Summary
HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, eight major attacks were detected, six vulnerabilities were actively exploited, and one threat actor group was closely monitored, signaling a concerning escalation in malicious activity worldwide.
Among the most significant developments, PaperCut has confirmed active zero-day exploitation of two chained flaws affecting all versions of PaperCut NG and MF. CVE-2026-81578 (Authentication Bypass, CVSS 8.8) lets an unauthenticated attacker alter configuration, and CVE-2026-82078 (Unsafe Dynamic Class Loading, CVSS 9.4) turns that access into arbitrary code execution, yielding unauthenticated remote code execution against internet-exposed Application Servers. In parallel, CVE-2026-21962, a maximum-severity (CVSS 10.0) improper access-control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, remains under active exploitation. Attackers were also confirmed exploiting CVE-2026-60004 in self-hosted Gitea servers to drop a cryptocurrency-miner-like payload, aided by Gitea’s default open registration.
Elsewhere, Dark Caracal, a cyberespionage group linked to Lebanon’s General Directorate of General Security, was observed deploying a previously undocumented Go framework tracked as GoCaracal alongside an updated Bandook variant against a Venezuelan communications organization. A separate China-nexus campaign, Operation QUICSILVER, targeted Myanmar government and diplomatic personnel with the custom QUICAgent backdoor, tunnelling encrypted traffic over QUIC to evade conventional inspection. A Cambodia-focused cluster rounded out the espionage activity, chaining DLL sideloading and a Bring Your Own Vulnerable Driver routine (CVE-2026-36425) to disable endpoint defences in kernel mode before deploying SparkRAT.
Insights
SynkLoader spreads via fake Microsoft Teams help-desk messages, using a pixel-perfect fake lock screen to steal users’ real passwords.
CVE-2026-60004 is being exploited to hijack self-hosted Gitea servers and drop cryptocurrency miners, aided by default open registration.
Operation QUICSILVER, a China-nexus campaign, hit Myanmar’s government with the QUICAgent backdoor, tunnelling over QUIC to evade inspection.
CVE-2026-82078 is an actively exploited PaperCut NG/MF zero-day, chaining with an auth-bypass flaw to give unauthenticated attackers remote code execution on all versions.
Dark Caracal, tied to Lebanese intelligence, deployed a new Go framework, GoCaracal, alongside Bandook against targets across Latin America.
CVE-2026-21962, a maximum-severity (CVSS 10.0) Oracle WebLogic Proxy flaw, is under active exploitation.
Targeted Countries & Industries
Most-targeted countries this week span Myanmar, Uruguay, Philippines, Vietnam, Brunei, Thailand, Cambodia, Venezuela, Chile, Brazil, Malaysia, Colombia, Singapore, Ecuador, Timor-Leste, El Salvador, Indonesia, Laos, South Africa, Netherlands, Maldives, Bhutan, Portugal, and Bolivia, with a long tail of least-targeted countries across Europe, Africa, and the Middle East. Targeted industries recorded activity across Business Process Outsourcing, Logistics, Think Tanks, Education, Energy, Automotive, Maritime, Nonprofit, Fashion, Online, Government, Hospitality, Retail, Banking, eCommerce, Political Parties, Legal, Insurance, Real Estate, Consumer, Entertainment, Religion, Technology, Construction, Financial, Computer Gaming, Agriculture, and Food and Beverage.
Top MITRE ATT&CK TTPs
Attacks Executed
C2Looper
Type: Backdoor Delivery Method: ClickFix chain Targeted CVE: - Affected Platform: Windows Associated Actor: -
Impact: Foothold, recon, payload delivery
IOC (SHA256): f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b
SynkLoader
Type: Loader Delivery Method: Phishing Targeted CVE: - Affected Platform: Windows Associated Actor: -
Impact: Data theft
IOC (SHA256): d150c70d2732df17aa77991b9ebf4c896f044445e900978581d9598dfa5dc98c
QUICAgent
Type: Backdoor Delivery Method: - Targeted CVE: - Affected Platform: Windows Associated Actor: China-nexus
Impact: Remote exec, espionage
IOC (SHA256): cd147efe37003399e174951927e5fe727a4481756b116f0204a14a64cc62b059
WeedHack
Type: MaaS Delivery Method: - Targeted CVE: - Affected Platform: Windows Associated Actor: -
Impact: remote-access
IOC (SHA256): 3951533d56803cd5d708014b4eed7e30349b4c4ba43f7d843133b3a5e2992ce6
GoCaracal
Type: RAT Delivery Method: Phishing Targeted CVE: - Affected Platform: Windows Associated Actor: Dark Caracal
Impact: Data theft, keylogging, RDP, SOCKS5
IOC (SHA256): 1E499C815146124C4A6D2B48C99068B980AD74E1A2CFD16013F8D75A9425A0CA, 77F7AD29F4A8037EE5F38D3D87FB91CFD97CB8F7FA7883EDF3FCE506DF5200C0
Bandook
Type: RAT Delivery Method: Phishing Targeted CVE: - Affected Platform: Windows Associated Actor: Dark Caracal
Impact: File theft, credential theft, keylogging
IOC (SHA256): a2cdf2fe741de4b13ad2298b387a6c32da4a94da180ae75bf8547386aee7376b
Delphi loader
Type: Loader Delivery Method: - Targeted CVE: - Affected Platform: Windows Associated Actor: Dark Caracal
Impact: Payload delivery
IOC (SHA256): 0A6DA70548F14834ACB8960689A589B48FF422F8385AE445A281AAB77045FE22
SparkRAT
Type: RAT Delivery Method: Phishing Targeted CVE: CVE-2026-36425 Affected Platform: Windows Associated Actor: -
Impact: System Compromise
IOC (SHA256): c1a8556741564c3698b56419f66cc27ad50be9148ef483f92866d4edabc46624, f949d967355578cb6a34a678b6e8683b21e58e2ea6b6d5e0cdd4f59af2e37f19
Vulnerabilities Exploited
| CVE ID | Name | Affected Product | CWE | Associated TTPs | Patch Link |
|---|---|---|---|---|---|
CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control | Oracle HTTP Server, Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); WebLogic Server Proxy Plug-in for Microsoft IIS (12.2.1.4.0) | CWE-284 | T1190, T1059 | https://www.oracle.com/security-alerts/cpujan2026.html |
CVE-2026-60004 | Gitea Code Injection | Gitea (1.17 through 1.27.0, before 1.27.1) | CWE-94 | T1190, T1059 | https://blog.gitea.com/release-of-1.27.1/ |
CVE-2026-75604 | Vercel Next.js Windows-Hosted Remote Code Execution | Vercel Next.js (>= 13.4 and < 15.5.24; >= 16.0 and < 16.3.3) on Windows filesystem hosts | CWE-22 | T1190, T1059 | https://nextjs.org/blog/august-2026-security-release |
CVE-2026-36425 | OPSWAT AppRemover Arbitrary Process Termination | OPSWAT AppRemover (ardrv.sys) | CWE-269 | T1068 | https://www.opswat.com/products/oesis-framework/application-removal |
CVE-2026-82078 | PaperCut NG and PaperCut MF Unsafe Dynamic Class Loading | All versions of PaperCut NG and PaperCut MF | CWE-470 | T1190, T1059, T1070 | https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ |
CVE-2026-81578 | PaperCut NG and PaperCut MF Authentication Bypass | All versions of PaperCut NG and PaperCut MF | CWE-306 | T1190, T1562 | https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/ |
Adversaries in Action
Dark Caracal (aka ATK 27, TAG-CT3)
Origin: Lebanon Motive: Espionage and Information Theft Affected Product: Windows
Targeted Industries: Communications, Government, Military, Businesses, Journalists, Activists, Legal, Healthcare, Education
Targeted Regions: Venezuela, Brazil, Ecuador, Chile, Colombia, El Salvador, Uruguay
Associated Attacks/Malware: GoCaracal, Bandook, Delphi loader
Recommendations
Security Teams: This digest can be utilized as a drive to force security teams to prioritize the six exploited vulnerabilities and block the indicators related to the threat actor Dark Caracal, and malware C2Looper, SynkLoader, QUICAgent, WeedHack, GoCaracal, Bandook, Delphi loader, and SparkRAT.
Uni5 Users: This is an actionable threat digest for HivePro Uni5 customers, who can get comprehensive insights into their threat exposure and action it effortlessly over the HivePro Uni5 dashboard by running a scan to discover assets impacted by the six exploited vulnerabilities, and testing the efficacy of their security controls by simulating the attacks related to Dark Caracal and the associated malware families in Breach and Attack Simulation (BAS).
Threat Advisories Referenced
- August 2026 Linux Patch Roundup
- C2Looper Builds Footholds for Ransomware
- SynkLoader: When a Teams Message Fakes Your Lock Screen
- CVE-2026-21962: Critical Oracle WebLogic Proxy Plug-in Flaw Exploited in the Wild
- Operation QUICSILVER Drops a Go Backdoor on Myanmar Government
- WeedHack Resurfaces via Fake Minecraft Clients and SEO Poisoning
- Gitea RCE (CVE-2026-60004) Exploited to Hijack Servers for Crypto Mining
- Dark Caracal Modernizes Its Espionage Toolkit
- Critical Next.js Flaws Enable Unauthenticated Remote Code Execution
- SparkRAT Ignites Cambodia via BYOVD Chain
- PaperCut NG/MF Zero-Day Under Active Exploitation Across All Versions
Indicators of Compromise (IoCs)
| Attack Name | Type | Value |
|---|---|---|
| C2Looper | SHA256 | f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b |
| SynkLoader | SHA256 | d150c70d2732df17aa77991b9ebf4c896f044445e900978581d9598dfa5dc98c |
| QUICAgent | SHA256 | cd147efe37003399e174951927e5fe727a4481756b116f0204a14a64cc62b059 |
| WeedHack | SHA256 | 3951533d56803cd5d708014b4eed7e30349b4c4ba43f7d843133b3a5e2992ce6 |
| GoCaracal | IPv4 | 109[.]120[.]187[.]217, 109[.]172[.]95[.]121, 138[.]124[.]112[.]213, 138[.]124[.]14[.]130, 176[.]124[.]220[.]153, 185[.]125[.]101[.]181, 185[.]96[.]80[.]110, 185[.]96[.]80[.]54, 193[.]233[.]245[.]52, 193[.]233[.]245[.]45, 193[.]233[.]245[.]0, 62[.]60[.]237[.]22, 77[.]110[.]104[.]98, 77[.]110[.]105[.]244, 77[.]110[.]105[.]56, 77[.]110[.]105[.]59, 77[.]110[.]98[.]66, 80[.]71[.]224[.]30, 82[.]117[.]87[.]138, 82[.]117[.]87[.]192, 85[.]192[.]30[.]211, 79[.]137[.]192[.]38, 46[.]226[.]162[.]68, 45[.]152[.]198[.]108 |
| GoCaracal | SHA256 | 1E499C815146124C4A6D2B48C99068B980AD74E1A2CFD16013F8D75A9425A0CA, 77F7AD29F4A8037EE5F38D3D87FB91CFD97CB8F7FA7883EDF3FCE506DF5200C0 |
| Bandook | IPv4 | 91[.]208[.]197[.]80, 91[.]208[.]184[.]45, 91[.]208[.]206[.]88, 91[.]208[.]184[.]130, 176[.]123[.]1[.]174 |
| Bandook | SHA256 | a2cdf2fe741de4b13ad2298b387a6c32da4a94da180ae75bf8547386aee7376b |
| Delphi loader | SHA256 | 0A6DA70548F14834ACB8960689A589B48FF422F8385AE445A281AAB77045FE22 |
| SparkRAT | SHA256 | c1a8556741564c3698b56419f66cc27ad50be9148ef483f92866d4edabc46624, f949d967355578cb6a34a678b6e8683b21e58e2ea6b6d5e0cdd4f59af2e37f19, d56c6513a8b25b1883ef33a95d4ece591eabbe17a58f7e3d0fc77c6f29344148, a2c1b858c1d4788e87bb699e3775e851cda95488979b15f4d676f6e1915d8bc8 |
A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
