Cyware Daily Threat Intelligence - September 24, 2026

A surge of supply-chain attacks is slashing through developer ecosystems, as compromised MemTensor packages now drop the sckit implant and exfiltrate secrets to skyleen[.]fr. Cyware.com tracks how this campaign blends into normal workflows, putting source code and cloud environments at risk with a single dependency update.
Attackers are actively exploiting CVE-2026-94127, a critical flaw in F5 BIG-IP Access Policy Manager (APM), turning access gateways into entry points for remote code execution. With a CVSS score of 9.3, federal agencies face urgent patch deadlines as exploitation unfolds in the wild.
A Russian-Armenian threat group is hijacking logistics sector accounts with the Corp MDM Android implant, stealing over 1,600 login credentials through phishing and voice phishing. By intercepting SMS and enabling call forwarding, the campaign exposes operational data and disrupts shipments across the sector.
Top Malware Reported in the Last 24 Hours
RemControl lures banking victims via TVTap
RemControl is a new Android banking trojan designed to steal credentials and facilitate account takeover. RemControl leverages geofencing and mobile User-Agent checks, especially in Italy, to restrict campaign visibility and evade disruption. RemControl abuses Accessibility Service permissions to deploy phishing overlays, capture screens and inputs, and hinder removal, transforming routine phone use into a credential-theft vector. RemControl retrieves encrypted command-and-control details from Telegram channels and demonstrates potential linkages to the Medusa banking trojan. RemControl is distributed via malvertising that impersonates the TVTap IPTV app and directs victims to fake Google Play pages. The campaign targets users in Italy, France, Spain, Poland, Portugal, and Canada, with researchers highlighting the risk of silent credential harvesting and account compromise.
MemTensor supply-chain breach drops sckit implant
MemTensor supply-chain compromise has delivered the Go-based implant sckit to developer machines and build systems across Windows, Linux, and macOS. MemTensor enables sckit to trigger on agent gateway startup or memory-recall events in npm, and upon importing the “memos” module in PyPI, blending into standard development workflows. MemTensor allows sckit to self-propagate via GitHub and by publishing to npm and PyPI, increasing the risk of rapid supply-chain spread. MemTensor targets high-value secrets such as .npmrc, .vault-token, id_ecdsa, NPM_TOKEN, PYPI_API_TOKEN, AWS access keys, and GitHub/GitLab tokens, exfiltrating them to skyleen[.]fr. Teams using these dependencies face credential theft that can expose source code, cloud environments, and CI/CD pipelines, as reported by researchers.
Fake Xcode site pushes AMOS stealer
Atomic macOS Stealer (AMOS) is a macOS infostealer deployed via a ClickFix-style campaign using a fake Xcode download site. AMOS employs obfuscation and encryption to disguise its initial script, which reconstructs utilities like md5, xxd, openssl, and gunzip to decrypt and execute a second-stage payload. AMOS performs host discovery and delivers additional payloads, leveraging MITRE ATT&CK techniques T1204.004, T1059.004, T1027, T1082, T1033, T1105, and T1553.001. AMOS is delivered when users are tricked into running a Terminal command after visiting the fraudulent site. Menlo Security detected and blocked the campaign, advising organizations to block the involved domains and monitor for suspicious command execution.
Top Vulnerabilities Reported in Last 24 hours
F5 access manager zero-day hit in wild
CVE-2026-94127 is a heap-based buffer overflow vulnerability in F5 BIG-IP Access Policy Manager (APM) (CVSS 9.3). CVE-2026-94127 allows remote code execution on exposed systems configured as an OAuth Authorization Server. CVE-2026-94127 is actively exploited in the wild. CVE-2026-94127 was disclosed by F5 and CISA, both of which warned of heightened risk for federal agencies. A patch is available from F5, and CISA set a patch deadline due to national security and public safety concerns. CVE-2026-94127 affects BIG-IP APM deployments configured as OAuth Authorization Servers.
Zero-day puts SD-WAN control at risk
CVE-2026-93952 is a critical authentication bypass vulnerability in VeloCloud Orchestrator (CVSS 10.0). CVE-2026-93952 enables remote attackers to access privileged internal functionality without authentication, allowing manipulation of network traffic and policies across managed SD-WAN sites. CVE-2026-93952 is being actively exploited in the wild. CVE-2026-93952 was disclosed by Arista Networks, and CISA imposed a three-day remediation deadline for federal agencies. Fixes are available on the 5.2.x and 6.4.x branches, and the vulnerability impacts SD-WAN control planes across enterprise networks.
Cisco ISE bug gives attackers root
A CVSS 10.0 authentication-bypass vulnerability in Cisco Identity Services Engine (ISE) allows unauthenticated API access and command execution with root privileges. Successful exploitation lets attackers bypass access controls and conceal their activity. The vulnerability is actively exploited in the wild and is listed in CISA’s Known Exploited Vulnerabilities catalog. The Canadian Cyber Centre warns that external telemetry may be required to verify system integrity, as local logs may be inconclusive. Fixes are available in 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4, and the vulnerability affects organizations relying on ISE for network access control.
Top Threat Actors Reported in Last 24 hours
Russian-Armenian phishers push Corp MDM spyware
A Russian-Armenian threat actor, suspected to operate from Russia and Armenia, is motivated by credential theft and surveillance. The actor uses multi-pronged campaigns, including an Android implant called Corp MDM, to intercept SMS messages and enable call forwarding on compromised devices. The actor lures victims to fake Google Play pages branded as logistics companies and leverages a phishing-as-a-service platform to steal over 1,600 login credentials through spear-phishing and voice phishing. The actor targets the logistics sector, exposing customer and operational data and disrupting shipments. The campaign relies on a hard-coded IP address for command-and-control and phishing lures, with defenders urged to block known infrastructure and monitor for SMS interception and call-forwarding activity.
Konni phishes Ukraine watchers with VelvetCake
Konni (also tracked as Konni Group), a suspected North Korea-linked espionage actor, is focused on intelligence collection. Konni uses ZIP archives with LNK files disguised as PDFs and trojanized Zoom installers to deliver the VelvetCake task runner, which fetches PowerShell modules for reconnaissance, antivirus discovery, system and network information collection, and screenshot capturing. Konni targets Ukraine-focused researchers, NGOs, and policy communities. The campaign leverages lures themed around peace negotiations and food-price disruptions, with operational timestamps aligning to Korea/Japan Standard Time (+0900). Researchers mapped the campaign to MITRE ATT&CK techniques and noted the use of GitHub for payload delivery.
F5 BIG-IP APM zero-day exploited
Attackers are actively exploiting CVE-2026-94127, a critical zero-day in F5 BIG-IP Access Policy Manager (APM), to achieve remote code execution on OAuth Authorization Server configurations. The flaw is a heap-based buffer overflow with a CVSS score of 9.3, putting internet-facing access infrastructure at risk. The exploitation can result in stolen sessions, credentials, and disrupted authentication for affected organizations. F5 and CISA have issued warnings, with CISA setting a federal patching deadline. The Register notes that a previous wave of F5 exploitation was linked to UNC5174, a group assessed to operate from China, highlighting the rapid targeting of high-value edge vulnerabilities by advanced actors.
Frequently Asked Questions
What is RemControl? RemControl is a new Android banking trojan spreading through malvertising that masquerades as the TVTap IPTV app, pushing victims to fake Google Play pages. It uses geofencing and mobile User-Agent checks—especially in Italy—to control who sees the scam and to make the campaign harder to disrupt.
What is sckit? Compromised MemTensor packages on npm and PyPI have been used to deliver a Go-based implant called sckit, putting developer machines and build systems at risk across Windows, Linux, and macOS. The malicious payload can trigger when the agent gateway starts or during memory-recall events in the npm package, and it runs when the “memos” module is imported in the PyPI package—blending into normal development workflows.
What is Atomic macOS Stealer (AMOS)? A ClickFix-style campaign is tricking macOS users with a fake Xcode download site that coerces them into running a Terminal command, ultimately delivering Atomic macOS Stealer (AMOS). The chain relies on obfuscation and encryption so the downloaded script looks opaque while it prepares the next stage, turning a single copy-paste into a full compromise.
What is CVE-2026-94127? Attackers are exploiting a critical zero-day in F5 BIG-IP Access Policy Manager (APM) that can lead to remote code execution on exposed systems (CVE-2026-94127, CVSS 9.3). The issue affects BIG-IP APM deployments configured as an OAuth Authorization Server, meaning a successful compromise can turn an access-management component into an entry point for broader network intrusion.
What is CVE-2026-93952? A critical zero-day in VeloCloud Orchestrator is being exploited to let remote attackers access privileged internal functionality without authentication (CVE-2026-93952, CVSS 10.0). Because Orchestrator is the control plane for SD-WAN, a takeover can translate into unauthorized access and manipulation of network traffic and policies across managed sites.
What is Cisco Identity Services Engine (ISE)? A CVSS 10.0 authentication-bypass flaw in Cisco Identity Services Engine (ISE) is being exploited to enable unauthenticated API access that can lead to command execution with root privileges. For organizations relying on ISE to control who and what can connect to the network, a compromised node can undermine access decisions and let intruders hide their tracks.
What is Corp MDM? A Russian-Armenian threat actor, driven by credential theft and surveillance, is hitting the logistics sector with a multi-pronged campaign that now includes an Android implant called Corp MDM. After luring victims to fake Google Play pages branded as logistics companies, they get targets to install an app that asks for permissions to intercept newly received SMS messages and enable call forwarding, giving the group a way to hijack accounts and divert calls.
What is Konni? Konni (also tracked as Konni Group), a North Korea-linked espionage actor, is using “Operation Conflict Compass” to collect intelligence from Ukraine-focused targets by disguising malicious shortcuts as everyday documents. They deliver ZIP archives containing LNK files masquerading as PDFs, then pull additional payloads from GitHub and even deploy trojanized Zoom installers that bundle legitimate files alongside malicious components.
What is CVE-2026-94127? Attackers are actively exploiting CVE-2026-94127, a critical zero-day in F5 BIG-IP Access Policy Manager (APM) that can enable remote code execution on systems configured as an OAuth Authorization Server. The flaw is a heap-based buffer overflow with a CVSS score of 9.3, putting internet-facing access infrastructure—often a gateway into wider enterprise environments—at immediate risk.