zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 8, 2026

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 8, 2026

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Aur0ra Ransomware Lists U.S. Defense Contractor Metrea as Victim
  • Fake IT Calls Target Executives in Data Theft and Extortion Attacks
  • Liquid Network Hit in USD 320 Million Crypto Theft; Most Funds Returned

Aur0ra Ransomware Lists U.S. Defense Contractor Metrea as Victim

Source: https://cloud.zerofox.com/intelligence_new/advanced_dark_web/110647

What we know: ZeroFox has found Aurora (or “Aur0ra”) ransomware claiming to have stolen military data from the U.S.-based defense contractor Metrea LLC and its subsidiary Commuter Air Technology, Inc. The entities provide intelligence, surveillance, and reconnaissance aircraft services to various departments of the U.S. security forces.

Context: The threat actor claims to have exfiltrated 339 MB of ITAR-controlled military radio firmware, named deployment data for operators at active military sites, and 232 employee personnel files with security clearances.

  • Aurora was first observed by ZeroFox in April 2026, initially targeting insurance, logistics, and hospitality sectors before escalating to defense-adjacent industries. Over the past month, the group launched nine attacks primarily targeting electronics and semiconductor manufacturing, split roughly equally between Europe-Russia and North America regions.
  • In August 2026, the ransomware group was reportedly observed using an AI-powered coding assistant to target networks of at least 10 organizations. The group is also suspected to be a Russian-speaking threat group.

Analyst note: The alleged data, if authentic, carries significant national security implications well beyond financial extortion, given that named operator deployment data would almost certainly be of high intelligence value to foreign state actors.

  • Aurora's consistent targeting of electronics, semiconductor, and defense-adjacent industries, combined with its suspected Russian origin, very likely reflects priorities that are aligned with the interests of the Russian-state.

Fake IT Calls Target Executives in Data Theft and Extortion Attacks

Source: https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html

What we know: A data theft and extortion threat cluster is reportedly targeting senior executives such as directors and vice presidents via IT help desk vishing attacks, adversary-in-the-middle (AitM) attacks, and residential-proxy sign-ins to obtain authenticated sessions and access corporate data.

Context: Attackers impersonate internal IT personnel and direct victims to fake authentication-themed websites designed to capture credentials, MFA approvals, and session tokens. The activity has primarily targeted U.S. organizations across construction, healthcare, real estate, finance, and professional services. The suspected threat group is a rebrand of BlackFile extortion group.

Analyst Note: BlackFile has been associated with vishing attacks against the financial sector in the United States, as well as the Levi Strauss breach disclosed in August 2026. The threat group’s continued reliance on IT help desk vishing calls likely indicate success using the method. The group is likely targeting senior executives to obtain admin-level access to corporate data and communications.

Liquid Network Hit in USD 320 Million Crypto Theft; Most Funds Returned

Source: https://www.bloomberg.com/news/articles/2026-09-07/bitcoin-network-says-320-million-stolen-in-latest-crypto-hack

What we know: Liquid Network, an open-source Bitcoin solution, has confirmed that “white-hat hackers” stole about 4,000 of 4,200 BTC (worth USD 320 million) from its federation wallet. The attackers reportedly recently returned 3400 BTC and kept 600 BTC (worth USD 47 million).

Context: The Bitcoin was withdrawn through SideSwap, a settlement platform, by exploiting a vulnerability. Liquid Network said the key was not compromised and has halted new transactions.

Analyst Note: As the cryptocurrency industry continues to face thefts by financially motivated actors, this incident likely indicates a rare shift from conventional profit-driven attacks toward ideological motivations.

DEEP AND DARK WEB INTELLIGENCE

ShinyHunters adds Metabase to leak site: ShinyHunters has claimed data theft targeting Metabase, a U.S.-based open-source business intelligence company. Metabase has been listed on ShinyHunters’ leak site along with alleged internal files and GitHub repositories related to the entity.

THREAT CAMPAIGN WATCH

ShinyHunters target Medela: Extortion group ShinyHunters has threatened to leak data allegedly stolen from Medela, a Switzerland-based healthcare medical device manufacturer, unless the company complies with the group’s demands. At the time of writing, Medela operates 20 healthcare subsidiaries across the Americas, Europe, and Asia and primarily serves healthcare institutions, including maternity and neonatal care providers, and hospitals, as well as home users.

  • An alleged sample of stolen data is likely to be published on the leak site if demands are unmet. If legitimate, leaked data from Medela is likely to be leveraged by other threat actors to target patients and employees in phishing and social engineering attacks.

VULNERABILITY AND EXPLOIT INTELLIGENCE

Nightmare Eclipse zero-day vulnerabilities Nightmare Eclipse has dropped three new zero-day exploits named PrettyPrague, FalconFlank, and GreenSection, affecting Avast Antivirus, CrowdStrike Falcon Sensor, and Nvidia GPU components, respectively. PrettyPrague can reportedly enable attackers to gain system-level privileges through the Avast sandbox, while FalconFlank exploits the Office malicious-macro remediation feature for privilege escalation. GreenSection targets an out-of-bounds memory write in a shared memory section used by Nvidia user-mode components, potentially enabling cross-user access or compromising dwm.exe.

Affected products: Avast Antivirus, potentially AVG and Norton; CrowdStrike Falcon Sensor; and certain Nvidia GPU display driver components on Windows.

CVE-2026-75650 This is a zero-day remote code execution (RCE) flaw in Adobe Commerce and Magento that enables attackers to inject PHP code into Magento’s template system. The attack works in two stages: attackers first inject the code by generating a failure report, then Magento executes it through a failed-payment email. The code also executes when Magento resends the email or when email delivery fails, requiring no user interaction. The flaw is being actively exploited to deploy backdoors on online stores.

Affected products: The affected products are listed here.

Tags: DIBtlp:green