Summary & highlights
Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijack Login Sessions. Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login Sessions to Drain Usage. Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment Methods.
Highlights
- TL-2026-2250 — BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation
- TL-2026-2251 — HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2
- TL-2026-2256 — ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL Sideloading
- TL-2026-2259 — JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode Payloads
- TL-2026-2260 — TerminalFix Campaign Deploys Custom Python Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA, DLL Sideloading, and PNG Steganography
Theme of the day
Unattributed threats dominated the day, with Aurora being the only named actor, signaling a shift toward stealthy, unclaimed operations.
- credential-theft
- infostealer
- malware-as-a-service
- session-cookie-theft
- session-hijacking
Threats published
17 threat lines in the 2026-08-31 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Cronos Blockchain Halted After $74M Price-Manipulation Exploit of Tectonic Lending ProtocolCRITICAL
- TerminalFix Campaign Deploys Custom Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA and Multistage IntrusionCRITICAL
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries) (update)CRITICAL
- CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read / RCE via libvips Image Processing (update)CRITICAL
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB OperationHIGH
- HexMage Magecart Campaign Uses Ethereum Smart Contracts for Resilient Card-Skimmer C2HIGH
- ValleyRAT (Winos 4.0) Backdoor Hides in Signed QN Wallpaper Installer via DLL SideloadingHIGH
- JSCeal Cryptocurrency Stealer: Check Point Details Static Deobfuscation of Compiled V8 Bytecode PayloadsHIGH
- TerminalFix Campaign Deploys Custom Python Reverse-Tunnel Implant via Fake Cloudflare CAPTCHA, DLL Sideloading, and PNG SteganographyHIGH
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer/AMOS) Hijacking Claude AI Sessions to Drain Paid UsageHIGH
- Auto-Color Linux Backdoor Reverse-Engineered: Root-Level LD_PRELOAD Persistence and Encrypted C2 (update)HIGH
- Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijack Login SessionsMEDIUM
- Infostealer Malware (Vidar, LummaC2, StealC, RedLine, Acreed, Atomic Stealer) Hijacking Claude Login Sessions to Drain UsageMEDIUM
- Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment MethodsMEDIUM
- HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege EscalationMEDIUM
- Password Spraying Campaign Targets AWS Root User Accounts Across 150+ OrganizationsMEDIUM
- Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting PlotLOW
Techniques observed
152 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1005
- T1010
- T1012
- T1014
- T1016
- T1018
- T1021.001
- T1021.002
- T1027
- T1027.002
- T1027.003
- T1036
- T1036.005
- T1036.008
- T1039
- T1040
- T1041
- T1046
- T1053
- T1053.005
- T1055
- T1055.001
- T1055.012
- T1056
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.007
- T1068
- T1069.002
- T1070.003
- T1070.004
- T1071
- T1071.001
- T1074.001
- T1078
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1090
- T1090.001
- T1090.002
- T1091
- T1095
- T1098
- T1102.001
- T1102.002
- T1106
- T1110
- T1110.001
- T1110.003
- T1112
- T1113
- T1119
- T1123
- T1129
- T1133
- T1136
- T1140
- T1190
- T1195
- T1204
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1217
- T1222.001
- T1482
- T1486
- T1489
- T1495
- T1497
- T1497.001
- T1498
- T1505
- T1518
- T1526
- T1528
- T1531
- T1539
- T1542
- T1547
- T1547.001
- T1547.004
- T1548
- T1550
- T1550.004
- T1552
- T1552.004
- T1553
- T1553.004
- T1555
- T1555.003
- T1556
- T1557
- T1564
- T1564.001
- T1564.003
- T1565.001
- T1566
- T1567
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1574.006
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.005
- T1583.008
- T1584.005
- T1585
- T1586
- T1587
- T1587.004
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1589.002
- T1592
- T1592.002
- T1594
- T1595
- T1595.001
- T1595.002
- T1602.002
- T1606
- T1606.001
- T1657
- T1665
- T1685
- T1685.001
- T1685.002
- T1685.006
- T1686
Threat actors
3 named threat actors across the reports.
- Exilware
- Void Arachne
- Lynx)
Nation-state attribution
- China
- Russia
Threat categories
- MALWARE
- VULNERABILITY
- CLOUD
- THREAT_INTEL
- CAMPAIGN
Severity breakdown
- critical4
- high7
- medium5
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- file 101
- network 70
- entity 59
- behavioral 50
- tool 48
- infrastructure 42
- malware 42
- package 6
- technique 6
- vulnerability 1