Today’s roundup
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers
APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Summary
A new Linux botnet, Evooo1Bot, based on Mirai, is actively targeting internet-facing gateway devices. The malware transforms compromised routers into SOCKS5 traffic relay nodes, enabling threat actors to mask their activities and facilitate further malicious operations. This represents an evolving threat to network infrastructure.
France's Directorate-General for Public Finances (DGFiP) has confirmed a sophisticated cyberattack in late June resulted in the exposure of personal data for 678,000 taxpayers, including individuals and businesses. The stolen information, which includes income and tax details, could facilitate identity theft and targeted phishing campaigns, although it does not grant direct access to taxpayer accounts. A criminal investigation is underway by the Paris Public Prosecutor's Office and OFAC, following a series of recent breaches against other French government bodies.
Acronis has uncovered the PATCHCORD espionage campaign, attributed with moderate confidence to APT36 (Transparent Tribe), targeting Afghan telecom providers and South Asian critical infrastructure. The operation utilizes a new C/C++ backdoor, PATCHCORD, and an evolved Go-based implant, SHEETCORD, which notably uses Google Sheets API for command and control. A third identified malware, HACKERAI C2 Agent, exhibits signs of AI-assisted coding. The malware is delivered via highly specific fake VPN installers impersonating legitimate organizations, and its persistence mechanism involves hijacking browser shortcuts. The discovery was aided by an exposed staging server revealing the attacker's toolkit.
A critical unauthenticated Remote Code Execution (RCE) vulnerability in SAP Commerce Cloud, CVE-2026-58231 (CVSS 10.0), is being actively exploited in the wild, just three days after SAP released a patch. The flaw allows attackers to compromise internal components due to insufficient authorization checks and input validation. Researchers observed exploitation attempts against honeypots, highlighting the rapid weaponization of this maximum severity vulnerability.
Want to dig deeper?
Vulnerabilities
Cyber Groups