The Bridewell Threat-Led Approach
Bridewell’s managed security services are built upon a proactive, threat-led defence strategy. Moving beyond reactive monitoring, we actively track adversary infrastructure and tradecraft. By seamlessly integrating Cyber Threat Intelligence (CTI), Incident Response (IR), and Managed Detection and Response (MDR), we ensure our clients remain ahead of the evolving threat landscape.
In a landscape defined by rapid adaptation, knowing what is attacking you is just as critical as knowing how. This month’s Threat Insights leverages data from Bridewell’s global MDR and Incident Response engagements to expose the top malicious infrastructure of September 2026. We go beyond the headlines to provide actionable detection guidance on the month's threat insights, equipping your team with the foresight to stay one step ahead.
Top 5 Malicious Infrastructure Threats Tracked
| Name | Category | Sept Volume | Monthly Trend |
|---|---|---|---|
| Amnesia Stealer | Remote Access Trojan (RAT) | 118 | ▼ Decreasing |
| Cobalt Strike | Exploitation Framework | 110 | ▼ Decreasing |
| Sliver | Exploitation Framework | 88 | ▼ Decreasing |
| CyberStrikeAI | Exploitation Framework | 60 | ▼ Decreasing |
| Crypto-jackers | Cryptominer | 51 | ▲ Increasing |
Threat Detection Insights - September
Throughout September, our team tracked two developments that between them illustrate how the threat to the endpoint is shifting away from the perimeter and towards the people and tooling that sit behind it.
The first was Mirage Kitten, the Iran-linked espionage group also tracked as UNC1549, Smoke Sandstorm and Nimbus Manticore, which Kaspersky reported on the 1st of September 2026 as having expanded beyond its established native C, C++ and Go implants to deploy two previously undocumented cross-platform remote access trojans, NodeRabbit and PollCat, written in Node.js and obfuscated JavaScript respectively. The delivery mechanism is familiar: fake recruiter personas on LinkedIn and other job platforms send software engineers a time-limited coding challenge hosted on legitimate Amazon S3 storage, in which the projects contain malicious bundled code and, in NodeRabbit's case, a trojanised npm dependency that launches the implant when the project is run.
Confirmed victims were identified in the aviation, aerospace and fintech sectors across Egypt, Ethiopia and Afghanistan, but Kaspersky also observed related archives being submitted to an online multi-scanner from India, Türkiye, Israel, Iraq, Germany and Ireland. This delivery model means the exposure is not limited to the sectors already observed: organisations whose engineers use external recruitment platforms should consider themselves potentially exposed to similar lures.
Alongside this, September also saw the release of BigDiskBuster, the latest in a run of Microsoft Defender proof-of-concept exploits published by the researcher known as NightmareEclipse, MSNightmare and Chaotic Eclipse. Published to GitHub on the 19th of September 2026, BigDiskBuster is notable for what it does not do: it does not disable Defender, and it does not provide an obvious route to SYSTEM. Instead, it waits for a platform or security intelligence update to begin, fills the system drive with hidden temporary files so the installer runs out of space, and holds an exclusive handle on MRT.exe, leaving the antivirus running but frozen on whatever engine and definitions it had when the tool started.
As of the 28th of September 2026, there is no CVE, no Microsoft advisory specifically addressing BigDiskBuster, no confirmed patch and no evidence of in-the-wild use. The researcher's claim that it works on all supported Windows versions is unverified, but the technique is trivially cheap to reproduce and, given that several of the same researcher's earlier releases were exploited after publication, it warrants a detection use case now rather than later.
Mirage Kitten: Trojanised Coding Challenges and Developer-Centric Persistence
Mirage Kitten is an Iran-linked cyberespionage group, also tracked as UNC1549, Smoke Sandstorm and Nimbus Manticore, that has targeted the aerospace, aviation, defence and telecommunications sectors of the Middle East and Africa since at least 2022. Its historical tooling has been native malware written in C, C++ and Go, typically deployed through DLL search-order hijacking, and Kaspersky's July reporting on the group's NightLedger backdoor and ArcBridge and BridgeHead tunnelling tools fitted that pattern.
The September research breaks that pattern. NodeRabbit is a Node.js remote access trojan with three variants recovered from systems in Afghanistan, Egypt and Ethiopia, and PollCat is a separate RAT in obfuscated JavaScript, both delivered inside trojanised coding challenges and both designed to operate across Windows, Linux and macOS. Kaspersky attributes the activity to Mirage Kitten with high confidence on the strength of victimology, the group's characteristic Azure Websites and Cloudflare-fronted infrastructure, and close structural overlap between PollCat and the earlier Retrograde/MiniFast backdoor. PollCat and Retrograde/MiniFast both treat an HTTP 400 response as a successful handshake, extract a socketId for use as a session token, and poll for tasks using closely aligned GET request patterns. They also share a default beacon interval of 120 seconds with a five-second jitter value, and reuse several command identifiers, including two that PollCat declares but never implements.
Initial access relies entirely on social engineering of individual engineers. A fake recruiter, in one publicly described case posing as a talent acquisition specialist at a major technology company, contacts the target on LinkedIn, offers a role and sends a link to a technical assessment hosted in an Amazon S3 bucket. The NodeRabbit lure, a TaskFlow task-management app built on Express, React and Vite, ships with a README that imposes a three-hour limit, forbids the use of AI assistants and states that server.js is bug-free and must not be modified, which is precisely the one file the attackers altered. Its first line imports a trojanised npm package, colorised_terminal or pretty-log, pinned to version 2.1.0 and bundled directly in node_modules rather than published to the registry, which launches the implant from a hidden .cache directory as a detached background process.
The PollCat lure, a React challenge named RankChallenge-react, wraps the same pressure in a login flow, a one-hour session gated by a six-digit OTP that the recruiter supplies and which purports to rotate every 30 seconds. PollCat starts during application load, before any code is entered, and continues running whether or not validation succeeds. A valid code simply spawns a second instance and triggers persistence. In both cases the timer is aimed at the candidate's judgement rather than their schedule, leaving no room to verify that the recruiter exists.
NodeRabbit's three variants show steady operational maturation. The first derives a 32-character agent identifier from a hash of host attributes, uses a fixed localhost port as a single-instance mutex, persists as a fake Microsoft Edge Update component and communicates with a rotating chain of Azure-hosted C2 servers over AES-256-GCM-wrapped JSON, supporting eleven commands covering shell execution, file operations, network enumeration and arbitrary Node.js script execution. The second adds sandbox checks for low memory, low CPU count, short uptime and analyst usernames, sends benign HEAD requests to Google, Microsoft and Cloudflare before exiting if it suspects analysis, implements corporate proxy discovery including PAC and WinHTTP settings and delegates NTLM and Negotiate challenges to curl.exe, and masquerades as Intel Driver & Support Assistant with a daily scheduled task.
The third, launched via the same pretty-log package, expands the command set to 23 and introduces the campaign's most distinctive feature, persistence through the developer's own workflow. On command it installs a fake VS Code extension named GitHub Copilot Helper, activated on StartupFinished and borrowing a trusted publisher name from local extension metadata, and attempts to disable Workspace Trust. Separately it scans recent VS Code workspaces and common locations such as ~/projects and ~/source for Git repositories and appends a marked launcher to the post-merge and post-checkout hooks, so that a later Git operation can relaunch the implant if the referenced Node runtime and payload remain available. It also harvests account addresses from Outlook OST and PST files and can replace its C2 chain in memory and on disk.
PollCat, for its part, polls every two minutes over a binary command protocol with 22 declared commands including chunked file upload, arbitrary JavaScript evaluation and a SYSTEM_CHECK routine that inventories running processes and enumerates program directories against a hardcoded list of 24 security vendor names. Infrastructure relied heavily on Azure Websites and Cloudflare-backed domains, with several actor-controlled domains registered through Namecheap. In some cases the operators embedded the targeted organisation's name in the Azure subdomain so that beaconing resembled routine business traffic from an employee device.
Defence should start from the premise that an unsolicited coding assessment is untrusted software, and that the campaign targets the individual rather than the corporate perimeter. Engineers should be instructed never to execute unsolicited recruitment assessments on a corporate device, regardless of how credible the recruiter or hosting service appears. Any technical test should be executed in a disposable virtual machine or container with no access to corporate credentials, SSH keys or source repositories.
Application allow-listing and EDR policy should treat node.exe spawning detached processes from a node_modules/.cache path, or a copy of node.exe renamed to nodew.exe or IntelDSA.exe with its PE subsystem patched, as high-severity events, and alerting should cover new scheduled tasks and Run keys named MicrosoftEdgeUpdate, IntelDriverSupportUpdate or NetSync_, LaunchAgents named com.microsoft.edgeupdate, com.intel.dsa.helper or com.harsh.requireobject, and @reboot cron entries pointing at Node scripts. Because the third variant persists inside the development toolchain, defenders should periodically audit VS Code extension directories for unsigned extensions claiming trusted publishers and scan .git/hooks in corporate repositories for the shepherd-persist marker or any hook that launches a Node process. Network controls should flag outbound HTTPS to azurewebsites.net subdomains that no internal application owns, and where proxies enforce authentication, unexpected curl.exe invocations with --proxy-anyauth are a strong signal.
Finally, the Outlook harvesting capability could support target discovery and follow-on phishing, while the OTP-gated lure demonstrates the operators’ use of convincing, time-pressured social engineering. An engineer who has executed one of these challenges should therefore be treated as a potential initial-access point and investigated accordingly.
Community Detection Opportunities
MDE_DeviceNetworkEvents_MirageKitten_NodeRabbit_loopback_single-instance_listener - Hunts the reported NodeRabbit loopback listener behaviour: fixed port 48739 for the first variant and derived listener ports between 41984 and 46983 for the second variant.
DeviceNetworkEvents | where Timestamp >= ago(30d) | where ActionType has "Listening" | where LocalIP in ("127.0.0.1", "::1") | where LocalPort == 48739 or LocalPort between (41984 .. 46983) | where InitiatingProcessFileName in~ ("node.exe", "nodew.exe", "IntelDSA.exe", "node") or InitiatingProcessCommandLine has_any ("msedge_update.js", "idriver_support.js", "node_modules", ".320697f1") | project Timestamp, DeviceName, ActionType, LocalIP, LocalPort, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessFolderPath
BigDiskBuster: Starving Microsoft Defender of Updates
BigDiskBuster is a proof-of-concept tool published to GitHub on the 19th of September by the researcher known as NightmareEclipse, MSNightmare and Chaotic Eclipse. It is the latest instalment in a dispute that began in April, when the researcher started publishing Windows zero-days and exploit code without prior disclosure. The releases followed a succession of proof-of-concept disclosures, including RoguePlanet in June, LegacyHive in July, ShieldBreak in August and ShieldCrash earlier in September, alongside exploits affecting products from CrowdStrike, Nvidia, Avast and Kaspersky. Several of the earlier Windows bugs have since been patched, and some were exploited in the wild after their public release, which is the main reason BigDiskBuster deserves attention despite being, by the author's own admission, buggy and in need of a rewrite. As of the 28th of September 2026, there is no CVE, Microsoft advisory specifically addressing BigDiskBuster, confirmed patch or vendor workaround. The claim that it works on every supported Windows version has also not been independently tested.
The technique is a local denial of service against Defender's update pipeline rather than a bypass of its detection logic, and it requires code execution on the host. It is a post-compromise defence-evasion tool rather than an entry point. According to analysis of the published proof of concept, BigDiskBuster monitors the system volume for new directories appearing under ProgramData\Microsoft\Windows Defender\Platform and the Definition Updates path, which is where Defender stages platform and security intelligence updates. When one appears, it checks remaining free space and creates a hidden, delete-on-close temporary file under the user's Temp directory sized to consume nearly all of it, spinning up additional worker threads to reclaim any capacity that frees up as the installer modifies or removes files. In parallel it opens MRT.exe, the Malicious Software Removal Tool binary, with restrictive sharing so that other processes cannot obtain write or delete access while the handle is held, potentially interfering with replacement or servicing of MRT.exe, alongside the disk-exhaustion technique used against Defender’s update staging. Once the monitored update directory disappears, the tool treats the update as failed, closes its handles and releases the space, leaving nothing obviously amiss on disk.
The screenshot accompanying the release shows Windows Security reporting a protection definition update failure with error 0x80070643, though that is a generic installer error with many benign causes and cannot on its own be taken as evidence of tampering. The practical result is an endpoint whose Windows Security dashboard reports protection as active while the engine and signatures quietly age, an outcome that is arguably more useful to an intruder than an outright kill because protection can remain enabled while its platform and intelligence content become stale, potentially attracting less immediate attention than the antivirus service being disabled outright.
Defensively, BigDiskBuster is noisy in ways that tamper protection alone will not catch, so the value lies in correlating signals that are each individually unremarkable. Free space on the system drive collapsing to near zero and then recovering within minutes, coinciding with a Defender update attempt, is the primary indicator, and endpoint telemetry that records hidden file creation in user Temp directories with unusually large allocations should be alerted on. Persistent open handles to MRT.exe from a non-Microsoft process are a second, and repeated Defender update failures, or simply the absence of successes, are a third. Microsoft logs signature update outcomes to the Microsoft-Windows-Windows Defender/Operational channel, where Event ID 2000 records a successful security intelligence update, so a fleet-wide hunt for hosts that have not logged Event ID 2000 within the organisation’s expected update interval can identify potentially stale protection.
A 24-hour threshold may be appropriate for frequently connected endpoints but should be adjusted for the organisation’s update cadence and intermittently connected devices. Organisations should also compare reported engine and signature versions against the current release through their management tooling rather than trusting the endpoint's own health status and treat any host that has silently fallen behind as a candidate for investigation rather than a servicing ticket. Where a host is confirmed affected, responders should preserve process and file-handle telemetry before terminating the process, recover disk capacity, force a trusted update via Windows Update, WSUS or MpCmdRun.exe -SignatureUpdate, and then, because the tool has no initial access capability of its own, work backwards to establish how the code came to be running in the first place. Given the researcher's stated intention to continue publishing and the track record of post-release exploitation, this is a detection that should be built and tested ahead of any confirmed abuse rather than in response to it.
Community Detection Opportunities
MDE_DeviceFile_BigDiskBuster_Correlate_Code-Derived_temp_File_Behaviour_with_Defender_Failures - Correlate code-derived temp-file behaviour with Defender failures.
let HuntStart = ago(14d);
let GuidFileName =
@"^\{[0-9A-Fa-f]{8}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{4}-[0-9A-Fa-f]{12}\}$";
let SuspiciousTempActivity =
DeviceFileEvents
| where Timestamp >= HuntStart
| where FolderPath endswith @"\Temp"
or FolderPath contains @"\Temp\"
| where FileName matches regex GuidFileName
| extend Host = tolower(tostring(split(DeviceName, ".")[0]))
| summarize
TempFirstSeen = min(Timestamp),
TempLastSeen = max(Timestamp),
TempEventCount = count(),
UniqueGuidFiles = dcount(FileName),
GuidFiles = make_set(FileName, 20),
FileActions = make_set(ActionType, 20)
by
Host,
DeviceName,
InitiatingProcessAccountName,
InitiatingProcessFileName,
InitiatingProcessFolderPath,
InitiatingProcessCommandLine,
InitiatingProcessId,
InitiatingProcessCreationTime,
InitiatingProcessSHA1;
let DefenderUpdateFailures =
WindowsEvent
| where TimeGenerated >= HuntStart
| where Provider == "Microsoft-Windows-Windows Defender"
| where EventID in (2001, 2003, 2006)
| extend Host = tolower(tostring(split(Computer, ".")[0]))
| project
Host,
DefenderFailureTime = TimeGenerated,
Computer,
EventID,
EventData;
SuspiciousTempActivity
| join kind=inner DefenderUpdateFailures on Host
| where DefenderFailureTime between
(TempFirstSeen - 5m .. TempLastSeen + 15m)
| project
DefenderFailureTime,
DeviceName,
EventID,
TempFirstSeen,
TempLastSeen,
TempEventCount,
UniqueGuidFiles,
GuidFiles,
FileActions,
InitiatingProcessAccountName,
InitiatingProcessFileName,
InitiatingProcessFolderPath,
InitiatingProcessCommandLine,
InitiatingProcessId,
InitiatingProcessSHA1,
EventData
| order by DefenderFailureTime desc
Bridewell CSIRT Detection Rules & Analytics
| Detection Analytic Concept | Category |
|---|---|
| MDE_DeviceProcessEvents_MirageKitten_Node.js_execution_from_reported_trojanized_package_paths | Execution |
| MDE_DeviceFileEvents_MirageKitten_NodeRabbit_Intel_DSA_masquerade_persistence-variant_2 | Persistence and Defence Evasion |
| MDE_DeviceFileEvents_MirageKitten_Reported_coding_challenge_archive_IOC | Initial Access |
| MDE_DeviceFileEvents_MirageKitten_PollCat_NetSync_persistence_under_AppData_Microsoft_Network | Persistence |
| MDE_DeviceProcessEvents_MirageKitten_NodeRabbit_proxy_authentication_through_curl.exe | Command and Control |
| MDE_DeviceProcessEvents_MirageKitten_NodeRabbit_WSL_launcher_VBS_persistence | Persistence and Execution |
| MDE_DeviceRegistryEvents_MirageKitten_NodeRabbit_EdgeUpdate_Run_Key_Persistence_Mechanism_variant_1 | Persistence and Defence Evasion |
| MDE_DeviceNetworkEvents_MirageKitten_NodeRabbit/PollCat_C2_Connections | Command and Control |
| MDE_BigDiskBuster_triage_Exact_Demonstration_Binary | Execution |
| MDE_WindowsEvents_BigDiskBuster_MRT.exe_Detection_Opportunity | Defence Evasion |
| MDE_WindowsEvent_BigDiskBuster_Defender_Platform/Security_Update_Failure | Defence Evasion |
| MDE_DeviceFileEvents_BigDiskBuster_GUID-only_Temporary_Files_Matching_BigDiskBuster_Behaviour | Defence Evasion and Impact |
| MDE_DeviceFileEvents_BigDiskBuster_Multiple_GUID_Temp_Allocations_by_Single_Process | Defence Evasion and Impact |