Cyware Daily Threat Intelligence - September 03, 2026

Attackers are turning everyday software downloads and social media activity into high-stakes security risks, as seen in campaigns that siphon credentials, monitor keystrokes, and quietly bypass endpoint defenses. Cyware spotlights how a single installer or a stealthy rootkit can open the door to persistent surveillance, while AI-assisted malware now assembles detailed user profiles for fraud and account takeover.
Edge devices and VPN appliances remain prime targets, with attackers chaining zero-days and exploiting decade-old bugs to seize control of perimeter systems. Recent incidents tracked by cyware.com show how state-backed and criminal groups converge on the same vulnerabilities, using rogue admin accounts and lateral movement to breach internal networks and extract sensitive data from organizations worldwide.
Ransomware operators and advanced threat groups are escalating their tactics, from custom malware targeting Russian companies to coordinated exploitation of SonicWall VPNs in Australia, the United States, and Switzerland. These campaigns blend credential theft, data extortion, and disruptive encryption, underscoring the urgent need for rapid patching and vigilant monitoring across all exposed infrastructure.
Top Malware Reported in the Last 24 Hours
NodeStealer evolves into AI-assisted spyware
NodeStealer is a Python-based stealer that has evolved into a comprehensive spyware toolkit with keylogging, clipboard monitoring, and screenshot capture capabilities. NodeStealer uses the pynput library to record keystrokes, pyperclip to monitor clipboard activity, and pyautogui to capture screenshots, exposing sensitive user data. NodeStealer queries over 20 Facebook Graph API endpoints to build detailed user profiles for fraud and account takeover. The malware is delivered via campaigns that leverage a dual Telegram C2 setup, separating operational data from Facebook-specific collections for resilience. NodeStealer primarily targets victims in Asia and North America, focusing on the financial services sector. Researchers at Netskope identified AI-assisted code and detailed the campaign’s technical evolution.
Silver Fox installers sabotage Windows defenses
Silver Fox is a Chinese threat group deploying fake software installers to disable Windows Update and undermine Microsoft Defender protections. Silver Fox delivers ZIP-based installers from spoofed vendor pages hosted on .com.cn and .hl.cn domains, with payloads dynamically generated per download to evade detection. Silver Fox establishes persistence via scheduled tasks, modifies Defender exclusions using PowerShell, deletes volume shadow copies, and alters access controls to hinder recovery. The group uses non-standard ports for C2 traffic and is linked to domains such as iualef[.]net and oijfwe[.]net, distributing Gh0st RAT and ValleyRAT for data collection and exfiltration. The campaign targets China-based operations and Chinese-speaking users in healthcare, manufacturing, and government sectors, resulting in long-term surveillance or disruptive remediation.
Singularity rootkit slips past Elastic Defend
Singularity is a Linux rootkit engineered for stealth at the kernel level, capable of bypassing Elastic Defend’s eBPF module-load detection by exploiting trusted-process exclusions. Singularity initially triggers alerts but evades them by registering itself as a trusted process, undermining detection controls. Singularity places kernel objects in DKMS directories to blend with legitimate build activity and avoid warnings about new .ko files. The rootkit uses source code obfuscation to reduce YARA matches and hides from interfaces such as lsmod, /proc/modules, and /sys/module. Organizations relying on endpoint visibility for system integrity face the risk of long-running, hard-to-detect compromises.
Top Vulnerabilities Reported in Last 24 hours
Multiple threat groups converge on edge devices
Twelve CVEs affecting edge devices from vendors such as F5, Citrix, Ivanti, and Fortinet are being exploited by state-sponsored and criminal actors, with multi-nexus attribution spanning China, Russia, DPRK, Iran, and ransomware groups. Successful exploitation allows attackers to create rogue admin accounts, export device configurations, reuse stolen credentials, and move laterally into internal networks. These vulnerabilities are actively exploited, with perimeter appliances such as VPN gateways and firewalls under constant pressure. SentinelOne researchers identified the convergence and highlighted Ivanti as facing new exploited CVEs every 8.5 to 13 months, keeping organizations in a repeated cycle of perimeter compromise risk. Affected systems include VPN gateways, firewalls, and remote access appliances across major vendors.
PostgreSQL replication bug enables code execution (CVE-2026-6471)
CVE-2026-6471 is a decade-old vulnerability in PostgreSQL (CVSS not specified) that allows a low-privilege account with the REPLICATION attribute to execute arbitrary code and fully compromise the server. Successful exploitation escalates privileges to superuser across databases and potentially the underlying operating system. CVE-2026-6471 is actively exploited in the wild, with 114 malicious PostgreSQL plugins reported, including trojans and reverse shells. The vulnerability is especially critical for Windows deployments, where attackers can load DLLs from remote SMB servers without placing files locally. A fix is available in recent supported PostgreSQL releases, and all deployments should update immediately.
SonicWall SMA1000 zero-days hit enterprises (CVE-2026-83548, CVE-2026-83549)
CVE-2026-83548 and CVE-2026-83549 are zero-day vulnerabilities in SonicWall SMA1000 VPN appliances that enable unauthenticated access and command execution (CVSS not specified). Attackers exploit SSRF to pivot traffic internally, then use OS command injection to run arbitrary commands, turning the appliance into a credential theft and network entry point. Both vulnerabilities are actively exploited in the wild. INC Ransomware has been linked to attacks targeting organizations in Australia, the United States, and Switzerland, with previous waves involving ROOTRUN, KNUCKLEBALL, and ORANGETAIL malware. A fix is available in firmware 12.4.3-03526 or 12.5.0-02952, and organizations should update immediately.
Top Threat Actors Reported in Last 24 hours
Silver Fox spreads RATs via fake installers
Silver Fox is a China-based threat group suspected of financially motivated operations, specializing in fake software installers. Silver Fox disables Windows Update and weakens Microsoft Defender, then persists via scheduled tasks and PowerShell-based Defender exclusions. Silver Fox distributes trojanized installers from spoofed vendor pages on .com.cn and .hl.cn domains, using ZIP archives and msiexec.exe to launch randomized executables. The group targets healthcare, manufacturing, and government sectors, especially organizations with China-based operations or Chinese-speaking users. The campaign leverages non-standard C2 ports and supports Gh0st RAT and ValleyRAT for credential theft and surveillance. The campaign’s infrastructure and TTPs have been detailed in recent reporting.
INC Ransomware exploits SonicWall SMA1000
INC Ransomware is a financially motivated ransomware group suspected of targeting enterprise VPN appliances. INC Ransomware exploits CVE-2026-83548 (SSRF) and CVE-2026-83549 (OS command injection) to gain root-level control of SonicWall SMA1000 VPN appliances. INC Ransomware uses these appliances as credential collection points, enabling deeper access into internal systems. The group’s activity follows earlier SMA1000 attacks involving ROOTRUN, KNUCKLEBALL, and ORANGETAIL malware. Targeted organizations include those in Australia, the United States, and Switzerland. SonicWall urges customers to apply hotfix firmware and audit for compromise.
VantaCore brings custom ransomware to Russia
VantaCore is a pro-Ukrainian hacker group suspected of financial motivation, targeting Russian companies with custom ransomware and multimillion-dollar ransom demands. VantaCore develops bespoke tooling, avoiding Russian-origin ransomware, and exploits poorly secured VPNs, remote-access tools, and internet-facing application flaws. VantaCore uses a Tor-based chat service for ransom negotiations and operates a leak site for stolen data. The group’s toolkit includes VantaCoreLoader for ransomware delivery and VantaCoreRAT for remote access and data gathering. Victims face both system disruption and reputational fallout if sensitive data is leaked or sold. Defenders are advised to secure remote-access exposure and patch internet-facing applications.
Frequently Asked Questions
What is NodeStealer? <b>NodeStealer</b> has expanded from a Python stealer into a fuller spyware toolkit, with the newest variant adding keylogging, clipboard monitoring, and screenshot capture alongside deep Facebook data theft. It uses the <i>pynput</i> library to record keystrokes, <i>pyperclip</i> to watch what victims copy and paste, and <i>pyautogui</i> to grab screenshots—turning everyday activity into a stream of exposed secrets.
What is Silver Fox? <b>Silver Fox</b>, a Chinese threat group, is using fake software installers to quietly weaken Windows machines by disabling Windows Update and undermining Microsoft Defender protections. After victims arrive at spoofed vendor pages—hosted on <i>.com.cn</i> and <i>.hl.cn</i> domains—the threat delivers ZIP-based installers whose payloads are dynamically generated for each download, making repeatable detection harder.
What is Singularity? <b>Singularity</b> is a Linux rootkit designed to stay hidden at the kernel level, and recent reporting shows how it can bypass Elastic Defend’s eBPF module-load detection by abusing trusted-process exclusions. In testing, it initially triggered alerts, but it evaded them by temporarily registering itself as a trusted process—undercutting the very controls meant to spot suspicious module loads.
What is CVE-2026-6471? A decade-old PostgreSQL vulnerability can turn a low-privilege “backup-style” account into a pathway for arbitrary code execution and full server compromise (<b>CVE-2026-6471</b>). The issue lets an account with the <i>REPLICATION</i> attribute load and run malicious code, escalating to superuser access across databases and potentially the underlying operating system.
What is CVE-2026-83548? SonicWall SMA1000 VPN appliances are being actively exploited via a two-bug chain that can lead to unauthenticated access and command execution on a device that often sits directly on the perimeter (<b>CVE-2026-83548</b> and <b>CVE-2026-83549</b>). The attack flow starts by abusing SSRF to pivot traffic internally, then follows with OS command injection to run attacker-chosen commands—turning the appliance into a credential theft and network entry point.
What is INC Ransomware? <b>INC Ransomware</b>, a financially motivated ransomware group, has been linked to active attacks chaining two newly disclosed SonicWall SMA1000 flaws to take over VPN appliances that sit at the front door of enterprise networks. They exploit <b>CVE-2026-83548</b> (an SSRF issue) to route requests internally without authentication, then pivot to <b>CVE-2026-83549</b> (OS command injection) to run arbitrary commands and ultimately reach root-level control.
What is VantaCore? <b>VantaCore</b>, a pro-Ukrainian hacker group that appears driven primarily by financial gain, is targeting <b>Russian companies</b> with custom ransomware and multimillion-dollar ransom demands. Rather than relying on widely available malware, they are part of a broader reshuffle in pro-Ukrainian circles toward building bespoke tooling and avoiding ransomware with Russian origins.