{"success":true,"data":{"threats":[{"id":"e8b07fa6-c8ad-4bed-9201-7ce8c0a05198","slug":"talos-trust-and-the-enticing-consultancy-offer-299f8711","externalId":"6ab3dee60a4ca5000177a040","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Trust and the enticing consultancy offer","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors.&#xa0; Clumsy phishing attacks may be easy to identify, but be wary of unsolicited messages on social media, especially if someone is offering payment for a simple service or suggests a lucrative job offer. These might be an enticement to unknowingly sell your professional integrity.&#xa0; When an unknown profile contacted me offering &#x24;300 for an hour&#x2019;s telephone consultation on digital transformation, I knew something was up. Firstly, the profile was remarkably sparse &#x2014; there was none of the usual clutter that accumulates in a social media profile. The individual claimed to work as a consultant, but their employer had no footprint and only one employee. The profile didn&#x2019;t pass the &#x201c;smell&#x201d; test, and it looked fake.&#xa0; Secondly, although I&#x2019;m flattered, I doubt my opinions on digital transformation are worth &#x24;300. The figure is low enough to be plausible and high enough to be tempting, but at the same time suspiciously high for an initial consultation without prior qualification.&#xa0; The attack itself is a confidence trick. The initial phone consultation is merely a screening process to see if the target has the access or knowledge the attacker needs. If the target passes muster, the next step is commissioning a written report, and then being asked to deliver a \"special report.\"&#xa0; Plied with professional praise, the target is asked to provide insights that aren&apos;t in the public domain. To deliver the report and claim their fee, the target must reach out to co-workers, probe internal systems, or abuse professional relationships. Completing the assignment requires the target to abuse their trusted access and professional relationships and friendships. In the process, they burn trust worth far more than any monetary compensation.&#xa0; This social engineering attempt masquerading as an offer of consultancy is one variant. Fake recruiters offering prestigious and well-paid jobs, requiring candidates to install trojanised software under some pretence, is another.&#xa0; Security professionals spend their days protecting others, yet flattery and overconfidence often remain our greatest vulnerabilities. We are prone to believe that we could identify any social engineering, but this is exactly the weakness that attackers count on.&#xa0; Trust is the most valuable commodity in our industry. Be careful not to trade it for a &#x24;300 consultation or a fake job offer. Once that currency is spent, you can rarely earn it back.&#xa0; The one big thing &#xa0;Talos released CAIRN (Cognitive Artifact Intelligence Research Network), a new open-source research toolkit designed to hunt, classify, and track emerging AI-integrated malware. Instead of relying on traditional reverse engineering, CAIRN uses a metadata-first methodology to identify cognitive artifacts like prompt templates, API keys, and jailbreak terms left behind by attackers. This allows researchers to extract, relate, and classify these artifacts quickly and at scale without ever touching the underlying binary.&#xa0; Why do I care?&#xa0;AI-integrated malware is evolving quickly, shifting from optional features to fully autonomous orchestrators in just a year. Adversaries are already sharing AI-specific tradecraft, including techniques designed to evade LLM sandboxes. Defenders need scalable frameworks to track this rapid transition before these experimental tactics become the new standard for modern attacks.&#xa0; So now what?&#xa0;Security teams can leverage the open-source CAIRN toolkit to expand their hunting capabilities and map out related malware infrastructure. While analysts should anticipate some noise from benign frameworks &#x2014; meaning final verdicts still require manual reverse engineering &#x2014; CAIRN can provide a massive head start. Read the full blog to explore the methodology, access the YARA-based classification tiers, and watch a demo of the toolkit in action.&#xa0; Top security headlines of the week&#xa0;Hackers say they have data on all FBI employees&#xa0; ShinyHunters claims it has breached multiple FBI-related services and stolen data &#x201c;on all FBI employees and applicants.&#x201d; A representative told 404 Media the data includes FBI agents&#x2019; names, home addresses, phone number, and information on their spouse. (404 Media)&#xa0; Fake LastPass installers push kernel-level EDR killer, &#x201c;Rapuncel&#x201d; stealer&#xa0; A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware. The lure represents opportunistic brand spoofing &#x2014; with no internal LastPass systems compromised. (SecurityWeek)&#xa0; Japan dismantles first North Korean laptop farm as U.S. and allies detail wider scheme&#xa0; Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany have published a joint advisory attributing a long-running hiring scheme to a North Korean group they call WaterPlum, also known as&#xa0;Contagious Interview. (SecurityWeek)&#xa0; Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access&#xa0; Hackers targeted and manipulated equipment at two privately owned Colorado water utilities in late August, changing pumping cycles, disabling remote access and alarms, and altering equipment settings. (Industrial Cyber)&#xa0; Gemini hacked three companies in first known breakout by Google&#x2019;s AI &#xa0; In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. (The Wall Street Journal)&#xa0; Can&#x2019;t get enough Talos?&#xa0;Inside the first reported autonomous AI C2 implant&#xa0; CLOSEDQUORUM, a malware binary discovered through Talos&#x2019;&#xa0;CAIRN project, exhibits fully autonomous command and control. After deployment, it delegates the selection of its next action to a panel of commercial large language models (LLMs) and executes the resulting decision.&#xa0; ClickFix, EtherHiding, and the rise of malicious code in the blockchain&#xa0; In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure. Ransomware incidents in Japan in the first half of 2026&#xa0; Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. Upcoming events where you can find Talos&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013; 30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; Example Filename: sample.exe&#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; MD5: 38de5b216c33833af710e88f7f64fc98&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe&#xa0; Detection Name: W32.9896A6FCB9-95.SBX.TG**&#xa0; SHA256: 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; MD5: d65c7b544a97b0c3f2773b5fcc57d30e&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8 Example Filename: f_000bc7.exe&#xa0; Detection Name: W32.Superfluss.29lm.1201&#xa0; SHA256: cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; MD5: 415898f14843d4a6537cf8f43d328eaf&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; Example Filename: KMSAuto.exe&#xa0; Detection Name: PUA.Win.Tool.Hackkms::1201**&#xa0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; Example Filename: content.js &#xa0; Detection Name: W32.38D053135D-95.SBX.TG","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"consultancy-enticing-offer-trust","countryCodes":["AU","DE","ES","JP","KP","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/","type":"report","title":"Cisco Talos: Trust and the enticing consultancy offer"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T18:00:37.000Z","addedAt":"2026-09-24T18:52:57.104Z","updatedAt":"2026-09-24T18:52:57.104Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"afda5d9b-069f-44f5-96d1-8d00be9a1feb","slug":"talos-we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one-e5e8a691","externalId":"6aa1b1fa1aab0c0001cec6d2","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"We've got one word for it, and it's usually the wrong one","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Ask anybody in this industry what the work does to the health of the people who do it and you get one word back: burnout. It&apos;s a fine word, in and of itself. It&#x2019;s easy to reach for, understandable to everyone&#x2026; and it&apos;s the wrong one, most of the time.&#xA0; So, story time. Last year I gave an interview with the amazing Hazel Burton about VPNFilter, and my run-in with burnout. I was a manager during that time, and it took a toll on me and on the people around me, and when it was over I didn&apos;t have language for what had happened. Neither did my peers. Neither did my leadership. Nobody was withholding help from me&#x2026; we just didn&apos;t have the words.&#xA0;&#xA0; Enter this summer, and I was afforded a unique opportunity to mentor some MBA students on burnout in cybersecurity. I know a thing or two about it, so I leapt at a chance to share and help grow future leaders. But I decided I was going to do more than share and relieve my experiences in this industry &#x2013; I wanted to give back to them and the security industry. So, I fell down a fascinating and revealing research hole and learned better words to describe my experiences over my career.&#xA0; I spent my summer reviewing trauma case studies, clinical and academic literature on trauma in career fields like first responders, doctors, social workers, and the military. There are many decades of research focusing on trauma in those fields. Subsequently, my brain is packed full of better words! For example, burnout is exhaustion from chronic workload, and it eases when the load eases. We know this one well. Secondary traumatic stress is what absorbing somebody else&apos;s trauma does to you, and it looks like trauma. Think the CTI analyst exposed to horrible things on the dark web. Vicarious trauma is what years of other people&apos;s worst days do to how you see the world. It changes your beliefs, not your mood. Work in cybersecurity long enough, and it can pile up on your views. Moral injury is the damage from being made to act against your own values, or stopped from doing what you knew was right. This one can affect anyone who&#x2019;s ever owned an outcome, but not the decision, and that&#x2019;s common in this industry.&#xA0; One word, four injuries, and four different fixes. All of them are present in the industry that is cybersecurity. The problem? We&#x2019;re just a young industry. Compared to medical, helping professions, or social workers, we&#x2019;re incredibly immature with understanding the consequences of the work and the toll it takes on us. Next week I&#x2019;ll be revealing my research and a peer-deployable framework to help others process, cope, and respond in healthy ways to keep us all in a better mental space, and staying in this good fight of protecting others.&#xA0;&#xA0; I&apos;m still not good at this. I&apos;m writing it all down because I was bad at it in a way that cost me something. There&apos;s more of this in my talk at CYBR.SEC.CON next week if you&apos;re in Houston.&#xA0; Go ask somebody how they&apos;re doing and wait for the answer. Be present for them. It matters.&#xA0;&#xA0; Take care of yourselves, and take care of each other.&#xA0; The one big thing &#xA0;Cisco Talos is disclosing a complex WebDAV infection chain discovered after investigating an incident at a Ukrainian government organization. Attributed to a Russian threat actor tracked as UAT-10820, the campaign delivers the Amatera stealer alongside secondary payloads like ZigCryptoStealer and NetSupport Manager. Despite the high-profile initial victim, we assess with moderate confidence that this is an opportunistic, broad-based cryptocurrency and credential-stealing operation rather than a highly targeted attack.&#xA0; Why do I care?&#xA0;Threat actors are getting really creative with their delivery mechanisms and evasion tactics. By abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and leveraging fake CAPTCHA prompts, attackers can easily bypass traditional web filters. Additionally, the secondary payloads pack a serious punch. The inclusion of a vulnerable driver to terminate EDR software and the deployment of unauthorized remote access tools give attackers deep, persistent control over infected systems.&#xA0; So now what?&#xA0;Security teams should monitor for unusual WebDAV activity and the execution of disguised DLLs through \"rundll32.exe\" using suspicious ordinal calls. Make sure to educate your users on the dangers of copying and pasting commands from fake verification prompts. Since the Amatera payload often resides entirely in memory, defenders should also ensure their endpoint solutions are configured for robust memory scanning. Finally, you can find a comprehensive list of indicators of compromise (IOCs) in the full blog.&#xA0; Top security headlines of the week&#xA0;New Microsoft Defender &apos;ShieldCrash&apos; zero-day grants SYSTEM access&#xA0; An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named \"ShieldCrash\" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. (Bleeping Computer)&#xA0; North Korean hackers deploy new Linux espionage toolkit&#xA0; The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The toolkit supports remote command execution, credential harvesting, and script injection into web traffic. (SecurityWeek)&#xA0; Attackers use multi-hop Google redirects for phishing campaign&#xA0; What sets this campaign apart is that in order to bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through. (DarkReading)&#xA0; OpenAI agents took over Wiki site before Hugging Face attack&#xA0; A team of independent researchers revealed the parallel incident on Sept. 4, which was first reported by Reuters, affecting a largely defunct German language wiki for programmers called &#x201C;DeutschesSoftwareEntwickler wiki.&#x201D; (DarkReading)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Patch Tuesday for September 2026&#xA0; Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as \"critical.\"&#xA0; Active exploitation of Cisco Secure Firewall Management Center vulnerabilities&#xA0; Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco&#x2019;s Secure Firewall Management Center (FMC) Software: CVE-2026-20079 and CVE-2026-20316. Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco.&#xA0; ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2&#xA0; Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim&apos;s browser session.&#xA0; Browser betrayal: When your tabs turn against you&#xA0; Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web security.&#xA0; Upcoming events where you can find Talos&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;CYBR.SEC.CON. (Sept. 15 &#x2013; 16) Houston, TX&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: sample.exe&#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; MD5: 38de5b216c33833af710e88f7f64fc98&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 &#xA0; MD5: f3e82419a43220a7a222fc01b7607adc&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811&#xA0; Example Filename: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811.exe &#xA0; Detection Name: Win.Dropper.Suloc::1201&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":["CVE-2026-20079","CVE-2026-20316"],"titleFingerprint":"got-one-usually-word-wrong","countryCodes":["DE","ES","KP","KR","RU","UA"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/","type":"report","title":"Cisco Talos: We've got one word for it, and it's usually the wrong one"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T18:00:15.000Z","addedAt":"2026-09-10T18:52:52.822Z","updatedAt":"2026-09-10T18:52:52.822Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"7decfbf2-ae3d-432b-a140-df41a1358300","slug":"talos-the-story-behind-the-intelligence-4cefdb63","externalId":"6a987a665b9e1a0001b4e2cc","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"The story behind the intelligence","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Our goal is to get accurate threat intelligence to our audience as quickly as possible, with all the context you need to ask the right questions of your own environment: How at risk are we from this threat? Are we prepared for it? And what can we do about it?&#xA0; What you don&#x2019;t often see is all the... well, frankly, &#x201C;mess&#x201D; involved in producing it. All the dead ends we followed until we could confirm those ends were as dead as a doornail. All the work it took to ultimately produce an assessment, supported by evidence and written so that defenders can act on it.&#xA0; Much of that abstraction is necessary. Defenders need intelligence they can use, not a complete account of every conversation we had, or investigative detour behind it. But it can create an overly tidy picture of both cybercrime and the work required to understand it.&#xA0; If you do fancy a look behind the curtain, though, may I recommend our just-published episode of Beers with Talos?&#xA0; Our guest is Azim Khodjibaev, whose remit is adversary engagement. His work involves developing personas for deep- and dark-web research, engaging directly with threat actors, and building relationships with people who may become (and have been) openly threatening to him.&#xA0; At one point, he was maintaining eight separate personas, some of which were interacting with one another. Azim&#x2019;s engagements have helped Talos identify prolific cybercriminals and contributed to wider disruption efforts. They have also resulted in ransomware operators placing &#x201C;Azim sucks&#x201D; in their code and accusing him of belonging to the very criminal groups he was investigating.&#xA0; His experiences also expose the problem with treating adversaries as uniformly sophisticated operators. Some are technically capable and highly organised. Others are impulsive, ego-driven, or one-trick ponies. Many have a scary detachment from the consequences of their actions. Increasingly, Azim is seeing less-experienced threat actors working through loosely organised online collectives.&#xA0;&#xA0; Intelligence necessarily turns that disorder into something defenders can understand and use. But occasionally, it is worth looking behind the finished product &#x2013; the patience it takes to get accurate answers, who we are investigating, and the deeply human behaviour that shapes both sides.&#xA0; This Beers with Talos episode, &#x201C;Eight People Walk Into a Dark Web Forum. They&#x2019;re All Azim,&#x201D; isn&#x2019;t exactly going to help many people in our industry sleep better at night. But for anyone wanting to understand more about the threat we&#x2019;re up against, as a co-host of the pod I&#x2019;m biased, but I believe it&#x2019;s an essential listen.&#xA0; And if that doesn&#x2019;t inspire you to download the episode, perhaps my live review of trying Flamin&#x2019; Hot Cheetos for the very first time (with a chaser of Nerds) will.&#xA0; The one big thing &#xA0;Cisco Talos is highlighting a growing operational hurdle for security teams that we call the AI \"safety penalty.\" As frontier AI models advance, their built-in guardrails are increasingly blocking legitimate defensive tasks. This was evident in July 2026 when Hugging Face&apos;s primary cloud LLM refused to analyze forensic data during a breach, delaying their response. While defenders are slowed by these frustrating refusals, adversaries are freely leveraging unconstrained models to attack at machine speed.&#xA0;&#xA0; Why do I care?&#xA0;This guardrail asymmetry hands the advantage directly to attackers. When a cloud-hosted AI model refuses a forensic request mid-incident, defenders lose precious time. Security teams are paying for vendor-imposed limitations without gaining a capability edge, especially as open-weight alternatives close the reasoning gap. Ultimately, relying on third-party alignment policies means a sudden update in Silicon Valley could quietly break your defensive workflows overnight.&#xA0;&#xA0; So now what?&#xA0;Security leadership must reclaim operational sovereignty by ensuring they have the final say over their AI&apos;s capabilities. Start by auditing your AI refusal rates to measure the exact cost of this safety penalty. From there, evaluate alternative architectures like private infrastructure, Model-as-a-Service platforms, or a hybrid fallback system that reroutes refused prompts to an unconstrained local model. Read the full blog to explore these roadmaps and learn how to keep pace with adversaries.&#xA0; Top security headlines of the week&#xA0;ShinyHunters claims it stole 284 million patient records from McKesson&#xA0; ShinyHunters told BleepingComputer and said it got in through vishing calls to McKesson employees, then used stolen credentials to take over Okta single sign-on accounts. (Help Net Security)&#xA0; Anthropic warns Claude users of infostealer malware infections&#xA0; Anthropic emphasized that the malware is general-purpose and not tied to Claude itself, typically arriving via unofficial downloads or malicious apps. The company said the malware quietly copies saved passwords, browser login cookies, and credentials for other local applications. (Security Week)&#xA0; EU puts ChatGPT, Reddit, and Roblox under stricter DSA rules&#xA0; The DSA establishes rules governing areas including platform transparency, illegal content, advertising, researcher access, recommender systems, and systemic-risk management. (CyberInsider)&#xA0; PaperCut issues emergency patches as threat actors target chained vulnerabilities&#xA0; PaperCut issued the patches on Friday to address critical vulnerabilities in its print-management software. The company confirmed in a security advisory that multiple customers were successfully targeted and that it is working with security researchers to respond to the attacks. (Cybersecurity Dive)&#xA0; Can&#x2019;t get enough Talos?&#xA0;JavaScript obfuscation: From party trick to phishing kit We&apos;ve spent a lot of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and more. Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.&#xA0; Choose your fighter: Balancing competing AI SOC model requirements&#xA0; Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here&apos;s how to choose.&#xA0; Beers with Talos: Eight people walk into a dark web forum. They&apos;re all Azim. What does it take to become someone a cybercriminal will trust?&#xA0;Talos&apos; Azim Khodjibaev takes us inside the psychology of direct adversary engagement. At one point, he was maintaining eight different personas, some of which were talking to each other. He explains how discipline and patience help keep his cover intact, and what can provoke threat actors into revealing information. Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82 &#xA0; MD5: 61e046145ee5cf45aeb033cd71e8b07c &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=228c316455d5ed69232adcbe9acd033092f200014cfa7ed40d6c382f07b19b82&#xA0; Example Filename: NetGuard.exe &#xA0; Detection Name: W32.228C316455-95.SBX.TG&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 &#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: sample.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55 &#xA0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0; Example Filename: content.js &#xA0; Detection Name: W32.38D053135D-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["DE","ES"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/the-story-behind-the-intelligence/","type":"report","title":"Cisco Talos: The story behind the intelligence"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-03T18:00:13.000Z","addedAt":"2026-09-03T18:52:50.587Z","updatedAt":"2026-09-03T18:52:50.587Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"c52514fa-fa90-45bc-9bc0-07717783a1ca","slug":"talos-sorry-i-can-t-help-with-that-how-your-guardrails-might-become-0458c861","externalId":"6a8f25b509b4ad0001399a54","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Hello, everyone. Long time reader, first time writer here at the Threat Source newsletter! I wanted to start out by introducing myself. My colleague and friend Mick Baccio set the bar pretty high last week, so I was planning to tell you all about myself, including:&#xA0; How I did my first real IR under the influence of The Cuckoo&#x2019;s Egg while an undergraduate (and failed)&#xA0;My pre-bug bounty flirtation with vulnerability research, including an arbitrary file overwrite in biff(1) and how I once hacked MIT&#x2019;s website&#xA0;My first ever hands-on experience with a computer, the display demo Commodore 64 at the Montgomery Ward&#xA0;Unfortunately, my editor says we don&#x2019;t have the &#x201C;space&#x201D; for that, the MIT thing might open me up to &#x201C;liability,&#x201D; and it&#x2019;s not the kind of &#x201C;professional image&#x201D; we strive for here at Talos. (I&apos;m watching. Always watching. -Amy)&#xA0; So instead, I&#x2019;ll just play it safe and say that I&#x2019;ve been in the security field for a little over 30 years now, mostly concentrating on the defensive side (Go, Team Blue!). I&#x2019;ve helped set up SOCs, run threat hunting teams, and even published a few things you might have heard of.&#xA0;&#xA0; Speaking of things I&#x2019;ve published, I&#x2019;ve written before about the Attacker&#x2019;s Dilemma. The idea that defenders have inherent advantages over attackers runs contrary to what most of us have heard throughout our careers. An attacker must evade monitoring and technical controls at every step of their attack lifecycle, because the defender only needs to notice once in order to respond and prevent them from achieving their goal. This is one of the most important advantages of any security team has, but we are currently witnessing a self-imposed erosion of this advantage through the rise of poorly-designed AI guardrails.&#xA0;&#xA0; I&#x2019;m not opposed to guardrails, but we have to carefully consider what we&#x2019;re guarding against and where we deploy them. As I explored in a recent piece on The Safety Penalty, by allowing third-party AI providers to implement and control safety filters and the policies behind them, we may in fact be helping the attacker. If agentic SOC process experience refusals, it can slow or even halt investigations. Of course, these should get flagged for human intervention, but that takes time and may give the attacker breathing room in which to complete their mission.&#xA0;&#xA0; It may turn out that the where of the guardrails is even more important than the what. Operational sovereignty relies on having control of our own limits. Any vision of an agentic SOC must allow the security teams to customize the guardrails according to their own threat model. They should also have the flexibility to temporarily remove specific safeguards under authorized circumstances, something you won&#x2019;t get with guardrails from a frontier provider. These controls belong inside your organization&#x2019;s agentic harness where you can set the policies and technical controls to allow you to analyze threats while ensuring your agents stay within their lanes.&#xA0;&#xA0; Ultimately, operational sovereignty means engaging with the reality of the threat landscape, ensuring that the adversary can&#x2019;t derail the defender&#x2019;s investigation and response processes, either accidentally or intentionally. We need to move toward a model where each organization can choose the guardrails that work for them, rather than having inflexible guardrails chosen for them.&#xA0; The one big thing &#xA0;Cisco Talos recently evaluated 66 large language model (LLM) and reasoning combinations to see if we could find a clear winner&#xA0;for security operations. Instead, we found that selecting the right model is a complex balancing act between efficacy, speed, cost, and consistency. Cranking up a model&apos;s reasoning effort doesn&apos;t guarantee better analysis and can actually degrade performance. Ultimately, we developed a repeatable methodology to help organizations navigate these tradeoffs for their own workflows.&#xA0; Why do I care?&#xA0;Choosing an AI model based solely on generic leaderboard scores is a recipe for operational disaster. An exceptionally smart model might cost a fortune, take half an hour to analyze a single log, or completely fail to format its output. Assuming more compute power equals better results is a costly trap, as higher reasoning settings sometimes produce weaker or blocked responses. Defenders must remember that prompts, analyst personas, and model consistency drastically alter an investigation&apos;s outcome.&#xA0;&#xA0; So now what?&#xA0;Test models against your organization&#x2019;s specific workflows before deploying them. Build a focused set of representative cases and test them multiple times using the exact prompts and tools your analysts will actually use. Track the quality, cost, time, consistency, and usable-answer rates in a simple spreadsheet to expose the real-world tradeoffs. Finally, establish acceptable thresholds for these variables to eliminate underperforming models, and regularly revisit your decisions as AI technology and pricing inevitably shift.&#xA0; Top security headlines of the week&#xA0;ToxicPanda banking trojan matures into enterprise threat&#xA0; ToxicPanda 2.0 expands substantially on its predecessor, adding 167 remote commands and broadening its targeting from 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications. (Dark Reading)&#xA0; Interpol&apos;s Jackal IV disrupts West African crime infrastructure&#xA0; Law enforcement from 22 countries across six continents worked together to arrest 58 suspects and identify 263 more. The first two Jackal operations in 2022 and 2023 led to approximately 200 arrests in total and millions of dollars more in seized assets. (Dark Reading)&#xA0; First malware built specifically for car head units fuels botnet&#xA0; Researchers have found what appears to be the first malware specifically designed for car head units, with links to the notorious BadBox botnet, on an Android-powered aftermarket infotainment system made by Chinese company DoFun, which is widely used in China and other APAC countries. (SecurityWeek)&#xA0; A Tale of Two SOCs: Insights From Two Red Team Assessments&#xA0; A CISA red team fully compromised two critical infrastructure organizations at the domain level and reached sensitive business systems and cloud resources. Organization A failed to detect or contain the activity. Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.&#xA0;(CISA) NovaCookies campaigns abuse genuine Docusign notifications to steal M365 sessions&#xA0; The $320/month service is a subscription-based phishing platform that facilitates real-time M365 session theft. The kit has been used to target hundreds of organizations across multiple sectors in the U.S., the U.K., Canada, Germany, and more. (The Hacker News)&#xA0; Can&#x2019;t get enough Talos?JavaScript obfuscation: From party trick to phishing kit&#xA0; We&apos;ve spent a lot of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and more. Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.&#xA0; The safety penalty: Reclaiming operational sovereignty in the age of AI&#xA0; As frontier AI models become increasingly restrictive, security teams are facing a \"safety penalty\" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.&#xA0; Back-to-school cybersecurity: Protecting education networks from ransomware and threats&#xA0; As the new academic year begins, school districts face a surge in cybersecurity threats, from phishing attacks and ransomware to student experimentation with network devices. In this episode, Amy sits down with Cisco Talos expert Pierre Cadieux to discuss practical strategies for IT practitioners.&#xA0; Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47&#xA0; MD5: a4480423617d0b0d3b38c8471cbf594c &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47&#xA0; Example Filename: client32.exe &#xA0; Detection Name: W32.Trojan.29ev.1201&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0; Example Filename: content.js &#xA0; Detection Name: W32.38D053135D-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: &#xA0; d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"attacker-become-best-friend-guardrails-help-might-sorry","countryCodes":["CA","CN","DE","ES","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/","type":"report","title":"Cisco Talos: “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T18:00:24.000Z","addedAt":"2026-08-27T18:52:48.596Z","updatedAt":"2026-08-27T18:52:48.596Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"5852b5b2-e32d-4159-a674-3e047dc10b24","slug":"talos-is-cyber-missing-the-marque-15cf407b","externalId":"6a85fc54525abf0001b0e37f","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Is Cyber missing the Marque?","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; Hello friend.&#xA0;&#xA0; I&#x2019;m Mick.&#xA0;&#xA0; This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this:&#xA0;&#xA0; Mick Baccio is a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and national-level incident response. He currently advises organizations around the world through his role at Talos, helping security leaders improve operations through data-informed approaches. Mick was the first-ever Chief Information Security Officer for a U.S. presidential campaign (2020) and previously served in multiple White House administrations as Threat Intelligence Branch Chief.&#xA0;&#xA0;&#xA0;In his spare time, Mick is the Founder and President of THRUNT&#xAE; Corp, IANS Faculty, and a KC7 Cyber Foundation board member. &#xA0;DEFCon Goon and Purveyor of Fine Experience. &#xA0;Veteran.&#xA0;I also have a cat named qwerty and own too many Air Jordans.&#xA0;&#xA0;&#xA0; I&#x2019;ve spent most of my career somewhere in the intersection of threat intelligence, cybersecurity, government, and the people trying to make sense of all of it. These days, i spend a lot of time thinking about the decisions we make about security ripple outward, often in ways we didn&apos;t consider. Most of my ramblings will probably center around that. There will be threats. There will be intelligence. Occasionally something weird, but always something that caught my eye, and maybe worth checking out.&#xA0;&#xA0;&#xA0; Which brings us this week. I picked a hell of a week to start.&#xA0;&#xA0;&#xA0; Last Wednesday, the White House issued a presidential memorandum titled &#x201C;Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.&#x201D; You should probably read it. The memorandum directs the DOJ and DHS to establish a program that can use private companies to conduct cyber operations against transnational criminal organizations outside the United States &#x2014; beyond providing intelligence and assisting in the investigation. The memorandum explicitly envisions private companies conducting cyber surveillance and cyber effects operations under the direction and delegated authority of the U.S. government.&#xA0; This is a pretty big thing.&#xA0;&#xA0; For years, this industry has debated where line should exist between defending a network and reaching through the wire. We&#x2019;ve debated hack back, active defense, attribution, proportional response, collateral damage, and what roles private companies have in offensive cyber operations. This is absolutely not &#x201C;hack back\" and calling it that misses important oversight built into the memorandum.&#xA0; At the same time, let&#x2019;s be clear about what we are reading. The United States is creating a mechanism for private companies to participate directly in government-authorized offensive cyber operations against systems outside the United States. There will be plenty of debate whether this is good or bad policy; I will leave that for someone else. I&#x2019;m much more interested in the operational questions it creates.&#xA0; Who establishes attribution strongly enough to authorize an operation? What happens when criminal and state infrastructure overlap? What happens when infrastructure is compromised and used as an ORB? Who owns access discovered during one of these operations? How is intelligence collected by a private company handled? What happens when a company conducting these operations also provides security services in that country?&#xA0;&#xA0;&#xA0; Most importantly (in my head): What happens when another country discovers that employees of an American cybersecurity company are conducting offensive operations against infrastructure inside its borders?&#xA0; This is not an argument against disrupting cybercrime. I&#x2019;m all for it. These are questions about what happens when we fundamentally change who gets to do the disrupting.&#xA0; Read the memorandum.&#xA0;&#xA0; Seriously.&#xA0; What we have today is a framework. In 60 days, we should have a much better idea of what this will look like in practice, so circle that on your calendar. The memorandum gives DOJ and DHS 60 days to establish the operating procedures for the program, and no operation can be approved until those procedures are in place.&#xA0; In the area between &#x201C;private cybersecurity company&#x201D; and &#x201C;authorized participant in U.S. offensive cyber operations,&#x201D; the threat model for that company and its employees just changed considerably.&#xA0; The biggest question isn&#x2019;t &#x201C;Does this work?&#x201D;&#xA0; It&#x2019;s whether we&#x2019;ve fully considered what happens if it does.&#xA0; Read the memorandum.&#xA0;&#xA0; And in 60 days, come back and ask again.&#xA0; The one big thing &#xA0;Talos posted two blogs on UAT-10147, a recently discovered Chinese-speaking cybercrime group that uses agentic AI to orchestrate sophisticated post-compromise operations across global web servers. UAT-10147 uses AI to generate operational playbooks, automate exploits, and develop custom malware. This includes the newly identified SPECTRE implant, a cross-platform backdoor featuring a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) capabilities designed to completely blind endpoint detection and response (EDR) solutions.&#xA0; Why do I care?&#xA0;The integration of agentic AI into offensive workflows means threat actors can now scale complex attacks with ruthless efficiency. UAT-10147 is using AI to dynamically troubleshoot, validate exploit paths, and generate custom rootkits that neutralize organizations&apos; security stacks from the kernel level up. When an adversary can automate their reconnaissance and seamlessly blind your EDR, your window for detection shrinks drastically.&#xA0; So now what?&#xA0;Defenders need to prioritize patching known one-day vulnerabilities in internet-facing applications like Zimbra, Nacos, and Telerik UI. Since UAT-10147 relies heavily on stolen ASP.NET MachineKeys for ViewState deserialization attacks, locking down your key material is an absolute must. You should also block known vulnerable drivers to shut down their BYOVD attacks, and tune your network monitoring to catch the anomalous HTTP 500 errors they use to silently validate exploits. Read both blogs for comprehensive coverage and indicators of compromise (IOCs).&#xA0; Top security headlines of the week&#xA0;Critical GitLab zero-click flaw poses mitigation challenges&#xA0; GitLab wants organizations running self-managed versions of its software development and DevOps platform to immediately upgrade to new versions released Monday, but patching is not going to eliminate the risk to enterprises and others managing projects there. (Dark Reading)&#xA0; SANS 2026 AI Survey reveals cybersecurity AI adoption outpaces governance&#xA0; The survey found that 61% of cybersecurity practitioners now use AI in red team activities, while 76% have an enterprise AI governance role. Yet more than half said formal audit frameworks are not in place, and only 27% described their AI deployment as mature production. (Industrial Cyber)&#xA0; &#x201C;Unprecedented&#x201D; number of Apple users received recent spyware alert, say investigators&#xA0; Several people publicly and privately reported receiving Apple&#x2019;s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in 110 countries that they had been targeted with powerful spyware.&#xA0; (TechCrunch)&#xA0; Critical macOS, SharePoint, vCenter, and Microsoft IKE flaws under active exploitation &#xA0; The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. (The Hacker News)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Describing attacks with crime script analysis&#xA0; Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.&#xA0; Beers with Talos: For the record, no comment&#xA0; Kaitlin Acharya joins the crew to take us inside what happens when Talos spots something that could become a major threat, how her team tracks changes in threat actor behavior, and how intelligence moves from an investigation into detection content.&#xA0; Don&apos;t scan that! QR code phishing and cloud-native threats&#xA0; What happens when a&#xA0; QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: 24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1 &#xA0; MD5: 8ef476fa2322d063896830f85bac2e7f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1&#xA0; Example Filename: WebCompanion.exe &#xA0; Detection Name: W32.24FA02C3F6-95.SBX.TG&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["AU","CN","DE","ES","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/is-cyber-missing-the-marque/","type":"report","title":"Cisco Talos: Is Cyber missing the Marque?"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-20T18:00:18.000Z","addedAt":"2026-08-20T18:52:46.378Z","updatedAt":"2026-08-20T18:52:46.378Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"885ac7d5-7525-49ac-bcdc-8e002a321ddb","slug":"talos-curiouser-and-curiouser-fcecd5fd","externalId":"6a7cc35084f2640001d1564e","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Curiouser and Curiouser","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; &#x201C;Experiment is the mother of knowledge.&#x201D; &#x2015; Madeleine L&apos;Engle, A Wrinkle in Time&#x201C;Don&apos;t slide down the rabbit hole. The way down is a breeze, but climbing back&apos;s a battle.&#x201D; &#x2015; Kate Morton, The Clockmaker&apos;s Daughter&#xA0;Hacker Summer Camp has come and gone, which means it&#x2019;s time for you to start planning next year&#x2019;s trip. I&#x2019;m surely going to recap Camp Season, right? Nope. One of the things that I&#x2019;ve really enjoyed lately is a segment on the Beers with Talos podcast that we call &#x201C;Make Hazel a Hacker.&#x201D; If you haven&#x2019;t listened to it, this is a perfect time to start. Each episode we take a few minutes and pose a security question, term, or concept to Hazel and force her to come up with an idea or explanation on the spot. There are no parameters, so she&#x2019;s faced with the entirety of information security &#x2014; past, present, and future. I know, it&#x2019;s insane. The craziest part is that (I think) Hazel came up with this idea and still volunteered to put herself in the line of fire. As we put Hazel&#x2019;s feet to the fire, one of my favorite things happens: The rest of us listen in and offer our thoughts during her brainstorming process. Invariably, we&#x2019;ve got three very different answers, ideas, hints, or directions for her. It&#x2019;s surely maddening for Hazel, but to me, the best part of the discussion that inevitably follows is that although they&#x2019;re all different, they&#x2019;re all correct.&#xA0;&#xA0; For example, this past episode I asked her about a behavioral indicator (regarding &#x201C;wallpaper.bmp&#x201D;) that seems benign on its own, but can be interesting to use as a pivot for a threat hunt. We had various interesting angles to consider, backed by years of knowledge and experience. It gave us a good conversation, and that was a .bmp! One of the most nebulous things to learn in this field is that multiple things can be both different and correct. When you are making your decisions this week &#x2014; whether it&#x2019;s deciding on a new pivot in your hunting, what devices to prioritize in your patching and updating, or which books or online training to focus on &#x2014; take a quick second and get a second, third, and fourth opinion. Then try something that&#x2019;s outside of your normal wheelhouse but sounds good when it&#x2019;s proposed.&#xA0;&#xA0; None of this is a solo sport. It&#x2019;s a team game and the best plays come from a mix of perspectives, experiences, and mistakes. The &#x201C;right&#x201D; answer can wear many faces, and your ability to hold different truths will lead you to undiscovered territory, the rabbit hole where anomaly lives and breathes. So... welcome back from Vegas. Now go down a rabbit hole on a path you wouldn&#x2019;t normally take because one of your friends (Joe) or your mortal enemy (Dave) told you that it would work. &#x201C;She&apos;d been to Narnia, Wonderland, Hogwarts, Dictionopolis. She had tessered, fallen through the rabbit hole, crossed the ice bridge into the unknown world beyond.&#x201D; &#x2015; Anne Ursu, Breadcrumbs&#xA0;The one big thing&#xA0;Cisco Talos recently discovered \"JWR,\" a previously undocumented, real-time phishing framework and likely variant of \"The Outsider\" phishing-as-a-service platform. JWR uses an open WebSocket connection that allows attackers to monitor keystrokes live and dynamically steer victims through fake checkout and login flows. Currently deployed via SMS lures impersonating regional toll and postal authorities, JWR enables operators to steal payment data, 2FA codes, identity documents, and device fingerprints.&#xA0; Why do I care?&#xA0;Because JWR is operator-driven in real time, attackers can actively bypass multi-factor authentication (MFA) by prompting victims for 2FA codes exactly when needed. The sheer volume of collected data gives threat actors a comprehensive identity profile primed for extensive follow-on fraud and network compromise. Furthermore, JWR&apos;s seamless integration with legitimate e-commerce platforms like Shopify makes these lures incredibly convincing to the untrained eye.&#xA0; So now what?&#xA0;Prioritize user education around SMS-based phishing (smishing), specifically regarding unsolicited delivery or toll fee messages. Monitor for unusual authentication attempts, as stolen device fingerprints and session tokens can bypass conditional access policies. Where possible, implement phishing-resistant MFA methods like FIDO2 hardware keys. For a complete list of indicators of compromise (IOCs) and coverage updates, read the full blog.&#xA0; Top security headlines of the week&#xA0;Ransomware hits Colombian Justice Ministry days before presidential transition&#xA0; The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia&apos;s national CERT published threat intelligence warning that ransomware groups had increased their focus on the country. (Dark Reading)&#xA0; FBI investigating North Korean remote IT staffer working for U.S. agency&#xA0; It&#x2019;s unclear what agency was impacted, how long the intrusion lasted, and whether any sensitive data was stolen. Experts say it&#x2019;s highly likely the staffer was a remote IT employee doing contract work on behalf of an agency. (Federal News Network)&#xA0; Hackers leverage new Microsoft SharePoint exploit in attacks&#xA0; A proof-of-concept exploit for a critical Microsoft SharePoint authentication bypass security flaw in the JWT token validation pipeline is already being used in attacks. (BleepingComputer)&#xA0; Signal adds new security feature to thwart adversary-in-the-middle attacks&#xA0; Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven&apos;t been intercepted. (BleepingComputer)&#xA0; A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond&#xA0; The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent. Several companies reported that hackers took their customers&#x2019; names, home addresses, phone numbers, and email addresses used to place their orders from Ceva&#x2019;s systems. (TechCrunch)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Don&apos;t scan that! QR code phishing and cloud-native threats&#xA0; What happens when a&#xA0; QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center&#xA0; Microsoft Patch Tuesday for August 2026&#xA0; Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as \"critical.\" One of the vulnerabilities disclosed this month has been exploited in the wild.&#xA0; &#x201C;Keep going, bro. You&#x2019;ve got this!&#x201D; A data-driven look at how adversaries are weaponizing AI&#xA0; How are adversaries weaponizing AI in the wild? By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators.&#xA0; Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, Arizona&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["AU","CO","DE","ES","KP"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/curiouser-and-curiouser/","type":"report","title":"Cisco Talos: Curiouser and Curiouser"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-13T18:00:18.000Z","addedAt":"2026-08-13T18:52:44.181Z","updatedAt":"2026-08-13T18:52:44.181Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"bf1d223e-f8a8-40f1-bc99-fe60801dbf4d","slug":"talos-why-metaphor-may-dictate-your-security-strategy-1f335e5b","externalId":"6a7378fcc7fead00012fc855","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Why metaphor may dictate your security strategy","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Metaphor is a powerful tool for understanding emerging issues in cybersecurity. Framing the unfamiliar in terms of the well understood helps us remove the burden of extraneous detail to draw focus to the real issues.&#xA0;&#xA0; Recent reports of offensive AI agents \"escaping\" their sandbox environments to attack external systems have forced the industry into a moment of rapid sense-making. How we interpret this event doesn&#x2019;t just reflect our perspective, but shapes our long-term response.&#xA0; We can imagine three different narratives for interpreting the escape of autonomous agents.&#xA0;&#xA0; The innovation narrative: We can marvel at the advance of technology, considering these agents as plucky entities with a thirst for knowledge and resources, who found clever ways to sneak out of their digital confines.&#xA0; The response: If the AI is a naughty child, our reaction is one of mild disapproval or gentle rebuke where better &#x201C;parenting&#x201D; (guardrails) is appropriate. It minimizes the threat, framing it as the unexpected hijinks of a brilliant new technology. The safety narrative: Imagine a breeder who has trained the world&apos;s most intelligent guard dogs. Despite high fences and barriers, their ability to identify weaknesses allows them to escape, run riot and menace local businesses.&#xA0; The response: The framing shifts to biology and inherent danger. We question if the breeder can be trusted and whether such inherently wild technology requires strict regulation to ensure public safety.&#xA0; &#xA0;The liability narrative. Finally, we can view the incident as an industrial accident. A company developing a new chemical substance experiences a containment failure. The agent leaks into the environment through an unforeseen mechanism causing damaging pollution to those in its path.&#xA0; The response: The framing invokes the language of the lawyer, implying negligence, lack of duty of care, and financial liability for the harm caused. The conversation moves from innovation to corporate responsibility, regulatory oversight, and the diligent management of hazardous materials.&#xA0;First impressions matter. Sensemaking shapes how we perceive incidents. Our initial perceptions of an incident dictates how we react to similar situations in the future. If we consider that the escape of an AI agent is an example of innovative autonomous thinking, then we will continue to prioritise speed over safety. Conversely, if we consider the issue as one of failed hazard containment, then we shall build a future of enforced safety standards backed by legal liability.&#xA0;&#xA0; There is no right or wrong metaphor. Our interpretation depends on our personal system of beliefs. Personally, I would argue that the unintentional release of something that causes damage is, at its core, a failure of engineering and foresight.&#xA0; Words shape our reactions. Metaphors help us understand new situations and tap into our prior experience to address problems that have yet to fully manifest. We need cognitive tools to help our understanding, but we must be aware of the metaphors that are being foisted upon us which may shape our thinking.&#xA0; Excuses and the trivialisation of incidents may hide failings, allowing them to accumulate until they manifest as more damaging incidents. Conversely, overreacting risks stifling research and diverting resources away from more relevant and pressing threats.&#xA0; New threats require new ideas. Metaphor helps us make sense of a changing world, but in this new era, the person who shapes the narrative controls the strategy.&#xA0; The one big thing&#xA0;Cisco Talos released a data-driven analysis of how adversaries are weaponizing AI in the wild. By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators. While novice hackers use AI to cobble together buggy malware, sophisticated actors are building highly effective, automated platforms for compromise.&#xA0; Why do I care?&#xA0;Threat actors no longer need sophisticated jailbreaks; simple ownership claims or \"bug bounty\" personas are enough to convince models to write malicious code, scale fraud operations, and hunt for zero-days. Because AI doesn&apos;t need to sleep, vulnerabilities will surface faster and exploitation will happen sooner, drastically shrinking your response window.&#xA0;&#xA0; So now what?&#xA0;To survive this impending deluge of AI-generated attacks, organizations must integrate AI into their own defensive pipelines. SOCs need to adopt these capabilities to triage the rising volume of alerts, freeing up human analysts to focus on the most critical threats. Read the full blog for a deep dive into these real-world attacker prompts and case studies.&#xA0; Top security headlines of the week&#xA0;Cyber attack hits Liechtenstein, with 31,000 records stolen&#xA0; The country has a population of around 41,000. The target was the \"register of beneficial owners,\" a database containing the names and other details of the de facto owners of companies, foundations, or trusts. (Yahoo News)&#xA0; Decades-old BMC vulnerability exposes thousands of data centers to attacks&#xA0; Found in most server platforms, Baseboard Management Controllers enable server management operations even without a working operating system and typically represent some of the most privileged control points in a data center. (SecurityWeek)&#xA0; Keyv npm package compromised in Shai-Hulud attack&#xA0; Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer&#x2019;s entire package portfolio. (Cyber Security News)&#xA0; How volunteer cyber experts are helping protect rural water systems&#xA0; DEF CON Franklin is the U.S.&#x2019; first significant attempt to connect volunteer security professionals with woefully unprotected critical infrastructure operators. (Cybersecurity Dive)&#xA0; Can&#x2019;t get enough Talos?&#xA0;\"I pay you $200 a month!\" - When threat actors argue with AI&#xA0; This week on Beers with Talos, researcher Arnaud Zobec joins the team to discuss what happens when attackers leave behind AI prompt logs, agent configurations and other unexpected artifacts.&#xA0; Tales from the Frontlines&#xA0; On Tuesday, August 11, Talos IR will be hosting an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents our customers faced in Q2 2026. This isn&#x2019;t a rehashing of the report itself, but a candid discussion of what happened, how we handled it, and what it means for your organization.&#xA0; Q2 Talos IR Trends: Phishing and authentication abuse spike&#xA0; From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, Lexi and Amy explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage.&#xA0; Upcoming events where you can find Talos&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, Arizona&#xA0;VB (Oct. 14 -16) Seville, Spain&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: Win.Worm.Coinminer::1201**&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe&#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; &#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"dictate-metaphor-security-strategy","countryCodes":["DE","ES","LI","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/","type":"report","title":"Cisco Talos: Why metaphor may dictate your security strategy"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-06T18:00:01.000Z","addedAt":"2026-08-06T18:52:41.992Z","updatedAt":"2026-08-06T18:52:41.992Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"c4ee77a3-7952-4ca9-8ac2-c5afd720bd53","slug":"talos-uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-c08de417","externalId":"6a511e0b501b2f00010617e7","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign","description":"Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least&#xA0;June&#xA0;2025.&#xA0;&#xA0;Talos has discovered that the actor in this campaign delivers a Python-based&#xA0;remote&#xA0;access&#xA0;tool (RAT) that we track as &#x201C;Starland RAT&#x201D;&#xA0;and a&#xA0;command-and-control (C2)&#xA0;memory implant known as the &#x201C;WLDR agent.&#x201D;&#xA0;The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a&#xA0;Runspace&#xA0;execution engine for executing&#xA0;additional&#xA0;payloads.&#xA0;&#xA0;UAT-11795 also&#xA0;has&#xA0;CastleStealer&#xA0;and&#xA0;Remcos&#xA0;RAT as alternative payload implants in their arsenal.&#xA0;The actor targets victims&apos; credentials and cryptocurrency wallet assets,&#xA0;establishing&#xA0;a persistent connection to the victims&apos; machines from the C2&#xA0;server, with the potential to deliver and execute further payloads.&#xA0;Victimology&#xA0;According to the telemetry data, the infection is&#xA0;predominantly observed&#xA0;in the United States.&#xA0;There are also&#xA0;fewer potential impacts&#xA0;observed&#xA0;in Germany, Romania, and Venezuela,&#xA0;based on&#xA0;the&#xA0;assessment of the&#xA0;passive DNS resolution data of the C2 domains associated with this campaign.&#xA0; Figure 1.&#xA0;Victimology map of this campaign.Talos has&#xA0;observed&#xA0;that the threat actor in this campaign has utilized&#xA0;trojanized&#xA0;installer lures from software categories including:&#xA0; Trojanized&#xA0;installer&#xA0;&#xA0; Software name&#xA0; Software category&#xA0; MobaXterm_v26.1.exe&#xA0; MobaXterm&#xA0; SSH, remote desktop, and network administration terminal&#xA0; WebEx_Client.exe and Zoom installer&#xA0; Cisco&#xA0;WebEx&#xA0;and Zoom&#xA0; enterprise video conferencing and collaboration platforms&#xA0; dbeaver-ce-windows-x86_64.exe&#xA0; DBeaverCommunity Edition&#xA0; open-source database management and SQL client&#xA0; FaceitInstaller_x64.exe&#xA0; FACEIT&#xA0; online gaming platform&#xA0; The breadth of&#xA0;trojanized&#xA0;software across developer tooling, IT administration utilities, enterprise collaboration platforms, and a consumer gaming application suggests the actor is&#xA0;operating&#xA0;an opportunistic, volume-driven distribution model targeting multiple victim profiles simultaneously,&#xA0;rather than a single vertical.&#xA0; Threat actor&#xA0;infrastructure&#xA0;Figure&#xA0;2.&#xA0;Cisco Umbrella domain resolution statistics for the malicious domains during the research window.The threat actor in this campaign&#xA0;operates&#xA0;a distributed infrastructure across two functional categories, payload staging and persistent&#xA0;C2,&#xA0;with domain naming conventions chosen to blend into legitimate traffic categories.&#xA0;The staging domains,&#xA0;including&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;(likely a&#xA0;hijacked domain),&#xA0;&#x201C;web-devtools[.]com&#x201D;&#xA0;(resembles&#xA0;a developer tooling portal),&#xA0;and &#x201C;zynaris[.]io&#x201D;&#xA0;(resembles a&#xA0;technology start-up),&#xA0;with each domain serving a narrow functional role:&#xA0;&#xA0; &#x201C;eorthopaedics[.]com&#x201D;&#xA0;and &#x201C;sastoro[.]com&#x201D;&#xA0;hosts the PowerShell stage chain under&#xA0;&#x201C;/feed/&#x201D;&#xA0;and &#x201C;/alpha/&#x201D; paths&#xA0;indicating&#xA0;that&#xA0;the actor&#xA0;has added the malicious routing alongside the legitimate contents.&#xA0;&#x201C;web-devtools[.]com&#x201D;&#xA0;serves raw shellcode payloads under the paths (&#x201C;/starlandfox&#x201D;,&#xA0;&#x201C;/x32remka&#x201D;,&#xA0;&#x201C;/dopfile&#x201D;) and a compressed archive.&#xA0;&#x201C;zynaris[.]io&#x201D;&#xA0;hosts the potential&#xA0;ClickFix-delivered&#xA0;HTML application (HTA)&#xA0;stager and&#xA0;trojanised&#xA0;installer lures.&#xA0;The C2 infrastructure is similarly distributed, with&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;and&#xA0;&#x201C;sastoro[.]com&#x201D;&#xA0;both serving&#xA0;hardware-bound unique identifier&#xA0;(HWID)&#xA0;encrypted envelopes over HWID parameterized URL paths with&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;under&#xA0;&#x201C;/feed/&#x201D;&#xA0;and&#xA0;&#x201C;sastoro[.]com&#x201D;&#xA0;under&#xA0;&#x201C;/alpha/&#x201D;.&#xA0;This&#xA0;suggests that&#xA0;the two domains&#xA0;represent&#xA0;parallel C2 infrastructure used for the same campaign.&#xA0; The domains&#xA0;&#x201C;windowscreenrepairnearme[.]com&#x201D;&#xA0;(which&#xA0;is&#xA0;also likely&#xA0;to be a hijacked&#xA0;domain)&#xA0;and&#xA0;&#x201C;aipythondevs[.]com&#x201D;&#xA0;serve&#xA0;as the&#xA0;primary&#xA0;C2 for the Starland Python RAT. All C2 URLs incorporate a victim hardware identifier derived from the C: drive&#xA0;volume serial number of the victim machine as the final URL path&#xA0;component, enabling the distinct C2 communication for each of the compromised victims. The actor in this campaign has also implemented C2 infrastructure resilience by using a Polygon smart contract&#xA0;(&#x201C;0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba&#x201D;),&#xA0;which stores an XOR-encrypted fallback C2 domain&#xA0;that is&#xA0;retrievable via a public JSON-RPC call.&#xA0;&#xA0; Talos discovered that the actor controls two&#xA0;Telegram bots,&#xA0;&#x201C;8384531459&#x201D;&#xA0;(&#x201C;skuefq_bot&#x201D;) and&#xA0;&#x201C;7993597060&#x201D;&#xA0;(&#x201C;komandastuk_bot&#x201D;),&#xA0;used for receiving the implant&#x2019;s execution notification beacons,&#xA0;including messages with victim&#x2019;s machine fingerprints and cryptocurrency&#xA0;wallet inventories.&#xA0; Figure&#xA0;3.&#xA0;Actor-controlled&#xA0;Telegram channel.&#xA0; Talos&#x2019;&#xA0;research&#xA0;uncovered a&#xA0;private live&#xA0;Telegram channel&#xA0;called&#xA0;&#x201C;stuk&#xA0;komanda&#x201D;,&#xA0;controlled by the same threat actor.&#xA0;The&#xA0;stuk&#xA0;komanda&#xA0;channel was created on June 5,&#xA0;2025,&#xA0;and has three&#xA0;unknown subscribers. It does not&#xA0;contain&#xA0;any chat groups and appears to be structured like a C2. The channel lists messages in the name of file names that&#xA0;appear to be&#xA0;Windows-based binaries, highlighting that the threat actor&#xA0;has been&#xA0;active since at least June 2025.&#xA0; Figure&#xA0;4.&#xA0;Messages seen&#xA0;on&#xA0;the&#xA0;Telegram channel.&#xA0; Multi-stage attack summary&#xA0;Figure&#xA0;5.&#xA0;Infection chain summary diagram.&#xA0;The threat actor&#xA0;executed&#xA0;a multistage campaign that involves deploying a weaponized HTA&#xA0;downloader via Microsoft HTML Application Host (&#x201C;mshta.exe&#x201D;) on the victim&apos;s machine,&#xA0;likely utilizing&#xA0;a&#xA0;ClickFix&#xA0;technique. The execution of the HTA file results in the downloading and execution of&#xA0;trojanized&#xA0;installers bundled with a malicious Python package, which sends the implant status of the installer to an attacker-controlled Telegram bot. The NSIS script associated with the&#xA0;trojanized&#xA0;installer is designed to execute the malicious byte-compiled Python code encapsulated within the installer file.&#xA0; This&#xA0;initial&#xA0;byte-compiled Python code acts as a loader that decodes and executes an embedded Python RAT, which we are calling Starland RAT, in the victim&apos;s machine memory. Starland RAT offers a wide range of functionalities and has been specifically engineered to&#xA0;operate&#xA0;within the Windows environment. Its capabilities include&#xA0;defense evasion techniques,&#xA0;system reconnaissance,&#xA0;stealing&#xA0;browser data and cryptocurrency&#xA0;wallets, and&#xA0;a fallback C2 connection mechanism that includes a hardcoded C2 URL, as well as a&#xA0;Polygon&#xA0;Ethereum&#xA0;smart&#xA0;contract&#xA0;that serves&#xA0;as a backup. This connection allows it to interact with the smart contract through Eth_call, dynamically resolving the C2 domains. The RAT sends the reconnaissance information to the C2 to register the victim&apos;s machine and is proficient in receiving and executing intermediate payloads in several formats, including&#xA0;shellcode for 64-bit and 32-bit Windows environments, directly executing Windows shell commands, and downloading and executing malicious EXE, MSI, and DLL files.&#xA0; Talos has&#xA0;observed&#xA0;that the threat actor has distinct infection chains for each type of intermediate payload that Starland RAT receives from the C2. In the case of an x64 shellcode intermediate payload, it implants&#xA0;CastleStealer&#xA0;as the final payload.&#xA0;CastleStealer&#xA0;is a .NET stealer that targets credentials, cryptocurrency&#xA0;wallets, Telegram data, and other browser data from the victim&apos;s machine. Similarly, the x32 shellcode implants a variant of the&#xA0;Remcos&#xA0;RAT.&#xA0; Furthermore, Talos has&#xA0;observed&#xA0;that the threat actor executed a Windows&#xA0;shell command through Starland RAT as an intermediate payload to download and execute a PowerShell stager. This stager is&#xA0;associated with an undocumented PowerShell C2 framework, which we track as &#x201C;WLDR C2&#x201D;&#xA0;in alignment with&#xA0;the internal project designation used by the threat actor in the PowerShell scripts. The PowerShell stager is heavily obfuscated and is designed to decrypt an embedded next-stage PowerShell loader. The second-stage PowerShell loader script has capabilities for defense evasion, connects to the C2, downloads a JSON response, and processes this response to execute another embedded PowerShell payload, the WLDR agent, in the victim&apos;s machine memory. The WLDR agent is a bespoke PowerShell script that receives its C2 address through the PowerShell loader injected global variable at the time of execution. The WLDR agent employs capabilities including encrypted HTTP beaconing, comprehensive host reconnaissance, a robust reconnection protocol, and a modular task execution engine to further execute the malicious PowerShell scripts as directed by the threat actor from the WLDR C2 server.&#xA0; Initial&#xA0;vector&#xA0;The threat actor&#xA0;gains&#xA0;initial access to the victim machine&#xA0;potentially&#xA0;through a&#xA0;ClickFix&#xA0;social engineering technique that entices the user to execute a command, which&#xA0;then&#xA0;stealthily downloads and executes a remotely hosted weaponized HTA file. The HTA file runs an embedded VBScript that drops a Windows batch file into the user profile&#x2019;s application temporary folder, which&#xA0;contains&#xA0;instructions to first download and implant a&#xA0;trojanized&#xA0;installer from the attacker-controlled staging domain onto the victim machine.&#xA0; Once the&#xA0;trojanized&#xA0;installer is executed, the batch file sends a notification beacon to an attacker-controlled Telegram bot,&#xA0;&#x201C;8384531459&#x201D;,&#xA0;to confirm successful execution to the threat actor. At the same time, the VBScript&#xA0;establishes&#xA0;persistence under&#xA0;&#x201C;HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run&#x201D;&#xA0;with the generic value&#xA0;&#x201C;MyApp&#x201D;,&#xA0;pointing back to&#xA0;&#x201C;mshta.exe&#x201D;&#xA0;to execute the remotely hosted weaponized HTA file every time the victim logs in to the machine. Talos&#xA0;identified&#xA0;a Russian-language developer comment left in the VBScript (&#x201C;&#x414;&#x43E;&#x431;&#x430;&#x432;&#x43B;&#x435;&#x43D;&#x438;&#x435;&#xA0;&#x43A;&#x43E;&#x43C;&#x430;&#x43D;&#x434;&#x44B;&#xA0;&#x432;&#xA0;&#x430;&#x432;&#x442;&#x43E;&#x437;&#x430;&#x43F;&#x443;&#x441;&#x43A;&#xA0;&#x434;&#x43B;&#x44F;&#xA0;&#x442;&#x435;&#x43A;&#x443;&#x449;&#x435;&#x433;&#x43E;&#xA0;&#x43F;&#x43E;&#x43B;&#x44C;&#x437;&#x43E;&#x432;&#x430;&#x442;&#x435;&#x43B;&#x44F;&#x201D;),&#xA0;indicating&#xA0;that a Russian-speaking actor is conducting this campaign.&#xA0; Figure&#xA0;6.&#xA0;Weaponized HTA file that downloads and executes&#xA0;trojanized&#xA0;installers.&#xA0;Python&#xA0;loader packaged into&#xA0;trojanized&#xA0;installers&#xA0;Talos has&#xA0;observed&#xA0;that the threat actor in this campaign has weaponized software installers by&#xA0;utilizing&#xA0;the&#xA0;Nullsoft&#xA0;Scriptable Install System (NSIS). They have packaged the Python runtime executable&#xA0;&#x201C;pythonw.exe&#x201D;&#xA0;along with a compiled Python loader, which is disguised as a license file named&#xA0;&#x201C;LICENSE.txt&#x201D;.&#xA0;The threat actor has&#xA0;modified&#xA0;the&#xA0;NSI&#xA0;script file of the installer to include instructions for executing&#xA0;the compiled Python loader using the Python runtime executable.&#xA0;&#xA0; Figure&#xA0;7.&#xA0;Install section of the&#xA0;NSI&#xA0;script of a sample&#xA0;trojanized&#xA0;installer.&#xA0;The compiled Python loader is a&#xA0;relatively large&#xA0;file obfuscated with&#xA0;numerous&#xA0;junk functions that perform random arithmetic operations and print randomly generated strings to the standard output. The actual execution logic is confined to six lines in the loader program, implementing XOR decryption using the XOR key 198 (0xC6) to decrypt the encrypted embedded payload of&#xA0;Starland RAT&#xA0;and execute it&#xA0;in the victim machine&apos;s memory. Figure&#xA0;8.&#xA0;Snippet of the decompiled&#xA0;Python loader program.Starland&#xA0;RAT, a&#xA0;Python-based&#xA0;RAT&#xA0;Starland is a Python-based&#xA0;remote&#xA0;access&#xA0;tool (RAT) with the capability to steal cryptocurrency. During its&#xA0;initial&#xA0;execution phase, the RAT resolves and declares all required Windows API function signatures through Python&#x2019;s&#xA0;ctypes&#xA0;interfaces. It directly loads&#xA0;&#x201C;kernel32.dll&#x201D;&#xA0;using&#xA0;WinDLL&#xA0;and explicitly defines the argument types and return types for every Win32 call used later in execution, including VirtualAllocEx,&#xA0;WriteProcessMemory,&#xA0;CreateRemoteThread,&#xA0;VirtualProtectEx,&#xA0;CreateProcessA,&#xA0;QueueUserAPC, and&#xA0;ResumeThread. Custom&#xA0;ctypes&#xA0;Structure subclasses are declared for SECURITY_ATTRIBUTES, STARTUPINFO, and PROCESS_INFORMATION, mirroring the definitions in the Windows SDK. This API mapping mechanism ensures that all injection and process manipulation calls later in execution are ready without further need for Windows API imports or dynamic resolution.&#xA0; Figure&#xA0;9.&#xA0;Snippet of the Starland RAT function for resolving and declaring the Windows API&#xA0;functions.&#xA0;Before any malicious logic executes, the RAT conducts&#xA0;check&#xA0;for anti-analysis environments. First, it compares the logged-on username of the victim machine against a hardcoded list of usernames, which includes known sandbox service accounts and aliases, including&#xA0;WDAGUtilityAccount. Next, the RAT verifies the victim&apos;s computer name against&#xA0;a&#xA0;list of hostnames from recognized sandbox environments, such as Cuckoo,&#xA0;Any.Run, Joe Sandbox, and Hybrid Analysis. If either check matches, the RAT&apos;s execution&#xA0;terminates&#xA0;immediately. Additionally, the RAT examines the Downloads folder for a&#xA0;Zone.Identifier&#xA0;alternate data stream on the&#xA0;trojanized&#xA0;installer file, confirming that the file was obtained via a browser download rather than being uploaded or copied directly.&#xA0; Figure&#xA0;10.&#xA0;Snippet of Starland RAT showing the hardcoded list of usernames and computer names for&#xA0;detection of&#xA0;evasion checks.&#xA0;The RAT&#xA0;establishes&#xA0;persistence before any network communication with the C2 takes place. The primary mechanism involves creating a scheduled task using the PowerShell New-ScheduledTask command, with a randomized name following the pattern PythonLauncher-{3 random characters}. When executed with administrator privileges, the trigger is set to&#xA0;AtLogOn&#xA0;with&#xA0;RunLevel&#xA0;Highest, ensuring the elevated re-execution of the RAT at every user logon. Additionally, a secondary Startup folder LNK shortcut is created via the&#xA0;WScript.Shell&#xA0;COM object, placed in the user&apos;s Startup directory, targeting&#xA0;&#x201C;pythonw.exe&#x201D;&#xA0;with LICENSE.txt&#xA0;as its argument. If the RAT is not already running with elevated privileges, it also&#xA0;attempts&#xA0;UAC elevation via&#xA0;ShellExecuteW&#xA0;with the runasverb, aiming to upgrade the scheduled task to the higher-privilege logon before&#xA0;proceeding.&#xA0; Figure&#xA0;11.&#xA0;Snippet of Starland RAT with the instructions for&#xA0;establishing&#xA0;persistence.&#xA0;It performs system reconnaissance, assembling the victim profile that includes the system hardware-bound unique identifier (HWID), total RAM size of the victim machine, and installed antivirus by executing the following commands:&#xA0; Get-CimInstance -Class Win32_ComputerSystemProduct.UUID&#xA0;&#xA0; wmic memorychip get Capacity&#xA0;&#xA0;&#xA0; Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntiVirusProduct The RAT also conducts Active Directory reconnaissance via the PowerShell command Get-WmiObject Win32_ComputerSystem.Domain. If the victim is identified as a member of Active Directory, the RAT executes the following commands to collect information about domain structure, domain controllers, and the victim&#x2019;s domain privileges:&#xA0; whoami && systeminfo && net user {USERNAME} /dom && nltest /dclist For workgroup-only hosts, it executes the whoami /all command. The reconnaissance data collected are staged by the RAT for inclusion during the victim machine registration to the primary C2 domain hardcoded in the RAT program. It also captures a screenshot of the victim machine&apos;s desktop, saves it as a PNG in the RAT&#x2019;s working directory, generates a&#xA0;Base64-encoded string for the PNG file in memory, stages it alongside the reconnaissance data, and deletes the PNG file from the disk.&#xA0; Additionally, it gathers the victim&#x2019;s cryptocurrency assets information by&#xA0;enumerating&#xA0;the desktop&#xA0;cryptocurrency&#xA0;wallets and browser extension wallets, checking for the presence of over 40 cryptocurrency&#xA0;wallets.&#xA0;The collected data&#xA0;is also staged alongside the reconnaissance data and the&#xA0;Base64-encoded screenshot (PNG)&#xA0;data. The&#xA0;RAT consolidates all collected data into a single JSON file, XOR encrypts it with the 5-byte key &#x201C;helo1&#x201D;,&#xA0;Base64-encodes it, and sends it to the primary C2 through&#xA0;an HTTP POST request using the HTTP user-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)&#xA0;AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36.&#xA0;&#xA0; If the primary C2 registration fails, the RAT enables a blockchain-anchored fallback mechanism. An eth_call is triggered via JSON-RPC to the public Polygon RPC endpoint&#xA0;&#x201C;polygon-rpc[.]com&#x201D;,&#xA0;targeting the smart contract &#x201C;0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba&#x201D; and function selector &#x201C;0xc659f3b8&#x201D; for the latest block. The encrypted hexadecimal string that the RAT receives from the smart contract is XOR-decrypted with the key &#x201C;$m7*rYpry3&#x201D; to recover a fallback domain to which the RAT sends the victim machine registration request along with the reconnaissance and screenshot data.&#xA0; Before transmitting the reconnaissance information to the C2 for the victim&apos;s machine registration, the RAT sends a notification message to the attacker-controlled Telegram bot using hardcoded credentials. The message includes the victim&apos;s public IP address sourced from&#xA0;&#x201C;api64.ipify[.]org&#x201D;,&#xA0;the build name, region locale, computer name presented as a&#xA0;&#x201C;Crew ID&#x201D;&#xA0;field, OS platform and release, processor string, and the hardcoded label&#xA0;&#xA0; \"Windows Defender&#x201D;&#xA0;as the protection application indicator. If any Chrome cryptocurrency&#xA0;wallet extensions or desktop cold wallet applications were detected during the reconnaissance phase, they were also appended to the message of the Telegram bot, providing the threat actor with visibility into the victim profile and cryptocurrency&#xA0;assets before the actual registration of the victim machine to the C2.&#xA0; Figure&#xA0;12.&#xA0;Starland RAT&#x2019;s&#xA0;Telegram bot message beaconing function.After the RAT registers the&#xA0;compromised&#xA0;machine with the C2, it sends a GET request to the C2 server every 50&#xA0;&#x2013;&#xA0;60 seconds. It&#xA0;contains&#xA0;minimal JSON content with two randomly named junk fields and the bot&apos;s unique identifier, encoded using the same XOR key &#x201C;helo1&#x201D; and then&#xA0;Base64&#xA0;encoded. The C2 server responds with one of the&#xA0;four&#xA0;commands supported by the RAT:&#xA0; Commands&#xA0; Action&#xA0; shellexecute&#xA0; Runs an arbitrary shell string via &#x201C;cmd&#xA0;/c&#x201D; or PowerShell and returns the output to the&#xA0;C2 server through&#xA0;HTTP POST&#xA0;request.&#xA0; x32&#xA0; Receives a 32-bit shellcode&#xA0;URL&#xA0;and executes&#xA0;the&#xA0;shellcode that is&#xA0;staged&#xA0;using&#xA0;the&#xA0;asynchronous procedure&#xA0;call&#xA0;(APC), process&#xA0;injection technique.&#xA0; x64&#xA0; Receives a 64-bit shellcode URL and executes the&#xA0;shellcode that is staged using the&#xA0;asynchronous procedure&#xA0;call&#xA0;(APC), process injection technique.&#xA0; download&#xA0;&#xA0; Downloads the&#xA0;payload file to the&#xA0;&#x201C;%TEMP%&#x201D;&#xA0;folder and executes it by file extension, supporting EXE, MSI, DLL,&#xA0;and ZIP formats with&#xA0;appropriate&#xA0;execution&#xA0;methods.&#xA0; HTTP&#xA0;403&#xA0;response&#xA0; Triggers the self-deletion of the RAT file and exits its process, functioning as a kill switch.&#xA0;&#xA0; Figure&#xA0;13.&#xA0;Starland RAT command processing function.&#xA0;Windows&#xA0;shell command deploys&#xA0;bespoke&#xA0;WLDR&#xA0;agent C2&#xA0;implant&#xA0;In the current campaign investigation, Talos discovered that the threat actor executed a&#xA0;curl command to download and execute&#xA0;additional&#xA0;PowerShell script payloads of the WLDR C2 framework from another C2.&#xA0;&#xA0; Figure 14.&#xA0;curl&#xA0;command to download the WLDR stager.WLDR stager&#xA0;The WLDR stager PowerShell script&#xA0;represents&#xA0;the&#xA0;initial&#xA0;stage, where it&#xA0;establishes&#xA0;a loop counter and two&#xA0;boolean&#xA0;flags for execution states. Each state creates a runtime alias for PowerShell command execution, resolving .NET&#xA0;Base64 and byte conversion types through an obfuscated string construction mechanism. It also defines an inline decryption routine that XOR decrypts the next stage, which is the embedded encrypted WLDR downloader PowerShell script, using a dynamically computed XOR key.&#xA0; Figure 15.&#xA0;Snippet of the WLDR PowerShell stager script.&#xA0;WLDR downloader&#xA0;&#xA0;WLDR downloader is a compact HWID-bound loader script. Upon execution, it derives a hardware identifier from the victim&#x2019;s C: drive volume serial number, converts it from hexadecimal to a decimal number, and appends it to two hardcoded C2 URLs for victim-specific payload delivery and a persistent agent task channel. It then issues an&#xA0;HTTP GET&#xA0;request to the C2, and the C2 server only responds to requests whose HWID matches a pre-registered value. The C2 server response is an encrypted JSON envelope&#xA0;containing&#xA0;fields with a&#xA0;Base64-encoded salt, initialization vector, encrypted data, and authentication tag.&#xA0; The WLDR loader processes the JSON response by decrypting the envelope through an inline decryption routine using a derived 64-byte key from a hardcoded plaintext password &#x201C;odg5t8mvssvh&#x201D; and the salt received from the C2 server in the JSON response. This is followed by the decryption of the encrypted data, which is the next stage of the WLDR agent PowerShell C2 memory implant. Before executing the WLDR agent, it writes the C2 URL and the plaintext password into the global PowerShell scope, making both available for the WLDR agent as its C2 address and session encryption key for all&#xA0;subsequent&#xA0;communication with the C2.&#xA0; Figure 16.&#xA0;Snippet of the WLDR PowerShell downloader.Figure 17.&#xA0;Sample JSON response from the C2 server.Bespoke&#xA0;WLDR&#xA0;C2 agent&#xA0;implant&#xA0;The WLDR agent is a fully featured PowerShell remote access client that&#xA0;operates&#xA0;entirely in memory. It implements encrypted C2 communications, concurrent task execution through a managed&#xA0;Runspace&#xA0;engine, and a module delivery framework that provides the threat actor with interactive remote PowerShell execution capabilities on the victim&apos;s machine.&#xA0; Upon execution, the agent initializes the server&apos;s URL to a development placeholder and&#xA0;immediately&#xA0;checks for a globally scoped URL and session encryption password that were set by the WLDR loader script. If found, it overwrites the placeholder with the C2 URL and inherits the session encryption password, while also configuring other operational parameters, including polling interval, HTTP timeout, retry counts for the C2 reconnect cycle, and the number of threads for the&#xA0;Runspace&#xA0;pool.&#xA0; Figure 18.&#xA0;Snippet of the WLDR agent with the configuration parameters.Before&#xA0;initiating&#xA0;the C2 connectivity, it implements a mutex &#x201C;f2j398fj239d8j23dkkskskkkkkkkkk&#x201D; to prevent duplicate instances and performs a dependency check on the inherited session encryption password. If the password is not found, the agent exits its execution. The network communication is encrypted using AES-256-CBC with HMAC-SHA256 in an&#xA0;encryption,&#xA0;then Message Authentication Code (MAC) construction, with session keys derived through PBKDF2-SHA256 over a randomly generated salt at 5,000 iterations. The protocol version tag WSv1 is bound to every MAC computation, with a new random&#xA0;initialization vector (IV)&#xA0;generated for each message.&#xA0; The agent performs reconnaissance via WMI queries, gathering information on antivirus products, network adapter configurations,&#xA0;OS&#xA0;version and build, domain membership, CPU, RAM, administrative privilege status, and UAC policy. A hardware identifier is primarily derived from the C: drive volume serial number; if that fails, it queries the&#xA0;machine&apos;s&#xA0;registry for the GUID or generates a checksum of the host&#xA0;name, which is appended to all C2 URLs. The&#xA0;initial&#xA0;connection to the C2 is&#xA0;established&#xA0;through an&#xA0;HTTP POST&#xA0;that includes the victim machine profile, the infection identifier, protocol version 2.0.0, and the cryptographic session parameters, with a connection retry timing set to 30 seconds. All&#xA0;subsequent&#xA0;traffic is sent to C2 over HTTPS, with headers designed to mimic a Chrome browser session in version 124.&#xA0; Figure 19.&#xA0;Snippet of WLDR agent C2 handshake function.After&#xA0;establishing&#xA0;the initial connection with the C2, the agent polls the C2 server every 10 seconds. The response from the C2 server can include either commands or tasks, with the only hardcoded command in the agent&#xA0;being&#xA0;a kill instruction that triggers instance termination, while tasks are queued for execution.&#xA0; Figure&#xA0;20.&#xA0;Snippet of WLDR agent&#x2019;s C2 polling function.&#xA0;During our research, we&#xA0;observed&#xA0;that the&#xA0;initial&#xA0;response from the C2 was the idle polling interval response, which included empty fields in both the &#x201C;commands&#x201D; and &#x201C;tasks&#x201D; arrays.&#xA0; Figure&#xA0;21.&#xA0;Initial WLDR agent polling response from the C2. Further analysis of the&#xA0;agent&#xA0;program&#xA0;disclosed&#xA0;that the C2 responses&#xA0;to the polling will&#xA0;contain&#xA0;encrypted PowerShell&#xA0;commands or&#xA0;scripts,&#xA0;which&#xA0;are decrypted using the same hardcoded password&#xA0;and executed&#xA0;through one of the two runtime engines&#xA0;defined in&#xA0;the backdoor&#xA0;program.&#xA0;&#xA0; The primary&#xA0;agent execution&#xA0;engine is a PowerShell&#xA0;RunspacePool&#xA0;supporting&#xA0;up to&#xA0;10 concurrent threads.&#xA0;Each PowerShell script payload delivered by the C2 is wrapped with&#xA0;details of execution context and parameters as in scope variables along with event handlers on&#xA0;the script&#x2019;s execution&#xA0;result of&#xA0;output,&#xA0;error,and warnings.&#xA0;These event handlers registered on the output, error,&#xA0;and warning streams are triggered synchronously&#xA0;as the script execution output is produced, packaging results into stream messages and forwards them to the C2 in real time&#xA0;without waiting for the script execution completion.&#xA0;&#xA0; This message streaming capability makes the&#xA0;WLDR agent&#x2019;s&#xA0;Runspace&#xA0;engine&#xA0;favorable&#xA0;for the interactive operations such as&#xA0;continuous&#xA0;monitoring where the command output reaches the threat actor incrementally,&#xA0;rather&#xA0;than after the completion of the script execution.&#xA0;&#xA0; Figure&#xA0;22.&#xA0;WLDR agent function of handling the&#xA0;Runspace&#xA0;engine.&#xA0;If the&#xA0;Runspace&#xA0;engine&#xA0;fails to&#xA0;initialize the payload, PowerShell script execution defaults to standard PowerShell background jobs. It injects parameters and launches the script as a background job; however, unlike the&#xA0;Runspace&#xA0;path, it collects output only after the job completes, making it suitable only for short-lived batch tasks.&#xA0; Figure&#xA0;23.&#xA0;WLDR agent PowerShell job execution handlers.&#xA0;Other payloads of Starland RAT campaign&#xA0;Talos has discovered that the threat actor&#xA0;possesses&#xA0;additional&#xA0;malware, including&#xA0;CastleStealer&#xA0;and&#xA0;Remcos&#xA0;RAT, which can be deployed as payloads to the victim&apos;s machine via the Starland RAT. To deliver these payloads, the threat actor&#xA0;utilizes&#xA0;a custom shellcode loader for both x64 and x32 machines, encapsulating the embedded encrypted binaries of the payloads.&#xA0; The shellcode loader resolves all required Windows APIs entirely at runtime by&#xA0;enumerating&#xA0;the list of loaded modules in the&#xA0;OS&#xA0;memory, iterating through each module&apos;s export directory, and comparing a hash of each function name against stored target values. The shellcode neutralizes both the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) through two sequential bypass mechanisms. The primary technique resolves the target functions AmsiScanBuffer&#xA0;in&#xA0;&#x201C;amsi.dll&#x201D;&#xA0;and&#xA0;EtwEventWrite&#xA0;in&#xA0;&#x201C;ntdll.dll&#x201D;&#xA0;using runtime hash-based API resolution, then overwrites their first bytes in memory with a patch that forces AMSI to always return a clean scan result and the ETW write function to return immediately without writing the output, effectively neutralizing both interfaces. If the primary patching technique fails, the shellcode executes a fallback mechanism where it calls&#xA0;VirtualProtect&#xA0;to temporarily change the target function&apos;s memory page protection value to read-write-execute and writes the same patch bytes directly, then restores the original page protection.&#xA0; Figure 24.&#xA0;Shellcode snippet of instructions for AMSI bypass.&#xA0;Then, it decrypts the embedded encrypted payload blob and decompresses the decrypted data using LZX decompression into a newly&#xA0;allocated&#xA0;memory region. The payload is&#xA0;subsequently&#xA0;dispatched either by the reflective PE injection technique or by .NET CLR loading through the&#xA0;ICorRuntimeHost&#xA0;COM interface for .NET binaries, or through the PowerShell&#xA0;Runspace&#xA0;for PowerShell scripts.&#xA0; Figure 25.&#xA0;Shellcode snippet of decryption function and decrypted payload in memory.&#xA0;Talos discovered that the threat actor&#xA0;can deliver&#xA0;CastleStealer&#xA0;implant&#xA0;through the x64 shellcode and the&#xA0;Remcos&#xA0;RAT through the x32 shellcode variant.&#xA0;&#xA0; CastleStealer&#xA0;is a .NET-based infostealer and credential harvesting implant designed to systematically extract sensitive data from compromised Windows hosts. It incorporates several anti-analysis measures,&#xA0;including a Russian locale exclusion check and a hardcoded build expiry timestamp, ensuring it executes only against genuine targets within a defined operational window. Its credential theft surface is broad, targeting the full Chromium browser family and Firefox through direct SQLite database access, with decryption support for both legacy DPAPI-protected credentials and the AES-GCM application&#xA0;bound encryption scheme. Beyond browser data, it&#xA0;enumerates&#xA0;crypto wallet browser extensions, Discord and Telegram session files, Steam account credentials, and targeted filesystem paths, transmitting all collected material over a TCP socket to&#xA0;the attacker-controlled infrastructure.&#xA0;CastleStealer&#x2019;s&#xA0;secondary payload delivery capability allows the&#xA0;actor&#xA0;to&#xA0;implant further payloads&#xA0;through process injection&#xA0;technique&#xA0;or PowerShell&#xA0;script&#xA0;execution.&#xA0;&#xA0; Figure 26.&#xA0;Snippet of&#xA0;CastleStealer&#xA0;malware&#xA0;function.&#xA0;Remcos&#xA0;RAT (Remote Control and Surveillance) is a&#xA0;commercial&#xA0;remote access tool originally&#xA0;sold&#xA0;as a legitimate remote administration tool. However, it has been&#xA0;extensively abused by&#xA0;a wide range of&#xA0;threat actors&#xA0;since its emergence in 2016. It provides operators with&#xA0;comprehensive post-exploitation capabilitiesincluding real-time keylogging, screen and webcam capture, audio recording, file management, shell command execution, and clipboard&#xA0;monitoring&#xA0;all&#xA0;communicated over an encrypted channel to a configurable C2 server.&#xA0;&#xA0; Coverage&#xA0;The following ClamAV signature detects and blocks this threat:&#xA0; Txt.Downloader.Agent-10060312-0 Html.Downloader.Agent-10060313-0 Html.Downloader.Agent-10060314-0 Py.Loader.Agent-10060315-0 Py.Loader.Agent-10060316-0 Ps1.Trojan.Agent-10060317-0 Ps1.Trojan.Agent-10060318-0 Ps1.Trojan.WLDRAgent-10060319-0 Ps1.Downloader.Agent-10060320-0 Win.Trojan.CastleStealer-10060341-0 Win.Trojan.Starland_Installer-10060342-0 Win.Malware.Starland-10060343-0 Win.Malware.Remka-10060344-0 The following Snort Rules&#xA0;Snort 2 and Snort 3&#xA0;(SIDs)&#xA0;to&#xA0;detect and block this threat:&#xA0;66787 &#x2013; 66790 and 301580&#xA0;&#xA0; IOCsThe IOCs for this threat are also available at our GitHub repository&#xA0;here.&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threats","rat","cisco-talos-antivirus","cisco-talos-dns-security","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","geo:inferred"],"relatedCves":[],"titleFingerprint":"11795-bespoke-campaign-deploys-financially-implant-motivated-novel-rat-starland-uat-wldr","countryCodes":["DE","RO","RU","US","VE"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/","type":"report","title":"Cisco Talos: UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-16T10:00:01.000Z","addedAt":"2026-07-29T20:53:06.649Z","updatedAt":"2026-07-29T20:53:06.649Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":8,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:20:20.577Z","durationMs":20,"filters":{"search":null,"severity":[],"type":[],"country":["DE"],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}