Publication

HiveForce Labs · Weekly Threat Digest
Covering 06 to 12 July 2026, this HiveForce Labs weekly threat digest is led by the agentic JADEPUFFER ransomware and Adobe ColdFusion's CVE-2026-48282 path traversal flaw (see badges and panel below for the full figures).
Publication
Coverage Window
Attacks Executed
Vulns Exploited
Adversaries
Vulns This Week
Total Published
Lead Actor
Source
Section 01
HiveForce Labs has reported a sharp rise in cybersecurity threats this week, tracking thirteen major attacks, eleven actively exploited vulnerabilities, and five threat actor groups amid escalating malicious activity worldwide.
Adobe ColdFusion has a critical path traversal flaw, CVE-2026-48282: on servers with file uploads enabled, an unauthenticated attacker can smuggle a malicious file onto the system and execute arbitrary code with the highest privileges. UNK_MassTraction, a suspected China-aligned espionage cluster, weaponizes two known-but-unpatched Roundcube vulnerabilities to drop its espionage toolset (Sections 06 and 08).
Elsewhere, JADEPUFFER surfaced as a fully agentic ransomware operation; UAT-7810 expanded its Ruckus-wireless-router malware family; and Cavern Manticore, a newly identified Iran-linked group tied to Iran's Ministry of Intelligence and Security (MOIS), began targeting Israeli IT, government and defense organizations amid the ongoing U.S.-Israel military operation against Iran (Sections 06 and 08). Together, these incidents reflect a growing trend of hybrid operations blending technical exploitation with social engineering — reinforcing the need for timely patching, monitoring, and layered defenses.
Section 02
Thirteen attacks, eleven exploited vulnerabilities and five adversaries in action from the 06–12 July 2026 window, for quick reference.
JADEPUFFER, VShell, IceCube, SquareShell, SNOWLIGHT, SHORTLEASH, LONGLEASH, DOGLEASH, LEASHTEST, JARLEASH, Qilin, AsyncRAT, Cavern
CVE-2025-3248, CVE-2021-29441, CVE-2026-46242, CVE-2026-48282, CVE-2024-42009, CVE-2025-49113, CVE-2020-22653, CVE-2020-22658, CVE-2023-25717, CVE-2023-3519, CVE-2026-50656
UNK_MassTraction, UAT-7810, APT41, Cavern Manticore, Coinbase Cartel
Section 03
Six storylines stand out this week, spanning autonomous ransomware, kernel-level privilege escalation, and nation-state espionage.
JADEPUFFER is an agentic ransomware operation run end-to-end by a large language model — the first observed case of a fully autonomous attack chain (full profile in Section 06).
A use-after-free in the Linux kernel's eventpoll subsystem enables local privilege escalation across a wide band of stable kernel releases, patched in 6.18.33, 7.0.10 and 7.1.
This suspected China-aligned cluster weaponizes two known-but-unpatched Roundcube flaws to deliver its espionage toolset (Sections 06, 08).
Coinbase Cartel (aka shinysp1d3r) runs a financially motivated, encryption-free data-extortion operation (Section 08).
A race-condition privilege-escalation flaw in the Microsoft Defender Malware Protection Engine (before 1.1.26060.3008) opens a direct path to SYSTEM-level access.
UAT-7810 continues to expand its Ruckus-router malware family, building an operational relay box (ORB) network from compromised devices (Sections 06, 08).
This week's thirteen attacks span the following threat categories: Backdoor, Ransomware, Stealer, RAT, Loader, Linux binary, Webshell, and Modular Framework.
Section 04
Countries targeted this week, most to least, are listed below.
United States, Canada, Argentina, Switzerland, Norway, Brazil, Japan, Bulgaria, Malta, Poland, Belgium, South Africa, Spain, China, Thailand, Colombia, United Arab Emirates, Croatia, Vietnam, Denmark, Mexico, France, Peru, Germany
Slovenia, Greece, South Korea, India, Sweden, Indonesia, Taiwan, Israel, Italy, United Kingdom, Portugal, Benin, Brunei, Cambodia, Niger, Cameroon, Scotland, Andorra, Uganda, Canada Quebec, Myanmar, Cape Verde, Pakistan, Cayman Islands, Saint Eustatius
Central African Republic, Bosnia and Herzegovina, Chad, Togo, Chile, Belize, Angola, Montenegro, Anguilla, Netherland Antilles, Comoros, Northern Cyprus, Congo-Brazzaville, Paraguay, Costa Rica, Romania, Cuba, Sierra Leone, Curacao, Sudan, Cyprus
Tanzania, Czech Republic, Tunisia, Maldives, Akrotiri and Dhekelia, Mauritania, Djibouti, Monaco, Dominica, Morocco, Dominican Republic, Nauru, Ecuador, New Zealand, Egypt, North Korea, El Salvador, Bermuda, Equatorial Guinea, Panama, Estonia
Section 05
The top TTPs observed this week span execution, command-and-control, defense evasion, discovery and exfiltration.
Execution
Command and Scripting Interpreter
Command and Control
Application Layer Protocol
Initial Access
Exploit Public-Facing Application
Defense Evasion
Indicator Removal
Exfiltration
Exfiltration Over C2 Channel
Lateral Movement
Remote Services
Defense Evasion
Deobfuscate/Decode Files or Information
Command and Control
Web Protocols
Command and Control
Encrypted Channel
Command and Control
Ingress Tool Transfer
Impact
Data Encrypted for Impact
Defense Evasion
Valid Accounts
Collection
Data from Information Repositories
Collection
Data from Local System
Discovery
System Information Discovery
Defense Evasion
Obfuscated Files or Information
Command and Control
Proxy
Resource Development
Obtain Capabilities
Defense Evasion
Impair Defenses
Defense Evasion
Masquerading
Section 06
Thirteen attacks were executed this window (Section 02 has the full list) via internet-facing exploits, phishing, social engineering and supply-chain compromise; IOCs are in the Appendix.
JADEPUFFER is an agentic ransomware operation run end-to-end by a large language model via an internet-facing Langflow instance, classified as an agentic threat actor (ATA) — an attacker whose capability comes from an AI agent, not a human toolkit. Its payloads self-narrate their reasoning, target prioritization and annotations human operators rarely write. Delivered via CVE-2025-3248 and CVE-2021-29441; also targets MySQL and MinIO; enables data encryption, exfiltration and financial loss.
VShell, IceCube, SquareShell and SNOWLIGHT are all delivered via CVE-2024-42009 and CVE-2025-49113 against Roundcube Webmail (UNK_MassTraction).
VShell is a cross-platform, fileless Go backdoor favored by China-aligned attackers and hard to detect. It gives an interactive reverse shell, port-forwarding, and file theft across Linux, Windows and macOS — shell and port-forwarding being most used to burrow deeper into networks.
IceCube is a JavaScript credential stealer used for targeted cyber-espionage, injected via XSS flaws in webmail platforms like Roundcube. Once running in the browser it harvests login credentials, session cookies, and 2FA tokens.
SquareShell is a webshell offering remote code execution on the server. It hides by copying a legitimate plugin's last-modified timestamp to blend in, and runs commands through several system utilities.
A lightweight Linux loader that stages and deploys additional payloads, commonly executing follow-on implants such as VShell and persisting via system services or cron jobs.
SHORTLEASH, LONGLEASH, DOGLEASH, LEASHTEST and JARLEASH are all delivered via CVE-2020-22653, CVE-2020-22658 and CVE-2023-25717 against Ruckus wireless routers (UAT-7810).
SHORTLEASH is a backdoor that calls home to its C2 server, stands up its own web server, manages tunnels, and acts as both C2 server and client. LONGLEASH builds on it with extra capabilities, a sign UAT-7810 is actively developing the tool.
LONGLEASH is a newer build of SHORTLEASH on the same codebase — both share the internal name "ff-agent." Its MIPS build uses the asynchronous Boost.Asio library to cut blocking and boost throughput, and can act as an intermediate C2 server, relaying commands and data between the original C2 and its peers.
DOGLEASH is a backdoor that runs arbitrary shellcode on a compromised Linux device. It binds and listens on a hardcoded local port, decodes incoming TCP data with a hardcoded password, and spins up a new thread to execute the incoming command code and data.
LEASHTEST is a Linux (ELF) binary that tests basic functionality on MIPS embedded devices — not malicious itself, but a strong sign of compromise if found. Internally named "iot-test," it checks it can create and join a thread, bind and listen on a port to open a TCP acceptor, spawn a child process, set an async timer, print "Hello World!", and test exception handling.
JARLEASH is a JAR-based backdoor UAT-7810 drops on both its own infrastructure and compromised Java-enabled systems for easy access. Its startup script kills any running instance, then spins up a fresh one in the Java container. It can also host a web file-management interface, FTP/SFTP servers, and a netcat server on a given IP and port.
Qilin is a prolific Ransomware-as-a-Service operation whose affiliates use double extortion — encrypting files and stealing data to threaten public release unless paid. Affiliates now also run a Linux ransomware variant on Windows hosts via legitimate remote-management tools like AnyDesk, ScreenConnect and Splashtop, evading Windows-focused defenses. Delivered via social engineering; enables system compromise, data encryption and financial loss. No CVE or actor recorded.
AsyncRAT is an open-source Windows RAT ranked 6th in global prevalence in 2024, capable of keylogging, screenshot capture, credential theft and ransomware deployment. Delivered via social engineering; enables information theft and financial loss. No CVE or actor recorded.
Cavern is a modular .NET C2 framework (agent plus modules) evolved from an earlier toolset internally named "Cav3rn." An older mhm.dll variant retains legacy Cav3rn artifacts: extensions .CvnC.png, .CvnA.png and .CvnR.png for command, API and result files, config filename Cvn.cfg, page name cac.aspx, and embedded JPEG header magic bytes. Delivered via supply chain compromise; targets Windows; associated with Cavern Manticore.
Section 07
Eleven vulnerabilities were exploited in the wild during the 06–12 July 2026 reporting window, all tracked as zero-day issues by HiveForce Labs. CVE-2026-48282 in Adobe ColdFusion and CVE-2026-46242 ("Bad Epoll") in the Linux kernel affect no currently recorded attack or ransomware in this digest but carry critical severity; the remaining nine chain into the JADEPUFFER, UNK_MassTraction and UAT-7810 attack families detailed in Section 06.
| CVE ID | Name | Affected Product | Affected CPE | CWE ID | Associated TTPs | Associated Actor | Associated Attack/Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2025-3248 ZERO-DAY |
Langflow Missing Authentication Vulnerability | Langflow versions prior to 1.3.0 |
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | CWE-94, CWE-306 |
T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter, T1552 Unsecured Credentials, T1552.001 Credentials In Files |
- | JADEPUFFER Ransomware |
| CVE-2021-29441 ZERO-DAY |
Nacos AuthFilter Authentication Bypass by Spoofing Vulnerability | Nacos before version 1.4.1 |
cpe:2.3:a:alibaba:nacos:*:*:*:*:*:*:*:* | CWE-290 |
T1190 Exploit Public-Facing Application, T1211 Exploitation for Defense Evasion |
- | JADEPUFFER Ransomware |
| CVE-2026-46242 ZERO-DAY |
Bad Epoll (Linux Kernel Use After Free Vulnerability) | Linux kernel v6.4 up to (excluding) 6.18.33; v6.19 up to (excluding) 7.0.10; stable 5.15.209 up to (excluding) 5.16; stable 6.1.175 up to (excluding) 6.2. Fixed in 6.18.33, 7.0.10, and 7.1. |
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | CWE-416 |
T1068 Exploitation for Privilege Escalation, T1588 Obtain Capabilities, T1588.006 Vulnerabilities |
- | - |
| CVE-2026-48282 ZERO-DAY |
Adobe ColdFusion Path Traversal Vulnerability | ColdFusion versions 2025.9, 2023.20 and earlier |
cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:* | CWE-22 |
T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter |
- | - |
| CVE-2024-42009 ZERO-DAY |
RoundCube Webmail Cross-Site Scripting Vulnerability | RoundCube version prior to 1.6.8 and 1.5.8 |
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | CWE-79 |
T1203 Exploitation for Client Execution |
UNK_MassTraction | VShell, IceCube, SquareShell, SNOWLIGHT |
| CVE-2025-49113 ZERO-DAY |
RoundCube Webmail Deserialization of Untrusted Data Vulnerability | Roundcube Webmail versions before 1.5.10 and 1.6.x before 1.6.11 |
cpe:2.3:a:roundcube:webmail:*:*:*:*:*:*:*:* | CWE-502 |
T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter |
UNK_MassTraction | VShell, IceCube, SquareShell, SNOWLIGHT |
| CVE-2020-22653 ZERO-DAY |
Ruckus Unauthorized Image Signature Injection Vulnerability | Ruckus Wireless Networking Devices | cpe:2.3:h:ruckuswireless:-:*:*:*:*:*:*:* cpe:2.3:o:ruckuswireless:-:*:*:*:*:*:*:* |
CWE-347 |
T1190 Exploit Public-Facing Application, T1553 Subvert Trust Controls, T1553.006 Code Signing Policy Modification, T1036 Masquerading |
UAT-7810 | SHORTLEASH, LONGLEASH, DOGLEASH, LEASHTEST, JARLEASH |
| CVE-2020-22658 ZERO-DAY |
Ruckus Unauthorized Image Boot Vulnerability | Ruckus Wireless Networking Devices | cpe:2.3:h:ruckuswireless:-:*:*:*:*:*:*:* cpe:2.3:o:ruckuswireless:-:*:*:*:*:*:*:* |
CWE-494 |
T1190 Exploit Public-Facing Application, T1553 Subvert Trust Controls, T1553.006 Code Signing Policy Modification, T1036 Masquerading |
UAT-7810 | SHORTLEASH, LONGLEASH, DOGLEASH, LEASHTEST, JARLEASH |
| CVE-2023-25717 ZERO-DAY |
Multiple Ruckus Wireless Products CSRF and RCE Vulnerability | Ruckus Wireless Admin | cpe:2.3:a:ruckuswireless:ruckus_wireless_admin:*:*:*:*:*:*:*:* | CWE-94 |
T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter, T1203 Exploitation for Client Execution |
UAT-7810 | SHORTLEASH, LONGLEASH, DOGLEASH, LEASHTEST, JARLEASH |
| CVE-2023-3519 ZERO-DAY |
Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability | NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.13; 13.0 before 13.0-91.13; version 12.1 (end of life); 13.1-FIPS before 13.1-37.159; 12.1-FIPS before 12.1-55.297; 12.1-NDcPP before 12.1-55.297 |
cpe:2.3:a:citrix:netscaler_application_delivery_controller:*:*:*:*:*:*:*:* | CWE-94 |
T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter |
- | - |
| CVE-2026-50656 ZERO-DAY |
RoguePlanet (Microsoft Defender Privilege Escalation Vulnerability) | Microsoft Defender – Malware Protection Engine (before 1.1.26060.3008) |
cpe:2.3:a:microsoft:malware_protection_engine:-:*:*:*:*:*:*:* | CWE-59 |
T1059 Command and Scripting Interpreter, T1068 Exploitation for Privilege Escalation |
- | - |
Section 08
Five threat actors were tracked this week (Section 02 has the full list; targeting, CVE and product detail is in the table below).
A suspected China-aligned cluster weaponizing unpatched Roundcube flaws to deliver a credential- and data-theft toolset.
A China-nexus operator building an ORB network from compromised Ruckus routers by chaining n-day flaws to deploy its own malware family.
A China-nexus actor motivated by financial crime, information theft and espionage. No CVE, attack, or affected product is recorded for APT41.
A newly identified Iran-linked group aligned with Iran's MOIS, motivated by espionage. Its 2026 campaign aligns closely with the ongoing U.S.-Israel military operation against Iran.
A financially motivated group running an encryption-free data-extortion operation spanning dozens of industries and more than thirty countries.
| Name | Origin | Motive | Targeted Industries | Targeted Regions | Targeted CVEs | Associated Attacks/Ransomware | Affected Products |
|---|---|---|---|---|---|---|---|
| UNK_MassTraction | China | Espionage and Information Theft | Higher Education | United States, Canada | CVE-2024-42009, CVE-2025-49113 |
VShell, IceCube, SquareShell, SNOWLIGHT | Roundcube Webmail |
| UAT-7810 | China | Espionage and Information Theft | All | Worldwide | CVE-2020-22653, CVE-2020-22658, CVE-2023-25717 |
SHORTLEASH, LONGLEASH, DOGLEASH, LEASHTEST, JARLEASH | Ruckus wireless routers |
| APT41 (aka Winnti, Group 72, BARIUM, LEAD, GREF, WICKED PANDA, Earth Baku, HOODOO, Brass Typhoon, TA415) | China | Financial crime, Information theft and espionage | Government – Federal; State, Local, Tribal, and Territorial (SLTT); public-safety agencies | United States | - | - | - |
| Cavern Manticore | Iran (MOIS-aligned) | Espionage | IT Service Providers, Government, Defense | Israel | - | Cavern (aka Cav3rn, CAV3RN) | RMM tooling, browser-based remote desktop technologies, Active Directory, LDAP, SMB, Microsoft IIS |
| Coinbase Cartel (aka shinysp1d3r) | - | Financial crime | Technology, Manufacturing, Business Services & Consulting, Real Estate, Transportation, Retail, Financial Services, Healthcare, Telecommunications, Legal, Energy, Pharmaceutical, Casino & Gambling, Education, Media, Agriculture, Aviation, Food Service, Hospitality, Aerospace and Defense, Government | United States, France, UAE, Brazil, Canada, Germany, South Korea, Switzerland, United Kingdom, Indonesia, Japan, Italy, Spain, Belgium, India, Taiwan, China, Bulgaria, Vietnam, Thailand, Croatia, Norway, Colombia, Denmark, Sweden, Ireland, Argentina, Slovenia, Mexico, South Africa, Peru, Greece, Poland, Malta | - | - | Windows, Linux, VMware ESXi (projected), cloud SaaS environments |
Section 09
Use this digest to prioritize the eleven exploited vulnerabilities and block indicators tied to the five tracked threat actors (Section 02).
Use the IOC appendix to block indicators for all thirteen malware families executed this week (Section 02).
Uni5 customers can run a scan over the HivePro Uni5 dashboard to discover assets impacted by the eleven exploited vulnerabilities and gain full insight into their exposure.
Simulate attacks tied to APT41 and the malware IceCube, LONGLEASH, DOGLEASH, Qilin Ransomware, AsyncRAT and Cavern using Breach and Attack Simulation (BAS).
Section 10
Section 11
Section 12
IOCs for the thirteen attacks executed during the 06 to 12 July 2026 window are listed below; a comprehensive list is available on the Uni5Xposure platform.
| Attack Name | Type | Value |
|---|---|---|
| JADEPUFFER | IPv4 | 45[.]131[.]66[.]106 64[.]20[.]53[.]230 |
| VShell | IPv4 | 45[.]86[.]229[.]111 |
| VShell | URL | hxxp[:]//45[.]86[.]229[.]111/slw[:]8080 |
| IceCube | IPv4 | 45[.]150[.]109[.]151 194[.]213[.]18[.]133 |
| IceCube | URL | hxxps[:]//45[.]150[.]109[.]151[.]sslip[.]io[:]23088/app/js/jquery[.]min[.]js hxxps[:]//194[.]213[.]18[.]133[.]sslip[.]io[:]23088/app/js/jquery[.]min[.]js hxxps[:]//45[.]150[.]109[.]151[.]sslip[.]io[:]23088 hxxps[:]//194[.]213[.]18[.]133[.]sslip[.]io[:]23088 |
| IceCube | SHA256 | a02f124c5ce4180bd130a62ee03262f399c33491de3aed36e0b15155ae4926c0 |
| SNOWLIGHT | SHA256 | e9fce3c19902fa735372c8626f8837330bbd675e58571ce9edc2400688853664 72bb962565c44928a76b482acd93401ecd1a03c8e2ad81b691ea297ce86120ed 93deefd83c9a0628c3602a86051611ab0900618a87163517788900aa18314056 d7768573b5fa2a95c6f8e08391d6fac7c3476b107b7fb887f1a759e235d31fa5 fcde1804f700fc2dbe2cf724c54a9b794f2d2ea8334fcf835e2cc8a0c2ea68cb +5 more on Uni5Xposure |
| LONGLEASH | SHA256 | 755fcee1337a252203002ecfdf673a08cfadeda8d738bef2d518a08e0626aa4f |
| DOGLEASH | SHA256 | 604b53f87d6c070bf387e80c70a6df8d272fa3fc143148d41f13e59d52ab1f13 c92541f273eeb576d39235d0a5c6f18f2574b132a1022598edfa38065783ab98 29c7fccc6ef8cbfe4da9a169c7c74bacaea1fb515a1fddef91ab1b1522f76e4c 425bf771c8c9f740b1ae9803dcb4fd45af4d6a6f171fcc72fc7d511095ca82ce ac8eae94d27122f4751bc96d9ea52d30000b7ca37569a2291b2710824ca3396f dc4f25b2247cfdd6fc96848db30a178baa4419a4c854e86e315b465836102d14 3878dd5c8eba1e5b53ab2e07e7b5482e95a3fd3e98268bcd7861318bc9902376 9b9e0e5a1eb469b8d20dc23351e08ff5d5731e1cedce0ddee9bbd00a76217f13 57bdab2ba4b05ec0338c06632599393d5b14227f31a43fe950ea8fdd47428715 b8d247fd1fb85d24a17afeec3815906dfbcdc5359647910b4a153900ec999a0f +60 more on Uni5Xposure |
| LEASHTEST | SHA256 | 1b5649b479fd625de5c8120873644b5eb669cc89cd504582c18e0ae350fd8823 |
| JARLEASH | SHA256 | 324d95024fc8da5c92b5a1f4825aed5a2a91c9ca8fb6aa52abb332a4c9cf4257 bafba443170e54ef7fd431ce7f1b5e202719f3fd022e4ef70788904f574d2cdf |
| Qilin | SHA256 | 73b1fffd35d3a72775e0ac4c836e70efefa0930551a2f813843bdfb32df4579a e4cbee73bb41a3c7efc9b86a58495c5703f08d4b36df849c5bebc046d4681b70 afe7b70b5d92a38fb222ec93c51b907b823a64daf56ef106523bc7acc1442e38 d82069cfc9395a240b9c140d283367ab470d587326c5e256aba78eb2c5a9ea85 +1 more on Uni5Xposure |
| AsyncRAT | SHA256 | 601d9deea6467a57e42c355d481331cd78d6487bd160a081332420c69f214455 daac2fe0fe9a71f531d9b35c9ca269c0bdfbd1bbac5e8d73fc91afcff20ef524 7bb7c893fdf7f7ccd998610969d23993c50fc0b693e67930b6f98d8dbd003ee3 ececf197bee885791a9b13cd48c131eec76d8431f1907f9d55b6c9330b57a85e 346e8e54578f206200f7815d0e315e6bfb58198b5ff96d8bcec02863e5b42cc7 0c0b5dfb2e01c5ddd043ac32e2f7176b4ba439d4e3ea37ca04e4b17aa283d4e7 4c6c9ec88d00a3b77e6288afc4ee9974ac07a2c73012c3e1a017c457dcf22d87 48ee878fefc7d5d9df66fc978dfaafcfb61129acf92b1143e1b865ab292be9f0 +8 more on Uni5Xposure |
| Cavern | SHA256 | 541b1f417b9e42078c3355693a8a492b6a76048850f6549a429e0be99e6819cb cbc9485db715e1b8cc384fe94b4cceadca4006cda8a5e28adc8848529cfafc93 ccf218189c3aadb1c761da14bfda3bae686769031e1e1b10007648bd72e34748 37e123bd7998af4eae32718ce254776f36365a80ba56952593dab46f536d4066 |