Cyware Daily Threat Intelligence - July 29, 2026

A ransomware group is transforming extortion into a public spectacle, auctioning off stolen data and demanding ransoms as high as 30 BTC. On cyware.com, we track how this shift exposes both victims and bidders to new legal and reputational risks, with sectors like healthcare and higher education facing direct consequences.
Developers and organizations relying on npm packages are now at risk from a campaign that leverages blockchain technology to deliver remote access trojans. Attackers use compromised packages to drop infostealers and maintain persistent access, with ties to North Korean threat clusters and infrastructure like 23[.]27[.]13[.]43.
Critical vulnerabilities are surfacing across core infrastructure, from Check Point SmartConsole to NGINX and Firefox. Attackers are already exploiting authentication bypasses and remote code execution flaws, with public exploits raising the stakes for administrators and end users alike.
State-backed and criminal threat actors are escalating their campaigns, from Iranian groups deploying new Windows backdoors to Russian-linked hackers targeting Signal users for account takeovers. These operations are leveraging phishing, custom malware, and auction-based extortion to compromise organizations and individuals worldwide.
Top Malware Reported in the Last 24 Hours
CMD Organization ransomware auctions stolen data
CMD Organization is a newly emerged ransomware group that combines file encryption with an auction-style extortion scheme. CMD Organization encrypts files using ChaCha20 for bulk encryption and RSA for key wrapping, targeting databases such as Microsoft Access, Oracle, and Microsoft Exchange. CMD Organization puts pressure on victims by turning data theft into a public marketplace, creating legal exposure for bidders. CMD Organization registered its leak site in March 2026 and has claimed about 30 victims, with confirmed attacks on sectors including healthcare, engineering, construction, aerospace, and higher education. CMD Organization targeted Mount Royal University with a ransom demand of 30 BTC (about $1.9 million).
Joyfill npm packages deliver blockchain RAT
@joyfill/layouts and @joyfill/components are npm packages compromised to deliver a remote access trojan linked to the DEV#POPPER malware family. The malware uses a multi-blockchain resolver across Tron, Aptos, and BNB Smart Chain, allowing attackers to update payload delivery through blockchain transactions. The malware employs a dual payload approach: one branch executes an in-process JavaScript payload, while another launches a Node.js process to fetch and run additional code from 23[.]27[.]13[.]43. The RAT features include file upload, host profiling, clipboard access, and retrieval of further JavaScript, and it drops a Python infostealer that harvests Windows Credential Manager data, browser data, and Git credentials. The campaign is attributed to threat clusters PolinRider and Contagious Interview, associated with North Korean threat actors.
STAC4749 vishes Teams to deploy Chaos ransomware
STAC4749 is leveraging Microsoft Teams “vishing” to convince targets to grant access, leading to deployments of Chaos ransomware across North American organizations. STAC4749 uses .top domains and impersonates IT support staff in Teams chats and calls, steering victims into remote sessions via Microsoft Quick Assist and RemSupp. STAC4749 executes PowerShell to download additional payloads and establishes persistence via registry Run keys, enabling lateral movement. Sophos observed at least three compromises where encryption followed initial access. Between February and June 2026, STAC4749 targeted organizations in Canada and the U.S., focusing on services, manufacturing, energy, and construction.
Top Vulnerabilities Reported in Last 24 hours
CVE-2026-16232: Check Point SmartConsole authentication bypass
CVE-2026-16232 is a critical authentication bypass in Check Point SmartConsole with a CVSS score not specified in the alert. Successful exploitation allows an unauthenticated attacker to gain a full administrator SmartConsole session, exposing security policies and configurations. CVE-2026-16232 is already being exploited as a zero-day. Rapid7 published technical analysis showing attackers can move from unauthenticated network access to privileged operations. A fix is available via vendor-supplied patches, and all SmartConsole deployments are at risk until patched.
CVE-2026-42533: NGINX remote code execution
CVE-2026-42533 is a critical remote code execution vulnerability in multiple NGINX products. Exploitation allows unauthorized attackers to run arbitrary code and potentially take over affected systems. CVE-2026-42533 has not yet been widely exploited, but the release of proof-of-concept exploit code has increased risk. Finland’s National Cyber Security Centre warns the issue affects NGINX Open Source before 1.30.4 and 1.31.3, and NGINX Plus before 37.0.3.1 and R36 P7. The PoC works even when ASLR is enabled. A patch was released on July 15, 2026, and all affected deployments should update immediately.
CVE-2026-10702: Firefox arbitrary code execution
CVE-2026-10702 is a critical flaw in Firefox that enables arbitrary code execution when a user visits a malicious webpage. Successful exploitation can lead to full system compromise. CVE-2026-10702 has public exploit material available from Nebula Security, and the bug is part of an advanced attack chain that can be paired with the GhostLock Linux kernel privilege-escalation flaw on Android. The vulnerability stems from Firefox’s JIT compiler, specifically in MObjectToIterator, allowing arbitrary memory read/write. A fix is available in Firefox 151.0.3, and Tor Browser users are especially at risk if using affected versions.
Top Threat Actors Reported in Last 24 hours
Nimbus Manticore (Iranian state-backed) deploys NightLedger backdoor
Nimbus Manticore (suspected Iranian state-backed) is deploying the NightLedger Windows backdoor to maintain persistent access to victim networks. Nimbus Manticore uses tailored phishing lures, including job opportunity-themed emails and lookalike videoconferencing pages, to deliver malicious archives hosted on third-party file-sharing services. Nimbus Manticore’s backdoor downloads files, collects network information, and updates beacon intervals, allowing flexible and covert operations. Nimbus Manticore targets government, SMB, aviation, and telecommunications organizations across the Middle East, Africa, and South Asia. The campaign uses custom WebSocket tunnelers BridgeHead and ArcBridge, and is linked to HOLLOWGRAPH, which leverages Microsoft Graph API for data exfiltration.
UNC5792 (Russian intelligence-linked) phishes Signal backup recovery keys
UNC5792 (alongside UNC4221, suspected Russian intelligence-linked) is targeting Signal users for account takeover by phishing for Backup Recovery Keys. UNC5792 masquerades as Signal support, claiming a mandatory two-factor verification step, and guides targets through a fraudulent in-app flow to capture the key. UNC5792 uses the stolen key to decrypt and download full account backups, accessing historical message archives and account data. UNC5792’s campaign is global, targeting users of commercial messaging applications, especially government officials, military personnel, and journalists. The reporting warns that if a victim deletes and re-registers an account with the same phone number without generating a new key, UNC5792 can regain access.
Frequently Asked Questions
What is CMD Organization? CMD Organization is a newly emerged ransomware group that is pairing file encryption with an auction-style extortion scheme that invites the public to bid on stolen data. It encrypts files using CMD Organization is a newly emerged ransomware group that is pairing file encryption with an auction-style extortion scheme that invites the public to bid on stolen data.
What is @joyfill/layouts? The npm packages @joyfill/layouts and @joyfill/components were compromised to deliver a remote access trojan linked to the DEV#POPPER malware family, using a multi-blockchain resolver across Tron, Aptos, and BNB Smart Chain. This design lets the attackers update payload delivery through blockchain transactions without republishing the packages, helping the operation stay resilient.
What is STAC4749? STAC4749 is using Microsoft Teams “vishing” to talk targets into granting access, culminating in deployments of Chaos ransomware across North American organizations. The attackers lean on .top domains and impersonate IT support staff in Teams chats and calls, then steer victims into remote sessions using tools such as Microsoft Quick Assist and RemSupp.
What is CVE-2026-16232? A critical authentication bypass in Check Point SmartConsole (CVE-2026-16232) lets an unauthenticated attacker jump straight into a full administrator SmartConsole session, putting security policies and configurations at the attacker’s mercy. Rapid7’s analysis says the break happens at a trust boundary in the authentication path, where misuse of getCertificateDnName() can let an attacker impersonate a trusted application and obtain the tokens needed for SSO access; the Java methods authenticateUser and authenticateRemoteApplication are part of the affected flow.
What is CVE-2026-42533? A critical remote code execution bug in multiple NGINX products (CVE-2026-42533) can allow unauthorized attackers to run arbitrary code and potentially take over affected systems. Finland’s National Cyber Security Centre warns the issue affects NGINX Open Source before 1.30.4 and 1.31.3, and NGINX Plus before 37.0.3.1 and R36 P7, with related impact called out across products such as NGINX Instance Manager and NGINX Ingress Controller.
What is CVE-2026-10702? A critical Firefox flaw (CVE-2026-10702) enables arbitrary code execution simply by luring a user to a malicious webpage, turning routine browsing into a potential system compromise. The Hacker News reports the bug stems from Firefox’s JIT compiler, where handling of operations in MObjectToIterator can be abused for arbitrary memory read/write by reclaiming freed allocations and corrupting a Uint8Array—an exploitation path described as architecture-independent.
What is Nimbus Manticore? Nimbus Manticore, an Iranian state-backed hacking group, is deploying a new Windows backdoor called NightLedger to quietly hold on to victim networks over time. They are drawing targets in with tailored phishing lures, including job opportunity-themed emails and lookalike videoconferencing pages that funnel victims toward malicious archives hosted on third-party file-sharing services.
What is UNC5792? UNC5792 (alongside UNC4221), described as Russian intelligence-linked hackers, is pursuing Signal account takeovers by tricking people into handing over their Backup Recovery Keys rather than breaking Signal’s encryption. They masquerade as Signal support and claim a mandatory two-factor verification step, then walk targets through a fraudulent in-app flow designed to capture the key.
What is CMD Organization? CMD Organization, a new ransomware group, is trying to differentiate itself by turning extortion into an auction—inviting public bidding on stolen data instead of relying on private negotiations. The group has claimed approximately 30 victims, with only a few confirmed, and it recently demanded 30 BTC (about $1.9 million) in an attack on Mount Royal University.