Meet Cyware at Black Hat
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - August 03, 2026

shutterstock 2069195879

A single zero-value Ethereum transaction now hides the command center for a new wave of npm supply-chain attacks. Cyware spotlights how NullReceiver leverages blockchain tricks to evade takedowns, embedding its C2 address in the recipient field and quietly pulling developers into DPRK-linked espionage. Two malicious packages, bianira-ui and fluid-type-ui, are already active in the wild.

Attackers are seizing root-level control of remote access appliances by chaining two SonicWall SMA 1000 zero-days. With CVE-2026-15409 and CVE-2026-15410, intruders mimic legitimate clients and stage payloads that run as root, exposing plaintext LDAP credentials and cached secrets. The campaign is attributed to UTA0533, with active exploitation confirmed.

Hotel Wi-Fi portals in the U.S., India, and Saudi Arabia have become hunting grounds for Storm-2945 (linked to Russia’s SVR), which redirects travelers to fake login pages and delivers surveillance malware. The operation, disclosed by ReliaQuest, singles out corporate travelers and may soon expand to Android devices.

Top Malware Reported in the Last 24 Hours

NullReceiver hides DPRK npm malware C2

NullReceiver is a blockchain-based command-and-control technique used in trojanized npm packages tied to the DPRK “Contagious Interview” campaign. NullReceiver encodes its C2 address into the recipient field of a zero-value Ethereum transfer, making takedowns and tracking more difficult. NullReceiver looks up a hardcoded attacker wallet, finds the latest outbound transaction, decodes the C2 from the recipient address bytes, and connects out. NullReceiver is linked to the malicious packages bianira-ui and fluid-type-ui, which can quietly pull developers and downstream users into an espionage supply-chain event. NullReceiver is distributed through active npm packages. Researchers have confirmed active use of this technique.

Adform breach spreads crypto clipboard hijacker

Adform was compromised to distribute malware that reroutes cryptocurrency payments via its ad-delivery infrastructure. Adform’s breach embedded malicious JavaScript into thousands of websites, exposing a wide range of users to the threat. Adform’s malware changes cryptocurrency wallet addresses copied to the clipboard or inserted via browser autofill, redirecting funds to attacker-controlled wallets. Adform’s infection vector was the ad platform itself, though the initial access method remains undisclosed. The campaign targets end users across all sites loading Adform-delivered ads. Adform publicly acknowledged the incident, and Finland’s Veikkaus issued warnings to customers.

Storm-2945 hijacks hotel Wi-Fi for espionage

Storm-2945 is a Russian state-sponsored threat actor linked to Russia’s Foreign Intelligence Service (SVR) and specializes in espionage malware delivery. Storm-2945 compromises hotel Wi-Fi captive portals to steal credentials and deploy malware such as CornFlake (a RAT for file theft, keystroke logging, and audio/video capture) and ChocoShell (an infostealer for cookies, saved passwords, and Wi-Fi credentials). Storm-2945 redirects victims to fake login pages or fraudulent update screens to deliver its payloads. Storm-2945 targets corporate travelers at hotels and hospitality venues in the U.S., India, and Saudi Arabia. ReliaQuest discovered the operation and notes the campaign may expand to Android devices.

Top Vulnerabilities Reported in Last 24 hours

SonicWall SMA zero-days deliver root access

CVE-2026-15409 and CVE-2026-15410 are zero-day vulnerabilities in SonicWall SMA 1000 series appliances that allow root-level access (CVSS not specified). Successful exploitation enables arbitrary RPC calls and payload execution as root. Attackers are actively exploiting these flaws in the wild. Incident responders attribute the campaign to UTA0533, which has deployed malware families including KnuckleBall, OrangeTail, and Suo5. A fix is available in the latest SonicWall firmware, and affected systems include all unpatched SMA 1000 series devices.

Hackers hijack N-central RMM consoles

CVE-2026-18577 is a critical authentication-bypass vulnerability in N-able’s N-central RMM (CVSS not specified). Exploitation allows attackers to seize administrative control of MSP tooling and run scripts, deploy tools, and launch remote-control sessions. Attackers are already exploiting CVE-2026-18577 in the wild. Reports indicate intruders have abused the Take Control feature, accessed sensitive systems, and maintained persistence using Cloudflare-based tunnels. A hotfix is available in version 2026.3.1.7, and all versions before this are vulnerable.

Langflow endpoint flaw enables silent RCE

CVE-2026-0770 is a critical remote code execution vulnerability in Langflow (CVSS not specified) that affects the /api/v1/validate/code endpoint. Successful exploitation allows unauthenticated attackers to run arbitrary commands via unsafe use of Python’s exec() in the validate_code() function. Attackers are targeting internet-facing Langflow instances, with activity from ransomware affiliates and cryptojacking actors. Discovery is attributed to unnamed researchers observing opportunistic and financially motivated attacks. A fix is available in Langflow 1.10.1 or later, and all prior versions are at risk.

Top Threat Actors Reported in Last 24 hours

Storm-2945 hijacks hotel Wi‑Fi logins

Storm-2945 (linked to Russia’s Foreign Intelligence Service (SVR)) is a suspected Russian state-sponsored group focused on espionage. Storm-2945 tampers with hotel Wi‑Fi captive portals to redirect travelers to fake login pages and bogus update screens. Storm-2945 deploys CornFlake (a remote-access trojan for surveillance) and ChocoShell (an infostealer targeting browsers and Wi‑Fi credentials). Storm-2945 targets corporate travelers at hotels and hospitality venues in the U.S., India, and Saudi Arabia. The campaign involves credential theft and malware delivery via compromised captive portals. ReliaQuest disclosed the operation and notes possible expansion to Android devices.

China-linked iOS watering holes spread GHOSTBLADE

A Chinese threat actor (no explicit alias provided) is a suspected China-based group motivated by espionage. The actor uses watering-hole sites and the leaked DarkSword exploit kit to install GHOSTBLADE on iOS devices running versions 18.4 through 18.7. The actor operates over 100 web properties, including fake AWS sign-in pages, to lure victims into the exploit chain. The actor targets users in Hong Kong, Japan, the United States, and Europe. The campaign leverages infrastructure linked to the Coruna exploit kit and is referenced in attacks against Ukrainian entities. Researchers have tied this activity to additional tooling and infrastructure.

UTA0533 exploits SonicWall SMA zero-days

UTA0533 is a suspected threat actor of unknown origin focused on network intrusion and credential theft. UTA0533 exploits SonicWall SMA 1000 zero-days (CVE-2026-15409 and CVE-2026-15410) to seize root-level control of remote access appliances. UTA0533 accesses plaintext LDAP credentials, cached secrets, and intercepts authentication traffic. UTA0533 targets organizations using SonicWall SMA 1000 series devices. The campaign involves malware deployment (KnuckleBall, OrangeTail, Suo5) and a multi-week exposure window before patches were released. The campaign is currently under active exploitation in the wild.

Frequently Asked Questions

  1. What is NullReceiver? NullReceiver is a new blockchain-based command-and-control trick used in trojanized npm packages tied to the DPRK “Contagious Interview” campaign, making takedowns and tracking harder. It hides where the malware should call home by encoding the C2 address into the recipient field of a zero-value Ethereum transfer, instead of relying on the fixed “burn address” approach used by EtherHiding.

  2. What is Adform? Adform was hacked in a way that turned its ad-delivery plumbing into a distribution channel for malware that reroutes cryptocurrency payments, prompting Finland’s state gambling company Veikkaus to warn customers even though it does not accept crypto. The malicious JavaScript was embedded via Adform and loaded by thousands of websites, giving it a broad chance to reach everyday browsing sessions.

  3. What is Storm-2945? Storm-2945, described as Russian state-sponsored and linked to Russia’s Foreign Intelligence Service (SVR), has been compromising hotel Wi-Fi captive portals to steal travelers’ credentials and push espionage malware. ReliaQuest disclosed the operation after observing activity at hotels and hospitality venues in multiple U.S. cities, as well as in India and Saudi Arabia, with corporate travelers singled out as prime targets.

  4. What is CVE-2026-15409? Attackers are using two SonicWall SMA 1000 series zero-days (CVE-2026-15409 and CVE-2026-15410) to reach root-level control, turning remote-access appliances into a direct path into corporate networks. The campaign abuses a crafted WebSocket request that mimics the SMA Connect Agent client, including a specific User-Agent string and a bmID parameter, then leverages the Erlang protocol and a hardcoded cookie to make arbitrary RPC calls before staging payloads that run as root.

  5. What is CVE-2026-18577? A critical authentication-bypass bug in N-able’s N-central RMM (CVE-2026-18577) is being used to seize administrative control of MSP tooling, effectively granting “god-mode” access across managed customer environments. The issue stems from an incomplete patch that left a path to account takeover in versions before 2026.3.1.7, enabling attackers to run scripts, deploy tools, and launch remote-control sessions at scale.

  6. What is CVE-2026-0770? A critical Langflow flaw (CVE-2026-0770) allows unauthenticated remote code execution through the platform’s /api/v1/validate/code endpoint, putting AI orchestration deployments at risk of full process-level takeover. The root cause is the unsafe use of Python’s exec() in the validate_code() function, letting attackers submit “validation” input that actually runs arbitrary commands and can be used to steal credentials or pivot deeper into cloud resources.

  7. What is UTA0533? UTA0533 has been exploiting two SonicWall SMA 1000 zero-days (CVE-2026-15409 and CVE-2026-15410) to seize root-level control of remote access appliances used by organizations. They abuse the flaws to access sensitive data on the devices, including plaintext LDAP credentials and cached secrets, and to intercept authentication traffic moving through the gateway.

  8. What is GHOSTBLADE? A Chinese threat actor is using watering-hole sites and the leaked DarkSword exploit kit to install GHOSTBLADE on iOS devices, targeting versions 18.4 through 18.7. They operate more than 100 web properties, including fake AWS sign-in pages, to draw victims into the exploit chain.

Discover Related Resources