Summary & highlights
DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising Network. Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding Ransomware Access Brokers. Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain.
Highlights
- TL-2026-2304 — Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding Ransomware Access Brokers
- TL-2026-2305 — Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery Chain
- TL-2026-2308 — US-First RMM Phishing Campaign Spans 46 Countries via Disposable Vercel/Netlify Infrastructure and Password-Protected VBS-to-PowerShell Delivery
- TL-2026-2310 — Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum Crypto
- TL-2026-2311 — Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 Channel
Theme of the day
Unattributed actors dominated today's activity with multiple new threats, while critical exploits targeting Sangoma Switchvox and JFrog Artifactory fueled active RCE and takeover campaigns.
- credential-theft
- infostealer
- social-engineering
- unauthenticated-rce
- blockchain-c2
Threats published
17 threat lines in the 2026-09-03 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the WildCRITICAL
- HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code ExecutionCRITICAL
- CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)CRITICAL
- JADEPUFFER Agentic Ransomware: Autonomous LLM Agent Exploits Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441) for End-to-End Database Extortion (update)CRITICAL
- Node.js Living-off-the-Land: Multiple Threat Actors Abuse Signed node.exe as a Script Interpreter, Feeding Ransomware Access BrokersHIGH
- Ousaban Banking Trojan Targets Iberian Peninsula via Steganographic Delivery ChainHIGH
- US-First RMM Phishing Campaign Spans 46 Countries via Disposable Vercel/Netlify Infrastructure and Password-Protected VBS-to-PowerShell DeliveryHIGH
- Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum CryptoHIGH
- Malware on the Blockchain: EtherHiding/Amatera ClickFix Campaign Adds a Covert WebRTC C2 ChannelHIGH
- StreamRat Android Banking Trojan Spreads via Fake Streaming-Service Ads on Meta and TikTokHIGH
- BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target Financial-Sector CEOs via Browser-in-the-MiddleHIGH
- Serbian Authorities Deploy Pegasus and NoviSpy Spyware Against Journalists, Opposition Politicians, and Student ProtestersHIGH
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via Exposed FortiGate DevicesHIGH
- "Phantom Deal": Fake M&A Business Email/WhatsApp Compromise Scam Targets Large Enterprises with Forged NDAsHIGH
- Attacks in Korea Deploy Radmin and UltraVNC for Remote Control, Followed by Proxy/VPN Tools for Infrastructure AbuseHIGH
- Remus Stealer: 64-bit Lumma-Derived Infostealer-as-a-Service with EtherHiding Blockchain C2 and Application-Bound Encryption Bypass (update)HIGH
- DOJ/FBI Seize $560,000 in Hamas-Linked Cryptocurrency Fundraising NetworkMEDIUM
Techniques observed
188 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0819
- T1003.001
- T1005
- T1012
- T1016
- T1021
- T1027
- T1027.002
- T1027.003
- T1027.010
- T1036
- T1036.005
- T1040
- T1041
- T1046
- T1053
- T1053.003
- T1053.005
- T1055
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1068
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1078
- T1078.001
- T1082
- T1087
- T1090
- T1090.002
- T1095
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1111
- T1112
- T1113
- T1114.002
- T1115
- T1127
- T1132.001
- T1134.001
- T1136
- T1136.001
- T1140
- T1185
- T1189
- T1190
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1213
- T1218
- T1218.005
- T1218.007
- T1219
- T1398
- T1404
- T1407
- T1409
- T1417
- T1417.001
- T1417.002
- T1418
- T1420
- T1421
- T1422
- T1424
- T1426
- T1429
- T1430
- T1437
- T1437.001
- T1453
- T1456
- T1461
- T1481
- T1482
- T1484.001
- T1485
- T1486
- T1490
- T1497
- T1497.001
- T1499
- T1499.004
- T1505.003
- T1512
- T1513
- T1516
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1539
- T1541
- T1543.003
- T1544
- T1547
- T1547.001
- T1550.001
- T1552
- T1552.001
- T1555
- T1555.003
- T1555.005
- T1556
- T1557
- T1558
- T1561.001
- T1562
- T1564.003
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1568.002
- T1571
- T1573
- T1573.001
- T1574
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.006
- T1584
- T1584.003
- T1584.006
- T1584.008
- T1585
- T1585.001
- T1585.002
- T1588
- T1588.002
- T1588.006
- T1589.002
- T1589.003
- T1591.002
- T1591.004
- T1592
- T1592.002
- T1593.001
- T1595
- T1595.001
- T1595.002
- T1598.001
- T1601.001
- T1608
- T1611
- T1619
- T1620
- T1622
- T1624.001
- T1626
- T1626.001
- T1628
- T1629
- T1629.001
- T1630
- T1636.002
- T1636.003
- T1636.004
- T1644
- T1645
- T1646
- T1655
- T1657
- T1658
- T1660
- T1664
- T1684.001
- T1685
Threat actors
6 named threat actors across the reports.
Nation-state attribution
- Brazil
- CN
- Serbia
- Russia
Threat categories
- THREAT_INTEL
- MALWARE
- PHISHING
- APT
- ICS_SCADA
- VULNERABILITY
- RANSOMWARE
Severity breakdown
- critical4
- high12
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 147
- file 108
- infrastructure 55
- entity 40
- behavioral 29
- tool 27
- malware 20
- package 15
- technique 6