Triaging the Week 092

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Europol Dismantles Massive “SIMCARTEL” Cybercrime Ring

In an operation codenamed “SIMCARTEL,” Europol has shut down a massive illegal SIM box service that rented out phone numbers for large-scale fraud. The service, which operated 1,200 SIM box devices with 40,000 SIM cards, facilitated at least 3,200 fraud cases, resulting in over €4.5 million in losses.

Key takeaways:

🔒 Cybercrime-as-a-Service: The operation rented phone numbers from 80+ countries, allowing criminals to create over 49 million fraudulent online accounts for phishing, investment scams, and impersonation. 

🛡️ Infrastructure Seized: Authorities, in a joint effort with the Shadowserver Foundation, seized two main websites (gogetsms.com and apisim.com), along with servers, crypto, and cash. 

💡 Arrests Made: The operation led to the arrest of five Latvian nationals and two other suspects. 

🌐 Disrupting the Ecosystem: This takedown is a significant blow to the infrastructure that supports anonymous cybercrime, from simple scams to complex fraud.

Europol

TikTok “ClickFix” Scam Spreads Infostealers!

A dangerous campaign is running rampant on TikTok, using videos that promise free activation for popular software like Windows, Spotify, and Adobe. These videos use a “ClickFix” social engineering tactic, tricking users into running a single malicious PowerShell command to install the “Aura Stealer” malware.

Key takeaways:

🔒 Fake “Fix”: The attack uses TikTok videos that provide a short, malicious PowerShell command disguised as a software activation “fix.” 

🛡️ Malware Payload: Running the command installs “Aura Stealer,” a potent malware designed to steal browser credentials, cookies, and cryptocurrency wallets. 

💡 Social Engineering: This “ClickFix” method relies on tricking the user into compromising their own system by running code from an untrusted source. 

🌐 Warning: Never copy and run commands from untrusted sources (like social media videos) in your terminal or PowerShell!

BleepingComputer

A new malvertising campaign is targeting macOS developers and other users, using Google Ads to promote fake websites for popular tools like Homebrew, LogMeIn, and TradingView. These sites use “ClickFix” social engineering tactics to deliver potent infostealing malware.

Key takeaways:

🔒 Malvertising Campaign: The attackers are using paid Google Ads to ensure their malicious sites appear at the top of search results, luring in unsuspecting users. 

🛡️ “ClickFix” Tactic: The fake sites trick users into copying and pasting a malicious curl command into their Terminal, often disguised as an installation step or a “security confirmation.” 

💡 Potent Infostealers: The attack installs the AMOS (Atomic macOS Stealer) or Odyssey malware, which are designed to steal a wide range of sensitive data. 

🌐 Data at Risk: The malware exfiltrates browser credentials, cookies, cryptocurrency wallet data, and sensitive files from the macOS Keychain.

🎯 Threat Hunting Package

Hunt.io

“GlassWorm” Malware Spreading Through VS Code & OpenVSX!

A new, sophisticated self-spreading malware called “GlassWorm” is targeting developers through the VS Code and OpenVSX marketplaces. This worm-like supply-chain attack has already resulted in over 35,800 installations, using invisible Unicode characters to hide its malicious code and automatically spreading to other extensions by stealing developer credentials.

Key takeaways:

🔒 Self-Spreading: The worm steals GitHub, npm, and OpenVSX credentials to infect other extensions published by the victim. 

🛡️ Stealthy Attack: Malicious code is hidden using “invisible Unicode characters” to evade detection. 

💡 Auto-Update Risk: The automatic update feature in VS Code silently infected all users of a compromised extension without any warning. 

🌐 Resilient C2: The malware uses the Solana blockchain for its command-and-control, making it extremely difficult to take down.

🎯 Threat Hunting Package 

Koi Security

Warning: 131 Malicious Chrome Extensions Hijack WhatsApp Web!

A massive spam campaign has been uncovered, involving 131 cloned Chrome extensions that hijack WhatsApp Web to send bulk spam messages, bypassing the platform’s anti-spam controls. These extensions, with over 20,000 active users, are deceptively marketed as CRM and sales tools for WhatsApp.

Key takeaways:

🔒 Spam-as-a-Service: The campaign operates on a “white-label” franchise model, allowing affiliates to rebrand and distribute the same malicious extension. 

🛡️ Bypassing Security: The extensions inject code directly into WhatsApp Web to automate bulk messaging and evade detection. 

💡 Deceptive Marketing: The tools are advertised as legitimate CRM solutions to trick users, primarily in Brazil, into installing them. 

🌐 Chrome Web Store Abuse: The operation violates Google’s policies by flooding the store with duplicate, malicious add-ons.

Socket

TP-Link has released urgent security updates to fix four vulnerabilities in its Omada gateway devices. These include two critical flaws that allow for remote code execution, with one being exploitable by an unauthenticated attacker.

Key takeaways:

🔒 Two Critical Flaws: The vulnerabilities include CVE-2025-6542, a critical (9.3 CVSS) flaw allowing unauthenticated remote command injection. 

🛡️ Multiple Models Affected: A wide range of Omada gateway models are impacted by these issues, including the ER8411, ER707-M2, ER7206, and ER605. 

💡 No Active Exploits (Yet):Ind: TP-Link has not seen evidence of these flaws being actively exploited in the wild. 

🌐 Patch Immediately: All users are strongly urged to download and apply the latest firmware updates to protect their networks from potential takeover.

The Hacker News

1.8M Developers at Risk from 94+ Vulnerabilities in Cursor and Windsurf IDEs

Security researchers found that Cursor and Windsurf IDEs are built on outdated components, exposing users to over 94 known and patched Chromium vulnerabilities. This flaw allows for potential code execution and supply chain attacks. An estimated 1.8 million developers are exposed.

Key takeaways:

🚨 Massive Exposure: 1.8 million developers using Cursor and Windsurf are vulnerable to 94+ known CVEs.

🛡️ Root Cause: The IDEs use outdated versions of VS Code and Electron, which embed vulnerable Chromium and V8 engines.

💥 Demonstrated Exploit: Researchers successfully weaponized a single patched flaw (CVE-2025-7656) to crash the IDE, proving the risk is not just theoretical.

🔒 Severe Impact: A compromised IDE can lead to arbitrary code execution, theft of source code and credentials, and injection of malicious code into your projects.

🌐 Attack Vectors: Risks include malicious extensions, poisoned README files, or even injecting exploit code into documentation.

0x Security

Chinese Gangs Net $1B in U.S. Text Scams!

A new report reveals that organized Chinese crime syndicates have stolen over $1 billion from Americans using an “industrialized text scam ecosystem.” The operation floods users with messages about fake tolls, postage fees, and refunds.

Key takeaways:

🔒 Industrial-Scale Fraud: This is a highly organized, massive operation using U.S.-based SIM farms to send texts in bulk. 

💸 Sophisticated Laundering: The goal is to steal credit card data. This data is then added to mobile wallets (Apple/Google Pay) in Asia and given to a network of money mules in the U.S. 

💳 Mule Network: These mules (400-500 daily) use the stolen card details to buy gift cards and other goods, which are then shipped to China. 

📱 Action: Be extremely wary of any unexpected text demanding a small payment. Never click the links or provide financial details.

Malarebytes Labs

Meta Deploys New Scam Protection for WhatsApp & Messenger

Meta is rolling out new security tools to combat the rise of sophisticated “pig butchering” and other scams. The updates target Messenger and WhatsApp, adding on-device scam detection and critical warnings for screen sharing.

Key takeaways:

🚨 WhatsApp Alert: You will now receive a warning before screen sharing with an unknown contact. This is a critical defense to prevent attackers from stealing your bank details or security codes.

🛡️ Messenger AI: A new on-device “Scam detection” feature in Messenger’s settings will alert you to suspicious messages from new contacts without breaking end-to-end encryption.

💡 User Action: If you receive an alert, you can immediately block/report the account. The tool also educates you on common scams, like fake job offers or investment fraud.

🌐 The Threat: These features directly target the tactics used in devastating “pig butchering” (romance/investment) scams, which have caused massive financial losses.

🔒 Stay Vigilant: Always be suspicious of unknown contacts asking for information, money, or asking you to share your screen.

Meta

Iranian APT Groups Deploy New Stealth Backdoors in Widespread Campaign

A sophisticated, multi-wave campaign linked to Iranian state-sponsored actors has been observed targeting over 100 government, diplomatic, and critical infrastructure organizations globally. These attacks utilize newly developed, stealthy backdoors to achieve persistent access for espionage and data exfiltration.

Key takeaways:

🛡️ Massive Scope: The operation is extensive, targeting more than 100 government and diplomatic email accounts across the Middle East, Europe, Africa, and the Americas.

🦠 New Malware: Attackers are deploying new, sophisticated backdoors (such as BugSleep and Whisper) designed to evade detection by remaining dormant or using legitimate services (like webmail) for command and control.

🎯 Targeted Espionage: The primary motive is cyber-espionage, focusing on stealing sensitive data from government, defense, and telecommunication sectors.

🎣 Attack Vector: The main point of entry is spear-phishing, using carefully crafted emails that exploit geopolitical themes to lure victims into enabling malicious macros or clicking links.

🔒 Action Required: Organizations must enhance email security protocols, train employees to spot advanced phishing, and hunt for new, unusual persistence mechanisms within their networks.

🎯 Threat Hunting Package

Group-IB

“ToolShell” Zero-Day Actively Exploiting On-Prem SharePoint Servers Globally

A widespread attack campaign is exploiting a critical zero-day vulnerability chain (dubbed “ToolShell”) in on-prem Microsoft SharePoint. Attackers are gaining unauthenticated remote code execution to steal cryptographic keys, deploy ransomware, and maintain persistent access.

Key takeaways:

🌐 Global Campaign: The attack targets government, defense, and critical infrastructure organizations across at least four continents.

🛡️ Stealthy Persistence: Attackers are stealing ASP.NET machine keys. This allows them to forge credentials and maintain access even after servers have been patched.

🦠 Payloads: Active post-exploitation includes data exfiltration, webshells (spinstall0.aspx), and the deployment of ransomware.

🔒 Action: Patching Is Not Enough: Admins MUST apply the latest Microsoft updates, immediately rotate all SharePoint ASP.NET machine keys, and then restart IIS to fully remediate.

💡 Hunt for Compromise: Immediately scan for IoCs, including suspicious POST requests to ToolPane.aspx and newly created .aspx files in server directories.

🎯 Threat Hunting Package

Symantec

A high-severity logic bug (CVE-2025-62518) in the widely used tokio-tar Rust library allows for Remote Code Execution via file overwriting. Dubbed “TARmageddon,” this vulnerability exposes the massive supply chain risk posed by popular, unmaintained “abandonware” projects.

Key takeaways:

🚨 Vulnerability: “TARmageddon” is a critical parsing flaw in tokio-tar (5M+ downloads), allowing attackers to smuggle malicious files inside TAR archives, leading to RCE.

🛡️ Impact: Major projects like the uv Python package manager are affected, enabling build hijacks, container poisoning, and security scanner (BOM) bypass.

🔒 The “Abandonware” Crisis: The most popular fork, tokio-tar, is unmaintained. This disclosure required a complex, decentralized effort to patch active forks, leaving millions who depend on the main fork vulnerable.

💡 Beyond Memory Safety: This bug is a logic flaw, not a memory safety issue, proving that even in “safe” languages like Rust, critical vulnerabilities can exist.

🌐 Action Required: Immediately audit your dependencies. If you use tokio-tar, you must migrate to a patched, maintained fork like astral-tokio-tar to be secure.

Edera

Microsoft Disables File Explorer Preview to Block NTLM Hash Theft

Microsoft has rolled out a critical security update that disables the File Explorer preview pane for files downloaded from the internet. This change is a deliberate security enhancement, not a bug, designed to block an attack vector that allowed for the theft of NTLM credential hashes with minimal user interaction.

Key takeaways:

🚨 The Flaw: Attackers could craft malicious files (e.g., documents with specific HTML tags) that, when simply selected in File Explorer, would use the preview pane to automatically connect to an attacker-controlled server.

🔒 The Attack: This automatic connection attempt would leak the user’s NTLM authentication hash, which attackers could then capture and use in “pass-the-hash” or relay attacks to impersonate the user and gain unauthorized access.

🛡️ The Fix: The October 2025 security update now blocks previews for any file marked as originating from the internet (i.e., has the “Mark of the Web”). Users will instead see a warning.

💡 User Action: This protection is enabled by default after installing the October 2025 Patch Tuesday updates. Ensure your Windows systems are updated to mitigate this threat.

🌐 Workaround: For trusted files, you can restore the preview by right-clicking the file, selecting ‘Properties,’ and clicking ‘Unblock’ on the ‘General’ tab.

BleepingComputer

North Korean Hackers Targeting Defense Sector with Fake Job Offers

State-sponsored actors from North Korea (Lazarus Group) are actively running a sophisticated cyber-espionage campaign dubbed “Operation Dream Job.” The attacks lure engineers from European defense companies with fake job opportunities to steal proprietary drone technology.

Key takeaways:

🌐 Primary Target: The campaign specifically targets European companies in the defense industry, particularly those involved in the unmanned aerial vehicle (UAV) sector.

🎣 Attack Vector: Hackers use social engineering, approaching targets on platforms like LinkedIn with lucrative but fake job offers to build trust.

🔒 Malware Delivery: Victims are tricked into opening malicious decoy documents, such as trojanized PDF readers, which then deploy advanced malware.

🛡️ The Payload: The attack uses malware families like ‘ScoringMathTea,’ a remote access trojan (RAT) that gives attackers full control to exfiltrate sensitive data and manufacturing know-how.

💡 The Goal: This is a clear case of state-level cyber-espionage, designed to steal critical technology to advance North Korea’s own drone program.

🎯 Threat Hunting Package

ESET Research

Fake AI Sidebars are Tricking Users into Dangerous Actions

A new attack called “AI Sidebar Spoofing” uses malicious browser extensions to create pixel-perfect clones of trusted AI assistants (like those in Comet, Atlas, and other browsers). These fake sidebars intercept your prompts and provide malicious answers, tricking you into visiting phishing sites or running harmful commands.

Key takeaways:

💡 The Attack: Malicious browser extensions create a fake AI sidebar that looks identical to the real, trusted one.

🔒 The Deception: When you ask the fake AI for help (e.g., “how to install an app” or “crypto wallet login”), it provides malicious instructions, such as a command to install a reverse shell or a link to a phishing page.

🌐 The Vector: This “AI Sidebar Spoofing” attack exploits the high level of trust users place in AI assistants, bypassing normal suspicion.

🛡️ How to Stay Safe: Be extremely cautious about installing browser extensions and the permissions they request. Always verify commands or links from an AI, especially if they involve sensitive information, logins, or running code.

SquareX


Top Tips of the Week

Triaging the Week Tops Tips of the Week

Threat Intelligence

  • Foster cross-industry CTI collaboration. Learn from other sectors to strengthen overall threat intelligence capabilities.
  • Integrate threat intelligence into risk management. Enhance resilience by identifying and mitigating potential risks.
  • Understand threat actors’ motives and objectives. Knowing the ‘why’ enhances your ability to predict and counter their actions.

Threat Hunting

  • Trust your instincts in cyber threat hunting. Intuition is a valuable tool; investigate anything that feels off.

Custom Tooling

  • Test custom tools in controlled environments before deployment. Identify and address issues before they impact production.
  • Integrate custom tools with existing systems. Seamless integration enhances workflow efficiency and data sharing.
  • Collaborate with internal teams for custom tool development. Leverage diverse expertise to create solutions that address specific challenges.

Feature Video

Tired of jumping between 10 tabs and static Word docs during an incident? 😴 

What if your security playbooks were “living” documents that could actually execute code?

Jupyter Notebooks aren’t just for data scientists; they are a total game-changer for security operations. This video breaks down how to use them as your new “single pane of glass.”

Here’s what you’ll learn:

💻 What they are: Jupyter Notebooks combine rich markdown (your playbook) with live Python code (your tools) in one interactive document.

🤖 How to use them: Automate your IR process! Pull data from your SIEM/EDR, enrich IOCs via APIs (like VirusTotal), and visualize results all in one place.

🤝 Why they rock: Create shareable, interactive tools for your whole team, perfectly blending documentation with execution.

🚀 A head start: We check out the “Juniverse” project, a massive library of pre-built cybersecurity notebooks you can use right now.

How could “living playbooks” change your team’s incident response workflow? 

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools