Summary & highlights
Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown Complexity. GitHub Codespaces RCE via VS Code Configuration Files. SystemBC Malware Resurges with 10K+ Infections.
Highlights
- TL-2026-0099 — Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown Complexity
- TL-2026-0100 — GitHub Codespaces RCE via VS Code Configuration Files
- TL-2026-0101 — SystemBC Malware Resurges with 10K+ Infections
- TL-2026-0104 — Screensaver (.SCR) Files Used as Initial Access Vector
- TL-2026-0106 — APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform Espionage
Theme of the day
- cisa-kev
- credential-theft
- critical-infrastructure
- fileless-execution
- pre-auth-rce
Threats published
26 threat lines in the 2026-02-16 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- CVE-2026-1731 — BeyondTrust Pre-Auth RCE, CVSS 9.8, CISA KEV, Actively Exploited — Unauthenticated OS Command Injection in Remote Support & Privileged Remote Access, SimpleHelp RAT Post-Exploitation, Full Domain Control, Silk Typhoon Predecessor ChainCRITICAL
- Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch Government Breached, Bulletproof Hosting IAB, Sleeper Webshells, 28K+ Attacking IPsCRITICAL
- n8n Multi-CVE Vulnerability Cascade — Expression Sandbox Escape, Pyodide RCE, Arbitrary File Write, Command Injection (9 CVEs, 2× CVSS 10.0) (update)CRITICAL
- Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline Operator Conpet — 4,000km Critical Infrastructure, ~1TB Exfiltrated, Chrome Credential Harvesting via GPO (update)CRITICAL
- Aisuru-Kimwolf Botnet Launches Record 31.4 Tbps DDoS — 47.1M Attacks in 2025, Night Before Christmas Campaign, 1-4M Infected Android TVs, Operator 'Forky' Identified (update)CRITICAL
- SmarterMail Dual-CVE Pre-Auth RCE Chain — CVE-2026-23760 Admin Password Reset + CVE-2026-24423 ConnectToHub RCE, CISA KEV, Mass Automated Exploitation, 2-Day Patch Weaponization via .NET Decompiler (update)CRITICAL
- Nitrogen Ransomware Coding Bug Permanently Destroys ESXi Data — Curve25519 Memory Corruption Makes Decryption Mathematically Impossible, Even Attackers Can't Decrypt, Azote Group UNC4696, Malvertising via Google/Bing Ads, Conti 2 Derivative (update)CRITICAL
- TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37 Countries, Recons 155 Nations, Novel ShadowGuard eBPF Rootkit, Diaoyu Loader, Event-Driven Geopolitical Targeting (update)CRITICAL
- Ransomware Threat Landscape 2025-2027 — RaaS Destabilization, Conti Leak Cascade, ESXi Hypervisor Targeting, BYOVD as Standard Prep, Double/Triple Extortion Economics, IAB Vertical Integration, Critical Infrastructure Escalation (update)CRITICAL
- Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown ComplexityHIGH
- GitHub Codespaces RCE via VS Code Configuration FilesHIGH
- SystemBC Malware Resurges with 10K+ InfectionsHIGH
- Screensaver (.SCR) Files Used as Initial Access VectorHIGH
- APT36/Transparent Tribe Deploys Crimson RAT and CapraRAT for India-Targeted Multi-Platform EspionageHIGH
- State-Sponsored Signal Messenger Hijacking — QR Code Phishing Abusing Linked Devices, WAVESIGN Database Exfiltration, Infamous Chisel Android Malware (APT44/Sandworm, Turla, UNC5792, UNC4221, UNC1151)HIGH
- CVE-2024-3393 PAN-OS DNS Security DoS — Unauthenticated Firewall Crash Forces Maintenance Mode, Perimeter Security CollapseHIGH
- CSVDE.exe LOLBIN for Active Directory Reconnaissance — FIN7 + APT10/menuPass Documented Usage, Bulk LDAP Export, Kerberoasting PrecursorHIGH
- ZeroDayRAT Commercial Mobile Spyware — Telegram-Sold Cross-Platform Android/iOS Surveillance, Live Cam/Mic/Screen, Crypto Clipboard Hijacking, Banking Overlays, SMS OTP BypassHIGH
- ClickFix Evolution — nslookup DNS Smuggling + CrashFix Browser DoS + ModeloRAT Python RAT, KongTuke Actor, Enterprise Domain-Joined TargetingHIGH
- Matryoshka ClickFix macOS Variant — Nested Heredoc Obfuscation, AppleScript Credential Stealer, Trezor Suite Replacement, Ledger Live Surgical Patching, API-Gated C2HIGH
- 25 Zero-Knowledge Bypass Vulnerabilities in Cloud Password Managers (Bitwarden/LastPass/Dashlane) — ETH Zurich Research, Key Escrow, AES-CBC Malleability, KDF Downgrade (300Kx Brute-Force), Unauthenticated Public Keys, 60M+ UsersHIGH
- GitLab CI Lint API SSRF — CVE-2021-39935 Patch Bypass, CISA KEV Feb 2026, Cloud Metadata Theft, Internal Service Enumeration, 4-Year Exploitation Gap on Self-Managed Instances (update)HIGH
- DEAD#VAX AsyncRAT Campaign — IPFS-Hosted VHD Phishing, 5-Stage Fileless Infection Chain, Mark-of-the-Web Bypass, Self-Parsing Batch Scripts, 4-Layer PowerShell Deobfuscation, In-Memory Shellcode Injection into Trusted Processes (update)HIGH
- NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date Persistence (February 31st), Fileless Payment Card Skimming, Dropbear SSH C2 Impersonation, Chinese-Nexus eCommerce Targeting (update)HIGH
- BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest Encryption (4m30s), DLL Sideloading via Cortex XDR, Direct Syscalls EDR Evasion, Autonomous AD GPO Propagation, 122K Students Affected, Millions-Euro Ransom (update)HIGH
- VMware ESXi 3-CVE Zero-Day Chain — VMCI Heap-Overflow + Sandbox Escape + HGFS Info Leak (VMSA-2025-0004, Active Ransomware)MEDIUM
Techniques observed
260 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1001.003
- T1003
- T1003.001
- T1005
- T1014
- T1016
- T1018
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1021.006
- T1025
- T1027
- T1027.002
- T1027.003
- T1027.013
- T1030
- T1033
- T1036
- T1036.002
- T1036.003
- T1036.004
- T1036.005
- T1036.007
- T1037
- T1039
- T1041
- T1046
- T1047
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.001
- T1056
- T1056.001
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069.002
- T1070
- T1070.001
- T1070.002
- T1070.004
- T1070.005
- T1070.007
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1078
- T1078.002
- T1078.003
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1090.002
- T1090.003
- T1091
- T1095
- T1098
- T1098.001
- T1098.003
- T1098.005
- T1102
- T1105
- T1106
- T1110
- T1110.001
- T1110.003
- T1112
- T1113
- T1114.001
- T1114.002
- T1115
- T1119
- T1120
- T1123
- T1125
- T1129
- T1132.001
- T1133
- T1135
- T1136.001
- T1136.002
- T1137
- T1140
- T1176
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1195.003
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1210
- T1211
- T1213
- T1213.003
- T1218
- T1218.005
- T1218.011
- T1219
- T1398
- T1412
- T1417.001
- T1417.002
- T1418
- T1426
- T1429
- T1430
- T1480
- T1481
- T1482
- T1484.001
- T1485
- T1486
- T1489
- T1490
- T1491.001
- T1496
- T1497
- T1497.001
- T1498.001
- T1498.002
- T1499
- T1499.002
- T1499.003
- T1505
- T1505.003
- T1510
- T1512
- T1513
- T1517
- T1518
- T1518.001
- T1525
- T1526
- T1528
- T1529
- T1530
- T1531
- T1539
- T1541
- T1546
- T1546.002
- T1547
- T1547.001
- T1547.006
- T1548
- T1550
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553
- T1553.002
- T1553.005
- T1555
- T1555.003
- T1555.005
- T1556
- T1558.003
- T1558.004
- T1559
- T1560
- T1560.001
- T1562.001
- T1562.003
- T1562.004
- T1562.006
- T1562.008
- T1562.009
- T1562.010
- T1564
- T1564.001
- T1564.003
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1568
- T1568.002
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.002
- T1574.006
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.005
- T1583.006
- T1583.008
- T1584.001
- T1584.004
- T1584.005
- T1585.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1590.006
- T1595
- T1595.001
- T1595.002
- T1600
- T1600.001
- T1606
- T1608
- T1608.001
- T1608.002
- T1608.005
- T1611
- T1614
- T1614.001
- T1620
- T1622
- T1628.001
- T1635
- T1636.001
- T1636.002
- T1636.003
- T1646
- T1649
- T1655.001
- T1657
- T1660
Threat actors
7 named threat actors across the reports.
- APT36 / Transparent Tribe
- KongTuke
- Femwar02 (BaBlock/Rorschach affiliate)
- Qilin (Agenda)
- Aisuru-Kimwolf (Forky)
- Azote Group / UNC4696
- TGR-STA-1030
Nation-state attribution
- Russia
- Pakistan
- Russia, Belarus
- China (APT10), Unattributed (FIN7)
- Switzerland
- China (predecessor exploitation)
- China
- China (assessed with high confidence — Asian state-aligned, GMT+8, AS 9808, regional tooling, JackMa handle)
Threat categories
- VULNERABILITY
Severity breakdown
- critical9
- high16
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 287
- technique 185
- network 155
- file 92
- email 4