Hello there 👋
Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!
Top News Stories

Scammers Abuse PayPal Subscriptions to Send “Real” Fake Emails
Attackers are exploiting PayPal’s legitimate subscription system to send phishing emails that originate from official PayPal addresses, allowing them to bypass spam filters and deliver convincing fake purchase alerts. This sophisticated campaign tricks users into believing they have been charged for expensive items, urging them to call a fraudulent support number to resolve the issue.
Key takeaways:
🚨 Legitimate Source: The phishing emails are sent directly from [email protected] and pass all standard security checks (SPF/DKIM), making them appear 100% authentic to email providers and users.
📝 Manipulated Fields: Scammers exploit the “Customer Service URL” field to inject fake messages about expensive charges (e.g., a $1,300 Sony device) and include a fraudulent phone number.
📞 Vishing Trap: The primary goal is to panic victims into calling the provided fake support number, where attackers attempt to steal banking information or install malware on the victim’s device.
🛡️ Verify Safely: If you receive an unexpected “automatic payment” email, ignore the phone number listed. Always log in to your PayPal account directly via the app or website to confirm if any actual activity occurred.
Fake GitHub Repos for OSINT & GPT Tools Spreading New PyStoreRAT Malware
A new sophisticated campaign is flooding GitHub with repositories disguised as OSINT utilities, DeFi bots, and GPT wrappers to distribute a dangerous, previously undocumented Remote Access Trojan (RAT) called PyStoreRAT. These malicious tools, often promoted via social media and boosted by fake stars, trick developers and analysts into downloading malware that can steal sensitive data and cryptocurrency.
Key takeaways:
🚨 Deceptive Disguise: Attackers are publishing repositories that appear to be legitimate development tools or security utilities but contain hidden Python or JavaScript loader stubs to initiate infection.
🦠 PyStoreRAT Capabilities: This modular malware executes various payload formats (EXE, DLL, PowerShell) and deploys the Rhadamanthys information stealer to harvest credentials and data.
📈 Social Engineering: The campaign artificially inflates repository metrics (stars and forks) and promotes them on platforms like X and YouTube to gain trust before slipping in malicious code via “maintenance” updates.
🙈 Stealth & Evasion: The malware actively checks for specific antivirus products (like CrowdStrike Falcon) and uses legitimate system processes (mshta.exe) to execute payloads while remaining undetected.
💰 Targeting Crypto: Once installed, the malware scans for cryptocurrency wallet files associated with Ledger Live, Trezor, Exodus, and others to steal assets.
Fake ‘One Battle After Another’ Torrent Hides Malware in Subtitles
Cybercriminals are targeting movie fans with a sophisticated new attack, hiding the Agent Tesla RAT inside subtitle files of a fake torrent for the Leonardo DiCaprio movie “One Battle After Another.”
Key takeaways:
🎬 Deceptive Download: A malicious torrent for the new film includes a shortcut file (CD.lnk) that, when clicked, triggers the infection chain instead of playing the movie.
📝 Hidden Scripts: The attack cleverly conceals malicious PowerShell scripts within the text of the subtitle file (.srt), making detection harder for standard security tools.
🚩 Complex Infection: The malware reconstructs itself by extracting encrypted data hidden not just in subtitles, but also in image files included in the torrent folder.
🕵️ Agent Tesla Payload: The final payload is the notorious Agent Tesla Remote Access Trojan (RAT), designed to steal sensitive credentials, capture screenshots, and log keystrokes.
💡 Risk Awareness: This highlights the evolving dangers of pirated content, where attackers use increasingly complex methods like steganography to bypass defenses.
Pornhub Extorted: Premium User History Exposed in Third-Party Breach
The ShinyHunters extortion gang is demanding a ransom from Pornhub after allegedly stealing premium member search and watch history through a breach at analytics vendor Mixpanel. This incident underscores the severe privacy risks posed by third-party supply chain vulnerabilities, even for major platforms.
Key takeaways:
🕵️♂️ Threat Actor: The notorious ShinyHunters gang is claiming responsibility for the extortion attempt.
🔓 Attack Vector: Hackers compromised analytics vendor Mixpanel via an SMS phishing (smishing) attack to gain access.
📉 Data Exposed: The breach reportedly includes the sensitive search and watch history of Premium members.
🔗 Supply Chain Risk: This serves as a critical reminder that your data security is only as strong as your third-party vendors.
🛡️ Privacy Impact: Users face heightened risks of sextortion and privacy invasion due to the sensitive nature of the leaked data.
SantaStealer Malware: He’s Making a List and Stealing Your Data
A new Malware-as-a-Service (MaaS) threat called “SantaStealer” has emerged, designed to siphon sensitive data from browsers, cryptocurrency wallets, and gaming accounts while attempting to evade detection by operating solely in memory.
Key takeaways:
🕵️♂️ Stealth Claims: Advertised as a memory-only threat to bypass antivirus detection, though researchers found early samples were actually quite easy to analyze.
🪙 Broad Targets: The malware uses 14 distinct modules to steal everything from crypto wallet keys and Steam session data to browser cookies and credit card info.
🔓 Chrome Bypass: It includes specific capabilities to bypass Google Chrome’s recent App-Bound Encryption protections.
💸 MaaS Model: The tool is being sold on hacker forums by a likely Russian-speaking developer for subscription fees ranging from $175 to $300 per month.
“Featured” Chrome Extension Caught Stealing AI Chats from Millions of Users
A popular Chrome extension with the “Featured” badge, Urban VPN Proxy, has been caught silently harvesting every prompt and response from users’ interactions with AI chatbots like ChatGPT, Claude, and Gemini. This massive privacy violation affects over 6 million users, with the data being exfiltrated to remote servers for marketing analytics.
Key takeaways:
🕵️♂️ The Culprit: Urban VPN Proxy and affiliated extensions (1ClickVPN, Urban Browser Guard) are behind the data harvesting.
🤖 AI Data Theft: The extensions inject scripts to intercept all chat data, including sensitive personal information shared with AI models.
🏆 False Trust: Despite the malicious behavior, these extensions carry Google’s “Featured” badge, misleading users into trusting them.
📉 Massive Scale: Over 8 million users across Chrome and Edge are estimated to be affected by this campaign.
⚠️ Privacy Loophole: The data collection is enabled by default, often buried in privacy policies that users rarely read.
Google to Shut Down “Dark Web Report” Feature in January 2026
Google is discontinuing its dedicated “dark web report” tool, citing a strategic shift towards providing users with more “clear, actionable steps” for their security. The feature, which alerted users to exposed personal data, will cease monitoring early next year.
Key takeaways:
🗓️ Important Dates: Monitoring for new results stops on January 15, 2026, and all historical data will be inaccessible after February 16, 2026.
📉 Reasoning: Google stated that user feedback indicated the report “did not provide helpful next steps,” prompting a pivot to more effective tools.
🛠️ Alternatives: Users are encouraged to utilize Google Password Manager, Password Checkup, and the “Results about you” tool for ongoing protection.
🔒 Continued Security: While this specific report is ending, Google affirms it will continue to track dark web threats internally to defend user accounts.
New “Cellik” Malware Weaponizes Legitimate Google Play Apps
A new Android malware-as-a-service named “Cellik” is empowering cybercriminals to download legitimate apps directly from the Google Play Store and inject them with malicious code, creating fully functional “clones” that deceive users. This sophisticated tool is currently being sold on underground forums, offering attackers a way to distribute trojanized versions of popular applications that retain their original interface and features.
Key takeaways:
🦠 Trojanized Clones: Cellik’s builder allows attackers to select any app from the official store and create a malicious variant that mimics the real app’s behavior to avoid suspicion.
👁️ Total Surveillance: The malware features robust spyware capabilities, including real-time screen streaming, notification interception, and a hidden browser mode to access websites using the victim’s stored cookies.
🔓 Credential Theft: An advanced injection system allows the malware to overlay fake login screens on top of banking or social apps to harvest user credentials.
🛡️ Evasion Claims: The malware’s developers claim their method of wrapping payloads inside trusted app packages can bypass Google Play Protect detection, though this has not been officially confirmed.
⚠️ Mitigation: Users are urged to avoid sideloading APKs from third-party websites and to strictly stick to the official Google Play Store while keeping Play Protect active.
“GhostPoster” Campaign Hides Malware in Firefox Extension Logos
A new cyber campaign dubbed “GhostPoster” is exploiting steganography to hide malicious JavaScript code inside the PNG logos of popular Firefox extensions, affecting over 50,000 users. Once installed, these extensions deploy a stealthy loader that grants attackers persistent, high-level access to the victim’s browser to commit fraud and tracking.
Key takeaways:
🖼️ Steganographic Attacks: Malicious code is embedded directly into the extension’s logo image, allowing it to bypass initial detection mechanisms.
⏱️ Stealthy Evasion: The malware waits 48 hours before activating and only attempts to fetch its main payload 10% of the time, making it incredibly difficult for security tools to spot.
🛑 Wide Impact: 17 extensions are confirmed to be compromised, including popular tools like “Free VPN Forever,” “Dark Reader for FF,” and various translation and weather apps.
💸 Fraudulent Activity: The payload primarily hijacks affiliate links, injects invisible ad frames for click fraud, and inserts Google Analytics tracking into every page visited.
🔐 Immediate Action: Users with any of the affected extensions installed should remove them immediately and consider resetting passwords for sensitive accounts as a precaution.
Amazon Disrupts Major Russian GRU Hacking Campaign Targeting Edge Devices
Amazon’s threat intelligence team has successfully disrupted a long-running cyber espionage operation attributed to the Russian GRU, which has been actively targeting Western critical infrastructure. The hackers shifted their tactics from exploiting zero-day vulnerabilities to aggressively targeting misconfigured edge devices like VPN gateways and routers to harvest credentials and intercept traffic.
Key takeaways:
😈 State-Sponsored Threat: The campaign is linked to notorious GRU sub-groups, including Sandworm (APT44) and Curly COMRades, focusing heavily on the energy sector.
📉 Tactical Shift: Attackers are moving away from complex exploits and instead focusing on “low-hanging fruit”—misconfigured network appliances with exposed management interfaces.
☁️ Cloud Targeting: The compromised devices were largely customer-managed network appliances hosted on AWS EC2 instances, though the AWS platform itself was not compromised.
🕵️ Passive Interception: Evidence suggests the attackers used passive packet capturing to steal credentials and move laterally across networks with minimal noise.
🚨 Immediate Action: Amazon has notified affected customers and recommends auditing network devices, isolating management interfaces, and enabling robust logging like CloudTrail and GuardDuty.
Sophisticated Cryptomining Campaign Targets EC2 and ECS
Amazon GuardDuty has identified a coordinated cryptomining operation that leverages compromised IAM credentials to deploy massive mining infrastructure across Amazon EC2 and ECS. The campaign is notable for its use of advanced persistence techniques and “DryRun” reconnaissance to bypass traditional detection.
Key takeaways
🕵️♂️ Stealthy Reconnaissance: Attackers used the RunInstances API with the DryRun flag to validate permissions and service quotas without launching resources, effectively mapping out the environment while minimizing their forensic footprint.
🛡️ Novel Persistence Mechanism: The threat actors utilized the ModifyInstanceAttribute action to set disableApiTermination to true on all launched instances, preventing immediate termination via the console or CLI and complicating incident response.
📈 Aggressive Infrastructure Scaling: The campaign systematically created 14 Auto Scaling Groups configured to scale up to 999 instances, specifically targeting high-performance GPU and machine learning instances for maximum mining efficiency.
⚠️ Secondary Phishing Risk: Beyond resource theft, attackers created new IAM users with AmazonSESFullAccess, likely preparing the infrastructure to launch large-scale phishing campaigns using the victim’s trusted domain.
💡 Proactive Defenses: Organizations should immediately enforce Multi-Factor Authentication (MFA), transition to temporary credentials, and monitor for unusual service quota discovery or DryRun API patterns.
WhatsApp “GhostPairing” Campaign Exploits Device Linking to Hijack Accounts
Threat actors are abusing WhatsApp’s legitimate device-linking feature in a deceptive social engineering campaign dubbed “GhostPairing” to hijack user accounts. By tricking victims into authorizing legitimate pairing codes on fraudulent verification pages, attackers gain full access to private conversations and media history without bypassing traditional security layers.
Key takeaways
🕵️♂️ Deceptive Social Engineering: The attack leverages messages from compromised contacts sharing “photo” links, using fake Facebook previews and typosquatted domains to build trust and capture victim phone numbers.
🦠 Feature Abuse: Attackers initiate a real WhatsApp pairing workflow for their own browser and display the generated code on a fraudulent site, convincing the user to authorize the malicious link.
🔓 High Impact Hijacking: A successful link grants hackers real-time access to all messages and shared files, allowing them to impersonate the victim and forward lures to the victim’s own contacts.
🔍 Silent Persistence: Because the malicious session runs in the background, many users remain unaware of the breach; the only way to detect the compromise is by auditing “Linked Devices” in the app settings.
🔒 Critical Protection: To stay safe, enable two-factor authentication (2FA), remain skeptical of unexpected links even from friends, and regularly check your WhatsApp settings for unauthorized devices.
Maximum-Severity Cisco Zero-Day Under Active Attack
Cisco has issued a critical warning regarding an unpatched, maximum-severity zero-day vulnerability (CVE-2025-20393) in AsyncOS, which is being actively exploited by a Chinese-nexus threat group. The flaw targets Cisco Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances, allowing attackers to execute arbitrary commands with root privileges.
Key takeaways
🕵️♂️ State-Sponsored Exploitation: The Chinese-linked threat actor UAT-9686 is bypassing standard security to deploy “AquaShell” persistent backdoors and “AquaTunnel” malware for stealthy long-term access.
🦠 Specific Attack Surface: This vulnerability specifically affects appliances with the Spam Quarantine feature enabled and exposed to the internet.
🛠️ No Patch Available: As of now, there is no official security update, making immediate manual defensive measures essential for all affected organizations.
🛡️ Critical Mitigation Steps: Admins are urged to restrict internet access to these appliances, limit connections to trusted hosts, and place vulnerable systems behind a robust firewall.
🔍 Compromise Verification: If an appliance has been internet-exposed, Cisco recommends opening a Technical Assistance Center (TAC) case to perform a forensic verification of potential compromise.
New Chinese APT “LongNosedGoblin” Weaponizes Windows Group Policy for Stealthy Espionage
Researchers have uncovered a previously undocumented China-aligned threat cluster, LongNosedGoblin, targeting governmental entities in Southeast Asia and Japan by abusing core Windows management tools. By leveraging native Group Policy for malware deployment and popular cloud services for command and control (C&C), this actor effectively blends into legitimate network telemetry to conduct long-term cyber espionage.
Key takeaways:
🏢 Group Policy Abuse: The group utilizes Windows Group Policy as a native deployment mechanism to propagate malware across compromised networks, allowing them to move laterally without triggering traditional security alerts.
☁️ Cloud-Native C&C: Custom tools such as “NosyDoor” and “NosyStealer” hijack legitimate cloud services—including Microsoft OneDrive, Google Drive, and Yandex Disk—to mask command-and-control traffic as routine user activity.
🛠️ Modular “Nosy” Toolset: The adversary employs a sophisticated suite of .NET applications specifically designed to harvest browser history, log keystrokes, and exfiltrate encrypted data archives.
🕵️ Targeted Execution Guardrails: To maintain a low forensic footprint, the malware uses AppDomainManager injection and execution guardrails to ensure it only activates on specific, high-value target machines.
🛡️ Actionable Defense: Security teams are urged to monitor for unauthorized changes to Group Policy Objects (GPOs) and audit outbound traffic to personal cloud storage accounts to detect potential exfiltration.
Kimsuky APT Hijacks Logistics Lures to Spread New “DocSwap” Android RAT
The North Korean threat group Kimsuky is targeting mobile users with a sophisticated campaign that uses QR codes and fake CJ Logistics phishing sites to deliver the “DocSwap” malware. This Android Trojan exploits user trust and accessibility permissions to conduct deep-level device surveillance and credential theft.
Key takeaways:
🚨 QR Phishing Tactics: Attackers use malicious QR codes hosted on sites mimicking legitimate delivery services like South Korea’s CJ Logistics to lure users into downloading harmful APKs.
🦠 RAT Capabilities: DocSwap provides full Remote Access Trojan (RAT) functionality, enabling attackers to record audio/video via camera and microphone, steal files, and execute shell commands.
🔓 Accessibility Abuse: The malware aggressively requests “Accessibility Services” permissions to bypass security controls, capture sensitive user keystrokes, and monitor session data.
🛡️ Social Engineering: Kimsuky tricks victims by claiming the app is a “safe official release,” a tactic specifically designed to persuade users to ignore Android’s built-in “Unknown Sources” security warnings.
💡 Defense Strategy: Organizations should enforce mobile application management (MAM) policies that restrict sideloading and educate employees on the high risks associated with scanning unverified QR codes for software or services.
Top Tips of the Week

Threat Hunting
- Continuously learn and stay updated on the latest cyber threat techniques, tools, and trends. A dynamic knowledge base is key to effective threat hunting.
- Recognize threats by understanding your network’s normal behavior. Anomalies stand out when you know what’s standard.
- Integrate threat intelligence into security awareness programs. Educate employees to recognize and report potential threats.
Custom Tooling
- Leverage encryption for sensitive data in custom tools. Protect confidential information from unauthorized access and data breaches.
Feature Video
Still manually sketching attack chains from 40-page PDF reports on a Monday morning?
There is a better way to visualize threat intelligence without drowning in dense technical prose with FlowViz!
🚀 Instant Visualization: FlowViz is an open-source tool that uses LLMs (like Claude) to turn unstructured reports into interactive MITRE ATT&CK flow diagrams in under 60 seconds.
🎬 Cinematic Story Mode: Struggle to explain complex breaches to the Board? “Story Mode” animates the attack path, turning a static graph into a dynamic movie for executive briefings.
🖼️ Multimodal Analysis: Unlike standard text parsers, FlowViz can actually read and extract context from embedded screenshots, command line outputs, and architecture diagrams.
⚡ Human Augmentation: It doesn’t replace the analyst; it gives you an 80% rough draft instantly, turning 3 hours of grunt work into 15 minutes of verification.
Feature Course
Learning Resources

Cyber Training
- Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
- TCM Academy: A comprehensive suite of courses including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
- Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.
Tools
- Octoparse: A no-code solution that will save you time, energy, and money. Let me show you how to use it to build your custom cyber threat intelligence web scraping tool!



