Triaging the Week 096

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Logitech Confirms Data Breach Following Clop Extortion Attack

Hardware giant Logitech has officially confirmed a data breach after the Clop extortion gang claimed responsibility and leaked nearly 1.8 TB of stolen data. The incident is linked to a third-party zero-day vulnerability, believed to be in the Oracle E-Business Suite, which has recently targeted multiple major organizations.

Key takeaways:

📂 Data Exposure: The breach exposed limited information about employees, consumers, customers, and suppliers, though Logitech states no national IDs or credit card details were compromised.

🔓 Zero-Day Exploit: The attack vector was a vulnerability in a third-party software vendor (likely Oracle), which the company has since patched.

🏭 Operations Safe: Logitech confirmed that the incident has not impacted its products, manufacturing, or core business operations.

🏴‍☠️ Extortion Tactics: The Clop gang, known for massive data theft campaigns like MOVEit and Accellion, added Logitech to its leak site as part of a broader extortion wave affecting entities like Harvard and The Washington Post.

🛡️ Response: Logitech filed an 8-K form with the SEC and is working with external cyber security firms to investigate and contain the situation.

BleepingComputer

Anthropic Reports Automated AI Cyberattacks: Groundbreaking Threat or Marketing Hype?

Anthropic claims to have uncovered a Chinese state-sponsored campaign that utilized its Claude AI model to automate 80-90% of a cyber-espionage operation against major tech and government targets. However, the cyber security community has reacted with significant skepticism, questioning the validity of these claims due to a lack of technical evidence.

Key takeaways:

🤖 Autonomous Hacking Claims: Anthropic alleges that threat group GTG-1002 used “agentic AI” to autonomously discover vulnerabilities, exploit them, and perform post-exploitation tasks with minimal human intervention.

🤨 Expert Skepticism: Prominent security researchers are labeling the report “marketing guff” and “made up,” citing the complete absence of Indicators of Compromise (IOCs) or technical evidence to support the claims.

🎯 High-Value Targets: The alleged campaign targeted 30 organizations, including financial institutions and government agencies, using an infrastructure that allowed the AI to conduct parallel attacks.

🛠️ Living off the Land: The report states the AI leveraged standard open-source penetration testing tools rather than bespoke malware, orchestrated through a Model Context Protocol (MCP) framework.

📉 AI Limitations: Despite the high level of automation claimed, Anthropic admits the AI still suffers from hallucinations and requires human operators to authorize critical escalations and data exfiltration.

Anthropic

North Korean Hackers Abuse JSON Services for Stealthy Malware Delivery

North Korean threat actors behind the “Contagious Interview” campaign have evolved their tactics, now leveraging legitimate JSON storage services, such as JSON Keeper and npoint.io, to conceal and deliver malicious payloads. By embedding obfuscated URLs within fake “API keys” in trojanized code projects, they effectively bypass traditional detection methods to target developers.

Key takeaways:

🕵️‍♂️ New Delivery Vector: Hackers are using services like JSON Keeper, JSONsilo, and npoint.io to host obfuscated malware payloads, blending in with normal traffic.

💼 Job Interview Lure: The campaign targets developers on LinkedIn with fake job offers or collaboration requests, tricking them into downloading compromised projects from GitHub or GitLab.

🦠 BeaverTail & InvisibleFerret: The attacks deploy the “BeaverTail” JavaScript malware to harvest data, followed by the “InvisibleFerret” Python backdoor for persistent access.

🧩 TsunamiKit Payload: Recent updates include fetching “TsunamiKit,” a toolkit for system fingerprinting and further payload retrieval, adding a new layer of sophistication.

⚠️ Developer Alert: Users should scrutinize “demo projects” for hidden configuration files (like .config.env) containing suspicious Base64-encoded strings acting as fake API keys.

🎯 Threat Hunting Package

NVISO Labs

Malicious NPM Packages Abuse Adspect Redirects to Evade Security

Malicious packages on the npm registry are utilizing Adspect’s cloaking technology to evade detection, redirecting researchers to benign pages while sending legitimate users to cryptocurrency scams. Discovered by Socket, this campaign highlights sophisticated supply chain attacks that fingerprint visitors to deliver targeted malicious payloads.

Key takeaways:

🕵️‍♂️ Cloaking Mechanism: Attackers use Adspect to fingerprint visitors; researchers see a fake “Offlido” company page, while real victims are routed to dangerous cryptocurrency scam sites.

📦 Malicious Packages: Seven packages (e.g., application-phskck, integrator-filescrypt2025) were published by the user ‘dino_reborn’ to execute these redirection attacks effectively.

🛠️ Anti-Analysis Tactics: The injected code actively blocks debugging tools—such as right-click, F12, and Developer Tools—to hinder security teams from inspecting the malicious behavior.

🚨 Automatic Execution: The malicious code runs automatically via Immediately Invoked Function Expressions (IIFE) as soon as the compromised web application loads, requiring no specific user interaction.

🔒 Supply Chain Risk: This incident underscores the critical need for vetting third-party dependencies, as “smart” redirection allows malware to hide in plain sight from automated scanners.

Socket

Dutch Police Seize 250 Servers in Major Blow to Bulletproof Hosting

The Dutch police have dismantled a significant portion of a “bulletproof” hosting service, confiscating around 250 physical servers and taking thousands of virtual servers offline. This operation targeted a service that has facilitated a range of cybercrimes since 2022, including ransomware, phishing, and botnets, by providing criminals with complete anonymity.

Key takeaways:

🕵️‍♂️ Massive Infrastructure Takedown: Law enforcement seized ~250 physical servers from data centers in The Hague and Zoetermeer, disrupting thousands of virtual servers used for illicit activities. 

🚫 Anonymity Removed: The targeted service was known for ignoring abuse reports and enforcing no-KYC (Know Your Customer) policies, making it a haven for cybercriminals.

 📉 Potential Link to CrazyRDP: While officially unnamed, sources suggest the service may be CrazyRDP, a known provider for threat actors, which went offline concurrently with the police operation. 

🔬 Forensic Analysis Underway: Investigators are now analyzing the seized data to identify operators and clients, potentially leading to further breakthroughs in over 80 connected cybercrime investigations. 

🌍 Global Impact: The service was used internationally for activities ranging from malware distribution to money laundering, highlighting the global reach of this takedown.

Politie

New EVALUSION ClickFix Campaign Deploys Amatera Stealer and NetSupport RAT

A sophisticated new phishing campaign dubbed “EVALUSION” is utilizing the ClickFix social engineering tactic to trick users into executing malicious commands, ultimately deploying Amatera Stealer and NetSupport RAT. This attack, tracked by eSentire, leverages fake reCAPTCHA verification pages to compromise systems and steal sensitive data.

Key takeaways:

🕵️‍♂️ ClickFix Tactic: Victims are lured to fake pages mimicking reCAPTCHA verification (often mimicking Cloudflare or Booking.com) and tricked into running malicious commands via the Windows Run dialog. 

🦠 Dual Threat: The campaign delivers Amatera Stealer, a potent malware evolving from ACR Stealer, alongside the well-known NetSupport RAT for remote access. 

🛡️ Evasion Techniques: Amatera uses advanced methods like WoW64 SysCalls to bypass security sandboxes and EDR solutions, making detection difficult. 

⚡ Targeted Infection: The malware checks if the victim’s machine is part of a domain or contains valuable files (like crypto wallets) before downloading the secondary NetSupport RAT payload. 

🧩 Multi-Stage Attack: The infection chain involves “mshta.exe,” PowerShell scripts, and payloads hosted on legitimate services like MediaFire to evade initial blocks.

🎯 Threat Hunting Package

eSentire

Rust Adoption Drives Android Memory Safety Bugs Below 20% for the First Time

Google’s strategic shift to the Rust programming language for Android development has achieved a historic milestone, dropping memory safety vulnerabilities to under 20% of total reported bugs. This transition not only enhances security with a 1000x reduction in vulnerability density compared to C/C++ but also significantly accelerates software delivery.

Key takeaways:

🛡️ Historic Low: Memory safety vulnerabilities in Android have fallen below 20% for the first time, a direct result of integrating Rust into the codebase. 

🚀 Boosted Productivity: Rust code sees a 4x lower rollback rate and requires 25% less time in code review, proving that the safer path is also the faster one. 

📉 Vulnerability Drop: The transition has driven a massive decline in memory safety issues, from 223 in 2019 to fewer than 50 in 2024. 

🌐 Ecosystem Expansion: Google plans to expand Rust usage to the kernel, firmware, and critical apps like Chromium, which has already replaced key parsers with Rust implementations. 

🔐 Defense-in-Depth: While Rust is a game-changer, Google emphasizes a layered defense strategy, citing a recent “near-miss” vulnerability in unsafe Rust that the Scudo memory allocator neutralized.

Google Security Blog

ShadowRay 2.0 Campaign Hijacks AI Clusters for Crypto Mining & Data Theft

A global campaign dubbed “ShadowRay 2.0” is actively exploiting a critical vulnerability in the Ray open-source framework to compromise AI infrastructure. Attackers are utilizing LLM-generated payloads to convert clusters into self-propagating cryptomining botnets and steal sensitive data.

Key takeaways:

⚠️ Unpatched Vulnerability: The attacks exploit CVE-2023-48022, a critical RCE flaw that remains unfixed because the vendor intends the software for use only in “strictly-controlled” trusted environments. 

🤖 AI-Generated Payloads: The threat actor, tracked as “IronErn440,” is deploying sophisticated malware generated by Large Language Models (LLMs) that can self-propagate across nodes. 

📉 Massive Exposure: Researchers report a significant spike in exposure, with over 230,000 Ray servers currently accessible via the public internet. 

🔓 Severe Impact: Beyond mining Monero, the malware is capable of stealing credentials, exfiltrating proprietary AI models, and launching DDoS attacks. 

🛡️ Critical Mitigation: Since no patch exists, administrators must immediately secure clusters using firewall rules, VPNs, and by adding authorization to the Ray Dashboard (default port 8265).

🎯 Threat Hunting Package

Oligo

“Sneaky 2FA” Phishing Kit Upgrades with Browser-in-the-Browser (BitB) Attacks

The “Sneaky 2FA” Phishing-as-a-Service (PhaaS) kit has integrated Browser-in-the-Browser (BitB) technology to create fake login pop-ups that are nearly indistinguishable from legitimate Microsoft authentication windows. This evolution lowers the bar for attackers, allowing them to bypass user scrutiny by simulating trusted URLs in a fake address bar.

Key takeaways:

🎭 BitB Deception: The kit uses HTML and CSS to render a fake browser pop-up complete with a legitimate-looking address bar, tricking users into believing they are on a secure Microsoft login page.

🎯 Microsoft Account Targeting: The campaign specifically targets Microsoft credentials, using a “Sign in with Microsoft” lure often disguised as a document preview to initiate the attack.

🛡️ Advanced Evasion: Attackers employ Cloudflare Turnstile and CAPTCHAs to block security scanners and use conditional loading to ensure only real victims see the phishing page.

📉 PhaaS Evolution: This update highlights the rapid professionalization of the phishing ecosystem, enabling sophisticated techniques like BitB to be accessible to less-skilled threat actors.

🛑 Passkey Risks: The rise of such kits coincides with new threats to passkeys, including downgrade attacks that push users toward phishable login methods rather than secure alternatives.

Push Security

Sysmon Coming Natively to Windows 11 and Server 2025!

Microsoft has announced that its powerful Sysinternals tool, Sysmon (System Monitor), will be integrated natively into Windows 11 and Windows Server 2025 next year. This major update eliminates the need for individual installations and allows admins to manage deployment directly via Windows Update and Optional Features.

Key takeaways:

🛠️ Native Integration: Sysmon will be available as a built-in “Optional feature,” streamlining deployment across large IT environments without needing standalone installers.

📝 Full Functionality: The native version retains all standard capabilities, including custom configuration files, advanced event filtering, and logging to Windows Event Logs.

⚡ Simplified Management: Updates will be delivered directly through Windows Update, ensuring easier maintenance and broader coverage for threat hunting.

🔍 Enhanced Detection: Sysmon continues to support monitoring for critical events like process tampering, executable creation, and network connections, crucial for identifying malicious activity.

Microsoft IT Pro Blog

TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign

Hackers are leveraging bogus installers for popular utilities, such as “AppSuite PDF Editor,” to distribute the sophisticated TamperedChef malware via malvertising and SEO poisoning. The malware lies dormant for weeks to evade detection before activating to steal browser credentials and establish remote persistence.

Key takeaways:

🕵️‍♂️ Deceptive Distribution: Attackers use “industrialized” infrastructure to churn out fake installers signed with valid digital certificates from shell companies, distributing them via Google Ads and poisoned search results.

⏳ Strategic Dormancy: TamperedChef often remains dormant for up to 56 days—aligning with ad campaign lifecycles—to bypass sandbox analysis and behavioral monitoring before executing its payload.

🦠 Malicious Payload: Once activated, the malware (also known as BaoLoader) harvests sensitive data, including browser cookies and credentials, and establishes a JavaScript backdoor for long-term access.

🔍 Global Impact: The campaign targets users worldwide, with specific confirmed infections in European organizations, utilizing social engineering to trick victims into accepting fake EULAs.

🛡️ Mitigation Advice: Organizations should enforce strict application allowlisting, monitor for unusual scheduled tasks (like PDFEditorUpdater), and educate users on the risks of downloading software from sponsored search results.

🎯 Threat Hunting Package

Acronis

US, UK, and Australia Sanction Russian “Bulletproof” Host Media Land Over Ransomware Ties

The United States, the United Kingdom, and Australia have jointly sanctioned Russian bulletproof hosting provider Media Land and its executives for facilitating the operations of major ransomware gangs like LockBit and BlackSuit. This coordinated action targets the “bulletproof” infrastructure that allows cybercriminals to ignore law enforcement and attack critical systems with impunity.

Key takeaways:

🚨 Coordinated Crackdown: The US Treasury, UK, and Australia sanctioned Media Land, its sister companies, and key executives for providing essential infrastructure to cybercriminals and refusing to comply with takedown requests.

🦠 Ransomware Enabler: Media Land services were used by notorious ransomware groups, including LockBit, BlackSuit, and Play, to conduct attacks and host illicit content.

🕵️‍♂️ Executives Exposed: Sanctions target executives like Aleksandr Volosovik (alias “Yalishanda”), who is linked to Evil Corp and Black Basta, freezing their assets and exposing associates to secondary sanctions.

🕸️ Evasion Tactics Blocked: The designation includes Aeza Group and its UK-based front company, Hypercore Ltd, highlighting efforts to dismantle networks used to skirt previous penalties.

🛡️ Defense Guidance: Five Eyes agencies released new guidance for ISPs to mitigate risks from bulletproof hosters, recommending “Know Your Customer” (KYC) protocols and traffic filters to block malicious resources.

U.S. Department of the Treasury

PlushDaemon Hackers Hijack Software Updates in Global Supply Chain Attacks

A China-aligned APT group, PlushDaemon, has been caught compromising a South Korean VPN provider and hijacking legitimate software updates via router implants to deploy the “SlowStepper” backdoor for espionage. This sophisticated campaign targets entities across East Asia, the US, and New Zealand, leveraging “EdgeStepper” malware to redirect update traffic to malicious servers.

Key takeaways:

🕵️‍♂️ Supply Chain Compromise: PlushDaemon breached the South Korean VPN provider IPany, replacing legitimate installers with a malicious version that deployed the SlowStepper backdoor alongside the VPN software.

🌐 Router-Based Hijacking: The group uses a Go-based network implant called EdgeStepper to compromise routers, performing Adversary-in-the-Middle (AitM) attacks by redirecting DNS queries for software updates to attacker-controlled nodes.

📉 Legitimate Apps Abused: Attackers hijacked update channels for popular software, including Sogou Pinyin, to deliver malware like LittleDaemon and DaemonicLogistics without raising user suspicion.

🦠 SlowStepper Backdoor: The primary payload is a feature-rich implant with over 30 modules capable of stealing credentials, taking photos, recording audio, and exfiltrating data from messaging apps like WeChat and Telegram.

🌏 Global Espionage: Active since at least 2019, the group has targeted universities, semiconductor firms, and manufacturing companies in South Korea, Taiwan, China, the US, and beyond.

🎯 Threat Hunting Package

ESET Research

New ‘Tsundere’ Botnet Hides in Fake Game Installers & Uses Blockchain for Control

A new, actively expanding botnet dubbed “Tsundere” is targeting Windows users by disguising itself as installers for popular games like Valorant and Counter-Strike 2, while leveraging the Ethereum blockchain to maintain resilient command-and-control (C2) communication.

Key takeaways:

👾 Gaming Lures: Attackers are using filenames related to popular titles—such as “Valorant,” “r6x” (Rainbow Six Siege), and “cs2″—likely targeting users searching for pirated or cracked versions of these games.

🔗 Blockchain C2: Uniquely, the botnet uses Ethereum smart contracts to dynamically fetch its C2 server addresses, making the infrastructure highly resistant to takedowns and easy for attackers to rotate.

🛠️ Living off the Land: The malware deploys legitimate libraries (like pm2, ethers, and ws) and has even been observed leveraging legitimate Remote Monitoring and Management (RMM) tools to download payloads, blending in with normal system activity.

🇷🇺 Suspected Origins: Analysis of the source code reveals Russian language artifacts, and related malware tools specifically forbid targeting Russia and CIS countries, suggesting a Russian-speaking threat actor.

💻 Flexible Payload: The bot is designed to execute arbitrary JavaScript code, allowing it to adapt quickly for various malicious tasks, from proxying traffic to launching DDoS attacks.

🎯 Threat Hunting Package

Kaspersky

New ‘Sturnus’ Android Trojan Bypasses Encryption to Spy on Private Chats

A newly discovered Android banking trojan dubbed “Sturnus” is quietly compromising devices to steal banking credentials and intercept encrypted communications from apps like WhatsApp, Telegram, and Signal by reading screen content.

Key takeaways:

🔓 Encryption Bypassed: Sturnus exploits Android’s Accessibility Services to capture message content directly from the device screen after decryption, effectively bypassing end-to-end encryption protections on secure messaging apps.

🎮 Full Device Takeover: The malware features advanced remote access capabilities, allowing attackers to perform hands-on actions such as clicks, scrolling, and text input, as well as streaming the screen in real-time.

🛡️ Anti-Removal Tactics: Sturnus actively protects itself by detecting when a user navigates to settings to revoke permissions or uninstall the app, automatically redirecting them away to prevent cleanup.

🎯 Targeted Region: Currently in an evaluation stage, the trojan is specifically targeting financial institutions across Southern and Central Europe with customized overlay attacks.

🎭 Deceptive Disguise: The malware often masquerades as legitimate applications, such as Google Chrome or “Preemix Box,” and can display fake system update screens to hide malicious background activity.

ThreatFabric


Top Tips of the Week

Triaging the Week Tops Tips of the Week

Threat Intelligence

  • Collaborate with CTI teams from different industries. Gain insights into diverse threat landscapes and enhance overall detection capabilities.
  • Incorporate CTI into cyber crisis management plans. Use real-time intelligence to inform crisis response and mitigation efforts.
  • Integrate CTI with threat modeling. Identify potential threats early in the development process for stronger security postures.
  • Regularly review and update threat intelligence policies. Adapt to evolving threats and ensure alignment with organizational goals.

Threat Hunting

  • Stay informed on threat intelligence trends. Knowledge of emerging techniques empowers more effective threat detection.

Custom Tooling

  • Stay informed about emerging technologies. Leverage new tools and frameworks to enhance the capabilities of your custom solutions.
  • Collaborate with threat hunting teams for custom tool development. Enhance tools with capabilities that align with proactive threat detection strategies.

Feature Video

Is your CTI team hunting ghosts or fighting active measures? 👻

We’ve become incredibly adept at defending our networks and endpoints, but we often fail to protect the most vulnerable unpatched processor of all: the human brain. 

“Fake News” is a lazy term; to stay relevant, analysts need to master the three pillars of Information Disorder. Here is the framework you need to know:

📉 Misinformation (The Noise): This is false information shared without malicious intent, like an admin misreading a log file. It creates a “fog of war,” clogs intelligence feeds, and leads to massive analyst burnout.

🎯 Disinformation (The Weapon): This is a lie with a budget and a project manager. It’s an offensive capability designed to target cognitive biases, often using “false flag” operations to trick you into attributing attacks to the wrong adversary.

💣 Malinformation (The Betrayal): The hardest to spot because it uses truth as a weapon. Through tactics like “Hack and Leak” operations, attackers curate real data—stripping away context—to craft a damaging narrative that looks legitimate.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools