Meet Cyware at Black Hat
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - July 20, 2026

shutterstock 1951619836

Fake game downloads are being weaponized to quietly steal credentials and cryptocurrency, as attackers embed malicious scripts inside popular engines and distribute them through mainstream file-sharing sites. Cyware highlights how one campaign leverages the Ren’Py engine to plant credential-stealing malware, with victims facing immediate risk of account takeover and financial loss.

A new attack chain is slashing the time between WordPress vulnerability disclosure and real-world exploitation, letting hackers seize control of sites without a login. By chaining two CVEs and exploiting REST API confusion, attackers can turn a stock install into a remote entry point—prompting urgent patching across affected versions.

Espionage operations are hiding in plain sight as adversaries turn trusted business tools into covert command channels. One campaign has compromised at least 12 systems by embedding instructions in Microsoft 365 calendar events, making detection and response a challenge for targeted organizations.

Top Malware Reported in the Last 24 Hours

RenPy Loader smuggles Amatera via fake games

RenPy Loader is a loader malware that plants Amatera Stealer, focusing on credential and cryptocurrency theft. RenPy Loader hides its activity inside the Ren’Py game engine, commonly used for visual novels, and spreads through fake downloads of games, mods, and software. RenPy Loader executes embedded malicious Python scripts to initiate a larger infection chain, then leverages MSBuild and an EtherHiding-style approach to obscure next-stage delivery and locate its command-and-control infrastructure. RenPy Loader is distributed via fake download sites and mainstream file-sharing services, as reported by Malwarebytes. RenPy Loader targets users seeking games and mods, with the immediate consequence of password and cryptocurrency wallet theft leading to account takeover and financial loss.

Cruciferra crypter helps gangs hide malware

Cruciferra is a Mono-based crypter service that disguises malware and prolongs payload execution. Cruciferra supports evasion techniques including indirect system calls, API unhooking, BYOVD-based EDR tampering, persistence, and a custom form of Process Ghosting. Cruciferra has been used to deliver remote access trojans and infostealers such as Agent Tesla, Formbook, Remcos, XWorm, DarkCloud Stealer, and zgRAT. Cruciferra is distributed through campaigns using tax-themed lures, Social Security Administration impersonation, and hospitality sector “guest complaint” themes, as observed by Proofpoint. Cruciferra enables familiar malware to bypass defenses in new ways, increasing the risk of credential theft and remote access before detection.

HOLLOWGRAPH turns calendars into spy C2

HOLLOWGRAPH is malware that uses Microsoft 365 calendars as a covert command-and-control channel for espionage. HOLLOWGRAPH embeds instructions in future-dated calendar events and uses DNS tunneling with IPv6 AAAA records to refresh Microsoft Entra ID credentials, maintaining access without interactive logins. HOLLOWGRAPH leverages the Cavern framework and the Microsoft Graph API to pull tasks and return results through calendar activity. HOLLOWGRAPH targets Israeli entities, with at least 12 compromised systems and active communication in three cases, according to Group-IB. HOLLOWGRAPH turns everyday collaboration tools into attacker-controlled messaging layers, complicating detection and response.

Top Vulnerabilities Reported in Last 24 hours

Hackers chain WordPress bugs for takeover

CVE-2026-63030 and CVE-2026-60137 are a chained vulnerability in WordPress core enabling unauthenticated remote code execution (RCE) with a CVSS score not specified in the source. Successful exploitation allows attackers to take over affected WordPress sites without a login by abusing REST API batch-route confusion and SQL injection. Attackers are actively exploiting this chain in the wild. Researchers at Searchlight Cyber disclosed the vulnerabilities, with exploitation observed by Patchstack, Hexastrike, and WatchTowr. Mitigation is available in WordPress 6.9.5 and 7.0.2, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.

Nginx flaw risks pre-auth server compromise

CVE-2026-42533 is a pre-auth remote code execution vulnerability in nginx that allows arbitrary code execution on affected servers. CVE-2026-42533 results from a missing save-and-restore mechanism for PCRE capture state in nginx’s two-pass script evaluation engine, enabling heap buffer overflow and information leak to defeat ASLR. No active exploitation has been reported, but a proof-of-concept exists and was withheld to allow patching. The vulnerability can be triggered via common configuration directives such as proxy_set_header, proxy_pass, fastcgi_param, add_header, rewrite, set, root, alias, and access_log, broadening the scope of affected systems. A fix is available in nginx 1.30.4 and 1.31.3.

Frequently Asked Questions

  1. What is RenPy Loader? RenPy Loader is being used to plant Amatera Stealer, hiding its malicious activity inside the Ren’Py game engine commonly used for visual novels. It spreads through fake downloads of games, mods, and software, then runs embedded malicious Python scripts that quietly kick off a larger infection chain.

  2. What is Cruciferra? Cruciferra is a Mono-based crypter service sold to cybercriminals to help disguise malware and keep it running long enough to do damage. It supports a wide menu of evasion tricks—indirect system calls, API unhooking, BYOVD-based EDR tampering, persistence, and even a custom form of Process Ghosting—so payloads can slip past defensive tooling.

  3. What is HOLLOWGRAPH? HOLLOWGRAPH is malware that uses Microsoft 365 calendars as a covert command-and-control channel, embedding instructions in future-dated events to blend into normal business systems. It also uses DNS tunneling with IPv6 AAAA records to refresh Microsoft Entra ID credentials, keeping access alive without obvious interactive logins.

  4. What is CVE-2026-63030? Attackers are using the “wp2shell” chain in WordPress core to take over sites without a login, combining CVE-2026-63030 with CVE-2026-60137 to achieve unauthenticated remote code execution on affected versions including 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The attack path hinges on REST API batch-route confusion that lets a malicious request slip past validation, then leverages SQL injection to reach code execution—turning a stock WordPress install into a remote entry point.

  5. What is CVE-2026-42533? A pre-auth remote code execution bug in nginx, CVE-2026-42533, can let an attacker execute arbitrary code on affected servers—potentially turning a front-door web service into a full system compromise. The flaw stems from a missing save-and-restore mechanism for PCRE capture state in nginx’s two-pass script evaluation engine, which can be abused to trigger a heap buffer overflow and an information leak that helps defeat ASLR.

  6. What is Cruciferra? Cruciferra is a commercial crypter service written in Mono that multiple cybercriminal groups use to sneak well-known malware past defenses, effectively turning malware delivery into a paid subscription. In campaigns observed by Proofpoint, they’ve used it to support email-lure operations including TA4922 tax-themed messages that ultimately delivered AsyncRAT, alongside other runs impersonating the Social Security Administration and “guest complaint” themes aimed at the hospitality sector.

  7. What is HOLLOWGRAPH? HOLLOWGRAPH, a stealthy espionage-focused malware linked to the Cavern framework, has been observed using Microsoft 365 calendars as a covert command-and-control channel while targeting Israeli entities. Instead of relying on obvious external infrastructure, they embed commands and stolen data inside future-dated calendar events—set as far out as the year 2050—and use the Microsoft Graph API to read and act on those instructions.

Discover Related Resources