# Threat Intel Brief — September 1, 2026

TL;DR

  • TerminalFix campaign uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands, deploying reverse-tunnel backdoors for persistent network access.
  • Chinese APT Fire Ant compromises Cisco IOS XR routers and TACACS servers, creating covert surveillance platforms and harvesting credentials across telecommunications infrastructure.
  • North Korean IT worker fraud expands beyond technology roles into healthcare and sales sectors, leveraging AI-assisted interviews to evade detection and generate sanctions-evasion revenue.
  • Aurora ransomware operators integrate AI coding assistants (Cursor) into attack planning, targeting organizations across nine countries with dual-platform (Windows/Linux) encryptors.
  • Berlin city administration confirms data theft following Rhysida ransomware attack, with threat actors claiming exfiltration of critical infrastructure assessments and classified government records.

---

Critical Threats

TerminalFix: Fake CAPTCHA Campaign Deploys Reverse Tunnels

What happened:
Microsoft disclosed a new ClickFix variant called TerminalFix that weaponizes fake Cloudflare CAPTCHA prompts on compromised websites. Victims are socially engineered into copying and executing malicious PowerShell commands via Windows Terminal or the Run dialog. The attack chain uses DLL sideloading (LockScreenContentServer.exe loading malicious dui70.dll), steganographic payloads embedded in PNG images, and establishes persistence through Registry Run keys and scheduled tasks. The final payload deploys a reverse-tunnel backdoor communicating with gitnow[.]dev:443 via encrypted WebSocket channels, enabling attackers to pivot through the victim's network and reach any host visible from the compromised endpoint.

Impact:
Organizations face high-risk exposure to persistent network-level proxy access. Attackers gain comprehensive Active Directory reconnaissance capabilities, privilege escalation paths, lateral movement opportunities, and data exfiltration channels. The reverse tunnel allows arbitrary TCP traffic to be routed through the victim's network, effectively turning compromised endpoints into internal proxies for further exploitation. The attack bypasses traditional email security controls by leveraging compromised websites and user interaction rather than phishing messages.

Recommendations:

  • Restrict PowerShell and Windows Run dialog execution for standard users via AppLocker or Application Control for Windows (0-24h).
  • Enable PowerShell script block logging (Event ID 4104) and monitor for obfuscated or encoded commands, particularly multi-line scripts (0-24h).
  • Block or monitor access to known malicious domains: bestsocialmedianewspapper[.]com, offlineupdater[.]com, gitnow[.]dev (0-24h).
  • Monitor for DLL sideloading indicators, specifically LockScreenContentServer.exe loading suspicious dui70.dll files outside legitimate system paths (24-72h).
  • Train users to recognize fake CAPTCHA prompts requesting PowerShell command execution and establish reporting procedures for suspicious website behavior (this week).

---

Fire Ant: Chinese APT Hijacks Cisco Routers for Espionage

What happened:
China-linked threat actor Fire Ant has expanded its cyber espionage campaign to compromise Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. The actor deploys custom malware that creates unexplained GRE tunnel interfaces on routers, modifies system libraries to suppress security logs, and harvests credentials from TACACS+ authentication flows using a novel library-injection technique (TacTap). The group also deploys BridgeAgent, a previously undocumented Linux backdoor masquerading as a Zabbix monitoring agent. Fire Ant captures network traffic from multiple routers and exfiltrates PCAP files to external FTP servers, exposing internal topology, authentication flows, and routing relationships. The campaign represents an evolution from the actor's previous VMware hypervisor targeting and demonstrates a "target behind the target" strategy—compromising trusted infrastructure to explore paths into connected high-value environments.

Impact:
Compromised routers become covert surveillance platforms providing visibility into encrypted traffic metadata, routing relationships, and authentication flows. Attackers gain the ability to manipulate network telemetry, suppress security logs, and maintain persistent access that is difficult to detect through traditional endpoint monitoring. The systematic harvesting of TACACS credentials enables lateral movement across network infrastructure and facilitates further compromise of administrative systems. Organizations relying on Cisco routing infrastructure and TACACS-based authentication face exposure to long-term espionage and potential pre-positioning for future disruptive operations.

Recommendations:

  • Monitor Cisco IOS XR routers for active GRE tunnel interfaces that do not correspond to running configurations or commit history; automate configuration drift detection (0-24h).
  • Implement out-of-band logging for network infrastructure devices to external SIEM platforms that attackers cannot tamper with from compromised devices (24-72h).
  • Detect systemd services masquerading as legitimate monitoring agents (e.g., Zabbix) by validating service binaries against known-good hashes and inspecting services with unusual execution patterns (24-72h).
  • Monitor for outbound Telnet connections from network infrastructure devices and block this protocol where not explicitly required; baseline normal FTP upload behavior from routers (this week).
  • Implement integrity monitoring for TACACS+ server binaries (tac_plus daemon) and system libraries, detecting unauthorized processes like acppid or suspicious library injections into authentication processes (this week).

---

Malicious Browser Extensions Steal Crypto and Credentials

What happened:
Nineteen malicious Chrome and Edge extensions deployed a modular malware framework capable of stealing cryptocurrency, credentials, browser history, and injecting ClickFix social engineering attacks. The campaign affected over 80,000 users, with the most popular extension ("Enable Right Click & Copy") installed by 70,000+ Chrome users and 10,000+ Edge users. Five extensions were legitimate but later compromised via malicious updates. The framework delivered encrypted JavaScript modules via WebSocket C2 connections, removed Content Security Policy headers, and injected scripts into websites. Attackers targeted cryptocurrency wallets (EVM, Solana, Tron) and session tokens from major exchanges (Coinbase, Binance, Kraken, OKX, MEXC, KuCoin, Bybit, MetaMask), deployed seed phrase phishing via fake Ledger/Trezor pages, and exfiltrated browser history.

Impact:
Users face credential theft across all websites, cryptocurrency wallet draining, session hijacking from financial services, and exposure to secondary ClickFix attacks. Organizations face credential compromise, financial loss, and potential lateral movement if corporate accounts were accessed from affected browsers. The modular framework indicates ongoing payload development and suggests attackers can rapidly deploy new capabilities to installed extensions.

Recommendations:

  • Audit all Chrome and Edge browser extensions across endpoints; remove any matching the extension IDs listed by Socket (see source for full list) (0-24h).
  • Force password resets for users who installed affected extensions; prioritize accounts for financial services, cryptocurrency exchanges, and corporate SSO (0-24h).
  • Instruct cryptocurrency holders to immediately transfer assets to newly created wallets with fresh seed phrases; treat existing wallets as compromised (0-24h).
  • Review network logs for WebSocket connections to C2 domains listed in Socket's report; investigate any matches for scope of compromise (24-72h).
  • Deploy browser extension whitelisting via Group Policy (Chrome) or Intune (Edge) to prevent installation of unapproved extensions (this week).

---

Threat Actor Activity

North Korean IT Worker Fraud Expands Into Healthcare and Sales

North Korean state-sponsored actors (tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267, and Wagemole) have expanded their fraudulent employment scheme beyond IT roles into healthcare, sales, marketing, and financial services sectors. The campaign uses stolen or forged identity documents, AI-generated personas, VPNs, proxy services, and KVM switches (PiKVM, TinyPilot) to mask operators' true identity and location. Actors leverage ChatGPT and AI transcription tools to generate real-time interview responses and coordinate via Telegram and Slack. The PurpleDelta cluster alone applied to jobs at over 1,100 companies between late 2024 and early 2025, with at least 60 applications per day across 10 job platforms. Documented cases include an Australian healthcare company (February 2026), a sales/marketing hire (August 2026), and a financial services firm. The scheme generates revenue for the DPRK's nuclear weapons and ballistic missile programs under international sanctions.

Defensive priorities:

  • Implement rigorous identity verification during recruitment including video interviews with spontaneous questions that cannot be answered via AI chatbots.
  • Monitor for anomalous VPN and proxy usage patterns during onboarding and employment, particularly connections through Astrill VPN or IPRoyal Proxy.
  • Detect unauthorized KVM devices (PiKVM, TinyPilot) and USB capture cards (Guermok) through endpoint detection tools and USB device whitelisting.
  • Flag suspicious document anomalies in identity verification including word processing errors in bills/proof of residence and passport similarities between multiple candidates.

---

Aurora Ransomware Operators Leverage AI Coding Assistant

Aurora (aka Aur0ra) ransomware operators, a Russian-speaking cybercrime group, have been observed using Cursor, an AI-powered coding assistant, to conduct attacks against organizations across nine countries. CloudSEK and Gambit Security discovered the group's exposed infrastructure revealing shell history, encryptor binaries, and evidence of Cursor usage between April 8 and May 21, 2026. The group operates a ransomware-as-a-service model with affiliates receiving 54-79% revenue splits. Initial access is achieved via social engineering combining aggressive email bombing with vishing attacks (posing as IT help desk). Post-compromise activities include NTLM relay attacks using PetitPotam, Coerce Plus, and PrinterBug, Active Directory Certificate Services exploitation, and deployment of dual-platform (Windows/Linux) encryptors written in Zig. The group has targeted over 33 organizations across the United States, Germany, Netherlands, Canada, United Kingdom, Argentina, and Italy, affecting manufacturing, chemical/industrial services, construction, maritime certification, real estate, and pharmaceutical distribution sectors. The group deliberately excludes CIS-country domains and IP ranges from targeting.

Defensive priorities:

  • Monitor for anomalous email volume spikes followed by unusual IT help desk calls; implement out-of-band verification procedures for remote access requests.
  • Deploy enhanced logging and alerting for NTLM relay attack indicators, including PetitPotam (MS-EFSRPC), PrinterBug (MS-RPRN), and Coerce Plus exploitation attempts.
  • Implement detection for Active Directory Certificate Services exploitation patterns using tools like Certipy; audit certificate templates for ESC1-ESC8 misconfigurations.
  • Detect volume shadow copy deletion (vssadmin.exe, wmic.exe) and Registry modifications to System Restore settings; on ESXi environments, alert on mass VM termination commands.

---

Spring Ring Campaign Weaponizes Microsoft Teams for Vishing

Spring Ring is a coordinated social engineering campaign active between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel. The operation targeted more than 150 employees across at least 10 companies in various industries. Attackers create personas using professional display names like "help desk" or "IT assistance" to establish trust, then transition from Teams chat to voice calls (vishing) to manipulate victims into executing payloads. The campaign delivers remote monitoring and management tools or custom malware, and in advanced variants, pivots to NTLM relay attacks using tools like PetitPotam to target domain controllers for domain-level privilege escalation. The campaign exploits Microsoft Teams' "Chat with Anyone" feature to bypass traditional email security controls. According to KnowBe4's Phishing Threat Trends Report, Teams-based attacks rose by 41% between October 2025 and March 2026.

Defensive priorities:

  • Monitor and restrict Microsoft Teams external access settings, particularly the "Chat with Anyone" feature, to prevent unsolicited external chat requests from unknown domains.
  • Deploy detection rules for suspicious Microsoft Teams chat creation patterns, especially those involving external identities with IT support-themed display names.
  • Implement network monitoring for NTLM relay attack indicators, particularly PetitPotam exploitation attempts targeting domain controllers; enforce NTLM relay protections such as SMB signing and LDAP channel binding.
  • Establish user awareness training focused on vishing techniques via collaboration platforms, emphasizing verification procedures for IT support requests that involve executing software or providing credentials.

---

Silver Fox Distributes ValleyRAT via Signed Chinese Adware

Threat actor Silver Fox has been distributing the ValleyRAT backdoor (also tracked as Winos 4.0) disguised as signed Chinese adware, specifically masquerading as QN Wallpaper, a legitimate desktop-wallpaper tool. The campaign leverages DLL sideloading by planting a malicious libcef.dll alongside the legitimate, signed QnWallpaper.exe executable. The malware achieves persistence through registry autorun entries, disables Windows Defender via the DisableAntiSpyware registry key, and uses runas for privilege escalation when initial execution lacks privileges. ValleyRAT establishes full remote control capabilities including keylogging, clipboard monitoring, and screen capture. The malware can flag itself as a critical process to prevent termination, triggering a blue screen if removal is attempted. Kaspersky recorded over 100,000 ValleyRAT detections affecting more than 1,500 unique users in 2026, with victims concentrated primarily in China and India. Previous Silver Fox campaigns have targeted a Japanese manufacturer and organizations in India and Russia through tax-themed lures.

Defensive priorities:

  • Monitor for DLL sideloading by detecting unsigned or suspicious DLLs loaded by signed executables, particularly libcef.dll in non-browser contexts.
  • Alert on registry modifications to DisableAntiSpyware key (HKLM\SOFTWARE\Policies\Microsoft\Windows Defender) and block unauthorized changes to security software settings.
  • Implement application control policies to prevent execution of software from untrusted sources and prohibit adding third-party applications to antivirus exclusion lists.
  • Monitor network connections to known C2 infrastructure: 103.45.66.18 (ports 441-443) and 192.253.225.173 (ports 6666, 8888).

---

Rhysida Ransomware Attacks Berlin City Administration

Berlin's city administration confirmed a data theft following a Rhysida ransomware attack, with the threat actors listing the city on their data leak site and attempting extortion. The breach, discovered in mid-August 2026, reportedly compromised 5.79 TB of sensitive government data (approximately 1.44 million files) exfiltrated between August 7-12, 2026. Stolen data included plaintext credentials, database accounts, password vaults, SQL database dumps, personnel files, financial records, and critical infrastructure assessments (Berlin water supply security data). The attackers also claimed exfiltration of Bundesrat committee records and classified government material. Berlin refused to pay the reported ransom demand, aligning with German federal policy discouraging payments to criminal actors. Rhysida is a ransomware-as-a-service operation active since mid-2023, conducting double-extortion attacks against high-value targets including healthcare organizations, state and local governments, educational institutions, and critical infrastructure operators. The group leverages regulatory pressure (such as GDPR violations) to coerce payment.

Defensive priorities:

  • Implement robust credential hygiene and enforce multi-factor authentication across all administrative and privileged accounts, particularly given Rhysida's exfiltration of plaintext credentials and password vaults.
  • Deploy network segmentation to isolate sensitive departmental networks and implement egress filtering with data loss prevention to detect and block large-scale exfiltration attempts.
  • Monitor for anomalous authentication patterns and lateral movement using EDR/XDR solutions, focusing on detection of credential dumping and unusual data access volumes over short timeframes.
  • Establish offline, immutable backups with regular restoration testing to enable recovery without ransom payment.

---

Chinese QTFY Group Targets U.S. Federal Agencies

The U.S. Department of Justice corrected a previous statement regarding Chinese threat actor attacks, clarifying that multiple U.S. federal agencies including NASA, the Federal Reserve, Department of Energy, and Department of Justice were targeted rather than being victims of successful breaches. QTFY (also known as QT and QTCYBER) is a Chinese state-sponsored threat actor active since 2018, operating on behalf of Nanjing Xinjiuwei Network Technology Co. with evidence of payments from China's Ministry of State Security. The group functions as a technical quartermaster, providing reconnaissance, proxy management, and operational routing capabilities to facilitate Chinese cyber espionage operations. QTFY employs vulnerability scanning and exploitation via QScan platform, targeting known CVEs such as CVE-2019-11510 (Pulse Secure VPN). The group creates decentralized IoT botnets through compromised devices and leased VPS infrastructure, utilizing QTRouter as an obfuscation network. The FBI disrupted QTFY infrastructure in 2026 by seizing domains connected to QScan and QTRouter (qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com).

Defensive priorities:

  • Monitor for exploitation attempts against known vulnerabilities in VPN appliances and IoT devices, particularly CVE-2019-11510 and similar remote access flaws.
  • Implement network segmentation and anomalous traffic analysis to detect lateral movement from compromised IoT devices within trusted network zones.
  • Block known QTFY infrastructure domains (qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com) and monitor for connections to Chinese commercial proxy services like fastlink[.]ws.
  • Harden IoT device security through firmware updates, credential management, and network isolation to prevent botnet enrollment in QTRouter infrastructure.

---

Geopolitical Context

China-Linked Infrastructure Targeting Escalates

Chinese state-sponsored actors continue to demonstrate strategic interest in network infrastructure and critical systems. The Fire Ant campaign's pivot from VMware hypervisors to Cisco routers and TACACS servers represents a tactical evolution toward deeper, more persistent access that is harder to detect and remediate. The "target behind the target" methodology—compromising trusted infrastructure to explore paths into connected high-value environments—aligns with long-standing Chinese intelligence collection priorities: mapping trusted network relationships, understanding critical infrastructure interdependencies, and establishing pre-positioned access for potential future operations. The DoJ's correction regarding targeted versus compromised U.S. federal agencies suggests that while QTFY conducted reconnaissance and exploitation attempts against high-value networks, the actual compromise rate may have been lower than initially conveyed. This distinction is critical in assessing both the effectiveness of U.S. defensive posture and the operational success of Chinese state-sponsored activity.

North Korean Sanctions Evasion Through IT Worker Fraud

The DPRK's expansion of fraudulent employment operations into healthcare and sales sectors demonstrates operational maturation and diversification of both revenue streams and potential access to sensitive data across critical infrastructure. The integration of AI-assisted interview techniques and identity-brokering services reflects increasing sophistication in tradecraft. The suspected China-based operational infrastructure complicates attribution and enforcement efforts, as operators benefit from jurisdictional ambiguity and limited bilateral cooperation on sanctions enforcement. The scheme directly supports Pyongyang's efforts to evade international sanctions by generating foreign currency to fund its nuclear weapons and ballistic missile programs—activities prohibited under multiple UN Security Council resolutions.

Russian Cybercrime Ecosystem Adapts AI Tools

The Aurora ransomware operation's integration of commercial AI tools (Cursor, powered by Anthropic's Claude) into offensive cyber operations represents an evolution in cybercriminal tradecraft. The group's systematic exclusion of CIS targets—a hallmark of Russia-based cybercrime groups operating under tacit state tolerance—suggests adherence to informal boundaries that have historically allowed such actors to operate with relative impunity within Russian jurisdiction. The campaign's targeting of Western entities across the U.S., Germany, Netherlands, Canada, and the U.K. aligns with established patterns of Russia-nexus cybercrime that disproportionately affects NATO member states and their economic infrastructure. The revelation that AI coding assistants can be weaponized for Active Directory exploitation, lateral movement, and infrastructure reconnaissance may prompt regulatory responses from the EU's AI Act enforcement bodies.

---

Recommended Actions

Immediate (0-24 hours)

  • TerminalFix response: Restrict PowerShell execution for standard users, enable script block logging (Event ID 4104), and block access to known malicious domains (bestsocialmedianewspapper[.]com, offlineupdater[.]com, gitnow[.]dev).
  • Browser extension audit: Remove all Chrome/Edge extensions matching the malicious extension IDs disclosed by Socket; force password resets for users who installed affected extensions; instruct cryptocurrency holders to transfer assets to newly created wallets.
  • Fire Ant detection: Monitor Cisco IOS XR routers for unauthorized GRE tunnel interfaces and configuration anomalies without commit history; implement out-of-band logging for network infrastructure devices.

Near-term (24-72 hours)

  • TACACS security: Implement integrity monitoring for TACACS+ server binaries and system libraries; detect unauthorized processes like acppid or suspicious library injections into authentication processes.
  • NTLM relay defenses: Deploy enhanced logging and alerting for PetitPotam, PrinterBug, and Coerce Plus exploitation attempts; enforce SMB signing and LDAP channel binding.
  • DLL sideloading detection: Monitor for LockScreenContentServer.exe executing outside legitimate paths and unsigned DLLs loaded by signed executables, particularly libcef.dll in non-browser contexts.

This week

  • Microsoft Teams security: Restrict external access settings, particularly the "Chat with Anyone" feature; deploy detection rules for suspicious external chat creation patterns with IT support-themed display names.
  • North Korean IT worker fraud: Implement rigorous identity verification during recruitment including video interviews with spontaneous questions; monitor for anomalous VPN and proxy usage patterns (Astrill VPN, IPRoyal Proxy).
  • AD CS hardening: Audit Active Directory Certificate Services templates for ESC1-ESC8 misconfigurations; implement detection for Certipy exploitation patterns.
  • IoT security: Harden IoT device security through firmware updates, credential management, and network isolation to prevent botnet enrollment; block known QTFY infrastructure domains.

---

Watch List

  • TerminalFix evolution: Monitor for additional fake CAPTCHA campaigns leveraging Windows Terminal or PowerShell; track new C2 infrastructure beyond gitnow[.]dev.
  • Fire Ant expansion: Watch for similar router-targeting tactics adopted by other Chinese APT groups; monitor for BridgeAgent backdoor deployment using Sygnia's published YARA rules.
  • AI-assisted attacks: Track adoption of AI coding assistants (Cursor, GitHub Copilot) by other ransomware operators; assess whether AI model providers implement safeguards against malicious use cases.
  • North Korean job fraud: Monitor for expansion into additional sectors beyond healthcare and sales; track new identity-brokering services and KVM device usage patterns.
  • Rhysida data publication: Watch for Berlin data appearing on leak sites; assess secondary exploitation by other criminal actors if data is published.

---

Sources

  • BleepingComputer: [Microsoft warns of TerminalFix attacks deploying reverse tunnels](https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/)
  • BleepingComputer: [Chrome Web Store extensions caught stealing crypto, browser data](https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/)
  • BleepingComputer: [Chinese Fire Ant hackers turn Cisco routers into spying platforms](https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/)
  • BleepingComputer: [Berlin confirms data theft after Rhysida ransomware attack claims](https://www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/)
  • BleepingComputer: [FulcrumSec claims Manchester Airports hack, theft of 86 GB of data](https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/)
  • BleepingComputer: [Nigerians extradited to US for sextortion, deaths of two teens](https://www.bleepingcomputer.com/news/security/nigerians-charged-US-over-sextortion-deaths-of-us-teens/)
  • The Hacker News: [TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor](https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html)
  • The Hacker News: [North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales](https://thehackernews.com/2026/08/north-korean-job-fraud-expands-beyond.html)
  • The Hacker News: [ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions](https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html)
  • The Hacker News: [Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets](https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html)
  • The Hacker News: [China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs](https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html)
  • The Hacker News: [DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims](https://thehackernews.com/2026/08/doj-corrects-china-hacking-claim-says.html)
  • Unit 42 (Palo Alto): [Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)