|ThreatClaw

New ThreatClaw Coverage: Exploited CVEs, Ransomware Evasion & BYOVD Risks

This week’s ThreatClaw update expands detection for 4 exploited CVEs, ransomware staging techniques, BYOVD attacks, and 258 new Sigma rules targeting enterprise threats.

T1003T1003.001KEVDétection

Exploited CVEs Now Detected: Critical Enterprise Risks

This week, ThreatClaw expanded detection coverage for four newly exploited vulnerabilities in enterprise software, reinforcing defenses against advanced threat actors leveraging these flaws for initial access and lateral movement:

  • CVE-2026-45659 (Microsoft SharePoint Server): Exploitation enables authenticated attackers to execute arbitrary code, often leading to privilege escalation (T1068) and persistence (T1546). SharePoint’s integration with Active Directory amplifies risk, as compromised instances can facilitate domain-wide attacks.

  • CVE-2026-48558 (SimpleHelp): Remote support tools like SimpleHelp are frequent targets for abuse, with exploitation allowing threat actors to deploy malware (T1105) or establish persistence (T1547.001) under the guise of legitimate support activity.

  • CVE-2026-12569 (PTC Windchill/FlexPLM): Vulnerabilities in PLM systems can expose sensitive intellectual property and supply chain data. Exploitation may lead to data exfiltration (T1048) or sabotage (T1486), with attackers targeting design files and proprietary documentation.

  • CVE-2026-20230 (Cisco Unified Communications Manager): VoIP and UC systems are critical infrastructure; exploitation can enable eavesdropping (T1040), call fraud, or serve as a pivot point for internal network compromise (T1021.006).

Ransomware and Evasion: New Detection for Staging and Bypass Techniques

ThreatClaw now detects LockBit affiliate pre-encryption staging (T1486, T1490), with a focus on APAC-targeted campaigns. This technique involves preparing victim environments for mass encryption by disabling security controls (T1562.001) and clearing recovery options (T1490) prior to deployment. Additionally, coverage includes:

  • Safe Mode boot configuration via bcdedit (T1562.009): Ransomware operators increasingly force systems into Safe Mode to evade EDR solutions, a tactic observed in recent high-impact attacks. Detection now spans both safeboot and recoveryenabled tampering (T1490).

  • Boot recovery tampering (T1490): Attackers manipulate boot settings to hinder system restoration, complicating incident response and recovery efforts.

  • In-memory AMSI tampering via PowerShell (T1562.001): Threat actors bypass AMSI (Antimalware Scan Interface) to execute malicious scripts undetected, a technique commonly paired with reflective code loading (T1620).

BYOVD and Driver Abuse: Escalation and Persistence Risks

Bring Your Own Vulnerable Driver (BYOVD) attacks remain a persistent threat, with ThreatClaw now detecting:

  • Known vulnerable drivers loaded from user-writable paths (T1068, T1543.003): Attackers exploit signed but vulnerable drivers to escalate privileges or disable security controls. Detection covers both standalone driver loads and kernel service creation (T1543.003).

  • EDR-killer drivers (T1068): Threat actors deploy drivers designed to terminate or blind security tools, often as a precursor to ransomware deployment or data exfiltration.

Living-off-the-Land and Lateral Movement: Expanded Coverage

Advanced threat actors increasingly abuse legitimate tools for stealthy operations. New detection includes:

  • Volt Typhoon techniques: Coverage for netsh portproxy internal tunneling (T1090.001) and WMI remote process creation (T1047), both used for command-and-control and lateral movement in targeted intrusions.

  • Active Directory enumeration: Detection for dsquery (T1087.002), nltest (T1482), and SharpHound collector artifacts (T1069.002), which threat actors use to map domain structures and identify high-value targets.

  • Cloud environment reconnaissance: Azure and AWS CLI usage from Windows endpoints (T1526), indicating attackers probing cloud resources for misconfigurations or sensitive data.

  • DLL sideloading and hijacking: Expanded coverage for sideloading via signed binaries (T1574.002) and hijacking of commonly abused DLLs (T1574.001), including amsi.dll loaded from user-writable paths (T1562.001).

Malware Families and Post-Exploitation Tools

New YARA rules enhance detection for 21 malware families and post-exploitation tools, including:

  • ShadowPad: Persistence via updater-themed scheduled tasks (T1053.005), a technique used by advanced threat actors for long-term access.

  • PlugX: Persistence in nested ProgramData directories (T1547.001), a hallmark of this modular malware family.

  • RedLine Stealer: Detection for credential harvesting and data exfiltration, often deployed via phishing or exploit kits.

  • AD CS abuse tools: Coverage for Certipy and ESC1 certificate requests with arbitrary SANs (T1649), enabling attackers to impersonate privileged accounts.

Call to Action

ThreatClaw Premium subscribers receive real-time rule updates to stay ahead of emerging threats. Contact your account manager to enable automated deployment and ensure continuous protection across your enterprise.

Related articles