Cyware at Billington CyberSecurity Summit
Monthly Threat Briefing
Diamond Trail

Cyware Monthly Threat Intelligence - August 2026

14 min read
shutterstock 2494462775

This month’s reporting clustered around two parallel pressures: ransomware activity that combined affiliate scaling and vulnerability-led initial access, and high-impact exploitation against widely deployed enterprise software. In parallel, multiple supply-chain compromises targeted developer ecosystems at build and dependency layers, while state-backed and state-aligned actors continued espionage operations against telecoms, government, defense-aligned sectors, and senior officials using a mix of infrastructure targeting, email exploitation, and messaging-app social engineering.

Malware

Gentlemen ransomware scales attacks via RaaS affiliate recruiting

Gentlemen ransomware is a ransomware-as-a-service (RaaS) operation that encrypts victim environments and drives data-theft extortion through publicized breach claims. Gentlemen ransomware conducted 675 attacks since mid-2025, including 600 attacks in 2026 alone, and Gentlemen ransomware activity includes confirmed incidents that breached 30,000 records at Soniva Dental Care (US), 92,000 records at Caribbean Medical Center (Puerto Rico), and 641,000 records at MEDICUS SHUPPAN (Japan). Gentlemen ransomware breaches totaled 796,140 records across reported incidents, and Gentlemen ransomware targeted businesses (516 attacks) alongside healthcare (36 attacks), government (32 attacks), and education (16 attacks). Gentlemen ransomware exploits vulnerabilities including CVE-2025-32433 and CVE-2025-33073 to expand access opportunities. Gentlemen ransomware partnered with BreachForums to recruit affiliates such as pentesters and access brokers to scale operations globally, and Gentlemen ransomware victim distribution includes the US representing 21% of victims with activity also reported in Thailand, France, and India.

ToxicPanda 2.0 Android banking trojan expands remote command set and financial app targeting

ToxicPanda 2.0 is an Android banking trojan that steals financial credentials by abusing accessibility features and overlay-based account capture. ToxicPanda 2.0 added 167 remote commands and expanded targeting from 16 to 349 financial institutions across 16 countries while aiming at more than 140 banking and cryptocurrency applications globally. ToxicPanda 2.0 exploits Android accessibility services and Wireless Debugging for privilege escalation, and ToxicPanda 2.0 communicates with command-and-control using WebSocket. ToxicPanda 2.0 delivers credential theft through overlays that impersonate legitimate app screens. ToxicPanda 2.0 defensive guidance in reporting recommends auditing app permissions, removing unfamiliar applications, downloading apps only from trusted sources, keeping devices updated, and enabling two-factor authentication (2FA) for online accounts.

ChainDrop npm worm spreads through tarballs and steals developer credentials without requiring package installation

ChainDrop is a worm variant of the Shai-Hulud npm worm that propagates through npm supply chains and exfiltrates credentials from developer environments. ChainDrop infected 444 packages from multiple publishers in a large-scale attack, and ChainDrop impacted widely used dependencies collectively downloaded about 2 billion times a month. ChainDrop can compromise systems even when an infected package is not installed because ChainDrop can take control when a user opens an infected Git branch in VS Code or Claude Code. ChainDrop propagates by rebuilding tarballs to include the payload, and ChainDrop scours workspaces for npm tokens and other credentials before encrypting and sending stolen data to attacker-controlled endpoints. Reported guidance recommends evaluating trusted publishing tools such as GitHub Actions, checking for unexpected .claude/settings.json and .vscode/tasks.json files across branches, consulting SafeDep’s compromised-package list, and enhancing monitoring of CI/CD pipelines to prevent spread during automated rebuilds.

Malicious Rust crates abuse proc-macro1 dependency to execute cross-platform payloads during Cargo builds

The proc-macro1 supply-chain compromise is a malicious Rust dependency attack that executes malware at build time by impersonating a legitimate crate. The proc-macro1 attack compromised the Rust crates arrayref, internment, and append-only-vec via malicious releases published on August 20, 2026, and researchers from Socket's Threat Research Team and Nextron Systems reported the activity. The proc-macro1 loader reconstructs Base64-obfuscated C2 addresses, disables TLS certificate verification, and downloads payloads from 23[.]254[.]165[.]112 while communicating over ports 9089 and 443. The proc-macro1 stage-2 payload profiles the host, inventories browsers, establishes persistence, and uses fallback communication to deterministic domains. The Rust Security Response Team removed the affected releases and locked the maintainer account, and reported guidance recommends searching for compromised versions (arrayref 0.3.10, internment 0.8.7, append-only-vec 0.1.9, and proc-macro1), pinning safe versions (arrayref ≤ 0.3.9, internment ≤ 0.8.6, append-only-vec ≤ 0.1.8), and investigating host artifacts such as /tmp/rust-setup and %TEMP%\rust-setup.ps1.

SynkLoader abuses Microsoft Teams phishing to install modular tooling for credential theft and internal access

SynkLoader is a modular malware family distributed via Microsoft Teams phishing that impersonates IT help desks to drive execution of a fake "PowerShell Cleaner" and related components. SynkLoader deploys modules that perform system and network profiling, establish persistence at user logon, and capture credentials using a fake lock screen via the PhishLocker module. SynkLoader enables internal network access by creating a reverse proxy using the TrafficRedirector module and provides remote control through an interactive shell (RAT) and VNC-based remote desktop capability (StreamMaster). SynkLoader delivers an MSI payload hosted on Microsoft Azure as part of the phishing flow, and SynkLoader campaigns have operated since at least July 28, 2026 per reporting. SynkLoader activity emphasizes Active Directory profiling that reporting assessed as suggestive of potential ransomware use, and defenders recommended verifying IT requests independently and avoiding unsolicited MSI installs while monitoring for unusual network activity and unauthorized access attempts.

Vulnerabilities

INC ransomware exploits SonicWall SMA 1000 zero-days CVE-2026-15409 and CVE-2026-15410 for pre-auth root access

CVE-2026-15409 and CVE-2026-15410 are critical zero-day vulnerabilities in SonicWall SMA 1000 series involving pre-authentication SSRF in the /wsproxy component and a path traversal flaw in the remove_hotfix workflow (CVSS 10.0 reported for the issue set). CVE-2026-15409 and CVE-2026-15410 exploitation can enable attackers to gain root access without authentication and maintain persistence by stealing session tokens and MFA seed data. CVE-2026-15409 and CVE-2026-15410 are actively exploited in the wild as zero-days by the INC ransomware group, and reporting also cites initial access brokers selling access to compromised devices. CVE-2026-15409 and CVE-2026-15410 activity has impacted telecommunications, manufacturing, professional services, and public sector organizations. SonicWall mitigates CVE-2026-15409 and CVE-2026-15410 by upgrading SMA 1000 firmware to 12.4.3-03453 or 12.5.0-02835 or later and by regenerating MFA TOTP seeds, rotating administrator credentials, auditing logs for unexplained reboots and altered hotfix logs, and reviewing outbound network logs for unauthorized WebSocket tunnel connections.

Clop ransomware exploited PTC Windchill zero-day CVE-2026-12569 to steal engineering data from 43 organizations

CVE-2026-12569 is a zero-day deserialization vulnerability affecting PTC Windchill PDMLink and FlexPLM (CVSS score not provided). CVE-2026-12569 exploitation can enable unauthorized access and data theft, and reporting ties CVE-2026-12569 intrusions to stolen engineering blueprints, project plans, and facility test reports. CVE-2026-12569 is actively exploited, and sources state Clop exploited CVE-2026-12569 in early June 2026 as part of a two-flaw, zero-authentication attack chain that also included an information-disclosure flaw. CVE-2026-12569 activity is attributed to the Clop ransomware gang, and reporting also describes webshell deployment and extortion emails to hundreds of employees. PTC addressed CVE-2026-12569 with patches released on June 17 and remediation guidance to patch to Windchill/FlexPLM 11.0 M030 or later, hunt for webshells under /Windchill/login/, review for the header X-windchill-req: ?x8Fmgow, block C2 addresses 79[.]141[.]160[.]78 and 5[.]180[.]41[.]35, rotate credentials before restoring, and preserve forensic artifacts and consult legal counsel if regulated data may have been exfiltrated.

CVE-2026-33824 actively exploited against Microsoft Windows IKE Service Extension

CVE-2026-33824 is a critical remote code execution vulnerability affecting the Microsoft Windows IKE Service Extension (CVSS score not provided). CVE-2026-33824 exploitation can allow attackers to gain unauthorized access and execute code on impacted systems. CVE-2026-33824 is actively exploited in the wild, and sources describe a Chinese-speaking threat actor leveraging CVE-2026-33824 in an AI-enabled hacking campaign. CVE-2026-33824 activity appears linked to a Chinese-speaking threat actor (no further attribution provided). Microsoft released patches for CVE-2026-33824 in April 2026, and organizations should apply the available update immediately.

CVE-2026-55040 exploitation follows public PoC targeting Microsoft SharePoint

CVE-2026-55040 is a critical vulnerability in Microsoft SharePoint enabling exploitation via an authentication bypass and/or remote code execution path (CVSS score not provided). CVE-2026-55040 exploitation can lead to unauthorized access and downstream deployment of malicious software in compromised environments. CVE-2026-55040 is actively exploited in the wild, and reporting states attackers began targeting CVE-2026-55040 following the release of a proof-of-concept exploit. CVE-2026-55040 reporting does not name a specific threat actor. Microsoft released patches for CVE-2026-55040 in July 2026, and defenders should apply the update immediately and monitor for unauthorized access attempts and unusual network activity.

CVE-2026-21962 actively exploited against Oracle HTTP Server and WebLogic Proxy Plug-in

CVE-2026-21962 is an improper access control vulnerability in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in with a CVSS score of 10.0. CVE-2026-21962 allows unauthenticated attackers to create, delete, access, or modify critical data via HTTP, which can lead to system compromise and data breaches. CVE-2026-21962 is actively exploited in the wild, and CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities (KEV) Catalog while BOD 26-04 directs Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk exploited vulnerabilities. CloudSEK reported exploitation targeting honeypots in March 2026, and activity observed in February 2026 linked exploitation attempts to 193[.]24[.]123[.]42 alongside attempts against CVE-2020-14882/14883, CVE-2020-2551, and CVE-2017-10271. Oracle released patches for CVE-2026-21962 in January 2026, and defenders should apply the updates, monitor and block 193[.]24[.]123[.]42, review and update security configurations to prevent unauthorized access, and conduct regular security assessments to identify and remediate exposure.

Threat Actors

Salt Typhoon forces telecom defenders to isolate networks to expel persistent access

Salt Typhoon is a Chinese state-backed threat actor associated with telecom-focused cyber espionage. Salt Typhoon intruded into telecom environments by targeting routers and telecom infrastructure and by exploiting routing relationships across interconnected organizations to access sensitive communications. Salt Typhoon activity highlighted that logical controls alone can fail to fully remove nation-state access when equipment and trust relationships span multiple operators, prompting containment actions that include physical disconnection. Salt Typhoon activity linked to T-Mobile in November 2024 led T-Mobile’s security team to cut a network cable as part of eradication efforts, while T-Mobile reported no significant customer data compromise. Salt Typhoon targeted systems associated with lawful intercept obligations that store sensitive call records and metadata, and reporting described the broader campaign as affecting at least 200 organizations across 80 countries.

Laundry Bear exploits Zimbra zero-click XSS to steal email data and 2FA tokens

Laundry Bear is a Russian state-sponsored threat actor assessed as espionage-motivated. Laundry Bear exploited CVE-2025-66376, a zero-click cross-site scripting flaw in the Zimbra Collaboration Suite Classic UI, by sending emails containing malicious JavaScript that executes when the message is displayed. Laundry Bear used the Flowerbed framework to exfiltrate data by hiding content in DNS requests and used adversary-in-the-middle phishing kits to capture credentials, session cookies, and 2FA tokens. Laundry Bear targeted unpatched Zimbra deployments across the defense, education, energy, and government sectors, including the Dutch National Police and Ukrainian military personnel, underscoring the geopolitical sensitivity of the intrusions. Laundry Bear used Proton Mail accounts to impersonate organizations fighting disinformation, and Laundry Bear leveraged access to steal up to 90 days of emails and create unauthorized application passcodes (including those labeled "ZimbraWeb") for persistence; reported phishing domains included mailnalysis[.]com, zimbrastat[.]com, zimbra-metadata[.]com, and zmailanalytics[.]com.

SilkParasite runs China-linked AI-assisted espionage campaign against Central Asian governments

SilkParasite is a China-linked campaign assessed as cyber-espionage focused, with a strategic emphasis on AI-assisted malware development. SilkParasite used seven malware families, including previously unknown families, and SilkParasite used modular malware that can dynamically load additional capabilities. SilkParasite delivered payloads via DLL sideloading and phishing documents impersonating government entities, and SilkParasite packaged malicious Microsoft Office files in password-protected RAR archives to evade detection. SilkParasite targeted government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. SilkParasite artifacts showed AI-assisted development traits such as test functions left in GoginRAT and hardcoded AES keys, and SilkParasite used deliberately sloppy AI-generated lures to blend with low-quality content while sustaining intelligence collection.

Tortoiseshell expands infrastructure and deploys TWOSTROKE plus SSH-tunneling utility against defense-aligned sectors

Tortoiseshell is an Iranian-linked APT group assessed as affiliated with Iran’s IRGC and associated with espionage-focused operations. Tortoiseshell has operated since at least 2018 and has a history of targeting defense, aerospace, IT service providers, and military organizations, including activity involving supply chain compromises and fake recruitment websites. Tortoiseshell expanded operational infrastructure and tooling with new malware samples, including an SSH-based tunneling utility masquerading as a Windows DLL to establish encrypted connections for data exfiltration. Tortoiseshell also used the TWOSTROKE backdoor disguised as a DLL to execute commands, upload files, and communicate with multiple C2 servers via a custom protocol, with infrastructure including 172[.]86[.]98[.]113 and 185[.]253[.]116[.]81 indicating targeting expansion across Middle Eastern and European countries. Defenders can respond to Tortoiseshell by subscribing to threat intelligence feeds for IOC updates, maintaining threat hunting to detect related infrastructure and malware, monitoring outbound traffic for C2 patterns, and blocking identified IPs and domains tied to Tortoiseshell operations.

Russian-linked spearphishing targets EU officials via WhatsApp and Signal account-takeover social engineering

Russian-linked state-sponsored threat activity targeted high-ranking EU officials for espionage via messaging-app spearphishing, according to reporting referenced by EU and national intelligence warnings. Russian-linked operators used social engineering that posed as fake Signal support chatbots to trick targets into sharing codes that enable account takeover and access to incoming communications and group chats. Russian-linked operators also used personalized spearphishing messages designed to drive clicks on malicious links or the opening of harmful attachments, increasing the risk of compromising sensitive communications among political, military, diplomatic, and investigative journalism targets. Russian-linked activity triggered European Commission guidance to shut down certain Signal groups, and reporting cited eight significant incidents reported this year associated with the threat. EU institutions can reduce exposure by adopting a unified cybersecurity approach for institutional communications, implementing multi-factor authentication, and reinforcing regular security training focused on resisting social engineering and account-takeover attempts.

Frequently Asked Questions

  1. What is Gentlemen ransomware and how does it operate as a RaaS operation? Gentlemen ransomware is a ransomware-as-a-service (RaaS) operation that encrypts victim environments and drives data-theft extortion through publicized breach claims. Gentlemen ransomware conducted 675 attacks since mid-2025, including 600 attacks in 2026 alone, and Gentlemen ransomware activity includes confirmed incidents that breached 30,000 records at Soniva Dental Care (US), 92,000 records at Caribbean Medical Center (Puerto Rico), and 641,000 records at MEDICUS SHUPPAN (Japan).

  2. How does ToxicPanda 2.0 steal financial credentials on Android devices? ToxicPanda 2.0 is an Android banking trojan that steals financial credentials by abusing accessibility features and overlay-based account capture. ToxicPanda 2.0 added 167 remote commands and expanded targeting from 16 to 349 financial institutions across 16 countries while aiming at more than 140 banking and cryptocurrency applications globally.

  3. What is ChainDrop and how does it spread through npm supply chains? ChainDrop is a worm variant of the Shai-Hulud npm worm that propagates through npm supply chains and exfiltrates credentials from developer environments. ChainDrop infected 444 packages from multiple publishers in a large-scale attack, and ChainDrop impacted widely used dependencies collectively downloaded about 2 billion times a month.

  4. What is the proc-macro1 supply-chain compromise affecting Rust crates? The proc-macro1 supply-chain compromise is a malicious Rust dependency attack that executes malware at build time by impersonating a legitimate crate. The proc-macro1 attack compromised the Rust crates arrayref, internment, and append-only-vec via malicious releases published on August 20, 2026, and researchers from Socket's Threat Research Team and Nextron Systems reported the activity.

  5. What are CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA 1000 series and what do they enable? CVE-2026-15409 and CVE-2026-15410 are critical zero-day vulnerabilities in SonicWall SMA 1000 series involving pre-authentication SSRF in the /wsproxy component and a path traversal flaw in the remove_hotfix workflow (CVSS 10.0 reported for the issue set). CVE-2026-15409 and CVE-2026-15410 exploitation can enable attackers to gain root access without authentication and maintain persistence by stealing session tokens and MFA seed data.

  6. How did Salt Typhoon intrude into telecom environments, according to the report? Salt Typhoon is a Chinese state-backed threat actor associated with telecom-focused cyber espionage. Salt Typhoon intruded into telecom environments by targeting routers and telecom infrastructure and by exploiting routing relationships across interconnected organizations to access sensitive communications.

Discover Related Resources