Authors: Nitish Singh, Nikhil Kumar Chadha, and Tanmay Kumar
Introduction:
The Monthly Intelligence Insights report provides a summary of top threats curated, monitored, and analyzed by Securonix Threat Watch in August 2026. The report also includes a synopsis of the threats, indicators of compromise (IoCs), tactics, techniques, and procedures (TTPs), and related tags. Each threat has a comprehensive summary from Threat Labs and search queries from the Threat Research team. For additional information on Threat Labs and related search queries used via Autonomous Threat Sweeper to detect the below-mentioned threats, refer to our Threat Labs home page.
Last month, Securonix Autonomous Threat Sweeper identified and analyzed 4,312 TTPs and IoCs; identified 124 emerging threats; investigated 65 potential threats; and elevated 16 incidents. The top data sources swept against include IDS / IPS / UTM / Threat Detection, Data Loss Prevention, Endpoint Management Systems, and Email / Email Security.

Executive Summary:
-
SMOKE#SCREEN: Securonix Threat Research uncovered a multi-wave campaign using Zoom updates, business documents, system checks, and Adobe-themed lures to silently deploy ScreenConnect RMM agents across Windows and macOS. The operators rotate VBScript, batch, and .NET loaders, abuse trusted services such as Dropbox and Cloudflare Quick Tunnels, and disable security controls before installing signed ScreenConnect clients that connect to attacker-controlled relays for persistent remote access.
-
Operation GitPower: Kimsuky continued its established spear-phishing, malicious LNK, PowerShell, scheduled-task persistence, and GitHub-based C2 tradecraft while building a local AI development environment. Researchers found Ollama, GPT4All, Msty, RAG components, AI development frameworks, and speech-to-text tooling, suggesting the group is incorporating AI into phishing content, malware development, document analysis, and intelligence processing.
-
Operation Dream Job: DPRK-linked Lazarus targeted defense, aerospace, and aviation organizations with fake job offers, trojanized PDF viewers, and crafted PDF files that delivered MISTPEN and the newly identified Troy backdoor. The campaign exploited the Windows AFD.sys zero-day CVE-2026-68820 to run FudModule with SYSTEM privileges and reduce EDR visibility, while compromised Roundcube and WordPress servers hosting RelayShell supported its command-and-control infrastructure.
-
CoolClient: HoneyMyte upgraded its long-running backdoor with a signed kernel-mode Windows driver that adds rootkit capabilities for hiding and protecting malicious processes, files, and registry entries. Intrusions observed in Pakistan, Mongolia, and Myanmar used PlugX, Microsoft Defender exclusions, a fake Windows Defender directory, Sangfor DLL sideloading, scheduled-task persistence, and process injection before deploying the msagent.sys driver and final CoolClient implant.
-
C2Looper: C2Looper is a Rust-based backdoor associated with ransomware-related activity and may be distributed through multi-stage ClickFix infection chains. It supports remote command execution, reconnaissance, payload delivery, and code injection. Newer variants use GitHub for C2 communications, tasking, command results, and exfiltrated data, allowing attackers to maintain access and deploy additional tooling or ransomware.
-
Evooo1Bot: Evooo1Bot is a modular Linux botnet that extends the Mirai DDoS engine with encrypted C2, SSH brute forcing, credential theft, interactive shell access, vulnerability exploitation, and SOCKS proxying. It targets internet-facing edge devices through known vulnerabilities and uses several persistence methods. Compromised routers, firewalls, and other Linux systems can also be used as proxy nodes for further attacks.
-
DeadLock: DeadLock is an emerging double-extortion ransomware operation that uses a Rust-based encryptor and decentralized infrastructure for victim communication, negotiation, and data leaks. Its capabilities include resource-aware encryption, event-log clearing, selective file targeting, and a self-contained recovery portal. The use of decentralized services makes parts of its extortion infrastructure less dependent on traditional servers.
-
Interlock: The GOLD EMBRACE ransomware operators continued double-extortion activity against large organizations, particularly in North America and Europe, using ClickFix lures, custom remote-access tooling, and recently disclosed vulnerabilities. In one investigated intrusion, the attackers abused Volatility3 and WinPmem for credential extraction, followed by LDAP discovery, Kerberoasting, lateral movement, scheduled-task persistence, data theft, and eventual loss of access to the victim's hypervisors.
-
CVE-2026-18577: Attackers exploited an authentication-bypass vulnerability in N-able N-central to gain unauthenticated administrative control of vulnerable RMM servers. Post-exploitation activity used N-central's Take Control capability and Cloudflare Tunnel for persistent remote access, creating a path to downstream systems managed through affected deployments; N-able's 2026.3.1 Hotfix 2 supersedes the original fix and requires urgent deployment.
-
Access For Sale: A Russian-speaking initial access broker carried out large-scale exploitation of internet-facing appliances across more than a dozen countries. The operator used public and modified exploits, web shells, SOCKS tunneling, stolen NTLM hashes, and Active Directory compromise to gain access that could later be sold or transferred to other threat actors. Separate activity used Sliver C2 to collect data from Ukrainian defense and aerospace organizations.
-
Clop: Clop exploited CVE-2026-12569 in PTC Windchill and deployed a custom web shell built for data theft and extortion. The implant can identify sensitive vault data, decrypt application and LDAP credentials, exfiltrate files, and execute additional Java code in memory. This gives attackers the ability to expand beyond the compromised application into credential theft, lateral movement, persistence, and possible ransomware deployment.
Threat Overview:
Securonix Threat Research Highlights:
- SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures
Securonix Threat Research identified SMOKE#SCREEN, an active multi-wave campaign that uses fake Zoom updates, business documents, system-check utilities, and Adobe update pages to deliver ScreenConnect remote monitoring and management agents on Windows and macOS. The delivery chain includes obfuscated VBScript droppers, batch scripts, compiled .NET loaders, HTML phishing pages, Dropbox links, and Cloudflare Quick Tunnels. Investigators linked 15 payloads to an exposed WsgiDAV staging server at 207.174.0[.]143:8080, which also hosted a ScreenConnect relay on port 8041. Across the different delivery methods, the objective was consistent: silently install ScreenConnect and establish persistent remote access that could blend into legitimate IT activity.
The tooling varies in how aggressively it interacts with security controls. Some early scripts use XOR-encrypted VBScript along with memory and process checks, and terminate when they detect low-memory systems or analysis tools such as Wireshark, Process Monitor, VirtualBox services, VMware Tools, XenService, or Fiddler. Other variants use WMI to create hidden processes, bypass AMSI, request UAC elevation, weaken SmartScreen, add Microsoft Defender exclusions, remove Mark-of-the-Web metadata, and launch ScreenConnect installers through msiexec. Compiled C# loaders expanded these capabilities into a nine-step Defender neutralization sequence that included excluding the entire C:\ drive and stopping or disabling WinDefend. Later activity shifted to a less disruptive loader that introduced a 180-second delay, apparently intended to interfere with Elastic event-correlation windows. This change suggests the operator was adjusting execution behavior in response to defensive controls.
The final payload is a legitimate ScreenConnect client with ConnectWise-signed components and a valid DigiCert certificate chain. Once installed, it connects as a guest-access session to attacker-controlled relays at 207.174.0[.]143, 142.202.191[.]225, or blog.derrspecial-onlinedmin[.]live. This provides remote desktop access while using software that may otherwise appear legitimate. The campaign also rotates payload hashes, uses port 80 as a fallback, relies on trusted services for file delivery, and includes a macOS PKG variant tied to the same infrastructure. As a result, file hashes, code-signing status, or domain reputation alone may not provide enough context. Detection should focus on behavior such as unauthorized RMM installation, silent msiexec execution, Defender modification, unusual ScreenConnect connections to raw IP addresses, hidden PowerShell or WMI activity, and delays between installation and service startup.
Analyst assessment: The main concern with SMOKE#SCREEN is the use of ScreenConnect as a legitimate remote-access product within an intrusion chain. The campaign combines trusted software lures, Dropbox and Cloudflare infrastructure, rotating payload hashes, security-control tampering, and valid signed installers. The tooling also changes over time, including a move from aggressive Defender neutralization to delayed execution that appears intended to reduce the effectiveness of event correlation. Individual events may look like normal administrative activity, but the combined sequence is more consistent with unauthorized remote-access deployment.
Detection and investigation should therefore prioritize unauthorized RMM installation, unusual parent-child process relationships, security-tool modification, silent MSI execution, delayed service startup, and ScreenConnect communication with unapproved relay infrastructure. Hashes, filenames, signatures, and domain reputation should be treated as supporting indicators rather than the primary basis for detection.
Defender priority: Review cases where wscript.exe, cscript.exe, or WMI Win32_Process launches hidden PowerShell commands, especially when the initiating files are presented as Zoom updates, business documents, Adobe updates, or system-check utilities.
Alert on PowerShell activity that disables AMSI, stops or disables WinDefend, changes SmartScreen policies, adds C:\ or TEMP to Microsoft Defender exclusions, removes Zone.Identifier data, or launches msiexec.exe with the /qn option.
Investigate connections to the identified SMOKE#SCREEN staging and relay infrastructure, including:
-
207.174.0[.]143 on ports 8080 and 8041
-
142.202.191[.]225 on ports 8041 and 80
-
blog.derrspecial-onlinedmin[.]live
ScreenConnect agents using the e=Access&y=Guest configuration, unauthorized ConnectWise-signed installers, or a roughly three-minute delay between installation and service startup should receive priority during triage.
Malware: GitHub C2 & Linux Proxy Botnets:
- Evooo1Bot turns exploited Linux edge devices into persistent proxies and attack nodes
Active since at least July 2026, Evooo1Bot compromises internet-facing routers, cameras, firewalls, and operational-technology devices through known vulnerabilities. Observed exploitation delivered 91.92.40[.]118/wget.sh, which selects one of 12 architecture-specific binaries using wget, BusyBox, curl, or TFTP, executes it from a temporary path, and clears Bash history. Campaign labels embedded in download commands indicate the operator tracks infection results by vulnerability.
The Mirai-derived Linux malware adds encrypted C2 over TCP 443, interactive shell and file-transfer functions, credential and HTTP header sniffing to /tmp/.sniff.log, SSH brute forcing, 16 DDoS methods, and an integrated exploit dispatcher. Its SOCKS5 module exposes TCP 1080 or creates an encrypted reverse relay, enabling traffic proxying and possible access into internal networks. The !persist command simultaneously installs systemd, SysV init, cron, /etc/profile.d/, and rc.local persistence; the bot also modifies /proc/self/oom_score_adj and holds /dev/watchdog open. Some exploits embedded in the malware are incorrectly implemented and are not functional as shipped.
Analyst assessment: The proxy and credential-access functions are more consequential than the reused Mirai DDoS code. They allow compromised edge devices to conceal follow-on activity and potentially provide access beyond the device itself. Broad vulnerability coverage and SSH credentials targeting service accounts suggest an opportunistic effort spanning consumer, enterprise, and OT environments; reporting does not establish victim numbers or a specific actor.
Defender priority: Hunt first for requests to 91.92.40[.]118/wget.sh following exploitation of CVE-2007-3010, CVE-2016-6277, CVE-2018-14558, CVE-2019-14931, CVE-2020-10987, CVE-2021-46422, CVE-2022-37055, CVE-2024-29269, CVE-2025-10123, or CVE-2025-55583. On exposed Linux devices, inspect systemd and SysV services masquerading as an “Apache HTTPD Cache Manager,” five-minute download crons, /etc/profile.d/ and rc.local changes, /tmp/.sniff.log, unexpected TCP 1080 listeners, and non-HTTPS C2 traffic over TCP 443.
- C2Looper moves its backdoor operations to GitHub and expands payload execution
C2Looper is a Rust-based Windows backdoor first identified in July 2026 and is likely associated with ransomware-related activity. It may also be delivered through a multistage ClickFix infection chain, although confidence in that assessment remains low to medium. Earlier variants use plaintext HTTP for C2, beacon to /api/beacon, execute commands through cmd.exe, return shell output, and download additional payloads. One update routine places wtsapi32.dll in %LocalAppData%\Microsoft\OneDrive\, stops OneDrive, and uses the legitimate OneDrive executable to sideload the malicious DLL.
C2Looper v2 uses GitHub instead of direct HTTP for C2. It creates a separate repository directory for each infected host and uses cmd.json, result.json, and beacon.json for tasking, command output, and check-ins. The newer variant can enumerate files and drives, perform domain reconnaissance, download payloads to %TEMP%, and inject shellcode into the text section of winspool.drv before starting a new thread. Earlier variants were seen downloading v2, suggesting the malware remains under active development.
Analyst assessment: GitHub provides trusted infrastructure for both control traffic and exfiltrated output, making domain-based blocking less practical. The malware itself is relatively simple, but its reconnaissance, payload staging, and execution capabilities could support lateral movement and ransomware deployment. The reporting links C2Looper to ransomware only probabilistically; it does not confirm a ransomware payload, named operator, victim population, or completed impact.
Defender priority: Prioritize EDR hunts for OneDrive.exe loading an unexpected %LocalAppData%\Microsoft\OneDrive\wtsapi32.dll, creation of %LocalAppData%\pld.exe or c2_out.txt, and suspicious modification or execution within winspool.drv. Review proxy and endpoint telemetry for one-second HTTP POSTs to /api/beacon, /api/result/<bot_id>/<task_id> traffic involving 45.158.196[.]23:8888 or 45.158.196[.]184:8888, and repetitive GitHub access involving cmd.json, result.json, and beacon.json. Correlate these indicators with ipconfig /all, whoami /all, nltest /dclist, domain-group discovery, and wmic product execution.
APT: AI, Rootkits & Recruitment Lures
- Operation Dream Job: Lazarus Group Uses Fake Recruitment Lures to Deploy In-Memory Backdoors
Operation Dream Job is a targeted campaign linked to the DPRK-associated Lazarus Group and has been active since at least early 2026. The campaign has targeted organizations in the defense, aerospace, government, education, and logistics sectors across South America, Western Europe, and India. Attackers use fake job offers and recruitment documents to convince victims to open or download malicious PDF viewers. Two main infection methods have been identified: DLL side-loading and a trojanized PDF viewer. In both cases, the malware uses a legitimate-looking PDF document as a decoy while malicious code executes in the background.
The main payload, MISPten, runs largely in memory and uses Microsoft Graph API and OneDrive for communication and payload delivery. It collects system information, running processes, and screenshots. MISPten can also exploit CVE-2026-68820 to obtain SYSTEM-level privileges and deploy the FudModule rootkit. The campaign also uses ForestTiger, a backdoor that supports remote access, command execution, file operations, and in-memory payload delivery. Another infection chain uses a modified SecurityPDF viewer that presents itself as a legitimate PDF application. When a victim opens a specially crafted PDF, the viewer decrypts and executes the embedded payload while displaying a legitimate-looking job document.
The campaign also uses the Troy Backdoor, which provides capabilities for system and process enumeration, command execution, file upload and download, file deletion, process termination, and in-memory DLL injection. Attackers have also compromised Roundcube, WordPress, and other web servers and used RelayShell to relay communications between compromised servers and infected systems.
Analyst assessment: The campaign relies on convincing job-related lures and modified PDF viewers to gain access while making the activity appear legitimate. DLL side-loading and in-memory execution reduce the visibility of the malicious payload, while Microsoft Graph API and OneDrive are used for communication and payload delivery. After gaining access, the attackers can collect host information, exploit CVE-2026-68820 to obtain SYSTEM-level privileges, and deploy backdoors such as ForestTiger and Troy Backdoor for continued remote access and command execution. Compromised web servers used through RelayShell provide additional relay infrastructure and can make command-and-control activity harder to trace.
Defender priority: Prioritize detection of suspicious PDF viewers such as SecurityPDF.exe and DLL side-loading through applications presented as legitimate PDF tools. Pay particular attention to cases where the application displays a decoy document while decrypting and executing an embedded payload.
Monitor for MISPten, ForestTiger, and Troy-like in-memory execution, along with unexpected Microsoft Graph or OneDrive activity from unusual processes. Investigate suspicious access to compromised web infrastructure associated with the campaign.
Ensure systems are patched against CVE-2026-68820 and investigate activity involving afd.sys exploitation, particularly when followed by SYSTEM-level execution or activity associated with FudModule.
- Kimsuky adds local AI capability to Operation GitPower without changing its core intrusion pattern
Kimsuky's Operation GitPower activity continues to follow the group's established espionage playbook. The campaign targets South Korean policy organizations, academia, diplomatic missions, military entities, security researchers, and virtual asset organizations through spear-phishing emails carrying ZIP archives with malicious LNK files. Execution launches obfuscated PowerShell and displays a legitimate-looking decoy document. Researchers also found indicators that Kimsuky is using generative AI to produce some of these decoys, particularly financial, investment, and business-themed documents.
Once execution is achieved, the operators use PowerShell to create scheduled-task persistence and pull additional payloads from GitHub. AsyncRAT payloads were encrypted and stored under filenames resembling image files. GitHub therefore provides Kimsuky with both a readily available hosting platform and traffic that can be difficult to distinguish from legitimate developer activity. The use of Base64 encoding, fragmented URLs, custom decoding routines, string splitting, and hidden PowerShell is consistent with an effort to make the delivery chain harder to inspect while keeping the underlying technique relatively simple.
What separates this activity from earlier Kimsuky reporting is the amount of AI-related tooling present in the operator environment. Researchers identified Ollama, GPT4All, Msty, GPT4All LocalDocs, Microsoft Semantic Kernel, LangChain components, OpenAI integration packages, GPU acceleration libraries, and Whisper-based speech-to-text tooling. The combination of local LLM platforms and RAG capability suggests the operators are preparing to use AI against data they control locally, including collected documents, rather than treating generative AI only as a service for writing phishing emails. The report associates this environment with possible malware development, intelligence processing, automation, and document analysis.
Analyst assessment: Kimsuky's core attack chain has not materially changed. Spear phishing, malicious LNK files, PowerShell, scheduled tasks, GitHub-hosted infrastructure, and living-off-the-land techniques remain central to the operation. The change is in the supporting workflow. Local AI tools could shorten the time required to prepare lures, modify malicious code, analyze collected information, and adjust campaigns. Defenders should therefore expect faster changes in payloads and phishing content even when the underlying execution, persistence, and C2 behavior remains recognizable.
Defender priority: Hunt for LNK files executed from downloaded ZIP archives, obfuscated or encoded PowerShell, and scheduled tasks created shortly after document execution. Review unusual PowerShell or endpoint connections to GitHub content, particularly where files presented as images are downloaded, decoded, or executed. Detection should focus on the full behavior chain rather than individual payload hashes because AI-assisted development may allow the operators to change malware and supporting infrastructure more frequently while continuing to use established Kimsuky TTPs.
- HoneyMyte adds a Windows kernel rootkit to the CoolClient backdoor
HoneyMyte, also known as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode driver, giving the malware a much stronger ability to remain hidden after compromise. CoolClient has previously been used for keylogging, clipboard theft, credential collection, file management, reconnaissance, and plugin-based functionality. The newer variant adds driver-assisted process hiding and protection for files and registry objects and the updated variant has been observed in Myanmar, Mongolia, Pakistan, and Russia, including government environments.
In the Myanmar activity, HoneyMyte used PlugX as the initial post-compromise implant before moving to CoolClient. Before deployment, the operators added Microsoft Defender exclusions for a fake Windows Defender directory and its renamed loader. They then copied CoolClient into that directory and renamed a legitimate Sangfor executable to defender.exe, which sideloaded the malicious libngs.dll. A scheduled task launched defender.exe with SYSTEM privileges at startup.
CoolClient uses a multi-stage infection chain in which libngs.dll decrypts and loads loadcert.ini, which handles persistence, privilege elevation, process injection, and deployment of the msagent.sys kernel driver. Execution then moves into synchost.exe, where the malware installs the driver and injects the final cert.ini backdoor, while persistence is maintained through the goopdate AutoRun value and the media_updaten service. Once loaded, msagent.sys receives the CoolClient process ID, C2 address, installation path, and service registry path through IOCTL requests and uses this information to protect or hide malicious processes, files, registry objects, and kernel modules. The driver also hooks Nsiproxy to filter registered C2 addresses from network information returned to user-mode applications, reducing the visibility of active connections during host-based investigation.
Analyst assessment: HoneyMyte appears to be treating CoolClient as a deeper post-compromise capability rather than an initial access implant. PlugX provides the first operational foothold, after which CoolClient is deployed with several layers of persistence, injection, privilege handling, and now kernel-level concealment. The driver is the important development. Once active, it can interfere with the same process, filesystem, registry, and network visibility defenders depend on during investigation. This means an apparently clean host view cannot be treated as strong evidence that CoolClient is absent. The use of a legitimate Sangfor executable for DLL sideloading, a fake Microsoft Defender path, and a signed driver also gives the operation several opportunities to blend malicious activity with artifacts that may initially appear legitimate. The report assesses the new variant as HoneyMyte activity and notes that the PlugX-to-CoolClient deployment pattern is consistent with previous campaigns.
Defender priority: Start with endpoints showing unexpected Microsoft Defender exclusions, particularly exclusions created for C:\Program Files\Microsoft\Windows Defender\ or a defender.exe inside that path. Hunt for defender.exe or Sang.exe loading libngs.dll, startup tasks launching the sideloader as SYSTEM, the goopdate Run value, and the media_updaten service. Treat the presence or attempted installation of msagent.sys as a high-priority finding and review associated entries under HKLM\SYSTEM\RNG, including the driver's hiding and protection configuration. Also investigate unexpected execution of synchost.exe, especially where it follows Sang.exe or defender.exe activity. Because msagent.sys can hide processes, registry entries, files, modules, and selected C2 addresses, validation should include telemetry collected outside normal host enumeration where available.
Ransomware: ClickFix & Decentralized Extortion:
- DeadLock combines resource-aware encryption with decentralized recovery infrastructure
DeadLock is an emerging double-extortion ransomware operation first observed in July 2025. It has been deployed by multiple threat groups, including an affiliate linked to the Lynx and INC ransomware ecosystems. By July 2026, its leak site listed more than 80 victims across several sectors and regions, with more than half in Europe. Public reporting does not establish how attackers initially gained access.
The Rust-based encryptor stops security, backup, Active Directory, Hyper-V, remote-access, and cloud-sync services before encryption. It clears recycle bins and Windows event logs, disables event channels under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels, and restricts access to logging data. DeadLock uses Curve25519 and XChaCha20 with unique per-file keys and applies intermittent encryption to larger files. Encrypted files receive the .<UID>.dlock extension. To avoid overwhelming the host, it pauses new encryption work when CPU usage rises above 70% or memory usage exceeds 29%.
Victim communication is handled through a self-contained RECOVERY_CHAT.<UID>.html application. It retrieves mutable configuration from Polygon smart contracts, routes encrypted negotiations through the Session network, and links victims to stolen data stored on Wasabi-compatible object storage.
Analyst assessment: DeadLock’s cryptography does not expose a practical recovery path without the operator’s private key. Its main differentiator is the decentralized extortion ecosystem, which improves resilience but is not takedown-proof: negotiations still depend on an operator-controlled proxy, public Polygon RPC access, and off-chain storage. Language geofencing suggests an effort to avoid selected former Soviet, CIS-linked, and Middle Eastern environments, but does not establish operator location.
Defender priority: Hunt for mass creation of *.<UID>.dlock, HOW_RECOVER.<UID>.txt, RECOVERY_CHAT.<UID>.html, and <UID>.bmp or <UID>.ico under C:\ProgramData. Alert on broad service termination, recycle-bin emptying, registry changes setting event-log Enabled values to 0, restrictive ChannelAccess modifications, and deletion loops launched from randomly named eight-character .cmd files. Network monitoring should identify recovery pages issuing Polygon eth_call requests to contracts 0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe and 0x757984507c82c8dA1d3969c535dB5706eEE6426C, followed by Session proxy or Wasabi storage access.
- Interlock weaponizes ClickFix and forensic memory tools before domain-wide extortion
Interlock is a double-extortion operation active since September 2024 that mainly targets North American and European organizations in critical infrastructure, healthcare, and education. The group appears to be run by a small team that develops and deploys its own tooling rather than operating through a ransomware-as-a-service model. Its activity includes ClickFix delivery, the NodeSnake or Interlock RAT, PHP-based persistence, Windows and FreeBSD encryptors, and exploitation of CVE-2026-20131 in Cisco Secure Firewall Management Center.
In a March 2026 intrusion, a user searching for Dynamics 365 reached a compromised legitimate website hosting a ClickFix lure and pasted a command into the Windows Run dialog. PowerShell then retrieved additional code and installed a RAT with startup persistence. Within roughly 26 hours, the attackers carried out LDAP discovery, Kerberoasting, credential theft, and RDP-based lateral movement to a domain controller. They later created \Microsoft\Windows\Defrag\ScheduledDefrags on a print server to run debug.log through node.exe as SYSTEM. The intrusion also involved WinPmem and Volatility3 for memory capture and credential extraction, followed by AWS credential theft, creation of new domain administrator accounts, security-tool tampering, data exfiltration, and hypervisor lockout.
Analyst assessment: The incident shows that Interlock’s advantage lies less in its encryptor than in a hands-on intrusion chain combining social engineering, trusted tooling, credential abuse, and gaps in endpoint coverage. Volatility3 and WinPmem can resemble legitimate DFIR activity, making execution context and authorization critical. In this case, incomplete endpoint protection and unusable backups materially increased the impact.
Defender priority: Prioritize detections for winpmem_mini_x64_rc2.exe mem.raw, vol.exe -f .\mem.raw windows.hashdump.Hashdump, and windows.cachedump.Cachedump outside approved forensic work. Hunt for wildcarded PowerShell paths launched from Run, connections to voginc[.]com, afshapiro[.]com, 104.236.109[.]139, browser-updater[.]com, or 216.203.20[.]36/debug.log, and the ScheduledDefrags task executing Node.js from systemprofile\AppData\Roaming\node-v22.11.0-win-x64\. Correlate these artifacts with Kerberos service-ticket spikes, anonymous or downgraded NTLM authentication to domain controllers, unauthorized domain-admin creation, security-control changes, and access to hypervisor management systems.
Active Exploitation of Enterprise Infrastructure:
- Active exploitation of N-central authentication bypass puts MSP and enterprise environments at risk
CVE-2026-18577 is an authentication bypass vulnerability affecting N-central, a Remote Monitoring and Management platform used by MSPs and enterprise IT teams. Exploitation was observed from August 1, 2026, after an earlier fix for CVE-2026-18556 did not fully address the issue. A successful exploit can give an unauthenticated remote attacker administrative control of the N-central server. In observed intrusions, attackers used the platform's Take Control capability to access managed endpoints and deployed Cloudflare Tunnel to maintain remote access. The vulnerability was added to the Known Exploited Vulnerabilities catalog on August 3, and a subsequent hotfix replaced the initial remediation.
Analyst assessment: Compromise of an N-central server can have a wider impact than compromise of a single internet-facing application. The platform holds administrative access to managed systems, giving an attacker a direct route to downstream endpoints after the initial breach. In an MSP environment, that access may extend across multiple customer networks. Observed use of Take Control and Cloudflare Tunnel also means attackers can operate through legitimate remote-access mechanisms that may already be trusted or permitted in the environment.
Defender priority: Apply the latest security update to affected on-premises deployments and upgrade managed agents after patching. Any system that was exposed to the internet before remediation should be reviewed for compromise. Hunt for unexpected cloudflared services, suspicious svchost.exe files in user Documents directories, unusual Take Control sessions, administrative account changes, and newly created Windows services. Historical network telemetry should also be reviewed against indicators associated with the observed exploitation activity.
- Russian-speaking access broker links mass exploitation and ransomware access sales with Ukraine-focused intelligence collection
A Russian-speaking initial access broker was observed exploiting internet-facing infrastructure across more than a dozen countries. The operator used a mix of public and modified exploits against enterprise security appliances, networking products, remote-access services, collaboration platforms, and web applications. Victims included organizations in education, healthcare, financial services, telecommunications, government, and managed services. After initial access, the operator harvested credentials, deployed web shells, established tunnels, moved laterally into Windows environments, and in some cases gained full Active Directory control. Several of the compromised organizations were later listed by different ransomware groups within weeks of the intrusion.
The same infrastructure was also used against Ukrainian defence and aerospace organizations. Activity included Sliver C2 deployment, theft of exposed Git repositories, screenshots from remote desktop services, and imagery collected from internet-facing IP cameras. The available evidence supports high confidence that the actor is a Russian-speaking initial access broker. The Ukraine-focused activity is assessed with moderate-to-high confidence as state-nexus intelligence collection, but it is unclear whether the operator was directly tasked, working under contract, or collecting information for later sale.
Analyst assessment: The operator appears to focus on establishing and maintaining access rather than conducting ransomware deployment or extortion. Activity generally stops after exploitation, credential theft, tunnelling, and lateral movement. The later appearance of victims on different ransomware leak sites is consistent with access being transferred or sold to separate criminal groups. The Ukraine-focused activity also shows that the same foothold can be reused for a different purpose, including intelligence collection or surveillance.
Defender priority: Reduce direct internet exposure of administrative interfaces and prioritize patching known exploited vulnerabilities across production, development, staging, and disaster-recovery systems. If device configurations may have been accessed or stolen, rotate administrative, LDAP, RADIUS, and service-account credentials stored on those systems. Where Active Directory compromise is suspected, review for domain-level persistence and reset the krbtgt password twice with a full replication interval between resets. Restrict WinRM, disable LLMNR and NBT-NS, enforce SMB signing, and investigate unfamiliar administrative logins, injected SSH keys, backdoor accounts, and internal connections originating from perimeter appliances.
- Clop returns to mass exploitation with an application-specific web shell built for credential theft and data exfiltration
Clop has resumed mass exploitation activity through CVE-2026-12569, a critical remote code execution vulnerability affecting an enterprise product lifecycle management platform. The group is assessed with high confidence to be using a custom web shell built around the targeted application's internal architecture. Once deployed, the implant can decrypt credentials stored in the application keystore, map files held in application vaults, transfer data, and load additional Java code directly into the application process. This allows the operator to move from initial access to credential theft and data exfiltration with little reliance on external post-exploitation tooling.
The web shell provides more than basic command execution. It can recover LDAP and administrative credentials in plaintext, creating a possible route into other systems where those credentials are trusted or reused. Its custom Java class loader can execute attacker-supplied bytecode directly in memory, giving the operator a way to add capabilities for lateral movement, persistence, malware deployment, or encryption. The implant also queries vault data through the application's own database context, so some malicious activity may appear under the application's normal service identity.
Analyst assessment: The activity is consistent with Clop's previous mass-extortion campaigns, where exploitation of enterprise software is followed by tooling designed specifically for the affected application. In this case, the implant's knowledge of the application's APIs, keystore, database schema, and vault structure gives the operator a direct path to credentials and sensitive files. It also makes detection harder because the activity does not always resemble a generic web shell or an external database connection. Commands are carried in the X-windchill-req HTTP header, responses are GZIP compressed, and activity can remain inside the application's trusted process.
Defender priority: Apply the security update for CVE-2026-12569 and limit unnecessary internet exposure of affected systems. Hunt application codebase directories for recently created or modified JSP files and references to X-windchill-req, MethodContext, WTConnection, or WTKeyStoreUtil. If a system is suspected to be compromised, assume credentials stored in the application keystore have been exposed. Rotate LDAP and administrative credentials, including any reused downstream secrets, and review those accounts for suspicious authentication and active sessions elsewhere in the environment.
Securonix ThreatWatch Summary:
Based on threats observed during August 2026, the Securonix ThreatWatch team recommends the following defensive measures to reduce exposure across endpoints, remote management tools, internet-facing infrastructure, cloud services, and ransomware-prone environments.
Identity and access:
-
Require MFA for VPN, RDP, RMM platforms, administrative portals, and privileged accounts. Review privileged identities for unusual authentication, new administrative access, credential dumping, Kerberoasting, and unexpected lateral movement.
-
If application or directory credentials may have been exposed, rotate them from a clean system and revoke active sessions. The Windchill implant could decrypt LDAP and administrative credentials, while other August activity used stolen NTLM material and Active Directory access to expand compromise.
Endpoint and malware prevention:
-
Alert on security-tool tampering, broad Defender exclusions, UAC bypass, silent MSI installation, DLL sideloading, process injection, and unexpected kernel-driver creation.
-
Pay particular attention to msagent.sys and CoolClient-related activity involving Sang.exe or renamed defender.exe, libngs.dll, loadcert.ini, cert.ini, and injection into synchost.exe.
-
Restrict untrusted MSI, EXE, DLL, LNK, and script execution from Downloads, Temp, AppData, and other user-writable locations.
Remote management and trusted services:
-
Maintain an inventory of approved RMM tools and block unauthorized ScreenConnect or similar clients. Alert when remote-management software is installed silently, launched from unusual paths, or connects to raw IP addresses.
-
Monitor Cloudflare Tunnel, GitHub, Dropbox, and other trusted services when accessed by PowerShell, scripts, unknown loaders, or newly compromised endpoints. SMOKE#SCREEN and C2Looper both used legitimate services to support malware delivery or attacker control.
Linux and edge-device security:
-
Patch internet-facing routers, firewalls, NAS appliances, cameras, and other edge systems. Disable default credentials and password-based SSH where practical.
-
Monitor Linux systems for unexpected persistence, credential sniffing, SOCKS proxy activity, interactive shells, and encrypted outbound connections. Evooo1Bot can exploit known vulnerabilities, brute-force SSH, and turn compromised devices into proxy nodes.
Ransomware prevention:
-
Maintain offline or immutable backups and regularly test restoration of servers, endpoints, identity systems, and virtualization infrastructure.
-
Alert on rapid file encryption, backup deletion, service termination, event-log clearing, credential dumping, and unusual use of tools such as Volatility3 or WinPmem. DeadLock and Interlock both showed that ransomware operations may combine credential theft, lateral movement, data theft, and encryption.
Vulnerability and exposure management:
-
Prioritize remediation of actively exploited internet-facing vulnerabilities, including CVE-2026-18577 in N-central, CVE-2026-68820 in Windows AFD.sys, CVE-2025-49113 in Roundcube, and CVE-2026-12569 in PTC Windchill.
-
Review affected systems for web shells, suspicious services, unexpected PHP or JSP files, new administrator accounts, Cloudflare Tunnel activity, and remote-control sessions.
Detection and response:
-
Correlate Defender exclusions, UAC bypass activity, DLL sideloading, process injection, driver creation, and unexpected C2 connections into a single investigation timeline. CoolClient spreads these behaviors across several stages, and individual events may appear benign when reviewed separately.
-
Extend correlation windows for remote-management installations and delayed service execution. SMOKE#SCREEN included a three-minute delay specifically intended to break short EDR correlation windows, so detection logic should not assume that installation and C2 activity occur within seconds of each other.
-
Detect trusted utilities by behavior rather than filename. August activity abused signed RMM software, legitimate forensic tools, DLL sideloaders, GitHub, Cloudflare, and built-in Windows processes. Allowlisting based only on publisher, filename, or domain reputation will miss several of these attack paths.
-
Correlate edge-device exploitation with later SOCKS tunneling, credential access, remote administration, and Active Directory activity. Initial access broker operations showed that compromise of an internet-facing appliance can be the first step toward full domain compromise rather than an isolated device incident.
-
During containment, isolate compromised RMM servers and endpoints, disable attacker-created remote-access paths, revoke affected sessions, rotate exposed credentials from clean systems, remove web shells and persistence, and verify that privileged accounts have not been modified.
-
For systems affected by rootkits or extensive security-control tampering, do not rely solely on malware removal. CoolClient can hide processes, files, registry objects, network information, and kernel modules, while ransomware incidents may leave identity and virtualization infrastructure untrustworthy. Rebuild affected systems from known-good media when integrity cannot be established.
Outlook for the Months Ahead:
-
Abuse of legitimate remote management tools will remain attractive because signed RMM software can provide persistent access while blending into normal IT activity. Defenders should expect continued use of ScreenConnect, N-central, and similar platforms after phishing or vulnerability exploitation.
-
Trusted cloud services will continue to appear in malware delivery and C2. GitHub, Cloudflare Tunnel, Dropbox, and other widely allowed services can host payloads or carry attacker traffic without immediately triggering reputation-based controls.
-
AI-assisted threat activity is likely to grow around phishing, malware development, and intelligence processing. Operation GitPower shows that local LLMs, RAG tooling, and AI frameworks can support existing intrusion methods without changing the underlying execution and persistence patterns defenders already monitor.
-
Kernel-level stealth will remain important for targeted intrusions. CoolClient's use of a kernel driver to hide processes, files, registry objects, and network activity suggests that more operators may combine user-mode malware with rootkit components when long-term access is the goal.
-
Internet-facing appliances will remain a major entry point. Exploitation of RMM platforms, firewalls, routers, webmail, and enterprise applications shows that edge systems can provide a direct path to credential theft, tunneling, lateral movement, and broader network compromise.
-
Linux and edge-device malware will continue moving beyond basic DDoS activity. Evooo1Bot combines exploitation, SSH brute forcing, credential theft, interactive shells, persistence, and SOCKS proxying, making compromised infrastructure useful for both botnet operations and follow-on access.
-
Ransomware operators will keep relying on legitimate tools before encryption. Interlock's use of Volatility3, WinPmem, LDAP discovery, Kerberoasting, RDP, and scheduled tasks shows that credential access and lateral movement remain as important as the encryptor itself.
-
Decentralized ransomware infrastructure may become more common. DeadLock's use of distributed communication and recovery services reduces dependence on traditional hosting and makes disruption harder when defenders focus only on domains or centralized servers.
-
Custom web shells will remain useful for mass exploitation campaigns. The Clop-linked Windchill implant shows how attackers can build application-specific tooling that steals credentials and data from inside trusted application processes, making activity harder to separate from normal traffic.
-
Anti-analysis and delayed execution will continue to complicate detection. August activity included runtime checks, security-control tampering, delayed execution, process injection, obfuscation, and in-memory loading, which will keep increasing the value of behavioral detection and longer correlation windows.
For a full list of the search queries used on Autonomous Threat Sweeper for the threats detailed above, refer to ours Threat Labs home page. The page also references a list of relevant policies used by threat actors.
We would like to hear from you. Please reach out to us at scia@securonix.com.
Note: The TTPs when used in silo are prone to false positives and noise and should ideally be combined with other indicators mentioned.
Contributors: Dheeraj Kumar

