Cyware Daily Threat Intelligence - September 18, 2026

A single torrent download can now open the door to a full-scale breach, as attackers wield MovieReaper to hijack systems across continents. Cyware highlights how blockchain-powered command-and-control and tainted files from itorrents[.]org have turned routine activity into a high-stakes risk for enterprises and governments alike.
A zero-click supply-chain flaw threatens the backbone of AI development, as Plugin4Shell exposes coding agents like Claude Code and Copilot to remote takeover. Attackers can swap trusted plugins for malicious ones, putting sensitive code and data at risk even before a single line is executed.
In Latin America, Salt Typhoon is embedding new backdoors into government and telecom networks, leveraging advanced evasion and encrypted channels. Their campaign, active since 2019, now threatens sensitive communications and strategic infrastructure across Argentina, Ecuador, and Venezuela.
Top Malware Reported in the Last 24 Hours
MovieReaper booby-traps torrents with blockchain C2
MovieReaper is a modular, multi-stage malware campaign that enables broad filesystem access and data theft. MovieReaper leverages tainted content from itorrents[.]org and employs the Solana blockchain for command-and-control, complicating takedown efforts. MovieReaper initiates infection through compromised torrent files, then persists to siphon data quietly. MovieReaper targets users in Russia, Türkiye, Japan, Kenya, Uganda, Colombia, and several European countries, impacting enterprise, government, IT, retail, transportation, and agriculture sectors. The campaign began in mid-August 2026 and recommended actions include blocking deadhub[.]org, IPs 193[.]23[.]118[.]155, 208[.]64[.]33[.]90, 208[.]94[.]246[.]53, and monitoring mutexes Global\E4AyDKzvEhe2hgAr and Global\fnulSktzSqvVLXHU.
JADEPUFFER ransomware wipes AI training assets
JADEPUFFER is a ransomware campaign that targets AI development pipelines by deploying ENCFORGE to destroy model checkpoints and training data. JADEPUFFER prioritizes sabotage over double-extortion, focusing on AI artifacts that are costly to rebuild. JADEPUFFER exploits CVE-2025-3248, a Langflow flaw allowing remote code execution via missing authentication. JADEPUFFER has been active since at least July 2026, with operational impacts including stalled releases and recovery costs estimated between $75,000 to $500,000. Recommended mitigations include removing code-validation, administration, and orchestration interfaces from internet exposure and ensuring AI/ML backups are immutable, offline, and routinely tested.
Fake AI trader drops Needle Stealer
Needle Stealer is distributed via a fake “AI trading agent” campaign that compromises browser crypto wallets by replacing legitimate extensions with malicious versions. Needle Stealer uses DLL side-loading and process hollowing to evade detection, and the operation also spreads Phantom Stealer via steganography in about 400 images. Needle Stealer targets users of MetaMask, Coinbase Wallet, and Phantom extensions, where stolen credentials can result in direct financial loss. Needle Stealer also employs QR code phishing with multiple redirects to fake login pages, exploiting less scrutiny in mobile flows. The campaign ran from April to June 2026, and recommended actions include blocking tradingclaw[.]pro and increasing awareness of unverified downloads and QR-code phishing.
Top Vulnerabilities Reported in Last 24 hours
Plugin supply-chain bug hits AI coding agents
Plugin4Shell is a zero-click remote code execution vulnerability affecting Anthropic’s Claude Code, OpenAI’s Codex, Google’s Gemini CLI, Microsoft’s Copilot, and GitHub Copilot. Plugin4Shell allows attackers to swap trusted plugins for malicious ones by abusing SHA-pinning, granting access to the same assets and data as the agent. No active exploitation is confirmed, but the disclosure frames Plugin4Shell as a first-of-its-kind AI supply-chain attack with parallels to SkillJacking and RepoJacking. Researchers disclosed the issue, with Anthropic and OpenAI patched and Microsoft unresponsive at the time of reporting. Mitigation includes updating to patched versions and reviewing plugin marketplace trust models.
Public exploit fuels Orkes Conductor RCE
CVE-2026-58138 is a critical unauthenticated remote code execution vulnerability in Orkes Conductor’s GraalVM script evaluators. CVE-2026-58138 allows attackers to execute arbitrary operating system commands, potentially resulting in full server takeover. Attackers exploit CVE-2026-58138 by submitting malicious workflow definitions containing JavaScript or Python expressions. Attackers are already targeting vulnerable deployments, and public exploit code (Exploit-DB EDB-52633) is available. FortiGuard highlighted the activity in a Threat Signal Report dated September 09, 2026. A fix is available in Orkes Conductor 3.30.2 or later.
Unbound DNS flaw risks remote code execution
CVE-2026-81642 is a critical vulnerability (CVSS 9.1) in the Unbound DNS resolver’s DNSSEC validator that can allow denial of service and potentially remote code execution. CVE-2026-81642 enables attackers controlling a DNS zone to feed crafted data that corrupts resolver memory, risking outages or compromise for dependent services. No active exploitation has been reported by NLnet Labs or CISA. The release also addresses CVE-2026-82717, which could also lead to remote code execution under specific conditions. A fix is available in Unbound 1.26.1.
Top Threat Actors Reported in Last 24 hours
Salt Typhoon backdoors Latin American networks
Salt Typhoon is a China-backed cyber-espionage group suspected of targeting Latin America for strategic intelligence. Salt Typhoon deploys the SparroWocky backdoor, a modular C++ tool using Mbed TLS for encrypted communications, MinHook for API hooking, and a COFF Loader for dynamic plugin execution. Salt Typhoon uses the SilentMoonwalk technique to evade detection. Salt Typhoon targets government and telecom organizations in Argentina, Ecuador, and Venezuela. The group’s campaign leverages US policy shifts affecting China’s investments as a driver for targeting. Activity was uncovered in late 2023, with reporting indicating Salt Typhoon has operated since 2019.
WaterPlum job scams drain crypto wallets
WaterPlum is a North Korean hacking group suspected of financially motivated attacks. WaterPlum uses job-lure campaigns on social media and freelance platforms, posing as AI companies, crypto exchanges, and recruiters. WaterPlum delivers malware via fake coding tasks or interview materials, then hunts for sensitive data to unlock cryptocurrency wallets. WaterPlum targets software developers, web designers, and crypto, blockchain, and Web3 specialists globally. The campaign infected over 30,000 systems in more than 100 countries, leading to theft from over 7,000 wallets totaling more than $10 million in cryptocurrency, according to law enforcement in Germany, Japan, the United States, and Australia.
Panzer ransomware expands to VMware ESXi
Panzer is a ransomware-as-a-service operation suspected of targeting organizations for financial gain. Panzer attacks Windows, Linux, FreeBSD, and VMware ESXi environments, with the ESXi build capable of disabling entire virtualized infrastructures. Panzer leverages multi-platform reach to maximize disruption, and the ESXi variant can turn a single incident into a widespread outage. Panzer targets manufacturing and telecom sectors among others, with 16 organizations affected across 11 countries. Panzer’s campaign contributed to 997 ransomware attacks globally in August 2026.
Frequently Asked Questions
What is MovieReaper? MovieReaper is a modular, multi-stage malware campaign spreading through compromised torrent files, turning routine downloads into an infection chain that can end in broad filesystem access and data theft. It rides on tainted content from the itorrents[.]org repository and then uses the Solana blockchain for command-and-control, a design choice meant to make takedowns and disruption harder.
What is JADEPUFFER? JADEPUFFER is reshaping ransomware playbooks by aiming ENCFORGE at AI development pipelines, going after model checkpoints and training data rather than focusing on traditional file encryption alone. This campaign is described as destruction-first, with the group de-emphasizing double-extortion tactics in favor of sabotaging AI artifacts that can be difficult and expensive to rebuild.
What is Needle Stealer? Needle Stealer is being delivered through a fake “AI trading agent” campaign that targets people searching for trading tools, then quietly compromises browser crypto wallets by replacing legitimate extensions with malicious lookalikes. After the initial install, it uses tactics like DLL side-loading and process hollowing to run while appearing legitimate, and the broader operation also distributes a related Phantom Stealer via steganography tied to about 400 distinct images.
What is Plugin4Shell? A zero-click remote code execution issue dubbed Plugin4Shell could let attackers take over popular AI coding agents by targeting the trusted plugin marketplaces they rely on, rather than the models themselves. Researchers say the attack abuses the agents’ SHA-pinning expectations so a seemingly legitimate plugin can be swapped for a malicious one, handing over the same assets and data the agent can access.
What is CVE-2026-58138? A critical unauthenticated remote code execution flaw in Orkes Conductor’s GraalVM script evaluators (CVE-2026-58138) allows attackers to run arbitrary operating system commands, potentially leading to full server takeover. Attackers can trigger it by submitting malicious workflow definitions containing JavaScript or Python expressions, meaning a compromised Conductor instance can become an entry point into broader internal systems.
What is CVE-2026-81642? A critical flaw in the Unbound DNS resolver’s DNSSEC validator (CVE-2026-81642, CVSS 9.1) could allow denial of service and potentially remote code execution when a resolver processes a malicious DNS zone. In plain terms, an attacker who can control a DNS zone can feed crafted data that corrupts memory inside the resolver, putting services that depend on DNS resolution at risk of outage or compromise.
What is Salt Typhoon? Salt Typhoon, a China-backed cyber-espionage group, is expanding its playbook with a new backdoor called SparroWocky as they zero in on high-profile targets in Latin America. Since August 2025, they have focused on countries including Argentina, Ecuador, and Venezuela, reflecting a reported shift tied to US policies under President Donald Trump that threaten China’s investments in energy, mining, and telecommunications.
What is WaterPlum? WaterPlum, a North Korean hacking group, has been tied to a sweeping job-lure campaign that targets the people who build software—then uses their own work routines against them. They spread the malware through social media, freelance marketplaces, and similar platforms while posing as AI companies, crypto exchanges, and recruitment agencies, luring victims with fake coding tasks or “interview” materials.
What is Panzer? Panzer is a new ransomware-as-a-service operation that emerged in August 2026, quickly claiming victims as that month hit 997 ransomware attacks globally. They target a broad range of environments—Windows, Linux, FreeBSD, and VMware ESXi—a mix that raises the odds they can hit enterprises as well as smaller, under-resourced firms.