Cyware at Space ISAC 2026
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - August 07, 2026

shutterstock 2053035026

Attackers are turning everyday Mac users into cryptocurrency victims, as a single Terminal command can now open the door to ClickFix. This Go-based malware campaign siphons Bitcoin, Ethereum, and more, while raiding browser passwords and Apple Keychain data. Cyware.com tracks how the campaign’s links to sanctioned Russian infrastructure raise the stakes for both individuals and organizations.

A critical flaw in WinRAR is giving ransomware gangs a direct path to Windows startup folders, with CVE-2025-8088 already under active exploitation. Attackers are planting malicious files that run on boot, and the lack of automatic updates means countless endpoints remain exposed.

Ransomware crews are scaling up across Europe, with Qilin and The Gentlemen driving a surge of 866 attacks in just six months. Construction, manufacturing, and professional services are feeling the pressure as ransomware tactics become faster and more repeatable.

Top Malware Reported in the Last 24 Hours

ClickFix malware siphons crypto from macOS

ClickFix is a Go-based macOS malware campaign designed to steal cryptocurrency and account credentials. ClickFix intercepts and redirects transactions for Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple's XRP, siphoning funds directly from victims. ClickFix also targets browser password databases, the Apple Keychain, and cached credentials in browser cookies, enabling broad account takeovers. ClickFix infects users by prompting them to run a Terminal command, then creates directories mimicking legitimate macOS processes and removes quarantine attributes to evade detection. ClickFix has been linked to infrastructure associated with the Aeza Group, a Russian corporation sanctioned for providing bulletproof hosting to ransomware groups.

Orova ransomware launches with Hong Kong hits

Orova is an emerging ransomware group first detected in May 2026, specializing in double-extortion attacks. Orova steals data before encrypting systems, threatening exposure even if victims restore from backups. Orova gains access through vulnerabilities, weak passwords, phishing, and credentials purchased from infostealer markets, followed by reconnaissance, data exfiltration, and backup destruction. Orova extorts victims via a Tor-hosted data leak site and negotiation portal, leveraging the threat of publication to pressure payments. Orova has targeted healthcare, financial services, and consumer brands, listing 24 victims across six countries in its initial campaigns.

Lumma Stealer hides in pirated movies

Lumma Stealer is distributed via fake pirated downloads of the movie “The Odyssey,” using pop-culture lures to facilitate credential and cryptocurrency theft. Lumma Stealer harvests passwords, browser sessions, cookies, and crypto wallets once the disguised file is executed. Lumma Stealer leverages familiar packaging, such as executable icons resembling VLC Media Player, and exploits Windows defaults like hidden file extensions to evade user suspicion. Lumma Stealer’s latest versions focus on rapid data gathering at execution, foregoing droppers or persistence mechanisms. Researchers note this campaign as part of a broader trend of using pirated media and software as repeatable malware delivery vectors.

Top Vulnerabilities Reported in Last 24 hours

CVE-2025-8088: WinRAR path traversal exploited for ransomware

CVE-2025-8088 is a path traversal vulnerability in WinRAR (CVSS not specified) that allows attackers to plant malicious files in Windows startup directories during archive extraction. Successful exploitation enables code execution on system boot, often leading to ransomware deployment. Attackers are already exploiting CVE-2025-8088 in the wild, with reports of exploitation before a patch was available. The RomCom group has leveraged this flaw in campaigns involving cyberspionage and financial theft. A fix is available in WinRAR 7.13, but endpoints running versions prior to 7.13 remain exposed due to lack of automatic updates.

CVE-2026-64564: Linux kernel container escape

CVE-2026-64564 is a use-after-free vulnerability in the Linux kernel’s SCTP ASCONF transport logic affecting kernels 2.6.25 to 7.2-rc2 (CVSS v4.0 8.5). Exploitation allows local privilege escalation and container-to-host escape, granting attackers root access to the underlying host. No active exploitation has been reported, but a working exploit chain exists, including pg_vec leak, arbitrary read, IDT KASLR recovery, and commit_creds manipulation. Researchers at Tencent Matrix validated the exploit on Debian 13, Rocky Linux 9, and Ubuntu 24.04. Fixes are available upstream in 6.6.148, 6.12.101, 6.18.42, and 7.1.6.

AOMEI Cyber Backup v2.3.0: Pre-auth root command injection

A critical pre-auth remote code execution vulnerability in AOMEI Cyber Backup v2.3.0 allows attackers with internal network access to execute arbitrary commands as root within the backup infrastructure container. The flaw results from command injection via unescaped fields in CIFS mount commands, enabling attackers to inject shell commands through crafted credential values. A proof-of-concept is publicly available, increasing the risk of opportunistic exploitation. The 0day Rubbish Research Team disclosed the vulnerability, detailing how attackers could read stored credentials, alter storage records, or disrupt backup operations. Patch availability has not been specified, so defenders should limit exposure until updates are released.

Top Threat Actors Reported in Last 24 hours

Qilin and The Gentlemen dominate Europe

Qilin and The Gentlemen are ransomware groups of suspected Russian origin focused on financial gain. Qilin and The Gentlemen employ rapid, repeatable ransomware playbooks, driving a total of 866 ransomware attacks across Europe in H1 2026. Qilin is responsible for 158 incidents in Germany, France, the UK, Spain, and Italy, while The Gentlemen followed with 144 incidents across Europe, the US, and Thailand. Qilin and The Gentlemen target construction, manufacturing, and professional services, causing operational disruption and data leak threats. Their campaigns are part of a broader ecosystem that includes pro-Russian hacktivism and cybercrime, with NoName057(16) targeting NATO and Ukraine. Cyble reported that other groups such as LockBit, Akira, and Dragonforce also contributed to the European ransomware surge.

UNC6671 vishes cloud users for extortion

UNC6671 (also linked to the BlackFile extortion campaign) is a financially motivated group of suspected Eastern European origin. UNC6671 uses phone-based social engineering (vishing) to trick employees into revealing credentials and MFA tokens, then reuses shared phishing templates and infrastructure across multiple extortion brands, including Redact, Pink, Helix, and Falcon. UNC6671 targets financial services and enterprise cloud environments such as Microsoft 365 and Okta, with campaigns tied to domains like passkeyhelpdesk[.]com and portalpasskey[.]com. UNC6671 maintains access by performing unauthorized password resets and deleting security notifications, enabling exfiltration of intellectual property, source code, and customer data. BleepingComputer reported UNC6671 has extorted over $10.6 million in Bitcoin, with initial demands up to $3 million and common settlements around $750,000.

Frequently Asked Questions

  1. What is ClickFix? ClickFix is a Go-based macOS malware campaign built to steal both cryptocurrency and account access, with victims pushed into running a Terminal command that kicks off the infection. After launch, it goes after Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple's XRP by intercepting and redirecting transactions, potentially siphoning off a portion of the funds.

  2. What is Orova? Orova is an emerging ransomware group first detected in May 2026, and it opened with a debut campaign that targeted five Hong Kong organizations as it began building out its victim list. It runs a double-extortion playbook: attackers steal data before encrypting systems, raising the stakes by threatening exposure even if a business can restore from backups.

  3. What is Lumma Stealer? Lumma Stealer is being pushed through fake pirated downloads of the movie “The Odyssey,” turning a pop-culture lure into a direct path to credential and crypto theft. Once a user runs the disguised file, it harvests passwords, browser sessions, cookies, and cryptocurrency wallets, enabling everything from account hijacking to drained funds.

  4. What is CVE-2025-8088? Attackers are using a critical WinRAR vulnerability to plant and run malicious code on Windows systems, a path that can end in ransomware deployment (CVE-2025-8088). The bug is a path traversal issue during archive extraction that lets a specially crafted file be dropped into Windows startup directories so it runs when the machine starts.

  5. What is CVE-2026-64564? A high-severity Linux kernel flaw can let an attacker jump from a container to full control of the underlying host, turning a single foothold into a broader compromise (CVE-2026-64564, CVSS v4.0 8.5). The issue is a use-after-free in the kernel’s SCTP ASCONF transport logic, enabling local privilege escalation and container-to-host escape across kernels 2.6.25 to 7.2-rc2.

  6. What is Qilin? Qilin, a ransomware group highlighted in a new H1 2026 Europe review, stood out for the sheer volume of attacks—helping drive a tally of 866 ransomware attacks across the region in the first half of the year. They hit Germany, France, the UK, Spain, and Italy with 158 incidents, as several large crews increasingly turn speed and repeatable playbooks into a business advantage.

  7. What is UNC6671? UNC6671 (also linked to the BlackFile extortion campaign) is a financially motivated group that has turned phone-based social engineering into a fast path to cloud data theft—using vishing to trick employees into handing over credentials and MFA tokens. After first surfacing around February 2025, they shifted by July 2026 toward financial organizations including hedge funds and private-equity firms, with Google and other reporting describing a broader focus on financial services and enterprise cloud environments such as Microsoft 365 and Okta.

Discover Related Resources