Weekly Threat Digest: 24 to 30 AUGUST 2026

Weekly Threat Digest
Download Now
Weekly Threat Digest — 24 to 30 August 2026 | HiveForce Labs

Summary

HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, eight major attacks were detected, six vulnerabilities were actively exploited, and one threat actor group was closely monitored, signaling a concerning escalation in malicious activity worldwide.

Among the most significant developments, PaperCut has confirmed active zero-day exploitation of two chained flaws affecting all versions of PaperCut NG and MF. CVE-2026-81578 (Authentication Bypass, CVSS 8.8) lets an unauthenticated attacker alter configuration, and CVE-2026-82078 (Unsafe Dynamic Class Loading, CVSS 9.4) turns that access into arbitrary code execution, yielding unauthenticated remote code execution against internet-exposed Application Servers. In parallel, CVE-2026-21962, a maximum-severity (CVSS 10.0) improper access-control flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, remains under active exploitation. Attackers were also confirmed exploiting CVE-2026-60004 in self-hosted Gitea servers to drop a cryptocurrency-miner-like payload, aided by Gitea’s default open registration.

Elsewhere, Dark Caracal, a cyberespionage group linked to Lebanon’s General Directorate of General Security, was observed deploying a previously undocumented Go framework tracked as GoCaracal alongside an updated Bandook variant against a Venezuelan communications organization. A separate China-nexus campaign, Operation QUICSILVER, targeted Myanmar government and diplomatic personnel with the custom QUICAgent backdoor, tunnelling encrypted traffic over QUIC to evade conventional inspection. A Cambodia-focused cluster rounded out the espionage activity, chaining DLL sideloading and a Bring Your Own Vulnerable Driver routine (CVE-2026-36425) to disable endpoint defences in kernel mode before deploying SparkRAT.


Insights

01

SynkLoader spreads via fake Microsoft Teams help-desk messages, using a pixel-perfect fake lock screen to steal users’ real passwords.

02

CVE-2026-60004 is being exploited to hijack self-hosted Gitea servers and drop cryptocurrency miners, aided by default open registration.

03

Operation QUICSILVER, a China-nexus campaign, hit Myanmar’s government with the QUICAgent backdoor, tunnelling over QUIC to evade inspection.

04

CVE-2026-82078 is an actively exploited PaperCut NG/MF zero-day, chaining with an auth-bypass flaw to give unauthenticated attackers remote code execution on all versions.

05

Dark Caracal, tied to Lebanese intelligence, deployed a new Go framework, GoCaracal, alongside Bandook against targets across Latin America.

06

CVE-2026-21962, a maximum-severity (CVSS 10.0) Oracle WebLogic Proxy flaw, is under active exploitation.


Targeted Countries & Industries

Most-targeted countries this week span Myanmar, Uruguay, Philippines, Vietnam, Brunei, Thailand, Cambodia, Venezuela, Chile, Brazil, Malaysia, Colombia, Singapore, Ecuador, Timor-Leste, El Salvador, Indonesia, Laos, South Africa, Netherlands, Maldives, Bhutan, Portugal, and Bolivia, with a long tail of least-targeted countries across Europe, Africa, and the Middle East. Targeted industries recorded activity across Business Process Outsourcing, Logistics, Think Tanks, Education, Energy, Automotive, Maritime, Nonprofit, Fashion, Online, Government, Hospitality, Retail, Banking, eCommerce, Political Parties, Legal, Insurance, Real Estate, Consumer, Entertainment, Religion, Technology, Construction, Financial, Computer Gaming, Agriculture, and Food and Beverage.


Top MITRE ATT&CK TTPs

T1059
Command and Scripting Interpreter
T1204
User Execution
T1027
Obfuscated Files or Information
T1190
Exploit Public-Facing Application
T1071
Application Layer Protocol
T1082
System Information Discovery
T1204.002
Malicious File
T1566
Phishing
T1071.001
Web Protocols
T1588
Obtain Capabilities
T1070
Indicator Removal
T1140
Deobfuscate/Decode Files or Information
T1083
File and Directory Discovery
T1588.006
Vulnerabilities
T1573.001
Symmetric Cryptography
T1518
Software Discovery
T1053
Scheduled Task/Job
T1573
Encrypted Channel
T1547
Boot or Logon Autostart Execution
T1057
Process Discovery

Attacks Executed

C2Looper

Type: Backdoor   Delivery Method: ClickFix chain   Targeted CVE: -   Affected Platform: Windows   Associated Actor: -

Impact: Foothold, recon, payload delivery

IOC (SHA256): f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b

SynkLoader

Type: Loader   Delivery Method: Phishing   Targeted CVE: -   Affected Platform: Windows   Associated Actor: -

Impact: Data theft

IOC (SHA256): d150c70d2732df17aa77991b9ebf4c896f044445e900978581d9598dfa5dc98c

QUICAgent

Type: Backdoor   Delivery Method: -   Targeted CVE: -   Affected Platform: Windows   Associated Actor: China-nexus

Impact: Remote exec, espionage

IOC (SHA256): cd147efe37003399e174951927e5fe727a4481756b116f0204a14a64cc62b059

WeedHack

Type: MaaS   Delivery Method: -   Targeted CVE: -   Affected Platform: Windows   Associated Actor: -

Impact: remote-access

IOC (SHA256): 3951533d56803cd5d708014b4eed7e30349b4c4ba43f7d843133b3a5e2992ce6

GoCaracal

Type: RAT   Delivery Method: Phishing   Targeted CVE: -   Affected Platform: Windows   Associated Actor: Dark Caracal

Impact: Data theft, keylogging, RDP, SOCKS5

IOC (SHA256): 1E499C815146124C4A6D2B48C99068B980AD74E1A2CFD16013F8D75A9425A0CA, 77F7AD29F4A8037EE5F38D3D87FB91CFD97CB8F7FA7883EDF3FCE506DF5200C0

Bandook

Type: RAT   Delivery Method: Phishing   Targeted CVE: -   Affected Platform: Windows   Associated Actor: Dark Caracal

Impact: File theft, credential theft, keylogging

IOC (SHA256): a2cdf2fe741de4b13ad2298b387a6c32da4a94da180ae75bf8547386aee7376b

Delphi loader

Type: Loader   Delivery Method: -   Targeted CVE: -   Affected Platform: Windows   Associated Actor: Dark Caracal

Impact: Payload delivery

IOC (SHA256): 0A6DA70548F14834ACB8960689A589B48FF422F8385AE445A281AAB77045FE22

SparkRAT

Type: RAT   Delivery Method: Phishing   Targeted CVE: CVE-2026-36425   Affected Platform: Windows   Associated Actor: -

Impact: System Compromise

IOC (SHA256): c1a8556741564c3698b56419f66cc27ad50be9148ef483f92866d4edabc46624, f949d967355578cb6a34a678b6e8683b21e58e2ea6b6d5e0cdd4f59af2e37f19


Vulnerabilities Exploited

CVE IDNameAffected ProductCWEAssociated TTPsPatch Link
CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access ControlOracle HTTP Server, Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server (12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0); WebLogic Server Proxy Plug-in for Microsoft IIS (12.2.1.4.0)CWE-284T1190, T1059https://www.oracle.com/security-alerts/cpujan2026.html
CVE-2026-60004Gitea Code InjectionGitea (1.17 through 1.27.0, before 1.27.1)CWE-94T1190, T1059https://blog.gitea.com/release-of-1.27.1/
CVE-2026-75604Vercel Next.js Windows-Hosted Remote Code ExecutionVercel Next.js (>= 13.4 and < 15.5.24; >= 16.0 and < 16.3.3) on Windows filesystem hostsCWE-22T1190, T1059https://nextjs.org/blog/august-2026-security-release
CVE-2026-36425OPSWAT AppRemover Arbitrary Process TerminationOPSWAT AppRemover (ardrv.sys)CWE-269T1068https://www.opswat.com/products/oesis-framework/application-removal
CVE-2026-82078PaperCut NG and PaperCut MF Unsafe Dynamic Class LoadingAll versions of PaperCut NG and PaperCut MFCWE-470T1190, T1059, T1070https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
CVE-2026-81578PaperCut NG and PaperCut MF Authentication BypassAll versions of PaperCut NG and PaperCut MFCWE-306T1190, T1562https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/

Adversaries in Action

Dark Caracal (aka ATK 27, TAG-CT3)

Origin: Lebanon   Motive: Espionage and Information Theft   Affected Product: Windows

Targeted Industries: Communications, Government, Military, Businesses, Journalists, Activists, Legal, Healthcare, Education

Targeted Regions: Venezuela, Brazil, Ecuador, Chile, Colombia, El Salvador, Uruguay

Associated Attacks/Malware: GoCaracal, Bandook, Delphi loader


Recommendations

Security Teams: This digest can be utilized as a drive to force security teams to prioritize the six exploited vulnerabilities and block the indicators related to the threat actor Dark Caracal, and malware C2Looper, SynkLoader, QUICAgent, WeedHack, GoCaracal, Bandook, Delphi loader, and SparkRAT.

Uni5 Users: This is an actionable threat digest for HivePro Uni5 customers, who can get comprehensive insights into their threat exposure and action it effortlessly over the HivePro Uni5 dashboard by running a scan to discover assets impacted by the six exploited vulnerabilities, and testing the efficacy of their security controls by simulating the attacks related to Dark Caracal and the associated malware families in Breach and Attack Simulation (BAS).


Threat Advisories Referenced

  • August 2026 Linux Patch Roundup
  • C2Looper Builds Footholds for Ransomware
  • SynkLoader: When a Teams Message Fakes Your Lock Screen
  • CVE-2026-21962: Critical Oracle WebLogic Proxy Plug-in Flaw Exploited in the Wild
  • Operation QUICSILVER Drops a Go Backdoor on Myanmar Government
  • WeedHack Resurfaces via Fake Minecraft Clients and SEO Poisoning
  • Gitea RCE (CVE-2026-60004) Exploited to Hijack Servers for Crypto Mining
  • Dark Caracal Modernizes Its Espionage Toolkit
  • Critical Next.js Flaws Enable Unauthenticated Remote Code Execution
  • SparkRAT Ignites Cambodia via BYOVD Chain
  • PaperCut NG/MF Zero-Day Under Active Exploitation Across All Versions

Indicators of Compromise (IoCs)

Attack NameTypeValue
C2LooperSHA256f96ff2f3abbff7f382ace509b90e54853b4b61c402ecde27d82f1c17b414867b
SynkLoaderSHA256d150c70d2732df17aa77991b9ebf4c896f044445e900978581d9598dfa5dc98c
QUICAgentSHA256cd147efe37003399e174951927e5fe727a4481756b116f0204a14a64cc62b059
WeedHackSHA2563951533d56803cd5d708014b4eed7e30349b4c4ba43f7d843133b3a5e2992ce6
GoCaracalIPv4109[.]120[.]187[.]217, 109[.]172[.]95[.]121, 138[.]124[.]112[.]213, 138[.]124[.]14[.]130, 176[.]124[.]220[.]153, 185[.]125[.]101[.]181, 185[.]96[.]80[.]110, 185[.]96[.]80[.]54, 193[.]233[.]245[.]52, 193[.]233[.]245[.]45, 193[.]233[.]245[.]0, 62[.]60[.]237[.]22, 77[.]110[.]104[.]98, 77[.]110[.]105[.]244, 77[.]110[.]105[.]56, 77[.]110[.]105[.]59, 77[.]110[.]98[.]66, 80[.]71[.]224[.]30, 82[.]117[.]87[.]138, 82[.]117[.]87[.]192, 85[.]192[.]30[.]211, 79[.]137[.]192[.]38, 46[.]226[.]162[.]68, 45[.]152[.]198[.]108
GoCaracalSHA2561E499C815146124C4A6D2B48C99068B980AD74E1A2CFD16013F8D75A9425A0CA, 77F7AD29F4A8037EE5F38D3D87FB91CFD97CB8F7FA7883EDF3FCE506DF5200C0
BandookIPv491[.]208[.]197[.]80, 91[.]208[.]184[.]45, 91[.]208[.]206[.]88, 91[.]208[.]184[.]130, 176[.]123[.]1[.]174
BandookSHA256a2cdf2fe741de4b13ad2298b387a6c32da4a94da180ae75bf8547386aee7376b
Delphi loaderSHA2560A6DA70548F14834ACB8960689A589B48FF422F8385AE445A281AAB77045FE22
SparkRATSHA256c1a8556741564c3698b56419f66cc27ad50be9148ef483f92866d4edabc46624, f949d967355578cb6a34a678b6e8683b21e58e2ea6b6d5e0cdd4f59af2e37f19, d56c6513a8b25b1883ef33a95d4ece591eabbe17a58f7e3d0fc77c6f29344148, a2c1b858c1d4788e87bb699e3775e851cda95488979b15f4d676f6e1915d8bc8

A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.