Weekly ALL-SOURCE Cyber Warfare Intelligence Brief 9.21.26
Reporting period: September 14–21, 2026Assessment cutoff: September 21, 2026Scope: State and sta 2026-9-21 17:58:26 Author: krypt3ia.wordpress.com(查看原文) 阅读量:12 收藏

Reporting period: September 14–21, 2026
Assessment cutoff: September 21, 2026
Scope: State and state-aligned cyber operations, APT campaigns, technical intelligence, active exploitation, critical-infrastructure risk, and cyber-enabled intelligence activity.

Executive assessment

This reporting period produced four developments of immediate intelligence significance.

Iranian MOIS cyber activity is now more tightly connected to physical-world counterintelligence and repression. A joint UK-U.S.-Dutch disclosure on September 15 exposed CHOSEN BRICK, while a parallel FBI technical release substantially expanded analysis of the related HEAVYGRAM malware ecosystem. The campaigns target dissidents, journalists, activists, and other perceived opponents of the Iranian government. Collection includes communications, contacts, email, screenshots, microphone audio, location/pattern-of-life information, and social-media data. The agencies explicitly note that Iranian intelligence has previously plotted kidnapping and lethal operations against perceived enemies abroad. (FBI)

China-aligned FamousSparrow has concentrated approximately 90% of its observed recent targeting on Latin America and replaced SparrowDoor with a substantially redesigned implant, SparroWocky. Government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela were affected. The geographic concentration is unusual for this actor and plausibly reflects Beijing’s growing intelligence requirements concerning U.S. political and economic competition in the region. (ESET)

North Korea’s Contagious Interview ecosystem has been formally attributed and quantified by four governments. The September 18 multinational advisory identifies the actor as WaterPlum, reports at least 30,000 compromised PCs in more than 100 countries, and connects the campaign to theft or compromise involving more than 7,000 cryptocurrency wallets. The operation is important beyond cryptocurrency theft because developer compromise can expose enterprise credentials, source code, cloud environments, and intellectual property. (Cyber.gov.au)

Two actively exploited vulnerabilities in security infrastructure require immediate defensive attention, although neither currently has a defensible nation-state attribution. CVE-2026-76461 permits unauthenticated root-level command execution against Cisco Secure Email Gateway simply through malicious email processing. CVE-2026-76460 permits unauthenticated bypass of Cisco Identity Services Engine authentication. Both affect systems positioned at unusually sensitive trust boundaries. (Cisco)

The week’s broader intelligence trend is:

State cyber operations are increasingly exploiting the boundary between a target’s personal life and its institutional security perimeter.

Iran targets personal devices after corporate defenses interfere. North Korea approaches developers as private job seekers. Chinese espionage increasingly targets governmental infrastructure in regions where political and commercial intelligence requirements overlap. At the same time, active exploitation is moving directly against identity and email-security infrastructure.

Priority: CRITICAL
Actor: Iranian state cyber actors acting for the Ministry of Intelligence and Security
Malware: CHOSEN BRICK / HEAVYGRAM ecosystem
Objective: Counterintelligence, surveillance, data theft, harassment, potentially physical targeting support
Attribution confidence: High

On September 15, the UK National Cyber Security Centre, FBI, and Netherlands AIVD jointly disclosed technical details concerning CHOSEN BRICK, malware used by Iranian state actors against dissidents, activists, and journalists in the United Kingdom, United States, Netherlands, and elsewhere. The NCSC says the malware has been used since at least 2025; the FBI’s broader HEAVYGRAM investigation traces related activity to autumn 2023. (FBI)

The intelligence significance exceeds conventional cyberespionage. The NCSC states that collected information can reveal contacts, location, and pattern of life. Some stolen personal information subsequently appeared on pro-Iranian leak sites. The advisory further notes that Iranian intelligence has previously plotted kidnapping or lethal operations against perceived regime enemies abroad. (FBI)

This creates a potential chain:

The last stages are not demonstrated for every CHOSEN BRICK victim, but the intelligence utility is clear.

FBI Cyber Alerts

Initial access and social engineering

Operators conduct substantial target research before engagement.

Initial contact occurs through:

  • Telegram.
  • WhatsApp.
  • Other messaging/social platforms.

The actor impersonates trusted acquaintances, organizations, or technical-support personnel and develops rapport before delivering the malicious payload.

Observed disguises include:

  • Pictory.
  • RunwayML.
  • Norton Antivirus.
  • Telegram.
  • Adobe Flash Player.
  • KeePass.
  • Fabricated MRI scan results.

One particularly important operational behavior is security-boundary migration. When delivery against a corporate device fails or appears likely to trigger detection, the operator attempts to convince the victim to move the activity onto a personal computer. This is allows a bypass of enterprise security architecture through social engineering.

Persistence and defense evasion

CHOSEN BRICK commonly persists through:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Observed values include:

SMQDService

winappx

The implant can also add exclusions to Microsoft Defender.

Observed mutexes include:

ytyjyujyu

noi672pp434awkc12f

The FBI observed PowerShell commands invoking:

Add-MpPreference -ExclusionPath

bypassing against malware directories and even the victim’s Telegram Desktop download directory.

Command and control

CHOSEN BRICK communicates using Telegram bots.

More importantly, each infected machine receives a different Telegram Bot ID. That design limits infrastructure correlation across victims and reduces the consequences of discovering one bot. Recent variants additionally obscure Telegram communications through commercial HTTPS/SOCKS5 proxies.

Relevant services include:

iproyal[.]com

lightningproxies[.]net

Exfiltration also uses legitimate object-storage services:

backblazeb2[.]com

vultrobjects[.]com

storjshare[.]io

This is another example of the continuing movement toward legitimate-service C2 and exfiltration.

Collection capabilities

Observed capabilities include:

  • Process enumeration.
  • System-information collection.
  • Screenshots.
  • Microphone activation/audio capture.
  • Telegram browser-data theft.
  • WhatsApp browser-data theft.
  • Email theft.
  • File collection.
  • Additional payload delivery.
  • File deletion.
  • System wiping.

No automated lateral movement has been observed. This is consistent with the campaign’s person-centric rather than network-centric intelligence requirement.

Selected HEAVYGRAM observables

Pictory masquerade

SHA-256:

E8B633DCAD173EB41EF02686B46779A4A0E53DF7F6C63039A798F2DB5EB83AFC

MD5:

1E6B601F733BC40EAA58916986BFC5B9

Observed delivery:

sgp1.vultrobjects[.]com/downloads/pictory/Pictory_premium_ver9.0.4.exe

Telegram authenticator masquerade

SHA-256:

9014FE4F16F01C0439B261ADE4CF980F460E0DAE46B1EC5F58FD9BC0AF26E531

MD5:

B9086413E7B6A0C6A11C25D14C22615F

Additional observed path:

C:\ProgramData\SMQDServicePackages\488ht1-8ww648q\

ATT&CK

The joint advisory maps activity including:

  • T1589 Gather Victim Identity Information.
  • T1566.003 Spearphishing via Service.
  • T1204.002 Malicious File.
  • T1547.001 Registry Run Keys / Startup Folder.
  • T1685 Disable or Modify Tools.
  • T1057 Process Discovery.
  • T1082 System Information Discovery.
  • T1113 Screen Capture.
  • T1123 Audio Capture.
  • T1005 Data from Local System.
  • T1114.001 Local Email Collection.
  • T1102.002 Web Service: Bidirectional Communication.
  • T1090.002 External Proxy.
  • T1567.002 Exfiltration to Cloud Storage.
  • T1485 Data Destruction.

Assessment

Technical evidence: Very high.
MOIS attribution: High.
Campaign objective: Intelligence collection and repression, High confidence.
Potential physical-targeting utility: High.
Evidence CHOSEN BRICK itself has directly enabled a specific assassination: Not established.

The strongest analytic conclusion is that this malware should be considered cyber-enabled counterintelligence infrastructure, not merely spyware.

Priority: HIGH
Actor: FamousSparrow
Nexus: China-aligned
Malware: SparroWocky
Previous malware: SparrowDoor
Objective: Government espionage
Attribution confidence: High to FamousSparrow; China-state alignment Moderate to High

On September 17, ESET disclosed a major evolution in FamousSparrow operations. Since mid-2025, approximately 90% of FamousSparrow targets visible in ESET telemetry have been in Latin America.

Observed governmental victims or targets occurred in:

  • Argentina.
  • Ecuador.
  • Guatemala.
  • Honduras.
  • Panama.
  • Peru.
  • Puerto Rico.
  • Venezuela.

This sustained geographic concentration is unusual for a Chinese espionage cluster historically observed across multiple regions.

ESET FamousSparrow research announcement

SparroWocky

Beginning around August 2025, FamousSparrow appears to have largely replaced SparrowDoor with a new C++ implant called SparroWocky. It is not simply another SparrowDoor version. It represents a separate malware family with a modular architecture and substantial Windows-internals functionality.

Capabilities include:

  • Shell-command execution.
  • Arbitrary file execution.
  • TCP proxy functionality.
  • System profiling.
  • File exfiltration.
  • Periodic screenshot collection.
  • BOF execution. (ESET)

Collected host information includes:

  • Computer name.
  • Username.
  • Domain.
  • Windows version.
  • Network-interface IP addresses.

Persistence and C2

Persistence varies by configuration and can use:

  • A Windows service.
  • Registry Run keys.

Stolen data is encrypted with RC4 and transmitted through TLS. (ESET)

The malware incorporates code from open-source projects, including:

  • Mbed TLS.
  • MinHook.

It can execute Beacon Object Files, allowing operators to deploy modular post-exploitation capabilities without conventional executables.

Defense evasion

SparroWocky:

  • Manipulates low-level in-memory structures.
  • Patches code dynamically.
  • Uses API hooking.
  • Employs in-memory execution.
  • Supports call-stack manipulation/spoofing.
  • Can remove components after execution. (ESET)

This represents a clear maturation from FamousSparrow’s earlier tooling.

Attribution basis

ESET’s attribution is strengthened by two important observations:

  1. Early SparroWocky deployments occurred through SparrowDoor, which ESET associates specifically with FamousSparrow.
  2. SparroWocky appeared against organizations previously targeted using SparrowDoor. (ALLATRA Media)

That is materially stronger than attribution based solely on victimology.

Strategic assessment

ESET assesses that the concentration on Latin America probably reflects China’s reaction to increasing U.S. political and economic activity in the region.

That interpretation is plausible.

China has substantial interests in Latin American:

  • Energy.
  • Mining.
  • Telecommunications.
  • Infrastructure.
  • Trade.
  • Government relationships.

Government compromise could therefore provide Beijing with insight into:

Assessment confidence: Moderate.

There is currently no public evidence that SparroWocky is intended for destructive operations.

The campaign is best assessed as strategic political-economic espionage.

Priority: HIGH
Actor: WaterPlum
Aliases: Contagious Interview; overlapping industry nomenclature includes Deceptive Development
Nexus: DPRK
Objective: Cryptocurrency theft, credential acquisition, access development, sanctions evasion, and potential espionage
Attribution confidence: High

On September 18, Japan’s National Police Agency and National Cybersecurity Office, the FBI, U.S. Defense Cyber Crime Center, Australian Signals Directorate’s ACSC, Germany’s BND, and Germany’s BfV jointly attributed the WaterPlum campaign to North Korea.

The reported scale is significant.

From approximately December 2025 through July 2026:

≥30,000 PCs compromised

>100 countries affected

>7,000 cryptocurrency wallets affected

≥¥1.7 billion / approximately $10.7 million transferred to North Korea

Australian Cyber Security Centre WaterPlum advisory

Initial access

WaterPlum operators pose as:

  • Recruiters.
  • Employers.
  • AI companies.
  • Cryptocurrency companies.
  • NFT organizations.

Targets include:

  • Software developers.
  • Web designers.
  • Cryptocurrency specialists.
  • Blockchain/Web3 personnel.

Victims receive purported:

  • Coding tests.
  • Programming assignments.
  • Interview software.
  • Development projects.
  • Video-conferencing troubleshooting instructions.

The social engineering exploits something defenders cannot easily disable: developers routinely execute unfamiliar code as part of legitimate work.

Malware ecosystem

Reported malware includes:

  • BeaverTail.
  • InvisibleFerret.
  • OtterCookie.
  • OtterCandy.
  • StoatWaffle.

Malicious npm packages and developer projects provide execution.

StoatWaffle can use blockchain-themed Visual Studio Code projects as decoys, with malicious project configuration triggering execution after the victim trusts the project. (wall street review)

Collection

WaterPlum seeks:

  • Browser credentials.
  • Usernames and passwords.
  • Clipboard contents.
  • Keystrokes.
  • Screenshots.
  • Cryptocurrency private keys.
  • Seed phrases.
  • Identity documents.
  • Enterprise credentials.

The last category changes the intelligence assessment.

A developer attacked while privately searching for employment may possess credentials for:

  • GitHub.
  • GitLab.
  • AWS.
  • Azure.
  • GCP.
  • VPN.
  • CI/CD.
  • Container registries.
  • Production systems.

A personal compromise can therefore become an enterprise initial-access event.

Connection to DPRK IT-worker operations

The joint attribution also discusses North Korean remote IT workers.

Reporting based on the advisory indicates infrastructure overlap between malicious cyber operators and IT-worker activity, including shared access patterns involving laptop farms, employment platforms, and crowdsourcing services. (Decryption Digest)

This reinforces the model:

operating alongside:

These should increasingly be viewed as components of the same DPRK revenue-and-access ecosystem, rather than entirely separate threat categories.

Two exploitation events require special attention because the vulnerable systems themselves occupy security-control positions.

CVE-2026-76461: Secure Email Gateway

Cisco disclosed CVE-2026-76461 on September 14 and updated its advisory September 17.

CVSS: 9.8
Authentication: None required
User interaction: None
Result: Root command execution
Active exploitation: Confirmed

Cisco CVE-2026-76461 advisory

The vulnerability exists in AsyncOS email-parsing logic. A crafted email containing malicious SQL can cause the appliance to execute arbitrary SQL statements, ultimately enabling commands as root. That means the attack path can effectively be:

No user has to open the email.

IOC hunting

Cisco recommends searching mail_logs for suspicious SQL statements, including patterns such as:

COPY.*TO PROGRAM

A real-world administrator report published September 20 identified exploitation attempts retrieving content from:

87[.]120[.]219[.]207

and described large volumes of malicious email contributing to an ESA work queue exceeding 150,000 messages. This community observation is useful but should be treated as single-source incident reporting, not equivalent to Cisco-confirmed campaign attribution.

Cluster implications

Successful compromise may expose private SSH keys used between clustered Secure Email Gateway members.

Cisco therefore recommends treating the entire cluster as potentially compromised if one member was successfully exploited. (Cisco)

That is a significant lateral-movement opportunity.

CVE-2026-76460: Identity Services Engine

A second Cisco zero-day disclosed September 16 affects Identity Services Engine and ISE Passive Identity Connector.

CVSS: 10.0
Authentication: None required
Attack vector: Remote
Active exploitation: Confirmed
Workaround: None

Cisco CVE-2026-76460 advisory

ISE controls network identity and access-policy enforcement. Compromise therefore potentially gives an attacker access to an exceptionally valuable trust system.

Attribution

Neither exploitation campaign currently has a defensible public nation-state attribution.

Accordingly, these vulnerabilities are included as priority technical intelligence, not labeled APT activity.

Any reporting assigning CVE-2026-76460 or CVE-2026-76461 to China, Russia, Iran, or another government without additional evidence should presently be treated as unsubstantiated.

The week’s campaigns reinforce three operational patterns.

Personal devices are becoming a deliberate bypass route

Iranian operators explicitly move victims from protected corporate devices to personal systems when enterprise controls interfere. DPRK operators approach developers through personal job searches and freelance interactions.

The security boundary is therefore no longer:

enterprise network ↔ Internet

It increasingly includes:

employee identity ↔ personal device ↔ social platform ↔ recruiter/contact ↔ corporate credentials

Legitimate infrastructure continues replacing bespoke C2

CHOSEN BRICK uses:

  • Telegram.
  • Vultr.
  • Storj.
  • Backblaze.
  • Commercial proxy networks.

WaterPlum uses:

  • Development repositories.
  • npm.
  • VS Code projects.
  • Normal recruiting platforms.

SparroWocky integrates open-source offensive components directly into a custom implant. The resulting traffic is harder to classify solely through reputation.

Trust infrastructure is itself becoming the target

The Cisco exploitation adds another dimension.

Secure Email Gateway is supposed to inspect malicious email.

ISE is supposed to determine who and what may access the network.

Compromising those systems creates the possibility of:

security control → adversary access point

This is consistent with the broader trend documented in previous briefs involving routers, authentication infrastructure, hypervisors, load balancers, and cloud services.

CampaignTypeObservable
CHOSEN BRICKMutexytyjyujyu
CHOSEN BRICKMutexnoi672pp434awkc12f
CHOSEN BRICKRegistryHKCU\Software\Microsoft\Windows\CurrentVersion\Run
CHOSEN BRICKRun valueSMQDService
CHOSEN BRICKRun valuewinappx
CHOSEN BRICKDomainapi.telegram[.]org
CHOSEN BRICKDomainvultrobjects[.]com
CHOSEN BRICKDomainstorjshare[.]io
CHOSEN BRICKDomainbackblazeb2[.]com
CHOSEN BRICKProxyiproyal[.]com
CHOSEN BRICKProxylightningproxies[.]net
HEAVYGRAMSHA-256E8B633DCAD173EB41EF02686B46779A4A0E53DF7F6C63039A798F2DB5EB83AFC
HEAVYGRAMSHA-2569014FE4F16F01C0439B261ADE4CF980F460E0DAE46B1EC5F58FD9BC0AF26E531
Cisco SEG exploitationIP87[.]120[.]219[.]207*
Cisco SEGLog patternCOPY.*TO PROGRAM

*Community-reported exploitation observable; corroborate before blocking.

Iran: Exceptionally strong sourcing. The technical findings are jointly supported by NCSC, FBI, and AIVD. The FBI additionally analyzed seven malware samples obtained through investigations. Attribution to MOIS is therefore assessed High confidence. (FBI)

FamousSparrow: Strong vendor telemetry and malware lineage. Attribution to FamousSparrow is strengthened by SparrowDoor delivering SparroWocky and recurring victim overlap. The interpretation that Latin American targeting responds to increasing U.S. regional influence is analytically plausible but remains an assessment rather than demonstrated tasking. (ESET)

WaterPlum: Attribution quality is exceptionally high because seven agencies across Japan, the United States, Australia, and Germany participated. Exact equivalence among every commercial alias associated with Contagious Interview should nevertheless be treated cautiously. (Cyber.gov.au)

Cisco exploitation: Active exploitation is vendor-confirmed. Actor identity is unknown. Claims of nation-state attribution are presently unsupported. (Cisco)

No significant adversary or hacktivist claims discovered during this collection period were elevated to confirmed campaign status without independent corroboration.

1. High confidence: Iran’s MOIS is using cyber compromise as an extension of transnational counterintelligence and repression rather than simply conventional strategic espionage.

2. High confidence: Personal devices and personal online identities increasingly represent viable paths around mature enterprise security controls.

3. High confidence: DPRK malicious recruitment and fraudulent IT-worker operations should be treated as an integrated access-and-revenue problem.

4. High confidence: FamousSparrow has made Latin American governmental intelligence collection a major operational priority.

5. Moderate confidence: That geographic shift reflects Beijing’s need to understand Latin American government responses to renewed U.S.-China strategic competition.

6. High confidence: Security infrastructure itself, particularly identity, email, network, and virtualization systems, is becoming an increasingly important high-value attack surface.

7. High confidence: Indicator-only defenses will continue losing effectiveness as state actors route C2 and exfiltration through legitimate cloud, messaging, proxy, and development services.

  • Iran: Per-victim Telegram bot segregation improves OPSEC and limits infrastructure correlation. Commercial proxy layers now further obscure Telegram C2.
  • Iran: Operators deliberately shift infection attempts from corporate endpoints to personal systems when defensive controls interfere.
  • China: FamousSparrow has replaced SparrowDoor with an independently designed modular backdoor incorporating open-source code directly into its implant.
  • DPRK: Developer tooling itself, including npm packages and VS Code projects, has become an execution environment for recruitment-themed intrusion.
  • Active exploitation: Attackers are targeting defensive infrastructure that can provide root or identity-plane access without compromising a conventional workstation first.

The most consequential current pattern is:

trusted relationship → trusted platform → malicious execution

Examples:

The attack surface is shifting toward systems and relationships that users and defenders are institutionally conditioned to trust.

  1. CVE-2026-76460 and CVE-2026-76461 exploitation infrastructure, particularly evidence connecting activity to established APT clusters.
  2. Additional CHOSEN BRICK/HEAVYGRAM infrastructure, Telegram bot architecture, commercial proxy use, and cloud-storage accounts.
  3. Iranian cyber-to-physical targeting convergence, particularly evidence of cyber-derived pattern-of-life information appearing in surveillance, intimidation, kidnapping, or assassination planning.
  4. SparroWocky expansion outside Latin America or additional Latin American governmental victims.
  5. FamousSparrow infrastructure overlap capable of resolving relationships with other PRC espionage clusters.
  6. WaterPlum malware evolution, especially new malicious npm packages, VS Code configurations, GitHub repositories, interview platforms, and recruiter personas.
  7. WaterPlum/IT-worker infrastructure overlap, especially laptop farms, shared IP space, identity documents, payment channels, and employment accounts.
  8. Compromise of security infrastructure, particularly email gateways, identity platforms, VPNs, hypervisors, routers, and authentication servers.
  9. Post-disclosure migration of Iranian Telegram C2 and SparroWocky infrastructure.
  10. Any evidence that currently unattributed Cisco exploitation is being incorporated into established state-actor access operations.

Conclusion

The dominant development this week is a further erosion of the distinction between cyber access, human intelligence targeting, personal-device compromise, and trusted infrastructure exploitation.

Iran’s CHOSEN BRICK campaign demonstrates how cyber collection can generate contacts, communications, location, and pattern-of-life intelligence useful well beyond the computer itself. FamousSparrow’s sustained concentration on Latin American governments indicates a strategic intelligence requirement rather than opportunistic compromise. North Korea’s WaterPlum operation demonstrates that recruitment and developer workflows can simultaneously generate revenue, credentials, intellectual property, and enterprise access. The Cisco vulnerabilities show that the systems designed to enforce email and identity security can themselves become high-value intrusion points.

The resulting operational model is increasingly:

For defenders, the implication is substantial. Protecting the corporate endpoint is no longer enough. Personal devices, developer environments, browser identities, messaging platforms, security appliances, authentication infrastructure, and the human trust relationships connecting them must now be treated as parts of the same attack surface.


文章来源: https://krypt3ia.wordpress.com/2026/09/21/weekly-all-source-cyber-warfare-intelligence-brief-9-21-26/
如有侵权请联系:admin#unsafe.sh