| New Threats Detection Added | • ZimReaper • SpyPress |
| New Threat Protection | 65 |
| Newly Detected Threats | 8 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
ZimReaper | ||||||||||||||||||
|
ZimReaper is a JavaScript-based malware used in an espionage campaign targeting unpatched versions of the Zimbra Collaboration Suite. It utilises a Cross-Site Scripting (XSS) vulnerability embedded within a phishing email that requires only minimal user interaction and can be executed by simply opening or previewing the email. Once this is executed, it can steal user credentials, CSRF tokens, and 2FAs, and can also exfiltrate emails, contact lists, and mailbox data. ZimReaper is primarily targeting government, defence, research and critical infrastructure particularly in Ukraine and other Western Countries.
|
|||||||||||||||||||
|
Threat Protected:
|
06 | ||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||
|
Class Type:
|
Trojan-Activity | ||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||
|
Threat name:
|
SpyPress | ||||||||||||||||||
|
SpyPress is a JavaScript-based malware used in a campaign targeting high value webmail servers such as Roundcube, Zimbra, Horde and Mdaemon. This malware is linked to threat groups like Fancy Bear / APT28. SpyPress extracts emails, credentials, and sensitive information from webmail by exploiting Cross-Site Scripting vulnerabilities using specially crafted phishing emails that executes malicious JavaScript when opened. SpyPress is often described as a “half-click” attack because the victim only needs to open the email from a vulnerable webmail platform to be compromised without having to click a malicious URL or execute a malicious file.
|
|||||||||||||||||||
|
Threat Protected:
|
08 | ||||||||||||||||||
|
Rule Set Type:
|
|
||||||||||||||||||
|
Class Type:
|
Trojan-Activity | ||||||||||||||||||
|
Kill Chain:
|
|
||||||||||||||||||
Known Exploited Vulnerabilities (Week 4 - July 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-4th-week-of-july-2026/678.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
9.1
|
Authentication Bypass - Check Point SmartConsole contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to gain administrative access to the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
Unauthenticated RCE - Microsoft SharePoint Server (on-premises) contains a deserialisation vulnerability that can allow an unauthenticated remote attacker to execute code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
5.9
|
SQL Injection - WordPress Core contains an SQL injection vulnerability that can allow an unauthenticated remote attacker to retrieve information stored within the database, when chained with CVE-2026-63030 this vulnerability can result in code execute on the system. This vulnerability can be exploited on default installations of WordPress without requiring a specific configuration.
|
6.8 - 6.8.5
6.9 - 6.9.4 7.0 - 7.0.1 |
6.8.6
6.9.5 7.0.2 |
||
|
9.8
|
Unauthenticated RCE - WordPress Core contains a vulnerability within the REST API that can allow an unauthenticated remote attacker to exploit an SQL Injection vulnerability which can result in code execution on the system when chained with CVE-2026-137. This vulnerability can be exploited on default installations of WordPress without requiring a specific configuration.
|
6.9 - 6.9.4
7.0 - 7.0.1 |
6.9.5
7.0.2 |
||
|
9.8
|
Unauthenticated RCE - Langflow contains a vulnerability that can allow an unauthenticated remote attacker to execute code on the system in the context of root.
|
Check vendor advisory for affected versions.
|
|||
|
8.1
|
Unauthenticated RCE - DD-WRT contains a buffer overflow vulnerability within UPnP that can allow an unauthenticated attacker to execute code on the system.
|
Check vendor advisory for affected products and versions.
|
|||
Updated Malware Signature (Week 4 - July 2026)
|
Threat
|
Description | |
|
XWorm v2 Command
|
XWorm v2 Command is a Remote Access Trojan (RAT) that is commonly used to establish and maintain unauthorised access, collect sensitive information and conduct botnet-related operations. This malware communicates with Command-and-Control server to receive instructions and carry out malicious activities.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that Qilin was the most active ransomware group, impacting 40 countries, which accounted for 23.39% of the total ransomware hits. This made Qilin the leading ransomware actor during the reporting period. The Gentlemen recorded the second-highest activity, attacking 33 countries and contributing 19.30% of the total ransomware activity. Nova followed with 15 countries impacted, representing 8.77% of overall ransomware hits. A moderate level of activity was observed from Inc Ransom, which affected 10 countries, accounting for 5.85%, and SafePay, which impacted 9 countries, representing 5.26%. Krybit and Akira each attacked 7 countries, contributing 4.09% individually. Other ransomware groups with notable activity included Play, which impacted 5 countries and accounted for 2.92%, while Chaos affected 4 countries, representing 2.34% of total activity. Several groups recorded lower activity levels, impacting 3 countries each. These included DragonForce, Anubis, Coinbase Cartel, Space Bears, and KillSec3, each contributing 1.75% individually. Groups such as Kairos, WorldLeaks, M3rx, and Settra impacted 2 countries, accounting for 1.17% each. The remaining ransomware groups, including Blackout, Gunra, Payload, Doommageddon, Titan, Morpheus, Black X, Brain Cipher, RansomHouse, Leaknet, Nightspire, Money Message, CMD Organization, Pear, Eraleign (APT73), Deadlock, Triple X, and Insomnia, each impacted 1 country, representing 0.58% individually. |

CMD RANSOMWARE
Threat Actor Description
CMD Organization (leak brand “CMDOfficial”; tracker spellings Cmdorganization/CMDOrganization) is an emerging ransomware operator with confirmed activity from late March 2026 and first public victim posts in early April 2026. Beazley Security Labs worked on one of the earliest confirmed intrusions “only weeks after their public emergence,” giving this actor an unusually solid primary-source foundation for a new group. [1]
Operating model: double extortion (encrypt + exfiltrate) plus an unusual public crypto bidding/auction platform integrated into the leak site. WatchGuard categorises the operation across data auctions, direct extortion, double extortion, free data leaks, and re-leaks. The leak site adopts a mock “corporate security/pentest” framing common to extortion crews. [1][2]
Infrastructure & contacts: clearnet DLS cmdofficial[.]com (TLS cert and Namecheap registration both dated 29 Mar 2026; later fronted by Cloudflare) with a Tor mirror; backend Ubuntu + nginx. Operator contact is via OnionMail addresses only - no Telegram, Tox, Session, jabber, or published crypto wallet has surfaced. A monetary-format quirk (comma decimals, e.g. 1.000,00) in the bidding panel suggests developers outside US/Western formatting conventions. [1]
Sophistication & attribution note: assessed low-to-moderate - limited locker capability (no self-propagation), dependence on outsourced tooling/IAB access (supported by a ~25-day dwell before encryption), and a beta bidding panel. Beazley confirmed the panel’s immaturity firsthand: no wallet or verification deposit was required to place a bid. No confirmed rebrand lineage exists. [1]
Tactics, Techniques, and Procedures (TTPs)
Attribution Framework
The mapping below is drawn primarily from Beazley Security Labs’ forensic IR engagement, so most rows are CONFIRMED for CMD Organization - a materially stronger evidence base than claim-only trackers provide. Confidence is explicit per row. [1]
|
Tactic
|
Technique ID
|
Technique
|
Evidence/Observed Behaviour
|
|
Initial Access
|
T1566/T1189
|
Phishing/Drive-by (SEO poisoning)
|
SEO-poisoned Bing result delivering a fake “PDF” archive (malvertising).
|
|
Execution
|
T1059.007/.001
|
JavaScript & PowerShell
|
Encoded JS run via cscript.exe → obfuscated PowerShell loader.
|
|
Execution
|
T1204.002
|
User Execution: Malicious File
|
Victim opens the fake-PDF archive to trigger the loader.
|
|
Defence Evasion
|
T1027/T1140/
T1620
|
Obfuscation/In-memory
|
Anti-analysis PowerShell; string obfuscation; reflective in-memory staging.
|
|
Credential Access
|
T1078
|
Valid Accounts
|
Reused original victim account credentials for remote execution.
|
|
Discovery
|
T1046/T1018
|
Network/Remote System Discovery
|
Advanced IP Scanner and Advanced Port Scanner.
|
|
Lateral Movement
|
T1021.002/T1570
|
SMB/Lateral Tool Transfer
|
Invoke-SMBRemoting fileless interactive shells over SMB.
|
|
Persistence
|
T1547.001/T1543
|
Run Keys/Service
|
“Meow” backdoor DLL; Run keys disguised as “Install Microsoft Teams.”
|
|
Command & Control
|
T1071.001/T1105
|
Web Protocols/Ingress Tool
|
Loader C2 (StealC indicators); Meow backdoor C2 over HTTPS JSON check-in.
|
|
Command & Control
|
T1572
|
Protocol Tunneling
|
OpenSSL abused for proxy tunnelling.
|
|
Impact
|
T1486
|
Data Encrypted for Impact
|
“Lockit”/paste1.exe ChaCha20 + RSA locker; “[CMD]” file tags; __README__.html; pushed via GPO / SYSVOL.
|
Attack Lifecycle
The following reconstructs a CMD Organization intrusion from the Beazley forensic engagement. This is a true locker operation - encryption is confirmed, not leak-only - with a notably long dwell time before detonation. [1]
INITIAL ACCESS - SEO-Poisoned Lure/Brokered Access
Entry occurs via an SEO-poisoned Bing search result delivering a fake “PDF” archive; a JavaScript loader executes through cscript.exe into obfuscated PowerShell with StealC-linked C2 check-ins. A ~25-day dwell before encryption is consistent with IAB-sourced or staged access. [1]
Observable artefacts: cscript.exe/wscript.exe spawning PowerShell from user-download paths; fake-PDF ZIP execution; outbound to the loader/StealC C2 addresses; StealC-style URL loading into memory.
DISCOVERY & LATERAL MOVEMENT - Recon + SMB Shells
The actor enumerates the network with Advanced IP/Port Scanner and moves laterally using Invoke-SMBRemoting fileless shells with harvested valid credentials. [1]
Observable artefacts: Advanced IP/Port Scanner execution; Invoke-SMBRemoting patterns; east-west SMB admin-share activity; use of valid accounts for remote command execution.
PERSISTENCE & C2 - “Meow” Backdoor
Persistence is established via the “Meow” backdoor DLL (Netdrv.dll) and Run-key entries masquerading as “Install Microsoft Teams.” C2 runs over HTTPS with a JSON check-in; OpenSSL is abused for proxy tunnelling. [1]
Observable artefacts: Run-key values named “Install Microsoft Teams” with fake version numbers; Netdrv.dll with a “Meow” export; HTTPS JSON beacons to the Meow C2; OpenSSL used as a tunnel.
EXFILTRATION & IMPACT - Encryption via GPO/SYSVOL
Data is exfiltrated (tooling subsequently wiped), then the “Lockit”/paste1.exe locker is distributed via GPO and SYSVOL and encrypts with ChaCha20 + RSA, tagging files with “[CMD]” metadata and dropping __README__.html (opened in Chrome). Victims are then listed on the DLS with the auction / bidding pressure model. [1]
Observable artefacts: Unexpected GPO changes/new SYSVOL scripts; mass file modification with “[CMD]” tags; __README__.html creation; large outbound transfers prior to encryption; victim appearing on the CMDOfficial DLS/auction panel.
Mitigation - Crystal Eye 5.5 Controls
Controls map directly to CMD Organization’s confirmed kill chain. Priority: block the known IOCs, cut the SEO-poisoning/script-execution entry path, contain SMB and GPO/SYSVOL propagation, and retain backup resilience against the ChaCha20 + RSA locker.
CE Antivirus + Endpoint Controls (block known IOCs)
Block and alert on the confirmed file hashes, the “Meow” backdoor (Netdrv.dll), and the locker (paste1.exe/__README__.html/“[CMD]” file tags). Deploy the CMDOrganization YARA rule and StealC detections; validate the 209.99.x host octet (source typo) before firewalling.
CE Secure Web Gateway + Anti-phishing
Block the malvertising / SEO-poisoning delivery domains and newly-registered domains, and filter fake-“PDF” archive downloads. Enable signature, heuristic, SSL-mismatch, and cloaked-URL detection to intercept the search-lure entry vector.
CE Endpoint Hardening - Script Execution & GPO/SYSVOL
Block cscript.exe/wscript.exe for standard users and enforce PowerShell constrained-language mode + script-block logging to break the JS → PowerShell loader chain. Lock down GPO and SYSVOL write access - the locker’s propagation vector - and alert on unexpected GPO changes or new SYSVOL scripts.
CE Advanced Firewall + IDPS
Block the confirmed C2 addresses, restrict SMB/RDP lateral movement to explicit administrative sources, and use IDPS rules to detect Invoke-SMBRemoting, network-scanner activity, OpenSSL tunnelling, and Tor egress. Correlate any traffic to the onion/OnionMail indicators below.
CE Identity Hardening + MFA
Enforce phishing-resistant MFA on all remote and privileged access, monitor infostealer-log marketplaces for exposed corporate credentials, and alert on valid-account reuse for remote execution and impossible-travel authentication.
CE DLP + SWG Egress Monitoring
Enable DLP and SWG monitoring to detect bulk outbound transfers before encryption, block or inspect anonymised (Tor) egress, and block the OnionMail contact domains used for negotiation.
CE Backup Integrity + Vulnerability Scanning
Maintain immutable, offline, tested backups and alert on mass file modification/shadow-copy deletion (the ChaCha20 + RSA locker). Given the ~25-day dwell, hunt at least a month back for any client showing loader/recon/Meow-backdoor artefacts. Scan internet-facing and remote-access systems to reduce IAB entry points.
CE SIEM + CESOC Escalation
Ingest all confirmed IOCs and correlate web-gateway, endpoint, identity, IDPS, and DLP events. If a managed client appears on the CMD Organization DLS, treat it as an unconfirmed claim but assume exfiltration occurred, apply a ≥ 25-day look-back, and escalate to CESOC for IR-grade validation.
Indicators Of Compromise (IOCs)
Source & availability: Unlike many emerging brands, CMD Organization has confirmed, attributable IOCs from the Beazley Security Labs IR engagement. These are provided below (defanged). Do not conflate with generic cmd.exe/locker.exe/Conti-tagged artefacts returned by hash-DB searches - those are unrelated. [1]
File Hashes & Tooling
|
File
|
Hash
|
Role
|
|
paste1.exe
|
SHA-1 07c14b82f673ba5caa8c1188f052ea31583f0af7
|
CMD locker (“Lockit”)
|
|
Patricia-va-a-california-pdf.zip
|
SHA-256 69aa0eeab454e6967e9c860d02749857b0b4c4ea8c55ba0c1a1af12af5a25bca
|
Malvertisement payload
|
|
qlgdhgk.ps1
|
SHA-1 8ed2c2e67ae8d3cfe1fca15d5c7b33e7011bb8dd
|
Infostealer PowerShell
|
|
qu.ps1
|
SHA-1 c18cef4610d272caa3c51ec5803439aff3b4982e
|
Infostealer PowerShell
|
|
Netdrv.dll
|
SHA-1 463554c76a0aa472daf9b42e9414942910b4ac54
|
“Meow” backdoor DLL
|
Network & Infrastructure
|
Type
|
Indicator (defanged)
|
|
Clearnet DLS
|
cmdofficial[.]com
|
|
Tor DLS (onion)
|
cmdnkiqjije2tllr3biee2sjgj3i4robg2cbtilbnytdhh2wy3syrlyd[.]onion
|
|
Host IP
|
209.99.186[.]211 (source also lists 209.99.286[.]211 - invalid octet / typo)
|
|
Meow C2
|
188.190.2[.]165:666 (HTTPS JSON check-in)
|
|
Loader/StealC C2
|
167.99.233[.]78 ; 213.165.47[.]49
|
|
Delivery/C2 URLs
|
hxxps://clubsoar[.]com/fd/... ; hxxps://artistichairlounge[.]com/.../template.php ; hxxp://213.165.47[.]49/b0c9ed38f2b14c119546.php ; hxxp://167.99.233[.]78/mbd
|
|
Operator emails
|
cmd2official@onionmail[.]org ; Cmdhtmnjksgkuhilrtrh@onionmail[.]org ; MitsueWhite@onionmail[.]org ; JedAdams@onionmail[.]org
|
|
Host/file marker
|
“[CMD]” metadata tags in encrypted files ; Run key “Install Microsoft Teams”
|
Ransom Demands
|
Victim
|
Demand
|
|
Lørenskog kommune (Norway)
|
20 BTC (~USD 1.18M)
|
|
Tracker-recorded amounts
|
7 BTC ($543,162) ; 8 BTC ($607,720)
|
References
[1] Beazley Security Labs - CMD Organization: New Ransomware Operator (forensic IR analysis) - https://labs.beazley.security/articles/cmd-organization-new-ransomware-operator-moves-to-place-public-bidding-wars-on-ransomed-data. PRIMARY source: full intrusion + locker analysis, TTPs, IOCs (hashes, C2, URLs, contacts), bidding-panel and origin assessment.
[2] WatchGuard - Ransomware Tracker: CMD Organization - https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/. Extortion categories and recorded extortion amounts (7 BTC / 8 BTC).
Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 66 victims, accounting for 38.60% of the total ransomware activity. This indicates that the United States remained the primary target region during this period, representing a significant portion of global ransomware incidents.
Canada recorded the second-highest number of victims, with 15 cases, contributing 8.77% of the total. Germany followed with 9 victims, accounting for 5.26%, while India reported 7 victims, representing 4.09% of overall ransomware activity.
Other countries with notable ransomware impact included Indonesia and Australia, each recording 6 victims, contributing 3.51% individually. France and Argentina each reported 5 victims, accounting for 2.92% each. The United Kingdom recorded 4 victims, representing 2.34% of the total.
Moderate ransomware activity was observed in Singapore, Peru, Portugal, Spain, and the Netherlands, each reporting 3 victims, accounting for 1.75% individually. Countries including Bulgaria, Philippines, South Africa, Colombia, Turkey, Brazil, Italy, and Czech Republic each recorded 2 victims, contributing 1.17% individually.
The remaining countries recorded 1 victim each, accounting for 0.58% individually. These included Taiwan, South Korea, Belgium, Japan, Ireland, Paraguay, Pakistan, New Zealand, Austria, Hungary, Poland, Ecuador, Dominican Republic, Morocco, Malaysia, Vietnam, and South Sudan.

Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 31 victims, accounting for 18.13% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Business Services recorded the second-highest number of victims, with 29 cases, representing 16.96% of the total. Retail followed with 19 victims, contributing 11.11%, while Healthcare accounted for 12 victims, representing 7.02% of overall ransomware activity.
Other sectors with notable ransomware impact included Education, with 9 victims, accounting for 5.26%, and Transportation, with 8 victims, contributing 4.68%. IT recorded 7 victims, representing 4.09% of the total.
Moderate activity was observed in Construction and Insurance, each with 6 victims, accounting for 3.51% individually. Energy, Hospitality, Real Estate, and Consumer Services each reported 5 victims, contributing 2.92% each.
Lower levels of ransomware activity were observed across several sectors. Law Firms, Telecommunications, Agriculture, Electronics, Media & Internet, Finance, and Bulgaria each recorded 3 victims, representing 1.75% individually. Organisations and Architecture each reported 2 victims, accounting for 1.17% each.
The least affected sectors were Federal, with 1 victim, representing 0.58% of the total ransomware activity.
