This weekly recap catalogs widespread supply-chain and developer tool abuse, SEO-poisoning lures, zero-days (including YellowKey and GreenPlasma), and varied APT/ransomware activity across packages, installers, and cloud environments. Major trends include package registry compromises, installer/rootkit delivery, credential and wallet theft, tunneling/C2 expansion, and exploitation of cached/patched appliances and assigned CVEs. #TrapDoor #r77 #YellowKey #GreenPlasma #CoinbaseCartel #SonicWall
Supply Chain & Developer Tool Abuse
- TrapDoor crypto-stealer hit npm, PyPI, and Crates.io, abusing AI config files to steal wallets, SSH keys, cloud creds, and browser data β original
- Compromised @antv npm packages spread Mini Shai-Hulud-style install-time payloads that steal developer secrets and republish infected releases β original
- Typosquatted Go module github.com/shopsprint/decimal shipped a DNS TXT backdoor and remained available via proxy mirrors β original
- Trojanized JDownloader installers delivered an r77 rootkit bot and WDAC policy to disable security tools β original
- Compromised art-template npm package helped deliver a Coruna-linked iOS browser exploit kit β original
- Malicious Windsurf IDE extension used the Solana blockchain to stage a NodeJS stealer and hidden persistence β original
AI, SEO Poisoning & Fake Developer Tool Lures
- SEO poisoning used fake Gemini CLI and Claude Code downloads to install an infostealer that grabs tokens, cookies, files, and credentials β original
- Google Ads impersonating Claude Code pushed Windows stealers and a macOS backdoor via ClickFix-style commands β original
- Gemini-assisted influence and fraud campaign automated credential theft, crypto scams, and propaganda through a fake persona network β original
- AI-generated scripts are increasingly reaching production, raising governance and embedded-credential risks in SMB automation β original
Windows Exploitation, Zero-Days & Privilege Escalation
- YellowKey and GreenPlasma zero-days enabled BitLocker bypass and SYSTEM escalation; CVE-2026-45585 was assigned to YellowKey β original
- Nightmare-Eclipse publicly released YellowKey and GreenPlasma, with evidence the toolkit is already used in intrusions β original
- Legacy MSHTA remains a common malware launcher for LummaStealer, PurpleFox, loaders, and multi-stage HTA/PowerShell chains β original
- SonicWall SSL VPN exploitation of CVE-2024-12802 showed patched devices can remain exposed without manual reconfiguration β original
- Azure VMAccess naming abuse can evade password-reset telemetry and create a detection gap in Azure environments β original
APT, Espionage & Regional Operations
- Screening Serpens used tailored lures, DLL sideloading, and AppDomainManager hijacking to deploy MiniUpdate and MiniJunk V2 RATs β original
- Nimbus Manticore reused phishing, Trojanized installers, and MiniFast in campaigns against aviation and software targets β original
- Cloud Atlas expanded SSH-tunnel tradecraft with VBCloud, PowerShower, RevSocks, Tor, and PowerCloud for covert access β original
- Webworm added EchoCreep and GraphWorm, leveraging Discord, Microsoft Graph API, GitHub staging, and cloud infrastructure β original
- UNG0002 targeted Chinese academia with a weaponized institutional lure, DLL sideloading, and a final Cobalt Strike beacon β original
- Void Dokkaebi updated InvisibleFerret to Cython-compiled binaries and broadened BeaverTail for credential theft and wallet installation β original
Ransomware, Extortion & Credential Theft
- CoinbaseCartel ran a single-extortion, data-theft-only model and tied into ShinyHunters/Scattered Spider/Lapsus$ ecosystems β original
- The Gentlemen ransomware used Scheduled Tasks, PowerShell, log clearing, and Defender tampering for defense evasion β original
- Agent Tesla campaign hit LATAM enterprises with procurement lures, fileless execution, and FTP-based exfiltration β original
- ValleyRAT was delivered through fake Microsoft Teams downloads, NSIS installers, and DLL sideloading β original
- Banana RAT was linked to banking fraud activity originating from a compromised build server β original
- ShinyHunters, Andariel, BlueNoroff, and others featured in a broader financial-sector phishing, infostealer, and ransomware wave β original
Cloud, Platform & Infrastructure Abuse
- Azure-based vulnerable lab environments and validation workflows help test misconfigurations, privilege escalation, and cross-account access at scale β original
- Kubernetes CVE-2021-25740 allows traffic redirection via EndpointSlice/Endpoint manipulation in multi-tenant clusters β original
- UEFI PNG decoder flaw in BIOS firmware can trigger boot-time buffer over-read and potential memory/NVRAM leakage β original
Fraud, Phishing & Consumer Abuse
- Android carrier-billing fraud used nearly 250 malicious apps for premium SMS abuse across multiple countries β original
- Discord- and Dropbox-backed lure campaign hijacked Google accounts by abusing Family Link and malicious parent controls β original
- Fake event-invitation phishing delivered remote management tools such as ScreenConnect and LogMeIn Rescue for unauthorized access β original
- Phishing-to-RMM activity abused trusted tools and routine-looking downloads to create a remote-access blind spot for SOCs β original
- IPL 2026 betting ecosystem expanded through fake domains, tipper networks, deepfakes, and money-mule services β original
Malware Infrastructure, TTPs & Trend Reporting
- Dark web profile and sector reports highlighted growing reuse of stolen credentials, Telegram theft channels, and malware-for-hire ecosystems β original
- Global domain activity data showed millions of newly registered domains with a large malicious share, reinforcing NRD abuse trends β original
- AI-era threat research notes a need for machine-speed prioritization of actively exploited CVEs like React2Shell β original