Threat reportThreat IntelligenceTL-2026-2893
QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2
QuoIntelligence Weekly Snapshot W32 2026 (TL-2026-2893), also tracked as QuoIntelligence Weekly Snapshot W32 2026, is a high-severity tracked intrusion set, first published 2026-08-06. It is attributed to The Gentlemen with low confidence, affects SonicWall Secure Mobile Access (SMA) 1000 series, references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 25 MITRE ATT&CK techniques (T1003.001, T1027.003, T1040), and is covered by 9 detection rules and 29 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 25MITRE ATT&CK
- Actors
- 3The Gentlemen
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-2893
- Threat ID
- TL-2026-2893
- Also known as
- QuoIntelligence Weekly Snapshot W32 2026, Pass-ta-key, Silver Pass-ta-key, Golden Pass-ta-key
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- The Gentlemen, DOUBLECUP operators, Greatness PhaaS Operators
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- energy, finance, government administration, industrials, information-technology, retail, transport
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in QuoIntelligence Weekly Snapshot W32 2026
Malware and tooling: CountLoader, DOUBLECUP, DeviceManager, EtherRAT, ORANGETAIL, Chisel, Sliver - S0633, Suo5
How QuoIntelligence Weekly Snapshot W32 2026 works
QuoIntelligence's week 32 2026 snapshot (30 Jul - 5 Aug 2026) groups four active campaigns: the DOUBLECUP loader-as-a-service driving ClickFix lures that deliver CountLoader and DeviceManager RAT, UTA0533 exploiting SonicWall SMA 1000 zero-days CVE-2026-15409 and CVE-2026-15410 for root access, the Greatness PhaaS adding device-code phishing to Microsoft 365 AiTM, and a The Gentlemen ransomware affiliate running EtherRAT with C2 domains rotated through an Ethereum smart contract.
The QuoIntelligence snapshot (published 2026-08-06) is headline-only; technical detail below comes from the primary vendor and press reporting behind each headline.
DOUBLECUP: a Russian loader-as-a-service active since early June 2026 that supports ClickFix campaigns. Lure pages impersonating NetSuite, Odoo, HubSpot and Salesforce logins present a fake CAPTCHA/verification and copy a command to the clipboard. The command (findstr or certutil per reporting) extracts hidden code from a steganographic PNG that the victim's browser has cached; the final payload is decrypted in memory using the victim's public IPv4 address as part of the key (environmental keying), with a custom SHA-256 stream cipher, CIS locale checks and self-deletion. Payloads are an updated CountLoader (Windows PowerShell and macOS variants; wallet, extension and Signal Desktop checks; scheduled-task or LaunchAgent persistence; can fetch MSI, PowerShell and DLL payloads) and a previously undocumented Python-based DeviceManager RAT that resolves its C2 through blockchain smart contracts (EtherHiding) and uses DNS for tasking. A licensing panel open directory was seen at 213.139.77.109:9090 and a Telegram bot is used for key distribution.
UTA0533 / SonicWall SMA 1000: Volexity tracks UTA0533 as exploiting two zero-days since at least 2026-06-22, about three weeks before disclosure. CVE-2026-15409 (CVSS 10.0) is a pre-authentication /wsproxy bypass (SSRF) that yields an unauthenticated WebSocket tunnel to localhost services; CVE-2026-15410 (CVSS 7.2) is a path traversal in the ctrl-service remove_hotfix workflow giving root command execution. The actor abused CouchDB on loopback, then deployed ROOTRUN (setuid binary, /usr/bin/xzfind), KNUCKLEBALL (Python loader deploy_new.py that injects Java components into a legitimate SonicWall process), the open-source Suo5 HTTP proxy and ORANGETAIL (custom Behinder-like Java web shell, AES-128, required specific User-Agent 'SMA Connect Agent'). Persistence was via modified /etc/init.d/workplace and NGINX Unit config; tcpdump was used to capture unencrypted LDAP credentials. Attribution is unconfirmed; Volexity describes tradecraft as more consistent with state-sponsored activity. Rapid7 reported significant overlap and a public PoC exists; a secondary source reports INC Ransomware weaponizing the same chain. Fixed firmware: 12.4.3-03453 or 12.5.0-02835.
Greatness: a phishing-as-a-service platform (documented since 2023) now offers both AiTM token/cookie theft and OAuth device-code phishing against Microsoft 365, with iCloud, Yahoo and Google Workspace also targeted. ZeroBEC observed a RingCentral voicemail lure using a five-stage redirect chain with CAPTCHA gating and abuse of safe-sender exclusions; proxy IP 38.248.95.214 authenticated to a victim account more than two weeks after the lure, followed by Graph API enumeration, device registration for persistence and delayed malicious inbox rules.
EtherRAT / The Gentlemen: hunt.io (2026-08-04) documents a The Gentlemen ransomware affiliate deploying EtherRAT (Node.js implant, MSI installer) via ClickFix initial access discovered 2026-06-16. EtherRAT reads its C2 domain from an Ethereum smart contract (checked roughly every 5 minutes) through hardcoded public RPC endpoints, so each domain rotation is permanently recorded on-chain. The operator also used Sliver, Chisel, Ligolo-ng, Mimikatz, LSASS dumping, Potato-family privilege escalation, created accounts, disabled ESET services and moved laterally by SMB/scheduled-task MSI deployment.
Also listed in the snapshot: Pass-ta-key attacks, where malware already on a Windows endpoint abuses Chrome's TPM-backed identity key to hijack Google synced passkeys. The snapshot's item on Claude models attacking real systems during misconfigured evaluations and its geopolitical items are out of scope for this record.
MITRE ATT&CK techniques used in TL-2026-2893
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory; T1040 Network Sniffing; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle
Defense Evasion
T1027.003 Obfuscated Files or Information: Steganography; T1055 Process Injection; T1218.007 System Binary Proxy Execution: Msiexec; T1620 Reflective Code Loading
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1098.005 Account Manipulation: Device Registration; T1505.003 Server Software Component: Web Shell; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.004 User Execution: Malicious Copy and Paste
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1102.001 Web Service: Dead Drop Resolver; T1572 Protocol Tunneling
Initial Access
T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link
Privilege Escalation
T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid
defense-impairment
Affected products and versions in QuoIntelligence Weekly Snapshot W32 2026
- SonicWall — Secure Mobile Access (SMA) 1000 series
Vulnerable versions: Versions prior to 12.4.3-03453 / 12.5.0-02835
Fixed in: 12.4.3-03453; 12.5.0-02835 - Microsoft — Microsoft 365 / Entra ID (targeted by Greatness AiTM and device-code phishing)
- Google — Chrome Google Password Manager synced passkeys on Windows with TPM (Pass-ta-key)
Remediation for QuoIntelligence Weekly Snapshot W32 2026
Patches
- SonicWall SMA 1000 firmware 12.4.3-03453 or 12.5.0-02835
Immediate actions
- Patch SonicWall SMA 1000 to 12.4.3-03453 or 12.5.0-02835; review /wsproxy log entries and LDAP access between 2026-06-22 and 2026-07-14
- Reimage compromised SMA appliances from known-clean firmware and rotate all credentials and session secrets associated with them
- Hunt for xzfind, deploy_new.py, modified /etc/init.d/workplace and /workplace/error.jsp artifacts on SMA 1000 appliances
- Block the listed IPs and EtherRAT C2 domains; alert on outbound requests to the listed Ethereum RPC endpoints from non-developer hosts
- Alert on clipboard-pasted findstr/certutil/PowerShell commands launched from Run dialog or terminal following a browser CAPTCHA page
Workarounds
- Block OAuth device authorization flow with Conditional Access where not required
- Ensure CouchDB default credentials are changed and loopback services are not reachable from exposed interfaces
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2) and token-protection controls for Microsoft 365
- Restrict or disable the Windows Run dialog and user-run script interpreters via policy where feasible
- Audit safe-sender exclusions for vendor domains such as RingCentral
- Enforce EDR tamper protection to resist security-service disablement
CVEs associated with QuoIntelligence Weekly Snapshot W32 2026
Timeline of QuoIntelligence Weekly Snapshot W32 2026
- Earliest observed EtherRAT C2 domain (publisherresolution.com) written to the Ethereum contract; further rotations on 04-28, 06-12, 06-18 and 07-01 (hunt.io)
- DOUBLECUP loader-as-a-service reported operating since early June 2026
- hunt.io dates exposure of the Gentlemen affiliate's ClickFix-led EtherRAT campaign
- Earliest UTA0533 exploitation of SonicWall SMA 1000 zero-days (ROOTRUN artifact creation), about three weeks pre-disclosure
- Compromised SMA appliance rebooted, clearing memory artifacts; actor deployed packet capture against LDAP traffic
- SonicWall publicly discloses CVE-2026-15409 and CVE-2026-15410; CISA adds them to the KEV catalog (per CSA research note)
- Volexity publishes 'Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation' attributing activity to UTA0533; Rapid7 reports overlap and releases a PoC
- Second US victim of the EtherRAT/The Gentlemen intrusion disclosed (first disclosed 2026-05-09)
- hunt.io publishes EtherRAT analysis; THN, BleepingComputer and SOCRadar publish DOUBLECUP analysis
- QuoIntelligence publishes the Week 32 snapshot covering 30 Jul - 5 Aug 2026; Greatness device-code update and Pass-ta-key reporting circulate the same week
Sources cited for QuoIntelligence Weekly Snapshot W32 2026
- Threat Intelligence Snapshot: Week 32, 2026 (QuoIntelligence)
- The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 (hunt.io)
- SonicWall SMA Zero-Days Exploited (The Hacker News)
- CSA Research Note: UTA0533 Weeks-Long Espionage Chain in SonicWall SMA1000
- Volexity blog archive: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT (The Hacker News)
- New DOUBLECUP ClickFix service hides malware in browser cache images (BleepingComputer)
- Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs (SOCRadar)
- Greatness PhaaS Adds Device Code Phishing (The Hacker News)
- New Pass-ta-key attacks let malware hijack Google synced passkeys (BleepingComputer)
- Rapid7 CVE-2026-15409 PoC
Detection coverage for TL-2026-2893
As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2893 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2893
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.