GajShield Threat Intelligence

Live protection updates from GajShield's indigenous security research and threat intelligence team.

This page documents new and updated detections developed for GajShield security engines, including IPS, Anti-Malware, malicious infrastructure and emerging threat intelligence.

IPS Signature Oct 06, 2026

GajIPS - IPS Signature Update — GS PHISHING: Fake AI Ads Browser-in-the-Browser campaign

Severity: HIGH · Priority: P2 — live-operator MFA relay targeting advertising accounts, investigate on hit

These rules provide comprehensive detection for a sophisticated phishing-as-a-service campaign documented by Island.io on October 6, 2026, in which attackers place sponsored Google Ads for fake versions of prominent AI tools — ChatGPT, Gemini, Claude, Anthropic, Perplexity, Manus, and a newly minted fake "Muse Ads" created eight days after Meta launched Muse — and use them to steal advertising account credentials and multi-factor authentication codes from digital marketing professionals.

The attack is technically distinctive because it uses a Browser-in-the-Browser technique rather than a redirect to a lookalike site. When a victim clicks the "Connect" button on what appears to be a legitimate AI advertising tool, a fake Google sign-in window appears embedded inside the original page, complete with a spoofed accounts.google.com address bar. The window is an iframe styled to look like a pop-up, not a real browser window. A human operator monitors victim sessions in real time and sends commands to the victim's browser through a persistent Socket.IO channel — selecting which authentication challenge to show next: a password prompt (up to three times), an SMS code entry, a Google authenticator prompt, a QR code verification, an Okta push notification, or an Okta authenticator app request. The attack intercepts the credentials and MFA codes as they are entered and uses them in real time to authenticate to the real platform before the session expires. Google advertising accounts, Meta Business Manager, TikTok Ads Manager, and Okta-gated enterprise SSO are all targeted by this kit.

A hit on any behavioral rule or a lure-domain rule indicates a user on your network is actively engaged with the phishing kit and may already be in the MFA relay step. Act immediately: a human operator on the attacker's side is watching and directing the session in real time, and the window between credential entry and account takeover can be seconds. Identify the affected user, immediately revoke all active sessions for any accounts they may have entered credentials for — prioritise Google Ads, Meta Business Manager, TikTok Ads, and Okta — and audit all active OAuth authorisations and recent ad campaign changes. Because the kit specifically targets advertising accounts, also audit for fraudulent ad spend, modified payment methods, and newly created ad campaigns from the compromised accounts.

IPS Signature Oct 06, 2026

GajIPS - IPS Signature Update — GS TROJAN: Action1 RMM abuse via fake PDF invoice phishing campaign

Severity: HIGH · Priority: P2 — RMM tool abuse via fake-invoice phishing, investigate on hit

These rules cover a complete kill chain, in which threat actors distribute phishing emails carrying a fake PDF invoice. When the PDF is opened, an embedded OpenActiontag automatically redirects the victim's browser to download a VBScript hosted on a Vercel deployment (up-theta-rose.vercel.app/adobe_new_update.vbs). The VBScript displays a decoy PDF to keep the victim calm, then downloads and silently installs the Action1 Remote Management and Monitoring agent as a Windows service named A1Agent. The agent is a legitimately signed, real Action1 binary, but registered to a customer account (49b18106-681d-456a-b098-092e2818c09a) controlled by the attacker rather than the victim's organisation. This gives the attacker full, persistent remote access through Action1's own legitimate cloud infrastructure — a technique that bypasses most network-based detection because all traffic goes to genuine Action1 servers over HTTPS.

A second wave in the same campaign uses a ZIP file containing an HTA to deliver the agent from a second Vercel host (update-two-tau.vercel.app). The broader CSuite phishing operation documented by Xcitium places this Action1 abuse in a wider context: the same operation also delivers ScreenConnect, Atera, and Syncro agents renamed to Adobe or DocuSign packages, and sometimes steals Microsoft 365 session cookies alongside installing the RMM.

A hit on the Customer ID rule or the non-Action1-host MSI rule is a confirmed RMM abuse event. Identify the affected device, check for the service A1Agent (action1_agent.exe) and the registry key HKLM\Software\Action1\Agent, and remove both. Any credentials or data the attacker could access through the remote session should be treated as exposed. Because legitimate Action1 connections cannot be distinguished from attacker-controlled ones by destination alone, only a Customer ID check (the registry key above) or an authorised-deployment inventory confirms or clears a device. A hit on the PDF OpenAction rules indicates a phishing email is being delivered and a user may have clicked. Report the sending address to Action1 (abuse@action1.com) so the attacker's free tenant can be revoked.

IPS Signature Oct 06, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Atlassian Data Center path traversal, CVE-2026-21589 — four-variant detection set

Severity: HIGH · Priority: P2 — critical unauthenticated file read across eight Atlassian Data Center products, patch immediately

These four rules collectively detect exploitation attempts against CVE-2026-21589, a critical unauthenticated path traversal and arbitrary file read vulnerability disclosed by Atlassian on October 5, 2026, affecting eight self-hosted Data Center products: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye. The flaw carries a CVSS v4.0 score of 9.3. An unauthenticated attacker can read any file within the web application's root directory by crafting a request with a path traversal sequence — without needing credentials or an account. The constraint is that the attacker must know the exact filename and path of the target; the flaw does not allow directory enumeration. Sensitive files that can be reached this way include configuration files, authentication tokens stored in the web root, and application credentials depending on the deployment. Atlassian's own advisory recommends deploying WAF rules targeting double-dot traversal patterns adjacent to forward slashes, backslashes, or double colons — this rule set directly implements that guidance.

A hit indicates an active path traversal attempt against a self-hosted Atlassian Data Center instance. Confirm whether the targeted product and version are among the affected releases and apply the fixed builds immediately. For Jira Software and Jira Service Management, fix versions are 9.12.40, 10.3.26, and 11.3.12; for Confluence, 9.2.26 and 10.2.19; check the advisory for Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. As an interim measure while patching, Atlassian provides product-specific rewrite.config and Tomcat RewriteValve configurations that block the traversal patterns at the application layer. Review access logs for matching traversal patterns — a successful exploitation attempt leaves a log entry with the traversal sequence, though the response body content may not be logged by default. No confirmed exploitation in the wild has been reported as of October 5–6, 2026, though no-exploit-yet status is expected to change rapidly given public disclosure.

IPS Signature Oct 06, 2026

GajIPS - IPS Signature Update — GS TROJAN: ClickFix browser cache-smuggling campaign — pre-cached VBScript delivery and multi-stage credential-theft chain

Severity: HIGH · Priority: P2 — novel ClickFix cache-smuggling variant, investigate on hit

These rules detect a technically novel variant of ClickFix attacks, documented by Microsoft Threat Intelligence on October 3, 2026, in which the malicious payload is hidden inside the victim's browser cache before the attacker asks them to do anything. The technique — called browser cache smuggling — was originally described by Expel's Marcus Hutchins in October 2025, but this campaign introduces a new twist: the cached payload is retrieved not by a content marker or filename, but purely by file size, allowing a shorter, harder-to-detect clipboard command to fit inside the Windows Run dialog's character limit.

The attack chain works as follows. When a user visits a compromised website, the page silently forces their browser to cache a large VBScript file disguised as a PNG image — the server sends a Content-Type: image/png header, but the file body is not a PNG and contains Windows scripting commands. The ClickFix fake-CAPTCHA prompt then instructs the user to paste a short command that invokes cmd.exe to search Firefox's profile cache directory for files beginning with "f_" and matching a specific file size set by the attacker. When found, the cached entry is copied to %LOCALAPPDATA%\Temp\t.vbsand executed through wscript.exe. The VBScript gathers host information via WMI, retrieves a PowerShell script (v.ps1) from cocojambo.us.com/alfa, and launches PowerShell with execution-policy bypass and no user profile. This PowerShell stage compiles .NET code on the victim's machine using csc.exe and cvtres.exe, then injects into timeout.exe to harvest browser credentials and device data. A further memory-resident stage is fetched from capsysnet.vg, and the injected process maintains persistent contact with ciliabula.cc via a Python payload launched through a scheduled task.

A hit on the response-detection rules indicates a device is actively receiving a cache-smuggled VBScript payload — the attack is in progress but no command has been executed yet; blocking at this point prevents the infection. A hit on the domain rules or the lure-page rule indicates the infection chain is already running or the user is on the lure page. In either case, identify the device and check for t.vbs in %LOCALAPPDATA%\Temp, unexpected scheduled tasks running Python, timeout.exe behaving unexpectedly, and the v.ps1 script in memory or recent PowerShell history. Because the final stage specifically targets browser-stored credentials, treat all saved passwords in Chrome, Edge, Firefox, and Brave as potentially exposed and rotate them from a known-clean device.

IPS Signature Oct 06, 2026

GajIPS - IPS Signature Update — GS TROJAN: ClingSTUN IoT backdoor — STUN C2 heartbeat, CVE-2021-35394 exploit, payload delivery, and infection-tag detection

Severity: HIGH · Priority: P2 — IoT botnet infection spreading via unpatched Realtek SDK devices, investigate on hit

These rules provide comprehensive detection for ClingSTUN (also tracked as Cling), a Linux back-connect proxy backdoor. ClingSTUN turns compromised IoT devices — routers, DVRs, IP cameras, access points, and UPnP-enabled appliances — into remotely controlled proxy nodes, and spreads by exploiting unpatched vulnerabilities in internet-facing devices including the Realtek Jungle SDK flaw CVE-2021-35394 (CVSS 9.8), a critical command injection bug that remains unpatched in tens of thousands of devices years after disclosure.

ClingSTUN's defining technical feature is using the STUN protocol — a standard mechanism for voice-over-IP and WebRTC applications to discover their external IP addresses through NAT — as a covert C2 channel. Rather than contacting a dedicated malware command server, ClingSTUN sends 20-byte STUN Binding Requests to 13 public STUN servers (including Google's) roughly every five seconds. These look like ordinary VoIP infrastructure traffic from the outside. The single detection anomaly: ClingSTUN uses all-zero Transaction IDs instead of the random values RFC 5389 requires. One server in that list (145.249.115.184:3478) is operator-controlled — devices advertise their externally mapped ports to it and later receive C2 commands in return. The STUN response rules detect when a ClingSTUN-infected device receives a response with the matching all-zero Transaction ID from this C2 path.

A hit on the inbound CVE-2021-35394 rule indicates an internet-facing Realtek SDK device is being actively attacked. A hit on the outbound CVE-2021-35394 rule indicates a device inside your network is already infected and propagating. A hit on the STUN heartbeat or C2 IP rules indicates an infected device on your network is checking in with the botnet operator. In all cases: identify and isolate the affected device; patch or replace it (the Realtek SDK CVE-2021-35394 fix is available for updated firmware, but many affected devices have no vendor-provided update path, making replacement the safest option); and search for ClingSTUN persistence artifacts on the device filesystem: .cling, wget.r, wget.p, and entries in /etc/init.d/, /etc/rc.local, and similar init scripts.

IPS Signature Oct 05, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Rejetto HFS admin session forgery to RCE via server_code, CVE-2026-61500

Severity: CRITICAL · Priority: P1 — actively exploited unauthenticated RCE in a public file server, escalate on hit

This rule detects the code-execution step of CVE-2026-61500, a critical vulnerability in Rejetto HTTP File Server (HFS) versions 3.0.0 through 3.2.0, actively exploited since October 3, 2026 — one day after a public exploit walkthrough was published by Horizon3.ai. The vulnerability is caused by HFS generating its session-cookie signing key using JavaScript's Math.random(), a non-cryptographic generator whose outputs are also leaked to unauthenticated clients during the login handshake. An attacker collects a handful of login responses, reconstructs the V8 engine's PRNG internal state, recovers the exact signing key, and forges a session cookie that HFS accepts as a valid administrator session. With forged admin access, the attacker calls the set_config API to insert arbitrary JavaScript into the server_code configuration field, which HFS executes immediately and with the privileges of the server process, achieving full remote code execution.

A hit indicates that an attacker has already successfully forged an administrator session and is actively installing a code-execution payload. Isolate the server immediately — by the time this rule fires, the payload has likely already executed. Check the HFS server_code configuration for any JavaScript you did not add, particularly anything involving require('child_process') or external network calls. Treat the server as fully compromised: any files it hosted, credentials stored on it, or other services reachable from it should be considered exposed. Upgrade to HFS 3.2.1 as the definitive fix.

IPS Signature Oct 05, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Citrix NetScaler CVE-2026-88779 SAML authentication heuristic detection

Severity: HIGH · Priority: P2 — exploited NetScaler SAML zero-day, CISA KEV; RCE variant suspected but unconfirmed

These rules address CVE-2026-88779, a zero-day in Citrix NetScaler ADC and Gateway affecting appliances configured as SAML service providers or identity providers. Citrix published the bulletin CTX697174 on October 3, 2026 and CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on October 4 with a federal remediation deadline of October 7. The officially documented exploitation causes a memory buffer overflow that crashes or reboots the appliance — denial of service. Administrators who applied September NetScaler patches for CVE-2026-88771 and CVE-2026-88772 must apply another upgrade to fix this separate flaw.

A hit on either rule warrants immediate escalation. For the body-inspection rule: a SAML authentication POST body containing shell metacharacters and download or execution commands has no legitimate explanation and is strong evidence of active exploitation, whether for denial of service or the suspected command-execution variant. For the C2 IP rule: outbound connections from a NetScaler appliance to a single-source-reported attacker address should prompt investigation even given the limited provenance. In both cases, apply the fix builds immediately — 14.1-73.41 or 13.1-64.28 — and check for signs of compromise using the IOC sweep methodology described alongside Citrix's September advisory. If no crash has occurred but these rules fire, the appliance may be under probing for the RCE path rather than the DoS path.

IPS Signature Oct 04, 2026

GajIPS - IPS Signature Update — GS TROJAN: TA419 credential-phishing campaign targeting US AI policy experts — redirect and AitM domain detection

Severity: HIGH · Priority: P2 — China-nexus espionage targeting AI policy professionals, investigate on hit

These rules detect connections to infrastructure used by TA419, a China-aligned espionage group, in a sustained credential-phishing campaign against artificial intelligence policy experts at US think tanks, universities, and law firms. The campaign is assessed with high confidence to support Chinese intelligence objectives around understanding US AI policy, export controls, and national AI strategy — a strategic collection priority in the context of intense US-China competition over AI development and governance.

TA419's technique is unusually patient and convincing. Rather than opening with a malicious link, the actor sends an initial benign email that appears to come from a respected AI policy figure — in the July 2026 wave, the impersonated identities included a former director of the White House Office of Science and Technology Policy and a prominent foreign-policy economist; in February 2026, a named Anthropic employee. The initial message invites the target to join a fictitious AI Policy Advisory Committee, contribute to a Senate AI export-control report, or give input on AI supply chains — topics a genuine AI policy expert would reasonably discuss. Only after the target replies does TA419 send a follow-up with a shortened URL that triggers the multi-stage redirect chain. This reply-triggered design ensures the group invests only against confirmed interested targets, and the initial rapport-building makes the victim less suspicious of the follow-on link.

The infection chain separates across two domain tiers. The first-stage domains display a convincing fake OneDrive file-loading screen and run a Cloudflare Turnstile human-verification check before silently forwarding the victim's browser to the second-stage phishing domain. The second-stage domains present a fake OneDrive folder containing lure documents and host the adversary-in-the-middle (AitM) phishing kit — a combination of standard credential capture and a Browser-in-the-Browser component — to harvest both Microsoft 365 credentials and live session cookies, allowing the attacker to access the victim's Microsoft cloud account without needing to know the password or bypass multi-factor authentication separately.

A hit on any of these rules indicates a device on your network has contacted TA419 infrastructure. Given the highly targeted nature of this campaign, a hit strongly suggests the affected user is a research, policy, or legal professional working on AI-related topics, and should be investigated accordingly. If the connection reached a second-stage domain, treat Microsoft 365 credentials and active sessions as compromised: immediately revoke all active Microsoft sessions and reset passwords for the affected account from a known-clean device, paying particular attention to Microsoft Teams, SharePoint, and OneDrive contents which may have been accessed by the attacker after credential capture. Also audit Microsoft Entra ID sign-in logs and OAuth application grants for unexpected access. Review the user's recent email for the benign-looking first contact from an apparent AI policy figure — that conversation thread is evidence the user has been under active targeting.

Antivirus Oct 03, 2026

GajAV - Malware Signature — GajAV: Warlock ransomware toolchain

These signatures detect components of the Warlock ransomware operation, also tracked as Water Manaul and Storm-2603, a China-nexus ransomware group documented by Cisco Talos and Trend Micro throughout 2026. Warlock has been consistently exploiting unpatched Microsoft SharePoint servers for initial access, entering victim networks through the IIS worker process and establishing a persistent foothold before deploying ransomware — in one documented January 2026 case, operators spent 15 days inside a network before encrypting it. The operation targets technology, manufacturing, and government sectors, with the United States, Germany, Russia, and the UK among the most affected countries.

The signatures cover the full Warlock toolchain across five component categories. The ransomware encryptors (Win.Ransom.Warlock) are the final-stage payloads deployed for data encryption. The DLL components (Win.Trojan.Warlock.Dll) implement the DLL sideloading chain Warlock uses to execute its payloads through legitimate-looking processes, pulling staged files from open hosting services such as catbox.moe and wasabisys.com. The bootstrap loader (Win.Trojan.Warlock.Bootstrap) is the initial stager that unpacks and stages the rest of the toolchain. The PowerShell component (Ps1.Trojan.Warlock) handles scripted setup, persistence, and execution orchestration. The BYOVD driver (Win.Malware.Warlock.VulnDriver-BYOVD) is the most dangerous single component: it is a signed but vulnerable kernel driver that Warlock loads to terminate security product processes at the kernel level before deploying the ransomware, effectively blinding endpoint protection across the machine. The suspicious components (Win.Trojan.Warlock.Suspicious) are unclassified artifacts consistent with the Warlock toolchain whose exact roles are not fully characterised.

If GajAV flags the BYOVD driver component specifically, act with urgency: its presence means security tooling on that host has likely already been disabled and the ransomware payload may be imminent or already running. For any other Warlock component hit, treat the affected machine as in an active pre-ransomware intrusion: isolate it immediately, do not attempt to clean it in place, and escalate to incident response. Check for web shells in the SharePoint LAYOUTS folder (particularly aspx files such as layout2sp.aspx), unexpected PowerShell commands from w3wp.exe, Visual Studio Code installed as a service with tunnel mode enabled, and Cloudflare Tunnel clients in webserver or task directories. Treat Active Directory as compromised if any domain controller shows Warlock artifacts, as the group deploys its payload through SYSVOL and NETLOGON to reach machines it cannot reach directly. Because Warlock conducts double extortion, also assume data was exfiltrated via Rclone or similar tools before encryption, and notify affected parties accordingly.

IPS Signature Oct 03, 2026

GajIPS - IPS Signature Update — GS TROJAN: UAT-11587 ANTINO JavaScript downloader CloudFront staging host

Severity: HIGH · Priority: P2 — UAT-11587 ANTINO staging infrastructure, investigate on hit

This rule detects a TLS connection to d32tpl7xt7175h.cloudfront.net, a CloudFront content delivery distribution used as staging infrastructure by UAT-11587 in its ANTINO backdoor campaign. This rule extends the existing ANTINO detection coverage for this session's earlier rules and covers the JavaScript downloader stage of the five-stage infection chain, where JScript orchestrators and serialized .NET gadget resources are retrieved from attacker-controlled CloudFront distributions.

The domain was identified in a JavaScript downloader associated with UAT-11587. It was also previously flagged by Arctic Wolf in connection with UNC6384, a separate China-nexus threat actor observed targeting European diplomatic and government entities. The two may share tool infrastructure without being the same group. The rule message labels it "UNC6384-linked" to document this overlap without asserting identity between the actors.

A hit indicates a device on your network connected to UAT-11587 delivery infrastructure during the early stages of the ANTINO infection chain. Treat it the same way as the other ANTINO indicators — check for execution of mshta.exe or wscript.exe, look for GatherOsState.exe sideloading slc.dll, and review Microsoft Entra ID sign-in logs for unexpected OAuth app registrations consistent with ANTINO's OneDrive C2 channel.