Threat View from the Lens of Huntress Adversary Tactics: September 2026

Threats Seen in the SOC

Adversary Tactics documents, makes sense of, and informs the broader community about interesting threats that surface from our SOC. Here are some examples of standout trends we’ve seen in the last few weeks.

Browser-in-the-Browser Phishing Delivers Rogue RMMs

Huntress SOC analysts investigated two phishing attacks that used browser-in-the-browser pages to impersonate Adobe Reader. In one case, a fake CAPTCHA led to a page showing blurred documents and a prompt to install an “update.” In another, a malicious message delivered through a legitimate communications platform used the same template. Instead of Adobe Reader, victims downloaded rogue ScreenConnect clients. Each attack installed two clients, creating redundant, service-based persistence, before using HideCursor or HideUL to conceal on-screen activity. Huntress stopped both attacks before they progressed further, but the campaigns show how familiar branding and legitimate-looking browser elements can turn a phishing click into persistent remote access. Huntress SOC analyst Sarah Reddish outlined the attack in this blog post.

A phishing campaign with an Adobe lure

The Takeaway

Treat unexpected file-viewing pages, CAPTCHA prompts, and software updates with suspicion, even when they appear to use trusted branding. Restrict unapproved RMM tools and investigate new ScreenConnect installations, unusual relay connections, and executables launched from Downloads folders.


Power BI Phishing Delivers Rogue ScreenConnect Clients

Huntress observed a phishing campaign that abused Microsoft Power BI to make its lure look legitimate and slip past controls that trust the service. Victims received an email linking to a public Power BI page that displayed a fake “Download Reference” button. Clicking it opened an attacker-controlled site that fingerprinted the browser and host before triggering a rogue ScreenConnect download. The initial client installed a second remote-access client, giving the attackers redundant access. In one incident, the attackers also used a PowerShell script, a scheduled task set to run every two minutes, and HideUL_x64.exe to evade defenses. The SOC stopped the activity before it could advance.

An outline of the phishing campaign

The Takeaway

A legitimate cloud domain does not make a link safe. Review protections and reporting workflows for trusted services that lead to downloads, and alert on unexpected ScreenConnect clients, scheduled tasks, and remote-access scripts.


Settra Ransomware Uses MeshAgent and BYOVD

Huntress investigated a September ransomware incident involving Settra, a newer ransomware variant first publicly reported in June. The Huntress agent was installed while the intrusion was already underway, but telemetry still showed the attacker’s post-compromise playbook. The actor installed MeshAgent for remote access and used a Bring Your Own Vulnerable Driver technique, likely to interfere with security tools. They then launched ransomware from the compromised user’s Documents folder, encrypted files with the .locked_wip extension, created RESTORE_FILES.txt ransom notes, cleared numerous Windows event logs, and disabled Windows recovery options. A misspelled Defender log name left one valuable source of evidence intact. Check out our analysis of Settra for more information.

Signals indicating the attacker's use of BYOVD and the MeshAgent RMM

The Takeaway

Watch for unauthorized RMM installations, vulnerable driver loading, log clearing, and recovery-environment changes. Even when encryption succeeds, surviving endpoint telemetry can reveal the attacker’s access path and help scope the broader intrusion.


The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT

Huntress researchers found a modular RAT hidden inside a tampered Exodus crypto wallet installer. Victims opened fake PDFs or software-update ZIP files that launched JavaScript, displayed a legitimate decoy document, and silently installed the wallet. The package was nearly indistinguishable from the real application: just three of 1,973 files were modified, and it had no VirusTotal detections. Those changes prevented a window from appearing and loaded a memory-resident payload with hidden VNC, a SOCKS proxy, browser credential theft, file management, and remote commands. An hourly scheduled task relaunched the invisible application, while command-and-control traffic used Azure Table Storage rather than an attacker-owned domain. Learn more about the attack in this blog post by Jonathan Semon and Jose Oregon.

How an unopenable crypto wallet ends up installing a modular RAT to steal browser credentials

The Takeaway

A trusted application name or a clean hash isn’t necessarily a clean bill of health. Defenders should investigate silent per-user application installs, Electron applications with no visible window, and scheduled tasks launching executables from AppData. They should also treat browser credentials and active sessions on affected hosts as compromised.


Inside Knight Office, a New M365 AiTM Phishing Kit

Huntress researchers uncovered Knight Office, an operator console behind an adversary-in-the-middle phishing campaign targeting Microsoft 365 accounts. A DocuSign-style lure used Monday redirects and a compromised Joomla website to hide the final phishing page. After a victim completed MFA, the kit captured a valid session token and replayed it from attacker infrastructure, bypassing password-based controls. The actor then registered an unauthorized Microsoft Entra device and bound a Windows Hello for Business key credential to the account. That created durable passwordless access that could survive session revocation. Huntress linked at least nine token-replay attacks to the kit and found hundreds of related lures reported through its telemetry.

The lure email behind the AiTM attack

The Takeaway

AiTM attacks steal the authenticated session, not just the password. Monitor post-MFA sign-ins from callback proxies, newly registered Entra devices, and new Windows Hello credentials, then revoke sessions and remove unauthorized authentication methods.

Threats Around the World

Microsoft’s record Patch Tuesday includes two exploited zero-days

Microsoft’s September Patch Tuesday was its biggest yet, addressing 974 vulnerabilities across Windows, Office, SQL Server, Exchange, SharePoint, Azure, and developer tools. Two Windows privilege-escalation vulnerabilities were already being exploited in the wild, while the release also included 20 potentially wormable flaws. The scale alone makes this update cycle noteworthy, but the active exploitation raises the stakes.

The Takeaway

Organizations should prioritize the exploited bugs, inventory affected systems, and accelerate testing and deployment of the remaining updates.


Cisco patches an actively exploited, maximum-severity ISE flaw

Cisco issued emergency fixes for CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector. The flaw lets an unauthenticated, remote attacker send crafted requests to a vulnerable API endpoint, bypass the web management interface, and gain root-level command execution.

The Takeaway

Cisco confirmed that the vulnerability is being actively exploited, and CISA added it to its Known Exploited Vulnerabilities catalog. Organizations using appliances should apply Cisco’s releases and review systems for compromise.


Brevo supply-chain attack injects ClickFix malware into customer sites

Brevo disclosed a supply-chain attack in which attackers used a compromised Cloudflare API key to deploy a Worker at the CDN edge. For roughly five hours, the Worker rewrote Brevo-hosted scripts embedded on sites. Visitors were shown a fake Cloudflare verification page that pushed ClickFix malware, while logged-in WordPress administrators faced an attempted backdoor installation.

The Takeaway

Security researchers estimated the incident could have affected more than 100,000 websites, demonstrating how one exposed credential can amplify risk.

Rapid Responses

At Huntress, we spin up “Rapid Responses” when there is a vulnerability or threat being used by attackers to escalate the deployment of malware at scale. When we hear about a potential vulnerability, the Adversary Tactics team works across Huntress to figure out the potential impact, update our customers, and provide documentation for the security community. Here are two incidents we handled in the last month:

Critical N-able N-central Vulnerability and Active Exploitation

In August, Huntress supported its customers when N-able disclosed actively exploited N-central flaws. Then September brought a new series of discoveries. On September 5, Huntress reproduced a separate exploit chain affecting fully patched environments, involving CVE-2026-86206 and CVE-2026-86207, that could bypass access controls and create unauthorized administrative accounts. The team shared its findings with N-able, which released Hotfix 3. The next day, N-able disclosed CVE-2026-86218, an actively exploited pre-authentication RCE rated 10.0, and released Hotfix 4, which supersedes prior fixes. Huntress also worked with Cloudflare to disable adversary tunnels and published hunting guidance for API anomalies and suspicious .invalid account changes in N-central environments worldwide.

The Takeaway

Hotfix 4 is the mandatory baseline for on-premises N-central instances, since Hotfix 3 does not protect against CVE-2026-86218. Restrict inbound access to the console, audit API and account changes, and investigate possible compromise.


Rogue ScreenConnect Installations Suggest Worm-Like Activity

Huntress investigated three incidents in which social engineering led victims to install rogue ScreenConnect clients. On unrelated endpoints, those clients repeatedly spawned wscript.exe to run four staged VBScript files, then created WindowsServiceHost persistence in AppData. The modified ScreenConnect clients did more than provide remote access: they watched for new Host connections, transferred the same scripts through ScreenConnect’s virtual file-transfer feature, and executed them on connected systems. That gave the campaign a potentially worm-like propagation path. The campaign also used Quick Assist and UltraViewer. ConnectWise released version 26.6.5 to address an authorization flaw in Client Support and Access session file transfers.

Huntress detected ScreenConnect.WindowsClient.exe spawning the child process wscript.exe

The Takeaway

Treat unexplained ScreenConnect clients and RunFiles or RanFiles audit-log entries involving 1.vbs through 4.vbs as signs of compromise. Upgrade to ScreenConnect 26.6.5 and reimage impacted endpoints from known-good media.

Relevant Product Updates

While not a direct product of the Adversary Tactics team, we’d like to highlight some killer new capabilities that our partners in Product Research and Product have released to help mess up attackers. We can’t wait to start using this data to expand our understanding of the threat actors our customers face.

Check out this month’s Product Lab, where Huntress CTO Chris Bisnett and Chief Innovation Officer Daniel Westendorf discussed product updates, upcoming features, and more.

September 2026 Product Lab

Managed EDR

  • Unsecured Credentials - New Credential Files Dashboard and Allowlisting: We've given Unsecured Credentials a complete overhaul, with a new dashboard, full visibility into flagged files, and the ability to allowlist files you don't want reported. What's new?
    • Credential Files page. A new home for Unsecured Credentials, available from the Process Insights dashboard in Managed EDR. View and manage every file triggering an Unsecured Credentials report in one place.
    • See before you enable. You can now preview which Credential Files would generate an Incident Report, without turning reporting on!
    • Allowlisting. Exclude the files you've reviewed and accepted, so reports stay focused on what actually needs attention.

Have you turned these off before? Give them another look.


Managed ITDR

  • New ITDR dashboard is now live: The redesigned Managed ITDR dashboard is now generally available to all partners and customers! Built to help you investigate identity threats faster and get the context you need in one place, the new dashboard brings powerful investigation capabilities directly into your ITDR workflow, including Rapid Identity Triage, Failed Login Characterization, and Quick SIEM Search. Starting now, the redesigned dashboard will be the default dashboard when you access Managed ITDR. Get more ITDR dashboard details in our new blog.

Managed ISPM

  • Managed ISPM now offers two ways to deploy security controls: Managed Deployments, the recommended default, is when Huntress picks the controls and rolls them out for you automatically. It’s built for teams that want hardening handled without hands-on review. Brand new: Modified Deployments allow you to build your own set of controls from the full Huntress policy library and set your own rollout schedule. New controls aren’t rolled out until you’ve first approved them. This method is built for change-control and compliance-heavy environments like CMMC or ISO 27001.
  • New security controls in Managed ISPM: As we continue to build out depth of controls to harden Microsoft 365 environments, we have added new controls in Microsoft Exchange Online and Microsoft Defender for Office 365 to protect against Shadow Workflows.

Managed SIEM

  • New log sources in the Huntress SIEM: We are happy to announce that we officially support powerful new log sources, including IT Glue, Cato, Checkpoint, N-Able, and Scout DNS. By normalizing this data, we are unlocking deeper, more actionable insights into your IT infrastructure than ever before!

Managed SAT

  • New Learner Onboarding Video: This new assignable video gives learners the complete run down of what to expect from their new Security Awareness Training program, from episodes, to phishing scenarios, Phishing Defense Coaching, Threat Simulators, and more.

Highlights

Tradecraft Tuesday: Borrowed Faces, Borrowed Certs: Inside a Post-DEFCON Malware Campaign

September’s Tradecraft Tuesday, “Borrowed Faces, Borrowed Certs,” unpacked a post-DEFCON campaign that impersonated a CoinDesk executive and used a Google Doc as lure and reconnaissance tool. A container-bound Apps Script collected a viewer’s IP address, location, browser details, and crypto-wallet extensions, then sent the data to Telegram. Victims were steered toward macOS or Windows payloads through decryption errors, ClickFix prompts, and downloads signed with stolen certificates. The macOS path delivered an AMOS-like stealer, while the Windows chain recovered a NetSupport RAT, a rogue certificate authority, and a crypto-wallet implant. Researchers also showed how they recovered stages after C2 went offline. Check out the full recap here—and make sure to sign up for our October Tradecraft Tuesday!

The September Tradecraft Tuesday episode was focused on a post-DEFCON malware campaign