Cyware Daily Threat Intelligence - September 15, 2026

Attackers are exploiting a patch gap in Google Chrome and Microsoft Windows to quietly install backdoors and credential stealers before official fixes reach users. On cyware.com, we track how UTA0560 and other actors chain multiple vulnerabilities, using spear-phishing and reflected XSS to redirect victims and gain deep control over targeted systems.
A hijacked HBO Max Reddit account ran 108 malicious ads in just 48 hours, steering users to fake crypto wallet sites and delivering malware to both Windows and macOS devices. A single copy-and-paste mistake can now lead to account theft or diverted payments.
A China-linked group scanned 1,386 Gitea servers and compromised 13 organizations across six countries, using automated tools and Linux implants to maintain persistence and steal data from development environments.
Top Malware Reported in the Last 24 Hours
UTA0560 weaponizes Chrome zero-day patch gap
GRIMWEDGE is a backdoor deployed by UTA0560, a Chinese threat actor, to gain persistent access to targeted systems. GRIMWEDGE can execute commands such as Info, Dir, Mkdir, Del, Tasklist, Taskkill, Type, Run, and Upload, enabling attackers to control compromised hosts. GRIMWEDGE is delivered through spear-phishing that leverages a reflected XSS weakness, then chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to achieve arbitrary code execution. GRIMWEDGE targets NGOs and organizations using Google Chrome and Microsoft Windows. JungleBamboo, a second actor, uses the same chain to deploy LONGTALE, a credential-stealing Chrome extension. The campaign was discovered before official Chrome stable fixes were available; patches are released only after Chrome stable updates catch up to Chromium fixes.
PasteSwitch turns Reddit ads into malware
PasteSwitch is a malvertising campaign that leverages a hijacked HBO Max Reddit account to distribute malware. PasteSwitch uses ClickFix-style lures to trick users into running malicious commands on Windows and macOS. PasteSwitch ran 108 malicious ads over 48 hours, directing victims to fake sites such as hbomaxx[.]app, codex-craft[.]com, and apple.clean-disk-guide[.]com. On macOS, PasteSwitch uses Base64-encoded terminal commands via ClickFix prompts; on Windows, it relies on mshta and PowerShell to execute payloads. PasteSwitch can deliver information stealers and cryptocurrency clippers, resulting in account theft or diverted payments. Reddit admins paused the ads and escalated the incident to their Security and Safety teams.
Hacking Cat escalates with RAT and ransomware
Hacking Cat is a pro-Ukraine hacktivist group active since February 2024, shifting from defacements to malware-driven intrusions against Russian targets. Hacking Cat exploits vulnerabilities in Microsoft Exchange servers to deploy Gorilla RAT for remote access and expand operations. Hacking Cat has breached a contractor for Rosatom and attacked Donbassteploenergo with Monkey Ransomware, which encrypts data and appends a .monkey extension. Multiple Monkey Ransomware variants may be produced with generative AI. Affected organizations face operational disruption and data loss, with remediation dependent on patching the exploited Exchange vulnerabilities.
Top Vulnerabilities Reported in Last 24 hours
No critical vulnerabilities were reported in the last 24 hours.
Top Threat Actors Reported in Last 24 hours
Red Heron hits Gitea servers worldwide
Red Heron (suspected China-linked) is a threat actor focused on espionage and data theft. Red Heron exploits a critical Gitea remote-code-execution flaw and uses an automated Python framework (exp_enhanced[.]py) to scan and compromise development servers. Red Heron relies on a C++ Linux implant (JITTERLY) and an LD_PRELOAD rootkit (SIXZUT) to maintain persistence and support lateral movement. Red Heron targets election bodies, government teams, aerospace firms, and research organizations across multiple regions. The campaign included enumeration of an Argentine firm, data theft from a Taiwanese company, and infrastructure mapping at a Canadian company. Red Heron compromised 13 organizations in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka.
Hacking Cat shifts to destructive malware
Hacking Cat (pro-Ukraine hacktivist group) is suspected to originate from Ukraine and is motivated by disruption of Russian organizations. Hacking Cat collaborates with Cyber Anarchy Squad and Ukrainian Cyber Alliance, sharing tooling and infection chains. Hacking Cat uses Gorilla RAT for remote access and deploys Monkey Ransomware, which encrypts data and appends a .monkey extension. Hacking Cat targets Russian organizations and contractors, raising the risk of operational outages and encrypted systems. The group’s campaigns involve near-identical infection chains and public disputes over malware attribution. Researchers have found numerous Monkey Ransomware variants, some possibly developed with generative AI.
ShinyHunters phone phish targets passkeys
ShinyHunters (criminal group) is suspected to operate for financial gain. ShinyHunters uses telephone-based phishing to defeat passkeys, MFA, and SSO by impersonating helpdesk staff and directing victims to credential-harvesting pages. ShinyHunters relies on private phone calls and device-code phishing flows, leaving little endpoint evidence. ShinyHunters targets IT and security teams, enabling account takeover and downstream data exposure. Recent campaigns include attacks on North American water utilities, resulting in boil water advisories and manual operations. Microsoft has warned that these tactics are active in the wild and combine social engineering with techniques that lower the barrier to real-world disruption.
Frequently Asked Questions
What is UTA0560? UTA0560, described as a Chinese threat actor, is exploiting a patch gap in Google Chrome alongside Microsoft Windows flaws to install the GRIMWEDGE backdoor on targeted systems. It starts with spear-phishing that leverages a reflected XSS weakness to redirect victims, then chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to reach arbitrary code execution and deeper control.
What is PasteSwitch? PasteSwitch is a malvertising campaign that used a hijacked HBO Max official Reddit account to push ClickFix-style lures that trick people into running malicious commands on Windows and macOS. The operation ran 108 malicious ads over 48 hours, steering victims to fake sites such as hbomaxx[.]app, codex-craft[.]com, and apple.clean-disk-guide[.]com that advertised bogus apps (including fake crypto wallets like Ledger, Trezor Suite, and Exodus).
What is Hacking Cat? Hacking Cat, a pro-Ukraine hacktivist group active since February 2024, is being tracked as it shifts from defacements toward malware-driven intrusions against Russian targets. According to reporting that cites Kaspersky, it exploits vulnerabilities in Microsoft Exchange servers to deploy Gorilla RAT for remote access, then uses that foothold to expand operations.
What is Red Heron? Red Heron, a China-linked threat actor, is exploiting a critical Gitea remote-code-execution flaw to rapidly break into exposed development servers across multiple regions. They scanned 1,386 Gitea instances and kept a dataset of 477 Taiwan-based systems, then moved from broad discovery to targeted intrusions that included enumeration of an Argentine firm, data theft from a Taiwanese company, and infrastructure mapping at a Canadian company.
What is Hacking Cat? Hacking Cat, a pro-Ukraine hacktivist group, is moving beyond web defacements and into malware-backed intrusions and disruptive attacks against Russian targets. They have collaborated with other hacktivist crews including Cyber Anarchy Squad and Ukrainian Cyber Alliance, with shared tooling and near-identical infection chains that blur who is responsible for what.
What is ShinyHunters? ShinyHunters, a criminal group, is associated with telephone-based phishing that aims to defeat passkeys, MFA, and SSO by impersonating helpdesk staff and steering victims to credential-harvesting pages. After the first mention, they rely on private phone calls and device-code phishing flows that can leave little endpoint evidence, then use stolen credentials and session tokens to expand access inside organizations.