September 7, 2026 Emerging Threats Weekly

Sep 7, 2026

This week’s briefing covers:

00:00 – Intro

00:50 [THREAT ACTOR] QTFY’s Scanning and Obfuscation Platforms Remain a Live Risk to Critical Infrastructure
U.S. agencies published new detail this week on QTFY, a China-linked intrusion cluster tied to Nanjing Xinjiuwei Network Technology Co., describing it as an operator and service provider for large-scale reconnaissance, exploitation and traffic obfuscation.

04:28 [SOCIAL ENGINEERING] Mirage Kitten Used Fake Coding Tests and “No AI” Instructions to Deliver New Implants
Kaspersky research published this week describes a Mirage Kitten campaign that used recruiter personas on LinkedIn to deliver trojanized coding assessments to software engineers. Victims were sent what appeared to be legitimate take-home tests hosted on Amazon S3, shifting the lure away from conventional phishing attachments towards normal hiring workflows.

07:06 [THREAT ACTOR] Breeze Comet is Targeting Brazilian Payment Rails with Focused Intrusion Tradecraft
Google Threat Intelligence Group reporting published this week describes Breeze Comet, formerly tracked as UNC5669, as a financially motivated actor targeting Brazilian organizations since 2024. The group focuses on entities with access to domestic payment systems and banking workflows, including Pix, STR and Boleto, rather than pursuing broad ransomware-style monetisation.

09:31 [CAMPAIGN] BlueDelta Uses HOOKEDGE Against European Defense and Diplomatic Targets
Recorded Future reported a series of initial-access campaigns that researchers assessed with moderate confidence were conducted by the Russian state-sponsored threat actor KTA007, also known as APT28 and Fancy Bear, a Russian state-sponsored threat group attributed to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).

11:44 [AI] Gryxa Shows how AI-assisted Development is Lowering the Barrier for Full Intrusion Toolkits
Security researchers reported this week on Gryxa, a new toolkit used by a financially motivated actor. Its management console listed 324 hosts, 69 of them reporting online at the time of analysis, although not every listed host was necessarily a confirmed victim.

Dive deeper:

Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report

Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing

Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto

Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist

Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber

Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports

Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber

#krollcyber #threatintelligence #cyberthreats