10-September-2026
Welcome to the weekly threat detection update report from Stamus Networks. Each week, you will receive this email with a summary of the updates.
Current Stamus Threat Intelligence (STI) release version: 1738
This week, in addition to daily ruleset and IOC updates, we provided Stamus Security Platform customers with the following improved defense(s):
Note: a "method" as referenced below, is a discrete detection vector for a given threat.
The following detections were added to your Stamus NDR this past week:
OnionDrop is a significant threat with a sophisticated evasion architecture that exceeds nation-state tooling. The focus on high-profile threats leaves a gap in addressing commoditized malware like OnionDrop.
TonRAT is a malware acting as a RAT and downloader, utilizing the blockchain system The Open Network (TON) and Obfuscator.io's VM Obfuscation. Code is extensive and obfuscated.
The following detections were updated this past week with changes to kill chain phase(s) or MITRE ATT&CK tactic(s)/technique(s):
APT28, linked to Russia's Main Intelligence Directorate, compromised the Hillary Clinton campaign, DNC, and DCCC in 2016 to interfere with U.S. election. Active since 2004.
In April 2024, researchers found compromised sites leading to an iframe on pley[.]es showing an error message. The payload domain was taken offline, preventing infection. Later, the iframe was replaced with the ClearFake inject.
Phishing involves scammers posing as familiar companies to obtain personal information. Consumers should avoid responding to suspicious emails requesting personal or financial details to prevent falling victim to these scams.
Trojan-Banker programs steal bank account information and other data, then transfer it to malicious users. Stolen data can be transmitted through email, FTP, the web, or other methods.
Fake update variants like SocGholish, Clear Fake, Smart Ape, and ClickFix are being tracked by a collaboration introducing the LandUpdate808 Fake Update Variant.
Lumma is a C-based information stealer sold on Russian underground forums and Telegram by LummaC since August 2022. It targets cryptocurrency wallets and has file grabber capabilities.
FIN6 or Magecart is a cybercrime group that steals payment card data from PoS systems in hospitality and retail, selling it on underground markets for profit.
Malicious domains are used by threat actors for malware spreading and phishing. C2 servers are established worldwide to evade detection. DGA generates domain names for command and control, challenging security professionals. Stamus Networks offers specialized detection methods.
Misconfigured applications open the door for data breaches, unauthorized access, financial losses, and reputational damage. Vulnerabilities provide easy entry points for attackers, leading to costly breaches and compromised systems.
Remote Access Trojans allow covert surveillance and unauthorized access to victim PCs, collecting keystrokes, passwords, screenshots, and more. They differ from keyloggers by providing remote access capabilities to attackers.
Adversaries can abuse PowerShell for execution, discovery, and code running. Examples include Start-Process and Invoke-Command cmdlets, requiring administrator permissions for remote connections.
Malwarebytes found a new social engineering toolkit that uses compromised websites to perform advanced fingerprinting checks and deliver the NetSupport RAT payload.
TA2726 serves as a TDS for TA2727 and TA569, distributing SocGholish malware that pretends to be a browser update on compromised sites.
Cybercriminal group TA2727 collaborates with others for financial gain, purchasing online traffic to disseminate malware. Proofpoint identified them in an attack campaign delivering malicious payloads via compromised websites in North America.
Cybersecurity firms report multiple groups tied to India, including TA397, TA399, and TA395, linked to the Sloppy Lemming threat group, targeting individuals and critical infrastructure.
Proofpoint has identified an Indian APT actor known as TA425.
Malicious programs in the Trojan-Spy.AndroidOS.Agent family covertly send data from infected Android devices to criminals.
Cyble research labs found a malware developer advertising a powerful Windows RAT on the dark web during a threat-hunting exercise.
The following threat detection(s) were improved this past week with new or updated threat methods.
| Name of threat | New coverage | Total coverage | Last updated | ||||
|---|---|---|---|---|---|---|---|
| New methods | Kill chain phases | Protocols | Methods | Kill chain phases | Protocols | ||
| APT28 | 7 | delivery, installation, command and control | http | 806 | delivery, exploitation, installation, command and control, actions on objectives | dns, http, http1, tcp, tcp-pkt, tls | 2026-09-04 |
| ClickFix | 3 | delivery | dns, http, tls | 820 | delivery, exploitation, installation, command and control | dns, http, tls | 2026-09-10 |
| Fake Service | 5 | delivery, command and control | dns, http | 213 | delivery, installation, command and control, actions on objectives | dns, http, http1, tcp, tls | 2026-09-04 |
| Hqwar | 3 | command and control | dns, http, tls | 176 | command and control, actions on objectives | dns, http, http1, tls | 2026-09-04 |
| LandUpdate808 | 12 | command and control | dns, http, tls | 1204 | delivery, exploitation, command and control, actions on objectives | dns, http, tls | 2026-09-09 |
| Lumma | 45 | command and control, actions on objectives | dns, http, tls | 8671 | delivery, installation, command and control, actions on objectives | dns, http, tls | 2026-09-10 |
| MageCart | 3 | command and control | dns, http, tls | 527 | delivery, command and control, actions on objectives | dns, http, tls | 2026-09-03 |
| Malicious DGA Domain | 72 | command and control | http, tls | 349 | command and control | http, tls | 2026-09-09 |
| Misconfigured Application | 7 | pre condition | tcp | 33 | pre condition | smtp, tcp | 2026-09-09 |
| NetSupport RAT | 1 | command and control | http | 242 | exploitation, installation, command and control, actions on objectives | dns, http, tls | 2026-09-04 |
| OnionDrop | 3 | command and control | http | 3 | command and control | http | 2026-09-04 |
| Powershell | 5 | delivery | http | 77 | delivery, installation, command and control, actions on objectives | dns, http, http1, tcp, tcp-pkt, tls | 2026-09-10 |
| SocGholish | 21 | command and control | dns, http, tls | 2488 | reconnaissance, delivery, exploitation, command and control, actions on objectives | dns, http, tcp, tcp-pkt, tls | 2026-09-09 |
| TA2726 | 6 | delivery, command and control | http | 192 | delivery, command and control | dns, http, tls | 2026-09-08 |
| TA2727 | 6 | command and control | dns, http, tls | 21 | command and control | dns, http, tls | 2026-09-08 |
| TA395 | 10 | command and control, actions on objectives | http, tls | 25 | command and control, actions on objectives | dns, http, tcp-pkt, tls | 2026-09-04 |
| TA425 | 9 | command and control | dns, http, tls | 28 | command and control | dns, http, tls | 2026-09-03 |
| TonRAT | 3 | delivery, command and control | http | 3 | delivery, command and control | http | 2026-09-04 |
| TrojanSpy-Android | 2 | command and control | dns | 1574 | delivery, installation, command and control, actions on objectives | dns, http, http1, tcp, tls | 2026-09-04 |
| XWorm | 41 | command and control | tcp-pkt | 5782 | delivery, command and control | dns, http, tcp, tcp-pkt, tls | 2026-09-04 |
ABOUT STAMUS® NETWORKS
Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.
© 2014-2026 Stamus Networks, Inc. All rights Reserved.