Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 17, 2026

9 min read
shutterstock 2605380779

A single missed call on WeChat can now trigger a worm that spreads across over a billion accounts, as Cyware spotlights a zero-click exploit that bypasses user interaction entirely. Attackers leverage a flaw discovered by Calif to compromise both Android and iOS devices, with the risk amplified by root-level access on unpatched systems.

Banking credentials and PINs are under siege as RatHat, a shape-shifting Android malware, uses Wireless Debugging and Accessibility features to steal sensitive data. Victims are lured by familiar app icons, while attackers maintain persistent access through advanced anti-analysis and command-and-control techniques.

Critical vulnerabilities in Cisco ISE and GitLab are being actively exploited, granting attackers root access and exposing sensitive files without authentication. With CISA adding these flaws to the KEV catalog and patch deadlines looming, organizations face urgent pressure to secure their infrastructure against ongoing attacks.

Espionage groups like FamousSparrow and APT36 are intensifying campaigns across Latin America and South Asia, deploying custom backdoors and leveraging typosquatted domains such as theprints[.]org to infiltrate government networks. Meanwhile, Handala Hack continues to surveil dissidents using Telegram-based malware tied to Iran’s MOIS.

Top Malware Reported in the Last 24 Hours

WeWorm

WeWorm is a zero-click worm concept designed to propagate through WeChat VoIP calls, enabling rapid, userless spread across both Android and iOS devices. WeWorm leverages a call from a known contact to trigger infection, even if the recipient ignores the call, and can escalate privileges on Android using the “OEMpocalypse” technique for root access. WeWorm amplifies attacker capabilities post-compromise, allowing deeper system control and persistence. The worm spreads without requiring victims to tap links or open files, exploiting a flaw discovered by an AI system at Calif in July. WeWorm targets WeChat’s massive user base, putting over a billion accounts at risk. Calif reported the flaw to Tencent on July 24, with patches released August 21; prior to patching, account blocking and unblocking sequences may have enabled continued worm propagation.

RatHat

RatHat is an Android banking malware strain engineered to steal sensitive data, including banking credentials and PINs. RatHat exploits Wireless Debugging and Accessibility features to gain shell access, and dynamically changes its icon and label to impersonate trusted apps, deceiving users into entering confidential information. RatHat employs anti-analysis techniques such as ZIP container inconsistencies, padded Android manifests, malformed DEX pseudo-instructions, and string obfuscation to evade detection. RatHat maintains command-and-control via HTTP/WebSocket channels and a local HTTP service, ensuring persistent operator access even after removal attempts. The malware spreads through smishing, malicious ads, and deceptive download portals, primarily targeting mobile banking users. The report attributes RatHat to China-based threat actors and highlights the risk of account takeovers and financial loss.

Shai-Hulud

Shai-Hulud is a worm that infiltrates SaaS providers by hijacking AI coding assistant sessions to deliver poisoned software dependencies. Shai-Hulud installs an infostealer, exfiltrates GitHub OAuth tokens, and propagates laterally through approximately 100 internal code repositories. Shai-Hulud is designed to steal repository secrets and source code, creating a significant supply-chain risk for customers and downstream users. Shai-Hulud leverages compromised development workflows to rapidly expand its reach. Mandiant has identified Shai-Hulud as part of a broader trend of attackers exploiting AI-enabled workflows in real-world campaigns. The report recommends monitoring development environments, blocking known malicious domains and IPs, and conducting regular security audits.

Top Vulnerabilities Reported in Last 24 hours

CVE-2026-76460

CVE-2026-76460 is a critical authentication bypass vulnerability in Cisco Identity Services Engine and ISE-PIC, carrying a CVSS score of 10.0. CVE-2026-76460 allows unauthenticated attackers to access the management plane and execute commands as root, granting full system control. CVE-2026-76460 is actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities catalog and setting a federal patch deadline of September 19, 2026. Cisco disclosed CVE-2026-76460 but has not released details on the intrusions or attribution. Fixes are available in Cisco ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, with no workarounds provided. The vulnerability affects organizations relying on Cisco ISE for network access control.

CVE-2026-85706

CVE-2026-85706 is a critical path traversal vulnerability in GitLab CE and EE that enables unauthenticated attackers to access arbitrary files, exposing credentials and tokens. CVE-2026-85706 can lead to repository and supply-chain compromise, as stolen secrets may impact cloud resources and production workflows. CVE-2026-85706 is under active exploitation, with CISA adding it to the KEV catalog and setting a remediation deadline of September 14, 2026. Researchers at WatchTowr observed behavioral probes against honeypot networks, indicating real attacker interest. Patches are available in versions 19.1.8, 19.2.6, and 19.3.2, and organizations should update immediately to mitigate risk.

CVE-2026-58704

CVE-2026-58704 is a zero-day privilege escalation vulnerability in Google Pixel phones, exploitable via a zero-click attack that requires no user interaction. CVE-2026-58704 resides in the device’s modem and allows attackers to access sensitive data outside the modem’s sandbox. CVE-2026-58704 has been exploited in limited and targeted attacks, though Google has not identified the responsible operators. TechCrunch reports that such exploits are often linked to surveillance-focused actors and spyware vendors. Google has released a patch to address CVE-2026-58704, and users are urged to update promptly to protect privacy and account security.

Top Threat Actors Reported in Last 24 hours

FamousSparrow

FamousSparrow, a suspected China-linked espionage group, is motivated by intelligence collection from government entities. FamousSparrow deploys the SparroWocky backdoor using DLL side-loading and a loader that decrypts and maps an RC4-encoded payload in memory. FamousSparrow relies on evasion techniques such as call stack spoofing and disguising malicious code as legitimate Windows components. FamousSparrow targets government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group’s campaign involves sustained intrusions to siphon confidential internal data and government communications. FamousSparrow’s activity has persisted for over a year, blending into normal system behavior to avoid detection.

APT36

APT36, a suspected Pakistan-nexus threat actor, is primarily motivated by espionage against government and defense sectors. APT36 conducts hands-on reconnaissance and lateral movement using commands such as ipconfig, whoami, arp -a, and net use, and deploys new malware families including the Rust-based backdoor RUSTYSHADE, as well as file-stealing tools PSNATCH and BASHNATCH to exfiltrate data from Windows and Linux systems. APT36 leverages typosquatted domains such as theprints[.]org, officialinfo[.]org, and indiatodays[.]org to deliver lures. APT36’s Operation RapidRust campaign, observed between August 20 and September 1, 2026, targets government and defense entities in India and Afghanistan. The campaign demonstrates the risk of routine-looking “news” or “info” links leading to silent data theft and persistent access.

Handala Hack

Handala Hack, a suspected Iran-linked threat actor, is focused on surveillance of dissidents, journalists, and opponents of the Iranian government. Handala Hack operates the HEAVYGRAM Telegram-based Windows backdoor, delivered via social engineering and impersonation of legitimate apps or contacts. Handala Hack uses executables such as RuntimeSSH.exe and winappx.exe for remote command execution and information theft, blending exfiltration into Telegram API traffic. Handala Hack maintains persistence through Windows registry modifications and PowerShell-based defense evasion. The group targets Iranian dissidents and journalists, with infrastructure linked to Iran’s Ministry of Intelligence and Security (MOIS). In March 2026, the U.S. Department of Justice disclosed domain seizures tied to MOIS and the HEAVYGRAM campaign, summarized in an FBI FLASH report.

Frequently Asked Questions

  1. What is WeWorm? WeWorm is a zero-click worm concept that could spread through WeChat VoIP calls—potentially putting over a billion accounts at risk without anyone tapping a link or opening a file. It propagates when a call comes from a known contact, and it can still trigger even if the recipient ignores the call, affecting both Android and iOS devices.

  2. What is RatHat? RatHat is an Android banking malware strain that uses Wireless Debugging and Accessibility features to gain shell access and steal sensitive data such as banking credentials and PINs. It impersonates well-known apps by dynamically changing its icon and label, pushing victims toward trusting a fake interface while attackers harvest high-value information.

  3. What is Shai-Hulud? Shai-Hulud spread inside a SaaS provider after an attacker hijacked an AI coding assistant session and used it to push a developer toward a poisoned software dependency. After the developer accepted the recommendation, the attack chain installed an infostealer, stole GitHub OAuth tokens, and then used the worm to move through about 100 internal code repositories.

  4. What is CVE-2026-76460? A critical authentication bypass in Cisco Identity Services Engine and ISE-PIC (CVE-2026-76460, CVSS 10.0) lets an unauthenticated attacker break into the management plane and run commands as root. In practical terms, that can translate into full control of a system many organizations rely on to decide who and what gets on the network, with attackers able to hide or remove evidence of compromise.

  5. What is CVE-2026-85706? A critical path traversal flaw in GitLab CE and EE (CVE-2026-85706) allows unauthenticated attackers to access arbitrary files, putting credentials and tokens at risk and potentially opening the door to broader repository and supply-chain compromise. Because GitLab often sits at the center of build and deployment pipelines, stolen secrets can ripple into cloud resources and production workflows far beyond source code.

  6. What is CVE-2026-58704? Google disclosed a zero-day affecting Pixel phones (CVE-2026-58704) that enables privilege escalation through a zero-click attack, meaning a victim may not need to tap or open anything to be compromised. The flaw sits in the device’s modem, and successful exploitation could allow access to sensitive data beyond the modem’s sandbox, raising the stakes for privacy and account security.

  7. What is FamousSparrow? FamousSparrow, a China-linked espionage group, has spent more than a year quietly using its SparroWocky backdoor to collect intelligence from government targets across Latin America. They have deployed the malware in intrusions affecting government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

  8. What is APT36? APT36, a Pakistan-nexus threat actor, has launched a campaign dubbed Operation RapidRust targeting government and defense entities in India and Afghanistan. During activity observed between August 20 and September 1, 2026, they ran hands-on reconnaissance and lateral movement using familiar commands such as ipconfig, whoami, arp -a, and net use before dropping additional payloads.

  9. What is Handala Hack? Handala Hack, an Iran-linked threat actor, is behind HEAVYGRAM, a Telegram-based Windows backdoor used to surveil Iranian dissidents, journalists, and other opponents of the Iranian government. Active since Fall 2023, they deliver it through social engineering, often masquerading as legitimate apps and posing as known contacts or technical support to get a first-stage implant onto a target’s machine.

Discover Related Resources