INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Atlas ASM Asset Management System Breached Due to Inability

| 2026-10-06 07:51 HIGH HIGH MALWARE & BOTNETS CYBERATTACK (GENERAL)
Executive Summary
AI-generated
The financial institution's "Atlas ASM" asset management system, which manages 270,000 financial assets, has been breached repeatedly due to its inability to withstand continuous hacking attempts. According to the Financial Security Institute, as of June this year, the financial institution has been operating the ASM service for financial institutions since December last year, with 147 financial institutions using the service and identifying over 270,000 items of external assets exceeding the financial sector. The attack works by exploiting internal vulnerabilities such as identity verification and access control errors, undiscovered vulnerabilities, and zero-day attacks that are not detected by the system's ASM scanning stage. As a result, the current status is one of repeated breaches, with no guarantee that the current attack can be completely prevented despite using ASM.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-0257 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

5e20d8••••••••••••••••••••••••••••••••••
1d8332••••••••••••••••••••••••••••••••••
f6e4fa••••••••••••••••••••••••••••••••••
fdaee6••••••••••••••••••••••••••••••••••
255314••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
0c36cf••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
10de61••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
3f2f48••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
qr•••••.br
in•••••.online
wa•••••.com
nu•••••.com
7a7d96••••••••••••••••••••••••••
0e00ad••••••••••••••••••••••••••
271671••••••••••••••••••••••••••
7f1cba••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
91.92.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation MasterOperation Master CVE-2026-0257CVE-2026-0257
Target & Sectors
NORDICS NORDICS BENELUX BENELUX LATAM LATAM NORTH_AMERICA NORTH_AMERICA energyenergy retailretail financefinance
Incident Timeline
‎September 10 to 15
Threat actors used penetration test tools Strix and Cairn, along with an autonomous AI agent Hermes, to conduct attacks against 27 companies from September 10 to 15.
general_metric 146 times
infrastructure 138 hosts
general_metric 105 attacks
general_metric 27 companies
‎2025/10/06
Threat actors, identified as BraZetsu, supplied an underground ecosystem with malware targeting the 'Atlas ASM' service operated by a financial institution since December last year.
attribution the Financial Security Institute
‎February 2026
Threat actors, identified as BraZetsu, began supplying an underground ecosystem with a malware that rapidly evolved from basic remote access to an AI-enhanced intelligence collection platform starting in February 2026.
‎August 25
Threat actors used an OpenRouter account to spend $7,005.71 over roughly four weeks as of August 25.
organisation OpenRouter
financial $7,005.71 account
‎2026/09/22
Threat actors using Hermes and claude-opus-4.6 orchestrated malicious activity against 138 hosts over a period of eight days, from August 23 to September 1, 2023.
general_metric 146 times
infrastructure 138 hosts
infrastructure 4.6
general_metric 633 August
‎September 22
Threat actors, identified as BraZetsu, have been supplying an underground ecosystem with malware since at least July.
‎2026/10/06
Threat actors used ARTEX AI and other open-source tools to target hundreds of online retailers, stealing over 600,000 credit card records.
infrastructure Windows
organisation Attack Surface Management
organisation ASM
organisation Advanced Security Management
organisation DBMS
organisation The Financial Security Institute
organisation the YG Bank
organisation the S2W Integrated Analysis Room
organisation Shinhan Bank's
organisation Shinhan Bank
infrastructure 270,000 financial assets
organisation Fortinet
organisation Hestra Strike
organisation ARTEX
organisation LLM
organisation ARTEX AI
organisation Juniper Security Center
data_breach 10 September
data_breach 15 September
organisation Androptic
organisation GLM
organisation DeepSight
organisation HexStrike AI
organisation CyberStrike AI
organisation a Multi-Tiered Intrusion
organisation CVE-2026-0257
organisation GlobalProtect
organisation SQL
organisation xp_cmdshell
victims 81 value targets
organisation BraZetsu
organisation Initial Access Brokers
organisation Exilware
organisation Magento
organisation Google
organisation S3
organisation Kubernetes
organisation NFL
organisation CHANEL
data_breach 600,000 card records
financial $12,000 $ total costs
‎August 23 to 31
Threat actors used the penetration test tool Strix in deep mode 146 times and then Cairn with Hermes AI to conduct 105 attacks, causing damage to more than 27 companies.
general_metric 146 times
infrastructure 138 hosts
general_metric 105 attacks
general_metric 27 companies
‎between August 23 and 31
Threat actors using Hermes and claude-opus-4.6 orchestrated post-exploitation work against 138 hosts between August 23 and 31, accumulating 633 scanning hours.
general_metric 146 times
infrastructure 138 hosts
infrastructure 4.6
general_metric 633 August
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
270,000
Financial Assets
Metrics
infrastructure
138
Hosts
Metrics
victims
81
Value Targets
Metrics
infrastructure
‎4.6
Software Version
Metrics
financial
7,006
Account
Metrics
data_breach
600,000
Card Records
Metrics
data_breach
10
September
Metrics
data_breach
15
September
Metrics
financial
12,000
$ Total Costs