Cybersecurity Threat Research ‘Weekly’ Recap. Attackers abused fake installers, developer-platform lures, and AI-driven tooling to deliver loaders and steal credentials, including campaigns tied to Silver Fox, GlassWorm, JSCEAL, TA419, Remcos, and Vidar. Alongside these tradecraft shifts, the roundup highlighted active zero-day exploitation in Citrix NetScaler and PaperCut MF, plus supply-chain and exposed-credential risks involving MALFEX and leaked GitHub datasets.
#SilverFox #GlassWorm #JSCEAL #TA419 #Remcos #Vidar #CitrixNetScaler #CVE-2026-88771 #CVE-2026-88772 #PaperCutMF #AdaptixC2 #MALFEX #TIKTOUK #Jewelbug #Warlock
#SilverFox #GlassWorm #JSCEAL #TA419 #Remcos #Vidar #CitrixNetScaler #CVE-2026-88771 #CVE-2026-88772 #PaperCutMF #AdaptixC2 #MALFEX #TIKTOUK #Jewelbug #Warlock
Fake software, browser, and marketplace delivery
- Fake vendor installers targeted China-based and Chinese-speaking orgs in a Silver Fox campaign. (DNS Spotlight: Silver Fox Strikes Anew…)
- Malicious VS Code theme extensions on Marketplace/Open VSX used obfuscated loaders and dead drops linked to GlassWorm. (Pretty Themes, Hidden Loaders…)
- Facebook crypto-reward ads pushed fake installers and Node.js payloads in a JSCEAL campaign. (Beware of Malware infection in Facebook Ads…)
- ChatGPT Custom GPTs and Google Sites were abused to trigger PowerShell and deploy a RAT. (Attackers Abuse ChatGPT Custom GPTs…)
Edge appliance and zero-day exploitation
- Citrix NetScaler zero-days CVE-2026-88771/88772 were actively exploited for web shells, persistence, and internal access. (Threat Brief: NetScaler Zero Days…)
- Follow-on guidance detailed exploitation artifacts, reverse shells, and privilege creation on NetScaler devices. (Citrix NetScaler CVE-2026-88771…)
- CISA amplified the NetScaler emergency, warning of multiple exploited flaws and urging IoC review before patching. (Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway)
- PaperCut MF zero-days enabled a loader-to-web-shell intrusion ending with AdaptixC2 and domain compromise. (PaperCut MF Zero-Day Intrusion…)
- Telerik UI exploitation led to web shells, scanners, and reverse shells on exposed ASP.NET AJAX servers. (Vulnerability Attack Case: Installation of a Web Shell…)
Malware loaders, infostealers, and crypto theft
- 2CLoader delivered Vidar, Remus, and XWorm using anti-analysis and HTTP C2. (2CLoader: A New Malware Loader…)
- Remus distribution used EtherHiding rotation and multiple loaders to spread the infostealer at scale. (SLTT C2 Traffic Tied to Remus Malware Distribution Operation)
- Underground abused browser-session injection to drain crypto exchange accounts and steal funds. ($100k in Crypto Drained by the Underground Operation)
- Fake crypto reward-vote sites mimicked major projects to trick users into wallet approvals and token theft. (Fake xStocks, Pendle, and other sites…)
- SC WordPress malware used self-healing loaders and blockchain-controlled backdoor logic for persistence. (SC WordPress Malware…)
Phishing, AitM, and credential theft
- TA419 impersonated economists and AI policymakers to steal Microsoft 365 and Entra ID credentials. (Hallucinating Credibility…)
- AI-powered intrusion chained Zammad zero-days for rapid session hijack, root access, and exfiltration. (AI agent exploits Zammad zero-days…)
- Quote-request phishing dropped VBScript/PowerShell and installed Remcos RAT via Google Drive. (Beware of phishing emails disguised as quote requests)
- Another phishing wave used malicious XLS files and CVE-2017-0199 to deploy Remcos RAT. (Beware of Phishing Emails That Disguise Themselves…)
- West African fraud actors abused compromised .edu accounts for credential harvesting and job-scam payment fraud. (From EDU Account Takeover to Job Scam Abuse…)
Supply chain, developer ecosystem, and exposed credentials
- MALFEX ran a long-lived npm/GitHub supply chain with malicious postinstall packages and stealers. (MALFEX – A malicious npm postinstall…)
- GitHub code datasets for AI training still contained hundreds of thousands of valid leaked credentials. (GitHub Credentials Also Exposed in Datasets…)
- TIKTOUK harvested WordPress and email credentials through probing, config scraping, and secret scanning. (TIKTOUK: Tracing a WordPress Credential Collection Toolkit)
- Open Directories beta expands hunting across exposed web files and historical directory datasets. (Introducing Open Directories: Search Exposed Web Files)
Advanced malware and edge backdoors
- BPFDoor, BPF Rekoobe, and AVERAT disguised themselves in telecom/appliance environments to evade detection. (SMTP is the key: BPFDoor and AVERAT hitting the network edge)
- Warlock ransomware operators used SharePoint flaws, VS Code tunneling, and SYSVOL abuse to hit critical infrastructure. (Warlock Ransomware Attackers Hit Water and Telecom Operators)
- KMS Auto was abused as initial access in a multi-stage intrusion involving mining, remote access, and scareware. (From KMS Auto to Scareware…)
Regional espionage and cybercrime infrastructure
- Jewelbug ran espionage and crypto-fraud operations from a shared control panel with massive cookie theft. (Jewelbug Targets the Middle East and Asia…)
- Spetsvuzavtomatika leak exposed an SVR cyber-development ecosystem and related infrastructure. (Spetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem)
- September attack trends showed more session theft, remote access abuse, and payment-fraud blending into normal workflows. (Major Cyber Attacks in September 2026…)
AI and exploitation trends
- GTIG reported AI is accelerating vuln discovery, disclosure, and exploitation across enterprise middleware and AI stacks. (Vulnerability Discovery and Exploitation Trends in the AI Era)
- MITRE released ATT&CK v19 updates affecting technique mapping and defensive workflows. (MITRE ATT&CK v19: What’s changed…)