Publication

HiveForce Labs · Weekly Threat Digest
Covering 29 June to 05 July 2026, this HiveForce Labs weekly threat digest details six major attacks — TinyRCT, Prinz Eugen, RustDuck, Veil#Drop, PureLog Stealer and Ousaban — alongside five actively exploited vulnerabilities led by CVE-2026-45659 in Microsoft SharePoint Server, and two threat actors, CL-STA-1062 and ROOTBOY.
Publication
Coverage Window
Attacks Executed
Vulns Exploited
Adversaries
Vulns This Week
Total Published
Lead Actor
Source
Section 01
HiveForce Labs has reported a sharp rise in cybersecurity threats, highlighting the growing complexity and frequency of global cyber incidents. Over the past week, this weekly threat digest tracked six major attacks, five vulnerabilities actively exploited, and two threat actor groups closely monitored, signaling a concerning escalation in malicious activity worldwide. HiveForce Labs recorded 472.1K total vulnerabilities published to date, with 1,854 new vulnerabilities published during the 29 June–05 July 2026 window alone, of which five were confirmed as actively exploited.
Leading the pack is CVE-2026-45659, a high-severity flaw in Microsoft SharePoint Server that lets attackers run their own code on the server. The catch is small but nasty: an attacker only needs basic Site Member access, then a single crafted payload does the rest, no clicking or user action required. On the ransomware front, Prinz Eugen showed up in April 2026, a quiet Go-based operation likely run by one person (ROOTBOY, aka GERMANIA). It sneaks in through stolen RDP logins, hijacks the legitimate RemotePC tool to do its dirty work, steals data, locks everything with ChaCha20-Poly1305, and skips the classic ransom note entirely, choosing to negotiate off the radar.
Rounding things out is RustDuck, a botnet built for large-scale DDoS attacks that's been active since February 2026. It grabs whatever it can reach — weak Telnet and SSH passwords, exposed Android Debug Bridge, and a grab-bag of old bugs — sweeping up routers, DVRs, IP cameras, and Linux servers along the way. Alongside RustDuck, this HiveForce Labs weekly threat digest also covers TinyRCT (tied to CL-STA-1062), the fileless Veil#Drop delivery framework, PureLog Stealer, and the Ousaban banking trojan. Put together, these cases point to the same uncomfortable direction: attackers are blending technical exploits with social tricks, and the old "patch it later" habit no longer holds up. Staying ahead means patching fast, watching continuously, and layering defenses so one weak spot doesn't open the whole door.
Section 02
Six attacks were executed during the 29 June to 05 July 2026 window: TinyRCT, Prinz Eugen, RustDuck, Veil#Drop, PureLog Stealer and Ousaban. Five of the six affect Microsoft Windows; RustDuck additionally sweeps up routers, DVRs, IP cameras and Linux servers. Delivery ranges from ASPX web shells and stolen RDP credentials to weak Telnet/SSH credential guessing and phishing.
TinyRCT is a lightweight, C#-based remote access Trojan built to quietly take control of Windows systems. Once executed, it acts as a full-featured backdoor, running arbitrary commands, enumerating and exfiltrating files, capturing screenshots, and giving attackers hands-on remote management of the compromised host. What sets it apart is its evasion-first design: before doing anything else, TinyRCT checks whether it's running from %LOCALAPPDATA%, and if it isn't — say, in a sandbox or on an analyst's machine — it shuts itself down immediately. TinyRCT is delivered via ASPX web shells, is associated with the threat actor CL-STA-1062, and enables system compromise, command execution and screen capture on affected Windows platforms. No targeted CVE or patch link is recorded for TinyRCT.
Prinz Eugen is a financially motivated, Go-based ransomware operation that surfaced publicly in April 2026, with its encryptor first analyzed hands-on the following month. It runs a deliberately quiet double-extortion playbook, stealing data first, encrypting second, but skips the usual ransom note entirely, instead pushing all victim communication out-of-band through direct email and a dedicated Tor leak portal. The operation carries a distinct anti-forensic footprint, prioritizing freshly modified files during encryption to maximize damage fast. Prinz Eugen is delivered via compromised RDP credentials, is associated with the threat actor ROOTBOY, and enables data encryption and data theft on affected Windows platforms. No targeted CVE or patch link is recorded for Prinz Eugen.
RustDuck is a two-stage botnet, active since February 2026, whose main purpose is launching large-scale distributed denial-of-service (DDoS) attacks. It spreads opportunistically through weak Telnet and SSH passwords, exposed Android Debug Bridge interfaces, and a mix of older vulnerabilities in devices and web applications — affecting routers, DVRs, IP cameras, and Linux servers. RustDuck is delivered by guessing weak passwords on exposed Telnet and SSH services and by exploiting known vulnerabilities, targeting CVE-2025-29635, CVE-2017-17215, CVE-2018-8007 and CVE-2024-1781. Affected platforms include Huawei HG532, D-Link DIR-823X, Totolink X6000R, Apache CouchDB, TP-Link, ZTE, Ruijie, TVT, ThinkPHP, Jenkins and Hadoop YARN devices, and RustDuck enables service disruption, network downtime and device hijacking.
Veil#Drop is a multi-stage delivery framework that chains social engineering, compromised websites, and malicious JavaScript launchers into PowerShell download cradles, then abuses trusted cloud-hosted infrastructure to run PureLog Stealer entirely in memory, never touching disk. Delivered via phishing, Veil#Drop enables command execution and the loading of additional payloads on affected Windows platforms. No associated actor, targeted CVE, or patch link is recorded for Veil#Drop.
PureLog Stealer is a .NET-based information stealer that harvests browser credentials, cookies, autofill data, and browsing history, alongside cryptocurrency wallet information and system reconnaissance data. Delivered via phishing (and dropped fileless via Veil#Drop), PureLog Stealer enables data theft on affected Windows platforms. No associated actor, targeted CVE, or patch link is recorded for PureLog Stealer.
The Ousaban banking trojan campaign has been observed targeting Windows users in Spain and Portugal. Its trick is patience: a fake "corrupted" PDF, one click on "Update," and it waits silently until the victim logs into their bank. The malware monitors banking sessions, captures screenshots and keystrokes, manipulates clipboard content, displays fraudulent dialogs, and grants attackers remote control of infected systems. Delivered via phishing, Ousaban enables credential theft, financial fraud and session hijacking on affected Windows platforms. No associated actor, targeted CVE, or patch link is recorded for Ousaban.
Section 03
Five vulnerabilities were exploited in the wild during the reporting window, four of them chained together by the RustDuck botnet and the fifth, CVE-2026-45659, exploited independently against Microsoft SharePoint Server. All five are tracked as zero-day issues by HiveForce Labs.
This zero-day flaw affects D-Link DIR-823X firmware versions 240126 and 240802. Classified under CWE-77, it is exploited by RustDuck via the T1059 Command and Scripting Interpreter technique. The affected device is end-of-life (EOL), with no vendor patch available.
This zero-day flaw affects the Huawei HG532 router. Classified under CWE-20, it is exploited by RustDuck via the T1059 Command and Scripting Interpreter technique. The affected device is end-of-life (EOL), with no vendor patch available.
This zero-day flaw affects Apache CouchDB, all versions up to and including 1.7.1. Classified under CWE-20, it is exploited by RustDuck via T1190 Exploit Public-Facing Application, T1078 Valid Accounts and T1068 Exploitation for Privilege Escalation.
This zero-day flaw affects the Totolink X6000R AX3000, firmware version 9.4.0cu.852_20230719. Classified under CWE-77, it is exploited by RustDuck via T1595 Active Scanning and T1059 Command and Scripting Interpreter.
This zero-day flaw affects Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Classified under CWE-502, it allows an attacker with only basic Site Member access to achieve remote code execution via a single crafted payload, without any user interaction. It is exploited via T1190 Exploit Public-Facing Application and T1059 Command and Scripting Interpreter. No associated actor or attack is recorded for CVE-2026-45659 in this digest.
| CVE ID | Name | Affected Product | Affected CPE | CWE ID | Associated TTPs |
|---|---|---|---|---|---|
| CVE-2025-29635 ZERO-DAY |
D-Link DIR-823X Command Injection Vulnerability | D-Link DIR-823X 240126 and 240802 | cpe:2.3:h:dlink:dir-823x:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-823x_firmware:*:*:*:*:*:*:*:* |
CWE-77 |
T1059 Command and Scripting Interpreter |
| CVE-2017-17215 ZERO-DAY |
Huawei HG532 Remote Code Execution Vulnerability | Huawei HG532 | cpe:2.3:o:huawei:hg532_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:huawei:hg532:-:*:*:*:*:*:*:* |
CWE-20 |
T1059 Command and Scripting Interpreter |
| CVE-2018-8007 ZERO-DAY |
Apache CouchDB Privilege Escalation Vulnerability | Apache CouchDB — all versions up to and including 1.7.1 | cpe:2.3:a:apache:couchdb:*:*:*:*:*:*:*:* | CWE-20 |
T1190 Exploit Public-Facing Application, T1078 Valid Accounts, T1068 Exploitation for Privilege Escalation |
| CVE-2024-1781 ZERO-DAY |
Totolink Command Injection Vulnerability | Totolink X6000R AX3000 9.4.0cu.852_20230719 |
cpe:2.3:h:totolink:x6000r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:x6000r_firmware:9.4.0cu.852_b20230719:*:*:*:*:*:*:* |
CWE-77 |
T1595 Active Scanning, T1059 Command and Scripting Interpreter |
| CVE-2026-45659 ZERO-DAY |
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Enterprise Server 2016 | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server:-:*:*:*:*:subscription:*:*:* |
CWE-502 |
T1190 Exploit Public-Facing Application, T1059 Command and Scripting Interpreter |
Section 04
Two threat actors were tracked this week: CL-STA-1062 and ROOTBOY. CL-STA-1062, originating from China, is motivated by espionage and information theft, mixing old open-source tools with the new custom backdoor TinyRCT to quietly work its way into state-owned energy and government networks across Southeast Asia. It targets Government, Critical Energy Infrastructure and State-Owned Enterprises, is associated with TinyRCT, and affects Windows platforms.
ROOTBOY (also known by the aliases avtokz and GERMANIA) is financially motivated and runs the solo Prinz Eugen ransomware operation — sneaking in via stolen RDP credentials, hijacking RemotePC for staging, then stealing and encrypting data quietly. ROOTBOY targets Financial Services, Professional Services, Education and Automotive organizations across South Africa, France, the United States and the United Kingdom, is associated with Prinz Eugen Ransomware, and affects Windows platforms.
| Name | Motive | Targeted Industries | Targeted Regions | Associated Attacks | Affected Products |
|---|---|---|---|---|---|
| CL-STA-1062 (origin: China) | Espionage and Information Theft | Government, Critical Energy Infrastructure, State-Owned Enterprises | Southeast Asia | TinyRCT | Windows |
| ROOTBOY (aka avtokz, GERMANIA) | Financial Gains | Financial Services, Professional Services, Education, Automotive | South Africa, France, United States, United Kingdom | Prinz Eugen Ransomware | Windows |
Section 05
The countries most targeted by this week's attacks include the Philippines, Spain, Singapore, Brunei, the United Kingdom, Cambodia, Portugal, France, South Africa, Indonesia, Thailand, Laos, the United States of America, Malaysia, Vietnam and Australia, among others. The least-targeted countries recorded include Denmark, Saint Kitts and Nevis, Djibouti, San Marino, Dominica, Serbia, the Dominican Republic, Slovakia, Ecuador, Azerbaijan and Egypt, among others.
Philippines, Spain, Singapore, Brunei, United Kingdom, Cambodia, Portugal, France, South Africa, Indonesia, Thailand, Laos, United States of America, Malaysia, Vietnam, Australia, Mauritania, Tajikistan, Belgium, Nicaragua, Belize, Sierra Leone, Benin, Uruguay, Bhutan
Morocco, Bolivia, Palau, Bosnia and Herzegovina, Saint Vincent and the Grenadines, Botswana, South Sudan, Brazil, Turkey, Albania, Maldives, Bulgaria, Moldova, Burkina Faso, Nauru, Burundi, North Macedonia, Cabo Verde, Paraguay, Algeria, Russia, Cameroon, Saudi Arabia, Canada, Solomon Islands
Suriname, Chad, Togo, Chile, Ukraine, China, Malawi, Colombia, Malta, Comoros, Mexico, Congo, Mongolia, Costa Rica, Myanmar, Côte d'Ivoire, Netherlands, Croatia, Nigeria, Cuba, Oman, Cyprus, Panama, Czechia
Denmark, Saint Kitts and Nevis, Djibouti, San Marino, Dominica, Serbia, Dominican Republic, Slovakia, Ecuador, Azerbaijan, Egypt, Sri Lanka, El Salvador, Switzerland, Equatorial Guinea, Bahrain, Eritrea, Trinidad and Tobago, Estonia, Tuvalu, Eswatini
Section 06
This digest can be used to drive security teams to prioritize the five exploited vulnerabilities — CVE-2025-29635, CVE-2017-17215, CVE-2018-8007, CVE-2024-1781 and CVE-2026-45659.
Block the indicators related to the threat actors CL-STA-1062 and ROOTBOY, and the malware TinyRCT, Prinz Eugen Ransomware, RustDuck, Veil#Drop, PureLog Stealer, and Ousaban.
HivePro Uni5 customers can run a scan over the HivePro Uni5 dashboard to discover the assets impacted by the five exploited vulnerabilities and gain comprehensive insight into their threat exposure.
Test the efficacy of security controls by simulating the attacks related to the malware TinyRCT, Prinz Eugen Ransomware, RustDuck, PureLog Stealer, and Ousaban in Breach and Attack Simulation (BAS).
Section 07
The following indicators of compromise are associated with the attacks executed during the 29 June to 05 July 2026 window. A comprehensive list of IOCs associated with the executed attacks is available on the Uni5Xposure platform.
| Attack Name | Type | Value |
|---|---|---|
| TinyRCT | SHA256 | 4e1f8888d020decd09799ec946f1bf677cac6612b24582ddbf4d8ede425d8384 |
| Prinz Eugen | Domain | g-captchafestung[.]sbs festung-e[.]duckdns[.]org |
| Prinz Eugen | URL | hxxps[:]//212[.]80[.]7[.]74/serverscan[.]ps1 hxxps[:]//212[.]80[.]7[.]74/stager/mini hxxps[:]//212[.]80[.]7[.]74/stager/ps1 hxxp[:]//stndrdbnk[.]cc |
| Prinz Eugen | Email | prinzeugen[@]mail2tor[.]co standardbankcc[@]cock[.]li |
| Prinz Eugen | SHA256 | 686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4 |
| Prinz Eugen | TOR Address | prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd[.]onion 6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad[.]onion prinzkpn6d3itrgcytmsmlcpt5mgwn3ihpck2hsed5cezlbtbi3wklid[.]onion |
| Prinz Eugen | Bitcoin Address | bc1q2ztpcvqdaptej6uu2ywt9mrlatx6envu34rf0v |
| Prinz Eugen | Tox ID | 496187425B2944D73FBB17CAF3F9FD569B9ED3A08A497A8314CB4F27A51E65081ACEE1E22F21 |
| RustDuck | SHA256 | a5d1b65b1055677156cd87b357ef488704115a2cbf52044dbb041072efed2f9d |
| PureLog Stealer | SHA256 | 7e4646d0cf91153653c5e366f98a65aad5ef363e0edeb246c809f53085971453 3d3342af3608399704d5daf9dc061ad1f8b243531fd9ef8497a10c6a9dd59661 |
| Ousaban | SHA256 | ffb9eb47cc0cb2f43e04a10dc84df13d04bca1ebacbe47fad0b669728de2f59c 18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4e 4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcb 5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0d e6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14 |
Section 08
The top MITRE ATT&CK TTPs observed across this week's six attacks span execution, defense evasion, discovery, exfiltration, and command-and-control techniques. The following are the leading techniques reported in this HiveForce Labs weekly threat digest.
Execution
Command and Scripting Interpreter
Command and Control
Application Layer Protocol
Defense Evasion
Obfuscated Files or Information
Command and Control
Ingress Tool Transfer
Discovery
System Information Discovery
Command and Control
Web Protocols
Exfiltration
Exfiltration Over C2 Channel
Command and Control
Encrypted Channel
Defense Evasion
Virtualization/Sandbox Evasion
Execution
User Execution
Defense Evasion
Indicator Removal
Defense Evasion
Masquerading
Initial Access
Exploit Public-Facing Application
Execution
PowerShell
Execution
Malicious File
Defense Evasion
Deobfuscate/Decode Files or Information
Collection
Data from Local System
Defense Evasion
File Deletion
Command and Control
Dynamic Resolution
Command and Control
Symmetric Cryptography
Section 09