Weekly Threat Digest: 14 to 20 September 2026
HiveForce Labs tracked ten attacks, eight actively exploited vulnerabilities and two adversaries this week, led by Cisco ISE and Secure Email Gateway zero-days, GitLab CVE-2026-85706, and Kimsuky's expanded espionage toolkit.
Summary
HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, ten major attacks were detected, eight vulnerabilities were actively exploited, and two threat actor groups were closely monitored, signaling a concerning escalation in malicious activity worldwide.
Among the most significant developments, Cisco has confirmed zero-day exploitation of CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass in Identity Services Engine that grants unauthenticated attackers root-level command execution, alongside CVE-2026-76461 (CVSS 9.8), where a single crafted email compromises Secure Email Gateway with root privileges. In parallel, GitLab patched CVE-2026-85706, a maximum-severity path traversal in self-managed CE and EE that enables unauthenticated arbitrary file read, with scanning escalating to theft of configuration and SSH files within days.
Elsewhere, Kimsuky, the North Korean espionage group, expanded its arsenal with AI-generated lures, weaponized QR codes harvesting Microsoft 365 and Okta credentials, and Operation GitPower, which routes payloads and exfiltration through GitHub, Pastebin, Dropbox, and Slack. Separately, Stormous, the Arabic-speaking extortion group active since 2021, announced the termination of its operations and took all leak-site mirrors offline, though a rebrand cannot be ruled out. Together, these incidents reinforce a landscape in which rapidly weaponised edge-facing vulnerabilities and patient, evasion-heavy espionage operations advance side by side, underscoring the need for prompt patching of internet-facing systems and continuous monitoring for post-exploitation activity.
Insights
CVE-2026-76460 is a Cisco ISE authentication bypass under active zero-day exploitation, granting unauthenticated attackers root command execution.
JFrog Artifactory flaws were chained to forge persistent admin tokens on internet-facing repositories, peaking at 406,000 attempts in a day, and the minted tokens survive patching.
CVE-2026-85706 is a GitLab path traversal allowing unauthenticated file read on self-managed servers, exploited within a day to steal SSH and configuration secrets.
Kimsuky, the North Korean espionage group, expanded its arsenal with AI-generated lures, weaponized QR codes, and Operation GitPower, routing payloads and stolen data through GitHub, Pastebin, Dropbox, and Slack.
Stormous, the Arabic-speaking extortion group with up to 240 claimed victims, announced its shutdown and took all leak-site mirrors offline, though a rebrand cannot be ruled out.
CVE-2026-76461 lets a single crafted email seize root on Cisco Secure Email Gateway, with no login, password, or user interaction required.
Threat distribution
Vulnerability volume
Attacks Executed
AppleSeed (KGH_SPY)
AppleSeed is Kimsuky's flagship espionage implant, first seen in 2019 and still active through version 2.1, with the KGH_SPY suite tracked as a closely related modular toolset from the same actor. KGH_SPY is a modular spyware suite giving the operators reconnaissance, keylogging, information-stealing and backdoor functions. The AppleSeed family ships in two forms: a Dropper variant that pulls down further malware and runs C2 commands, and a Spy variant that harvests documents, screenshots, keystrokes and USB drive listings.
- Type
- Backdoor
- Actor
- Kimsuky
- Delivery
- Spear-phishing emails
- Impact
- Persistent access, remote execution, keystroke logging
- Platform
- Windows
- Targeted CVE
- -
HappyDoor
HappyDoor is a backdoor, with the name taken from the "happy" string found in its export DLL name and debug data. It is a DLL that stores its configuration, including C2 addresses and encryption keys, in registry paths designed to look like legitimate software, and it communicates using a custom fixed-length packet structure with several authentication fields.
- Type
- Backdoor
- Actor
- Kimsuky
- Delivery
- Spear-phishing emails
- Impact
- Persistent access, remote execution, screen capture, file exfiltration
- Platform
- Windows
- Targeted CVE
- -
HelloDoor
HelloDoor is a DLL-based backdoor and is Kimsuky's first known malware written in Rust, a language the group rarely uses. Its C2 is hosted on TryCloudflare, a temporary Cloudflare tunneling service that requires no account or setup, which makes the infrastructure behind it hard to trace. On execution it fingerprints the host using the MAC address, computer name and a fixed string, hashes that into a unique ID, and binds to local port 5555 or 5554 depending on whether its token is elevated.
- Type
- Backdoor
- Actor
- Kimsuky
- Delivery
- Spear-phishing emails
- Impact
- Autorun tampering, host fingerprinting, local port-binding, process termination
- Platform
- Windows
- Targeted CVE
- -
httpMalice
httpMalice is a backdoor, surfacing no later than December 2025. It profiles the host with Windows commands run under code page 949, indicating Korean-language (EUC-KR) targets, and its command set covers file transfer, directory archiving and upload, screen capture, in-memory payload loading, hibernation and self-removal.
- Type
- Backdoor
- Actor
- Kimsuky
- Delivery
- Spear-phishing emails
- Impact
- Persistent backdoor, service creation, remote execution
- Platform
- Windows
- Targeted CVE
- -
httpTroy
httpTroy is the final-stage backdoor in a Kimsuky three-part chain. Its role is long-term access and data exfiltration. It marks infected hosts by writing eight random bytes to an Alternate Data Stream, depending on whether it holds an elevated token. It is heavily obfuscated: API calls are hidden behind custom hashing and strings are scrambled with XOR and SIMD operations, with both reconstructed at runtime rather than reused, which frustrates static analysis.
- Type
- Backdoor
- Actor
- Kimsuky
- Delivery
- Spear-phishing
- Impact
- Remote execution, reverse shell, file transfer, persistent access
- Platform
- Windows
- Targeted CVE
- -
MemLoad
MemLoad is a loader; its purpose is twofold: to keep the real backdoor off disk to evade detection and vet the target before committing the payload, using anti-VM checks and basic reconnaissance.
- Type
- Loader
- Actor
- Kimsuky
- Delivery
- Spear-phishing attachment
- Impact
- Payload delivery, memory injection, scheduled-task persistence, privilege check
- Platform
- Windows
- Targeted CVE
- -
HTTPSpy
HttpSpy is a remote access trojan seen in use around April 2026 against South Korean military and enterprise targets. The newer variant abandons the old single-binary design for a three-stage chain with the final RAT decrypted and executed entirely in memory. Its command set covers shell execution, file upload in chunks and download, screen capture, secure file wiping, timestomping, DLL injection into a chosen process, execution in a specified terminal session, TCP connectivity testing, live config updates and full self-uninstall.
- Type
- RAT
- Actor
- Kimsuky
- Delivery
- Spear-phishing attachments
- Impact
- Remote execution, file exfiltration, file download
- Platform
- Windows
- Targeted CVE
- -
AsyncRAT
AsyncRAT is a widely available open-source .NET remote access trojan, not custom Kimsuky tooling; the group adopts it alongside other commodity RATs. In Kimsuky's hands, it appears most prominently in the campaign tracks as Operation GitPower, where encrypted AsyncRAT payloads are staged in Git repositories disguised as image files, with GitHub serving as both the distribution point and the C2 channel so traffic blends into trusted developer infrastructure.
- Type
- RAT
- Actor
- Kimsuky
- Delivery
- Spear-phishing
- Impact
- Remote control, keystroke logging, screen capture, credential theft
- Platform
- Windows
- Targeted CVE
- -
StormousX
StormousX is the ransomware program the Stormous group has marketed under its own brand since 2023 and later offered alongside GhostLocker through the STMX_GhostLocker affiliate service. It is advertised as a file-encrypting payload supporting the group's double-extortion operations, with victims listed across multiple regions.
- Type
- Ransomware
- Actor
- Stormous
- Delivery
- Phishing
- Impact
- Data theft and public leak
- Platform
- -
- Targeted CVE
- -
XMRig
XMRig is an open-source, cross-platform Monero (XMR) cryptocurrency miner that is legitimate software but is one of the most widely abused tools in illicit cryptojacking, as attackers embed it in malware chains to hijack victim CPU resources for mining.
- Type
- Cryptominer
- Actor
- -
- Delivery
- Social engineering
- Impact
- Resource hijacking, persistent access
- Platform
- ConnectWise ScreenConnect
- Targeted CVE
CVE-2026-84869
Vulnerabilities Exploited
CVE-2026-85706
- Affected product
- GitLab CE/EE self-managed (18.7 before 19.1.8; 19.2 before 19.2.6; 19.3 before 19.3.2)
- CWE ID
CWE-22- Associated TTPs
- T1190: Exploit Public-Facing Application, T1005: Data from Local System
- Associated attacks
- -
- Patch link
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
CVE-2026-76461
- Affected product
- Cisco Secure Email Gateway (AsyncOS): 15.5 and earlier (before 15.5.5-014), 16.0 (before 16.0.4-302), 16.5 (before 16.5.0-780)
- CWE ID
CWE-89- Associated TTPs
- T1190: Exploit Public-Facing Application, T1059: Command and Scripting Interpreter
- Associated attacks
- -
- Patch link
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX
CVE-2026-87886
- Affected product
- Acronis Backup plugin for cPanel & WHM (before 1.9.3.1021); Acronis Backup extension for Plesk (before 1.8.11.638)
- CWE ID
CWE-276- Associated TTPs
- T1068: Exploitation for Privilege Escalation
- Associated attacks
- -
- Patch link
https://security-advisory.acronis.com/updates/UPD-2609-3d72-20a7https://security-advisory.acronis.com/updates/UPD-2609-efb0-50b2https://security-advisory.acronis.com/advisories/SEC-10986
CVE-2026-84869
- Affected product
- ConnectWise ScreenConnect client version before 26.6.5
- CWE ID
CWE-269, CWE-862- Associated TTPs
- T1068: Exploitation for Privilege Escalation, T1548: Abuse Elevation Control Mechanism
- Associated attacks
- XMRig cryptominer
- Patch link
https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
CVE-2026-76460
- Affected product
- Cisco ISE & ISE-PIC (releases 3.0 through 3.5, before the first fixed release)
- CWE ID
CWE-648- Associated TTPs
- T1190: Exploit Public-Facing Application, T1068: Exploitation for Privilege Escalation
- Associated attacks
- -
- Patch link
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
CVE-2026-42016
- Affected product
- JFrog Artifactory Self-Hosted before 7.133.11
- CWE ID
CWE-863- Associated TTPs
- T1583: Acquire Infrastructure, T1587: Develop Capabilities, T1528: Steal Application Access Token, T1190: Exploit Public-Facing Application
- Associated attacks
- -
- Patch link
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
CVE-2026-42018
- Affected product
- JFrog Artifactory Self-Hosted before 7.111.20; 7.117.0 to 7.117.27; 7.125.0 to 7.125.19; 7.133.0 to 7.133.28; 7.146.0 to 7.146.8
- CWE ID
CWE-287- Associated TTPs
- T1190: Exploit Public-Facing Application, T1562: Impair Defenses
- Associated attacks
- -
- Patch link
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
CVE-2026-82329
- Affected product
- JFrog Artifactory Self-Hosted 7.111.4 to 7.111.20; 7.117.0 to 7.117.27; 7.125.0 to 7.125.19; 7.133.0 to 7.133.28; 7.146.0 to 7.146.37; 7.161.0 to 7.161.19
- CWE ID
CWE-287- Associated TTPs
- T1190: Exploit Public-Facing Application, T1562: Impair Defenses
- Associated attacks
- -
- Patch link
https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
Adversaries in Action
Kimsuky
- Also known as
- APT43, Thallium, THALLIUM, Velvet Chollima, Black Banshee, Emerald Sleet, Ruby Sleet, Sparkling Pisces, Springtail, TA427, TA406, Earth Kumiho, PatheticSlug, ARCHIPELAGO, SharpTongue, ITG16, Greendinosa, RGB-D5, Cerium
- Origin
- North Korea
- Motive
- Espionage, financial gains
- Targeted industries
- Government, Public Administration, Defense, Think Tanks, Policy Research Institutes, Academia, Universities, NGOs, Human Rights Organizations, Media, Healthcare, Machinery, Energy, Nuclear Power Operations, Manufacturing, Business Services, Legal Services, Construction, Financial, Insurance, Retail, Cryptocurrency
- Targeted regions
- South Korea, United States, Japan, Vietnam, Thailand, Brazil, Germany, Russia, Canada, and broader Europe
- Targeted CVEs
CVE-2017-11882CVE-2018-0802CVE-2019-0708CVE-2019-1405CVE-2020-0787CVE-2024-1709CVE-2025-48703- Associated attacks
- AppleSeed (KGH_SPY), AlphaSeed, HappyDoor, PebbleDash, HelloDoor, httpMalice, httpTroy, MemLoad, HTTPSpy, AsyncRAT, BabyShark, GoldDragon, KLogEXE, Troll Stealer, Gomir, NavRAT, NikiHTTP, NikiTeaR, ComeBacker, DRATzarus, FastFire, FastSpy, FlowerPower, RandomQuery, Yorekey, Grease, TRANSLATEXT, QuasarRAT, Gh0st RAT, KimJongRAT, CSPY Downloader, BITTERSWEET, VENOMBITE, xRAT, MailFetch.py, Reger Dropper, Pidoc Dropper
- Affected products
- GitHub, Pastebin, Dropbox, Slack, Cloudflare Quick Tunnels, Visual Studio, Microsoft 365, Okta
- Key TTPs
T1566Phishing,T1566.001Spearphishing Attachment,T1566.002Spearphishing Link,T1657Financial Theft,T1041Exfiltration Over C2 Channel,T1111MFA Interception,T1056.001Keylogging,T1102Web Service,T1071.001Web Protocols,T1003.001LSASS Memory,T1059.001PowerShell,T1105Ingress Tool Transfer,T1190Exploit Public-Facing Application,T1203Exploitation for Client Execution,T1588.007Artificial Intelligence,T1620Reflective Code Loading,T1682Query Public AI Services
Stormous
- Motive
- Financial gain
- Associated ransomware
- StormousX
- Targeted industries
- Technology, Business Services & Consulting, Manufacturing, Retail, Hospitality, Education, Healthcare, Telecommunications, Media, Government, Financial Services, Pharmaceutical, Energy, Transportation, Casino & Gambling, Aerospace and Defense, Food Service, Religion, Agriculture, Real Estate, Aviation, Insurance
- Targeted regions
- Worldwide, including the United States, United Kingdom, Spain, France, Italy, India, Brazil, China and Japan across more than 50 countries
- TTPs
TA0042Resource Development,TA0001Initial Access,TA0009Collection,TA0010Exfiltration,TA0040Impact,T1583Acquire Infrastructure,T1583.001Domains,T1583.006Web Services,T1585Establish Accounts,T1585.001Social Media Accounts,T1587Develop Capabilities,T1587.001Malware,T1078Valid Accounts,T1566Phishing,T1005Data from Local System,T1213Data from Information Repositories,T1114Email Collection,T1567Exfiltration Over Web Service,T1567.002Exfiltration to Cloud Storage,T1486Data Encrypted for Impact,T1657Financial Theft
Recommendations
- 01Security TeamsUse this digest to prioritize the eight exploited vulnerabilities and block the indicators related to the threat actors Kimsuky and Stormous and to the malware AppleSeed (KGH_SPY), HappyDoor, HelloDoor, httpMalice, httpTroy, MemLoad, HTTPSpy, AsyncRAT, StormousX, and XMRig.
- 02Uni5 Users: Scan for ExposureRun a Scan in the HivePro Uni5 dashboard to discover the assets impacted by the eight exploited vulnerabilities.
- 03Uni5 Users: Validate ControlsTest the efficacy of security controls by simulating the attacks related to the threat actor Kimsuky and the malware StormousX in Breach and Attack Simulation (BAS).
Top MITRE ATT&CK TTPs
Indicators of Compromise (IoCs)
| Type | Value |
|---|---|
| AppleSeed SHA256 | 0845f218a588f7619169787c4db69ce9de0c84143b100400b6476d7289a1c493 2c796053053a571e9f913fd5bae3bb45e27a9f510eace944af4b331e802a4ba0 8c35eed98b295d2fc13cb7280e17dcbf232f6703ee74052a479196786ea9f333 |
| HappyDoor SHA256 | 4ac02dc231f2546ce64335729145db672b5ab01d8943df8a550cc77fc436df14 |
| HappyDoor Domains | cms[.]spaceyou[.]o-r[.]kr erp[.]spaceme[.]p-e[.]kr |
| HelloDoor SHA256 | db284cc9b6536ab6f956a45ce9e5905716c7547f5e8dc572dc07aa125d27819e 62aac86f38f26700cf534c0a316d31882ffb74488bd1d87a3caeef604fc3a124 |
| HelloDoor FileName | [별지 제8호서식] 개인정보(열람 정정삭제 처리정지) 요구서(개인정보 보호법 시행규칙).hwp.jse |
| httpMalice SHA256 | 23420100260cc80055fbf02f4464212278c0e71a4387537771f3fb50f2f891e5 |
| httpMalice URL | hxxps[:]//www[.]pyrotech[.]co[.]kr/common/include/tech/default[.]php hxxp[:]//newjo-imd[.]com/common/include/library/default[.]php |
| httpMalice MD5 | 08160acf08fccecde7b34090db18b321 94faed9af49c98a89c8acc55e97276c9 |
| httpTroy MD5 | 7e0825019d0de0c1c4a1673f94043ddb |
| httpTroy Domains | file[.]bigcloud[.]n-e[.]kr load[.]auraria[.]org |
| MemLoad MD5 | 58ac2f65e335922be3f60e57099dc8a3 f73ba062116ea9f37d072aa41c7f5108 |
| MemLoad SHA256 | 2d597c3a726970927b302bf015cec4e37cdc974959cb846dbcb23cdb46386a6c |
| MemLoad Domains | load[.]ssangyongcne[.]o-r[.]kr load[.]yju[.]o-r[.]kr attach[.]docucloud[.]o-r[.]kr load[.]supershop[.]o-r[.]kr load[.]erasecloud[.]n-e[.]kr |
| HTTPSpy URLs | hxxps[:]//bigfile[.]jaycloudlab[.]com/download[.]php?id=745896 hxxps[:]//download[.]birdriver[.]org/download[.]php?id=393156 |
| HTTPSpy MD5 | a581fdea0970f8a5b6cfec4853c802d7 |
| AsyncRAT SHA256 | 601d9deea6467a57e42c355d481331cd78d6487bd160a081332420c69f214455 daac2fe0fe9a71f531d9b35c9ca269c0bdfbd1bbac5e8d73fc91afcff20ef524 7bb7c893fdf7f7ccd998610969d23993c50fc0b693e67930b6f98d8dbd003ee3 |
| StormousX TOR Address | 3slz4povugieoi3tw7sblxoowxhbzxeju427cffsst5fo2tizepwatid[.]onion h3reihqb2y7woqdary2g3bmk3apgtxuyhx4j2ftovbhe3l5svev7bdyd[.]onion pdcizqzjitsgfcgqeyhuee5u6uki6zy5slzioinlhx6xjnsw25irdgqd[.]onion 6sf5xa7eso3e3vk46i5tpcqhnlayczztj7zjktzaztlotyy75zs6j7qd[.]onion zib7duoiglvzvnpjs5faly6bio4xhwiby2lupsnxrkjnx46gmwdfyrid[.]onion ahb6hjhe4nomgfwxequu52hazigh4ty4gdcnrf3r7z5tiyhour5py2id[.]onion stniiomyjliimcgkvdszvgen3eaaoz55hreqqx6o77yvmpwt7gklffqd[.]onion 5pbckbo5ra36srfwmb2y6mqpqj7akx3e6ewanujszv7nnjndbbgsjsad[.]onion |
| XMRig Filename | SearchIndex.exe |
Threat Advisories
- GitLab Path Traversal (CVE-2026-85706) Exploited to Steal Secrets
- Root Delivered by Email: Cisco Secure Email Gateway Zero-Day
- Kimsuky Blends AI-Generated Lures and Quishing into an Expanded Espionage Arsenal
- Acronis Backup Plugin Flaw Exploited in the Wild
- Stormous Extortion Group Announces Shutdown After Four Years of Leak-Site Activity
- CVE-2026-84869: Critical ScreenConnect Client Flaw Under Active Exploitation
- Cisco ISE Authentication Bypass Zero-Day Under Active Exploitation
- JFrog Artifactory Flaws Chained for Administrative Takeover
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
