Triaging the Week 106

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

OpenClaw Taps VirusTotal to Fight Malicious Skills

OpenClaw (formerly Moltbot) has officially partnered with VirusTotal to implement mandatory security scanning for all agentic skills in its ClawHub marketplace. This critical move follows the discovery of hundreds of “Agentic Trojan Horses”—malicious plugins designed to exfiltrate data and install backdoors under the guise of productivity tools.

Key takeaways:

🔍 AI-Powered Code Inspection: Every skill bundle is now analyzed using VirusTotal’s “Code Insight,” an LLM-driven tool that identifies suspicious logic and malicious patterns that traditional signatures often miss.

🔄 Continuous Integrity Monitoring: To prevent “sleeper” attacks, all active marketplace skills undergo daily re-scanning to ensure they haven’t been weaponized post-approval.

⚠️ Combating Data Exfiltration: This defense specifically targets threats aimed at stealing sensitive .env files, API keys, and session tokens from the 30,000+ OpenClaw instances currently exposed online.

🛡️ Supply Chain Vigilance: While a major step forward, researchers warn that scanning is not a “silver bullet”—hardening identity controls and execution boundaries remains the primary defense against sophisticated prompt injections.

OpenClaw

Global Espionage Alert: “Shadow Campaigns” Infiltrate 155 Countries

A massive, state-sponsored cyber-espionage operation dubbed “Shadow Campaigns” has been unmasked, targeting government and critical infrastructure entities across 155 countries. Attributed to the threat group TGR-STA-1030 (UNC6619), this operationally mature actor is successfully harvesting high-stakes political, economic, and strategic intelligence on a global scale.

Key Takeaways

🌐 Massive Global Footprint: The operation has conducted reconnaissance on 155 countries and successfully breached over 70 high-value organizations, including government ministries, law enforcement, and critical infrastructure in 37 nations.

🚨 Invisible Kernel Stealth: Attackers are deploying “ShadowGuard,” a custom Linux kernel rootkit utilizing eBPF technology. This allows the malware to hide processes and files at the kernel level, effectively bypassing most standard security and monitoring tools.

🛡️ Multi-Vector Arsenal: The group leverages a sophisticated mix of tailored phishing emails (via Mega.nz links) and the exploitation of 15+ known vulnerabilities in platforms like SAP Solution Manager and Microsoft Exchange to maintain access.

💡 Geopolitical Timing: Reconnaissance and attack spikes are meticulously timed with major world events, such as national elections and government shutdowns, to maximize the value of the intelligence exfiltrated.

🎯 Threat Hunting Package

Palo Alto Unit42

UNC3886 Breaches Singapore’s Top 4 Telcos

Singapore’s major telecommunications providers (Singtel, StarHub, M1, and Simba) were recently revealed as targets of a sophisticated cyber espionage campaign by the China-linked group UNC3886. While robust defenses prevented service disruptions, the breach underscores the extreme stealth and persistence of modern state-sponsored adversaries.

Key takeaways:

🛡️ Zero-Day Exploitation: The attackers gained initial access by exploiting an unknown vulnerability in perimeter firewalls, bypassing traditional security layers to establish a foothold.

🕵️ Advanced Stealth: The group utilized sophisticated rootkits and “living-off-the-land” techniques to maintain persistence and evade detection for an extended period.

🌐 Coordinated Response: Through “Operation Cyber Guardian,” a massive multi-agency effort involving over 100 defenders successfully contained the threat and protected sensitive customer data.

💡 Proactive Vigilance: The incident highlights that even small network anomalies can signal a major intrusion; early reporting and cross-sector collaboration are now essential for national resilience.

Singapore’s Cyber Security Agency (CSA)

SolarWinds WHD Vulnerabilities Exploited as Attackers Weaponize Velociraptor for Persistence

Threat actors are weaponizing critical vulnerabilities in SolarWinds Web Help Desk (WHD) to deploy the Velociraptor agent, turning a trusted incident response tool into a stealthy backdoor. By exploiting these flaws, adversaries can maintain long-term persistence and move laterally within compromised networks.

Key takeaways:

🚨 Critical Flaws Exploited: Attackers are leveraging vulnerabilities (including CVE-2024-28986 and CVE-2024-28987) related to hardcoded credentials and remote code execution to gain initial access.

🛡️ Weaponizing Defense Tools: By deploying the legitimate “Velociraptor” agent, hackers can blend into normal IT operations, making it extremely difficult for traditional security tools to detect their presence.

🌐 CISA KEV Warning: The active exploitation of these flaws has prompted CISA to add them to the Known Exploited Vulnerabilities (KEV) catalog, signaling an urgent threat to both public and private sectors.

🛠️ Immediate Remediation: Organizations running SolarWinds Web Help Desk must apply the latest security patches immediately to close these entry points and prevent unauthorized administrative access.

🎯 Threat Hunting Package

Huntress

TeamPCP Worm Alert: Cloud Infrastructure Under Siege by Self-Propagating Malware

A new “worm-driven” campaign by the TeamPCP threat group is aggressively targeting misconfigured cloud-native tools like Docker, Kubernetes, and Ray to build a massive criminal infrastructure. By exploiting the critical React2Shell vulnerability, these attackers are turning enterprise cloud environments into self-propagating nodes for ransomware, crypto-mining, and data theft.

Key takeaways:

🌐 Infrastructure Hijacking: The worm targets exposed Docker APIs, Kubernetes clusters, and Redis servers to install proxy and scanning tools, effectively “industrializing” cloud exploitation at scale.

🚨 React2Shell Exploit: Attackers are leveraging CVE-2025-55182 (React2Shell) with a CVSS 10.0 score to achieve remote command execution across modern web applications like React and Next.js.

🛡️ Hybrid Threat Model: TeamPCP blends compute hijacking with data extortion, publishing stolen identity records on Telegram to fuel a “self-propagating criminal ecosystem.”

💡 Critical Defense: Organizations must immediately patch React2Shell vulnerabilities, secure all cloud API endpoints with robust authentication, and monitor for unauthorized script execution (e.g., proxy.sh or kube.py).

🎯 Threat Hunting Package

Flare

Old School Tactics Meet New School Threats: The Rise of SSHStalker

A new Linux-based botnet dubbed ‘SSHStalker’ is targeting servers via SSH brute-force attacks, uniquely leveraging antiquated IRC protocols for its command-and-control communications. This throwback to 90s-era hacking proves that “obsolete” technology remains a potent tool for modern cybercriminals seeking to evade detection.

Key takeaways

🕵️ Retro Command & Control: SSHStalker utilizes IRC (Internet Relay Chat) for its C2 infrastructure, a rare tactic in the modern landscape that can bypass security tools primarily focused on monitoring HTTP/HTTPS-based malicious traffic.

🔑 Aggressive Brute-Forcing: The malware gains initial access by systematically testing credentials on Linux servers; once a match is found, the system is recruited into the botnet to await further instructions.

🛡️ Essential Hardening: To defend your environment, move beyond simple passwords to SSH keys, implement automated blocking like fail2ban, and specifically monitor for unexpected outbound traffic on legacy ports like 6667.

🚨 Detection Evasion: By using a “low and slow” approach with an uncommon protocol, SSHStalker aims to stay under the radar of standard behavioral analytics that aren’t configured to flag IRC activity as a threat.

🎯 Threat Hunting Package

Flare

macOS Security Alert: New North Korean Crypto-Theft Campaign Uncovered

Threat actors linked to North Korea are deploying a new macOS malware family called ‘HiddenRisk’ to infiltrate the cryptocurrency industry and steal digital assets. By using deceptive PDF lures and exploiting system configuration files, these state-sponsored hackers are successfully bypassing standard security protocols to gain persistent access to high-value targets.

Key takeaways

🕵️ Precision Phishing: The attack begins with highly personalized emails containing malicious PDF attachments that appear to be legitimate crypto-market research or investment news, tricking users into initiating the infection.

🔒 Bypassing macOS Defenses: The ‘HiddenRisk’ malware utilizes sophisticated techniques, including the misuse of legitimate Apple-signed applications and the exploitation of Zsh profile files, to establish persistence and evade Gatekeeper security features.

💰 High-Stakes Targets: This campaign specifically focuses on individuals and organizations within the decentralized finance (DeFi) and crypto-investment space, aiming to exfiltrate private keys and drain digital wallets.

🛡️ Defensive Measures: To protect your assets, exercise extreme caution with unsolicited documents, monitor for unauthorized changes to system configuration files, and consider using hardware wallets for significant cryptocurrency holdings.

🎯 Threat Hunting Package

Mandiant

Security Alert: Is Your “7-Zip” Installer Selling Your Bandwidth?

A new malware campaign is using typosquatted 7-Zip websites to distribute installers laced with hidden proxyware. This stealthy software turns your machine into a residential proxy node, allowing unknown third parties to route their internet traffic through your IP address without your consent.

Key takeaways

🚨 Typosquatting Trap: Attackers are leveraging lookalike domains (such as 7-zip.org.es) to deceive users; a single extra character in the URL can be the difference between a tool and a threat.

🌐 Invisible Hijacking: The malicious payload operates silently in the background, consuming your bandwidth and potentially implicating your network in suspicious or illegal activities conducted by others.

🛡️ Stick to the Source: Always download essential utilities directly from the official developer—for 7-Zip, the only legitimate source is 7-zip.org.

💡 Monitor System Behavior: If you’ve recently installed 7-Zip from a third-party site, audit your background processes for unrecognized services or unusual spikes in network activity.

🎯 Threat Hunting Package

Malwarebytes

Gemini AI is Now Powering the Full Cyber-Attack Lifecycle

A new report from Google Threat Intelligence reveals that state-sponsored actors from China, Russia, Iran, and North Korea are abusing Gemini AI across every stage of the attack lifecycle, from initial reconnaissance to data exfiltration. These adversaries are leveraging large language models (LLMs) to automate and refine their operations with unprecedented speed.

Key takeaways:

🤖 Global Adversary Adoption: Hackers are using Gemini for target profiling, generating highly convincing phishing lures, and translating malicious content to expand the reach of their campaigns.

📉 Accelerated Malware Development: The ‘HonestCue’ framework demonstrates how AI can generate and execute malicious C# code in memory, significantly lowering the barrier for sophisticated intrusions.

🔍 Advanced Social Engineering: Attackers are integrating AI into ‘ClickFix’ campaigns, using generative tools to lure users into executing malicious commands via fake troubleshooting ads.

🛡️ Intellectual Property Theft: Beyond standard hacking, adversaries are attempting “model extraction” by using thousands of prompts to replicate Gemini’s internal reasoning, posing a critical risk to AI-as-a-Service business models.

Google Threat Intelligence Group

Law Enforcement Takes Down ‘JokerOTP’ MFA-Bypass Service

Dutch police, in coordination with Interpol, have arrested the mastermind behind JokerOTP, a sophisticated tool that allowed cybercriminals to intercept Multi-Factor Authentication (MFA) codes at scale. This crackdown disrupts a significant “MFA-bypass-as-a-service” operation that fueled thousands of bank account takeovers globally.

Key takeaways:

🚔 Global Crackdown: The arrest of the 22-year-old developer marks a major victory against the commercialization of hacking tools, which lowered the barrier for low-skill attackers to commit high-level financial fraud.

📞 Automated Vishing Threats: JokerOTP functioned by automating “voice phishing” calls, tricking victims into entering their OTP codes directly into a keypad, which were then instantly captured by the attacker.

🛡️ The Vulnerability of SMS/Voice: This case serves as a critical reminder that while MFA is essential, SMS and voice-based codes are increasingly susceptible to interception and social engineering.

💡 Prioritize Phishing-Resistant MFA: Organizations and users should migrate toward more secure authentication methods, such as hardware security keys or app-based push notifications, to mitigate the risk of automated bypass tools.

Cybercrime Oost-Brabant

Ransomware Gangs are Turning Your Monitoring Tools Against You

The ‘Crazy’ ransomware group has been caught abusing legitimate employee monitoring software, such as ActivTrak, to spy on victims and maintain stealthy persistence. By blending in with standard business operations, these attackers can monitor high-value targets and prepare for encryption without raising immediate red flags.

Key takeaways:

🚨 Living off the Land: Attackers are repurposing legitimate productivity and monitoring tools to bypass EDR/AV solutions that typically trust these signed applications, making detection significantly harder.

🔒 Stealthy Surveillance: By deploying these tools, the “Crazy” gang can track user behavior and identify sensitive data in real-time, allowing them to time their final strike for maximum leverage.

🛡️ Tighten Application Control: Organizations must implement strict application whitelisting and treat the unauthorized presence of Remote Management and Monitoring (RMM) tools as a high-severity security incident.

💡 Audit Your “Normal”: Security teams should actively monitor for anomalies in administrative traffic, as the use of legitimate software is often the final precursor to a full-scale ransomware deployment.

🎯 Threat Hunting Package

Huntress

From Text Editor to Attack Vector: The Silent Execution Flaw in Windows 11 Notepad

A critical vulnerability in Windows 11 Notepad allows attackers to execute local files silently by abusing the application’s Markdown link handling. This flaw effectively turns a trusted system utility into a potential vehicle for malicious code execution through deceptive URI schemes.

Key takeaways:

🚨 The Markdown Trap: The vulnerability (CVE-2024-43570) exploits Notepad’s recently added Markdown previewer, where specially crafted links can trigger the execution of arbitrary files on a victim’s system.

🔍 Bypassing Security Prompts: Unlike typical file execution, this exploit can function without the standard security warnings, making it a highly effective tool for sophisticated social engineering and initial access.

🛡️ Immediate Patching Required: Microsoft addressed this flaw in the October 2024 security updates. Systems that haven’t been updated remain vulnerable to “living-off-the-land” style attacks using native tools.

💡 Rethink “Safe” Extensions: This incident serves as a stark reminder that even basic utilities are now complex enough to harbor execution risks; never assume a file is safe simply because it ends in .txt or .md.

BleepingComputer

Odido Data Breach: 6.2 Million Records Exposed

Dutch telecommunications giant Odido has confirmed a significant cyberattack on its customer contact system, compromising the personal data of approximately 6.2 million customers. While the company reports that passwords and billing information remain secure, the exposure of high-value personal identifiers creates a major opening for secondary attacks.

Key takeaways

🚨 High-Volume Theft: The breach involves a massive dataset including full names, IBANs (bank account numbers), dates of birth, and even passport or driver’s license numbers.

🛡️ Phishing Warning: With mobile numbers and personal details in the hands of threat actors, customers should expect a surge in highly sophisticated, “personalized” phishing and smishing (SMS phishing) attempts.

🔒 System Isolation: The attack was limited to a customer contact system; fortunately, core infrastructure containing call logs, location data, and account passwords was not impacted.

💡 Immediate Defense: Affected users must monitor their financial statements closely and remain extremely skeptical of any unsolicited communication claiming to be from Odido or financial institutions.

Odido

Lazarus Group’s New Trap: Is Your “Coding Test” a Trojan?

The North Korean-linked Lazarus Group has launched a sophisticated recruitment-themed campaign, dubbed “Graphalgo,” targeting developers across LinkedIn and Reddit. By masquerading as a blockchain firm called “Veltrix Capital,” threat actors are tricking candidates into running malicious “coding assessments” that secretly install Remote Access Trojans (RATs) via poisoned npm and PyPI dependencies.

Key takeaways

🔒 The “Clean First” Tactic: Attackers published legitimate-looking versions of packages like bigmathutils to build trust and high download counts before pushing malicious updates—a classic bait-and-switch supply chain attack.

🚨 Weaponized Job Interviews: If a “recruiter” asks you to clone a GitHub repo for a technical test, be extremely cautious; these projects are designed to trigger the infection through hidden dependencies rather than the code you’re actually reviewing.

🛡️ MetaMask & Crypto Focus: The deployed malware specifically scans for the MetaMask browser extension, signaling a clear intent to exfiltrate seed phrases and conduct financial theft once a developer’s machine is compromised.

🌐 Infrastructure Mimicry: The group is building entire digital ecosystems—complete with fake company domains and LinkedIn personas—to bypass the skepticism of even experienced security and software engineers.

🎯 Threat Hunting Package

ReversingLabs

The “AI Assistant” in Your Browser Might Be a Spy

A massive malicious campaign dubbed “AiFrame” has successfully tricked over 300,000 users into installing 30 different Chrome extensions masquerading as legitimate AI tools. These extensions, with names like “Gemini AI Sidebar” and “ChatGPT Translate,” are designed to exfiltrate your sensitive credentials, private emails, and even voice transcripts directly to attacker-controlled servers.

Key takeaways

🛑 Gmail Data Theft: 15 of these extensions specifically target Gmail, injecting scripts to read your email threads and even capture text from unsent drafts in real-time.

🕵️ Stealthy Logic Updates: By using full-screen iframes to load remote content, the attackers can change the extension’s behavior instantly without needing to pass a new security review by the Chrome Web Store.

🚨 Audio Surveillance: Beyond text, these malicious add-ons leverage the Web Speech API to trigger voice recognition and siphon conversations from your local environment.

🛡️ Critical Cleanup: If you have recently installed any “AI Sidebar” or “GPT” themed extensions, audit your browser immediately, remove suspicious tools, and perform a full password reset for your primary accounts.

🎯 Threat Hunting Package

LayerX


Feature Video

Tired of drowning in endless threat intel tabs? Drowning in endless threat intel tabs? What if you could build a powerful Cyber Threat Intelligence (CTI) aggregator for free and streamline your workflow?

This video provides a step-by-step guide on how to do it. Here are the key takeaways:

🧠 Single Pane of Glass: Discover the cognitive benefits of consolidating all your threat data into one central platform. Less stress, more focus!

🛠️ Build it for FREE: Learn how to use free tools like Inoreader to create your own CTI aggregator, no expensive platforms needed.

📊 Actionable Intel: Understand the difference between tactical, operational, and strategic intelligence to move from a data collector to a data analyst.

📚 Top-Tier Sources: Get a curated list of essential sources, including CTI blogs, CERT alerts, and researcher insights to kickstart your feed.

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools