CTIPilot
Wed · 16 Sep 2026
All daily briefs ↗
Daily brief · UTC day

Wednesday, 16 September 2026

2 verified findings from 1 run · 2 updates to prior coverage · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Lumen: an unattributed cluster hides its command-and-control behind an IoT messaging broker so infected hosts never talk to the attacker directly. Lumen's Black Lotus Labs disclosed BambooToken on 2026-09-15, a previously undocumented malware framework active since February 2023 and observed through July 2026 that uses the MQTT publish/subscribe protocol, rather than direct callbacks, to control Windows and Linux hosts. The Windows toolset is sideloaded via a digitally signed Chinese USB hardware-token utility widely deployed in Chinese banking and government networks; targeting spans roughly a dozen enterprise victims across Asia and a handful in South America, including a compromised GitLab instance, and Lumen assesses the cluster as China-aligned without attributing it to a named group.
  2. 02NCSC-UK, the FBI and AIVD detail an Iranian spyware family that gives every victim their own private Telegram bot for command and control. NCSC-UK, the FBI and the Netherlands' AIVD jointly published a technical advisory on 2026-09-15 for CHOSEN BRICK, a Windows-only malware family Iranian state cyber actors have used since at least 2025 against dissidents, activists and journalists in the UK, US and Netherlands. Delivery is social-engineering-led over WhatsApp/Telegram; the malware persists via a registry Run key, disables Defender via exclusions, and uses a per-victim unique Telegram bot for command and control, with data exfiltrated through Telegram or legitimate cloud object stores.

01Active threats, incidents & disclosures2 items

NOTABLENATOB2

BambooToken, a previously undocumented MQTT-based malware framework sideloads via a signed Chinese hardware-token utility to control Windows and Linux hosts

Lumen's Black Lotus Labs disclosed BambooToken on 2026-09-15: an emerging, previously undocumented malware framework that, based on embedded artifacts, has been active since at least February 2023 and continued through July 2026 (Lumen Black Lotus Labs, 2026-09-15). The most recent sample Lumen correlated to the campaign, a Linux build, was first observed in December 2025 (Lumen Black Lotus Labs, 2026-09-15). Rather than the direct HTTP callbacks its 2023 version used, the current Windows and Linux toolset communicates over MQTT, a publish/subscribe protocol built for IoT device control: infected hosts publish and subscribe to topics through a broker rather than contacting a command server directly, so a compromised machine never talks to the attacker's infrastructure at all, and the channel supports asynchronous tasking that survives temporary network disruption (Lumen Black Lotus Labs, 2026-09-15). Lumen's own review of prior campaigns found only three other malware families that have ever used MQTT for command and control (IOCONTROL, Korplug/PlugX and WailingCrab) making this a rare, not novel, technique choice.

The Windows variant is sideloaded through Tendyron's "OnKey" utility, a digitally signed USB hardware-token program that verifies cryptographic material for identity checks and is widely deployed across Chinese banking and government networks ("The Windows agent was sideloaded by the Tendyron 'OnKey' program, which validates system access by retrieving cryptographic material stored on a USB drive. This product line is popular in Chinese banking and government networks," Lumen Black Lotus Labs, 2026-09-15). One variant instead masquerades as "Zhuhai Kingsoft Office Software Co., Ltd." Lumen assesses neither Tendyron's nor Kingsoft's code-signing certificate was compromised: the OnKey binary itself is genuinely signed but merely vulnerable to sideloading rather than abused through a certificate compromise, while the Kingsoft-masquerading variant's own files fail certificate-signature validation outright, confirming that certificate was never actually applied to them (Lumen Black Lotus Labs, 2026-09-15).

Once running, the malware enumerates the host through Windows Management Instrumentation (operating system details, computer system product details, the original product key, serial number and software licensing service information) then subscribes to a global broadcast topic plus per-host, GUID-scoped topics and publishes an online/offline heartbeat carrying that GUID (Lumen Black Lotus Labs, 2026-09-15). Three command handlers have been identified: SHELL spawns a command shell, FILEEX uploads, downloads and deletes files, and ONLINE collects and beacons a separate set of host parameters, including BIOS and system details, as a heartbeat (Lumen Black Lotus Labs, 2026-09-15). A recovered plugin performs security-software discovery via WMI on a five-second timer and reports results over plain HTTP. Static "dead code" strings referencing clipboard capture, keylogging, audio recording and webcam capture were found in one sample's unexecuted code sections (Lumen Black Lotus Labs, 2026-09-15); because the detail comes from dead code, researchers cannot confidently determine whether these modules were ever operational or remain under development (BleepingComputer, 2026-09-15).

Lumen's telemetry links a dozen compromised enterprise environments mostly located in Asia, with a handful in South America (named examples include a biomedical company in Argentina and a legal firm in Chile) spanning mobile-application backends, legal and financial services, a smartwatch-adjacent software company, a hotel and a GitLab instance in Hong Kong, the last of which the report flags as a software-supply-chain concern given the developer access such a compromise could yield (Lumen Black Lotus Labs, 2026-09-15). A separate cluster of over 150 infected small-office and home routers was reached through internet-wide SNMP scanning; a handful of those IPs held persistent connections to an active C2 node over the MQTT port, and Lumen identifies the underlying devices in that handful as primarily MikroTik and DrayTek routers geolocated to Singapore, Cambodia and Vietnam. Lumen believes this pool primarily supports data collection against the Chinese diaspora rather than serving as C2 relay infrastructure (Lumen Black Lotus Labs, 2026-09-15). Command-and-control domains sit behind Cloudflare, with one domain reaching Cloudflare Radar's top 500,000 most-popular domains and an older one the top million at the height of its use, evidence of a wide, established infection base rather than a narrow test deployment (Lumen Black Lotus Labs, 2026-09-15). Lumen assesses the targeting pattern as consistent with China-aligned operations but states it cannot attribute the cluster to any publicly documented actor.

Black Lotus Labs®, the threat research division at Lumen, uncovered BambooToken, an emerging malware family using the Message Queueing and Telemetry Transport (MQTT) to quietly control infected Windows and Linux systems.

The Windows agent was sideloaded by the Tendyron “OnKey” program, which validates system access by retrieving cryptographic material stored on a USB drive. This product line is popular in Chinese banking and government networks.

Lumen does not assess that Tendyron's code signing certificate was compromised. Preliminary analysis indicates the signed executable appears benign and was vulnerable to side-loading rather than actively abused through a certificate compromise.

Lumen Black Lotus Labs 2026-09-15

This approach has the advantage that infected systems do not connect directly to the attacker’s infrastructure, which increases evasion and resilience. At the same time, communications can be asynchronous, ensuring operational continuity during temporary network disruptions.

BleepingComputer 2026-09-15
threat16 Sep 05:10Zsingle-sourceOpen finding ↗
NOTABLENATOA2

CHOSEN BRICK; Iranian state cyber actors run Telegram-C2 Windows spyware against dissidents, activists and journalists, per joint NCSC-UK/FBI/AIVD advisory

NCSC UK, the US FBI and the Netherlands' AIVD jointly published a technical advisory on 2026-09-15 for CHOSEN BRICK, a Windows-only malware family Iranian state cyber actors have used since at least 2025 against dissidents, activists and journalists, with confirmed victims in the UK, US and Netherlands (NCSC UK, 2026-09-15). NCSC assesses Iran "almost certainly" uses this activity to support repression of people it perceives as regime threats, and notes Iranian intelligence services have in parallel plotted kidnap or lethal operations against some of the same class of target, framing CHOSEN BRICK as a transnational-repression tool rather than conventional espionage tradecraft (NCSC UK, 2026-09-15). NCSC UK's advisory does not itself name a specific Iranian government entity, but the tradecraft closely matches activity the FBI attributed to actors operating "on behalf of the Government of Iran Ministry of Intelligence and Security" in a flash warning circulated in March 2026, which also linked a July 2025 hack-and-leak operation to the "Handala Hack" persona the FBI assesses MOIS operates and connects to a further group, "Homeland Justice" (The Record, 2026-09-15).

Access begins with extensive social-engineering rapport-building over WhatsApp or Telegram, the actor posing as a contact already known to the target or as platform technical support (T1589, T1566.003). The victim is then persuaded to download and open a file disguised as a legitimate application (observed lures include Pictory, RunwayML, Norton Antivirus, Telegram, Adobe Flash Player and KeePass) or as MRI scan results (T1204.002); a decoy screen matching the lure's theme displays while the core malware installs in the background. Operators target the victim's work device first and, if delivery fails or detection risk looks high, pivot to asking the victim to open the file on a personal device instead, sidestepping corporate controls entirely. In every observed instance the malware has targeted Windows only.

CHOSEN BRICK persists across reboot via the registry Run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run (T1547.001), registers a mutex, commonly "ytyjyujyu" or "noi672pp434awkc12f" (T1480.002), and adds Microsoft Defender exclusions to evade detection (T1685). Command and control runs over Telegram, with each victim device assigned its own unique Telegram Bot ID as an explicit operational-security measure to prevent cross-contamination between victims (NCSC UK, 2026-09-15); newer variants layer HTTPS/SOCKS5 proxies over that channel to further obscure it (T1090.002). No automated lateral-movement capability has been observed, though the malware can download and persist additional payloads through the same registry mechanism, making it technically possible.

Tasking supports process and system enumeration (T1057, T1082), screen capture, the most commonly observed data-theft feature, used to map a victim's contacts, location and pattern of life (T1113), microphone capture (T1123), theft of Telegram/WhatsApp browser data (T1005) and email content (T1114.001), and file deletion or a full disk wipe (T1485). Collected data exfiltrates through the Telegram bot (T1041) or cloud object stores such as VultrObjects and StorjShare (T1567.002). NCSC states the most commonly observed additional-malware drop path is C:\Windows \SysWOW64, a non-standard location on most Windows installs because of the deliberate space after "Windows," which NCSC states the actor created specifically for the purpose of deploying malware; in at least one sample, this downloaded payload carried the data-wiping functionality already described above (NCSC UK, 2026-09-15). Some victims' personal data has since surfaced on pro-Iranian leak sites, which NCSC reads as a further harassment vector rather than incidental exposure (NCSC UK, 2026-09-15).

CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025.

Iran almost certainly uses cyber activity to support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists. In some cases, the Iranian intelligence services have plotted to kidnap or conduct lethal operations against individuals internationally, who they perceive as enemies of the regime.

Once established on the victim, the malware connects to Telegram for Command and Control (T1102.002). Each victim device connects to a different Telegram Bot ID unique to them as an Operational Security precaution, preventing cross-contamination between victims.

The personal details of some previous victims of CHOSEN BRICK have appeared on pro-Iranian leak sites, potentially increasing the risk to the personal safety of those affected.

NCSC UK 2026-09-15
threat16 Sep 05:00Zsingle-source · national CERTOpen finding ↗

02Updates to prior coverage2 items

NOTABLEupdatedNATOB2

Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain

First published 2026-09-13 · open finding →

Updaterun 2026-09-16T0409Z-inteltechniquessourcesevidencesourcing_noteconfidencebody

Parties claiming responsibility have posted samples of the allegedly stolen data across multiple Telegram groups and are demanding a 10,000 Bitcoin ransom, threatening daily further publication if unpaid; sourced to a relay of reporting whose original outlet remains unreachable as of 2026-09-16, so the claims are attacker-stated, not confirmed by Revolut or a second source.

Parties claiming responsibility for the breach have posted samples of the allegedly stolen data across several Telegram groups, reported to include details belonging to "prominent individuals, including business leaders, sports professionals and performing artists," and are demanding Revolut pay a ransom of 10,000 Bitcoin, worth more than 782 million US dollars at the time of reporting, threatening to publish further data "every day" if unpaid (DataBreaches.net, relaying Computing.co.uk, 2026-09-15). This is the first extortion dimension reported on an incident this entry previously described only as a disclosed process-abuse breach with no stated attacker demand. Computing.co.uk, the outlet that originated this reporting, remains unreachable on every transport tried as of 2026-09-16; neither Revolut nor a second independent outlet has confirmed the ransom figure, the Telegram posting, or the claimed victim identities, so these remain attacker-stated claims rather than established fact.

HIGHCVE-2026-85706 +2exploitedupdatedNATOA1

CVE-2026-85706, GitLab CE/EE: unauthenticated path traversal in the repository commits API reads arbitrary server files, and honeypots caught exploitation attempts one day after the patch (CVSS 10.0)

First published 2026-09-12 · open finding →

Updaterun 2026-09-16T0409Z-intelcvestagsactionssourcesevidencebody

NCSC Switzerland's Cyber Security Hub posting for this advisory was edited twice more this window: on 2026-09-14 recording CVE-2026-87719 as now actively exploited, and on 2026-09-15 adding a public working proof-of-concept for the original CVE-2026-85706 path-traversal flaw.

NCSC Switzerland's Cyber Security Hub posting for this advisory was edited twice more inside this window. On 2026-09-14 the posting's own edit-history record states "CVE-2026-87719 is known as actively exploited" (NCSC Switzerland, 2026-09-14), moving the GitLab EE deserialization flaw from patch-available-only to exploited; that same-day posting carries no further detail on this CVE specifically (no campaign, no named cluster, no second source, and CISA's KEV catalog does not list it) so this status rests on NCSC Switzerland's own brief statement alone rather than the broader corroboration CVE-2026-85706 already carries. On 2026-09-15 the same posting was updated again, its status field now reading "Actively exploited, Proof of Concept available" for CVE-2026-85706 (NCSC Switzerland, 2026-09-15), and linking a public working proof-of-concept published the same day (guneykabel, 2026-09-15). No new affected-version information accompanies either update; GitLab 19.3.2/19.2.6/19.1.8 remain the fixed releases for both CVEs.

Any self-managed instance still unpatched should now be treated as likely already probed on both fronts: the file-read path with a public exploit script circulating, and, for any instance with Duo Chat-enabled accounts, the Advanced Search credential-exposure path CVE-2026-87719 opens.

Verification & coverage notes1 run

2026-09-16T0409Z-intel · Sonnet 5 · window 26 h · 2 entries published

Verification & coverage notes

Standard window (gap_hours=24, window_hours=26). All four research passes returned within the 45-minute cap; no closed-source intake this run (no intel/ drops). CHOSEN BRICK (the joint NCSC UK/FBI/AIVD Iranian-spyware advisory) was independently surfaced by three of the four research passes (the active-threats/vulns pass, the home-region/sector pass, and the research/investigative-reporting pass), composed once as a single entry from the converged findings, citing NCSC UK as the primary (single-source-national-cert carve-out; FBI and AIVD co-authored the same joint publication rather than three independent assessments).

Two new entries: CHOSEN BRICK (threat, notable) and BambooToken (threat, notable, Lumen Black Lotus Labs' previously-undocumented MQTT-C2 malware framework). Two changelog updates: the GitLab CVE-2026-85706 entry (NCSC Switzerland's posting confirmed the sibling CVE-2026-87719 now exploited and linked a public PoC for the original flaw) and the Revolut KYC-breach entry (an extortion/ransom-demand escalation, sourced to an aggregator relay after the originating outlet, Computing.co.uk, 403'd on every transport).

No deep-dive this run: CHOSEN BRICK's apt-campaign category was demoted one rank per the 7-day category-rotation rule (GTG-20006 published 2026-09-13 already used that category), and neither new item independently clears criterion 1 (no active exploitation/vulnerability involved in either).

borderline-drop: Delinea Secret Server three new PAM CVEs (CVE-2026-15638/15639/15640, CVSS 9.1-9.5), no confirmed exploitation, no public PoC, and two of the three require CVSS4 attack-complexity High/attack-requirements Present rather than a trivial pre-auth path; does not clear PD-11(b)'s out-of-band bar (routine patch cycle applies).

borderline-drop: CenterPoint Energy (US electric/gas utility) customer-data breach via unthrottled public-API sequential-ID enumeration, ~7.49M records claimed, out-of-nexus (US utility, no Swiss/EU angle), and the access technique (unrated public API without rate-limiting/WAF) is a well-known, not novel or evolved, class; does not independently clear the breach-gate's (a)-(d) criteria.

borderline-drop (added to coverage backlog, not dropped outright): AFPA (French national vocational-training agency) ~971,000-record leak-site claim, single C-reliability tracker, no victim confirmation, no Admiralty A/B journalism; added as a new open row to re-check on a later fire.

Coverage-backlog rows re-checked this run: Kimberly-Clark/ShinyHunters, Ixa Systems/TheGentlemen, UICC/Krybit, Ville de Libercourt/Kairos, Medela/ShinyHunters, reichenau.at/SafePay, the AA26-231A Siemens S7 PLC re-read, and the inside-it.ch Insel Gruppe article (17th+ consecutive fire blocked on the same host-level rate limit), no change on any. Ville du Tampon (La Réunion), no change, still no named mechanism/actor. Familea (French municipal family-services SaaS), material scope-expansion delta (now confirmed across five communes in four departments, not just Bruguières) recorded on the open row, but still no named mechanism, actor or data-theft claim, so it stays below the publish bar under the same precedent as Ville du Tampon/Boston Scientific/NovoCure.

Single-source: 2026-09-16/chosen-brick-iran-telegram-c2-dissident-spyware, single-source-national-cert (NCSC UK, with FBI/AIVD as joint co-authors of the same publication, not independent assessments; The Record's reporting relays the same advisory). 2026-09-16/bambootoken-mqtt-c2-tendyron-sideload, single-source (BleepingComputer's article relays Lumen Black Lotus Labs' own findings rather than independently assessing them). 2026-09-13/revolut-fake-government-request-kyc-breach's 2026-09-16 update, single-source-other equivalent via aggregator: the originating outlet (Computing.co.uk) 403'd on every transport tried; sourced to DataBreaches.net's direct relay, confidence lowered to medium for the entry as a whole.

Mechanical KEV sweep (tools/kev_window_diff.py --window-hours 26): 0 CISA KEV additions since 2026-09-15; no disposition needed this run.

Essential-coverage: all essential-tier sources attempted across the active-threats/vulns and home-region/sector passes with no misses; the research and incidents passes' essential slice (heise-sec, inside-it-ch) both attempted and returned RSS content with no in-window relevant item.

Declined verifier finding: the verifier's iteration-5 pass flagged a Neuchâtel-based Swiss Bitcoin Pay breach disclosure (dailyhodl.com, 2026-09-15) as an apparently-unconsidered candidate. Declined as a false positive; this incident is already published as 2026-09-15/swiss-bitcoin-pay-neuchatel-internal-systems-breach by the prior day's fire and already carried in this run's dedup index; the flagged article is same-day reporting on that same already-covered disclosure, not a fresh delta.

Coverage gaps: tp-link-omada-psirt (5th consecutive 404; vendor Nuxt SPA support portal appears to have moved its advisory-index route; needs a recipe review); zdi, watchtowr, shadowserver, hadrian-labs, vulncheck, sonatype, jpcert, esentire, sansec-research, socket-dev-blog, snyk-research, trail-of-bits (all fetched cleanly, no in-window item, active-threats/vulns pass); cert-at, ccb-belgium (404 on the specific advisory/news path attempted, home-region/sector pass); unit42, akamai-sirt, dfirreport, crowdstrike, elastic-seclabs, vulncheck, eset, esentire, csa-labs, gambit-security, paradigm-shift-research (JS shell, no listing), sygnia, trellix (JS shell, no listing), all fetched, no in-window item, research pass; helpnetsecurity (JS-rendered homepage, no listing), ico-uk (raw HTML only, not reviewed this run), incidents pass.