Summary
A single click on a business-themed phishing email can now hand attackers persistent access to enterprise systems, as the CSuite campaign combines Microsoft 365 session theft with remote-access tool deployment. With 51% of CSuite phishing submissions originating from the United States, cyware.com highlights how mailbox takeovers and financial fraud are just the beginning for affected organizations.
Attackers are chaining two PaperCut MF zero-days to bypass authentication and seize control of print servers, escalating to domain-wide compromise and theft of privileged tokens. Emergency patches are available, but the risk of attackers jumping from a print server to domain controllers puts entire networks at stake.
Iran’s Ministry of Intelligence and Security is leveraging HEAVYGRAM spyware, which hides inside fake apps and uses Telegram for command-and-control, to surveil dissidents and journalists in the U.K., U.S., and the Netherlands. Stolen personal details have surfaced on pro-Iranian leak sites, raising the stakes for targeted individuals.
A critical MikroTik RouterOS flaw, CVE-2026-84411, is being exploited in the wild to grant unauthenticated attackers root-level access to network routers. Once compromised, these devices can be used to observe, manipulate, or launch attacks deeper into organizational networks, with fixes available in RouterOS 7.24 or newer.
Star Blizzard, a Russian government-linked group, is scaling its phishing operations by sending malware-laden emails from hacked WordPress and cPanel accounts. Over 100 organizations, including NGOs and government agencies in the U.S. and U.K., have been affected, with infection chains designed for stealthy, long-term access.
Top Malware Reported in the Last 24 Hours
CSuite phishers steal sessions, plant RATs
CSuite is a phishing campaign that pairs Microsoft 365 session theft with the deployment of remote-access tooling, turning a single click into lasting access to business systems. It uses familiar business lures themed around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then attackers can follow up by installing tools like ScreenConnect or Action1 to reach endpoints. For affected organizations, the real-world fallout can include mailbox takeover, financial fraud, persistent remote access, and lateral spread across internal systems. Researchers at ANY.RUN reported that 51% of CSuite phishing submissions came from the United States, with 18% from India. The write-up urges security leaders to focus on shortening investigation time, controlling unauthorized remote-access tooling, and improving visibility across identity and endpoint activity.
PaperCut zero-days open door to domains
PaperCut MF is under active exploitation via two reported zero-day vulnerabilities, CVE-2026-81578 and CVE-2026-82078, that can be chained to bypass authentication and execute code on affected servers. Once attackers get in, the impact can jump from a print-management server to domain-wide compromise, including access to domain controllers and theft of privileged tokens. The report describes intrusions using a web shell and the AdaptixC2 implant to run commands, steal credentials, and attempt actions like extracting the Active Directory database. For businesses, that can translate into broad identity compromise and unauthorized access to sensitive information across the network. Emergency fixes are available, and the article calls out applying PaperCut’s emergency patches and restricting external access to trusted IPs as immediate priorities.
HEAVYGRAM spyware hides inside fake apps
HEAVYGRAM is spyware attributed to Iran’s Ministry of Intelligence and Security that uses the Telegram app ecosystem for command-and-control while masquerading as legitimate software. It spreads through deceptive messages posing as trusted contacts or tech support, and it has been disguised as tools and files ranging from KeePass and Telegram installers to “MRI scan results.” Once running, it can take screenshots, activate microphones, and steal data from apps including Telegram and WhatsApp, putting targets at risk of surveillance and exposure. The report says it has targeted individuals in the U.K., U.S., and the Netherlands, and notes stolen personal details appearing on pro-Iranian leak sites. The advisory recommends using free check tools to vet unfamiliar download links, domains, or crypto wallets and monitoring for suspicious Telegram bot activity.
Top Vulnerabilities Reported in Last 24 hours
PaperCut zero-days chained for domain takeover
Attackers are exploiting two PaperCut MF zero-days to break in without valid credentials and potentially take over Windows domains, using CVE-2026-81578 and CVE-2026-82078 to bypass authentication and run arbitrary code. Once inside, the intrusions can escalate from the print server to identity systems by stealing domain-privileged service account tokens and even extracting the Active Directory database, turning a single foothold into widespread account compromise. Attackers are already exploiting this in the wild. Reporting says the attack chain used web shells and the AdaptixC2 implant, including delivery of hex-encoded Java classes through javax.servlet.Filter and jakarta.servlet.Filter. PaperCut has issued emergency fixes for MF and NG, and defenders have been urged to review PaperCut server.log for suspicious hex-encoded Java or unexpected .bin files and to investigate unusual mscopilot.exe execution paths.
Hackers actively exploit MikroTik router flaw
A critical MikroTik RouterOS bug is being exploited to let unauthenticated attackers run code remotely and seize root-level control of affected routers (CVE-2026-84411). The issue stems from an integer underflow in the RouterOS web management service, meaning a router’s management interface can become a direct entry point into the network it protects. Attackers are already exploiting this in the wild, alongside three other RouterOS vulnerabilities: CVE-2026-67277, CVE-2026-67279, and CVE-2026-86060. The report frames the risk in plain terms: once a router is owned, traffic can be observed or manipulated and the device can be used as a launchpad deeper into an organization. A fix is available in RouterOS 7.24 or newer, and guidance alongside the disclosure calls out monitoring for unusual network traffic and using network segmentation to limit blast radius.
Apple fixes exploited CoreGraphics zero-click
Apple patched an exploited zero-day in CoreGraphics that can allow attackers to run arbitrary code through a zero-click delivery path, making it particularly dangerous for high-value targets (CVE-2026-86950). The underlying flaw is an out-of-bounds write in Apple’s 2D graphics framework, which processes untrusted content and can be abused with maliciously crafted files as an entry point in a broader exploit chain. Attackers have exploited this in targeted attacks. Meta’s security team discovered the issue, underscoring how spyware-grade tradecraft continues to pressure widely deployed consumer platforms. Apple says fixes are available in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
Top Threat Actors Reported in Last 24 hours
Star Blizzard scales phishing via hacked sites
Star Blizzard (also tracked as a Russian government-affiliated group), which is linked to the FSB, is widening its cyberespionage reach by using fake event invitations and other lures to push malware to targets at scale. They have used decoys including fake tax audit notices and references to DarkSword iPhone exploit kits, while also shifting away from free email services to sending phishing from hacked WordPress and cPanel accounts to look more legitimate. The group’s recent infection chains are designed to persist quietly by setting scheduled tasks that appear like normal system components, ultimately delivering backdoors such as CosmicPulse, and Microsoft-linked reporting also describes the use of RedFlick in related phishing waves. The primary impact falls on NGOs, think tanks, and government organizations—especially in the U.S. and U.K.—where a single convincing email can turn into long-term access to sensitive policy and research work. Guidance shared alongside the reporting urges targets to adopt phishing-resistant sign-in methods and to review logs beyond a 7-day window to spot earlier suspicious activity, among other steps. Over 100 organizations have been affected, according to the reporting.
HEAVYGRAM spyware hunts dissidents abroad
HEAVYGRAM, spyware attributed to Iran’s Ministry of Intelligence and Security, is built around an unusual control channel: they use Telegram itself for command-and-control while stalking dissidents, journalists, and activists. The campaign has been active since at least 2025 against individuals in the U.K., U.S., and the Netherlands, and stolen personal details have reportedly surfaced on pro-Iranian leak sites that also include threats of violence. They rely on deception to get installed, disguising the malware as legitimate downloads such as the AI video app Pictory, KeePass, Telegram, RunwayML, Norton Antivirus, Adobe Flash Player, and even MRI scan results. Once running, it can capture screenshots, activate microphones, and steal data from messaging apps, turning everyday communications into a surveillance feed with real-world safety consequences for targets and their families. Recommended actions published with the research include using free check tools to verify unfamiliar download links, domains, or crypto wallets before trusting them, and blocking known IOCs while monitoring for suspicious Telegram bot activity.
APT36 abuses KMS tools for scareware
APT36 is linked in recent reporting to a multi-stage intrusion chain that starts by abusing KMS Auto, a common unauthorized software activation utility, to open the door for additional payloads. They move in timed steps—roughly 12–24 hours apart—progressing from cryptocurrency mining with XMRig to remote-access tooling such as ScreenConnect and MeshAgent, and then to a final scareware program named SecurityHealthServices.exe. The end payload masquerades as ransomware through wallpaper changes and fake ransom prompts, aiming to pressure victims psychologically even though it does not actually encrypt files. For affected businesses and users, the practical harm is disruption, loss of control of endpoints, and the risk that remote access could be used for follow-on theft or deeper compromise. Recommended actions cited in the write-up include restricting unauthorized software activation utilities and monitoring for execution of known dual-use tools like XMRig, alongside broader controls such as application whitelisting and user education.
Frequently Asked Questions
What is CSuite? CSuite is a phishing campaign that pairs Microsoft 365 session theft with the deployment of remote-access tooling, turning a single click into lasting access to business systems. It uses familiar business lures themed around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then attackers can follow up by installing tools like ScreenConnect or Action1 to reach endpoints.
What is CVE-2026-81578? PaperCut MF is under active exploitation via two reported zero-day vulnerabilities, CVE-2026-81578 and CVE-2026-82078, that can be chained to bypass authentication and execute code on affected servers. Once attackers get in, the impact can jump from a print-management server to domain-wide compromise, including access to domain controllers and theft of privileged tokens.
What is HEAVYGRAM? HEAVYGRAM is spyware attributed to Iran’s Ministry of Intelligence and Security that uses the Telegram app ecosystem for command-and-control while masquerading as legitimate software. It spreads through deceptive messages posing as trusted contacts or tech support, and it has been disguised as tools and files ranging from KeePass and Telegram installers to “MRI scan results.”
What is CVE-2026-81578? Attackers are exploiting two PaperCut MF zero-days to break in without valid credentials and potentially take over Windows domains, using CVE-2026-81578 and CVE-2026-82078 to bypass authentication and run arbitrary code. Once inside, the intrusions can escalate from the print server to identity systems by stealing domain-privileged service account tokens and even extracting the Active Directory database, turning a single foothold into widespread account compromise.
What is CVE-2026-84411? A critical MikroTik RouterOS bug is being exploited to let unauthenticated attackers run code remotely and seize root-level control of affected routers (CVE-2026-84411). The issue stems from an integer underflow in the RouterOS web management service, meaning a router’s management interface can become a direct entry point into the network it protects.
What is CVE-2026-86950? Apple patched an exploited zero-day in CoreGraphics that can allow attackers to run arbitrary code through a zero-click delivery path, making it particularly dangerous for high-value targets (CVE-2026-86950). The underlying flaw is an out-of-bounds write in Apple’s 2D graphics framework, which processes untrusted content and can be abused with maliciously crafted files as an entry point in a broader exploit chain.
What is Star Blizzard? Star Blizzard (also tracked as a Russian government-affiliated group), which is linked to the FSB, is widening its cyberespionage reach by using fake event invitations and other lures to push malware to targets at scale. They have used decoys including fake tax audit notices and references to DarkSword iPhone exploit kits, while also shifting away from free email services to sending phishing from hacked WordPress and cPanel accounts to look more legitimate.
What is HEAVYGRAM? HEAVYGRAM, spyware attributed to Iran’s Ministry of Intelligence and Security, is built around an unusual control channel: they use Telegram itself for command-and-control while stalking dissidents, journalists, and activists. The campaign has been active since at least 2025 against individuals in the U.K., U.S., and the Netherlands, and stolen personal details have reportedly surfaced on pro-Iranian leak sites that also include threats of violence.
What is APT36? APT36 is linked in recent reporting to a multi-stage intrusion chain that starts by abusing KMS Auto, a common unauthorized software activation utility, to open the door for additional payloads. They move in timed steps—roughly 12–24 hours apart—progressing from cryptocurrency mining with XMRig to remote-access tooling such as ScreenConnect and MeshAgent, and then to a final scareware program named SecurityHealthServices.exe.


