Cyware Daily Threat Intelligence - July 23, 2026

Attackers are racing through enterprise networks, using Royal ransomware to leap from a single compromised workstation to full Windows domain takeovers. Cyware spotlights nearly 60 victims in a campaign that exfiltrates data to cloud storage before locking systems, forcing defenders to rethink visibility and response.
A single authentication bypass—CVE-2026-16232—is handing attackers admin-level access to Check Point SmartConsole environments. With exploitation already in the wild and a federal patch deadline looming, organizations must act fast to block unauthorized management access and monitor for suspicious IPs.
North Korea-linked Kimsuky (APT43) is spearphishing diplomats and software vendors, using booby-trapped LNK files and PowerShell-driven malware to breach supply chains. Each new campaign exposes downstream customers to data theft and persistent access, underscoring the risk of vendor compromise across the SaaS ecosystem.
Top Malware Reported in the Last 24 Hours
Royal ransomware races through Windows domains
Royal ransomware is a ransomware strain that specializes in full Windows domain compromise and double-extortion. Royal ransomware leverages Qbot access and Cobalt Strike post-exploitation tooling to move laterally, using encoded PowerShell commands and legitimate Windows processes to evade detection. Royal ransomware exfiltrates data to cloud storage services such as Dropbox and MegaSync before encrypting systems, enabling a double-extortion model. Royal ransomware typically enters via spearphished workstations and spreads rapidly across domains. The campaign has targeted organizations in late 2022, with nearly 60 victims reported.
Anubis ransomware stalls Fairlife milk production
Anubis ransomware is a ransomware variant that disrupts business operations and threatens data exposure. Anubis ransomware infiltrates networks via spear-phishing emails and exposed RDP services, using stolen or brute-forced credentials to deploy its payload. Anubis ransomware claims to have stolen 1 terabyte of data from Fairlife, a Coca-Cola-owned brand, and offers a “token agreement” to restore systems and prevent leaks. Anubis ransomware targets U.S. food and beverage production environments, causing operational halts and supply chain issues. BankInfoSecurity reports that Coca-Cola is working with cybersecurity experts to assess and remediate the impact.
msaRAT hides C2 inside browsers
msaRAT is a Rust-based remote access trojan designed for covert command-and-control. msaRAT uses the Chrome DevTools Protocol (CDP) and WebRTC to blend attacker traffic with normal browser activity, complicating detection. msaRAT secures communications using DTLS and ChaCha-Poly1305 encryption. msaRAT is delivered via spam emails and vishing, with persistent access established post-infection. Cisco Talos attributes msaRAT’s use to the Chaos ransomware group, and warns that organizations should monitor for unusual browser automation and keep endpoint detection updated.
Top Vulnerabilities Reported in Last 24 hours
Hackers bypass Check Point SmartConsole logins (CVE-2026-16232)
CVE-2026-16232 is an authentication bypass vulnerability in Check Point SmartConsole GUI that enables attackers to gain administrator-level access. Successful exploitation allows attackers to change security policies and configurations, weakening defenses across managed environments. CVE-2026-16232 is actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities catalog and setting a U.S. federal patch deadline of July 25, 2026. Check Point reports a very small number of affected customers and notes that similar vulnerabilities, including CVE-2026-50751 and CVE-2024-24919, have been targeted by ransomware gangs. A fix is available in the latest Check Point update. Monitoring for unauthorized access from the following IPs is recommended: 151[.]241[.]99[.]207, 151[.]241[.]99[.]233, 158[.]62[.]198[.]182, 192[.]142[.]10[.]99, 139[.]28[.]37[.]250.
SharePoint bug enables remote code execution (CVE-2026-50522)
CVE-2026-50522 is a remote code execution vulnerability in Microsoft SharePoint that allows attackers to execute arbitrary code over a network. Exploitation of CVE-2026-50522 can provide attackers with a foothold to expand access within targeted environments. CVE-2026-50522 is actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities catalog on July 22, 2026, and setting a mitigation due date of July 25, 2026 for U.S. federal agencies. A fix is available via Microsoft’s security updates, and organizations relying on SharePoint should apply patches immediately.
Top Threat Actors Reported in Last 24 hours
Kimsuky spearphishes diplomats, hits vendors
Kimsuky (also known as APT43) is a suspected North Korea-linked espionage group focused on intelligence collection. Kimsuky uses diplomat-themed spearphishing with booby-trapped LNK files such as "vvn.31.Pdf...Lnk" and "D.21 SEOUL.Lnk" to trigger PowerShell-driven malware installs and data theft. Kimsuky maintains persistence using RDP Wrapper, backdoor accounts, and privilege escalation tools like UACMe, along with keylogging. Kimsuky targets South Korean diplomats and software vendors, exploiting remote code execution flaws and using social engineering to plant remote access tools. ENKI WhiteHat researchers linked Kimsuky to campaigns in 2025 and early 2026 that compromised collaborative-work software vendors. A single supplier breach by Kimsuky can expose downstream customer systems and sensitive internal data.
Iran-linked APTs probe exposed PLCs
Iranian-affiliated APTs are suspected to originate from Iran and are motivated by disruption and espionage. Iran-linked APTs interact with internet-facing programmable logic controllers (PLCs), manipulating project files and displaying deceptive data on HMI and SCADA interfaces. Iran-linked APTs use Add-On Instructions (AOIs) and reusable modules to disable shutdown and alarm logic, allowing unsafe conditions to persist undetected. Iran-linked APTs target industrial environments, including equipment from Rockwell, Schneider Electric, and Siemens. Recent campaigns involve malicious traffic on Rockwell EtherNet/IP ports 44818 and 2222, Siemens S7 on 102, Modbus on 502, and SSH on 22. US agencies issued a joint advisory describing the risk of real-world disruption and financial loss.
Chaos ransomware group hides C2 in browsers
Chaos ransomware group is a financially motivated threat actor known for double-extortion ransomware operations. Chaos ransomware group uses a Rust-based remote access trojan called msaRAT to establish covert command-and-control channels via browser features. Chaos ransomware group initiates infections with a curl command that downloads an MSI, which loads a DLL carrying the RAT payload. Chaos ransomware group manipulates Chrome or Edge using the Chrome DevTools Protocol (CDP) and WebRTC to blend malicious traffic with normal browser activity. Chaos ransomware group targets large organizations, enabling prolonged access for data theft and extortion. Cisco Talos highlights the group’s “living off the browser” approach as a stealthy evolution in ransomware tradecraft.
Frequently Asked Questions
What is Royal ransomware? Royal ransomware has been spreading from a single spearphished workstation into full Windows domain compromises by pairing Qbot access with Cobalt Strike post-exploitation tooling. Once inside, it uses encoded PowerShell commands and legitimate Windows processes to move laterally and stay persistent, making the intrusion harder to spot before encryption hits.
What is Anubis ransomware? Anubis ransomware has disrupted Fairlife’s milk production in the U.S., with the group claiming it stole 1 terabyte of data from the Coca-Cola-owned brand. It typically gets in through spear-phishing emails and by abusing exposed internet-facing services like RDP, then uses stolen or brute-forced credentials to push the payload.
What is msaRAT? msaRAT is a Rust-based remote access trojan that blends into normal web activity by using the Chrome DevTools Protocol (CDP) and WebRTC to create a covert command-and-control channel from inside Chrome or Edge. Instead of relying on noisy custom network beacons, it can manipulate the browser to relay attacker traffic in a way that looks like ordinary internet use, complicating detection.
What is CVE-2026-16232? Attackers are actively exploiting an authentication bypass in Check Point SmartConsole GUI that can hand them administrator-level access (CVE-2026-16232). In real terms, that level of control can let an intruder change security policies and configurations, weakening defenses across a managed environment and making later breaches easier to pull off.
What is CVE-2026-50522? A Microsoft SharePoint vulnerability tracked as CVE-2026-50522 has been listed by CISA as exploited in the wild, raising the stakes for organizations that rely on SharePoint to run internal sites and document workflows. CISA says the flaw can enable code execution over a network, meaning an attacker could potentially run their own code on a targeted server and use that foothold to expand access.
What is Kimsuky? Kimsuky (also known as APT43), a North Korea-linked espionage group, is blending diplomat-themed spearphishing with deeper intrusions into South Korean software suppliers. In one wave, they impersonated diplomats and sent booby-trapped LNK files such as "vvn.31.Pdf...Lnk" and "D.21 SEOUL.Lnk" to trigger PowerShell-driven malware installs and data theft.
What is Chaos? The Chaos ransomware group, a financially motivated crew known for double-extortion tactics, has been observed using a Rust-based remote access trojan called msaRAT that turns everyday browser features into a covert command channel. Cisco Talos reports that they can start the infection chain with a curl command that downloads an MSI, which then loads a DLL carrying the RAT payload.