ASD’s ACSC advisory (first published / last updated 8 September 2026) explains how financially motivated crypters advertise on dark-web forums and sell specialised crypter software that obfuscates, anti-analyses, and cryptographically scrambles malware so it can run while remaining “fully undetected” (FUD). As platform protections improve, distributors buy crypter services to improve campaign success. ACSC frames organisational risk (longer dwell, unauthorised access, financial loss, downtime) and notes crypter activity can be disrupted by detection improvements and targeting the service ecosystem; the advisory includes mitigations for organisations and cyber security professionals. Audience: large organisations and infrastructure / government. No CVE. Primary: ACSC advisory. Rechecked on the 17 September 2026 13:00 Perth desk pass (still listed on ACSC alerts and advisories).
ACSC — Digital camouflage: crypters make malware undetectable (8 Sep 2026)
australia
BleepingComputer (8 September 2026) covers German firm Nebty’s report on DoppelCart, a fake e-shop cluster of more than 119,000 domains (mostly .SHOP; Nebty says ~2.72% of that TLD), with more than 105,000 still active in latest scans. About 96% of confirmed shops share identical build files and resolve to 27 commerce backends; they impersonate ~44,182 brands (median two clones each; some brands >30 clones) and advertise discounts up to ~65%. Checkout pages collect PAN, expiry, CVV, name, email, phone and address over WebSockets to C2 in real time, and can relay bank OTPs. Victims sometimes email the real brand’s support address shown on the fake shop. Nebty built a searchable brand-abuse database and said the main hosting provider did not respond. Distinct from BogusBazaar (~75k sites). Wire: BleepingComputer; research: Nebty.
BleepingComputer — DoppelCart (8 Sep 2026)
tech cloud identity
SOCRadar (covered by The Hacker News, ~7 September 2026) documents PEEP, a Chromium-based post-exploitation toolkit that requires prior admin or code-execution access. An installer injects a malicious extension masquerading as "Smart Bookmarks" into Chrome/Edge profiles; the extension (based on the open-source RedExt framework) beacons for commands, harvests browser data, and uses a native messaging host (nm_host.exe) for host-level command execution and file management. Chinese-language artifacts in the source point to a Chinese-speaking actor; activity remains unattributed. Distinct from browser-infostealer cards: this is a post-compromise backdoor, not an initial-access drop. Primary wire: The Hacker News; research: SOCRadar.
The Hacker News — PEEP Chromium toolkit (~7 Sep 2026)
tech identity cloud
Netskope Threat Labs (covered by BleepingComputer, 5 September 2026) describe an ongoing campaign on more than 5,400 compromised sites (mostly WordPress and PrestaShop) that inject a script fetching the next-stage payload from a Binance Smart Chain Testnet smart contract — EtherHiding — so operators can rotate payloads without retaking the site. The lure is ClickFix: a fake CAPTCHA that tells the visitor to open Windows Run and paste a PowerShell command. Later variants replace the ClickFix stage with a WebRTC data-channel stager that opens a covert channel to attacker infrastructure and runs received JavaScript in browser memory. Telemetry showed roughly 300–400 sites hitting BSC Testnet RPC endpoints daily through summer 2026, peaking near 536 in August. Distinct from the ACSC ClickFix/Vidar-via-WordPress Australia advisory (separate desk card): this card is the blockchain-backed delivery pattern. Defenders: block BSC Testnet RPC where policy allows, treat unexpected Run/paste prompts as hostile, and hunt injected site scripts that call testnet endpoints. Primary: Netskope blog.
Netskope — malware on the blockchain / WebRTC twist
tech network
Rapid7 Labs (4 September 2026) describes a Linux toolkit that compiles the Ted implant into victims' own HAProxy 2.8.x builds so it can intercept selected web traffic, hide C2 from HAProxy stats, rewrite responses, and run commands via a named pipe under /tmp. It is not an HAProxy CVE: operators need code execution on the host and the ability to replace binaries. Companion tooling includes a trojanized sshd password logger, a stager that overwrites crond (CentOS 7.7-7.9 / Ubuntu 22.04 paths cited), and curlRAT (distinct from SideCopy's CurlBack). Rapid7 attributes the activity with medium confidence to DPRK APTs (ThreatFox/maltrail links to APT37 C2 lists) against South Korean automotive and media victims; initial access is hypothesised via exposed Groupware/mail edges consistent with Kimsuky tradecraft, not proven. Hunt for unexpected HAProxy rebuilds, crond/sshd replacements, and the IoCs in Rapid7's post; do not expose Groupware portals without patching and MFA.
Rapid7 Labs (4 Sep 2026)
tech network supply chain
Microsoft Security Research (3 September 2026) documents a high-volume phishing campaign that inserts invisible Unicode Tags-block characters (U+E0000-U+E007F) inside finance lure words such as funding so human readers still see the word while keyword/regex filters miss the contiguous string. Telemetry tied to a Defender for Office 365 hunting signature rose from about 21,000 hits on 8 February 2026 to more than 1.3 million the next day, stayed elevated on weekdays for roughly three months, and dropped sharply after 15 May 2026 (weekday peaks cited up to about 2.37 million). Microsoft links the Unicode-obfuscated wave to a broader ActiveCampaign-relayed SBA/finance-themed phishing cluster previously described by Fortra, with disposable finance-themed domains and click-tracking via ActiveCampaign hosts. Defenders should strip or normalise Unicode tag characters before keyword detection, hunt U+E0000-U+E007F outside legitimate subdivision-flag emoji use, and treat marketing-platform abuse as a reputation-filter complication.
Microsoft Security Blog (3 Sep 2026)
tech email identity ai
The Hacker News (3 September 2026) summarises a Symantec Threat Hunter Team report: since February 2026, operators have abused the legitimate, signed node.exe runtime to execute malicious JavaScript rather than dropping unsigned binaries, with registry Run-key persistence, against government, technology and hotel targets. One Asian technology company intrusion (March–July 2026) installed official Node.js from nodejs.org after ClickFix access, then used EtherHiding-style retrieval after AdaptixC2/Cobalt Strike beacons were blocked. Related tooling includes ModeloRAT, Mistic/MLTBackdoor (KongTuke/Woodgnat), GateKeeper, NexShield Chrome extension, and C2Looper against a U.S. fintech. Prefer application-control policies that constrain node.exe outside developer workstations; hunt for unexpected node.exe + Run keys and EtherHiding beacons.
The Hacker News (3 Sep 2026)
tech identity
The Hacker News (3 September 2026) summarises Group-IB research on BraZetsu, a modular Python-based Windows malware framework attributed to Portuguese-speaking operators tracked as Exilware. Unlike a simple infostealer, BraZetsu is described as a master toolkit for initial access brokers: it commercialises access to compromised hosts for Iberian and Latin American e-commerce and corporate targets, with modular staging and stealth that left some samples fully undetectable on VirusTotal at analysis time. Name blends Brazil with the Naruto character Zetsu. Defenders in those regions should hunt for the BraZetsu toolkit behaviours in Group-IB’s write-up, restrict script interpreters where policy allows, and treat brokered access listings as post-compromise inventory rather than the root cause.
The Hacker News (3 Sep 2026)
tech identity
Cyber Security Minister Tony Burke launched the pilot of Australia's Voluntary Security Labelling Scheme for Smart Devices (SLSSD) at the Connecting Technology Summit on 2 September 2026. The scheme is co-developed by the Department of Home Affairs and the Connected Technology Alliance (CTA), funded by Home Affairs, and sits under the 2023–2030 Australian Cyber Security Strategy. Labels give consumers an independently verified Level 1–4 security rating for consumer-grade smart-home IoT (TVs, doorbells/cameras, baby monitors, robot vacuums, solar inverters; not cars, medical devices, phones, tablets or PCs). Pilot vendors named: NetComm, Telstra, ASSA ABLOY/Lockwood, Electrolux; labs: Viden, Securus Consulting Group, Teron Labs, DEKRA, TÜV SÜD. Industry pilot phase from about October 2026; voluntary labels expected on products from 2027. Distinct from the mandatory Cyber Security (Security Standards for Smart Devices) Rules 2025 (commenced 4 March 2026) that require no default passwords, vulnerability reporting paths, and update-policy clarity, with a statement of compliance — the SLSSD badge is designed to surface that compliance. Primary: CTA Labelling Scheme page; wires: techpartner.news 3 Sep, ACS Information Age 8 Sep.
Connected Technology Alliance — Security Labelling Scheme for Smart Devices
australia
Elastic Security Labs (2 September 2026) analyses REVSTEALER, an emerging Windows infostealer that hides backup C2 addresses in Polygon smart contracts, and documents four follow-on modules delivered by C2 tasking: ProManager (wallet-file and browser-extension theft, phishing overlays, password-aware input capture and payload delivery), WinUpdate (cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (reverse SOCKS5 proxy / backconnect over an encrypted WebSocket), and LockAppHost (XMRig miner deployment, competitor suspension, and persistence). The four modules share obfuscated configuration, VMProtect-style packing, and Polygon dead drops for replaceable settings including C2 endpoints and XMRig command lines. Elastic also covers CIS locale exclusion checks, sandbox scoring, credential harvesting, payload watermarking, and self-deletion. Observed distribution includes game-cheat social engineering — Elastic identified at least 17 YouTube channels promoting elitecheatsx.live and resight-cheats.net — plus builds whose names and metadata impersonate unrelated software (Slack, qBittorrent, SteelSeries GG, Blender, and others). Gen Threat Labs covered the family earlier in 2026. The Hacker News (6 September 2026) summarises the Elastic activity set. Primary: Elastic Security Labs Threat Command report.
Elastic Security Labs — REVSTEALER (2 Sep 2026)
tech identity
The Hacker News (2 September 2026) reports Check Point Research tracking Chinese-speaking cluster Gambling Goblin since mid-2025 installing malicious Apache modules on compromised Brazilian government and education web servers. Modules reverse-proxy visitors to phishing pages that spoof Google Play, Microsoft Store and Amazon while stripping security headers, mainly to inflate SEO for online gambling. ANY.RUN had previously noted at least 20 .gov.br municipal and police portals abused in related distribution. Hunt for unexpected Apache modules/loadable objects, outbound reverse-proxy behaviour, and stripped CSP/HSTS on public sites.
The Hacker News (2 Sep 2026)
vulnerabilities network
Citizen Lab (2 September 2026), with the SHARE Foundation, confirmed that an iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware via an iMessage zero-click exploit. High-confidence indicators cover December 2025–January 2026; Citizen Lab assesses the exploit was addressed in Apple iOS 18.4.1 (April 2025). SHARE has documented at least 14 recent Apple Threat Notifications among Serbian students, civil society and an opposition MP ahead of 2026 election cycles; Amnesty has separately described related Android spyware (NoviSpy-like) installed during detention. Primary: Citizen Lab research note. Recipients of Apple Threat Notifications should treat devices as presumed targeted and seek forensic help; keep iOS current.
Citizen Lab (2 Sep 2026)
breaches identity