ZeroFox Daily Intelligence Brief - September 1, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - September 1, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Anthropic Warns of Infostealer Campaigns Targeting Claude Session Credentials
- “TerminalFix” Campaign Deploys Reverse Tunnels for Network Intrusion
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Anthropic Warns of Infostealer Campaigns Targeting Claude Session Credentials
Source: https://www.securityweek.com/anthropic-warns-claude-users-of-infostealer-malware-infections/
What we know: A threat actor is reportedly identifying and exploiting stolen Claude session credentials to access user accounts and run up usage limits. The credentials were stolen from malware infected systems. The infostealers are often delivered through unofficial software downloads and malicious applications.
Context: Anthropic reportedly detected the activity and signed out affected sessions, removed saved payment methods, and refunded charges it identified as unauthorized. It has released mitigation measures to prevent further compromise. Separately, a new Windows infostealer, “RevStealer”, is reportedly being distributed through a fake desktop application offering free access to Anthropic’s Claude Opus 5.
Analyst note: Threat actors are likely to use compromised or stolen Claude accounts for malicious activities while also obscuring their identities behind legitimate user accounts. Stolen Claude sessions are also likely to be directly monetized or leveraged to access sensitive data and connected resources as AI assistants become increasingly integrated into developer workflows and third-party applications.
“TerminalFix” Campaign Deploys Reverse Tunnels for Network Intrusion
What we know: A new ClickFix variant dubbed “TerminalFix” has been tricking victims into executing malicious PowerShell commands via fake Cloudflare CAPTCHA prompts, deploying a multi-stage attack chain that ultimately establishes a reverse tunnel into the victim's internal network.
Context: The attack chain combines DLL sideloading and steganographic payload extraction across three PNG images, enabling dual persistence, and Active Directory reconnaissance targeting domain controllers, databases, backup servers, and mail systems. A custom Python-based reverse-tunnel implant is then deployed, giving the attacker persistent SOCKS-style TCP proxy access into the victim's internal network.
Analyst note: The campaign is very likely oriented toward long-term network access and follow-on operations, suggesting targeted espionage or pre-positioning for high-impact ransomware deployment. ClickFix-style techniques are very likely to continue maturing and diversifying, given that enforcing broad technical restrictions on PowerShell and Terminal access are unlikely to be practical across most enterprise environments.
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Source: https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
What we know: China-nexus actor Fire Ant has expanded beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux hosts, using the access to capture traffic, harvest credentials, and suppress security logging.
Context: The intrusion was reportedly identified via an unexplained GRE tunnel on a Cisco router; initial access remains unknown. The actor deployed router malware to filter logs and hide tunnel configs, a new TACACS credential-collection tool (TacTap), and a Zabbix-disguised backdoor (BridgeAgent) for persistence. Tradecraft reportedly parallels a separate August 2025 Salt Typhoon campaign against routers and TACACS+ servers.
Analyst note: Compromising routers likely provides attackers with both visibility into trusted network traffic and access to connected systems, while log suppression reduces defenders’ ability to detect and investigate activity. The targeting of network infrastructure and management systems creates a significant espionage risk, particularly where these devices provide access to critical infrastructure environments.
DEEP AND DARK WEB INTELLIGENCE
Telegram user 313 Team: On August 30, 2026, Iran-linked hacktivist group “313 Team” claimed to have conducted a distributed denial-of-service (DDoS) attack against a U.S. federal government background-check system, allegedly disrupting the service on August 30.
- The claim follows the group’s recent targeting of Western technology entities like Proton and GitHub. Proton confirmed an outage on August 27 linked to data center cooling failure, while GitHub also confirmed service disruptions between August 12 and 13.
- The 313 Team is likely making opportunistic claims following legitimate reports of outages to gain reputation and create a psychological impact on victims and the public. The hacktivist group also likely used botnet-for-hire services to carry out DDoS attacks.
VULNERABILITY AND EXPLOIT INTELLIGENCE
PaperCut NG/MF Zero-Days: PaperCut has released emergency patches for two actively exploited zero-day vulnerabilities in PaperCut NG/MF print management software. CVE-2026-81578 is an authentication bypass flaw that enables an unauthenticated remote attacker to modify system configurations, while CVE-2026-82078 is an unsafe dynamic class loading flaw. When chained together, the two vulnerabilities enable unauthenticated remote code execution.
Affected products: PaperCut NG/MF versions 24, 25, and 26
Tags: DIB, tlp:green