<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ctipilot.ch · Defense</title><link>https://ctipilot.ch/</link><atom:link href="https://ctipilot.ch/feed-defense.xml" rel="self" type="application/rss+xml"/><description>Items affecting defense, intelligence, military supply chain.</description><language>en</language><lastBuildDate>Mon, 13 Jul 2026 20:36:00 +0000</lastBuildDate><item><title>Dutch intelligence: Russia hijacked default-credential internet cameras along military-supply routes; four EU states summon Russian ambassadors</title><link>https://ctipilot.ch/entries/2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes/</guid><pubDate>Mon, 13 Jul 2026 20:36:00 +0000</pubDate><dc:date>2026-07-13T20:36:00Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>europe</category><category>dach</category><category>nordics</category><description><![CDATA[<p>AIVD and MIVD disclosed that Russia-linked actors compromised internet-connected cameras — reachable because they still used default passwords or outdated firmware, including cameras operated by businesses along the routes — carrying military supplies to Ukraine through the Netherlands, to watch the shipments and equipment being moved. The 2026-07-13 diplomatic escalation (NL/France/Germany/Finland ambassador summons, NATO condemnation) followed. Transferable lesson: internet-exposed cameras/IoT are treated as a state-actor surveillance grid.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes" data-tags="nation-state espionage russia-nexus" data-regions="europe dach nordics" data-kind="incident" data-priority="notable" data-discovered="2026-07-13T20:36:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="russia-ip-camera-hijacking-nato-military-supply-routes"><a href="https://ctipilot.ch/entries/2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes/">AIVD/MIVD: Russia-linked actors hijack default-credential IP cameras along NATO military-supply routes to monitor Ukraine-bound shipments</a></h3><p>Dutch intelligence services AIVD (General Intelligence and Security Service) and MIVD (Military Intelligence and Security Service) disclosed on 2026-07-11 that Russia-linked actors compromised &quot;a small number&quot; of internet-connected cameras positioned along routes used to move military supplies to Ukraine through the Netherlands — including cameras operated by businesses located on those routes — giving the operators remote viewing access to the shipments and equipment being moved (<a href="https://nltimes.nl/2026/07/11/dutch-spy-agencies-russia-hacked-cameras-spy-military-routes" target="_blank" rel="noopener noreferrer">NL Times/ANP, 2026-07-11</a>). The agencies state the cameras were reachable chiefly because they &quot;still us[e] default passwords or outdated firmware&quot; — weak/default-credential abuse and unpatched embedded firmware on internet-exposed devices, not a bespoke exploit chain. On 2026-07-13, after EU ministerial consultations in Brussels, the Netherlands summoned the Russian ambassador; France, Germany and Finland took the same step over related espionage and sabotage concerns, and NATO issued a joint statement condemning &quot;the persistent malicious cyber activities of Russia&quot; (<a href="https://nltimes.nl/2026/07/13/netherlands-summons-russian-ambassador-russias-hacking-military-supply-routes" target="_blank" rel="noopener noreferrer">NL Times/ANP, 2026-07-13</a>). AIVD/MIVD separately warned businesses located along military-logistics routes to harden their camera and IoT security. This is a distinct technical story from the same-day FSB Centre 16 router-hijacking advisory and the Turla espionage attribution covered separately today — here the compromised asset class is consumer/commercial IP cameras used for physical-logistics surveillance.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the transferable lesson reaches any critical-infrastructure operator, not only those on a logistics route — a state actor is treating internet-exposed cameras, DVRs/NVRs and smart-building IoT with default credentials or unpatched firmware as a physical-surveillance sensor grid. Inventory internet-reachable camera and IoT devices across your estate, and in egress/flow telemetry watch for outbound video/RTSP or streaming sessions from those devices to destinations outside the expected vendor-cloud or monitoring endpoints. <strong>Triage:</strong> many IP cameras legitimately stream to a vendor cloud or an on-prem NVR — the discriminator is a camera establishing an interactive or streaming session to an unfamiliar external destination that is neither its vendor cloud nor the site&#39;s own recorder, particularly a device still answering on a factory-default credential from the public internet.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Dutch intelligence services disclosed Friday that Russian actors had compromised “a small number of cameras” on routes for military shipments to Ukraine. The breaches allowed the hackers remote viewing access, according to statements from the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD).</p><p class="entry-cite__quote">We strongly condemn the persistent malicious cyber activities of Russia. The country uses its cyber ecosystem to attack allies and NATO partners.</p><figcaption class="entry-cite__attr"><a href="https://nltimes.nl/2026/07/11/dutch-spy-agencies-russia-hacked-cameras-spy-military-routes" target="_blank" rel="noopener noreferrer">NL Times (ANP)</a> <span class="entry-cite__date mono">2026-07-11</span></figcaption></figure></div><div class="prov"><span>incident</span><span>13 Jul 20:36Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/russia-ip-camera-hijacking-nato-military-supply-routes/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://nltimes.nl/2026/07/11/dutch-spy-agencies-russia-hacked-cameras-spy-military-routes" target="_blank" rel="noopener noreferrer">NL Times (ANP)</a></div></article>]]></content:encoded></item><item><title>ANSSI publishes CERTFR-2026-CTI-005 on FSB Centre 16&#39;s Turla cluster as France and the EU formally attribute it and sanction AO AST and NPP Gamma</title><link>https://ctipilot.ch/entries/2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology/</guid><pubDate>Mon, 13 Jul 2026 20:35:00 +0000</pubDate><dc:date>2026-07-13T20:35:00Z</dc:date><category>nation-state</category><category>espionage</category><category>phishing</category><category>russia-nexus</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>On 2026-07-13 France (ANSSI/C4) and the EU High Representative formally attributed the Turla intrusion set to Russia&#39;s FSB 16th Centre, publishing CERT-FR report CERTFR-2026-CTI-005 with French victimology (defence, diplomatic, justice and technology entities since 2017) and its spearphishing/watering-hole TTPs; the EU sanctioned 9 individuals and 4 organisations (incl. AO AST, NPP Gamma) and the UK sanctioned 24. Companion to the morning&#39;s Static Tundra router-hijacking advisory — the sibling FSB Centre 16 espionage cluster.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology" data-tags="nation-state espionage phishing russia-nexus" data-regions="europe switzerland" data-kind="threat" data-priority="notable" data-discovered="2026-07-13T20:35:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="france-eu-turla-fsb-centre-16-attribution-french-victimology"><a href="https://ctipilot.ch/entries/2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology/">France and the EU attribute the Turla intrusion set to FSB Centre 16, with French victimology, TTPs and EU/UK sanctions</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions</a> <span class="mono muted">(2026-07-13)</span></p><p>The morning entry covered the 19-agency Static Tundra/Berserk Bear advisory (SNMP and Cisco Smart Install router hijacking) and the UK/EU attribution of the December 2025 Polish grid sabotage. This delta covers the <strong>sibling FSB Centre 16 cluster</strong> — Turla — which France and the EU formally attributed the same day. France&#39;s Cyber Crisis Coordination Centre (C4 — ANSSI, COMCYBER, DGA, DGSE, DGSI and the Ministry for Europe and Foreign Affairs) and the EU High Representative jointly attributed the Turla intrusion set to the FSB&#39;s 16th Centre on 2026-07-13, publishing CERT-FR&#39;s technical report CERTFR-2026-CTI-005 alongside formal French and EU attribution statements (<a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/" target="_blank" rel="noopener noreferrer">CERT-FR, 2026-07-13</a>; <a href="https://cyber.gouv.fr/actualites/ciblage-et-compromission-dentites-francaises-par-le-fsb/" target="_blank" rel="noopener noreferrer">ANSSI, 2026-07-13</a>). France&#39;s COMCYBER describes Turla as an FSB 16th Centre attack mode (<em>mode opératoire</em>) used for intelligence-gathering since at least 2004 (<a href="https://www.defense.gouv.fr/comcyber/actualites/ciblage-compromission-dentites-francaises-au-moyen-du-mode-du-mode-operatoire-dattaque-turla" target="_blank" rel="noopener noreferrer">COMCYBER, 2026-07-13</a>). The 16th Centre is the parent unit behind both this Turla/Secret Blizzard espionage set and the Static Tundra/Berserk Bear router-hijacking cluster covered this morning — the EU-sanctions reporting describes the 16th Centre as controlling groups including Turla (<a href="https://www.heise.de/en/news/EU-sanctions-Russia-for-serious-cyberattacks-and-sabotage-11363418.html" target="_blank" rel="noopener noreferrer">heise online, 2026-07-13</a>).</p>
<p>ANSSI documents French Turla victims including Ministry of Armed Forces webmail accounts compromised since 2017, the network of the French Embassy in Moscow (2018), a justice-sector personnel-training host (2019) and an advanced-technology company (2025), plus opportunistic intermediary compromises across varied sectors between 2019 and 2025 used as relay infrastructure (<a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/" target="_blank" rel="noopener noreferrer">CERT-FR, 2026-07-13</a>). The initial-access tradecraft combines spearphishing and watering-hole attacks that lure targets into downloading malicious files masquerading as legitimate software, plus exploitation of vulnerabilities in webmail/messaging services, browsers, business applications and web servers; the operators favour rented or previously-compromised infrastructure for camouflage (<a href="https://cyber.gouv.fr/actualites/ciblage-et-compromission-dentites-francaises-par-le-fsb/" target="_blank" rel="noopener noreferrer">ANSSI, 2026-07-13</a>). In coordination, the EU sanctioned 9 individuals and 4 organisations (entry bans and asset freezes), including the enabler firms Advanced System Technology (AST) and NPP Gamma, and the UK sanctioned 24 individuals and organisations; the EU Council statement names Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland among affected states (<a href="https://www.heise.de/en/news/EU-sanctions-Russia-for-serious-cyberattacks-and-sabotage-11363418.html" target="_blank" rel="noopener noreferrer">heise online, 2026-07-13</a>).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the operational surface for EU/Swiss government, diplomatic and defence entities is Turla&#39;s <em>access</em> tradecraft, not the diplomacy — hunt for trojanised &quot;legitimate software&quot; delivered via spearphishing or watering-holes, and for exploitation of exposed webmail, browser and web-server surfaces, which is where this set gets in. The relay-through-compromised-third-parties pattern (opportunistic intermediary victims used as infrastructure) means a Swiss or EU organisation may surface as <em>staging infrastructure</em> for onward targeting rather than as the final objective — outbound connections from your estate to other victims&#39; networks, and inbound access that pivots onward, are as much the signal as data leaving toward Russia.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Members of the Cyber Crisis Coordination Centre (C4) have observed the targeting and compromise of French entities using the Turla intrusion set operated by the 16th Centre of the Federal Security Service of the Russian Federation (FSB).</p><figcaption class="entry-cite__attr"><a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/" target="_blank" rel="noopener noreferrer">CERT-FR (ANSSI)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Russian technology companies supporting the intelligence service are also affected. For example, Advanced System Technology (AST) and NPP Gamma will no longer be allowed to do business in the EU in the future.</p><figcaption class="entry-cite__attr">heise online (citing EU Council statement)</figcaption></figure></div><div class="prov"><span>threat</span><span>13 Jul 20:35Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/france-eu-turla-fsb-centre-16-attribution-french-victimology/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-005/" target="_blank" rel="noopener noreferrer">CERT-FR (ANSSI)</a> · <a href="https://cyber.gouv.fr/actualites/ciblage-et-compromission-dentites-francaises-par-le-fsb/" target="_blank" rel="noopener noreferrer">ANSSI (cyber.gouv.fr)</a> · <a href="https://www.defense.gouv.fr/comcyber/actualites/ciblage-compromission-dentites-francaises-au-moyen-du-mode-du-mode-operatoire-dattaque-turla" target="_blank" rel="noopener noreferrer">Ministère des Armées / COMCYBER</a> · <a href="https://www.heise.de/en/news/EU-sanctions-Russia-for-serious-cyberattacks-and-sabotage-11363418.html" target="_blank" rel="noopener noreferrer">heise online</a></div></article>]]></content:encoded></item><item><title>19-agency advisory details FSB Centre 16 router hijacking via SNMP and Cisco Smart Install as the UK and EU attribute Poland&#39;s Dec-2025 grid sabotage</title><link>https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/</guid><pubDate>Mon, 13 Jul 2026 12:40:00 +0000</pubDate><dc:date>2026-07-13T12:40:00Z</dc:date><category>nation-state</category><category>espionage</category><category>actively-exploited</category><category>cisa-kev</category><category>wiper</category><category>law-enforcement</category><category>ot-ics</category><category>russia-nexus</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2018-0171</category><description><![CDATA[<p>A joint Cybersecurity Advisory from 19 agencies across 13 countries (2026-07-13) details how Russian FSB Centre 16 (Static Tundra / Berserk Bear) opportunistically compromises internet-facing routers across energy, government, telecom, finance and healthcare — chiefly by abusing default/weak SNMP community strings and the seven-year-old Cisco Smart Install flaw CVE-2018-0171 (CISA KEV) to exfiltrate device configurations. On the same day the UK and EU formally attributed the destructive 29 Dec 2025 attack on Poland&#39;s energy grid to this FSB unit and imposed their first joint cyber-sanctions package. Swiss and European critical-infrastructure operators running Cisco IOS/IOS XE or legacy SNMP on exposed network devices should treat router hygiene as an active-exploitation priority.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory" data-tags="nation-state espionage actively-exploited cisa-kev wiper law-enforcement ot-ics russia-nexus" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-07-13T12:40:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2018-0171/">CVE-2018-0171</a><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="fsb-centre-16-static-tundra-router-hijacking-advisory"><a href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions</a></h3><p><strong>Background.</strong> The FSB Centre 16 network-device cluster is not new — it has a decade-plus public record under the vendor labels Berserk Bear, Energetic Bear, Crouching Yeti, Dragonfly and Ghost Blizzard, and Cisco Talos profiled it in August 2025 as &quot;Static Tundra,&quot; documenting long-term compromise of unpatched and end-of-life network gear for configuration theft and persistent collection (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). What is new is a same-day trio of actions on 2026-07-13: a much fuller TTP disclosure, a formal government attribution of a destructive attack, and the first coordinated EU/UK cyber-sanctions package.</p>
<p>A joint Cybersecurity Advisory carrying 19 authoring and co-sealing agencies across 13 countries — NSA, CISA, FBI and DC3 (US) alongside the cyber and intelligence authorities of Australia, Canada, New Zealand, the UK, Czech Republic, Denmark, Estonia, Finland, France, Italy, Poland and Sweden — describes FSB Centre 16 opportunistically compromising poorly configured routers across communications, defense industrial base, energy, financial services, government (especially state/local), and healthcare sectors (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA/CISA/FBI joint advisory, 2026-07-13</a>; <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). The advisory notes these TTPs overlap with Salt Typhoon activity, so the hardening below counters more than one actor.</p>
<p>The primary access vector is not a novel exploit but weak SNMP hygiene. The actors scan internet IP ranges for SNMP agents that accept common or default community strings, then issue spoofed-source SNMP Set-Requests carrying object identifiers that instruct the device to copy its running configuration to a file (commonly <code>config.bkp</code> or <code>output.txt</code>) and transfer it, usually over TFTP, to a leased VPS or a compromised FTP server (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). The advisory names the exact OIDs abused — <code>1.3.6.1.4.1.9.9.96.1.1</code> (Cisco Config Copy) and <code>1.3.6.1.4.1.9.9.96.1.1.1.1.5</code> (the destination address for the copied config). A stolen configuration frequently discloses further credentials and additional community strings, feeding lateral movement. Talos&#39;s profile records the actor guessing or reusing insecure read-write community strings such as <code>public</code> and <code>anonymous</code> (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>). Secondarily — &quot;occasionally,&quot; per the advisory — the actors exploit known Cisco bugs and the Smart Install (SMI) feature, naming CVE-2018-0171 (the Smart Install pre-auth RCE, in CISA KEV since 2021) and CVE-2008-4128 (end-of-life devices only, no patch). Persistence has historically included the SYNful Knock IOS firmware implant.</p>
<p><strong>The Poland grid attribution.</strong> On the same day, the UK together with EU member states formally attributed the destructive 29 December 2025 attack on Poland&#39;s energy grid to FSB Centre 16 (<a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK, 2026-07-13</a>). CERT Polska&#39;s own incident report describes coordinated destructive activity against 30-plus wind and photovoltaic grid-connection substations — RTU, HMI and protection-relay firmware damaged or system files deleted — and a combined heat-and-power plant serving roughly half a million people, where wiper malware was blocked by the operator&#39;s EDR before detonation; CERT Polska tied the activity to the Static Tundra / Berserk Bear / Ghost Blizzard / Dragonfly cluster via VPS, router and anonymizing-infrastructure overlap and called it &quot;the first publicly described destructive activity attributed to this activity cluster&quot; (<a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-01-30</a>). Note the attribution is contested at the cluster-label level: earlier ESET reporting attributed the same DynoWiper attack to the GRU&#39;s Sandworm (<a href="https://www.bleepingcomputer.com/news/security/sandworm-hackers-linked-to-failed-wiper-attack-on-polands-energy-systems/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-01-24</a>), and the EU Council statement names FSB Centre 16 as the parent controlling several groups including Turla — so treat &quot;FSB Centre 16&quot; as an umbrella unit rather than a single team.</p>
<p>The sanctions package is the policy layer: the EU designated 9 individuals and 4 entities and the UK designated 24, covering senior GRU figures, the front company IMPULS accused of recruiting hackers for GRU Unit 29155, Lumma Stealer operators, and the disinformation outlet Rybar LLC (<a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government, 2026-07-13</a>; <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-13</a>).</p>
<p><strong>Detection.</strong> The telemetry classes to prioritise on network gear: network-flow and firewall logs for inbound SNMP Set-Requests (especially with spoofed or unfamiliar source addresses) and for outbound TFTP sessions initiated from a router/switch management interface to non-management destinations; device syslog and AAA/TACACS+ logs for unexpected &quot;config copy&quot; events, new local-account creation, and unexplained drops in logging volume — Talos documents the actor tampering with TACACS+ configuration to blind logging and standing up GRE tunnels to redirect victim traffic (<a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2025-08-20</a>); and IDS rules keyed to inbound SNMP Set-Requests carrying the config-copy OIDs above, as the advisory recommends (<a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">joint advisory, 2026-07-13</a>). Baseline NetFlow for the new GRE tunnel endpoints Talos describes.</p>
<p><strong>Defender takeaway.</strong> For a Swiss or European CI operator this is a router-hygiene mandate with a live destructive precedent next door. Disable Smart Install where it is not in active use, confirm CVE-2018-0171 is patched, migrate management SNMP to v3 with authPriv and disable SNMPv1/v2c (or, where legacy SNMP is unavoidable, replace every default/weak community string and enforce read-only), restrict all management protocols to known stations via out-of-band ACLs, use Cisco password hashing type 8 (never 0/4/7), and treat the device configuration held in your management system — not the device itself — as the source of truth so a tampered config is detectable.</p>
<p><strong>Triage:</strong> legitimate network-management stations poll SNMP on a predictable cadence from a known IP set, almost always read-only GET/GET-NEXT. The signal is a <em>write</em> (SNMP Set-Request) — particularly one carrying the config-copy OIDs — from a source outside the management range or with an inconsistent/spoofed source address, followed by an outbound TFTP transfer from the device; either alone is weak, the sequence config-write-then-TFTP-egress is the discriminator.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The actors scan for Internet IP ranges with active Simple Network Management Protocol (SNMP) agents that accept common or default community strings for authentication</p><figcaption class="entry-cite__attr"><a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The UK together with EU member states has also today formally attributed the December 2025 attack on Poland&#39;s energy grid to Russia&#39;s FSB Centre 16.</p><figcaption class="entry-cite__attr"><a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This is, however, the first publicly described destructive activity attributed to this activity cluster.</p><figcaption class="entry-cite__attr"><a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> <span class="entry-cite__date mono">2026-01-30</span></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">This reckless attack failed but could have caused 500,000 citizens to lose electricity in the depths of winter.</p><figcaption class="entry-cite__attr"><a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> <span class="entry-cite__date mono">2026-07-13</span></figcaption></figure></div><div class="prov"><span>threat</span><span>13 Jul 12:40Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.gov.uk/news/uk-and-allies-urge-critical-sectors-to-improve-defences-against-russian-intelligence-targeting" target="_blank" rel="noopener noreferrer">NCSC-UK</a> · <a href="https://media.defense.gov/2026/Jul/09/2003959498/-1/-1/1/CSA_IMPROVE_ROUTER_HYGIENE.PDF" target="_blank" rel="noopener noreferrer">NSA / CISA / FBI / DC3 joint Cybersecurity Advisory (19 agencies, 13 countries)</a> · <a href="https://www.gov.uk/government/news/uk-and-eu-strike-russian-cyber-networks-with-new-sanctions" target="_blank" rel="noopener noreferrer">UK Government (FCDO)</a> · <a href="https://cert.pl/en/posts/2026/01/incident-report-energy-sector-2025/" target="_blank" rel="noopener noreferrer">CERT Polska</a> · <a href="https://blog.talosintelligence.com/static-tundra/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://www.bleepingcomputer.com/news/security/eu-and-uk-hit-russia-with-first-joint-cyber-sanctions-package/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article>]]></content:encoded></item><item><title>CERT-PL: Ghostwriter/UNC1151 now phishes Gmail with a live 2FA-relay panel that defeats TOTP and SMS</title><link>https://ctipilot.ch/entries/2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing/</guid><pubDate>Thu, 09 Jul 2026 04:32:59 +0000</pubDate><dc:date>2026-07-09T04:32:59Z</dc:date><category>phishing</category><category>nation-state</category><category>identity</category><category>russia-nexus</category><category>europe</category><category>switzerland</category><category>dach</category><description><![CDATA[<p>CERT Polska reports that the Belarus-linked UNC1151/Ghostwriter group has, since March 2026, run a high-intensity Gmail phishing campaign against political and public-life figures, senior officials, researchers, journalists, and public-administration and law-enforcement staff. The fake login panel relays the second factor in real time — harvesting the password then requesting the TOTP/SMS code for an immediate automated login — defeating both app-based and SMS 2FA. Push FIDO2/WebAuthn for exposed EU/CH public-sector Gmail identities; TOTP and SMS are not sufficient against this design.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing" data-tags="phishing nation-state identity russia-nexus" data-regions="europe switzerland dach" data-kind="threat" data-priority="high" data-discovered="2026-07-09T04:32:59Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="unc1151-ghostwriter-gmail-realtime-2fa-phishing"><a href="https://ctipilot.ch/entries/2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing/">CERT Polska: UNC1151/Ghostwriter shifts to Gmail with real-time 2FA-relay phishing against officials and public administration</a></h3><p>CERT Polska (NASK) reports that <strong>UNC1151/Ghostwriter</strong> — the Belarus-linked cluster that for years phished Polish-provider webmail (Onet, WP, Interia) — has since March 2026 shifted at high, near-daily intensity to <strong>Gmail accounts</strong>, with new phishing domains appearing almost daily (<a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-07-08</a>). The lure imitates a Gmail security/administrator notice (&quot;suspicious activity&quot;, &quot;account may be blocked&quot;) written in error-free Polish and sent from purpose-created Gmail accounts or compromised mailboxes with a spoofed display name, frequently via BCC to obscure the target list. Targeting is broad — political and public-life figures, senior officials, researchers, journalists, public-administration and law-enforcement staff, and their family and social contacts — with some campaigns narrowed to specific professional groups such as translators and court experts.</p>
<p>The core technical escalation over prior campaigns is a <strong>real-time second-factor relay</strong>: after harvesting the password, the fake login panel displays a second form requesting the TOTP/SMS code, which the operators feed into an automated login against the real account, defeating both app-based (Google Authenticator) and SMS-based factors (<a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-07-08</a>). Infrastructure mixes dedicated phishing domains on <code>.icu</code>/<code>.digital</code>/<code>.top</code> TLDs with abuse of <code>*.netlify.app</code> subdomains, plus fake panels planted on compromised Polish websites whose main pages are left untouched to avoid tipping off the site owner. The initial lure maps to <code>T1566.002 Phishing: Spearphishing Link</code>; the live-relay capture is best described qualitatively (CERT Polska does not name specific AitM tooling).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">this is the same actor cluster tracked as <code>campaign:frostyneighbor-2026-05-campaign</code> (Poland/Lithuania/Ukraine), now with a Gmail-specific, 2FA-defeating tradecraft shift directly relevant to any EU/CH government, law-enforcement or public-administration workforce that uses Google identities. The operational consequence is concrete: TOTP and SMS OTP no longer bound the risk for high-value targets — only phishing-resistant, hardware-bound FIDO2/WebAuthn does. The strongest detection signal is not credential entry but the near-simultaneous automated login from an unfamiliar ASN immediately after a user touches a flagged phishing URL.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Since March 2026, however, the group has been running phishing campaigns targeting Gmail users. These campaigns are carried out with high intensity, mainly on weekdays. Notably, they enable the theft of two-factor authentication (2FA) credentials.</p><p class="entry-cite__quote">If a second factor is required, the phishing page displays an additional form requesting the code. This allows attackers to capture both SMS-based codes and those generated by applications such as Google Authenticator.</p><figcaption class="entry-cite__attr">CERT Polska</figcaption></figure></div><div class="prov"><span>threat</span><span>09 Jul 04:32Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska (NASK)</a></div></article>]]></content:encoded></item><item><title>CVE-2026-14439 — Altium Enterprise Server / Altium 365: authenticated path-traversal to RCE</title><link>https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/</guid><pubDate>Thu, 02 Jul 2026 04:55:21 +0000</pubDate><dc:date>2026-07-02T04:55:21Z</dc:date><category>vulnerabilities</category><category>rce</category><category>path-traversal</category><category>patch-available</category><category>europe</category><category>patch-available</category><category>CVE-2026-14439</category><description><![CDATA[<p>A CWE-22 path-traversal flaw (CVSS 9.4) in the Git Service component shared by Altium Enterprise Server and the Altium 365 SaaS platform (electronics CAD / PCB-design collaboration) lets an authenticated user with only basic git access chain a sequence of post-clone file-manipulation operations that accept …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic" data-tags="vulnerabilities rce path-traversal patch-available" data-regions="europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-02T04:55:21Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-14439/">CVE-2026-14439</a></div><h3 class="f-h" id="cve-2026-14439-altium-enterprise-server-altium-365-authentic"><a href="https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/">CVE-2026-14439 — Altium Enterprise Server / Altium 365: authenticated path-traversal to RCE</a></h3><p>A CWE-22 path-traversal flaw (CVSS 9.4) in the Git Service component shared by Altium Enterprise Server and the Altium 365 SaaS platform (electronics CAD / PCB-design collaboration) lets an authenticated user with only basic git access chain a sequence of post-clone file-manipulation operations that accept user-supplied paths without validation, moving arbitrary files outside the intended repository. Because moved files can land in locations later executed by the Git Service, the primitive escalates to remote code execution under the Git Service account; on multi-tenant Altium 365 the flaw could expose data belonging to other tenants sharing the same node (<a href="https://github.com/advisories/GHSA-m97g-7h77-r5pr" target="_blank" rel="noopener noreferrer">GitHub Security Advisory GHSA-m97g-7h77-r5pr, 2026-07-02</a>). Altium Enterprise Server is fixed in 8.1.1; Altium 365&#39;s shared multi-tenant deployments were remediated at the service level, with remaining deployments in progress. No exploitation reported. The low privilege bar plus cross-tenant SaaS exposure make this notable for CH/EU manufacturing and defence-industrial-base engineering firms; multi-tenant customers should confirm with Altium that their specific node received the service-level fix rather than assuming blanket coverage.</p><div class="prov"><span>vulnerability</span><span>02 Jul 04:55Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.com/advisories/GHSA-m97g-7h77-r5pr" target="_blank" rel="noopener noreferrer">GitHub Security Advisory GHSA-m97g-7h77-r5pr</a></div></article>]]></content:encoded></item><item><title>Kaspersky GReAT: ToddyCat&#39;s &quot;Umbrij&quot; automates Gmail/Workspace OAuth-token theft via Chromium remote-debugging abuse</title><link>https://ctipilot.ch/entries/2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace/</guid><pubDate>Wed, 01 Jul 2026 04:41:18 +0000</pubDate><dc:date>2026-07-01T04:41:18Z</dc:date><category>espionage</category><category>identity</category><category>cloud</category><category>china-nexus</category><category>global</category><description><![CDATA[<p>Kaspersky GReAT documented Umbrij, a .NET tool used by the ToddyCat APT that automates theft of Google Workspace OAuth tokens through a technique GReAT calls Shadow Token via Remote Debug (STRD) (Kaspersky Securelist, 2026-06-30).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace" data-tags="espionage identity cloud china-nexus" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-01T04:41:18Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace"><a href="https://ctipilot.ch/entries/2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace/">Kaspersky GReAT: ToddyCat&#39;s &quot;Umbrij&quot; automates Gmail/Workspace OAuth-token theft via Chromium remote-debugging abuse</a></h3><p>Kaspersky GReAT documented <strong>Umbrij</strong>, a .NET tool used by the ToddyCat APT that automates theft of Google Workspace OAuth tokens through a technique GReAT calls <strong>Shadow Token via Remote Debug (STRD)</strong> (<a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-06-30</a>). Umbrij copies the victim&#39;s existing Chromium profile (cached credentials, session cookies), relaunches the browser headless with the DevTools remote-debugging port enabled, and drives it via Puppeteer Sharp to silently replay a legitimate OAuth authorization-code flow against Google APIs — extracting the authorization code with no user interaction, then exchanging it server-side for access/refresh tokens. The requested scopes include <code>https://mail.google.com/</code> and <code>https://www.googleapis.com/auth/gmail.insert</code>. Prerequisites are on-host code execution plus an already-authenticated Gmail/Workspace browser session; no separate phishing step. Umbrij loads via DLL search-order hijacking (<code>T1574.001</code>) through signed legitimate binaries — <code>BDSubWiz.exe</code> (a Bitdefender ConnectAgent component, loading <code>log.dll</code>), <code>VSTestVideoRecorder.exe</code> (a Visual Studio testing tool), and the discontinued <code>GoogleDesktop.exe</code> (loading <code>GoogleServices.dll</code>). Because it operates inside a standard browser-automation framework rather than touching credential stores directly, it evades detection tuned to credential-store access; Securelist maps the access-token stages to <code>T1550.001</code> (Use Application Access Token) and <code>T1134.003</code> (Access Token Manipulation: Make and Impersonate Token). <strong>[SINGLE-SOURCE]</strong> — Kaspersky is the sole publisher. Detection concepts: alert on Chromium/Edge launched with <code>--remote-debugging-port</code> (and <code>--headless</code>) from non-browser parents such as <code>BDSubWiz.exe</code>, <code>VSTestVideoRecorder.exe</code> or <code>GoogleDesktop.exe</code>; watch Workspace admin logs for OAuth token issuance to unexpected client IDs. Hardening: enforce Chrome Enterprise <code>DeveloperToolsAvailability=Disabled</code> where remote debugging isn&#39;t needed, and review OAuth app grants.</p><div class="prov"><span>research</span><span>01 Jul 04:41Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist / GReAT</a></div></article>]]></content:encoded></item><item><title>US posts $10M bounty on the Russia-nexus Signal/WhatsApp crews and adds Signal Backup-Recovery-Key theft to the advisory</title><link>https://ctipilot.ch/entries/2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew/</guid><pubDate>Tue, 30 Jun 2026 05:10:43 +0000</pubDate><dc:date>2026-06-30T05:10:43Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>phishing</category><category>identity</category><category>europe</category><category>global</category><description><![CDATA[<p>UPDATE (originally covered 2026-06-27): The US Department of State&#39;s Rewards for Justice program posted a $10 million reward on 2026-06-29 for information on members of UNC5792 (assessed associated with Russia&#39;s FSB) and UNC4221 (assessed associated with the GRU), and the FBI/CISA advisory was updated with a newly …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew" data-tags="nation-state espionage russia-nexus phishing identity" data-regions="europe global" data-kind="threat" data-priority="notable" data-discovered="2026-06-30T05:10:43Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span></div><h3 class="f-h" id="us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew"><a href="https://ctipilot.ch/entries/2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew/">US posts $10M bounty on the Russia-nexus Signal/WhatsApp crews and adds Signal Backup-Recovery-Key theft to the advisory</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-27/fbi-cisa-russian-intelligence-now-phishing-signal-backup-rec/">FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover</a> <span class="mono muted">(2026-06-27)</span></p><p>The US Department of State&#39;s Rewards for Justice program posted a $10 million reward on 2026-06-29 for information on members of UNC5792 (assessed associated with Russia&#39;s FSB) and UNC4221 (assessed associated with the GRU), and the FBI/CISA advisory was updated with a newly observed tactic — theft of Signal <strong>Backup Recovery Keys</strong> (<a href="https://rewardsforjustice.net/rewards/unc5792/" target="_blank" rel="noopener noreferrer">Rewards for Justice, 2026-06-29</a> · <a href="https://www.bleepingcomputer.com/news/security/us-offers-10-million-for-hackers-targeting-whatsapp-signal-users/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-29</a>).</p>
<p>The recovery-key tactic is the operationally material change: a stolen backup recovery key is persistent — even after the victim rotates their phone number or reinstalls, the attacker can restore the full message backup, including prior history and group content, so access survives the initial social-engineering window (<a href="https://www.securityweek.com/us-offers-10-million-bounty-for-russian-state-hackers-as-messaging-app-attacks-evolve/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-29</a>). Targets are current/former government and military officials, political figures, journalists, and Ukraine-based officials across Europe and the US. Swiss federal and cantonal officials using Signal should treat backup-recovery-key protection (and re-checking the NCSC-CH Signal guidance covered 2026-06-25) as an action item, not a watch item.</p><div class="prov"><span>threat</span><span>30 Jun 05:10Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://rewardsforjustice.net/rewards/unc5792/" target="_blank" rel="noopener noreferrer">Rewards for Justice</a> · <a href="https://www.bleepingcomputer.com/news/security/us-offers-10-million-for-hackers-targeting-whatsapp-signal-users/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.securityweek.com/us-offers-10-million-bounty-for-russian-state-hackers-as-messaging-app-attacks-evolve/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article>]]></content:encoded></item><item><title>FortiBleed</title><link>https://ctipilot.ch/entries/2026-06-29/fortibleed/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/fortibleed/</guid><pubDate>Mon, 29 Jun 2026 00:21:19 +0000</pubDate><dc:date>2026-06-29T00:21:19Z</dc:date><category>actively-exploited</category><category>data-breach</category><category>identity</category><category>russia-nexus</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p>FortiBleed escalates from credential exposure to confirmed AD domain takeover at a NATO-aligned defence contractor — patch level is irrelevant; rotate any FortiGate credential active May–June and hunt AD persistence. (daily 06-24, CISA)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/fortibleed" data-tags="actively-exploited data-breach identity russia-nexus" data-regions="global europe switzerland" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:21:19Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="fortibleed"><a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">FortiBleed</a></h3><p>The W25 top story continued without a scale revision — the device count holds at the 86,644 figure the dailies reported — but the in-window development is the clearest state-interest signal yet: CISA <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-of-credential-exposure" target="_blank" rel="noopener noreferrer">updated its hardening alert on 06-22</a> to link Fortinet&#39;s revised guidance, and reporting now confirms that on in mid-June the Russian-speaking operator completed offline Kerberos-hash cracking from captured FortiGate configs and immediately exfiltrated DFS backup data from a NATO-aligned defence contractor — a full AD domain takeover (<a href="https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html" target="_blank" rel="noopener noreferrer">Security Affairs</a>). Outstanding for defenders: treat any FortiGate admin/VPN credential active May–June 2026 as compromised, rotate, then hunt AD for pass-the-hash, DCSync and DFS-backup exfiltration (Kerberos ticket anomalies, LSASS access, <code>ntdsutil</code>/impacket artefacts). Patch level is irrelevant — this is credential reuse, not a new CVE.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-of-credential-exposure" target="_blank" rel="noopener noreferrer">CISA alert</a> · <a href="https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html" target="_blank" rel="noopener noreferrer">Security Affairs</a></div></article>]]></content:encoded></item><item><title>ESET Gamaredon 2025 — annual actor retrospective</title><link>https://ctipilot.ch/entries/2026-06-29/eset-gamaredon-2025-annual-actor-retrospective/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/eset-gamaredon-2025-annual-actor-retrospective/</guid><pubDate>Mon, 29 Jun 2026 00:21:18 +0000</pubDate><dc:date>2026-06-29T00:21:18Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>europe</category><description><![CDATA[<p>Background. Gamaredon (FSB-linked, Russia-nexus) has been ESET&#39;s most-tracked Ukraine-focused operator for years; its prior annual papers documented a high-tempo, PowerShell-heavy toolset and aggressive infrastructure churn.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/eset-gamaredon-2025-annual-actor-retrospective" data-tags="nation-state espionage russia-nexus" data-regions="europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-29T00:21:18Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eset-gamaredon-2025-annual-actor-retrospective"><a href="https://ctipilot.ch/entries/2026-06-29/eset-gamaredon-2025-annual-actor-retrospective/">ESET Gamaredon 2025 — annual actor retrospective</a></h3><p><strong>Background.</strong> Gamaredon (FSB-linked, Russia-nexus) has been ESET&#39;s most-tracked Ukraine-focused operator for years; its prior annual papers documented a high-tempo, PowerShell-heavy toolset and aggressive infrastructure churn.</p>
<p>ESET&#39;s <a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/" target="_blank" rel="noopener noreferrer">2025 Gamaredon paper</a> (covered 06-26) documents six new PowerShell tools and the wholesale migration of exfiltration and C2 onto trusted cloud services, tunnels and &quot;workers&quot; — the horizon implication for European public-sector defenders is detection-oriented: Gamaredon-class C2 increasingly hides inside legitimate cloud-service traffic (Cloudflare workers, Telegram, dead-drop resolvers), so network-indicator blocking degrades and behavioural detection on the endpoint and on anomalous cloud-service egress becomes the durable control.</p><div class="prov"><span>annual-report</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/eset-gamaredon-2025-annual-actor-retrospective/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.sekoia.com/blog/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel" target="_blank" rel="noopener noreferrer">Sekoia</a></div></article>]]></content:encoded></item><item><title>Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters</title><link>https://ctipilot.ch/entries/2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne/</guid><pubDate>Mon, 29 Jun 2026 00:21:15 +0000</pubDate><dc:date>2026-06-29T00:21:15Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>china-nexus</category><category>north-korea-nexus</category><category>europe</category><category>switzerland</category><category>apac</category><category>global</category><description><![CDATA[<p>Turla&#39;s new STOCKSTAY backdoor (GTIG) broadens Russia-nexus espionage toward Western-European foreign-policy targets — delivered via WinRAR CVE-2025-8088 and malicious RDP files; relevant to Swiss/EU governmental entities with Ukraine-adjacent policy work. (daily 06-26, Google GTIG)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne" data-tags="nation-state espionage russia-nexus china-nexus north-korea-nexus" data-regions="europe switzerland apac global" data-kind="research" data-priority="high" data-discovered="2026-06-29T00:21:15Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="threat-actor-developments-russia-nexus-espionage-broadens-ne"><a href="https://ctipilot.ch/entries/2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne/">Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters</a></h3><p>The most significant new actor finding the dailies did not carry is Turla&#39;s <strong>STOCKSTAY</strong> — Google GTIG <a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering" target="_blank" rel="noopener noreferrer">characterised</a> a multi-component .NET/Windows Forms backdoor that communicates C2 over secure WebSocket and shares significant code overlap with Kazuar (Turla&#39;s staple implant since 2017). Delivery used malicious RDP files by phishing and, as recently as November 2025, RAR archives exploiting WinRAR&#39;s CVE-2025-8088 (a flaw also abused by Sandworm, Gamaredon and RomCom). Current targeting is Ukrainian government and military, but earlier victims had Italian, Dutch, Polish and German foreign-policy interest — a direct read-across for Swiss federal and European governmental entities with Ukraine-adjacent policy work (<a href="https://thehackernews.com/2026/06/google-details-turlas-new-stockstay.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>). This sits alongside the week&#39;s other Russia-nexus signal: FBI/CISA escalated their warning that Russian intelligence (tracked as UNC5792) is now <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noopener noreferrer">phishing Signal Backup Recovery Keys</a> for persistent account takeover, and ESET&#39;s Gamaredon retrospective (§ 7) shows the FSB-linked group moving exfil and C2 wholesale onto trusted cloud services.</p>
<p>Two non-Russian clusters round out the picture. Unit 42 documented <strong>CL-STA-1062</strong>, a Chinese-speaking cluster (overlapping Talos&#39;s UAT-7237) deploying the new TinyRCT .NET backdoor via AppDomainManager injection against Southeast-Asian government and state-owned energy targets (<a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/" target="_blank" rel="noopener noreferrer">Unit 42</a>); Kaspersky GReAT analysed the <strong>StrikeShark</strong> cluster&#39;s SharkLoader deploying Cobalt Strike via &quot;Perfect DLL Hijacking&quot; against government targets (<a href="https://securelist.com/strikeshark-campaign/120326/" target="_blank" rel="noopener noreferrer">Securelist</a>). And SentinelLABS&#39; <strong>macOS.Gaslight</strong>, a DPRK-aligned Rust backdoor, notably turns prompt injection on the LLM-assisted analyst rather than the sandbox (<a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/" target="_blank" rel="noopener noreferrer">SentinelLABS</a>) — an early instance of tradecraft built specifically to poison AI-assisted triage. Attribute the claim to the research outfit, not the state, where the source itself hedges.</p><div class="prov"><span>research</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering" target="_blank" rel="noopener noreferrer">Google GTIG — STOCKSTAY</a> · <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noopener noreferrer">FBI IC3 PSA I-062626-PSA</a> · <a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/" target="_blank" rel="noopener noreferrer">Unit 42 — CL-STA-1062</a></div></article>]]></content:encoded></item><item><title>CVE-2026-12569 — PTC Windchill / FlexPLM: pre-auth deserialization RCE, now confirmed exploited with JSP web shells (CISA KEV)</title><link>https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/</guid><pubDate>Mon, 29 Jun 2026 00:20:58 +0000</pubDate><dc:date>2026-06-29T00:20:58Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>rce</category><category>pre-auth</category><category>cisa-kev</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-12569</category><description><![CDATA[<p>When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours. The in-window delta: CISA added it to KEV on 06-25 and JSP web-shell deployment against the login interface is now confirmed in the wild.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio" data-tags="vulnerabilities actively-exploited rce pre-auth cisa-kev" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:20:58Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12569/">CVE-2026-12569</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">CVE-2026-12569 — PTC Windchill / FlexPLM: pre-auth deserialization RCE, now confirmed exploited with JSP web shells (CISA KEV)</a></h3><p>When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours. The in-window delta: CISA <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html" target="_blank" rel="noopener noreferrer">added it to KEV on 06-25</a> and JSP web-shell deployment against the login interface is now confirmed in the wild. Any internet-reachable Windchill PDMLink or FlexPLM instance should be treated as assume-compromise — manufacturing and defence-supplier PLM is exactly the externally-reachable engineering surface a Swiss/EU industrial estate forgets to inventory.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-37831" target="_blank" rel="noopener noreferrer">ENISA EUVD EUVD-2026-37831</a></div></article>]]></content:encoded></item><item><title>Turla&#39;s STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection</title><link>https://ctipilot.ch/entries/2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat/</guid><pubDate>Sat, 27 Jun 2026 05:17:52 +0000</pubDate><dc:date>2026-06-27T05:17:52Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>europe</category><category>switzerland</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2025-8088</category><description><![CDATA[<p>Background. Google Threat Intelligence Group (GTIG, formerly Mandiant) published a full technical analysis of STOCKSTAY on 2026-06-25, a modular .NET backdoor it attributes with high confidence to Turla — also tracked as Secret Blizzard, SUMMIT and FSB Center 16 — with activity dating to December 2022 (Google …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat" data-tags="nation-state espionage russia-nexus" data-regions="europe switzerland global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-27T05:17:52Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-8088/">CVE-2025-8088</a><span class="b exp">exploited</span></div><h3 class="f-h" id="turla-s-stockstay-a-four-component-net-backdoor-for-diplomat"><a href="https://ctipilot.ch/entries/2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat/">Turla&#39;s STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection</a></h3><p><strong>Background.</strong> Google Threat Intelligence Group (GTIG, formerly Mandiant) published a full technical analysis of STOCKSTAY on 2026-06-25, a modular .NET backdoor it attributes with high confidence to <strong>Turla</strong> — also tracked as Secret Blizzard, SUMMIT and FSB Center 16 — with activity dating to December 2022 (<a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering" target="_blank" rel="noopener noreferrer">Google Cloud / GTIG, 2026-06-25</a>). GTIG ties STOCKSTAY to Turla&#39;s long-running <strong>Kazuar</strong> implant lineage through shared code: the <code>K1MORPHER</code> Squirrel3-based string obfuscator Turla introduced in April 2025, identical environmental-keying logic, and the same component-separation design pattern — placing this tool in the same toolset GTIG and others have tracked across European diplomatic targeting for years (<a href="https://therecord.media/russia-turla-espionage-ukraine-stockstay-malware" target="_blank" rel="noopener noreferrer">The Record, 2026-06-26</a>). Primary targets are Ukrainian government and military organisations and European entities with Italian foreign-policy interests.</p>
<p><strong>Architecture and mechanics.</strong> STOCKSTAY is partitioned into four .NET assemblies that communicate over Windows <code>WM_COPYDATA</code> inter-process messages, deliberately decoupling the network layer from command execution. <code>MARKETMAKER</code> is the downloader/installer that establishes Registry Run-key persistence masquerading as <code>MicrosoftUpdateOneDrive</code> (<a href="https://attack.mitre.org/techniques/T1547/001/" target="_blank" rel="noopener noreferrer"><code>T1547.001</code></a>); <code>STOCKMARKET</code> (&quot;cor&quot;) is the orchestrator that generates a 4096-bit RSA key pair on first run; <code>STOCKBROKER</code> (&quot;net&quot;) is a proxy-aware WebSocket tunneller built on the open-source <code>websocket-sharp</code> library; and <code>STOCKTRADER</code> (&quot;sys&quot;) is the backdoor executor supporting 13 commands (directory listing, file get/put, process execution, registry read/write/delete, screenshot capture, WMI-based system reconnaissance, archive unpacking, and self-destruct). Configuration is AES-encrypted using hostname/domain-name <strong>environmental keying</strong> (<a href="https://attack.mitre.org/techniques/T1480/" target="_blank" rel="noopener noreferrer"><code>T1480</code></a>) once past the reconnaissance phase, so the payload will not decrypt or execute off-target — a standard Turla anti-analysis measure.</p>
<p><strong>Command-and-control.</strong> C2 responses are wrapped in an RSA-4096-encrypted &quot;CryptoContainer&quot; JSON structure and tunnelled over encrypted WebSocket sessions hosted on <strong>legitimate PaaS platforms (Render.com, Glitch)</strong> (<a href="https://attack.mitre.org/techniques/T1071/001/" target="_blank" rel="noopener noreferrer"><code>T1071.001</code></a>). The controller — a Python Tornado WebSocket server storing victim data in a SQLite database — was found in a public GitHub repository, and the use of third-party PaaS prevents the platform operator from introspecting the encrypted traffic. The implant enforces working hours (09:00–18:00, Mon–Fri) to blend with normal activity.</p>
<p><strong>Delivery / kill chain.</strong> Initial access is via spearphishing (<a href="https://attack.mitre.org/techniques/T1566/" target="_blank" rel="noopener noreferrer"><code>T1566.001</code>/<code>.002</code></a>) using diplomatic-themed lures (drone content, military logistics, diplomatic-education platforms), with malicious RDP configuration files and RAR archives exploiting <strong>WinRAR path traversal <code>CVE-2025-8088</code></strong> for code drop, followed by MSI/HTA execution. STOCKSTAY is then installed, keys to its environment, establishes Run-key persistence, and beacons out over PaaS-hosted WebSockets — staging the operator&#39;s interactive command set (<code>T1059</code>) for collection (<code>T1005</code>) and exfiltration over the C2 channel (<a href="https://attack.mitre.org/techniques/T1041/" target="_blank" rel="noopener noreferrer"><code>T1041</code></a>). GTIG notes deployment alongside other confirmed Turla tools (<code>WILDDAY</code>, <code>DIAMONDBACK</code>).</p>
<p><strong>Detection concepts (no IOCs).</strong> Alert on outbound WebSocket connections to <code>*.onrender.com</code> / <code>*.glitch.me</code> from non-browser processes; <code>WM_COPYDATA</code> messages between unrelated processes in EDR telemetry (Sysmon EID 8/10 process-injection/access correlation); Registry Run-key creation pointing at user-space paths masquerading as Microsoft/OneDrive updaters (Sysmon EID 13 / Windows EID 4657); LNK or RDP-config writes into staging directories (Sysmon EID 11); and the WinRAR <code>CVE-2025-8088</code> exploitation pattern (archive extraction writing files outside the target directory). GTIG published YARA and Google SecOps detection rules with the report.</p>
<p><strong>Hardening / mitigation.</strong> Patch WinRAR to 7.11+ to close <code>CVE-2025-8088</code>; enable AMSI and ETW for .NET assemblies and block the AppDomainManager-hijack DLL-placement path; apply GPO to restrict RDP-config auto-connection; and where not operationally required, block Render/Glitch WebSocket egress at the perimeter for diplomat and ministry workstations. For Swiss federal and cantonal foreign-affairs, defence and diplomatic environments, the named Italian-foreign-policy targeting puts this squarely in scope.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Background.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>27 Jun 05:17Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-27/turla-s-stockstay-a-four-component-net-backdoor-for-diplomat/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering" target="_blank" rel="noopener noreferrer">Google Cloud / GTIG</a> · <a href="https://therecord.media/russia-turla-espionage-ukraine-stockstay-malware" target="_blank" rel="noopener noreferrer">The Record</a> · <a href="https://thehackernews.com/2026/06/google-details-turlas-new-stockstay.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>PTC Windchill CVE-2026-12569 now confirmed exploited in the wild with JSP web shells</title><link>https://ctipilot.ch/entries/2026-06-27/ptc-windchill-cve-2026-12569-now-confirmed-exploited-in-the/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-27/ptc-windchill-cve-2026-12569-now-confirmed-exploited-in-the/</guid><pubDate>Sat, 27 Jun 2026 05:17:47 +0000</pubDate><dc:date>2026-06-27T05:17:47Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>rce</category><category>pre-auth</category><category>cisa-kev</category><category>global</category><category>europe</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2026-12569</category><description><![CDATA[<p>PTC Windchill RCE is now CISA-confirmed exploited. CVE-2026-12569 was added to the KEV catalog with JSP web shells observed in the wild; patch and hunt /Windchill/login/*.jsp (The Hacker News, 2026-06-26).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-27/ptc-windchill-cve-2026-12569-now-confirmed-exploited-in-the" data-tags="vulnerabilities actively-exploited rce pre-auth cisa-kev" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-06-27T05:17:47Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12569/">CVE-2026-12569</a><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="ptc-windchill-cve-2026-12569-now-confirmed-exploited-in-the"><a href="https://ctipilot.ch/entries/2026-06-27/ptc-windchill-cve-2026-12569-now-confirmed-exploited-in-the/">PTC Windchill CVE-2026-12569 now confirmed exploited in the wild with JSP web shells</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ/">PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane</a> <span class="mono muted">(2026-06-20)</span></p><p>CISA added the PTC Windchill PDMLink / FlexPLM pre-auth deserialization RCE (<code>CVE-2026-12569</code>) to its Known Exploited Vulnerabilities catalog on 2026-06-25, confirming active in-the-wild exploitation — the operational shift from the disclosure we deep-dived on June 20 (<a href="https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-26</a>).</p>
<p>Reported post-exploitation deploys JSP web shells to <code>/Windchill/login/&lt;16-hex&gt;.jsp</code> plus a <code>flst.txt</code> persistence marker — concrete hunt artefacts beyond the earlier abstract RCE description. ENISA&#39;s EUVD entry corroborates the unauthenticated deserialization root cause (<a href="https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-37831" target="_blank" rel="noopener noreferrer">ENISA EUVD EUVD-2026-37831</a>). The driver for Swiss/EU manufacturing, pharma and aerospace operators running Windchill is the confirmed exploitation and the web-shell pattern, not the US-only federal remediation date; patch per PTC CS473270 and hunt web-server logs for <code>.jsp</code> creation under <code>/Windchill/login/</code>.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">UPDATE (originally covered 2026-06-20): CISA added the PTC Windchill PDMLink / FlexPLM pre-auth deserialization RCE (CVE-2026-12569) to its Known Exploited Vulnerabilities catalog on 2026-06-25, confirming active in-the-wild exploitation — the operational shift from the disclosure we deep-dived on …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>27 Jun 05:17Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-27/ptc-windchill-cve-2026-12569-now-confirmed-exploited-in-the/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-37831" target="_blank" rel="noopener noreferrer">ENISA EUVD EUVD-2026-37831</a></div></article>]]></content:encoded></item><item><title>Kaspersky GReAT: &quot;StrikeShark&quot; loader deploys Cobalt Strike via &quot;Perfect DLL Hijacking&quot; against government targets</title><link>https://ctipilot.ch/entries/2026-06-27/kaspersky-great-strikeshark-loader-deploys-cobalt-strike-via/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-27/kaspersky-great-strikeshark-loader-deploys-cobalt-strike-via/</guid><pubDate>Sat, 27 Jun 2026 05:17:43 +0000</pubDate><dc:date>2026-06-27T05:17:43Z</dc:date><category>espionage</category><category>nation-state</category><category>china-nexus</category><category>global</category><category>europe</category><description><![CDATA[<p>Kaspersky GReAT published a full technical analysis (2026-06-26) of SharkLoader, an undocumented loader used in a cluster it tracks as StrikeShark and assesses with low confidence as a Chinese-speaking actor (based on the Chinese-authored FScan/Searchall/Pillager toolkit it deploys) (Kaspersky …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-27/kaspersky-great-strikeshark-loader-deploys-cobalt-strike-via" data-tags="espionage nation-state china-nexus" data-regions="global europe" data-kind="research" data-priority="notable" data-discovered="2026-06-27T05:17:43Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="kaspersky-great-strikeshark-loader-deploys-cobalt-strike-via"><a href="https://ctipilot.ch/entries/2026-06-27/kaspersky-great-strikeshark-loader-deploys-cobalt-strike-via/">Kaspersky GReAT: &quot;StrikeShark&quot; loader deploys Cobalt Strike via &quot;Perfect DLL Hijacking&quot; against government targets</a></h3><p>Kaspersky GReAT published a full technical analysis (2026-06-26) of <strong>SharkLoader</strong>, an undocumented loader used in a cluster it tracks as <strong>StrikeShark</strong> and assesses with <em>low confidence</em> as a Chinese-speaking actor (based on the Chinese-authored <code>FScan</code>/<code>Searchall</code>/<code>Pillager</code> toolkit it deploys) (<a href="https://securelist.com/strikeshark-campaign/120326/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-06-24</a>). The loader&#39;s signature is &quot;Perfect DLL Hijacking&quot;: it sideloads through legitimate signed binaries (<code>SystemSettings.exe</code>, <code>msedge.exe</code>), then forcibly releases <code>LdrpLoaderLock</code> and decrements <code>LdrpWorkInProgress</code> so it can spawn threads from <code>DllMain</code> without deadlocking the Windows loader — an unusually sophisticated pattern. Two encrypted modules (<code>DscCoreR.mui</code>, Blowfish; <code>SyncRes.dat</code>, AES-128) install Microsoft Detours hooks across 50+ APIs to null ETW (<code>EtwEventWrite</code>), spoof <code>svchost.exe</code> as parent PID (<code>T1134.004</code>), and demote Beacon memory from RWX to RW during sleep via MinHook on <code>VirtualAlloc</code>/<code>Sleep</code> to evade memory scanners (<a href="https://www.helpnetsecurity.com/2026/06/26/sharkloader-dropper-governments-software-developers/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-06-26</a>). Initial access is via a long list of public-facing RCEs (ProxyLogon <code>CVE-2021-26855</code>, Openfire <code>CVE-2023-32315</code>, GeoServer <code>CVE-2024-36401</code>, F5 BIG-IP <code>CVE-2023-46747</code>, FortiOS <code>CVE-2024-21762</code>), with European targets including North Macedonia and Serbia.
<strong>Why it matters to us:</strong> Swiss/EU organisations still exposed on any of the listed CVE versions are in the initial-access set. Hunt for <code>SystemSettings.exe</code> executing from <code>%APPDATA%</code> subdirectories, <code>PrintDialog.dll</code> loaded outside <code>system32</code> (Sysmon EID 7), and processes whose ETW subsystem produces zero events.</p><div class="prov"><span>research</span><span>27 Jun 05:17Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-27/kaspersky-great-strikeshark-loader-deploys-cobalt-strike-via/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/strikeshark-campaign/120326/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist (GReAT)</a> · <a href="https://www.helpnetsecurity.com/2026/06/26/sharkloader-dropper-governments-software-developers/" target="_blank" rel="noopener noreferrer">Help Net Security</a></div></article>]]></content:encoded></item><item><title>FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover</title><link>https://ctipilot.ch/entries/2026-06-27/fbi-cisa-russian-intelligence-now-phishing-signal-backup-rec/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-27/fbi-cisa-russian-intelligence-now-phishing-signal-backup-rec/</guid><pubDate>Sat, 27 Jun 2026 05:17:38 +0000</pubDate><dc:date>2026-06-27T05:17:38Z</dc:date><category>nation-state</category><category>espionage</category><category>phishing</category><category>identity</category><category>mobile</category><category>russia-nexus</category><category>global</category><category>europe</category><category>switzerland</category><description><![CDATA[<p><strong>Russian intelligence now phishes Signal Backup Recovery Keys.</strong> FBI/CISA say UNC5792/UNC4221 elicit the 30-character backup key for persistent account takeover that survives re-registration on the same number; regenerate keys for high-risk staff (FBI IC3, 2026-06-26).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-27/fbi-cisa-russian-intelligence-now-phishing-signal-backup-rec" data-tags="nation-state espionage phishing identity mobile russia-nexus" data-regions="global europe switzerland" data-kind="threat" data-priority="high" data-discovered="2026-06-27T05:17:38Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="fbi-cisa-russian-intelligence-now-phishing-signal-backup-rec"><a href="https://ctipilot.ch/entries/2026-06-27/fbi-cisa-russian-intelligence-now-phishing-signal-backup-rec/">FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover</a></h3><p>The FBI and CISA issued an updated joint advisory (PSA I-062626-PSA, 2026-06-26) escalating their March 2026 warning about Russian Intelligence Services operators tracked as <strong>UNC5792</strong> (FSB-linked) and <strong>UNC4221</strong> (military-linked) (<a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noopener noreferrer">FBI IC3, 2026-06-26</a>). The new tactic abuses Signal&#39;s optional encrypted-backup feature rather than any flaw in the Signal Protocol: operators impersonate Signal support, walk the target through <em>Settings → Chats → Chat Backups</em>, then elicit the 30-character <strong>Backup Recovery Key</strong>. With that key an attacker can download and decrypt the complete private and group message history offline. Critically, the advisory states the compromised key remains valid <em>even if the victim later re-registers a new account on the same phone number</em> — generating a new key in Settings invalidates future downloads but does not undo data already exfiltrated (<a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noopener noreferrer">FBI IC3, 2026-06-26</a>). Stated targets are current and former government officials, military personnel, political figures, journalists, and Ukraine-related officials. This is <code>T1598.003</code> (spearphishing via service) leading to <code>T1078</code> (valid-account takeover via the backup mechanism), with no platform-layer sensor — detection relies on user reporting and MDM telemetry for backup-enable events.
<strong>Why it matters to us:</strong> Swiss federal, cantonal-police, and parliamentary staff using Signal for sensitive coordination sit squarely in the named target population. Issue policy now: high-risk personnel should regenerate their Signal Backup Recovery Key, treat any unsolicited &quot;Signal support&quot; message as hostile, and on managed devices disable Signal backups via MDM where operational security requires it.</p><div class="prov"><span>threat</span><span>27 Jun 05:17Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-27/fbi-cisa-russian-intelligence-now-phishing-signal-backup-rec/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noopener noreferrer">FBI IC3 PSA I-062626-PSA</a> · <a href="https://thehackernews.com/2026/06/fbi-warns-russian-intelligence-hackers.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>ESET&#39;s 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)</title><link>https://ctipilot.ch/entries/2026-06-26/eset-s-2025-gamaredon-paper-exfil-and-c2-moved-wholesale-ont/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-26/eset-s-2025-gamaredon-paper-exfil-and-c2-moved-wholesale-ont/</guid><pubDate>Fri, 26 Jun 2026 04:54:41 +0000</pubDate><dc:date>2026-06-26T04:54:41Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>europe</category><description><![CDATA[<p>ESET&#39;s 2025 Gamaredon paper shows the FSB group&#39;s exfil and C2 moving entirely onto trusted cloud services — S3-compatible object storage (Wasabi/Tebi/Intercolo) via rclone and Cloudflare-tunnel/Workers/DevTunnel C2 that blends with legitimate egress; targeting stayed exclusively Ukrainian, but the tradecraft is the transferable part (ESET, 2026-06-25).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-26/eset-s-2025-gamaredon-paper-exfil-and-c2-moved-wholesale-ont" data-tags="nation-state espionage russia-nexus" data-regions="europe" data-kind="annual-report" data-priority="high" data-discovered="2026-06-26T04:54:41Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="eset-s-2025-gamaredon-paper-exfil-and-c2-moved-wholesale-ont"><a href="https://ctipilot.ch/entries/2026-06-26/eset-s-2025-gamaredon-paper-exfil-and-c2-moved-wholesale-ont/">ESET&#39;s 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)</a></h3><p>ESET&#39;s annual Gamaredon paper documents the FSB-linked group&#39;s 2025 toolset — six new PowerShell tools (PteroDee, PteroCache, PteroDum, PteroOdd, PteroEffigy, PteroPaste) plus a resurrected PteroSetup VBScript weaponizer — and, more usefully for defenders elsewhere, a wholesale shift of infrastructure onto trusted services (<a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/" target="_blank" rel="noopener noreferrer">ESET, 2026-06-25</a>). C2 now rides Cloudflare tunnels (<code>trycloudflare.com</code>), Cloudflare Workers (<code>workers.dev</code>), Microsoft DevTunnels (<code>devtunnels.ms</code>), Loophole, No-IP DDNS, Clever Cloud and Supabase; data is exfiltrated via <code>rclone</code> to S3-compatible object storage (Wasabi, Tebi, and Intercolo — which became the primary destination by December), and hostnames are brokered through dead-drop resolvers spread across Telegram, Telegra.ph, Dropbox, GoFile, Mastodon and a dozen paste services so no fixed IP or domain appears in the implant. ESET also confirms an early-2025 collaboration with Turla. Sekoia independently documented the same 2025 shift toward tunnel-service C2 and S3-compatible cloud-storage exfiltration in its parallel &quot;FSB&#39;s Matryoshka&quot; Gamaredon series (<a href="https://www.sekoia.com/blog/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel" target="_blank" rel="noopener noreferrer">Sekoia, 2026-06-04</a>). Targeting stayed <strong>exclusively</strong> Ukrainian government and military — the report names no EU targets — so the relevance here is the tradecraft, not the victimology.</p>
<p><strong>Why it matters to us:</strong> the tunnel-and-cloud-storage model defeats domain/IP blocklists and blends with legitimate egress, and it is exactly the pattern any espionage operator can adopt. Detection concepts: alert on tunnel-service egress (<code>trycloudflare.com</code> / <code>workers.dev</code> / <code>devtunnels.ms</code>) initiated by Office or scripting processes; flag <code>rclone</code> or S3-API <code>PUT</code>/<code>POST</code> from hosts with no backup role; hunt PowerShell that reads paste-site domains and decodes base64 blobs.</p><div class="prov"><span>annual-report</span><span>26 Jun 04:54Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-26/eset-s-2025-gamaredon-paper-exfil-and-c2-moved-wholesale-ont/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.sekoia.com/blog/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel" target="_blank" rel="noopener noreferrer">Sekoia</a></div></article>]]></content:encoded></item><item><title>Threat actor: FishMonger (I-SOON) ports SprySOCKS to Windows with a kernel-mode rootkit</title><link>https://ctipilot.ch/entries/2026-06-22/threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi/</guid><pubDate>Mon, 22 Jun 2026 00:14:59 +0000</pubDate><dc:date>2026-06-22T00:14:59Z</dc:date><category>nation-state</category><category>espionage</category><category>china-nexus</category><category>global</category><category>europe</category><description><![CDATA[<p>ESET&#39;s full research paper detailed two previously undocumented Windows variants of the SprySOCKS backdoor attributed to FishMonger (Earth Lusca / Aquatic Panda — the Winnti-contractor tracked as I-SOON), centred on a RawWNPF.sys kernel driver that hides processes (NtQuerySystemInformation hook), network …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi" data-tags="nation-state espionage china-nexus" data-regions="global europe" data-kind="research" data-priority="notable" data-discovered="2026-06-22T00:14:59Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi"><a href="https://ctipilot.ch/entries/2026-06-22/threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi/">Threat actor: FishMonger (I-SOON) ports SprySOCKS to Windows with a kernel-mode rootkit</a></h3><p>ESET&#39;s full research paper detailed two previously undocumented Windows variants of the SprySOCKS backdoor attributed to <strong>FishMonger</strong> (Earth Lusca / Aquatic Panda — the Winnti-contractor tracked as I-SOON), centred on a <code>RawWNPF.sys</code> kernel driver that hides processes (<code>NtQuerySystemInformation</code> hook), network connections (<code>nsiproxy.sys</code> IOCTL interception), files (minifilter callbacks) and persistence registry keys, and redirects crafted TCP packets to a hidden backdoor port via the Windows Filtering Platform (<a href="https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/" target="_blank" rel="noopener noreferrer">ESET, 2026-06-16</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). <strong>Background:</strong> FishMonger has been publicly tracked since the 2024 I-SOON contractor-leak exposed its government-espionage-for-hire model; ESET&#39;s earlier work documented the Linux SprySOCKS lineage, and this report extends the toolkit to a Windows kernel rootkit with a possible UEFI-bootkit component (leveraging the patched BlackLotus Secure Boot bypass, CVE-2023-24932). Confirmed victims are government organisations in Honduras, Taiwan, Thailand and Pakistan; the targeting class — government and defence — keeps EU government networks in scope. Enable the vulnerable-driver blocklist, hunt for the named driver and for process/network-hiding behaviours, and verify Secure Boot is at current patch level.</p><div class="prov"><span>research</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://thehackernews.com/2026/06/china-linked-sprysocks-backdoor-expands.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window</title><link>https://ctipilot.ch/entries/2026-06-22/cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th/</guid><pubDate>Mon, 22 Jun 2026 00:14:41 +0000</pubDate><dc:date>2026-06-22T00:14:41Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>rce</category><category>auth-bypass</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2026-39808</category><category>CVE-2026-39813</category><category>CVE-2026-25089</category><description><![CDATA[<p>What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command injection …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th" data-tags="vulnerabilities actively-exploited pre-auth rce auth-bypass" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:41Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-39808/">CVE-2026-39808 +2</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th/">CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window</a></h3><p>What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command injection (CVE-2026-25089, 9.8) (<a href="https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html" target="_blank" rel="noopener noreferrer">Security Affairs</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). FortiSandbox supplies the verdicts FortiGate, FortiMail, FortiProxy and FortiClient consume, so a compromised sandbox can suppress detection across the dependent Fortinet stack. The CVE-2026-25089 in-the-wild exploit appears AI-generated and faulty yet still finds traction against unpatched interfaces; Fortinet has not officially confirmed exploitation. Patch all three and restrict management-interface exposure.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html" target="_blank" rel="noopener noreferrer">Security Affairs</a> · <a href="https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/" target="_blank" rel="noopener noreferrer">Help Net Security</a></div></article>]]></content:encoded></item><item><title>CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:30</title><link>https://ctipilot.ch/entries/2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/</guid><pubDate>Mon, 22 Jun 2026 00:14:33 +0000</pubDate><dc:date>2026-06-22T00:14:33Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>rce</category><category>europe</category><category>dach</category><category>switzerland</category><category>exploited</category><category>patch-available</category><category>CVE-2026-12569</category><description><![CDATA[<p>PTC Windchill CVE-2026-12569 — pre-auth deserialization RCE (CVSS 10.0) exploited; BSI phoned operators at 02:30 — a DACH manufacturing/defence emergency. (daily 06-20, Heise)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio" data-tags="vulnerabilities actively-exploited pre-auth rce" data-regions="europe dach switzerland" data-kind="synthesis" data-priority="high" data-discovered="2026-06-22T00:14:33Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12569/">CVE-2026-12569</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:30</a></h3><p><strong>If you did nothing this week:</strong> if you run an internet-reachable PTC Windchill or FlexPLM instance, assume compromise — a pre-auth deserialization flaw on the login interface is being exploited to drop backdoors, and the German BSI considered it urgent enough to phone operators in the middle of the night.</p>
<p>CVE-2026-12569 (CVSS 3.1 10.0; CVSS 4.0 9.3) is an unsafe deserialization of untrusted data reachable on the web-based Windchill/FlexPLM login interface <em>before</em> authentication — no credentials, no prior foothold, no user interaction (<a href="https://security-hub.ncsc.admin.ch/#/posts/12713" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20 deep dive</a>). PTC shipped fixes on 2026-06-15 and auto-patched cloud tenants; affected on-premises builds span the 11.x, 12.0.x, 12.1.x, 13.0.x and 13.1.0.0–13.1.3.0 lines as well as releases prior to 11.0 M030 (<a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability" target="_blank" rel="noopener noreferrer">PTC PSIRT</a>). Both BSI and NCSC-CH treat it as actively exploited, with Heise reporting backdoor deployment on vulnerable servers and the BSI escalating to direct after-hours phone calls — a step reserved for its highest-urgency advisories (<a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security, 2026-06-19</a>).</p>
<p>Windchill and FlexPLM are the product-lifecycle-management backbone across DACH manufacturing, aerospace, automotive and the defence-industrial base, holding engineering crown jewels (CAD, BOMs, supplier data) behind increasingly internet-reachable supplier portals — which is exactly why the BSI mobilised. Patch every on-premises instance, confirm cloud tenants were auto-patched, and until then pull the login interface off the internet behind a VPN or authenticating reverse proxy. Hunt for Java deserialization exception bursts on the login path and for the Windchill application-server process (JBoss/WildFly/WebLogic) spawning shells or scripting interpreters (<code>T1190</code> → <code>T1505.003</code>).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Attacks on the deserialization vulnerability are apparently already underway to place backdoors on vulnerable servers.</p><p class="entry-cite__quote">At 2:30 AM, a BSI employee called the company, reported a new zero-day vulnerability, and urged immediate patches.</p><figcaption class="entry-cite__attr"><a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security</a></figcaption></figure></div><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability" target="_blank" rel="noopener noreferrer">PTC PSIRT advisory</a> · <a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12713" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a></div></article>]]></content:encoded></item><item><title>PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane</title><link>https://ctipilot.ch/entries/2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ/</guid><pubDate>Sat, 20 Jun 2026 05:12:21 +0000</pubDate><dc:date>2026-06-20T05:12:21Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>rce</category><category>europe</category><category>dach</category><category>switzerland</category><category>exploited</category><category>patch-available</category><category>CVE-2026-12569</category><description><![CDATA[<p>PTC Windchill / FlexPLM CVE-2026-12569 (CVSS 10.0) is under active exploitation — backdoors being deployed. An unauthenticated Java-deserialization flaw in the Windchill/FlexPLM web login interface yields pre-auth RCE; Germany&#39;s BSI took the unusual step of phoning administrators after-hours and NCSC-CH lists the status as actively exploited (Heise Security, 2026-06-19). PLM platforms are pervasive in DACH manufacturing, aerospace and the defence-industrial base. Patch released 2026-06-15.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ" data-tags="vulnerabilities actively-exploited pre-auth rce" data-regions="europe dach switzerland" data-kind="vulnerability" data-priority="critical" data-discovered="2026-06-20T05:12:21Z"><div class="badges"><span class="b crit">CRITICAL</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12569/">CVE-2026-12569</a><span class="b exp">exploited</span></div><h3 class="f-h" id="ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ"><a href="https://ctipilot.ch/entries/2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ/">PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane</a></h3><p><strong>Context.</strong> PTC Windchill and the FlexPLM apparel/retail variant are dominant product-lifecycle-management platforms across DACH manufacturing, aerospace, automotive and the defence-industrial base — systems that hold the engineering crown jewels (CAD, BOMs, supplier data) and increasingly sit behind internet-reachable web front-ends to support distributed engineering and supplier portals. That combination — high-value data and a network-exposed login surface — is what makes CVE-2026-12569 an emergency rather than a routine critical.</p>
<p><strong>The flaw.</strong> CVE-2026-12569 (CVSS 3.1 10.0; CVSS 4.0 9.3) is an unsafe deserialization of untrusted data reachable on the web-based Windchill/FlexPLM login interface <em>before</em> authentication (<a href="https://security-hub.ncsc.admin.ch/#/posts/12713" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-06-19</a>). A deserialization sink consumes attacker-controlled serialized data at the network edge; the only prerequisite is network access to the login endpoint, with no valid credentials, no prior foothold and no user interaction. PTC released fixes on 2026-06-15 and auto-patched cloud-hosted tenants (<a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability" target="_blank" rel="noopener noreferrer">PTC PSIRT</a>). Affected on-premises builds span the 11.x, 12.0.x, 12.1.x, 13.0.x and 13.1.0.0–13.1.3.0 lines as well as releases prior to 11.0 M030 — verify exact fixed-build numbers against the PTC advisory for your release train.</p>
<p><strong>Exploitation status.</strong> Both BSI (Germany) and NCSC-CH treat this as actively exploited: Heise reported active exploitation deploying backdoors on vulnerable systems, and the BSI escalated to direct after-hours phone calls to known Windchill operators — a step reserved for the highest-urgency advisories (<a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security, 2026-06-19</a>).</p>
<p><strong>Kill chain (mapped to MITRE ATT&amp;CK).</strong></p>
<ul><li><strong>Initial access / execution</strong> — pre-auth deserialization RCE against the public-facing login interface (<a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190 Exploit Public-Facing Application</a>). The deserialization gadget executes in the context of the Windchill Java application server.</li><li><strong>Persistence</strong> — the sources report follow-on backdoor deployment on compromised hosts; this is consistent with installing a server-side implant or web component on the application server (<a href="https://attack.mitre.org/techniques/T1505/003/" target="_blank" rel="noopener noreferrer">T1505.003 Server Software Component: Web Shell</a>), though the specific implant class was not detailed publicly.</li><li><strong>Discovery / collection</strong> — a foothold on a PLM server places the attacker adjacent to engineering IP, supplier records and integration credentials to ERP/CAD systems.</li></ul>
<p><strong>Hunt and detection concepts (no IOCs).</strong> Watch Windchill application-server logs for Java deserialization exception bursts and class-resolution errors around the login path; alert on unexpected child processes spawned by the Windchill application-server process (JBoss/WildFly/WebLogic parent), which should not normally fork shells or scripting interpreters; flag anomalous inbound connections to Windchill HTTP/HTTPS ports from CIDR ranges that never legitimately reach the login surface; and treat any new outbound connections initiated by a PLM server as suspect, since these servers should have tightly-bounded egress.</p>
<p><strong>Hardening / mitigation.</strong> Apply the 2026-06-15 patch on every on-premises instance and confirm cloud tenants were auto-patched. Until patched, remove the login interface from direct internet exposure — front it with VPN or an authenticating reverse proxy and segment the PLM tier so it cannot be reached from untrusted networks. Constrain the application-server service account to least privilege and restrict its outbound network paths so a successful deserialization yields the smallest possible blast radius.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Active exploitation is underway to deploy backdoors on vulnerable systems.</p><figcaption class="entry-cite__attr"><a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Current exploitation status: Actively Exploited</p><figcaption class="entry-cite__attr"><a href="https://security-hub.ncsc.admin.ch/#/posts/12713" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>20 Jun 05:12Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability" target="_blank" rel="noopener noreferrer">PTC PSIRT advisory</a> · <a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12713" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a></div></article>]]></content:encoded></item><item><title>Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane</title><link>https://ctipilot.ch/entries/2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c/</guid><pubDate>Fri, 19 Jun 2026 05:21:01 +0000</pubDate><dc:date>2026-06-19T05:21:01Z</dc:date><category>vulnerabilities</category><category>rce</category><category>priv-esc</category><category>auth-bypass</category><category>info-disclosure</category><category>identity</category><category>patch-available</category><category>global</category><category>europe</category><category>switzerland</category><category>patch-available</category><category>CVE-2026-20181</category><category>CVE-2026-20190</category><description><![CDATA[<p>Cisco Identity Services Engine is not just another exposed appliance — it is the policy brain of network access control in most large Swiss and European public-sector estates: the RADIUS/TACACS+ server behind 802.1X port authentication, the posture/profiling engine, and frequently the AD/identity-policy enforcement …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c" data-tags="vulnerabilities rce priv-esc auth-bypass info-disclosure identity patch-available" data-regions="global europe switzerland" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-19T05:21:01Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20181/">CVE-2026-20181 +1</a></div><h3 class="f-h" id="cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c"><a href="https://ctipilot.ch/entries/2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c/">Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane</a></h3><p>Cisco Identity Services Engine is not just another exposed appliance — it is the policy brain of network access control in most large Swiss and European public-sector estates: the RADIUS/TACACS+ server behind 802.1X port authentication, the posture/profiling engine, and frequently the AD/identity-policy enforcement point for both wired and wireless. A root shell on an ISE node is therefore not an endpoint compromise; it is control of the authentication plane that decides which devices and users get onto the network. That is what makes the pair Cisco patched on 2026-06-17 worth a deep read even with no in-the-wild exploitation yet reported (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv" target="_blank" rel="noopener noreferrer">Cisco PSIRT, 2026-06-17</a>).</p>
<p><strong>The two primitives.</strong> CVE-2026-20190 (CVSS 7.5, improper authorization) is the entry primitive: specific ISE/ISE-PIC APIs fail to enforce authorization, so an unauthenticated remote attacker who can reach the management interface over HTTP can read sensitive data — explicitly including hashed administrator credentials — with crafted requests (<code>T1190</code> Exploit Public-Facing Application → <code>T1212</code> Exploitation for Credential Access). CVE-2026-20181 (CVSS 9.1, path traversal / CWE-22) is the impact primitive: an <em>authenticated</em> administrator can submit a crafted request that escapes the intended directory and executes arbitrary operating-system commands, escalating to root; on single-node deployments the same flaw can also be driven to a denial-of-service (<a href="https://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-18</a>).</p>
<p><strong>Why the chain matters more than either CVE.</strong> On its own, CVE-2026-20181 requires administrator authentication — a meaningful barrier. CVE-2026-20190 removes that barrier: it hands an unauthenticated attacker the hashed admin credentials, which can then be cracked offline (<code>T1110.002</code> Password Cracking) or, depending on the credential material and authentication scheme, replayed (<code>T1550</code> Use Alternate Authentication Material). With administrator authentication in hand (<code>T1078</code> Valid Accounts), the attacker pivots to CVE-2026-20181 for command execution as root (<code>T1059</code> Command and Scripting Interpreter → <code>T1068</code> Exploitation for Privilege Escalation). The net effect is a network-reachable, no-interactive-credential path from &quot;can talk to the ISE management plane&quot; to &quot;root on the identity controller.&quot; From root on ISE, an adversary is positioned to tamper with authentication and authorization policy itself (<code>T1556</code> Modify Authentication Process) — issuing or trusting RADIUS responses, weakening 802.1X enforcement, or harvesting credentials traversing the policy engine.</p>
<p><strong>Exposure and prerequisites.</strong> The only hard prerequisite for the entry primitive is network reachability of the ISE management/API interface; everything after that is consequence. Cisco states there is <strong>no workaround</strong>. Affected trains are fixed in ISE 3.3 Patch 11 and 3.4 Patch 6 (both available now). ISE 3.5 is the gap: Patch 3 closes only the unauthenticated read (CVE-2026-20190), and the full fix (Patch 4) is not scheduled until August 2026 — so 3.5 operators carry the authenticated-RCE half for roughly two months and must compensate with exposure reduction.</p>
<p><strong>Hunt and detection concepts.</strong> Because there is no public exploit detail yet, detection here is behavioural and access-surface-oriented, not signature-based:</p>
<ul><li><strong>Management-plane reachability is the first control:</strong> alert on any source outside your defined administration subnets reaching the ISE management/API interface at all. The unauthenticated read only works if the attacker can reach those APIs.</li><li><strong>API-access anomalies:</strong> review ISE application/admin logs for unauthenticated or unexpected requests to the credential-adjacent API endpoints, and for ERS/API request patterns from newly-seen source addresses.</li><li><strong>Administrator-session anomalies:</strong> correlate any administrator CLI/command activity with the set of source addresses and accounts you expect to perform it; a successful chain shows up as admin-context command execution from an unusual origin shortly after anomalous unauthenticated API reads.</li><li><strong>Identity-plane integrity:</strong> baseline expected RADIUS/TACACS+ behaviour and alert on policy or device-admin changes that did not originate from your change process — post-compromise tampering is the high-impact outcome to catch even if the intrusion itself was missed.</li></ul>
<p><strong>Hardening / mitigation (cite Cisco&#39;s own guidance).</strong> Apply the fixed patches as the only complete remediation: ISE 3.3 Patch 11 or 3.4 Patch 6 now; for 3.5, apply Patch 3 immediately to remove the unauthenticated credential read and plan the August Patch 4 upgrade. Independently of patch state, restrict the ISE management and API interfaces to dedicated, tightly-firewalled administration subnets (out-of-band management VLAN), enforce strong administrator credentials and MFA on admin logon to blunt the offline-cracking step, and monitor the management plane as a tier-0 asset. Treat ISE, like AD and the PKI, as identity infrastructure whose compromise is a full-network event — segment and instrument it accordingly.</p><div class="prov"><span>vulnerability</span><span>19 Jun 05:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-19/cisco-ise-cve-2026-20181-cve-2026-20190-an-unauthenticated-c/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a> · <a href="https://www.securityweek.com/critical-command-execution-vulnerability-patched-in-cisco-ise/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1989" target="_blank" rel="noopener noreferrer">BSI CERT-Bund WID-SEC-2026-1989</a></div></article>]]></content:encoded></item><item><title>ScarCruft (APT37) delivers NarwhalRAT behind fake Microsoft OTP &quot;security alert&quot; lures</title><link>https://ctipilot.ch/entries/2026-06-18/scarcruft-apt37-delivers-narwhalrat-behind-fake-microsoft-ot/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-18/scarcruft-apt37-delivers-narwhalrat-behind-fake-microsoft-ot/</guid><pubDate>Thu, 18 Jun 2026 05:10:29 +0000</pubDate><dc:date>2026-06-18T05:10:29Z</dc:date><category>nation-state</category><category>espionage</category><category>phishing</category><category>north-korea-nexus</category><category>apac</category><category>europe</category><description><![CDATA[<p>ScarCruft (APT37) deploys NarwhalRAT behind fake Microsoft OTP alerts; China arrests 67 Silver Fox/ValleyRAT operators. North Korean spearphishing impersonating Microsoft MFA notices delivers a compiled-Python RAT with a pCloud dead-drop resolver (Genians, 2026-06-16); separately, Chinese police dismantled the supply chain behind the Winos/ValleyRAT operator network.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-18/scarcruft-apt37-delivers-narwhalrat-behind-fake-microsoft-ot" data-tags="nation-state espionage phishing north-korea-nexus" data-regions="apac europe" data-kind="threat" data-priority="high" data-discovered="2026-06-18T05:10:29Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="scarcruft-apt37-delivers-narwhalrat-behind-fake-microsoft-ot"><a href="https://ctipilot.ch/entries/2026-06-18/scarcruft-apt37-delivers-narwhalrat-behind-fake-microsoft-ot/">ScarCruft (APT37) delivers NarwhalRAT behind fake Microsoft OTP &quot;security alert&quot; lures</a></h3><p>Genians Security Center attributed a new campaign to ScarCruft / APT37 (North Korea nexus) deploying a previously-undocumented RAT it calls NarwhalRAT (<a href="https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat" target="_blank" rel="noopener noreferrer">Genians, 2026-06-16</a>). The lure is a spearphishing email impersonating a Microsoft multi-factor authentication / OTP security alert; the attached ZIP carries a Windows shortcut (LNK) that launches PowerShell with <code>-ExecutionPolicy Bypass</code> to pull a batch loader, which establishes persistence via a scheduled task running on a one-minute interval (<code>T1053.005</code>). The payload is a compiled-Python binary loading obfuscated bytecode and providing keylogging (<code>T1056.001</code>), screenshot and audio capture, USB collection and remote command execution; C2 resilience comes from a pCloud dead-drop resolver (<code>T1102.001</code>) that hands out current relay addresses, defeating static domain/IP blocking (<a href="https://thehackernews.com/2026/06/fake-microsoft-alerts-used-to-deploy.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-17</a>).</p>
<p><strong>Why it matters to us:</strong> APT37 targets government, diplomatic, policy-research and Korean-diaspora organisations, including in Europe. The behavioural chain is hunt-friendly without IOCs: alert on <code>schtasks.exe</code> creating tasks under an unusual <code>Microsoft…</code>-style name from a non-installer parent, on LNK→PowerShell <code>-ExecutionPolicy Bypass</code> execution trees, and on compiled-Python process images making outbound calls to consumer cloud-storage APIs. Treat the cloud dead-drop pattern as the durable detection surface — blocking one relay does not break C2.</p><div class="prov"><span>threat</span><span>18 Jun 05:10Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-18/scarcruft-apt37-delivers-narwhalrat-behind-fake-microsoft-ot/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat" target="_blank" rel="noopener noreferrer">Genians Security Center</a> · <a href="https://thehackernews.com/2026/06/fake-microsoft-alerts-used-to-deploy.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>FortiSandbox — three critical flaws now exploited simultaneously, including the previously disclosure-only CVE-2026-25089</title><link>https://ctipilot.ch/entries/2026-06-17/fortisandbox-three-critical-flaws-now-exploited-simultaneous/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-17/fortisandbox-three-critical-flaws-now-exploited-simultaneous/</guid><pubDate>Wed, 17 Jun 2026 05:14:32 +0000</pubDate><dc:date>2026-06-17T05:14:32Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>pre-auth</category><category>rce</category><category>auth-bypass</category><category>global</category><category>exploited</category><category>patch-available</category><category>CVE-2026-39808</category><category>CVE-2026-39813</category><category>CVE-2026-25089</category><description><![CDATA[<p>Three critical FortiSandbox flaws are now under simultaneous active exploitation — CVE-2026-39808, CVE-2026-39813 (April patches) and CVE-2026-25089 (patched 2026-06-09, previously disclosure-only here on 06-12) were all observed exploited in a 24-hour window; FortiSandbox feeds verdicts to the wider FortiGate/FortiMail stack (§ 4).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-17/fortisandbox-three-critical-flaws-now-exploited-simultaneous" data-tags="vulnerabilities actively-exploited pre-auth rce auth-bypass" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-06-17T05:14:32Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-39808/">CVE-2026-39808 +2</a><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="fortisandbox-three-critical-flaws-now-exploited-simultaneous"><a href="https://ctipilot.ch/entries/2026-06-17/fortisandbox-three-critical-flaws-now-exploited-simultaneous/">FortiSandbox — three critical flaws now exploited simultaneously, including the previously disclosure-only CVE-2026-25089</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-12/cve-2026-25089-fortinet-fortisandbox-unauthenticated-os-comm/">CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI&#39;s VNC-launch handler (CVSS 9.8)</a> <span class="mono muted">(2026-06-12)</span></p><p>When CVE-2026-25089 was covered on 06-12 it was disclosure-only. Threat-intel firm Defused Cyber has now reported active exploitation of three FortiSandbox flaws within a single 24-hour window — CVE-2026-39808 (CVSS 9.8, JRPC OS command injection), CVE-2026-39813 (CVSS 9.1, JRPC path traversal / auth bypass), both with patches available since April 2026, and CVE-2026-25089 (CVSS 9.8, web-UI command injection), patched 2026-06-09 (<a href="https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html" target="_blank" rel="noopener noreferrer">Security Affairs, 2026-06-16</a>).</p>
<p>FortiSandbox supplies sandboxed file verdicts that FortiGate, FortiMail, FortiProxy and FortiClient consume to make blocking decisions, so a compromised sandbox can suppress detection across the dependent Fortinet stack (<a href="https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-06-16</a>). The CVE-2026-25089 exploit seen in the wild appears AI-generated and is assessed as faulty, yet still finds traction against unpatched deployments — evidence that exposed, unpatched FortiSandbox interfaces remain. Fortinet has not yet officially confirmed exploitation. Patch all three; until then, restrict management-interface exposure and watch FortiSandbox web-UI/JRPC access logs for unauthenticated external POSTs.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">UPDATE (originally covered 2026-06-12): When CVE-2026-25089 was covered on 06-12 it was disclosure-only.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>17 Jun 05:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-17/fortisandbox-three-critical-flaws-now-exploited-simultaneous/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html" target="_blank" rel="noopener noreferrer">Security Affairs, 2026-06-16</a> · <a href="https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-06-16</a></div></article>]]></content:encoded></item><item><title>PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule</title><link>https://ctipilot.ch/entries/2026-06-16/prc-unc6508-ran-year-plus-espionage-through-internet-facing/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-16/prc-unc6508-ran-year-plus-espionage-through-internet-facing/</guid><pubDate>Tue, 16 Jun 2026 05:08:53 +0000</pubDate><dc:date>2026-06-16T05:08:53Z</dc:date><category>nation-state</category><category>espionage</category><category>identity</category><category>china-nexus</category><category>global</category><category>europe</category><description><![CDATA[<p>PRC actor UNC6508 ran year-plus espionage through internet-facing REDCap research servers and abused a Google Workspace content-compliance rule to silently BCC research/defence email to attacker Gmail — REDCap is widely run at Swiss/EU academic medical centres. (Google GTIG, 2026-06-15)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-16/prc-unc6508-ran-year-plus-espionage-through-internet-facing" data-tags="nation-state espionage identity china-nexus" data-regions="global europe" data-kind="threat" data-priority="high" data-discovered="2026-06-16T05:08:53Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="prc-unc6508-ran-year-plus-espionage-through-internet-facing"><a href="https://ctipilot.ch/entries/2026-06-16/prc-unc6508-ran-year-plus-espionage-through-internet-facing/">PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule</a></h3><p>Google&#39;s Threat Intelligence Group attributes a September 2023 – November 2025 espionage campaign to <strong>UNC6508</strong>, a PRC-nexus cluster that compromised North American academic, medical and military-health organisations by exploiting externally-facing <strong>REDCap</strong> (Research Electronic Data Capture) servers, then dropping a bespoke PHP implant tracked as <strong>INFINITERED</strong> (<a href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research" target="_blank" rel="noopener noreferrer">Google GTIG, 2026-06-15</a>). INFINITERED trojanises REDCap&#39;s own upgrade mechanism to survive platform updates, harvests credentials from the REDCap login page, and exposes a cookie-gated backdoor for shell, file, SQL and credential operations (<a href="https://www.helpnetsecurity.com/2026/06/15/chinese-hackers-redcap-medical-research-institutions-breach/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-06-15</a>). The exfiltration tradecraft is the notable part: after pivoting to a Workspace admin account, the actor created a Google Workspace <strong>content-compliance rule named &quot;Patroit&quot;</strong> that silently BCC-forwarded any message matching ~150 research/defence keywords to an attacker-controlled Gmail address — abusing a legitimate administrative feature rather than dropping exfiltration malware (<code>T1114.003</code> Email Forwarding Rule), which evades most DLP that watches for new tooling (<a href="https://www.securityweek.com/chinese-hackers-target-medical-military-and-ai-research-in-north-america/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-15</a>). Initial access mapped to <code>T1190</code>; web-shell persistence to <code>T1505.003</code>; admin credential reuse to <code>T1078</code>.</p>
<p><strong>Why it matters to us:</strong> REDCap is deployed across Swiss and EU university hospitals, cantonal research bodies and clinical-trial coordinators, and the Workspace BCC-rule technique is tenant-agnostic. Hunt now: Google Workspace admin audit logs for content-compliance/BCC rule creation by non-IT-admin accounts (especially rules with external Gmail recipients), and file-integrity-monitor the REDCap upgrade-staging directory and login handlers — standard web-root scanning misses the upgrade-path implant.</p><div class="prov"><span>threat</span><span>16 Jun 05:08Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-16/prc-unc6508-ran-year-plus-espionage-through-internet-facing/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research" target="_blank" rel="noopener noreferrer">Google GTIG</a> · <a href="https://www.helpnetsecurity.com/2026/06/15/chinese-hackers-redcap-medical-research-institutions-breach/" target="_blank" rel="noopener noreferrer">Help Net Security</a> · <a href="https://www.securityweek.com/chinese-hackers-target-medical-military-and-ai-research-in-north-america/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article>]]></content:encoded></item><item><title>Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C2</title><link>https://ctipilot.ch/entries/2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat/</guid><pubDate>Sun, 14 Jun 2026 05:00:05 +0000</pubDate><dc:date>2026-06-14T05:00:05Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>ai-abuse</category><category>identity</category><category>europe</category><category>global</category><description><![CDATA[<p>APT28 (GRU Unit 26165) tradecraft has moved to LLM-driven and cloud-native evasion. Sekoia documents LameHug — the first APT28 stealer that generates exfiltration code at runtime via a hosted LLM — plus BeardShell C2 over consumer cloud-storage providers and the FrostArmada SOHO-router DNS-hijack AiTM campaign against Microsoft 365 (Sekoia TDR, 2026-06-11).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat" data-tags="nation-state espionage russia-nexus ai-abuse identity" data-regions="europe global" data-kind="research" data-priority="high" data-discovered="2026-06-14T05:00:05Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat"><a href="https://ctipilot.ch/entries/2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat/">Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C2</a></h3><p>Sekoia&#39;s Threat Detection &amp; Research team published a tradecraft-evolution retrospective on APT28 (Fancy Bear / Forest Blizzard), and the operationally relevant material is the 2025–2026 tooling (<a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/" target="_blank" rel="noopener noreferrer">Sekoia TDR, 2026-06-11</a>). Three developments stand out for European defenders. <strong>LameHug</strong> is the first documented APT28 infostealer that delegates its logic to a large language model: base64-encoded prompts are sent to Alibaba&#39;s Qwen 2.5-Coder model via the Hugging Face inference API to generate collection and exfiltration code on the fly, observed against Ukrainian government targets — meaning the malicious behaviour is not statically present in the binary. <strong>BeardShell</strong> is a C++ backdoor that rotates its command-and-control across consumer cloud-storage providers (Koofr, Icedrive, Filen), defeating domain/IP blocklisting because the traffic is ordinary HTTPS to legitimate services. <strong>FrostArmada</strong> (April 2026) is a SOHO-router DNS-hijack campaign — 18,000-plus unique IPs across 120-plus countries — that rewrites DHCP/DNS on MikroTik and TP-Link devices to mount adversary-in-the-middle attacks against Microsoft 365 sign-ins (<code>T1557</code> Adversary-in-the-Middle, <code>T1071.001</code> Web Protocols for the cloud C2). Sekoia notes APT28&#39;s GooseEgg implant (CVE-2022-38028) ran for roughly five years before public disclosure — a reminder that current tools likely carry a similar blind-spot horizon.</p>
<p><strong>Why it matters to us:</strong> NATO European ministries, defence suppliers and critical-infrastructure operators are named in the targeting. The detection priorities are concrete and IoC-free: hunt cloud-storage beaconing to Koofr/Icedrive/Filen from non-user workstations, alert on outbound traffic to Hugging Face inference endpoints from Windows hosts, monitor MikroTik/TP-Link DNS-setting changes in network-device logs, and treat Office documents delivered through Signal Desktop as a Mark-of-the-Web bypass risk — Sekoia notes APT28 uses the messenger to deliver Office lures that arrive without the Mark-of-the-Web protection.</p><div class="prov"><span>research</span><span>14 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/sekoia-apt28-gru-unit-26165-tradecraft-shifts-to-llm-generat/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/" target="_blank" rel="noopener noreferrer">Sekoia TDR</a></div></article>]]></content:encoded></item><item><title>Black Lotus Labs: the Volt Typhoon-linked JDY botnet doubles to 1,500+ devices and weaponises CVE disclosures within hours</title><link>https://ctipilot.ch/entries/2026-06-11/black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-11/black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles/</guid><pubDate>Thu, 11 Jun 2026 05:00:04 +0000</pubDate><dc:date>2026-06-11T05:00:04Z</dc:date><category>nation-state</category><category>espionage</category><category>botnet</category><category>china-nexus</category><category>global</category><description><![CDATA[<p>Lumen&#39;s Black Lotus Labs reports that the JDY botnet — the reconnaissance cluster that survived the 2024 KV-botnet takedown and is assessed with high confidence to support multiple China-nexus actors including Volt Typhoon — has more than doubled from roughly 650 bots in January 2024 to over 1,500 compromised SOHO and …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-11/black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles" data-tags="nation-state espionage botnet china-nexus" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-06-11T05:00:04Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles"><a href="https://ctipilot.ch/entries/2026-06-11/black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles/">Black Lotus Labs: the Volt Typhoon-linked JDY botnet doubles to 1,500+ devices and weaponises CVE disclosures within hours</a></h3><p>Lumen&#39;s Black Lotus Labs reports that the JDY botnet — the reconnaissance cluster that survived the 2024 KV-botnet takedown and is assessed with high confidence to support multiple China-nexus actors including Volt Typhoon — has more than doubled from roughly 650 bots in January 2024 to over 1,500 compromised SOHO and IoT devices (<a href="https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation" target="_blank" rel="noopener noreferrer">Lumen Black Lotus Labs, 2026-06-10</a>). The botnet now spans Cisco, Araknis, Mimosa Networks, Ubiquiti, Draytek, Hikvision and Linksys devices, performs multiprotocol service fingerprinting, banner-grabbing and TLS-certificate collection at scale, and routes C2 through hidden Tor services while managing victims with the open-source Platypus reverse-shell server. The operationally significant finding: scanning of Fortinet devices spiked within hours of the public disclosure of CVE-2026-35616, demonstrating sub-24-hour integration of new vulnerability intelligence into the recon-to-exploitation pipeline (<a href="https://thehackernews.com/2026/06/china-linked-jdy-botnet-expands-to-1500.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-10</a>). Targeting centres on US military and associated entities, with distributed European nodes. Technique mapping: <code>T1595.002</code> Active Scanning: Vulnerability Scanning, <code>T1590</code> Gather Victim Network Information, <code>T1584.005</code> Compromise Infrastructure: Botnet.</p>
<p><strong>Why it matters to us:</strong> JDY scanning should be treated as a precursor to targeted exploitation, not background noise — the sub-24-hour weaponisation window means CH/EU public-sector and critical-infrastructure operators must compress patch cycles for internet-facing edge appliances to hours, not weeks, after a disclosure. Hunt for outbound connections from edge/SOHO devices to the Platypus default service, unusual high-rate outbound SYN scanning, and unexpected TLS-certificate harvesting.</p><div class="prov"><span>research</span><span>11 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-11/black-lotus-labs-the-volt-typhoon-linked-jdy-botnet-doubles/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation" target="_blank" rel="noopener noreferrer">Lumen Black Lotus Labs</a> · <a href="https://thehackernews.com/2026/06/china-linked-jdy-botnet-expands-to-1500.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>Year-old WinRAR flaw (CVE-2025-8088) still fuels Ukraine intrusions — GIFTEDCROOK via UAC-0226 and an Earth Dahu chain</title><link>https://ctipilot.ch/entries/2026-06-10/year-old-winrar-flaw-cve-2025-8088-still-fuels-ukraine-intru/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-10/year-old-winrar-flaw-cve-2025-8088-still-fuels-ukraine-intru/</guid><pubDate>Wed, 10 Jun 2026 05:00:12 +0000</pubDate><dc:date>2026-06-10T05:00:12Z</dc:date><category>espionage</category><category>infostealer</category><category>russia-nexus</category><category>actively-exploited</category><category>europe</category><category>russia-cis</category><category>exploited</category><category>patch-available</category><category>CVE-2025-8088</category><description><![CDATA[<p>Trend Micro documents two Russia-aligned campaigns still exploiting CVE-2025-8088 — a path traversal via NTFS Alternate Data Streams in WinRAR patched in July 2025 — nearly a year after the fix (Trend Micro, 2026-06-08).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-10/year-old-winrar-flaw-cve-2025-8088-still-fuels-ukraine-intru" data-tags="espionage infostealer russia-nexus actively-exploited" data-regions="europe russia-cis" data-kind="research" data-priority="notable" data-discovered="2026-06-10T05:00:12Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-8088/">CVE-2025-8088</a><span class="b exp">exploited</span></div><h3 class="f-h" id="year-old-winrar-flaw-cve-2025-8088-still-fuels-ukraine-intru"><a href="https://ctipilot.ch/entries/2026-06-10/year-old-winrar-flaw-cve-2025-8088-still-fuels-ukraine-intru/">Year-old WinRAR flaw (CVE-2025-8088) still fuels Ukraine intrusions — GIFTEDCROOK via UAC-0226 and an Earth Dahu chain</a></h3><p>Trend Micro documents two Russia-aligned campaigns still exploiting CVE-2025-8088 — a path traversal via NTFS Alternate Data Streams in WinRAR patched in July 2025 — nearly a year after the fix (<a href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html" target="_blank" rel="noopener noreferrer">Trend Micro, 2026-06-08</a>). SHADOW-EARTH-066 (UAC-0226) delivers GIFTEDCROOK via crafted RAR archives with decoy PDFs and hidden ADS payloads that extract to the Startup folder and run in-memory PowerShell DLL loaders to steal passwords, cookies and documents from Chrome, Edge, Opera and Firefox; a separate Earth Dahu chain uses an HTA-to-VBScript dropper (<a href="https://thehackernews.com/2026/06/winrar-flaw-exploited-by-russia-aligned.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-09</a>). Both actors moved C2 off Telegram to dedicated servers after Russia&#39;s February 2026 Telegram block. The defender lesson is the persistence of an exploited entry point in unmanaged software: hunt <code>wscript.exe</code>/<code>mshta.exe</code> spawned from archive-extraction events, Startup-folder writes (Sysmon EID 11), and PowerShell script-block logging (EID 4104) for in-memory reflection. CVE-2025-8088 affects any unpatched WinRAR globally; ensure deployed versions are current (T1059.005, T1547.001, T1555.003).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Trend Micro documents two Russia-aligned campaigns still exploiting CVE-2025-8088 — a path traversal via NTFS Alternate Data Streams in WinRAR patched in July 2025 — nearly a year after the fix (Trend Micro, 2026-06-08).</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>research</span><span>10 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-10/year-old-winrar-flaw-cve-2025-8088-still-fuels-ukraine-intru/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html" target="_blank" rel="noopener noreferrer">Trend Micro, 2026-06-08</a> · <a href="https://thehackernews.com/2026/06/winrar-flaw-exploited-by-russia-aligned.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-09</a></div></article>]]></content:encoded></item><item><title>Five Eyes joint bulletin: Chinese military intelligence recruiting cleared personnel through LinkedIn and job platforms</title><link>https://ctipilot.ch/entries/2026-06-06/five-eyes-joint-bulletin-chinese-military-intelligence-recru/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-06/five-eyes-joint-bulletin-chinese-military-intelligence-recru/</guid><pubDate>Sat, 06 Jun 2026 05:00:00 +0000</pubDate><dc:date>2026-06-06T05:00:00Z</dc:date><category>nation-state</category><category>espionage</category><category>china-nexus</category><category>global</category><category>uk</category><description><![CDATA[<p>Five Eyes issue a rare joint bulletin on Chinese intelligence recruiting via LinkedIn and job platforms — targeting cleared personnel, researchers and policy staff; directly relevant to Swiss/EU public-sector personnel security (The Record, 2026-06-03).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-06/five-eyes-joint-bulletin-chinese-military-intelligence-recru" data-tags="nation-state espionage china-nexus" data-regions="global uk" data-kind="threat" data-priority="high" data-discovered="2026-06-06T05:00:00Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="five-eyes-joint-bulletin-chinese-military-intelligence-recru"><a href="https://ctipilot.ch/entries/2026-06-06/five-eyes-joint-bulletin-chinese-military-intelligence-recru/">Five Eyes joint bulletin: Chinese military intelligence recruiting cleared personnel through LinkedIn and job platforms</a></h3><p>On 2026-06-03 the five Five Eyes domestic-intelligence services (ASIO, CSIS, FBI, MI5, NZSIS) released an unusual joint bulletin, <em>Safeguarding Our Secrets</em>, warning that China&#39;s military-intelligence apparatus is systematically using professional-networking and freelance-work platforms — LinkedIn, Indeed, Upwork — to identify and cultivate people with access to classified or otherwise privileged information (<a href="https://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets" target="_blank" rel="noopener noreferrer">MI5, 2026-06-03</a>; <a href="https://therecord.media/five-eyes-warns-chinese-spies-are-using-job-sites-to-recruit-insiders" target="_blank" rel="noopener noreferrer">The Record, 2026-06-03</a>). Operatives pose as recruiters, consultants, HR representatives or think-tank staff for fabricated cover companies outside China, open with benign foreign-policy / defence / trade research commissions paying hundreds to a few thousand dollars per deliverable, then escalate toward sensitive material and migrate the relationship to encrypted messaging to reduce platform visibility. Named target categories include security-clearance holders, military personnel, academics, researchers and journalists.</p>
<p><strong>Why it matters to us:</strong> This is a human-intelligence tradecraft advisory rather than a technical-intrusion one, and Switzerland — outside Five Eyes but a hub for international organisations, financial regulation and dual-use research — is squarely in the target set. The defensible surface is personnel-security, not EDR: brief cleared and research staff on the innocuous-task-to-sensitive-request progression, give them a low-friction route to report unsolicited foreign-recruitment contact, and treat unsolicited &quot;paid policy paper&quot; approaches to staff with administrative or network access as a counter-intelligence signal, not a side gig.</p><div class="prov"><span>threat</span><span>06 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-06/five-eyes-joint-bulletin-chinese-military-intelligence-recru/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.mi5.gov.uk/five-eyes-joint-bulletin-safeguarding-our-secrets" target="_blank" rel="noopener noreferrer">MI5 — Five Eyes joint bulletin &quot;Safeguarding Our Secrets&quot;</a> · <a href="https://therecord.media/five-eyes-warns-chinese-spies-are-using-job-sites-to-recruit-insiders" target="_blank" rel="noopener noreferrer">The Record, 2026-06-03</a></div></article>]]></content:encoded></item><item><title>Gamaredon weaponises WinRAR CVE-2025-8088 and adds the GammaSteel stealer</title><link>https://ctipilot.ch/entries/2026-06-03/gamaredon-weaponises-winrar-cve-2025-8088-and-adds-the-gamma/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-03/gamaredon-weaponises-winrar-cve-2025-8088-and-adds-the-gamma/</guid><pubDate>Wed, 03 Jun 2026 05:00:08 +0000</pubDate><dc:date>2026-06-03T05:00:08Z</dc:date><category>espionage</category><category>nation-state</category><category>russia-nexus</category><category>infostealer</category><category>vulnerabilities</category><category>actively-exploited</category><category>patch-available</category><category>europe</category><category>russia-cis</category><category>exploited</category><category>patch-available</category><category>CVE-2025-8088</category><description><![CDATA[<p>UPDATE (originally covered 2026-06-02): Sekoia TDR&#39;s &quot;FSB&#39;s Matryoshka&quot; series adds material technical detail to the Gamaredon (UAC-0010 / ACTINIUM) tooling consolidation covered yesterday: the group is exploiting the WinRAR path-traversal flaw CVE-2025-8088 as an initial-access vector, using the traversal to …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-03/gamaredon-weaponises-winrar-cve-2025-8088-and-adds-the-gamma" data-tags="espionage nation-state russia-nexus infostealer vulnerabilities actively-exploited patch-available" data-regions="europe russia-cis" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-03T05:00:08Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-8088/">CVE-2025-8088</a><span class="b exp">exploited</span><span class="b upd">update</span></div><h3 class="f-h" id="gamaredon-weaponises-winrar-cve-2025-8088-and-adds-the-gamma"><a href="https://ctipilot.ch/entries/2026-06-03/gamaredon-weaponises-winrar-cve-2025-8088-and-adds-the-gamma/">Gamaredon weaponises WinRAR CVE-2025-8088 and adds the GammaSteel stealer</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-02/sekoia-consolidates-gamaredon-tooling-under-gammaphish-gamma/">Sekoia consolidates Gamaredon tooling under GammaPhish / GammaWorm, details an NTFS-ADS USB+network worm</a> <span class="mono muted">(2026-06-02)</span></p><p>Sekoia TDR&#39;s &quot;FSB&#39;s Matryoshka&quot; series adds material technical detail to the Gamaredon (UAC-0010 / ACTINIUM) tooling consolidation covered yesterday: the group is exploiting the WinRAR path-traversal flaw <strong>CVE-2025-8088</strong> as an initial-access vector, using the traversal to write payloads directly into <code>%APPDATA%\…\Start Menu\Programs\Startup\</code> for persistence without a Registry or Scheduled-Task artefact (<a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR, 2026-06-01</a>).</p>
<p>The series also names <strong>GammaSteel</strong>, a modular file-stealer (consolidating prior QuietSieve/HarvesterX-class modules) that captures files by extension and — newly — exfiltrates to attacker-controlled S3-compatible cloud storage in addition to Gamaredon&#39;s previously documented HTTP/Telegram channels (<a href="https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-02</a>). The full chain runs WinRAR archive → GammaPhish (HTA) → GammaLoad (VBScript downloader) → GammaWorm/GammaSteel.</p>
<p>Delta for defenders: CVE-2025-8088 is fixed in WinRAR 7.13 (August 2025), so the entry vector is closed by patching — inventory WinRAR versions across the estate. Hunt for archive utilities writing executables or <code>.vbs</code> into <code>Programs\Startup</code> paths (Sysmon EID 11 on target path containing <code>Programs\Startup</code>), WinRAR spawning <code>wscript.exe</code>/<code>mshta.exe</code>, and VBScript processes making outbound requests to S3 endpoints inconsistent with normal business traffic. The targeting is Ukraine-centric, but the WinRAR vector reaches any organisation that opens archive-format lures.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">UPDATE (originally covered 2026-06-02): Sekoia TDR&#39;s &quot;FSB&#39;s Matryoshka&quot; series adds material technical detail to the Gamaredon (UAC-0010 / ACTINIUM) tooling consolidation covered yesterday: the group is exploiting the WinRAR path-traversal flaw CVE-2025-8088 as an initial-access vector, using the …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>03 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-03/gamaredon-weaponises-winrar-cve-2025-8088-and-adds-the-gamma/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR</a> · <a href="https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>CVE-2025-48595 — Android Framework: actively-exploited integer-overflow privilege escalation</title><link>https://ctipilot.ch/entries/2026-06-03/cve-2025-48595-android-framework-actively-exploited-integer/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-03/cve-2025-48595-android-framework-actively-exploited-integer/</guid><pubDate>Wed, 03 Jun 2026 05:00:03 +0000</pubDate><dc:date>2026-06-03T05:00:03Z</dc:date><category>vulnerabilities</category><category>actively-exploited</category><category>zero-day</category><category>priv-esc</category><category>mobile</category><category>cisa-kev</category><category>patch-available</category><category>global</category><category>exploited</category><category>cisa-kev</category><category>patch-available</category><category>CVE-2025-48595</category><description><![CDATA[<p>Google patches an actively-exploited, High-severity Android zero-day, CVE-2025-48595, in the June 2026 bulletin — an Android Framework integer overflow giving no-interaction local privilege escalation across Android 14/15/16; Google reports &quot;limited, targeted exploitation&quot; (a profile consistent with commercial-spyware use, though no source attributes this case). Full fix requires the 2026-06-05 patch level (Android Security Bulletin, 2026-06-01).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-03/cve-2025-48595-android-framework-actively-exploited-integer" data-tags="vulnerabilities actively-exploited zero-day priv-esc mobile cisa-kev patch-available" data-regions="global" data-kind="vulnerability" data-priority="high" data-discovered="2026-06-03T05:00:03Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-48595/">CVE-2025-48595</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2025-48595-android-framework-actively-exploited-integer"><a href="https://ctipilot.ch/entries/2026-06-03/cve-2025-48595-android-framework-actively-exploited-integer/">CVE-2025-48595 — Android Framework: actively-exploited integer-overflow privilege escalation</a></h3><p>Google&#39;s June 2026 Android Security Bulletin patches CVE-2025-48595, a High-severity integer overflow in the Android Framework component that Google reports is under &quot;limited, targeted exploitation&quot; (<a href="https://source.android.com/docs/security/bulletin/2026/2026-06-01" target="_blank" rel="noopener noreferrer">Android Security Bulletin, 2026-06-01</a>). The bug gives a local attacker — typically a malicious app already on the device — privilege escalation with no user interaction and no prior privileges, reaching system-level code execution across Android 14, 15, 16 and 16-QPR2 (<a href="https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-02</a>). The &quot;limited, targeted&quot; descriptor and the Framework location are, in our assessment, consistent with the historical pattern of commercial-spyware operators weaponising Framework LPEs against high-value targets — but no cited source attributes this specific case; the full fix requires reaching the 2026-06-05 patch level, which also carries chipset fixes from Qualcomm, MediaTek, Imagination and Unisoc (<a href="https://source.android.com/docs/security/bulletin/2026/2026-06-01" target="_blank" rel="noopener noreferrer">Android Security Bulletin, 2026-06-01</a>). Defenders managing Android fleets: push the 2026-06-05 patch level via MDM/EMM and gate non-compliant devices via Security-Patch-Level compliance policy; disable sideloading and restrict installs to managed stores; this is doubly relevant for Swiss federal device fleets given the G7 Évian travel window (§ 1).</p>
<h4 id="cve-summary-table">CVE Summary Table</h4>
<p>A third actively-exploited CVE added to KEV this window — <strong>CVE-2022-0492</strong>, a Linux cgroup-v1 <code>release_agent</code> container escape — is covered in full in today&#39;s deep dive (§ 5).</p>
<div class="table-wrap"><table>
<thead><tr>
<th style="text-align:left">CVE</th>
<th style="text-align:left">Product</th>
<th style="text-align:left">CVSS</th>
<th style="text-align:left">EPSS</th>
<th style="text-align:left">KEV</th>
<th style="text-align:left">Exploited</th>
<th style="text-align:left">Patch</th>
<th style="text-align:left">Source</th>
</tr></thead><tbody>
<tr>
<td style="text-align:left">CVE-2024-21182</td>
<td style="text-align:left">Oracle WebLogic Server, versions 12.2.1.4.0 / 14.1.1.0.0</td>
<td style="text-align:left">7.5</td>
<td style="text-align:left">high</td>
<td style="text-align:left">yes (2026-06-01)</td>
<td style="text-align:left">yes — unauth T3/IIOP</td>
<td style="text-align:left">Oracle CPU Jul 2024</td>
<td style="text-align:left"><a href="https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html" target="_blank" rel="noopener noreferrer">THN</a></td>
</tr>
<tr>
<td style="text-align:left">CVE-2025-48595</td>
<td style="text-align:left">Android Framework (14/15/16/16-QPR2)</td>
<td style="text-align:left">High</td>
<td style="text-align:left">n/a</td>
<td style="text-align:left">yes (2026-06-02)</td>
<td style="text-align:left">yes — limited, targeted</td>
<td style="text-align:left">2026-06-05 patch level</td>
<td style="text-align:left"><a href="https://source.android.com/docs/security/bulletin/2026/2026-06-01" target="_blank" rel="noopener noreferrer">Android Bulletin</a></td>
</tr>
<tr>
<td style="text-align:left">CVE-2022-0492</td>
<td style="text-align:left">Linux kernel cgroup v1 (&lt; 5.17)</td>
<td style="text-align:left">7.0</td>
<td style="text-align:left">n/a</td>
<td style="text-align:left">yes (2026-06-02)</td>
<td style="text-align:left">yes — container escape</td>
<td style="text-align:left">kernel 5.17+ / distro backport</td>
<td style="text-align:left"><a href="https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA</a></td>
</tr>
</tbody></table></div><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Google&#39;s June 2026 Android Security Bulletin patches CVE-2025-48595, a High-severity integer overflow in the Android Framework component that Google reports is under &quot;limited, targeted exploitation&quot; (Android Security Bulletin, 2026-06-01).</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>03 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-03/cve-2025-48595-android-framework-actively-exploited-integer/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://source.android.com/docs/security/bulletin/2026/2026-06-01" target="_blank" rel="noopener noreferrer">Android Security Bulletin</a> · <a href="https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.helpnetsecurity.com/2026/06/02/android-vulnerability-exploited-cve-2025-48595/" target="_blank" rel="noopener noreferrer">Help Net Security</a></div></article>]]></content:encoded></item><item><title>Sekoia consolidates Gamaredon tooling under GammaPhish / GammaWorm, details an NTFS-ADS USB+network worm</title><link>https://ctipilot.ch/entries/2026-06-02/sekoia-consolidates-gamaredon-tooling-under-gammaphish-gamma/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-02/sekoia-consolidates-gamaredon-tooling-under-gammaphish-gamma/</guid><pubDate>Tue, 02 Jun 2026 05:00:07 +0000</pubDate><dc:date>2026-06-02T05:00:07Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>botnet</category><category>europe</category><description><![CDATA[<p>Sekoia&#39;s Threat Detection &amp; Research team published part one of a Gamaredon (UAC-0010 / ACTINIUM, attributed to Russia&#39;s FSB) series describing a January 2026 campaign against Ukrainian government and military targets, introducing unified naming for two capability clusters: GammaPhish (the funnel from …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-02/sekoia-consolidates-gamaredon-tooling-under-gammaphish-gamma" data-tags="nation-state espionage russia-nexus botnet" data-regions="europe" data-kind="research" data-priority="notable" data-discovered="2026-06-02T05:00:07Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="sekoia-consolidates-gamaredon-tooling-under-gammaphish-gamma"><a href="https://ctipilot.ch/entries/2026-06-02/sekoia-consolidates-gamaredon-tooling-under-gammaphish-gamma/">Sekoia consolidates Gamaredon tooling under GammaPhish / GammaWorm, details an NTFS-ADS USB+network worm</a></h3><p>Sekoia&#39;s Threat Detection &amp; Research team published part one of a Gamaredon (UAC-0010 / ACTINIUM, attributed to Russia&#39;s FSB) series describing a January 2026 campaign against Ukrainian government and military targets, introducing unified naming for two capability clusters: <strong>GammaPhish</strong> (the funnel from spearphishing through GammaLoad deployment) and <strong>GammaWorm</strong> (the propagation layer, subsuming the tooling previously tracked as LitterDrifter / PteroLNK) (<a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR, 2026-06-01</a> · <a href="https://www.infosecurity-magazine.com/news/gamaredon-worm-ntfs-data-streams/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine, 2026-06-01</a>). The chain begins with weaponised xHTML files exploiting CVE-2025-8088 (the WinRAR path-traversal flaw) to drop HTA payloads into Windows Startup directories via <code>mshta.exe</code>. GammaWorm itself is a 20,000+-line obfuscated VBScript worm that persists via scheduled tasks and <code>RunOnce</code>/<code>Run</code> registry keys, hides components in NTFS Alternate Data Streams, propagates across USB and mapped network drives using Ukrainian-language lures, and resolves C2 through dead-drop resolvers on Telegram, Telegra.ph, Teletype.in, Supabase and Cloudflare Workers.</p>
<p><strong>Why it matters to us:</strong> The ADS-hiding + removable-media propagation + legitimate-service dead-drop pattern is highly transferable to any EU public-sector estate. Hunt for <code>mshta.exe</code> spawning <code>wscript.exe</code>, large obfuscated VBScripts executing from <code>%APPDATA%</code>, scheduled tasks with randomised GUID names pointing into user-profile paths, ADS on <code>%TEMP%</code>/<code>%APPDATA%</code> files, and outbound HTTPS to Telegra.ph / Supabase / Workers endpoints from non-developer hosts.</p><div class="prov"><span>research</span><span>02 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-02/sekoia-consolidates-gamaredon-tooling-under-gammaphish-gamma/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR</a> · <a href="https://www.infosecurity-magazine.com/news/gamaredon-worm-ntfs-data-streams/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>Spain arrests doxer who published personal data on INCIBE, prosecutorial and security-service staff</title><link>https://ctipilot.ch/entries/2026-06-02/spain-arrests-doxer-who-published-personal-data-on-incibe-pr/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-02/spain-arrests-doxer-who-published-personal-data-on-incibe-pr/</guid><pubDate>Tue, 02 Jun 2026 05:00:00 +0000</pubDate><dc:date>2026-06-02T05:00:00Z</dc:date><category>data-breach</category><category>law-enforcement</category><category>phishing</category><category>europe</category><description><![CDATA[<p>Spain&#39;s National Police arrested a doxer who published personal data on staff of INCIBE, the State Attorney General, the Civil Guard and the National Security Council (BleepingComputer, 2026-06-01); separately, attackers socially engineered Meta&#39;s AI support chatbot into resetting Instagram passwords, bypassing the account-recovery MFA envelope (Krebs on Security, 2026-06-01).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-02/spain-arrests-doxer-who-published-personal-data-on-incibe-pr" data-tags="data-breach law-enforcement phishing" data-regions="europe" data-kind="incident" data-priority="high" data-discovered="2026-06-02T05:00:00Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="spain-arrests-doxer-who-published-personal-data-on-incibe-pr"><a href="https://ctipilot.ch/entries/2026-06-02/spain-arrests-doxer-who-published-personal-data-on-incibe-pr/">Spain arrests doxer who published personal data on INCIBE, prosecutorial and security-service staff</a></h3><p>Spain&#39;s National Police arrested an individual in Granada on 27 May 2026 for publishing personal data belonging to staff of the State Attorney General&#39;s Office (Fiscalía General del Estado), the National Cybersecurity Institute (INCIBE), the National Police, the Civil Guard and the National Security Council; the operation was overseen by Madrid Investigating Court No. 22 (<a href="https://www.bleepingcomputer.com/news/security/spain-arrests-doxer-leaking-sensitive-data-of-govt-employees/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-01</a> · <a href="https://policia.es/_es/comunicacion_prensa_detalle.php?ID=16895" target="_blank" rel="noopener noreferrer">Policía Nacional, 2026-06-01</a>). The data was published on BreachForums under the &quot;Police-ESP-Doxed&quot; handle. INCIBE has previously assessed that no direct compromise of its systems occurred — the dossiers were assembled from older breaches, credential dumps and OSINT, with some records containing names of staff who had left years earlier. The investigation opened after police detected &quot;mass dissemination&quot; of the data, which they assessed as an immediate risk to the named individuals and institutions.</p>
<p><strong>Why it matters to us:</strong> This is the OSINT-aggregation-plus-prior-breach-enrichment pattern aimed squarely at the personnel of a national cybersecurity authority and security services — a reconnaissance precursor to targeted phishing, vishing and coercion against critical-infrastructure officials. Swiss and EU public-sector security teams should treat circulated staff dossiers as an elevated-phishing trigger and push data-broker opt-out / breach-exposure monitoring for sensitive-role employees.</p><div class="prov"><span>incident</span><span>02 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-02/spain-arrests-doxer-who-published-personal-data-on-incibe-pr/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/spain-arrests-doxer-leaking-sensitive-data-of-govt-employees/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://policia.es/_es/comunicacion_prensa_detalle.php?ID=16895" target="_blank" rel="noopener noreferrer">Policía Nacional press release</a></div></article>]]></content:encoded></item><item><title>Gamaredon — GammaPhish / GammaWorm / GammaSteel: Russian FSB campaign with USB worm and S3 exfiltration (Sekoia TDR part one)</title><link>https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai/</guid><pubDate>Mon, 01 Jun 2026 05:00:20 +0000</pubDate><dc:date>2026-06-01T05:00:20Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>botnet</category><category>europe</category><description><![CDATA[<p>Sekoia&#39;s first part of the Gamaredon series disclosed a January 2026 campaign arc (Sekoia TDR, 2026-06-01; daily 2026-06-02; update daily 2026-06-03). Initial access via CVE-2025-8088 (WinRAR path-traversal, widely unpatched) drops HTA payloads from xHTML attachments.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-01/gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai" data-tags="nation-state espionage russia-nexus botnet" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-01T05:00:20Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai"><a href="https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai/">Gamaredon — GammaPhish / GammaWorm / GammaSteel: Russian FSB campaign with USB worm and S3 exfiltration (Sekoia TDR part one)</a></h3><p>Sekoia&#39;s first part of the Gamaredon series disclosed a January 2026 campaign arc (<a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR, 2026-06-01</a>; <a href="https://ctipilot.ch/briefs/2026-06-02/" target="_blank" rel="noopener noreferrer">daily 2026-06-02</a>; update <a href="https://ctipilot.ch/briefs/2026-06-03/" target="_blank" rel="noopener noreferrer">daily 2026-06-03</a>). Initial access via CVE-2025-8088 (WinRAR path-traversal, widely unpatched) drops HTA payloads from xHTML attachments. GammaWorm&#39;s NTFS-ADS concealment and USB-propagation pattern is the signature detection challenge: filesystem timestamps are useless (ADS hides the worm content), and the worm spreads to any mounted drive and mapped share, meaning air-gap-adjacent workstations remain in scope. GammaSteel exfiltrates collected data directly to S3. Part two of the Sekoia series is outstanding and expected to detail further tooling. Open question: has the campaign reached any EU public-sector estate beyond its primary Ukrainian targets? The USB-propagation vector is exactly the mechanism Luna Moth used this week for physical office intrusion — conceptually distinct actors, coincidentally parallel technique.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR</a></div></article>]]></content:encoded></item><item><title>Gamaredon: GammaPhish → GammaWorm (NTFS ADS + USB) → GammaSteel (S3 exfil) — the week&#39;s most complete intrusion kill-chain disclosure</title><link>https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex/</guid><pubDate>Mon, 01 Jun 2026 05:00:04 +0000</pubDate><dc:date>2026-06-01T05:00:04Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>botnet</category><category>europe</category><description><![CDATA[<p>Monday 2 June brought Sekoia&#39;s part-one Gamaredon series (Sekoia TDR, 2026-06-01), consolidating three capability clusters under unified naming: GammaPhish (the spearphishing-through-GammaLoad funnel), GammaWorm (the USB-and-network-propagation layer), and GammaSteel (the S3-exfiltration stealer confirmed …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex" data-tags="nation-state espionage russia-nexus botnet" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-01T05:00:04Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex"><a href="https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex/">Gamaredon: GammaPhish → GammaWorm (NTFS ADS + USB) → GammaSteel (S3 exfil) — the week&#39;s most complete intrusion kill-chain disclosure</a></h3><p>Monday 2 June brought Sekoia&#39;s part-one Gamaredon series (<a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR, 2026-06-01</a>), consolidating three capability clusters under unified naming: <strong>GammaPhish</strong> (the spearphishing-through-GammaLoad funnel), <strong>GammaWorm</strong> (the USB-and-network-propagation layer), and <strong>GammaSteel</strong> (the S3-exfiltration stealer confirmed in the same campaign arc via Sekoia TDR follow-up, <a href="https://ctipilot.ch/briefs/2026-06-03/" target="_blank" rel="noopener noreferrer">daily 2026-06-03</a>).</p>
<p><strong>Initial access (GammaPhish):</strong> weaponised xHTML files exploiting CVE-2025-8088 (the WinRAR path-traversal flaw, patched but widely unpatched) drop HTA payloads into Windows Startup directories via <code>mshta.exe</code>. <strong>Propagation (GammaWorm):</strong> a 20,000+-line obfuscated VBScript worm persists via scheduled tasks and <code>Run</code>/<code>RunOnce</code> registry keys, hides components in <strong>NTFS Alternate Data Streams</strong>, and spreads across USB drives and mapped network shares using Ukrainian-language lures (<code>T1025</code>, <code>T1091</code>). C2 resolves through dead-drop pages on Telegram, Telegra.ph, Teletype.in, Supabase and Cloudflare Workers — all platforms with high allow-list rates at enterprise egress proxies. <strong>Exfiltration (GammaSteel):</strong> the S3-exfiltration stealer stages and uploads collected data directly to attacker-controlled AWS S3 buckets.</p>
<p>The detection pattern across all three stages is highly transferable to non-Ukraine targets. Hunt for: <code>mshta.exe</code> spawning <code>wscript.exe</code>; large obfuscated VBScripts executing from <code>%APPDATA%</code>; scheduled tasks with randomised GUID names pointing into user-profile paths; NTFS ADS on <code>%TEMP%</code>/<code>%APPDATA%</code> files (<code>dir /r</code> or Sysmon EID 11 for streams); outbound HTTPS to Telegra.ph / Supabase / Workers from non-developer hosts; and anomalous S3-API calls from user endpoints.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR — GammaPhish and GammaWorm</a></div></article>]]></content:encoded></item><item><title>Kimsuky (Velvet Chollima) deploys HTTPSpy RAT and Rust-based HelloDoor via VS Code Remote Tunnel and Cloudflare Quick Tunnel C2</title><link>https://ctipilot.ch/entries/2026-05-30/kimsuky-velvet-chollima-deploys-httpspy-rat-and-rust-based-h/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-30/kimsuky-velvet-chollima-deploys-httpspy-rat-and-rust-based-h/</guid><pubDate>Sat, 30 May 2026 05:00:07 +0000</pubDate><dc:date>2026-05-30T05:00:07Z</dc:date><category>nation-state</category><category>espionage</category><category>north-korea-nexus</category><category>phishing</category><category>apac</category><category>europe</category><category>global</category><description><![CDATA[<p>ENKI WhiteHat and The Hacker News documented Kimsuky campaigns in March and April 2026 targeting South Korean military personnel and corporate entities with two malware chains (The Hacker News, 2026-05-29; ENKI WhiteHat, 2026-05-27).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-30/kimsuky-velvet-chollima-deploys-httpspy-rat-and-rust-based-h" data-tags="nation-state espionage north-korea-nexus phishing" data-regions="apac europe global" data-kind="research" data-priority="notable" data-discovered="2026-05-30T05:00:07Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="kimsuky-velvet-chollima-deploys-httpspy-rat-and-rust-based-h"><a href="https://ctipilot.ch/entries/2026-05-30/kimsuky-velvet-chollima-deploys-httpspy-rat-and-rust-based-h/">Kimsuky (Velvet Chollima) deploys HTTPSpy RAT and Rust-based HelloDoor via VS Code Remote Tunnel and Cloudflare Quick Tunnel C2</a></h3><p>ENKI WhiteHat and The Hacker News documented Kimsuky campaigns in March and April 2026 targeting South Korean military personnel and corporate entities with two malware chains (<a href="https://thehackernews.com/2026/05/kimsuky-deploys-httpspy-expands-arsenal.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-29</a>; <a href="https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant" target="_blank" rel="noopener noreferrer">ENKI WhiteHat, 2026-05-27</a>). March chain: masquerade installers for nProtect Online Security and AhnLab Safe Transaction launch MemLoader.dll via <code>regsvcs.exe</code>, which downloads HTTPSpy. April chain: fake Webex meeting page delivers encrypted JavaScript (<code>.jse</code> extension) which stages a PowerShell downloader, ultimately installing HTTPSpy. HTTPSpy is a full-capability RAT (first observed 2022; previously used against a German defence manufacturer May–September 2024): RC4-encrypted C2, shell execution, file upload/download, screenshot capture, process injection, self-deletion. HelloDoor is a Rust-based PebbleDash variant (assessed LLM-assisted per ENKI): configurable sleep, command execution, directory traversal. C2 evasion: Kimsuky now abuses Visual Studio Code Remote Tunneling (authenticated via GitHub OAuth, registered via <code>code --tunnel --name &lt;name&gt;</code>) and Cloudflare Quick Tunnels (<code>cloudflared.exe</code>) — neither can be blocked by IP or domain without blocking Microsoft and Cloudflare respectively. JSONPing confirms active infections via a locally-running HTTP server, reducing exposure of attacker infrastructure. MITRE ATT&amp;CK: T1036 (Masquerading), T1059.001 (PowerShell), T1059.007 (JavaScript), T1071 (Application Layer Protocol). Detection: hunt for <code>regsvcs.exe</code> as a parent of DLL loads in non-.NET-Framework contexts; alert on VS Code CLI processes with <code>--tunnel</code> argument from non-developer endpoints; audit GitHub OAuth app grants for unrecognised VS Code tunnel registrations; monitor <code>cloudflared.exe</code> on managed endpoints without prior baseline.</p><div class="prov"><span>research</span><span>30 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-30/kimsuky-velvet-chollima-deploys-httpspy-rat-and-rust-based-h/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/05/kimsuky-deploys-httpspy-expands-arsenal.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant" target="_blank" rel="noopener noreferrer">ENKI WhiteHat</a></div></article>]]></content:encoded></item><item><title>ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset</title><link>https://ctipilot.ch/entries/2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na/</guid><pubDate>Sat, 30 May 2026 05:00:06 +0000</pubDate><dc:date>2026-05-30T05:00:06Z</dc:date><category>nation-state</category><category>espionage</category><category>supply-chain</category><category>russia-nexus</category><category>north-korea-nexus</category><category>china-nexus</category><category>europe</category><category>global</category><description><![CDATA[<p>ESET APT Activity Report Q4 2025–Q1 2026: Sandworm wiper targets Polish NATO energy company; Lazarus targets European drone manufacturers; UNC5221 deploys a new SPAWN toolset implant against Ivanti VPN appliances (ESET WeLiveSecurity, 2026-05-28).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na" data-tags="nation-state espionage supply-chain russia-nexus north-korea-nexus china-nexus" data-regions="europe global" data-kind="annual-report" data-priority="high" data-discovered="2026-05-30T05:00:06Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na"><a href="https://ctipilot.ch/entries/2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na/">ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset</a></h3><p>ESET published its APT Activity Report covering October 2025 through March 2026 on 28 May 2026 (<a href="https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity, 2026-05-28</a>). EU- and NATO-relevant findings for public-sector defenders: Sandworm (Russia/GRU) intensified destructive winter operations against Ukrainian infrastructure and targeted a Polish energy company in December 2025 — a NATO member state critical-infrastructure attack attributed with medium confidence; this represents continued Sandworm willingness to conduct wiper operations beyond Ukraine&#39;s borders. Sednit/APT28 deployed Covenant and BeardShell implants against Ukrainian military, drone manufacturers, and logistics companies. Lazarus Group ran Operation DreamJob targeting European drone manufacturers — ESET assesses this as technology acquisition for North Korea&#39;s weapons programme. Operation DangerousPassword compromised the axios JavaScript library (100+ million weekly npm downloads), injecting trojanised code and demonstrating ongoing North Korea supply-chain interest in developer ecosystem targeting. UNC5221 (China-nexus) deployed a new implant assessed as part of the SPAWN toolset, specifically targeting Ivanti VPN appliances (Connect Secure, Policy Secure); organisations running unpatched Ivanti VPN should audit for SPAWN toolset artefacts including SPAWNANT installer, SPAWNMOLE tunneller, SPAWNSNAIL SSH backdoor, and SPAWNSLOTH log-tampering utility. The report PDF is available at <code>https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-apt-activity-report-q4-2025-q1-2026.pdf</code>. Key defender actions: (a) confirm Sandworm wiper detection capability (file-destruction followed by MBR/VBR overwrite patterns, VSS deletion); (b) review Ivanti VPN logs for SPAWN footprints per <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a" target="_blank" rel="noopener noreferrer">CISA AA24-060A</a> indicators; (c) audit npm dependency trees for axios versions &lt;1.8.0 or 0.x released after the DangerousPassword campaign window.</p><div class="prov"><span>annual-report</span><span>30 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-30/eset-apt-activity-report-q4-2025-q1-2026-sandworm-strikes-na/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.infosecurity-magazine.com/news/chinese-hackers-exploit-iran-war/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>GREYVIBE — newly documented Russia-nexus cluster deploys five parallel attack chains against Ukraine with AI-generated lures and two PowerShell RATs</title><link>https://ctipilot.ch/entries/2026-05-30/greyvibe-newly-documented-russia-nexus-cluster-deploys-five/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-30/greyvibe-newly-documented-russia-nexus-cluster-deploys-five/</guid><pubDate>Sat, 30 May 2026 05:00:02 +0000</pubDate><dc:date>2026-05-30T05:00:02Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>ai-abuse</category><category>phishing</category><category>europe</category><category>global</category><description><![CDATA[<p>WithSecure Labs disclosed GREYVIBE on 28–29 May 2026, a previously-unnamed Russia-nexus threat cluster active since at least August 2025, targeting Ukrainian military, government, civilians, and businesses (WithSecure Labs, 2026-05-29; SecurityWeek, 2026-05-28).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-30/greyvibe-newly-documented-russia-nexus-cluster-deploys-five" data-tags="nation-state espionage russia-nexus ai-abuse phishing" data-regions="europe global" data-kind="threat" data-priority="notable" data-discovered="2026-05-30T05:00:02Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="greyvibe-newly-documented-russia-nexus-cluster-deploys-five"><a href="https://ctipilot.ch/entries/2026-05-30/greyvibe-newly-documented-russia-nexus-cluster-deploys-five/">GREYVIBE — newly documented Russia-nexus cluster deploys five parallel attack chains against Ukraine with AI-generated lures and two PowerShell RATs</a></h3><p>WithSecure Labs disclosed GREYVIBE on 28–29 May 2026, a previously-unnamed Russia-nexus threat cluster active since at least August 2025, targeting Ukrainian military, government, civilians, and businesses (<a href="https://labs.withsecure.com/publications/greyvibe" target="_blank" rel="noopener noreferrer">WithSecure Labs, 2026-05-29</a>; <a href="https://www.securityweek.com/russia-linked-greyvibe-attackers-use-ai-to-supercharge-cyberattacks/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-05-28</a>). Five parallel attack chains: PhantomMail (spear-phishing with ZIP/RAR archives via Google Drive and 4sync), PhantomClick (fake CAPTCHA/ClickFix pages impersonating Zoom and LAPAS), PrincessClub (fraudulent adult-club sites with WebRTC-based social engineering), DroneLink (counterfeit Ukrainian Armed Forces charity sites), and Nebo (fake Russian military login portals). Core malware: LegionRelay (PowerShell RAT with file theft, screenshots, credential harvesting, RDP access; RC4 C2 comms), PhantomRelay (PowerShell RAT with dynamic script loading and watchdog persistence), and FallSpy (Android spyware for contact, call log, and geolocation extraction). Four custom obfuscators — LOOKVALPS, LOOKVALJS, DAYLIGHT, TEASOUP — were assessed as LLM-assisted developments. Attribution evidence: Russian-language panels and code comments; C2 servers in UTC+3 (Moscow time); OPSEC failures including public scan-platform uploads. WithSecure identifies possible links to UAC-0098 (former TrickBot associates). MITRE ATT&amp;CK: T1566.001/T1566.002, T1059.001, T1005, T1204.001, T1133. Detection: alert on PowerShell spawned from archive-extraction utility parent processes; hunt scheduled tasks created by PowerShell beaconing to dynamic DNS; Android MDM alerts on sideloaded APKs accessing mic/camera. Organisations supporting Ukrainian government or civil-society counterparts are within the targeting scope.</p><div class="prov"><span>threat</span><span>30 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-30/greyvibe-newly-documented-russia-nexus-cluster-deploys-five/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://labs.withsecure.com/publications/greyvibe" target="_blank" rel="noopener noreferrer">WithSecure Labs</a> · <a href="https://www.securityweek.com/russia-linked-greyvibe-attackers-use-ai-to-supercharge-cyberattacks/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>Nimbus Manticore (UNC1549 / Screening Serpens) — Check Point details MiniFast backdoor, Zoom-task hijacking and SEO-poisoning delivery</title><link>https://ctipilot.ch/entries/2026-05-27/nimbus-manticore-unc1549-screening-serpens-check-point-detai/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-27/nimbus-manticore-unc1549-screening-serpens-check-point-detai/</guid><pubDate>Wed, 27 May 2026 05:00:04 +0000</pubDate><dc:date>2026-05-27T05:00:04Z</dc:date><category>nation-state</category><category>espionage</category><category>iran-nexus</category><category>europe</category><category>middle-east</category><category>us</category><description><![CDATA[<p>UPDATE (originally covered 2026-05-23): Following Unit 42&#39;s coverage of UNC1549 / Screening Serpens AppDomainManager hijacking, Check Point Research (published 2026-05-22, widely re-reported this week) adds material technical depth on three February–April 2026 campaign waves keyed to Operation Epic Fury (Check …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-27/nimbus-manticore-unc1549-screening-serpens-check-point-detai" data-tags="nation-state espionage iran-nexus" data-regions="europe middle-east us" data-kind="threat" data-priority="notable" data-discovered="2026-05-27T05:00:04Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span></div><h3 class="f-h" id="nimbus-manticore-unc1549-screening-serpens-check-point-detai"><a href="https://ctipilot.ch/entries/2026-05-27/nimbus-manticore-unc1549-screening-serpens-check-point-detai/">Nimbus Manticore (UNC1549 / Screening Serpens) — Check Point details MiniFast backdoor, Zoom-task hijacking and SEO-poisoning delivery</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim/">Unit 42 — Iran&#39;s Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name checks in six new RATs</a> <span class="mono muted">(2026-05-23)</span></p><p>Following Unit 42&#39;s coverage of UNC1549 / Screening Serpens AppDomainManager hijacking, Check Point Research (published 2026-05-22, widely re-reported this week) adds material technical depth on three February–April 2026 campaign waves keyed to Operation Epic Fury (<a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/" target="_blank" rel="noopener noreferrer">Check Point Research, 2026-05-22</a>; <a href="https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-26</a>). The IRGC-affiliated actor replaced its MiniJunk family with a new backdoor, MiniFast — a 64-bit DLL with a single <code>CheckForUpdates</code> export and a JSON HTTP C2 using API-style endpoints (<code>/agent/init</code>, <code>/agent/poll</code>, <code>/upload/</code>) and a 14-opcode command set including DLL injection, UAC elevation and scheduled-task persistence.</p>
<p>Two persistence/delivery techniques are new versus the prior coverage: (1) <strong>Zoom scheduled-task hijacking</strong> (<code>T1053.005</code>) — instead of creating a suspicious new task, the malware watches for the legitimate <code>ZoomUpdateTaskUser-&lt;SID&gt;</code> task and hijacks it; (2) <strong>SEO poisoning</strong> (<code>T1598.003</code>) via a fake SQL Developer download domain ranked on Bing/DuckDuckGo, alongside <code>T1574.008</code> AppDomain hijacking via redirected <code>.config</code> files. The loader chain validates <code>parent=svchost.exe</code> before proceeding and abused two SSL.com-issued code-signing certificates (<a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/" target="_blank" rel="noopener noreferrer">Check Point Research, 2026-05-22</a>). Hunt for <code>ZoomUpdateTaskUser-*</code> task modifications by non-Zoom processes, non-default <code>AppDomainManager</code> values in .NET <code>.config</code> files, and execution from user-writable AppData paths.</p><div class="prov"><span>threat</span><span>27 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-27/nimbus-manticore-unc1549-screening-serpens-check-point-detai/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/" target="_blank" rel="noopener noreferrer">Check Point Research, 2026-05-22</a> · <a href="https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-26</a></div></article>]]></content:encoded></item><item><title>GREYVIBE — independent corroboration; OPSEC slips enabled attribution; charity-front sub-campaign</title><link>https://ctipilot.ch/entries/2026-05-25/greyvibe-independent-corroboration-opsec-slips-enabled-attri/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-25/greyvibe-independent-corroboration-opsec-slips-enabled-attri/</guid><pubDate>Mon, 25 May 2026 05:00:25 +0000</pubDate><dc:date>2026-05-25T05:00:25Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>ai-abuse</category><category>phishing</category><category>europe</category><category>russia-cis</category><description><![CDATA[<p>The Russia-nexus GREYVIBE cluster (2026-05-30 daily) gained independent in-window corroboration from SecurityWeek and Security Affairs of the original WithSecure Labs disclosure.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-25/greyvibe-independent-corroboration-opsec-slips-enabled-attri" data-tags="nation-state espionage russia-nexus ai-abuse phishing" data-regions="europe russia-cis" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:25Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="greyvibe-independent-corroboration-opsec-slips-enabled-attri"><a href="https://ctipilot.ch/entries/2026-05-25/greyvibe-independent-corroboration-opsec-slips-enabled-attri/">GREYVIBE — independent corroboration; OPSEC slips enabled attribution; charity-front sub-campaign</a></h3><p>The Russia-nexus GREYVIBE cluster (2026-05-30 daily) gained independent in-window corroboration from SecurityWeek and Security Affairs of the original WithSecure Labs disclosure. The added detail: despite heavy AI integration in lure generation, the operators left <strong>Russian-language code comments and Moscow-timezone activity patterns</strong> that enabled attribution, and the <strong>PrincessClub</strong> sub-campaign masqueraded as Ukrainian-Armed-Forces charitable foundations (FPV-drone / UAV support) to harvest credentials. No expansion beyond Ukrainian targets was found. For CH/EU bodies with Ukraine-linked engagements, the relevant control is spear-phishing scrutiny on charity/fundraising lures referencing military support.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/greyvibe-independent-corroboration-opsec-slips-enabled-attri/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://labs.withsecure.com/publications/greyvibe" target="_blank" rel="noopener noreferrer">WithSecure Labs — GREYVIBE</a> · <a href="https://www.securityweek.com/russia-linked-greyvibe-attackers-use-ai-to-supercharge-cyberattacks/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article>]]></content:encoded></item><item><title>ESET APT Activity Report Q4 2025–Q1 2026 — three state programmes converging on EU energy, defence and edge appliances</title><link>https://ctipilot.ch/entries/2026-05-25/eset-apt-activity-report-q4-2025-q1-2026-three-state-program/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-25/eset-apt-activity-report-q4-2025-q1-2026-three-state-program/</guid><pubDate>Mon, 25 May 2026 05:00:18 +0000</pubDate><dc:date>2026-05-25T05:00:18Z</dc:date><category>nation-state</category><category>espionage</category><category>supply-chain</category><category>russia-nexus</category><category>north-korea-nexus</category><category>china-nexus</category><category>europe</category><category>global</category><description><![CDATA[<p>ESET&#39;s APT Activity Report covering Q4 2025–Q1 2026 landed mid-window (first covered 2026-05-30).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-25/eset-apt-activity-report-q4-2025-q1-2026-three-state-program" data-tags="nation-state espionage supply-chain russia-nexus north-korea-nexus china-nexus" data-regions="europe global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-25T05:00:18Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eset-apt-activity-report-q4-2025-q1-2026-three-state-program"><a href="https://ctipilot.ch/entries/2026-05-25/eset-apt-activity-report-q4-2025-q1-2026-three-state-program/">ESET APT Activity Report Q4 2025–Q1 2026 — three state programmes converging on EU energy, defence and edge appliances</a></h3><p>ESET&#39;s APT Activity Report covering Q4 2025–Q1 2026 landed mid-window (<a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">first covered 2026-05-30</a>). The daily recapped the headline findings — a rare out-of-Ukraine Sandworm destructive incident (a medium-confidence December 2025 attack on a single Polish energy company), Lazarus targeting the EU drone/defence sector, and UNC5221 pivoting to the Ivanti SPAWN toolset. The synthesis a daily reader could not see from those three bullets is that they are the <em>same story told by three different state programmes</em>: Russia-, North-Korea- and China-nexus operators are independently converging on (a) European energy and <strong>defence-industrial-base supply chains</strong> as the target set — Sandworm&#39;s move against a Polish energy target being notable precisely because the operator rarely acts destructively outside Ukraine — and (b) <strong>internet-facing edge appliances</strong> (Ivanti) as the entry vector. For a Swiss / European public-sector SOC the implication is a prioritisation argument rather than a new IOC list: edge-appliance patch SLAs and defence-supplier third-party-risk review are where all three programmes are applying pressure simultaneously, so they should outrank generic campaign awareness in the next planning cycle. The report reinforces, with cross-actor telemetry, the structural shift the W21 Verizon DBIR and Rapid7 reports flagged — exploitation of exposed software as the dominant access vector.</p><div class="prov"><span>annual-report</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/eset-apt-activity-report-q4-2025-q1-2026-three-state-program/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity — APT Activity Report Q4 2025–Q1 2026</a> · <a href="https://www.infosecurity-magazine.com/news/chinese-hackers-exploit-iran-war/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article>]]></content:encoded></item><item><title>Ghostwriter / UAC-0057 / FrostyNeighbor — CERT-UA documents new OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK implant chain via Prometheus learning-platform lures</title><link>https://ctipilot.ch/entries/2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy/</guid><pubDate>Sat, 23 May 2026 05:00:11 +0000</pubDate><dc:date>2026-05-23T05:00:11Z</dc:date><category>nation-state</category><category>espionage</category><category>phishing</category><category>russia-nexus</category><category>europe</category><description><![CDATA[<p>UPDATE (originally covered weekly 2026-W21): CERT-UA published a bulletin (surfaced 2026-05-22) on a spring-2026 phishing campaign by Ghostwriter (a.k.a.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy" data-tags="nation-state espionage phishing russia-nexus" data-regions="europe" data-kind="threat" data-priority="notable" data-discovered="2026-05-23T05:00:11Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy"><a href="https://ctipilot.ch/entries/2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy/">Ghostwriter / UAC-0057 / FrostyNeighbor — CERT-UA documents new OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK implant chain via Prometheus learning-platform lures</a></h3><p><strong>UPDATE (originally covered weekly 2026-W21):</strong> CERT-UA published a bulletin (surfaced 2026-05-22) on a spring-2026 phishing campaign by <strong>Ghostwriter</strong> (a.k.a. UAC-0057, UNC1151, FrostyNeighbor) targeting Ukrainian government entities through lures themed on the Prometheus online-learning platform (<a href="https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-22</a> · <a href="https://www.scworld.com/brief/belarus-linked-ghostwriter-group-targets-ukraine-using-prometheus-learning-platform-lures" target="_blank" rel="noopener noreferrer">SC World, 2026-05-22</a>). The material delta from this week&#39;s weekly long-running coverage of FrostyNeighbor / Ghostwriter activity is a <strong>new three-stage implant trio</strong> distinct from the prior PicassoLoader toolset.</p>
<p>Chain: phishing email from a compromised account → PDF attachment with a link to a ZIP archive → ZIP carrying a JavaScript file (<strong>OYSTERFRESH</strong>). OYSTERFRESH renders a decoy document as cover while writing an obfuscated, RC4-encrypted <strong>OYSTERBLUES</strong> payload to the Windows Registry and launching <strong>OYSTERSHUCK</strong>. OYSTERSHUCK decodes OYSTERBLUES (executed via JavaScript) which then collects computer name, user account, OS version, last boot time and running process list, exfiltrates via HTTP POST to C2, and executes dynamically received JavaScript via <code>eval()</code>. The final payload is assessed as Cobalt Strike. <em>(MITRE ATT&amp;CK overlay added by this brief, not by the CERT-UA narrative as carried by The Hacker News: T1027 Obfuscated Files/Information on the OYSTERFRESH stage, T1547.001 Registry Run Keys on the OYSTERBLUES persistence, T1059.007 JavaScript on OYSTERSHUCK execution, T1219 Remote Access Software on the Cobalt Strike final.)</em></p>
<p>Defender vantage: CERT-UA&#39;s own recommendation is to <strong>block <code>wscript.exe</code> execution for standard user accounts</strong> — a high-yield control because the OYSTER<em> trio relies on script-host execution from user context. EDR signal: <code>wscript.exe</code> spawning <code>powershell.exe</code> or a base64-encoded command; registry monitoring for new <code>HKCU\Software</code> Run-key values containing binary blobs or script paths; hunt for Cobalt Strike beacon signatures in HTTP POST egress to non-corporate domains. The EU/CH relevance is direct: Ghostwriter historically targets Belgium, Germany, Poland, Lithuania, Latvia and other NATO members alongside Ukraine, and the OYSTER</em> implant chain is a toolset upgrade defenders should expect to see surfaced in EU government tenants and Eastern-Europe-focused think tanks.</p><div class="prov"><span>threat</span><span>23 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.scworld.com/brief/belarus-linked-ghostwriter-group-targets-ukraine-using-prometheus-learning-platform-lures" target="_blank" rel="noopener noreferrer">SC World</a></div></article>]]></content:encoded></item><item><title>Unit 42 — ROADtools operationalised by Midnight Blizzard, Curious Serpens and UTA0355 for Entra ID device registration, token theft and tenant enumeration</title><link>https://ctipilot.ch/entries/2026-05-23/unit-42-roadtools-operationalised-by-midnight-blizzard-curio/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-23/unit-42-roadtools-operationalised-by-midnight-blizzard-curio/</guid><pubDate>Sat, 23 May 2026 05:00:07 +0000</pubDate><dc:date>2026-05-23T05:00:07Z</dc:date><category>nation-state</category><category>espionage</category><category>identity</category><category>cloud</category><category>russia-nexus</category><category>iran-nexus</category><category>global</category><category>europe</category><description><![CDATA[<p>Unit 42 documents (2026-05-22) systematic nation-state operationalisation of ROADtools — the open-source Python Entra ID attack/defence framework hosted at github.com/dirkjanm/ROADtools — by three named clusters: Cloaked Ursa / Midnight Blizzard / APT29 / NOBELIUM (Russia), Curious Serpens / Peach …</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-23/unit-42-roadtools-operationalised-by-midnight-blizzard-curio" data-tags="nation-state espionage identity cloud russia-nexus iran-nexus" data-regions="global europe" data-kind="research" data-priority="notable" data-discovered="2026-05-23T05:00:07Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="unit-42-roadtools-operationalised-by-midnight-blizzard-curio"><a href="https://ctipilot.ch/entries/2026-05-23/unit-42-roadtools-operationalised-by-midnight-blizzard-curio/">Unit 42 — ROADtools operationalised by Midnight Blizzard, Curious Serpens and UTA0355 for Entra ID device registration, token theft and tenant enumeration</a></h3><p>Unit 42 documents (2026-05-22) systematic nation-state operationalisation of <strong>ROADtools</strong> — the open-source Python Entra ID attack/defence framework hosted at <code>github.com/dirkjanm/ROADtools</code> — by three named clusters: <strong>Cloaked Ursa / Midnight Blizzard / APT29 / NOBELIUM</strong> (Russia), <strong>Curious Serpens / Peach Sandstorm / APT33</strong> (Iran) and <strong>UTA0355</strong> (Russian state-affiliated) (<a href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-05-22</a>). The chain begins with credential compromise (password spray or OAuth device-code phishing, then uses <code>roadtx</code> to register attacker-controlled devices in the victim&#39;s Entra ID tenant, establishing persistence via a Primary Refresh Token bound to a registered device. The <code>roadrecon</code> module performs systematic directory enumeration via legacy Azure AD Graph API calls — now also ported to the msgraph branch — targeting users, groups, service principals, application permissions and OAuth token grants.</p>
<p>MITRE ATT&amp;CK techniques mapped explicitly by Unit 42: T1098.005 (Account Manipulation: Device Registration), T1550 (Use Alternate Authentication Material), and T1087 (Account Discovery via Microsoft Graph API). The device-PRT-binding step functionally bypasses tenant MFA — the brief leaves the explicit T1556.006 framing off since Unit 42 does not map it that way; defenders running custom ATT&amp;CK overlays may want to add it themselves. Volexity&#39;s April 2025 <a href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/" target="_blank" rel="noopener noreferrer">OAuth device-code paper</a> is the historical background for the device-code half of the chain. Detection vantage: monitor Entra ID audit logs for <code>Add device</code> events from unfamiliar device names or from IPs not in expected employee geographies; alert on sign-in logs carrying the <code>roadtx</code> user-agent string or unexpected <code>https://login.microsoftonline.com/common/oauth2/token</code> device-code grant flows; review Microsoft Graph Activity Logs for bulk <code>GET /users</code>, <code>GET /groups</code> and <code>GET /servicePrincipals</code> calls clustered by time. Hardening: enforce Conditional Access token-protection (token binding renders stolen tokens non-transferable across devices); restrict device registration to compliant or hybrid-joined devices only; enforce Privileged Access Workstation policy for admin token issuance; block Azure AD Graph via <code>blockLegacyAuthentication</code>. Midnight Blizzard has a documented pattern of targeting EU diplomatic corps and government Microsoft 365 tenants, so the relevance to Swiss federal and EU institution Entra estates is direct.</p><div class="prov"><span>research</span><span>23 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-23/unit-42-roadtools-operationalised-by-midnight-blizzard-curio/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/" target="_blank" rel="noopener noreferrer">Unit 42</a> · <a href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/" target="_blank" rel="noopener noreferrer">Volexity OAuth device-code background (2025-04)</a></div></article>]]></content:encoded></item><item><title>Unit 42 — Iran&#39;s Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name checks in six</title><link>https://ctipilot.ch/entries/2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim/</guid><pubDate>Sat, 23 May 2026 05:00:06 +0000</pubDate><dc:date>2026-05-23T05:00:06Z</dc:date><category>nation-state</category><category>espionage</category><category>iran-nexus</category><category>middle-east</category><category>global</category><description><![CDATA[<p>Iran&#39;s Screening Serpens (UNC1549) operationalises AppDomainManager hijacking against aerospace, defence and telecom. Unit 42 documents six new RAT variants (four MiniUpdate, two MiniJunk V2) deployed via legitimate Microsoft .NET binaries paired with weaponised .runtimeconfig.json files that silently disable ETW tracing and strong-name validation before the RAT runs (Unit 42, 2026-05-22).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim" data-tags="nation-state espionage iran-nexus" data-regions="middle-east global" data-kind="research" data-priority="high" data-discovered="2026-05-23T05:00:06Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim"><a href="https://ctipilot.ch/entries/2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim/">Unit 42 — Iran&#39;s Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name checks in six new RATs</a></h3><p>Unit 42 published a comprehensive write-up on <strong>Screening Serpens</strong> (a.k.a. UNC1549, Smoke Sandstorm, Nimbus Manticore) on 2026-05-22 covering operations from February through April 2026 timed to the onset of the U.S.–Israeli Middle East conflict that began 2026-02-28 (<a href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-05-22</a> · <a href="https://www.cybersecuritydive.com/news/iran-cyberattacks-espionage-us-israel-uae/820990/" target="_blank" rel="noopener noreferrer">Cybersecurity Dive, 2026-05-22</a>). The group deployed new RAT variants across two malware families: <strong>MiniUpdate</strong> in four variants used between 2026-03-26 and 2026-04-17 with lures impersonating aviation, healthcare and financial-services firms, and <strong>MiniJunk V2</strong> in two variants used between 2026-02-17 and 2026-03-27 against Middle Eastern and U.S. targets.</p>
<p>The technically significant evolution is <strong>AppDomainManager hijacking</strong> (T1574.014) paired with classic DLL sideloading (T1574.001): the infection chain drops a legitimate Microsoft .NET executable alongside a weaponised <code>UpdateChecker.dll</code> / <code>InitInstall.dll</code> / <code>Updater.dll</code> and — critically — a malicious <code>.runtimeconfig.json</code> that redirects the CLR&#39;s AppDomainManager loading at process startup, <em>silently disabling ETW tracing and strong-name validation before the RAT executes</em>. That leaves the host&#39;s EDR operating in a reduced-telemetry mode on every infected workstation. Delivery is high-touch — fake recruitment PDFs, spoofed video-conference meeting invitations, and ZIP archives containing a legitimate executable as the trigger; persistence uses scheduled tasks; C2 routes through Azure-hosted domains. Confirmed targets: U.S., Israel, UAE, plus at least two further Middle Eastern entities consistent with prior UNC1549 focus on aerospace, defence and telecommunications. The CH/EU nexus is indirect but real — Swiss aerospace and defence suppliers (RUAG, Pilatus and defence export channels) sit squarely in the sector profile, as do EU R&amp;D firms historically swept up in Iranian collection campaigns.</p>
<p>Detection vantage: alert on <code>.runtimeconfig.json</code> writes by non-installer processes; watch the <code>Microsoft-Windows-DotNETRuntime</code> ETW provider for <code>StrongNameVerification=0</code> startup events and CLR debug-mode initialisation; watch scheduled-task creation from processes with <code>.dll</code> parent images loading via <code>rundll32.exe</code> / <code>svchost.exe</code>. Hardening: enforce a code-integrity policy (UMCI + trusted-signers allowlist) so unsigned DLLs cannot load into the .NET CLR; restrict <code>.runtimeconfig.json</code> writes outside install paths via FIM.</p><div class="prov"><span>research</span><span>23 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-23/unit-42-iran-s-screening-serpens-unc1549-smoke-sandstorm-nim/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/" target="_blank" rel="noopener noreferrer">Unit 42</a> · <a href="https://www.cybersecuritydive.com/news/iran-cyberattacks-espionage-us-israel-uae/820990/" target="_blank" rel="noopener noreferrer">Cybersecurity Dive</a></div></article>]]></content:encoded></item><item><title>Kimwolf / &quot;Dort&quot; DDoS-for-hire operator arrested — 30+ Tbps IoT botnet, U.S. DoD-range targeting, AISURU variant</title><link>https://ctipilot.ch/entries/2026-05-23/kimwolf-dort-ddos-for-hire-operator-arrested-30-tbps-iot-bot/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-23/kimwolf-dort-ddos-for-hire-operator-arrested-30-tbps-iot-bot/</guid><pubDate>Sat, 23 May 2026 05:00:01 +0000</pubDate><dc:date>2026-05-23T05:00:01Z</dc:date><category>law-enforcement</category><category>botnet</category><category>ddos</category><category>organized-crime</category><category>global</category><category>us</category><description><![CDATA[<p>Kimwolf / &quot;Dort&quot; arrested in Ottawa — 30+ Tbps DDoS-for-hire infrastructure. Jacob Butler, 23, charged in U.S. and Canada for operating the AISURU-variant Kimwolf botnet; &gt;25,000 attack commands including against DoD IP space; coordinated C2 takedown March 2026 dismantled Kimwolf alongside AISURU/JackSkid/Mossad (KrebsOnSecurity, 2026-05-22).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-23/kimwolf-dort-ddos-for-hire-operator-arrested-30-tbps-iot-bot" data-tags="law-enforcement botnet ddos organized-crime" data-regions="global us" data-kind="threat" data-priority="high" data-discovered="2026-05-23T05:00:01Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="kimwolf-dort-ddos-for-hire-operator-arrested-30-tbps-iot-bot"><a href="https://ctipilot.ch/entries/2026-05-23/kimwolf-dort-ddos-for-hire-operator-arrested-30-tbps-iot-bot/">Kimwolf / &quot;Dort&quot; DDoS-for-hire operator arrested — 30+ Tbps IoT botnet, U.S. DoD-range targeting, AISURU variant</a></h3><p>Canadian authorities (Ontario Provincial Police) arrested Jacob Butler, 23, of Ottawa — alias <strong>Dort</strong> — earlier this week on a U.S. extradition warrant; the U.S. Department of Justice unsealed the criminal complaint in the District of Alaska on <strong>Thursday 2026-05-21</strong> (<a href="https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos" target="_blank" rel="noopener noreferrer">U.S. Department of Justice, 2026-05-21</a> · <a href="https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/" target="_blank" rel="noopener noreferrer">KrebsOnSecurity, 2026-05-22</a> · <a href="https://therecord.media/canadian-man-arrested-charged-running-kimwolf-botnet" target="_blank" rel="noopener noreferrer">The Record, 2026-05-22</a>). Butler is alleged to have developed and operated <strong>Kimwolf</strong>, a DDoS-for-hire botnet assessed as a variant of AISURU. Kimwolf infected primarily consumer IoT — digital photo frames, webcams and other internet-exposed devices — via default credentials and known public CVEs, issued more than 25,000 DDoS attack commands, and peaked at <strong>nearly 30 Tbps</strong> per the DOJ and KrebsOnSecurity (The Hacker News reports the peak as 31.4 Tbps — the discrepancy is between the DOJ-cited figure used in the unsealed complaint and a secondary number cited by THN; treat the DOJ number as the reference for capacity-planning purposes). Targets included U.S. Department of Defense IP ranges and at least one victim with confirmed losses exceeding $1 million per incident. Kimwolf C2 infrastructure was seized 2026-03-19 in a coordinated multi-jurisdiction action alongside three sibling botnets — AISURU, JackSkid and Mossad — collectively infecting &gt;3 million devices.</p>
<p>The complaint also documents that Butler conducted DDoS, doxing and swatting attacks against researchers who investigated him, including Synthient&#39;s Ben Brundage who had helped identify a Kimwolf-exploited vulnerability. Defender takeaway for Swiss and EU operators: the 30 Tbps capability is now demonstrably in range of a single operator&#39;s commercial service, and DDoS-for-hire infrastructure reorganises within weeks of takedowns. Re-baseline ISP scrubbing SLAs against a 10–30 Tbps reference, audit citizen-facing portals&#39; application-layer rate limits, and segment consumer-grade IoT (frames, cameras, NVRs) off any path that touches critical infrastructure or admin networks.</p>
<p><strong>Why it matters to us:</strong> Kimwolf belongs to the IoT-amplification class of botnets that target Swiss/EU public-sector portals; the arrest is an opportunity to re-test scrubbing capacity and IoT segmentation, not to assume the supply has shrunk.</p><div class="prov"><span>threat</span><span>23 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-23/kimwolf-dort-ddos-for-hire-operator-arrested-30-tbps-iot-bot/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos" target="_blank" rel="noopener noreferrer">U.S. Department of Justice press release</a> · <a href="https://krebsonsecurity.com/2026/05/alleged-kimwolf-botmaster-dort-arrested-charged-in-u-s-and-canada/" target="_blank" rel="noopener noreferrer">KrebsOnSecurity</a> · <a href="https://therecord.media/canadian-man-arrested-charged-running-kimwolf-botnet" target="_blank" rel="noopener noreferrer">The Record</a> · <a href="https://thehackernews.com/2026/05/kimwolf-ddos-botnet-operator-arrested.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article>]]></content:encoded></item><item><title>CVE-2026-45585 (YellowKey) — Microsoft formally assigns CVE and publishes WinRE mitigation</title><link>https://ctipilot.ch/entries/2026-05-20/cve-2026-45585-yellowkey-microsoft-formally-assigns-cve-and/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-20/cve-2026-45585-yellowkey-microsoft-formally-assigns-cve-and/</guid><pubDate>Wed, 20 May 2026 05:00:11 +0000</pubDate><dc:date>2026-05-20T05:00:11Z</dc:date><category>vulnerabilities</category><category>no-patch</category><category>poc-public</category><category>global</category><category>poc-public</category><category>mitigation-only</category><category>CVE-2026-45585</category><description><![CDATA[<p>UPDATE (originally covered 2026-05-15): Microsoft formally assigned CVE-2026-45585 to the BitLocker / WinRE bypass disclosed by &quot;Nightmare Eclipse&quot; on 2026-05-12 and confirmed there is still no security update.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-20/cve-2026-45585-yellowkey-microsoft-formally-assigns-cve-and" data-tags="vulnerabilities no-patch poc-public" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-20T05:00:11Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-45585/">CVE-2026-45585</a><span class="b upd">update</span></div><h3 class="f-h" id="cve-2026-45585-yellowkey-microsoft-formally-assigns-cve-and"><a href="https://ctipilot.ch/entries/2026-05-20/cve-2026-45585-yellowkey-microsoft-formally-assigns-cve-and/">CVE-2026-45585 (YellowKey) — Microsoft formally assigns CVE and publishes WinRE mitigation</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-05-15/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-zero-days/">Windows BitLocker &quot;YellowKey&quot; and CTFMON &quot;GreenPlasma&quot; zero-days: public PoC, no patch, TPM-only BitLocker bypassed</a> <span class="mono muted">(2026-05-15)</span></p><p>Microsoft formally assigned <strong>CVE-2026-45585</strong> to the BitLocker / WinRE bypass disclosed by &quot;Nightmare Eclipse&quot; on 2026-05-12 and confirmed there is still no security update. The <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585" target="_blank" rel="noopener noreferrer">MSRC update guide entry, published 2026-05-19</a>, classifies it as CWE-77 (command injection in BitLocker / Windows Recovery Environment), CVSS 6.8 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), with exploit-code maturity rated <code>E:P</code> (proof-of-concept) and remediation level <code>RL:W</code> (workaround only).</p>
<p>Microsoft&#39;s interim mitigation requires per-endpoint work on every device using TPM-only BitLocker (no PIN / password protector): mount the WinRE image, <strong>remove the <code>autofstx.exe</code> entry from the <code>BootExecute</code> registry value inside the WinRE image</strong>, commit the image, then re-establish BitLocker trust for WinRE. The MSRC FAQ states: <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585" target="_blank" rel="noopener noreferrer">&quot;A successful attacker could bypass the BitLocker Device Encryption feature on the system storage device. An attacker with physical access to the target could exploit this vulnerability to gain access to encrypted data.&quot;</a></p>
<p>Practically: for fleets at scale (Swiss federal admin, cantonal endpoints, classified Windows devices), the more durable hardening is to <strong>add a BitLocker PIN or password protector</strong> rather than relying solely on TPM-only. The WinRE registry edit is fragile and breaks on Windows feature updates that re-stage the WinRE image; the PIN/password protector closes the exposure regardless of WinRE state.</p><div class="prov"><span>vulnerability</span><span>20 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-20/cve-2026-45585-yellowkey-microsoft-formally-assigns-cve-and/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585" target="_blank" rel="noopener noreferrer">MSRC CVE-2026-45585, 2026-05-19</a></div></article>]]></content:encoded></item><item><title>Symantec / Carbon Black document Fast16 hook engine targeting LS-DYNA/AUTODYN nuclear-simulation codes; Kim Zetter corrects &quot;pre-Stuxnet&quot; framing to</title><link>https://ctipilot.ch/entries/2026-05-19/symantec-carbon-black-document-fast16-hook-engine-targeting/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-19/symantec-carbon-black-document-fast16-hook-engine-targeting/</guid><pubDate>Tue, 19 May 2026 05:00:06 +0000</pubDate><dc:date>2026-05-19T05:00:06Z</dc:date><category>nation-state</category><category>espionage</category><category>ot-ics</category><category>iran-nexus</category><category>middle-east</category><category>global</category><description><![CDATA[<p>Background. Fast16 — a Lua-based sabotage framework — was first disclosed by SentinelOne at LABScon 2026 in April 2026 and originally framed as a Stuxnet predecessor by approximately two years. Earlier reporting also speculated that the malware operated against physical centrifuge equipment.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-19/symantec-carbon-black-document-fast16-hook-engine-targeting" data-tags="nation-state espionage ot-ics iran-nexus" data-regions="middle-east global" data-kind="research" data-priority="notable" data-discovered="2026-05-19T05:00:06Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="symantec-carbon-black-document-fast16-hook-engine-targeting"><a href="https://ctipilot.ch/entries/2026-05-19/symantec-carbon-black-document-fast16-hook-engine-targeting/">Symantec / Carbon Black document Fast16 hook engine targeting LS-DYNA/AUTODYN nuclear-simulation codes; Kim Zetter corrects &quot;pre-Stuxnet&quot; framing to contemporaneous-and-simulation-sabotage</a></h3><p><strong>Background.</strong> Fast16 — a Lua-based sabotage framework — was first disclosed by SentinelOne at LABScon 2026 in April 2026 and originally framed as a Stuxnet predecessor by approximately two years. Earlier reporting also speculated that the malware operated against physical centrifuge equipment. Both framings now appear incorrect on closer expert review.</p>
<p>Broadcom&#39;s Symantec and Carbon Black teams published a technical analysis on 2026-05-18 documenting the framework&#39;s operating envelope and target selection (<a href="https://www.security.com/blog-post/fast16-nuclear-sabotage" target="_blank" rel="noopener noreferrer">Broadcom Security, 2026-05-18</a>; <a href="https://thehackernews.com/2026/05/pre-stuxnet-fast16-malware-tampered.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-18</a>). The architecture: a service binary embedding an early Lua 5.0 VM; a boot-start filesystem driver intercepting executable code as it is read from disk; and a rule-driven hook engine rewriting specific instruction sequences inside narrowly targeted simulation applications. The hook engine selectively intercepts execution inside LS-DYNA and AUTODYN — the canonical high-explosive simulation codes used for weapons design — and activates only when the simulated material density exceeds 30 g/cm³, the threshold reachable only under implosion shock-compression conditions relevant to weapons-grade uranium. Kim Zetter&#39;s investigative analysis on 2026-05-16 separately corrected the historical framing of the campaign (<a href="https://www.zetter-zeroday.com/experts-confirm-the-fast16-malware-was-sabotaging-nuclear-weapons-tests-likely-in-iran/" target="_blank" rel="noopener noreferrer">Kim Zetter / ZERO DAY, 2026-05-16</a>): Fast16 was contemporaneous with Stuxnet, not a predecessor, and was engineered to feed false output to weapons engineers rather than to physically alter nuclear infrastructure. Defender relevance is narrow but specific: Broadcom appears to describe the first publicly-documented use of a filesystem-driver-level instruction-rewriting hook engine to corrupt scientific-simulation output — a sabotage technique class distinct from data exfiltration, ransomware, or DoS. Operators of national-laboratory research-computing environments, defence-related HPC clusters, and reactor-physics-modelling labs should add filesystem-driver-load monitoring (Sysmon EID 6, Windows boot-start driver enumeration) and integrity checking of long-running simulation binaries to their threat models.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Fast16&#39;s hook engine is selectively interested in high-explosive simulations inside LS-DYNA and AUTODYN, and the malware checks for the density of the material being simulated and only acts when that value passes 30 g/cm³, the threshold uranium can only be reached under the shock compression of an implosion device</p><figcaption class="entry-cite__attr"><a href="https://www.security.com/blog-post/fast16-nuclear-sabotage" target="_blank" rel="noopener noreferrer">Broadcom Security</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Fast16 didn&#39;t predate Stuxnet but was contemporaneous with it. It also wasn&#39;t aimed at altering nuclear weapons but was simply feeding false data to engineers about the nuclear detonation tests they were conducting, in order to trick them into believing the tests were failing</p><figcaption class="entry-cite__attr"><a href="https://www.zetter-zeroday.com/experts-confirm-the-fast16-malware-was-sabotaging-nuclear-weapons-tests-likely-in-iran/" target="_blank" rel="noopener noreferrer">Kim Zetter / ZERO DAY</a></figcaption></figure></div><div class="prov"><span>research</span><span>19 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-19/symantec-carbon-black-document-fast16-hook-engine-targeting/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.security.com/blog-post/fast16-nuclear-sabotage" target="_blank" rel="noopener noreferrer">Broadcom Security</a> · <a href="https://thehackernews.com/2026/05/pre-stuxnet-fast16-malware-tampered.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.zetter-zeroday.com/experts-confirm-the-fast16-malware-was-sabotaging-nuclear-weapons-tests-likely-in-iran/" target="_blank" rel="noopener noreferrer">Kim Zetter / ZERO DAY</a></div></article>]]></content:encoded></item><item><title>CISA contractor (Nightwing) exposed AWS GovCloud admin keys and internal credentials in public GitHub repo for ~6 months</title><link>https://ctipilot.ch/entries/2026-05-19/cisa-contractor-nightwing-exposed-aws-govcloud-admin-keys-an/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-19/cisa-contractor-nightwing-exposed-aws-govcloud-admin-keys-an/</guid><pubDate>Tue, 19 May 2026 05:00:02 +0000</pubDate><dc:date>2026-05-19T05:00:02Z</dc:date><category>data-breach</category><category>supply-chain</category><category>identity</category><category>cloud</category><category>us</category><category>global</category><description><![CDATA[<p>CISA contractor (Nightwing) exposed AWS GovCloud admin keys and internal credentials for ~6 months via public GitHub repo (Krebs on Security, 2026-05-18). GitGuardian found credentials to three GovCloud accounts, plaintext passwords for dozens of internal CISA systems, and the LZ-DSO Artifactory build-package repo; keys validated live 48h after takedown.</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-19/cisa-contractor-nightwing-exposed-aws-govcloud-admin-keys-an" data-tags="data-breach supply-chain identity cloud" data-regions="us global" data-kind="incident" data-priority="high" data-discovered="2026-05-19T05:00:02Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="cisa-contractor-nightwing-exposed-aws-govcloud-admin-keys-an"><a href="https://ctipilot.ch/entries/2026-05-19/cisa-contractor-nightwing-exposed-aws-govcloud-admin-keys-an/">CISA contractor (Nightwing) exposed AWS GovCloud admin keys and internal credentials in public GitHub repo for ~6 months</a></h3><p>A Nightwing government contractor used a public GitHub repository named &quot;Private-CISA&quot; as a personal sync mechanism between work and home machines, exposing highly-privileged credentials for CISA / DHS infrastructure from approximately 2025-11-13 to 2026-05-15 — about six months (<a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/" target="_blank" rel="noopener noreferrer">Krebs on Security, 2026-05-18</a>; <a href="https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330" target="_blank" rel="noopener noreferrer">Gizmodo, 2026-05-19</a>). GitGuardian researcher Guillaume Valadon surfaced the repository on 2026-05-15. Exposed material included administrative credentials for three Amazon AWS GovCloud accounts, plaintext usernames and passwords (<code>AWS-Workspace-Firefox-Passwords.csv</code>) for dozens of internal CISA systems, SSH keys and cloud tokens, and credentials to CISA&#39;s internal Artifactory code-package repository (&quot;LZ-DSO&quot; — Landing Zone DevSecOps). The contractor had deliberately disabled GitHub&#39;s default push-protection secret scanning. Independent researcher Philippe Caturegli (Seralys) validated AWS keys against live GovCloud accounts at high privilege and confirmed the keys remained valid for at least 48 hours after the repository was taken down. CISA acknowledged a ~one-third workforce reduction from buyouts and resignations under the Trump administration may have weakened oversight of contractor behaviour.</p>
<p><strong>Why it matters to us:</strong> Caturegli identified the Artifactory access as the highest-impact exposure — write access to a national cybersecurity agency&#39;s build-package repo would enable backdoor insertion into anything CISA built or deployed (T1195.002 Supply Chain Compromise: Compromise Software Supply Chain). The transferable lesson for EU/CH national CERT operators is independent of US politics: contractors and integrators with write access to NCSC / BSI / ANSSI build pipelines must be subject to organisation-level GitHub push-protection that administrators cannot disable, mandatory short-lived OIDC role assumption (no long-lived AWS keys), Artifactory access-log SIEM integration with off-hours bulk-download anomaly detection, and quarterly secret-scanning sweeps of contractor personal repos under contract. T1552.001 (Credentials In Files) / T1552.004 (Private Keys).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">one of the most egregious government data leaks in recent history</p><figcaption class="entry-cite__attr"><a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/" target="_blank" rel="noopener noreferrer">Krebs on Security</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature</p><figcaption class="entry-cite__attr">Guillaume Valadon / GitGuardian via Krebs on Security</figcaption></figure></div><div class="prov"><span>incident</span><span>19 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-19/cisa-contractor-nightwing-exposed-aws-govcloud-admin-keys-an/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/" target="_blank" rel="noopener noreferrer">Krebs on Security</a> · <a href="https://gizmodo.com/the-worst-leak-that-ive-witnessed-u-s-cybersecurity-agency-leaves-its-digital-keys-out-in-public-on-github-2000760330" target="_blank" rel="noopener noreferrer">Gizmodo</a></div></article>]]></content:encoded></item><item><title>Screening Serpens / UNC1549 (Iran; Smoke Sandstorm / Nimbus Manticore) — AppDomainManager hijacking in six new RATs</title><link>https://ctipilot.ch/entries/2026-05-18/screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-18/screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic/</guid><pubDate>Mon, 18 May 2026 05:00:32 +0000</pubDate><dc:date>2026-05-18T05:00:32Z</dc:date><category>nation-state</category><category>espionage</category><category>iran-nexus</category><category>middle-east</category><category>global</category><description><![CDATA[<p>Unit 42 detailed Screening Serpens using AppDomainManager hijacking to silently disable ETW and strong-name verification across six newly-documented RATs (daily 2026-05-23).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-18/screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic" data-tags="nation-state espionage iran-nexus" data-regions="middle-east global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:32Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic"><a href="https://ctipilot.ch/entries/2026-05-18/screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic/">Screening Serpens / UNC1549 (Iran; Smoke Sandstorm / Nimbus Manticore) — AppDomainManager hijacking in six new RATs</a></h3><p>Unit 42 detailed Screening Serpens using <strong>AppDomainManager hijacking</strong> to silently disable ETW and strong-name verification across six newly-documented RATs (<a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>). The ETW-blinding plus strong-name-check bypass is the detection-relevant tradecraft — it defeats both behavioural telemetry and signature-trust controls in one step. Where AppDomainManager-redirection is not required by an application, monitor for the <code>appDomainManagerAssembly</code> / <code>appDomainManagerType</code> config and environment-variable hijack vectors.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/" target="_blank" rel="noopener noreferrer">Unit 42 — Screening Serpens</a> · <a href="https://www.cybersecuritydive.com/news/iran-cyberattacks-espionage-us-israel-uae/820990/" target="_blank" rel="noopener noreferrer">Cybersecurity Dive</a></div></article>]]></content:encoded></item><item><title>Midnight Blizzard and others operationalise ROADtools for Entra ID abuse</title><link>https://ctipilot.ch/entries/2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en/</guid><pubDate>Mon, 18 May 2026 05:00:31 +0000</pubDate><dc:date>2026-05-18T05:00:31Z</dc:date><category>nation-state</category><category>espionage</category><category>identity</category><category>cloud</category><category>russia-nexus</category><category>iran-nexus</category><category>global</category><category>europe</category><description><![CDATA[<p>An unusually active espionage week — Webworm pivoted to EU government targets (Graph/OneDrive C2), Midnight Blizzard and others operationalised ROADtools against Entra ID, and Iran&#39;s Screening Serpens used AppDomainManager hijacking to blind ETW. (daily 2026-05-21; daily 2026-05-23)</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en" data-tags="nation-state espionage identity cloud russia-nexus iran-nexus" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-05-18T05:00:31Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="midnight-blizzard-and-others-operationalise-roadtools-for-en"><a href="https://ctipilot.ch/entries/2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en/">Midnight Blizzard and others operationalise ROADtools for Entra ID abuse</a></h3><p>Unit 42 documented systematic nation-state operationalisation of the open-source <strong>ROADtools</strong> Entra ID framework by Midnight Blizzard, Curious Serpens and UTA0355 for device registration, token theft and tenant enumeration (<a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>). This is the most broadly relevant item in the section — every M365/Entra tenant is in scope. Hunt for unexpected device-registration events, anomalous service-principal token requests, and ROADtools-characteristic enumeration patterns; tighten conditional-access on device-registration and review legacy-auth exposure.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/" target="_blank" rel="noopener noreferrer">Unit 42 — ROADtools cloud attacks</a> · <a href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/" target="_blank" rel="noopener noreferrer">Volexity — OAuth device-code background</a></div></article>]]></content:encoded></item><item><title>Ghostwriter / UAC-0057 / FrostyNeighbor (Belarus-aligned) — new OYSTER implant chain</title><link>https://ctipilot.ch/entries/2026-05-18/ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst/</link><guid isPermaLink="true">https://ctipilot.ch/entries/2026-05-18/ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst/</guid><pubDate>Mon, 18 May 2026 05:00:30 +0000</pubDate><dc:date>2026-05-18T05:00:30Z</dc:date><category>nation-state</category><category>espionage</category><category>russia-nexus</category><category>europe</category><description><![CDATA[<p>CERT-UA documented a spring-2026 phishing campaign deploying a new OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK implant chain via Prometheus learning-platform lures (daily 2026-05-23).</p>]]></description><content:encoded><![CDATA[<article class="finding entry-card" data-entry-id="2026-05-18/ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst" data-tags="nation-state espionage russia-nexus" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:30Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst"><a href="https://ctipilot.ch/entries/2026-05-18/ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst/">Ghostwriter / UAC-0057 / FrostyNeighbor (Belarus-aligned) — new OYSTER implant chain</a></h3><p>CERT-UA documented a spring-2026 phishing campaign deploying a new <strong>OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK</strong> implant chain via Prometheus learning-platform lures (<a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>). The campaign continues the actor&#39;s focus on Ukrainian and allied government organisations; the staged implant chain is the new tradecraft. For EU/CH government estates that share the actor&#39;s target profile, the relevant control is attachment-detonation and learning-platform-lure awareness for staff.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html" target="_blank" rel="noopener noreferrer">The Hacker News — Ghostwriter / CERT-UA</a></div></article>]]></content:encoded></item></channel></rss>