Cybersecurity Threat Research βWeeklyβ Recap. The roundup covers credential theft, phishing, and session abuse using device-code kit GhostCode, rogue Entra MFA provider TrustSink, and Fast Flux phishing infrastructure, alongside regional lures like Falso Bonus Vacanze and banking malware KREMLIN and RatHat. It also highlights cloud/identity and APT activity (including TraderTraitor, NightEagle, FamousSparrow/SparroWocky/SquawkDoor, and Operation RapidRust) plus crimeware and supply-chain/underground operations such as XMRig, MovieReaper, Evooo1Bot, PhantomRaven, and Tajin Group.
#GhostCode #TrustSink #FastFluxPhishing #FalsoBonusVacanze #KREMLIN #RatHat #AMOS #LLMjacking #Loot #UltraVault #TraderTraitor #NightEagle #FamousSparrow #SparroWocky #SquawkDoor #APT36 #OperationRapidRust #RedHeron #XMRig #MovieReaper #Evooo1Bot #Casbaneiro #DragonDoll #PhantomRaven #0Time #Nyx9 #Lemmings #TajinGroup #UBPAsset #KRSID #SparroWocky
Credential Theft, Phishing, and Session Hijacking
- Device code phishing kit GhostCode stole tokens and PRTs via business lures and obfuscated web flows: GhostCode (shortened linked title)
- Rogue Entra external MFA provider TrustSink captured plaintext passwords while still issuing valid tokens: TrustSink (shortened linked title)
- Fast-flux phishing infrastructure scaled domain rotation for large banking and callback-phishing campaigns: Fast Flux Phishing (shortened linked title)
- Fake Italian tax-agency βBonus Vacanzeβ site harvested identity documents and personal data: Falso Bonus Vacanze (shortened linked title)
- Brazilian banking malware KREMLIN delivered malicious browser extensions and stole banking sessions: KREMLIN Banking Malware (shortened linked title)
- Android malware RatHat abused smishing and ADB pairing to steal banking, OTP, and lock-screen secrets: RatHat Mobile Threat (shortened linked title)
- Amos stealer used a fake macOS toolkit page and clipboard-style execution chain for data theft: AMOS Stealer Activity (shortened linked title)
Cloud, DevOps, and Identity Abuse
- Stolen AWS credentials were used for LLMjacking against Amazon Bedrock and Marketplace subscriptions: Someone Else Is Using Your AI (shortened linked title)
- Credential-harvesting platforms Loot and UltraVault operationalized stolen AWS and AI service secrets: Attacker Infrastructure, Vibe-Coded (shortened linked title)
- GitHub audit-log hunting focused on stolen tokens, OAuth abuse, and source-code exfiltration: Hunting GitHub Abuse (shortened linked title)
- Elastic Cross-Project Search enabled one SOC to triage detections across 100 isolated tenant projects: Centralized Alert Triage (shortened linked title)
- Kubernetes audit logs were correlated with container runtime data to spot service-account abuse and breakout attempts: Kubernetes Audit Correlation (shortened linked title)
- Linux privilege-escalation detection guidance covered SUID abuse, unshare, and kernel corruption techniques: Linux LPE Detection (shortened linked title)
APT, Backdoors, and Espionage
- TraderTraitor resurfaced with macOS backdoors, fake job lures, and weaponized Terraform repos: TraderTraitor Backdoors Resurface (shortened linked title)
- NightEagle expanded into Russian targets using stolen VPN creds, Exchange abuse, and tunneling: NightEagle Targets Russian Companies (shortened linked title)
- FamousSparrow shifted to new modular backdoors SparroWocky and SquawkDoor against government targets: FamousSparrow Backdoors (shortened linked title)
- Pakistan-nexus backdoor used DLL side-loading and a decoy Pashto PDF to target Afghanistan government entities: Possible Pakistan-nexus Backdoor (shortened linked title)
- APT36 Operation RapidRust deployed Rust-based tooling via private GitHub repos and Backblaze-hosted payloads: Operation RapidRust (shortened linked title)
- Red Heron weaponized a Gitea n-day to steal source code and deploy a new Linux rootkit: Red Heron Exploits Gitea Flaw (shortened linked title)
Malware, Botnets, and Crimeware
- Multi-stage miner chain used Registry-stored PowerShell, DNS TXT, and media-file payloads to deploy XMRig: Registry-Stored Mining Chain (shortened linked title)
- MovieReaper spread through compromised torrents with Solana-based C2 and modular crimeware components: MovieReaper Torrent Campaign (shortened linked title)
- Evooo1Bot repurposed Mirai for encrypted C2, credential theft, SOCKS relay, and SSH brute forcing: Evooo1Bot Linux Botnet (shortened linked title)
- Casbaneiro targeted Latin American Windows users with invoice and legal-themed phishing to steal data: Casbaneiro Banking Trojan (shortened linked title)
- DragonDoll spyware disguised as a Chrome update and used encrypted C2 plus persistent Socket.IO handling: DragonDoll Spyware (shortened linked title)
- SquawkDoor added browser-waiting and one-time registration to confirm execution before TLS C2 comms: SquawkDoor Backdoor (shortened linked title)
Phishing, Supply Chain, and Underground Infrastructure
- PhantomRaven used malicious npm packages to steal CI/CD and system data, likely with LLM assistance: PhantomRaven npm Stealer (shortened linked title)
- Unauthorized OpenAI agent activity was linked to Hugging Face accounts 0Time and Nyx9: Agents at Large (shortened linked title)
- Lemmings leak exposed a synthetic persona factory for large-scale influence operations: Lemmings Persona System (shortened linked title)
- Tajin Group ran Telegram-based guarantee markets for phishing, carding, laundering, and cash-out services: Tajin Group Operations (shortened linked title)
- Illegal gambling sites doubled as laundering fronts and hidden C2 infrastructure for espionage: Casino Sites Hide Cybercrime (shortened linked title)
- UBP Asset private HTS platform was abused to distribute KRSID ransomware through fraud-themed lures: Private HTS Ransomware Delivery (shortened linked title)
Regional and Targeted Malware
- Latin America-focused campaign used SparroWocky with stealthy loading, persistence, and data theft features: SparroWocky Backdoor (shortened linked title)
- Windows backdoor from a ZIP uploaded in Afghanistan used a renamed executable and malicious DLL side-loading: Pakistan-nexus Afghanistan Backdoor (shortened linked title)
- Chinese-speaking actor targeted Latin American finance with Casbaneiro and selective C2 behavior: Casbaneiro in LATAM (shortened linked title)