Threat Research | Weekly Recap [27 Sep 2026]

Threat Research | Weekly Recap [27 Sep 2026]
Cybersecurity Threat Research ‘Weekly’ Recap. The report highlights frequent ransomware and identity-focused intrusion chains, including PAYLOAD’s abuse of Active Directory GPO/SYSVOL, Qilin’s continued cross-sector activity in ANZ, and multiple OAuth/session and phishing techniques such as TeamFiltration, CSuite, and token theft even in MFA-protected environments. It also covers software supply-chain and platform abuse (MemTensor, OpenCode, CI/CD hardening, and AWS IAM key protection), plus notable loader/infostealer malware (ShinyHunters/UNC6240, Kothamine, AvisLoader, Vidar, MacSync, SilentXMRMiner) and exploitation work like pfSense stored XSS to root RCE and MagicINFO leading to miner deployment.
#PAYLOAD #ActiveDirectory #Qilin #TeamFiltration #CSuite #OAuth #AppX #WWAHost #MemTensor #OpenCode #ShinyHunters #UNC6240 #Kothamine #AvisLoader #Vidar #MacSync #SilentXMRMiner #pfSense #MagicINFO #VolzTyphoon #SaltTyphoon #UNC6293 #UNC7005 #UNC5976

Ransomware, Extortion & Initial Access

  • PAYLOAD ransomware abused Active Directory GPO/SYSVOL to disable defenses, stage data, and extort a Middle East manufacturer; group policy weaponization recap.
  • Qilin remained the most active cross-sector ransomware actor in ANZ, alongside broader identity-driven intrusion trends; ANZ threat landscape.
  • Ransomware defense is most effective pre-encryption, using threat intel to spot exposed creds and attacker infrastructure earlier; stop ransomware with threat intelligence.

Phishing, Account Takeover & Credential Theft

  • TeamFiltration hit 5,700+ Microsoft 365 accounts via service-account password spraying and session hijacking in Latin America; Andes campaign details.
  • CSuite used device-code phishing, session theft, and legitimate remote tools to compromise US and EU orgs; CSuite attack analysis.
  • OAuth token theft abused a sideloaded AppX and WWAHost to capture Microsoft login tokens even with MFA; Microsoft front-door abuse.
  • Firefox extension takeover impersonated a PDF tool to hijack Google accounts and steal OAuth cookies; Google account hijack via extension.
  • Ledger phishing used Google Ads and rapid Vercel redirects to steal wallet recovery phrases; Ledger lure campaign.
  • ACI tax phishing abused the Automobile Club d’Italia brand to collect payment and card data; ACI phishing alert.
  • MintsLoader spread through compromised PEC mailboxes with fake payment reminders and malware-laden ZIPs; PEC lure campaign.
  • Google Ads also delivered fake security-locker tech-support scams with hidden C2 and anti-analysis tricks; fake locker delivery.

Supply Chain, Developer & CI/CD Threats

  • MemTensor compromise pushed malicious npm/PyPI releases to steal developer secrets, tokens, and cloud creds; package supply-chain breach.
  • OpenCode RCE turned a content-type confusion bug into remote code execution via a crafted npm tarball; OpenCode vulnerability report.
  • CI/CD hardening guidance stressed secret scanning, isolated runners, provenance, and stronger identities across the SDLC; pipeline defense recap.
  • AWS compromised key quarantine now auto-isolates exposed IAM keys, tied to GitHub secret scanning and push protection; AWS IAM protection.

Loaders, RATs, Stealers & Malware Tradecraft

  • ShinyHunters/UNC6240 mass-exploited Oracle PeopleSoft CVE-2026-35273 with web shells, SIDEEYE, Neo-ReGeorg, and MeshAgent; PeopleSoft exploitation.
  • Kothamine Agent used Tailscale/tailcat for encrypted control while stealing browser data and media on some builds; Kothamine malware recap.
  • AvisLoader used ClickFix, Tox P2P C2, persistence artifacts, and anti-removal tooling; AvisLoader analysis.
  • Vidar advanced string obfuscation with per-build virtual machines and custom stream ciphers; Vidar obfuscation update.
  • MacSync evolved into a macOS infostealer with fake apps, malicious DMGs, iCloud abuse, and layered exfiltration; MacSync deep dive.
  • Python MaaS stealer builder packaged browser, Discord, Wi-Fi, and webhook-based exfiltration for Windows theft; TokenGrabberBuilder report.
  • Larva-25012 resumed proxyware distribution using DPLoader, PowerShell, scheduled tasks, and sideloading; proxyware campaign.
  • SilentXMRMiner was compiled on-host after MagicINFO exploitation and Defender tampering for Monero mining; endpoint miner intrusion.

Exploitation, Malware Delivery & Vulnerability Research

  • pfSense/pfBlockerNG flaw enabled stored XSS from DNS poisoning and could escalate to root RCE; CVE-2026-78902 write-up.
  • Samsung MagicINFO exploitation served as the initial access point for follow-on miner deployment; MagicINFO intrusion.
  • Third-party ICS integrator guidance from FBI/CISA emphasized least privilege, remote-access monitoring, and secure contracting; ICS integrator advice.

Sector, Region & Nation-State Activity

Threat Research | Weekly Recap – hendryadrian.com