Meet Cyware at Black Hat
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - July 28, 2026

shutterstock 2635053275

Attackers are blending into routine IT operations by hijacking admin tools and cloud storage, as seen in a four-day ransomware campaign that used Nmap scans, PSExec, and the Sliver framework to evade detection. Cyware.com highlights how this approach, which included exfiltration to Wasabi cloud and SMBv1-based ransomware deployment, can force operational shutdowns and double-extortion scenarios for businesses.

A critical flaw with a CVSS score of 10.0 in Arista VeloCloud Orchestrator is being exploited in the wild, letting unauthenticated attackers seize SD-WAN control planes. With public exploits for Linux kernel privilege escalation and a FastJson zero-day also in play, organizations face urgent patching decisions as attackers move quickly to capitalize on exposed systems.

China-linked espionage groups are routing global campaigns through the RedRelay network, which leverages compromised routers and leased VPS nodes to obscure origins. This infrastructure-as-a-service model, tracked by researchers via unique Linux commands and payloads, is slowing investigations and enabling persistent attacks against government and telecom targets.

Top Malware Reported in the Last 24 Hours

Darktrace spots ransomware hiding in tools

A four-day, multi-stage ransomware intrusion detailed by Darktrace blended into normal IT activity by leveraging widely used admin tools instead of deploying obvious malware. Darktrace observed the attack begin with compromised VPN credentials and reconnaissance using Nmap scans targeting ports 21, 80, 445, 4899, and 8080. The attacker escalated privileges by abusing Active Directory replication via drsuapi::DRSGetNCChanges, then moved laterally with legitimate utilities such as PSExec, WMI, and RDP. Darktrace reported use of the Sliver framework for command-and-control and exfiltration of data to Wasabi cloud storage. On Day 4, the ransomware payload spread using SMBv1 and encrypted systems across the environment. The attack resulted in both data theft and encryption, causing operational shutdowns and exposing the business to double-extortion threats.

Qilin pivots through enterprise VPN weaknesses

The Qilin ransomware group targets enterprise VPN and firewall appliances by combining credential harvesting with exploitation of unpatched flaws. Qilin uses remote access to bypass perimeter defenses, enabling lateral movement, privilege escalation, and ransomware deployment as part of a double-extortion strategy. Qilin specifically targets VPN solutions from Palo Alto Networks, Fortinet, Citrix, and Check Point, making shared infrastructure a single point of failure. Qilin campaigns result in stolen data, regulatory exposure, operational disruption, reputational damage, and direct financial loss. Cybersecurity Insiders emphasize that security updates are available for many known issues, but exploitation depends on systems remaining unpatched.

Cruciferra crypter boosts stealthy malware

The Cruciferra crypter-as-a-service enables criminals to evade antivirus detection and is sold commercially for $450 to $2,000 per month. Cruciferra supports multiple unrelated groups and delivers payloads such as Snake Keylogger and XWorm. Cruciferra has been linked to campaigns by TA4922, a Chinese-speaking group with overlaps with Silver Fox, using income-tax-themed lures targeting Indian taxpayers and ZIP files disguised as tax documents. Cruciferra employs unique encryption routines and modular defense-evasion features that complicate static analysis. Victims may experience prolonged infections and increased credential theft before detection.

Top Vulnerabilities Reported in Last 24 hours

Hackers hit Arista VeloCloud orchestrators

CVE-2026-16812 is a command-injection vulnerability in Arista VeloCloud Orchestrator (VCO) with a CVSS score of 10.0. Successful exploitation allows unauthenticated attackers to execute OS commands and potentially take over the SD-WAN control plane. CVE-2026-16812 is already being exploited in the wild. Arista stated the issue was discovered externally, and CISA has added it to the Known Exploited Vulnerabilities catalog. A fix is available in VCO versions 5.2.3.14, 6.1.3.4, and 6.4.2.4 and later, and all orchestrator-managed data and associated VeloCloud Edge devices are at risk if unpatched.

FastJson zero-day targets US businesses

CVE-2026-16723 is a remote code execution vulnerability in the FastJson Java library that is being exploited to run attacker-controlled code remotely without user interaction or elevated privileges. Successful exploitation of CVE-2026-16723 enables attackers to abuse @type processing during deserialization, bypassing AutoType restrictions. CVE-2026-16723 is already being exploited in the wild. Researchers at FearsOff reported the issue, with attacks targeting US-based organizations in Financial Services, Healthcare, and Retail. No fix is currently available for CVE-2026-16723, and FastJson 1.x is no longer actively maintained, leaving affected systems exposed.

Public exploit boosts Linux kernel risk

CVE-2026-53264 is a Linux kernel vulnerability in the network traffic-control subsystem that allows local attackers to escalate privileges to root. Exploitation of CVE-2026-53264 enables attackers to turn a local foothold into full system control via a use-after-free race condition. A working exploit for CVE-2026-53264 has been publicly released. Researcher Lee Jia Jie used AI assistance to discover the flaw and develop the exploit, increasing visibility and the likelihood of copycat attacks. The upstream fix was released on June 1, 2026, but patching across Linux distributions remains inconsistent, with some still shipping vulnerable packages.

Top Threat Actors Reported in Last 24 hours

RedRelay network shields China-linked espionage

RedRelay is a multi-hop infrastructure-as-a-service network suspected to originate from China and used primarily for espionage. RedRelay enables groups including Vixen Panda, Red Vulture, and Nylon Typhoon to route operations through compromised routers, IoT devices, and leased VPS nodes. RedRelay supports global intrusion campaigns against government, defense, and telecom targets. The network blurs operational boundaries, slowing investigations and takedowns. Researchers identified a distinctive FCN Linux command (“ip a”) and linked tunneling activity to the bulbature payload (also known as WHIPWEAVE), providing tracking clues for defenders.

Qilin ransomware hits exposed enterprise VPNs

Qilin is a ransomware group suspected to operate from an unknown origin, with financial gain as its primary motive. Qilin uses credential harvesting and exploits unpatched VPN and firewall vulnerabilities to gain unauthorized access. Qilin targets VPN solutions from Palo Alto Networks, Fortinet, Citrix, and Check Point, causing operational disruption, reputational fallout, and regulatory exposure. Qilin employs a double-extortion playbook, stealing data before encrypting systems. Recommended mitigations include enabling multi-factor authentication, prioritizing security updates for VPN/firewall appliances, and conducting regular security assessments.

Teams vishers push GoGRPC backdoor

An initial access broker of unknown origin is using Microsoft Teams vishing to trick employees into launching Quick Assist sessions and deploying the GoGRPC backdoor. The actor has been active since January 2026, starting with spam bombing and impersonating IT staff to gain access. The actor uses four GoGRPC variants—Lep, Giver, Pet, and Kind—that differ in fingerprinting, obfuscation, and C2 communication, including mutex-based single-instance checks and TLS support. The actor targets corporate environments, where a single coerced support session can lead to broader compromise and set the stage for ransomware or data theft. Zscaler also observed use of BlindDoor, RevSocket, PyGRPC, and RSOX, indicating a toolkit designed for persistent access and lateral movement.

Frequently Asked Questions

  1. What is Darktrace? Darktrace detailed a four-day, multi-stage ransomware intrusion that blended into normal IT activity by leaning on widely used admin tools instead of loud, obvious malware. It began with compromised VPN credentials and reconnaissance that included Nmap scans targeting ports 21, 80, 445, 4899, and 8080, before the operator escalated privileges by abusing Active Directory replication via drsuapi::DRSGetNCChanges.

  2. What is Qilin? Qilin is targeting a familiar weak point for many companies—enterprise VPN and firewall appliances—by combining credential harvesting with exploitation of unpatched flaws to get inside networks. Once it has remote access, it can bypass perimeter defenses and set the stage for lateral movement, privilege escalation, and ransomware deployment as part of its double-extortion playbook.

  3. What is Cruciferra? Cruciferra is a crypter-as-a-service designed to help criminals sneak malware past antivirus tools, and it is being sold commercially for $450 to $2,000 per month. Rather than being tied to a single gang, it supports multiple unrelated groups and can deliver different payloads, including Snake Keylogger and XWorm.

  4. What is CVE-2026-16812? A critical command-injection flaw in Arista VeloCloud Orchestrator (VCO) (CVE-2026-16812, CVSS 10.0) lets unauthenticated attackers execute OS commands and potentially take over the SD-WAN control plane. Because VCO is exposed by default, attackers can reach the web interface and jump straight into privileged internal functionality without needing credentials, putting orchestrator-managed data and potentially associated VeloCloud Edge devices at risk.

  5. What is CVE-2026-16723? A critical remote code execution flaw in the FastJson Java library (CVE-2026-16723) is being exploited to run attacker-controlled code remotely without user interaction or elevated privileges, with attacks reported as primarily targeting US-based organizations. The weakness stems from FastJson’s type-resolution logic, where attacker-controlled resource lookups can occur before AutoType restrictions are enforced, enabling abuse of @type processing during deserialization.

  6. What is CVE-2026-53264? A Linux kernel bug (CVE-2026-53264) allows local attackers to escalate privileges to root, turning a foothold on a machine into full control. The issue sits in the kernel’s network traffic-control subsystem, where a use-after-free race condition can be exploited under specific configuration and build conditions.

  7. What is RedRelay? RedRelay is being used as a multi-hop “hide the origin” network for China state-linked intrusion activity tied to groups including Vixen Panda, Red Vulture, and Nylon Typhoon. The infrastructure is described as an infrastructure-as-a-service model built from compromised routers, IoT devices, and leased VPS nodes, giving multiple Chinese APTs a shared way to route operations.

  8. What is Qilin? The Qilin ransomware group is actively breaking in through enterprise remote-access gateways, targeting VPN solutions from Palo Alto Networks, Fortinet, Citrix, and Check Point. They do it by credential harvesting and exploiting unpatched VPN and firewall vulnerabilities, turning perimeter devices into a direct on-ramp for unauthorized access and eventual ransomware deployment.

  9. What is GoGRPC? A threat actor believed to be an initial access broker is using Microsoft Teams vishing to trick employees into launching Quick Assist sessions, then planting a Go-based backdoor called GoGRPC. Active since January 2026, they typically start by “spam bombing” inboxes and then impersonate IT/helpdesk staff to persuade targets to open a Quick Assist link, giving them a foothold in corporate environments.

Discover Related Resources