top of page

Cyber Security Report - August 2026

11 minutes ago
15 min read

Research by OSINT Monitoring Team, NTT Security Japan K.K



Table Contents


This report selects and summarizes three particularly important topics from various incidents and events related to information security that occurred during August 2026, as well as the changes in the surrounding environment. The main points of each topic are as follows.


Chapter 1: 'U.S. Government to Establish Cybercrime Attack System by Private Companies'

  • On August 12, 2026, the U.S. government issued a presidential memorandum directing the creation of a new system under government supervision that allows private companies to participate in offensive cyber operations against cybercriminal organizations.

  • While this system is expected to enhance private companies' ability to respond by leveraging their technical capabilities and expertise, practical challenges such as the burden of participation requirements and the responsibility under international law have also been pointed out.

  • In China and Russia, cases have been pointed out where private entities such as companies and cybercriminal organizations are involved in state-run cyber activities, while the United States is institutionalizing private company involvement and attempting to operate it under legal grounds and regulatory frameworks, drawing attention to these trends.


Chapter 2: 'CaptiveCrunch' Public Wi-Fi Abuse Attack by Russian APTs

  • Microsoft has reported on the attack campaign "CaptiveCrunch," carried out by the Russian-based cyberattack group Storm-2945.

  • CaptiveCrunch is a cyber espionage activity that exploits the authentication infrastructure (CaptivePortal platform) of public Wi-Fi environments such as hotels and conference venues, involving credential theft and malware deployment.

  • Measures based on zero trust are required, such as not trusting external networks such as public Wi-Fi, and by assuming that "the breach may already be compromised."


Chapter 3: 'Communication Equipment Risks Indicated by Backdoor Incidents of Chinese Routers'

  • In August 2026, U.S. security company VulnCheck released research results showing that multiple routers manufactured by Chinese manufacturer Zbtlink (Shenzhen Zhibotong Electronics) have backdoors called "ENDLESSDOORS" built into multiple routers from shipment.

  • This router spontaneously communicated with external servers via backdoors and had the ability to execute commands sent from the destination server with root privileges.

  • This case demonstrated that the risks to communication equipment may not be fully understood by addressing vulnerabilities or taking measures against exploitation alone. Going forward, evaluations will become important not only for product features and price, but also for the reliability of suppliers and their development and maintenance systems.


U.S. Government to Establish Cybercrime Attack System for Private Companies


1.1. Overview


On August 12, 2026, the White House issued a presidential memorandum directing the creation of a new system allowing private companies to conduct aggressive cyber operations against cybercrime organizations under government supervision.[1]


This system allows U.S. government-approved private companies to participate in cyber surveillance and sabotage activities targeting cyber-enabled transnational criminal organizations (CE-TCO) that utilize cyber technology. Efforts to institutionally incorporate private companies into government-led offensive cyber operations are rare.[2]


It is also drawing attention from the perspective of future public-private partnerships and the nature of cyber response capabilities.


1.2. Framework of the System and Background of Its Establishment


Background of Establishment

As cybercrimes by CE-TCOs—such as ransomware, online fraud, and phishing—expand as threats to U.S. citizens, businesses, and national security, the private sector's technological capabilities and innovation have not been fully utilized, which is the background of this system. In fact, by 2025, U.S. consumers have reported losses exceeding $20.8 billion due to cybercrime.[3]


The U.S. government rushed to strengthen its countermeasures. Furthermore, regarding ransomware damage, the number of reports to the FBI alone has increased by more than 20% since 2023, but it has been pointed out that these incidents represent only a portion of the total number of actual damages.[4]


This indicates that it is not easy to fully grasp and address cybercrime damage. In response to these circumstances, there was a growing need for a response system that leveraged not only government agencies but also private companies. In March 2026, Presidential Decree No. 14390 was issued, outlining policies for utilizing private companies.[5]


This memorandum concretizes that policy and establishes the institutional framework.[1]


Framework of the System and Supervisory Structure

Companies participating in this new system can conduct "Cyber Surveillance Operations" aimed at gathering information, and "Cyber Effects Operations" aimed at disrupting or disrupting systems or infrastructure.[1] The target is CE-TCO, which the memorandum defines as foreign organizations targeting the U.S. government, Americans, and U.S. interests.[1] However, national agencies and threat actors suspected of involvement (such as APT groups under state-directed or supported orders) are not included in this system.[1]


The system is operated by the National Coordination Center and operates under the supervision of the Department of Justice and the Department of Homeland Security.[1] Furthermore, this system does not grant private companies unlimited attack authority.[1]


In particular, strict restrictions are imposed on operations that may cause death or serious injury, or those that may constitute the use of force under international law.[1]Participating companies are required to meet technical and safety requirements, as well as deposit a minimum deposit of $1 million.[1] Additionally, the memorandum instructs relevant authorities to set eligibility criteria so that not only large enterprises but also "smaller and more agile companies" can participate.[1]


Upcoming Schedule

The memorandum stipulates that within 60 days of signing, the operational procedures and participation requirements for the system must be established.[1]Going forward, the criteria for selecting participating companies and details of the operational system are expected to become clear, and attention will be focused on the specific methods of the system's operation.


1.3. Expected Effects and Challenges


Although the forms of abuse of residential proxies are diverse, based on confirmed cases, they are classified into the following three categories.


Expected Effects

With the introduction of this system, it is expected that the scope of response to numerous ransomware groups and fraud organizations that government agencies alone would find difficult to respond to, by leveraging private companies' technical capabilities and human resources, will be expanded. In particular, leveraging the expertise of private companies with expertise in tracking threat actors and analyzing infrastructure could enable faster identification of cybercriminal organizations' operational bases and the implementation of disruption measures against them.


Furthermore, promoting public-private information sharing is expected to enhance the ability to collect and analyze threat information related to cybercrime. Furthermore, the participation of diverse private companies, including small and agile firms, may promote the adoption of new technologies and insights.


Anticipated Issues and Issues

This system does not allow so-called "hackbacks," where private companies independently and freely retaliate; in practice, it is closer to a mechanism that incorporates private companies into government-led aggressive cyber operations.[2]


Therefore, the discretion of participating companies may be limited. While participation from small and startup companies is expected to expand, companies with limited financial resources and management systems face significant burdens such as a minimum $1 million deposit system and various screening requirements. Therefore, which companies will actually be able to participate is expected to depend on the detailed participation requirements and operational methods to be announced in the future. Depending on the results, participating companies may be biased toward certain major corporations or existing government contractors. Furthermore, since private companies participate in aggressive cyber operations under government control, there is a risk of international legal responsibility and diplomatic friction. Additionally, there is a risk that stakeholders of participating companies may face legal actions such as prosecution or detention by governments of countries targeted by cyber operations.[6]


Comparison with China and Russia

In China and Russia, there have also been reports of private entities such as companies and cybercrime organizations being involved in state cyber activities. In China, private companies and contractors have traditionally been said to support national cyber operations, and the U.S. Department of Justice has cracked down on and prosecuted private company members involved in Chinese government-linked hacker activities.[7], [8]


In Russia, state-sponsored cyber activities such as APT groups continue to be confirmed.[9] There have also been reports of cybercriminal organizations suspected of having ties to state-of-the-state organizations. For example, the leader of the ransomware group Evil Corp allegedly received operational favors in exchange for providing confidential information to the Russian Federal Security Service (FSB).[10]Additionally, the ransomware group Conti has been linked to the FSB due to leaks of internal chats.[11]


Furthermore, Conti was analyzed to have operated as an organization resembling a company, with clear role divisions and hierarchical structures.[12] Additionally, it has been confirmed that the cybercrime group FIN7 operated multiple frontline companies and conducted recruitment activities for security personnel under the guise of cybersecurity firms.[13], [14], known as cases where cybercriminal organizations operate under the guise of companies.


In the United States, contracts with private companies providing offensive cyber capabilities and procurement have tended to prioritize high reliability and secrecy, giving large defense contractors an advantage and making it difficult for small and startup companies to enter government projects.[15],[16]Meanwhile, in China, private companies—from large corporations to small and medium-sized enterprises - have established systems to support cyber activities, and private companies are said to be involved not only in providing offensive cyber capabilities and technologies but also in the actual execution of cyber operations.[16]There is also a view that these differences have led to a decline in U.S. mobility and strategic advantage compared to China[16]。 The aforementioned "standard allowing not only large corporations but also small, agile companies to participate" aims to correct these traditional structural issues, broaden the base for private sector utilization, and incorporate diverse corporate capabilities.



1.4. Summary

This system is a new public-private partnership model that leverages private companies' advanced technological capabilities and knowledge of cyber threats to enhance their ability to respond to CE-TCO. Meanwhile, the system is currently at the 'establishment instruction' stage, and the specific operational procedures and announcement of participating companies will still be underway. While private actors have been pointed out as involved in state cyber activities in China and Russia, the U.S. institutionalizes private company involvement and seeks to clarify legal grounds and oversight frameworks. In Japan as well, since active cyber defense laws limit the implementation of proactive cyber defense measures to the government [17], the results of the system's operation in the U.S. may serve as a reference case in discussions about the division of roles between public and private sectors.

[1] Source: The White House 'Expanding Capabilities to Combat Transnational Cyber-Enabled Crime'https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/

[2] Source: Wiley, 'Navigating the New Presidential Memorandum on Transnational Cyber Enabled-Crime'https://www.wiley.law/alert-Navigating-the-New-Presidential-Memorandum-on-Transnational-Cyber-Enabled-Crime

[3] Source: The White House 'Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled Crime'https://www.whitehouse.gov/fact-sheets/2026/08/fact-sheet-president-donald-j-trump-expands-capabilities-to-combat-transnational-cyber-enabled-crime/

[4] Source: Homeland Security Committee 'Testimony of Cynthia Kaiser (Halcyon Ransomware Research Center)' (on a joint hearing "Online Scams, Crypto Fraud, and Digital Extortion: An Examination of Ransomware Research Center" How Transnational Criminal Networks Target Americans")https://homeland.house.gov/wp-content/uploads/2026/04/2026-04-21-BSECIP-Hearing.pdf

[5] Source: The White House 'Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens'https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/

[6] Source: TechCrunch 'In a first, US will allow some private firms to carry out cyberattacks'https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks/

[7] Source: U.S. Department of Justice 'Justice Department and FBI Seize Platforms Operated and Used by China State-Sponsored Hackers to Target U.S. Critical Infrastructure'https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers

[10] Source: The Record 'Eduard Benderskiy: Western authorities link Russian intelligence officer to Evil Corp cybercrime empire'https://therecord.media/evil-corp-cybercrime-eduard-benderskiy-russian-intelligence

[11] Source: ProPublica 'Why It's Hard to Sanction Ransomware Groups'https://www.propublica.org/article/ransomware-russia-ukraine-sanctions-ofac-conti

[12] Source: CrimRxiv 'Inside the Leak: Exploring the Structure of the Conti Ransomware Group'https://www.crimrxiv.com/pub/i6n43dnf/release/1

[13] Source: U.S. Department of Justice 'Three Members of Notorious International Cybercrime Group "Fin7" in Custody for Role in Attacking Over 100 U.S. Companies'https://www.justice.gov/usao-wdwa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacking-over

[14] Source: The Record 'FIN7 hacker trialed in Russia gets no prison time'https://therecord.media/fin7-hacker-trialed-in-russia-gets-no-prison-time

[15] Source: CSIS 'The Presidential Memo on Combating Transnational Cybercrime: Implications for Industry and Government'https://www.csis.org/analysis/presidential-memo-combating-transnational-cybercrime-implications-industry-and-government

[16] Source: Atlantic Council 'Crash (exploit) and burn: Securing the offensive cyber supply chain to counter China in cyberspace'https://www.atlanticcouncil.org/in-depth-research-reports/report/crash-exploit-and-burn/

[17] Source: Cabinet Secretariat National Cyber Management Office, 'On the Cyber Response Capability Enhancement Act and the Corresponding Development Act' (Cabinet Office)https://www.cao.go.jp/cybersecurity/pdf/setsumei.pdf


Russian APT Exploits Public Wi-Fi Attack 'CaptiveCrunch'



2.1. Overview

Microsoft reported on the attack campaign "CaptiveCrunch" carried out by the Russian-based cyberattack group Storm-2945. CaptiveCrunch is a cyber espionage activity that exploits the authentication infrastructure (CaptivePortal platform) of public Wi-Fi environments such as hotels and conference venues, involving credential theft and malware deployment.[18]


Picture of Microsoft's CaptiveCrunch report
Figure 1: Microsoft's CaptiveCrunch report


2.2. About CaptiveCrunch

CaptiveCrunch has been confirmed since around May 2026. Attackers can steal Microsoft 365 credentials or authentication tokens from users accessing the captive portal platform, gain unauthorized access to cloud environments, or deploy malware, thereby securing access infrastructure that can be used for collecting and continuously monitoring sensitive information. Targets include officials in government, diplomacy, and defense, corporate executives who have access to confidential information, and users who frequently connect to public Wi-Fi during business trips or international conferences.[18]


Attack Methods


CaptiveCrunch attack flow
Figure 2: CaptiveCrunch attack flow (from Microsoft report)[18]

The attack is mainly carried out in the following steps:


(1) Infringing on the captive portal infrastructure of public Wi-Fi provided by hotels and other facilities.This allows users connected to the Wi-Fi to operate their communications.


(2) Using compromised captive portal infrastructure, DNS responses and HTTP communications are tampered with, guiding users to websites managed by the attacker.

(3) The following attacks are executed on the destination site:


Credential theft

Fake login sites disguised as legitimate services such as Microsoft 365 appear. When users enter credentials, those information and valid authentication tokens are stolen and used for unauthorized access.


Malware infection

Fake sites are displayed, posing as Windows or web browser updates, security checks, or network connection repairs. When users download files or execute commands, their devices can become infected with malware, enabling attackers to steal files or control them remotely.


Screen prompting Wi-Fi users to operate malware
Figure 3: Screen prompting Wi-Fi users to operate malware[18]

Fake Windows Update Screen
Figure 4: Fake Windows Update Screen[18]


2.3. About the Attackers

Storm-2945, operated by CaptiveCrunch, is considered a subgroup of the cyber intelligence organization Midnight Blizzard (APT29, Cozy Bear), which is suspected of having ties to Russia's Foreign Intelligence Service (SVR). Midnight Blizzard's main purpose is intelligence gathering in diplomatic, military, political, and technological fields that benefit the Russian government's security interests, and CaptiveCrunch is also considered part of such efforts. [18]


Examples of attacks by Midnight Blizzard include supply chain attacks that infiltrate backdoors into legitimate updates of the network management software "SolarWinds Orion," and account breaches targeting Microsoft executives[20].


2.4. Similar Case: 'Dark Hotel'

While CaptiveCrunch is gaining attention as a new threat, cyber espionage targeting hotel guests is nothing new. In 2014, an attack known as the 'Darkhotel' was reported. Attackers compromised the networks of luxury hotels, displaying fake software update screens to targeted government officials and corporate executives, and infected them with malware to steal information. While some investigative agencies have pointed out links between the attackers and South Korea, the attribution at the national level remains unclear.While Dark Hotel targeted a specific small number of individuals, CaptiveCrunch is notable for targeting users of compromised Wi-Fi environments on a broad scale. Although there are differences in targets and attack methods, both share the common trait of using the hotel's Wi-Fi environment as a foothold for attacks and exploiting the trust of those users.[21


2.5. Recommended Measures

The most reliable measure against CaptiveCrunch is to avoid using public Wi-Fi. However, if usage is unavoidable due to business trips or away from home, it is important to use a VPN that supports Full Tunnel mode, where all communication is transmitted via VPN, or to use SASE, a cloud-based security platform, to protect all traffic, including DNS communications.


In split tunnel configurations where only part of the communication is via VPN, DNS communications may be set to be sent to public Wi-Fi DNS servers, which may prevent DNS operations like CaptiveCrunch from redirecting users to fake sites. Even if multi-factor authentication (MFA) is implemented, unauthorized access can still be allowed if sessions or tokens are abused after verification.


Therefore, in addition to MFA, it is important to introduce FIDO2, a password-agnostic authentication method with phishing resistance, and to continuously verify the reliability of the source and device through conditional access.


2.6. Summary

CaptiveCrunch is an attack campaign that exploits third-party infrastructure such as hotels and conference venues that companies cannot directly manage, aiming to gather information through corporate account compromises and malware infections. This case also highlights the limitations of traditional security measures that focus solely on internal corporate networks and devices. The risk of public Wi-Fi being exploited for cyber intelligence activities in hotels has long been pointed out through attacks like the Dark Hotel, but CaptiveCrunch has once again demonstrated that this threat remains a real risk.


Going forward, it will be necessary to avoid trusting external networks such as public Wi-Fi, and to implement measures based on the premise of zero trust, which may already be compromised. It is also noteworthy that the attacks have shifted their focus to identity compromises such as Microsoft 365 accounts and authentication tokens. It is important to place identity at the center of defense rather than network boundaries, and to promote security strategies that assume that credentials and authentication tokens can be stolen.

[18] Source: Microsoft 'CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft'https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/

[20] Source: Reuters 'Microsoft says Russian state-sponsored hackers spied on its executives'https://www.reuters.com/technology/cybersecurity/microsoft-says-it-was-hacked-by-russian-state-sponsored-group-2024-01-19/

Communication device risks revealed by the backdoor case of a Chinese router


3.1. Overview

On August 5, 2026, U.S. security company VulnCheck released its findings that multiple routers manufactured by Chinese manufacturer Zbtlink (Shenzhen Zhibotong Electronics) have backdoors (mechanisms for unauthorized external access) built into multiple routers from the outset. According to VulnCheck, more than 100,000 devices in use worldwide may be affected by this incident.[22]


3.2. Overview of the Backdoor

VulnCheck named this backdoor "ENDLESSDOORS." At present, no fixed patches or other fixes have been provided by the manufacturer, and no fundamental solution has been provided. This incident has been assigned the common vulnerability identifier CVE-2026-66747.


How it works

On the routers under investigation, the backdoor was actually operating, communicating with external servers about every 35 seconds and connecting to China-related domains and IP addresses. Furthermore, this backdoor could execute commands sent from the destination server with root privileges without verifying its legitimacy, and also had the ability to launch an interactive shell (an environment where commands could be executed from outside).These communications were conducted without the router's user knowing, and the backdoor continued to operate even after shipment.


"ENDLESSDOORS" Communication Destination (C2 Server)
Figure 5: Zbtlink AX3000 Dual SIM 5G CPE WiFi 6 (Model No.: Z8102AX-2DSIM) and "ENDLESSDOORS" Communication Destination (C2 Server)

3.3. Concerns Surrounding Chinese-Made Communication Equipment

Until now, various concerns have been raised regarding Chinese-made communication equipment from the perspectives of security and supply chain risks. Many of these concerns future risks, such as the possibility of unknown vulnerabilities or backdoors, as well as whether the discovered vulnerabilities will be properly addressed.


One background to these concerns is China's vulnerability management system. In China, it is mandatory to report vulnerability information to government agencies, and there are certain restrictions on the publication of unresolved vulnerability information. *[23] As a result, since the government can monitor information before it is shared with individuals or companies using the product, concerns have been raised by Western countries about the transparency of vulnerability information management and disclosure processes.


In 2024, it was revealed that vulnerabilities in TP-Link routers were exploited by Chinese threat actors to build large-scale botnets. In this case, no direct evidence has been confirmed indicating TP-Link's concealment of information or prioritizing reporting to the Chinese government. However, the use of Chinese manufacturers' products for activities by Chinese threat actors was perceived as a renewed reminder of the longstanding security concerns surrounding Chinese-made telecommunications equipment. ※[24]


Trends in Regulations and Measures in Various Countries

In the United States, companies that have traditionally been considered national security concerns, such as Huawei and ZTE, are listed on the Federal Communications Commission (FCC) Covered List (a list of telecommunications devices and services deemed to pose national security risks). For communication equipment manufactured by these companies, the acquisition of new FCC certification (a certification required for selling wireless communication equipment in the U.S.) has been restricted, thereby suppressing sales and adoption in the U.S. market. [26]


Efforts to address such supply chain risks are also underway in countries outside the United States. In the UK, Huawei is positioned as a high-risk vendor and is working to eliminate it from 5G networks.

[27] On the other hand, in Japan, instead of designating specific companies, government procurement involves conducting risk assessments of products and services. ※[28]


3.4. Particularities of the Case

VulnCheck assessed that the backdoor built into Zbtlink routers was not just a design flaw but was likely intentionally implemented. This case differs in nature from previous vulnerability exploitation cases in that the product itself was said to have built-in functions enabling remote operation from outside.


3.5. Summary

This case illustrates that risks in communication devices may not be fully understood by addressing vulnerabilities or taking measures against exploitation alone, and demonstrated that risks arising from the design and manufacturing stages, which have been pointed out so far, can manifest as real phenomena beyond mere concerns. Furthermore, it was reaffirmed that the reliability of communication equipment depends not only on operational security measures but also on the entire supply chain, including design, manufacturing, and supply. Going forward, it is expected that evaluating not only product features and prices but also the reliability of suppliers and development and maintenance systems will become more important than ever.

[22] Source: VulnCheck 『ENDLESSDOORS Is Phoning Home. Pick Up.』https://www.vulncheck.com/blog/zbt-endlessdoors

[23] Source: Office of the Central Cyberspace Affairs Commission, 'Notice from the Ministry of Industry and Information Technology, Cyberspace Administration, National Cyberspace Administration, and Ministry of Public Security on Issuing the Regulations on the Management of Security Vulnerabilities in Network Products https://www.cac.gov.cn/2021-07/13/c_1627761607640342.htm

[24] Source: Select Committee on the CCP 'Letter to Commerce on Call for Investigation into Chinese Wi-Fi Routers in U.S. Vulnerable to CCP Hacking & Data Harvesting'https://chinaselectcommittee.house.gov/media/letters/letter-commerce-call-investigation-chinese-wi-fi-routers-us-vulnerable-ccp-hacking

[25] Source: Federal Communications Commission 'Prohibition on Authorization of "Covered" Equipment'https://www.fcc.gov/laboratory-division/equipment-authorization-approval-guide/equipment-authorization-system

[26] Source: Federal Communications Commission 'List of Equipment and Services Covered By Section 2 of The Secure Networks Act'https://www.fcc.gov/supplychain/coveredlist

[28] Source: National Cyber Administration Office, 'Agreement on Procurement Policy and Procedures for National Goods or Services Related to IT Procurement'https://www.cyber.go.jp/pdf/council/cs/dai21/21shiryou05.pdf

  1. Disclaimer

Please note that while we do our best to ensure that the content of this article is accurate, we do not guarantee the content and do not compensate for any damages or losses incurred as a result of the use of this article. If you have any inquiries such as typographical errors, content errors, or other points in the article, please contact us at the following address.


Inquiries

NTT Security Japan Corporation

Professional Services OSINT Monitoring Team

 
 
bottom of page