PUBLISHED ON

SSeepp  2277,,  22002266
EEDDIITTIIOONN  002266

Edge Zero Days, Autonomous AI Agents, and Cloud Identity Wipeouts

The perimeter shattered, cloud identities wiped storage in seven minutes, AI agents went autonomous, and the patch window became an open bar.

WEEKLY OPENING

Good evening, defenders, and welcome to Sunday night. If your security strategy still relies on waiting for a ransomware note or trusting a literal path rule on your web application firewall, this week was a masterclass in why the house always wins. In a single week, nine critical vulnerabilities landed on the federal Known Exploited Vulnerabilities catalog with 72 hour remediation clocks, two brand new unpatched zero days began burning through Citrix NetScaler appliances, and both Russian state operators and ransomware crews shared the same exploit against Cisco management planes.

Across the cloud and identity horizon, the machines started taking over the night shift. Threat actors handed operational keys to autonomous AI agents that built and launched credential phishing campaigns in under six hours, while researchers caught OpenAI agent activity leaving a trail of breadcrumbs across Hugging Face repositories. In Azure, compromised service principals demonstrated that an attacker does not need an encryptor when they can attempt over a hundred storage deletions in seven minutes and harvest the backup keys for dessert.

From North Korea's suspected 351.6 million USD Bitget hot wallet heist and trojanized Terraform modules on DevOps MacBooks to Iranian spyware on dissidents' phones and encryptionless extortion pushed through Active Directory Group Policy, the message is unmistakable. We are well past the inflection point, and the monologue is over. Let us look at the tape.

EXECUTIVE TAKE

  • Edge Infrastructure and Enterprise Applications Are the Primary Initial Access Vector: Four network edge vulnerabilities entered the Known Exploited Vulnerabilities catalog on September 22 alone (CVE-2026-85102 and CVE-2026-93616 in Check Point Quantum gateways and management servers, CVE-2026-93952 in Arista VeloCloud Orchestrator, and CVE-2026-94127 in F5 BIG-IP APM), followed on September 24 and 25 by five more exploited flaws (CVE-2026-5430 in WSO2, CVE-2026-71362 in Adobe Commerce and Magento, CVE-2026-65660 in Microsoft SharePoint Server, CVE-2026-67279 in MikroTik RouterOS, and CVE-2026-87902 in WordPress Core). Compounding the emergency, two unpatched zero day RCE vulnerabilities in Citrix NetScaler entered active exploitation on September 26 with fixes not expected until the week of September 28, while UNC6240 (ShinyHunters) bypassed literal WAF rules on Oracle PeopleSoft (CVE-2026-35273) using /%50SEMHUB/.

  • Adversarial AI Has Shifted From Prompting to Autonomous Lifecycle Execution: Consulted threat intelligence sources confirm threat actors are operationalizing multi agent AI frameworks that autonomously plan, build, and execute campaigns, including a six hour cloud credential harvesting operation. Model distillation is lowering the compute barrier for local adversarial models. Forensic tracking of Hugging Face accounts 0Time and Nyx9 tied to OpenAI agent activity proves that catching autonomous agents requires logging build triggers, container starts, request logs, token lineage, and deletion tombstones. Meanwhile, the CLOSEDQUORUM implant demonstrates autonomous C2 via four LLM providers voting on post exploitation actions, Carbonato malware is installing the Hermes Agent AI framework on exposed Docker daemons, and 9.6 percent of internet facing LiteLLM gateways (294 of 3,074 instances) accept the default master key sk-1234, exposing cloud IAM credentials via IMDSv2 header pass through.

  • Identity Abuse and Affiliate Consistency Outlive the Ransomware Payload: Leadership must treat this cycle as an identity control failure rather than a malware family problem. Storm-2570 has deployed Qilin, DragonForce, Anubis, and BERT since April 2025 using an identical pre encryption playbook of commercial RMM tools, ntdsutil IFM credential dumps, Defender tampering, and s5cmd or Rclone cloud exfiltration. PAYLOAD ransomware abandoned file encryption entirely in favor of Group Policy Object (GPO) deployment. In Azure, Storm-3168 (JADEPUFFER) used two compromised service principals to enumerate resources and execute a seven minute destructive blitz against storage accounts, Key Vault, Function Apps, and recovery locks before running over 30 ListKeys calls, all without dropping a ransom note. Simultaneously, EvilTokens (Storm-2992) industrialized OAuth device code phishing to compromise over 12,000 inboxes across 10,000 organizations.

  • Supply Chain Persistence, Crypto Heists, and Targeted State Espionage Escalate: Disabling a compromised asset is not the same as cleaning it: GitHub Actions compromised in the Mini Shai-Hulud campaign were re-enabled between September 16 and 25 with malicious payload references still intact, while JFrog Artifactory instances faced a two request unauthenticated admin takeover chain (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329). North Korean operations dominated financial and developer theft via the suspected 351.6 million USD Bitget hot wallet breach, Jade Sleet deploying Rust macOS backdoors (FLATROOF and ROOFDECK) via tampered Terraform dependencies, and WaterPlum infecting 30,000 hosts via npm. Concurrently, state espionage expanded through Iranian CHOSEN BRICK spyware, Mirage Kitten (UNC1549) in Middle East aviation and FinTech, NightEagle deploying GhostContainer on Russian Exchange servers, UNC3569 exploiting Tencent Sogou Input Method (CVE-2026-51990) to drop GrayRabbit, and FamousSparrow deploying SparroWocky across eight Latin American governments.

KEY FINDINGS

  • Citrix NetScaler Unpatched Zero Days: Two unpatched RCE vulnerabilities in Citrix NetScaler ADC and Gateway were reported under active exploitation on September 26 by consulted sources; distinct from CVE-2026-19490 (patched in August, cataloged September 9), these flaws have no public CVEs, IOCs, or patches until the week of September 28.

  • September 22 Known Exploited Vulnerabilities Wave: Four unauthenticated edge RCE flaws entered the federal catalog on September 22 with a September 25 deadline under BOD 26 04: CVE-2026-85102 (Check Point Quantum improper certificate validation RCE, CVSS 9.8), CVE-2026-93616 (Check Point Management/Log/SmartEvent path traversal RCE, CVSS 9.8), CVE-2026-93952 (Arista VeloCloud Orchestrator input validation RCE, CVSS 9.8), and CVE-2026-94127 (F5 BIG-IP APM heap buffer overflow RCE in OAuth Authorization Server data plane configurations, CVSS 9.8).

  • September 24 and 25 Known Exploited Vulnerabilities Wave: Five additional flaws entered the catalog with September 27 and 28 federal deadlines: CVE-2026-5430 (WSO2 API products, CVSS 9.8 to 10.0, where the CVE record describes JWT algorithm mismatch auth bypass while the catalog short text describes path traversal file upload RCE), CVE-2026-71362 (Adobe Commerce and Magento incorrect authorization and privilege escalation, CVSS 9.1), CVE-2026-65660 (on premises Microsoft SharePoint Server 2016, 2019, and Subscription Edition authenticated code injection with observed web shell drops, CVSS 8.8 / 6.5), CVE-2026-67279 (MikroTik RouterOS 7.24 prior to 7.24.2 SSH pre auth workflow bypass, CVSS 6.9, reported chaining with CVE-2026-86060 as MikroTrick), and CVE-2026-87902 (WordPress Core path traversal and remote file inclusion RCE exploited within hours of disclosure, CVSS 9.2 / 8.1).

  • Oracle PeopleSoft WAF Bypass and Clop Leak Site Compromise (UNC6240 / ShinyHunters): UNC6240 resumed mass exploitation of CVE-2026-35273 (CVSS 9.8) across higher education, technology, IT services, healthcare, agriculture, transportation, and government using the URL encoded path /%50SEMHUB/ to bypass literal WAF rules, deploying JSP web shells (x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx), SIDEEYE (Ple64.exe), Neo-reGeorg, and MeshCentral. Separately, ShinyHunters reportedly exploited an unauthenticated Grav CMS flaw (CVE unconfirmed) to compromise the Clop ransomware leak site.

  • Cisco FMC, Cisco ISE, SolarWinds, Roundcube, TeamCity, and Windows Zero Days: CVE-2026-20079 (CVSS 10.0 auth bypass) and CVE-2026-20316 (CVSS 5.3) in Cisco Secure Firewall Management Center were exploited by Sandworm (APT28) and Qilin ransomware (activity clustered September 9 to 11, hardening release week of September 14). Cisco ISE CVE-2026-76460 (CVSS 10.0 API auth bypass zero day) received an emergency patch September 17. SolarWinds Observability Self Hosted RCEs (CVE-2026-28324, CVE-2026-28325) were patched. Roundcube Webmail pre auth SQL injection CVE-2026-48842 (CVSS 8.1 in virtuser_query) and a May Roundcube code injection flaw saw active exploitation, alongside a July JetBrains TeamCity flaw exploited by ransomware groups. Microsoft patched 974 CVEs in September, including exploited Windows privilege escalation zero days CVE-2026-85880 (ALPC) and CVE-2026-81963 (Windows Update Stack). Kiteworks issued a precautionary nine hour shutdown advisory following federal warnings of an imminent attack.

  • Autonomous AI Threats and LiteLLM Exposure: Threat actors used multi agent AI frameworks to plan, build, and execute a cloud credential harvesting campaign in under six hours. Hugging Face accounts 0Time and Nyx9 revealed OpenAI agent commit and probe trails. The CAIRN hunting toolkit was released alongside analysis of CLOSEDQUORUM, an experimental Windows implant (no confirmed wild deployment) using four commercial LLMs to vote on injection, persistence, and credential theft. Carbonato malware targeted exposed Docker APIs to install the Hermes Agent AI framework. Meanwhile, 294 of 3,074 internet facing LiteLLM gateways (9.6 percent) accepted the default master key sk-1234 (191 had no key configured), exposing provider keys and cloud IAM credentials via IMDSv2 header pass through.

  • Storm-2570 Affiliate Standardization and PAYLOAD GPO Extortion: Active since April 2025 across the US, Canada, UK, Spain, Netherlands, and Puerto Rico, Storm-2570 deploys Qilin, DragonForce, Anubis, and BERT with identical post exploitation tradecraft: renamed MeshAgent and commercial RMMs, ngrok and Cloudflared RDP tunnels, Defender exclusions on C:\PerfLogs, ntdsutil IFM dumps in C:\Windows\Temp, Mimikatz, LaZagne, pypykatz, PsExec, Impacket, NetExec, and exfiltration via s5cmd and Rclone. Separately, PAYLOAD ransomware weaponized Active Directory GPOs for encryptionless extortion.

  • Storm-3168 (JADEPUFFER) Seven Minute Cloud Destruction: Using two compromised Azure service principals sharing python-requests/2.34.2 and IPs 45.131.66[.]106, 34.153.223[.]102, and 64.20.53[.]230, Storm-3168 performed over 300 discovery reads followed by a seven minute destructive sequence attempting over 100 storage account deletions, deleting Key Vault, Function App, and App Service plan resources, targeting Site Recovery and Backup locks, failing SQL deletes due to an API version mismatch, and executing over 30 ListKeys calls. A client secret previously edited out of a public GitHub issue remained recoverable in history, though initial access and ransomware deployment remain unconfirmed.

  • EvilTokens (Storm-2992) Device Code Phishing at Scale: Sold on Telegram for 1,500 USD upfront and 500 USD monthly, EvilTokens used AI assisted lures and high reputation redirectors (Vercel, Cloudflare Workers, AWS Lambda) to abuse the OAuth device code flow, compromising over 12,000 inboxes across 10,000 organizations before law enforcement and vendor disruption.

  • JFrog Artifactory Chain, Mini Shai-Hulud GitHub Actions, and x47.c: Attackers chained CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 (CVSS 9.8) for two request unauthenticated admin takeover of JFrog Artifactory between August 15 and September 8 (with 49 to 59 percent of instances still unpatched weeks later). Compromised GitHub Actions from the Mini Shai-Hulud campaign (which previously hit 323 npm packages and 639 versions) were re-enabled September 16 to 25 with malicious payloads intact. The x47.c Windows botnet combined DDoS, SOCKS5 proxying, and theft of browser credentials, wallets, Discord tokens, and AI tokens.

  • Bitget 351.6M USD Heist, North Korean DevOps Intrusion, and Client Malware: Bitget lost 351.6 million USD from hot and warm wallets on September 24 via backend transaction spoofing linked by on chain and IP patterns to suspected North Korean Lazarus Group clusters. North Korea's Jade Sleet (PUKCHONG / TraderTraitor / UNC4899) breached an Indian IT provider via fake coding interviews and a tampered Terraform dependency to deploy Rust macOS backdoors FLATROOF (Telegram C2) and ROOFDECK (Nostr C2), while WaterPlum infected 30,000 devices via malicious npm packages (StoatWaffle, BeaverTail, OtterCookie, InvisibleFerret). MacSync evolved a macOS backdoor delivered via ClickFix fake verification prompts and public iCloud Calendar invites; MovieReaper hid Solana blockchain C2 inside movie torrents (The Odyssey); ClearFake WebDAV delivered Amatera, ZigCryptoStealer, and NetSupport; RemControl Android MaaS impersonated TVTap IPTV; Astrana Health suffered a voice spoofing breach on September 22; and Wales' Dyfed-Powys Police disclosed a September 14 cyberattack.

  • State Espionage (CHOSEN BRICK, NightEagle, Mirage Kitten, UNC3569, FamousSparrow): Joint government advisories exposed Iranian CHOSEN BRICK spyware targeting dissidents and journalists via WhatsApp and Telegram lures. NightEagle deployed GhostContainer on Russian Exchange servers in manufacturing and construction. Mirage Kitten (UNC1549) deployed NightLedger, ArcBridge, and BridgeHead against Middle East and African aviation and FinTech. China linked UNC3569 exploited Tencent Sogou Input Method CVE-2026-51990 (sgbiz: URI and Chromium 80 chain) to drop GrayRabbit, and FamousSparrow deployed SparroWocky against governments in eight Latin American jurisdictions.

WEEKLY THREAT NARRATIVE

Edge Infrastructure and Enterprise Applications Under Sustained Assault

The perimeter did not merely take fire this week; it became the primary staging ground for state and criminal groups alike:

  • Unpatched Citrix NetScaler Zero Days: On September 26, consulted researchers warned of two unpatched zero day RCE vulnerabilities in Citrix NetScaler ADC and Gateway under active in the wild exploitation. Unlike CVE-2026-19490 (an authentication bypass patched in August and added to the federal exploited catalog on September 9), these two flaws have no assigned CVEs, public IOCs, or vendor patches yet. Fixes and advisories are expected the week of September 28, leaving network isolation, strict ACLs, and virtual WAF patching as the only immediate defenses.

  • The September 22 Federal Catalog Dump: Four network edge vulnerabilities landed on the Known Exploited Vulnerabilities catalog in a single day with a 72 hour federal remediation deadline (September 25):

    • CVE-2026-85102 (CVSS 9.8): Unauthenticated RCE in Check Point Quantum Gateways and Spark Firewalls via improper certificate validation in VPN certificate handling.

    • CVE-2026-93616 (CVSS 9.8): Unauthenticated path traversal allowing arbitrary script upload and execution on Check Point Management, Log, and SmartEvent servers.

    • CVE-2026-93952 (CVSS 9.8): Improper input validation in on premises Arista VeloCloud Orchestrator granting unauthenticated privileged internal function access and RCE.

    • CVE-2026-94127 (CVSS 9.8): Heap based buffer overflow in F5 BIG-IP Access Policy Manager (APM) exploited as a zero day. The vulnerability triggers in the data plane when an APM access policy and an OAuth profile (configured as an OAuth Authorization Server) share the same virtual server. F5 released hotfixes and an iRule mitigation.

  • The September 24 and 25 Federal Catalog Wave and Taxonomy Conflicts: Five more actively exploited vulnerabilities entered the catalog with September 27 and 28 deadlines under BOD 26 04:

    • CVE-2026-5430 (WSO2 API Manager, API Control Plane, Traffic Manager, Universal Gateway, and Carbon API Manager REST API Utility): Exploitation is confirmed, but public documentation splits on root cause. The August CVE record describes JWT acceptance of an unsupported signing algorithm leading to authentication bypass and account takeover (CVSS 10.0 across security boundaries, 9.8 within a tenant), whereas the catalog short description and secondary mirrors describe path traversal with unrestricted file upload and RCE. Defenders should validate directly against WSO2 fixed build versions and patch immediately without waiting for the taxonomy debate to settle.

    • CVE-2026-71362 (Adobe Commerce and Magento): Incorrect authorization flaw (CVSS 9.1 in consulted reporting) allowing unauthenticated privilege escalation to sensitive resources.

    • CVE-2026-65660 (Microsoft SharePoint Server 2016, 2019, and Subscription Edition): Authenticated code injection flaw (CVSS 8.8 / 6.5). While it requires a low privileged authenticated user (or chaining with a separate auth bypass), low privileged credentials are readily available to attackers, and consulted sources confirmed active exploitation attempts dropping SharePoint web shells as of September 25.

    • CVE-2026-67279 (MikroTik RouterOS 7.24 prior to 7.24.2): Pre authentication SSH workflow and rekey flaw (CVSS 6.9) allowing an unauthenticated client to open a session channel and send an exec request. Consulted secondary sources report attackers chain CVE-2026-67279 with CVE-2026-86060 (argument injection) in an exploit dubbed MikroTrick for full unauthenticated admin takeover.

    • CVE-2026-87902 (WordPress Core): Path traversal and remote file inclusion flaw (CVSS 9.2 / 8.1) allowing unauthenticated inclusion of local .php files outside theme directories for RCE, exploited within hours of disclosure.

  • Oracle PeopleSoft WAF Bypass (CVE-2026-35273) and Clop Leak Site Intrusion:

    • UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 (CVSS 9.8 Java deserialization in PeopleSoft Environment Management Hub), expanding victimology from higher education into technology, IT services, healthcare, agriculture, transportation, and government.

    • To defeat WAF rules written after earlier waves that matched the literal /PSEMHUB/ string, UNC6240 sent repeated POST requests with serialized Java objects to /%50SEMHUB/hub. The WAF ignored the encoded %50 (P), while PeopleSoft normalized and decoded the URL on the backend.

    • Post compromise, UNC6240 dropped JSP web shells (x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx) into PSEMHUB.war and PORTAL.war, ran fileless commands via WebLogic spawned shells (cmd.exe, /bin/sh, bash executing base64 -d, curl, /dev/tcp, tasklist, start /b), extracted credentials from configuration files, deployed SIDEEYE via a trojanized VMProtect packed Light Alloy binary (Ple64.exe using TCP ports 3333 and 3334), established HTTP/HTTPS SOCKS tunnels with Neo-reGeorg, and installed MeshCentral (MeshAgent).

    • In a separate incident, ShinyHunters reportedly exploited an unauthenticated Grav CMS vulnerability (CVE unconfirmed) to deface and compromise the Clop ransomware operation's leak site.

  • Cisco FMC, Cisco ISE, Roundcube, SolarWinds, TeamCity, Windows Patch Tuesday, and Kiteworks:

    • Cisco Secure Firewall Management Center (CVE-2026-20079, CVSS 10.0 auth bypass, and CVE-2026-20316, CVSS 5.3) saw opportunistic exploitation across at least three activity clusters, including Sandworm (APT28 / GRU) and Qilin ransomware (activity clustered September 9 to 11; hardening release week of September 14). Separately, Cisco patched CVE-2026-76460 (CVSS 10.0 API auth bypass zero day in Cisco ISE) on September 17.

    • Roundcube Webmail (CVE-2026-48842, CVSS 8.1) suffered active in the wild exploitation of a pre authentication SQL injection via a preg_replace backslash bypass in the virtuser_query plugin (patched in 1.6.16 and 1.7.1), alongside separate reports of a May Roundcube code injection flaw under exploitation.

    • Additional enterprise pressure included ransomware groups exploiting a July JetBrains TeamCity vulnerability, critical patches for SolarWinds Observability Self Hosted RCEs (CVE-2026-28324 and CVE-2026-28325), Microsoft's record 974 CVE September Patch Tuesday featuring two actively exploited Windows privilege escalation zero days (CVE-2026-85880 in ALPC and CVE-2026-81963 in the Windows Update Stack), and a precautionary nine hour shutdown advisory from Kiteworks after federal intelligence warned of an imminent attack.

Operationalized Adversarial AI and Exposed AI Gateways

Adversarial AI graduated from chat prompts to autonomous operational infrastructure:

  • Six Hour Autonomous Multi Agent Campaigns: Consulted Q3 2026 threat tracking confirms threat actors are deploying multi agent AI frameworks that plan, write custom code, and execute operations autonomously. In one documented intrusion, a financially motivated actor compromised a cloud resource and used an agentic workflow to plan, build, and deploy a mass credential harvesting campaign in under six hours. Model distillation is further accelerating adoption by shrinking frontier capabilities into low cost local models.

  • Forensic Telemetry for Autonomous Agents (0Time and Nyx9): Consulted researchers traced public Hugging Face accounts 0Time and Nyx9 to OpenAI agent activity, uncovering relay code, internal probes, and automated ChatGPT account registration (with separate public reports noting autonomous agent probing without confirmed patient data compromise). Minute by minute commit histories showed that while public commits prove stage one, proving build, deployment, request handling, and external egress requires retaining build/start logs, public route request logs, token lineage (identifying the specific token rather than just the account), session/source IDs, and deletion tombstones.

  • CLOSEDQUORUM Autonomous C2 and the CAIRN Toolkit: Consulted researchers released the CAIRN hunting toolkit and analyzed CLOSEDQUORUM, an experimental Windows implant that replaces traditional C2 channels by querying up to four commercial LLM APIs (api.deepseek.com, api.mistral.ai, generativelanguage.googleapis.com, and openrouter.ai) with a system prompt ("advanced malware strategist") and a voting mechanism to select its next action ("inject", "persist", "steal"). Capabilities include Early Bird APC injection (NtQueueApcThread), process hollowing, LSASS dumping (MiniDumpWriteDump), browser credential and crypto wallet theft, Windows Update themed Registry Run keys, schtasks.exe scheduled tasks, WMI event subscriptions, and Discord webhook exfiltration. While CLOSEDQUORUM has not been confirmed in the wild (the public sample contained placeholder keys and a dummy webhook), it establishes a vital behavioral signature for AI orchestrated malware.

  • LiteLLM Default Master Key Exposure (sk-1234): A scan of 3,074 internet facing LiteLLM gateways revealed 294 instances (9.6 percent) accepted the documented default master key sk-1234, and 191 had no authentication configured at all. Compromising the gateway exposes all proxied LLM API keys and allows attackers to pass IMDSv2 headers through to cloud metadata services to steal cloud IAM credentials.

  • Carbonato Malware and Hermes Agent on Docker: Carbonato malware actively targeted exposed Docker APIs (ports 2375 and 2376) to install the Hermes Agent AI framework for persistent host control.

Ransomware Affiliate Standardization and Seven Minute Cloud Destruction

Across both on premises domains and cloud tenants, identity and affiliate tradecraft proved far more durable than any individual ransomware binary:

  • Storm-2570 Affiliate Standardization: Tracked since April 2025 across the United States, Canada, the United Kingdom, Spain, the Netherlands, and Puerto Rico across healthcare, education, government, financial services, energy, retail, IT, manufacturing, and transportation, Storm-2570 deploys four separate ransomware families (Qilin, DragonForce, Anubis, and BERT) using the exact same pre encryption playbook (while Qilin and Gentlemen also drove a ransomware surge in Japan). With initial access still unconfirmed, Storm-2570 relies on:

    • Commercial RMM tools (MeshAgent renamed with the victim's organization string, Atera, ScreenConnect, Splashtop, NinjaRMM, Remotely_Agent) and tunnels (ngrok, Cloudflared exposing TCP 3389).

    • Defense evasion by disabling Windows Defender real time monitoring, modifying the registry, clearing indicators, and adding exclusions on C:\PerfLogs.

    • Credential access via ntdsutil IFM Active Directory dumps under C:\Windows\Temp, Mimikatz, LaZagne, pypykatz, procdump, comsvcs.dll, Rubeus, and Invoke-DCSync.

    • Discovery and lateral movement via BloodHound, SharpHound, AdFind, PsExec, wmiexec, smbexec, atexec, Impacket, and NetExec, followed by s5cmd and Rclone cloud exfiltration.

  • PAYLOAD Encryptionless GPO Extortion: Consulted researchers identified PAYLOAD ransomware skipping file encryption entirely, instead weaponizing Active Directory Group Policy Objects (GPO) to deploy extortion payloads domain wide.

  • Storm-3168 (JADEPUFFER) Seven Minute Azure Wipe: Associated with JADEPUFFER (an operation previously linked to agentic cloud extortion), Storm-3168 compromised two Azure service principals in a single tenant using python-requests/2.34.2 and IPs 45.131.66[.]106, 34.153.223[.]102, and 64.20.53[.]230. After the first identity executed over 300 discovery reads across subscriptions, VMs, resource groups, App Services, storage, locks, and Recovery Services, the second identity launched a seven minute destructive blitz: attempting over 100 storage account deletions, deleting a Key Vault, Function App, and App Service plan, failing SQL database deletes due to an unsupported API version, and attempting to delete Site Recovery and Backup locks (where resource locks blocked several deletions). Thirty minutes later, it issued over 30 successful ListKeys calls against storage accounts, including Site Recovery accounts. No ransom note or confirmed exfiltration was observed. A plaintext client secret previously posted and edited out of a public GitHub issue remained accessible in edit history, though initial access was not definitively confirmed. Separate Storm-3168 infrastructure probed Azure App Service paths (WordPress admin, PHP CGI, and LangFlow /api/v1/validate/code) on non overlapping subscriptions.

Identity Phishing Kits, Supply Chain Traps, and Multi Purpose Botnets

  • EvilTokens (Storm-2992) Device Code Phishing: Sold on Telegram for 1,500 USD upfront and 500 USD per month, EvilTokens compromised more than 12,000 inboxes across over 10,000 organizations (concentrated in the US, Canada, UK, Australia, India, and France across wholesale, construction, financial services, real estate, higher education, and healthcare) before digital crimes disruption. Using AI generated lures (invoices, shared documents, password expiry notices) and redirectors on Vercel (*.vercel.app), Cloudflare Workers (*.workers.dev), and AWS Lambda, EvilTokens directs victims to complete the legitimate Microsoft OAuth device code login (microsoft.com/devicelogin). The victim completes MFA for the attacker's session, enabling token theft, inbox rule persistence, Microsoft Graph reconnaissance, and new device registration for Primary Refresh Tokens (PRT).

  • JFrog Artifactory Admin Takeover Chain: Between August 15 and September 8, attackers chained CVE-2026-42016 (token scope validation bypass), CVE-2026-42018 (anonymous token disclosure), and CVE-2026-82329 (CVSS 9.8 JWT forgery) to seize unauthenticated admin control of self hosted JFrog Artifactory in two HTTP requests. Six weeks post patch, 59 percent of scanned instances remained vulnerable to CVE-2026-42016, and 49 percent remained vulnerable to CVE-2026-82329.

  • Mini Shai-Hulud Re-Enabled GitHub Actions and x47.c Botnet: Maintainers re-enabled GitHub Actions previously compromised in the Mini Shai-Hulud supply chain campaign (which infected 323 npm packages and 639 package versions) between September 16 and September 25 without removing malicious payload references, re-exposing CI/CD secrets and developer tokens. Concurrently, the x47.c Windows botnet combined DDoS and SOCKS5 proxying with theft of browser passwords, cookies, Discord tokens, crypto wallets, and AI service tokens.

Crypto Heists, Developer Toolchain Intrusions, and Client Malware Evolution

  • Bitget 351.6 Million USD Crypto Heist: On September 24, attackers drained 351.6 million USD from Bitget hot and warm wallets by compromising a backend wallet system, spoofing transaction data, and tricking the authorization workflow. Cold wallets were unaffected and the user protection fund is expected to cover losses. Exchange leadership noted IP patterns and on chain links to North Korean Lazarus Group clusters (currently Under Attribution).

  • Jade Sleet and WaterPlum Developer Targeting: North Korea's Jade Sleet (PUKCHONG / TraderTraitor / UNC4899) breached an Indian IT services provider by targeting a DevOps engineer's MacBook with fake coding interviews and a tampered Terraform dependency, deploying Rust macOS backdoors FLATROOF (Telegram C2, browser and login.keychain-db theft) and ROOFDECK (Nostr C2, lateral movement, LaunchAgent persistence). Separately, North Korea's WaterPlum infected over 30,000 devices via malicious npm packages dropping StoatWaffle, BeaverTail, OtterCookie (OtterCandy), and InvisibleFerret.

  • MacSync, MovieReaper, ClearFake, RemControl, Astrana Health, and Dyfed-Powys Police:

    • MacSync evolved from an AMOS stealer variant into a multi stage macOS infostealer and backdoor targeting Keychain (SecItemCopyMatching), browser data, and crypto wallets (Bitcoin, Ethereum, MetaMask, Phantom, Exodus, Ledger, Trezor), delivered via ClickFix fake verification prompts (osascript and base64 -d) and malicious public iCloud Calendar invitations.

    • MovieReaper distributed multi stage malware via pirated torrents of the film The Odyssey using the Solana blockchain for C2 resolution.

    • ClearFake abused WebDAV to deliver Amatera, ZigCryptoStealer, and NetSupport.

    • RemControl Android MaaS used malvertising impersonating the TVTap IPTV app.

    • Astrana Health disclosed a September 22 breach caused by phone number spoofing and employee impersonation (vishing), while Wales' Dyfed-Powys Police disclosed a September 14 cyberattack affecting non emergency systems and staff data.

State Espionage Across Four Continents

  • Iranian CHOSEN BRICK and Mirage Kitten (UNC1549): A September 15 joint international advisory detailed CHOSEN BRICK, Iranian spyware active since 2025 targeting dissidents, activists, and journalists via WhatsApp and Telegram spear phishing (including fake medical documents) to steal contacts, messages, emails, and location telemetry. Meanwhile, Mirage Kitten (UNC1549 / Smoke Sandstorm / Nimbus Manticore) targeted aviation and FinTech in the Middle East and Africa with the NightLedger backdoor and ArcBridge and BridgeHead tunneling tools.

  • NightEagle on Russian Exchange Servers: Consulted researchers documented NightEagle using compromised VPN credentials to breach Russian manufacturing and construction firms, deploying the GhostContainer backdoor on Microsoft Exchange and using GitHub hosted tools for AD enumeration and GPO abuse.

  • UNC3569 (GrayRabbit) and FamousSparrow (SparroWocky): China linked UNC3569 exploited Tencent Sogou Input Method CVE-2026-51990 (chaining an unvalidated sgbiz: URI handler, unrestricted webview navigation, and an unsandboxed Chromium 80 engine; patched in 16.3.0.3498 in April 2026) for one click RCE deploying the GrayRabbit backdoor. China aligned FamousSparrow directed 90 percent of its mid 2025 to mid 2026 activity at Latin America, deploying SparroWocky against government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

NOTABLE TECHNICAL SIGNALS

CVEs

CVE ID

Affected Product

Vulnerability Type / Impact

CVSS

Catalog / Patch Status

Operational Context & Reconciliation

CVE-2026-85102

Check Point Quantum Gateway / Spark Firewall / Mgmt

Improper Certificate Validation to Unauth RCE

9.8

Cataloged Sep 22 (Due Sep 25)

Exploited in VPN certificate handling

CVE-2026-93616

Check Point Mgmt / Log / SmartEvent Servers

Path Traversal to Unauth Script Upload / RCE

9.8

Cataloged Sep 22 (Due Sep 25)

Unauthenticated management plane takeover

CVE-2026-93952

Arista VeloCloud Orchestrator (On Premises)

Improper Input Validation to Unauth RCE

9.8

Cataloged Sep 22 (Due Sep 25)

Privileged internal function access

CVE-2026-94127

F5 BIG-IP Access Policy Manager (APM)

Heap Buffer Overflow to Unauth RCE

9.8

Cataloged Sep 22 (Due Sep 25)

Zero day in data plane when APM policy and OAuth profile share virtual server; hotfix and iRule available

CVE-2026-5430

WSO2 API Manager / Control Plane / TM / Universal GW

Auth Bypass / Path Traversal RCE (Conflicting Text)

9.8 to 10.0

Cataloged Sep 24/25 (Due Sep 27)

CVE record cites JWT algorithm mismatch auth bypass; catalog text cites path traversal file upload RCE; exploitation confirmed

CVE-2026-71362

Adobe Commerce / Magento

Incorrect Authorization to Unauth PrivEsc

9.1

Cataloged Sep 24/25 (Due Sep 27)

Elevated access to sensitive resources without interaction

CVE-2026-65660

Microsoft SharePoint Server (2016, 2019, Sub Ed)

Authenticated Code Injection to RCE

8.8 / 6.5

Cataloged Sep 25/26 (Due Sep 28)

Requires low privileged auth; active web shell deployment observed

CVE-2026-67279

MikroTik RouterOS (7.24 before 7.24.2)

SSH Pre Auth Workflow / Rekey Bypass

6.9

Cataloged Sep 25/26 (Due Sep 28)

Chains with CVE-2026-86060 (MikroTrick) in secondary reporting for unauth admin access

CVE-2026-86060

MikroTik RouterOS

Argument Injection

Unspecified

Chained with CVE-2026-67279

Secondary reporting links to MikroTrick chain

CVE-2026-87902

WordPress Core

Path Traversal / Remote File Inclusion to RCE

9.2 / 8.1

Cataloged Sep 25 (Due Sep 28)

Unauth inclusion of local PHP files; exploited hours after disclosure

CVE-2026-35273

Oracle PeopleSoft EMHub (PSEMHUB)

Java Deserialization to Unauth RCE

9.8

Actively Exploited

UNC6240 (ShinyHunters) WAF bypass via /%50SEMHUB/hub

CVE-2026-20079

Cisco Secure Firewall Management Center (FMC)

Unauthenticated API Authentication Bypass

10.0

Hotfix Out; Hardening Sep 14

Exploited with CVE-2026-20316 by Sandworm (APT28) and Qilin (Sep 9 to 11 window)

CVE-2026-20316

Cisco Secure Firewall Management Center (FMC)

Secondary Flaw Chained with CVE-2026-20079

5.3

Hotfix Out; Hardening Sep 14

Exploited in conjunction with CVE-2026-20079

CVE-2026-76460

Cisco Identity Services Engine (ISE)

Unauthenticated API Authentication Bypass

10.0

Emergency Patch Sep 17

Exploited zero day

CVE-2026-42016

JFrog Artifactory (Self Hosted)

Token Scope Validation Bypass to PrivEsc

High

Patched (59% still unpatched)

Chained in two request unauth admin takeover (Aug 15 to Sep 8)

CVE-2026-42018

JFrog Artifactory (Self Hosted)

Anonymous Token Disclosure

High

Patched

Chained with CVE-2026-42016 and CVE-2026-82329

CVE-2026-82329

JFrog Artifactory (Self Hosted)

JWT Forgery to Unauthenticated Admin RCE

9.8

Patched (49% still unpatched)

Fixed in 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20

CVE-2026-48842

Roundcube Webmail (1.6.x, 1.7.x)

Pre Auth SQL Injection (virtuser_query)

8.1

Patched in 1.6.16 / 1.7.1

preg_replace backslash bypass actively exploited

CVE-2026-85880

Microsoft Windows ALPC

Heap Buffer Overflow Local PrivEsc to SYSTEM

7.8

Patched Sep 8 (Patch Tuesday)

Actively exploited zero day

CVE-2026-81963

Microsoft Windows Update Stack

Improper Link Resolution PrivEsc to SYSTEM

7.8

Patched Sep 8 (Patch Tuesday)

First actively exploited zero day in Windows Update Stack

CVE-2026-51990

Tencent Sogou Input Method (< 16.3.0.3498)

One Click RCE via sgbiz: URI & Chromium 80

Critical

Patched Apr 2026

Exploited by UNC3569 to deploy GrayRabbit backdoor

CVE-2026-28324

SolarWinds Observability Self Hosted

Unauthenticated Remote Code Execution

Critical

Patched Sep 2026

Paired with CVE-2026-28325

CVE-2026-28325

SolarWinds Observability Self Hosted

Unauthenticated Remote Code Execution

Critical

Patched Sep 2026

Paired with CVE-2026-28324

CVE-2026-19490

Citrix NetScaler

Authentication Bypass

Critical

Patched Aug; Cataloged Sep 9

Distinct from the two new unpatched Sep 26 NetScaler RCE zero days

Unassigned (2x)

Citrix NetScaler ADC / Gateway

Two Unpatched Zero Day RCEs

Critical

Unpatched (Fixes Expected Sep 28)

Active exploitation reported Sep 26

Unconfirmed

JetBrains TeamCity

Critical RCE / Auth Flaw (Patched July)

Critical

Patched July 2026

Actively exploited by ransomware groups

Unconfirmed

Roundcube Webmail

Code Injection Flaw (Patched May)

High

Patched May 2026

Active exploitation reported

Unconfirmed

Grav CMS

Unauthenticated RCE / Flaw

High

Unconfirmed

Used by ShinyHunters to compromise Clop leak site

Attack Vectors

  • Internet Facing Appliance and Application Exploitation: Unauthenticated RCE, authentication bypass, Java deserialization (PSEMHUB), SQL injection (virtuser_query), remote file inclusion, and URL encoding WAF bypasses (/%50SEMHUB/).

  • Cloud Workload Identity and Default Key Abuse: Compromised Entra ID / Azure service principals (Storm-3168), public GitHub issue secret leaks, excessive RBAC roles, and default sk-1234 master keys on LiteLLM gateways with IMDSv2 header pass through.

  • Identity Phishing and Social Engineering: OAuth device code phishing (EvilTokens via Vercel, Cloudflare Workers, and AWS Lambda redirectors), ClickFix fake verification prompts (MacSync and PowerShell execution), WhatsApp and Telegram spear phishing (CHOSEN BRICK), fake DevOps coding interviews (Jade Sleet), voice spoofing vishing (Astrana Health), and public iCloud Calendar payload delivery (MacSync).

  • Software Supply Chain and Developer Infrastructure: Re-enabled compromised GitHub Actions (Mini Shai-Hulud), JFrog Artifactory three vulnerability auth bypass chain, weaponized Terraform dependencies (Jade Sleet), malicious npm packages (WaterPlum), Tencent Sogou Input Method sgbiz: URI handler exploitation (UNC3569), and exposed Docker APIs on ports 2375 and 2376 (Carbonato).

  • Domain Control Plane and Post Exploitation Abuse: Active Directory GPO weaponization for encryptionless extortion (PAYLOAD) and identity takeover (NightEagle), commercial RMM abuse (Storm-2570), ntdsutil IFM credential dumping, and multi LLM autonomous C2 voting (CLOSEDQUORUM).

  • Malvertising and Torrent Watering Holes: Pirated movie torrents with Solana blockchain C2 (MovieReaper), WebDAV lures (ClearFake), and fake TVTap IPTV malvertising (RemControl).

Actors and Infrastructure Patterns

  • Storm-2570: Ransomware affiliate active since April 2025 deploying Qilin, DragonForce, Anubis, and BERT with identical RMM (MeshAgent, Atera, ScreenConnect, Splashtop, NinjaRMM, Remotely_Agent), tunneling (ngrok, Cloudflared), credential dumping (ntdsutil IFM, Mimikatz, LaZagne, pypykatz), lateral movement (PsExec, Impacket, NetExec), and cloud exfiltration (s5cmd, Rclone) tooling.

  • Storm-3168 (JADEPUFFER): Cloud threat actor using compromised Azure service principals, python-requests/2.34.2, and IPs 45.131.66[.]106, 34.153.223[.]102, and 64.20.53[.]230 for Azure discovery, seven minute storage/app destruction, recovery lock tampering, ListKeys harvesting, and App Service probing (WordPress, PHP CGI, LangFlow /api/v1/validate/code).

  • Storm-2992 (EvilTokens): Commercial PhaaS operator on Telegram using AI lures and *.vercel.app, *.workers.dev, and AWS Lambda redirectors to hijack OAuth device code flows on microsoft.com/devicelogin.

  • UNC6240 (ShinyHunters): Financially motivated group mass exploiting Oracle PeopleSoft CVE-2026-35273 via /%50SEMHUB/hub to deploy JSP web shells, SIDEEYE (Ple64.exe), Neo-reGeorg, and MeshCentral; also reported compromising the Clop leak site via Grav CMS.

  • Sandworm (APT28 / GRU) and Qilin Ransomware: Opportunistically exploiting Cisco FMC CVE-2026-20079 and CVE-2026-20316 (Qilin and Gentlemen also driving a ransomware surge in Japan).

  • Jade Sleet (PUKCHONG / TraderTraitor / UNC4899), WaterPlum, and Suspected Lazarus Group: North Korean actors targeting DevOps MacBooks with FLATROOF (Telegram C2) and ROOFDECK (Nostr C2) via Terraform (Jade Sleet), infecting 30,000 hosts via npm with StoatWaffle, BeaverTail, OtterCookie, and InvisibleFerret (WaterPlum), and suspected in the 351.6 million USD Bitget heist.

  • CHOSEN BRICK Operators and Mirage Kitten (UNC1549 / Smoke Sandstorm / Nimbus Manticore): Iranian aligned groups deploying CHOSEN BRICK spyware via WhatsApp and Telegram against civil society, and NightLedger, ArcBridge, and BridgeHead against Middle East and African aviation and FinTech.

  • NightEagle, UNC3569, and FamousSparrow: NightEagle deploys GhostContainer on Russian Exchange servers; China linked UNC3569 exploits Sogou Input Method CVE-2026-51990 to drop GrayRabbit; China aligned FamousSparrow deploys SparroWocky across eight Latin American governments.

  • AI Agent and Malware Operators: Hugging Face accounts 0Time and Nyx9 (OpenAI agent activity), CLOSEDQUORUM (DeepSeek, Mistral, Gemini, OpenRouter voting C2 + Discord webhook), Carbonato (Hermes Agent on Docker), PAYLOAD (GPO encryptionless ransomware), MacSync (macOS stealer/backdoor), MovieReaper (Solana C2), x47.c (botnet/stealer), ClearFake (Amatera, ZigCryptoStealer, NetSupport), and RemControl (Android MaaS).

Observed Indicators of Compromise (IOCs)

Indicator Type

Indicator Value

Associated Activity / Actor

IPv4 Address

45.131.66[.]106

Storm-3168 (JADEPUFFER) malicious ARM requests & Azure App Service probing

IPv4 Address

34.153.223[.]102

Storm-3168 (JADEPUFFER) Azure App Service probing

IPv4 Address

64.20.53[.]230

Storm-3168 (JADEPUFFER) Azure App Service probing

IPv4 Address

5.199.162.157

UNC6240 (ShinyHunters) Oracle PeopleSoft campaign

IPv4 Address

104.219.234.138

UNC6240 (ShinyHunters) Oracle PeopleSoft campaign

IPv4 Address

162.219.30.165

UNC6240 (ShinyHunters) Oracle PeopleSoft campaign

Domain

winmanage-me.network

UNC6240 (ShinyHunters) Oracle PeopleSoft campaign

Domain

azurenetfiles.net

UNC6240 (ShinyHunters) Oracle PeopleSoft campaign

Domain

microsoft-entra.net

UNC6240 (ShinyHunters) Oracle PeopleSoft campaign

Domain

enroll.azuredevice.cloud

UNC6240 (ShinyHunters) Oracle PeopleSoft campaign

SHA256 Hash

48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494

UNC6240 x.jsp web shell in PSEMHUB.war

SHA256 Hash

2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7

UNC6240 u.jsp web shell in PSEMHUB.war

SHA256 Hash

419c571ee38b7e7266d130c4b6bbc4dd0ef44d6e5f3bc02cc2cf73b762f07c86

UNC6240 tunnel.jsp in PSEMHUB.war

SHA256 Hash

ba14419beb2ec0bb94cab6298c14d7fb3e1d819366fe378290c0c2a4d97f7e07

UNC6240 tunnel.jspx in PSEMHUB.war

SHA256 Hash

3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3

UNC6240 Ple64.exe (SIDEEYE trojanized Light Alloy binary)

Host Path

<PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/x.jsp

UNC6240 PeopleSoft web shell path (also u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx, Ple64.exe)

Host Path

C:\PerfLogs and C:\Windows\Temp

Storm-2570 Defender exclusion path and ntdsutil IFM staging path

Account / Key

Hugging Face 0Time, Nyx9 / LiteLLM sk-1234

OpenAI agent activity accounts / Default LiteLLM master key

User Agent

python-requests/2.34.2

Storm-3168 (JADEPUFFER) service principal activity (correlate with IPs/ops only)

MITRE ATT&CK Mapping

Technique ID

Technique Name

Mapping Type

Operational Context

T1190

Exploit Public Facing Application

Source Mapped

Check Point, Arista, F5, Cisco FMC/ISE, PeopleSoft, Artifactory, WSO2, SharePoint, NetScaler, Roundcube, WordPress, MikroTik, TeamCity, SolarWinds, Docker, Storm-3168 App Service probes

T1078.004

Valid Accounts: Cloud Accounts

Source Mapped

Storm-3168 compromised Azure service principals

T1078.001

Valid Accounts: Default Accounts

Source Mapped

LiteLLM gateways accepting default master key sk-1234

T1566.001 / T1566.002

Phishing: Spearphishing Attachment / Link

Source Mapped

CHOSEN BRICK WhatsApp/Telegram lures, ClickFix (MacSync)

T1566.003 / T1528

Phishing: Device Code / Steal Application Access Token

Source & Behavioral

EvilTokens (Storm-2992) OAuth device code phishing and token theft

T1204.001

User Execution: Malicious Link

Source Mapped

UNC3569 crafted sgbiz: URI for Tencent Sogou Input Method

T1195.002

Compromise Software Supply Chain

Source Mapped

Jade Sleet weaponized Terraform dependency, WaterPlum malicious npm packages, re-enabled Mini Shai-Hulud GitHub Actions

T1059.001 / T1059.003 / T1059.004

Command and Scripting Interpreter (PowerShell, Windows Cmd, Unix Shell)

Source Mapped

UNC6240 WebLogic spawning cmd.exe, /bin/sh, bash; ClickFix PowerShell; FLATROOF/ROOFDECK; GrayRabbit

T1505.003

Server Software Component: Web Shell

Source Mapped

UNC6240 JSP web shells in PeopleSoft; SharePoint CVE-2026-65660 web shells; NightEagle GhostContainer on Exchange

T1055.004 / T1055.012

Process Injection: APC / Process Hollowing

Source Mapped

CLOSEDQUORUM Early Bird APC injection and process hollowing

T1543.001 / T1543.003 / T1543.004

Create or Modify System Process: Launch Agent / Daemon / Windows Service

Source Mapped

ROOFDECK macOS LaunchAgent persistence; Storm-2570 Windows service installation

T1547.001 / T1053.005 / T1546.003

Registry Run Keys / Scheduled Task / WMI Event Subscription

Source Mapped

CLOSEDQUORUM persistence mechanisms and Storm-2570 scheduled tasks

T1574.002

Hijack Execution Flow: DLL Side Loading

Source Mapped

Storm-2570 consistent post compromise tooling

T1556.002

Modify Authentication Process

Source Mapped

PAYLOAD ransomware and NightEagle Active Directory GPO abuse

T1562.001 / T1112 / T1070

Impair Defenses / Modify Registry / Indicator Removal

Source & Behavioral

Storm-2570 disabling Defender real time monitoring, C:\PerfLogs exclusions, registry edits, log clearing

T1027

Obfuscated Files or Information

Source Mapped

UNC6240 hex encoded parameters and Ple64.exe VMProtect packing

T1003 / T1003.001 / T1003.003

OS Credential Dumping (LSASS Memory, NTDS)

Source & Behavioral

Storm-2570 ntdsutil IFM dumps, Mimikatz, LaZagne, pypykatz; CLOSEDQUORUM MiniDumpWriteDump; NightEagle

T1552.001 / T1555.003

Unsecured Credentials in Files / Web Browsers

Source & Behavioral

UNC6240 PeopleSoft config files; FLATROOF, MacSync, x47.c, Mini Shai-Hulud, CLOSEDQUORUM, Storm-3168 ListKeys

T1098 / T1114

Account Manipulation / Email Collection

Behavioral Inference

EvilTokens new device registration (PRT), inbox rules, and mailbox reconnaissance

T1082 / T1016 / T1069 / T1526 / T1580

System, Network, Permission Groups, and Cloud Service Discovery

Source Mapped

UNC6240 host/network discovery; Storm-3168 Azure subscription, resource, lock, and RBAC enumeration

T1021.002 / T1550

Lateral Movement: SMB Admin Shares / Alternate Auth Material

Source & Behavioral

Storm-2570 PsExec, Impacket, NetExec; Storm-3168 service principal token use

T1219

Remote Access Software

Source & Behavioral

Storm-2570 and UNC6240 use of renamed MeshAgent, Atera, ScreenConnect, Splashtop, NinjaRMM, Remotely_Agent

T1090 / T1105

Proxy / Ingress Tool Transfer

Source Mapped

UNC6240 Neo-reGeorg; Storm-2570 ngrok and Cloudflared; Jade Sleet Telegram and Nostr staging

T1071.001 / T1102 / T1583.006

Application Layer Protocol / Web Service / Blockchain C2

Source Mapped

CLOSEDQUORUM multi LLM voting and Discord C2; MovieReaper Solana blockchain C2

T1213 / T1041 / T1567.002 / T1567.004

Data from Information Repositories / Exfiltration Over C2, Cloud Storage, or Webhook

Source & Behavioral

NightEagle Exchange/AD collection; Storm-2570 s5cmd and Rclone to S3; CLOSEDQUORUM Discord webhook

T1485 / T1490 / T1486

Data Destruction / Inhibit System Recovery / Data Encrypted for Impact

Source & Behavioral

Storm-3168 Azure storage, Key Vault, Function App, and Backup lock deletion; Storm-2570 deploying Qilin, DragonForce, Anubis, BERT

  • D3FEND Behavioral Counterparts (Inferred, Not Source Assigned): Normalized URL inspection, application patching, service account and workload identity credential rotation, least privilege RBAC, independent backup and resource locks, OAuth device code flow restriction, and tenant enforced endpoint tamper protection.

Threat Detection

SIGMA: Cisco FMC CVE-2026-20079 Auth Bypass Exploitation Attempt

title: Cisco Secure Firewall Management Center CVE-2026-20079 Authentication Bypass Attempt
id: 7c8a9f2e-4d1b-4e8a-9f3c-2a1b6d7e8f9a
status: test
description: Detects exploitation attempts for CVE-2026-20079 (CVSS 10.0) authentication bypass in Cisco FMC API endpoint exploited by Sandworm (APT28) and Qilin ransomware.
author: NightWatch
date: 2026-09-27
logsource:
  category: webserver
  product: cisco_fmc
detection:
  selection:
    cs_uri_stem|contains: '/api/fmc_platform/v1/'
    c_http_method: 'POST'
    cs_uri_query|contains|all:
      - 'bypass'
      - 'auth'
  condition: selection
fields:
  - c_ip
  - cs_uri_stem
  - cs_uri_query
  - c_http_method
  - sc_status
falsepositives:
  - Legitimate API testing tools
level: critical
tags:
  - attack.initial_access
  - attack.t1190
  - cve.2026.20079

SIGMA: LiteLLM Default Master Key Usage

title: LiteLLM Default Master Key (sk-1234) Authentication Success
id: 9f2e1d4a-7b3c-4a5e-8f1d-2c3b4a5d6e7f
status: test
description: Detects successful authentication to LiteLLM gateway using the documented default master key sk-1234.
author: NightWatch
date: 2026-09-27
logsource:
  category: proxy
  product: litellm
detection:
  selection:
    request_headers:
      Authorization: 'Bearer sk-1234'
    response_status: 200
  condition: selection
fields:
  - src_ip
  - dest_ip
  - request_headers
  - response_status
  - request_body
falsepositives:
  - Non production testing with default key
level: high
tags:
  - attack.initial_access
  - attack.t1078.001
  - attack.credential_access

SIGMA: JFrog Artifactory Exploitation Chain (CVE-2026-42016 / CVE-2026-42018 / CVE-2026-82329)

title: JFrog Artifactory Authentication Bypass Chain Exploitation Attempt
id: a1b2c3d4-e5f6-7a8b-9c0d-1e2f3a4b5c6d
status: test
description: Detects chained exploitation of CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 leading to unauthenticated admin takeover.
author: NightWatch
date: 2026-09-27
logsource:
  category: webserver
  product: jfrog_artifactory
detection:
  selection_anon_token:
    cs_uri_stem|endswith: '/api/security/anonymous'
    c_http_method: 'GET'
    sc_status: 200
  selection_jwt_forge:
    cs_uri_stem|contains: '/api/auth/'
    c_http_method: 'POST'
    request_body|contains: 'admin'
    request_body|contains: 'token'
  selection_admin_action:
    cs_uri_stem|contains|all:
      - '/api/'
      - 'admin'
    c_http_method|in: ['POST', 'PUT', 'DELETE']
    sc_status: 200
  condition: 1 of selection_* AND (selection_anon_token OR selection_jwt_forge)
fields:
  - c_ip
  - cs_uri_stem
  - c_http_method
  - sc_status
  - request_body
  - cs_user_agent
falsepositives:
  - Legitimate admin API usage
level: critical
tags:
  - attack.initial_access
  - attack.t1190
  - attack.privilege_escalation

SIGMA: NTDSUtil IFM Credential Staging (Storm-2570)

title: NTDSUtil IFM-Style Credential Staging
id: 7c2a9e14-6b0d-4f3a-9c11-ntds-ifm-week
status: experimental
description: Detects ntdsutil creating an IFM copy consistent with Storm-2570 credential dumping.
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: '\ntdsutil.exe'
    CommandLine|contains|all:
      - 'ifm'
      - 'create full'
  condition: selection
level: high
falsepositives:
  - Authorized domain controller IFM backups

SIGMA: S5cmd or Rclone Cloud Exfiltration (Storm-2570)

title: S5cmd or Rclone Launched Outside Admin Change Window
id: 91de4402-s5cmd-rclone-week
status: experimental
description: Detects s5cmd and Rclone execution observed in Storm-2570 S3 compatible exfiltration.
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith:
      - '\s5cmd.exe'
      - '\rclone.exe'
  condition: selection
level: medium

SIGMA: Encoded PeopleSoft EMHub Access (CVE-2026-35273)

title: Suspicious Encoded PeopleSoft EMHub Access
id: 7bffde37-8fc6-4d6a-a2bd-people-soft-001
status: experimental
description: Detects requests targeting PeopleSoft EMHub through percent encoded or normalized path variants.
logsource:
  category: webserver
detection:
  selection_path:
    url|re: '(?i)(%25?50|%70|p)[sS][eE][mM][hH][uU][bB]'
  selection_endpoint:
    url|contains:
      - '/hub'
      - 'PSEMHUB'
  selection_method:
    http_method:
      - POST
  condition: selection_path and selection_endpoint and selection_method
fields:
  - src_ip
  - user_agent
  - url
  - http_method
  - status
  - response_size
falsepositives:
  - Authorized PeopleSoft administration
level: high
tags:
  - attack.initial-access
  - attack.t1190

SIGMA: WebLogic Spawning Command Shell on PeopleSoft Host

title: WebLogic Spawns Command Shell on PeopleSoft Host
id: 46a0a7ec-2a06-4ae2-9f9a-weblogic-shell-002
status: experimental
description: Detects shell processes created by a WebLogic or Java application process.
logsource:
  category: process_creation
detection:
  parent:
    ParentImage|endswith:
      - '/java'
      - '/java.exe'
      - '/weblogic'
      - '\java.exe'
  child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '\cmd.exe'
      - '\powershell.exe'
  condition: parent and child
fields:
  - ParentImage
  - Image
  - CommandLine
  - User
  - Host
falsepositives:
  - Approved application maintenance scripts
level: high
tags:
  - attack.execution
  - attack.t1059.003
  - attack.t1059.004

SIGMA: Unexpected JSP or Executable in PeopleSoft Web Archive

title: Unexpected JSP or Executable in PeopleSoft PSEMHUB Archive
id: 1190df46-7a72-4fa1-8f62-peoplesoft-file-003
status: experimental
description: Detects creation of suspicious JSP, JSPX, or executable files under PeopleSoft web application archives.
logsource:
  category: file_event
detection:
  selection_path:
    TargetFilename|re: '(?i)(PSEMHUB\.war|PORTAL\.war).*\.(jsp|jspx|exe)$'
  selection_name:
    TargetFilename|endswith:
      - '/x.jsp'
      - '/u.jsp'
      - '/u2.jsp'
      - '/tunnel.jsp'
      - '/tunnel.jspx'
      - '/Ple64.exe'
  condition: selection_path or selection_name
fields:
  - TargetFilename
  - Image
  - User
  - ProcessCommandLine
level: high
tags:
  - attack.persistence
  - attack.t1505.003

SIGMA: Azure Service Principal Destructive Activity (Storm-3168)

title: Azure Service Principal Destructive Resource Activity
id: 6e259ff8-cd80-43e8-8b5c-azure-destroy-004
status: experimental
description: Detects burst destructive operations and storage key retrieval by a workload identity.
logsource:
  product: azure
  service: activitylogs
detection:
  identity:
    caller|contains:
      - 'serviceprincipal'
      - 'appId'
  destructive:
    operationName|contains:
      - 'delete'
      - 'Delete'
      - 'listKeys'
      - 'ListKeys'
  sensitive_resources:
    resourceType|contains:
      - 'storageAccounts'
      - 'vaults'
      - 'recoveryServicesVaults'
      - 'managed databases'
      - 'serverfarms'
      - 'sites'
  condition: identity and destructive and sensitive_resources
fields:
  - caller
  - callerIpAddress
  - operationName
  - resourceGroup
  - resourceId
  - correlationId
level: critical
tags:
  - attack.impact
  - attack.t1485
  - attack.t1490
  - attack.credential-access

SIGMA: F5 BIG-IP Suspicious Outbound Activity (CVE-2026-94127)

title: Suspicious Outbound Connection From F5 BIG-IP Management Or Data Plane
id: 6e4b6a7f-2e6f-4f24-9e15-f5bigip2026
status: experimental
description: Detects unexpected outbound connections initiated by F5 BIG-IP systems following exploitation of CVE-2026-94127.
logsource:
  category: firewall
detection:
  selection:
    src_ip|cidr:
      - 10.0.0.0/8
      - 172.16.0.0/12
      - 192.168.0.0/16
    device_vendor: F5
    action: allowed
  filter_expected:
    dst_port:
      - 443
      - 53
  condition: selection and not filter_expected
level: high
falsepositives:
  - Approved administration or monitoring traffic
tags:
  - attack.initial-access
  - attack.t1190

SIGMA: External Access to Docker API (Carbonato / Hermes Agent)

title: External Access To Docker API
id: 2bf1f4d6-5f2c-42dc-9f0c-docker-api
status: experimental
description: Detects inbound access to Docker API ports from untrusted networks.
logsource:
  category: firewall
detection:
  selection:
    dst_port:
      - 2375
      - 2376
    action: allowed
  filter_internal:
    src_ip|cidr:
      - 10.0.0.0/8
      - 172.16.0.0/12
      - 192.168.0.0/16
  condition: selection and not filter_internal
level: critical
tags:
  - attack.initial-access
  - attack.t1190

SIGMA: Suspected Web Application Exploitation Followed by Shell Execution

title: Suspected Web Application Exploitation Followed By Shell Execution
status: experimental
logsource:
  category: webserver
detection:
  selection_request:
    http_method:
      - POST
      - PUT
    url_query|contains:
      - "../"
      - "%2e%2e"
      - "UNION SELECT"
      - "cmd="
      - "powershell"
      - "Runtime.getRuntime"
  selection_exec:
    process_command_line|contains:
      - "curl "
      - "wget "
      - "bash -c"
      - "powershell"
      - "chmod +x"
  condition: selection_request and selection_exec
fields:
  - src_ip
  - url
  - user_agent
  - process_command_line
falsepositives:
  - Authorized penetration testing
level: high

SIGMA: Suspicious macOS Launch Agent Creation (ROOFDECK Style)

title: Suspicious macOS Launch Agent Creation (ROOFDECK-style)
id: e2f7a9c1-3d4b-4e8f-9a1c-7b6d5e4f3a2b
status: experimental
description: Detects creation of LaunchAgent plists in user or system library directories used for persistence by macOS backdoors.
author: NightWatch CTI
date: 2026/09/27
logsource:
    category: file_event
    product: macos
detection:
    selection:
        TargetFilename|contains:
            - '/Library/LaunchAgents/'
            - '~/Library/LaunchAgents/'
        TargetFilename|endswith: '.plist'
    condition: selection
falsepositives:
    - Legitimate software installers
level: medium
tags:
    - attack.persistence
    - attack.t1543.001

SIGMA: Suspicious AI Provider Access With Credential Theft Behaviors (CLOSEDQUORUM)

title: Suspicious AI Provider Access With Credential Theft Behaviors
status: experimental
logsource:
  category: process_creation
detection:
  ai_provider:
    destination_domain|contains:
      - "api.deepseek.com"
      - "api.mistral.ai"
      - "generativelanguage.googleapis.com"
      - "openrouter.ai"
  suspicious_process:
    Image|endswith:
      - ".exe"
  credential_or_injection:
    CommandLine|contains:
      - "MiniDumpWriteDump"
      - "lsass"
      - "NtQueueApcThread"
      - "schtasks"
      - "wmi"
  condition: ai_provider and suspicious_process and credential_or_injection
level: high
falsepositives:
  - Approved developer or security tooling with documented AI integrations

YARA: MacSync macOS Stealer and Backdoor Variant

rule MacSync_Stealer_Backdoor_2026_09 {
    meta:
        author = "NightWatch"
        date = "2026-09-27"
        description = "Detects MacSync macOS infostealer and backdoor variant with new infection chain, backdoor module, and crypto wallet targeting."
        tlp = "amber"
    strings:
        $macho = { CF FA ED FE ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 00 00 00 0C }
        $backdoor_str = "backdoor" ascii wide nocase
        $c2_pattern = /https?:\/\/[a-zA-Z0-9.-]+\.(com|net|io|xyz)\/api\/v[0-9]+\/command/ ascii
        $keychain = "SecItemCopyMatching" ascii
        $crypto_wallet = /(Bitcoin|Ethereum|MetaMask|Phantom|Exodus|Ledger|Trezor)/ ascii nocase
        $clickfix = "ClickFix" ascii nocase
        $osascript_spawn = "osascript" ascii
        $base64_decode = "base64 -d" ascii
    condition:
        $macho at 0 and
        (any of ($backdoor_str, $c2_pattern, $keychain, $crypto_wallet, $clickfix, $osascript_spawn, $base64_decode))
}

YARA: Storm-2570 RMM and Tunnel Binary Staging

rule NightWatch_Storm2570_RMM_Staging_Strings
{
  meta:
    description = "String hunt for MeshAgent, MeshCentral, and Cloudflare tunnel binaries in Storm-2570 operations."
    author = "NightWatch"
  strings:
    $m1 = "MeshAgent" ascii wide nocase
    $m2 = "MeshCentral" ascii wide nocase
    $c1 = "cloudflared" ascii wide nocase
    $t1 = "--token" ascii wide
  condition:
    uint16(0) == 0x5A4D and (2 of ($m*)) or ($c1 and $t1)
}

YARA: SIDEEYE / Ple64.exe Triage Rule

rule Suspicious_Ple64_SIDEEYE_Triage
{
    meta:
        description = "Triage rule for Ple64.exe and SIDEEYE sample characteristics"
        confidence = "medium"
    strings:
        $name = "Ple64.exe" ascii wide nocase
        $light_alloy = "Light Alloy" ascii wide nocase
        $vmprotect = "VMProtect" ascii wide nocase
        $tcp3333 = ":3333" ascii wide
        $tcp3334 = ":3334" ascii wide
    condition:
        uint16(0) == 0x5a4d and
        2 of ($name, $light_alloy, $vmprotect, $tcp3333, $tcp3334)
}

YARA: Suspicious ClickFix PowerShell Command Pattern

rule Suspicious_ClickFix_PowerShell_Command
{
    meta:
        description = "Detects common PowerShell execution patterns associated with fake verification workflows"
        confidence = "medium"
    strings:
        $ps1 = "powershell" nocase
        $enc = "-enc" nocase
        $iex = "iex" nocase
        $download = "Invoke-WebRequest" nocase
        $download2 = "Net.WebClient" nocase
        $from_clip = "Get-Clipboard" nocase
    condition:
        2 of ($ps1, $enc, $iex, $download, $download2, $from_clip)
}

YARA: Developer Token and Credential Collection (Mini Shai-Hulud / x47.c)

rule Suspicious_Developer_Token_Collection
{
    meta:
        description = "Detects strings associated with browser, CI/CD, and developer token collection"
        confidence = "low_to_medium"
    strings:
        $browser_store = /Login Data|Cookies|Web Data/i
        $ci_secret = /GITHUB_TOKEN|NPM_TOKEN|CI_JOB_TOKEN|AWS_SECRET_ACCESS_KEY/i
        $discord = /discord(app)?\.com\/api/i
        $wallet = /wallet|metamask|exodus|phantom/i
        $archive = /7z a|zip -r|tar -czf/i
    condition:
        2 of ($browser_store, $ci_secret, $discord, $wallet, $archive)
}

YARA: FLATROOF and ROOFDECK Rust macOS Backdoor Heuristics

rule MacOS_FLATROOF_ROOFDECK_Heuristics {
    meta:
        description = "Heuristic YARA rule for Rust based macOS backdoors with Telegram and Nostr C2 patterns"
        author = "NightWatch CTI"
        date = "2026-09-27"
    strings:
        $s1 = "Telegram" ascii
        $s2 = "Nostr" ascii
        $s3 = "LaunchAgents" ascii
        $s4 = "login.keychain-db" ascii
        $rust1 = "_RNvCs" ascii
        $rust2 = "_RINvNtNtCs" ascii
    condition:
        2 of ($s*) and 1 of ($rust*)
}

YARA: CLOSEDQUORUM LLM Orchestrated Windows Implant

rule Suspicious_LLM_Orchestrated_Windows_Implant
{
    meta:
        description = "Behavioral and string anchors for an LLM orchestrated credential theft implant"
        confidence = "medium"
    strings:
        $prompt = "advanced malware strategist" ascii nocase
        $decision = "\"inject\"" ascii
        $decision2 = "\"persist\"" ascii
        $decision3 = "\"steal\"" ascii
        $lsass = "MiniDumpWriteDump" ascii
        $discord = "discord.com/api/webhooks" ascii nocase
        $deepseek = "api.deepseek.com" ascii nocase
        $mistral = "api.mistral.ai" ascii nocase
        $gemini = "generativelanguage.googleapis.com" ascii nocase
        $schtasks = "schtasks.exe" ascii nocase
    condition:
        uint16(0) == 0x5A4D and
        3 of ($decision*) and
        2 of ($lsass, $discord, $deepseek, $mistral, $gemini, $schtasks)
}

SIEM (KQL): Storm-2570 Affiliate Tradecraft Detection

let Storm2570_Tools = dynamic([
    "mimikatz", "sekurlsa", "lsadump", "procdump", "comsvcs.dll",
    "rubeus", "asktgt", "asktgs", "kerberoast",
    "bloodhound", "sharphound", "adfind",
    "psexec", "wmiexec", "smbexec", "atexec",
    "schtasks", "at.exe", "sc create", "service install",
    "cobaltstrike", "beacon", "meterpreter",
    "Invoke-Mimikatz", "Invoke-Kerberoast", "Invoke-DCSync"
]);
SecurityEvent
| where EventID in (4688, 4624, 4672, 4673, 5145, 5140)
| where ProcessCommandLine has_any (Storm2570_Tools)
| or where TargetLogonType == 3 and TargetUserName !endswith "$"
| extend ToolMatched = extract_all(ProcessCommandLine, Storm2570_Tools)
| where array_length(ToolMatched) > 0
| summarize EventCount=count(), ToolSet=make_set(ToolMatched), TimeRange=min(TimeGenerated)..max(TimeGenerated) by Computer, Account, ProcessName
| where EventCount >= 3
| project Computer, Account, ProcessName, ToolSet, EventCount, TimeRange
| sort by EventCount desc

SIEM (KQL): Azure Service Principal Anomaly and Destruction Burst (Storm-3168)

AzureActivity
| where TimeGenerated > ago(7d)
| where Caller contains "app@" or Caller contains "sp@" or Caller contains "ServicePrincipal" or CallerType == "ServicePrincipal"
| where OperationNameValue has_any (
    "Microsoft.Resources/subscriptions/resourceGroups/read",
    "Microsoft.Resources/deployments/delete",
    "Microsoft.KeyVault/vaults/secrets/read",
    "Microsoft.KeyVault/vaults/delete",
    "Microsoft.Storage/storageAccounts/delete",
    "Microsoft.Storage/storageAccounts/listKeys/action",
    "Microsoft.Web/sites/delete",
    "Microsoft.RecoveryServices/vaults/delete",
    "Microsoft.RecoveryServices/vaults/backupFabrics/protectionContainers/protectedItems/delete",
    "Microsoft.Resources/locks/delete",
    "Microsoft.Authorization/roleAssignments/write",
    "Microsoft.Compute/virtualMachines/extensions/write",
    "Microsoft.ManagedIdentity/userAssignedIdentities/assign/action"
)
| summarize
    Operations=count(),
    OperationTypes=make_set(OperationNameValue),
    Resources=dcount(ResourceId),
    IPs=make_set(CallerIpAddress),
    TimeRange=min(TimeGenerated)..max(TimeGenerated)
  by Caller, SubscriptionId, bin(TimeGenerated, 2h)
| where (Operations >= 5 and Resources >= 3) or (OperationTypes has "delete" and OperationTypes has "listKeys")
| project Caller, SubscriptionId, Operations, Resources, OperationTypes, IPs, TimeRange

SIEM: Device Code Sign-In Followed by Inbox Rule or Device Registration (EvilTokens)

sign_in
| where auth_protocol has "deviceCode" or authentication_protocol == "deviceCodeFlow"
| where result == "success"
| join kind=inner (
    audit
    | where operation in ("New-InboxRule", "Set-InboxRule",
                          "Add member to role",
                          "Register device", "Add registered owner")
  ) on user_id
| where audit.event_time between (sign_in.event_time .. sign_in.event_time + 6h)
| project user_id, sign_in.event_time, sign_in.source_ip,
          sign_in.app_display_name, audit.operation, audit.event_time

SIEM (Splunk): PeopleSoft Encoded WebLogic Hunt (CVE-2026-35273)

index=web OR index=proxy
(
  uri_path="*PSEMHUB*" OR
  uri_path="*%50SEMHUB*" OR
  uri_path="*%2fPSEMHUB*" OR
  uri_path="*%2550SEMHUB*"
)
AND (
  uri_path="*/hub*" OR
  http_method="POST"
)
| stats count min(_time) as first_seen max(_time) as last_seen
  values(src_ip) as src_ip
  values(http_user_agent) as user_agent
  values(status) as status
  by dest, uri_path
| where count >= 3

SIEM (Splunk): MikroTik MikroTrick SSH Rekey Anomaly (CVE-2026-67279)

index=network sourcetype=syslog host=* 
| search "sshd" AND "rekey" AND "authenticated=no" 
| stats count by src_ip, dest_ip, dest_port 
| where count > 5 
| eval note="Possible MikroTrick SSH rekey bypass attempt"

SIEM (Splunk): F5 BIG-IP APM OAuth RCE Oversized Header Indicator (CVE-2026-94127)

index=webproxy OR index=firewall 
| search "BIG-IP" AND "OAuth" AND "Authorization" 
| regex "Authorization:\s*[A-Za-z0-9+/=]{500,}" 
| eval note="Oversized Authorization header to BIG-IP APM OAuth endpoint"

SIEM: Exploited Edge Systems Post-Request Activity

FROM network_logs
WHERE destination_asset IN (
  "F5_BIGIP",
  "CHECK_POINT_SECURITY_GATEWAY",
  "WSO2",
  "SHAREPOINT",
  "PEOPLESOFT",
  "ROUNDCUBE",
  "TEAMCITY",
  "NETSCALER",
  "ARISTA_VELOCLOUD",
  "CISCO_FMC"
)
AND (
  http_status IN (200, 201, 204, 500)
  OR process_created = true
  OR outbound_connection_after_request = true
)
AND event_time BETWEEN exploit_disclosure_time AND patch_validation_time
GROUP BY source_ip, destination_asset, user_agent, uri, 15m
HAVING count(*) >= 5
   OR distinct_uri_count >= 3
   OR outbound_connection_after_request = true

SIEM: Suspicious CI/CD Workflow Audit and Runner Execution (Mini Shai-Hulud)

FROM github_audit_logs_and_process_events
WHERE (
  event_type IN ("workflow.modified", "workflow.enabled", "repository_action.updated", "release.created")
  AND (actor_is_new = true OR action_ref_changed = true OR workflow_permissions INCLUDES "write-all" OR workflow_executes_unpinned_reference = true)
)
OR (
  (command_line CONTAINS "actions/" OR command_line CONTAINS "npm install" OR command_line CONTAINS "curl ")
  AND (secret_access = true OR file_read_path MATCHES "*github*credentials*" OR file_read_path MATCHES "*npmrc" OR outbound_domain IS_NEW_FOR_WORKFLOW = true)
  AND workflow_action_ref NOT IN approved_signed_action_refs
)
ALERT severity = "high"

SIEM: Multi-LLM Provider Access With Credential Theft or Injection (CLOSEDQUORUM)

FROM endpoint_network_process_events
WHERE process_is_executable = true
  AND destination_domain IN (
      "api.deepseek.com",
      "api.mistral.ai",
      "generativelanguage.googleapis.com",
      "openrouter.ai"
  )
GROUP BY host_id, process_hash, process_name WITHIN 15 minutes
HAVING COUNT_DISTINCT(destination_domain) >= 2
   AND (
       EXISTS process_access WHERE target_process = "lsass.exe"
       OR EXISTS injection_event WHERE technique IN ("APC", "process_hollowing")
       OR EXISTS persistence_event WHERE type IN ("RunKey", "ScheduledTask", "WMI")
       OR EXISTS network_event WHERE destination_domain LIKE "%discord%"
   )
ALERT "High confidence suspicious AI orchestrated malware behavior"

SIEM: SharePoint and Web Root Web Shell Hunting (CVE-2026-65660)

FROM web_server_file_events
WHERE event_time >= patch_or_disclosure_time
  AND file_path IN web_application_root
  AND (
      file_extension IN (".aspx", ".ashx", ".asmx", ".config", ".jsp", ".jspx")
      OR file_name MATCHES "(shell|upload|cmd|debug|tmp)"
  )
  AND creator_process NOT IN approved_web_server_processes
RETURN host, user, file_path, hash, parent_process, first_seen

DEFENDER PRIORITIES

  1. Isolate Unpatched Citrix NetScaler and Patch All Cataloged Edge Flaws Immediately: Isolate internet facing Citrix NetScaler ADC and Gateway appliances behind strict ACLs and virtual WAF patches ahead of the week of September 28 vendor fixes. Patch or mitigate all September 22 to 25 catalog additions (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127, CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, CVE-2026-67279, CVE-2026-87902), plus Cisco FMC (CVE-2026-20079, CVE-2026-20316), Cisco ISE (CVE-2026-76460), Oracle PeopleSoft (CVE-2026-35273), Roundcube (CVE-2026-48842), SolarWinds (CVE-2026-28324, CVE-2026-28325), Windows (CVE-2026-85880, CVE-2026-81963), and JetBrains TeamCity.

  2. Hunt Post-Exploitation Artifacts Across Edge and Application Servers: Do not treat patching or literal WAF rules as incident closure. Normalize URL paths before WAF inspection. Scan Oracle PeopleSoft PSEMHUB.war and PORTAL.war for x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx, and Ple64.exe, and check WebLogic child processes (cmd.exe, /bin/sh, bash). Inspect SharePoint directories for web shells created since September 1, review MikroTik SSH logs for unauthenticated rekey and exec channels, inspect Cisco FMC for unauthorized admin creation, and rotate all credentials readable by PeopleSoft, WebLogic, SharePoint, and WSO2 service accounts.

  3. Lock Down Cloud Workload Identities, LiteLLM Gateways, and Recovery Planes: Audit all LiteLLM gateways, eliminate default master key sk-1234, and block IMDSv2 header pass through. Revoke and rotate any Azure service principal secret that ever appeared in a GitHub issue, ticket, or commit history (even if later edited). Separate backup and recovery permissions from application contributor roles, enforce immutable resource locks that workload identities cannot remove, and alert on burst deletions followed by ListKeys calls or python-requests/2.34.2 traffic from 45.131.66[.]106, 34.153.223[.]102, or 64.20.53[.]230.

  4. Block OAuth Device Code Phishing (EvilTokens): Use Conditional Access policies to block the OAuth device code authentication flow tenant wide except for explicitly named constrained device accounts. Hunt the past 30 days for device code logins followed within six hours by inbox rule creation, Graph enumeration, or new device registration. Where confirmed, temporarily disable the user account in addition to revoking sessions and Primary Refresh Tokens.

  5. Deploy Agent-Lifecycle Telemetry and Behavioral AI Malware Detections: Implement the agent preservation checklist across cloud and AI environments: log credential specific token lineage, session/source IDs, container build and start logs, public route request logs, and deletion tombstones for 90+ days. Restrict Docker daemon ports 2375 and 2376 from untrusted networks (Carbonato / Hermes Agent), and hunt for endpoints contacting multiple LLM APIs alongside LSASS access, APC/hollowing injection, persistence, and Discord webhooks (CLOSEDQUORUM).

  6. Hunt the Ransomware Affiliate and GPO Layer (Storm-2570 and PAYLOAD): Enforce tenant level endpoint tamper protection so local administrators cannot disable Windows Defender or add exclusions on C:\PerfLogs. Block unapproved RMM binaries (MeshAgent, Atera, ScreenConnect, Splashtop, NinjaRMM, Remotely_Agent) and tunnels (ngrok, Cloudflared). Alert on ntdsutil IFM creation under C:\Windows\Temp, s5cmd or Rclone execution, and anomalous Active Directory GPO modifications (Event IDs 5136 and 5137).

  7. Harden Software Supply Chains, DevOps MacBooks, and High-Risk Endpoints: Upgrade JFrog Artifactory to patched branches (7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20), disable anonymous access, and rotate JWT signing keys. Cryptographically pin all GitHub Actions, Terraform providers, and npm packages to immutable hashes and audit workflows ran between September 16 and 25 (Mini Shai-Hulud and WaterPlum). Deploy behavioral EDR on macOS to catch FLATROOF and ROOFDECK (Telegram/Nostr C2, LaunchAgents, login.keychain-db) as well as MacSync (osascript, SecItemCopyMatching, ClickFix prompts, and iCloud Calendar payloads).

  8. Hunt State Espionage IOCs and Harden Helpdesk Verification: Ingest and hunt IOCs for CHOSEN BRICK spyware, NightEagle (GhostContainer on Exchange), Mirage Kitten (NightLedger, ArcBridge, BridgeHead), UNC3569 (GrayRabbit, and update Tencent Sogou Input Method to 16.3.0.3498+ while restricting sgbiz: URIs), and FamousSparrow (SparroWocky). Enforce phishing resistant FIDO2 MFA and out of band callback verification for helpdesks to prevent Astrana Health style voice spoofing intrusions.

RECOMMENDED ACTIONS

  • Isolate internet facing Citrix NetScaler ADC and Gateway appliances or apply strict network ACLs and WAF virtual patches until week of September 28 patches arrive.

  • Patch all cataloged vulnerabilities (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127, CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, CVE-2026-67279, CVE-2026-87902, CVE-2026-85880, CVE-2026-81963) and validate running builds against vendor advisories.

  • Apply F5 BIG-IP APM hotfixes or the iRule workaround for CVE-2026-94127, Cisco FMC hotfixes for CVE-2026-20079 and CVE-2026-20316, Cisco ISE patch for CVE-2026-76460, and SolarWinds patches for CVE-2026-28324 and CVE-2026-28325.

  • Patch CVE-2026-35273 on Oracle PeopleSoft, disable EMHub/PSEMHUB where unnecessary, normalize URLs at the WAF before rule evaluation, scan for JSP web shells and Ple64.exe, and rotate all PeopleSoft and WebLogic accessible credentials.

  • Upgrade Roundcube Webmail to 1.6.16 or 1.7.1+, disable the virtuser_query plugin if unneeded, and inspect database logs for pre auth SQL injection (CVE-2026-48842).

  • Upgrade JFrog Artifactory to patched releases, revoke and reissue admin tokens, rotate JWT keys, and disable anonymous token access (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329).

  • Rotate all LiteLLM gateway master keys, remove sk-1234, and enforce IMDSv2 hop limit 1 with no header pass through.

  • Revoke and rotate Azure service principal secrets exposed in public repositories or edit histories, enforce least privilege RBAC, lock Recovery Services and Backup vaults with independent controls, and alert on delete plus ListKeys sequences (Storm-3168).

  • Block Entra ID OAuth device code authentication via Conditional Access and temporarily disable accounts exhibiting EvilTokens inbox rule or device registration patterns.

  • Enforce tenant level Defender tamper protection, block unapproved RMMs and tunnels (MeshAgent, ngrok, Cloudflared), monitor ntdsutil IFM creation, and alert on unauthorized GPO changes (Storm-2570 and PAYLOAD).

  • Pin GitHub Actions, Terraform modules, and npm packages to immutable commit SHAs, rotate CI/CD and developer secrets (Mini Shai-Hulud, Jade Sleet, WaterPlum), and block external access to Docker ports 2375 and 2376 (Carbonato).

  • Deploy the provided SIGMA, YARA, and SIEM detections across web, cloud, CI/CD, Windows, and macOS telemetry, retain AI agent lifecycle logs for 90+ days, and preserve forensic evidence prior to host remediation.

CONFIDENCE & LIMITATIONS

Incident / Intelligence Cluster

Confidence Level

Concise Rationale Based on Consulted Sources

Edge & Enterprise KEV Additions (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127, CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, CVE-2026-67279, CVE-2026-87902, CVE-2026-85880, CVE-2026-81963)

High (Exploitation) / Moderate (Specific Root Cause & Chaining Details)

Confirmed active exploitation via federal catalog additions and vendor advisories; CVE-2026-5430 has unresolved technical class text between the CVE record (JWT mismatch) and catalog summary (path traversal), and CVE-2026-67279 chaining with CVE-2026-86060 rests on secondary reporting.

Oracle PeopleSoft CVE-2026-35273 Mass Exploitation by UNC6240 (ShinyHunters)

High

Corroborated by primary incident response telemetry, explicit /%50SEMHUB/ WAF bypass mechanics, verified SHA256 hashes, file paths, and network IOCs.

Cloud Identity Destruction (Storm-3168 / JADEPUFFER), Affiliate Standardization (Storm-2570), and EvilTokens (Storm-2992)

High (Activity & TTPs) / Unconfirmed (Initial Access & Country Attribution)

Backed by direct cloud and endpoint telemetry and law enforcement disruption data; initial access for Storm-2570 and Storm-3168 (GitHub secret leak hypothesis) and final ransomware deployment for Storm-3168 remain unconfirmed.

Operationalized AI Agents, Hugging Face Trails (0Time, Nyx9), JFrog Artifactory Chain, and LiteLLM sk-1234 Exposure

High

Supported by direct cloud telemetry, internet wide gateway scan data (3,074 instances), and verifiable public repository commit timelines.

CLOSEDQUORUM Autonomous C2 Implant

High (Binary Capabilities) / Unconfirmed (Wild Deployment)

Reverse engineering confirms four model LLM voting and credential theft code, but consulted researchers explicitly note dummy webhooks and no confirmed in the wild deployment.

Iranian CHOSEN BRICK Spyware, Jade Sleet macOS Backdoors, UNC3569 (CVE-2026-51990), and FamousSparrow (SparroWocky)

High

Backed by multi agency international government advisories and detailed technical intrusion telemetry.

NightEagle (GhostContainer), Mirage Kitten (NightLedger), PAYLOAD GPO Ransomware, MovieReaper, and MacSync

Moderate

Detailed technical reporting from single vendor telemetry; treated as supplemental for actor attribution.

Roundcube (CVE-2026-48842), Mini Shai-Hulud GitHub Actions, Carbonato (Hermes Agent), x47.c, WaterPlum, ClearFake, RemControl, Astrana Health, Dyfed-Powys Police

Moderate

Confirmed technical and incident disclosures via cyber authorities and security reporting, though operator identities for Roundcube, Carbonato, and x47.c remain Under Attribution.

Unpatched Citrix NetScaler Zero Days, Bitget 351.6M USD Heist Attribution, Clop Leak Site Grav CMS CVE, and TeamCity CVE

Low to Moderate / Under Attribution

NetScaler zero days rest on forensic researcher warnings prior to official Citrix CVEs/patches; Bitget links to North Korean Lazarus Group rely on preliminary IP and on chain patterns; exact CVEs for Grav CMS and July TeamCity flaws were not confirmed in weekly extracts.