Cyware at Auto-ISAC Summit 2026
Understand Where You Are on the CTI Maturity Curve
Weekly Threat Briefing
Diamond Trail

Cyware Weekly Threat Intelligence - September 26 - October 2, 2026

14 min read
Share this article
shutterstock 2379342661

Summary

This week’s threat intelligence briefing from cyware.com reveals a surge in coordinated cyber operations targeting critical infrastructure, government, and civil society organizations worldwide. State-linked threat actors from Russia, China, and Iran intensified their campaigns, leveraging advanced malware and exploiting multiple high-severity vulnerabilities to achieve persistent access and data exfiltration. The rapid weaponization of newly disclosed vulnerabilities and the expansion of sophisticated malware frameworks underscore the evolving risk landscape for organizations across sectors and geographies.

The week is defined by the intersection of aggressive ransomware, espionage backdoors, and infostealers with active exploitation of critical software vulnerabilities. Cross-category linkages—such as threat actors deploying custom malware in tandem with zero-day exploits—highlight the need for rapid patching, vigilant monitoring, and robust defense strategies.

CTA_1_LI_Wednesday_Friday_DTI_WTI_After_Overview

Top Malware Reported This Week

Warlock ransomware exploits SharePoint vulnerabilities in critical infrastructure

Warlock ransomware is a ransomware strain developed by the China-nexus group Longlegs, designed to encrypt and extort critical infrastructure, government, and educational organizations. Warlock ransomware exploits Microsoft SharePoint vulnerabilities, deploying webshells in the LAYOUTS directory to harvest ASP[.]NET machine keys for remote code execution. Warlock ransomware uses DLL sideloading and living-off-the-land techniques to evade detection, and leverages PowerShell commands to deploy ransomware via the SYSVOL share for mass network infection. Warlock ransomware gains initial access by exploiting SharePoint zero-day vulnerabilities, with observed attacks using file indicator 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c and network IOCs such as litter[.]catbox[.]moe and 45[.]158[.]196[.]23:8888. Warlock ransomware has targeted water utilities, telecommunications providers, regional government bodies, and universities in Portuguese and Spanish-speaking countries across Europe, Africa, and Latin America.

  • Implement patches for known SharePoint vulnerabilities.

  • Enhance monitoring of network traffic for suspicious activities.

Star Blizzard expands RedFlick malware campaigns globally

Star Blizzard is a Russian government-affiliated threat group deploying the RedFlick malware for cyberespionage against NGOs, think tanks, and government organizations. Star Blizzard has shifted tactics from targeted spear-phishing to large-scale phishing campaigns, using lures such as event invitations and tax audit notifications to deliver RedFlick. Star Blizzard enables RedFlick to compromise systems with a single user interaction, deploying the CosmicPulse backdoor via scheduled tasks to evade detection and maintain persistence. Star Blizzard delivers RedFlick through phishing emails, with campaigns evolving since 2023 and at least 13 significant operations in 2026, initially focusing on Ukraine before expanding to the U.S. and U.K. Star Blizzard primarily targets NGOs, think tanks, and government organizations worldwide, reflecting a strategic enhancement in operational capabilities.

UAT-11587 leverages Antino backdoor in Asian government targeting

UAT-11587 is a China-linked threat group deploying the Antino backdoor to compromise government and policy organizations across Asia. UAT-11587 uses spear-phishing emails with sender spoofing and Gmail attachment widget cloning to enhance infection success. UAT-11587 employs a Rust-compiled Antino backdoor that uses Microsoft 365 for C2, leverages Cloudflare and Amazon CloudFront for delivery, and executes a multi-stage infection chain involving HTA and WSF stagers, .NET deserialization, and DLL sideloading. UAT-11587 initiates attacks via sophisticated spear-phishing, with major campaigns observed in Taiwan, the Philippines, and a peak in India. UAT-11587 targets defense, government, and research institutions in Taiwan, India, the Philippines, and Cambodia.

  • Monitor for specific IOCs related to UAT-11587.

  • Scrutinize email headers for sender-domain misalignment.

  • Monitor for unusual activity in Microsoft 365 environments.

FamousSparrow deploys SparroWocky backdoor against Latin American governments

FamousSparrow is a China-aligned cyberespionage group that has shifted focus from hotels to government organizations in Latin America, deploying the SparroWocky backdoor. FamousSparrow uses DLL side-loading for deployment, achieves persistence via Windows services and registry keys, and supports in-memory execution with TLS-encrypted C2 on ports 443 and 8080. FamousSparrow enables SparroWocky to execute commands, transfer data, perform reconnaissance, proxy TCP traffic, manipulate files, and capture screenshots, with RC4 encryption over TLS and integration of open-source offensive tooling. FamousSparrow delivers SparroWocky through DLL side-loading, with activity observed since July 2025. FamousSparrow targets government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela.

  • Monitor for anomalous DLL side-loading and suspicious persistence mechanisms.

  • Inspect network traffic for unusual connections on ports 443 and 8080.

Remus infostealer leverages blockchain for resilient C2 and targets AI clients

Remus is an advanced infostealer distributed via a MaaS model, designed to bypass MFA by targeting authenticated browser sessions and expanding to AI clients like Claude, Codex, OpenCode, Cursor, and Devin. Remus uses EtherHiding, a blockchain-based mechanism, for C2 address rotation, and employs techniques such as PLYCHIP pre-filtering, screening, and Host header spoofing to evade detection. Remus communicates with its C2 server via encrypted channels, uses syscall.Syscall for execution transfer, and exfiltrates data through browser-process injection and clipboard capture. Remus is delivered via domains such as one-verif[.]lol and genuskox[.]biz, exploiting delivery chains like ClickFix, DonutLoader, and GoFlateLoader. Remus targets browser credentials and session tokens, with campaigns active from March to September 2026.

  • Monitor for domains and IPs such as fightwa[.]biz and ethereum-rpc[.]publicnode[.]com.

  • Block access to Ethereum smart contract-related services if not needed.

  • Implement EDR solutions to identify and block suspicious PowerShell activities.

Top Vulnerabilities Reported This Week

CVE-2026-88771 and CVE-2026-88772 actively exploited in Citrix NetScaler ADC and Gateway

CVE-2026-88771 is an unauthenticated command execution vulnerability and CVE-2026-88772 is a memory corruption vulnerability in Citrix NetScaler ADC and Gateway, both with a CVSS score of 9.5. Successful exploitation of CVE-2026-88771 and CVE-2026-88772 allows attackers to execute remote commands, cause memory corruption, and gain unauthorized control over affected systems, potentially leading to data exfiltration and service disruption. Both CVE-2026-88771 and CVE-2026-88772 are being actively exploited globally, with attackers leveraging unique webshells, anti-forensic techniques such as crontab jobs, and custom scripts to maintain access and evade detection. Researchers including Simo Kohonen and Kevin Beaumont have reported widespread exploitation, and CISA, CERT Europe, and Australia's Cyber Security Centre have issued alerts. Citrix released patches on September 27, 2026, and agencies are required to implement fixes by September 30, with a strong recommendation to capture forensic data before patching due to the risk of losing evidence. CVE-2026-88771 exploitation specifically involves crafted POST requests to the /nf/auth/doAuthentication[.]do endpoint, using log-poison payloads, `${IFS}` evasion, Python-urllib, and DNS exfiltration to httpworkbench[.]com.

CVE-2026-104286 actively exploited in FortiMail via path traversal and null byte injection

CVE-2026-104286 is a critical path traversal and null byte injection vulnerability in FortiMail, affecting versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, with a CVSS score of 9.8. Successful exploitation of CVE-2026-104286 allows attackers to execute unauthorized code or commands, leading to data breaches and system compromise. CVE-2026-104286 is being actively exploited in zero-day attacks, with IOCs including altered files such as /data/lib/liblog[.]so and /bin/smit, and associated IPs 79[.]141[.]169[.]187 and 45[.]129[.]0[.]192. Fortinet identified the vulnerability, and CISA has mandated federal agencies to mitigate it by October 4th. Recommended actions include disabling the IBE feature, restricting management interface access, upgrading to the 7.4 branch or later, applying security updates, and monitoring for IOCs and suspicious IPs.

CVE-2026-76504 actively exploited authentication bypass in Cisco Catalyst SD-WAN Manager

CVE-2026-76504 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, with a CVSS 3.1 score of 9.8, affecting releases earlier than 20.9. Exploitation of CVE-2026-76504 allows unauthenticated remote attackers to access the management API with administrator privileges, depending on deployment and attacker actions. Cisco confirmed active exploitation in September 2026, and CISA added CVE-2026-76504 to its KEV catalog with an October 3, 2026, remediation deadline. The vulnerability was discovered due to improper handling of URI encoding (CWE-177), with exploitation involving encoded characters such as %6a for 'j' in the j_security_check indicator. Mitigation steps include upgrading to a fixed release, restricting management access, collecting admin-tech files for Cisco TAC, and reviewing administrator accounts and authentication logs for suspicious encoded requests.

CVE-2026-85706 exploited for unauthenticated file read in GitLab

CVE-2026-85706 is an arbitrary file read vulnerability in GitLab, with a CVSS score of 10.0, affecting versions prior to 19.1.8, 19.2.6, and 19.3.2. Exploitation of CVE-2026-85706 allows attackers to access sensitive files, including configuration files and internal logs, without authentication, severely impacting data confidentiality and integrity. CVE-2026-85706 has been actively exploited in the wild and is listed in CISA's Known Exploited Vulnerabilities catalog. EQSTLab identified the vulnerability, which is exploited by URL-encoding a letter in the commits API to bypass access controls. Immediate patching to versions 19.1.8, 19.2.6, or 19.3.2 is required, along with monitoring for unauthorized access attempts and reviewing logs for suspicious activity.

Top Threat Actors Reported This Week

UAC-0244 and UAC-0263 intensify mobile malware campaigns against Ukrainian entities

UAC-0244 and UAC-0263 are Russian-affiliated threat actors focused on cyber operations against Ukrainian military personnel and government officials, primarily for intelligence gathering. UAC-0244 and UAC-0263 deploy the DarkSword exploit kit to compromise iPhones via watering-hole attacks, exploiting vulnerabilities in Safari and iOS, and distribute malicious Android apps by impersonating legitimate entities. UAC-0244 and UAC-0263 use impersonation tactics, creating fake websites to lure victims into downloading malware-laden apps. UAC-0244 targets Ukrainian regional news outlets, courts, and food processing companies, while UAC-0263 focuses on broader Ukrainian entities. UAC-0244 leverages the CamelSpy malware to collect location data, SIM card information, contacts, call logs, and images, while UAC-0263 uses BTMOB for remote access to infected devices.

UAT-11587 (China-linked) expands Antino backdoor campaigns across Asian government and policy sectors

UAT-11587 is a China-linked threat actor conducting cyber espionage against government and policy organizations across Asia. UAT-11587 employs spear-phishing emails with sender spoofing and Gmail attachment widget cloning to increase the credibility of their attacks. UAT-11587 delivers the Antino backdoor, a Rust-compiled malware that uses Microsoft 365 for command-and-control, leveraging legitimate cloud services like Cloudflare and Amazon CloudFront for delivery and tracking. UAT-11587 targets defense, government, and research institutions in Taiwan, India, the Philippines, and Cambodia. UAT-11587's infection chain involves multiple stages, including HTA and WSF stagers, .NET deserialization, and DLL sideloading, with significant campaign activity observed from September 2025 through July 2026.

Star Blizzard (FSB-linked) escalates global phishing campaigns with CosmicPulse and RedFlick malware

Star Blizzard (also known as a Russian state-sponsored group linked to the FSB) is engaged in cyber espionage and information operations targeting organizations worldwide. Star Blizzard exploits hacked WordPress and cPanel accounts to send phishing emails, delivering the CosmicPulse backdoor and RedFlick malware, and has shifted from free email services to compromised infrastructure for increased credibility. Star Blizzard targets NGOs, think tanks, and government organizations, with a focus on the U.S., U.K., and Ukraine. Star Blizzard's campaigns use lures such as fake event invitations and tax audit notices, with malware infection flows requiring minimal user interaction and establishing persistence via scheduled tasks. Researchers observed at least 13 significant campaigns in 2026, affecting over 100 organizations and demonstrating a strategic enhancement in operational capabilities.

HEAVYGRAM spyware leverages Telegram for C2 in targeting Iranian dissidents and journalists

HEAVYGRAM is a sophisticated spyware attributed to Iran's Ministry of Intelligence and Security, primarily motivated by surveillance of dissidents, journalists, and activists. HEAVYGRAM spreads through deceptive messages, posing as trusted contacts or tech support, and disguises itself as legitimate software such as Pictory, KeePass, Telegram, RunwayML, Norton Antivirus, Adobe Flash Player, and MRI scan results. HEAVYGRAM connects to a Telegram bot for command and control, persists by adding itself to Windows 'Run' registry keys, and configures Microsoft Defender to ignore its presence. HEAVYGRAM targets individuals in the U.K., U.S., and the Netherlands, with operations traced back to 2023. HEAVYGRAM exfiltrates data via Telegram bots and cloud storage services like Vultr and Storj, with stolen personal details appearing on pro-Iranian leak sites.

FamousSparrow pivots to Latin American government targets with SparroWocky backdoor

FamousSparrow is a China-aligned cyberespionage group that has shifted its focus from global hotel chains to government organizations in Latin America. FamousSparrow deploys the SparroWocky backdoor using DLL side-loading, achieving persistence through Windows services and registry keys, and supports in-memory execution with TLS-based C2 communication on ports 443 and 8080. FamousSparrow targets government organizations in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. FamousSparrow's SparroWocky is a modular C++ backdoor enabling command execution, data transfer, system reconnaissance, TCP proxying, file manipulation, and screenshot capture, with data encrypted using RC4 over TLS. Researchers observed this operational shift beginning around July 2025 and continuing into 2026, highlighting the group's advanced defense-evasion and extensibility.

CTA_2_LI_Wednesday_Friday_DTI_WTI_Before_FAQ

Frequently Asked Questions

  1. What is Warlock ransomware? Warlock ransomware is a ransomware strain developed by the China-nexus group Longlegs, designed to encrypt and extort critical infrastructure, government, and educational organizations. Warlock ransomware exploits Microsoft SharePoint vulnerabilities, deploying webshells in the LAYOUTS directory to harvest ASP[.]NET machine keys for remote code execution.

  2. What is RedFlick? Star Blizzard is a Russian government-affiliated threat group deploying the RedFlick malware for cyberespionage against NGOs, think tanks, and government organizations. Star Blizzard has shifted tactics from targeted spear-phishing to large-scale phishing campaigns, using lures such as event invitations and tax audit notifications to deliver RedFlick.

  3. What is Antino? UAT-11587 is a China-linked threat group deploying the Antino backdoor to compromise government and policy organizations across Asia. UAT-11587 uses spear-phishing emails with sender spoofing and Gmail attachment widget cloning to enhance infection success.

  4. What is SparroWocky? FamousSparrow is a China-aligned cyberespionage group that has shifted focus from hotels to government organizations in Latin America, deploying the SparroWocky backdoor. FamousSparrow uses DLL side-loading for deployment, achieves persistence via Windows services and registry keys, and supports in-memory execution with TLS-encrypted C2 on ports 443 and 8080.

  5. What is Remus? Remus is an advanced infostealer distributed via a MaaS model, designed to bypass MFA by targeting authenticated browser sessions and expanding to AI clients like Claude, Codex, OpenCode, Cursor, and Devin. Remus uses EtherHiding, a blockchain-based mechanism, for C2 address rotation, and employs techniques such as PLYCHIP pre-filtering, screening, and Host header spoofing to evade detection.

  6. What is BraZetsu? BraZetsu is a Python-based malware framework attributed to the Brazilian threat actor Exilware, facilitating the conversion of compromised systems into assets for sale on the Infected Marketplace. BraZetsu uses Python and Nuitka for compilation, employs social engineering for initial infection, and establishes persistent WebSocket C2 connections for remote command execution.

  7. What is CVE-2026-88771? CVE-2026-88771 is an unauthenticated command execution vulnerability and CVE-2026-88772 is a memory corruption vulnerability in Citrix NetScaler ADC and Gateway, both with a CVSS score of 9.5. Successful exploitation of CVE-2026-88771 and CVE-2026-88772 allows attackers to execute remote commands, cause memory corruption, and gain unauthorized control over affected systems, potentially leading to data exfiltration and service disruption.

  8. What is CVE-2026-88772? CVE-2026-88771 is an unauthenticated command execution vulnerability and CVE-2026-88772 is a memory corruption vulnerability in Citrix NetScaler ADC and Gateway, both with a CVSS score of 9.5. Successful exploitation of CVE-2026-88771 and CVE-2026-88772 allows attackers to execute remote commands, cause memory corruption, and gain unauthorized control over affected systems, potentially leading to data exfiltration and service disruption.

  9. What is CVE-2026-104286? CVE-2026-104286 is a critical path traversal and null byte injection vulnerability in FortiMail, affecting versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, with a CVSS score of 9.8. Successful exploitation of CVE-2026-104286 allows attackers to execute unauthorized code or commands, leading to data breaches and system compromise.

  10. What is CVE-2026-76504? CVE-2026-76504 is a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager, with a CVSS 3.1 score of 9.8, affecting releases earlier than 20.9. Exploitation of CVE-2026-76504 allows unauthenticated remote attackers to access the management API with administrator privileges, depending on deployment and attacker actions.

  11. What is CVE-2026-85706? CVE-2026-85706 is an arbitrary file read vulnerability in GitLab, with a CVSS score of 10.0, affecting versions prior to 19.1.8, 19.2.6, and 19.3.2. Exploitation of CVE-2026-85706 allows attackers to access sensitive files, including configuration files and internal logs, without authentication, severely impacting data confidentiality and integrity.

  12. What is UAC-0244? UAC-0244 and UAC-0263 are Russian-affiliated threat actors focused on cyber operations against Ukrainian military personnel and government officials, primarily for intelligence gathering. UAC-0244 and UAC-0263 deploy the DarkSword exploit kit to compromise iPhones via watering-hole attacks, exploiting vulnerabilities in Safari and iOS, and distribute malicious Android apps by impersonating legitimate entities.

  13. What is UAT-11587? UAT-11587 is a China-linked threat actor conducting cyber espionage against government and policy organizations across Asia. UAT-11587 employs spear-phishing emails with sender spoofing and Gmail attachment widget cloning to increase the credibility of their attacks.

  14. What is Star Blizzard? Star Blizzard (also known as a Russian state-sponsored group linked to the FSB) is engaged in cyber espionage and information operations targeting organizations worldwide. Star Blizzard exploits hacked WordPress and cPanel accounts to send phishing emails, delivering the CosmicPulse backdoor and RedFlick malware, and has shifted from free email services to compromised infrastructure for increased credibility.

  15. What is HEAVYGRAM? HEAVYGRAM is a sophisticated spyware attributed to Iran's Ministry of Intelligence and Security, primarily motivated by surveillance of dissidents, journalists, and activists. HEAVYGRAM spreads through deceptive messages, posing as trusted contacts or tech support, and disguises itself as legitimate software such as Pictory, KeePass, Telegram, RunwayML, Norton Antivirus, Adobe Flash Player, and MRI scan results.

Share this article

Discover Related Resources