Weekly Threat Digest : JUNE 29 to JULY 05

Threat Digest
Download Now
Weekly Threat Digest — 29 June to 05 July 2026 | HiveForce Labs

HiveForce Labs · Weekly Threat Digest

Weekly Threat Digest: Six Attacks, SharePoint's CVE-2026-45659 Exploitation, and the Prinz Eugen Ransomware and RustDuck Botnet

Covering 29 June to 05 July 2026, this HiveForce Labs weekly threat digest details six major attacks — TinyRCT, Prinz Eugen, RustDuck, Veil#Drop, PureLog Stealer and Ousaban — alongside five actively exploited vulnerabilities led by CVE-2026-45659 in Microsoft SharePoint Server, and two threat actors, CL-STA-1062 and ROOTBOY.

ATTACKS EXECUTED: 6 VULNERABILITIES EXPLOITED: 5 ADVERSARIES IN ACTION: 2 CVE-2026-45659 · ZERO-DAY PUBLISHED: JULY 6, 2026

Publication

July 6, 2026

Coverage Window

29 June–05 July 2026

Attacks Executed

6

Vulns Exploited

5

Adversaries

2

Vulns This Week

1,854

Total Published

472.1K

Lead Actor

ROOTBOY & CL-STA-1062

Source

HiveForce Labs

Summary

HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, this weekly threat digest tracked six major attacks, five vulnerabilities actively exploited, and two threat actor groups closely monitored, signaling a concerning escalation in malicious activity worldwide. HiveForce Labs recorded 472.1K total vulnerabilities published to date, with 1,854 new vulnerabilities published during the 29 June–05 July 2026 window alone, of which five were confirmed as actively exploited.

Leading the pack is CVE-2026-45659, a high-severity flaw in Microsoft SharePoint Server that lets attackers run their own code on the server. The catch is small but nasty: an attacker only needs basic Site Member access, then a single crafted payload does the rest, no clicking or user action required. On the ransomware front, Prinz Eugen showed up in April 2026, a quiet Go-based operation likely run by one person (ROOTBOY, aka GERMANIA). It sneaks in through stolen RDP logins, hijacks the legitimate RemotePC tool to do its dirty work, steals data, locks everything with ChaCha20-Poly1305, and skips the classic ransom note entirely, choosing to negotiate off the radar.

Rounding things out is RustDuck, a botnet built for large-scale DDoS attacks that's been active since February 2026. It grabs whatever it can reach — weak Telnet and SSH passwords, exposed Android Debug Bridge, and a grab-bag of old bugs — sweeping up routers, DVRs, IP cameras, and Linux servers along the way. Alongside RustDuck, this HiveForce Labs weekly threat digest also covers TinyRCT (tied to CL-STA-1062), the fileless Veil#Drop delivery framework, PureLog Stealer, and the Ousaban banking trojan. Put together, these cases point to the same uncomfortable direction: attackers are blending technical exploits with social tricks, and the old "patch it later" habit no longer holds up. Staying ahead means patching fast, watching continuously, and layering defenses so one weak spot doesn't open the whole door.


Attack Details

Six attacks were executed during the 29 June to 05 July 2026 window: TinyRCT, Prinz Eugen, RustDuck, Veil#Drop, PureLog Stealer and Ousaban. Five of the six affect Microsoft Windows; RustDuck additionally sweeps up routers, DVRs, IP cameras and Linux servers. Delivery ranges from ASPX web shells and stolen RDP credentials to weak Telnet/SSH credential guessing and phishing.

TinyRCT — Backdoor

TinyRCT is a lightweight, C#-based remote access Trojan built to quietly take control of Windows systems. Once executed, it acts as a full-featured backdoor, running arbitrary commands, enumerating and exfiltrating files, capturing screenshots, and giving attackers hands-on remote management of the compromised host. What sets it apart is its evasion-first design: before doing anything else, TinyRCT checks whether it's running from %LOCALAPPDATA%, and if it isn't — say, in a sandbox or on an analyst's machine — it shuts itself down immediately. TinyRCT is delivered via ASPX web shells, is associated with the threat actor CL-STA-1062, and enables system compromise, command execution and screen capture on affected Windows platforms. No targeted CVE or patch link is recorded for TinyRCT.

Prinz Eugen — Ransomware

Prinz Eugen is a financially motivated, Go-based ransomware operation that surfaced publicly in April 2026, with its encryptor first analyzed hands-on the following month. It runs a deliberately quiet double-extortion playbook, stealing data first, encrypting second, but skips the usual ransom note entirely, instead pushing all victim communication out-of-band through direct email and a dedicated Tor leak portal. The operation carries a distinct anti-forensic footprint, prioritizing freshly modified files during encryption to maximize damage fast. Prinz Eugen is delivered via compromised RDP credentials, is associated with the threat actor ROOTBOY, and enables data encryption and data theft on affected Windows platforms. No targeted CVE or patch link is recorded for Prinz Eugen.

RustDuck — Botnet

RustDuck is a two-stage botnet, active since February 2026, whose main purpose is launching large-scale distributed denial-of-service (DDoS) attacks. It spreads opportunistically through weak Telnet and SSH passwords, exposed Android Debug Bridge interfaces, and a mix of older vulnerabilities in devices and web applications — affecting routers, DVRs, IP cameras, and Linux servers. RustDuck is delivered by guessing weak passwords on exposed Telnet and SSH services and by exploiting known vulnerabilities, targeting CVE-2025-29635, CVE-2017-17215, CVE-2018-8007 and CVE-2024-1781. Affected platforms include Huawei HG532, D-Link DIR-823X, Totolink X6000R, Apache CouchDB, TP-Link, ZTE, Ruijie, TVT, ThinkPHP, Jenkins and Hadoop YARN devices, and RustDuck enables service disruption, network downtime and device hijacking.

Veil#Drop — Framework

Veil#Drop is a multi-stage delivery framework that chains social engineering, compromised websites, and malicious JavaScript launchers into PowerShell download cradles, then abuses trusted cloud-hosted infrastructure to run PureLog Stealer entirely in memory, never touching disk. Delivered via phishing, Veil#Drop enables command execution and the loading of additional payloads on affected Windows platforms. No associated actor, targeted CVE, or patch link is recorded for Veil#Drop.

PureLog Stealer — Infostealer

PureLog Stealer is a .NET-based information stealer that harvests browser credentials, cookies, autofill data, and browsing history, alongside cryptocurrency wallet information and system reconnaissance data. Delivered via phishing (and dropped fileless via Veil#Drop), PureLog Stealer enables data theft on affected Windows platforms. No associated actor, targeted CVE, or patch link is recorded for PureLog Stealer.

Ousaban — Banking Trojan

The Ousaban banking trojan campaign has been observed targeting Windows users in Spain and Portugal. Its trick is patience: a fake "corrupted" PDF, one click on "Update," and it waits silently until the victim logs into their bank. The malware monitors banking sessions, captures screenshots and keystrokes, manipulates clipboard content, displays fraudulent dialogs, and grants attackers remote control of infected systems. Delivered via phishing, Ousaban enables credential theft, financial fraud and session hijacking on affected Windows platforms. No associated actor, targeted CVE, or patch link is recorded for Ousaban.


Vulnerabilities Exploited

Five vulnerabilities were exploited in the wild during the reporting window, four of them chained together by the RustDuck botnet and the fifth, CVE-2026-45659, exploited independently against Microsoft SharePoint Server. All five are tracked as zero-day issues by HiveForce Labs.

CVE-2025-29635 — D-Link DIR-823X Command Injection Vulnerability

This zero-day flaw affects D-Link DIR-823X firmware versions 240126 and 240802. Classified under CWE-77, it is exploited by RustDuck via the T1059 Command and Scripting Interpreter technique. The affected device is end-of-life (EOL), with no vendor patch available.

CVE-2017-17215 — Huawei HG532 Remote Code Execution Vulnerability

This zero-day flaw affects the Huawei HG532 router. Classified under CWE-20, it is exploited by RustDuck via the T1059 Command and Scripting Interpreter technique. The affected device is end-of-life (EOL), with no vendor patch available.

CVE-2018-8007 — Apache CouchDB Privilege Escalation Vulnerability

This zero-day flaw affects Apache CouchDB, all versions up to and including 1.7.1. Classified under CWE-20, it is exploited by RustDuck via T1190 Exploit Public-Facing Application, T1078 Valid Accounts and T1068 Exploitation for Privilege Escalation.

CVE-2024-1781 — Totolink Command Injection Vulnerability

This zero-day flaw affects the Totolink X6000R AX3000, firmware version 9.4.0cu.852_20230719. Classified under CWE-77, it is exploited by RustDuck via T1595 Active Scanning and T1059 Command and Scripting Interpreter.

CVE-2026-45659 — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

This zero-day flaw affects Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Classified under CWE-502, it allows an attacker with only basic Site Member access to achieve remote code execution via a single crafted payload, without any user interaction. It is exploited via T1190 Exploit Public-Facing Application and T1059 Command and Scripting Interpreter. No associated actor or attack is recorded for CVE-2026-45659 in this digest.

CVE IDNameAffected ProductAffected CPECWE IDAssociated TTPs
CVE-2025-29635
ZERO-DAY
D-Link DIR-823X Command Injection Vulnerability D-Link DIR-823X 240126 and 240802 cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-823x_firmware:*:*:*:*:*:*:*:*
CWE-77 T1059 Command and Scripting Interpreter
CVE-2017-17215
ZERO-DAY
Huawei HG532 Remote Code Execution Vulnerability Huawei HG532 cpe:2.3:o:huawei:hg532_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:huawei:hg532:-:*:*:*:*:*:*:*
CWE-20 T1059 Command and Scripting Interpreter
CVE-2018-8007
ZERO-DAY
Apache CouchDB Privilege Escalation Vulnerability Apache CouchDB — all versions up to and including 1.7.1 cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:* CWE-20 T1190 Exploit Public-Facing Application, T1078 Valid Accounts, T1068 Exploitation for Privilege Escalation
CVE-2024-1781
ZERO-DAY
Totolink Command Injection Vulnerability Totolink X6000R AX3000 9.4.0cu.852_20230719 cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.852_b20230719:*:*:*:*:*:*:*
CWE-77 T1595 Active Scanning, T1059 Command and Scripting Interpreter
CVE-2026-45659
ZERO-DAY
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016 cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:-:*:*:*:*:subscription:*:*:*
CWE-502 T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter

Adversaries in Action

Two threat actors were tracked this week: CL-STA-1062 and ROOTBOY. CL-STA-1062, originating from China, is motivated by espionage and information theft, mixing old open-source tools with the new custom backdoor TinyRCT to quietly work its way into state-owned energy and government networks across Southeast Asia. It targets Government, Critical Energy Infrastructure and State-Owned Enterprises, is associated with TinyRCT, and affects Windows platforms.

ROOTBOY (also known by the aliases avtokz and GERMANIA) is financially motivated and runs the solo Prinz Eugen ransomware operation — sneaking in via stolen RDP credentials, hijacking RemotePC for staging, then stealing and encrypting data quietly. ROOTBOY targets Financial Services, Professional Services, Education and Automotive organizations across South Africa, France, the United States and the United Kingdom, is associated with Prinz Eugen Ransomware, and affects Windows platforms.

NameMotiveTargeted IndustriesTargeted RegionsAssociated AttacksAffected Products
CL-STA-1062 (origin: China) Espionage and Information Theft Government, Critical Energy Infrastructure, State-Owned Enterprises Southeast Asia TinyRCT Windows
ROOTBOY (aka avtokz, GERMANIA) Financial Gains Financial Services, Professional Services, Education, Automotive South Africa, France, United States, United Kingdom Prinz Eugen Ransomware Windows

Targeted Countries

The countries most targeted by this week's attacks include the Philippines, Spain, Singapore, Brunei, the United Kingdom, Cambodia, Portugal, France, South Africa, Indonesia, Thailand, Laos, the United States of America, Malaysia, Vietnam and Australia, among others. The least-targeted countries recorded include Denmark, Saint Kitts and Nevis, Djibouti, San Marino, Dominica, Serbia, the Dominican Republic, Slovakia, Ecuador, Azerbaijan and Egypt, among others.

Most Targeted

Philippines, Spain, Singapore, Brunei, United Kingdom, Cambodia, Portugal, France, South Africa, Indonesia, Thailand, Laos, United States of America, Malaysia, Vietnam, Australia, Mauritania, Tajikistan, Belgium, Nicaragua, Belize, Sierra Leone, Benin, Uruguay, Bhutan

Also Targeted

Morocco, Bolivia, Palau, Bosnia and Herzegovina, Saint Vincent and the Grenadines, Botswana, South Sudan, Brazil, Turkey, Albania, Maldives, Bulgaria, Moldova, Burkina Faso, Nauru, Burundi, North Macedonia, Cabo Verde, Paraguay, Algeria, Russia, Cameroon, Saudi Arabia, Canada, Solomon Islands

Lower Incidence

Suriname, Chad, Togo, Chile, Ukraine, China, Malawi, Colombia, Malta, Comoros, Mexico, Congo, Mongolia, Costa Rica, Myanmar, Côte d'Ivoire, Netherlands, Croatia, Nigeria, Cuba, Oman, Cyprus, Panama, Czechia

Least Targeted

Denmark, Saint Kitts and Nevis, Djibouti, San Marino, Dominica, Serbia, Dominican Republic, Slovakia, Ecuador, Azerbaijan, Egypt, Sri Lanka, El Salvador, Switzerland, Equatorial Guinea, Bahrain, Eritrea, Trinidad and Tobago, Estonia, Tuvalu, Eswatini


Recommendations

01
Prioritize the five exploited vulnerabilities

This digest can be used to drive security teams to prioritize the five exploited vulnerabilities — CVE-2025-29635, CVE-2017-17215, CVE-2018-8007, CVE-2024-1781 and CVE-2026-45659.

02
Block indicators tied to CL-STA-1062, ROOTBOY and the six malware families

Block the indicators related to the threat actors CL-STA-1062 and ROOTBOY, and the malware TinyRCT, Prinz Eugen Ransomware, RustDuck, Veil#Drop, PureLog Stealer, and Ousaban.

03
Run a scan to discover impacted assets (Uni5 users)

HivePro Uni5 customers can run a scan over the HivePro Uni5 dashboard to discover the assets impacted by the five exploited vulnerabilities and gain comprehensive insight into their threat exposure.

04
Test control efficacy with Breach and Attack Simulation (Uni5 users)

Test the efficacy of security controls by simulating the attacks related to the malware TinyRCT, Prinz Eugen Ransomware, RustDuck, PureLog Stealer, and Ousaban in Breach and Attack Simulation (BAS).


Indicators of Compromise (IoCs)

The following indicators of compromise are associated with the attacks executed during the 29 June to 05 July 2026 window. A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.

Attack NameTypeValue
TinyRCTSHA2564e1f8888d020decd09799ec946f1bf677cac6612b24582ddbf4d8ede425d8384
Prinz EugenDomaing-captchafestung[.]sbs
festung-e[.]duckdns[.]org
Prinz EugenURLhxxps[:]//212[.]80[.]7[.]74/serverscan[.]ps1
hxxps[:]//212[.]80[.]7[.]74/stager/mini
hxxps[:]//212[.]80[.]7[.]74/stager/ps1
hxxp[:]//stndrdbnk[.]cc
Prinz EugenEmailprinzeugen[@]mail2tor[.]co
standardbankcc[@]cock[.]li
Prinz EugenSHA256686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4
Prinz EugenTOR Addressprinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd[.]onion
6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad[.]onion
prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid[.]onion
Prinz EugenBitcoin Addressbc1q2ztpcvqdaptej6uu2ywt9mrlatx6envu34rf0v
Prinz EugenTox ID496187425B2944D73FBB17CAF3F9FD569B9ED3A08A497A8314CB4F27A51E65081ACEE1E22F21
RustDuckSHA256a5d1b65b1055677156cd87b357ef488704115a2cbf52044dbb041072efed2f9d
PureLog StealerSHA2567e4646d0cf91153653c5e366f98a65aad5ef363e0edeb246c809f53085971453
3d3342af3608399704d5daf9dc061ad1f8b243531fd9ef8497a10c6a9dd59661
OusabanSHA256ffb9eb47cc0cb2f43e04a10dc84df13d04bca1ebacbe47fad0b669728de2f59c
18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4e
4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcb
5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0d
e6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14

MITRE ATT&CK TTPs

The top MITRE ATT&CK TTPs observed across this week's six attacks span execution, defense evasion, discovery, exfiltration, and command-and-control techniques. The following are the leading techniques reported in this HiveForce Labs weekly threat digest.

T1059

Execution

Command and Scripting Interpreter

T1071

Command and Control

Application Layer Protocol

T1027

Defense Evasion

Obfuscated Files or Information

T1105

Command and Control

Ingress Tool Transfer

T1082

Discovery

System Information Discovery

T1071.001

Command and Control

Web Protocols

T1041

Exfiltration

Exfiltration Over C2 Channel

T1573

Command and Control

Encrypted Channel

T1497

Defense Evasion

Virtualization/Sandbox Evasion

T1204

Execution

User Execution

T1070

Defense Evasion

Indicator Removal

T1036

Defense Evasion

Masquerading

T1190

Initial Access

Exploit Public-Facing Application

T1059.001

Execution

PowerShell

T1204.002

Execution

Malicious File

T1140

Defense Evasion

Deobfuscate/Decode Files or Information

T1005

Collection

Data from Local System

T1070.004

Defense Evasion

File Deletion

T1568

Command and Control

Dynamic Resolution

T1573.001

Command and Control

Symmetric Cryptography


References & Patch Links