# Cisco Talos Malware Protection

Published articles for Cisco Talos Malware Protection.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen's infrastructure and evidence of Qilin's AI use

DevFeed: [Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen's infrastructure and evidence of Qilin's AI use](<https://devfeed.tech/articles/ransomware-incidents-in-japan-in-the-first-half-of-2026-investigation-of-the-gentlemen-s-infrastructure-and-evidence-of-qilin-s-ai-use-49139.md>)

Original publisher: [Read original article](<https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/>)

Author: Takahiro Takeda

Published: 2026-09-17T10:00:43Z

Content type: article

Language: en

Sources: [Cisco Talos Blog](<https://devfeed.tech/sources/cisco-talos-blog.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Cisco Talos](<https://devfeed.tech/topics/cisco-talos.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cisco-talos-malware-protection](<https://devfeed.tech/tags/cisco-talos-malware-protection.md>), [cisco-talos-network-intrusion-prevention](<https://devfeed.tech/tags/cisco-talos-network-intrusion-prevention.md>), [japan](<https://devfeed.tech/tags/japan.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [threat-spotlight](<https://devfeed.tech/tags/threat-spotlight.md>)

### AI overview

Cisco Talos reports that ransomware incidents affecting Japanese organizations increased 4.7% year over year in the first half of 2026. The Gentlemen was the most active group, while Qilin appeared to use AI to improve operational efficiency. Organizations with capital below JPY 1 billion represented about 80% of victims.

### Source excerpt

Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.

## Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

DevFeed: [Active exploitation of Cisco Secure Firewall Management Center vulnerabilities](<https://devfeed.tech/articles/active-exploitation-of-cisco-secure-firewall-management-center-vulnerabilities-49135.md>)

Original publisher: [Read original article](<https://blog.talosintelligence.com/fmc-ongoing-exploitation/>)

Author: Cisco Talos

Published: 2026-09-09T16:08:59Z

Content type: article

Language: en

Sources: [Cisco Talos Blog](<https://devfeed.tech/sources/cisco-talos-blog.md>)

Topics: [Cisco Talos](<https://devfeed.tech/topics/cisco-talos.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [Security](<https://devfeed.tech/topics/security.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>)

Tags: [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cisco-talos-antivirus](<https://devfeed.tech/tags/cisco-talos-antivirus.md>), [cisco-talos-malware-protection](<https://devfeed.tech/tags/cisco-talos-malware-protection.md>), [cisco-talos-network-intrusion-prevention](<https://devfeed.tech/tags/cisco-talos-network-intrusion-prevention.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [landing-page-top-story](<https://devfeed.tech/tags/landing-page-top-story.md>), [malware](<https://devfeed.tech/tags/malware.md>), [security](<https://devfeed.tech/tags/security.md>), [security-advisory](<https://devfeed.tech/tags/security-advisory.md>), [threat-advisory](<https://devfeed.tech/tags/threat-advisory.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Cisco Talos reports active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center software. The flaws enable authentication bypass or low-privileged access, and observed intrusions involved web shells, command execution, credential exfiltration, reverse shells, proxy tooling, and malware deployment.

### Source excerpt

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco's Secure Firewall Management Center (FMC) Software.

## ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

DevFeed: [ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager](<https://devfeed.tech/articles/clearfake-webdav-infection-chain-delivers-amatera-stealer-zigcryptostealer-and-netsupport-manager-49133.md>)

Original publisher: [Read original article](<https://blog.talosintelligence.com/clearfake-webdav-infection-chain/>)

Author: Vanja Svajcer

Published: 2026-09-08T10:01:07Z

Content type: news

Language: en

Sources: [Cisco Talos Blog](<https://devfeed.tech/sources/cisco-talos-blog.md>)

Topics: [infection chain](<https://devfeed.tech/topics/infection-chain.md>), [payload](<https://devfeed.tech/topics/payload.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [ClickFix](<https://devfeed.tech/topics/clickfix.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cisco](<https://devfeed.tech/tags/cisco.md>), [cisco-talos](<https://devfeed.tech/tags/cisco-talos.md>), [cisco-talos-antivirus](<https://devfeed.tech/tags/cisco-talos-antivirus.md>), [cisco-talos-malware-protection](<https://devfeed.tech/tags/cisco-talos-malware-protection.md>), [cisco-talos-network-intrusion-prevention](<https://devfeed.tech/tags/cisco-talos-network-intrusion-prevention.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [go](<https://devfeed.tech/tags/go.md>), [google](<https://devfeed.tech/tags/google.md>), [infection](<https://devfeed.tech/tags/infection.md>), [infection-chain](<https://devfeed.tech/tags/infection-chain.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [payload](<https://devfeed.tech/tags/payload.md>), [threat-spotlight](<https://devfeed.tech/tags/threat-spotlight.md>), [threats](<https://devfeed.tech/tags/threats.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>)

### AI overview

Cisco Talos investigates two related WebDAV-based infection chains delivering the Amatera stealer. The chains use a Cloudflare Worker, JavaScript stored on BNB Smart Chain, and a fake Google CAPTCHA prompt, with secondary payloads including ZigCryptoStealer, a Go-based reverse proxy, and unauthorized NetSupport Manager.

### Source excerpt

We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.

## UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities

DevFeed: [UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities](<https://devfeed.tech/articles/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities-49145.md>)

Original publisher: [Read original article](<https://blog.talosintelligence.com/uat-10147-deploys-spectre-a-cross-platform-implant-with-linux-rootkit-and-byovd-capabilities/>)

Author: Joey Chen

Published: 2026-08-20T10:00:50Z

Content type: article

Language: en

Sources: [Cisco Talos Blog](<https://devfeed.tech/sources/cisco-talos-blog.md>)

Topics: [C2](<https://devfeed.tech/topics/c2.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-development](<https://devfeed.tech/tags/ai-assisted-development.md>), [c2](<https://devfeed.tech/tags/c2.md>), [cisco-talos-antivirus](<https://devfeed.tech/tags/cisco-talos-antivirus.md>), [cisco-talos-malware-protection](<https://devfeed.tech/tags/cisco-talos-malware-protection.md>), [cisco-talos-network-intrusion-prevention](<https://devfeed.tech/tags/cisco-talos-network-intrusion-prevention.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [edr](<https://devfeed.tech/tags/edr.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [malware](<https://devfeed.tech/tags/malware.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [threat-spotlight](<https://devfeed.tech/tags/threat-spotlight.md>)

### AI overview

Cisco Talos analyzes UAT-10147 and its SPECTRE implant, describing cross-platform command-and-control, process injection, credential theft, anti-analysis protections, and kernel-level EDR bypass. The campaign also uses Linux rootkits, custom and open-source tooling, web shells, and SEO fraud components, with evidence suggesting some malware development involved AI-assisted workflows.

### Source excerpt

The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and response (EDR) bypass functionality.