Cyware at MM-ISAC Conference
Understand Where You Are on the CTI Maturity Curve
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - September 22, 2026

9 min read
shutterstock 2225722675

A new breed of Windows malware is letting artificial intelligence decide the next move, as CLOSEDQUORUM delegates attacks to a panel of large language models. Cyware highlights how this shift slashes the time between compromise and credential theft, with Cisco Talos warning defenders to watch for unusual API traffic and process injection attempts.

Critical vulnerabilities are under active attack, with CISA ordering U.S. agencies to patch three Linux kernel bugs within three days. These flaws, including CVE-2025-39682 (CVSS 9.8), can crash systems or hand over root access, while Zyxel GS1900 switches and Veeam Agent for Windows face their own zero-day exploitation waves.

Threat actors are pivoting fast: SideCopy is now targeting Indian academic institutions with spear-phishing, while the BlueMoon exploit kit chains three CVEs for rapid Windows compromise. Meanwhile, Exvicy’s ClickFix framework is hijacking WordPress sites, turning routine web visits into credential theft.

Top Malware Reported in the Last 24 Hours

CLOSEDQUORUM lets AI vote on attacks

CLOSEDQUORUM is a newly documented Windows implant classified as an autonomous command-and-control system. CLOSEDQUORUM delegates tactical decisions to a quorum of large language models—DeepSeek, Qwen, Mistral, and Google Gemini—using their votes to select actions focused on credential and cryptocurrency wallet theft. CLOSEDQUORUM constrains these choices with an attack-decision language defined by a JSON schema, steering payloads toward capabilities such as steal, inject, persist, and move. CLOSEDQUORUM is delivered to Windows hosts, where it can operate even if a single LLM provider is unavailable. Targeted platforms include Windows environments, with a focus on credential and wallet theft. Cisco Talos discovered the implant and recommends monitoring for unusual LLM API traffic, TLS-inspected structured prompts, and behavioral indicators such as process injection and LSASS access.

INC ransomware uses drivers to disarm defenses

INC ransomware is a Windows-targeting ransomware strain that orchestrates double-extortion attacks. INC uses BYOVD (bring your own vulnerable driver) to disable security controls and then deploys ransomware across the environment. INC leverages AnyDesk for remote access, netscan.exe for network scanning, and scheduled tasks for persistence and lateral movement after a 17-day lull. INC is delivered in two phases, leaving victims with two ransom notes threatening data publication and outreach to stakeholders. Targeted environments include businesses with more than 175 endpoints impacted in the documented case. Huntress reported the incident and recommends blocking known malicious IPs/domains, scanning for specific files, and monitoring for unauthorized scheduled tasks and remote access tools.

ChainScript RAT hides C2 in Polygon

ChainScript is a Node.js-based remote access trojan (RAT) that uses blockchain smart contracts for command-and-control discovery. ChainScript leverages PowerShell and VBScript to run components and persist in user profiles without admin rights. ChainScript retrieves its C2 location from a Polygon smart contract at address 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4 (defanged: 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4), chain ID 137, function selector 0x4ab7874e, caching the result for five minutes to enable backend rotation. ChainScript is distributed via ClickFix campaigns, masquerading as apps like Spotify, Zoom, and Microsoft Teams. Targeted platforms are Windows systems, with persistence achieved through artifacts such as msiexec.exe, wscript, and node.exe. The campaign was discovered during ClickFix investigations, with recommendations to monitor for unusual process relationships and outbound blockchain RPC requests.

Top Vulnerabilities Reported in Last 24 hours

CISA warns of exploited Linux kernel bugs

CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 are Linux kernel vulnerabilities with CVSS scores of 9.8, 7.8, and 8.8 respectively, affecting Linux systems. Successful exploitation can crash systems, corrupt data, or elevate privileges for local attackers. These vulnerabilities are actively exploited in the wild, according to CISA. CISA has directed U.S. government agencies to remediate within three days. Patches are available for affected Linux distributions.

Hackers exploit Zyxel GS1900 switches

CVE-2026-7273 is a stack-based buffer overflow vulnerability in Zyxel GS1900 series switches with a CVSS score not specified in the alert. Successful exploitation allows unauthenticated attackers to execute arbitrary operating-system commands via crafted HTTP requests to the device’s CGI program. CVE-2026-7273 is already being exploited in the wild, and CISA has tracked it as a known exploited issue. Researchers Lei Gu, Jun Cao, Zhiqing Rui, Jingzheng Wu, and Tianyue Luo from ISCAS disclosed the vulnerability. Fixes are available in firmware versions: GS1900-8 2.90(AAHH.2)C0; GS1900-8HP 2.90(AAHI.2)C0; GS1900-10HP 2.90(AAZI.2)C0; GS1900-16 2.90(AAHJ.2)C0; GS1900-24 2.90(AAHL.2)C0; GS1900-24E 2.90(AAHK.2)C0; GS1900-24EP 2.90(ABTO.2)C0; GS1900-24HPv2 2.90(ABTP.2)C0; GS1900-48 2.90(AAHN.2)C0; GS1900-48HPv2 2.90(ABTQ.2)C0.

Veeam Agent bug hands out SYSTEM access

CVE-2026-32996 is a local privilege-escalation vulnerability in Veeam Agent for Microsoft Windows with a CVSS score not specified in the alert. Successful exploitation allows attackers to escalate from a low-privileged account to NT AUTHORITY\SYSTEM, granting full control of a Windows endpoint. CVE-2026-32996 is actively exploited, with a public proof-of-concept released on September 14, 2026, on GitHub. Security reporting notes that session IDs can be recovered from a log file accessible to standard users, making SYSTEM-level command execution straightforward. The issue affects Veeam Agent for Microsoft Windows up to version 13.0.1.2067, with a fix included in Veeam Backup & Replication 13.0.2.29 or later.

Top Threat Actors Reported in Last 24 hours

SideCopy spear-phishes Indian academic institutions

SideCopy (suspected Pakistan-origin APT group) is a threat actor with a primary motive of espionage. SideCopy delivers weaponized ZIP files containing Windows shortcuts (LNK) disguised as documents, which pull obfuscated HTA payloads and execute them via mshta.exe. SideCopy uses appT.bat to trigger startT.hta through a Registry Run Key, with commskl.docx as the decoy document. SideCopy targets Indian academic institutions, universities, and research staff. The campaign uses a hard-coded encryption key NMXIKS09?:709,!~lnsYUS and sends C2 traffic over port 5863. Victims risk remote control and theft of sensitive research and credentials via ReverseRAT.

BlueMoon exploit kit fuels espionage intrusions

BlueMoon exploit kit is a tool adopted by espionage-focused threat actors, suspected to originate from multiple regions, with a primary motive of data theft. BlueMoon chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to combine browser exploitation, sandbox escape, and privilege escalation. BlueMoon has been used by TA412 and UNK_LateNight to deliver payloads such as GemStone and ShadowPad. Targeted sectors include aerospace, defense, and government in the US and Asia. Recent campaigns leverage AI-assisted development, potentially accelerating copycat adoption and wider availability.

Exvicy ClickFix MaaS hijacks WordPress sites

Exvicy is a ClickFix malware-as-a-service (MaaS) framework built on ErrTraffic code, suspected to be operated by financially motivated actors. Exvicy injects obfuscated JavaScript into compromised WordPress sites, displaying a fake Cloudflare Turnstile check and social-engineering visitors into running PowerShell via the Win+R prompt. Exvicy tracks each step and reports back to the operator, using functions such as fingerprinting, anti-analysis, and polling. Targeted environments are businesses relying on WordPress for customer-facing web traffic. Sekoia researchers traced the infrastructure from 13 panels on July 9 to about 80 hosts by late August, with the framework advertising instructions in 13 languages.

Frequently Asked Questions

  1. What is CLOSEDQUORUM? CLOSEDQUORUM is a newly documented Windows implant that turns command-and-control into an autonomous system, delegating tactical decisions to a quorum of large language models instead of a human operator. It queries DeepSeek, Qwen, Mistral, and Google Gemini, then uses their “votes” to decide actions aimed at credential and cryptocurrency wallet theft, reducing reliance on traditional C2 infrastructure.

  2. What is INC? INC ransomware is behind an intrusion that unfolded in two phases and left victims with two ransom notes threatening data publication and outreach to stakeholders. In the incident documented by Huntress, the attackers used BYOVD (bring your own vulnerable driver) to disable security controls, then pushed ransomware across the environment.

  3. What is ChainScript? ChainScript is a Node.js remote access trojan (RAT) that sidesteps common takedown and blocking tactics by using a blockchain smart contract to discover where it should connect next. Discovered during an investigation into a ClickFix campaign, it masquerades as popular apps like Spotify, Zoom, and Microsoft Teams, then relies on PowerShell and VBScript to run components and persist inside the user profile without needing admin rights.

  4. What is CVE-2025-39682? CISA says attackers are actively exploiting three Linux kernel vulnerabilities that can crash systems, corrupt data, or elevate privileges: CVE-2025-39682 (CVSS 9.8), CVE-2025-39964 (CVSS 7.8), and CVE-2026-53266 (CVSS 8.8). In practical terms, successful attacks can take machines offline through denial-of-service, undermine data integrity, or let a local attacker gain higher-level control than they should have.

  5. What is CVE-2026-7273? A critical stack-based buffer overflow in Zyxel GS1900 series switches (CVE-2026-7273) allows unauthenticated attackers to execute arbitrary operating-system commands, putting network infrastructure directly in the blast radius. Attackers can trigger the flaw using crafted HTTP requests to the device’s CGI program, turning a management interface into a path for command execution.

  6. What is CVE-2026-32996? A local privilege-escalation flaw in Veeam Agent for Microsoft Windows (CVE-2026-32996) is being exploited to jump from a low-privileged account to NT AUTHORITY\SYSTEM, effectively handing an attacker full control of a Windows endpoint. The issue stems from how the Veeam Endpoint Backup service tracks elevated client sessions: an attacker can abuse a client-controlled session UID and reuse an elevated administrator context that isn’t bound to the requesting user.

  7. What is SideCopy? SideCopy, a Pakistan-origin APT group, is widening its footprint in India by shifting recent spear-phishing toward academic institutions after a history of targeting defense forces and government officials. They deliver a weaponized ZIP that contains a Windows shortcut (LNK) disguised as a document, which pulls an obfuscated HTA and runs it via mshta.exe before deleting the HTA to frustrate investigation.

  8. What is BlueMoon? The BlueMoon exploit kit is being adopted quickly by espionage-focused threat actors to move from a single click to deeper Windows compromise across high-value sectors. It chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to combine browser exploitation with sandbox escape and privilege escalation.

  9. What is Exvicy? Exvicy is a newly observed ClickFix malware-as-a-service framework built on ErrTraffic code, and it is being used to push malware through compromised WordPress sites. Researchers from Sekoia traced the operation’s infrastructure from a forum screenshot, finding 13 panels on July 9 that grew to about 80 hosts by late August.

Discover Related Resources