Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
rapid-weaponizationstate-sponsored-espionagegovernment-diplomatic-threatvendor-distribution-compromise

Weekly Cyber Threat Roundups Highlight Linux Fileless Malware, Office Zero-Day Exploitation, and Multiple Breach Claims

Updated 3mo agoFirst seen Feb 2, 20266 sources

Multiple weekly threat roundups and research posts reported a mix of active exploitation, new malware tradecraft, and breach claims. Ukraine’s CERT reported APT28 rapidly weaponized a Microsoft Office zero-day (CVE-2026-21509) within roughly a day of Microsoft’s disclosure, using spearphishing emails with malicious DOC lures to deliver Covenant backdoors against Ukrainian government targets and EU-related entities. Separately, researchers described ShadowHS, a stealthy fileless Linux post-exploitation framework that runs in-memory (e.g., via memfd-style execution), uses encrypted multi-stage loading (AES-256-CBC), fingerprints defensive tooling (including major EDR agents), and retains operator-driven capabilities such as credential theft, lateral movement, and covert tunneling for exfiltration.

Other reporting highlighted incident and exposure claims and defensive takeaways. Check Point described a supply-chain compromise affecting eScan (MicroWorld Technologies) in which malicious updates were pushed through the legitimate updater, prompting an emergency shutdown of global update services; it also noted Crunchbase confirmed a breach affecting 2M+ records claimed by ShinyHunters, and cited extortion/leak claims involving Qilin (Tulsa International Airport) and WorldLeaks (Nike). Google’s legal/technical disruption of the IPIDEA residential proxy network was also cited as reducing available proxy nodes by millions and cutting off C2 domains used to route attacker traffic. Additional coverage described a phishing chain using a fake DHL invoice to abuse a signed Java utility via DLL sideloading (malicious jli.dll) and process hollowing into AddInProcess32.exe to run Phantom Stealer; detection-engineering updates emphasized new rules for Windows defense-evasion (e.g., tampering with Credential Guard/HVCI, disabling AMSI and the vulnerable driver blocklist) and expanded Kubernetes and Linux post-exploitation detections.

Share:
Weekly Cyber Threat Roundups Highlight Linux Fileless Malware, Office Zero-Day Exploitation, and Multiple Breach Claims
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Feb 2, 20265mo ago

Weekly reports highlight emergency patching and active exploitation trends

Security roundups published on February 2 summarized major ongoing developments, including emergency Microsoft and Ivanti patches for actively exploited zero-days and broader active exploitation of enterprise vulnerabilities. They also highlighted related incidents such as Static Tundra attacks in Poland, Google disruption of the IPIDEA proxy botnet, and continued abuse of exposed AI and cloud services.

Detection rules added for CVE-2026-21509 and other active threats

A detections digest covering the period from January 26 to February 2 reported new and updated rules for multiple ecosystems, including hunting content for CVE-2026-21509, FortiGate post-exploitation tied to CVE-2026-24858, and other active threats. The update also introduced YARA detections for malware families such as HijackLoader, Mythic/Apollo, Tiny Shell, and UNC2891 SLAPSTICK.

ShadowHS fileless Linux malware framework is uncovered

Researchers reported a new fileless Linux malware framework called ShadowHS that runs entirely in memory using encrypted multi-stage loaders and memfd-style execution. The framework includes environment fingerprinting, credential theft, lateral movement, privilege escalation, covert exfiltration, and anti-competition features.

Researchers document fake DHL invoice campaign delivering Phantom Stealer

A multi-stage malware campaign was reported using fake DHL invoice emails with a ZIP attachment containing a renamed signed Java utility and a malicious DLL for sideloading. The chain used process hollowing into AddInProcess32.exe and ultimately deployed Phantom Stealer v3.5.0 for credential theft and data exfiltration.

APT28 begins exploiting CVE-2026-21509 against Ukrainian and EU targets

Within 24 hours of Microsoft's disclosure, CERT-UA said Russian state-linked APT28 (UAC-0001) began exploiting CVE-2026-21509 using malicious Word documents sent via impersonation emails. The campaign targeted Ukrainian government agencies and also used similar lures against organizations in EU countries, fetching follow-on payloads over WebDAV and deploying Covenant with Filen.io for C2.

Feb 1, 20265mo ago

Microsoft discloses Office zero-day CVE-2026-21509

Microsoft publicly disclosed the Microsoft Office zero-day vulnerability CVE-2026-21509 and later issued an emergency fix. The disclosure set off rapid defensive guidance and follow-on reporting about active exploitation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

188 LINKEDOpen in app
Vulnerabilities
44 linked
FortiCloud SSO Authentication Bypass in Fortinet FortiOS/FortiManager/FortiAnalyzer/FortiProxy/FortiWebUnauthenticated RCE in SmarterTools SmarterMail ConnectToHub APIPath Traversal in WinRAR for Windows via NTFS Alternate Data StreamsAuthentication Bypass in SmarterTools SmarterMail Password Reset APIMicrosoft Office Shell.Explorer.1 OLE Security Feature BypassSessionReaper in Adobe Commerce / Magento Open Source REST APIArbitrary File Overwrite via Symlink in Mitsubishi Electric ICONICS/GENESIS ServicesUnauthenticated Authentication Bypass and RCE in PaperCut MF/NGCleartext Password Exposure in GNOME Keyring PAM ModuleArgument injection leading to 1-click RCE in IDIS Cloud Manager (ICM) Viewer for WindowsOpenSSH VerifyHostKeyDNS Machine-in-the-Middle Host Verification BypassGit submodule path CR parsing vulnerability leading to hook executionInadequate permission management in camera guest account (CVE-2025-52599)Command execution via improper input validation in camera video analyticsXSS via inadequate XML request validation (CVE-2025-8075)Hardcoded encryption key in Nozomi Networks Device ManagerCommand Injection RCE in gemini-mcp-tool execAsyncLocal privilege escalation via JWT directory traversal and arbitrary file write in Check Point Harmony SASE (Perimeter81) Windows clientInformation Disclosure in Xiaomi Redmi Buds RFCOMM TEST HandlingDenial of Service in Xiaomi Redmi Buds RFCOMM Control ChannelsWhisperPair in Google Fast Pair Bluetooth audio accessoriesRemote Command Injection in Apache bRPC /pprof/heap Heap Profilern8n python-task-executor sandbox escape leading to arbitrary Python executionUnsafe pickle deserialization in PLY 3.11 yacc() via undocumented picklefile parameterGNU Inetutils telnetd remote authentication bypass via USER argument injectionDenial of Service in React Server Components Server Function endpointsAuthenticated command injection in TP-Link Archer MR600 v5 admin interfaceSandbox escape in vm2 Promise callback sanitizationLocal DLL search order hijacking in Western Digital WD Discovery Installer (WD Discovery <= 5.2.730)n8n Expression Sandbox Escape RCECross-origin data leak in Google Chrome Background Fetch APIUnauthenticated Deserialization RCE in SolarWinds Web Help DeskUnauthenticated RCE in SolarWinds Web Help Desk DeserializationAuthentication Bypass in SolarWinds Web Help DeskHardcoded Credentials in SolarWinds Web Help DeskThunderbird OpenPGP inline decryption CSS-based content exfiltrationSecurity Control Bypass in SolarWinds Web Help DeskSQL Injection in Johnson Controls Metasys SQL Express DeploymentsInteger overflow/wraparound in NVIDIA Display Driver for Linux kernel moduleUse-after-free in NVIDIA vGPU Virtual GPU Manager (guest-to-host impact)Integer overflow in NVIDIA GPU Display Driver for Windows kernel-mode (nvlddmkm.sys)Use-after-free in NVIDIA Display Driver for Windows (user-mode)Unauthenticated RCE in Ivanti EPMM Android File TransferUnauthenticated RCE in Ivanti Endpoint Manager Mobile In-House App Distribution
Affected products
35 linked
AndroidWindowsOllamaMicrosoft OfficeSmartermailTelegramGithubHarmony EndpointChatgptGithubWinrarGoogle DriveWinrarGoogle DriveGoogle DriveWhatsappFortigateFalconElastic AgentIconics SuiteMagento Open SourceNetScreenconnectPapercut NgKubernetesOpensslVisual Studio CodeAdobe CommerceMongodbOpensslGitNetVllmLinuxOpenssl
Organizations
66 linked
FortinetSmartertoolsCheck Point Software TechnologiesGoogleMicroworld TechnologiesHugging FaceNikeWinRARGitHubTelegramCrunchbaseMicrosoft CorporationElasticWizMozillaPositive TechnologiesWestern Digital CorporationBarracuda NetworksK7 ComputingHanwha VisionJohnson ControlsCisco SystemsCybleSplunkNvidiaAmazon Web ServicesRapid7Sublime SecurityZscalerPalo Alto NetworksTenableSamsung ElectronicsEsetHunt.ioNetflixCloudflareAnthropicForescoutVaronisSolarWindsXiaomiMeta PlatformsOasis SecurityCrowdStrikeIvantiSaudi AramcoAppleProofpointConnectwiseAdobeDHLCyberarkOracleDragosJetbrainsBloombergPatchstackFlareTinesKU LeuvenWeTransferSecure AnnexPillar SecurityMonday.comAirMDRMagicSword
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.