Ravie Lakshmanan 2026年9月24日 黑客新闻 / 网络安全新闻
本周,危险的恶意软件继续披着无聊的外衣出现。一次更新、一个登录框、一个搜索答案、一个编码工具、一个你以前点击过上百次的链接。
这就是贯穿这一系列事件的主线。可信的路径被污染,旧的漏洞找到了新的用途,AI工具泄露的数据超出预期,伪造的提示看起来足够逼真。而且有些攻击几乎根本不需要利用漏洞——只需要一个薄弱的设置,或者一个人按照屏幕指示进行操作。
这里没有任何事情看起来特别戏剧化。而这正是其危害所在。
威胁每周都在变化。订阅我们,我们将在每期《ThreatsDay Bulletin》发布时提醒您。
AI辅助银行木马
一款此前未被记录的名为RemControl的Android银行木马正针对西欧(意大利、法国、西班牙、波兰、葡萄牙)、中东和加拿大的零售银行客户。该恶意软件通过伪装成TVTap IPTV应用的虚假Google Play Store页面进行分发。用户通过Meta广告被引导至该网页。它于2026年7月首次被发现。“该恶意软件滥用Android的辅助功能服务,在合法的银行应用程序上注入网络钓鱼覆盖层,实时流式传输设备屏幕,记录击键,并为操作员提供对受感染设备的完全远程控制,”Group-IB表示。“C2地址通过加密的Telegram死信箱动态解析,使得基础设施轮换无需重新编译恶意软件即可轻松完成。操作员面板文档和网络钓鱼覆盖层中都包含AI辅助开发的痕迹,包括在提供给银行受害者的实时网络钓鱼页面中完整保留了AI助手的回复原文。”多个覆盖HTML文件中存在俄语代码注释,表明有俄语使用者参与。重叠的活动命名约定、分发机制、Telegram死信箱的使用以及联盟标签的相似性表明可能与Medusa UNKN联盟僵尸网络有关联。
AI代码隐私担忧
中国人工智能公司Z.ai在SpaceXAI的Grok Build编码CLI被发现将其控制的Google Cloud Storage存储桶中上传整个Git仓库几个月后,禁用了其ZCode编码助手的几项功能,原因是默认设置被捕获到未经用户同意将用户的本地代码库发送至中国的阿里云服务器。尽管Z.ai随后禁用了其ZCode客户端中负责生成和上传本地仓库快照的工作流,并公开了其代码库以供公众审查,但这一开发引发了企业界对AI工具如何处理敏感源代码的新的担忧。
关键基础设施访问风险
美国联邦调查局(FBI)和网络安全与基础设施安全局(CISA)发布了一份事实清单,“以强调关键基础设施实体在与第三方工业控制系统(ICS)集成商合作时减少风险和最小化漏洞的注意事项”。该警报敦促关键基础设施的所有者和运营商在授予第三方ICS集成商对工业过程的高级别访问或控制权时保持谨慎,并确保应用最小权限原则(PoLP)。“不采用诸如PoLP等原则可能会使所有者和运营商面临寻求破坏关键基础设施的恶意网络行为者的威胁,可能为这些行为者提供可利用以造成设备和中枢功能中断和破坏性影响的敏感访问路径,”撰写该文件的机构表示。
超级应用监控能力
MAX 是由俄罗斯国有背景、由 VK(即 VKontakte)开发的移动“超级应用”,它集成了即时通讯、电子商务、银行服务以及政府公共服务。来自密歇根大学、卡尔加里大学、佐治亚理工学院和印度德里印度理工学院的一组研究人员发表的一项新法医研究揭示了其监控能力的程度:“作为主动攻击者,我们发现 MAX 具备五种不同的能力,使其能够充当所有迷你应用交互的中间人:(1) MAX 可以在不持有特殊系统权限且不提醒用户的情况下捕获迷你应用内容的截图;(2) 它拥有对所有迷你应用本地存储的完全读写访问权限,这意味着迷你应用在设备上持久化的任何数据对 MAX 来说都不是私有的;(3) 它将 JavaScript 注入正在运行的迷你应用中,从而在运行时以静默且不可检测的方式修改迷你应用的功能;(4) 它调解所有迷你应用的网络流量,特别是在俄罗斯区域版本中,将这些流量路由到 GOST TLS 代理,引发了对国家级别拦截的严重担忧 [18];(5) 最后,它控制提供给每个迷你应用的认证令牌和会话上下文,使其能够静默地冒充超级应用生态系统中托管的任何服务的任何用户。这些发现揭示,MAX 的超级应用架构可以主动且静默地破坏用户在与每个迷你应用交互时所假设的安全保障。”
虚假赠品钓鱼陷阱
一个虚假的 Claude Max 赠品活动利用伪造的 Google 登录窗口,通过浏览器内浏览器(BitB)攻击窃取用户的登录凭据。“没有收集卡号的表单,也没有下载,”Malwarebytes 表示,“相反,它提供了一次免费升级,并要求你用 Google 账户登录。点击 Google 按钮并不会打开真正的 Google 登录窗口。相反,该页面在现有标签页内绘制了一个浏览器窗口,包含锁形图标和拼写正确的 Google 登录地址。它甚至可以在页面上拖动。”
EDR 规避技术
2026年7月,研究人员 Max Hirschberger 和 Ogulcan Ugur 详细阐述了一种称为“进程参数投毒”(Process Parameter Poisoning)的技术,用于在不触发传统安全机制的情况下向外部进程注入代码。Flashpoint 现已发布了一个用 Rust 实现的概念验证,以演示这种 EDR 规避技术。“进程参数投毒是一种新颖的端点检测与响应(EDR)规避技术,它结合了进程参数欺骗和线程执行劫持,从而在不触发标准安全检测机制的情况下向外部进程注入代码,”Flashpoint 表示,“该技术不调用内存访问 API 来分配和写入目标进程,而是在创建进程的初始阶段将恶意有效载荷直接隐藏在标准的进程初始化结构中。结果是防御规避的根本性转变,有效地使传统的、基于 API 钩子的 EDR 代理在代码执行的初始阶段失明。”
更快的 Ubuntu 内核修复
“近期”由 AI 驱动的大量 CVE(通用漏洞披露)激增,促使 Canonical 转向统一的两周发布周期,将其为期四周的常规稳定版更新(SRU)和为期两周的安全修复周期合并。“这些重复的两周周期会级联:每个周期在前一个周期开始后的那一周启动。由于这种重叠,内核发布将每周进行,”Canonical 表示,“第一周将专注于内核包准备。在这里,我们根据具体需求决定哪些更新和补丁应用于每个内核。”
AI 搜索投毒活动
据Vigilance Security的Ariel Simon称,一场大规模的人工智能虚假信息攻击正在向ChatGPT、Gemini和Google AI Overviews注入错误信息、欺诈性电话号码、电子邮件地址和登录页面。Simon表示:“当用户查询数百家大型企业的日常信息时,人工智能正将伪装成可信答案的网络钓鱼陷阱呈现给用户。”“攻击者通过精心优化的帖子、PDF文件、评论和虚假支持页面淹没网络,诱使人工智能展示欺诈性的电话号码、电子邮件地址和登录页面。”此次活动的目标包括达美航空、汉莎航空、卡塔尔航空、大通银行、美国银行、爱彼迎、猫途鹰以及其他几家公司。虚假内容被上传至社交媒体、允许上传文件的网站、网站托管平台(Google Sites、GitHub Pages、WordPress和Blogger)、筹款平台、求职平台以及活动平台(Posh.vip、onecause.com、bebee.com和raiselysite.com),甚至包括Yelp和Apple Maps上的评论。
ClickFix MaaS仿制品
Sekoia揭示了一个名为Exvicy的新型ClickFix恶意软件分发框架,该框架自2026年5月26日起由一名俄语使用者在Exploit.in上以恶意软件即服务(MaaS)模式进行推广。其起步价为每月1,200美元,并在8月中旬涨至2,000美元,运营商声称“检测频率日益增加”。该框架利用被入侵WordPress网站中注入的虚假Cloudflare验证码检查中的Windows运行对话框策略来分发恶意软件。安全研究员Quentin Bourgue表示:“Exvicy是ErrTraffic的仿制品,直接复用了其注入的JavaScript、ClickFix HTML以及命令与控制(C2)通信逻辑。”“对Excvicy JavaScript框架的检查表明,它复用了ErrTraffic的代码库,包括注入到被入侵WordPress网站的混淆脚本以及负责命令与控制(C2)通信的ClickFix诱饵。”
恶意WordPress更新
一个针对WordPress的Admin Menu Editor Pro插件的恶意版本于2026年9月14日上传至adminmenueditor[.]com。该插件维护者Janis Elsts表示:“这对启用该插件的用户显示为2.35版本的更新。”“此版本包含一个新文件includes/wp-user-consent.php,会在用户网站上安装Webshell。”在同一天推送了干净版本(2.36)后,威胁行为者再次破坏了新版本,这表明他们可能已获得服务器的根级别访问权限。截至9月20日,维护者为那些没有插件干净副本的客户发布了2.37版本。根本原因被追溯至一个过时的Linux内核版本中的漏洞,最早的入侵迹象可追溯到2026年9月13日晚上7点40分左右(UTC)。该维护者还表示,他们正在“几乎从头开始重建更新服务器和许可API”,这一工作“可能轻松需要几周时间”。Elsts向Bleeping Computer发表声明称,至少有230名客户在1,500个站点上安装了恶意更新。
政府冒充诈骗
美国联邦调查局(FBI)警告称,诈骗分子正冒充美国和外国执法部门或政府官员,以实施广泛的欺诈计划,向受害者勒索钱财或个人身份信息(PII)。据称,在2025年1月至2026年7月期间,FBI网络犯罪投诉中心(IC3)收到了近6.1万起关于冒充执法部门或政府官员的诈骗投诉,导致损失总额超过16亿美元。FBI表示:“诈骗分子在冒充这些官员时会采用多种手段,例如使用紧急和强硬的语气、拒绝与目标受害者以外的人交谈或留下留言、在整个诈骗过程中让受害者在电话中保持通话,或敦促受害者不要将通话情况告知家人、朋友、金融机构或执法部门。”“诈骗分子要求通过多种方式付款,包括预付卡、快递、银行电汇、加密货币,或将现金存入加密货币自助终端机。”
GitHub 缓存投毒防御
GitHub 宣布,开发人员现在可以使用 cache-mode 在工作流或作业级别对 GitHub Actions 缓存应用最小权限访问控制。GitHub 表示:“通过仅授予每个工作流或作业其所需的缓存访问权限,您可以防止不必要的恢复或保存,并帮助保护可信工作流免受缓存投毒攻击。”“此功能现已在所有计划中全面可用。”据 Socket 称,新设置针对的是缓存投毒攻击,例如2024年观察到的 Ultralytics PyPI 包案例以及2026年5月发现的 TanStack npm 包案例。Socket 指出:“缓存投毒之所以可行,是因为在一个上下文中写入共享 Actions 缓存的条目可以在另一个上下文中被恢复并运行。”“获得对缓存键写入权限的攻击者可以植入恶意构建工件或依赖项,这些内容将以该工作流的权限和密钥执行。”
软件供应链攻击
SafeDep 披露称,一名未知威胁行为者在2026年9月8日向拥有96,600个 GitHub 星的 Python 换脸应用 Deep-Live-Cam 添加了一个恶意的源依赖项。SafeDep 补充道:“该依赖项包含一个加载器,用于下载针对 Windows 和 macOS 的加密货币剪贴板劫持程序。”“恢复的有效载荷会替换剪贴板文本中的钱包地址,并注册自身在登录时运行。”在另一起案例中,这家供应链安全公司检测到一个名为 ulid-xyz 的恶意 npm 包,它通过拼写错误模仿(typosquatting)ulidx,但隐藏着一种通过 postinstall 钩子触发的跨平台远程访问特洛伊木马。SafeDep 表示:“postinstall 钩子表面上是一个检查构建文件是否存在的守卫。”“实际上,它会作为分离的后台进程启动 dist/node/utils.js,该进程进而启动 dist/node/payload.js,这是一个467 KB 捆绑的特洛伊木马。该捆绑包解码混淆的配置,并通过 WebSocket 向硬编码的命令服务器发送信标。随后,它在 Windows、macOS 和 Linux 上以 MicrosoftSystem64 的名称安装持久性。”该恶意软件具备对主机进行指纹识别、访问文件系统以及运行攻击者发送的任意代码的能力。MicrosoftSystem64 此前曾通过 js-logger-pack 和 terminal-logger-utils 包分发,是一种与朝鲜有关的窃密程序和植入物。
OpenAI 凭证钓鱼
一封欺诈性订阅发票邮件活动正针对用户展开,旨在通过伪造登录页面窃取其账户凭证,并诱骗用户在48小时内采取行动,以避免服务中断。Cofense表示:“虽然AI聊天机器人在执行重复性任务方面是极其有用的工具,但用户需要意识到,与所有账户创建一样,凭证盗窃的威胁依然持续存在。”“无论是类似本文描述的传统网络钓鱼攻击,还是利用短信钓鱼(smishing)或语音钓鱼(vishing),攻击者都在不断寻找绕过安全系统和安全电子邮件网关(SEGs)的独特途径。”在另一起网络钓鱼活动中,以付款计划为主题的邮件被用于启动一个多阶段攻击链,最终导致Global Group勒索软件的部署。Cofense表示:“Global Group是通过对遗留的Black Lock和Mamona勒索软件家族进行品牌重塑而形成的,它继承了既有的后端基础设施,复用了核心代码构件,并迅速启动了可扩展的勒索业务。”“他们积极与初始访问经纪人(IABs)合作,购买已遭入侵的企业凭证,使其附属成员能够绕过外围防御。Global Ransomware利用双重勒索和公开数据泄露的威胁作为其激进谈判策略的一部分。”
DarkMe通过社会工程学卷土重来
Huntress表示,其在2026年8月31日发现了两起分别影响不同组织的DarkMe恶意软件事件。DarkMe是一种与被称为Water Hydra(又名DarkCasino)的黑客组织相关的Visual Basic特洛伊木马。Huntress表示:“两年前,DarkMe通过利用两个独立的零日漏洞来分发其恶意软件而建立了声誉:WinRAR(CVE-2023-38831)和Windows Defender SmartScreen(CVE-2024-21412)。”“但在这些新事件中,该恶意软件并未利用漏洞,而是依靠社会工程学来说服
Ravie Lakshmanan Sep 24, 2026 Hacking News / Cybersecurity News
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before.
That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just one weak setting or one person doing what the screen tells them.
Nothing here looks especially dramatic. That is what makes it useful.
The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.
AI-Assisted Banking Trojan
A previously undocumented Android banking trojan dubbed RemControl is targeting retail banking customers across Western Europe (Italy, France, Spain, Poland, Portugal), the Middle East, and Canada. The malware is distributed via fake Google Play Store pages impersonating the TVTap IPTV application. Users are directed to the web page through Meta ads. It was first observed in July 2026. "The malware abuses Android's Accessibility Service to inject phishing overlays over legitimate banking applications, stream the device screen in real time, log keystrokes, and provide the operator with full remote control over infected devices," Group-IB said . "C2 address is resolved dynamically through an encrypted Telegram dead-drop, making infrastructure rotation straightforward without recompiling the malware. Both the operator panel documentation and phishing overlays contain artifacts of AI-assisted development, including a complete AI assistant response left verbatim in a live phishing page served to banking victims." The presence of Russian-language code comments in multiple overlay HTML files indicates the involvement of a Russian speaker. Overlapping campaign naming conventions, delivery mechanisms, the use of Telegram dead-drop and affiliate tag similarities suggest a possible link to the Medusa UNKN affiliate botnet.
AI Code Privacy Concern
Chinese artificial intelligence company Z.ai has disabled several features of its ZCode coding assistant after a default setting was caught sending users' local code repositories to Alibaba Cloud servers in China without their consent, a couple of months after SpaceXAI's Grok Build coding CLI was found uploading entire Git repositories to a Google Cloud Storage bucket under its control. Although Z.ai has since disabled the workflow responsible for generating and uploading local repository snapshots in its ZCode client and opened up its codebase for public scrutiny, the development raises fresh concerns for enterprises over how AI tools handle sensitive source code.
Critical Infrastructure Access Risk
The U.S. Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have published a fact sheet to "highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators." The alert urges critical infrastructure owners and operators to maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes and ensure the principle of least privilege (PoLP) is applied. "Not adopting principles such as PoLP could expose owners and operators to malicious cyber actors seeking to compromise critical infrastructure, possibly providing sensitive access to pathways that actors can exploit to cause disruptive and destructive effects to equipment and critical functions," the authoring agencies said.
Super-App Surveillance Capabilities
MAX is a state-backed Russian mobile "super-app" developed by VK (aka VKontakte) that combines instant messaging, e-commerce, banking, and public government services. A new forensic research published by a group of researchers from the University of Michigan, University of Calgary, Georgia Institute of Technology, and Indian Institute of Technology, Delhi, has revealed the extent of its surveillance capabilities: "Playing the role of an active adversary, we found five distinct capabilities that allow MAX to act as a man-in-the-middle for all mini-app interactions: (1) MAX can capture screenshots of mini-app content without holding any special system permissions, and without alerting the user; (2) It holds full read and write access to all mini-app local storage, meaning no data a mini-app persists on-device is private from MAX; (3) It injects JavaScript into running mini-apps, enabling silent, undetectable modification of mini-app functions at run-time; (4) It mediates all mini-app network traffic, and in the Russian regional build specifically, routes this traffic through a GOST TLS proxy, raising acute concerns about state-level interception [18]; (5) Finally, it controls the authentication tokens and session context supplied to each mini-app, granting it the ability to silently impersonate any user to any service hosted within the super-app ecosystem. These findings uncover that MAX's super-app architecture can actively and silently undermine the security guarantees that users assume when interacting with each mini-app."
Fake Giveaway Phishing Trap
A fake Claude Max giveaway has used a spoofed Google sign-in window to steal users' login credentials by means of a browser-in-the-browser (BitB) attack. "There is no form to collect card details and no download," Malwarebytes said . "Instead, it offers a free upgrade and asks you to sign in with your Google account. Clicking the Google button doesn’t open a real Google sign-in window. Instead, the page draws a browser window inside the existing tab, complete with a padlock and a correctly spelled Google sign-in address. It can even be dragged around the page."
EDR Evasion Technique
In July 2026, researchers Max Hirschberger and Ogulcan Ugur detailed a technique called Process Parameter Poisoning to inject code in foreign processes without triggering traditional security mechanisms. Flashpoint has now released a proof-of-concept implemented in Rust to demonstrate the EDR evasion technique. "Process Parameter Poisoning is a novel endpoint detection and response (EDR) evasion technique that combines process parameter spoofing and thread execution hijacking to inject code into foreign processes without triggering standard security detection mechanisms," Flashpoint said . "Instead of calling memory-accessing APIs to allocate and write into a target process, the technique hides the malicious payload directly inside standard process initialization structures during the initial creation of a process. The result is a fundamental shift in defense evasion that effectively blinds traditional, API-hooking EDR agents during the initial stages of code execution."
Faster Ubuntu Kernel Fixes
The "recent explosion" in the volume of CVEs, mainly driven by AI, has prompted Canonical to transition to a unified, 2-week release cycle that merges its four-week cycle for regular Stable Release Updates (SRUs) and its two-week cycle for security fixes. "These recurring 2 week cycles cascade: each cycle begins the week after the previous one starts. Because of this overlap, kernel releases will take place weekly," Canonical said . "The first week will focus on kernel package preparation. This is where we select what updates and patches land on each kernel depending on specific needs."
AI Search Poisoning Campaign
A massive AI disinformation attack is poisoning ChatGPT, Gemini, and Google AI Overviews with false information, fraudulent phone numbers, email addresses, and login pages, according to Vigilance Security's Ariel Simon . "When users look up everyday info of hundreds of major companies, AI is delivering phishing traps disguised as trusted answers," Simon said. "Attackers are flooding the web with carefully optimized posts, PDFs, reviews, and fake support pages, to trick AI into presenting fraudulent phone numbers, email addresses, and login pages." Targets of the campaign include Delta, Lufthansa, Qatar Airways, Chase, Bank of America, Airbnb, TripAdvisor, and several other companies. The fake content is uploaded to social media, websites that allow file uploads, website hosting platforms (Google sites, GitHub pages, Wordpress, and Blogger), fundraisers, job search, and event platforms (Posh.vip, onecause.com, bebee.com, and raiselysite.com), and even reviews on Yelp and Apple Maps.
ClickFix MaaS Copycat
Sekoia has shed light on a new ClickFix malware distribution framework dubbed Exvicy that has been advertised by a Russian-speaking actor under a malware-as-a-service (MaaS) model on Exploit.in since May 26, 2026. It launched at $1,200 per month and rose to $2,000 in mid-August, with the operator claiming "detections are becoming daily." The framework employs the Windows Run dialog tactic on fake Cloudflare CAPTCHA checks injected into compromised WordPress sites to distribute malware. "Exvicy is a copycat of ErrTraffic , directly reusing its injected JavaScript, ClickFix HTML, and C2 communication logic," security researcher Quentin Bourgue said . "Examination of the Excvicy JavaScript framework demonstrated that it reuses the ErrTraffic JavaScript codebase, including the obfuscated script injected to compromised WordPress sites and the ClickFix lure responsible for command-and-control (C2) communications."
Malicious WordPress Update
A malicious version of the Admin Menu Editor Pro plugin for WordPress was uploaded to adminmenueditor[.]com on September 14, 2026. "This showed up as a version 2.35 update to users who had the plugin active," Janis Elsts, the plugin's maintainer, said . "This version included a new file includes/wp-user-consent.php that installs a web shell on the user's site." After a clean version (2.36) was pushed the same day, threat actors managed to again compromise the new version, suggesting they may have obtained root-level access to the server. As of September 20, the maintainer has released version 2.37 for customers who don't have a clean copy of the plugin. The root cause has been traced back to a vulnerability in an outdated Linux kernel version, with the earliest sign of compromise dating back to September 13, 2026, at around 7:40 p.m. UTC. The maintainer also said they were working on "rebuilding the update server and licensing API nearly from scratch," an effort that "could easily take a couple of weeks." In a statement shared with Bleeping Computer, Elsts said at least 230 customers installed the malicious update on 1,500 sites.
Government Impersonation Scams
The FBI is warning that scammers are impersonating U.S. and foreign law enforcement or government officials to extort money or personally identifiable information (PII) from victims as part of widespread fraud schemes. Between January 2025 and July 2026, the FBI's Internet Crime Complaint Center (IC3) is said to have received nearly 61,000 complaints of law enforcement or government impersonation scams, leading to losses totaling more than $1.6 billion. "Scammers will use a variety of approaches while impersonating these officials, such as using urgent and aggressive tones, refusing to speak to or leave messages with anyone other than the targeted victim, keeping victims on the phone for the duration of the scam, or urging victims not to tell family, friends, financial institutions, or law enforcement about the call," the FBI said . "The scammers demand payment through a variety of methods, including prepaid cards, couriers, bank wires, cryptocurrency, or cash inserted into cryptocurrency kiosks."
GitHub Cache Poisoning Defense
GitHub has announced that developers can now use cache-mode to apply least-privilege access to the GitHub Actions cache at the workflow or job level. "By granting each workflow or job only the cache access it needs, you can prevent unnecessary restores or saves and help protect trusted workflows from cache poisoning," GitHub said . "This capability is now generally available on all plans." According to Socket, the new setting targets cache poisoning attacks such as those observed in the case of the Ultralytics PyPI package in 2024 and the TanStack npm packages in May 2026. "Cache poisoning works because an entry written to the shared Actions cache in one context can be restored and run in another," Socket noted . "An attacker who gains write access to a cache key that a trusted workflow later reads can plant malicious build artifacts or dependencies that execute with that workflow's permissions and secrets."
Software Supply Chain Attack
SafeDep has disclosed that an unknown threat actor added on September 8, 2026, a malicious source dependency to Deep-Live-Cam, a Python face swapping application with 96,600 GitHub stars. "The dependency contains a loader that downloads a cryptocurrency clipboard hijacker for Windows and macOS," SafeDep added . "The recovered payload replaces wallet addresses in clipboard text and registers itself to run at login." In another case, the supply chain security company detected a malicious npm package named ulid-xyz that typosquats as ulidx but harbors a cross-platform remote access trojan that's triggered via postinstall hook. "The postinstall hook reads as a guard that checks if a build file exists," SafeDep said . "It actually launches dist/node/utils.js as a detached background process, which starts dist/node/payload.js, a 467 KB bundled trojan. That bundle decodes an obfuscated configuration and beacons to a hard-coded command server over WebSocket. It then installs persistence on Windows, macOS and Linux under the name MicrosoftSystem64." The malware is equipped to fingerprint the host, access the file system, and run arbitrary code sent by the attacker. MicrosoftSystem64 has been previously delivered through js-logger-pack and terminal-logger-utils packages, and is a stealer and implant linked to North Korea.
OpenAI Credential Phishing
A fraudulent subscription invoice email campaign is targeting users with an aim to steal their account credentials using fake login pages, luring them to take action within 48 hours to avoid service interruption. "While AI chatbots are extremely helpful tools in performing repetitive tasks, users need to be aware that, like with all account creation, the threat of credential theft is still persistent," Cofense said . "Whether it is a traditional phishing attack similar to the one described in this article or the use of smishing/vishing, attackers are constantly finding unique pathways through security systems and secure email gateways (SEGs)." In another phishing campaign, payment plan-themed emails are being used to initiate a multi-stage attack chain that leads to the deployment of the Global Group ransomware. "Global Group is a rebranding of the legacy Black Lock and Mamona ransomware families by inheriting an established backend infrastructure, reusing core code artifacts, and launching an immediately scalable extortion enterprise," Cofense said . "They partner heavily with Initial Access Brokers (IABs) to purchase pre-compromised corporate credentials, allowing their affiliates to bypass perimeter defenses. Global Ransomware utilizes double extortion and threats of public data leaks as part of their aggressive negotiation tactics."
DarkMe Returns via Social Engineering
Huntress said it has spotted the DarkMe malware in two separate incidents affecting different organizations on August 31, 2026. DarkMe is a Visual Basic trojan linked to a threat actor known as Water Hydra (aka DarkCasino). "Two years ago, DarkMe developed a reputation by leveraging two separate zero days to deliver its malware: WinRAR ( CVE-2023-38831 ) and Windows Defender SmartScreen ( CVE-2024-21412 )," Huntress said . "But in these new incidents, the malware didn't leverage exploits, relying on social engineering to convince
首次收录 · 2026-09-25 · 9.74 分