domains

Winsage
September 9, 2026
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days. The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include: - APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone. - UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor. - UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary. - UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly. CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Winsage
September 4, 2026
Microsoft is addressing an issue (TM1466820) causing delays or preventing some users from accessing the Microsoft Teams desktop client on Windows systems, acknowledged on Thursday at 16:45 EDT. Affected users may experience loading failures or delays of up to two minutes and are advised to use the web or mobile versions of Teams as a temporary workaround. Microsoft is analyzing service logs and telemetry data to identify the root cause and has contacted some affected users for more information. Additionally, there is a separate issue (TM1466659) affecting Mac users, preventing them from joining Teams calls and meetings, confirmed on Sunday at 08:32 EDT. Microsoft is reassessing the cause of this disruption. Earlier this year, Microsoft resolved an issue blocking some Teams Free users from chats and calls. The company also confirmed a bug causing crashes and launch failures for Teams and New Outlook users after recent Windows security updates. Furthermore, there is an ongoing Exchange Online issue affecting multiple mailboxes, resulting in "Server busy" errors and delays in email communications with external domains.
AppWizard
September 3, 2026
The National Cybercrime Threat Analytics Unit (NCTAU) has reported a rise in financial fraud linked to deceptive Android applications that pose as pornography apps. These apps are advertised on social media platforms like Facebook and Instagram under names such as ‘Night Play’, ‘Reloop’, ‘Kyss’, ‘Vimo’, ‘Rivo’, ‘Nexo’, and ‘Vixa’. Users who click on these ads are redirected to websites promising adult content, where they are encouraged to download APK files. Once installed, these apps often request sensitive permissions, particularly Accessibility access, which can allow malware to take control of the device and facilitate financial fraud. Some malicious apps may also install a VPN, rerouting internet traffic through servers controlled by attackers and exposing sensitive data. The malware is primarily promoted through ads linked to pornographic content, redirecting users to phishing websites that prompt APK downloads from non-Google Play sources, often using the “.live” domain extension. After installation, the initial app may download a second malicious package disguised as an update, exploiting the permissions granted to the original app.
Winsage
September 2, 2026
An active malware campaign is using counterfeit software-download websites to distribute malicious installers, primarily targeting users seeking popular software. This campaign has significantly affected China-based operations of multinational corporations and Chinese-speaking users. The malware, once executed, can establish persistence, undermine security measures, and communicate with attacker-controlled infrastructure. Victims span various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft associates this campaign with a Chinese threat cluster called Silver Fox, known for using spoofed vendor download pages to spread Gh0st RAT and ValleyRAT. The malicious websites are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content. The downloaded files are dynamically generated, and upon execution, they deploy a wrapper installer that initiates the malware payload. The malware achieves persistence through scheduled tasks and interferes with Windows Update services. The campaign establishes command-and-control communication over non-standard ports, with two identified domains linked to the activity. Microsoft Defender has detected the threat and initiated containment procedures. Kaspersky reported a related malicious installer exploiting a legitimate adware application to execute a backdoor, which captures keystrokes and clipboard contents. ValleyRAT, a sophisticated implant, can collect system information, reboot the computer, capture screenshots, and transmit logs. The attackers are motivated by cyber espionage and financial gain, targeting organizations globally. A subgroup within GoldenEyeDog, known as CuboidalCanine, has also been linked to the use of ValleyRAT, particularly in the gambling industry. In June 2026, Chinese authorities addressed cybercrime cases involving a new variant of the Silver Fox trojan.
AppWizard
September 1, 2026
Cybercriminals are targeting Android users with deceptive advertisements for malicious applications disguised as pornographic content on platforms like Facebook and Instagram. The National Cybercrime Threat Analytics Unit (NCTAU) has reported that these ads lead users to phishing traps or malware downloads that can compromise banking credentials. Malicious applications linked to this threat include “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo,” and “Vixa.” The scam involves promoting these apps through enticing ads, redirecting users to websites offering pornographic content, and prompting them to download APK files directly from these sites, often using “.live” domains. The initial app may request users to download a second package disguised as an update, which can exploit permissions granted to the first app. This malware can gain extensive control over the device, potentially installing a VPN that routes internet traffic through attackers' servers. To protect against this threat, users should download apps only from trusted sources, avoid installing APK files from ads or suspicious links, refrain from granting Accessibility access to unknown apps, regularly review installed apps, keep Google Play Protect enabled, and monitor bank accounts for unusual activity. If a suspicious app cannot be uninstalled, users can try Safe Mode, remove special permissions, or perform a factory reset as a last resort.
Search