zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - August 25, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - August 25, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
  • ShinyHunters Reportedly Failed to Breach Cybersecurity Firm
  • China-Linked Threat Group Targets 170,000 Web Servers in AI-Assisted Attacks

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Source: https://hackread.com/fake-minecraft-clients-weedhack-malware-windows-passwords/

What we know: Multiple websites masquerading as legitimate Minecraft clients, mods, and utility tools are reportedly actively distributing the WeedHack malware family to gamers. The multi-stage attack deploys malicious Java Archive (JAR) payloads that collect system information, configure Microsoft Defender exclusions, and exfiltrate sensitive victim data.

Context: The campaign uses SEO poisoning to promote fake Minecraft websites across search engines. Malicious links were primarily associated with Discord,MediaFire, and GitHub, with additional distribution through Minecraft community platforms.

Analyst note: Successful execution of the malware is likely to result in complete system takeover along with compromise of Minecraft player account. Threat actors are likely to exfiltrate sensitive information, cryptocurrency wallet details, and credentials stored on browsers leading to financial theft.

ShinyHunters Reportedly Failed to Breach Cybersecurity Firm

Source: https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-theft-attack-after-shinyhunters-breach/

What we know: A U.S.-based cybersecurity company has confirmed that their employees were targeted in a failed social engineering attack by the ShinyHunters extortion gang. Threat actors impersonated a member of the company's security team, directing employees to a lookalike SSO phishing page on a fraudulent domain.

Context: One employee entered their credentials and approved a multi-factor authentication (MFA) push notification, granting temporary, view-only access to the company's identity dashboard. Device-trust controls blocked all subsequent application access, and no systems or customer data were compromised. ShinyHunters published evidence of access on its extortion portal.

Analyst note: ShinyHunters' continued effectiveness with this social engineering vector very likely signals the group will persist with this approach against target organizations.

China-Linked Threat Group Targets 170,000 Web Servers in AI-Assisted Attacks

Source: https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html

What we know: China-linked threat group UAT-10147 is reportedly integrating AI across its attack chain, using AI-powered tools such as DeepAudit and PentestGPT for vulnerability scanning, exploit development, reconnaissance, payload generation, troubleshooting, and post-exploitation.

Context: UAT-10147 is reportedly targeting web servers at scale, with a list of approximately 170,000 URLs spanning multiple countries, including the United States, India, United Kingdom, Germany, and the Netherlands. The group combines exploitation with persistent access and data theft, deploying web shells and malware strains like BadIIS, Quasar RAT, and SPECTRE.

Analyst note: UAT-10147’s activity suggests AI is increasingly being used to support the operational side of cybercrime rather than used solely to develop malware or code. The target pool of roughly 170,000 URLs is likely to have been enabled by AI usage.

DEEP AND DARK WEB INTELLIGENCE

PwnForums user misere: Moderately credible threat actor “misere” has advertised a database allegedly belonging to Solimut Mutuelle de France, a French non-profit insurance company. The actor claimed the dataset covers hundreds of thousands of policyholders and includes bank, address, identity, passport, payroll, and insurance data. The actor has also added sample data. In 2026, misere was observed primarily targeting French entities across different sectors, including government departments. ZeroFox has recorded seven incidents. Misere’s claims likely suggest an interest in high-value personal and institutional data rather than a narrow sector focus. The actor is likely to continue targeting French organizations.

VULNERABILITY AND EXPLOIT INTELLIGENCE

CVE-2026-75501: This is an unpatched missing authentication vulnerability in Calix GS7 XGS (GS5239XG) residential routers. The flaw stems from the device exposing its UPnP control endpoint on the public WAN interface on TCP port 5000 without access controls, enabling any unauthenticated remote attacker to send SOAP requests that create, delete, or enumerate port-forwarding rules. Successful exploitation is very likely to result in unauthorized access to internal network devices.

Affected products: Calix GS7 XGS (GS5239XG), firmware EXOS/6.6.47

Tags: DIBtlp:green