Sappers DFIR
Weekly Threat Watch
August 31, 2026
2
MIN READ
SonicWall Zero-Days, BGP Hijacking, and Mirage Kitten Developer Attacks

A weekly threat watch detailing active SonicWall zero-days, Virtualizor BGP hijacking, Mirage Kitten developer targeting, and China-nexus cyber operations.

Share this post

TABLE OF CONTENT

This week’s intelligence highlights an aggressive pivot by threat actors targeting core routing infrastructure, developer ecosystems, and edge security appliances. Adversaries are hijacking BGP routes to deploy malicious updates, weaponizing technical coding challenges to distribute cross-platform RATs, and heavily leveraging AI to enhance evasive spyware and stealth backdoors.

SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.

1. Edge Appliances, Routing & Core Infrastructure

Threat actors are executing high-impact attacks against underlying network infrastructure, utilizing zero-days and protocol manipulation to bypass standard perimeter security.

  • Virtualizor BGP Hijacking — In a highly sophisticated attack, adversaries are leveraging Border Gateway Protocol (BGP) hijacking to intercept network traffic destined for Virtualizor infrastructure. By manipulating BGP routes, the attackers seamlessly redirect administrative traffic to malicious servers, delivering trojanized software updates directly to virtualization management panels.
  • SonicWall SMA1000 Zero-Days (SNWLID-2026-0016) — Multiple zero-day vulnerabilities in SonicWall SMA1000 series appliances are undergoing active exploitation in the wild. Attackers are leveraging these unpatched flaws to bypass authentication and achieve remote execution, gaining unconstrained access to internal enterprise networks.
  • Cisco Nexus 9000 & IOS XR Critical RCE — Critical remote code execution vulnerabilities have been disclosed affecting Cisco Silicon One-based Nexus 9000 series switches and IOS XR software. These flaws allow attackers to execute arbitrary code at the network core, prompting Cisco to issue a major software hardening release.

2. Supply Chain & Developer Ecosystem Targeting

Advanced persistent threats (APTs) are aggressively targeting software developers and open-source supply chains to achieve stealthy initial access.

  • Mirage Kitten Developer Challenges — The Mirage Kitten threat group is targeting software engineers by distributing trojanized developer challenges and technical interviews. These malicious coding tests silently deploy the cross-platform NodeRabbit and PollCat Remote Access Trojans (RATs), compromising developer workstations across multiple operating systems.
  • npm Supply Chain Compromise (Trinitite Campaign) — A malicious supply-chain campaign successfully compromised the @7nohe/openapi-react-query-codegen package. Utilizing the Mini Shai-Hulud malware variant (part of the Trinitite campaign), the poisoned package executes malicious scripts during the build process, compromising downstream applications and CI/CD pipelines.

3. Advanced Malware, AI-Assisted Spyware, and Stealth C2

Malware authors are increasingly utilizing trusted runtimes and AI assistance to upgrade information stealers and obfuscate command-and-control (C2) channels.

  • Dual-Vector Node.js & AI-Assisted NodeStealer — Threat actors are abusing trusted, signed Node.js runtimes to bypass endpoint execution restrictions. This dual-vector campaign delivers an upgraded, AI-assisted version of Python NodeStealer spyware, which autonomously identifies and extracts high-value authentication tokens and financial data.
  • Emerging Stealth Backdoors (TED, BraZetsu, and Toy Ghouls) — A new wave of evasive backdoors features AI-enhanced access frameworks and novel C2 communication channels. These implants utilize dynamic, machine-learning-driven evasion techniques to bypass network heuristics and establish deeply persistent footholds.
  • REVSTEALER Information Stealer — A rapidly proliferating information stealer has emerged with a highly modular payload architecture, allowing operators to dynamically push new extraction modules targeting modern browser storage, cryptocurrency wallets, and local password managers.

4. Privilege Escalation & State-Sponsored Operations

State-sponsored clusters are utilizing deep OS-level memory corruption and systematic targeting to escalate privileges and maintain access to critical endpoints.

  • China-Nexus Enterprise Targeting — A coordinated escalation in China-nexus cyber operations has been observed, systematically targeting enterprise endpoints and core network infrastructure to establish long-term espionage footholds.
  • Zero-Days in Security Products & Display Drivers — Multiple zero-day memory corruption and privilege escalation vulnerabilities have been discovered affecting enterprise security agents and local display drivers. Attackers are exploiting these deep-system flaws to bypass Protected Process Light (PPL) controls and elevate standard user privileges to SYSTEM.

Proactive Steps for the Week

  • Monitor BGP Routes and Virtualization Infrastructure: Implement BGP route monitoring (e.g., RPKI validation) to detect unauthorized route announcements and hijack attempts targeting Virtualizor or other core management infrastructure. Ensure software updates are verified via cryptographic signatures, not just TLS transport.
  • Secure Developer Workflows: Mandate that all technical assessments, coding challenges, and untrusted repositories be executed exclusively within isolated, ephemeral sandboxes or virtual machines to neutralize the Mirage Kitten (NodeRabbit/PollCat) threat vector.
  • Audit Open-Source Dependencies: Immediately audit projects utilizing @7nohe/openapi-react-query-codegen for signs of the Mini Shai-Hulud variant. Pin dependencies to known-safe hashes and employ Software Composition Analysis (SCA) to detect anomalous build-script behaviors.
  • Patch Edge & Core Routing Hardware: Apply the latest firmware updates and Cisco IOS XR software hardening releases to mitigate the Nexus 9000 RCE flaws. Isolate SonicWall SMA1000 series appliances and apply the emergency hotfixes associated with SNWLID-2026-0016 to halt active zero-day exploitation.
  • Restrict Trusted Runtime Abuse: Implement Application Control (WDAC/AppLocker) to strictly govern the execution of portable or locally dropped node.exe and Python runtimes to prevent the dual-vector deployment of AI-assisted NodeStealer spyware.

Explore our DFIR Solutions to discover how our advanced incident response support, compromise assessments, and threat hunting frameworks can insulate your enterprise infrastructure against these campaigns.

SHARE THIS POST

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.