QTFY Threat Group Exploits Log4Shell, Ivanti, and BeyondTrust Vulnerabilities Using QTRouter and OpenWrt
Joint Cybersecurity Advisory JCSA-20260826-01, issued by the FBI, NSA, and CNMF, details the ongoing operations of the China-linked threat group QTFY (also known as QT or QTCYBER), which is associated with Nanjing Xinjiuwei Network Technology Co. Active since 2018, the group targets critical infrastructure, government, and defense sectors globally using three proprietary platforms: QScan, a high-volume distributed vulnerability scanning and exploitation pipeline; QTRouter, an obfuscation network that routes malicious traffic through compromised OpenWrt routers and commercial residential proxies like Fastlink; and various botnet management systems that enroll compromised IoT devices as proxy nodes. QTFY's initial access strategy relies on exploiting public-facing applications, leveraging a database of over 200 exploits targeting vulnerabilities such as Log4Shell (CVE-2021-44228), Ivanti CSA zero-days (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380), and BeyondTrust Remote Support (CVE-2026-1731). Because QTRouter blends malicious commands with legitimate residential and commercial proxy traffic, defenders must vet associated indicators of compromise before implementing broad IP blocking to avoid collateral disruption, while prioritizing the patching of edge devices and monitoring for persistent web shells.
Severity: Critical
Threat Details and IOCs
| Malware: | QScan, QTBotnet, QTRouter |
|---|---|
| CVEs: | CVE-2018-13379, CVE-2019-10068, CVE-2019-11510, CVE-2019-19781, CVE-2020-5902, CVE-2021-26855, CVE-2021-44228, CVE-2023-22515, CVE-2024-24919, CVE-2024-8190, CVE-2024-8963, CVE-2024-9380, CVE-2025-31161, CVE-2026-1731 |
| Technologies: | Apache Log4j, Atlassian Confluence, BeyondTrust Remote Support, Check Point Quantum Security Gateway, Citrix Application Delivery Controller, Citrix Application Delivery Controller and Gateway, Citrix Gateway, Citrix NetScaler ADC, CrushFTP, Fortinet FortiOS, Ivanti Cloud Services Appliance, Ivanti Pulse Connect Secure, Kentico Xperience, Linux Kernel, Microsoft Exchange Server, Microsoft SQL Server, NGINX |
| Threat Actors: | BronzePresident, BronzeSilhouette, CamaroDragon, DEV-0391, EarthPreta, EtherealPanda, FlaxTyphoon, HoneyMyte, InsidiousTaurus, ISOON, LuminousMoth, MUSTANGPANDA, QTCYBER, RedDelta, Redfly, RedJuliett, RedLich, SaltTyphoon, StatelyTaurus, Storm-0391, Storm-0919, TA416, Tantalum, TEMPHex, TwillTyphoon, UNC3236, UNC5007, VanguardPanda, VoltTyphoon, Voltzite |
| Attacker Countries: | China |
| Attacker IPs: | 154[.]64[.]238[.]222, 206[.]119[.]167[.]207 |
| Attacker Domains: | fastlink[.]ws, jump[.]qt-proxy[.]org, jump[.]qt-team[.]com, mq-result[.]qt-proxy[.]org, mq-result[.]qt-team[.]com, mq-task[.]qt-proxy[.]org, mq-task[.]qt-team[.]com, qt-proxy[.]org, qtproxy[.]xyz, qt-team[.]com, securelink[.]qtproxy[.]xyz, www[.]qtproxy[.]xyz |
| Attacker Hashes: | 00b0045e9e28b89946e7e839ac910f1f2e6f3c28937839aff3b0b41008c80188, 08dc78ae82d9c480420f7cfa797334c8976077a02df5f6b4cee3072ed4a197f9, 0cf8ed7064d3d4827f841451c661d788d4cf7d067901e35a7a019f1c9d5ef656, 0d48039b416a236f6e0e0fd702b5a824e8c7118af597c81271c64bd6b0adfec2, 12b1f2078fcdcf792e5482308acaea8cc617c58d51019edd4a381fef52329dec, 239b9f5677b66d3dc69e003028d041c09440330dd367763e68c0a56454afd91a, 26c9b561e431d033aa16f94580bfa7ace390a1c9c6834a0ee1a6b0a9a306485c, 27eb761a029d5ee4cee1d6a1ad3b60400b91723b6927cdc0032d97d8c9e636a3, 2d29f9f75e40e5b58cb4379d44ff7b511620e8dea584ffaf4db6a7597ee23562, 32876e31b1ef1b300ab4cb65ce647b110b6b801bc4e46aad3e43d406b96a6f33, 4a7a9354c5764a0977a004f3bf590db8c86ea747d170bf9a1541b8c7cfcf4009, 5329f26cc11cba660382f58f388d2dad50e10e2ba37d0d6002622c8061b211b2, 5653a062a37d8a650c9a603cee0e7744af128bad28be8916c9de9ac16f1a82e5, 5c0708b7a7a7ca00188b40df6b80f4875b2e430b2b0c38b68dd9428bfcb98d09, 5fb500afd83fb64f64a2789abc66f0a158d915167e1def6ba56d9543dd9de3d7, 6547c0f20c7770bb228b9b0ac61a6d2e16e74afad37b62bcecc7e69b51354a87, 69a20babb22ffb372733900cb2e6739598b316aecdbc0394ce8029717ee13089, 6decf77b1a3595374a15a014bbb9ac9774f67dca7df59ccf4b734a68d9e35224, 7a4c87677d7892b66c30c82ea72893bd29cfe793fade45222b4cf853b877d300, 7bba7912b7fc01795b3a0503d0e546087990124a2256b083c1c5a498a205a721, 86881181d7244a8e9d45f5fe1e2b7f4c3e8bd6cd1e6383c92693ee956c4d87fb, 92e9c9c36d469d56fbeba052d3062b77cd869c6df8f10faafd184717c557a245, 9759492bc73a1704d6d71c6f40ab5321a095f9ab2ae5ca069dd4f7b3a98235fa, 996b3aedb34426184ca4f8141daec29a0c5785b11e7eea47559f2e0ef1e6180a, a617e06c27d3514c57fd83711c75846d798e6ecefd5a0246b5ac9a191392e98a, ab745ad10ffcbf65acdf171cd47d20aed581ac07304570d96caffacc6ece2651, ad2fae2894432da7b82fec0d5d3a75b5ffa1b84a50ad67477b6063a1769a3846, b3b32e592a73d46566c51ed18c07155ad3d980142f1a4c32c4e9728208c02fce, ba20494fe5a12955a408f076c3677bf8ae600c890554b9906049b8cd07206cfb, bb1428134f6f587d63a3092ef125a7a2ac50fda3ee71b830bf725f20956b0d3f, bea44e8cbf35c240c9cddc88284b6f8f94129e4e0a42a85e2603406980b83990, c1381b35c21aec9e74e8d42b60c4733abd23fd012c75ab0e9101e37c9be62a7a, c337b92789987efe8ae0afcd56da948b38aa4b0e5859f2d51a61e2bc152c1feb, c46944343b7e33c0f88ca9583b8145a4735d6e9780f9df1777b4c59887b56a35, c73bd1c498a147e71e345a99f5f85e3442243c2a7b7cb65f0d00a72acc0a87e7, c7abdd66dae9f0e190361d7a39a73128e9d7dc3da338c02f3d93488786813eb3, ce8832b4681e63118c159f379de82f8c97adc62a81c19cae903d1ba0e5629cf1, d810f1253ee4bee05ca96a70a9c293f2839fb00b2aa238861f7b89e3a66bd357, dbcd1588caae92b7525aac096b7ec8c543b5ab8c4c95dfb33051d42c351e19b3, dc0624c316667b89aa88afa716933235584a27d14b2a08606e43a657a95db991, dd014653fce1fe5f19d1b0e1ad5f254118ca6d002e29c549ecb15029ed0a381e, e939954618ec089485eff4de098f6c5ce4d672acfd03150f5f0b38bbecbba664, ea89a969d7a4e4b9c3da24577fe2d633f74c4f25fd1494905063b40b57aeca31, ed24ea239799e470c66d160eb7b097ab1d7627fc6c51236d6169da920f5b3b5c, ef1b84fa1f3087415ba1e798b018f35c675de1032723579e38d81f79dcc37878 |
| Victim Industries: | Aerospace, Cloud Infrastructure, Defense, Education, Energy, Financial Services, Government, Healthcare, Information Technology, Retail, Telecommunications, Utilities |
| Victim Countries: | Taiwan, United States |
Mitigation Advice
- Immediately patch all internet-facing Ivanti Cloud Services Appliance (CSA) instances against CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380.
- Immediately patch all internet-facing Check Point Quantum Gateway devices against CVE-2024-24919.
- Immediately patch all internet-facing BeyondTrust Remote Support (RS) instances against CVE-2026-1731.
- Immediately patch all internet-facing CrushFTP servers against CVE-2025-31161.
- Immediately identify and patch all systems vulnerable to Log4Shell (CVE-2021-44228) by updating Apache Log4j libraries to the latest secure version.
- Immediately patch all internet-facing Atlassian Confluence servers against CVE-2023-22515.
- Immediately patch all internet-facing Pulse Secure VPN appliances against CVE-2019-11510.
- Immediately patch all internet-facing Fortinet FortiOS SSL VPN devices against CVE-2018-13379.
- Immediately patch all internet-facing Citrix Application Delivery Controller (ADC) and Gateway appliances against CVE-2019-19781.
- Immediately patch all Microsoft Exchange servers against the ProxyLogon vulnerability (CVE-2021-26855).
- Immediately patch all F5 BIG-IP appliances against CVE-2020-5902.
- Immediately patch all web servers running Kentico CMS against CVE-2019-10068.
- Download the IOCs from the 'QTFY_IOC_Files.csv' and 'QTFY_IOC_Infrastructure.csv' files mentioned in the advisory and conduct a retrospective search in SIEM, firewall, proxy, and DNS logs for any matches. Investigate all hits before implementing any blocking rules.
- Perform an immediate scan of all internet-facing web servers, especially those running Content Management Systems (CMS), for the presence of web shells or other unauthorized scripts.
Compliance Best Practices
- Develop and implement a network segmentation strategy based on Zero Trust principles to isolate critical internal systems from internet-facing edge devices and services.
- Establish a formal asset lifecycle management program to identify, track, and create a replacement plan for all hardware and software that is approaching or has passed its End-of-Life (EOL) or End-of-Support (EOS) date.
- Configure security monitoring tools to baseline normal traffic patterns and create alerts for anomalous authentication activity originating from commercial proxy services, residential IP ranges, and cloud providers like Alibaba Cloud.
- Implement monitoring on network devices, including IoT and SOHO routers, to detect unauthorized outbound connections, SOCKS5 proxy behavior, or the presence of tools like Clash.
- Implement a recurring security audit process for all public-facing web applications to identify and remove exposed secrets, API keys, tokens, and sensitive configuration details.
- Implement an automated patch management system for operating systems and third-party applications on servers and endpoints to reduce the time window between vulnerability disclosure and patch deployment.
PaperCut NG and MF Facing Active Zero-Day Exploitation
PaperCut has issued an urgent warning regarding the active zero-day exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. In response to confirmed customer compromises, emergency patches have been released for public-facing PaperCut NG/MF application servers, and administrators are urged to immediately restrict web interface access to trusted IP addresses using firewalls or network access controls. Identified indicators of compromise (IOCs) include suspicious activity originating from the legitimate `pc-app.exe` process, modified or missing `server.log` files, and specific log errors such as "ERROR No suitable driver found for jdbc:no:x" and "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST". Although details regarding the threat actors and post-exploitation activities remain undisclosed, historical precedents with prior PaperCut flaws like CVE-2023-27350 show a pattern of exploitation by ransomware groups, including Clop, LockBit, and Bl00dy, as well as state-sponsored actors for initial network access.
Severity: High
Threat Details and IOCs
| Malware: | ABCD, Bl00dy, Cl0p, Clop, CryptoMix, LockBit, LockBit Black, LockBit Green, LockBit Red |
|---|---|
| CVEs: | CVE-2023-27350 |
| Technologies: | Microsoft Windows, PaperCut MF |
| Threat Actors: | Bl00dyRansomwareGang, Clop, FIN11, GracefulSpider, LockBit, Ta505 |
| Attacker Countries: | Iran |
| Victim Industries: | Education |
| Victim Countries: | United States |
Mitigation Advice
- Apply the emergency patches for PaperCut NG and PaperCut MF to all servers immediately, prioritizing those exposed to the internet.
- Use firewall rules or network access controls to immediately restrict all access to PaperCut Application Server web interfaces, allowing connections only from explicitly trusted internal IP addresses.
- Scan all PaperCut server.log files for the specific error messages 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST' to identify potential compromise.
- Investigate PaperCut servers for signs of compromise by checking file integrity of server.log files and analyzing process monitoring logs for any anomalous activity associated with the pc-app.exe process.
Compliance Best Practices
- Re-architect network access to eliminate all direct internet exposure for PaperCut servers, mandating that all administrative access occurs via a secure solution like a VPN with multi-factor authentication.
- Implement network segmentation to isolate print management servers from the broader corporate network, strictly limiting their communication paths to only what is required for their function and preventing access to critical assets like domain controllers and databases.
- Configure PaperCut servers to forward application and system logs to a central SIEM and create automated detection rules to generate alerts for the specific IOCs mentioned in the advisory and other suspicious activities.
- Formally classify PaperCut servers as critical assets within the vulnerability management program, subjecting them to more frequent automated scanning and a stricter patching SLA.
CVE-2026-31431 'Copy-Fail' Local Privilege Escalation in Linux Kernel
CVE-2026-31431, also known as "Copy-Fail," is a high-severity local privilege escalation vulnerability (CVSS 7.8) residing in the Linux kernel's `algif_aead` module, which implements the AEAD (Authenticated Encryption with Associated Data) interface within the `AF_ALG` socket family. The vulnerability is caused by an out-of-bounds write that occurs during `sendmsg()` and `recvmsg()` operations when the output buffer is smaller than expected; specifically, the kernel executes a `copy_to_user` operation via `algif_aead_copy_sgl()` and `sg_copy_to_buffer()` without properly validating the buffer size, allowing an unprivileged local attacker to overwrite adjacent kernel heap structures and escalate privileges to root. This flaw affects Linux kernel versions prior to 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, and 7.0, with active exploitation demonstrated on systems running vulnerable branches such as kernel 6.2.x. Remediation requires upgrading to a patched kernel version, though immediate mitigations include blacklisting the `algif_aead` module, disabling unprivileged user namespaces by setting ``kernel.unprivileged_userns_clone=0`,` or restricting `AF_ALG` socket creation using AppArmor policies.
Severity: Critical
Threat Details and IOCs
| CVEs: | CVE-2026-31431 |
|---|---|
| Technologies: | Linux Kernel |
| Attacker Domains: | github[.]com, raw[.]githubusercontent[.]com, sploitus[.]com |
| Attacker URLs: | hxxps[://]github[.]com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431, hxxps[://]github[.]com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431/raw/main/copyfail, hxxps[://]github[.]com/mfloresdacunha/CVE-2026-31431.git, hxxps[://]github[.]com/tgies/copy-fail-c, hxxps[://]raw[.]githubusercontent[.]com/mfloresdacunha/CVE-2026-31431/main/exploit.py, hxxps[://]raw[.]githubusercontent[.]com/mfloresdacunha/CVE-2026-31431/main/test_cve_2026_31431.py, hxxps[://]sploitus[.]com/exploit?id=KITPLOIT:TOOLS-GITHUB-ALVAROGUZMANCODE-CVE-2026-31431-MITIGACION |
| Victim Industries: | Industrial Sector, Technology Hardware |
| Victim Countries: | Thailand |
Mitigation Advice
- Identify all Linux systems running vulnerable kernel versions (e.g., < 5.10.254, < 5.15.204, < 6.1.170) and apply the latest kernel security updates provided by your distribution vendor using commands like `sudo apt update && sudo apt dist-upgrade` or `sudo dnf update`.
- On systems that cannot be immediately patched, prevent the vulnerable `algif_aead` module from loading by adding it to the modprobe blacklist. Execute `echo "blacklist algif_aead" | sudo tee /etc/modprobe.d/blacklist-algif-aead.conf`, then run `sudo update-initramfs -u` and reboot the system as soon as a maintenance window is available.
- On systems where it will not break critical functionality (e.g., Docker), disable unprivileged user namespaces by running `sudo sysctl -w kernel.unprivileged_userns_clone=0`. To make this change persistent across reboots, add `kernel.unprivileged_userns_clone=0` to a configuration file in `/etc/sysctl.d/`.
- For systems using AppArmor, update the profiles for at-risk services, such as web servers running as `www-data`, to explicitly deny access to the `AF_ALG` socket family. Add the rule `deny network af_alg,` to the relevant AppArmor profile and reload it using `sudo apparmor_parser -r /etc/apparmor.d/<profile_name>`.
- Run vulnerability scans or manual checks across all Linux assets to identify systems with vulnerable kernel versions and the loaded `algif_aead` module. Use the commands `uname -r` and `lsmod | grep algif_aead` to confirm exposure on individual hosts.
Compliance Best Practices
- Establish a formal patch management policy and program that defines schedules for testing and deploying kernel and operating system security updates. Ensure the program includes a comprehensive asset inventory to track all Linux kernel versions in the environment.
- Conduct a comprehensive review of all user and service accounts on Linux systems to enforce the principle of least privilege. Remove unnecessary permissions, disable interactive shell access for service accounts where not required, and limit their access to only essential files and directories.
- Develop and deploy a comprehensive Mandatory Access Control (MAC) security policy using AppArmor or SELinux. Create default-deny profiles for all internet-facing services and critical applications to restrict their system call access and limit the impact of a potential compromise.
- Configure endpoint security tools (e.g., EDR) or system auditing (e.g., auditd) to monitor for and alert on anomalous usage of the `AF_ALG` socket interface, especially from unexpected processes like web servers or common user shells. Forward these logs to a SIEM for correlation and alerting.
GPUThor Rowhammer Exploit Bypasses ECC on NVIDIA Ampere GPUs for Root Access
Researchers at the University of Toronto have developed a new Rowhammer-class exploit called GPUThor that successfully bypasses Error-Correcting Code (ECC) and Target Row Refresh (TRR) protections on Ampere-generation NVIDIA GPUs equipped with GDDR6 memory, including the RTX A4000, RTX A4500, RTX A5000, and RTX A6000. By restructuring memory request sequences to align with the GPU's memory controller operations, GPUThor achieves memory corruption significantly faster than previous techniques, producing between 72,000 and 377,000 bit flips per gigabyte and locating exploitable faults in approximately 1.1 minutes compared to the 21.9 hours required by GPUHammer. Even with ECC enabled, the attack triggered 387 uncorrectable double-bit faults and two triple-bit errors, and it successfully demonstrated a denial-of-service condition on the RTX A6000. Furthermore, by corrupting the GPU's page tables, an unprivileged program running on the CUDA platform gained arbitrary memory access and escalated privileges to open a root shell on the host system. In response, NVIDIA recommends enabling memory error correction alongside hardware-based direct memory access isolation, monitoring for GPU errors, and restricting untrusted workloads, while researchers advise against sharing a single GPU across multiple tenants in cloud environments.
Severity: Critical
Threat Details and IOCs
| Technologies: | Linux, NVIDIA, NVIDIA Ampere |
|---|---|
| Attacker URLs: | github[.]com/sith-lab/gputhor |
| Victim Industries: | Cloud Infrastructure, Semiconductors |
| Victim Countries: | United States |
Mitigation Advice
- Inventory all systems to identify NVIDIA Ampere-generation graphics cards with GDDR6 memory, specifically the RTX A4000, RTX A4500, RTX A5000, and RTX A6000 models.
- On systems with affected NVIDIA GPUs, enable hardware-based Direct Memory Access (DMA) isolation, such as IOMMU or VT-d, in the system's UEFI/BIOS settings.
- Verify that memory Error-Correcting Code (ECC) is enabled on all identified vulnerable NVIDIA GPUs and their host systems.
- Configure system monitoring and alerting to detect and report GPU errors, specifically focusing on uncorrectable ECC errors and unexpected GPU resets on systems with affected NVIDIA cards.
- Immediately review and restrict the execution of untrusted or unnecessary applications, especially those utilizing the CUDA platform, on workstations equipped with the affected NVIDIA GPUs.
Compliance Best Practices
- Develop and implement a formal policy that prohibits sharing a single physical GPU among multiple users or virtual machines (multi-tenancy), especially in environments handling sensitive data.
- Implement a comprehensive application control solution, such as application whitelisting, on high-risk workstations to ensure only approved, signed, and vetted software can execute.
- Incorporate the GPUThor vulnerability findings into the hardware lifecycle and procurement process, prioritizing GPUs with more robust hardware-level protections for future purchases, especially for multi-user or high-security workloads.
- Integrate GPU-specific error logs into the central Security Information and Event Management (SIEM) system and tune Endpoint Detection and Response (EDR) rules to correlate GPU faults with suspicious process activity on the host system.
AuraStealer, ACRStealer, and Remus Stealer Show Malware-as-a-Service Trend, With Remus Using Ethereum for C2
The rise of malware-as-a-service (MaaS) has significantly lowered the barrier to entry for cybercriminals, driving the proliferation of sophisticated infostealers that target credentials, session tokens, and cryptocurrency wallets. Recent threat intelligence highlights three active infostealer families: AuraStealer, ACRStealer (also known as Amatera), and Remus Stealer. AuraStealer, which emerged in July 2025, recently integrated virtualization techniques in summer 2026 to obfuscate its code, increasing its file size from under 1 MB to 10 MB. ACRStealer, active since 2018, underwent a rebranding and technical alignment with the Amatera family following a brief hiatus in 2024. Remus Stealer, emerging in early 2026, functions as a 64-bit variant of LummaStealer, sharing its string obfuscation and application-bound encryption override methods, but distinguishing itself by utilizing Etherhiding via Ethereum smart contracts for command-and-control communications. These threats are primarily distributed through social engineering vectors such as ClickFix, ClearFake, and search engine optimization (SEO) poisoning campaigns, which trick users into executing malicious payloads.
Severity: High
Threat Details and IOCs
| Malware: | AcridRain Stealer, ACRStealer, Amadey, Amadey Bot, Amatera, AuraStealer, G-Cleaner, GCleaner, Lumma, LummaC2, Lumma Stealer, LummaStealer, OffLoader, Remus, Remus Stealer, RemusStealer, Tenzor |
|---|---|
| CVEs: | CVE-2024-21412 |
| Technologies: | Google Chrome, Microsoft Outlook, Microsoft Windows |
| Threat Actors: | Amatera, AngryLikho |
| Attacker Countries: | Russia |
| Attacker IPs: | 143[.]244[.]141[.]187, 147[.]135[.]84[.]14, 148[.]230[.]76[.]66, 158[.]94[.]208[.]7, 158[.]94[.]211[.]222, 165[.]227[.]123[.]79, 167[.]99[.]78[.]100, 77[.]42[.]90[.]175, 85[.]239[.]147[.]6, 91[.]92[.]241[.]243, 91[.]92[.]242[.]236 |
| Attacker Domains: | aetherfluxnode10[.]lol, aetherfluxnode1[.]lol, aetherfluxnode2[.]lol, aetherfluxnode3[.]lol, aetherfluxnode4[.]lol, aetherfluxnode5[.]lol, aetherfluxnode6[.]lol, aetherfluxnode7[.]lol, aetherfluxnode8[.]lol, aetherfluxnode9[.]lol, aethersyncmatrix10[.]lol, aethersyncmatrix1[.]lol, aethersyncmatrix2[.]lol, aethersyncmatrix3[.]lol, aethersyncmatrix4[.]lol, aethersyncmatrix5[.]lol, aethersyncmatrix6[.]lol, aethersyncmatrix7[.]lol, aethersyncmatrix8[.]lol, aethersyncmatrix9[.]lol, aewaterdelivery[.]com, aimemtools[.]cfd, alphagridnexus10[.]lol, alphagridnexus1[.]lol, alphagridnexus2[.]lol, alphagridnexus3[.]lol, alphagridnexus4[.]lol, alphagridnexus5[.]lol, alphagridnexus6[.]lol, alphagridnexus7[.]lol, alphagridnexus8[.]lol, alphagridnexus9[.]lol, approe[.]shop, auth[.]automationportal[.]cc, azurhay[.]shop, carogra[.]biz, chalx[.]live, cryptomeshforge10[.]lol, cryptomeshforge1[.]lol, cryptomeshforge2[.]lol, cryptomeshforge3[.]lol, cryptomeshforge4[.]lol, cryptomeshforge5[.]lol, cryptomeshforge6[.]lol, cryptomeshforge7[.]lol, cryptomeshforge8[.]lol, cryptomeshforge9[.]lol, cyberdriftmatrix10[.]lol, cyberdriftmatrix1[.]lol, cyberdriftmatrix2[.]lol, cyberdriftmatrix3[.]lol, cyberdriftmatrix4[.]lol, cyberdriftmatrix5[.]lol, cyberdriftmatrix6[.]lol, cyberdriftmatrix7[.]lol, cyberdriftmatrix8[.]lol, cyberdriftmatrix9[.]lol, data[.]nomadhive[.]cc, datapulseforge10[.]lol, datapulseforge1[.]lol, datapulseforge2[.]lol, datapulseforge3[.]lol, datapulseforge4[.]lol, datapulseforge5[.]lol, datapulseforge6[.]lol, datapulseforge7[.]lol, datapulseforge8[.]lol, datapulseforge9[.]lol, dev-tools[.]cfd, digitalwavehub10[.]lol, digitalwavehub1[.]lol, digitalwavehub2[.]lol, digitalwavehub3[.]lol, digitalwavehub4[.]lol, digitalwavehub5[.]lol, digitalwavehub6[.]lol, digitalwavehub7[.]lol, digitalwavehub8[.]lol, digitalwavehub9[.]lol, dikdiy[.]xyz, dolmaq[.]shop, dreaub[.]top, edge[.]kernelmonitor[.]cc, ethereum-rpc[.]publicnode[.]com, fasea[.]top, fightwa[.]biz, fimmora[.]surf, fluokq[.]xyz, freshis[.]biz, hooiuse[.]click, hypercorevector10[.]lol, hypercorevector1[.]lol, hypercorevector2[.]lol, hypercorevector3[.]lol, hypercorevector4[.]lol, hypercorevector5[.]lol, hypercorevector6[.]lol, hypercorevector7[.]lol, hypercorevector8[.]lol, hypercorevector9[.]lol, login[.]metricsdashboard[.]cc, memaiagent[.]cfd, metaforgechain10[.]lol, metaforgechain1[.]lol, metaforgechain2[.]lol, metaforgechain3[.]lol, metaforgechain4[.]lol, metaforgechain5[.]lol, metaforgechain6[.]lol, metaforgechain7[.]lol, metaforgechain8[.]lol, metaforgechain9[.]lol, myrtler[.]biz, neuralcoreflux10[.]lol, neuralcoreflux1[.]lol, neuralcoreflux2[.]lol, neuralcoreflux3[.]lol, neuralcoreflux4[.]lol, neuralcoreflux5[.]lol, neuralcoreflux6[.]lol, neuralcoreflux7[.]lol, neuralcoreflux8[.]lol, neuralcoreflux9[.]lol, neuralcorepulse10[.]lol, neuralcorepulse1[.]lol, neuralcorepulse2[.]lol, neuralcorepulse3[.]lol, neuralcorepulse4[.]lol, neuralcorepulse5[.]lol, neuralcorepulse6[.]lol, neuralcorepulse7[.]lol, neuralcorepulse8[.]lol, neuralcorepulse9[.]lol, neuralorbitgrid10[.]lol, neuralorbitgrid1[.]lol, neuralorbitgrid2[.]lol, neuralorbitgrid3[.]lol, neuralorbitgrid4[.]lol, neuralorbitgrid5[.]lol, neuralorbitgrid6[.]lol, neuralorbitgrid7[.]lol, neuralorbitgrid8[.]lol, neuralorbitgrid9[.]lol, neurostreamlink10[.]lol, neurostreamlink1[.]lol, neurostreamlink2[.]lol, neurostreamlink3[.]lol, neurostreamlink4[.]lol, neurostreamlink5[.]lol, neurostreamlink6[.]lol, neurostreamlink7[.]lol, neurostreamlink8[.]lol, neurostreamlink9[.]lol, nexuswavecore10[.]lol, nexuswavecore1[.]lol, nexuswavecore2[.]lol, nexuswavecore3[.]lol, nexuswavecore4[.]lol, nexuswavecore5[.]lol, nexuswavecore6[.]lol, nexuswavecore7[.]lol, nexuswavecore8[.]lol, nexuswavecore9[.]lol, noevara[.]shop, omnidataflow10[.]lol, omnidataflow1[.]lol, omnidataflow2[.]lol, omnidataflow3[.]lol, omnidataflow4[.]lol, omnidataflow5[.]lol, omnidataflow6[.]lol, omnidataflow7[.]lol, omnidataflow8[.]lol, omnidataflow9[.]lol, onesdto[.]shop, orbitmeshlink10[.]lol, orbitmeshlink1[.]lol, orbitmeshlink2[.]lol, orbitmeshlink3[.]lol, orbitmeshlink4[.]lol, orbitmeshlink5[.]lol, orbitmeshlink6[.]lol, orbitmeshlink7[.]lol, orbitmeshlink8[.]lol, orbitmeshlink9[.]lol, pivotq[.]top, quantumbytehub10[.]lol, quantumbytehub1[.]lol, quantumbytehub2[.]lol, quantumbytehub3[.]lol, quantumbytehub4[.]lol, quantumbytehub5[.]lol, quantumbytehub6[.]lol, quantumbytehub7[.]lol, quantumbytehub8[.]lol, quantumbytehub9[.]lol, quantumpulsegrid10[.]lol, quantumpulsegrid1[.]lol, quantumpulsegrid2[.]lol, quantumpulsegrid3[.]lol, quantumpulsegrid4[.]lol, quantumpulsegrid5[.]lol, quantumpulsegrid6[.]lol, quantumpulsegrid7[.]lol, quantumpulsegrid8[.]lol, quantumpulsegrid9[.]lol, res[.]explicittweak[.]cc, secupd[.]cfd, sgw[.]portallbridge[.]cc, slyfogx[.]shop, softwareguard[.]cfd, static[.]quorashift[.]cc, stellarnodegrid10[.]lol, stellarnodegrid1[.]lol, stellarnodegrid2[.]lol, stellarnodegrid3[.]lol, stellarnodegrid4[.]lol, stellarnodegrid5[.]lol, stellarnodegrid6[.]lol, stellarnodegrid7[.]lol, stellarnodegrid8[.]lol, stellarnodegrid9[.]lol, stream[.]pawpalace[.]cc, sys-tools[.]cfd, tensorforgegrid10[.]lol, tensorforgegrid1[.]lol, tensorforgegrid2[.]lol, tensorforgegrid3[.]lol, tensorforgegrid4[.]lol, tensorforgegrid5[.]lol, tensorforgegrid6[.]lol, tensorforgegrid7[.]lol, tensorforgegrid8[.]lol, tensorforgegrid9[.]lol, topxgax[.]click, tzpx[.]courses, uiccvbk[.]click, vectorquantforge10[.]lol, vectorquantforge1[.]lol, vectorquantforge2[.]lol, vectorquantforge3[.]lol, vectorquantforge4[.]lol, vectorquantforge5[.]lol, vectorquantforge6[.]lol, vectorquantforge7[.]lol, vectorquantforge8[.]lol, vectorquantforge9[.]lol, vectorquantnexus10[.]lol, vectorquantnexus1[.]lol, vectorquantnexus2[.]lol, vectorquantnexus3[.]lol, vectorquantnexus4[.]lol, vectorquantnexus5[.]lol, vectorquantnexus6[.]lol, vectorquantnexus7[.]lol, vectorquantnexus8[.]lol, vectorquantnexus9[.]lol, vertexpulsecore10[.]lol, vertexpulsecore1[.]lol, vertexpulsecore2[.]lol, vertexpulsecore3[.]lol, vertexpulsecore4[.]lol, vertexpulsecore5[.]lol, vertexpulsecore6[.]lol, vertexpulsecore7[.]lol, vertexpulsecore8[.]lol, vertexpulsecore9[.]lol, wss[.]vectorplatform[.]cc, youngel[.]biz, zelpx[.]garden, zkevopenanu[.]cfd |
| Attacker URLs: | hxxp[://]158[.]94[.]208[.]7/files/8705834433/8njNDcy.exe, hxxp[://]158[.]94[.]211[.]222/files/1660459253/W3Trdgs.exe, hxxp[://]158[.]94[.]211[.]222/files/bur/fast.exe, hxxp[://]85[.]239[.]147[.]6/files/5851730241/IQEr4wy.exe, hxxp[://]85[.]239[.]147[.]6/files/Leetootoo/random.exe, hxxp[://]91[.]92[.]241[.]243/files/file_391c1e83ac309020.exe, hxxp[://]91[.]92[.]242[.]236/files-129312398/files/file_03e1dd22b8ec149f.exe, hxxp[:]//azurhay.shop:8539, hxxp[:]//carogra.biz:4219, hxxp[:]//fimmora.surf:6504, hxxp[:]//freshis.biz:7752, hxxp[:]//hooiuse.click:4938, hxxp[:]//myrtler.biz:9549, hxxp[:]//onesdto.shop:2535, hxxps[:]//dwn.metaforgechain4.lol/g/zip/..., hxxps[:]//ethereum-rpc.publicnode.com, hxxp[:]//slyfogx.shop:5776, hxxp[:]//topxgax.click:4930, hxxp[:]//tzpx.courses:4437, hxxp[:]//uiccvbk.click:8839, hxxp[:]//youngel.biz:8768, hxxp[:]//zelpx.garden:9895 |
| Attacker Hashes: | 00b639b26e321b308ecff93998ee33637bde2a9e198b42208ab70ff9dabe35ee, 049545b6d7e2ae529a6c754c555164a79b4ebe90da7c56155c9a4282c01304de, 06f6a0dc417bf0c8d1fa54754f53d37d190a3b9bf66658e00a630ae0bb56dfab, 08057bea6ee1cc68c1f1bdcbe702a3558270d8f19cc329b8b34bcd133984da86, 0843ddfbe1908c5151495295ff7d1007b3c8bca287a766c437cea6b0e3f72f4d, 08fd3ce1ca451b1dffd00c657b6ac1ad8ad769171faa1ba9688b572283d32cd7, 0d2c9e04fcdb10ff2d4565758ceda1331fc80def548742a79b60be81da9b9d3b, 1019d8a20bd7732b2c2747b30646a5d10725fd5ee532b5e858dab27ba150db1e, 10ce9e01292433f1e1163abb6a8896e3ebb2269a0489fa91a1dec7d54fec5c92, 15ba6382ab6244d3d36036280e1ec3e438f442759b6917e6bc19bcb29f1d3d7e, 1a398687d1f626e71c3beec3b0bda9589415babbcdae6171293c097d3103472e, 1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9f68, 1c11f37cbf8365d26d243515cd23e822ecfa1d25f3262b62ffb1085efd09d9c2, 205fc66381b8e254508d40c693a1314c9fc2b94b8023b29483803c8b0e449c4d, 231123d03fa985bdb4edbcc45fafc8f4fb93f692b00f6f37df81435cd0ff1c7b, 26530b7c8d9c8a48d16c94670cc9755f09b0d09efa92d65fbd1f9c7ebadce663, 27bfec23f77b6c9f2addd7f1fe8016b41078c8dbdda34737f7cb6b5563ec22b4, 28c30dc88160f1fc44a5c11976f9de8da06be3c996d50ef76b0dbd032da210b6, 28d1f5d695ed65461b36f032f057a2d48b97ea68f149c73ea3401bf9ec0576cb, 2ab248b392653566fe4fb34e2ced50acd8e91941010f38e2a85c792968261f20, 2c92e4a8d22fc18a4e7510fc7ea4a207be80c5028bdc25f2aa06f7aa21627dba, 30a24d6aed654adff341b2c6ad2ba6c971c028dfce1ca455a37d1fbdf4617ab8, 35392a9849d7e9dfb4ee700a16700a94883fde859d57fdd891631bdbc6a75db0, 37280893d138dcc18a14ae4f5e4a13d71419da82ba978d7dcad510af95e86aa2, 41b3e4f80aa2deeaf56c5181cd3fc1b2ee545d053d29934408bb17ddd7ea2096, 41bcdaec2580058bfcbf8415ae123c7d9907c688cb107df79e20024e3bc23e2e, 42871749873401e97d2651c5bc1c874ae9a3832a1c14b48630390dff0acafc09, 4332227474b0d7db91a1e156ac3afa58ea4973ff00cb455dfd073fa1ec6dabcd, 44d8e760012d6f08e91fd59176e59a3e13326f8079cdcc6e3a43b30f040769b6, 450216a711f8b3371a2936923201f204fa1c686a2b831dac4a1c0094c105a5fd, 45357593df7614af68592c0f1ef578f824dc6c9d82f7a6198b21be7c06a57d69, 51bfb2f390653647b087d789ef1559c3fdf220c565a909f1eee4d593893420dd, 52ad5844e88d5e3da533f8d913442cdc72d018ed29594a994e19a403026aa0d3, 57c1b9fe23cd8220f39383c2ab5b392e8f1416cbf75e2668fc6426294abb818f, 5b5434cc8bb3556075c6967d2ffee5a6b33793de07b9d4701bc63d369de63861, 5df134ab4b33ab555f3a77d43e94891698834a9b739b065764a702c7c52e3f4c, 5fd126063af89eb1c5639a56dcf365f2e817813a45758b3f12a18f12d5561d14, 67397566a51d405c351e5134650463d5872e218682f7f34a5f314539d087837e, 6758769a19ce049454101441e8d9e29b02c13a62146a43fa7b5692cff09ddf30, 67873a847a2b996bd3b44b38c819768274efda6daf2978532c7b6b4f1a0acb11, 682fc6e8ea93f44c2c86fcd06e664971f42e8290a534c65a32a92d9b53a14b40, 683c423efa53f048b26c3b1c530e2598d7b55833fbe3b198cd5f13a9986fb42a, 69a11394f6ee9d2af144f57d47632806f0760d5f1bdb69310a000b436ee3b5bc, 69d4b349416a93227b332b50a0d6aa38ec522d528f31f4400f248b247fd607e3, 6a771b99ea4fa87af203a786608d3f7396d1698f43242905a66e6f9539df60e5, 6aa279fe9991405963ddf7ab18116fcde85190c2639b830791fe903d90697dec, 6e69bc51a02e619fcae64815445b5d8232d38361d3b055677687621e9b29c7ad, 77e1b540fd76b28638231ca69f955130768ea9de045e6af18b6e5b88e59211d4, 7a7a38d8e7d729aa0d9312fae2ebd13b7c11a5ae91474a883b7ceb56298f3958, 7b092a35e70113f5165a653135cb3a7ca29312ceb0b4a874c160473d30830a60, 80965fa878946421e5778044fcb16bc523206eb8f3853c0f833e9dbb87fe24f1, 8b82c79a90ed401449260948b269d0909bbdb53847678dfbba09c368016bd7e6, 935b9d36e8b6ac544a9a990bcccda8eb346596fbbcb5259bc929835b737c4d27, 959e77a7733be97f17a64c949ef061c9fe5b23ebf3b8a171cad8f4f094ecf62f, 9d02336c331bd335887c04ee466be41bc1a2a7e9069a9e9aaca2765484af0f14, 9ee3575caf8bd87912689ebb1d13770990248f93c5d882db8c849bee02cb7c0a, a1f23f90cd08417a86783f9c0f80c31cc621e852091f2e7ad724b89f74f11c85, a3cf2cd75d78359f4ee1bc64703864781ffd8b93145c58a82078342b8097cef6, a43efc1f87e3f0566daef895ddccf21dff9eb70fbea17ec7d60ba7fdceb35c1b, a84ab5bc2462fa6f673f22f59e759de458d4e561763af3be0bc3397564272347, abb2d9250e78af3b0636a83f6031a14512d7d891e34a043cafc771f2ac3ea121, af61581328f2df00b47971c2b3882122ab7e52416dc4ac2a9637ea8255810f73, b29391ba505af508f2110f54f73b203e2710b8b6c8a8717005e5c7a4050630e1, ba32766e087f5a6855fa7da9feea2968280a019aec31d7d173adcd4b848caf3e, bad93389f4234f81358fa29c65473b5bfc3c60ab7b3c2189185988f03a66aeda, bfad1100bc3054dd26151c7acea412960ece04c3aa075ba323c10cf75c31a9a4, c35c4ca7a9c5170587e4e8f0100f3730082e2a872e74129e38f26d3107e7e0c8, c5860e0e6bdbc49ae5f07d85989469a41a108dede6f6086541d276ccc155fe99, c8730e9e0bd0a41438d7d7af227f1441b4f9d8a54988e0add3a2e0fbd7312cc1, cb47ab1775a4be4ec9b997b58bedfeb2076079df0804dc80982c0309fa9a2c1e, cde41aae4e4477a62781afdaa25c3020af8ff03008cc75e6fa0d140428abb632, ce365972cd411ba22eb09d29792d6bb52dc485be9552a45200502e168d733b54, ce36e61c71aa43b274142d8be1cb6e38d4ed52336d7b76d06a761534c0da8c4c, cee7ddbeb8d937f8a6855c52cee704bb6f4a10934fcaf17544a8c31cced39b7c, d412434f9fb3d06b009c6e793938e88ab7edf71bf3180753edbcc5f1702f18ee, d703c69ec8421a5351dc02735179aee12e8257b5816108feda8716b695b49dbd, d7979fb0377c30a5361cd3f2f934c1e058a5c86031792dc66eeb24d6d7569661, d9294331c15c7ee0f4a03f8b95eda42fa065ec7d008bc326f9d8db562c118de0, d93afbd9c5718fe14d9f24a080e8debc6b83f6596babe0aad1b3a9cb5013d010, d9da446bbb8adcb72c5c086705d58a8dad9d9268606e86568b893d122384b5b3, da7935affcec91c317acf98b52eca551f2501b29ad502749e4c084492142c6eb, e008c4e82cff39aa0f4c040944f8deeb80b06c50aab558e8b84e20c8ee453418, e96c774b2c8425ab237b0fb36f57a7d8cc7e782b6d4e9a99434f3d21c93d5128, ece6e9395edb8935c993a2945ac196a614149d65f10212e912e4654981646e37, eecf2b15c3656275f7f4d4e1e4287fee795cb857790ca7eca107efa9cd6fad30, f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be4, f2636d9b60715c2ea7c032cfd20492b7701bfa72ed3652b2bc540760988a0fc8, f52809d57d816cf9ea7e95de64df46fcc1cf62d3da972c167497935b5eca74d7, f698f7919b026700cc2a2a9166258b8770ab9412122207f7b955fb97d249b8b9, f737981ac722be8ae1c05a295667d050abe1b45dd946e1dbf4c46467c517c5f5, fa65bbadec7e0d448b4d167ac48399f1f9a0966d5574b25876169171a204abab, fac8922b1afc82d02b7a2d059ec6964a0b29196166b1377d165c08e134400dbc, fb5a654149e5bdb09b1453fa7679e32826e81abbaa0114ca02b13be6408a5ee3 |
| Victim Industries: | Cryptocurrency, Financial Services, Gaming, Government, Healthcare, Information Technology, Managed Service Providers |
| Victim Countries: | Turkey |
Mitigation Advice
- Add all file hashes listed in the article for AuraStealer, ACRStealer/Amatera, and Remus Stealer to your Endpoint Detection and Response (EDR) and antivirus (AV) blocklists.
- Block all domains, URLs, and IP addresses listed as Indicators of Compromise in the article at the network perimeter using the corporate firewall and web proxy.
- Query SIEM and EDR logs for any historical or current activity matching the file hashes, domains, URLs, and IP addresses provided for AuraStealer, ACRStealer, and Remus Stealer.
- Add all domains listed as Indicators of Compromise for AuraStealer, ACRStealer, and Remus Stealer to your DNS blocklist or sinkhole.
Compliance Best Practices
- Develop and implement a recurring security awareness training program that educates users on identifying and reporting social engineering attacks, including fake software updates, malicious search results, and prompts to run scripts.
- Implement and enforce a policy via Group Policy (GPO) or Mobile Device Management (MDM) to prevent web browsers from saving user passwords and credentials.
- Deploy PowerShell Constrained Language Mode and enable script block logging across all endpoints to restrict the execution of unauthorized scripts and improve visibility into command-line activity.
- Configure network firewalls to enforce an egress filtering policy that denies all outbound traffic by default and only allows connections to known-good destinations on expected ports and protocols.
- Tune your Endpoint Detection and Response (EDR) solution to create alerts for suspicious behavioral patterns like process injection, process hollowing, and attempts by non-browser processes to access browser data stores.
- Implement a web content filtering solution to block user access to high-risk website categories, including newly registered domains, malvertising networks, and sites with poor reputation.


