GajShield Threat Intelligence

Live protection updates from GajShield's indigenous security research and threat intelligence team.

This page documents new and updated detections developed for GajShield security engines, including IPS, Anti-Malware, malicious infrastructure and emerging threat intelligence.

IPS Signature Sep 17, 2026

GajIPS - IPS Signature Update — GS TROJAN: Shai-Hulud npm supply-chain worm data exfiltration

Severity: HIGH · Priority: P2 — probable developer-system compromise, investigate on hit

This rule raises an alert when a device on your network sends data to the specific web address used by the Shai-Hulud worm to steal secrets. Shai-Hulud is a self-spreading worm that infected hundreds of packages in the npm software ecosystem (the library repository used by JavaScript/Node.js developers) beginning September 2025. When a developer installs a compromised package, the malware harvests credentials — npm and GitHub tokens, and cloud secrets from AWS and Google — and sends them to a hardcoded collection point. It then uses the stolen GitHub access to spread itself further and to make the victim's private code repositories public. This rule watches for the outbound connection to that exact collection address.

A hit strongly suggests a developer machine on your network is infected and is leaking credentials. The address this rule matches has no legitimate use — it is the worm's specific, hardcoded drop point — so a match is a high-confidence indicator, not routine noise. Treat it as a probable compromise of the originating machine and the developer's accounts: identify the device and user, and treat all their credentials as exposed — rotate npm and GitHub tokens, and any cloud (AWS/Google) secrets that machine could reach, from a known-clean system. Then hunt for the worm's other fingerprints: a malicious workflow file named shai-hulud-workflow.yml in code repositories, unexpected public repositories or a repository named "Shai-Hulud" under affected accounts, and the compromised package versions in project dependencies.

Antivirus Sep 16, 2026

GajAV - Malware Signature Update — GhostContainer / NightEagle (APT-Q-95) Exchange malware

This update adds file-fingerprint detections for malware used in targeted attacks against Microsoft Exchange servers, associated with the NightEagle (APT-Q-95) activity cluster. Two related sets are covered: the GhostContainer Exchange backdoor and its disguised tunneling component, which give an attacker full control of a compromised mail server and can relay traffic deeper into the network; and additional NightEagle-associated loader components.

If GajAV flags any of these files, treat it as a probable server compromise: isolate the server, preserve it for forensic investigation, escalate to incident response, and confirm the server is fully patched — these intrusions typically begin by exploiting a known ("N-day") Exchange vulnerability.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — GS TROJAN: GhostContainer Microsoft Exchange backdoor command-and-control

Severity: HIGH · Priority: P2 — probable Exchange compromise, investigate on hit

This rule looks for signs of GhostContainer, a stealthy backdoor on compromised Microsoft Exchange mail servers at high-value organisations. Unlike typical malware, GhostContainer does not call out to an attacker's server; instead it sits quietly on the Exchange server and waits for the attacker to send it hidden commands inside what look like ordinary Exchange webmail requests. The commands are concealed in a specific request header (x-owa-urlpostdata), scrambled so they are not visible in plain traffic. This rule watches for that header being used to smuggle commands in.

A hit may indicate an attacker is operating a backdoor on one of our Exchange servers — a serious situation, since GhostContainer gives full control of the mail server and can be used to steal data, relay traffic deeper into the network, and hide from security tools by disabling built-in Windows protections. Treat a confirmed hit as a probable server compromise: identify the Exchange server involved, look for an unexpected server component or DLL disguised as a legitimate Exchange file, review the server for signs of tampering with security logging, and escalate to incident response. Because this backdoor typically follows exploitation of a known Exchange vulnerability, confirm the server is fully patched.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Issabel PBX unauthenticated remote code execution, CVE-2026-89026

Severity: CRITICAL · Priority: P1 — active exploitation, escalate on hit

This rule raises an alert when an attacker attempts to exploit a critical flaw in Issabel, an open-source phone-system (PBX) platform built on Asterisk and widely used for business telephony. The affected software shipped with a secret signing key built into its code that was identical on every installation. Because that key was public knowledge once discovered, an attacker needs no username, password, or prior access — they can forge a valid-looking access token and send a single request to the phone system's management interface that instructs it to run operating-system commands on the server. This rule watches for that command-execution request.

A hit here is a top-urgency signal. The flaw is rated critical (9.3), and security researchers confirmed real-world exploitation beginning 9 September 2026, with internet-exposed Issabel systems being actively targeted. A successful attack runs commands on the phone server and can lead to malware installation, theft of call records and configuration, tampering with call routing, toll fraud, and a foothold to move deeper into the network. Treat an alert as an active, serious intrusion attempt against the phone system.

On a hit: identify whether the targeted host is an Issabel PBX and whether its Framework component has been updated to a fixed build (the corrected version released after the flaw was patched); anything earlier is vulnerable. If it is unpatched and internet-exposed, assume potential compromise and escalate to incident response immediately — review web-server, Issabel, and Asterisk logs for unusual access-token activity and unexpected "originate" requests, look for unfamiliar processes or outbound connections from the server, and check for tampering with dial plans or new persistence. Because the underlying weakness is a shared secret key, updating to the fixed version is the definitive fix; systems should not be considered safe until patched.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — Rule note — GS TROJAN: N0va phishing kit device-code credential phishing endpoint

Severity: HIGH · Priority: P2 — probable phishing interaction, investigate on hit

This rule raises an alert when a user on your network visits a phishing page belonging to the N0va phishing kit, a credential-theft toolkit disclosed by researchers at ANY.RUN in September 2026 that targets organisations across North America and Europe, including government, technology, consulting, and healthcare. N0va abuses a legitimate Microsoft sign-in feature ("device code" authentication): it shows the user a page imitating a trusted service — Microsoft Teams, SharePoint, OneDrive, DocuSign and others — and guides them to complete a genuine Microsoft login that, unknown to them, authorises the attacker's session. Because the victim signs in on Microsoft's real website and can even complete multi-factor authentication, the attacker ends up with valid, lasting access to the account — access and refresh tokens, and single-sign-on into corporate resources — even though no password was ever handed over. This rule watches for the specific web-address pattern of the N0va phishing kit's sign-in page.

A hit means a user likely reached an N0va phishing page. Treat it as a probable phishing interaction: identify the user and device, and check whether they went on to complete a Microsoft sign-in prompt they did not themselves initiate. If so, treat the account as potentially compromised — review it for unexpected sign-ins, newly registered devices, and mailbox or sharing-rule changes, revoke active sessions and tokens, and confirm no unauthorised app or device registrations remain. Because this attack grants ongoing token-based access rather than just a password, resetting the password alone is not sufficient; existing sessions and tokens must be revoked.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: JWT alg:none authentication bypass attempt

Severity: MEDIUM · Priority: P3 — technique tripwire, tune before relying on

This rule raises an alert when a web request carries a JSON Web Token (JWT) whose header declares that it has no signature. JWTs are digital tokens many applications use to prove a user is logged in; a properly issued one is cryptographically signed so it can't be forged. A token marked with the "none" algorithm claims to need no signature — a long-known trick where an attacker strips the signature and edits the token's contents (for example, changing their role to administrator) in the hope that a poorly configured server accepts it as genuine. This rule watches for that tell-tale "none" marker in incoming tokens, covering several ways it can be spelled.

A hit means something sent a token that asks to skip signature checking. On most systems that is abnormal and worth investigating, but it is not by itself proof of a successful break-in — it flags an attempt or a misconfiguration, and whether it works depends entirely on how the receiving application validates tokens. A correctly configured, patched application rejects these tokens outright. Treat an alert as a prompt to check which application received the token and whether it is hardened against this technique.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Citrix NetScaler SAML authentication bypass, CVE-2026-19490

Severity: CRITICAL · Priority: P1 — active exploitation, escalate on hit

This rule raises an alert when an attacker attempts to exploit a critical authentication-bypass flaw in Citrix NetScaler ADC and NetScaler Gateway appliances — the devices many organisations use as their remote-access (VPN) and single-sign-on front door. The flaw lets an unauthenticated attacker forge a valid login session in a single request to the appliance's SAML sign-on path, without any credentials or user interaction. On a vulnerable, exposed Gateway that can mean anonymous access to internal applications, and it is being chained with a companion flaw to reach full remote code execution. This rule watches for the crafted sign-on request used in that attack.

A hit here is a high-urgency signal. The flaw is rated critical (9.3), is confirmed under active exploitation, and targets the security appliance that guards remote access — so a success can expose the internal network behind it. Treat an alert as an active attack against the NetScaler appliance.

On a hit: identify whether the targeted device is a Citrix NetScaler configured for SAML authentication (an AAA or Gateway virtual server with a SAML action), and whether it is on a fixed software build — note that early hotfixes for the related flaw are not sufficient for this one, so verify against the latest recommended build for the branch. Impact depends on configuration; Gateway virtual servers are the higher-risk case. If the appliance is unpatched, assume potential compromise and escalate to incident response: review appliance access logs for repeated unauthenticated requests to the SAML and related sign-on paths from external addresses, hunt for unexpected script files created outside update windows on the appliance, and rotate credentials and session material. Upgrading to the fixed build is the definitive fix.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update — GS EXPLOIT: Cisco Secure Email Gateway crafted-email SQL-injection root RCE, CVE-2026-76461

Severity: CRITICAL · Priority: P1 — active exploitation, escalate on hit

This rule raises an alert when an inbound email arriving at one of our mail gateways contains the signature of an attack against a critical flaw in Cisco Secure Email Gateway appliances. The flaw is in the part of the appliance that reads and parses incoming email: a specially crafted message can smuggle database commands into the appliance, which then runs them — ultimately allowing an unauthenticated attacker to take full, highest-level (root) control of the device just by sending it an email. No password, no login, and no action by any recipient is needed. This rule looks for the specific command pattern used to turn that database access into command execution on the appliance.

A hit here is a high-urgency signal. The flaw is rated among the most severe possible (9.8 out of 10), Cisco has confirmed it is being exploited in the wild, and government authorities have placed it on their catalogue of known-exploited vulnerabilities with an emergency patch deadline. Because the target is the email gateway itself — the device that sees all inbound mail — a compromise is especially serious: it can expose mail in transit, appliance credentials, and provide a foothold into connected systems. Treat an alert as an active attack against the mail appliance.

On a hit: identify whether the receiving appliance is a Cisco Secure Email Gateway and whether it is running a fixed software release; both physical and virtual appliances are affected in any configuration. If it is unpatched, assume potential compromise and escalate to incident response immediately. Note Cisco's own guidance that an attacker with root can erase or hide evidence on the device, so on-device logs alone should not be trusted to rule out compromise — corroborate with network and firewall logs, and where compromise is suspected, rebuild affected virtual appliances from a clean fixed release and rotate all credentials and cryptographic material on the device. Applying Cisco's update is the definitive fix.

IPS Signature Sep 16, 2026

GajIPS - IPS Signature Update: WooCommerce Wholesale Lead Capture unauthenticated file-upload RCE, CVE-2026-27540

Severity: CRITICAL · Priority: P1 — active exploitation, block/escalate on hit

This rule raises an alert when an attacker attempts to exploit a critical flaw in the WooCommerce Wholesale Lead Capture plugin for WordPress to upload a malicious file to one of the web servers. The plugin has a file-upload feature that, in vulnerable versions, can be tricked into accepting executable PHP files from anyone on the internet — no login or user interaction required. A successful attempt lets the attacker plant a hidden control file (a webshell) and run commands on the site, which can lead to full compromise. This rule watches for the specific upload request used in that attack.

A hit here is a high-confidence, high-urgency signal. This is not background noise — the request pattern has no legitimate use, the flaw is rated among the most severe (9.8 out of 10), and it is being exploited in the wild right now. Treat an alert as an active exploitation attempt against the targeted server.

On a hit: confirm whether the affected site runs the WooCommerce Wholesale Lead Capture plugin and whether it has been updated to the fixed version (2.0.3.2 or later); versions 2.0.3.1 and earlier are vulnerable. If the site is unpatched, assume the attempt may have succeeded, escalate to incident response, and check for newly uploaded files in the site's upload folders and any unexpected administrator accounts (a related flaw in the same plugin allows attackers to create admin users). The lasting fix is to update the plugin.

Antivirus Sep 16, 2026

GajAV - Malware Signature Update — HEAVYGRAM / CHOSEN BRICK (Iranian state-linked Telegram spyware)

What this update does

We have updated your product's malware signatures to add detection for HEAVYGRAM, a spyware toolkit also tracked as CHOSEN BRICK. This note is to inform you that the signatures are now available. We recommend confirming your product is set to receive signature updates so this detection is applied.

What the threat is

HEAVYGRAM is spying malware attributed by a joint UK, US, and Netherlands government advisory to Iran's Ministry of Intelligence and Security (MOIS). Rather than targeting organisations broadly, this campaign has focused on specific individuals — Iranian dissidents, journalists, activists, and opposition figures — in the UK, US, Netherlands, and elsewhere, and has been active over a period of years.

The malware reaches victims through social engineering, typically a message or file the target is persuaded to open. Once installed, it gives the attackers remote access to the device to monitor activity and steal data, and it has been used to support "hack-and-leak" operations intended to damage the reputations of those targeted.

Why it's notable

A distinctive feature of this malware is that it is operated through the Telegram messaging platform, which the attackers use to control infected devices and retrieve stolen information. It also routes some of its activity through ordinary, legitimate online services to blend in with normal traffic and avoid standing out. Official reporting notes that the malware's file names and folder locations change over time, so no single indicator should be relied on alone — the updated signatures target the underlying behaviours rather than surface details.

What we recommend

  • Ensure signature updates are enabled so the new and future detections are applied.
  • Treat unexpected files or links shared through messaging apps with caution, and obtain software only from official sources.
  • Keep operating systems and applications current, ideally through automatic updates.
  • Do not dismiss download or security warnings from the browser or operating system.
  • For higher-risk individuals, phishing-resistant multi-factor authentication and managed-device controls such as application allow-listing add meaningful protection.