
Threat Intelligence Brief: Escalating Exploitation of Network Infrastructure and Cloud Identity
Analysis of recent zero-day campaigns targeting MikroTik, F5 BIG-IP, and Microsoft cloud authentication mechanisms
Recent intelligence indicates a surge in sophisticated exploitation targeting network edge devices and cloud identity. Threat actors are increasingly leveraging memory-resident malware and passkey phishing to bypass traditional security controls.
Executive Takeaway — TL;DR
- Category:
- Technical Deep Dive
- Author:
- Encrygma Intelligence Desk
- Published:
- 2026-09-15
- Read Time:
- 8 min
- Pages:
- 4
- Access:
- Public
- Key Terms:
- Zero-Day, Infrastructure Security, Identity Theft, Memory-Resident Malware, APT, Cloud Security
Executive Summary
The current threat landscape is characterized by a rapid escalation in the exploitation of network edge devices and sophisticated identity-based attacks. Over the past 72 hours, intelligence confirms that threat actors are actively weaponizing critical vulnerabilities in MikroTik routers and F5 BIG-IP systems to maintain persistence. Furthermore, the emergence of passkey phishing campaigns targeting Microsoft cloud accounts highlights a critical shift in adversary tactics, moving away from traditional credential harvesting toward more resilient authentication bypass methods.
Background & Context
As of September 15, 2026, the cybersecurity environment remains volatile. Following the record-breaking Patch Tuesday on September 9, where Microsoft addressed 964 vulnerabilities, threat actors have intensified their efforts to exploit unpatched systems. The focus has shifted heavily toward infrastructure components that serve as gateways to enterprise networks. The exploitation of MikroTik routers, in particular, demonstrates a concerted effort to compromise the perimeter, while the use of memory-resident web shells in F5 BIG-IP devices underscores a trend toward fileless malware designed to evade standard endpoint detection and response (EDR) solutions.
Analysis
The recent activity surrounding MikroTik routers involves a dangerous chain of vulnerabilities: CVE-2026-67276 (SSH authentication bypass) and CVE-2026-86060 (SSH session privilege escalation). By chaining these, attackers can achieve full system control without valid credentials. This is not an isolated incident; it reflects a broader trend of targeting network appliances that are often overlooked in standard patch management cycles.
Simultaneously, the use of memory-resident web shells in F5 BIG-IP environments represents a significant challenge for defenders. By operating entirely in memory, these shells avoid writing files to the disk, rendering traditional signature-based antivirus ineffective. This technique requires advanced memory forensics and behavioral monitoring to detect.
On the identity front, the rise of passkey phishing targeting Microsoft cloud accounts marks a maturation of social engineering. Attackers are no longer just seeking passwords; they are targeting the very mechanisms designed to replace them, exploiting user trust in modern authentication flows.
Key Findings
- Infrastructure Weaponization: Active exploitation of MikroTik RouterOS via SSH authentication bypass and privilege escalation chains.
- Fileless Persistence: F5 BIG-IP systems are being targeted with memory-resident web shells to evade disk-based detection.
- Identity Evolution: Shift toward passkey phishing campaigns to hijack Microsoft cloud accounts, bypassing traditional MFA.
- Patch Management Gap: Despite record-breaking patches, the speed of weaponization for edge device vulnerabilities continues to outpace organizational remediation efforts.
Attribution & Confidence
While specific attribution for the latest MikroTik and F5 campaigns remains under investigation, the sophistication of the exploit chains suggests the involvement of well-resourced threat actors. We maintain high confidence that these campaigns are designed for long-term espionage and network persistence rather than opportunistic ransomware deployment. The Lazarus Group remains a primary suspect in recent high-profile zero-day exploits, though the current infrastructure attacks may involve multiple distinct threat clusters.
Defensive Recommendations
- Immediate Patching: Prioritize the deployment of security updates for all edge devices, specifically MikroTik and F5 BIG-IP appliances.
- Memory Forensics: Implement advanced EDR solutions capable of scanning active memory processes for unauthorized web shells and anomalous code execution.
- Identity Hardening: Transition to phishing-resistant MFA (e.g., FIDO2/WebAuthn) and conduct rigorous audits of Microsoft cloud account access logs for suspicious passkey registration events.
- Network Segmentation: Isolate management interfaces for network infrastructure from the public internet to reduce the attack surface.
Outlook
We anticipate that the trend toward memory-resident malware and identity-based attacks will continue to accelerate through Q4 2026. As organizations harden their endpoints, attackers will increasingly focus on the 'soft underbelly' of the network—the edge infrastructure and the cloud identity provider. Defenders must move beyond perimeter-based security and adopt a zero-trust architecture that assumes the network edge is already compromised.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
