ZeroHour

Search: “Payload”

11 stories in the last 24h

APT36 Uses USB-Spreading Malware to Reach Air-Gapped Government Networksnew

Zscaler attributes the RapidRust campaign by Pakistan-linked APT36 to USB-propagating Rust malware targeting air-gapped government networks in India and Afghanistan.

Zscaler identified in August 2026 a campaign tracked as RapidRust in which APT36 uses infected removable drives to reach air-gapped government environments in India and Afghanistan. RUSTYMOVE, a Rust USB-spreading utility, copies a fake-PDF shortcut and the RUSTYSHADE backdoor to removable media; RUSTYSHADE uses attacker-controlled private GitHub repositories for C2, running shell commands, capturing screenshots and webcam images, while PSNATCH and BASHNATCH steal files. Operators enumerated users, shares, and remote administrative shares to expand beyond initial victims, with payloads staged on lookalike domains mimicking Indian media outlets and Backblaze B2 storage.

Cyber Security News · 40m agoThreat actor in the wild 3 sources

The skb that wasn't freed - the Fragnesia primitive via Open vSwitch

Doyensec details CVE-2026-90049 in Open vSwitch, enabling deterministic Linux kernel local privilege escalation on default major distribution installs.

Doyensec reports that the Open vSwitch datapath strips the SKBFL_SHARED_FRAG flag from packets it is still forwarding, allowing an in-place decrypt to write attacker-chosen bytes into root-owned page cache — a Dirty COW-class primitive that re-opens the Fragnesia bug family. The issues are tracked as CVE-2026-90049, CVE-2026-89487, and CVE-2026-80977, and were reported to the kernel security team with fixes coordinated alongside OVS maintainers. A deterministic local privilege escalation works on default installs of Arch, Fedora, Debian, Amazon Linux, and RHEL where unprivileged user namespaces and openvswitch auto-loading are enabled; the fix landed in mainline and shipped in stable on 09/04/2026. The write technique builds on the earlier Fragnesia and Dirty Frag bugs, including CVE-2026-43284 and CVE-2026-43500.

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Cisco Talos reports 90 ransomware incidents hit Japanese organizations in H1 2026, led by The Gentlemen, with Qilin using AI for efficiency.

Cisco Talos observed 90 ransomware incidents against Japanese organizations from January to July 2026, up about 4.7% year over year, with manufacturing accounting for 34% of victims. The Gentlemen was the most active group with 14 incidents; its leak-site listings grew from 48 in January to 105 in July. Qilin and SafePay followed with seven incidents each, and Talos notes Qilin is leveraging AI to improve operational efficiency.

Cisco Talos · 57m agoRansomware in the wild

Malware bypasses browser checks to force install Chrome, Edge extensions

Elastic Security Labs detailed KREMLIN, a Brazilian banking malware that silently installs malicious Chrome and Edge extensions, with 1,515 confirmed infections.

Elastic Security Labs analyzed KREMLIN, a toolkit used by a Brazilian operation in at least seven campaigns since May 2025 that impersonates 12 banks to trick users into opening a JavaScript file disguised as a bank receipt or invoice. After anti-sandbox checks, it downloads Node.js, persists via a scheduled task, and fetches payload locations from an Ethereum smart contract, hiding payloads in JPEG images on Internet Archive. The toolkit bypasses Chromium integrity mechanisms to install unapproved Chrome/Edge extensions masquerading as AVSync that steal cookies, keylog form input, capture screenshots, and intercept HTTP traffic, while recent campaigns deployed the REMCOS RAT and earlier ones Pulsar RAT. Elastic confirmed 1,515 infected systems, almost all in Brazil, and disrupted the campaign by registering an anti-sandbox canary domain; the linked wallet handled roughly 20,800 USDT incoming and 19,000 USDT outgoing.

BleepingComputer · 16h agoMalware in the wild 3 sources

Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites

Infoblox links China-aligned APT PeckBirdy C2 infrastructure hidden in casino and adult websites targeting Asian government, finance, IT, and education sectors.

Infoblox researchers report that China-aligned APT groups have used casino and adult websites as cover for PeckBirdy, a JavaScript command-and-control framework active since 2023. The sites embed C2 servers, register service workers for persistence, and serve fake browser-update prompts delivering backdoors capable of running commands, stealing credentials, and providing remote access. Targeted sectors across Asia include education, IT, banking, financial services, and government. Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with detection coverage on VirusTotal ranging from 13 detections to none.

Cyber Security News · 23h agoThreat actor 2 sources

Chinese hackers use SparroWocky malware in govt espionage attacks

ESET reports China-linked FamousSparrow deployed a new modular backdoor, SparroWocky, in year-long espionage attacks on Latin American government organizations.

ESET researchers observed FamousSparrow using SparroWocky, a modular C++ backdoor replacing the earlier SparrowDoor tool, against government targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. Deployed via DLL side-loading with an RC4-encrypted payload mapped in memory, it captures screenshots, acts as a TCP proxy, and hooks CreateThread so malicious threads appear as AnimateWindow. Persistence uses a ProcAuditManager Windows service or SnapCart registry key; ESET tracked at least 18 C2 addresses and published IoCs.

BleepingComputer · 1h agoThreat actor in the wild

Fake AI trading agent steals crypto wallet passwords

Fake AI crypto trading agent sites deliver Needle Stealer, which replaces browser wallet extensions to steal wallet passwords, HP reports.

HP researchers tracked campaigns between April and June 2026 in which a fake AI trading agent site, tradingclaw[.]pro, distributed a Microsoft-signed OLEView executable that DLL side-loads a malicious iviewers.dll and launches Needle Stealer via process hollowing. Needle replaces one of seven browser wallet extensions, including MetaMask, Coinbase Wallet, and Phantom, to capture wallet passwords. Related campaigns used QR-code invoice phishing leading to fake OneDrive pages, Phantom Stealer sold as a penetration testing tool with VBScript-to-PowerShell steganographic loaders, and image-hidden payloads delivering XWorm, PureLogs Stealer, and Formbook; a perceptual-hash VirusTotal search found about 400 distinct rigged images.

Help Net Security · 2h agoMalware in the wild1

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Iranian state-linked hackers use CHOSEN BRICK Windows malware, spread via Telegram and WhatsApp social engineering, to spy on dissidents and journalists worldwide.

US, UK, and Dutch cyber agencies with the FBI issued a joint advisory on Iranian state-linked hackers deploying a Windows malware strain called CHOSEN BRICK against dissidents, activists, and journalists, primarily in the US, UK, and Netherlands. Attacks begin with messages on WhatsApp or Telegram impersonating trusted contacts or technical support, tricking victims into running malicious files disguised as apps such as Pictory, RunwayML, Norton Antivirus, Telegram, and KeePass. The malware persists via Registry Run keys, adds Microsoft Defender exclusions, and uses a per-victim Telegram bot for command-and-control while stealing email, Telegram and WhatsApp data, screenshots, and audio. Stolen data is exfiltrated via Telegram or cloud services like VultrObjects and StorjShare, and sometimes appears on pro-Iranian leak sites, increasing physical risk for dissidents abroad.

BleepingComputerupdated · 3h agofirst · 14h agoThreat actor in the wild 7 sources

CISA Warns of Critical ScreenConnect Vulnerability Actively Exploited in Attacks

CISA added actively exploited ConnectWise ScreenConnect flaw CVE-2026-84869 to the KEV catalog, setting a September 14 patch deadline.

CISA added CVE-2026-84869, a critical improper privilege management and missing authorization flaw (CWE-269, CWE-862) in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities Catalog on September 11, 2026, confirming active exploitation. The flaw lets attackers transfer files to a device and execute them during an active remote ScreenConnect session without authorization or host-user confirmation, enabling payload delivery, unauthorized tools, and persistence while blending into legitimate remote-management traffic. CISA set a September 14 remediation deadline under BOD 26-04 and flagged the vulnerability as requiring forensic triage. ConnectWise has published a security bulletin, and defenders are urged to review exposure, sessions, file-transfer records, and outbound connections.

Cyber Security News · 19h agoExploit / PoC in the wild 4 sourcesCVE-2026-848693

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls targeting Russian enterprises with Exchange backdoors, Gorilla RAT, and destructive Monkey ransomware.

Kaspersky reports three threat clusters targeting Russian enterprises: NightEagle (APT-Q-95), the pro-Ukrainian hacktivist group Hacking Cat, and Toy Ghouls. NightEagle uses compromised VPN credentials and the GhostContainer modular backdoor to fully compromise Microsoft Exchange servers, chaining CVE-2020-0688 exploitation, BlueKeep (CVE-2019-0708), Active Directory vulnerabilities, and DCSync to seize domain controllers. Hacking Cat exploits Exchange flaws including CVE-2021-26855 and CVE-2026-42897 to deliver the Gorilla RAT and multiple Monkey ransomware variants written in Rust, .NET, C++, and Golang targeting Windows, Linux, and VMware ESXi, with some variants acting as wipers that never store the encryption key.

The Hacker Newsupdated · 3h agofirst · 19h agoThreat actor in the wild 5 sourcesCVE-2020-0688CVE-2019-0708CVE-2021-26855+1 CVEs1

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Two unauthenticated CVSS 9.8 code-injection and PHP object injection flaws in The Events Calendar plugin expose 200,000+ WordPress sites to RCE and takeover.

Defiant identified two critical vulnerabilities in The Events Calendar WordPress plugin, which has over 600,000 active installations. CVE-2026-78159, unauthenticated code injection during single-event HTML processing, was patched in version 6.17.3.1 on August 25; CVE-2026-78006, unauthenticated PHP object injection via event comments, was patched in 6.17.4.1 on September 10. Both independent chains lead to remote code execution and full site compromise. Roughly 240,000 sites run versions vulnerable to both flaws, and about 300,000 downloads between September 10 and 14 suggest half of installations may still lack the second fix.