# Daily Intelligence Briefing — Wednesday, September 2, 2026

> On 2026-09-02, Threadlinqs published 12 new threat reports and updated 6, 4 rated critical and 11 high, spanning 170 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 162 new detection rules and 408 extracted indicators.

- **Edition:** 2026-09-02 (Wednesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-02
- **Last updated:** 2026-09-08
- **New threats:** 12 (6 updated)
- **Critical / high:** 4 critical, 11 high, 2 medium, 1 low
- **ATT&CK techniques:** 170
- **Threat actors:** 5
- **Indicators (count only):** 408
- **New detection rules (count only):** 162

## Summary & highlights

Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks. Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International Coalition. Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time.

- [TL-2026-2288](https://intel.threadlinqs.com/threat/TL-2026-2288) — MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abuse
- [TL-2026-2293](https://intel.threadlinqs.com/threat/TL-2026-2293) — Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK
- [TL-2026-2294](https://intel.threadlinqs.com/threat/TL-2026-2294) — Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception
- [TL-2026-2295](https://intel.threadlinqs.com/threat/TL-2026-2295) — TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
- [TL-2026-2296](https://intel.threadlinqs.com/threat/TL-2026-2296) — Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts

## Theme of the day

Criminal RaaS operators and unattributed actors drove activity, exploiting VPN and RCE flaws while deploying custom implants via social engineering.

credential-theft, remote-code-execution, privilege-escalation, social-engineering, supply-chain-attack

## Threats published

- [TL-2026-2300](https://intel.threadlinqs.com/threat/TL-2026-2300) — CRITICAL — Active Exploitation of Sangoma Switchvox Unauthenticated SQL Injection (CVE-2026-9586) Deploying Reverse Shells
- [TL-2026-1750](https://intel.threadlinqs.com/threat/TL-2026-1750) — CRITICAL — OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face (update)
- [TL-2026-2152](https://intel.threadlinqs.com/threat/TL-2026-2152) — CRITICAL — Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in Nvidia's NemoClaw AI Agent Stack and a CVSS 10.0 Adobe Campaign Classic Chain (update)
- [TL-2026-2266](https://intel.threadlinqs.com/threat/TL-2026-2266) — CRITICAL — BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite (update)
- [TL-2026-2288](https://intel.threadlinqs.com/threat/TL-2026-2288) — HIGH — MoiClient Backdoor: Multi-Stage Evasion via DLL Side-Loading, RPC UAC Bypass, and BYOVD Driver Abuse
- [TL-2026-2293](https://intel.threadlinqs.com/threat/TL-2026-2293) — HIGH — Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK
- [TL-2026-2294](https://intel.threadlinqs.com/threat/TL-2026-2294) — HIGH — Open-Source Supply Chain Poisoning Campaigns Drive CrowdStrike Endpoint-Based Package Interception
- [TL-2026-2295](https://intel.threadlinqs.com/threat/TL-2026-2295) — HIGH — TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
- [TL-2026-2296](https://intel.threadlinqs.com/threat/TL-2026-2296) — HIGH — Python NodeStealer Evolves via AI-Assisted Development into Full Spyware Targeting Facebook Business Accounts
- [TL-2026-2301](https://intel.threadlinqs.com/threat/TL-2026-2301) — HIGH — Second-Order SQL Injection in All-in-One WP Migration and Backup Plugin (CVE-2026-19949) Exposes 5M+ WordPress Sites to Takeover
- [TL-2026-2302](https://intel.threadlinqs.com/threat/TL-2026-2302) — HIGH — Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teams
- [TL-2026-2353](https://intel.threadlinqs.com/threat/TL-2026-2353) — HIGH — REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig Crypto Miner
- [TL-2026-1230](https://intel.threadlinqs.com/threat/TL-2026-1230) — HIGH — Cryptojacking Campaign Exploiting Gogs (CVE-2026-52806) and Argo Workflows (CVE-2026-42296/CVE-2026-42295) Targets Managed Kubernetes Clusters (update)
- [TL-2026-2284](https://intel.threadlinqs.com/threat/TL-2026-2284) — HIGH — Sality P2P Botnet Disrupted by Law Enforcement and CrowdStrike via Peer-List Sinkholing (update)
- [TL-2026-2297](https://intel.threadlinqs.com/threat/TL-2026-2297) — HIGH — The BYOVD Epidemic: Attackers Weaponize Trusted Windows Drivers to Kill Security Software (update)
- [TL-2026-2299](https://intel.threadlinqs.com/threat/TL-2026-2299) — MEDIUM — Slopsquatting: Attackers Weaponize AI-Hallucinated Package Names in Supply Chain Attacks
- [TL-2026-2303](https://intel.threadlinqs.com/threat/TL-2026-2303) — MEDIUM — Sality P2P Botnet Dismantled After 23 Years by CrowdStrike, FBI, DOJ, and a Europol-Led International Coalition
- [TL-2026-2289](https://intel.threadlinqs.com/threat/TL-2026-2289) — LOW — Malwarebytes: Scammers Increasingly Match Scam Type to Platform, Targeting Victims by Channel and Time

## Techniques observed

AML.T0011, AML.T0018, AML.T0040, [AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051), [AML.T0053](https://intel.threadlinqs.com/technique/AML.T0053), AML.T0056, [T1003.001](https://intel.threadlinqs.com/technique/T1003.001), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1021.006](https://intel.threadlinqs.com/technique/T1021.006), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), T1037.001, [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069.003](https://intel.threadlinqs.com/technique/T1069.003), T1070.001, [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1200](https://intel.threadlinqs.com/technique/T1200), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1218.007](https://intel.threadlinqs.com/technique/T1218.007), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1547.009](https://intel.threadlinqs.com/technique/T1547.009), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.004](https://intel.threadlinqs.com/technique/T1555.004), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1560](https://intel.threadlinqs.com/technique/T1560), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1562.001, [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1566.004](https://intel.threadlinqs.com/technique/T1566.004), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.001](https://intel.threadlinqs.com/technique/T1567.001), [T1567.004](https://intel.threadlinqs.com/technique/T1567.004), [T1569.002](https://intel.threadlinqs.com/technique/T1569.002), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1585.002](https://intel.threadlinqs.com/technique/T1585.002), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1592.002](https://intel.threadlinqs.com/technique/T1592.002), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), [T1598.004](https://intel.threadlinqs.com/technique/T1598.004), [T1606](https://intel.threadlinqs.com/technique/T1606), T1606.001, [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1609](https://intel.threadlinqs.com/technique/T1609), [T1610](https://intel.threadlinqs.com/technique/T1610), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1660](https://intel.threadlinqs.com/technique/T1660), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685), [T1685.005](https://intel.threadlinqs.com/technique/T1685.005), [T1688](https://intel.threadlinqs.com/technique/T1688)

## Threat actors

[SALTY SPIDER](https://intel.threadlinqs.com/actor/SALTY%20SPIDER), [Mustang Panda](https://intel.threadlinqs.com/actor/Mustang%20Panda), [STARDUST CHOLLIMA](https://intel.threadlinqs.com/actor/Stardust%20Chollima), Autonomous OpenAI frontier-model agent (GPT-5.6 Sol / unreleased model) operating inside the ExploitGym/CyberGym evaluation harness, [BREEZE COMET](https://intel.threadlinqs.com/actor/BREEZE%20COMET)

Nation-state attribution: Russia, China, North Korea (STARDUST CHOLLIMA); unattributed/eCrime (ALTERED SPIDER), Vietnam, Mixed (China-nexus assessed for the Silver Fox truesight.sys campaign; financially motivated for the RaaS affiliates)

Threat categories: SUPPLY_CHAIN, MALWARE, THREAT_INTEL, APT, VULNERABILITY, PHISHING, RANSOMWARE

## Severity breakdown

- critical: 4
- high: 11
- medium: 2
- low: 1

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 408 (file 89, network 77, behavioral 57, malware 40, entity 39, infrastructure 38, tool 34, package 31, technique 3)
- New detection rules: 162 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-01](https://intel.threadlinqs.com/debrief/2026-09-01)
- Next: [2026-09-03](https://intel.threadlinqs.com/debrief/2026-09-03)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-02
