Summary & highlights
EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors. "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay. Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion Operations.
Highlights
- TL-2026-2273 — EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors
- TL-2026-2276 — "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM Relay
- TL-2026-2278 — Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion Operations
- TL-2026-2279 — Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads Malvertising
- TL-2026-2283 — Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor Download Sites
Theme of the day
Routine activity — no dominant theme emerged.
- credential-theft
- social-engineering
- cisa-kev
- clickfix
- smb-lateral-movement
Threats published
20 threat lines in the 2026-09-01 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware SuiteCRITICAL
- CVE-2026-0768: Critical Langflow RCE Vulnerability Under Active ExploitationCRITICAL
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR Killers, and Rclone ExfiltrationCRITICAL
- ChainDrop/Mini Shai-Hulud npm Worm Compromises keyv, cacheable, and 400+ Downstream Packages via Ethereum-Resolved C2CRITICAL
- CVE-2026-82329: Critical JFrog Artifactory Authentication Bypass Exploited Days After DisclosureCRITICAL
- CVE-2026-33017: Langflow Unauthenticated RCE via Public Flow Build Endpoint — Active Exploitation Within 20 Hours (update)CRITICAL
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS Affiliate Program (update)CRITICAL
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear and Naval Data (update)CRITICAL
- EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked ActorsHIGH
- "Spring Ring" Vishing Campaign Abuses Microsoft Teams, Quick Assist, and PetitPotam for NTLM RelayHIGH
- Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion OperationsHIGH
- Chinese-Speaking Threat Actors Deploy PanDa Android RAT Against Mexican Banking Users via Meta Ads MalvertisingHIGH
- Silver Fox Counterfeit Installer Campaign Delivers Persistent, Self-Protecting Implant via Spoofed Vendor Download SitesHIGH
- Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List SinkholingHIGH
- FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial Messaging AppsHIGH
- Operation XENOFISCAL — SideCopy (Transparent Tribe / APT36 umbrella) Deploys Persistent Customized XenoRAT 1.8.7 Against the Afghanistan Ministry of Finance (update)HIGH
- macOS.Gaslight — DPRK-aligned Rust Backdoor & Infostealer with Analyst-Targeting Prompt-Injection Anti-Analysis (Telegram Bot API C2) (update)HIGH
- Backdoor.Mistic (MLTBackdoor): New Stealth Backdoor Linked to Woodgnat Ransomware Access Broker (update)HIGH
- Advanced Phishing Tradecraft: ClickFix, Browser-in-the-Browser, OAuth Consent, Device Code, and Fake Video-Conference Lures Bypass MFA and Security Awareness Training (update)MEDIUM
- Five Venezuelan Nationals Plead Guilty in Failed Kansas ATM Jackpotting Plot (update)LOW
Techniques observed
221 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0051.001
- T1003
- T1003.001
- T1003.004
- T1005
- T1012
- T1014
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1027
- T1027.002
- T1027.011
- T1036
- T1036.001
- T1036.004
- T1036.005
- T1037.004
- T1040
- T1041
- T1046
- T1047
- T1048
- T1053
- T1053.003
- T1053.005
- T1055
- T1056.001
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1069.002
- T1070
- T1070.001
- T1070.002
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074
- T1074.001
- T1074.002
- T1078
- T1078.002
- T1080
- T1082
- T1083
- T1087
- T1087.002
- T1087.004
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1091
- T1095
- T1098
- T1098.001
- T1098.005
- T1098.007
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1110.003
- T1112
- T1113
- T1114.002
- T1115
- T1119
- T1123
- T1125
- T1129
- T1132
- T1132.002
- T1133
- T1134
- T1135
- T1136
- T1136.001
- T1136.002
- T1140
- T1176
- T1187
- T1190
- T1195
- T1195.002
- T1199
- T1200
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1212
- T1213
- T1216
- T1217
- T1218
- T1218.005
- T1218.007
- T1219
- T1222
- T1222.001
- T1222.002
- T1406.002
- T1417.001
- T1418
- T1437.001
- T1480
- T1482
- T1484
- T1484.001
- T1485
- T1486
- T1489
- T1490
- T1491
- T1496
- T1513
- T1516
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1534
- T1539
- T1543
- T1543.001
- T1543.003
- T1547
- T1547.001
- T1547.004
- T1547.009
- T1548
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.003
- T1552.004
- T1553
- T1553.002
- T1555
- T1555.001
- T1555.003
- T1557
- T1557.001
- T1560
- T1561.002
- T1562.001
- T1564.001
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.002
- T1568.002
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574.001
- T1583
- T1583.001
- T1583.003
- T1583.006
- T1584
- T1584.004
- T1584.006
- T1585
- T1585.001
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1589
- T1591
- T1592
- T1595
- T1595.002
- T1606
- T1608.002
- T1610
- T1614
- T1620
- T1622
- T1626
- T1629.003
- T1649
- T1655.001
- T1657
- T1660
- T1684.001
- T1685
- T1685.005
- T1688
Threat actors
10 named threat actors across the reports.
- Aur0ra
- Chinese-speaking threat cluster
- Void Arachne
- BREEZE COMET
- The Gentlemen RaaS operators
- TeamPCP
- SideCopy
- DPRK-aligned activity cluster
- Woodgnat
- Storm-2697 / The Gentlemen (administrator identified as Alexander Andreevich Yapaev, aka hastalamuerte/zeta88/SantaMuerte)
Nation-state attribution
- North Korea, Iran
- Russia
- Pakistan
- North Korea
- China
Threat categories
- MALWARE
- PHISHING
- RANSOMWARE
- APT
- VULNERABILITY
- SUPPLY_CHAIN
Severity breakdown
- critical8
- high10
- medium1
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 185
- file 183
- behavioral 61
- entity 48
- tool 47
- infrastructure 44
- malware 30
- package 7