INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
AI Compute Hijacking Exploited in Ransomware Attacks
| 2026-07-02 15:24 CRITICAL MEDIUM AI-ENABLED ATTACK · AUTONOMOUS RANSOMWARE & EXTORTION EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape has undergone a significant shift, with the emergence of sophisticated and targeted cyber attacks that exploit vulnerabilities in various sectors. The Chinese-linked RAT activity dubbed BeepRAT is a prime example of this trend, operating within the China-nexus espionage ecosystem. This malicious framework has been linked to widespread phishing campaigns targeting US government officials, military leadership, and allied personnel, with the aim of gaining unauthorized access.
The threat actors behind these attacks are increasingly adopting platform-aware delivery methods that adapt to the victim's device, browser, and environment. This shift in tactics is a clear indication of the evolving nature of cyber threats, which require organizations to stay vigilant and proactive in their defense strategies.
Technical Mitigations AI-generated
* Implement secure coding practices and validate input parameters to prevent local code execution attacks like the one described in the BlueHammer vulnerability.
* Regularly update and patch operating systems, browsers, and software to ensure that known vulnerabilities are addressed before they can be exploited by attackers.
* Use sandboxing and isolation techniques to limit the attack surface of Windows-based systems and prevent malicious files from being planted or hijacked.
* Implement robust email security measures, such as SPF, DKIM, and DMARC, to protect against phishing attacks like those described in the RAW NEWS ARTICLE.
* Conduct regular security audits and penetration testing to identify vulnerabilities and weaknesses in systems and applications before they can be exploited by attackers.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
HF•••••.exe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-33825CVE-2026-33825
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
MIDDLE_EAST
MIDDLE_EAST
EUROPE
EUROPE
governmentgovernment
Incident Timeline
September 2023
ShinyEnigma used a known Windows vulnerability in the BlueHammer ransomware to target victims.
Click on any entity below to view its context and source!
organisation
DotStealer
The malware is attributed to a developer named ShinyEnigma, who is also behind DotStealer and was first seen in September 2023.
May 2025
The threat actor used social engineering to trick users into executing malicious payloads by masquerading them as legitimate software or cracked applications.
Click on any entity below to view its context and source!
tactic
Social Engineering
The threat actor has been active since May 2025, using social engineering as a way to trick users into executing malicious payloads by masquerading them as legitimate software or cracked applications.
the period between March 1
Threat actors used a vulnerability in Windows systems to target and infect ReliaQuest's platforms between March 1 and May 31, 2026.
Click on any entity below to view its context and source!
infrastructure
Windows
Data from ReliaQuest for the period between March 1 and May 31, 2026, ClickFix
remained
the dominant delivery method during this period and targeted both Windows and macOS systems.
infrastructure
Macos
Data from ReliaQuest for the period between March 1 and May 31, 2026, ClickFix
remained
the dominant delivery method during this period and targeted both Windows and macOS systems.
organisation
ReliaQuest
Data from ReliaQuest for the period between March 1 and May 31, 2026, ClickFix
remained
the dominant delivery method during this period and targeted both Windows and macOS systems.
the month of March 2026
Threat actors exploited a vulnerability in Windows to infect approximately 16,000 computers with ransomware.
Click on any entity below to view its context and source!
general_metric
16,000 infections
versions, with more than 16,000 infections reported in the month of March 2026 alone.
April 2026
BlueHammer exploited a zero-day vulnerability in Windows.
Click on any entity below to view its context and source!
organisation
BlueHammer
BlueHammer was first disclosed as a zero-day by an anonymous researcher named Chaotic Eclipse (aka Nightmare-Eclipse) in April 2026.
organisation
Nightmare-Eclipse
BlueHammer was first disclosed as a zero-day by an anonymous researcher named Chaotic Eclipse (aka Nightmare-Eclipse) in April 2026.
April 10, 2026
Attackers used BlueHammer exploiting a vulnerability in Windows starting April 10, 2026.
Click on any entity below to view its context and source!
organisation
RedSun
Attackers used BlueHammer starting April 10, 2026, then followed with RedSun and UnDefend proof-of-concept exploits on April 16.
April 14
Microsoft patched the vulnerability on April 14.
April 16
Attackers used BlueHammer exploiting a vulnerability in Windows starting April 10, 2026.
Click on any entity below to view its context and source!
organisation
RedSun
Attackers used BlueHammer starting April 10, 2026, then followed with RedSun and UnDefend proof-of-concept exploits on April 16.
April 22
Ransomware gangs flagged as exploited by the BlueHammer flaw were ordered to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks.
Click on any entity below to view its context and source!
tactic
Ransomware
CISA
added
the BlueHammer flaw to its Known Exploited Vulnerabilities catalog on April 22 and later updated the entry to note ransomware use.
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
Known Exploited
CISA
added
the BlueHammer flaw to its Known Exploited Vulnerabilities catalog on April 22 and later updated the entry to note ransomware use.
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
tactic
T1588.006 - Vulnerabilities
CISA
added
the BlueHammer flaw to its Known Exploited Vulnerabilities catalog on April 22 and later updated the entry to note ransomware use.
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
infrastructure
Windows
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
vulnerability
CVE-2026-33825
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
BlueHammer
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
KEV
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
Federal Civilian Executive Branch
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
FCEB
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
CVE-2026
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
May 7
Ransomware gangs flagged as exploited by the BlueHammer flaw were ordered to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks.
Click on any entity below to view its context and source!
tactic
Ransomware
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
infrastructure
Windows
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
vulnerability
CVE-2026-33825
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
BlueHammer
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
Known Exploited
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
tactic
T1588.006 - Vulnerabilities
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
KEV
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
Federal Civilian Executive Branch
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
FCEB
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
attribution
CVE-2026
Flagged as exploited by ransomware gangs
CISA
added the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
May 29, 2026
Threat actors exploited a previously unknown vulnerability in Windows to infect systems with the BlueHammer ransomware.
May 31, 2026
Threat actors used a vulnerability in Windows to target systems with macOS operating systems.
Click on any entity below to view its context and source!
infrastructure
Windows
Data from ReliaQuest for the period between March 1 and May 31, 2026, ClickFix
remained
the dominant delivery method during this period and targeted both Windows and macOS systems.
infrastructure
Macos
Data from ReliaQuest for the period between March 1 and May 31, 2026, ClickFix
remained
the dominant delivery method during this period and targeted both Windows and macOS systems.
organisation
ReliaQuest
Data from ReliaQuest for the period between March 1 and May 31, 2026, ClickFix
remained
the dominant delivery method during this period and targeted both Windows and macOS systems.
June 2026
Microsoft fixed the GreenPlasma, MiniPlasma, and YellowKey security flaws in Windows three weeks ago as part of June 2026 Patch Tuesday updates.
Click on any entity below to view its context and source!
organisation
MiniPlasma
Microsoft fixed the GreenPlasma, MiniPlasma, and YellowKey security flaws three weeks ago as part of the
June 2026 Patch Tuesday
updates.
Jul 02, 2026
Threat actors exploited a previously unknown vulnerability in Windows to infect and target systems using the BlueHammer ransomware.
2026/07/02
BlueHammer Exploited Windows Flaw in Ransomware Attacks.
Click on any entity below to view its context and source!
organisation
The U.S. State Department
"This trend reflects a broader strategic change in the threat landscape, one that is designed to increase the likelihood of compromise, expand target coverage, and improve threat actor return on investment."
Russian hacker reward
The U.S. State Department is offering a reward of up to $10 million for information leading to the identification or location of threat actors associated with
UNC5792
, a malicious cyber group associated with the Russian Federal Security Service (FSB) Border Guards and UNC4221, a malicious group of cyber actors working on behalf of the Russian military services.
organisation
the Russian Federal Security Service
"This trend reflects a broader strategic change in the threat landscape, one that is designed to increase the likelihood of compromise, expand target coverage, and improve threat actor return on investment."
Russian hacker reward
The U.S. State Department is offering a reward of up to $10 million for information leading to the identification or location of threat actors associated with
UNC5792
, a malicious cyber group associated with the Russian Federal Security Service (FSB) Border Guards and UNC4221, a malicious group of cyber actors working on behalf of the Russian military services.
organisation
Ransomware
Ransomware phishing lure
A phishing campaign is targeting small businesses across Europe, Asia, the Middle East, and the U.S. with fake investigation emails impersonating law enforcement officials.
organisation
Cofense
"
Platform-aware phishing
Cofense said it's observing a "clear shift in phishing operations" where threat actors are moving beyond broad, one-size-fits-all campaigns to adopt platform-aware delivery that adapts to the victim's device, browser, and environment.
infrastructure
Windows
Phishing campaigns have been found to deliver Itarian RAT or the ConnectWise tool via Ninite Loader on Windows, while serving credential harvesting phishing pages when URLs are visited from macOS or Android.
"What began as simple Windows-focused malware distribution campaigns has evolved into more sophisticated campaigns that can selectively deliver credential phishing, remote access tools, or malware across Windows, MacOS, and Android," it
said
.
BlueHammer ya se utiliza en ciberataques de ransomware contra sistemas Windows.
Aunque el parche está disponible desde hace meses, la confirmación de su uso por parte de operadores de ransomware aumenta la urgencia de actualizar los dispositivos Windows que todavía sigan expuestos.
Windows BlueHammer flaw now exploited by ransomware gangs.
"
Sandbox root escape
New research from Armadin has discovered an attack chain affecting Claude Cowork on Windows.
"As a full-featured remote access trojan, Millenium RAT 4.* is designed to compromise Windows machines," Group-IB
said
.
In Mid April, Huntress researchers reported attackers were exploiting the three Windows flaws to target systems, though the victims and attackers remain unknown.
Un usuario con permisos limitados podría acceder a recursos reservados y terminar ejecutando procesos con privilegios SYSTEM, el nivel más alto disponible en Windows.
El analista de vulnerabilidades Will Dormann explicó que el fallo permite acceder a la base de datos Security Account Manager, conocida como SAM, donde Windows almacena los hashes de las contraseñas de las cuentas locales.
"
Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the
RoguePlanet
,
RedSun
,
GreenPlasma
,
Some of these vulnerabilities affect Microsoft Defender, while others target BitLocker and Windows components.
infrastructure
Macos
Phishing campaigns have been found to deliver Itarian RAT or the ConnectWise tool via Ninite Loader on Windows, while serving credential harvesting phishing pages when URLs are visited from macOS or Android.
"What began as simple Windows-focused malware distribution campaigns has evolved into more sophisticated campaigns that can selectively deliver credential phishing, remote access tools, or malware across Windows, MacOS, and Android," it
said
.
infrastructure
Android
Phishing campaigns have been found to deliver Itarian RAT or the ConnectWise tool via Ninite Loader on Windows, while serving credential harvesting phishing pages when URLs are visited from macOS or Android.
"What began as simple Windows-focused malware distribution campaigns has evolved into more sophisticated campaigns that can selectively deliver credential phishing, remote access tools, or malware across Windows, MacOS, and Android," it
said
.
organisation
ConnectWise
Phishing campaigns have been found to deliver Itarian RAT or the ConnectWise tool via Ninite Loader on Windows, while serving credential harvesting phishing pages when URLs are visited from macOS or Android.
organisation
Ninite Loader
Phishing campaigns have been found to deliver Itarian RAT or the ConnectWise tool via Ninite Loader on Windows, while serving credential harvesting phishing pages when URLs are visited from macOS or Android.
organisation
UNC1151
A spear-phishing attack
orchestrated
by
UNC1151
(aka Ghostwriter) targeting Belarusian pro-democracy politician Yury Hubarevich has been assessed to be part of a much broader credential phishing operation.
organisation
Paste Protect
"
Clipboard attack defense
Opera has introduced Paste Protect, a new security feature designed to block
ClickFix
-style attacks that deceive users into executing malicious commands through social engineering techniques.
organisation
ClickFix
"
Clipboard attack defense
Opera has introduced Paste Protect, a new security feature designed to block
ClickFix
-style attacks that deceive users into executing malicious commands through social engineering techniques.
organisation
BlueHammer Ransomware
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories.
organisation
BlueHammer
BlueHammer ya se utiliza en ciberataques de ransomware contra sistemas Windows.
BlueHammer allows attackers to escalate privileges locally in Microsoft Defender.
organisation
ciberataques de ransomware contra sistemas
BlueHammer ya se utiliza en ciberataques de ransomware contra sistemas Windows.
organisation
Microsoft Defender
Los grupos de ransomware han comenzado a explotar activamente BlueHammer para ciberataques, una vulnerabilidad de escalada de privilegios en Microsoft Defender que permite a un atacante con acceso local elevar sus permisos hasta alcanzar el nivel SYSTEM y tomar el control
"Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally,"
Microsoft explains
in a security advisory.
BlueHammer allows attackers to escalate privileges locally in Microsoft Defender.
organisation
una vulnerabilidad de escalada de privilegios
Los grupos de ransomware han comenzado a explotar activamente BlueHammer para ciberataques, una vulnerabilidad de escalada de privilegios en Microsoft Defender que permite a un atacante con acceso local elevar sus permisos hasta alcanzar el nivel SYSTEM y tomar el control
organisation
un
Los grupos de ransomware han comenzado a explotar activamente BlueHammer para ciberataques, una vulnerabilidad de escalada de privilegios en Microsoft Defender que permite a un atacante con acceso local elevar sus permisos hasta alcanzar el nivel SYSTEM y tomar el control
organisation
el control
Los grupos de ransomware han comenzado a explotar activamente BlueHammer para ciberataques, una vulnerabilidad de escalada de privilegios en Microsoft Defender que permite a un atacante con acceso local elevar sus permisos hasta alcanzar el nivel SYSTEM y tomar el control
organisation
Aunque el
Aunque el parche está disponible desde hace meses, la confirmación de su uso por parte de operadores de ransomware aumenta la urgencia de actualizar los dispositivos Windows que todavía sigan expuestos.
organisation
de operadores de ransomware
Aunque el parche está disponible desde hace meses, la confirmación de su uso por parte de operadores de ransomware aumenta la urgencia de actualizar los dispositivos Windows que todavía sigan expuestos.
organisation
urgencia de actualizar los
Aunque el parche está disponible desde hace meses, la confirmación de su uso por parte de operadores de ransomware aumenta la urgencia de actualizar los dispositivos Windows que todavía sigan expuestos.
organisation
Las vulnerabilidades de escalada de privilegios
De vulnerabilidad local a herramienta para el ransomware
Las vulnerabilidades de escalada de privilegios son especialmente útiles en las operaciones de ransomware.
organisation
las operaciones de ransomware
De vulnerabilidad local a herramienta para el ransomware
Las vulnerabilidades de escalada de privilegios son especialmente útiles en las operaciones de ransomware.
organisation
la primera cuenta comprometida
En muchos casos, la primera cuenta comprometida no dispone de permisos suficientes para desactivar herramientas de seguridad, acceder a datos sensibles o desplegar el ransomware en toda la red.
organisation
Microsoft
Microsoft corrigió CVE-2026-33825 el 14 de abril.
Search hijack extension
Microsoft said it discovered a malicious Chromium-based extension that impersonates the AI-powered answer engine Perplexity AI to trick unsuspecting users into installing it.
The vulnerability, along with two other zero-days dubbed
RedSun
, and
UnDefend
, was
disclosed
by a researcher known as
Chaotic Eclipse
after criticizing Microsoft’s handling of the disclosure.
"Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally,"
Microsoft explains
in a security advisory.
organisation
fue corregida
La vulnerabilidad había sido explotada previamente como día cero y fue corregida por Microsoft el pasado 14 de abril dentro de sus actualizaciones de seguridad mensuales.
organisation
Microsoft el
La vulnerabilidad había sido explotada previamente como día cero y fue corregida por Microsoft el pasado 14 de abril dentro de sus actualizaciones de seguridad mensuales.
organisation
Sandbox
"
Sandbox root escape
New research from Armadin has discovered an attack chain affecting Claude Cowork on Windows.
organisation
Armadin
"
Sandbox root escape
New research from Armadin has discovered an attack chain affecting Claude Cowork on Windows.
organisation
Huntress
In Mid April, Huntress researchers reported attackers were exploiting the three Windows flaws to target systems, though the victims and attackers remain unknown.
According to Huntress, ClickFix was responsible for over
53% of all malware loader activity
in 2025.
organisation
SYSTEM
Un usuario con permisos limitados podría acceder a recursos reservados y terminar ejecutando procesos con privilegios SYSTEM, el nivel más alto disponible en Windows.
organisation
el nivel más alto
Un usuario con permisos limitados podría acceder a recursos reservados y terminar ejecutando procesos con privilegios SYSTEM, el nivel más alto disponible en Windows.
organisation
El analista de vulnerabilidades
El analista de vulnerabilidades Will Dormann explicó que el fallo permite acceder a la base de datos Security Account Manager, conocida como SAM, donde Windows almacena los hashes de las contraseñas de las cuentas locales.
organisation
el fallo permite
El analista de vulnerabilidades Will Dormann explicó que el fallo permite acceder a la base de datos Security Account Manager, conocida como SAM, donde Windows almacena los hashes de las contraseñas de las cuentas locales.
organisation
SAM
El analista de vulnerabilidades Will Dormann explicó que el fallo permite acceder a la base de datos Security Account Manager, conocida como SAM, donde Windows almacena los hashes de las contraseñas de las cuentas locales.
Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts.
organisation
Nightmare
"
Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the
RoguePlanet
,
RedSun
,
GreenPlasma
,
organisation
GreenPlasma
"
Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the
RoguePlanet
,
RedSun
,
GreenPlasma
,
organisation
BitLocker
Some of these vulnerabilities affect Microsoft Defender, while others target BitLocker and Windows components.
organisation
the Microsoft Security Response Center
Dubbed BlueHammer, the security flaw (
CVE-2026-33825
) was
leaked
by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process.
organisation
MSRC
Dubbed BlueHammer, the security flaw (
CVE-2026-33825
) was
leaked
by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process.
infrastructure
62,289 devices
As of writing, 62,289 devices have been infected with the Millenium RAT 4.*
organisation
Hacking News / Cybersecurity News
Ravie Lakshmanan
Jul 02, 2026
Hacking News / Cybersecurity News
This week’s security news is mostly about weak spots.
organisation
Claude Desktop's
The attack allows an attacker with local code execution to plant a malicious file in Claude Desktop's application directory, hijacking a trusted process to communicate with Cowork's underlying VM service.
organisation
Cowork
The attack allows an attacker with local code execution to plant a malicious file in Claude Desktop's application directory, hijacking a trusted process to communicate with Cowork's underlying VM service.
organisation
Claude Cowork's
"An attacker with local code execution could run arbitrary commands as root in Claude Cowork's sandbox without network egress restrictions," the company
said
.
organisation
Apple
A vulnerability has been disclosed in Apple's Hide My Email service that allows users' real email addresses to be unmasked.
organisation
DNS
The malware establishes persistence on the host via scheduled tasks, and resolves the command-and-control infrastructure using DNS-over-HTTPS (DoH) requests.
organisation
the State Department
"Although these malicious cyber activities did not exploit any security vulnerability in the platforms' encryption protections, they have compromised thousands of individual commercial messaging application accounts," the State Department
said
.
organisation
CoT Forgery
The attack, dubbed CoT Forgery, involves injecting fabricated reasoning into user prompts and tool outputs, causing the models to mistake the forgery for their own thoughts and act on them, yielding 60% attack success against frontier models.
organisation
API
The
relevant code
checks Claude Code's
base URL environment variable
that's used to route API requests to a proxy or gateway.
organisation
Opera
"When any kind of suspicious clipboard activity is detected, Opera's Paste Protect warns users before dangerous content can be executed."
organisation
Censys
Attack surface management platform Censys has since
uncovered
additional domains impersonating the I.UA email portal, suggesting the activity also likely targeted Ukrainians.
organisation
FTC
FTC enforcement action
The U.S. Federal Trade Commission has fined Amazon $2.25 million to settle claims that the company failed to help customers who fell victim to identity theft.
organisation
The U.S. Federal Trade Commission
FTC enforcement action
The U.S. Federal Trade Commission has fined Amazon $2.25 million to settle claims that the company failed to help customers who fell victim to identity theft.
organisation
Amazon
FTC enforcement action
The U.S. Federal Trade Commission has fined Amazon $2.25 million to settle claims that the company failed to help customers who fell victim to identity theft.
financial
$2.25 Amazon
FTC enforcement action
The U.S. Federal Trade Commission has fined Amazon $2.25 million to settle claims that the company failed to help customers who fell victim to identity theft.
organisation
FTC’s Bureau of Consumer Protection
"Amazon often puts identity theft victims through a Kafkaesque ordeal by demanding they identify the thief who stole their information before Amazon would release the records the law entitles them to – records that could help victims protect themselves and recover from the fraudulent conduct,"
said
Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection.
organisation
Y2K Operators
Exploitation campaigns involving the malware are carried out by a threat actor cluster codenamed Y2K Operators.
organisation
Group-IB
"They take popular RATs, builders, and exploit kits, add a backdoor, and redistribute them — so the would-be attacker downloads a working tool and gets infected at the same time," Group-IB said.
organisation
Chromium
Search hijack extension
Microsoft said it discovered a malicious Chromium-based extension that impersonates the AI-powered answer engine Perplexity AI to trick unsuspecting users into installing it.
organisation
Perplexity AI
Search hijack extension
Microsoft said it discovered a malicious Chromium-based extension that impersonates the AI-powered answer engine Perplexity AI to trick unsuspecting users into installing it.
organisation
Google
The extension, named "Search for Perplexity ai" (ID: flkebkiofojicogddingbdmcmkpbplcd), has since been taken down by Google, but not before it attracted 10,000 installs.
infrastructure
10,000 installs
The extension, named "Search for Perplexity ai" (ID: flkebkiofojicogddingbdmcmkpbplcd), has since been taken down by Google, but not before it attracted 10,000 installs.
organisation
Manifest Version
"However, unlike traditional search hijackers that rely primarily on aggressive monetization or visible redirection, this extension combines Manifest Version 3 (MV3) capabilities with intermediary infrastructure and declarativeNetRequest (DNR) rules to transparently intercept Omnibox queries while preserving the appearance of legitimate search results."
organisation
DNR
"However, unlike traditional search hijackers that rely primarily on aggressive monetization or visible redirection, this extension combines Manifest Version 3 (MV3) capabilities with intermediary infrastructure and declarativeNetRequest (DNR) rules to transparently intercept Omnibox queries while preserving the appearance of legitimate search results."
organisation
Teams
"That's why we're introducing a new Teams admin policy designed to give organizations more visibility and control over external bots in their meetings.
organisation
CAPTCHA
With these new safeguards rolling out, Microsoft plans to retire the existing CAPTCHA verification experience.
financial
$10 month
It is offered as malware-as-a-service (MaaS) for $50 for the first month, $10 for subsequent months, or a one-time $90 lifetime purchase.
financial
$90 $ lifetime
It is offered as malware-as-a-service (MaaS) for $50 for the first month, $10 for subsequent months, or a one-time $90 lifetime purchase.
organisation
Tharros
Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts.
organisation
BleepingComputer
Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts.
organisation
la gestión de permisos permite
Según la descripción de Microsoft, una granularidad insuficiente en la gestión de permisos permite que un atacante autorizado localmente eleve sus privilegios dentro del sistema.
organisation
Esto
Esto significa que el
fallo
no permite comprometer un equipo directamente desde internet.
organisation
Sin
Sin embargo, una vez dentro, la vulnerabilidad puede ser decisiva para avanzar en el ataque.
organisation
una vez dentro
Sin embargo, una vez dentro, la vulnerabilidad puede ser decisiva para avanzar en el ataque.
organisation
El
El acceso a esta información puede facilitar el robo de credenciales, el movimiento lateral hacia otros sistemas y la consolidación del control sobre el dispositivo.
organisation
el robo de credenciales
El acceso a esta información puede facilitar el robo de credenciales, el movimiento lateral hacia otros sistemas y la consolidación del control sobre el dispositivo.
organisation
el movimiento
El acceso a esta información puede facilitar el robo de credenciales, el movimiento lateral hacia otros sistemas y la consolidación del control sobre el dispositivo.
organisation
los atacantes podrían
Tras elevar sus privilegios, los atacantes podrían manipular defensas, extraer credenciales, crear nuevas cuentas administrativas, desactivar servicios y ejecutar el cifrado con mayores garantías de éxito.
organisation
extraer
Tras elevar sus privilegios, los atacantes podrían manipular defensas, extraer credenciales, crear nuevas cuentas administrativas, desactivar servicios y ejecutar el cifrado con mayores garantías de éxito.
organisation
el cifrado
Tras elevar sus privilegios, los atacantes podrían manipular defensas, extraer credenciales, crear nuevas cuentas administrativas, desactivar servicios y ejecutar el cifrado con mayores garantías de éxito.
organisation
la cadena de ataque
Este tipo de vulnerabilidad no suele constituir por sí sola toda la cadena de ataque, pero puede convertirse en una pieza fundamental para transformar una intrusión limitada en un compromiso completo.
organisation
El exploit
El exploit se filtró antes del parche
BlueHammer fue divulgada a comienzos de abril por un investigador conocido como “Nightmare Eclipse”, quien publicó además un código de prueba de concepto.
organisation
un código de prueba de concepto
El exploit se filtró antes del parche
BlueHammer fue divulgada a comienzos de abril por un investigador conocido como “Nightmare Eclipse”, quien publicó además un código de prueba de concepto.
organisation
los procesos de comunicación de vulnerabilidades
Centro de Respuesta de Seguridad de Microsoft gestionaba los procesos de comunicación de vulnerabilidades.
organisation
una corrección aumentó
La publicación del exploit antes de que la mayoría de los usuarios pudiera aplicar una corrección aumentó considerablemente el riesgo.
organisation
el riesgo
La publicación del exploit antes de que la mayoría de los usuarios pudiera aplicar una corrección aumentó considerablemente el riesgo.
organisation
parte de los operadores
Los ataques observados mostraban actividad manual directa por parte de los operadores, lo que sugiere que la vulnerabilidad estaba siendo utilizada dentro de intrusiones dirigidas y no únicamente mediante herramientas automatizadas.
organisation
siendo
Los ataques observados mostraban actividad manual directa por parte de los operadores, lo que sugiere que la vulnerabilidad estaba siendo utilizada dentro de intrusiones dirigidas y no únicamente mediante herramientas automatizadas.
organisation
dentro de intrusiones dirigidas
Los ataques observados mostraban actividad manual directa por parte de los operadores, lo que sugiere que la vulnerabilidad estaba siendo utilizada dentro de intrusiones dirigidas y no únicamente mediante herramientas automatizadas.
organisation
El código de prueba podía
El código de prueba podía servir a otros investigadores para estudiar el fallo, pero también proporcionaba a los atacantes una base para desarrollar herramientas operativas.
organisation
el fallo
El código de prueba podía servir a otros investigadores para estudiar el fallo, pero también proporcionaba a los atacantes una base para desarrollar herramientas operativas.
organisation
apuntaban
Sin embargo, pocos días después, investigadores de Huntress Labs informaron de señales que apuntaban a su explotación como vulnerabilidad de día cero antes de la llegada del parche.
organisation
Dormann
“At that point, [the attackers] basically own the system, and can do things like spawn a SYSTEM-privileged shell,” Dormann said.
organisation
Huntress Labs
However, days later, Huntress Labs security researchers revealed that threat actors
had been exploiting it as a zero-day
in attacks that showed evidence of "hands-on-keyboard threat actor activity.
organisation
YellowKey
MiniPlasma
,
YellowKey
, and
UnDefend
flaws.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Phishing campaigns have been found to deliver Itarian RAT or the ConnectWise tool via Ninite Loader on Windows, while serving credential harvesting phishing pages when URLs are visited from macOS or Android.
"What began as simple Windows-focused malware distribution campaigns has evolved into more sophisticated campaigns that can selectively deliver credential phishing, remote access tools, or malware across Windows, MacOS, and Android," it
said
.
"
Sandbox root escape
New research from Armadin has discovered an attack chain affecting Claude Cowork on Windows.
Data from ReliaQuest for the period between March 1 and May 31, 2026, ClickFix
remained
the dominant delivery method during this period and targeted both Windows and macOS systems.
"As a full-featured remote access trojan, Millenium RAT 4.* is designed to compromise Windows machines," Group-IB
said
.
In Mid April, Huntress researchers reported attackers were exploiting the three Windows flaws to target systems, though the victims and attackers remain unknown.
BlueHammer ya se utiliza en ciberataques de ransomware contra sistemas Windows.
Aunque el parche está disponible desde hace meses, la confirmación de su uso por parte de operadores de ransomware aumenta la urgencia de actualizar los dispositivos Windows que todavía sigan expuestos.
Un usuario con permisos limitados podría acceder a recursos reservados y terminar ejecutando procesos con privilegios SYSTEM, el nivel más alto disponible en Windows.
El analista de vulnerabilidades Will Dormann explicó que el fallo permite acceder a la base de datos Security Account Manager, conocida como SAM, donde Windows almacena los hashes de las contraseñas de las cuentas locales.
Windows BlueHammer flaw now exploited by ransomware gangs.
…the BlueHammer flaw
to its
Known Exploited Vulnerabilities (KEV) Catalog
on April 22, ordering Federal Civilian Executive Branch (FCEB) agencies to patch their Windows devices against ongoing CVE-2026-33825 attacks within two weeks, until May 7.
"
Over the past several months, Nightmare Eclipse has disclosed multiple other Windows zero-day exploits, including for the
RoguePlanet
,
RedSun
,
GreenPlasma
,
Some of these vulnerabilities affect Microsoft Defender, while others target BitLocker and Windows components.
Metrics
infrastructure
Macos
Affected Product
Phishing campaigns have been found to deliver Itarian RAT or the ConnectWise tool via Ninite Loader on Windows, while serving credential harvesting phishing pages when URLs are visited from macOS or Android.
"What began as simple Windows-focused malware distribution campaigns has evolved into more sophisticated campaigns that can selectively deliver credential phishing, remote access tools, or malware across Windows, MacOS, and Android," it
said
.
Data from ReliaQuest for the period between March 1 and May 31, 2026, ClickFix
remained
the dominant delivery method during this period and targeted both Windows and macOS systems.
Metrics
infrastructure
Android
Affected Product
Phishing campaigns have been found to deliver Itarian RAT or the ConnectWise tool via Ninite Loader on Windows, while serving credential harvesting phishing pages when URLs are visited from macOS or Android.
"What began as simple Windows-focused malware distribution campaigns has evolved into more sophisticated campaigns that can selectively deliver credential phishing, remote access tools, or malware across Windows, MacOS, and Android," it
said
.
Metrics
financial
2,250,000
Amazon
FTC enforcement action
The U.S. Federal Trade Commission has fined Amazon $2.25 million to settle claims that the company failed to help customers who fell victim to identity theft.
Metrics
infrastructure
10,000
Installs
The extension, named "Search for Perplexity ai" (ID: flkebkiofojicogddingbdmcmkpbplcd), has since been taken down by Google, but not before it attracted 10,000 installs.
Metrics
financial
10
Month
It is offered as malware-as-a-service (MaaS) for $50 for the first month, $10 for subsequent months, or a one-time $90 lifetime purchase.
Metrics
financial
90
$ Lifetime
It is offered as malware-as-a-service (MaaS) for $50 for the first month, $10 for subsequent months, or a one-time $90 lifetime purchase.
Metrics
infrastructure
62,289
Devices
As of writing, 62,289 devices have been infected with the Millenium RAT 4.*
Intelligence Sources
BleepingComputer
2026-06-30
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
BleepingComputer
Bit Life Media
2026-07-01
Security Affairs
2026-07-01
CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks
Security Affairs
The Hacker News
2026-07-02
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-03T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
96x
organisation
Identified Entity
The U.S. State Department
entity
17x
attribution
Attributing Entity
Signal
authority
16x
timeline
Temporal Reference
May 2025
date
6x
tactic
Cyber Operation Type
Espionage
tactic
5x
tactic
MITRE ATT&CK Technique
T1496.001 - Compute Hijacking
technique
4x
general metric
%
100
%
4x
target region
Target Country
Belarus
country
3x
industry
Targeted Sector
Media
sector
3x
infrastructure
Affected Product
Windows
software
2x
source region
Origin Country
China
country
2x
target region
Target Region
MIDDLE_EAST
region
Contextual Telemetry
Context Block
12 METRICS
general metric
Media
404
media
general metric
Stories
14
stories
vulnerability
Exploited CVE
CVE-2026-33825
cve
general metric
Millenium Rat
4
millenium rat
general metric
Jul
2
jul
financial
Amazon
2,250,000
amazon
general metric
Infections
16,000
infections
infrastructure
Installs
10,000
installs
general metric
Manifest Version
3
manifest version
financial
Month
10
month
financial
$ Lifetime
90
$ lifetime
infrastructure
Devices
62,289
devices
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.