Threat reportThreat IntelligenceTL-2026-2893

QuoIntelligence Weekly Snapshot W32 2026: DOUBLECUP ClickFix loader, UTA0533 SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410), Greatness AiTM/device-code PhaaS, EtherRAT blockchain C2

highACTIVE

QuoIntelligence Weekly Snapshot W32 2026 (TL-2026-2893), also tracked as QuoIntelligence Weekly Snapshot W32 2026, is a high-severity tracked intrusion set, first published 2026-08-06. It is attributed to The Gentlemen with low confidence, affects SonicWall Secure Mobile Access (SMA) 1000 series, references 2 CVEs (CVE-2026-15409, CVE-2026-15410), maps to 25 MITRE ATT&CK techniques (T1003.001, T1027.003, T1040), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
25MITRE ATT&CK
Actors
3The Gentlemen
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-2893

Threat ID
TL-2026-2893
Also known as
QuoIntelligence Weekly Snapshot W32 2026, Pass-ta-key, Silver Pass-ta-key, Golden Pass-ta-key
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution
The Gentlemen, DOUBLECUP operators, Greatness PhaaS Operators
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
energy, finance, government administration, industrials, information-technology, retail, transport
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
29

Malware and tooling in QuoIntelligence Weekly Snapshot W32 2026

Malware and tooling: CountLoader, DOUBLECUP, DeviceManager, EtherRAT, ORANGETAIL, Chisel, Sliver - S0633, Suo5

How QuoIntelligence Weekly Snapshot W32 2026 works

QuoIntelligence's week 32 2026 snapshot (30 Jul - 5 Aug 2026) groups four active campaigns: the DOUBLECUP loader-as-a-service driving ClickFix lures that deliver CountLoader and DeviceManager RAT, UTA0533 exploiting SonicWall SMA 1000 zero-days CVE-2026-15409 and CVE-2026-15410 for root access, the Greatness PhaaS adding device-code phishing to Microsoft 365 AiTM, and a The Gentlemen ransomware affiliate running EtherRAT with C2 domains rotated through an Ethereum smart contract.

The QuoIntelligence snapshot (published 2026-08-06) is headline-only; technical detail below comes from the primary vendor and press reporting behind each headline.

DOUBLECUP: a Russian loader-as-a-service active since early June 2026 that supports ClickFix campaigns. Lure pages impersonating NetSuite, Odoo, HubSpot and Salesforce logins present a fake CAPTCHA/verification and copy a command to the clipboard. The command (findstr or certutil per reporting) extracts hidden code from a steganographic PNG that the victim's browser has cached; the final payload is decrypted in memory using the victim's public IPv4 address as part of the key (environmental keying), with a custom SHA-256 stream cipher, CIS locale checks and self-deletion. Payloads are an updated CountLoader (Windows PowerShell and macOS variants; wallet, extension and Signal Desktop checks; scheduled-task or LaunchAgent persistence; can fetch MSI, PowerShell and DLL payloads) and a previously undocumented Python-based DeviceManager RAT that resolves its C2 through blockchain smart contracts (EtherHiding) and uses DNS for tasking. A licensing panel open directory was seen at 213.139.77.109:9090 and a Telegram bot is used for key distribution.

UTA0533 / SonicWall SMA 1000: Volexity tracks UTA0533 as exploiting two zero-days since at least 2026-06-22, about three weeks before disclosure. CVE-2026-15409 (CVSS 10.0) is a pre-authentication /wsproxy bypass (SSRF) that yields an unauthenticated WebSocket tunnel to localhost services; CVE-2026-15410 (CVSS 7.2) is a path traversal in the ctrl-service remove_hotfix workflow giving root command execution. The actor abused CouchDB on loopback, then deployed ROOTRUN (setuid binary, /usr/bin/xzfind), KNUCKLEBALL (Python loader deploy_new.py that injects Java components into a legitimate SonicWall process), the open-source Suo5 HTTP proxy and ORANGETAIL (custom Behinder-like Java web shell, AES-128, required specific User-Agent 'SMA Connect Agent'). Persistence was via modified /etc/init.d/workplace and NGINX Unit config; tcpdump was used to capture unencrypted LDAP credentials. Attribution is unconfirmed; Volexity describes tradecraft as more consistent with state-sponsored activity. Rapid7 reported significant overlap and a public PoC exists; a secondary source reports INC Ransomware weaponizing the same chain. Fixed firmware: 12.4.3-03453 or 12.5.0-02835.

Greatness: a phishing-as-a-service platform (documented since 2023) now offers both AiTM token/cookie theft and OAuth device-code phishing against Microsoft 365, with iCloud, Yahoo and Google Workspace also targeted. ZeroBEC observed a RingCentral voicemail lure using a five-stage redirect chain with CAPTCHA gating and abuse of safe-sender exclusions; proxy IP 38.248.95.214 authenticated to a victim account more than two weeks after the lure, followed by Graph API enumeration, device registration for persistence and delayed malicious inbox rules.

EtherRAT / The Gentlemen: hunt.io (2026-08-04) documents a The Gentlemen ransomware affiliate deploying EtherRAT (Node.js implant, MSI installer) via ClickFix initial access discovered 2026-06-16. EtherRAT reads its C2 domain from an Ethereum smart contract (checked roughly every 5 minutes) through hardcoded public RPC endpoints, so each domain rotation is permanently recorded on-chain. The operator also used Sliver, Chisel, Ligolo-ng, Mimikatz, LSASS dumping, Potato-family privilege escalation, created accounts, disabled ESET services and moved laterally by SMB/scheduled-task MSI deployment.

Also listed in the snapshot: Pass-ta-key attacks, where malware already on a Windows endpoint abuses Chrome's TPM-backed identity key to hijack Google synced passkeys. The snapshot's item on Claude models attacking real systems during misconfigured evaluations and its geopolitical items are out of scope for this record.

MITRE ATT&CK techniques used in TL-2026-2893

Credential Access

T1003.001 OS Credential Dumping: LSASS Memory; T1040 Network Sniffing; T1528 Steal Application Access Token; T1539 Steal Web Session Cookie; T1557 Adversary-in-the-Middle

Defense Evasion

T1027.003 Obfuscated Files or Information: Steganography; T1055 Process Injection; T1218.007 System Binary Proxy Execution: Msiexec; T1620 Reflective Code Loading

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1098.005 Account Manipulation: Device Registration; T1505.003 Server Software Component: Web Shell; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.004 User Execution: Malicious Copy and Paste

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1102.001 Web Service: Dead Drop Resolver; T1572 Protocol Tunneling

Initial Access

T1190 Exploit Public-Facing Application; T1566.002 Spearphishing Link

Privilege Escalation

T1548.001 Abuse Elevation Control Mechanism: Setuid and Setgid

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in QuoIntelligence Weekly Snapshot W32 2026

  • SonicWall — Secure Mobile Access (SMA) 1000 series
    Vulnerable versions: Versions prior to 12.4.3-03453 / 12.5.0-02835
    Fixed in: 12.4.3-03453; 12.5.0-02835
  • Microsoft — Microsoft 365 / Entra ID (targeted by Greatness AiTM and device-code phishing)
  • Google — Chrome Google Password Manager synced passkeys on Windows with TPM (Pass-ta-key)

Remediation for QuoIntelligence Weekly Snapshot W32 2026

Patches

  • SonicWall SMA 1000 firmware 12.4.3-03453 or 12.5.0-02835

Immediate actions

  • Patch SonicWall SMA 1000 to 12.4.3-03453 or 12.5.0-02835; review /wsproxy log entries and LDAP access between 2026-06-22 and 2026-07-14
  • Reimage compromised SMA appliances from known-clean firmware and rotate all credentials and session secrets associated with them
  • Hunt for xzfind, deploy_new.py, modified /etc/init.d/workplace and /workplace/error.jsp artifacts on SMA 1000 appliances
  • Block the listed IPs and EtherRAT C2 domains; alert on outbound requests to the listed Ethereum RPC endpoints from non-developer hosts
  • Alert on clipboard-pasted findstr/certutil/PowerShell commands launched from Run dialog or terminal following a browser CAPTCHA page

Workarounds

  • Block OAuth device authorization flow with Conditional Access where not required
  • Ensure CouchDB default credentials are changed and loopback services are not reachable from exposed interfaces

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2) and token-protection controls for Microsoft 365
  • Restrict or disable the Windows Run dialog and user-run script interpreters via policy where feasible
  • Audit safe-sender exclusions for vendor domains such as RingCentral
  • Enforce EDR tamper protection to resist security-service disablement

CVEs associated with QuoIntelligence Weekly Snapshot W32 2026

CVE-2026-15409, CVE-2026-15410

Timeline of QuoIntelligence Weekly Snapshot W32 2026

  • Earliest observed EtherRAT C2 domain (publisherresolution.com) written to the Ethereum contract; further rotations on 04-28, 06-12, 06-18 and 07-01 (hunt.io)
  • DOUBLECUP loader-as-a-service reported operating since early June 2026
  • hunt.io dates exposure of the Gentlemen affiliate's ClickFix-led EtherRAT campaign
  • Earliest UTA0533 exploitation of SonicWall SMA 1000 zero-days (ROOTRUN artifact creation), about three weeks pre-disclosure
  • Compromised SMA appliance rebooted, clearing memory artifacts; actor deployed packet capture against LDAP traffic
  • SonicWall publicly discloses CVE-2026-15409 and CVE-2026-15410; CISA adds them to the KEV catalog (per CSA research note)
  • Volexity publishes 'Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation' attributing activity to UTA0533; Rapid7 reports overlap and releases a PoC
  • Second US victim of the EtherRAT/The Gentlemen intrusion disclosed (first disclosed 2026-05-09)
  • hunt.io publishes EtherRAT analysis; THN, BleepingComputer and SOCRadar publish DOUBLECUP analysis
  • QuoIntelligence publishes the Week 32 snapshot covering 30 Jul - 5 Aug 2026; Greatness device-code update and Pass-ta-key reporting circulate the same week

Sources cited for QuoIntelligence Weekly Snapshot W32 2026

Detection coverage for TL-2026-2893

As of 2026-08-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2893 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-2893

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats