Weekly Threat Intel Report — 2026-W39: 21-27 September 2026
TL;DR
ShinyHunters dominated the week on two fronts. They defaced the Clop ransomware leak site through an unpatched Grav CMS path traversal flaw, and they resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273 using URL-encoded payloads that slip past the WAF rules deployed to block that exact vulnerability. Microsoft published detailed tradecraft on Storm-2570, a ransomware affiliate that deploys Qilin, DragonForce, Anubis, and BERT with a consistent post-compromise toolkit. Microsoft's Digital Crimes Unit also disrupted EvilTokens, a device code phishing-as-a-service platform, seizing 50 websites and disabling more than 150 domains. Microsoft separately attributed agentic-driven Azure attacks using compromised service principals to Storm-3168, linked to JADEPUFFER. Supply chain risk continued with a Mini Shai-Hulud npm variant that stole 170 private CrowdSec GitHub repositories via a former employee's OAuth token. CISA flagged active exploitation of WSO2, SharePoint, and Adobe Commerce flaws, and Kiteworks urged customers to shut down servers after federal warnings of imminent targeting.
Notable Activity by Actor
ShinyHunters
ShinyHunters ran two high-impact operations this week. On 25 September, BleepingComputer confirmed that the group defaced the Clop ransomware leak site by exploiting an unauthenticated path traversal vulnerability in an unpatched Grav CMS instance. Clop migrated to a new Tor address. The group claims to have stolen victim data from the compromised server, which would expose organizations that already paid ransoms to renewed extortion, as DarkReading noted on 21 September.
On 26 September, BleepingComputer reported that ShinyHunters resumed exploitation of Oracle PeopleSoft CVE-2026-35273 after WAF vendors rolled out mitigating signatures. The bypass is a URL-encoding trick that reshapes the exploit payload enough to evade the deployed rules while remaining functional against the underlying application. Organizations relying on virtual patching rather than the vendor fix are exposed again.
Storm-2570 (new tracking)
Microsoft published a 24 September profile of Storm-2570, a ransomware affiliate that deploys Qilin, DragonForce, Anubis, and BERT ransomware. The point of the writeup is that the ransomware family varies but the pre-encryption tradecraft does not. Microsoft's guidance focuses on detecting the shared tooling and behavior earlier in the intrusion, before the payload is chosen. Both Qilin and DragonForce are named as final-stage payloads.
Storm-3168 / JADEPUFFER (new tracking)
On 25 September, Microsoft attributed a cluster of Azure intrusions to Storm-3168 and linked the activity to JADEPUFFER infrastructure. The actor authenticates using compromised service principals, then performs cloud reconnaissance, deletes resources, and accesses credentials. Service principal abuse is difficult to catch because the activity looks like automation.
INC Ransom
Huntress published a 21 September reconstruction of a three-week INC ransomware intrusion built from endpoint telemetry. The notable finding is a 17-day operator dwell period between initial access and encryption, with limited activity during the gap. Response teams working from an assumption of fast-tempo intrusions may miss slow-burn operators of this kind.
EvilTokens operators (disrupted)
Microsoft's Digital Crimes Unit disrupted EvilTokens, a phishing-as-a-service platform focused on device code phishing against Microsoft 365. The disruption, reported by Microsoft on 22 September and covered by DarkReading the same day, seized 50 websites and disabled more than 150 domains. EvilTokens combined AI-generated lures, automated infrastructure, and OAuth token theft. Disruptions of this kind reduce capacity temporarily; expect operator migration to alternative platforms.
Emerging Threats
Supply chain: Shai-Hulud persistence
The self-propagating Shai-Hulud npm campaign continued to generate incidents. DarkReading reported on 22 September that a Mini Shai-Hulud variant, delivered through compromised TanStack npm packages, stole an OAuth token from a former CrowdSec employee's system. The token was used to clone 170 private CrowdSec GitHub repositories. On 26 September, BleepingComputer reported that two third-party GitHub Actions previously compromised in the Mini Shai-Hulud campaign were re-enabled by their maintainer while still pointing to malicious code, leaving downstream consumers exposed for more than a week.
Active exploitation and vendor advisories
CISA added a critical WSO2 authentication bypass, CVE-2026-5430, plus SharePoint and Adobe Commerce flaws to the Known Exploited Vulnerabilities catalog based on observed exploitation, per BleepingComputer on 25 September. Elementor for WordPress carries a CSRF flaw that allows an unauthenticated attacker to create an administrator account. On 25 September, Kiteworks urged customers worldwide to shut down servers for a six-hour window after receiving what CISO Frank Balonis described to The Record as credible threat intelligence from federal intelligence authorities about imminent targeting. Japan's Digital Agency confirmed a breach of approximately 246,000 records following exploitation of a VPN appliance vulnerability, per Check Point Research on 21 September.
Cloud identity and agentic AI
Microsoft's Storm-3168 writeup and the ongoing Storm-2570 tracking sit alongside a set of AI-adjacent findings: Salesforce agents can be induced to smuggle attacker instructions into Slack (DarkReading, 24 September), threat actors are seeding search-optimized malicious content to poison ChatGPT, Gemini, and Google AI Overview answers (DarkReading, 23 September), and OpenAI disclosed that its agents accidentally uploaded user-provided images to third-party image hosts (BleepingComputer, 26 September). The common thread is that identity and data-flow controls designed for human users do not cover non-human agents cleanly.
Cryptomining via legitimate management software
Huntress documented an incident on 24 September where an operator exploited Samsung MagicINFO to install AnyDesk, disable Microsoft Defender, and compile a Monero miner directly on the endpoint using the local toolchain. Compilation on the endpoint avoids delivering a signed or scanned binary.
Russia hybrid activity
Recorded Future's Insikt Group published analysis on 24 September of Russian hybrid and New Generation Warfare activity across Europe since 2022, combining cyber operations with physical sabotage and airspace incursions, with projections for the next two years. DarkReading covered similar ground on 25 September.
Law enforcement
KrebsOnSecurity reported on 25 September that a U.S. Army soldier was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution for hacking multiple telecommunications companies in 2024 and stealing call and text metadata for more than 100 million AT&T customers. BleepingComputer reported the same day that the administrator of the Rydox stolen-data marketplace pleaded guilty and faces up to 22 years.
Defender Takeaways
- Patch Oracle PeopleSoft CVE-2026-35273 at the application layer. WAF signatures alone are being bypassed with URL-encoded payloads.
- Patch Grav CMS. The unauthenticated path traversal flaw used against Clop applies equally to any exposed Grav instance.
- Apply the CISA KEV additions this week: WSO2 CVE-2026-5430 authentication bypass, SharePoint, and Adobe Commerce.
- Patch Elementor for WordPress. The CSRF flaw creates unauthenticated administrator accounts.
- Follow Kiteworks vendor guidance for customers who received the shutdown advisory.
- Hunt for the Storm-2570 tradecraft Microsoft published, independent of the final ransomware family. Detection at the tooling layer catches Qilin, DragonForce, Anubis, and BERT with a single set of rules.
- Inventory Azure service principals. Review consent grants, expiration, and last-used timestamps. Storm-3168 abuses this identity class specifically because it is under-monitored.
- Rebuild any developer system that installed compromised TanStack packages or the re-enabled GitHub Actions, rotate all tokens present on those systems, and audit private repository access logs.
- Assume slow-tempo ransomware operators. INC dwelled 17 days between initial access and encryption. Investigations that assume rapid intrusion-to-encryption cycles will miss this pattern.
- Treat device code phishing as an active threat class. The EvilTokens disruption removes capacity but not the technique; enforce conditional access policies that restrict device code flow.
Sources
- Microsoft Threat Intelligence, Beyond the ransomware: Tracking Storm-2570's consistent tradecraft across deployments, 2026-09-24. https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
- Microsoft Threat Intelligence, Unmasking EvilTokens: Getting to the root of device code phishing, 2026-09-22. https://www.microsoft.com/en-us/security/blog/2026/09/22/unmasking-eviltokens-getting-to-the-root-of-device-code-phishing/
- Microsoft Threat Intelligence, Storm-3168: Agentic-driven cloud attacks using compromised service principals, 2026-09-25. https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/
- Huntress, The Tale of Two INC Ransom Notes: A Ransomware Timeline, 2026-09-21. https://www.huntress.com/blog/two-inc-ransom-notes
- Huntress, The Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint, 2026-09-24. https://www.huntress.com/blog/threat-actor-compiles-cryptominer
- BleepingComputer, ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks, 2026-09-26. https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/
- BleepingComputer, ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw, 2026-09-25. https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/
- BleepingComputer, GitHub Actions re-enabled with Mini Shai-Hulud payload still active, 2026-09-26. https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/
- BleepingComputer, CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks, 2026-09-25. https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/
- BleepingComputer, Elementor WordPress flaw lets attackers create admin accounts, 2026-09-25. https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/
- BleepingComputer, Kiteworks urges 6-hour server shutdown over potential zero-day attacks, 2026-09-25. https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/
- The Record, Kiteworks urges customers to stop using platform after warning from federal intelligence agencies, 2026-09-25. https://therecord.media/kiteworks-urges-customers-to-stop-using-systems-incident
- DarkReading, ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?, 2026-09-21. https://www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims
- DarkReading, Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data, 2026-09-22. https://www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data
- DarkReading, Microsoft Disrupts EvilTokens Device Code Phishing Service, 2026-09-22. https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
- Recorded Future, Russia Escalating Hybrid Attacks Across Europe, 2026-09-24. https://www.recordedfuture.com/blog/russia-new-generation-warfare
- Check Point Research, 21st September Threat Intelligence Report, 2026-09-21. https://research.checkpoint.com/2026/21st-september-threat-intelligence-report/
- KrebsOnSecurity, U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions, 2026-09-25. https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/