Introducing CAIRN: Frontier Tracking for AI-Integrated Malware by Cisco Talos
Cisco Talos has open-sourced CAIRN, a metadata-first framework engineered to detect and attribute AI-integrated malware without requiring binary execution. By utilizing 24 specialized acquisition filters and a three-tier YARA ontology (T1–T3), CAIRN identifies emerging threats such as LLM-powered Command and Control (C2) and AI-driven analysis evasion. The framework incorporates semantic clustering via UMAP/HDBSCAN and relationship graph exploration to map connections between samples, infrastructure, and threat actors. This capability provides scalable, proactive defense against the escalating autonomy of AI-enabled malware, such as the ClosedQuorum sample, by facilitating retroactive rule application and community-driven intelligence updates.
Lunex MaaS Platform Weaponizes AMD Driver CVE-2025-54517
The Lunex Malware-as-a-Service (MaaS) platform is deploying the Psychedelic Stealer by exploiting CVE-2025-54517 in the legitimate AMD driver amdhdl64.sys. This campaign utilizes a Bring Your Own Vulnerable Driver (BYOVD) technique to achieve unsigned kernel-mode code execution, allowing attackers to disable EDR sensors within approximately two minutes of infection. Following defense neutralization, the stealer harvests browser credentials, session cookies, and autofill data from Chrome, Edge, and Firefox. Targeting Ukrainian-speaking users via fake CAPTCHA/ClickFix social engineering prompts, the campaign has impacted approximately 12,000 endpoints, resulting in significant credential theft and an estimated $3.2M in financial losses.
ClosedQuorum: Autonomous AI C2 Implant Uses Model Panel Voting
The ClosedQuorum implant, first observed in-the-wild Q3 2024, is an autonomous AI‑driven command‑and‑control (C2) framework that employs an ensemble of specialized models (reconnaissance, lateral movement, data exfiltration) whose weighted votes select the next post‑compromise action without human operator input. This adaptive task selection reduces mean time to compromise by ~40% versus non‑AI C2 and evades signature‑based AV/EDR through behavioral variability, prompting Cisco Talos to release the open‑source CAIRN hunter for AI‑integrated malware.
PEEP Post-Exploitation Toolkit Targets Google Chrome and Microsoft Edge
PEEP is a specialized post-exploitation toolkit targeting Chromium-based browsers, specifically Google Chrome and Microsoft Edge. Deployed as a secondary-stage payload following initial administrative compromise or arbitrary code execution (ACE), PEEP achieves persistence by injecting malicious extensions directly into browser profile directories. The toolkit bypasses Web Store validation and suppresses installation prompts by forging "Secure Preferences" integrity values. By leveraging the Native Messaging API, PEEP establishes a communication bridge between the browser environment and the host operating system, enabling arbitrary shell command execution, credential exfiltration, and session hijacking, effectively transforming the browser into a stealthy command-and-control node.
Infostealer Compromise of Blind Eagle Malware Production Pipeline
A critical intelligence reversal has occurred where commodity infostealer campaigns—utilizing variants such as RedLine, Lumma, and Stealc—successfully compromised the development environment of the Blind Eagle APT. Utilizing delivery vectors including malicious GitHub repositories and impersonated brand lures, attackers exfiltrated high-value session cookies, SSH keys, and API tokens from Blind Eagle operators. This breach directly exposed the group's backend malware production pipeline, revealing build scripts, C2 management panels, and code signing certificates. This event demonstrates a potent "infostealer-to-APT" pipeline, where low-level commodity malware facilitates the breach of high-level state-sponsored infrastructure, allowing defenders to proactively generate signatures for future malware generated by this specific build system.
Silver Fox Leverages Signed QN Wallpaper Adware for ValleyRAT Deployment via DLL Sideloading
The threat actor Silver Fox is utilizing a sophisticated delivery chain to deploy the ValleyRAT Remote Access Trojan (RAT) by weaponizing the legitimate, digitally signed QN Wallpaper adware. The attack employs DLL sideloading, where the trusted QN Wallpaper executable is manipulated to load a malicious DLL containing the ValleyRAT payload. This technique exploits the inherent trust placed in digitally signed binaries and leverages common security configurations where users or administrators add known adware to antivirus exclusion lists. Once execution is achieved, the malware provides full remote system control and data exfiltration capabilities while operating under the guise of a legitimate, trusted process.
SLEEPWALKER Backdoor: ESET Management Agent Impersonation and Passive Trigger Evasion
The SLEEPWALKER backdoor targets ESET-managed environments by side-loading a malicious 64-bit dpapi.dll into the ESET Management Agent (ERAgent.exe). To evade detection, the malware maintains a passive in-memory state with no outbound C2 traffic or open ports, activating only upon receiving a specific "magic packet." Once triggered, it executes a proprietary 23-instruction bytecode language, enabling staged file delivery and in-memory code execution. This APT-style approach bypasses traditional network monitoring and antivirus tools by impersonating legitimate system DLLs and utilizing alternative communication channels, including VMware VMCI, to maintain a stealthy presence within the victim's security infrastructure.
Russian APT28 Campaign Leveraging HOOKEDGE and webhook.site for European Espionage
Between September 2025 and April 2026, a Russian GRU-linked threat actor, identified as BlueDelta (overlapping with APT28), conducted a targeted espionage campaign against defense and diplomatic organizations in Romania, Spain, and Trkiye. The attackers deployed "HOOKEDGE," a lightweight Windows batch script backdoor designed for stealthy command-and-control (C2). The campaign utilizes the legitimate developer utility webhook.site for C2 infrastructure and employs traffic masking techniques to mimic standard Microsoft Edge browser activity. This approach effectively bypasses traditional network security monitoring by blending malicious telemetry with benign web traffic, facilitating long-term persistence and data exfiltration from high-value geopolitical targets.
Global Takedown of the Sality P2P Botnet
On August 31, 2026, an international law enforcement and private sector operation successfully neutralized the Sality botnet, a resilient Peer-to-Peer (P2P) malware infrastructure active for over two decades. Led by the US Department of Justice and supported by Europol and CrowdStrike, the operation utilized specialized P2P node poisoning and sinkholing techniques to dismantle the botnet's decentralized command-and-control (C2) architecture. The botnet, linked to Russian-based malicious operations, infected over 11 million IP addresses globally, serving as a primary distribution hub for diverse payloads including ransomware, info-stealers, and loaders across multiple operating systems.
Iranian APT Screening Serpens Expands Espionage Capabilities with Six New RAT Variants
Iranian-aligned threat actor Screening Serpens has escalated its espionage operations by deploying six distinct Remote Access Trojan (RAT) variants. The campaign utilizes sophisticated social engineering via fraudulent recruitment platforms and fake job sites to target high-value technology professionals in the United States, Israel, and the United Arab Emirates. The malware employs advanced obfuscation, diverse Command and Control (C2) infrastructures, and complex persistence mechanisms to facilitate long-term network presence. This evolution indicates a strategic shift toward highly targeted intelligence gathering, aiming to compromise sensitive intellectual property and national security interests through credential harvesting and lateral movement within critical governmental and corporate infrastructures.