September 1, 2026 Emerging Threats Weekly

Sep 1, 2026

This week’s briefing covers:

00:00 – Intro

00:47 [THREAT ACTOR] Russian-Linked Clusters Abuse App Passwords, OAuth and Device Linking
Google’s Threat Intelligence Group disclosed three Russia-linked espionage clusters, UNC6293, UNC7005 and UNC5976, using authentication abuse rather than conventional malware-heavy intrusion chains to compromise high-value targets.

04:02 [PHISHING] ZeroTokens Turns Financial Phishing Into a Live Operator Workflow
ZeroTokens is a phishing platform built for financial institution impersonation at scale, but its distinguishing feature is operational control rather than simple cloning. The platform lets a human operator watch each session in real time, see what the target enters, and choose which prompts the victim to see next, making the phishing interaction responsive rather than fixed.

06:57 [THREAT ACTOR] Nimbus Manticore Expands Infrastructure Across Europe and the Middle East
Group-IB reported additional infrastructure and previously undocumented malware linked to KTA109, also known as Nimbus Manticore or Tortoiseshell, an Iranian state-sponsored actor associated with the IRGC.

08:46 [MALWARE] Dindoor Uses the Deno Runtime to Blend Backdoor Execution Into Legitimate Tooling
Binary Defense disclosed Dindoor, a backdoor linked to the Iranian APT group KTA060 (MuddyWater) that uses the legitimate Deno JavaScript and TypeScript runtime as its execution engine. The backdoor was observed at U.S. software companies and banking firms and a Canadian non-profit.

10:52 [MALWARE] Sleepwalker Introduces a Passive Windows Backdoor Triggered by a Single Packet
A newly disclosed Windows backdoor named Sleepwalker remains dormant in system memory until it receives a specific network packet, departing from the more common beaconing model used by many implants.

Dive deeper:

Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report

Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing

Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto

Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist

Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber

Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports

Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber

#krollcyber #threatintelligence #cyberthreats