Cyware Weekly Threat Intelligence - August 15 - 21, 2026

Ransomware crews are slashing through critical infrastructure this week, with Medusa ransomware clocking over 500 victims and prompting an updated FBI warning. Cyware spotlights how attackers are leveraging both phishing and remote service exploits to breach healthcare and vital sectors, while new RaaS platforms like Eclipse Ransomware are disrupting hybrid enterprise environments with advanced encryption and affiliate management.
A coordinated supply chain attack on the Rust ecosystem has exposed Linux, macOS, and Windows developers to cross-platform malware, with the malicious proc-macro1 crate delivering payloads that reconstruct obfuscated C2 addresses and disable TLS verification. The Rust Security Response Team responded by removing compromised releases and locking the maintainer account after reports from Socket and Nextron Systems.
Zero-day exploitation surged as Lazarus Group weaponized a Windows kernel flaw (CVE-2026-68820) to deploy the FudModule rootkit in defense and aerospace targets across Europe, India, and Brazil. Meanwhile, SonicWall, VMware, and Apple scrambled to patch actively exploited vulnerabilities, with hundreds of vCenter servers and macOS devices compromised globally.
AI-driven espionage is reshaping the threat landscape, as groups like Kimsuky and SilkParasite integrate AI into spear-phishing and malware development. Laundry Bear’s exploitation of a Zimbra zero-click flaw has compromised Western defense and government organizations, while Iranian actors are blending DNS tunneling with Microsoft 365 calendar abuse for covert C2.
Top Malware Reported This Week
Medusa ransomware expands attacks on critical sectors
Medusa ransomware is a ransomware strain focused on extortion and data disclosure. Medusa ransomware leverages vulnerabilities in Fortra GoAnywhere, BeyondTrust, Fortinet EMS, and ScreenConnect, and uses legitimate remote access tools such as AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop to maintain persistence and evade detection. Medusa ransomware exfiltrates sensitive data before encryption, determines ransom amounts based on victim revenue, and offers deadline extensions for additional fees. Medusa ransomware gains initial access through phishing campaigns and exploitation of remote service vulnerabilities. Medusa ransomware has impacted over 500 organizations, with a significant focus on healthcare and other vital sectors. The FBI has issued an updated warning highlighting the increasing number of victims and the evolving tactics of Medusa ransomware.
Eclipse Ransomware RaaS targets hybrid enterprise environments
Eclipse Ransomware is a Ransomware-as-a-Service platform that encrypts files on Windows, Linux, NAS, VMware ESXi, and Nutanix systems, disrupting business operations. Eclipse Ransomware employs ChaCha20 encryption, Kyber-based key exchange, automated lateral movement, defense evasion, and process termination, with configurable modes for speed and stealth. Eclipse Ransomware provides affiliates with management features such as separate Bitcoin and Monero wallets, Tor .onion addresses, and direct leak-site publishing, while prohibiting sample submissions to public scanners. EclipseSupport actively recruits affiliates with a $300 entry fee (refundable upon first payout) and a revenue-sharing scheme starting at 90/10 for the first 10 extortions, shifting to 80/20. Eclipse Ransomware targets hybrid enterprise environments, including ESXi and Nutanix, across multiple platforms. The Windows payload is developed in Rust, while other variants use C++, enabling effective cross-platform attacks.
Supply chain attack on Rust crates delivers cross-platform malware
A coordinated supply chain attack compromised the Rust crates arrayref, internment, and append-only-vec by introducing a malicious dependency, proc-macro1, which impersonates the legitimate proc-macro2 crate. The malicious proc-macro1 crate executes a build script during Cargo builds, downloading and running platform-specific payloads that reconstruct Base64-obfuscated C2 addresses and disable TLS certificate verification. The stage-2 payload profiles the host, inventories browsers, establishes persistence, and communicates with C2 servers at 23[.]254[.]165[.]112, using fallback deterministic domains for resilience. The attack spreads through compromised crate versions: arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9, affecting Linux, macOS, and Windows systems. The Rust Security Response Team removed the affected releases and locked the maintainer account after reports from Socket's Threat Research Team and Nextron Systems.
Lazarus Group exploits Windows kernel zero-day to deploy FudModule rootkit
Lazarus Group is a North Korea-linked threat actor that deploys the FudModule rootkit to disable security features and tamper with system processes, operating undetected by most EDR tools. Lazarus Group exploits CVE-2026-68820, a zero-day vulnerability in AFD.sys, to gain SYSTEM-level privileges on Windows systems. Lazarus Group uses two parallel infection chains: DLL sideloading (via encrypted ZIP archives containing a legitimate PDF viewer, malicious DLL, and encrypted payload) and a trojanized PDF viewer called SecurityPDF, delivered through SEO-optimized websites. Lazarus Group employs the MISTPEN downloader, hijacked webmail and CMS sites for C2, and VPN services like ExpressVPN to mask origins. Lazarus Group targets defense, aerospace, and aviation sectors in Europe, India, and Brazil. Mitigation steps include immediate patching of CVE-2026-68820, monitoring outbound traffic to compromised infrastructure, and enhancing detection for associated IOCs.
ToxicPanda 2.0 and GoldDigger expand Android banking malware campaigns
ToxicPanda 2.0 is an Android banking trojan that uses overlays and WebSocket C2 to steal credentials, now targeting 349 financial institutions in 16 countries. ToxicPanda 2.0 exploits Android accessibility services and Wireless Debugging for privilege escalation, supporting 167 remote commands. GoldDigger employs the "dpt-shell" packer to obfuscate code, encrypts native logic, detects debugging attempts, and injects inputs to mimic user interactions for credential theft. GoldDigger distributes via impersonation of airline companies and shopping retailers, leading to infections in South Africa and the U.K. GoldDigger captures input from any app, collects contacts and SMS, and streams audio/video using RTMP, while running targeted apps in a virtual environment. Both malware families demonstrate sophisticated evasion and data theft techniques, posing a significant threat to global banking and cryptocurrency users.
Top Vulnerabilities Reported This Week
CVE-2026-68820 actively exploited in Microsoft Windows by Lazarus Group
CVE-2026-68820 is a critical use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), with a CVSS score not specified in the sources. CVE-2026-68820 enables attackers to escalate privileges to SYSTEM level, allowing complete control over affected Windows systems. CVE-2026-68820 is actively exploited in the wild by the Lazarus Group as part of Operation 'Dream Job', targeting sectors such as surveillance sensors, drones, and robotics in France, Germany, Brazil, and India. Check Point discovered and reported CVE-2026-68820, with the Lazarus Group leveraging phishing attacks that impersonate recruiters from companies like Lockheed Martin and Enveil, using malicious PDFs and trojanized PDF viewers to deliver the exploit. Microsoft has released a patch for CVE-2026-68820 in the August Patch Tuesday update, and federal agencies have been given a two-week deadline to apply it. The Lazarus Group has a history of high-profile attacks, including the Sony Pictures hack and the WannaCry ransomware outbreak, demonstrating advanced capabilities and persistent targeting of critical infrastructure.
CVE-2026-59310 path traversal exploited in VMware vCenter servers
CVE-2026-59310 is a critical path traversal vulnerability in VMware vCenter servers, with a CVSS score not specified in the sources. CVE-2026-59310 allows unauthenticated attackers to execute arbitrary code, leading to unauthorized access and potential data breaches. CVE-2026-59310 is actively exploited in the wild, with hundreds of compromised servers observed, particularly in Germany, the United States, and Turkey. An advanced persistent threat (APT) group is suspected to be behind the exploitation, installing a reverse SSH framework for persistent access. Broadcom has released security updates to address CVE-2026-59310, and organizations are urged to apply these patches immediately. 361 unique IP addresses across 47 countries have been linked to compromised vCenter servers, highlighting the global impact of this vulnerability.
CVE-2026-33824 exploited in Microsoft Windows IKE Service Extension
CVE-2026-33824 is a double free vulnerability in the Microsoft Windows IKE Service Extension, with a CVSS score not specified in the sources. CVE-2026-33824 enables remote code execution, potentially granting attackers unauthorized access and control over affected systems. CVE-2026-33824 has been actively exploited by a Chinese-speaking threat actor in an AI-enabled hacking campaign. CISA has issued an urgent advisory for immediate patching, and Microsoft released a patch in April 2026. Organizations using Windows IKE Service Extension are at risk of severe security breaches if the patch is not applied promptly.
CVE-2026-65400 root access exploited in Apple macOS
CVE-2026-65400 is a vulnerability in Apple macOS, with a CVSS score not specified in the sources. CVE-2026-65400 enables attackers to gain root access and deploy malicious software, such as a Monero cryptocurrency miner. CVE-2026-65400 has been actively exploited in the wild, with attackers leveraging the flaw to take control of affected devices. CISA has urged immediate patching, and Apple released an update on August 6, 2026. Organizations using macOS should ensure systems are updated and monitor for signs of unauthorized access or mining activity.
CVE-2026-15409 and CVE-2026-15410 zero-days exploited in SonicWall SMA 1000 series
CVE-2026-15409 and CVE-2026-15410 are critical pre-authentication SSRF and path traversal vulnerabilities in the SonicWall SMA 1000 series, with a CVSS score not specified in the sources. CVE-2026-15409 and CVE-2026-15410 allow attackers to gain root access without authentication, steal session tokens, and compromise MFA seed data. CVE-2026-15409 and CVE-2026-15410 have been exploited as zero-days by the INC ransomware group, with initial access brokers selling access to compromised devices. SonicWall has released firmware updates (12.4.3-03453 or 12.5.0-02835 or later) to address these vulnerabilities, and organizations are advised to update immediately. Telecommunications, manufacturing, professional services, and public sector organizations have been severely impacted, prompting a shift toward zero trust network access architectures.
Top Threat Actors Reported This Week
Laundry Bear exploits Zimbra zero-click flaw to target Western defense and government sectors
Laundry Bear (Russian state-sponsored) is primarily motivated by cyber espionage. Laundry Bear has exploited a zero-click cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite. Laundry Bear uses malicious JavaScript in emails to execute code upon display, leverages the Flowerbed framework for data exfiltration via DNS requests, and deploys adversary-in-the-middle phishing kits to capture credentials and session cookies. Laundry Bear targets organizations in the defense, education, energy, and government sectors, with confirmed attacks on the Dutch National Police and Ukrainian military personnel. Laundry Bear initiates attacks by sending phishing emails from Proton Mail accounts, impersonating organizations combating disinformation, and can steal 90 days of emails while creating unauthorized application passcodes for persistent access. Laundry Bear has affected over 10 Western organizations since July 2025, using phishing domains such as mailnalysis[.]com, zimbrastat[.]com, zimbra-metadata[.]com, and zmailanalytics[.]com.
Lazarus Group leverages Winsock zero-day in Operation Dream Job targeting global defense technology
Lazarus Group (North Korea-linked) is driven by cyber espionage and financial gain. Lazarus Group exploits CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, to achieve SYSTEM-level code execution, using phishing attacks with malicious PDFs and a trojanized PDF viewer named SecurityPDF to deliver the exploit and deploy the Troy backdoor. Lazarus Group targets surveillance sensor, drone, and robotics sectors in France, Germany, Brazil, and India, focusing on organizations involved in defense technology. In Operation 'Dream Job', Lazarus Group impersonates recruiters from companies like Lockheed Martin and Enveil, using SEO techniques and impersonation websites to distribute malicious payloads. Check Point discovered and reported the campaign, which leverages trusted branding and infrastructure to bypass detection and has prompted urgent patching directives from federal agencies.
Cavern Manticore and OilRig enhance Cavern C2 with DNS tunneling and Microsoft 365 calendar abuse
Cavern Manticore and OilRig (Iranian nation-state groups) conduct cyber espionage operations, utilizing the Cavern C2 framework with advanced communication modules. Cavern Manticore employs the HOLLOWGRAPH module to exfiltrate files and receive commands via Microsoft 365 calendar events, blending C2 traffic with legitimate network activity and complicating detection. Cavern Manticore uses DNS A-record responses to switch between direct HTTPS and Google Apps Script relays, while DNS tunneling is leveraged to refresh credentials and evade monitoring. Cavern Manticore targets organizations with access to Microsoft 365 environments, focusing on sectors where covert data exfiltration is critical. APT42, associated with these operations, has resurfaced with TAMECAT malware, leveraging AI for enhanced spear-phishing attacks against the nuclear energy sector. Researchers from Check Point Research documented these developments, highlighting the integration of AI and novel C2 techniques.
Kimsuky integrates AI into Operation GitPower for advanced spear-phishing and GitHub-based C2
Kimsuky (North Korea-linked) is focused on cyber espionage and has incorporated AI capabilities into its Operation GitPower campaign. Kimsuky uses spear-phishing emails with themes such as government correspondence, research materials, and financial documents, now augmented with AI-generated decoy documents to increase effectiveness. Kimsuky employs malicious LNK files, PowerShell loaders, and encrypted payloads disguised as images hosted on GitHub-based C2 infrastructure, using extensive obfuscation techniques like Base64 encoding and custom routines. Kimsuky targets organizations likely to handle sensitive government or financial information, leveraging AI to enhance phishing content and malware development. Kimsuky is developing an internal AI environment with tools such as GPT4All's LocalDocs, Semantic Kernel, and LangChain libraries, indicating a shift toward AI-augmented operations.
SilkParasite deploys AI-assisted malware in espionage campaign against Central Asian governments
SilkParasite (China-linked) is engaged in cyber espionage, strategically leveraging AI to optimize malware development and operational effectiveness. SilkParasite employs DLL sideloading and phishing documents impersonating government entities to deliver malicious Microsoft Office files, often packaged in password-protected RAR archives to evade detection. SilkParasite targets government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan, continuing the intelligence-gathering focus of previous operations by UAC-0063 and FamousSparrow. SilkParasite's malware is modular and exhibits AI-assisted development, with test functions left in GoginRAT and hardcoded AES keys, while the deliberate sloppiness in AI-generated lures is used to blend in with low-quality content. The campaign involves seven malware families, including previously unknown ones, and demonstrates the increasing sophistication and low-footprint nature of AI-driven cyber espionage.
Frequently Asked Questions
What is Medusa ransomware? Medusa ransomware is a ransomware strain that encrypts victim data and demands payment, with a core focus on extortion and data disclosure threats. Medusa ransomware leverages vulnerabilities in Fortra GoAnywhere, BeyondTrust, Fortinet EMS, and ScreenConnect, and uses legitimate remote access tools such as AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop to maintain persistence and evade detection.
What is Eclipse Ransomware? Eclipse Ransomware is a Ransomware-as-a-Service (RaaS) platform that encrypts files on Windows, Linux, NAS, VMware ESXi, and Nutanix systems, disrupting business operations. Eclipse Ransomware employs ChaCha20 encryption, Kyber-based key exchange, automated lateral movement, defense evasion, and process termination, with configurable modes for speed and stealth.
What is proc-macro1? A coordinated supply chain attack compromised the Rust crates arrayref, internment, and append-only-vec by introducing a malicious dependency, proc-macro1, which impersonates the legitimate proc-macro2 crate. The malicious proc-macro1 crate executes a build script during Cargo builds, downloading and running platform-specific payloads that reconstruct Base64-obfuscated C2 addresses and disable TLS certificate verification.
What is FudModule? Lazarus Group, a North Korea-linked threat actor, deploys the FudModule rootkit to disable security features and tamper with system processes, operating undetected by most EDR tools. Lazarus Group exploits CVE-2026-68820, a zero-day vulnerability in AFD.sys, to gain SYSTEM-level privileges on Windows systems.
What is ToxicPanda 2.0? ToxicPanda 2.0 is an Android banking trojan that uses overlays and WebSocket C2 to steal credentials, now targeting 349 financial institutions in 16 countries. ToxicPanda 2.0 exploits Android accessibility services and Wireless Debugging for privilege escalation, supporting 167 remote commands.
What is GoldDigger? GoldDigger employs the "dpt-shell" packer to obfuscate code, encrypts native logic, detects debugging attempts, and injects inputs to mimic user interactions for credential theft. GoldDigger distributes via impersonation of airline companies and shopping retailers, leading to infections in South Africa and the U.K.
What is Shadow hVNC? Shadow hVNC is a malware-as-a-service toolkit that provides attackers with hidden virtual desktop control, browser credential theft, and persistent access on Windows systems. Shadow hVNC creates a hidden desktop object named `RemoteXHidden` using the Windows `CreateDesktopW` API and leverages the Chrome DevTools Protocol to inject cookies and access browser sessions.
What is CVE-2026-68820? CVE-2026-68820 is a critical use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), with a CVSS score not specified in the sources. CVE-2026-68820 enables attackers to escalate privileges to SYSTEM level, allowing complete control over affected Windows systems.
What is CVE-2026-59310? CVE-2026-59310 is a critical path traversal vulnerability in VMware vCenter servers, with a CVSS score not specified in the sources. CVE-2026-59310 allows unauthenticated attackers to execute arbitrary code, leading to unauthorized access and potential data breaches.
What is CVE-2026-33824? CVE-2026-33824 is a double free vulnerability in the Microsoft Windows IKE Service Extension, with a CVSS score not specified in the sources. CVE-2026-33824 enables remote code execution, potentially granting attackers unauthorized access and control over affected systems.
What is CVE-2026-55040? CVE-2026-55040 is a weak authentication flaw in Microsoft SharePoint, with a CVSS score not specified in the sources. CVE-2026-55040 allows attackers to bypass authentication, leading to unauthorized access and potential deployment of malicious software.
What is CVE-2026-65400? CVE-2026-65400 is a vulnerability in Apple macOS, with a CVSS score not specified in the sources. CVE-2026-65400 enables attackers to gain root access and deploy malicious software, such as a Monero cryptocurrency miner.
What is CVE-2026-15409? CVE-2026-15409 and CVE-2026-15410 are critical pre-authentication SSRF and path traversal vulnerabilities in the SonicWall SMA 1000 series, with a CVSS score not specified in the sources. CVE-2026-15409 and CVE-2026-15410 allow attackers to gain root access without authentication, steal session tokens, and compromise MFA seed data.
What is CVE-2026-15410? CVE-2026-15409 and CVE-2026-15410 are critical pre-authentication SSRF and path traversal vulnerabilities in the SonicWall SMA 1000 series, with a CVSS score not specified in the sources. CVE-2026-15409 and CVE-2026-15410 allow attackers to gain root access without authentication, steal session tokens, and compromise MFA seed data.
What is Lazarus Group? Lazarus Group (North Korea-linked) is driven by cyber espionage and financial gain, with a history of high-profile attacks including the Sony Pictures hack and the WannaCry ransomware outbreak. Lazarus Group exploits CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, to achieve SYSTEM-level code execution, using phishing attacks with malicious PDFs and a trojanized PDF viewer named SecurityPDF to deliver the exploit and deploy the Troy backdoor.