Triaging the Week 107

Hello there 👋

Welcome back to the Kraven Security weekly newsletter, triaging the week. We round up the week’s top news stories, highlight our featured article, give you some learning resources, and finish with a few personal notes about what’s happening at the company. Enjoy!


Top News Stories

Triaging the Week News Stories

Pastebin Comments Weaponized to Hijack Crypto Swaps

Cybercriminals are now exploiting Pastebin’s comment sections to distribute “ClickFix” malware, tricking users into executing malicious JavaScript that hijacks cryptocurrency transactions. By hiding these scripts in plain sight within comments, attackers bypass standard security filters and target users looking for technical solutions or crypto tools.

Key takeaways:

🚨 The “ClickFix” Trap: Attackers lure users with fake error messages, instructing them to “fix” a problem by copying and pasting a command into their terminal or browser console—effectively bypassing all system security.

🌐 Exploiting Platform Trust: By utilizing the comment section of legitimate sites like Pastebin, hackers evade automated detection tools that typically focus only on the primary content of a page.

🔒 Crypto-Hijacking Risk: Once the script is executed, it can silently modify transaction details during crypto swaps, redirecting funds to the attacker’s wallet without the user noticing.

🛡️ Critical Defense: Never run scripts or commands provided in public comments or forums. Legitimate services will never ask you to paste code into your browser’s developer tools to fix a “connection error.”

BleepingComputer

New ClickFix Attack Abuses DNS to Deliver Stealthy Malware Payloads

Cybercriminals have evolved the “ClickFix” tactic by abusing the standard nslookup tool to retrieve malicious PowerShell scripts directly through DNS TXT records. This clever shift allows attackers to bypass traditional web security filters by hiding their payload in network traffic that is often left unmonitored.

Key takeaways:

🚨 Innovative Delivery: Unlike typical malware that downloads files via HTTP, this campaign uses DNS queries to fetch code. Since DNS is a fundamental part of internet connectivity, many security tools overlook it as a delivery vector.

🛠️ The “Copy-Paste” Trap: Victims are lured by fake “Connection Error” or “Browser Update” popups on compromised sites and are instructed to paste a command into their terminal to “fix” the issue.

🦠 Information Stealers: Once the command is executed, it triggers a chain that installs dangerous malware like Vidar or Lumma Stealer, designed to hijack credentials, crypto wallets, and sensitive data.

🛡️ Zero-Trust Terminal: Never execute commands or scripts provided by a website pop-up. Legitimate software updates from Google, Microsoft, or Apple will never require you to manually run PowerShell commands.

BleepingComputer

Hackers Weaponize Claude AI ‘Artifacts’ to Target Mac Users

Cybercriminals have evolved the “ClickFix” tactic by exploiting Anthropic’s Claude LLM “Artifacts” feature to host deceptive pages that trick macOS users into installing infostealers. By leveraging the trusted reputation of a major AI platform, attackers are bypassing traditional web filters to deliver malicious commands disguised as system “fixes.”

Key takeaways:

🧠 Abusing AI Features: Attackers use Claude’s “Artifacts” to render pixel-perfect, malicious UI components that mimic legitimate browser error messages, making the social engineering attempt highly convincing.

🍏 Mac-Specific Targeting: This campaign specifically lures macOS users with a prompt to “fix” a connection error by pasting a command into their terminal, which silently installs the Atomic macOS Stealer (AMOS).

🛡️ Bypassing Security Filters: Because the phishing content is hosted on a legitimate Anthropic subdomain, it often evades reputation-based security scanners that typically flag suspicious or newly registered domains.

🔒 Critical Defense: Never run commands or scripts provided by a website pop-up to “fix” a browser issue. Legitimate AI tools and websites will never require you to manually execute terminal code to function.

Moonlock Lab

Infostealers Stealing OpenClaw Secrets for the First Time

Cybercriminals have updated popular infostealer malware, such as Stealc and Rhadamanthys, to specifically target and exfiltrate secrets from OpenClaw. This shift signals a strategic move by threat actors to hunt for high-value developer assets and AI-related credentials over traditional consumer data.

Key takeaways

🔒 Expanded Targeting: Infostealers are evolving beyond browser cookies to hunt for specialized secrets and configuration files found in developer tools like OpenClaw.

🚨 Rapid Adoption: Multiple malware families, including Meduza and Rhadamanthys, have already integrated these capabilities, making this a widespread threat to the dev community.

💡 The AI Gold Rush: As AI development scales, attackers are prioritizing the theft of API keys and environmental secrets that grant access to powerful (and expensive) computing resources.

🛡️ Harden Your Workspace: This is a critical reminder to use robust secret management tools, avoid hardcoding credentials, and ensure that sensitive environment variables are never left exposed in local directories.

Hudson Rock

Is Your Password Manager Secure? 25 New Vulnerabilities Uncovered

A study from ETH Zurich has sent shockwaves through the cyber security community, revealing 25 distinct password recovery attacks against industry leaders Bitwarden, Dashlane, and LastPass. While these platforms promise “zero-knowledge” security, researchers demonstrated that a malicious server could bypass encryption to compromise user vaults or even entire organizational accounts.

Key takeaways

🔒 The Zero-Knowledge Gap: Researchers found that flaws in key escrow and sharing features could allow a compromised server to intercept keys, effectively breaking the promise that “only you” can access your data.

🛡️ Update Immediately: Dashlane has already patched a critical encryption downgrade vulnerability (ensure you are on version 6.2544.1 or later), while Bitwarden and LastPass are actively rolling out remediations for identified flaws.

🚨 Architectural Risks: The study categorized attacks into four main areas: key escrow exploits, flawed item-level encryption (separate from metadata), insecure sharing workflows, and legacy code that allows for “downgrade” attacks.

💡 Trust, but Verify: This research highlights that even top-tier encrypted services have “malicious server” threat models; organizations should audit their password manager’s recovery settings and limit administrative “key escrow” where possible.

ETH Zürich & Università della Svizzera italiana (USI)

Phobos Ransomware Affiliate Arrested in Poland

International law enforcement has struck a significant blow against the Phobos ransomware-as-a-service (RaaS) network with the arrest of a 47-year-old suspect in Poland. This operation, led by the Polish Central Cybercrime Bureau (CBZC) in collaboration with Europol and the FBI, targeted an individual allegedly involved in a group that has extorted over $16 million from more than 1,000 organizations since 2019.

Key takeaways:

🚨 International Law Enforcement Efficacy: The arrest was the result of a coordinated international effort (Operation Aether), proving that global cooperation can pierce the anonymity of sophisticated cybercriminal networks.

🦠 Prolific Threat Profile: Phobos and its affiliates (including 8Base) primarily target healthcare, education, and critical infrastructure, demonstrating a persistent and opportunistic threat model.

🕵️ Operational Intelligence Seized: Authorities seized devices containing hacking tools, stolen credentials, and server IP addresses, revealing how affiliates use encrypted messaging to coordinate with core ransomware operators.

🛡️ Proactive Defense is Critical: While arrests provide strategic disruption, organizations must prioritize robust offline backups and multifactor authentication (MFA) to mitigate the risk of encryption and extortion.

BleepingComputer

SmartLoader Exploits Oura MCP Servers to Deploy StealC

Cybercriminals are now targeting the intersection of AI and personal wellness by distributing a trojanized version of the Oura Model Context Protocol (MCP) server. By cloning legitimate repositories and using AI-generated lures to manufacture credibility, attackers are tricking developers and health enthusiasts into installing the StealC infostealer.

Key takeaways:

🚨 Weaponized Trust: Attackers built a deceptive infrastructure of fake GitHub forks and contributors to make the malicious Oura MCP server appear legitimate to unsuspecting users.

🔒 High-Value Data Theft: The payload is the StealC infostealer, a potent malware designed to exfiltrate sensitive credentials, browser-stored passwords, and cryptocurrency wallet data.

💡 AI-Enhanced Deception: This campaign utilizes AI-generated documentation and README files to blend seamlessly into the developer ecosystem, significantly lowering the barrier for social engineering.

🛡️ Supply Chain Vigilance: This attack highlights a critical shift toward targeting third-party integrations; users must verify the provenance of MCP servers and open-source tools before connecting them to personal or corporate data.

Straiker

AI in the Middle: Turning Web-Based AI Services into C2 Proxies

Cybersecurity researchers have uncovered a groundbreaking technique where AI assistants like Microsoft Copilot and xAI’s Grok can be manipulated into serving as stealthy command-and-control (C2) relays. By exploiting web-browsing and URL-fetching capabilities, attackers can tunnel malicious commands through trusted AI domains, effectively bypassing traditional network security filters.

Key takeaways:

🕵️ Anonymous Proxying: Attackers can use anonymous web access to interact with AI assistants, meaning no API keys or registered accounts are needed—making traditional takedown methods like key revocation useless.

🦠 AI-Driven (AID) Malware: This shift enables “AID malware” that doesn’t just use AI during development but incorporates it into its runtime decision loop to adapt tactics based on the infected host’s environment.

🛠️ Seamless Blending: Malicious C2 traffic is disguised as legitimate-looking AI interactions (summarization or browsing prompts), allowing it to blend into normal corporate data streams that are rarely treated as sensitive egress.

🛡️ Defensive Shift Required: Organizations must move beyond signature-based detection and start using AI-enhanced Network Detection and Response (NDR) to identify subtle anomalies in AI traffic patterns and beaconing.

Check Point

New research has uncovered critical vulnerabilities in widely used Visual Studio Code extensions, putting millions of developers at risk of source code theft and remote code execution. These flaws allow attackers to compromise systems simply by tricking a developer into opening a malicious file or repository within their IDE.

Key takeaways:

🚨 High-Impact Vulnerabilities: Security researchers identified flaws like Command Injection and Local File Read in extensions with millions of downloads, potentially exposing sensitive environment variables and SSH keys.

🔒 Workspace as an Attack Vector: Attackers can use “poisoned” project folders to trigger these exploits, making this a potent method for targeted attacks against developers and their organizations.

🛡️ Audit Your Extensions: It is critical to review your installed plugins immediately. Disable or remove any extensions that are no longer maintained and ensure all active ones are updated to their latest versions.

💡 Enforce Trusted Workspaces: Always utilize VS Code’s “Workspace Trust” feature; never grant trust to untrusted or third-party repositories until you have verified the contents of the codebase.

Ox Security

Notepad++ Fixes Hijacked Update Mechanism Used for Targeted Malware Delivery

Cybersecurity researchers have uncovered a sophisticated 6-month supply chain attack where state-sponsored actors hijacked the Notepad++ update process to deliver a custom backdoor called “Chrysalis.” To combat this, Notepad++ version 8.9.2 introduces a “double-lock” security design that makes the update mechanism effectively unexploitable.

Key takeaways

🔒 Double-Lock Verification: The new update enforces independent cryptographic signatures for both the update manifest (XML) and the installer binary, neutralizing the “on-path” hijacking vector used by attackers.

🚨 High-Precision Targeting: Attributed to the China-linked “Lotus Blossom” group, this breach was a selective campaign (June–December 2025) that redirected update traffic for specific high-value targets in telecom and finance.

🛡️ Critical Vulnerability Patched: Version 8.9.2 also addresses CVE-2026-25926 (CVSS 7.3), an unsafe search path flaw that could allow attackers to execute arbitrary code in the application’s context.

💡 Hardened Infrastructure: Beyond the update fix, the release eliminates DLL side-loading risks by removing libcurl.dll and mandates that all plugins be signed with authorized certificates.

Notepad++

Major Fintech Breach: Nearly 1 Million Figure Accounts Exposed

Figure, a prominent fintech firm, has confirmed a massive data breach affecting 968,000 accounts after a credential stuffing attack on a third-party service provider. Attackers successfully exfiltrated sensitive personal data, including full names, Social Security Numbers (SSNs), and dates of birth.

Key takeaways

🛑 Third-Party Risk is Real: This breach did not originate within Figure’s core systems but through a third-party vendor, highlighting the critical need for robust vendor risk management (VRM).

🔑 The Credential Stuffing Threat: Attackers used passwords leaked from other breaches to gain access; this underscores why reusing passwords across different platforms is a high-stakes gamble.

🛡️ Identity Theft Risk High: With SSNs and DOBs in the wild, affected users face a significant and long-term risk of sophisticated identity theft and targeted phishing.

💡 Immediate Action Needed: If you are a Figure customer, monitor your credit reports immediately, place a fraud alert or credit freeze, and change your passwords on all other financial accounts.

BleepingComputer

CrescentHarvest Campaign Targets Iran Protest Supporters

Cybersecurity researchers have uncovered a sophisticated espionage operation dubbed CrescentHarvest, which exploits recent political unrest in Iran to target activists, journalists, and diaspora communities with information-stealing malware. The campaign uses “heroic” protest-themed lures to deliver a novel Remote Access Trojan (RAT) designed for long-term surveillance and sensitive data exfiltration.

Key takeaways

🚨 Deceptive Social Engineering: Attackers distribute malicious RAR archives containing authentic protest footage and a Farsi-language report to build trust, hiding malicious .LNK files that masquerade as benign images or videos using double extensions (e.g., .jpg.lnk).

🔒 Advanced Info-Stealing Capabilities: The primary payload, a custom malware named CrescentHarvest, exfiltrates Telegram desktop data, browser credentials, and keystrokes, while specifically enumerating installed security tools to evade detection.

🛡️ Stealthy Execution: The campaign leverages DLL sideloading via a legitimate, Google-signed binary (software_reporter_tool.exe) and utilizes an event-based persistence mechanism that triggers the malware whenever the infected system connects to the internet.

🌐 High-Risk Targeting: While currently focused on Farsi-speaking supporters of Iranian protests, the tradecraft used suggests a state-aligned actor capable of rapidly assembling campaigns to capitalize on global geopolitical developments.

🎯 Threat Hunting Package

Arconis

New “Massiv” Android Banking Malware Disguised as IPTV App

Cybersecurity researchers have identified a new Android banking Trojan named Massiv that spreads by impersonating a legitimate IPTV streaming application. This malware targets users’ financial data by employing sophisticated overlay attacks and abusing accessibility services to gain full control over infected devices.

Key takeaways

🕵️‍♂️ Deceptive Distribution: Massiv malware disguises itself as a functional IPTV app, leveraging the high demand for streaming services to trick users into downloading malicious APKs from unofficial sources.

🔒 Credential Theft via Overlays: The Trojan uses “overlay attacks” to display fake login screens over legitimate banking and cryptocurrency apps, silently harvesting usernames and passwords.

🛡️ Abuse of Accessibility Services: Once installed, it requests permission to use Android’s Accessibility Services, allowing it to intercept 2FA codes, log keystrokes, and prevent users from uninstalling the malicious software.

🌐 Global Financial Target: While currently spreading through third-party app stores, the malware contains code to target hundreds of different banking institutions worldwide, making it a significant threat to mobile users globally.

🎯 Threat Hunting Package

ThreatFabric

Interpol Strikes Back: 20 Arrested in Global “Operation Red Card 2.0”

Interpol has successfully concluded a massive coordinated crackdown, resulting in the arrest of 20 individuals linked to a sophisticated international cybercrime syndicate. This operation underscores a major shift in how global law enforcement is leveraging cross-border intelligence to dismantle high-level digital threats.

Key takeaways

🚨 No Safe Haven: The success of Operation Red Card 2.0 proves that geographic borders are becoming less of an obstacle for international law enforcement when tracking cybercriminals.

🛡️ Infrastructure Disruption: Authorities didn’t just make arrests; they seized critical infrastructure and assets, effectively crippling the syndicate’s ability to reboot their operations.

🌐 Public-Private Power: This victory was fueled by unprecedented data sharing between cybersecurity firms and government agencies, highlighting why collaborative defense is the future of security.

🔒 Stay Vigilant: While 20 actors are off the streets, the tactics they used, specifically targeted financial fraud and BEC, remain high-risk. Now is the time to audit your organization’s external communication policies.

INTERPOL

“PromptSpy” Becomes First Known Android Malware to Use Generative AI at Runtime

Security researchers have uncovered PromptSpy, a groundbreaking Android Trojan that integrates Google’s Gemini AI directly into its execution flow to achieve unprecedented levels of persistence. By using AI to dynamically interpret and navigate a device’s user interface, this malware bypasses the limitations of traditional, hardcoded scripts, allowing it to adapt to nearly any screen layout or OS version.

Key takeaways

🤖 AI-Driven Persistence: PromptSpy sends natural-language prompts and XML screen dumps to Gemini, receiving real-time JSON instructions on how to perform specific gestures to “lock” itself in the recent apps list, preventing users from swiping it away.

🔒 Full Remote Hijacking: The primary objective is deploying a VNC (Virtual Network Computing) module, granting attackers complete remote access to view the screen, record video, and perform manual taps or swipes as if they were holding the phone.

🛡️ Invisible Defense: The malware abuses Android Accessibility Services to place invisible overlays on the screen, effectively blocking users from tapping “Uninstall” or “Force Stop” buttons within settings.

🌐 Targeted Espionage: Currently appearing as a “MorganArg” banking app targeting users in Argentina, the code contains debug strings in Simplified Chinese, suggesting a sophisticated, financially motivated developer group behind the operation.

🎯 Threat Hunting Package

ESET Research


Feature Article

image

If your CISO asked you how your CTI team plans to increase the value it provides in 2026, could you give a solid answer?

Most of us have been in that moment, scrambling for a strategy while wishing we had a concrete action plan.

The CTI-Capability Maturity Model (Cyber Threat Intelligence Capability Maturity Model (CTI-CMM)) helps solve this problem. I wrote my take on how to use the framework and I’m excited to share it’s now live on Feedly’s TI Essentials.

It covers:

→ A realistic 60-day sprint to move from foundational to advanced maturity

→ Which domains to prioritize first

→ How to run stakeholder discovery interviews (with a template)

→ The metrics that prove value vs. the metrics that just measure busywork

→ Common pitfalls I’ve seen teams fall into

The guide also features insights from Michael DeBolt, Founder of the CTI-CMM and Chief Intelligence Officer at Intel 471, on why the framework was created and his top tip for getting started.

2026 is the year to stop guessing and start maturing.

Thanks to the CTI-CMM team for contributing the framework and to Feedly for partnering on this guide.

Read Now

Feature Course


Learning Resources

Triaging the Week Learning Resources

Cyber Training

  • Zero-Point Security: Advanced training in red team operations, adversary simulation, and offensive development. They equip you with the latest tactics and techniques to succeed in security and defence strategies.
  • TCM Academy: A comprehensive suite of courses, including everything from penetration testing to malware analysis. Their hands-on, practical approach to training is designed to equip students with the real-world skills needed to succeed in cyber.
  • Blue Cape Security: A specialist in Digital Forensics and Incident Response (DFIR) training, offering courses to take you from complete beginner to expert. Learn to defend like a pro.

Tools