Last Updated On

Edge Zero Days Active Exploitation Surge And Massive Identity Infrastructure Takeover
Critical edge network infrastructure is weathering an unprecedented wave of concurrent zero day attacks targeting Cisco, F5, Arista, and Check Point appliances.
Concurrently, Microsoft disrupted the massive EvilTokens platform after automated device code phishing compromised more than twelve thousand corporate inboxes across global enterprises.
Security operations must immediately deploy out of band appliance hotfixes, restrict OAuth device login flows, and hunt for active post exploitation implants.
10
CVSS Score
68
IOC Count
32
Source Count
87
Confidence Score
CVE-2026-20079, CVE-2026-20316, CVE-2026-94127, CVE-2026-93952, CVE-2026-93616, CVE-2026-91843, CVE-2026-85102, CVE-2026-76460, CVE-2026-7273, CVE-2026-85880, CVE-2026-81963, CVE-2026-85046, CVE-2026-87491, CVE-2026-32996, CVE-2026-63030, CVE-2026-60137, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-60004, CVE-2026-56271, CVE-2026-79756, CVE-2026-54569, CVE-2023-54391, CVE-2022-0847, CVE-2025-39682, CVE-2025-39964, CVE-2026-53266, CVE-2026-84869, CVE-2026-69730, CVE-2026-69676, CVE-2026-69852, CVE-2026-69854, CVE-2026-83501, CVE-2026-70585, CVE-2026-69857, CVE-2026-62916, CVE-2026-83941, CVE-2026-65818, CVE-2026-80098, CVE-2026-70352, CVE-2026-72957, CVE-2026-83548, CVE-2026-83549, CVE-2026-9586, CVE-2026-82329, CVE-2026-48710, CVE-2026-49869, CVE-2026-59822, CVE-2026-19490, CVE-2025-25249, CVE-2026-42016, CVE-2026-42018, CVE-2026-67277, CVE-2026-86060, CVE-2026-87886, CVE-2026-85706, CVE-2026-44756, CVE-2026-58240, CVE-2026-67279, CVE-2026-94545, CVE-2026-87902, CVE-2026-45498
UAT-11823, Sandworm, UAT-11988, Qilin, UAT-12197, Storm 2992, APT31, UTA0565, UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket, Kapibala, ShinyHunters, WaterPlum, Payroll Pirates, Black Axe, Unattributed Threat Actors
Government, Defense Industrial Base, Aerospace, Critical Manufacturing, Financial Services, Consulting, Non-Governmental Organizations, Commodity Trading, Telecommunications, Cloud and Artificial Intelligence Infrastructure, Healthcare, Higher Education, Software Engineering, Construction, Wholesale Distribution, Real Estate, Municipal Utilities
Global, United States, Canada, United Kingdom, European Union, Italy, France, Germany, Netherlands, Ukraine, Singapore, Indonesia, Vietnam, Taiwan, South Korea, India, Australia, Latin America, Morocco
Chapter 01 - Executive Overview
Executive leadership faces an acute convergence of perimeter collapse and identity infrastructure compromise across the enterprise landscape. During the current observation window, multiple critical edge platforms have experienced concurrent zero day exploitation, while industrialized credential operations bypassed conventional multifactor authentication barriers at scale.
Cisco Secure Firewall Management Center: Critical: Enterprise And Government Estates
[+] Threat overview: Unauthenticated remote adversaries actively weaponize a vulnerability pair within Cisco Secure Firewall Management Center web services under CVE-2026-20079 and CVE-2026-20316 to achieve root execution and appliance takeover.
[+] Strategic risk context: Compromise of centralized firewall management engines exposes underlying network topologies, yields access to internal administrative credentials, and enables direct traffic manipulation across managed enforcement points.
[+] Threat actor activity: Three distinct adversary groups are actively exploiting these flaws, including Russian state sponsored military intelligence operators deploying persistent implants, criminal ransomware syndicates staging network wide encryption, and credential theft operators.
[+] Leadership directive: Infrastructure leaders must immediately enforce out of band hotfixes across all exposed firewall management appliances and isolate web interfaces from external routing.
F5 BIG IP Access Policy Manager: Critical: Enterprise And Financial Perimeters
[+] Threat overview: Consulted sources confirm in the wild exploitation of CVE-2026-94127, an unauthenticated heap buffer overflow vulnerability in F5 BIG IP Access Policy Manager instances operating as OAuth Authorization Servers.
[+] Strategic risk context: The vulnerability resides in the data plane processing pipeline, allowing remote attackers to execute arbitrary system code directly on internet facing authentication gateways without user interaction.
[+] Severity and business impact: Exploitation completely compromises corporate identity perimeters, jeopardizes downstream single sign on sessions, and invalidates zero trust network architectures.
[+] Leadership directive: Security leadership must deploy engineering hotfixes immediately or apply vendor supplied traffic filtering rules to block malformed OAuth token requests.
Arista VeloCloud Orchestrator: Critical: Software Defined Networking Estates
[+] Threat overview: Threat actors are actively exploiting an unauthenticated input validation flaw under CVE-2026-93952 in on premises VeloCloud Orchestrator platforms configuring certificate based Edge authentication.
[+] Strategic risk context: Successful exploitation grants access to privileged internal management functions without requiring tenant credentials, creating a systemic supply chain exposure across all connected branch edges.
[+] Patch gap exposure: Vendor fixes remain restricted to specific release branches, leaving several active operational trains completely unpatched and reliant entirely on strict network isolation.
[+] Leadership directive: Network engineering directors must restrict orchestrator administrative interfaces to trusted internal subnets and audit connected branch edge device configurations.
Check Point Security Management Infrastructure: Critical: Enterprise Network Operations
[+] Threat overview: Adversaries conducted approximately two months of undetected access by exploiting preauthentication directory traversal and arbitrary file upload vulnerabilities under CVE-2026-93616 and CVE-2026-91843.
[+] Strategic risk context: The flaw allows unauthenticated attackers to execute scripts as root across security management, multi domain management, and event logging appliances.
[+] Operational blast radius: Centralized policy stores, administrative keys, and audit logging repositories are directly exposed to adversary modification and covert exfiltration.
[+] Leadership directive: Operations teams must deploy the latest vendor jumbo hotfix and inspect management service transaction logs for oversized administrative authentication sequences.
Industrialized Identity Theft Platform Disruption: High: Cloud Enterprise Environments
[+] Threat overview: Major cloud telemetry providers dismantled the core infrastructure supporting EvilTokens, an automated phishing as a service architecture that compromised more than twelve thousand accounts across ten thousand corporate entities.
[+] Strategic risk context: Operating under threat actor Storm 2992, the platform weaponized OAuth device login flows to bypass standard multifactor authentication, harvest application access tokens, and automate enterprise reconnaissance.
[+] Post breach compromise: Infiltrated organizations experienced automated corporate mailbox analysis, unauthorized device registrations for persistent primary refresh tokens, and malicious forwarding rule deployments.
[+] Leadership directive: Identity security teams must immediately restrict OAuth device code authentication flows within conditional access policies to explicitly authorized hardware profiles.
Multi Platform Mass Exploitation And Government Infiltration: High: Public Sector And Networking
[+] Threat overview: A sophisticated adversary tracked as Kapibala compromised nearly one thousand Zyxel network switches globally under CVE-2026-7273 while executing structured intrusions across public sector web properties.
[+] Strategic risk context: Attackers chained web application vulnerabilities to penetrate database backends, exfiltrating tens of thousands of sensitive records including law enforcement identity details and cleartext credentials.
[+] Technical tradecraft: The campaign combined obfuscated exploit binaries, defense evasion bypass scripts, token impersonation primitives, and automated network share credential spraying.
[+] Leadership directive: Security executives must mandate immediate firmware upgrades across peripheral network switching fleets and initiate enterprise credential rotations across impacted public domains.
Chapter 02 - Threat & Exposure Analysis
Adversary operations across this reporting window reflect a pronounced emphasis on perimeter control planes, identity session theft, and autonomous exploitation loops that collapse traditional defense timelines.
Incident Identifier | Vulnerability Or Vector | Threat Actor Or Nexus | Primary Mechanism And Impact |
|---|---|---|---|
Cisco FMC Intrusion Wave | CVE-2026-20079, CVE-2026-20316 | Sandworm, Qilin, UAT-12197 | Web application auth bypass enabling root execution, credential theft, and reverse SSH proxying |
F5 BIG IP APM Breach | CVE-2026-94127 | Under Attribution | Preauthentication heap buffer overflow in OAuth authorization server profile yielding data plane RCE |
VeloCloud Orchestrator Flaw | CVE-2026-93952 | Under Attribution | Improper input validation in certificate based edge authentication granting privileged internal access |
Check Point Management Zero Day | CVE-2026-93616, CVE-2026-91843 | Under Attribution | Preauthentication directory traversal and file upload permitting unauthenticated script execution as root |
EvilTokens Identity Platform | Device Code Flow Abuse | Storm 2992 | Industrialized OAuth device flow phishing bypassing MFA to capture access tokens and automate BEC |
Kapibala Edge And Web Campaign | CVE-2026-7273, CVE-2026-63030 | Kapibala (Red Heron overlap) | Mass switch exploitation and WordPress compromise leading to privilege escalation and database theft |
BlueMoon Espionage Chain | CVE-2026-85046, CVE-2026-87491 | APT31, UTA0565, Linked Clusters | Chromium V8 type confusion chained with sandbox escape and Windows ALPC kernel escalation |
Microsoft Zero Day Releases | CVE-2026-85880, CVE-2026-81963 | Commercial And State Clusters | Windows ALPC heap overflow and Update Stack link resolution exploited for unprivileged SYSTEM escalation |
[+] Cisco FMC exploitation dynamics: Attackers leverage CVE-2026-20079, a root cause failure in Tomcat request validation that routes unauthenticated web traffic directly into privileged script processing pipelines. When combined with CVE-2026-20316 low privilege access, actors execute arbitrary commands through package installation scripts that run natively with root authority.
[+] Adversary divergence on Cisco FMC: Consulted sources track three separate operational clusters exploiting the same management interface. UAT-12197 places Java server page web shells titled home.jsp and deploys cmd.jar to query user credential databases via OmniQuery utilities. UAT-11823, exhibiting strong behavioral overlap with Russian GRU Sandworm operators, drops self extracting archives containing Netcat reverse shells and deploys the modular Cyclops Blink ELF implant configured for DNS over HTTPS communication and device configuration exfiltration. UAT-11988, associated with Qilin ransomware affiliates, leverages living off the land scripts to map Active Directory infrastructures, stages SOCKS5 proxies alongside reverse SSH tunnels forwarding LDAP, Kerberos, SMB, and WinRM ports, and terminates antivirus software prior to deploying ransomware.
[+] F5 BIG IP APM execution pathway: Exploitation targets the Traffic Management Microkernel data plane where virtual servers host both an access policy and an OAuth Authorization Server profile. Crafted network traffic induces a heap buffer overflow in token validation parsing, resulting in arbitrary code execution without requiring administrative credentials or control plane access.
[+] VeloCloud Orchestrator control plane exposure: In on premises environments utilizing certificate based authentication between edge hardware and the centralized orchestrator, CVE-2026-93952 allows attackers possessing edge certificate public components to access backend configuration APIs. This enables unauthorized adversaries to alter software defined routing rules and issue arbitrary management commands across downstream network estates.
[+] Check Point long term persistence: Adversaries leveraged CVE-2026-93616 to bypass administrative authentication barriers on management servers, uploading arbitrary web payloads and Java classes. Consulted sources indicate attackers maintained persistent access across targeted organizations for approximately sixty days prior to public disclosure.
[+] EvilTokens attack automation: Operating across distributed cloud computing platforms including Vercel, Cloudflare Workers, and AWS Lambda, Storm 2992 orchestrated automated phishing campaigns simulating corporate applications. Victims entering authentication codes on legitimate vendor login portals unknowingly authorized attacker sessions, granting OAuth access tokens that automated scripts immediately leveraged to conduct corporate directory mapping and deploy email exfiltration rules.
[+] Kapibala campaign forensics: Threat actors tracked as Kapibala executed scanning operations dating back to early 2026 before launching automated exploit packages against nearly one thousand Zyxel network switches using PyArmor obfuscated Python binaries. On parallel vectors, the group breached public sector WordPress deployments via web shell injection, conducted local account creation with backdated timestamps, utilized MSBuild inline tasks to bypass security controls, and dumped local security accounts to facilitate database exfiltration.
[+] BlueMoon browser exploit kit chaining: Espionage actors deployed multi stage exploit chains beginning with spear phishing lures directing victims to actor controlled web pages. The chain triggers a type confusion vulnerability in the Chromium V8 engine under CVE-2026-85046, escapes renderer sandboxes via CVE-2026-87491, and escalates to SYSTEM privileges on Windows endpoints through ALPC kernel pool corruption under CVE-2026-85880, ultimately installing browser extensions that survive standard software updates.
Chapter 03 - Operational Response
Security operations, threat hunting, and infrastructure teams must immediately adopt an aggressive containment posture across perimeter management planes, identity tenants, and endpoint fleets.
Perimeter Appliances And Control Planes: Immediate Response And Containment
[+] Emergency perimeter isolation: Immediately restrict network access to administrative web interfaces for Cisco FMC, F5 BIG IP, Arista VeloCloud, and Check Point systems to dedicated, out of band management networks.
[+] F5 BIG IP APM hotfix deployment: Apply engineering hotfixes across active branches including 21.1.0, 17.5.x, and 17.1.x, or implement vendor supplied traffic inspection rules to drop malformed OAuth authorization server requests.
[+] Cisco FMC remediation: Apply emergency vendor hotfixes for CVE-2026-20079 and CVE-2026-20316, followed by inspecting web directory paths for unauthorized JSP files or unusual Java archive execution.
[+] Arista VeloCloud exposure mitigation: Upgrade orchestrator software on supported release trains 5.2 and 6.4 to versions 5.2.3.16 and 6.4.2.8; for unsupported trains 6.1 and 7.0, enforce strict source IP access control lists and isolate edge certificate stores.
[+] Check Point management hotfix: Install the designated jumbo hotfix accumulator across all security management, multi domain, and log recording appliances, ensuring legacy gateway communication is monitored.
Identity And Cloud Systems: Immediate Response And Containment
[+] Restrict device code flow: Implement conditional access policies within corporate identity tenants to block OAuth device code authentication across all user groups except explicitly designated conference hardware.
[+] Revoke compromised sessions: Terminate active refresh tokens and revoke user sessions for identities exhibiting anomalous sign in events or rapid geographic transitions following authentication.
[+] Malicious inbox rule remediation: Execute automated tenant wide scans for newly registered mailbox forwarding rules containing keywords related to financial transactions, invoices, or administrative credentials.
[+] Device registration audit: Inspect corporate device directories for newly joined or registered endpoints that lack hardware compliance records and were enrolled immediately following external authentication events.
Endpoint And Fleet Hardening: Immediate Response And Containment
[+] Windows operating system patching: Deploy security updates addressing kernel privilege escalation flaws CVE-2026-85880 and CVE-2026-81963 across all domain controllers, workstations, and member servers.
[+] Browser update enforcement: Verify enterprise wide installation of Google Chrome and Microsoft Edge versions equal to or greater than 129.0.6668.89 to remediate active V8 memory corruption primitives.
[+] Peripheral switch remediation: Upgrade firmware across Zyxel GS1900 series devices to releases matching or exceeding 2.90(AAxx.2)C0, rotate administrative passwords, and disable remote web management.
[+] Software package integrity verification: Audit development environments and package managers for unauthorized dependencies including compromised MemTensor packages, isolating systems hosting untrusted libraries.
Defender Priority Action Matrix
Sequence Priority | Action Target | Operational Rationale | Execution Window |
|---|---|---|---|
Priority 1 | F5 BIG IP APM | Remediate data plane remote code execution on public authentication gateways | Within 4 hours |
Priority 2 | Cisco FMC | Patch actively weaponized management flaw utilized by ransomware syndicates | Within 4 hours |
Priority 3 | Arista VCO And Check Point | Upgrade control plane orchestrators and apply management jumbo hotfixes | Within 12 hours |
Priority 4 | Cloud Identity Tenants | Disable OAuth device code authentication and audit inbox forwarding rules | Within 24 hours |
Priority 5 | Enterprise Endpoints | Deploy Windows ALPC patches and enforce updated browser releases | Within 24 hours |
Priority 6 | Zyxel And Edge Switches | Upgrade switch firmware, rotate default credentials, and audit local TFTP logs | Within 48 hours |
[+] 2026/05/07: Threat telemetry records initial scanning activity from single source IP addresses associated with the Kapibala threat actor group.
[+] 2026/06/11: Kapibala initiates systematic vulnerability scanning operations targeting enterprise remote access portals.
[+] 2026/06/12: Threat actors attempt exploitation against peripheral appliance chains, delivering initial stage backdoor payloads from dedicated staging servers.
[+] 2026/06/16: Hardware vendors release proactive firmware patches for peripheral switching hardware prior to wide scale in the wild exploitation.
[+] 2026/07/20: Adversaries begin mass exploitation of public web applications via automated command injection chains.
[+] 2026/07/22 01:27 to 06:01: Threat operators execute a complete public sector intrusion, deploying web shells, executing multiple privilege escalation variants, dumping security databases, and exfiltrating thousands of records.
[+] 2026/07/23: Telemetry sources observe targeted exploitation of unauthenticated path traversal vulnerabilities within Check Point security management platforms.
[+] 2026/08/17: Kapibala launches wide scale automated exploitation targeting nearly one thousand Zyxel network switches across dozens of countries.
[+] 2026/08/28: Intelligence teams observe the BlueMoon exploit kit weaponized in spear phishing campaigns chaining browser zero days with local privilege escalation.
[+] 2026/09/02: Forensic investigators document an autonomous intrusion workflow where human operators utilized frontier artificial intelligence agents to compress a multi week intrusion into hours.
[+] 2026/09/08: Security researchers detect active zero day exploitation of Windows ALPC and Update Stack vulnerabilities ahead of monthly scheduled patch releases.
[+] 2026/09/16: Advisory bodies issue urgent alerts regarding active exploitation of Cisco Identity Services Engine authentication bypass vulnerabilities under federal compliance directives.
[+] 2026/09/22: Coordinated vendor disclosures confirm active in the wild exploitation of F5 BIG IP APM, Arista VeloCloud Orchestrator, and Check Point Management Servers, accompanied by emergency federal tracking updates.
[+] 2026/09/22 14:30: Microsoft details the disruption of the EvilTokens phishing as a service infrastructure following widespread cloud account compromises.
[+] 2026/09/23 10:40: Reporting window concludes with multiple critical edge appliances under active exploitation and emergency remediation operations underway globally.
Chapter 04 - Detection Intelligence
Cisco FMC Authentication Bypass And Privilege Escalation
[+] Vulnerability classification: Authentication bypass leading to remote root command execution under CVE-2026-20079 and low privilege session establishment under CVE-2026-20316.
[+] Underlying root cause: Flawed URI path normalization and authentication filtering inside the Apache Tomcat web layer permits external requests to bypass identity verification checks and invoke backend administrative controllers.
[+] Exploitation mechanics: Unauthenticated HTTP requests directly target vulnerable servlets, passing parameters to underlying Perl maintenance scripts including package_info.pl, which executes with native operating system root privileges.
[+] Post exploitation tooling: Adversaries deploy home.jsp, a minimal web shell that receives Base64 encoded class names via parameter strings to load arbitrary bytecode into the Java Virtual Machine.
[+] Credential harvesting mechanics: Operators execute cmd.jar via Java runtime wrappers, invoking OmniQuery command line utilities to extract database credentials directly from MySQL user stores.
F5 BIG IP APM Preauthentication Heap Buffer Overflow
[+] Vulnerability classification: Preauthentication heap based buffer overflow under CVE-2026-94127, categorized under CWE-122.
[+] Vulnerability prerequisites: The target BIG IP instance must operate an active Access Policy Manager access policy paired with an OAuth profile where the appliance acts specifically as an OAuth Authorization Server.
[+] Execution mechanism: Crafted network requests directed to the virtual server trigger an off by one or sizing mismatch during token parameter processing in the Traffic Management Microkernel data plane, allowing memory overwrite and remote execution without control plane exposure.
Arista VeloCloud Orchestrator Improper Input Validation
[+] Vulnerability classification: Improper input validation under CVE-2026-93952, categorized under CWE-20.
[+] Architectural flaw: When VeloCloud Orchestrator On Premises instances are configured to authenticate connected edge hardware via cryptographic certificates, input sanitation routines fail to validate client supplied control requests.
[+] Exploit vector: Attackers possessing the public component of an edge authentication certificate transmit crafted API commands to the orchestrator web interface, gaining unauthenticated access to internal administrative methods without requiring operator passwords.
Check Point Security Management Server Directory Traversal
[+] Vulnerability classification: Preauthentication directory traversal and arbitrary file upload under CVE-2026-93616 and CVE-2026-91843.
[+] Trigger condition: Weak parameter sanitization in the management web daemon allows remote actors to break out of intended webroot paths, upload malicious executable scripts, and register Java classes directly within the server process space.
[+] Forensic footprint: Malicious transactions generate characteristic application log artifacts within cpm.elg containing abnormally long username strings that exceed one thousand characters in length.
BlueMoon Exploit Kit Multi Tier Browser Chain
[+] Initial renderer compromise: The exploit begins with CVE-2026-85046, a type confusion vulnerability in the Chromium V8 engine that enables out of bounds read and write primitives in memory.
[+] Virtual machine escape: Operators trigger CVE-2026-87491 to bypass V8 sandbox protections, obtaining arbitrary code execution within the unprivileged browser renderer process.
[+] Local kernel escalation: The payload invokes CVE-2026-85880, exploiting a heap buffer overflow in the Windows Advanced Local Procedure Call subsystem to corrupt kernel pool memory and elevate execution tokens to SYSTEM integrity.
[+] Persistence survival: The chain installs persistent browser extensions under legitimate names, configures scheduled tasks, and stages binary components within public user directories that survive browser software upgrades.
Indicator Value | Indicator Type | Context And Association | Verdict |
|---|---|---|---|
74[.]48[.]66[.]73 | IPv4 Address | Kapibala staging and backdoor delivery server on port 9860 | Malicious |
104[.]225[.]153[.]141 | IPv4 Address | Kapibala command and control infrastructure | Malicious |
172[.]245[.]247[.]21 | IPv4 Address | Kapibala active exploitation source IP | Malicious |
208[.]123[.]119[.]215 | IPv4 Address | Sandworm UAT-11823 Netcat reverse shell listener on port 3090 | Malicious |
89[.]34[.]96[.]56 | IPv4 Address | UAT-11823 secondary network communication node | Malicious |
*.981666[.]xyz | Domain Wildcard | Kapibala active C2 domain infrastructure including Redis port 6379 | Malicious |
p3.981666[.]xyz | Domain Name | Kapibala resolved communication endpoint | Malicious |
0e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480f | File Hash SHA256 | Kapibala backdoor binary payload | Malicious |
0f6e757e82c4d91df5bd249f775b9970b59dee42cc0dfe40f879d77fc16821c6 | File Hash SHA256 | Kapibala secondary implant binary | Malicious |
2ff2945b13a4cd0e9a65c85af29ea1539e162a516466c0de682dbf9f8a4000b1 | File Hash SHA256 | Kapibala UniFi exploit backdoor delivery artifact | Malicious |
6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 | File Hash SHA256 | Sandworm Cyclops Blink modular Linux implant deployed on FMC | Malicious |
Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e | File Hash SHA256 | UAT-12197 cmd.jar generic command execution wrapper on FMC | Malicious |
64e6ce23db74aed7c923268e953688fa5cc909cc9d1e84dd46063b62bd649bf6 | File Hash SHA256 | Malicious AWS Lambda function ex script used for environment exfiltration | Malicious |
250d4fa37488af9b025333fa17705573d721467b203765bc360890ab4f5a90cd7 | File Hash SHA256 | CLOSEDQUORUM autonomous artificial intelligence malware build | Suspicious |
c4dc171f2513fcaf9d5ecc815a94aee4063b213ab380f80bd3ac422dee5205a7 | File Hash SHA256 | CLOSEDQUORUM secondary binary artifact | Suspicious |
c13cea04f598e2b0c248d603a6e31bd13aabb64d8149c1b6a77b64e0b983a86f | File Hash SHA256 | CLOSEDQUORUM development research sample | Suspicious |
f5f1f8c3e7b883793800ab6ccf21b3e60bd0730f300b4595fe74a33adc17a63c | File Hash SHA256 | CLOSEDQUORUM compiled Windows PE executable | Suspicious |
5191cf625dfc209a347f137b50aea199e82040fd5ee9086fb3e2de73c133f3cb | File Hash SHA256 | CLOSEDQUORUM experimental capability artifact | Suspicious |
eddbd0ecf7195d38fefae5b9d393abfa79e6f3f94bde19308ecef130a05a42e5 | File Hash SHA256 | CLOSEDQUORUM payload generation module | Suspicious |
kapibala | User Account | Unauthorized administrator account created for persistence | Malicious |
kapibala2 | User Account | Rogue account created with backdated Active Directory timestamps | Malicious |
/wp-content/plugins/kapibala_plugin/kapibala_index.php | File Path | Kapibala PHP web shell deployment location | Malicious |
/home/web/tmp/info.txt | File Path | Zyxel switch staging file containing reconnaissance data | Malicious |
/var/tmp/license.tmp | File Path | Sandworm self extracting archive dropped on Cisco FMC | Malicious |
C:\Users\Public\stomp_ext | Directory Path | BlueMoon persistent browser extension staging folder | Malicious |
{5D4CFCB7-222C-4CA3-96B6-1F8195FBBB4B} | Registry CLSID | GhostChrome-X COM class identifier for browser integrity bypass | Malicious |
Cisco FMC Web Shell And Script Abuse SIGMA Detection
Kapibala WordPress Web Shell Access SIGMA Detection
BlueMoon GemStone Extension YARA Signature
Cyclops Blink Linux Implant YARA Signature
SIEM Operational Correlation Logic
[+] Check Point management log query: Execute regular expressions across cpm.elg log sources to identify authentication events containing usernames exceeding one thousand characters: grep -nHP "login\(loginRequest=LoginRequest\{authenticationInfo=AuthenticationInfoBase\{username='[^']{1001,}'" "$MDS_FWDIR"/log/cpm.elg*
[+] F5 BIG IP APM OAuth anomaly query: In Splunk environments, correlate OAuth validation failures originating from single IP sources: index=f5 sourcetype=f5:apm "invalid_token" "UserInfo" | stats count values(uri_path) by src_ip | where count >= 10
[+] EvilTokens device code hunting query: In Microsoft Defender KQL, detect device code sign in events immediately followed by anomalous activity within thirty minutes:
MITRE Technique | Technique Name | Context And Application | D3FEND Countermeasure |
|---|---|---|---|
T1190 | Exploit Public Facing Application | Weaponized against Cisco FMC, F5 BIG IP, Arista VCO, Check Point, Zyxel | D3-NCD (Network Containment Deployment) |
T1505.003 | Web Shell | Deployed via home.jsp on FMC and kapibala_index.php on WordPress | D3-ICM (Isolate Compromised Module) |
T1557.003 | Adversary in the Middle: Device Flow | Storm 2992 EvilTokens platform abusing OAuth device code authentication | D3-MFA (Phishing Resistant Authentication) |
T1068 | Exploitation For Privilege Escalation | Exploited under CVE-2026-85880 in Windows ALPC and Linux kernel flaws | D3-PSP (Privilege Separation Enforcement) |
T1055.004 | Process Injection: APC Injection | Documented in browser exploit chains and advanced implant samples | D3-PA (Process Spawning Analysis) |
T1078.004 | Valid Accounts: Cloud Accounts | EvilTokens harvesting stolen access tokens for cloud tenant access | D3-CRM (Credential Rotation Management) |
T1136.001 | Local Account Creation | Kapibala creating rogue administrative accounts with backdated metadata | D3-UAA (User Account Authentication Audit) |
T1003.002 | Security Account Manager Dump | Kapibala executing registry saves to extract local SAM credentials | D3-CH (Credential Storage Hardening) |
T1572 | Protocol Tunneling | Qilin affiliate staging reverse SSH and SOCKS5 tunnels through FMC | D3-ITF (Inbound Traffic Filtering) |
T1486 | Data Encrypted For Impact | Qilin ransomware deploying file encryption post appliance breach | D3-SBR (System Backup And Restore Validation) |
T1195.002 | Compromise Software Supply Chain | Malicious MemTensor packages delivering Go backdoors via npm and PyPI | D3-SVA (Software Verification Analysis) |
Chapter 05 - Governance, Risk & Compliance
Enterprise exposure across this reporting cycle extends beyond immediate perimeter failure into critical regulatory compliance and operational liability domains.
[+] Federal directive mandates: CISA Binding Operational Directive 26-04 enforces mandatory remediation deadlines across federal civilian agencies for newly listed vulnerabilities, including Cisco FMC, F5 BIG IP, Arista VeloCloud, and Check Point, requiring documented asset level verification.
[+] Data privacy breach disclosures: The theft of public sector records containing law enforcement credentials and plaintext access keys triggers strict seventy two hour notification windows under GDPR Article 33 and comparable global privacy statutes including the India DPDP Act.
[+] Software defined supply chain liability: Compromise of centralized network orchestrators such as Arista VeloCloud allows adversaries to alter traffic routing into third party tenants, creating contractual breach liabilities under service level agreements.
[+] Identity governance controls: Widespread account compromise via OAuth device authorization flows mandates formal compliance audits against NIST SP 800-63B standards, requiring transition to phishing resistant hardware tokens.
[+] Operational continuity risks: Reliance on unpatched release trains across enterprise network appliances requires immediate submission of documented risk acceptance waivers approved by executive leadership.
Chapter 06 - Adversary Emulation
Security engineering and purple teams must validate enterprise detection layers against the specific adversary behaviors observed during this operational window.
Scenario 1: Cisco FMC Perimeter Takeover Simulation
[+] Emulation objective: Validate security monitoring alerts against unauthenticated servlet requests chaining into underlying operating system shell execution.
[+] Execution sequence: Within a dedicated laboratory segment, generate synthetic HTTP traffic mimicking the authentication bypass structure against test endpoints, drop a dummy script in temporary directories, and spawn interactive shell interpreters.
[+] Expected detection alert: SIEM platforms must trigger critical alerts on web server daemons executing package installation scripts or spawning command shells.
[+] Failure indicator: Inability of endpoint detection tools to observe child process creation originating from web container binaries indicates an unmonitored blind spot.
Scenario 2: EvilTokens OAuth Device Flow Abuse Simulation
[+] Emulation objective: Verify automated alerting when user accounts complete device code authentication and subsequently initiate anomalous administrative operations.
[+] Execution sequence: Execute an authorized device code authentication workflow using dedicated evaluation identities, immediately followed by issuing Microsoft Graph directory queries and creating test forwarding rules.
[+] Expected detection alert: Identity protection engines must flag rapid subsequent administrative API activity following device code authentication within thirty minutes.
[+] Failure indicator: Execution of new inbox rules without correlation to the preceding device flow sign in event demonstrates alert pipeline fragmentation.
Scenario 3: Kapibala Privilege Escalation And Account Staging
[+] Emulation objective: Test EDR telemetry coverage against MSBuild inline task compilation, token manipulation, and registry extraction.
[+] Execution sequence: Execute benign MSBuild project files from temporary system directories, execute token duplicate API calls, and simulate registry access targeting local credential hives.
[+] Expected detection alert: Endpoint defenses must detect abnormal process parentage involving developer build tools writing to temporary directory structures.
[+] Failure indicator: Silent execution of administrative credential exports signifies an urgent requirement to tune endpoint prevention policies.
Evaluation Category | Score Contribution | Evidential Basis And Assessment |
|---|---|---|
Primary Evidence Quality | 40 / 40 | Consulted sources include authoritative government catalogs, vendor security advisories, and primary incident response investigations |
Multi Source Corroboration | 25 / 25 | Active exploitation claims for edge appliances, browser kits, and phishing rings are corroborated across multiple independent research bodies |
Technical Data Completeness | 15 / 15 | Report provides complete CVE listings, CVSS rankings, technical execution mechanics, and actionable detection code |
Attribution Clarity Deduction | Minus 8 | Identity attributing certain clusters remains incomplete, specifically regarding UAT-12197 and the AI assisted attack actor |
Unverified Claims Deduction | Minus 5 | ShinyHunters data exfiltration claims against public recruitment portals remain under investigation without full technical confirmation |
Final Confidence Assessment | 87 / 100 | High operational confidence supporting immediate defensive and remediation engineering across enterprise environments |
