Cyware Weekly Threat Intelligence - September 12 - 18, 2026

This week’s threat intelligence briefing from Cyware highlights a surge in advanced ransomware and espionage operations leveraging both artificial intelligence and critical vulnerabilities. Ransomware groups have expanded their reach into AI development environments and virtualization infrastructure, while state-sponsored actors intensified global espionage campaigns targeting government, enterprise, and research sectors. The exploitation of high-impact vulnerabilities in widely used platforms underscores the persistent risk to supply chain and operational resilience. Organizations are urged to prioritize patching, network segmentation, and enhanced monitoring as threat actors continue to innovate and automate their attack strategies.
Top Malware Reported This Week
JADEPUFFER Ransomware Targets AI Development with ENCFORGE Payload
JADEPUFFER is a ransomware operation that has evolved to specifically target AI models and training data using its ENCFORGE payload, disrupting AI development lifecycles. JADEPUFFER demonstrates advanced agentic capabilities, dynamically adjusting attack methods and rapidly correcting failed actions to maximize destruction. JADEPUFFER exploits CVE-2025-3248, a missing-authentication vulnerability in Langflow, to gain remote code execution and initial access. JADEPUFFER focuses on AI assets, targeting organizations involved in AI development and research, with attacks observed since at least July 2026. JADEPUFFER leaves an 80-page audit report as a pressure tactic, and recovery costs can range from $75,000 to $500,000.
Panzer Ransomware-as-a-Service Expands Global Reach Across Critical Sectors
Panzer is a ransomware-as-a-service (RaaS) operation that emerged in August 2026, rapidly establishing itself with a polished affiliate model and targeting multiple platforms. Panzer supports Windows, Linux, FreeBSD, and VMware ESXi, with its ESXi-specific build capable of disabling entire virtualized infrastructures. Panzer employs an 80/20 revenue split to attract experienced affiliates and leverages bulk outbound data transfers for exfiltration. Panzer gains initial access by exploiting unsecured VPN and RDP endpoints, focusing on manufacturing and telecom sectors in countries including Thailand, Italy, and Indonesia. Panzer claimed 16 victims across 11 countries during a record-setting month of 997 ransomware attacks globally.
MovieReaper Modular Malware Campaign Leverages Torrents and Blockchain C2
MovieReaper is a modular, multi-stage malware campaign that targets users across Russia, Türkiye, Japan, Kenya, Uganda, Colombia, and several European countries, affecting sectors such as enterprise, government, IT, retail, transportation, and agriculture. MovieReaper uses a loader disguised as popular content, executes shellcode, bypasses UAC, and establishes persistence, with the final implant enabling extensive filesystem access and data exfiltration. MovieReaper employs the Solana blockchain for resilient C2 communication, making takedown efforts more difficult. MovieReaper spreads via compromised torrent files from the defanged repository itorrents[.]org, impacting users of multiple torrent trackers. MovieReaper has been active since mid-August 2026, with a large-scale infection campaign affecting both individuals and organizations.
GTG-20006 State-Sponsored Group Uses AI-Enhanced Malware for Espionage
GTG-20006 is a Russian state-sponsored group leveraging AI to enhance malware operations, enabling rapid rebuilding of malware after detection and increasing operational stealth and persistence. GTG-20006 uses a toolkit including PowerChrome, WUEngine, Shadow C2, MiniPlasma, and CloudSyncSvc for Windows, GiftDrop for Android, and DarkSword for iOS, supporting credential theft, phishing, and remote access. GTG-20006 employs DNS hijacking on hotel Wi-Fi networks, compromising hospitality vendors to redirect traffic and deliver malware, capturing device identifiers and IP addresses of hotel guests. GTG-20006 targets diplomatic and government personnel, stealing Microsoft 365 tokens via a cloud email espionage platform built on the Embassy Kit framework. GTG-20006 has led to unauthorized access to mail records from multiple organizations, significantly impacting defenders' costs.
Cyclops Blink Returns with Enhanced Modules Targeting Cisco FMC Devices
Cyclops Blink is a sophisticated modular malware associated with the IRON VIKING group, providing persistent remote access and extensive network reconnaissance capabilities. Cyclops Blink features a parent controller and five worker modules for host reconnaissance, file transfer, network scanning, packet capture, and persistence, communicating with its C2 infrastructure using encrypted sessions. Cyclops Blink exploits Linux-based network appliances, including Cisco Firewall Management Center, SD-WAN controllers, and VPNs, using SysV persistence and targeting ports 43856 and 49172. Cyclops Blink now targets x86-64 Linux systems, expanding beyond its previous focus on WatchGuard devices. Cyclops Blink poses a risk to a wide range of network-edge devices, with the 2026 version including additional modules for network scanning and packet capture.
Top Vulnerabilities Reported This Week
CVE-2026-76461 actively exploited in Cisco Secure Email Gateway
CVE-2026-76461 is a critical email parsing vulnerability in Cisco Secure Email Gateway (physical and virtual), allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. CVE-2026-76461 enables complete system compromise, potentially resulting in data breaches and operational disruption. CVE-2026-76461 is actively exploited in the wild, with CISA adding it to the Known Exploited Vulnerabilities catalog and mandating remediation by September 17, 2026. Cisco disclosed CVE-2026-76461 and provided a specific log detection command: cisco-esa> grep -i " COPY.*TO PROGRAM" [IronPort Text Mail Logs Log name - Default: mail_logs]. No patch or workaround is currently available; organizations must monitor logs for suspicious SQL statements and contact Cisco for further guidance. CVE-2026-76461 affects all supported versions of Cisco Secure Email Gateway, and attackers may remove or hide indicators of compromise due to root access.
CVE-2026-85706 exploited via repository commits API in GitLab CE and EE
CVE-2026-85706 is a critical path traversal vulnerability (CVSS 10.0) in GitLab Community Edition (CE) and Enterprise Edition (EE), affecting versions prior to 19.3.2, 19.2.6, and 19.1.8. CVE-2026-85706 allows unauthenticated remote attackers to access arbitrary files, including sensitive credentials and tokens, by exploiting improper path confinement and missing authentication in the repository commits API endpoint. CVE-2026-85706 is under active exploitation, with WatchTowr and other sources confirming behavioral probes and attacks against honeypot networks shortly after GitLab's patch release. The vulnerability was highlighted by CISA and NCSC, who issued urgent alerts following GitLab's security update on September 10. Organizations must immediately upgrade to versions 19.3.2, 19.2.6, or 19.1.8, review logs for suspicious API activity (especially requests to /api/v4/projects/{id}/repository/commits/), and rotate any potentially exposed secrets. CVE-2026-85706 poses a significant risk to supply chain and DevOps environments, with potential for widespread data breaches.
CVE-2026-59310 ransomware attacks target VMware vCenter via directory traversal
CVE-2026-59310 is a critical directory traversal vulnerability in VMware vCenter's Syslog server, enabling unauthenticated attackers to execute arbitrary code remotely. CVE-2026-59310 can result in unauthorized network access, data breaches, and operational disruption, with ransomware gangs leveraging the flaw for data encryption and extortion. CVE-2026-59310 exploitation began with APT actors deploying a reverse SSH tool for persistence and remote access, followed by ransomware gangs abusing the vulnerability; Broadcom released a patch on July 29, and QUIRSO reported over 361 compromised IPs across 47 countries. CISA subsequently added CVE-2026-59310 to its Known Exploited Vulnerabilities Catalog, emphasizing the urgency of patching. Organizations must immediately apply Broadcom's patch, review network logs and configurations for signs of compromise, and implement network segmentation and enhanced monitoring. CVE-2026-59310's exploitation highlights the persistent targeting of VMware infrastructure by both APT and ransomware actors.
CVE-2026-75650 StyleSmuggler exploited in Magento and Adobe Commerce
CVE-2026-75650, known as StyleSmuggler, is a critical server-side template injection vulnerability (CWE-1336, CVSS 10.0) in Magento Open Source and Adobe Commerce versions 2.4.4 to 2.4.9. CVE-2026-75650 allows remote attackers to execute arbitrary PHP code by exploiting the styles property during email template rendering, specifically targeting the BlockFactory and UrlGeneratorFactory components where attacker-named classes are instantiated before type-checking. CVE-2026-75650 is actively exploited in the wild, with Sansec reporting ongoing compromises before Adobe's advisory and attackers bypassing WAF rules by executing code during internal email rendering. Sansec discovered CVE-2026-75650 and Adobe released emergency patch APSB26-146 to address the flaw. Organizations must apply the patch immediately, assume compromise for stores active between September 4-7, rotate all credentials, and implement runtime monitoring for disguised malware processes such as [kworker/u:8:0], fc-cache, and chronyd. CVE-2026-75650 affects over 111,000 Magento stores, with attackers using port 123 to mimic NTP traffic and evade detection.
Top Threat Actors Reported This Week
GTG-20006 leverages AI-driven malware for espionage and persistence
GTG-20006 is a Russian state-sponsored threat actor primarily focused on cyber espionage and operational persistence. GTG-20006 employs AI to monitor malware stealth and persistence, enabling rapid rebuilding of malware after detection and significantly increasing defenders' operational costs. GTG-20006 has developed a cloud email espionage platform using the Embassy Kit framework to steal Microsoft 365 tokens, and utilizes DNS hijacking on hotel Wi-Fi networks to redirect traffic and deliver malware. GTG-20006 targets diplomatic and government personnel, compromising hospitality vendors to capture device identifiers and IP addresses of hotel guests. GTG-20006 deploys a diverse malware toolkit, including Windows implants (PowerChrome, WUEngine, Shadow C2, MiniPlasma, CloudSyncSvc), the Android surveillance RAT GiftDrop, and the iOS tool DarkSword, for credential theft, phishing, and remote access.
Salt Typhoon intensifies Latin American espionage with SparroWocky backdoor
Salt Typhoon is a China-backed cyber-espionage group motivated by intelligence collection and strategic interests. Salt Typhoon has developed the modular C++ backdoor SparroWocky, which uses open-source projects like Mbed TLS for secure communication, MinHook for API hooking, and the SilentMoonwalk technique for evasion. Salt Typhoon shifted its focus to Latin America, targeting telecommunications and government agencies in Argentina, Ecuador, and Venezuela, influenced by US policies under President Donald Trump that threaten China's investments in the region. Salt Typhoon's recent campaign involves deploying SparroWocky to infiltrate high-profile organizations, executing nearly 30 commands for file theft, screenshot capture, and session ID collection. Researchers uncovered Salt Typhoon's activities in late 2023, noting the use of TLS-encrypted C2 channels on ports 443 and 8080.
FamousSparrow deploys SparroWocky in advanced Latin American espionage
FamousSparrow, linked to China, is a cyber-espionage group focused on intelligence collection from government organizations. FamousSparrow deploys the SparroWocky backdoor via DLL side-loading, using a loader to decrypt and map RC4-encoded payloads in memory, and employs evasion techniques such as call stack spoofing and disguising malicious code as legitimate Windows components. FamousSparrow targets government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela, with operations ongoing for over a year. FamousSparrow's campaign leverages SparroWocky's modular C++ architecture to run commands, execute files, and collect system information, including frequent screenshot capture and Windows thread creation interception via MinHook. FamousSparrow communicates with C2 servers over ports 443 and 8080, using HTTP and SOCKS5 proxies to evade detection.
APT36 launches Operation RapidRust targeting Indian and Afghan government sectors
APT36 (also tracked as Transparent Tribe) is a Pakistan-nexus threat actor motivated by intelligence gathering against regional adversaries. APT36 utilizes sophisticated tools such as the Rust-based backdoor RUSTYSHADE and file-stealing tools PSNATCH and BASHNATCH, and employs reconnaissance and lateral movement commands including ipconfig, whoami, arp -a, and net use. APT36 targets government and defense entities in India and Afghanistan, leveraging typosquatted domains and legitimate services like GitHub and Backblaze for staging and exfiltration. APT36's Operation RapidRust campaign, conducted between August 20 and September 1, 2026, involved registering domains impersonating Indian media outlets and using GitHub for command-and-control communication. APT36's malware encrypts messages with AES-256-GCM and exfiltrates data to GitHub repositories, with file hashes and domains identified for blocking.
Red Heron exploits Gitea RCE for global intelligence collection
Red Heron is a Chinese threat actor focused on strategic intelligence collection and cyber espionage. Red Heron exploits the critical Gitea RCE vulnerability (CVE-2026-60004) using an automated Python framework to gain unauthorized access, and deploys a C++ Linux implant (JITTERLY) and LD_PRELOAD rootkit (SIXZUT) for persistent access and lateral movement. Red Heron targets organizations in the elections, aerospace, government, public safety, and research sectors across Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka. Red Heron's campaign includes enumeration, data exfiltration, and infrastructure mapping, with activities marked by the use of Simplified Chinese labels and the classification of Taiwan as part of China, indicating a strategic intelligence collection effort. Red Heron scanned 1,386 Gitea instances and maintained a dataset of 477 Taiwan-based systems, compromising 13 organizations in total.
Handala Hack deploys HEAVYGRAM and CRUDEEXCLUDE against Iranian dissidents
Handala Hack is an Iran-linked threat actor associated with the Ministry of Intelligence and Security (MOIS), primarily motivated by surveillance and suppression of opposition. Handala Hack deploys the sophisticated Windows backdoor HEAVYGRAM, which uses Telegram for command-and-control, and leverages the related CRUDEEXCLUDE malware family to enhance capabilities. Handala Hack targets Iranian dissidents, journalists, and government opponents, delivering malware via social engineering and impersonation of legitimate applications such as Pictory, KeePass, and Telegram. Handala Hack's campaign involves executables like RuntimeSSH.exe and winappx.exe for screen and audio recording, cache capture, encrypted file compression, and exfiltration via the Telegram API, with persistence achieved through Windows registry modifications and PowerShell-based defense evasion. The FBI and U.S. Department of Justice have linked Handala Hack to domain infrastructure seizures and detailed the malware's use in targeting individuals opposing the Iranian government.
Frequently Asked Questions
What is JADEPUFFER? JADEPUFFER is a ransomware operation that has evolved to specifically target AI models and training data using its ENCFORGE payload, disrupting AI development lifecycles. JADEPUFFER demonstrates advanced agentic capabilities, dynamically adjusting attack methods and rapidly correcting failed actions to maximize destruction.
What is Panzer? Panzer is a ransomware-as-a-service (RaaS) operation that emerged in August 2026, rapidly establishing itself with a polished affiliate model and targeting multiple platforms. Panzer supports Windows, Linux, FreeBSD, and VMware ESXi, with its ESXi-specific build capable of disabling entire virtualized infrastructures.
What is MovieReaper? MovieReaper is a modular, multi-stage malware campaign that targets users across Russia, Türkiye, Japan, Kenya, Uganda, Colombia, and several European countries, affecting sectors such as enterprise, government, IT, retail, transportation, and agriculture. MovieReaper uses a loader disguised as popular content, executes shellcode, bypasses UAC, and establishes persistence, with the final implant enabling extensive filesystem access and data exfiltration.
What is Cyclops Blink? Cyclops Blink is a sophisticated modular malware associated with the IRON VIKING group, providing persistent remote access and extensive network reconnaissance capabilities. Cyclops Blink features a parent controller and five worker modules for host reconnaissance, file transfer, network scanning, packet capture, and persistence, communicating with its C2 infrastructure using encrypted sessions.
What is CVE-2025-3248? JADEPUFFER exploits CVE-2025-3248, a missing-authentication vulnerability in Langflow, to gain remote code execution and initial access. JADEPUFFER focuses on AI assets, targeting organizations involved in AI development and research, with attacks observed since at least July 2026.
What is CVE-2026-76461? CVE-2026-76461 is a critical email parsing vulnerability in Cisco Secure Email Gateway (physical and virtual), allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. CVE-2026-76461 enables complete system compromise, potentially resulting in data breaches and operational disruption.
What is CVE-2026-85706? CVE-2026-85706 is a critical path traversal vulnerability (CVSS 10.0) in GitLab Community Edition (CE) and Enterprise Edition (EE), affecting versions prior to 19.3.2, 19.2.6, and 19.1.8. CVE-2026-85706 allows unauthenticated remote attackers to access arbitrary files, including sensitive credentials and tokens, by exploiting improper path confinement and missing authentication in the repository commits API endpoint.
What is CVE-2026-59310? CVE-2026-59310 is a critical directory traversal vulnerability in VMware vCenter's Syslog server, enabling unauthenticated attackers to execute arbitrary code remotely. CVE-2026-59310 can result in unauthorized network access, data breaches, and operational disruption, with ransomware gangs leveraging the flaw for data encryption and extortion.
What is CVE-2026-75650? CVE-2026-75650, known as StyleSmuggler, is a critical server-side template injection vulnerability (CWE-1336, CVSS 10.0) in Magento Open Source and Adobe Commerce versions 2.4.4 to 2.4.9. CVE-2026-75650 allows remote attackers to execute arbitrary PHP code by exploiting the styles property during email template rendering, specifically targeting the BlockFactory and UrlGeneratorFactory components where attacker-named classes are instantiated before type-checking.
What is SparroWocky? Salt Typhoon has developed the modular C++ backdoor SparroWocky, which uses open-source projects like Mbed TLS for secure communication, MinHook for API hooking, and the SilentMoonwalk technique for evasion. Salt Typhoon shifted its focus to Latin America, targeting telecommunications and government agencies in Argentina, Ecuador, and Venezuela, influenced by US policies under President Donald Trump that threaten China's investments in the region.