ALERTS H ARTICLES ALERTS CONFERENCE MALWARE TRAFFICS UPDATE SOFTWARE BATTLEFIELD UKRAINE
PlikanLocker Ransomware
Point Wild Threat Intelligence has recently identified a new .NET-based ransomware strain named PlikanLocker that blends file extortion with aggressive endpoint lockdown tactics. Distributed primarily through phishing attachments, malicious links, and social media lures, the malware targets general Windows environments by securing administrator rights via UAC prompts. Once running, the payload parallelizes the encryption of user data using AES-CBC, processing files in chunks and appending a new extension. The threat is highly notable for its reliance on the Telegram Bot API to quietly exfiltrate WMI system profiles, encryption statistics, and captured desktop screenshots. To maximize victim pressure, the malware completely disables standard Windows interface elements—hiding the taskbar and Start menu—and traps the user behind a fullscreen, retro-styled ransom note.
Attack chain decomposition: Phishing/Social Media Lure → .NET Executable Execution → UAC Privilege Escalation → Mutex Check (Single Instance) → AES-CBC File Encryption (.locked) → WMI Host Profiling & Screenshot Capture → Telegram Bot API Exfiltration → Windows UI Suppression (Desktop/Taskbar Hidden) → Fullscreen Ransom Note Display
Threat Actors Deploy WordlistLoader in Latest Amatera Attacks
Researchers at Gen Threat Labs recently reported a new malware family called WordlistLoader, which threat actors are utilizing to deliver the Amatera infostealer to a wide range of victims. According to their analysis, the attack begins on legitimate but compromised websites where visitors encounter a fake CAPTCHA prompt as part of a ClearFake campaign. When users attempt the verification, they are manipulated through a ClickFix social engineering flow into copying and executing a malicious command via the Windows Run dialog. This action initiates the download of WordlistLoader, a loader that evades analysis by reconstructing its malicious shellcode from an array of plain English words or UUIDs. Once executed, the loader ultimately drops an updated version of the Amatera stealer, which has recently incorporated stronger obfuscation and system evasion techniques to silently harvest sensitive credentials.
Attack chain decomposition: Compromised website → Malicious JavaScript overlay (Fake CAPTCHA) → ClickFix clipboard prompt → User-initiated CMD execution via Windows Run → Remote WebDAV share mapped via pushd → WordlistLoader DLL executed via rundll32 → Defense evasion (ETW bypass, module unhooking) → Shellcode reconstructed from English wordlist → Amatera Stealer unpacked and executed in memory
Mirage2FA Campaigns
ANY.RUN has published a report on Mirage2FA, a commercial phishing-as-a-service (PhaaS) kit operated by LinX Coders that has been active between September 2024 and July 2026. Built to bypass multi-factor authentication and hijack Microsoft 365 sessions via an adversary-in-the-middle (AiTM) framework, the kit primarily targets organizations in the United States across the technology, manufacturing, and education sectors. Attackers deliver browser-executable attachments, such as HTML and SVG files, that leverage HTML smuggling and obfuscated JavaScript to retrieve a remote payload. Victims are presented with a reverse-proxied login page that intercepts credentials and one-time passcodes over a WebSocket connection. Once the user authenticates, the threat actors capture and exfiltrate the active session cookies, enabling unauthorized access to corporate resources without triggering additional MFA prompts.
Attack chain decomposition: Phishing email → .htm / .xhtml / .svg attachment → Browser execution of embedded stager → HTML smuggling / inline JavaScript execution → Remote loader retrieval → Fake Microsoft 365 login page presentation (AiTM reverse proxy) → Real-time credential relay over WebSocket → Authenticated session cookie exfiltration
Grandoreiro Banking Trojan Resurfaces With DLL Sideloading Campaign in Mexico
In a recent write-up, Acronis details a campaign demonstrating the geographic expansion of the Grandoreiro banking trojan from South America into Mexican financial, logistics, and industrial sectors. Distributed through tax- and invoice-themed phishing emails containing malicious ZIP archive attachments or direct download links, the attack chain lures victims into executing a heavily padded installer binary. The initial payload drops a combination of a signed, legitimate executable alongside a malicious dependency DLL to perform DLL sideloading. Once loaded, the DLL decrypts and launches the primary Grandoreiro payload in memory. This variant incorporates sophisticated anti-analysis controls, including string encryption, sandbox checks, and process monitoring, before establishing persistent communication with command-and-control servers to facilitate credential theft and online banking fraud.
Threat Group UAT-10147 Deploys SPECTRE Backdoor and Linux Rootkits
Researchers at Cisco Talos recently reported on malicious campaigns conducted by the Chinese-speaking threat group UAT-10147 targeting Linux and Windows web servers across government, education, technology, media, and gaming sectors worldwide. The threat actor leverages publicly disclosed vulnerabilities to achieve initial access before deploying a multi-platform post-exploitation framework centered on SEO fraud monetization. Intrusion workflows feature the deployment of SPECTRE, a newly identified cross-platform backdoor capable of process injection, credential harvesting, anti-analysis, and kernel-level endpoint defense neutralization via Bring Your Own Vulnerable Driver (BYOVD) techniques. Operational infrastructure is further sustained using Linux kernel rootkits and in-memory web shells.
AmnesiaStealer - a macOS infostealer written in Rust
Jamf Threat Labs researchers recently reported on AmnesiaStealer, an advanced multi-stage macOS malware written in Rust. Threat actors have been distributing this malware via "ClickFix" social engineering tactics, leveraging deceptive GitHub download pages. Once executed, the stealer extracts system passwords using native-looking prompts, exfiltrates Keychain data, and sweeps local storage for sensitive files, Apple Notes, and Telegram sessions. It also attempts outdated macOS security bypasses to access restricted disk locations and Safari data. A defining trait of AmnesiaStealer is its handling of Chromium-based browsers. The malware overwrites existing encryption keys with attacker-controlled values, ensuring newly secured data remains decryptable by the operator.
StealNui - a new Linux RAT variant
Security researchers at ExaTrack report on StealNui, an emerging C++-based Remote Access Trojan (RAT) crafted for Linux platforms. The malware provides operators with extensive espionage and surveillance functionality. Its toolkit includes screen capture utilities, a keystroke logger, reverse shell access, local file exfiltration, and arbitrary remote command execution and a cryptocurrency clipper module. In addition to surveillance, the implant actively loots sensitive user data, specifically targeting Discord authentication tokens, Roblox session cookies, and stored web browser credentials. The malware leverages Discord as its command-and-control (C2) channel and secures prolonged access using several persistence mechanisms across Linux hosts.
JWR PhaaS
In a recent write-up, Cisco Talos details an undocumented phishing framework dubbed JWR, which is built to impersonate major payment and e-commerce platforms. Delivered primarily through SMS lures disguised as postal and toll authorities in Southeast Asia and the Middle East, the framework operates as a highly interactive, real-time threat rather than a static credential harvester. Attackers maintain live control over the victim's session using an encrypted WebSocket connection, allowing them to stream keystrokes as they are typed and remotely dictate the flow of the attack. Through this hands-on-keyboard approach, operators can dynamically serve additional forms to siphon payment card details, identity documents, and two-factor authentication codes. Analysts assess this toolkit is likely a variant of the previously established "The Outsider" phishing-as-a-service platform.
Attack chain decomposition: SMS text message lure (postal/courier impersonation) → Malicious URL → JWR phishing page loaded (Vue.js application) → Persistent WebSocket C2 connection established → Real-time keystroke streaming → Operator-driven form delivery (credentials, 2FA, identity documents) → Data exfiltration → Victim redirection
QUICAgent Backdoor Hidden in VHD Lures
Researchers at Seqrite recently reported a campaign orchestrated by a China-nexus threat actor targeting Myanmar's government and IT sectors. Dubbed Operation QUICSILVER, the attacks single out diplomats and officials by using deceptive Burmese-language graduation ceremony invitations packaged inside Virtual Hard Disk (VHD) files.
Per their analysis, once a victim mounts the VHD, they are presented with a malicious shortcut disguised as a PDF document. Opening this shortcut triggers a legitimate FTP utility to silently reconstruct a hidden payload from split files. This process deploys QUICAgent, a custom Go-based backdoor that uses Cloudflare Workers to dynamically resolve its command-and-control infrastructure. The implant is particularly notable for utilizing the QUIC protocol over UDP and RC4 encryption to obscure its malicious traffic while executing remote commands and exfiltrating data.
Attack chain decomposition: VHD file → LNK shortcut disguised as PDF → FTP utility execution → Payload reconstruction → Go-based backdoor execution (QUICAgent) → Dynamic C2 resolution via Cloudflare Workers → C2 communication via QUIC over UDP/443 → Persistence via Startup folder shortcut
Lucid Stealer malware
Lucid Stealer is a sophisticated information-harvesting malware variant promoted through Telegram that masquerades as a legitimate Node.js JavaScript runtime. Upon execution, the malware deploys native modular components to conduct data harvesting operations. As reported by the researchers from Cyfirma, the malware forcibly terminates running processes to exfiltrate saved credentials, cookies, autofill entries, bookmarks, browsing histories, and payment card details across numerous Chromium- and Gecko-based web browsers. Furthermore, it intercepts Discord authorization tokens, copies sensitive files from popular cryptocurrency wallet applications (such as Exodus, Atomic Wallet, and Binance), captures desktop screenshots, and logs user keystrokes using a PowerShell script. Stolen data is continuously exfiltrated through persistent WebSocket connections and Axios-driven HTTP POST requests to command-and-control servers.
A new C2Looper backdoor variant identified
Cybersecurity researchers at Zscaler ThreatLabz uncovered C2Looper, an emerging Rust-based malware strain likely utilized by extortion actors and initial access brokers to establish footholds for network intrusion. Operating as a backdoor, C2Looper enables adversaries to perform system reconnaissance, run remote shell commands, dynamically resolve Windows APIs, and deliver secondary payloads for lateral movement. The threat remains under rapid development, evolving across multiple versions. Early variants relied on straightforward, plaintext HTTP POST requests containing JSON-formatted metadata to beacon host information back to adversary servers. A newer iteration, internally designated as version 2, is deployed directly through older implants and leverages GitHub repositories for all command-and-control operations.
Mustang Panda Updates CoolClient Backdoor with Rootkit
Kaspersky’s GReAT team has identified a major upgrade to the CoolClient backdoor, used by the Mustang Panda (aka HoneyMyte) APT group against government and corporate targets across Asia and Russia. Deployed alongside PlugX, CoolClient is sideloaded via a legitimate Sangfor application, executes an RPC-based privilege escalation, and injects into a suspended system process. The update introduces a signed kernel-mode driver controlled by the user-mode payload via IOCTL handlers. This driver hides and protects the malware’s processes, files, and registry keys while hooking networking components to mask command-and-control communications from security and forensic tools.
Majinahanashi Ransomware
Researchers at The Raven File recently reported a new ransomware family known as Majinahanashi, marking the emergence of another Japanese-themed extortion group. Translating to "ghost stories," the operators follow the branding patterns of earlier threats like Yurei and Tengu. The group leverages a non-vanity Tor domain for its data leak site. On successful compromise, a .majin extension will be appended to encrypted files.
Based on the victims they have claimed, this actor focuses on mid-sized enterprises globally, with average victim revenues of around $25 million and recorded targets including a high-revenue organization in Switzerland. Prior to releasing full datasets, the attackers publish stolen personally identifiable information as proof of compromise, indicating a standard double-extortion operational model.
ClickFix Lures Drop CNCMachineRMS RAT
LevelBlue SpiderLabs has published a report on a previously undocumented remote administration tool named CNCMachineRMS, distributed through a deceptive ClickFix lure. The infection flow abuses a legitimately signed IBM executable to activate a sequence of decoy dynamic link libraries, ultimately executing a BabaDeda shellcode loader. Once deployed, the CNCMachineRMS trojan grants attackers comprehensive hands-on-keyboard access, including screen capture, file management, and the creation of backdoor local accounts with elevated privileges. Notably, the implant evades traditional behavioral signatures by dynamically constructing its strings in memory, utilizing its own custom scripting language for task execution, and routing command-and-control traffic through DNS over HTTPS to bypass standard network logging.
Gh0st RAT malware distribution continues to be observed in the wild
The researchers from Checkpoint recently presented an update on ongoing malicious deployments of the Gh0st RAT, which is a well known Remote Access Trojan designed to grant cybercriminals covert, full-scale surveillance and unauthorized control over compromised endpoints. The malware relies on a modular client-server framework consisting of an administrative management console, a setup dropper, a persistent user-level payload, and an evasion-focused kernel driver. Attackers distribute Gh0st RAT through diverse social engineering vectors, including unsolicited phishing emails, direct messages across social networks, compromised Discord communities, and deceptive YouTube software lures. Once established, the malware conducts host reconnaissance and extracts sensitive assets - such as saved browser credentials, autofill records, financial details, and system hardware specifications. These modular capabilities allow operators to maintain persistent access and execute high-impact data exfiltration across targeted environments.
Evooo1Bot Linux botnet
Discovered by FortiGuard Labs, Evooo1Bot is an emerging Linux malware family named after a hardcoded string embedded in its binaries. Active against internet-exposed systems across multiple regions since at least July 2026, the botnet expands upon Mirai’s leaked DDoS engine with a sophisticated, modular toolset. Beyond traditional DDoS functionality - which includes highly customizable HTTP flood attacks - Evooo1Bot features multiple specialized offensive modules. It incorporates a credential-harvesting sniffer alongside an SSH brute-force engine designed to detect and bypass honeypots by inspecting target banners during protocol handshakes. Furthermore, a dedicated proxy component converts infected hosts into SOCKS5 network relays, operating over default ports with dual-stack IPv6 and IPv4 compatibility.
Project CAV3RN abuses trusted Google infrastructure for resilient espionage
Project CAV3RN is an evolving cyberespionage framework distinguished by its modular architecture and stealthy communication methods. Recent intelligence presented by the researchers from Securelist reveals the attackers leveraging command-and-control mechanism orchestrated through a 64-bit .NET 8 NativeAOT module. The payload utilizes DNS A-record queries to dynamically determine whether outbound traffic routes directly to an attacker-managed server or via an intermediate Google Apps Script relay.
Furthermore, the malware incorporates a local DLL broker that discovers, coordinates, and hot-swaps functional modules in memory while the infected machine remains operational, granting operators resilience and runtime upgrade flexibility. By transitioning from previously abused platforms like Outlook calendar events to Google Apps Script, the threat actors attempt to camouflage malicious traffic within standard enterprise cloud communications.
GhostDesk via Fake Softwares
A new campaign documented by Malwarebytes details the distribution of a malicious Google Chrome extension dubbed GhostDesk, delivered through counterfeit software installers. Threat actors are luring Windows users to spoofed download portals for popular utilities, including CCleaner, 7-Zip, and Adobe Acrobat. Once the trojanized executable is launched, it uses a legitimate scripting engine to hijack system components and forcibly patch Chrome's security extension settings. This allows the GhostDesk payload to silently load in the background, granting the attackers sweeping spyware capabilities. The malware can harvest credentials from web forms, log keystrokes, steal session cookies, capture screenshots, and manipulate clipboard data to hijack cryptocurrency transactions.
Attack chain decomposition: Fake software download site → Trojanized executable → Scripting engine execution → DLL hijacking → Chrome extension manifest patched → JavaScript payloads dropped → C2 connection → GhostDesk Chrome extension executes → Keylogging, credential theft, and cryptojacking
WindRelay and SpyNote Drive NFC Fraud
Researchers at Group-IB recently reported a new malware family combination involving a custom near-field communication (NFC) relay tool dubbed WindRelay deployed alongside the known SpyNote remote access trojan (RAT). This campaign primarily targets banking customers in Czechia, Slovakia, and Slovenia. The attack begins with a social engineering phone call where operators posing as bank employees convince victims to sideload a customized SpyNote payload. Leveraging the RAT's remote access capabilities, the attackers silently install WindRelay in the background while keeping the victim on the line. The threat actors then execute a dual cash-out strategy by remotely applying for a loan through the victim's banking app and instructing the victim to tap their payment card against the compromised device. WindRelay captures the dynamic NFC data exchange and forwards it to an attacker-controlled device, enabling immediate fraudulent point-of-sale transactions or ATM withdrawals.
Attack chain decomposition: Voice phishing call (impersonating bank) → Sideloaded APK payload (SpyNote RAT) → Remote access via Accessibility Services → Silent secondary APK install (WindRelay) → Remote banking app manipulation (digital loan) → Victim taps physical card to infected device → Real-time NFC data relay to attacker device → Fraudulent physical terminal cash-out
Sandworm-Linked Group Uses Fake Job Interviews to Deploy Trojanized WireGuard Client
According to CERT-UA, the Russian state-sponsored threat group Sandworm (tracked in this campaign as UAC-0145) is actively targeting system administrators and IT staff through fake job recruitment offers. Posing as hiring representatives from legitimate IT firms, the operators engage candidates via email and Telegram before conducting online technical interviews. During these assessments, candidates are instructed to download a corporate VPN setup that triggers a deliberate connection error, prompting them to retrieve a modified WireGuard installer hosted on SourceForge. The trojanized application, dubbed SopraVPN, incorporates custom key handling and obfuscated decoding logic to execute malicious commands on both Windows and Linux systems. On Windows, the client leverages a nonstandard configuration file parameter to execute PowerShell code that configures persistence and fetches secondary payloads, while Linux installations pull additional ELF binaries via cURL over the VPN tunnel.
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side
A months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into government ministries across Asia and the Middle East while quietly running a cryptocurrency fraud business on the side. The two are not separate ventures that happen to share a name: our investigation revealed they are run by the same small team, on shared infrastructure, from one control panel.
Jewelbug’s commercial arm is tied to a known registered company in Hunan Province, China. The group has developed five generations of command-and-control (C&C) code and a family of implants spanning browsers, Windows endpoints, Linux servers and network devices, all of it feeding a single database of victims. That toolset serves two missions: espionage attacks against foreign governments and militaries, and for-profit crypto fraud aimed at Chinese-speaking victims.
Chaos Malware Variant Targeting Linux Cloud Infrastructure
A new variant documented by Darktrace highlights how the Go-based Chaos botnet has shifted its targeting from edge routers to Linux cloud environments. Following an initial infection that quickly deletes its own footprint from the disk, the malware establishes long-term persistence using systemd services alongside a keep-alive script. While the payload retains its core distributed denial-of-service functions, this iteration notably abandons its previous SSH brute-forcing mechanisms in favor of a SOCKS5 proxy module. This embedded proxy capability is highly effective for adversaries, allowing them to route malicious traffic through the victimized cloud server to mask their true location, evade rate-limiting, and seamlessly pivot into otherwise restricted internal networks.
Gunra Ransomware expands its operations
A joint cybersecurity advisory released by international law enforcement and intelligence agencies including CISA, the FBI, NSA, USSS, DC3, and South Korea’s KNPA warns organizations of Gunra, an escalating ransomware-as-a-service (RaaS) threat. Initially discovered in April 2025 and built upon leaked Conti ransomware source code, the encryptor targeted Windows environments before incorporating Linux capabilities to enable multi-platform attacks. By early 26, the operators established a dark-web-promoted affiliate program targeting government entities and critical infrastructure. Gunra employs a double-extortion scheme, exfiltrating sensitive organizational files prior to encrypting system drives.
A new variant of the Kimwolf botnet identified in the wild
Researchers at Unit 42 of Palo Alto Networks detailed the operation of Aeternum, a C++ botnet loader that uses public Polygon blockchain smart contracts to manage decentralized command-and-control (C2) operations. The threat actors leverage JSON-RPC requests to public Polygon endpoints to bypass conventional IP and domain blocking, staging secondary payloads including XWorm RAT, XMRig cryptocurrency miners, data stealers, and Telegram-controlled Python backdoors. The loader also implements anti-analysis routines, including virtual machine verification and security control evasion, to ensure resilience against disruption.
Aeternum Botnet
Researchers at Unit 42 of Palo Alto Networks detailed the operation of Aeternum, a C++ botnet loader that uses public Polygon blockchain smart contracts to manage decentralized command-and-control (C2) operations. The threat actors leverage JSON-RPC requests to public Polygon endpoints to bypass conventional IP and domain blocking, staging secondary payloads including XWorm RAT, XMRig cryptocurrency miners, data stealers, and Telegram-controlled Python backdoors. The loader also implements anti-analysis routines, including virtual machine verification and security control evasion, to ensure resilience against disruption.
DeadLock Ransomware Combines Resource-Aware Encryption with Resilient Extortion Protocols
In a recent write-up, Microsoft Threat Intelligence details DeadLock, a Rust-based ransomware strain deployed by affiliates associated with established extortion syndicates. Active since mid-2025, the double-extortion operation has impacted more than 80 organizations across technology, manufacturing, transportation, and other critical sectors globally, with over half located in Europe. The malware decrypts an embedded configuration upon launch, evaluates system language settings to exit in excluded regions, and attempts privilege escalation using generated command scripts. To ensure maximum disruption and hinder recovery, DeadLock disables security services, terminates backup tools, suppresses event logging, and registers a custom file extension before encrypting localized drive contents. Crucially, the threat relies on decentralized communication channels—such as the Session messaging protocol and blockchain-supported assets—to maintain resilient victim negotiation portals.
CRPxO Ransomware
CRPxO is a ransomware group that operates under a Ransomware-as-a-Service (RaaS) model. They made a notable debut in the ransomware landscape during July 26, emerging alongside a few other new entrants to immediately establish a significant footprint. The actor has claimed 37 victims between 9 July and 2 August 26, and the set is heavily weighted toward US organisations. Türkiye is a distant but conspicuous second at seven, with single claims scattered across the Netherlands, South Korea, Australia, China, the UK and Ireland.
Symantec has analyzed one of their recent ransomware variants (sys_core_*.bin); it runs inside a portable Python virtual environment, allowing it to seamlessly execute its attack chain across Windows, Darwin (macOS), and Linux platforms. It handles everything from command-and-control (C2) communication—routing through both clearweb and .onion endpoints—to encryption and self-deletion, all within the same script. The binary doubles as the decryptor if passed the correct key via the command line.
The crypto splits along an unusual line. Local files get a randomly generated symmetric key encrypted with Fernet, and that key is uploaded to the C2 rather than wrapped locally with an embedded public key. Files on remote Windows shares take a different path: RSA with a hard-coded public key, so the private half sits only with whoever runs the panel. Shares are encrypted directly—skipping .exe, .dll, .sys, .ini, .lnk and existing .crpx0 files—meaning a file server can be hit without the malware ever executing on it.
Propagation is where it stops behaving like commodity Python ransomware. On Windows it enumerates neighbours via Active Directory, IP broadcast and the ARP cache, copies itself to C$\Windows\Temp, registers a scheduled task named "OneDrive Maintenance", and fires it off with wmic; it may also write a GPO startup script into SYSVOL. On Linux and Darwin it parses known_hosts and rides passwordless ssh/scp into /tmp on peers. Persistence is uneven—an onlogon task on Windows, com.apple.sync.plist on macOS, and nothing at all on Linux, where reinfection from a peer appears to be the intended survival mechanism.
Collection is selective. Alongside a sample of ordinary documents it pulls everything matching a curated keyword list—password, credential, token, wallet, metamask, seed, passport, ssn, vpn, backup—plus .kdbx, .keychain, .pem, .p12, .env, .ovpn and .keystore. The encryption exclusions are the tell: OS trees and the Python install are spared so the host stays usable, /tmp is skipped on Linux because that is the staging directory, and .ssh plus shell history are preserved outright—the very key material propagation depends on. Whoever wrote this was thinking about the next host, not just the current one.
The Windows evasion stack is far more developed than the crude chr()-obfuscated loader suggests: three debugger checks including debug-register inspection, sleep/GetTickCount timing comparison, sandbox artifact enumeration, and over a million API calls fired purely to exhaust analysis timeouts. It tries to unhook ntdll.dll from disk, patch AmsiScanBuffer and EtwEventWrite, bypass UAC through fodhelper.exe, and kill 73 security processes and 57 services across essentially every major vendor. Cleanup is a dropped .vbs or .sh that deletes the payload and then itself.
Impact is layered—notes across Desktop, Documents, Downloads and platform-specific paths, an HTML variant opened through Python's webbrowser module, wallpaper replaced. The scan_report.json it leaves behind doubles as the decryptor's own file index. Two loose threads in the code: a reference to a decoy PDF, and an embedded affiliate ID.
DOUBLECUP Loader-as-a-Service Deploys Stealthy RATs via Fake CRM Portals
Researchers at SOCRadar's Threat Research Unit recently reported on DOUBLECUP, a Russian Loader-as-a-Service platform built for ClickFix-style social engineering campaigns and active since early June 26. Operators license access to a client panel and embed DOUBLECUP's front-end logic into lure pages, including sites spoofing NetSuite, Odoo, HubSpot, and Salesforce login portals. Victims are tricked into pasting a clipboard-hijacked command that retrieves hidden code from a steganographic PNG cached by the browser, which then decrypts and loads a final payload in memory using a key derived from the victim's own public IP address, a technique intended to frustrate sandbox analysis. The service has been observed delivering an updated, fileless PowerShell build of CountLoader, a companion Mach-O variant for macOS, and a previously undocumented modular RAT called DeviceManager. DeviceManager is notable for resolving its command-and-control infrastructure through Ethereum and Polygon smart contracts (EtherHiding) and communicating over DNS tunneling or HTTP, making its infrastructure resilient to conventional takedown and blocklisting efforts.
Fake CAPTCHA Prompts Leverage ClickFix Tactics to Infect macOS Systems
In a recent write-up, Huntress details a macOS stealer malware campaign that uses ClickFix social engineering tricks to compromise Apple systems and siphon cryptocurrency wallets. Initiated through malicious links in email messages, the attack presents victims with a fake CAPTCHA window instructing them to paste a shell command into the macOS Terminal. The command fetches a profiling script that gathers hardware details, checks CPU architecture, and creates a masqueraded cache folder. It then downloads an architecture-matched Go-compiled Mach-O binary, removes Gatekeeper quarantine attributes, and executes the payload. Beyond harvesting browser password stores and Apple Keychain data, the stealer actively inspects crypto wallets to drain held funds into threat-actor-controlled accounts.
Vanta Stealer
Dubbed Vanta Stealer, a Python-based information stealer has been analyzed by the Lat61 Threat Intelligence Team, who describe it as a PyInstaller-packaged Windows executable with PyArmor-obfuscated bytecode protecting its core logic. The researchers note the sample itself gives no indication of how it reaches victims, but assess that social engineering is the likely route — phishing attachments, cracked or trojanized installers, fake software updates, game cheats and mods, malicious code repositories, and SEO poisoning or malvertising.
Rather than building browser credential theft into the payload, the stealer pulls down a separate extraction component when it runs — a modular design that lets the operators refresh browser support without rebuilding the malware. Alongside browser passwords, cookies and stored payment data, it queries the Discord API with each token it finds, pulling back the account's email, user ID, server admin rights, Nitro status and any saved payment methods, turning a raw token into a triage-ready victim profile. Additional modules target Steam, Roblox, Valorant, Telegram, Minecraft, Mullvad VPN configurations, cryptocurrency wallet files, screenshots, webcam captures, and local documents containing wallet recovery phrases or private keys. A Summary.txt inventory is generated before all artifacts are bundled into a ZIP archive and uploaded to a command-and-control endpoint via HTTP POST alongside victim metadata.
Attack chain decomposition: Social Engineering (Phishing / Trojanized Download) → PyInstaller-Packaged Executable → PyArmor-Obfuscated Python Payload → Runtime Retrieval of Browser Extractor Module → Credential, Token & Wallet Harvesting → Summary Generation → ZIP Archive Creation → HTTP POST Exfiltration to C2
Greatness PhaaS Campaigns Continue
In a recent write-up, ZeroBEC details a campaign utilizing the Greatness phishing-as-a-service (PhaaS) platform, tracked under the HoneyStorm tag by URLQuery. This evolving threat integrates adversary-in-the-middle (AiTM) token theft, device code phishing, and OAuth consent abuse into a centralized toolkit targeting Microsoft 365, iCloud, Yahoo, and Google Workspace. According to their findings, recent operations—consistent with the platform's documented targeting of the financial sector—initiated attacks using fabricated RingCentral voicemail and performance appraisal notifications.
Users who interacted with the lure were routed through a multi-stage redirect chain incorporating click-tracking services, anti-debugging redirectors, and bot detection gates before reaching either an AiTM proxy replicating the target's genuine tenant branding, or a device code phishing page themed around document sharing. The platform captures authentication tokens that have already satisfied multi-factor authentication, enabling threat actors to replay these tokens through commercial VPN infrastructure and achieve unauthorized access to corporate tenants.
Attack chain decomposition: Spoofed voicemail email → Malicious URL → Click-tracking redirect → Anti-analysis redirector with bot detection → Human verification gate → Greatness AiTM phishing domain or device code lure → Token capture via backend proxy → Benign decoy document redirection → Token replay via commercial VPN → Graph API enumeration and M365 access
Popular NPM Packages Hijacked with New Shai-Hulud Malware
Researchers at Aikido Security recently reported an active supply chain attack impacting widely downloaded npm libraries, including keyv and related caching utilities. The campaign leverages compromised maintainer credentials to publish poisoned package versions containing malicious preinstall hooks. When installed by developers or CI/CD pipelines, these scripts retrieve the legitimate Bun JavaScript runtime to execute an obfuscated stealer that harvests npm, GitHub, AWS, Kubernetes, and HashiCorp Vault secrets. Stolen credentials are encrypted and exfiltrated to attacker-controlled public GitHub repositories or secondary C2 infrastructure. Notably, the threat exhibits worm-like behavior, using hijacked tokens to automatically publish infected packages and commit backdoors into connected source repositories.
Abuse of ScreenConnect RMM and Cloudflare Tunnels in SMOKE#SCREEN Campaign
Researchers at Securonix recently reported an active multi-stage campaign dubbed SMOKE#SCREEN that abuses legitimate ScreenConnect remote monitoring and management (RMM) software to gain persistent access to enterprise endpoints. The operation targets both Windows and macOS environments using social engineering lures themed around Zoom updates, corporate document reviews, and system utilities. Attackers stage payloads on WebDAV infrastructure while leveraging Cloudflare Quick Tunnels and cloud storage links to distribute malware. Execution involves rotating droppers, spanning XOR-encoded VBScript files to compiled .NET binaries that dismantle local host defenses prior to installing signed ConnectWise ScreenConnect agents. Once deployed, the software beacons to attacker-controlled C2 relay servers, granting operators persistent and authorized-looking administrative access to targeted networks.
Hump Hump Locker Ransomware
Symantec's Threat Intelligence teams worldwide offer unparalleled analysis and commentary on current cyberthreats impacting businesses. Symantec's browser extensions integrate this intelligence directly into your browser, enabling effective detection and blocking of various web-borne threats.
Symantec Endpoint Security (SES) and Symantec Endpoint Protection (SEP) provide browser protection through dedicated browser extensions for Google Chrome and Microsoft Edge. These extensions leverage two core technologies:
URL reputation, which identifies and blocks websites hosting malicious content,
including phishing, malware, fraud, scams, and spam.
Browser Intrusion Prevention, which utilizes Symantec's advanced deep packet
inspection engine to safeguard users against a diverse range of threats.
The integration of these technologies within the browser environment delivers a
robust browser protection solution.
Over the past 30 days, a total of 46.6M attacks were successfully mitigated via the Endpoint protection browser extensions. This figure includes:
42.7M attacks blocked through URL reputation.
3.8M attempts to redirect users to attacker-controlled websites.
88.4K Browser Notification Scam, Technical Support Scam, and Cryptojacking
attacks.
25.2K attacks exploiting malicious script injections on compromised websites.
Customers are strongly advised to enable Endpoint browser protection. Detailed
instructions for implementation are available here. For those without SEP,
Symantec Browser Protection offers an alternative solution for securing your
browser, accessible here.
Go-based BlueShell Linux RAT Latest Variant
A new Go-written variant of the Linux-based BlueShell RAT, linked to BlackTech and other China-based threat actors, was recently reported by researchers at IIJ Sec. The variant deploys via an XOR-encoded dropper and focuses heavily on evasion, renaming its process to mimic a legitimate kernel worker thread to blend into standard system activity. Per their analysis, the configuration data is retrieved from encoded environment variables rather than on-disk files. Notably, this version bypasses direct outbound communication by tunneling its command-and-control traffic through the victim’s internal proxy servers, verifying connections via X.509 certificate checks before providing attackers with a remote shell.
Attack chain decomposition: SSH deployment of dropper → XOR and FastLZ4 decoding → Payload extraction to /tmp/kthread → Process masquerading as [kworker/12:12] → Configuration retrieved from wtim environment variable → C2 connection via internal proxy → X.509 certificate validation → Remote shell execution → Artifact self-deletion
Symantec protects you from this threat, identified by the following:
Carbon Black-based
Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.
AtlasRAT malware variant
AtlasRAT is a Remote Access Trojan (RAT) variant delivered through malicious setup files disguised as legitimate Flash Player software. As reported by researchers from ASEC, to obfuscate its command-and-control traffic, AtlasRAT utilizes ChaCha20 encryption over TLS, employing self-signed certificates spoofed to resemble Microsoft update infrastructure. Once active, the core malware provides threat actors with broad system control, including offline keystroke logging, file execution capabilities, process monitoring, and DLL code injection specifically targeting the WeChat application.
Symantec protects you from this threat, identified by the following:
Carbon Black-based
Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.
ValleyRAT distribution campaign targeting organizations in Japan
As reported by the researchers from Cato Networks, the Monarch threat group (aka SilverFox) has recently launched a malicious campaign targeting a Japanese industrial manufacturing company to deliver ValleyRAT, a persistent remote access trojan. Initiated via invoice-themed phishing emails linked to attacker-controlled content hosted on legitimate Tencent Cloud and QQ services, the attack drops a compressed file containing an initial downloader executable. To evade security monitoring, the threat actors abuse legitimate applications to sideload a malicious dynamic-link libraries. The used libraries operate as a modular Bring Your Own Vulnerable Driver (BYOVD) framework and has been observed to incorporate three separate vulnerable kernel-level drivers.
Flying Eagle Android RAT Source Code Leak Fuels New Attacks
Researchers at Hunt.io and NetAskari recently reported a new malware family known as the Flying Eagle Android RAT, which has fueled a fractured cybercriminal ecosystem following its source code leak. Threat actors have deployed over 170 active servers running the framework, primarily targeting Chinese users with fraudulent APKs that impersonate provincial government services, financial platforms, and adult apps. Once installed on a victim's device, the malware heavily abuses Android Accessibility Services for privilege escalation, enabling it to steal payment passwords, log keystrokes, and capture screen contents. According to their analysis, the builder framework stands out for its robust evasion capabilities, automatically obfuscating classes, encrypting command-and-control URLs, and injecting decoy JSON files to bypass static security analysis. Multiple modified variants of the RAT are now circulating in the wild, and its developers have already introduced a successor platform named Night Dragon.
Malicious npm Packages Target Chinese-Speaking Engineers
In a recent write-up, Socket details a complex supply chain attack utilizing a cluster of fraudulent npm packages to distribute a cross-platform remote access trojan. The threat actors uploaded counterfeit unscoped modules designed to impersonate proprietary Alibaba Group dependencies, primarily targeting Chinese-speaking software engineers. Upon installation, a seemingly benign dependency evaluator retrieves configurations from a remote repository and exploits a Node.js virtual machine sandbox evasion technique to load the subsequent malware stage. The final payload is a sophisticated backdoor equipped with comprehensive command execution, lateral movement capabilities, and the capacity to persist by injecting malicious code into common enterprise collaboration applications. This campaign is highly notable for its prolonged evasion of detection over several months, relying heavily on modular code fragmentation and geographically blended command-and-control infrastructure to maintain operational stealth.
Attack chain decomposition: Lure npm package installation → Dependency resolution via smart-config-manager → Configuration download from attacker GitHub repository → Node.js virtual machine sandbox escape → Third-stage JavaScript loader execution → Platform profiling and aone-cli RAT deployment → Collaboration tool persistence via Python script poisoning → Encrypted C2 proxy communication
Symantec protects you from this threat, identified by the following:
Carbon Black-based
Associated malicious indicators are blocked and detected by existing policies within Carbon Black products. The recommended policy at a minimum is to block all types of malware from executing (Known, Suspect, and PUP) as well as delay execution for cloud scan to get maximum benefit from Carbon Black Cloud reputation service.