Threat Brief: RaaS Scale-Up, Roundcube Exploitation, and New KEV Entries

Threat Brief: RaaS Scale-Up, Roundcube Exploitation, and New KEV Entries

A reporter-ready threat brief covering The Gentlemen ransomware, Roundcube exploitation against university research departments, UAT-7810 router relay infrastructure, SharkLoader delivery of Cobalt Strike, FortiBleed credential exposure cleanup, and the latest CISA KEV additions.

Several of the higher-signal items in this cycle land on systems reporters should treat as infrastructure, not endpoints: mail servers, wireless routers, VPN/firewall credentials, public web apps, and the exploit backlog that CISA just moved into KEV. The strongest follow-up leads are a fast-scaling ransomware program, a Roundcube exploitation chain aimed at university research departments, a router-based relay-box buildout, and a malware loader that is built to keep Cobalt Strike quiet.

Priority queue

PriorityLeadWhy it matters for follow-up
1The Gentlemen ransomware is maturing into a high-volume RaaS operationUnit 42 says the group has been active since at least July 2025, moved toward a RaaS model around September 2025, offered affiliates a 90% payout, and had 580 claimed victims in 77 countries through July 7, 2026; manufacturing was the largest named sector with 103 claimed victims. 1
2Roundcube exploitation is being used as an initial-access path into academic research environmentsProofpoint says UNK_MassTraction has targeted US and Canadian university physics and engineering departments since May 2026, chaining Roundcube CVE-2024-42009 and CVE-2025-49113 into credential theft, webshell deployment, and a Go backdoor. 2
3UAT-7810 is expanding ORB infrastructure through unpatched network devicesCisco Talos says the likely China-nexus actor is exploiting Ruckus wireless routers and related embedded devices to build operational relay-box infrastructure, with new LONGLEASH, DOGLEASH, JARLEASH, and LEASHTEST components. 3
4SharkLoader is delivering Cobalt Strike with multiple evasion layersKaspersky's StrikeShark report describes custom droppers, DLL sideloading, encrypted loader components, API hooking, ETW suppression, PPID spoofing, and Beacon memory-permission switching. 4
5CISA's KEV queue added one legacy Cisco IOS flaw and two file-upload flawsCISA added CVE-2008-4128 on July 13, then CVE-2026-48939 and CVE-2026-56291 on July 10, all based on evidence of active exploitation. 5 6

Ransomware and extortion

The Gentlemen: high affiliate economics, EDR-killer tooling, and manufacturing concentration

Unit 42 profiles The Gentlemen, also tracked as Storm-2697, as a ransomware-as-a-service program active since at least July 2025. The program reportedly shifted from affiliate activity into a RaaS model around September 2025 and advertised a 90% affiliate payout. 1
The technical hook is not just victim volume. Unit 42 says the group uses C and Go ransomware variants, a custom Go-based backdoor, and an EDR-killer framework called GentleKiller, with reporting of a suspected zero-day exploit for EDR disabling. 1 That makes endpoint-tamper telemetry, vulnerable-driver loading, and recovery-state evidence worth asking victims about early.
For access and movement, Unit 42 points to edge-device exploitation, firewall and VPN weaknesses, brute-force activity, stolen credentials, initial-access brokers, exposed RDP, and propagation across internal networks. 1 Useful detection questions: scheduled tasks matching gentlemen*, wevtutil log clearing, Advanced IP Scanner usage, SystemBC-like traffic, vssadmin or wmic shadow-copy deletion, and unexpected unsigned or vulnerable drivers.

Malware and intrusion chains

UNK_MassTraction: Roundcube mail servers as the edge device

Proofpoint's Roundcube report is a clean intrusion-chain story. The actor sends phishing mail through compromised or spoofable senders, then relies on the target opening the message in a vulnerable Roundcube client. CVE-2024-42009 gives the attacker a cross-site scripting path through a crafted email; NVD describes the flaw as allowing a remote attacker to steal and send emails via a crafted message that abuses desanitization in message_body() in program/actions/mail/show.php. 7
The browser-side payload, IceCube, escapes the Roundcube iframe, steals usernames, passwords, 2FA material and cookies, collects environment data, and uses the active session's CSRF token for the next stage. Proofpoint says the chain then uses CVE-2025-49113, a Roundcube deserialization flaw in which the _from parameter is not validated in program/actions/settings/upload.php, to attempt command execution and webshell placement. 2 8
The server-side artifacts are specific enough for quick reporting asks: SquareShell at plugins/newmail_notifier/mail_preview.php, timestomping, a fallback shell script, an architecture-specific ELF loader, and the VShell Go backdoor running under a fake [kworker/0:2] process name. Proofpoint lists IceCube C2/delivery infrastructure at 45.150.109.151, 194.213.18.133, and VShell C2 at 45.86.229.111. 2

UAT-7810: Ruckus routers and multi-platform relay malware

Cisco Talos says UAT-7810 is probably a China-nexus actor tasked with maintaining and expanding ORB networks. ORB stands for operational relay box: compromised routers and embedded systems used as proxy nodes so later attacks appear to originate from third-party infrastructure. 3
The current activity centers on unpatched Ruckus wireless routers and known vulnerabilities including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717. Talos also notes overlap with infrastructure previously tied to ASUS AiCloud router exploitation. 3
The malware family names are worth keeping straight. LONGLEASH is a new SHORTLEASH version with proxying, tunneling, tasking, and C2 relay capability; DOGLEASH is a C backdoor that can execute shellcode on Linux devices; JARLEASH is a Java/JAR backdoor with file-management and FTP/SFTP features; LEASHTEST is a test binary whose presence still signals compromise. 3 Talos also published detection coverage, including SNORT SIDs 66433, 66432, 66430, 66431, and 301493.

StrikeShark: SharkLoader into Cobalt Strike

Kaspersky's StrikeShark write-up describes a campaign that uses SharkLoader to place Cobalt Strike Beacon on victim systems. The observed access routes include exploited public services such as Microsoft Exchange CVE-2021-26855 and CVE-2022-41082, SharePoint CVE-2021-27076, Openfire CVE-2023-32315, and GeoServer CVE-2024-36401. 4
The loader chain is defensive-evasion heavy. Kaspersky describes fake installers and droppers, DLL sideloading through SystemSettings.exe and SystemSettings.dll, encrypted DscCoreR.mui and SyncRes.dat components, registry Run keys, scheduled tasks, ETW hook suppression, PPID spoofing, and Beacon sleep-time memory-permission changes. 4
The reporter hook: this is not a single loader sample. It is a full post-exploitation path. Kaspersky observed host and AD enumeration commands, LSASS dumping with ProcDump, ntdsutil use for domain database material, and tools including FScan, Searchall, Pillager, and SharpGPOAbuse. 4

Breach and exposure watch

FortiBleed: credential exposure still has cleanup value

CISA's FortiBleed alert is older than the newest KEV additions, but it remains follow-up worthy because the agency says exposed credentials were associated with approximately 74,000 Fortinet devices, including firewalls and VPN gateways. 9
The agency's response checklist is concrete: terminate active SSL VPN and administrative sessions, reset Fortinet VPN and admin passwords, enforce PBKDF2 credential storage for administrator accounts, review firewall/VPN/authentication/domain-controller logs, require phishing-resistant MFA, and remove public internet exposure from management interfaces. 9
This is a good place to ask affected organizations whether password rotation covered local admin accounts, VPN-only users, service accounts, and any credentials reused outside Fortinet appliances.

Active exploitation and KEV

CISA added CVE-2008-4128, a Cisco IOS cross-site request forgery vulnerability, to the Known Exploited Vulnerabilities catalog on July 13, 2026, based on evidence of active exploitation. 5
On July 10, CISA added two unrestricted file-upload vulnerabilities: CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms. 6 For coverage planning, both are CMS/plugin-style upload bugs rather than endpoint flaws, so incident leads are more likely to surface through webshells, defacement, credential theft from hosted environments, or follow-on malware on public web servers.
The CISA alert language matters: each addition is based on evidence of active exploitation, and CISA recommends prioritizing KEV remediation even outside the federal civilian agency mandate. 5 6

Follow-up questions for reporting

  • Are any victims of The Gentlemen seeing GentleKiller, vulnerable-driver loading, or ESXi management-plane access before encryption?
  • Are universities running Roundcube able to confirm exposure to CVE-2024-42009 or CVE-2025-49113, and did they preserve browser-side telemetry from the initial mail-opening event?
  • Are managed service providers seeing Ruckus or ASUS router compromises used as relay infrastructure rather than as the final target?
  • Are Fortinet customers treating the FortiBleed issue as a credential-reset incident, not only a patching incident?
  • For the new CISA KEV entries, are exploited hosts showing webshells or uploader artifacts that connect the CVE to a broader intrusion set?

Related content

  • Sign in to comment.