Triaging the Week 104

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Sandworm Unleashes New “DynoWiper” in Major Attack on Poland’s Energy Grid

Hackers linked to the notorious Russian GRU unit Sandworm (APT44) launched a sophisticated, large-scale cyberattack against Poland’s energy infrastructure in late December 2025. The operation utilized a previously undocumented data-wiping malware, dubbed DynoWiper, specifically designed to “brick” Windows-based systems and cause widespread blackouts.

Key takeaways

🦠 Destructive New Malware: The attack introduced DynoWiper (Win32/KillFiles.NMO), a destructive tool that irreversibly overwrites files and corrupts system components to render infrastructure inoperable.

🎯 Strategic Targeting: Attackers focused on the communication layers of renewable energy sources (wind and solar) and heat-and-power plants, aiming to trigger a frequency collapse in the national grid during peak winter demand.

🗓️ Symbolic Timing: The strike occurred on the 10th anniversary of the 2015 Sandworm-orchestrated blackout in Ukraine, signaling an escalation of Russian hybrid warfare tactics against NATO members.

🛡️ Defensive Success: Polish cybersecurity forces identified anomalous traffic patterns and contained the threat before any operational disruption occurred, preventing a near-miss blackout that could have affected 500,000 people.

🔒 Regulatory Response: In light of the attack, Poland is finalizing the Act on the National Cybersecurity System to impose stricter risk management and protection requirements on IT and OT (operational technology) environments.

BleepingComputer

1Password Level Ups: New Real-Time Protection Against Phishing

In a major move to protect users from credential theft, 1Password has introduced a proactive security feature: real-time pop-up warnings for suspected phishing sites. This update directly tackles the rise of “look-alike” domains by alerting users before they autofill their sensitive data into a fraudulent site.

Key takeaways

⚠️ Proactive Warnings: When a user visits a site that mimics a known service but doesn’t match the stored URL, 1Password now triggers a prominent visual warning to block accidental data entry.

🔍 Smart Matching: The feature uses advanced logic to detect subtle “typosquatting” (e.g., 1passvvord.com vs 1password.com) that human eyes often miss during a busy workday.

🛑 Preventing “Auto-Pilot” Mistakes: By interrupting the autofill process, the tool forces a “moment of friction,” requiring users to manually confirm they trust the site before proceeding.

🏢 Enterprise Security: For IT admins, this reduces the risk of corporate credential harvesting, which remains a leading entry point for ransomware and data breaches.

🛡️ Defense in Depth: While no tool is 100% foolproof, integrating phishing detection directly into the password manager creates a seamless “Zero Trust” workflow for the average user.

1Password

Konni Hackers Weaponize AI to Target Blockchain Developers

A new cyber espionage campaign by the North Korea-linked threat actor Konni (Opal Sleet) is making headlines for its use of AI-generated malware. Targeting blockchain engineers and developers across the Asia-Pacific region, the group is moving beyond traditional spear-phishing into more sophisticated, automated territory.

Key takeaways

🤖 AI-Built Backdoors: The group is now using AI-generated PowerShell malware to create persistent backdoors. This allows them to iterate faster and produce code that is harder for traditional antivirus tools to flag.

🏢 Targeting the Development Pipeline: The lures are specifically designed to look like legitimate blockchain project documentation (e.g., technical architecture, budgets). The goal is to compromise dev environments to steal API credentials, source code, and cryptocurrency.

📦 Multi-Stage Infection: The attack typically starts with a Discord-hosted link delivering a ZIP archive. Once opened, it executes a complex chain involving LNK shortcuts, CAB archives, and UAC bypass techniques to gain admin privileges.

🌏 Geographic Expansion: While historically focused on South Korea, this latest wave has seen samples uploaded from Japan, Australia, and India, indicating that Konni is broadening its scope to global Web3 and crypto hubs.

💡 Evolving Tactics: This campaign mirrors a broader trend among North Korean groups (such as Lazarus), which impersonate recruiters and use “technical screens” to trick high-value targets into installing malware.

🎯 Threat Hunting Package

Check Point

New “ClickFix” Attack Abuses Trusted Microsoft App-V Scripts to Deploy Malware

Cybercriminals have evolved the notorious “ClickFix” tactic, now abusing a signed Microsoft Application Virtualization (App-V) script to bypass security filters. By tricking users into running a command via a fake CAPTCHA, attackers are successfully deploying the Amatera infostealer while hiding malicious activity behind trusted Windows components.

Key takeaways

🛠️ Living-off-the-Land (LotL): The attack leverages a legitimate, signed Microsoft script (SyncAppvPublishingServer.vbs) to proxy PowerShell execution, making the malicious behavior appear as a trusted system process.

🧩 Fake CAPTCHA Deception: Victims are lured to a site showing a fake human verification check that instructs them to manually paste a malicious command into the Windows “Run” dialog.

🖼️ Stealthy Steganography: To evade network detection, the campaign hides its secondary payloads inside seemingly harmless PNG images hosted on public CDNs, extracting the code only once it’s in memory.

📅 Google Calendar C2: The malware retrieves its configuration data from base64-encoded values hidden within public Google Calendar events, further blending in with legitimate web traffic.

🛡️ Actionable Defense: Organizations should consider restricting access to the Windows Run dialog (via GPO), removing unused App-V components, and enabling enhanced PowerShell logging to detect these sophisticated execution chains.

🎯 Threat Hunting Package

BlackPoint Cyber

Critical NPM Bypass: “Shai-Hulud” Defenses Thwarted via Git Dependencies

Security researchers have uncovered “PackageGate,” a series of vulnerabilities allowing hackers to bypass NPM’s newest security defenses. By leveraging Git dependencies, attackers can achieve full code execution on developer machines—even when the –ignore-scripts safety flag is enabled—leaving the JavaScript ecosystem vulnerable to a new wave of supply-chain attacks.

Key takeaways

🛠️ The Git Dependency Loophole: Attackers can use a malicious .npmrc file within a Git repository to override the git binary path, forcing NPM to execute arbitrary code during the installation process.

🛡️ –ignore-scripts Isn’t Enough: While developers use this flag to prevent malicious lifecycle scripts, this bypass triggers execution via the underlying version control system, rendering the primary defense mechanism useless.

⚠️ “Works as Expected”: While Bun, vlt, and pnpm have issued patches, NPM initially rejected the findings, stating the behavior is by design, though GitHub has since confirmed they are working on a solution.

📈 Massive Potential Impact: This follows the original “Shai-Hulud” attacks, which compromised hundreds of packages and exposed over 400,000 developer secrets; this bypass effectively re-opens that door.

💡 Immediate Action: Developers should vet all Git-based dependencies rigorously and consider using lockfile integrity checks and granular access tokens (2FA) to fortify their local environments.

Koi Security

Fortinet FortiCloud SSO Zero-Day Exploited in the Wild

Fortinet has confirmed a sophisticated new zero-day attack (CVE-2026-24858) that allows unauthenticated attackers to bypass Single Sign-On (SSO) authentication and gain full administrative control of FortiGate devices. Alarmingly, this campaign has successfully targeted firewalls that were fully patched against previous December 2025 vulnerabilities, signaling a critical new “alternate path” for exploitation.

Key takeaways:

🛡️ Critical Bypass: Attackers are using crafted SAML messages to bypass SSO logins, even on devices running the most recent firmware versions like FortiOS 7.4.10.

🕵️ Rogue Account Creation: Once access is gained, threat actors rapidly create local administrative accounts (e.g., audit, backup, itadmin, secadmin, support) to ensure long-term persistence.

📦 Data Exfiltration: Malicious actors have been observed exporting full device configuration files via the GUI, which likely contain hashed credentials and sensitive network mapping data.

🛑 Immediate Mitigation: Admins should immediately disable the “Allow administrative login using FortiCloud SSO” setting and apply the latest emergency patches (FortiOS 7.4.11+).

🔒 Network Hardening: Restrict administrative access to trusted internal IP addresses only by implementing “local-in” policies to prevent exposure to the public internet.

🎯 Threat Hunting Package

Fortinet

The 2-Year-Old WinRAR Bug That Still Grants Access to Hackers

Despite a critical patch being released in August 2023, cybercriminals and state-sponsored threat actors continue to successfully exploit a major path traversal vulnerability (CVE-2023-38831) in WinRAR. This persistent threat highlights a massive global failure in patch management, as attackers use “zombie” vulnerabilities to breach even modern networks.

Key takeaways

🚨 Global Exploitation: High-profile hacking groups like Sandworm and APT40 are actively using this flaw to target government, finance, and energy sectors worldwide.

🕵️ Deceptive Execution: Attackers craft malicious ZIP archives that appear to contain harmless PDFs or images, but trigger hidden code execution the moment a user attempts to open the file.

🛡️ Critical Update Needed: If your organization is running any version of WinRAR older than 6.23, you are currently exposed to remote code execution. Update to the latest version (7.01+) immediately.

💡 Legacy Risk: This campaign proves that hackers don’t always need “new” bugs; they simply wait for users to ignore “old” updates for utility software that often flies under the radar of IT audits.

🔒 Validate Your Stack: Treat every desktop utility, from file archivers to PDF readers, as a potential entry point. If it hasn’t been updated in six months, it’s a liability.

🎯 Threat Hunting Package

Google Threat Intelligence Group 

New Tsundere Botnet Leveraging Game Lures and Web3 for Stealth

Security researchers have uncovered the “Tsundere” botnet, a resilient Windows-based threat using fake game setups and Ethereum blockchain to evade detection. Hackers are exploiting the popularity of titles like Valorant and CS2 to deploy Node.js-based malware capable of total system takeover.

Key takeaways:

👾 Predatory Lures: Malicious MSI and PowerShell files are disguised as installers for AAA games (Valorant, CS2, Rainbow Six Siege) to target unsuspecting gamers.

⛓️ Web3 Resilience: By using Ethereum smart contracts to host C2 addresses, threat actors can rotate their infrastructure instantly with a single blockchain transaction.

⚡ Node.js Bot Architecture: The bot exploits the pm2 process manager to maintain persistence and execute arbitrary JavaScript code retrieved via encrypted WebSockets.

🕵️‍♂️ InfoStealer Connection: Tsundere is linked to ‘123 Stealer,’ suggesting that initial access is often followed by high-value credential and cryptocurrency theft.

🛡️ Immediate Action: Audit systems for unauthorized Node.js environments and strictly enforce the use of official, verified software distribution platforms.

🎯 Threat Hunting Package

Proofpoint

Malicious PyPI Alert: Fake Spellcheckers Hiding Python RATs

Developers, it’s time to audit your requirements! Researchers have uncovered sophisticated malicious packages on the Python Package Index (PyPI) that masquerade as spellcheckers to deliver a stealthy Remote Access Trojan (RAT).

Key takeaways:

📦 Deceptive Branding: The packages spellcheckerpy and spellcheckpy mimicked the popular pyspellchecker library, successfully tricking developers into over 1,000 downloads before being removed.

🕵️ Advanced Obfuscation: In a clever move to evade detection, the Base64-encoded payload was concealed inside a Basque language dictionary file (eu.json.gz), rather than the typical __init__.py script.

🌑 The “Dormant” Strategy: The threat actor published several harmless versions of the code first to bypass initial security checks, only “flipping the switch” to activate the malicious trigger in version 1.2.0.

💻 Total System Access: Once the package is imported, the RAT fingerprints the host machine and connects to a remote server, allowing attackers to execute arbitrary commands and steal sensitive data.

🤖 The AI Hallucination Risk: This campaign highlights the rise of “slopsquatting,” where hackers claim package names that AI coding assistants frequently hallucinate, leading developers to unknowingly install malware.

🎯 Threat Hunting Package

Aikido

WhatsApp Deploys “Lockdown Mode” to Shield High-Risk Users from Targeted Spyware

Meta has officially rolled out “Strict Account Settings,” a powerful new security layer designed to protect journalists, activists, and public figures from sophisticated zero-click cyberattacks. This feature introduces extreme safeguards that prioritize user safety over convenience to neutralize advanced surveillance threats like Pegasus.

Key takeaways

🛡️ Total Account Lockdown: Activating this feature instantly flips your privacy settings to the most restrictive levels, hardening the app against high-level exploitation and data harvesting.

🚫 Zero-Click Prevention: WhatsApp now automatically blocks all media, attachments, and link previews from unknown senders, effectively closing off the primary infection vectors used by modern spyware.

🔇 Communication Shield: Incoming calls from unknown numbers are silenced by default, preventing attackers from using call-based vulnerabilities to compromise a device without any user interaction.

👥 Privacy Wall: Access to your profile photo, “Last Seen” status, and “About” details is strictly limited to verified contacts to prevent reconnaissance and footprinting by threat actors.

🦀 Under-the-Hood Hardening: The platform is migrating its media-sharing infrastructure to the Rust programming language, providing a robust defense-in-depth against the memory-safety bugs typically targeted by hackers.

WhatsApp

Max-Severity Sandbox Escape Hits vm2 Node.js Library

A critical vulnerability (CVE-2026-22709) with a 9.8 CVSS score has been discovered in the popular vm2 library, allowing attackers to bypass security boundaries. This flaw enables untrusted code to escape its sandboxed environment and execute arbitrary commands directly on the host operating system.

Key takeaways:

🔓 Sandbox Breach: Attackers can bypass sanitization for Promise prototype handlers, turning a restricted execution environment into a launchpad for full system compromise.

⚙️ The “Global Promise” Flaw: The vulnerability stems from how async functions return globalPromise objects, which evade the strict sanitization logic applied to local sandboxed promises.

📉 Recurring Risk: This discovery is the latest in a long history of high-severity escapes for vm2, highlighting the extreme difficulty of maintaining secure in-process JavaScript isolation.

🛠️ Immediate Action Required: Developers using vm2 to run untrusted input must update to version 3.10.3 immediately to mitigate active exploitation risks.

🛡️ Migrate for Safety: Given the library’s fragile security history, researchers strongly recommend migrating to more robust alternatives like isolated-vm or using containerized isolation (Docker).

Semgrep

Match Group Breach: 10 Million Records Leaked via Sophisticated Vishing Campaign

Match Group has confirmed a cybersecurity incident affecting Hinge, Tinder, and OkCupid after the ShinyHunters threat group compromised an Okta SSO account through social engineering. While financial data and private messages remain secure, 1.7 GB of user tracking data and internal documents have been exposed.

Key takeaways

📞 Vishing Attack Vector: Hackers used a sophisticated voice phishing (vishing) campaign and a deceptive ‘matchinternal.com’ domain to hijack a single sign-on (SSO) account.

🔓 Multi-Platform Exposure: The breach granted unauthorized access to the company’s marketing analytics (AppsFlyer) and cloud storage across Google Drive and Dropbox.

🛡️ Phishing-Resistant MFA: This incident highlights that traditional push-based or SMS MFA is no longer enough; experts urge a shift toward FIDO2 security keys and passkeys.

🔍 Shadow API Monitoring: Security teams must implement strict app authorization policies and monitor logs for anomalous API activity to detect unauthorized device enrollments early.

⚠️ Ongoing Notification: Match Group is currently notifying affected individuals, though they maintain the incident impact involves a “limited” amount of PII.

BleepingComputer

Hugging Face Abused to Distribute Android Malware

Cybercriminals are now weaponizing the AI community’s trust. A sophisticated new campaign has turned Hugging Face into a repository for over 6,000 variants of a credential-stealing Trojan. Disguised as a security tool called “TrustBastion,” this malware uses server-side polymorphism to evade detection and drain financial accounts.

Key takeaways

🤖 Abusing AI Repositories: Threat actors used Hugging Face’s trusted infrastructure and CDN to host malicious APKs, making the downloads appear legitimate to standard network security filters.

🎭 The “Scareware” Hook: Victims are lured via ads claiming their device is infected, prompting the installation of a fake security app that then pushes a “mandatory update” mimicking the Google Play Store.

🔄 Polymorphic Evasion: The attackers utilized server-side automation to commit new malware variants every 15 minutes, resulting in thousands of unique samples to bypass signature-based antivirus tools.

🔓 Accessibility Service Exploitation: Once installed, the malware tricks users into granting Accessibility permissions, allowing it to log keystrokes, capture screens, and overlay fake login pages for apps like Alipay and WeChat.

🛡️ Hygiene is Mandatory: This serves as a critical reminder to disable “Install from Unknown Sources” and to be extremely skeptical of security “alerts” originating from web browsers or third-party ads.

🎯 Threat Hunting Package

Bitdefender

Google Pulls the Rug Out From IPIDEA: Global Proxy Network Dismantled

In a massive blow to cybercrime infrastructure, Google has disrupted IPIDEA, one of the world’s largest residential proxy networks. By taking legal action and seizing dozens of domains, Google has neutralized a marketplace that sold access to over 6 million hijacked consumer devices used for everything from state-sponsored espionage to massive credential stuffing attacks.

Key takeaways

🕸️ Weaponized Residential IPs: IPIDEA functioned by routing malicious traffic through home internet connections, allowing over 550 threat groups (including APTs from Russia and China) to “hide in plain sight” while attacking corporate networks.

📦 Hidden in Plain Sight: The network grew by embedding malicious SDKs (like Castar and Earn SDK) into 600+ Android apps and “monetization” tools that promised users cash for their unused bandwidth, effectively turning their devices into exit nodes.

📺 IoT & Smart TV Risk: Malware was frequently found pre-installed on off-brand Android TV streaming boxes, silently participating in DDoS attacks and relaying commands behind household firewalls.

🛡️ Automated Protection: Google has updated Play Protect to automatically warn users and remove apps containing IPIDEA code; however, users should remain vigilant of “free VPN” apps like Galleon and Radish VPN.

🛑 Critical Infrastructure Takedown: The disruption affected multiple subsidiary brands, including 360 Proxy, 922 Proxy, and Luna Proxy, dealing a significant blow to the “proxy-as-a-service” economy.

🎯 Threat Hunting Package

Google Threat Intelligence Group 

The Shadow AI Layer: 175,000 Ollama Servers Exposed Worldwide

A massive joint investigation by SentinelOne and Censys has uncovered a sprawling, unmanaged layer of AI infrastructure consisting of 175,000 publicly accessible Ollama hosts. These servers, often running in residential networks, bypass enterprise guardrails and are being actively commercialized by cybercriminals in a new trend called “LLMjacking.”

Key takeaways

🛠️ Trivial Exposure Risk: While Ollama binds to the local host by default, a simple configuration change to “0.0.0.0” can inadvertently expose powerful AI models to the entire internet without authentication.

🏴‍☠️ Rise of LLMjacking: Threat actors (such as those behind ‘Operation Bizarre Bazaar’) are scanning for these exposed servers to resell AI compute power on the criminal underground, leaving the original owners to foot the bill.

⚙️ Dangerous Tool-Calling: Nearly half of these exposed hosts have “tool-calling” enabled, allowing attackers to not just generate text, but to execute code, access private APIs, and interact with external systems.

🛡️ Lack of Governance: Over 30% of these exposures are located in China, with significant footprints in the U.S. and Germany, highlighting a global lack of monitoring for edge-deployed AI compute.

🔒 Essential Security Hygiene: Organizations must treat local AI deployments with the same rigor as any other web-facing infrastructure, implementing strict authentication, network controls, and continuous monitoring.

SentinelLabs


Feature Video

Feel like a line cook just following recipes in the SOC? 👨🍳 It might be time to become the chef and write your own cookbook.

Learn what detection engineering is and how to become one in this video!

🔄 Flip the Script: Stop waiting for a vendor’s “black box” to tell you something is wrong. Detection Engineering moves you from a reactive posture to a proactive defense architect.

💻 Detection as Code: It’s not just writing queries; it’s engineering. Treat your detections like software with version control, automated testing, and CI/CD pipelines to reduce false positives.

🔺 Climb the Pyramid of Pain: Move beyond easy-to-change indicators like IPs and hashes. Focus on TTPs (behaviors) to make attacks fundamentally expensive and painful for the adversary.

🧠 The Hybrid Skill Set: This role combines the best of three worlds: the coding chops of a developer, the query mastery of a senior analyst, and the deep OS knowledge of a researcher.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training equips students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools