Cybersecurity Threat Research ‘Weekly’ Recap. The recap covers a spike in open-source and developer-supply-chain compromises (including PyPI/npm/Docker/GitHub Actions), alongside phishing and social-engineering campaigns that use ClickFix-style infrastructure, Outlook Web Access exploits (TA488), and helpdesk vishing/Quick Assist to deploy GoGRPC backdoors. It also highlights new RAT/backdoor tools (AtlasRAT, OctLurk, SilkLurk, Mirage Kitten, Astaroth’s spambot), ransomware/intrusion chains (GenieLocker, Operation Double Barrel, OWAReaper), detection advances (Alert Zero, eBPF rootkit detection primitives), and financial/sanctions evasion involving Zedxion-linked entities. #PyPI #npm #DockerHub #GitHubActions #BattenDownYourPackages #DEV#POPPER #Joyfill #ClickFix #RemusStealer #AnimateClipper #SessionGate #TA488 #OWAreaper #LenAI #ErrTraffic #OutlookWebAccess #GoGRPC #AtlasRAT #OctLurk #SilkLurk #LurkProxy #MirageKitten #NightLedger #ArcBridge #BridgeHead #GenieLocker #OperationDoubleBarrel #VoidLink #LinkPro #Zedxion
Supply Chain, Package Poisoning & Developer Ecosystems
- Open source compromise surges across PyPI, npm, Docker Hub, and GitHub Actions, with mitigation guidance for credential theft and workflow abuse — Batten Down Your Packages
- Compromised npm betas in the @joyfill namespace delivered DEV#POPPER via hidden blockchain-resolved payloads — Joyfill npm Beta Releases
- Multi-package npm campaign impersonated Alibaba tooling to deploy a cross-platform RAT with theft, lateral movement, and persistence — npm RAT Targets Alibaba
- XCSSET v40 updates macOS supply-chain infection via poisoned Xcode projects, adding browser hijacking and stronger evasion — The Xcode Assassin Returns
Phishing, Social Engineering & ClickFix Distribution
- ClickFix-style DNS/TDS infrastructure pushed victims toward RemusStealer, AnimateClipper, and SessionGate — TDS-Powered ClickFix Ecosystem
- LenAI/ErrTraffic network used DNS infrastructure to distribute ClickFix lures and related payloads — LenAI ErrTraffic DNS Investigation
- TA488 exploited Outlook Web Access with a half-click attack to deploy OWAReaper against multiple sectors — TA488 Comes for Outlook
- Teams vishing and Quick Assist were used to install GoGRPC backdoors and support ransomware-style intrusion chains — Helpdesk Hijackers
- Indian taxpayers were targeted with fake notices and refund lures delivering malware and remote access tooling — Tax Season, Open Season
- Italian drivers faced a phishing site impersonating the transport portal to steal license and identity data — Phishing Scam Targeting Drivers
- False sextortion emails impersonating ShinyHunters reached Italy, demanding Bitcoin payments — False Sextortion ShinyHunters
- Astaroth/Guildma added a WhatsApp Web spambot to spread itself through infected victims — Astaroth’s New Spambot
- Adversarial prompt injection tools are being sold on underground forums for future abuse against AI agents — Notes from Underground
RATs, Backdoors & Espionage Tooling
- AtlasRAT uses a four-stage in-memory loader chain, TLS C2, and plugin-based execution for stealthy Windows control — Not Every Fox is Silver
- OctLurk, SilkLurk, and LurkProxy are tailored backdoors used in Central Asia espionage with loader diversity and heavy obfuscation — OctLurk and SilkLurk
- Mirage Kitten deployed NightLedger, ArcBridge, and BridgeHead for espionage across the Middle East, Africa, and Europe — Mirage Kitten Targets MENA
- GoGRPC variants plus proxying and theft tooling were used to maintain access and support hands-on intrusion activity — Helpdesk Hijackers
- MS-SQL compromise by Larva-26009 deployed VShell, GotoHTTP, SoftEther, and XMRig for remote control and mining — MS-SQL Server Case Study
- Kerberoasting and DNS tunneling can be surfaced in KATA through anomaly-based network detection rather than signatures — Network Anomaly Detection in KATA
Ransomware, Intrusion Chains & Lateral Movement
- GenieLocker ransomware hit Russian organizations with Windows, Linux, and ESXi variants after OpenVPN credential abuse — Toy Ghouls’ new toy
- Operation Double Barrel linked a state-sponsored intrusion chain with Gunra ransomware using shared infrastructure and malware overlap — Operation Double Barrel
- TA488’s OWAReaper added credential theft, persistence, and DNS/HTTPS exfiltration after an Outlook exploit — Cleaning Out Inboxes
Linux, Cloud & Kernel Evasion
- eBPF rootkits like VoidLink and LinkPro reveal themselves through suspicious helpers, enabling load-time fingerprinting — Detection Primitives for eBPF Rootkits
- Azure VM extension abuse can run root commands and steal managed identity tokens through a rogue Salt Master — Azure VM Command Execution using Third-Party Extensions
Detection, Analytics & Security Operations
- Elastic Alert Zero automates triage, correlates alerts, and embeds investigations while keeping analysts in control — Alert Zero
- Validin search and YARA updates add CIDR/ASN filtering and better indicator visibility for analysts — Advanced Search & YARA Improvements
- Security scripts at scale should be governed like production software, whether template-based or AI-generated — Two ways to scale your scripts
Sanctions Evasion & Financial Infrastructure
- Zedxion-linked entities formed a durable financial network allegedly used for illicit Iranian fund transfers and IRGC ties — Zedxion Corporate Nexus