Related Threat Actors: GTG-10007, Charcoal Typhoon, Salmon Typhoon, SweetSpecter, Keyhole Panda, Vixen Panda, APT41, Ravine Castle
China and the Cyber Arms Race for AI Supremacy
Sep 21, 2026, 2:27:05 PM / by The Hivemind posted in Threat Bulletin, AI cybersecurity threats, Anthropic threat intelligence, Chinese APTs, Anthropic Claude, China cyber operations, PRC cyber operationsPRC cyber operations
BlueMoon Exploit Kit Rapidly Targets Key Verticals Across Multiple Espionage Campaigns
Sep 21, 2026, 1:13:44 PM / by The Hivemind posted in Threat Bulletin, BlueMoon exploit kit, BlueMoon exploit chain, Chrome zero-day exploit, BlueMoon cyberattack, Chromium zero-day
Verticals Targeted: Aerospace, Defense, Government, Financial, Manufacturing, Mining & Natural Resources, Nonprofit/NGO, Professional Services, Commodity Trading
Regions Targeted: US, Asia
Related Threat Actors: TA412 (Violet Typhoon), UNK_LateNight, UNK_DoubleCheck, UNK_QuietRacket
Related Families: BlueMoon, GemStone, ShadowPad
Executive Summary
Four espionage-focused threat actors were observed using BlueMoon, a newly tracked exploit kit chaining two Chromium V8 vulnerabilities with a Windows kernel privilege-escalation flaw. First observed in late August 2026, BlueMoon spread rapidly among mostly China-aligned clusters targeting organizations across the United States and Asia. Campaigns delivered payloads including GemStone and ShadowPad. Researchers also identified artifacts consistent with possible AI-assisted development, although evidence remains inconclusive. Proofpoint warns the kit may proliferate further as attackers increasingly exploit open-source patch gaps before downstream security updates reach users.
Gamers Get Played: Fake GTA6 Leaks Deliver a Grab Bag of Malware
Sep 14, 2026, 1:53:20 PM / by The Hivemind posted in Threat Bulletin, information stealer, GTA6 malware, video game malware, GTA6 ransomware, gaming malware
Verticals Targeted: Gamers
Regions Targeted: Eastern Europe
Related Families: Chaos, Mercurial Grabber, DCRAT, NJRAT
BraZetsu: AI-Enhanced Reconnaissance Fuels Exilware’s Access Marketplace
Sep 11, 2026, 1:23:19 PM / by The Hivemind posted in Threat Bulletin, initial access broker, BraZetsu, Infect Marketplace, AgenteV2, Banco de Infects, CNABHunter, Exilware
Verticals Targeted: Finance, Enterprise, Government, Industrial
Regions Targeted: Brazil, Latin America, Spain, US
Related Threat Actors: Exilware
Related Families: AgenteV2, CNABHunter
The Job Offer Has Claws: Mirage Kitten Deploys NodeRabbit and PollCat
Sep 8, 2026, 2:00:19 PM / by The Hivemind posted in Threat Bulletin, Nimbus Manticore, UNC1549, Mirage Kitten, Smoke Sandstorm, NodeRabbit malware, PollCat malware, Mirage Kitten APT
Verticals Targeted: Fintech, Aviation, Aerospace
Regions Targeted: Middle East, Africa, Egypt, Ethiopia, Afghanistan
Related Families: NodeRabbit, PollCat
Hooked on Espionage: BlueDelta Targets Europe with HOOKEDGE
Sep 4, 2026, 2:35:10 PM / by The Hivemind posted in Threat Bulletin, Fancy Bear, APT28, BlueDelta, Forest Blizzard, Russian cyberespionage, Russian GRU, BlueDelta malware, HOOKEDGE malware
Verticals Targeted: Government, Diplomacy, Defense Manufacturing
Regions Targeted: Romania, Spain, Turkey, Europe
Related Malware: HEADLACE
Executive Summary
Russian state-sponsored threat group BlueDelta deployed the HOOKEDGE Windows backdoor in espionage campaigns targeting European diplomatic, government, and defense-related organizations. Delivered through macro-enabled Microsoft Word documents, HOOKEDGE uses scheduled tasks, Microsoft Edge, and legitimate webhook services for C2, payload staging, and data exfiltration. The campaigns demonstrate BlueDelta’s continued refinement of established tradecraft to evade detection, minimize infrastructure requirements, and selectively escalate activity against targets assessed as having higher intelligence value.
SLEEPWALKER: Passive Backdoor Awakens Only When Attackers Call
Aug 31, 2026, 2:54:48 PM / by The Hivemind posted in Threat Bulletin, DLL side-loading, passive backdoor, ESET Management Agent malware, ERAAgent.exe, SLEEPWALKER malware
Executive Summary
SLEEPWALKER is a novel passive Windows backdoor. The malware is designed for DLL side-loading into the ESET Management Agent process ERAAgent.exe and does not autonomously beacon or contain fixed C2 infrastructure. Instead, SLEEPWALKER remains dormant until receiving a specially crafted network packet, then decrypts and executes attacker-supplied bytecode through a custom 23-instruction command language supporting scheduling, multiple communications mechanisms, staged payload delivery, lateral movement, and in-memory code execution.
UAT-10147 Uses AI-Assisted Workflows to Deploy SPECTRE Backdoor
Aug 28, 2026, 12:23:10 PM / by The Hivemind posted in Threat Bulletin, BYOVD attack, AI-assisted malware, UAT-10147, SPECTRE malware, AI-powered cybercrime, agentic AI cyberattacks, cross-platform malware
Verticals Targeted: Government, Education, Media, Technology, Gaming
Regions Targeted: Brazil, Bolivia, China, Canada, Vietnam
Executive Summary
Cisco Talos identified an advanced intrusion ecosystem operated by UAT-10147, a Chinese-speaking, financially motivated threat actor targeting internet-facing Windows and Linux servers. The group combines exploitation of known vulnerabilities with AI-assisted offensive workflows, custom malware, open-source tools, and commodity backdoors. Central to recent activity is SPECTRE, a cross-platform backdoor providing extensive post-exploitation, credential theft, process injection, and defense evasion capabilities. On Linux systems, SPECTRE can deploy the Specter kernel rootkit, while its Windows variant incorporates Bring Your Own Vulnerable Driver (BYOVD) functionality capable of neutralizing endpoint detection and response (EDR) visibility.