ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories

ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
This week’s roundup shows attackers succeeding through a mix of greed, carelessness, and weak security, from exposed infrastructure and rogue ransomware affiliates to malicious developer packages and phishing lures. It also highlights deeper risks like vulnerable medical devices, predictable session cookies, and AI-targeted prompt injection hidden inside phishing messages. #Qilin #BraZetsu #VulcanRAT207 #GlassWorm #PowerBI #ScreenConnect #Muse #Baidu #Mimikatz #OpenVSX #VisualStudioMarketplace

Keypoints

  • Malicious VS Code themes in Visual Studio Marketplace and Open VSX were linked to Aurora Nocturne Night Theme and GlassWorm activity.
  • BraZetsu infrastructure was traced to phishing-driven access and an underground market selling compromised Windows hosts.
  • A WhatsApp-delivered lure installed VulcanRAT207 through a multi-stage chain using elevation, driver abuse, and DLL side-loading.
  • Azazel, a Gentlemen ransomware affiliate, stole victim data and extorted targets through a private leak site for personal profit.
  • Malicious npm and RubyGems packages targeted developers with credential theft, reverse shells, and a self-spreading Linux worm.

Read More: https://thehackernews.com/2026/10/threatsday-ransomware-affiliate.html