Weekly review

ThreatNoir Weekend Brief — August 16

2026-08-16Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — August 16, 2026

The threat landscape continues to accelerate as attackers move swiftly to exploit newly disclosed vulnerabilities and deploy sophisticated malware variants. Today's security briefing covers active exploitation campaigns, advanced persistent threat activity, and infrastructure-level compromises that demand immediate attention from security teams worldwide.

New Evooo1Bot Linux Botnet Turns Routers into Traffic Relay Nodes

A newly identified Mirai-based modular Linux botnet named Evooo1Bot has emerged as a significant threat to internet-facing gateway devices. The malware targets routers and similar network infrastructure, converting them into SOCKS5 traffic relay nodes that can be leveraged for obfuscating malicious traffic and conducting distributed attacks. This modular approach allows attackers to customize the botnet's functionality across compromised devices, expanding its operational flexibility. Source: New Evooo1Bot Linux botnet turns routers into traffic relay nodes

Max Severity SAP Commerce Cloud Flaw Now Targeted in Attacks

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud is already under active exploitation just three days after its patch release, according to threat intelligence firm Defused. The rapid weaponization of this flaw demonstrates the compressed window between vulnerability disclosure and real-world attack deployment. Organizations running SAP Commerce Cloud environments face urgent pressure to apply available patches before attackers can establish persistent access to their systems. Source: Max severity SAP Commerce Cloud flaw now targeted in attacks

APT Group HoneyMyte Upgrades CoolClient with Kernel-Level Windows Rootkit

Advanced persistent threat group HoneyMyte has significantly enhanced its CoolClient backdoor by integrating a kernel-mode rootkit driver, substantially increasing its evasion capabilities. The new variant can hide malicious processes, files, and network connections from security tools and threat analysts, making detection and incident response substantially more difficult. This upgrade reflects the group's commitment to maintaining persistent access within compromised enterprise environments and underscores the escalating sophistication of nation-state cyber operations. Source: APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Hackers Exploiting Unpatched GeoServer Zero-Day

An unpatched zero-day vulnerability in GeoServer has become the target of active exploitation campaigns. The security defect is characterized as an SQL injection flaw that enables attackers to achieve remote code execution on affected systems. The rapid exploitation of this vulnerability highlights the critical importance of timely patching and monitoring for zero-day indicators across open-source geospatial infrastructure deployments. Source: Hackers Exploiting Unpatched GeoServer Zero-Day

Security teams should prioritize patch deployment for SAP Commerce Cloud systems, implement network segmentation to limit router compromise impact, and increase monitoring for GeoServer exploitation attempts. The convergence of multiple active threats underscores the need for elevated vigilance across all infrastructure layers.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
MITRE ATT&CK5
  • DLL Side-Loading (renaming Sangfor executable to defender.exe)
  • Command execution via wmic for Defender exclusions
  • Process Injection into synchost.exe
  • Scheduled task for AutoRun persistence
  • IOCTL command dispatcher for driver communication
Malware2
  • CoolClient
    Backdoor family updated with kernel-mode rootkit
  • PlugX
    Used as initial post-compromise implant to deploy CoolClient