Cyware Daily Threat Intelligence - August 25, 2026

Cyware spotlights a ransomware group that has stolen 6TB of sensitive patient data from a major U.S. health system, exposing highly personal records and triggering a wave of fraud risks. Attackers even hijacked the organization’s social media to amplify threats, showing how data theft now extends beyond downtime into direct intimidation and potential scams.
A critical flaw in widely deployed middleware has drawn active exploitation, with attackers targeting Oracle HTTP Server and WebLogic Server Proxy-plug-in for remote code execution. With a CVSS 10.0 rating and a patch deadline set by CISA, organizations face a race to secure exposed systems before compromise.
AI-powered automation is reshaping the threat landscape as a Chinese-speaking group accelerates attacks on Windows and Linux servers. By using machine learning to troubleshoot exploits and adapt payloads, UAT-10147 is shrinking defenders’ response windows and making even smaller organizations viable targets for rapid, scalable intrusions.
Top Malware Reported in the Last 24 Hours
The Gentlemen ransomware hits AnMed, steals 6TB
The The Gentlemen ransomware group is a data-extortion threat targeting healthcare organizations. The Gentlemen exfiltrates large volumes of sensitive data, including mental health and genetic testing records, and leverages stolen information for downstream scams or coercion. The Gentlemen also compromises social media accounts to post threats and amplify pressure on victims. The Gentlemen gains access to nonprofit health systems, with AnMed confirming the theft of 6TB of patient data. The Gentlemen targets U.S. healthcare, exposing patients to fraud and intimidation tied to their medical data. AnMed’s CEO described the situation as “very complicated and rapidly changing,” with an independent review underway.
KrustyLoader hides Sliver in AWS
The KrustyLoader downloader is a malware loader that delivers encrypted Sliver payloads and injects them into Windows Explorer. KrustyLoader self-deletes after execution, making infections difficult to detect and investigate. KrustyLoader uses AWS S3 buckets for delivery, including kleinnretail[.]s3[.]amazonaws[.]com, and exploits CVE-2023-46805, CVE-2024-21887, and CVE-2025-31324 for initial access. KrustyLoader targets exposed Windows environments and leverages AES-128-CFB for in-memory decryption, referencing Rust crates such as self-replace-1.3.5 and cfb-mode-0.7.1. No confirmed infections in U.S. SLTT environments have been reported in the source.
EvilTokens hijacks Microsoft logins without passwords
The EvilTokens phishing-as-a-service platform enables account takeover of Microsoft accounts without stealing passwords. EvilTokens abuses OAuth 2.0’s Device Authorization Grant to generate device codes after a target opens a lure page, keeping authorization valid for the real Microsoft sign-in flow. EvilTokens is sold commercially, with a $1,500 panel-access fee and a $500 monthly license, lowering barriers for criminals. EvilTokens was used in a 16-day campaign that compromised 344 organizations across the United States, Canada, Australia, New Zealand, and Germany. Once EvilTokens hijacks an account, attackers can move into business email compromise and targeted fraud.
Top Vulnerabilities Reported in Last 24 hours
CVE-2026-21962: Oracle middleware flaw hit by attackers (CVSS 10.0)
CVE-2026-21962 is a remote code execution vulnerability in Oracle HTTP Server and WebLogic Server Proxy-plug-in with a CVSS 10.0 score. Successful exploitation allows unauthenticated attackers to take over vulnerable servers over the internet. CVE-2026-21962 is actively exploited in the wild. Security firm Defused reported exploitation attempts shortly after Oracle released the fix, and CISA confirmed active exploitation and set a three-day patch deadline for U.S. agencies. A patch is available from Oracle (released January 20, 2026), and all deployments of affected middleware should be updated immediately.
CVE-2026-73570: Zimbra email servers breached in attacks
CVE-2026-73570 is a command injection vulnerability in the Zimbra Collaboration Suite (ZCS) SNMP monitoring component, affecting email servers. Exploitation allows attackers to run arbitrary commands remotely on vulnerable systems. CVE-2026-73570 is actively exploited in the wild, with more than 270 instances reported compromised. CERT Polska first flagged the activity, CISA added the issue to its KEV catalog, and Shadowserver reported the scale of compromise as of August 22. A fix is available in ZCS version 10.1.20, and organizations should update immediately.
CVE-2026-42533: NGINX buffer overflow risks outages, RCE
CVE-2026-42533 is a heap-based buffer overflow vulnerability in NGINX Open Source and NGINX Plus. Successful exploitation can crash services or enable remote code execution if protections like ASLR are bypassed. No active exploitation has been reported in the provided sources. Fortinet’s threat signal report highlighted the risk and confirmed that Fortinet products are not affected. A fix is available by upgrading to NGINX 1.30.4 or 1.31.3 (or later) or NGINX Plus R36 P7 / 37.0.3.1.
Top Threat Actors Reported in Last 24 hours
UAT-10147 uses AI to speed intrusions
UAT-10147, a suspected Chinese-speaking cybercrime group, is financially motivated and leverages AI-driven tooling to accelerate intrusions. UAT-10147 uses automation to troubleshoot failed exploits and adapt payloads, establishing persistence on internet-facing Windows and Linux servers. UAT-10147 reduces the need for deep specialist expertise by automating exploit adaptation and persistence. UAT-10147 targets smaller organizations, making rapid attacks at scale possible regardless of complexity. UAT-10147 leans on known vulnerabilities and existing offensive tools, with AI helping identify exposed servers and improve exploit success. The report recommends pre-approved containment actions, governance around automated defenses, and compensating controls such as segmentation or temporary isolation when immediate patching is not possible.
EvilTokens hijacks accounts via device codes
EvilTokens, a phishing-as-a-service platform run for financial gain, is used to take over Microsoft accounts by abusing the device authorization flow. EvilTokens was used in a 16-day campaign that began in February and accelerated in March, affecting 344 organizations across the United States, Canada, Australia, New Zealand, and Germany. EvilTokens generates device codes only after a target opens the lure page, keeping the authorization request valid when the victim reaches the real Microsoft sign-in screen. EvilTokens enables attackers to bypass password theft, making genuine login pages and successful MFA prompts unreliable indicators of safety. The report recommends user awareness training and treating unsolicited device codes or unexpected authentication prompts as potential phishing attempts.
Kimsuky plants secret access via AnyDesk
Kimsuky (a North Korea-linked group) is a suspected state-sponsored actor focused on espionage. Kimsuky uses remote-access tools such as AnyDesk and Chrome Remote Desktop to maintain covert control of victim PCs. Kimsuky delivers spear-phishing emails and malicious LNK files to gain initial access, then establishes persistence through scheduled tasks. Kimsuky targets organizations and individuals in South Korea and Japan, turning endpoints into long-running surveillance or data-theft platforms. Kimsuky’s campaign includes a malicious Chrome extension that intercepts Gmail activity to capture sensitive information, according to ENKI WhiteHat. The report recommends monitoring for unauthorized AnyDesk or Chrome Remote Desktop usage, reviewing scheduled tasks for suspicious entries such as Chrome_Update and User_Feed_Synchronization, and implementing network monitoring to spot unusual outbound traffic patterns.
Frequently Asked Questions
What is The Gentlemen? The Gentlemen ransomware group has claimed a major data haul from AnMed, a nonprofit health system, saying it stole 6TB of sensitive patient information. AnMed confirmed the ransomware incident and warned that the stolen material could include highly personal records such as mental health and genetic testing data, raising the risk of downstream scams or coercion.
What is KrustyLoader? KrustyLoader is a downloader that pulls an encrypted Sliver payload, injects it into Windows Explorer, and then self-deletes, a combination designed to make infections hard to spot and harder to investigate after the fact. It blends in by using AWS S3 buckets for delivery, including one identified as kleinnretail[.]s3[.]amazonaws[.]com, which researchers flagged as actively hosting the threat.
What is EvilTokens? EvilTokens is a phishing-as-a-service platform that takes over Microsoft accounts without stealing passwords, using a workflow that can still lead victims through what looks like a legitimate login and MFA experience. It does this by abusing OAuth 2.0’s Device Authorization Grant, generating device codes after a target opens the lure page so the authorization remains valid when the victim reaches Microsoft’s sign-in flow.
What is CVE-2026-21962? A perfect-10 remote code execution flaw in Oracle Fusion Middleware components lets unauthenticated attackers take over vulnerable servers over the internet (CVE-2026-21962, CVSS 10.0). The issue affects Oracle HTTP Server and the WebLogic Server Proxy-plug-in, putting exposed middleware in the path of full system compromise and the data access that comes with it.
What is CVE-2026-73570? Hackers have been using a Zimbra Collaboration Suite bug to run code on email servers, with more than 270 instances reported compromised (CVE-2026-73570). The weakness is a command injection problem in ZCS’s SNMP monitoring component, meaning organizations that enabled SNMP notifications can end up with an attacker running commands remotely.
What is CVE-2026-42533? A heap-based buffer overflow in NGINX Open Source and NGINX Plus can be triggered remotely, potentially crashing services or, in worst cases, enabling code execution (CVE-2026-42533). The issue can be reached via crafted HTTP requests that target certain configurations using map directives with regex captures, turning a core web front door into a potential failure point.
What is UAT-10147? UAT-10147, a Chinese-speaking cybercrime group, is using AI-driven tooling to accelerate break-ins against internet-facing Windows and Linux servers, shrinking the time defenders have to react. They use automation to troubleshoot failed exploits, adapt payloads, and establish persistence faster, reducing the need for deep specialist expertise.
What is EvilTokens? EvilTokens, a phishing-as-a-service platform run for financial gain, is being used to take over Microsoft accounts by abusing the device authorization flow rather than stealing passwords. In a 16-day campaign that began in February and accelerated in March, they affected 344 organizations across the United States, Canada, Australia, New Zealand, and Germany.
What is Kimsuky? Kimsuky (a North Korea-linked group) has been observed using remote-access tools such as AnyDesk to maintain covert control of victim PCs in South Korea and Japan. They use spear-phishing and malicious LNK files to get in, then set up persistence so access keeps returning even after reboots.