Triaging the Week 087

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top 10 News Stories

Triaging the Week News Stories

“Whitecobra” Floods VSCode Market with Crypto-Stealing Malware

A threat actor known as “Whitecobra” is conducting a large-scale campaign, flooding the Visual Studio Code and Open VSX marketplaces with malicious extensions designed to steal cryptocurrency. These deceptive extensions mimic legitimate tools to trick developers into installing them, posing a significant supply chain risk.

Key takeaways:

🔒 Deceptive Tactics: The extensions use professional-looking icons, detailed descriptions, and inflated download counts to appear legitimate, tricking developers into trusting and installing them.

💻 Multi-Platform Attack: The campaign targets multiple code editors, including VSCode, Cursor, and Windsurf, using a cross-platform VSIX extension format to maximize its reach.

🛡️ Sophisticated Malware Delivery: The malicious extensions use a multi-stage process, initially appearing harmless but later downloading platform-specific malware like LummaStealer to steal credentials and crypto wallet data.

💡 Organized Operation: Leaked internal documents from Whitecobra reveal a highly organized operation with clear revenue targets and detailed plans for infrastructure and social engineering.

🎯  Threat Hunting Package

Koi

New “VoidProxy” Phishing Service Targets Microsoft 365 & Google Accounts

A sophisticated Phishing-as-a-Service (PhaaS) platform named “VoidProxy” is enabling attackers to bypass multi-factor authentication and compromise Microsoft 365 and Google accounts. This service uses adversary-in-the-middle (AitM) techniques to steal credentials, MFA codes, and session cookies in real-time, posing a significant threat to organizations.

Key takeaways:

🔒 Advanced Phishing Kits: VoidProxy provides attackers with scalable and evasive tools to create convincing replicas of login pages, including those for SSO providers like Okta.

🌐 Real-time Data Theft: The service intercepts and captures sensitive user data as it’s transmitted, allowing attackers to hijack accounts and bypass security measures.

🛡️ Cloudflare Protection: The phishing sites are shielded by Cloudflare, making it difficult to identify and block their malicious infrastructure.

💡 Phishing-Resistant MFA is Key: The most effective defense against this type of attack is to implement phishing-resistant authentication methods, such as FIDO2 security keys or Okta FastPass.

Okta

Chinese-Speaking Users Targeted in Malware Campaigns

Two sophisticated malware campaigns are exploiting SEO poisoning to distribute a variety of Remote Access Trojans (RATs), including HiddenGh0st, Winos, and the newly discovered kkRAT. These campaigns target Chinese-speaking users by creating fake websites for popular software to trick them into downloading malicious installers.

Key takeaways:

🔒 SEO Poisoning: Attackers are manipulating search engine results to lead users to malicious websites that look like legitimate software download pages.

💻 Multi-Stage Attacks: The attacks use a complex, multi-stage infection process to deliver the malware and evade detection.

🛡️ Antivirus Evasion: The malware is designed to disable several popular antivirus products to remain undetected.

💰 Cryptocurrency Theft: A primary goal of these attacks is to steal cryptocurrency by hijacking digital wallets and manipulating clipboard data.

🌐 New Malware: The discovery of the kkRAT highlights the constantly evolving threat landscape and the need for continuous vigilance.

🎯  Threat Hunting Package

Fortinet

Self-Propagating Supply Chain Attack Hits 187 NPM Packages

A worm-like, self-propagating supply chain attack has compromised at least 187 npm packages, including some published by cybersecurity firm CrowdStrike. The attack, which began with the popular @ctrl/tinycolor package, abuses a legitimate secret-scanning tool to steal credentials and other sensitive information.

Key takeaways:

🔒 Automated Spread: The malware automatically infects other packages maintained by the same developer, leading to rapid and widespread compromise.

🛡️ Legitimate Tools Abused: The attackers are using a legitimate tool called TruffleHog to scan for and exfiltrate sensitive data like API keys and passwords.

💡 Data Exfiltration: Stolen credentials are being sent to a hardcoded webhook endpoint, and the malware can create unauthorized GitHub Actions workflows.

🌐 High-Profile Victims: The attack has impacted packages from well-known sources, including CrowdStrike, highlighting the vulnerability of the open-source ecosystem.

StepSecurity

New ‘FileFix’ Phishing Attack Delivers StealC Malware

A sophisticated phishing campaign is using a novel “FileFix” tactic to trick users into downloading the StealC information-stealing malware. The attack uses a convincing, multilingual fake Facebook Security page to lure victims into executing malicious code.

Key takeaways:

🔒 Deceptive Social Engineering: The “FileFix” method tricks users into pasting a malicious command into their File Explorer address bar, a clever evolution of the “ClickFix” tactic.

🛡️ Convincing Phishing Site: The attack leverages a highly realistic, multilingual phishing page that creates a false sense of urgency by threatening account suspension.

💡 Multi-Stage Payload: The malware is delivered in stages, starting with a PowerShell script that downloads seemingly harmless images containing the malicious code.

🌐 Evasive Maneuvers: Attackers are using legitimate services like Bitbucket to host malware and employ advanced obfuscation techniques to evade detection.

🎯  Threat Hunting Package

Acronis

RaccoonO365 Phishing Network Shut Down

Microsoft and Cloudflare have dismantled a major phishing-as-a-service (PhaaS) network called RaccoonO365, which provided cybercriminals with a toolkit to steal Microsoft 365 credentials. The operation, linked to a Nigerian threat actor, underscores the increasing availability of sophisticated cybercrime tools.

Key takeaways:

🔒 Phishing-as-a-Service: RaccoonO365 offered a subscription-based service, making it easy for less-skilled actors to launch large-scale phishing campaigns.

🛡️ Infrastructure Takedown: A proactive approach to disrupting the entire network, rather than just individual domains, is a more effective strategy against such operations.

💡 AI-Powered Attacks: The service even included an AI-powered component to enhance the effectiveness of phishing emails, demonstrating the evolving nature of cyber threats.

🌐 Global Impact: The network targeted thousands of organizations worldwide, stealing over 5,000 Microsoft 365 credentials in just a few months.

Microsoft

Google Play Store Purges 224 Apps in Massive Ad Fraud Bust

Google has removed 224 malicious Android apps from the Play Store after uncovering a massive ad fraud campaign dubbed “SlopAds.” The operation, which generated billions of fraudulent ad requests daily, highlights the ongoing battle against sophisticated cybercrime on mobile platforms.

Key takeaways:

🔒 Widespread Deception: The 224 apps, downloaded over 38 million times, used steganography and other advanced techniques to hide their malicious ad-clicking behavior.

🛡️ Massive Scale: The SlopAds campaign was responsible for an astounding 2.3 billion ad requests per day, with the U.S. being the most targeted nation.

💡 Hidden in Plain Sight: The malware, named “FatModule,” was cleverly hidden within PNG images and would only activate when the app was installed through one of the attacker’s ad campaigns.

🌐 Proactive Defense: Google Play Protect will now alert users to the presence of these malicious apps and prompt for their removal, demonstrating a commitment to user security.

🎯  Threat Hunting Package

HUMAN

ShinyHunters Claims 1.5 Billion Salesforce Records Stolen in Drift Hack

The notorious extortion group ShinyHunters is claiming responsibility for a massive data breach, alleging the theft of 1.5 billion Salesforce records from 760 companies. The attackers reportedly gained access by exploiting compromised OAuth tokens from Salesloft Drift, a popular sales engagement platform.

Key takeaways:

🔒 Third-Party Risk: The breach originated from a compromised third-party application, highlighting the critical need to vet and secure all integrated services.

🛡️ Credential Theft: The attackers targeted Salesloft’s GitHub repository, scanning for and stealing OAuth tokens that provided access to their victims’ Salesforce instances.

💡 Sensitive Data Exposed: The stolen data includes sensitive customer information from “Account,” “Contact,” “Case,” “Opportunity,” and “User” tables.

🌐 Widespread Impact: The list of affected companies includes major tech players like Google, Cloudflare, Zscaler, and Palo Alto Networks.

BleepingComputer

Scattered Spider Resurfaces with Attacks on the Financial Sector

The notorious cybercrime group, Scattered Spider, has resurfaced, targeting the financial sector despite previous claims of retirement. This development serves as a stark reminder that cyber threats are persistent and adaptable.

Key takeaways:

🔒 Social Engineering: The group’s latest attack on a U.S. bank began with social engineering to gain initial access, emphasizing the continued importance of employee security awareness.

🛡️ Privilege Escalation: Once inside, the attackers escalated their privileges and attempted to exfiltrate data from various cloud repositories, highlighting the need for robust internal security controls.

💡 Deceptive Tactics: The “retirement” of cybercrime groups is often a strategic move to evade law enforcement and regroup. Organizations should not lower their guard based on such announcements.

🌐 Interconnected Threats: Scattered Spider is part of a larger network of cybercrime groups, making attribution and tracking a complex challenge for security professionals.

ReliaQuest

SystemBC Malware Hijacks VPS Systems for Malicious Proxies

The SystemBC proxy botnet is actively compromising vulnerable commercial virtual private servers (VPS) and turning them into a massive network for routing malicious traffic. This botnet, which maintains an average of 1,500 active bots daily, is being used to fuel other criminal proxy services and facilitate attacks like brute-forcing WordPress credentials.

Key takeaways:

🔒 Vulnerable Servers Targeted: The attackers are specifically targeting commercial VPS systems with unpatched vulnerabilities, with infected servers having an average of 20 unpatched security issues.

🛡️ High-Volume Traffic: The compromised servers are being used to generate a high volume of malicious traffic, with one observed IP address generating over 16 gigabytes of proxy data in a single day.

💡 Long-Term Infections: A significant number of compromised systems (nearly 40%) remain infected for over a month, indicating a lack of detection and remediation.

🌐 Powering Other Criminal Services: The SystemBC network is being used to power other criminal proxy services, including REM Proxy and VN5Socks, expanding the reach and impact of their malicious activities.

🎯  Threat hunting package

Black Lotus Labs


Top Tips of the Week

Triaging the Week Tops Tips of the Week

Threat Intelligence

  • Use CTI to inform threat modeling efforts. Identify potential threats and vulnerabilities during the development phase for proactive security measures.
  • Use CTI in security architecture design. Develop robust architectures that align with threat intelligence for effective defenses.
  • Engage in threat intelligence forums. Participate in discussions to share insights and learn from others in the field.
  • Create a threat intelligence roadmap. Define objectives, processes, and milestones for a strategic and effective intelligence program.

Threat Hunting

  • Implement threat intelligence in your cyber threat hunting workflow. Enhance detection capabilities with real-time threat data.
  • Leverage threat intelligence in cloud security in cyber threat hunting. Adapt your strategies for the unique challenges of cloud environments.
     

Custom Tooling

  • Implement secure update mechanisms for custom tools. Ensure a secure and seamless process for deploying updates and patches.

Feature Video

Ever get an email that feels wrong? Don’t risk clicking that link! In this video, I’ll show you how to safely detonate a real phishing email using the powerful ANY.RUN sandbox.

You’ll learn how to uncover hidden threats, track malicious network connections, and find Indicators of Compromise (IOCs) in just a few minutes. This is a must-have skill for anyone serious about cyber security.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Must Learn Python Tools for Cyber Security

If you write Python scripts for automation, incident response, threat hunting, or analysis, these four tools can radically improve your workflow:

🚀 UV: A lightning-fast alternative to pip. UV installs packages 100x faster and automatically manages virtual environments. No more dependency nightmares.

📊 Streamlit: Instantly turn your Python scripts into interactive dashboards. Perfect for visualizing logs, alerts, or risk scores without touching HTML/JS.

🧪 python-dotenv: Keep your API keys and secrets out of your codebase. Just two lines to load .env files securely — essential for all your SOC automation.

🎨 Rich & Textual: Create beautifully styled terminal UIs. Think live dashboards, CPU monitors, or colorful CLI tools — all from your console.

Even if you’re not a developer full-time, these tools can help you move faster, stay secure, and build solutions that scale.

Check out the video below to learn more about these excellent Python tools and start building faster, cleaner, and more secure code right now!

Going Phishing With Evilginx

If you’re serious about simulating real-world phishing attacks, this breakdown is gold! It’s a deep dive on building a complete phishing infrastructure using Evilginx2 — the exact framework used in red team engagements to bypass MFA and capture session tokens.

Here’s what stood out:

🛠️ End-to-end setup: From domain registration (think: azureportal.cam) to DNS records and Azure VM config.

🎣 Evilginx2 in action: Reverse proxy phishing that intercepts creds + MFA tokens in real time.

🔒 Defensive value: Understand how attackers operate so you can design better detections, controls, and user training.

If you’re on the blue team or the red team, watching how MFA can be sidestepped through legitimate-looking phishing lures is a must. Let’s sharpen our skills and stay one step ahead!