Cybersecurity Threat Research ‘Weekly’ Recap. This week covered government/health phishing schemes for refund and reimbursement theft, plus Microsoft 365 session hijacking via AiTM tooling and broader crypto fraud using fake AML checkers, wallet apps, and stealer pipelines. Across malware delivery, supply chain, and cloud/identity abuse, researchers tracked campaigns involving ToxicPanda 2.0, ClearFake-to-Amatera chains, StopAndProtect WordPress intrusions, and covert infrastructure using BOFScale and Cloudflare Workers, alongside defensive guidance and emerging AI security benchmarking (EchoBench, AVDH).
#Mirage2FA #OperationASTERIX #ToxicPanda #ClearFake #Amatera #StopAndProtect #BRIDGEHEAD #BOFScale #CloudflareWorkers #EchoBench #BTRsys #Cruciferra
#Mirage2FA #OperationASTERIX #ToxicPanda #ClearFake #Amatera #StopAndProtect #BRIDGEHEAD #BOFScale #CloudflareWorkers #EchoBench #BTRsys #Cruciferra
Phishing, Fraud & Account Theft
- Government/health-themed phishing used fake refund and reimbursement lures to steal personal and card data. [Health Ticket Refund phishing] [EHR medicine refund phishing]
- MFA/session theft campaigns targeted Microsoft 365 users with AiTM tooling to bypass authentication and hijack sessions. [Mirage2FA steals M365 sessions] [Russian clusters abuse legit auth flows]
- Crypto fraud and wallet theft surged through fake AML checkers, wallet apps, phishing panels, and credential-stealing pipelines. [Operation ASTERIX] [Fake crypto AML checkers] [77 Firefox extensions steal wallets] [AI-driven crypto theft operation] [BRIDGEHEAD wallet stealer]
- Employment and insider-risk abuse used fabricated personas, AI tools, and remote access to obtain and retain jobs at scale. [PurpleDelta fraudulent employment ops]
Malware Delivery, Loaders & Banking Trojans
- Android threats expanded with ToxicPanda 2.0’s broader fraud features and new abuse of wireless debugging, plus head-unit malware via legitimate updater chains. [ToxicPanda 2.0] [Android head unit malware]
- Loader-based campaigns delivered stealer payloads via ClearFake/ClickFix-style chains and malicious attachments. [WordlistLoader -> Amatera] [PhantomStealer quote lure] [ErrTraffic + Cruciferra]
- Linux and Windows malware ecosystems continued evolving with new loaders, backdoors, and delivery networks. [Silver Fox / Gh0stRAT delivery network] [N4D Mesh Controller / go-titan] [Operation QUICSILVER] [Grandoreiro sideloading] [Deceptive download sites]
Supply Chain & Developer Ecosystem Attacks
- Open-source and package compromise hit Rust and npm ecosystems with malicious dependencies, typosquatting, and build-time malware. [Compromised Rust crates] [BRIDGEHEAD npm typosquatting] [Developer dependency culture and supply chain risk]
- WordPress abuse at scale supported backdoors, encryption, exfiltration, and infrastructure persistence. [StopAndProtect] [AI-driven WordPress compromise]
Cloud, Identity & Covert Infrastructure
- Cloud and auth abuse leveraged legitimate services for covert access, delivery, and C2. [BOFScale CDN-fronted tailnet] [Blockchain dead drop resolvers] [Russian espionage clusters] [QUICAgent via Cloudflare Workers]
- Exposed services remained a key entry point for Linux intrusion and lateral movement. [N4D targeting exposed MCP servers] [Siemens S7 PLC advisory] [SoftEther VPN attack cases]
Windows, Kernel & Defender Abuse
- Privilege escalation and AV/EDR evasion abused signed drivers, remediation paths, and filesystem/cloud sync primitives. [BTR.sys kernel primitive] [ShieldBreak LPE] [Cruciferra kills EDR]
AI Security, Agentic Research & Benchmarking
- AI-assisted offensive and defensive research advanced both pentest benchmarking and secure-code review. [EchoBench autonomous pentesting] [AVDH source code review] [CoSnitch Copilot flaw] [Coding agents secure-coding test]
Policy, Risk & Infrastructure Defense
- Government and vendor guidance highlighted elevated risk for critical infrastructure and patch management decisions. [Patch quality across SMB Windows fleets] [US transnational cybercrime policy risk] [Siemens PLC defensive advisory]