Threat Research | Weekly Recap [13 Sep 2026]

Threat Research | Weekly Recap [13 Sep 2026]
Cybersecurity Threat Research ‘Weekly’ Recap. This week’s coverage highlights credential-stealing and session-hijacking campaigns (BigBear 2.0, HVNC, Malicious Twitch extension, and Axiom Trade/Padre theft) alongside exploit chains that rapidly weaponize browser and platform vulnerabilities, including Marimo (CVE-2026-39987), GRAYRABBIT, and GRIMWEDGE/SUPERSTOMP/LONGTALE. Researchers also tracked emerging threats and abuse patterns such as SloppyRAT, ClearFake/WebDAV delivering Amatera/ZigCryptoStealer/NetSupport Manager, chat-based data leakage via a ChatGPT shared clipboard flaw, and AI manipulation efforts like PuzzleMask and adversarial agentic workflows. #BigBear2_0 #Evilginx2 #HVNC #Twitch #JeetBot #AxiomTrade #Padre #Marimo #CVE-2026-39987 #GRAYRABBIT #GRIMWEDGE #SUPERSTOMP #LONGTALE #BlueMoon #GemStone #ShadowPad #SloppyRAT #ClearFake #Amatera #ZigCryptoStealer #NetSupportManager #EtherHiding #SourTrade #CL-CRI-1171 #MantaxOtax #MacSync #Syslogk #ChatGPT #PuzzleMask #LockBit #Cl0p #Akira #Medusa #Qilin

Phishing, Social Engineering & Credential Theft

  • Fake tax-themed phishing uses VHDX payloads, loader/DLL injection, and disposable domains to target Indian taxpayers — shortened linked title
  • BigBear 2.0 rebranded Evilginx2 PhaaS steals Microsoft 365 sessions and bypasses MFA via AiTM — shortened linked title
  • HVNC backdoor spreads via fake tax and DocuSign lures, adding hidden remote access and data theft — shortened linked title
  • Malicious Twitch extension exposes live OAuth tokens through proxy infrastructure tied to JeetBot — shortened linked title
  • Cross-browser crypto extensions steal Axiom Trade and Padre sessions, wallets, cookies, and tokens — shortened linked title

Exploit Chains, Zero-Days & Backdoors

  • Marimo CVE-2026-39987 exploited in seconds to pivot from WebSocket terminal access to SSH and AWS credential theft — shortened linked title
  • Sogou Input Method CVE-2026-51990 enables one-click RCE and delivered GRAYRABBIT in the wild — shortened linked title
  • Chrome/Windows zero-day chains rapidly adopted by state-aligned actors to deploy GRIMWEDGE, SUPERSTOMP, and LONGTALEshortened linked title
  • BlueMoon exploit kit chains Chrome and Windows flaws for espionage payload delivery, including GemStone and ShadowPadshortened linked title

Malware, Loaders & Ransomware Ecosystems

  • SloppyRAT emerges as a multi-stage, anti-analysis tool likely used in ransomware-related intrusions — shortened linked title
  • ClearFake/WebDAV chains deliver Amatera, ZigCryptoStealer, and NetSupport Manager with EtherHiding support — shortened linked title
  • SourTrade malvertising impersonates trading brands to spread unfinished malware across a large typosquatting infrastructure — shortened linked title
  • CL-CRI-1171 runs a pay-per-install campaign via YouTube and SEO-poisoned downloads to drop multiple payloads — shortened linked title
  • Mantax Otax combines Android spyware, theft, remote surveillance, and ransomware in one campaign — shortened linked title
  • MacSync Stealer targets macOS via ClickFix lures and malvertising to steal Keychain, cookies, SSH keys, and wallets — shortened linked title
  • Syslogk rootkit hides Linux processes, connections, files, and modules with kernel-level stealth — shortened linked title

Browser, Cloud & SaaS Abuse

  • AWS access key compromise detection correlates CloudTrail and GuardDuty to trace validation, persistence, and exfiltration — shortened linked title
  • Defender ASR + Wazuh detects blocked Windows attack behaviors and ASR tampering across endpoints — shortened linked title
  • ChatGPT shared clipboard flaw enables cross-account task execution and data leakage via hidden command channels — shortened linked title

AI Threats, Abuse & Adversarial Operations

  • PuzzleMask hides malicious prompts in plain prose to bypass AI gatekeepers and trigger target models — shortened linked title
  • Adversarial AI activity is shifting from prompting to agentic workflows for credential theft, supply chain abuse, and model targeting — shortened linked title
  • China-based AI firms allegedly run industrial-scale distillation campaigns against major U.S. frontier models — shortened linked title

Infrastructure, Tracking & Ransomware Intelligence

  • DNS spotlight on ransomware maps infrastructure for LockBit, Cl0p, Akira, Medusa, and Qilin — shortened linked title
  • Threat infrastructure analysis links commodity abuse, typosquatting, and rotational domains across campaigns — shortened linked title

Threat Research | Weekly Recap – hendryadrian.com