EXPLORE

Article

Don’t Drink from That! Gootloader Watering Hole Leads to REvil Attack

Arete Analysis

Threat Actors

REvil, more commonly referred to as Sodinokibi, is one of the most prolific ransomware threat groups currently active in the cyber extortion space. In the past year alone, Arete has responded to countless incidents where REvil has facilitated cyberattacks against client sites.

From our investigations, we have curated and documented threat intelligence to better understand the group’s tactics, techniques, and procedures (TTPs). Based on incident analysis, the threat group primarily leverages three main vectors to gain initial access to targeted environments:

  • They exploit externally facing and unsecured Remote Desktop Protocol (RDP).

  • They leverage access to a compromised remote management platform, such as ScreenConnect/ConnectWise or NinjaRMM.

  • Or, they leverage compromised VPN appliances.

Other entry and deployment methodologies have been employed previously by the REvil group, such as the WinRAR Italia distributor supply chain attack in June of 2019. However, based off of the numerous REvil attacks we have responded to since the group’s inception, the above methodologies are those most commonly leveraged by the REvil threat group.

During a recent incident, however, we noted an interesting change in the group’s initial  access tactics, whereby they leveraged a successful Cobalt Strike compromise, which was initially introduced into the victim environment by way of the execution of Gootloader that was downloaded from a fraudulent messaging forum.

Arete Analysis

During our investigation, we identified the root cause of this incident as a successful watering hole attack that had impacted an employee workstation.

While conducting an online search for legal contract agreements specific to septic systems, the employee selected a site that a Google search had returned. Unbeknownst to the employee, threat actors had compromised the site, configuring it to display a malicious web page designed to look like an active messaging forum.

As shown below, the forum’s first post appeared to come from a user — display name “Emma Hill” — who had requested the same type of legal contract agreement that the employee had been searching for. The web page also made it seem that another user — display name “Admin” — had replied to the initial post, providing a direct download link to the requested document.


Figure 1: Malicious web page that appears to show a legitimate messaging forum

In this case, the hyperlinked text reached out to an external domain, one that was hosting a PHP script named down.php. When clicked, this link fetched a request to this PHP script, which then automatically downloaded a ZIP archive that contained a highly obfuscated JavaScript file. This JavaScript file had the same name as the ZIP archive. The content of this JavaScript file is below:

Figure 2: JavaScript file

Based on our analysis and the fact that we observed Cobalt Strike indicators on the endpoint less than an hour later, this JavaScript file was attributed to the Gootkit Remote Access Trojan (RAT), which was then further leveraged to introduce a secondary payload, Cobalt Strike, into the victim environment.  A REvil threat actor leveraged this initial compromise to gain access into this organization’s environment and, approximately eight (8) days later, deployed the REvil ransomware.

Another interesting observation from the analysis of this web page was that, after visiting the site from the same IP address in a short amount of time, the page redirected the end user to a different web page, one with a title page indicative of the legal contract the user was searching for. Unfortunately, this web page was simply a veil designed to shroud the site’s compromise and suppress any user suspicions.

Figure 3: Web page after initial site visitation

Indicators

Based on analysis performed during this engagement, Arete has compiled a list of indicators for public use and incorporation into security infrastructure.

Zip Archive Containing JavaScript Payload

  • MD5: E435D74D8A4009C955635C11DA1D3AFC

  • SHA1: F7C620AD560CDA2A9BA90B3E17C6D43A5FB91B44

  • SHA256: 2D6AB5C855F86032C4B2213B7FC5E53F0A772B4F709AE85299B8D33C1867845C

JavaScript Payload

  • MD5: 31C8B072C6FF386645DB60A4D9E121BB

  • SHA1: F6D85FFE4CA1A77F0DF7FE2379D6BB2103B6EE15

  • SHA256: 71C838EAC60AFBFE39728887240781AA5A10E0E563FB4AC259F965BFCD1FD5EA

Domains Serving Zip Archive

  • https[:]//www[.]vacanzenelmediterraneo[.]com/down.php

    • IPv4: 89.46.108[.]30

  • https[:]//www[.]thursdaybram[.]com/down.php

    • IPv4: 104.131.158[.]83

  • https[:]//yukata-sienne[.]jp/down.php

    • IPv4: 183.181.97[.]13

  • https[:]//www[.]frerecapucinbenin[.]org/down.php

    • IPv4: 94.177.165[.]14

  • https[:]//www[.]willkommen[.]org[.]rs/down.php

    • IPv4: 46.151.128[.]3

Watering Hole Communication Strings

  • Hi, I am looking to*A friend of mine told me he had seen it on your forum. I will appreciate any help here.

  • Here is a direct download link,

  • Thank you so much for your response! This is exactly what Ive been looking for

  • Thank you, Admin

  • Issue resolved. The ticket can be closed.

Fraudulent Forum – Full

Back to Blog Posts

Article

Critical Vulnerability in Progress Kemp LoadMaster Exploited

Researchers have identified active exploitation of CVE-2026-8037, a critical unauthenticated remote code execution vulnerability affecting Progress Kemp LoadMaster. The vulnerability affects LoadMaster GA versions 7.2.63.1 and earlier and LTSF versions 7.2.54.17 and earlier and can allow a remote adversary to execute commands on an affected appliance without valid credentials when the vulnerable API is exposed. Progress has released updates addressing CVE-2026-8037 and CVE-2026-33691, a separate Web Application Firewall security control bypass, in GA 7.2.63.2 and LTSF 7.2.54.18.

The exploitation of this vulnerability reflects a broader trend of threat actors targeting internet-facing enterprise technologies. For example, Progress MOVEit Transfer experienced significant scanning and exploitation activity in 2025 involving CVE-2023-34362 and CVE-2023-36934, as well as the 2023 exploitation of CVE-2023-34362 by the Cl0p ransomware group for large-scale data theft and extortion. More recently, CISA confirmed the exploitation of SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, by ransomware groups. Collectively, these incidents demonstrate the continued targeting of perimeter-facing enterprise technologies as high-value entry points into corporate environments. 

What’s Notable and Unique

  • Public exploit research, observed exploitation attempts, and CISA KEV inclusion indicate that CVE-2026-8037 has progressed into an active operational threat, increasing urgency for organizations with exposed and unpatched LoadMaster systems. 

  • Internet-facing infrastructure can be rapidly identified through automated scanning, enabling threat actors to quickly identify vulnerable systems and capitalize on newly disclosed vulnerabilities and publicly available exploit techniques. 

Analyst Comments

CVE-2026-8037 is significant not only for its severity but also because it affects infrastructure positioned between the internet and critical enterprise applications. The combination of external exposure, unauthenticated exploitation, and public exploit research lowers the barrier for threat actors seeking initial access, and the broader threat landscape reinforces this concern. The exploitation of Progress MOVEit by Cl0p, continued scanning activity against MOVEit, and recent ransomware exploitation of SonicWall SMA1000 vulnerabilities demonstrate sustained adversarial interest in perimeter-facing enterprise technologies. These incidents indicate that such infrastructure should be treated as high-value assets within enterprise security programs.  

Sources

  • Surge in MOVEit Transfer Scanning Could Signal Emerging Threat Activity 

  • LoadMaster Critical Security Bulletin – June 2026 – (CVE-2026-8037, CVE-2026-33691)

  • Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037)

  • CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

Podcast

Blockchain Unmasked: The Role of Cryptocurrency in Cybercrime and Threat Intelligence

In this episode of Bytes of Insight, host Vinny Sakore sits down with John Morrissey, Arete’s Director of Cryptocurrency Operations and Sanctions Compliance, and Trenton Howard, Arete’s Lead Threat Intelligence Consultant, to discuss cryptocurrency and blockchain technology. They explore the impact of cryptocurrency on both innovation and cybercrime, threat actors’ use of the blockchain for ransom payments, and Arete’s patent-pending Compliance and Sanctions Analysis Process.

Article

ClickFix Evolves in Server-Side Polymorphic Malware Delivery Campaigns

The ClickFix social engineering technique has significantly evolved from a relatively simple malware delivery mechanism into a highly sophisticated, evasive attack framework. Initially relying on straightforward PowerShell downloaders and disk-based payloads, the campaign now employs fileless execution, advanced obfuscation techniques, and server-side polymorphism to evade traditional security controls. 

What’s Notable and Unique 

  • ClickFix primarily relies on social engineering, as victims are presented with fake CAPTCHA verification pages that imitate trusted services such as Cloudflare or Google reCAPTCHA. Users are instructed to copy and execute a PowerShell command, believing they are completing a legitimate verification process. Instead, the command initiates the malware infection chain. 


  • To bypass traditional security tools, threat actors transitioned to fileless techniques. Instead of downloading scripts directly to disk, newer variants execute malicious code entirely in memory. The most notable recent advancement in ClickFix is the adoption of server-side polymorphism. Unlike traditional malware that delivers a static payload, the threat actor's server dynamically generates unique payloads for each victim request. This approach undermines signature-based detection methods because each delivered payload appears unique, preventing defenders from relying solely on file hashes or static indicators. 


  • The campaign was observed beginning around March 25, 2026, with a significant increase in activity thereafter, indicating that the techniques are proving effective against many organizations' defenses. 

Analyst Comments 

ClickFix social engineering campaigns continue to evolve in 2026, becoming more sophisticated and expanding across multiple operating systems. Organizations should focus on behavioral detection, browser isolation, endpoint monitoring, and user awareness training rather than relying solely on indicators such as hashes or blocklists. The campaign's use of fake CAPTCHA prompts also reinforces the importance of educating users never to execute commands from websites. 

Sources 

  • The Evolution of ClickFix: From Cleartext to Server Side Polymorphism 

Article

Ransomware Trends & Data Insights: July 2026

INC Ransom was the most active threat group in July, while activity remained relatively distributed among multiple threat groups, with 19 unique groups observed throughout the month. Alongside INC Ransom, Qilin, Global Secret Group, Anubis, and DragonForce rounded out the five most active threat groups observed in July. Several emerging threat actors were also observed during the month, including Booba Team, Settra, and Global Secret Group.

Figure 1. Activity from the top 3 threat groups in July 2026

 Throughout the month, analysts at Arete identified several trends behind the threat actors perpetrating cybercrime activities:

  • In July 2026, Global Secret Group emerged as a new threat actor, leveraging the leaked LockBit 3.0 (LockBit Black) source code. Although the group began operations in June 2026, it quickly accumulated a substantial number of victims on its data leak site (DLS). The group operates through TOR-based negotiation portals and qTox communications. Notably, its DLS provides step-by-step guidance on purchasing Bitcoin, including references to Coinbase and Binance, demonstrating a streamlined, victim-focused extortion process designed to simplify ransom payments.

  • Similar to Fulcrumsec, the recently emerged Settra ransomware group appears to leverage AI-driven analysis of stolen data, publishing detailed and highly structured victim reports on its DLS. Additionally, a potential EDR-disabling tool, edr_blind.exe, was identified in multiple cases, suggesting a focus on defense-evasion capabilities.

  • With the continuation of the FortiBleed campaign, researchers have now identified compromised FortiGate credentials being leveraged by both the INC and Lynx ransomware operations. Analysis revealed direct operational links between the groups, including shared ransomware infrastructure and overlap between FortiBleed victims and ransomware targets. The operators are also incorporating AI to enhance various stages of the attack lifecycle and increase operational efficiency and scale. Notably, Arete also observed an INC ransomware intrusion leveraging FortiBleed-derived access in July, reinforcing the campaign's role as a precursor to ransomware deployment.

Sources

  • Arete Internal