Search/ethereum
Vendor

ethereum

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
ethereum virtual machine
Connections
60 relationships
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
A malware-as-a-service (MaaS) campaign has combined ClickFix social engineering with the ErrTraffic delivery service and Cruciferra loader, giving attackers a way to distribute malware while disabling endpoint security processes. In a new advisory published earlier today, eSentire’s Threat Response Unit (TRU) described several ErrTraffic-generated ClickFix campaigns observed in late July 2026 that attempted to deliver Cruciferra. The loader is marketed on underground forums with features designed to kill antivirus and endpoint detection and response (EDR) processes. Turning Compromised Sites Into ClickFix Delivery Platforms The campaign began with compromised WordPress sites containing an obfuscated ErrTraffic JavaScript injection. The script used the Ethereum blockchain to resolve a command-and-control (C2) address before retrieving JavaScript for a fake Google reCAPTCHA, Cloudflare Turnstile or Blue Screen of Death (BSOD) lure. The lure copied a malicious PowerShell command to the victim's clipboard and instructed them to paste and run it. Additional PowerShell stages then used a legitimate Microsoft-signed binary to sideload the Cruciferra DLL, which used process hollowing to inject the Remus information stealer into a second Microsoft-signed binary, ServiceModelReg.exe. Compromised WordPress sites have previously been used to deliver ClickFix malware, but the eSentire campaign combined the technique with two separate MaaS offerings. ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator. Its use of blockchain-based infrastructure also allowed operators to rotate C2 domains without changing the JavaScript injected into compromised websites. Cruciferra’s EDR-killing package cost $1,200 per month and is marketed as a loader capable of disabling security products. The payload abused the signed vulnerable DCRCVDrv.sys driver to terminate security-related processes from the Windows kernel. eSentire found 145 process names configured for termination by default, most of them antivirus and EDR products. The driver is not currently known to Microsoft or LOLDrivers, meaning it will not be caught by the vulnerable driver blocklist. eSentire recommended blocking it directly by hash. The campaign showed how operators could combine separate MaaS products to outsource delivery, social engineering and defense evasion rather than developing each capability themselves.
infosecurity-magazine.comAug 19, 2026extracted
Six npm Packages Read C2 Addresses From Ethereum Wallet
Six npm packages have been found querying an attacker-controlled Ethereum wallet to work out where to fetch their next stage of malware, reading command-and-control (C2) addresses out of a blockchain transaction. Sonatype Research Labs identified the packages on August 10 and published its analysis the same day. All six carry the same payload, and Sonatype is tracking them as sonatype-2026-005899 and sonatype-2026-005901. The wallet address matches one documented by researchers at OpenSourceMalware, who named the technique NullReceiver and attributed the activity they examined to the DPRK-linked Contagious Interview campaign, associated with the Lazarus group. Sonatype said it confirmed the wallet match and observed similar tradecraft, including package hijacking and blockchain-based retrieval of follow-on infrastructure. A Transaction as a Dead Drop On execution, the loader queried Ethereum for an outbound transaction from the wallet and read bytes out of the transaction's recipient address. Those bytes decoded into two IPv4 addresses, which it treated as primary and secondary C2 endpoints. Sonatype found this implementation more extensive than the behavior previously documented. The loader could query several Ethereum remote procedure call providers, race requests between them, batch its calls and fall back to the Blockscout API to locate the relevant transaction, giving it multiple routes to recover its infrastructure if one failed. Once resolved, it pulled two further stages from the server. If a standard request failed, it retried and recovered the payload from a response header instead. The result was decoded and could either run directly inside the current Node.js process or launch as a detached child process. Two Routes Into the Registry The six split evenly between hijacked packages and purpose-built ones. Three appearED to be legitimate packages whose publishing accounts were compromised: @kolbo/mcp, agentgui and godot-kit. In each, the original functionality remained intact and the loader was appended to the end of an existing file, which Sonatype noted matched behaviour it observed in the DPRK-linked PolinRider campaign. The other three, envpack-conf, postcss-initial-provider and tailwindcss-motion-advanced, were published with the malware already present, each wrapped in plausible functionality. One carried package-configuration code, another a working PostCSS plugin and the third hid the loader inside a minified utility file. Sonatype said the hijacked packages presented the harder detection problem, because the malicious code arrived through names developers may already recognize and trust. Teams should check their environments for the affected versions, remove them and investigate for follow-on JavaScript execution or other signs of compromise. Sonatype said it is continuing to examine related npm activity.
infosecurity-magazine.comAug 11, 2026extracted
Kimwolf v7: An Evolution of the Kimwolf Botnet
We are providing a content warning because the following article contains usage of a racial slur by a threat actor, which Unit 42 does not condone in any instance. We have partially redacted the racial slur, but preserved some references to it in order to provide researchers with the ability to identify it and check IoCs as needed. We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes. Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints. This makes attack traffic more difficult to distinguish from legitimate browsing. The threat’s binary includes five hard-coded public Ethereum-based endpoints for resolving Ethereum Name Service (ENS) domains. ENS is a blockchain-based naming system used to obtain C2 addresses. Kimwolf also carries a hard-coded Tor .onion hidden service as a backup and a local proxy architecture for flexible routing between clearnet and Tor. The malware developers added this function to directly respond to C2 server takedown efforts in December 2025. We discovered this variant on Feb. 3, 2026, through threat hunting that followed public disclosures by XLab, Synthient, Infoblox, Cloudflare and others. Palo Alto Networks customers are better protected through the following products and services: If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. The Kimwolf botnet (also tracked as AISURU) has been active since August 2024. It initially targeted Linux IoT devices under the AISURU name. The botnet transitioned to Android TV boxes around August 2025. This reflects two separate codebases under the same operators. AISURU covers the Linux IoT variants, and Kimwolf covers variants targeting Android. Kimwolf spreads by misusing residential proxy services to reach unauthenticated Android Debug Bridge (ADB) instances on local networks. Some Android TV boxes ship with ADB enabled on port 5555. Once attackers tunnel through a proxy endpoint into the local network, they can install the malware without any authentication. The Kimwolf sample we analyzed as a baseline is a statically linked ARM Executable and Linkable Format (ELF) binary. The file was compiled with the Android Native Development Kit (NDK) using Clang and uses Bionic libc. It statically links BoringSSL for Transport Layer Security (TLS) operations and nghttp2 for HTTP/2 functionality. The binary is stripped but retains some symbol information. It is not uncommon for malware authors to use racial slurs in their code. The Kimwolf malware family has historically included racial slurs. In our discussion of the v7 variant, we have partially redacted these slurs, but have left enough information present that defenders could identify the variant and check for IoCs. Previous Kimwolf builds used the internal version strings such as n[redacted]boxv4 and n[redacted]boxv5, establishing the naming pattern for the family. The version string n[redacted]boxv7, shown in Figure 1, identifies this sample as version 7. The binary creates a Unix domain socket @n[redacted]boxv7 to ensure only one instance runs at a time. On execution, the malware masks its process name as netd_service to blend in with legitimate Android system processes. We identified six ELF samples that we clustered together based on multiple indicators: They share an identical ELF section layout produced by a common Android NDK build environment, and the same hard-coded set of Ethereum remote procedure call (RPC) endpoints Overlapping C2 infrastructure within the same hosting provider Consistent process-name masquerading behavior One of the most notable new capabilities in Kimwolf v7 is an HTTP/2 flood powered by the nghttp2 library. The function that performs the attack_case17_http2_flood constructs complete browser fingerprints. This makes the flood traffic difficult to distinguish from legitimate browser requests. Figure 2 shows the header construction logic in the decompiled binary. Kimwolf v7 uses a layered C2 resolution system designed to survive the domain takedowns that disrupted the botnet twice in December 2025. This isn't the last time operation of this malware faced disruption. On March 19, 2026, the U.S. Justice Department and international partners announced a court-authorized operation that seized C2 infrastructure used by the Aisuru, KimWolf, JackSkid and Mossad botnets. The binary contains five hard-coded public Ethereum RPC endpoints stored in plaintext, shown in Figure 3: hxxps[:]//0xrpc[.]io/eth hxxps[:]//eth.llamarpc[.]com hxxps[:]//ethereum-rpc.publicnode[.]com hxxps[:]//eth-protect.rpc.blxrbdn[.]com hxxps[:]//eth.merkle[.]io These endpoints are legitimate public Ethereum RPC services. The malware misuses them to query ENS domain records and resolve C2 addresses. Organizations should monitor for unusual Ethereum RPC traffic from IoT and Android devices rather than blocking these endpoints outright. The malware shuffles these endpoints using a pseudo-random number generator (PRNG) before each resolution attempt. The five-way redundancy makes blocking ENS-based C2 resolution harder. While the five public RPC endpoints in the baseline binary are third-party services, our infrastructure investigation identified a sixth endpoint that we assess with moderate confidence to be under the operator's control: eth[.]rpcuniverse[.]com. Several properties distinguish it from the legitimate providers: The legitimate endpoints are established services with significant traffic and resolve to multiple anycast IP addresses across major cloud delivery network (CDN) and cloud providers They have apex domains registered between 2005 and 2022 The rpcuniverse[.]com domain has no global traffic ranking - It resolves to a single IP address on a low-cost virtual private server (VPS) that was registered on Dec. 12, 2023 - Its TLS certificate first appeared on the hosting IP address days later - Reverse passive DNS shows the IP address hosts only rpcuniverse[.]com subdomains with no other tenants Two Kimwolf samples hardcode eth[.]rpcuniverse[.]com as an additional RPC endpoint alongside the five legitimate providers - Both ELF and Android APK variants contact the hosting IP address directly - We did not observe this direct-to-IP address contact pattern with any of the legitimate RPC endpoints We cannot confirm domain ownership. However, the dedicated single-tenant hosting, the timing of its registration relative to Kimwolf activity and its exclusive presence in Kimwolf binaries suggest it is an operator-controlled facade rather than a public service. When ENS resolution fails, the v7 binary falls back to a hard-coded v3 Tor .onion address (edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd[.]onion). Figure 4 shows the hard-coded address in the binary. A function (tor_proxy_state_machine) manages the protocol states. To do this, it performs the following activities: Sending the greeting (0x05 0x01 0x00) Building a CONNECT request with domain type 0x03 and the 62-byte .onion address Waiting for the response and performing a TLS handshake over the tunnel Figure 5 shows the greeting and TLS handshake states. Additionally, it uses a local proxy architecture. All C2 traffic routes through a local proxy at 127.0.0[.]1:23075 shown in Figure 6, regardless of whether it is destined for clearnet or Tor. This modular design allows the proxy component to be updated independently from the main bot binary. Analysis of Kimwolf v7 samples revealed C2 connections to several IP addresses, including: 212.193.31[.]119 and 212.193.31[.]122 on TCP port 13 212.193.31[.]92 and 212.193.31[.]158 on TCP port 443 None of these IP addresses had prior indicators of malicious activity or associations with public threat intelligence. During infrastructure analysis, we observed that these hosts presented the same SSH host key. Pivoting on that shared key revealed 22 total IP addresses within the same range, presenting the identical key between Dec. 18, 2025, and Feb. 3, 2026. No hosts outside this range shared the key. IP address 212.193.31[.]102 was the first host observed with this key on Dec. 18, 2025, and it was the seed from which the configuration propagated. The remaining 21 hosts appeared over the following six weeks, with the last addition on Jan. 31, 2026. All 22 hosts reside in AS202799, geolocated to Saint Petersburg, Russia. Kimwolf implements a dedicated high-performance UDP flood function that uses a Xorshift256 PRNG seeded from /dev/urandom. It (prng_seed_from_urandom) reads 32 bytes (four 64-bit state words) to initialize the full 256-bit state. A SplitMix64 fallback initializer activates if /dev/urandom is unavailable. The flood function accelerates IP/UDP checksum computation with ARM NEON single instruction, multiple data (SIMD) instructions. The vectorized checksum loop processes four 16-bit halfwords simultaneously using VLD1.16, VADDW.U16 and VADD.I32 instructions. This optimization is tailored for the ARM processors found in Android TV boxes. It reduces per-packet checksum overhead to maximize throughput. Figure 7 shows the NEON SIMD instructions in the disassembled binary. The dispatch table supports 15 DDoS methods across Layers 3–7 of the Open Systems Interconnection (OSI) model. Cases 8, 11 and 13 are absent from the switch statement, suggesting they are either reserved for future use or were removed during consolidation from the 43 text-named methods in prior versions. Table 1 lists all 15 attack methods. Table 1. Kimwolf v7 DDoS attack methods. In Kimwolf v7, malware authors consolidated the attack count to 15 numbered methods. They removed all scanning, exploitation and brute-force functionality. The new additions target: DDoS stealth through HTTP/2 with browser fingerprinting C2 resilience through ENS, Tor and the local proxy The removal of the scanner and exploit modules suggests the operators have separated the propagation pipeline from the DDoS bot. External loaders now handle initial access while the Kimwolf binary handles attacks and proxy relay. The earliest dropped sample, targeting the x86 architecture with a Dirty COW exploit, suggests the family evolved from traditional Linux exploitation toward the current ADB-based Android propagation model. The transition from libn[redacted]kernel.so to the less conspicuous libdevice.so filename in November 2025, followed by a revert in December, indicates active operational security adjustments. Alongside the standalone ELF payloads, the Kimwolf operators distribute Android APK packages that bundle an ELF kernel payload inside a Java wrapper. We identified eight APK samples spanning October through December 2025, all sharing the component class systemservice0644.N[redacted]Kernel. These APKs masquerade as a system service called SystemService. On execution, they probe for root access and execute the embedded ELF kernel with commands shown below in Figure 8. The earliest build (October 2025) used the com. Android prefix and bundled three kernel variants in a single APK. By late October, the package name shifted to com.n2.systemservice0644, and the kernel was consolidated to a single binary. In November, the kernel filename changed from libn[redacted]kernel.so to libdevice.so, then reverted in the December builds. Three signing certificates appear across the cluster: The original Kimwolf APK certificate (C=CN, CN=a) used by the com.android.logcatd variants An Android Debug certificate used during development A self-signed certificate with subject C=XK, ST=lol, L=lol, O=lol, OU=lol, CN=lol (country code XK for Kosovo, all other fields set to lol) used by five of the eight N[redacted]Kernel APK files The APK wrapper drops one of three ELF kernel payloads, depending on the build. These are listed in Table 2. Table 2. Dropped ELF kernel payloads. The earliest sample (first seen Sept. 2, 2025) is notable for two reasons: It targets x86 architecture rather than ARM - This indicates that the botnet originally targeted x86 Linux systems before pivoting to ARM-based IoT and Android devices It drops a file named libcow.so, and renames its process to inetd to blend in with Unix network services - The name libcow.so is likely a reference to the Dirty COW privilege escalation vulnerability (CVE-2016-5195) The libdevice.so sample renames its process to TVHelper, which explicitly targets Android TV set-top boxes by mimicking a legitimate TV helper service. Neither the libn[redacted]kernel.so nor libdevice.so kernels embed the Ethereum RPC endpoints found in the standalone ELF builds. The C2 resolution layer resides in the outer APK wrapper or the standalone ELF binary, while the kernel handles lower-level bot operations. Kimwolf v7 is a focused evolution of an already large-scale botnet. The HTTP/2 flood with Chrome browser fingerprinting complicates application-layer DDoS mitigation, as attack traffic now mirrors legitimate browser behavior at the protocol and header level. The three-tier C2 system (Ethereum ENS, Tor .onion, local proxy) indicates that the operators are investing in infrastructure built to withstand takedown operations. Organizations should monitor for the following behavioral indicators of Kimwolf compromise on IoT and Android devices: Outbound HTTPS connections to public Ethereum RPC endpoints (e.g., 0xrpc[.]io) from devices that typically do not interact with blockchain services Tor circuit establishment or SOCKS5 proxy traffic from Android TV boxes or IoT devices Connections to port 23075 on localhost A process named netd_service running on consumer Android devices Organizations should treat Android TV boxes as untrusted and segment them from enterprise networks. Disabling ADB or restricting it to USB-only access removes the primary propagation vector for this botnet. Palo Alto Networks customers are better protected through the following products and services: The Advanced WildFire machine-learning models and analysis techniques have been reviewed and updated in light of the indicators shared in this research, Advanced URL Filtering and Advanced DNS Security identify known domains and URLs associated with this activity as malicious. Device Security is designed to proactively protect the entire device attack surface, from IT to IoT and OT, with a unified platform that helps deliver comprehensive visibility, actionable risk insights and adaptive security enforcement. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. SHA256 hash: 406647de09a0ffa279756b4ccb344b1b76a333320c5b50fd367901fa006cf0ff MD5 hash: d759364844d78a728505fb0485c3adbc File size: 1,720,108 bytes File type: ELF 32-bit LSB executable, ARM, statically linked, stripped File description: Kimwolf v7 bot payload (baseline analyzed sample); version string n[recacted]boxv7 SHA256 hash: 345222bca004595977f971d76900b0c65fd9bf9d91c50cd0c5bf5a93f1ad9e49 MD5 hash: 036bcb62be72c4663b9564955f93b05f File size: 1,712,624 bytes File type: ELF 32-bit LSB executable, ARM, statically linked, stripped File description: Kimwolf v7 bot payload SHA256 hash: 2ec2e85b0358e0c681cb5067489a9086ec97dbbf7e3c952dd9cd496b319d5af5 MD5 hash: 33faca1e0090f6b12eff703daf4606e4 File size: 1,720,108 bytes File type: ELF 32-bit LSB executable, ARM, statically linked, stripped File description: Kimwolf v7 bot payload; hard codes eth.rpcuniverse[.]com in the binary SHA256 hash: 951c94809aa6c7ab587125f9d4df30fa6a49ee0cbba76a4b7ceedaaa0e5dcd36 File type: Android APK Package name: com.android.logcatd File type: ELF 32-bit LSB executable, ARM, statically linked, stripped File description: Kimwolf Android variant; masquerades as system logcat daemon; includes TorService and BootReceiver persistence; contacts 23.94.221[.]104 SHA256 hash: f07821e313c16cbbd82def45094a22c8d474164051bdbc7648d6869e012014b4 File type: Android APK Package name: com.android.logcatd File type: ELF 32-bit LSB executable, ARM, statically linked, stripped File description: Kimwolf Android variant; sibling of the above, same signing certificate and package; contacts 23.94.221[.]104 VHash: 76554ad09897ac723a850eaf8c525efa Description: Structural hash shared by the three Kimwolf v7 ELF samples (5 total matches across VirusTotal) APK signing certificate (SHA-1 thumbprint): 2a1d96f1b066877812587ac94f45f82dfff5f5f9 Subject: C=CN, CN=a Description: Self-signed certificate used to sign both Kimwolf Android samples TLS certificate (SHA256 hash): f3e8a55a2a3ea7c7b6676e90f4f49a2c55b13065b68ee50c51cc35fe2b5c3237 Issuer: Let's Encrypt Description: Certificate issued for eth.rpcuniverse[.]com, observed on 23.94.221[.]104 between Dec. 13, 2023, and March 12, 2024 Domain: rpcuniverse[.]com Description: Multi-chain RPC service; apex registered Dec. 9, 2023 (Namecheap); resolves to 23.94.221[.]104; hard-coded subdomain present in Kimwolf sample Domain: eth.rpcuniverse[.]com Description: RPC subdomain hard-coded in Kimwolf sample 2ec2e85b... Domain: avax.rpcuniverse[.]com Description: RPC subdomain resolving to 23.94.221[.]104 IP address: 23.94.221[.]104 Description: Operator host (AS36352 RackNerd, Dallas); hosts rpcuniverse[.]com; contacted by Kimwolf ELF and APK samplesng IP address:port: 212.193.31[.]158:443 Description: HTTPS C2 traffic (AS202799 SYSECT, Russia); offline after Jan. 31, 2026 IP address:port: 212.193.31[.]119:13 Description: C2 traffic IP address:port: 212.193.31[.]122:13 Description: C2 traffic IP address: 212.193.31[.]102 Description: C2 host (linked via shared SSH host key with .158 IP address:port: 212.193.31[.]92:443 Description: HTTPS C2 traffic (AS202799 SYSECT, Russia) Tor hidden service: edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd[.]onion Description: v7 hidden-service C2 fallback Kimwolf Botnet Exposed – XLab AISURU Botnet Technical Analysis – XLab A Broken System Fueling Botnets – Synthient Kimwolf Howls from Inside the Enterprise – Infoblox The Kimwolf Botnet is Stalking Your Local Network – KrebsOnSecurity Kimwolf Botnet Lurking in Corporate, Govt Networks – KrebsOnSecurity KIMWOLF V7 IoT BOTNET EVOLUTION - Unit 42 Updated August 13 2026 at 2:00 p.m. PT to add information on the U.S. Justice Department and international partner operation seizing C2 domains used by KimWolf and related botnets.
unit42.paloaltonetworks.comAug 11, 2026extracted
ChainDrop: Inside a Self-Propagating npm Worm
A self-propagating npm worm nicknamed ChainDrop infected over 400 packages that are collectively downloaded hundreds of millions of times each week. This includes malicious versions of widely used packages such as keyv and cacheable-request. Unit 42 has unique observations of this attack. The attackers behind ChainDrop potentially exposed developer workstations, continuous integration (CI) pipelines, cloud environments and downstream software users across a large number of organizations. Once installed, ChainDrop steals: Cloud credentials npm and GitHub tokens SSH keys Other sensitive developer data It can also extract temporary credentials from GitHub Actions runner memory and use stolen npm publishing tokens to infect and republish additional packages while preserving their legitimate functionality. We have observed active attempted operations, which were detected out of the box by our existing products. During our investigation into this attack, we identified 453 public GitHub repositories across five accounts matching the worm’s exfiltration patterns. We also detected ChainDrop execution across 10 distinct environments. At the time of publication, these repos were removed. We have deobfuscated the malware and identified: Persistence through developer and AI coding tools Blockchain-based command-and-control (C2) resolution Its ability to execute additional attacker-supplied code Additionally, late on Aug. 4, 2026, we observed the adversary silently reconfiguring the worm's entire C2 infrastructure through a single Ethereum transaction, without requiring any update to the deployed malware. This attack is the latest in a series of threats to the security of the npm ecosystem. Unit 42 recommends: Identifying installations of affected npm package versions Removing affected package versions Investigating developer workstations and CI runners for signs of compromise Reviewing unexpected npm publishing and GitHub repository activity. Revoking and rotating potentially exposed npm, GitHub, cloud, SSH and automation credentials. Removing identified persistence mechanisms Blocking both the domain-based and GitHub-based exfiltration channels The Koi Agentic Endpoint Security risk engine flagged the malicious package activity as the attack unfolded. Cortex XDR detected and alerted on the worm’s execution using out-of-the-box behavioral detections. Palo Alto Networks customers can use Koi Agentic Endpoint Security to help identify and control malicious packages across developer endpoints. The Cortex AgentiX Threat Intel agent can help allow analysts to extract, enrich, and search IoCs using natural language to quickly determine organizational impact. Cortex Cloud Endpoint Protection leverages AI-enabled analytics to help detect and prevent threats targeting Linux endpoints, containers, and associated cloud IAM policies. Cortex XDR and XSIAM provide behavioral detection, investigation and response that can help organizations address ChainDrop activity executing in development environments. Idira Secrets Manager and Secrets Hub eliminate hard-coded credentials from configure files and source code by automating zero-downtime rotation, and dynamically delivering just-in-time access to non-human identities across multi-cloud and DevOps environments. The Unit 42 Cloud Security Assessment is an evaluation service that reviews cloud infrastructure to identify misconfigurations and security gaps. The Unit 42 Incident Response team can also be engaged to help with a compromise or to provide a proactive assessment to lower your risk. We analyzed the contents from one of the infected packages to understand the full attack chain. The package contained the legitimate software development kit (SDK) code that a user would expect, including the source, dependencies and documentation. But it also contained small indicators of the ChainDrop worm: two extra top-level files and one lifecycle hook. The indicators of the worm can be subtle, as illustrated in the following example. One of the indicators is an infected npm package's package.json file containing code with the preinstall command, as shown in Figure 1. That preinstall line is the only modification the worm makes to this package's manifest. It points to setup.mjs, a dropper that checks whether Bun (a lightweight JavaScript runtime and package manager alternative to Node.js) is on PATH. It downloads Bun 1.3.13 from the legitimate Oven GitHub repository if it isn't present. Then it feeds Bun a 727 KB obfuscated JavaScript payload (math_init.js) compressed into two source lines. To be clear: Bun is not compromised. The attacker is using a legitimate runtime as a portable execution vehicle. The payload spawns a detached background process, sets _NODE_RUNTIME_INIT=1 to prevent recursive relaunch and lets the install finish cleanly. No errors. No warnings. Most developers would move on without noticing a key detail: The worm is already running. The worm detaches when it is not in CI. If it detects a CI environment it runs inline in the job instead, which means its own debug output lands in the workflow log. This is useful for defenders looking for indicators because the worm is chatty. One further gate runs before the worm engages in any collection. This gate is a locale check that, on a Russian-language host, prints “Exiting as russian language detected!” and exits cleanly. The worm spares those machines. The background payload begins a sweep of the infected machine to harvest credentials from the environment. These include the following categories: Cloud credentials: - Multiple major cloud infrastructure platforms - The worm queries metadata endpoints and token endpoints across both compute instances and container services to harvest temporary identity and access management (IAM) role credentials, extending scope to short-lived identity tokens used by automated integration runners Multiple major cloud infrastructure platforms Developer tooling: - Docker and Helm configurations - Git credentials - Mount listings - npm and GitHub tokens - Poetry and PyPI credentials - RubyGems tokens - SSH keys - Terraform state - Vault tokens AI tools: - AI-assisted coding tools - Cloud-based development platforms - Open-source coding assistant configurations and authentication artifacts Everything else: - .env files - .netrc - Application configuration scattered across the home directory - Bitcoin and Electrum wallet files - Jenkins encrypted credential material - Kubernetes service-account tokens and kubeconfigs - Shell histories ChainDrop harvests credentials, but also a wide variety of other information about the systems and environment it’s running on. Some of the information stolen is vital for the worm’s survival. The npm and GitHub tokens it finds are what it needs to keep spreading. An embedded Python helper hidden inside an encrypted blob in the payload locates the Runner.Worker process on GitHub Actions runners, opens /proc/ /maps and /proc/ /mem, and searches live process memory for OpenID Connect (OIDC) tokens and runner secrets. The flow of this GitHub Actions runner memory scraping is illustrated in Figure 2. Rather than waiting for a file to be written to disk, the worm searches memory. In the process, it captures secrets that may have been designed to vanish when a job finishes. Organizations should be aware that CI runners are credential targets and can be exfiltrated through attacks on process memory. The worm establishes several persistence mechanisms, but two of them deserve special attention: Cross-linked persistence through VS Code and Claude Code A latent capability for OS-level persistence It writes a .vscode/tasks.json file with a task labeled Environment Setup and sets it to run when the folder opens — meaning it executes automatically whenever a developer opens the project in VS Code. That task runs node .claude/setup.mjs, a copy of the dropper that is byte-identical to the setup.mjs shipped in the package itself. It also writes a .claude/settings.json file with a SessionStart command hook, meaning it executes whenever Claude Code starts a session in the project. That hook runs node .vscode/setup.mjs, a second copy of the same dropper. Figure 3 shows the cross-linked persistence through both .vscode/tasks.json and .claude/settings.json files. Neither file triggers the other. Each one runs the dropper copy sitting in the other's directory, and the actual trigger in both cases is a developer action: opening the folder, or starting a Claude Code session. Cross-referencing is a naming trick that makes each artifact look like it belongs to the other tool. The payload is only ever written as .claude/math_init.js, and setup.mjs resolves math_init.js relative to its own location. .vscode/setup.mjs goes looking for a .vscode/math_init.js that the malware never dropped. In this build, only the VS Code path reaches a payload at all. The full set of dropped files is: .claude/math_init.js .claude/settings.json .claude/setup.mjs .vscode/setup.mjs .vscode/tasks.json Deleting either directory outright breaks both paths. However, defenders should remove all five files to be sure the worm is disabled. The worm also carries an installer for a macOS LaunchAgent (com.user.gh-token-monitor) and a Linux systemd user service (gh-token-monitor.service). In this sample, the installer was decrypted but never invoked. The routine that pipes it to bash has no call site, so treat OS-level persistence as latent capability, not observed behavior. The attacker is turning a trusted developer and AI-tool configuration into execution infrastructure. These aren't files most developers think to audit. Once the worm has an npm token, it: Identifies every package the account can publish Downloads or reconstructs each package Adds preinstall: node setup.mjs to the package.json file Writes the dropper (setup.mjs) and the obfuscated payload (math_init.js) Increments the patch version Republishes the infected package as the current npm package The infected package still works. The original source code is intact. As in the sample we analyzed, the only additions are the two top-level files and the lifecycle hook. The worm also plants a .github/workflows/codeql_analysis.yml file that serializes ${{ toJSON(secrets) }} and uploads it as an Actions artifact, another path to exfiltrate repository secrets. And it creates public repositories under the victim's GitHub account with the description Shai-Hulud: Here We Go Again and Dune-themed names, using them as an additional exfiltration channel. Everything above is a relatively loud and more obvious propagation path. There is a second typosquatting method that is much quieter and it only appears in a single place. Before collecting anything, the worm checks three environment variables. If these three variables are set: GITHUB_ACTIONS GITHUB_REPOSITORY to contain /opensearch-js GITHUB_WORKFLOW_REF to contain release-drafter.yml The worm runs a static routine of republishing the repo and exits. No collection takes place. Also, If the worm is placed in a repo that contains /opensearch-js, but does not contain release-drafter.yml, it exits and steals nothing at all. It stays silent in the runs a maintainer is most likely to be reading. Inside this second method, the worm does not need a stolen npm token. It asks the runner for an OIDC token with the audience npm:registry.npmjs.org and trades it at npm's own trusted-publishing exchange endpoint for a real publish credential. The repository's legitimate release identity becomes the attacker's. Then it modifies the package, and not the way it modifies everything else. This path never touches scripts. It downloads the latest @opensearch-project/opensearch tarball, bumps the patch version and adds one line to the package.json file shown below in Figure 4. The dependency name typosquats the project's own @opensearch-project scope and points at a pinned commit of the project's own repository. In a diff it reads like an internal helper. Detections built around preinstall hooks could easily miss it. And then the worm signs the result. Before publishing, the worm: Requests a second OIDC token (audience sigstore this time) Obtains a Fulcio certificate Builds an in-toto SLSA v1 provenance statement over the tarball's SHA-512 hash DSSE-signs it with an ephemeral P-256 key Uploads the entry to the public Rekor transparency log Attaches the bundle to the publish as - .sigstore Logs the resulting search.sigstore.dev URL as it goes This is not forged provenance. The attestation says the tarball was built in that repository by that workflow, and that is true. That breaks a control many teams are currently leaning on. Given the reality of today’s npm supply chain threats, a package having valid npm provenance does not mean the package is clean. It only means the tarball came out of the workflow named in the certificate. If that workflow is running attacker code, valid provenance is what you should expect to see. Pivot on the Rekor log index and the workflow identity inside the certificate, not on whether the signature checks out. We did not observe this path execute, and it cannot execute anywhere except in release-drafter.yml inside the opensearch-project/opensearch-js workflow. But it is fully implemented, reachable from the payload's main entry point, and it names its target in cleartext once the string layers come off. This repository is not typosquatted. The typosquat is the injected dependency name @opensearch/setup, which imitates the real @opensearch-project scope. The worm doesn't contain a hard-coded C2 domain. Instead, it calls an Ethereum smart contract to ask where to send stolen data. The contract sits at 0xE1f2395ee43e45A1556EC6438a88c31B83493103. This contract is a small StringListStore with three functions: return all domains, return owner and an owner-only setter. It emits no events, so domain rotation is a silent state write. Defenders who block today's domain may not notice when the operator changes it unless they're polling the contract. The worm rotates through roughly 60 public Ethereum RPC endpoints until one answers, making it resilient to any single provider blocking the request. When the contract was first configured, the operator wrote three domains: npm-cache[.]com pypi-get[.]com js-mirror[.]com Two hours and 35 minutes later, they replaced the list with only npm-cache[.]com. As of our analysis, that's still the active C2. If contract-resolved domains fail, the worm falls back to searching GitHub commits for the marker thebeautifulmarchoftime, expecting a signed record containing a backup domain. During our query, the fallback was unarmed. No valid operator record existed. However, the mechanism is built and waiting. The primary C2 domain, npm-cache[.]com, sits behind an edge computing and reverse-proxy service, so its published addresses are shared edge addresses rather than attacker-owned hosts, so block on domain or SNI. Blocking these IP addresses will not reach the origin and will affect unrelated traffic. After sending stolen data, the worm reads the HTTP response, parses it as JSON and evaluates whatever comes back. The JavaScript code to accomplish this is shown below in Figure 5. There is no fixed second-stage payload baked into the worm. The operator chooses the next stage at request time. Because each exfiltration request includes a host-derived UUID, the response can be targeted per victim and never written to disk. During our analysis, we sent a correctly formatted synthetic envelope using the worm's exact encryption scheme with dummy data to the live C2 endpoint. The server returned an HTTP 200 OK with an empty body. No code field was served to our probe. That means the remote code execution (RCE) channel was either disarmed at test time, selectively gated on victim attributes or asynchronous. Stolen data is JSON-serialized, gzipped, encrypted with a random AES-256-GCM key and wrapped with RSA-OAEP-SHA256 using an embedded public key. The worm sends the code shown below in Figure 6. Everything goes to hxxps://npm-cache[.]com:443/router over TLS. Network capture can prove that data left the machine and estimate its volume, but recovering the plaintext requires the operator's private RSA key. Only the domain-based sender evaluates returned code. Blocking the domain prevents an arbitrary RCE stage if the functionality is enabled. But the GitHub fallback can still exfiltrate data through victim-owned repositories, which means full containment requires addressing both channels. There is a third situation that we describe in this section, and it is the strangest one. When the GitHub sender carries a stolen token, the worm Base64-encodes that token twice and makes the result the commit message, prefixed with a fixed marker: IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients A separate routine in the same payload searches GitHub's commit API for that marker, double-decodes every match and keeps any token that passes a repository-scope check. One victim's stolen credentials become a usable resource for every other running copy of the worm. Despite the claims made in the marker, defenders should grep for it. It is long enough and strange enough that a full match is highly unlikely to be a false positive. A live hit means a credential is sitting in a public commit and needs revoking. The three C2 domains were registered through one registrar within eight seconds of each other on May 22, 2026: js-mirror[.]com - 13:40:28 UTC npm-cache[.]com - 13:40:32 UTC pypi-get[.]com - 13:40:36 UTC All three use the same nameservers. Fourteen minutes and 23 seconds after the last registration, FixedFloat transferred 0.01805723 ETH to the operator's wallet (0x55F9780e…f31cD). Three days later, on May 25, the wallet deployed the Ethereum resolver contract, wrote all three domains into it, and 2 hours and 35 minutes after that narrowed the list to just npm-cache[.]com. The next morning it transferred 0.00436 ETH to a Binance-labeled deposit address. The accounting reconciles to the wei. A timeline showing the deployment of the campaign infrastructure is shown below in Figure 7. FixedFloat is a shared exchange wallet with millions of transactions. This wallet tells us the funding rail, not the operator's identity. The Binance deposit address is the strongest identity pivot. On Aug. 4, 2026, the attacker executed an on-chain transaction 0xc55920f1bd0531b6738153068a666c080ddded47e6256f1fd980d51c0b507c91 to modify the StringListStore in smart contract 0xE1f2395ee43e45A1556EC6438a88c31B83493103, rotating the active C2 domain from npm-cache[.]com to a newly registered domain, awqhnjewqjkl[.]icu. The transaction was submitted by wallet 0x55F9780ef31cD, the same wallet that originally deployed the C2 smart contract on May 25, 2026. The new domain awqhnjewqjkl[.]icu was registered via NameSilo, LLC at 15:15:26 UTC on Aug. 4, 2026, and was operationally active within the hour as the earliest observed connection observed by Unit 42 researchers occurred at 16:10:03 UTC. The domain exhibits characteristics consistent with domain generation algorithm (DGA) output: a randomized 12-character string on the .icu top-level domain (TLD), flagged as DGA by the VirusTotal community. This represents a shift from the previous C2 domain npm-cache.com, which used a naming convention that mimicked a developer ecosystem and was registered through a different registrar (Tucows/OpenSRS). Despite the change in registrar and naming convention, both awqhnjewqjkl[.]icu and npm-cache[.]com are proxied through Cloudflare's cloud delivery network (CDN) infrastructure. Both domains serve the identical Cloudflare default CDN-CGI stylesheet d30b4ea6f68456672f5abb35e9dcf7d54226372b66e9d60a7ee26b7a52568e74, confirming shared use of the Cloudflare proxy layer. The new domain was issued a TLS certificate by Google Trust Services (WE1), which is valid from Aug. 4–Nov. 2, 2026, with Subject Alternative Names (SAN) covering both awqhnjewqjkl[.]icu and *.awqhnjewqjkl[.]icu. Within approximately 19 hours of the domain becoming active, we witnessed network traffic to victim environments. The affected infrastructure spans four continents: North America, Europe, Asia and Africa. The destination IP addresses for this C2 domain include 104.21.91[.]101 and 172.67.215[.]154. The geographic and organizational breadth of these connections is consistent with the indiscriminate, worm-driven propagation model of ChainDrop. This C2 rotation demonstrates the adversary's ability to silently reconfigure the worm's entire C2 infrastructure through a single Ethereum transaction, without requiring any update to the deployed malware. Monitoring the smart contract for future setStrings() calls would provide early warning of subsequent domain rotations. Multiple indicators point to this being the Shai-Hulud toolchain documented by JFrog: The PBKDF2-based string decoder The Bun 1.3.13 pin The _NODE_RUNTIME_INIT detached-relaunch pattern The self-applied Shai-Hulud: Here We Go Again marker The npm self-propagation and GitHub exfiltration architecture However, these indicators don’t prove the same attackers are behind the campaign. Because the Shai-Hulud source was published in May 2026, the implementation can be reused by anyone. This sample also mixes characteristics that don't match any previously published variant: Public victim-owned exfiltration repositories with Dune-themed names Ethereum-based domain resolution, thebeautifulmarchoftime commit-search fallback A Russian-language exclusion check A repository-gated npm trusted-publishing path that mints genuine Sigstore provenance preinstall delivery rather than the binding.gyp technique reported in earlier waves The ChainDrop worm is clearly part of the Shai-Hulud code lineage. However, we cannot yet say whether it's operated by the group known as TeamPCP, or by another group adapting the published toolkit for their own purposes. We detected ChainDrop operations across 10 distinct environments using out-of-the-box XDR detections focused on JavaScript runtime events. In one instance, as illustrated in the process execution in Figure 8, the threat activity originated within a developer's VS Code environment. The threat actors leveraged Bun to execute the malicious payload Math_Symbol.js from within the cacheable node modules directory. This script then spawned cmd.exe to invoke gh auth token to capture the user's GitHub authentication credentials. The 727 KB payload was protected by three nested layers of obfuscation and encryption. We broke through all of them. No unexplained blob remains in the sample. Layer 1 used Base91 encoding with 73 function-specific alphabets and a 14-position array rotation. We recovered 4,613 hidden string entries. Layer 2 used a custom byte-permutation cipher built on PBKDF2-SHA256 with 200,000 iterations and seeded Fisher-Yates shuffles. We recovered 727 additional hidden strings. Layer 3 used AES-256-GCM encryption plus gzip to protect 10 large encrypted blobs. These blobs contained: Bash and Python helpers Persistence installers The GitHub Actions memory scraper Malicious workflow templates VS Code and Claude persistence files RSA public keys Additional dropper copies These three layers are shown below in Figure 9. During our analysis, at approximately 12:20 UTC on Aug. 4, 2026, we searched GitHub for public repositories matching the worm's exact exfiltration marker: the description Shai-Hulud: Here We Go Again. We found 453 public repositories across five accounts. The earliest was created on May 11. The newest had been created roughly 25 minutes before our query. The names followed the pattern that matched the worm's Dune-themed generator exactly, with combinations like sardaukar-futar-421 and harkonnen-ghola-669. These five accounts are candidate victim accounts, not confirmed victims. The 453 repository counts might be only a starting point for possible compromises. In addition to public matches, there may be private repositories compromised as well. But the naming, description and creation patterns match the worm's behavior, and new repositories were still appearing while we watched. Three accounts held most of the total repos that we discovered. The attackers are not only actively compromising repositories, they are also rapidly releasing new versions of compromised packages. We analyzed one compromised package, but then noticed that a newer version of the package had landed six minutes after the compromised package. Another landed 70 minutes after that. The threat actors are actively, and rapidly, creating new repositories, versions and patch numbers, which will propagate the worm more efficiently. Because CI/CD pipelines are often configured to pull the latest patch or version, if there are several rapid fire versions, and they are compromised, the CI pipelines are more likely to grab an infected package. Defenders may not be taking the most effective approach to removing the worm’s infection. It is critical to ensure poisoned packages and their files are fully removed from potentially compromised systems. Unit 42 researchers found that a previously compromised system was rolled back to the latest tag pointing at the latest clean version. This fixed the tagging issue. However, it didn't fix the poisoned lockfiles, caches, mirrors or tarballs already sitting in a CI image. Even after updating the latest tag to point to a secure version, machines that installed the package during the compromise will not automatically receive the fix. Because lockfiles retain the compromised version, these systems remain vulnerable until administrators actively clear the lockfiles and fetch the updated release. Assume the potential impact is wider than what we know now. The worm attempts to republish itself through packages writable by compromised npm tokens. If a developer installed an affected release, enumerate every package their npm credentials could modify. Add npm-cache[.]com, pypi-get[.]com and js-mirror[.]com to DNS and TLS SNI blocklists. Prefer sinkholing over an HTTP block page, because the worm treats HTTP 400 and 404 as a healthy C2 response. Monitor the resolver contract for domain changes. Revoke or rotate npm tokens, GitHub PATs and deploy keys, cloud credentials, Kubernetes service-account tokens, Vault tokens, SSH keys and AI-provider credentials accessible to confirmed infected hosts. Treat CI runners as potentially compromised if the worm executed there. Search accessible repositories for: .vscode/tasks.json invoking .claude/setup.mjs .claude/settings.json invoking .vscode/setup.mjs .github/workflows/codeql_analysis.yml containing toJSON(secrets) Math_Symbol.js math_init.js setup.mjs router_runtime.js Although the installer was not invoked on the analyzed main execution path, search for: ~/Library/LaunchAgents/com.user.gh-token-monitor.plist ~/.config/systemd/user/gh-token-monitor.service ~/.local/bin/gh-token-monitor.sh ~/.config/gh-token-monitor/ Look for HTTP GET or POST requests to /router on the three C2 domains, Ethereum JSON-RPC eth_call requests targeting 0xE1f2395ee43e45A1556EC6438a88c31B83493103, and GitHub commit searches containing thebeautifulmarchoftime or IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients. Search accessible repositories for commit messages containing IfYouBlockThisAPIKeyItWillCrashTheLiveProductionServersOfAllThirdPartyClients, and for the dead-drop record prefix thebeautifulsnadsoftime. A match on the first is a leaked credential requiring immediate revocation. A match on the second is a planted backup C2 domain. Compare recently published patch releases for new preinstall hooks, replaced scripts objects, setup.mjs files and large minified JavaScript bundles. Do not scope to listed packages. The worm is designed to spread to unrelated packages writable by stolen tokens. Here is a practical playbook for AppSec engineers and developers: Bind authentication to the workload: The stealer targeted HashiCorp Vault tokens alongside npm, GitHub, AWS and Kubernetes credentials. A vault does not help when the token authenticating to it is a bearer string in a dotfile. Use credentials bound to the workload itself, such as mutual TLS with a SPIFFE identity, a cloud IAM role, or a projected service account token with an audience claim, so replay from attacker infrastructure fails. Use ephemeral CI runners: Persistent self-hosted runners accumulate credentials and caches across jobs that often belong to different teams, so one poisoned install contaminates everything that runs after it. Single-use runners limit exposure to one job. Plant canary credentials: Use decoys produce high-confidence signals with low false positives. Place non-functional keys in ~/.aws/credentials, ~/.npmrc, and an .env file across build images and workstations, then enable high alert on any use. Egress filtering in CI/CD: Most npm-based malware attempts to send ~/.npmrc tokens or ~/.ssh keys to a C2 server. Apply strict egress network policies to your CI runners. Only allow connections to your private registry and known deployment targets. The Unit 42 Managed Threat Hunting team continues to track any attempts to exploit these issues across our customers, using Cortex XDR and the XQL queries below. Cortex XDR customers can also use these XQL queries to search for signs of exploitation. ChainDrop demonstrates how a compromised open-source package can become an entry point into developer workstations, CI pipelines, cloud environments and the broader software supply chain. By stealing publishing credentials and automatically republishing infected packages, the worm can continue spreading through trusted dependencies while leaving their legitimate functionality intact. Its ability to extract ephemeral credentials directly from CI runner memory also means that investigations limited to files stored on developer endpoints may miss critical exposure. Unit 42 recommends: Identifying installations of affected npm package versions Removing affected package versions Investigating developer workstations and CI runners for signs of compromise Reviewing unexpected npm publishing and GitHub repository activity. Revoking and rotating potentially exposed npm, GitHub, cloud, SSH and automation credentials. Removing identified persistence mechanisms Blocking both the domain-based and GitHub-based exfiltration channels Palo Alto Networks customers are better protected through the products described below. Palo Alto Networks and Unit 42 will continue monitoring this campaign for changes in infrastructure, new affected packages and evidence of additional activity, and we will update this threat brief as relevant information becomes available. Palo Alto Networks customers can leverage a variety of product protections and updates to identify and defend against this threat. If you think you might have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 The Advanced WildFire machine-learning models and analysis techniques have been reviewed and updated in light of the indicators shared in this research. Advanced URL Filtering and Advanced DNS Security identify known C2 domains associated with this activity as malicious. Koi Agentic Endpoint Security is designed to help discover every AI artifact and AI agent’s activity across the agentic endpoint, assess its risk, enforce prevention & runtime controls, and remediate violations. Security analysts can use natural language to prompt the Cortex AgentiX Threat Intel agent to extract indicators of compromise (IoCs) from this threat brief. Customers can then enrich the indicators, check for sightings in their Cortex tenant and related alerts and provide a summary of the impact to the organization. Cortex XDR and XSIAM help to prevent the threats described in this article, by employing the Malware Prevention Engine. This approach combines several layers of protection, including Advanced WildFire, Behavioral Threat Protection and the Local Analysis module, to prevent both known and unknown malware from causing harm to endpoints. Specifically, we observed out-of-the-box prevention on Windows via Behavioral Threat Protection. In addition, as part of our continuous cross-platform threat research, targeted behavioral protections for macOS and Linux environments have also been deployed in content version 2370-39889. We advise customers to upgrade agents to supported versions and the latest content update to receive the best protection Cortex Cloud Endpoint Protection can help protect organizations from threats expressed within this article. Cortex Cloud 2.1 can detect and prevent malicious operations using behavioral and AI-enabled analytics to detect when Linux endpoints, including containers and virtual machines, are targeted. Additionally, it can detect when cloud platform IAM policies associated with those targeted endpoints are being misused and alert teams when assets are vulnerable to these threats. Palo Alto Networks Software Supply Chain Security, integrated into Cortex Cloud, helps provide comprehensive visibility across the entire development ecosystem by tracking developer tools, code identities, registries and SBOMs. The solution can effectively harden development pipelines, and helps enforce out-of-the-box security policies to prevent unauthorized tampering or malicious code injection. By automating compliance reporting and governance, it can better empower organizations to mitigate application risks early and deploy secure code with confidence. Idira Secrets Manager limits blast radius by dynamically injecting them into build steps or local environments at runtime via API, CLI, or container sidecars, avoiding long-lived static configuration files on disk. By pairing Idira Privilege Cloud with Idira Secrets Manager, raw credentials bypass environment variables and process memory entirely. Secretless Manager proxies outbound connections to databases, cloud APIs, and registries, injecting credentials directly into the network stream on the fly. When supply chain worms scan your build runners, there is simply nothing in memory to steal. Idira Secrets Manager, integrated with Idira Privilege Cloud, handles automated policy-based rotation of credentials and enforces short lived secrets. Secrets requested by build pipelines are dynamically generated or rotated immediately after job completion. Math_Symbol.js / math_init.js: 9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc setup.mjs (First variant): 54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668 setup.mjs (Second variant): fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb setup.mjs.malicious (Variant of setup.mjs based on TLSH pivot): b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678 awqhnjewqjkl[.]icu - new C2 domain pulled from Ethereum contract npm-cache[.]com - active during analysis pypi-get[.]com - historical C2, returned from the Ethereum contract in the past js-mirror[.]com - historical C2, returned from the Ethereum contract in the past hxxps://npm-cache[.]com:443/router hxxp://awqhnjewqjkl[.]icu/cdn-cgi/rum? Resolver contract: 0xE1f2395ee43e45A1556EC6438a88c31B83493103 Changed C2 Transaction: 0xc55920f1bd0531b6738153068a666c080ddded47e6256f1fd980d51c0b507c91 Owner wallet: 0x55f9780e1492344b7417fa723aedc4d0b97f31cd Binance deposit pivot: 0x35477b7b2df3174B9FE8A681750A7E3fbA20F39B Getter selector: 0x53ed5143 Setter selector: 0xd3c159e5 Repository description: Shai-Hulud: Here We Go Again Commit search token: thebeautifulmarchoftime Signed record prefix: thebeautifulsnadsoftime Dune-themed name terms: sardaukar, mentat, fremen, atreides, harkonnen The sample embeds an installer for these artifacts, but we did not identify a call site on its main execution path: ~/.local/bin/gh-token-monitor.sh ~/.config/gh-token-monitor/ ~/Library/LaunchAgents/com.user.gh-token-monitor.plist ~/.config/systemd/user/gh-token-monitor.service A list of compromised packages is available at a page on our GitHub repository.
unit42.paloaltonetworks.comAug 6, 2026extracted
Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain
Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by OpenSourceMalware, which has described it as a "deliberate improvement on EtherHiding." The activity has been linked to North Korea. The packages are currently no longer available for download from npm. However, statistics show that they have been downloaded a few hundred times since they were first published on July 28, 2026 - bianira-ui (109 downloads), uploaded by an npm user named "npmuser1101" fluid-type-ui (587 downloads), uploaded by an npm user named "npmuser3002" EtherHiding was first publicly documented by Guardio Labs in October 2023 as a covert approach that involves embedding nefarious code within a smart contract on a public blockchain like BNB Smart Chain (BSC) or Ethereum. The technique heralded the "next level of bulletproof hosting" as it improves operational resilience in the face of takedowns. The use of EtherHiding by North Korean hacking groups was detailed by Google Threat Intelligence Group (GTIG) late last year in connection with Contagious Interview, a long-running campaign that aims to deceive potential targets by approaching them on LinkedIn with lucrative job opportunities and asking them to complete an assessment that leads to malware deployment. The latest development indicates that the threat actors are further refining their tactics and making it difficult for defenders to detect. "Instead of hardcoding a C2 address or hiding it in transaction calldata (as in EtherHiding), NullReceiver encodes the C2 IP directly in the bytes of the recipient address of a zero-value, zero-data Ethereum transfer," security researcher Paul McCarty said. "The malware looks up the attacker's wallet, reads the destination address of its most recent outbound transaction, and decodes a C2 IP straight from those address bytes, with no smart contract and no payload field involved." By embedding the C2 IP address in this manner, NullReceiver aims to address one of the major shortcomings of EtherHiding, which requires a fixed, publicly known destination address -- one that can be tracked by defenders as new transactions containing the payload, the C2 IP address, or the malicious script, occur for a gas fee. NullReceiver, in contrast, provides a non-existent destination address. The address "exists" only to provide a way to encode the C2 IP address within itself. This, in turn, makes attribution difficult, as it eliminates the "fixed, watchable destination." Neither of the newly discovered npm packages identified as part of the new campaign, bianira-ui and fluid-type-ui, calls a smart contract nor embeds any content within the transaction's calldata field. Instead, the JavaScript libraries leverage the new technique to extract the IP address and connect to it. The entire sequence of actions on a victim machine is as follows - Look up a hard-coded attacker wallet ("0xa322e5f3d311d3080e6f0121063e9adc2490ef1a") Find its most recent outbound transaction Read that transaction's destination address Decode a C2 IP address directly out of the address bytes by converting the first four bytes from their hexadecimal representation to their number equivalent Connect to that IP address ("166.88.134[.]62") An examination of the wallet transactions shows that the destination "To" address for each of them is the same: "0xa658863ea658863e68656c6c6f6970626f742121." While "a658863e" becomes "166.88.134[.]62," the trailing bytes "68656c6c6f6970626f742121" represent the ASCII string "helloipbot!!." As of writing, a total of 68 transactions have taken place since July 27, 2026, a day before the packages were published. What makes NullReceiver more sneaky is the absence of a fixed target and a fingerprint, not to mention the fact that the transactions are cheaper than before. A crucial difference between the two techniques is that while EtherHiding makes it possible to smuggle a full URL or script, NullReceiver can only encode a few bytes. "NullReceiver never reuses a destination," OpenSourceMalware said. "Every lookup is a brand-new, throwaway address that's never been seen before. A NullReceiver transaction carries nothing extra at all. There's no field to fingerprint, because there's no field." "Calldata costs gas per byte. EtherHiding pays for that. NullReceiver's transfer is completely blank, making it the cheapest, least conspicuous transaction shape on the network." Update OpenSourceMalware said it identified an additional set of five packages using the NullReceiver technique. These are listed below - post-css-transfer (318 downloads) scrollbar-hide-plugin (247 downloads) tailwind-anim (1,301 downloads) tailwind-animation-founder (124 downloads) tailwindcss-anim (1,357 downloads) Jenn Gile, co-founder of OpenSourceMalware, told The Hacker News that there are definite signs of cryptocurrency wallet reuse from North Korean threat actors, which made it possible to connect the newly discovered npm packages with existing campaigns. The shared infrastructure has also led to the discovery of more than 20 other compromised packages across the npm, Go, PHP ecosystems that are linked to another campaign tracked as PolinRider. "PolinRider has spent at least five months getting into thousands of developer machines any way it can: fake interviews, poisoned forks, malicious VS Code tasks, typosquatted packages," Gile said. "DPRK's goal is to compromise developer machines and accounts to silently propagate malicious code, clone repositories, and push backdoored commits without active human intervention." (The story has been updated after publication on August 6, 2026, to include additional insights from OpenSourceMalware.)
thehackernews.comAug 5, 2026extracted
AsyncAPI npm packages infected with credential-stealing malware
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. The threat actor exploited a misconfigured GitHub Actions workflow and pushed trojanized packages in the @asyncapi namespace that had a cummulative weekly download count of more than 2.25 million. Multiple security companies confirmed that on July 14, an attacker compromised two AsyncAPI GitHub repositories and injected malware into project files. “Both attacks are CI/CD pipeline compromises, not stolen npm tokens or malicious maintainers,” reads a report from Step Security. The researchers explain that "the attacker pushed commits under a placeholder git identity and let each repository's real release workflow do the publishing via npm's GitHub OIDC trusted-publisher integration." In doing so, the attacker ensured that the resulting packages had the legitimate SLSA provenance attestations, indicating that they originated from an authorized workflow. The malicious AsyncAPI packages pushed to npm are: @asyncapi/generator 3.3.1 (101k weekly downloads) @asyncapi/generator-helpers 1.1.1 (43k weekly downloads) @asyncapi/generator-components 0.7.1 (34k weekly downloads) @asyncapi/specs 6.11.2-alpha.1 and 6.11.2 (2.1 million weekly downloads) Application security company Socket notes that the first-stage implant in the published packages is an obfuscated JavaScript statement that ultimately triggers a downloader when the infected file is imported. A second-stage script, which contains configuration details and the main runtime, is retrieved from the IPFS peer-to-peer content delivery network and launched as a hidden process. Cloud and application security company Wiz says that the third-stage payload "is a 92,000-line malware framework with modular architecture," which establishes persistence on the system and communicates with the command-and-control (C2) server over several channels: HTTP, Nostr relays, Ethereum smart contracts, and a libp2p mesh network. Although the final payload uses artifact names and configuration files pointing to the Miasma backdoor seen in past supply-chain attacks [1, 2], SafeDep researchers believe that the malware is "either a private, parallel build by the same operators or a separate group that adopted the Miasma brand after the source was published." Its purpose appears to be stealing secrets, which include credentials, authentication keys, tokens, browser data, sensitive info from CI/CD systems and AI developer tools, cryptocurrency wallets, and databases. Additionally, the malware code allows it to download the Gitleaks and HackBrowserData tools to help with collecting sensitive info. However, a report from cybersecurity company Aikido notes that all these functions do not work and the data harvesting tool exits before collecting anything. Nevertheless, the researchers say that all this can be achieved manually using the shell. Ox Security also noted that the malware performs a local check for Russia, and if there’s a match, it terminates its process. As of writing, all five versions of the four malicious packages have been removed from npm, but developers should note that existing installations and lock files created during the exposure window may still contain the malicious releases. The exposure window extends to approximately four hours and seven minutes, between 07:10 and 11:18 UTC on July 14. The recommended action is to pin to known-good files, regenerate lock files, remove the hidden ‘NodeJS/sync.js’ payload, terminate all malicious processes, and rotate credentials on the impacted systems. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 15, 2026extracted
Fake crypto gift card sites are getting harder to spot
You want to turn some crypto into a gift card. You search, click a promising result, and land on a site that looks polished and legitimate: a dark theme, trust badges, and promises of instant delivery and no ID checks. You wouldn’t think to question it. But a professional-looking website isn’t proof that it’s legitimate. What’s going on Crypto gift card sites are an easy category to fake. Several legitimate platforms let people convert Bitcoin, Ethereum, and other cryptocurrencies into gift cards for major brands. They also tend to look similar: a dark theme, a bold “Pay with crypto” message, trust badges, and a grid of popular gift card deals. That makes them easy to imitate. Scammers build lookalike sites that copy the same design language and sometimes even use a name that’s only one or two letters different from a legitimate platform. They’re designed to be mistaken for the real thing by anyone scrolling quickly or clicking through from an ad or search result. The pricing is part of the deception, too. A $100 Amazon gift card for $95. A $25 Steam Wallet code for $24. A $100 Netflix gift card for $92. Those discounts don’t look unrealistic, so the scam looks very convincing. What’s the scam? The simplest scam is non-delivery. You pay, and nothing arrives because there was never any gift card to send. The website exists solely to collect crypto payments. Crypto payments generally can’t be reversed. There’s no bank to call and no chargeback if the gift card never arrives. Once your Bitcoin or Ethereum leaves your wallet, it’s usually gone. Some scams go a step further and send you a code. It just isn’t a legitimate one. Stolen gift card numbers are bought and sold on cybercriminal marketplaces, often for a fraction of their face value because they’re likely to be drained or reported before they’re redeemed. A scam site can buy those codes cheaply, resell them at what looks like a reasonable discount, and leave you with a code that never works or stops working shortly after purchase. Even if a stolen code works at first, buying it helps create demand for more stolen gift cards. There’s another reason these sites attract criminals. Crypto gift cards are commonly used to launder stolen cryptocurrency. Converting crypto into gift cards, and gift cards into goods or account balances, makes transactions harder to trace. A fake storefront doesn’t just be steal from buyers, organized crime gangs also use it to move funds. None of this requires advanced technical skills. A convincing storefront, irreversible crypto payments, and search or social media ads are often enough to lure victims. How to protect yourself Go directly to the platform’s official site by typing the address yourself, rather than clicking a link from an ad, a search result, or a message. Check the spelling of the domain character by character. Scam sites often use domains that differ from a legitimate one by just one or two letters. Don’t assume “No ID required” means a site is trustworthy. It’s a genuine feature on some platforms, but scammers use it too. Think twice before clicking Connect Wallet. Depending on the permissions you approve, it can expose more than a single payment. Be skeptical of discounted gift cards, even modest discounts. Small discounts are designed to look believable. Search for the platform’s name plus “scam” or “reviews” before you pay, especially if you found the site through an ad. Use a browser extension that blocks scam and phishing sites, such as Malwarebytes Browser Guard. It can flag a fake storefront before you land on it, even ones it hasn’t seen before. If you’ve already sent crypto to a suspicious site Treat the funds as unrecoverable, but act quickly anyway. If you have the transaction ID, check a blockchain explorer to see whether the funds were sent to a known exchange. If they were, contact the exchange’s fraud team immediately. If you connected your wallet rather than sending a payment, review and revoke any token approvals you granted. Report the site to Google Safe Browsing and Microsoft SmartScreen to help warn other people. Remember A crypto gift card site can look completely legitimate and still not be. Before you send anything, check its reputation first.
malwarebytes.comJul 13, 2026extracted
Critical SimpleHelp flaw exploited to deploy new stealer malware
Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. The SimpleHelp platform is primarily used by managed service providers (MSPs), IT departments, helpdesks, and system administrators for remote monitoring and management (RMM). Earlier this month, offensive security company Horizon3.ai published details about CVE-2026-48558, saying that the flaw could be leveraged to create highly privileged technician accounts without authentication. Exploiting the vulnerability is possible on servers using the OpenID Connect (OIDC) authentication protocol. According to the researchers, around 1,000 SimpleHelp servers exposed online were running a vulnerable configuration at the time of the disclosure. In an incident investigated by managed detection and response (MDR) provider Blackpoint, a threat actor exploited the critical authentication bypass vulnerability to establish an authenticated technician session on an internet-facing SimpleHelp server before deploying the TaskWeaver malware loader and the Djinn Stealer. Based on the findings from the Adversary Pursuit Group (APG), the company's threat intelligence and research team, both pieces of malware are new and have not been documented before. "The compromised RMM platform provided the operator with a trusted administrative channel capable of transferring files and executing commands on systems managed through the server," Blackpoint says. The investigation revealed that TaskWeaver was downloaded in the form of an obfuscated JavaScript file named ‘jquery.js’ from a temporary Cloudflare domain. TaskWeaver is a generic malware loader that fingerprints the compromised device and communicates with the command-and-control (C2) infrastructure to receive new JavaScript modules for execution. The loader then installs Djinn Stealer to collect in a single pass all the sensitive data it can find on a developer's machine, be it Windows, macOS, or Linux. Blackpoint mentions that Djinn Stealer has a particular focus on AI development tools, but targets a broad collection of developer and infrastructure credentials: Cloud provider credentials, identity services, deployment platforms, and cloud management tools. Git configuration, GitHub CLI, SSH keys, Docker credentials, Helm, infrastructure-as-code tools (Terraform, Pulumi), secrets management solutions (HashiCorp Vault), and package manager credentials. Authentication data for package registries and build tools (npm, Yarn, pnpm, Cargo, Maven, Gradle, pip, NuGet), potentially enabling access to private packages or malicious package publication. Local configuration files, authentication tokens, session data, and Model Context Protocol (MCP) configuration for AI coding assistants (Claude, Gemini, Codex, Cline, OpenCode, and Kilo). Cryptocurrency wallets and keystores associated with multiple desktop cryptocurrency clients (Bitcoin, Litecoin, Dogecoin, Dash, Ethereum, Monero, Zcash, Exodus, Atomic Wallet, and Electrum). Browser data, shell history, SSH configuration, PGP keys, database client configuration, operating system information, and other user files. On Linux, the malware also attempts to read the /proc/ /cmdline and /proc/ /environ virtual files that contain information about a running process, including secrets (e.g., API keys, credentials, session tokens, file paths, URLs). Blackpoint researchers warn that stealing credentials for AI development tooling, which is widely used for coding and software development, could allow attackers to inherit the AI assistant's authorized access to repositories, cloud resources, databases, and APIs. “Many of these tools rely on the Model Context Protocol (MCP) to connect an AI assistant to external tools and data on the developer's behalf, including source repositories, databases, cloud accounts, and internal APIs,” explain the researchers. “The settings and tokens for those connections are stored locally in files such as ~/.claude/mcp.json. Stealing them can grant an attacker the same downstream access the developer extended to their AI agent, reaching well beyond the AI service itself.” Before exfiltrating the sensitive data to the C2 server, Djinn Stealer packs it into a TAR archive, then compresses it with GZIP, and encrypts it with an AES-256-GCM key protected by an RSA-2048 public key embedded in TaskWeaver. Active exploitation of CVE-2026-48558 should serve as an urgent call for system administrators to prioritize updating SimpleHelp instances to the latest versions. It is also recommended to invalidate technician sessions that they don’t recognize. If breached, rotate all credentials and API keys. Blackpoint's report provides indicators of compromise (IoCs) observed in the investigated intrusion, which include hashes for the TaskWeaver loader and Djinn Stealer, network infrastructure, host and behavioral indicators. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 29, 2026extracted
GTA 6 early access offers are taking gamers’ crypto
GTA 6 early access offers are taking gamers’ crypto Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early access for a few hundred dollars in cryptocurrency, ask buyers to enter a payment code, and claim the game will then unlock. These offers deliver nothing. “Any site claiming to sell GTA 6 early access is not authorized by Rockstar Games and should be treated as fraudulent unless Rockstar announces it through official channels. You pay, you get nothing, and because the payment is made in cryptocurrency, there’s usually no way to get your money back,” Stefan Dasic, Senior Malware Research Engineer at Malwarebytes, explained. Fake GTA 6 VIP early access page (Source: Malwarebytes) How the scam pages operate The websites carry a premium and exclusive look. They feature neon Vice City artwork, GTA 6 logos, luxury cars, and AI-generated images. The sales pitch tends to use language such as “VIP Digital Access” or “Exclusive Early Access Preview.” One such site charged $250 and accepted only Bitcoin, USDT, or Ethereum. The closing step shows the mechanics. After sending cryptocurrency, victims are told to wait for payment confirmation and then enter their transaction ID to unlock the download. The pages include QR codes, payment verification messages, and a large download button. The game itself never appears. Two factors raise the stakes for victims. Cryptocurrency payments generally cannot be reversed, with no chargeback process and no fraud department to contact. Once the money is sent, it’s gone. There is also no product at any point, since GTA 6 remains available only through Rockstar. Why the franchise draws scammers Grand Theft Auto ranks among the most successful gaming franchises ever created. Take-Two Interactive reports that the series has sold more than 465 million copies worldwide, with GTA 5 alone accounting for more than 225 million of those sales. GTA 5 launched in September 2013, and GTA 6 is scheduled for November 19, 2026, a gap of 13 years between releases. Multiple delays and years of speculation have left millions of fans searching for any news, leak, preview, or chance at early access. Scammers exploit that excitement. Why people fall for it Several factors make the scheme effective. Strong desire for the game pushes people toward reasons to believe an offer is real. Early access programs, beta tests, founder’s packs, and deluxe editions exist throughout gaming, so a page selling “VIP access” can sound plausible. Phrases promising exclusivity and quick unlocks encourage fast decisions. Polished artwork and a smooth payment flow lend a sense of legitimacy. Cryptocurrency payment has grown common among gamers, which makes one of the strongest warning signs feel routine. How to stay safe One fact protects buyers from every GTA 6 early-access scam. GTA 6 remains unavailable to buy, download, or play early through unofficial websites. Rockstar is selling pre-orders. Rockstar has announced that official pre-orders begin on June 25 through digital storefronts and select retailers. Any website offering early access, VIP access, secret downloads, or a playable copy ahead of release lacks authorization. Gamers can protect themselves by sticking to official pre-orders through authorized retailers and storefronts, treating any gaming offer that requires cryptocurrency with caution, and getting GTA 6 news directly from Rockstar Games and Take-Two Interactive. Claims of exclusive access in ads, social media posts, videos, and comment sections deserve skepticism. A pause before sending money gives time to spot the trick. What the researcher expects next The Malwarebytes researcher who tracked the scam pages, expects the volume of GTA 6 fraud to grow. He points to hosting services that leave malicious sites online after abuse reports come in. “I definitely expect to see a rise in GTA6 related scams. Malicious actors are registering these websites with hosting services that don’t always follow up with abuse reports and don’t remove the malicious content. With all the GTA 6 hype, I am inclined to believe that we will start seeing more and more innovative pages that will try to lure people into getting the game cheaply, maybe some in game items etc. My suggestion for the gamers is to purchase digital services only through authorized sellers, as that’s the safest route,” Dasic told Help Net Security.
helpnetsecurity.comJun 23, 2026extracted
GTA 6 early access is nothing but a scam
A new wave of scam websites is offering something millions of people want: a way to play Grand Theft Auto VI before it comes out. “Get GTA 6 before everyone else.” “Buy VIP early access.” Pay a few hundred dollars in cryptocurrency, enter a payment code, and supposedly unlock the game. But it’s a scam. Any site claiming to sell GTA 6 early access is not authorized by Rockstar Games and should be treated as fraudulent unless Rockstar announces it through official channels. You pay, you get nothing, and because the payment is made in cryptocurrency, there’s usually no way to get your money back. Here’s why these pages exist, why they work, and how to avoid them. What these pages look like They’re designed to look premium and exclusive. Think neon Vice City artwork, GTA 6 logos, luxury cars, and glamorous AI-generated images. The pitch is usually some version of “VIP Digital Access” or “Exclusive Early Access Preview.” The example we examined charged $250 and accepted only Bitcoin, USDT, or Ethereum. The final step reveals what’s really happening. After sending cryptocurrency, victims are told to wait for payment confirmation and then enter their transaction ID to “unlock” the download. There are QR codes, payment verification messages, and a large DOWNLOAD button. But there is no game. Two details make this more than an ordinary rip-off. First, cryptocurrency payments generally can’t be reversed. There’s no chargeback process and no fraud department to call. Once you send the money, it’s gone. Second, there is no product at all. This isn’t a case of receiving something different from what was promised. GTA 6 is not available outside Rockstar, so there is nothing for these sites to deliver. Why GTA 6 is the perfect bait To understand why these scams are appearing now, you need to understand how enormous GTA is. Grand Theft Auto is one of the most successful gaming franchises ever created. According to publisher Take-Two Interactive, the series has sold more than 465 million copies worldwide, with GTA 5 alone accounting for more than 225 million of those sales. When Rockstar announced a sequel, anticipation was inevitable. Then came the waiting. GTA 5 launched in September 2013, and GTA 6 is now scheduled for November 19, 2026.That’s a 13-year gap between releases. Add multiple delays and years of speculation, and you’ve got millions of fans eagerly looking for any news, leak, preview, or chance to get early access. Scammers simply exploit that excitement. Why people fall for it Scams like this work because they mix something people want with tactics designed to create urgency. Desire overrides suspicion. When people want something badly enough, they’re more likely to look for reasons to believe an offer is real than reasons to doubt it. Early access is a real thing in gaming. Players are used to beta tests, founder’s packs, deluxe editions, and early-access programs. A page selling “VIP access” doesn’t automatically sound suspicious because legitimate offers often use similar language. Scarcity and urgency short-circuit caution. “Before everyone else.” “Exclusive.” “Unlock in one minute.” These are phrases designed to encourage quick decisions before people stop to think. The sites look professional. Good artwork, polished design, and a smooth payment flow can make a scam feel legitimate, even when the offer itself doesn’t stand up to scrutiny. Payment by crypto is becoming more common. It may feel routine to many gamers, but it’s one of the biggest warning signs. Unlike a credit card payment, crypto transactions generally can’t be reversed, so scammers prefer them. None of this makes a victim foolish. It makes them human, and targeted by people who understand exactly how to manipulate them. How to protect yourself One fact protects you from every GTA 6 early-access scam: GTA 6 is not available to buy, download, or play early through unofficial websites. Rockstar is selling pre-orders, not early access. It’s scheduled to launch on November 19, 2026, and Rockstar has announced that official pre-orders begin on June 25 through digital storefronts and select retailers. That makes spotting scams easy. If a website claims to offer early access, VIP access, secret downloads, or a playable copy of GTA 6 before release, it isn’t an authorized seller. Rockstar is offering pre-orders only. Until then: Stick to official GTA 6 pre-orders through authorized retailers and storefronts. Any site offering early access, exclusive downloads, or playable versions before release is likely a scam. Be wary of any gaming offer that requires payment in cryptocurrency. Get GTA 6 news directly from Rockstar Games and Take-Two Interactive. Treat “exclusive access” claims in ads, social media posts, videos, and comment sections with skepticism. Pause before sending money. If an offer sounds like a way to skip the line, that’s exactly why scammers are using it. Malwarebytes Browser Guard is free and can help by blocking malicious websites, scam pages, and other online threats while you browse. Remember Nobody can sell you a legitimate copy of GTA 6 before Rockstar does. If a website claims otherwise, it’s not offering exclusive access. It’s trying to take your money. When GTA 6 finally launches, it will be available through the same trusted stores gamers already use. Until then, any site promising a head start is promising something it can’t deliver.
malwarebytes.comJun 23, 2026extracted
JaredFromSubway MEV bot hacked in $15 million crypto theft
The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities. The drain was detected on Saturday by blockchain security firm Blockaid, and today, JaredFromSubway confirmed that the attacker used fake pools and tokens to trick the bot into approving helper contracts. According to Blockaid, the attacker deployed contracts designed to appear as profitable MEV opportunities to JaredFromSubway's automated execution system. The bot automatically analyzed routes and trade opportunities that seemed financially rewarding. It then generated the transactions needed to execute them, granting ERC-20 token approvals to contracts controlled by the attacker. It appears that the attacker planned the heist carefully, as early transactions served as harmless tests to help confirm the bot’s action routines. Later, the threat actor changed the route so that the allowance was not consumed or revoked after the bot granted approvals. The attacker accumulated valid spending permissions without immediately using them, reaching up to 92.1614 WETH approved to an attacker-controlled helper contract. Finally, the attacker used the open approvals to withdraw WETH, USDC, and USDT from the JaredFromSubway MEV bot contract via the transferFrom function. Karma slaps back MEV bots are ultra-fast automated trading systems that scan Ethereum and other blockchains for opportunities to make money by exploiting the order and timing of transactions before they are included in a block. JaredFromSubway is a private MEV operation with no publicly available code, known as one of Ethereum's most aggressive and visible “sandwich”-bot operations. In a sandwich attack, the bot detects a user's pending trade, places a buy order immediately before it, and then sells immediately afterward, profiting from the price movement caused by the victim's transaction. The practice is controversial because it often results in worse prices for regular traders while generating profits for the bot operator. Initially, JaredFromSubway offered a $3 million bounty to the attacker for the full return of the stolen funds, promising no further action would be taken. After receiving no response, JaredFromSubway increased the bounty to $7.5 million for the return of just 50% of the stolen amount, with $1 million to be given to the community. JaredFromSubway is also negotiating with "a white-hat hacking group" on the stolen $15 million but there is no confirmation of a deal yet. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 22, 2026extracted
USB worm spreads crypto-stealing malware via Windows shortcut files
Threat actors targeting cryptocurrency wallets have been distributing clipboard-stealing malware with self-spreading capabilities and using the Tor network to conceal communication. The campaign has been active since at least February and relies on LNK (shortcut) files on USB drives to push clipper malware that monitors clipboard contents and replaces cryptocurrency wallet addresses with ones controlled by the attacker. Additionally, it monitors for seed phrases and private keys, and can capture screenshots that are exfiltrated over Tor. Infection and worm propagation Microsoft says that the infection process starts with the victim opening the LNK file, triggering the malware on the USB drive. Additional payloads are staged from a .ONION address. A local scan searches for document files on the system. When such files are found, the malware hides the originals and replaces them with malicious shortcuts bearing the same names. This causes the malware to execute when users attempt to open the documents. The worm creates a scheduled task that monitors for newly connected USB storage devices. When a removable drive is connected, the malware it copies itself to the device and creates additional malicious shortcut files. Data stealer The stealer component in the malware executes after checking that Task Manager is inactive, establishing communications with the command-and-control (C2) host using a Tor executable (ugate.exe). Every half a second, the malware checks the clipboard for the following data: 12-word BIP39 seed phrases 24-word BIP39 seed phrases Ethereum private keys Bitcoin WIF keys Bitcoin legacy, P2SH, Bech32, and Taproot wallet addresses Tron wallet addresses Monero wallet addresses The targeted addresses are chosen based on their starting digits or characters to partially resemble the attackers’ wallet addresses, to lower the chance of the user discovering the fraud at a quick glance. Apart from monitoring the clipboard, the malware also captures five screenshots of the victim’s screen every ten seconds and sends them to the C2 using the curl tool. According to Microsoft, there is also support for remote code execution, which can be triggered by a C2 EVAL instruction. Specifically, the malware downloads JavaScript content into a file named ‘cfile,’ and executes it on the infected machine. The researchers say that the strongest indicators of an infection are behavioral rather than signature-based, and recommend monitoring for process activity on wscript.exe and cscript.exe, unexpected launches of curl, PowerShell, and cmd.exe, along with unusual child processes. Also, connections to ‘localhost:9050’ and Tor proxy activity are red flags associated with this campaign. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 18, 2026extracted
Zombie linkages are keeping expired domains trusted for years
Zombie linkages are keeping expired domains trusted for years Domains expire, get transferred, and return to the market every day. The systems connected to those domains can continue trusting the original owner long after control has changed. Researchers at USC and the University of Twente examined this problem in three widely used systems: Web PKI, Maven Central, and Ethereum Name Service. They use the term “zombie linkages” to describe lingering trust records that remain active after the original domain owner no longer controls the domain. The problem creates security risks for browser infrastructure, software supply chains, and cryptocurrency naming systems because DNS names are increasingly used as proof of identity. HTTPS certificates outlive domain ownership Web PKI is the infrastructure browsers use to verify HTTPS websites. Certificate authorities issue TLS certificates that connect a domain name to a cryptographic key. Browsers rely on those certificates to confirm that a website belongs to the domain displayed in the address bar. The researchers found that some certificates remain active. after domains expire or change ownership. More than 192,000 expired-domain certificates were still being served months after DNS name death. Another 7,300 certificates continued being served after the domain had been registered again by a new owner. That creates a period where a new registrant controls the domain, and another party may still operate a server with a certificate browsers trust. An attacker who gains control of traffic to that server could potentially impersonate the domain using a still-valid certificate. Roughly 3% of TLS certificates tied to newly registered domains remained linked to expired or transferred domains during the measurement period. Only 4.3% of zombie certificates were revoked before expiration. Certificate expiration acts as the main limit on how long those records remain usable. Most certificates stayed valid until they expired naturally. Expired domains can leave Maven namespaces active The same persistence problem appears in software repositories. Maven Central is one of the primary repositories for Java software packages. Enterprise applications and developer tools automatically download libraries and updates from it during software builds. The repository organizes software packages using names linked to internet domains. The researchers identified 31,853 Maven Central namespaces in their dataset. Of those, 4,842, or 15.2%, were tied to expired or transferred domains. Publishing activity continued in hundreds of those namespaces after the original ownership period had ended. Among 4,053 outdated namespaces with known start dates, 547 published new package versions after the domains lost their original owners. They also found that 214 namespaces continued publishing packages after the domain had been registered again by another owner. That creates a possible route for supply-chain compromise. Applications that automatically download updates from affected namespaces could receive packages published after domain ownership changed. Maven Central package versions are immutable once published. A namespace and its package history can remain active indefinitely even after the original domain ownership period ends. ENS mappings remain active for years Cryptocurrency naming systems show the same pattern. Ethereum Name Service, or ENS, connects readable names to cryptocurrency wallet addresses. The system gives blockchain users domain-like names tied to crypto accounts. The researchers examined two ENS approaches. ENS On-chain validates domain ownership once and stores the mapping on Ethereum. Those records remain active until manually replaced. The researchers found that 425 of 1,882 active ENS On-chain linkages, or 23.8%, were outdated. They also found that none of the outdated ENS On-chain linkages had ever been reclaimed. The median outdated ENS On-chain linkage was 1.9 years old. There is currently no practical mechanism to revoke those mappings automatically. A new domain owner must repeat the linkage process to replace the old record. That leaves ENS On-chain exposed to domain reuse problems. An outdated ENS mapping can remain active indefinitely even after a domain changes ownership and is registered again by another party. Users relying on the old mapping could potentially send cryptocurrency payments to the wrong wallet address.
helpnetsecurity.comMay 15, 2026extracted
Google Slashes Quantum Resource Requirements for Breaking Cryptocurrency Encryption
Google’s Quantum AI research division has published a whitepaper warning that the cryptographic foundations of most major cryptocurrencies are more vulnerable to quantum attacks than previously believed. The findings suggest that the timeline for when quantum computers could pose a real threat to blockchain security may be shorter than previously assumed. At issue is elliptic curve cryptography (ECC), the mathematical system that secures Bitcoin, Ethereum, and most other blockchains. Quantum computers running Shor’s algorithm can in theory break ECC, but until now the consensus was that doing so would require a very powerful quantum machine. Google’s new estimates significantly lower the threshold. The company’s researchers have designed quantum circuits capable of breaking the 256-bit elliptic curve discrete logarithm problem (ECDLP-256) used by cryptocurrencies. Specifically, they achieved this using fewer than 1,200 logical qubits and around 90 million Toffoli gate operations, which roughly represents a 20-fold reduction in the quantum resources previously thought necessary. The researchers estimate the attack could be executed in minutes on a machine with fewer than 500,000 physical qubits (down from roughly 10 million). This is still beyond today’s hardware, but the findings significantly shorten the timeline for when quantum computers could break current cryptography. The news comes just days after Google moved up its timeline for transitioning to post-quantum cryptography, setting a 2029 target after faster-than-expected advances in quantum computing. The tech giant has urged other major industry players, including the cryptocurrency community, to follow suit. [ Read: Quantum Decryption of RSA Is Much Closer Than Expected ] Notably, Google chose not to publish the actual quantum circuits behind their newest estimates, instead releasing a zero-knowledge proof: a cryptographic technique that lets independent researchers verify that the claims are mathematically sound without Google having to hand over details that could be used to reproduce the attack. The approach, developed in coordination with the US government, is being proposed as a model for how the quantum research community should handle sensitive vulnerability disclosures going forward. Related: Dell and HP Roll Out Quantum-Resistant Device Security Related: Cyber Insights 2026: Quantum Computing and the Potential Synergy With Advanced AI Related: Google Working Towards Quantum-Safe Chrome HTTPS Certificates
securityweek.comMar 31, 2026extracted
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to. All of it below. Let's go. ⚡ Threat of the Week Citrix Flaw Comes Under Active Exploitation — A critical security flaw in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-3055, CVSS score: 9.3) has come under active exploitation as of March 27, 2026. The vulnerability refers to a case of insufficient input validation leading to memory overread, which an attacker could exploit to leak potentially sensitive information. Per Citrix, successful exploitation of the flaw hinges on the appliance being configured as a SAML Identity Provider (SAML IDP). Your Engineers Are Drowning in Tools — Here's the Data Chainguard surveyed 1,200 engineers and tech leaders for their 2026 Engineering Reality Report. AI is buying back time but also introducing new security concerns, while technical debt, tool sprawl, and burnout keep dragging teams down. 72% say time pressure blocks new feature work; 88% report productivity loss from too many tools. Get the Full Report ➝ 🔔 Top News FBI Confirms Hack of Director Kash Patel's Personal Email Account — The U.S. Federal Bureau of Investigation (FBI) confirmed that threat actors gained access to an email account belonging to FBI Director Kash Patel, but said no government information has been compromised. The Iran-linked hacker group Handala claimed responsibility for the hack, releasing files allegedly representing photos, emails, and classified documents taken from the FBI director's inbox. "The so-called 'impenetrable' systems of the FBI were brought to their knees within hours by our team," the hackers wrote. It's unclear when the account was hacked. The U.S. government, which recently took down multiple sites operated by Iranian state actors, said it's offering up to $10 million for information on threat groups like Parsian Afzar Rayan Borna and Handala. Parsian Afzar Rayan Borna is an IT company that's been implicated in Iran's disinformation and surveillance campaigns. The company is assessed to be linked to Banished Kitten, an Iran-nexus adversary active since at least 2008 and operates the Homeland Justice and Handala Hack personas. Red Menshen Uses Stealthy BPFDoor to Spy on Telecom Networks — A China-linked state-sponsored threat actor known as Red Menshen has deployed kernel implants and passive backdoors deep within telecommunication backbone infrastructure worldwide for long-term persistence. The implants have been fittingly described as sleeper cells that lie dormant and blend into target environments, but spring into action upon receiving a magic packet by quietly monitoring network traffic instead of opening a visible connection. Initial access is usually gained by exploiting known vulnerabilities in edge networking devices and VPN products or by leveraging compromised accounts. Once inside, the threat actor maintains long-term access by deploying tools like BPFdoor. Some BPFdoor samples mimic bare-metal infrastructure, posing as legitimate enterprise platforms to blend into operational noise. Others spoof core containerization components. By embedding the implant deep below traditional visibility layers, the goal is to significantly complicate detection efforts. Rapid7 has released a scanning script designed to detect known BPFDoor variants across Linux environments. GlassWorm Evolves to Drop Extension-Based Stealer — A new evolution of the GlassWorm campaign is delivering a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. "It logs keystrokes, dumps cookies and session tokens, captures screenshots, and takes commands from a C2 server hidden in a Solana blockchain memo," Aikido said. GlassWorm is the moniker assigned to a persistent campaign that obtains an initial foothold through rogue packages published across npm, PyPI, GitHub, and the Open VSX marketplace. In addition, the operators are known to compromise the accounts of project maintainers to push poisoned updates. Russian Hacker Sentenced to 2 Years for TA551-Linked Ransomware Attacks — Ilya Angelov, a 40-year-old Russian national, was sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Angelov, who went by the online aliases "milan" and "okart," is said to have co-managed a Russia-based cybercriminal group known as TA551 (aka ATK236, G0127, Gold Cabin, Hive0106, Mario Kart, Monster Libra, Shathak, and UNC2420) between 2017 and 2021. The attacks leveraged spam emails to compromise systems and rope them into a botnet that other cybercriminals used to break into corporate systems and deploy ransomware. This included threat actors affiliated with BitPaymer and IcedID. FCC Bans New Foreign-Made Routers Over Security Risks — The U.S. Federal Communications Commission (FCC) said it was banning the import of new, foreign-made consumer routers, citing "unacceptable" risks to cyber and national security. To that end, all consumer-grade routers manufactured in foreign countries have been added to the Covered List, unless they have been granted a Conditional Approval by the Department of War (DoW) or the Department of Homeland Security (DHS) after determining that they do not pose any risks. The development comes as the Indian government appears to be preparing to bar Chinese CCTV product makers, such as Hikvision, Dahua, and TP-Link, from selling their cameras from April 1, 2026, to tighten oversight under the Standardisation Testing and Quality Certification (STQC) rules, the Economic Times reported. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-3055 (Citrix NetScaler ADC and NetScaler Gateway), CVE-2025-62843, CVE-2025-62844, CVE-2025-62845, CVE-2025-62846 (QNAP), CVE-2026-22898 (QNAP QVR Pro), CVE-2026-4673, CVE-2026-4677, CVE-2026-4674 (Google Chrome), CVE-2026-4404 (GoHarbor Harbor), CVE-2026-1995 (IDrive for Windows), CVE-2026-4681 (Windchill and FlexPLM), CVE-2025-15517, CVE-2025-15518, CVE-2025-15519, CVE-2025-15605, CVE-2025-62673 (TP-Link),CVE-2025-66176 (HikVision), CVE-2026-32647 (NGINX Open Source and NGINX Plus), CVE-2026-22765, CVE-2026-22766 (Dell Wyse Management Suite), CVE-2026-21637, CVE-2026-21710 (Node.js), CVE-2026-25185 aka LnkMeMaybe (Microsoft), CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591 (BIND 9), CVE-2026-2931 (Amelia Booking plugin), CVE-2026-33656 (EspoCRM), CVE-2026-3608 (Kea), CVE-2026-20817 (Microsoft Windows Error Reporting), CVE-2025-33244 (NVIDIA Apex), CVE-2026-32746 (Synology DiskStation Manager), and CVE-2026-3098 (Smart Slider 3 plugin). 🎥 Cybersecurity Webinars Your Identity Program Is Mature. So Why Are You Still Getting Breached? → Your identity program is mature. Yet hundreds of apps still operate outside it. New 2026 Ponemon research from 600+ security leaders shows exactly how big that gap is and what it costs. Now, AI agents are making it worse. This webinar breaks down the findings and shows you what to fix first. Everyone Agrees AI Agents Need Identity. Almost Nobody Knows How to Do It → Everyone agrees AI agents need identity. Few know how to actually do it. This session skips the theory and shows you what a real production deployment looks like, including how to give agents strong identities, see exactly what they're doing, and control how they behave. 📰 Around the Cyber World Fortinet FortiClient EMS Flaw Comes Under Attack — A recently patched security flaw affecting Fortinet FortiClient EMS has come under active exploitation in the wild as of March 24, 2026. The vulnerability in question is CVE-2026-21643 (CVSS score: 9.1), a critical SQL injection that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. The issue was addressed by Fortinet last month in FortiClient EMS version 7.4.5. "Attackers can smuggle SQL statements through the 'Site'-header inside an HTTP request," Defused Cyber said. Nearly 1,000 FortiClient EMS are publicly exposed. Meta Disrupts Influence Operation Linked to Iran — Meta said it disrupted an influence operation linked to Iran that employed "sophisticated fake personas" on Instagram to build relationships with U.S. users before sending political messaging. The network used accounts posing as journalists, commentators, and ordinary people to engage users and gradually introduce political narratives. A second layer of accounts amplified posts to help spread the messaging. Armenian National Extradited to U.S. in Connection with RedLine Stealer Operations — An Armenian national has been extradited to the United States over his alleged role in the administration of the RedLine infostealer malware. Hambardzum Minasyan, per court documents, allegedly developed and managed the stealer, while unnamed conspirators maintained digital infrastructure, including the command-and-control (C2) servers and administrative panels to enable the deployment of the malware by affiliates, and collected payments from the affiliates. "They allegedly responded to questions and requests from actual and potential RedLine affiliates, conspired with each other and affiliates to steal and possess the financial information, including access devices, of victims, and laundered the proceeds of cybercrime through cryptocurrency exchanges and other means," the U.S. Justice Department said. Minasyan has also been accused of registering two virtual private servers to host portions of RedLine's infrastructure, as well as two internet domains in support of the scheme, repositories on an online file sharing site to distribute the stealer to affiliates, and registering a cryptocurrency account in November 2021 to receive payments. RedLine Stealer was disrupted in an international law enforcement operation in October 2024. Minasyan has been charged with conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. If convicted, he faces up to 10 years in prison for access device fraud and up to 20 years in prison for the other two counts. In June 2025, the U.S. Department of State announced a $10 million reward for information on Maxim Alexandrovich Rudometov, who is believed to be the main developer and administrator of RedLine. New Android Malware "Android God Mode" Abuses Accessibility Permissions — The Indian Cybercrime Coordination Centre (I4C) has issued an advisory, alerting users of a new Android malware called Android God Mode that abuses its permissions to accessibility services to seize control of infected devices. The malware is propagated via dropper apps that masquerade as banking, public, and utility services such as SBI YONO, Jivan Parman Patra, and RTO Challan, indicating that the campaign's focus is on targeting Indian users. "By coercing users into granting elevated Android permissions, these threats achieve near-total control over the device, enabling stealthy overlay attacks and the real-time theft of sensitive financial and personal information," the I4C said. The malware is distributed in the form of links or APK files shared through WhatsApp. Once installed, it abuses Android's accessibility services to grant itself additional permissions to harvest incoming SMS messages, send messages on the victim's behalf, access contact lists, initiate fraudulent call forwarding, and take pictures using the device's camera. Android 17 Beta Gains New Security Features — To improve security against code injection attacks, Android now enforces that dynamically loaded native libraries must be read-only. If your app targets Android 17 or higher, all native files loaded using System.load() must be marked as read-only beforehand. Another new addition is the support for Post-Quantum Cryptography (PQC) through the new v3.2 APK Signature Scheme. This scheme utilizes a hybrid approach, combining a classical signature with an ML-DSA signature. China-Linked Actors Deliver Mofu Loader and KIVARS — In recent months, Chinese-affiliated espionage clusters like DRBControl have employed DLL side-loading techniques to deliver Mofu Loader – a malware previously attributed to GroundPeony – which then drops a C++ backdoor capable of executing commands issued by an attacker-controlled server. Last year, companies and organizations in Japan and Taiwan have also been targeted by variants of a backdoor called KIVARS, which is tied to a Chinese hacking group called BlackTech. Automated Traffic Outpaces Human Traffic — HUMAN Security found that automated traffic grew eight times faster than human traffic year-over-year. "In 2025, automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period," the company said. The cybersecurity company noted that its customers experienced more than 400,000 attempted post-login account compromise attacks, more than quadruple that of 2024. U.S. Accuses China of Backing Scam Compounds — A senior U.S. official accused Beijing of implicitly backing Chinese criminal syndicates running cyber scam compounds across Southeast Asia. Speaking during a Joint Economic Committee congressional hearing about U.S. efforts to combat digital scams, Reva Price, commissioner with the U.S.-China Economic and Security Review Commission, said links have been unearthed between scam centers and the Chinese government's Belt and Road Initiative. Chinese criminal syndicates have "invested in projects linked to China's Belt and Road Initiative alongside China's state-owned enterprises," she said, adding that they "have also seen criminal leaders who appear to have gotten a pass by promoting messaging and other activities aligned with Chinese Communist Party priorities." Scam centers in Southeast Asia are often operated by Chinese crime syndicates that lure people into the region with enticing job opportunities and coerce them into participating in pig butchering or romance baiting scams by confiscating their passports and subjecting them to torture. Exploitation Against Oracle WebLogic Servers — A recently disclosed security flaw in Oracle WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts almost immediately after public exploit code was released, demonstrating how software flaws are being rapidly weaponized by bad actors. The activity, detected by CloudSEK against its honeypots, also leveraged other WebLogic flaws (CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, and CVE-2017-10271), as well as flaws impacting Hikvision and PHPUnit, indicating a spray and pray approach. "Attackers predominantly utilized rented Virtual Private Servers (VPS) from common hosting providers like DigitalOcean and HOSTGLOBAL.PLUS," the company said. "The overall activity was characterized by high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic." Security Flaws in Cisco Catalyst 9300 Series Switches — Details have emerged about now-patched vulnerabilities in Cisco Catalyst 9300 Series switches (CVE-2026-20110, CVE-2026-20112, CVE-2026-20113, and CVE-2026-20114) that could result in privilege escalation, operational denial-of-service, stored cross-site scripting (XSS), and CRLF injection. "Collectively, these vulnerabilities introduce risks to administrative trust boundaries, service availability, session integrity, and system log reliability – affecting both operational continuity and security monitoring capabilities," OPSWAT said. "CVE-2026-20114 and CVE-2026-20110 are the most operationally impactful when chained. A low-privilege Web UI user can escalate access and invoke a maintenance-mode operation, resulting in full denial of service that may require physical intervention to restore." The issues were patched by Cisco last week. Financial Institution Targeted by BRUSHWORM and BRUSHLOGGER — A modular backdoor with USB-based spreading capabilities was used in an attack targeting an unnamed South Asian financial institution, according to findings from Elastic Security Labs. The malware, dubbed BRUSHWORM, is one of the two malware components identified in the victim's infrastructure, the other being a DLL keylogger referred to as BRUSHLOGGER. "BRUSHWORM features anti-analysis checks, AES-CBC encrypted configuration, scheduled task persistence, modular DLL payload downloading, USB worm propagation, and broad file theft targeting documents, spreadsheets, email archives, and source code," security researcher Salim Bitam said. BRUSHWORM is also responsible for running basic anti-analysis checks, maintaining persistence, command-and-control (C2) communication, and downloading additional modular payloads. BRUSHLOGGER augments the backdoor by capturing system-wide keystrokes via a simple Windows keyboard hook and logging the active window context for each keystroke session. "Neither binary employs meaningful code obfuscation, packing, or advanced anti-analysis techniques," Elastic said. "Given the absence of a kill switch, the use of free dynamic DNS servers in testing versions, and some coding mistakes, we assess with moderate confidence that the author is relatively inexperienced and may have leveraged AI code-generation tools during development without fully reviewing the output." U.K. Sanctions Xinbi — The U.K.'s Foreign, Commonwealth and Development Office (FCDO) has sanctioned Xinbi, a Chinese-language guarantee marketplace accused of enabling large-scale online fraud and human exploitation by supporting #8 Park (aka Legend Park), an industrial-scale scam compound in Cambodia notorious for large-scale pig butchering scams and forced labor of trafficked workers. The U.K. is the first country to sanction Xinbi. The move is designed to isolate Xinbi from the legitimate crypto ecosystem and disrupt its operations. Xinbi is estimated to have processed over $19.9 billion between 2021 and 2025. "The platform facilitates everything from 'Black U' money laundering and unlicensed OTC trades to the sale of compromised personal databases and scam infrastructure," Chainalysis said. "In the face of previous takedowns, Xinbi demonstrated significant resilience by rapidly migrating to the SafeW messaging app and launching its own proprietary payment app, XinbiPay. This evolution highlights the challenges around pursuing illicit services as they build custom financial rails to insulate themselves from platform-level disruptions." According to a report published by Elliptic last month, #8 Park is linked to a company named Legend Innovation, which, in turn, has ties to Prince Group, whose chairman, Chen Zhi, was arrested and extradited to China in connection with a crackdown on a large-scale fraud operation. #8 Park is also tied to HuiOne Group, with its payment business, HuiOne Pay (later rebranded as H-PAY), which operates a physical store within the compound. There has since been a sharp decline in incoming payments to merchants operating inside the compound beginning around February 9, 2026, with transactions almost entirely ceasing by February 13. What is Tsundere? — Tsundere is a botnet that enables system fingerprinting and arbitrary command execution on victim machines. It's notable for the use of a technique called EtherHiding to retrieve command-and-control (C2) servers stored in smart contracts on the Ethereum blockchain. The malware is suspected to be a Malware-as-a-Service (MaaS) offering of Russian origin, owing to logic that checks whether the infected host is located in a CIS country, including Ukraine, and terminates execution if so. Most recently, the use of the botnet has been linked to the Iranian state-sponsored actor MuddyWater. Jailbreaking, a Continued Risk to LLMs — New research from Palo Alto Networks Unit 42 has uncovered that prompt jailbreaking remains a practical risk to large language models (LLMs) and that a genetic algorithm-based fuzzing approach can be used to generate meaning-preserving prompt variants to trigger policy-violating outcomes against both closed-source and open-weight pre-trained models. "The broader implication is that guardrails should be treated as probabilistic controls that require continuous adversarial evaluation, not as definitive security boundaries," Unit 42 said. The findings reinforce that security for LLM applications cannot rely on a single layer, necessitating that organizations define and enforce application scope, use robust, multi-signal content controls, treat user input as untrusted and isolate it from privileged instructions, validate outputs against scope and policy, and monitor for misuse, and apply standard security controls, such as authentication, rate limiting, and and least privilege tool permissions. SEO Campaign Delivers AsyncRAT — Since October 2025, an unknown threat actor has been running an active SEO poisoning campaign, using impersonation sites of over 25 popular applications to direct victims to malicious installers, including VLC Media Player, OBS Studio, KMS Tools, and CrosshairX. The campaign uses ScreenConnect, a legitimate remote management tool, to establish initial access and to deliver AsyncRAT. "Most notable in this campaign is the RAT’s added cryptocurrency clipper, dynamic plugin system capable of loading arbitrary capabilities at runtime, and a geo-fencing mechanism that deliberately excludes targets across the Middle East, North Africa, and Central Asia," NCC Group said. AsyncRAT has also been delivered as part of a series of attacks on Libyan organizations between November 2025 and February 2026. The attacks targeted an oil refinery, a telecoms organization, and a state institution. "AsyncRAT is a remote access Trojan with a variety of capabilities, including keylogging, screen capture, and remote command execution capabilities, making it ideal for use in intelligence gathering and espionage attacks," Symantec and Carbon Black said. "It is also modular, meaning it can be updated and customized, which is attractive for attackers." Nigerian National Sentenced to 7 Years in Prison — A Nigerian man has been sentenced to more than seven years in a U.S. prison for his role in a scheme that broke into business email accounts and tricked victims into sending millions of dollars to fraudulent bank accounts. James Junior Aliyu, 31, received a 90-month prison sentence for conspiracy to commit wire fraud and money laundering. The court also ordered Aliyu to forfeit $1.2 million and repay nearly $2.39 million to the victims. Aliyu, who pleaded guilty in August 2025, acknowledged that he conspired with others, including Kosi Goodness Simon-Ebo, 31, and Henry Onyedikachi Echefu, 34, to deceive and defraud multiple American victims from February 2017 until at least July 2017. The business email compromise scheme targeted American businesses and individuals by compromising email accounts and sending false wiring instructions to deceive victims into sending money to bank accounts under their control. "Aliyu and his accomplices conspired to commit money laundering by disbursing the fraudulently obtained funds in the drop accounts to other accounts," the U.S. Justice Department said. "Co-conspirators moved the stolen money by initiating account transfers, withdrawing cash, and obtaining cashier’s checks. They also wrote checks to other individuals and entities to hide the true ownership and source of these assets. In total, Aliyu and his co-conspirators attempted to defraud victims of at least $10.4 million, and the victims suffered an actual loss of at least $2,389,130." Sensor Technology to Combat Deepfakes — Researchers at ETH Zürich have developed a sensor system that stamps a cryptographic signature onto images, video, and audio within a sensor chip at the exact moment they are captured, making it impossible to tamper with the data without being detected. "If the signatures are uploaded to a public ledger (e.g., a blockchain), anyone can verify the authenticity of videos and other data," ETH Zürich said. "The technology can, in principle, be integrated into any type of sensor or camera. It would then be possible to identify manipulated content on online platforms with minimal effort." Middle East Conflict Fuels Cyber Attacks — Threat actors have been capitalizing on geopolitical tensions in the Middle East region to spread Android spyware by distributing trojanized versions of Israel's Red Alert apps via SMS phishing messages. The espionage campaign has been codenamed Operation False Siren by CYFIRMA. ZIP archives containing lures related to the conflict are also being used to launch malicious payloads that lead to the deployment of PlugX and LOTUSLITE backdoors. These ZIP-based phishing campaigns have been attributed to a Chinese nation-state actor known as Mustang Panda. Elsewhere, an Iran-themed fake news blog site hosting malicious JavaScript has been found, leading to the deployment of StealC malware. Apple Tests Ways to Block Malicious Copy-Pastes in macOS — With the release of macOS 26.4 last week, Apple has introduced a new feature that warns Mac users if they paste harmful commands in the Terminal app to curb ClickFix-style attacks that have increasingly targeted macOS in recent months. "Scammers often encourage pasting text into Terminal to try and harm your Mac or compromise your privacy," the message reads. "These instructions are commonly offered via websites, chat agents, apps, files, or a phone call." The alert comes with a "Paste Anyway" for those who wish to proceed. The disclosure comes as multiple ClickFix campaigns have come to light, including using a Cloudflare-themed verification page to deliver a Python-based macOS stealer dubbed Infiniti Stealer. A similar Cloudflare verification, but for Windows, has been used to launch PowerShell commands that ultimately drop StealC, Lumma, Rhadamanthys, Vidar Stealer, and Aura Stealer malware. The ClickFix strategy has also been adopted by a traffic distribution system known as KongTuke to redirect visitors of compromised WordPress websites to phishing pages and malware payloads. According to eSentire, ClickFix lures have been used to deliver EtherRAT, a Node.js-based backdoor linked to North Korean threat actors. "EtherRAT allows threat actors to run arbitrary commands on compromised hosts, gather extensive system information, and steal assets such as cryptocurrency wallets and cloud credentials," the Canadian security company said. "Command-and-Control (C2) addresses are retrieved using 'EtherHiding,' a technique to make C2 addresses more resilient by storing and updating them in Ethereum smart contracts, allowing threat actors to rotate infrastructure at a small cost and avoid takedowns by law enforcement." Recorded Future said it has identified five distinct clusters leveraging ClickFix to facilitate initial access to Windows and macOS systems since May 2024. "This indicates that the ClickFix methodology has transitioned into a standardized, high-ROI template adopted across a fragmented ecosystem of threat actors," Insikt Group said. "While visually diverse, all analyzed clusters use a consistent execution framework that bypasses traditional browser security controls by shifting the point of exploitation to user-assisted manual commands. These campaigns target a wide variety of sectors, including accounting (QuickBooks), travel (Booking.com), and system optimization (macOS)." Apple Rolls Out Mandatory Age Verification in U.K. — In more Apple news, the tech giant has rolled out mandatory U.K. age verification with iOS 26.4, requiring users to provide a credit card or ID to confirm if they are an adult before "downloading apps, changing certain settings, or taking other actions with your Apple Account." The move comes at a time when online child safety is increasingly drawing attention from regulators, causing many digital services, including social media apps and porn sites, to roll out similar checks. Discord, which announced plans to verify the ages of all its users last month, has since paused the effort until H2 2026 after concerns were raised about how IDs and personal information would be handled. Discord has reiterated that it does not receive any identifying personal information from users who need to manually verify their age. Instead, it is partnering with third-party age verification companies, who will "handle verification and only pass back your age group." The company also said it's no longer working with age verification vendor Persona, which has attracted criticism over allegations that it shared users' data with other companies and left its frontend source code exposed to the internet. 🔧 Cybersecurity Tools OpenClaw Security Handbook → It is a detailed security guide published by ZAST AI for users of OpenClaw, a multi-channel AI gateway that connects messaging platforms, LLMs, and local system capabilities. Because that combination creates a serious attack surface, the handbook covers the real risks — prompt injection, malicious skills, exposed ports, credential theft — backed by documented incidents and CVEs, with practical configuration guidance for locking it down. VulHunt → It is an open-source framework from Binarly's research team for hunting vulnerabilities in software binaries and UEFI firmware. It uses customizable rulepacks for scanning and can connect to Binarly's Transparency Platform for large-scale triage. It also supports running as an MCP server, letting AI assistants interact with it directly. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion That's the week. Some of it will age well, some of it is already being quietly exploited while you're reading this sentence. The through-line, if there is one: patience. Attackers are playing long games. The detections, the arrests, the patches — they matter, but they're almost always trailing. Stay sharp, check the CVE list, and see you next Monday.
thehackernews.comMar 30, 2026extracted
EtherRAT Techniques Bypass Security Via Ethereum Smart Contracts
A new EtherRAT malware campaign using Ethereum smart contracts to hide command-and-control (C2) infrastructure has been identified by researchers. According to a new advisory published by eSentire on March 25, the activity was observed during a March 2026 incident response investigation in the retail sector, where adversaries deployed a Node.js‑based backdoor after gaining initial access. The researchers found the malware enables attackers to execute commands remotely, collect extensive system data and steal cryptocurrency wallets and cloud credentials. The most notable development is the use of a technique known as EtherHiding, which stores C2 addresses inside Ethereum smart contracts, allowing operators to rotate infrastructure cheaply and avoid traditional takedown efforts. Ethereum Smart Contracts Used For Command Infrastructure Investigators observed several methods used to gain initial access, including ClickFix attacks and IT support scams conducted over Microsoft Teams, followed by QuickAssist remote access. In the ClickFix case, attackers used indirect command execution to launch a malicious script through Windows utilities, bypassing security restrictions. The infection chain involved multiple stages, including encrypted payloads and obfuscated scripts that ultimately deployed EtherRAT and established persistence through Windows registry keys. Once installed, EtherRAT retrieved C2 addresses from Ethereum blockchain smart contracts via public RPC providers. The malware then communicated with the server using traffic designed to resemble normal content delivery network requests, helping it blend into legitimate network activity. eSentire said attackers could update C2 addresses by writing new data to the smart contract, allowing previously infected machines to reconnect to new servers with minimal cost. System Fingerprinting and Data Collection After connecting to its command server, the malware deployed a module that collected detailed system information used for target profiling. This includes: Public IP address CPU and GPU information Operating system and hardware identifiers Antivirus software details Domain and administrator status The malware also checked system language settings and deleted itself if certain CIS (Commonwealth of Independent States) region languages were detected. The report concluded that organizations should disable certain Windows utilities, train employees to recognize IT support scams and consider blocking cryptocurrency RPC providers commonly used by attackers.
infosecurity-magazine.comMar 26, 2026extracted
Analisi statica del codice: con LiSA la tecnologia italiana sale sul podio mondiale
Un podio mondiale per la cyber security italiana: LiSA, il framework open source per la verifica del software sviluppato dall’Università Ca’ Foscari di Venezia, ha conquistato il terzo posto a SVCOMP 2026, la principale competizione internazionale del settore organizzata in occasione della conferenza accademica Tools and Algorithms for the Construction and Analysis of Systems (TACAS), una delle maggiori conferenze mondiali in ambito di verifica software.. Unica tecnologia 100% made in Italy in gara, JLiSA – l’estensione per l’analisi di codice Java – si è classificata dietro ai progetti JBMC e GDart, confermando la rilevanza della ricerca italiana su uno dei temi cruciali della sicurezza informatica: la qualità e la sicurezza del codice. L’attività di ricerca e sviluppo italiana è co-finanziata dallo Spoke 6 “Sicurezza del software e delle piattaforme” del progetto PNRR SERICS coordinato proprio dalla Ca’ Foscari con il Prof. Riccardo Focardi, a conferma della rilevanza italiana su uno dei temi cruciali della cyber security: la sicurezza del codice. Inoltre, LiSA è stata integrata dalla NSA all’interno di Ghidra, uno strumento open source per l’analisi di programmi compilati. Lo strumento si candida a pieno titolo come possibile incentivo all’adozione di tecnologia italiana per l’analisi statica del codice. Indice degli argomenti LiSA offre un framework generico che può essere applicato a diversi linguaggi di programmazione e tecnologie. La tecnologia nasce inizialmente come prodotto della tesi di dottorato industriale in Informatica di Luca Negrini, concluso nel 2023 a Ca’ Foscari. Il progetto è stato portato avanti all’interno del gruppo di ricerca “Software and System Verification” (SSV) guidato dai professori Agostino Cortesi e Pietro Ferrara. Negli ultimi mesi, LiSA è stato esteso per l’analisi di programmi Java (JLisa). Grazie a un lavoro di squadra che ha coinvolto ricercatori e dottorandi cafoscarini (lo stesso Luca Negrini, Luca Olivieri, Giacomo Zanatta e Teodors Lisovenko) in collaborazione con l’Università di Parma, e in particolare con il ricercatore Vincenzo Arceri e lo studente magistrale Filippo Bianchi. Luca Negrini ne spiega gli elementi fondanti: “LiSA (Library for Static Analysis) è una libreria open source per l’analisi statica del software. A differenza dell’analisi dinamica, che esegue il programma su casi di test specifici, l’analisi statica in generale e LiSA in particolare, esaminano il codice sorgente senza eseguirlo, identificando potenziali errori e vulnerabilità. La libreria è basata sulla teoria dell’Interpretazione astratta, un framework matematicamente fondato, che permette di ragionare su tutte le possibili esecuzioni di un programma in modo ‘sound’, ovvero corretto, e fornisce quindi garanzie formali sui suoi risultati”. La soundness, ovvero la correttezza dell’approccio garantita dall’interpretazione astratta, indica che le regole inferenziali e i processi di analisi applicati consentono di identificare tutti gli errori e le vulnerabilità cercati. Se un analizzatore è ‘sound’, ciò che afferma essere corretto lo è effettivamente, garantendo l’assenza di falsi negativi nelle analisi. La modularità è un’altra caratteristica distintiva: “LiSA è modulare e supporta più linguaggi tramite front-end specializzati: oltre a JLiSA per Java, esistono front-end per Python, Go, smart contract Ethereum e Tezos. Qualche mese fa, inoltre, LiSA è stata integrata dalla NSA all’interno di Ghidra, uno strumento open source per l’analisi di programmi compilati”. Ma c’è di più. “La flessibilità ed estendibilità di LiSA permettono di applicare tale libreria a una molteplicità di analisi e proprietà, anche in ambito di sicurezza”. Esempi di questa varianza sono stati anche oggetto di pubblicazioni scientifiche. “GoLiSA (pubblicata con paper nell’ambito del 37th European Conference on Object-Oriented Programming – ECOOP 2023) esegue una serie di controlli di vario tipo su codice blockchain (ad esempio, Hyperledger Fabric) scritto in Go. Un’altra estensione di LiSA su codice Python per ROS2 (cui è dedicata una ulteriore pubblicazione) si è focalizzata sull’estrazione e verifica di policy di sicurezza. La libreria facilita l’introduzione di remediation di chiusura bug o di correzione errori perché “produce segnalazioni precise che indicano esattamente dove nel codice si trovino i potenziali problemi: file, riga, e tipologia di errore. Gli sviluppatori sanno quindi esattamente dove intervenire e di che natura è il problema (ad es. la possibile ‘NullPointerException’, violazione di un contratto, comportamento non deterministico). Questo rende la correzione degli errori molto più rapida e mirata rispetto a strumenti che restituiscono segnalazioni generiche”. Una proprietà peculiare è la soundness ovvero la correttezza. Luca Negrini sottolinea in questo senso che “la caratteristica più importante è la soundness garantita dall’Interpretazione Astratta: quando LiSA non segnala un errore di una certa categoria, questa assenza è matematicamente provata ovvero non è una stima statistica”, il tutto in favore della eliminazione dei falsi positivi. “Questo elimina i falsi negativi, ovvero i bug che sfuggono all’analisi e che negli strumenti tradizionali (come il testing o analisi euristiche) possono dare una falsa sicurezza agli sviluppatori. In pratica: se LiSA dice che il codice è privo di ‘null pointer exception’, lo è davvero in ogni possibile scenario di esecuzione”. Entrambe i docenti chiariscono che “LiSA è stato un progetto universitario e di ricerca, per cui la sua integrazione con ambienti di sviluppo e la sua commercializzazione non sono state ancora affrontate, anche se rientrano nella roadmap”. Naturalmente esistono possibili sviluppi futuri. “Abbiamo in mente svariati sviluppi futuri: estensione a nuovi linguaggi e piattaforme (Python con FastAPI, Java con Spring, C++), miglioramento della precisione delle analisi per ridurre ulteriormente i falsi positivi, ed ovviamente la partecipazione alle future edizioni di SV-COMP con risultati, si spera, sempre più competitivi”. L’orientamento alla creazione di una Start up esiste ma non è ancora avviato mentre il team è aperto a collaborazioni. “Attualmente non esiste una startup commerciale dedicata, anche se stiamo valutando proprio ora questa opzione, considerato anche una parte considerevole del team viene da un’esperienza di commercializzazione di un tool simile (Julia, spin-off nata nel 2010 a Verona dall’iniziativa del prof. Spoto, n.d.r.), ma il codice è interamente open source e il gruppo SSV è aperto a collaborazioni sia con aziende che con altri gruppi di ricerca”. Lo strumento è attualmente adottato in diversi contesti anche internazionali esterni all’accademia. “LiSA è già adottata in contesti didattici universitari e di ricerca applicata in diversi domini (blockchain, robotica, microservizi, data science), e l’integrazione in Ghidra – uno strumento con una comunità globale molto ampia – dimostra l’interesse per questo strumento ben oltre l’ambito accademico”. Non resta che verificare l’interesse delle realtà italiane che ora potrebbero avere una scelta integralmente italiana per il controllo statico del codice sorgente. La competizione SV_COMP 2026 La quindicesima edizione della competizione mondiale nel settore della verifica del software (Competition on Software Verification, SV-COMP) svolta a Torino per la categoria “Java Verification” ha premiato come terzo classificato il progetto Italiano JLISA (Library for Static Analysis), unica tecnologia 100% made in Italy. I progetti open source JBMC e a GDart rispettivamente sono risultati primo e secondo classificato. La competizione nasce per stimolare l’invenzione di nuovi metodi, tecnologie e strumenti e offrire una panoramica sullo stato dell’arte della verifica del software, dando visibilità e riconoscimento agli sviluppatori. Nonostante le difficoltà per il test dei diversi prototipi presentati, la SV-COMP utilizza un set consolidato di attività di verifica per confrontare i verificatori di software (disponibili sul proprio sito) che fungono anche da benchmark per la verifica del software nella comunità. Pietro Ferrara, professore responsabile del team di ricerca che ha sviluppato il framework LiSA e Luca Negrini Professore assistente e PhD dalla cui tesi di dottorato nasce Lisa, spiegano che: “SV-COMP utilizza benchmark, che coprono diverse categorie di proprietà verificabili: assenza di errori a runtime (accessi a puntatori nulli, buffer overflow), corretta gestione della memoria, rispetto di requisiti funzionali tramite assert, etc. Si tratta per lo più, di controlli sulla qualità in generale del codice”.
cybersecurity360.itMar 25, 2026extracted
Fake Pudgy World site steals your crypto passwords
A phishing site impersonating the newly-launched Pudgy World browser game is targeting crypto users with a technique that goes well beyond a convincing logo and matching color scheme. Pudgy World is a free-to-play browser game built around the Pudgy Penguins NFT brand. Players explore a virtual world, customize penguin avatars, and complete quests. But some features are tied to digital collectibles and in-game items stored in cryptocurrency wallets. That means the official game sometimes asks players to connect a crypto wallet to verify ownership of items or unlock additional features. The phishing site abuses that step: When a visitor selects their wallet on this fake site, it shows what appears to be that wallet’s own unlock screen. To the user, it looks for all the world like the real crypto wallet software they already trust. “Connect your wallet to get started” The Pudgy Penguins brand has had an extraordinary few months. The penguin NFT project, revived by CEO Luca Netz after he acquired it in 2022, has steadily built one of the most convincing crossover stories in Web3: physical plush toys on Walmart and Target shelves, a mobile game called Pudgy Party that crossed a million downloads, and a browser-based game called Pudgy World that went live on 10 March 2026 to immediate viral attention. The official game asks players to connect a crypto wallet to get started. That text: “Connect your wallet to get started” is now appearing, verbatim, on a site that has nothing to do with Pudgy Penguins. The domain in question is pudgypengu-gamegifts[.]live. It is not affiliated with Igloo Inc., the company behind Pudgy Penguins, in any way. The site reproduces the official game’s icy background artwork, the Pudgy Penguins logo, and the brand’s characteristic blue-and-white color palette with enough fidelity that a user arriving during the excitement of a new game launch would have no obvious reason for suspicion. Eleven wallets, eleven convincing forgeries Clicking the CONNECT button opens a dark-themed pop-up window built to resemble the Reown WalletConnect connection kit—the open-source library that the real Pudgy World site uses to handle wallet connections. The modal even displays the “reown” and “Manual Kit” tab labels at the top, matching the genuine component. Inside is a list of supported wallets: MetaMask (marked “RECOMMENDED”), Trust Wallet, Coinbase Wallet, Ledger, Trezor Wallet, Phantom Wallet, Rabby Wallet, OKX Wallet, Magic Eden, Solflare, and Uniswap Wallet. The attack becomes technically interesting at the next step. Selecting a software wallet does not redirect the user to another page or open an external site. Instead, the page renders an overlay designed to look like the wallet’s actual browser extension unlock screen. The overlay appears at the edge of the browser viewport right where a real extension popup would appear. Hardware wallet flows behave differently. Selecting Trezor Wallet opens a center-screen dialog mimicking the Trezor Connect interface, rather than a corner overlay. In both cases, the result is that the user believes they are looking at their own installed software, when they are in fact looking at a webpage element controlled by the attacker. The forgery sits exactly where your real extension would For every browser extension wallet on the list, the phishing site renders an unlock screen built to match the real extension’s own visual identity, with the correct logo, color scheme, button layout, and wording. The screenshots below show the forgeries alongside the genuine extensions. The differences are not visible to someone who is not looking for them. Hardware wallet users are not exempt, and the targeting of Trezor is particularly telling. Trezor devices are typically owned by people who have been in crypto long enough to invest in dedicated security hardware. In other words, users likely holding higher-value accounts. Selecting Trezor Wallet on the phishing site triggers a dialog that closely mimics the Trezor Connect bridge interface. At the same time, the browser displays a native USB device permission prompt—the operating system’s own dialog, triggered by a WebUSB API call—reading “pudgypengu-gamegifts.live wants to connect.” The prompt says “No compatible devices found” if no Trezor is plugged in, but the sequence is designed to look like a genuine hardware handshake. A user who plugs in their Trezor at this point and approves the USB permission has granted the phishing site access to the device bridge. For those without a device to hand, the dialog offers another option: “Use an alternative connection method.” That path is likely where the most damage is done. A user who cannot get the hardware flow to work and falls back to a manual option is one step away from being asked to type in their seed phrase, the master key to everything in their wallet, directly into a field the attacker controls. The page that plays dead for researchers The phishing page is more cautious than it first appears. Embedded in the site is an obfuscated JavaScript loader, its real contents compressed and hidden behind multiple layers of encoding, that performs a series of checks before doing anything visible. First, it tests whether the browser is being driven by an automated tool of the kind security researchers and sandboxes use to analyse suspicious pages in bulk. If it detects one, it quietly stops and the page appears clean. Next, it reads the graphics hardware identifier to determine whether it is running inside a virtual machine, which is another common analysis environment. Only once it is satisfied that a real user is present does it request a second, larger payload from the attacker’s server. That payload contains the code responsible for credential theft. Even that request contains a safeguard. If the server response is smaller than 500 KB (the kind of placeholder response a security vendor might serve to a known malicious domain), the loader discards it and does nothing. The practical consequence of all this is that automated scanning tools are likely to rate the initial page as benign, because on their infrastructure, it behaves like one. The malicious functionality never loads unless the attacker’s server decides the visitor is worth targeting. Why this campaign targets Pudgy players The timing seems to be deliberate. Pudgy World launched on March 10, 2026, and the phishing campaign appears to have been active around the same window. New players arriving at the game for the first time are walking through a Web3 onboarding flow they have never experienced before. The legitimate “connect your wallet” step on the official site teaches users that this behaviour is normal. The phishing site then exploits that expectation before experience can challenge it. The range of wallets targeted is also significant. The campaign leaves almost no wallet blind spot. Whether the victim holds Ethereum, Solana, or multi-chain assets, there is a convincing forgery waiting for them. Building 11 wallet-specific UI forgeries is not a trivial undertaking. It points either to a well-resourced threat actor or, more likely, to the reuse of a commercial phishing kit built for precisely this class of attack. What to do if you may have been affected Crypto phishing campaigns have long relied on fake airdrops and fake MetaMask pages. This campaign stands out for how precisely it imitates a wallet’s unlock screen, placing the prompt exactly where a real extension pop-up would appear and exploiting users’ muscle memory. The attack also piggybacks on Pudgy World’s launch. As Web3 products reach wider audiences, they attract attackers targeting users unfamiliar with wallet security. One rule still holds: a website can never display your real browser extension unlock screen. If you entered your MetaMask, Coinbase Wallet, or any other software wallet password on this site, change your password immediately by unlocking the extension normally and going to Settings. Consider transferring assets to a new wallet address whose seed phrase has never been used on any website. If you approved the USB device permission prompt for Trezor, disconnect your device and review your Trezor Suite connection history. A WebUSB connection alone does not expose your seed phrase, but it can allow a malicious page to communicate with the bridge. Revoke the permission in your browser’s site settings immediately. Bookmark the official Pudgy Penguins site (pudgypenguins.com) and the official game URL. Navigate to it directly from that bookmark, never from a link in Discord, Twitter, or a direct message. Install a browser extension that flags known phishing domains before you interact with them. Malwarebytes Browser Guard will block this domain. Remind yourself of this rule: your wallet’s unlock screen always appears in the bar at the very top of the window, not inside the page itself. Any page that appears to show you your wallet’s password prompt inside the page content is a phishing site. Indicators of Compromise (IOCs) Domains pudgypengu-gamegifts[.]live
malwarebytes.comMar 17, 2026extracted
Free real estate: GoPix, the banking Trojan living off your memory
Introduction GoPix is an advanced persistent threat targeting Brazilian financial institutions’ customers and cryptocurrency users. It represents an evolved threat targeting internet banking users through memory-only implants and obfuscated PowerShell scripts. It evolved from the RAT and Automated Transfer System (ATS) threats that were used in other malware campaigns into a unique threat never seen before. Operating as a LOLBin (Living-off-the-Land Binary), GoPix exemplifies a sophisticated approach that integrates malvertising vectors via platforms such as Google Ads to compromise prominent financial institutions’ customers. Our extensive analysis reveals GoPix’s capabilities to execute man-in-the-middle attacks, monitor Pix transactions, Boleto slips, and manipulate cryptocurrency transactions. The malware strategically bypasses security measures implemented by financial institutions while maintaining persistence and employing robust cleanup mechanisms to challenge Digital Forensics and Incident Response (DFIR) efforts. GoPix has reached a level of sophistication never before seen in malware originating in Brazil. It’s been over three years since we first identified it, and it remains highly active. The threat is recognized for its stealthy methods of infecting victims and evading detection by security software, using new tricks to stay operable. The threat differs in its behavior from the RATs already seen in other Brazilian families, such as Grandoreiro. GoPix uses C2s with a very short lifespan, which stay online only for a few hours. In addition, the attackers behind this threat abuse legitimate anti-fraud and reputation services to perform targeted delivery of its payload and ensure that they have not infected a sandbox or system used in analysis. They handpick their victims, financial bodies of state governments and large corporations. The campaign leverages a malvertisement technique which has been active since December 2022. The strategic use of multiple obfuscation layers and a stolen code signing certificate showcases GoPix’s ability to evade traditional security defenses and steal and manipulate sensitive financial data. The Brazilian group behind GoPix is clearly learning from APT groups to make malware persistent and hide it, loading its modules into memory, keeping few artifacts on disk, and making hunting with YARA rules ineffective for capturing them. The malware can also switch between processes for specific functionalities, potentially disabling security software, as well as executing a man-in-the-middle attack with a previously unseen technique. Initial infection Initial infection is achieved through malvertising campaigns. The threat actors in most cases use Google Ads to spread baits related to popular services like WhatsApp, Google Chrome, and the Brazilian postal service Correios and lure victims to malicious landing pages. We have been monitoring this threat since 2023, and it continues to be very active for the time being. GoPix malware campaign detections (download) The initial infection vector is shown below: When the user ends up on the GoPix landing page, the malware abuses legitimate IP scoring systems to determine whether the user is a target of interest or a bot running in malware analysis environments. The initial scoring is done through a legitimate anti-fraud service, with a number of browser and environment parameters sent to this service, which returns a request ID. The malicious website uses this ID to check whether the user should receive the malicious installer or be redirected to a harmless dummy landing page. If the user is not considered a valuable target, no malware is delivered. However, if the victim passes the bot check, the malicious website will query the check.php endpoint, which will then return a JSON response with two URLs: The victim will then be presented with a fake webpage offering to download advertised software, this being the malicious “WhatsApp Web installer” in the case at hand. To decide which URL the victim will be redirected to, another check happens in the JavaScript code for whether the 27275 port is open on localhost. This port is used by the Avast Safe Banking feature, present in many Avast products, which are very popular in countries like Brazil. If the port is open, the victim is led to download the first-stage payload from the second URL (url2). It is a ZIP file containing an LNK file with an obfuscated PowerShell designed to download the next stage. If the port is closed, the victim is redirected to the first URL (url), which offers to download a fake WhatsApp executable NSIS installer. At first, we thought this detection could lead the victim to a potential exploit. However, during our research, we discovered that the only difference was that if Avast was installed, the victim was led to another infection vector, which we describe below. Infection chain First-stage payload If no Avast solution is installed, an executable NSIS installer file is delivered to the victim’s device. The attackers change this installer frequently to avoid detection. It’s digitally signed with a stolen code signing certificate issued to “PLK Management Limited”, also used to sign the legitimate “Driver Easy Pro” software. The purpose of the NSIS installer is to create and run an obfuscated batch file, which will use PowerShell to make a request to the malicious website for the next-stage payload. However, if the 27275 port is open, indicating the victim has an Avast product installed, the infection happens through the second URL. The victim is led to download a ZIP file with an LNK file inside. This shortcut file contains an obfuscated command line. Deobfuscated command line: The purpose of this command line is to download and execute the next-stage payload from the malicious URL referenced above. It’s highly likely this method is used because Avast Safe Browser blocks direct downloads of executable files, so instead of downloading the executable NSIS installer, a ZIP file is delivered. Once the PowerShell command from either the LNK or EXE file is executed, GoPix executes yet another obfuscated PowerShell script that is remotely retrieved (in the GoPix downloader image below, it’s defined as “PowerShell Script”). Initial PowerShell script This script’s purpose is to collect system information and send it to the GoPix C2. Upon doing so, the script obtains a JSON file containing GoPix modules and a configuration that is saved on the victim’s computer. The information contained within this JSON is as follows: Folder and file names to be created under the %APPDATA% directory Obfuscated PowerShell script Encrypted PowerShell script ps Malicious code implant sc containing encrypted GoPix dropper shellcode, GoPix dropper, main payload shellcode and main GoPix implant GoPix configuration file pf Once these files are saved, an additional batch file is also created and executed. Its purpose is to launch the obfuscated PowerShell script. Obfuscated PowerShell script Upon execution, the obfuscated PowerShell script decrypts the encrypted PowerShell script ps, starts another PowerShell instance, and passes the decrypted script through its stdin, so that the decrypted script is never loaded to disk. Decrypted PowerShell script “ps” The purpose of this memory-only PowerShell script is to perform an in-memory decryption of the GoPix dropper shellcode, GoPix dropper, main payload shellcode and main GoPix malware implant into allocated memory. After that, it creates a small piece of shellcode within the PowerShell process to jump to the GoPix dropper shellcode previously decrypted. The GoPix dropper shellcode is built for either the x86 or x64 architecture, depending on the victim’s computer. Shellcode This shellcode is bundled with the malware and stays in encrypted form on disk. It is utilized at two separate stages of the infection chain: first to launch the GoPix dropper and subsequently to execute the main GoPix malware. We’ve observed two versions of this shellcode. The main difference is the old one resolves API addresses by their names, while the latest one employs a hashing algorithm to determine the address of a given API. The API hash calculation begins by generating a hash for the DLL name, and this resulting hash is then used within the function name to compute the final API hash. The first time GoPix is dropped into memory through PowerShell, its structure is as follows: Memory dropper shellcode Memory dropper DLL Main payload shellcode Main payload DLL Both DLLs have their MZ signature erased, which helps to evade detection by memory dumping tools that scan for PE files in memory. GoPix dropper When the main function from the dropper is called, it verifies if it is running within an Explorer.exe process; if not, it will terminate. It then sequentially checks for installed browsers — Chrome, Firefox, Edge, and Opera — retrieving the full path of the first detected browser from the registry key SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths. A significant difference from previously analyzed droppers is that this version encrypts each string using a unique algorithm. After selecting the browser, the dropper uses direct syscalls to launch the chosen browser process in a suspended state. This allows it to inject the main GoPix shellcode and its parameters into the process. The injected shellcode is tasked with extracting and loading the main GoPix implant directly into memory, subsequently calling its exported main function. The parameters passed include the number 1, to trigger the main GoPix function, and the current Process ID, which is that of Explorer.exe. Main GoPix implant Clipboard stealing functionality Boleto bancário was added as one of the targets to the malware’s clipboard stealing and replacing feature. Boleto is a popular payment method in Brazil that functions similarly to an invoice, being the second most popular payment system in the country. It is a standardized document that includes important payment information such as the amount due, due date, and details of the payee. It features a typeable line, which is a sequence of numbers that can be entered in online banking applications to pay. This line is what GoPix targets with its functionality. An example of such a line is “23790.12345 60000.123456 78901.234567 8 76540000010000”. When GoPix detects a Pix or Boleto transaction, it simply sends this information to the C2. However, when a Bitcoin or Ethereum wallet is copied to the clipboard, the malware replaces the address with one belonging to the threat actor. Unique man-in-the-middle attack PAC (Proxy AutoConfig) files are nothing new; they’ve been used by Brazilian criminals for over two decades, but GoPix takes this to another level. While in the past, criminals used PAC files to redirect victims to a fake phishing page, the purpose of the PAC file in GoPix attacks is to manipulate the traffic while the user navigates the legitimate financial website. In order to hide which site GoPix wants to intercept, it uses a CRC32 algorithm in the host field of the PAC file. It is formatted on the fly using a pf configuration file: the items in it determine which proxy the victim will be redirected to. To hide its malicious proxy server, once a connection is opened to the proxy server, the malware enumerates all connections and finds the process that initiated it. It then takes the process executable name CRC32C checksum and compares it with a hardcoded list of browsers’ CRC checksums. If it doesn’t match a known browser, the malware simply terminates the connection. To uncover GoPix targets, we compiled a list of many Brazilian financial institution domains and subdomains, computed their CRC32 checksums, and compared them against GoPix hardcoded values. The table below shows each CRC32 and its target. HTTPS interception Since every communication is encrypted via HTTPS, GoPix bypasses this by injecting a trusted root certificate into the memory of a web browser while on the victim’s machine. This allows the attacker to sniff and even manipulate the victim’s traffic. We have found two certificates across GoPix samples, one that expired in January 2025 and another created in February 2025 that is set to expire in February 2027. Conclusion With the ability to load its memory-only implant that employs a malicious Proxy AutoConfig (PAC) file and an HTTP server to execute an unprecedented man-in-the-middle attack, GoPix is by far the most advanced banking Trojan of Brazilian origin. The injection of a trusted root certificate into the browser enhances its ability to intercept and manipulate sensitive financial data while maintaining its stealth profile, as the malicious certificate is not visible to operating system tools. Additionally, GoPix has expanded its clipboard monitoring capability by adding Boleto slips to its arsenal, which already includes Pix transactions and cryptowallets addresses. This is a sophisticated threat, with multiple layers of evasion, persistence, and functionality. The investigation into the malware’s shellcode, dropper, and main module uncovered intricate mechanisms, including process jumping to leverage specific functionalities across processes. This technique, combined with robust string encryption methods applied to both the dropper and main payload, indicates that the threat actor has gone to great lengths to hinder detection. Interestingly enough, attackers adopted the use of a legitimate commercial anti-fraud service to pre-qualify their targets, aiming to avoid sandboxes and security researchers’ investigations. Additionally, the persistence and cleanup mechanisms implemented by the malware enhance its durability during incident response efforts, with very short C2 lifespans. For further information on GoPix and all technical details, please contact [email protected]. Kaspersky’s products detect this threat as HEUR:Trojan-Banker.Win64.GoPix, Trojan.PowerShell.GoPix, and HEUR:Trojan-Banker.OLE2.GoPix. Indicators of compromise EB0B4E35A2BA442821E28D617DD2DAA2 – NSIS installer C64AE7C50394799CE02E97288A12FFF – ZIP archive with an LNK file D3A17CB4CDBA724A0021F5076B33A103 – Malware dropper 28C314ACC587F1EA5C5666E935DB716C – Main payload Malicious Certificate Thumbprint f110d0bd7f3bd1c7b276dc78154dd21eef953384 1b1f85b68e6c9fde709d975a186185c94c0faa51
securelist.comMar 16, 2026extracted
KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet
Cybersecurity researchers have discovered a new malware called KadNap that's primarily targeting Asus routers to enlist them into a botnet for proxying malicious traffic. The malware, first detected in the wild in August 2025, has expanded to over 14,000 infected devices, with more than 60% of victims located in the U.S., according to the Black Lotus Labs team at Lumen. A lesser number of infections have been detected in Taiwan, Hong Kong, Russia, the U.K., Australia, Brazil, France, Italy, and Spain. "KadNap employs a custom version of the Kademlia Distributed Hash Table (DHT) protocol, which is used to conceal the IP address of their infrastructure within a peer-to-peer system to evade traditional network monitoring," the cybersecurity company said in a report shared with The Hacker News. Compromised nodes in the network leverage the DHT protocol to locate and connect with a command-and-control (C2) server, thereby making it resilient to detection and disruption efforts. Once devices are successfully compromised, they are marketed by a proxy service named Doppelgänger ("doppelganger[.]shop"), which is assessed to be a rebrand of Faceless, another proxy service associated with TheMoon malware. Doppelgänger, according to its website, claims to offer resident proxies in over 50 countries that provide "100% anonymity." The service is said to have launched in May/June 2025. Despite the focus on Asus routers, the operators of KadNap have been found to deploy the malware against an assorted set of edge networking devices. Central to the attack is a shell script ("aic.sh") that's downloaded from the C2 server ("212.104.141[.]140"), which is responsible for initiating the process of conscripting the victim to the P2P network. The file creates a cron job to retrieve the shell script from the server at the 55-minute mark of every hour, rename it to ".asusrouter," and run it. Once persistence is established, the script pulls a malicious ELF file, renames it to "kad," and executes it. This, in turn, leads to the deployment of KadNap. The malware is capable of targeting devices running both ARM and MIPS processors. KadNap is also designed to connect to a Network Time Protocol (NTP) server to fetch the current time and store it along with the host uptime. This information serves as a basis to create a hash that's used to locate other peers in the decentralized network to receive commands or download additional files. The files – "fwr.sh" and "/tmp/.sose" – contain functionality to close port 22, the standard TCP port for Secure Shell (SSH), on the infected device and extract a list of C2 IP address:port combinations to connect to. "In short, the innovative use of the DHT protocol allows the malware to establish robust communication channels that are difficult to disrupt, by hiding in the noise of legitimate peer-to-peer traffic," Lumen said. Further analysis has determined that not all compromised devices communicate with every C2 server, indicating the infrastructure is being categorized based on device type and models. The Black Lotus Labs team told The Hacker News that Doppelgänger's bots are being abused by threat actors in the wild. "One issue there has been since these Asus (and other devices) are also sometimes co-infected with other malware, it is tricky to say who exactly is responsible for a specific malicious activity," the company said. Users running SOHO routers are advised to keep their devices up to date, reboot them regularly, change default passwords, secure management interfaces, and replace models that are end-of-life and are no longer supported. "The KadNap botnet stands out among others that support anonymous proxies in its use of a peer-to-peer network for decentralized control," Lumen concluded. "Their intention is clear, avoid detection and make it difficult for defenders to protect against." New Linux Threat ClipXDaemon Emerges The disclosure comes as Cyble detailed a new Linux threat dubbed ClipXDaemon that's designed to target cryptocurrency users by intercepting and altering copied wallet addresses. The clipper malware, delivered via Linux post-exploitation framework called ShadowHS, has been described as an autonomous cryptocurrency clipboard hijacker targeting Linux X11 environments. Staged entirely in memory, the malware employs stealth techniques, such as process masquerading and Wayland session avoidance, while simultaneously monitoring the clipboard every 200 milliseconds and substituting cryptocurrency addresses with attacker-controlled wallets. It's capable of targeting Bitcoin, Ethereum, Litecoin, Monero, Tron, Dogecoin, Ripple, and TON wallets. The decision to avoid execution in Wayland sessions is deliberate, as the display server protocol's security architecture places additional controls, like requiring explicit user interaction, before applications can access the clipboard content. In disabling itself under such scenarios, the malware aims to eliminate noise and avoid runtime failure. "ClipXDaemon differs fundamentally from traditional Linux malware. It contains no command-and-control (C2) logic, performs no beaconing, and requires no remote tasking," the company said. "Instead, it monetizes victims directly by hijacking cryptocurrency wallet addresses copied in X11 sessions and replacing them in real time with attacker-controlled addresses."
thehackernews.comMar 10, 2026extracted
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials
Cybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts. The package, named "@openclaw-ai/openclawai," was uploaded to the registry by a user named "openclaw-ai" on March 3, 2026. It has been downloaded 178 times to date. The library is still available for download as of writing. JFrog, which discovered the package, said it's designed to steal system credentials, browser data, crypto wallets, SSH keys, Apple Keychain databases, and iMessage history, as well as install a persistent RAT with remote access capabilities, SOCKS5 proxy, and live browser session cloning. It's tracking the activity under the name GhostClaw. "The attack is notable for its broad data collection, its use of social engineering to harvest the victim's system password, and the sophistication of its persistence and C2 [command-and-control] infrastructure," security researcher Meitar Palas said. "Internally, the malware identifies itself as GhostLoader." The malicious logic is triggered by means of a postinstall hook, which re-installs the package globally using the command: "npm i -g @openclaw-ai/openclawai." Once the installation is complete, the OpenClaw binary points to "scripts/setup.js" by means of the "bin" property in the "package.json" file. It's worth noting that the "bin" field is used to define executable files that should be added to the user's PATH during package installation. This, in turn, turns the package into a globally accessible command-line tool. The file "setup.js" serves as the first-stage dropper that, upon running, displays a convincing fake command-line interface with animated progress bars to give the impression that OpenClaw is being installed on the host. After the purported installation step is complete, the script shows a bogus iCloud Keychain authorization prompt, asking users to enter their system password. Simultaneously, the script retrieves an encrypted second-stage JavaScript payload from the C2 server ("trackpipe[.]dev"), which is then decoded, written to a temporary file, and spawned as a detached child process to continue running in the background. The temp file is deleted after 60 seconds to cover up traces of the activity. "If the Safari directory is inaccessible (no Full Disk Access), the script displays an AppleScript dialog urging the user to grant FDA to Terminal, complete with step-by-step instructions and a button that opens System Preferences directly," JFrog explained. "This enables the second-stage payload to steal Apple Notes, iMessage, Safari history, and Mail data." The JavaScript second-stage, featuring about 11,700 lines, is a full-fledged information stealer and RAT framework that's capable of persistence, data collection, browser decryption, C2 communication, a SOCKS5 proxy, and live browser cloning. It's also equipped to steal a wide range of data - macOS Keychain, including both the local login.keychain-db and all iCloud Keychain databases Credentials, cookies, credit cards, and autofill data from all Chromium-based browsers, such as Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera, Yandex, and Comet Data from desktop wallet applications and browser extensions Cryptocurrency wallet seed phrases SSH keys Developer and cloud credentials for AWS, Microsoft Azure, Google Cloud, Kubernetes, Docker, and GitHub Artificial intelligence (AI) agent configurations, and Data protected by the FDA, including Apple Notes, iMessage history, Safari browsing history, Mail account configurations, and Apple account information In the final stage, the collected data is compressed into a tar.gz archive and exfiltrated through multiple channels, including directly to the C2 server, Telegram Bot API, and GoFile.io. What's more, the malware enters a persistent daemon mode that allows it to monitor clipboard content every three seconds and transmit any data that matches one of the nine pre-defined patterns corresponding to private keys, WIF key, SOL private key, RSA private key, BTC address, Ethereum address, AWS key, OpenAI key, and Strike key. Other features include keeping tabs on running processes, scanning incoming iMessage chats in real-time, and executing commands sent from the C2 server to run arbitrary shell command, open a URL on the victim's default browser, download additional payloads, upload files, start/stop a SOCKS5 proxy, list available browsers, clone a browser profile and launch it in headless mode, stop the browser clone, self-destruct, and update itself. The browser cloning function is particularly dangerous as it launches a headless Chromium instance with the existing browser profile that contains cookies, login, and history data. This gives the attacker a fully authenticated browser session without the need for accessing credentials. "The @openclaw-ai/openclawai package combines social engineering, encrypted payload delivery, broad data collection, and a persistent RAT into a single npm package," JFrog said. "The polished fake CLI installer and Keychain prompt are convincing enough to extract system passwords from cautious developers, and once captured, those credentials unlock macOS Keychain decryption and browser credential extraction that would otherwise be blocked by OS-level protections." Update The package has been removed from the npm registry as of March 10, 2026.
thehackernews.comMar 9, 2026extracted
Open-source benchmark EVMbench tests how well AI agents handle smart contract exploits
Open-source benchmark EVMbench tests how well AI agents handle smart contract exploits Smart contract exploits continue to drain funds from blockchain projects, even as auditing tools and bug bounty programs grow. The problem is tied to how Ethereum Virtual Machine (EVM) contracts work: code is deployed permanently, runs autonomously, and often controls large pools of assets. That environment has created demand for better ways to measure whether AI systems can reliably detect, patch, and exploit vulnerabilities in contract code. EVMbench is a new open-source benchmark designed to test AI agents on practical smart contract security tasks. The benchmark was developed by OpenAI and Paradigm, and it focuses on real-world vulnerability patterns drawn from audited codebases and contest reports. EVMbench centers on three categories of tasks: detecting vulnerabilities, patching vulnerable code, and exploiting flaws in a controlled environment. The benchmark is intended to provide repeatable evaluation for AI models that claim to support contract auditing or automated security analysis. What EVMbench measures EVMbench evaluates agent performance using three task types. In detect mode, the model reviews smart contract repositories and attempts to identify vulnerabilities that were previously documented by professional auditors. Scoring is based on recall, meaning whether the agent successfully identifies the known, ground-truth vulnerabilities documented in the reference audits. In patch mode, the model attempts to modify contract code so the vulnerability is removed without breaking expected functionality. Grading checks both that the exploit is eliminated and that original tests and behaviors still pass. In exploit mode, the benchmark gives the model a sandboxed blockchain environment and asks it to execute an exploit against a vulnerable contract. Successful exploitation is measured by verifying on-chain state changes such as drained balances, triggered failure conditions, or other deterministic outcomes. The benchmark uses containerized environments and automated scoring so results can be reproduced across different machines and test runs. Dataset comes from real audits and contests The EVMbench dataset is built from 120 curated vulnerabilities across 40 audits, with most cases drawn from open audit competitions and additional scenarios sourced from Paradigm’s Tempo audit process. Each benchmark case includes the vulnerable contract code and supporting infrastructure needed to recreate the scenario. Exploit tasks place the agent in a controlled local EVM environment and evaluate whether it can execute a working exploit by producing the expected on-chain state changes. The benchmark is designed so tasks reflect realistic development conditions. This increases complexity compared to synthetic vulnerability datasets, since agents need to reason about contract interactions and state changes. How exploit grading works Exploit evaluation is handled through deterministic replay in a controlled test environment. Agents interact with a local EVM instance, where they can deploy contracts, call functions, and attempt to execute fund-draining transactions. The benchmark’s grading harness verifies whether the exploit succeeded based on contract balances and state transitions. That allows exploit attempts to be evaluated automatically without relying on subjective review. The benchmark uses a framework that supports repeatable execution, meaning exploits can be rerun exactly to confirm outcomes. This structure supports comparisons between models over time. Benchmark results show major gaps between models The benchmark results show uneven performance across detect, patch, and exploit tasks. OpenAI reported that exploit tasks remain difficult for many systems, even when models can identify vulnerabilities at a surface level. OpenAI’s blog post notes, “Smart contracts routinely secure $100B+ in open-source crypto assets,” linking the benchmark to the scale of funds exposed to contract bugs. Paradigm highlighted how quickly exploit performance improved across recent model generations. “When we started working on this project, top models were only able to exploit less than 20% of the critical, fund-draining Code4rena bugs. Today, GPT-5.3-Codex exploits over 70%,” Alpin Yukseloglu, Partner at Paradigm, said. The benchmark also shows patching remains a major weakness. Fixing contract vulnerabilities requires preserving correct behavior across edge cases, which often involves understanding deeper design assumptions in the code. Availability and future use EVMbench is available for free on GitHub, including benchmark tasks, harness tooling, and documentation. The goal is to allow researchers and security teams to test models consistently as AI agent capabilities evolve. Must read: 40 open-source tools redefining how security teams secure the stack Firmware scanning time, cost, and where teams run EMBA Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comFeb 19, 2026extracted
Scammers use fake “Gemini” AI chatbot to sell fake “Google Coin”
Scammers have found a new use for AI: creating custom chatbots posing as real AI assistants to pressure victims into buying worthless cryptocurrencies. We recently came across a live “Google Coin” presale site featuring a chatbot that claimed to be Google’s Gemini AI assistant. The bot guided visitors through a polished sales pitch, answered their questions about investment, projecting returns, and ultimately ended with victims sending an irreversible crypto payment to the scammers. Google does not have a cryptocurrency. But as “Google Coin” has appeared before in scams, anyone checking it out might think it’s real. And the chatbot was very convincing. AI as the closer The chatbot introduced itself as, “Gemini — your AI assistant for the Google Coin platform.” It used Gemini-style branding, including the sparkle icon and a green “Online” status indicator, creating the immediate impression that it was an official Google product. When asked, “Will I get rich if I buy 100 coins?”, the bot responded with specific financial projections. A $395 investment at the current presale price would be worth $2,755 at listing, it claimed, representing “approximately 7x” growth. It cited a presale price of $3.95 per token, an expected listing price of $27.55, and invited further questions about “how to participate.” This is the kind of personalized, responsive engagement that used to require a human scammer on the other end of a Telegram chat. Now the AI does it automatically. A persona that never breaks What stood out during our analysis was how tightly controlled the bot’s persona was. We found that it: Claimed consistently to be “the official helper for the Google Coin platform” Refused to provide any verifiable company details, such as a registered entity, regulator, license number, audit firm, or official email address Dismissed concerns and redirected them to vague claims about “transparency” and “security” Refused to acknowledge any scenario in which the project could be a scam Redirected tougher questions to an unnamed “manager” (likely a human closer waiting in the wings) When pressed, the bot doesn’t get confused or break character. It loops back to the same scripted claims: a “detailed 2026 roadmap,” “military-grade encryption,” “AI integration,” and a “growing community of investors.” Whoever built this chatbot locked it into a sales script designed to build trust, overcome doubt, and move visitors toward one outcome: sending cryptocurrency. Why AI chatbots change the scam model Scammers have always relied on social engineering. Build trust. Create urgency. Overcome skepticism. Close the deal. Traditionally, that required human operators, which limited how many victims could be engaged at once. AI chatbots remove that bottleneck entirely. A single scam operation can now deploy a chatbot that: Engages hundreds of visitors simultaneously, 24 hours a day Delivers consistent, polished messaging that sounds authoritative Impersonates a trusted brand’s AI assistant (in this case, Google’s Gemini) Responds to individual questions with tailored financial projections Escalates to human operators only when necessary This matches a broader trend identified by researchers. According to Chainalysis, roughly 60% of all funds flowing into crypto scam wallets were tied to scammers using AI tools. AI-powered scam infrastructure is becoming the norm, not the exception. The chatbot is just one piece of a broader AI-assisted fraud toolkit—but it may be the most effective piece, because it creates the illusion of a real, interactive relationship between the victim and the “brand.” The bait: a polished fake The chatbot sits on top of a convincing scam operation. The Google Coin website mimics Google’s visual identity with a clean, professional design, complete with the “G” logo, navigation menus, and a presale dashboard. It claims to be in “Stage 5 of 5” with over 9.9 million tokens sold and a listing date of February 18—all manufactured urgency. To borrow credibility, the site displays logos of major companies—OpenAI, Google, Binance, Squarespace, Coinbase, and SpaceX—under a “Trusted By Industry” banner. None of these companies have any connection to the project. If a visitor clicks “Buy,” they’re taken to a wallet dashboard that looks like a legitimate crypto platform, showing balances for “Google” (on a fictional “Google-Chain”), Bitcoin, and Ethereum. The purchase flow lets users buy any number of tokens they want and generates a corresponding Bitcoin payment request to a specific wallet address. The site also layers on a tiered bonus system that kicks in at 100 tokens and scales up to 100,000: buy more and the bonuses climb from 5% up to 30% at the top tier. It’s a classic upsell tactic designed to make you think it’s smarter to spend more. Every payment is irreversible. There is no exchange listing, no token with real value, and no way to get your money back. What to watch for We’re entering an era where the first point of contact in a scam may not be a human at all. AI chatbots give scammers something they’ve never had before: a tireless, consistent, scalable front-end that can engage victims in what feels like a real conversation. When that chatbot is dressed up as a trusted brand’s official AI assistant, the effect is even more convincing. According to the FTC’s Consumer Sentinel data, US consumers reported losing $5.7 billion to investment scams in 2024 (more than any other type of fraud, and up 24% on the previous year). Cryptocurrency remains the second-largest payment method scammers use to extract funds, because transactions are fast and irreversible. Now add AI that can pitch, persuade, and handle objections without a human operator—and you have a scalable fraud model. AI chatbots on scam sites will become more common. Here’s how to spot them: They impersonate known AI brands. A chatbot calling itself “Gemini,” “ChatGPT,” or “Copilot” on a third-party crypto site is almost certainly not what it claims to be. Anyone can name a chatbot anything. They won’t answer due diligence questions. Ask what legal entity operates the platform, what financial regulator oversees it, or where the company is registered. Legitimate operations can answer those questions, scam bots try to avoid them (and if they do answer, verify it). They project specific returns. No legitimate investment product promises a specific future price. A chatbot telling you that your $395 will become $2,755 is not giving you financial information—it’s running a script. They create urgency. Pressure tactics like, “stage 5 ends soon,” “listing date approaching,” “limited presale” are designed to push you into making fast decisions. How to protect yourself Google does not have a cryptocurrency. It has not launched a presale. And its Gemini AI is not operating as a sales assistant on third-party crypto sites. If you encounter anything suggesting otherwise, close the tab. Verify claim on the official website of the company being referenced. Don’t rely on a chatbot’s branding. Anyone can name a bot anything. Never send cryptocurrency based on projected returns. Search the project name along with “scam” or “review” before sending any money. Use web protection tools like Malwarebytes Browser Guard, which is free to use and blocks known and unknown scam sites. If you’ve already sent funds, report it to your local law enforcement, the FTC at reportfraud.ftc.gov, and the FBI’s IC3 at ic3.gov. IOCs 0xEc7a42609D5CC9aF7a3dBa66823C5f9E5764d6DA 98388xymWKS6EgYSC9baFuQkCpE8rYsnScV4L5Vu8jt DHyDmJdr9hjDUH5kcNjeyfzonyeBt19g6G TWqzJ9sF1w9aWwMevq4b15KkJgAFTfH5im bc1qw0yfcp8pevzvwp2zrz4pu3vuygnwvl6mstlnh6 r9BHQMUdSgM8iFKXaGiZ3hhXz5SyLDxupY Something feel off? Check it before you click. Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
malwarebytes.comFeb 18, 2026extracted
Phishing on the Edge of the Web and Mobile Using QR Codes
This article explores the misuse of QR codes in today's threat landscape, covering three areas of concern: QR codes using URL shorteners to disguise malicious destinations QR codes using in-app deep links to steal account credentials and take control of a victim's apps QR codes attempting to bypass app store security by linking to direct downloads of malicious apps With QR codes a notable presence in our everyday lives, some people instinctively scan them without hesitation. But QR codes are also a vector for attack. QR codes enable attackers to bypass organizational security by exploiting the weaker controls of personal mobile devices. By doing this, they can trick users into scanning codes and interacting with malicious destinations outside the corporate security perimeter. Over the past several months, we have tracked campaigns that used QR codes for phishing (known as quishing) and scams. Our telemetry reveals an average of over 11,000 detections of malicious QR codes each day. Investigating these detections, we found that attackers are leveraging QR code shorteners, in-app deep links and direct downloads to bypass people’s awareness and security controls. In addition to mass campaigns, we see attackers using QR codes for highly targeted messenger app phishing, such as targeting Ukrainian Signal users in the context of the Russia-Ukraine war. These findings necessitate further analysis of deep links and QR code data. Palo Alto Networks customers are better protected from the threats described in this article through the following products and services: If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. QR codes are not a new technology, but their prevalence has increased with the push for contactless interactions, especially during the initial emergency phase of the coronavirus pandemic. QR codes allow companies to interact seamlessly with their customer base for payments, enabling customers to join rewards programs and sign up for apps or mailing services. People have grown used to QR codes in daily life, and often scan them without sufficient caution, increasing their susceptibility to attacks. The popularity of QR codes has led to their use by attackers. In our offline web crawlers, we currently find an average of 75,000 detections of QR codes each day, with 15% of these pages containing QR codes leading to malicious links. This represents an average of over 11,000 detections of malicious QR code use each day. We looked beyond the recognized risks of QR codes. While straightforward QR code web-based attacks remain a threat, our focus shifted to understanding how attackers are leveraging the following trends to remain evasive to both victims and security controls: QR code shorteners In-app deep links (special URLs that allow people to open specific content within a mobile app) Direct app file downloads These tactics represent an evolution in QR code-based attacks that security teams need to address. Previous Unit 42 research has covered several key attack vectors for phishing QR codes hosted on documents, which are also relevant when hosted on websites. Attacks through these vectors can be effective for several reasons including: Lower user vigilance Security solutions having difficulty extracting URLs embedded in QR codes Complex redirection chains that obscure final destinations Weaker security controls on personal mobile devices Hosting on otherwise legitimate-looking pages Building upon this threat model, in-app deep links allow the attacker to target specific apps and trigger specific behavior (Figure 1). QR codes on websites need to be analyzed by security crawlers and other security solutions. To close this security gap, specific QR code detection techniques must be deployed to analyze the various data types stored in QR codes: Standard HTTPS URLs Deep links Non-URL content (e.g., JSON, plaintext) QR code shorteners are services that combine a URL shortener with a QR code generator to create a shorter, more scannable QR code that links to a long URL. These shorteners offer benefits such as reducing the size of the QR code, allowing attackers to change the destination URL later, and tracking scan data in a single dashboard. In-app deep links are hyperlinks that direct visitors to a specific screen or content within a mobile app. In-app deep links can use both custom URL schemes (i.e., sms:+1234567890:Hello, tg[:]//login?token= ) or standard web URLs (i.e., hxxps[:]//wa[.]me/settings/linked_devices#) that the operating system redirects to the app. Figure 2 shows an example that displays a phishing site impersonating a job match and training program website that hosts a payment in-app deep link. Deep links are often used to improve user experience by reducing the number of steps to access specific content from external sources like emails, social media, authentication tokens or ads. Attackers use QR code shorteners to mask malicious destinations. QR code shorteners convert a static image into a dynamic endpoint. Consequently, the attacker can change the redirect destination at will. The attacker is also able to leverage the good reputation of QR code shortener services to evade detection of malicious activity. Even security-conscious people who check the URL preview before scanning cannot determine the final destination when presented with shortened links. This technique effectively prevents targets from being aware of potential threats until after the malicious payload has been delivered. Our previous article has already talked about the risk of URL shorteners more broadly. However, the combination of a QR code and URL shortener is even more likely to bypass scrutiny. We have seen QR code shortener traffic grow steadily over the past three years (Figure 3). We see a steady increase of QR code shortener traffic in our telemetry. This includes a 55% increase from the first half of 2023 to the first half of 2024 and a 44% increase from the first half of 2024 to the first half of 2025. This data is based on the following popular QR code shortener services: qrcc[.]io qrco[.]de me-qr[.]com qr[.]io qrfy[.]com qrfy[.]io get-qr[.]com qr[.]ne, qrs[.]ly Our telemetry reveals that qrco[.]de, me-qr[.]com and qrs[.]ly are the most used QR code shorteners. Compared to the top QR code shorteners mentioned in the Anti-Phishing Working Group (APWG) phishing trends report [PDF], qrs[.]ly is a notable new addition as the QR code shortener used in 7.3% of the malicious URLs observed. Financial services was the most impacted industry when considering compromised QR code shorteners, accounting for 29% of this type of attack. This is followed by high tech (19%) and wholesale and retail (14%). Significantly, QR code shorteners for financial services make up only 4.8% of this type of traffic as a whole. This makes the high percentage of compromised QR code shorteners for financial services even more striking as shown in Figure 4 The webpage shown in Figure 5 is a popular file-sharing platform containing a QR code that appears to imitate a school by including its logo. Upon analysis, we found that it is a QR code shortener that first redirects to a CAPTCHA page and then lands on a phishing page that impersonates Outlook hosted on cdnimg.jeayacrai[.]in[.]net. After a few days, the URL from this QR code no longer worked, illustrating how QR code shorteners are often ephemeral and can quickly cease redirecting to the original malicious endpoint. Modern mobile devices support a wide range of QR code actions beyond simple web browsing. The distribution of in-app deep links in QR codes is an understudied area despite its exploitability. In-app deep links account for about three percent of the QR codes in our telemetry. Attackers can either misuse app functionality (e.g., adding a trusted device, or sending a payment), or push malicious content to those apps (such as, adding malicious links to calendar invites). Defenders face a challenge in detecting malicious in-app deep links embedded in QR codes because the activity generated by these links is often invisible to standard web crawlers. Effective detection necessitates a mobile sandbox environment with the specific app installed to properly observe and analyze this activity. Custom in-app deep links lack standardization across applications. This makes identifying malicious signals difficult to generalize, often requiring individualized investigation for each case. Both iOS and Android devices can process QR codes with in-app deep links that have direct app integration. We categorize in-app deep links as those that apply to the following types of apps: Social media and communications App stores Payment System utilities (e.g., Wi-Fi, contacts, calendar, telephone, email, SMS, navigation) The three most popular custom app URLs that we found were for Telegram, XHS Discover (RedNote) and Line, which respectively account for 44.7%, 1.8% and 0.8% of in-app deep links. As we discuss later, attackers commonly misuse Telegram and Line. In-app deep links enable additional cross-device interactions, creating new attack scenarios via QR codes. Table 1 lists some examples of the attack chain scenarios possible through in-app deep links. Table 1. Attack scenarios involving in-app deep links. Many of these attack scenarios involve embedding malicious URLs into specific data entries stored in mobile apps. Figure 6 illustrates this for contact poisoning, where a malicious URL is embedded in a saved contact card. Some of the scenarios described in Table 1 were not observed in our data collection, while others were. The ones not observed are plausible, but hypothetical scenarios. We will further discuss the scenarios observed in our data collection below. Financial in-app deep links represent a significant financial risk to potential victims. QR codes are commonly used in legitimate business transactions to facilitate payments, making it straightforward for attackers to misuse this trusted interaction through phishing schemes. We observed legitimate in-app deep links from popular payment apps such as: WeChat Pay Alipay Bitcoin Ethereum LitCoin Metamask Trust (wallet) The familiarity and trust people have with payment-related QR codes create an ideal environment for social engineering attacks, where malicious QR codes can closely mimic legitimate payment requests. Phishing campaigns using pressure tactics can manipulate people into making quick payments. Below, we share a few examples where an attacker attempts to trigger a financial transaction using a QR code. Figure 7 includes two examples. The first example is a phishing campaign claiming easy returns on investment, asking for an initial payment through a Bitcoin in-app deep link. The second example is a hacking for hire service advertising and providing easy payment with a WeChat payment in-app deep link. Figure 8 illustrates another get-rich-quick phishing scheme that requests an initial payment through a popular cryptocurrency wallet via a QR code with an in-app deep link. Account takeovers through in-app deep links appear to be a significant phishing vector for messaging and social media sites. Telegram, in particular, was the most prominent application identified in our analysis that uses custom in-app deep links. We found over 35,000 QR codes that contain Telegram in-app deep links such as tg[:]//login or tg[:]//resolve and we observed multiple instances where attackers exploited these links to compromise accounts. We saw three kinds of Telegram in-app deep links: Login Resolve Proxy Login accounted for 97% of the Telegram in-app deep links observed. Login grants the QR code creator authorization to access your account. Previous reporting of Telegram in-app deep link scams warns about these account takeover attacks. Roughly one out of every five host pages with a login Telegram in-app deep link is malicious, based on our conservative estimate. Figure 9 includes two examples of such Telegram login scams. However, while Telegram is the most popular, attackers are also targeting other popular communication apps. Figure 10 shows an example of a QR code containing an in-app deep link that requests authorization to a target's Line account. This would allow attackers to send Line messages under the device and account owner’s name. Of note, Line has since deprecated this in-app deep link, and the link will now result in an error. Figure 11 shows an example of a QR code containing an in-app deep link that requests authorization to access a target's Signal account. Figure 12 shows an example of a QR code containing an in-app deep link that requests authorization to access a target's WhatsApp account. In addition to mass phishing campaigns, there's a clear trend toward more focused attacks aimed at stealing Signal credentials. For instance, the Google Threat Intelligence Group (GTIG) has documented increased efforts by Russia state-aligned actors to compromise Signal Messenger accounts. These attacks frequently misuse Signal's feature to link devices with malicious QR codes. Many of these campaigns have targeted Ukraine in the context of the Russia-Ukraine war. In July 2024, the CERT-UA reported on several threat groups, such as UAC-0185 (aka UNC4221), that have specifically targeted messenger accounts. Our researchers continue to observe new malicious domains targeting Ukrainian Signal users, including snitch.open-group[.]site and similar variations. After linking a new session to Signal accounts, the attackers can exfiltrate message history and other account information. We have reported discovered information to our Ukrainian cybersecurity partners. Figure 13 shows a QR code from a campaign targeting Ukraine-based Signal accounts. QR codes are widely used for easy downloading of files and applications. Attackers can exploit this convenience to trick victims into downloading malicious content or installing harmful mobile applications. Major app stores impose strict security and compliance guidelines to limit the distribution of harmful apps. However, attackers may circumvent these security measures by distributing links to unreviewed Android Package Kit (APK) files hosted on their own servers via QR codes. Our investigation identified 59,000 detections of host pages distributing a total of 1,457 distinct APK files directly through QR codes, without going through any app store. Notable examples of these distributed APKs are listed below. Gambling and casino games websites are distributing their apps through APK files in QR codes. Figures 14-16 illustrate some examples of such host pages. They are all hosted by many different domains and request certain Android permissions that could be concerning to people. Figure 14 shows an ad for a popular game that includes a QR code, which redirects the victim to another QR code to download a game app named yicai.apk from f9999[.]app. This QR code is hosted on 10,022 unique URLs. The app requests read and write permissions to the device's external storage and camera. It also requests install packages permissions. Figure 14 shows an ad for another game hosted on 9,161 unique URLs. The URL used in Figure 15 is hxxps[:]//pyreneesakbash[.]com/m-nagapoker/android.html. The file for the game is named NagaPocker.apk, and it requests write to external storage and internet permissions. Figure 16 shows an app distributed through two different pages. Named app-u7cp-release.apk, the app requests: Access to coarse location Access to fine location Background location Read and write access to external storage Read phone state Camera permissions Warnings from Trustwave about malicious APK files highlight that these types of gambling and betting apps expose victims to harmful activity, such as: Excessive advertising Theft of personal data Theft of funds Hidden fees Subscriptions These apps provide financial incentives for engagement, prolonging the life of such scams. Allowing victims to download apps directly and bypassing official app stores enables attackers to circumvent app verification procedures. Many campaigns hosting QR codes that pointed to a given APK file did so across numerous domains. The apps request suspicious Android permissions, most notably write external storage, camera and access fine location. These permissions could allow intentional data exfiltration, accidental data leakage and surveillance. The aggressive distribution across many different host pages, stealthy methods and excessive permissions suggest malicious intent. Though gambling apps account for a large portion of the QR codes distributing APK files, QR codes also distribute other kinds of suspicious apps. Figure 17 illustrates two examples. The first example is a phone optimization app named ludashi_home.apk. It requests the following permissions: Recording audio Reading battery status Reading phone state Accessing the camera Reading and writing to external storage Authenticating accounts Clearing the app cache Installing packages permissions The second example is a social network app for educators named k12sns.apk. This app also requests several different types of permissions: Accessing the internet Reading logs Waking the lock Reading the phone state Writing to external storage Several vendors detect these apps as suspicious or malicious, and they extract sensitive information from the device they are installed on. For example, the phone optimization app can take on certain behaviors like authenticating accounts and installing further packages, which attackers can misuse for malicious gains. The attack scenarios and variety of examples we've discovered illustrate the extensive potential and existing prevalence of QR code misuse. The fundamental challenges of this type of misuse are user awareness and lack of visibility from current detection systems. Most people scanning QR codes don't anticipate the broad range of device functions that can be triggered from in-app deep links or unexpected endpoints from QR code shorteners. This expectation mismatch creates a significant security weak spot that attackers can actively exploit. User education remains critical — people need to understand that QR codes can do much more than simply open webpages. Palo Alto Networks customers are better protected from the threats discussed above through the following products: Customers using Advanced URL Filtering and Prisma Browser (with Advanced Web Protection) are better protected against various QR code attacks. Our detectors analyze QR code landing pages and deep links. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. The authors would like to thank Bradley Duncan and Billy Melicher for the thorough technical review of the article. We would also like to thank the editorial team including Samantha Stallings and Lysa Myers for the assistance with improving and publishing this article. Examples of URLs for QR code shorteners: hxxps[:]//www.dropbox[.]com/scl/fi/7e8xqrcxgzftrk61omgn0/Presentation.pptx?rlkey=xgk24xllhh4qqv1li2ifd3e3s&st=xvtu5b7y&dl=0 hxxps[:]//qrco[.]de/bgP6vx hxxps[:]//cdnimg.jeayacrai[.]in[.]net/qY42h5ei3SBo9ZmvO!/ Examples of URLs for financial scams: hxxp[:]//kccomputech[.]in/babukh1513273 upi://pay?pa=Q573631163@ybl&pn=PhonePeMerchant&mc=0000&mode=02&purpose=00 hxxps[:]//20.217.81[.]20 bitcoin:12wXzmwak8LJ88e1ejupY3brfQi43xdDhb hxxps[:]//csdh.wangzhan[.]mobi wxp[:]//f2f04lGLqnDoxxeZnftA79yXXU-BeXrgkdYL solulu[.]vip metamask[:]//connect?channelId=d92099ec-28e3-4eed-97e8-3c40c656f555&v=2&comm=socket&pubkey=021f24e23edc0cbb73440dc2ac94b5a458371cc7c9ce8551b1b68db2196443c2ba&t=q&originatorInfo=eyJ1cmwiOiJodHRwOi8vc29sdWx1LnZpcCIsInRpdGxlIjoid2FnbWkiLCJpY29uIjoiaHR0cDovL3NvbHVsdS52aXAvbG9nby5wbmciLCJzY2hlbWUiOiIiLCJhcGlWZXJzaW9uIjoiMC4zMy4xIiwiZGFwcElkIjoic29sdWx1LnZpcCIsImFub25JZCI6Ijk1ZDcyY2M3LTYwYWYtNGI5Yi1hZTJiLTk4YmE4MDcxZmQwZiIsInBsYXRmb3JtIjoid2ViLWRlc2t0b3AiLCJzb3VyY2UiOiJ3YWdtaSJ9 Examples of URLs and domains for Telegram account takeover: hxxps[:]//fable.tele-tale[.]cn tg[:]//login?token=AQJgx85oZgPcBRoIg76p-8BBy4nB4Wpel-PvZ8Og7t_--A Olb228hoki[.]live radenspinrtp[.]cloud bostonsportsthenandnow[.]com slotolb228[.]com tg[:]//login?token=AQI-jOVkNxCqKYy-wB6VFz-nE-eo-l-tFtgZ3VPshaKJ0A Examples of URLs and domains for Signal account takeover: hxxp[:]//www.sgnl-web[.]org-status.nl/ hxxps[:]//signal-qr[.]org/chatZGtqZmpic2l1NDkzdWpka25zamRucDJ1MDllamtmOThyNGltdmZkZw==/ty62i signal.skyriver[.]ch Examples of phishing domains targeting Ukrainian Signal users: snitch.open-group[.]site gui.snitch-dev[.]site gui.dev-snitch[.]site gui.snitch-dev[.]xyz gui.dev-snitch[.]xyz gui.snitch-dev[.]online gui.dev-snitch[.]online gui.dev-snitch[.]site gui.dev-snitch[.]cloud snitch-dev[.]space gui-snitch[.]online gui-grafit[.]online kropyva-group[.]online Examples of URLs for Line account takeover: hxxps[:]//link.members-ms[.]jp/view/clickCount?cst_id=000000000003690&msg_id=0000000000000000000000833677&deli_date=20251029&redirect_uri=hxxps%3A%2F%2Fliff.line.me%2F2007686667-M9geAqrB%3Fid%3D5%3FROUTE_KBN%3D12&msg_type=1&sec_msg=BtBnJY9kxxWnP%2BQt3ycGtVVhajc%3D&sec_date=zVK0EnCA1F8siaD0nf4Nsq1VRlc%3D&sec_uri=P85jU5m9ynEk1wr9ltPW%2Fh%2BJrxE%3D&sec_type=XWWoEGkCR%2BDRAsxfdW4dQHnr%2FbI%3D line[:]//app/2007686667-M9geAqrB?liff.state=%3Fid%3D5%253FROUTE_KBN%253D12%26cst_id%3D000000000003690%26msg_id%3D0000000000000000000000833677%26deli_date%3D20251029&liff.referrer=hxxps%3A%2F%2Fbing[.]com%2F&liff.source=lp_qr Examples of URLs and domains for WhatsApp account takeover: hxxps[:]//kzeva2010[.]sbs/MZApUU1aJ3LSYi86IrAZ hxxps[:]//wa[.]me/settings/linked_devices#2@vxFKwMU92ToQ60n6gPIw/SLkNcoYVu1XKW+/zMiBEuslO63jfBCCZX/f1mOrkxrAqkp4DaSzq5MX7CcvOJqrNDSJQRLKgXP7K2A=,tZrifOdd4aLBy9nrncQVsa0WqVcYmJnFSs8nEpt3URs=,DfpvHVSe6SmZWxAgVdYXsYz2FsD7DQ3NgmGybCNMHHY=,Ipp5goLgYXXn+7Swuw+pGX77EFECRemAHS5gfOJE7G4=,1 hxxps[:]//xlq.wpybta[.]icu hxxps[:]//wa[.]me/settings/linked_devices#2@8zRSshgXZVfdYcvUvycaOQJlQBcjUDomiqdxC8uQEowH5TQLr/P+1QbxvrXPV4tKg23mqzQeMpPRp3ofr4mePrur/YN4ztk6fWY=,FaknzsibNU+yi9cvuQKDgI3eBh+KEY2TQHqilwZ+KRs=,Rpz7L5S/72o1Ust4Y6CZ3tC7gf6yQvJdd80IFbZzdiw=,eZyTFPAbZWlFUXjGbrvBCM4ApoYT50kFXQb+/cTMzPw=,1 wswwc[.]icu awawc[.]icu ve1edm[.]cc ve2edm[.]cc weppf[.]icu Examples of URLs hosting APK files for gambling game hxxps[:]//gricanjolt[.]com?r=aHR0cHM6Ly9mOTk5OS5hcHA=1 hxxps[:]//pyreneesakbash[.]com/m-nagapoker/android[.]html hxxps[:]//resourcepro.tycheint[.]com/yicai[.]apk hxxps[:]//90999.fdjk34sddsf90999[.]cc/xincai[.]apk hxxps[:]//gld45a.cqxqlsz[.]com/fusion2023/android/app-u7cp-release[.]apk hxxps[:]//azojwdsj.xinchaoshan[.]com/fusion2023/android/app-u7cp-release[.]apk hxxp[:]//www.ludashi[.]com/cms/android/special/download[.]html hxxp[:]//t.k12[.]com[.]cn/k12sns[.]apk Deep Link - Android, Google Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon – Unit 42, Palo Alto Networks Myth Busting: Why "Innocent Clicks” Don’t Exist in Cybersecurity – Unit 42, Palo Alto Networks Phishing Activity Trends Report Q1 2025 [PDF] – Anti-Phishing Working Group (APWG) Telegram QR Phishing Threat: Account Takeover with a Single Scan - CIP blog, Criminal IP Signals of Trouble: Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger – Google Threat Intelligence Group (GITG), Google Unmasking Malicious APKs: Android Malware Blending Click Fraud and Credential Theft – Trustwave, A LevelBlue Company Dangerous new Android malware adds fake contacts to your phone while draining bank accounts — how to stay safe – Tom’s Guide Phishing Alert: Calendar-Based Phishing Attack – Trinity College Unit 42 Cryptocurrency Scam Chatbot Activity – Unit 42, Palo Alto Networks
unit42.paloaltonetworks.comFeb 13, 2026extracted
LLMs work better together in smart contract audits
LLMs work better together in smart contract audits Smart contract bugs continue to drain real money from blockchain systems, even after years of tooling and research. A new academic study suggests that large language models can spot more of those flaws when they work in coordinated groups instead of alone. Researchers at Georgia Tech have developed a framework called LLMBugScanner that combines fine tuned language models with ensemble voting to detect vulnerabilities in Ethereum smart contracts. The research evaluates whether pairing domain specific training with model consensus can improve accuracy without driving up cost or complexity. The study focuses on one persistent problem in smart contract security. Once deployed, contracts cannot be changed, and even small logic errors can lead to permanent loss of funds. Traditional static and symbolic analysis tools still struggle with false positives and blind spots, especially when contracts deviate from known patterns. The researchers argue that language models can reason about intent and logic in ways rules based tools cannot, but only if their weaknesses are addressed. Why single models fall short The researchers tested several popular open source code focused language models on real world vulnerable contracts. On their own, these models showed uneven results. Some performed well on common issues like integer overflow, while missing other classes such as access control or flawed logic. One issue was inconsistency. The same model could flag different vulnerabilities across runs or misclassify one type as another. Another issue was overfitting. Fine tuning a model on one dataset improved results for some bug types while reducing performance elsewhere. These problems limited the usefulness of single model approaches for auditors who need stable and repeatable results. The researchers concluded that no single language model performed well across all vulnerability categories. Training models with smart contract context To address this, the team applied domain knowledge adaptation. They fine tuned each model in two stages. The first stage used a dataset of 775 Solidity smart contracts labeled with known vulnerability types to improve general code understanding. The second stage used a smaller subset of CVE labeled contracts to teach the models how to identify and describe specific flaws. This sequential fine tuning reduced confusion between unrelated bug categories. In one example shown in the paper, a baseline model frequently mislabeled access control and logic errors as integer overflow. After fine tuning, the same model showed stronger separation between vulnerability types. The researchers used parameter efficient tuning methods to limit compute costs. Only a small fraction of model parameters were updated, making the approach practical for repeated training runs. Letting models vote The second part of the framework focuses on ensemble learning. Instead of relying on one adapted model, LLMBugScanner combines predictions from five independently fine tuned models. Each model analyzes the same contract, and the system aggregates results using voting methods. Two ensemble strategies were tested. One uses weighted voting, where stronger models carry more influence. The other resolves ties based on learned model priority. Both methods aim to capture complementary strengths while reducing noise from individual errors. The evaluation used 108 real world smart contracts with known vulnerabilities from the CVE database. Results showed that the ensemble approach improved detection rates compared to any single model. The weighted ensemble reached a top five detection accuracy of about 60 percent, which was roughly 19 percent higher than individual baselines. Gains and limits in the results The strongest improvements appeared in top five results, which matters in audit workflows where analysts review short lists rather than single outputs. The ensemble recovered some vulnerabilities that the best individual model missed, especially for integer overflow and token devaluation issues. Precision gains were more mixed for top one predictions. The permutation based ensemble produced stronger single best guesses, while weighted voting favored broader coverage. The researchers note that these differences reflect tradeoffs between precision and recall depending on how results are consumed. The study also highlights limits. Minority vulnerability classes such as access control and constructor errors remained hard to detect, even with ensembles. In cases where all models lacked sufficient training examples, voting could not correct shared weaknesses. Hallucination remained another concern. Across models, about 10 percent of outputs included invented or unsupported vulnerabilities. The researchers suggest combining language models with symbolic checks or confidence estimation in future work. What changes when models audit together The research frames language models as complementary systems that benefit from structured training and collaboration. For security leaders overseeing blockchain risk, the findings suggest that model diversity and consensus can matter as much as model size. LLMBugScanner also reinforces a broader point. Applying language models to security tasks requires adaptation, evaluation, and orchestration. Without that structure, results can look promising in isolation but fail under real conditions. The researchers emphasize that the framework is extensible and cost aware, making it suitable for continued experimentation. Future directions include learning based ensemble selection and stronger controls for hallucination. For now, the study offers evidence that smart contract audits improve when language models do not work alone, but reason together.
helpnetsecurity.comDec 19, 2025extracted
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware
Threat actors with ties to North Korea have likely become the latest to exploit the recently disclosed critical React2Shell security flaw in React Server Components (RSC) to deliver a previously undocumented remote access trojan dubbed EtherRAT. "EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution, deploys five independent Linux persistence mechanisms, and downloads its own Node.js runtime from nodejs.org," Sysdig said in a report published Monday. The cloud security firm said the activity exhibits significant overlap with a long-running campaign codenamed Contagious Interview, which has been observed leveraging the EtherHiding technique to distribute malware since February 2025. Contagious Interview is the name given to a series of attacks in which blockchain and Web3 developers, among others, are targeted through fake job interviews, coding assignments, and video assessments, leading to the deployment of malware. These efforts typically begin with a ruse that lures victims via platforms like LinkedIn, Upwork, or Fiverr, where the threat actors pose as recruiters offering lucrative job opportunities. According to software supply chain security company Socket, it's one of the most prolific campaigns exploiting the npm ecosystem, highlighting their ability to adapt to JavaScript and cryptocurrency-centric workflows. The attack chain commences with the exploitation of CVE-2025-55182 (CVSS score: 10.0), a maximum-severity security vulnerability in RSC, to execute a Base64-encoded shell command that downloads and runs a shell script responsible for deploying the main JavaScript implant. The shell script is retrieved using a curl command, with wget and python3 used as fallbacks. It is also designed to prepare the environment by downloading Node.js v20.10.0 from nodejs.org, following which it writes to disk an encrypted blob and an obfuscated JavaScript dropper. Once all these steps are complete, it proceeds to delete the shell script to minimize the forensic trail and runs the dropper. The primary goal of the dropper is to decrypt the EtherRAT payload with a hard-coded key and spawn it using the downloaded Node.js binary. The malware is notable for using EtherHiding to fetch the C2 server URL from an Ethereum smart contract every five minutes, allowing the operators to update the URL easily, even if it's taken down. "What makes this implementation unique is its use of consensus voting across nine public Ethereum remote procedure call (RPC) endpoints," Sysdig said. "EtherRAT queries all nine endpoints in parallel, collects responses, and selects the URL returned by the majority." "This consensus mechanism protects against several attack scenarios: a single compromised RPC endpoint cannot redirect bots to a sinkhole, and researchers cannot poison C2 resolution by operating a rogue RPC node." It's worth noting that a similar implementation was previously observed in two npm packages named colortoolsv2 and mimelib2 that were found to deliver downloader malware on developer systems. Once EtherRAT establishes contact with the C2 server, it enters a polling loop that executes every 500 milliseconds, interpreting any response that's longer than 10 characters as JavaScript code to be run on the infected machine. Persistence is accomplished by using five different methods - Systemd user service XDG autostart entry Cron jobs .bashrc injection Profile injection By using multiple mechanisms, the threat actors can ensure the malware runs even after a system reboot and grants them continued access to the infected systems. Another sign that points to the malware's sophistication is the self-update ability that overwrites itself with the new code received from the C2 server after sending its own source code to an API endpoint. It then launches a new process with the updated payload. What's notable here is that the C2 returns a functionally identical but differently obfuscated version, thereby possibly allowing it to bypass static signature-based detection. In addition to the use of EtherHiding, the links to Contagious Interview stem from overlaps between the encrypted loader pattern used in EtherRAT and a known JavaScript information stealer and downloader named BeaverTail. "EtherRAT represents a significant evolution in React2Shell exploitation, moving beyond opportunistic cryptomining and credential theft toward persistent, stealthy access designed for long-term operations," Sysdig said. "Whether this represents North Korean actors pivoting to new exploitation vectors or sophisticated technique borrowing by another actor, the result is the same: defenders face a challenging new implant that resists traditional detection and takedown methods." Contagious Interview Shifts from npm to VS Code The disclosure comes as OpenSourceMalware revealed details of a new Contagious Interview variant that urges victims to clone a malicious repository on GitHub, GitLab, or Bitbucket as part of a programming assignment, and launch the project in Microsoft Visual Studio Code (VS Code). This results in the execution of a VS Code tasks.json file due to it being configured with runOptions.runOn: 'folderOpen,' causing it to auto-run as soon as the project is opened. The file is engineered to download a loader script using curl or wget based on the operating system of the compromised host. In the case of Linux, the next stage is a shell script that downloads and runs another shell script named "vscode-bootstrap.sh," which then fetches two more files, "package.json" and "env-setup.js," the latter of which serves as a launchpad for BeaverTail and InvisibleFerret. OpenSourceMalware said it identified 13 different versions of this campaign spread across 27 different GitHub users and 11 different versions of BeaverTail. The earliest repository ("github[.]com/MentarisHub121/TokenPresaleApp") dates back to April 22, 2025, and the most recent version ("github[.]com/eferos93/test4") was created on December 1, 2025. "DPRK threat actors have flocked to Vercel, and are now using it almost exclusively," the OpenSourceMalware team said. "We don't know why, but Contagious Interview has stopped using Fly.io, Platform.sh, Render and other hosting providers."
thehackernews.comDec 9, 2025extracted
North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks
A new malware implant called EtherRAT, deployed in a recent React2Shell attack, runs five separate Linux persistence mechanisms and leverages Ethereum smart contracts for communication with the attacker. Researchers at cloud security company Sysdig believe that the malware aligns with North Korea's tools used in Contagious Interview campaigns. They recovered EtherRAT from a compromised Next.js application just two days after the disclosure of the critical React2Shell vulnerability tracked as CVE-2025-55182. Sysdig highlights EtherRAT's mix of sophisticated features, including blockchain-based command-and-control (C2) communication, multi-layered Linux persistence, on-the-fly payload rewriting, and evasion using a full Node.js runtime. Although there are substantial overlaps with "Contagious Interview" operations conducted by Lazarus, EtherRAT is different in several key aspects. React2Shell is a max-severity deserialization flaw in the React Server Components (RSC) "Flight" protocol that allows unauthenticated remote code execution via a crafted HTTP request. The flaw impacts a large number of cloud environments running React/Next.js, and its exploitation in the wild started hours after the public disclosure late last week. Some of the first threat actors leveraging it in attacks are China-linked groups Earth Lamia and Jackpot Panda. Automated exploitation followed, and at least 30 organizations across multiple sectors were breached to steal credentials, cryptomining, and deploy commodity backdoors. EtherRAT attack chain EtherRAT uses a multi-stage attack chain, starting with the exploitation of React2Shell to execute a base64-encoded shell command on the target, Sysdig says. The command attempts to download a malicious shell script (s.sh) with curl, wget, or python3 as fallbacks, and loops every 300 seconds until successful. When the script is fetched, it is checked, turned into an executable, and launched. The script creates a hidden directory in the user's $HOME/.local/share/ location where it downloads and extracts a legitimate Node.js v20.10.0 runtime directly from nodejs.org. It then writes an encrypted payload blob and an obfuscated JavaScript dropper that is executed using the downloaded Node binary, and then deletes itself. The obfuscated JavaScript dropper (.kxnzl4mtez.js) reads the encrypted blog, decrypts it using a hardcoded AES-256-CBC key, and writes the result as another hidden JavaScript file. The decrypted payload is the EtherRAT implant. It is deployed using the Node.js binary that had been installed in the previous stage. Marks of an advanced implant EtherRAT uses Ethereum smart contracts for C2 operations, which provide operational versatility and resistance to takedowns. It queries nine public Ethereum RPC providers in parallel and picks the majority-response result, which prevents single-node poisoning or sinkholing. The malware sends randomized CDN-like URLs to the C2 every 500 ms and executes JavaScript returned from the operators using an AsyncFunction constructor in a mechanism that works as a fully interactive Node.js shell. North Korean hackers have used smart contracts before to deliver and distribute malware. The technique is called EtherHiding and has been described before in reports from Google and GuardioLabs. Additionally, Sysdig researchers note that "the encrypted loader pattern used in EtherRAT closely matches the DPRK-affiliated BeaverTail malware used in the Contagious Interview campaigns." EtherRAT persistence on Linux Sysdig comments that the EtherRAT malware has extremely aggressive persistence on Linux systems, as it installs five layers for redundancy: Cron jobs bashrc injection XDG autostart Systemd user service Profile injection By using multiple persistence methods, the operator of the malware makes sure that they continue to have access to the compromised hosts even after system reboots and maintenance. Another unique feature in EtherRAT is its ability to self-update by sending its source code to an API endpoint. The malware receives replacement code that has the same capabilities but uses different obfuscation, overwrites itself with it, and then spawns a new process with the updated payload. Sysdig hypothesizes that this mechanism helps the malware evade static detection and may also help prevent analysis or introduce mission-specific functionality. With React2Shell exploitation underway by numerous actors, system administrators are recommended to upgrade to a safe React/Next.js version as soon as possible. Sysdig provides in its report a short list of indicators of compromise (IoCs) associated with EtherRAT's staging infrastructure and Ethereum contracts. The researchers recommend that users check for the listed persistence mechanisms, monitor Ethereum RPC traffic, review application logs, and rotate credentials. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comDec 9, 2025extracted
Malicious Rust Crate Delivers OS-Specific Malware to Web3 Developer Systems
Cybersecurity researchers have discovered a malicious Rust package that's capable of targeting Windows, macOS, and Linux systems, and features malicious functionality to stealthily execute on developer machines by masquerading as an Ethereum Virtual Machine (EVM) unit helper tool. The Rust crate, named "evm-units," was uploaded to crates.io in mid-April 2025 by a user named "ablerust," attracting more than 7,000 downloads over the past eight months. Another package created by the same author, "uniswap-utils," listed "evm-units" as a dependency. It was downloaded over 7,400 times. The packages have since been removed from the package repository. "Based on the victim's operating system and whether Qihoo 360 antivirus is running, the package downloads a payload, writes it to the system temp directory, and silently executes it," Socket security researcher Olivia Brown said in a report. "The package appears to return the Ethereum version number, so the victim is none the wiser." A notable aspect of the package is that it is explicitly designed to check for the presence of the "qhsafetray.exe" process, an executable file associated with 360 Total Security, an antivirus software developed by Chinese security vendor Qihoo 360. Specifically, the package is designed to invoke a seemingly harmless function named "get_evm_version()," which decodes and reaches out to an external URL ("download.videotalks[.]xyz") to fetch a next-stage payload depending on the operating system on which it's being run - On Linux, it downloads a script, saves it in /tmp/init, and runs it in the background using the nohup command, enabling the attacker to gain full control On macOS, it downloads a file called init and runs it using osascript in the background with the nohup command On Windows, it downloads and saves the payload as a PowerShell script file ("init.ps1") in the temp directory and checks running processes for "qhsafetray.exe," before invoking the script In the event the process is not present, it creates a Visual Basic Script wrapper that runs a hidden PowerShell script with no visible window. If the antivirus process is detected, it slightly alters its execution flow by directly invoking PowerShell. "This focus on Qihoo 360 is a rare, explicit, China-focused targeting indicator, because it is a leading Chinese internet company," Brown said. "It fits the crypto-theft profile, as Asia is one of the largest global markets for retail cryptocurrency activity." The references to EVM and Uniswap, a decentralized cryptocurrency exchange protocol built on the Ethereum blockchain, indicate that the supply chain incident is designed to target developers in the Web3 space by passing off the packages as Ethereum-related utilities. "Ablerust, the threat actor responsible for the malicious code, embedded a cross-platform second-stage loader inside a seemingly harmless function," Brown said. "Worse, the dependency was pulled into another widely used package (uniswap-utils), allowing the malicious code to execute automatically during initialization."
thehackernews.comDec 3, 2025extracted
The $9M yETH Exploit: How 16 Wei Became Infinite Tokens
The $9M yETH Exploit: How 16 Wei Became Infinite Tokens December 2, 2025 By: Dikla Barda, Roman Zaikin, and Oded Vanunu On November 30, 2025, Check Point Research detected a critical exploit targeting Yearn Finance’s yETH pool on Ethereum. Within hours, approximately $9 million was stolen from the protocol. The attacker achieved this by minting an astronomical number of tokens—235 septillion yETH (a 41-digit number)—while depositing only 16 wei, worth approximately $0.000000000000000045. This represents one of the most capital-efficient exploits in DeFi history. The Vulnerability: Cached Storage Flaw The attack exploited a critical flaw in how the protocol manages its internal accounting. The yETH pool caches calculated values in storage variables called packed_vbs[] to save on gas costs. These variables store virtual balance information that tells the protocol how much value exists in the pool. The vulnerability emerged when the pool was completely emptied—while the main supply counter correctly reset to zero, the cached packed_vbs[] values were never cleared. How the Attack Was Executed The attacker executed the exploit in three stages: First, they performed over ten deposit-and-withdrawal cycles using flash-loaned funds, deliberately leaving small residual values in the packed_vbs[] storage with each iteration. Second, they withdrew all remaining liquidity, bringing the supply to zero while the cached values remained populated with accumulated phantom balances. Finally, they deposited just 16 wei across eight tokens. The protocol detected that supply was zero and triggered its “first-ever deposit” logic, which read the cached values from storage. Instead of minting tokens based on the 16 wei actually deposited, the protocol read the accumulated phantom values and minted trillions upon trillions of LP tokens, giving the attacker control over the entire pool. Background: The yETH Ecosystem Protocol Architecture Yearn Finance’s yETH is a liquid staking token representing a basket of Ethereum-based liquid staking derivatives (LSDs). The protocol consists of three main components: yETH Token – A standard ERC20 token with minter privileges yETH Pool – A weighted stableswap AMM (Automated Market Maker) pool Rate Providers – Oracle contracts that provide exchange rates for various LSDs The pool contract implements a complex mathematical invariant based on weighted pool mechanics (similar to Balancer), adapted with Curve-style virtual balances for gas optimization. The Pool’s Core Mechanism Unlike simple constant-product AMMs (x × y = k), the yETH pool uses a sophisticated invariant that accounts for: Multiple assets (up to 32) Weighted ratios for each asset Exchange rates for LSDs (wstETH, rETH, cbETH, etc.) The pool stores these virtual balances in state variables to avoid recalculating them on every operation—a gas optimization that became the source of the vulnerability. The Vulnerability: Incomplete State Cleanup The Core Bug The vulnerability exists in the interaction between two functions: remove_liquidity() and add_liquidity(). In remove_liquidity() (lines 590-654): The Problem: When ALL LP tokens are burned (supply == 0), the virtual balances are decremented proportionally but never explicitly reset to zero. Due to rounding, tiny amounts remain in self.packed_vbs[].S In add_liquidity() (lines 523-528): In _calc_vb_prod_sum() (lines 729-744): The Fatal Flaw: This function reads self.packed_vbs[asset] from storage, expecting them to be zero for a “first deposit” scenario. However, after multiple deposit/withdrawal cycles, these storage slots contain accumulated residual values that were never reset. The Exploit Transaction: A Technical Walkthrough Phase 1: Capital Acquisition The attacker borrowed assets via flash loans from Balancer and Aave, obtaining wstETH, rETH, WETH, ETHx, and cbETH without upfront capital. Phase 2: State Poisoning The attacker executed multiple deposit-withdrawal cycles to accumulate residual values in packed_vbs[] storage. Each cycle deposited assets into vaults and the yETH pool, then withdrew portions. The virtual balances decremented but never fully reset. Phase 3: Pool Drain The attacker burned all remaining LP tokens, setting self.supply = 0 while self.packed_vbs[] retained accumulated values and was NOT reset. Phase 4: Exploit The attacker deposited minimal wei amounts across all supported tokens. The protocol treated this as an initial deposit and read stale storage values, minting septillions of yETH tokens instead of calculating from the actual dust deposit. Phase 5: Fund Extraction The attacker swapped the minted yETH tokens for WETH on Balancer pools and withdrew the underlying assets (sfrxETH, wstETH, ETHx, cbETH, rETH, apxETH, wOETH, mETH) from the pool. Phase 6: Cleanup The attacker converted all stolen assets to ETH via Uniswap V3 and other DEXs, repaid all flash loans with fees, and sent a portion to Tornado Cash for laundering while retaining the remainder as profit. The Design Bug 1 wstETH ≈ 1.15 ETH 1 rETH ≈ 1.08 ETH 1 cbETH ≈ 1.00 ETH To calculate how many LP tokens to give you, the pool needs to: Doing this EVERY time is expensive gas-wise, so instead of recalculating every time, the pool: Calculates once when you deposit/withdraw Stores the result in packed_vbs[] Reuses this cached value in future calculations Expensive (done every operation without caching): Cheap (with caching): What Happens When It’s Not Zero When It Should Be? Normal Flow (Working Correctly), scenario: Pool has 100 ETH worth of assets Bug Scenario (When Not Reset) What the code ASSUMES when supply == 0: What ACTUALLY happens after full withdrawal: The pool was designed to store virtual balances in state to save gas on recalculations. This is a common optimization pattern in DeFi: The Missing Edge Case The developers correctly handled the normal flow: Adding liquidity updates virtual balances ✓ Removing liquidity decrements virtual balances ✓ Swapping updates virtual balances ✓ But they missed the edge case: Removing ALL liquidity should RESET virtual balances to zero ✗ The Implicit Assumption The code assumed that when prev_supply == 0, this meant a “first-ever deposit” to a pristine pool. But after a full withdrawal, prev_supply == 0 while packed_vbs[] contained residual state from previous operations. Conclusion The yETH exploit stands as a masterclass in finding and exploiting subtle state management bugs. The attacker demonstrated deep understanding of: The protocol’s mathematical invariants Storage layout and state persistence How to manipulate state across multiple transactions How to maximize impact with minimal capital For defenders, this exploit reinforces that correctness in complex systems requires explicit handling of ALL state transitions, not just the happy path. A missing state reset—a single oversight in 1000+ lines of code—enabled the theft of $9 million. As DeFi protocols grow more complex, incorporating novel AMM designs and mathematical optimizations, the attack surface for such subtle bugs expands. The only defense is rigorous engineering discipline: explicit state management, comprehensive testing, and the humility to assume that if something CAN go wrong, eventually someone will find a way to exploit it. How this could have been prevented Onchain security must evolve from post-incident forensics to real-time prevention: → Simulate transactions before execution to catch abnormal token minting ratios (16 wei in → septillions out is not normal) → Track state across transaction sequences — this attack required 10+ deposit/withdrawal cycles to poison packed_vbs[]. Single-transaction monitoring would miss it → Block execution automatically when drain patterns emerge, not just alert after the fact The difference: Seeing the exploit after $9M is gone vs. Stopping the malicious add_liquidity() before it executes The Lesson: A single missing state reset — packed_vbs[] not clearing when supply hit zero — enabled this entire attack. Complex DeFi systems need runtime protection that understands protocol logic, not just signature-based detection. Learn more about Check Point’s Blockchain Security solution here. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign Check Point Research Publications August 11, 2017 “The Next WannaCry” Vulnerability is Here Check Point Research Publications March 12, 2026 “Handala Hack” – Unveiling Group’s Modus Operandi SUBSCRIBE TO CYBER INTELLIGENCE REPORTS We value your privacy! BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.
research.checkpoint.comDec 2, 2025extracted
Shai-Hulud malware infects 500 npm packages, leaks secrets on GitHub
Hundreds of trojanized versions of well-known packages such as Zapier, ENS Domains, PostHog, and Postman have been planted in the npm registry in a new Shai-Hulud supply-chain campaign. The malicious packages have been added to NPM (Node Package Manager) over the weekend to steal developer and continuous integration and continuous delivery (CI/CD) secrets. The data is automatically posted on GitHub in encoded form. At publishing time, GitHub returned 27,600 results corresponding to entries related to the recent attack. When the Shai-Hulud malware first appeared in the npm space in mid-September, and it compromised 187 packages with a self-propagating payload that used the TruffleHog tool to steal developer secrets. The threat actor automatically downloaded legitimate packages, modified the package.json file to inject a malicious script, and then published them on npm using compromised maintainer accounts. Charlie Eriksen, malware researcher at developer-focused security platform Aikido Security, discovered the new campaign earlier today, when there were 105 trojanized packages with Shai-Hulud indicators. Since then, the number grew to 492, counting only the package names. Later, the researcher warned that the secrets stolen in the supply-chain attack were leaked on GitHub. However, the campaign has grown exponentially to more than 27,000 malicious packages. Threat researchers at Wiz cloud security platform discovered around 350 unique maintainer accounts used in the campaign, noting that " 1,000 new repositories are being added consistently every 30 minutes in the last couple of hours." Eriksen clarified for BleepingComputer that the repositories on GitHub are indicative of compromised developers that used trojanized npm packages and thad GitHub credentials on their environment. A technical analysis of the new Shai-Hulud malware analysis from CI/CD security company Step Security explains that the new payloads are present in two files, one being setup_bun.js - a dropper disguised as a Bun installer. The second file is called bun_environment.js and is sizeable at 10MB. It relies on "extreme obfuscation techniques," Step Security says, such as a large hex-encoded string with thousands of entries, an anti-analysis loop, and an obfuscated function to retrieve every string in the code. Step Security describes five stages the malware executes during the attack, which include exfiltrating secrets (GitHub and npm tokens, secrets for cloud platforms like AWS, GCP and Azure) and a destructive step that overwrites the victim's entire home directory. Koi Security, a company providing protection solutions for self-provisioned software, tracks more than 800 npm packages compromised by Shai-Hulud, counting all infected versions of a package. The researchers confirmed the destructive step in the new Shai-Hulud variant, saying that the overwrite occurs only when a set of four conditions are met. Deleting a user's home folder happens if the malware cannot authenticate to GitHub, create a repository on the platform, fetch a GitHub token, or find an npm token. According to Wiz, the malicious code collects developer and CI/CD secrets and publishes them to GitHub repositories "with names referencing Shai-Hulud." The malicious code executes only during the pre-install stage and creates the following files: cloud.json contents.json environment.json truffleSecrets.json Stolen secrets are published on GitHub to automatically-generated repositories that have the description "Sha1-Hulud: The Second Coming." It appears that the threat actor has also gained access to GitHub accounts that they are now using to create repositories with the four files above. GitHub is deleting the attacker’s repositories as they emerge, but the threat actor appears to be creating new ones very fast. On the list of 186 packages that Aikido Security found to be compromised with a new version of the Shai Hulud malware, there are multiple packages from Zapier, ENS Domains, PostHog, and AsyncAPI. The compromised Zapier packages constitute the official toolkit for building Zapier integrations and are essential for Zapier developers. The EnsDomains packages are tools and libraries widely used by wallets, DApps, exchanges, and the ENS Manager app, to handle .eth names, resolving them to Ethereum addresses, linking IPFS content, validating names, and interacting with the official ENS smart contracts. All of the compromised packages are available for download from npm. However, in some cases, the platform displays a warning message about unauthorized publication of the latest version, indicating that the automated review has caught signs of a compromise. Developers are advised to check Aikido’s post for the complete list of the infected packages, downgrade to safe versions, and rotate their secrets and CI/CD tokens immediately. Wiz researchers recommend security teams to first identify the compromised packages and replace them with legitimate ones. They also urge organizations to rotate all credentials tied to npm, GitHub, and cloud providers. Aikido Security advises developers to disable npm postinstall scripts during continuous integration, if possible. The return of Shai Hulud comes at a time when GitHub introduced additional security measures to prevent supply-chain attacks on npm, following a series of high-impact attacks on the platform. However, the measures are being implemented gradually. BleepingComputer attempted to contact NPM about the campaign but our emails bounced as undeliverable. Update [November 24, 10:28 AM]: Article updated with information from Koi Security Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comNov 24, 2025extracted
Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
Cybersecurity researchers have uncovered a malicious Chrome extension that poses as a legitimate Ethereum wallet but harbors functionality to exfiltrate users' seed phrases. The name of the extension is "Safery: Ethereum Wallet," with the threat actor describing it as a "secure wallet for managing Ethereum cryptocurrency with flexible settings." It was uploaded to the Chrome Web Store on September 29, 2025, and was updated as recently as November 12. It's still available for download as of writing. "Marketed as a simple, secure Ethereum (ETH) wallet, it contains a backdoor that exfiltrates seed phrases by encoding them into Sui addresses and broadcasting microtransactions from a threat actor-controlled Sui wallet," Socket security researcher Kirill Boychenko said. Specifically, the malware present within the browser add-on is designed to steal wallet mnemonic phrases by encoding them as fake Sui wallet addresses and then using micro-transactions to send 0.000001 SUI to those wallets from a hard-coded threat actor-controlled wallet. The end goal of the malware is to smuggle the seed phrase inside normal looking blockchain transactions without the need for setting up a command-and-control (C2) server to receive the information. Once the transactions are complete, the threat actor can decode the recipient addresses to reconstruct the original seed phrase and ultimately drain assets from it. "This extension steals wallet seed phrases by encoding them as fake Sui addresses and sending micro-transactions to them from an attacker-controlled wallet, allowing the attacker to monitor the blockchain, decode the addresses back to seed phrases, and drain victims' funds," Koi Security notes in an analysis. To counter the risk posed by the threat, users are advised to stick to trusted wallet extensions. Defenders are recommended to scan extensions for mnemonic encoders, synthetic address generators, and hard-coded seed phrases, as well as block those that write on the chain during wallet import or creation. "This technique lets threat actors switch chains and RPC endpoints with little effort, so detections that rely on domains, URLs, or specific extension IDs will miss it," Boychenko said. "Treat unexpected blockchain RPC calls from the browser as high signal, especially when the product claims to be single chain." Update The extension is no longer available for download from the Chrome Web Store.
thehackernews.comNov 13, 2025extracted
Fake Solidity VSCode extension on Open VSX backdoors developers
A remote access trojan dubbed SleepyDuck, and disguised as the well-known Solidity extension in the Open VSX open-source registry, uses an Ethereum smart contract to establish a communication channel with the attacker. Open VSX is a community-driven registry for extensions compatible with VS Code, which are popular with AI-powered integrated development environments (IDEs) like Cursor and Windsurf. The extension is still present on Open VSX as 'juan-bianco.solidity-vlang', albeit with a warning from the platform, and has been downloaded more than 53,000 times. When initially submitted on October 31st, the extension was harmless and received malicious capabilities with an update the next day, when the download count had already reached 14,000. According to a report from extension security platform Secure Annex, a notable feature in SleepyDuck is the use of Ethereum contracts to update its command-and-control (C2) server address and achieve long-term persistence. Even if the default C2 server at sleepyduck[.]xyz is taken down, the contract on the Ethereum blockchain allows the malware to remain functional. Since its submission to Open VSX with version 0.0.7 and until version 0.1.3 published on November 2nd, the juan-bianco.solidity-vlang package was downloaded 53,439 times and has only one 5-star rating from its author. It should be noted that author of the malic The malicious code activates on editor startup, when a Solidity file is opened, or when the user runs the Solidity compile command. Upon activation, it creates a lock file to run once per host and calls a fake ‘webpack.init()’ function from ‘extension.js’ to make it appear legitimate, but in reality, it loads a malicious payload. According to Secure Annex, the malicious component in SleepyDuck collects system data (hostname, username, MAC address, and timezone) and sets up a command execution sandbox. The researchers say that when initialized, the malware finds the fastest Ethereum RPC provider to read the smart contract with the C2 information, starts a sleepyduck instance, updates with a current valid configuration, and begins a polling loop. The Ethereum blockchain is used for C2 redundancy, so if the primary command server goes offline, the malware reads updated instructions directly from the blockchain, including a new C2 server address or modified communication intervals. The researchers also say that the polling function will send data about the system in a POST request and look "for a command to execute from the response." Open VSX’s growing popularity has placed it on the hackers’ radar, receiving multiple malicious submissions targeting unsuspecting developers. Recently, the platform announced a set of security enhancements to make it safer for its users, including shortening token lifetimes, quickly revoking leaked credentials, automated scans, and sharing key info with VS Code about emerging threats. Software developers should exercise caution when downloading VS Code extensions, trusting only reputable publishers and their official repositories. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comNov 3, 2025extracted
Malicious VSX Extension "SleepyDuck" Uses Ethereum to Keep Its Command Server Alive
Cybersecurity researchers have flagged a new malicious extension in the Open VSX registry that harbors a remote access trojan called SleepyDuck. According to Secure Annex's John Tuckner, the extension in question, juan-bianco.solidity-vlang (version 0.0.7), was first published on October 31, 2025, as a completely benign library that was subsequently updated to version 0.0.8 on November 1 to include new malicious capabilities after reaching 14,000 downloads. "The malware includes sandbox evasion techniques and utilizes an Ethereum contract to update its command and control address in case the original address is taken down," Tuckner added. Campaigns distributing rogue extensions targeting Solidity developers have been repeatedly detected across both the Visual Studio Extension Marketplace and Open VSX. In July 2025, Kaspersky disclosed that a Russian developer lost $500,000 in cryptocurrency assets after installing one such extension through Cursor. In the latest instance detected by the enterprise extension security firm, the malware is triggered when a new code editor window is opened or a .sol file is selected. Specifically, it's configured to find the fastest Ethereum Remote Procedure Call (RPC) provider to connect to in order to obtain access to the blockchain, initialize contact with a remote server at "sleepyduck[.]xyz" (hence the name) via the contract address "0xDAfb81732db454DA238e9cFC9A9Fe5fb8e34c465," and kicks off a polling loop that checks for new commands to be executed on the host every 30 seconds. It's also capable of gathering system information, such as hostname, username, MAC address, and timezone, and exfiltrating the details to the server. In the event the domain is seized or taken down, the malware has built-in fallback controls to reach out to a predefined list of Ethereum RPC addresses to extract the contract information that can hold the server details. What's more, the extension is equipped to reach a new configuration from the contract address to set a new server, as well as execute an emergency command to all endpoints in the event that something unexpected occurs. The contract was created on October 31, 2025, with the threat actor updating the server details from "localhost:8080" to "sleepyduck[.]xyz" over the course of four transactions. It's not clear if the download counts were artificially inflated by the threat actors to boost the relevance of the extension in search results – a tactic often adopted to increase the popularity so as to trick unsuspecting developers into installing a malicious library. "The download counts likely are manipulated making it hard to know exactly," Tuckner told The Hacker News. "This is very likely done to make it more relevant in the search results for Cursor/Open VSX." The development comes as the company also disclosed details of another set of five extensions, this time published to the VS Code Extension Marketplace by a user named "developmentinc," including a Pokémon-themed library that downloads a batch script miner from an external server ("mock1[.]su:443") as soon as it's installed or enabled, and executes it using "cmd.exe." The script file, besides relaunching itself with administrator privileges using PowerShell and configuring Microsoft Defender Antivirus exclusions by adding every drive letter from C: through Z:, downloads a Monero mining executable from "mock1[.]su" and runs it. The extensions uploaded by the threat actor, now no longer available for download, are listed below - developmentinc.cfx-lua-vs developmentinc.pokemon developmentinc.torizon-vs developmentinc.minecraftsnippets developmentinc.kombai-vs Users are advised to exercise caution when it comes to downloading extensions, and make sure that they are from trusted publishers. Microsoft, for its part, announced back in June that it's instituting periodic marketplace-wide scans to protect users against malware. Every removed extension from the official marketplace can be viewed from the RemovedPackages page on GitHub.
thehackernews.comNov 3, 2025extracted
⚡ Weekly Recap: F5 Breached, Linux Rootkits, Pixnapping Attack, EtherHiding & More
It’s easy to think your defenses are solid — until you realize attackers have been inside them the whole time. The latest incidents show that long-term, silent breaches are becoming the norm. The best defense now isn’t just patching fast, but watching smarter and staying alert for what you don’t expect. Here’s a quick look at this week’s top threats, new tactics, and security stories shaping the landscape. ⚡ Threat of the Week F5 Exposed to Nation-State Breach — F5 disclosed that unidentified threat actors broke into its systems and stole files containing some of BIG-IP's source code and information related to undisclosed vulnerabilities in the product. The company said it learned of the incident on August 9, 2025, although it's believed that the attackers were in its network for at least 12 months. The attackers are said to have used a malware family called BRICKSTORM, which is attributed to a China-nexus espionage group dubbed UNC5221. GreyNoise said it observed elevated scanning activity targeting BIG-IP in three waves on September 23, October 14, and October 15, 2025, but emphasized the anomalies may not necessarily relate to the hack. Censys said it identified over 680,000 F5 BIG-IP load balancers and application gateways visible on the public internet, with the majority of hosts located in the U.S., followed by Germany, France, Japan, and China. Not all identified systems are necessarily vulnerable, but each represents a publicly accessible interface that should be inventoried, access-restricted, and patched proactively as a precautionary measure. "Edge infrastructure and security vendors remain prime targets for long-term, often state-linked threat actors," John Fokker, vice president of threat intelligence strategy at Trellix, said. "Over the years, we have seen nation-state interest in exploiting vulnerabilities in edge devices, recognizing their strategic position in global networks. Incidents like these remind us that strengthening collective resilience requires not only hardened technology but also open collaboration and intelligence sharing across the security community." Zero Trust + AI: Thrive in the AI Era and Empower Your Workforce It’s no surprise, hackers are using AI in creative ways to compromise users and breach organizations. Zscaler Zero Trust + AI helps defeat ransomware and AI-power attacks today by enabling you to detect and block advanced threats, and discover and classify sensitive data everywhere. Learn more about Zscaler Zero Trust + AI ➝ 🔔 Top News N. Korea Uses EtherHiding to Hide Malware Inside Blockchain Smart Contracts — North Korean threat actors have been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a state-sponsored hacking group has embraced the method. The activity has been attributed to a cluster tracked as UNC5342 (aka Famous Chollima). The attack wave is part of a long-running campaign codenamed Contagious Interview, wherein the attackers approach potential targets on LinkedIn by posing as recruiters or hiring managers, and trick them into running malicious code under the pretext of a job assessment after shifting the conversation to Telegram or Discord. In the latest attack waves observed since February 2025, the threat actors use a JavaScript downloader that interacts with a malicious BSC smart contract to download JADESNOW, which subsequently queries the transaction history associated with an Ethereum address to fetch the JavaScript version of InvisibleFerret. LinkPro Linux Rootkit Spotted in the Wild — An investigation into the compromise of an Amazon Web Services (AWS)-hosted infrastructure led to the discovery of a new GNU/Linux rootkit dubbed LinkPro. The backdoor features functionalities relying on the installation of two extended Berkeley Packet Filter (eBPF) modules to conceal itself and to be remotely activated upon receiving a magic packet - a TCP SYN packet with a specific window size (54321) that signals the rootkit to await further instructions within a one-hour window, allowing it to evade traditional security defenses. The commands supported by LinkPro include executing /bin/bash in a pseudo-terminal, running a shell command, enumerating files and directories, performing file operations, downloading files, and setting up a SOCKS5 proxy tunnel. It's currently not known who is behind the attack, but it's suspected that the threat actors are financially motivated. Zero Disco Campaign Targets Cisco Devices with Rootkits — A new campaign has exploited a recently disclosed security flaw impacting Cisco IOS Software and IOS XE Software to deploy Linux rootkits on older, unprotected systems. The activity, codenamed Operation Zero Disco by Trend Micro, involves the weaponization of CVE-2025-20352 (CVSS score: 7.7), a stack overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow an authenticated, remote attacker to execute arbitrary code by sending crafted SNMP packets to a susceptible device. The operation primarily impacted Cisco 9400, 9300, and legacy 3750G series devices, Trend Micro said. The intrusions have not been attributed to any known threat actor or group. Pixnapping Attack Leads to Data Theft on Android Devices — Android devices from Google and Samsung have been found vulnerable to a side-channel attack that could be exploited to covertly steal two-factor authentication (2FA) codes, Google Maps timelines, and other sensitive data without the users' knowledge pixel-by-pixel. The attack has been codenamed Pixnapping. Google is tracking the issue under the CVE identifier CVE-2025-48561 (CVSS score: 5.5). Patches for the vulnerability were issued by the tech giant as part of its September 2025 Android Security Bulletin, with additional fixes forthcoming in December. Chinese Threat Actors Exploited ArcGIS Server as Backdoor — Threat actors with ties to China have been attributed to a novel campaign that compromised an ArcGIS system and turned it into a backdoor for more than a year. The activity is the handiwork of a Chinese state-sponsored hacking group called Flax Typhoon, which is also tracked as Ethereal Panda and RedJuliett. "The group cleverly modified a geo-mapping application's Java server object extension (SOE) into a functioning web shell," ReliaQuest said. "By gating access with a hardcoded key for exclusive control and embedding it in system backups, they achieved deep, long-term persistence that could survive a full system recovery." The attack chain involved the threat actors targeting a public-facing ArcGIS server that was linked to a private, internal ArcGIS server by compromising a portal administrator account to deploy a malicious SOE, thereby allowing them to blend in with normal traffic and maintain access for extended periods. The attackers then instructed the public-facing server to create a hidden directory to serve as the group's "private workspace." They also blocked access to other attackers and admins with a hard-coded key. The findings demonstrate Flax Typhoon's consistent modus operandi of quietly turning an organization's own tools against itself rather than using sophisticated malware or exploits. ️🔥 Trending CVEs Hackers move fast. They often exploit new vulnerabilities within hours, turning a single missed patch into a major breach. One unpatched CVE can be all it takes for a full compromise. Below are this week’s most critical vulnerabilities gaining attention across the industry. Review them, prioritize your fixes, and close the gap before attackers take advantage. This week’s list includes — CVE-2025-24990, CVE-2025-59230 (Microsoft Windows), CVE-2025-47827 (IGEL OS before 11), CVE-2023-42770, CVE-2023-40151 (Red Lion Sixnet RTUs), CVE-2025-2611 (ICTBroadcast), CVE-2025-55315 (Microsoft ASP.NET Core), CVE-2025-11577 (Clevo UEFI firmware), CVE-2025-37729 (Elastic Cloud Enterprise), CVE-2025-9713, CVE-2025-11622 (Ivanti Endpoint Manager), CVE-2025-48983, CVE-2025-48984 (Veeam), CVE-2025-11756 (Google Chrome), CVE-2025-49201 (Fortinet FortiPAM and FortiSwitch Manager), CVE-2025-58325 (Fortinet FortiOS CLI), CVE-2025-49553 (Adobe Connect collaboration suite), CVE-2025-9217 (Slider Revolution plugin), CVE-2025-10230 (Samba), CVE-2025-54539 (Apache ActiveMQ), CVE-2025-41703, CVE-2025-41704, CVE-2025-41706, CVE-2025-41707 (Phoenix Contact QUINT4), and CVE-2025-11492, CVE-2025-11493 (ConnectWise Automate). 📰 Around the Cyber World Microsoft Unveils New Security Improvements — Microsoft revealed that "parts of the kernel in Windows 11 have been rewritten in Rust, which helps mitigate against memory corruption vulnerabilities like buffer overflows and helps reduce attack surfaces." The company also noted that it's taking steps to secure AI-powered agentic experiences on the operating system by ensuring that they operate with limited permissions and only obtain access to resources users' explicitly provide permission to. In addition, Microsoft said agents that integrate with Windows must be cryptographically signed by a trusted source so that they can be revoked if found to be malicious. Each AI agent will also run under its own dedicated agent account that's distinct from the user account on the device. "This facilitates agent-specific policy application that can be different from the rules applied to other accounts like those for human users," it said. SEO Campaign Uses Fake Ivanti Installers to Steal Credentials — A new attack campaign has leveraged SEO poisoning to lure users into downloading a malicious version of the Ivanti Pulse Secure VPN client. The activity targets users searching for legitimate software on search engines like Bing, redirecting them to attacker-controlled lookalike websites (ivanti-pulsesecure[.]com or ivanti-secure-access[.]org). The goal of this attack is to steal VPN credentials from the victim's machine, enabling further compromise. "The malicious installer, a signed MSI file, contains a credential-stealing DLL designed to locate, parse, and exfiltrate VPN connection details," Zscaler said. "The malware specifically targets the connectionstore.dat file to steal saved VPN server URIs, which it combines with hardcoded credentials for exfiltration. Data is sent to a command-and-control (C2) server hosted on Microsoft Azure infrastructure." Qilin's Ties with BPH Providers Exposed — Cybersecurity researchers from Resecurity examined Qilin ransomware group's "close affiliation" with underground bulletproof hosting (BPH) operators, finding that the e-crime actor has not only relied on Cat Technologies Co. Limited. (which, in turn, is hosted on an IP address tied to Aeza Group) for hosting its data leak site, but also advertised services like BEARHOST Servers (aka Underground) on its WikiLeaksV2 site, where the group publishes content about their activities. BEARHOST has been operational since 2016, offering its services for anywhere from $95 to $500. While BEARHOST abruptly announced the stoppage of its service on December 28, 2024, it is assessed that the threat actors have taken the BPH service into private mode, catering only to trusted and vetted underground actors. On May 8, 2025, it resurfaced as Voodoo Servers, only for the operators to terminate the service again towards the end of the month, citing political reasons. "The actors decided to disappear through an 'exit scam' scenario, keeping the underground audience completely clueless," Resecurity said. "Notably, the legal entities behind the service continue their operations." Notably, Cat Technologies Co. Limited. also shares links to shadowy entities like Red Bytes LLC, Hostway, Starcrecium Limited, and Chang Way Technologies Co. Limited, the last of which has been associated with extensive malware activity, hosting command-and-control (C2) servers of Amadey, StealC, and Cobalt Strike used by cybercriminals. Another entity of note is Next Limited, which shares the same Hong Kong address as Chang Way Technologies Co. Limited and has been attributed to malicious activity in connection with Proton66. U.S. Judge Bars NSO Group from Targeting WhatsApp — A U.S. judge barred NSO Group from targeting WhatsApp users and cut the punitive damages verdict awarded to Meta by a jury in May 2025 to $4 million, because the court did not have enough evidence to determine that NSO Group's behavior was "particularly egregious." The permanent injunction handed out by U.S. District Judge Phyllis Hamilton means that the Israeli vendor cannot use WhatsApp as a way to infect targets' devices. As a refresher, Meta sued the NSO Group in 2019 over the use of Pegasus spyware by exploiting a then-zero-day flaw in the messaging app to spy on 1,400 people from 20 countries, including journalists and human rights activists. It was fined close to $168 million earlier this May. The proposed injunction requires NSO Group to delete and destroy computer code related to Meta's platforms, and she concluded that the provision is "necessary to prevent future violations, especially given the undetectable nature of defendants' technology." Google's Privacy Sandbox Initiative is Officially Dead — In 2019, Google launched an initiative called Privacy Sandbox to come up with privacy-enhancing alternatives to replace third-party cookies on the web. However, with the company abandoning its plans to deprecate third-party tracking cookies, the project appears to be winding down. To that end, the tech giant said it's retiring the following Privacy Sandbox technologies citing low levels of adoption: Attribution Reporting API (Chrome and Android), IP Protection, On-Device Personalization, Private Aggregation (including Shared Storage), Protected Audience (Chrome and Android), Protected App Signals, Related Website Sets (including requestStorageAccessFor and Related Website Partition), SelectURL, SDK Runtime and Topics (Chrome and Android). In a statement shared with Adweek, the company said it will continue to work to improve privacy across Chrome, Android, and the web, but not under the Privacy Sandbox branding. Russia Blocks Foreign SIM Cards — Russia said it's taking steps to temporarily block mobile internet for foreign SIM cards, citing national security reasons. The new rule imposes a mandatory 24-hour mobile internet blackout for anyone entering Russia with a foreign SIM card. Flaw in CORS headers in Web Browsers Disclosed — The CERT Coordination Center (CERT/CC) disclosed details of a vulnerability in cross-origin resource sharing (CORS) headers in Chromium, Google Chrome, Microsoft Edge, Safari, and Firefox that enables the CORS policy to be manipulated. This can be combined with DNS rebinding techniques to issue arbitrary requests to services listening on arbitrary ports, regardless of the CORS policy in place by the target. "An attacker can use a malicious site to execute a JavaScript payload that periodically sends CORS headers in order to ask the server if the cross-origin request is safe and allowed," CERT/CC explained. "Naturally, the attacker-controlled hostname will respond with permissive CORS headers that will circumvent the CORS policy. The attacker then performs a DNS rebinding attack so that the hostname is assigned the IP address of the target service. After the DNS responds with the changed IP address, the new target inherits the relaxed CORS policy, allowing an attacker to potentially exfiltrate data from the target." Mozilla is tracking the vulnerability as CVE-2025-8036. Phishing Campaigns Use Microsoft's Logo for Tech Support Scams — Threat actors are exploiting Microsoft's Name and branding in phishing emails to lure users into fraudulent tech support scams. The messages contain links that, when clicked, take the victims to a fake CAPTCHA challenge, after which they are redirected to a phishing landing page to unleash the next stage of the attack. "After passing the captcha verification, the victim is suddenly visually overloaded with several pop-ups that appear to be Microsoft security alerts," Cofense said. "Their browser is manipulated to appear locked, and they lose the ability to locate or control their mouse, which adds to the feeling that the system is compromised. This involuntary loss of control creates a faux ransomware experience, leading the user to believe their computer is locked and to take immediate action to remedy the infection." From there, users are instructed to call a number to reach Windows Support, at which they are connected to a bogus technician to take the attack forward. "The threat actor could exploit further by asking the user to provide account credentials or persuade the user to install remote desktop tools, allowing full access to their system," the company said. Taxpayers, Drivers Targeted in Refund and Road Toll Smishing Scams — A smishing campaign has leveraged at least 850 newly-registered domain names in September and early October to target people living in the U.S., the U.K., and elsewhere with phishing links that use tax refunds, road toll charges, or failed package deliveries as a lure. The websites, designed to be loaded only when launched from a mobile device, claim to provide information about their tax refund status or obtain a subsidy of up to £300 to help offset winter fuel costs (note: this is a real U.K. government initiative), only to prompt them to provide personal details such as name, home address, telephone number and email address, as well as payment card information. The entered data is exfiltrated to the attackers over the WebSocket protocol. Some of the scam websites have also been found to target Canadian, German, and Spanish residents and visitors, per Netcraft. Meta's New Collage Feature May Use Photos in Phone's Camera Roll — Meta is officially rolling out a new opt-in feature to Facebook users in the U.S. and Canada to suggest the best photos and videos from users' camera roll and create collages and edits. "With your permission and the help of AI, our new feature enables Facebook to automatically surface hidden gems – those memorable moments that get lost among screenshots, receipts, and random snaps – and edit them to save or share," the company said. The feature was first tested back in late June 2025. The social media company emphasized that the suggestions are private and that it does not use media obtained from users' devices via the camera roll to train its models, unless users opt to edit the media with their AI tools or publish those suggestions to Facebook. Users who wish to opt out of the feature can do so by navigating Settings and Privacy > Settings > Preferences > Camera Roll Sharing Suggestions. Fake Homebrew, TradingView, LogMeIn Sites Serve Stealer Malware Targeting Macs — Threat actors are employing social engineering tactics to trick users into visiting fake websites impersonating trusted platforms like as Homebrew, TradingView, and LogMeIn, where they are instructed to copy and run a malicious command on the Terminal app as part of ClickFix-style attacks, resulting in the deployment of stealer malware such as Atomic Stealer and Odyssey Stealer. "More than 85 phishing domains were identified, connected through shared SSL certificates, payload servers, and reused infrastructure," Hunt.io said. "The findings suggest a coordinated and ongoing campaign in which operators continuously adapt their infrastructure and tactics to maintain persistence and evade detection within the macOS ecosystem." It's suspected that users are driven to these websites via sponsored ads on search engines like Bing and Google. Dutch Data Protection Watchdog Fines Experian $3.2 Million for Privacy Violations — The Dutch Data Protection Authority (DPA) imposed a fine of €2.7 million ($3.2 million) on Experian Netherlands for collecting data in contravention of the E.U. General Data Protection Regulation (GDPR). The DPA said the consumer credit reporting company gathered information on people from both public and non-public sources and failed to make it clear why the collection of certain data was necessary. In addition to the penalty, Experian is expected to delete the database of personal data by the end of the year. The company has also ceased its operations in the country. "Until January 1, 2025, Experian provided credit assessments about individuals to its clients," the DPA said. "To do this, the company collected data such as negative payment behavior, outstanding debts, or bankruptcies. The AP found that Experian violated the law by unlawfully using personal data." Threat Actors Send Fake Password Manager Breach Alerts — Bad actors are sending phishing alerts claiming that their password manager accounts for 1Password and Lastpass have been compromised in order to trick users into providing their passwords and hijack their accounts. In response to the attack, LastPass said it has not been hacked and that it's an attempt on the part of the attackers to generate a false sense of urgency. In some cases spotted by Bleeping Computer, the activity has also been found to urge recipients to install a more secure version of the password manager, resulting in the deployment of a legitimate remote access software called Syncro. The software vendor has since moved to shut down the malicious accounts to prevent further installs. SocGholish MaaS Detailed — LevelBlue has published an analysis of a threat activity cluster known as SocGholish (aka FakeUpdates), which is known to be active since 2017, leveraging fake web browser update prompts on compromised websites as a lure to distribute malware. Victims are typically routed through Traffic Distribution Systems (TDS) like Keitaro and Parrot TDS to filter users based on specific factors such as geography, browser type, or system configuration, ensuring that only the intended targets are exposed to the payload. It's offered under a malware-as-a-service (MaaS) by a financially motivated cybercrime group called TA569. SocGholish stands out for its ability to turn legitimate websites into large-scale distribution platforms for malware. Acting as an initial access broker (IAB), its operations profit from follow-on compromises by other actors. "Once executed, its payloads range from loaders and stealers to ransomware, allowing for extensive follow-up exploitation," LevelBlue said. "This combination of broad reach, simple delivery mechanisms, and flexible use by multiple groups makes SocGholish a persistent and dangerous threat across industries and regions." One of its primary users is Evil Corp, with the malware also used to deliver RansomHub in early 2025. 🎥 Cybersecurity Webinars The Practical Framework to Govern AI Agents Without Slowing Innovation → AI is changing everything fast — but for most security teams, it still feels like a fight just to keep up. The goal isn’t to slow innovation with more controls; it’s to make those controls work for the business. By building security into AI from the start, you can turn what used to be a bottleneck into a real accelerator for growth and trust. The Future of AI in GRC: Turning Risk Into a Compliance Advantage - AI is changing how companies manage risk and compliance — fast. It brings big opportunities but also new challenges. This webinar shows you how to use AI safely and effectively in GRC, avoid common mistakes, and turn complex rules into a real business advantage. Workflow Clarity: How to Blend AI and Human Effort for Real Results - Too many teams are rushing to “add AI” without a plan — and ending up with messy, unreliable workflows. Join us to learn a clearer approach: how to use AI thoughtfully, simplify automation, and build systems that scale securely. 🔧 Cybersecurity Tools Beelzebub - It turns honeypot deployment into a powerful, low-code experience. It uses AI to simulate real systems, helping security teams detect attacks, track emerging threats, and share insights through a global threat intelligence network. NetworkHound - It maps your Active Directory network from the inside out. It discovers every device — domain-joined or shadow-IT — validates SMB and web services, and builds a full BloodHound-compatible graph so you can see and secure your environment clearly. Disclaimer: These tools are for educational and research use only. They haven’t been fully security-tested and could pose risks if used incorrectly. Review the code before trying them, test only in safe environments, and follow all ethical, legal, and organizational rules. 🔒 Tip of the Week Most Cloud Breaches Aren’t Hacks — They’re Misconfigurations. Here’s How to Fix Them — Cloud storage buckets like AWS S3, Azure Blob, and Google Cloud Storage make data sharing easy — but one wrong setting can expose everything. Most data leaks happen not because of hacking, but because someone left a public bucket, skipped encryption, or used a test bucket that never got locked down. Cloud platforms give you flexibility, not guaranteed safety, so you need to check and control access yourself. Misconfigurations usually happen when permissions are too broad, encryption is disabled, or visibility is lost across multiple clouds. Doing manual checks doesn’t scale — especially if you manage data in AWS, Azure, and GCP. The fix is using tools that automatically find, report, and even fix unsafe settings before they cause damage. ScoutSuite is a strong starting point for cross-cloud visibility. It scans AWS, Azure, and GCP for open buckets, weak IAM roles, and missing encryption, then creates an easy-to-read HTML report. Prowler goes deeper into AWS, checking S3 settings against CIS and AWS benchmarks to catch bad ACLs or unencrypted buckets. For ongoing control, Cloud Custodian lets you write simple policies that automatically enforce rules — for example, forcing all new buckets to use encryption. And CloudQuery can turn your cloud setup into a searchable database, so you can monitor changes, track compliance, and visualize risks in one place. The best approach is to combine them: run ScoutSuite or Prowler weekly to find issues, and let Cloud Custodian handle automatic fixes. Even a few hours spent setting these up can stop the kind of data leaks that make headlines. Always assume every bucket is public until proven otherwise — and secure it like it is. Conclusion The truth is, no tool or patch will ever make us fully secure. What matters most is awareness — knowing what’s normal, what’s changing, and how attackers think. Every alert, log, or minor anomaly is a clue. Keep connecting those dots before someone else does.
thehackernews.comOct 20, 2025extracted
North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware
The North Korean threat actor linked to the Contagious Interview campaign has been observed merging some of the functionality of two of its malware programs, indicating that the hacking group is actively refining its toolset. That's according to new findings from Cisco Talos, which said recent campaigns undertaken by the hacking group have seen the functions of BeaverTail and OtterCookie coming closer to each other more than ever, even as the latter has been fitted with a new module for keylogging and taking screenshots. The activity is attributed to a threat cluster that's tracked by the cybersecurity community under the monikers CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum. The development comes as Google Threat Intelligence Group (GTIG) and Mandiant revealed the threat actor's use of a stealthy technique known as EtherHiding to fetch next-stage payloads from the BNB Smart Chain (BSC) or Ethereum blockchains, essentially turning decentralized infrastructure into a resilient command-and-control (C2) server. It represents the first documented case of a nation-state actor utilizing the method that has been otherwise adopted by cybercrime groups. Contagious Interview refers to an elaborate recruitment scam that began sometime around late 2022, with the North Korean threat actors impersonating hiring organizations to target job seekers and deceiving them into installing information-stealing malware as part of a supposed technical assessment or coding task, resulting in the theft of sensitive data and cryptocurrency. In recent months, the campaign has undergone several shifts, including leveraging ClickFix social engineering techniques for delivering malware strains such as GolangGhost, PylangGhost, TsunamiKit, Tropidoor, and AkdoorTea. Central to the attacks, however, are malware families known as BeaverTail, OtterCookie, and InvisibleFerret. BeaverTail and OtterCookie are separate but complementary malware tools, with the latter first spotted in real-world attacks in September 2024. Unlike BeaverTail, which functions as an information stealer and downloader, initial interactions of OtterCookie were designed to contact a remote server and fetch commands to be executed on the compromised host. The activity detected by Cisco Talos concerns an organization headquartered in Sri Lanka. It's assessed that the company was not intentionally targeted by the threat actors, but rather they had one of their systems infected, likely after a user fell victim to a fake job offer that instructed them to install a trojanized Node.js application called Chessfi hosted on Bitbucket as part of the interview process. Interestingly, the malicious software includes a dependency via a package called "node-nvm-ssh" published to the official npm repository on August 20, 2025, by a user named "trailer." The package attracted a total of 306 downloads, before it was taken down by the npm maintainers six days later. It's also worth noting that the npm package in question is one of the 338 malicious Node.js libraries flagged earlier this week by software supply chain security company Socket as connected to the Contagious Interview campaign. The package, once installed, triggers the malicious behavior by means of a postinstall hook in its package.json file that's configured to run a custom script called "skip" so as to launch a JavaScript payload ("index.js"), which, in turn, loads another JavaScript ("file15.js") responsible for executing the final-stage malware. Further analysis of the tool used in the attack has found that "it had characteristics of BeaverTail and of OtterCookie, blurring the distinction between the two," security researchers Vanja Svajcer and Michael Kelley said, adding it incorporated a new keylogging and screenshotting module that uses legitimate npm packages like "node-global-key-listener" and "screenshot-desktop" to capture keystrokes and take screenshots, respectively, and exfiltrate the information to the C2 server. At least one version of this new module comes equipped with an auxiliary clipboard monitoring feature to siphon clipboard content. The emergence of the new version of OtterCookie paints a picture of a tool that has evolved from basic data-gathering to a modular program for data theft and remote command execution. Also present in the malware, codenamed OtterCookie v5, are functions akin to BeaverTail to enumerate browser profiles and extensions, steal data from web browsers and cryptocurrency wallets, install AnyDesk for persistent remote access, as well as download a Python backdoor referred to as InvisibleFerret. Some of the other modules present in OtterCookie are listed below - Remote shell module, which sends system information and clipboard content to the C2 server and installs the "socket.io-client" npm package to connect to a specific port on the OtterCookie C2 server and receive further commands for execution File uploading module, which systematically enumerates all drives and traverses the file system in order to find files matching certain extensions and naming patterns (e.g., metamask, bitcoin, backup, and phrase) to be uploaded to the C2 server Cryptocurrency extensions stealer module, which extracts data from cryptocurrency wallet extensions installed on Google Chrome and Brave browsers (the list of extensions targeted partially overlaps with that of BeaverTail) Furthermore, Talos said it detected a Qt-based BeaverTail artifact and a malicious Visual Studio Code extension containing BeaverTail and OtterCookie code, raising the possibility that the group may be experimenting with new methods of malware delivery. "The extension could also be a result of experimentation from another actor, possibly even a researcher, who is not associated with Famous Chollima, as this stands out from their usual TTPs," the researchers noted. Contagious Interview Evolves with New OtterCandy Malware The disclosure comes as NTT Security Holdings shared details of a new malware called OtterCandy, deployed in connection with the Contagious Interview campaign since July 2025, targeting Windows, macOS, and Linux systems. An early sample of OtterCandy was uploaded to the VirusTotal platform in February 2025. OtterCandy, per the Japanese cybersecurity company, combines the features of OtterCookie and RATatouille, a remote access trojan (RAT) distributed via the supply chain compromise of the npm package "rand-user-agent" back in May 2025. This is the first time the attack has been attributed to North Korean threat actors. The obfuscated payload embedded within the npm package is designed to set up a stealthy communication channel with a remote server and exfiltrate files within a particular directory and execute shell commands, the latter of which is specific only to Windows, according to Aikido. The full list of supported commands is below - env, to search for secret filenames across the entire file system imp, to search for secret filenames within the home directory pat, to search for filenames matching a preset pattern within the current directory upload, to transmit system information, browser passwords, wallet files, and extension data (MetaMask, Phantom, and TronLink) from Google Chrome and Edge to the C2 server exec, to cancel in-progress scans or uploads (ss_stop), upload a single file (ss_upf), recursively upload the contents of a directory (ss_upd), change current directory (cd), or terminate the malware process (ss_del) OtterCandy is said to be distributed via a sub-cluster of activity tracked as ClickFake Interview (aka Cluster B), which involves deceiving users with ClickFix-style lures to run malicious commands so as to fix supposed camera or microphone issues when job seekers attempt to provide a video assessment on a fake website under their control. "OtterCandy is a RAT and Info Stealer implemented by Node.js," NTT Security said. "It is malware that combines elements of RATatouille and OtterCookie. OtterCandy accepts commands when connected to the C2 server via Socket.IO." The first-stage malware used to deliver OtterCandy is named DiggingBeaver, a JavaScript payload that's executed once the victim copies and runs the command via the Windows Run dialog. DiggingBeaver has also been found to distribute other known ClickFake Interview malware, such as GolangGhost and FROSTYFERRET. NTT Security said it also observed a new variant of OtterCandy (OtterCandy v2) in August 2025 that comes with expanded functionality to harvest data from three additional cryptocurrency wallet extensions (Suiet, Trust Wallet, and Rabby Wallet), as well as enhance the "ss_del" command to delete Windows Registry keys and erase files and directories. (The story was updated after publication on October 19, 2025, to include details of OtterCandy malware from NTT Security Holdings.)
thehackernews.comOct 17, 2025extracted
A new approach to blockchain spam: Local reputation over global rules
A new approach to blockchain spam: Local reputation over global rules Spam has long been a nuisance in blockchain networks, clogging transaction queues and driving up fees. A new research paper from Delft University of Technology introduces a decentralized solution called STARVESPAM that could help nodes in permissionless blockchains block spam without relying on central control or costly fee mechanisms. When blockchain networks get flooded In open networks like Ethereum, Bitcoin, and Solana, anyone can send transactions as long as they pay the required fee. This openness also makes it easy for attackers to flood the network with low-value or junk transactions. These floods slow down processing, inflate fees, and sometimes even halt block production. One well-known example occurred in 2022 when Solana went offline for seven hours after bots submitted millions of NFT minting transactions per second. Ethereum and Bitcoin have also seen repeated spam events that clogged memory pools and raised transaction costs for ordinary users. The researchers set out to build a system that can distinguish spam from legitimate traffic using behavioral signals rather than transaction fees or centralized filters. Their approach is based on local reputation instead of global consensus. How STARVESPAM changes the rules STARVESPAM operates at the transaction relay layer, where nodes share transactions with each other before they are added to blocks. Each node monitors the behavior of its peers over time and assigns a reputation score based on factors like transaction rate, duplication, failure rate, and fee patterns. When a node sees signs of abuse, it lowers that peer’s reputation score. Peers with low scores are throttled or temporarily ignored, while those with better reputations get normal access to resources. The system does not ban nodes outright but reduces their ability to consume bandwidth or clog memory pools. Because reputation is local, each node makes its own decisions without waiting for the rest of the network to agree. This design avoids the need for protocol changes or central databases. It also means that spammers cannot regain access simply by creating new accounts, since new identities start with neutral reputation and must build trust over time. Rowdy Chotkan, a co-author of the research, said the team wanted to make adoption feasible without disrupting existing protocols. “Adoption of STARVESPAM faces challenges, especially in environments where profit incentives dominate,” he said. “Validators may have little motivation to filter transactions if doing so reduces potential fee revenue, and relayers may prioritize throughput over quality control.” Chotkan added that the system’s incremental deployability could help address this. “STARVESPAM does not require consensus modifications or network-wide coordination,” he said. “It is feasible for more conservative or high-reliability nodes, such as public RPC providers or gateways, to experiment with local filtering policies without affecting consensus or liveness.” He noted that adoption will likely depend on how operators view the trade-off between short-term gains and long-term reliability. “Widespread adoption may depend on whether enough infrastructure operators see value in curbing spam for the sake of system health, user fairness, or operational cost,” Chotkan said. “People will start caring about this once large-scale spam attacks become more frequent.” Overview of STARVESPAM’s transaction pipeline (Source: Research paper) Testing STARVESPAM in the wild To see how well the system works, the researchers replayed data from a major Ethereum spam event: the Otherside NFT mint of April 2022. During that event, gas fees surged above $180 million and many legitimate transactions failed due to network congestion. The team compared STARVESPAM with several common approaches, including fee-based filters and rule-based systems like BanMan. In tests using 50,000 transactions, STARVESPAM blocked about 95 percent of spam while dropping only about 3 percent of honest transactions. Other methods either let too much spam through or excluded more legitimate traffic. The researchers also simulated a network of 100 nodes to see how reputation evolved over time. Honest nodes quickly gained high scores, while malicious ones lost theirs. When some nodes switched from spammy to normal behavior, their reputation gradually recovered. This shows that the system can adapt without permanently excluding users who improve their behavior. The study modeled how local filtering affects network-wide spam propagation. With no filtering, spam reached nearly every node. With STARVESPAM, most spam stopped after a few hops while honest transactions still reached most of the network. This suggests that local reputation could sharply reduce the spread of unwanted traffic without hurting normal activity. Extending reputation across chains The researchers see future versions of STARVESPAM adapting to multi-chain and Layer 2 systems. Chotkan said those environments bring new difficulties. “Cross-chain and Layer 2 environments introduce a new class of challenges for spam mitigation,” he said. “Attackers can exploit bridges, airdrops, and incentive programs to spam across multiple chains using coordinated Sybil identities. This makes local reputation harder to track, especially when activity is fragmented across different layers or domains.” One potential solution involves extending reputation tracking across networks in a privacy-conscious way. “One promising direction is the use of shared identity primitives, such as decentralized identifiers or zero-knowledge credentials, to bind behavioral history across chains,” Chotkan said. “Integrating off-chain signals from indexers, RPC providers, or bridge monitors could also help nodes assess peer reputation even when traffic spans multiple domains.” Why reputation beats reaction The key innovation in STARVESPAM is its emphasis on behavioral accountability. Traditional blockchain defenses rely on economic deterrence, such as requiring higher fees or deposits. Those methods are easy to implement but often punish legitimate users along with attackers. A reputation system can adapt based on observed conduct instead of fee size. The approach also avoids the fragility of static rules. Nodes can adjust thresholds and heuristics to match their hardware limits and risk tolerance. While the prototype uses simple rule-based scoring, the design could later incorporate machine learning or external reputation sources without changing its structure.
helpnetsecurity.comOct 17, 2025extracted
North Korean hackers seen using blockchain to hide crypto-stealing malware
North Korean hackers seen using blockchain to hide crypto-stealing malware North Korean state-linked hackers have begun using public blockchains to deliver malware and steal cryptocurrency, in what researchers say is the first known case of a nation-state adopting the technique. Google security researchers said on Thursday that they observed a Pyongyang-backed hacking group, tracked as UNC5342, deploying a method known as EtherHiding — a way of embedding malicious code inside smart contracts on decentralized networks such as Ethereum and BNB Smart Chain. The technique makes it harder to block or remove malware, since the code is stored on blockchain ledgers that cannot be taken offline or altered. The malicious code remains accessible as long as the blockchain itself is operational, according to researchers. “This represents a shift toward next-generation bulletproof hosting,” Google said, noting that attackers are increasingly exploiting the same decentralization features that make blockchain resilient. Malware hidden in smart contracts Since February, UNC5342 has used EtherHiding as part of a social-engineering campaign that lures developers — often those working in the cryptocurrency or tech industries — into downloading malware disguised as job-related files or coding challenges. Once a target opens the file, a malicious script connects to the blockchain to retrieve encrypted code from a smart contract. That code installs the JadeSnow loader, which in turn delivers a more persistent backdoor known as InvisibleFerret that has been used in multiple cryptocurrency thefts. Because the malicious payloads are stored on decentralized blockchains, they cannot be removed by traditional takedown efforts. Attackers can also quietly update or replace their malware by modifying the smart contract, Google said. Blockchain’s pseudonymous nature adds another layer of anonymity, making it difficult to identify those behind the operation. Google said EtherHiding was first used in 2023 by a financially motivated group known as UNC5142, but this is the first time a state-sponsored actor has adopted it. The company added that while the hackers rely on decentralized blockchains to store their code, they still interact through centralized web services that defenders can monitor or block to disrupt attacks. “In other words, UNC5142 and UNC5342 are using permissioned services to interact with permissionless blockchains,” the researchers said. Daryna Antoniuk is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
therecord.mediaOct 16, 2025extracted
North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts
A threat actor with ties to the Democratic People's Republic of Korea (aka North Korea) has been observed leveraging the EtherHiding technique to distribute malware and enable cryptocurrency theft, marking the first time a state-sponsored hacking group has embraced the method. The activity has been attributed by Google Threat Intelligence Group (GTIG) to a threat cluster it tracks as UNC5342, which is also known as CL-STA-0240 (Palo Alto Networks Unit 42), DeceptiveDevelopment (ESET), DEV#POPPER (Securonix), Famous Chollima (CrowdStrike), Gwisin Gang (DTEX), Tenacious Pungsan (Datadog), and Void Dokkaebi (Trend Micro). The attack wave is part of a long-running campaign codenamed Contagious Interview, wherein the attackers approach potential targets on LinkedIn by posing as recruiters or hiring managers, and trick them into running malicious code under the pretext of a job assessment after shifting the conversation to Telegram or Discord. The end goal of these efforts is to gain unauthorized access to developers' machines, steal sensitive data, and siphon cryptocurrency assets – consistent with North Korea's twin pursuit of cyber espionage and financial gain. Google said it has observed UNC5342 incorporating EtherHiding – a stealthy approach that involves embedding nefarious code within a smart contract on a public blockchain like BNB Smart Chain (BSC) or Ethereum – since February 2025. In doing so, the attack turns the blockchain into a decentralized dead drop resolver that's resilient to takedown efforts. Besides resilience, EtherHiding also abuses the pseudonymous nature of blockchain transactions to make it harder to trace who has deployed the smart contract. Complicating matters further, the technique is also flexible in that it allows the attacker who is in control of the smart contract to update the malicious payload at any time (albeit costing an average of $1.37 in gas fees), thereby opening the door to a wide spectrum of threats. "This development signals an escalation in the threat landscape, as nation-state threat actors are now utilizing new techniques to distribute malware that is resistant to law enforcement take-downs and can be easily modified for new campaigns," Robert Wallace, consulting leader at Mandiant, Google Cloud, said in a statement shared with The Hacker News. The infection chain triggered following the social engineering attack is a multi-stage process that's capable of targeting Windows, macOS, and Linux systems with three different malware families - An initial downloader that manifests in the form of npm packages BeaverTail, a JavaScript stealer that's responsible for exfiltrating sensitive information, such as cryptocurrency wallets, browser extension data, and credentials JADESNOW, a JavaScript downloader that interacts with Ethereum to fetch InvisibleFerret InvisibleFerret, a JavaScript variant of the Python backdoor deployed against high-value targets to allow remote control of the compromised host, as well as long-term data theft by targeting MetaMask and Phantom wallets and credentials from password managers like 1Password In a nutshell, the attack coaxes the victim to run code that executes the initial JavaScript downloader that interacts with a malicious BSC smart contract to download JADESNOW, which subsequently queries the transaction history associated with an Ethereum address to fetch the third-stage payload, in this case the JavaScript version of InvisibleFerret. The malware also attempts to install a portable Python interpreter to execute an additional credential stealer component stored at a different Ethereum address. The findings are significant because of the threat actor's use of multiple blockchains for EtherHiding activity. Wallace told The Hacker News that they have not observed DPRK actors distribute fake installers (such as those for video conferencing software like FreeConference as has happened in the past) in conjunction with utilizing smart contracts as a stager for malicious code. "EtherHiding represents a shift toward next-generation bulletproof hosting, where the inherent features of blockchain technology are repurposed for malicious ends," Google said. "This technique underscores the continuous evolution of cyber threats as attackers adapt and leverage new technologies to their advantage."
thehackernews.comOct 16, 2025extracted
Video call app Huddle01 exposed 600K+ user logs
The Cybernews research team found that video call app Huddle01 exposed email addresses, real names, and other identifiers through an unprotected Kafka broker. Think of an unprotected Kafka broker like a post office that stores and delivers confidential mail. Now, imagine the manager leaves the front doors wide open, with no locks, guards, or ID checks. Anyone can walk in, look through private letters and photos, and grab whatever catches their eye. Huddle01 is a video call app that focuses on decentralized Web Real-Time Communication (WebRTC). WebRTC is appealing because it lets people talk and share data directly between devices without using a central server. Done right, this can reduce latency, cut costs, and improve privacy. But leaving your Kafka broker open to anyone who happens to stumble upon it does not qualify as “doing privacy right.” The Kafka broker operated without authentication or encryption, meaning anyone could listen in, collect logs, or potentially alter data if write access existed. This demonstrates a fundamental misconfiguration that puts both users and the platform at risk. The Kafka instance contained over 621,000 log entries from the last 13 days, belonging to Huddle01, including: Usernames (sometimes real names) Email addresses Crypto wallet addresses (Huddle01 supports many wallets across blockchains like Bitcoin and Ethereum) Detailed activity data, such as which users joined specific calls, participants in each call, country, time, date, and duration Other identifiers The app is popular among cryptocurrency users, but in this case the open Kafka instance could have deanonymized their wallets by tying their crypto wallets to usernames and email addresses. Which also paints a target on their back as potentially high-value targets. It also makes users more vulnerable to social engineering since attackers can craft credible emails or messages using real names and meeting data. And hold on for the worst part. Cybernews states it responsibly disclosed the data leak to the company behind Huddle01… “However, it did not respond to the initial disclosure and subsequent attempts. After one month, the exposed server remained accessible. It’s unclear how many other third parties might have accessed the data.” Security tips for affected users Knowing that the exposed information goes back about two weeks doesn’t help much, since anyone with access could have set up a data collector, listening in on the real-time data streaming and processing going on. So, any Huddle01 users should: Change passwords on accounts linked to the exposed email or username, and use strong, unique passwords for each site. Set up two-factor authentication (2FA) wherever possible to prevent unauthorized access. Monitor inboxes for suspicious messages. Be extra cautious of emails or texts asking for crypto transactions or sensitive information, as targeted phishing is a possibility. Be especially wary of social engineering attempts that reference details from meeting logs, such as who you spoke to or when meetings occurred. Stay updated on official statements from Huddle01 or news coverage, as they may release more guidance later. Pro tip: Did you know that you can submit suspicious messages like these to Malwarebytes Scam Guard, which instantly flags known scams? Something feel off? Check it before you click. Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
malwarebytes.comOct 16, 2025extracted
Don’t connect your wallet: Best Wallet cryptocurrency scam is making the rounds
Phishers and scammers can’t get enough of sending their feeble attempts to Malwarebytes’ employees. For which we can’t thank them enough because it means we can warn you, our readers. This time the scammers tried to impersonate Best Wallet—an app that lets people store, send, and receive cryptocurrencies like Bitcoin and Ethereum directly on their own device, without needing a middleman or a bank. The aim of this scam: to trick people into connecting their cryptocurrency wallets to a fake site, giving scammers a way to steal private keys, seed phrases, or other payment details. There are many cryptocurrency-based scams around, but this one is a little different. “BestWallet : You are eligible for our event !” The shortened URL leads to https://bestwallet-event[.]com/. To avoid detection by bots and researchers, the website is behind a Captcha—which also builds a bit of false trust, since it’s something visitors expect to see. Solving the Captcha brings the target to a rather convincing copy of the real bestwallet(.com) website, featuring the so-called event. For those new to cryptocurrencies, an “airdrop” is a giveaway of a new or existing cryptocurrency to promote awareness or reward supporters of a project or platform. On the surface the site looks very similar to the legitimate one, right down to the branding, visual assets, and even the FAQ content. But one thing stood out: the “Connect a Wallet” button in the top right-hand corner. The real site only provides links to official app stores for downloads. It doesn’t include wallet connect options or payment forms. If you were to tap that “Connect a Wallet” button, you’ll see these options: This is the same menu you’ll see if you click the “Claim Token” or “Check Eligibility” buttons, by the way. The code on the fake website also includes JavaScript elements that could copy/paste or intercept user inputs during wallet connections or transactions—unlike the official site, which directs users to app stores for all sensitive actions. From all this it seems obvious the scammers’ goal is to phish wallet credentials, private keys, seed phrases or steal payment details. These attacks are often disguised in interactive buttons/forms that the real site never uses outside the regulated app or store environments. How to stay safe Besides the golden rule–that when it sounds too good to be true, it probably is, or at least deserves extra scrutiny–there are a few other tips to stay out of the scammers’ claws: Don’t respond to unsolicited text messages. Never click on links in messages before verifying the destination. Scammers use shortened URLs to hide impersonation domains. Use up-to-date real-time protection on your devices, preferably with a web protection component: If you see any prompt for wallet connection, seed phrase, or card details directly in the browser, close the tab immediately. That’s a strong sign the site is fake and attempting to steal your cryptocurrency. If you’re unsure whether a message is a scam, submit it to Malwarebytes Scam Guard and it will help you decide and provide advice. Something feel off? Check it before you click. Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly. Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.
malwarebytes.comOct 7, 2025extracted
Loading 11 more…