Skip to main content
Blog

Securonix ThreatWatch Monthly Intelligence Insights – September 2026

  • October 7, 2026
  • 0 replies
  • 3 views
Dheeraj Kumar
Forum|alt.badge.img

Authors: Nitish Singh, Nikhil Kumar Chadha, and Tanmay Kumar 

Introduction:

The Monthly Intelligence Insights report provides a summary of top threats curated, monitored, and analyzed by Securonix Threat Watch in September 2026. The report also includes a synopsis of the threats, indicators of compromise (IoCs), tactics, techniques, and procedures (TTPs), and related tags. Each threat has a comprehensive summary from Threat Labs and search queries from the Threat Research team. For additional information on Threat Labs and related search queries used via Autonomous Threat Sweeper to detect the below-mentioned threats, refer to our Threat Labs home page.

Last month, Securonix Autonomous Threat Sweeper identified and analyzed 4,819 TTPs and IoCs; identified 157 emerging threats; investigated 77 potential threats; and elevated 18 incidents. The top data sources swept against include IDS / IPS / UTM / Threat Detection, Data Loss Prevention, Endpoint Management Systems, and Email / Email Security.

Executive Summary:

  • TASK#STOMP: Securonix Threat Research uncovered a script-driven Windows backdoor chain that uses VBS orchestration, scheduled-task and Startup-folder persistence, timestomping, hidden PowerShell, Base64-in-DAT payload loading, and runtime C# compilation to support document theft, surveillance, credential collection, and remote command execution.

  • Angry Birds: Toy Ghouls moved from public tooling and ransomware builders into custom backdoor development. The new "bird" agents use WinRM delivery, Windows service persistence, machine-bound configuration sealing, and unconventional C2 over HiveMQ MQTT or Matrix-based Element infrastructure.

  • FamousSparrow / SparroWocky: FamousSparrow shifted heavily toward Latin American government targeting while replacing SparrowDoor with a modular C++ backdoor. SparroWocky adds DLL side-loading, reflective in-memory loading, BOF execution, proxying, screenshot capture, file exfiltration, and advanced stack and loader camouflage.

  • Knight Office: The M365 AiTM phishing kit used DocuSign-style lures, trusted redirect paths, compromised Joomla sites, callback proxies, and device-code flows to steal valid session tokens. Operators then replayed tokens, registered rogue Entra devices, and added Windows Hello for Business credentials to regain access after token revocation.

  • Galago: Galago appears to be an early-stage ransomware operation linked by self-reporting and leak-site naming to Panzer. Its own leak site was inactive with no published victims, so the reported Iceland healthcare compromise remains unconfirmed until DLS activity or independent corroboration appears.

  • Settra: Settra ransomware activity shows a repeatable post-compromise pattern: MeshAgent RMM for persistence, victim-domain-named ransomware binaries, file encryption, RESTORE_FILES.txt ransom notes, Windows recovery disruption, event-log clearing, and in one September case, BYOVD using gdrv.sys.

  • Meowciety403: Meowciety403 is better treated as a financially motivated data-extortion and brokerage operation than a confirmed encryption ransomware group. Reported activity centers on UAE, Singapore, and Germany victims, with claimed theft of internal documents, HR records, payment data, SQL files, source structures, API keys, and financial details.

  • BlueMoon / Patch-Gap Panic: State-aligned actors rapidly adopted a Chrome and Windows exploit chain that combined V8 type confusion, a V8 sandbox escape, and Windows kernel privilege escalation. The activity exposed a patch-gap risk in Chromium-based browsers and enabled payload delivery ranging from GemStone browser surveillance to ShadowPad and Rust loader chains.


Threat Overview:

Securonix Threat Research Highlights:

  • TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access

Securonix Threat Research team has identified TASK#STOMP as a PowerShell-based Windows backdoor used for document theft, surveillance, persistent remote access, and arbitrary command execution. The observed chain starts with wscript.exe launching a randomly named VBScript from a user accessible location, then staging components under %LOCALAPPDATA%\WinDefendSvc, a folder name that mimics a Windows Defender service. Initial access is still unconfirmed, but this notes that the script location fits common delivery routes such as downloads, email attachments, copied files, archives, removable media, or other social engineering.

The VBScript works as the installer and controller. It creates four scheduled tasks from XML definitions, places msdiag.vbs in the user Startup folder, kills older sys_loader and win_conn instances, backdates staged files, launches hidden PowerShell modules, opens a Chrome URL, and runs purge.bat. The scheduled task names rotate across executions, including "Local Credential Manager," "Network Audio Service," "Windows Display Manager," and "Device Credential Handler," so defenders should treat the names as camouflage rather than reliable indicators. The XML files and task actions matter more than the display names.

TASK#STOMP keeps persistence through both scheduled tasks and the Startup-folder launcher. On logon, msdiag.vbs can recreate tasks, replace stale payload processes, reapply fixed timestamps, and bring the implant back to a known working state. The malware timestomps msdiag.vbs, diag_pack.dat, win_conn_cfg.dat, sys_loader.ps1, and win_conn.ps1 to 2024-01-15 08:30:00, which gives investigators a strong anti-forensic hunting pivot. Several related files in a user writable path sharing that same old timestamp should be treated as suspicious.

The two PowerShell modules run hidden with -NoProfile, -ExecutionPolicy Bypass, and -WindowStyle Hidden. sys_loader.ps1 decodes diag_pack.dat, while win_conn.ps1 decodes win_conn_cfg.dat; both turn Base64 .dat content into in memory ScriptBlocks. The decoded payload confirms document discovery and exfiltration, continuous file monitoring, Wi-Fi password theft, screenshot capture, clipboard theft and clearing, system reconnaissance, and arbitrary PowerShell execution. Both modules also use PowerShell Add-Type, which triggers csc.exe and cvtres.exe to compile C# helpers that force TLS 1.2 and accept invalid certificates. Confirmed C2 domains are corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz, with requests using an X-Auth-Token header and paths such as /api/c2/poll/, /api/c2/result/, /api/heartbeat, and /upload.

Analyst assessment: TASK#STOMP is concerning because it combines common Windows scripting and administration tools into a resilient collection framework. None of the individual signals, such as wscript.exe, schtasks.exe, hidden PowerShell, or csc.exe, is automatically malicious by itself. The ordered chain is the problem: script-hosted task creation, AppData staging, Startup persistence, forced process replacement, timestomping, in memory PowerShell execution, runtime C# compilation, redundant C2, and continuous document theft. The payload appears focused on espionage and persistent collection, but arbitrary PowerShell execution gives the operator room to deploy additional malware, steal more credentials, or take more disruptive action.  

Defender priority: Review systems where wscript.exe or cscript.exe spawns schtasks.exe with /Create and /XML, especially when task XML is stored in AppData, Temp, Desktop, Downloads, or another user writable path. Collect Security Event ID 4698, Task Scheduler Operational logs, the full XML definitions, Startup-folder contents, and the staged WinDefendSvc files before remediation. Alert on hidden or execution-policy-bypassed PowerShell running .ps1 files from %LOCALAPPDATA%\WinDefendSvc or similar paths, especially when it reads Base64 .dat files, creates ScriptBlocks, changes LastWriteTime values, spawns csc.exe or cvtres.exe, or reaches the confirmed C2 infrastructure. Retain PowerShell 4103 and 4104 logs, AMSI telemetry, compiler response files, and temporary compilation artifacts for investigation.


Emerging Custom Backdoors: Toy Ghouls and Famous Sparrow:

  • The cyber threat group Toy Ghouls is using HiveMQ and Element services to run their new custom backdoors

Active since 2025, the financially motivated threat group Toy Ghouls has upgraded its arsenal with two new custom backdoors mqtt-bird-agent and matrix-bird-agent specifically targeting Russian organizations. The group uses Evil-WinRM and WinRM-fs to drop payloads and configuration files onto compromised Windows systems. Once inside, they maintain a persistent foothold by hiding behind services named cplsupport or wtas. 

The two variants handle communications differently: the HiveMQ version relies on broker.hivemq[.]com for telemetry and fetching commands, while the Element variant connects to an attacker-controlled domain, meet.element[.]tw. Both versions gather public IP addresses and host performance data. However, the HiveMQ variant executes commands via hidden PowerShell, whereas the Element version uses cmd.exe. Interestingly, the Element implant wipes its configuration right after the initial run and securely stores its sealed settings inside the HKLM\Software\synapse\Config\SealedConfig registry path. 

Analyst assessment: The real worry here is how the group is shifting away from publicly available tools. Instead, they are turning to custom implants and C2 infrastructure designed to blend right into legitimate services. These backdoors grant them persistent, interactive control over networks, which could easily support the group’s ransomware operations even though no ransomware was actually deployed in these specific incidents. 

Defender priority: Hunt for WinRM activity that leads to the creation of cplsupport or wtas services, the execution of cplsupport.exe or wtass.exe, or the generation of config.toml files. You should also audit registry changes within HKLM\Software\synapse\Config\SealedConfig and HKLM\Software\SynapseAgent\metrics_interval. Additionally, keep a close eye on any outbound connections from affected endpoints to broker.hivemq[.]com, meet.element[.]tw, or ip-api[.]com especially if they coincide with hidden PowerShell execution.

  • FamousSparrow has replaced its SparrowDoor implant with a new modular, memory-resident backdoor named SparroWocky

Active since at least August 2025, FamousSparrow has been rapidly replacing its older SparrowDoor backdoor with a new variant called SparroWocky. Security experts assess this campaign as FamousSparrow activity with high confidence, noting that roughly 90% of their targets from mid-2025 into 2026 have been government organizations in Latin America. The group deploys SparroWocky via DLL side-loading, using a legitimate executable to reflectively map a signature-stripped PE directly into memory from an encrypted .dat payload.

Written in C++, this advanced implant supports everything from command execution and file theft to TCP proxying and screenshot capture. To stay efficient, it only exfiltrates changed screenshot blocks after the initial capture, encrypting all stolen data with RC4 over TLS (typically via port 443 or 8080). SparroWocky also actively hides its footprints using stack spoofing, CreateThread hooking, and fake Windows loader structures, while securing a permanent foothold through either the 'ProcAuditManager' service or a 'SnapCart' Registry Run-key.

Analyst assessment: SparroWocky is notable for integrating modular BOF execution with advanced memory-resident evasion. This internal tooling minimizes the threat actor's on-disk footprint during operations. Current indicators confirm that FamousSparrow remains actively engaged in espionage, though data is insufficient to link them directly to other known China-aligned clusters. 

Defender priority: Investigate DLL side-loading chains that combine a legitimate executable, a modified DLL, and an adjacent .dat file. Be sure to hunt for persistence indicators like the creation of the 'ProcAuditManager' service or 'SnapCart' Run-key values. Additionally, audit hosts with side-loading artifacts for suspicious private memory regions, threads with anomalous start addresses or call stacks, and unexpected outbound TLS connections over ports 443 or 8080.


A New Emerging Phishing Kit: Knight Office

  • A New M365 AiTM Phishing Kit

Knight Office is a phishing kit used in Adversary-in-the-Middle (AiTM) attacks targeting Microsoft 365 users. The threat actors distributed phishing emails impersonating legitimate services such as DocuSign. The emails used urgent themes, including document signing, voicemail notifications, and shared documents to convince users to click malicious links. Some emails also used lookalike characters, such as replacing the uppercase “I” with a lowercase “l” in words such as “lmportant” and “Slgnature.”  

The attack chain redirected victims through legitimate services such as Monday[.]com and compromised Joomla websites before leading them to fraudulent Microsoft SharePoint or Teams login pages. Victims were instructed to enter a provided device authentication code on Microsoft's legitimate login portal. Once the user entered their credentials and completed MFA, the attackers captured the Microsoft 365 session token and reused it to access the authenticated session. The attackers used the Knight Office operator console to manage compromised sessions, access victims' webmail, distribute phishing links, and monitor visitor activity. 

Analyst assessment: The Knight Office campaign employs realistic business-themed phishing lures, trusted redirect services, compromised websites, device-code phishing, and Adversary-in-the-Middle (AiTM) techniques to obtain valid Microsoft 365 authentication sessions. A key risk is that even after successfully completing MFA, a victim session can still be compromised because the attacker captures and replays the resulting session token. Following initial access, the threat actor can establish persistence by registering an unauthorized device in Microsoft Entra ID and associating a Windows Hello for Business (WHfB) credential with the compromised account, allowing access to persist even after existing session tokens are revoked. 

Defender priority: Prioritize detection of unusual post-MFA Microsoft 365 authentication, particularly Microsoft Authentication Broker activity originating from callback-proxy, residential-proxy, cloud-hosting, or otherwise unfamiliar IP space.  

Monitor for authentication activity associated with the identified Knight Office infrastructure, including suspicious [.]vu phishing domains, and the python-requests/2.34.2, OAuth2:Token user-agent observed during token replay. 

Review Microsoft Entra ID for newly registered or unmanaged devices, unauthorized Windows Hello for Business credentials, and unfamiliar Dsreg/10.0 user-agent activity.


Ransomware Threat Highlights:

  • Settra ransomware deploys remote-management tools and recovery-inhibition techniques

Settra is a newer ransomware variant first reported in June 2026. Two observed incidents, one in July and one in September, followed a similar post-compromise pattern. Initial access was not confirmed, although reporting links Settra activity to compromised VPNs and stolen credentials. 

In both incidents, the operators deployed MeshAgent for remote access, ran a ransomware executable named after the victim's domain with a _win64.exe suffix, encrypted files, and created RESTORE_FILES.txt ransom notes. The July incident used a renamed MeshAgent binary, mvtcs.exe, connected to 45[.]13[.]122[.]7. The September incident used MeshAgent connected to 193[.]5[.]65[.]114 and showed evidence of the gdrv.sys Bring Your Own Vulnerable Driver technique.

The ransomware disabled Windows Recovery Environment used DiskPart in an apparent attempt to remove recovery partitions, and cleared several Windows event logs. The July incident also used cipher /w to overwrite free disk space and make deleted files harder to recover. In September, a misspelling in the command intended to clear the Windows Defender event log meant that log remained available.

Analyst assessment: Settra combines common ransomware tradecraft with legitimate remote-management tooling and, in one case, a vulnerable driver used to interfere with security products. The repeated executable naming convention and recovery-inhibition actions provide useful detection opportunities.

Defender priority: Restrict and monitor remote-management tools, investigate unsigned or unexpected MeshAgent deployments, and alert on executables using the <domain>_win64.exe naming pattern. Protect VPN access with phishing-resistant MFA, and monitor for reagentc /disable, DiskPart, event-log clearing, and cipher /w.

  • Galago ransomware claims Panzer partnership, but its activity remains at an early and unverified stage

Galago is a newly observed ransomware operation first identified on 9 September 2026. Its dark leak site was inactive when researchers checked it on 15 September, and no victims had been published. The group claims to work with the Panzer ransomware operation, and both leak-site addresses use the pnzr naming prefix. 

Panzer published 32 victims between 5 August and 23 September. This supports a possible operational relationship, although the available evidence does not confirm whether Galago is an affiliate, a rebrand, or a separate group using shared infrastructure.

One public claim alleges that Galago compromised Inter ehf, an Iceland-based healthcare organization, and stole about 105 GB of data. The claimed publication window was from 28 to 29 September. Because Galago's leak site remained down and no victim entry was published, this incident should be treated as unverified.

Analyst assessment: Galago may be an emerging Panzer-linked operation, but its capabilities, victimology, and intrusion methods are not yet established.

Defender priority: Reduce exposure of internet-facing systems and remote-access services, enforce phishing-resistant MFA for VPN and privileged accounts, and monitor for credential abuse, lateral movement, security-tool tampering, and large outbound data transfers.

  • Meowciety403 focuses on data theft and extortion against financial and technology organizations

Meowciety403, also tracked as Nekoneko200, is an emerging financially motivated extortion group active since August 2026. The group has targeted organizations in the United Arab Emirates, Singapore, and Germany, with known victim sectors including financial brokerage, foreign exchange, IT consulting, and technology. 

The group operates a Tor-based leak site and uses Telegram accounts for victim contact and public pressure. Its model appears to centre on data theft, data auctions, and direct extortion. Reported Singapore victims received ransom demands of USD 5,000. The group has claimed access to internal documents, HR records, API keys, SQL files, backend code, payment inventories, and bank-account data containing SWIFT codes. 

There is no confirmed evidence that Meowciety403 encrypts victim systems, so it currently appears to operate primarily as a data-extortion broker. 

Analyst assessment: Meowciety403's value comes from access to sensitive business and customer information rather than confirmed ransomware deployment. Its targeting of finance, payroll, recruitment, and technology data raises the risk of follow-on fraud, credential misuse, and regulatory exposure. 

Defender priority: Remove direct internet exposure of RDP and place remote access behind VPN or zero-trust controls. Monitor for unusual archive creation, mass access to documents, source code, HR records, and large outbound transfers. Segment high-value finance and HR systems, maintain tested offline backups, and assess shared accounts, infrastructure, and vendors for credential reuse or common administrative access.


BlueMoon Exploits Target Chromium and Windows:

  • BlueMoon Exploit Chain: Multiple Espionage-Focused Actors Exploit Chromium and Windows Vulnerabilities

BlueMoon is a browser exploit chain used in targeted phishing campaigns observed from late August through September 2026. Multiple espionage-focused threat actors, several assessed as China-aligned, targeted organizations in the NGO, aerospace and defense, mining, manufacturing, government, and financial sectors across the United States and Southeast Asia. Campaigns used credible-looking themes including job or university outreach, conference invitations, donation requests, and requests for quotation. Victims who clicked on the malicious link were redirected to an attacker-controlled site that attempted exploitation before sending them to a legitimate website.

The exploit chain combines three vulnerabilities: CVE-2026-85046, a Chromium V8 type-confusion vulnerability; CVE-2026-87491, a V8 sandbox escape; and CVE-2026-85880, a Windows kernel privilege-escalation vulnerability. Together, these flaws can allow an attacker to move from a single browser click to code execution with elevated privileges on the host. The Windows privilege-escalation component primarily targets older Windows builds, making legacy systems a higher-risk population.

Following successful exploitation, attackers downloaded payloads through a suspicious browser process chain, typically involving the browser launching command shell and curl before writing an executable to a temporary location. Observed payloads included loaders, remote-access backdoors, and a malicious browser extension disguised as an AI browsing assistant. The extension can collect cookies, keystrokes, browser storage, screenshots, and session data, then receive commands from attacker-controlled infrastructure. Other activities used DLL side-loading, scheduled tasks, registry persistence, encrypted payloads, and DNS-over-HTTPS for command-and-control traffic.

Analyst assessment: The rapid use of the same exploit chain by several threat actors suggests that the capability was shared or obtained through a common source. The activity also demonstrates the risk created when fixes become visible in upstream open-source code before all browser vendors release stable updates. While the delivery chain can be effective against unpatched systems, its browser-to-command-shell execution pattern creates several strong detection opportunities.

Defender priority: Enforce current security updates for Chromium-based browsers and Windows, and ensure browsers restart after patching. Prioritize older Windows systems for review. Hunt for browser processes spawning cmd.exe, curl.exe, or unexpected executables such as msgbox.exe or ChromeUpdate.exe, especially when files are written to temporary or user-profile directories. Investigate unexpected browser-extension installs, Chromium Secure Preferences modifications, session-storage keys such as v8ctf_exp_attempt, suspicious scheduled tasks, and outbound connections to newly registered or low-reputation domains. Strengthen phishing controls for conference, recruitment, and business-inquiry lures, and review browser cookies and credentials on potentially affected systems.


Securonix ThreatWatch Summary:

Based on threats observed during September 2026, the Securonix ThreatWatch team recommends the following defensive measures to reduce exposure across endpoints, browsers, identity systems, remote access paths, trusted cloud services, and ransomware or extortion-prone environments.

Identity and access:

  • Require phishing-resistant MFA for VPN, RDP, RMM platforms, administrative portals, Microsoft 365, Google Workspace, and privileged accounts. Review privileged identities for unusual post-MFA authentication, token replay, new device registration, new Windows Hello for Business credentials, unexpected OAuth activity, and sign-ins from callback proxies or unfamiliar infrastructure. Knight Office showed that attackers can bypass password and MFA controls by stealing valid session tokens, then register rogue Entra devices and bind WHfB credentials for continued access.

  • If identity tokens, cookies, API keys, or directory credentials may have been exposed, revoke active sessions, rotate credentials from a clean system, remove unauthorized authentication methods, and review newly registered devices. Meowciety403 activity centered on data theft and exposed business records, while SparroWocky and BlueMoon-linked payloads included file collection, browser surveillance, cookie theft, and screenshot capture.

Endpoint and malware prevention:

  • Alert on DLL side-loading, reflective in-memory loading, suspicious Windows services, Registry Run key persistence, hidden PowerShell, runtime C# compilation, process injection, browser extension tampering, and unexpected scheduled tasks. Securonix Threat Research uncovered a Windows backdoor chain using VBS orchestration, scheduled-task and Startup-folder persistence, timestomping, hidden PowerShell, Base64-in-DAT payload loading, and runtime C# compilation.

  • Pay particular attention to legitimate binaries loading unusual DLLs, encrypted payload files beside trusted executables, and payloads mapped directly into memory. SparroWocky used a three-part loader with a legitimate executable, a malicious DLL, and an encrypted payload file, then reflectively mapped the PE payload into memory.

  • Restrict untrusted EXE, DLL, LNK, script, DAT, and ZIP execution from Downloads, Temp, AppData, Public, browser profile paths, and other user-writable locations. BlueMoon follow-on activity downloaded payloads through browser-spawned command lines, while Settra incidents launched ransomware from user-accessible locations and relied on post-compromise tooling before encryption.

Browser and cloud-service security:

  • Patch Chrome and other Chromium-based browsers quickly and confirm browsers have restarted after updating. Prioritize hunting for BlueMoon activity on systems exposed before the September patch window, especially where Chrome or Chromium-based browsers spawned cmd.exe, curl.exe, msgbox.exe, or ChromeUpdate.exe.

  • Monitor for suspicious browser extensions, Chrome Secure Preferences tampering, extension storage abuse, cookie capture, active-tab data collection, and unexpected screenshot upload behavior. GemStone masqueraded as a Google Gemini companion extension and used browser permissions for cookies, storage, tabs, scripting, downloads, web navigation, command polling, and data exfiltration.

  • Review trusted services and collaboration platforms when accessed by PowerShell, unknown loaders, browser implants, or newly compromised endpoints. September activity used public or trusted infrastructure in several places, including HiveMQ MQTT, Matrix-based Element, Cloudflare Workers, Cloudflare R2, Google DNS-over-HTTPS, and legitimate redirect paths in phishing chains.

Remote management and access paths:

  • Maintain an inventory of approved RMM tools and block unauthorized remote-management clients. Alert when RMM software is installed silently, launched from unusual paths, renamed, or connected to raw IP addresses. Settra intrusions used MeshAgent RMM for persistence before encryption, with observed C2 addresses tied to July and September activity.

  • Monitor WinRM use for file transfer, remote execution, and service installation outside approved administrative workflows. Toy Ghouls used WinRM to deliver backdoors and configuration files, then installed the backdoor as a Windows service.

Ransomware and extortion prevention:

  • Maintain offline or immutable backups and test recovery for servers, endpoints, identity systems, file shares, and virtualization infrastructure. Settra activity included encryption, RESTORE_FILES.txt ransom notes, Windows recovery disruption, event-log clearing, and use of diskpart and reagentc to interfere with recovery.

  • Alert on rapid file encryption, ransom-note creation, backup deletion, event-log clearing, security-tool tampering, BYOVD activity, and unexpected use of recovery or disk utilities. The September Settra incident included gdrv.sys BYOVD activity, MeshAgent RMM installation, .locked_wip encrypted files, and repeated recovery-disruption behavior.

  • Treat data-extortion claims separately from confirmed encryption events. Galago had no published victims on its own inactive leak site at the time of reporting, while Meowciety403 appeared to operate more as a data broker than a confirmed encryption-based ransomware operation.

Vulnerability and exposure management:

  • Prioritize remediation of actively exploited browser and internet-facing vulnerabilities, especially the BlueMoon chain involving Chrome V8 and Windows privilege escalation. The chain combined CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, then delivered payloads such as GemStone, ShadowPad, Rust loaders, and custom malware depending on the actor.

  • Review exposed systems for phishing infrastructure abuse, unauthorized browser extensions, web-service C2, suspicious scheduled tasks, new services, unexpected registry persistence, and cloud-hosted payload delivery. BlueMoon campaigns used same-day or recently created infrastructure, campaign-specific landing pages, redirects, and multiple payload families across different actor clusters.

Detection and response:

  • Correlate browser exploitation, child-process execution, payload downloads, scheduled tasks, DLL side-loading, RMM installation, identity token replay, and follow-on C2 into a single investigation timeline. September activity often spread compromise across browsers, endpoints, identity systems, and cloud services, so single-event triage may miss the full chain.

  • Extend correlation windows for phishing and identity activity. Knight Office attacks used redirects, compromised websites, callback proxies, token theft, rogue device registration, and WHfB credential binding, which may not appear as one compact burst in logs.

  • Detect trusted utilities by behavior rather than filename, publisher, or domain reputation alone. September campaigns abused legitimate executables, Chromium browsers, public MQTT infrastructure, Element messaging, Cloudflare services, Google DNS-over-HTTPS, RMM clients, and native Windows utilities. Allowlisting based only on reputation will miss several of these paths.

  • During containment, isolate compromised endpoints and RMM servers, disable attacker-created remote-access paths, revoke sessions, remove rogue devices and authentication methods, rotate exposed credentials from clean systems, remove malicious browser extensions, delete persistence, and verify that privileged identities have not been modified.

  • For systems affected by rootkits, BYOVD, browser exploit chains, or extensive security-control tampering, do not rely only on malware removal. Rebuild from known-good media when system integrity cannot be established, then restore only validated data and reissue credentials after containment is complete.


Outlook for the Months Ahead:

  • Browser exploit chains will remain a high-risk entry point. BlueMoon showed how quickly state-aligned actors can move from a Chromium patch gap to working exploitation, then pair browser compromise with Windows privilege escalation and follow-on payloads.

  • Patch gaps in open-source browser components will keep attracting exploit developers. Public Chromium fixes can give attackers a narrow but useful window before stable browser releases reach every endpoint, especially in environments where browser restarts are delayed.

  • AiTM phishing will keep shifting attention away from passwords and toward valid sessions. Knight Office showed that attackers can use trusted redirects, compromised websites, callback proxies, and device-code flows to capture tokens, register rogue Entra devices, and regain access through Windows Hello for Business.

  • Malicious browser extensions will remain useful after initial compromise. GemStone-style payloads can collect cookies, storage data, keystrokes, active-tab metadata, screenshots, and browser history while blending into normal Chromium activity.

  • Ransomware operators will keep using remote management tools before encryption. Settra’s use of MeshAgent shows that signed RMM software still gives attackers a practical way to hold access, move through an environment, and stage encryption with less immediate suspicion.

  • Data-extortion groups may continue to operate without confirmed encryption. Meowciety403’s activity points to a model built around stolen documents, HR records, SQL data, source structures, API keys, and financial information, with leak pressure doing the work that encryption usually does.

  • Early-stage ransomware brands will remain hard to assess. Galago had a claimed link to Panzer and an alleged healthcare victim, but its inactive leak site and lack of published victims show why defenders should track new names without treating every claim as confirmed.

  • China-aligned espionage tooling will keep investing in stealth and modularity. SparroWocky’s DLL side-loading, reflective loading, BOF execution, stack spoofing, proxy support, screenshots, and file exfiltration suggest that more implants will combine custom backdoors with in-memory offensive tooling.

  • Trusted cloud and web infrastructure will continue to support delivery and C2. September activity used Cloudflare Workers, Cloudflare R2, Google DNS-over-HTTPS, HiveMQ MQTT, Matrix-based Element, and legitimate redirect paths, making reputation-only controls less reliable.

  • Script-based persistence will remain attractive because it is simple and durable. TASK#STOMP’s rotating scheduled tasks, Startup-folder VBS launcher, hidden PowerShell, Base64 .dat payloads, timestomping, and runtime C# compilation show how much an actor can do without a large malware footprint.

  • Detection programs will need longer correlation windows. Several September chains spread activity across browser exploitation, script execution, token replay, device registration, RMM deployment, scheduled tasks, and delayed payload execution. Reviewing each event alone will miss the intrusion pattern.

  • Containment will increasingly depend on cleaning identity, browser, and endpoint state together. Removing malware is not enough when attackers have stolen session tokens, registered devices, added persistence, installed browser extensions, or modified recovery and security controls.


For a full list of the search queries used on Autonomous Threat Sweeper for the threats detailed above, refer to ours Threat Labs home page. The page also references a list of relevant policies used by threat actors.  

We would like to hear from you. Please reach out to us at scia@securonix.com.  

Note: The TTPs when used in silo are prone to false positives and noise and should ideally be combined with other indicators mentioned. 

Contributors: Dheeraj Kumar