CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (26 May 2026)

Published: Loading…

At a Glance

  • Dutch authorities arrested two suspects and seized 800 servers linked to MIRhosting and WorkTitans supporting Russian cyber operations infrastructure.
  • TrapDoor supply chain campaign distributed credential-stealing malware through npm, PyPI, and Crates.io using 384 malicious package versions.
  • Lazarus Group deployed RemotePE memory-only RAT via DPAPILoader and RemotePELoader targeting financial and cryptocurrency organisations.
  • KnowledgeDeliver LMS CVE-2026-5426 enabled unauthenticated ViewState deserialization leading to BLUEBEAM web shell deployment and Cobalt Strike infections.
  • Chinese-language phishing services used RCS, iMessage and AI-generated pages to capture OTPs and hijack digital wallet provisioning globally.
  • Ghost CMS CVE-2026-26980 was exploited to inject JavaScript across 700+ websites, enabling ClickFix-driven malicious redirections.

Summary

Infrastructure disruption actions involved Dutch authorities seizing more than 800 servers and arresting operators tied to MIRhosting and WorkTitans. The infrastructure was linked to hosting services associated with Stark Industries and Russian-aligned cyber operations including distributed denial-of-service activity. Seized systems were connected to networks used in election-period attacks against Danish government entities.

Supply chain compromise activity intensified across multiple open-source ecosystems, with malicious packages distributed through npm, PyPI and Crates.io alongside large-scale GitHub repository infections. Attackers targeted CI/CD pipelines, injecting workflows designed to steal credentials, tokens and other build secrets from development environments. The activity included coordinated campaigns such as TrapDoor and Megalodon affecting thousands of software projects.

Nation-state-linked operations included Lazarus Group deployment of the RemotePE memory-only RAT using DPAPILoader and RemotePELoader across financial and cryptocurrency organisations. The malware chain used DPAPI-based encryption, ETW suppression and in-memory execution to avoid forensic detection. Command-and-control infrastructure relied on staged payload delivery and encrypted session-based communication channels.

Web application vulnerabilities included CVE-2026-5426 in KnowledgeDeliver LMS, caused by shared ASP.NET machine keys enabling ViewState deserialization attacks. The exploitation led to BLUEBEAM web shell deployment within IIS worker processes and subsequent delivery of Cobalt Strike BEACON payloads. Ghost CMS CVE-2026-26980 was also exploited to inject JavaScript across hundreds of compromised websites.

Phishing and social engineering operations expanded through Chinese-language phishing-as-a-service platforms leveraging RCS and iMessage channels for OTP interception. Attackers used AI-generated phishing pages and real-time administrative panels to hijack digital wallet provisioning and payment card tokenisation. Campaigns attributed to services such as Darcula targeted global users across financial and consumer platforms.

Highlights of the Day

Kali365 Steals Microsoft 365 Tokens Through Device Code Phishing

The FBI warned that the Kali365 phishing-as-a-service platform, first observed in April 2026 and distributed through Telegram, enables attackers to steal Microsoft 365 OAuth tokens and bypass multi-factor authentication. Kali365 campaigns send phishing emails containing device codes that direct victims to legitimate Microsoft verification pages, where entered codes authorise attacker-controlled devices to access accounts. The stolen access and refresh tokens provide persistent access to Microsoft 365 services including Outlook, Teams and OneDrive without requiring passwords or additional MFA prompts, while the platform also offers AI-generated phishing lures and real-time tracking dashboards.

Lazarus Deploys Memory-Only RemotePE Malware Chain

Fox-IT analysed a Lazarus-linked malware chain comprising DPAPILoader, RemotePELoader and RemotePE, which targets financial and cryptocurrency organisations using DPAPI encryption, reflective PE loading and fully memory-resident execution. RemotePELoader retrieves AES-GCM encrypted payloads from HTTP-based command-and-control servers, disables ETW logging, remaps clean ntdll.dll sections through HellsGate syscalls and polls operators for manually delivered malware stages. The final-stage RemotePE RAT supports file operations, process execution, plugin loading and secure file deletion, while using Microsoft-themed cookie fields and JSON keys to disguise command-and-control traffic on Namecheap-hosted infrastructure.

Source: Fox-IT

Dutch Police Seize Servers Linked to Russian Cyber Operations

Dutch financial crime investigators arrested two men and seized more than 800 servers during raids targeting MIRhosting and WorkTitans, companies accused of providing infrastructure to EU-sanctioned Russian entities. Authorities said the firms operated network infrastructure linked to Stark Industries, a hosting provider associated with distributed denial-of-service attacks, proxy services and cyber operations attributed to Russian intelligence groups. De Volkskrant reported that WorkTitans and MIRhosting networks were heavily used in pro-Russian attacks against Danish government organisations during Denmark’s municipal elections in November 2025.

KnowledgeDeliver Flaw Enables Remote Code Execution Attacks

Mandiant disclosed CVE-2026-5426, a critical unauthenticated remote code execution flaw in the KnowledgeDeliver learning management system caused by identical ASP.NET machine keys shared across customer deployments. Attackers exploited malicious ViewState deserialisation through the __VIEWSTATE parameter, deployed the BLUEBEAM in-memory web shell inside IIS worker processes and modified JavaScript files to load remote malicious scripts. Mandiant observed the compromised sites delivering fake security plugin installers that infected users with Cobalt Strike BEACON payloads encrypted using organisation-specific keys.

Chinese Phishing Platforms Target Digital Wallets Worldwide

Google Threat Intelligence Group analysed multiple Chinese-language phishing-as-a-service platforms that use Telegram, RCS and iMessage to deliver phishing campaigns targeting payment cards, digital wallets and account credentials across international markets. The services provide real-time interception panels that capture one-time passcodes, enabling attackers to provision stolen payment cards into attacker-controlled digital wallets for contactless payments and ATM withdrawals. Google linked the Darcula platform to UNC5814 and reported that operators increasingly use AI-generated phishing pages, browser automation tools and localised templates impersonating brands including Apple, Amazon, PayPay, Nintendo and Japanese financial institutions.

Daily Coverage

Developments
Trapdoor Supply ChainLazarus RemotepeDutch Server SeizuresKnowledgedeliver Rce
Vulnerabilities
CVE-2026-5426Knowledgedeliver (High)CVE-2026-45659Microsoft Sharepoint Enterprise Server 2016 16.0.0 (High)CVE-2026-34926CVE-2026-45695CVE-2025-62582Diaview (Critical)CVE-2026-26980CVE-2018-25368CVE-2026-31431Linux 72548B093Ee38A6D4F2A19E6Ef1948Ae05C181F7 (High)CVE-2026-43284Linux Cac2661C53F35Cbe651Bef9B07026A5A05Ab8Ce0CVE-2026-43500Linux D0D5C0Cd1E711C98703F3544C1E6Fc1372898De5
Threat Groups
Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.