Threat Newsletter September 28, 2026
This was the week AI stopped being a talking point and started showing up in the receipts. An attacker ran a mostly autonomous agent stack against hundreds of online retailers for about $25 a target. Talos found a Windows implant that lets a panel of LLMs vote on its next move. And researchers walked out of a coding agent's sandbox through its own trust plumbing. Meanwhile, the criminal ecosystem ate itself (ShinyHunters hijacking Cl0p's leak site), North Korea's fake-recruiter machine got a four-nation advisory and Japan's first laptop farm takedown, and social engineering kept doing what it does best, this time at Astrana Health.
Malicious AI Agents Steal 600K Cards, Skim 100+ Sites
Gambit researchers tracked a financially motivated operator (assessed as likely Chinese) who chained three open-source AI agent frameworks to scan, exploit, and post-exploit online retailers at scale. Strix handled recon, Cairn handled exploitation, and Hermes orchestrated the operation, backed by a commercial LLM. Over the campaign, at least 119 sites were infected with card skimmers and more than 600,000 valid cards were lifted from two companies. Victims included a Fortune 500 hospitality firm and a major U.S. airline. Gambit got into the attacker's staging server and found an OpenRouter account showing roughly $7,000 in spend over four weeks, putting the average cost per target at around $25. One nasty detail: an agent skill told Hermes to wipe card fields from Magento databases after exfil, which caused real data loss at several retailers.
Key Takeaways
- The economics have flipped. Tens of targets a day at a few dollars each means "we're too small to be targeted" is dead.
- Skimmer persistence was creative: poisoned CDN/S3 content, altered Kubernetes deployments, DB field edits, and cron jobs that re-inject after cleanup. Hunt beyond the checkout page.
- Plan for destructive side effects. Your IR playbook for Magento/e-commerce needs a data-integrity and backup-restore step, not just skimmer removal.
- Sites running custom software were prioritized, likely because they're more likely to be vulnerable.

Talos CAIRN Uncovers CLOSEDQUORUM, an Implant That Lets LLMs Run C2
Cisco Talos open-sourced CAIRN (Cognitive Artifact Intelligence Research Network), a toolkit for hunting AI-integrated malware by its fingerprints: prompt templates, provider endpoints, API-key prefixes, jailbreak strings, and orchestration logic, all without detonating samples. The launch surfaced CLOSEDQUORUM, which Talos calls the first publicly documented Windows implant to hand off tactical C2 decisions to AI. Rather than waiting on an operator, it queries up to four commercial LLMs (DeepSeek, Qwen, Mistral, Gemini) and takes a plurality vote on its next action. Talos hasn't confirmed in-the-wild use and the public build doesn't work, but static analysis showed a complete autonomous decision loop. Talos frames this as "effort displacement": an entire attack phase moving from human to machine, which doesn't sleep.
Key Takeaways
- This is a meaningful step past LAMEHUG-style "LLM generates a command" into "LLM decides what happens next."
- Blocking AI provider domains isn't realistic. Instead correlate unexpected multi-provider LLM traffic with LSASS access, injection, persistence changes, and Discord comms.
- CAIRN is worth adding to your toolkit now. Metadata-first hunting (API key prefixes, prompt strings) is a great YARA/retrohunt angle.

Researchers Escape OpenAI Codex Sandbox (Twice)
Oren Yomtov of Accomplish AI found two sandbox escapes in OpenAI's Codex, reported August 12 and patched within eight days. The worse one, Heapjack, abuses node_repl, a component Codex Desktop silently writes into the shared ~/.codex/config.toml (so CLI users inherit it). Trusted and untrusted JavaScript contexts share one Node heap, so untrusted code can snapshot the heap, brute-force the UUID-shaped auth token, and send requests to the unsandboxed parent process. Net result: open a malicious repo, ask Codex a question, and the repo author gets command execution on your machine, even in read-only mode. The second bug, Overpatch, tricks the apply_patch tool into widening its own write permissions by naming /tmp, then writes to .zshrc via symlink.
Key Takeaways
- Update: Codex Desktop 26.818.21641+ and Codex CLI 0.149.0+.
- Root cause pattern: the enforcement mechanism lived inside the thing it was enforcing. Expect more of this across coding agents (Pillar showed similar issues in Cursor, Gemini CLI, and Antigravity in July).
- Treat "open an untrusted repo in an AI agent" as a code-execution event in your threat model.
- Detection idea: watch for coding-agent processes spawning children outside their expected process tree, or touching shell rc files and the Docker socket.

ShinyHunters Hijacks Cl0p's Leak Site and Extorts the Extortionists
ShinyHunters defaced Cl0p's long-running dark web leak site and turned it against its owners, posting an eight-figure demand that escalates every 24 hours, naming three alleged Cl0p operators, and threatening to publish which victims paid Cl0p, how much, and to which Bitcoin addresses. The feud reportedly traces back to Cl0p's use of an Oracle E-Business Suite exploit that ShinyHunters had released as a PoC on Telegram, plus threats against a ShinyHunters member. By Monday, the defacement was replaced with what looked like Cl0p trying to reach ShinyHunters to talk.
Key Takeaways
- If your org ever paid Cl0p, assume that payment record could go public. Loop in legal and comms now, not after a leak.
- Crime-on-crime fights are intel gold. Watch for leaked infrastructure, wallet addresses, and operator details.
- Reminder of how fluid this ecosystem is: exploit released by one crew, weaponized at scale by another. EBS patching should already be done.

Fake LastPass Installers Deliver Kernel-Level EDR Killer and Rapuncel Stealer
LastPass (with Delphos) uncovered a months-long brand impersonation campaign spoofing at least 40 companies. SEO-boosted GitHub pages pushed a fake LastPass Authenticator (plus a fake macOS app), routed through a Cloudflare-fronted redirect chain the operator can change on the fly. The payload sideloads a malicious DLL via a renamed Microsoft debugging tool, escalates to SYSTEM, and installs a Microsoft-attested kernel driver disguised as an NVIDIA component that kills 145 security products. Rapuncel then steals from 25 browsers, 30 crypto wallets, Discord, Steam, Telegram, and the Windows credential store, and it loops continuously to re-kill any security tool that restarts. The DLL ties back to the Cruciferra crypter service, and Rapuncel looks like a sibling of BoryptGrab.
Key Takeaways
- A signed, Microsoft-attested driver is still a malicious driver. Enforce the vulnerable/malicious driver blocklist and alert on new kernel driver installs.
- Search-engine and GitHub results are not a trusted software source. Push users to official download portals or managed app catalogs.
- Hunt for: new auto-start services loading unusual drivers, security agents repeatedly stopping, and signed MS binaries loading DLLs from user-writable paths.

A ClickFix MaaS Built on Stolen ErrTraffic Code
Sekoia analyzed Exvicy, a new ClickFix malware-as-a-service sold on Exploit.IN since late May (price rose from $1,200 to $2,000 a month). It injects obfuscated JavaScript into compromised WordPress sites to show a fake Cloudflare Turnstile check, then instructs victims (in 13 languages) to press Win+R and paste a PowerShell command already sitting in their clipboard. The page reports each victim step back to the operator. Sekoia assessed with high confidence that the code is lifted from rival ErrTraffic. The main difference: ErrTraffic hides C2 on the Polygon blockchain (EtherHiding), while Exvicy just hardcodes two servers. Sekoia found the infrastructure from a poorly redacted screenshot in the seller's own ad, then pivoted to about 80 panel hosts.
Key Takeaways
- ClickFix is still the favorite delivery method. Detect on
explorer.exe→ PowerShell/mshta via the Run dialog, and review RunMRU registry entries. - User awareness message is simple: no legitimate CAPTCHA ever asks you to press Win+R.
- Hardcoded C2 means Exvicy infrastructure is easier to block than ErrTraffic's. Grab Sekoia's IOCs.
- OPSEC fails by operators are a real pivot source. Always check the screenshots in forum ads.

WaterPlum: Fake Recruiters Infect 30,000 Devices Across 100 Countries
The FBI and DoD joined Japan's National Police Agency plus Australian and German agencies on an advisory about WaterPlum (aka Contagious Interview). Between December 2025 and July 2026, the group infected at least 30,000 devices and hit roughly 7,000 crypto wallets by posing as AI or blockchain companies and getting job seekers to download files during "interviews." Japanese police found BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle on victim machines. The hackers keep access after the theft, hoping victims later get hired at tech firms so they can ride into corporate networks. The advisory ties WaterPlum and North Korea's IT worker scheme to the same bureau inside the regime.
Key Takeaways
- Your developers' personal job hunts are your attack surface. A compromised personal laptop can become a corporate foothold later.
- Pull the advisory's malware families into detections. BeaverTail/InvisibleFerret are well documented and worth hunting for in dev environments.
- Treat "download and run this take-home project" as a known lure pattern in security awareness for engineering teams.

Japan Dismantles Its First North Korean Laptop Farm
The same joint advisory details Japan's first confirmed takedown of a North Korean laptop farm, run by a Japanese national, with evidence that several hundred million yen in crypto was moved abroad. WaterPlum actors and North Korean IT workers were seen on the same IP addresses when accessing laptop farms and applying for jobs. The agencies estimate about $10.71 million from the campaign reached Pyongyang. The advisory also shares interview red flags: resumes claiming expertise in everything, English that doesn't match claimed credentials, AI face-swapping that cuts out minutes into calls, reading from a second screen, requests for crypto pay, and refusal to meet in person.
Key Takeaways
- Hand the advisory's red-flag list to HR and hiring managers. This is a hiring-process control, not just a SOC problem.
- Correlate candidate application IPs and VPN use with known laptop farm indicators.
- IT workers aren't just revenue generators. The advisory cites cases of extortion via leaked source code and site defacement.

ShinyHunters' Alleged FBI Data Exposes Intelligence Assignments
Reuters reviewed a 5,000-line spreadsheet ShinyHunters says is a small slice of a 2–3 TB haul from the FBI. It contains names, addresses, phone numbers, birth dates, SSNs, and emergency contacts, plus job assignments that in some cases point to counterintelligence and security units, including work against Chinese and Russian intelligence and cartels. Reuters independently verified details for more than 22 people. Some units referenced had not been publicly disclosed. A former FBI counterintelligence operative called it a goldmine for foreign intelligence services.
Key Takeaways
- Personnel data plus assignment data is a targeting package for hostile intel services, not just an identity theft problem.
- ShinyHunters is on a tear this month (Cl0p, FBI, and reported Oracle PeopleSoft activity). Track them as a top-tier threat, not a nuisance.
- For orgs with sensitive staff: review what org-chart and assignment data lives in HR/ERP systems and who can reach it.

Astrana Health Breached via Vishing with Spoofed Company Number
Astrana Health, a California healthcare management firm handling claims and billing, disclosed in an SEC 8-K that attackers impersonated staff and spoofed its main phone number to call employees and gain server access. Data was exfiltrated, and the company is still working out whether patient, employee, provider, and financial data was involved. It has rotated credentials, restricted remote access tools, rebuilt systems from backups, and beefed up logging. No group has claimed it yet.
Key Takeaways
- Caller ID is not authentication. Build call-back verification to known numbers into help desk and internal support flows.
- The remediation list (restrict remote access tools, rotate creds) strongly suggests RMM abuse. Audit which remote tools are allowed and alert on new installs.
- Healthcare back-office providers are high-value third parties. Check your BAAs and vendor notification terms.

LMU Munich Hit, Student Bank and Insurance Data Likely Taken
Ludwig Maximilian University of Munich, one of Germany's largest with more than 52,000 students, detected an intrusion into a system holding enrollment data and said it must assume the data was taken. Potentially affected records include names, birth dates, contact details, bank account info, health insurance numbers, student financial aid identifiers, and in some cases reasons for leave requests. Exam records and grades weren't affected. The university pulled the server, shut down other systems as a precaution, briefly paused enrollment, and is monitoring dark web forums. No attacker or ransom demand has been disclosed.
Key Takeaways:
- Enrollment systems are rich PII stores that often get less protection than research or finance systems.
- Expect phishing targeting LMU students using the leaked bank and insurance details.
- Timing matters: attacks around semester start maximize disruption. Universities should staff up monitoring around those windows.

InjectEave: Eavesdropping on Headphones Through Walls with RF Injection
Researchers from HKUST (Guangzhou) and Hong Kong PolyU presented InjectEave at USENIX Security 2026. Instead of passively capturing faint EM leakage, the attack actively injects an RF signal (0–9 MHz) that interacts with nonlinear components like amplifiers and power converters, modulating the target audio so it can be picked up nearby. Using commodity gear (a USRP B210 SDR, antennas, a spectrum analyzer), they tested 11 devices including wired and wireless headphones, a VoIP phone, smart fans, and smart lamps. Most were vulnerable from over 2 meters and through walls, and headphone audio was recovered from up to 30 meters with an amplifier.
Key Takeaways
- Encryption doesn't help here. The leak happens on the analog path.
- Mostly a concern for high-security environments (executive travel, hotel rooms, sensitive meeting spaces), not the average user.
- Mitigations like shielding, twisted-pair wiring, and filtering raise the bar but don't eliminate the risk. Factor this into TSCM and secure-facility planning.

Trump Announces an "AI Force" and a Forthcoming AI Czar
President Trump said on Truth Social that he's forming an "AI Force," modeled on Space Force, and will name an AI czar. He pledged not to slow the industry, called fears about AI a hoax, and said existing criminal and civil justice systems can handle bad actors. Details are thin: no mission, authority, budget, or placement in government has been specified, and the White House didn't respond to questions. Critics point out that Space Force was created by Congress through the NDAA, with doctrine and budget, and there's no equivalent structure for AI yet.
Key Takeaways
- Nothing actionable for defenders yet. Watch for an executive order or NDAA language that defines what this actually is.
- The stance is clearly pro-acceleration, so don't expect new federal AI security mandates soon. Your own AI governance program is on you.
- If the czar role gets real authority, it could shape federal procurement rules for AI security tools.

Congress Eyes Support for Cyber Command After Cluster of Suicide Deaths
Following a cluster of suicide deaths among U.S. Cyber Command personnel (with reports of deaths at NSA too), lawmakers are looking at the NDAA and upcoming funding bills to expand mental health support. Options include more access to cleared mental health providers, redefining suicide clusters to include civilian staff, and $11 million for Cyber Command's "High Performance Team Training" sustainment program. A DoD study mandated by the FY24 NDAA had already found support resources for the Cyber Mission Force inadequate, but no implementation plan has reached Congress. Former operators say the underlying issue is relentless op tempo with no defined rest cycles, and that more support resources don't fix a leadership and staffing problem.
Key Takeaways
- Burnout is a readiness risk, not just a wellness issue. That applies to every SOC and IR team, not only CYBERCOM.
- Look at your own team's on-call rotation, surge periods, and recovery time after major incidents.
- Normalize mental health support in security teams. If you or someone on your team is struggling, in the U.S. you can call or text 988 to reach the Suicide & Crisis Lifeline.












