Weekly review

ThreatNoir Afternoon Brief — July 17

2026-07-17Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — July 17, 2026

The threat landscape continues to shift rapidly as researchers disclose critical vulnerabilities and threat actors actively exploit newly patched systems. Today's security briefing covers emerging zero-day exploits, sophisticated espionage campaigns targeting government entities, and active exploitation of recently disclosed flaws affecting widely deployed enterprise software.

New Windows LegacyHive Zero-Day Grants Admin Privileges

A security researcher operating under the handle "Nightmare Eclipse" has publicly released a Windows zero-day exploit designated LegacyHive that enables attackers to escalate privileges on fully updated Windows systems. The vulnerability represents a significant threat to organizations maintaining current patch levels, as the exploit bypasses standard security protections to grant administrative access to compromised systems. Associated malware families including BlueHammer, GreenPlasma, MiniPlasma, RoguePlanet, and YellowKey have been observed in conjunction with this vulnerability. Source: New Windows LegacyHive zero-day gives hackers admin privileges

ACR Stealer Exploits ClickFix Social Engineering to Harvest Enterprise Data

ACR Stealer, an infostealer malware family active since 2024, continues to extract sensitive data from enterprise networks by leveraging ClickFix social engineering lures that trick users into executing commands via the Windows Run dialog. The malware successfully harvests saved browser passwords, active session tokens, PDF documents, Microsoft 365 files, and data from synced OneDrive and SharePoint folders. Microsoft's Defender Experts team has documented two distinct delivery chains being used to distribute this threat, with associated infrastructure including domains such as claude-desktop.gitlab.io, creativecommunityinfo.art, enhanceblabber.cc, and sphere-api.dialectosphere.in.net. Source: ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

GoSerpent Malware Targets Southeast Asian Government and Diplomatic Entities

Researchers have identified a previously unknown malware family called GoSerpent that has been deployed in targeted attacks against government and diplomatic organizations throughout Southeast Asia since late 2025. Kaspersky discovered the activity in February 2026 and assessed the campaign as focused on establishing persistent access and conducting long-term intelligence gathering operations. The malware toolkit incorporates several secondary tools including McMx RAT, Mimikatz, QuarksDumpLocalHash, Stowaway, ThumbcacheService, and TmcLoader for post-exploitation and credential harvesting activities. Source: New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

Critical SharePoint Vulnerability Actively Exploited Following Public Disclosure

A critical-severity vulnerability in SharePoint that permits remote authenticated attackers to execute arbitrary code on affected servers has been exploited in the wild shortly after disclosure and patching. The rapid weaponization of this flaw demonstrates the narrow window organizations have to deploy security updates before threat actors begin active exploitation campaigns. Multiple related CVE identifiers including CVE-2026-25089, CVE-2026-39808, CVE-2026-55040, CVE-2026-56164, and CVE-2026-58644 have been associated with SharePoint security defects. Source: Fresh SharePoint Vulnerability Exploited Soon After Disclosure

The convergence of disclosed vulnerabilities, active exploitation, and sophisticated targeted campaigns underscores the critical importance of maintaining rapid patching cycles and implementing defense-in-depth strategies across enterprise infrastructure. Organizations should prioritize immediate assessment and remediation of exposed systems while monitoring for indicators of compromise associated with the malware families and infrastructure detailed in today's threat intelligence.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

New Windows LegacyHive zero-day gives hackers admin privileges
Malware6
  • LegacyHive
    Windows privilege escalation exploit targeting User Profile Service
  • GreenPlasma
    Windows vulnerability patched June 2026
  • YellowKey
    Windows vulnerability patched June 2026
  • MiniPlasma
    Windows vulnerability patched June 2026
  • BlueHammer
    Windows zero-day exploit previously disclosed by Nightmare Eclipse
  • RoguePlanet
    Windows Defender zero-day vulnerability patched July 2026
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
Malware1
  • ACR Stealer
    Infostealer malware stealing browser credentials, tokens, and Microsoft 365 documents
Domain4
  • creativecommunityinfo.art
    ACR Stealer payload host and C2 server (Campaign 2)
  • enhanceblabber.cc
    ACR Stealer payload host and C2 server (Campaign 2)
  • sphere-api.dialectosphere.in.net
    WebDAV share host for DLL payload delivery
  • claude-desktop.gitlab.io
    Fake Claude Code page hosting ACR Stealer via GitLab
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Malware7
  • GoSerpent
    Primary Go-based backdoor and RAT targeting Southeast Asian government entities since late 2025
  • QuarksDumpLocalHash
    Tool for extracting local account password hashes from SAM registry
  • Mimikatz
    Credential dumping tool for extracting LSASS memory
  • TmcLoader
    C++ loader module containing encrypted TmcPayload for data exfiltration
  • McMx RAT
    Lightweight Go-based proxy tool with SOCKS5 and file transfer capabilities
  • ThumbcacheService
    DLL for sophisticated file collection and sensitive data staging
  • Stowaway
    Evolved proxy and remote access tool deployed May 2026 with SOCKS5 proxying and SSH tunneling