Threat Alerts
Your place for the latest CyberProof cyber threat intelligence alerts and updates
Speak with an ExpertTukTuk C2 Linked to The Gentlemen Ransomware
The Gentlemen ransomware group has been linked to TukTuk, a previously undocumented command-and-control (C2) framework designed to maintain remote access and control over compromised Windows and Linux systems. The framework consists of dedicated Windows and Linux agents, a backend server, and an operator panel, providing capabilities including arbitrary command execution, file management, process control, screen capture, and credential theft through spoofed Windows Security prompts.
TukTuk can be deployed through DLL sideloading, with observed activity using the legitimate Greenshot executable to load a malicious log4net.dll, which launches the TukTuk agent and contains configuration associated with C2 communication through services including Slack, GitHub, and Dropbox. The group was also observed researching DLL sideloading opportunities involving additional legitimate applications, including ProcMon, Slack, and Postman.
The Gentlemen has additionally demonstrated a strong focus on EDR neutralization and defense evasion, maintaining tools related to Bring Your Own Vulnerable Driver (BYOVD) techniques, EDR process termination, vulnerable-driver discovery, and kernel-level exploitation. The identified materials indicate continued development of techniques intended to disable endpoint protection and create an operational window for subsequent malicious activity, supporting the group’s ability to maintain access and progress through compromised environments while reducing endpoint visibility.
Silver Fox Uses Fake Installers to Weaken Windows Security
An active malware campaign is using counterfeit software download websites to impersonate trusted vendors and distribute malicious installers. The activity has resulted in compromises across multiple sectors, including healthcare, manufacturing, gaming, technology, logistics, government and education. The campaign is consistent with the publicly reported Silver Fox fake software distribution activity, although it has not been attributed to a nation-state actor.
The attack begins with fraudulent websites that closely replicate legitimate software vendor pages and direct victims to malicious downloads. A notable characteristic of the campaign is the use of archives with the same filename but a different hash for each download, indicating that payloads are likely generated dynamically by the server for individual requests. Multiple well-known software brands are impersonated while directing victims to the same underlying delivery infrastructure. Once executed, the malicious installer deploys a stage-one payload to a randomized file path, reducing the effectiveness of name-based detection. The malware then establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure, providing a foothold for further malicious activity.
Knight Office Targets Microsoft 365 with Token Replay and Rogue Device Registration
A newly identified phishing kit called Knight Office has been observed targeting Microsoft 365 accounts through an Adversary-in-the-Middle (AiTM) attack, representing a growing class of threats designed specifically to bypass multi-factor authentication. Rather than stealing passwords directly, the attack captures valid session tokens after the victim completes MFA, giving attackers authenticated access without triggering standard credential-based alerts. The campaign is not isolated — telemetry links at least nine token replay logins to this kit over a two-week period, with hundreds of related phishing emails reported since April.
The infection chain begins with a DocuSign-style phishing email using a self-spoofing technique, making it appear as though the message originated from the recipient’s own address. The embedded link routes victims through a legitimate work management platform’s tracking service before landing on a compromised third-party website, effectively obscuring the final destination from reputation scanners. Victims are then presented with a fake SharePoint or Teams page, given a device authentication code, and instructed to paste it into Microsoft’s legitimate device authentication login screen — after which they are prompted for their credentials and MFA, completing the token capture without suspicion.
Once session tokens are harvested, the attacker registers a rogue device, makes OAuth 2.0 token-authentication attempts, and then enrolls an unauthorized host into the identity platform to complete an attacker-controlled device registration. A Windows Hello for Business key credential is then bound to the compromised account — a persistence mechanism that allows the attacker to regain access even after existing tokens are revoked, since the enrolled key effectively functions as a passwordless backdoor. The kit’s control panel, while relatively simple in appearance, sits atop a broader attack chain that leverages trusted redirect infrastructure, compromised websites, and residential callback proxies — and once the victim completes MFA, they unknowingly hand over a valid session token, shifting the entire attack from credential theft to the abuse of already-authenticated access.
Teams IT Support Impersonation Delivers Node.js Backdoor
Threat actors are impersonating IT or helpdesk staff through Microsoft Teams to socially engineer users into granting interactive remote access to their devices. Once access is established, the attackers deploy a malicious MSI that stages a portable Node.js runtime and an obfuscated JavaScript implant, providing persistent command execution and a foothold for broader compromise.
The intrusion begins when an attacker operating from an external Teams tenant convinces the victim to initiate or approve a remote-assistance session, including through legitimate tools such as Quick Assist. During the session, PowerShell is used to silently deploy the MSI, which installs a script-based loader and encrypted implant under the user’s LocalAppData directory. Notably, the attack retrieves a legitimate portable Node.js runtime from the official distribution and uses it to execute the malicious JavaScript implant, reducing reliance on custom executables. The implant communicates with its C2 over HTTPS, performs host and Active Directory reconnaissance, captures screenshots, executes additional payloads, and supports operator-driven lateral movement via WinRM toward high-value infrastructure, including domain controllers and certificate authorities.
Unlike more conventional phishing campaigns that primarily attempt to steal credentials or deliver malware, this activity uses social engineering to obtain user-authorized, interactive access before transitioning into a hands-on-keyboard intrusion. The extensive use of legitimate collaboration, remote-support, runtime, and administrative tools allows much of the attack chain to resemble normal enterprise activity, while potentially providing attackers with a path from a single user interaction to broader domain-level access.
Critical VMware Workstation and Fusion Vulnerabilities Enable VM Escape
Two critical vulnerabilities have been identified in VMware Workstation and VMware Fusion that could allow an attacker to escape a virtual machine and execute code on the underlying host system. The vulnerabilities, tracked as CVE-2026-59346 (CVSS 9.3) and CVE-2026-59347 (CVSS 8.1), affect the VMXNET3 virtual network adapter and Host-Guest File System (HGFS), respectively.
CVE-2026-59346 is an integer-overflow vulnerability in VMXNET3 that can be exploited by an attacker with local administrative privileges inside a VM configured with the affected virtual network adapter. Successful exploitation could result in code execution on the host. CVE-2026-59347 is a stack buffer-overflow vulnerability in HGFS that can similarly cross the guest-to-host security boundary under affected configurations.
The vulnerabilities are particularly significant because they break the isolation normally provided between virtual machines and their hosts. An attacker who has already compromised a guest VM could potentially use these flaws to extend access to the host system, increasing the impact of an initial VM compromise.
Google Chrome V8 Zero-Day Actively Exploited in the Wild
A high-severity zero-day in Chrome’s V8 JavaScript engine, CVE-2026-85046 (CVSS Score 8.8), is being actively exploited. The type-confusion flaw allows crafted JavaScript to achieve arbitrary memory read/write in the renderer, potentially enabling remote code execution and sandbox escape.
The vulnerability is a V8 type-confusion bug that can cause compiled engine code to operate on incorrect object layouts. A malicious webpage can deliver crafted JavaScript which exploits this mismatch to gain arbitrary heap read/write inside the renderer process, enabling sandbox bypass and native code execution. The flaw affects Chrome and other Chromium-based browsers and any application embedding V8.
Exploitation typically follows delivery of crafted JavaScript from a webpage, yielding arbitrary memory control, sandbox escape, and execution of follow-on payloads such as credential theft, data exfiltration, or malware deployment. Third-party desktop applications embedding Chromium/V8 can be affected as well. Active exploitation has been observed, making this an immediate risk to unpatched systems.





