Welcome to Security Signals
Every two weeks, we bring you expert insights and handpicked articles covering the latest threats, threat actor activity, vulnerabilities, incident trends, and defensive strategies. Whether you’re on the front lines or shaping your organization’s security posture, Security Signals delivers the information you need to stay informed and ready.
For more articles, check out our #onpatrol4malware blog.
Our Latest Blog Post
August 2026 Edition
Key stats from real-world telemetry and live attack observations over the past month – a concise look at what we’re seeing across malware, phishing, ransomware, C2s, and domain abuse.
Insights (TL;DR)
To help maximize your time, these insights summarize the most common attacker behaviors, techniques, and defensive themes observed across the articles featured below.
Top ATT&CK Techniques Observed
T1566 – Phishing: ClickFix campaigns, fake tax documents, job-themed lures, device-code phishing, malicious downloads, and targeted spearphishing remained common initial-access methods.
T1071 – Application Layer Protocol: Attackers used legitimate and less-monitored services for C2 and payload delivery, including Telegram, MQTT, GitHub, Google-hosted infrastructure, and blockchain smart contracts.
T1195 – Supply Chain Compromise: Developer and software-distribution channels remained frequent targets, including malicious RubyGems and Packagist packages, compromised dependencies, browser extensions, and third-party service compromises.
What Matters Most
Abuse of trusted infrastructure appeared across many campaigns. Attackers used public code repositories, cloud services, messaging platforms, blockchain networks, compromised websites, browser extensions, and legitimate remote-access tools to conceal malware delivery and C2 traffic.
Credential and information theft remained prominent, alongside ransomware, mobile threats, banking malware, and espionage campaigns targeting government, enterprise, financial, and developer environments.
What Defenders Should Watch
- ClickFix, job-themed lures, device-code phishing, and fake software or document downloads
- C2 and payload delivery through cloud services, messaging platforms, blockchain networks, and unusual protocols
- Unexpected packages, dependencies, browser extensions, remote-access tools, and software updates
- Credential or session-token theft followed by account access, persistence, or lateral movement
Key Insight: Attackers repeatedly placed malicious activity inside services and software that organizations already trust, making behavior and context more useful detection signals than reputation alone.
Articles
Mid September 2026 Cyber Threat Reports highlight attackers’ continued use of trusted services and software to conceal malicious activity. This edition of Security Signals covers ClickFix and device-code phishing, blockchain- and cloud-based C2, compromised packages and dependencies, new RATs and stealers, ransomware, mobile threats, and espionage campaigns targeting enterprise and government environments.
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Source: Cisco Talos Blog
(September 8, 2026)
Cisco Talos has recently observed a criminal campaign that leveraged an interesting twist on what we refer to as “legitimate service abuse.” In this monthslong… Read more.
HVNC Backdoor Targets LATAM Organizations with Fake Tax Lures
Source: ANY.RUN’s Cybersecurity Blog
(September 8, 2026)
Fake tax documents are being used to target organizations across LATAM, delivering a custom HVNC backdoor built for stealthy, persistent access. Read more.
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures
Source: Seqrite Labs
(September 8, 2026)
MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. Read more.
Peeling Back the Layers: Inside Vidar – From Virtualized Code to Stolen Credentials
Source: Splunk
(September 8, 2026)
Vidar has earned a reputation as one of the most persistent information stealers in today’s threat landscape. Read more.
The Job Offer Has Claws: Mirage Kitten Deploys NodeRabbit and PollCat
Source: PolySwarm
(September 8, 2026)
Kaspersky discovered the activity while investigating Mirage Kitten infections and identified an initial NodeRabbit sample on a system in Afghanistan. Read more.
[Op Report] Hands-on-Keyboard Activity from the DPRK “PolinRider” Supply Chain Attack — Deception.Pro Blog
Source: Deception.Pro Blog
(September 9, 2026)
For one week at the end of August 2026, a Fortune 500 enterprise CTI team stood up a decoy corporate workstation and waited. Read more.
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Source: Cisco Talos Blog
(September 9, 2026)
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. Read more.
ClearFake 2026
Source: Malware Analysis
(September 9, 2026)
Here I will walk through finding recent ClearFake infected sites and discuss how to extract and follow the code that ultimately copies a malicious command… Read more.
Death by a Thousand PaperCuts: AI-Driven Exploitation at Scale
Source: Blackpoint Cyber
(September 9, 2026)
The Adversary Pursuit Group (APG) uncovered a PaperCut exploitation campaign while investigating malicious activity involving an internet facing PaperCut server. Read more.
Deep-Live-Cam Supply Chain Attack: Technical Analysis
Source: SafeDep – Real-time Open Source Software Supply Chain Security
(September 9, 2026)
On September 8, 2026, an attacker added a malicious source dependency to Deep-Live-Cam, a Python face swapping application with 96,600 GitHub stars. Read more.
Grand Theft Auto VI hype leads to malware | Huntress
Source: Huntress
(September 9, 2026)
There’s still three months until the release of Grand Theft Auto VI (GTA6), but the internet has already reached a fever pitch thanks to a… Read more.
KATARU: IoT Malware Adopts Public LPE Exploits
Source: https://www.nozominetworks.com/
(September 9, 2026)
KATARU is an IoT malware sample observed in a recent honeypot compromise through Telnet credential brute forcing. Read more.
Koktevrat – wieloetapowy Android RAT dystrybuowany pod przykrywk? aplikacji MandatGO
Source: CERT Orange
(September 9, 2026)
Nieistniej?ca aplikacja rz?dowa, reklama na Facebooku i obietnica prostego sposobu na op?acenie mandatu. Read more.
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data
Source: Socket
(September 9, 2026)
Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data. Read more.
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration
Source: Zimperium, Inc.
(September 9, 2026)
The zLabs research team has discovered a sophisticated and highly aggressive mobile malware strain linked to Indonesian threat actors, that marks a dangerous tactical evolution… Read more.
Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows
Source: Volexity
(September 9, 2026)
On September 1, 2026, Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers… Read more.
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days
Source: Proofpoint
(September 9, 2026)
Beginning in late August and continuing into September 2026, Proofpoint identified multiple espionage-motivated threat actors rapidly adopting the BlueMoon exploit kit in targeted spearphishing campaigns. Read more.
Passkey-themed social engineering leads to identity and cloud compromise
Source: Microsoft Security Blog
(September 9, 2026)
Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph… Read more.
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence | Huntress
Source: Huntress
(September 9, 2026)
The Huntress Security Operations Center (SOC) recently came across two interesting variants of the same attack involving a browser-in-the-browser (BiTB) phishing technique. Read more.
ShieldCrash: Testing the Claimed Microsoft Defender Zero-Day
Source: Cyderes.com
(September 9, 2026)
Nightmare-Eclipse is a single researcher operating under a rotating set of handles. Read more.
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
Source: Unit 42
(September 9, 2026)
A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of… Read more.
Vwork: Weaponized Open-source Software as an Addon for Gigabud
Source: Group-IB
(September 9, 2026)
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders. Read more.
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329 | Wiz Blog
Source: wiz.io
(September 10, 2026)
Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities affecting JFrog Artifactory: CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329. Read more.
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | FortiGuard Labs
Source: Fortinet Blog
(September 10, 2026)
FortiGuard Labs examines how a new Casbaneiro campaign targeting Latin America uses geofencing and distributed servers to evade analysis and detection… Read more.
EquationGroup’s MiniLoader
Source: Exatrack
(September 10, 2026)
In this article, we examine a relatively small, concise, and extremely clean malicious code that we consider very likely linked to an entity belonging to… Read more.
From a Pension-Themed Spear-Phishing Email to a GitHub-Backed Implant: Investigating a SideWinder Connection — Malware INFO Blog
Source: Malwareinfo
(September 10, 2026)
An evidence-led investigation traces a Myanmar pension lure from an encrypted Word attachment to an embedded implant and evaluates its overlap with regional SideWinder reporting. Read more.
Gray Rabbits and the Tale of a One-Click Backdoor
Source: Gen Digital Inc.
(September 10, 2026)
Gen Threat Labs discovered a critical remote code execution vulnerability (CVE-2026-51990) in Sogou Input Method, one of the most widely used Chinese-language input method editors… Read more.
Inside Two Multi-Stage Attack Chains Hiding Behind Job Offers
Source: Cyderes.com
(September 10, 2026)
Job-themed social engineering has become one of the most productive initial access routes in criminal operations, and it is worth being precise about why. Read more.
Malware Melofee: New Versions of Linux Implant
Source: Stormshield
(September 10, 2026)
Melofee came back, and it just evolved! Read more.
Protecting organizations from AI-assisted executive impersonation and invoice fraud | Microsoft Security Blog
Source: Microsoft Security Blog
(September 10, 2026)
Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent… Read more.
Remus: A New Infostealer Hunting Wallets, Passwords, and AI Credentials
Source: SpyCloud
(September 10, 2026)
Remus is one of several infostealer threats SpyCloud Labs is tracking as criminals adapt their tooling. Read more.
SloppyRAT: A New Tool For Ransomware Attacks | ThreatLabz
Source: Zscaler
(September 10, 2026)
In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. Read more.
Analysis of the Liquid Network Cache Key Collision Vulnerability: Nearly 4,000 L-BTC Minted Out of Thin Air
Source: SlowMist
(September 11, 2026)
At 13:52:10 UTC on September 6, two transactions with the same structure appeared in Liquid block 4,050,335. Read more.
BraZetsu: AI-Enhanced Reconnaissance Fuels Exilware’s Access Marketplace
Source: PolySwarm
(September 11, 2026)
Group-IB has identified BraZetsu, a Python-based Windows malware framework attributed with high confidence to the Brazilian threat actor Exilware. Read more.
Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit
Source: Sysdig
(September 11, 2026)
AI is lowering the barrier to entry for attackers; that much is settled. Read more.
Panzer: New Cross-Platform RaaS Claims Global Victims in Its First Month Panzer: New Cross-Platform RaaS Claims Global Victims in Its First Month
Source: Hivepro
(September 11, 2026)
A newly emerged Ransomware-as-a-Service operation listed 20+ victims across 10+ countries in its first month, with an ESXi build that can encrypt an entire hypervisor… Read more.
Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service
Source: Socket
(September 11, 2026)
A Twitch browser extension on Chrome and Firefox forwards users’ live OAuth session tokens through proxies controlled by a Russian bot service. Read more.
“Eye” Spy: Cyclops Blink Returns With Extended Capabilities
Source: Sophos
(September 11, 2026)
In August 2026, Counter Threat Unit™ researchers analyzed a malicious 64-bit Linux executable named timezone_check that was discovered on multiple compromised Cisco Firewall Management Center… Read more.
Behind the CAPTCHA: ClickFix, WallStealer and a Hidden Miner
Source: Ctrl-Alt-Intel
(September 12, 2026)
Static analysis of a ClickFix collection reveals WallStealer payloads, Steam-based C2 discovery and an XMRig mining chain sharing the delivery IP. Read more.
Fake Tax-Themed Phishing Campaign Delivers Malware – CYFIRMA
Source: CYFIRMA
(September 12, 2026)
CYFIRMA has identified a multi-domain malware distribution campaign abusing the Indian Income Tax Department theme to deliver a malicious payload. Read more.
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
Source: Acronis
(September 13, 2026)
Acronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing… Read more.
Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
Source: Wordfence
(September 14, 2026)
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin… Read more.
HBO Max ads on a compromised Reddit account exposed a massive PasteSwitch ClickFix operation
Source: InfoStealers
(September 14, 2026)
Through joint research conducted by Hudson Rock and Kirk from ADAMnetworks (with additional thanks to Tuxxin from Whack.sh and Emiliano from The Matrix Project), we… Read more.
Malicious browser extension: inside KREMLIN banking malware
Source: Elastic
(September 14, 2026)
Elastic Security Labs tracked this malicious browser extension across seven campaigns and 15 months, through Brazilian bank lures and the Ethereum smart contracts that hold… Read more.
GhostCode: Dissecting a Novel Device Code Phishing Kit
Source: eSentire
(September 15, 2026)
eSentire’s TRU uncovers GhostCode, a novel device code phishing kit using AES-256-GCM encryption and triple-layer HTML obfuscation to bypass MFA and hijack Microsoft 365 accounts… Read more.
Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware
Source: Huntress
(September 15, 2026)
Many Black Hat and DEFCON attendees come home to an inbox full of DMs. Read more.
Illegal Gambling Sites Reveal Three Types of Cybercrime
Source: Infoblox Blog
(September 15, 2026)
Many security teams ignore online gambling and casino domains, especially Chinese-language websites. Read more.
Mythic C2 Activity at Internet Scale – Censys
Source: Censys
(September 15, 2026)
Mythic was created as a successor to an earlier macOS-focused project (Apfell). Read more.
New packages identified in GemStuffer ‘OpenAI Swarm’ malicious RubyGems campaign
Source: JFrog Security Research
(September 15, 2026)
JFrog Security Research is actively monitoring the recent GemStuffer incident, and using our extensive Catalog of RubyGems artifacts, managed to identify 3,022 campaign-associated RubyGems packages… Read more.
PAPERMILL: Tracking an Emerging China-Nexus Malware Factory | JUMPSEC
Source: JUMPSEC
(September 15, 2026)
JUMPSEC’s Detection and Response Team (DART) recently escalated a phishing email after it reached a client’s inbox despite passing standard email authentication checks. Read more.
PhantomRaven: LLM-generated Information Stealer for Bug Bounty Hunting
Source: CrowdStrike.com
(September 15, 2026)
CrowdStrike identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript-based information stealer PhantomRaven. Read more.
Proliferation of Coruna and DarkSword
Source: iVerify
(September 15, 2026)
Explore how Coruna and DarkSword iOS exploit kits are evolving, proliferating, and being combined to expand mobile attack capabilities in the wild. Read more.
Silent Push Tracks a Mass Phishing Operation Through Fast Flux
Source: Silent Push
(September 15, 2026)
While the “fast flux” technique of rapidly rotating a domain’s DNS records across many IP addresses and networks to avoid detection is not new, it… Read more.
The banana stand: brokering and managing infections across Asia using MQTT
Source: Lumen
(September 15, 2026)
Black Lotus Labs®, the threat research division at Lumen, uncovered BambooToken, an emerging malware family using the Message Queueing and Telemetry Transport (MQTT) to quietly… Read more.
Brevo supply chain attack hits 100k+ sites with WordPress backdoors and Clickfix malware
Source: Sansec
(September 16, 2026)
The recent Brevo security incident is much larger than reported. Read more.
Discernment Deleted: Inside the Operation Server of BlackHatSect0r && DXQRTXX
Source: SOCRadar
(September 16, 2026)
An operation server belonging to the crew that brands itself BlackHatSect0r && DXQRTXX was left open to the internet. Read more.
Hunting Feral Wolf: New Tools and Techniques
Source: BI.ZONE
(September 16, 2026)
The threat actor uses backdoors that masquerade C2 communications as legitimate MQTT and Matrix traffic, impeding detection and extending dwell time. Read more.
NightEagle APT targets Russian organizations
Source: Securelist
(September 16, 2026)
Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (also tracked as APT-Q-95) . Read more.
Operation RapidRust: New APT36 Malware Tools
Source: Zscaler
(September 16, 2026)
In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust . Read more.
Private HTS programs that spread ransomware – ASEC
Source: ASEC
(September 16, 2026)
AhnLab SEcurity intelligence Center (ASEC) recently identified a case in which ransomware was distributed through a private home trading system (HTS). Read more.
RatHat: AI-Powered Mobile Threat is Here for Your Credentials & Bank Accounts
Source: Zimperium, Inc.
(September 16, 2026)
The zLabs team has uncovered RatHat , a novel Android malware strain linked to threat actors that appear to be operating in China. Read more.
When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Source: Cloudflare Blog
(September 16, 2026)
A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with analytics, or asking a… Read more.
Beware the SparroWock: The backdoor that bites, the commands that catch
Source: Welivesecurity
(September 17, 2026)
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group Read more.
Chatbot Conundrum: Phishing Attempts of OpenAI’s ChatGPT
Source: Cofense
(September 17, 2026)
As generative AI tools like OpenAI’s ChatGPT become increasingly common, their large user bases create new opportunities for threat actors. Read more.
EtherHiding Exposed: Inside a Blockchain-powered Malware Campaign Hiding in Plain Sight
Source: GuidePoint Security
(September 17, 2026)
This is our deep dive into how we tracked cybercriminals using cryptocurrency infrastructure to build a bulletproof command-and-control network and how we unraveled… Read more.
HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack
Source: Group-IB
(September 17, 2026)
Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Read more.
How a Malware-as-a-Service Platform Used GitHub as a Distribution Channel
Source: LastPass
(September 17, 2026)
On August 13, 2026, the LastPass TIME Team identified a fraudulent GitHub organization impersonating LastPass Authenticator which redirected visitors to attacker-controlled infrastructure… Read more.
LausivLoader analysis, or how to pass data between malware stages
Source: SANS Internet Storm Center
(September 17, 2026)
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. Read more.
MovieReaper: Trojan attack via movie torrents, including “The Odyssey”
Source: Securelist
(September 17, 2026)
Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Read more.
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Source: Socket
(September 17, 2026)
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads. Read more.
Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMM | Huntress
Source: Huntress
(September 17, 2026)
Huntress analysts recently observed two incidents where a newer ransomware variant, Settra, was deployed. Read more.
SideCopy Threat Intel: MSHTA-driven Execution and RAT Deployment
Source: Trellix
(September 17, 2026)
The modern cyber warfare landscape has evolved significantly as threat actors pivot toward simple yet highly effective and evasive malware. Read more.
The Alert Gap: Hunting an Undetected Device Code Phishing Compromise
Source: CyberProof
(September 17, 2026)
Device code phishing bypasses conventional controls because, technically, it is legitimate authentication. Read more.
Threat Snapshot: LabubaRAT
Source: Blackpoint Cyber
(September 17, 2026)
LabubaRAT is a custom, unsigned 64-bit Rust-based remote access trojan (RAT) identified by the Blackpoint Adversary Pursuit Group (APG), designed to masquerade as legitimate NVIDIA… Read more.
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
Source: OpenSourceMalware
(September 17, 2026)
WeaselBiscuit is a lean new infostealer hiding in npm that we suspect was created by DPRK Read more.
ChainScript: Tracing a Node.js RAT Through the Blockchain
Source: Blackpoint Cyber
(September 18, 2026)
Blackpoint’s Adversary Pursuit Group (APG) identified and analyzed a previously unnamed Node.js remote access trojan, now being tracked as ChainScript . Read more.
From Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain – K7 Labs
Source: K7 Labs
(September 18, 2026)
We had an opportunity to analyse a system with frequent detection-alerts over powershell execution. Read more.
Why Does an npm Math Library Need an Encrypted Loader?
Source: SafeDep – Real-time Open Source Software Supply Chain Security
(September 18, 2026)
We found a loader for encrypted code inside [email protected] , an npm mathematics library. Read more.
Threat Intelligence | Analysis of FomoPeek App Store Poisoning and iOS Kernel Exploitation
Source: SlowMist
(September 20, 2026)
Recently, the SlowMist security team received multiple reports of user assets being stolen. Read more.
Want more articles? Check out the previous edition of Security Signals here.
Free Evaluation
Gain a comprehensive view of the external cyber landscape with Malware Patrol’s Cyber Threat Intelligence (CTI) services. We cover a broad spectrum of malicious activities, including malware, ransomware, phishing, cryptominers, newly registered domains, and command-and-control servers to equip your organization with the insights needed to proactively detect and mitigate potential attacks.
Take advantage of a free trial to test our data for yourself.