Reporting period: September 14–21, 2026
Assessment cutoff: September 21, 2026
Scope: State and state-aligned cyber operations, APT campaigns, technical intelligence, active exploitation, critical-infrastructure risk, and cyber-enabled intelligence activity.
This reporting period produced four developments of immediate intelligence significance.
Iranian MOIS cyber activity is now more tightly connected to physical-world counterintelligence and repression. A joint UK-U.S.-Dutch disclosure on September 15 exposed CHOSEN BRICK, while a parallel FBI technical release substantially expanded analysis of the related HEAVYGRAM malware ecosystem. The campaigns target dissidents, journalists, activists, and other perceived opponents of the Iranian government. Collection includes communications, contacts, email, screenshots, microphone audio, location/pattern-of-life information, and social-media data. The agencies explicitly note that Iranian intelligence has previously plotted kidnapping and lethal operations against perceived enemies abroad. (FBI)
China-aligned FamousSparrow has concentrated approximately 90% of its observed recent targeting on Latin America and replaced SparrowDoor with a substantially redesigned implant, SparroWocky. Government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela were affected. The geographic concentration is unusual for this actor and plausibly reflects Beijing’s growing intelligence requirements concerning U.S. political and economic competition in the region. (ESET)
North Korea’s Contagious Interview ecosystem has been formally attributed and quantified by four governments. The September 18 multinational advisory identifies the actor as WaterPlum, reports at least 30,000 compromised PCs in more than 100 countries, and connects the campaign to theft or compromise involving more than 7,000 cryptocurrency wallets. The operation is important beyond cryptocurrency theft because developer compromise can expose enterprise credentials, source code, cloud environments, and intellectual property. (Cyber.gov.au)
Two actively exploited vulnerabilities in security infrastructure require immediate defensive attention, although neither currently has a defensible nation-state attribution. CVE-2026-76461 permits unauthenticated root-level command execution against Cisco Secure Email Gateway simply through malicious email processing. CVE-2026-76460 permits unauthenticated bypass of Cisco Identity Services Engine authentication. Both affect systems positioned at unusually sensitive trust boundaries. (Cisco)
The week’s broader intelligence trend is:
State cyber operations are increasingly exploiting the boundary between a target’s personal life and its institutional security perimeter.
Iran targets personal devices after corporate defenses interfere. North Korea approaches developers as private job seekers. Chinese espionage increasingly targets governmental infrastructure in regions where political and commercial intelligence requirements overlap. At the same time, active exploitation is moving directly against identity and email-security infrastructure.
Priority: CRITICAL
Actor: Iranian state cyber actors acting for the Ministry of Intelligence and Security
Malware: CHOSEN BRICK / HEAVYGRAM ecosystem
Objective: Counterintelligence, surveillance, data theft, harassment, potentially physical targeting support
Attribution confidence: High
On September 15, the UK National Cyber Security Centre, FBI, and Netherlands AIVD jointly disclosed technical details concerning CHOSEN BRICK, malware used by Iranian state actors against dissidents, activists, and journalists in the United Kingdom, United States, Netherlands, and elsewhere. The NCSC says the malware has been used since at least 2025; the FBI’s broader HEAVYGRAM investigation traces related activity to autumn 2023. (FBI)
The intelligence significance exceeds conventional cyberespionage. The NCSC states that collected information can reveal contacts, location, and pattern of life. Some stolen personal information subsequently appeared on pro-Iranian leak sites. The advisory further notes that Iranian intelligence has previously plotted kidnapping or lethal operations against perceived regime enemies abroad. (FBI)
This creates a potential chain:
The last stages are not demonstrated for every CHOSEN BRICK victim, but the intelligence utility is clear.
Operators conduct substantial target research before engagement.
Initial contact occurs through:
The actor impersonates trusted acquaintances, organizations, or technical-support personnel and develops rapport before delivering the malicious payload.
Observed disguises include:
One particularly important operational behavior is security-boundary migration. When delivery against a corporate device fails or appears likely to trigger detection, the operator attempts to convince the victim to move the activity onto a personal computer. This is allows a bypass of enterprise security architecture through social engineering.
CHOSEN BRICK commonly persists through:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Observed values include:
SMQDService
winappx
The implant can also add exclusions to Microsoft Defender.
Observed mutexes include:
ytyjyujyu
noi672pp434awkc12f
The FBI observed PowerShell commands invoking:
Add-MpPreference -ExclusionPath
bypassing against malware directories and even the victim’s Telegram Desktop download directory.
CHOSEN BRICK communicates using Telegram bots.
More importantly, each infected machine receives a different Telegram Bot ID. That design limits infrastructure correlation across victims and reduces the consequences of discovering one bot. Recent variants additionally obscure Telegram communications through commercial HTTPS/SOCKS5 proxies.
Relevant services include:
iproyal[.]com
lightningproxies[.]net
Exfiltration also uses legitimate object-storage services:
backblazeb2[.]com
vultrobjects[.]com
storjshare[.]io
This is another example of the continuing movement toward legitimate-service C2 and exfiltration.
Observed capabilities include:
No automated lateral movement has been observed. This is consistent with the campaign’s person-centric rather than network-centric intelligence requirement.
Pictory masquerade
SHA-256:
E8B633DCAD173EB41EF02686B46779A4A0E53DF7F6C63039A798F2DB5EB83AFC
MD5:
1E6B601F733BC40EAA58916986BFC5B9
Observed delivery:
sgp1.vultrobjects[.]com/downloads/pictory/Pictory_premium_ver9.0.4.exe
Telegram authenticator masquerade
SHA-256:
9014FE4F16F01C0439B261ADE4CF980F460E0DAE46B1EC5F58FD9BC0AF26E531
MD5:
B9086413E7B6A0C6A11C25D14C22615F
Additional observed path:
C:\ProgramData\SMQDServicePackages\488ht1-8ww648q\
The joint advisory maps activity including:
Technical evidence: Very high.
MOIS attribution: High.
Campaign objective: Intelligence collection and repression, High confidence.
Potential physical-targeting utility: High.
Evidence CHOSEN BRICK itself has directly enabled a specific assassination: Not established.
The strongest analytic conclusion is that this malware should be considered cyber-enabled counterintelligence infrastructure, not merely spyware.
Priority: HIGH
Actor: FamousSparrow
Nexus: China-aligned
Malware: SparroWocky
Previous malware: SparrowDoor
Objective: Government espionage
Attribution confidence: High to FamousSparrow; China-state alignment Moderate to High
On September 17, ESET disclosed a major evolution in FamousSparrow operations. Since mid-2025, approximately 90% of FamousSparrow targets visible in ESET telemetry have been in Latin America.
Observed governmental victims or targets occurred in:
This sustained geographic concentration is unusual for a Chinese espionage cluster historically observed across multiple regions.
ESET FamousSparrow research announcement
Beginning around August 2025, FamousSparrow appears to have largely replaced SparrowDoor with a new C++ implant called SparroWocky. It is not simply another SparrowDoor version. It represents a separate malware family with a modular architecture and substantial Windows-internals functionality.
Capabilities include:
Collected host information includes:
Persistence varies by configuration and can use:
Stolen data is encrypted with RC4 and transmitted through TLS. (ESET)
The malware incorporates code from open-source projects, including:
It can execute Beacon Object Files, allowing operators to deploy modular post-exploitation capabilities without conventional executables.
SparroWocky:
This represents a clear maturation from FamousSparrow’s earlier tooling.
ESET’s attribution is strengthened by two important observations:
That is materially stronger than attribution based solely on victimology.
ESET assesses that the concentration on Latin America probably reflects China’s reaction to increasing U.S. political and economic activity in the region.
That interpretation is plausible.
China has substantial interests in Latin American:
Government compromise could therefore provide Beijing with insight into:
Assessment confidence: Moderate.
There is currently no public evidence that SparroWocky is intended for destructive operations.
The campaign is best assessed as strategic political-economic espionage.
Priority: HIGH
Actor: WaterPlum
Aliases: Contagious Interview; overlapping industry nomenclature includes Deceptive Development
Nexus: DPRK
Objective: Cryptocurrency theft, credential acquisition, access development, sanctions evasion, and potential espionage
Attribution confidence: High
On September 18, Japan’s National Police Agency and National Cybersecurity Office, the FBI, U.S. Defense Cyber Crime Center, Australian Signals Directorate’s ACSC, Germany’s BND, and Germany’s BfV jointly attributed the WaterPlum campaign to North Korea.
The reported scale is significant.
From approximately December 2025 through July 2026:
≥30,000 PCs compromised
>100 countries affected
>7,000 cryptocurrency wallets affected
≥¥1.7 billion / approximately $10.7 million transferred to North Korea
Australian Cyber Security Centre WaterPlum advisory
WaterPlum operators pose as:
Targets include:
Victims receive purported:
The social engineering exploits something defenders cannot easily disable: developers routinely execute unfamiliar code as part of legitimate work.
Reported malware includes:
Malicious npm packages and developer projects provide execution.
StoatWaffle can use blockchain-themed Visual Studio Code projects as decoys, with malicious project configuration triggering execution after the victim trusts the project. (wall street review)
WaterPlum seeks:
The last category changes the intelligence assessment.
A developer attacked while privately searching for employment may possess credentials for:
A personal compromise can therefore become an enterprise initial-access event.
The joint attribution also discusses North Korean remote IT workers.
Reporting based on the advisory indicates infrastructure overlap between malicious cyber operators and IT-worker activity, including shared access patterns involving laptop farms, employment platforms, and crowdsourcing services. (Decryption Digest)
This reinforces the model:
operating alongside:
These should increasingly be viewed as components of the same DPRK revenue-and-access ecosystem, rather than entirely separate threat categories.
Two exploitation events require special attention because the vulnerable systems themselves occupy security-control positions.
Cisco disclosed CVE-2026-76461 on September 14 and updated its advisory September 17.
CVSS: 9.8
Authentication: None required
User interaction: None
Result: Root command execution
Active exploitation: Confirmed
The vulnerability exists in AsyncOS email-parsing logic. A crafted email containing malicious SQL can cause the appliance to execute arbitrary SQL statements, ultimately enabling commands as root. That means the attack path can effectively be:
No user has to open the email.
Cisco recommends searching mail_logs for suspicious SQL statements, including patterns such as:
COPY.*TO PROGRAM
A real-world administrator report published September 20 identified exploitation attempts retrieving content from:
87[.]120[.]219[.]207
and described large volumes of malicious email contributing to an ESA work queue exceeding 150,000 messages. This community observation is useful but should be treated as single-source incident reporting, not equivalent to Cisco-confirmed campaign attribution.
Successful compromise may expose private SSH keys used between clustered Secure Email Gateway members.
Cisco therefore recommends treating the entire cluster as potentially compromised if one member was successfully exploited. (Cisco)
That is a significant lateral-movement opportunity.
A second Cisco zero-day disclosed September 16 affects Identity Services Engine and ISE Passive Identity Connector.
CVSS: 10.0
Authentication: None required
Attack vector: Remote
Active exploitation: Confirmed
Workaround: None
ISE controls network identity and access-policy enforcement. Compromise therefore potentially gives an attacker access to an exceptionally valuable trust system.
Neither exploitation campaign currently has a defensible public nation-state attribution.
Accordingly, these vulnerabilities are included as priority technical intelligence, not labeled APT activity.
Any reporting assigning CVE-2026-76460 or CVE-2026-76461 to China, Russia, Iran, or another government without additional evidence should presently be treated as unsubstantiated.
The week’s campaigns reinforce three operational patterns.
Iranian operators explicitly move victims from protected corporate devices to personal systems when enterprise controls interfere. DPRK operators approach developers through personal job searches and freelance interactions.
The security boundary is therefore no longer:
enterprise network ↔ Internet
It increasingly includes:
employee identity ↔ personal device ↔ social platform ↔ recruiter/contact ↔ corporate credentials
CHOSEN BRICK uses:
WaterPlum uses:
SparroWocky integrates open-source offensive components directly into a custom implant. The resulting traffic is harder to classify solely through reputation.
The Cisco exploitation adds another dimension.
Secure Email Gateway is supposed to inspect malicious email.
ISE is supposed to determine who and what may access the network.
Compromising those systems creates the possibility of:
security control → adversary access point
This is consistent with the broader trend documented in previous briefs involving routers, authentication infrastructure, hypervisors, load balancers, and cloud services.
| Campaign | Type | Observable |
|---|---|---|
| CHOSEN BRICK | Mutex | ytyjyujyu |
| CHOSEN BRICK | Mutex | noi672pp434awkc12f |
| CHOSEN BRICK | Registry | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
| CHOSEN BRICK | Run value | SMQDService |
| CHOSEN BRICK | Run value | winappx |
| CHOSEN BRICK | Domain | api.telegram[.]org |
| CHOSEN BRICK | Domain | vultrobjects[.]com |
| CHOSEN BRICK | Domain | storjshare[.]io |
| CHOSEN BRICK | Domain | backblazeb2[.]com |
| CHOSEN BRICK | Proxy | iproyal[.]com |
| CHOSEN BRICK | Proxy | lightningproxies[.]net |
| HEAVYGRAM | SHA-256 | E8B633DCAD173EB41EF02686B46779A4A0E53DF7F6C63039A798F2DB5EB83AFC |
| HEAVYGRAM | SHA-256 | 9014FE4F16F01C0439B261ADE4CF980F460E0DAE46B1EC5F58FD9BC0AF26E531 |
| Cisco SEG exploitation | IP | 87[.]120[.]219[.]207* |
| Cisco SEG | Log pattern | COPY.*TO PROGRAM |
*Community-reported exploitation observable; corroborate before blocking.
Iran: Exceptionally strong sourcing. The technical findings are jointly supported by NCSC, FBI, and AIVD. The FBI additionally analyzed seven malware samples obtained through investigations. Attribution to MOIS is therefore assessed High confidence. (FBI)
FamousSparrow: Strong vendor telemetry and malware lineage. Attribution to FamousSparrow is strengthened by SparrowDoor delivering SparroWocky and recurring victim overlap. The interpretation that Latin American targeting responds to increasing U.S. regional influence is analytically plausible but remains an assessment rather than demonstrated tasking. (ESET)
WaterPlum: Attribution quality is exceptionally high because seven agencies across Japan, the United States, Australia, and Germany participated. Exact equivalence among every commercial alias associated with Contagious Interview should nevertheless be treated cautiously. (Cyber.gov.au)
Cisco exploitation: Active exploitation is vendor-confirmed. Actor identity is unknown. Claims of nation-state attribution are presently unsupported. (Cisco)
No significant adversary or hacktivist claims discovered during this collection period were elevated to confirmed campaign status without independent corroboration.
1. High confidence: Iran’s MOIS is using cyber compromise as an extension of transnational counterintelligence and repression rather than simply conventional strategic espionage.
2. High confidence: Personal devices and personal online identities increasingly represent viable paths around mature enterprise security controls.
3. High confidence: DPRK malicious recruitment and fraudulent IT-worker operations should be treated as an integrated access-and-revenue problem.
4. High confidence: FamousSparrow has made Latin American governmental intelligence collection a major operational priority.
5. Moderate confidence: That geographic shift reflects Beijing’s need to understand Latin American government responses to renewed U.S.-China strategic competition.
6. High confidence: Security infrastructure itself, particularly identity, email, network, and virtualization systems, is becoming an increasingly important high-value attack surface.
7. High confidence: Indicator-only defenses will continue losing effectiveness as state actors route C2 and exfiltration through legitimate cloud, messaging, proxy, and development services.
The most consequential current pattern is:
trusted relationship → trusted platform → malicious execution
Examples:

The attack surface is shifting toward systems and relationships that users and defenders are institutionally conditioned to trust.
The dominant development this week is a further erosion of the distinction between cyber access, human intelligence targeting, personal-device compromise, and trusted infrastructure exploitation.
Iran’s CHOSEN BRICK campaign demonstrates how cyber collection can generate contacts, communications, location, and pattern-of-life intelligence useful well beyond the computer itself. FamousSparrow’s sustained concentration on Latin American governments indicates a strategic intelligence requirement rather than opportunistic compromise. North Korea’s WaterPlum operation demonstrates that recruitment and developer workflows can simultaneously generate revenue, credentials, intellectual property, and enterprise access. The Cisco vulnerabilities show that the systems designed to enforce email and identity security can themselves become high-value intrusion points.
The resulting operational model is increasingly:
For defenders, the implication is substantial. Protecting the corporate endpoint is no longer enough. Personal devices, developer environments, browser identities, messaging platforms, security appliances, authentication infrastructure, and the human trust relationships connecting them must now be treated as parts of the same attack surface.