Cyware Daily Threat Intelligence - September 26, 2026

Summary
A single npm install can now open the door to full workstation compromise, as Kothamine RAT quietly hijacks developer environments through poisoned JavaScript dependencies. Cyware highlights how this malware leverages encrypted command-and-control and over 30 invasive commands, putting credentials and source code at risk for any organization relying on the JavaScript supply chain.
A six-hour global shutdown of KiteWorks servers signals the severity of a credible zero-day threat targeting secure file transfer infrastructure. With financial institutions and government agencies on high alert, the company’s unprecedented move aims to prevent unauthorized access and data breaches before attackers can exploit the undisclosed flaw.
FamousSparrow has shifted its espionage focus to government networks across Latin America, deploying a new backdoor that blends into routine network traffic. The group’s toolkit enables persistent access and deep reconnaissance, raising the stakes for internal communications and strategic data in Argentina, Ecuador, and beyond.
A suspected North Korea-linked threat actor has siphoned $351.6 million from Bitget’s hot wallets, exploiting backend infrastructure without touching private keys. The attack triggered asset freezes and a sweeping investigation, underscoring the persistent risk to crypto exchanges and the scale of financial losses in the sector.
Top Malware Reported in the Last 24 Hours
Kothamine RAT hides inside npm installs
Kothamine is a Windows remote-access Trojan (RAT) spreading through malicious npm packages, turning routine developer installs into a quiet takeover path. It uses Tailscale’s tailcat for encrypted command-and-control, making it harder for network defenders to spot and block once the infection is running. The malware supports more than 30 commands, including getdiscord, screenshot, and camera, enabling data theft and invasive surveillance through the microphone and webcam. Researchers at Malwarebytes tied the activity to a GitHub-hosted distribution point (hxxps://github[.]com/cphc811-ui/) and identified samples by SHA-256 ec4219a7ecf132c29080fbb20e4ab410c57faa85aeed7acade1eb15d905a6ee0 and 74eca3973ad72a6ddc9397aff8250d9ee287211fc9a055d5ee290d01cf76a70c. For organizations that rely on JavaScript supply chains, a single compromised dependency can hand attackers persistent access to developer workstations and the credentials and code they touch.
Red Heron raids Gitea for source
Red Heron has been exploiting CVE-2026-60004, a remote code execution flaw in self-hosted Gitea servers, to steal repositories and then entrench itself on Linux hosts. The campaign’s exploitation method centers on triggering RCE against exposed Gitea environments, turning developer infrastructure into a gateway for intellectual property theft and deeper network access. After access, it deploys the JITTERLY C++ implant for shell execution, file operations, tunneling, interactive terminal use, process control, and internal network pivoting. It then installs the SIXZUT rootkit to hide files, directories, processes, and network connections, while also blocking attempts to terminate protected processes. The activity is linked to the 981666[.]xyz domain cluster and shares infrastructure with attacks reported against WordPress, UniFi devices, and ZyXEL switches.
Lunex infostealer tricks Ukrainians with CAPTCHA
A new infostealer linked to the Lunex malware-as-a-service platform is targeting Ukrainian users with a four-stage attack chain that begins on a fake CAPTCHA page. It escalates its control by using a BYOVD approach to disable kernel-level monitoring, then leverages Windows Driver Signature Enforcement weaknesses to gain kernel access using a valid vendor certificate. For persistence, it relies on browser-based APIs and maintains remote filesystem access via a PowerShell-based Native Messaging Host, extending the attacker’s reach beyond a one-time credential grab. The activity is attributed to a CIS-aligned threat actor believed to be developed by a Russian-speaking team, according to the report. For victims, the payoff for the attacker is direct: stolen data and cryptocurrency wallet contents, plus the ability to keep coming back to the machine quietly.
Top Vulnerabilities Reported in Last 24 hours
KiteWorks orders six-hour global shutdown
KiteWorks told customers to temporarily shut down KiteWorks servers worldwide amid what it called a credible threat of an imminent zero-day attack against its secure file transfer and communications products. The company warned that exploitation could enable unauthorized access and lead to data breaches or ransomware, with particular risk for financial institutions and government authorities that rely on the platform for sensitive exchanges. Attackers are not yet confirmed to be exploiting the flaw, and KiteWorks has not disclosed the vulnerability type. KiteWorks CISO Frank Balonis issued the advisory, drawing parallels to past large-scale zero-day abuse by the cl0p gang against other file-transfer products. Systems are expected to be offline from 4 a.m. to 10 a.m. Central European Time on Saturday, September 26, and customers are told to monitor KiteWorks for patch updates or further instructions.
CISA flags exploited SharePoint, MikroTik bugs
CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog, warning that attackers can achieve high-impact outcomes ranging from code execution on Microsoft SharePoint (CVE-2026-65660) to authentication bypass on MikroTik RouterOS (CVE-2026-67279). For RouterOS users, the key risk is that an attacker can get past login controls and run commands, potentially paving the way to full device control. Attackers are already exploiting this in the wild, and CERT Polska said attacks targeting CVE-2026-67279 date back to at least September 2, 2026. Under Binding Operational Directive 22-01, FCEB agencies must address the issues by September 28, 2026. Patches or updates are available from Microsoft and MikroTik, and CISA’s guidance also calls out restricting SSH access on affected MikroTik devices.
ShinyHunters breaks into Oracle PeopleSoft servers
The threat actor ShinyHunters (also tracked as UNC6240) is actively exploiting an Oracle PeopleSoft vulnerability (CVE-2026-35273) to gain unauthorized access and establish persistence across victim environments. The campaign’s edge is its ability to bypass web application firewall rules by using URL-encoded characters, letting malicious requests slip through defenses meant to block them. Attackers are already exploiting this in the wild, deploying web shells and moving quickly from initial access to sustained control. Google’s threat intelligence team reported post-exploitation activity that includes deploying a trojanized installer called Ple64.exe as a backdoor and using Neo-reGeorg for tunneling. Oracle has issued a security alert patch for CVE-2026-35273.
Top Threat Actors Reported in Last 24 hours
FamousSparrow shifts to Latin American governments
FamousSparrow, a China-aligned cyberespionage group, has moved beyond its earlier focus on hotels and is now burrowing into government organizations across Latin America using a new backdoor called SparroWocky. The group deploys the malware via DLL side-loading and keeps access by setting up persistence through Windows services and registry keys. Once inside, they use a modular toolkit for command execution, data transfer, and system reconnaissance—capabilities that can quietly map networks and siphon sensitive government information over time. Targets named in recent activity include government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, raising the risk of leaked internal communications and strategic planning. The backdoor’s C2 traffic is wrapped in TLS and observed on ports 443 and 8080, helping it blend into common network patterns.
North Korea suspected in Bitget theft
A suspected North Korea-linked threat actor is accused of pulling off a roughly $351.6 million theft from Bitget’s hot wallets, a reminder that crypto exchanges remain high-value targets for financially motivated intrusions. Bitget said it detected unauthorized transfers on September 24, 2026, affecting assets including ETH, XRP, BNB, AVAX, USDT, and USDC, with XRP seeing the largest loss on a single chain. The company believes the attacker compromised a critical backend system in its wallet infrastructure, enabling fraudulent transfers without taking private keys, while its cold wallets remained secure. For customers and the wider crypto market, incidents like this can trigger delayed withdrawals, confidence shocks, and follow-on scams that prey on victims searching for recovery options. Some blockchain foundations responded by freezing wallet addresses linked to the attacker, and Mandiant and SlowMist are assisting Bitget’s investigation; the report also points to the FBI-cited $1.5 billion Bybit heist in February 2025 as part of a broader pattern.
ShinyHunters exploits Oracle, leaks FBI data
ShinyHunters (also tracked as UNC6240) has paired a high-profile data theft with an aggressive exploitation campaign, targeting both government-linked data and widely used enterprise software. The group claims it stole sensitive medical information tied to FBI personnel—reportedly affecting around 60,000 current and former staff—and demanded a retraction of an FBI advisory rather than money, while threatening to publish the data within five days. Separately, Google’s threat intelligence team said they are exploiting Oracle PeopleSoft CVE-2026-35273, using URL-encoded characters to bypass WAF rules, then deploying web shells and a trojanized installer to maintain access. Education, healthcare, and government environments are among the sectors cited as targets, where a successful compromise can translate into data theft, service disruption, and long-term persistence on systems that support real-world operations. Mitigations referenced in the reporting include applying Oracle’s security patch and monitoring for suspicious activity tied to the exploitation.
Frequently Asked Questions
What is Kothamine? Kothamine is a Windows remote-access Trojan (RAT) spreading through malicious npm packages, turning routine developer installs into a quiet takeover path. It uses Tailscale’s tailcat for encrypted command-and-control, making it harder for network defenders to spot and block once the infection is running.
What is Red Heron? Red Heron has been exploiting CVE-2026-60004, a remote code execution flaw in self-hosted Gitea servers, to steal repositories and then entrench itself on Linux hosts. The campaign’s exploitation method centers on triggering RCE against exposed Gitea environments, turning developer infrastructure into a gateway for intellectual property theft and deeper network access.
What is Lunex? A new infostealer linked to the Lunex malware-as-a-service platform is targeting Ukrainian users with a four-stage attack chain that begins on a fake CAPTCHA page. It escalates its control by using a BYOVD approach to disable kernel-level monitoring, then leverages Windows Driver Signature Enforcement weaknesses to gain kernel access using a valid vendor certificate.
What is KiteWorks? KiteWorks told customers to temporarily shut down KiteWorks servers worldwide amid what it called a credible threat of an imminent zero-day attack against its secure file transfer and communications products. The company warned that exploitation could enable unauthorized access and lead to data breaches or ransomware, with particular risk for financial institutions and government authorities that rely on the platform for sensitive exchanges.
What is CVE-2026-65660? CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog, warning that attackers can achieve high-impact outcomes ranging from code execution on Microsoft SharePoint (CVE-2026-65660) to authentication bypass on MikroTik RouterOS (CVE-2026-67279). For RouterOS users, the key risk is that an attacker can get past login controls and run commands, potentially paving the way to full device control.
What is CVE-2026-35273? The threat actor ShinyHunters (also tracked as UNC6240) is actively exploiting an Oracle PeopleSoft vulnerability (CVE-2026-35273) to gain unauthorized access and establish persistence across victim environments. The campaign’s edge is its ability to bypass web application firewall rules by using URL-encoded characters, letting malicious requests slip through defenses meant to block them.
What is FamousSparrow? FamousSparrow, a China-aligned cyberespionage group, has moved beyond its earlier focus on hotels and is now burrowing into government organizations across Latin America using a new backdoor called SparroWocky. The group deploys the malware via DLL side-loading and keeps access by setting up persistence through Windows services and registry keys.
What is ShinyHunters? ShinyHunters (also tracked as UNC6240) has paired a high-profile data theft with an aggressive exploitation campaign, targeting both government-linked data and widely used enterprise software. The group claims it stole sensitive medical information tied to FBI personnel—reportedly affecting around 60,000 current and former staff—and demanded a retraction of an FBI advisory rather than money, while threatening to publish the data within five days.

