# Daily Intelligence Briefing — Tuesday, September 8, 2026

> On 2026-09-08, Threadlinqs published 10 new threat reports and updated 6, 11 rated critical and 5 high, spanning 182 MITRE ATT&CK techniques and 9 named threat actors. Coverage that day added 144 new detection rules and 475 extracted indicators.

- **Edition:** 2026-09-08 (Tuesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-08
- **Last updated:** 2026-09-14
- **New threats:** 10 (6 updated)
- **Critical / high:** 11 critical, 5 high, 0 medium, 0 low
- **ATT&CK techniques:** 182
- **Threat actors:** 9
- **Indicators (count only):** 475
- **New detection rules (count only):** 144

## Summary & highlights

Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker). QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service. The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and Infostealers.

- [TL-2026-2390](https://intel.threadlinqs.com/threat/TL-2026-2390) — Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- [TL-2026-2397](https://intel.threadlinqs.com/threat/TL-2026-2397) — QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service
- [TL-2026-2402](https://intel.threadlinqs.com/threat/TL-2026-2402) — The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and Infostealers
- [TL-2026-2405](https://intel.threadlinqs.com/threat/TL-2026-2405) — China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier AI Models
- [TL-2026-2387](https://intel.threadlinqs.com/threat/TL-2026-2387) — ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)

## Theme of the day

A steady stream of new threats surfaced today, dominated by unattributed activity, with APT-C-60, General Boss, and Lovely also emerging; no common tags were reported, indicating varied, low-signature campaigns.

credential-theft, lateral-movement, financially-motivated, persistence, defense-evasion

## Threats published

- [TL-2026-2387](https://intel.threadlinqs.com/threat/TL-2026-2387) — CRITICAL — ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)
- [TL-2026-2396](https://intel.threadlinqs.com/threat/TL-2026-2396) — CRITICAL — Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745 Unauthenticated Deserialization RCE, CVE-2026-12645-12647 Missing Authorization RCE, CVE-2026-18851 EPMM Privilege Escalation, CVE-2026-83527 Sentry Auth Bypass)
- [TL-2026-2398](https://intel.threadlinqs.com/threat/TL-2026-2398) — CRITICAL — September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEs
- [TL-2026-2407](https://intel.threadlinqs.com/threat/TL-2026-2407) — CRITICAL — Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)
- [TL-2026-2408](https://intel.threadlinqs.com/threat/TL-2026-2408) — CRITICAL — Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)
- [TL-2026-2409](https://intel.threadlinqs.com/threat/TL-2026-2409) — CRITICAL — Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint Defenses
- [TL-2026-1118](https://intel.threadlinqs.com/threat/TL-2026-1118) — CRITICAL — FortiBleed Credential Theft Campaign Linked to INC and Lynx Ransomware Operations (update)
- [TL-2026-1360](https://intel.threadlinqs.com/threat/TL-2026-1360) — CRITICAL — AsyncAPI npm Supply Chain Attack: Pwn-Request GitHub Actions Compromise Deploys Miasma Tasking Framework (update)
- [TL-2026-1362](https://intel.threadlinqs.com/threat/TL-2026-1362) — CRITICAL — Daxin Returns: China-Linked Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Backdoor (update)
- [TL-2026-2358](https://intel.threadlinqs.com/threat/TL-2026-2358) — CRITICAL — StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores (update)
- [TL-2026-2374](https://intel.threadlinqs.com/threat/TL-2026-2374) — CRITICAL — BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass (update)
- [TL-2026-2390](https://intel.threadlinqs.com/threat/TL-2026-2390) — HIGH — Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- [TL-2026-2397](https://intel.threadlinqs.com/threat/TL-2026-2397) — HIGH — QuimaRAT v2.0 — Java-Based Cross-Platform Remote Access Trojan Offered as Malware-as-a-Service
- [TL-2026-2402](https://intel.threadlinqs.com/threat/TL-2026-2402) — HIGH — The TTF Trap — Global Campaign Using Low-Detection Lua Loader Disguised as TrueType Font Files to Deploy RATs and Infostealers
- [TL-2026-2405](https://intel.threadlinqs.com/threat/TL-2026-2405) — HIGH — China-Based AI Companies Conducting Industrial-Scale Knowledge Distillation Campaigns Against U.S. Frontier AI Models
- [TL-2026-1356](https://intel.threadlinqs.com/threat/TL-2026-1356) — HIGH — "Patriot Bait": Solo Threat Actor 'bandcampro' Runs 5-Year AI-Automated Telegram Influence-and-Fraud Campaign (update)

## Techniques observed

AML.T0006, AML.T0008, AML.T0010, AML.T0012, AML.T0024.002, AML.T0040, AML.T0042, AML.T0048.004, [AML.T0051](https://intel.threadlinqs.com/technique/AML.T0051), [AML.T0053](https://intel.threadlinqs.com/technique/AML.T0053), [AML.T0054](https://intel.threadlinqs.com/technique/AML.T0054), T1001.003, [T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.003](https://intel.threadlinqs.com/technique/T1003.003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.007](https://intel.threadlinqs.com/technique/T1027.007), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.003](https://intel.threadlinqs.com/technique/T1036.003), [T1036.004](https://intel.threadlinqs.com/technique/T1036.004), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1036.008](https://intel.threadlinqs.com/technique/T1036.008), T1037.001, [T1039](https://intel.threadlinqs.com/technique/T1039), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1048.003](https://intel.threadlinqs.com/technique/T1048.003), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1055.001](https://intel.threadlinqs.com/technique/T1055.001), [T1055.012](https://intel.threadlinqs.com/technique/T1055.012), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1071.004](https://intel.threadlinqs.com/technique/T1071.004), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), T1102.003, [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195.001](https://intel.threadlinqs.com/technique/T1195.001), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1205](https://intel.threadlinqs.com/technique/T1205), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1218.011](https://intel.threadlinqs.com/technique/T1218.011), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1480.001](https://intel.threadlinqs.com/technique/T1480.001), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1497.001](https://intel.threadlinqs.com/technique/T1497.001), [T1505](https://intel.threadlinqs.com/technique/T1505), T1505.002, [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1543.002](https://intel.threadlinqs.com/technique/T1543.002), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), T1546.003, [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.004](https://intel.threadlinqs.com/technique/T1550.004), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1552.005](https://intel.threadlinqs.com/technique/T1552.005), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1555.005](https://intel.threadlinqs.com/technique/T1555.005), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1556.006](https://intel.threadlinqs.com/technique/T1556.006), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1558](https://intel.threadlinqs.com/technique/T1558), T1558.001, [T1560](https://intel.threadlinqs.com/technique/T1560), T1562, [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.003](https://intel.threadlinqs.com/technique/T1583.003), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), T1586.003, [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.001](https://intel.threadlinqs.com/technique/T1588.001), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.001](https://intel.threadlinqs.com/technique/T1595.001), [T1596](https://intel.threadlinqs.com/technique/T1596), T1597.002, [T1598.003](https://intel.threadlinqs.com/technique/T1598.003), T1600, [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1614](https://intel.threadlinqs.com/technique/T1614), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1657](https://intel.threadlinqs.com/technique/T1657), [T1685](https://intel.threadlinqs.com/technique/T1685), T1690

## Threat actors

nethoodus, China-Based AI Companies, [UAT-10820](https://intel.threadlinqs.com/actor/UAT-10820), [Hyadina](https://intel.threadlinqs.com/actor/Hyadina), bandcampro, [FortiBleed Initial Access Broker](https://intel.threadlinqs.com/actor/FortiBleed%20Initial%20Access%20Broker), [M-Red-Team](https://intel.threadlinqs.com/actor/M-RED-TEAM), China-linked espionage group, [General Boss](https://intel.threadlinqs.com/actor/General%20Boss)

Nation-state attribution: China, Russia

Threat categories: THREAT_INTEL, MALWARE, APT, VULNERABILITY, RANSOMWARE, THREAT_ACTOR, SUPPLY_CHAIN, PHISHING

## Severity breakdown

- critical: 11
- high: 5
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 475 (network 174, file 139, behavioral 80, tool 26, infrastructure 22, malware 20, entity 8, package 6)
- New detection rules: 144 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-03](https://intel.threadlinqs.com/debrief/2026-09-03)
- Next: [2026-09-09](https://intel.threadlinqs.com/debrief/2026-09-09)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-08
