2026-06-11
2026-06-11 09:21Z
HIGH

Bulbature, beneath the waves of GobRAT

Sekoia.io·sekoia.io

Sekoia TDR published a comprehensive analysis of a Chinese-attributed infrastructure controlling 63+ servers that compromise edge devices (primarily Asus/Qnap routers) and transform them into Operational Relay Boxes (ORBs). The campaign deploys two malwares—GobRAT (a Go-based RAT with DDoS/exploitation capabilities) and Bulbature (an undocumented C-based implant providing proxy tunneling)—to relay offensive attacks and enable rotating proxy infrastructure. A July 2023 export revealed ~75,000 compromised relay boxes, predominantly US-based, with active infrastructure still operating as of September 2024.

TACTA0001SRFNetworkSRFNetwork ApplianceTACTA0003TACTA0008TACTA0011SWBulbatureSWFrp
78
Edit Score
2026-06-11
2026-06-11 09:21Z
HIGH

Hadooken and K4Spreader: The 8220 Gang's Latest Arsenal

Sekoia.io·sekoia.ioCVE-2017-10271CVE-2020-14883in the wild

Sekoia's TDR team linked a WebLogic exploitation chain to the 8220 Gang, a China-based cryptomining intrusion set. The attackers exploited CVE-2017-10271 and CVE-2020-14883 to deploy K4Spreader (a Go-based loader), Tsunami DDoS backdoor, and PwnRig Monero miners across Windows and Linux systems. The campaign shares infrastructure, payloads, and TTPs with the previously reported Hadooken case, with victimology suggesting potential South American operator involvement based on Portuguese function names and Brazil-heavy targeting.

SRFApplicationTACTA0005TACTA0001TACTA0003SRFCloudTACTA0011OSLinuxOSWindows
78
Edit Score
2026-06-11
2026-06-11 09:21Z
HIGH

SilentSelfie: Major Campaign Against Kurdish Websites

Sekoia.io·sekoia.io

Sekoia's TDR team uncovered SilentSelfie, a watering-hole campaign targeting 25 Kurdish websites with four malicious JavaScript variants ranging from simple geolocation theft to complex frameworks that exfiltrate selfie camera images and distribute a malicious Android APK. The campaign, active since late 2022, represents a previously unknown intrusion set distinct from known regional threat actors like StrongPity, employing no sophisticated exploits but notable for scale, duration, and targeting precision against the Kurdish diaspora and Rojava administration.

SRFMobileTACTA0006SRFWebTACTA0043TYPResearchTYPThreat IntelSTGReconSTGCollection
78
Edit Score
2026-06-11
2026-06-11 09:21Z
HIGH

WebDAV-as-a-Service: The Infrastructure Behind Emmenhtal

Sekoia.io·sekoia.io

Sekoia TDR analyzed a WebDAV-based infrastructure distributing the Emmenhtal loader (PeakLight) since December 2023, identifying over 100 malicious WebDAV servers hosting .lnk files that invoke mshta.exe to fetch payloads. The infrastructure delivers multiple commodity malware families (DarkGate, Amadey, Lumma, Remcos, Redline, and others) and exhibits characteristics of a commercial Infrastructure-as-a-Service operation, with consistent use of specific ASNs and recurring test files suggesting multiple threat actors are renting the service.

TACTA0001TACTA0002SRFWebTYPResearchTYPThreat IntelSTGExecutionSTGInitial AccessTECT1204
72
Edit Score
2026-06-11
2026-06-11 09:21Z
MED

Hunting typosquatted domains during the 2024 Olympics

Sekoia.io·sekoia.io

Sekoia's Threat Detection & Research team conducted a proactive hunt for typosquatted domains impersonating Paris 2024 Olympics websites during July–August 2024, identifying 650+ malicious domains across 149 legitimate targets. Using DNS fuzzing (DNSTwist) and Censys SSL certificate monitoring, they found registration spikes before the opening ceremony, with ~45% targeting ticketing platforms, significant impersonation of French government security sites (Passe Jeux), and a small number of information-operation domains. Telemetry showed minimal malicious hits, with confirmed access primarily via phishing emails rather than widespread compromise.

TACTA0001SRFWebTYPResearchTYPThreat IntelSTGInitial AccessSTGReconTECT1583.001
62
Edit Score
2026-06-11
2026-06-11 09:20Z
HIGH

Quad7 Operators' Next Moves And Associated Botnets

Sekoia.io·sekoia.ioin the wild

Sekoia's TDR team published a comprehensive threat-intelligence report on the Quad7 botnet operators, detailing five *login botnet variants (xlogin, alogin, rlogin, axlogin, zylogin) targeting SOHO routers and VPN appliances from TP-Link, Asus, Zyxel, D-Link, Netgear, Axentra, and Ruckus. The operators are evolving their toolset with new HTTP-based reverse shells (UPDTAE backdoor), KCP-based relay infrastructure (FsyNet), and CJDNS-based tunneling (netd), moving away from open SOCKS proxies to evade detection and prevent researcher tracking.

TACTA0005TACTA0001SRFNetworkSRFNetwork ApplianceTACTA0003TACTA0011VNDTp LinkVNDAsus
78
Edit Score
2026-06-11
2026-06-11 09:20Z
HIGH

Emulating and Detecting Scattered Spider-like Attacks

Sekoia.io·sekoia.io

Sekoia and Mitigant demonstrate a Threat-Informed Defense strategy by emulating a seven-stage Scattered Spider AWS attack chain—from phishing-based initial access through S3 data exfiltration—and documenting detection coverage using Sekoia Defend rules and Sigma detection rules. The article maps each attack phase (initial access, execution, persistence, privilege escalation, defense evasion, credential access, collection) to MITRE ATT&CK techniques and provides practical guidance on which events warrant pre-built detection rules versus environment-specific tuning.

TACTA0004TACTA0005TACTA0001TACTA0002TACTA0006TACTA0007TACTA0003SRFCloud
68
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-11
2026-06-11 09:20Z
HIGH

Solving the 7777 Botnet enigma: A cybersecurity quest

Sekoia.io·sekoia.io

Sekoia.io investigated the Quad7/7777 botnet, a long-running operation targeting TP-Link routers to deploy SOCKS5 proxies for password-spraying attacks against Microsoft 365 accounts. Through honeypot monitoring and physical intervention on a compromised Archer C7 router in France, researchers identified an unauthenticated file-disclosure vulnerability chained with command injection to achieve RCE, and recovered malware binaries including telnetd and xlogin services. The botnet operators appear to be cybercriminals conducting BEC reconnaissance rather than APT actors, with activity declining from 16,000 to 7,000 unique IPs between August 2022 and July 2024.

TACTA0001SRFFirmwareSRFNetwork ApplianceTACTA0006TACTA0003SWBusyboxVNDTp LinkTYPResearch
76
Edit Score
2026-06-11
2026-06-11 09:20Z
HIGH

MuddyWater replaces Atera by custom MuddyRot implant

Sekoia.io·sekoia.ioin the wild

Sekoia TDR identified MuddyWater (Iranian MOIS-linked APT) deploying a custom C-based implant called MuddyRot in June 2024 campaigns, replacing their previous reliance on the Atera RMM tool. MuddyRot is a x64 backdoor offering reverse shell, file transfer, and persistence via scheduled tasks over raw TCP port 443, with command delivery obfuscated via simple byte-subtraction. The shift to homemade tooling likely reflects increased vendor monitoring of abused RMM platforms, enabling defenders to track MuddyWater more effectively.

SRFApplicationTACTA0005TACTA0001SRFNetworkTACTA0003TACTA0011SWMuddyrotVNDAtera
78
Edit Score
2026-06-11
2026-06-11 09:19Z
HIGH

PikaBot: a Guide to its Deep Secrets and Operations

Sekoia.io·sekoia.ioin the wild

Sekoia TDR provides a comprehensive technical analysis of PikaBot, a malware loader actively distributed by TA577 since February 2023. The analysis covers PikaBot's three-stage architecture, anti-analysis techniques (junk code, RC4 encryption, SysWhispers2 syscalls, environment detection), and C2 infrastructure tracking across 360+ unique IP addresses. The malware has been linked to Black Basta ransomware deployments and was disrupted during Operation Endgame in May 2024.

SRFApplicationTACTA0005TACTA0001TYPResearchTYPThreat IntelSTGDefense EvasionSTGExecutionSTGInitial Access
78
Edit Score
2026-06-11
2026-06-11 09:19Z
HIGH

DoppelGänger: inside the pro-Russian influence campaign

Sekoia.io·sekoia.io

Sekoia TDR published a comprehensive analysis of the DoppelGänger pro-Russian influence campaign, attributed to Russian entities Structura and the Social Design Agency (SDA), active since May 2022. The campaign uses typosquatted media sites, pseudo-independent news outlets, and inauthentic social media accounts across X, Facebook, TikTok, Instagram, and YouTube to spread disinformation targeting Western democracies, with specific focus on undermining support for Ukraine. Sekoia uncovered a new Russian-language cluster and control panel showing 26+ million site visits, demonstrating the campaign remains active and adaptive to geopolitical events.

TACTA0001TACTA0006SRFWebVNDMetaVNDYoutubeVNDFacebookVNDInstagramVNDTiktok
72
Edit Score
2026-06-11
2026-06-11 09:18Z
HIGH

Mallox Ransomware Affiliate Uses PureCrypter in MS-SQL Attacks

Sekoia.io·sekoia.ioin the wild

Sekoia's TDR team analyzed a Mallox ransomware affiliate campaign leveraging PureCrypter loader against MS-SQL servers via brute-force initial access and CLR assembly/xp_cmdshell exploitation. The attack chain demonstrates two distinct exploitation patterns: CLR assembly abuse with TRUSTWORTHY/clr_enabled parameters, and xp_cmdshell with OLE Automation for command execution. PureCrypter employs extensive anti-analysis evasion (Sandboxie/VM detection, AMSI/ETW patching, Defender exclusions) before reflectively loading and executing Mallox ransomware.

SRFApplicationTACTA0005TACTA0001TACTA0002SRFNetworkTACTA0003SWMalloxSWPurecrypter
72
Edit Score
2026-06-11
2026-06-11 09:18Z
HIGH

Assessing Cyber Threats to 2024 Worldwide Elections

Sekoia.io·sekoia.io

Sekoia TDR published a threat assessment of cyber operations targeting 2024 worldwide elections affecting 54% of global population. The analysis categorizes past election attacks into four types: hack-and-leak operations, information/influence campaigns, voting disruption attempts, and cybercrime; identifies US, European Parliament, Moldova, and India elections as likely targets; and assesses information campaigns as the primary threat vector over sophisticated intrusions.

TACTA0005TACTA0001SRFNetworkTYPResearchTYPThreat IntelSTGInitial AccessSTGReconTECT1598
62
Edit Score
2026-06-11
2026-06-11 07:16Z
HIGH

CVE-2026-41700 — Spring: for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41700

Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page, allowing the attacker to execute arbitrary GraphQL operations with the victim's credentials. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8; 1.0.0 through 1.0.6. CVSSv3.1 8.1 (HIGH)

CWECWE 346VNDSpringTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 07:16Z
HIGH

CVE-2026-41699 — Spring: for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41699

Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Execution when the application exposes a paginated (Connection) field and the classpath contains specific classes that can be leveraged during deserialization. Affected versions: Spring for GraphQL 2.0.0 through 2.0.3; 1.4.0 through 1.4.5; 1.3.0 through 1.3.8. CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDSpringTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 07:16Z
HIGH

CVE-2026-40999 — Addressing: When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40999

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8. CVSSv3.1 8.6 (HIGH)

CWECWE 918VNDAddressingTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-11
2026-06-11 07:16Z
HIGH

CVE-2026-40998 — Jaxp13XPathTemplate: Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40998

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0 CVSSv3.1 8.2 (HIGH)

CWECWE 611VNDJaxp13xpathtemplateTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 07:16Z
HIGH

CVE-2026-40994 — Wss4jSecurityInterceptor: initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40994

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8. CVSSv3.1 8.2 (HIGH)

CWECWE 1188VNDWss4jsecurityinterceptorTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 07:16Z
HIGH

CVE-2026-10795 — UpdraftPlus: The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10795

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp_loaded function. This is due to insufficient validation of the remote communications message format, where signature verification can be bypassed and unchecked decryption return values collapse to a predictable all-zero encryption key. This makes it possible for unauthenticated a CVSSv3.1 8.1 (HIGH)

CWECWE 347VNDUpdraftplusTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 06:30Z
CRIT

APT28, an evolution of tradecraft

Sekoia.io·sekoia.ioCVE-2023-23397CVE-2022-38028in the wild

Sekoia's Threat Detection & Research team published a comprehensive two-decade retrospective of APT28 (GRU Unit 26165) tradecraft evolution, documenting shifts from monolithic signature implants (X-Agent/X-Tunnel) through disposable single-task modules to recent infrastructure pivots onto compromised edge routers (MooBot, FrostArmada campaigns). The analysis reveals APT28's systematic migration to SOHO/edge device botnet infrastructure for credential harvesting, DNS hijacking, and C2 relay, with the FrostArmada campaign alone affecting 18,000+ IPs across 120+ countries and 200 organizations by December 2025.

SRFApplicationTACTA0001SRFNetworkSRFNetwork ApplianceTACTA0006TACTA0007SRFIdentityTACTA0008
88
Edit Score
2026-06-11
2026-06-11 04:16Z
CRIT

CVE-2026-35273 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35273

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrit CVSSv3.1 9.8 (CRITICAL)

VNDVulnerabilityTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-11
2026-06-11 00:00Z
CRIT

June Patch Tuesday smashes past 500-CVE mark

Microsoft released 209 patches addressing 24 product families in June 2026, surpassing 500 CVEs for the month when combined with 388 third-party advisories. Thirty-eight patches are Critical severity, with 16 expected to be exploited within 30 days; notably, CVE-2026-45585 (Windows BitLocker bypass) and multiple Office RCEs via Preview Pane are already under active exploitation. The patch set includes significant Graphics Component integer overflows (CVE-2026-44803, CVE-2026-44812) affecting Windows and Office, plus Chaotic Eclipse-related disclosures (MiniPlasma, RedSun, YellowKey, GreenPlasma).

SRFApplicationSRFOsTACTA0004TACTA0002OSWindowsSWAzureSWDefenderSWExchange
72
Edit Score
2026-06-10
2026-06-10 23:16Z
HIGH

CVE-2026-50223 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50223

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 23:16Z
HIGH

CVE-2026-47342 — Apache: A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47342

A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue. CVSSv3.1 8.8 (HIGH) · EPSS 4th percentile

CWECWE 285VNDApacheTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-10
2026-06-10 23:16Z
CRIT

CVE-2026-46703 — Boxlite: Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46703

Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not account for the possibility that entries may be symlinks pointing to absolute paths. An attacker can craft a malicious OCI image and distribute it on i CVSSv3.1 9.6 (CRITICAL)

CWECWE 22VNDBoxliteTYPVulnerability
9.6
CVSS v3.1
98
Edit Score