GajShield Threat Intelligence

Live protection updates from GajShield's indigenous security research and threat intelligence team.

This page documents new and updated detections developed for GajShield security engines, including IPS, Anti-Malware, malicious infrastructure and emerging threat intelligence.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: JWT alg:none authentication bypass attempt

Severity: MEDIUM · Priority: P3 — technique tripwire, tune before relying on

This rule raises an alert when a web request carries a JSON Web Token (JWT) whose header declares that it has no signature. JWTs are digital tokens many applications use to prove a user is logged in; a properly issued one is cryptographically signed so it can't be forged. A token marked with the "none" algorithm claims to need no signature — a long-known trick where an attacker strips the signature and edits the token's contents (for example, changing their role to administrator) in the hope that a poorly configured server accepts it as genuine. This rule watches for that tell-tale "none" marker in incoming tokens, covering several ways it can be spelled.

A hit means something sent a token that asks to skip signature checking. On most systems that is abnormal and worth investigating, but it is not by itself proof of a successful break-in — it flags an attempt or a misconfiguration, and whether it works depends entirely on how the receiving application validates tokens. A correctly configured, patched application rejects these tokens outright. Treat an alert as a prompt to check which application received the token and whether it is hardened against this technique.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Citrix NetScaler SAML authentication bypass, CVE-2026-19490

Severity: CRITICAL · Priority: P1 — active exploitation, escalate on hit

This rule raises an alert when an attacker attempts to exploit a critical authentication-bypass flaw in Citrix NetScaler ADC and NetScaler Gateway appliances — the devices many organisations use as their remote-access (VPN) and single-sign-on front door. The flaw lets an unauthenticated attacker forge a valid login session in a single request to the appliance's SAML sign-on path, without any credentials or user interaction. On a vulnerable, exposed Gateway that can mean anonymous access to internal applications, and it is being chained with a companion flaw to reach full remote code execution. This rule watches for the crafted sign-on request used in that attack.

A hit here is a high-urgency signal. The flaw is rated critical (9.3), is confirmed under active exploitation, and targets the security appliance that guards remote access — so a success can expose the internal network behind it. Treat an alert as an active attack against the NetScaler appliance.

On a hit: identify whether the targeted device is a Citrix NetScaler configured for SAML authentication (an AAA or Gateway virtual server with a SAML action), and whether it is on a fixed software build — note that early hotfixes for the related flaw are not sufficient for this one, so verify against the latest recommended build for the branch. Impact depends on configuration; Gateway virtual servers are the higher-risk case. If the appliance is unpatched, assume potential compromise and escalate to incident response: review appliance access logs for repeated unauthenticated requests to the SAML and related sign-on paths from external addresses, hunt for unexpected script files created outside update windows on the appliance, and rotate credentials and session material. Upgrading to the fixed build is the definitive fix.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Cisco Secure Email Gateway crafted-email SQL-injection root RCE, CVE-2026-76461

Severity: CRITICAL · Priority: P1 — active exploitation, escalate on hit

This rule raises an alert when an inbound email arriving at one of our mail gateways contains the signature of an attack against a critical flaw in Cisco Secure Email Gateway appliances. The flaw is in the part of the appliance that reads and parses incoming email: a specially crafted message can smuggle database commands into the appliance, which then runs them — ultimately allowing an unauthenticated attacker to take full, highest-level (root) control of the device just by sending it an email. No password, no login, and no action by any recipient is needed. This rule looks for the specific command pattern used to turn that database access into command execution on the appliance.

A hit here is a high-urgency signal. The flaw is rated among the most severe possible (9.8 out of 10), Cisco has confirmed it is being exploited in the wild, and government authorities have placed it on their catalogue of known-exploited vulnerabilities with an emergency patch deadline. Because the target is the email gateway itself — the device that sees all inbound mail — a compromise is especially serious: it can expose mail in transit, appliance credentials, and provide a foothold into connected systems. Treat an alert as an active attack against the mail appliance.

On a hit: identify whether the receiving appliance is a Cisco Secure Email Gateway and whether it is running a fixed software release; both physical and virtual appliances are affected in any configuration. If it is unpatched, assume potential compromise and escalate to incident response immediately. Note Cisco's own guidance that an attacker with root can erase or hide evidence on the device, so on-device logs alone should not be trusted to rule out compromise — corroborate with network and firewall logs, and where compromise is suspected, rebuild affected virtual appliances from a clean fixed release and rotate all credentials and cryptographic material on the device. Applying Cisco's update is the definitive fix.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update: WooCommerce Wholesale Lead Capture unauthenticated file-upload RCE, CVE-2026-27540

Severity: CRITICAL · Priority: P1 — active exploitation, block/escalate on hit

This rule raises an alert when an attacker attempts to exploit a critical flaw in the WooCommerce Wholesale Lead Capture plugin for WordPress to upload a malicious file to one of the web servers. The plugin has a file-upload feature that, in vulnerable versions, can be tricked into accepting executable PHP files from anyone on the internet — no login or user interaction required. A successful attempt lets the attacker plant a hidden control file (a webshell) and run commands on the site, which can lead to full compromise. This rule watches for the specific upload request used in that attack.

A hit here is a high-confidence, high-urgency signal. This is not background noise — the request pattern has no legitimate use, the flaw is rated among the most severe (9.8 out of 10), and it is being exploited in the wild right now. Treat an alert as an active exploitation attempt against the targeted server.

On a hit: confirm whether the affected site runs the WooCommerce Wholesale Lead Capture plugin and whether it has been updated to the fixed version (2.0.3.2 or later); versions 2.0.3.1 and earlier are vulnerable. If the site is unpatched, assume the attempt may have succeeded, escalate to incident response, and check for newly uploaded files in the site's upload folders and any unexpected administrator accounts (a related flaw in the same plugin allows attackers to create admin users). The lasting fix is to update the plugin.

Antivirus Sep 16, 2026

GajAV - Malware Signature Update — HEAVYGRAM / CHOSEN BRICK (Iranian state-linked Telegram spyware)

What this update does

We have updated your product's malware signatures to add detection for HEAVYGRAM, a spyware toolkit also tracked as CHOSEN BRICK. This note is to inform you that the signatures are now available. We recommend confirming your product is set to receive signature updates so this detection is applied.

What the threat is

HEAVYGRAM is spying malware attributed by a joint UK, US, and Netherlands government advisory to Iran's Ministry of Intelligence and Security (MOIS). Rather than targeting organisations broadly, this campaign has focused on specific individuals — Iranian dissidents, journalists, activists, and opposition figures — in the UK, US, Netherlands, and elsewhere, and has been active over a period of years.

The malware reaches victims through social engineering, typically a message or file the target is persuaded to open. Once installed, it gives the attackers remote access to the device to monitor activity and steal data, and it has been used to support "hack-and-leak" operations intended to damage the reputations of those targeted.

Why it's notable

A distinctive feature of this malware is that it is operated through the Telegram messaging platform, which the attackers use to control infected devices and retrieve stolen information. It also routes some of its activity through ordinary, legitimate online services to blend in with normal traffic and avoid standing out. Official reporting notes that the malware's file names and folder locations change over time, so no single indicator should be relied on alone — the updated signatures target the underlying behaviours rather than surface details.

What we recommend

  • Ensure signature updates are enabled so the new and future detections are applied.
  • Treat unexpected files or links shared through messaging apps with caution, and obtain software only from official sources.
  • Keep operating systems and applications current, ideally through automatic updates.
  • Do not dismiss download or security warnings from the browser or operating system.
  • For higher-risk individuals, phishing-resistant multi-factor authentication and managed-device controls such as application allow-listing add meaningful protection.
Antivirus Sep 16, 2026

GajAV - Malware Signature Update — KREMLIN / REF9334 Brazilian banking malware (malicious Chrome & Edge extension)

What this update does

We have updated the product's malware signatures to detect and block KREMLIN, a banking-fraud toolkit tracked by researchers as REF9334. 

What the threat is

KREMLIN is a credential-stealing operation that has been active since at least mid-2025 and primarily targets customers of Brazilian banks. It reaches victims through fake messages and files that impersonate around a dozen well-known banks. If a user is tricked into opening the lure, the malware quietly installs a malicious add-on (extension) into the Google Chrome or Microsoft Edge browser.

Once in place, that extension can capture banking logins, active login sessions, saved cookies, browsing activity, and other sensitive information, and send it to the attackers. Because it hijacks an already-logged-in browser session, it can be used to commit fraud even where a password alone would not be enough. Reporting indicates well over a thousand systems were affected, the overwhelming majority in Brazil.

Why it's notable

This malware is designed to be stealthy. It tampers with the browser's own internal settings so the malicious extension appears trusted and legitimate, which helps it avoid casual detection. It also tries to detect security-analysis environments and shut itself down to avoid being studied. The updated signatures target the components behind these behaviours.

What we recommend

Even with detection in place, a few practical steps meaningfully lower your risk:

  • Ensure automatic signature updates are enabled so you continue to receive protection against new variants.
  • Only install software and browser extensions from official sources, and be cautious with unexpected files or links referencing banks — especially anything urging urgent action on your account.
  • Periodically review the extensions installed in Chrome and Edge and remove any you do not recognise.
  • If you bank with, or have staff or customers connected to, Brazilian financial institutions, treat this as higher priority.
IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update - GS TROJAN: Admin Menu Editor Pro backdoor webshell access

Severity: HIGH · Priority: P2 — probable compromise, escalate on hit

This rule raises an alert when someone tries to reach the hidden backdoor file left behind by a compromised version of the Admin Menu Editor Pro plugin for WordPress. In September 2026 an attacker tampered with the official plugin update (versions 2.35 and 2.36), and sites that installed it had a concealed access file planted in them. That file lets an outsider run commands on the site. This rule watches for attempts to contact that specific file on web servers.

A hit here is a high-confidence signal, not routine noise. The file this rule looks for has no legitimate reason to exist — its presence and any attempt to reach it point to a genuine compromise. Treat an alert as a probable active intrusion: confirm whether the affected site is running one of the tampered plugin versions, and if so, escalate to incident response and check for the other signs of this backdoor (an unexpected administrator account and leftover attacker files).

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update - GS INFO: iProyal residential proxy DNS lookup

This rule raises an informational alert when a device on our network looks up the residential-proxy service iProyal. That service is named in the joint UK/US/Netherlands government advisory on an Iranian state-linked spying campaign (tracked as HEAVYGRAM / CHOSEN BRICK) as one of the outside services the attackers route their activity through to blend in with normal traffic.

Important context: iProyal is also a legitimate commercial service with entirely lawful uses, so a hit on this rule is not proof of compromise on its own. It's a low-priority lead, not an incident. The advisory itself lists this service in the "otherwise-legitimate" category, and the campaign deliberately changes its other fingerprints, which is why we watch for this softer signal.

How to treat an alert: use it as a prompt to check whether the same device shows any of the stronger warning signs from the same campaign, rather than acting on this alert alone. 

Reference: NCSC advisory on Iranian targeting of dissidents, activists and journalists (15 Sep 2026).