Cyware at Space ISAC 2026
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - August 21, 2026

8 min read
shutterstock 1453727786

A single click on a fake wire-transfer document can now hand over credentials from more than 40 applications, as attackers wield Agent Tesla v4 in fileless attacks that evade traditional scanning. Cyware spotlights how finance departments are being targeted by business email compromise lures that spoof trusted banks, turning routine invoice checks into high-stakes account takeovers.

Rust developers face a new supply chain threat after malicious versions of arrayref, internment, and append-only-vec crates poisoned Cargo builds on Linux, macOS, and Windows. The campaign, exposed on August 20, 2026, lets malware execute during software compilation, with infected hosts connecting to command-and-control at 23[.]254[.]165[.]112.

Diplomats and policy experts are being lured into real Google and Microsoft login flows by UNC7005, which leverages OAuth phishing to steal credentials and deploy malware like VIDAR. With infrastructure tied to owa-ms365[.]com and 31[.]57[.]243[.]154, these campaigns threaten sensitive communications across Europe and the US.

Top Malware Reported in the Last 24 Hours

Agent Tesla v4 hides in memory

Agent Tesla v4 is a credential-stealing infostealer that arrives via a Business Email Compromise (BEC) lure spoofing Metropolitan Bank and Trust Company. Agent Tesla v4 operates filelessly by leveraging DonutLoader shellcode for reflective in-memory injection, evading traditional file-based scanning. Agent Tesla v4 targets logins from over 40 applications, including Chromium and Mozilla browsers, Outlook, Discord, and Windows Credential Manager. Agent Tesla v4 infects victims through a fake wire-transfer document, with initial access achieved via a malicious JScript dropper. Agent Tesla v4 focuses on finance departments and Windows platforms. KnowBe4 documented that Agent Tesla v4 employs debugger checks, cloud/hosting IP checks, VM timing attacks, sandbox DLL enumeration, and WMI-based VM detection to resist analysis.

Malicious Rust crates poison Cargo builds

Malicious Rust crates represent a supply chain compromise targeting Rust developers by pushing tainted releases of arrayref, internment, and append-only-vec. Malicious Rust crates execute during Cargo builds, enabling malware to run on developer and CI machines across Linux, macOS, and Windows. Malicious Rust crates download and execute platform-specific payloads, profile infected hosts, inventory browsers, and establish persistence while communicating with command-and-control infrastructure. Malicious Rust crates are distributed via compromised crate versions—arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9—published on August 20, 2026. Socket’s Threat Research Team and Nextron Systems discovered the campaign, and the Rust Security Response Team removed the affected releases and locked the maintainer account.

FTP banners deliver E4del and PINHOLE

E4del and PINHOLE are new Windows RATs delivered through FTP server banners, where attackers embed commands that victim scripts read to fetch next-stage payloads. E4del masquerades as a Discord app, supports remote command execution, screenshots, and payload deployment, and includes a Node.js module for privilege escalation. PINHOLE retrieves its C2 configuration from Pinterest and SurveyMonkey and uses Early Bird APC injection for stealthy process management. The infection chain begins with a ZIP file and LNK-based execution, pulling PowerShell content from FTP banners. SOCRadar observed the campaign since early July 2026, with only 11 execution events recorded for PINHOLE.

Top Vulnerabilities Reported in Last 24 hours

CISA flags exploited TrueConf server flaws

CVE-2026-72529 and CVE-2026-72530 are critical vulnerabilities in TrueConf Server with CVSS scores of 9.3 and 9.5, allowing unauthenticated attackers to execute code and escape to the underlying host system. Successful exploitation enables remote code execution on exposed servers. Attackers are already exploiting these vulnerabilities in the wild. Vyacheslav Kopeytsev of Kaspersky ICS CERT discovered the flaws. CISA set remediation deadlines of August 23, 2026, and September 2, 2026, and a fix is available from TrueConf.

Citrix NetScaler patches high-risk bypass

CVE-2026-19490 is an authentication bypass vulnerability in Citrix NetScaler ADC and Gateway with a CVSS score of 9.3. Exploitation allows attackers to bypass login checks and gain unauthorized access, potentially enabling reconnaissance, lateral movement, and data theft. No active exploitation was confirmed, but experts warn weaponization is likely soon. Charlie Winckless and Brian Levine highlighted that Citrix vulnerabilities are often exploited rapidly, with CISA flagging 22 known Citrix exploits in five years. Citrix also patched CVE-2026-19489, a memory overflow denial-of-service issue, and patches are available.

Malicious Rust crates booby-trap builds

A coordinated supply-chain attack introduced a malicious dependency into widely used Rust crates, enabling malware execution during normal software builds on Linux, macOS, and Windows. Exploitation is inherent to building the compromised versions, as the malicious build script fetches and runs platform-specific payloads. Socket’s Threat Research Team and Nextron Systems discovered the tainted releases for arrayref, internment, and append-only-vec, published on August 20, 2026. The loader reconstructs obfuscated command-and-control addresses and disables TLS certificate verification, followed by a second-stage payload that profiles the host, inventories browsers, establishes persistence, and communicates with operators. The Rust Security Response Team removed the affected releases and locked the maintainer account.

Top Threat Actors Reported in Last 24 hours

UNC7005 phishes diplomats via OAuth tricks

UNC7005 (alongside UNC6293 and UNC5976) is a suspected Russian-linked cluster focused on credential theft and espionage. UNC7005 leverages OAuth phishing by tricking targets into signing into real Google, Microsoft, or WhatsApp flows, and uses device-code phishing and WhatsApp device-linking for account takeover. UNC7005 targets academia, aerospace, defense, government, and think tanks across Europe and the US. UNC7005 uses phishing infrastructure tied to owa-ms365[.]com and 31[.]57[.]243[.]154, with lures themed around diplomatic events. UNC7005 deploys malware families including VIDAR, ATOMIC, and CHERRYPIE to steal credentials and exfiltrate data, as documented by Google and others.

Head Mare APT hits TrueConf servers

Head Mare is an APT group of suspected origin focused on gaining privileged access and persistence. Head Mare exploits vulnerabilities in TrueConf Server to deliver PhantomCore malware and escalate to NT AUTHORITY\SYSTEM-level control. Head Mare chains flaws KLCERT-26-057 and KLCERT-26-058 to achieve unauthenticated remote code execution and full system compromise. Head Mare targets organizations running vulnerable TrueConf Server versions, including those indirectly affected via partner compromise. Head Mare hides activity by replacing server files with a web shell, removing event log entries, and using Linux tooling with GitHub-based command-and-control. The advisory recommends upgrading to TrueConf Server versions 5.3.9, 5.4.9, or 5.5.5.

LockBit threatens US Bank data leak

LockBit is a ransomware group of suspected criminal origin focused on data-theft extortion. LockBit claims to have breached US Bank and threatens to publish allegedly stolen data if a ransom is not paid. LockBit adds US Bank to its leak site with a September 3 deadline, prompting an investigation by the bank. LockBit targets financial institutions and their customers, raising risks of personal and financial data exposure, fraud, and reputational harm. LockBit previously reemerged in 2025 with the LockBit 5.0 variant after being dismantled in 2024, and this campaign follows prior incidents involving US Bank customers and third-party providers.

Frequently Asked Questions

  1. What is Agent Tesla v4? Agent Tesla v4 is a credential-stealing infostealer arriving through a Business Email Compromise (BEC) lure that spoofs Metropolitan Bank and Trust Company and targets finance departments with a fake wire-transfer document. It runs filelessly by using DonutLoader shellcode for reflective in-memory injection, helping it avoid traditional, file-based scanning.

  2. What is E4del? Two new Windows RATs, E4del and PINHOLE, are being delivered through an unusual channel: attackers embed commands in FTP server banners that victims’ scripts then read to fetch the next-stage payload. It starts with a ZIP file that triggers an LNK-based infection chain, which pulls PowerShell content from those FTP banners instead of a typical web paste site.

  3. What is CVE-2026-72529? Two critical bugs in TrueConf Server now sit on CISA’s Known Exploited Vulnerabilities list, and together they can let attackers run code on exposed servers (CVE-2026-72529, CVSS 9.3; CVE-2026-72530, CVSS 9.5). In practical terms, an unauthenticated attacker can send specially crafted scripts to a vulnerable TrueConf Server and end up executing code, with the second flaw enabling escape to the underlying host system.

  4. What is CVE-2026-19490? Citrix issued urgent updates for NetScaler ADC and Gateway after disclosing an authentication bypass that could open the door to unauthorized access on internet-facing appliances (CVE-2026-19490, CVSS 9.3). If exploited, the bypass can let attackers slip past login checks and use the device as a foothold for reconnaissance, lateral movement, and data theft across a victim network.

  5. What is UNC7005? UNC7005 (alongside Russian-linked clusters UNC6293 and UNC5976) is leaning on a more unsettling kind of phishing: getting targets to sign into real Google, Microsoft, or WhatsApp flows so the theft looks legitimate. They have targeted individuals in academia, aerospace, defense, government, and think tanks across Europe and the US, using social engineering such as device-code phishing for Microsoft accounts and WhatsApp device-linking to take over accounts.

  6. What is Head Mare? Head Mare, an APT group, has been exploiting vulnerabilities in TrueConf Server to deliver PhantomCore malware and turn exposed communications infrastructure into an entry point for deeper compromise. They chain two flaws (KLCERT-26-057 and KLCERT-26-058) to move from unauthenticated remote code execution to NT AUTHORITY\SYSTEM-level control, a level of access that can let an attacker run commands freely, deploy additional payloads, and establish long-term persistence.

  7. What is LockBit? LockBit, a ransomware group known for data-theft extortion, has claimed it breached US Bank and is threatening to publish allegedly stolen data if a ransom is not paid. They added the bank to their leak site with a September 3 deadline, and US Bank said it is aware of the claims and is investigating.

Discover Related Resources