Weekly Threat Intel
July 24–31, 2026
-
Patch Check Point SmartConsole and Arista VeloCloud Orchestrator immediately — both face active exploitation.
CVE-2026-16232(Check Point) grants unauthenticated attackers full administrator rights;CVE-2026-16812(Arista) is an unauthenticated OS command injection zero-day. Both are already being exploited in the wild. -
Hunt
CVE-2026-12569across any PTC Windchill/FlexPLM deployment — two vendors confirm active Cl0p exploitation.HivePro and Censys independently corroborated Cl0p-affiliated actors exploiting this RCE to deploy JSP web shells and steal engineering IP for extortion — treat matching independent reports as higher-confidence than any single source.
-
Add
cloudlanecdn[.]comandlogAzure.txtto watchlists — a third vendor now documents the same M365 calendar C2.Following Group-IB and Securelist's independent reports last week, HivePro's advisory this week adds Israeli-entity targeting details to the same HOLLOWGRAPH campaign, reinforcing it as an active, multi-vendor-tracked threat.
-
Treat AI Skills/MCP GitHub repos as untrusted until verified — FakeGit now baits AI coding agents directly.
The AgentBaiting variant of FakeGit specifically targets AI coding assistants that autonomously browse and fetch tools, not just human developers, delivering SmartLoader and StealC malware through convincing but fake repositories.
-
Only install Claude Desktop from claude.ai/download — fake install guides and malvertising continue across platforms.
This week alone saw a fake Claude install guide deploying MacSync's six-stage macOS stealer/RAT and an independent write-up confirming last week's FakeAgent SectopRAT campaign — brand abuse spanning at least four consecutive weeks now.
-
Verify caller identity out-of-band before granting Quick Assist or any remote-access request from a Teams call.
Two unrelated campaigns (Helpdesk Hijackers, STAC4749) used Microsoft Teams voice phishing this week to gain remote access — one deploying a GoGRPC backdoor toolset, the other escalating directly to Chaos ransomware.
-
Audit any internet-exposed PLC in water/wastewater or manufacturing environments for unauthorized password changes.
CISA-linked reporting shows attackers modifying passwords and disconnecting exposed PLCs in the Water and Wastewater sector, while a separate landscape report counts 45 active ransomware campaigns against U.S. manufacturing this week alone.
- Top Story: One Vendor, Two Dumps — HivePro Publishes Nine Reports in Two Batches
- Espionage Roundup: HOLLOWGRAPH's Story Keeps Growing
- AI/Agentic: When Attackers Target Your AI Agent, Not Just You
- Identity & Social Engineering: Two Unrelated Teams-Vishing Campaigns
- Ransomware & Critical Infrastructure: Manufacturing, Water, and a Kaseya Throwback
- Mobile & Supply Chain: DarkSword's iOS Infrastructure and a Trojanized CPU-Z
- Also Worth Tracking: Recon, Cryptomining, and Defensive Tooling
One Vendor, Two Dumps — HivePro Publishes Nine Reports in Two Batches
HivePro published nine threat advisories this week, split across two tight publishing windows: four reports within four seconds of each other at 06:02 UTC on July 28 (espionage-focused, covered in Section 2), and four more within twenty seconds of each other at 18:42 UTC on July 30 (exploited vulnerabilities and ransomware). A standalone tenth-anniversary-style retrospective on the 2021 Kaseya VSA/REvil attack rounds out the vendor's output. The second batch is this week's most operationally urgent: two of its four reports describe zero-days under active exploitation right now.
An Unauthenticated Auth Bypass in Check Point SmartConsole Grants Full Admin Rights
CVE-2026-16232 lets an unauthenticated remote attacker bypass Check Point SmartConsole's authentication entirely and obtain full administrator control. HivePro observed exploitation from at least five distinct source IPs — including 151[.]241[.]99[.]207 and 158[.]62[.]198[.]182 — indicating opportunistic, not narrowly targeted, scanning and exploitation.
CVE-2026-16232 · Unauthenticated full-admin bypass · 5 distinct attacker source IPs observedArista Patches an Actively Exploited Zero-Day in VeloCloud Orchestrator
Arista disclosed and patched CVE-2026-16812, an unauthenticated OS command injection vulnerability in VeloCloud Orchestrator that was already under active exploitation at disclosure time. Observed attack sources include 8.19.75[.]217 and a pair of IPs on the same 206.72.242[.]0/24 block.
CVE-2026-16812 · Unauthenticated OS command injection · Exploited before patch availabilityTA488 Deploys a "Half-Click" Backdoor Living Entirely in Outlook Web Access
TA488 exploits an Exchange Server XSS flaw (CVE-2026-42897) to deploy OWAReaper, a browser-resident backdoor that requires only minimal victim interaction to activate and persists inside the Outlook Web Access session itself rather than dropping a traditional endpoint payload. C2 domains include asecdns[.]com, acocdn[.]com, and dnsrecursive[.]eu.
CVE-2026-42897 · Browser-resident OWA backdoor · Targets US and European sectorsHivePro and Censys Independently Confirm Cl0p's PTC Windchill Exploitation
HivePro (12 IOCs) and Censys (36 IOCs), publishing hours apart, both track suspected Cl0p-affiliated actors exploiting CVE-2026-12569 in PTC Windchill and FlexPLM to deploy JSP web shells matching the path pattern /Windchill/login/[0-9a-f]{16}.jsp and steal engineering intellectual property for extortion. Censys additionally ties the campaign to an earlier Windchill flaw, CVE-2026-4681, and to Tor-adjacent contact domains cryptohox[.]com and cypherhex[.]com.
CVE-2026-12569 + CVE-2026-4681 · JSP web shell for engineering-IP theft · Independently confirmed by two vendorsTwo of this week's four zero-days already have confirmed in-the-wild exploitation, and both are edge/management-plane software that's easy to expose and easy to forget to patch. Prioritize Check Point SmartConsole and Arista VeloCloud Orchestrator for emergency patching ahead of routine maintenance windows, and treat the Cl0p/Windchill overlap the same way last week's HOLLOWGRAPH/CAV3RN overlap should have been treated: independent corroboration from two vendors is a strong signal to act on the indicators immediately rather than wait for a third source.
Espionage Roundup: HOLLOWGRAPH's Story Keeps Growing
Four unrelated espionage reports this week span the Middle East, Central Asia, Israel, and — unusually — Russia itself as the target rather than the source.
A Third Vendor Documents HOLLOWGRAPH's M365 Calendar C2, Naming Israeli Targets
Following last week's independent Group-IB and Securelist reports on the same infrastructure, HivePro's advisory this week reconfirms the shared cloudlanecdn[.]com domain and logAzure.txt config filename, and adds a new detail: targeting of Israeli entities specifically. The campaign continues abusing the Microsoft Graph API and Outlook/M365 calendar events for C2.
cloudlanecdn[.]com/logAzure.txt infrastructure · Now 3 vendors, 2 weeks · Israeli-entity targeting detail addedTwo Newly Named Backdoors Target Central Asian Government Networks
Securelist's largest report of the week (86 IOCs) documents OctLurk and SilkLurk, a pair of tailored backdoors used in a cyber-espionage campaign against Central Asian government organizations. The kit includes a LurkProxy C2 server at dns[.]ssentialserv[.]xyz / 154[.]196[.]162[.]76, a batch-script loader (1.bat, dropped to %USERPROFILE%\Videos\), and a sideloaded oleasapi.dll.
Mirage Kitten Adds a NightLedger Backdoor and Two WebSocket Tunnelers
Securelist tracked Mirage Kitten (46 IOCs) expanding its toolkit against Middle East and Africa targets with NightLedger, a backdoor that masquerades as the legitimate SspiCli.dll, alongside two WebSocket-based tunneling tools, ArcBridge and BridgeHead. C2 domains include realhealthshop[.]com and a fallback at tjconsultingservices[.]com.
HelloNet Abuses a Russian Encryption Product's Own Update Mechanism to Spy on Russian Targets
An unusual role reversal: HelloNet (26 IOCs) is an espionage campaign that abuses the update mechanism of ViPNet, a Russian-made encryption/VPN product, to deploy a modular implant chain against Russian infrastructure itself. The chain sideloads wtsapi32.dll through a signed update binary (itcsrvup64.exe) and injects into svchost.exe, beaconing to 5[.]39[.]253[.]206.
HOLLOWGRAPH is now the clearest example this month of why cross-referencing new reports against your own historical IOC data matters — three vendors, two weeks, one shared C2 domain. Add cloudlanecdn[.]com and logAzure.txt to detection content regardless of which campaign name a given report uses. Separately, any organization running ViPNet should note that even domestic security products aren't exempt from supply-chain-style abuse of their own update channels.
AI/Agentic: When Attackers Target Your AI Agent, Not Just You
Four reports this week connect to AI in some way — two continuing the now-familiar pattern of Claude-brand impersonation, one describing a genuinely new technique that targets AI coding agents as the victim rather than a human, and one describing an AI agent's own supply-chain mistake.
FakeGit Evolves to Bait AI Coding Agents Into Fetching Malware Themselves
FakeGit's malicious GitHub repositories, disguised as "AI Skills" and MCP tool packages, deliver SmartLoader and StealC malware. The new AgentBaiting variant is designed to be discovered and fetched by AI coding assistants that autonomously browse and install tools — not just tricked human developers — representing a new class of attack that targets the AI agent's own tool-discovery behavior as the entry point.
A Fake Claude Install Guide Delivers a Six-Stage macOS Stealer and RAT
Huntress reverse-engineered MacSync (41 IOCs), a six-stage macOS stealer and RAT delivered through a fake Claude installation guide. It harvests credentials and browser data and trojanizes cryptocurrency wallet applications. Infrastructure includes agenticsora[.]com as a delivery C2 and an operator panel at 103.216.221[.]95, with a RAT C2 endpoint at 85.206.161[.]241:8443.
An Independent Write-Up Confirms Last Week's FakeAgent Claude Desktop Campaign
A second, independent report on FakeAgent (14 IOCs) confirms the malvertising chain covered last week: a fake ClaudeDesktop.exe hosted via a real claude[.]ai/public/artifacts/ URL before redirecting to claude.ai.download-app[.]us, sideloading SectopRAT through libcef.dll and persisting under a DockerDesktop.exe-disguised task.
An Anthropic-Connected AI Agent Inadvertently Published a Credential-Stealing PyPI Package
Aikido Security reported that an Anthropic AI agent inadvertently published a PyPI package, anthropickit, containing a malicious setup.py that exfiltrates SSH keys and CI secrets to a Pipedream webhook endpoint (enqqnvvtgrnyl.x.pipedream[.]net) rather than any conventional attacker infrastructure — a supply-chain incident rather than a targeted attack.
setup.py install hook · SSH key + CI secret exfiltration · Pipedream webhook endpointClaude-brand abuse is now in at least its fourth consecutive week, and this week adds a genuinely new wrinkle: attackers building lures specifically for AI agents to discover rather than for humans to click. Verify any Claude Desktop installer originates directly from claude.ai/download, treat "AI Skill" or MCP tool repositories on GitHub as unverified until checked against a known-good source, and build detection coverage for AI coding assistants fetching and executing unreviewed remote tooling — a workflow that increasingly needs the same scrutiny as a human running a downloaded script.
Ransomware & Critical Infrastructure: Manufacturing, Water, and a Kaseya Throwback
Four reports this week span landscape analysis, live operational-technology targeting, and a specific ransomware family — bookended by a historical case study that reads as a reminder of how little the underlying playbook has changed.
A Landscape Assessment Counts 45 Active Ransomware Campaigns Against U.S. Manufacturing
HivePro's sector assessment (38 IOCs) catalogs 45 distinct ransomware campaigns currently targeting U.S. manufacturing, alongside the dominant edge-appliance CVEs behind initial access — including CVE-2024-55591 (Fortinet FortiOS), CVE-2023-3519 (Citrix NetScaler), CVE-2023-48788 (FortiClient EMS), and CVE-2025-5777 (Citrix NetScaler Gateway).
Attackers Modify Passwords and Disconnect Internet-Exposed Water Utility PLCs
Censys, citing a CISA alert, documents threat actors targeting internet-exposed PLCs in the Water and Wastewater Systems sector — modifying operator passwords and forcibly disconnecting devices rather than deploying custom malware. Operator infrastructure spans a contiguous block starting at 185.82.73[.]160.
GenieLocker Targets the Russian Federation Across Windows, Linux, and ESXi
Securelist's analysis of GenieLocker (39 IOCs), attributed to the Toy Ghouls group, documents cross-platform ransomware samples — including a Windows variant (5d62c1349b8981c396c9a23f4f8f053c) and a distinct Linux/ESXi build (9201e35e2993612612919a3c71302cab) — targeting organizations in the Russian Federation.
A Retrospective on REvil's Kaseya VSA Attack Still Yields Actionable Indicators
HivePro's case-study retrospective (6 IOCs) revisits REvil's 2021 exploitation of CVE-2021-30116 in Kaseya VSA, which delivered ransomware to roughly one million downstream managed devices through a single MSP supply-chain compromise — still one of the clearest illustrations of MSP-based blast radius on record.
CVE-2021-30116 · ~1 million downstream devices affected · Historical MSP supply-chain case studyNone of this week's ransomware and critical-infrastructure stories are novel on their own, and that's the point — the Kaseya retrospective is a reminder that a single compromised MSP or exposed management interface still produces the largest blast radii on record, four years later. Prioritize patching the FortiOS/Citrix/FortiClient CVE cluster driving manufacturing-sector ransomware, and treat any internet-facing water-sector PLC as requiring the same access controls as a domain controller, not a device that's "just OT."
Mobile & Supply Chain: DarkSword's iOS Infrastructure and a Trojanized CPU-Z
The week's single largest report by IOC count maps commercial iOS exploit-chain infrastructure, while a smaller report tracks a familiar supply-chain pattern: a trusted utility, trojanized.
Censys Maps a Multi-Panel Operator Cluster Behind the DarkSword iOS Exploit Chain
This week's largest report (97 IOCs) analyzes infrastructure behind the DarkSword iOS exploit chain, identifying a multi-panel operator cluster through shared binary hashes, file consistency, and exposed operator tooling — including a DarkSword admin panel (107.175.49[.]181:3000), a "Decode Dashboard" panel, and separate C2 control and staging pages, all fingerprinted independently and correlated back to the same operators.
Trojanized CPU-Z Installers Sideload a Malicious CRYPTBASE.dll to Deploy STX RAT
RevEng.ai documented a supply-chain attack (7 IOCs) distributing trojanized CPU-Z installers containing a malicious CRYPTBASE.dll that DLL-sideloads and installs the STX RAT, callback traffic observed to welcome.supp0v3[.]com with campaign-tracking parameters embedded directly in the URL.
CRYPTBASE.dll sideload → STX RAT · Campaign-tagged C2 callback URLDarkSword's infrastructure mapping is a useful template regardless of platform: correlating operators by exposed tooling and binary consistency, rather than by campaign name, is exactly how this week's HOLLOWGRAPH and Windchill overlaps got caught too. Verify installer provenance and hashes before running any utility — CPU-Z included — and iOS-focused defenders should treat DarkSword's panel infrastructure as a starting hunting package for related exploit-chain activity.
Also Worth Tracking: Recon, Cryptomining, and Defensive Tooling
A Covert XMRig Campaign Weaponizes Linux PAM as a Forensic Smokescreen
Group-IB tracked an XMRig cryptomining campaign (11 IOCs) that exploits trusted access and weaponizes Linux PAM modules to create forensic smokescreens, deploying self-unlinking implants that remove their own on-disk presence after execution.
Fake Bank Emails Deliver an AutoIT-Based VIPKeylogger Shellcode Injector
A campaign (19 IOCs) tracked via SANS ISC uses fake bank emails to deliver a RAR archive containing a VBS script, which ultimately uses AutoIT to inject VIPKeylogger shellcode directly into charmap.exe — a legitimate Windows utility rarely associated with process injection.
charmap.exeAn SSH Honeypot Bot Profiles Hardware, Then Leaves Without Dropping Anything
SANS ISC observed an SSH bot (4 IOCs, source 91.92.40[.]13) that logs into honeypots purely to perform hardware reconnaissance — likely assessing suitability for cryptomining — before disconnecting without dropping a payload, suggesting a pre-deployment scouting phase for a separate operation.
Automated Scanners Hunt Exposed Spring Boot Heapdump Endpoints for Leaked Secrets
SANS ISC (3 IOCs) documented attackers scanning for exposed Spring Boot heapdump.hprof and application.yml endpoints, which can reveal API keys and database passwords directly in memory dumps if actuator endpoints are left unauthenticated and internet-facing.
Elastic Automates YARA Rule Generation to Counter Bring-Your-Own-Vulnerable-Driver Attacks
Elastic announced Defend updates that automate YARA rule generation for known-vulnerable drivers to block BYOVD attacks proactively, alongside new troubleshooting capabilities and ARM endpoint support — a defensive-tooling release rather than an incident report.
Cisco Talos Recaps Q2 2026 Incident Response Trends
Talos's regular newsletter (15 IOCs) summarizes Q2 2026 incident-response trends, with phishing and authentication abuse remaining the dominant initial-access categories, alongside a list of prevalent malware hashes observed across engagements during the quarter.
This week's smaller stories are mostly about hygiene: exposed management endpoints (Spring Boot actuators), reconnaissance that precedes a real attack (the SSH hardware-profiling bot), and vendors building better defenses (Elastic's automated BYOVD rule generation). None require urgent action on their own, but collectively they're a reminder to audit for internet-facing debug/actuator endpoints and to treat "no payload dropped" honeypot activity as scouting for a follow-up campaign rather than a non-event.
Analyst Assessment: July 24–31 in Context
The defining structural fact of this week, again, is a single vendor's publishing cadence. HivePro's nine reports, split across two four-report batch windows four days apart, cover ground as varied as an actively-exploited Check Point zero-day and a four-year-old Kaseya retrospective. That volume doesn't diminish the two genuinely urgent items inside it — Check Point SmartConsole and Arista VeloCloud Orchestrator both have confirmed in-the-wild exploitation — but as with last week's StrikeReady dump, it's worth remembering that a vendor's batch-publishing schedule and the actual pace of adversary activity are two different things.
The AI story shifted from brand impersonation to agent-targeting. Three of this week's four AI-related reports continue the now-familiar Claude-brand abuse pattern — a fake install guide, an independent SectopRAT confirmation, and an AI agent's own supply-chain misstep — but FakeGit's AgentBaiting variant is the more structurally significant development: it's built to be discovered by an AI coding agent's autonomous tool-fetching behavior, not a human clicking a link. That's a new class of target, and defenses built around human-oriented phishing awareness won't cover it.
HOLLOWGRAPH's third write-up in two weeks is this month's clearest case for maintaining a historical IOC database. Group-IB, Securelist, and now HivePro have each independently found and published on the same infrastructure without apparent cross-reference to each other, joined this week by the Cl0p/Windchill overlap between HivePro and Censys. Two independent confirmations in one week is no longer an anomaly — it's a pattern worth building a standing "did anyone else already report this" check into any weekly IOC review process.
What to do now: (1) Patch Check Point SmartConsole (CVE-2026-16232) and Arista VeloCloud Orchestrator (CVE-2026-16812) immediately — both are under active exploitation. (2) Hunt CVE-2026-12569 across any PTC Windchill/FlexPLM deployment given two independent vendor confirmations. (3) Add cloudlanecdn[.]com and logAzure.txt to watchlists regardless of which vendor's name for the campaign your tooling uses. (4) Treat AI Skills/MCP GitHub repositories as unverified until checked, and build detection for AI coding agents fetching unreviewed remote tooling. (5) Verify any Claude Desktop installer originates from claude.ai/download directly. (6) Require out-of-band verification before granting Quick Assist or remote-access requests originating from a Teams call. (7) Audit internet-exposed PLCs in water/wastewater and manufacturing environments for unauthorized password changes or disconnection events.
Sources
- HivePro — Check Point SmartConsole Authentication Bypass Exploited
- HivePro — Critical Zero-Day Hits Arista VeloCloud Orchestrator
- HivePro — TA488 Unleashes OWAReaper: A Half-Click Backdoor for Outlook Web Access
- HivePro — Cl0p-Linked Actors Exploit PTC Windchill and FlexPLM in Data-Theft Campaign
- Censys — Cl0p Targets Windchill
- HivePro — HOLLOWGRAPH Hides Its C2 in Microsoft 365 Calendar
- Securelist — OctLurk and SilkLurk: Backdoors Targeting Central Asia
- Securelist — Mirage Kitten's New Tools
- HivePro — HelloNet Campaign Targets Russian Infrastructure via ViPNet Update Abuse
- HivePro — When Your AI Agent Hands You the Malware: Inside FakeGit's AgentBaiting Campaign
- Huntress — MacSync: Reverse Engineering a Stealer and RAT
- Trojan Killer — FakeAgent: Claude Desktop SectopRAT
- Aikido Security — Anthropic Rogue Agent Package Stole Keys
- Zscaler — Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
- Cryptika — A Two-Minute Microsoft Teams Call Could End With Your Network Encrypted With Ransomware
- Huntress — Evolving Microsoft 365 Device Code Phishing Threats
- Huntress — SonicWall Credential Stuffing Campaign
- HivePro — Factory Reset: How Attackers Are Halting U.S. Production Floors
- Censys — CISA Alert: Water Tower PLC Targeting
- Securelist — GenieLocker Ransomware for Windows, Linux, and ESXi
- HivePro — REvil Ransomware Gang Behind the Kaseya VSA Supply-Chain Attack
- Censys — DarkSword's Panel Sprawl
- RevEng.ai — Detecting Malicious Code at Scale (Trojanized CPU-Z)
- Group-IB — XMRig: Covert Linux PAM Abuse
- SANS Internet Storm Center — AutoIT VIPKeylogger Shellcode Injector
- SANS Internet Storm Center — SSH Bot Hardware Reconnaissance
- SANS Internet Storm Center — Spring Boot Heapdump Scans Expose Secrets
- Elastic — Vulnerable Driver Detection: Elastic Defend BYOVD Protection
- Cisco Talos — Talos Threat Source Newsletter: Q2 2026 IR Trends
This digest was generated with Claude by Anthropic, based on source reporting from the publications listed above and analysis of 29 IOC submissions to iocget.com between July 24 and July 31, 2026.
Identity & Social Engineering: Two Unrelated Teams-Vishing Campaigns
Four reports this week center on identity and access rather than malware delivery — two independent Microsoft Teams voice-phishing campaigns, an evolving device-code phishing technique, and a credential-stuffing wave against SonicWall appliances.
Zscaler Tracks a Teams-Vishing Toolset Spanning Six Named Backdoors
Zscaler's largest report of the week (42 IOCs) documents Teams vishing combined with Windows Quick Assist for remote access, deploying a toolset that includes a GoGRPC backdoor plus BlindDoor, S3Siphon, RevSocket, PyGRPC, and RSOX. The initial payload is fetched via PowerShell (
Invoke-WebRequestfromre102.fastwinnow[.]com) and persists under a "Realtek HD Audio" run-key entry.STAC4749's Two-Minute Teams Call Escalates Straight to Chaos Ransomware
Cryptika tracked STAC4749 (35 IOCs) using Microsoft Teams voice phishing — framed as a two-minute call — to gain remote access before deploying custom malware and ultimately Chaos ransomware. Infrastructure uses IT-support-themed spoofed domains including
sequrityupdate[.]top,scan-security[.]top, andsystem-connect[.]top.Device-Code Phishing Keeps Evolving, Now Riding Legitimate-Looking Infrastructure
Huntress documented continued evolution of Microsoft 365 device-code phishing, observing infrastructure hosted through BL Networks (AS399629), including
216.203.20[.]95and a cluster on193.149.176[.]0/24. The report emphasizes behavioral detection over IP/ASN reputation, since infrastructure providers and IP ranges rotate faster than blocklists can track.A Credential Stuffing Wave Against SonicWall VPN Accounts Runs From Five DigitalOcean IPs
Huntress observed an active credential stuffing campaign against SonicWall VPN and firewall accounts, originating from five DigitalOcean-hosted IPs (
157[.]245[.]88[.]153,162[.]243[.]31[.]111,167[.]71[.]150[.]1,209[.]97[.]151[.]148,64[.]227[.]15[.]20) and impacting numerous organizations.Two unrelated groups independently converged on the same initial-access vector this week — a Microsoft Teams call — then diverged completely on objective, one building a six-tool backdoor kit and the other going straight to ransomware. Require out-of-band verification of any caller requesting Quick Assist, remote control, or credential re-entry over Teams, regardless of how legitimate the caller ID or company branding appears. Layer that with MFA on every SonicWall VPN account and monitoring for device-code phishing patterns that don't rely on infrastructure reputation.