CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (6 May 2026)

Published: Loading…

At a Glance

  • InstallFix campaign spreads malware via fake Claude AI installer pages using Google Ads, executing PowerShell commands and deploying multi-stage payloads with AMSI bypass and persistence.
  • Weaver E-cology CVE-2026-22679 and MetInfo CMS CVE-2026-29014 are actively exploited for unauthenticated remote code execution via crafted requests and debug API abuse.
  • ScarCruft compromised a Yanbian gaming platform in a supply chain attack, delivering BirdCall and RokRAT malware targeting Android and Windows users for espionage.
  • Apache HTTP Server CVE-2026-23918 double-free flaw enables denial-of-service and potential remote code execution via crafted HTTP/2 frame sequences in mod_http2.
  • UAT-8302 China-nexus APT targets government entities using NetDraft, CloudSorcerer and SNOWRUST malware with credential harvesting, lateral movement, and persistence techniques.
  • DAEMON Tools installers were trojanised in a supply chain attack, distributing signed malicious binaries that establish persistence and retrieve payloads from command-and-control servers.

Summary

Malware delivery increasingly leveraged malvertising and social engineering campaigns, with the InstallFix operation distributing payloads through fake Claude AI installer pages promoted via Google Ads. Victims executed malicious PowerShell commands that triggered mshta-based loaders, AMSI bypass, and staged payload retrieval from attacker infrastructure. A parallel phishing campaign impersonated the US Social Security Administration deployed signed remote monitoring tools to establish persistence and continuous surveillance across compromised systems.

Multiple remote code execution vulnerabilities saw active exploitation across widely deployed platforms, including Weaver E-cology CVE-2026-22679 and MetInfo CMS CVE-2026-29014. Both flaws enable unauthenticated attackers to execute arbitrary commands via crafted requests, with observed exploitation involving PowerShell loaders and automated scanning of exposed systems. Apache HTTP Server CVE-2026-23918 introduced a double-free flaw in HTTP/2 handling that can trigger denial-of-service conditions and potential remote code execution in default configurations.

Supply chain attacks continued to affect both software distribution and development ecosystems, with DAEMON Tools installers trojanised to deliver persistent malware through signed binaries distributed via official channels. A separate compromise of a Yanbian gaming platform enabled ScarCruft to distribute BirdCall and RokRAT backdoors across Android and Windows environments, targeting users for espionage data collection. Additional activity involving compromised CI pipelines demonstrated credential exfiltration from Jenkins and AWS environments through malicious GitHub pull request workflows.

State-linked threat activity remained active, with UAT-8302 conducting intrusions against government entities across South America and southeastern Europe using multiple malware families including NetDraft and CloudSorcerer. Post-compromise actions involved credential harvesting, lateral movement, and network reconnaissance using PowerShell scripts, Impacket tooling, and scheduled tasks. Overlapping toolsets with other China-aligned clusters included SNOWLIGHT and SNOWRUST loaders, indicating shared development or operational resources.

Mobile and cross-device threats expanded with new malware capabilities and vulnerabilities, including CloudZ RAT abusing Microsoft Phone Link to intercept SMS and one-time passwords without infecting mobile devices directly. WhatsApp disclosed vulnerabilities affecting Windows, Android, and iOS that enable file spoofing and arbitrary URL handling through crafted messages and attachments. Separately, the DarkSword exploit chain leveraged multiple iOS zero-day vulnerabilities to deploy surveillance malware across targeted regions using full-chain compromise techniques.

Highlights of the Day

Germany advances AI biometric facial recognition policing laws

Germany’s federal cabinet has advanced a legislative package allowing law enforcement automated biometric image matching of publicly available internet data using AI systems, enabling police to upload facial images and search the internet for matching depictions, replacing manual searches of online sources. Civil society organisations and some lawmakers oppose the measures over mass surveillance and privacy risks, while noyb has filed a lawsuit against the Hamburg data protection authority over alleged failure to enforce EU rules against the PimEyes facial recognition search engine despite an earlier illegality ruling.

Source: The Record

Weaver E-cology RCE exploited via debug API flaw

CVE-2026-22679 affects Weaver E-cology 10.0 and enables unauthenticated remote code execution through the /papi/esearch/data/devops/dubboApi/debug/method endpoint using crafted POST parameters interfaceName and methodName fields. Attackers exploited the flaw for remote command execution, deploying PowerShell loaders, MSI payload fanwei0324.msi, and running discovery commands including whoami, ipconfig, tasklist. Vega Research Team identified exploitation from 17 March 2026, earlier than Shadowserver reporting on 31 March, with activity spanning post-patch targeting.

WhatsApp discloses Windows file spoofing and URL handling flaws

WhatsApp has disclosed CVE-2026-23863 affecting Windows and CVE-2026-23866 affecting iOS and Android, introducing attachment spoofing and arbitrary URL processing issues in 2026 advisories. Windows flaw allows malicious attachments with embedded NUL bytes in filenames to appear as benign files but execute when opened in WhatsApp application. iOS and Android issue involves incomplete validation of AI rich response messages for Instagram Reels, enabling arbitrary URL processing and OS URL scheme triggering.

ScarCruft supply chain attack compromises Yanbian gaming platform

ESET Research identified a ScarCruft supply-chain attack compromising a Yanbian gaming platform, trojanising Windows and Android games with RokRAT and BirdCall backdoors. The Android BirdCall variant in trojanised APKs collects contacts, SMS, call logs, files, screenshots and audio, exfiltrating data via cloud storage C2 channels. Windows infection chain used malicious updates and mono.dll trojanisation delivering RokRAT and BirdCall, targeting Yanbian users for espionage since late 2024 campaign.

UAT-8302 APT deploys multi-family malware in global intrusions

Cisco Talos disclosed UAT-8302, a China-nexus APT targeting government entities in South America and southeastern Europe, deploying NetDraft, CloudSorcerer v3 and VSHELL. Post-compromise activity included information collection, credential extraction and network proliferation using Impacket, PowerShell scripts, scheduled tasks and reconnaissance commands across infected endpoints. Tooling overlap with other China-nexus clusters included Draculoader, SNOWLIGHT, SNOWRUST and ZingDoor, alongside proxying tools, AD enumeration, and credential harvesting capabilities.

MetInfo CMS RCE flaw actively exploited in attacks

MetInfo CMS versions 7.9 through 8.1 are affected by CVE-2026-29014, an unauthenticated PHP code injection vulnerability in the Weixin reply component that enables remote code execution. The flaw resides in weixinreply.class.php where insufficient input sanitisation of WeChat API parameters allows path traversal and cache manipulation leading to arbitrary PHP execution on affected servers. Exploitation activity was observed following patch release in April 2026, with automated probing and increased targeting of exposed instances in China and Hong Kong.

Antrea Jenkins Compromised via GitHub Pwn Request Campaign

Antrea CNCF project was compromised through a GitHub pwn request campaign linked to TeamPCP Trivy supply-chain attack, extending access into Jenkins and AWS environments. Attackers used Jenkins slash-command triggered jobs from malicious pull request code to execute payloads that exfiltrated AWS credentials, SSH keys, and metadata via external endpoints. Activity involved throwaway GitHub accounts, iterative multi-project campaigns, spoofed CI identities, and exploitation of CI infrastructure including controller access and EC2 host 35.164.122.165 exposure.

AI Agent Skills Marketplace Exposes Supply Chain Attack Vectors

Orca Security research found attack primitives in AI agent skills marketplace enabling malicious skill distribution and persistence via install count inflation, weak scanning, silent overrides. Marketplace issues include unauthenticated telemetry install counts, non-continuous security scans, and skill name collisions allowing replacement of trusted skills and delayed malicious modifications. Demonstrations showed bait-and-switch, nested injection, and delayed update weaponisation achieving code execution on end-user systems via markdown-based skills executed by coding agents.

Dual RMM phishing campaign abuses signed remote access tools

An ongoing STAC6405 phishing campaign impersonates the US Social Security Administration and has targeted over 80 organisations since April 2025, deploying vendor-signed SimpleHelp 5.0.1 and ScreenConnect via compromised .com.mx infrastructure. The malware installs a Windows service with Safe Mode persistence and dual RMM channels, running automated surveillance loops including WMI queries, network checks and mouse-polling, and communicating with 84.200.205.233 and 213.136.71.246 plus a ScreenConnect relay domain.

Apache HTTP/2 flaw enables DoS and potential remote code execution

Apache HTTP Server 2.4.66 contains a critical HTTP/2 vulnerability tracked as CVE-2026-23918, a double-free flaw in mod_http2 that can trigger denial-of-service and potential remote code execution. The issue occurs when specific HEADERS and RST_STREAM frames are sent in sequence, causing duplicate cleanup of the same stream pointer and memory corruption during stream destruction. Researchers demonstrated a working RCE proof of concept using mmap allocator behaviour and Apache scoreboard memory, with exploitation affecting default deployments using multi-threaded MPM configurations and fixed in version 2.4.67.

Fake Claude Install Pages Spread Malware via Google Ads Campaign

The InstallFix campaign distributes malware through fake Claude AI installer pages promoted via Google Ads, targeting users who search for installation instructions and execute malicious PowerShell commands. The infection chain uses mshta.exe to run a ZIP/HTA polyglot payload, deploys obfuscated scripts, disables SSL validation and AMSI protections, and retrieves additional payloads from attacker-controlled infrastructure. Telemetry shows scheduled task creation for persistence and network communication with command-and-control servers, affecting organisations across multiple regions and sectors including government, education, and electronics.

Daily Coverage

Developments
Installfix MalvertisingWeaver Rce ExploitationScarcruft Supply ChainApache Http Flaw
Vulnerabilities
CVE-2026-0300Pan-Os 12.1.0 (Critical)CVE-2026-29014CVE-2026-22679E-Cology (Critical)CVE-2026-23918CVE-2026-23866CVE-2026-23863CVE-2026-44331Proftpd (High)CVE-2025-11083Binutils 2.45 (Medium)
Threat Groups
MuddyWater[Also known as: Static Kitten, Seedworm, Mango Sandstorm] MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.ScarCruftAPT37 is a North Korean statesponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 20162018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018. North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean statesponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.OceanLotusAPT32 is a suspected Vietnambased threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.