Cyware at Billington CyberSecurity Summit
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 02, 2026

9 min read
shutterstock 2048595065

Attackers are slashing dwell times and maximizing pressure, as seen in the latest wave of double-extortion ransomware. On cyware.com, the Gentlemen operation, linked to GOLD SHERWOOD, has clocked 683 victims by July 2026, with 169 added in a single month. Affiliates move from initial access to encryption in under 24 hours, pairing data theft with file-locking to drive ransom demands.

Zero-day exploitation is sweeping remote access infrastructure, with SonicWall SMA1000 appliances facing chained attacks that combine a CVSS 10.0 SSRF flaw and a CVSS 7.8 command execution bug. Attackers are already exploiting these vulnerabilities in the wild, targeting organizations that rely on these gateways for secure remote access.

Ransomware’s human toll is on display in Berlin, where the Rhysida group stole 1.44 million files and disrupted services for over 50,000 households. The city’s refusal to pay a 30 bitcoin ransom has left sensitive data and regulatory exposure hanging in the balance.

Top Malware Reported in the Last 24 Hours

Gentlemen ransomware hits fast after break-ins

Gentlemen is a ransomware-as-a-service operation specializing in rapid double-extortion attacks. Gentlemen exfiltrates data using tools such as Rclone, Restic, and MinIO Client before encrypting files to maximize leverage. Gentlemen maps networks with Advanced IP Scanner and SoftPerfect Network Scanner, targets credentials via the LSASS process, and establishes persistence with Cloudflared and Datto RMM. Gentlemen affiliates employ defense evasion techniques, including EDR killers like GentleKiller and disabling Windows Defender. Gentlemen typically gains initial access and completes encryption in under 24 hours, targeting organizations across sectors. Sophos attributes the operation to GOLD SHERWOOD, with 683 victim names listed on its leak site by July 2026, including 169 added in July alone.

EtherHiding backdoor uses Polygon as C2

EtherHiding is a malware campaign that leverages the Polygon blockchain to store command-and-control details, enabling dynamic C2 updates that evade simple blocking. EtherHiding delivers a persistent backdoor via compromised websites that display a fake CAPTCHA prompt (“ClickFix”) to trick users into executing malicious commands. EtherHiding maintains persistence across reboots and provides attackers with ongoing access to compromised systems. EtherHiding has been adopted by North Korean state actors since late 2025 and Iran-linked groups by early 2026, following its initial appearance in 2023. GuidePoint Security reports EtherHiding has compromised at least 31 organizations in sectors such as e-commerce and professional services. Endpoint detection clues for EtherHiding include specific registry values, scheduled tasks, and XOR keys.

StreamRat ads lead to Android takeovers

StreamRat is an Android banking trojan distributed through deceptive Meta and TikTok ads, enabling attackers to seize full device control. StreamRat abuses Accessibility Services and the MediaProjection API to provide VNC-style remote control, keylogging, and credential-stealing overlays. StreamRat funnels victims from ads to malicious sites that guide them through payload installation, targeting Spanish-speaking users. StreamRat’s “Steamtv Esp.” campaign targeted approximately 570,000 Meta users in Spain between June and July 2026. StreamRat allows attackers to watch screens, capture logins, and manipulate banking sessions in real time. ThreatFabric highlights on-device detection clues, including Accessibility Services abuse and unusual VPN-related behavior.

Top Vulnerabilities Reported in Last 24 hours

Hackers chain SonicWall SMA1000 zero-days

CVE-2026-83548 (pre-auth SSRF, CVSS 10.0) and CVE-2026-83549 (post-auth RCE, CVSS 7.8) are zero-day vulnerabilities in SonicWall SMA1000 appliances that allow attackers to execute arbitrary OS commands. Successful exploitation enables attackers to break in and run commands on the underlying system. Attackers are actively exploiting these vulnerabilities in the wild, chaining both flaws in real attacks. SonicWall discovered and disclosed the issues, warning that both state-sponsored and ransomware actors are targeting these appliances. Affected devices include SMA1000 models 6210, 7210, and 8200v running 12.4.3-03453 and older or 12.5.0-02835 and older. SonicWall has released hotfixes and urges customers to contact Technical Support for IoCs, re-image compromised appliances, change all passwords, and reset TOTP tokens.

Exchange bug enables mailbox hijacking at scale

CVE-2026-62911 is an authentication bypass vulnerability in Microsoft Exchange Server that allows attackers to hijack user mailboxes, read and send email, and download attachments. Exploitation of CVE-2026-62911 can lead to direct business-email compromise. Public exploit code is available online, lowering the barrier to abuse, though no active exploitation has been explicitly confirmed. The Netherlands’ NCSC (NCSC-NL) reported the availability of exploit code, and Shadowserver identified 21,899 unpatched on-premises Exchange servers exposed, including 6,200 in the United States and 5,100 in Germany. Microsoft has released patches, and 85% of on-premises Exchange servers in Germany remain vulnerable.

Switchvox SQL injection yields remote code execution

CVE-2026-9586 is a critical SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (phone system) with a CVSS score not specified in the source. Successful exploitation allows attackers to execute code as the PostgreSQL superuser and steal cookie signing keys for forging authentication material. Attackers are already exploiting CVE-2026-9586 in the wild, targeting approximately 4,000 exposed instances, most in the U.S. Security Risk Advisors (SRA) Labs independently discovered and reported the issue in April 2026. The report flags IP address 176[.]65[.]148[.]184 for port scanning and brute-force attempts. A patch is available in version 8.4.0.2.

Top Threat Actors Reported in Last 24 hours

GOLD SHERWOOD scales Gentlemen ransomware raids

GOLD SHERWOOD (operator of Gentlemen ransomware) is a suspected criminal group focused on financial gain through double-extortion. GOLD SHERWOOD exploits firewall vulnerabilities such as CVE-2024-55591 and abuses VPN credentials, often bypassing defenses due to absent MFA. GOLD SHERWOOD affiliates use admin tools for discovery and theft, including Advanced IP Scanner, SoftPerfect Network Scanner, LSASS credential targeting, and exfiltration via Rclone, Restic, and MinIO Client. GOLD SHERWOOD targets organizations across sectors, causing operational disruption and data exposure. GOLD SHERWOOD’s campaign began in mid-2025, with victim names first appearing in September 2025 and 683 victims listed by July 2026, including 169 in July alone. Sophos links GOLD SHERWOOD to this activity and recommends MFA enforcement, patching, segmentation, EDR coverage, and regular audits.

Rhysida ransom hit cripples Berlin services

Rhysida is a ransomware-as-a-service group of suspected criminal origin, primarily motivated by financial extortion. Rhysida leverages data theft and encryption to pressure victims, demanding cryptocurrency payments for decryption and non-disclosure. Rhysida infiltrated Berlin’s administrative network, stealing 1.44 million files and demanding 30 bitcoin after a seven-day delay in network isolation. Rhysida’s attack disrupted public services, suspending housing-benefit applications for over 50,000 households and exposing personal records of more than 12,000 people. Rhysida’s campaign was publicly acknowledged by Berlin on August 31, 2026, with ongoing forensic investigations and potential GDPR and NIS2 regulatory exposure if data is published.

Phishers push PowerShell RAT into SLTTs

An as-yet-unnamed threat actor of suspected criminal origin is targeting U.S. state, local, tribal, and territorial (SLTT) government networks for data theft and remote access. The group deploys a custom PowerShell WebSocket RAT and dual remote monitoring and management (RMM) tools, using phishing lures such as Google Drive share notifications and domains impersonating law firms with Unicode homoglyphs. The actor pivots through fake DocuSign PDFs to Google Cloud Storage-hosted downloads, delivering four RAT variants that share core PowerShell code but differ in delivery and stealth. The group targets public-sector teams and other sectors, leveraging “living off trusted platforms” tradecraft to increase the risk of business email compromise. The campaign’s infrastructure overlaps include Cloudzy AS14956 patterns and consistent GCS bucket naming conventions. CISA’s MS-ISAC attributes the activity to this evolving threat group.

Frequently Asked Questions

  1. What is Gentlemen? Gentlemen is a ransomware-as-a-service operation that prides itself on speed, with affiliates often moving from initial access to encryption in under 24 hours. It pairs data theft with file-locking, using exfiltration tools such as Rclone, Restic, and MinIO Client before it encrypts systems to fuel double-extortion pressure.

  2. What is EtherHiding? EtherHiding is a malware campaign that keeps its command-and-control details on the Polygon blockchain, letting operators change where infected machines call home in ways that make simple blocking far less effective. It typically arrives through compromised websites that present a fake CAPTCHA prompt (“ClickFix”) designed to trick users into running the command that installs a persistent backdoor.

  3. What is StreamRat? StreamRat is an Android banking trojan pushed through deceptive Meta and TikTok ads that can escalate from a single click into full device control for Spanish-speaking victims. It abuses Accessibility Services and runs screen streaming via Android’s MediaProjection API, enabling capabilities such as VNC-style remote control, keylogging, and credential-stealing overlays.

  4. What is CVE-2026-83548? Two zero-day flaws in SonicWall SMA1000 secure remote access appliances let attackers break in and run commands on the underlying system, raising the stakes for organizations that rely on these gateways for remote access (CVE-2026-83548, CVSS 10.0; CVE-2026-83549, CVSS 7.8). SonicWall says attackers can use a pre-authentication SSRF bug (CVE-2026-83548) to reach internal functionality and then pivot to a post-authentication RCE/command-execution bug (CVE-2026-83549) to execute arbitrary OS commands.

  5. What is CVE-2026-62911? A Microsoft Exchange Server authentication bypass can let attackers hijack user mailboxes—reading and sending email and downloading attachments—turning a single server flaw into a direct business-email compromise risk (CVE-2026-62911). The Netherlands’ NCSC (NCSC-NL) said exploit code is available online, meaning the barrier to real-world abuse is lower than a typical “theoretical” bug report.

  6. What is CVE-2026-9586? A critical SQL injection in Sangoma Switchvox SMB Edition 8.3 can be exploited without credentials to reach remote code execution, giving intruders a path to take over phone-system infrastructure used by smaller organizations (CVE-2026-9586). Researchers say successful attacks can execute code as the PostgreSQL superuser and even enable theft of a cookie signing key that could be used to forge authentication material for arbitrary users.

  7. What is GOLD SHERWOOD? GOLD SHERWOOD, the operator behind the Gentlemen ransomware service, is driving a fast-moving double-extortion business where data theft comes before encryption and the final payload can land within 24 hours of an initial break-in. They are getting in by exploiting firewall weaknesses such as CVE-2024-55591 and by abusing VPN credentials, with the absence of MFA repeatedly enabling unauthorized access.

  8. What is Rhysida? Rhysida, a ransomware-as-a-service group known for financially motivated extortion, has forced Berlin’s government into a public reckoning after a breach of the city’s administrative network. They stole 1.44 million files and demanded 30 bitcoin, an extortion attempt Berlin publicly acknowledged on August 31, 2026 after refusing to pay.

  9. What is PowerShell WebSocket RAT? An as-yet-unnamed threat actor is running a broad phishing operation that has targeted U.S. state, local, tribal, and territorial (SLTT) government networks with a custom PowerShell WebSocket RAT and dual remote monitoring and management (RMM) tooling. They lure victims with Google Drive share notifications and domains impersonating law firms using Unicode homoglyphs, then pivot through a fake DocuSign PDF to a Google Cloud Storage-hosted download.

Discover Related Resources