Last Updated On

CCTTII--22002266--00992222
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

Zyxel Zero Day Exploited as Nation States Weaponize Chrome and Terraform

Emergency advisories confirm widespread active exploitation of critical infrastructure, client software, and edge appliances across global networks. Threat actors are aggressively weaponizing a stack buffer overflow in Zyxel GS1900 switches alongside an industrialized Chrome and Windows zero day exploit kit that delivers the stealthy CLEANGULP backdoor.

Simultaneously, maximum severity authentication bypass vulnerabilities in Cisco Identity Services Engine expose enterprise network access control policies to unauthenticated remote adversaries. State sponsored actors from North Korea continue executing sophisticated supply chain intrusions, poisoning Terraform developer configurations and compromising cryptocurrency assets through fraudulent technical recruitment campaigns.

Security teams must immediately enforce firmware updates across network edge appliances, restrict administrative management interfaces, deploy updated detection rules, and audit software development pipelines.

10

CVSS Score

110

IOC Count

24

Source Count

88

Confidence Score

CVEs

CVE-2026-7273, CVE-2026-85046, CVE-2026-87491, CVE-2026-85880, CVE-2026-76460, CVE-2026-76423, CVE-2025-39682, CVE-2026-53266, CVE-2025-39964, CVE-2026-32996, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-56271, CVE-2026-63030, CVE-2026-60137, CVE-2022-0847, CVE-2026-60004, CVE-2026-79756, CVE-2026-54569, CVE-2023-54391

Actors

Suspected Chinese Malicious Cyber Actor Kapibala, Red Heron, UTA0565, TA412 JungleBamboo Violet Typhoon APT31, UTA0560, UNK LateNight, UNK DoubleCheck, UNK QuietRacket, Jade Sleet TraderTraitor UNC4899 PUKCHONG, WaterPlum Contagious Interview 313 General Bureau, FamousSparrow, SideCopy TAG 140

Sectors

Government, Critical Infrastructure, Information Technology, Telecommunications, Financial Services, Cryptocurrency, Healthcare, Education, Small and Medium Business, Manufacturing, Aerospace, Defense, Media, Software Development, Digital Marketing, Retail

Regions

Global, North America, Europe, Asia Pacific, Latin America, United States, Italy, Taiwan, France, South Korea, Netherlands, Czech Republic, United Kingdom, Thailand, Slovakia, India, Germany, Brazil, Colombia, Switzerland, Japan, Poland, Vietnam

Chapter 01 - Executive Overview

[+] Primary Incident: Zyxel GS1900 Smart Managed Switches Mass Infiltration
Consulted sources and official catalogs confirm active in the wild exploitation of CVE-2026-7273, a critical stack based buffer overflow residing in the CGI program of Zyxel GS1900 series network switches. A disciplined Chinese speaking threat actor has weaponized this vulnerability since mid August 2026, compromising at least 996 switches across 48 sovereign nations. Alarmingly, 564 of these compromised devices operated with factory default credentials, allowing the adversary to achieve unauthenticated adjacent network command execution, deploy automated collector payloads, and exfiltrate device configurations, hashed administrative credentials, and internal network maps. Emergency directives mandate complete remediation by September 24 2026.

[+] Secondary Incident: Industrialized Browser Zero Day Chain Deployed Against Governments
A sophisticated cyber espionage operator designated UTA0565 has been uncovered utilizing a commercial grade exploit kit named BlueMoon to target Asian government personnel and policy institutions. The attack chain links three zero day vulnerabilities spanning Google Chrome V8 memory corruption under CVE-2026-85046, WebAssembly sandbox escape under CVE-2026-87491, and Microsoft Windows kernel local privilege escalation under CVE-2026-85880. By directing victims to cloned media and think tank web properties through targeted spear phishing, the adversary silently achieves unauthenticated SYSTEM level code execution, deploying a newly identified stealth backdoor known as CLEANGULP.

[+] Tertiary Incident: Enterprise Identity and Core Operating System Vulnerabilities Exploited
Enterprise identity fabrics face catastrophic risk following the confirmed exploitation of Cisco Identity Services Engine vulnerabilities CVE-2026-76460 and CVE-2026-76423, both rated at maximum CVSS 10.0 severity. These flaws permit unauthenticated remote attackers to bypass web authentication mechanisms, seize administrative control, manipulate network access policies, and forge trust certificates. Concurrently, active exploitation of three Linux kernel vulnerabilities under CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 triggered emergency governmental remediation deadlines due to weaponized exploits capable of system crashes, memory disclosure, and privilege escalation.

[+] Quaternary Incident: State Sponsored Supply Chain Poisoning and Developer Targeting
Democratic People Republic of Korea state sponsored threat groups have accelerated attacks against software engineering infrastructure. The actor known as Jade Sleet breached an Indian information technology provider by distributing weaponized Terraform lock files through fake employment evaluations, dropping Rust backdoors FLATROOF and ROOFDECK that abuse Telegram and decentralized Nostr protocols. In a parallel campaign, the WaterPlum group compromised over 30000 devices across 100 countries, siphoning 10.71 million dollars in cryptocurrency from more than 7000 developer and corporate wallets through fraudulent technical interview software.

[+] Additional Threat Campaigns: Backup Systems, Content Delivery Networks, and Regional Espionage
Additional high severity incidents encompass public exploit availability and exploitation attempts against Veeam Agent for Windows under CVE-2026-32996, enabling standard users to escalate to SYSTEM privileges by abusing cached session identifiers. In the web ecosystem, a compromised Cloudflare API key enabled attackers to alter Brevo services, injecting malicious ClickFix scripts into over 100000 websites. Concurrently, the FamousSparrow espionage group deployed the SparroWocky backdoor against eight Latin American governments, SideCopy targeted Indian academic institutions with ReverseRAT, and Gyazo remediated a breach exposing 23.62 million user records.

Chapter 02 - Threat & Exposure Analysis

[+] Exploitation Mechanics of the Zyxel Network Switch Campaign:
The exploitation of CVE-2026-7273 centers on input validation failures within the web management CGI binaries of Zyxel GS1900 series firmware versions 2.10 through 2.90. An unauthenticated attacker positioned on an adjacent local network transmits a crafted HTTP POST request containing an oversized buffer that corrupts the execution stack, overwriting return pointers to hijack program control flow. The threat actor orchestrates this initial breach using an obfuscated Python script compiled with PyArmor, featuring command line parameters tailored for specific switch architectures.

[+] Automated Network Device Data Collection and Staging:
Following successful memory corruption, the exploit invokes a shell command instructing the switch operating system to execute a trivial file transfer protocol download command, retrieving a collector script labeled as file c from an external staging host over UDP port 6969. This collector automates local system discovery, copying system configurations, routing tables, and hashed administrative credentials to a local staging file at path /home/web/tmp/info.txt. The adversary then downloads this archive over standard web protocols and establishes backdoor administrative accounts named kapibala and kapibala2.

[+] Wider Tactical Footprint of the Kapibala Intrusion Cluster:
Consulted sources indicate that the threat actor driving the Zyxel switch campaign possesses extensive multi vector capabilities, demonstrating substantial tactical overlap with the Red Heron espionage cluster. Between May and September 2026, the actor systematically compromised varied internet facing software suites, including Ubiquiti UniFi OS appliances, Flowise machine learning orchestration interfaces, Gitea code repositories, and WordPress web environments. In one July 2026 intrusion into a western governmental agency, the adversary utilized the wp2shell exploit chain to exfiltrate over 18566 sensitive law enforcement and personnel records.

[+] The BlueMoon Zero Day Espionage Ecosystem:
The BlueMoon exploitation framework represents an industrialized offensive capability shared among at least five distinct China aligned threat actors, including TA412, UTA0560, UNK LateNight, UNK DoubleCheck, and UTA0565. The framework exploits a critical patch gap in Google Chrome under CVE-2026-85046, where security fixes merged into public Chromium source code were reverse engineered by adversaries before the stable release reached end users. By pairing this renderer memory corruption flaw with a WebAssembly sandbox escape under CVE-2026-87491 and a Windows kernel elevation flaw under CVE-2026-85880, the exploit achieves full remote machine takeover through web visits alone.

[+] Deployment and Architecture of the CLEANGULP Implant:
In operations conducted by UTA0565, targets were directed via targeted emails to convincing clones of media outlets and policy institutes, such as the Center for American Progress and China Digital Times, hosted on dedicated infrastructure. The cloned web pages embedded a hidden iframe linking to an exploit staging page that triggered the BlueMoon chain without disrupting the visual rendering of the legitimate site. Upon gaining kernel level privileges, the loader downloaded an 893 kilobyte binary named chrome_cleanup.exe, stripped its Mark of the Web attributes, and launched the CLEANGULP backdoor using Component Object Model execution. CLEANGULP installs into the user profile directory, masquerades as an official Microsoft Input Method Editor component, establishes a persistent scheduled task, and beacons to typosquatted domains using AES 256 GCM encrypted payloads disguised within custom Base64 alphabets.

[+] Enterprise Exposure from Cisco Identity Services Engine Compromise:
The emergence of unauthenticated remote authentication bypass vulnerabilities CVE-2026-76460 and CVE-2026-76423 in Cisco Identity Services Engine exposes enterprise network perimeters to total compromise. Because Identity Services Engine serves as the central policy decision point for network segmentation, virtual private networks, and device authentication, administrative compromise allows adversaries to silently rewrite access control lists, permit unauthorized devices onto restricted network segments, create rogue administrator identities, and extract internal security certificates.

[+] North Korean Software Supply Chain and Developer Targeting:
The Democratic People Republic of Korea cyber apparatus has heavily prioritized developer environments as high yield initial access vectors. The Jade Sleet campaign demonstrates advanced understanding of infrastructure as code workflows by inserting malicious dependency requirements into Terraform lock files distributed during technical interview evaluations. Developers running standard initialization commands inadvertently download poisoned packages, leading to the execution of FLATROOF and ROOFDECK backdoors that extract browser credentials, terminal histories, and cryptocurrency keys. Simultaneously, WaterPlum operations utilize fraudulent recruiter personas to trick developers into running trojanized video conferencing and coding test applications, stealing millions from corporate treasuries.

[+] Backup Platform Exploitation and Local Privilege Escalation Risks:
The disclosure of public exploit scripts targeting Veeam Agent for Microsoft Windows under CVE-2026-32996 introduces substantial lateral movement risks within enterprise environments. Standard, unprivileged local users can inspect world readable endpoint backup logs to harvest cached administrator session identifiers. By transmitting these stolen tokens across internal named pipes to the backup service, unprivileged users force the service to execute arbitrary commands under the NT AUTHORITY SYSTEM context, effectively neutralizing local endpoint controls.

Chapter 03 - Operational Response

[+] Immediate Containment Priorities (0 to 24 Hours):
Security operations must immediately isolate all Zyxel GS1900 series switches from untrusted local area network segments and internet facing gateways. Verify switch firmware versions against known vulnerable builds, applying vendor firmware updates in the 2.90(XXXX.2)C0 series without delay. For environments running Cisco Identity Services Engine versions 3.0 through 3.3, immediately upgrade nodes to build 3.3.1.11100-149 or later, while restricting administrative interface access strictly to isolated out of band management networks. Inspect all endpoints running Google Chrome to confirm the installation of version 152.0.7977.82 or higher, accompanied by the Microsoft September 2026 cumulative security updates.

[+] Host and Infrastructure Triage Protocols (24 to 72 Hours):
Perform network wide forensic sweeps across firewall and routing telemetry for outbound TFTP sessions on UDP port 69 or port 6969 originating from network appliance management IP addresses. Execute endpoint detection sweeps across Windows workstations for scheduled tasks bearing the label MicrosoftIME or any binary residing within local application data directories referencing Microsoft Input Method Editor paths. Conduct retroactive proxy and DNS log reviews spanning a minimum of thirty days for connections to known BlueMoon domains, Nostr relay infrastructure, and typosquatted provider registries.

[+] Eradication and Identity Hardening Procedures (1 to 2 Weeks):
Enforce immediate credential revocation and password rotation for all administrative accounts configured on Zyxel switches, Veeam backup deployments, and Cisco Identity Services Engine clusters. Assume that any switch compromised prior to patching has had its hashed root credentials harvested, rendering password rotation mandatory. In software development teams, establish mandatory verification policies for Terraform dependency locks, prohibiting the execution of initialization commands from unverified repositories. Inspect all websites utilizing external form and marketing scripts to ensure that compromised Brevo endpoints are purged, implementing Subresource Integrity hashes and strict Content Security Policies.

Timestamp

Event Summary

Strategic Significance

2026/03/18

Initial FLATROOF and ROOFDECK infection on Apple Silicon hardware

Earliest detection of North Korean macOS backdoors in developer environments

2026/03/29

Decentralized C2 beaconing initiated via Nostr and Telegram

Adversary establishes stealth command channels using public protocols

2026/06/01

WaterPlum Contagious Interview campaign initiates operations

Mass targeting of developers and digital currency wallets commences

2026/06/16

Zyxel publishes initial patches for GS1900 buffer overflow

Vendor releases firmware updates prior to public exploitation awareness

2026/06/25

Gyazo discovers internal image upload server vulnerability

Media server vulnerability identified during internal system review

2026/08/17

Active in the wild exploitation of Zyxel switches observed

Chinese speaking threat actor initiates automated switch compromise campaigns

2026/08/28

BlueMoon zero day exploit kit observed in targeted spear phishing

TA412 deploys commercial grade Chrome and Windows zero day exploit chain

2026/09/03

UTA0565 deploys cloned web portals and CLEANGULP backdoor

Third distinct espionage operator adopts the BlueMoon exploit framework

2026/09/11

Gyazo publicly discloses unauthorized data exposure

Disclosure confirms compromise of 23.62 million user records

2026/09/14

Brevo Cloudflare key compromised; Veeam LPE PoC published

Script injection hits 100000 sites while Veeam exploit becomes public

2026/09/16

Cisco releases emergency patches for ISE vulnerabilities

CISA adds CVSS 10.0 flaws to KEV catalog with immediate deadlines

2026/09/18

Joint international advisory exposes WaterPlum; Linux KEV added

Law enforcement warns of 30000 infections; Linux flaws added to catalog

2026/09/21

CISA mandates federal remediation for Zyxel GS1900 switches

CISA sets September 24 remediation deadline under emergency directive

2026/09/22

Multi organization reports corroborate extensive campaigns

Coordinated reporting reveals global scale of switch and browser compromises

Chapter 04 - Detection Intelligence

[+] Detailed Mechanics of CVE-2026-7273 Zyxel Switch Exploitation:
The vulnerability represents a classical stack based buffer overflow categorized as CWE 121 within the web administrative interface CGI binary of Zyxel GS1900 switches. When handling incoming HTTP requests, the application parses user supplied input parameters without verifying length boundaries against allocated stack buffers. By sending an oversized payload across an adjacent network connection, an attacker overwrites the saved frame pointer and return address on the program stack. This redirection transfers control flow to injected shellcode or existing executable segments within memory, granting root shell access. Because the switch executes administrative web services with root privileges, the injected command shell inherits unrestricted control over hardware interfaces and network configuration files.

[+] Deconstruction of the BlueMoon Three Stage Exploit Chain:
The BlueMoon exploit kit orchestrates a seamless three stage privilege escalation sequence starting from an unauthenticated browser context. The initial stage weaponizes CVE-2026-85046, a type confusion vulnerability residing within the Google Chrome V8 JavaScript engine. This flaw stems from a timing window where patch commits in public Chromium repositories exposed memory optimization weaknesses before stable client updates were distributed. Exploitation of this flaw provides the attacker with arbitrary read and write primitives inside the restricted V8 heap sandbox.

[+] Sandbox Escape and Kernel Privilege Escalation Execution:
Stage two transitions execution through CVE-2026-87491 by intentionally corrupting WebAssembly internal data structures, bypassing Chrome renderer isolation to execute arbitrary shellcode within the main browser process. Stage three achieves operating system takeover by triggering CVE-2026-85880, a vulnerability within the Microsoft Windows kernel Advanced Local Procedure Call subsystem. The exploit manipulates message communication structures to achieve kernel memory write primitives, completely breaking process isolation and elevating the payload thread to NT AUTHORITY SYSTEM. The payload then injects directly into the parent browser process, downloads the final implant, and invokes Component Object Model interfaces to launch the executable while removing Mark of the Web telemetry flags.

[+] Architectural Analysis of the CLEANGULP Backdoor:
The CLEANGULP implant represents a custom engineered Windows 64 bit espionage backdoor developed in C and compiled using Microsoft Visual Studio. To impede automated static disassembly, the malware incorporates extensive control flow flattening, dummy function loops, and dynamic API address resolution. Persistence is established by writing the executable payload to %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe and creating a scheduled task titled MicrosoftIME. Network communication operates across standard HTTP to typosquatted domains, transmitting system surveys and receiving secondary plugins. Communication bodies are encrypted using AES 256 GCM where the encryption key is derived from a hardcoded SHA256 seed, followed by encoding through a non standard, custom Base64 alphabet that evades basic network protocol decoders.

[+] Exploitation Flow of Cisco Identity Services Engine Flaws:
Vulnerabilities CVE-2026-76460 and CVE-2026-76423 exist within the web administration request dispatcher of Cisco Identity Services Engine. Attackers transmit specifically structured HTTP requests containing manipulated header attributes and path traversals that cause internal authentication validation filters to bypass credential checks. As a result, the internal servlet container processes the incoming request as an authenticated administrative session, exposing the full suite of configuration and policy modification endpoints to unauthenticated remote entities.

[+] Veeam Agent Session Identifier Theft and Service Hijacking:
The vulnerability designated CVE-2026-32996 in Veeam Agent for Microsoft Windows arises from improper access control applied to service diagnostic logs, categorized under CWE 532. The primary backup service records active user session unique identifiers to a local log file situated at C:\ProgramData\Veeam\Endpoint\Svc.VeeamEndpointBackup.log. Because this file system directory permits read permissions to standard authenticated local users, unprivileged accounts can parse the log file to extract valid administrator session tokens. The attacker subsequently initiates communication across the local named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe, providing the stolen session token alongside arbitrary commands. The backup service executes the requested payload under the NT AUTHORITY SYSTEM context without verifying that the named pipe caller matches the token owner.

[+] Network and Host Indicators Table:

Indicator Type

Defanged Value

Operational Context

IPv4 Address

172.245.247[.]21

Zyxel GS1900 active exploitation source node

IPv4 Address

74.48.66[.]73

Staging server for switch collectors and UniFi payloads

IPv4 Address

104.225.153[.]141

Command and control node for Kapibala infrastructure

IPv4 Address

96.9.125[.]52

Hosting server for cloned China Digital Times portal

IPv4 Address

45.61.157[.]22

SideCopy ReverseRAT command and control endpoint

IPv4 Address

216.238.110[.]120

FamousSparrow SparroWocky command and control node

Domain

chinadigitaltimes[.]top

Cloned news portal delivering BlueMoon exploit chain

Domain

americanprgoress[.]top

Typosquatted think tank portal hosting CLEANGULP

Domain

thecovnresation[.]com

Primary C2 domain for CLEANGULP backdoor communication

Domain

*.981666[.]xyz

Wildcard C2 domain infrastructure utilized by Kapibala

Domain

dns.educationportals[.]biz

SideCopy dynamic DNS infrastructure

URL Endpoint

hxxp://thecovnresation[.]com/beacon/pre-register

Initial registration beacon endpoint for CLEANGULP

SHA256 Hash

8858ea412dc306b3558885af18006c5ca24689e8875733b5e13b3c2692e603cb

Win64 CLEANGULP payload binary chrome_cleanup.exe

SHA256 Hash

0e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480f

Backdoor binary associated with Kapibala operations

SHA256 Hash

2ff2945b13a4cd0e9a65c85af29ea1539e162a516466c0de682dbf9f8a4000b1

Secondary backdoor payload deployed in appliance attacks

SHA256 Hash

c491d477dbe0ae04e9aed9dbe237144c03f73ec4

Jade Sleet ROOFDECK macOS backdoor executable

File Path

%LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe

Masqueraded disk install location for CLEANGULP

File Path

/home/web/tmp/info.txt

Local staging file for exfiltrated Zyxel switch data

Named Pipe

\.\pipe\Veeam\VAW\ServiceConnectionPipe

Interprocess pipe abused for Veeam privilege escalation

Account Name

kapibala

Rogue local administrative user created on switches

Account Name

kapibala2

Secondary rogue administrator account created on switches

[+] SIGMA Rule for Detecting Zyxel CGI Buffer Overflow Exploitation:

title: Zyxel GS1900 CGI Buffer Overflow Exploitation Attempt
status: experimental
description: Detects crafted HTTP POST requests to Zyxel GS1900 CGI endpoints indicative of CVE-2026-7273 exploitation
logsource:
    category: webserver
    product: nginx
detection:
    selection_uri:
        c-uri|contains:
            - '/cgi-bin/'
            - 'GS1900'
    selection_method:
        c-method: 'POST'
    selection_anomaly:
        c-status:
            - 200
            - 500
    condition: selection_uri and selection_method and selection_anomaly
falsepositives:
    - Legitimate administrative requests from authorized network engineering consoles
level: high
tags:
    - attack.initial_access
    - attack.t1190

[+] SIGMA Rule for Detecting CLEANGULP Scheduled Task Persistence:

title: CLEANGULP Persistence via MicrosoftIME Scheduled Task
status: experimental
description: Detects the creation of a scheduled task named MicrosoftIME designed to establish persistence for the CLEANGULP backdoor
logsource:
    product: windows
    category: process_creation
detection:
    selection_proc:
        Image|endswith: '\schtasks.exe'
    selection_cli:
        CommandLine|contains|all:
            - '/create'
            - 'MicrosoftIME'
    condition: selection_proc and selection_cli
falsepositives:
    - Highly unlikely in standard enterprise environments
level: critical
tags:
    - attack.persistence
    - attack.t1053.005

[+] SIGMA Rule for Detecting Suspicious Outbound Switch TFTP Traffic:

title: Outbound TFTP Data Transfer from Network Management Segment
status: experimental
description: Detects unexpected outbound TFTP connections from management subnets indicating automated payload retrieval or data exfiltration
logsource:
    category: firewall
detection:
    selection_port:
        dst_port: 69
        protocol: udp
    selection_direction:
        direction: outbound
    condition: selection_port and selection_direction
falsepositives:
    - Legitimate firmware provisioning to internal network TFTP servers
level: high
tags:
    - attack.exfiltration
    - attack.t1567

[+] YARA Rule for Detecting CLEANGULP Windows Backdoor:

rule Win64_Backdoor_CLEANGULP {
    meta:
        description = "Detects CLEANGULP Windows 64-bit backdoor deployed in BlueMoon zero-day operations"
        author = "Inferlume CTI"
        date = "2026/09/22"
        score = 85
    strings:
        $s1 = "thecovnresation" ascii
        $s2 = "/beacon/pre-register" ascii
        $s3 = "\\Microsoft\\IME\\MicrosoftIME" ascii wide
        $s4 = "MicrosoftIME" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 2MB and
        3 of ($s1, $s2, $s3, $s4)
}

[+] YARA Rule for Detecting PyArmor Obfuscated Collector Scripts:

rule Script_PyArmor_Zyxel_Collector {
    meta:
        description = "Detects PyArmor obfuscated Python scripts utilized to collect configurations from Zyxel GS1900 switches"
        author = "Inferlume CTI"
        date = "2026/09/22"
        score = 80
    strings:
        $header = "PYARMOR" ascii
        $cmd1 = "tftp -gr c" ascii
        $path1 = "/home/web/tmp/info.txt" ascii
        $str1 = "Zyxel GS1900" ascii
    condition:
        $header and ($cmd1 or $path1 or $str1)
}

[+] SIEM Field Logic for Splunk Environments:

// Identification of suspicious outbound TFTP activity from switch management addresses
index=firewall sourcetype=pan:traffic dest_port=69 protocol=udp direction=outbound
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_port
| where count > 1
| eval alert_description="Potential Zyxel Switch Exploitation Payload Retrieval"

// Detection of unauthorized access to Veeam Endpoint Backup service logs
index=wineventlog EventCode=4663 ObjectName="*Svc.VeeamEndpointBackup.log*" AccessMask=0x1
| eval Process=ProcessName, User=SubjectUserName
| where not match(User, "(?i)SYSTEM")
| stats count by _time, ComputerName, User, Process, ObjectName
| eval alert_description="Potential Veeam Session UID Extraction Attempt"

// Detection of unauthorized administrative access attempts on Cisco ISE nodes
index=cisco_ise sourcetype=cisco:ise:admin
| search action="LOGIN_SUCCESS" AND NOT src_ip IN ("10.0.0.0/8", "172.16.0.0/12", "192.168.0.0/16")
| stats count by _time, src_ip, user, endpoint
| eval alert_description="Anomalous Cisco ISE Remote Authentication Success"

[+] T1190 Exploit Public Facing Application:
Observed directly in the unauthenticated network exploitation of Zyxel GS1900 CGI programs under CVE-2026-7273 and remote authentication bypass on Cisco Identity Services Engine web consoles under CVE-2026-76460. Defenses should implement strict network layer access control lists restricting management consoles to dedicated out of band administrative subnets.

[+] T1195.002 Compromise Software Supply Chain:
Exemplified by the Jade Sleet intrusion manipulating developer Terraform lock files to pull backdoored packages, as well as the Brevo Cloudflare key theft injecting malicious ClickFix scripts into customer websites. Mitigate by deploying cryptographic artifact signature verification and continuous software dependency audits.

[+] T1203 Exploitation for Client Execution:
Demonstrated by the BlueMoon framework chaining Google Chrome V8 memory corruption under CVE-2026-85046 and WebAssembly sandbox escape under CVE-2026-87491 to achieve client code execution during drive by browsing. Enforce rapid browser patch cycles and browser isolation technologies.

[+] T1068 Exploitation for Privilege Escalation:
Documented across the Microsoft Windows kernel ALPC vulnerability CVE-2026-85880, Linux kernel subsystems CVE-2025-39682, CVE-2026-53266, CVE-2025-39964, and the Veeam Agent session token hijacking flaw CVE-2026-32996. Mitigate through kernel privilege separation, endpoint hardening, and rapid security update distribution.

[+] T1053.005 Scheduled Task Persistence:
Employed by the CLEANGULP backdoor establishing a scheduled task labeled MicrosoftIME to guarantee persistent execution following operating system reboots. Defenders should deploy behavior monitoring to alert on scheduled task creation pointing to non standard executable locations in user profiles.

[+] T1036.005 Masquerading Match Legitimate Name or Location:
Evidenced by CLEANGULP establishing execution binaries inside %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe to blend in with official Microsoft Input Method Editor system utilities. Mitigate by restricting unsigned executable binaries from launching directly out of user writable application data paths.

[+] T1567 Exfiltration Over Web Service:
Observed in the Zyxel campaign staging exfiltrated switch data to web accessible paths for subsequent HTTP retrieval, and in Jade Sleet utilizing public Telegram Bot APIs and Nostr relays for outbound command and control communication. Monitor perimeter gateways for anomalous connections to public application programming interfaces from server subnets.

Chapter 05 - Governance, Risk & Compliance

[+] Regulatory and Compliance Directives:
United States federal agencies operate under Binding Operational Directive 26 04, which establishes an enforceable deadline of September 24 2026 to inventory, triage, and remediate all Zyxel GS1900 series switches. Non compliance exposes entities to administrative intervention and funding sanctions. Furthermore, the active exploitation of Linux kernel vulnerabilities was subjected to Binding Operational Directive 22 01, where emergency deadlines have elapsed, requiring immediate verification.

[+] International Breach Notification Obligations:
Organizations operating within the European Union subject to NIS2 guidelines must treat the unauthenticated compromise of network switching and identity infrastructure as significant cybersecurity incidents, triggering mandatory early warning notifications within 24 hours. The exfiltration of hashed administrative credentials and configuration data from governmental and commercial entities engages European Union General Data Protection Regulation Article 33 requirements, mandating supervisory authority notification within 72 hours if personal data exposure is identified. In India, cyber security incident directions issued by CERT In establish mandatory reporting within six hours for system intrusions and supply chain compromises.

[+] Business and Operational Risk Posture:
The simultaneous weaponization of network appliances, client side browser engines, and administrative access control systems represents severe systemic risk. Network switches compromised via CVE-2026-7273 grant attackers permanent network tapping and traffic diversion points, facilitating undetected lateral movement. Similarly, unauthenticated compromise of Cisco Identity Services Engine invalidates existing zero trust architectures, while browser zero day chains compromise high privilege corporate workstations without requiring user interaction.

Chapter 06 - Adversary Emulation

[+] Purple Team Simulation Scenario 1: Zyxel CGI Buffer Overflow Validation
In a dedicated test laboratory environment isolated from production networks, deploy an unpatched Zyxel GS1900 switch running firmware version 2.90(AAHL.1)C0. Using a custom script, simulate the transmission of an oversized HTTP POST request directed to the management CGI endpoint. Verify whether existing network intrusion detection sensors and perimeter firewalls generate alerts on the malformed request, and monitor network segment interfaces for subsequent unauthorized outbound TFTP connections on UDP port 69.

[+] Purple Team Simulation Scenario 2: CLEANGULP Persistence and Masquerading Execution
On an isolated Windows 11 endpoint, execute an administrative PowerShell test script that drops a non malicious, signed test executable into the path %LOCALAPPDATA%\Microsoft\IME\MicrosoftIME.exe. Configure a scheduled task titled MicrosoftIME set to execute the dropped binary at system startup. Verify whether local endpoint detection and response agents flag the execution of an unrecognized executable from this masqueraded user path and whether security information management systems capture event code 4698 alerting on suspicious task registration.

[+] Purple Team Simulation Scenario 3: Veeam Named Pipe Session Hijacking Emulation
Within an isolated domain test environment running Veeam Agent for Microsoft Windows, configure an unprivileged user session. Execute a test utility that reads sample session tokens from the local application log file and attempts transmission across named pipe \\.\pipe\Veeam\VAW\ServiceConnectionPipe. Measure whether host behavioral monitoring rules detect unprivileged processes opening handles to the Veeam service pipe, and validate whether alerts trigger before command execution occurs.

Intelligence Confidence88%

Confidence Assessment Dimension

Weight

Assigned Score

Evaluation Rationale

Official Authoritative Validation

30 Percent

95 out of 100

CISA KEV catalog additions and international government advisories definitively confirm active exploitation across multiple listed vulnerabilities.

Telemetry and Multi Source Corroboration

25 Percent

90 out of 100

GreyNoise, Volexity, Proofpoint, and SentinelOne provide consistent independent telemetry confirming victim counts, exploitation mechanics, and infrastructure.

Technical Reproducibility and Exploit PoC

20 Percent

88 out of 100

Public proof of concept availability, detailed binary reverse engineering, and explicit CVE mappings establish complete technical reproducibility.

Threat Actor Attribution Rigor

15 Percent

75 out of 100

Attribution for North Korean operations is supported by joint advisories; Chinese actor Kapibala and UTA0565 attribution rests on solid operational telemetry but lacks joint state attribution.

Information Completeness and Longevity

10 Percent

80 out of 100

Detailed indicator lists and detection rules exist for primary clusters, with minor gaps in specific victim disclosures for Linux kernel exploitation.

[+] Overall Assessment:
The composite confidence score is calculated at 88 out of 100. This evaluation reflects authoritative confirmation of in the wild exploitation by governmental bodies, extensive corroboration from leading commercial threat intelligence organizations, and granular technical evidence covering malware binaries, network infrastructure, and victimology.