# Daily Intelligence Briefing — Tuesday, September 15, 2026

> On 2026-09-15, Threadlinqs published 12 new threat reports and updated 2, 4 rated critical and 10 high, spanning 132 MITRE ATT&CK techniques and 7 named threat actors. Coverage that day added 126 new detection rules and 281 extracted indicators.

- **Edition:** 2026-09-15 (Tuesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-09-15
- **Last updated:** 2026-09-21
- **New threats:** 12 (2 updated)
- **Critical / high:** 4 critical, 10 high, 0 medium, 0 low
- **ATT&CK techniques:** 132
- **Threat actors:** 7
- **Indicators (count only):** 281
- **New detection rules (count only):** 126

## Summary & highlights

Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged). Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation. Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices.

- [TL-2026-2514](https://intel.threadlinqs.com/threat/TL-2026-2514) — Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
- [TL-2026-2515](https://intel.threadlinqs.com/threat/TL-2026-2515) — Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation
- [TL-2026-2517](https://intel.threadlinqs.com/threat/TL-2026-2517) — Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
- [TL-2026-2519](https://intel.threadlinqs.com/threat/TL-2026-2519) — BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL Side-Loading and Kingsoft Office Impersonation
- [TL-2026-2520](https://intel.threadlinqs.com/threat/TL-2026-2520) — BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2

## Theme of the day

Unattributed threats dominated the day with no dominant actor or sector, suggesting a broad, low-attribution attack surface.

cisa-kev, credential-theft, cross-platform-malware, linux-malware, windows-malware

## Threats published

- [TL-2026-2522](https://intel.threadlinqs.com/threat/TL-2026-2522) — CRITICAL — Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and Xcode — Bundles a Previously KEV-Listed Pre-Auth Screen Sharing RCE
- [TL-2026-2524](https://intel.threadlinqs.com/threat/TL-2026-2524) — CRITICAL — Admin Menu Editor Pro WordPress Plugin Backdoored via Supply-Chain Compromise, 1,500 Sites Affected
- [TL-2026-2508](https://intel.threadlinqs.com/threat/TL-2026-2508) — CRITICAL — CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog (update)
- [TL-2026-2516](https://intel.threadlinqs.com/threat/TL-2026-2516) — CRITICAL — Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit (update)
- [TL-2026-2514](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH — Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)
- [TL-2026-2515](https://intel.threadlinqs.com/threat/TL-2026-2515) — HIGH — Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian Targets via Exchange/SharePoint Exploitation
- [TL-2026-2517](https://intel.threadlinqs.com/threat/TL-2026-2517) — HIGH — Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
- [TL-2026-2519](https://intel.threadlinqs.com/threat/TL-2026-2519) — HIGH — BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL Side-Loading and Kingsoft Office Impersonation
- [TL-2026-2520](https://intel.threadlinqs.com/threat/TL-2026-2520) — HIGH — BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2
- [TL-2026-2523](https://intel.threadlinqs.com/threat/TL-2026-2523) — HIGH — CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Plugin
- [TL-2026-2525](https://intel.threadlinqs.com/threat/TL-2026-2525) — HIGH — KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to Steal Brazilian Bank Credentials
- [TL-2026-2526](https://intel.threadlinqs.com/threat/TL-2026-2526) — HIGH — Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and Journalists
- [TL-2026-2527](https://intel.threadlinqs.com/threat/TL-2026-2527) — HIGH — PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network (CVE-2020-16040)
- [TL-2026-2529](https://intel.threadlinqs.com/threat/TL-2026-2529) — HIGH — Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)

## Techniques observed

[T1005](https://intel.threadlinqs.com/technique/T1005), [T1014](https://intel.threadlinqs.com/technique/T1014), T1016.001, [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.004](https://intel.threadlinqs.com/technique/T1021.004), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.001](https://intel.threadlinqs.com/technique/T1036.001), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1048](https://intel.threadlinqs.com/technique/T1048), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.003](https://intel.threadlinqs.com/technique/T1053.003), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), T1070.002, [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.004](https://intel.threadlinqs.com/technique/T1070.004), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), T1071.005, [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.003](https://intel.threadlinqs.com/technique/T1078.003), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1090.001](https://intel.threadlinqs.com/technique/T1090.001), [T1090.002](https://intel.threadlinqs.com/technique/T1090.002), [T1090.003](https://intel.threadlinqs.com/technique/T1090.003), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114](https://intel.threadlinqs.com/technique/T1114), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1129](https://intel.threadlinqs.com/technique/T1129), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1210](https://intel.threadlinqs.com/technique/T1210), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1218.005](https://intel.threadlinqs.com/technique/T1218.005), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1518.001](https://intel.threadlinqs.com/technique/T1518.001), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543.003](https://intel.threadlinqs.com/technique/T1543.003), [T1543.004](https://intel.threadlinqs.com/technique/T1543.004), [T1546.004](https://intel.threadlinqs.com/technique/T1546.004), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.001](https://intel.threadlinqs.com/technique/T1548.001), [T1548.003](https://intel.threadlinqs.com/technique/T1548.003), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1552.004](https://intel.threadlinqs.com/technique/T1552.004), [T1553.002](https://intel.threadlinqs.com/technique/T1553.002), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.001](https://intel.threadlinqs.com/technique/T1555.001), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), [T1561.001](https://intel.threadlinqs.com/technique/T1561.001), T1562.001, [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.003](https://intel.threadlinqs.com/technique/T1566.003), [T1567.002](https://intel.threadlinqs.com/technique/T1567.002), T1568.001, [T1570](https://intel.threadlinqs.com/technique/T1570), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), [T1574.006](https://intel.threadlinqs.com/technique/T1574.006), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.004](https://intel.threadlinqs.com/technique/T1583.004), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1584.004](https://intel.threadlinqs.com/technique/T1584.004), [T1584.006](https://intel.threadlinqs.com/technique/T1584.006), [T1584.008](https://intel.threadlinqs.com/technique/T1584.008), [T1585.001](https://intel.threadlinqs.com/technique/T1585.001), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1587.004](https://intel.threadlinqs.com/technique/T1587.004), [T1588.003](https://intel.threadlinqs.com/technique/T1588.003), [T1588.005](https://intel.threadlinqs.com/technique/T1588.005), [T1588.006](https://intel.threadlinqs.com/technique/T1588.006), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1608.001](https://intel.threadlinqs.com/technique/T1608.001), [T1620](https://intel.threadlinqs.com/technique/T1620), T1633.001, [T1660](https://intel.threadlinqs.com/technique/T1660), [T1665](https://intel.threadlinqs.com/technique/T1665), [T1684.001](https://intel.threadlinqs.com/technique/T1684.001), [T1685](https://intel.threadlinqs.com/technique/T1685), [T1685.005](https://intel.threadlinqs.com/technique/T1685.005), [T1685.006](https://intel.threadlinqs.com/technique/T1685.006)

## Threat actors

[Hacking Cat](https://intel.threadlinqs.com/actor/Hacking%20Cat), [REF9334](https://intel.threadlinqs.com/actor/REF9334), [Iran Ministry of Intelligence](https://intel.threadlinqs.com/actor/Iran%20Ministry%20of%20Intelligence), China-aligned APT clusters, [Yalishanda](https://intel.threadlinqs.com/actor/Yalishanda), [UAT-9686](https://intel.threadlinqs.com/actor/UAT-9686), [Red Heron](https://intel.threadlinqs.com/actor/Red%20Heron)

Nation-state attribution: Ukraine, MY, China, Iran, Russia

Threat categories: DATA_BREACH, RANSOMWARE, MALWARE, VULNERABILITY, PHISHING, SUPPLY_CHAIN, APT

## Severity breakdown

- critical: 4
- high: 10
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 281 (network 69, file 59, infrastructure 40, entity 33, malware 30, tool 23, package 21, behavioral 6)
- New detection rules: 126 (100% of the day’s threats covered)

## More editions

- Previous: [2026-09-13](https://intel.threadlinqs.com/debrief/2026-09-13)
- Next: [2026-09-18](https://intel.threadlinqs.com/debrief/2026-09-18)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-09-15
