Threat Research | Weekly Recap [20 Sep 2026]

Threat Research | Weekly Recap [20 Sep 2026]
Cybersecurity Threat Research β€˜Weekly’ Recap. The roundup covers credential theft, phishing, and session abuse using device-code kit GhostCode, rogue Entra MFA provider TrustSink, and Fast Flux phishing infrastructure, alongside regional lures like Falso Bonus Vacanze and banking malware KREMLIN and RatHat. It also highlights cloud/identity and APT activity (including TraderTraitor, NightEagle, FamousSparrow/SparroWocky/SquawkDoor, and Operation RapidRust) plus crimeware and supply-chain/underground operations such as XMRig, MovieReaper, Evooo1Bot, PhantomRaven, and Tajin Group.

#GhostCode #TrustSink #FastFluxPhishing #FalsoBonusVacanze #KREMLIN #RatHat #AMOS #LLMjacking #Loot #UltraVault #TraderTraitor #NightEagle #FamousSparrow #SparroWocky #SquawkDoor #APT36 #OperationRapidRust #RedHeron #XMRig #MovieReaper #Evooo1Bot #Casbaneiro #DragonDoll #PhantomRaven #0Time #Nyx9 #Lemmings #TajinGroup #UBPAsset #KRSID #SparroWocky

Credential Theft, Phishing, and Session Hijacking

  • Device code phishing kit GhostCode stole tokens and PRTs via business lures and obfuscated web flows: GhostCode (shortened linked title)
  • Rogue Entra external MFA provider TrustSink captured plaintext passwords while still issuing valid tokens: TrustSink (shortened linked title)
  • Fast-flux phishing infrastructure scaled domain rotation for large banking and callback-phishing campaigns: Fast Flux Phishing (shortened linked title)
  • Fake Italian tax-agency β€œBonus Vacanze” site harvested identity documents and personal data: Falso Bonus Vacanze (shortened linked title)
  • Brazilian banking malware KREMLIN delivered malicious browser extensions and stole banking sessions: KREMLIN Banking Malware (shortened linked title)
  • Android malware RatHat abused smishing and ADB pairing to steal banking, OTP, and lock-screen secrets: RatHat Mobile Threat (shortened linked title)
  • Amos stealer used a fake macOS toolkit page and clipboard-style execution chain for data theft: AMOS Stealer Activity (shortened linked title)

Cloud, DevOps, and Identity Abuse

  • Stolen AWS credentials were used for LLMjacking against Amazon Bedrock and Marketplace subscriptions: Someone Else Is Using Your AI (shortened linked title)
  • Credential-harvesting platforms Loot and UltraVault operationalized stolen AWS and AI service secrets: Attacker Infrastructure, Vibe-Coded (shortened linked title)
  • GitHub audit-log hunting focused on stolen tokens, OAuth abuse, and source-code exfiltration: Hunting GitHub Abuse (shortened linked title)
  • Elastic Cross-Project Search enabled one SOC to triage detections across 100 isolated tenant projects: Centralized Alert Triage (shortened linked title)
  • Kubernetes audit logs were correlated with container runtime data to spot service-account abuse and breakout attempts: Kubernetes Audit Correlation (shortened linked title)
  • Linux privilege-escalation detection guidance covered SUID abuse, unshare, and kernel corruption techniques: Linux LPE Detection (shortened linked title)

APT, Backdoors, and Espionage

  • TraderTraitor resurfaced with macOS backdoors, fake job lures, and weaponized Terraform repos: TraderTraitor Backdoors Resurface (shortened linked title)
  • NightEagle expanded into Russian targets using stolen VPN creds, Exchange abuse, and tunneling: NightEagle Targets Russian Companies (shortened linked title)
  • FamousSparrow shifted to new modular backdoors SparroWocky and SquawkDoor against government targets: FamousSparrow Backdoors (shortened linked title)
  • Pakistan-nexus backdoor used DLL side-loading and a decoy Pashto PDF to target Afghanistan government entities: Possible Pakistan-nexus Backdoor (shortened linked title)
  • APT36 Operation RapidRust deployed Rust-based tooling via private GitHub repos and Backblaze-hosted payloads: Operation RapidRust (shortened linked title)
  • Red Heron weaponized a Gitea n-day to steal source code and deploy a new Linux rootkit: Red Heron Exploits Gitea Flaw (shortened linked title)

Malware, Botnets, and Crimeware

  • Multi-stage miner chain used Registry-stored PowerShell, DNS TXT, and media-file payloads to deploy XMRig: Registry-Stored Mining Chain (shortened linked title)
  • MovieReaper spread through compromised torrents with Solana-based C2 and modular crimeware components: MovieReaper Torrent Campaign (shortened linked title)
  • Evooo1Bot repurposed Mirai for encrypted C2, credential theft, SOCKS relay, and SSH brute forcing: Evooo1Bot Linux Botnet (shortened linked title)
  • Casbaneiro targeted Latin American Windows users with invoice and legal-themed phishing to steal data: Casbaneiro Banking Trojan (shortened linked title)
  • DragonDoll spyware disguised as a Chrome update and used encrypted C2 plus persistent Socket.IO handling: DragonDoll Spyware (shortened linked title)
  • SquawkDoor added browser-waiting and one-time registration to confirm execution before TLS C2 comms: SquawkDoor Backdoor (shortened linked title)

Phishing, Supply Chain, and Underground Infrastructure

  • PhantomRaven used malicious npm packages to steal CI/CD and system data, likely with LLM assistance: PhantomRaven npm Stealer (shortened linked title)
  • Unauthorized OpenAI agent activity was linked to Hugging Face accounts 0Time and Nyx9: Agents at Large (shortened linked title)
  • Lemmings leak exposed a synthetic persona factory for large-scale influence operations: Lemmings Persona System (shortened linked title)
  • Tajin Group ran Telegram-based guarantee markets for phishing, carding, laundering, and cash-out services: Tajin Group Operations (shortened linked title)
  • Illegal gambling sites doubled as laundering fronts and hidden C2 infrastructure for espionage: Casino Sites Hide Cybercrime (shortened linked title)
  • UBP Asset private HTS platform was abused to distribute KRSID ransomware through fraud-themed lures: Private HTS Ransomware Delivery (shortened linked title)

Regional and Targeted Malware

  • Latin America-focused campaign used SparroWocky with stealthy loading, persistence, and data theft features: SparroWocky Backdoor (shortened linked title)
  • Windows backdoor from a ZIP uploaded in Afghanistan used a renamed executable and malicious DLL side-loading: Pakistan-nexus Afghanistan Backdoor (shortened linked title)
  • Chinese-speaking actor targeted Latin American finance with Casbaneiro and selective C2 behavior: Casbaneiro in LATAM (shortened linked title)

Threat Research | Weekly Recap – hendryadrian.com