Threat Research | Weekly Recap [24 May 2026]

Threat Research | Weekly Recap [24 May 2026]

This weekly recap catalogs widespread supply-chain and developer tool abuse, SEO-poisoning lures, zero-days (including YellowKey and GreenPlasma), and varied APT/ransomware activity across packages, installers, and cloud environments. Major trends include package registry compromises, installer/rootkit delivery, credential and wallet theft, tunneling/C2 expansion, and exploitation of cached/patched appliances and assigned CVEs. #TrapDoor #r77 #YellowKey #GreenPlasma #CoinbaseCartel #SonicWall

Supply Chain & Developer Tool Abuse

  • TrapDoor crypto-stealer hit npm, PyPI, and Crates.io, abusing AI config files to steal wallets, SSH keys, cloud creds, and browser data β€” original
  • Compromised @antv npm packages spread Mini Shai-Hulud-style install-time payloads that steal developer secrets and republish infected releases β€” original
  • Typosquatted Go module github.com/shopsprint/decimal shipped a DNS TXT backdoor and remained available via proxy mirrors β€” original
  • Trojanized JDownloader installers delivered an r77 rootkit bot and WDAC policy to disable security tools β€” original
  • Compromised art-template npm package helped deliver a Coruna-linked iOS browser exploit kit β€” original
  • Malicious Windsurf IDE extension used the Solana blockchain to stage a NodeJS stealer and hidden persistence β€” original

AI, SEO Poisoning & Fake Developer Tool Lures

  • SEO poisoning used fake Gemini CLI and Claude Code downloads to install an infostealer that grabs tokens, cookies, files, and credentials β€” original
  • Google Ads impersonating Claude Code pushed Windows stealers and a macOS backdoor via ClickFix-style commands β€” original
  • Gemini-assisted influence and fraud campaign automated credential theft, crypto scams, and propaganda through a fake persona network β€” original
  • AI-generated scripts are increasingly reaching production, raising governance and embedded-credential risks in SMB automation β€” original

Windows Exploitation, Zero-Days & Privilege Escalation

  • YellowKey and GreenPlasma zero-days enabled BitLocker bypass and SYSTEM escalation; CVE-2026-45585 was assigned to YellowKey β€” original
  • Nightmare-Eclipse publicly released YellowKey and GreenPlasma, with evidence the toolkit is already used in intrusions β€” original
  • Legacy MSHTA remains a common malware launcher for LummaStealer, PurpleFox, loaders, and multi-stage HTA/PowerShell chains β€” original
  • SonicWall SSL VPN exploitation of CVE-2024-12802 showed patched devices can remain exposed without manual reconfiguration β€” original
  • Azure VMAccess naming abuse can evade password-reset telemetry and create a detection gap in Azure environments β€” original

APT, Espionage & Regional Operations

  • Screening Serpens used tailored lures, DLL sideloading, and AppDomainManager hijacking to deploy MiniUpdate and MiniJunk V2 RATs β€” original
  • Nimbus Manticore reused phishing, Trojanized installers, and MiniFast in campaigns against aviation and software targets β€” original
  • Cloud Atlas expanded SSH-tunnel tradecraft with VBCloud, PowerShower, RevSocks, Tor, and PowerCloud for covert access β€” original
  • Webworm added EchoCreep and GraphWorm, leveraging Discord, Microsoft Graph API, GitHub staging, and cloud infrastructure β€” original
  • UNG0002 targeted Chinese academia with a weaponized institutional lure, DLL sideloading, and a final Cobalt Strike beacon β€” original
  • Void Dokkaebi updated InvisibleFerret to Cython-compiled binaries and broadened BeaverTail for credential theft and wallet installation β€” original

Ransomware, Extortion & Credential Theft

  • CoinbaseCartel ran a single-extortion, data-theft-only model and tied into ShinyHunters/Scattered Spider/Lapsus$ ecosystems β€” original
  • The Gentlemen ransomware used Scheduled Tasks, PowerShell, log clearing, and Defender tampering for defense evasion β€” original
  • Agent Tesla campaign hit LATAM enterprises with procurement lures, fileless execution, and FTP-based exfiltration β€” original
  • ValleyRAT was delivered through fake Microsoft Teams downloads, NSIS installers, and DLL sideloading β€” original
  • Banana RAT was linked to banking fraud activity originating from a compromised build server β€” original
  • ShinyHunters, Andariel, BlueNoroff, and others featured in a broader financial-sector phishing, infostealer, and ransomware wave β€” original

Cloud, Platform & Infrastructure Abuse

  • Azure-based vulnerable lab environments and validation workflows help test misconfigurations, privilege escalation, and cross-account access at scale β€” original
  • Kubernetes CVE-2021-25740 allows traffic redirection via EndpointSlice/Endpoint manipulation in multi-tenant clusters β€” original
  • UEFI PNG decoder flaw in BIOS firmware can trigger boot-time buffer over-read and potential memory/NVRAM leakage β€” original

Fraud, Phishing & Consumer Abuse

  • Android carrier-billing fraud used nearly 250 malicious apps for premium SMS abuse across multiple countries β€” original
  • Discord- and Dropbox-backed lure campaign hijacked Google accounts by abusing Family Link and malicious parent controls β€” original
  • Fake event-invitation phishing delivered remote management tools such as ScreenConnect and LogMeIn Rescue for unauthorized access β€” original
  • Phishing-to-RMM activity abused trusted tools and routine-looking downloads to create a remote-access blind spot for SOCs β€” original
  • IPL 2026 betting ecosystem expanded through fake domains, tipper networks, deepfakes, and money-mule services β€” original

Malware Infrastructure, TTPs & Trend Reporting

  • Dark web profile and sector reports highlighted growing reuse of stolen credentials, Telegram theft channels, and malware-for-hire ecosystems β€” original
  • Global domain activity data showed millions of newly registered domains with a large malicious share, reinforcing NRD abuse trends β€” original
  • AI-era threat research notes a need for machine-speed prioritization of actively exploited CVEs like React2Shell β€” original

Threat Research | Weekly Recap – hendryadrian.com