Cyware Daily Threat Intelligence - July 17, 2026

Cloud and AI infrastructure is under siege as attackers wield NadMesh, a polymorphic botnet that targets over 30 services and leverages more than 20 remote-code-execution paths to seize credentials and execution rights. Cyware spotlights how this threat exploits exposed Kubernetes, Docker, and AI frontends, using obfuscation and automated reconnaissance to persist in production environments.
Critical vulnerabilities in widely deployed platforms are being exploited in real time. Attackers are actively abusing CVE-2026-25089 and CVE-2026-39808 in FortiSandbox appliances, turning malware analysis tools into entry points for broader compromise. With CISA adding these flaws to its Known Exploited Vulnerabilities catalog, defenders must act quickly to patch and secure affected systems.
Social engineering campaigns are evolving, as the Pink group hijacks Microsoft 365 and Entra ID passkeys through vishing and phishing, using lookalike domains and fake recovery pages to capture credentials and establish persistent access. Organizations across healthcare, technology, and other sectors face durable threats to cloud data and account integrity.
Top Malware Reported in the Last 24 Hours
NadMesh botnet hijacks AI infrastructure at scale
NadMesh is a Go-based botnet designed to compromise AI and MCP infrastructure by commandeering exposed cloud services for stolen execution rights and credentials. NadMesh targets over 30 services, including Kubernetes, Docker APIs, Redis, Elasticsearch, and AI frontends such as ComfyUI, Ollama, n8n, and Gradio, using more than 20 remote-code-execution paths to deploy agents. NadMesh employs a five-stage kill chain—intelligence, control, supply, construction, delivery—and evades detection with Garble obfuscation, UPX-9 compression, and random padding for polymorphic builds. NadMesh leverages the Shodan API to prioritize internet-facing targets and persists via SSH backdoors and Cron watchdogs, enabling lateral movement to capture accounts and access paths. NadMesh primarily targets organizations building or hosting AI workflows across cloud platforms. GBHackers identified NadMesh in early July 2026, noting its aggressive deployment and immediate operational impact.
ACR Stealer campaigns weaponize ClickFix lures
ACR Stealer, a rebranded variant of Amatera Stealer, is an infostealer that exfiltrates browser credentials and enterprise files through ClickFix-style social engineering. ACR Stealer uses two intrusion chains: one with WebDAV and Python loaders plus blockchain-backed C2, and another leveraging MSHTA for fileless execution and steganography for delivery. ACR Stealer evades detection with obfuscated PowerShell scripts, environment variable obfuscation, and headless execution. ACR Stealer targets browser credential stores and enterprise-synced directories such as OneDrive and SharePoint, enabling attackers to move laterally through cloud applications. Microsoft observed increased ACR Stealer activity from April to June 2026, warning of account takeover and persistent data loss.
OkoBot steals crypto via hidden extensions
OkoBot is malware targeting cryptocurrency users by deploying ClickFix scams and hidden browser extensions to steal wallet files, seed phrases, and passwords. OkoBot has compromised hundreds of users across more than 25 countries, with notable activity in Brazil, Vietnam, Canada, Mexico, and Türkiye, while blocking connections from Russia and CIS countries. OkoBot uses malicious PowerShell scripts for SSH-based exfiltration and installs spyware targeting Exodus, MetaMask, Tonkeeper, Litecoin QT, KeePassXC, and 1Password. OkoBot disables Windows Defender notifications, opens firewall ports, and creates new remote users to maintain persistence and evade detection. OkoBot primarily impacts individuals and small teams managing cryptocurrency wallets, resulting in emptied accounts and compromised password vaults. Hackread reported on OkoBot’s global reach and technical methods.
Top Vulnerabilities Reported in Last 24 hours
Hackers exploit FortiSandbox command injection bugs
CVE-2026-25089 and CVE-2026-39808 are command injection vulnerabilities in Fortinet FortiSandbox appliances, both with critical severity. Successful exploitation allows unauthenticated attackers to execute arbitrary commands on the underlying server, turning malware-analysis appliances into entry points for broader compromise. Attackers are actively exploiting these vulnerabilities in the wild, as confirmed by CISA. CISA added these flaws to its Known Exploited Vulnerabilities catalog, highlighting their widespread use and targeting. Fortinet released updates in April and June 2026 to address the flaws. Affected products include FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
Active SharePoint exploits expand beyond one bug
CVE-2026-58644 is a remote code execution vulnerability in SharePoint (CVSS not specified) that allows attackers with Site Owner-level access to run arbitrary code on a SharePoint server. Exploitation results from deserialization of untrusted data, enabling full server compromise. Attackers are actively exploiting this vulnerability in the wild, and CISA also flagged CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 as actively exploited. Mandiant/Google FLARE linked CVE-2026-56164 to real-world attacks. A security update is available, and impacted deployments include SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
Siemens OT switches hit by chained zero-days
CVE-2025-40948 (CVSS 6.8), CVE-2025-40947 (CVSS 7.5), and CVE-2025-40949 (CVSS 9.1) are zero-day vulnerabilities in Siemens ROX II OT switches. Successful chaining enables persistent, root-level control of industrial network devices. Exploitation escalates from arbitrary file disclosure to privilege escalation and persistent root code execution, turning network control points into attacker-controlled platforms. The advisory details exploitation methods but does not confirm active exploitation in the wild. Palo Alto Networks Unit 42 collaborated with Siemens to surface and address these issues. Firmware version V2.17.1 contains the fix, and compromised OT switches can undermine industrial communications even after reboots.
Top Threat Actors Reported in Last 24 hours
GoSerpent RAT siphons Southeast Asia files
GoSerpent is a Go-based remote access trojan suspected to originate from a cyber-espionage group with a primary motive of intelligence collection. GoSerpent acts as a staging and deployment framework, providing remote shell access and enabling file shuttling and traffic routing through compromised machines. GoSerpent employs encrypted communications, including ChaCha20 for C2 traffic and Base64-encoded arguments protected with AES-CBC, to evade detection. GoSerpent targets government and diplomatic organizations in Southeast Asia, focusing on prolonged, low-noise exfiltration of sensitive documents. The campaign evolved in May 2026 to include Stowaway RAT, TmcLoader, TmcPayload, and credential theft tools such as ThumbcacheService, Mimikatz, and QuarksDumpLocalHash.
Sandworm uses fake CAPTCHAs in Ukraine
Sandworm (also tracked as a Russia-linked GRU hacking group) is a suspected Russian state actor focused on disruptive and espionage operations. Sandworm leverages fake CAPTCHA prompts on compromised websites to trick Ukrainian targets into running malicious PowerShell commands. Sandworm deploys malware such as FreakyPoll, FluidLeech, and LoadLoop, and dynamically alters website content to steer victims into infection chains. Sandworm targets organizations in Ukraine, undermining daily operations and trust in online services. The campaign began in spring 2026 and continued through the summer, with defenders monitoring for web shells and unauthorized extensions as part of incident response.
Pink vishers hijack Entra ID passkeys
Pink is a data extortion group suspected to operate globally with a primary motive of financial gain. Pink uses vishing-led intrusion campaigns against Microsoft 365 and Entra ID environments, impersonating IT helpdesk staff and directing employees to lookalike subdomains to capture credentials. Pink deploys a Microsoft-branded recovery page displaying BIP-39 seed phrases as a distraction while registering phishing-resistant passkeys for persistence. Pink targets healthcare, technology, aviation, automotive, construction, and food-and-beverage organizations, enabling durable access to cloud data and facilitating exfiltration from SharePoint and OneDrive. The campaign has been active since April 2026, with a surge in July 2026.
Frequently Asked Questions
What is NadMesh? NadMesh is a new Go-based botnet built to take over AI and MCP infrastructure, turning exposed cloud services into a pool of stolen execution rights and credentials. It goes after more than 30 services—from Kubernetes, Docker APIs, Redis, and Elasticsearch to AI frontends like ComfyUI, Ollama, n8n, and Gradio—using over 20 remote-code-execution paths to plant agents.
What is ACR Stealer? ACR Stealer, a rebranded version of Amatera Stealer, is being used in two observed intrusion chains that start with ClickFix-style prompts and end with stolen browser credentials and sensitive enterprise files. Microsoft says activity increased from April to June 2026, with one chain using WebDAV and Python loaders plus blockchain-backed C2 resolution, while the other leans on MSHTA for fileless execution and steganography for delivery.
What is OkoBot? OkoBot is malware aimed squarely at cryptocurrency users, using ClickFix scams and hidden browser extensions to steal wallet files, seed phrases, and passwords. Hackread reports it has hit hundreds of users across more than 25 countries, with notable activity in Brazil, Vietnam, Canada, Mexico, and Türkiye, while its servers block connections from Russia and other CIS countries—suggesting potential Russian-speaking involvement.
What is CVE-2026-25089? Two critical flaws in Fortinet FortiSandbox let unauthenticated attackers execute arbitrary commands on the underlying server, and CISA says attackers are already exploiting them in the wild (CVE-2026-25089 and CVE-2026-39808). The reported attack path is straightforward for defenders to grasp and hard to ignore: a crafted HTTP request can trigger OS command injection, turning a malware-analysis appliance into an entry point for broader compromise.
What is CVE-2026-58644? Microsoft says attackers are actively exploiting a critical SharePoint remote code execution flaw (CVE-2026-58644) that can let an attacker with Site Owner-level access run arbitrary code on a SharePoint server. The exploitation hinges on deserialization of untrusted data, a failure mode that can turn routine collaboration infrastructure into a beachhead for full server compromise.
What is CVE-2025-40948? Researchers disclosed three zero-day vulnerabilities in Siemens ROX II OT switches that can be chained to reach persistent, root-level control of devices that sit at the heart of industrial networks (CVE-2025-40948 CVSS 6.8, CVE-2025-40947 CVSS 7.5, CVE-2025-40949 CVSS 9.1). The described chain escalates from arbitrary file disclosure (used for reconnaissance) to privilege escalation and then persistent root code execution, turning a network control point into an attacker-controlled platform.
What is GoSerpent? GoSerpent is a Go-based remote access trojan used in a cyber-espionage campaign focused on government and diplomatic organizations in Southeast Asia, quietly collecting documents for weeks before moving them out through network shares. They use the malware as a staging and deployment framework, giving them remote shell access and the ability to shuttle files and route traffic through compromised machines.
What is Sandworm? Sandworm (also tracked as a Russia-linked GRU hacking group) is leaning on a low-friction social engineering trick—fake CAPTCHA prompts on compromised websites—to get Ukrainian targets to run malicious PowerShell commands. After victims follow the prompt, they install malware that can backdoor systems and support follow-on intrusions, including FreakyPoll, FluidLeech, and LoadLoop.
What is Pink? The Pink data extortion group is running a vishing-led intrusion campaign against Microsoft 365 and Entra ID environments, exploiting confusion around passkeys to turn “security” calls into account takeovers. They impersonate IT helpdesk staff, send employees to lookalike subdomains, and capture credentials via a backend panel while setting up longer-term access.