Cyware Weekly Threat Intelligence - September 19 - 25, 2026

Summary
This week’s threat intelligence briefing from Cyware spotlights a rapidly evolving landscape shaped by the intersection of AI-driven attack automation, widespread exploitation of critical vulnerabilities, and coordinated espionage campaigns. Multiple China-linked threat actors and cybercrime groups escalated their operations, leveraging zero-day vulnerabilities and sophisticated exploit kits to target government, law enforcement, and enterprise sectors across the US, Asia, and Europe. The convergence of advanced malware, urgent vulnerability disclosures, and high-profile breaches underscores the need for immediate patching, vigilant monitoring, and adaptive defense strategies. All findings are based strictly on the intelligence collected and verified by cyware.com during the past week.
Top Malware Reported This Week
CLOSEDQUORUM debuts as autonomous AI-driven C2 implant for Windows
CLOSEDQUORUM is an autonomous AI-driven command-and-control (C2) implant for Windows that delegates tactical decisions to a quorum of large language models (LLMs) without human intervention. CLOSEDQUORUM leverages a unique architecture where LLMs vote on actions, enabling capabilities such as steal, inject, persist, and move as defined by a constrained JSON schema. CLOSEDQUORUM queries multiple LLM providers to determine its next steps, reducing reliance on traditional C2 infrastructure and complicating detection. CLOSEDQUORUM infects systems by executing Windows executables that communicate with various LLM APIs and may use Discord webhooks for exfiltration. CLOSEDQUORUM targets Windows platforms, focusing on credential and cryptocurrency wallet theft. CLOSEDQUORUM represents a significant shift in attack automation, as documented by Talos Intelligence.
Remus infostealer targets AI platform credentials and browser data
Remus is a sophisticated Windows infostealer designed to exfiltrate API tokens and credentials from AI platforms such as OpenAI and Anthropic, as well as applications including Claude Code, Cursor, Codex, Bitwarden, 1Password, KeePass, NordVPN, and OpenVPN, and Chromium-based browsers like Chrome, Edge, and Brave. Remus employs advanced techniques such as system-call evasion, COM-object abuse, staged exfiltration, and targets 2FA-related browser extensions to facilitate account takeover. Remus shares code and tooling with LummaC2, uses a private Obfuscator-LLVM fork for obfuscation, performs syscall-hook sweeps, and leverages Ethereum-based C2 resolution for resilient infrastructure. Remus is distributed via ClickFix social engineering, using fake CAPTCHA prompts delivered through phishing, malvertising, or compromised websites to trick users into executing malicious commands. Remus primarily targets users of AI platforms, cloud services, and a wide range of browsers and password managers. Remus has been linked to the theft of millions of API keys and tokens, as documented by SpyCloud researchers.
GraphWorm leverages Microsoft Graph and OneDrive for stealthy C2
GraphWorm is a malware implant associated with the China-nexus APT group Webworm, utilizing Microsoft Graph and OneDrive for command-and-control operations to evade traditional network detection. GraphWorm supports shell execution, file upload/download, session key upgrades, and can replace its OAuth credentials to maintain persistence even after token revocation. GraphWorm authenticates with Microsoft Graph using cleartext credentials embedded in the binary and identifies victims by hashing hardware-based identifiers such as network adapter MAC addresses, CPU, and disk serial numbers. GraphWorm infects systems through binaries that communicate with graph[.]microsoft[.]com over TLS, polling OneDrive accounts for encrypted task files and uploading results. GraphWorm targets Windows endpoints, with a focus on evading network-based detection in enterprise environments. GraphWorm's persistence and identity replacement mechanisms present significant challenges for traditional incident response, as highlighted in recent reporting.
RemControl Android banking trojan expands with AI-assisted development
RemControl is a newly identified Android banking trojan offered as a Malware-as-a-Service platform, targeting banking customers in Europe, the Middle East, and Canada. RemControl features overlay injection, screen streaming, keylogging, pattern lock capture, self-preservation, and uses Telegram dead-drop resolution and WebSocket protocol for C2 communication. RemControl employs AI-assisted development for its infrastructure and exhibits Russian-language developer artifacts, while generating unique signing certificates and using a local VPN service to block Google Play Protect. RemControl is distributed via fake Google Play Store pages impersonating the TVTap IPTV app, luring users to install the trojan. RemControl targets Android banking applications across more than 30 banks in multiple countries. RemControl has been active since May 2026, with samples observed from July 2026, as reported by Group-IB.
n0n ransomware group escalates double extortion with psychological tactics
n0n is a ransomware group employing a double extortion model, threatening to destroy backups and release stolen data if ransoms are not paid. n0n uses psychological tactics such as countdown timers to instill fear and urgency in victims, and leverages compromised credentials from third-party infostealer malware for initial access, followed by privilege escalation and data staging. n0n exploits compromised credentials to infiltrate networks and manipulates data for extortion, with attacks beginning through credential theft and progressing to backup destruction threats. n0n gains access via compromised credentials, often obtained from infostealer malware, and escalates privileges to stage data for extortion. n0n has targeted financial services (23% of victims), technology, retail, and education sectors (15% each), with victims in the US, Vietnam, Uzbekistan, Brazil, Sweden, and Luxembourg. n0n has released data for victims who refused to pay, as documented in recent reporting.
Top Vulnerabilities Reported This Week
CVE-2026-93952 actively exploited in Arista VeloCloud Orchestrator with CISA three-day deadline
CVE-2026-93952 is a critical improper input validation vulnerability (CWE-20) in Arista VeloCloud Orchestrator on-premises deployments, carrying a CVSS score of 10.0. CVE-2026-93952 allows remote attackers to access privileged internal functionality without authentication, potentially compromising the entire SD-WAN network. CVE-2026-93952 is actively exploited in the wild, prompting CISA to enforce a three-day remediation deadline for federal agencies. Arista Networks issued an emergency advisory in response to ongoing exploitation. Patches are available for 5.2.x and 6.4.x branches, while for 6.1.x and 7.0.x, administrators should remove the management interface from public exposure and restrict access via IP allowlisting or VPN until patches are released. Organizations are advised to review administrator activity logs for anomalies and rotate administrative credentials as a precaution.
CVE-2026-94127 exploited in F5 BIG-IP APM with links to UNC5174
CVE-2026-94127 is a critical heap-based buffer overflow vulnerability in F5 BIG-IP Access Policy Manager (APM) systems configured as an OAuth Authorization Server, with a CVSS score of 9.3. CVE-2026-94127 enables remote code execution, allowing attackers to compromise affected systems. CVE-2026-94127 is under active exploitation, with historical context linking previous F5 vulnerability exploitation to UNC5174, a group assessed to operate from China. F5 and CISA have issued urgent warnings and mandated immediate patching. The patch for CVE-2026-94127 must be applied without delay, and organizations should review and enhance security measures around access management and OAuth configurations. Federal agencies are required to meet CISA's patch deadline due to the potential risks to national security.
CVE-2026-93616 actively exploited in Check Point Management Server
CVE-2026-93616 is a critical path traversal and file upload vulnerability in Check Point Security Management Server and related products, with a CVSS score of 9.8. CVE-2026-93616 allows unauthenticated attackers to upload and execute arbitrary scripts, leading to unauthorized access and control over affected systems. CVE-2026-93616 is being actively exploited, with Check Point reporting attacks on several customers and providing a security hotfix. Check Point has published a detailed advisory at hxxps://support[.]checkpoint[.]com/results/sk/sk1000171/ for further information. Administrators should immediately apply the available hotfix or restrict access to the Management Server (TCP/19009) using a firewall if patching is not possible. Monitoring log files for path traversal indicators and reviewing for signs of compromise are strongly recommended.
CVE-2026-63077 exploited by ransomware gangs in JetBrains TeamCity
CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises versions 2025.11.7 and 2026.1.3, enabling unauthenticated attackers to execute commands with server-level privileges. CVE-2026-63077 can result in unauthorized access to sensitive data, modification of server states, and compromise of CI/CD pipelines. CVE-2026-63077 is actively exploited by ransomware gangs, with CISA and JetBrains confirming exploitation and a reduction in unpatched servers from 700 to 160. JetBrains released a patch in July 2026, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog in August. Administrators must patch Internet-exposed TeamCity servers immediately or restrict access to trusted networks if patching is not feasible. Continuous monitoring for indicators of compromise and unusual activity is essential.
CVE-2026-58704 exploited in Google Pixel modems; Chromium browser flaws also targeted
CVE-2026-58704 is a critical improper authorization vulnerability in Google Pixel phones' cellular modems, enabling zero-click attacks, while CVE-2026-85046 and CVE-2026-87491 affect Chromium-based browsers through type confusion and out-of-bounds write flaws in the V8 engine. CVE-2026-58704 allows remote code execution and privilege escalation without user interaction, posing a significant threat to device and browser security. CVE-2026-58704, CVE-2026-85046, and CVE-2026-87491 have been exploited in the wild, with espionage groups—some suspected to be linked to China—using these vulnerabilities to infiltrate networks in the US and Southeast Asia. CISA has mandated a three-day patch deadline for federal agencies regarding CVE-2026-58704. Users must update Google Pixel devices and all Chromium-based browsers to the latest versions and monitor for signs of exploitation. Network segmentation and access controls are recommended to limit the impact of potential breaches.
Top Threat Actors Reported This Week
ShinyHunters exploits Oracle PeopleSoft zero-day to breach FBI systems
ShinyHunters is a cybercrime group motivated by retaliation rather than financial gain, as evidenced by their recent breach of FBI systems. ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft to achieve remote code execution on the FBI jobs webpage, then moved laterally into FBI-managed AWS GovCloud infrastructure. ShinyHunters claims to have obtained 2–3 TB of data, including addresses, birth dates, and spousal information of current, former, and prospective FBI employees, as well as compromising services such as human resources, MedLink, and Criminal Justice Information Services. ShinyHunters defaced the FBI jobs portal and demanded that the FBI amend or remove a May 2026 report describing their operations and advising against ransom payments, threatening to leak the stolen data if their demand is not met within a week. Oracle and AWS have not yet responded to inquiries regarding the exploited vulnerability and the scope of the data theft. 404 Media received a sample of the data, which helped verify its authenticity.
Red Heron-linked Chinese-speaking actor targets government and law enforcement via multi-vector exploits
A Chinese-speaking threat actor linked to Red Heron is believed to be engaged in cyber espionage, targeting government and law enforcement agencies. The actor exploited wp2shell vulnerabilities (CVE-2026-63030 and CVE-2026-60137) in WordPress, a high-severity flaw (CVE-2026-7273) in ZyXEL GS1900 switches, and chained Ubiquiti vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) to achieve root-level remote code execution. The threat actor used 17 custom scripts to bypass security controls, escalate privileges, and extract registry data, and performed password-spraying attacks to access internal SQL servers. The actor targeted a range of technologies, including PAN-OS GlobalProtect, FlowiseAI, Nuclio, Proxmox, and Ubiquity, and compromised 996 devices, including a Russian state organization in occupied Ukraine. The campaign resulted in the theft of over 18,566 records containing accounts, plaintext passwords, and personally identifiable information.
UTA0565 leverages zero-days in Chrome and Microsoft products for espionage against Asian governments
UTA0565 is a China-aligned threat group primarily focused on cyber espionage, recently observed exploiting zero-day vulnerabilities in Chrome and Microsoft products (CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880). UTA0565 used phishing emails and spoofed domains, such as the Center for American Progress and China Digital Times, to deliver a previously undocumented malware family named CLEANGULP. UTA0565 exploited these vulnerabilities to achieve remote code execution and privilege escalation, targeting Asian government organizations and other entities. The group conducted these attacks in a narrow window before public disclosure or patching of the vulnerabilities. Proofpoint researchers noted that other Chinese espionage groups, including APT31, UNK_LateNight, and UNK_DoubleCheck, also weaponized the same exploit kit, indicating a coordinated effort within the Chinese cyber-espionage landscape.
TA412 and UNK_LateNight deploy BlueMoon exploit kit in espionage campaigns targeting US and Asian sectors
TA412 and UNK_LateNight are espionage-focused threat actors suspected to be China-linked, operating with the primary motive of intelligence collection. TA412 and UNK_LateNight leveraged the BlueMoon exploit kit, which chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 to exploit Chromium V8 vulnerabilities and a Windows kernel flaw, enabling browser exploitation, sandbox escape, and privilege escalation. TA412 and UNK_LateNight delivered payloads such as GemStone and ShadowPad through spearphishing campaigns, demonstrating a sophisticated exploitation approach. The actors targeted aerospace, defense, and government sectors in the US and Asia, aiming to gain elevated privileges and access sensitive data. Researchers observed rapid adoption of BlueMoon, which is suspected to have been developed with AI assistance, potentially accelerating its proliferation.
Frequently Asked Questions
What is CLOSEDQUORUM? CLOSEDQUORUM is an autonomous AI-driven command-and-control (C2) implant for Windows that delegates tactical decisions to a quorum of large language models (LLMs) without human intervention. CLOSEDQUORUM leverages a unique architecture where LLMs vote on actions, enabling capabilities such as steal, inject, persist, and move as defined by a constrained JSON schema.
What is Remus? Remus is a sophisticated Windows infostealer designed to exfiltrate API tokens and credentials from AI platforms such as OpenAI and Anthropic, as well as applications including Claude Code, Cursor, Codex, Bitwarden, 1Password, KeePass, NordVPN, and OpenVPN, and Chromium-based browsers like Chrome, Edge, and Brave. Remus employs advanced techniques such as system-call evasion, COM-object abuse, staged exfiltration, and targets 2FA-related browser extensions to facilitate account takeover.
What is GraphWorm? GraphWorm is a malware implant associated with the China-nexus APT group Webworm, utilizing Microsoft Graph and OneDrive for command-and-control operations to evade traditional network detection. GraphWorm supports shell execution, file upload/download, session key upgrades, and can replace its OAuth credentials to maintain persistence even after token revocation.
What is RemControl? RemControl is a newly identified Android banking trojan offered as a Malware-as-a-Service platform, targeting banking customers in Europe, the Middle East, and Canada. RemControl features overlay injection, screen streaming, keylogging, pattern lock capture, self-preservation, and uses Telegram dead-drop resolution and WebSocket protocol for C2 communication.
What is n0n? n0n is a ransomware group employing a double extortion model, threatening to destroy backups and release stolen data if ransoms are not paid. n0n uses psychological tactics such as countdown timers to instill fear and urgency in victims, and leverages compromised credentials from third-party infostealer malware for initial access, followed by privilege escalation and data staging.
What is CVE-2026-93952? CVE-2026-93952 is a critical improper input validation vulnerability (CWE-20) in Arista VeloCloud Orchestrator on-premises deployments, carrying a CVSS score of 10.0. CVE-2026-93952 allows remote attackers to access privileged internal functionality without authentication, potentially compromising the entire SD-WAN network.
What is CVE-2026-94127? CVE-2026-94127 is a critical heap-based buffer overflow vulnerability in F5 BIG-IP Access Policy Manager (APM) systems configured as an OAuth Authorization Server, with a CVSS score of 9.3. CVE-2026-94127 enables remote code execution, allowing attackers to compromise affected systems.
What is CVE-2026-93616? CVE-2026-93616 is a critical path traversal and file upload vulnerability in Check Point Security Management Server and related products, with a CVSS score of 9.8. CVE-2026-93616 allows unauthenticated attackers to upload and execute arbitrary scripts, leading to unauthorized access and control over affected systems.
What is CVE-2026-63077? CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises versions 2025.11.7 and 2026.1.3, enabling unauthenticated attackers to execute commands with server-level privileges. CVE-2026-63077 can result in unauthorized access to sensitive data, modification of server states, and compromise of CI/CD pipelines.
What is CVE-2026-58704? CVE-2026-58704 is a critical improper authorization vulnerability in Google Pixel phones' cellular modems, enabling zero-click attacks, while CVE-2026-85046 and CVE-2026-87491 affect Chromium-based browsers through type confusion and out-of-bounds write flaws in the V8 engine. CVE-2026-58704 allows remote code execution and privilege escalation without user interaction, posing a significant threat to device and browser security.