly from MySQL user stores.

F5 BIG IP APM Preauthentication Heap Buffer Overflow

[+] Vulnerability classification: Preauthentication heap based buffer overflow under CVE-2026-94127, categorized under CWE-122.

[+] Vulnerability prerequisites: The target BIG IP instance must operate an active Access Policy Manager access policy paired with an OAuth profile where the appliance acts specifically as an OAuth Authorization Server.

[+] Execution mechanism: Crafted network requests directed to the virtual server trigger an off by one or sizing mismatch during token parameter processing in the Traffic Management Microkernel data plane, allowing memory overwrite and remote execution without control plane exposure.

Arista VeloCloud Orchestrator Improper Input Validation

[+] Vulnerability classification: Improper input validation under CVE-2026-93952, categorized under CWE-20.

[+] Architectural flaw: When VeloCloud Orchestrator On Premises instances are configured to authenticate connected edge hardware via cryptographic certificates, input sanitation routines fail to validate client supplied control requests.

[+] Exploit vector: Attackers possessing the public component of an edge authentication certificate transmit crafted API commands to the orchestrator web interface, gaining unauthenticated access to internal administrative methods without requiring operator passwords.

Check Point Security Management Server Directory Traversal

[+] Vulnerability classification: Preauthentication directory traversal and arbitrary file upload under CVE-2026-93616 and CVE-2026-91843.

[+] Trigger condition: Weak parameter sanitization in the management web daemon allows remote actors to break out of intended webroot paths, upload malicious executable scripts, and register Java classes directly within the server process space.

[+] Forensic footprint: Malicious transactions generate characteristic application log artifacts within cpm.elg containing abnormally long username strings that exceed one thousand characters in length.

BlueMoon Exploit Kit Multi Tier Browser Chain

[+] Initial renderer compromise: The exploit begins with CVE-2026-85046, a type confusion vulnerability in the Chromium V8 engine that enables out of bounds read and write primitives in memory.

[+] Virtual machine escape: Operators trigger CVE-2026-87491 to bypass V8 sandbox protections, obtaining arbitrary code execution within the unprivileged browser renderer process.

[+] Local kernel escalation: The payload invokes CVE-2026-85880, exploiting a heap buffer overflow in the Windows Advanced Local Procedure Call subsystem to corrupt kernel pool memory and elevate execution tokens to SYSTEM integrity.

[+] Persistence survival: The chain installs persistent browser extensions under legitimate names, configures scheduled tasks, and stages binary components within public user directories that survive browser software upgrades.

Indicator Value

Indicator Type

Context And Association

Verdict

74[.]48[.]66[.]73

IPv4 Address

Kapibala staging and backdoor delivery server on port 9860

Malicious

104[.]225[.]153[.]141

IPv4 Address

Kapibala command and control infrastructure

Malicious

172[.]245[.]247[.]21

IPv4 Address

Kapibala active exploitation source IP

Malicious

208[.]123[.]119[.]215

IPv4 Address

Sandworm UAT-11823 Netcat reverse shell listener on port 3090

Malicious

89[.]34[.]96[.]56

IPv4 Address

UAT-11823 secondary network communication node

Malicious

*.981666[.]xyz

Domain Wildcard

Kapibala active C2 domain infrastructure including Redis port 6379

Malicious

p3.981666[.]xyz

Domain Name

Kapibala resolved communication endpoint

Malicious

0e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480f

File Hash SHA256

Kapibala backdoor binary payload

Malicious

0f6e757e82c4d91df5bd249f775b9970b59dee42cc0dfe40f879d77fc16821c6

File Hash SHA256

Kapibala secondary implant binary

Malicious

2ff2945b13a4cd0e9a65c85af29ea1539e162a516466c0de682dbf9f8a4000b1

File Hash SHA256

Kapibala UniFi exploit backdoor delivery artifact

Malicious

6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461

File Hash SHA256

Sandworm Cyclops Blink modular Linux implant deployed on FMC

Malicious

Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e

File Hash SHA256

UAT-12197 cmd.jar generic command execution wrapper on FMC

Malicious

64e6ce23db74aed7c923268e953688fa5cc909cc9d1e84dd46063b62bd649bf6

File Hash SHA256

Malicious AWS Lambda function ex script used for environment exfiltration

Malicious

250d4fa37488af9b025333fa17705573d721467b203765bc360890ab4f5a90cd7

File Hash SHA256

CLOSEDQUORUM autonomous artificial intelligence malware build

Suspicious

c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7

File Hash SHA256

CLOSEDQUORUM secondary binary artifact

Suspicious

c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f

File Hash SHA256

CLOSEDQUORUM development research sample

Suspicious

f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c

File Hash SHA256

CLOSEDQUORUM compiled Windows PE executable

Suspicious

5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb

File Hash SHA256

CLOSEDQUORUM experimental capability artifact

Suspicious

eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5

File Hash SHA256

CLOSEDQUORUM payload generation module

Suspicious

kapibala

User Account

Unauthorized administrator account created for persistence

Malicious

kapibala2

User Account

Rogue account created with backdated Active Directory timestamps

Malicious

/wp-content/plugins/kapibala_plugin/kapibala_index.php

File Path

Kapibala PHP web shell deployment location

Malicious

/home/web/tmp/info.txt

File Path

Zyxel switch staging file containing reconnaissance data

Malicious

/var/tmp/license.tmp

File Path

Sandworm self extracting archive dropped on Cisco FMC

Malicious

C:\Users\Public\stomp_ext

Directory Path

BlueMoon persistent browser extension staging folder

Malicious

{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}

Registry CLSID

GhostChrome-X COM class identifier for browser integrity bypass

Malicious

Cisco FMC Web Shell And Script Abuse SIGMA Detection

title: Cisco FMC Web Shell Deployment And Process Abuse
id: d4f2c1a0-9b3e-4a7f-8c2e-1f5b9d8e7a6b
status: stable
description: Detects JSP web shell creation and package_info.pl abuse on Cisco FMC appliances
author: Inferlume CTI Team
date: 2026/09/23
logsource:
  product: cisco
  service: fmc
detection:
  selection_file:
    TargetFilename|endswith:
      - '\home.jsp'
      - '\cmd.jar'
  selection_process:
    Image|endswith: '\package_info.pl'
  selection_cmd:
    CommandLine|contains: 'license.tmp'
  condition: selection_file or (selection_process and selection_cmd)
fields:
  - TargetFilename
  - Image
  - CommandLine
  - User
level: critical
tags:
  - attack.t1505.003
  - attack.t1190
  - cve.2026.20079

Kapibala WordPress Web Shell Access SIGMA Detection

title: Kapibala Web Shell Parameter Invocation
status: experimental
logsource:
  category: webserver
detection:
  selection:
    cs-uri-stem|contains: '/wp-content/plugins/kapibala_plugin/kapibala_index.php'
    cs-uri-query|re: '.*kpbl=.*'
  condition: selection
fields:
  - c-ip
  - cs-method
  - cs-uri-stem
  - cs-uri-query
level: critical
tags:
  - attack.t1505.003
  - attack.t1190

BlueMoon GemStone Extension YARA Signature

rule BlueMoon_GemStone_Extension_Artifacts
{
    meta:
        description = "Detects GhostChrome-X integrity bypass and GemStone extension artifacts"
        author = "Inferlume CTI Team"
        date = "2026/09/23"
        cve = "CVE-2026-85046, CVE-2026-87491, CVE-2026-85880"
    strings:
        $clsid = "{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B}" ascii wide
        $folder = "stomp_ext" ascii wide
        $payload1 = "ChromeUpdate.exe" ascii wide
        $payload2 = "msgbox.exe" ascii wide
        $task1 = "EdgeCore_AutoUpdate" ascii wide
        $task2 = "MicrosoftEdgeUpdatesTaskMachine" ascii wide
        $mutex = "Dataupcheckinfo" ascii wide
    condition:
        3 of them
}

Cyclops Blink Linux Implant YARA Signature

rule UAT11823_Cyclops_Blink_Core
{
    meta:
        description = "Detects Cyclops Blink ELF implant deployed on Cisco FMC by UAT-11823"
        author = "Inferlume CTI Team"
        date = "2026/09/23"
        sha256 = "6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461"
    strings:
        $doh = "DNS over HTTPS" ascii
        $init = "/etc/init.d/" ascii
        $shell = "/bin/sh" ascii
        $rev1 = "nc 208.123.119.215" ascii
        $rev2 = "nc 89.34.96.56" ascii
        $archive = "license.tmp" ascii
    condition:
        uint32(0) == 0x464c457f and 3 of ($doh, $init, $shell, $rev1, $rev2, $archive)
}

SIEM Operational Correlation Logic

[+] Check Point management log query: Execute regular expressions across cpm.elg log sources to identify authentication events containing usernames exceeding one thousand characters: grep -nHP "login\(loginRequest=LoginRequest\{authenticationInfo=AuthenticationInfoBase\{username='[^']{1001,}'" "$MDS_FWDIR"/log/cpm.elg*

[+] F5 BIG IP APM OAuth anomaly query: In Splunk environments, correlate OAuth validation failures originating from single IP sources: index=f5 sourcetype=f5:apm "invalid_token" "UserInfo" | stats count values(uri_path) by src_ip | where count >= 10

[+] EvilTokens device code hunting query: In Microsoft Defender KQL, detect device code sign in events immediately followed by anomalous activity within thirty minutes:

SigninLogs
| where AuthenticationProtocol =~ "deviceCode"
| project DeviceCodeTime = TimeGenerated, UserPrincipalName, IPAddress, DeviceDetail
| join kind=inner (
    AuditLogs
    | where ActivityDisplayName in ("Add registered owner to device", "New-InboxRule", "Set-InboxRule")
    | project ActionTime = TimeGenerated, InitiatedBy = tostring(InitiatedBy.user.userPrincipalName), ActivityDisplayName, TargetResources
) on $left.UserPrincipalName == $right.InitiatedBy
| where ActionTime between (DeviceCodeTime .. (DeviceCodeTime + 30m))

MITRE Technique

Technique Name

Context And Application

D3FEND Countermeasure

T1190

Exploit Public Facing Application

Weaponized against Cisco FMC, F5 BIG IP, Arista VCO, Check Point, Zyxel

D3-NCD (Network Containment Deployment)

T1505.003

Web Shell

Deployed via home.jsp on FMC and kapibala_index.php on WordPress

D3-ICM (Isolate Compromised Module)

T1557.003

Adversary in the Middle: Device Flow

Storm 2992 EvilTokens platform abusing OAuth device code authentication

D3-MFA (Phishing Resistant Authentication)

T1068

Exploitation For Privilege Escalation

Exploited under CVE-2026-85880 in Windows ALPC and Linux kernel flaws

D3-PSP (Privilege Separation Enforcement)

T1055.004

Process Injection: APC Injection

Documented in browser exploit chains and advanced implant samples

D3-PA (Process Spawning Analysis)

T1078.004

Valid Accounts: Cloud Accounts

EvilTokens harvesting stolen access tokens for cloud tenant access

D3-CRM (Credential Rotation Management)

T1136.001

Local Account Creation

Kapibala creating rogue administrative accounts with backdated metadata

D3-UAA (User Account Authentication Audit)

T1003.002

Security Account Manager Dump

Kapibala executing registry saves to extract local SAM credentials

D3-CH (Credential Storage Hardening)

T1572

Protocol Tunneling

Qilin affiliate staging reverse SSH and SOCKS5 tunnels through FMC

D3-ITF (Inbound Traffic Filtering)

T1486

Data Encrypted For Impact

Qilin ransomware deploying file encryption post appliance breach

D3-SBR (System Backup And Restore Validation)

T1195.002

Compromise Software Supply Chain

Malicious MemTensor packages delivering Go backdoors via npm and PyPI

D3-SVA (Software Verification Analysis)

Chapter 05 - Governance, Risk & Compliance

Enterprise exposure across this reporting cycle extends beyond immediate perimeter failure into critical regulatory compliance and operational liability domains.

[+] Federal directive mandates: CISA Binding Operational Directive 26-04 enforces mandatory remediation deadlines across federal civilian agencies for newly listed vulnerabilities, including Cisco FMC, F5 BIG IP, Arista VeloCloud, and Check Point, requiring documented asset level verification.

[+] Data privacy breach disclosures: The theft of public sector records containing law enforcement credentials and plaintext access keys triggers strict seventy two hour notification windows under GDPR Article 33 and comparable global privacy statutes including the India DPDP Act.

[+] Software defined supply chain liability: Compromise of centralized network orchestrators such as Arista VeloCloud allows adversaries to alter traffic routing into third party tenants, creating contractual breach liabilities under service level agreements.

[+] Identity governance controls: Widespread account compromise via OAuth device authorization flows mandates formal compliance audits against NIST SP 800-63B standards, requiring transition to phishing resistant hardware tokens.

[+] Operational continuity risks: Reliance on unpatched release trains across enterprise network appliances requires immediate submission of documented risk acceptance waivers approved by executive leadership.

Chapter 06 - Adversary Emulation

Security engineering and purple teams must validate enterprise detection layers against the specific adversary behaviors observed during this operational window.

Scenario 1: Cisco FMC Perimeter Takeover Simulation

[+] Emulation objective: Validate security monitoring alerts against unauthenticated servlet requests chaining into underlying operating system shell execution.

[+] Execution sequence: Within a dedicated laboratory segment, generate synthetic HTTP traffic mimicking the authentication bypass structure against test endpoints, drop a dummy script in temporary directories, and spawn interactive shell interpreters.

[+] Expected detection alert: SIEM platforms must trigger critical alerts on web server daemons executing package installation scripts or spawning command shells.

[+] Failure indicator: Inability of endpoint detection tools to observe child process creation originating from web container binaries indicates an unmonitored blind spot.

Scenario 2: EvilTokens OAuth Device Flow Abuse Simulation

[+] Emulation objective: Verify automated alerting when user accounts complete device code authentication and subsequently initiate anomalous administrative operations.

[+] Execution sequence: Execute an authorized device code authentication workflow using dedicated evaluation identities, immediately followed by issuing Microsoft Graph directory queries and creating test forwarding rules.

[+] Expected detection alert: Identity protection engines must flag rapid subsequent administrative API activity following device code authentication within thirty minutes.

[+] Failure indicator: Execution of new inbox rules without correlation to the preceding device flow sign in event demonstrates alert pipeline fragmentation.

Scenario 3: Kapibala Privilege Escalation And Account Staging

[+] Emulation objective: Test EDR telemetry coverage against MSBuild inline task compilation, token manipulation, and registry extraction.

[+] Execution sequence: Execute benign MSBuild project files from temporary system directories, execute token duplicate API calls, and simulate registry access targeting local credential hives.

[+] Expected detection alert: Endpoint defenses must detect abnormal process parentage involving developer build tools writing to temporary directory structures.

[+] Failure indicator: Silent execution of administrative credential exports signifies an urgent requirement to tune endpoint prevention policies.

Intelligence Confidence87%

Evaluation Category

Score Contribution

Evidential Basis And Assessment

Primary Evidence Quality

40 / 40

Consulted sources include authoritative government catalogs, vendor security advisories, and primary incident response investigations

Multi Source Corroboration

25 / 25

Active exploitation claims for edge appliances, browser kits, and phishing rings are corroborated across multiple independent research bodies

Technical Data Completeness

15 / 15

Report provides complete CVE listings, CVSS rankings, technical execution mechanics, and actionable detection code

Attribution Clarity Deduction

Minus 8

Identity attributing certain clusters remains incomplete, specifically regarding UAT-12197 and the AI assisted attack actor

Unverified Claims Deduction

Minus 5

ShinyHunters data exfiltration claims against public recruitment portals remain under investigation without full technical confirmation

Final Confidence Assessment

87 / 100

High operational confidence supporting immediate defensive and remediation engineering across enterprise environments