Cyware Daily Threat Intelligence - September 09, 2026

A surge of ransomware and infostealer activity is slashing through critical sectors, with Cyware tracking Panzer ransomware’s rapid assault on Italian industry. Attackers are disabling recovery tools and deleting shadow copies, leaving manufacturers and telecoms facing both operational outages and the threat of sensitive data leaks. The group’s automated affiliate screening complicates investigation, and defenders are left relying on behavioral detection as no verified IOCs have surfaced.
Patch volumes are breaking records as Microsoft ships fixes for 974 vulnerabilities, including actively exploited flaws that let attackers seize SYSTEM privileges. Meanwhile, CitrixBleed 2 is forcing urgent patch deadlines as attackers hijack sessions and bypass MFA, and Google’s Chrome update closes a zero-day that could let a single web page compromise a device.
Threat actors are chaining zero-days and social engineering to breach organizations at scale. TA412 is leveraging the BlueMoon exploit kit for instant device compromise, while Scattered Spider racks up over 100 intrusions and $100 million in ransom by targeting people, not just software. Healthcare, aerospace, and financial institutions are all in the crosshairs as attackers pivot tactics and tools.
Top Malware Reported in the Last 24 Hours
Panzer ransomware hits Italian industry fast
Panzer is a newly emerged Ransomware-as-a-Service (RaaS) operation first observed in August 2026, specializing in double-extortion attacks. Panzer steals data before encrypting systems, forcing victims to contend with both operational outages and the threat of sensitive information exposure. Panzer disables Windows recovery environments and deletes Volume Shadow Copies, making recovery difficult and prolonging downtime. Panzer is distributed via a sophisticated affiliate platform with automated analyst screening, complicating external investigation. Panzer targets Italian manufacturing and telecommunications sectors, focusing on Windows environments. No verified malware samples or network IOCs are available, and researchers recommend phishing-resistant MFA, strong network segmentation, and DLP controls as mitigations.
Infostealers pivot to AI coding agents
Amatera and Remus are infostealers detected on Windows that target data from AI coding agents such as Claude, Cursor, Codex, Cline, Continue, and OpenCode, while Djinn Stealer targets several of these tools on macOS. Amatera and Remus steal access tokens, enabling attackers to consume paid AI capacity or gain temporary account access, and can expose prompt histories containing internal hostnames, repository structures, customer data, API keys, or trade secrets. Remus, a variant of Lumma Stealer, uses shared string obfuscation, anti-VM checks, syscall handling, indirect control-flow obfuscation, and an Application-Bound Encryption bypass, and leverages Ethereum smart contracts for resilient C2 resolution. Infostealers can expand to new AI tools through configuration updates, allowing existing infections to harvest new data without redeployment. CallbackBeaver has expanded to include Claude and Cursor, with over 5,000 samples observed in a recent 30-day period; using OS-backed credential stores and MFA are cited as mitigations.
Mirage Kitten lures engineers via LinkedIn
Mirage Kitten is an Iran-linked cyberespionage group targeting software engineers with the cross-platform NodeRabbit and PollCat RATs. Mirage Kitten uses fake recruiter personas on LinkedIn and similar platforms to deliver trojanized coding challenges that bundle malicious npm packages. Mirage Kitten achieves persistence and cross-platform operation on Windows, Linux, and macOS, turning job inquiries into long-term footholds on developer systems. Mirage Kitten leverages evasive infrastructure, including legitimate cloud services like Azure and domain mimicry, to avoid detection. Mirage Kitten targets aviation, aerospace, and fintech organizations in the Middle East and Africa. Researchers highlight the risk of compromised engineering environments exposing proprietary code and internal access paths.
Top Vulnerabilities Reported in Last 24 hours
Microsoft patches record 974 security flaws
CVE-2026-81963 (Windows Update Stack privilege escalation) and CVE-2026-85880 (Windows ALPC privilege escalation) are critical vulnerabilities in Microsoft Windows with a record CVSS score (not specified). Successful exploitation allows attackers with local access to escalate privileges to SYSTEM, granting full control over the affected machine. Attackers are already exploiting these vulnerabilities in the wild. Researchers at Volexity and Proofpoint contributed to the discovery of these flaws. Microsoft’s September 2026 Patch Tuesday addresses a total of 974 vulnerabilities, including an Exchange remote code execution bug (CVE-2026-55007) that can be triggered via a Visio email attachment with no user interaction.
CitrixBleed 2 exploited, CISA orders patch
CVE-2025-5777 (CitrixBleed 2) is a critical memory disclosure vulnerability in Citrix NetScaler with a high CVSS score (not specified). Successful exploitation allows attackers to extract sensitive data, including session tokens, from device memory and hijack user sessions, bypassing multi-factor authentication. Confirmed exploitation is ongoing, and the vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog. CISA has issued an urgent directive requiring federal agencies to patch within 24 hours. Over 400 NetScaler instances remain unpatched, and a related vulnerability (CVE-2025-6543) affects roughly 500 deployments.
Chrome zero-day lets attackers run code
CVE-2026-87491 is a remote code execution vulnerability in the Chrome V8 engine with a critical CVSS score (not specified). Successful exploitation allows attackers to execute code inside Chrome’s sandbox via a crafted HTML page, enabling drive-by compromise and potential data theft or account takeover. Attackers are already exploiting this vulnerability in the wild. The bug was discovered by Jihyeon Jeong of Compsec Lab, Seoul National University, and Google credited internal tools such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL for detection. The update also patches additional critical flaws, including WebGL issues (CVE-2026-87464, CVE-2026-87488, CVE-2026-87438, CVE-2026-87527) and a Cast use-after-free bug (CVE-2026-87628). A fix is available in Chrome 153.0.8010.36/.37 (Windows/macOS) and 153.0.8010.36 (Linux).
Top Threat Actors Reported in Last 24 hours
TA412 and peers rush BlueMoon zero-days
TA412 (China-aligned, no aliases provided) is a suspected state-sponsored group focused on espionage and access operations. TA412 rapidly adopts the BlueMoon exploit kit to chain zero-days, including CVE-2026-85046 (Chrome V8 RCE) and CVE-2026-85880 (Windows kernel privilege escalation), to achieve device compromise and privilege escalation after spearphishing. TA412 uses malicious browser extensions and targets NGOs, aerospace firms, manufacturers, and government teams, primarily in the US and Southeast Asia. TA412’s recent campaign, described by Proofpoint, enabled data theft and deeper network access via email lures. TA412’s activity overlaps with UNK_LateNight (targeting US aerospace with ShadowPad), UNK_DoubleCheck (Vietnamese manufacturing with Rust-based malware), and UNK_QuietRacket (Southeast Asian government and financial targets with modified payloads).
Scattered Spider keeps breaking in via people
Scattered Spider (no aliases provided) is a suspected cybercrime collective motivated by financial gain. Scattered Spider uses social engineering tactics such as vishing and SIM swapping to bypass technical controls and gain access. Scattered Spider collaborates with other groups including LAPSUS$ and ShinyHunters, and deploys ransomware such as ALPHV/BlackCat and DragonForce. Scattered Spider targets airlines, insurers, retailers, and large employers, leading to outages and business disruption. Scattered Spider’s recent campaigns include high-profile incidents at MGM Resorts and Caesars Entertainment, with over 100 network intrusions and $100 million in ransom payments. Despite arrests, Scattered Spider remains active and shifts targets as opportunities arise.
ShinyHunters and Mirage Kitten target staff
ShinyHunters (no aliases provided) is a suspected cybercrime group focused on credential theft and extortion. ShinyHunters uses vishing campaigns and reverse-proxy phishing kits to steal credentials and bypass MFA, employing aggressive follow-up voicemails and registering medical-themed domains to target healthcare staff. ShinyHunters targets hospitals and health organizations, with access often extending to cloud services like Microsoft 365 and Salesforce. ShinyHunters’ recent campaigns increase the risk of data exposure and extortion in the health sector. Separately, Mirage Kitten (Iran-linked) targets software engineers by posing as recruiters and delivering trojanized coding challenges that install NodeRabbit and PollCat RATs, focusing on aviation, aerospace, and fintech in the Middle East and Africa. In financially motivated activity, Slim Spider has targeted Brazilian financial institutions since March 2026, stealing cryptocurrency custody secrets and abusing Pix instant payments, highlighting the growing threat to digital-asset operations and payment rails.
Frequently Asked Questions
What is Panzer? Panzer is a newly emerged Ransomware-as-a-Service (RaaS) operation first observed in August 2026, and it is already moving quickly against Italian manufacturing and telecommunications targets. It uses a double-extortion playbook by stealing data before encrypting systems, leaving victims facing both outage pressure and the risk of sensitive information being published.
What is Amatera? Amatera and Remus have been detected on Windows targeting data from AI coding agents such as Claude, Cursor, Codex, Cline, Continue, and OpenCode, while Djinn Stealer targets several of these tools on macOS. Once inside, it can steal access tokens that attackers can use to consume paid AI capacity or gain temporary account access, and it can also expose prompt histories that may contain internal hostnames, repo structures, customer data, API keys, or trade secrets.
What is Mirage Kitten? Mirage Kitten, an Iran-linked cyberespionage group, is targeting software engineers with the cross-platform NodeRabbit and PollCat RATs. It approaches victims using fake recruiter personas on LinkedIn and similar platforms, then pushes trojanized “coding challenges” that bundle malicious npm packages to launch the malware.
What is CVE-2026-81963? Microsoft’s September 2026 Patch Tuesday ships fixes for a record 974 vulnerabilities, including bugs the company says attackers are already using. Two of the actively exploited issues — the Windows Update Stack flaw (CVE-2026-81963) and a Windows ALPC flaw (CVE-2026-85880) — can let an intruder who already has a foothold on a machine jump privileges up to SYSTEM, effectively taking full control.
What is CVE-2025-5777? A critical Citrix NetScaler flaw dubbed “CitrixBleed 2” (CVE-2025-5777) can let attackers pull sensitive data out of device memory — including session tokens — and hijack user sessions in a way that can bypass multi-factor authentication. In practical terms, that can mean an attacker logs in as a legitimate user without ever knowing their password, putting remote access gateways in the crosshairs.
What is CVE-2026-87491? Google’s latest Chrome update fixes 230 vulnerabilities, led by an actively exploited zero-day in the V8 engine (CVE-2026-87491) that can allow remote code execution inside Chrome’s sandbox via a crafted HTML page. For everyday users, that can translate into a drive-by compromise scenario where simply viewing content in a browser could let an attacker run code and pivot toward data theft or account takeover.
What is TA412? TA412, a China-aligned threat actor, is among several state-aligned groups rapidly adopting the BlueMoon exploit kit to turn spearphishing into near-instant device compromise using chained zero-days. They abuse CVE-2026-85046 (Chrome V8 remote code execution) and CVE-2026-85880 (Windows kernel privilege escalation) to run code and elevate access after a target clicks.
What is Scattered Spider? Scattered Spider, a cybercrime collective, keeps racking up intrusions by attacking people and processes rather than software—using social engineering like vishing and SIM swapping to talk their way past defenses. They have been linked to over 100 network intrusions and $100 million in ransom payments, with high-profile incidents including MGM Resorts and Caesars Entertainment.
What is ShinyHunters? ShinyHunters, a cybercrime group, is actively targeting the health sector with vishing campaigns designed to steal credentials and bypass MFA, including pressure tactics like aggressive follow-up voicemails. They use reverse-proxy phishing kits to capture logins in real time and establish unauthorized sessions, and they register medical-themed domains to make lures feel routine to busy healthcare staff.