Cyware Daily Threat Intelligence - August 26, 2026

Attackers are quietly embedding backdoors and tunneling utilities inside European networks, using disguised Windows DLLs to maintain encrypted access and siphon sensitive data. Cyware spotlights how Tortoiseshell is expanding its infrastructure, with new command-and-control nodes like 172[.]86[.]98[.]113 and 185[.]253[.]116[.]81, making persistent intrusions harder to detect for defense and aerospace organizations.
A single malicious patch can now let attackers seize control of Gitea servers, as exploitation of CVE-2026-60004 unfolds in the wild. With CISA mandating urgent patching by August 28, organizations running vulnerable versions face the risk of arbitrary code execution and supply chain compromise.
Ransomware groups are escalating their impact, as the Akira breach at Paylogix exposed the personal, financial, and health data of over 64,000 individuals in South Carolina alone. The fallout now includes class action lawsuits and federal investigations, underscoring the long-term consequences of data theft.
Top Malware Reported in the Last 24 Hours
Tortoiseshell expands backdoors across Europe
Tortoiseshell is an Iranian-linked APT group deploying backdoors and SSH-based tunneling utilities for covert access and data theft. Tortoiseshell leverages the TWOSTROKE backdoor, disguised as Windows DLLs, to enable encrypted communications and remote command execution. Tortoiseshell expands its infrastructure with new C2 and deployment nodes, including 172[.]86[.]98[.]113 and 185[.]253[.]116[.]81, broadening its operational reach. Tortoiseshell delivers these tools through supply chain compromises and fake recruitment lures. Tortoiseshell targets defense, aerospace, IT service providers, and military organizations across the Middle East and Europe. Group-IB reported the campaign, noting Tortoiseshell’s activity since at least 2018 and its persistent, hard-to-detect intrusions.
Malicious Firefox extensions raid crypto wallets
Malicious Firefox extensions are credential-stealing add-ons planted in Mozilla’s ecosystem to harvest crypto wallet seed phrases, private keys, passwords, and clipboard contents. Malicious Firefox extensions mimic legitimate wallet add-ons and repurpose sports-related extensions by adding theft features. Malicious Firefox extensions capture wallet secrets during setup and transmit them to attackers, enabling immediate unauthorized transfers. Malicious Firefox extensions are distributed via Mozilla’s add-on store, with 77 variants available from March until early this month before removal. Malicious Firefox extensions primarily target individuals and small businesses managing cryptocurrency. Socket researchers discovered the campaign and traced the extensions’ activity.
Car infotainment malware builds proxy botnet
MoYu Group is a criminal operation linked to Badbox campaigns, deploying the first known malware targeting Android-based automotive head units to create proxy-botnet nodes. MoYu Group abuses legitimate firmware update functionality on DoFun infotainment systems, using the TWCore app to install a dropper called JarService without driver awareness. MoYu Group’s dropper loads a second-stage payload, which downloads additional code, culminating in a third-stage component (“zhima”) that enables ad fraud and reverse-proxy traffic routing. MoYu Group delivers the malware through staged payloads leveraging legitimate update mechanisms. MoYu Group targets DoFun automotive infotainment systems, exposing vehicle owners to service degradation and potential network abuse. Kaspersky discovered the campaign, and DoFun remediated the issue after notification.
Top Vulnerabilities Reported in Last 24 hours
CVE-2026-60004: Gitea remote code execution flaw
CVE-2026-60004 is a critical remote code execution vulnerability in the Gitea platform. CVE-2026-60004 allows attackers with repository write access to execute arbitrary shell commands as the Gitea service account. CVE-2026-60004 is actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities catalog and requiring federal agencies to patch by August 28. CVE-2026-60004 was reported alongside CVE-2026-20896, which is not in CISA’s KEV catalog. A fix for CVE-2026-60004 is available in Gitea 1.27.1, and all prior versions are at risk.
CVE-2026-19478: GitLab GraphQL code injection
CVE-2026-19478 is a critical code-injection vulnerability in GitLab CE/EE (CVSS 9.4). CVE-2026-19478 enables unauthenticated attackers to modify or delete public projects and user data by abusing the @gl_introduced directive. CVE-2026-19478 has been exploited in the wild, with attackers scanning for exposed instances and targeting honeypot networks. CVE-2026-19478 was discovered through observed exploitation attempts, though widespread breaches are unconfirmed. Patches are available in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4, with affected ranges including 18.2 to 18.11 (before 18.11.11), 19.0 (before 19.0.8), 19.1 (before 19.1.6), and 19.2 (before 19.2.4).
CVE-2026-42167: ProFTPD SQL injection to RCE
CVE-2026-42167 is a post-authentication SQL injection vulnerability in the ProFTPD mod_sql module. CVE-2026-42167 allows attackers to escalate SQL injection into remote code execution, granting full OS-level command execution on affected servers. CVE-2026-42167 has a working proof-of-concept exploit publicly released. CVE-2026-42167 exploitation depends on ProFTPD using a PostgreSQL backend configured as a superuser, enabling command execution via PostgreSQL’s COPY ... TO PROGRAM capability. No patch information was provided for CVE-2026-42167, and the scope is limited to servers with the vulnerable configuration.
Top Threat Actors Reported in Last 24 hours
Tortoiseshell expands espionage tooling in Europe
Tortoiseshell (also tracked as an Iran-linked APT) is a group suspected to originate from Iran and is primarily motivated by espionage. Tortoiseshell deploys SSH-based tunneling utilities and the TWOSTROKE backdoor, both disguised as Windows DLL files, to blend into normal system activity and maintain covert access. Tortoiseshell leverages supply-chain compromises and fake recruitment sites to gain initial access and persist within target environments. Tortoiseshell targets defense, aerospace, IT service providers, and military organizations across the Middle East and Europe. Tortoiseshell’s recent campaign, reported by Group-IB, demonstrates ongoing infrastructure expansion and updated malware toolsets.
Russian-linked phishers target EU officials
Russian-linked threat groups are suspected to originate from Russia and are primarily motivated by intelligence collection. Russian-linked threat groups use spearphishing on messaging apps such as WhatsApp and Signal, employing social engineering tactics like fake Signal “support” chatbots to steal authentication codes. Russian-linked threat groups exploit these codes to take over accounts, exposing private messages and group discussions. Russian-linked threat groups target high-ranking EU officials, including those in politics, the military, diplomacy, and investigative journalism. Russian-linked threat groups have been linked to eight significant incidents this year, as reported by Politico, with Dutch and German intelligence services issuing warnings and the European Commission advising the shutdown of certain Signal groups.
Akira ransomware hit exposes Paylogix users
Akira is a financially motivated ransomware group suspected to operate globally. Akira combines disruptive ransomware attacks with data theft to maximize leverage over victims. Akira targets large organizations, focusing on benefits management platforms such as Paylogix, to exfiltrate sensitive personal, financial, and health data. Akira’s recent campaign against Paylogix affected 64,383 individuals in South Carolina, 2,304 in New Hampshire, and 1,102 in Vermont, with federal law enforcement involved. Akira’s breach has triggered class action lawsuits and is part of a broader pattern, with The Record attributing hundreds of attacks and over $244 million in ransomware proceeds to the group.
Frequently Asked Questions
What is Tortoiseshell? Tortoiseshell, an Iranian-linked APT group, has expanded its infrastructure and tooling as it targets countries in the Middle East and Europe. The campaign centers on an SSH-based tunneling utility and the TWOSTROKE backdoor, both disguised as Windows DLLs to support encrypted access, data theft, and remote command execution.
What is MoYu Group? MoYu Group, a criminal operation linked to Badbox campaigns, has been blamed for the first recorded malware known to target Android-based automotive head units and turn them into proxy-botnet nodes. Kaspersky says the infection chain abuses legitimate firmware update functionality on DoFun infotainment systems, where it leverages the TWCore app to install a dropper called JarService without the driver’s awareness.
What is CVE-2026-60004? Attackers are exploiting a critical remote code execution flaw in Gitea that can let someone with repository write access run arbitrary code on the server (CVE-2026-60004). The reported attack path is blunt: an attacker sends a malicious patch to the diffpatch API endpoint, leading to shell command execution as the Gitea service account.
What is CVE-2026-19478? A critical GitLab GraphQL code-injection flaw could let unauthenticated attackers modify or delete public projects and user data, raising direct supply-chain concerns for teams that rely on public repos (CVE-2026-19478, CVSS 9.4). The issue is tied to the @gl_introduced directive, where unsafe parsing of attacker-controlled field names can be abused to alter what a GitLab instance stores and serves.
What is CVE-2026-42167? A ProFTPD flaw in the mod_sql module can allow post-authentication SQL injection that escalates into remote code execution, potentially handing attackers full OS-level command execution on an exposed server (CVE-2026-42167). In plain terms, an attacker can abuse how the server logs activity by supplying a crafted STOR filename that breaks the intended database query and injects a second statement.
What is Tortoiseshell? Tortoiseshell (also tracked as an Iran-linked APT), a group associated in reporting with Iran’s IRGC, is widening its operational footprint with fresh infrastructure and malware aimed at targets across the Middle East and Europe. They have a track record since at least 2018 of going after defense, aerospace, IT service providers, and military organizations, including through supply-chain compromises and fake recruitment sites.
What is Akira? The Akira ransomware group, a financially motivated operation linked to numerous high-profile attacks, has been blamed for a breach at benefits management platform Paylogix that exposed sensitive personal, financial, and health data. They are known for targeting large organizations and combining disruption with data theft to increase pressure on victims, a model that can leave people facing identity and medical-privacy fallout long after systems come back online.