Cybersecurity Threat Research ‘Weekly’ Recap. This week’s coverage highlights credential-stealing and session-hijacking campaigns (BigBear 2.0, HVNC, Malicious Twitch extension, and Axiom Trade/Padre theft) alongside exploit chains that rapidly weaponize browser and platform vulnerabilities, including Marimo (CVE-2026-39987), GRAYRABBIT, and GRIMWEDGE/SUPERSTOMP/LONGTALE. Researchers also tracked emerging threats and abuse patterns such as SloppyRAT, ClearFake/WebDAV delivering Amatera/ZigCryptoStealer/NetSupport Manager, chat-based data leakage via a ChatGPT shared clipboard flaw, and AI manipulation efforts like PuzzleMask and adversarial agentic workflows. #BigBear2_0 #Evilginx2 #HVNC #Twitch #JeetBot #AxiomTrade #Padre #Marimo #CVE-2026-39987 #GRAYRABBIT #GRIMWEDGE #SUPERSTOMP #LONGTALE #BlueMoon #GemStone #ShadowPad #SloppyRAT #ClearFake #Amatera #ZigCryptoStealer #NetSupportManager #EtherHiding #SourTrade #CL-CRI-1171 #MantaxOtax #MacSync #Syslogk #ChatGPT #PuzzleMask #LockBit #Cl0p #Akira #Medusa #Qilin
Phishing, Social Engineering & Credential Theft
- Fake tax-themed phishing uses VHDX payloads, loader/DLL injection, and disposable domains to target Indian taxpayers — shortened linked title
- BigBear 2.0 rebranded Evilginx2 PhaaS steals Microsoft 365 sessions and bypasses MFA via AiTM — shortened linked title
- HVNC backdoor spreads via fake tax and DocuSign lures, adding hidden remote access and data theft — shortened linked title
- Malicious Twitch extension exposes live OAuth tokens through proxy infrastructure tied to JeetBot — shortened linked title
- Cross-browser crypto extensions steal Axiom Trade and Padre sessions, wallets, cookies, and tokens — shortened linked title
Exploit Chains, Zero-Days & Backdoors
- Marimo CVE-2026-39987 exploited in seconds to pivot from WebSocket terminal access to SSH and AWS credential theft — shortened linked title
- Sogou Input Method CVE-2026-51990 enables one-click RCE and delivered GRAYRABBIT in the wild — shortened linked title
- Chrome/Windows zero-day chains rapidly adopted by state-aligned actors to deploy GRIMWEDGE, SUPERSTOMP, and LONGTALE — shortened linked title
- BlueMoon exploit kit chains Chrome and Windows flaws for espionage payload delivery, including GemStone and ShadowPad — shortened linked title
Malware, Loaders & Ransomware Ecosystems
- SloppyRAT emerges as a multi-stage, anti-analysis tool likely used in ransomware-related intrusions — shortened linked title
- ClearFake/WebDAV chains deliver Amatera, ZigCryptoStealer, and NetSupport Manager with EtherHiding support — shortened linked title
- SourTrade malvertising impersonates trading brands to spread unfinished malware across a large typosquatting infrastructure — shortened linked title
- CL-CRI-1171 runs a pay-per-install campaign via YouTube and SEO-poisoned downloads to drop multiple payloads — shortened linked title
- Mantax Otax combines Android spyware, theft, remote surveillance, and ransomware in one campaign — shortened linked title
- MacSync Stealer targets macOS via ClickFix lures and malvertising to steal Keychain, cookies, SSH keys, and wallets — shortened linked title
- Syslogk rootkit hides Linux processes, connections, files, and modules with kernel-level stealth — shortened linked title
Browser, Cloud & SaaS Abuse
- AWS access key compromise detection correlates CloudTrail and GuardDuty to trace validation, persistence, and exfiltration — shortened linked title
- Defender ASR + Wazuh detects blocked Windows attack behaviors and ASR tampering across endpoints — shortened linked title
- ChatGPT shared clipboard flaw enables cross-account task execution and data leakage via hidden command channels — shortened linked title
AI Threats, Abuse & Adversarial Operations
- PuzzleMask hides malicious prompts in plain prose to bypass AI gatekeepers and trigger target models — shortened linked title
- Adversarial AI activity is shifting from prompting to agentic workflows for credential theft, supply chain abuse, and model targeting — shortened linked title
- China-based AI firms allegedly run industrial-scale distillation campaigns against major U.S. frontier models — shortened linked title
Infrastructure, Tracking & Ransomware Intelligence
- DNS spotlight on ransomware maps infrastructure for LockBit, Cl0p, Akira, Medusa, and Qilin — shortened linked title
- Threat infrastructure analysis links commodity abuse, typosquatting, and rotational domains across campaigns — shortened linked title