Threat activity stayed busy in early August, with ransomware crews pushing sharper extortion tactics, cloud-aware espionage groups refining their stealth, and a wave of edge-device and management-tool exploits giving attackers quick footholds. Botnets and stealers kept expanding through unpatched IoT and browser weaknesses, while social-engineering-driven mobile fraud added a fresh twist. Overall, fast patching, tighter access controls, and closer log scrutiny mattered more than ever as actors shifted tools and targets with little warning.
Report Links
Download Threat Brief For August 1-15 2026
Byer-Nichols Threat Brief Podcast August 1-15 2026
Ransomware Actors
| Ransomware | Percentage | Last Period | Two Ago |
|---|---|---|---|
| Qilin | 12.89% | 2 | 1 |
| The Gentlemen | 11.72% | 1 | 2 |
| CL0P | 8.79% | 56 | N/A |
| OROVA | 7.03% | N/A | N/A |
| INC Ransom | 3.91% | 5 | 4 |
Qilin leads with steady activity and aggressive leak-site pressure, while The Gentlemen keep up their quick, opportunistic hits. CL0P remains influential despite lower numbers, shifting to selective high-value targets after its earlier mass-impact campaigns. Newcomer OROVA is the standout, experimenting with fresh infrastructure and extortion tactics. INC Ransom continues its consistent mid-tier operations, often hitting environments where downtime hurts most.
Victim Sector
| Sector | Percentage | Last Period | Movement |
|---|---|---|---|
| Manufacturing | 17.77% | 1 | same |
| Technology | 11.00% | 4 | 4 -> 2 |
| Retail | 14.54% | 2 | 2 -> 3 |
| Construction | 11.20% | 3 | 3 -> 4 |
| Financial Services | 11.00% | 5 | same |
Victim Location
| Victim | Percentage | Last Period | Movement |
|---|---|---|---|
| USA | 45.31% | 1 | same |
| Canada | 4.69% | 2 | same |
| Italy | 4.10% | new | new |
| Germany | 2.93% | 3 | 3 -> 4 |
| UK | 2.93% | 5 | 5 -> 4 |
Victim Org Size
| Size | Percentage | Last Period | Change |
|---|---|---|---|
| Small Business (500 or less) | 73.28% | 80.16% | -6.8% |
| Mid-Market (501-5000) | 17.49% | 12.38% | +5.11% |
| Large Enterprise (5000+) | 9.23% | 7.47% | +1.76% |
Trending Adversaries
Armored Likho, GOLD EMBRACE, Head Mare, HoneyMyte, Jewelbug, and UNC6671 all lean heavily on stealthy, long-game intrusions, blending custom loaders, living-off-the-land tactics, and tight targeting of government or tech sectors. Several are refining cloud-focused tradecraft, while others push sharper social-engineering lures and cleaner post-exploitation workflows. Jewelbug and HoneyMyte stand out for disciplined espionage operations, but UNC6671 is the most concerning thanks to its rapid tooling shifts and willingness to pivot quickly across victim environments, making detection and containment tougher for defenders.
- Armored Likho
- GOLD EMBRACE
- Head Mare
- HoneyMyte
- Jewelbug
- UNC6671
Trending & Actively Exploited Vulnerabilities
Attackers are leaning hard on edge and management gear this fortnight, with Cisco ASA/FTD, Metabase, LoadMaster, TeamCity, N-central, and Tomcat bugs all seeing active exploitation for remote code execution and lateral movement. Windows WinSock and ShieldBreak engine flaws add a nasty client and AV angle, turning everyday endpoints into launchpads. Langflow exposure raises AI-service and data-leak risk. Priority moves: patch fast, lock down internet-facing admin portals, enforce strong auth, and watch logs and IPS for odd config changes and new services spinning up.
| CVE | Vendor | Product |
|---|---|---|
| CVE-2026-20349 | Cisco | Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) |
| CVE-2026-68820 | Microsoft | Windows Ancillary Function Driver for WinSock |
| CVE-2026-72898 | Metabase | Metabase |
| CVE-2026-8037 | Progress | LoadMaster |
| CVE-2026-63077 | JetBrains | TeamCity |
| CVE-2026-18556 | N-able | N-central |
| CVE-2026-34486 | Apache | Tomcat |
| CVE-2026-9198 | IBM | Langflow |
| CVE-2026-18577 | N-able | N-central |
| CVE-2026-69414 | Microsoft | Microsoft Malware Protection Engine (aka ShieldBreak) |
Trending Malware
| Trending Malware | Details |
|---|---|
| AmnesiaStealer | AmnesiaStealer targets Chromium-based browsers, injecting itself into the browser environment to monitor and hijack active sessions. It focuses on harvesting passwords, cookies, and authentication tokens, giving attackers direct access to webmail, SaaS, and banking portals without needing to re-authenticate. The stealer also exfiltrates browser configuration and autofill data, making it easier to replay victim identities at scale. Overall, it turns everyday browsing into a high-value data source for credential theft campaigns. |
| CHAINDROP | CHAINDROP spreads through infected npm packages, adding a subtle preinstall hook and obfuscated payload that most developers won’t notice during routine installs. Once running, it aggressively harvests cloud credentials, GitHub and npm tokens, SSH keys, and other developer secrets, then uses those tokens to republish compromised versions of legitimate packages while preserving their functionality. It resolves its C2 via an Ethereum smart contract, allowing operators to rotate domains without updating the malware. The result is a durable supply-chain threat that can persist in CI pipelines, caches, and lockfiles long after a package is “fixed.” |
| DeadLock | DeadLock uses a Rust encryptor with intermittent, resource-throttled file locking so victim systems stay responsive while data is quietly encrypted, reducing early detection. It combines XChaCha20 file encryption with modern key-wrapping schemes and per-file keys, making recovery without the attacker’s keys extremely difficult. Instead of traditional Tor sites, DeadLock stores negotiation and leak-site configuration on Polygon smart contracts and uses decentralized messaging for victim communications. This architecture, plus geofencing to avoid CIS and select regions, gives the operation strong resilience against infrastructure seizure and law-enforcement disruption. |
| Evooo1Bot | Evooo1Bot reuses Mirai’s DDoS engine but extends it with encrypted C2, layered string obfuscation, and a rich command set for remote administration. It spreads by exploiting numerous known vulnerabilities in routers, cameras, industrial controllers, and other Internet-facing devices, then installs persistence via systemd, cron, init scripts, and login profiles. Once established, operators can launch multi-vector DDoS attacks, brute-force SSH, sniff credentials, and convert victims into SOCKS proxies for stealthy traffic relaying. Its CVE exploit module lets attackers rapidly sweep exposed infrastructure, making unpatched edge devices prime entry points into enterprise networks. |
| Kimwolf v7 | Kimwolf v7 focuses on Android-based IoT devices such as TV boxes and signage, typically compromised via exposed ADB interfaces and weakly managed firmware. The new version drops scanning and exploit modules, relying on external loaders, and concentrates on resilient C2 and sophisticated DDoS capabilities. It resolves C2 addresses via Ethereum Name Service, with a hard-coded Tor .onion fallback and local proxy routing, making traditional DNS-based blocking far less effective. For impact, it crafts HTTP/2 floods with realistic Chrome-style fingerprints, multiplexed streams, and plausible headers, so attack traffic blends into normal web sessions and can slip past conventional WAF and rate-limit rules. |
| WindRelay | WindRelay is deployed alongside the SpyNote remote-access trojan in phone-based social-engineering scams where attackers impersonate banks and walk victims through sideloading a “support” app. SpyNote provides remote control and Accessibility access, allowing the attacker to silently install WindRelay and operate the victim’s banking app, even taking out loans in their name. WindRelay then uses the phone’s NFC interface to read the victim’s physical payment card when they tap it against the device, streaming EMV commands and responses in real time to an emulator on the attacker’s side. This ghost-tap setup lets criminals perform contactless purchases or ATM withdrawals while the victim still holds their card, making the fraud both fast and hard to spot until transactions appear. |
Top News
- Device Code Phishing Up 1,500% in 2026
- White House taps security firms for offensive hack-back operations
- Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
- Flaws in Google APK for Python Unlock Agent-to-Agent
- Attack AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
- Multistate Water System Attacks Widen, Iran Suspected
- Hackers arrested over €30M bank fraud exploiting service provider flaw
- Belgium's eID Authentication Opens Citizen Accounts to RCE
Contributors
Written by Jeremy Nichols, Director, Security Programs & Strategy at SecureSky Executive Summaries & Adversary Bio's by Geoff Rehmet, Cybersecurity Architect Produced & Distributed By Phish Tank Digital