Cyware Daily Threat Intelligence - September 04, 2026

Attackers are turning the blockchain into a resilient malware delivery network, as over 5,400 small business websites have been compromised by a campaign that hides payloads inside smart contracts. Cyware highlights how this approach, leveraging the BSC testnet and WebRTC channels, lets malicious code persist even as defenders clean up individual sites.
A surge of mass exploitation is slamming WordPress sites, with attackers launching over 440,000 exploit attempts against two popular plugins in just days. The vulnerabilities in Super Forms and Elementor Pro allow remote code execution, and fixes are available, but the scale of attack traffic shows how quickly unpatched sites can be overtaken.
North Korea-linked espionage groups are embedding ted backdoor and CurlRAT into South Korean Linux servers, using HAProxy and SSH keyloggers to maintain long-term access. The campaign, tracked since early 2025, targets media and automotive firms and demonstrates the evolving toolkit and persistence of DPRK APTs.
Top Malware Reported in the Last 24 Hours
EtherHiding hides malware in smart contracts
EtherHiding is a malware delivery technique that leverages blockchain smart contracts to store payloads, making takedowns significantly more difficult. EtherHiding retrieves second-stage scripts via JSON-RPC calls from contracts, allowing the campaign to persist even as individual compromised sites are remediated. EtherHiding operators use the BSC testnet for cost-free deployment and enhanced takedown resistance, distributing lures such as ClickFix-style prompts to entice users into executing commands that fetch the final payload. EtherHiding infects small business websites, particularly those running WordPress and PrestaShop, turning them into persistent malware launchpads. Researchers at Netskope identified a new variant using WebRTC data channels for command-and-control, further complicating detection. EtherHiding has compromised over 5,400 small business websites globally.
StreamRat spreads through Meta and TikTok ads
StreamRat is an Android banking Trojan and infostealer designed to steal credentials and enable remote device control. StreamRat monitors screens, captures input, displays fake login screens, and allows attackers to take over devices in real time. StreamRat is distributed via paid ads on Meta and TikTok platforms, masquerading as a “free TV-streaming” offer and targeting Spanish-speaking users, primarily in Spain. The campaign ran from June 11 through July 3, 2026, reaching approximately 570,000 Meta users by routing them to a site that detected Android devices and customized installation instructions. Malwarebytes reported that after-the-fact ad checks failed to prevent the campaign from gaining momentum. For individuals, a single sideloaded app can compromise banking access and authentication flows.
Shift Browser installs via fake PDF ads
Shift Browser is adware marketed as a security-focused productivity browser but flagged for fingerprinting and persistence techniques. Shift Browser performs system fingerprinting, contacts unwanted program infrastructure, and establishes persistence, mapping to MITRE ATT&CK techniques T1033, T1012, and T1082. Shift Browser is distributed via malvertising campaigns promoting it as a “PDF tool,” with a surge detected on September 2, 2026 across over 50 client environments. Heimdal’s SOC observed browser hijacking, auto-start behavior, and difficult uninstall attempts, increasing the risk of persistent endpoint profiling. Organizations face loss of control over browsing environments and privacy risks from routine “free tool” downloads.
Top Vulnerabilities Reported in Last 24 hours
Mass exploitation hits popular WordPress plugins
CVE-2026-14894 and CVE-2026-32475 are remote code execution vulnerabilities in the Super Forms and Elementor Pro WordPress plugins, allowing attackers to upload malicious files and execute code remotely. Successful exploitation grants full control of affected websites, enabling attackers to run arbitrary PHP payloads. Both vulnerabilities are being actively exploited in the wild, with over 440,000 exploit attempts observed and a peak of over 40,000 requests on August 18, 2026 for CVE-2026-14894. The Hacker News reported the activity, noting attack traffic from multiple sources. Fixes are available in Super Forms 6.3.314 and Elementor Pro 4.2.2, and all unpatched WordPress sites using these plugins are at risk.
FreePBX bug enables unauthenticated server takeover
CVE-2025-57819 is a critical SQL injection vulnerability in the Endpoint Manager module of FreePBX (CVSS 9.8), allowing unauthenticated attackers to execute arbitrary code on exposed phone-system servers. Exploitation can result in data theft or service disruption, as attackers gain shell access without valid credentials. A working proof-of-concept exploit is publicly available on Exploit DB, increasing the risk of widespread attacks. The vulnerability was disclosed by security researchers, and organizations are urged to update to the latest FreePBX releases for affected branches. All unpatched FreePBX servers with the vulnerable Endpoint Manager module are exposed to takeover.
Critical industrial Ethernet stack overflow patched
CVE-2026-78012 is a stack-based buffer overflow vulnerability in Pyramid Solutions’ NetStaX EtherNet/IP Stack (CVSS 9.8), which could allow remote attackers to crash devices or potentially execute code in industrial environments. Successful exploitation is triggered by oversized Class 3 explicit-message requests that exceed buffer limits without error notification. No active exploitation has been reported, but CISA warns that the affected footprint includes various versions of the EtherNet/IP Adapter and Scanner Kits used in manufacturing, energy, water, and chemical sectors. Pyramid Solutions released NetStaX v5.6.1 to address the issue, and all organizations using affected versions should update immediately.
Top Threat Actors Reported in Last 24 hours
DPRK APTs backdoor South Korean Linux servers
DPRK APTs (North Korea-linked espionage actors) are suspected to originate from North Korea and are primarily motivated by intelligence gathering. DPRK APTs use a Linux toolkit featuring the ted backdoor and CurlRAT, integrating with HAProxy to execute remote commands, harvest credentials, and enable surveillance. DPRK APTs deploy CurlRAT only after verifying the presence of HAProxy or cron, and use an SSH keylogger to intercept and encrypt plaintext passwords for exfiltration. DPRK APTs target South Korean media and automotive firms, exploiting vulnerabilities in Groupware login portals and mail servers to establish long-term monitoring. The campaign, observed since early 2025, involves a stager that decrypts configuration strings, profiles systems, and tailors payload deployment. Rapid7 mapped the tactics to MITRE ATT&CK techniques including T1190, T1059.004, T1574.006, T1036.005, T1556.003, T1185, T1071.001, and T1041.
China-linked actors turn PCs into proxies
A threat actor potentially of Chinese origin is suspected to operate from China and is motivated by the creation of proxy and VPN infrastructure. The group installs legitimate remote administration tools such as Radmin and UltraVNC on compromised systems, then adds proxy and tunneling tools including Netch, CCProxy, and SoftEther VPN to repurpose everyday PCs as relay nodes. The actor targets Korean systems, resulting in loss of control and privacy for victims, and exposing their networks to potential blocking or blame for follow-on attacks. The campaign’s access vector remains unknown, but AhnLab identified Chinese-language comments in scripts and configuration artifacts as indicators of a Chinese-speaking operator.
INC Ransom and rivals hit US healthcare
INC Ransom, Anubis, and RansomHouse are ransomware groups suspected to operate globally and are motivated by financial gain through data theft and extortion. INC Ransom and its rivals conduct attacks that result in both data encryption and exfiltration, with some victim data leaked online. The groups target US healthcare organizations, including Alta Orthopaedics in California (impacting 24,496 individuals), Cornerstone Behavioral Healthcare in Maine (14,830 patients), and Cameron Regional Medical Center in Missouri. The attacks involve both encryption and exfiltration, with some incidents claimed by INC Ransom and Anubis. For patients, exposed Social Security numbers, treatment details, and financial data create long-term risks of identity fraud and privacy harm.
Frequently Asked Questions
What is EtherHiding? <b>EtherHiding</b> is a malware delivery technique that makes takedowns harder by storing payloads inside blockchain smart contracts, and it has already compromised over <b>5,400</b> small business websites globally. Instead of relying on a single server that defenders can seize, it pulls second-stage scripts via JSON-RPC calls that retrieve code from a contract, helping the campaign persist even as individual sites are cleaned up.
What is StreamRat? <b>StreamRat</b> is an Android banking Trojan and infostealer pushed to Spanish-speaking users through paid ads that masqueraded as a “free TV-streaming” offer, with most victims located in <b>Spain</b>. Once installed, it can monitor screens, capture input, display convincing fake login screens to steal credentials, and even enable remote control of the device—turning a phone into a live target for account takeover.
What is Shift Browser? <b>Shift Browser</b>, marketed as a security-focused productivity browser, was flagged by researchers as adware with fingerprinting behavior after a malvertising campaign pushed it as a “PDF tool.” Heimdal’s SOC said it detected a surge on <b>September 2, 2026</b>, with installations appearing across <b>over 50</b> client environments, suggesting distribution at a scale that can overwhelm IT teams before they understand what users installed.
What is CVE-2026-14894? Attackers are hammering two WordPress plugin bugs that can hand them full control of a website by uploading a malicious file and running code remotely: Super Forms (<b>CVE-2026-14894</b>) and Elementor Pro (<b>CVE-2026-32475</b>). In the Super Forms case, the report describes an HTTP POST to <i>/wp-admin/admin-ajax.php</i> using the <i>super_submit_form</i> endpoint to deliver a Base64-encoded PHP payload; Elementor Pro is abused by submitting a form’s File Upload field as an array to bypass validation.
What is CVE-2025-57819? A critical FreePBX flaw in the Endpoint Manager module (<b>CVE-2025-57819</b>, CVSS <b>9.8</b>) enables unauthenticated attackers to run arbitrary code on exposed phone-system servers. The published exploit describes a SQL injection path through the <i>brand</i> parameter on the <i>/admin/ajax.php</i> endpoint, which can be chained into code execution by planting a malicious scheduled task.
What is CVE-2026-78012? A memory corruption flaw in Pyramid Solutions’ NetStaX EtherNet/IP Stack (<b>CVE-2026-78012</b>, CVSS <b>9.8</b>) could let remote attackers crash devices or potentially carry out remote attacks in industrial environments. CISA says the issue is a stack-based buffer overflow triggered by oversized Class 3 explicit-message requests that can exceed buffer limits without generating error notifications.
What is DPRK APTs? <b>DPRK APTs</b>, North Korea-linked espionage actors, are running a long-haul intrusion campaign against South Korean media and automotive firms using a Linux toolkit built for stealth and persistence. Rapid7 says the toolkit includes the <b>ted backdoor</b> and <b>CurlRAT</b>, with components integrated with <b>HAProxy</b> to execute remote commands, harvest credentials, and enable surveillance.
What is INC Ransom? Ransomware groups <b>INC Ransom</b>, <b>Anubis</b>, and <b>RansomHouse</b> have been linked to a cluster of reported healthcare data breaches in the US, exposing sensitive medical and identity information. The incidents span multiple states and include both data theft and encryption, with some victim data reportedly leaked online.